[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 15 20:31:07 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5316b051 by Salvatore Bonaccorso at 2026-09-15T21:30:40+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,13 +1,13 @@
 CVE-2026-92180 (pdfforge PDF Architect activation-service Update Service Uncontrolled  ...)
-	TODO: check
+	NOT-FOR-US: pdfforge PDF Architect
 CVE-2026-92179 (pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Cod ...)
-	TODO: check
+	NOT-FOR-US: pdfforge PDF Architect
 CVE-2026-92178 (pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code  ...)
-	TODO: check
+	NOT-FOR-US: pdfforge PDF Architect
 CVE-2026-92177 (pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Cod ...)
-	TODO: check
+	NOT-FOR-US: pdfforge PDF Architect
 CVE-2026-92176 (pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execu ...)
-	TODO: check
+	NOT-FOR-US: pdfforge PDF Architect
 CVE-2026-92082 (By default, Payara Server does not limit the number of failed login at ...)
 	NOT-FOR-US: Payara
 CVE-2026-92021 (Use-after-free in the JavaScript Engine: JIT component. This vulnerabi ...)
@@ -19,17 +19,17 @@ CVE-2026-92003 (Affected versions of MISP do not consistently apply the existing
 CVE-2026-92002 (Affected versions of MISP use Redis to throttle repeated authenticatio ...)
 	- misp <itp> (bug #1144317)
 CVE-2026-91998 (Casdoor through 4.4.0 contains an authorization bypass vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: Casdoor
 CVE-2026-91997 (evolution-api through 2.3.7 contains an incorrect array comparison in  ...)
-	TODO: check
+	NOT-FOR-US: evolution-api
 CVE-2026-91996 (lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for a ...)
-	TODO: check
+	NOT-FOR-US: lamp-cloud
 CVE-2026-91995 (pig before 4.1.0 contains an authentication bypass vulnerability in th ...)
-	TODO: check
+	NOT-FOR-US: pig-mesh Pig
 CVE-2026-91994 (Semaphore UI through 2.19.12 exempts GET and HEAD requests from projec ...)
-	TODO: check
+	NOT-FOR-US: Semaphore UI
 CVE-2026-91993 (Jpom through 2.11.12 fails to validate workspace ownership when resolv ...)
-	TODO: check
+	NOT-FOR-US: Jpom
 CVE-2026-91992 (Tornado before 6.5.7 contains a credential leak vulnerability in CurlA ...)
 	TODO: check
 CVE-2026-91991 (Tornado before 6.5.8 contains an incomplete fix for cookie attribute i ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5316b051028c886396b688615c178e5930f1a4b5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5316b051028c886396b688615c178e5930f1a4b5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/70131088/attachment.htm>


More information about the debian-security-tracker-commits mailing list