[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 15 20:31:07 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5316b051 by Salvatore Bonaccorso at 2026-09-15T21:30:40+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,13 +1,13 @@
CVE-2026-92180 (pdfforge PDF Architect activation-service Update Service Uncontrolled ...)
- TODO: check
+ NOT-FOR-US: pdfforge PDF Architect
CVE-2026-92179 (pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Cod ...)
- TODO: check
+ NOT-FOR-US: pdfforge PDF Architect
CVE-2026-92178 (pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code ...)
- TODO: check
+ NOT-FOR-US: pdfforge PDF Architect
CVE-2026-92177 (pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Cod ...)
- TODO: check
+ NOT-FOR-US: pdfforge PDF Architect
CVE-2026-92176 (pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execu ...)
- TODO: check
+ NOT-FOR-US: pdfforge PDF Architect
CVE-2026-92082 (By default, Payara Server does not limit the number of failed login at ...)
NOT-FOR-US: Payara
CVE-2026-92021 (Use-after-free in the JavaScript Engine: JIT component. This vulnerabi ...)
@@ -19,17 +19,17 @@ CVE-2026-92003 (Affected versions of MISP do not consistently apply the existing
CVE-2026-92002 (Affected versions of MISP use Redis to throttle repeated authenticatio ...)
- misp <itp> (bug #1144317)
CVE-2026-91998 (Casdoor through 4.4.0 contains an authorization bypass vulnerability i ...)
- TODO: check
+ NOT-FOR-US: Casdoor
CVE-2026-91997 (evolution-api through 2.3.7 contains an incorrect array comparison in ...)
- TODO: check
+ NOT-FOR-US: evolution-api
CVE-2026-91996 (lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for a ...)
- TODO: check
+ NOT-FOR-US: lamp-cloud
CVE-2026-91995 (pig before 4.1.0 contains an authentication bypass vulnerability in th ...)
- TODO: check
+ NOT-FOR-US: pig-mesh Pig
CVE-2026-91994 (Semaphore UI through 2.19.12 exempts GET and HEAD requests from projec ...)
- TODO: check
+ NOT-FOR-US: Semaphore UI
CVE-2026-91993 (Jpom through 2.11.12 fails to validate workspace ownership when resolv ...)
- TODO: check
+ NOT-FOR-US: Jpom
CVE-2026-91992 (Tornado before 6.5.7 contains a credential leak vulnerability in CurlA ...)
TODO: check
CVE-2026-91991 (Tornado before 6.5.8 contains an incomplete fix for cookie attribute i ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5316b051028c886396b688615c178e5930f1a4b5
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5316b051028c886396b688615c178e5930f1a4b5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/70131088/attachment.htm>
More information about the debian-security-tracker-commits
mailing list