[Secure-testing-commits] r14756 - data/CVE

Michael Gilbert gilbert-guest at alioth.debian.org
Wed May 26 01:35:33 UTC 2010


Author: gilbert-guest
Date: 2010-05-26 01:35:31 +0000 (Wed, 26 May 2010)
New Revision: 14756

Modified:
   data/CVE/list
Log:
NFUs

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2010-05-26 01:22:56 UTC (rev 14755)
+++ data/CVE/list	2010-05-26 01:35:31 UTC (rev 14756)
@@ -1,15 +1,15 @@
 CVE-2010-2032 (Multiple cross-site scripting (XSS) vulnerabilities in ...)
-	TODO: check
+	NOT-FOR-US: Caucho Technology Resin Professional
 CVE-2010-2031 (KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield ...)
-	TODO: check
+	NOT-FOR-US: Kingsoft Webshield
 CVE-2010-2030 (Cross-site scripting (XSS) vulnerability in the External Link Page ...)
-	TODO: check
+	NOT-FOR-US: External Link Page module for Drupal
 CVE-2010-2029 (Cybozu Office 7 Ktai and Dotsales do not properly restrict access to ...)
-	TODO: check
+	NOT-FOR-US: Cybozu Office and Dotsales
 CVE-2010-2028 (Buffer overflow in k23productions TFTPUtil GUI (aka TFTPGUI) 1.4.5 ...)
-	TODO: check
+	NOT-FOR-US: k23productions TFTPGUI
 CVE-2010-2027 (Mathematica 7, when running on Linux, allows local users to overwrite ...)
-	TODO: check
+	NOT-FOR-US: Mathematica
 CVE-2010-2026
 	RESERVED
 CVE-2010-2025
@@ -25,23 +25,23 @@
 CVE-2010-2020
 	RESERVED
 CVE-2010-2019 (SQL injection vulnerability in downlot.php in Lokomedia CMS 1.4.1, ...)
-	TODO: check
+	NOT-FOR-US: Lokomedia CMS
 CVE-2010-2018 (Directory traversal vulnerability in downlot.php in Lokomedia CMS ...)
-	TODO: check
+	NOT-FOR-US: Lokomedia CMS
 CVE-2010-2017 (Cross-site scripting (XSS) vulnerability in hasil-pencarian.html in ...)
-	TODO: check
+	NOT-FOR-US: Lokomedia CMS
 CVE-2010-2016 (SQL injection vulnerability in details.php in Iceberg CMS allows ...)
-	TODO: check
+	NOT-FOR-US: Iceberg CMS
 CVE-2010-2015 (Multiple SQL injection vulnerabilities in LiSK CMS 4.4 allow remote ...)
-	TODO: check
+	NOT-FOR-US: LiSK CMS
 CVE-2010-2014 (Cross-site scripting (XSS) vulnerability in cp/list_content.php in ...)
-	TODO: check
+	NOT-FOR-US: LiSK CMS
 CVE-2010-2013 (Cross-site scripting (XSS) vulnerability in cp/edit_email.php in LiSK ...)
-	TODO: check
+	NOT-FOR-US: LiSK CMS
 CVE-2010-2012 (SQL injection vulnerability in function.php in MigasCMS 1.1, when ...)
-	TODO: check
+	NOT-FOR-US: MigasCMS
 CVE-2006-7239 (The _gnutls_x509_oid2mac_algorithm function in lib/gnutls_algorithms.c ...)
-	TODO: check
+	- gnutls26 <not-affected> (fix is present in lenny/sid; fixed originally in upstream 1.4.2, which precedes 26)
 CVE-2010-2011 (Microsoft Dynamics GP uses a substitution cipher to encrypt the system ...)
 	NOT-FOR-US: Microsoft Dynamics GP
 CVE-2010-2010 (Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool ...)
@@ -805,7 +805,7 @@
 CVE-2010-1689 (The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in ...)
 	NOT-FOR-US: Microsoft Windows
 CVE-2010-1688 (Stack-based buffer overflow in 2BrightSparks SyncBack Freeware ...)
-	TODO: check
+	NOT-FOR-US: 2BrightSparks SyncBack Freeware
 CVE-2010-1687 (Stack-based buffer overflow in lpd.exe in Mocha W32 LPD 1.9 allows ...)
 	NOT-FOR-US: Mocha W32 LPD
 CVE-2010-1686 (Stack-based buffer overflow in (1) Urgent Backup 3.20, and (2) ABC ...)




More information about the Secure-testing-commits mailing list