[Secure-testing-commits] r27649 - data/CVE

Henri Salo fgeek-guest at moszumanska.debian.org
Tue Jul 8 09:57:52 UTC 2014


Author: fgeek-guest
Date: 2014-07-08 09:57:52 +0000 (Tue, 08 Jul 2014)
New Revision: 27649

Modified:
   data/CVE/list
Log:
NFUs

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-07-08 09:41:44 UTC (rev 27648)
+++ data/CVE/list	2014-07-08 09:57:52 UTC (rev 27649)
@@ -377,23 +377,23 @@
 CVE-2014-4569 (Cross-site scripting (XSS) vulnerability in ls/vv_login.php in the ...)
 	NOT-FOR-US: WordPress plugin VideoWhisper Live Streaming Integration
 CVE-2014-4568 (Cross-site scripting (XSS) vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2014-4567
 	RESERVED
 CVE-2014-4566 (Cross-site scripting (XSS) vulnerability in res/fake_twitter/frame.php ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2014-4565 (Multiple cross-site scripting (XSS) vulnerabilities in vcc.js.php in ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2014-4564 (Cross-site scripting (XSS) vulnerability in check.php in the Validated ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2014-4563 (Cross-site scripting (XSS) vulnerability in go.php in the URL Cloak & ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2014-4562
 	RESERVED
 CVE-2014-4561
 	RESERVED
 CVE-2014-4560 (Cross-site scripting (XSS) vulnerability in includes/getTipo.php in ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin ToolPage
 CVE-2014-4559
 	RESERVED
 CVE-2014-4558
@@ -1916,7 +1916,7 @@
 CVE-2014-3858
 	RESERVED
 CVE-2014-3857 (Multiple SQL injection vulnerabilities in Kerio Control Statistics in ...)
-	TODO: check
+	NOT-FOR-US: Kerio Control
 CVE-2014-3856
 	RESERVED
 	- fish <unfixed> (low; bug #746259)
@@ -2707,7 +2707,7 @@
 	NOTE: AD-related packages removed from src:samba4 in 4.0.0~beta2+dfsg1-3.2+deb7u2
 	NOTE: https://www.samba.org/samba/security/CVE-2014-3493
 CVE-2014-3492 (Multiple cross-site scripting (XSS) vulnerabilities in the host YAML ...)
-	TODO: check
+	- foreman <itp> (bug #663101)
 CVE-2014-3491 (Cross-site scripting (XSS) vulnerability in Foreman before 1.4.5 and ...)
 	- foreman <itp> (bug #663101)
 	NOTE: Details not yet known as behind http://projects.theforeman.org/issues/5881
@@ -9246,7 +9246,7 @@
 CVE-2014-0895 (Buffer overflow in the vsflex8l ActiveX control in IBM SPSS ...)
 	NOT-FOR-US: IBM SPSS
 CVE-2014-0894 (RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before ...)
-	TODO: check
+	NOT-FOR-US: IBM Algo Credit Limits
 CVE-2014-0893 (Cross-site scripting (XSS) vulnerability in customreport.jsp in IBM ...)
 	NOT-FOR-US: IBM Maximo Asset Management
 CVE-2014-0892 (IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 ...)
@@ -9292,21 +9292,21 @@
 CVE-2014-0872
 	RESERVED
 CVE-2014-0871 (RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before ...)
-	TODO: check
+	NOT-FOR-US: IBM Algo Credit Limits
 CVE-2014-0870 (Multiple cross-site scripting (XSS) vulnerabilities in RICOS in IBM ...)
-	TODO: check
+	NOT-FOR-US: IBM Algo Credit Limits
 CVE-2014-0869 (The decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) ...)
-	TODO: check
+	NOT-FOR-US: IBM Algo Credit Limits
 CVE-2014-0868 (RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before ...)
-	TODO: check
+	NOT-FOR-US: IBM Algo Credit Limits
 CVE-2014-0867 (rcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ...)
-	TODO: check
+	NOT-FOR-US: IBM Algo Credit Limits
 CVE-2014-0866 (RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before ...)
-	TODO: check
+	NOT-FOR-US: IBM Algo Credit Limits
 CVE-2014-0865 (RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before ...)
-	TODO: check
+	NOT-FOR-US: IBM Algo Credit Limits
 CVE-2014-0864 (Multiple cross-site request forgery (CSRF) vulnerabilities in Executer ...)
-	TODO: check
+	NOT-FOR-US: IBM Algo Credit Limits
 CVE-2014-0863
 	RESERVED
 CVE-2014-0862 (Unspecified vulnerability in Jazz Team Server in IBM Rational ...)




More information about the Secure-testing-commits mailing list