[Secure-testing-commits] r27450 - data/CVE

Joey Hess joeyh at moszumanska.debian.org
Wed Jun 25 21:14:11 UTC 2014


Author: joeyh
Date: 2014-06-25 21:14:11 +0000 (Wed, 25 Jun 2014)
New Revision: 27450

Modified:
   data/CVE/list
Log:
automatic update

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-06-25 15:56:05 UTC (rev 27449)
+++ data/CVE/list	2014-06-25 21:14:11 UTC (rev 27450)
@@ -1,10 +1,274 @@
+CVE-2014-4642
+	RESERVED
+CVE-2014-4641
+	RESERVED
+CVE-2014-4640
+	RESERVED
+CVE-2014-4639
+	RESERVED
+CVE-2014-4638
+	RESERVED
+CVE-2014-4637
+	RESERVED
+CVE-2014-4636
+	RESERVED
+CVE-2014-4635
+	RESERVED
+CVE-2014-4634
+	RESERVED
+CVE-2014-4633
+	RESERVED
+CVE-2014-4632
+	RESERVED
+CVE-2014-4631
+	RESERVED
+CVE-2014-4630
+	RESERVED
+CVE-2014-4629
+	RESERVED
+CVE-2014-4628
+	RESERVED
+CVE-2014-4627
+	RESERVED
+CVE-2014-4626
+	RESERVED
+CVE-2014-4625
+	RESERVED
+CVE-2014-4624
+	RESERVED
+CVE-2014-4623
+	RESERVED
+CVE-2014-4622
+	RESERVED
+CVE-2014-4621
+	RESERVED
+CVE-2014-4620
+	RESERVED
+CVE-2014-4619
+	RESERVED
+CVE-2014-4618
+	RESERVED
+CVE-2014-4612
+	RESERVED
+CVE-2014-4611
+	RESERVED
+CVE-2014-4610
+	RESERVED
+CVE-2014-4609
+	RESERVED
+CVE-2014-4608
+	RESERVED
+CVE-2014-4607
+	RESERVED
+CVE-2014-4606
+	RESERVED
+CVE-2014-4605
+	RESERVED
+CVE-2014-4604
+	RESERVED
+CVE-2014-4603
+	RESERVED
+CVE-2014-4602
+	RESERVED
+CVE-2014-4601
+	RESERVED
+CVE-2014-4600
+	RESERVED
+CVE-2014-4599
+	RESERVED
+CVE-2014-4598
+	RESERVED
+CVE-2014-4597
+	RESERVED
+CVE-2014-4596
+	RESERVED
+CVE-2014-4595
+	RESERVED
+CVE-2014-4594
+	RESERVED
+CVE-2014-4593
+	RESERVED
+CVE-2014-4592
+	RESERVED
+CVE-2014-4591
+	RESERVED
+CVE-2014-4590
+	RESERVED
+CVE-2014-4589
+	RESERVED
+CVE-2014-4588
+	RESERVED
+CVE-2014-4587
+	RESERVED
+CVE-2014-4586
+	RESERVED
+CVE-2014-4585
+	RESERVED
+CVE-2014-4584
+	RESERVED
+CVE-2014-4583
+	RESERVED
+CVE-2014-4582
+	RESERVED
+CVE-2014-4581
+	RESERVED
+CVE-2014-4580
+	RESERVED
+CVE-2014-4579
+	RESERVED
+CVE-2014-4578
+	RESERVED
+CVE-2014-4577
+	RESERVED
+CVE-2014-4576
+	RESERVED
+CVE-2014-4575
+	RESERVED
+CVE-2014-4574
+	RESERVED
+CVE-2014-4573
+	RESERVED
+CVE-2014-4572
+	RESERVED
+CVE-2014-4571
+	RESERVED
+CVE-2014-4570
+	RESERVED
+CVE-2014-4569
+	RESERVED
+CVE-2014-4568
+	RESERVED
+CVE-2014-4567
+	RESERVED
+CVE-2014-4566
+	RESERVED
+CVE-2014-4565
+	RESERVED
+CVE-2014-4564
+	RESERVED
+CVE-2014-4563
+	RESERVED
+CVE-2014-4562
+	RESERVED
+CVE-2014-4561
+	RESERVED
+CVE-2014-4560
+	RESERVED
+CVE-2014-4559
+	RESERVED
+CVE-2014-4558
+	RESERVED
+CVE-2014-4557
+	RESERVED
+CVE-2014-4556
+	RESERVED
+CVE-2014-4555
+	RESERVED
+CVE-2014-4554
+	RESERVED
+CVE-2014-4553
+	RESERVED
+CVE-2014-4552
+	RESERVED
+CVE-2014-4551
+	RESERVED
+CVE-2014-4550
+	RESERVED
+CVE-2014-4549
+	RESERVED
+CVE-2014-4548
+	RESERVED
+CVE-2014-4547
+	RESERVED
+CVE-2014-4546
+	RESERVED
+CVE-2014-4545
+	RESERVED
+CVE-2014-4544
+	RESERVED
+CVE-2014-4543
+	RESERVED
+CVE-2014-4542
+	RESERVED
+CVE-2014-4541
+	RESERVED
+CVE-2014-4540
+	RESERVED
+CVE-2014-4539
+	RESERVED
+CVE-2014-4538
+	RESERVED
+CVE-2014-4537
+	RESERVED
+CVE-2014-4536
+	RESERVED
+CVE-2014-4535
+	RESERVED
+CVE-2014-4534
+	RESERVED
+CVE-2014-4533
+	RESERVED
+CVE-2014-4532
+	RESERVED
+CVE-2014-4531
+	RESERVED
+CVE-2014-4530
+	RESERVED
+CVE-2014-4529
+	RESERVED
+CVE-2014-4528
+	RESERVED
+CVE-2014-4527
+	RESERVED
+CVE-2014-4526
+	RESERVED
+CVE-2014-4525
+	RESERVED
+CVE-2014-4524
+	RESERVED
+CVE-2014-4523
+	RESERVED
+CVE-2014-4522
+	RESERVED
+CVE-2014-4521
+	RESERVED
+CVE-2014-4520
+	RESERVED
+CVE-2014-4519
+	RESERVED
+CVE-2014-4518
+	RESERVED
+CVE-2014-4517
+	RESERVED
+CVE-2014-4516
+	RESERVED
+CVE-2014-4515
+	RESERVED
+CVE-2014-4514
+	RESERVED
+CVE-2014-4513
+	RESERVED
+CVE-2014-4512
+	RESERVED
+CVE-2014-4511
+	RESERVED
+CVE-2014-4509 (The MKDQUOTESAFE function in the Fan-out driver scripts in Fan-Out ...)
+	TODO: check
+CVE-2014-4507 (Directory traversal vulnerability in Smart-Proxy in Foreman before ...)
+	TODO: check
+CVE-2014-4506 (Cross-site scripting (XSS) vulnerability in the Custom Meta module ...)
+	TODO: check
+CVE-2014-4505 (Cross-site scripting (XSS) vulnerability in the Easy Breadcrumb module ...)
+	TODO: check
 CVE-2014-XXXX [mediawiki: unspecified security vulnerability]
 	- mediawiki <unfixed> (bug #752622)
-CVE-2014-4617 [DoS due to garbled compressed data packets]
+CVE-2014-4617 (The do_uncompress function in g10/compress.c in GnuPG 1.x before ...)
+	{DSA-2967-1}
 	- gnupg 1.4.16-1.2 (bug #752497)
 	- gnupg2 2.0.24-1 (bug #752498)
 	NOTE: http://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=commitdiff;h=11fdfcf82bd8
 CVE-2014-4616 [arbitrary process memory read]
+	RESERVED
 	- python2.6 <removed>
 	- python2.7 2.7.7-1 (bug #752395)
 	- python3.2 <removed>
@@ -12,18 +276,22 @@
 	- python3.4 3.4.0+20140417-1
 	NOTE: http://bugs.python.org/issue21529
 CVE-2014-4615
+	RESERVED
 	- neutron <unfixed>
 	- ceilometer <unfixed>
 	- python-pycadf <unfixed>
 	TODO: check
 CVE-2014-4614
+	RESERVED
 	- piwigo <removed>
 CVE-2014-4613
+	RESERVED
 	- piwigo <removed>
 CVE-2014-4510 [XSS in apt-cacher-ng apt redirector]
+	RESERVED
 	- apt-cacher-ng 0.7.26-2
 	[wheezy] - apt-cacher-ng <no-dsa> (Minor issue)
-CVE-2014-4508
+CVE-2014-4508 (arch/x86/kernel/entry_32.S in the Linux kernel through 3.15.1 on ...)
 	- linux <unfixed>
 	- linux-2.6 <removed>
 	NOTE: http://article.gmane.org/gmane.linux.kernel/1726110
@@ -338,12 +606,11 @@
 	RESERVED
 CVE-2014-4350
 	RESERVED
-CVE-2014-4349
-	RESERVED
+CVE-2014-4349 (Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin ...)
 	- phpmyadmin <unfixed>
 	TODO: check
-CVE-2014-4348
-	RESERVED
+CVE-2014-4348 (Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin ...)
+	TODO: check
 CVE-2014-4347
 	RESERVED
 CVE-2014-4346
@@ -695,8 +962,7 @@
 	RESERVED
 CVE-2014-4172
 	RESERVED
-CVE-2014-4171 [linux: mm/shmem.c denial of service]
-	RESERVED
+CVE-2014-4171 (mm/shmem.c in the Linux kernel through 3.15.1 does not properly ...)
 	- linux <unfixed>
 	- linux-2.6 <removed>
 	NOTE: http://ozlabs.org/~akpm/mmots/broken-out/shmem-fix-faulting-into-a-hole-while-its-punched.patch
@@ -718,7 +984,7 @@
 	NOT-FOR-US: SAP Supplier Relationship Management
 CVE-2014-4160 (Multiple cross-site scripting (XSS) vulnerabilities in the testcanvas ...)
 	NOT-FOR-US: SAP NetWeaver Business Client
-CVE-2014-4159 (Open redirect vulnerability in SAP Supplier Relationship Management ...)
+CVE-2014-4159 (Open redirect vulnerability in in la/umTestSSO.jsp in SAP Supplier  ...)
 	NOT-FOR-US: SAP Supplier Relationship Management
 CVE-2014-4158 (Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to ...)
 	NOT-FOR-US: Kolibri
@@ -990,8 +1256,7 @@
 	RESERVED
 	- neutron 2014.1.1-1 (bug #752021)
 	NOTE: https://launchpad.net/bugs/1309195
-CVE-2014-4157 [no SIGKILL after prctl(PR_SET_SECCOMP, 1, ...) on MIPS]
-	RESERVED
+CVE-2014-4157 (arch/mips/include/asm/thread_info.h in the Linux kernel before 3.14.8 ...)
 	- linux 3.14.7-1 (bug #751417)
 	- linux-2.6 <removed>
 CVE-2014-XXXX [Class loader vulnerability in DefaultResolver]
@@ -1099,14 +1364,12 @@
 	- scheme48 1.9-4 (bug #748766)
 	[wheezy] - scheme48 <no-dsa> (Minor issue)
 	[squeeze] - scheme48 1.8+dfsg-1+deb6u1
-CVE-2014-4027
-	RESERVED
+CVE-2014-4027 (The rd_build_device_space function in drivers/target/target_core_rd.c ...)
 	- linux 3.14.2-1
 	- linux-2.6 <removed>
 	[squeeze] - linux-2.6 <not-affected> (Introduced in 2.6.38)
 	NOTE: upstream fix: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=4442dc8a92b8f9ad8ee9e7f8438f4c04c03a22dc
-CVE-2014-4014
-	RESERVED
+CVE-2014-4014 (The capabilities implementation in the Linux kernel before 3.14.8 does ...)
 	- linux 3.14.7-1
 	- linux-2.6 <removed>
 	NOTE: fixing commit https://git.kernel.org/linus/23adbe12ef7d3d4195e80800ab36b37bee28cd03
@@ -1331,10 +1594,10 @@
 	RESERVED
 CVE-2014-3884
 	RESERVED
-CVE-2014-3883
-	RESERVED
-CVE-2014-3882
-	RESERVED
+CVE-2014-3883 (Usermin before 1.600 allows remote attackers to execute arbitrary ...)
+	TODO: check
+CVE-2014-3882 (Cross-site request forgery (CSRF) vulnerability in the Login rebuilder ...)
+	TODO: check
 CVE-2014-3881
 	RESERVED
 CVE-2014-3880 (The (1) execve and (2) fexecve system calls in the FreeBSD kernel 8.4 ...)
@@ -2147,8 +2410,7 @@
 CVE-2014-3497 [XSS in Swift requests through WWW-Authenticate header]
 	RESERVED
 	- swift 1.13.1-1 (bug #752087)
-CVE-2014-3496
-	RESERVED
+CVE-2014-3496 (cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 ...)
 	NOT-FOR-US: OpenShift Origin
 CVE-2014-3495 [improper verification of SSL certificates]
 	RESERVED
@@ -2159,8 +2421,7 @@
 	[wheezy] - kde4libs <not-affected> (Affects kdelibs 4.10.95 to 4.13.2)
 	[squeeze] - kde4libs <not-affected> (Affects kdelibs 4.10.95 to 4.13.2)
 	NOTE: http://quickgit.kde.org/?p=kdelibs.git&a=commitdiff&h=bbae87dc1be3ae063796a582774bd5642cacdd5d&hp=1ccdb43ed3b32a7798eec6d39bb3c83a6e40228f
-CVE-2014-3493 [Denial of service - Server crash/memory corruption]
-	RESERVED
+CVE-2014-3493 (The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x ...)
 	{DSA-2966-1}
 	- samba 2:4.1.9+dfsg-1
 	- samba4 4.0.0~beta2+dfsg1-3.2+deb7u2
@@ -2413,8 +2674,8 @@
 	RESERVED
 CVE-2014-3432
 	RESERVED
-CVE-2014-3431
-	RESERVED
+CVE-2014-3431 (Symantec PGP Desktop 10.x, and Encryption Desktop Professional 10.3.x ...)
+	TODO: check
 CVE-2014-3429
 	RESERVED
 CVE-2014-3428 (Cross-site scripting (XSS) vulnerability in Yealink VoIP Phones with ...)
@@ -2663,14 +2924,14 @@
 	RESERVED
 CVE-2014-3300
 	RESERVED
-CVE-2014-3299
-	RESERVED
+CVE-2014-3299 (Cisco IOS allows remote authenticated users to cause a denial of ...)
+	TODO: check
 CVE-2014-3298
 	RESERVED
 CVE-2014-3297
 	RESERVED
-CVE-2014-3296
-	RESERVED
+CVE-2014-3296 (The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server ...)
+	TODO: check
 CVE-2014-3295 (The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows ...)
 	NOT-FOR-US: Cisco NX-OS
 CVE-2014-3294 (Cisco WebEx Meeting Server does not properly restrict the content of ...)
@@ -3236,8 +3497,8 @@
 	RESERVED
 CVE-2014-3074
 	RESERVED
-CVE-2014-3073
-	RESERVED
+CVE-2014-3073 (Unspecified vulnerability in IBM Security Access Manager (ISAM) for ...)
+	TODO: check
 CVE-2014-3072
 	RESERVED
 CVE-2014-3071
@@ -3276,10 +3537,10 @@
 	RESERVED
 CVE-2014-3054
 	RESERVED
-CVE-2014-3053
-	RESERVED
-CVE-2014-3052
-	RESERVED
+CVE-2014-3053 (The Local Management Interface (LMI) in IBM Security Access Manager ...)
+	TODO: check
+CVE-2014-3052 (The reverse-proxy feature in IBM Security Access Manager (ISAM) for ...)
+	TODO: check
 CVE-2014-3051
 	RESERVED
 CVE-2014-3050
@@ -3441,17 +3702,14 @@
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1085618
 	NOTE: https://github.com/miniupnp/miniupnp/commit/3a87aa2f10bd7f1408e1849bdb59c41dd63a9fe9
 	NOTE: http://www.openwall.com/lists/oss-security/2014/04/30/3
-CVE-2014-4338 [handle BrowseAllow directive securely]
-	RESERVED
+CVE-2014-4338 (cups-browsed in cups-filters before 1.0.53 allows remote attackers to ...)
 	- cups-filters 1.0.53-1
 	[wheezy] - cups-filters <not-affected> (vulnerable code not present)
 	NOTE: http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7195
-CVE-2014-4337 [OOB accesses in the process_browse_data function when reading the packet variable]
-	RESERVED
+CVE-2014-4337 (The process_browse_data function in utils/cups-browsed.c in ...)
 	- cups-filters 1.0.53-1
 	[wheezy] - cups-filters <not-affected> (vulnerable code not present)
-CVE-2014-4336 [incomplete fix for CVE-2014-2707]
-	RESERVED
+CVE-2014-4336 (The generate_local_queue function in utils/cups-browsed.c in ...)
 	- cups-filters 1.0.53-1
 	[wheezy] - cups-filters <not-affected> (vulnerable code not present)
 	NOTE: incomplete fix was applied
@@ -4237,7 +4495,7 @@
 	NOTE: http://bugs.cacti.net/view.php?id=2405 (not yet public)
 	NOTE: http://svn.cacti.net/viewvc?view=rev&revision=7439
 	NOTE: CVE for all changes to graph_xport.php to ensure that data is numeric
-CVE-2014-2707 (cups-browsed in cups-filters 1.0.41 before 1.0.51 in allows remote IPP ...)
+CVE-2014-2707 (cups-browsed in cups-filters 1.0.41 before 1.0.51 allows remote IPP ...)
 	- cups-filters 1.0.51-1 (bug #743470)
 	[wheezy] - cups-filters <not-affected> (vulnerable code not present)
 	NOTE: Introduced in at least 1.0.41
@@ -5992,8 +6250,8 @@
 	RESERVED
 CVE-2014-2006
 	RESERVED
-CVE-2014-2005
-	RESERVED
+CVE-2014-2005 (Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) ...)
+	TODO: check
 CVE-2014-2004 (The PPP Access Concentrator (PPPAC) on SEIL SEIL/x86 routers 1.00 ...)
 	TODO: check
 CVE-2014-2003 (JustSystems JUST Online Update, as used in Ichitaro through 2014 and ...)
@@ -6800,8 +7058,7 @@
 	{DSA-2930-1}
 	- chromium-browser 34.0.1847.137-1
 	[squeeze] - chromium-browser <end-of-life>
-CVE-2014-1739 [linux: infoleak in media_enum_entities()]
-	RESERVED
+CVE-2014-1739 (The media_device_enum_entities function in ...)
 	- linux 3.14.7-1 (unimportant)
 	- linux-2.6 <removed>
 	[squeeze] - linux-2.6 <not-affected> (Vulnerability introduced in 2.6.38)
@@ -11108,8 +11365,7 @@
 	- sosreport <unfixed> (bug #749568)
 CVE-2014-0245
 	RESERVED
-CVE-2014-0244 [Denial of service - CPU loop]
-	RESERVED
+CVE-2014-0244 (The sys_recvfrom function in nmbd in Samba 3.6.x before 3.6.24, 4.0.x ...)
 	{DSA-2966-1}
 	- samba 2:4.1.9+dfsg-1
 	- samba4 4.0.0~beta2+dfsg1-3.2+deb7u2
@@ -11242,8 +11498,7 @@
 	- foreman <itp> (bug #663101)
 CVE-2014-0207
 	RESERVED
-CVE-2014-0206 [kernel: aio: insufficient sanitization of head in aio_read_events_ring()]
-	RESERVED
+CVE-2014-0206 (Array index error in the aio_read_events_ring function in fs/aio.c in ...)
 	- linux <unfixed>
 	[wheezy] - linux <not-affected> (introduced by a31ad380bed817aa25f8830ad23e1a0480fef797)
 	- linux-2.6 <not-affected> (introduced by a31ad380bed817aa25f8830ad23e1a0480fef797)
@@ -11255,8 +11510,7 @@
 	RESERVED
 	- keystone 2014.1-5 (bug #749026)
 	[wheezy] - keystone <not-affected>
-CVE-2014-0203
-	RESERVED
+CVE-2014-0203 (The __do_follow_link function in fs/namei.c in the Linux kernel before ...)
 	- linux <not-affected> (Vulnerable code not present; fixed in linux v2.6.33)
 	- linux-2.6 2.6.37-1
 	NOTE: upstream fix: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=86acdca1b63e6890540fa19495cfc708beff3d8b (v2.6.33)
@@ -11944,8 +12198,7 @@
 	- moodle 2.5.4-1 (low)
 	[squeeze] - moodle <not-affected> (Vulnerable code not present)
 	NOTE: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-36721
-CVE-2014-0007
-	RESERVED
+CVE-2014-0007 (The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows ...)
 	NOT-FOR-US: Foreman Proxy
 CVE-2014-0006 (The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 ...)
 	- swift 1.11.0-2 (low; bug #735582)
@@ -12389,8 +12642,8 @@
 	RESERVED
 CVE-2013-6738 (Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics ...)
 	NOT-FOR-US: IBM
-CVE-2013-6737
-	RESERVED
+CVE-2013-6737 (IBM System Storage Storwize V7000 Unified 1.3.x and 1.4.x before ...)
+	TODO: check
 CVE-2013-6736
 	RESERVED
 CVE-2013-6735 (IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, ...)
@@ -34153,8 +34406,8 @@
 	[squeeze] - chromium-browser <end-of-life>
 CVE-2012-5107
 	RESERVED
-CVE-2012-5106
-	RESERVED
+CVE-2012-5106 (Stack-based buffer overflow in FreeFloat FTP Server 1.0 allows remote ...)
+	TODO: check
 CVE-2012-5159 (phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror ...)
 	- phpmyadmin <not-affected>
 CVE-2012-5105 (Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager ...)
@@ -40933,8 +41186,8 @@
 	RESERVED
 CVE-2012-2592 (Cross-site scripting (XSS) vulnerability in Axigen Mail Server 8.0.1 ...)
 	NOT-FOR-US: AXIGEN Mail Server
-CVE-2012-2591
-	RESERVED
+CVE-2012-2591 (Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect ...)
+	TODO: check
 CVE-2012-2590 (Multiple cross-site scripting (XSS) vulnerabilities in ESCON ...)
 	NOT-FOR-US: ESCON SupportPortal Professional Edition
 CVE-2012-2589
@@ -40956,10 +41209,10 @@
 	- otrs2 3.1.7+dfsg1-4
 CVE-2012-2581
 	RESERVED
-CVE-2012-2580
-	RESERVED
-CVE-2012-2579
-	RESERVED
+CVE-2012-2580 (Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, ...)
+	TODO: check
+CVE-2012-2579 (Multiple cross-site scripting (XSS) vulnerabilities in the WP ...)
+	TODO: check
 CVE-2012-2578 (Multiple cross-site scripting (XSS) vulnerabilities in SmarterMail 9.2 ...)
 	NOT-FOR-US: SmarterMail
 CVE-2012-2577 (Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds ...)
@@ -46914,8 +47167,8 @@
 	NOT-FOR-US: Adobe Photoshop CS5
 CVE-2012-0274
 	RESERVED
-CVE-2012-0273
-	RESERVED
+CVE-2012-0273 (Multiple stack-based buffer overflows in MinaliC 2.0.0 allow remote ...)
+	TODO: check
 CVE-2012-0272 (Cross-site scripting (XSS) vulnerability in the WebAccess component in ...)
 	NOT-FOR-US: Novell GroupWise
 CVE-2012-0271 (Integer overflow in the WebConsole component in gwia.exe in GroupWise ...)
@@ -47787,8 +48040,8 @@
 	NOT-FOR-US: Joomla extension
 CVE-2011-4822 (Multiple cross-site scripting (XSS) vulnerabilities in the user ...)
 	NOT-FOR-US: Atlassian FishEye
-CVE-2011-4821
-	RESERVED
+CVE-2011-4821 (Directory traversal vulnerability in the TFTP server in D-Link DIR-601 ...)
+	TODO: check
 CVE-2011-4820
 	RESERVED
 CVE-2011-4819 (Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo ...)




More information about the Secure-testing-commits mailing list