[Secure-testing-commits] r29530 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sun Oct 19 09:44:58 UTC 2014


Author: carnil
Date: 2014-10-19 09:44:58 +0000 (Sun, 19 Oct 2014)
New Revision: 29530

Modified:
   data/CVE/list
Log:
Second round of NFUs

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-10-19 09:28:28 UTC (rev 29529)
+++ data/CVE/list	2014-10-19 09:44:58 UTC (rev 29530)
@@ -51,9 +51,9 @@
 CVE-2014-8295 (SQL injection vulnerability in joblogs.php in Bacula-Web 5.2.10 allows ...)
 	TODO: check
 CVE-2014-8294 (Multiple SQL injection vulnerabilities in Voice Of Web AllMyGuests ...)
-	TODO: check
+	NOT-FOR-US: Voice Of Web AllMyGuests
 CVE-2014-8293 (Cross-site scripting (XSS) vulnerability in Voice Of Web AllMyGuests ...)
-	TODO: check
+	NOT-FOR-US: Voice Of Web AllMyGuests
 CVE-2014-8764
 	RESERVED
 	- dokuwiki <unfixed>
@@ -2298,7 +2298,7 @@
 CVE-2014-7227
 	REJECTED
 CVE-2014-7226 (The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and ...)
-	TODO: check
+	NOT-FOR-US: Rejetto HTTP File Server
 CVE-2014-7225
 	RESERVED
 CVE-2014-7224
@@ -3748,13 +3748,13 @@
 	- mysql-5.5 <not-affected> (Only affects MySQL 5.6)
 	- mysql-5.1 <not-affected> (Only affects MySQL 5.6)
 CVE-2014-6563 (Unspecified vulnerability in the Java VM component in Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-6562 (Unspecified vulnerability in Oracle Java SE 8u20 allows remote ...)
 	- openjdk-8 <unfixed>
 CVE-2014-6561 (Unspecified vulnerability in the Oracle Payments component in Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2014-6560 (Unspecified vulnerability in the Java VM component in Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-6559 (Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, ...)
 	- mysql-5.5 <unfixed>
 	- mariadb-5.5 <undetermined>
@@ -3764,7 +3764,7 @@
 	- openjdk-7 <unfixed>
 	- openjdk-8 <unfixed>
 CVE-2014-6557 (Unspecified vulnerability in the Application Performance Management ...)
-	TODO: check
+	NOT-FOR-US: Oracle Enterprise Manager Grid Control
 CVE-2014-6556
 	RESERVED
 CVE-2014-6555 (Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier ...)
@@ -3772,51 +3772,51 @@
 	- mariadb-5.5 <undetermined>
 	- percona-xtradb-cluster-5.5 <undetermined>
 CVE-2014-6554 (Unspecified vulnerability in the Oracle Access Manager component in ...)
-	TODO: check
+	NOT-FOR-US: Oracle Fusion Middleware
 CVE-2014-6553 (Unspecified vulnerability in the Oracle Access Manager component in ...)
-	TODO: check
+	NOT-FOR-US: Oracle Fusion Middleware
 CVE-2014-6552 (Unspecified vulnerability in the Oracle Access Manager component in ...)
-	TODO: check
+	NOT-FOR-US: Oracle Fusion Middleware
 CVE-2014-6551 (Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier ...)
 	- mysql-5.5 5.5.39-1
 	- mariadb-5.5 <undetermined>
 	- percona-xtradb-cluster-5.5 <undetermined>
 CVE-2014-6550 (Unspecified vulnerability in the Oracle Applications Object Library ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2014-6549
 	RESERVED
 CVE-2014-6548
 	RESERVED
 CVE-2014-6547 (Unspecified vulnerability in the JPublisher component in Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-6546 (Unspecified vulnerability in the JPublisher component in Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-6545 (Unspecified vulnerability in the Java VM component in Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-6544 (Unspecified vulnerability in the JDBC component in Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-6543 (Unspecified vulnerability in the Agile PLM component in Oracle Supply ...)
-	TODO: check
+	NOT-FOR-US: Oracle Supply Chain Products Suite
 CVE-2014-6542 (Unspecified vulnerability in the SQLJ component in Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-6541
 	RESERVED
 CVE-2014-6540 (Unspecified vulnerability in the Oracle VM VirtualBox component in ...)
 	TODO: check
 CVE-2014-6539 (Unspecified vulnerability in the Oracle Applications Framework ...)
-	TODO: check
+	NOT-FOR-US: Oracle E-Business Suite
 CVE-2014-6538 (Unspecified vulnerability in the Java VM component in Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-6537 (Unspecified vulnerability in the Java VM component in Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-6536 (Unspecified vulnerability in the Agile PLM component in Oracle Supply ...)
-	TODO: check
+	NOT-FOR-US: Oracle Supply Chain Products Suite
 CVE-2014-6535 (Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools ...)
-	TODO: check
+	NOT-FOR-US: Oracle PeopleSoft Products
 CVE-2014-6534 (Unspecified vulnerability in the Oracle WebLogic Server component in ...)
-	TODO: check
+	NOT-FOR-US: Oracle Fusion Middleware
 CVE-2014-6533 (Unspecified vulnerability in the Oracle Transportation Management ...)
-	TODO: check
+	NOT-FOR-US: Oracle Supply Chain Products Suite
 CVE-2014-6532 (Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20 ...)
 	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
@@ -3830,7 +3830,7 @@
 	- mariadb-5.5 <undetermined>
 	- percona-xtradb-cluster-5.5 <undetermined>
 CVE-2014-6529 (Unspecified vulnerability in Oracle Sun Solaris 11 allows remote ...)
-	TODO: check
+	NOT-FOR-US: Oracle Sun Solaris 11
 CVE-2014-6528
 	RESERVED
 CVE-2014-6527 (Unspecified vulnerability in Oracle Java SE 7u67 and 8u20 allows ...)
@@ -3843,9 +3843,9 @@
 CVE-2014-6524
 	RESERVED
 CVE-2014-6523 (Unspecified vulnerability in the Oracle Applications Framework ...)
-	TODO: check
+	NOT-FOR-US: Oracle E-Business Suite
 CVE-2014-6522 (Unspecified vulnerability in the Oracle JDeveloper component in Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle Fusion Middleware
 CVE-2014-6521
 	RESERVED
 CVE-2014-6520 (Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier ...)
@@ -3864,7 +3864,7 @@
 	- openjdk-7 <unfixed>
 	- openjdk-8 <unfixed>
 CVE-2014-6516 (Unspecified vulnerability in the JD Edwards EnterpriseOne Tools ...)
-	TODO: check
+	NOT-FOR-US: Oracle JD Edwards Products
 CVE-2014-6515 (Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20 ...)
 	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
@@ -3889,7 +3889,7 @@
 CVE-2014-6509
 	RESERVED
 CVE-2014-6508 (Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows ...)
-	TODO: check
+	NOT-FOR-US: Oracle Sun Solaris 10 and 11
 CVE-2014-6507 (Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, ...)
 	- mysql-5.5 <unfixed>
 	- mariadb-5.5 <undetermined>
@@ -3915,18 +3915,18 @@
 	- openjdk-7 <unfixed>
 	- openjdk-8 <unfixed>
 CVE-2014-6501 (Unspecified vulnerability in Oracle Sun Solaris 11 allows local users ...)
-	TODO: check
+	NOT-FOR-US: Oracle Sun Solaris 11
 CVE-2014-6500 (Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, ...)
 	- mysql-5.5 <unfixed>
 	- mariadb-5.5 <undetermined>
 	- percona-xtradb-cluster-5.5 <undetermined>
 	- cyassl <undetermined>
 CVE-2014-6499 (Unspecified vulnerability in the Oracle WebLogic Server component in ...)
-	TODO: check
+	NOT-FOR-US: Oracle Fusion Middleware
 CVE-2014-6498 (Unspecified vulnerability in the Oracle Transportation Management ...)
-	TODO: check
+	NOT-FOR-US: Oracle Supply Chain Products Suite
 CVE-2014-6497 (Unspecified vulnerability in Oracle Sun Solaris 11 allows local users ...)
-	TODO: check
+	NOT-FOR-US: Oracle Sun Solaris 11
 CVE-2014-6496 (Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, ...)
 	- mysql-5.5 <unfixed>
 	- mariadb-5.5 <undetermined>
@@ -3956,16 +3956,16 @@
 	- percona-xtradb-cluster-5.5 <undetermined>
 	- cyassl <undetermined>
 CVE-2014-6490 (Unspecified vulnerability in Oracle Sun Solaris 11 allows remote ...)
-	TODO: check
+	NOT-FOR-US: Oracle Sun Solaris 11
 CVE-2014-6489 (Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier ...)
 	- mysql-5.5 <not-affected> (Only MySQL 5.6)
 	- mysql-5.1 <not-affected> (Only MySQL 5.6)
 CVE-2014-6488 (Unspecified vulnerability in the Enterprise Manager for Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle Enterprise Manager Grid Control EM Base Plattform
 CVE-2014-6487 (Unspecified vulnerability in the Oracle Identity Manager component in ...)
-	TODO: check
+	NOT-FOR-US: Oracle Fusion Middleware
 CVE-2014-6486 (Unspecified vulnerability in the PeopleSoft Enterprise HRMS component ...)
-	TODO: check
+	NOT-FOR-US: Oracle PeopleSoft Products
 CVE-2014-6485 (Unspecified vulnerability in Oracle Java SE 8u20 and JavaFX 2.2.65 ...)
 	- openjdk-8 <unfixed>
 CVE-2014-6484 (Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, ...)
@@ -3973,15 +3973,15 @@
 	- mariadb-5.5 <undetermined>
 	- percona-xtradb-cluster-5.5 <undetermined>
 CVE-2014-6483 (Unspecified vulnerability in the Application Express component in ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-6482 (Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools ...)
-	TODO: check
+	NOT-FOR-US: Oracle PeopleSoft Products
 CVE-2014-6481
 	RESERVED
 CVE-2014-6480
 	RESERVED
 CVE-2014-6479 (Unspecified vulnerability in the Oracle Applications Technology ...)
-	TODO: check
+	NOT-FOR-US: Oracle E-Business Suite
 CVE-2014-6478 (Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, ...)
 	- mysql-5.5 5.5.39-1
 	- mariadb-5.5 <undetermined>
@@ -3994,18 +3994,18 @@
 	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 	- openjdk-8 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2014-6475 (Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools ...)
-	TODO: check
+	NOT-FOR-US: Oracle PeopleSoft Products
 CVE-2014-6474 (Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier ...)
 	- mysql-5.5 <not-affected> (Only affects MySQL 5.6)
 	- mysql-5.1 <not-affected> (Only affects MySQL 5.6)
 CVE-2014-6473 (Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local ...)
-	TODO: check
+	NOT-FOR-US: Oracle Sun Solaris 10 and 11
 CVE-2014-6472 (Unspecified vulnerability in the Oracle Applications Framework ...)
-	TODO: check
+	NOT-FOR-US: Oracle E-Business Suite
 CVE-2014-6471 (Unspecified vulnerability in the Oracle Applications Manager component ...)
-	TODO: check
+	NOT-FOR-US: Oracle E-Business Suite
 CVE-2014-6470 (Unspecified vulnerability in Oracle Sun Solaris 11 allows local users ...)
-	TODO: check
+	NOT-FOR-US: Oracle Sun Solaris 11
 CVE-2014-6469 (Unspecified vulnerability in Oracle MySQL Server 5.5.39 and eariler ...)
 	- mysql-5.5 <unfixed>
 	- mariadb-5.5 <undetermined>
@@ -4013,13 +4013,13 @@
 CVE-2014-6468 (Unspecified vulnerability in Oracle Java SE 8u20 allows local users to ...)
 	- openjdk-8 <unfixed>
 CVE-2014-6467 (Unspecified vulnerability in the Java VM component in Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-6466 (Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20, when ...)
 	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 	- openjdk-8 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2014-6465 (Unspecified vulnerability in the Oracle Communications Session Border ...)
-	TODO: check
+	NOT-FOR-US: Oracle Communications Applications
 CVE-2014-6464 (Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier ...)
 	- mysql-5.5 <unfixed>
 	- mariadb-5.5 <undetermined>
@@ -4029,13 +4029,13 @@
 	- mariadb-5.5 <undetermined>
 	- percona-xtradb-cluster-5.5 <undetermined>
 CVE-2014-6462 (Unspecified vulnerability in the Oracle Access Manager component in ...)
-	TODO: check
+	NOT-FOR-US: Oracle Fusion Middleware
 CVE-2014-6461 (Unspecified vulnerability in the Agile PLM component in Oracle Supply ...)
-	TODO: check
+	NOT-FOR-US: Oracle Supply Chain Products Suite
 CVE-2014-6460 (Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools ...)
-	TODO: check
+	NOT-FOR-US: Oracle PeopleSoft Products
 CVE-2014-6459 (Unspecified vulnerability in the Oracle Secure Global Desktop ...)
-	TODO: check
+	NOT-FOR-US: Oracle Virtualization
 CVE-2014-6458 (Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20 ...)
 	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
@@ -4048,13 +4048,13 @@
 	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 	- openjdk-8 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2014-6455 (Unspecified vulnerability in the SQLJ component in Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-6454 (Unspecified vulnerability in the SQLJ component in Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-6453 (Unspecified vulnerability in the Java VM component in Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-6452 (Unspecified vulnerability in the SQLJ component in Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-6451
 	RESERVED
 CVE-2014-6450
@@ -7774,11 +7774,11 @@
 CVE-2014-4875
 	RESERVED
 CVE-2014-4874 (BMC Track-It! 11.3.0.355 allows remote authenticated users to read ...)
-	TODO: check
+	NOT-FOR-US: BMC Track-It!
 CVE-2014-4873 (SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC ...)
-	TODO: check
+	NOT-FOR-US: BMC Track-It!
 CVE-2014-4872 (BMC Track-It! 11.3.0.355 does not require authentication on TCP port ...)
-	TODO: check
+	NOT-FOR-US: BMC Track-It!
 CVE-2014-4871 (Cross-site scripting (XSS) vulnerability in wlsecurity.html on ...)
 	NOT-FOR-US: NetCommWireless NB604N routers
 CVE-2014-4870 (/opt/vyatta/bin/sudo-users/vyatta-clear-dhcp-lease.pl on the Brocade ...)
@@ -8002,7 +8002,7 @@
 CVE-2014-4762 (Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 ...)
 	NOT-FOR-US: IBM
 CVE-2014-4761 (IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 ...)
-	TODO: check
+	NOT-FOR-US: IBM WebSphere Portal
 CVE-2014-4760 (Open redirect vulnerability in IBM WebSphere Portal 6.1.0.0 through ...)
 	NOT-FOR-US: IBM WebSphere
 CVE-2014-4759 (An unspecified Ajax service in the Content Management toolkit in IBM ...)
@@ -9096,7 +9096,7 @@
 	RESERVED
 	NOT-FOR-US: Epicor
 CVE-2014-4310 (Unspecified vulnerability in the JPublisher component in Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-4309 (Multiple cross-site scripting (XSS) vulnerabilities in Openfiler 2.99 ...)
 	NOT-FOR-US: Openfiler
 CVE-2014-4308 (Multiple cross-site scripting (XSS) vulnerabilities in NICE Recording ...)
@@ -9116,29 +9116,29 @@
 CVE-2014-4301 (Multiple cross-site scripting (XSS) vulnerabilities in the ...)
 	NOT-FOR-US: Ajenti
 CVE-2014-4300 (Unspecified vulnerability in the SQLJ component in Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-4299 (Unspecified vulnerability in the SQLJ component in Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-4298 (Unspecified vulnerability in the SQLJ component in Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-4297 (Unspecified vulnerability in the JPublisher component in Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-4296 (Unspecified vulnerability in the JPublisher component in Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-4295 (Unspecified vulnerability in the Java VM component in Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-4294 (Unspecified vulnerability in the Java VM component in Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-4293 (Unspecified vulnerability in the JPublisher component in Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-4292 (Unspecified vulnerability in the JPublisher component in Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-4291 (Unspecified vulnerability in the JPublisher component in Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-4290 (Unspecified vulnerability in the JPublisher component in Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-4289 (Unspecified vulnerability in the JDBC component in Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle Database Server
 CVE-2014-4288 (Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20 ...)
 	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
@@ -9150,27 +9150,27 @@
 CVE-2014-4286
 	REJECTED
 CVE-2014-4285 (Unspecified vulnerability in the Oracle Applications Technology ...)
-	TODO: check
+	NOT-FOR-US: Oracle E-Business Suite
 CVE-2014-4284 (Unspecified vulnerability in Oracle Sun Solaris 11 allows local users ...)
-	TODO: check
+	NOT-FOR-US: Oracle Sun Solaris 11
 CVE-2014-4283 (Unspecified vulnerability in Oracle Sun Solaris 11 allows remote ...)
-	TODO: check
+	NOT-FOR-US: Oracle Sun Solaris 11
 CVE-2014-4282 (Unspecified vulnerability in Oracle Sun Solaris 11 allows local users ...)
-	TODO: check
+	NOT-FOR-US: Oracle Sun Solaris 11
 CVE-2014-4281 (Unspecified vulnerability in the Oracle Applications Framework ...)
-	TODO: check
+	NOT-FOR-US: Oracle E-Business Suite
 CVE-2014-4280 (Unspecified vulnerability in Oracle Sun Solaris 11 allows local users ...)
-	TODO: check
+	NOT-FOR-US: Oracle Sun Solaris 11
 CVE-2014-4279
 	RESERVED
 CVE-2014-4278 (Unspecified vulnerability in the Oracle Applications Technology Stack ...)
-	TODO: check
+	NOT-FOR-US: Oracle E-Business Suite
 CVE-2014-4277 (Unspecified vulnerability in Oracle Sun Solaris 11 allows remote ...)
-	TODO: check
+	NOT-FOR-US: Oracle Sun Solaris 11
 CVE-2014-4276 (Unspecified vulnerability in Oracle Sun Solaris 11 allows remote ...)
-	TODO: check
+	NOT-FOR-US: Oracle Sun Solaris 11
 CVE-2014-4275 (Unspecified vulnerability in Oracle Sun Solaris 11 allows local users ...)
-	TODO: check
+	NOT-FOR-US: Oracle Sun Solaris 11
 CVE-2014-4273
 	RESERVED
 CVE-2014-4272
@@ -9501,7 +9501,7 @@
 CVE-2014-4149
 	RESERVED
 CVE-2014-4148 (win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2014-4147
 	RESERVED
 CVE-2014-4146
@@ -9515,23 +9515,23 @@
 CVE-2014-4142
 	RESERVED
 CVE-2014-4141 (Microsoft Internet Explorer 8 through 11 allows remote attackers to ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2014-4140 (Microsoft Internet Explorer 8 through 11 allows remote attackers to ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2014-4139
 	RESERVED
 CVE-2014-4138 (Microsoft Internet Explorer 11 allows remote attackers to execute ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2014-4137 (Microsoft Internet Explorer 6 and 7 allows remote attackers to execute ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2014-4136
 	RESERVED
 CVE-2014-4135
 	RESERVED
 CVE-2014-4134 (Microsoft Internet Explorer 6 through 8 allows remote attackers to ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2014-4133 (Microsoft Internet Explorer 6 and 7 allows remote attackers to execute ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2014-4132 (Microsoft Internet Explorer 11 allows remote attackers to execute ...)
 	TODO: check
 CVE-2014-4131




More information about the Secure-testing-commits mailing list