[Secure-testing-commits] r52547 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Jun 14 04:39:25 UTC 2017


Author: carnil
Date: 2017-06-14 04:39:25 +0000 (Wed, 14 Jun 2017)
New Revision: 52547

Modified:
   data/CVE/list
Log:
Process NFUs

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-06-14 04:39:09 UTC (rev 52546)
+++ data/CVE/list	2017-06-14 04:39:25 UTC (rev 52547)
@@ -9,7 +9,7 @@
 	NOTE: http://www.openwall.com/lists/oss-security/2017/06/13/2
 	NOTE: Fixed by: https://git.kernel.org/linus/07678eca2cf9c9a18584e546c2b2a0d0c9a3150c (v4.12-rc5)
 CVE-2017-9603 (SQL injection vulnerability in the WP Jobs plugin before 1.5 for ...)
-	TODO: check
+	NOT-FOR-US: WP Jobs plugin for WordPress
 CVE-2017-9602
 	RESERVED
 CVE-2017-9601
@@ -111,7 +111,7 @@
 CVE-2017-9553
 	RESERVED
 CVE-2017-9552 (A design flaw in authentication in Synology Photo Station 6.0-2528 ...)
-	TODO: check
+	NOT-FOR-US: Synology Photo Station
 CVE-2015-9097 (The mail gem before 2.5.5 for Ruby (aka A Really Ruby Mail Library) is ...)
 	TODO: check
 CVE-2015-9096 (Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection ...)
@@ -450,7 +450,7 @@
 	NOTE: One scenario would be to have a web application that launches dnstracer
 	NOTE: with user supplied name strings to evaluate.
 CVE-2017-9429 (SQL injection vulnerability in the Event List plugin 0.7.8 for ...)
-	TODO: check
+	NOT-FOR-US: Event List plugin for WordPress
 CVE-2017-9428 (A directory traversal vulnerability exists in ...)
 	NOT-FOR-US: BigTree CMS
 CVE-2017-9427 (SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote ...)
@@ -1099,7 +1099,7 @@
 CVE-2017-9247
 	RESERVED
 CVE-2017-9246 (New Relic .NET Agent before 6.3.123.0 adds SQL injection flaws to safe ...)
-	TODO: check
+	NOT-FOR-US: New Relic .NET Agent
 CVE-2017-9245
 	RESERVED
 CVE-2017-9244
@@ -16923,7 +16923,7 @@
 CVE-2016-9985 (IBM Cognos Server 10.1.1 and 10.2 stores highly sensitive information ...)
 	NOT-FOR-US: IBM
 CVE-2016-9984 (IBM Maximo Asset Management 7.5 and 7.6 could allow a remote ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2016-9983
 	RESERVED
 CVE-2016-9982
@@ -16945,7 +16945,7 @@
 CVE-2016-9974
 	RESERVED
 CVE-2016-9973 (IBM Jazz Foundation is vulnerable to cross-site scripting. This ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2016-9972
 	RESERVED
 CVE-2016-9971
@@ -23597,17 +23597,17 @@
 CVE-2017-1105
 	RESERVED
 CVE-2017-1104 (IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2017-1103 (IBM Team Concert (RTC) is vulnerable to a denial of service, caused by ...)
 	NOT-FOR-US: IBM
 CVE-2017-1102 (IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2017-1101 (IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2017-1100 (IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2017-1099 (IBM Jazz Foundation could expose potentially sensitive information to ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2017-1098
 	RESERVED
 CVE-2017-1097
@@ -68876,7 +68876,7 @@
 CVE-2015-4597
 	RESERVED
 CVE-2015-4596 (Lenovo Mouse Suite before 6.73 allows local users to run arbitrary ...)
-	TODO: check
+	NOT-FOR-US: Lenovo
 CVE-2015-4595
 	RESERVED
 CVE-2015-4594 (eClinicalWorks Population Health (CCMR) suffers from a session ...)




More information about the Secure-testing-commits mailing list