[Secure-testing-commits] r55726 - data/CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Wed Sep 13 09:18:37 UTC 2017


Author: jmm
Date: 2017-09-13 09:18:37 +0000 (Wed, 13 Sep 2017)
New Revision: 55726

Modified:
   data/CVE/list
Log:
NFUs


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-09-13 09:10:13 UTC (rev 55725)
+++ data/CVE/list	2017-09-13 09:18:37 UTC (rev 55726)
@@ -13,25 +13,25 @@
 CVE-2017-14406 (A NULL pointer dereference was discovered in sync_buffer in interface.c ...)
 	TODO: check
 CVE-2017-14405 (The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote ...)
-	TODO: check
+	NOT-FOR-US: EyesOfNetwork (EON)
 CVE-2017-14404 (The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows local file ...)
-	TODO: check
+	NOT-FOR-US: EyesOfNetwork (EON)
 CVE-2017-14403 (The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection ...)
-	TODO: check
+	NOT-FOR-US: EyesOfNetwork (EON)
 CVE-2017-14402 (The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection ...)
-	TODO: check
+	NOT-FOR-US: EyesOfNetwork (EON)
 CVE-2017-14401 (The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection ...)
-	TODO: check
+	NOT-FOR-US: EyesOfNetwork (EON)
 CVE-2017-14400 (In ImageMagick 7.0.7-1 Q16, the PersistPixelCache function in ...)
 	TODO: check
 CVE-2017-14399 (In BlackCat CMS 1.2.2, unrestricted file upload is possible in ...)
-	TODO: check
+	NOT-FOR-US: BlackCat CMS
 CVE-2017-14398 (rzpnk.sys in Razer Synapse 2.20.15.1104 allows local users to read and ...)
-	TODO: check
+	NOT-FOR-US: Razer Synapse
 CVE-2017-14397 (AnyDesk before 3.6.1 on Windows has a DLL injection vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: AnyDesk
 CVE-2017-14396 (In osTicket 1.10, SQL injection is possible by constructing an array ...)
-	TODO: check
+	NOT-FOR-US: osTicket
 CVE-2017-14395
 	RESERVED
 CVE-2017-14394
@@ -127,9 +127,9 @@
 CVE-2017-14349
 	RESERVED
 CVE-2015-9230 (In the admin/db-backup-security/db-backup-security.php page in the ...)
-	TODO: check
+	NOT-FOR-US: Wordpress plugin
 CVE-2015-9229 (In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery ...)
-	TODO: check
+	NOT-FOR-US: Photocrati NextGEN Gallery
 CVE-2017-14347 (NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to ...)
 	NOT-FOR-US: NexusPHP
 CVE-2017-14346 (upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file ...)
@@ -1815,7 +1815,7 @@
 	{DSA-3971-1}
 	- tcpdump 4.9.2-1
 CVE-2017-13724 (On the Axesstel MU553S MU55XS-V1.14, there is a Stored Cross Site ...)
-	TODO: check
+	NOT-FOR-US: Axesstel MU553S MU55XS-V1.14
 CVE-2017-13723
 	RESERVED
 CVE-2017-13722
@@ -7098,17 +7098,17 @@
 CVE-2017-11767
 	RESERVED
 CVE-2017-11766 (Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-11765
 	RESERVED
 CVE-2017-11764 (Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-11763
 	RESERVED
 CVE-2017-11762
 	RESERVED
 CVE-2017-11761 (Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-11760 (uploadImage.php in ProjeQtOr before 6.3.2 allows remote authenticated ...)
 	NOT-FOR-US: ProjeQtOr
 CVE-2017-11759
@@ -8486,9 +8486,9 @@
 CVE-2017-11354 (Fiyo CMS v2.0.7 has an SQL injection vulnerability in ...)
 	NOT-FOR-US: Fiyo CMS
 CVE-2017-11351 (Axesstel MU553S MU55XS-V1.14 devices have a default password of admin ...)
-	TODO: check
+	NOT-FOR-US: Axesstel MU553S MU55XS-V1.14
 CVE-2017-11350 (Cross-Site Request Forgery (CSRF) exists in cgi-bin/ConfigSet on ...)
-	TODO: check
+	NOT-FOR-US: Axesstel MU553S MU55XS-V1.14
 CVE-2017-11349 (dataTaker DT8x dEX 1.72.007 allows remote attackers to compose programs ...)
 	NOT-FOR-US: dataTaker
 CVE-2017-11348 (In Octopus Deploy 3.x before 3.15.4, an authenticated user with ...)
@@ -15619,7 +15619,7 @@
 CVE-2017-8919 (NetApp OnCommand API Services before 1.2P3 logs the LDAP BIND password ...)
 	NOT-FOR-US: NetApp
 CVE-2017-8918 (XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - ...)
-	TODO: check
+	NOT-FOR-US: Dive Assistant
 CVE-2017-8917 (SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows ...)
 	NOT-FOR-US: Joomla
 CVE-2017-8916
@@ -16085,141 +16085,141 @@
 CVE-2017-8760 (An issue was discovered on Accellion FTA devices before FTA_9_12_180. ...)
 	NOT-FOR-US: Accellion FTA devices
 CVE-2017-8759 (Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8758 (Microsoft Exchange Server 2016 allows an elevation of privilege ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8757 (Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8756 (Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8755 (Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8754 (Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8753 (Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8752 (Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows ...)
 	NOT-FOR-US: Apache Atlas
 CVE-2017-8751 (Microsoft Edge in Microsoft Windows 1703 allows an attacker to execute ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8750 (Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8749 (Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8748 (Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8747 (Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8746 (Windows Device Guard in Windows 10 1607, 1703, and Windows Server 2016 ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8745 (An elevation of privilege vulnerability exists in Microsoft SharePoint ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8744 (A remote code execution vulnerability exists in Excel Services, ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8743 (A remote code execution vulnerability exists in Microsoft PowerPoint ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8742 (A remote code execution vulnerability exists in Microsoft PowerPoint ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8741 (Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8740 (Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8739 (Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8738 (Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and Windows ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8737 (Microsoft Windows PDF Library in Microsoft Windows 8.1 and Windows RT ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8736 (Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8735 (Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8734 (Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8733 (Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8732
 	RESERVED
 CVE-2017-8731 (Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8730
 	RESERVED
 CVE-2017-8729 (Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8728 (Microsoft Windows PDF Library in Microsoft Windows 8.1 and Windows RT ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8727
 	RESERVED
 CVE-2017-8726
 	RESERVED
 CVE-2017-8725 (A remote code execution vulnerability exists in Microsoft Publisher ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8724 (Microsoft Edge in Microsoft Windows 10 Version 1703 allows an attacker ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8723 (Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8722
 	RESERVED
 CVE-2017-8721
 	RESERVED
 CVE-2017-8720 (The Microsoft Windows graphics component on Microsoft Windows Server ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8719 (The Windows kernel component on Microsoft Windows Server 2008 SP2 and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8718
 	RESERVED
 CVE-2017-8717
 	RESERVED
 CVE-2017-8716 (Windows Control Flow Guard in Microsoft Windows 10 Version 1703 allows ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8715
 	RESERVED
 CVE-2017-8714 (The Windows Hyper-V component on Microsoft Windows 8.1, Windows Server ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8713 (The Windows Hyper-V component on Microsoft Windows Windows 8.1, ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8712 (The Windows Hyper-V component on Microsoft Windows 10 1607, 1703, and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8711 (The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8710 (The Microsoft Common Console Document (.msc) in Microsoft Windows 7 ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8709 (The Windows kernel component on Microsoft Windows Server 2008 SP2 and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8708 (The Windows kernel component on Microsoft Windows Server 2008 SP2 and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8707 (The Windows Hyper-V component on Microsoft Windows Server 2008 SP2 and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8706 (The Windows Hyper-V component on Microsoft Windows 10 Gold, 1511, ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8705
 	RESERVED
 CVE-2017-8704 (The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8703
 	RESERVED
 CVE-2017-8702 (Windows Error Reporting (WER) in Microsoft Windows 10 Gold, 1511, and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8701
 	RESERVED
 CVE-2017-8700
 	RESERVED
 CVE-2017-8699 (Windows Shell in Microsoft Windows 7 SP1, Windows Server 2008 and R2 ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8698
 	RESERVED
 CVE-2017-8697
 	RESERVED
 CVE-2017-8696 (Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8695 (Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8694
 	RESERVED
 CVE-2017-8693
 	RESERVED
 CVE-2017-8692 (The Windows Uniscribe component on Microsoft Windows 8.1, Windows ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8691 (Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow an ...)
 	NOT-FOR-US: Microsoft Windows
 CVE-2017-8690
@@ -16227,33 +16227,33 @@
 CVE-2017-8689
 	RESERVED
 CVE-2017-8688 (Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8687 (The Windows kernel component on Microsoft Windows Server 2008 SP2 and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8686 (The Windows Server DHCP service in Windows Server 2012 Gold and R2, ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8685 (Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8684 (Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8683 (Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8682 (Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8681 (The Windows kernel component on Microsoft Windows Server 2008 SP2 and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8680 (The Windows kernel component on Microsoft Windows Server 2008 SP2 and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8679 (The Windows kernel component on Microsoft Windows Server 2008 SP2 and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8678 (The Windows kernel component on Microsoft Windows Server 2008 SP2 and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8677 (The Windows GDI+ component on Microsoft Windows Server 2008 SP2 and R2 ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8676 (The Windows Graphics Device Interface (GDI) in Microsoft Windows ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8675 (The Windows Kernel-Mode Drivers component on Microsoft Windows Server ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8674 (Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to ...)
 	NOT-FOR-US: Microsoft
 CVE-2017-8673 (The Remote Desktop Protocol (RDP) implementation in Microsoft Windows ...)
@@ -16283,7 +16283,7 @@
 CVE-2017-8661 (Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server ...)
 	NOT-FOR-US: Microsoft
 CVE-2017-8660 (Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8659 (Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to ...)
 	NOT-FOR-US: Microsoft
 CVE-2017-8658 (A remote code execution vulnerability exists in the way that the ...)
@@ -16305,9 +16305,9 @@
 CVE-2017-8650 (Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to ...)
 	NOT-FOR-US: Microsoft
 CVE-2017-8649 (Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8648 (Microsoft Edge in Microsoft Windows Version 1703 allows an attacker to ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8647 (Microsoft Edge in Windows 10 1703 allows an attacker to execute ...)
 	NOT-FOR-US: Microsoft
 CVE-2017-8646 (Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 ...)
@@ -16317,7 +16317,7 @@
 CVE-2017-8644 (Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and ...)
 	NOT-FOR-US: Microsoft
 CVE-2017-8643 (Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8642 (Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to ...)
 	NOT-FOR-US: Microsoft
 CVE-2017-8641 (Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 ...)
@@ -16339,13 +16339,13 @@
 CVE-2017-8633 (Windows Error Reporting (WER) in Windows Server 2008 SP2 and R2 SP1, ...)
 	NOT-FOR-US: Microsoft
 CVE-2017-8632 (A remote code execution vulnerability exists in Microsoft Excel 2010 ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8631 (A remote code execution vulnerability exists in Excel Services, ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8630 (Microsoft Office 2016 allows a remote code execution vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8629 (Microsoft SharePoint Server 2013 Service Pack 1 allows an elevation of ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8628 (Microsoft Bluetooth Driver in Windows Server 2008 SP2, Windows 7 SP1, ...)
 	NOT-FOR-US: Microsoft Windows
 	NOTE: https://www.armis.com/blueborne/
@@ -16410,7 +16410,7 @@
 CVE-2017-8598 (Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and ...)
 	NOT-FOR-US: Microsoft
 CVE-2017-8597 (Microsoft Edge in Microsoft Windows 10 Version 1703 allows an attacker ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8596 (Microsoft Edge in Microsoft Windows 10 1607, and 1703, and Windows ...)
 	NOT-FOR-US: Microsoft
 CVE-2017-8595 (Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and ...)
@@ -16470,7 +16470,7 @@
 CVE-2017-8568
 	RESERVED
 CVE-2017-8567 (A remote code execution vulnerability exists in Microsoft Excel for ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-8566 (Microsoft Windows 1607, 1703, and Windows Server 2016 allows an ...)
 	NOT-FOR-US: Microsoft
 CVE-2017-8565 (Windows PowerShell in Windows Server 2008 SP2 and R2 SP1, Windows 7 ...)
@@ -17957,7 +17957,7 @@
 CVE-2017-8016
 	RESERVED
 CVE-2017-8015 (EMC AppSync (all versions prior to 3.5) contains a SQL injection ...)
-	TODO: check
+	NOT-FOR-US: EMC
 CVE-2017-8014
 	RESERVED
 CVE-2017-8013
@@ -20157,7 +20157,7 @@
 CVE-2017-7442 (Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code ...)
 	NOT-FOR-US: Nitro Pro
 CVE-2017-7441 (In Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the ...)
-	TODO: check
+	NOT-FOR-US: Sophos
 CVE-2017-7440 (Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop ...)
 	NOT-FOR-US: Kerio
 CVE-2017-7439 (NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 might ...)
@@ -24451,9 +24451,9 @@
 	NOTE: Fixed by: http://git.savannah.gnu.org/cgit/icoutils.git/commit/?id=f148ae5af1c9eeb85610a5653a7f625dd6c3ac2e
 	NOTE: Proposed patch from Red Hat contributor: https://bugzilla.redhat.com/attachment.cgi?id=1256407
 CVE-2017-6008 (A kernel pool overflow in the driver hitmanpro37.sys in Sophos ...)
-	TODO: check
+	NOT-FOR-US: Sophos
 CVE-2017-6007 (A kernel pool overflow in the driver hitmanpro37.sys in Sophos ...)
-	TODO: check
+	NOT-FOR-US: Sophos
 CVE-2017-6006
 	REJECTED
 CVE-2017-6005 (Waves MaxxAudio, as installed on Dell laptops, adds a "WavesSysSvc" ...)
@@ -37211,9 +37211,9 @@
 CVE-2017-1521
 	RESERVED
 CVE-2017-1520 (IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2017-1519 (IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2017-1518
 	RESERVED
 CVE-2017-1517
@@ -37347,9 +37347,9 @@
 CVE-2017-1453
 	RESERVED
 CVE-2017-1452 (IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2017-1451 (IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2017-1450 (IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to ...)
 	NOT-FOR-US: IBM
 CVE-2017-1449 (IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to ...)
@@ -37373,9 +37373,9 @@
 CVE-2017-1440 (IBM Emptoris Services Procurement 10.0.0.5 could allow a remote ...)
 	NOT-FOR-US: IBM
 CVE-2017-1439 (IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2017-1438 (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2017-1437
 	RESERVED
 CVE-2017-1436
@@ -37383,7 +37383,7 @@
 CVE-2017-1435
 	RESERVED
 CVE-2017-1434 (IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2017-1433
 	RESERVED
 CVE-2017-1432
@@ -37547,7 +37547,7 @@
 CVE-2017-1353
 	RESERVED
 CVE-2017-1352 (IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2017-1351
 	RESERVED
 CVE-2017-1350
@@ -37927,7 +37927,7 @@
 CVE-2017-1163
 	RESERVED
 CVE-2017-1162 (IBM QRadar 7.2 and 7.3 discloses sensitive information to unauthorized ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2017-1161 (IBM API Connect 5.0.6.0 could allow a remote attacker to execute ...)
 	NOT-FOR-US: IBM
 CVE-2017-1160 (IBM Financial Transaction Manager for ACH Services for Multi-Platform ...)
@@ -45338,7 +45338,7 @@
 CVE-2017-0162 (A remote code execution vulnerability exists when Windows Hyper-V ...)
 	NOT-FOR-US: Microsoft
 CVE-2017-0161 (The Windows NetBT Session Services component on Microsoft Windows ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2017-0160 (Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 ...)
 	NOT-FOR-US: Microsoft
 CVE-2017-0159 (A security feature bypass vulnerability exists in Windows 10 1607, ...)




More information about the Secure-testing-commits mailing list