[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso carnil at debian.org
Mon Jul 16 21:10:24 BST 2018


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
76663717 by security tracker role at 2018-07-16T20:10:16+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -1,7 +1,175 @@
-CVE-2018-14326 [integer overflow when resizing MP4Array for the ftyp atom in mp4array.h]
+CVE-2018-14324 (The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP ...)
+	TODO: check
+CVE-2018-14323
+	RESERVED
+CVE-2018-14322
+	RESERVED
+CVE-2018-14321
+	RESERVED
+CVE-2018-14320
+	RESERVED
+CVE-2018-14319
+	RESERVED
+CVE-2018-14318
+	RESERVED
+CVE-2018-14317
+	RESERVED
+CVE-2018-14316
+	RESERVED
+CVE-2018-14315
+	RESERVED
+CVE-2018-14314
+	RESERVED
+CVE-2018-14313
+	RESERVED
+CVE-2018-14312
+	RESERVED
+CVE-2018-14311
+	RESERVED
+CVE-2018-14310
+	RESERVED
+CVE-2018-14309
+	RESERVED
+CVE-2018-14308
+	RESERVED
+CVE-2018-14307
+	RESERVED
+CVE-2018-14306
+	RESERVED
+CVE-2018-14305
+	RESERVED
+CVE-2018-14304
+	RESERVED
+CVE-2018-14303
+	RESERVED
+CVE-2018-14302
+	RESERVED
+CVE-2018-14301
+	RESERVED
+CVE-2018-14300
+	RESERVED
+CVE-2018-14299
+	RESERVED
+CVE-2018-14298
+	RESERVED
+CVE-2018-14297
+	RESERVED
+CVE-2018-14296
+	RESERVED
+CVE-2018-14295
+	RESERVED
+CVE-2018-14294
+	RESERVED
+CVE-2018-14293
+	RESERVED
+CVE-2018-14292
+	RESERVED
+CVE-2018-14291
+	RESERVED
+CVE-2018-14290
+	RESERVED
+CVE-2018-14289
+	RESERVED
+CVE-2018-14288
+	RESERVED
+CVE-2018-14287
+	RESERVED
+CVE-2018-14286
+	RESERVED
+CVE-2018-14285
+	RESERVED
+CVE-2018-14284
+	RESERVED
+CVE-2018-14283
+	RESERVED
+CVE-2018-14282
+	RESERVED
+CVE-2018-14281
+	RESERVED
+CVE-2018-14280
+	RESERVED
+CVE-2018-14279
+	RESERVED
+CVE-2018-14278
+	RESERVED
+CVE-2018-14277
+	RESERVED
+CVE-2018-14276
+	RESERVED
+CVE-2018-14275
+	RESERVED
+CVE-2018-14274
+	RESERVED
+CVE-2018-14273
+	RESERVED
+CVE-2018-14272
+	RESERVED
+CVE-2018-14271
+	RESERVED
+CVE-2018-14270
+	RESERVED
+CVE-2018-14269
+	RESERVED
+CVE-2018-14268
+	RESERVED
+CVE-2018-14267
+	RESERVED
+CVE-2018-14266
+	RESERVED
+CVE-2018-14265
+	RESERVED
+CVE-2018-14264
+	RESERVED
+CVE-2018-14263
+	RESERVED
+CVE-2018-14262
+	RESERVED
+CVE-2018-14261
+	RESERVED
+CVE-2018-14260
+	RESERVED
+CVE-2018-14259
+	RESERVED
+CVE-2018-14258
+	RESERVED
+CVE-2018-14257
+	RESERVED
+CVE-2018-14256
+	RESERVED
+CVE-2018-14255
+	RESERVED
+CVE-2018-14254
+	RESERVED
+CVE-2018-14253
+	RESERVED
+CVE-2018-14252
+	RESERVED
+CVE-2018-14251
+	RESERVED
+CVE-2018-14250
+	RESERVED
+CVE-2018-14249
+	RESERVED
+CVE-2018-14248
+	RESERVED
+CVE-2018-14247
+	RESERVED
+CVE-2018-14246
+	RESERVED
+CVE-2018-14245
+	RESERVED
+CVE-2018-14244
+	RESERVED
+CVE-2018-14243
+	RESERVED
+CVE-2018-14242
+	RESERVED
+CVE-2018-14241
+	RESERVED
+CVE-2018-14326 (In MP4v2 2.0.0, there is an integer overflow (with resultant memory ...)
 	- mp4v2 <unfixed>
 	NOTE: http://www.openwall.com/lists/oss-security/2018/07/16/1
-CVE-2018-14325 [integer underflow when parsing MP4Atom in mp4atom.cpp]
+CVE-2018-14325 (In MP4v2 2.0.0, there is an integer underflow (with resultant memory ...)
 	- mp4v2 <unfixed>
 	NOTE: http://www.openwall.com/lists/oss-security/2018/07/16/1
 CVE-2018-14240
@@ -346,8 +514,8 @@ CVE-2018-14072 (libsixel 1.8.1 has a memory leak in sixel_decoder_decode in deco
 	- libsixel <unfixed> (low; bug #903858)
 	[stretch] - libsixel <no-dsa> (Minor issue)
 	NOTE: https://github.com/saitoha/libsixel/issues/67#issue-341198610
-CVE-2018-14071
-	RESERVED
+CVE-2018-14071 (The Geo Mashup plugin before 1.10.4 for WordPress has insufficient ...)
+	TODO: check
 CVE-2018-14070
 	RESERVED
 CVE-2018-14069 (An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability ...)
@@ -594,10 +762,10 @@ CVE-2018-13983
 	RESERVED
 CVE-2018-13982
 	RESERVED
-CVE-2018-13981
-	RESERVED
-CVE-2018-13980
-	RESERVED
+CVE-2018-13981 (The websites that were built from Zeta Producer Desktop CMS before ...)
+	TODO: check
+CVE-2018-13980 (The websites that were built from Zeta Producer Desktop CMS before ...)
+	TODO: check
 CVE-2018-13979
 	RESERVED
 CVE-2018-13978
@@ -1870,8 +2038,8 @@ CVE-2018-13389 (The attachment resource in Atlassian Confluence before version 6
 	NOT-FOR-US: Atlassian Confluence
 CVE-2018-13388 (The review attachment resource in Atlassian Fisheye and Crucible ...)
 	NOT-FOR-US: Atlassian Fisheye and Crucible
-CVE-2018-13387
-	RESERVED
+CVE-2018-13387 (The IncomingMailServers resource in Atlassian JIRA Server before ...)
+	TODO: check
 CVE-2018-13386
 	RESERVED
 CVE-2018-13385
@@ -6094,10 +6262,10 @@ CVE-2016-1000344 (In the Bouncy Castle JCE Provider version 1.55 and earlier the
 	- bouncycastle 1.56-1
 	[jessie] - bouncycastle <ignored> (Intrusive changes, can be mitigated by using a different mode than ECB)
 	NOTE: https://github.com/bcgit/bc-java/commit/9385b0ebd277724b167fe1d1456e3c112112be1f
-CVE-2018-11717
-	RESERVED
-CVE-2018-11716
-	RESERVED
+CVE-2018-11717 (An issue was discovered in Zoho ManageEngine Desktop Central before ...)
+	TODO: check
+CVE-2018-11716 (An issue was discovered in Zoho ManageEngine Desktop Central before ...)
+	TODO: check
 CVE-2018-11715 (The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread ...)
 	NOT-FOR-US: Recent Threads plugin for MyBB
 CVE-2018-11714 (An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 ...)
@@ -8290,8 +8458,7 @@ CVE-2018-10887 (A flaw was found in libgit2 before version 0.27.3. It has been .
 	- libgit2 <unfixed> (bug #903509)
 	NOTE: https://github.com/libgit2/libgit2/commit/3f461902dc1072acb8b7607ee65d0a0458ffac2a
 	NOTE: https://github.com/libgit2/libgit2/commit/c1577110467b701dcbcf9439ac225ea851b47d22
-CVE-2018-10886
-	RESERVED
+CVE-2018-10886 (ant before version 1.9.12 unzip and untar targets allows the ...)
 	- ant 1.10.4-1
 	NOTE: Fixed upstream in 1.9.12 and 1.10.4
 	NOTE: https://github.com/apache/ant/commit/e56e54565804991c62ec76dad385d2bdda8972a7
@@ -8403,8 +8570,7 @@ CVE-2018-10860 (perl-archive-zip is vulnerable to a directory traversal in ...)
 	- libarchive-zip-perl <unfixed> (bug #902882)
 	NOTE: https://github.com/redhotpenguin/perl-Archive-Zip/pull/33
 	NOTE: https://github.com/redhotpenguin/perl-Archive-Zip/commit/95e1df86327
-CVE-2018-10859
-	RESERVED
+CVE-2018-10859 (git-annex is vulnerable to an Information Exposure when decrypting ...)
 	- git-annex 6.20180626-1
 	[stretch] - git-annex 6.20170101-1+deb9u2
 	NOTE: http://www.openwall.com/lists/oss-security/2018/06/26/4
@@ -24191,8 +24357,8 @@ CVE-2018-5241 (Symantec Advanced Secure Gateway (ASG) 6.6 and 6.7, and ProxySG 6
 	NOT-FOR-US: Symantec
 CVE-2018-5240
 	RESERVED
-CVE-2018-5239
-	RESERVED
+CVE-2018-5239 (Norton App Lock prior to v1.3.0.332 can be susceptible to a bypass ...)
+	TODO: check
 CVE-2018-5238
 	RESERVED
 CVE-2018-5237 (Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 ...)
@@ -24219,8 +24385,8 @@ CVE-2018-5231 (The ForgotLoginDetails resource in Atlassian Jira before version 
 	NOT-FOR-US: Atlassian
 CVE-2018-5230 (The issue collector in Atlassian Jira before version 7.6.6, from ...)
 	NOT-FOR-US: Atlassian
-CVE-2018-5229
-	RESERVED
+CVE-2018-5229 (The NotificationRepresentationFactoryImpl class in Atlassian Universal ...)
+	TODO: check
 CVE-2018-5228 (The /browse/~raw resource in Atlassian Fisheye and Crucible before ...)
 	NOT-FOR-US: Atlassian
 CVE-2018-5227 (Various administrative application link resources in Atlassian ...)
@@ -37474,16 +37640,16 @@ CVE-2018-0712 (Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 
 	NOT-FOR-US: QNAP
 CVE-2018-0711 (Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build ...)
 	NOT-FOR-US: QNAP
-CVE-2018-0710
-	RESERVED
-CVE-2018-0709
-	RESERVED
-CVE-2018-0708
-	RESERVED
-CVE-2018-0707
-	RESERVED
-CVE-2018-0706
-	RESERVED
+CVE-2018-0710 (Command injection vulnerability in SSH of QNAP Q'center Virtual ...)
+	TODO: check
+CVE-2018-0709 (Command injection vulnerability in date of QNAP Q'center Virtual ...)
+	TODO: check
+CVE-2018-0708 (Command injection vulnerability in networking of QNAP Q'center Virtual ...)
+	TODO: check
+CVE-2018-0707 (Command injection vulnerability in change password of QNAP Q'center ...)
+	TODO: check
+CVE-2018-0706 (Exposure of Private Information in QNAP Q'center Virtual Appliance ...)
+	TODO: check
 CVE-2017-17042 (lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not ...)
 	- yard 0.9.12-1
 	[stretch] - yard <no-dsa> (Minor issue)
@@ -38343,12 +38509,12 @@ CVE-2018-0387
 	RESERVED
 CVE-2018-0386
 	RESERVED
-CVE-2018-0385
-	RESERVED
-CVE-2018-0384
-	RESERVED
-CVE-2018-0383
-	RESERVED
+CVE-2018-0385 (A vulnerability in the detection engine parsing of Security Socket ...)
+	TODO: check
+CVE-2018-0384 (A vulnerability in the detection engine of Cisco FireSIGHT System ...)
+	TODO: check
+CVE-2018-0383 (A vulnerability in the detection engine of Cisco FireSIGHT System ...)
+	TODO: check
 CVE-2018-0382
 	RESERVED
 CVE-2018-0381
@@ -38373,16 +38539,16 @@ CVE-2018-0372
 	RESERVED
 CVE-2018-0371 (A vulnerability in the Web Admin Interface of Cisco Meeting Server ...)
 	NOT-FOR-US: Cisco
-CVE-2018-0370
-	RESERVED
-CVE-2018-0369
-	RESERVED
-CVE-2018-0368
-	RESERVED
+CVE-2018-0370 (A vulnerability in the detection engine of Cisco Firepower System ...)
+	TODO: check
+CVE-2018-0369 (A vulnerability in the reassembly logic for fragmented IPv4 packets of ...)
+	TODO: check
+CVE-2018-0368 (A vulnerability in Cisco Digital Network Architecture (DNA) Center ...)
+	TODO: check
 CVE-2018-0367
 	RESERVED
-CVE-2018-0366
-	RESERVED
+CVE-2018-0366 (A vulnerability in the web-based management interface of Cisco Web ...)
+	TODO: check
 CVE-2018-0365 (A vulnerability in the web-based management interface of Cisco ...)
 	NOT-FOR-US: Cisco
 CVE-2018-0364 (A vulnerability in the web-based management interface of Cisco Unified ...)
@@ -38391,10 +38557,10 @@ CVE-2018-0363 (A vulnerability in the web-based management interface of Cisco Un
 	NOT-FOR-US: Cisco
 CVE-2018-0362 (A vulnerability in BIOS authentication management of Cisco 5000 Series ...)
 	NOT-FOR-US: Cisco
-CVE-2018-0361
-	RESERVED
-CVE-2018-0360
-	RESERVED
+CVE-2018-0361 (ClamAV before 0.100.1 lacks a PDF object length check, resulting in an ...)
+	TODO: check
+CVE-2018-0360 (ClamAV before 0.100.1 has an HWP integer overflow with a resultant ...)
+	TODO: check
 CVE-2018-0359 (A vulnerability in the session identification management functionality ...)
 	NOT-FOR-US: Cisco
 CVE-2018-0358 (A vulnerability in the file descriptor handling of Cisco TelePresence ...)
@@ -38431,8 +38597,8 @@ CVE-2018-0343
 	RESERVED
 CVE-2018-0342
 	RESERVED
-CVE-2018-0341
-	RESERVED
+CVE-2018-0341 (A vulnerability in the web-based UI of Cisco IP Phone 6800, 7800, and ...)
+	TODO: check
 CVE-2018-0340 (A vulnerability in the web framework of the Cisco Unified ...)
 	NOT-FOR-US: Cisco
 CVE-2018-0339 (A vulnerability in the web-based management interface of Cisco Identity ...)
@@ -68481,8 +68647,7 @@ CVE-2017-7470
 	NOT-FOR-US: Red Hat / spacewalk-backend
 CVE-2017-7469
 	REJECTED
-CVE-2017-7468
-	RESERVED
+CVE-2017-7468 (In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would ...)
 	- curl 7.52.1-5
 	[jessie] - curl <not-affected> (Only affects 7.52 and later)
 	[wheezy] - curl <not-affected> (Only affects 7.52 and later)
@@ -83431,8 +83596,7 @@ CVE-2017-2640 [Out-of-bounds write when stripping xml]
 CVE-2017-2639
 	RESERVED
 	NOT-FOR-US: Red Hat CloudForms Management Engine
-CVE-2017-2638
-	RESERVED
+CVE-2017-2638 (It was found that the REST API in Infinispan before version 9.0.0 did ...)
 	NOT-FOR-US: infinispan
 CVE-2017-2637
 	RESERVED
@@ -130953,7 +131117,7 @@ CVE-2015-4970
 CVE-2015-4969
 	RESERVED
 CVE-2015-4968
-	RESERVED
+	REJECTED
 CVE-2015-4967 (SQL injection vulnerability in IBM Maximo Asset Management 7.1 through ...)
 	NOT-FOR-US: IBM
 CVE-2015-4966 (IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 ...)
@@ -139805,9 +139969,9 @@ CVE-2015-1993 (IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5
 CVE-2015-1992 (IBM Systems Director 5.2.x, 6.1.x, 6.2.0.x, 6.2.1.x, 6.3.0.0, 6.3.1.x, ...)
 	NOT-FOR-US: IBM Systems Director
 CVE-2015-1991
-	RESERVED
+	REJECTED
 CVE-2015-1990
-	RESERVED
+	REJECTED
 CVE-2015-1989 (SQL injection vulnerability in IBM Security QRadar Incident Forensics ...)
 	NOT-FOR-US: IBM QRadar
 CVE-2015-1988 (Cross-site scripting (XSS) vulnerability in IBM Tivoli Storage Manger ...)
@@ -147648,7 +147812,7 @@ CVE-2015-0165
 CVE-2015-0164
 	REJECTED
 CVE-2015-0163
-	RESERVED
+	REJECTED
 CVE-2015-0162 (IBM Security SiteProtector System 3.0, 3.1, and 3.1.1 allows local ...)
 	NOT-FOR-US: IBM
 CVE-2015-0161 (SQL injection vulnerability in IBM Security SiteProtector System 3.0 ...)
@@ -147664,9 +147828,9 @@ CVE-2015-0157 (IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 1
 CVE-2015-0156 (Cross-site scripting (XSS) vulnerability in IBM Business Process ...)
 	NOT-FOR-US: IBM
 CVE-2015-0155
-	RESERVED
+	REJECTED
 CVE-2015-0154
-	RESERVED
+	REJECTED
 CVE-2015-0153 (D-Link DIR-815 devices with firmware before 2.07.B01 allow remote ...)
 	NOT-FOR-US: D-Link
 CVE-2015-0152 (D-Link DIR-815 devices with firmware before 2.07.B01 allow remote ...)
@@ -165714,8 +165878,7 @@ CVE-2014-2081 (Multiple SQL injection vulnerabilities in the login in ...)
 	NOT-FOR-US: Innovative vtls-Virtua
 CVE-2014-2080 (Cross-site scripting (XSS) vulnerability in ...)
 	NOT-FOR-US: MODx Revolution
-CVE-2014-2079 [File New sets inappropriate permissions in ACL enabled directories]
-	RESERVED
+CVE-2014-2079 (X File Explorer (aka xfe) might allow local users to bypass intended ...)
 	- xfe 1.37-2 (bug #739536)
 	[wheezy] - xfe <no-dsa> (Minor issue)
 	[squeeze] - xfe <no-dsa> (Minor issue)
@@ -182293,7 +182456,7 @@ CVE-2013-3024 (IBM WebSphere Application Server (WAS) 8.5 through 8.5.0.2 on UNI
 CVE-2013-3023 (IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and ...)
 	NOT-FOR-US: IBM
 CVE-2013-3022
-	RESERVED
+	REJECTED
 CVE-2013-3021
 	RESERVED
 CVE-2013-3020 (IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 ...)
@@ -182355,9 +182518,9 @@ CVE-2013-2993 (IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0
 CVE-2013-2992 (The Search component in IBM WebSphere Commerce 7.0 FP4 through FP6, in ...)
 	NOT-FOR-US: IBM
 CVE-2013-2991
-	RESERVED
+	REJECTED
 CVE-2013-2990
-	RESERVED
+	REJECTED
 CVE-2013-2989 (The file-copying functionality in IBM Sterling Connect:Direct 3.8.00, ...)
 	NOT-FOR-US: IBM
 CVE-2013-2988 (Absolute path traversal vulnerability in the server in IBM Cognos ...)
@@ -182365,7 +182528,7 @@ CVE-2013-2988 (Absolute path traversal vulnerability in the server in IBM Cognos
 CVE-2013-2987 (IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 ...)
 	NOT-FOR-US: IBM
 CVE-2013-2986
-	RESERVED
+	REJECTED
 CVE-2013-2985 (IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 ...)
 	NOT-FOR-US: IBM
 CVE-2013-2984 (Directory traversal vulnerability in IBM Sterling B2B Integrator 5.1 ...)
@@ -182391,11 +182554,11 @@ CVE-2013-2975
 CVE-2013-2974 (The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager ...)
 	NOT-FOR-US: IBM Tivoli Application Dependency Discovery Manager
 CVE-2013-2973
-	RESERVED
+	REJECTED
 CVE-2013-2972 (IBM WebSphere Cast Iron 6.3 allows remote attackers to bypass intended ...)
 	NOT-FOR-US: IBM
 CVE-2013-2971
-	RESERVED
+	REJECTED
 CVE-2013-2970 (Unspecified vulnerability in IBM QRadar Security Information and Event ...)
 	NOT-FOR-US: IBM
 CVE-2013-2969 (Cross-site scripting (XSS) vulnerability in IBM Sterling Control ...)
@@ -189845,7 +190008,7 @@ CVE-2013-0552
 CVE-2013-0551 (The Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 ...)
 	NOT-FOR-US: IBM Tivoli Monitoring
 CVE-2013-0550
-	RESERVED
+	REJECTED
 CVE-2013-0549 (Cross-site scripting (XSS) vulnerability in the Web Content Manager - ...)
 	NOT-FOR-US: IBM WebSphere Portal
 CVE-2013-0548 (Multiple cross-site scripting (XSS) vulnerabilities in the Basic ...)
@@ -189889,7 +190052,7 @@ CVE-2013-0530
 CVE-2013-0529 (The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 ...)
 	NOT-FOR-US: IBM Sterling Connect:Direct
 CVE-2013-0528
-	RESERVED
+	REJECTED
 CVE-2013-0527 (The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 ...)
 	NOT-FOR-US: IBM Sterling Connect:Direct
 CVE-2013-0526 (ping.php in Global Console Manager 16 (GCM16) and Global Console ...)
@@ -189900,8 +190063,8 @@ CVE-2013-0524
 	RESERVED
 CVE-2013-0523 (IBM WebSphere Commerce Enterprise 5.6.x through 5.6.1.5, 6.0.x through ...)
 	NOT-FOR-US: IBM WebSphere
-CVE-2013-0522
-	RESERVED
+CVE-2013-0522 (The Notes Client Single Logon feature in IBM Notes 8.0, 8.0.1, 8.0.2, ...)
+	TODO: check
 CVE-2013-0521
 	RESERVED
 CVE-2013-0520 (IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim ...)
@@ -189913,7 +190076,7 @@ CVE-2013-0518 (IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Inter
 CVE-2013-0517
 	RESERVED
 CVE-2013-0516
-	RESERVED
+	REJECTED
 CVE-2013-0515
 	RESERVED
 CVE-2013-0514
@@ -206208,7 +206371,7 @@ CVE-2012-0724 (Adobe Flash Player before 11.2.202.229 in Google Chrome before ..
 CVE-2012-0723 (The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, ...)
 	NOT-FOR-US: IBM AIX, VIOS
 CVE-2012-0721
-	RESERVED
+	REJECTED
 CVE-2012-0720 (Cross-site scripting (XSS) vulnerability in the Integration Solution ...)
 	NOT-FOR-US: IBM WebSphere Application
 CVE-2012-0719 (Cross-site scripting (XSS) vulnerability in IBM Tivoli Endpoint ...)
@@ -208047,11 +208210,11 @@ CVE-2011-4895 (Tor before 0.2.2.34, when configured as a bridge, sets up circuit
 CVE-2011-4894 (Tor before 0.2.2.34, when configured as a bridge, uses direct DirPort ...)
 	- tor 0.2.2.34-1 (unimportant)
 CVE-2011-4893
-	RESERVED
+	REJECTED
 CVE-2011-4892
-	RESERVED
+	REJECTED
 CVE-2011-4891
-	RESERVED
+	REJECTED
 CVE-2011-4890 (The server in IBM solidDB 6.5 before FP9 and 7.0 before FP1 allows ...)
 	NOT-FOR-US: IBM solidDB
 CVE-2011-4889 (The javax.naming.directory.AttributeInUseException class in the ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/76663717881bfc30c533af7d5da047a1f7e9b998

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/76663717881bfc30c533af7d5da047a1f7e9b998
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20180716/b0597889/attachment-0001.html>


More information about the debian-security-tracker-commits mailing list