[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso carnil at debian.org
Tue Sep 4 09:29:17 BST 2018


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
da61a1d9 by Salvatore Bonaccorso at 2018-09-04T08:28:52Z
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -17,15 +17,15 @@ CVE-2018-16450 (CraftedWeb through 2013-09-24 has reflected XSS via the p parame
 CVE-2018-16449 (OneThink 1.1.141212 allows CSRF for adding a page via ...)
 	TODO: check
 CVE-2018-16448 (Cscms 4 allows CSRF for creating a member via ...)
-	TODO: check
+	NOT-FOR-US: Cscms
 CVE-2018-16447 (Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF. ...)
-	TODO: check
+	NOT-FOR-US: Frog CMS
 CVE-2018-16446 (An issue was discovered in SeaCMS through 6.61. ...)
-	TODO: check
+	NOT-FOR-US: SeaCMS
 CVE-2018-16445 (An issue was discovered in SeaCMS through 6.61. SQL injection exists ...)
-	TODO: check
+	NOT-FOR-US: SeaCMS
 CVE-2018-16444 (An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF ...)
-	TODO: check
+	NOT-FOR-US: SeaCMS
 CVE-2018-16443
 	RESERVED
 CVE-2018-16442
@@ -49,9 +49,9 @@ CVE-2018-16434
 CVE-2018-16433
 	RESERVED
 CVE-2018-16432 (BlueCMS 1.6 allows SQL Injection via the user_name parameter to ...)
-	TODO: check
+	NOT-FOR-US: BlueCMS
 CVE-2018-16431 (admin/admin/adminsave.html in YFCMF v3.0 allows CSRF to add an ...)
-	TODO: check
+	NOT-FOR-US: YFCMF
 CVE-2018-16430 (GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in ...)
 	TODO: check
 CVE-2018-16429 (GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/da61a1d9d36f05ddc3205ff079de70d87db88e96

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/da61a1d9d36f05ddc3205ff079de70d87db88e96
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20180904/5cabc129/attachment.html>


More information about the debian-security-tracker-commits mailing list