[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso carnil at debian.org
Mon Sep 10 11:45:24 BST 2018


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5bd75f8b by Salvatore Bonaccorso at 2018-09-10T10:42:33Z
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -20,25 +20,25 @@ CVE-2018-16784
 CVE-2018-16783
 	RESERVED
 CVE-2018-16782 (libimageworsener.a in ImageWorsener 1.3.2 has a buffer overflow in the ...)
-	TODO: check
+	NOT-FOR-US: ImageWorsener
 CVE-2018-16781 (ffjpeg.dll in ffjpeg before 2018-08-22 allows remote attackers to cause ...)
 	TODO: check
 CVE-2018-16780 (Complete Responsive CMS Blog through 2018-05-20 has XSS via a comment. ...)
-	TODO: check
+	NOT-FOR-US: Complete Responsive CMS Blog
 CVE-2018-16779 (BlogCMS through 2016-10-25 has XSS via a comment. ...)
-	TODO: check
+	NOT-FOR-US: BlogCMS
 CVE-2018-16778
 	RESERVED
 CVE-2018-16777
 	RESERVED
 CVE-2018-16776 (wityCMS 0.6.2 has XSS via the "Site Name" field found in the "Contact" ...)
-	TODO: check
+	NOT-FOR-US: wityCMS
 CVE-2018-16775 (An issue was discovered in Victor CMS through 2018-05-10. There is XSS ...)
-	TODO: check
+	NOT-FOR-US: Victor CMS
 CVE-2018-16774 (HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file ...)
-	TODO: check
+	NOT-FOR-US: HongCMS
 CVE-2018-16773 (EasyCMS 1.5 allows XSS via the ...)
-	TODO: check
+	NOT-FOR-US: EasyCMS
 CVE-2018-16772 (Hoosk v1.7.0 allows XSS via the Navigation Title of a new page entered ...)
 	TODO: check
 CVE-2018-16771 (Hoosk v1.7.0 allows PHP code execution via a SiteUrl that is provided ...)
@@ -58,15 +58,15 @@ CVE-2018-16765 (In WAVM through 2018-07-26, a crafted file sent to the WebAssemb
 CVE-2018-16764 (In WAVM through 2018-07-26, a crafted file sent to the WebAssembly ...)
 	TODO: check
 CVE-2018-16763 (FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter ...)
-	TODO: check
+	NOT-FOR-US: FUEL CMS
 CVE-2018-16762 (FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or ...)
-	TODO: check
+	NOT-FOR-US: FUEL CMS
 CVE-2018-16761 (Eventum before 3.4.0 has an open redirect vulnerability. ...)
 	TODO: check
 CVE-2018-16760
 	RESERVED
 CVE-2018-16759 (The removeXSS function in App/Common/common.php (called from ...)
-	TODO: check
+	NOT-FOR-US: EasyCMS
 CVE-2018-16758
 	RESERVED
 CVE-2018-16757



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/5bd75f8b9ada94c6b46cf23edbc2e3ec37b5cfa6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/5bd75f8b9ada94c6b46cf23edbc2e3ec37b5cfa6
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20180910/9f7238d5/attachment.html>


More information about the debian-security-tracker-commits mailing list