[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso carnil at debian.org
Thu Sep 13 09:45:02 BST 2018


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
054edaab by Salvatore Bonaccorso at 2018-09-13T08:44:40Z
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,29 +1,29 @@
 CVE-2018-16983 (NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other ...)
 	TODO: check
 CVE-2018-16982 (Open Chinese Convert (OpenCC) 1.0.5 allows attackers to cause a denial ...)
-	TODO: check
+	NOT-FOR-US: Open Chinese Convert (OpenCC)
 CVE-2018-16981 (stb stb_image.h 2.19, as used in catimg, Emscripten, and other ...)
 	TODO: check
 CVE-2018-16980 (dotCMS V5.0.1 has XSS in the ...)
 	TODO: check
 CVE-2018-16979 (Monstra CMS V3.0.4 allows HTTP header injection in the ...)
-	TODO: check
+	NOT-FOR-US: Monstra CMS
 CVE-2018-16978 (Monstra CMS V3.0.4 has XSS when ones tries to register an account with ...)
-	TODO: check
+	NOT-FOR-US: Monstra CMS
 CVE-2018-16977 (Monstra CMS V3.0.4 has an information leakage risk (e.g., PATH, ...)
-	TODO: check
+	NOT-FOR-US: Monstra CMS
 CVE-2018-16975 (An issue was discovered in Elefant CMS before 2.0.7. There is a PHP ...)
-	TODO: check
+	NOT-FOR-US: Elefant CMS
 CVE-2018-16974 (An issue was discovered in Elefant CMS before 2.0.7. There is a PHP ...)
-	TODO: check
+	NOT-FOR-US: Elefant CMS
 CVE-2018-16973
 	RESERVED
 CVE-2018-16972
 	RESERVED
 CVE-2018-16971 (Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct ...)
-	TODO: check
+	NOT-FOR-US: Wisetail Learning Ecosystem
 CVE-2018-16970 (Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct ...)
-	TODO: check
+	NOT-FOR-US: Wisetail Learning Ecosystem
 CVE-2018-16969
 	RESERVED
 CVE-2018-16968
@@ -21575,7 +21575,7 @@ CVE-2018-8477
 CVE-2018-8476
 	RESERVED
 CVE-2018-8475 (A remote code execution vulnerability exists when Windows does not ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2018-8474 (A security feature bypass vulnerability exists when Lync for Mac 2011 ...)
 	TODO: check
 CVE-2018-8473
@@ -21585,43 +21585,43 @@ CVE-2018-8472
 CVE-2018-8471
 	RESERVED
 CVE-2018-8470 (A security feature bypass vulnerability exists in Internet Explorer ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2018-8469 (An elevation of privilege vulnerability exists in Microsoft Edge that ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2018-8468 (An elevation of privilege vulnerability exists when Windows, allowing ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2018-8467 (A remote code execution vulnerability exists in the way that the ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2018-8466 (A remote code execution vulnerability exists in the way that the ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2018-8465 (A remote code execution vulnerability exists in the way that the ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2018-8464 (An remote code execution vulnerability exists when Microsoft Edge PDF ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2018-8463 (An elevation of privilege vulnerability exists in Microsoft Edge that ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2018-8462 (An elevation of privilege vulnerability exists when the DirectX ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2018-8461 (A remote code execution vulnerability exists when Internet Explorer ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2018-8460
 	RESERVED
 CVE-2018-8459 (A remote code execution vulnerability exists in the way that the ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2018-8458
 	RESERVED
 CVE-2018-8457 (A remote code execution vulnerability exists in the way the scripting ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2018-8456 (A remote code execution vulnerability exists in the way that the ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2018-8455 (An elevation of privilege vulnerability exists in the way that the ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2018-8454
 	RESERVED
 CVE-2018-8453
 	RESERVED
 CVE-2018-8452 (An information disclosure vulnerability exists when the scripting ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2018-8451
 	RESERVED
 CVE-2018-8450



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/054edaabf21e1774d79e84bd9b4ed986dc85dd9b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/054edaabf21e1774d79e84bd9b4ed986dc85dd9b
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20180913/45a06868/attachment.html>


More information about the debian-security-tracker-commits mailing list