[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso
carnil at debian.org
Thu Sep 13 09:45:02 BST 2018
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
054edaab by Salvatore Bonaccorso at 2018-09-13T08:44:40Z
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,29 +1,29 @@
CVE-2018-16983 (NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other ...)
TODO: check
CVE-2018-16982 (Open Chinese Convert (OpenCC) 1.0.5 allows attackers to cause a denial ...)
- TODO: check
+ NOT-FOR-US: Open Chinese Convert (OpenCC)
CVE-2018-16981 (stb stb_image.h 2.19, as used in catimg, Emscripten, and other ...)
TODO: check
CVE-2018-16980 (dotCMS V5.0.1 has XSS in the ...)
TODO: check
CVE-2018-16979 (Monstra CMS V3.0.4 allows HTTP header injection in the ...)
- TODO: check
+ NOT-FOR-US: Monstra CMS
CVE-2018-16978 (Monstra CMS V3.0.4 has XSS when ones tries to register an account with ...)
- TODO: check
+ NOT-FOR-US: Monstra CMS
CVE-2018-16977 (Monstra CMS V3.0.4 has an information leakage risk (e.g., PATH, ...)
- TODO: check
+ NOT-FOR-US: Monstra CMS
CVE-2018-16975 (An issue was discovered in Elefant CMS before 2.0.7. There is a PHP ...)
- TODO: check
+ NOT-FOR-US: Elefant CMS
CVE-2018-16974 (An issue was discovered in Elefant CMS before 2.0.7. There is a PHP ...)
- TODO: check
+ NOT-FOR-US: Elefant CMS
CVE-2018-16973
RESERVED
CVE-2018-16972
RESERVED
CVE-2018-16971 (Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct ...)
- TODO: check
+ NOT-FOR-US: Wisetail Learning Ecosystem
CVE-2018-16970 (Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct ...)
- TODO: check
+ NOT-FOR-US: Wisetail Learning Ecosystem
CVE-2018-16969
RESERVED
CVE-2018-16968
@@ -21575,7 +21575,7 @@ CVE-2018-8477
CVE-2018-8476
RESERVED
CVE-2018-8475 (A remote code execution vulnerability exists when Windows does not ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2018-8474 (A security feature bypass vulnerability exists when Lync for Mac 2011 ...)
TODO: check
CVE-2018-8473
@@ -21585,43 +21585,43 @@ CVE-2018-8472
CVE-2018-8471
RESERVED
CVE-2018-8470 (A security feature bypass vulnerability exists in Internet Explorer ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2018-8469 (An elevation of privilege vulnerability exists in Microsoft Edge that ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2018-8468 (An elevation of privilege vulnerability exists when Windows, allowing ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2018-8467 (A remote code execution vulnerability exists in the way that the ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2018-8466 (A remote code execution vulnerability exists in the way that the ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2018-8465 (A remote code execution vulnerability exists in the way that the ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2018-8464 (An remote code execution vulnerability exists when Microsoft Edge PDF ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2018-8463 (An elevation of privilege vulnerability exists in Microsoft Edge that ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2018-8462 (An elevation of privilege vulnerability exists when the DirectX ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2018-8461 (A remote code execution vulnerability exists when Internet Explorer ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2018-8460
RESERVED
CVE-2018-8459 (A remote code execution vulnerability exists in the way that the ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2018-8458
RESERVED
CVE-2018-8457 (A remote code execution vulnerability exists in the way the scripting ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2018-8456 (A remote code execution vulnerability exists in the way that the ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2018-8455 (An elevation of privilege vulnerability exists in the way that the ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2018-8454
RESERVED
CVE-2018-8453
RESERVED
CVE-2018-8452 (An information disclosure vulnerability exists when the scripting ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2018-8451
RESERVED
CVE-2018-8450
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/054edaabf21e1774d79e84bd9b4ed986dc85dd9b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/054edaabf21e1774d79e84bd9b4ed986dc85dd9b
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20180913/45a06868/attachment.html>
More information about the debian-security-tracker-commits
mailing list