[Git][security-tracker-team/security-tracker][master] Process NFUs

Salvatore Bonaccorso carnil at debian.org
Wed Jun 5 21:24:44 BST 2019



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
13fcde40 by Salvatore Bonaccorso at 2019-06-05T20:24:11Z
Process NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2019-12743
 	RESERVED
 CVE-2019-12742 (Bludit prior to 3.9.1 allows a non-privileged user to change the passw ...)
-	TODO: check
+	NOT-FOR-US: bludit
 CVE-2019-12741 (XSS exists in the HAPI FHIR testpage overlay module of the HAPI FHIR l ...)
 	TODO: check
 CVE-2019-12740
@@ -37,7 +37,7 @@ CVE-2019-12729
 CVE-2019-12728 (Grails before 3.3.10 used cleartext HTTP to resolve the SDKMan notific ...)
 	TODO: check
 CVE-2019-12727 (On Ubiquiti airCam 3.1.4 devices, a Denial of Service vulnerability ex ...)
-	TODO: check
+	NOT-FOR-US: Ubiquiti airCam devices
 CVE-2019-12726
 	RESERVED
 CVE-2019-12725
@@ -411,17 +411,17 @@ CVE-2019-12545
 CVE-2019-12544
 	RESERVED
 CVE-2019-12543 (An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. The ...)
-	TODO: check
+	NOT-FOR-US: Zoho ManageEngine ServiceDesk
 CVE-2019-12542 (An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. The ...)
-	TODO: check
+	NOT-FOR-US: Zoho ManageEngine ServiceDesk
 CVE-2019-12541 (An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. The ...)
-	TODO: check
+	NOT-FOR-US: Zoho ManageEngine ServiceDesk
 CVE-2019-12540
 	RESERVED
 CVE-2019-12539
 	RESERVED
 CVE-2019-12538 (An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. The ...)
-	TODO: check
+	NOT-FOR-US: Zoho ManageEngine ServiceDesk
 CVE-2019-12537
 	RESERVED
 CVE-2019-12536
@@ -1278,7 +1278,7 @@ CVE-2019-12198 (In GoHttp through 2017-07-25, there is a stack-based buffer over
 CVE-2019-12197
 	RESERVED
 CVE-2019-12196 (A SQL injection vulnerability in /client/api/json/v2/nfareports/compar ...)
-	TODO: check
+	NOT-FOR-US: Zoho ManageEngine NetFlow Analyzer
 CVE-2019-12195 (TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name.  ...)
 	NOT-FOR-US: TP-Link
 CVE-2019-12194
@@ -1316,9 +1316,9 @@ CVE-2019-12179
 CVE-2019-12178
 	RESERVED
 CVE-2019-12177 (Privilege escalation due to insecure directory permissions affecting V ...)
-	TODO: check
+	NOT-FOR-US: HTC VIVEPORT
 CVE-2019-12176 (Privilege escalation in the "HTC Account Service" and "ViveportDesktop ...)
-	TODO: check
+	NOT-FOR-US: HTC VIVEPORT
 CVE-2019-12175
 	RESERVED
 CVE-2019-12174
@@ -1729,101 +1729,101 @@ CVE-2019-11990
 CVE-2019-11989
 	RESERVED
 CVE-2019-11988 (A Remote Unauthorized Access vulnerability was identified in HPE Smart ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11987 (A security vulnerability in HPE Smart Update Manager (SUM) prior to v8 ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11986 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11985 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11984 (A SQL injection code execution vulnerability was identified in HPE Int ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11983 (A remote buffer overflow vulnerability was identified in HPE Integrate ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11982 (A remote cross site scripting vulnerability was identified in HPE Inte ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11981
 	RESERVED
 CVE-2019-11980 (A remote code exection vulnerability was identified in HPE Intelligent ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11979 (A SQL injection code execution vulnerability was identified in HPE Int ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11978 (A SQL injection code execution vulnerability was identified in HPE Int ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11977 (A SQL injection code execution vulnerability was identified in HPE Int ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11976 (A SQL injection code execution vulnerability was identified in HPE Int ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11975 (A SQL injection code execution vulnerability was identified in HPE Int ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11974 (A SQL injection code execution vulnerability was identified in HPE Int ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11973 (A SQL injection code execution vulnerability was identified in HPE Int ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11972 (A SQL injection code execution vulnerability was identified in HPE Int ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11971 (A SQL injection code execution vulnerability was identified in HPE Int ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11970 (A SQL injection code execution vulnerability was identified in HPE Int ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11969 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11968 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11967 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11966 (A remote privilege escalation vulnerability was identified in HPE Inte ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11965 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11964 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11963 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11962 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11961 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11960 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11959 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11958 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11957 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11956 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11955 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11954 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11953 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11952 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11951 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11950 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11949 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11948 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11947 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11946 (A remote credential disclosure vulnerability was identified in HPE Int ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11945 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11944 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11943 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11942 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11941 (A remote code execution vulnerability was identified in HPE Intelligen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2019-11940
 	RESERVED
 CVE-2019-11939
@@ -3628,7 +3628,7 @@ CVE-2019-11228 (repo/setting.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 d
 CVE-2019-11227
 	RESERVED
 CVE-2019-11226 (CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Artic ...)
-	TODO: check
+	NOT-FOR-US: CMS Made Simple
 CVE-2019-11225
 	RESERVED
 CVE-2019-11224 (HARMAN AMX MVP5150 v2.87.13 devices allow remote OS Command Injection. ...)
@@ -5200,9 +5200,9 @@ CVE-2019-10639
 CVE-2019-10638
 	RESERVED
 CVE-2019-10637 (Marvell SSD Controller (88SS1074, 88SS1079, 88SS1080, 88SS1093, 88SS10 ...)
-	TODO: check
+	NOT-FOR-US: Marvell
 CVE-2019-10636 (Marvell SSD Controller (88SS1074, 88SS1079, 88SS1080, 88SS1093, 88SS10 ...)
-	TODO: check
+	NOT-FOR-US: Marvell
 CVE-2019-10635
 	RESERVED
 CVE-2019-10634 (An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allow ...)
@@ -8355,7 +8355,7 @@ CVE-2019-9649 (An issue was discovered in the SFTP Server component in Core FTP
 CVE-2019-9648 (An issue was discovered in the SFTP Server component in Core FTP 2.0 B ...)
 	NOT-FOR-US: Core FTP
 CVE-2019-9647 (Gila CMS 1.9.1 has XSS. ...)
-	TODO: check
+	NOT-FOR-US: Gila CMS
 CVE-2019-9645
 	RESERVED
 CVE-2019-9646 (The Contact Form Email plugin before 1.2.66 for WordPress allows wp-ad ...)
@@ -9496,7 +9496,7 @@ CVE-2019-9191 (The ETSI Enterprise Transport Security (ETS, formerly known as eT
 CVE-2019-9190
 	RESERVED
 CVE-2019-9189 (On Prima Systems FlexAir devices through 2.4.9api3, an authenticated u ...)
-	TODO: check
+	NOT-FOR-US: Prima Systems FlexAir devices
 CVE-2019-9188
 	RESERVED
 CVE-2019-9187 (ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190226  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/13fcde409f0a44df6fcbbbb31938bee21097ebba

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/13fcde409f0a44df6fcbbbb31938bee21097ebba
You're receiving this email because of your account on salsa.debian.org.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190605/81c78a21/attachment.html>


More information about the debian-security-tracker-commits mailing list