[Git][security-tracker-team/security-tracker][master] Process NFUs

Salvatore Bonaccorso carnil at debian.org
Fri Jul 24 12:55:14 BST 2020



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8057786b by Salvatore Bonaccorso at 2020-07-24T13:53:49+02:00
Process NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -15,19 +15,19 @@ CVE-2020-15926
 CVE-2020-15925
 	RESERVED
 CVE-2020-15924 (There is a SQL Injection in Mida eFramework through 2.9.0 that leads t ...)
-	TODO: check
+	NOT-FOR-US: Mida eFramework
 CVE-2020-15923 (Mida eFramework through 2.9.0 allows unauthenticated ../ directory tra ...)
-	TODO: check
+	NOT-FOR-US: Mida eFramework
 CVE-2020-15922 (There is an OS Command Injection in Mida eFramework 2.9.0 that allows  ...)
-	TODO: check
+	NOT-FOR-US: Mida eFramework
 CVE-2020-15921 (Mida eFramework through 2.9.0 has a back door that permits a change of ...)
-	TODO: check
+	NOT-FOR-US: Mida eFramework
 CVE-2020-15920 (There is an OS Command Injection in Mida eFramework through 2.9.0 that ...)
-	TODO: check
+	NOT-FOR-US: Mida eFramework
 CVE-2020-15919 (A Reflected Cross Site Scripting (XSS) vulnerability was discovered in ...)
-	TODO: check
+	NOT-FOR-US: Mida eFramework
 CVE-2020-15918 (Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discov ...)
-	TODO: check
+	NOT-FOR-US: Mida eFramework
 CVE-2020-15917 (common/session.c in Claws Mail before 3.17.6 has a protocol violation  ...)
 	- claws-mail 3.17.6-1
 	NOTE: https://git.claws-mail.org/?p=claws.git;a=commit;h=fcc25329049b6f9bd8d890f1197ed61eb12e14d5
@@ -60,9 +60,9 @@ CVE-2020-15904 (A buffer overflow in the patching routine of bsdiff4 before 1.2.
 CVE-2020-15903
 	RESERVED
 CVE-2020-15902 (Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url o ...)
-	TODO: check
+	NOT-FOR-US: Nagios XI
 CVE-2020-15901 (ajaxhelper.php in Nagios XI before 5.7.2 allows remote attackers to ex ...)
-	TODO: check
+	NOT-FOR-US: Nagios XI
 CVE-2020-15900
 	RESERVED
 CVE-2020-15899
@@ -91,19 +91,19 @@ CVE-2020-15889 (Lua through 5.4.0 has a getobjname heap-based buffer over-read b
 CVE-2020-15888 (Lua through 5.4.0 mishandles the interaction between stack resizes and ...)
 	TODO: check
 CVE-2020-15887 (A SQL injection vulnerability in softwareupdate_controller.php in the  ...)
-	TODO: check
+	NOT-FOR-US: MunkiReport
 CVE-2020-15886 (A SQL injection vulnerability in reportdata_controller.php in the repo ...)
-	TODO: check
+	NOT-FOR-US: MunkiReport
 CVE-2020-15885 (A Cross-Site Scripting (XSS) vulnerability in the comment module befor ...)
-	TODO: check
+	NOT-FOR-US: MunkiReport
 CVE-2020-15884 (A SQL injection vulnerability in TableQuery.php in MunkiReport before  ...)
-	TODO: check
+	NOT-FOR-US: MunkiReport
 CVE-2020-15883 (A Cross-Site Scripting (XSS) vulnerability in the managedinstalls modu ...)
-	TODO: check
+	NOT-FOR-US: MunkiReport
 CVE-2020-15882 (A CSRF issue in manager/delete_machine/{id} in MunkiReport before 5.6. ...)
-	TODO: check
+	NOT-FOR-US: MunkiReport
 CVE-2020-15881 (A Cross-Site Scripting (XSS) vulnerability in the munki_facts (aka Mun ...)
-	TODO: check
+	NOT-FOR-US: MunkiReport
 CVE-2020-15880
 	RESERVED
 CVE-2020-15879 (Bitwarden Server 1.35.1 allows SSRF because it does not consider certa ...)
@@ -672,11 +672,11 @@ CVE-2020-15635
 CVE-2020-15634
 	RESERVED
 CVE-2020-15633 (This vulnerability allows network-adjacent attackers to bypass authent ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2020-15632 (This vulnerability allows network-adjacent attackers to bypass authent ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2020-15631 (This vulnerability allows network-adjacent attackers to execute arbitr ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2020-15630
 	RESERVED
 CVE-2020-15629
@@ -4245,7 +4245,7 @@ CVE-2020-14177
 CVE-2020-14176
 	RESERVED
 CVE-2020-14175 (Affected versions of Atlassian Confluence Server and Data Center allow ...)
-	TODO: check
+	NOT-FOR-US: Atlassian
 CVE-2020-14174 (Affected versions of Atlassian Jira Server and Data Center allow remot ...)
 	NOT-FOR-US: Atlassian
 CVE-2020-14173 (The file upload feature in Atlassian Jira Server and Data Center in af ...)
@@ -16982,33 +16982,33 @@ CVE-2020-9689
 CVE-2020-9688 (Adobe Download Manager version 2.0.0.518 have a command injection vuln ...)
 	NOT-FOR-US: Adobe
 CVE-2020-9687 (Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2020-9686 (Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2020-9685 (Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2020-9684 (Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2020-9683 (Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2020-9682 (Adobe Creative Cloud Desktop Application versions 5.1 and earlier have ...)
 	NOT-FOR-US: Adobe
 CVE-2020-9681
 	RESERVED
 CVE-2020-9680 (Adobe Prelude versions 9.0 and earlier have an out-of-bounds write vul ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2020-9679 (Adobe Prelude versions 9.0 and earlier have an out-of-bounds read vuln ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2020-9678 (Adobe Prelude versions 9.0 and earlier have an out-of-bounds write vul ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2020-9677 (Adobe Prelude versions 9.0 and earlier have an out-of-bounds read vuln ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2020-9676 (Adobe Bridge versions 10.0.3 and earlier have an out-of-bounds write v ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2020-9675 (Adobe Bridge versions 10.0.3 and earlier have an out-of-bounds read vu ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2020-9674 (Adobe Bridge versions 10.0.3 and earlier have an out-of-bounds write v ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2020-9673 (Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2 ...)
 	NOT-FOR-US: Adobe
 CVE-2020-9672 (Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2 ...)
@@ -17026,11 +17026,11 @@ CVE-2020-9667
 CVE-2020-9666 (Adobe Campaign Classic before 20.2 have an out-of-bounds read vulnerab ...)
 	NOT-FOR-US: Adobe
 CVE-2020-9665 (Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a  ...)
-	TODO: check
+	NOT-FOR-US: Magento
 CVE-2020-9664 (Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a  ...)
-	TODO: check
+	NOT-FOR-US: Magento
 CVE-2020-9663 (Adobe Reader Mobile versions 20.0.1 and earlier have a directory trave ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2020-9662 (Adobe After Effects versions 17.1 and earlier have an out-of-bounds wr ...)
 	NOT-FOR-US: Adobe
 CVE-2020-9661 (Adobe After Effects versions 17.1 and earlier have an out-of-bounds re ...)
@@ -39618,7 +39618,7 @@ CVE-2019-18835 (Matrix Synapse before 1.5.0 mishandles signature checking on som
 	NOTE: https://github.com/matrix-org/synapse/pull/6262
 	NOTE: https://github.com/matrix-org/synapse/releases/tag/v1.5.0
 CVE-2019-18834 (Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 fo ...)
-	TODO: check
+	NOT-FOR-US: WooCommerce Subscriptions plugin for WordPress
 CVE-2019-18833 (Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Informa ...)
 	NOT-FOR-US: Barco ClickShare Button R9861500D01 devices
 CVE-2019-18832 (Barco ClickShare Button R9861500D01 devices before 1.9.0 have incorrec ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8057786b98b8a0ff297eb19eb18aa27ce63d6455

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8057786b98b8a0ff297eb19eb18aa27ce63d6455
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200724/1e84c054/attachment.html>


More information about the debian-security-tracker-commits mailing list