[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 25 21:58:24 BST 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bbaa6690 by Salvatore Bonaccorso at 2022-08-25T22:57:40+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2076,7 +2076,7 @@ CVE-2022-36373
 CVE-2022-36365
 	RESERVED
 CVE-2022-36358 (Cross-Site Request Forgery (CSRF) vulnerability in SEO Scout plugin &l ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-36355
 	RESERVED
 CVE-2022-36352
@@ -2342,7 +2342,7 @@ CVE-2022-37954
 CVE-2022-37953 (An HTTP response splitting vulnerability exists in the AM Gateway Chal ...)
 	TODO: check
 CVE-2022-37952 (A reflected cross-site scripting (XSS) vulnerability exists in the iHi ...)
-	TODO: check
+	NOT-FOR-US: iHistorian Data Display of WorkstationST
 CVE-2022-37951
 	RESERVED
 CVE-2022-37950
@@ -4150,21 +4150,21 @@ CVE-2022-37247
 CVE-2022-37246
 	RESERVED
 CVE-2022-37245 (MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulner ...)
-	TODO: check
+	NOT-FOR-US: MDaemon
 CVE-2022-37244 (MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulner ...)
-	TODO: check
+	NOT-FOR-US: MDaemon
 CVE-2022-37243 (MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulner ...)
-	TODO: check
+	NOT-FOR-US: MDaemon
 CVE-2022-37242 (MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulne ...)
-	TODO: check
+	NOT-FOR-US: MDaemon
 CVE-2022-37241 (MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulner ...)
-	TODO: check
+	NOT-FOR-US: MDaemon
 CVE-2022-37240 (MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulner ...)
-	TODO: check
+	NOT-FOR-US: MDaemon
 CVE-2022-37239 (MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulner ...)
-	TODO: check
+	NOT-FOR-US: MDaemon
 CVE-2022-37238 (MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulner ...)
-	TODO: check
+	NOT-FOR-US: MDaemon
 CVE-2022-37237
 	RESERVED
 CVE-2022-37236
@@ -4316,15 +4316,15 @@ CVE-2022-37164
 CVE-2022-37163
 	RESERVED
 CVE-2022-37162 (Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) ...)
-	TODO: check
+	NOT-FOR-US: Claroline
 CVE-2022-37161 (Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) ...)
-	TODO: check
+	NOT-FOR-US: Claroline
 CVE-2022-37160 (Claroline 13.5.7 and prior allows an authenticated attacker to elevate ...)
-	TODO: check
+	NOT-FOR-US: Claroline
 CVE-2022-37159 (Claroline 13.5.7 and prior is vulnerable to Remote code execution via  ...)
-	TODO: check
+	NOT-FOR-US: Claroline
 CVE-2022-37158 (RuoYi v3.8.3 has a Weak password vulnerability in the management syste ...)
-	TODO: check
+	NOT-FOR-US: RuoYi
 CVE-2022-37157
 	RESERVED
 CVE-2022-37156
@@ -4440,75 +4440,75 @@ CVE-2022-37102
 CVE-2022-37101
 	RESERVED
 CVE-2022-37100 (H3C H200 H200V100R004 was discovered to contain a stack overflow via t ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37099 (H3C H200 H200V100R004 was discovered to contain a stack overflow via t ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37098 (H3C H200 H200V100R004 was discovered to contain a stack overflow via t ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37097 (H3C H200 H200V100R004 was discovered to contain a stack overflow via t ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37096 (H3C H200 H200V100R004 was discovered to contain a stack overflow via t ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37095 (H3C H200 H200V100R004 was discovered to contain a stack overflow via t ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37094 (H3C H200 H200V100R004 was discovered to contain a stack overflow via t ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37093 (H3C H200 H200V100R004 was discovered to contain a stack overflow via t ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37092 (H3C H200 H200V100R004 was discovered to contain a stack overflow via t ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37091 (H3C H200 H200V100R004 was discovered to contain a stack overflow via t ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37090 (H3C H200 H200V100R004 was discovered to contain a stack overflow via t ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37089 (H3C H200 H200V100R004 was discovered to contain a stack overflow via t ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37088 (H3C H200 H200V100R004 was discovered to contain a stack overflow via t ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37087 (H3C H200 H200V100R004 was discovered to contain a stack overflow via t ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37086 (H3C H200 H200V100R004 was discovered to contain a stack overflow via t ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37085 (H3C H200 H200V100R004 was discovered to contain a stack overflow via t ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37084 (TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a sta ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-37083 (TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a com ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-37082 (TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a com ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-37081 (TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a com ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-37080 (TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a sta ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-37079 (TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a com ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-37078 (TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a com ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-37077 (TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a sta ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-37076 (TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a com ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-37075 (TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a sta ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-37074 (H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack over ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37073 (H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack over ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37072 (H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack over ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37071 (H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack over ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37070 (H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a command in ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37069 (H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack over ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37068 (H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack over ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37067 (H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack over ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37066 (H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack over ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-37065
 	RESERVED
 CVE-2022-37064
@@ -5818,137 +5818,137 @@ CVE-2022-36522
 CVE-2022-36521
 	RESERVED
 CVE-2022-36520 (H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack over ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36519 (H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack over ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36518 (H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack over ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36517 (H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack over ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36516 (H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack over ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36515 (H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack over ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36514 (H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack over ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36513 (H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack over ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36512
 	RESERVED
 CVE-2022-36511 (H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack over ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36510 (H3C GR2200 MiniGR1A0V100R014 was discovered to contain a command injec ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36509 (H3C GR3200 MiniGR1B0V100R014 was discovered to contain a command injec ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36508 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36507 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36506 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36505 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36504 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36503 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36502 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36501 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36500 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36499 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36498 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36497 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36496 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36495 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36494 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36493 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36492 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36491 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36490 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36489 (H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack ov ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36488 (TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a sta ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36487 (TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a com ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36486 (TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a com ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36485 (TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a com ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36484 (TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a sta ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36483 (TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a sta ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36482 (TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a com ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36481 (TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a com ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36480 (TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a sta ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36479 (TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a com ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36478 (H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow  ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36477 (H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow  ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36476
 	RESERVED
 CVE-2022-36475 (H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow  ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36474 (H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow  ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36473 (H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow  ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36472 (H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow  ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36471 (H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow  ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36470 (H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow  ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36469 (H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow  ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36468 (H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow  ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36467 (H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow  ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2022-36466 (TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a sta ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36465 (TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a sta ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36464 (TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a sta ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36463 (TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a sta ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36462 (TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a sta ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36461 (TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a com ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36460 (TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a com ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36459 (TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a com ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36458 (TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a com ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36457
 	RESERVED
 CVE-2022-36456 (TOTOLink A720R V4.1.5cu.532_B20210610 was discovered to contain a comm ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36455 (TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a co ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2022-36454
 	RESERVED
 CVE-2022-36453
@@ -6577,11 +6577,11 @@ CVE-2022-30535 (In versions 2.x before 2.3.0 and all versions of 1.x, An attacke
 CVE-2022-2466
 	RESERVED
 CVE-2022-2465 (Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6. ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2022-2464 (Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6. ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2022-2463 (Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6. ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2022-2462
 	RESERVED
 CVE-2022-2461



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bbaa6690fe68eeb67eb53f5ad1f8b2f036c7d67e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bbaa6690fe68eeb67eb53f5ad1f8b2f036c7d67e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220825/3c0749f1/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list