[Git][security-tracker-team/security-tracker][master] Process several NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Dec 1 20:48:00 GMT 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d454788b by Salvatore Bonaccorso at 2022-12-01T21:44:26+01:00
Process several NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -107,7 +107,7 @@ CVE-2022-4259
 CVE-2022-4258
 	RESERVED
 CVE-2022-4257 (A vulnerability was found in C-DATA Web Management System. It has been ...)
-	TODO: check
+	NOT-FOR-US: C-DATA Web Management System
 CVE-2022-4256
 	RESERVED
 CVE-2022-4255
@@ -115,19 +115,19 @@ CVE-2022-4255
 CVE-2022-4254
 	RESERVED
 CVE-2022-4253 (A vulnerability was found in SourceCodester Canteen Management System. ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester Canteen Management System
 CVE-2022-4252 (A vulnerability was found in SourceCodester Canteen Management System. ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester Canteen Management System
 CVE-2022-4251 (A vulnerability was found in Movie Ticket Booking System and classifie ...)
-	TODO: check
+	NOT-FOR-US: Movie Ticket Booking System
 CVE-2022-4250 (A vulnerability has been found in Movie Ticket Booking System and clas ...)
-	TODO: check
+	NOT-FOR-US: Movie Ticket Booking System
 CVE-2022-4249 (A vulnerability, which was classified as problematic, was found in Mov ...)
-	TODO: check
+	NOT-FOR-US: Movie Ticket Booking System
 CVE-2022-4248 (A vulnerability, which was classified as critical, has been found in M ...)
-	TODO: check
+	NOT-FOR-US: Movie Ticket Booking System
 CVE-2022-4247 (A vulnerability classified as critical was found in Movie Ticket Booki ...)
-	TODO: check
+	NOT-FOR-US: Movie Ticket Booking System
 CVE-2022-4246 (A vulnerability classified as problematic has been found in Kakao PotP ...)
 	TODO: check
 CVE-2022-46361
@@ -227,7 +227,7 @@ CVE-2022-4223
 CVE-2022-4222 (A vulnerability was found in SourceCodester Canteen Management System. ...)
 	NOT-FOR-US: SourceCodester Canteen Management System
 CVE-2022-4221 (Improper Neutralization of Special Elements used in an OS Command ('OS ...)
-	TODO: check
+	NOT-FOR-US: Asus NAS-M25
 CVE-2022-4220
 	RESERVED
 CVE-2022-4219
@@ -1614,7 +1614,7 @@ CVE-2021-46854 (mod_radius in ProFTPD before 1.3.7c allows memory disclosure to
 	NOTE: Fixed by: https://github.com/proftpd/proftpd/commit/10a227b4d50e0a2cd2faf87926f58d865da44e43 (v1.3.8rc2)
 	NOTE: Fixed by: https://github.com/proftpd/proftpd/commit/e7c0b6e78a81fa97ec41ea6332e5e11b864089b8 (v1.3.7c)
 CVE-2022-45797 (An arbitrary file deletion vulnerability in the Damage Cleanup Engine  ...)
-	TODO: check
+	NOT-FOR-US: Trend Micro
 CVE-2022-45796
 	RESERVED
 CVE-2022-45795
@@ -3961,7 +3961,7 @@ CVE-2022-45052
 CVE-2022-45051
 	RESERVED
 CVE-2022-45050 (A reflected XSS vulnerability has been found in Axiell Iguana CMS, all ...)
-	TODO: check
+	NOT-FOR-US: Axiell Iguana CMS
 CVE-2022-45049
 	RESERVED
 CVE-2022-45048
@@ -7490,7 +7490,7 @@ CVE-2022-44039
 CVE-2022-44038 (Russound XSourcePlayer 777D v06.08.03 was discovered to contain a remo ...)
 	NOT-FOR-US: Russound XSourcePlayer 777D
 CVE-2022-44037 (An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) ...)
-	TODO: check
+	NOT-FOR-US: APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software
 CVE-2022-44036
 	RESERVED
 CVE-2022-44035
@@ -9531,15 +9531,15 @@ CVE-2022-43934
 CVE-2022-43933
 	RESERVED
 CVE-2022-3713 (A code injection vulnerability allows adjacent attackers to execute co ...)
-	TODO: check
+	NOT-FOR-US: Sophos
 CVE-2022-3712
 	RESERVED
 CVE-2022-3711 (A post-auth read-only SQL injection vulnerability allows users to read ...)
-	TODO: check
+	NOT-FOR-US: Sophos
 CVE-2022-3710 (A post-auth read-only SQL injection vulnerability allows API clients t ...)
-	TODO: check
+	NOT-FOR-US: Sophos
 CVE-2022-3709 (A stored XSS vulnerability allows admin to super-admin privilege escal ...)
-	TODO: check
+	NOT-FOR-US: Sophos
 CVE-2022-3708 (The Web Stories plugin for WordPress is vulnerable to Server-Side Requ ...)
 	NOT-FOR-US: Web Stories plugin for WordPress
 CVE-2022-3707
@@ -9612,9 +9612,9 @@ CVE-2022-43903
 CVE-2022-43902
 	RESERVED
 CVE-2022-43901 (IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 coul ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-43900 (IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 coul ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-43899
 	RESERVED
 CVE-2022-43898
@@ -9919,7 +9919,7 @@ CVE-2022-3697 (A flaw was found in Ansible in the amazon.aws collection when usi
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2137664
 	NOTE: https://github.com/ansible-collections/amazon.aws/pull/1199
 CVE-2022-3696 (A post-auth code injection vulnerability allows admins to execute code ...)
-	TODO: check
+	NOT-FOR-US: Sophos
 CVE-2022-3695
 	RESERVED
 CVE-2022-3694
@@ -10424,11 +10424,11 @@ CVE-2022-43592
 CVE-2022-43591
 	RESERVED
 CVE-2022-43590 (A null pointer dereference vulnerability exists in the handle_ioctl_0x ...)
-	TODO: check
+	NOT-FOR-US: Callback technologies CBFS Filter
 CVE-2022-43589 (A null pointer dereference vulnerability exists in the handle_ioctl_83 ...)
-	TODO: check
+	NOT-FOR-US: Callback technologies CBFS Filter
 CVE-2022-43588 (A null pointer dereference vulnerability exists in the handle_ioctl_83 ...)
-	TODO: check
+	NOT-FOR-US: Callback technologies CBFS Filter
 CVE-2022-43587
 	RESERVED
 CVE-2022-43586
@@ -11208,7 +11208,7 @@ CVE-2022-43328 (Canteen Management System v1.0 was discovered to contain a SQL i
 CVE-2022-43327
 	RESERVED
 CVE-2022-43326 (An Insecure Direct Object Reference (IDOR) vulnerability in the passwo ...)
-	TODO: check
+	NOT-FOR-US: Telos Alliance Omnia MPX Node
 CVE-2022-43325
 	RESERVED
 CVE-2022-43324
@@ -15164,7 +15164,7 @@ CVE-2022-40965 (The affected product DIAEnergie (versions prior to v1.9.01.002)
 CVE-2022-40703 (CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Ka ...)
 	NOT-FOR-US: AliveCor Kardia App
 CVE-2022-40204 (A cross-site scripting (XSS) vulnerability exists in all current versi ...)
-	TODO: check
+	NOT-FOR-US: Digital Alert Systems DASDEC software
 CVE-2022-40202 (The database backup function in Delta Electronics InfraSuite Device Ma ...)
 	NOT-FOR-US: Delta Electronics
 CVE-2022-40201
@@ -15437,9 +15437,9 @@ CVE-2022-3348 (Just like in the previous report, an attacker could steal the acc
 CVE-2021-46841
 	RESERVED
 CVE-2022-41676 (Raiden MAILD Mail Server website mail field has insufficient filtering ...)
-	TODO: check
+	NOT-FOR-US: Raiden MAILD Mail Server
 CVE-2022-41675 (A remote attacker with general user privilege can inject malicious cod ...)
-	TODO: check
+	NOT-FOR-US: Raiden MAILD Mail Server
 CVE-2022-41674 (An issue was discovered in the Linux kernel before 5.19.16. Attackers  ...)
 	{DSA-5257-1 DLA-3173-1}
 	- linux 6.0.2-1
@@ -16444,7 +16444,7 @@ CVE-2022-3272 (Improper Handling of Length Parameter Inconsistency in GitHub rep
 CVE-2022-3271
 	RESERVED
 CVE-2022-3270 (In multiple products by Festo a remote unauthenticated attacker could  ...)
-	TODO: check
+	NOT-FOR-US: Festo
 CVE-2022-3269 (Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7. ...)
 	- rdiffweb <itp> (bug #969974)
 CVE-2022-3268 (Weak Password Requirements in GitHub repository ikus060/minarca prior  ...)
@@ -16515,7 +16515,7 @@ CVE-2022-41299
 CVE-2022-41298
 	RESERVED
 CVE-2022-41297 (IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-41296
 	RESERVED
 CVE-2022-41295
@@ -17519,7 +17519,7 @@ CVE-2022-40851 (Tenda AC15 V15.03.05.19 contained a stack overflow via the funct
 CVE-2022-40850
 	RESERVED
 CVE-2022-40849 (ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS ...)
-	TODO: check
+	NOT-FOR-US: ThinkCMF
 CVE-2022-40848
 	RESERVED
 CVE-2022-40847 (In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a  ...)
@@ -17773,7 +17773,7 @@ CVE-2022-40739 (Ragic report generation page has insufficient filtering for spec
 CVE-2022-3227
 	RESERVED
 CVE-2022-3226 (An OS command injection vulnerability allows admins to execute code vi ...)
-	TODO: check
+	NOT-FOR-US: Sophos
 CVE-2022-3225 (Improper Access Control in GitHub repository budibase/budibase prior t ...)
 	NOT-FOR-US: budibase
 CVE-2022-3224 (Misinterpretation of Input in GitHub repository ionicabizau/parse-url  ...)
@@ -18457,7 +18457,7 @@ CVE-2022-40491
 CVE-2022-40490
 	RESERVED
 CVE-2022-40489 (ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CS ...)
-	TODO: check
+	NOT-FOR-US: ThinkCMF
 CVE-2022-40488 (ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Fo ...)
 	NOT-FOR-US: ProcessWire
 CVE-2022-40487 (ProcessWire v3.0.200 was discovered to contain multiple cross-site scr ...)
@@ -21608,7 +21608,7 @@ CVE-2022-3090 (Red Lion Controls Crimson 3.0 versions 707.000 and prior, Crimson
 CVE-2022-3089
 	RESERVED
 CVE-2022-3088 (UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Imag ...)
-	TODO: check
+	NOT-FOR-US: Moxa
 CVE-2022-3087
 	RESERVED
 CVE-2022-3086
@@ -22554,11 +22554,11 @@ CVE-2022-38805
 CVE-2022-38804
 	RESERVED
 CVE-2022-38803 (Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrec ...)
-	TODO: check
+	NOT-FOR-US: Zkteco BioTime
 CVE-2022-38802 (Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrec ...)
-	TODO: check
+	NOT-FOR-US: Zkteco BioTime
 CVE-2022-38801 (In Zkteco BioTime < 8.5.3 Build:20200816.447, an employee can hijac ...)
-	TODO: check
+	NOT-FOR-US: Zkteco BioTime
 CVE-2022-38800
 	RESERVED
 CVE-2022-38799
@@ -23004,7 +23004,7 @@ CVE-2022-2971 (MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5
 CVE-2022-2970 (MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior ...)
 	NOT-FOR-US: libIEC61850
 CVE-2022-2969 (Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4  ...)
-	TODO: check
+	NOT-FOR-US: Delta Industrial Automation DIALink
 CVE-2022-2968
 	RESERVED
 CVE-2022-2967
@@ -25346,7 +25346,7 @@ CVE-2022-37934
 CVE-2022-37933
 	RESERVED
 CVE-2022-37932 (A potential security vulnerability has been identified in Hewlett Pack ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2022-37931 (A vulnerability in NetBatch-Plus software allows unauthorized access t ...)
 	NOT-FOR-US: HPE
 CVE-2022-37930 (A security vulnerability has been identified in HPE Nimble Storage Hyb ...)
@@ -25358,21 +25358,21 @@ CVE-2022-37928 (Insufficient Verification of Data Authenticity vulnerability in
 CVE-2022-37927 (URL Redirection to Untrusted Site ('Open Redirect') vulnerability in H ...)
 	NOT-FOR-US: HPE
 CVE-2022-37926 (A vulnerability within the web-based management interface of EdgeConne ...)
-	TODO: check
+	NOT-FOR-US: Aruba
 CVE-2022-37925 (A vulnerability within the web-based management interface of Aruba Edg ...)
-	TODO: check
+	NOT-FOR-US: Aruba
 CVE-2022-37924 (Vulnerabilities in the Aruba EdgeConnect Enterprise command line inter ...)
-	TODO: check
+	NOT-FOR-US: Aruba
 CVE-2022-37923 (Vulnerabilities in the Aruba EdgeConnect Enterprise command line inter ...)
-	TODO: check
+	NOT-FOR-US: Aruba
 CVE-2022-37922 (Vulnerabilities in the Aruba EdgeConnect Enterprise command line inter ...)
-	TODO: check
+	NOT-FOR-US: Aruba
 CVE-2022-37921 (Vulnerabilities in the Aruba EdgeConnect Enterprise command line inter ...)
-	TODO: check
+	NOT-FOR-US: Aruba
 CVE-2022-37920 (Vulnerabilities in the Aruba EdgeConnect Enterprise command line inter ...)
-	TODO: check
+	NOT-FOR-US: Aruba
 CVE-2022-37919 (A vulnerability exists in the API of Aruba EdgeConnect Enterprise. An  ...)
-	TODO: check
+	NOT-FOR-US: Aruba
 CVE-2022-37918
 	RESERVED
 CVE-2022-37917
@@ -27797,9 +27797,9 @@ CVE-2022-37019
 CVE-2022-37018 (A potential vulnerability has been identified in the system BIOS for c ...)
 	NOT-FOR-US: HPE
 CVE-2022-37017 (Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 R ...)
-	TODO: check
+	NOT-FOR-US: Symantec Endpoint Protection (Windows) agent
 CVE-2022-37016 (Symantec Endpoint Protection (Windows) agent may be susceptible to a P ...)
-	TODO: check
+	NOT-FOR-US: Symantec Endpoint Protection (Windows) agent
 CVE-2022-37015 (Symantec Endpoint Detection and Response (SEDR) Appliance, prior to 4. ...)
 	NOT-FOR-US: Symantec Endpoint Detection and Response (SEDR) Appliance
 CVE-2022-37014
@@ -27933,15 +27933,15 @@ CVE-2022-36966 (Users with Node Management rights were able to view and edit all
 CVE-2022-36965 (Insufficient sanitization of inputs in QoE application input field cou ...)
 	NOT-FOR-US: Solarwinds
 CVE-2022-36964 (SolarWinds Platform was susceptible to the Deserialization of Untruste ...)
-	TODO: check
+	NOT-FOR-US: SolarWinds
 CVE-2022-36963
 	RESERVED
 CVE-2022-36962 (SolarWinds Platform was susceptible to Command Injection. This vulnera ...)
-	TODO: check
+	NOT-FOR-US: SolarWinds
 CVE-2022-36961 (A vulnerable component of Orion Platform was vulnerable to SQL Injecti ...)
 	NOT-FOR-US: Solarwinds
 CVE-2022-36960 (SolarWinds Platform was susceptible to Improper Input Validation. This ...)
-	TODO: check
+	NOT-FOR-US: SolarWinds
 CVE-2022-36959
 	RESERVED
 CVE-2022-36958 (SolarWinds Platform was susceptible to the Deserialization of Untruste ...)
@@ -29091,11 +29091,11 @@ CVE-2022-36435
 CVE-2022-36434
 	RESERVED
 CVE-2022-36433 (The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plu ...)
-	TODO: check
+	NOT-FOR-US: Amasty Blog Pro
 CVE-2022-36432 (The Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Mag ...)
 	NOT-FOR-US: Amasty Blog Pro plugin for Magento
 CVE-2022-36431 (An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise  ...)
-	TODO: check
+	NOT-FOR-US: Rocket TRUfusion Enterprise
 CVE-2022-36430
 	RESERVED
 CVE-2022-2527 (An issue in Incident Timelines has been discovered in GitLab CE/EE aff ...)
@@ -30017,9 +30017,9 @@ CVE-2022-36139 (SWFMill commit 53d7690 was discovered to contain a heap-buffer o
 CVE-2022-36138
 	RESERVED
 CVE-2022-36137 (ChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers t ...)
-	TODO: check
+	NOT-FOR-US: ChurchCRM
 CVE-2022-36136 (ChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers t ...)
-	TODO: check
+	NOT-FOR-US: ChurchCRM
 CVE-2022-36135
 	RESERVED
 CVE-2022-36134
@@ -33515,7 +33515,7 @@ CVE-2022-34837 (Storing Passwords in a Recoverable Format vulnerability in ABB Z
 CVE-2022-34836 (Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the use ...)
 	NOT-FOR-US: ABB Zenon
 CVE-2022-34654 (Cross-Site Request Forgery (CSRF) in Virgial Berveling's Manage Notifi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-34650 (Multiple Authenticated (contributor or higher user role) Stored Cross- ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-34487 (Unauthenticated Arbitrary Option Update vulnerability in biplob018's S ...)
@@ -33563,7 +33563,7 @@ CVE-2022-29489 (Cross-Site Request Forgery (CSRF) vulnerability in Sucuri Securi
 CVE-2022-27235 (Multiple Broken Access Control vulnerabilities in Social Share Buttons ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-26366 (Cross-Site Request Forgery (CSRF) in AdRotate Banner Manager Plugin &l ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-25952 (Cross-Site Request Forgery (CSRF) vulnerability in Keywordrush Content ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-2276 (The WP Edit Menu WordPress plugin before 1.5.0 does not have authorisa ...)
@@ -41401,7 +41401,7 @@ CVE-2022-31879 (Online Fire Reporting System 1.0 is vulnerable to SQL Injection
 CVE-2022-31878
 	RESERVED
 CVE-2022-31877 (An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41 ...)
-	TODO: check
+	NOT-FOR-US: MSI Center
 CVE-2022-31876 (netgear wnap320 router WNAP320_V2.0.3_firmware is vulnerable to Incorr ...)
 	NOT-FOR-US: Netgear
 CVE-2022-31875 (Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an xss vulnera ...)
@@ -41813,7 +41813,7 @@ CVE-2022-1913 (The Add Post URL WordPress plugin through 2.1.0 does not have CSR
 CVE-2022-1912 (The Button Widget Smartsoft plugin for WordPress is vulnerable to Cros ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-1911 (Error in parser function in M-Files Server versions before 22.6.11534. ...)
-	TODO: check
+	NOT-FOR-US: M-Files Server
 CVE-2022-1910 (The Shortcodes and extra features for Phlox WordPress plugin before 2. ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-1909 (Cross-site Scripting (XSS) - Stored in GitHub repository causefx/organ ...)
@@ -46324,7 +46324,7 @@ CVE-2022-1608 (The OnePress Social Locker WordPress plugin through 5.6.2 does no
 CVE-2022-1607
 	RESERVED
 CVE-2022-1606 (Incorrect privilege assignment in M-Files Server versions before 22.3. ...)
-	TODO: check
+	NOT-FOR-US: M-Files Server
 CVE-2022-1605 (The Email Users WordPress plugin through 4.8.8 does not have CSRF chec ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-1604 (The MailerLite WordPress plugin before 1.5.4 does not sanitise and esc ...)
@@ -47672,7 +47672,7 @@ CVE-2022-29839
 CVE-2022-29838
 	RESERVED
 CVE-2022-29837 (A path traversal vulnerability was addressed in Western Digital My Clo ...)
-	TODO: check
+	NOT-FOR-US: Western Digital
 CVE-2022-29836 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
 	NOT-FOR-US: Western Digital
 CVE-2022-29835 (WD Discovery software executable files were signed with an unsafe SHA- ...)
@@ -64502,13 +64502,13 @@ CVE-2022-24191 (In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function
 	NOTE: https://github.com/michaelrsweet/htmldoc/issues/470
 	NOTE: Hang in CLI tool, no security impact
 CVE-2022-24190 (The /device/acceptBind end-point for Ourphoto App version 1.4.1 does n ...)
-	TODO: check
+	NOT-FOR-US: Ourphoto App
 CVE-2022-24189 (The user_token authorization header on the Ourphoto App version 1.4.1  ...)
-	TODO: check
+	NOT-FOR-US: Ourphoto App
 CVE-2022-24188 (The /device/signin end-point for the Ourphoto App version 1.4.1 disclo ...)
-	TODO: check
+	NOT-FOR-US: Ourphoto App
 CVE-2022-24187 (The user_id and device_id on the Ourphoto App version 1.4.1 /device/*  ...)
-	TODO: check
+	NOT-FOR-US: Ourphoto App
 CVE-2022-24186
 	RESERVED
 CVE-2022-24185
@@ -75672,7 +75672,7 @@ CVE-2021-45038 (An issue was discovered in MediaWiki before 1.35.5, 1.36.x befor
 CVE-2021-45037
 	RESERVED
 CVE-2021-45036 (Velneo vClient on its 28.1.3 version, could allow an attacker with kno ...)
-	TODO: check
+	NOT-FOR-US: Velneo vClient
 CVE-2021-45035 (Velneo vClient on its 28.1.3 version, does not correctly check the cer ...)
 	NOT-FOR-US: Velneo vClient
 CVE-2021-45034 (A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O  ...)
@@ -113957,7 +113957,7 @@ CVE-2021-31742
 CVE-2021-31741
 	RESERVED
 CVE-2021-31740 (SEPPMail's web frontend, user input is not embedded correctly in the w ...)
-	TODO: check
+	NOT-FOR-US: SEPPMail
 CVE-2021-31739 (The SEPPmail solution is vulnerable to a Cross-Site Scripting vulnerab ...)
 	NOT-FOR-US: SEPPmail
 CVE-2021-31738 (Adiscon LogAnalyzer 4.1.10 and 4.1.11 allow login.php XSS. ...)
@@ -228128,7 +228128,7 @@ CVE-2019-18267 (An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S
 CVE-2019-18266
 	RESERVED
 CVE-2019-18265 (Digital Alert Systems’ DASDEC software prior to version 4.1 cont ...)
-	TODO: check
+	NOT-FOR-US: Digital Alert Systems
 CVE-2019-18264
 	RESERVED
 CVE-2019-18263 (An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d454788bb70435a7c57d8c87e98b13c4facec6e0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d454788bb70435a7c57d8c87e98b13c4facec6e0
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20221201/52e6b271/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list