[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Dec 21 08:52:28 GMT 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
089c10fe by Salvatore Bonaccorso at 2022-12-21T09:51:47+01:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -645,7 +645,7 @@ CVE-2022-4621
 CVE-2022-4620
 	RESERVED
 CVE-2022-4619 (The Sidebar Widgets by CodeLights plugin for WordPress is vulnerable t ...)
-	TODO: check
+	NOT-FOR-US: Sidebar Widgets by CodeLights plugin for WordPress
 CVE-2022-4618
 	RESERVED
 CVE-2022-4617 (Cross-site Scripting (XSS) - Reflected in GitHub repository microweber ...)
@@ -4260,7 +4260,7 @@ CVE-2022-46773
 CVE-2022-46772
 	RESERVED
 CVE-2022-46771 (IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.18, 7.0.5.0 through 7 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-46770 (qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through  ...)
 	NOT-FOR-US: qubes-mirage-firewall
 CVE-2022-46769
@@ -4903,49 +4903,49 @@ CVE-2022-46553
 CVE-2022-46552
 	RESERVED
 CVE-2022-46551 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46550 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46549 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46548 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46547 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46546 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46545 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46544 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46543 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46542 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46541 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46540 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46539 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46538 (Tenda F1203 V2.0.1.6 was discovered to contain a command injection vul ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46537 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46536 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46535 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46534 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46533 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46532 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46531 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46530 (Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via t ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-46529
 	RESERVED
 CVE-2022-46528
@@ -7465,9 +7465,9 @@ CVE-2022-45668 (Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request For
 CVE-2022-45667 (Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery ( ...)
 	NOT-FOR-US: Tenda
 CVE-2022-45666 (Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow v ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-45665 (Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow v ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-45664 (Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow v ...)
 	NOT-FOR-US: Tenda
 CVE-2022-45663 (Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow v ...)
@@ -15219,7 +15219,7 @@ CVE-2022-43889
 CVE-2022-43888
 	RESERVED
 CVE-2022-43887 (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-43886
 	RESERVED
 CVE-2022-43885
@@ -15227,7 +15227,7 @@ CVE-2022-43885
 CVE-2022-43884
 	RESERVED
 CVE-2022-43883 (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-43882
 	RESERVED
 CVE-2022-43881
@@ -15243,13 +15243,13 @@ CVE-2022-43877
 CVE-2022-43876
 	RESERVED
 CVE-2022-43875 (IBM Financial Transaction Manager for SWIFT Services for Multiplatform ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-43874
 	RESERVED
 CVE-2022-43873
 	RESERVED
 CVE-2022-43872 (IBM Financial Transaction Manager 3.2.4 authorization checks are done  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-43871
 	RESERVED
 CVE-2022-43870
@@ -16666,7 +16666,7 @@ CVE-2022-43384
 CVE-2022-43383
 	RESERVED
 CVE-2022-43382 (IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a local user with eleva ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-43381
 	RESERVED
 CVE-2022-43380
@@ -23991,7 +23991,7 @@ CVE-2022-40609
 CVE-2022-40608 (IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File System ...)
 	NOT-FOR-US: IBM
 CVE-2022-40607 (IBM Spectrum Scale 5.1 could allow users with permissions to create po ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-3192
 	RESERVED
 CVE-2022-3191 (Insertion of Sensitive Information into Log File vulnerability in Hita ...)
@@ -27461,7 +27461,7 @@ CVE-2022-39168 (IBM Robotic Process Automation Clients are vulnerable to proxy c
 CVE-2022-39167
 	RESERVED
 CVE-2022-39166 (IBM Security Guardium 11.4 could allow a privileged user to obtain sen ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-39165
 	RESERVED
 CVE-2022-39164
@@ -27473,7 +27473,7 @@ CVE-2022-39162
 CVE-2022-39161
 	RESERVED
 CVE-2022-39160 (IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 is vulnerable to cross ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-3093
 	RESERVED
 CVE-2022-3092 (GE CIMPICITY versions 2022 and prior is vulnerable to an out-of-bounds ...)
@@ -28862,7 +28862,7 @@ CVE-2022-38710 ("IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose
 CVE-2022-38709 (IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 for Cloud Pa ...)
 	NOT-FOR-US: IBM
 CVE-2022-38708 (IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-38707
 	RESERVED
 CVE-2022-38706
@@ -29898,7 +29898,7 @@ CVE-2022-2872 (Unrestricted Upload of File with Dangerous Type in GitHub reposit
 CVE-2022-2871 (Cross-site Scripting (XSS) - Stored in GitHub repository notrinos/notr ...)
 	NOT-FOR-US: NotrinosERP
 CVE-2022-38391 (IBM Spectrum Control 5.4 uses weaker than expected cryptographic algor ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-38390 (Multiple IBM Business Automation Workflow versions are vulnerable to c ...)
 	NOT-FOR-US: IBM
 CVE-2022-38389



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/089c10fe551845cfe77965f44570d57d17cb8175

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/089c10fe551845cfe77965f44570d57d17cb8175
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20221221/66e3c607/attachment.htm>


More information about the debian-security-tracker-commits mailing list