[Git][security-tracker-team/security-tracker][master] Process NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jun 7 06:22:58 BST 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6c0255c2 by Salvatore Bonaccorso at 2022-06-07T07:22:36+02:00
Process NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -97,7 +97,7 @@ CVE-2022-1999
 CVE-2022-1998
 	RESERVED
 CVE-2022-1997 (Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacqu ...)
-	TODO: check
+	NOT-FOR-US: francoisjacquet/rosariosis
 CVE-2022-1996 (Authorization Bypass Through User-Controlled Key in GitHub repository  ...)
 	TODO: check
 CVE-2022-1995
@@ -435,7 +435,7 @@ CVE-2022-32293
 CVE-2022-32292
 	RESERVED
 CVE-2022-32291 (In Real Player through 20.1.0.312, attackers can execute arbitrary cod ...)
-	TODO: check
+	NOT-FOR-US: Real Player
 CVE-2022-32290
 	RESERVED
 CVE-2017-20040
@@ -2833,7 +2833,7 @@ CVE-2022-31495
 CVE-2022-31494
 	RESERVED
 CVE-2022-31493 (LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS. ...)
-	TODO: check
+	NOT-FOR-US: LibreHealth EHR Base
 CVE-2022-31492
 	RESERVED
 CVE-2022-31491
@@ -2847,21 +2847,21 @@ CVE-2022-31488 (Inout Blockchain AltExchanger 1.2.1 allows index.php/coins/updat
 CVE-2022-31487 (Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger ...)
 	NOT-FOR-US: Inout Blockchain AltExchanger
 CVE-2022-31486 (An authenticated attacker can send a specially crafted route to the &# ...)
-	TODO: check
+	NOT-FOR-US: HID Mercury Intelligent Controllers
 CVE-2022-31485 (An unauthenticated attacker can send a specially crafted packets to up ...)
-	TODO: check
+	NOT-FOR-US: HID Mercury Intelligent Controllers
 CVE-2022-31484 (An unauthenticated attacker can send a specially crafted network packe ...)
-	TODO: check
+	NOT-FOR-US: HID Mercury Intelligent Controllers
 CVE-2022-31483 (An authenticated attacker can upload a file with a filename including  ...)
-	TODO: check
+	NOT-FOR-US: HID Mercury Intelligent Controllers
 CVE-2022-31482 (An unauthenticated attacker can send a specially crafted unauthenticat ...)
-	TODO: check
+	NOT-FOR-US: HID Mercury Intelligent Controllers
 CVE-2022-31481 (An unauthenticated attacker can send a specially crafted update file t ...)
-	TODO: check
+	NOT-FOR-US: HID Mercury Intelligent Controllers
 CVE-2022-31480 (An unauthenticated attacker could arbitrarily upload firmware files to ...)
-	TODO: check
+	NOT-FOR-US: HID Mercury Intelligent Controllers
 CVE-2022-31479 (An unauthenticated attacker can update the hostname with a specially c ...)
-	TODO: check
+	NOT-FOR-US: HID Mercury Intelligent Controllers
 CVE-2022-31478
 	RESERVED
 CVE-2022-1841
@@ -4547,13 +4547,13 @@ CVE-2022-30865
 CVE-2022-30864
 	RESERVED
 CVE-2022-30863 (FUDForum 3.1.2 is vulnerable to Cross Site Scripting (XSS) via page_ti ...)
-	TODO: check
+	NOT-FOR-US: FUDForum
 CVE-2022-30862
 	RESERVED
 CVE-2022-30861 (FUDforum 3.1.2 is vulnerable to Stored XSS via Forum Name field in For ...)
-	TODO: check
+	NOT-FOR-US: FUDForum
 CVE-2022-30860 (FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload F ...)
-	TODO: check
+	NOT-FOR-US: FUDForum
 CVE-2022-30859
 	RESERVED
 CVE-2022-30858
@@ -5036,7 +5036,7 @@ CVE-2022-1705
 CVE-2022-1704
 	RESERVED
 CVE-2022-1703 (Improper neutralization of special elements in the SonicWall SSL-VPN S ...)
-	TODO: check
+	NOT-FOR-US: SonicWall
 CVE-2022-1702 (SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier ver ...)
 	NOT-FOR-US: SonicWall
 CVE-2022-1701 (SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier ver ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6c0255c2120110ea4fe5870609c8b2f342ab8357

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6c0255c2120110ea4fe5870609c8b2f342ab8357
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220607/9fb32124/attachment.htm>


More information about the debian-security-tracker-commits mailing list