[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Nov 10 13:39:29 GMT 2022



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
eddc0381 by Moritz Muehlenhoff at 2022-11-10T14:39:05+01:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7,9 +7,9 @@ CVE-2022-45132
 CVE-2022-45131
 	RESERVED
 CVE-2022-45130 (Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/command ...)
-	TODO: check
+	NOT-FOR-US: Plesk
 CVE-2022-45129 (Payara before 2022-11-04, when deployed to the root context, allows at ...)
-	TODO: check
+	NOT-FOR-US: Payara
 CVE-2022-45128
 	RESERVED
 CVE-2022-45117
@@ -11042,7 +11042,7 @@ CVE-2022-41876
 CVE-2022-41875
 	RESERVED
 CVE-2022-41874 (Tauri is a framework for building binaries for all major desktop platf ...)
-	TODO: check
+	NOT-FOR-US: Tauri
 CVE-2022-41873
 	RESERVED
 CVE-2022-41872
@@ -13042,37 +13042,37 @@ CVE-2022-41130
 CVE-2022-41129
 	RESERVED
 CVE-2022-41128 (Windows Scripting Languages Remote Code Execution Vulnerability. This  ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41127
 	RESERVED
 CVE-2022-41126
 	RESERVED
 CVE-2022-41125 (Windows CNG Key Isolation Service Elevation of Privilege Vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41124
 	RESERVED
 CVE-2022-41123 (Microsoft Exchange Server Elevation of Privilege Vulnerability. This C ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41122 (Microsoft SharePoint Server Spoofing Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41121
 	RESERVED
 CVE-2022-41120 (Microsoft Windows Sysmon Elevation of Privilege Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41119 (Visual Studio Remote Code Execution Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41118 (Windows Scripting Languages Remote Code Execution Vulnerability. This  ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41117
 	RESERVED
 CVE-2022-41116 (Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41115
 	RESERVED
 CVE-2022-41114 (Windows Bind Filter Driver Elevation of Privilege Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41113 (Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41112
 	RESERVED
 CVE-2022-41111
@@ -13080,55 +13080,55 @@ CVE-2022-41111
 CVE-2022-41110
 	RESERVED
 CVE-2022-41109 (Windows Win32k Elevation of Privilege Vulnerability. This CVE ID is un ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41108
 	RESERVED
 CVE-2022-41107 (Microsoft Office Graphics Remote Code Execution Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41106 (Microsoft Excel Remote Code Execution Vulnerability. This CVE ID is un ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41105 (Microsoft Excel Information Disclosure Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41104 (Microsoft Excel Security Feature Bypass Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41103 (Microsoft Word Information Disclosure Vulnerability. This CVE ID is un ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41102 (Windows Overlay Filter Elevation of Privilege Vulnerability. This CVE  ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41101 (Windows Overlay Filter Elevation of Privilege Vulnerability. This CVE  ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41100 (Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vu ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41099 (BitLocker Security Feature Bypass Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41098 (Windows GDI+ Information Disclosure Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41097 (Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vul ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41096 (Microsoft DWM Core Library Elevation of Privilege Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41095 (Windows Digital Media Receiver Elevation of Privilege Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41094
 	RESERVED
 CVE-2022-41093 (Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vu ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41092 (Windows Win32k Elevation of Privilege Vulnerability. This CVE ID is un ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41091 (Windows Mark of the Web Security Feature Bypass Vulnerability. This CV ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41090 (Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41089
 	RESERVED
 CVE-2022-41088 (Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulner ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41087
 	RESERVED
 CVE-2022-41086 (Windows Group Policy Elevation of Privilege Vulnerability. This CVE ID ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41085 (Azure CycleCloud Elevation of Privilege Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41084
 	RESERVED
 CVE-2022-41083 (Visual Studio Code Elevation of Privilege Vulnerability. ...)
@@ -13138,11 +13138,11 @@ CVE-2022-41082 (Microsoft Exchange Server Remote Code Execution Vulnerability. .
 CVE-2022-41081 (Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulner ...)
 	NOT-FOR-US: Microsoft
 CVE-2022-41080 (Microsoft Exchange Server Elevation of Privilege Vulnerability. This C ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41079 (Microsoft Exchange Server Spoofing Vulnerability. This CVE ID is uniqu ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41078 (Microsoft Exchange Server Spoofing Vulnerability. This CVE ID is uniqu ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41077
 	RESERVED
 CVE-2022-41076
@@ -13152,7 +13152,7 @@ CVE-2022-41075
 CVE-2022-41074
 	RESERVED
 CVE-2022-41073 (Windows Print Spooler Elevation of Privilege Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41072
 	RESERVED
 CVE-2022-41071
@@ -13166,51 +13166,51 @@ CVE-2022-41068
 CVE-2022-41067
 	RESERVED
 CVE-2022-41066 (Microsoft Business Central Information Disclosure Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41065
 	RESERVED
 CVE-2022-41064 (.NET Framework Information Disclosure Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41063 (Microsoft Excel Remote Code Execution Vulnerability. This CVE ID is un ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41062 (Microsoft SharePoint Server Remote Code Execution Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41061 (Microsoft Word Remote Code Execution Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41060 (Microsoft Word Information Disclosure Vulnerability. This CVE ID is un ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41059
 	RESERVED
 CVE-2022-41058 (Windows Network Address Translation (NAT) Denial of Service Vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41057 (Windows HTTP.sys Elevation of Privilege Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41056 (Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerab ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41055 (Windows Human Interface Device Information Disclosure Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41054 (Windows Resilient File System (ReFS) Elevation of Privilege Vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41053 (Windows Kerberos Denial of Service Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41052 (Windows Graphics Component Remote Code Execution Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41051 (Azure RTOS GUIX Studio Remote Code Execution Vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41050 (Windows Extensible File Allocation Table Elevation of Privilege Vulner ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41049 (Windows Mark of the Web Security Feature Bypass Vulnerability. This CV ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41048 (Microsoft ODBC Driver Remote Code Execution Vulnerability. This CVE ID ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41047 (Microsoft ODBC Driver Remote Code Execution Vulnerability. This CVE ID ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41046
 	RESERVED
 CVE-2022-41045 (Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vu ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41044 (Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulner ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41043 (Microsoft Office Information Disclosure Vulnerability. ...)
 	NOT-FOR-US: Microsoft
 CVE-2022-41042 (Visual Studio Code Information Disclosure Vulnerability. ...)
@@ -13220,7 +13220,7 @@ CVE-2022-41041
 CVE-2022-41040 (Microsoft Exchange Server Elevation of Privilege Vulnerability. ...)
 	NOT-FOR-US: Microsoft
 CVE-2022-41039 (Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulner ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2022-41038 (Microsoft SharePoint Server Remote Code Execution Vulnerability. This  ...)
 	NOT-FOR-US: Microsoft
 CVE-2022-41037 (Microsoft SharePoint Server Remote Code Execution Vulnerability. This  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eddc0381fc5086fd98809fbd8e2ab21f44cfe43d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eddc0381fc5086fd98809fbd8e2ab21f44cfe43d
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20221110/2b77f9c7/attachment.htm>


More information about the debian-security-tracker-commits mailing list