[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Jan 9 17:34:36 GMT 2023



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6de7d6b9 by Moritz Muehlenhoff at 2023-01-09T18:34:10+01:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -35,15 +35,15 @@ CVE-2015-10030 (A vulnerability has been found in SUKOHI Surpass and classified
 CVE-2014-125070 (A vulnerability has been found in yanheven console and classified as p ...)
 	NOT-FOR-US: yanheven console
 CVE-2014-125069 (A vulnerability was found in saxman maps-js-icoads. It has been classi ...)
-	TODO: check
+	NOT-FOR-US: saxman maps-js-icoads
 CVE-2014-125068 (A vulnerability was found in saxman maps-js-icoads and classified as c ...)
-	TODO: check
+	NOT-FOR-US: saxman maps-js-icoads
 CVE-2014-125067 (A vulnerability classified as critical was found in corincerami curios ...)
-	TODO: check
+	NOT-FOR-US: corincerami
 CVE-2014-125066 (A vulnerability was found in emmflo yuko-bot. It has been declared as  ...)
-	TODO: check
+	NOT-FOR-US: emmflo yuko-bot
 CVE-2007-10002 (A vulnerability, which was classified as critical, has been found in w ...)
-	TODO: check
+	NOT-FOR-US: web-cyradm
 CVE-2023-22855
 	RESERVED
 CVE-2023-22854
@@ -814,17 +814,17 @@ CVE-2023-0057 (Improper Restriction of Rendered UI Layers or Frames in GitHub re
 CVE-2023-0056
 	RESERVED
 CVE-2023-0055 (Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub ...)
-	TODO: check
+	- pyload <itp> (bug #1001980)
 CVE-2022-4876 (A vulnerability was found in Kaltura mwEmbed up to 2.96.rc1 and classi ...)
-	TODO: check
+	NOT-FOR-US: Kaltura mwEmbed
 CVE-2022-4875 (A vulnerability has been found in fossology and classified as problema ...)
-	TODO: check
+	- fossology <removed>
 CVE-2021-4302 (A vulnerability was found in slackero phpwcms up to 1.9.26. It has bee ...)
-	TODO: check
+	NOT-FOR-US: slackero phpwcms
 CVE-2021-4301 (A vulnerability was found in slackero phpwcms up to 1.9.26 and classif ...)
-	TODO: check
+	NOT-FOR-US: slackero phpwcms
 CVE-2021-4300 (A vulnerability has been found in ghostlander Halcyon and classified a ...)
-	TODO: check
+	NOT-FOR-US: ghostlander Halcyon
 CVE-2023-22618
 	RESERVED
 CVE-2023-22617
@@ -879,7 +879,7 @@ CVE-2023-0049 (Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143
 	NOTE: https://github.com/vim/vim/commit/7b17eb4b063a234376c1ec909ee293e42cff290c (v9.0.1143)
 	NOTE: Crash in CLI tool, no security impact
 CVE-2023-0048 (Code Injection in GitHub repository lirantal/daloradius prior to maste ...)
-	TODO: check
+	NOT-FOR-US: lirantal/daloradius
 CVE-2023-0047
 	RESERVED
 	- linux 5.15.3-1
@@ -887,7 +887,7 @@ CVE-2023-0047
 	[buster] - linux 4.19.232-1
 	NOTE: https://git.kernel.org/linus/60e2793d440a3ec95abb5d6d4fc034a4b480472d (5.16-rc1)
 CVE-2023-0046 (Improper Restriction of Names for Files and Other Resources in GitHub  ...)
-	TODO: check
+	NOT-FOR-US: lirantal/daloradius
 CVE-2023-0045
 	RESERVED
 CVE-2023-0044
@@ -980,9 +980,9 @@ CVE-2023-0038 (The "Survey Maker – Best WordPress Survey Plugin" plugin fo
 CVE-2023-0037
 	RESERVED
 CVE-2023-0036 (platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and ...)
-	TODO: check
+	NOT-FOR-US: OpenHarmony
 CVE-2023-0035 (softbus_client_stub in communication subsystem within OpenHarmony-v3.0 ...)
-	TODO: check
+	NOT-FOR-US: OpenHarmony
 CVE-2022-4871 (A vulnerability classified as problematic was found in ummmmm nflpick- ...)
 	NOT-FOR-US: ummmmm nflpick-em.com
 CVE-2022-48215
@@ -1132,7 +1132,7 @@ CVE-2023-0030
 CVE-2023-0029 (A vulnerability was found in Multilaser RE708 RE1200R4GC-2T2R-V3_v3411 ...)
 	NOT-FOR-US: Multilaser RE708
 CVE-2022-4869 (A vulnerability was found in Evolution Events Artaxerxes. It has been  ...)
-	TODO: check
+	NOT-FOR-US: Evolution Events Artaxerxes
 CVE-2022-48199
 	RESERVED
 CVE-2021-4297 (A vulnerability has been found in trampgeek jobe up to 1.6.4 and class ...)
@@ -1260,7 +1260,7 @@ CVE-2018-25061 (A vulnerability was found in rgb2hex up to 0.1.5. It has been ra
 CVE-2017-20160 (A vulnerability was found in flitto express-param up to 0.x. It has be ...)
 	NOT-FOR-US: express-param
 CVE-2014-125029 (A vulnerability was found in ttskch PaginationServiceProvider up to 0. ...)
-	TODO: check
+	NOT-FOR-US:  ttskch/PaginationServiceProvider
 CVE-2014-125028 (A vulnerability was found in valtech IDP Test Client and classified as ...)
 	NOT-FOR-US: valtech IDP Test Client
 CVE-2022-4868 (Improper Authorization in GitHub repository froxlor/froxlor prior to 2 ...)
@@ -1491,7 +1491,7 @@ CVE-2021-4295 (A vulnerability classified as problematic was found in ONC code-v
 CVE-2018-25058 (A vulnerability classified as problematic has been found in Twitter-Po ...)
 	NOT-FOR-US: Twitter-Post-Fetcher
 CVE-2023-22475 (Canarytokens is an open source tool which helps track activity and act ...)
-	TODO: check
+	NOT-FOR-US: canarytokens
 CVE-2023-22474
 	RESERVED
 CVE-2023-22473
@@ -1507,25 +1507,25 @@ CVE-2023-22469
 CVE-2023-22468
 	RESERVED
 CVE-2023-22467 (Luxon is a library for working with dates and times in JavaScript. On  ...)
-	TODO: check
+	NOT-FOR-US: Luxon
 CVE-2023-22466 (Tokio is a runtime for writing applications with Rust. Starting with v ...)
 	TODO: check
 CVE-2023-22465 (Http4s is a Scala interface for HTTP services. Starting with version 0 ...)
-	TODO: check
+	NOT-FOR-US: http4s
 CVE-2023-22463 (KubePi is a k8s panel. The jwt authentication function of KubePi throu ...)
-	TODO: check
+	NOT-FOR-US: KubePi
 CVE-2023-22462
 	RESERVED
 CVE-2023-22461 (The `sanitize-svg` package, a small SVG sanitizer to prevent cross-sit ...)
 	TODO: check
 CVE-2023-22460 (go-ipld-prime is an implementation of the InterPlanetary Linked Data ( ...)
 	TODO: check
-CVE-2023-22459
+	NOT-FOR-US: go-ipld-prime
 	RESERVED
 CVE-2023-22458
 	RESERVED
 CVE-2023-22457 (CKEditor Integration UI adds support for editing wiki pages using CKEd ...)
-	TODO: check
+	NOT-FOR-US: xwiki CKEditor Integration UI
 CVE-2023-22464 (ViewVC is a browser interface for CVS and Subversion version control r ...)
 	- viewvc <removed>
 	NOTE: https://github.com/viewvc/viewvc/issues/311#issuecomment-1371011216
@@ -1537,11 +1537,11 @@ CVE-2023-22456 (ViewVC, a browser interface for CVS and Subversion version contr
 	NOTE: https://github.com/viewvc/viewvc/security/advisories/GHSA-j4mx-f97j-gc5g
 	NOTE: https://github.com/viewvc/viewvc/commit/2d57d713aa9b64558a9ba3ea187866ce98564c0a (1.1.29)
 CVE-2023-22455 (Discourse is an option source discussion platform. Prior to version 2. ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2023-22454 (Discourse is an option source discussion platform. Prior to version 2. ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2023-22453 (Discourse is an option source discussion platform. Prior to version 2. ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2023-22452 (kenny2automate is a Discord bot. In the web interface for server setti ...)
 	NOT-FOR-US: kenny2automate
 CVE-2023-22451 (Kiwi TCMS is an open source test management system. In version 11.6 an ...)
@@ -2005,11 +2005,11 @@ CVE-2022-47978
 CVE-2022-47977
 	RESERVED
 CVE-2022-47976 (The DMSDP module of the distributed hardware has a vulnerability that  ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2022-47975 (The DUBAI module has a double free vulnerability.Successful exploitati ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2022-47974 (The Bluetooth AVRCP module has a vulnerability that can lead to DoS at ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2022-4797 (Improper Restriction of Excessive Authentication Attempts in GitHub re ...)
 	NOT-FOR-US: usememos
 CVE-2022-4796 (Incorrect Use of Privileged APIs in GitHub repository usememos/memos p ...)
@@ -2051,9 +2051,9 @@ CVE-2022-4779 (StreamX applications from versions 6.02.01 to 6.04.34 are affecte
 CVE-2022-4778 (StreamX applications from versions 6.02.01 to 6.04.34 are affected by  ...)
 	NOT-FOR-US: StreamX applications
 CVE-2021-46868 (The HW_KEYMASTER module has a problem in releasing memory.Successful e ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2021-46867 (The HW_KEYMASTER module has a problem in releasing memory.Successful e ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2021-4294 (A vulnerability was found in OpenShift OSIN. It has been classified as ...)
 	NOT-FOR-US: OpenShift OSIN
 CVE-2021-4293 (** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problema ...)
@@ -3753,9 +3753,9 @@ CVE-2022-47546
 CVE-2022-47545
 	RESERVED
 CVE-2022-47544 (An issue was discovered in Siren Investigate before 12.1.7. Script var ...)
-	TODO: check
+	NOT-FOR-US: Siren Investigate
 CVE-2022-47543 (An issue was discovered in Siren Investigate before 12.1.7. There is a ...)
-	TODO: check
+	NOT-FOR-US: Siren Investigate
 CVE-2022-47542
 	RESERVED
 CVE-2022-4615 (Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/op ...)
@@ -3833,7 +3833,7 @@ CVE-2022-47525
 CVE-2022-47524 (F-Secure SAFE Browser 19.1 before 19.2 for Android allows an IDN homog ...)
 	NOT-FOR-US: F-Secure SAFE Browser
 CVE-2022-47523 (Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pr ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2022-4607 (A vulnerability was found in 3D City Database OGC Web Feature Service  ...)
 	NOT-FOR-US: 3D City Database OGC Web Feature Service
 CVE-2021-4257 (A vulnerability was found in ctrlo lenio. It has been declared as prob ...)
@@ -6065,13 +6065,13 @@ CVE-2022-4436 (Use after free in Blink Media in Google Chrome prior to 108.0.535
 	- chromium 108.0.5359.124-1
 	[buster] - chromium <end-of-life> (see DSA 5046)
 CVE-2022-4435 (A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS ...)
-	TODO: check
+	NOT-FOR-US: Lenovo
 CVE-2022-4434 (A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS ...)
-	TODO: check
+	NOT-FOR-US: Lenovo
 CVE-2022-4433 (A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS ...)
-	TODO: check
+	NOT-FOR-US: Lenovo
 CVE-2022-4432 (A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS ...)
-	TODO: check
+	NOT-FOR-US: Lenovo
 CVE-2022-4431
 	RESERVED
 CVE-2022-4430
@@ -7257,9 +7257,9 @@ CVE-2022-46764 (A SQL injection issue in the web API in TrueConf Server 5.2.0.10
 CVE-2022-46763 (A SQL injection issue in a database stored function in TrueConf Server ...)
 	NOT-FOR-US: TrueConf Server
 CVE-2022-46762 (The memory management module has a logic bypass vulnerability.Successf ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2022-46761 (The system has a vulnerability that may cause dynamic hiding and resto ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2022-46760
 	RESERVED
 CVE-2022-46759
@@ -9214,13 +9214,13 @@ CVE-2022-46182
 CVE-2022-46181 (Gotify server is a simple server for sending and receiving messages in ...)
 	NOT-FOR-US: Gotify server
 CVE-2022-46180 (Discourse Mermaid (discourse-mermaid-theme-component) allows users of  ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2022-46179 (LiuOS is a small Python project meant to imitate the functions of a re ...)
 	NOT-FOR-US: LiuOS
 CVE-2022-46178 (MeterSphere is a one-stop open source continuous testing platform, cov ...)
 	NOT-FOR-US: MeterSphere
 CVE-2022-46177 (Discourse is an option source discussion platform. Prior to version 2. ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2022-46176
 	RESERVED
 CVE-2022-46175 (JSON5 is an extension to the popular JSON file format that aims to be  ...)
@@ -9836,11 +9836,11 @@ CVE-2022-45915 (ILIAS before 7.16 allows OS Command Injection. ...)
 CVE-2022-45914 (The ESL (Electronic Shelf Label) protocol, as implemented by (for exam ...)
 	NOT-FOR-US: ESL (Electronic Shelf Label) protocol
 CVE-2022-45913 (An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occ ...)
-	TODO: check
+	NOT-FOR-US: Zimbra
 CVE-2022-45912 (An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0.  ...)
 	NOT-FOR-US: Zimbra
 CVE-2022-45911 (An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occ ...)
-	TODO: check
+	NOT-FOR-US: Zimbra
 CVE-2022-4145
 	RESERVED
 	NOT-FOR-US: OpenShift
@@ -9940,17 +9940,17 @@ CVE-2022-45883
 CVE-2022-45877 (OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code i ...)
 	NOT-FOR-US: OpenHarmony
 CVE-2022-45875 (Improper validation of script alert plugin parameters in Apache Dolphi ...)
-	TODO: check
+	NOT-FOR-US: Apache DolphinScheduler
 CVE-2022-45874 (Huawei Aslan Children's Watch has an improper authorization vulnerabil ...)
 	NOT-FOR-US: Huawei
 CVE-2022-45126 (Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kerne ...)
-	TODO: check
+	NOT-FOR-US: OpenHarmony
 CVE-2022-45118 (OpenHarmony-v3.1.2 and prior versions had a vulnerability that telepho ...)
 	NOT-FOR-US: OpenHarmony
 CVE-2022-44455 (The appspawn and nwebspawn services within OpenHarmony-v3.1.2 and prio ...)
 	NOT-FOR-US: OpenHarmony
 CVE-2022-43662 (Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kerne ...)
-	TODO: check
+	NOT-FOR-US: OpenHarmony
 CVE-2022-41802 (Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kerne ...)
 	NOT-FOR-US: OpenHarmony
 CVE-2022-4138
@@ -10019,7 +10019,7 @@ CVE-2022-45859
 CVE-2022-45858
 	RESERVED
 CVE-2022-45857 (An incorrect user management vulnerability [CWE-286] in the FortiManag ...)
-	TODO: check
+	NOT-FOR-US: Fortinet
 CVE-2022-45856
 	RESERVED
 CVE-2022-45855
@@ -12285,11 +12285,11 @@ CVE-2022-3931
 CVE-2022-3930 (The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR v ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-3929 (Communication between the client and the server application of the aff ...)
-	TODO: check
+	NOT-FOR-US: Hitachi
 CVE-2022-3928 (Hardcoded credential is found in affected products' message queue. An  ...)
-	TODO: check
+	NOT-FOR-US: Hitachi
 CVE-2022-3927 (The affected products store both public and private key that are used  ...)
-	TODO: check
+	NOT-FOR-US: Hitachi
 CVE-2022-3926 (The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4 ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-3925 (The buddybadges WordPress plugin through 1.0.0 does not sanitise and e ...)
@@ -12531,13 +12531,13 @@ CVE-2022-45054
 CVE-2022-45053
 	RESERVED
 CVE-2022-45052 (A Local File Inclusion vulnerability has been found in Axiell Iguana C ...)
-	TODO: check
+	NOT-FOR-US: Axiell Iguana CMS
 CVE-2022-45051 (A reflected XSS vulnerability has been found in Axiell Iguana CMS, all ...)
-	TODO: check
+	NOT-FOR-US: Axiell Iguana CMS
 CVE-2022-45050 (A reflected XSS vulnerability has been found in Axiell Iguana CMS, all ...)
 	NOT-FOR-US: Axiell Iguana CMS
 CVE-2022-45049 (A reflected XSS vulnerability has been found in Axiell Iguana CMS, all ...)
-	TODO: check
+	NOT-FOR-US: Axiell Iguana CMS
 CVE-2022-45048
 	RESERVED
 CVE-2022-45047 (Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvide ...)
@@ -12830,7 +12830,7 @@ CVE-2022-44941
 CVE-2022-44940 (Patchelf v0.9 was discovered to contain an out-of-bounds read via the  ...)
 	TODO: check
 CVE-2022-44939 (Efs Software Easy Chat Server Version 3.1 was discovered to contain a  ...)
-	TODO: check
+	NOT-FOR-US: Efs Software Easy Chat Server
 CVE-2022-44938 (Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attac ...)
 	NOT-FOR-US: SeedDMS
 CVE-2022-44937 (Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery  ...)
@@ -12954,7 +12954,7 @@ CVE-2022-44879
 CVE-2022-44878
 	RESERVED
 CVE-2022-44877 (RESERVED An issue in the /login/index.php component of Centos Web Pane ...)
-	TODO: check
+	NOT-FOR-US: CWP (aka Control Web Panel or CentOS Web Panel)
 CVE-2022-44876
 	RESERVED
 CVE-2022-44875
@@ -12968,7 +12968,7 @@ CVE-2022-44872
 CVE-2022-44871
 	RESERVED
 CVE-2022-44870 (A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022 ...)
-	TODO: check
+	NOT-FOR-US: maccms10
 CVE-2022-44869
 	RESERVED
 CVE-2022-44868
@@ -15270,55 +15270,55 @@ CVE-2022-44448
 CVE-2022-44447
 	RESERVED
 CVE-2022-44446 (In wlan driver, there is a possible missing bounds check. This could l ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44445 (In wlan driver, there is a possible missing bounds check. This could l ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44444 (In wlan driver, there is a possible missing bounds check. This could l ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44443 (In wlan driver, there is a possible missing bounds check. This could l ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44442 (In wlan driver, there is a possible missing bounds check, This could l ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44441 (In wlan driver, there is a possible missing bounds check. This could l ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44440 (In wlan driver, there is a possible missing bounds check. This could l ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44439 (In messaging service, there is a missing permission check. This could  ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44438 (In messaging service, there is a missing permission check. This could  ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44437 (In messaging service, there is a missing permission check. This could  ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44436 (In messaging service, there is a missing permission check. This could  ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44435 (In messaging service, there is a missing permission check. This could  ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44434 (In messaging service, there is a missing permission check. This could  ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44433
 	RESERVED
 CVE-2022-44432 (In wlan driver, there is a possible missing bounds check. This could l ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44431 (In wlan driver, there is a possible missing bounds check. This could l ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44430 (In wlan driver, there is a possible missing bounds check. This could l ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44429 (In wlan driver, there is a possible missing bounds check. This could l ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44428 (In wlan driver, there is a possible missing bounds check. This could l ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44427 (In wlan driver, there is a possible missing bounds check. This could l ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44426 (In wlan driver, there is a possible missing bounds check. This could l ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44425 (In wlan driver, there is a possible missing bounds check. This could l ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44424 (In music service, there is a missing permission check. This could lead ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44423 (In music service, there is a missing permission check. This could lead ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44422 (In music service, there is a missing permission check. This could lead ...)
-	TODO: check
+	NOT-FOR-US: Unisoc
 CVE-2022-44421
 	RESERVED
 CVE-2022-44420
@@ -15870,7 +15870,7 @@ CVE-2022-44151 (Simple Inventory Management System v1.0 is vulnerable to SQL Inj
 CVE-2022-44150
 	RESERVED
 CVE-2022-44149 (The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 devices allow ...)
-	TODO: check
+	NOT-FOR-US: Nexxt Amp300 ARN02304U8
 CVE-2022-44148
 	RESERVED
 CVE-2022-44147
@@ -18163,7 +18163,7 @@ CVE-2022-3707
 CVE-2022-3706 (Improper authorization in GitLab CE/EE affecting all versions from 7.1 ...)
 	- gitlab <unfixed>
 CVE-2022-43932 (Improper neutralization of special elements in output used by a downst ...)
-	TODO: check
+	NOT-FOR-US: Synology
 CVE-2022-43931 (Out-of-bounds write vulnerability in Remote Desktop Functionality in S ...)
 	NOT-FOR-US: Synology VPN Plus Server
 CVE-2022-43930



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6de7d6b9b66d996bb803d680fd6e752c57d5bd1d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6de7d6b9b66d996bb803d680fd6e752c57d5bd1d
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230109/bc13aa68/attachment.htm>


More information about the debian-security-tracker-commits mailing list