[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu May 11 20:07:25 BST 2023
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a1a69a56 by Salvatore Bonaccorso at 2023-05-11T21:06:53+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -12007,11 +12007,11 @@ CVE-2023-27566 (Cubism Core in Live2D Cubism Editor 4.2.03 allows out-of-bounds
CVE-2023-27565
RESERVED
CVE-2023-27564 (The n8n package 0.218.0 for Node.js allows Information Disclosure.)
- TODO: check
+ NOT-FOR-US: n8n Node module
CVE-2023-27563 (The n8n package 0.218.0 for Node.js allows Escalation of Privileges.)
- TODO: check
+ NOT-FOR-US: n8n Node module
CVE-2023-27562 (The n8n package 0.218.0 for Node.js allows Directory Traversal.)
- TODO: check
+ NOT-FOR-US: n8n Node module
CVE-2023-27528
RESERVED
CVE-2023-27392
@@ -110379,7 +110379,7 @@ CVE-2021-45346 (A Memory Leak vulnerability exists in SQLite Project SQLite3 3.3
NOTE: https://sqlite.org/forum/forumpost/056d557c2f8c452ed5bb9c215414c802b215ce437be82be047726e521342161e
NOTE: Negligible security impact
CVE-2021-45345 (Buffer Overflow vulnerability found in En3rgy WebcamServer v.0.5.2 all ...)
- TODO: check
+ NOT-FOR-US: En3rgy WebcamServer
CVE-2021-45344
RESERVED
CVE-2021-45343 (In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of ...)
@@ -112546,13 +112546,13 @@ CVE-2021-4090 (An out-of-bounds (OOB) memory write flaw was found in the NFSD in
CVE-2022-21812 (Improper access control in the Intel(R) HAXM software before version 7 ...)
NOT-FOR-US: Intel
CVE-2022-21804 (Out-of-bounds write in software for the Intel QAT Driver for Windows b ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2022-21794 (Improper authentication in BIOS firmware for some Intel(R) NUC Boards, ...)
NOT-FOR-US: Intel
CVE-2022-21793 (Insufficient control flow management in the Intel(R) Ethernet 500 Seri ...)
NOT-FOR-US: Intel
CVE-2022-21239 (Out-of-bounds read in software for the Intel QAT Driver for Windows be ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2022-21229 (Improper buffer restrictions for some Intel(R) NUC 9 Extreme Laptop Ki ...)
NOT-FOR-US: Intel
CVE-2022-21226 (Out-of-bounds read in the Intel(R) Trace Analyzer and Collector before ...)
@@ -112570,7 +112570,7 @@ CVE-2022-21171
CVE-2022-21163 (Improper access control in the Crypto API Toolkit for Intel(R) SGX bef ...)
NOT-FOR-US: Intel
CVE-2022-21162 (Uncontrolled search path for the Intel(R) HDMI Firmware Update tool fo ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2022-21161
RESERVED
CVE-2022-21156 (Access of uninitialized pointer in the Intel(R) Trace Analyzer and Col ...)
@@ -163830,7 +163830,7 @@ CVE-2021-26408 (Insufficient validation of elliptic curve points in SEV-legacy f
CVE-2021-26407 (A randomly generated Initialization Vector (IV) may lead to a collisio ...)
NOT-FOR-US: AMD
CVE-2021-26406 (Insufficient validation in parsing Owner's Certificate Authority (OCA) ...)
- TODO: check
+ NOT-FOR-US: AMD
CVE-2021-26405
REJECTED
CVE-2021-26404 (Improper input validation and bounds checking in SEV firmware may leak ...)
@@ -163853,7 +163853,7 @@ CVE-2021-26399
CVE-2021-26398 (Insufficient input validation in SYS_KEY_DERIVE system call in a compr ...)
NOT-FOR-US: AMD
CVE-2021-26397 (Insufficient address validation, may allow an attacker with a compromi ...)
- TODO: check
+ NOT-FOR-US: AMD
CVE-2021-26396 (Insufficient validation of address mapping to IO in ASP (AMD Secure Pr ...)
NOT-FOR-US: AMD
CVE-2021-26395
@@ -163889,7 +163889,7 @@ CVE-2021-26381
CVE-2021-26380
RESERVED
CVE-2021-26379 (Insufficient input validation of mailbox data in the SMU may allow an ...)
- TODO: check
+ NOT-FOR-US: AMD
CVE-2021-26378 (Insufficient bound checks in the System Management Unit (SMU) may resu ...)
NOT-FOR-US: AMD
CVE-2021-26377
@@ -163905,7 +163905,7 @@ CVE-2021-26373 (Insufficient bound checks in the System Management Unit (SMU) ma
CVE-2021-26372 (Insufficient bound checks related to PCIE in the System Management Uni ...)
NOT-FOR-US: AMD
CVE-2021-26371 (A compromised or malicious ABL or UApp could send a SHA256 system call ...)
- TODO: check
+ NOT-FOR-US: AMD
CVE-2021-26370 (Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INS ...)
NOT-FOR-US: AMD
CVE-2021-26369 (A malicious or compromised UApp or ABL may be used by an attacker to s ...)
@@ -163935,11 +163935,11 @@ CVE-2021-26358
CVE-2021-26357
REJECTED
CVE-2021-26356 (A TOCTOU in ASP bootloader may allow an attacker to tamper with the SP ...)
- TODO: check
+ NOT-FOR-US: AMD
CVE-2021-26355 (Insufficient fencing and checks in System Management Unit (SMU) may re ...)
NOT-FOR-US: AMD
CVE-2021-26354 (Insufficient bounds checking in ASP may allow an attacker to issue a s ...)
- TODO: check
+ NOT-FOR-US: AMD
CVE-2021-26353 (Failure to validate inputs in SMM may allow an attacker to create a mi ...)
NOT-FOR-US: AMD
CVE-2021-26352 (Insufficient bound checks in System Management Unit (SMU) PCIe Hot Plu ...)
@@ -202931,9 +202931,9 @@ CVE-2020-23365
CVE-2020-23364
RESERVED
CVE-2020-23363 (Cross Site Request Forgery (CSRF) vulnerability found in Verytops Very ...)
- TODO: check
+ NOT-FOR-US: Verytops Verydows
CVE-2020-23362 (Insecure Permissons vulnerability found in Shop_CMS YerShop all versio ...)
- TODO: check
+ NOT-FOR-US: Shop_CMS YerShop
CVE-2020-23361 (phpList 3.5.3 allows type juggling for login bypass because == is used ...)
- phplist <itp> (bug #612288)
CVE-2020-23360 (oscommerce v2.3.4.1 has a functional problem in user registration and ...)
@@ -213777,7 +213777,7 @@ CVE-2020-18282 (Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows
CVE-2020-18281
RESERVED
CVE-2020-18280 (Cross Site Scripting vulnerability found in Phodal CMD v.1.0 allows a ...)
- TODO: check
+ NOT-FOR-US: Phodal CMD
CVE-2020-18279
RESERVED
CVE-2020-18278
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a1a69a56a8b0c14a7596683f3b4813a2462065f1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a1a69a56a8b0c14a7596683f3b4813a2462065f1
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230511/c26356ac/attachment.htm>
More information about the debian-security-tracker-commits
mailing list