[Git][security-tracker-team/security-tracker][master] Process more NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Nov 27 21:07:21 GMT 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5d8763a1 by Salvatore Bonaccorso at 2023-11-27T22:06:44+01:00
Process more NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -54,11 +54,11 @@ CVE-2023-4642 (The kk Star Ratings WordPress plugin before 5.4.6 does not implem
 CVE-2023-4590 (Buffer overflow vulnerability in Frhed hex editor, affecting version 1 ...)
 	TODO: check
 CVE-2023-4514 (The Mmm Simple File List WordPress plugin through 2.3 does not validat ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2023-4297 (The Mmm Simple File List WordPress plugin through 2.3 does not validat ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2023-4252 (The EventPrime WordPress plugin through 3.2.9 specifies the price of a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2023-49316 (In Math/BinaryField.php in phpseclib before 3.0.34, excessively large  ...)
 	- php-phpseclib3 <unfixed> (bug #1057008)
 	NOTE: Fixed by: https://github.com/phpseclib/phpseclib/commit/964d78101a70305df33f442f5490f0adb3b7e77f (3.0.34)
@@ -90,31 +90,31 @@ CVE-2023-45223 (Mattermost fails to properly validate the "Show Full Name" optio
 CVE-2023-43754 (Mattermost fails to check whether the \u201cAllow users to view archiv ...)
 	TODO: check
 CVE-2023-42000 (Arcserve UDP prior to 9.2 contains a path traversal vulnerability in c ...)
-	TODO: check
+	NOT-FOR-US: Arcserve
 CVE-2023-41999 (An authentication bypass exists in Arcserve UDP prior to version 9.2.  ...)
-	TODO: check
+	NOT-FOR-US: Arcserve
 CVE-2023-41998 (Arcserve UDP prior to 9.2 contained a vulnerability in thecom.ca.arcfl ...)
-	TODO: check
+	NOT-FOR-US: Arcserve
 CVE-2023-41257 (A type confusion vulnerability exists in the way Foxit Reader 12.1.2.1 ...)
-	TODO: check
+	NOT-FOR-US: Foxit Reader
 CVE-2023-40703 (Mattermost fails to properly limit the characters allowed in different ...)
 	- mattermost-server <itp> (bug #823556)
 CVE-2023-40194 (An arbitrary file creation vulnerability exists in the Javascript expo ...)
-	TODO: check
+	NOT-FOR-US: Foxit Reader
 CVE-2023-39542 (A code execution vulnerability exists in the Javascript saveAs API of  ...)
-	TODO: check
+	NOT-FOR-US: Foxit Reader
 CVE-2023-38573 (A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.1 ...)
-	TODO: check
+	NOT-FOR-US: Foxit Reader
 CVE-2023-35985 (An arbitrary file creation vulnerability exists in the Javascript expo ...)
-	TODO: check
+	NOT-FOR-US: Foxit Reader
 CVE-2023-35075 (Mattermost fails to use innerText /textContentwhen setting the channel ...)
 	TODO: check
 CVE-2023-32616 (A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.1 ...)
-	TODO: check
+	NOT-FOR-US: Foxit Reader
 CVE-2023-31275 (An uninitialized pointer use vulnerability exists in the functionality ...)
-	TODO: check
+	NOT-FOR-US: WPS Office
 CVE-2023-2707 (The gAppointments WordPress plugin through 1.9.5.1 does not sanitise a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2023-43701 (Improper payload validation and an improper REST API response type, ma ...)
 	NOT-FOR-US: Apache Superset
 CVE-2023-42501 (Unnecessary read permissions within the Gamma role would allow authent ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5d8763a1767fe536c826d66cbffcf176d4047bd7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5d8763a1767fe536c826d66cbffcf176d4047bd7
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231127/fe5058cf/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list