[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Oct 27 17:59:38 BST 2023



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5d0f9052 by Moritz Muehlenhoff at 2023-10-27T18:58:37+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -257,19 +257,19 @@ CVE-2023-43906 (Xolo CMS v0.11 was discovered to contain a reflected cross-site
 CVE-2023-43905 (Incorrect access control in writercms v1.1.0 allows attackers to direc ...)
 	NOT-FOR-US: writercms
 CVE-2023-38849 (An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtai ...)
-	TODO: check
+	NOT-FOR-US: tire-sales Line
 CVE-2023-38848 (An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker ...)
-	TODO: check
+	NOT-FOR-US: rmc R Beauty CLINIC Line
 CVE-2023-38847 (An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to  ...)
-	TODO: check
+	NOT-FOR-US: CHRISTINA JAPAN Line
 CVE-2023-38846 (An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obt ...)
-	TODO: check
+	NOT-FOR-US: Marbre Lapin Line
 CVE-2023-38845 (An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote ...)
-	TODO: check
+	NOT-FOR-US: Anglaise Company Anglaise.Company
 CVE-2023-31422 (An issue was discovered by Elastic whereby sensitive information is re ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2023-31421 (It was discovered that when acting as TLS clients, Beats, Elastic Agen ...)
-	TODO: check
+	NOT-FOR-US: Elastic
 CVE-2023-45872
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2246067
 	TODO: check, seems to only affect a r0 version of qtsvg
@@ -413,27 +413,27 @@ CVE-2023-42861 (A logic issue was addressed with improved state management. This
 CVE-2023-42857 (A privacy issue was addressed with improved private data redaction for ...)
 	NOT-FOR-US: Apple
 CVE-2023-42856 (The issue was addressed with improved memory handling. This issue is f ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-42854 (This issue was addressed by removing the vulnerable code. This issue i ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-42852 (A logic issue was addressed with improved checks. This issue is fixed  ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-42850 (The issue was addressed with improved permissions logic. This issue is ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-42849 (The issue was addressed with improved memory handling. This issue is f ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-42847 (A logic issue was addressed with improved checks. This issue is fixed  ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-42846 (This issue was addressed by removing the vulnerable code. This issue i ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-42845 (An authentication issue was addressed with improved state management.  ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-42844 (This issue was addressed with improved handling of symlinks. This issu ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-42842 (The issue was addressed with improved checks. This issue is fixed in m ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-42841 (The issue was addressed with improved memory handling. This issue is f ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-42494 (EisBaer Scada - CWE-749: Exposed Dangerous Method or Function)
 	NOT-FOR-US: EisBaer Scada
 CVE-2023-42493 (EisBaer Scada - CWE-256: Plaintext Storage of a Password)
@@ -451,21 +451,21 @@ CVE-2023-42488 (EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a R
 CVE-2023-42438 (An inconsistent user interface issue was addressed with improved state ...)
 	NOT-FOR-US: Apple
 CVE-2023-41997 (This issue was addressed by restricting options offered on a locked de ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-41989 (The issue was addressed by restricting options offered on a locked dev ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-41988 (This issue was addressed by restricting options offered on a locked de ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-41983 (The issue was addressed with improved memory handling. This issue is f ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-41982 (This issue was addressed by restricting options offered on a locked de ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-41977 (The issue was addressed with improved handling of caches. This issue i ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-41976 (A use-after-free issue was addressed with improved memory management.  ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-41975 (This issue was addressed by removing the vulnerable code. This issue i ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-41960 (The vulnerability allows an unprivileged(untrusted) third-party applic ...)
 	NOT-FOR-US: Bosch
 CVE-2023-41372 (The vulnerability allows an unprivileged (untrusted) third- party appl ...)
@@ -473,37 +473,37 @@ CVE-2023-41372 (The vulnerability allows an unprivileged (untrusted) third- part
 CVE-2023-41255 (The vulnerability allows an unprivileged user with access to the subne ...)
 	NOT-FOR-US: Bosch
 CVE-2023-41254 (A privacy issue was addressed with improved private data redaction for ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-41077 (The issue was addressed with improved checks. This issue is fixed in m ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-41072 (A privacy issue was addressed with improved private data redaction for ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-40449 (The issue was addressed with improved memory handling. This issue is f ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-40447 (The issue was addressed with improved memory handling. This issue is f ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-40445 (The issue was addressed with improved UI handling. This issue is fixed ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-40444 (A permissions issue was addressed with additional restrictions. This i ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-40425 (A privacy issue was addressed with improved private data redaction for ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-40423 (The issue was addressed with improved memory handling. This issue is f ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-40421 (A permissions issue was addressed with additional restrictions. This i ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-40416 (The issue was addressed with improved memory handling. This issue is f ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-40413 (The issue was addressed with improved handling of caches. This issue i ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-40408 (An inconsistent user interface issue was addressed with improved state ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-40405 (A privacy issue was addressed with improved private data redaction for ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-40404 (A use-after-free issue was addressed with improved memory management.  ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-40401 (The issue was addressed with additional permissions checks. This issue ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2023-3010 (Grafana is an open-source platform for monitoring and observability.   ...)
 	NOT-FOR-US: Grafana plugin
 CVE-2023-37913 (XWiki Platform is a generic wiki platform offering runtime services fo ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5d0f90526f47b18150ae0562eeaa926d6b8011ba

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5d0f90526f47b18150ae0562eeaa926d6b8011ba
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231027/9bedeb1d/attachment.htm>


More information about the debian-security-tracker-commits mailing list