[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jan 10 20:23:40 GMT 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
13cc4d6f by Salvatore Bonaccorso at 2024-01-10T21:23:07+01:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,73 +1,73 @@
 CVE-2024-20715 (Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2024-20714 (Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2024-20713 (Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2024-20712 (Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2024-20711 (Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2024-20710 (Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2024-0395
 	REJECTED
 CVE-2024-0389 (A vulnerability, which was classified as critical, was found in Source ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester Student Attendance System
 CVE-2024-0310 (A content-security-policy vulnerability in ENS Control browser extensi ...)
-	TODO: check
+	NOT-FOR-US: ENS Control browser extension
 CVE-2023-6158 (The EventON - WordPress Virtual Event Calendar Plugin plugin for WordP ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2023-5455 (A Cross-site request forgery vulnerability exists in ipa/session/login ...)
 	TODO: check
 CVE-2023-51972 (Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vu ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51971 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpv ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51970 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode  ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51969 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51968 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbal ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51967 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port  ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51966 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbal ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51965 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpv ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51964 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port  ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51963 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51962 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode  ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51961 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbal ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51960 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51959 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpv ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51958 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port  ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51957 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode  ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51956 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51955 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbal ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51954 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port  ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51953 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode  ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51952 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpv ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-51252 (PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because fil ...)
-	TODO: check
+	NOT-FOR-US: PublicCMS
 CVE-2023-51195
 	REJECTED
 CVE-2023-50916 (Kyocera Device Manager before 3.1.1213.0 allows NTLM credential exposu ...)
-	TODO: check
+	NOT-FOR-US: Kyocera Device Manager
 CVE-2023-50172 (A recovery notification bypass vulnerability exists in the userRecover ...)
 	TODO: check
 CVE-2023-50120 (MP4Box GPAC version 2.3-DEV-rev636-gfbd7e13aa-master was discovered to ...)
@@ -91,67 +91,67 @@ CVE-2023-49599 (An insufficient entropy vulnerability exists in the salt generat
 CVE-2023-49589 (An insufficient entropy vulnerability exists in the userRecoverPass.ph ...)
 	TODO: check
 CVE-2023-49471 (Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus B ...)
-	TODO: check
+	NOT-FOR-US: karlomikus Bar Assistant
 CVE-2023-49427 (Buffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remot ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-49394 (Zentao versions 4.1.3 and before has a URL redirect vulnerability, whi ...)
-	TODO: check
+	NOT-FOR-US: Zentao
 CVE-2023-48783 (AnAuthorization Bypass Through User-Controlled Key vulnerability [CWE- ...)
-	TODO: check
+	NOT-FOR-US: PortiPortal
 CVE-2023-48730 (A cross-site scripting (xss) vulnerability exists in the navbarMenuAnd ...)
 	TODO: check
 CVE-2023-48728 (A cross-site scripting (xss) vulnerability exists in the functiongetOp ...)
 	TODO: check
 CVE-2023-48266 (The vulnerability allows an unauthenticated remote attacker to perform ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48265 (The vulnerability allows an unauthenticated remote attacker to perform ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48264 (The vulnerability allows an unauthenticated remote attacker to perform ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48263 (The vulnerability allows an unauthenticated remote attacker to perform ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48262 (The vulnerability allows an unauthenticated remote attacker to perform ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48261 (The vulnerability allows a remote unauthenticated attacker to read arb ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48260 (The vulnerability allows a remote unauthenticated attacker to read arb ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48259 (The vulnerability allows a remote unauthenticated attacker to read arb ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48258 (The vulnerability allows a remote attacker to delete arbitrary files o ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48257 (The vulnerability allows a remote attacker to access sensitive data in ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48256 (The vulnerability allows a remote attacker to inject arbitrary HTTP re ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48255 (The vulnerability allows an unauthenticated remote attacker to send ma ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48254 (The vulnerability allows a remote attacker to inject and execute arbit ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48253 (The vulnerability allows a remote authenticated attacker to read or up ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48252 (The vulnerability allows an authenticated remote attacker to perform a ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48251 (The vulnerability allows a remote attacker to authenticate to the SSH  ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48250 (The vulnerability allows a remote attacker to authenticate to the web  ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48249 (The vulnerability allows an authenticated remote attacker to list arbi ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48248 (The vulnerability allows an authenticated remote attacker to upload a  ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48247 (The vulnerability allows an unauthenticated remote attacker to read ar ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48246 (The vulnerability allows a remote attacker to download arbitrary files ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48245 (The vulnerability allows an unauthenticated remote attacker to upload  ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48244 (The vulnerability allows a remote attacker to inject and execute arbit ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48243 (The vulnerability allows a remote attacker to upload arbitrary files i ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-48242 (The vulnerability allows an authenticated remote attacker to download  ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2023-47862 (A local file inclusion vulnerability exists in the getLanguageFromBrow ...)
 	TODO: check
 CVE-2023-47861 (A cross-site scripting (xss) vulnerability exists in the channelBody.p ...)
@@ -159,17 +159,17 @@ CVE-2023-47861 (A cross-site scripting (xss) vulnerability exists in the channel
 CVE-2023-47171 (An information disclosure vulnerability exists in the aVideoEncoder.js ...)
 	TODO: check
 CVE-2023-46712 (A improper access control in Fortinet FortiPortal version 7.0.0 throug ...)
-	TODO: check
+	NOT-FOR-US: FortiGuard
 CVE-2023-45139 (fontTools is a library for manipulating fonts, written in Python. The  ...)
 	TODO: check
 CVE-2023-44250 (An improper privilege management vulnerability [CWE-269] in a Fortinet ...)
-	TODO: check
+	NOT-FOR-US: FortiGuard
 CVE-2023-41603 (D-Link R15 before v1.08.02 was discovered to contain no firewall restr ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2023-37934 (An allocation of resources without limits or throttling vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: FortiGuard
 CVE-2023-37932 (An improper limitation of a pathname to a restricted directory ('path  ...)
-	TODO: check
+	NOT-FOR-US: FortiGuard
 CVE-2023-31488 (Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.264 ...)
 	TODO: check
 CVE-2023-49619 (Concurrent Execution using Shared Resource with Improper Synchronizati ...)
@@ -233269,13 +233269,13 @@ CVE-2020-26632
 CVE-2020-26631
 	RESERVED
 CVE-2020-26630 (A Time-Based SQL Injection vulnerability was discovered in Hospital Ma ...)
-	TODO: check
+	NOT-FOR-US: Hospital Management System
 CVE-2020-26629 (A JQuery Unrestricted Arbitrary File Upload vulnerability was discover ...)
 	TODO: check
 CVE-2020-26628 (A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital  ...)
-	TODO: check
+	NOT-FOR-US: Hospital Management System
 CVE-2020-26627 (A Time-Based SQL Injection vulnerability was discovered in Hospital Ma ...)
-	TODO: check
+	NOT-FOR-US: Hospital Management System
 CVE-2020-26626
 	RESERVED
 CVE-2020-26625 (A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and ea ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/13cc4d6fca1643d06e517680c99a1c44f58d1581

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/13cc4d6fca1643d06e517680c99a1c44f58d1581
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240110/a78c9492/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list