[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon May 6 21:24:20 BST 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d4cf6cc5 by Salvatore Bonaccorso at 2024-05-06T22:23:44+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,143 +1,143 @@
 CVE-2024-4568 (In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources lea ...)
 	TODO: check
 CVE-2024-4549 (A denial of service vulnerability exists in Delta Electronics DIAEnerg ...)
-	TODO: check
+	NOT-FOR-US: Delta Electronics
 CVE-2024-4548 (An SQLi vulnerability exists inDelta Electronics DIAEnergie v1.10.1.86 ...)
-	TODO: check
+	NOT-FOR-US: Delta Electronics
 CVE-2024-4547 (A SQLi vulnerability exists inDelta ElectronicsDIAEnergie v1.10.1.8610 ...)
-	TODO: check
+	NOT-FOR-US: Delta Electronics
 CVE-2024-4528 (A vulnerability was found in SourceCodester Prison Management System 1 ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester Prison Management System
 CVE-2024-4527 (A vulnerability was found in Campcodes Complete Web-Based School Manag ...)
-	TODO: check
+	NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-4526 (A vulnerability was found in Campcodes Complete Web-Based School Manag ...)
-	TODO: check
+	NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-4525 (A vulnerability has been found in Campcodes Complete Web-Based School  ...)
-	TODO: check
+	NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-4524 (A vulnerability, which was classified as problematic, was found in Cam ...)
-	TODO: check
+	NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-4523 (A vulnerability, which was classified as problematic, has been found i ...)
-	TODO: check
+	NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-4522 (A vulnerability classified as problematic was found in Campcodes Compl ...)
-	TODO: check
+	NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-4521 (A vulnerability classified as problematic has been found in Campcodes  ...)
-	TODO: check
+	NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-4519 (A vulnerability was found in Campcodes Complete Web-Based School Manag ...)
-	TODO: check
+	NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-4518 (A vulnerability was found in Campcodes Complete Web-Based School Manag ...)
-	TODO: check
+	NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-4517 (A vulnerability was found in Campcodes Complete Web-Based School Manag ...)
-	TODO: check
+	NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-4516 (A vulnerability was found in Campcodes Complete Web-Based School Manag ...)
-	TODO: check
+	NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-4515 (A vulnerability has been found in Campcodes Complete Web-Based School  ...)
-	TODO: check
+	NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-4514 (A vulnerability, which was classified as problematic, was found in Cam ...)
-	TODO: check
+	NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-4513 (A vulnerability, which was classified as problematic, has been found i ...)
-	TODO: check
+	NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-4512 (A vulnerability classified as problematic was found in SourceCodester  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester Prison Management System
 CVE-2024-4511 (A vulnerability classified as critical has been found in Shanghai Sunf ...)
-	TODO: check
+	NOT-FOR-US: Shanghai Sunfull Automation BACnet Server
 CVE-2024-4510 (A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been ...)
-	TODO: check
+	NOT-FOR-US: Ruijie RG-UAC
 CVE-2024-4509 (A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been ...)
-	TODO: check
+	NOT-FOR-US: Ruijie RG-UAC
 CVE-2024-4508 (A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been ...)
-	TODO: check
+	NOT-FOR-US: Ruijie RG-UAC
 CVE-2024-4507 (A vulnerability was found in Ruijie RG-UAC up to 20240428 and classifi ...)
-	TODO: check
+	NOT-FOR-US: Ruijie RG-UAC
 CVE-2024-4506 (A vulnerability has been found in Ruijie RG-UAC up to 20240428 and cla ...)
-	TODO: check
+	NOT-FOR-US: Ruijie RG-UAC
 CVE-2024-4505 (A vulnerability, which was classified as critical, was found in Ruijie ...)
-	TODO: check
+	NOT-FOR-US: Ruijie RG-UAC
 CVE-2024-4504 (A vulnerability, which was classified as critical, has been found in R ...)
-	TODO: check
+	NOT-FOR-US: Ruijie RG-UAC
 CVE-2024-4503 (A vulnerability classified as critical was found in Ruijie RG-UAC up t ...)
-	TODO: check
+	NOT-FOR-US: Ruijie RG-UAC
 CVE-2024-4502 (A vulnerability classified as critical has been found in Ruijie RG-UAC ...)
-	TODO: check
+	NOT-FOR-US: Ruijie RG-UAC
 CVE-2024-3756 (The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-3755 (The MF Gig Calendar WordPress plugin through 1.2.1 does not sanitise a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-3752 (The Crelly Slider WordPress plugin through 1.4.5 does not sanitise and ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-3661 (By design, the DHCP protocol does not authenticate messages, including ...)
 	TODO: check
 CVE-2024-3576 (The NPort 5100A Series prior to version 1.6 is affected by web server  ...)
-	TODO: check
+	NOT-FOR-US: Moxa
 CVE-2024-34538 (Mateso PasswordSafe through 8.13.9.26689 has Weak Cryptography.)
-	TODO: check
+	NOT-FOR-US: Mateso PasswordSafe
 CVE-2024-34529 (Nebari through 2024.4.1 prints the temporary Keycloak root password.)
-	TODO: check
+	NOT-FOR-US: Nebari
 CVE-2024-34528 (WordOps through 3.20.0 has a wo/cli/plugins/stack_pref.py TOCTOU race  ...)
 	TODO: check
 CVE-2024-34527 (spaces_plugin/app.py in SolidUI 0.4.0 has an unnecessary print stateme ...)
 	TODO: check
 CVE-2024-34525 (FileCodeBox 2.0 stores a OneDrive password and AWS key in a cleartext  ...)
-	TODO: check
+	NOT-FOR-US: FileCodeBox
 CVE-2024-34524 (In XLANG OpenAgents through fe73ac4, the allowed_file protection mecha ...)
 	TODO: check
 CVE-2024-34519 (Avantra Server 24.x before 24.0.7 and 24.1.x before 24.1.1 mishandles  ...)
-	TODO: check
+	NOT-FOR-US: Avantra Server
 CVE-2024-34515 (image-optimizer before 1.7.3 allows PHAR deserialization, e.g., the ph ...)
 	TODO: check
 CVE-2024-34472 (An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18 ...)
-	TODO: check
+	NOT-FOR-US: HSC Mailinspector
 CVE-2024-34471 (An issue was discovered in HSC Mailinspector 5.2.17-3. A Path Traversa ...)
-	TODO: check
+	NOT-FOR-US: HSC Mailinspector
 CVE-2024-34470 (An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18 ...)
-	TODO: check
+	NOT-FOR-US: HSC Mailinspector
 CVE-2024-34466
 	REJECTED
 CVE-2024-34412 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34390 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34389 (Missing Authorization vulnerability in AF themes WP Post Author.This i ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34388 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34387 (Missing Authorization vulnerability in AF themes WP Post Author.This i ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34386 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34383 (Authorization Bypass Through User-Controlled Key vulnerability in The  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34382 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34381 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34380 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34379 (Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Restaura ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34378 (Missing Authorization vulnerability in LeadConnector.This issue affect ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34377 (Missing Authorization vulnerability in A WP Life Video Gallery \u2013  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34376 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34375 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34374 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34373 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34372 (Missing Authorization vulnerability in AddonMaster Post Grid Master.Th ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34371 (Missing Authorization vulnerability in Hamid Alinia \u2013 idehweb Log ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34369 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34368 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34367 (Cross-Site Request Forgery (CSRF) vulnerability in Popup Box Team Popu ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34366 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-34252 (wasm3 v0.5.0 was discovered to contain a global buffer overflow which  ...)
 	TODO: check
 CVE-2024-34251 (An out-of-bound memory read vulnerability was discovered in Bytecode A ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d4cf6cc54338d1f0862e4fe300d024d4b37540d0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d4cf6cc54338d1f0862e4fe300d024d4b37540d0
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240506/14b09514/attachment.htm>


More information about the debian-security-tracker-commits mailing list