[Git][security-tracker-team/security-tracker][master] Process more NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Nov 21 09:19:50 GMT 2024
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
eaad350b by Salvatore Bonaccorso at 2024-11-21T10:15:06+01:00
Process more NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -35,35 +35,35 @@ CVE-2024-52797 (Opencast is free and open source software for automated video ca
CVE-2024-52796 (Password Pusher, an open source application to communicate sensitive i ...)
TODO: check
CVE-2024-52771 (DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vu ...)
- TODO: check
+ NOT-FOR-US: DedeBIZ
CVE-2024-52770 (An arbitrary file upload vulnerability in the component /admin/file_ma ...)
- TODO: check
+ NOT-FOR-US: DedeBIZ
CVE-2024-52769 (An arbitrary file upload vulnerability in the component /admin/friendl ...)
- TODO: check
+ NOT-FOR-US: DedeBIZ
CVE-2024-52765 (H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code executio ...)
- TODO: check
+ NOT-FOR-US: H3C GR-1800AX MiniGRW1B0V100R007
CVE-2024-52763 (A cross-site scripting (XSS) vulnerability in the component /graph_all ...)
TODO: check
CVE-2024-52762 (A cross-site scripting (XSS) vulnerability in the component /master/he ...)
TODO: check
CVE-2024-52757 (D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow ...)
- TODO: check
+ NOT-FOR-US: D-LINK
CVE-2024-52755 (D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow ...)
- TODO: check
+ NOT-FOR-US: D-LINK
CVE-2024-52754 (D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow ...)
- TODO: check
+ NOT-FOR-US: D-LINK
CVE-2024-52739 (D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote c ...)
- TODO: check
+ NOT-FOR-US: D-LINK
CVE-2024-52725 (SemCms v4.8 was discovered to contain a SQL injection vulnerability. T ...)
- TODO: check
+ NOT-FOR-US: SemCms
CVE-2024-52702 (A stored cross-site scripting (XSS) vulnerability in the component ins ...)
TODO: check
CVE-2024-52701 (A stored cross-site scripting (XSS) vulnerability in the Configuration ...)
TODO: check
CVE-2024-52677 (HkCms <= v2.3.2.240702 is vulnerable to file upload in the getFileName ...)
- TODO: check
+ NOT-FOR-US: HkCms
CVE-2024-52614 (Use of hard-coded cryptographic key issue exists in "Kura Sushi Offici ...)
- TODO: check
+ NOT-FOR-US: "Kura Sushi Official App Produced by EPARK" for Android
CVE-2024-52598 (2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts ...)
TODO: check
CVE-2024-52597 (2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts ...)
@@ -71,51 +71,51 @@ CVE-2024-52597 (2FAuth is a web app to manage Two-Factor Authentication (2FA) ac
CVE-2024-52595 (lxml_html_clean is a project for HTML cleaning functionalities copied ...)
TODO: check
CVE-2024-52581 (Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. ...)
- TODO: check
+ NOT-FOR-US: Litestar
CVE-2024-52473 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
- TODO: check
+ NOT-FOR-US: Sandeep Verma HTML5 Lyrics araoke Player
CVE-2024-52472 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52471 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52470 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52451 (Cross-Site Request Forgery (CSRF) vulnerability in Aaron Robbins Post ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52450 (Improper Control of Filename for Include/Require Statement in PHP Prog ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52449 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52448 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52447 (Path Traversal: '.../...//' vulnerability in Corporate Zen Contact Pag ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52446 (Cross-Site Request Forgery (CSRF) vulnerability in Buying Buddy Buying ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52445 (Deserialization of Untrusted Data vulnerability in Modeltheme QRMenu R ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52444 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52443 (Deserialization of Untrusted Data vulnerability in Nerijus Masikonis G ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52442 (Incorrect Privilege Assignment vulnerability in Userplus UserPlus allo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52441 (Improperly Controlled Modification of Object Prototype Attributes ('Pr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52440 (Deserialization of Untrusted Data vulnerability in Bueno Labs Pvt. Ltd ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52439 (Deserialization of Untrusted Data vulnerability in Mark O\u2019Donnell ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52438 (Missing Authentication for Critical Function vulnerability in deco.Age ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52437 (Missing Authentication for Critical Function vulnerability in Saul Mor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52392 (Cross-Site Request Forgery (CSRF) vulnerability in W3speedster W3SPEED ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52033 (Exposure of sensitive system information to an unauthorized control sp ...)
- TODO: check
+ NOT-FOR-US: Rakuten Turbo 5G firmware
CVE-2024-51669 (Cross-Site Request Forgery (CSRF) vulnerability in Vivwebs Dynamic Wid ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-51209 (Cross-Site Scripting (XSS) vulnerabilities in Anuj Kumar's Client Mana ...)
TODO: check
CVE-2024-51208 (File Upload vulnerability in change-image.php in Anuj Kumar's Boat Boo ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eaad350bf6ae552cb4a45c6624ae54aad5e49fc5
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eaad350bf6ae552cb4a45c6624ae54aad5e49fc5
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241121/4db21d48/attachment.htm>
More information about the debian-security-tracker-commits
mailing list