[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Sep 2 15:09:58 BST 2024



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
12ebb3b6 by Moritz Muehlenhoff at 2024-09-02T16:08:49+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2024-8370 (A vulnerability classified as problematic was found in Grocy up to 4.2 ...)
-	TODO: check
+	NOT-FOR-US: Grocy
 CVE-2024-8365 (Vault Community Edition and Vault Enterprise experienced a regression  ...)
 	NOT-FOR-US: HashiCorp Vault
 CVE-2024-7871 (SQL Injection in online dictionary function of Easytest Online Test Pl ...)
@@ -15,9 +15,9 @@ CVE-2024-7354 (The Ninja Forms  WordPress plugin before 3.8.11 does not escape a
 CVE-2024-45528 (CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1. ...)
 	NOT-FOR-US: CodeAstro MembershipM-PHP (aka Membership Management System in PHP)
 CVE-2024-45527 (REDCap 14.7.0 allows HTML injection via the project title of a New Pro ...)
-	TODO: check
+	NOT-FOR-US: REDCap
 CVE-2024-45522 (Linen before cd37c3e does not verify that the domain is linen.dev or w ...)
-	TODO: check
+	NOT-FOR-US: Linen
 CVE-2024-45509 (In MISP through 2.4.196, app/Controller/BookmarksController.php does n ...)
 	NOT-FOR-US: MISP
 CVE-2024-45508 (HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ...)
@@ -37,33 +37,33 @@ CVE-2024-43773 (SQL Injection in download class learning course function of Easy
 CVE-2024-43772 (SQL Injection in download student learning course function of Easytest ...)
 	NOT-FOR-US: Easytest Online Test Platform
 CVE-2024-41160 (in OpenHarmony v4.1.0 and prior versions allow a local attacker cause  ...)
-	TODO: check
+	NOT-FOR-US: OpenHarmony
 CVE-2024-41157 (in OpenHarmony v4.1.0 and prior versions allow a local attacker cause  ...)
-	TODO: check
+	NOT-FOR-US: OpenHarmony
 CVE-2024-39816 (in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitr ...)
-	TODO: check
+	NOT-FOR-US: OpenHarmony
 CVE-2024-39775 (in OpenHarmony v4.1.0 and prior versions allow a remote attacker cause ...)
-	TODO: check
+	NOT-FOR-US: OpenHarmony
 CVE-2024-39612 (in OpenHarmony v4.0.0 and prior versions allow a local attacker cause  ...)
-	TODO: check
+	NOT-FOR-US: OpenHarmony
 CVE-2024-38386 (in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitr ...)
-	TODO: check
+	NOT-FOR-US: OpenHarmony
 CVE-2024-38382 (in OpenHarmony v4.0.0 and prior versions allow a local attacker cause  ...)
-	TODO: check
+	NOT-FOR-US: OpenHarmony
 CVE-2024-28044 (in OpenHarmony v4.1.0 and prior versions allow a local attacker cause  ...)
-	TODO: check
+	NOT-FOR-US: OpenHarmony
 CVE-2024-20089 (In wlan, there is a possible denial of service due to incorrect error  ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2024-20088 (In keyinstall, there is a possible out of bounds read due to a missing ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2024-20087 (In vdec, there is a possible out of bounds write due to a missing boun ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2024-20086 (In vdec, there is a possible out of bounds write due to a missing boun ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2024-20085 (In power, there is a possible out of bounds read due to a missing boun ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2024-20084 (In power, there is a possible out of bounds read due to a missing boun ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2024-5053 (The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & D ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-8368 (A vulnerability was found in code-projects Hospital Management System  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/12ebb3b61b39029e5ab869ca0c3a0e0a32739f5e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/12ebb3b61b39029e5ab869ca0c3a0e0a32739f5e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240902/8462edae/attachment.htm>


More information about the debian-security-tracker-commits mailing list