[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Apr 30 13:33:59 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7c06bc1a by Salvatore Bonaccorso at 2025-04-30T14:33:48+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -77,7 +77,7 @@ CVE-2025-46550 (YesWiki is a wiki system written in PHP. Prior to version 4.5.4,
 CVE-2025-46549 (YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an at ...)
 	NOT-FOR-US: YesWiki
 CVE-2025-46350 (YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an at ...)
-	TODO: check
+	NOT-FOR-US: YesWiki
 CVE-2025-46349 (YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWi ...)
 	NOT-FOR-US: YesWiki
 CVE-2025-46348 (YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the r ...)
@@ -129,9 +129,9 @@ CVE-2025-30202 (vLLM is a high-throughput and memory-efficient inference and ser
 CVE-2025-29906 (Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 ...)
 	TODO: check
 CVE-2025-25962 (An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows ...)
-	TODO: check
+	NOT-FOR-US: Coresmartcontracts Uniswap
 CVE-2025-25403 (Slims (Senayan Library Management Systems) 9 Bulian V9.6.1 is vulnerab ...)
-	TODO: check
+	NOT-FOR-US: Slims (Senayan Library Management Systems)
 CVE-2025-23181 (CWE-250: Execution with Unnecessary Privileges)
 	TODO: check
 CVE-2025-23180 (CWE-250: Execution with Unnecessary Privileges)
@@ -151,13 +151,13 @@ CVE-2025-22882 (Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-
 CVE-2025-1551 (IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, and 9.0 ...)
 	NOT-FOR-US: IBM
 CVE-2025-1194 (A Regular Expression Denial of Service (ReDoS) vulnerability was ident ...)
-	TODO: check
+	NOT-FOR-US: huggingface/transformers
 CVE-2025-0716 (Improper sanitization of the value of the 'href' and 'xlink:href' attr ...)
 	TODO: check
 CVE-2025-0520 (An unrestricted file upload vulnerability in ShowDoc caused by imprope ...)
-	TODO: check
+	NOT-FOR-US: ShowDoc
 CVE-2024-57698 (An issue in modernwms v.1.0 allows an attacker view the MD5 hash of th ...)
-	TODO: check
+	NOT-FOR-US: modernwms
 CVE-2023-4377
 	REJECTED
 CVE-2025-4093 (Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7c06bc1a8b450ed11eb77655bf42406fa6eb88df

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7c06bc1a8b450ed11eb77655bf42406fa6eb88df
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250430/984b602c/attachment.htm>


More information about the debian-security-tracker-commits mailing list