[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Apr 30 13:33:59 BST 2025
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7c06bc1a by Salvatore Bonaccorso at 2025-04-30T14:33:48+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -77,7 +77,7 @@ CVE-2025-46550 (YesWiki is a wiki system written in PHP. Prior to version 4.5.4,
CVE-2025-46549 (YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an at ...)
NOT-FOR-US: YesWiki
CVE-2025-46350 (YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an at ...)
- TODO: check
+ NOT-FOR-US: YesWiki
CVE-2025-46349 (YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWi ...)
NOT-FOR-US: YesWiki
CVE-2025-46348 (YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the r ...)
@@ -129,9 +129,9 @@ CVE-2025-30202 (vLLM is a high-throughput and memory-efficient inference and ser
CVE-2025-29906 (Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 ...)
TODO: check
CVE-2025-25962 (An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows ...)
- TODO: check
+ NOT-FOR-US: Coresmartcontracts Uniswap
CVE-2025-25403 (Slims (Senayan Library Management Systems) 9 Bulian V9.6.1 is vulnerab ...)
- TODO: check
+ NOT-FOR-US: Slims (Senayan Library Management Systems)
CVE-2025-23181 (CWE-250: Execution with Unnecessary Privileges)
TODO: check
CVE-2025-23180 (CWE-250: Execution with Unnecessary Privileges)
@@ -151,13 +151,13 @@ CVE-2025-22882 (Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-
CVE-2025-1551 (IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, and 9.0 ...)
NOT-FOR-US: IBM
CVE-2025-1194 (A Regular Expression Denial of Service (ReDoS) vulnerability was ident ...)
- TODO: check
+ NOT-FOR-US: huggingface/transformers
CVE-2025-0716 (Improper sanitization of the value of the 'href' and 'xlink:href' attr ...)
TODO: check
CVE-2025-0520 (An unrestricted file upload vulnerability in ShowDoc caused by imprope ...)
- TODO: check
+ NOT-FOR-US: ShowDoc
CVE-2024-57698 (An issue in modernwms v.1.0 allows an attacker view the MD5 hash of th ...)
- TODO: check
+ NOT-FOR-US: modernwms
CVE-2023-4377
REJECTED
CVE-2025-4093 (Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7c06bc1a8b450ed11eb77655bf42406fa6eb88df
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7c06bc1a8b450ed11eb77655bf42406fa6eb88df
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250430/984b602c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list