[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 6 09:48:52 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
fbe2f1cf by Salvatore Bonaccorso at 2025-08-06T10:46:26+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,73 +1,73 @@
 CVE-2025-8656 (Kenwood DMX958XR Protection Mechanism Failure Software Downgrade Vulne ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8655 (Kenwood DMX958XR libSystemLib Command injection Remote Code Execution  ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8654 (Kenwood DMX958XR ReadMVGImage Command Injection Remote Code Execution  ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8653 (Kenwood DMX958XR JKRadioService Stack-based Buffer Overflow Remote Cod ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8652 (Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8651 (Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8650 (Kenwood DMX958XR libSystemLib Command Injection Remote Code Execution  ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8649 (Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8648 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8647 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8646 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8645 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8644 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8643 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8642 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8641 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8640 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8639 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8638 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8637 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8636 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8635 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8634 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8633 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8632 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8631 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8630 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8629 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8628 (Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Kenwood
 CVE-2025-8595 (The Zakra theme for WordPress is vulnerable to unauthorized data modif ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-8573 (Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS fro ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2025-8571 (Concrete CMS 9 to 9.4.2 and versions below 8.5.21 are vulnerable to Re ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2025-8420 (The Request a Quote Form plugin for WordPress is vulnerable to Remote  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-8100 (The Element Pack Elementor Addons and Templates plugin for WordPress i ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-7954 (A race condition vulnerability has been identified in Shopware's vouch ...)
-	TODO: check
+	NOT-FOR-US: Shopware
 CVE-2025-7727 (The Gutenverse plugin for WordPress is vulnerable to Stored Cross-Site ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-7502 (The WPBakery Page Builder for WordPress plugin for WordPress is vulner ...)
@@ -109,13 +109,13 @@ CVE-2025-55020
 CVE-2025-55019
 	REJECTED
 CVE-2025-54884 (Vision UI is a collection of enterprise-grade, dependency-free modules ...)
-	TODO: check
+	NOT-FOR-US: Vision UI
 CVE-2025-54883 (Vision UI is a collection of enterprise-grade, dependency-free modules ...)
-	TODO: check
+	NOT-FOR-US: Vision UI
 CVE-2025-54879 (Mastodon is a free, open-source social network server based on Activit ...)
 	TODO: check
 CVE-2025-54876 (The Janssen Project is an open-source identity and access management ( ...)
-	TODO: check
+	NOT-FOR-US: Janssen Project
 CVE-2025-54873 (RISC Zero is a zero-knowledge verifiable general computing platform ba ...)
 	TODO: check
 CVE-2025-54872 (onion-site-template is a complete, scalable tor hidden service self-ho ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fbe2f1cfa9b330413832febe81b00b4964660f27

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fbe2f1cfa9b330413832febe81b00b4964660f27
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250806/fe27c35d/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list