[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 14 09:31:08 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
548ff8b2 by Salvatore Bonaccorso at 2025-08-14T10:30:48+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -41,9 +41,9 @@ CVE-2025-7808 (The WP Shopify WordPress plugin before 1.5.4 does not sanitise an
 CVE-2025-6790 (The Quiz and Survey Master (QSM)  WordPress plugin before 10.2.3 does  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-5942 (Netskope was notified about a potential gap in its agent (NS Client) o ...)
-	TODO: check
+	NOT-FOR-US: Netskope
 CVE-2025-5941 (Netskope is notified about a potential gap in its agent (NS Client) in ...)
-	TODO: check
+	NOT-FOR-US: Netskope
 CVE-2025-55199 (Helm is a package manager for Charts for Kubernetes. Prior to version  ...)
 	TODO: check
 CVE-2025-55198 (Helm is a package manager for Charts for Kubernetes. Prior to version  ...)
@@ -59,29 +59,29 @@ CVE-2025-55193 (Active Record connects classes to relational database tables. Pr
 CVE-2025-3414 (The Structured Content (JSON-LD) #wpsc WordPress plugin before 1.7.0 d ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-34154 (UnForm Server Manager versions prior to 10.1.12 expose an unauthentica ...)
-	TODO: check
+	NOT-FOR-US: UnForm Server Manager
 CVE-2025-27388 (Loading arbitrary external URLs through WebView components introduces  ...)
 	TODO: check
 CVE-2025-0309 (An insufficient validation on the server connection endpoint in Netsko ...)
-	TODO: check
+	NOT-FOR-US: Netskope
 CVE-2024-7402 (Netskope has identified a potential gap in its agent (Netskope Client) ...)
-	TODO: check
+	NOT-FOR-US: Netskope
 CVE-2012-10060 (Sysax Multi Server versions prior to 5.55 contains a stack-based buffe ...)
-	TODO: check
+	NOT-FOR-US: Sysax Multi Server
 CVE-2012-10059 (Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authent ...)
-	TODO: check
+	- dolibarr <removed>
 CVE-2012-10058 (RabidHamster R4 v1.25 contains astack-based buffer overflow vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: RabidHamster
 CVE-2012-10057 (Lattice Semiconductor ispVM System v18.0.2 contains a buffer overflow  ...)
 	TODO: check
 CVE-2012-10056 (PHP Volunteer Management System v1.0.2 contains an arbitrary file uplo ...)
-	TODO: check
+	NOT-FOR-US: PHP Volunteer Management System
 CVE-2012-10055 (ComSndFTP FTP Server version 1.3.7 Beta contains a format string vulne ...)
-	TODO: check
+	NOT-FOR-US: ComSndFTP FTP Server
 CVE-2012-10054 (Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated  ...)
 	NOT-FOR-US: Umbraco CMS
 CVE-2011-10019 (Spreecommerce versions prior to 0.60.2 contains a remote command execu ...)
-	TODO: check
+	NOT-FOR-US: Spreecommerce
 CVE-2011-10018 (myBB version 1.6.4 was distributed with an unauthorized backdoor embed ...)
 	TODO: check
 CVE-2011-10017 (Snort Report versions < 1.3.2 contains a remote command execution vuln ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/548ff8b2d5f67333cf6e6a09cd0d4db3b162536d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/548ff8b2d5f67333cf6e6a09cd0d4db3b162536d
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250814/b19871b2/attachment.htm>


More information about the debian-security-tracker-commits mailing list