[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jan 16 06:39:10 GMT 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7b7084c0 by Salvatore Bonaccorso at 2025-01-16T07:38:43+01:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,111 +1,111 @@
 CVE-2025-23040 (GitHub Desktop is an open-source Electron-based GitHub app designed fo ...)
 	TODO: check
 CVE-2025-22968 (An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execu ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2025-22799 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22798 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22797 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22795 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22793 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22788 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22787 (Missing Authorization vulnerability in bPlugins LLC Button Block allow ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22786 (Path Traversal vulnerability in ElementInvader ElementInvader Addons f ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22785 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22784 (Cross-Site Request Forgery (CSRF) vulnerability in Johan Str\xf6m Back ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22782 (Unrestricted Upload of File with Dangerous Type vulnerability in Web R ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22781 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22780 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22779 (Missing Authorization vulnerability in Ugur CELIK WP News Sliders allo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22778 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22776 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22773 (Insertion of Sensitive Information into Externally-Accessible File or  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22769 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22766 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22765 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22764 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22762 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22761 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22760 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22759 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22758 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22755 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22754 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22753 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22752 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22751 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22750 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22749 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22748 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22747 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22746 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22745 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22744 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22743 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22742 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22738 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22737 (Missing Authorization vulnerability in MagePeople Team WpTravelly allo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22736 (Incorrect Privilege Assignment vulnerability in WPExperts User Managem ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22734 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22731 (Cross-Site Request Forgery (CSRF) vulnerability in silverplugins217 Bu ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22729 (Missing Authorization vulnerability in Infomaniak Staff VOD Infomaniak ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22724 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22587 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22346 (Server-Side Request Forgery (SSRF) vulnerability in Faizaan Gagan Cour ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22329 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22317 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-22146 (Sentry is a developer-first error tracking and performance monitoring  ...)
-	TODO: check
+	NOT-FOR-US: Sentry
 CVE-2025-21630 (In the Linux kernel, the following vulnerability has been resolved:  i ...)
 	- linux 6.12.9-1
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
@@ -118,41 +118,41 @@ CVE-2025-21629 (In the Linux kernel, the following vulnerability has been resolv
 CVE-2025-21088 (Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0 ...)
 	- mattermost-server <itp> (bug #823556)
 CVE-2025-21083 (Mattermost Mobile Apps versions <=2.22.0 fail to properly validate pos ...)
-	TODO: check
+	NOT-FOR-US: Mattermost Mobile Apps
 CVE-2025-20088 (Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0 ...)
 	- mattermost-server <itp> (bug #823556)
 CVE-2025-20086 (Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0 ...)
 	- mattermost-server <itp> (bug #823556)
 CVE-2025-20036 (Mattermost Mobile Apps versions <=2.22.0 fail to properly validate pos ...)
-	TODO: check
+	NOT-FOR-US: Mattermost Mobile Apps
 CVE-2025-0502 (Transmission of Private Resources into a New Sphere ('Resource Leak')  ...)
-	TODO: check
+	NOT-FOR-US: CrafterCMS
 CVE-2025-0501 (An issue in the native clients for Amazon WorkSpaces Clients when runn ...)
 	TODO: check
 CVE-2025-0500 (An issue in the native clients for Amazon WorkSpaces, Amazon AppStream ...)
 	TODO: check
 CVE-2025-0485 (A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been ...)
-	TODO: check
+	NOT-FOR-US: Fanli2012 native-php-cms
 CVE-2025-0484 (A vulnerability was found in Fanli2012 native-php-cms 1.0 and classifi ...)
-	TODO: check
+	NOT-FOR-US: Fanli2012 native-php-cms
 CVE-2025-0483 (A vulnerability has been found in Fanli2012 native-php-cms 1.0 and cla ...)
-	TODO: check
+	NOT-FOR-US: Fanli2012 native-php-cms
 CVE-2025-0482 (A vulnerability, which was classified as critical, was found in Fanli2 ...)
-	TODO: check
+	NOT-FOR-US: Fanli2012 native-php-cms
 CVE-2025-0481 (A vulnerability classified as problematic has been found in D-Link DIR ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2025-0480 (A vulnerability classified as problematic has been found in wuzhicms 4 ...)
-	TODO: check
+	NOT-FOR-US: wuzhicms
 CVE-2025-0193 (A stored Cross-site Scripting (XSS) vulnerability exists in the MGate  ...)
-	TODO: check
+	NOT-FOR-US: Moxa
 CVE-2024-9636 (The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-8603 (A \u201cUse of a Broken or Risky Cryptographic Algorithm\u201d vulnera ...)
-	TODO: check
+	NOT-FOR-US: B&R Automation
 CVE-2024-7085 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
-	TODO: check
+	NOT-FOR-US: OpenText
 CVE-2024-5198 (OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged loca ...)
-	TODO: check
+	NOT-FOR-US: OpenVPN ovpn-dco for Windows
 CVE-2024-57903 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
 	- linux 6.12.9-1
 	[bookworm] - linux 6.1.124-1
@@ -263,43 +263,43 @@ CVE-2024-57795 (In the Linux kernel, the following vulnerability has been resolv
 	- linux 6.12.9-1
 	NOTE: https://git.kernel.org/linus/2ac5415022d16d63d912a39a06f32f1f51140261 (6.13-rc6)
 CVE-2024-57025 (TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an O ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2024-57024 (TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an O ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2024-57023 (TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an O ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2024-57022 (TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an O ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2024-57021 (TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an O ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2024-57020 (TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an O ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2024-57019 (TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an O ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2024-57018 (TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an O ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2024-57017 (TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an O ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2024-57016 (TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an O ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2024-57015 (TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an O ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2024-57014 (TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an O ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2024-57013 (TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an O ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2024-57012 (TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an O ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2024-57011 (TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an O ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2024-56295 (Missing Authorization vulnerability in Poll Maker Team Poll Maker allo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-54540 (The issue was addressed with improved input sanitization. This issue i ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2024-54535 (A path handling issue was addressed with improved logic. This issue is ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2024-54470 (A logic issue was addressed with improved checks. This issue is fixed  ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2024-54031 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
 	- linux 6.12.9-1
 	[bookworm] - linux 6.1.124-1
@@ -310,27 +310,27 @@ CVE-2024-53681 (In the Linux kernel, the following vulnerability has been resolv
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/4db3d750ac7e894278ef1cb1c53cc7d883060496 (6.13-rc6)
 CVE-2024-52783 (Insecure permissions in the XNetSocketClient component of XINJE XDPPro ...)
-	TODO: check
+	NOT-FOR-US: XINJE XDPPro.exe
 CVE-2024-52005 (Git is a source code management tool. When cloning from a server (or f ...)
 	TODO: check
 CVE-2024-50954 (The XINJE XL5E-16T and XD5E-24R-E programmable logic controllers V3.5. ...)
-	TODO: check
+	NOT-FOR-US: XINJE
 CVE-2024-50953 (An issue in XINJE XL5E-16T V3.7.2a allows attackers to cause a Denial  ...)
-	TODO: check
+	NOT-FOR-US: XINJE
 CVE-2024-47140 (A cross-site scripting (xss) vulnerability exists in the add_alert_che ...)
-	TODO: check
+	NOT-FOR-US: Observium
 CVE-2024-47002 (A html code injection vulnerability exists in the vlan management part ...)
-	TODO: check
+	NOT-FOR-US: Observium
 CVE-2024-45061 (A cross-site scripting (xss) vulnerability exists in the weather map e ...)
-	TODO: check
+	NOT-FOR-US: Observium
 CVE-2024-44136 (This issue was addressed through improved state management. This issue ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2024-40854 (A memory initialization issue was addressed with improved memory handl ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2024-40839 (This issue was addressed through improved state management. This issue ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2024-40771 (The issue was addressed with improved memory handling. This issue is f ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2024-39282 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
 	- linux 6.12.9-1
 	[bookworm] - linux 6.1.124-1
@@ -341,33 +341,33 @@ CVE-2024-36476 (In the Linux kernel, the following vulnerability has been resolv
 	[bookworm] - linux 6.1.124-1
 	NOTE: https://git.kernel.org/linus/fb514b31395946022f13a08e06a435f53cf9e8b3 (6.13-rc6)
 CVE-2024-35280 (A improper neutralization of input during web page generation ('cross- ...)
-	TODO: check
+	NOT-FOR-US: FortiGuard
 CVE-2024-27856 (The issue was addressed with improved checks. This issue is fixed in m ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2024-13351 (The Social proof testimonials and reviews by Repuso plugin for WordPre ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-13215 (The Elementor Addon Elements plugin for WordPress is vulnerable to Sen ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-12818 (The WP Smart TV plugin for WordPress is vulnerable to Stored Cross-Sit ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-12593 (The PDF for WPForms + Drag and Drop Template Builder plugin for WordPr ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-12423 (The Contact Form 7 Redirect & Thank You Page plugin for WordPress is v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-12403 (The Image Gallery \u2013 Responsive Photo Gallery plugin for WordPress ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-12297 (Moxa\u2019s Ethernet switch EDS-508A Series, running firmware version  ...)
-	TODO: check
+	NOT-FOR-US: Moxa
 CVE-2024-11851 (The NitroPack plugin for WordPress is vulnerable to unauthorized arbit ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-11848 (The NitroPack plugin for WordPress is vulnerable to unauthorized modif ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-11322 (A denial-of-service vulnerability exists in CyberPower PowerPanel Busi ...)
 	TODO: check
 CVE-2024-11029 (A flaw was found in the FreeIPA API audit, where it sends the whole Fr ...)
 	TODO: check
 CVE-2024-10775 (The Piotnet Addons For Elementor plugin for WordPress is vulnerable to ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23061 (Mongoose before 8.9.5 can improperly use a nested $where filter with a ...)
 	NOT-FOR-US: Mongoose
 CVE-2025-23013 (In Yubico pam-u2f before 1.3.1, local privilege escalation can sometim ...)
@@ -1537,7 +1537,7 @@ CVE-2024-57616 (An issue in the vscanf component of MonetDB Server v11.47.11 all
 CVE-2024-57615 (An issue in the BATcalcbetween_intern component of MonetDB Server v11. ...)
 	NOT-FOR-US: MonetDB Server
 CVE-2024-56323 (OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1 ...)
-	TODO: check
+	NOT-FOR-US: OpenFGA
 CVE-2024-56138 (notion-go is a collection of libraries for supporting sign and verify  ...)
 	TODO: check
 CVE-2024-51491 (notion-go is a collection of libraries for supporting sign and verify  ...)
@@ -1551,7 +1551,7 @@ CVE-2024-13323 (The WP Booking Calendar plugin for WordPress is vulnerable to St
 CVE-2024-13154
 	REJECTED
 CVE-2024-12398 (An improper privilege management vulnerability in the web management i ...)
-	TODO: check
+	NOT-FOR-US: Zyxel
 CVE-2024-12365 (The W3 Total Cache plugin for WordPress is vulnerable to unauthorized  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-12298 (We found a vulnerability Improper Restriction of XML External Entity R ...)
@@ -1565,9 +1565,9 @@ CVE-2024-12006 (The W3 Total Cache plugin for WordPress is vulnerable to unautho
 CVE-2024-11637
 	REJECTED
 CVE-2024-11396 (The Event Monster \u2013 Event Management, Tickets Booking, Upcoming E ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-11128 (A vulnerability in the BitdefenderVirusScanner binary as used inBitdef ...)
-	TODO: check
+	NOT-FOR-US: Bitdefender
 CVE-2023-42250 (Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scr ...)
 	NOT-FOR-US: Selesta Visual Access Manager
 CVE-2023-42249 (Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scr ...)
@@ -383915,7 +383915,7 @@ CVE-2020-8096 (Untrusted Search Path vulnerability in Bitdefender High-Level Ant
 CVE-2020-8095 (A vulnerability in the improper handling of junctions before deletion  ...)
 	NOT-FOR-US: Bitdefender Total Security
 CVE-2020-8094 (An untrusted search path vulnerability in testinitsigs.exe as used in  ...)
-	TODO: check
+	NOT-FOR-US: Bitdefender
 CVE-2020-8093 (A vulnerability in the AntivirusforMac binary as used in Bitdefender A ...)
 	NOT-FOR-US: Bitdefender Antivirus for Mac
 CVE-2020-8092 (A privilege escalation vulnerability in BDLDaemon as used in Bitdefend ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7b7084c0cf7941ac49b6cf8869572f1ee39751f3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7b7084c0cf7941ac49b6cf8869572f1ee39751f3
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250116/1c8d3691/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list