[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Nov 7 20:14:31 GMT 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
518441af by security tracker role at 2025-11-07T20:14:23+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2025-9458 (A maliciously crafted PRT file, when parsed through certain Autodesk p ...)
-	TODO: check
+	NOT-FOR-US: Autodesk
 CVE-2025-7719 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
-	TODO: check
+	NOT-FOR-US: GE Vernova
 CVE-2025-64432 (KubeVirt is a virtual machine management add-on for Kubernetes. Versio ...)
 	TODO: check
 CVE-2025-64431 (Zitadel is an open source identity management platform. Versions 4.0.0 ...)
@@ -17,15 +17,15 @@ CVE-2025-63784 (An Open Redirect vulnerability exists in the OAuth callback hand
 CVE-2025-63783 (A Broken Object Level Authorization (BOLA) vulnerability was discovere ...)
 	TODO: check
 CVE-2025-63718 (A SQL injection vulnerability exists in the SourceCodester PQMS (Patie ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-63717 (The change password functionality at /pet_grooming/admin/change_pass.p ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-63716 (The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-63714 (Cross-Site Scripting (XSS) vulnerability in SourceCodester User Accoun ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-63713 (Cross-Site Scripting (XSS) vulnerability in SourceCodester "MatchMaste ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-63691 (In pig-mesh In Pig version 3.8.2 and below, within the Token Managemen ...)
 	TODO: check
 CVE-2025-63690 (In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled ta ...)
@@ -37,77 +37,77 @@ CVE-2025-63687 (An issue was discovered in rymcu forest thru commit f782e85 (202
 CVE-2025-63686 (There is an arbitrary file download vulnerability in GuoMinJim PersonM ...)
 	TODO: check
 CVE-2025-63640 (Sourcecodester Medicine Reminder App v1.0 is vulnerable to Cross-Site  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-63639 (The chat feature in the application Sourcecodester FAQ Bot with AI Ass ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-63638 (Sourcecodester AI-Powered To-Do List App v1.0 is vulnerable to Cross-S ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-61261 (A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1 ...)
 	TODO: check
 CVE-2025-58469 (A cross-site request forgery (CSRF) vulnerability has been reported to ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2025-58465 (A cross-site scripting (XSS) vulnerability has been reported to affect ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2025-58464 (A relative path traversal vulnerability has been reported to affect Qu ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2025-58463 (A relative path traversal vulnerability has been reported to affect Do ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2025-57712 (A path traversal vulnerability has been reported to affect Qsync Centr ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2025-57706 (A cross-site scripting (XSS) vulnerability has been reported to affect ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2025-57698 (AstrBot Project v3.5.22 contains a directory traversal vulnerability.  ...)
 	TODO: check
 CVE-2025-57697 (AstrBot Project v3.5.22 has an arbitrary file read vulnerability in fu ...)
 	TODO: check
 CVE-2025-54168 (A cross-site scripting (XSS) vulnerability has been reported to affect ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2025-54167 (A cross-site scripting (XSS) vulnerability has been reported to affect ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2025-53413 (An allocation of resources without limits or throttling vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2025-53412 (A NULL pointer dereference vulnerability has been reported to affect F ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2025-53411 (An allocation of resources without limits or throttling vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2025-53410 (An allocation of resources without limits or throttling vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2025-53409 (An allocation of resources without limits or throttling vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2025-53408 (A NULL pointer dereference vulnerability has been reported to affect F ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2025-52865 (A NULL pointer dereference vulnerability has been reported to affect F ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2025-52425 (An SQL injection vulnerability has been reported to affect QuMagie. A  ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2025-47207 (A NULL pointer dereference vulnerability has been reported to affect s ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2025-46413 (Use of password hash with insufficient computational effort issue exis ...)
 	TODO: check
 CVE-2025-3222 (Improper Authentication vulnerability in GE Vernova Smallworld on Wind ...)
-	TODO: check
+	NOT-FOR-US: GE Vernova
 CVE-2025-36186 (IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-36185 (IBM Db2 12.1.0 through 12.1.2 for Linux, UNIX and Windows (includes Db ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-36136 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UN ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-36135 (IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-36131 (IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 thr ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-36008 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UN ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-36006 (IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 throug ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-34299 (Monsta FTP versions 2.11 and earlier contain a vulnerability that allo ...)
 	TODO: check
 CVE-2025-33012 (IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 throug ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-2534 (IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 thr ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-12890 (Improper handling of  malformed Connection Request with the interval s ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2025-12873 (A security flaw has been discovered in Campcodes School File Managemen ...)
 	TODO: check
 CVE-2025-12862 (A vulnerability was identified in projectworlds Online Notes Sharing P ...)
@@ -121,23 +121,23 @@ CVE-2025-12859 (A vulnerability has been found in DedeBIZ up to 6.3.2. This impa
 CVE-2025-12858
 	REJECTED
 CVE-2025-12857 (A security vulnerability has been detected in code-projects Responsive ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2025-12856 (A weakness has been identified in code-projects Responsive Hotel Site  ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2025-12855 (A security flaw has been discovered in code-projects Responsive Hotel  ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2025-12854 (A vulnerability was identified in newbee-mall-plus up to 2.4.1. This v ...)
 	TODO: check
 CVE-2025-12853 (A vulnerability was determined in SourceCodester Best House Rental Man ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-12829 (An uninitialized stack read issue exists in Amazon Ion-C versions <v1. ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2025-10968 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
 	TODO: check
 CVE-2025-10870 (SQL injection vulnerability in DIAL's CentrosNet v2.64. Allows an atta ...)
 	TODO: check
 CVE-2024-47118 (IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 throug ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-64346 (archives is a Go library for extracting archives (tar, zip, etc.). Ver ...)
 	NOT-FOR-US: jaredallard/archives Go library
 CVE-2025-64343 ((conda) Constructor is a tool that enables users to create installers  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/518441afe4927841ebe77935d24b949ce7b61348

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/518441afe4927841ebe77935d24b949ce7b61348
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251107/1cf0648e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list