[Git][security-tracker-team/security-tracker][master] auto-nfu: Add Android

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 4 22:42:53 BST 2025



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
253ef968 by Moritz Muehlenhoff at 2025-09-04T23:42:43+02:00
auto-nfu: Add Android

Historically a lot of Linux issues were assigned via Android, but these
days they are exclusively assigned by the Linux kernel CNA.

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -23,83 +23,83 @@ CVE-2025-57576 (PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Sit
 CVE-2025-57263 (An authenticated SQL injection vulnerability in VX Guestbook 1.07 allo ...)
 	TODO: check
 CVE-2025-48581 (In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48563 (In onNullBinding of RemoteFillService.java, there is a possible backgr ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48562 (In writeContent of RemotePrintDocument.java, there is a possible infor ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48561 (In multiple locations, there is a possible way to access data displaye ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48560 (In AndroidManifest.xml, there is a possible way for an app to monitor  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48559 (In multiple functions of AppOpsService.java, there is a possible add a ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48558 (In multiple functions of BatteryService.java, there is a possible way  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48556 (In multiple methods of NotificationChannel.java, there is a possible d ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48554 (In handlePackagesChanged of DevicePolicyManagerService.java, there is  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48553 (In handlePackagesChanged of DevicePolicyManagerService.java, there is  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48552 (In saveGlobalProxyLocked of DevicePolicyManagerService.java, there is  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48551 (In multiple locations, there is a possible leak of an image across the ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48550 (In testGrantSlicePermission of SliceManagerTest.java, there is a possi ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48549 (In multiple locations, there is a possible way to record audio via a b ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48548 (In multiple functions of AppOpsControllerImpl.java, there is a possibl ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48547 (In multiple locations, there is a possible one-time permission bypass  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48546 (In checkPermissions of SafeActivityOptions.java, there is a possible b ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48545 (In isSystemUid of AccountManagerService.java, there is a possible way  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48544 (In multiple locations, there is a possible way to read files belonging ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48543 (In multiple locations, there is a possible way to escape chrome sandbo ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48542 (In multiple functions of AccountManagerService.java, there is a possib ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48541 (In onCreate of FaceSettings.java, there is a possible way to remove bi ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48540 (In processTransactInternal of RpcState.cpp, there is a possible local  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48539 (In SendPacketToPeer of acl_arbiter.cc, there is a possible out of boun ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48538 (In setApplicationHiddenSettingAsUser of PackageManagerService.java, th ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48537 (In multiple locations, there is a possible way to persistently DoS the ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48535 (In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , t ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48534 (In getDefaultCBRPackageName of CellBroadcastHandler.java, there is a p ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48533 (In multiple locations, there is a possible way to use apps linked from ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48532 (In markMediaAsFavorite of MediaProvider.java, there is a possible way  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48531 (In getCallingPackageName of CredentialStorage, there is a possible per ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48530 (In multiple locations, there is a possible condition that results in O ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48529 (In setRingtoneUri of VoicemailNotificationSettingsUtil.java , there is ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48528 (In multiple locations, there is a possible way to overlay biometrics d ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48527 (In multiple locations, there is a possible way to leak hidden work pro ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48526 (In createMultiProfilePagerAdapter of ChooserActivity.java , there is a ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48524 (In isSystem of WifiPermissionsUtil.java, there is a possible permissio ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48523 (In onCreate of SelectAccountActivity.java, there is a possible way to  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-48522 (In setDisplayName of AssociationRequest.java, there is a possible way  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-41063 (A vulnerability has been discovered in version 4.0.5 of appRain CMF, c ...)
 	TODO: check
 CVE-2025-41062 (A vulnerability has been discovered in version 4.0.5 of appRain CMF, c ...)
@@ -165,39 +165,39 @@ CVE-2025-41033 (An SQL injection vulnerability has been found in appRain CMF 4.0
 CVE-2025-41032 (An SQL injection vulnerability has been found in appRain CMF 4.0.5. Th ...)
 	TODO: check
 CVE-2025-32350 (In maybeShowDialog of ControlsSettingsDialogManager.kt, there is a pos ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-32349 (In multiple locations, there is a possible privilege escalation due to ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-32347 (In onStart of BiometricEnrollIntroduction.java, there is a possible wa ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-32346 (In onActivityResult of VoicemailSettingsActivity.java, there is a poss ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-32345 (In updateState of ContentProtectionTogglePreferenceController.java, th ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-32333 (In startSpaActivityForApp of SpaActivity.kt, there is a possible cross ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-32332 (In multiple locations, there is a possible memory corruption due to a  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-32331 (In showDismissibleKeyguard of KeyguardService.java, there is a possibl ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-32330 (In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-32327 (In multiple functions of PickerDbFacade.java, there is a possible unau ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-32326 (In multiple functions of AppRestrictionsFragment.java, there is a poss ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-32325 (In appendFrom of Parcel.cpp, there is a possible out of bounds write d ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-32324 (In onCommand of ActivityManagerShellCommand.java, there is a possible  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-32323 (In getCallingAppName of Shared.java, there is a possible way to trick  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-32322 (In onCreate of MediaProjectionPermissionActivity.java , there is a pos ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-32321 (In isSafeIntent of AccountTypePreferenceLoader.java, there is a possib ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-32312 (In createIntentsList of PackageParser.java , there is a possible way t ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-2694 (IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 thro ...)
 	NOT-FOR-US: IBM
 CVE-2025-2667 (IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 thro ...)
@@ -205,79 +205,79 @@ CVE-2025-2667 (IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0
 CVE-2025-2411 (Improper Restriction of Excessive Authentication Attempts vulnerabilit ...)
 	TODO: check
 CVE-2025-26464 (In executeAppFunction of AppSearchManagerService.java, there is a poss ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26463 (In allowPackageAccess of multiple files, resource exhaustion is possib ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26462 (In AccessibilityServiceConnection.java, there is a possible background ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26458 (In multiple functions of LocationProviderManager.java, there is a poss ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26456 (In multiple functions of DexUseManagerLocal.java, there is a possible  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26455 (In multiple functions of NdkMediaCodec.cpp, there is a possible out of ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26454 (In validateUriSchemeAndPermission of DisclaimersParserImpl.java , ther ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26453 (In isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26452 (In loadDrawableForCookie of ResourcesImpl.java, there is a possible wa ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26450 (In onInputEvent of IInputMethodSessionWrapper.java, there is a possibl ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26449 (In multiple locations, there is a possible permanent denial of service ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26448 (In writeToParcel of CursorWindow.cpp, there is a possible out of bound ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26445 (In offerNetwork of ConnectivityService.java, there is a possible leak  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26444 (In onHandleForceStop of VoiceInteractionManagerService.java, there is  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26443 (In parseHtml of HtmlToSpannedParser.java, there is a possible way to i ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26442 (In onCreate of NotificationAccessConfirmationActivity.java, there is a ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26441 (In add_attr of sdp_discovery.cc, there is a possible out of bounds rea ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26440 (In multiple functions of CameraService.cpp, there is a possible way to ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26439 (In getComponentName of AccessibilitySettingsUtils.java, there is a pos ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26438 (In smp_process_secure_connection_oob_data of smp_act.cc, there is a po ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26437 (In CredentialManagerServiceStub of CredentialManagerService.java, ther ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26436 (In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26435 (In updateState of ContentProtectionTogglePreferenceController.java, th ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26432 (In multiple locations, there is a possible way to persistently DoS the ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26431 (In setupAccessibilityServices of AccessibilityFragment.java, there is  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26430 (In getDestinationForApp of SpaAppBridgeActivity, there is a possible c ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26429 (In collectOps of AppOpsService.java, there is a possible way to cause  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26428 (In startLockTaskMode of LockTaskController.java, there is a possible l ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26427 (In multiple locations, there is a possible Android/data access due to  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26426 (In BroadcastController.java of registerReceiverWithFeatureTraced, ther ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26425 (In multiple functions of RoleService.java, there is a possible permiss ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26424 (In multiple functions of VpnManager.java, there is a possible cross-us ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26423 (In validateIpConfiguration of WifiConfigurationUtil.java, there is a p ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26422 (In dump of WindowManagerService.java, there is a possible way of runni ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26421 (In multiple locations, there is a possible lock screen bypass due to a ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26420 (In multiple functions of GrantPermissionsActivity.java , there is a po ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-26419 (In initPhoneSwitch of SystemSettingsFragment.java, there is a possible ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-25048 (IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 i ...)
 	NOT-FOR-US: IBM
 CVE-2025-23302 (NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of ...)
@@ -297,37 +297,37 @@ CVE-2025-23257 (NVIDIA DOCA contains a vulnerability in the collectx-clxapidev D
 CVE-2025-23256 (NVIDIA BlueField contains a vulnerability in the management interface, ...)
 	TODO: check
 CVE-2025-22441 (In getContextForResourcesEnsuringCorrectCachedApkPaths of RemoteViews. ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22425 (In onCreate of InstallStart.java, there is a possible permissions bypa ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22415 (In android_app of Android.bp, there is a possible way to launch any ac ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22414 (In FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a p ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-0089 (In multiple locations, there is a possible way to hijack the Launcher  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-0087 (In onCreate of UninstallerActivity.java, there is a possible way to un ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-0077 (In multiple functions of UserController.java, there is a possible lock ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-0076 (In multiple locations, there is a possible way to view icons belonging ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2024-49739 (In MMapVAccess of pmr_os.c, there is a possible out of bounds write du ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2024-49731 (In apk-versions.txt, there is a possible corruption of telemetry opt-i ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2024-49714 (In avrc_vendor_msg of avrc_opt.cc, there is a possible out of bounds w ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2024-43184 (IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 i ...)
 	NOT-FOR-US: IBM
 CVE-2024-40664 (In setupAccessibilityServices of AccessibilityFragment.java , there is ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2024-34598 (Improper export of component in GoodLock prior to version 2.2.04.95 al ...)
 	NOT-FOR-US: Samsung Mobile
 CVE-2024-13073 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
 	TODO: check
 CVE-2023-35657 (In bta_av_config_ind of bta_av_aact.cc, there is a possible out of bou ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-38730 (In the Linux kernel, the following vulnerability has been resolved:  i ...)
 	- linux 6.16.3-1
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
@@ -1028,45 +1028,45 @@ CVE-2025-57806 (Local Deep Research is an AI-powered research assistant for deep
 CVE-2025-54588 (Envoy is an open source L7 proxy and communication bus designed for la ...)
 	- envoyproxy <itp> (bug #987544)
 CVE-2025-26416 (In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible o ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22442 (In multiple functions of DevicePolicyManagerService.java, there is a p ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22439 (In onLastAccessedStackLoaded of ActionHandler.java , there is a possib ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22438 (In afterKeyEventLockedInterruptable of InputDispatcher.cpp, there is a ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22437 (In setMediaButtonReceiver of multiple files, there is a possible way t ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22435 (In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22434 (In handleKeyGestureEvent of PhoneWindowManager.java, there is a possib ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22433 (In canForward of IntentForwarderActivity.java, there is a possible byp ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22431 (In multiple locations, there is a possible method for a malicious app  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22430 (In isInSignificantPlace of multiple files, there is a possible way to  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22429 (In multiple locations, there is a possible way to execute arbitrary co ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22428 (In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22427 (In onCreate of NotificationAccessConfirmationActivity.java, there is a ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22423 (In ParseTag of dng_ifd.cpp, there is a possible way to crash the image ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22422 (In multiple locations, there is a possible way to mislead a user into  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22421 (In contentDescForNotification of NotificationContentDescription.kt, th ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22419 (In multiple locations, there is a possible way to mislead the user int ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22418 (In multiple locations, there is a possible confused deputy due to Inte ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22417 (In finishTransition of Transition.java, there is a possible way to byp ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-22416 (In onCreate of ChooserActivity.java , there is a possible way to view  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2025-21041 (Insecure Storage of Sensitive Information in Secure Folder prior to An ...)
 	NOT-FOR-US: Samsung Mobile
 CVE-2025-21040 (Improper verification of intent by ExternalBroadcastReceiver in S Assi ...)
@@ -1102,15 +1102,15 @@ CVE-2025-21026 (Improper handling of insufficient permission in ImsService prior
 CVE-2025-21025 (Improper access control in MARsExemptionManager prior to SMR Sep-2025  ...)
 	NOT-FOR-US: Samsung Mobile
 CVE-2024-49730 (In FuseDaemon.cpp, there is a possible out of bounds write due to memo ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2024-49728 (In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possi ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2024-49722 (In showAvatarPicker of EditUserPhotoController.java, there is a possib ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2024-49720 (In multiple functions of Permissions.java, there is a possible way to  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2024-40653 (In multiple functions of ConnectionServiceWrapper.java, there is a pos ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2024-32444 (Incorrect Privilege Assignment vulnerability in InspiryThemes RealHome ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2023-3666 (The Sticky Side Buttons WordPress plugin before 2.0.0 does not sanitis ...)


=====================================
data/packages/nfu.yaml
=====================================
@@ -13,6 +13,8 @@
   cna: AMZN
 - reason: AMI
   cna: AMI
+- reason: Android
+  cna: google_android
 - reason: Apple
   cna: apple
 - reason: ASR Microelectronics



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/253ef9686ab86224f9f7348b380b45d3ffbf2aac

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/253ef9686ab86224f9f7348b380b45d3ffbf2aac
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250904/c1faaab6/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list