Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
76663717 by security tracker role at 2018-07-16T20:10:16+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -1,7 +1,175 @@
-CVE-2018-14326 [integer overflow when resizing MP4Array for the ftyp atom in 
mp4array.h]
+CVE-2018-14324 (The demo feature in Oracle GlassFish Open Source Edition 5.0 
has TCP ...)
+       TODO: check
+CVE-2018-14323
+       RESERVED
+CVE-2018-14322
+       RESERVED
+CVE-2018-14321
+       RESERVED
+CVE-2018-14320
+       RESERVED
+CVE-2018-14319
+       RESERVED
+CVE-2018-14318
+       RESERVED
+CVE-2018-14317
+       RESERVED
+CVE-2018-14316
+       RESERVED
+CVE-2018-14315
+       RESERVED
+CVE-2018-14314
+       RESERVED
+CVE-2018-14313
+       RESERVED
+CVE-2018-14312
+       RESERVED
+CVE-2018-14311
+       RESERVED
+CVE-2018-14310
+       RESERVED
+CVE-2018-14309
+       RESERVED
+CVE-2018-14308
+       RESERVED
+CVE-2018-14307
+       RESERVED
+CVE-2018-14306
+       RESERVED
+CVE-2018-14305
+       RESERVED
+CVE-2018-14304
+       RESERVED
+CVE-2018-14303
+       RESERVED
+CVE-2018-14302
+       RESERVED
+CVE-2018-14301
+       RESERVED
+CVE-2018-14300
+       RESERVED
+CVE-2018-14299
+       RESERVED
+CVE-2018-14298
+       RESERVED
+CVE-2018-14297
+       RESERVED
+CVE-2018-14296
+       RESERVED
+CVE-2018-14295
+       RESERVED
+CVE-2018-14294
+       RESERVED
+CVE-2018-14293
+       RESERVED
+CVE-2018-14292
+       RESERVED
+CVE-2018-14291
+       RESERVED
+CVE-2018-14290
+       RESERVED
+CVE-2018-14289
+       RESERVED
+CVE-2018-14288
+       RESERVED
+CVE-2018-14287
+       RESERVED
+CVE-2018-14286
+       RESERVED
+CVE-2018-14285
+       RESERVED
+CVE-2018-14284
+       RESERVED
+CVE-2018-14283
+       RESERVED
+CVE-2018-14282
+       RESERVED
+CVE-2018-14281
+       RESERVED
+CVE-2018-14280
+       RESERVED
+CVE-2018-14279
+       RESERVED
+CVE-2018-14278
+       RESERVED
+CVE-2018-14277
+       RESERVED
+CVE-2018-14276
+       RESERVED
+CVE-2018-14275
+       RESERVED
+CVE-2018-14274
+       RESERVED
+CVE-2018-14273
+       RESERVED
+CVE-2018-14272
+       RESERVED
+CVE-2018-14271
+       RESERVED
+CVE-2018-14270
+       RESERVED
+CVE-2018-14269
+       RESERVED
+CVE-2018-14268
+       RESERVED
+CVE-2018-14267
+       RESERVED
+CVE-2018-14266
+       RESERVED
+CVE-2018-14265
+       RESERVED
+CVE-2018-14264
+       RESERVED
+CVE-2018-14263
+       RESERVED
+CVE-2018-14262
+       RESERVED
+CVE-2018-14261
+       RESERVED
+CVE-2018-14260
+       RESERVED
+CVE-2018-14259
+       RESERVED
+CVE-2018-14258
+       RESERVED
+CVE-2018-14257
+       RESERVED
+CVE-2018-14256
+       RESERVED
+CVE-2018-14255
+       RESERVED
+CVE-2018-14254
+       RESERVED
+CVE-2018-14253
+       RESERVED
+CVE-2018-14252
+       RESERVED
+CVE-2018-14251
+       RESERVED
+CVE-2018-14250
+       RESERVED
+CVE-2018-14249
+       RESERVED
+CVE-2018-14248
+       RESERVED
+CVE-2018-14247
+       RESERVED
+CVE-2018-14246
+       RESERVED
+CVE-2018-14245
+       RESERVED
+CVE-2018-14244
+       RESERVED
+CVE-2018-14243
+       RESERVED
+CVE-2018-14242
+       RESERVED
+CVE-2018-14241
+       RESERVED
+CVE-2018-14326 (In MP4v2 2.0.0, there is an integer overflow (with resultant 
memory ...)
        - mp4v2 <unfixed>
        NOTE: http://www.openwall.com/lists/oss-security/2018/07/16/1
-CVE-2018-14325 [integer underflow when parsing MP4Atom in mp4atom.cpp]
+CVE-2018-14325 (In MP4v2 2.0.0, there is an integer underflow (with resultant 
memory ...)
        - mp4v2 <unfixed>
        NOTE: http://www.openwall.com/lists/oss-security/2018/07/16/1
 CVE-2018-14240
@@ -346,8 +514,8 @@ CVE-2018-14072 (libsixel 1.8.1 has a memory leak in 
sixel_decoder_decode in deco
        - libsixel <unfixed> (low; bug #903858)
        [stretch] - libsixel <no-dsa> (Minor issue)
        NOTE: https://github.com/saitoha/libsixel/issues/67#issue-341198610
-CVE-2018-14071
-       RESERVED
+CVE-2018-14071 (The Geo Mashup plugin before 1.10.4 for WordPress has 
insufficient ...)
+       TODO: check
 CVE-2018-14070
        RESERVED
 CVE-2018-14069 (An issue was discovered in SRCMS V2.3.1. There is a CSRF 
vulnerability ...)
@@ -594,10 +762,10 @@ CVE-2018-13983
        RESERVED
 CVE-2018-13982
        RESERVED
-CVE-2018-13981
-       RESERVED
-CVE-2018-13980
-       RESERVED
+CVE-2018-13981 (The websites that were built from Zeta Producer Desktop CMS 
before ...)
+       TODO: check
+CVE-2018-13980 (The websites that were built from Zeta Producer Desktop CMS 
before ...)
+       TODO: check
 CVE-2018-13979
        RESERVED
 CVE-2018-13978
@@ -1870,8 +2038,8 @@ CVE-2018-13389 (The attachment resource in Atlassian 
Confluence before version 6
        NOT-FOR-US: Atlassian Confluence
 CVE-2018-13388 (The review attachment resource in Atlassian Fisheye and 
Crucible ...)
        NOT-FOR-US: Atlassian Fisheye and Crucible
-CVE-2018-13387
-       RESERVED
+CVE-2018-13387 (The IncomingMailServers resource in Atlassian JIRA Server 
before ...)
+       TODO: check
 CVE-2018-13386
        RESERVED
 CVE-2018-13385
@@ -6094,10 +6262,10 @@ CVE-2016-1000344 (In the Bouncy Castle JCE Provider 
version 1.55 and earlier the
        - bouncycastle 1.56-1
        [jessie] - bouncycastle <ignored> (Intrusive changes, can be mitigated 
by using a different mode than ECB)
        NOTE: 
https://github.com/bcgit/bc-java/commit/9385b0ebd277724b167fe1d1456e3c112112be1f
-CVE-2018-11717
-       RESERVED
-CVE-2018-11716
-       RESERVED
+CVE-2018-11717 (An issue was discovered in Zoho ManageEngine Desktop Central 
before ...)
+       TODO: check
+CVE-2018-11716 (An issue was discovered in Zoho ManageEngine Desktop Central 
before ...)
+       TODO: check
 CVE-2018-11715 (The Recent Threads plugin before 1.1 for MyBB allows XSS via a 
thread ...)
        NOT-FOR-US: Recent Threads plugin for MyBB
 CVE-2018-11714 (An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 
3.16 ...)
@@ -8290,8 +8458,7 @@ CVE-2018-10887 (A flaw was found in libgit2 before 
version 0.27.3. It has been .
        - libgit2 <unfixed> (bug #903509)
        NOTE: 
https://github.com/libgit2/libgit2/commit/3f461902dc1072acb8b7607ee65d0a0458ffac2a
        NOTE: 
https://github.com/libgit2/libgit2/commit/c1577110467b701dcbcf9439ac225ea851b47d22
-CVE-2018-10886
-       RESERVED
+CVE-2018-10886 (ant before version 1.9.12 unzip and untar targets allows the 
...)
        - ant 1.10.4-1
        NOTE: Fixed upstream in 1.9.12 and 1.10.4
        NOTE: 
https://github.com/apache/ant/commit/e56e54565804991c62ec76dad385d2bdda8972a7
@@ -8403,8 +8570,7 @@ CVE-2018-10860 (perl-archive-zip is vulnerable to a 
directory traversal in ...)
        - libarchive-zip-perl <unfixed> (bug #902882)
        NOTE: https://github.com/redhotpenguin/perl-Archive-Zip/pull/33
        NOTE: 
https://github.com/redhotpenguin/perl-Archive-Zip/commit/95e1df86327
-CVE-2018-10859
-       RESERVED
+CVE-2018-10859 (git-annex is vulnerable to an Information Exposure when 
decrypting ...)
        - git-annex 6.20180626-1
        [stretch] - git-annex 6.20170101-1+deb9u2
        NOTE: http://www.openwall.com/lists/oss-security/2018/06/26/4
@@ -24191,8 +24357,8 @@ CVE-2018-5241 (Symantec Advanced Secure Gateway (ASG) 
6.6 and 6.7, and ProxySG 6
        NOT-FOR-US: Symantec
 CVE-2018-5240
        RESERVED
-CVE-2018-5239
-       RESERVED
+CVE-2018-5239 (Norton App Lock prior to v1.3.0.332 can be susceptible to a 
bypass ...)
+       TODO: check
 CVE-2018-5238
        RESERVED
 CVE-2018-5237 (Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 
MP10 ...)
@@ -24219,8 +24385,8 @@ CVE-2018-5231 (The ForgotLoginDetails resource in 
Atlassian Jira before version 
        NOT-FOR-US: Atlassian
 CVE-2018-5230 (The issue collector in Atlassian Jira before version 7.6.6, 
from ...)
        NOT-FOR-US: Atlassian
-CVE-2018-5229
-       RESERVED
+CVE-2018-5229 (The NotificationRepresentationFactoryImpl class in Atlassian 
Universal ...)
+       TODO: check
 CVE-2018-5228 (The /browse/~raw resource in Atlassian Fisheye and Crucible 
before ...)
        NOT-FOR-US: Atlassian
 CVE-2018-5227 (Various administrative application link resources in Atlassian 
...)
@@ -37474,16 +37640,16 @@ CVE-2018-0712 (Command injection vulnerability in 
LDAP Server in QNAP QTS 4.2.6 
        NOT-FOR-US: QNAP
 CVE-2018-0711 (Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 
build ...)
        NOT-FOR-US: QNAP
-CVE-2018-0710
-       RESERVED
-CVE-2018-0709
-       RESERVED
-CVE-2018-0708
-       RESERVED
-CVE-2018-0707
-       RESERVED
-CVE-2018-0706
-       RESERVED
+CVE-2018-0710 (Command injection vulnerability in SSH of QNAP Q'center Virtual 
...)
+       TODO: check
+CVE-2018-0709 (Command injection vulnerability in date of QNAP Q'center 
Virtual ...)
+       TODO: check
+CVE-2018-0708 (Command injection vulnerability in networking of QNAP Q'center 
Virtual ...)
+       TODO: check
+CVE-2018-0707 (Command injection vulnerability in change password of QNAP 
Q'center ...)
+       TODO: check
+CVE-2018-0706 (Exposure of Private Information in QNAP Q'center Virtual 
Appliance ...)
+       TODO: check
 CVE-2017-17042 (lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 
does not ...)
        - yard 0.9.12-1
        [stretch] - yard <no-dsa> (Minor issue)
@@ -38343,12 +38509,12 @@ CVE-2018-0387
        RESERVED
 CVE-2018-0386
        RESERVED
-CVE-2018-0385
-       RESERVED
-CVE-2018-0384
-       RESERVED
-CVE-2018-0383
-       RESERVED
+CVE-2018-0385 (A vulnerability in the detection engine parsing of Security 
Socket ...)
+       TODO: check
+CVE-2018-0384 (A vulnerability in the detection engine of Cisco FireSIGHT 
System ...)
+       TODO: check
+CVE-2018-0383 (A vulnerability in the detection engine of Cisco FireSIGHT 
System ...)
+       TODO: check
 CVE-2018-0382
        RESERVED
 CVE-2018-0381
@@ -38373,16 +38539,16 @@ CVE-2018-0372
        RESERVED
 CVE-2018-0371 (A vulnerability in the Web Admin Interface of Cisco Meeting 
Server ...)
        NOT-FOR-US: Cisco
-CVE-2018-0370
-       RESERVED
-CVE-2018-0369
-       RESERVED
-CVE-2018-0368
-       RESERVED
+CVE-2018-0370 (A vulnerability in the detection engine of Cisco Firepower 
System ...)
+       TODO: check
+CVE-2018-0369 (A vulnerability in the reassembly logic for fragmented IPv4 
packets of ...)
+       TODO: check
+CVE-2018-0368 (A vulnerability in Cisco Digital Network Architecture (DNA) 
Center ...)
+       TODO: check
 CVE-2018-0367
        RESERVED
-CVE-2018-0366
-       RESERVED
+CVE-2018-0366 (A vulnerability in the web-based management interface of Cisco 
Web ...)
+       TODO: check
 CVE-2018-0365 (A vulnerability in the web-based management interface of Cisco 
...)
        NOT-FOR-US: Cisco
 CVE-2018-0364 (A vulnerability in the web-based management interface of Cisco 
Unified ...)
@@ -38391,10 +38557,10 @@ CVE-2018-0363 (A vulnerability in the web-based 
management interface of Cisco Un
        NOT-FOR-US: Cisco
 CVE-2018-0362 (A vulnerability in BIOS authentication management of Cisco 5000 
Series ...)
        NOT-FOR-US: Cisco
-CVE-2018-0361
-       RESERVED
-CVE-2018-0360
-       RESERVED
+CVE-2018-0361 (ClamAV before 0.100.1 lacks a PDF object length check, 
resulting in an ...)
+       TODO: check
+CVE-2018-0360 (ClamAV before 0.100.1 has an HWP integer overflow with a 
resultant ...)
+       TODO: check
 CVE-2018-0359 (A vulnerability in the session identification management 
functionality ...)
        NOT-FOR-US: Cisco
 CVE-2018-0358 (A vulnerability in the file descriptor handling of Cisco 
TelePresence ...)
@@ -38431,8 +38597,8 @@ CVE-2018-0343
        RESERVED
 CVE-2018-0342
        RESERVED
-CVE-2018-0341
-       RESERVED
+CVE-2018-0341 (A vulnerability in the web-based UI of Cisco IP Phone 6800, 
7800, and ...)
+       TODO: check
 CVE-2018-0340 (A vulnerability in the web framework of the Cisco Unified ...)
        NOT-FOR-US: Cisco
 CVE-2018-0339 (A vulnerability in the web-based management interface of Cisco 
Identity ...)
@@ -68481,8 +68647,7 @@ CVE-2017-7470
        NOT-FOR-US: Red Hat / spacewalk-backend
 CVE-2017-7469
        REJECTED
-CVE-2017-7468
-       RESERVED
+CVE-2017-7468 (In curl and libcurl 7.52.0 to and including 7.53.1, libcurl 
would ...)
        - curl 7.52.1-5
        [jessie] - curl <not-affected> (Only affects 7.52 and later)
        [wheezy] - curl <not-affected> (Only affects 7.52 and later)
@@ -83431,8 +83596,7 @@ CVE-2017-2640 [Out-of-bounds write when stripping xml]
 CVE-2017-2639
        RESERVED
        NOT-FOR-US: Red Hat CloudForms Management Engine
-CVE-2017-2638
-       RESERVED
+CVE-2017-2638 (It was found that the REST API in Infinispan before version 
9.0.0 did ...)
        NOT-FOR-US: infinispan
 CVE-2017-2637
        RESERVED
@@ -130953,7 +131117,7 @@ CVE-2015-4970
 CVE-2015-4969
        RESERVED
 CVE-2015-4968
-       RESERVED
+       REJECTED
 CVE-2015-4967 (SQL injection vulnerability in IBM Maximo Asset Management 7.1 
through ...)
        NOT-FOR-US: IBM
 CVE-2015-4966 (IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 
7.5.0.9 ...)
@@ -139805,9 +139969,9 @@ CVE-2015-1993 (IBM Security QRadar Incident Forensics 
7.2.x before 7.2.5 Patch 5
 CVE-2015-1992 (IBM Systems Director 5.2.x, 6.1.x, 6.2.0.x, 6.2.1.x, 6.3.0.0, 
6.3.1.x, ...)
        NOT-FOR-US: IBM Systems Director
 CVE-2015-1991
-       RESERVED
+       REJECTED
 CVE-2015-1990
-       RESERVED
+       REJECTED
 CVE-2015-1989 (SQL injection vulnerability in IBM Security QRadar Incident 
Forensics ...)
        NOT-FOR-US: IBM QRadar
 CVE-2015-1988 (Cross-site scripting (XSS) vulnerability in IBM Tivoli Storage 
Manger ...)
@@ -147648,7 +147812,7 @@ CVE-2015-0165
 CVE-2015-0164
        REJECTED
 CVE-2015-0163
-       RESERVED
+       REJECTED
 CVE-2015-0162 (IBM Security SiteProtector System 3.0, 3.1, and 3.1.1 allows 
local ...)
        NOT-FOR-US: IBM
 CVE-2015-0161 (SQL injection vulnerability in IBM Security SiteProtector 
System 3.0 ...)
@@ -147664,9 +147828,9 @@ CVE-2015-0157 (IBM DB2 9.7 through FP10, 9.8 through 
FP5, 10.1 before FP5, and 1
 CVE-2015-0156 (Cross-site scripting (XSS) vulnerability in IBM Business 
Process ...)
        NOT-FOR-US: IBM
 CVE-2015-0155
-       RESERVED
+       REJECTED
 CVE-2015-0154
-       RESERVED
+       REJECTED
 CVE-2015-0153 (D-Link DIR-815 devices with firmware before 2.07.B01 allow 
remote ...)
        NOT-FOR-US: D-Link
 CVE-2015-0152 (D-Link DIR-815 devices with firmware before 2.07.B01 allow 
remote ...)
@@ -165714,8 +165878,7 @@ CVE-2014-2081 (Multiple SQL injection vulnerabilities 
in the login in ...)
        NOT-FOR-US: Innovative vtls-Virtua
 CVE-2014-2080 (Cross-site scripting (XSS) vulnerability in ...)
        NOT-FOR-US: MODx Revolution
-CVE-2014-2079 [File New sets inappropriate permissions in ACL enabled 
directories]
-       RESERVED
+CVE-2014-2079 (X File Explorer (aka xfe) might allow local users to bypass 
intended ...)
        - xfe 1.37-2 (bug #739536)
        [wheezy] - xfe <no-dsa> (Minor issue)
        [squeeze] - xfe <no-dsa> (Minor issue)
@@ -182293,7 +182456,7 @@ CVE-2013-3024 (IBM WebSphere Application Server (WAS) 
8.5 through 8.5.0.2 on UNI
 CVE-2013-3023 (IBM Tivoli Application Dependency Discovery Manager (TADDM) 
7.1.2 and ...)
        NOT-FOR-US: IBM
 CVE-2013-3022
-       RESERVED
+       REJECTED
 CVE-2013-3021
        RESERVED
 CVE-2013-3020 (IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File 
Gateway 2.1 ...)
@@ -182355,9 +182518,9 @@ CVE-2013-2993 (IBM WebSphere Commerce 6.x through 
6.0.0.11 and 7.x through 7.0.0
 CVE-2013-2992 (The Search component in IBM WebSphere Commerce 7.0 FP4 through 
FP6, in ...)
        NOT-FOR-US: IBM
 CVE-2013-2991
-       RESERVED
+       REJECTED
 CVE-2013-2990
-       RESERVED
+       REJECTED
 CVE-2013-2989 (The file-copying functionality in IBM Sterling Connect:Direct 
3.8.00, ...)
        NOT-FOR-US: IBM
 CVE-2013-2988 (Absolute path traversal vulnerability in the server in IBM 
Cognos ...)
@@ -182365,7 +182528,7 @@ CVE-2013-2988 (Absolute path traversal vulnerability 
in the server in IBM Cognos
 CVE-2013-2987 (IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File 
Gateway 2.1 ...)
        NOT-FOR-US: IBM
 CVE-2013-2986
-       RESERVED
+       REJECTED
 CVE-2013-2985 (IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File 
Gateway 2.1 ...)
        NOT-FOR-US: IBM
 CVE-2013-2984 (Directory traversal vulnerability in IBM Sterling B2B 
Integrator 5.1 ...)
@@ -182391,11 +182554,11 @@ CVE-2013-2975
 CVE-2013-2974 (The BIRT viewer in IBM Tivoli Application Dependency Discovery 
Manager ...)
        NOT-FOR-US: IBM Tivoli Application Dependency Discovery Manager
 CVE-2013-2973
-       RESERVED
+       REJECTED
 CVE-2013-2972 (IBM WebSphere Cast Iron 6.3 allows remote attackers to bypass 
intended ...)
        NOT-FOR-US: IBM
 CVE-2013-2971
-       RESERVED
+       REJECTED
 CVE-2013-2970 (Unspecified vulnerability in IBM QRadar Security Information 
and Event ...)
        NOT-FOR-US: IBM
 CVE-2013-2969 (Cross-site scripting (XSS) vulnerability in IBM Sterling 
Control ...)
@@ -189845,7 +190008,7 @@ CVE-2013-0552
 CVE-2013-0551 (The Basic Services component in IBM Tivoli Monitoring (ITM) 
6.2.0 ...)
        NOT-FOR-US: IBM Tivoli Monitoring
 CVE-2013-0550
-       RESERVED
+       REJECTED
 CVE-2013-0549 (Cross-site scripting (XSS) vulnerability in the Web Content 
Manager - ...)
        NOT-FOR-US: IBM WebSphere Portal
 CVE-2013-0548 (Multiple cross-site scripting (XSS) vulnerabilities in the 
Basic ...)
@@ -189889,7 +190052,7 @@ CVE-2013-0530
 CVE-2013-0529 (The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 
and 1.5 ...)
        NOT-FOR-US: IBM Sterling Connect:Direct
 CVE-2013-0528
-       RESERVED
+       REJECTED
 CVE-2013-0527 (The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 
and 1.5 ...)
        NOT-FOR-US: IBM Sterling Connect:Direct
 CVE-2013-0526 (ping.php in Global Console Manager 16 (GCM16) and Global 
Console ...)
@@ -189900,8 +190063,8 @@ CVE-2013-0524
        RESERVED
 CVE-2013-0523 (IBM WebSphere Commerce Enterprise 5.6.x through 5.6.1.5, 6.0.x 
through ...)
        NOT-FOR-US: IBM WebSphere
-CVE-2013-0522
-       RESERVED
+CVE-2013-0522 (The Notes Client Single Logon feature in IBM Notes 8.0, 8.0.1, 
8.0.2, ...)
+       TODO: check
 CVE-2013-0521
        RESERVED
 CVE-2013-0520 (IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 
Interim ...)
@@ -189913,7 +190076,7 @@ CVE-2013-0518 (IBM Sterling Secure Proxy 3.2.0 and 
3.3.01 before 3.3.01.23 Inter
 CVE-2013-0517
        RESERVED
 CVE-2013-0516
-       RESERVED
+       REJECTED
 CVE-2013-0515
        RESERVED
 CVE-2013-0514
@@ -206208,7 +206371,7 @@ CVE-2012-0724 (Adobe Flash Player before 11.2.202.229 
in Google Chrome before ..
 CVE-2012-0723 (The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 
SP-02, ...)
        NOT-FOR-US: IBM AIX, VIOS
 CVE-2012-0721
-       RESERVED
+       REJECTED
 CVE-2012-0720 (Cross-site scripting (XSS) vulnerability in the Integration 
Solution ...)
        NOT-FOR-US: IBM WebSphere Application
 CVE-2012-0719 (Cross-site scripting (XSS) vulnerability in IBM Tivoli Endpoint 
...)
@@ -208047,11 +208210,11 @@ CVE-2011-4895 (Tor before 0.2.2.34, when configured 
as a bridge, sets up circuit
 CVE-2011-4894 (Tor before 0.2.2.34, when configured as a bridge, uses direct 
DirPort ...)
        - tor 0.2.2.34-1 (unimportant)
 CVE-2011-4893
-       RESERVED
+       REJECTED
 CVE-2011-4892
-       RESERVED
+       REJECTED
 CVE-2011-4891
-       RESERVED
+       REJECTED
 CVE-2011-4890 (The server in IBM solidDB 6.5 before FP9 and 7.0 before FP1 
allows ...)
        NOT-FOR-US: IBM solidDB
 CVE-2011-4889 (The javax.naming.directory.AttributeInUseException class in the 
...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/commit/76663717881bfc30c533af7d5da047a1f7e9b998

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/commit/76663717881bfc30c533af7d5da047a1f7e9b998
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to