Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c909f556 by Moritz Muehlenhoff at 2019-12-13T09:21:55Z
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2019-19783
        RESERVED
 CVE-2019-19782 (The FTP client in AceaXe Plus 1.0 allows a buffer overflow via 
a long  ...)
-       TODO: check
+       NOT-FOR-US: AceaXe Plus
 CVE-2019-19781
        RESERVED
 CVE-2019-19780
@@ -23,7 +23,7 @@ CVE-2019-19773
 CVE-2019-19772
        RESERVED
 CVE-2019-19771 (The lodahs package 0.0.1 for Node.js is a Trojan horse, and 
may have b ...)
-       TODO: check
+       NOT-FOR-US: lodahs malicious package on npm
 CVE-2019-XXXX [identified authors can inject content into database]
        - spip 3.2.7-1
 CVE-2020-3609
@@ -9774,125 +9774,125 @@ CVE-2019-18344 (Sourcecodester Online Grading System 
1.0 is vulnerable to unauth
 CVE-2019-18343
        RESERVED
 CVE-2019-18342 (A vulnerability has been identified in SiNVR 3 Central Control 
Server  ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18341 (A vulnerability has been identified in SiNVR 3 Central Control 
Server  ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18340 (A vulnerability has been identified in SiNVR 3 Central Control 
Server  ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18339 (A vulnerability has been identified in SiNVR 3 Central Control 
Server  ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18338 (A vulnerability has been identified in SiNVR 3 Central Control 
Server  ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18337 (A vulnerability has been identified in SiNVR 3 Central Control 
Server  ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18336
        RESERVED
 CVE-2019-18335 (A vulnerability has been identified in SPPA-T3000 Application 
Server ( ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18334 (A vulnerability has been identified in SPPA-T3000 Application 
Server ( ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18333 (A vulnerability has been identified in SPPA-T3000 Application 
Server ( ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18332 (A vulnerability has been identified in SPPA-T3000 Application 
Server ( ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18331 (A vulnerability has been identified in SPPA-T3000 Application 
Server ( ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18330 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18329 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18328 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18327 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18326 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18325 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18324 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18323 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18322 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18321 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18320 (A vulnerability has been identified in SPPA-T3000 Application 
Server ( ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18319 (A vulnerability has been identified in SPPA-T3000 Application 
Server ( ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18318 (A vulnerability has been identified in SPPA-T3000 Application 
Server ( ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18317 (A vulnerability has been identified in SPPA-T3000 Application 
Server ( ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18316 (A vulnerability has been identified in SPPA-T3000 Application 
Server ( ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18315 (A vulnerability has been identified in SPPA-T3000 Application 
Server ( ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18314 (A vulnerability has been identified in SPPA-T3000 Application 
Server ( ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18313 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18312 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18311 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18310 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18309 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18308 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18307 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18306 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18305 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18304 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18303 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18302 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18301 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18300 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18299 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18298 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18297 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18296 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18295 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18294 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18293 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18292 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18291 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18290 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18289 (A vulnerability has been identified in SPPA-T3000 MS3000 
Migration Ser ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18288 (A vulnerability has been identified in SPPA-T3000 Application 
Server ( ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18287 (A vulnerability has been identified in SPPA-T3000 Application 
Server ( ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18286 (A vulnerability has been identified in SPPA-T3000 Application 
Server ( ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18285 (A vulnerability has been identified in SPPA-T3000 Application 
Server ( ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18284 (A vulnerability has been identified in SPPA-T3000 Application 
Server ( ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18283 (A vulnerability has been identified in SPPA-T3000 Application 
Server ( ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-18282
        RESERVED
 CVE-2019-18281 (An out-of-bounds memory access in the 
generateDirectionalRuns() functi ...)
@@ -23482,17 +23482,17 @@ CVE-2019-13949 (SyGuestBook A5 Version 1.2 has no 
CSRF protection mechanism, as
 CVE-2019-13948 (SyGuestBook A5 Version 1.2 allows stored XSS because the 
isValidData f ...)
        NOT-FOR-US: SyGuestBook A5
 CVE-2019-13947 (A vulnerability has been identified in SiNVR 3 Central Control 
Server  ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-13946
        RESERVED
 CVE-2019-13945 (A vulnerability has been identified in SIMATIC S7-1200 CPU 
family (inc ...)
        NOT-FOR-US: Siemens
 CVE-2019-13944 (A vulnerability has been identified in EN100 Ethernet module 
DNP3 vari ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-13943 (A vulnerability has been identified in EN100 Ethernet module 
DNP3 vari ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-13942 (A vulnerability has been identified in EN100 Ethernet module 
DNP3 vari ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-13941
        RESERVED
 CVE-2019-13940
@@ -23512,11 +23512,11 @@ CVE-2019-13934 (Improper Neutralization of Input 
During Web Page Generation ('Cr
 CVE-2019-13933
        RESERVED
 CVE-2019-13932 (A vulnerability has been identified in XHQ (All versions < 
V6.0.0.2 ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-13931 (A vulnerability has been identified in XHQ (All versions < 
V6.0.0.2 ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-13930 (A vulnerability has been identified in XHQ (All versions < 
V6.0.0.2 ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2019-13929 (A vulnerability has been identified in SIMATIC IT UADM (All 
versions & ...)
        NOT-FOR-US: Siemens
 CVE-2019-13928
@@ -33486,9 +33486,9 @@ CVE-2019-10697
 CVE-2019-10696
        RESERVED
 CVE-2019-10695 (When using the cd4pe::root_configuration task to configure a 
Continuou ...)
-       TODO: check
+       NOT-FOR-US: cd4pe Puppet module
 CVE-2019-10694 (The express install, which is the suggested way to install 
Puppet Ente ...)
-       TODO: check
+       NOT-FOR-US: Puppet Enterprise
 CVE-2019-10693
        RESERVED
 CVE-2019-10692 (In the wp-google-maps plugin before 7.11.18 for WordPress, 
includes/cl ...)
@@ -33662,7 +33662,7 @@ CVE-2019-10620
 CVE-2019-10619
        RESERVED
 CVE-2019-10618 (Driver may access an invalid address while processing IO 
control due t ...)
-       TODO: check
+       NOT-FOR-US: Snapdragon
 CVE-2019-10617 (Low privilege users can access service configuration which 
contains re ...)
        NOT-FOR-US: Qualcomm
 CVE-2019-10616
@@ -44349,7 +44349,7 @@ CVE-2019-7006 (Avaya one-X Communicator uses weak 
cryptographic algorithms in th
 CVE-2019-7005
        RESERVED
 CVE-2019-7004 (A Cross-Site Scripting (XSS) vulnerability in the WebUI 
component of I ...)
-       TODO: check
+       NOT-FOR-US: Avaya
 CVE-2019-7003 (A SQL injection vulnerability in the reporting component of 
Avaya Cont ...)
        NOT-FOR-US: Avaya
 CVE-2019-7002
@@ -49026,6 +49026,7 @@ CVE-2019-5145
        RESERVED
 CVE-2019-5144 (A freed memory access vulnerability exists in the SVG Marker 
Element f ...)
        TODO: check
+       NOTE: There's apparently some mixup here, contacted MITRE
 CVE-2019-5143
        RESERVED
 CVE-2019-5142



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/commit/c909f556334e238f7a601f200441cbebe8156dfc

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/commit/c909f556334e238f7a601f200441cbebe8156dfc
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to