Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
e7976931 by Salvatore Bonaccorso at 2020-03-14T14:39:40+01:00
Process NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -43,7 +43,7 @@ CVE-2020-10546
 CVE-2020-10545
        RESERVED
 CVE-2020-10544 (An XSS issue was discovered in tooltip/tooltip.js in PrimeTek 
PrimeFac ...)
-       TODO: check
+       NOT-FOR-US: PrimeTek PrimeFaces
 CVE-2009-5159 (Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, 
when Int ...)
        NOT-FOR-US: Invision Power Board
 CVE-2020-10543
@@ -6674,7 +6674,7 @@ CVE-2020-7602
 CVE-2020-7601
        RESERVED
 CVE-2020-7600 (querymen prior to 2.1.4 allows modification of object 
properties. The  ...)
-       TODO: check
+       NOT-FOR-US: querymen nodejs module
 CVE-2020-7599
        RESERVED
 CVE-2020-7598 (minimist before 1.2.2 could be tricked into adding or modifying 
proper ...)
@@ -11946,7 +11946,7 @@ CVE-2020-5258 (In affected versions of dojo (NPM 
package), the deepCopy method i
        NOTE: 
https://github.com/dojo/dojo/security/advisories/GHSA-jxfh-8wgv-vfr2
        NOTE: 
https://github.com/dojo/dojo/commit/20a00afb68f5587946dc76fbeaa68c39bda2171d
 CVE-2020-5257 (In Administrate (rubygem) before version 0.13.0, when sorting 
by attri ...)
-       TODO: check
+       NOT-FOR-US: Administrate ruby gem
 CVE-2020-5256 (BookStack before version 0.25.5 has a vulnerability where a 
user could ...)
        NOT-FOR-US: BookStack
 CVE-2020-5255
@@ -11995,7 +11995,7 @@ CVE-2020-5242 (openHAB before 2.5.2 allow a remote 
attacker to use REST calls to
 CVE-2020-5241 (matestack-ui-core (RubyGem) before 0.7.4 is vulnerable to 
XSS/Script i ...)
        NOT-FOR-US: matestack-ui-core Ruby gem
 CVE-2020-5240 (In wagtail-2fa before 1.4.1, any user with access to the CMS 
can view  ...)
-       TODO: check
+       NOT-FOR-US: wagtail-2fa
 CVE-2020-5239 (In Mailu before version 1.7, an authenticated user can exploit 
a vulne ...)
        NOT-FOR-US: Mailu
 CVE-2020-5238
@@ -25325,7 +25325,7 @@ CVE-2020-0846
 CVE-2020-0845 (An elevation of privilege vulnerability exists in the way that 
the Win ...)
        NOT-FOR-US: Microsoft
 CVE-2020-0844 (An elevation of privilege vulnerability exists when Connected 
User Exp ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0843 (An elevation of privilege vulnerability exists in Windows 
Installer be ...)
        NOT-FOR-US: Microsoft
 CVE-2020-0842 (An elevation of privilege vulnerability exists in Windows 
Installer be ...)
@@ -25373,7 +25373,7 @@ CVE-2020-0822 (An elevation of privilege vulnerability 
exists when the Windows L
 CVE-2020-0821
        RESERVED
 CVE-2020-0820 (An information disclosure vulnerability exists when Media 
Foundation i ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0819 (An elevation of privilege vulnerability exists when the Windows 
Device ...)
        NOT-FOR-US: Microsoft
 CVE-2020-0818
@@ -25385,9 +25385,9 @@ CVE-2020-0816 (A remote code execution vulnerability 
exists when Microsoft Edge
 CVE-2020-0815 (An elevation of privilege vulnerability exists when Azure 
DevOps Serve ...)
        TODO: check
 CVE-2020-0814 (An elevation of privilege vulnerability exists in Windows 
Installer be ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0813 (An information disclosure vulnerability exists when Chakra 
improperly  ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0812 (A remote code execution vulnerability exists in the way that 
the Chakr ...)
        NOT-FOR-US: Microsoft
 CVE-2020-0811 (A remote code execution vulnerability exists in the way that 
the Chakr ...)
@@ -25415,15 +25415,15 @@ CVE-2020-0801 (A memory corruption vulnerability 
exists when Windows Media Found
 CVE-2020-0800 (An elevation of privilege vulnerability exists when the Windows 
Work F ...)
        NOT-FOR-US: Microsoft
 CVE-2020-0799 (An elevation of privilege vulnerability exists in Microsoft 
Windows wh ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0798 (An elevation of privilege vulnerability exists in the Windows 
Installe ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0797 (An elevation of privilege vulnerability exists when the Windows 
Work F ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0796 (A remote code execution vulnerability exists in the way that 
the Micro ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0795 (This vulnerability is caused when SharePoint Server does not 
properly  ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0794
        RESERVED
 CVE-2020-0793 (An elevation of privilege vulnerability exists when the 
Diagnostics Hu ...)
@@ -25431,51 +25431,51 @@ CVE-2020-0793 (An elevation of privilege 
vulnerability exists when the Diagnosti
 CVE-2020-0792 (An elevation of privilege vulnerability exists when the Windows 
Graphi ...)
        NOT-FOR-US: Microsoft
 CVE-2020-0791 (An elevation of privilege vulnerability exists when the Windows 
Graphi ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0790
        RESERVED
 CVE-2020-0789 (A denial of service vulnerability exists when the Visual Studio 
Extens ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0788 (An elevation of privilege vulnerability exists in Windows when 
the Win ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0787 (An elevation of privilege vulnerability exists when the Windows 
Backgr ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0786 (A denial of service vulnerability exists when the Windows Tile 
Object  ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0785 (An elevation of privilege vulnerability exists when the Windows 
User P ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0784
        RESERVED
 CVE-2020-0783 (An elevation of privilege vulnerability exists when the Windows 
Univer ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0782
        RESERVED
 CVE-2020-0781 (An elevation of privilege vulnerability exists when the Windows 
Univer ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0780 (An elevation of privilege vulnerability exists in the way that 
the Win ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0779 (An elevation of privilege vulnerability exists in the Windows 
Installe ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0778 (An elevation of privilege vulnerability exists in the way that 
the Win ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0777 (An elevation of privilege vulnerability exists when the Windows 
Work F ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0776 (An elevation of privilege vulnerability exists when the Windows 
AppX D ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0775 (An information disclosure vulnerability exists when Windows 
Error Repo ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0774 (An information disclosure vulnerability exists when the Windows 
GDI co ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0773 (An elevation of privilege vulnerability exists when the Windows 
Active ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0772 (An elevation of privilege vulnerability exists when Windows 
Error Repo ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0771 (An elevation of privilege vulnerability exists when the Windows 
CSC Se ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0770 (An elevation of privilege vulnerability exists when the Windows 
Active ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0769 (An elevation of privilege vulnerability exists when the Windows 
CSC Se ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0768 (A remote code execution vulnerability exists in the way the 
scripting  ...)
        TODO: check
 CVE-2020-0767 (A remote code execution vulnerability exists in the way that 
the Chakr ...)
@@ -25487,9 +25487,9 @@ CVE-2020-0765 (An information disclosure vulnerability 
exists in the Remote Desk
 CVE-2020-0764
        RESERVED
 CVE-2020-0763 (An elevation of privilege vulnerability exists when Windows 
Defender S ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0762 (An elevation of privilege vulnerability exists when Windows 
Defender S ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0761
        RESERVED
 CVE-2020-0760
@@ -25633,7 +25633,7 @@ CVE-2020-0692 (An elevation of privilege vulnerability 
exists in Microsoft Excha
 CVE-2020-0691 (An elevation of privilege vulnerability exists in Windows when 
the Win ...)
        NOT-FOR-US: Microsoft
 CVE-2020-0690 (An elevation of privilege vulnerability exists when DirectX 
improperly ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0689 (A security feature bypass vulnerability exists in secure boot, 
aka 'Mi ...)
        NOT-FOR-US: Microsoft
 CVE-2020-0688 (A remote code execution vulnerability exists in Microsoft 
Exchange sof ...)
@@ -25645,7 +25645,7 @@ CVE-2020-0686 (An elevation of privilege vulnerability 
exists in the Windows Ins
 CVE-2020-0685 (An elevation of privilege vulnerability exists when Windows 
improperly ...)
        NOT-FOR-US: Microsoft
 CVE-2020-0684 (A remote code execution vulnerability exists in Microsoft 
Windows that ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0683 (An elevation of privilege vulnerability exists in the Windows 
Installe ...)
        NOT-FOR-US: Microsoft
 CVE-2020-0682 (An elevation of privilege vulnerability exists in the way that 
the Win ...)
@@ -25723,7 +25723,7 @@ CVE-2020-0647 (A spoofing vulnerability exists when 
Office Online does not valid
 CVE-2020-0646 (A remote code execution vulnerability exists when the Microsoft 
.NET F ...)
        NOT-FOR-US: Microsoft
 CVE-2020-0645 (A tampering vulnerability exists when Microsoft IIS Server 
improperly  ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2020-0644 (An elevation of privilege vulnerability exists when Microsoft 
Windows  ...)
        NOT-FOR-US: Microsoft
 CVE-2020-0643 (An information disclosure vulnerability exists in the way that 
the Win ...)
@@ -26338,7 +26338,7 @@ CVE-2020-0585
 CVE-2020-0584
        RESERVED
 CVE-2020-0583 (Improper access control in the subsystem for Intel(R) Smart 
Sound Tech ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2020-0582
        RESERVED
 CVE-2020-0581
@@ -26356,7 +26356,7 @@ CVE-2020-0576
 CVE-2020-0575
        RESERVED
 CVE-2020-0574 (Improper configuration in block design for Intel(R) MAX(R) 10 
FPGA all ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2020-0573
        RESERVED
 CVE-2020-0572
@@ -26501,7 +26501,7 @@ CVE-2020-0522
 CVE-2020-0521
        RESERVED
 CVE-2020-0520 (Path traversal in igdkmd64.sys for Intel(R) Graphics Drivers 
before ve ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2020-0519 (Improper access control for Intel(R) Graphics Drivers before 
versions  ...)
        TODO: check
 CVE-2020-0518
@@ -29524,7 +29524,7 @@ CVE-2019-17660 (A cross-site scripting (XSS) 
vulnerability in admin/translate/tr
 CVE-2019-17659
        RESERVED
 CVE-2019-17658 (An unquoted service path vulnerability in the FortiClient 
FortiTray co ...)
-       TODO: check
+       NOT-FOR-US: Fortiguard
 CVE-2019-17657
        RESERVED
 CVE-2019-17656
@@ -29534,7 +29534,7 @@ CVE-2019-17655
 CVE-2019-17654
        RESERVED
 CVE-2019-17653 (A Cross-Site Request Forgery (CSRF) vulnerability in the user 
interfac ...)
-       TODO: check
+       NOT-FOR-US: Fortiguard
 CVE-2019-17652 (A stack buffer overflow vulnerability in FortiClient for Linux 
6.2.1 a ...)
        NOT-FOR-US: Fortiguard FortiClient
 CVE-2019-17651 (An Improper Neutralization of Input vulnerability in the 
description a ...)
@@ -33914,9 +33914,9 @@ CVE-2019-16159 (BIRD Internet Routing Daemon 1.6.x 
through 1.6.7 and 2.x through
 CVE-2019-16158
        RESERVED
 CVE-2019-16157 (An information exposure vulnerability in Fortinet FortiWeb 
6.2.0 CLI a ...)
-       TODO: check
+       NOT-FOR-US: Fortiguard
 CVE-2019-16156 (An Improper Neutralization of Input vulnerability in the 
Anomaly Detec ...)
-       TODO: check
+       NOT-FOR-US: Fortiguard
 CVE-2019-16155 (A privilege escalation vulnerability in FortiClient for Linux 
6.2.1 an ...)
        NOT-FOR-US: Fortiguard FortiClient
 CVE-2019-16154 (An improper neutralization of input during web page generation 
in Fort ...)
@@ -40314,9 +40314,9 @@ CVE-2019-14312 (Aptana Jaxer 1.0.3.4547 is vulnerable 
to a local file inclusion
 CVE-2019-14311
        RESERVED
 CVE-2019-14310 (Ricoh SP C250DN 1.05 devices allow denial of service (issue 2 
of 3). U ...)
-       TODO: check
+       NOT-FOR-US: Ricoh
 CVE-2019-14309 (Ricoh SP C250DN 1.05 devices have a fixed password. FTP 
service creden ...)
-       TODO: check
+       NOT-FOR-US: Ricoh
 CVE-2019-14308 (Several Ricoh printers have multiple buffer overflows parsing 
LPD pack ...)
        NOT-FOR-US: Ricoh
 CVE-2019-14307 (Several Ricoh printers have multiple buffer overflows parsing 
HTTP par ...)
@@ -40328,7 +40328,7 @@ CVE-2019-14305 (Several Ricoh printers have multiple 
buffer overflows parsing HT
 CVE-2019-14304 (Ricoh SP C250DN 1.06 devices allow CSRF. ...)
        NOT-FOR-US: Ricoh SP C250DN 1.06 devices
 CVE-2019-14303 (Ricoh SP C250DN 1.05 devices allow denial of service (issue 1 
of 3). S ...)
-       TODO: check
+       NOT-FOR-US: Ricoh
 CVE-2019-14302 (On Ricoh SP C250DN 1.06 devices, a debug port can be used. ...)
        NOT-FOR-US: Ricoh SP C250DN 1.06 devices
 CVE-2019-14301 (Ricoh SP C250DN 1.06 devices have Incorrect Access Control 
(issue 1 of ...)
@@ -40336,7 +40336,7 @@ CVE-2019-14301 (Ricoh SP C250DN 1.06 devices have 
Incorrect Access Control (issu
 CVE-2019-14300 (Several Ricoh printers have multiple buffer overflows parsing 
HTTP coo ...)
        NOT-FOR-US: Ricoh
 CVE-2019-14299 (Ricoh SP C250DN 1.05 devices have an Authentication Method 
Vulnerable  ...)
-       TODO: check
+       NOT-FOR-US: Ricoh
 CVE-2019-14298 (Veeam ONE Reporter 9.5.0.3201 allows XSS via a crafted 
Description(con ...)
        NOT-FOR-US: Veeam ONE Reporter
 CVE-2019-14297 (Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit 
Widget with  ...)
@@ -43792,11 +43792,11 @@ CVE-2019-13397 (Unauthenticated Stored XSS in 
osTicket 1.10.1 allows a remote at
 CVE-2019-13396 (FlightPath 4.x and 5.0-x allows directory traversal and Local 
File Inc ...)
        NOT-FOR-US: FlightPath
 CVE-2019-13395 (The Voo branded NETGEAR CG3700b custom firmware V2.02.03 
allows CSRF a ...)
-       TODO: check
+       NOT-FOR-US: Netgear
 CVE-2019-13394 (The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses 
HTTP Bas ...)
-       TODO: check
+       NOT-FOR-US: Netgear
 CVE-2019-13393 (The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses 
the same ...)
-       TODO: check
+       NOT-FOR-US: Netgear
 CVE-2019-13392 (A reflected Cross-Site Scripting (XSS) vulnerability in 
MindPalette Na ...)
        NOT-FOR-US: MindPalette NateMail
 CVE-2019-13391 (In ImageMagick 7.0.8-50 Q16, ComplexImages in 
MagickCore/fourier.c has ...)
@@ -44343,35 +44343,35 @@ CVE-2019-13207 (nsd-checkzone in NLnet Labs NSD 4.2.0 
has a Stack-based Buffer O
        NOTE: https://github.com/NLnetLabs/nsd/issues/20
        NOTE: 
https://github.com/NLnetLabs/nsd/commit/91102da24d5949ccfec8fdab5bae2d01c4cabab5
 CVE-2019-13206 (Some Kyocera printers (such as the ECOSYS M5526cdw 
2R7_2000.001.701) w ...)
-       TODO: check
+       NOT-FOR-US: Kyocera
 CVE-2019-13205 (All configuration parameters of certain Kyocera printers (such 
as the  ...)
-       TODO: check
+       NOT-FOR-US: Kyocera
 CVE-2019-13204 (Some Kyocera printers (such as the ECOSYS M5526cdw 
2R7_2000.001.701) w ...)
-       TODO: check
+       NOT-FOR-US: Kyocera
 CVE-2019-13203 (Some Kyocera printers (such as the ECOSYS M5526cdw 
2R7_2000.001.701) w ...)
-       TODO: check
+       NOT-FOR-US: Kyocera
 CVE-2019-13202 (Some Kyocera printers (such as the ECOSYS M5526cdw 
2R7_2000.001.701) w ...)
-       TODO: check
+       NOT-FOR-US: Kyocera
 CVE-2019-13201 (Some Kyocera printers (such as the ECOSYS M5526cdw 
2R7_2000.001.701) w ...)
-       TODO: check
+       NOT-FOR-US: Kyocera
 CVE-2019-13200 (The web application of several Kyocera printers (such as the 
ECOSYS M5 ...)
-       TODO: check
+       NOT-FOR-US: Kyocera
 CVE-2019-13199 (Some Kyocera printers (such as the ECOSYS M5526cdw 
2R7_2000.001.701) d ...)
-       TODO: check
+       NOT-FOR-US: Kyocera
 CVE-2019-13198 (The web application of several Kyocera printers (such as the 
ECOSYS M5 ...)
-       TODO: check
+       NOT-FOR-US: Kyocera
 CVE-2019-13197 (Some Kyocera printers (such as the ECOSYS M5526cdw 
2R7_2000.001.701) w ...)
-       TODO: check
+       NOT-FOR-US: Kyocera
 CVE-2019-13196 (Some Kyocera printers (such as the ECOSYS M5526cdw 
2R7_2000.001.701) w ...)
-       TODO: check
+       NOT-FOR-US: Kyocera
 CVE-2019-13195 (The web application of some Kyocera printers (such as the 
ECOSYS M5526 ...)
-       TODO: check
+       NOT-FOR-US: Kyocera
 CVE-2019-13194 (Some Brother printers (such as the HL-L8360CDW v1.20) were 
affected by ...)
-       TODO: check
+       NOT-FOR-US: Brother
 CVE-2019-13193 (Some Brother printers (such as the HL-L8360CDW v1.20) were 
affected by ...)
-       TODO: check
+       NOT-FOR-US: Brother
 CVE-2019-13192 (Some Brother printers (such as the HL-L8360CDW v1.20) were 
affected by ...)
-       TODO: check
+       NOT-FOR-US: Brother
 CVE-2019-13191 (A SQL injection vulnerability in IntraMaps MapControl 8 allows 
attacke ...)
        NOT-FOR-US: IntraMaps MapControl
 CVE-2019-13190 (In Knowage through 6.1.1, the sign up page does not invalidate 
a valid ...)
@@ -44429,21 +44429,21 @@ CVE-2019-13173 (fstream before 1.0.12 is vulnerable 
to Arbitrary File Overwrite.
        NOTE: https://www.npmjs.com/advisories/886
        NOTE: 
https://github.com/npm/fstream/commit/6a77d2fa6e1462693cf8e46f930da96ec1b0bb22
 CVE-2019-13172 (Some Xerox printers (such as the Phaser 3320 V53.006.16.000) 
were affe ...)
-       TODO: check
+       NOT-FOR-US: Xerox
 CVE-2019-13171 (Some Xerox printers (such as the Phaser 3320 V53.006.16.000) 
were affe ...)
-       TODO: check
+       NOT-FOR-US: Xerox
 CVE-2019-13170 (Some Xerox printers (such as the Phaser 3320 V53.006.16.000) 
did not i ...)
-       TODO: check
+       NOT-FOR-US: Xerox
 CVE-2019-13169 (Some Xerox printers (such as the Phaser 3320 V53.006.16.000) 
were affe ...)
-       TODO: check
+       NOT-FOR-US: Xerox
 CVE-2019-13168 (Some Xerox printers (such as the Phaser 3320 V53.006.16.000) 
were affe ...)
-       TODO: check
+       NOT-FOR-US: Xerox
 CVE-2019-13167 (Multiple Stored XSS vulnerabilities were found in the Xerox 
Web Applic ...)
-       TODO: check
+       NOT-FOR-US: Xerox
 CVE-2019-13166 (Some Xerox printers (such as the Phaser 3320 V53.006.16.000) 
did not i ...)
-       TODO: check
+       NOT-FOR-US: Xerox
 CVE-2019-13165 (Some Xerox printers (such as the Phaser 3320 V53.006.16.000) 
were affe ...)
-       TODO: check
+       NOT-FOR-US: Xerox
 CVE-2019-13164 (qemu-bridge-helper.c in QEMU 4.0.0 does not ensure that a 
network inte ...)
        {DSA-4512-1 DSA-4506-1 DLA-1927-1}
        - qemu 1:4.1-1 (bug #931351)
@@ -46889,7 +46889,7 @@ CVE-2019-12280 (PC-Doctor Toolbox before 7.3 has an 
Uncontrolled Search Path Ele
 CVE-2019-12279 (** DISPUTED ** Nagios XI 5.6.1 allows SQL injection via the 
username p ...)
        NOT-FOR-US: Nagios XI
 CVE-2019-12278 (Opera through 53 on Android allows Address Bar Spoofing. 
Characters fr ...)
-       TODO: check
+       NOT-FOR-US: Opera
 CVE-2019-12277 (Blogifier 2.3 before 2019-05-11 does not properly restrict 
APIs, as de ...)
        NOT-FOR-US: Blogifier
 CVE-2019-12276 (A Path Traversal vulnerability in 
Controllers/LetsEncryptController.cs ...)
@@ -47184,7 +47184,7 @@ CVE-2019-12184 (There is XSS in 
browser/components/MarkdownPreview.js in BoostIO
 CVE-2019-12183 (Incorrect Access Control in Safescan Timemoto TM-616 and 
TA-8000 serie ...)
        NOT-FOR-US: Safescan Timemoto
 CVE-2019-12182 (Directory Traversal in Safescan Timemoto and TA-8000 series 
version 1. ...)
-       TODO: check
+       NOT-FOR-US: Safescan Timemoto and TA-8000 series
 CVE-2019-12181 (A privilege escalation vulnerability exists in SolarWinds 
Serv-U befor ...)
        NOT-FOR-US: SolarWinds
 CVE-2019-12180 (An issue was discovered in SmartBear ReadyAPI through 2.8.2 
and 3.0.0  ...)
@@ -56849,25 +56849,25 @@ CVE-2019-9106 (The WebApp v04.68 in the supervisor on 
SAET Impianti Speciali TEB
 CVE-2019-9105 (The WebApp v04.68 in the supervisor on SAET Impianti Speciali 
TEBE Sma ...)
        NOT-FOR-US: SAET Impianti Speciali TEBE Small devices
 CVE-2019-9104 (An issue was discovered on Moxa MGate MB3170 and MB3270 devices 
before ...)
-       TODO: check
+       NOT-FOR-US: Moxa
 CVE-2019-9103 (An issue was discovered on Moxa MGate MB3170 and MB3270 devices 
before ...)
-       TODO: check
+       NOT-FOR-US: Moxa
 CVE-2019-9102 (An issue was discovered on Moxa MGate MB3170 and MB3270 devices 
before ...)
-       TODO: check
+       NOT-FOR-US: Moxa
 CVE-2019-9101 (An issue was discovered on Moxa MGate MB3170 and MB3270 devices 
before ...)
-       TODO: check
+       NOT-FOR-US: Moxa
 CVE-2019-9100
        RESERVED
 CVE-2019-9099 (An issue was discovered on Moxa MGate MB3170 and MB3270 devices 
before ...)
-       TODO: check
+       NOT-FOR-US: Moxa
 CVE-2019-9098 (An issue was discovered on Moxa MGate MB3170 and MB3270 devices 
before ...)
-       TODO: check
+       NOT-FOR-US: Moxa
 CVE-2019-9097 (An issue was discovered on Moxa MGate MB3170 and MB3270 devices 
before ...)
-       TODO: check
+       NOT-FOR-US: Moxa
 CVE-2019-9096 (An issue was discovered on Moxa MGate MB3170 and MB3270 devices 
before ...)
-       TODO: check
+       NOT-FOR-US: Moxa
 CVE-2019-9095 (An issue was discovered on Moxa MGate MB3170 and MB3270 devices 
before ...)
-       TODO: check
+       NOT-FOR-US: Moxa
 CVE-2019-9094 (A Reflected Cross Site Scripting (XSS) Vulnerability was 
discovered in ...)
        NOT-FOR-US: Humhub
 CVE-2019-9093 (A Reflected Cross Site Scripting (XSS) Vulnerability was 
discovered in ...)
@@ -63073,7 +63073,7 @@ CVE-2019-6701
 CVE-2019-6700 (An information exposure vulnerability in the external 
authentication p ...)
        NOT-FOR-US: FortiSIEM (Fortiguard)
 CVE-2019-6699 (An improper neutralization of input vulnerability in Fortinet 
FortiADC ...)
-       TODO: check
+       NOT-FOR-US: Fortiguard
 CVE-2019-6698 (Use of Hard-coded Credentials vulnerability in FortiRecorder 
all versi ...)
        NOT-FOR-US: Fortinet
 CVE-2019-6697



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e797693175ee14ac1188a65c665b88d33a961c73

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e797693175ee14ac1188a65c665b88d33a961c73
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to