Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c322d373 by Salvatore Bonaccorso at 2021-06-29T22:48:51+02:00
Process NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -37171,7 +37171,7 @@ CVE-2021-20747
 CVE-2021-20746 (Cross-site scripting vulnerability in WordPress Popular Posts 
5.3.2 an ...)
        TODO: check
 CVE-2021-20745 (Inkdrop versions prior to v5.3.1 allows an attacker to execute 
arbitra ...)
-       TODO: check
+       NOT-FOR-US: Inkdrop
 CVE-2021-20744 (Cross-site scripting vulnerability in EC-CUBE Category 
contents plugin ...)
        NOT-FOR-US: EC-CUBE Category contents plugin
 CVE-2021-20743 (Cross-site scripting vulnerability in EC-CUBE Email 
newsletters manage ...)
@@ -52214,7 +52214,7 @@ CVE-2020-26803 (In Sentrifugo 3.2, users can upload an 
image under "Assets ->
 CVE-2020-26802 (forma.lms 2.3.0.2 is affected by Cross Site Request Forgery 
(CSRF) in  ...)
        NOT-FOR-US: forma.lms
 CVE-2020-26801 (A stored cross-site scripting (XSS) vulnerability was 
discovered in /F ...)
-       TODO: check
+       NOT-FOR-US: TrippLite
 CVE-2020-26800 (A stack overflow vulnerability in Aleth Ethereum C++ client 
version &l ...)
        NOT-FOR-US: Aleth Ethereum
 CVE-2020-26799
@@ -69759,15 +69759,15 @@ CVE-2020-18670 (Cross Site Scripting (XSS) 
vulneraibility in Roundcube mail .4.4
 CVE-2020-18669
        RESERVED
 CVE-2020-18668 (Cross Site Scripting (XSS) vulnerabililty in WebPort 
<=1.19.1 via t ...)
-       TODO: check
+       NOT-FOR-US: WebPort
 CVE-2020-18667 (SQL Injection vulnerability in WebPort <=1.19.1 via the new 
connect ...)
-       TODO: check
+       NOT-FOR-US: WebPort
 CVE-2020-18666
        REJECTED
 CVE-2020-18665 (Directory Traversal vulnerability in WebPort <=1.19.1 in 
tags of sy ...)
-       TODO: check
+       NOT-FOR-US: WebPort
 CVE-2020-18664 (Cross Site Scripting (XSS) vulnerability in WebPort 
<=1.19.1via the ...)
-       TODO: check
+       NOT-FOR-US: WebPort
 CVE-2020-18663 (Cross Site Scripting (XSS) vulnerability in gnuboard5 
<=v5.3.2.8 vi ...)
        TODO: check
 CVE-2020-18662 (SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the 
table_p ...)
@@ -77446,7 +77446,7 @@ CVE-2020-15304 (An issue was discovered in OpenEXR 
before 2.5.2. An invalid tile
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/36e05c14c612a89c43d4e0b013669ecd7f8e3440
 (v3.0.4)
        NOTE: Introduced by 
https://github.com/AcademySoftwareFoundation/openexr/commit/e79d2296496a50826a15c667bf92bdc5a05518b4
 (v2.4.1)
 CVE-2020-15303 (Infoblox NIOS before 8.5.2 allows entity expansion during an 
XML uploa ...)
-       TODO: check
+       NOT-FOR-US: Infoblox NIOS
 CVE-2020-15302 (In Argent RecoveryManager before 
0xdc350d09f71c48c5D22fBE2741e4d6A0397 ...)
        NOT-FOR-US: Argent RecoveryManager
 CVE-2020-15301 (SuiteCRM through 7.11.13 allows CSV Injection via registration 
fields  ...)
@@ -98584,11 +98584,11 @@ CVE-2020-7873
 CVE-2020-7872
        RESERVED
 CVE-2020-7871 (A vulnerability of Helpcom could allow an unauthenticated 
attacker to  ...)
-       TODO: check
+       NOT-FOR-US: Cnesty Helpcom
 CVE-2020-7870 (A memory corruption vulnerability exists when ezPDF improperly 
handles ...)
        TODO: check
 CVE-2020-7869 (An improper input validation vulnerability of ZOOK software 
(remote ad ...)
-       TODO: check
+       NOT-FOR-US: ZOOK software
 CVE-2020-7868 (A remote code execution vulnerability exists in helpUS(remote 
administ ...)
        NOT-FOR-US: helpUS(remote administration tool)
 CVE-2020-7867
@@ -98602,7 +98602,7 @@ CVE-2020-7864 (Parameter manipulation can bypass 
authentication to cause file up
 CVE-2020-7863
        RESERVED
 CVE-2020-7862 (A vulnerability in agent program of HelpU remote control 
solution coul ...)
-       TODO: check
+       NOT-FOR-US: HelpU remote control solution
 CVE-2020-7861 (AnySupport (Remote support solution) before 2019.3.21.0 allows 
directo ...)
        NOT-FOR-US: AnySupport
 CVE-2020-7860 (UnEGG v0.5 and eariler versions have a Integer overflow 
vulnerability, ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c322d3734eb032f45be0d142ee9c135e8d6fb8ca

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c322d3734eb032f45be0d142ee9c135e8d6fb8ca
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to