Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
02479081 by Salvatore Bonaccorso at 2023-12-07T09:57:02+01:00
Process NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -15,7 +15,7 @@ CVE-2023-5711 (The System Dashboard plugin for WordPress is 
vulnerable to unauth
 CVE-2023-5710 (The System Dashboard plugin for WordPress is vulnerable to 
unauthorize ...)
        NOT-FOR-US: WordPress plugin
 CVE-2023-49225 (A cross-site-scripting vulnerability exists in Ruckus Access 
Point pro ...)
-       TODO: check
+       NOT-FOR-US: Ruckus
 CVE-2023-48861 (DLL hijacking vulnerability in TTplayer version 7.0.2, allows 
local at ...)
        TODO: check
 CVE-2023-48860 (TOTOLINK N300RT version 3.2.4-B20180730.0906 has a 
post-authentication ...)
@@ -55,45 +55,45 @@ CVE-2023-48824 (BoidCMS 2.0.1 is vulnerable to Multiple 
Stored Cross-Site Script
 CVE-2023-48823 (A Blind SQL injection issue in ajax.php in GaatiTrack Courier 
Manageme ...)
        TODO: check
 CVE-2023-48208 (A Cross Site Scripting vulnerability in Availability Booking 
Calendar  ...)
-       TODO: check
+       NOT-FOR-US: Availability Booking Calendar
 CVE-2023-48207 (Availability Booking Calendar 5.0 allows CSV injection via the 
unique  ...)
-       TODO: check
+       NOT-FOR-US: Availability Booking Calendar
 CVE-2023-48206 (A Cross Site Scripting (XSS) vulnerability in GaatiTrack 
Courier Manag ...)
-       TODO: check
+       NOT-FOR-US: GaatiTrack CourierManagement System
 CVE-2023-48205 (Jorani Leave Management System 1.0.2 allows a remote attacker 
to spoof ...)
-       TODO: check
+       NOT-FOR-US: Jorani Leave Management System
 CVE-2023-48172 (A Cross Site Scripting (XSS) vulnerability in Shuttle Booking 
Software ...)
-       TODO: check
+       NOT-FOR-US: Shuttle Booking Software
 CVE-2023-46916 (Maxima Max Pro Power 1.0 486A devices allow BLE traffic 
replay. An att ...)
-       TODO: check
+       NOT-FOR-US: Maxima Max Pro Power
 CVE-2023-46354 (In the module "Orders (CSV, Excel) Export PRO" (ordersexport) 
< 5.2.0  ...)
-       TODO: check
+       NOT-FOR-US: PrestaShop module
 CVE-2023-46353 (In the module "Product Tag Icons Pro" (ticons) before 1.8.4 
from MyPre ...)
-       TODO: check
+       NOT-FOR-US: PrestaShop module
 CVE-2023-46307 (An issue was discovered in server.js in etcd-browser 
87ae63d75260. By  ...)
        TODO: check
 CVE-2023-43304 (An issue in PARK DANDAN mini-app on Line v13.6.1 allows 
attackers to s ...)
-       TODO: check
+       NOT-FOR-US: PARK DANDAN mini-app on Line
 CVE-2023-43303 (An issue in craftbeer bar canvas mini-app on Line v13.6.1 
allows attac ...)
-       TODO: check
+       NOT-FOR-US: craftbeer bar canvas mini-app on Line
 CVE-2023-43302 (An issue in sanTas mini-app on Line v13.6.1 allows attackers 
to send c ...)
-       TODO: check
+       NOT-FOR-US: sanTas mini-app on Line
 CVE-2023-43301 (An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows 
attackers ...)
-       TODO: check
+       NOT-FOR-US: DARTS SHOP MAXIM mini-app on Line
 CVE-2023-43300 (An issue in urban_project mini-app on Line v13.6.1 allows 
attackers to ...)
-       TODO: check
+       NOT-FOR-US: urban_project mini-app on Line
 CVE-2023-43299 (An issue in DA BUTCHERS mini-app on Line v13.6.1 allows 
attackers to s ...)
-       TODO: check
+       NOT-FOR-US: DA BUTCHERS mini-app on Line
 CVE-2023-43298 (An issue in SCOL Members Card mini-app on Line v13.6.1 allows 
attacker ...)
-       TODO: check
+       NOT-FOR-US: SCOL Members Card mini-app on Line
 CVE-2023-43103 (An XSS issue was discovered in a web endpoint in Zimbra 
Collaboration  ...)
-       TODO: check
+       NOT-FOR-US: Zimbra
 CVE-2023-43102 (An issue was discovered in Zimbra Collaboration (ZCS) before 
10.0.4. A ...)
-       TODO: check
+       NOT-FOR-US: Zimbra
 CVE-2023-41106 (An issue was discovered in Zimbra Collaboration (ZCS) before 
10.0.3. A ...)
-       TODO: check
+       NOT-FOR-US: Zimbra
 CVE-2023-40238 (A LogoFAIL issue was discovered in BmpDecoderDxe in Insyde 
InsydeH2O w ...)
-       TODO: check
+       NOT-FOR-US: Insyde
 CVE-2023-6560 [io_uring out of boundary memory access in __io_uaddr_map()]
        - linux <unfixed>
        [bookworm] - linux <not-affected> (Vulnerable code not present)
@@ -40626,7 +40626,7 @@ CVE-2023-28019 (Insufficient validation in Bigfix WebUI 
API App site version < 1
 CVE-2023-28018
        RESERVED
 CVE-2023-28017 (HCL Connections is vulnerable to a cross-site scripting attack 
where a ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2023-28016 (Host Header Injection vulnerability in the HCL BigFix OSD Bare 
Metal S ...)
        NOT-FOR-US: HCL
 CVE-2023-28015 (The HCL Domino AppDev Pack IAM service is susceptible to a 
User Accoun ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0247908116e9ce4b5a234c148aa9fca23730a86e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0247908116e9ce4b5a234c148aa9fca23730a86e
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to