Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
eaad350b by Salvatore Bonaccorso at 2024-11-21T10:15:06+01:00
Process more NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -35,35 +35,35 @@ CVE-2024-52797 (Opencast is free and open source software 
for automated video ca
 CVE-2024-52796 (Password Pusher, an open source application to communicate 
sensitive i ...)
        TODO: check
 CVE-2024-52771 (DedeBIZ v6.3.0 was discovered to contain an arbitrary file 
deletion vu ...)
-       TODO: check
+       NOT-FOR-US: DedeBIZ
 CVE-2024-52770 (An arbitrary file upload vulnerability in the component 
/admin/file_ma ...)
-       TODO: check
+       NOT-FOR-US: DedeBIZ
 CVE-2024-52769 (An arbitrary file upload vulnerability in the component 
/admin/friendl ...)
-       TODO: check
+       NOT-FOR-US: DedeBIZ
 CVE-2024-52765 (H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code 
executio ...)
-       TODO: check
+       NOT-FOR-US: H3C GR-1800AX MiniGRW1B0V100R007
 CVE-2024-52763 (A cross-site scripting (XSS) vulnerability in the component 
/graph_all ...)
        TODO: check
 CVE-2024-52762 (A cross-site scripting (XSS) vulnerability in the component 
/master/he ...)
        TODO: check
 CVE-2024-52757 (D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer 
overflow ...)
-       TODO: check
+       NOT-FOR-US: D-LINK
 CVE-2024-52755 (D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer 
overflow ...)
-       TODO: check
+       NOT-FOR-US: D-LINK
 CVE-2024-52754 (D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer 
overflow ...)
-       TODO: check
+       NOT-FOR-US: D-LINK
 CVE-2024-52739 (D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple 
remote c ...)
-       TODO: check
+       NOT-FOR-US: D-LINK
 CVE-2024-52725 (SemCms v4.8 was discovered to contain a SQL injection 
vulnerability. T ...)
-       TODO: check
+       NOT-FOR-US: SemCms
 CVE-2024-52702 (A stored cross-site scripting (XSS) vulnerability in the 
component ins ...)
        TODO: check
 CVE-2024-52701 (A stored cross-site scripting (XSS) vulnerability in the 
Configuration ...)
        TODO: check
 CVE-2024-52677 (HkCms <= v2.3.2.240702 is vulnerable to file upload in the 
getFileName ...)
-       TODO: check
+       NOT-FOR-US: HkCms
 CVE-2024-52614 (Use of hard-coded cryptographic key issue exists in "Kura 
Sushi Offici ...)
-       TODO: check
+       NOT-FOR-US: "Kura Sushi Official App Produced by EPARK" for Android
 CVE-2024-52598 (2FAuth is a web app to manage Two-Factor Authentication (2FA) 
accounts ...)
        TODO: check
 CVE-2024-52597 (2FAuth is a web app to manage Two-Factor Authentication (2FA) 
accounts ...)
@@ -71,51 +71,51 @@ CVE-2024-52597 (2FAuth is a web app to manage Two-Factor 
Authentication (2FA) ac
 CVE-2024-52595 (lxml_html_clean is a project for HTML cleaning functionalities 
copied  ...)
        TODO: check
 CVE-2024-52581 (Litestar is an Asynchronous Server Gateway Interface (ASGI) 
framework. ...)
-       TODO: check
+       NOT-FOR-US: Litestar
 CVE-2024-52473 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
-       TODO: check
+       NOT-FOR-US: Sandeep Verma HTML5 Lyrics araoke Player
 CVE-2024-52472 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52471 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52470 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52451 (Cross-Site Request Forgery (CSRF) vulnerability in Aaron 
Robbins Post  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52450 (Improper Control of Filename for Include/Require Statement in 
PHP Prog ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52449 (Improper Limitation of a Pathname to a Restricted Directory 
('Path Tra ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52448 (Improper Limitation of a Pathname to a Restricted Directory 
('Path Tra ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52447 (Path Traversal: '.../...//' vulnerability in Corporate Zen 
Contact Pag ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52446 (Cross-Site Request Forgery (CSRF) vulnerability in Buying 
Buddy Buying ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52445 (Deserialization of Untrusted Data vulnerability in Modeltheme 
QRMenu R ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52444 (Improper Limitation of a Pathname to a Restricted Directory 
('Path Tra ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52443 (Deserialization of Untrusted Data vulnerability in Nerijus 
Masikonis G ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52442 (Incorrect Privilege Assignment vulnerability in Userplus 
UserPlus allo ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52441 (Improperly Controlled Modification of Object Prototype 
Attributes ('Pr ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52440 (Deserialization of Untrusted Data vulnerability in Bueno Labs 
Pvt. Ltd ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52439 (Deserialization of Untrusted Data vulnerability in Mark 
O\u2019Donnell ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52438 (Missing Authentication for Critical Function vulnerability in 
deco.Age ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52437 (Missing Authentication for Critical Function vulnerability in 
Saul Mor ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52392 (Cross-Site Request Forgery (CSRF) vulnerability in W3speedster 
W3SPEED ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-52033 (Exposure of sensitive system information to an unauthorized 
control sp ...)
-       TODO: check
+       NOT-FOR-US: Rakuten Turbo 5G firmware
 CVE-2024-51669 (Cross-Site Request Forgery (CSRF) vulnerability in Vivwebs 
Dynamic Wid ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-51209 (Cross-Site Scripting (XSS) vulnerabilities in Anuj Kumar's 
Client Mana ...)
        TODO: check
 CVE-2024-51208 (File Upload vulnerability in change-image.php in Anuj Kumar's 
Boat Boo ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eaad350bf6ae552cb4a45c6624ae54aad5e49fc5

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eaad350bf6ae552cb4a45c6624ae54aad5e49fc5
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to