Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
253ef968 by Moritz Muehlenhoff at 2025-09-04T23:42:43+02:00
auto-nfu: Add Android

Historically a lot of Linux issues were assigned via Android, but these
days they are exclusively assigned by the Linux kernel CNA.

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -23,83 +23,83 @@ CVE-2025-57576 (PHPGurukul Online Shopping Portal 2.1 is 
vulnerable to Cross Sit
 CVE-2025-57263 (An authenticated SQL injection vulnerability in VX Guestbook 
1.07 allo ...)
        TODO: check
 CVE-2025-48581 (In VerifyNoOverlapInSessions of apexd.cpp, there is a possible 
way to  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48563 (In onNullBinding of RemoteFillService.java, there is a 
possible backgr ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48562 (In writeContent of RemotePrintDocument.java, there is a 
possible infor ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48561 (In multiple locations, there is a possible way to access data 
displaye ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48560 (In AndroidManifest.xml, there is a possible way for an app to 
monitor  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48559 (In multiple functions of AppOpsService.java, there is a 
possible add a ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48558 (In multiple functions of BatteryService.java, there is a 
possible way  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48556 (In multiple methods of NotificationChannel.java, there is a 
possible d ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48554 (In handlePackagesChanged of DevicePolicyManagerService.java, 
there is  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48553 (In handlePackagesChanged of DevicePolicyManagerService.java, 
there is  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48552 (In saveGlobalProxyLocked of DevicePolicyManagerService.java, 
there is  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48551 (In multiple locations, there is a possible leak of an image 
across the ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48550 (In testGrantSlicePermission of SliceManagerTest.java, there is 
a possi ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48549 (In multiple locations, there is a possible way to record audio 
via a b ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48548 (In multiple functions of AppOpsControllerImpl.java, there is a 
possibl ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48547 (In multiple locations, there is a possible one-time permission 
bypass  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48546 (In checkPermissions of SafeActivityOptions.java, there is a 
possible b ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48545 (In isSystemUid of AccountManagerService.java, there is a 
possible way  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48544 (In multiple locations, there is a possible way to read files 
belonging ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48543 (In multiple locations, there is a possible way to escape 
chrome sandbo ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48542 (In multiple functions of AccountManagerService.java, there is 
a possib ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48541 (In onCreate of FaceSettings.java, there is a possible way to 
remove bi ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48540 (In processTransactInternal of RpcState.cpp, there is a 
possible local  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48539 (In SendPacketToPeer of acl_arbiter.cc, there is a possible out 
of boun ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48538 (In setApplicationHiddenSettingAsUser of 
PackageManagerService.java, th ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48537 (In multiple locations, there is a possible way to persistently 
DoS the ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48535 (In assertSafeToStartCustomActivity of 
AppRestrictionsFragment.java , t ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48534 (In getDefaultCBRPackageName of CellBroadcastHandler.java, 
there is a p ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48533 (In multiple locations, there is a possible way to use apps 
linked from ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48532 (In markMediaAsFavorite of MediaProvider.java, there is a 
possible way  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48531 (In getCallingPackageName of CredentialStorage, there is a 
possible per ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48530 (In multiple locations, there is a possible condition that 
results in O ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48529 (In setRingtoneUri of VoicemailNotificationSettingsUtil.java , 
there is ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48528 (In multiple locations, there is a possible way to overlay 
biometrics d ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48527 (In multiple locations, there is a possible way to leak hidden 
work pro ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48526 (In createMultiProfilePagerAdapter of ChooserActivity.java , 
there is a ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48524 (In isSystem of WifiPermissionsUtil.java, there is a possible 
permissio ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48523 (In onCreate of SelectAccountActivity.java, there is a possible 
way to  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-48522 (In setDisplayName of AssociationRequest.java, there is a 
possible way  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-41063 (A vulnerability has been discovered in version 4.0.5 of 
appRain CMF, c ...)
        TODO: check
 CVE-2025-41062 (A vulnerability has been discovered in version 4.0.5 of 
appRain CMF, c ...)
@@ -165,39 +165,39 @@ CVE-2025-41033 (An SQL injection vulnerability has been 
found in appRain CMF 4.0
 CVE-2025-41032 (An SQL injection vulnerability has been found in appRain CMF 
4.0.5. Th ...)
        TODO: check
 CVE-2025-32350 (In maybeShowDialog of ControlsSettingsDialogManager.kt, there 
is a pos ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-32349 (In multiple locations, there is a possible privilege 
escalation due to ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-32347 (In onStart of BiometricEnrollIntroduction.java, there is a 
possible wa ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-32346 (In onActivityResult of VoicemailSettingsActivity.java, there 
is a poss ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-32345 (In updateState of 
ContentProtectionTogglePreferenceController.java, th ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-32333 (In startSpaActivityForApp of SpaActivity.kt, there is a 
possible cross ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-32332 (In multiple locations, there is a possible memory corruption 
due to a  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-32331 (In showDismissibleKeyguard of KeyguardService.java, there is a 
possibl ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-32330 (In generateRandomPassword of LocalBluetoothLeBroadcast.java, 
there is  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-32327 (In multiple functions of PickerDbFacade.java, there is a 
possible unau ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-32326 (In multiple functions of AppRestrictionsFragment.java, there 
is a poss ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-32325 (In appendFrom of Parcel.cpp, there is a possible out of bounds 
write d ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-32324 (In onCommand of ActivityManagerShellCommand.java, there is a 
possible  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-32323 (In getCallingAppName of Shared.java, there is a possible way 
to trick  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-32322 (In onCreate of MediaProjectionPermissionActivity.java , there 
is a pos ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-32321 (In isSafeIntent of AccountTypePreferenceLoader.java, there is 
a possib ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-32312 (In createIntentsList of PackageParser.java , there is a 
possible way t ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-2694 (IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 
6.2.0.0 thro ...)
        NOT-FOR-US: IBM
 CVE-2025-2667 (IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 
6.2.0.0 thro ...)
@@ -205,79 +205,79 @@ CVE-2025-2667 (IBM Sterling B2B Integrator 6.0.0.0 
through 6.1.2.7_1 and 6.2.0.0
 CVE-2025-2411 (Improper Restriction of Excessive Authentication Attempts 
vulnerabilit ...)
        TODO: check
 CVE-2025-26464 (In executeAppFunction of AppSearchManagerService.java, there 
is a poss ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26463 (In allowPackageAccess of multiple files, resource exhaustion 
is possib ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26462 (In AccessibilityServiceConnection.java, there is a possible 
background ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26458 (In multiple functions of LocationProviderManager.java, there 
is a poss ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26456 (In multiple functions of DexUseManagerLocal.java, there is a 
possible  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26455 (In multiple functions of NdkMediaCodec.cpp, there is a 
possible out of ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26454 (In validateUriSchemeAndPermission of 
DisclaimersParserImpl.java , ther ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26453 (In isContentUriForOtherUser of BluetoothOppSendFileInfo.java, 
there is ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26452 (In loadDrawableForCookie of ResourcesImpl.java, there is a 
possible wa ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26450 (In onInputEvent of IInputMethodSessionWrapper.java, there is a 
possibl ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26449 (In multiple locations, there is a possible permanent denial of 
service ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26448 (In writeToParcel of CursorWindow.cpp, there is a possible out 
of bound ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26445 (In offerNetwork of ConnectivityService.java, there is a 
possible leak  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26444 (In onHandleForceStop of VoiceInteractionManagerService.java, 
there is  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26443 (In parseHtml of HtmlToSpannedParser.java, there is a possible 
way to i ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26442 (In onCreate of NotificationAccessConfirmationActivity.java, 
there is a ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26441 (In add_attr of sdp_discovery.cc, there is a possible out of 
bounds rea ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26440 (In multiple functions of CameraService.cpp, there is a 
possible way to ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26439 (In getComponentName of AccessibilitySettingsUtils.java, there 
is a pos ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26438 (In smp_process_secure_connection_oob_data of smp_act.cc, there 
is a po ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26437 (In CredentialManagerServiceStub of 
CredentialManagerService.java, ther ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26436 (In clearAllowBgActivityStarts of PendingIntentRecord.java, 
there is a  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26435 (In updateState of 
ContentProtectionTogglePreferenceController.java, th ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26432 (In multiple locations, there is a possible way to persistently 
DoS the ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26431 (In setupAccessibilityServices of AccessibilityFragment.java, 
there is  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26430 (In getDestinationForApp of SpaAppBridgeActivity, there is a 
possible c ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26429 (In collectOps of AppOpsService.java, there is a possible way 
to cause  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26428 (In startLockTaskMode of LockTaskController.java, there is a 
possible l ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26427 (In multiple locations, there is a possible Android/data access 
due to  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26426 (In BroadcastController.java of 
registerReceiverWithFeatureTraced, ther ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26425 (In multiple functions of RoleService.java, there is a possible 
permiss ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26424 (In multiple functions of VpnManager.java, there is a possible 
cross-us ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26423 (In validateIpConfiguration of WifiConfigurationUtil.java, 
there is a p ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26422 (In dump of WindowManagerService.java, there is a possible way 
of runni ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26421 (In multiple locations, there is a possible lock screen bypass 
due to a ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26420 (In multiple functions of GrantPermissionsActivity.java , there 
is a po ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-26419 (In initPhoneSwitch of SystemSettingsFragment.java, there is a 
possible ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-25048 (IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 
7.0.3 i ...)
        NOT-FOR-US: IBM
 CVE-2025-23302 (NVIDIA HGX and DGX contain a vulnerability where a 
misconfiguration of ...)
@@ -297,37 +297,37 @@ CVE-2025-23257 (NVIDIA DOCA contains a vulnerability in 
the collectx-clxapidev D
 CVE-2025-23256 (NVIDIA BlueField contains a vulnerability in the management 
interface, ...)
        TODO: check
 CVE-2025-22441 (In getContextForResourcesEnsuringCorrectCachedApkPaths of 
RemoteViews. ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22425 (In onCreate of InstallStart.java, there is a possible 
permissions bypa ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22415 (In android_app of Android.bp, there is a possible way to 
launch any ac ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22414 (In FrpBypassAlertActivity of FrpBypassAlertActivity.java, 
there is a p ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-0089 (In multiple locations, there is a possible way to hijack the 
Launcher  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-0087 (In onCreate of UninstallerActivity.java, there is a possible 
way to un ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-0077 (In multiple functions of UserController.java, there is a 
possible lock ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-0076 (In multiple locations, there is a possible way to view icons 
belonging ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2024-49739 (In MMapVAccess of pmr_os.c, there is a possible out of bounds 
write du ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2024-49731 (In apk-versions.txt, there is a possible corruption of 
telemetry opt-i ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2024-49714 (In avrc_vendor_msg of avrc_opt.cc, there is a possible out of 
bounds w ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2024-43184 (IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 
7.0.3 i ...)
        NOT-FOR-US: IBM
 CVE-2024-40664 (In setupAccessibilityServices of AccessibilityFragment.java , 
there is ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2024-34598 (Improper export of component in GoodLock prior to version 
2.2.04.95 al ...)
        NOT-FOR-US: Samsung Mobile
 CVE-2024-13073 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
        TODO: check
 CVE-2023-35657 (In bta_av_config_ind of bta_av_aact.cc, there is a possible 
out of bou ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-38730 (In the Linux kernel, the following vulnerability has been 
resolved:  i ...)
        - linux 6.16.3-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
@@ -1028,45 +1028,45 @@ CVE-2025-57806 (Local Deep Research is an AI-powered 
research assistant for deep
 CVE-2025-54588 (Envoy is an open source L7 proxy and communication bus 
designed for la ...)
        - envoyproxy <itp> (bug #987544)
 CVE-2025-26416 (In initializeSwizzler of SkBmpStandardCodec.cpp, there is a 
possible o ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22442 (In multiple functions of DevicePolicyManagerService.java, 
there is a p ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22439 (In onLastAccessedStackLoaded of ActionHandler.java , there is 
a possib ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22438 (In afterKeyEventLockedInterruptable of InputDispatcher.cpp, 
there is a ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22437 (In setMediaButtonReceiver of multiple files, there is a 
possible way t ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22435 (In avdt_msg_ind of avdt_msg.cc, there is a possible memory 
corruption  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22434 (In handleKeyGestureEvent of PhoneWindowManager.java, there is 
a possib ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22433 (In canForward of IntentForwarderActivity.java, there is a 
possible byp ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22431 (In multiple locations, there is a possible method for a 
malicious app  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22430 (In isInSignificantPlace of multiple files, there is a possible 
way to  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22429 (In multiple locations, there is a possible way to execute 
arbitrary co ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22428 (In hasInteractAcrossUsersFullPermission of AppInfoBase.java, 
there is  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22427 (In onCreate of NotificationAccessConfirmationActivity.java, 
there is a ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22423 (In ParseTag of dng_ifd.cpp, there is a possible way to crash 
the image ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22422 (In multiple locations, there is a possible way to mislead a 
user into  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22421 (In contentDescForNotification of 
NotificationContentDescription.kt, th ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22419 (In multiple locations, there is a possible way to mislead the 
user int ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22418 (In multiple locations, there is a possible confused deputy due 
to Inte ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22417 (In finishTransition of Transition.java, there is a possible 
way to byp ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-22416 (In onCreate of ChooserActivity.java , there is a possible way 
to view  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2025-21041 (Insecure Storage of Sensitive Information in Secure Folder 
prior to An ...)
        NOT-FOR-US: Samsung Mobile
 CVE-2025-21040 (Improper verification of intent by ExternalBroadcastReceiver 
in S Assi ...)
@@ -1102,15 +1102,15 @@ CVE-2025-21026 (Improper handling of insufficient 
permission in ImsService prior
 CVE-2025-21025 (Improper access control in MARsExemptionManager prior to SMR 
Sep-2025  ...)
        NOT-FOR-US: Samsung Mobile
 CVE-2024-49730 (In FuseDaemon.cpp, there is a possible out of bounds write due 
to memo ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2024-49728 (In generateFileInfo of BluetoothOppSendFileInfo.java, there is 
a possi ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2024-49722 (In showAvatarPicker of EditUserPhotoController.java, there is 
a possib ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2024-49720 (In multiple functions of Permissions.java, there is a possible 
way to  ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2024-40653 (In multiple functions of ConnectionServiceWrapper.java, there 
is a pos ...)
-       TODO: check
+       NOT-FOR-US: Android
 CVE-2024-32444 (Incorrect Privilege Assignment vulnerability in InspiryThemes 
RealHome ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2023-3666 (The Sticky Side Buttons WordPress plugin before 2.0.0 does not 
sanitis ...)


=====================================
data/packages/nfu.yaml
=====================================
@@ -13,6 +13,8 @@
   cna: AMZN
 - reason: AMI
   cna: AMI
+- reason: Android
+  cna: google_android
 - reason: Apple
   cna: apple
 - reason: ASR Microelectronics



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/253ef9686ab86224f9f7348b380b45d3ffbf2aac

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/253ef9686ab86224f9f7348b380b45d3ffbf2aac
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to