Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c8c28049 by Moritz Muehlenhoff at 2020-07-03T12:04:11+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -889,7 +889,7 @@ CVE-2020-15093
 CVE-2020-15092
        RESERVED
 CVE-2020-15091 (TenderMint from version 0.33.0 and before version 0.33.6 
allows block  ...)
-       TODO: check
+       NOT-FOR-US: TenderMint
 CVE-2020-15090
        RESERVED
 CVE-2020-15089
@@ -903,7 +903,7 @@ CVE-2020-15086
 CVE-2020-15085 (In Saleor Storefront before version 2.10.3, request data used 
to authe ...)
        NOT-FOR-US: Saleor Storefront
 CVE-2020-15084 (In express-jwt (NPM package) up and including version 5.3.3, 
the algor ...)
-       TODO: check
+       NOT-FOR-US: Node express-jwt
 CVE-2020-15083 (In PrestaShop from version 1.7.0.0 and before version 1.7.6.6, 
if a ta ...)
        NOT-FOR-US: PrestaShop
 CVE-2020-15082 (In PrestaShop from version 1.6.0.1 and before version 1.7.6.6, 
the das ...)
@@ -3171,9 +3171,9 @@ CVE-2020-14175
 CVE-2020-14174
        RESERVED
 CVE-2020-14173 (The file upload feature in Atlassian Jira Server and Data 
Center in af ...)
-       TODO: check
+       NOT-FOR-US: Atlasstian
 CVE-2020-14172 (Affected versions of Atlassian Jira Server and Data Center 
allow remot ...)
-       TODO: check
+       NOT-FOR-US: Atlasstian
 CVE-2020-14171
        RESERVED
 CVE-2020-14170
@@ -4568,7 +4568,7 @@ CVE-2020-13655
 CVE-2020-13654
        RESERVED
 CVE-2020-13653 (An XSS vulnerability exists in the Webmail component of Zimbra 
Collabo ...)
-       TODO: check
+       NOT-FOR-US: Zimbra
 CVE-2020-13652 (An issue was discovered in DigDash 2018R2 before p20200528, 
2019R1 bef ...)
        NOT-FOR-US: DigDash
 CVE-2020-13651 (An issue was discovered in DigDash 2018R2 before p20200528, 
2019R1 bef ...)
@@ -8276,7 +8276,7 @@ CVE-2020-12121
 CVE-2020-12120 (The Correos Express addon for PrestaShop 1.6 through 1.7 
allows remote ...)
        NOT-FOR-US: PrestaShop
 CVE-2020-12119 (Ledger Live before 2.7.0 does not handle Bitcoin's 
Replace-By-Fee (RBF ...)
-       TODO: check
+       NOT-FOR-US: Ledger Live
 CVE-2020-12118 (The keygen protocol implementation in Binance tss-lib before 
1.2.0 all ...)
        NOT-FOR-US: Binance tss-lib
 CVE-2020-12117 (Moxa Service in Moxa NPort 5150A firmware version 1.5 and 
earlier allo ...)
@@ -11994,7 +11994,7 @@ CVE-2020-11076 (In Puma (RubyGem) before 4.3.4 and 
3.12.5, an attacker could smu
 CVE-2020-11075 (In Anchore Engine version 0.7.0, a specially crafted container 
image m ...)
        NOT-FOR-US: Anchore Engine
 CVE-2020-11074 (In PrestaShop from version 1.5.3.0 and before version 1.7.7.6, 
there i ...)
-       TODO: check
+       NOT-FOR-US: PrestaShop
 CVE-2020-11073 (In Autoswitch Python Virtualenv before version 0.16.0, a user 
who ente ...)
        NOT-FOR-US: zsh-autoswitch-virtualenv
 CVE-2020-11072 (In SLP Validate (npm package slp-validate) before version 
1.2.1, users ...)
@@ -19300,7 +19300,7 @@ CVE-2020-8190
 CVE-2020-8189
        RESERVED
 CVE-2020-8188 (We have recently released new version of UniFi Protect firmware 
v1.13. ...)
-       TODO: check
+       NOT-FOR-US: UniFi Protect
 CVE-2020-8187
        RESERVED
 CVE-2020-8186
@@ -19321,7 +19321,7 @@ CVE-2020-8181
 CVE-2020-8180 (A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 
allowed a cod ...)
        NOT-FOR-US: Nextcloud Talk
 CVE-2020-8179 (Improper access control in Nextcloud Deck 1.0.0 allowed an 
attacker to ...)
-       TODO: check
+       NOT-FOR-US: Nextcloud Deck
 CVE-2020-8178
        RESERVED
 CVE-2020-8177
@@ -19330,7 +19330,7 @@ CVE-2020-8177
        NOTE: https://curl.haxx.se/docs/CVE-2020-8177.html
        NOTE: 
https://github.com/curl/curl/commit/8236aba58542c5f89f1d41ca09d84579efb05e22 
(7.71.0)
 CVE-2020-8176 (A cross-site scripting vulnerability exists in koa-shopify-auth 
v3.1.6 ...)
-       TODO: check
+       NOT-FOR-US: koa-shopify-auth
 CVE-2020-8175
        RESERVED
 CVE-2020-8174 [napi_get_value_string_*() allows various kinds of memory 
corruption]



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c8c28049df4b5a35c05bbc4d037e6c22e4456bfa

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c8c28049df4b5a35c05bbc4d037e6c22e4456bfa
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to