Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: c17eddec by Salvatore Bonaccorso at 2021-08-25T22:54:37+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -2157,7 +2157,7 @@ CVE-2021-39138 (Parse Server is an open source backend that can be deployed to a CVE-2021-39137 (go-ethereum is the official Go implementation of the Ethereum protocol ...) TODO: check CVE-2021-39136 (baserCMS is an open source content management system with a focus on J ...) - TODO: check + NOT-FOR-US: baserCMS CVE-2021-39135 RESERVED CVE-2021-39134 @@ -14024,15 +14024,15 @@ CVE-2017-20005 (NGINX before 1.13.6 has a buffer overflow for years that exceed CVE-2021-33887 (Insufficient verification of data authenticity in Peloton TTR01 up to ...) NOT-FOR-US: Peloton TTR01 CVE-2021-33886 (An improper sanitization of input vulnerability in B. Braun SpaceCom2 ...) - TODO: check + NOT-FOR-US: B. Braun SpaceCom2 CVE-2021-33885 (An Insufficient Verification of Data Authenticity vulnerability in B. ...) - TODO: check + NOT-FOR-US: B. Braun SpaceCom2 CVE-2021-33884 (An Unrestricted Upload of File with Dangerous Type vulnerability in B. ...) - TODO: check + NOT-FOR-US: B. Braun SpaceCom2 CVE-2021-33883 (A Cleartext Transmission of Sensitive Information vulnerability in B. ...) - TODO: check + NOT-FOR-US: B. Braun SpaceCom2 CVE-2021-33882 (A Missing Authentication for Critical Function vulnerability in B. Bra ...) - TODO: check + NOT-FOR-US: B. Braun SpaceCom2 CVE-2021-33881 (On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a w ...) NOT-FOR-US: NXP CVE-2021-33880 (The aaugustin websockets library before 9.1 for Python has an Observab ...) @@ -16139,7 +16139,7 @@ CVE-2021-33017 CVE-2021-33016 RESERVED CVE-2021-33015 (Cscape (All Versions prior to 9.90 SP5) lacks proper validation of use ...) - TODO: check + NOT-FOR-US: Cscape CVE-2021-33014 RESERVED CVE-2021-33013 @@ -16179,7 +16179,7 @@ CVE-2021-32997 CVE-2021-32996 RESERVED CVE-2021-32995 (Cscape (All Versions prior to 9.90 SP5) lacks proper validation of use ...) - TODO: check + NOT-FOR-US: Cscape CVE-2021-32994 RESERVED CVE-2021-32993 @@ -16219,7 +16219,7 @@ CVE-2021-32977 CVE-2021-32976 RESERVED CVE-2021-32975 (Cscape (All Versions prior to 9.90 SP5) lacks proper validation of use ...) - TODO: check + NOT-FOR-US: Cscape CVE-2021-32974 RESERVED CVE-2021-32973 @@ -18675,7 +18675,7 @@ CVE-2021-31991 CVE-2021-31990 RESERVED CVE-2021-31989 (A user with permission to log on to the machine hosting the AXIS Devic ...) - TODO: check + NOT-FOR-US: AXIS CVE-2021-31988 RESERVED CVE-2021-31987 @@ -43652,7 +43652,7 @@ CVE-2021-21779 (A use-after-free vulnerability exists in the way Webkit’s [bullseye] - wpewebkit <postponed> (Minor issue, fix along with next update) NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2021-1238 CVE-2021-21778 (A denial of service vulnerability exists in the ASDU message processin ...) - TODO: check + NOT-FOR-US: MZ Automation GmbH lib60870.NET CVE-2021-21777 (An information disclosure vulnerability exists in the Ethernet/IP UDP ...) NOT-FOR-US: EIP Stack Group OpENer CVE-2021-21776 (An out-of-bounds write vulnerability exists in the SGI Format Buffer S ...) @@ -80091,7 +80091,7 @@ CVE-2020-18919 CVE-2020-18918 RESERVED CVE-2020-18917 (The plus/search.php component in DedeCMS 5.7 SP2 allows remote attacke ...) - TODO: check + NOT-FOR-US: DedeCMS CVE-2020-18916 RESERVED CVE-2020-18915 @@ -80099,7 +80099,7 @@ CVE-2020-18915 CVE-2020-18914 RESERVED CVE-2020-18913 (EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerabi ...) - TODO: check + NOT-FOR-US: EARCLINK ESPCMS-P8 CVE-2020-18912 RESERVED CVE-2020-18911 @@ -210563,7 +210563,7 @@ CVE-2018-10792 CVE-2018-10791 RESERVED CVE-2018-10790 (The AP4_CttsAtom class in Core/Ap4CttsAtom.cpp in Bento4 1.5.1.0 allow ...) - TODO: check + NOT-FOR-US: Bento4 CVE-2018-10789 RESERVED CVE-2018-10788 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c17eddec2102316813d3871474e42f80aeae6e2c -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c17eddec2102316813d3871474e42f80aeae6e2c You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits