Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
b45c086c by security tracker role at 2020-06-04T08:10:24+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,119 @@
+CVE-2020-13815
+       RESERVED
+CVE-2020-13814
+       RESERVED
+CVE-2020-13813
+       RESERVED
+CVE-2020-13812
+       RESERVED
+CVE-2020-13811
+       RESERVED
+CVE-2020-13810
+       RESERVED
+CVE-2020-13809
+       RESERVED
+CVE-2020-13808
+       RESERVED
+CVE-2020-13807
+       RESERVED
+CVE-2020-13806
+       RESERVED
+CVE-2020-13805
+       RESERVED
+CVE-2020-13804
+       RESERVED
+CVE-2020-13803
+       RESERVED
+CVE-2020-13802
+       RESERVED
+CVE-2020-13801
+       RESERVED
+CVE-2020-13799
+       RESERVED
+CVE-2020-13798 (An issue was discovered in Navigate CMS through 2.8.7. It 
allows XSS b ...)
+       TODO: check
+CVE-2020-13797 (An issue was discovered in Navigate CMS through 2.8.7. It 
allows XSS b ...)
+       TODO: check
+CVE-2020-13796 (An issue was discovered in Navigate CMS through 2.8.7. It 
allows XSS b ...)
+       TODO: check
+CVE-2020-13795 (An issue was discovered in Navigate CMS through 2.8.7. It 
allows Direc ...)
+       TODO: check
+CVE-2020-13794
+       RESERVED
+CVE-2020-13793
+       RESERVED
+CVE-2020-13792 (PlayTube 1.8 allows disclosure of user details via 
ajax.php?type=../ad ...)
+       TODO: check
+CVE-2019-20837
+       RESERVED
+CVE-2019-20836
+       RESERVED
+CVE-2019-20835
+       RESERVED
+CVE-2019-20834
+       RESERVED
+CVE-2019-20833
+       RESERVED
+CVE-2019-20832
+       RESERVED
+CVE-2019-20831
+       RESERVED
+CVE-2019-20830
+       RESERVED
+CVE-2019-20829
+       RESERVED
+CVE-2019-20828
+       RESERVED
+CVE-2019-20827
+       RESERVED
+CVE-2019-20826
+       RESERVED
+CVE-2019-20825
+       RESERVED
+CVE-2019-20824
+       RESERVED
+CVE-2019-20823
+       RESERVED
+CVE-2019-20822
+       RESERVED
+CVE-2019-20821
+       RESERVED
+CVE-2019-20820
+       RESERVED
+CVE-2019-20819
+       RESERVED
+CVE-2019-20818
+       RESERVED
+CVE-2019-20817
+       RESERVED
+CVE-2019-20816
+       RESERVED
+CVE-2019-20815
+       RESERVED
+CVE-2019-20814
+       RESERVED
+CVE-2019-20813
+       RESERVED
+CVE-2018-21244
+       RESERVED
+CVE-2018-21243
+       RESERVED
+CVE-2018-21242
+       RESERVED
+CVE-2018-21241
+       RESERVED
+CVE-2018-21240
+       RESERVED
+CVE-2018-21239
+       RESERVED
+CVE-2018-21238
+       RESERVED
+CVE-2018-21237
+       RESERVED
+CVE-2018-21236
+       RESERVED
+CVE-2018-21235
+       RESERVED
 CVE-2020-XXXX [Cross-Site Scripting (XSS) vulnerability via malicious XML 
messages]
        - roundcube 1.4.5+dfsg.1-1 (bug #962124)
        NOTE: 1.4.x: 
https://github.com/roundcube/roundcubemail/commit/ccaccae6653031b809b4347a60021951e19a0e43
@@ -7,6 +123,7 @@ CVE-2020-XXXX [Cross-Site Scripting (XSS) vulnerability in 
template object 'user
        NOTE: 1.4.x: 
https://github.com/roundcube/roundcubemail/commit/4beec65d40c5e5b1f2bace935c110baf05e10ae5
        NOTE: 1.3.x: 
https://github.com/roundcube/roundcubemail/commit/37e2bc745723ef6322f0f785aefd0b9313a40f19
 CVE-2020-13800 [ati-vga: infinite recursion in ati_mm_read/write calls may 
lead to DoS]
+       RESERVED
        - qemu <unfixed>
        [buster] - qemu <not-affected> (Vulnerable code introduced later)
        [stretch] - qemu <not-affected> (Vulnerable code introduced later)
@@ -14,6 +131,7 @@ CVE-2020-13800 [ati-vga: infinite recursion in 
ati_mm_read/write calls may lead
        NOTE: https://www.openwall.com/lists/oss-security/2020/06/04/2
        NOTE: 
https://lists.gnu.org/archive/html/qemu-devel/2020-06/msg00833.html
 CVE-2020-13791 [ati-vga: OOB access while reading PCI configuration may lead 
to DoS]
+       RESERVED
        - qemu <unfixed>
        [buster] - qemu <not-affected> (Vulnerable code introduced later)
        [stretch] - qemu <not-affected> (Vulnerable code introduced later)
@@ -46,8 +164,7 @@ CVE-2020-13779
        RESERVED
 CVE-2020-13778
        RESERVED
-CVE-2020-13777 [session resumption works without master key allowing MITM]
-       RESERVED
+CVE-2020-13777 (GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for 
encrypting  ...)
        - gnutls28 <unfixed>
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1843723
        NOTE: https://gitlab.com/gnutls/gnutls/-/issues/1011
@@ -7513,14 +7630,14 @@ CVE-2020-11096
        RESERVED
 CVE-2020-11095
        RESERVED
-CVE-2020-11094
-       RESERVED
+CVE-2020-11094 (The October CMS debugbar plugin before version 3.1.0 contains 
a featur ...)
+       TODO: check
 CVE-2020-11093
        RESERVED
 CVE-2020-11092
        RESERVED
-CVE-2020-11091
-       RESERVED
+CVE-2020-11091 (In Weave Net before version 2.6.3, an attacker able to run a 
process a ...)
+       TODO: check
 CVE-2020-11090
        RESERVED
 CVE-2020-11089 (In FreeRDP before 2.1.0, there is an out-of-bound read in irp 
function ...)
@@ -7564,8 +7681,7 @@ CVE-2020-11082 (In Kaminari before 1.2.1, there is a 
vulnerability that would al
        NOTE: 
https://github.com/kaminari/kaminari/commit/8dd52a1aed3d2fa2835d836de23fc0d8c4ff5db8
 CVE-2020-11081
        RESERVED
-CVE-2020-11080 [HTTP/2 Large Settings Frame DoS]
-       RESERVED
+CVE-2020-11080 (In nghttp2 before version 1.41.0, the overly large HTTP/2 
SETTINGS fra ...)
        - nodejs <unfixed> (bug #962145)
        [stretch] - nodejs <ignored> (Nodejs in stretch not covered by security 
support)
        NOTE: 
https://nodejs.org/en/blog/vulnerability/june-2020-security-releases/#http-2-large-settings-frame-dos-low-cve-2020-11080
@@ -9391,14 +9507,14 @@ CVE-2020-10551 (QQBrowser before 10.5.3870.400 installs 
a Windows service TsServ
        NOT-FOR-US: QQBrowser
 CVE-2020-10550
        RESERVED
-CVE-2020-10549
-       RESERVED
-CVE-2020-10548
-       RESERVED
-CVE-2020-10547
-       RESERVED
-CVE-2020-10546
-       RESERVED
+CVE-2020-10549 (rConfig 3.9.4 and previous versions has unauthenticated 
snippets.inc.p ...)
+       TODO: check
+CVE-2020-10548 (rConfig 3.9.4 and previous versions has unauthenticated 
devices.inc.ph ...)
+       TODO: check
+CVE-2020-10547 (rConfig 3.9.4 and previous versions has unauthenticated 
compliancepoli ...)
+       TODO: check
+CVE-2020-10546 (rConfig 3.9.4 and previous versions has unauthenticated 
compliancepoli ...)
+       TODO: check
 CVE-2020-10545
        RESERVED
 CVE-2020-10544 (An XSS issue was discovered in tooltip/tooltip.js in PrimeTek 
PrimeFac ...)
@@ -17589,8 +17705,8 @@ CVE-2020-7032
        RESERVED
 CVE-2020-7031
        RESERVED
-CVE-2020-7030
-       RESERVED
+CVE-2020-7030 (A sensitive information disclosure vulnerability was discovered 
in the ...)
+       TODO: check
 CVE-2020-7029
        RESERVED
 CVE-2020-7028
@@ -18869,30 +18985,30 @@ CVE-2020-6506
        RESERVED
 CVE-2020-6505
        RESERVED
-CVE-2020-6504
-       RESERVED
-CVE-2020-6503
-       RESERVED
-CVE-2020-6502
-       RESERVED
-CVE-2020-6501
-       RESERVED
-CVE-2020-6500
-       RESERVED
-CVE-2020-6499
-       RESERVED
-CVE-2020-6498
-       RESERVED
-CVE-2020-6497
-       RESERVED
-CVE-2020-6496
-       RESERVED
-CVE-2020-6495
-       RESERVED
-CVE-2020-6494
-       RESERVED
-CVE-2020-6493
-       RESERVED
+CVE-2020-6504 (Insufficient policy enforcement in notifications in Google 
Chrome prio ...)
+       TODO: check
+CVE-2020-6503 (Inappropriate implementation in accessibility in Google Chrome 
prior t ...)
+       TODO: check
+CVE-2020-6502 (Incorrect implementation in permissions in Google Chrome prior 
to 80.0 ...)
+       TODO: check
+CVE-2020-6501 (Insufficient policy enforcement in CSP in Google Chrome prior 
to 80.0. ...)
+       TODO: check
+CVE-2020-6500 (Inappropriate implementation in interstitials in Google Chrome 
prior t ...)
+       TODO: check
+CVE-2020-6499 (Inappropriate implementation in AppCache in Google Chrome prior 
to 80. ...)
+       TODO: check
+CVE-2020-6498 (Incorrect implementation in user interface in Google Chrome on 
iOS pri ...)
+       TODO: check
+CVE-2020-6497 (Insufficient policy enforcement in Omnibox in Google Chrome on 
iOS pri ...)
+       TODO: check
+CVE-2020-6496 (Use after free in payments in Google Chrome on MacOS prior to 
83.0.410 ...)
+       TODO: check
+CVE-2020-6495 (Insufficient policy enforcement in developer tools in Google 
Chrome pr ...)
+       TODO: check
+CVE-2020-6494 (Incorrect security UI in payments in Google Chrome on Android 
prior to ...)
+       TODO: check
+CVE-2020-6493 (Use after free in WebAuthentication in Google Chrome prior to 
83.0.410 ...)
+       TODO: check
 CVE-2020-6492
        RESERVED
 CVE-2020-6491 (Insufficient data validation in site information in Google 
Chrome prio ...)
@@ -19008,8 +19124,8 @@ CVE-2020-6455 (Out of bounds read in WebSQL in Google 
Chrome prior to 81.0.4044.
 CVE-2020-6454 (Use after free in extensions in Google Chrome prior to 
81.0.4044.92 al ...)
        - chromium 81.0.4044.92-1
        [stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2020-6453
-       RESERVED
+CVE-2020-6453 (Inappropriate implementation in V8 in Google Chrome prior to 
80.0.3987 ...)
+       TODO: check
 CVE-2020-6452 (Heap buffer overflow in media in Google Chrome prior to 
80.0.3987.162  ...)
        {DSA-4654-1}
        - chromium 80.0.3987.162-1
@@ -19120,8 +19236,8 @@ CVE-2020-6420 (Insufficient policy enforcement in media 
in Google Chrome prior t
        {DSA-4638-1}
        - chromium 80.0.3987.132-1
        [stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2020-6419
-       RESERVED
+CVE-2020-6419 (Out of bounds write in V8 in Google Chrome prior to 
81.0.4044.92 allow ...)
+       TODO: check
 CVE-2020-6418 (Type confusion in V8 in Google Chrome prior to 80.0.3987.122 
allowed a ...)
        {DSA-4638-1}
        - chromium 80.0.3987.122-1
@@ -21635,16 +21751,16 @@ CVE-2020-5301 (SimpleSAMLphp versions before 1.18.6 
contain an information discl
        - simplesamlphp <not-affected> (Windows-only issue)
 CVE-2020-5300 (In Hydra (an OAuth2 Server and OpenID Certified&#8482; OpenID 
Connect  ...)
        NOT-FOR-US: ORY Hydra
-CVE-2020-5299
-       RESERVED
-CVE-2020-5298
-       RESERVED
-CVE-2020-5297
-       RESERVED
-CVE-2020-5296
-       RESERVED
-CVE-2020-5295
-       RESERVED
+CVE-2020-5299 (In OctoberCMS (october/october composer package) versions from 
1.0.319 ...)
+       TODO: check
+CVE-2020-5298 (In OctoberCMS (october/october composer package) versions from 
1.0.319 ...)
+       TODO: check
+CVE-2020-5297 (In OctoberCMS (october/october composer package) versions from 
1.0.319 ...)
+       TODO: check
+CVE-2020-5296 (In OctoberCMS (october/october composer package) versions from 
1.0.319 ...)
+       TODO: check
+CVE-2020-5295 (In OctoberCMS (october/october composer package) versions from 
1.0.319 ...)
+       TODO: check
 CVE-2020-5294 (PrestaShop module ps_facetedsearch versions before 2.1.0 has a 
reflect ...)
        NOT-FOR-US: PrestaShop
 CVE-2020-5293 (In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are 
improper ...)
@@ -321863,8 +321979,8 @@ CVE-2011-2864 (Google Chrome before 14.0.835.163 does 
not properly handle Tibeta
        - chromium-browser 14.0.835.163~r101024-1
        [squeeze] - chromium-browser <not-affected>
        - webkit <not-affected> (chromium specific)
-CVE-2011-2863
-       RESERVED
+CVE-2011-2863 (Insufficient policy enforcement in V8 in Google Chrome prior to 
14.0.0 ...)
+       TODO: check
 CVE-2011-2862 (Google V8, as used in Google Chrome before 14.0.835.163, does 
not prop ...)
        - chromium-browser 14.0.835.163~r101024-1
        [squeeze] - chromium-browser <not-affected>
@@ -324801,8 +324917,8 @@ CVE-2011-1806 (Google Chrome before 11.0.696.71 does 
not properly implement the
        - chromium-browser 11.0.696.71~r86024-1
        [squeeze] - chromium-browser <not-affected>
        - webkit <not-affected> (chromium specific)
-CVE-2011-1805
-       RESERVED
+CVE-2011-1805 (Bad cast in CSS in Google Chrome prior to 11.0.0.0 allowed a 
remote at ...)
+       TODO: check
 CVE-2011-1804 (rendering/RenderBox.cpp in WebCore in WebKit before r86862, as 
used in ...)
        - chromium-browser 11.0.696.71~r86024-1
        [squeeze] - chromium-browser <not-affected>



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b45c086c25128fc3e8948c2e901e0f31ae6d2364

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b45c086c25128fc3e8948c2e901e0f31ae6d2364
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to