Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c425aebc by security tracker role at 2021-03-15T20:10:35+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,207 @@
+CVE-2021-3442
+       RESERVED
+CVE-2021-28483
+       RESERVED
+CVE-2021-28482
+       RESERVED
+CVE-2021-28481
+       RESERVED
+CVE-2021-28480
+       RESERVED
+CVE-2021-28479
+       RESERVED
+CVE-2021-28478
+       RESERVED
+CVE-2021-28477
+       RESERVED
+CVE-2021-28476
+       RESERVED
+CVE-2021-28475
+       RESERVED
+CVE-2021-28474
+       RESERVED
+CVE-2021-28473
+       RESERVED
+CVE-2021-28472
+       RESERVED
+CVE-2021-28471
+       RESERVED
+CVE-2021-28470
+       RESERVED
+CVE-2021-28469
+       RESERVED
+CVE-2021-28468
+       RESERVED
+CVE-2021-28467
+       RESERVED
+CVE-2021-28466
+       RESERVED
+CVE-2021-28465
+       RESERVED
+CVE-2021-28464
+       RESERVED
+CVE-2021-28463
+       RESERVED
+CVE-2021-28462
+       RESERVED
+CVE-2021-28461
+       RESERVED
+CVE-2021-28460
+       RESERVED
+CVE-2021-28459
+       RESERVED
+CVE-2021-28458
+       RESERVED
+CVE-2021-28457
+       RESERVED
+CVE-2021-28456
+       RESERVED
+CVE-2021-28455
+       RESERVED
+CVE-2021-28454
+       RESERVED
+CVE-2021-28453
+       RESERVED
+CVE-2021-28452
+       RESERVED
+CVE-2021-28451
+       RESERVED
+CVE-2021-28450
+       RESERVED
+CVE-2021-28449
+       RESERVED
+CVE-2021-28448
+       RESERVED
+CVE-2021-28447
+       RESERVED
+CVE-2021-28446
+       RESERVED
+CVE-2021-28445
+       RESERVED
+CVE-2021-28444
+       RESERVED
+CVE-2021-28443
+       RESERVED
+CVE-2021-28442
+       RESERVED
+CVE-2021-28441
+       RESERVED
+CVE-2021-28440
+       RESERVED
+CVE-2021-28439
+       RESERVED
+CVE-2021-28438
+       RESERVED
+CVE-2021-28437
+       RESERVED
+CVE-2021-28436
+       RESERVED
+CVE-2021-28435
+       RESERVED
+CVE-2021-28434
+       RESERVED
+CVE-2021-28433
+       RESERVED
+CVE-2021-28432
+       RESERVED
+CVE-2021-28431
+       RESERVED
+CVE-2021-28430
+       RESERVED
+CVE-2021-28429
+       RESERVED
+CVE-2021-28428
+       RESERVED
+CVE-2021-28427
+       RESERVED
+CVE-2021-28426
+       RESERVED
+CVE-2021-28425
+       RESERVED
+CVE-2021-28424
+       RESERVED
+CVE-2021-28423
+       RESERVED
+CVE-2021-28422
+       RESERVED
+CVE-2021-28421
+       RESERVED
+CVE-2021-28420
+       RESERVED
+CVE-2021-28419
+       RESERVED
+CVE-2021-28418
+       RESERVED
+CVE-2021-28417
+       RESERVED
+CVE-2021-28416
+       RESERVED
+CVE-2021-28415
+       RESERVED
+CVE-2021-28414
+       RESERVED
+CVE-2021-28413
+       RESERVED
+CVE-2021-28412
+       RESERVED
+CVE-2021-28411
+       RESERVED
+CVE-2021-28410
+       RESERVED
+CVE-2021-28409
+       RESERVED
+CVE-2021-28408
+       RESERVED
+CVE-2021-28407
+       RESERVED
+CVE-2021-28406
+       RESERVED
+CVE-2021-28405
+       RESERVED
+CVE-2021-28404
+       RESERVED
+CVE-2021-28403
+       RESERVED
+CVE-2021-28402
+       RESERVED
+CVE-2021-28401
+       RESERVED
+CVE-2021-28400
+       RESERVED
+CVE-2021-28399
+       RESERVED
+CVE-2021-28398
+       RESERVED
+CVE-2021-28397
+       RESERVED
+CVE-2021-28396
+       RESERVED
+CVE-2021-28395
+       RESERVED
+CVE-2021-28394
+       RESERVED
+CVE-2021-28393
+       RESERVED
+CVE-2021-28392
+       RESERVED
+CVE-2021-28391
+       RESERVED
+CVE-2021-28390
+       RESERVED
+CVE-2021-28389
+       RESERVED
+CVE-2021-28388
+       RESERVED
+CVE-2021-28387
+       RESERVED
+CVE-2021-28386
+       RESERVED
+CVE-2021-28385
+       RESERVED
+CVE-2021-28384
+       RESERVED
+CVE-2021-28383
+       RESERVED
 CVE-2021-28382
        RESERVED
 CVE-2021-28381
@@ -35,8 +239,8 @@ CVE-2021-28365
        RESERVED
 CVE-2021-28364
        RESERVED
-CVE-2021-28363
-       RESERVED
+CVE-2021-28363 (The urllib3 library 1.26.x before 1.26.4 for Python omits SSL 
certific ...)
+       TODO: check
 CVE-2021-28362
        RESERVED
 CVE-2021-28361 (An issue was discovered in Storage Performance Development Kit 
(SPDK)  ...)
@@ -1014,14 +1218,14 @@ CVE-2021-27951
        RESERVED
 CVE-2021-27950
        RESERVED
-CVE-2021-27949
-       RESERVED
-CVE-2021-27948
-       RESERVED
-CVE-2021-27947
-       RESERVED
-CVE-2021-27946
-       RESERVED
+CVE-2021-27949 (Cross-site Scripting vulnerability in MyBB before 1.8.26 via 
Custom mo ...)
+       TODO: check
+CVE-2021-27948 (SQL Injection vulnerability in MyBB before 1.8.26 via User 
Groups. (is ...)
+       TODO: check
+CVE-2021-27947 (SQL Injection vulnerability in MyBB before 1.8.26 via the Copy 
Forum f ...)
+       TODO: check
+CVE-2021-27946 (SQL Injection vulnerability in MyBB before 1.8.26 via poll 
vote count. ...)
+       TODO: check
 CVE-2021-27945
        RESERVED
 CVE-2021-28039 (An issue was discovered in the Linux kernel 5.9.x through 
5.11.3, as u ...)
@@ -1175,16 +1379,16 @@ CVE-2021-27895
        RESERVED
 CVE-2021-27894
        RESERVED
-CVE-2021-27893
-       RESERVED
-CVE-2021-27892
-       RESERVED
-CVE-2021-27891
-       RESERVED
-CVE-2021-27890
-       RESERVED
-CVE-2021-27889
-       RESERVED
+CVE-2021-27893 (SSH Tectia Client and Server before 6.4.19 on Windows allow 
local priv ...)
+       TODO: check
+CVE-2021-27892 (SSH Tectia Client and Server before 6.4.19 on Windows allow 
local priv ...)
+       TODO: check
+CVE-2021-27891 (SSH Tectia Client and Server before 6.4.19 on Windows have 
weak key ge ...)
+       TODO: check
+CVE-2021-27890 (SQL Injection vulnerablity in MyBB before 1.8.26 via theme 
properties  ...)
+       TODO: check
+CVE-2021-27889 (Cross-site Scriptiong (XSS) vulnerability in MyBB before 
1.8.26 via Ne ...)
+       TODO: check
 CVE-2021-27888 (ZendTo before 6.06-4 Beta allows XSS during the display of a 
drop-off  ...)
        NOT-FOR-US: ZendTo
 CVE-2021-27887
@@ -1333,8 +1537,8 @@ CVE-2021-27819
        RESERVED
 CVE-2021-27818
        RESERVED
-CVE-2021-27817
-       RESERVED
+CVE-2021-27817 (A remote command execution vulnerability in shopxo 1.9.3 
allows an att ...)
+       TODO: check
 CVE-2021-27816
        RESERVED
 CVE-2021-27815
@@ -1497,8 +1701,8 @@ CVE-2021-27738
        RESERVED
 CVE-2021-27737
        RESERVED
-CVE-2020-35358
-       RESERVED
+CVE-2020-35358 (DomainMOD domainmod-v4.15.0 is affected by an insufficient 
session exp ...)
+       TODO: check
 CVE-2021-27803 (A vulnerability was discovered in how p2p/p2p_pd.c in 
wpa_supplicant b ...)
        {DLA-2581-1}
        - wpa 2:2.9.0-21
@@ -1596,8 +1800,8 @@ CVE-2021-27697
        RESERVED
 CVE-2021-27696
        RESERVED
-CVE-2021-27695
-       RESERVED
+CVE-2021-27695 (Multiple stored cross-site scripting (XSS) vulnerabilities in 
openMAIN ...)
+       TODO: check
 CVE-2021-27694
        RESERVED
 CVE-2021-27693
@@ -1843,8 +2047,7 @@ CVE-2021-27578
        RESERVED
 CVE-2021-27577
        RESERVED
-CVE-2021-27576
-       RESERVED
+CVE-2021-27576 (If was found that the NetTest web service can be used to 
overload the  ...)
        NOT-FOR-US: Apache OpenMeetings
 CVE-2021-27575
        RESERVED
@@ -2277,10 +2480,10 @@ CVE-2021-27383
        RESERVED
 CVE-2021-27382
        RESERVED
-CVE-2021-27381
-       RESERVED
-CVE-2021-27380
-       RESERVED
+CVE-2021-27381 (A vulnerability has been identified in Solid Edge SE2020 (All 
Versions ...)
+       TODO: check
+CVE-2021-27380 (A vulnerability has been identified in Solid Edge SE2020 (All 
Versions ...)
+       TODO: check
 CVE-2021-27379 (An issue was discovered in Xen through 4.11.x, allowing x86 
Intel HVM  ...)
        - xen 4.14.0+80-gd101b417b7-1
        [stretch] - xen <not-affected> (Incomplete fix for CVE-2020-15565 not 
applied)
@@ -2651,8 +2854,8 @@ CVE-2021-27210 (TP-Link Archer C5v 1.7_181221 devices 
allows remote attackers to
        NOT-FOR-US: TP-Link
 CVE-2021-27209 (In the management interface on TP-Link Archer C5v 1.7_181221 
devices,  ...)
        NOT-FOR-US: TP-Link
-CVE-2021-27208
-       RESERVED
+CVE-2021-27208 (When booting a Zync-7000 SOC device from nand flash memory, 
the nand d ...)
+       TODO: check
 CVE-2021-27207
        RESERVED
 CVE-2021-27206
@@ -3317,10 +3520,10 @@ CVE-2021-26925 (Roundcube before 1.4.11 allows XSS via 
crafted Cascading Style S
        [stretch] - roundcube <not-affected> (Vulnerable code introduced later)
        NOTE: https://roundcube.net/news/2021/02/08/security-update-1.4.11
        NOTE: 
https://github.com/roundcube/roundcubemail/commit/9dc276d5f26042db02754fa1bac6fbd683c6d596
-CVE-2021-26924
-       RESERVED
-CVE-2021-26923
-       RESERVED
+CVE-2021-26924 (An issue was discovered in Argo CD before 1.8.4. Browser XSS 
protectio ...)
+       TODO: check
+CVE-2021-26923 (An issue was discovered in Argo CD before 1.8.4. Accessing the 
endpoin ...)
+       TODO: check
 CVE-2021-26922
        RESERVED
 CVE-2021-26921 (In util/session/sessionmanager.go in Argo CD before 1.8.4, 
tokens cont ...)
@@ -6524,16 +6727,16 @@ CVE-2021-25678
        RESERVED
 CVE-2021-25677
        RESERVED
-CVE-2021-25676
-       RESERVED
-CVE-2021-25675
-       RESERVED
-CVE-2021-25674
-       RESERVED
-CVE-2021-25673
-       RESERVED
-CVE-2021-25672
-       RESERVED
+CVE-2021-25676 (A vulnerability has been identified in RUGGEDCOM RM1224 
(V6.3), SCALAN ...)
+       TODO: check
+CVE-2021-25675 (A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 
(All ver ...)
+       TODO: check
+CVE-2021-25674 (A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 
(All ver ...)
+       TODO: check
+CVE-2021-25673 (A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 
(All ver ...)
+       TODO: check
+CVE-2021-25672 (A vulnerability has been identified in Mendix Forgot Password 
Appstore ...)
+       TODO: check
 CVE-2021-25671
        RESERVED
 CVE-2021-25670
@@ -6542,8 +6745,8 @@ CVE-2021-25669
        RESERVED
 CVE-2021-25668
        RESERVED
-CVE-2021-25667
-       RESERVED
+CVE-2021-25667 (A vulnerability has been identified in RUGGEDCOM RM1224 (All 
versions  ...)
+       TODO: check
 CVE-2021-25666 (A vulnerability has been identified in SCALANCE W780 and W740 
(IEEE 80 ...)
        NOT-FOR-US: Siemens
 CVE-2021-25665
@@ -7377,8 +7580,8 @@ CVE-2021-3169
        RESERVED
 CVE-2021-3168
        RESERVED
-CVE-2021-3167
-       RESERVED
+CVE-2021-3167 (In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication 
tokens ar ...)
+       TODO: check
 CVE-2021-3166 (An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 
devices. An at ...)
        NOT-FOR-US: ASUS devices
 CVE-2021-3165 (SmartAgent 3.1.0 allows a ViewOnly attacker to create a 
SuperUser acco ...)
@@ -7671,8 +7874,8 @@ CVE-2021-3152 (** DISPUTED ** Home Assistant before 
2021.1.3 does not have a pro
        NOT-FOR-US: Home Assistant
 CVE-2021-3151 (i-doit before 1.16.0 is affected by Stored Cross-Site Scripting 
(XSS)  ...)
        NOT-FOR-US: i-doit
-CVE-2021-3150
-       RESERVED
+CVE-2021-3150 (A cross-site scripting (XSS) vulnerability on the Delete 
Personal Data ...)
+       TODO: check
 CVE-2021-3149 (On Netshield NANO 25 10.2.18 devices, 
/usr/local/webmin/System/manual_ ...)
        NOT-FOR-US: Netshield NANO devices
 CVE-2021-3148 (An issue was discovered in SaltStack Salt before 3002.5. 
Sending craft ...)
@@ -10465,8 +10668,8 @@ CVE-2021-23881 (A stored cross site scripting 
vulnerability in ePO extension of
        NOT-FOR-US: McAfee
 CVE-2021-23880 (Improper Access Control in attribute in McAfee Endpoint 
Security (ENS) ...)
        NOT-FOR-US: McAfee
-CVE-2021-23879
-       RESERVED
+CVE-2021-23879 (Unquoted service path vulnerability in McAfee Endpoint Product 
Removal ...)
+       TODO: check
 CVE-2021-23878 (Clear text storage of sensitive Information in memory 
vulnerability in ...)
        NOT-FOR-US: McAfee
 CVE-2021-23877
@@ -11564,12 +11767,12 @@ CVE-2021-23359
        RESERVED
 CVE-2021-23358
        RESERVED
-CVE-2021-23357
-       RESERVED
-CVE-2021-23356
-       RESERVED
-CVE-2021-23355
-       RESERVED
+CVE-2021-23357 (All versions of package github.com/tyktechnologies/tyk/gateway 
are vul ...)
+       TODO: check
+CVE-2021-23356 (This affects all versions of package kill-process-by-name. If 
(attacke ...)
+       TODO: check
+CVE-2021-23355 (This affects all versions of package ps-kill. If 
(attacker-controlled) ...)
+       TODO: check
 CVE-2021-23354 (The package printf before 0.6.1 are vulnerable to Regular 
Expression D ...)
        NOT-FOR-US: Node printf
 CVE-2021-23353 (This affects the package jspdf before 2.3.1. ReDoS is possible 
via the ...)
@@ -14067,8 +14270,7 @@ CVE-2021-22193
        RESERVED
 CVE-2021-22192
        RESERVED
-CVE-2021-22191
-       RESERVED
+CVE-2021-22191 (Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 
3.2.11  ...)
        - wireshark 3.4.4-1
        [buster] - wireshark <postponed> (Minor issue, can be fixed along in 
future update)
        [stretch] - wireshark <postponed> (Minor issue, can be fixed along in 
future update)
@@ -19291,8 +19493,8 @@ CVE-2021-20442 (IBM Security Verify Bridge contains 
hard-coded credentials, such
        NOT-FOR-US: IBM
 CVE-2021-20441 (IBM Security Verify Bridge uses weaker than expected 
cryptographic alg ...)
        NOT-FOR-US: IBM
-CVE-2021-20440
-       RESERVED
+CVE-2021-20440 (IBM API Connect 10.0.0.0, and 2018.4.1.0 through 2018.4.1.13 
does not  ...)
+       TODO: check
 CVE-2021-20439
        RESERVED
 CVE-2021-20438
@@ -19601,8 +19803,7 @@ CVE-2021-20288
        RESERVED
 CVE-2021-20287
        RESERVED
-CVE-2021-20286 [Assertion failure in nbd_unlocked_opt_go in lib/opt.c]
-       RESERVED
+CVE-2021-20286 (A flaw was found in libnbd 1.7.3. An assertion failure in 
nbd_unlocked ...)
        - libnbd 1.6.2-1
        NOTE: Fixed by: 
https://gitlab.com/nbdkit/libnbd/-/commit/2216190ecbbd853648df6a3280c17b345b0907a0
 (v1.6.2)
        NOTE: Fixed by: 
https://gitlab.com/nbdkit/libnbd/-/commit/fb4440de9cc76e9c14bd3ddf3333e78621f40ad0
 (v1.7.3)
@@ -20112,8 +20313,7 @@ CVE-2021-20180
        [buster] - ansible <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1915808
        NOTE: https://github.com/ansible-collections/community.general/pull/1635
-CVE-2021-20179
-       RESERVED
+CVE-2021-20179 (A flaw was found in pki-core. An attacker who has successfully 
comprom ...)
        - dogtag-pki 10.10.2-2
        NOTE: https://github.com/dogtagpki/pki/pull/3475
 CVE-2021-20178 [user data leak in snmp_facts module]
@@ -23419,14 +23619,14 @@ CVE-2020-29558
        RESERVED
 CVE-2020-29557 (An issue was discovered on D-Link DIR-825 R1 devices through 
3.0.1 bef ...)
        NOT-FOR-US: D-Link
-CVE-2020-29556
-       RESERVED
-CVE-2020-29555
-       RESERVED
+CVE-2020-29556 (The Backup functionality in Grav CMS through 1.7.0-rc.17 
allows an aut ...)
+       TODO: check
+CVE-2020-29555 (The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 
allows  ...)
+       TODO: check
 CVE-2020-29554
        RESERVED
-CVE-2020-29553
-       RESERVED
+CVE-2020-29553 (The Scheduler in Grav CMS through 1.7.0-rc.17 allows an 
attacker to ex ...)
+       TODO: check
 CVE-2020-29552 (An issue was discovered in URVE Build 24.03.2020. By using the 
_intern ...)
        NOT-FOR-US: URVE
 CVE-2020-29551 (An issue was discovered in URVE Build 24.03.2020. Using the 
_internal/ ...)
@@ -27462,12 +27662,12 @@ CVE-2020-28389
        RESERVED
 CVE-2020-28388 (A vulnerability has been identified in Nucleus NET (All 
versions &lt;  ...)
        NOT-FOR-US: Siemens
-CVE-2020-28387
-       RESERVED
+CVE-2020-28387 (A vulnerability has been identified in Solid Edge SE2020 (All 
Versions ...)
+       TODO: check
 CVE-2020-28386 (A vulnerability has been identified in Solid Edge SE2020 (All 
Versions ...)
        NOT-FOR-US: Siemens
-CVE-2020-28385
-       RESERVED
+CVE-2020-28385 (A vulnerability has been identified in Solid Edge SE2020 (All 
Versions ...)
+       TODO: check
 CVE-2020-28384 (A vulnerability has been identified in Solid Edge SE2020 (All 
Versions ...)
        NOT-FOR-US: Siemens
 CVE-2020-28383 (A vulnerability has been identified in JT2Go (All Versions 
&lt; V13.1. ...)
@@ -29520,8 +29720,8 @@ CVE-2020-28151
        RESERVED
 CVE-2020-28150 (I-Net Software Clear Reports 20.10.136 web application accepts 
a user- ...)
        NOT-FOR-US: I-Net Software Clear Reports
-CVE-2020-28149
-       RESERVED
+CVE-2020-28149 (myDBR 5.8.3/4262 is affected by: Cross Site Scripting (XSS). 
The impac ...)
+       TODO: check
 CVE-2020-28148
        RESERVED
 CVE-2020-28147
@@ -37158,18 +37358,18 @@ CVE-2020-25243
        RESERVED
 CVE-2020-25242
        RESERVED
-CVE-2020-25241
-       RESERVED
-CVE-2020-25240
-       RESERVED
-CVE-2020-25239
-       RESERVED
+CVE-2020-25241 (A vulnerability has been identified in SIMATIC MV400 family 
(All Versi ...)
+       TODO: check
+CVE-2020-25240 (A vulnerability has been identified in SINEMA Remote Connect 
Server (A ...)
+       TODO: check
+CVE-2020-25239 (A vulnerability has been identified in SINEMA Remote Connect 
Server (A ...)
+       TODO: check
 CVE-2020-25238 (A vulnerability has been identified in PCS neo (Administration 
Console ...)
        NOT-FOR-US: Siemens
 CVE-2020-25237 (A vulnerability has been identified in SINEC NMS (All versions 
&lt; V1 ...)
        NOT-FOR-US: Siemens
-CVE-2020-25236
-       RESERVED
+CVE-2020-25236 (A vulnerability has been identified in LOGO! 8 BM (incl. 
SIPLUS varian ...)
+       TODO: check
 CVE-2020-25235 (A vulnerability has been identified in LOGO! 8 BM (incl. 
SIPLUS varian ...)
        NOT-FOR-US: Siemens
 CVE-2020-25234 (A vulnerability has been identified in LOGO! 8 BM (incl. 
SIPLUS varian ...)
@@ -37772,14 +37972,14 @@ CVE-2020-24987 (Tenda AC18 Router through 
V15.03.05.05_EN and through V15.03.05.
        NOT-FOR-US: Tenda AC18 Router
 CVE-2020-24986 (Concrete5 up to and including 8.5.2 allows Unrestricted Upload 
of File ...)
        NOT-FOR-US: Concrete5
-CVE-2020-24985
-       RESERVED
+CVE-2020-24985 (An issue was discovered in Quadbase EspressReports ES 7 Update 
9. An a ...)
+       TODO: check
 CVE-2020-24984 (An issue was discovered in Quadbase EspressReports ES 7 Update 
9. It a ...)
        NOT-FOR-US: Quadbase EspressReports
 CVE-2020-24983 (An issue was discovered in Quadbase EspressReports ES 7 Update 
9. An u ...)
        NOT-FOR-US: Quadbase EspressReports
-CVE-2020-24982
-       RESERVED
+CVE-2020-24982 (An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 
Update 9 ...)
+       TODO: check
 CVE-2020-24981 (An Incorrect Access Control vulnerability exists in 
/ucms/chk.php in U ...)
        NOT-FOR-US: UCMS
 CVE-2020-24980
@@ -38014,8 +38214,8 @@ CVE-2020-24879
        RESERVED
 CVE-2020-24878
        RESERVED
-CVE-2020-24877
-       RESERVED
+CVE-2020-24877 (A SQL injection vulnerability in zzzphp v1.8.0 through 
/form/index.php ...)
+       TODO: check
 CVE-2020-24876 (Use of a hard-coded cryptographic key in Pancake versions &lt; 
4.13.29 ...)
        NOT-FOR-US: Pancake
 CVE-2020-24875
@@ -88575,8 +88775,8 @@ CVE-2020-4186 (IBM Security Guardium 10.5, 10.6, and 
11.1 could disclose sensiti
        NOT-FOR-US: IBM
 CVE-2020-4185 (IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than 
expected c ...)
        NOT-FOR-US: IBM
-CVE-2020-4184
-       RESERVED
+CVE-2020-4184 (IBM Security Guardium 11.2 performs an operation at a privilege 
level  ...)
+       TODO: check
 CVE-2020-4183 (IBM Security Guardium 11.1 is vulnerable to cross-site 
scripting. This ...)
        NOT-FOR-US: IBM
 CVE-2020-4182 (IBM Security Guardium 11.1 is vulnerable to cross-site 
scripting. This ...)
@@ -96595,7 +96795,7 @@ CVE-2019-19302
        RESERVED
 CVE-2019-19301 (A vulnerability has been identified in SCALANCE X-200 switch 
family (i ...)
        NOT-FOR-US: Siemens
-CVE-2019-19300 (A vulnerability has been identified in KTK ATE530S (All 
versions), SID ...)
+CVE-2019-19300 (A vulnerability has been identified in Development/Evaluation 
Kits for ...)
        NOT-FOR-US: Siemens
 CVE-2019-19299 (A vulnerability has been identified in SiNVR 3 Central Control 
Server  ...)
        NOT-FOR-US: SiNVR 3 Central Control Server (CCS)
@@ -125523,9 +125723,9 @@ CVE-2019-10928 (A vulnerability has been identified 
in SCALANCE SC-600 (V2.0). A
        NOT-FOR-US: Siemens
 CVE-2019-10927 (A vulnerability has been identified in SCALANCE SC-600 (V2.0), 
SCALANC ...)
        NOT-FOR-US: Siemens
-CVE-2019-10926 (A vulnerability has been identified in SIMATIC Ident MV420 
family (All ...)
+CVE-2019-10926 (A vulnerability has been identified in SIMATIC MV400 family 
(All Versi ...)
        NOT-FOR-US: Siemens
-CVE-2019-10925 (A vulnerability has been identified in SIMATIC Ident MV420 
family (All ...)
+CVE-2019-10925 (A vulnerability has been identified in SIMATIC MV400 family 
(All Versi ...)
        NOT-FOR-US: Siemens
 CVE-2019-10924 (A vulnerability has been identified in LOGO! Soft Comfort (All 
version ...)
        NOT-FOR-US: Siemens



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c425aebc96dbab64635e86180c397ffe01998f25

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c425aebc96dbab64635e86180c397ffe01998f25
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to