Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
af7a3e3e by security tracker role at 2024-10-14T20:12:03+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,119 @@
+CVE-2024-9936 (When manipulating the selection node cache, an attacker may
have been ...)
+ TODO: check
+CVE-2024-9823 (There exists a security vulnerability in Jetty's DosFilter
which can b ...)
+ TODO: check
+CVE-2024-9139 (The affected product permits OS command injection through
improperly r ...)
+ TODO: check
+CVE-2024-9137 (The affected product lacks an authentication check when sending
comman ...)
+ TODO: check
+CVE-2024-8602 (When the XML is read from the codes in the PDF and parsed using
a Docu ...)
+ TODO: check
+CVE-2024-8184 (There exists a security vulnerability in Jetty's
ThreadLimitHandler.ge ...)
+ TODO: check
+CVE-2024-7847 (VULNERABILITY DETAILS Rockwell Automation used the latest
versions of ...)
+ TODO: check
+CVE-2024-6763 (Eclipse Jetty is a lightweight, highly scalable, Java-based web
server ...)
+ TODO: check
+CVE-2024-6762 (Jetty PushSessionCacheFilter can be exploited by
unauthenticated users ...)
+ TODO: check
+CVE-2024-48799 (An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping
1.4.22 allows ...)
+ TODO: check
+CVE-2024-48798 (An issue in Hubble Connected (com.hubbleconnected.vervelife)
2.00.81 a ...)
+ TODO: check
+CVE-2024-48797 (An issue in PCS Engineering Preston Cinema
(com.prestoncinema.app) 0.2 ...)
+ TODO: check
+CVE-2024-48796 (An issue in EQUES com.eques.plug 1.0.1 allows a remote
attacker to obt ...)
+ TODO: check
+CVE-2024-48795 (An issue in Creative Labs Pte Ltd com.creative.apps.xficonnect
2.00.02 ...)
+ TODO: check
+CVE-2024-48793 (An issue in INATRONIC com.inatronic.bmw 2.7.1 allows a remote
attacker ...)
+ TODO: check
+CVE-2024-48792 (An issue in Hideez com.hideez 2.7.8.3 allows a remote attacker
to obta ...)
+ TODO: check
+CVE-2024-48791 (An issue in Plug n Play Camera com.starvedia.mCamView.zwave
5.5.1 allo ...)
+ TODO: check
+CVE-2024-48790 (An issue in ILIFE com.ilife.home.global 1.8.7 allows a remote
attacker ...)
+ TODO: check
+CVE-2024-48789 (An issue in INATRONIC com.inatronic.drivedeck.home 2.6.23
allows a rem ...)
+ TODO: check
+CVE-2024-48261
+ REJECTED
+CVE-2024-48259 (Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via
station ...)
+ TODO: check
+CVE-2024-48257 (Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes
station_id SQL in ...)
+ TODO: check
+CVE-2024-48255 (Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id
SQL inject ...)
+ TODO: check
+CVE-2024-48253 (Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL
injection.)
+ TODO: check
+CVE-2024-48251 (Wavelog 1.8.5 allows Activated_gridmap_model.php
get_band_confirmed SQ ...)
+ TODO: check
+CVE-2024-48249 (Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL
injectio ...)
+ TODO: check
+CVE-2024-48168 (A stack overflow vulnerability exists in the sub_402280
function of th ...)
+ TODO: check
+CVE-2024-48153 (DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious
command ...)
+ TODO: check
+CVE-2024-48150 (D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in
the sub_ ...)
+ TODO: check
+CVE-2024-48120 (X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting
(XSS) in the ...)
+ TODO: check
+CVE-2024-48119 (Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the
module par ...)
+ TODO: check
+CVE-2024-47885 (The Astro web framework has a DOM Clobbering gadget in the
client-side ...)
+ TODO: check
+CVE-2024-47831 (Next.js is a React Framework for the Web. Cersions on the
10.x, 11.x, ...)
+ TODO: check
+CVE-2024-47826 (eLabFTW is an open source electronic lab notebook for research
labs. A ...)
+ TODO: check
+CVE-2024-47767 (Tuleap is a tool for end to end traceability of application
and system ...)
+ TODO: check
+CVE-2024-47766 (Tuleap is a tool for end to end traceability of application
and system ...)
+ TODO: check
+CVE-2024-46988 (Tuleap is a tool for end to end traceability of application
and system ...)
+ TODO: check
+CVE-2024-46980 (Tuleap is a tool for end to end traceability of application
and system ...)
+ TODO: check
+CVE-2024-46911 (Cross-site Resource Forgery (CSRF), Privilege escalation
vulnerability ...)
+ TODO: check
+CVE-2024-46535 (Jepaas v7.2.8 was discovered to contain a SQL injection
vulnerability ...)
+ TODO: check
+CVE-2024-46528 (An Insecure Direct Object Reference (IDOR) vulnerability in
KubeSphere ...)
+ TODO: check
+CVE-2024-45741 (In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk
Cloud P ...)
+ TODO: check
+CVE-2024-45740 (In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk
Cloud P ...)
+ TODO: check
+CVE-2024-45739 (In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6,
the softw ...)
+ TODO: check
+CVE-2024-45738 (In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6,
the softw ...)
+ TODO: check
+CVE-2024-45737 (In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6
and Splunk ...)
+ TODO: check
+CVE-2024-45736 (In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6
and Splunk ...)
+ TODO: check
+CVE-2024-45735 (In Splunk Enterprise versions below 9.2.3 and 9.1.6, and
Splunk Secure ...)
+ TODO: check
+CVE-2024-45734 (In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a
low-privilege ...)
+ TODO: check
+CVE-2024-45733 (In Splunk Enterprise for Windows versions below 9.2.3 and
9.1.6, a low ...)
+ TODO: check
+CVE-2024-45732 (In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions
below 9. ...)
+ TODO: check
+CVE-2024-45731 (In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3,
and 9.1. ...)
+ TODO: check
+CVE-2024-43701 (Software installed and run as a non-privileged user may
conduct GPU sy ...)
+ TODO: check
+CVE-2024-41997 (An issue was discovered in version of Warp Terminal prior to
2024.07.1 ...)
+ TODO: check
+CVE-2024-40616
+ REJECTED
+CVE-2023-50780 (Apache ActiveMQ Artemis allows access to diagnostic
information and co ...)
+ TODO: check
+CVE-2023-48082 (Nagios XI before 5.11.3 2024R1 was discovered to improperly
handle API ...)
+ TODO: check
+CVE-2023-45817
+ REJECTED
CVE-2024-9924 (The fix for CVE-2024-26261 was incomplete, and and the specific
packag ...)
NOT-FOR-US: Hgiga OAKlouds
CVE-2024-9923 (The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a
specif ...)
@@ -4169,6 +4285,7 @@ CVE-2024-46985 (DataEase is an open source data
visualization analysis tool. Pri
CVE-2024-46639 (A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2
allows ...)
NOT-FOR-US: HelpDeskZ
CVE-2024-46544 (Incorrect Default Permissions vulnerability in Apache Tomcat
Connector ...)
+ {DLA-3919-1}
- libapache-mod-jk <unfixed> (bug #1082713)
NOTE: https://www.openwall.com/lists/oss-security/2024/09/23/1
NOTE: Fixed by:
https://github.com/apache/tomcat-connectors/commit/d55706e92b65018c2e4c7ab14014a996b0174966
(JK_1_2_50)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/af7a3e3e3a8d54e3f921f6a5cad6de4e4b1e355a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/af7a3e3e3a8d54e3f921f6a5cad6de4e4b1e355a
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits