Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
932dda8c by security tracker role at 2024-10-15T20:12:04+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,4 +1,278 @@
-CVE-2024-47674 [mm: avoid leaving partial pfn mappings around in error case]
+CVE-2024-9986 (A vulnerability was found in code-projects Blood Bank
Management Syste ...)
+ TODO: check
+CVE-2024-9985 (Enterprise Cloud Database from Ragic does not properly validate
the fi ...)
+ TODO: check
+CVE-2024-9984 (Enterprise Cloud Database from Ragic does not authenticate
access to s ...)
+ TODO: check
+CVE-2024-9983 (Enterprise Cloud Database from Ragic does not properly validate
a spec ...)
+ TODO: check
+CVE-2024-9979 (A flaw was found in PyO3. This vulnerability causes a
use-after-free i ...)
+ TODO: check
+CVE-2024-9977 (A vulnerability, which was classified as critical, was found in
MitraS ...)
+ TODO: check
+CVE-2024-9976 (A vulnerability classified as critical has been found in
code-projects ...)
+ TODO: check
+CVE-2024-9975 (A vulnerability was found in SourceCodester Drag and Drop Image
Upload ...)
+ TODO: check
+CVE-2024-9974 (A vulnerability was found in SourceCodester Online Eyewear Shop
1.0. I ...)
+ TODO: check
+CVE-2024-9973 (A vulnerability was found in SourceCodester Online Eyewear Shop
1.0. I ...)
+ TODO: check
+CVE-2024-9925 (SQL injection vulnerability in TAI Smart Factory's QPLANT SF
version 1 ...)
+ TODO: check
+CVE-2024-9895 (The Smart Online Order for Clover plugin for WordPress is
vulnerable t ...)
+ TODO: check
+CVE-2024-9676 (A vulnerability was found in Podman, Buildah, and CRI-O. A
symlink tra ...)
+ TODO: check
+CVE-2024-9506 (Improper regular expression in Vue's parseHTML function leads
to a pot ...)
+ TODO: check
+CVE-2024-5749 (Certain HP DesignJet products may be vulnerable to credential
reflecti ...)
+ TODO: check
+CVE-2024-49388 (Sensitive information manipulation due to improper
authorization. The ...)
+ TODO: check
+CVE-2024-49387 (Cleartext transmission of sensitive information in
acep-collector serv ...)
+ TODO: check
+CVE-2024-49384 (Excessive attack surface in acep-collector service due to
binding to a ...)
+ TODO: check
+CVE-2024-49383 (Excessive attack surface in acep-importer service due to
binding to an ...)
+ TODO: check
+CVE-2024-49382 (Excessive attack surface in archive-server service due to
binding to a ...)
+ TODO: check
+CVE-2024-49195 (Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer
underrun in pkw ...)
+ TODO: check
+CVE-2024-48948 (The Elliptic package 6.5.7 for Node.js, in its for ECDSA
implementatio ...)
+ TODO: check
+CVE-2024-48915 (Agent Dart is an agent library built for Internet Computer for
Dart an ...)
+ TODO: check
+CVE-2024-48914 (Vendure is an open-source headless commerce platform. Prior to
version ...)
+ TODO: check
+CVE-2024-48913 (Hono, a web framework, prior to version 4.6.5 is vulnerable to
bypass ...)
+ TODO: check
+CVE-2024-48624 (In segments\edit.php of DomainMOD below v4.12.0, the segid
parameter i ...)
+ TODO: check
+CVE-2024-48623 (In queue\index.php of DomainMOD below v4.12.0, the list_id and
domain_ ...)
+ TODO: check
+CVE-2024-48622 (A cross-site scripting (XSS) issue in DomainMOD below v4.12.0
allows r ...)
+ TODO: check
+CVE-2024-48283 (Phpgurukul User Registration & Login and User Management
System 3.2 is ...)
+ TODO: check
+CVE-2024-48282 (A SQL Injection vulnerability was found in
/password-recovery.php of P ...)
+ TODO: check
+CVE-2024-48280 (A SQL Injection vulnerability was found in /search-result.php
of PHPGu ...)
+ TODO: check
+CVE-2024-48279 (A HTML Injection vulnerability was found in /search-result.php
of PHPG ...)
+ TODO: check
+CVE-2024-48278 (Phpgurukul User Registration & Login and User Management
System 3.2 is ...)
+ TODO: check
+CVE-2024-47945 (The devices are vulnerable to session hijacking due to
insufficient e ...)
+ TODO: check
+CVE-2024-47944 (The device directly executes .patch firmware upgrade files on
a USB st ...)
+ TODO: check
+CVE-2024-47943 (The firmware upgrade function in the admin web interface of
the Rittal ...)
+ TODO: check
+CVE-2024-47876 (Sakai is a Collaboration and Learning Environment. Starting in
version ...)
+ TODO: check
+CVE-2024-47874 (Starlette is an Asynchronous Server Gateway Interface (ASGI)
framework ...)
+ TODO: check
+CVE-2024-47824 (matrix-react-sdk is react-based software development kit for
inserting ...)
+ TODO: check
+CVE-2024-47779 (Element is a Matrix web client built using the Matrix React
SDK .Eleme ...)
+ TODO: check
+CVE-2024-47771 (Element Desktop is a Matrix client for desktop platforms.
Element Desk ...)
+ TODO: check
+CVE-2024-47080 (matrix-js-sdk is the Matrix Client-Server SDK for JavaScript
and TypeS ...)
+ TODO: check
+CVE-2024-45276 (An unauthenticated remote attacker can get read access to
files in the ...)
+ TODO: check
+CVE-2024-45275 (The devices contain two hard coded user accounts with
hardcoded passwo ...)
+ TODO: check
+CVE-2024-45274 (An unauthenticated remote attacker can execute OS commands via
UDP on ...)
+ TODO: check
+CVE-2024-45273 (An unauthenticated local attacker can decrypt the devices
config file ...)
+ TODO: check
+CVE-2024-45272 (An unauthenticated remote attacker can perform a brute-force
attack on ...)
+ TODO: check
+CVE-2024-45271 (An unauthenticated local attacker can gain admin privileges by
deployi ...)
+ TODO: check
+CVE-2024-44337 (The package `github.com/gomarkdown/markdown` is a Go library
for parsi ...)
+ TODO: check
+CVE-2024-41344 (A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13
allows attac ...)
+ TODO: check
+CVE-2024-35584 (SQL injection vulnerability in Ajax.php, ForWindow.php,
ForExport.php, ...)
+ TODO: check
+CVE-2024-21286 (Vulnerability in the PeopleSoft Enterprise ELM Enterprise
Learning Man ...)
+ TODO: check
+CVE-2024-21285 (Vulnerability in the Oracle Banking Liquidity Management
product of Or ...)
+ TODO: check
+CVE-2024-21284 (Vulnerability in the Oracle Banking Liquidity Management
product of Or ...)
+ TODO: check
+CVE-2024-21283 (Vulnerability in the PeopleSoft Enterprise HCM Global Payroll
Core pro ...)
+ TODO: check
+CVE-2024-21282 (Vulnerability in the Oracle Financials product of Oracle
E-Business Su ...)
+ TODO: check
+CVE-2024-21281 (Vulnerability in the Oracle Banking Liquidity Management
product of Or ...)
+ TODO: check
+CVE-2024-21280 (Vulnerability in the Oracle Service Contracts product of
Oracle E-Busi ...)
+ TODO: check
+CVE-2024-21279 (Vulnerability in the Oracle Sourcing product of Oracle
E-Business Suit ...)
+ TODO: check
+CVE-2024-21278 (Vulnerability in the Oracle Contract Lifecycle Management for
Public S ...)
+ TODO: check
+CVE-2024-21277 (Vulnerability in the Oracle MES for Process Manufacturing
product of O ...)
+ TODO: check
+CVE-2024-21276 (Vulnerability in the Oracle Work in Process product of Oracle
E-Busine ...)
+ TODO: check
+CVE-2024-21275 (Vulnerability in the Oracle Quoting product of Oracle
E-Business Suite ...)
+ TODO: check
+CVE-2024-21274 (Vulnerability in the Oracle WebLogic Server product of Oracle
Fusion M ...)
+ TODO: check
+CVE-2024-21273 (Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualiza ...)
+ TODO: check
+CVE-2024-21272 (Vulnerability in the MySQL Connectors product of Oracle MySQL
(compone ...)
+ TODO: check
+CVE-2024-21271 (Vulnerability in the Oracle Field Service product of Oracle
E-Business ...)
+ TODO: check
+CVE-2024-21270 (Vulnerability in the Oracle Common Applications Calendar
product of Or ...)
+ TODO: check
+CVE-2024-21269 (Vulnerability in the Oracle Incentive Compensation product of
Oracle E ...)
+ TODO: check
+CVE-2024-21268 (Vulnerability in the Oracle Applications Manager product of
Oracle E-B ...)
+ TODO: check
+CVE-2024-21267 (Vulnerability in the Oracle Cost Management product of Oracle
E-Busine ...)
+ TODO: check
+CVE-2024-21266 (Vulnerability in the Oracle Advanced Pricing product of Oracle
E-Busin ...)
+ TODO: check
+CVE-2024-21265 (Vulnerability in the Oracle Site Hub product of Oracle
E-Business Suit ...)
+ TODO: check
+CVE-2024-21264 (Vulnerability in the PeopleSoft Enterprise CC Common
Application Objec ...)
+ TODO: check
+CVE-2024-21263 (Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualiza ...)
+ TODO: check
+CVE-2024-21262 (Vulnerability in the MySQL Connectors product of Oracle MySQL
(compone ...)
+ TODO: check
+CVE-2024-21261 (Vulnerability in Oracle Application Express (component:
General). Sup ...)
+ TODO: check
+CVE-2024-21260 (Vulnerability in the Oracle WebLogic Server product of Oracle
Fusion M ...)
+ TODO: check
+CVE-2024-21259 (Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualiza ...)
+ TODO: check
+CVE-2024-21258 (Vulnerability in the Oracle Installed Base product of Oracle
E-Busines ...)
+ TODO: check
+CVE-2024-21257 (Vulnerability in the Oracle Hyperion BI+ product of Oracle
Hyperion (c ...)
+ TODO: check
+CVE-2024-21255 (Vulnerability in the PeopleSoft Enterprise PeopleTools product
of Orac ...)
+ TODO: check
+CVE-2024-21254 (Vulnerability in the Oracle BI Publisher product of Oracle
Analytics ( ...)
+ TODO: check
+CVE-2024-21253 (Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualiza ...)
+ TODO: check
+CVE-2024-21252 (Vulnerability in the Oracle Product Hub product of Oracle
E-Business S ...)
+ TODO: check
+CVE-2024-21251 (Vulnerability in the Java VM component of Oracle Database
Server. Sup ...)
+ TODO: check
+CVE-2024-21250 (Vulnerability in the Oracle Process Manufacturing Product
Development ...)
+ TODO: check
+CVE-2024-21249 (Vulnerability in the PeopleSoft Enterprise FIN Expenses
product of Ora ...)
+ TODO: check
+CVE-2024-21248 (Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualiza ...)
+ TODO: check
+CVE-2024-21247 (Vulnerability in the MySQL Client product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21246 (Vulnerability in the Oracle Service Bus product of Oracle
Fusion Middl ...)
+ TODO: check
+CVE-2024-21244 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21243 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21242 (Vulnerability in the XML Database component of Oracle Database
Server. ...)
+ TODO: check
+CVE-2024-21241 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21239 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21238 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21237 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21236 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21235 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK,
Oracle Gr ...)
+ TODO: check
+CVE-2024-21234 (Vulnerability in the Oracle WebLogic Server product of Oracle
Fusion M ...)
+ TODO: check
+CVE-2024-21233 (Vulnerability in the Oracle Database Core component of Oracle
Database ...)
+ TODO: check
+CVE-2024-21232 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21231 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21230 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21219 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21218 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21217 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK,
Oracle Gr ...)
+ TODO: check
+CVE-2024-21216 (Vulnerability in the Oracle WebLogic Server product of Oracle
Fusion M ...)
+ TODO: check
+CVE-2024-21215 (Vulnerability in the Oracle WebLogic Server product of Oracle
Fusion M ...)
+ TODO: check
+CVE-2024-21214 (Vulnerability in the PeopleSoft Enterprise PeopleTools product
of Orac ...)
+ TODO: check
+CVE-2024-21213 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21212 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21211 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK,
Oracle Gr ...)
+ TODO: check
+CVE-2024-21210 (Vulnerability in Oracle Java SE (component: Hotspot).
Supported versi ...)
+ TODO: check
+CVE-2024-21209 (Vulnerability in the MySQL Client product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21208 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK,
Oracle Gr ...)
+ TODO: check
+CVE-2024-21207 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21206 (Vulnerability in the Oracle Enterprise Command Center
Framework produc ...)
+ TODO: check
+CVE-2024-21205 (Vulnerability in the Oracle Service Bus product of Oracle
Fusion Middl ...)
+ TODO: check
+CVE-2024-21204 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21203 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21202 (Vulnerability in the PeopleSoft Enterprise PeopleTools product
of Orac ...)
+ TODO: check
+CVE-2024-21201 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21200 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21199 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21198 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21197 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21196 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21195 (Vulnerability in the Oracle BI Publisher product of Oracle
Analytics ( ...)
+ TODO: check
+CVE-2024-21194 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21193 (Vulnerability in the MySQL Server product of Oracle MySQL
(component: ...)
+ TODO: check
+CVE-2024-21192 (Vulnerability in the Oracle Enterprise Manager for Fusion
Middleware p ...)
+ TODO: check
+CVE-2024-21191 (Vulnerability in the Oracle Enterprise Manager Fusion
Middleware Contr ...)
+ TODO: check
+CVE-2024-21190 (Vulnerability in the Oracle Global Lifecycle Management FMW
Installer ...)
+ TODO: check
+CVE-2024-21172 (Vulnerability in the Oracle Hospitality OPERA 5 product of
Oracle Hosp ...)
+ TODO: check
+CVE-2023-31493 (RCE (Remote Code Execution) exists in ZoneMinder through
1.36.33 as an ...)
+ TODO: check
+CVE-2024-47674 (In the Linux kernel, the following vulnerability has been
resolved: m ...)
- linux 6.10.11-1
[bookworm] - linux 6.1.112-1
NOTE:
https://git.kernel.org/linus/79a61cc3fc0466ad2b7b89618a6157785f0293b3 (6.11)
@@ -18,7 +292,7 @@ CVE-2024-9969 (NewType WebEIP v3.0 does not properly
validate user input, allowi
NOT-FOR-US: NewType
CVE-2024-9968 (WebEIP v3.0 from NewTypedoes not properly validate user
input, allow ...)
NOT-FOR-US: NewType
-CVE-2024-9953 (A Potential DOS Vulnerability exists in CERT VINCE software
prior to v ...)
+CVE-2024-9953 (A potential denial-of-service (DoS) vulnerability exists in
CERT VINCE ...)
NOT-FOR-US: CERT VINCE software
CVE-2024-9952 (A vulnerability was found in SourceCodester Online Eyewear Shop
1.0 an ...)
NOT-FOR-US: SourceCodester Online Eyewear ShopSourceCodester Online
Eyewear Shop
@@ -97982,7 +98256,7 @@ CVE-2023-4624 (Server-Side Request Forgery (SSRF) in
GitHub repository bookstack
NOT-FOR-US: bookstack
CVE-2023-4600 (The AffiliateWP for WordPress is vulnerable to unauthorized
modificati ...)
NOT-FOR-US: AffiliateWP for WordPress
-CVE-2023-4571 (In Splunk IT Service Intelligence (ITSI) versions below below
4.13.3, ...)
+CVE-2023-4571 (In Splunk IT Service Intelligence (ITSI) versions below 4.13.3
or 4.15 ...)
NOT-FOR-US: Splunk
CVE-2023-4209 (The POEditor WordPress plugin before 0.9.8 does not have CSRF
checks i ...)
NOT-FOR-US: WordPress plugin
@@ -102365,7 +102639,7 @@ CVE-2023-4010 (A flaw was found in the USB Host
Controller Driver framework in t
- linux <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2227726
NOTE: https://github.com/wanrenmi/a-usb-kernel-bug
-CVE-2023-3997 (Splunk SOAR versions lower than 6.1.0 are indirectly affected
by a pot ...)
+CVE-2023-3997 (Splunk SOAR versions 6.0.2 and earlier are indirectly affected
by a po ...)
NOT-FOR-US: Splunk SOAR
CVE-2023-3983 (An authenticated SQL injection vulnerability exists in
Advantech iView ...)
NOT-FOR-US: Advantech iView
@@ -139243,7 +139517,7 @@ CVE-2023-22646
RESERVED
CVE-2023-22645 (An Improper Privilege Management vulnerability in SUSE
kubewarden allo ...)
NOT-FOR-US: kubewarden
-CVE-2023-22644 (An Innsertion of Sensitive Information into Log File
vulnerability in ...)
+CVE-2023-22644 (A user can reverse engineer the JWT token (JSON Web Token)
used in aut ...)
NOT-FOR-US: SUSE Manager Server Module
CVE-2023-22643 (An Improper Neutralization of Special Elements used in an OS
Command ( ...)
NOT-FOR-US: SAP
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/932dda8c17db17f81a5abf794df76e29fd77c98b
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/932dda8c17db17f81a5abf794df76e29fd77c98b
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits