Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
e0b2fc90 by Salvatore Bonaccorso at 2025-03-04T22:21:43+01:00
Process some NFUs
- - - - -
c72b30df by Salvatore Bonaccorso at 2025-03-04T22:21:43+01:00
Add CVE-2024-41147/miniaudio
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -41,9 +41,9 @@ CVE-2025-22225 (VMware ESXi contains an arbitrary
writevulnerability.A malicious
CVE-2025-22224 (VMware ESXi, and Workstationcontain a TOCTOU (Time-of-Check
Time-of-Us ...)
NOT-FOR-US: VMware
CVE-2025-1969 (Improper request input validation in Temporary Elevated Access
Managem ...)
- TODO: check
+ NOT-FOR-US: Temporary Elevated Access Management (TEAM) for AWS IAM
Identity Center
CVE-2025-1953 (A vulnerability has been found in vLLM AIBrix 0.2.0 and
classified as ...)
- TODO: check
+ NOT-FOR-US: vLLM AIBrix
CVE-2025-1952 (A vulnerability, which was classified as critical, was found in
PHPGur ...)
NOT-FOR-US: PHPGurukul
CVE-2025-1949 (A vulnerability, which was classified as problematic, has been
found i ...)
@@ -88,15 +88,16 @@ CVE-2024-50705 (Unauthenticated reflected cross-site
scripting (XSS) vulnerabili
CVE-2024-50704 (Unauthenticated remote code execution vulnerability in
Uniguest Triple ...)
NOT-FOR-US: Uniguest Tripleplay
CVE-2024-41147 (An out-of-bounds write vulnerability exists in the
ma_dr_flac__decode_ ...)
- TODO: check
+ - miniaudio <unfixed>
+ NOTE:
https://talosintelligence.com/vulnerability_reports/TALOS-2024-2063
CVE-2024-13724 (The Wallet System for WooCommerce \u2013 Wallet, Wallet
Cashback, Refu ...)
NOT-FOR-US: WordPress plugin
CVE-2024-13682 (The Wallet System for WooCommerce \u2013 Wallet, Wallet
Cashback, Refu ...)
NOT-FOR-US: WordPress plugin
CVE-2024-11957 (Improper verification of the digital signature in
ksojscore.dll in Kin ...)
- TODO: check
+ NOT-FOR-US: Kingsoft WPS Office
CVE-2024-10930 (An Uncontrolled Search Path Element vulnerability exists which
could a ...)
- TODO: check
+ NOT-FOR-US: Carrier
CVE-2025-1943 (Memory safety bugs present in Firefox 135 and Thunderbird 135.
Some of ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2025-14/#CVE-2025-1943
@@ -305,7 +306,7 @@ CVE-2024-58044 (Permission verification bypass
vulnerability in the notification
CVE-2024-58043 (Permission bypass vulnerability in the window module Impact:
Successfu ...)
NOT-FOR-US: Huawei
CVE-2024-55064 (Multiple cross-site scripting (XSS) vulnerabilities in
EasyVirt DC Net ...)
- TODO: check
+ NOT-FOR-US: EasyVirt DC NetScope
CVE-2024-48248 (NAKIVO Backup & Replication before 11.0.0.88174 allows
absolute path t ...)
NOT-FOR-US: NAKIVO Backup & Replication
CVE-2024-47262 (Dzmitry Lukyanenka, member of the AXIS OS Bug Bounty Program,
has foun ...)
@@ -317,7 +318,7 @@ CVE-2024-47259 (Girishunawane, member of the AXIS OS Bug
Bounty Program, has fou
CVE-2024-13686 (The VW Storefront theme for WordPress is vulnerable to
unauthorized mo ...)
NOT-FOR-US: WordPress plugin
CVE-2024-13685 (The Admin and Site Enhancements (ASE) WordPress plugin before
7.6.10 r ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-27501 (OpenZiti is a free and open source project focused on bringing
zero tr ...)
NOT-FOR-US: OpenZiti
CVE-2025-27500 (OpenZiti is a free and open source project focused on bringing
zero tr ...)
@@ -857,43 +858,43 @@ CVE-2024-51944 (There is a stored Cross-site Scripting
vulnerability in ArcGIS S
CVE-2024-51942 (There is a stored Cross-site Scripting vulnerability in ArcGIS
Server ...)
NOT-FOR-US: Esri
CVE-2024-51091 (Cross Site Scripting vulnerability in seajs v.2.2.3 allows a
remote at ...)
- TODO: check
+ NOT-FOR-US: seajs
CVE-2024-49836 (Memory corruption may occur during the synchronization of the
camera`s ...)
NOT-FOR-US: Qualcomm
CVE-2024-47092 (Insecure deserialization and improper certificate validation
in Checkm ...)
TODO: check
CVE-2024-45580 (Memory corruption while handling multuple IOCTL calls from
userspace f ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2024-43169 (IBM Engineering Requirements Management DOORS Next 7.0.2,
7.0.3, and 7 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2024-43062 (Memory corruption caused by missing locks and checks on the
DMA fence ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2024-43061 (Memory corruption during voice activation, when sound model
parameters ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2024-43060 (Memory corruption during voice activation, when sound model
parameters ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2024-43059 (Memory corruption while invoking IOCTL calls from the
use-space for HG ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2024-43057 (Memory corruption while processing command in Glink linux.)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2024-43056 (Transient DOS during hypervisor virtual I/O operation in a
virtual mac ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2024-43055 (Memory corruption while processing camera use case IOCTL call.)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2024-43051 (Information disclosure while deriving keys for a session for
any Widev ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2024-41771 (IBM Engineering Requirements Management DOORS Next 7.0.2,
7.0.3, and 7 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2024-41770 (IBM Engineering Requirements Management DOORS Next 7.0.2,
7.0.3, and 7 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2024-38426 (While processing the authentication message in UE, improper
authentica ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2024-30154 (HCL SX is vulnerable to cross-site request forgery
vulnerability which ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2024-10904 (There is a stored Cross-site Scripting vulnerability in ArcGIS
Server ...)
NOT-FOR-US: Esri
CVE-2023-49031 (Directory Traversal (Local File Inclusion) vulnerability in
Tikit (now ...)
- TODO: check
+ NOT-FOR-US: Tikit (now Advanced) eMarketing platform
CVE-2024-24778 (Improper privilege management in a REST interface allowed
registered u ...)
NOT-FOR-US: Apache StreamPipes
CVE-2025-27590 (In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID
migration ...)
@@ -413732,7 +413733,7 @@ CVE-2020-3123 (A vulnerability in the
Data-Loss-Prevention (DLP) module in Clam
[jessie] - clamav <not-affected> (Vulnerable code introduced in 0.102.x)
NOTE:
https://blog.clamav.net/2020/02/clamav-01022-security-patch-released.html
CVE-2020-3122 (A vulnerability in the web-based management interface of Cisco
AsyncOS ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2020-3121 (A vulnerability in the web-based management interface of Cisco
Small B ...)
NOT-FOR-US: Cisco
CVE-2020-3120 (A vulnerability in the Cisco Discovery Protocol implementation
for Cis ...)
@@ -473742,7 +473743,7 @@ CVE-2019-1817 (A vulnerability in the web proxy
functionality of Cisco AsyncOS S
CVE-2019-1816 (A vulnerability in the log subscription subsystem of the Cisco
Web Sec ...)
NOT-FOR-US: Cisco
CVE-2019-1815 (A security vulnerability was discovered in the local status
page funct ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2019-1814 (A vulnerability in the interactions between the DHCP and TFTP
features ...)
NOT-FOR-US: Cisco
CVE-2019-1813 (A vulnerability in the Image Signature Verification feature of
Cisco N ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/6846e00f49232fd83c7c1de89eb01c8c044823c0...c72b30dfcb87082039bb226abca6477d72a2f28b
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/6846e00f49232fd83c7c1de89eb01c8c044823c0...c72b30dfcb87082039bb226abca6477d72a2f28b
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits