Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
e0b2fc90 by Salvatore Bonaccorso at 2025-03-04T22:21:43+01:00
Process some NFUs

- - - - -
c72b30df by Salvatore Bonaccorso at 2025-03-04T22:21:43+01:00
Add CVE-2024-41147/miniaudio

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -41,9 +41,9 @@ CVE-2025-22225 (VMware ESXi contains an arbitrary 
writevulnerability.A malicious
 CVE-2025-22224 (VMware ESXi, and Workstationcontain a TOCTOU (Time-of-Check 
Time-of-Us ...)
        NOT-FOR-US: VMware
 CVE-2025-1969 (Improper request input validation in Temporary Elevated Access 
Managem ...)
-       TODO: check
+       NOT-FOR-US: Temporary Elevated Access Management (TEAM) for AWS IAM 
Identity Center
 CVE-2025-1953 (A vulnerability has been found in vLLM AIBrix 0.2.0 and 
classified as  ...)
-       TODO: check
+       NOT-FOR-US: vLLM AIBrix
 CVE-2025-1952 (A vulnerability, which was classified as critical, was found in 
PHPGur ...)
        NOT-FOR-US: PHPGurukul
 CVE-2025-1949 (A vulnerability, which was classified as problematic, has been 
found i ...)
@@ -88,15 +88,16 @@ CVE-2024-50705 (Unauthenticated reflected cross-site 
scripting (XSS) vulnerabili
 CVE-2024-50704 (Unauthenticated remote code execution vulnerability in 
Uniguest Triple ...)
        NOT-FOR-US: Uniguest Tripleplay
 CVE-2024-41147 (An out-of-bounds write vulnerability exists in the 
ma_dr_flac__decode_ ...)
-       TODO: check
+       - miniaudio <unfixed>
+       NOTE: 
https://talosintelligence.com/vulnerability_reports/TALOS-2024-2063
 CVE-2024-13724 (The Wallet System for WooCommerce \u2013 Wallet, Wallet 
Cashback, Refu ...)
        NOT-FOR-US: WordPress plugin
 CVE-2024-13682 (The Wallet System for WooCommerce \u2013 Wallet, Wallet 
Cashback, Refu ...)
        NOT-FOR-US: WordPress plugin
 CVE-2024-11957 (Improper verification of the digital signature in 
ksojscore.dll in Kin ...)
-       TODO: check
+       NOT-FOR-US: Kingsoft WPS Office
 CVE-2024-10930 (An Uncontrolled Search Path Element vulnerability exists which 
could a ...)
-       TODO: check
+       NOT-FOR-US: Carrier
 CVE-2025-1943 (Memory safety bugs present in Firefox 135 and Thunderbird 135. 
Some of ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2025-14/#CVE-2025-1943
@@ -305,7 +306,7 @@ CVE-2024-58044 (Permission verification bypass 
vulnerability in the notification
 CVE-2024-58043 (Permission bypass vulnerability in the window module Impact: 
Successfu ...)
        NOT-FOR-US: Huawei
 CVE-2024-55064 (Multiple cross-site scripting (XSS) vulnerabilities in 
EasyVirt DC Net ...)
-       TODO: check
+       NOT-FOR-US: EasyVirt DC NetScope
 CVE-2024-48248 (NAKIVO Backup & Replication before 11.0.0.88174 allows 
absolute path t ...)
        NOT-FOR-US: NAKIVO Backup & Replication
 CVE-2024-47262 (Dzmitry Lukyanenka, member of the AXIS OS Bug Bounty Program, 
has foun ...)
@@ -317,7 +318,7 @@ CVE-2024-47259 (Girishunawane, member of the AXIS OS Bug 
Bounty Program, has fou
 CVE-2024-13686 (The VW Storefront theme for WordPress is vulnerable to 
unauthorized mo ...)
        NOT-FOR-US: WordPress plugin
 CVE-2024-13685 (The Admin and Site Enhancements (ASE) WordPress plugin before 
7.6.10 r ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-27501 (OpenZiti is a free and open source project focused on bringing 
zero tr ...)
        NOT-FOR-US: OpenZiti
 CVE-2025-27500 (OpenZiti is a free and open source project focused on bringing 
zero tr ...)
@@ -857,43 +858,43 @@ CVE-2024-51944 (There is a stored Cross-site Scripting 
vulnerability in ArcGIS S
 CVE-2024-51942 (There is a stored Cross-site Scripting vulnerability in ArcGIS 
Server  ...)
        NOT-FOR-US: Esri
 CVE-2024-51091 (Cross Site Scripting vulnerability in seajs v.2.2.3 allows a 
remote at ...)
-       TODO: check
+       NOT-FOR-US: seajs
 CVE-2024-49836 (Memory corruption may occur during the synchronization of the 
camera`s ...)
        NOT-FOR-US: Qualcomm
 CVE-2024-47092 (Insecure deserialization and improper certificate validation 
in Checkm ...)
        TODO: check
 CVE-2024-45580 (Memory corruption while handling multuple IOCTL calls from 
userspace f ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2024-43169 (IBM Engineering Requirements Management DOORS Next 7.0.2, 
7.0.3, and 7 ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2024-43062 (Memory corruption caused by missing locks and checks on the 
DMA fence  ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2024-43061 (Memory corruption during voice activation, when sound model 
parameters ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2024-43060 (Memory corruption during voice activation, when sound model 
parameters ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2024-43059 (Memory corruption while invoking IOCTL calls from the 
use-space for HG ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2024-43057 (Memory corruption while processing command in Glink linux.)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2024-43056 (Transient DOS during hypervisor virtual I/O operation in a 
virtual mac ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2024-43055 (Memory corruption while processing camera use case IOCTL call.)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2024-43051 (Information disclosure while deriving keys for a session for 
any Widev ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2024-41771 (IBM Engineering Requirements Management DOORS Next 7.0.2, 
7.0.3, and 7 ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2024-41770 (IBM Engineering Requirements Management DOORS Next 7.0.2, 
7.0.3, and 7 ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2024-38426 (While processing the authentication message in UE, improper 
authentica ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2024-30154 (HCL SX is vulnerable to cross-site request forgery 
vulnerability which ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2024-10904 (There is a stored Cross-site Scripting vulnerability in ArcGIS 
Server  ...)
        NOT-FOR-US: Esri
 CVE-2023-49031 (Directory Traversal (Local File Inclusion) vulnerability in 
Tikit (now ...)
-       TODO: check
+       NOT-FOR-US: Tikit (now Advanced) eMarketing platform
 CVE-2024-24778 (Improper privilege management in a REST interface allowed 
registered u ...)
        NOT-FOR-US: Apache StreamPipes
 CVE-2025-27590 (In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID 
migration ...)
@@ -413732,7 +413733,7 @@ CVE-2020-3123 (A vulnerability in the 
Data-Loss-Prevention (DLP) module in Clam
        [jessie] - clamav <not-affected> (Vulnerable code introduced in 0.102.x)
        NOTE: 
https://blog.clamav.net/2020/02/clamav-01022-security-patch-released.html
 CVE-2020-3122 (A vulnerability in the web-based management interface of Cisco 
AsyncOS ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2020-3121 (A vulnerability in the web-based management interface of Cisco 
Small B ...)
        NOT-FOR-US: Cisco
 CVE-2020-3120 (A vulnerability in the Cisco Discovery Protocol implementation 
for Cis ...)
@@ -473742,7 +473743,7 @@ CVE-2019-1817 (A vulnerability in the web proxy 
functionality of Cisco AsyncOS S
 CVE-2019-1816 (A vulnerability in the log subscription subsystem of the Cisco 
Web Sec ...)
        NOT-FOR-US: Cisco
 CVE-2019-1815 (A security vulnerability was discovered in the local status 
page funct ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2019-1814 (A vulnerability in the interactions between the DHCP and TFTP 
features ...)
        NOT-FOR-US: Cisco
 CVE-2019-1813 (A vulnerability in the Image Signature Verification feature of 
Cisco N ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/6846e00f49232fd83c7c1de89eb01c8c044823c0...c72b30dfcb87082039bb226abca6477d72a2f28b

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/6846e00f49232fd83c7c1de89eb01c8c044823c0...c72b30dfcb87082039bb226abca6477d72a2f28b
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to