Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
926988ed by security tracker role at 2025-04-16T08:12:07+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,10 +1,362 @@
+CVE-2025-3698 (Interface exposure vulnerability in the mobile application 
(com.transs ...)
+       TODO: check
+CVE-2025-3676 (A vulnerability classified as critical has been found in 
xxyopen Novel ...)
+       TODO: check
+CVE-2025-3675 (A vulnerability was found in TOTOLINK A3700R 
9.1.2u.5822_B20200513. It ...)
+       TODO: check
+CVE-2025-3674 (A vulnerability was found in TOTOLINK A3700R 
9.1.2u.5822_B20200513. It ...)
+       TODO: check
+CVE-2025-3668 (A vulnerability was found in TOTOLINK A3700R 
9.1.2u.5822_B20200513. It ...)
+       TODO: check
+CVE-2025-3667 (A vulnerability was found in TOTOLINK A3700R 
9.1.2u.5822_B20200513. It ...)
+       TODO: check
+CVE-2025-3666 (A vulnerability was found in TOTOLINK A3700R 
9.1.2u.5822_B20200513 and ...)
+       TODO: check
+CVE-2025-3665 (A vulnerability has been found in TOTOLINK A3700R 
9.1.2u.5822_B2020051 ...)
+       TODO: check
+CVE-2025-3664 (A vulnerability, which was classified as critical, was found in 
TOTOLI ...)
+       TODO: check
+CVE-2025-3663 (A vulnerability, which was classified as critical, has been 
found in T ...)
+       TODO: check
+CVE-2025-3495 (Delta Electronics COMMGR v1 and v2uses insufficiently 
randomized value ...)
+       TODO: check
+CVE-2025-3247 (The Contact Form 7 plugin for WordPress is vulnerable to Order 
Replay  ...)
+       TODO: check
+CVE-2025-3077 (The Betheme theme for WordPress is vulnerable to Stored 
Cross-Site Scr ...)
+       TODO: check
+CVE-2025-32923 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-32784 (conda-forge-webservices is the web app deployed to run 
conda-forge adm ...)
+       TODO: check
+CVE-2025-32782 (Ash Authentication provides authentication for the Ash 
framework. The  ...)
+       TODO: check
+CVE-2025-32778 (Web-Check is an all-in-one OSINT tool for analyzing any 
website. A com ...)
+       TODO: check
+CVE-2025-32435 (Hydra is a Continuous Integration service for Nix based 
projects. Eval ...)
+       TODO: check
+CVE-2025-32388 (SvelteKit is a framework for rapidly developing robust, 
performant web ...)
+       TODO: check
+CVE-2025-32385 (EspoCRM is an Open Source Customer Relationship Management 
software. P ...)
+       TODO: check
+CVE-2025-32021 (Weblate is a web based localization tool. Prior to version 
5.11, when  ...)
+       TODO: check
+CVE-2025-31950 (An unauthenticated attacker can obtain EV charger energy 
consumption i ...)
+       TODO: check
+CVE-2025-31949 (An authenticated attacker can obtain any plant name by knowing 
the pla ...)
+       TODO: check
+CVE-2025-31945 (An unauthenticated attacker can obtain other users' charger 
informatio ...)
+       TODO: check
+CVE-2025-31941 (An unauthenticated attacker can obtain a list of smart devices 
by know ...)
+       TODO: check
+CVE-2025-31933 (An unauthenticated attacker can check the existence of 
usernames in th ...)
+       TODO: check
+CVE-2025-31654 (An attacker can get information about the groups of the smart 
home dev ...)
+       TODO: check
+CVE-2025-31499 (Jellyfin is an open source self hosted media server. Versions 
before 1 ...)
+       TODO: check
+CVE-2025-31360 (Unauthenticated attackers can trigger device actions 
associated with s ...)
+       TODO: check
+CVE-2025-31357 (An unauthenticated attacker can obtain a user's plant list by 
knowing  ...)
+       TODO: check
+CVE-2025-31147 (Unauthenticated attackers can query information about total 
energy con ...)
+       TODO: check
+CVE-2025-30984 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-30982 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-30970 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-30967 (Cross-Site Request Forgery (CSRF) vulnerability in NotFound 
WPJobBoard ...)
+       TODO: check
+CVE-2025-30966 (Path Traversal vulnerability in NotFound WPJobBoard allows 
Path Traver ...)
+       TODO: check
+CVE-2025-30740 (Vulnerability in the JD Edwards EnterpriseOne Tools product of 
Oracle  ...)
+       TODO: check
+CVE-2025-30737 (Vulnerability in the Oracle Smart View for Office product of 
Oracle Hy ...)
+       TODO: check
+CVE-2025-30736 (Vulnerability in the Java VM component of Oracle Database 
Server.  Sup ...)
+       TODO: check
+CVE-2025-30735 (Vulnerability in the PeopleSoft Enterprise CC Common 
Application Objec ...)
+       TODO: check
+CVE-2025-30733 (Vulnerability in the RDBMS Listener component of Oracle 
Database Serve ...)
+       TODO: check
+CVE-2025-30732 (Vulnerability in the Oracle Application Object Library product 
of Orac ...)
+       TODO: check
+CVE-2025-30731 (Vulnerability in the Oracle Applications Technology Stack 
product of O ...)
+       TODO: check
+CVE-2025-30730 (Vulnerability in the Oracle Application Object Library product 
of Orac ...)
+       TODO: check
+CVE-2025-30729 (Vulnerability in the Oracle Communications Order and Service 
Managemen ...)
+       TODO: check
+CVE-2025-30728 (Vulnerability in the Oracle Configurator product of Oracle 
E-Business  ...)
+       TODO: check
+CVE-2025-30727 (Vulnerability in the Oracle Scripting product of Oracle 
E-Business Sui ...)
+       TODO: check
+CVE-2025-30726 (Vulnerability in the Oracle Application Object Library product 
of Orac ...)
+       TODO: check
+CVE-2025-30725 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
+       TODO: check
+CVE-2025-30724 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
+       TODO: check
+CVE-2025-30723 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
+       TODO: check
+CVE-2025-30722 (Vulnerability in the MySQL Client product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-30721 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-30720 (Vulnerability in the Oracle Configurator product of Oracle 
E-Business  ...)
+       TODO: check
+CVE-2025-30719 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
+       TODO: check
+CVE-2025-30718 (Vulnerability in the Oracle Applications Framework product of 
Oracle E ...)
+       TODO: check
+CVE-2025-30717 (Vulnerability in the Oracle Teleservice product of Oracle 
E-Business S ...)
+       TODO: check
+CVE-2025-30716 (Vulnerability in the Oracle Common Applications product of 
Oracle E-Bu ...)
+       TODO: check
+CVE-2025-30715 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-30714 (Vulnerability in the MySQL Connectors product of Oracle MySQL 
(compone ...)
+       TODO: check
+CVE-2025-30713 (Vulnerability in the PeopleSoft Enterprise HCM Talent 
Acquisition Mana ...)
+       TODO: check
+CVE-2025-30712 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
+       TODO: check
+CVE-2025-30711 (Vulnerability in the Oracle Applications Framework product of 
Oracle E ...)
+       TODO: check
+CVE-2025-30710 (Vulnerability in the MySQL Cluster product of Oracle MySQL 
(component: ...)
+       TODO: check
+CVE-2025-30709 (Vulnerability in the JD Edwards EnterpriseOne Tools product of 
Oracle  ...)
+       TODO: check
+CVE-2025-30708 (Vulnerability in the Oracle User Management product of Oracle 
E-Busine ...)
+       TODO: check
+CVE-2025-30707 (Vulnerability in the Oracle iStore product of Oracle 
E-Business Suite  ...)
+       TODO: check
+CVE-2025-30706 (Vulnerability in the MySQL Connectors product of Oracle MySQL 
(compone ...)
+       TODO: check
+CVE-2025-30705 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-30704 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-30703 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-30702 (Vulnerability in the Fleet Patching and amp; Provisioning 
component of ...)
+       TODO: check
+CVE-2025-30701 (Vulnerability in the RAS Security component of Oracle Database 
Server. ...)
+       TODO: check
+CVE-2025-30700 (Vulnerability in the Oracle Solaris product of Oracle Systems 
(compone ...)
+       TODO: check
+CVE-2025-30699 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-30698 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, 
Oracle Gr ...)
+       TODO: check
+CVE-2025-30697 (Vulnerability in the PeopleSoft Enterprise PeopleTools product 
of Orac ...)
+       TODO: check
+CVE-2025-30696 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-30695 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-30694 (Vulnerability in the XML Database component of Oracle Database 
Server. ...)
+       TODO: check
+CVE-2025-30693 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-30692 (Vulnerability in the Oracle iSupplier Portal product of Oracle 
E-Busin ...)
+       TODO: check
+CVE-2025-30691 (Vulnerability in Oracle Java SE (component: Compiler).  
Supported vers ...)
+       TODO: check
+CVE-2025-30690 (Vulnerability in the Oracle Solaris product of Oracle Systems 
(compone ...)
+       TODO: check
+CVE-2025-30689 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-30688 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-30687 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-30686 (Vulnerability in the Oracle Hospitality Simphony product of 
Oracle Foo ...)
+       TODO: check
+CVE-2025-30685 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-30684 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-30683 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-30682 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-30681 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-30514 (Unauthenticated attackers can obtain restricted information 
about a us ...)
+       TODO: check
+CVE-2025-30512 (Unauthenticated attackers can send configuration settings to 
device an ...)
+       TODO: check
+CVE-2025-30511 (An authenticated attacker can achieve stored XSS by exploiting 
imprope ...)
+       TODO: check
+CVE-2025-30510 (An attacker can upload an arbitrary file instead of a plant 
image.)
+       TODO: check
+CVE-2025-30257 (Unauthenticated attackers can retrieve serial number of smart 
meters a ...)
+       TODO: check
+CVE-2025-30254 (An unauthenticated attacker can obtain a serial number of a 
smart mete ...)
+       TODO: check
+CVE-2025-30100 (Dell Alienware Command Center 6.x, versions prior to 6.7.37.0 
contain  ...)
+       TODO: check
+CVE-2025-2497 (A maliciously crafted DWG file, when parsed through Autodesk 
Revit, ca ...)
+       TODO: check
+CVE-2025-2314 (The User Profile Builder \u2013 Beautiful User Registration 
Forms, Use ...)
+       TODO: check
+CVE-2025-29471 (Cross Site Scripting vulnerability in Nagios Log Server 
v.2024R1.3.1 a ...)
+       TODO: check
+CVE-2025-27939 (An attacker can change registered email addresses of other 
users and t ...)
+       TODO: check
+CVE-2025-27938 (Unauthenticated attackers can obtain restricted information 
about a us ...)
+       TODO: check
+CVE-2025-27929 (Unauthenticated attackers can retrieve full list of users 
associated w ...)
+       TODO: check
+CVE-2025-27927 (An unauthenticated attackers can obtain a list of smart 
devices by kno ...)
+       TODO: check
+CVE-2025-27892 (Shopware prior to version 6.5.8.13 is affected by a SQL 
injection vuln ...)
+       TODO: check
+CVE-2025-27719 (Unauthenticated attackers can query an API endpoint and get 
device det ...)
+       TODO: check
+CVE-2025-27575 (An unauthenticated attacker can obtain EV charger version and 
firmware ...)
+       TODO: check
+CVE-2025-27571 (Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x 
<= 9.11 ...)
+       TODO: check
+CVE-2025-27568 (An unauthenticated attacker can get users' emails by knowing 
usernames ...)
+       TODO: check
+CVE-2025-27565 (An unauthenticated attacker can delete any user's "rooms" by 
knowing t ...)
+       TODO: check
+CVE-2025-27561 (Unauthenticated attackers can rename "rooms" of arbitrary 
users.)
+       TODO: check
+CVE-2025-27538 (Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to 
enforce ...)
+       TODO: check
+CVE-2025-27011 (Improper Control of Filename for Include/Require Statement in 
PHP Prog ...)
+       TODO: check
+CVE-2025-27008 (Missing Authorization vulnerability in NotFound Unlimited 
Timeline all ...)
+       TODO: check
+CVE-2025-26998 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-26996 (Improper Control of Generation of Code ('Code Injection') 
vulnerabilit ...)
+       TODO: check
+CVE-2025-26953 (Missing Authorization vulnerability in NotFound JetMenu allows 
Accessi ...)
+       TODO: check
+CVE-2025-26951 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-26950 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-26934 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-26930 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-26927 (Unrestricted Upload of File with Dangerous Type vulnerability 
in EPC A ...)
+       TODO: check
+CVE-2025-26919 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-26908 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
+       TODO: check
+CVE-2025-26906 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-26903 (Cross-Site Request Forgery (CSRF) vulnerability in RealMag777 
InPost G ...)
+       TODO: check
+CVE-2025-26880 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-26870 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-26857 (Unauthenticated attackers can rename arbitrary devices of 
arbitrary us ...)
+       TODO: check
+CVE-2025-26749 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-26748 (Cross-Site Request Forgery (CSRF) vulnerability in LOOS,Inc. 
Arkhe all ...)
+       TODO: check
+CVE-2025-26746 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-26740 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-26730 (Exposure of Sensitive System Information to an Unauthorized 
Control Sp ...)
+       TODO: check
+CVE-2025-25458 (Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer 
Overflow in Adv ...)
+       TODO: check
+CVE-2025-25453 (Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer 
Overflow in Adv ...)
+       TODO: check
+CVE-2025-25276 (An unauthenticated attacker can hijack other users' devices 
and potent ...)
+       TODO: check
+CVE-2025-24850 (An attacker can export other users' plant information.)
+       TODO: check
+CVE-2025-24839 (Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x 
<= 9.11 ...)
+       TODO: check
+CVE-2025-24487 (An unauthenticated attacker can infer the existence of 
usernames in th ...)
+       TODO: check
+CVE-2025-24315 (Unauthenticated attackers can add devices of other users to 
their scen ...)
+       TODO: check
+CVE-2025-24297 (Due to lack of server-side input validation, attackers can 
inject mali ...)
+       TODO: check
+CVE-2025-22911 (RE11S v1.11 was discovered to contain a stack overflow via the 
rootAPm ...)
+       TODO: check
+CVE-2025-22269 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-22268 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-22263 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2025-21588 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-21587 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, 
Oracle Gr ...)
+       TODO: check
+CVE-2025-21586 (Vulnerability in the JD Edwards EnterpriseOne Tools product of 
Oracle  ...)
+       TODO: check
+CVE-2025-21585 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-21584 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-21583 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-21582 (Vulnerability in the Oracle CRM Technical Foundation product 
of Oracle ...)
+       TODO: check
+CVE-2025-21581 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-21580 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-21579 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-21578 (Vulnerability in Oracle Secure Backup (component: General).  
Supported ...)
+       TODO: check
+CVE-2025-21577 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-21576 (Vulnerability in the Oracle Commerce Platform product of 
Oracle Commer ...)
+       TODO: check
+CVE-2025-21575 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-21574 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
+       TODO: check
+CVE-2025-21573 (Vulnerability in the Oracle Financial Services Revenue 
Management and  ...)
+       TODO: check
+CVE-2025-1656 (A maliciously crafted PDF file, when linked or imported into 
Autodesk  ...)
+       TODO: check
+CVE-2025-1277 (A maliciously crafted PDF file, when parsed through Autodesk 
applicati ...)
+       TODO: check
+CVE-2025-1276 (A maliciously crafted DWG file, when parsed through certain 
Autodesk a ...)
+       TODO: check
+CVE-2025-1275 (A maliciously crafted JPG file, when linked or imported into 
certain A ...)
+       TODO: check
+CVE-2025-1274 (A maliciously crafted RCS file, when parsed through Autodesk 
Revit, ca ...)
+       TODO: check
+CVE-2025-1273 (A maliciously crafted PDF file, when linked or imported into 
Autodesk  ...)
+       TODO: check
+CVE-2025-0101 (A low privileged user can set the date of the devices to the 
19th of J ...)
+       TODO: check
+CVE-2024-49200 (An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in 
Insyde I ...)
+       TODO: check
+CVE-2024-44843 (An issue in the web socket handshake process of SteVe v3.7.1 
allows at ...)
+       TODO: check
+CVE-2024-13452 (The Contact Form by Supsystic plugin for WordPress is 
vulnerable to Cr ...)
+       TODO: check
+CVE-2024-10680 (The Form Maker by 10Web  WordPress plugin before 1.15.32 does 
not sani ...)
+       TODO: check
 CVE-2025-3620
        - chromium 135.0.7049.95-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2025-3619
        - chromium 135.0.7049.95-1
        [bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2025-22018 [atm: Fix NULL pointer dereference]
+CVE-2025-22018 (In the Linux kernel, the following vulnerability has been 
resolved:  a ...)
        - linux 6.12.22-1
        [bookworm] - linux 6.1.133-1
        NOTE: 
https://git.kernel.org/linus/bf2986fcf82a449441f9ee4335df19be19e83970 (6.15-rc1)
@@ -1436,7 +1788,7 @@ CVE-2023-33844 (IBM Security Verify Governance 10.0.2 is 
vulnerable to cross-sit
        NOT-FOR-US: IBM
 CVE-2017-20197 (A vulnerability was found in propanetank 
Roommate-Bill-Tracking up to  ...)
        NOT-FOR-US: Roommate-Bill-Tracking
-CVE-2025-30215
+CVE-2025-30215 (NATS-Server is a High-Performance server for NATS.io, the 
cloud and ed ...)
        - nats-server 2.10.27-1
        NOTE: https://advisories.nats.io/CVE/secnote-2025-01.txt
 CVE-2025-3442 (This vulnerability exists in TP-Link TapoH200 V1  IoT Smart Hub 
due to ...)
@@ -4011,7 +4363,7 @@ CVE-2024-36465 (A low privilege (regular) Zabbix user 
with API access can use SQ
        NOTE: https://support.zabbix.com/browse/ZBX-26257
 CVE-2024-13941 (A vulnerability was found in ouch-org ouch up to 0.3.1. It has 
been cl ...)
        NOT-FOR-US: ouch-org ouch
-CVE-2023-46988 (Directory Traversal vulnerability in ONLYOFFICE Document 
Server v.7.5. ...)
+CVE-2023-46988 (Path Traversal vulnerability in ONLYOFFICE Document Server 
before v8.0 ...)
        NOT-FOR-US: ONLYOFFICE
 CVE-2003-20001 (An issue was discovered on Mitel ICP VoIP 3100 devices. When a 
remote  ...)
        NOT-FOR-US: Mitel



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/926988ed318d1c5c0dd3349d45fb081712999634

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/926988ed318d1c5c0dd3349d45fb081712999634
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to