Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
29d11c66 by Salvatore Bonaccorso at 2025-11-07T21:26:54+01:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3,19 +3,19 @@ CVE-2025-9458 (A maliciously crafted PRT file, when parsed
through certain Autod
CVE-2025-7719 (Improper Limitation of a Pathname to a Restricted Directory
('Path Tra ...)
NOT-FOR-US: GE Vernova
CVE-2025-64432 (KubeVirt is a virtual machine management add-on for
Kubernetes. Versio ...)
- TODO: check
+ NOT-FOR-US: KubeVirt
CVE-2025-64431 (Zitadel is an open source identity management platform.
Versions 4.0.0 ...)
- TODO: check
+ NOT-FOR-US: Zitadel
CVE-2025-64430 (Parse Server is an open source backend that can be deployed to
any inf ...)
- TODO: check
+ NOT-FOR-US: Parse Server
CVE-2025-64347 (Apollo Router Core is a configurable Rust graph router written
to run ...)
- TODO: check
+ NOT-FOR-US: Apollo Router Core
CVE-2025-63785 (A DOM-based Cross-Site Scripting (XSS) vulnerability exists in
the tex ...)
- TODO: check
+ NOT-FOR-US: Onlook web application
CVE-2025-63784 (An Open Redirect vulnerability exists in the OAuth callback
handler in ...)
- TODO: check
+ NOT-FOR-US: Onlook web application
CVE-2025-63783 (A Broken Object Level Authorization (BOLA) vulnerability was
discovere ...)
- TODO: check
+ NOT-FOR-US: Onlook web application
CVE-2025-63718 (A SQL injection vulnerability exists in the SourceCodester
PQMS (Patie ...)
NOT-FOR-US: SourceCodester
CVE-2025-63717 (The change password functionality at
/pet_grooming/admin/change_pass.p ...)
@@ -27,15 +27,15 @@ CVE-2025-63714 (Cross-Site Scripting (XSS) vulnerability in
SourceCodester User
CVE-2025-63713 (Cross-Site Scripting (XSS) vulnerability in SourceCodester
"MatchMaste ...)
NOT-FOR-US: SourceCodester
CVE-2025-63691 (In pig-mesh In Pig version 3.8.2 and below, within the Token
Managemen ...)
- TODO: check
+ NOT-FOR-US: pig-mesh In Pig
CVE-2025-63690 (In pig-mesh Pig versions 3.8.2 and below, when setting up
scheduled ta ...)
- TODO: check
+ NOT-FOR-US: pig-mesh In Pig
CVE-2025-63689 (Multiple SQL injection vulnerabilitites in ycf1998 money-pos
system be ...)
- TODO: check
+ NOT-FOR-US: ycf1998 money-pos system
CVE-2025-63687 (An issue was discovered in rymcu forest thru commit f782e85
(2025-09-0 ...)
- TODO: check
+ NOT-FOR-US: rymcu forest
CVE-2025-63686 (There is an arbitrary file download vulnerability in GuoMinJim
PersonM ...)
- TODO: check
+ NOT-FOR-US: GuoMinJim PersonManage
CVE-2025-63640 (Sourcecodester Medicine Reminder App v1.0 is vulnerable to
Cross-Site ...)
NOT-FOR-US: SourceCodester
CVE-2025-63639 (The chat feature in the application Sourcecodester FAQ Bot
with AI Ass ...)
@@ -57,9 +57,9 @@ CVE-2025-57712 (A path traversal vulnerability has been
reported to affect Qsync
CVE-2025-57706 (A cross-site scripting (XSS) vulnerability has been reported
to affect ...)
NOT-FOR-US: QNAP
CVE-2025-57698 (AstrBot Project v3.5.22 contains a directory traversal
vulnerability. ...)
- TODO: check
+ NOT-FOR-US: AstrBot Project
CVE-2025-57697 (AstrBot Project v3.5.22 has an arbitrary file read
vulnerability in fu ...)
- TODO: check
+ NOT-FOR-US: AstrBot Project
CVE-2025-54168 (A cross-site scripting (XSS) vulnerability has been reported
to affect ...)
NOT-FOR-US: QNAP
CVE-2025-54167 (A cross-site scripting (XSS) vulnerability has been reported
to affect ...)
@@ -83,7 +83,7 @@ CVE-2025-52425 (An SQL injection vulnerability has been
reported to affect QuMag
CVE-2025-47207 (A NULL pointer dereference vulnerability has been reported to
affect s ...)
NOT-FOR-US: QNAP
CVE-2025-46413 (Use of password hash with insufficient computational effort
issue exis ...)
- TODO: check
+ NOT-FOR-US: BUFFALO
CVE-2025-3222 (Improper Authentication vulnerability in GE Vernova Smallworld
on Wind ...)
NOT-FOR-US: GE Vernova
CVE-2025-36186 (IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows
(includes Db ...)
@@ -101,7 +101,7 @@ CVE-2025-36008 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0
through 12.1.3 for Lin
CVE-2025-36006 (IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7,
11.5.0 throug ...)
NOT-FOR-US: IBM
CVE-2025-34299 (Monsta FTP versions 2.11 and earlier contain a vulnerability
that allo ...)
- TODO: check
+ NOT-FOR-US: Monsta FTP
CVE-2025-33012 (IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7,
11.5.0 throug ...)
NOT-FOR-US: IBM
CVE-2025-2534 (IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and
12.1.0 thr ...)
@@ -109,15 +109,15 @@ CVE-2025-2534 (IBM Db2 11.1.0 through 11.1.4.7, 11.5.0
through 11.5.9, and 12.1.
CVE-2025-12890 (Improper handling of malformed Connection Request with the
interval s ...)
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2025-12873 (A security flaw has been discovered in Campcodes School File
Managemen ...)
- TODO: check
+ NOT-FOR-US: Campcodes School File Management
CVE-2025-12862 (A vulnerability was identified in projectworlds Online Notes
Sharing P ...)
- TODO: check
+ NOT-FOR-US: projectworlds Online Notes Sharing Platform
CVE-2025-12861 (A vulnerability was determined in DedeBIZ up to 6.3.2.
Affected by thi ...)
- TODO: check
+ NOT-FOR-US: DedeBIZ
CVE-2025-12860 (A vulnerability was found in DedeBIZ up to 6.3.2. Affected is
an unkno ...)
- TODO: check
+ NOT-FOR-US: DedeBIZ
CVE-2025-12859 (A vulnerability has been found in DedeBIZ up to 6.3.2. This
impacts an ...)
- TODO: check
+ NOT-FOR-US: DedeBIZ
CVE-2025-12858
REJECTED
CVE-2025-12857 (A security vulnerability has been detected in code-projects
Responsive ...)
@@ -127,15 +127,15 @@ CVE-2025-12856 (A weakness has been identified in
code-projects Responsive Hotel
CVE-2025-12855 (A security flaw has been discovered in code-projects
Responsive Hotel ...)
NOT-FOR-US: code-projects
CVE-2025-12854 (A vulnerability was identified in newbee-mall-plus up to
2.4.1. This v ...)
- TODO: check
+ NOT-FOR-US: newbee-mall-plus
CVE-2025-12853 (A vulnerability was determined in SourceCodester Best House
Rental Man ...)
NOT-FOR-US: SourceCodester
CVE-2025-12829 (An uninitialized stack read issue exists in Amazon Ion-C
versions <v1. ...)
NOT-FOR-US: Amazon
CVE-2025-10968 (Improper Neutralization of Special Elements used in an SQL
Command ('S ...)
- TODO: check
+ NOT-FOR-US: PaperWork
CVE-2025-10870 (SQL injection vulnerability in DIAL's CentrosNet v2.64. Allows
an atta ...)
- TODO: check
+ NOT-FOR-US: DIAL's CentrosNet
CVE-2024-47118 (IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7,
11.5.0 throug ...)
NOT-FOR-US: IBM
CVE-2025-64346 (archives is a Go library for extracting archives (tar, zip,
etc.). Ver ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/29d11c66badf0293e73bb50e3a5a9359031f7b73
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/29d11c66badf0293e73bb50e3a5a9359031f7b73
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits