Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
29d11c66 by Salvatore Bonaccorso at 2025-11-07T21:26:54+01:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,19 +3,19 @@ CVE-2025-9458 (A maliciously crafted PRT file, when parsed 
through certain Autod
 CVE-2025-7719 (Improper Limitation of a Pathname to a Restricted Directory 
('Path Tra ...)
        NOT-FOR-US: GE Vernova
 CVE-2025-64432 (KubeVirt is a virtual machine management add-on for 
Kubernetes. Versio ...)
-       TODO: check
+       NOT-FOR-US: KubeVirt
 CVE-2025-64431 (Zitadel is an open source identity management platform. 
Versions 4.0.0 ...)
-       TODO: check
+       NOT-FOR-US: Zitadel
 CVE-2025-64430 (Parse Server is an open source backend that can be deployed to 
any inf ...)
-       TODO: check
+       NOT-FOR-US: Parse Server
 CVE-2025-64347 (Apollo Router Core is a configurable Rust graph router written 
to run  ...)
-       TODO: check
+       NOT-FOR-US: Apollo Router Core
 CVE-2025-63785 (A DOM-based Cross-Site Scripting (XSS) vulnerability exists in 
the tex ...)
-       TODO: check
+       NOT-FOR-US: Onlook web application
 CVE-2025-63784 (An Open Redirect vulnerability exists in the OAuth callback 
handler in ...)
-       TODO: check
+       NOT-FOR-US: Onlook web application
 CVE-2025-63783 (A Broken Object Level Authorization (BOLA) vulnerability was 
discovere ...)
-       TODO: check
+       NOT-FOR-US: Onlook web application
 CVE-2025-63718 (A SQL injection vulnerability exists in the SourceCodester 
PQMS (Patie ...)
        NOT-FOR-US: SourceCodester
 CVE-2025-63717 (The change password functionality at 
/pet_grooming/admin/change_pass.p ...)
@@ -27,15 +27,15 @@ CVE-2025-63714 (Cross-Site Scripting (XSS) vulnerability in 
SourceCodester User
 CVE-2025-63713 (Cross-Site Scripting (XSS) vulnerability in SourceCodester 
"MatchMaste ...)
        NOT-FOR-US: SourceCodester
 CVE-2025-63691 (In pig-mesh In Pig version 3.8.2 and below, within the Token 
Managemen ...)
-       TODO: check
+       NOT-FOR-US: pig-mesh In Pig
 CVE-2025-63690 (In pig-mesh Pig versions 3.8.2 and below, when setting up 
scheduled ta ...)
-       TODO: check
+       NOT-FOR-US: pig-mesh In Pig
 CVE-2025-63689 (Multiple SQL injection vulnerabilitites in ycf1998 money-pos 
system be ...)
-       TODO: check
+       NOT-FOR-US: ycf1998 money-pos system
 CVE-2025-63687 (An issue was discovered in rymcu forest thru commit f782e85 
(2025-09-0 ...)
-       TODO: check
+       NOT-FOR-US: rymcu forest
 CVE-2025-63686 (There is an arbitrary file download vulnerability in GuoMinJim 
PersonM ...)
-       TODO: check
+       NOT-FOR-US: GuoMinJim PersonManage
 CVE-2025-63640 (Sourcecodester Medicine Reminder App v1.0 is vulnerable to 
Cross-Site  ...)
        NOT-FOR-US: SourceCodester
 CVE-2025-63639 (The chat feature in the application Sourcecodester FAQ Bot 
with AI Ass ...)
@@ -57,9 +57,9 @@ CVE-2025-57712 (A path traversal vulnerability has been 
reported to affect Qsync
 CVE-2025-57706 (A cross-site scripting (XSS) vulnerability has been reported 
to affect ...)
        NOT-FOR-US: QNAP
 CVE-2025-57698 (AstrBot Project v3.5.22 contains a directory traversal 
vulnerability.  ...)
-       TODO: check
+       NOT-FOR-US: AstrBot Project
 CVE-2025-57697 (AstrBot Project v3.5.22 has an arbitrary file read 
vulnerability in fu ...)
-       TODO: check
+       NOT-FOR-US: AstrBot Project
 CVE-2025-54168 (A cross-site scripting (XSS) vulnerability has been reported 
to affect ...)
        NOT-FOR-US: QNAP
 CVE-2025-54167 (A cross-site scripting (XSS) vulnerability has been reported 
to affect ...)
@@ -83,7 +83,7 @@ CVE-2025-52425 (An SQL injection vulnerability has been 
reported to affect QuMag
 CVE-2025-47207 (A NULL pointer dereference vulnerability has been reported to 
affect s ...)
        NOT-FOR-US: QNAP
 CVE-2025-46413 (Use of password hash with insufficient computational effort 
issue exis ...)
-       TODO: check
+       NOT-FOR-US: BUFFALO
 CVE-2025-3222 (Improper Authentication vulnerability in GE Vernova Smallworld 
on Wind ...)
        NOT-FOR-US: GE Vernova
 CVE-2025-36186 (IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows 
(includes Db ...)
@@ -101,7 +101,7 @@ CVE-2025-36008 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 
through 12.1.3 for Lin
 CVE-2025-36006 (IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 
11.5.0 throug ...)
        NOT-FOR-US: IBM
 CVE-2025-34299 (Monsta FTP versions 2.11 and earlier contain a vulnerability 
that allo ...)
-       TODO: check
+       NOT-FOR-US: Monsta FTP
 CVE-2025-33012 (IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 
11.5.0 throug ...)
        NOT-FOR-US: IBM
 CVE-2025-2534 (IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 
12.1.0 thr ...)
@@ -109,15 +109,15 @@ CVE-2025-2534 (IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 
through 11.5.9, and 12.1.
 CVE-2025-12890 (Improper handling of  malformed Connection Request with the 
interval s ...)
        NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2025-12873 (A security flaw has been discovered in Campcodes School File 
Managemen ...)
-       TODO: check
+       NOT-FOR-US: Campcodes School File Management
 CVE-2025-12862 (A vulnerability was identified in projectworlds Online Notes 
Sharing P ...)
-       TODO: check
+       NOT-FOR-US: projectworlds Online Notes Sharing Platform
 CVE-2025-12861 (A vulnerability was determined in DedeBIZ up to 6.3.2. 
Affected by thi ...)
-       TODO: check
+       NOT-FOR-US: DedeBIZ
 CVE-2025-12860 (A vulnerability was found in DedeBIZ up to 6.3.2. Affected is 
an unkno ...)
-       TODO: check
+       NOT-FOR-US: DedeBIZ
 CVE-2025-12859 (A vulnerability has been found in DedeBIZ up to 6.3.2. This 
impacts an ...)
-       TODO: check
+       NOT-FOR-US: DedeBIZ
 CVE-2025-12858
        REJECTED
 CVE-2025-12857 (A security vulnerability has been detected in code-projects 
Responsive ...)
@@ -127,15 +127,15 @@ CVE-2025-12856 (A weakness has been identified in 
code-projects Responsive Hotel
 CVE-2025-12855 (A security flaw has been discovered in code-projects 
Responsive Hotel  ...)
        NOT-FOR-US: code-projects
 CVE-2025-12854 (A vulnerability was identified in newbee-mall-plus up to 
2.4.1. This v ...)
-       TODO: check
+       NOT-FOR-US: newbee-mall-plus
 CVE-2025-12853 (A vulnerability was determined in SourceCodester Best House 
Rental Man ...)
        NOT-FOR-US: SourceCodester
 CVE-2025-12829 (An uninitialized stack read issue exists in Amazon Ion-C 
versions <v1. ...)
        NOT-FOR-US: Amazon
 CVE-2025-10968 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
-       TODO: check
+       NOT-FOR-US: PaperWork
 CVE-2025-10870 (SQL injection vulnerability in DIAL's CentrosNet v2.64. Allows 
an atta ...)
-       TODO: check
+       NOT-FOR-US: DIAL's CentrosNet
 CVE-2024-47118 (IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 
11.5.0 throug ...)
        NOT-FOR-US: IBM
 CVE-2025-64346 (archives is a Go library for extracting archives (tar, zip, 
etc.). Ver ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/29d11c66badf0293e73bb50e3a5a9359031f7b73

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/29d11c66badf0293e73bb50e3a5a9359031f7b73
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to