Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
b00836e9 by security tracker role at 2025-12-26T20:13:11+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,49 @@
+CVE-2025-67349 (A cross-site scripting (XSS) vulnerability was identified in 
FluentCMS ...)
+       TODO: check
+CVE-2025-67015 (Incorrect access control in Comtech EF Data CDM-625 / CDM-625A 
Advance ...)
+       TODO: check
+CVE-2025-67014 (Incorrect access control in DEV Systemtechnik GmbH DEV 7113 RF 
over Fi ...)
+       TODO: check
+CVE-2025-67013 (The web management interface in ETL Systems Ltd DEXTRA Series 
' Digita ...)
+       TODO: check
+CVE-2025-66947 (SQL injection vulnerability in krishanmuraiji SMS v.1.0, 
within the /s ...)
+       TODO: check
+CVE-2025-66738 (An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote 
normal pr ...)
+       TODO: check
+CVE-2025-66737 (Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory 
Traversal. ...)
+       TODO: check
+CVE-2025-65885 (An issue was discovered in the Delight Custom Firmware (CFW) 
for Nokia ...)
+       TODO: check
+CVE-2025-64645 (IBM Concert 1.0.0 through 2.1.0 could allow a local user to 
escalate t ...)
+       TODO: check
+CVE-2025-57403 (Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When 
a DNS qu ...)
+       TODO: check
+CVE-2025-36230 (IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to 
HTML injec ...)
+       TODO: check
+CVE-2025-36229 (IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow 
authenticated u ...)
+       TODO: check
+CVE-2025-36228 (IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow 
inconsistent perm ...)
+       TODO: check
+CVE-2025-36192 (IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 
10.1.3.010.2.45 ...)
+       TODO: check
+CVE-2025-25341 (A vulnerability exists in the libxmljs 1.0.11 when parsing a 
specially ...)
+       TODO: check
+CVE-2025-1721 (IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker 
to obtai ...)
+       TODO: check
+CVE-2025-14687 (IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an 
authent ...)
+       TODO: check
+CVE-2025-13915 (IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could 
allow a ...)
+       TODO: check
+CVE-2025-13158 (Prototype pollution vulnerability in apidoc-core versions 
0.2.0 and al ...)
+       TODO: check
+CVE-2025-12771 (IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based 
buffer  ...)
+       TODO: check
+CVE-2024-44065 (Time-based blind SQL Injection vulnerability in Cloudlog 
v2.6.15 at th ...)
+       TODO: check
+CVE-2024-42718 (A path traversal vulnerability in Croogo CMS 4.0.7 allows 
remote attac ...)
+       TODO: check
+CVE-2024-29720 (An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 
allows a  ...)
+       TODO: check
 CVE-2025-8075 (Cybersecurity Nozomi Networks Labs, a specialized security 
company foc ...)
        NOT-FOR-US: Hanwha Vision Co., Ltd. QNV-C8012
 CVE-2025-68946 (In Gitea before 1.20.1, a forbidden URL scheme such as 
javascript: can ...)
@@ -5548,7 +5594,7 @@ CVE-2025-13610 (The RegistrationMagic \u2013 Custom 
Registration Forms, User Reg
        NOT-FOR-US: WordPress plugin
 CVE-2025-13608 (The CC Child Pages plugin for WordPress is vulnerable to 
Stored Cross- ...)
        NOT-FOR-US: WordPress plugin
-CVE-2025-13489 (IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 Deploy 
transmits data  ...)
+CVE-2025-13489 (IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps 
Deploy tran ...)
        NOT-FOR-US: IBM
 CVE-2025-13367 (The User Registration & Membership \u2013 Custom Registration 
Form Bui ...)
        NOT-FOR-US: WordPress plugin
@@ -10440,6 +10486,7 @@ CVE-2025-66471 (urllib3 is a user-friendly HTTP client 
library for Python. Start
        NOTE: The fix requires an updated src:brotli >= 1.2.0 for the fix to be 
effective,
        NOTE: which adds the optional output_buffer_limit option to avoid these 
attacks.
 CVE-2025-66418 (urllib3 is a user-friendly HTTP client library for Python. 
Starting in ...)
+       {DLA-4421-1}
        - python-urllib3 <unfixed> (bug #1122030)
        NOTE: https://www.openwall.com/lists/oss-security/2025/12/05/4
        NOTE: 
https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53
@@ -64761,6 +64808,7 @@ CVE-2025-50182 (urllib3 is a user-friendly HTTP client 
library for Python. Start
        NOTE: Introduced with: 
https://github.com/urllib3/urllib3/commit/1812eac7115b3a4e9a5feece5fae0c9cffe8c585
 (2.2.0
        NOTE: Fixed by: 
https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f
 (2.5.0)
 CVE-2025-50181 (urllib3 is a user-friendly HTTP client library for Python. 
Prior to 2. ...)
+       {DLA-4421-1}
        - python-urllib3 2.3.0-3 (bug #1108076)
        [bookworm] - python-urllib3 <no-dsa> (Minor issue)
        NOTE: 
https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b00836e936e8463815fa95b4ea1189110c13f2da

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b00836e936e8463815fa95b4ea1189110c13f2da
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to