Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
b00836e9 by security tracker role at 2025-12-26T20:13:11+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,49 @@
+CVE-2025-67349 (A cross-site scripting (XSS) vulnerability was identified in
FluentCMS ...)
+ TODO: check
+CVE-2025-67015 (Incorrect access control in Comtech EF Data CDM-625 / CDM-625A
Advance ...)
+ TODO: check
+CVE-2025-67014 (Incorrect access control in DEV Systemtechnik GmbH DEV 7113 RF
over Fi ...)
+ TODO: check
+CVE-2025-67013 (The web management interface in ETL Systems Ltd DEXTRA Series
' Digita ...)
+ TODO: check
+CVE-2025-66947 (SQL injection vulnerability in krishanmuraiji SMS v.1.0,
within the /s ...)
+ TODO: check
+CVE-2025-66738 (An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote
normal pr ...)
+ TODO: check
+CVE-2025-66737 (Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory
Traversal. ...)
+ TODO: check
+CVE-2025-65885 (An issue was discovered in the Delight Custom Firmware (CFW)
for Nokia ...)
+ TODO: check
+CVE-2025-64645 (IBM Concert 1.0.0 through 2.1.0 could allow a local user to
escalate t ...)
+ TODO: check
+CVE-2025-57403 (Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When
a DNS qu ...)
+ TODO: check
+CVE-2025-36230 (IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to
HTML injec ...)
+ TODO: check
+CVE-2025-36229 (IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow
authenticated u ...)
+ TODO: check
+CVE-2025-36228 (IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow
inconsistent perm ...)
+ TODO: check
+CVE-2025-36192 (IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0)
10.1.3.010.2.45 ...)
+ TODO: check
+CVE-2025-25341 (A vulnerability exists in the libxmljs 1.0.11 when parsing a
specially ...)
+ TODO: check
+CVE-2025-1721 (IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker
to obtai ...)
+ TODO: check
+CVE-2025-14687 (IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an
authent ...)
+ TODO: check
+CVE-2025-13915 (IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could
allow a ...)
+ TODO: check
+CVE-2025-13158 (Prototype pollution vulnerability in apidoc-core versions
0.2.0 and al ...)
+ TODO: check
+CVE-2025-12771 (IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based
buffer ...)
+ TODO: check
+CVE-2024-44065 (Time-based blind SQL Injection vulnerability in Cloudlog
v2.6.15 at th ...)
+ TODO: check
+CVE-2024-42718 (A path traversal vulnerability in Croogo CMS 4.0.7 allows
remote attac ...)
+ TODO: check
+CVE-2024-29720 (An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0
allows a ...)
+ TODO: check
CVE-2025-8075 (Cybersecurity Nozomi Networks Labs, a specialized security
company foc ...)
NOT-FOR-US: Hanwha Vision Co., Ltd. QNV-C8012
CVE-2025-68946 (In Gitea before 1.20.1, a forbidden URL scheme such as
javascript: can ...)
@@ -5548,7 +5594,7 @@ CVE-2025-13610 (The RegistrationMagic \u2013 Custom
Registration Forms, User Reg
NOT-FOR-US: WordPress plugin
CVE-2025-13608 (The CC Child Pages plugin for WordPress is vulnerable to
Stored Cross- ...)
NOT-FOR-US: WordPress plugin
-CVE-2025-13489 (IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 Deploy
transmits data ...)
+CVE-2025-13489 (IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps
Deploy tran ...)
NOT-FOR-US: IBM
CVE-2025-13367 (The User Registration & Membership \u2013 Custom Registration
Form Bui ...)
NOT-FOR-US: WordPress plugin
@@ -10440,6 +10486,7 @@ CVE-2025-66471 (urllib3 is a user-friendly HTTP client
library for Python. Start
NOTE: The fix requires an updated src:brotli >= 1.2.0 for the fix to be
effective,
NOTE: which adds the optional output_buffer_limit option to avoid these
attacks.
CVE-2025-66418 (urllib3 is a user-friendly HTTP client library for Python.
Starting in ...)
+ {DLA-4421-1}
- python-urllib3 <unfixed> (bug #1122030)
NOTE: https://www.openwall.com/lists/oss-security/2025/12/05/4
NOTE:
https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53
@@ -64761,6 +64808,7 @@ CVE-2025-50182 (urllib3 is a user-friendly HTTP client
library for Python. Start
NOTE: Introduced with:
https://github.com/urllib3/urllib3/commit/1812eac7115b3a4e9a5feece5fae0c9cffe8c585
(2.2.0
NOTE: Fixed by:
https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f
(2.5.0)
CVE-2025-50181 (urllib3 is a user-friendly HTTP client library for Python.
Prior to 2. ...)
+ {DLA-4421-1}
- python-urllib3 2.3.0-3 (bug #1108076)
[bookworm] - python-urllib3 <no-dsa> (Minor issue)
NOTE:
https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b00836e936e8463815fa95b4ea1189110c13f2da
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b00836e936e8463815fa95b4ea1189110c13f2da
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits