Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
4b1addc6 by security tracker role at 2026-03-21T20:12:51+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,4 +1,95 @@
+CVE-2026-4516 (A vulnerability was found in Foundation Agents MetaGPT up to 
0.8.1. Th ...)
+       TODO: check
+CVE-2026-4515 (A vulnerability has been found in Foundation Agents MetaGPT up 
to 0.8. ...)
+       TODO: check
+CVE-2026-4514 (A flaw has been found in PbootCMS up to 3.2.12. Affected by 
this issue ...)
+       TODO: check
+CVE-2026-4513 (A vulnerability was detected in vanna-ai vanna up to 2.0.2. 
Affected b ...)
+       TODO: check
+CVE-2026-4511 (A security vulnerability has been detected in vanna-ai vanna up 
to 2.0 ...)
+       TODO: check
+CVE-2026-2756 (A security vulnerability has been detected in OmniPEMF 
NeoRhythm up to ...)
+       TODO: check
+CVE-2019-25582 (i-doit CMDB 1.12 contains an arbitrary file download 
vulnerability tha ...)
+       TODO: check
+CVE-2019-25581 (i-doit CMDB 1.12 contains an SQL injection vulnerability that 
allows u ...)
+       TODO: check
+CVE-2019-25580 (ownDMS 4.7 contains an SQL injection vulnerability that allows 
unauthe ...)
+       TODO: check
+CVE-2019-25579 (phpTransformer 2016.9 contains a directory traversal 
vulnerability tha ...)
+       TODO: check
+CVE-2019-25578 (phpTransformer 2016.9 contains an SQL injection vulnerability 
that all ...)
+       TODO: check
+CVE-2019-25577 (SeoToaster Ecommerce 3.0.0 contains a local file inclusion 
vulnerabili ...)
+       TODO: check
+CVE-2019-25576 (Kepler Wallpaper Script 1.1 contains an SQL injection 
vulnerability th ...)
+       TODO: check
+CVE-2019-25575 (SimplePress CMS 1.0.7 contains an SQL injection vulnerability 
that all ...)
+       TODO: check
+CVE-2019-25574 (Green CMS 2.x contains a path traversal vulnerability that 
allows auth ...)
+       TODO: check
+CVE-2019-25573 (Green CMS 2.x contains an SQL injection vulnerability that 
allows auth ...)
+       TODO: check
+CVE-2019-25572 (NordVPN 6.19.6 contains a denial of service vulnerability that 
allows  ...)
+       TODO: check
+CVE-2019-25571 (MediaMonkey 4.1.23 contains a denial of service vulnerability 
that all ...)
+       TODO: check
+CVE-2019-25570 (RealTerm Serial Terminal 2.0.0.70 contains a denial of service 
vulnera ...)
+       TODO: check
+CVE-2019-25569 (RealTerm Serial Terminal 2.0.0.70 contains a stack-based 
buffer overfl ...)
+       TODO: check
+CVE-2019-25568 (Memu Play 6.0.7 contains an insecure file permissions 
vulnerability th ...)
+       TODO: check
+CVE-2019-25567 (Valentina Studio 9.0.5 Linux contains a buffer overflow 
vulnerability  ...)
+       TODO: check
+CVE-2019-25566 (TransMac 12.3 contains a buffer overflow vulnerability in the 
volume n ...)
+       TODO: check
+CVE-2019-25565 (Magic Iso Maker 5.5 build 281 contains a buffer overflow 
vulnerability ...)
+       TODO: check
+CVE-2019-25564 (PCHelpWareV2 1.0.0.5 contains a denial of service 
vulnerability that a ...)
+       TODO: check
+CVE-2019-25563 (PCHelpWareV2 1.0.0.5 contains a denial of service 
vulnerability that a ...)
+       TODO: check
+CVE-2019-25562 (jetAudio 8.1.7 contains a buffer overflow vulnerability in the 
video c ...)
+       TODO: check
+CVE-2019-25561 (Lyric Maker 2.0.1.0 contains a buffer overflow vulnerability 
that allo ...)
+       TODO: check
+CVE-2019-25560 (Lyric Video Creator 2.1 contains a denial of service 
vulnerability tha ...)
+       TODO: check
+CVE-2019-25559 (SpotPaltalk 1.1.5 contains a denial of service vulnerability 
in the re ...)
+       TODO: check
+CVE-2019-25558 (Selfie Studio 2.17 contains a denial of service vulnerability 
in the R ...)
+       TODO: check
+CVE-2019-25557 (TwistedBrush Pro Studio 24.06 contains a denial of service 
vulnerabili ...)
+       TODO: check
+CVE-2019-25556 (TwistedBrush Pro Studio 24.06 contains a denial of service 
vulnerabili ...)
+       TODO: check
+CVE-2019-25555 (TwistedBrush Pro Studio 24.06 contains a denial of service 
vulnerabili ...)
+       TODO: check
+CVE-2019-25554 (Tomabo MP4 Converter 3.25.22 contains a denial of service 
vulnerabilit ...)
+       TODO: check
+CVE-2019-25553 (CEWE PHOTO IMPORTER 6.4.3 contains a denial of service 
vulnerability t ...)
+       TODO: check
+CVE-2019-25552 (CEWE PHOTO SHOW 6.4.3 contains a denial of service 
vulnerability that  ...)
+       TODO: check
+CVE-2019-25551 (Sandboxie 5.30 contains a denial of service vulnerability that 
allows  ...)
+       TODO: check
+CVE-2019-25550 (Encrypt PDF 2.3 contains a buffer overflow vulnerability that 
allows l ...)
+       TODO: check
+CVE-2019-25549 (VeryPDF PCL Converter 2.7 contains a denial of service 
vulnerability t ...)
+       TODO: check
+CVE-2019-25548 (BlueStacks 4.80.0.1060 contains a denial of service 
vulnerability that ...)
+       TODO: check
+CVE-2019-25547 (NetAware 1.20 contains a buffer overflow vulnerability in the 
User Blo ...)
+       TODO: check
+CVE-2019-25546 (NetAware 1.20 contains a buffer overflow vulnerability in the 
Share Na ...)
+       TODO: check
+CVE-2019-25545 (Terminal Services Manager 3.2.1 contains a local buffer 
overflow vulne ...)
+       TODO: check
+CVE-2019-25544 (Pidgin 2.13.0 contains a denial of service vulnerability that 
allows l ...)
+       TODO: check
 CVE-2026-33250
+       {DSA-6173-1}
        - freeciv <unfixed>
 CVE-2026-4510 (A weakness has been identified in PbootCMS up to 3.2.12. This 
impacts  ...)
        NOT-FOR-US: PbootCMS
@@ -16481,6 +16572,7 @@ CVE-2026-20678 (An authorization issue was addressed 
with improved state managem
 CVE-2026-20677 (A race condition was addressed with improved handling of 
symbolic link ...)
        NOT-FOR-US: Apple
 CVE-2026-20676 (This issue was addressed through improved state management. 
This issue ...)
+       {DSA-6172-1}
        - webkit2gtk 2.50.6-1
        - wpewebkit 2.50.6-1
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in Trixie)
@@ -16520,6 +16612,7 @@ CVE-2026-20654 (The issue was addressed with improved 
memory handling. This issu
 CVE-2026-20653 (A parsing issue in the handling of directory paths was 
addressed with  ...)
        NOT-FOR-US: Apple
 CVE-2026-20652 (The issue was addressed with improved memory handling. This 
issue is f ...)
+       {DSA-6172-1}
        - webkit2gtk 2.50.6-1
        - wpewebkit 2.50.6-1
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in Trixie)
@@ -16539,6 +16632,7 @@ CVE-2026-20646 (A logging issue was addressed with 
improved data redaction. This
 CVE-2026-20645 (An inconsistent user interface issue was addressed with 
improved state ...)
        NOT-FOR-US: Apple
 CVE-2026-20644 (The issue was addressed with improved memory handling. This 
issue is f ...)
+       {DSA-6172-1}
        - webkit2gtk 2.50.6-1
        - wpewebkit 2.50.6-1
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in Trixie)
@@ -16554,6 +16648,7 @@ CVE-2026-20640 (An inconsistent user interface issue 
was addressed with improved
 CVE-2026-20638 (A logic issue was addressed with improved checks. This issue 
is fixed  ...)
        NOT-FOR-US: Apple
 CVE-2026-20636 (The issue was addressed with improved memory handling. This 
issue is f ...)
+       {DSA-6172-1}
        - webkit2gtk 2.50.6-1
        - wpewebkit 2.50.6-1
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in Trixie)
@@ -16561,6 +16656,7 @@ CVE-2026-20636 (The issue was addressed with improved 
memory handling. This issu
        [bullseye] - wpewebkit <end-of-life> (see #1035997)
        NOTE: https://webkitgtk.org/security/WSA-2026-0001.html
 CVE-2026-20635 (The issue was addressed with improved memory handling. This 
issue is f ...)
+       {DSA-6172-1}
        - webkit2gtk 2.50.6-1
        - wpewebkit 2.50.6-1
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in Trixie)
@@ -16610,6 +16706,7 @@ CVE-2026-20610 (This issue was addressed with improved 
handling of symlinks. Thi
 CVE-2026-20609 (The issue was addressed with improved memory handling. This 
issue is f ...)
        NOT-FOR-US: Apple
 CVE-2026-20608 (This issue was addressed through improved state management. 
This issue ...)
+       {DSA-6172-1}
        - webkit2gtk 2.50.6-1
        - wpewebkit 2.50.6-1
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in Trixie)
@@ -42293,6 +42390,7 @@ CVE-2025-43513 (A permissions issue was addressed by 
removing the vulnerable cod
 CVE-2025-43512 (A logic issue was addressed with improved checks. This issue 
is fixed  ...)
        NOT-FOR-US: Apple
 CVE-2025-43511 (A use-after-free issue was addressed with improved memory 
management.  ...)
+       {DSA-6172-1}
        - webkit2gtk 2.50.5-1
        - wpewebkit 2.50.5-1
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in Trixie)
@@ -55716,6 +55814,7 @@ CVE-2025-43458 (This issue was addressed through 
improved state management. This
        [bullseye] - wpewebkit <end-of-life> (see #1035997)
        NOTE: https://webkitgtk.org/security/WSA-2025-0009.html
 CVE-2025-43457 (A use-after-free issue was addressed with improved memory 
management.  ...)
+       {DSA-6172-1}
        - webkit2gtk 2.50.6-1
        - wpewebkit 2.50.6-1
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in Trixie)
@@ -89586,6 +89685,7 @@ CVE-2025-43216 (A use-after-free issue was addressed 
with improved memory manage
 CVE-2025-43215 (The issue was addressed with improved checks. This issue is 
fixed in m ...)
        NOT-FOR-US: Apple
 CVE-2025-43214 (The issue was addressed with improved memory handling. This 
issue is f ...)
+       {DSA-6172-1}
        - webkit2gtk 2.50.5-1
        - wpewebkit 2.50.5-1
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in Trixie)
@@ -922191,7 +922291,7 @@ CVE-2006-3972 (Directory traversal vulnerability in 
includes/operator_chattransc
        NOT-FOR-US: Ajax Chat
 CVE-2006-3971 (Cross-site scripting (XSS) vulnerability in 
visitor/livesupport/chat.p ...)
        NOT-FOR-US: Ajax Chat
-CVE-2006-10002 (XML::Parser versions through 2.47 for Perl could overflow the 
pre-allo ...)
+CVE-2006-10002 (XML::Parser versions through 2.45 for Perl could overflow the 
pre-allo ...)
        - libxml-parser-perl 2.46-1 (bug #378411; medium)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/38106361/
        NOTE: https://rt.cpan.org/Ticket/Display.html?id=19859



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4b1addc6ae152816f5146507ce55c72b78794f37

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4b1addc6ae152816f5146507ce55c72b78794f37
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to