Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
9dd92820 by security tracker role at 2026-09-14T07:12:50+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,307 @@
+CVE-2026-90691 (A security vulnerability has been detected in 0x4m4 HexStrike
AI up to ...)
+ TODO: check
+CVE-2026-90690 (A weakness has been identified in 0x4m4 HexStrike AI up to
d689933ff57 ...)
+ TODO: check
+CVE-2026-90689 (A security flaw has been discovered in Tenda W20E
15.11.0.61068_1546_8 ...)
+ TODO: check
+CVE-2026-90688 (A vulnerability was identified in Tenda W20E
15.11.0.61068_1546_841_CN ...)
+ TODO: check
+CVE-2026-90687 (A vulnerability was determined in GPAC up to f1219cde. This
vulnerabil ...)
+ TODO: check
+CVE-2026-90686 (A vulnerability was found in GPAC up to f1219cde. This affects
the fun ...)
+ TODO: check
+CVE-2026-90685 (A vulnerability has been found in GPAC up to f1219cde.
Affected by thi ...)
+ TODO: check
+CVE-2026-90684 (A flaw has been found in GPAC up to f1219cde. Affected by this
vulnera ...)
+ TODO: check
+CVE-2026-90683 (A vulnerability was detected in GPAC up to f1219cde. Affected
is the f ...)
+ TODO: check
+CVE-2026-90682 (A security vulnerability has been detected in Matthias-Wandel
jhead up ...)
+ TODO: check
+CVE-2026-90681 (A weakness has been identified in Matthias-Wandel jhead up to
3.3. Thi ...)
+ TODO: check
+CVE-2026-90680 (A security flaw has been discovered in D-Link DIR-823G
1.0.2B05_201812 ...)
+ TODO: check
+CVE-2026-90623 (A weakness has been identified in andreashappe cochise up to
0.4.1. Af ...)
+ TODO: check
+CVE-2026-90622 (A security flaw has been discovered in GNU libredwg 0.13.4.
This impac ...)
+ TODO: check
+CVE-2026-90621 (A vulnerability was identified in ipa-lab HackingBuddyGPT up
to 0.5.0. ...)
+ TODO: check
+CVE-2026-90620 (A vulnerability was determined in 0x4m4 HexStrike AI up to
d689933ff57 ...)
+ TODO: check
+CVE-2026-90619 (A vulnerability has been found in 0x4m4 HexStrike AI up to
d689933ff57 ...)
+ TODO: check
+CVE-2026-90618 (A flaw has been found in GH05TCREW PentestAgent up to
cf882dabea3ed91c ...)
+ TODO: check
+CVE-2026-90617 (A vulnerability was detected in GH05TCREW PentestAgent up to
cf882dabe ...)
+ TODO: check
+CVE-2026-90615 (A security vulnerability has been detected in SourceCodester
Class and ...)
+ TODO: check
+CVE-2026-90614 (A weakness has been identified in FedML-AI FedML up to 0.9.6.
Affected ...)
+ TODO: check
+CVE-2026-90613 (A security flaw has been discovered in GPAC up to f1219cde.
Affected b ...)
+ TODO: check
+CVE-2026-90612 (A vulnerability was identified in GPAC up to f1219cde.
Affected is the ...)
+ TODO: check
+CVE-2026-90611 (A vulnerability was determined in GPAC up to f1219cde. This
impacts th ...)
+ TODO: check
+CVE-2026-90610 (A vulnerability was found in GPAC up to f1219cde. This affects
the fun ...)
+ TODO: check
+CVE-2026-90609 (A vulnerability has been found in GPAC up to f1219cde. The
impacted el ...)
+ TODO: check
+CVE-2026-90608 (A flaw has been found in Totolink A3002MU Hh-B20211125.1046.
The affec ...)
+ TODO: check
+CVE-2026-90607 (A vulnerability was detected in Totolink A3002MU
Hh-B20211125.1046. Im ...)
+ TODO: check
+CVE-2026-90606 (A security vulnerability has been detected in Totolink A3002MU
Hh-B202 ...)
+ TODO: check
+CVE-2026-90605 (A weakness has been identified in Totolink A3002MU
Hh-B20211125.1046. ...)
+ TODO: check
+CVE-2026-90604 (A security flaw has been discovered in Totolink A3002MU
Hh-B20211125.1 ...)
+ TODO: check
+CVE-2026-90603 (A vulnerability was identified in Anil-matcha
Open-Generative-AI up to ...)
+ TODO: check
+CVE-2026-90602 (A vulnerability was determined in Anil-matcha
Open-Generative-AI up to ...)
+ TODO: check
+CVE-2026-90601 (A vulnerability was found in getzep graphiti up to 0.30.2.
Affected is ...)
+ TODO: check
+CVE-2026-90600 (A vulnerability has been found in itsourcecode Sales and
Inventory Sys ...)
+ TODO: check
+CVE-2026-90599 (A flaw has been found in Rizwan17 inventory-management-system
up to 5e ...)
+ TODO: check
+CVE-2026-90598 (A vulnerability was detected in jaygajera17
E-commerce-project-springB ...)
+ TODO: check
+CVE-2026-90597 (A security vulnerability has been detected in itsourcecode
Sales and I ...)
+ TODO: check
+CVE-2026-90596 (A weakness has been identified in embedded-graphics up to
0.8.2 on 32- ...)
+ TODO: check
+CVE-2026-90595 (A security flaw has been discovered in wxiaoqi
Spring-Cloud-Platform 1 ...)
+ TODO: check
+CVE-2026-90594 (A vulnerability was identified in wxiaoqi
Spring-Cloud-Platform 3.0.1/ ...)
+ TODO: check
+CVE-2026-90593 (A vulnerability was determined in embedded-graphics up to
0.8.2. This ...)
+ TODO: check
+CVE-2026-90584 (A weakness has been identified in TooTallNate Java-WebSocket
up to 1.6 ...)
+ TODO: check
+CVE-2026-90583 (A security flaw has been discovered in kagisearch smallweb up
to 0ecb9 ...)
+ TODO: check
+CVE-2026-90582 (A vulnerability was identified in evanchiu serverless-todo
1.0.3/2.0.0 ...)
+ TODO: check
+CVE-2026-90581 (A vulnerability was determined in cym1102 nginxWebUI up to
4.4.2. This ...)
+ TODO: check
+CVE-2026-90580 (A vulnerability was found in FlowiseAI Flowise up to 3.0.2.
This vulne ...)
+ TODO: check
+CVE-2026-89050 (The Quads Ads Manager for Google AdSense WordPress plugin
before 3.0.5 ...)
+ TODO: check
+CVE-2026-88853 (Joomla Extension - regularlabs.com - Privileged stored XSS via
event h ...)
+ TODO: check
+CVE-2026-88852 (Joomla Extension - regularlabs.com - Privileged stored XSS via
url opt ...)
+ TODO: check
+CVE-2026-88802 (The MDJM Event Management WordPress plugin before 1.7.8.5 and
the Mobi ...)
+ TODO: check
+CVE-2026-88793 (The YouTube Embed WordPress plugin from 10.0 to 10.3 does not
perform ...)
+ TODO: check
+CVE-2026-85196 (Joomla Extension - regularlabs.com - Reflected XSS in Articles
Anywher ...)
+ TODO: check
+CVE-2026-85195 (Joomla Extension - regularlabs.com - Privileged stored XSS via
link op ...)
+ TODO: check
+CVE-2026-85192 (Joomla Extension - regularlabs.com - Authenticated, privileged
remote ...)
+ TODO: check
+CVE-2026-85191 (Joomla Extension - regularlabs.com - Privileged stored XSS via
rtla-al ...)
+ TODO: check
+CVE-2026-85190 (Joomla Extension - regularlabs.com - Privileged stored XSS via
class o ...)
+ TODO: check
+CVE-2026-85189 (Joomla Extension - regularlabs.com - Privileged stored XSS via
executa ...)
+ TODO: check
+CVE-2026-85188 (Joomla Extension - regularlabs.com - Database data disclosure
in Advan ...)
+ TODO: check
+CVE-2026-85129 (The Hoo Companion WordPress plugin 1.0.2 does not have any
authorisati ...)
+ TODO: check
+CVE-2026-85125 (The Android application "YAMAP -Social Trekking GPS App"
contains an i ...)
+ TODO: check
+CVE-2026-82796 (SolarView Compact contains a cross-site scripting
vulnerability in Ima ...)
+ TODO: check
+CVE-2026-82795 (SolarView Compact contains a cross-site scripting
vulnerability in Sch ...)
+ TODO: check
+CVE-2026-82794 (SolarView Compact contains an OS command Injection
vulnerability in in ...)
+ TODO: check
+CVE-2026-82793 (Unrestricted upload of file with dangerous type issue exists
in Contec ...)
+ TODO: check
+CVE-2026-82792 (Cross-site scripting vulnerability exists in Contec CAN 2.0B
Communica ...)
+ TODO: check
+CVE-2026-82791 (Improper neutralization of special elements used in an OS
command ('OS ...)
+ TODO: check
+CVE-2026-82790 (Cross-site scripting vulnerability exists in PC-HELPER
Wireless I/O DI ...)
+ TODO: check
+CVE-2026-82789 (An improper neutralization of directives in dynamically
evaluated code ...)
+ TODO: check
+CVE-2026-82788 (Cross-site scripting vulnerability exists in CPSL-08P1EN. If
this vuln ...)
+ TODO: check
+CVE-2026-82787 (Missing authentication for critical function vulnerability
exists in C ...)
+ TODO: check
+CVE-2026-82786 (Insufficiently protected credentials issue exists in Remote
I/O Couple ...)
+ TODO: check
+CVE-2026-82785 (Stack-based buffer overflow vulnerability exists in Remote I/O
Coupler ...)
+ TODO: check
+CVE-2026-82784 (Missing authentication for critical function vulnerability
exists in R ...)
+ TODO: check
+CVE-2026-82783 (Plaintext storage of a password issue exists in CONPROSYS nano
Series ...)
+ TODO: check
+CVE-2026-82782 (Out-of-bounds write vulnerability exists in CONPROSYS nano
Series. Rec ...)
+ TODO: check
+CVE-2026-82781 (Cross-site scripting vulnerability exists in CONPROSYS nano
Series. If ...)
+ TODO: check
+CVE-2026-82780 (Unrestricted upload of file with dangerous type issue exists
in CONPRO ...)
+ TODO: check
+CVE-2026-82779 (Improper neutralization of special elements used in an OS
command ('OS ...)
+ TODO: check
+CVE-2026-82778 (An exposure of information through directory listing issue
exists in C ...)
+ TODO: check
+CVE-2026-82777 (Improper neutralization of special elements used in an OS
command ('OS ...)
+ TODO: check
+CVE-2026-82776 (Cross-site scripting vulnerability exists in CONPROSYS PAC
Series. If ...)
+ TODO: check
+CVE-2026-82775 (An exposure of information through directory listing issue
exists in C ...)
+ TODO: check
+CVE-2026-82774 (Improper neutralization of special elements used in an OS
command ('OS ...)
+ TODO: check
+CVE-2026-82773 (Cross-site scripting vulnerability exists in CONPROSYS M2M
Gateway Ser ...)
+ TODO: check
+CVE-2026-82772 (Buffer overflow vulnerability exists in Contec EC1000 series.
If a rem ...)
+ TODO: check
+CVE-2026-82771 (Cross-site scripting vulnerability exists in Contec EC1000
series. If ...)
+ TODO: check
+CVE-2026-82770 (Buffer overflow vulnerability exists in Contec RP-WAH-SR
Series. If a ...)
+ TODO: check
+CVE-2026-82769 (Cross-site scripting vulnerability exists in Contec RP-WAH-SR
Series. ...)
+ TODO: check
+CVE-2026-82768 (Path traversal vulnerability exists in SGA1000. If this
vulnerability ...)
+ TODO: check
+CVE-2026-82767 (Cross-site scripting vulnerability exists in SGA1000. If this
vulnerab ...)
+ TODO: check
+CVE-2026-82766 (Improper neutralization of special elements used in an OS
command ('OS ...)
+ TODO: check
+CVE-2026-82765 (Path traversal vulnerability exists in Contec FX5000 series,
FX4000 se ...)
+ TODO: check
+CVE-2026-82764 (Cross-site request forgery vulnerability exists in multiple
Contec pro ...)
+ TODO: check
+CVE-2026-82763 (Cross-site scripting vulnerability exists in Contec FX5000
series, FX4 ...)
+ TODO: check
+CVE-2026-82762 (Improper neutralization of special elements used in an OS
command ('OS ...)
+ TODO: check
+CVE-2026-81648 (The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2
does no ...)
+ TODO: check
+CVE-2026-74933 (The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not
have au ...)
+ TODO: check
+CVE-2026-68955 (The installer for Rakuten Kobo Desktop Application (Windows
version) i ...)
+ TODO: check
+CVE-2026-52297 (FFmpeg before 9.0 has an out-of-bounds read because there is
insuffici ...)
+ TODO: check
+CVE-2026-52296 (FFmpeg before 9.0 has an out-of-bounds read because of missing
require ...)
+ TODO: check
+CVE-2026-49030
+ REJECTED
+CVE-2026-38924 (In Oraios AI Serena before 1.0.0, the listen address of the
MCP server ...)
+ TODO: check
+CVE-2026-38332 (TinyEXIF before 1.1.0 has a heap-based buffer over-read in
EntryParser ...)
+ TODO: check
+CVE-2026-37008 (CrewAI before fb2323b offers a Python blocklist approach that
operates ...)
+ TODO: check
+CVE-2026-36989 (A SQL Injection vulnerability exists in LuxSoft LuxCal through
5.3.4L ...)
+ TODO: check
+CVE-2026-36453 (Rhymix before 2.1.31 allows insecure direct object reference,
aka RVE- ...)
+ TODO: check
+CVE-2026-35867 (A Command Injection vulnerability exists in the
bs_SetLimitCli_info fu ...)
+ TODO: check
+CVE-2026-33970 (An issue was discovered in NR RRC and L2 in Samsung Mobile
Processor, ...)
+ TODO: check
+CVE-2026-33968 (An issue was discovered in camera in Samsung Mobile Processor
Exynos 1 ...)
+ TODO: check
+CVE-2026-33967 (An issue was discovered in camera in Samsung Mobile Processor
Exynos 1 ...)
+ TODO: check
+CVE-2026-33966 (An issue was discovered in camera in Samsung Mobile Processor
Exynos 1 ...)
+ TODO: check
+CVE-2026-33964 (An issue was discovered in camera in Samsung Mobile Processor
Exynos 1 ...)
+ TODO: check
+CVE-2026-33963 (An issue was discovered in camera in Samsung Mobile Processor
Exynos 1 ...)
+ TODO: check
+CVE-2026-33962 (An issue was discovered in Wi-Fi in Samsung Mobile Processor
Exynos 85 ...)
+ TODO: check
+CVE-2026-33960 (An issue was discovered in Samsung Mobile Processor and
Wearable Proce ...)
+ TODO: check
+CVE-2026-33957 (An issue was discovered in CustOS Driver in Samsung Mobile
Processor E ...)
+ TODO: check
+CVE-2026-33956 (An issue was discovered in camera in Samsung Mobile Processor
Exynos 1 ...)
+ TODO: check
+CVE-2026-31278 (An issue in the /api/v2/setting/adserversetting endpoint of
Suprema Bi ...)
+ TODO: check
+CVE-2026-29812 (CyberPanel before 2.4.4 has no logging for actions that could
potentia ...)
+ TODO: check
+CVE-2026-29811 (CyberPanel before 2.4.4 attempts to detect an "alais" domain
(i.e., a ...)
+ TODO: check
+CVE-2026-29810 (CyberPanel before 2.4.4 omits a "return 0" that is required by
the bus ...)
+ TODO: check
+CVE-2026-23793 (An issue was discovered in Samsung Mobile Processor Exynos
1330, 1380, ...)
+ TODO: check
+CVE-2026-23792 (An issue was discovered in NR RRC in Samsung Mobile Processor
and Mode ...)
+ TODO: check
+CVE-2026-23791 (An issue was discovered in DPU in Samsung Mobile Processor
Exynos 1280 ...)
+ TODO: check
+CVE-2026-23790 (An issue was discovered in DPU in Samsung Mobile Processor
Exynos 1280 ...)
+ TODO: check
+CVE-2026-23789 (An issue was discovered in MFC in Samsung Mobile Processor and
Wearabl ...)
+ TODO: check
+CVE-2026-23788 (An issue was discovered in DPU in Samsung Mobile Processor
Exynos 1280 ...)
+ TODO: check
+CVE-2026-23787 (An issue was discovered in DPU in Samsung Mobile Processor
Exynos 1280 ...)
+ TODO: check
+CVE-2026-23786 (An issue was discovered in DPU in Samsung Mobile Processor
Exynos 1280 ...)
+ TODO: check
+CVE-2026-16726 (Buffer overflow vulnerabilityin Panasonic IndustryUSB Driver
for MINAS ...)
+ TODO: check
+CVE-2026-15892 (The mcumgr SMP settings-management group handlers
settings_mgmt_read() ...)
+ TODO: check
+CVE-2026-15891 (The MQTT-SN client keepalive handler process_ping() in
subsys/net/lib/ ...)
+ TODO: check
+CVE-2025-70820 (Zettlab D6 Ultra before 1.7.0 allows absolute path traversal
to reach ...)
+ TODO: check
+CVE-2025-68624 (N-able Mail Assure through April 2026 contains a design-level
authoriz ...)
+ TODO: check
+CVE-2025-64031 (libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer
overflow ...)
+ TODO: check
+CVE-2025-63842 (A Cross-Site Scripting (XSS) vulnerability in the web backend
for the ...)
+ TODO: check
+CVE-2025-26790 (Withsecure Atlant with Capricorn engine before 2025-01-20_02
allows a ...)
+ TODO: check
+CVE-2024-53922 (An issue was discovered in the buffer queue driver in Samsung
Automoti ...)
+ TODO: check
+CVE-2023-51769 (Frappe before 14.49.0 allows an XSS attack that is associated
with blo ...)
+ TODO: check
+CVE-2023-50462 (An issue was discovered in the content_consent (aka Content
Consent) e ...)
+ TODO: check
+CVE-2023-50461 (An issue was discovered in the direct_mail (aka Direct Mail)
extension ...)
+ TODO: check
+CVE-2023-50460 (An issue was discovered in the femanager extension 7.x before
7.2.3 fo ...)
+ TODO: check
+CVE-2023-50459 (An issue was discovered in the femanager extension 7.x before
7.2.3 fo ...)
+ TODO: check
+CVE-2023-46273 (Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a,
and thro ...)
+ TODO: check
+CVE-2023-46035 (The svg_optimizer gem before 0.3.0 for Ruby performs entity
expansion ...)
+ TODO: check
+CVE-2023-45858 (A directory traversal was identified in Paessler PRTG before
23.4.88.1 ...)
+ TODO: check
+CVE-2023-45023 (The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect
Access ...)
+ TODO: check
+CVE-2023-40772 (A directory Traversal vulnerability in DataEase before 1.18.10
allows ...)
+ TODO: check
+CVE-2023-37366 (An issue was discovered in Samsung Exynos Mobile Processor,
Automotive ...)
+ TODO: check
+CVE-2023-32803 (The ca-certificates package before
ca-certificates-2021.2.50-72 for Am ...)
+ TODO: check
+CVE-2023-32778 (An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1.
An atta ...)
+ TODO: check
CVE-2026-90783 (MKVToolNix through 101.0 contains a heap buffer overflow in
the bundle ...)
- mkvtoolnix <unfixed> (bug #1147621)
NOTE: Fixed by:
https://codeberg.org/mbunkus/mkvtoolnix/commit/1495126138e086080f0163bee27fafbdf956a1d0
@@ -13715,7 +14019,7 @@ CVE-2026-55951 (The Erlang/OTP httpc HTTP client does
not enforce a limit on the
CVE-2026-53682 (An unauthenticated client can query the Security Domain hosts
inventor ...)
- dogtag-pki <removed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2487511
-CVE-2026-52295 (Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows
an atta ...)
+CVE-2026-52295 (FFmpeg before 9.0 has an out-of-bounds read because the copied
extrada ...)
{DSA-6268-1}
- ffmpeg 7:8.1.1-1
[bookworm] - ffmpeg <not-affected> (Vulnerable code not present)
@@ -62062,7 +62366,7 @@ CVE-2026-47057 (Vulnerability in Oracle Java SE
(component: Scripting). Support
- openjdk-11 11.0.32+9-1
- openjdk-8 8u502-ga-1
NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
-CVE-2026-25832
+CVE-2026-25832 (In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS
1.3 cli ...)
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point
releases)
[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
@@ -403850,7 +404154,7 @@ CVE-2024-0684 (A flaw was found in the GNU coreutils
"split" program. A heap ove
NOTE: Fixed by:
https://github.com/coreutils/coreutils/commit/c4c5ed8f4e9cd55a12966d4f520e3a13101637d9
(v9.5)
CVE-2024-23175
NOT-FOR-US: MediaWiki extension FlexDiagrams
-CVE-2024-23176
+CVE-2024-23176 (An issue was discovered in the MassMessage extension in
MediaWiki befo ...)
NOT-FOR-US: MediaWiki extension MassMessage
CVE-2024-22819 (FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF)
vulnerability ...)
NOT-FOR-US: FlyCms
@@ -436961,9 +437265,9 @@ CVE-2023-36674 (An issue was discovered in MediaWiki
before 1.35.11, 1.36.x thro
[buster] - mediawiki <not-affected> (BadFileLookup was introduced in
version 1.35)
NOTE: https://phabricator.wikimedia.org/T335612
NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/934571/
-CVE-2023-37252
+CVE-2023-37252 (An issue was discovered in the CheckUser extension for
MediaWiki throu ...)
NOT-FOR-US: MediaWiki extension CheckUser
-CVE-2023-37253
+CVE-2023-37253 (An issue was discovered in the ProofreadPage extension for
MediaWiki t ...)
NOT-FOR-US: MediaWiki extension ProofreadPage
CVE-2023-3493 (Improper Neutralization of Formula Elements in a CSV File in
GitHub re ...)
NOT-FOR-US: fossbilling
@@ -448863,8 +449167,8 @@ CVE-2023-29379
RESERVED
CVE-2023-29378
RESERVED
-CVE-2023-29377
- RESERVED
+CVE-2023-29377 (An issue was discovered in Softing OPC UA C++ SDK through 6.20
and Sof ...)
+ TODO: check
CVE-2023-29376 (An issue was discovered in Progress Sitefinity 13.3 before
13.3.7647, ...)
NOT-FOR-US: Progress Sitefinity
CVE-2023-29375 (An issue was discovered in Progress Sitefinity 13.3 before
13.3.7647, ...)
@@ -453222,8 +453526,8 @@ CVE-2023-28150 (An issue was discovered in
Independentsoft JODF before 1.1.110.
NOT-FOR-US: Independentsoft
CVE-2023-28149 (An issue was discovered in the IhisiServiceSmm module in
Insyde Insyde ...)
NOT-FOR-US: Insyde
-CVE-2023-28148
- RESERVED
+CVE-2023-28148 (A bodyclass XSS issue was discovered in Paessler PRTG before
23.3.86.1 ...)
+ TODO: check
CVE-2023-28147 (An issue was discovered in the Arm Mali GPU Kernel Driver. A
non-privi ...)
NOT-FOR-US: ARM
CVE-2023-28146
@@ -464912,8 +465216,7 @@ CVE-2023-24293
RESERVED
CVE-2023-24292
RESERVED
-CVE-2023-24291 [A crafted save file can cause a buffer overrun in Simon
Tatham's Portable Puzzle Collection]
- RESERVED
+CVE-2023-24291 (Portable Puzzle Collection before 20230116.5782e29 was
discovered to c ...)
- sgt-puzzles 20230122.806ae71-1 (bug #1028986)
[bullseye] - sgt-puzzles 20191231.79a5378-3+deb11u1
[buster] - sgt-puzzles <end-of-life> (Games are not supported in LTS)
@@ -464921,33 +465224,27 @@ CVE-2023-24290
RESERVED
CVE-2023-24289
RESERVED
-CVE-2023-24288 [A crafted save file can cause a buffer overrun in Simon
Tatham's Portable Puzzle Collection]
- RESERVED
+CVE-2023-24288 (An issue in Portable Puzzle Collection before 20230116.5782e29
allows ...)
- sgt-puzzles 20230122.806ae71-1 (bug #1028986)
[bullseye] - sgt-puzzles 20191231.79a5378-3+deb11u1
[buster] - sgt-puzzles <end-of-life> (Games are not supported in LTS)
-CVE-2023-24287 [A crafted save file can cause a buffer overrun in the Undead
puzzle]
- RESERVED
+CVE-2023-24287 (Portable Puzzle Collection before 20230116.5782e29 was
discovered to c ...)
- sgt-puzzles 20230122.806ae71-1 (bug #1028986)
[bullseye] - sgt-puzzles 20191231.79a5378-3+deb11u1
[buster] - sgt-puzzles <end-of-life> (Games are not supported in LTS)
-CVE-2023-24286 [A crafted save file can cause a buffer overrun in the Mosaic
puzzle]
- RESERVED
+CVE-2023-24286 (Portable Puzzle Collection before 20230116.5782e29 was
discovered to c ...)
- sgt-puzzles 20230122.806ae71-1 (bug #1028986)
[bullseye] - sgt-puzzles <not-affected> (Vulnerable code introduced
later)
[buster] - sgt-puzzles <not-affected> (Vulnerable code introduced later)
-CVE-2023-24285 [A crafted save file can cause a buffer overrun in the Netslide
puzzle]
- RESERVED
+CVE-2023-24285 (Portable Puzzle Collection before 20230116.5782e29 was
discovered to c ...)
- sgt-puzzles 20230122.806ae71-1 (bug #1028986)
[bullseye] - sgt-puzzles 20191231.79a5378-3+deb11u1
[buster] - sgt-puzzles <end-of-life> (Games are not supported in LTS)
-CVE-2023-24284 [A crafted save file can cause a buffer overrun in the Guess
puzzle]
- RESERVED
+CVE-2023-24284 (Portable Puzzle Collection before 20230116.5782e29 was
discovered to c ...)
- sgt-puzzles 20230122.806ae71-1 (bug #1028986)
[bullseye] - sgt-puzzles 20191231.79a5378-3+deb11u1
[buster] - sgt-puzzles <end-of-life> (Games are not supported in LTS)
-CVE-2023-24283 [A crafted save file can cause a buffer overrun in the Guess
puzzle]
- RESERVED
+CVE-2023-24283 (Portable Puzzle Collection before 20230116.5782e29 was
discovered to c ...)
- sgt-puzzles 20230122.806ae71-1 (bug #1028986)
[bullseye] - sgt-puzzles 20191231.79a5378-3+deb11u1
[buster] - sgt-puzzles <end-of-life> (Games are not supported in LTS)
@@ -465520,10 +465817,10 @@ CVE-2023-24037
RESERVED
CVE-2023-24036
RESERVED
-CVE-2023-24035
- RESERVED
-CVE-2023-24034
- RESERVED
+CVE-2023-24035 (An issue was discovered in Nagios XI before 5.9.3. The
is_insecure_log ...)
+ TODO: check
+CVE-2023-24034 (An issue was discovered in twilio_ajax_handler.php in Nagios
XI before ...)
+ TODO: check
CVE-2023-24033 (The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980,
Exynos 1 ...)
NOT-FOR-US: Samsung
CVE-2023-24032 (In Zimbra Collaboration Suite through 9.0 and 8.8.15, an
attacker (who ...)
@@ -470234,10 +470531,10 @@ CVE-2014-125040 (A vulnerability was found in
stevejagodzinski DevNewsAggregator
NOT-FOR-US: stevejagodzinski DevNewsAggregator
CVE-2007-10001 (A vulnerability classified as problematic has been found in
web-cyradm ...)
NOT-FOR-US: web-cyradm
-CVE-2023-22632
- RESERVED
-CVE-2023-22631
- RESERVED
+CVE-2023-22632 (PRTG Network Monitor before 23.1.82 allows remote attackers to
write t ...)
+ TODO: check
+CVE-2023-22631 (PRTG Network Monitor before 23.1.82 allows remote attackers to
write t ...)
+ TODO: check
CVE-2023-22630 (IzyBat Orange casiers before 20221102_1 allows SQL Injection
via a get ...)
NOT-FOR-US: IzyBat Orange casiers
CVE-2023-22629 (An issue was discovered in TitanFTP through 1.94.1205. The
move-file f ...)
@@ -480705,7 +481002,7 @@ CVE-2022-45594
RESERVED
CVE-2022-45593
RESERVED
-CVE-2023-34854 [Authenticated remote code execution via backup/restore in
HotelDruid]
+CVE-2023-34854 (HotelDruid before 3.0.6 has insufficient file upload
sanitation in the ...)
- hoteldruid 3.0.6-1
[bookworm] - hoteldruid <no-dsa> (Minor issue)
[bullseye] - hoteldruid <no-dsa> (Minor issue)
@@ -491436,8 +491733,8 @@ CVE-2022-3500 (A vulnerability was found in keylime.
This security issue happens
NOT-FOR-US: keylime
CVE-2022-42918
RESERVED
-CVE-2022-42917
- RESERVED
+CVE-2022-42917 (In FRRouting FRR before 8.5, the service user (usually frr)
can escala ...)
+ TODO: check
CVE-2022-42916 (In curl before 7.86.0, the HSTS check could be bypassed to
trick it in ...)
- curl 7.86.0-1
[bullseye] - curl <ignored> (curl is not built with HSTS support)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9dd92820f0feb10c06e02dc806898f8d4f11db6f
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9dd92820f0feb10c06e02dc806898f8d4f11db6f
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits