Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
9dd92820 by security tracker role at 2026-09-14T07:12:50+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,307 @@
+CVE-2026-90691 (A security vulnerability has been detected in 0x4m4 HexStrike 
AI up to ...)
+       TODO: check
+CVE-2026-90690 (A weakness has been identified in 0x4m4 HexStrike AI up to 
d689933ff57 ...)
+       TODO: check
+CVE-2026-90689 (A security flaw has been discovered in Tenda W20E 
15.11.0.61068_1546_8 ...)
+       TODO: check
+CVE-2026-90688 (A vulnerability was identified in Tenda W20E 
15.11.0.61068_1546_841_CN ...)
+       TODO: check
+CVE-2026-90687 (A vulnerability was determined in GPAC up to f1219cde. This 
vulnerabil ...)
+       TODO: check
+CVE-2026-90686 (A vulnerability was found in GPAC up to f1219cde. This affects 
the fun ...)
+       TODO: check
+CVE-2026-90685 (A vulnerability has been found in GPAC up to f1219cde. 
Affected by thi ...)
+       TODO: check
+CVE-2026-90684 (A flaw has been found in GPAC up to f1219cde. Affected by this 
vulnera ...)
+       TODO: check
+CVE-2026-90683 (A vulnerability was detected in GPAC up to f1219cde. Affected 
is the f ...)
+       TODO: check
+CVE-2026-90682 (A security vulnerability has been detected in Matthias-Wandel 
jhead up ...)
+       TODO: check
+CVE-2026-90681 (A weakness has been identified in Matthias-Wandel jhead up to 
3.3. Thi ...)
+       TODO: check
+CVE-2026-90680 (A security flaw has been discovered in D-Link DIR-823G 
1.0.2B05_201812 ...)
+       TODO: check
+CVE-2026-90623 (A weakness has been identified in andreashappe cochise up to 
0.4.1. Af ...)
+       TODO: check
+CVE-2026-90622 (A security flaw has been discovered in GNU libredwg 0.13.4. 
This impac ...)
+       TODO: check
+CVE-2026-90621 (A vulnerability was identified in ipa-lab HackingBuddyGPT up 
to 0.5.0. ...)
+       TODO: check
+CVE-2026-90620 (A vulnerability was determined in 0x4m4 HexStrike AI up to 
d689933ff57 ...)
+       TODO: check
+CVE-2026-90619 (A vulnerability has been found in 0x4m4 HexStrike AI up to 
d689933ff57 ...)
+       TODO: check
+CVE-2026-90618 (A flaw has been found in GH05TCREW PentestAgent up to 
cf882dabea3ed91c ...)
+       TODO: check
+CVE-2026-90617 (A vulnerability was detected in GH05TCREW PentestAgent up to 
cf882dabe ...)
+       TODO: check
+CVE-2026-90615 (A security vulnerability has been detected in SourceCodester 
Class and ...)
+       TODO: check
+CVE-2026-90614 (A weakness has been identified in FedML-AI FedML up to 0.9.6. 
Affected ...)
+       TODO: check
+CVE-2026-90613 (A security flaw has been discovered in GPAC up to f1219cde. 
Affected b ...)
+       TODO: check
+CVE-2026-90612 (A vulnerability was identified in GPAC up to f1219cde. 
Affected is the ...)
+       TODO: check
+CVE-2026-90611 (A vulnerability was determined in GPAC up to f1219cde. This 
impacts th ...)
+       TODO: check
+CVE-2026-90610 (A vulnerability was found in GPAC up to f1219cde. This affects 
the fun ...)
+       TODO: check
+CVE-2026-90609 (A vulnerability has been found in GPAC up to f1219cde. The 
impacted el ...)
+       TODO: check
+CVE-2026-90608 (A flaw has been found in Totolink A3002MU Hh-B20211125.1046. 
The affec ...)
+       TODO: check
+CVE-2026-90607 (A vulnerability was detected in Totolink A3002MU 
Hh-B20211125.1046. Im ...)
+       TODO: check
+CVE-2026-90606 (A security vulnerability has been detected in Totolink A3002MU 
Hh-B202 ...)
+       TODO: check
+CVE-2026-90605 (A weakness has been identified in Totolink A3002MU 
Hh-B20211125.1046.  ...)
+       TODO: check
+CVE-2026-90604 (A security flaw has been discovered in Totolink A3002MU 
Hh-B20211125.1 ...)
+       TODO: check
+CVE-2026-90603 (A vulnerability was identified in Anil-matcha 
Open-Generative-AI up to ...)
+       TODO: check
+CVE-2026-90602 (A vulnerability was determined in Anil-matcha 
Open-Generative-AI up to ...)
+       TODO: check
+CVE-2026-90601 (A vulnerability was found in getzep graphiti up to 0.30.2. 
Affected is ...)
+       TODO: check
+CVE-2026-90600 (A vulnerability has been found in itsourcecode Sales and 
Inventory Sys ...)
+       TODO: check
+CVE-2026-90599 (A flaw has been found in Rizwan17 inventory-management-system 
up to 5e ...)
+       TODO: check
+CVE-2026-90598 (A vulnerability was detected in jaygajera17 
E-commerce-project-springB ...)
+       TODO: check
+CVE-2026-90597 (A security vulnerability has been detected in itsourcecode 
Sales and I ...)
+       TODO: check
+CVE-2026-90596 (A weakness has been identified in embedded-graphics up to 
0.8.2 on 32- ...)
+       TODO: check
+CVE-2026-90595 (A security flaw has been discovered in wxiaoqi 
Spring-Cloud-Platform 1 ...)
+       TODO: check
+CVE-2026-90594 (A vulnerability was identified in wxiaoqi 
Spring-Cloud-Platform 3.0.1/ ...)
+       TODO: check
+CVE-2026-90593 (A vulnerability was determined in embedded-graphics up to 
0.8.2. This  ...)
+       TODO: check
+CVE-2026-90584 (A weakness has been identified in TooTallNate Java-WebSocket 
up to 1.6 ...)
+       TODO: check
+CVE-2026-90583 (A security flaw has been discovered in kagisearch smallweb up 
to 0ecb9 ...)
+       TODO: check
+CVE-2026-90582 (A vulnerability was identified in evanchiu serverless-todo 
1.0.3/2.0.0 ...)
+       TODO: check
+CVE-2026-90581 (A vulnerability was determined in cym1102 nginxWebUI up to 
4.4.2. This ...)
+       TODO: check
+CVE-2026-90580 (A vulnerability was found in FlowiseAI Flowise up to 3.0.2. 
This vulne ...)
+       TODO: check
+CVE-2026-89050 (The Quads Ads Manager for Google AdSense WordPress plugin 
before 3.0.5 ...)
+       TODO: check
+CVE-2026-88853 (Joomla Extension - regularlabs.com - Privileged stored XSS via 
event h ...)
+       TODO: check
+CVE-2026-88852 (Joomla Extension - regularlabs.com - Privileged stored XSS via 
url opt ...)
+       TODO: check
+CVE-2026-88802 (The MDJM Event Management WordPress plugin before 1.7.8.5 and 
the Mobi ...)
+       TODO: check
+CVE-2026-88793 (The YouTube Embed WordPress plugin from 10.0 to 10.3 does not 
perform  ...)
+       TODO: check
+CVE-2026-85196 (Joomla Extension - regularlabs.com - Reflected XSS in Articles 
Anywher ...)
+       TODO: check
+CVE-2026-85195 (Joomla Extension - regularlabs.com - Privileged stored XSS via 
link op ...)
+       TODO: check
+CVE-2026-85192 (Joomla Extension - regularlabs.com - Authenticated, privileged 
remote  ...)
+       TODO: check
+CVE-2026-85191 (Joomla Extension - regularlabs.com - Privileged stored XSS via 
rtla-al ...)
+       TODO: check
+CVE-2026-85190 (Joomla Extension - regularlabs.com - Privileged stored XSS via 
class o ...)
+       TODO: check
+CVE-2026-85189 (Joomla Extension - regularlabs.com - Privileged stored XSS via 
executa ...)
+       TODO: check
+CVE-2026-85188 (Joomla Extension - regularlabs.com - Database data disclosure 
in Advan ...)
+       TODO: check
+CVE-2026-85129 (The Hoo Companion WordPress plugin 1.0.2 does not have any 
authorisati ...)
+       TODO: check
+CVE-2026-85125 (The Android application "YAMAP -Social Trekking GPS App" 
contains an i ...)
+       TODO: check
+CVE-2026-82796 (SolarView Compact contains a cross-site scripting 
vulnerability in Ima ...)
+       TODO: check
+CVE-2026-82795 (SolarView Compact contains a cross-site scripting 
vulnerability in Sch ...)
+       TODO: check
+CVE-2026-82794 (SolarView Compact contains an OS command Injection 
vulnerability in in ...)
+       TODO: check
+CVE-2026-82793 (Unrestricted upload of file with dangerous type issue exists 
in Contec ...)
+       TODO: check
+CVE-2026-82792 (Cross-site scripting vulnerability exists in Contec CAN 2.0B 
Communica ...)
+       TODO: check
+CVE-2026-82791 (Improper neutralization of special elements used in an OS 
command ('OS ...)
+       TODO: check
+CVE-2026-82790 (Cross-site scripting vulnerability exists in PC-HELPER 
Wireless I/O DI ...)
+       TODO: check
+CVE-2026-82789 (An improper neutralization of directives in dynamically 
evaluated code ...)
+       TODO: check
+CVE-2026-82788 (Cross-site scripting vulnerability exists in CPSL-08P1EN. If 
this vuln ...)
+       TODO: check
+CVE-2026-82787 (Missing authentication for critical function vulnerability 
exists in C ...)
+       TODO: check
+CVE-2026-82786 (Insufficiently protected credentials issue exists in Remote 
I/O Couple ...)
+       TODO: check
+CVE-2026-82785 (Stack-based buffer overflow vulnerability exists in Remote I/O 
Coupler ...)
+       TODO: check
+CVE-2026-82784 (Missing authentication for critical function vulnerability 
exists in R ...)
+       TODO: check
+CVE-2026-82783 (Plaintext storage of a password issue exists in CONPROSYS nano 
Series  ...)
+       TODO: check
+CVE-2026-82782 (Out-of-bounds write vulnerability exists in CONPROSYS nano 
Series. Rec ...)
+       TODO: check
+CVE-2026-82781 (Cross-site scripting vulnerability exists in CONPROSYS nano 
Series. If ...)
+       TODO: check
+CVE-2026-82780 (Unrestricted upload of file with dangerous type issue exists 
in CONPRO ...)
+       TODO: check
+CVE-2026-82779 (Improper neutralization of special elements used in an OS 
command ('OS ...)
+       TODO: check
+CVE-2026-82778 (An exposure of information through directory listing issue 
exists in C ...)
+       TODO: check
+CVE-2026-82777 (Improper neutralization of special elements used in an OS 
command ('OS ...)
+       TODO: check
+CVE-2026-82776 (Cross-site scripting vulnerability exists in CONPROSYS PAC 
Series. If  ...)
+       TODO: check
+CVE-2026-82775 (An exposure of information through directory listing issue 
exists in C ...)
+       TODO: check
+CVE-2026-82774 (Improper neutralization of special elements used in an OS 
command ('OS ...)
+       TODO: check
+CVE-2026-82773 (Cross-site scripting vulnerability exists in CONPROSYS M2M 
Gateway Ser ...)
+       TODO: check
+CVE-2026-82772 (Buffer overflow vulnerability exists in Contec EC1000 series. 
If a rem ...)
+       TODO: check
+CVE-2026-82771 (Cross-site scripting vulnerability exists in Contec EC1000 
series. If  ...)
+       TODO: check
+CVE-2026-82770 (Buffer overflow vulnerability exists in Contec RP-WAH-SR 
Series. If a  ...)
+       TODO: check
+CVE-2026-82769 (Cross-site scripting vulnerability exists in Contec RP-WAH-SR 
Series.  ...)
+       TODO: check
+CVE-2026-82768 (Path traversal vulnerability exists in SGA1000. If this 
vulnerability  ...)
+       TODO: check
+CVE-2026-82767 (Cross-site scripting vulnerability exists in SGA1000. If this 
vulnerab ...)
+       TODO: check
+CVE-2026-82766 (Improper neutralization of special elements used in an OS 
command ('OS ...)
+       TODO: check
+CVE-2026-82765 (Path traversal vulnerability exists in Contec FX5000 series, 
FX4000 se ...)
+       TODO: check
+CVE-2026-82764 (Cross-site request forgery vulnerability exists in multiple 
Contec pro ...)
+       TODO: check
+CVE-2026-82763 (Cross-site scripting vulnerability exists in Contec FX5000 
series, FX4 ...)
+       TODO: check
+CVE-2026-82762 (Improper neutralization of special elements used in an OS 
command ('OS ...)
+       TODO: check
+CVE-2026-81648 (The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 
does no ...)
+       TODO: check
+CVE-2026-74933 (The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not 
have au ...)
+       TODO: check
+CVE-2026-68955 (The installer for Rakuten Kobo Desktop Application (Windows 
version) i ...)
+       TODO: check
+CVE-2026-52297 (FFmpeg before 9.0 has an out-of-bounds read because there is 
insuffici ...)
+       TODO: check
+CVE-2026-52296 (FFmpeg before 9.0 has an out-of-bounds read because of missing 
require ...)
+       TODO: check
+CVE-2026-49030
+       REJECTED
+CVE-2026-38924 (In Oraios AI Serena before 1.0.0, the listen address of the 
MCP server ...)
+       TODO: check
+CVE-2026-38332 (TinyEXIF before 1.1.0 has a heap-based buffer over-read in 
EntryParser ...)
+       TODO: check
+CVE-2026-37008 (CrewAI before fb2323b offers a Python blocklist approach that 
operates ...)
+       TODO: check
+CVE-2026-36989 (A SQL Injection vulnerability exists in LuxSoft LuxCal through 
5.3.4L  ...)
+       TODO: check
+CVE-2026-36453 (Rhymix before 2.1.31 allows insecure direct object reference, 
aka RVE- ...)
+       TODO: check
+CVE-2026-35867 (A Command Injection vulnerability exists in the 
bs_SetLimitCli_info fu ...)
+       TODO: check
+CVE-2026-33970 (An issue was discovered in NR RRC and L2 in Samsung Mobile 
Processor,  ...)
+       TODO: check
+CVE-2026-33968 (An issue was discovered in camera in Samsung Mobile Processor 
Exynos 1 ...)
+       TODO: check
+CVE-2026-33967 (An issue was discovered in camera in Samsung Mobile Processor 
Exynos 1 ...)
+       TODO: check
+CVE-2026-33966 (An issue was discovered in camera in Samsung Mobile Processor 
Exynos 1 ...)
+       TODO: check
+CVE-2026-33964 (An issue was discovered in camera in Samsung Mobile Processor 
Exynos 1 ...)
+       TODO: check
+CVE-2026-33963 (An issue was discovered in camera in Samsung Mobile Processor 
Exynos 1 ...)
+       TODO: check
+CVE-2026-33962 (An issue was discovered in Wi-Fi in Samsung Mobile Processor 
Exynos 85 ...)
+       TODO: check
+CVE-2026-33960 (An issue was discovered in Samsung Mobile Processor and 
Wearable Proce ...)
+       TODO: check
+CVE-2026-33957 (An issue was discovered in CustOS Driver in Samsung Mobile 
Processor E ...)
+       TODO: check
+CVE-2026-33956 (An issue was discovered in camera in Samsung Mobile Processor 
Exynos 1 ...)
+       TODO: check
+CVE-2026-31278 (An issue in the /api/v2/setting/adserversetting endpoint of 
Suprema Bi ...)
+       TODO: check
+CVE-2026-29812 (CyberPanel before 2.4.4 has no logging for actions that could 
potentia ...)
+       TODO: check
+CVE-2026-29811 (CyberPanel before 2.4.4 attempts to detect an "alais" domain 
(i.e., a  ...)
+       TODO: check
+CVE-2026-29810 (CyberPanel before 2.4.4 omits a "return 0" that is required by 
the bus ...)
+       TODO: check
+CVE-2026-23793 (An issue was discovered in Samsung Mobile Processor Exynos 
1330, 1380, ...)
+       TODO: check
+CVE-2026-23792 (An issue was discovered in NR RRC in Samsung Mobile Processor 
and Mode ...)
+       TODO: check
+CVE-2026-23791 (An issue was discovered in DPU in Samsung Mobile Processor 
Exynos 1280 ...)
+       TODO: check
+CVE-2026-23790 (An issue was discovered in DPU in Samsung Mobile Processor 
Exynos 1280 ...)
+       TODO: check
+CVE-2026-23789 (An issue was discovered in MFC in Samsung Mobile Processor and 
Wearabl ...)
+       TODO: check
+CVE-2026-23788 (An issue was discovered in DPU in Samsung Mobile Processor 
Exynos 1280 ...)
+       TODO: check
+CVE-2026-23787 (An issue was discovered in DPU in Samsung Mobile Processor 
Exynos 1280 ...)
+       TODO: check
+CVE-2026-23786 (An issue was discovered in DPU in Samsung Mobile Processor 
Exynos 1280 ...)
+       TODO: check
+CVE-2026-16726 (Buffer overflow vulnerabilityin Panasonic IndustryUSB Driver 
for MINAS ...)
+       TODO: check
+CVE-2026-15892 (The mcumgr SMP settings-management group handlers 
settings_mgmt_read() ...)
+       TODO: check
+CVE-2026-15891 (The MQTT-SN client keepalive handler process_ping() in 
subsys/net/lib/ ...)
+       TODO: check
+CVE-2025-70820 (Zettlab D6 Ultra before 1.7.0 allows absolute path traversal 
to reach  ...)
+       TODO: check
+CVE-2025-68624 (N-able Mail Assure through April 2026 contains a design-level 
authoriz ...)
+       TODO: check
+CVE-2025-64031 (libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer 
overflow  ...)
+       TODO: check
+CVE-2025-63842 (A Cross-Site Scripting (XSS) vulnerability in the web backend 
for the  ...)
+       TODO: check
+CVE-2025-26790 (Withsecure Atlant with Capricorn engine before 2025-01-20_02 
allows a  ...)
+       TODO: check
+CVE-2024-53922 (An issue was discovered in the buffer queue driver in Samsung 
Automoti ...)
+       TODO: check
+CVE-2023-51769 (Frappe before 14.49.0 allows an XSS attack that is associated 
with blo ...)
+       TODO: check
+CVE-2023-50462 (An issue was discovered in the content_consent (aka Content 
Consent) e ...)
+       TODO: check
+CVE-2023-50461 (An issue was discovered in the direct_mail (aka Direct Mail) 
extension ...)
+       TODO: check
+CVE-2023-50460 (An issue was discovered in the femanager extension 7.x before 
7.2.3 fo ...)
+       TODO: check
+CVE-2023-50459 (An issue was discovered in the femanager extension 7.x before 
7.2.3 fo ...)
+       TODO: check
+CVE-2023-46273 (Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, 
and thro ...)
+       TODO: check
+CVE-2023-46035 (The svg_optimizer gem before 0.3.0 for Ruby performs entity 
expansion  ...)
+       TODO: check
+CVE-2023-45858 (A directory traversal was identified in Paessler PRTG before 
23.4.88.1 ...)
+       TODO: check
+CVE-2023-45023 (The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect 
Access  ...)
+       TODO: check
+CVE-2023-40772 (A directory Traversal vulnerability in DataEase before 1.18.10 
allows  ...)
+       TODO: check
+CVE-2023-37366 (An issue was discovered in Samsung Exynos Mobile Processor, 
Automotive ...)
+       TODO: check
+CVE-2023-32803 (The ca-certificates package before 
ca-certificates-2021.2.50-72 for Am ...)
+       TODO: check
+CVE-2023-32778 (An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. 
An atta ...)
+       TODO: check
 CVE-2026-90783 (MKVToolNix through 101.0 contains a heap buffer overflow in 
the bundle ...)
        - mkvtoolnix <unfixed> (bug #1147621)
        NOTE: Fixed by: 
https://codeberg.org/mbunkus/mkvtoolnix/commit/1495126138e086080f0163bee27fafbdf956a1d0
@@ -13715,7 +14019,7 @@ CVE-2026-55951 (The Erlang/OTP httpc HTTP client does 
not enforce a limit on the
 CVE-2026-53682 (An unauthenticated client can query the Security Domain hosts 
inventor ...)
        - dogtag-pki <removed>
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2487511
-CVE-2026-52295 (Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows 
an atta ...)
+CVE-2026-52295 (FFmpeg before 9.0 has an out-of-bounds read because the copied 
extrada ...)
        {DSA-6268-1}
        - ffmpeg 7:8.1.1-1
        [bookworm] - ffmpeg <not-affected> (Vulnerable code not present)
@@ -62062,7 +62366,7 @@ CVE-2026-47057 (Vulnerability in Oracle Java SE 
(component: Scripting).  Support
        - openjdk-11 11.0.32+9-1
        - openjdk-8 8u502-ga-1
        NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
-CVE-2026-25832
+CVE-2026-25832 (In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 
1.3 cli ...)
        - mbedtls 3.6.7-2
        [trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point 
releases)
        [bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
@@ -403850,7 +404154,7 @@ CVE-2024-0684 (A flaw was found in the GNU coreutils 
"split" program. A heap ove
        NOTE: Fixed by: 
https://github.com/coreutils/coreutils/commit/c4c5ed8f4e9cd55a12966d4f520e3a13101637d9
 (v9.5)
 CVE-2024-23175
        NOT-FOR-US: MediaWiki extension FlexDiagrams
-CVE-2024-23176
+CVE-2024-23176 (An issue was discovered in the MassMessage extension in 
MediaWiki befo ...)
        NOT-FOR-US: MediaWiki extension MassMessage
 CVE-2024-22819 (FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) 
vulnerability ...)
        NOT-FOR-US: FlyCms
@@ -436961,9 +437265,9 @@ CVE-2023-36674 (An issue was discovered in MediaWiki 
before 1.35.11, 1.36.x thro
        [buster] - mediawiki <not-affected> (BadFileLookup was introduced in 
version 1.35)
        NOTE: https://phabricator.wikimedia.org/T335612
        NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/934571/
-CVE-2023-37252
+CVE-2023-37252 (An issue was discovered in the CheckUser extension for 
MediaWiki throu ...)
        NOT-FOR-US: MediaWiki extension CheckUser
-CVE-2023-37253
+CVE-2023-37253 (An issue was discovered in the ProofreadPage extension for 
MediaWiki t ...)
        NOT-FOR-US: MediaWiki extension ProofreadPage
 CVE-2023-3493 (Improper Neutralization of Formula Elements in a CSV File in 
GitHub re ...)
        NOT-FOR-US: fossbilling
@@ -448863,8 +449167,8 @@ CVE-2023-29379
        RESERVED
 CVE-2023-29378
        RESERVED
-CVE-2023-29377
-       RESERVED
+CVE-2023-29377 (An issue was discovered in Softing OPC UA C++ SDK through 6.20 
and Sof ...)
+       TODO: check
 CVE-2023-29376 (An issue was discovered in Progress Sitefinity 13.3 before 
13.3.7647,  ...)
        NOT-FOR-US: Progress Sitefinity
 CVE-2023-29375 (An issue was discovered in Progress Sitefinity 13.3 before 
13.3.7647,  ...)
@@ -453222,8 +453526,8 @@ CVE-2023-28150 (An issue was discovered in 
Independentsoft JODF before 1.1.110.
        NOT-FOR-US: Independentsoft
 CVE-2023-28149 (An issue was discovered in the IhisiServiceSmm module in 
Insyde Insyde ...)
        NOT-FOR-US: Insyde
-CVE-2023-28148
-       RESERVED
+CVE-2023-28148 (A bodyclass XSS issue was discovered in Paessler PRTG before 
23.3.86.1 ...)
+       TODO: check
 CVE-2023-28147 (An issue was discovered in the Arm Mali GPU Kernel Driver. A 
non-privi ...)
        NOT-FOR-US: ARM
 CVE-2023-28146
@@ -464912,8 +465216,7 @@ CVE-2023-24293
        RESERVED
 CVE-2023-24292
        RESERVED
-CVE-2023-24291 [A crafted save file can cause a buffer overrun in Simon 
Tatham's Portable Puzzle Collection]
-       RESERVED
+CVE-2023-24291 (Portable Puzzle Collection before 20230116.5782e29 was 
discovered to c ...)
        - sgt-puzzles 20230122.806ae71-1 (bug #1028986)
        [bullseye] - sgt-puzzles 20191231.79a5378-3+deb11u1
        [buster] - sgt-puzzles <end-of-life> (Games are not supported in LTS)
@@ -464921,33 +465224,27 @@ CVE-2023-24290
        RESERVED
 CVE-2023-24289
        RESERVED
-CVE-2023-24288 [A crafted save file can cause a buffer overrun in Simon 
Tatham's Portable Puzzle Collection]
-       RESERVED
+CVE-2023-24288 (An issue in Portable Puzzle Collection before 20230116.5782e29 
allows  ...)
        - sgt-puzzles 20230122.806ae71-1 (bug #1028986)
        [bullseye] - sgt-puzzles 20191231.79a5378-3+deb11u1
        [buster] - sgt-puzzles <end-of-life> (Games are not supported in LTS)
-CVE-2023-24287 [A crafted save file can cause a buffer overrun in the Undead 
puzzle]
-       RESERVED
+CVE-2023-24287 (Portable Puzzle Collection before 20230116.5782e29 was 
discovered to c ...)
        - sgt-puzzles 20230122.806ae71-1 (bug #1028986)
        [bullseye] - sgt-puzzles 20191231.79a5378-3+deb11u1
        [buster] - sgt-puzzles <end-of-life> (Games are not supported in LTS)
-CVE-2023-24286 [A crafted save file can cause a buffer overrun in the Mosaic 
puzzle]
-       RESERVED
+CVE-2023-24286 (Portable Puzzle Collection before 20230116.5782e29 was 
discovered to c ...)
        - sgt-puzzles 20230122.806ae71-1 (bug #1028986)
        [bullseye] - sgt-puzzles <not-affected> (Vulnerable code introduced 
later)
        [buster] - sgt-puzzles <not-affected> (Vulnerable code introduced later)
-CVE-2023-24285 [A crafted save file can cause a buffer overrun in the Netslide 
puzzle]
-       RESERVED
+CVE-2023-24285 (Portable Puzzle Collection before 20230116.5782e29 was 
discovered to c ...)
        - sgt-puzzles 20230122.806ae71-1 (bug #1028986)
        [bullseye] - sgt-puzzles 20191231.79a5378-3+deb11u1
        [buster] - sgt-puzzles <end-of-life> (Games are not supported in LTS)
-CVE-2023-24284 [A crafted save file can cause a buffer overrun in the Guess 
puzzle]
-       RESERVED
+CVE-2023-24284 (Portable Puzzle Collection before 20230116.5782e29 was 
discovered to c ...)
        - sgt-puzzles 20230122.806ae71-1 (bug #1028986)
        [bullseye] - sgt-puzzles 20191231.79a5378-3+deb11u1
        [buster] - sgt-puzzles <end-of-life> (Games are not supported in LTS)
-CVE-2023-24283 [A crafted save file can cause a buffer overrun in the Guess 
puzzle]
-       RESERVED
+CVE-2023-24283 (Portable Puzzle Collection before 20230116.5782e29 was 
discovered to c ...)
        - sgt-puzzles 20230122.806ae71-1 (bug #1028986)
        [bullseye] - sgt-puzzles 20191231.79a5378-3+deb11u1
        [buster] - sgt-puzzles <end-of-life> (Games are not supported in LTS)
@@ -465520,10 +465817,10 @@ CVE-2023-24037
        RESERVED
 CVE-2023-24036
        RESERVED
-CVE-2023-24035
-       RESERVED
-CVE-2023-24034
-       RESERVED
+CVE-2023-24035 (An issue was discovered in Nagios XI before 5.9.3. The 
is_insecure_log ...)
+       TODO: check
+CVE-2023-24034 (An issue was discovered in twilio_ajax_handler.php in Nagios 
XI before ...)
+       TODO: check
 CVE-2023-24033 (The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, 
Exynos 1 ...)
        NOT-FOR-US: Samsung
 CVE-2023-24032 (In Zimbra Collaboration Suite through 9.0 and 8.8.15, an 
attacker (who ...)
@@ -470234,10 +470531,10 @@ CVE-2014-125040 (A vulnerability was found in 
stevejagodzinski DevNewsAggregator
        NOT-FOR-US: stevejagodzinski DevNewsAggregator
 CVE-2007-10001 (A vulnerability classified as problematic has been found in 
web-cyradm ...)
        NOT-FOR-US: web-cyradm
-CVE-2023-22632
-       RESERVED
-CVE-2023-22631
-       RESERVED
+CVE-2023-22632 (PRTG Network Monitor before 23.1.82 allows remote attackers to 
write t ...)
+       TODO: check
+CVE-2023-22631 (PRTG Network Monitor before 23.1.82 allows remote attackers to 
write t ...)
+       TODO: check
 CVE-2023-22630 (IzyBat Orange casiers before 20221102_1 allows SQL Injection 
via a get ...)
        NOT-FOR-US: IzyBat Orange casiers
 CVE-2023-22629 (An issue was discovered in TitanFTP through 1.94.1205. The 
move-file f ...)
@@ -480705,7 +481002,7 @@ CVE-2022-45594
        RESERVED
 CVE-2022-45593
        RESERVED
-CVE-2023-34854 [Authenticated remote code execution via backup/restore in 
HotelDruid]
+CVE-2023-34854 (HotelDruid before 3.0.6 has insufficient file upload 
sanitation in the ...)
        - hoteldruid 3.0.6-1
        [bookworm] - hoteldruid <no-dsa> (Minor issue)
        [bullseye] - hoteldruid <no-dsa> (Minor issue)
@@ -491436,8 +491733,8 @@ CVE-2022-3500 (A vulnerability was found in keylime. 
This security issue happens
        NOT-FOR-US: keylime
 CVE-2022-42918
        RESERVED
-CVE-2022-42917
-       RESERVED
+CVE-2022-42917 (In FRRouting FRR before 8.5, the service user (usually frr) 
can escala ...)
+       TODO: check
 CVE-2022-42916 (In curl before 7.86.0, the HSTS check could be bypassed to 
trick it in ...)
        - curl 7.86.0-1
        [bullseye] - curl <ignored> (curl is not built with HSTS support)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9dd92820f0feb10c06e02dc806898f8d4f11db6f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9dd92820f0feb10c06e02dc806898f8d4f11db6f
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to