[Secure-testing-commits] r41919 - data/CVE
security tracker role
sectracker at moszumanska.debian.org
Fri May 20 21:10:11 UTC 2016
Author: sectracker
Date: 2016-05-20 21:10:11 +0000 (Fri, 20 May 2016)
New Revision: 41919
Modified:
data/CVE/list
Log:
automatic update
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2016-05-20 21:03:37 UTC (rev 41918)
+++ data/CVE/list 2016-05-20 21:10:11 UTC (rev 41919)
@@ -2574,8 +2574,7 @@
- imlib2 1.4.8-1 (bug #785369)
NOTE: https://git.enlightenment.org/legacy/imlib2.git/commit/?id=37a96801663b7b4cd3fbe56cc0eb8b6a17e766a8
NOTE: http://www.openwall.com/lists/oss-security/2016/04/09/6
-CVE-2016-4070 [Integer overflow in php_raw_url_encode]
- RESERVED
+CVE-2016-4070 (** DISPUTED ** Integer overflow in the php_raw_url_encode function in ...)
{DSA-3560-1}
- php7.0 7.0.5-1
- php5 5.6.20+dfsg-1
@@ -2583,8 +2582,7 @@
NOTE: https://bugs.php.net/bug.php?id=71798
NOTE: https://git.php.net/?p=php-src.git;a=commit;h=95433e8e339dbb6b5d5541473c1661db6ba2c451
NOTE: http://www.openwall.com/lists/oss-security/2016/04/11/7
-CVE-2016-4071 [Format string vulnerability in php_snmp_error()]
- RESERVED
+CVE-2016-4071 (Format string vulnerability in the php_snmp_error function in ...)
{DSA-3560-1}
- php7.0 7.0.5-1
- php5 5.6.20+dfsg-1
@@ -2592,8 +2590,7 @@
NOTE: https://bugs.php.net/bug.php?id=71704
NOTE: https://git.php.net/?p=php-src.git;a=commit;h=6e25966544fb1d2f3d7596e060ce9c9269bbdcf8
NOTE: http://www.openwall.com/lists/oss-security/2016/04/11/7
-CVE-2016-4072 [Invalid memory write in phar on filename containing \0 inside name]
- RESERVED
+CVE-2016-4072 (The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x ...)
{DSA-3560-1}
- php7.0 7.0.5-1
- php5 5.6.20+dfsg-1
@@ -2602,8 +2599,7 @@
NOTE: https://gist.github.com/smalyshev/80b5c2909832872f2ba2
NOTE: https://git.php.net/?p=php-src.git;a=commit;h=1e9b175204e3286d64dfd6c9f09151c31b5e099a
NOTE: http://www.openwall.com/lists/oss-security/2016/04/11/7
-CVE-2016-4073 [Negative size parameter in memcpy]
- RESERVED
+CVE-2016-4073 (Multiple integer overflows in the mbfl_strcut function in ...)
{DSA-3560-1}
- php7.0 7.0.5-1
- php5 5.6.20+dfsg-1
@@ -2729,8 +2725,7 @@
- tiff3 <removed> (unimportant)
NOTE: src:tiff3: built binary packages do not contain the TIFF tools
NOTE: http://bugzilla.maptools.org/show_bug.cgi?id=2545
-CVE-2015-8865 [Buffer over-write in finfo_open with malformed magic file]
- RESERVED
+CVE-2015-8865 (The file_check_mem function in funcs.c in file before 5.23, as used in ...)
{DSA-3560-1 DLA-460-1}
- php7.0 7.0.5-1
- php5 5.6.20+dfsg-1
@@ -9156,146 +9151,146 @@
RESERVED
CVE-2016-1860
RESERVED
-CVE-2016-1859
- RESERVED
-CVE-2016-1858
- RESERVED
-CVE-2016-1857
- RESERVED
-CVE-2016-1856
- RESERVED
-CVE-2016-1855
- RESERVED
-CVE-2016-1854
- RESERVED
-CVE-2016-1853
- RESERVED
-CVE-2016-1852
- RESERVED
-CVE-2016-1851
- RESERVED
-CVE-2016-1850
- RESERVED
-CVE-2016-1849
- RESERVED
-CVE-2016-1848
- RESERVED
-CVE-2016-1847
- RESERVED
-CVE-2016-1846
- RESERVED
+CVE-2016-1859 (The WebKit Canvas implementation in Apple iOS before 9.3.2, Safari ...)
+ TODO: check
+CVE-2016-1858 (WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and ...)
+ TODO: check
+CVE-2016-1857 (WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and ...)
+ TODO: check
+CVE-2016-1856 (WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and ...)
+ TODO: check
+CVE-2016-1855 (WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and ...)
+ TODO: check
+CVE-2016-1854 (WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and ...)
+ TODO: check
+CVE-2016-1853 (Tcl in Apple OS X before 10.11.5 allows remote attackers to obtain ...)
+ TODO: check
+CVE-2016-1852 (Siri in Apple iOS before 9.3.2 does not block data detectors within ...)
+ TODO: check
+CVE-2016-1851 (The Screen Lock feature in Apple OS X before 10.11.5 mishandles ...)
+ TODO: check
+CVE-2016-1850 (SceneKit in Apple OS X before 10.11.5 allows remote attackers to ...)
+ TODO: check
+CVE-2016-1849 (The "Clear History and Website Data" feature in Apple Safari before ...)
+ TODO: check
+CVE-2016-1848 (QuickTime in Apple OS X before 10.11.5 allows remote attackers to ...)
+ TODO: check
+CVE-2016-1847 (OpenGL, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+ TODO: check
+CVE-2016-1846 (The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 ...)
+ TODO: check
CVE-2016-1845
RESERVED
-CVE-2016-1844
- RESERVED
-CVE-2016-1843
- RESERVED
-CVE-2016-1842
- RESERVED
-CVE-2016-1841
- RESERVED
-CVE-2016-1840
- RESERVED
-CVE-2016-1839
- RESERVED
-CVE-2016-1838
- RESERVED
-CVE-2016-1837
- RESERVED
-CVE-2016-1836
- RESERVED
-CVE-2016-1835
- RESERVED
-CVE-2016-1834
- RESERVED
-CVE-2016-1833
- RESERVED
-CVE-2016-1832
- RESERVED
-CVE-2016-1831
- RESERVED
-CVE-2016-1830
- RESERVED
-CVE-2016-1829
- RESERVED
-CVE-2016-1828
- RESERVED
-CVE-2016-1827
- RESERVED
-CVE-2016-1826
- RESERVED
-CVE-2016-1825
- RESERVED
-CVE-2016-1824
- RESERVED
-CVE-2016-1823
- RESERVED
-CVE-2016-1822
- RESERVED
-CVE-2016-1821
- RESERVED
-CVE-2016-1820
- RESERVED
-CVE-2016-1819
- RESERVED
-CVE-2016-1818
- RESERVED
-CVE-2016-1817
- RESERVED
-CVE-2016-1816
- RESERVED
-CVE-2016-1815
- RESERVED
-CVE-2016-1814
- RESERVED
-CVE-2016-1813
- RESERVED
-CVE-2016-1812
- RESERVED
-CVE-2016-1811
- RESERVED
-CVE-2016-1810
- RESERVED
-CVE-2016-1809
- RESERVED
-CVE-2016-1808
- RESERVED
-CVE-2016-1807
- RESERVED
-CVE-2016-1806
- RESERVED
-CVE-2016-1805
- RESERVED
-CVE-2016-1804
- RESERVED
-CVE-2016-1803
- RESERVED
-CVE-2016-1802
- RESERVED
-CVE-2016-1801
- RESERVED
-CVE-2016-1800
- RESERVED
-CVE-2016-1799
- RESERVED
-CVE-2016-1798
- RESERVED
-CVE-2016-1797
- RESERVED
-CVE-2016-1796
- RESERVED
-CVE-2016-1795
- RESERVED
-CVE-2016-1794
- RESERVED
-CVE-2016-1793
- RESERVED
-CVE-2016-1792
- RESERVED
-CVE-2016-1791
- RESERVED
-CVE-2016-1790
- RESERVED
+CVE-2016-1844 (The Messages component in Apple OS X before 10.11.5 mishandles roster ...)
+ TODO: check
+CVE-2016-1843 (The Messages component in Apple OS X before 10.11.5 mishandles ...)
+ TODO: check
+CVE-2016-1842 (MapKit in Apple iOS before 9.3.2, OS X before 10.11.5, and watchOS ...)
+ TODO: check
+CVE-2016-1841 (libxslt, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+ TODO: check
+CVE-2016-1840 (libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+ TODO: check
+CVE-2016-1839 (libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+ TODO: check
+CVE-2016-1838 (libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+ TODO: check
+CVE-2016-1837 (libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+ TODO: check
+CVE-2016-1836 (libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+ TODO: check
+CVE-2016-1835 (libxml2, as used in Apple iOS before 9.3.2 and OS X before 10.11.5, ...)
+ TODO: check
+CVE-2016-1834 (libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+ TODO: check
+CVE-2016-1833 (libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+ TODO: check
+CVE-2016-1832 (libc in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before ...)
+ TODO: check
+CVE-2016-1831 (The kernel in Apple iOS before 9.3.2 and OS X before 10.11.5 allows ...)
+ TODO: check
+CVE-2016-1830 (The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before ...)
+ TODO: check
+CVE-2016-1829 (The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before ...)
+ TODO: check
+CVE-2016-1828 (The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before ...)
+ TODO: check
+CVE-2016-1827 (The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before ...)
+ TODO: check
+CVE-2016-1826 (Integer overflow in the dtrace implementation in the kernel in Apple ...)
+ TODO: check
+CVE-2016-1825 (IOHIDFamily in Apple OS X before 10.11.5 allows attackers to execute ...)
+ TODO: check
+CVE-2016-1824 (IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+ TODO: check
+CVE-2016-1823 (IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+ TODO: check
+CVE-2016-1822 (IOFireWireFamily in Apple OS X before 10.11.5 allows attackers to ...)
+ TODO: check
+CVE-2016-1821 (IOAudioFamily in Apple OS X before 10.11.5 allows attackers to execute ...)
+ TODO: check
+CVE-2016-1820 (Buffer overflow in IOAudioFamily in Apple OS X before 10.11.5 allows ...)
+ TODO: check
+CVE-2016-1819 (IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, ...)
+ TODO: check
+CVE-2016-1818 (IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, ...)
+ TODO: check
+CVE-2016-1817 (IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, ...)
+ TODO: check
+CVE-2016-1816 (IOAcceleratorFamily in Apple OS X before 10.11.5 allows attackers to ...)
+ TODO: check
+CVE-2016-1815 (IOAcceleratorFamily in Apple OS X before 10.11.5 allows attackers to ...)
+ TODO: check
+CVE-2016-1814 (IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, ...)
+ TODO: check
+CVE-2016-1813 (IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, ...)
+ TODO: check
+CVE-2016-1812 (Buffer overflow in Intel Graphics Driver in Apple OS X before 10.11.5 ...)
+ TODO: check
+CVE-2016-1811 (ImageIO in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before ...)
+ TODO: check
+CVE-2016-1810 (The Graphics Drivers subsystem in Apple OS X before 10.11.5 allows ...)
+ TODO: check
+CVE-2016-1809 (Disk Utility in Apple OS X before 10.11.5 uses incorrect encryption ...)
+ TODO: check
+CVE-2016-1808 (The Disk Images subsystem in Apple iOS before 9.3.2, OS X before ...)
+ TODO: check
+CVE-2016-1807 (Race condition in the Disk Images subsystem in Apple iOS before 9.3.2, ...)
+ TODO: check
+CVE-2016-1806 (Crash Reporter in Apple OS X before 10.11.5 allows attackers to ...)
+ TODO: check
+CVE-2016-1805 (CoreStorage in Apple OS X before 10.11.5 allows attackers to execute ...)
+ TODO: check
+CVE-2016-1804 (The Multi-Touch subsystem in Apple OS X before 10.11.5 allows ...)
+ TODO: check
+CVE-2016-1803 (CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+ TODO: check
+CVE-2016-1802 (CCCrypt in CommonCrypto in Apple iOS before 9.3.2, OS X before ...)
+ TODO: check
+CVE-2016-1801 (The CFNetwork Proxies subsystem in Apple iOS before 9.3.2, OS X before ...)
+ TODO: check
+CVE-2016-1800 (Captive Network Assistant in Apple OS X before 10.11.5 mishandles a ...)
+ TODO: check
+CVE-2016-1799 (Audio in Apple OS X before 10.11.5 allows attackers to execute ...)
+ TODO: check
+CVE-2016-1798 (Audio in Apple OS X before 10.11.5 allows attackers to cause a denial ...)
+ TODO: check
+CVE-2016-1797 (Apple Type Services (ATS) in Apple OS X before 10.11.5 allows ...)
+ TODO: check
+CVE-2016-1796 (Apple Type Services (ATS) in Apple OS X before 10.11.5 allows ...)
+ TODO: check
+CVE-2016-1795 (AppleGraphicsPowerManagement in Apple OS X before 10.11.5 allows ...)
+ TODO: check
+CVE-2016-1794 (AppleGraphicsControl in Apple OS X before 10.11.5 allows attackers to ...)
+ TODO: check
+CVE-2016-1793 (AppleGraphicsControl in Apple OS X before 10.11.5 allows attackers to ...)
+ TODO: check
+CVE-2016-1792 (The AMD subsystem in Apple OS X before 10.11.5 allows attackers to ...)
+ TODO: check
+CVE-2016-1791 (The AMD subsystem in Apple OS X before 10.11.5 allows attackers to ...)
+ TODO: check
+CVE-2016-1790 (Buffer overflow in the Accessibility component in Apple iOS before ...)
+ TODO: check
CVE-2016-1789 (Apple iBooks Author before 2.4.1 allows remote attackers to read ...)
TODO: check
CVE-2016-1788 (Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS ...)
@@ -9395,8 +9390,8 @@
TODO: check
CVE-2016-1743 (The Intel driver in the Graphics Drivers subsystem in Apple OS X ...)
TODO: check
-CVE-2016-1742
- RESERVED
+CVE-2016-1742 (Untrusted search path vulnerability in the installer in Apple iTunes ...)
+ TODO: check
CVE-2016-1741 (The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X ...)
TODO: check
CVE-2016-1740 (FontParser in Apple iOS before 9.3, OS X before 10.11.4, tvOS before ...)
More information about the Secure-testing-commits
mailing list