[Secure-testing-commits] r44920 - data/CVE

security tracker role sectracker at moszumanska.debian.org
Mon Sep 26 21:10:12 UTC 2016


Author: sectracker
Date: 2016-09-26 21:10:12 +0000 (Mon, 26 Sep 2016)
New Revision: 44920

Modified:
   data/CVE/list
Log:
automatic update

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-09-26 20:25:30 UTC (rev 44919)
+++ data/CVE/list	2016-09-26 21:10:12 UTC (rev 44920)
@@ -1,3 +1,7 @@
+CVE-2016-1000244
+	RESERVED
+CVE-2016-1000243
+	RESERVED
 CVE-2016-7553 [Information disclosure vulnerability in buf.pl]
 	RESERVED
 	- irssi 0.8.20-2 (bug #838762)
@@ -2158,8 +2162,8 @@
 	NOTE: http://www.openwall.com/lists/oss-security/2016/09/25/2
 CVE-2016-7552
 	RESERVED
-CVE-2016-7549
-	RESERVED
+CVE-2016-7549 (Google Chrome before 53.0.2785.113 does not ensure that the recipient ...)
+	TODO: check
 CVE-2016-7548
 	RESERVED
 CVE-2016-7547
@@ -2523,6 +2527,7 @@
 	RESERVED
 CVE-2016-7401
 	RESERVED
+	{DSA-3678-1}
 	- python-django <not-affected> (Django 1.10 and the master development branch are not affected.)
 	[wheezy] - python-django <undetermined>
 	[jessie] - python-django 1.7.11-1+deb8u1
@@ -5203,10 +5208,10 @@
 	RESERVED
 CVE-2016-6533
 	RESERVED
-CVE-2016-6532
-	RESERVED
-CVE-2016-6531
-	RESERVED
+CVE-2016-6532 (DEXIS Imaging Suite 10 has a hardcoded password for the sa account, ...)
+	TODO: check
+CVE-2016-6531 (** DISPUTED ** Open Dental 16.1 and earlier has a hardcoded MySQL root ...)
+	TODO: check
 CVE-2016-6530 (Dentsply Sirona (formerly Schick) CDR Dicom 5 and earlier has default ...)
 	TODO: check
 CVE-2016-6529
@@ -5583,18 +5588,18 @@
 	TODO: check
 CVE-2016-6414 (iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 ...)
 	TODO: check
-CVE-2016-6413
-	RESERVED
-CVE-2016-6412
-	RESERVED
-CVE-2016-6411
-	RESERVED
-CVE-2016-6410
-	RESERVED
-CVE-2016-6409
-	RESERVED
-CVE-2016-6408
-	RESERVED
+CVE-2016-6413 (The installation procedure on Cisco Application Policy Infrastructure ...)
+	TODO: check
+CVE-2016-6412 (The Cisco Application-hosting Framework (CAF) component in Cisco IOS ...)
+	TODO: check
+CVE-2016-6411 (Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 ...)
+	TODO: check
+CVE-2016-6410 (The Cisco Application-hosting Framework (CAF) component in Cisco IOS ...)
+	TODO: check
+CVE-2016-6409 (The Data in Motion (DMo) component in Cisco IOS 15.6(1)T and IOS XE, ...)
+	TODO: check
+CVE-2016-6408 (Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files ...)
+	TODO: check
 CVE-2016-6407 (Cisco AsyncOS through 9.5.0-444 on Web Security Appliance (WSA) ...)
 	TODO: check
 CVE-2016-6406 (Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, ...)
@@ -7185,10 +7190,10 @@
 	RESERVED
 CVE-2016-5998
 	RESERVED
-CVE-2016-5997
-	RESERVED
-CVE-2016-5996
-	RESERVED
+CVE-2016-5997 (The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 ...)
+	TODO: check
+CVE-2016-5996 (The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 ...)
+	TODO: check
 CVE-2016-5995
 	RESERVED
 CVE-2016-5994
@@ -7223,24 +7228,24 @@
 	RESERVED
 CVE-2016-5979
 	RESERVED
-CVE-2016-5978
-	RESERVED
-CVE-2016-5977
-	RESERVED
-CVE-2016-5976
-	RESERVED
-CVE-2016-5975
-	RESERVED
-CVE-2016-5974
-	RESERVED
+CVE-2016-5978 (Cross-site scripting (XSS) vulnerability in the Web UI in the web ...)
+	TODO: check
+CVE-2016-5977 (Open redirect vulnerability in the web portal in IBM Tealeaf Customer ...)
+	TODO: check
+CVE-2016-5976 (The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 ...)
+	TODO: check
+CVE-2016-5975 (Cross-site scripting (XSS) vulnerability in the Web UI in the web ...)
+	TODO: check
+CVE-2016-5974 (Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security ...)
+	TODO: check
 CVE-2016-5973
 	RESERVED
-CVE-2016-5972
-	RESERVED
-CVE-2016-5971
-	RESERVED
-CVE-2016-5970
-	RESERVED
+CVE-2016-5972 (IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x ...)
+	TODO: check
+CVE-2016-5971 (IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x ...)
+	TODO: check
+CVE-2016-5970 (Directory traversal vulnerability in IBM Security Privileged Identity ...)
+	TODO: check
 CVE-2016-5969
 	RESERVED
 CVE-2016-5968
@@ -7253,8 +7258,8 @@
 	RESERVED
 CVE-2016-5964
 	RESERVED
-CVE-2016-5963
-	RESERVED
+CVE-2016-5963 (IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x ...)
+	TODO: check
 CVE-2016-5962
 	RESERVED
 CVE-2016-5961
@@ -7265,8 +7270,8 @@
 	RESERVED
 CVE-2016-5958
 	RESERVED
-CVE-2016-5957
-	RESERVED
+CVE-2016-5957 (IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x ...)
+	TODO: check
 CVE-2016-5956
 	RESERVED
 CVE-2016-5955
@@ -7285,16 +7290,16 @@
 	RESERVED
 CVE-2016-5948
 	RESERVED
-CVE-2016-5947
-	RESERVED
-CVE-2016-5946
-	RESERVED
-CVE-2016-5945
-	RESERVED
-CVE-2016-5944
-	RESERVED
-CVE-2016-5943
-	RESERVED
+CVE-2016-5947 (IBM Spectrum Control (formerly Tivoli Storage Productivity Center) ...)
+	TODO: check
+CVE-2016-5946 (Directory traversal vulnerability in IBM Spectrum Control (formerly ...)
+	TODO: check
+CVE-2016-5945 (IBM Spectrum Control (formerly Tivoli Storage Productivity Center) ...)
+	TODO: check
+CVE-2016-5944 (Cross-site scripting (XSS) vulnerability in the Web UI in IBM Spectrum ...)
+	TODO: check
+CVE-2016-5943 (IBM Spectrum Control (formerly Tivoli Storage Productivity Center) ...)
+	TODO: check
 CVE-2016-5942
 	RESERVED
 CVE-2016-5941
@@ -7617,8 +7622,8 @@
 	RESERVED
 CVE-2016-5794
 	RESERVED
-CVE-2016-5793
-	RESERVED
+CVE-2016-5793 (Unquoted Windows search path vulnerability in Moxa Active OPC Server ...)
+	TODO: check
 CVE-2016-5792 (SQL injection vulnerability in Moxa SoftCMS before 1.5 allows remote ...)
 	NOT-FOR-US: Moxa
 CVE-2016-5791
@@ -10016,38 +10021,32 @@
 	RESERVED
 CVE-2016-5176
 	RESERVED
-CVE-2016-5175
-	RESERVED
+CVE-2016-5175 (Multiple unspecified vulnerabilities in Google Chrome before ...)
 	{DSA-3667-1}
 	- chromium-browser 53.0.2785.113-1
 	[wheezy] - chromium-browser <end-of-life> (Not supported in Wheezy)
-CVE-2016-5174
-	RESERVED
+CVE-2016-5174 (browser/ui/cocoa/browser_window_controller_private.mm in Google Chrome ...)
 	{DSA-3667-1}
 	- chromium-browser 53.0.2785.113-1
 	[wheezy] - chromium-browser <end-of-life> (Not supported in Wheezy)
-CVE-2016-5173
-	RESERVED
+CVE-2016-5173 (The extensions subsystem in Google Chrome before 53.0.2785.113 does ...)
 	{DSA-3667-1}
 	- chromium-browser 53.0.2785.113-1
 	[wheezy] - chromium-browser <end-of-life> (Not supported in Wheezy)
-CVE-2016-5172
-	RESERVED
+CVE-2016-5172 (The parser in Google V8, as used in Google Chrome before ...)
 	{DSA-3667-1}
 	- chromium-browser 53.0.2785.113-1
 	[wheezy] - chromium-browser <end-of-life> (Not supported in Wheezy)
-CVE-2016-5171
-	RESERVED
+CVE-2016-5171 (WebKit/Source/bindings/templates/interface.cpp in Blink, as used in ...)
 	{DSA-3667-1}
 	- chromium-browser 53.0.2785.113-1
 	[wheezy] - chromium-browser <end-of-life> (Not supported in Wheezy)
-CVE-2016-5170
-	RESERVED
+CVE-2016-5170 (WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as ...)
 	{DSA-3667-1}
 	- chromium-browser 53.0.2785.113-1
 	[wheezy] - chromium-browser <end-of-life> (Not supported in Wheezy)
-CVE-2016-5169
-	RESERVED
+CVE-2016-5169 (Format string vulnerability in Google Chrome OS before 53.0.2785.103 ...)
+	TODO: check
 CVE-2016-5168
 	RESERVED
 CVE-2016-5167 (Multiple unspecified vulnerabilities in Google Chrome before ...)
@@ -11289,8 +11288,8 @@
 	RESERVED
 CVE-2016-4846
 	RESERVED
-CVE-2016-4845
-	RESERVED
+CVE-2016-4845 (Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE ...)
+	TODO: check
 CVE-2016-4844
 	RESERVED
 CVE-2016-4843
@@ -11468,178 +11467,178 @@
 	RESERVED
 CVE-2016-4780
 	RESERVED
-CVE-2016-4779
-	RESERVED
-CVE-2016-4778
-	RESERVED
-CVE-2016-4777
-	RESERVED
-CVE-2016-4776
-	RESERVED
-CVE-2016-4775
-	RESERVED
-CVE-2016-4774
-	RESERVED
-CVE-2016-4773
-	RESERVED
-CVE-2016-4772
-	RESERVED
-CVE-2016-4771
-	RESERVED
+CVE-2016-4779 (Apple Type Services (ATS) in Apple OS X before 10.12 allows remote ...)
+	TODO: check
+CVE-2016-4778 (The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, ...)
+	TODO: check
+CVE-2016-4777 (The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, ...)
+	TODO: check
+CVE-2016-4776 (The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, ...)
+	TODO: check
+CVE-2016-4775 (The kernel in Apple OS X before 10.12, tvOS before 10, and watchOS ...)
+	TODO: check
+CVE-2016-4774 (The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, ...)
+	TODO: check
+CVE-2016-4773 (The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, ...)
+	TODO: check
+CVE-2016-4772 (The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, ...)
+	TODO: check
+CVE-2016-4771 (The kernel in Apple iOS before 10 and OS X before 10.12 allows local ...)
+	TODO: check
 CVE-2016-4770
 	RESERVED
-CVE-2016-4769
-	RESERVED
-CVE-2016-4768
-	RESERVED
-CVE-2016-4767
-	RESERVED
-CVE-2016-4766
-	RESERVED
-CVE-2016-4765
-	RESERVED
+CVE-2016-4769 (WebKit in Apple iTunes before 12.5.1 on Windows and Safari before 10 ...)
+	TODO: check
+CVE-2016-4768 (WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on ...)
+	TODO: check
+CVE-2016-4767 (WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on ...)
+	TODO: check
+CVE-2016-4766 (WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on ...)
+	TODO: check
+CVE-2016-4765 (WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on ...)
+	TODO: check
 CVE-2016-4764
 	RESERVED
-CVE-2016-4763
-	RESERVED
-CVE-2016-4762
-	RESERVED
+CVE-2016-4763 (WKWebView in WebKit in Apple iOS before 10, iTunes before 12.5.1 on ...)
+	TODO: check
+CVE-2016-4762 (WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, iCloud ...)
+	TODO: check
 CVE-2016-4761
 	RESERVED
-CVE-2016-4760
-	RESERVED
-CVE-2016-4759
-	RESERVED
-CVE-2016-4758
-	RESERVED
+CVE-2016-4760 (WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and ...)
+	TODO: check
+CVE-2016-4759 (WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on ...)
+	TODO: check
+CVE-2016-4758 (WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and ...)
+	TODO: check
 CVE-2016-4757
 	RESERVED
 CVE-2016-4756
 	RESERVED
-CVE-2016-4755
-	RESERVED
-CVE-2016-4754
-	RESERVED
-CVE-2016-4753
-	RESERVED
-CVE-2016-4752
-	RESERVED
-CVE-2016-4751
-	RESERVED
-CVE-2016-4750
-	RESERVED
+CVE-2016-4755 (Terminal in Apple OS X before 10.12 uses weak permissions for the ...)
+	TODO: check
+CVE-2016-4754 (ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 ...)
+	TODO: check
+CVE-2016-4753 (Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS ...)
+	TODO: check
+CVE-2016-4752 (The SecKeyDeriveFromPassword function in Apple OS X before 10.12 does ...)
+	TODO: check
+CVE-2016-4751 (The Safari Tabs component in Apple Safari before 10 allows remote ...)
+	TODO: check
+CVE-2016-4750 (S2 Camera in Apple iOS before 10 and OS X before 10.12 allows ...)
+	TODO: check
 CVE-2016-4749 (Printing UIKit in Apple iOS before 10 mishandles environment ...)
 	TODO: check
-CVE-2016-4748
-	RESERVED
+CVE-2016-4748 (Perl in Apple OS X before 10.12 allows local users to bypass the ...)
+	TODO: check
 CVE-2016-4747 (Mail in Apple iOS before 10 mishandles certificates, which makes it ...)
 	TODO: check
 CVE-2016-4746 (The Keyboards component in Apple iOS before 10 does not properly use a ...)
 	TODO: check
-CVE-2016-4745
-	RESERVED
+CVE-2016-4745 (The Kerberos 5 (aka krb5) PAM module in Apple OS X before 10.12 does ...)
+	TODO: check
 CVE-2016-4744
 	RESERVED
 CVE-2016-4743
 	RESERVED
-CVE-2016-4742
-	RESERVED
+CVE-2016-4742 (NSSecureTextField in Apple OS X before 10.12 does not enable Secure ...)
+	TODO: check
 CVE-2016-4741 (The Assets component in Apple iOS before 10 allows man-in-the-middle ...)
 	TODO: check
 CVE-2016-4740 (Apple iOS before 10, when Handoff for Messages is used, does not ...)
 	TODO: check
-CVE-2016-4739
-	RESERVED
-CVE-2016-4738
-	RESERVED
-CVE-2016-4737
-	RESERVED
-CVE-2016-4736
-	RESERVED
-CVE-2016-4735
-	RESERVED
-CVE-2016-4734
-	RESERVED
-CVE-2016-4733
-	RESERVED
+CVE-2016-4739 (mDNSResponder in Apple OS X before 10.12, when VMnet.framework is ...)
+	TODO: check
+CVE-2016-4738 (libxslt in Apple iOS before 10, OS X before 10.12, tvOS before 10, and ...)
+	TODO: check
+CVE-2016-4737 (WebKit in Apple iOS before 10, Safari before 10, tvOS before 10, and ...)
+	TODO: check
+CVE-2016-4736 (libarchive in Apple OS X before 10.12 allows remote attackers to cause ...)
+	TODO: check
+CVE-2016-4735 (WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 ...)
+	TODO: check
+CVE-2016-4734 (WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 ...)
+	TODO: check
+CVE-2016-4733 (WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 ...)
+	TODO: check
 CVE-2016-4732
 	RESERVED
-CVE-2016-4731
-	RESERVED
-CVE-2016-4730
-	RESERVED
-CVE-2016-4729
-	RESERVED
-CVE-2016-4728
-	RESERVED
-CVE-2016-4727
-	RESERVED
-CVE-2016-4726
-	RESERVED
-CVE-2016-4725
-	RESERVED
-CVE-2016-4724
-	RESERVED
-CVE-2016-4723
-	RESERVED
-CVE-2016-4722
-	RESERVED
+CVE-2016-4731 (WebKit in Apple iOS before 10 and Safari before 10 allows remote ...)
+	TODO: check
+CVE-2016-4730 (WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 ...)
+	TODO: check
+CVE-2016-4729 (WebKit in Apple iOS before 10 and Safari before 10 allows remote ...)
+	TODO: check
+CVE-2016-4728 (WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on ...)
+	TODO: check
+CVE-2016-4727 (IOThunderboltFamily in Apple OS X before 10.12 allows attackers to ...)
+	TODO: check
+CVE-2016-4726 (IOAcceleratorFamily in Apple iOS before 10, OS X before 10.12, tvOS ...)
+	TODO: check
+CVE-2016-4725 (IOAcceleratorFamily in Apple iOS before 10, OS X before 10.12, tvOS ...)
+	TODO: check
+CVE-2016-4724 (IOAcceleratorFamily in Apple iOS before 10 and OS X before 10.12 ...)
+	TODO: check
+CVE-2016-4723 (Intel Graphics Driver in Apple OS X before 10.12 allows attackers to ...)
+	TODO: check
+CVE-2016-4722 (The IDS - Connectivity component in Apple iOS before 10 and OS X ...)
+	TODO: check
 CVE-2016-4721
 	RESERVED
 CVE-2016-4720
 	RESERVED
 CVE-2016-4719 (The GeoServices component in Apple iOS before 10 and watchOS before 3 ...)
 	TODO: check
-CVE-2016-4718
-	RESERVED
-CVE-2016-4717
-	RESERVED
-CVE-2016-4716
-	RESERVED
-CVE-2016-4715
-	RESERVED
+CVE-2016-4718 (Buffer overflow in FontParser in Apple iOS before 10, OS X before ...)
+	TODO: check
+CVE-2016-4717 (The File Bookmark component in Apple OS X before 10.12 mishandles ...)
+	TODO: check
+CVE-2016-4716 (diskutil in DiskArbitration in Apple OS X before 10.12 allows local ...)
+	TODO: check
+CVE-2016-4715 (The Date & Time Pref Pane component in Apple OS X before 10.12 ...)
+	TODO: check
 CVE-2016-4714
 	RESERVED
-CVE-2016-4713
-	RESERVED
-CVE-2016-4712
-	RESERVED
-CVE-2016-4711
-	RESERVED
-CVE-2016-4710
-	RESERVED
-CVE-2016-4709
-	RESERVED
-CVE-2016-4708
-	RESERVED
-CVE-2016-4707
-	RESERVED
-CVE-2016-4706
-	RESERVED
+CVE-2016-4713 (CoreDisplay in Apple OS X before 10.12 allows attackers to view ...)
+	TODO: check
+CVE-2016-4712 (CoreCrypto in Apple iOS before 10, OS X before 10.12, tvOS before 10, ...)
+	TODO: check
+CVE-2016-4711 (CCrypt in corecrypto in CommonCrypto in Apple iOS before 10 and OS X ...)
+	TODO: check
+CVE-2016-4710 (WindowServer in Apple OS X before 10.12 allows local users to obtain ...)
+	TODO: check
+CVE-2016-4709 (WindowServer in Apple OS X before 10.12 allows local users to obtain ...)
+	TODO: check
+CVE-2016-4708 (CFNetwork in Apple iOS before 10, OS X before 10.12, tvOS before 10, ...)
+	TODO: check
+CVE-2016-4707 (CFNetwork in Apple iOS before 10 and OS X before 10.12 mishandles ...)
+	TODO: check
+CVE-2016-4706 (cd9660 in Apple OS X before 10.12 allows local users to cause a denial ...)
+	TODO: check
 CVE-2016-4705 (otool in Apple Xcode before 8 allows local users to gain privileges or ...)
 	TODO: check
 CVE-2016-4704 (otool in Apple Xcode before 8 allows local users to gain privileges or ...)
 	TODO: check
-CVE-2016-4703
-	RESERVED
-CVE-2016-4702
-	RESERVED
-CVE-2016-4701
-	RESERVED
-CVE-2016-4700
-	RESERVED
-CVE-2016-4699
-	RESERVED
-CVE-2016-4698
-	RESERVED
-CVE-2016-4697
-	RESERVED
-CVE-2016-4696
-	RESERVED
+CVE-2016-4703 (Bluetooth in Apple OS X before 10.12 allows attackers to execute ...)
+	TODO: check
+CVE-2016-4702 (Audio in Apple iOS before 10, OS X before 10.12, tvOS before 10, and ...)
+	TODO: check
+CVE-2016-4701 (Application Firewall in Apple OS X before 10.12 allows local users to ...)
+	TODO: check
+CVE-2016-4700 (AppleUUC in Apple OS X before 10.12 allows attackers to execute ...)
+	TODO: check
+CVE-2016-4699 (AppleUUC in Apple OS X before 10.12 allows attackers to execute ...)
+	TODO: check
+CVE-2016-4698 (AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 ...)
+	TODO: check
+CVE-2016-4697 (Apple HSSPI Support in Apple OS X before 10.12 allows attackers to ...)
+	TODO: check
+CVE-2016-4696 (AppleEFIRuntime in Apple OS X before 10.12 allows attackers to execute ...)
+	TODO: check
 CVE-2016-4695
 	RESERVED
-CVE-2016-4694
-	RESERVED
+CVE-2016-4694 (The Apache HTTP Server in Apple OS X before 10.12 and OS X Server ...)
+	TODO: check
 CVE-2016-4693
 	RESERVED
 CVE-2016-4692
@@ -11710,8 +11709,8 @@
 	RESERVED
 CVE-2016-4659
 	RESERVED
-CVE-2016-4658
-	RESERVED
+CVE-2016-4658 (libxml2 in Apple iOS before 10, OS X before 10.12, tvOS before 10, and ...)
+	TODO: check
 CVE-2016-4657 (WebKit in Apple iOS before 9.3.5 allows remote attackers to execute ...)
 	TODO: check
 CVE-2016-4656 (The kernel in Apple iOS before 9.3.5 allows attackers to execute ...)
@@ -11790,8 +11789,8 @@
 	TODO: check
 CVE-2016-4619 (libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before ...)
 	TODO: check
-CVE-2016-4618
-	RESERVED
+CVE-2016-4618 (Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS ...)
+	TODO: check
 CVE-2016-4617
 	RESERVED
 CVE-2016-4616 (libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before ...)
@@ -11804,8 +11803,8 @@
 	RESERVED
 CVE-2016-4612 (libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before ...)
 	TODO: check
-CVE-2016-4611
-	RESERVED
+CVE-2016-4611 (WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 ...)
+	TODO: check
 CVE-2016-4610 (libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before ...)
 	TODO: check
 CVE-2016-4609 (libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before ...)
@@ -16414,8 +16413,8 @@
 	RESERVED
 CVE-2016-3041
 	RESERVED
-CVE-2016-3040
-	RESERVED
+CVE-2016-3040 (IBM WebSphere Application Server (WAS) Liberty, as used in IBM ...)
+	TODO: check
 CVE-2016-3039 (IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated ...)
 	TODO: check
 CVE-2016-3038
@@ -16480,24 +16479,24 @@
 	RESERVED
 CVE-2016-3008 (Cross-site scripting (XSS) vulnerability in the Web UI in IBM ...)
 	TODO: check
-CVE-2016-3007
-	RESERVED
-CVE-2016-3006
-	RESERVED
+CVE-2016-3007 (Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.x ...)
+	TODO: check
+CVE-2016-3006 (Cross-site scripting (XSS) vulnerability in the Web UI in IBM ...)
+	TODO: check
 CVE-2016-3005 (Cross-site scripting (XSS) vulnerability in the Web UI in IBM ...)
 	TODO: check
 CVE-2016-3004
 	RESERVED
-CVE-2016-3003
-	RESERVED
+CVE-2016-3003 (Cross-site scripting (XSS) vulnerability in the Web UI in IBM ...)
+	TODO: check
 CVE-2016-3002
 	RESERVED
-CVE-2016-3001
-	RESERVED
-CVE-2016-3000
-	RESERVED
-CVE-2016-2999
-	RESERVED
+CVE-2016-3001 (Cross-site scripting (XSS) vulnerability in the Web UI in IBM ...)
+	TODO: check
+CVE-2016-3000 (The help service in IBM Connections 4.x through 4.5 CR5, 5.0 before ...)
+	TODO: check
+CVE-2016-2999 (IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before ...)
+	TODO: check
 CVE-2016-2998 (Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 ...)
 	TODO: check
 CVE-2016-2997 (Cross-site scripting (XSS) vulnerability in the Web UI in IBM ...)
@@ -24113,8 +24112,7 @@
 	NOT-FOR-US: EMC Avamar
 CVE-2016-0919
 	RESERVED
-CVE-2016-0918
-	RESERVED
+CVE-2016-0918 (EMC RSA Identity Management and Governance before 6.8.1 P25 and 6.9.x ...)
 	NOT-FOR-US: EMC RSA Identity Governance and Lifecycle
 CVE-2016-0917 (The SMB service in EMC VNXe, VNX1 File OE before 7.1.80.3, and VNX2 ...)
 	NOT-FOR-US: EMC VNX
@@ -25969,8 +25967,8 @@
 	TODO: check
 CVE-2016-0380 (IBM Sterling Connect:Direct for Unix 4.1.0 before 4.1.0.4 iFix073 and ...)
 	TODO: check
-CVE-2016-0379
-	RESERVED
+CVE-2016-0379 (IBM WebSphere MQ 7.5 before 7.5.0.7 and 8.0 before 8.0.0.5 mishandles ...)
+	TODO: check
 CVE-2016-0378
 	RESERVED
 CVE-2016-0377
@@ -26231,8 +26229,8 @@
 	RESERVED
 CVE-2016-0249
 	RESERVED
-CVE-2016-0248
-	RESERVED
+CVE-2016-0248 (IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows ...)
+	TODO: check
 CVE-2016-0247
 	RESERVED
 CVE-2016-0246




More information about the Secure-testing-commits mailing list