[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso carnil at debian.org
Mon Nov 26 08:10:22 GMT 2018


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
73f5ad77 by security tracker role at 2018-11-26T08:10:12Z
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,91 @@
-CVE-2018-19520
+CVE-2018-19562 (An issue was discovered in PHPok 4.9.015. admin.php?c=update&f=unzip ...)
+	TODO: check
+CVE-2018-19561 (sikcms 1.1 has CSRF via admin.php?m=Admin&c=Users&a=userAdd to add an ...)
+	TODO: check
+CVE-2018-19560 (BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate ...)
+	TODO: check
+CVE-2018-19559 (CuppaCMS before 2018-11-12 has SQL Injection in ...)
+	TODO: check
+CVE-2018-19558 (An issue was discovered in arcms through 2018-03-19. SQL injection ...)
+	TODO: check
+CVE-2018-19557 (An issue was discovered in arcms through 2018-03-19. No authentication ...)
+	TODO: check
+CVE-2018-19556 (zb_system/admin/index.php?act=UploadMng in Z-BlogPHP 1.5 mishandles ...)
+	TODO: check
+CVE-2018-19555 (tp4a TELEPORT 3.1.0 has CSRF via user/do-reset-password to change any ...)
+	TODO: check
+CVE-2018-19554 (An issue was discovered in Dotcms through 5.0.3. Attackers may perform ...)
+	TODO: check
+CVE-2018-19553 (Interspire Email Marketer through 6.1.6 has SQL Injection via an ...)
+	TODO: check
+CVE-2018-19552 (Interspire Email Marketer through 6.1.6 has SQL Injection via a ...)
+	TODO: check
+CVE-2018-19551 (Interspire Email Marketer through 6.1.6 has SQL Injection via a ...)
+	TODO: check
+CVE-2018-19550 (Interspire Email Marketer through 6.1.6 allows arbitrary file upload ...)
+	TODO: check
+CVE-2018-19549 (Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids ...)
+	TODO: check
+CVE-2018-19548 (index.php?r=site%2Flogin in EduSec through 4.2.6 does not restrict ...)
+	TODO: check
+CVE-2018-19547 (JTBC(PHP) 3.0.1.7 has XSS via the ...)
+	TODO: check
+CVE-2018-19546 (JTBC(PHP) 3.0.1.7 has CSRF via the ...)
+	TODO: check
+CVE-2018-19545 (JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user. ...)
+	TODO: check
+CVE-2018-19544 (JEECMS 9.3 has CSRF via the api/admin/content/save URI to add news. ...)
+	TODO: check
+CVE-2018-19543 (An issue was discovered in JasPer 2.0.14. There is a heap-based buffer ...)
+	TODO: check
+CVE-2018-19542 (An issue was discovered in JasPer 2.0.14. There is a NULL pointer ...)
+	TODO: check
+CVE-2018-19541 (An issue was discovered in JasPer 2.0.14. There is a heap-based buffer ...)
+	TODO: check
+CVE-2018-19540 (An issue was discovered in JasPer 2.0.14. There is a heap-based buffer ...)
+	TODO: check
+CVE-2018-19539 (An issue was discovered in JasPer 2.0.14. There is an access violation ...)
+	TODO: check
+CVE-2018-19538
 	RESERVED
-CVE-2018-19519
+CVE-2018-19537 (TP-Link Archer C5 devices through V2_160201_US allow remote command ...)
+	TODO: check
+CVE-2018-19536
+	RESERVED
+CVE-2018-19535 (In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in ...)
+	TODO: check
+CVE-2018-19534
+	RESERVED
+CVE-2018-19533
+	RESERVED
+CVE-2018-19532 (A NULL pointer dereference vulnerability exists in the function ...)
+	TODO: check
+CVE-2018-19531 (HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote ...)
+	TODO: check
+CVE-2018-19530 (HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote ...)
+	TODO: check
+CVE-2018-19529
 	RESERVED
+CVE-2018-19528 (TP-Link TL-WR886N 7.0 1.1.0 devices allow remote attackers to cause a ...)
+	TODO: check
+CVE-2018-19527
+	RESERVED
+CVE-2018-19526
+	RESERVED
+CVE-2018-19525
+	RESERVED
+CVE-2018-19524
+	RESERVED
+CVE-2018-19523
+	RESERVED
+CVE-2018-19522
+	RESERVED
+CVE-2018-19521
+	RESERVED
+CVE-2018-19520 (An issue was discovered in SDCMS 1.6 with PHP 5.x. ...)
+	TODO: check
+CVE-2018-19519 (In tcpdump 4.9.2, a stack-based buffer over-read exists in the ...)
+	TODO: check
 CVE-2018-19516
 	RESERVED
 CVE-2018-19515
@@ -54,17 +138,20 @@ CVE-2018-19494
 CVE-2018-19493
 	RESERVED
 CVE-2018-19492 (An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue ...)
+	{DLA-1595-1}
 	- gnuplot <unfixed> (unimportant)
 	- gnuplot5 <removed> (unimportant)
 	NOTE: https://sourceforge.net/p/gnuplot/bugs/2089/
 	NOTE: https://sourceforge.net/p/gnuplot/gnuplot-main/ci/d5020716834582b20a5e12cdd49f39ee4f9dd949/
 	NOTE: No security impact, neutralised by toolchain hardening
 CVE-2018-19491 (An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows ...)
+	{DLA-1595-1}
 	- gnuplot <unfixed>
 	- gnuplot5 <removed>
 	NOTE: https://sourceforge.net/p/gnuplot/bugs/2094/
 	NOTE: https://sourceforge.net/p/gnuplot/gnuplot-main/ci/d5020716834582b20a5e12cdd49f39ee4f9dd949/
 CVE-2018-19490 (An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue ...)
+	{DLA-1595-1}
 	- gnuplot <unfixed>
 	- gnuplot5 <removed>
 	NOTE: https://sourceforge.net/p/gnuplot/bugs/2093/



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/73f5ad77c46f6e9d825f8b9a92b463f05fe95c8e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/73f5ad77c46f6e9d825f8b9a92b463f05fe95c8e
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20181126/148a81b5/attachment-0001.html>


More information about the debian-security-tracker-commits mailing list