[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso carnil at debian.org
Mon Mar 15 20:10:43 GMT 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c425aebc by security tracker role at 2021-03-15T20:10:35+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,207 @@
+CVE-2021-3442
+	RESERVED
+CVE-2021-28483
+	RESERVED
+CVE-2021-28482
+	RESERVED
+CVE-2021-28481
+	RESERVED
+CVE-2021-28480
+	RESERVED
+CVE-2021-28479
+	RESERVED
+CVE-2021-28478
+	RESERVED
+CVE-2021-28477
+	RESERVED
+CVE-2021-28476
+	RESERVED
+CVE-2021-28475
+	RESERVED
+CVE-2021-28474
+	RESERVED
+CVE-2021-28473
+	RESERVED
+CVE-2021-28472
+	RESERVED
+CVE-2021-28471
+	RESERVED
+CVE-2021-28470
+	RESERVED
+CVE-2021-28469
+	RESERVED
+CVE-2021-28468
+	RESERVED
+CVE-2021-28467
+	RESERVED
+CVE-2021-28466
+	RESERVED
+CVE-2021-28465
+	RESERVED
+CVE-2021-28464
+	RESERVED
+CVE-2021-28463
+	RESERVED
+CVE-2021-28462
+	RESERVED
+CVE-2021-28461
+	RESERVED
+CVE-2021-28460
+	RESERVED
+CVE-2021-28459
+	RESERVED
+CVE-2021-28458
+	RESERVED
+CVE-2021-28457
+	RESERVED
+CVE-2021-28456
+	RESERVED
+CVE-2021-28455
+	RESERVED
+CVE-2021-28454
+	RESERVED
+CVE-2021-28453
+	RESERVED
+CVE-2021-28452
+	RESERVED
+CVE-2021-28451
+	RESERVED
+CVE-2021-28450
+	RESERVED
+CVE-2021-28449
+	RESERVED
+CVE-2021-28448
+	RESERVED
+CVE-2021-28447
+	RESERVED
+CVE-2021-28446
+	RESERVED
+CVE-2021-28445
+	RESERVED
+CVE-2021-28444
+	RESERVED
+CVE-2021-28443
+	RESERVED
+CVE-2021-28442
+	RESERVED
+CVE-2021-28441
+	RESERVED
+CVE-2021-28440
+	RESERVED
+CVE-2021-28439
+	RESERVED
+CVE-2021-28438
+	RESERVED
+CVE-2021-28437
+	RESERVED
+CVE-2021-28436
+	RESERVED
+CVE-2021-28435
+	RESERVED
+CVE-2021-28434
+	RESERVED
+CVE-2021-28433
+	RESERVED
+CVE-2021-28432
+	RESERVED
+CVE-2021-28431
+	RESERVED
+CVE-2021-28430
+	RESERVED
+CVE-2021-28429
+	RESERVED
+CVE-2021-28428
+	RESERVED
+CVE-2021-28427
+	RESERVED
+CVE-2021-28426
+	RESERVED
+CVE-2021-28425
+	RESERVED
+CVE-2021-28424
+	RESERVED
+CVE-2021-28423
+	RESERVED
+CVE-2021-28422
+	RESERVED
+CVE-2021-28421
+	RESERVED
+CVE-2021-28420
+	RESERVED
+CVE-2021-28419
+	RESERVED
+CVE-2021-28418
+	RESERVED
+CVE-2021-28417
+	RESERVED
+CVE-2021-28416
+	RESERVED
+CVE-2021-28415
+	RESERVED
+CVE-2021-28414
+	RESERVED
+CVE-2021-28413
+	RESERVED
+CVE-2021-28412
+	RESERVED
+CVE-2021-28411
+	RESERVED
+CVE-2021-28410
+	RESERVED
+CVE-2021-28409
+	RESERVED
+CVE-2021-28408
+	RESERVED
+CVE-2021-28407
+	RESERVED
+CVE-2021-28406
+	RESERVED
+CVE-2021-28405
+	RESERVED
+CVE-2021-28404
+	RESERVED
+CVE-2021-28403
+	RESERVED
+CVE-2021-28402
+	RESERVED
+CVE-2021-28401
+	RESERVED
+CVE-2021-28400
+	RESERVED
+CVE-2021-28399
+	RESERVED
+CVE-2021-28398
+	RESERVED
+CVE-2021-28397
+	RESERVED
+CVE-2021-28396
+	RESERVED
+CVE-2021-28395
+	RESERVED
+CVE-2021-28394
+	RESERVED
+CVE-2021-28393
+	RESERVED
+CVE-2021-28392
+	RESERVED
+CVE-2021-28391
+	RESERVED
+CVE-2021-28390
+	RESERVED
+CVE-2021-28389
+	RESERVED
+CVE-2021-28388
+	RESERVED
+CVE-2021-28387
+	RESERVED
+CVE-2021-28386
+	RESERVED
+CVE-2021-28385
+	RESERVED
+CVE-2021-28384
+	RESERVED
+CVE-2021-28383
+	RESERVED
 CVE-2021-28382
 	RESERVED
 CVE-2021-28381
@@ -35,8 +239,8 @@ CVE-2021-28365
 	RESERVED
 CVE-2021-28364
 	RESERVED
-CVE-2021-28363
-	RESERVED
+CVE-2021-28363 (The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certific ...)
+	TODO: check
 CVE-2021-28362
 	RESERVED
 CVE-2021-28361 (An issue was discovered in Storage Performance Development Kit (SPDK)  ...)
@@ -1014,14 +1218,14 @@ CVE-2021-27951
 	RESERVED
 CVE-2021-27950
 	RESERVED
-CVE-2021-27949
-	RESERVED
-CVE-2021-27948
-	RESERVED
-CVE-2021-27947
-	RESERVED
-CVE-2021-27946
-	RESERVED
+CVE-2021-27949 (Cross-site Scripting vulnerability in MyBB before 1.8.26 via Custom mo ...)
+	TODO: check
+CVE-2021-27948 (SQL Injection vulnerability in MyBB before 1.8.26 via User Groups. (is ...)
+	TODO: check
+CVE-2021-27947 (SQL Injection vulnerability in MyBB before 1.8.26 via the Copy Forum f ...)
+	TODO: check
+CVE-2021-27946 (SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. ...)
+	TODO: check
 CVE-2021-27945
 	RESERVED
 CVE-2021-28039 (An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as u ...)
@@ -1175,16 +1379,16 @@ CVE-2021-27895
 	RESERVED
 CVE-2021-27894
 	RESERVED
-CVE-2021-27893
-	RESERVED
-CVE-2021-27892
-	RESERVED
-CVE-2021-27891
-	RESERVED
-CVE-2021-27890
-	RESERVED
-CVE-2021-27889
-	RESERVED
+CVE-2021-27893 (SSH Tectia Client and Server before 6.4.19 on Windows allow local priv ...)
+	TODO: check
+CVE-2021-27892 (SSH Tectia Client and Server before 6.4.19 on Windows allow local priv ...)
+	TODO: check
+CVE-2021-27891 (SSH Tectia Client and Server before 6.4.19 on Windows have weak key ge ...)
+	TODO: check
+CVE-2021-27890 (SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties  ...)
+	TODO: check
+CVE-2021-27889 (Cross-site Scriptiong (XSS) vulnerability in MyBB before 1.8.26 via Ne ...)
+	TODO: check
 CVE-2021-27888 (ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off  ...)
 	NOT-FOR-US: ZendTo
 CVE-2021-27887
@@ -1333,8 +1537,8 @@ CVE-2021-27819
 	RESERVED
 CVE-2021-27818
 	RESERVED
-CVE-2021-27817
-	RESERVED
+CVE-2021-27817 (A remote command execution vulnerability in shopxo 1.9.3 allows an att ...)
+	TODO: check
 CVE-2021-27816
 	RESERVED
 CVE-2021-27815
@@ -1497,8 +1701,8 @@ CVE-2021-27738
 	RESERVED
 CVE-2021-27737
 	RESERVED
-CVE-2020-35358
-	RESERVED
+CVE-2020-35358 (DomainMOD domainmod-v4.15.0 is affected by an insufficient session exp ...)
+	TODO: check
 CVE-2021-27803 (A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant b ...)
 	{DLA-2581-1}
 	- wpa 2:2.9.0-21
@@ -1596,8 +1800,8 @@ CVE-2021-27697
 	RESERVED
 CVE-2021-27696
 	RESERVED
-CVE-2021-27695
-	RESERVED
+CVE-2021-27695 (Multiple stored cross-site scripting (XSS) vulnerabilities in openMAIN ...)
+	TODO: check
 CVE-2021-27694
 	RESERVED
 CVE-2021-27693
@@ -1843,8 +2047,7 @@ CVE-2021-27578
 	RESERVED
 CVE-2021-27577
 	RESERVED
-CVE-2021-27576
-	RESERVED
+CVE-2021-27576 (If was found that the NetTest web service can be used to overload the  ...)
 	NOT-FOR-US: Apache OpenMeetings
 CVE-2021-27575
 	RESERVED
@@ -2277,10 +2480,10 @@ CVE-2021-27383
 	RESERVED
 CVE-2021-27382
 	RESERVED
-CVE-2021-27381
-	RESERVED
-CVE-2021-27380
-	RESERVED
+CVE-2021-27381 (A vulnerability has been identified in Solid Edge SE2020 (All Versions ...)
+	TODO: check
+CVE-2021-27380 (A vulnerability has been identified in Solid Edge SE2020 (All Versions ...)
+	TODO: check
 CVE-2021-27379 (An issue was discovered in Xen through 4.11.x, allowing x86 Intel HVM  ...)
 	- xen 4.14.0+80-gd101b417b7-1
 	[stretch] - xen <not-affected> (Incomplete fix for CVE-2020-15565 not applied)
@@ -2651,8 +2854,8 @@ CVE-2021-27210 (TP-Link Archer C5v 1.7_181221 devices allows remote attackers to
 	NOT-FOR-US: TP-Link
 CVE-2021-27209 (In the management interface on TP-Link Archer C5v 1.7_181221 devices,  ...)
 	NOT-FOR-US: TP-Link
-CVE-2021-27208
-	RESERVED
+CVE-2021-27208 (When booting a Zync-7000 SOC device from nand flash memory, the nand d ...)
+	TODO: check
 CVE-2021-27207
 	RESERVED
 CVE-2021-27206
@@ -3317,10 +3520,10 @@ CVE-2021-26925 (Roundcube before 1.4.11 allows XSS via crafted Cascading Style S
 	[stretch] - roundcube <not-affected> (Vulnerable code introduced later)
 	NOTE: https://roundcube.net/news/2021/02/08/security-update-1.4.11
 	NOTE: https://github.com/roundcube/roundcubemail/commit/9dc276d5f26042db02754fa1bac6fbd683c6d596
-CVE-2021-26924
-	RESERVED
-CVE-2021-26923
-	RESERVED
+CVE-2021-26924 (An issue was discovered in Argo CD before 1.8.4. Browser XSS protectio ...)
+	TODO: check
+CVE-2021-26923 (An issue was discovered in Argo CD before 1.8.4. Accessing the endpoin ...)
+	TODO: check
 CVE-2021-26922
 	RESERVED
 CVE-2021-26921 (In util/session/sessionmanager.go in Argo CD before 1.8.4, tokens cont ...)
@@ -6524,16 +6727,16 @@ CVE-2021-25678
 	RESERVED
 CVE-2021-25677
 	RESERVED
-CVE-2021-25676
-	RESERVED
-CVE-2021-25675
-	RESERVED
-CVE-2021-25674
-	RESERVED
-CVE-2021-25673
-	RESERVED
-CVE-2021-25672
-	RESERVED
+CVE-2021-25676 (A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALAN ...)
+	TODO: check
+CVE-2021-25675 (A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All ver ...)
+	TODO: check
+CVE-2021-25674 (A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All ver ...)
+	TODO: check
+CVE-2021-25673 (A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All ver ...)
+	TODO: check
+CVE-2021-25672 (A vulnerability has been identified in Mendix Forgot Password Appstore ...)
+	TODO: check
 CVE-2021-25671
 	RESERVED
 CVE-2021-25670
@@ -6542,8 +6745,8 @@ CVE-2021-25669
 	RESERVED
 CVE-2021-25668
 	RESERVED
-CVE-2021-25667
-	RESERVED
+CVE-2021-25667 (A vulnerability has been identified in RUGGEDCOM RM1224 (All versions  ...)
+	TODO: check
 CVE-2021-25666 (A vulnerability has been identified in SCALANCE W780 and W740 (IEEE 80 ...)
 	NOT-FOR-US: Siemens
 CVE-2021-25665
@@ -7377,8 +7580,8 @@ CVE-2021-3169
 	RESERVED
 CVE-2021-3168
 	RESERVED
-CVE-2021-3167
-	RESERVED
+CVE-2021-3167 (In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens ar ...)
+	TODO: check
 CVE-2021-3166 (An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices. An at ...)
 	NOT-FOR-US: ASUS devices
 CVE-2021-3165 (SmartAgent 3.1.0 allows a ViewOnly attacker to create a SuperUser acco ...)
@@ -7671,8 +7874,8 @@ CVE-2021-3152 (** DISPUTED ** Home Assistant before 2021.1.3 does not have a pro
 	NOT-FOR-US: Home Assistant
 CVE-2021-3151 (i-doit before 1.16.0 is affected by Stored Cross-Site Scripting (XSS)  ...)
 	NOT-FOR-US: i-doit
-CVE-2021-3150
-	RESERVED
+CVE-2021-3150 (A cross-site scripting (XSS) vulnerability on the Delete Personal Data ...)
+	TODO: check
 CVE-2021-3149 (On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ ...)
 	NOT-FOR-US: Netshield NANO devices
 CVE-2021-3148 (An issue was discovered in SaltStack Salt before 3002.5. Sending craft ...)
@@ -10465,8 +10668,8 @@ CVE-2021-23881 (A stored cross site scripting vulnerability in ePO extension of
 	NOT-FOR-US: McAfee
 CVE-2021-23880 (Improper Access Control in attribute in McAfee Endpoint Security (ENS) ...)
 	NOT-FOR-US: McAfee
-CVE-2021-23879
-	RESERVED
+CVE-2021-23879 (Unquoted service path vulnerability in McAfee Endpoint Product Removal ...)
+	TODO: check
 CVE-2021-23878 (Clear text storage of sensitive Information in memory vulnerability in ...)
 	NOT-FOR-US: McAfee
 CVE-2021-23877
@@ -11564,12 +11767,12 @@ CVE-2021-23359
 	RESERVED
 CVE-2021-23358
 	RESERVED
-CVE-2021-23357
-	RESERVED
-CVE-2021-23356
-	RESERVED
-CVE-2021-23355
-	RESERVED
+CVE-2021-23357 (All versions of package github.com/tyktechnologies/tyk/gateway are vul ...)
+	TODO: check
+CVE-2021-23356 (This affects all versions of package kill-process-by-name. If (attacke ...)
+	TODO: check
+CVE-2021-23355 (This affects all versions of package ps-kill. If (attacker-controlled) ...)
+	TODO: check
 CVE-2021-23354 (The package printf before 0.6.1 are vulnerable to Regular Expression D ...)
 	NOT-FOR-US: Node printf
 CVE-2021-23353 (This affects the package jspdf before 2.3.1. ReDoS is possible via the ...)
@@ -14067,8 +14270,7 @@ CVE-2021-22193
 	RESERVED
 CVE-2021-22192
 	RESERVED
-CVE-2021-22191
-	RESERVED
+CVE-2021-22191 (Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11  ...)
 	- wireshark 3.4.4-1
 	[buster] - wireshark <postponed> (Minor issue, can be fixed along in future update)
 	[stretch] - wireshark <postponed> (Minor issue, can be fixed along in future update)
@@ -19291,8 +19493,8 @@ CVE-2021-20442 (IBM Security Verify Bridge contains hard-coded credentials, such
 	NOT-FOR-US: IBM
 CVE-2021-20441 (IBM Security Verify Bridge uses weaker than expected cryptographic alg ...)
 	NOT-FOR-US: IBM
-CVE-2021-20440
-	RESERVED
+CVE-2021-20440 (IBM API Connect 10.0.0.0, and 2018.4.1.0 through 2018.4.1.13 does not  ...)
+	TODO: check
 CVE-2021-20439
 	RESERVED
 CVE-2021-20438
@@ -19601,8 +19803,7 @@ CVE-2021-20288
 	RESERVED
 CVE-2021-20287
 	RESERVED
-CVE-2021-20286 [Assertion failure in nbd_unlocked_opt_go in lib/opt.c]
-	RESERVED
+CVE-2021-20286 (A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked ...)
 	- libnbd 1.6.2-1
 	NOTE: Fixed by: https://gitlab.com/nbdkit/libnbd/-/commit/2216190ecbbd853648df6a3280c17b345b0907a0 (v1.6.2)
 	NOTE: Fixed by: https://gitlab.com/nbdkit/libnbd/-/commit/fb4440de9cc76e9c14bd3ddf3333e78621f40ad0 (v1.7.3)
@@ -20112,8 +20313,7 @@ CVE-2021-20180
 	[buster] - ansible <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1915808
 	NOTE: https://github.com/ansible-collections/community.general/pull/1635
-CVE-2021-20179
-	RESERVED
+CVE-2021-20179 (A flaw was found in pki-core. An attacker who has successfully comprom ...)
 	- dogtag-pki 10.10.2-2
 	NOTE: https://github.com/dogtagpki/pki/pull/3475
 CVE-2021-20178 [user data leak in snmp_facts module]
@@ -23419,14 +23619,14 @@ CVE-2020-29558
 	RESERVED
 CVE-2020-29557 (An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 bef ...)
 	NOT-FOR-US: D-Link
-CVE-2020-29556
-	RESERVED
-CVE-2020-29555
-	RESERVED
+CVE-2020-29556 (The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an aut ...)
+	TODO: check
+CVE-2020-29555 (The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows  ...)
+	TODO: check
 CVE-2020-29554
 	RESERVED
-CVE-2020-29553
-	RESERVED
+CVE-2020-29553 (The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to ex ...)
+	TODO: check
 CVE-2020-29552 (An issue was discovered in URVE Build 24.03.2020. By using the _intern ...)
 	NOT-FOR-US: URVE
 CVE-2020-29551 (An issue was discovered in URVE Build 24.03.2020. Using the _internal/ ...)
@@ -27462,12 +27662,12 @@ CVE-2020-28389
 	RESERVED
 CVE-2020-28388 (A vulnerability has been identified in Nucleus NET (All versions <  ...)
 	NOT-FOR-US: Siemens
-CVE-2020-28387
-	RESERVED
+CVE-2020-28387 (A vulnerability has been identified in Solid Edge SE2020 (All Versions ...)
+	TODO: check
 CVE-2020-28386 (A vulnerability has been identified in Solid Edge SE2020 (All Versions ...)
 	NOT-FOR-US: Siemens
-CVE-2020-28385
-	RESERVED
+CVE-2020-28385 (A vulnerability has been identified in Solid Edge SE2020 (All Versions ...)
+	TODO: check
 CVE-2020-28384 (A vulnerability has been identified in Solid Edge SE2020 (All Versions ...)
 	NOT-FOR-US: Siemens
 CVE-2020-28383 (A vulnerability has been identified in JT2Go (All Versions < V13.1. ...)
@@ -29520,8 +29720,8 @@ CVE-2020-28151
 	RESERVED
 CVE-2020-28150 (I-Net Software Clear Reports 20.10.136 web application accepts a user- ...)
 	NOT-FOR-US: I-Net Software Clear Reports
-CVE-2020-28149
-	RESERVED
+CVE-2020-28149 (myDBR 5.8.3/4262 is affected by: Cross Site Scripting (XSS). The impac ...)
+	TODO: check
 CVE-2020-28148
 	RESERVED
 CVE-2020-28147
@@ -37158,18 +37358,18 @@ CVE-2020-25243
 	RESERVED
 CVE-2020-25242
 	RESERVED
-CVE-2020-25241
-	RESERVED
-CVE-2020-25240
-	RESERVED
-CVE-2020-25239
-	RESERVED
+CVE-2020-25241 (A vulnerability has been identified in SIMATIC MV400 family (All Versi ...)
+	TODO: check
+CVE-2020-25240 (A vulnerability has been identified in SINEMA Remote Connect Server (A ...)
+	TODO: check
+CVE-2020-25239 (A vulnerability has been identified in SINEMA Remote Connect Server (A ...)
+	TODO: check
 CVE-2020-25238 (A vulnerability has been identified in PCS neo (Administration Console ...)
 	NOT-FOR-US: Siemens
 CVE-2020-25237 (A vulnerability has been identified in SINEC NMS (All versions < V1 ...)
 	NOT-FOR-US: Siemens
-CVE-2020-25236
-	RESERVED
+CVE-2020-25236 (A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS varian ...)
+	TODO: check
 CVE-2020-25235 (A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS varian ...)
 	NOT-FOR-US: Siemens
 CVE-2020-25234 (A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS varian ...)
@@ -37772,14 +37972,14 @@ CVE-2020-24987 (Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.
 	NOT-FOR-US: Tenda AC18 Router
 CVE-2020-24986 (Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File ...)
 	NOT-FOR-US: Concrete5
-CVE-2020-24985
-	RESERVED
+CVE-2020-24985 (An issue was discovered in Quadbase EspressReports ES 7 Update 9. An a ...)
+	TODO: check
 CVE-2020-24984 (An issue was discovered in Quadbase EspressReports ES 7 Update 9. It a ...)
 	NOT-FOR-US: Quadbase EspressReports
 CVE-2020-24983 (An issue was discovered in Quadbase EspressReports ES 7 Update 9. An u ...)
 	NOT-FOR-US: Quadbase EspressReports
-CVE-2020-24982
-	RESERVED
+CVE-2020-24982 (An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9 ...)
+	TODO: check
 CVE-2020-24981 (An Incorrect Access Control vulnerability exists in /ucms/chk.php in U ...)
 	NOT-FOR-US: UCMS
 CVE-2020-24980
@@ -38014,8 +38214,8 @@ CVE-2020-24879
 	RESERVED
 CVE-2020-24878
 	RESERVED
-CVE-2020-24877
-	RESERVED
+CVE-2020-24877 (A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php ...)
+	TODO: check
 CVE-2020-24876 (Use of a hard-coded cryptographic key in Pancake versions < 4.13.29 ...)
 	NOT-FOR-US: Pancake
 CVE-2020-24875
@@ -88575,8 +88775,8 @@ CVE-2020-4186 (IBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensiti
 	NOT-FOR-US: IBM
 CVE-2020-4185 (IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than expected c ...)
 	NOT-FOR-US: IBM
-CVE-2020-4184
-	RESERVED
+CVE-2020-4184 (IBM Security Guardium 11.2 performs an operation at a privilege level  ...)
+	TODO: check
 CVE-2020-4183 (IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This ...)
 	NOT-FOR-US: IBM
 CVE-2020-4182 (IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This ...)
@@ -96595,7 +96795,7 @@ CVE-2019-19302
 	RESERVED
 CVE-2019-19301 (A vulnerability has been identified in SCALANCE X-200 switch family (i ...)
 	NOT-FOR-US: Siemens
-CVE-2019-19300 (A vulnerability has been identified in KTK ATE530S (All versions), SID ...)
+CVE-2019-19300 (A vulnerability has been identified in Development/Evaluation Kits for ...)
 	NOT-FOR-US: Siemens
 CVE-2019-19299 (A vulnerability has been identified in SiNVR 3 Central Control Server  ...)
 	NOT-FOR-US: SiNVR 3 Central Control Server (CCS)
@@ -125523,9 +125723,9 @@ CVE-2019-10928 (A vulnerability has been identified in SCALANCE SC-600 (V2.0). A
 	NOT-FOR-US: Siemens
 CVE-2019-10927 (A vulnerability has been identified in SCALANCE SC-600 (V2.0), SCALANC ...)
 	NOT-FOR-US: Siemens
-CVE-2019-10926 (A vulnerability has been identified in SIMATIC Ident MV420 family (All ...)
+CVE-2019-10926 (A vulnerability has been identified in SIMATIC MV400 family (All Versi ...)
 	NOT-FOR-US: Siemens
-CVE-2019-10925 (A vulnerability has been identified in SIMATIC Ident MV420 family (All ...)
+CVE-2019-10925 (A vulnerability has been identified in SIMATIC MV400 family (All Versi ...)
 	NOT-FOR-US: Siemens
 CVE-2019-10924 (A vulnerability has been identified in LOGO! Soft Comfort (All version ...)
 	NOT-FOR-US: Siemens



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c425aebc96dbab64635e86180c397ffe01998f25

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c425aebc96dbab64635e86180c397ffe01998f25
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210315/f715d30e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list