[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Oct 15 09:10:20 BST 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
77c2bcaf by security tracker role at 2022-10-15T08:10:11+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,35 @@
+CVE-2022-42963
+	RESERVED
+CVE-2022-42962
+	RESERVED
+CVE-2022-42961 (An issue was discovered in wolfSSL before 5.5.0. A fault injection att ...)
+	TODO: check
+CVE-2022-42960
+	RESERVED
+CVE-2022-42959
+	RESERVED
+CVE-2022-42958
+	RESERVED
+CVE-2022-42957
+	RESERVED
+CVE-2022-42956
+	RESERVED
+CVE-2022-42955
+	RESERVED
+CVE-2022-42954
+	RESERVED
+CVE-2022-42953
+	RESERVED
+CVE-2022-42952
+	RESERVED
+CVE-2022-42951
+	RESERVED
+CVE-2022-42950
+	RESERVED
+CVE-2022-42949
+	RESERVED
+CVE-2017-20149 (The Mikrotik RouterOS web server allows memory corruption in releases  ...)
+	TODO: check
 CVE-2022-42948
 	RESERVED
 CVE-2022-42947
@@ -1488,14 +1520,14 @@ CVE-2022-42344
 	RESERVED
 CVE-2022-42343
 	RESERVED
-CVE-2022-42342
-	RESERVED
-CVE-2022-42341
-	RESERVED
-CVE-2022-42340
-	RESERVED
-CVE-2022-42339
-	RESERVED
+CVE-2022-42342 (Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30 ...)
+	TODO: check
+CVE-2022-42341 (Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and ea ...)
+	TODO: check
+CVE-2022-42340 (Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and ea ...)
+	TODO: check
+CVE-2022-42339 (Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30 ...)
+	TODO: check
 CVE-2022-42338
 	RESERVED
 CVE-2022-42337
@@ -3038,8 +3070,8 @@ CVE-2022-41634
 	RESERVED
 CVE-2022-41633
 	RESERVED
-CVE-2022-41623
-	RESERVED
+CVE-2022-41623 (Sensitive Data Exposure in Villatheme ALD - AliExpress Dropshipping an ...)
+	TODO: check
 CVE-2022-41620
 	RESERVED
 CVE-2022-41618
@@ -3644,8 +3676,8 @@ CVE-2022-41438
 	RESERVED
 CVE-2022-41437 (Billing System Project v1.0 was discovered to contain a remote code ex ...)
 	NOT-FOR-US: Billing System Project
-CVE-2022-41436
-	RESERVED
+CVE-2022-41436 (An issue in OXHOO TP50 OXH1.50 allows unauthenticated attackers to acc ...)
+	TODO: check
 CVE-2022-41435
 	RESERVED
 CVE-2022-41434
@@ -3686,8 +3718,8 @@ CVE-2022-41418
 	RESERVED
 CVE-2022-41417
 	RESERVED
-CVE-2022-41416
-	RESERVED
+CVE-2022-41416 (Online Tours & Travels Management System v1.0 was discovered to co ...)
+	TODO: check
 CVE-2022-41415
 	RESERVED
 CVE-2022-41414 (An insecure default in the component auth.login.prompt.enabled of Life ...)
@@ -8598,12 +8630,12 @@ CVE-2022-39313
 	RESERVED
 CVE-2022-39312
 	RESERVED
-CVE-2022-39311
-	RESERVED
-CVE-2022-39310
-	RESERVED
-CVE-2022-39309
-	RESERVED
+CVE-2022-39311 (GoCD is a continuous delivery server. GoCD helps you automate and stre ...)
+	TODO: check
+CVE-2022-39310 (GoCD is a continuous delivery server. GoCD helps you automate and stre ...)
+	TODO: check
+CVE-2022-39309 (GoCD is a continuous delivery server. GoCD helps you automate and stre ...)
+	TODO: check
 CVE-2022-39308 (GoCD is a continuous delivery server. GoCD helps you automate and stre ...)
 	TODO: check
 CVE-2022-39307
@@ -11135,34 +11167,34 @@ CVE-2022-38463 (ServiceNow through San Diego Patch 4b and Patch 6 allows reflect
 	NOT-FOR-US: ServiceNow
 CVE-2022-38462
 	RESERVED
-CVE-2022-38450
-	RESERVED
-CVE-2022-38449
-	RESERVED
-CVE-2022-38448
-	RESERVED
-CVE-2022-38447
-	RESERVED
-CVE-2022-38446
-	RESERVED
-CVE-2022-38445
-	RESERVED
-CVE-2022-38444
-	RESERVED
-CVE-2022-38443
-	RESERVED
-CVE-2022-38442
-	RESERVED
-CVE-2022-38441
-	RESERVED
-CVE-2022-38440
-	RESERVED
+CVE-2022-38450 (Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30 ...)
+	TODO: check
+CVE-2022-38449 (Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30 ...)
+	TODO: check
+CVE-2022-38448 (Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnera ...)
+	TODO: check
+CVE-2022-38447 (Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnera ...)
+	TODO: check
+CVE-2022-38446 (Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnera ...)
+	TODO: check
+CVE-2022-38445 (Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnera ...)
+	TODO: check
+CVE-2022-38444 (Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnera ...)
+	TODO: check
+CVE-2022-38443 (Adobe Dimension versions 3.4.5 is affected by an out-of-bounds read vu ...)
+	TODO: check
+CVE-2022-38442 (Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnera ...)
+	TODO: check
+CVE-2022-38441 (Adobe Dimension versions 3.4.5 is affected by an out-of-bounds read vu ...)
+	TODO: check
+CVE-2022-38440 (Adobe Dimension versions 3.4.5 is affected by an out-of-bounds read vu ...)
+	TODO: check
 CVE-2022-38439 (Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected b ...)
 	NOT-FOR-US: Adobe
 CVE-2022-38438 (Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected b ...)
 	NOT-FOR-US: Adobe
-CVE-2022-38437
-	RESERVED
+CVE-2022-38437 (Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30 ...)
+	TODO: check
 CVE-2022-38436
 	RESERVED
 CVE-2022-38435
@@ -11187,20 +11219,20 @@ CVE-2022-38426 (Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and ea
 	NOT-FOR-US: Adobe
 CVE-2022-38425 (Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are ...)
 	NOT-FOR-US: Adobe
-CVE-2022-38424
-	RESERVED
-CVE-2022-38423
-	RESERVED
-CVE-2022-38422
-	RESERVED
-CVE-2022-38421
-	RESERVED
-CVE-2022-38420
-	RESERVED
-CVE-2022-38419
-	RESERVED
-CVE-2022-38418
-	RESERVED
+CVE-2022-38424 (Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and ea ...)
+	TODO: check
+CVE-2022-38423 (Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and ea ...)
+	TODO: check
+CVE-2022-38422 (Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and ea ...)
+	TODO: check
+CVE-2022-38421 (Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and ea ...)
+	TODO: check
+CVE-2022-38420 (Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and ea ...)
+	TODO: check
+CVE-2022-38419 (Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and ea ...)
+	TODO: check
+CVE-2022-38418 (Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and ea ...)
+	TODO: check
 CVE-2022-38417 (Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) ar ...)
 	NOT-FOR-US: Adobe
 CVE-2022-38416 (Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) ar ...)
@@ -18404,12 +18436,12 @@ CVE-2021-46827 (An issue was discovered in Oxygen XML WebHelp before 22.1 build
 	NOT-FOR-US: Oxygen XML WebHelp
 CVE-2022-35713 (Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) ...)
 	NOT-FOR-US: Adobe
-CVE-2022-35712
-	RESERVED
-CVE-2022-35711
-	RESERVED
-CVE-2022-35710
-	RESERVED
+CVE-2022-35712 (Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and ea ...)
+	TODO: check
+CVE-2022-35711 (Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and ea ...)
+	TODO: check
+CVE-2022-35710 (Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and ea ...)
+	TODO: check
 CVE-2022-35709 (Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are ...)
 	NOT-FOR-US: Adobe
 CVE-2022-35708 (Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are ...)
@@ -18432,8 +18464,8 @@ CVE-2022-35700 (Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlie
 	NOT-FOR-US: Adobe
 CVE-2022-35699 (Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are ...)
 	NOT-FOR-US: Adobe
-CVE-2022-35698
-	RESERVED
+CVE-2022-35698 (Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) ...)
+	TODO: check
 CVE-2022-35697 (Adobe Experience Manager Core Components version 2.20.6 (and earlier)  ...)
 	NOT-FOR-US: Adobe
 CVE-2022-35696
@@ -18446,12 +18478,12 @@ CVE-2022-35693
 	RESERVED
 CVE-2022-35692 (Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) ...)
 	NOT-FOR-US: Adobe
-CVE-2022-35691
-	RESERVED
-CVE-2022-35690
-	RESERVED
-CVE-2022-35689
-	RESERVED
+CVE-2022-35691 (Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30 ...)
+	TODO: check
+CVE-2022-35690 (Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and ea ...)
+	TODO: check
+CVE-2022-35689 (Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) ...)
+	TODO: check
 CVE-2022-35688
 	RESERVED
 CVE-2022-35687
@@ -22290,7 +22322,7 @@ CVE-2021-46824 (Cross Site Scripting (XSS) vulnerability in sourcecodester Schoo
 	NOT-FOR-US: sourcecodester School File Management System
 CVE-2022-34327
 	RESERVED
-CVE-2022-34326 (On Realtek RTL8195AM devices before 284241d70308ff2519e40afd7b284ba892 ...)
+CVE-2022-34326 (In ambiot amb1_sdk (aka SDK for Ameba1) before 2022-06-20 on Realtek R ...)
 	NOT-FOR-US: Realtek
 CVE-2022-34325
 	RESERVED



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/77c2bcaf84b5d38ac9123a09d796c0815388b0a2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/77c2bcaf84b5d38ac9123a09d796c0815388b0a2
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20221015/6535837d/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list