[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jan 10 20:12:03 GMT 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d2448eb9 by security tracker role at 2024-01-10T20:11:50+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,4 +1,176 @@
-CVE-2023-49619
+CVE-2024-20715 (Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by a ...)
+	TODO: check
+CVE-2024-20714 (Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by a ...)
+	TODO: check
+CVE-2024-20713 (Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by a ...)
+	TODO: check
+CVE-2024-20712 (Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by a ...)
+	TODO: check
+CVE-2024-20711 (Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by a ...)
+	TODO: check
+CVE-2024-20710 (Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by a ...)
+	TODO: check
+CVE-2024-0395
+	REJECTED
+CVE-2024-0389 (A vulnerability, which was classified as critical, was found in Source ...)
+	TODO: check
+CVE-2024-0310 (A content-security-policy vulnerability in ENS Control browser extensi ...)
+	TODO: check
+CVE-2023-6158 (The EventON - WordPress Virtual Event Calendar Plugin plugin for WordP ...)
+	TODO: check
+CVE-2023-5455 (A Cross-site request forgery vulnerability exists in ipa/session/login ...)
+	TODO: check
+CVE-2023-51972 (Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vu ...)
+	TODO: check
+CVE-2023-51971 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpv ...)
+	TODO: check
+CVE-2023-51970 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode  ...)
+	TODO: check
+CVE-2023-51969 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan ...)
+	TODO: check
+CVE-2023-51968 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbal ...)
+	TODO: check
+CVE-2023-51967 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port  ...)
+	TODO: check
+CVE-2023-51966 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbal ...)
+	TODO: check
+CVE-2023-51965 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpv ...)
+	TODO: check
+CVE-2023-51964 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port  ...)
+	TODO: check
+CVE-2023-51963 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan ...)
+	TODO: check
+CVE-2023-51962 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode  ...)
+	TODO: check
+CVE-2023-51961 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbal ...)
+	TODO: check
+CVE-2023-51960 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan ...)
+	TODO: check
+CVE-2023-51959 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpv ...)
+	TODO: check
+CVE-2023-51958 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port  ...)
+	TODO: check
+CVE-2023-51957 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode  ...)
+	TODO: check
+CVE-2023-51956 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan ...)
+	TODO: check
+CVE-2023-51955 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbal ...)
+	TODO: check
+CVE-2023-51954 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port  ...)
+	TODO: check
+CVE-2023-51953 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode  ...)
+	TODO: check
+CVE-2023-51952 (Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpv ...)
+	TODO: check
+CVE-2023-51252 (PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because fil ...)
+	TODO: check
+CVE-2023-51195
+	REJECTED
+CVE-2023-50916 (Kyocera Device Manager before 3.1.1213.0 allows NTLM credential exposu ...)
+	TODO: check
+CVE-2023-50172 (A recovery notification bypass vulnerability exists in the userRecover ...)
+	TODO: check
+CVE-2023-50120 (MP4Box GPAC version 2.3-DEV-rev636-gfbd7e13aa-master was discovered to ...)
+	TODO: check
+CVE-2023-49864 (An information disclosure vulnerability exists in the aVideoEncoderRec ...)
+	TODO: check
+CVE-2023-49863 (An information disclosure vulnerability exists in the aVideoEncoderRec ...)
+	TODO: check
+CVE-2023-49862 (An information disclosure vulnerability exists in the aVideoEncoderRec ...)
+	TODO: check
+CVE-2023-49810 (A login attempt restriction bypass vulnerability exists in the checkLo ...)
+	TODO: check
+CVE-2023-49738 (An information disclosure vulnerability exists in the image404Raw.php  ...)
+	TODO: check
+CVE-2023-49715 (A unrestricted php file upload vulnerability exists in the import.json ...)
+	TODO: check
+CVE-2023-49599 (An insufficient entropy vulnerability exists in the salt generation fu ...)
+	TODO: check
+CVE-2023-49589 (An insufficient entropy vulnerability exists in the userRecoverPass.ph ...)
+	TODO: check
+CVE-2023-49471 (Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus B ...)
+	TODO: check
+CVE-2023-49427 (Buffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remot ...)
+	TODO: check
+CVE-2023-49394 (Zentao versions 4.1.3 and before has a URL redirect vulnerability, whi ...)
+	TODO: check
+CVE-2023-48783 (AnAuthorization Bypass Through User-Controlled Key vulnerability [CWE- ...)
+	TODO: check
+CVE-2023-48730 (A cross-site scripting (xss) vulnerability exists in the navbarMenuAnd ...)
+	TODO: check
+CVE-2023-48728 (A cross-site scripting (xss) vulnerability exists in the functiongetOp ...)
+	TODO: check
+CVE-2023-48266 (The vulnerability allows an unauthenticated remote attacker to perform ...)
+	TODO: check
+CVE-2023-48265 (The vulnerability allows an unauthenticated remote attacker to perform ...)
+	TODO: check
+CVE-2023-48264 (The vulnerability allows an unauthenticated remote attacker to perform ...)
+	TODO: check
+CVE-2023-48263 (The vulnerability allows an unauthenticated remote attacker to perform ...)
+	TODO: check
+CVE-2023-48262 (The vulnerability allows an unauthenticated remote attacker to perform ...)
+	TODO: check
+CVE-2023-48261 (The vulnerability allows a remote unauthenticated attacker to read arb ...)
+	TODO: check
+CVE-2023-48260 (The vulnerability allows a remote unauthenticated attacker to read arb ...)
+	TODO: check
+CVE-2023-48259 (The vulnerability allows a remote unauthenticated attacker to read arb ...)
+	TODO: check
+CVE-2023-48258 (The vulnerability allows a remote attacker to delete arbitrary files o ...)
+	TODO: check
+CVE-2023-48257 (The vulnerability allows a remote attacker to access sensitive data in ...)
+	TODO: check
+CVE-2023-48256 (The vulnerability allows a remote attacker to inject arbitrary HTTP re ...)
+	TODO: check
+CVE-2023-48255 (The vulnerability allows an unauthenticated remote attacker to send ma ...)
+	TODO: check
+CVE-2023-48254 (The vulnerability allows a remote attacker to inject and execute arbit ...)
+	TODO: check
+CVE-2023-48253 (The vulnerability allows a remote authenticated attacker to read or up ...)
+	TODO: check
+CVE-2023-48252 (The vulnerability allows an authenticated remote attacker to perform a ...)
+	TODO: check
+CVE-2023-48251 (The vulnerability allows a remote attacker to authenticate to the SSH  ...)
+	TODO: check
+CVE-2023-48250 (The vulnerability allows a remote attacker to authenticate to the web  ...)
+	TODO: check
+CVE-2023-48249 (The vulnerability allows an authenticated remote attacker to list arbi ...)
+	TODO: check
+CVE-2023-48248 (The vulnerability allows an authenticated remote attacker to upload a  ...)
+	TODO: check
+CVE-2023-48247 (The vulnerability allows an unauthenticated remote attacker to read ar ...)
+	TODO: check
+CVE-2023-48246 (The vulnerability allows a remote attacker to download arbitrary files ...)
+	TODO: check
+CVE-2023-48245 (The vulnerability allows an unauthenticated remote attacker to upload  ...)
+	TODO: check
+CVE-2023-48244 (The vulnerability allows a remote attacker to inject and execute arbit ...)
+	TODO: check
+CVE-2023-48243 (The vulnerability allows a remote attacker to upload arbitrary files i ...)
+	TODO: check
+CVE-2023-48242 (The vulnerability allows an authenticated remote attacker to download  ...)
+	TODO: check
+CVE-2023-47862 (A local file inclusion vulnerability exists in the getLanguageFromBrow ...)
+	TODO: check
+CVE-2023-47861 (A cross-site scripting (xss) vulnerability exists in the channelBody.p ...)
+	TODO: check
+CVE-2023-47171 (An information disclosure vulnerability exists in the aVideoEncoder.js ...)
+	TODO: check
+CVE-2023-46712 (A improper access control in Fortinet FortiPortal version 7.0.0 throug ...)
+	TODO: check
+CVE-2023-45139 (fontTools is a library for manipulating fonts, written in Python. The  ...)
+	TODO: check
+CVE-2023-44250 (An improper privilege management vulnerability [CWE-269] in a Fortinet ...)
+	TODO: check
+CVE-2023-41603 (D-Link R15 before v1.08.02 was discovered to contain no firewall restr ...)
+	TODO: check
+CVE-2023-37934 (An allocation of resources without limits or throttling vulnerability  ...)
+	TODO: check
+CVE-2023-37932 (An improper limitation of a pathname to a restricted directory ('path  ...)
+	TODO: check
+CVE-2023-31488 (Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.264 ...)
+	TODO: check
+CVE-2023-49619 (Concurrent Execution using Shared Resource with Improper Synchronizati ...)
 	NOT-FOR-US: Apache Answer
 CVE-2024-21643 (IdentityModel Extensions for .NET provide assemblies for web developer ...)
 	NOT-FOR-US: IdentityModel Extensions for .NET
@@ -96,6 +268,7 @@ CVE-2023-31446 (In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.
 CVE-2023-6476 (A flaw was found in CRI-O that involves an experimental annotation lea ...)
 	- cri-o <itp> (bug #979702)
 CVE-2024-0333
+	{DSA-5598-1}
 	- chromium 120.0.6099.216-1
 	[buster] - chromium <end-of-life> (see DSA 5046)
 CVE-2024-22370 (In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was  ...)
@@ -303,7 +476,7 @@ CVE-2023-42797 (A vulnerability has been identified in CP-8031 MASTER MODULE (Al
 	NOT-FOR-US: Siemens
 CVE-2022-48618 (The issue was addressed with improved checks. This issue is fixed in m ...)
 	NOT-FOR-US: Apple
-CVE-2023-41056 [Buffer overflow in certain payloads may lead to remote code execution]
+CVE-2023-41056 (Redis is an in-memory database that persists on disk. Redis incorrectl ...)
 	- redis 5:7.0.15-1 (bug #1060316)
 	[bullseye] - redis <not-affected> (Vulnerable code not present)
 	[buster] - redis <not-affected> (Vulnerable code not present)
@@ -2131,7 +2304,7 @@ CVE-2023-51084 (hyavijava v6.0.07.1 was discovered to contain a stack overflow v
 	NOT-FOR-US: hyavijava
 CVE-2023-51080 (The NumberUtil.toBigDecimal method in hutool-core v5.8.23 was discover ...)
 	NOT-FOR-US: Hutool
-CVE-2023-51079 (A TimeOut error exists in the ParseTools.subCompileExpression method i ...)
+CVE-2023-51079 (A long execution time can occur in the ParseTools.subCompileExpression ...)
 	NOT-FOR-US: mvel2
 CVE-2023-51075 (hutool-core v5.8.23 was discovered to contain an infinite loop in the  ...)
 	NOT-FOR-US: Hutool
@@ -41970,8 +42143,8 @@ CVE-2023-29446
 	RESERVED
 CVE-2023-29445
 	RESERVED
-CVE-2023-29444
-	RESERVED
+CVE-2023-29444 (An uncontrolled search path element vulnerability (DLL hijacking) has  ...)
+	TODO: check
 CVE-2023-29443 (Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP  ...)
 	NOT-FOR-US: Zoho ManageEngine
 CVE-2023-29442 (Zoho ManageEngine Applications Manager before 16400 allows proxy.html  ...)
@@ -233093,14 +233266,14 @@ CVE-2020-26632
 	RESERVED
 CVE-2020-26631
 	RESERVED
-CVE-2020-26630
-	RESERVED
-CVE-2020-26629
-	RESERVED
-CVE-2020-26628
-	RESERVED
-CVE-2020-26627
-	RESERVED
+CVE-2020-26630 (A Time-Based SQL Injection vulnerability was discovered in Hospital Ma ...)
+	TODO: check
+CVE-2020-26629 (A JQuery Unrestricted Arbitrary File Upload vulnerability was discover ...)
+	TODO: check
+CVE-2020-26628 (A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital  ...)
+	TODO: check
+CVE-2020-26627 (A Time-Based SQL Injection vulnerability was discovered in Hospital Ma ...)
+	TODO: check
 CVE-2020-26626
 	RESERVED
 CVE-2020-26625 (A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and ea ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d2448eb93c4f4fa4f8442c9ca1e6a243e2cd0cb9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d2448eb93c4f4fa4f8442c9ca1e6a243e2cd0cb9
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240110/f918ce52/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list