[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 1 09:12:36 BST 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bd533afd by security tracker role at 2024-07-01T08:12:17+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,35 @@
+CVE-2024-6419 (A vulnerability classified as critical was found in SourceCodester Med ...)
+	TODO: check
+CVE-2024-6418 (A vulnerability classified as critical has been found in SourceCodeste ...)
+	TODO: check
+CVE-2024-6417 (A vulnerability was found in SourceCodester Simple Online Bidding Syst ...)
+	TODO: check
+CVE-2024-6416 (A vulnerability was found in SeaCMS 12.9. It has been declared as crit ...)
+	TODO: check
+CVE-2024-6130 (The Form Maker by 10Web  WordPress plugin before 1.15.26 does not sani ...)
+	TODO: check
+CVE-2024-4934 (The Quiz and Survey Master (QSM)  WordPress plugin before 9.0.2 does n ...)
+	TODO: check
+CVE-2024-3123 (CHANGING Mobile One Time Password's uploading function in a hidden pag ...)
+	TODO: check
+CVE-2024-3122 (CHANGING Mobile One Time Password does not properly filter parameters  ...)
+	TODO: check
+CVE-2024-38480 ("Piccoma" App for Android and iOS versions prior to 6.20.0 uses a hard ...)
+	TODO: check
+CVE-2024-34703 (Botan is a C++ cryptography library. X.509 certificates can identify e ...)
+	TODO: check
+CVE-2024-20081 (In gnss service, there is a possible out of bounds write due to improp ...)
+	TODO: check
+CVE-2024-20080 (In gnss service, there is a possible escalation of privilege due to im ...)
+	TODO: check
+CVE-2024-20079 (In gnss service, there is a possible out of bounds write due to improp ...)
+	TODO: check
+CVE-2024-20078 (In venc, there is a possible out of bounds write due to type confusion ...)
+	TODO: check
+CVE-2024-20077 (In Modem, there is a possible system crash due to incorrect error hand ...)
+	TODO: check
+CVE-2024-20076 (In Modem, there is a possible system crash due to incorrect error hand ...)
+	TODO: check
 CVE-2024-5062 (A reflected Cross-Site Scripting (XSS) vulnerability was identified in ...)
 	NOT-FOR-US: zenml
 CVE-2024-35119 (IBM InfoSphere Information Server 11.7 could allow a remote attacker t ...)
@@ -25662,6 +25694,7 @@ CVE-2024-1456 (An S3 bucket takeover vulnerability was identified in the h2oai/h
 CVE-2024-1183 (An SSRF (Server-Side Request Forgery) vulnerability exists in the grad ...)
 	NOT-FOR-US: Gradio
 CVE-2024-1135 (Gunicorn fails to properly validate Transfer-Encoding headers, leading ...)
+	{DLA-3851-1}
 	- gunicorn 22.0.0-1 (bug #1069126)
 	[bookworm] - gunicorn <no-dsa> (Minor issue)
 	[bullseye] - gunicorn <no-dsa> (Minor issue)
@@ -43440,7 +43473,7 @@ CVE-2023-49721 (An insecure default to allow UEFI Shell in EDK2 was left enabled
 	NOTE: https://www.openwall.com/lists/oss-security/2024/02/14/4
 	NOTE: https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139
 CVE-2023-48733 (An insecure default to allow UEFI Shell in EDK2 was left enabled in Ub ...)
-	{DSA-5624-1}
+	{DSA-5624-1 DLA-3852-1}
 	- edk2 2023.11-7
 	NOTE: https://www.openwall.com/lists/oss-security/2024/02/14/4
 	NOTE: https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137
@@ -286141,6 +286174,7 @@ CVE-2020-25831
 CVE-2020-25830 (An issue was discovered in MantisBT before 2.24.3. Improper escaping o ...)
 	- mantis <removed>
 CVE-2020-25829 (An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x befo ...)
+	{DLA-3855-1}
 	- pdns-recursor 4.3.5-1 (bug #972159)
 	[buster] - pdns-recursor <no-dsa> (Minor issue)
 	NOTE: https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-07.html
@@ -313183,6 +313217,7 @@ CVE-2020-14198 (Bitcoin Core 0.20.0 allows remote denial of service.)
 CVE-2020-14197
 	RESERVED
 CVE-2020-14196 (In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1 ...)
+	{DLA-3855-1}
 	- pdns-recursor 4.3.2-1 (low; bug #964103)
 	[buster] - pdns-recursor <postponed> (Minor issue, fix along in next DSA)
 	NOTE: https://www.openwall.com/lists/oss-security/2020/07/01/1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bd533afda8c5c23ea4a9c07bfcb64445448ead8a

-- 
This project does not include diff previews in email notifications.
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bd533afda8c5c23ea4a9c07bfcb64445448ead8a
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240701/54b4d665/attachment.htm>


More information about the debian-security-tracker-commits mailing list