[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Jul 18 09:11:49 BST 2024
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
44c8954c by security tracker role at 2024-07-18T08:11:35+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,4 +1,38 @@
-CVE-2024-41011 [drm/amdkfd: don't allow mapping the MMIO HDP page with large pages]
+CVE-2024-6705 (The RegLevel plugin for WordPress is vulnerable to Stored Cross-Site S ...)
+ TODO: check
+CVE-2024-6599 (The Meks Video Importer plugin for WordPress is vulnerable to unauthor ...)
+ TODO: check
+CVE-2024-6175 (The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for ...)
+ TODO: check
+CVE-2024-6164 (The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Loc ...)
+ TODO: check
+CVE-2024-5964 (The Zenon Lite theme for WordPress is vulnerable to Stored Cross-Site ...)
+ TODO: check
+CVE-2024-5726 (The Timeline Event History plugin for WordPress is vulnerable to PHP O ...)
+ TODO: check
+CVE-2024-41184 (In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived th ...)
+ TODO: check
+CVE-2024-40764 (Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allo ...)
+ TODO: check
+CVE-2024-40492 (Cross Site Scripting vulnerability in Heartbeat Chat v.15.2.1 allows a ...)
+ TODO: check
+CVE-2024-39682 (Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPre ...)
+ TODO: check
+CVE-2024-39681 (Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPre ...)
+ TODO: check
+CVE-2024-39680 (Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPre ...)
+ TODO: check
+CVE-2024-39679 (Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPre ...)
+ TODO: check
+CVE-2024-39678 (Cooked is a recipe plugin for WordPress. The Cooked plugin is vulnerab ...)
+ TODO: check
+CVE-2024-29014 (Vulnerability in SonicWall NetExtender Windows (32 and 64-bit) client ...)
+ TODO: check
+CVE-2023-6708 (The SVG Support plugin for WordPress is vulnerable to Stored Cross-Sit ...)
+ TODO: check
+CVE-2023-43971 (Cross Site Scripting vulnerability in ACG-faka v1.1.7 allows a remote ...)
+ TODO: check
+CVE-2024-41011 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 6.8.11-1
[bookworm] - linux 6.1.94-1
NOTE: https://git.kernel.org/linus/be4a2a81b6b90d1a47eaeaace4cc8e2cb57b96c7 (6.9)
@@ -356,27 +390,35 @@ CVE-2024-41009 (In the Linux kernel, the following vulnerability has been resolv
[bookworm] - linux 6.1.98-1
NOTE: https://git.kernel.org/linus/cfa1a2329a691ffd991fcf7248a57d752e712881 (6.10-rc6)
CVE-2024-6779 (Out of bounds memory access in V8 in Google Chrome prior to 126.0.6478 ...)
+ {DSA-5732-1}
- chromium 126.0.6478.182-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2024-6778 (Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an a ...)
+ {DSA-5732-1}
- chromium 126.0.6478.182-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2024-6777 (Use after free in Navigation in Google Chrome prior to 126.0.6478.182 ...)
+ {DSA-5732-1}
- chromium 126.0.6478.182-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2024-6776 (Use after free in Audio in Google Chrome prior to 126.0.6478.182 allow ...)
+ {DSA-5732-1}
- chromium 126.0.6478.182-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2024-6775 (Use after free in Media Stream in Google Chrome prior to 126.0.6478.18 ...)
+ {DSA-5732-1}
- chromium 126.0.6478.182-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2024-6774 (Use after free in Screen Capture in Google Chrome prior to 126.0.6478. ...)
+ {DSA-5732-1}
- chromium 126.0.6478.182-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2024-6773 (Inappropriate implementation in V8 in Google Chrome prior to 126.0.647 ...)
+ {DSA-5732-1}
- chromium 126.0.6478.182-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2024-6772 (Inappropriate implementation in V8 in Google Chrome prior to 126.0.647 ...)
+ {DSA-5732-1}
- chromium 126.0.6478.182-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2024-6621 (The RSS Aggregator \u2013 RSS Import, News Feeds, Feed to Post, and Au ...)
@@ -185837,7 +185879,7 @@ CVE-2020-36518 (jackson-databind before 2.13.0 allows a Java StackOverflow excep
{DSA-5283-1 DLA-3207-1 DLA-2990-1}
- jackson-databind 2.13.2.2-1 (bug #1007109)
NOTE: https://github.com/FasterXML/jackson-databind/issues/2816
-CVE-2018-25031 (Swagger UI before 4.1.3 could allow a remote attacker to conduct spoof ...)
+CVE-2018-25031 (Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct ...)
- node-swagger-ui <itp> (bug #871461)
- swagger-ui <itp> (bug #895422)
CVE-2022-26850 (When creating or updating credentials for single-user access, Apache N ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/44c8954c270d4792dcf3e8537c0097aefe7e65e0
--
This project does not include diff previews in email notifications.
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/44c8954c270d4792dcf3e8537c0097aefe7e65e0
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240718/fed9acd6/attachment.htm>
More information about the debian-security-tracker-commits
mailing list