[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Oct 16 01:25:55 BST 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
932dda8c by security tracker role at 2024-10-15T20:12:04+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,4 +1,278 @@
-CVE-2024-47674 [mm: avoid leaving partial pfn mappings around in error case]
+CVE-2024-9986 (A vulnerability was found in code-projects Blood Bank Management Syste ...)
+	TODO: check
+CVE-2024-9985 (Enterprise Cloud Database from Ragic does not properly validate the fi ...)
+	TODO: check
+CVE-2024-9984 (Enterprise Cloud Database from Ragic does not authenticate access to s ...)
+	TODO: check
+CVE-2024-9983 (Enterprise Cloud Database from Ragic does not properly validate a spec ...)
+	TODO: check
+CVE-2024-9979 (A flaw was found in PyO3. This vulnerability causes a use-after-free i ...)
+	TODO: check
+CVE-2024-9977 (A vulnerability, which was classified as critical, was found in MitraS ...)
+	TODO: check
+CVE-2024-9976 (A vulnerability classified as critical has been found in code-projects ...)
+	TODO: check
+CVE-2024-9975 (A vulnerability was found in SourceCodester Drag and Drop Image Upload ...)
+	TODO: check
+CVE-2024-9974 (A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. I ...)
+	TODO: check
+CVE-2024-9973 (A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. I ...)
+	TODO: check
+CVE-2024-9925 (SQL injection vulnerability in TAI Smart Factory's QPLANT SF version 1 ...)
+	TODO: check
+CVE-2024-9895 (The Smart Online Order for Clover plugin for WordPress is vulnerable t ...)
+	TODO: check
+CVE-2024-9676 (A vulnerability was found in Podman, Buildah, and CRI-O. A symlink tra ...)
+	TODO: check
+CVE-2024-9506 (Improper regular expression in Vue's parseHTML function leads to a pot ...)
+	TODO: check
+CVE-2024-5749 (Certain HP DesignJet products may be vulnerable to credential reflecti ...)
+	TODO: check
+CVE-2024-49388 (Sensitive information manipulation due to improper authorization. The  ...)
+	TODO: check
+CVE-2024-49387 (Cleartext transmission of sensitive information in acep-collector serv ...)
+	TODO: check
+CVE-2024-49384 (Excessive attack surface in acep-collector service due to binding to a ...)
+	TODO: check
+CVE-2024-49383 (Excessive attack surface in acep-importer service due to binding to an ...)
+	TODO: check
+CVE-2024-49382 (Excessive attack surface in archive-server service due to binding to a ...)
+	TODO: check
+CVE-2024-49195 (Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkw ...)
+	TODO: check
+CVE-2024-48948 (The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementatio ...)
+	TODO: check
+CVE-2024-48915 (Agent Dart is an agent library built for Internet Computer for Dart an ...)
+	TODO: check
+CVE-2024-48914 (Vendure is an open-source headless commerce platform. Prior to version ...)
+	TODO: check
+CVE-2024-48913 (Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass  ...)
+	TODO: check
+CVE-2024-48624 (In segments\edit.php of DomainMOD below v4.12.0, the segid parameter i ...)
+	TODO: check
+CVE-2024-48623 (In queue\index.php of DomainMOD below v4.12.0, the list_id and domain_ ...)
+	TODO: check
+CVE-2024-48622 (A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows r ...)
+	TODO: check
+CVE-2024-48283 (Phpgurukul User Registration & Login and User Management System 3.2 is ...)
+	TODO: check
+CVE-2024-48282 (A SQL Injection vulnerability was found in /password-recovery.php of P ...)
+	TODO: check
+CVE-2024-48280 (A SQL Injection vulnerability was found in /search-result.php of PHPGu ...)
+	TODO: check
+CVE-2024-48279 (A HTML Injection vulnerability was found in /search-result.php of PHPG ...)
+	TODO: check
+CVE-2024-48278 (Phpgurukul User Registration & Login and User Management System 3.2 is ...)
+	TODO: check
+CVE-2024-47945 (The devices are vulnerable to session hijacking due to insufficient  e ...)
+	TODO: check
+CVE-2024-47944 (The device directly executes .patch firmware upgrade files on a USB st ...)
+	TODO: check
+CVE-2024-47943 (The firmware upgrade function in the admin web interface of the Rittal ...)
+	TODO: check
+CVE-2024-47876 (Sakai is a Collaboration and Learning Environment. Starting in version ...)
+	TODO: check
+CVE-2024-47874 (Starlette is an Asynchronous Server Gateway Interface (ASGI) framework ...)
+	TODO: check
+CVE-2024-47824 (matrix-react-sdk is react-based software development kit for inserting ...)
+	TODO: check
+CVE-2024-47779 (Element is a Matrix web client built using the Matrix React SDK .Eleme ...)
+	TODO: check
+CVE-2024-47771 (Element Desktop is a Matrix client for desktop platforms. Element Desk ...)
+	TODO: check
+CVE-2024-47080 (matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeS ...)
+	TODO: check
+CVE-2024-45276 (An unauthenticated remote attacker can get read access to files in the ...)
+	TODO: check
+CVE-2024-45275 (The devices contain two hard coded user accounts with hardcoded passwo ...)
+	TODO: check
+CVE-2024-45274 (An unauthenticated remote attacker can execute OS commands via UDP on  ...)
+	TODO: check
+CVE-2024-45273 (An unauthenticated local attacker can decrypt the devices config file  ...)
+	TODO: check
+CVE-2024-45272 (An unauthenticated remote attacker can perform a brute-force attack on ...)
+	TODO: check
+CVE-2024-45271 (An unauthenticated local attacker can gain admin privileges by deployi ...)
+	TODO: check
+CVE-2024-44337 (The package `github.com/gomarkdown/markdown` is a Go library for parsi ...)
+	TODO: check
+CVE-2024-41344 (A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attac ...)
+	TODO: check
+CVE-2024-35584 (SQL injection vulnerability in Ajax.php, ForWindow.php, ForExport.php, ...)
+	TODO: check
+CVE-2024-21286 (Vulnerability in the PeopleSoft Enterprise ELM Enterprise Learning Man ...)
+	TODO: check
+CVE-2024-21285 (Vulnerability in the Oracle Banking Liquidity Management product of Or ...)
+	TODO: check
+CVE-2024-21284 (Vulnerability in the Oracle Banking Liquidity Management product of Or ...)
+	TODO: check
+CVE-2024-21283 (Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core pro ...)
+	TODO: check
+CVE-2024-21282 (Vulnerability in the Oracle Financials product of Oracle E-Business Su ...)
+	TODO: check
+CVE-2024-21281 (Vulnerability in the Oracle Banking Liquidity Management product of Or ...)
+	TODO: check
+CVE-2024-21280 (Vulnerability in the Oracle Service Contracts product of Oracle E-Busi ...)
+	TODO: check
+CVE-2024-21279 (Vulnerability in the Oracle Sourcing product of Oracle E-Business Suit ...)
+	TODO: check
+CVE-2024-21278 (Vulnerability in the Oracle Contract Lifecycle Management for Public S ...)
+	TODO: check
+CVE-2024-21277 (Vulnerability in the Oracle MES for Process Manufacturing product of O ...)
+	TODO: check
+CVE-2024-21276 (Vulnerability in the Oracle Work in Process product of Oracle E-Busine ...)
+	TODO: check
+CVE-2024-21275 (Vulnerability in the Oracle Quoting product of Oracle E-Business Suite ...)
+	TODO: check
+CVE-2024-21274 (Vulnerability in the Oracle WebLogic Server product of Oracle Fusion M ...)
+	TODO: check
+CVE-2024-21273 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
+	TODO: check
+CVE-2024-21272 (Vulnerability in the MySQL Connectors product of Oracle MySQL (compone ...)
+	TODO: check
+CVE-2024-21271 (Vulnerability in the Oracle Field Service product of Oracle E-Business ...)
+	TODO: check
+CVE-2024-21270 (Vulnerability in the Oracle Common Applications Calendar product of Or ...)
+	TODO: check
+CVE-2024-21269 (Vulnerability in the Oracle Incentive Compensation product of Oracle E ...)
+	TODO: check
+CVE-2024-21268 (Vulnerability in the Oracle Applications Manager product of Oracle E-B ...)
+	TODO: check
+CVE-2024-21267 (Vulnerability in the Oracle Cost Management product of Oracle E-Busine ...)
+	TODO: check
+CVE-2024-21266 (Vulnerability in the Oracle Advanced Pricing product of Oracle E-Busin ...)
+	TODO: check
+CVE-2024-21265 (Vulnerability in the Oracle Site Hub product of Oracle E-Business Suit ...)
+	TODO: check
+CVE-2024-21264 (Vulnerability in the PeopleSoft Enterprise CC Common Application Objec ...)
+	TODO: check
+CVE-2024-21263 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
+	TODO: check
+CVE-2024-21262 (Vulnerability in the MySQL Connectors product of Oracle MySQL (compone ...)
+	TODO: check
+CVE-2024-21261 (Vulnerability in Oracle Application Express (component: General).  Sup ...)
+	TODO: check
+CVE-2024-21260 (Vulnerability in the Oracle WebLogic Server product of Oracle Fusion M ...)
+	TODO: check
+CVE-2024-21259 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
+	TODO: check
+CVE-2024-21258 (Vulnerability in the Oracle Installed Base product of Oracle E-Busines ...)
+	TODO: check
+CVE-2024-21257 (Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (c ...)
+	TODO: check
+CVE-2024-21255 (Vulnerability in the PeopleSoft Enterprise PeopleTools product of Orac ...)
+	TODO: check
+CVE-2024-21254 (Vulnerability in the Oracle BI Publisher product of Oracle Analytics ( ...)
+	TODO: check
+CVE-2024-21253 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
+	TODO: check
+CVE-2024-21252 (Vulnerability in the Oracle Product Hub product of Oracle E-Business S ...)
+	TODO: check
+CVE-2024-21251 (Vulnerability in the Java VM component of Oracle Database Server.  Sup ...)
+	TODO: check
+CVE-2024-21250 (Vulnerability in the Oracle Process Manufacturing Product Development  ...)
+	TODO: check
+CVE-2024-21249 (Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Ora ...)
+	TODO: check
+CVE-2024-21248 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
+	TODO: check
+CVE-2024-21247 (Vulnerability in the MySQL Client product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21246 (Vulnerability in the Oracle Service Bus product of Oracle Fusion Middl ...)
+	TODO: check
+CVE-2024-21244 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21243 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21242 (Vulnerability in the XML Database component of Oracle Database Server. ...)
+	TODO: check
+CVE-2024-21241 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21239 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21238 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21237 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21236 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21235 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
+	TODO: check
+CVE-2024-21234 (Vulnerability in the Oracle WebLogic Server product of Oracle Fusion M ...)
+	TODO: check
+CVE-2024-21233 (Vulnerability in the Oracle Database Core component of Oracle Database ...)
+	TODO: check
+CVE-2024-21232 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21231 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21230 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21219 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21218 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21217 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
+	TODO: check
+CVE-2024-21216 (Vulnerability in the Oracle WebLogic Server product of Oracle Fusion M ...)
+	TODO: check
+CVE-2024-21215 (Vulnerability in the Oracle WebLogic Server product of Oracle Fusion M ...)
+	TODO: check
+CVE-2024-21214 (Vulnerability in the PeopleSoft Enterprise PeopleTools product of Orac ...)
+	TODO: check
+CVE-2024-21213 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21212 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21211 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
+	TODO: check
+CVE-2024-21210 (Vulnerability in Oracle Java SE (component: Hotspot).  Supported versi ...)
+	TODO: check
+CVE-2024-21209 (Vulnerability in the MySQL Client product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21208 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
+	TODO: check
+CVE-2024-21207 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21206 (Vulnerability in the Oracle Enterprise Command Center Framework produc ...)
+	TODO: check
+CVE-2024-21205 (Vulnerability in the Oracle Service Bus product of Oracle Fusion Middl ...)
+	TODO: check
+CVE-2024-21204 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21203 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21202 (Vulnerability in the PeopleSoft Enterprise PeopleTools product of Orac ...)
+	TODO: check
+CVE-2024-21201 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21200 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21199 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21198 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21197 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21196 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21195 (Vulnerability in the Oracle BI Publisher product of Oracle Analytics ( ...)
+	TODO: check
+CVE-2024-21194 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21193 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
+	TODO: check
+CVE-2024-21192 (Vulnerability in the Oracle Enterprise Manager for Fusion Middleware p ...)
+	TODO: check
+CVE-2024-21191 (Vulnerability in the Oracle Enterprise Manager Fusion Middleware Contr ...)
+	TODO: check
+CVE-2024-21190 (Vulnerability in the Oracle Global Lifecycle Management FMW Installer  ...)
+	TODO: check
+CVE-2024-21172 (Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hosp ...)
+	TODO: check
+CVE-2023-31493 (RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an ...)
+	TODO: check
+CVE-2024-47674 (In the Linux kernel, the following vulnerability has been resolved:  m ...)
 	- linux 6.10.11-1
 	[bookworm] - linux 6.1.112-1
 	NOTE: https://git.kernel.org/linus/79a61cc3fc0466ad2b7b89618a6157785f0293b3 (6.11)
@@ -18,7 +292,7 @@ CVE-2024-9969 (NewType WebEIP v3.0 does not properly validate user input, allowi
 	NOT-FOR-US: NewType
 CVE-2024-9968 (WebEIP v3.0 from   NewTypedoes not properly validate user input, allow ...)
 	NOT-FOR-US: NewType
-CVE-2024-9953 (A Potential DOS Vulnerability exists in CERT VINCE software prior to v ...)
+CVE-2024-9953 (A potential denial-of-service (DoS) vulnerability exists in CERT VINCE ...)
 	NOT-FOR-US: CERT VINCE software
 CVE-2024-9952 (A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 an ...)
 	NOT-FOR-US: SourceCodester Online Eyewear ShopSourceCodester Online Eyewear Shop
@@ -97982,7 +98256,7 @@ CVE-2023-4624 (Server-Side Request Forgery (SSRF) in GitHub repository bookstack
 	NOT-FOR-US: bookstack
 CVE-2023-4600 (The AffiliateWP for WordPress is vulnerable to unauthorized modificati ...)
 	NOT-FOR-US: AffiliateWP for WordPress
-CVE-2023-4571 (In Splunk IT Service Intelligence (ITSI) versions below below 4.13.3,  ...)
+CVE-2023-4571 (In Splunk IT Service Intelligence (ITSI) versions below 4.13.3 or 4.15 ...)
 	NOT-FOR-US: Splunk
 CVE-2023-4209 (The POEditor WordPress plugin before 0.9.8 does not have CSRF checks i ...)
 	NOT-FOR-US: WordPress plugin
@@ -102365,7 +102639,7 @@ CVE-2023-4010 (A flaw was found in the USB Host Controller Driver framework in t
 	- linux <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2227726
 	NOTE: https://github.com/wanrenmi/a-usb-kernel-bug
-CVE-2023-3997 (Splunk SOAR versions lower than 6.1.0 are indirectly affected by a pot ...)
+CVE-2023-3997 (Splunk SOAR versions 6.0.2 and earlier are indirectly affected by a po ...)
 	NOT-FOR-US: Splunk SOAR
 CVE-2023-3983 (An authenticated SQL injection vulnerability exists in Advantech iView ...)
 	NOT-FOR-US: Advantech iView
@@ -139243,7 +139517,7 @@ CVE-2023-22646
 	RESERVED
 CVE-2023-22645 (An Improper Privilege Management vulnerability in SUSE kubewarden allo ...)
 	NOT-FOR-US: kubewarden
-CVE-2023-22644 (An Innsertion of Sensitive Information into Log File vulnerability in  ...)
+CVE-2023-22644 (A user can reverse engineer the JWT token (JSON Web Token) used in aut ...)
 	NOT-FOR-US: SUSE Manager Server Module
 CVE-2023-22643 (An Improper Neutralization of Special Elements used in an OS Command ( ...)
 	NOT-FOR-US: SAP



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/932dda8c17db17f81a5abf794df76e29fd77c98b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/932dda8c17db17f81a5abf794df76e29fd77c98b
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241016/54d24689/attachment.htm>


More information about the debian-security-tracker-commits mailing list