[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 18 21:12:13 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d93f2d19 by security tracker role at 2025-08-18T20:12:07+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,83 @@
+CVE-2025-7693 (A security issue exists due to improper handling of malformed CIP Forw ...)
+	TODO: check
+CVE-2025-55591 (TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a comm ...)
+	TODO: check
+CVE-2025-55590 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an com ...)
+	TODO: check
+CVE-2025-55589 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multip ...)
+	TODO: check
+CVE-2025-55588 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buff ...)
+	TODO: check
+CVE-2025-55587 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buff ...)
+	TODO: check
+CVE-2025-55586 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buff ...)
+	TODO: check
+CVE-2025-55585 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eva ...)
+	TODO: check
+CVE-2025-55584 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecu ...)
+	TODO: check
+CVE-2025-55300 (Komari is a lightweight, self-hosted server monitoring tool designed t ...)
+	TODO: check
+CVE-2025-55299 (VaulTLS is a modern solution for managing mTLS (mutual TLS) certificat ...)
+	TODO: check
+CVE-2025-55296 (librenms is a community-based GPL-licensed network monitoring system.  ...)
+	TODO: check
+CVE-2025-55293 (Meshtastic is an open source mesh networking solution. Prior to v2.6.3 ...)
+	TODO: check
+CVE-2025-55291 (Shaarli is a minimalist bookmark manager and link sharing service. Pri ...)
+	TODO: check
+CVE-2025-55288 (Genealogy is a family tree PHP application. Prior to 4.4.0, Authentica ...)
+	TODO: check
+CVE-2025-55287 (Genealogy is a family tree PHP application. Prior to 4.4.0, Authentica ...)
+	TODO: check
+CVE-2025-55283 (aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7,  ...)
+	TODO: check
+CVE-2025-55282 (aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7,  ...)
+	TODO: check
+CVE-2025-55214 (Copier library and CLI app for rendering project templates. From 7.1.0 ...)
+	TODO: check
+CVE-2025-55213 (OpenFGA is a high-performance and flexible authorization/permission en ...)
+	TODO: check
+CVE-2025-55205 (Capsule is a multi-tenancy and policy-based framework for Kubernetes.  ...)
+	TODO: check
+CVE-2025-55201 (Copier library and CLI app for rendering project templates. Prior to 9 ...)
+	TODO: check
+CVE-2025-54421 (NamelessMC is a free, easy to use & powerful website software for Mine ...)
+	TODO: check
+CVE-2025-54234 (ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected  ...)
+	TODO: check
+CVE-2025-54118 (NamelessMC is a free, easy to use & powerful website software for Mine ...)
+	TODO: check
+CVE-2025-54117 (NamelessMC is a free, easy to use & powerful website software for Mine ...)
+	TODO: check
+CVE-2025-4962 (An Insecure Direct Object Reference (IDOR) vulnerability was identifie ...)
+	TODO: check
+CVE-2025-47206 (An out-of-bounds write vulnerability has been reported to affect File  ...)
+	TODO: check
+CVE-2025-43733 (A reflected cross-site scripting (XSS) vulnerability in the Liferay Po ...)
+	TODO: check
+CVE-2025-43732 (Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 thro ...)
+	TODO: check
+CVE-2025-43731 (A reflected cross-site scripting (XSS) vulnerability in the Liferay Po ...)
+	TODO: check
+CVE-2025-41242 (Spring Framework MVC applications can be vulnerable to a \u201cPath Tr ...)
+	TODO: check
+CVE-2025-3639 (Liferay Portal 7.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1 throug ...)
+	TODO: check
+CVE-2025-36120 (IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authentic ...)
+	TODO: check
+CVE-2025-33100 (IBM Concert Software 1.0.0 through 1.1.0   contains hard-coded credent ...)
+	TODO: check
+CVE-2025-33090 (IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker ...)
+	TODO: check
+CVE-2025-32992 (Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Cont ...)
+	TODO: check
+CVE-2025-27909 (IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sh ...)
+	TODO: check
+CVE-2025-1759 (IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker ...)
+	TODO: check
+CVE-2024-49827 (IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive da ...)
+	TODO: check
 CVE-2025-9109 (A security flaw has been discovered in Portabilis i-Diario up to 1.5.0 ...)
 	NOT-FOR-US: Portabilis
 CVE-2025-9108 (Affected is an unknown function of the component Login Page. The manip ...)
@@ -4034,7 +4114,7 @@ CVE-2025-8519 (A vulnerability classified as problematic has been found in givan
 	NOT-FOR-US: givanz Vvveb
 CVE-2025-8518 (A vulnerability was found in givanz Vvveb 1.0.5. It has been rated as  ...)
 	NOT-FOR-US: givanz Vvveb
-CVE-2025-8517 (A vulnerability was found in givanz Vvveb 1.0.6.1. It has been declare ...)
+CVE-2025-8517 (A vulnerability was detected in givanz Vvveb 1.0.6.1. Impacted is an u ...)
 	NOT-FOR-US: givanz Vvveb
 CVE-2025-8516 (A vulnerability was found in Kingdee Cloud-Starry-Sky Enterprise Editi ...)
 	NOT-FOR-US: Kingdee Cloud-Starry-Sky Enterprise Edition
@@ -5060,6 +5140,7 @@ CVE-2025-43267 (An injection issue was addressed with improved validation. This
 CVE-2025-43266 (A permissions issue was addressed with additional restrictions. This i ...)
 	NOT-FOR-US: Apple
 CVE-2025-43265 (An out-of-bounds read was addressed with improved input validation. Th ...)
+	{DSA-5978-1}
 	- webkit2gtk 2.48.5-1
 	- wpewebkit 2.48.5-1
 	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in trixie)
@@ -5101,6 +5182,7 @@ CVE-2025-43243 (A permissions issue was addressed with additional restrictions.
 CVE-2025-43241 (A permissions issue was addressed with additional restrictions. This i ...)
 	NOT-FOR-US: Apple
 CVE-2025-43240 (A logic issue was addressed with improved checks. This issue is fixed  ...)
+	{DSA-5978-1}
 	- webkit2gtk 2.48.5-1
 	- wpewebkit 2.48.5-1
 	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in trixie)
@@ -5124,6 +5206,7 @@ CVE-2025-43230 (The issue was addressed with additional permissions checks. This
 CVE-2025-43229 (This issue was addressed through improved state management. This issue ...)
 	NOT-FOR-US: Apple
 CVE-2025-43228 (The issue was addressed with improved UI. This issue is fixed in iOS 1 ...)
+	{DSA-5978-1}
 	- webkit2gtk 2.48.5-1
 	- wpewebkit 2.48.5-1
 	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in trixie)
@@ -5131,6 +5214,7 @@ CVE-2025-43228 (The issue was addressed with improved UI. This issue is fixed in
 	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
 	NOTE: https://webkitgtk.org/security/WSA-2025-0005.html
 CVE-2025-43227 (This issue was addressed through improved state management. This issue ...)
+	{DSA-5978-1}
 	- webkit2gtk 2.48.5-1
 	- wpewebkit 2.48.5-1
 	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in trixie)
@@ -5156,6 +5240,7 @@ CVE-2025-43218 (An out-of-bounds read was addressed with improved input validati
 CVE-2025-43217 (The issue was addressed by adding additional logic. This issue is fixe ...)
 	NOT-FOR-US: Apple
 CVE-2025-43216 (A use-after-free issue was addressed with improved memory management.  ...)
+	{DSA-5978-1}
 	- webkit2gtk 2.48.5-1
 	- wpewebkit 2.48.5-1
 	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in trixie)
@@ -5169,6 +5254,7 @@ CVE-2025-43214 (The issue was addressed with improved memory handling. This issu
 CVE-2025-43213 (The issue was addressed with improved memory handling. This issue is f ...)
 	NOT-FOR-US: Apple
 CVE-2025-43212 (The issue was addressed with improved memory handling. This issue is f ...)
+	{DSA-5978-1}
 	- webkit2gtk 2.48.5-1
 	- wpewebkit 2.48.5-1
 	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in trixie)
@@ -5176,6 +5262,7 @@ CVE-2025-43212 (The issue was addressed with improved memory handling. This issu
 	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
 	NOTE: https://webkitgtk.org/security/WSA-2025-0005.html
 CVE-2025-43211 (The issue was addressed with improved memory handling. This issue is f ...)
+	{DSA-5978-1}
 	- webkit2gtk 2.48.5-1
 	- wpewebkit 2.48.5-1
 	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in trixie)
@@ -5223,6 +5310,7 @@ CVE-2025-31280 (A memory corruption issue was addressed with improved validation
 CVE-2025-31279 (A permissions issue was addressed with additional restrictions. This i ...)
 	NOT-FOR-US: Apple
 CVE-2025-31278 (The issue was addressed with improved memory handling. This issue is f ...)
+	{DSA-5978-1}
 	- webkit2gtk 2.48.5-1
 	- wpewebkit 2.48.5-1
 	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in trixie)
@@ -5236,6 +5324,7 @@ CVE-2025-31276 (This issue was addressed through improved state management. This
 CVE-2025-31275 (A permissions issue was addressed with additional restrictions. This i ...)
 	NOT-FOR-US: Apple
 CVE-2025-31273 (The issue was addressed with improved memory handling. This issue is f ...)
+	{DSA-5978-1}
 	- webkit2gtk 2.48.5-1
 	- wpewebkit 2.48.5-1
 	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in trixie)
@@ -6315,7 +6404,7 @@ CVE-2025-29629 (An issue in Gardyn 4 allows a remote attacker to obtain sensitiv
 	NOT-FOR-US: Gardyn
 CVE-2025-29628 (An issue in Gardyn 4 allows a remote attacker to obtain sensitive info ...)
 	NOT-FOR-US: Gardyn
-CVE-2024-48730 (An issue in ETSI Open-Source MANO (OSM) v.14.x, v.15.x allows a remote ...)
+CVE-2024-48730 (The default configuration in ETSI Open-Source MANO (OSM) v.14.x, v.15. ...)
 	NOT-FOR-US: ETSI Open-Source MANO (OSM)
 CVE-2024-48729 (An issue in ETSI Open-Source MANO (OSM) 14.0.x before 14.0.3, 15.0.x b ...)
 	NOT-FOR-US: ETSI Open-Source MANO (OSM)
@@ -9130,7 +9219,7 @@ CVE-2025-6965 (There exists a vulnerability in SQLite versions before 3.50.2 whe
 	[bullseye] - sqlite3 <postponed> (Minor issue)
 	NOTE: https://www.sqlite.org/src/info/5508b56fd24016c13981ec280ecdd833007c9d8dd595edb295b984c2b487b5c8
 CVE-2025-6558 (Insufficient validation of untrusted input in ANGLE and GPU in Google  ...)
-	{DSA-5963-1}
+	{DSA-5978-1 DSA-5963-1}
 	- chromium 138.0.7204.157-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 	- webkit2gtk 2.48.5-1
@@ -12767,9 +12856,11 @@ CVE-2024-58254
 CVE-2023-50786 (Dradis through 4.16.0 allows referencing external images (resources) o ...)
 	NOT-FOR-US: Dradis
 CVE-2025-47917 (Mbed TLS before 3.6.4 allows a use-after-free in certain situations of ...)
+	{DLA-4274-1}
 	- mbedtls 3.6.4-1 (bug #1108791)
 	NOTE: https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-7.md
 CVE-2025-48965 (Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_a ...)
+	{DLA-4274-1}
 	- mbedtls 3.6.4-1 (bug #1108790)
 	NOTE: https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-6.md
 CVE-2025-49087 (In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in  ...)
@@ -12855,9 +12946,11 @@ CVE-2025-52776 (Improper Neutralization of Input During Web Page Generation ('Cr
 CVE-2025-52718 (Improper Control of Generation of Code ('Code Injection') vulnerabilit ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-52497 (Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer und ...)
+	{DLA-4274-1}
 	- mbedtls 3.6.4-1 (bug #1108786)
 	NOTE: https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-2.md
 CVE-2025-52496 (Mbed TLS before 3.6.4 has a race condition in AESNI detection if certa ...)
+	{DLA-4274-1}
 	- mbedtls 3.6.4-1 (bug #1108785)
 	NOTE: https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-1.md
 CVE-2025-50039 (Missing Authorization vulnerability in vgwort VG WORT METIS allows Exp ...)
@@ -34584,8 +34677,8 @@ CVE-2025-32982 (NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorizatio
 	NOT-FOR-US: NETSCOUT
 CVE-2025-32981 (NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage  ...)
 	NOT-FOR-US: NETSCOUT
-CVE-2025-32980
-	REJECTED
+CVE-2025-32980 (NETSCOUT nGeniusONE before 6.4.0 P11 b3245 has a Weak Sudo Configurati ...)
+	TODO: check
 CVE-2025-32979 (NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation  ...)
 	NOT-FOR-US: NETSCOUT
 CVE-2025-2907 (The Order Delivery Date WordPress plugin before 12.3.1 does not have a ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d93f2d19639bda7a73115e5bdd8cecd6134d3ee0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d93f2d19639bda7a73115e5bdd8cecd6134d3ee0
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250818/7249efca/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list