[Git][security-tracker-team/security-tracker][master] 2 commits: Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Mar 4 21:22:02 GMT 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e0b2fc90 by Salvatore Bonaccorso at 2025-03-04T22:21:43+01:00
Process some NFUs

- - - - -
c72b30df by Salvatore Bonaccorso at 2025-03-04T22:21:43+01:00
Add CVE-2024-41147/miniaudio

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -41,9 +41,9 @@ CVE-2025-22225 (VMware ESXi contains an arbitrary writevulnerability.A malicious
 CVE-2025-22224 (VMware ESXi, and Workstationcontain a TOCTOU (Time-of-Check Time-of-Us ...)
 	NOT-FOR-US: VMware
 CVE-2025-1969 (Improper request input validation in Temporary Elevated Access Managem ...)
-	TODO: check
+	NOT-FOR-US: Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center
 CVE-2025-1953 (A vulnerability has been found in vLLM AIBrix 0.2.0 and classified as  ...)
-	TODO: check
+	NOT-FOR-US: vLLM AIBrix
 CVE-2025-1952 (A vulnerability, which was classified as critical, was found in PHPGur ...)
 	NOT-FOR-US: PHPGurukul
 CVE-2025-1949 (A vulnerability, which was classified as problematic, has been found i ...)
@@ -88,15 +88,16 @@ CVE-2024-50705 (Unauthenticated reflected cross-site scripting (XSS) vulnerabili
 CVE-2024-50704 (Unauthenticated remote code execution vulnerability in Uniguest Triple ...)
 	NOT-FOR-US: Uniguest Tripleplay
 CVE-2024-41147 (An out-of-bounds write vulnerability exists in the ma_dr_flac__decode_ ...)
-	TODO: check
+	- miniaudio <unfixed>
+	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2024-2063
 CVE-2024-13724 (The Wallet System for WooCommerce \u2013 Wallet, Wallet Cashback, Refu ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-13682 (The Wallet System for WooCommerce \u2013 Wallet, Wallet Cashback, Refu ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-11957 (Improper verification of the digital signature in ksojscore.dll in Kin ...)
-	TODO: check
+	NOT-FOR-US: Kingsoft WPS Office
 CVE-2024-10930 (An Uncontrolled Search Path Element vulnerability exists which could a ...)
-	TODO: check
+	NOT-FOR-US: Carrier
 CVE-2025-1943 (Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2025-14/#CVE-2025-1943
@@ -305,7 +306,7 @@ CVE-2024-58044 (Permission verification bypass vulnerability in the notification
 CVE-2024-58043 (Permission bypass vulnerability in the window module Impact: Successfu ...)
 	NOT-FOR-US: Huawei
 CVE-2024-55064 (Multiple cross-site scripting (XSS) vulnerabilities in EasyVirt DC Net ...)
-	TODO: check
+	NOT-FOR-US: EasyVirt DC NetScope
 CVE-2024-48248 (NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path t ...)
 	NOT-FOR-US: NAKIVO Backup & Replication
 CVE-2024-47262 (Dzmitry Lukyanenka, member of the AXIS OS Bug Bounty Program, has foun ...)
@@ -317,7 +318,7 @@ CVE-2024-47259 (Girishunawane, member of the AXIS OS Bug Bounty Program, has fou
 CVE-2024-13686 (The VW Storefront theme for WordPress is vulnerable to unauthorized mo ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-13685 (The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 r ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-27501 (OpenZiti is a free and open source project focused on bringing zero tr ...)
 	NOT-FOR-US: OpenZiti
 CVE-2025-27500 (OpenZiti is a free and open source project focused on bringing zero tr ...)
@@ -857,43 +858,43 @@ CVE-2024-51944 (There is a stored Cross-site Scripting vulnerability in ArcGIS S
 CVE-2024-51942 (There is a stored Cross-site Scripting vulnerability in ArcGIS Server  ...)
 	NOT-FOR-US: Esri
 CVE-2024-51091 (Cross Site Scripting vulnerability in seajs v.2.2.3 allows a remote at ...)
-	TODO: check
+	NOT-FOR-US: seajs
 CVE-2024-49836 (Memory corruption may occur during the synchronization of the camera`s ...)
 	NOT-FOR-US: Qualcomm
 CVE-2024-47092 (Insecure deserialization and improper certificate validation in Checkm ...)
 	TODO: check
 CVE-2024-45580 (Memory corruption while handling multuple IOCTL calls from userspace f ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2024-43169 (IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2024-43062 (Memory corruption caused by missing locks and checks on the DMA fence  ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2024-43061 (Memory corruption during voice activation, when sound model parameters ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2024-43060 (Memory corruption during voice activation, when sound model parameters ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2024-43059 (Memory corruption while invoking IOCTL calls from the use-space for HG ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2024-43057 (Memory corruption while processing command in Glink linux.)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2024-43056 (Transient DOS during hypervisor virtual I/O operation in a virtual mac ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2024-43055 (Memory corruption while processing camera use case IOCTL call.)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2024-43051 (Information disclosure while deriving keys for a session for any Widev ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2024-41771 (IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2024-41770 (IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2024-38426 (While processing the authentication message in UE, improper authentica ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2024-30154 (HCL SX is vulnerable to cross-site request forgery vulnerability which ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2024-10904 (There is a stored Cross-site Scripting vulnerability in ArcGIS Server  ...)
 	NOT-FOR-US: Esri
 CVE-2023-49031 (Directory Traversal (Local File Inclusion) vulnerability in Tikit (now ...)
-	TODO: check
+	NOT-FOR-US: Tikit (now Advanced) eMarketing platform
 CVE-2024-24778 (Improper privilege management in a REST interface allowed registered u ...)
 	NOT-FOR-US: Apache StreamPipes
 CVE-2025-27590 (In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration ...)
@@ -413732,7 +413733,7 @@ CVE-2020-3123 (A vulnerability in the Data-Loss-Prevention (DLP) module in Clam
 	[jessie] - clamav <not-affected> (Vulnerable code introduced in 0.102.x)
 	NOTE: https://blog.clamav.net/2020/02/clamav-01022-security-patch-released.html
 CVE-2020-3122 (A vulnerability in the web-based management interface of Cisco AsyncOS ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2020-3121 (A vulnerability in the web-based management interface of Cisco Small B ...)
 	NOT-FOR-US: Cisco
 CVE-2020-3120 (A vulnerability in the Cisco Discovery Protocol implementation for Cis ...)
@@ -473742,7 +473743,7 @@ CVE-2019-1817 (A vulnerability in the web proxy functionality of Cisco AsyncOS S
 CVE-2019-1816 (A vulnerability in the log subscription subsystem of the Cisco Web Sec ...)
 	NOT-FOR-US: Cisco
 CVE-2019-1815 (A security vulnerability was discovered in the local status page funct ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2019-1814 (A vulnerability in the interactions between the DHCP and TFTP features ...)
 	NOT-FOR-US: Cisco
 CVE-2019-1813 (A vulnerability in the Image Signature Verification feature of Cisco N ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/6846e00f49232fd83c7c1de89eb01c8c044823c0...c72b30dfcb87082039bb226abca6477d72a2f28b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/6846e00f49232fd83c7c1de89eb01c8c044823c0...c72b30dfcb87082039bb226abca6477d72a2f28b
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250304/521bb2a1/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list