Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 54b4542f by Salvatore Bonaccorso at 2023-10-30T21:20:52+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -1,73 +1,73 @@ CVE-2023-5844 (Unverified Password Change in GitHub repository pimcore/admin-ui-class ...) - TODO: check + NOT-FOR-US: Pimcore admin-ui-classic-bundle CVE-2023-5843 (The Ads by datafeedr.com plugin for WordPress is vulnerable to Remote ...) - TODO: check + NOT-FOR-US: WordPress plugin CVE-2023-5833 (Improper Access Control in GitHub repository mintplex-labs/anything-ll ...) TODO: check CVE-2023-5832 (Improper Input Validation in GitHub repository mintplex-labs/anything- ...) TODO: check CVE-2023-5666 (The Accordion plugin for WordPress is vulnerable to Stored Cross-Site ...) - TODO: check + NOT-FOR-US: WordPress plugin CVE-2023-5583 (The WP Simple Galleries plugin for WordPress is vulnerable to PHP Obje ...) - TODO: check + NOT-FOR-US: WordPress plugin CVE-2023-5566 (The Simple Shortcodes plugin for WordPress is vulnerable to Stored Cro ...) - TODO: check + NOT-FOR-US: WordPress plugin CVE-2023-5565 (The Shortcode Menu plugin for WordPress is vulnerable to Stored Cross- ...) - TODO: check + NOT-FOR-US: WordPress plugin CVE-2023-5362 (The Carousel, Recent Post Slider and Banner Slider plugin for WordPres ...) - TODO: check + NOT-FOR-US: WordPress plugin CVE-2023-5335 (The Buzzsprout Podcasting plugin for WordPress is vulnerable to Stored ...) - TODO: check + NOT-FOR-US: WordPress plugin CVE-2023-5315 (The Google Maps made Simple plugin for WordPress is vulnerable to SQL ...) - TODO: check + NOT-FOR-US: WordPress plugin CVE-2023-5252 (The FareHarbor plugin for WordPress is vulnerable to Stored Cross-Site ...) - TODO: check + NOT-FOR-US: WordPress plugin CVE-2023-5251 (The Grid Plus plugin for WordPress is vulnerable to unauthorized modif ...) - TODO: check + NOT-FOR-US: WordPress plugin CVE-2023-5250 (The Grid Plus plugin for WordPress is vulnerable to Local File Inclusi ...) - TODO: check + NOT-FOR-US: WordPress plugin CVE-2023-5199 (The PHP to Page plugin for WordPress is vulnerable Local File Inclusio ...) - TODO: check + NOT-FOR-US: WordPress plugin CVE-2023-5164 (The Bellows Accordion Menu plugin for WordPress is vulnerable to Store ...) - TODO: check + NOT-FOR-US: WordPress plugin CVE-2023-5049 (The Giveaways and Contests by RafflePress plugin for WordPress is vuln ...) - TODO: check + NOT-FOR-US: WordPress plugin CVE-2023-4964 (Potential open redirect vulnerability in opentext Service Management A ...) TODO: check CVE-2023-47104 (tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell met ...) TODO: check CVE-2023-47101 (The installer (aka openvpn-client-installer) in Securepoint SSL VPN Cl ...) - TODO: check + NOT-FOR-US: Securepoint SSL VPN Client CVE-2023-45780 (In Print Service, there is a possible background activity launch due t ...) - TODO: check + NOT-FOR-US: Android CVE-2023-44323 (Adobe Acrobat for Edge version 118.0.2088.46 (and earlier) is affected ...) - TODO: check + NOT-FOR-US: Adobe CVE-2023-44078 REJECTED CVE-2023-43792 (baserCMS is a website development framework. In versions 4.6.0 through ...) - TODO: check + NOT-FOR-US: baserCMS CVE-2023-43649 (baserCMS is a website development framework. Prior to version 4.8.0, t ...) - TODO: check + NOT-FOR-US: baserCMS CVE-2023-43648 (baserCMS is a website development framework. Prior to version 4.8.0, t ...) - TODO: check + NOT-FOR-US: baserCMS CVE-2023-43647 (baserCMS is a website development framework. Prior to version 4.8.0, t ...) - TODO: check + NOT-FOR-US: baserCMS CVE-2023-42804 (BigBlueButton is an open-source virtual classroom. BigBlueButton prior ...) - TODO: check + NOT-FOR-US: BigBlueButton CVE-2023-42803 (BigBlueButton is an open-source virtual classroom. BigBlueButton prior ...) - TODO: check + NOT-FOR-US: BigBlueButton CVE-2023-42431 (Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension ...) - TODO: check + NOT-FOR-US: BlueSpiceAvatars extension of BlueSpice CVE-2023-41891 (FlyteAdmin is the control plane for Flyte responsible for managing ent ...) - TODO: check + NOT-FOR-US: FlyteAdmin CVE-2023-41605 REJECTED CVE-2023-40943 REJECTED CVE-2023-40101 (In collapse of canonicalize_md.c, there is a possible out of bounds re ...) - TODO: check + NOT-FOR-US: Android CVE-2023-36920 (In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_M ...) - TODO: check + NOT-FOR-US: SAP CVE-2020-36767 (tinyfiledialogs (aka tiny file dialogs) before 3.8.0 allows shell meta ...) TODO: check CVE-2023-5842 (Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/doli ...) @@ -51480,7 +51480,7 @@ CVE-2022-4824 (The WP Blog and Widgets WordPress plugin before 2.3.1 does not va CVE-2022-48190 REJECTED CVE-2022-48189 (An SMM driver input validation vulnerability in the BIOS of some Think ...) - TODO: check + NOT-FOR-US: Lenovo CVE-2022-48188 (A buffer overflow vulnerability in the SecureBootDXE BIOS driver of so ...) NOT-FOR-US: Lenovo CVE-2022-48187 @@ -55041,11 +55041,11 @@ CVE-2022-4577 (The Easy Testimonials WordPress plugin before 3.9.3 does not vali CVE-2022-4576 (The Easy Bootstrap Shortcode WordPress plugin through 4.5.4 does not v ...) NOT-FOR-US: WordPress plugin CVE-2022-4575 (A vulnerability due to improper write protection of UEFI variables was ...) - TODO: check + NOT-FOR-US: Lenovo CVE-2022-4574 (An SMI handler input validation vulnerability in the BIOS of some Thin ...) - TODO: check + NOT-FOR-US: Lenovo CVE-2022-4573 (An SMI handler input validation vulnerability in the ThinkPad X1 Fold ...) - TODO: check + NOT-FOR-US: Lenovo CVE-2022-4572 (A vulnerability, which was classified as problematic, has been found i ...) NOT-FOR-US: UBI reader CVE-2022-4571 (The Seriously Simple Podcasting WordPress plugin before 2.19.1 does no ...) @@ -63858,217 +63858,217 @@ CVE-2023-21400 (In multiple functions of io_uring.c, there is a possible kernel CVE-2023-21399 (there is a possible way to bypass cryptographic assurances due to a lo ...) NOT-FOR-US: Android/Pixel kernel CVE-2023-21398 (In sdksandbox, there is a possible strandhogg style overlay attack due ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21397 (In Setup Wizard, there is a possible way to save a WiFi network due to ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21396 (In Activity Manager, there is a possible background activity launch du ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21395 (In Bluetooth, there is a possible out of bounds read due to a use afte ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21394 (In Telecomm, there is a possible bypass of a multi user security bound ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21393 (In Settings, there is a possible way for the user to change SIM due to ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21392 (In Bluetooth, there is a possible way to corrupt memory due to a use a ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21391 (In Messaging, there is a possible way to disable the messaging applica ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21390 (In Sim, there is a possible way to evade mobile preference restriction ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21389 (In Settings, there is a possible bypass of profile owner restrictions ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21388 (In Settings, there is a possible restriction bypass due to a missing p ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21387 (In User Backup Manager, there is a possible way to leak a token to byp ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21386 RESERVED CVE-2023-21385 (In Whitechapel, there is a possible out of bounds read due to memory c ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21384 (In Package Manager, there is a possible possible permissions bypass du ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21383 (In Settings, there is a possible way for the user to unintentionally s ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21382 (In Content Resolver, there is a possible method to access metadata abo ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21381 (In Media Resource Manager, there is a possible local arbitrary code ex ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21380 (In Bluetooth, there is a possible out of bounds write due to a heap bu ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21379 (In Bluetooth, there is a possible out of bounds read due to a missing ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21378 (In Telecomm, there is a possible way to silence the ring for calls of ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21377 (In SELinux Policy, there is a possible restriction bypass due to a per ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21376 (In Telephony, there is a possible way to retrieve the ICCID due to a l ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21375 (In Sysproxy, there is a possible out of bounds write due to an integer ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21374 (In System UI, there is a possible factory reset protection bypass due ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21373 (In Telephony, there is a possible way for a guest user to change the p ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21372 (In libdexfile, there is a possible out of bounds read due to a missing ...) TODO: check CVE-2023-21371 (In Secure Element, there is a possible out of bounds write due to an i ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21370 (In the Security Element API, there is a possible out of bounds write d ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21369 (In Usage Access, there is a possible way to display a Settings usage a ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21368 (In Audio, there is a possible out of bounds read due to missing bounds ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21367 (In Scudo, there is a possible way to exploit certain heap OOB read/wri ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21366 (In Scudo, there is a possible way for an attacker to predict heap allo ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21365 (In Contacts, there is a possible crash loop due to resource exhaustion ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21364 (In ContactsProvider, there is a possible crash loop due to resource ex ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21363 RESERVED CVE-2023-21362 (In Usage, there is a possible permanent DoS due to resource exhaustion ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21361 (In Bluetooth, there is a possibility of code-execution due to a use af ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21360 (In Bluetooth, there is a possible out of bounds write due to improper ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21359 (In Bluetooth, there is a possible out of bounds read due to a missing ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21358 (In UWB Google, there is a possible way for a malicious app to masquera ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21357 (In NFC, there is a possible out of bounds read due to a missing bounds ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21356 (In Bluetooth, there is a possible out of bounds write due to a missing ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21355 (In libaudioclient, there is a possible out of bounds write due to a us ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21354 (In Package Manager Service, there is a possible way to determine wheth ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21353 (In NFA, there is a possible out of bounds read due to a missing bounds ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21352 (In NFA, there is a possible out of bounds read due to a missing bounds ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21351 (In Activity Manager, there is a possible background activity launch du ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21350 (In Media Projection, there is a possible way to determine whether an a ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21349 (In Package Manager, there is a possible way to determine whether an ap ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21348 (In Window Manager, there is a possible way to determine whether an app ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21347 (In Bluetooth, there is a possible out of bounds read due to a missing ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21346 (In the Device Idle Controller, there is a possible way to determine wh ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21345 (In Game Manager Service, there is a possible way to determine whether ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21344 (In Job Scheduler, there is a possible way to determine whether an app ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21343 (In ActivityStarter, there is a possible background activity launch due ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21342 (In Speech, there is a possible way to bypass background activity launc ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21341 (In Permission Manager, there is a possible way to bypass required perm ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21340 (In Telecomm, there is a possible way to get the call state due to a mi ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21339 (In Minikin, there is a possible way to trigger ANR by showing a malici ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21338 (In Input Method, there is a possible way to determine whether an app i ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21337 (In InputMethod, there is a possible way to determine whether an app is ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21336 (In Input Method, there is a possible way to determine whether an app i ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21335 (In Settings, there is a possible way to determine whether an app is in ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21334 (In App Ops Service, there is a possible disclosure of information abou ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21333 (In Text Services, there is a possible way to determine whether an app ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21332 (In Text Services, there is a possible way to determine whether an app ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21331 (In InputMethod, there is a possible way to determine whether an app is ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21330 (In Overlay Manager, there is a possible way to determine whether an ap ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21329 (In Activity Manager, there is a possible way to determine whether an a ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21328 (In Package Installer, there is a possible way to determine whether an ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21327 (In Permission Manager, there is a possible way to determine whether an ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21326 (In Package Manager Service, there is a possible way to determine wheth ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21325 (In Settings, there is a possible way to determine whether an app is in ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21324 (In Package Installer, there is a possible way to determine whether an ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21323 (In Activity Manager, there is a possible way to determine whether an a ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21322 RESERVED CVE-2023-21321 (In Package Manager, there is a possible cross-user settings disclosure ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21320 (In Device Policy, there is a possible way to verify if a particular ad ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21319 (In UsageStatsService, there is a possible way to read installed 3rd pa ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21318 (In Content, there is a possible way to determine whether an app is ins ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21317 (In ContentService, there is a possible way to determine whether an app ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21316 (In Content, there is a possible way to determine whether an app is ins ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21315 (In Bluetooth, there is a possible out of bounds read due to a heap buf ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21314 (In Bluetooth, there is a possible out of bounds read due to a missing ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21313 (In Core, there is a possible way to forward calls without user knowled ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21312 (In IntentResolver, there is a possible cross-user media read due to a ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21311 (In Settings, there is a possible way to control private DNS settings f ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21310 (In Bluetooth, there is a possible out of bounds write due to a heap bu ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21309 (In libcore, there is a possible out of bounds read due to a missing bo ...) TODO: check CVE-2023-21308 (In Composer, there is a possible out of bounds read due to a missing b ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21307 (In Bluetooth, there is a possible way for a paired Bluetooth device to ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21306 (In ContentService, there is a possible way to read installed sync cont ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21305 (In Content, there is a possible way to determine whether an app is ins ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21304 (In Content Service, there is a possible way to determine whether an ap ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21303 (In Content, here is a possible way to determine whether an app is inst ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21302 (In Package Manager, there is a possible way to determine whether an ap ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21301 (In ActivityManagerService, there is a possible way to determine whethe ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21300 (In PackageManager, there is a possible way to determine whether an app ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21299 (In Package Manager, there is a possible way to determine whether an ap ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21298 (In Slice, there is a possible disclosure of installed applications due ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21297 (In SEPolicy, there is a possible way to access the factory MAC address ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21296 (In Permission, there is a possible way to determine whether an app is ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21295 (In SliceManagerService, there is a possible way to check if a content ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21294 (In Slice, there is a possible disclosure of installed packages due to ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21293 (In PackageManagerNative, there is a possible way to determine whether ...) - TODO: check + NOT-FOR-US: Android CVE-2023-21292 (In openContentUri of ActivityManagerService.java, there is a possible ...) NOT-FOR-US: Android CVE-2023-21291 (In visitUris of Notification.java, there is a possible way to reveal i ...) @@ -146219,7 +146219,7 @@ CVE-2022-20533 (In getSlice of WifiSlice.java, there is a possible way to connec CVE-2022-20532 (In parseTrackFragmentRun() of MPEG4Extractor.cpp, there is a possible ...) NOT-FOR-US: Android CVE-2022-20531 (In Telecom, there is a possible way to determine whether an app is ins ...) - TODO: check + NOT-FOR-US: Android CVE-2022-20530 (In strings.xml, there is a possible permission bypass due to a mislead ...) NOT-FOR-US: Android CVE-2022-20529 (In multiple locations of WifiDialogActivity.java, there is a possible ...) @@ -146776,7 +146776,7 @@ CVE-2022-20266 (In Companion, there is a possible way to keep a service running CVE-2022-20265 (In Settings, there is a possible way to bypass factory reset permissio ...) NOT-FOR-US: Android CVE-2022-20264 (In Usage Stats Service, there is a possible way to determine whether a ...) - TODO: check + NOT-FOR-US: Android CVE-2022-20263 (In ActivityManager, there is a way to read process state for other use ...) NOT-FOR-US: Android CVE-2022-20262 (In ActivityManager, there is a possible way to check another process's ...) @@ -154324,7 +154324,7 @@ CVE-2021-39812 (In TBD of TBD, there is a possible out of bounds read due to a u CVE-2021-39811 RESERVED CVE-2021-39810 (In NFC, there is a possible way to setup a default contactless payment ...) - TODO: check + NOT-FOR-US: Android CVE-2021-39809 (In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible o ...) NOT-FOR-US: Android CVE-2021-39808 (In createNotificationChannelGroup of PreferencesHelper.java, there is ...) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/54b4542f9c3c9c09d15632390142da9c6f1d6f24 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/54b4542f9c3c9c09d15632390142da9c6f1d6f24 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits