Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d93f2d19 by security tracker role at 2025-08-18T20:12:07+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,83 @@
+CVE-2025-7693 (A security issue exists due to improper handling of malformed 
CIP Forw ...)
+       TODO: check
+CVE-2025-55591 (TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to 
contain a comm ...)
+       TODO: check
+CVE-2025-55590 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to 
contain an com ...)
+       TODO: check
+CVE-2025-55589 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to 
contain multip ...)
+       TODO: check
+CVE-2025-55588 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to 
contain a buff ...)
+       TODO: check
+CVE-2025-55587 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to 
contain a buff ...)
+       TODO: check
+CVE-2025-55586 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to 
contain a buff ...)
+       TODO: check
+CVE-2025-55585 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to 
contain an eva ...)
+       TODO: check
+CVE-2025-55584 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to 
contain insecu ...)
+       TODO: check
+CVE-2025-55300 (Komari is a lightweight, self-hosted server monitoring tool 
designed t ...)
+       TODO: check
+CVE-2025-55299 (VaulTLS is a modern solution for managing mTLS (mutual TLS) 
certificat ...)
+       TODO: check
+CVE-2025-55296 (librenms is a community-based GPL-licensed network monitoring 
system.  ...)
+       TODO: check
+CVE-2025-55293 (Meshtastic is an open source mesh networking solution. Prior 
to v2.6.3 ...)
+       TODO: check
+CVE-2025-55291 (Shaarli is a minimalist bookmark manager and link sharing 
service. Pri ...)
+       TODO: check
+CVE-2025-55288 (Genealogy is a family tree PHP application. Prior to 4.4.0, 
Authentica ...)
+       TODO: check
+CVE-2025-55287 (Genealogy is a family tree PHP application. Prior to 4.4.0, 
Authentica ...)
+       TODO: check
+CVE-2025-55283 (aiven-db-migrate is an Aiven database migration tool. Prior to 
1.0.7,  ...)
+       TODO: check
+CVE-2025-55282 (aiven-db-migrate is an Aiven database migration tool. Prior to 
1.0.7,  ...)
+       TODO: check
+CVE-2025-55214 (Copier library and CLI app for rendering project templates. 
From 7.1.0 ...)
+       TODO: check
+CVE-2025-55213 (OpenFGA is a high-performance and flexible 
authorization/permission en ...)
+       TODO: check
+CVE-2025-55205 (Capsule is a multi-tenancy and policy-based framework for 
Kubernetes.  ...)
+       TODO: check
+CVE-2025-55201 (Copier library and CLI app for rendering project templates. 
Prior to 9 ...)
+       TODO: check
+CVE-2025-54421 (NamelessMC is a free, easy to use & powerful website software 
for Mine ...)
+       TODO: check
+CVE-2025-54234 (ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are 
affected  ...)
+       TODO: check
+CVE-2025-54118 (NamelessMC is a free, easy to use & powerful website software 
for Mine ...)
+       TODO: check
+CVE-2025-54117 (NamelessMC is a free, easy to use & powerful website software 
for Mine ...)
+       TODO: check
+CVE-2025-4962 (An Insecure Direct Object Reference (IDOR) vulnerability was 
identifie ...)
+       TODO: check
+CVE-2025-47206 (An out-of-bounds write vulnerability has been reported to 
affect File  ...)
+       TODO: check
+CVE-2025-43733 (A reflected cross-site scripting (XSS) vulnerability in the 
Liferay Po ...)
+       TODO: check
+CVE-2025-43732 (Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 
2025.Q1.0 thro ...)
+       TODO: check
+CVE-2025-43731 (A reflected cross-site scripting (XSS) vulnerability in the 
Liferay Po ...)
+       TODO: check
+CVE-2025-41242 (Spring Framework MVC applications can be vulnerable to a 
\u201cPath Tr ...)
+       TODO: check
+CVE-2025-3639 (Liferay Portal 7.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1 
throug ...)
+       TODO: check
+CVE-2025-36120 (IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an 
authentic ...)
+       TODO: check
+CVE-2025-33100 (IBM Concert Software 1.0.0 through 1.1.0   contains hard-coded 
credent ...)
+       TODO: check
+CVE-2025-33090 (IBM Concert Software 1.0.0 through 1.1.0 could allow a remote 
attacker ...)
+       TODO: check
+CVE-2025-32992 (Thermo Fisher Scientific ePort through 3.0.0 has Incorrect 
Access Cont ...)
+       TODO: check
+CVE-2025-27909 (IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin 
resource sh ...)
+       TODO: check
+CVE-2025-1759 (IBM Concert Software 1.0.0 through 1.1.0 could allow a remote 
attacker ...)
+       TODO: check
+CVE-2024-49827 (IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to 
excessive da ...)
+       TODO: check
 CVE-2025-9109 (A security flaw has been discovered in Portabilis i-Diario up 
to 1.5.0 ...)
        NOT-FOR-US: Portabilis
 CVE-2025-9108 (Affected is an unknown function of the component Login Page. 
The manip ...)
@@ -4034,7 +4114,7 @@ CVE-2025-8519 (A vulnerability classified as problematic 
has been found in givan
        NOT-FOR-US: givanz Vvveb
 CVE-2025-8518 (A vulnerability was found in givanz Vvveb 1.0.5. It has been 
rated as  ...)
        NOT-FOR-US: givanz Vvveb
-CVE-2025-8517 (A vulnerability was found in givanz Vvveb 1.0.6.1. It has been 
declare ...)
+CVE-2025-8517 (A vulnerability was detected in givanz Vvveb 1.0.6.1. Impacted 
is an u ...)
        NOT-FOR-US: givanz Vvveb
 CVE-2025-8516 (A vulnerability was found in Kingdee Cloud-Starry-Sky 
Enterprise Editi ...)
        NOT-FOR-US: Kingdee Cloud-Starry-Sky Enterprise Edition
@@ -5060,6 +5140,7 @@ CVE-2025-43267 (An injection issue was addressed with 
improved validation. This
 CVE-2025-43266 (A permissions issue was addressed with additional 
restrictions. This i ...)
        NOT-FOR-US: Apple
 CVE-2025-43265 (An out-of-bounds read was addressed with improved input 
validation. Th ...)
+       {DSA-5978-1}
        - webkit2gtk 2.48.5-1
        - wpewebkit 2.48.5-1
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in trixie)
@@ -5101,6 +5182,7 @@ CVE-2025-43243 (A permissions issue was addressed with 
additional restrictions.
 CVE-2025-43241 (A permissions issue was addressed with additional 
restrictions. This i ...)
        NOT-FOR-US: Apple
 CVE-2025-43240 (A logic issue was addressed with improved checks. This issue 
is fixed  ...)
+       {DSA-5978-1}
        - webkit2gtk 2.48.5-1
        - wpewebkit 2.48.5-1
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in trixie)
@@ -5124,6 +5206,7 @@ CVE-2025-43230 (The issue was addressed with additional 
permissions checks. This
 CVE-2025-43229 (This issue was addressed through improved state management. 
This issue ...)
        NOT-FOR-US: Apple
 CVE-2025-43228 (The issue was addressed with improved UI. This issue is fixed 
in iOS 1 ...)
+       {DSA-5978-1}
        - webkit2gtk 2.48.5-1
        - wpewebkit 2.48.5-1
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in trixie)
@@ -5131,6 +5214,7 @@ CVE-2025-43228 (The issue was addressed with improved UI. 
This issue is fixed in
        [bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be 
sensibly backported)
        NOTE: https://webkitgtk.org/security/WSA-2025-0005.html
 CVE-2025-43227 (This issue was addressed through improved state management. 
This issue ...)
+       {DSA-5978-1}
        - webkit2gtk 2.48.5-1
        - wpewebkit 2.48.5-1
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in trixie)
@@ -5156,6 +5240,7 @@ CVE-2025-43218 (An out-of-bounds read was addressed with 
improved input validati
 CVE-2025-43217 (The issue was addressed by adding additional logic. This issue 
is fixe ...)
        NOT-FOR-US: Apple
 CVE-2025-43216 (A use-after-free issue was addressed with improved memory 
management.  ...)
+       {DSA-5978-1}
        - webkit2gtk 2.48.5-1
        - wpewebkit 2.48.5-1
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in trixie)
@@ -5169,6 +5254,7 @@ CVE-2025-43214 (The issue was addressed with improved 
memory handling. This issu
 CVE-2025-43213 (The issue was addressed with improved memory handling. This 
issue is f ...)
        NOT-FOR-US: Apple
 CVE-2025-43212 (The issue was addressed with improved memory handling. This 
issue is f ...)
+       {DSA-5978-1}
        - webkit2gtk 2.48.5-1
        - wpewebkit 2.48.5-1
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in trixie)
@@ -5176,6 +5262,7 @@ CVE-2025-43212 (The issue was addressed with improved 
memory handling. This issu
        [bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be 
sensibly backported)
        NOTE: https://webkitgtk.org/security/WSA-2025-0005.html
 CVE-2025-43211 (The issue was addressed with improved memory handling. This 
issue is f ...)
+       {DSA-5978-1}
        - webkit2gtk 2.48.5-1
        - wpewebkit 2.48.5-1
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in trixie)
@@ -5223,6 +5310,7 @@ CVE-2025-31280 (A memory corruption issue was addressed 
with improved validation
 CVE-2025-31279 (A permissions issue was addressed with additional 
restrictions. This i ...)
        NOT-FOR-US: Apple
 CVE-2025-31278 (The issue was addressed with improved memory handling. This 
issue is f ...)
+       {DSA-5978-1}
        - webkit2gtk 2.48.5-1
        - wpewebkit 2.48.5-1
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in trixie)
@@ -5236,6 +5324,7 @@ CVE-2025-31276 (This issue was addressed through improved 
state management. This
 CVE-2025-31275 (A permissions issue was addressed with additional 
restrictions. This i ...)
        NOT-FOR-US: Apple
 CVE-2025-31273 (The issue was addressed with improved memory handling. This 
issue is f ...)
+       {DSA-5978-1}
        - webkit2gtk 2.48.5-1
        - wpewebkit 2.48.5-1
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in trixie)
@@ -6315,7 +6404,7 @@ CVE-2025-29629 (An issue in Gardyn 4 allows a remote 
attacker to obtain sensitiv
        NOT-FOR-US: Gardyn
 CVE-2025-29628 (An issue in Gardyn 4 allows a remote attacker to obtain 
sensitive info ...)
        NOT-FOR-US: Gardyn
-CVE-2024-48730 (An issue in ETSI Open-Source MANO (OSM) v.14.x, v.15.x allows 
a remote ...)
+CVE-2024-48730 (The default configuration in ETSI Open-Source MANO (OSM) 
v.14.x, v.15. ...)
        NOT-FOR-US: ETSI Open-Source MANO (OSM)
 CVE-2024-48729 (An issue in ETSI Open-Source MANO (OSM) 14.0.x before 14.0.3, 
15.0.x b ...)
        NOT-FOR-US: ETSI Open-Source MANO (OSM)
@@ -9130,7 +9219,7 @@ CVE-2025-6965 (There exists a vulnerability in SQLite 
versions before 3.50.2 whe
        [bullseye] - sqlite3 <postponed> (Minor issue)
        NOTE: 
https://www.sqlite.org/src/info/5508b56fd24016c13981ec280ecdd833007c9d8dd595edb295b984c2b487b5c8
 CVE-2025-6558 (Insufficient validation of untrusted input in ANGLE and GPU in 
Google  ...)
-       {DSA-5963-1}
+       {DSA-5978-1 DSA-5963-1}
        - chromium 138.0.7204.157-1
        [bullseye] - chromium <end-of-life> (see #1061268)
        - webkit2gtk 2.48.5-1
@@ -12767,9 +12856,11 @@ CVE-2024-58254
 CVE-2023-50786 (Dradis through 4.16.0 allows referencing external images 
(resources) o ...)
        NOT-FOR-US: Dradis
 CVE-2025-47917 (Mbed TLS before 3.6.4 allows a use-after-free in certain 
situations of ...)
+       {DLA-4274-1}
        - mbedtls 3.6.4-1 (bug #1108791)
        NOTE: 
https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-7.md
 CVE-2025-48965 (Mbed TLS before 3.6.4 has a NULL pointer dereference because 
mbedtls_a ...)
+       {DLA-4274-1}
        - mbedtls 3.6.4-1 (bug #1108790)
        NOTE: 
https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-6.md
 CVE-2025-49087 (In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing 
discrepancy in  ...)
@@ -12855,9 +12946,11 @@ CVE-2025-52776 (Improper Neutralization of Input 
During Web Page Generation ('Cr
 CVE-2025-52718 (Improper Control of Generation of Code ('Code Injection') 
vulnerabilit ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-52497 (Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based 
buffer und ...)
+       {DLA-4274-1}
        - mbedtls 3.6.4-1 (bug #1108786)
        NOTE: 
https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-2.md
 CVE-2025-52496 (Mbed TLS before 3.6.4 has a race condition in AESNI detection 
if certa ...)
+       {DLA-4274-1}
        - mbedtls 3.6.4-1 (bug #1108785)
        NOTE: 
https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-1.md
 CVE-2025-50039 (Missing Authorization vulnerability in vgwort VG WORT METIS 
allows Exp ...)
@@ -34584,8 +34677,8 @@ CVE-2025-32982 (NETSCOUT nGeniusONE before 6.4.0 b2350 
has a Broken Authorizatio
        NOT-FOR-US: NETSCOUT
 CVE-2025-32981 (NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to 
leverage  ...)
        NOT-FOR-US: NETSCOUT
-CVE-2025-32980
-       REJECTED
+CVE-2025-32980 (NETSCOUT nGeniusONE before 6.4.0 P11 b3245 has a Weak Sudo 
Configurati ...)
+       TODO: check
 CVE-2025-32979 (NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File 
Creation  ...)
        NOT-FOR-US: NETSCOUT
 CVE-2025-2907 (The Order Delivery Date WordPress plugin before 12.3.1 does not 
have a ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d93f2d19639bda7a73115e5bdd8cecd6134d3ee0

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d93f2d19639bda7a73115e5bdd8cecd6134d3ee0
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to