Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
d93f2d19 by security tracker role at 2025-08-18T20:12:07+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,83 @@
+CVE-2025-7693 (A security issue exists due to improper handling of malformed
CIP Forw ...)
+ TODO: check
+CVE-2025-55591 (TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to
contain a comm ...)
+ TODO: check
+CVE-2025-55590 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to
contain an com ...)
+ TODO: check
+CVE-2025-55589 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to
contain multip ...)
+ TODO: check
+CVE-2025-55588 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to
contain a buff ...)
+ TODO: check
+CVE-2025-55587 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to
contain a buff ...)
+ TODO: check
+CVE-2025-55586 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to
contain a buff ...)
+ TODO: check
+CVE-2025-55585 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to
contain an eva ...)
+ TODO: check
+CVE-2025-55584 (TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to
contain insecu ...)
+ TODO: check
+CVE-2025-55300 (Komari is a lightweight, self-hosted server monitoring tool
designed t ...)
+ TODO: check
+CVE-2025-55299 (VaulTLS is a modern solution for managing mTLS (mutual TLS)
certificat ...)
+ TODO: check
+CVE-2025-55296 (librenms is a community-based GPL-licensed network monitoring
system. ...)
+ TODO: check
+CVE-2025-55293 (Meshtastic is an open source mesh networking solution. Prior
to v2.6.3 ...)
+ TODO: check
+CVE-2025-55291 (Shaarli is a minimalist bookmark manager and link sharing
service. Pri ...)
+ TODO: check
+CVE-2025-55288 (Genealogy is a family tree PHP application. Prior to 4.4.0,
Authentica ...)
+ TODO: check
+CVE-2025-55287 (Genealogy is a family tree PHP application. Prior to 4.4.0,
Authentica ...)
+ TODO: check
+CVE-2025-55283 (aiven-db-migrate is an Aiven database migration tool. Prior to
1.0.7, ...)
+ TODO: check
+CVE-2025-55282 (aiven-db-migrate is an Aiven database migration tool. Prior to
1.0.7, ...)
+ TODO: check
+CVE-2025-55214 (Copier library and CLI app for rendering project templates.
From 7.1.0 ...)
+ TODO: check
+CVE-2025-55213 (OpenFGA is a high-performance and flexible
authorization/permission en ...)
+ TODO: check
+CVE-2025-55205 (Capsule is a multi-tenancy and policy-based framework for
Kubernetes. ...)
+ TODO: check
+CVE-2025-55201 (Copier library and CLI app for rendering project templates.
Prior to 9 ...)
+ TODO: check
+CVE-2025-54421 (NamelessMC is a free, easy to use & powerful website software
for Mine ...)
+ TODO: check
+CVE-2025-54234 (ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are
affected ...)
+ TODO: check
+CVE-2025-54118 (NamelessMC is a free, easy to use & powerful website software
for Mine ...)
+ TODO: check
+CVE-2025-54117 (NamelessMC is a free, easy to use & powerful website software
for Mine ...)
+ TODO: check
+CVE-2025-4962 (An Insecure Direct Object Reference (IDOR) vulnerability was
identifie ...)
+ TODO: check
+CVE-2025-47206 (An out-of-bounds write vulnerability has been reported to
affect File ...)
+ TODO: check
+CVE-2025-43733 (A reflected cross-site scripting (XSS) vulnerability in the
Liferay Po ...)
+ TODO: check
+CVE-2025-43732 (Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP
2025.Q1.0 thro ...)
+ TODO: check
+CVE-2025-43731 (A reflected cross-site scripting (XSS) vulnerability in the
Liferay Po ...)
+ TODO: check
+CVE-2025-41242 (Spring Framework MVC applications can be vulnerable to a
\u201cPath Tr ...)
+ TODO: check
+CVE-2025-3639 (Liferay Portal 7.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1
throug ...)
+ TODO: check
+CVE-2025-36120 (IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an
authentic ...)
+ TODO: check
+CVE-2025-33100 (IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded
credent ...)
+ TODO: check
+CVE-2025-33090 (IBM Concert Software 1.0.0 through 1.1.0 could allow a remote
attacker ...)
+ TODO: check
+CVE-2025-32992 (Thermo Fisher Scientific ePort through 3.0.0 has Incorrect
Access Cont ...)
+ TODO: check
+CVE-2025-27909 (IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin
resource sh ...)
+ TODO: check
+CVE-2025-1759 (IBM Concert Software 1.0.0 through 1.1.0 could allow a remote
attacker ...)
+ TODO: check
+CVE-2024-49827 (IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to
excessive da ...)
+ TODO: check
CVE-2025-9109 (A security flaw has been discovered in Portabilis i-Diario up
to 1.5.0 ...)
NOT-FOR-US: Portabilis
CVE-2025-9108 (Affected is an unknown function of the component Login Page.
The manip ...)
@@ -4034,7 +4114,7 @@ CVE-2025-8519 (A vulnerability classified as problematic
has been found in givan
NOT-FOR-US: givanz Vvveb
CVE-2025-8518 (A vulnerability was found in givanz Vvveb 1.0.5. It has been
rated as ...)
NOT-FOR-US: givanz Vvveb
-CVE-2025-8517 (A vulnerability was found in givanz Vvveb 1.0.6.1. It has been
declare ...)
+CVE-2025-8517 (A vulnerability was detected in givanz Vvveb 1.0.6.1. Impacted
is an u ...)
NOT-FOR-US: givanz Vvveb
CVE-2025-8516 (A vulnerability was found in Kingdee Cloud-Starry-Sky
Enterprise Editi ...)
NOT-FOR-US: Kingdee Cloud-Starry-Sky Enterprise Edition
@@ -5060,6 +5140,7 @@ CVE-2025-43267 (An injection issue was addressed with
improved validation. This
CVE-2025-43266 (A permissions issue was addressed with additional
restrictions. This i ...)
NOT-FOR-US: Apple
CVE-2025-43265 (An out-of-bounds read was addressed with improved input
validation. Th ...)
+ {DSA-5978-1}
- webkit2gtk 2.48.5-1
- wpewebkit 2.48.5-1
[trixie] - wpewebkit <ignored> (wpewebkit not covered by security
support in trixie)
@@ -5101,6 +5182,7 @@ CVE-2025-43243 (A permissions issue was addressed with
additional restrictions.
CVE-2025-43241 (A permissions issue was addressed with additional
restrictions. This i ...)
NOT-FOR-US: Apple
CVE-2025-43240 (A logic issue was addressed with improved checks. This issue
is fixed ...)
+ {DSA-5978-1}
- webkit2gtk 2.48.5-1
- wpewebkit 2.48.5-1
[trixie] - wpewebkit <ignored> (wpewebkit not covered by security
support in trixie)
@@ -5124,6 +5206,7 @@ CVE-2025-43230 (The issue was addressed with additional
permissions checks. This
CVE-2025-43229 (This issue was addressed through improved state management.
This issue ...)
NOT-FOR-US: Apple
CVE-2025-43228 (The issue was addressed with improved UI. This issue is fixed
in iOS 1 ...)
+ {DSA-5978-1}
- webkit2gtk 2.48.5-1
- wpewebkit 2.48.5-1
[trixie] - wpewebkit <ignored> (wpewebkit not covered by security
support in trixie)
@@ -5131,6 +5214,7 @@ CVE-2025-43228 (The issue was addressed with improved UI.
This issue is fixed in
[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be
sensibly backported)
NOTE: https://webkitgtk.org/security/WSA-2025-0005.html
CVE-2025-43227 (This issue was addressed through improved state management.
This issue ...)
+ {DSA-5978-1}
- webkit2gtk 2.48.5-1
- wpewebkit 2.48.5-1
[trixie] - wpewebkit <ignored> (wpewebkit not covered by security
support in trixie)
@@ -5156,6 +5240,7 @@ CVE-2025-43218 (An out-of-bounds read was addressed with
improved input validati
CVE-2025-43217 (The issue was addressed by adding additional logic. This issue
is fixe ...)
NOT-FOR-US: Apple
CVE-2025-43216 (A use-after-free issue was addressed with improved memory
management. ...)
+ {DSA-5978-1}
- webkit2gtk 2.48.5-1
- wpewebkit 2.48.5-1
[trixie] - wpewebkit <ignored> (wpewebkit not covered by security
support in trixie)
@@ -5169,6 +5254,7 @@ CVE-2025-43214 (The issue was addressed with improved
memory handling. This issu
CVE-2025-43213 (The issue was addressed with improved memory handling. This
issue is f ...)
NOT-FOR-US: Apple
CVE-2025-43212 (The issue was addressed with improved memory handling. This
issue is f ...)
+ {DSA-5978-1}
- webkit2gtk 2.48.5-1
- wpewebkit 2.48.5-1
[trixie] - wpewebkit <ignored> (wpewebkit not covered by security
support in trixie)
@@ -5176,6 +5262,7 @@ CVE-2025-43212 (The issue was addressed with improved
memory handling. This issu
[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be
sensibly backported)
NOTE: https://webkitgtk.org/security/WSA-2025-0005.html
CVE-2025-43211 (The issue was addressed with improved memory handling. This
issue is f ...)
+ {DSA-5978-1}
- webkit2gtk 2.48.5-1
- wpewebkit 2.48.5-1
[trixie] - wpewebkit <ignored> (wpewebkit not covered by security
support in trixie)
@@ -5223,6 +5310,7 @@ CVE-2025-31280 (A memory corruption issue was addressed
with improved validation
CVE-2025-31279 (A permissions issue was addressed with additional
restrictions. This i ...)
NOT-FOR-US: Apple
CVE-2025-31278 (The issue was addressed with improved memory handling. This
issue is f ...)
+ {DSA-5978-1}
- webkit2gtk 2.48.5-1
- wpewebkit 2.48.5-1
[trixie] - wpewebkit <ignored> (wpewebkit not covered by security
support in trixie)
@@ -5236,6 +5324,7 @@ CVE-2025-31276 (This issue was addressed through improved
state management. This
CVE-2025-31275 (A permissions issue was addressed with additional
restrictions. This i ...)
NOT-FOR-US: Apple
CVE-2025-31273 (The issue was addressed with improved memory handling. This
issue is f ...)
+ {DSA-5978-1}
- webkit2gtk 2.48.5-1
- wpewebkit 2.48.5-1
[trixie] - wpewebkit <ignored> (wpewebkit not covered by security
support in trixie)
@@ -6315,7 +6404,7 @@ CVE-2025-29629 (An issue in Gardyn 4 allows a remote
attacker to obtain sensitiv
NOT-FOR-US: Gardyn
CVE-2025-29628 (An issue in Gardyn 4 allows a remote attacker to obtain
sensitive info ...)
NOT-FOR-US: Gardyn
-CVE-2024-48730 (An issue in ETSI Open-Source MANO (OSM) v.14.x, v.15.x allows
a remote ...)
+CVE-2024-48730 (The default configuration in ETSI Open-Source MANO (OSM)
v.14.x, v.15. ...)
NOT-FOR-US: ETSI Open-Source MANO (OSM)
CVE-2024-48729 (An issue in ETSI Open-Source MANO (OSM) 14.0.x before 14.0.3,
15.0.x b ...)
NOT-FOR-US: ETSI Open-Source MANO (OSM)
@@ -9130,7 +9219,7 @@ CVE-2025-6965 (There exists a vulnerability in SQLite
versions before 3.50.2 whe
[bullseye] - sqlite3 <postponed> (Minor issue)
NOTE:
https://www.sqlite.org/src/info/5508b56fd24016c13981ec280ecdd833007c9d8dd595edb295b984c2b487b5c8
CVE-2025-6558 (Insufficient validation of untrusted input in ANGLE and GPU in
Google ...)
- {DSA-5963-1}
+ {DSA-5978-1 DSA-5963-1}
- chromium 138.0.7204.157-1
[bullseye] - chromium <end-of-life> (see #1061268)
- webkit2gtk 2.48.5-1
@@ -12767,9 +12856,11 @@ CVE-2024-58254
CVE-2023-50786 (Dradis through 4.16.0 allows referencing external images
(resources) o ...)
NOT-FOR-US: Dradis
CVE-2025-47917 (Mbed TLS before 3.6.4 allows a use-after-free in certain
situations of ...)
+ {DLA-4274-1}
- mbedtls 3.6.4-1 (bug #1108791)
NOTE:
https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-7.md
CVE-2025-48965 (Mbed TLS before 3.6.4 has a NULL pointer dereference because
mbedtls_a ...)
+ {DLA-4274-1}
- mbedtls 3.6.4-1 (bug #1108790)
NOTE:
https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-6.md
CVE-2025-49087 (In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing
discrepancy in ...)
@@ -12855,9 +12946,11 @@ CVE-2025-52776 (Improper Neutralization of Input
During Web Page Generation ('Cr
CVE-2025-52718 (Improper Control of Generation of Code ('Code Injection')
vulnerabilit ...)
NOT-FOR-US: WordPress plugin
CVE-2025-52497 (Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based
buffer und ...)
+ {DLA-4274-1}
- mbedtls 3.6.4-1 (bug #1108786)
NOTE:
https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-2.md
CVE-2025-52496 (Mbed TLS before 3.6.4 has a race condition in AESNI detection
if certa ...)
+ {DLA-4274-1}
- mbedtls 3.6.4-1 (bug #1108785)
NOTE:
https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-1.md
CVE-2025-50039 (Missing Authorization vulnerability in vgwort VG WORT METIS
allows Exp ...)
@@ -34584,8 +34677,8 @@ CVE-2025-32982 (NETSCOUT nGeniusONE before 6.4.0 b2350
has a Broken Authorizatio
NOT-FOR-US: NETSCOUT
CVE-2025-32981 (NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to
leverage ...)
NOT-FOR-US: NETSCOUT
-CVE-2025-32980
- REJECTED
+CVE-2025-32980 (NETSCOUT nGeniusONE before 6.4.0 P11 b3245 has a Weak Sudo
Configurati ...)
+ TODO: check
CVE-2025-32979 (NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File
Creation ...)
NOT-FOR-US: NETSCOUT
CVE-2025-2907 (The Order Delivery Date WordPress plugin before 12.3.1 does not
have a ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d93f2d19639bda7a73115e5bdd8cecd6134d3ee0
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d93f2d19639bda7a73115e5bdd8cecd6134d3ee0
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits