diff options
author | security tracker role <sectracker@soriano.debian.org> | 2020-06-04 08:10:24 +0000 |
---|---|---|
committer | security tracker role <sectracker@soriano.debian.org> | 2020-06-04 08:10:24 +0000 |
commit | 93a48b01ebc8a4e0e67ef869020b06ae0ed807ef (patch) | |
tree | 544e8ad3917a5a42c22ee85b31f32719d06f4c61 | |
parent | d9c6d7118378bc2c0120b422883c725f0f1cc3f3 (diff) |
automatic update
-rw-r--r-- | data/CVE/list.2011 | 8 | ||||
-rw-r--r-- | data/CVE/list.2018 | 20 | ||||
-rw-r--r-- | data/CVE/list.2019 | 50 | ||||
-rw-r--r-- | data/CVE/list.2020 | 158 |
4 files changed, 176 insertions, 60 deletions
diff --git a/data/CVE/list.2011 b/data/CVE/list.2011 index 257b1a3d42..125be0fe17 100644 --- a/data/CVE/list.2011 +++ b/data/CVE/list.2011 @@ -6399,8 +6399,8 @@ CVE-2011-2864 (Google Chrome before 14.0.835.163 does not properly handle Tibeta - chromium-browser 14.0.835.163~r101024-1 [squeeze] - chromium-browser <not-affected> - webkit <not-affected> (chromium specific) -CVE-2011-2863 - RESERVED +CVE-2011-2863 (Insufficient policy enforcement in V8 in Google Chrome prior to 14.0.0 ...) + TODO: check CVE-2011-2862 (Google V8, as used in Google Chrome before 14.0.835.163, does not prop ...) - chromium-browser 14.0.835.163~r101024-1 [squeeze] - chromium-browser <not-affected> @@ -9252,8 +9252,8 @@ CVE-2011-1806 (Google Chrome before 11.0.696.71 does not properly implement the - chromium-browser 11.0.696.71~r86024-1 [squeeze] - chromium-browser <not-affected> - webkit <not-affected> (chromium specific) -CVE-2011-1805 - RESERVED +CVE-2011-1805 (Bad cast in CSS in Google Chrome prior to 11.0.0.0 allowed a remote at ...) + TODO: check CVE-2011-1804 (rendering/RenderBox.cpp in WebCore in WebKit before r86862, as used in ...) - chromium-browser 11.0.696.71~r86024-1 [squeeze] - chromium-browser <not-affected> diff --git a/data/CVE/list.2018 b/data/CVE/list.2018 index 9f849ce693..3ff8fe854c 100644 --- a/data/CVE/list.2018 +++ b/data/CVE/list.2018 @@ -1,3 +1,23 @@ +CVE-2018-21244 + RESERVED +CVE-2018-21243 + RESERVED +CVE-2018-21242 + RESERVED +CVE-2018-21241 + RESERVED +CVE-2018-21240 + RESERVED +CVE-2018-21239 + RESERVED +CVE-2018-21238 + RESERVED +CVE-2018-21237 + RESERVED +CVE-2018-21236 + RESERVED +CVE-2018-21235 + RESERVED CVE-2018-21234 (Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when ...) - jodd <unfixed> (bug #961298) [buster] - jodd <no-dsa> (Minor issue) diff --git a/data/CVE/list.2019 b/data/CVE/list.2019 index cff3ed9524..976e5c2116 100644 --- a/data/CVE/list.2019 +++ b/data/CVE/list.2019 @@ -1,3 +1,53 @@ +CVE-2019-20837 + RESERVED +CVE-2019-20836 + RESERVED +CVE-2019-20835 + RESERVED +CVE-2019-20834 + RESERVED +CVE-2019-20833 + RESERVED +CVE-2019-20832 + RESERVED +CVE-2019-20831 + RESERVED +CVE-2019-20830 + RESERVED +CVE-2019-20829 + RESERVED +CVE-2019-20828 + RESERVED +CVE-2019-20827 + RESERVED +CVE-2019-20826 + RESERVED +CVE-2019-20825 + RESERVED +CVE-2019-20824 + RESERVED +CVE-2019-20823 + RESERVED +CVE-2019-20822 + RESERVED +CVE-2019-20821 + RESERVED +CVE-2019-20820 + RESERVED +CVE-2019-20819 + RESERVED +CVE-2019-20818 + RESERVED +CVE-2019-20817 + RESERVED +CVE-2019-20816 + RESERVED +CVE-2019-20815 + RESERVED +CVE-2019-20814 + RESERVED +CVE-2019-20813 + RESERVED CVE-2019-20812 (An issue was discovered in the Linux kernel before 5.4.7. The prb_calc ...) - linux 5.4.8-1 [buster] - linux 4.19.98-1 diff --git a/data/CVE/list.2020 b/data/CVE/list.2020 index 9de5a2f9b6..118f192b0f 100644 --- a/data/CVE/list.2020 +++ b/data/CVE/list.2020 @@ -1,3 +1,49 @@ +CVE-2020-13815 + RESERVED +CVE-2020-13814 + RESERVED +CVE-2020-13813 + RESERVED +CVE-2020-13812 + RESERVED +CVE-2020-13811 + RESERVED +CVE-2020-13810 + RESERVED +CVE-2020-13809 + RESERVED +CVE-2020-13808 + RESERVED +CVE-2020-13807 + RESERVED +CVE-2020-13806 + RESERVED +CVE-2020-13805 + RESERVED +CVE-2020-13804 + RESERVED +CVE-2020-13803 + RESERVED +CVE-2020-13802 + RESERVED +CVE-2020-13801 + RESERVED +CVE-2020-13799 + RESERVED +CVE-2020-13798 (An issue was discovered in Navigate CMS through 2.8.7. It allows XSS b ...) + TODO: check +CVE-2020-13797 (An issue was discovered in Navigate CMS through 2.8.7. It allows XSS b ...) + TODO: check +CVE-2020-13796 (An issue was discovered in Navigate CMS through 2.8.7. It allows XSS b ...) + TODO: check +CVE-2020-13795 (An issue was discovered in Navigate CMS through 2.8.7. It allows Direc ...) + TODO: check +CVE-2020-13794 + RESERVED +CVE-2020-13793 + RESERVED +CVE-2020-13792 (PlayTube 1.8 allows disclosure of user details via ajax.php?type=../ad ...) + TODO: check CVE-2020-XXXX [Cross-Site Scripting (XSS) vulnerability via malicious XML messages] - roundcube 1.4.5+dfsg.1-1 (bug #962124) NOTE: 1.4.x: https://github.com/roundcube/roundcubemail/commit/ccaccae6653031b809b4347a60021951e19a0e43 @@ -7,6 +53,7 @@ CVE-2020-XXXX [Cross-Site Scripting (XSS) vulnerability in template object 'user NOTE: 1.4.x: https://github.com/roundcube/roundcubemail/commit/4beec65d40c5e5b1f2bace935c110baf05e10ae5 NOTE: 1.3.x: https://github.com/roundcube/roundcubemail/commit/37e2bc745723ef6322f0f785aefd0b9313a40f19 CVE-2020-13800 [ati-vga: infinite recursion in ati_mm_read/write calls may lead to DoS] + RESERVED - qemu <unfixed> [buster] - qemu <not-affected> (Vulnerable code introduced later) [stretch] - qemu <not-affected> (Vulnerable code introduced later) @@ -14,6 +61,7 @@ CVE-2020-13800 [ati-vga: infinite recursion in ati_mm_read/write calls may lead NOTE: https://www.openwall.com/lists/oss-security/2020/06/04/2 NOTE: https://lists.gnu.org/archive/html/qemu-devel/2020-06/msg00833.html CVE-2020-13791 [ati-vga: OOB access while reading PCI configuration may lead to DoS] + RESERVED - qemu <unfixed> [buster] - qemu <not-affected> (Vulnerable code introduced later) [stretch] - qemu <not-affected> (Vulnerable code introduced later) @@ -46,8 +94,7 @@ CVE-2020-13779 RESERVED CVE-2020-13778 RESERVED -CVE-2020-13777 [session resumption works without master key allowing MITM] - RESERVED +CVE-2020-13777 (GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting ...) - gnutls28 <unfixed> NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1843723 NOTE: https://gitlab.com/gnutls/gnutls/-/issues/1011 @@ -6154,14 +6201,14 @@ CVE-2020-11096 RESERVED CVE-2020-11095 RESERVED -CVE-2020-11094 - RESERVED +CVE-2020-11094 (The October CMS debugbar plugin before version 3.1.0 contains a featur ...) + TODO: check CVE-2020-11093 RESERVED CVE-2020-11092 RESERVED -CVE-2020-11091 - RESERVED +CVE-2020-11091 (In Weave Net before version 2.6.3, an attacker able to run a process a ...) + TODO: check CVE-2020-11090 RESERVED CVE-2020-11089 (In FreeRDP before 2.1.0, there is an out-of-bound read in irp function ...) @@ -6205,8 +6252,7 @@ CVE-2020-11082 (In Kaminari before 1.2.1, there is a vulnerability that would al NOTE: https://github.com/kaminari/kaminari/commit/8dd52a1aed3d2fa2835d836de23fc0d8c4ff5db8 CVE-2020-11081 RESERVED -CVE-2020-11080 [HTTP/2 Large Settings Frame DoS] - RESERVED +CVE-2020-11080 (In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS fra ...) - nodejs <unfixed> (bug #962145) [stretch] - nodejs <ignored> (Nodejs in stretch not covered by security support) NOTE: https://nodejs.org/en/blog/vulnerability/june-2020-security-releases/#http-2-large-settings-frame-dos-low-cve-2020-11080 @@ -7751,14 +7797,14 @@ CVE-2020-10551 (QQBrowser before 10.5.3870.400 installs a Windows service TsServ NOT-FOR-US: QQBrowser CVE-2020-10550 RESERVED -CVE-2020-10549 - RESERVED -CVE-2020-10548 - RESERVED -CVE-2020-10547 - RESERVED -CVE-2020-10546 - RESERVED +CVE-2020-10549 (rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.p ...) + TODO: check +CVE-2020-10548 (rConfig 3.9.4 and previous versions has unauthenticated devices.inc.ph ...) + TODO: check +CVE-2020-10547 (rConfig 3.9.4 and previous versions has unauthenticated compliancepoli ...) + TODO: check +CVE-2020-10546 (rConfig 3.9.4 and previous versions has unauthenticated compliancepoli ...) + TODO: check CVE-2020-10545 RESERVED CVE-2020-10544 (An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFac ...) @@ -15520,8 +15566,8 @@ CVE-2020-7032 RESERVED CVE-2020-7031 RESERVED -CVE-2020-7030 - RESERVED +CVE-2020-7030 (A sensitive information disclosure vulnerability was discovered in the ...) + TODO: check CVE-2020-7029 RESERVED CVE-2020-7028 @@ -16764,30 +16810,30 @@ CVE-2020-6506 RESERVED CVE-2020-6505 RESERVED -CVE-2020-6504 - RESERVED -CVE-2020-6503 - RESERVED -CVE-2020-6502 - RESERVED -CVE-2020-6501 - RESERVED -CVE-2020-6500 - RESERVED -CVE-2020-6499 - RESERVED -CVE-2020-6498 - RESERVED -CVE-2020-6497 - RESERVED -CVE-2020-6496 - RESERVED -CVE-2020-6495 - RESERVED -CVE-2020-6494 - RESERVED -CVE-2020-6493 - RESERVED +CVE-2020-6504 (Insufficient policy enforcement in notifications in Google Chrome prio ...) + TODO: check +CVE-2020-6503 (Inappropriate implementation in accessibility in Google Chrome prior t ...) + TODO: check +CVE-2020-6502 (Incorrect implementation in permissions in Google Chrome prior to 80.0 ...) + TODO: check +CVE-2020-6501 (Insufficient policy enforcement in CSP in Google Chrome prior to 80.0. ...) + TODO: check +CVE-2020-6500 (Inappropriate implementation in interstitials in Google Chrome prior t ...) + TODO: check +CVE-2020-6499 (Inappropriate implementation in AppCache in Google Chrome prior to 80. ...) + TODO: check +CVE-2020-6498 (Incorrect implementation in user interface in Google Chrome on iOS pri ...) + TODO: check +CVE-2020-6497 (Insufficient policy enforcement in Omnibox in Google Chrome on iOS pri ...) + TODO: check +CVE-2020-6496 (Use after free in payments in Google Chrome on MacOS prior to 83.0.410 ...) + TODO: check +CVE-2020-6495 (Insufficient policy enforcement in developer tools in Google Chrome pr ...) + TODO: check +CVE-2020-6494 (Incorrect security UI in payments in Google Chrome on Android prior to ...) + TODO: check +CVE-2020-6493 (Use after free in WebAuthentication in Google Chrome prior to 83.0.410 ...) + TODO: check CVE-2020-6492 RESERVED CVE-2020-6491 (Insufficient data validation in site information in Google Chrome prio ...) @@ -16903,8 +16949,8 @@ CVE-2020-6455 (Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044. CVE-2020-6454 (Use after free in extensions in Google Chrome prior to 81.0.4044.92 al ...) - chromium 81.0.4044.92-1 [stretch] - chromium <end-of-life> (see DSA 4562) -CVE-2020-6453 - RESERVED +CVE-2020-6453 (Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987 ...) + TODO: check CVE-2020-6452 (Heap buffer overflow in media in Google Chrome prior to 80.0.3987.162 ...) {DSA-4654-1} - chromium 80.0.3987.162-1 @@ -17015,8 +17061,8 @@ CVE-2020-6420 (Insufficient policy enforcement in media in Google Chrome prior t {DSA-4638-1} - chromium 80.0.3987.132-1 [stretch] - chromium <end-of-life> (see DSA 4562) -CVE-2020-6419 - RESERVED +CVE-2020-6419 (Out of bounds write in V8 in Google Chrome prior to 81.0.4044.92 allow ...) + TODO: check CVE-2020-6418 (Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a ...) {DSA-4638-1} - chromium 80.0.3987.122-1 @@ -19440,16 +19486,16 @@ CVE-2020-5301 (SimpleSAMLphp versions before 1.18.6 contain an information discl - simplesamlphp <not-affected> (Windows-only issue) CVE-2020-5300 (In Hydra (an OAuth2 Server and OpenID Certified™ OpenID Connect ...) NOT-FOR-US: ORY Hydra -CVE-2020-5299 - RESERVED -CVE-2020-5298 - RESERVED -CVE-2020-5297 - RESERVED -CVE-2020-5296 - RESERVED -CVE-2020-5295 - RESERVED +CVE-2020-5299 (In OctoberCMS (october/october composer package) versions from 1.0.319 ...) + TODO: check +CVE-2020-5298 (In OctoberCMS (october/october composer package) versions from 1.0.319 ...) + TODO: check +CVE-2020-5297 (In OctoberCMS (october/october composer package) versions from 1.0.319 ...) + TODO: check +CVE-2020-5296 (In OctoberCMS (october/october composer package) versions from 1.0.319 ...) + TODO: check +CVE-2020-5295 (In OctoberCMS (october/october composer package) versions from 1.0.319 ...) + TODO: check CVE-2020-5294 (PrestaShop module ps_facetedsearch versions before 2.1.0 has a reflect ...) NOT-FOR-US: PrestaShop CVE-2020-5293 (In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper ...) |