summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorsecurity tracker role <sectracker@soriano.debian.org>2020-06-04 08:10:24 +0000
committersecurity tracker role <sectracker@soriano.debian.org>2020-06-04 08:10:24 +0000
commit93a48b01ebc8a4e0e67ef869020b06ae0ed807ef (patch)
tree544e8ad3917a5a42c22ee85b31f32719d06f4c61
parentd9c6d7118378bc2c0120b422883c725f0f1cc3f3 (diff)
automatic update
-rw-r--r--data/CVE/list.20118
-rw-r--r--data/CVE/list.201820
-rw-r--r--data/CVE/list.201950
-rw-r--r--data/CVE/list.2020158
4 files changed, 176 insertions, 60 deletions
diff --git a/data/CVE/list.2011 b/data/CVE/list.2011
index 257b1a3d42..125be0fe17 100644
--- a/data/CVE/list.2011
+++ b/data/CVE/list.2011
@@ -6399,8 +6399,8 @@ CVE-2011-2864 (Google Chrome before 14.0.835.163 does not properly handle Tibeta
- chromium-browser 14.0.835.163~r101024-1
[squeeze] - chromium-browser <not-affected>
- webkit <not-affected> (chromium specific)
-CVE-2011-2863
- RESERVED
+CVE-2011-2863 (Insufficient policy enforcement in V8 in Google Chrome prior to 14.0.0 ...)
+ TODO: check
CVE-2011-2862 (Google V8, as used in Google Chrome before 14.0.835.163, does not prop ...)
- chromium-browser 14.0.835.163~r101024-1
[squeeze] - chromium-browser <not-affected>
@@ -9252,8 +9252,8 @@ CVE-2011-1806 (Google Chrome before 11.0.696.71 does not properly implement the
- chromium-browser 11.0.696.71~r86024-1
[squeeze] - chromium-browser <not-affected>
- webkit <not-affected> (chromium specific)
-CVE-2011-1805
- RESERVED
+CVE-2011-1805 (Bad cast in CSS in Google Chrome prior to 11.0.0.0 allowed a remote at ...)
+ TODO: check
CVE-2011-1804 (rendering/RenderBox.cpp in WebCore in WebKit before r86862, as used in ...)
- chromium-browser 11.0.696.71~r86024-1
[squeeze] - chromium-browser <not-affected>
diff --git a/data/CVE/list.2018 b/data/CVE/list.2018
index 9f849ce693..3ff8fe854c 100644
--- a/data/CVE/list.2018
+++ b/data/CVE/list.2018
@@ -1,3 +1,23 @@
+CVE-2018-21244
+ RESERVED
+CVE-2018-21243
+ RESERVED
+CVE-2018-21242
+ RESERVED
+CVE-2018-21241
+ RESERVED
+CVE-2018-21240
+ RESERVED
+CVE-2018-21239
+ RESERVED
+CVE-2018-21238
+ RESERVED
+CVE-2018-21237
+ RESERVED
+CVE-2018-21236
+ RESERVED
+CVE-2018-21235
+ RESERVED
CVE-2018-21234 (Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when ...)
- jodd <unfixed> (bug #961298)
[buster] - jodd <no-dsa> (Minor issue)
diff --git a/data/CVE/list.2019 b/data/CVE/list.2019
index cff3ed9524..976e5c2116 100644
--- a/data/CVE/list.2019
+++ b/data/CVE/list.2019
@@ -1,3 +1,53 @@
+CVE-2019-20837
+ RESERVED
+CVE-2019-20836
+ RESERVED
+CVE-2019-20835
+ RESERVED
+CVE-2019-20834
+ RESERVED
+CVE-2019-20833
+ RESERVED
+CVE-2019-20832
+ RESERVED
+CVE-2019-20831
+ RESERVED
+CVE-2019-20830
+ RESERVED
+CVE-2019-20829
+ RESERVED
+CVE-2019-20828
+ RESERVED
+CVE-2019-20827
+ RESERVED
+CVE-2019-20826
+ RESERVED
+CVE-2019-20825
+ RESERVED
+CVE-2019-20824
+ RESERVED
+CVE-2019-20823
+ RESERVED
+CVE-2019-20822
+ RESERVED
+CVE-2019-20821
+ RESERVED
+CVE-2019-20820
+ RESERVED
+CVE-2019-20819
+ RESERVED
+CVE-2019-20818
+ RESERVED
+CVE-2019-20817
+ RESERVED
+CVE-2019-20816
+ RESERVED
+CVE-2019-20815
+ RESERVED
+CVE-2019-20814
+ RESERVED
+CVE-2019-20813
+ RESERVED
CVE-2019-20812 (An issue was discovered in the Linux kernel before 5.4.7. The prb_calc ...)
- linux 5.4.8-1
[buster] - linux 4.19.98-1
diff --git a/data/CVE/list.2020 b/data/CVE/list.2020
index 9de5a2f9b6..118f192b0f 100644
--- a/data/CVE/list.2020
+++ b/data/CVE/list.2020
@@ -1,3 +1,49 @@
+CVE-2020-13815
+ RESERVED
+CVE-2020-13814
+ RESERVED
+CVE-2020-13813
+ RESERVED
+CVE-2020-13812
+ RESERVED
+CVE-2020-13811
+ RESERVED
+CVE-2020-13810
+ RESERVED
+CVE-2020-13809
+ RESERVED
+CVE-2020-13808
+ RESERVED
+CVE-2020-13807
+ RESERVED
+CVE-2020-13806
+ RESERVED
+CVE-2020-13805
+ RESERVED
+CVE-2020-13804
+ RESERVED
+CVE-2020-13803
+ RESERVED
+CVE-2020-13802
+ RESERVED
+CVE-2020-13801
+ RESERVED
+CVE-2020-13799
+ RESERVED
+CVE-2020-13798 (An issue was discovered in Navigate CMS through 2.8.7. It allows XSS b ...)
+ TODO: check
+CVE-2020-13797 (An issue was discovered in Navigate CMS through 2.8.7. It allows XSS b ...)
+ TODO: check
+CVE-2020-13796 (An issue was discovered in Navigate CMS through 2.8.7. It allows XSS b ...)
+ TODO: check
+CVE-2020-13795 (An issue was discovered in Navigate CMS through 2.8.7. It allows Direc ...)
+ TODO: check
+CVE-2020-13794
+ RESERVED
+CVE-2020-13793
+ RESERVED
+CVE-2020-13792 (PlayTube 1.8 allows disclosure of user details via ajax.php?type=../ad ...)
+ TODO: check
CVE-2020-XXXX [Cross-Site Scripting (XSS) vulnerability via malicious XML messages]
- roundcube 1.4.5+dfsg.1-1 (bug #962124)
NOTE: 1.4.x: https://github.com/roundcube/roundcubemail/commit/ccaccae6653031b809b4347a60021951e19a0e43
@@ -7,6 +53,7 @@ CVE-2020-XXXX [Cross-Site Scripting (XSS) vulnerability in template object 'user
NOTE: 1.4.x: https://github.com/roundcube/roundcubemail/commit/4beec65d40c5e5b1f2bace935c110baf05e10ae5
NOTE: 1.3.x: https://github.com/roundcube/roundcubemail/commit/37e2bc745723ef6322f0f785aefd0b9313a40f19
CVE-2020-13800 [ati-vga: infinite recursion in ati_mm_read/write calls may lead to DoS]
+ RESERVED
- qemu <unfixed>
[buster] - qemu <not-affected> (Vulnerable code introduced later)
[stretch] - qemu <not-affected> (Vulnerable code introduced later)
@@ -14,6 +61,7 @@ CVE-2020-13800 [ati-vga: infinite recursion in ati_mm_read/write calls may lead
NOTE: https://www.openwall.com/lists/oss-security/2020/06/04/2
NOTE: https://lists.gnu.org/archive/html/qemu-devel/2020-06/msg00833.html
CVE-2020-13791 [ati-vga: OOB access while reading PCI configuration may lead to DoS]
+ RESERVED
- qemu <unfixed>
[buster] - qemu <not-affected> (Vulnerable code introduced later)
[stretch] - qemu <not-affected> (Vulnerable code introduced later)
@@ -46,8 +94,7 @@ CVE-2020-13779
RESERVED
CVE-2020-13778
RESERVED
-CVE-2020-13777 [session resumption works without master key allowing MITM]
- RESERVED
+CVE-2020-13777 (GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting ...)
- gnutls28 <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1843723
NOTE: https://gitlab.com/gnutls/gnutls/-/issues/1011
@@ -6154,14 +6201,14 @@ CVE-2020-11096
RESERVED
CVE-2020-11095
RESERVED
-CVE-2020-11094
- RESERVED
+CVE-2020-11094 (The October CMS debugbar plugin before version 3.1.0 contains a featur ...)
+ TODO: check
CVE-2020-11093
RESERVED
CVE-2020-11092
RESERVED
-CVE-2020-11091
- RESERVED
+CVE-2020-11091 (In Weave Net before version 2.6.3, an attacker able to run a process a ...)
+ TODO: check
CVE-2020-11090
RESERVED
CVE-2020-11089 (In FreeRDP before 2.1.0, there is an out-of-bound read in irp function ...)
@@ -6205,8 +6252,7 @@ CVE-2020-11082 (In Kaminari before 1.2.1, there is a vulnerability that would al
NOTE: https://github.com/kaminari/kaminari/commit/8dd52a1aed3d2fa2835d836de23fc0d8c4ff5db8
CVE-2020-11081
RESERVED
-CVE-2020-11080 [HTTP/2 Large Settings Frame DoS]
- RESERVED
+CVE-2020-11080 (In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS fra ...)
- nodejs <unfixed> (bug #962145)
[stretch] - nodejs <ignored> (Nodejs in stretch not covered by security support)
NOTE: https://nodejs.org/en/blog/vulnerability/june-2020-security-releases/#http-2-large-settings-frame-dos-low-cve-2020-11080
@@ -7751,14 +7797,14 @@ CVE-2020-10551 (QQBrowser before 10.5.3870.400 installs a Windows service TsServ
NOT-FOR-US: QQBrowser
CVE-2020-10550
RESERVED
-CVE-2020-10549
- RESERVED
-CVE-2020-10548
- RESERVED
-CVE-2020-10547
- RESERVED
-CVE-2020-10546
- RESERVED
+CVE-2020-10549 (rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.p ...)
+ TODO: check
+CVE-2020-10548 (rConfig 3.9.4 and previous versions has unauthenticated devices.inc.ph ...)
+ TODO: check
+CVE-2020-10547 (rConfig 3.9.4 and previous versions has unauthenticated compliancepoli ...)
+ TODO: check
+CVE-2020-10546 (rConfig 3.9.4 and previous versions has unauthenticated compliancepoli ...)
+ TODO: check
CVE-2020-10545
RESERVED
CVE-2020-10544 (An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFac ...)
@@ -15520,8 +15566,8 @@ CVE-2020-7032
RESERVED
CVE-2020-7031
RESERVED
-CVE-2020-7030
- RESERVED
+CVE-2020-7030 (A sensitive information disclosure vulnerability was discovered in the ...)
+ TODO: check
CVE-2020-7029
RESERVED
CVE-2020-7028
@@ -16764,30 +16810,30 @@ CVE-2020-6506
RESERVED
CVE-2020-6505
RESERVED
-CVE-2020-6504
- RESERVED
-CVE-2020-6503
- RESERVED
-CVE-2020-6502
- RESERVED
-CVE-2020-6501
- RESERVED
-CVE-2020-6500
- RESERVED
-CVE-2020-6499
- RESERVED
-CVE-2020-6498
- RESERVED
-CVE-2020-6497
- RESERVED
-CVE-2020-6496
- RESERVED
-CVE-2020-6495
- RESERVED
-CVE-2020-6494
- RESERVED
-CVE-2020-6493
- RESERVED
+CVE-2020-6504 (Insufficient policy enforcement in notifications in Google Chrome prio ...)
+ TODO: check
+CVE-2020-6503 (Inappropriate implementation in accessibility in Google Chrome prior t ...)
+ TODO: check
+CVE-2020-6502 (Incorrect implementation in permissions in Google Chrome prior to 80.0 ...)
+ TODO: check
+CVE-2020-6501 (Insufficient policy enforcement in CSP in Google Chrome prior to 80.0. ...)
+ TODO: check
+CVE-2020-6500 (Inappropriate implementation in interstitials in Google Chrome prior t ...)
+ TODO: check
+CVE-2020-6499 (Inappropriate implementation in AppCache in Google Chrome prior to 80. ...)
+ TODO: check
+CVE-2020-6498 (Incorrect implementation in user interface in Google Chrome on iOS pri ...)
+ TODO: check
+CVE-2020-6497 (Insufficient policy enforcement in Omnibox in Google Chrome on iOS pri ...)
+ TODO: check
+CVE-2020-6496 (Use after free in payments in Google Chrome on MacOS prior to 83.0.410 ...)
+ TODO: check
+CVE-2020-6495 (Insufficient policy enforcement in developer tools in Google Chrome pr ...)
+ TODO: check
+CVE-2020-6494 (Incorrect security UI in payments in Google Chrome on Android prior to ...)
+ TODO: check
+CVE-2020-6493 (Use after free in WebAuthentication in Google Chrome prior to 83.0.410 ...)
+ TODO: check
CVE-2020-6492
RESERVED
CVE-2020-6491 (Insufficient data validation in site information in Google Chrome prio ...)
@@ -16903,8 +16949,8 @@ CVE-2020-6455 (Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.
CVE-2020-6454 (Use after free in extensions in Google Chrome prior to 81.0.4044.92 al ...)
- chromium 81.0.4044.92-1
[stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2020-6453
- RESERVED
+CVE-2020-6453 (Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987 ...)
+ TODO: check
CVE-2020-6452 (Heap buffer overflow in media in Google Chrome prior to 80.0.3987.162 ...)
{DSA-4654-1}
- chromium 80.0.3987.162-1
@@ -17015,8 +17061,8 @@ CVE-2020-6420 (Insufficient policy enforcement in media in Google Chrome prior t
{DSA-4638-1}
- chromium 80.0.3987.132-1
[stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2020-6419
- RESERVED
+CVE-2020-6419 (Out of bounds write in V8 in Google Chrome prior to 81.0.4044.92 allow ...)
+ TODO: check
CVE-2020-6418 (Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a ...)
{DSA-4638-1}
- chromium 80.0.3987.122-1
@@ -19440,16 +19486,16 @@ CVE-2020-5301 (SimpleSAMLphp versions before 1.18.6 contain an information discl
- simplesamlphp <not-affected> (Windows-only issue)
CVE-2020-5300 (In Hydra (an OAuth2 Server and OpenID Certified&#8482; OpenID Connect ...)
NOT-FOR-US: ORY Hydra
-CVE-2020-5299
- RESERVED
-CVE-2020-5298
- RESERVED
-CVE-2020-5297
- RESERVED
-CVE-2020-5296
- RESERVED
-CVE-2020-5295
- RESERVED
+CVE-2020-5299 (In OctoberCMS (october/october composer package) versions from 1.0.319 ...)
+ TODO: check
+CVE-2020-5298 (In OctoberCMS (october/october composer package) versions from 1.0.319 ...)
+ TODO: check
+CVE-2020-5297 (In OctoberCMS (october/october composer package) versions from 1.0.319 ...)
+ TODO: check
+CVE-2020-5296 (In OctoberCMS (october/october composer package) versions from 1.0.319 ...)
+ TODO: check
+CVE-2020-5295 (In OctoberCMS (october/october composer package) versions from 1.0.319 ...)
+ TODO: check
CVE-2020-5294 (PrestaShop module ps_facetedsearch versions before 2.1.0 has a reflect ...)
NOT-FOR-US: PrestaShop
CVE-2020-5293 (In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper ...)

© 2014-2024 Faster IT GmbH | imprint | privacy policy