Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
e8d280a9 by security tracker role at 2022-07-25T20:10:18+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,665 @@
+CVE-2022-36760
+       RESERVED
+CVE-2022-36759
+       RESERVED
+CVE-2022-36758
+       RESERVED
+CVE-2022-36757
+       RESERVED
+CVE-2022-36756
+       RESERVED
+CVE-2022-36755
+       RESERVED
+CVE-2022-36754
+       RESERVED
+CVE-2022-36753
+       RESERVED
+CVE-2022-36752
+       RESERVED
+CVE-2022-36751
+       RESERVED
+CVE-2022-36750
+       RESERVED
+CVE-2022-36749
+       RESERVED
+CVE-2022-36748
+       RESERVED
+CVE-2022-36747
+       RESERVED
+CVE-2022-36746
+       RESERVED
+CVE-2022-36745
+       RESERVED
+CVE-2022-36744
+       RESERVED
+CVE-2022-36743
+       RESERVED
+CVE-2022-36742
+       RESERVED
+CVE-2022-36741
+       RESERVED
+CVE-2022-36740
+       RESERVED
+CVE-2022-36739
+       RESERVED
+CVE-2022-36738
+       RESERVED
+CVE-2022-36737
+       RESERVED
+CVE-2022-36736
+       RESERVED
+CVE-2022-36735
+       RESERVED
+CVE-2022-36734
+       RESERVED
+CVE-2022-36733
+       RESERVED
+CVE-2022-36732
+       RESERVED
+CVE-2022-36731
+       RESERVED
+CVE-2022-36730
+       RESERVED
+CVE-2022-36729
+       RESERVED
+CVE-2022-36728
+       RESERVED
+CVE-2022-36727
+       RESERVED
+CVE-2022-36726
+       RESERVED
+CVE-2022-36725
+       RESERVED
+CVE-2022-36724
+       RESERVED
+CVE-2022-36723
+       RESERVED
+CVE-2022-36722
+       RESERVED
+CVE-2022-36721
+       RESERVED
+CVE-2022-36720
+       RESERVED
+CVE-2022-36719
+       RESERVED
+CVE-2022-36718
+       RESERVED
+CVE-2022-36717
+       RESERVED
+CVE-2022-36716
+       RESERVED
+CVE-2022-36715
+       RESERVED
+CVE-2022-36714
+       RESERVED
+CVE-2022-36713
+       RESERVED
+CVE-2022-36712
+       RESERVED
+CVE-2022-36711
+       RESERVED
+CVE-2022-36710
+       RESERVED
+CVE-2022-36709
+       RESERVED
+CVE-2022-36708
+       RESERVED
+CVE-2022-36707
+       RESERVED
+CVE-2022-36706
+       RESERVED
+CVE-2022-36705
+       RESERVED
+CVE-2022-36704
+       RESERVED
+CVE-2022-36703
+       RESERVED
+CVE-2022-36702
+       RESERVED
+CVE-2022-36701
+       RESERVED
+CVE-2022-36700
+       RESERVED
+CVE-2022-36699
+       RESERVED
+CVE-2022-36698
+       RESERVED
+CVE-2022-36697
+       RESERVED
+CVE-2022-36696
+       RESERVED
+CVE-2022-36695
+       RESERVED
+CVE-2022-36694
+       RESERVED
+CVE-2022-36693
+       RESERVED
+CVE-2022-36692
+       RESERVED
+CVE-2022-36691
+       RESERVED
+CVE-2022-36690
+       RESERVED
+CVE-2022-36689
+       RESERVED
+CVE-2022-36688
+       RESERVED
+CVE-2022-36687
+       RESERVED
+CVE-2022-36686
+       RESERVED
+CVE-2022-36685
+       RESERVED
+CVE-2022-36684
+       RESERVED
+CVE-2022-36683
+       RESERVED
+CVE-2022-36682
+       RESERVED
+CVE-2022-36681
+       RESERVED
+CVE-2022-36680
+       RESERVED
+CVE-2022-36679
+       RESERVED
+CVE-2022-36678
+       RESERVED
+CVE-2022-36677
+       RESERVED
+CVE-2022-36676
+       RESERVED
+CVE-2022-36675
+       RESERVED
+CVE-2022-36674
+       RESERVED
+CVE-2022-36673
+       RESERVED
+CVE-2022-36672
+       RESERVED
+CVE-2022-36671
+       RESERVED
+CVE-2022-36670
+       RESERVED
+CVE-2022-36669
+       RESERVED
+CVE-2022-36668
+       RESERVED
+CVE-2022-36667
+       RESERVED
+CVE-2022-36666
+       RESERVED
+CVE-2022-36665
+       RESERVED
+CVE-2022-36664
+       RESERVED
+CVE-2022-36663
+       RESERVED
+CVE-2022-36662
+       RESERVED
+CVE-2022-36661
+       RESERVED
+CVE-2022-36660
+       RESERVED
+CVE-2022-36659
+       RESERVED
+CVE-2022-36658
+       RESERVED
+CVE-2022-36657
+       RESERVED
+CVE-2022-36656
+       RESERVED
+CVE-2022-36655
+       RESERVED
+CVE-2022-36654
+       RESERVED
+CVE-2022-36653
+       RESERVED
+CVE-2022-36652
+       RESERVED
+CVE-2022-36651
+       RESERVED
+CVE-2022-36650
+       RESERVED
+CVE-2022-36649
+       RESERVED
+CVE-2022-36648
+       RESERVED
+CVE-2022-36647
+       RESERVED
+CVE-2022-36646
+       RESERVED
+CVE-2022-36645
+       RESERVED
+CVE-2022-36644
+       RESERVED
+CVE-2022-36643
+       RESERVED
+CVE-2022-36642
+       RESERVED
+CVE-2022-36641
+       RESERVED
+CVE-2022-36640
+       RESERVED
+CVE-2022-36639
+       RESERVED
+CVE-2022-36638
+       RESERVED
+CVE-2022-36637
+       RESERVED
+CVE-2022-36636
+       RESERVED
+CVE-2022-36635
+       RESERVED
+CVE-2022-36634
+       RESERVED
+CVE-2022-36633
+       RESERVED
+CVE-2022-36632
+       RESERVED
+CVE-2022-36631
+       RESERVED
+CVE-2022-36630
+       RESERVED
+CVE-2022-36629
+       RESERVED
+CVE-2022-36628
+       RESERVED
+CVE-2022-36627
+       RESERVED
+CVE-2022-36626
+       RESERVED
+CVE-2022-36625
+       RESERVED
+CVE-2022-36624
+       RESERVED
+CVE-2022-36623
+       RESERVED
+CVE-2022-36622
+       RESERVED
+CVE-2022-36621
+       RESERVED
+CVE-2022-36620
+       RESERVED
+CVE-2022-36619
+       RESERVED
+CVE-2022-36618
+       RESERVED
+CVE-2022-36617
+       RESERVED
+CVE-2022-36616
+       RESERVED
+CVE-2022-36615
+       RESERVED
+CVE-2022-36614
+       RESERVED
+CVE-2022-36613
+       RESERVED
+CVE-2022-36612
+       RESERVED
+CVE-2022-36611
+       RESERVED
+CVE-2022-36610
+       RESERVED
+CVE-2022-36609
+       RESERVED
+CVE-2022-36608
+       RESERVED
+CVE-2022-36607
+       RESERVED
+CVE-2022-36606
+       RESERVED
+CVE-2022-36605
+       RESERVED
+CVE-2022-36604
+       RESERVED
+CVE-2022-36603
+       RESERVED
+CVE-2022-36602
+       RESERVED
+CVE-2022-36601
+       RESERVED
+CVE-2022-36600
+       RESERVED
+CVE-2022-36599
+       RESERVED
+CVE-2022-36598
+       RESERVED
+CVE-2022-36597
+       RESERVED
+CVE-2022-36596
+       RESERVED
+CVE-2022-36595
+       RESERVED
+CVE-2022-36594
+       RESERVED
+CVE-2022-36593
+       RESERVED
+CVE-2022-36592
+       RESERVED
+CVE-2022-36591
+       RESERVED
+CVE-2022-36590
+       RESERVED
+CVE-2022-36589
+       RESERVED
+CVE-2022-36588
+       RESERVED
+CVE-2022-36587
+       RESERVED
+CVE-2022-36586
+       RESERVED
+CVE-2022-36585
+       RESERVED
+CVE-2022-36584
+       RESERVED
+CVE-2022-36583
+       RESERVED
+CVE-2022-36582
+       RESERVED
+CVE-2022-36581
+       RESERVED
+CVE-2022-36580
+       RESERVED
+CVE-2022-36579
+       RESERVED
+CVE-2022-36578
+       RESERVED
+CVE-2022-36577
+       RESERVED
+CVE-2022-36576
+       RESERVED
+CVE-2022-36575
+       RESERVED
+CVE-2022-36574
+       RESERVED
+CVE-2022-36573
+       RESERVED
+CVE-2022-36572
+       RESERVED
+CVE-2022-36571
+       RESERVED
+CVE-2022-36570
+       RESERVED
+CVE-2022-36569
+       RESERVED
+CVE-2022-36568
+       RESERVED
+CVE-2022-36567
+       RESERVED
+CVE-2022-36566
+       RESERVED
+CVE-2022-36565
+       RESERVED
+CVE-2022-36564
+       RESERVED
+CVE-2022-36563
+       RESERVED
+CVE-2022-36562
+       RESERVED
+CVE-2022-36561
+       RESERVED
+CVE-2022-36560
+       RESERVED
+CVE-2022-36559
+       RESERVED
+CVE-2022-36558
+       RESERVED
+CVE-2022-36557
+       RESERVED
+CVE-2022-36556
+       RESERVED
+CVE-2022-36555
+       RESERVED
+CVE-2022-36554
+       RESERVED
+CVE-2022-36553
+       RESERVED
+CVE-2022-36552
+       RESERVED
+CVE-2022-36551
+       RESERVED
+CVE-2022-36550
+       RESERVED
+CVE-2022-36549
+       RESERVED
+CVE-2022-36548
+       RESERVED
+CVE-2022-36547
+       RESERVED
+CVE-2022-36546
+       RESERVED
+CVE-2022-36545
+       RESERVED
+CVE-2022-36544
+       RESERVED
+CVE-2022-36543
+       RESERVED
+CVE-2022-36542
+       RESERVED
+CVE-2022-36541
+       RESERVED
+CVE-2022-36540
+       RESERVED
+CVE-2022-36539
+       RESERVED
+CVE-2022-36538
+       RESERVED
+CVE-2022-36537
+       RESERVED
+CVE-2022-36536
+       RESERVED
+CVE-2022-36535
+       RESERVED
+CVE-2022-36534
+       RESERVED
+CVE-2022-36533
+       RESERVED
+CVE-2022-36532
+       RESERVED
+CVE-2022-36531
+       RESERVED
+CVE-2022-36530
+       RESERVED
+CVE-2022-36529
+       RESERVED
+CVE-2022-36528
+       RESERVED
+CVE-2022-36527
+       RESERVED
+CVE-2022-36526
+       RESERVED
+CVE-2022-36525
+       RESERVED
+CVE-2022-36524
+       RESERVED
+CVE-2022-36523
+       RESERVED
+CVE-2022-36522
+       RESERVED
+CVE-2022-36521
+       RESERVED
+CVE-2022-36520
+       RESERVED
+CVE-2022-36519
+       RESERVED
+CVE-2022-36518
+       RESERVED
+CVE-2022-36517
+       RESERVED
+CVE-2022-36516
+       RESERVED
+CVE-2022-36515
+       RESERVED
+CVE-2022-36514
+       RESERVED
+CVE-2022-36513
+       RESERVED
+CVE-2022-36512
+       RESERVED
+CVE-2022-36511
+       RESERVED
+CVE-2022-36510
+       RESERVED
+CVE-2022-36509
+       RESERVED
+CVE-2022-36508
+       RESERVED
+CVE-2022-36507
+       RESERVED
+CVE-2022-36506
+       RESERVED
+CVE-2022-36505
+       RESERVED
+CVE-2022-36504
+       RESERVED
+CVE-2022-36503
+       RESERVED
+CVE-2022-36502
+       RESERVED
+CVE-2022-36501
+       RESERVED
+CVE-2022-36500
+       RESERVED
+CVE-2022-36499
+       RESERVED
+CVE-2022-36498
+       RESERVED
+CVE-2022-36497
+       RESERVED
+CVE-2022-36496
+       RESERVED
+CVE-2022-36495
+       RESERVED
+CVE-2022-36494
+       RESERVED
+CVE-2022-36493
+       RESERVED
+CVE-2022-36492
+       RESERVED
+CVE-2022-36491
+       RESERVED
+CVE-2022-36490
+       RESERVED
+CVE-2022-36489
+       RESERVED
+CVE-2022-36488
+       RESERVED
+CVE-2022-36487
+       RESERVED
+CVE-2022-36486
+       RESERVED
+CVE-2022-36485
+       RESERVED
+CVE-2022-36484
+       RESERVED
+CVE-2022-36483
+       RESERVED
+CVE-2022-36482
+       RESERVED
+CVE-2022-36481
+       RESERVED
+CVE-2022-36480
+       RESERVED
+CVE-2022-36479
+       RESERVED
+CVE-2022-36478
+       RESERVED
+CVE-2022-36477
+       RESERVED
+CVE-2022-36476
+       RESERVED
+CVE-2022-36475
+       RESERVED
+CVE-2022-36474
+       RESERVED
+CVE-2022-36473
+       RESERVED
+CVE-2022-36472
+       RESERVED
+CVE-2022-36471
+       RESERVED
+CVE-2022-36470
+       RESERVED
+CVE-2022-36469
+       RESERVED
+CVE-2022-36468
+       RESERVED
+CVE-2022-36467
+       RESERVED
+CVE-2022-36466
+       RESERVED
+CVE-2022-36465
+       RESERVED
+CVE-2022-36464
+       RESERVED
+CVE-2022-36463
+       RESERVED
+CVE-2022-36462
+       RESERVED
+CVE-2022-36461
+       RESERVED
+CVE-2022-36460
+       RESERVED
+CVE-2022-36459
+       RESERVED
+CVE-2022-36458
+       RESERVED
+CVE-2022-36457
+       RESERVED
+CVE-2022-36456
+       RESERVED
+CVE-2022-36455
+       RESERVED
+CVE-2022-36454
+       RESERVED
+CVE-2022-36453
+       RESERVED
+CVE-2022-36452
+       RESERVED
+CVE-2022-36451
+       RESERVED
+CVE-2022-36450 (Obsidian 0.14.x and 0.15.x before 0.15.5 allows 
obsidian://hook-get-ad ...)
+       TODO: check
+CVE-2022-36449
+       RESERVED
+CVE-2022-36448
+       RESERVED
+CVE-2022-36447
+       RESERVED
+CVE-2022-36446 (software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping 
for a U ...)
+       TODO: check
+CVE-2022-36445
+       RESERVED
+CVE-2022-36444 (An issue was discovered in Atos Unify OpenScape SBC 9 and 10 
before 10 ...)
+       TODO: check
+CVE-2022-36443
+       RESERVED
+CVE-2022-36442
+       RESERVED
+CVE-2022-36441
+       RESERVED
+CVE-2022-36440
+       RESERVED
+CVE-2022-2537
+       RESERVED
+CVE-2022-2536
+       RESERVED
+CVE-2022-2535
+       RESERVED
+CVE-2022-2534
+       RESERVED
+CVE-2022-2533
+       RESERVED
+CVE-2022-2532
+       RESERVED
+CVE-2022-2531
+       RESERVED
+CVE-2022-2530
+       RESERVED
+CVE-2022-2529
+       RESERVED
+CVE-2022-2528
+       RESERVED
 CVE-2022-36439
        RESERVED
 CVE-2022-36438
@@ -57,8 +719,8 @@ CVE-2022-34859
        RESERVED
 CVE-2022-33963
        RESERVED
-CVE-2022-2523
-       RESERVED
+CVE-2022-2523 (Cross-site Scripting (XSS) - Reflected in GitHub repository 
beancount/ ...)
+       TODO: check
 CVE-2022-36381
        RESERVED
 CVE-2022-36293
@@ -105,8 +767,8 @@ CVE-2022-34147
        RESERVED
 CVE-2022-31137 (Roxy-WI is a web interface for managing Haproxy, Nginx, Apache 
and Kee ...)
        NOT-FOR-US: Roxy-WI
-CVE-2022-2522
-       RESERVED
+CVE-2022-2522 (Heap-based Buffer Overflow in GitHub repository vim/vim prior 
to 9.0.0 ...)
+       TODO: check
 CVE-2022-2521
        RESERVED
 CVE-2022-2520
@@ -180,8 +842,8 @@ CVE-2022-34154
        RESERVED
 CVE-2022-33970
        RESERVED
-CVE-2022-33969
-       RESERVED
+CVE-2022-33969 (Authenticated WordPress Options Change vulnerability in Biplob 
Adhikar ...)
+       TODO: check
 CVE-2022-33943
        RESERVED
 CVE-2022-33201
@@ -190,8 +852,8 @@ CVE-2022-33142
        RESERVED
 CVE-2022-2515
        RESERVED
-CVE-2022-2514
-       RESERVED
+CVE-2022-2514 (The time and filter parameters in Fava prior to v1.22 are 
vulnerable t ...)
+       TODO: check
 CVE-2022-2513
        RESERVED
 CVE-2022-2512
@@ -1940,20 +2602,15 @@ CVE-2022-35655
        RESERVED
 CVE-2022-35654
        RESERVED
-CVE-2022-35653
-       RESERVED
+CVE-2022-35653 (A reflected XSS issue was identified in the LTI module of 
Moodle. The  ...)
        - moodle <removed>
-CVE-2022-35652
-       RESERVED
+CVE-2022-35652 (An open redirect issue was found in Moodle due to improper 
sanitizatio ...)
        - moodle <removed>
-CVE-2022-35651
-       RESERVED
+CVE-2022-35651 (A stored XSS and blind SSRF vulnerability was found in Moodle, 
occurs  ...)
        - moodle <removed>
-CVE-2022-35650
-       RESERVED
+CVE-2022-35650 (The vulnerability was found in Moodle, occurs due to input 
validation  ...)
        - moodle <removed>
-CVE-2022-35649
-       RESERVED
+CVE-2022-35649 (The vulnerability was found in Moodle, occurs due to improper 
input va ...)
        - moodle <removed>
 CVE-2022-33977
        RESERVED
@@ -2797,10 +3454,10 @@ CVE-2022-2343 (Heap-based Buffer Overflow in GitHub 
repository vim/vim prior to
        NOTE: Crash in CLI tool, no security impact
 CVE-2022-2342 (Cross-site Scripting (XSS) - Stored in GitHub repository 
outline/outli ...)
        NOT-FOR-US: outline
-CVE-2022-2341
-       RESERVED
-CVE-2022-2340
-       RESERVED
+CVE-2022-2341 (The Simple Page Transition WordPress plugin through 1.4.1 does 
not san ...)
+       TODO: check
+CVE-2022-2340 (The W-DALIL WordPress plugin through 2.0 does not sanitise and 
escape  ...)
+       TODO: check
 CVE-2022-35299
        RESERVED
 CVE-2022-35298
@@ -2823,16 +3480,16 @@ CVE-2022-35290
        RESERVED
 CVE-2022-35289
        RESERVED
-CVE-2022-35288
-       RESERVED
-CVE-2022-35287
-       RESERVED
+CVE-2022-35288 (IBM Security Verify Information Queue 10.0.2 could allow a 
user to obt ...)
+       TODO: check
+CVE-2022-35287 (IBM Security Verify Information Queue 10.0.2 contains 
hard-coded crede ...)
+       TODO: check
 CVE-2022-35286
        RESERVED
-CVE-2022-35285
-       RESERVED
-CVE-2022-35284
-       RESERVED
+CVE-2022-35285 (IBM Security Verify Information Queue 10.0.2 is vulnerable to 
cross-si ...)
+       TODO: check
+CVE-2022-35284 (IBM Security Verify Information Queue 10.0.2 could disclose 
sensitive  ...)
+       TODO: check
 CVE-2022-35283 (IBM Security Verify Information Queue 10.0.2 could allow an 
authentica ...)
        NOT-FOR-US: IBM
 CVE-2022-35282
@@ -3534,16 +4191,16 @@ CVE-2022-34967
        RESERVED
 CVE-2022-34966
        RESERVED
-CVE-2022-34965
-       RESERVED
-CVE-2022-34964
-       RESERVED
-CVE-2022-34963
-       RESERVED
-CVE-2022-34962
-       RESERVED
-CVE-2022-34961
-       RESERVED
+CVE-2022-34965 (OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was 
discovered ...)
+       TODO: check
+CVE-2022-34964 (OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was 
discovered ...)
+       TODO: check
+CVE-2022-34963 (OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was 
discovered ...)
+       TODO: check
+CVE-2022-34962 (OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was 
discovered ...)
+       TODO: check
+CVE-2022-34961 (OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was 
discovered ...)
+       TODO: check
 CVE-2022-34960
        RESERVED
 CVE-2022-34959
@@ -3660,8 +4317,8 @@ CVE-2022-2301 (Buffer Over-read in GitHub repository 
hpjansson/chafa prior to 1.
        NOTE: Crash in CLI tool, no security impact
 CVE-2022-2300 (Cross-site Scripting (XSS) - Stored in GitHub repository 
microweber/mi ...)
        NOT-FOR-US: microweber
-CVE-2022-2299
-       RESERVED
+CVE-2022-2299 (The Allow SVG Files WordPress plugin through 1.1 does not 
sanitise upl ...)
+       TODO: check
 CVE-2022-2298 (A vulnerability has been found in SourceCodester Clinics 
Patient Manag ...)
        NOT-FOR-US: Clinics Patient Management System
 CVE-2022-2297 (A vulnerability, which was classified as critical, was found in 
Source ...)
@@ -3895,8 +4552,8 @@ CVE-2022-34148
        RESERVED
 CVE-2022-33974
        RESERVED
-CVE-2022-33965
-       RESERVED
+CVE-2022-33965 (Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities 
in Osama ...)
+       TODO: check
 CVE-2022-33961
        RESERVED
 CVE-2022-33960 (Multiple Authenticated (subscriber or higher user role) SQL 
Injection  ...)
@@ -4230,10 +4887,10 @@ CVE-2022-2242
        RESERVED
 CVE-2022-2241
        RESERVED
-CVE-2022-2240
-       RESERVED
-CVE-2022-2239
-       RESERVED
+CVE-2022-2240 (The Request a Quote WordPress plugin through 2.3.7 does not 
validate u ...)
+       TODO: check
+CVE-2022-2239 (The Request a Quote WordPress plugin through 2.3.7 does not 
sanitise a ...)
+       TODO: check
 CVE-2022-2238
        RESERVED
        NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes 2 / 
Stolostron
@@ -4468,8 +5125,8 @@ CVE-2022-2221 (Information Exposure vulnerability in My 
Account Settings of Devo
 CVE-2022-2220
        RESERVED
        NOT-FOR-US: OpenShift
-CVE-2022-2219
-       RESERVED
+CVE-2022-2219 (The Unyson WordPress plugin before 2.7.27 does not sanitise and 
escape ...)
+       TODO: check
 CVE-2022-2218 (Cross-site Scripting (XSS) - Stored in GitHub repository 
ionicabizau/p ...)
        NOT-FOR-US: Node parse-url
 CVE-2022-2217 (Cross-site Scripting (XSS) - Generic in GitHub repository 
ionicabizau/ ...)
@@ -4879,7 +5536,8 @@ CVE-2022-2210 (Out-of-bounds Write in GitHub repository 
vim/vim prior to 8.2. ..
        NOTE: https://huntr.dev/bounties/020845f8-f047-4072-af0f-3726fe1aea25
        NOTE: 
https://github.com/vim/vim/commit/c101abff4c6756db4f5e740fde289decb9452efa 
(v8.2.5164)
        NOTE: Crash in CLI tool, no security impact
-CVE-2022-2209 (io_uring uses work_flags to determine which identity need to 
grab from ...)
+CVE-2022-2209
+       REJECTED
        - linux <unfixed>
 CVE-2022-2208 (NULL Pointer Dereference in GitHub repository vim/vim prior to 
8.2.516 ...)
        - vim <unfixed> (unimportant)
@@ -5322,8 +5980,8 @@ CVE-2022-34348
        RESERVED
 CVE-2022-2190
        RESERVED
-CVE-2022-2189
-       RESERVED
+CVE-2022-2189 (The WP Video Lightbox WordPress plugin before 1.9.5 does not 
escape th ...)
+       TODO: check
 CVE-2022-2188
        RESERVED
 CVE-2022-2187 (The Contact Form 7 Captcha WordPress plugin before 0.1.2 does 
not esca ...)
@@ -5908,8 +6566,8 @@ CVE-2022-2133 (The OAuth Single Sign On WordPress plugin 
before 6.22.6 doesn't v
        NOT-FOR-US: WordPress plugin
 CVE-2022-2132
        RESERVED
-CVE-2022-2131
-       RESERVED
+CVE-2022-2131 (OpenKM Community Edition in its 6.3.10 version and before was 
using XM ...)
+       TODO: check
 CVE-2022-2130 (Cross-site Scripting (XSS) - Reflected in GitHub repository 
microweber ...)
        NOT-FOR-US: microweber
 CVE-2022-XXXX [vlc issues fixed in 3.0.13]
@@ -6611,8 +7269,8 @@ CVE-2022-2117 (The GiveWP plugin for WordPress is 
vulnerable to Sensitive Inform
        NOT-FOR-US: WordPress plugin
 CVE-2022-2116
        RESERVED
-CVE-2022-2115
-       RESERVED
+CVE-2022-2115 (The Popup Anything WordPress plugin before 2.1.7 does not 
sanitise and ...)
+       TODO: check
 CVE-2022-2114 (The Data Tables Generator by Supsystic WordPress plugin before 
1.10.20 ...)
        NOT-FOR-US: WordPress plugin
 CVE-2022-2113 (Cross-site Scripting (XSS) - Stored in GitHub repository 
inventree/inv ...)
@@ -8199,9 +8857,11 @@ CVE-2022-29472
        RESERVED
 CVE-2022-27804
        RESERVED
-CVE-2022-2077 (** DISPUTED ** A vulnerability was found in Microsoft O365 and 
classif ...)
+CVE-2022-2077
+       REJECTED
        NOT-FOR-US: Microsoft
-CVE-2022-2076 (** DISPUTED ** A vulnerability has been found in Microsoft O365 
and cl ...)
+CVE-2022-2076
+       REJECTED
        NOT-FOR-US: Microsoft
 CVE-2022-2075
        RESERVED
@@ -8651,10 +9311,10 @@ CVE-2022-28710
        RESERVED
 CVE-2022-27805
        RESERVED
-CVE-2022-2072
-       RESERVED
-CVE-2022-2071
-       RESERVED
+CVE-2022-2072 (The Name Directory WordPress plugin before 1.25.3 does not 
sanitise an ...)
+       TODO: check
+CVE-2022-2071 (The Name Directory WordPress plugin before 1.25.4 does not have 
CSRF c ...)
+       TODO: check
 CVE-2022-2070
        RESERVED
 CVE-2022-2069
@@ -8685,8 +9345,8 @@ CVE-2022-2061 (Heap-based Buffer Overflow in GitHub 
repository hpjansson/chafa p
        NOTE: Crash in CLI tool, no security impact
 CVE-2022-2060 (Cross-site Scripting (XSS) - Stored in GitHub repository 
dolibarr/doli ...)
        - dolibarr <removed>
-CVE-2022-2059
-       RESERVED
+CVE-2022-2059 (In Pandora FMS v7.0NG.761 and below, in the agent creation 
section, th ...)
+       TODO: check
 CVE-2021-46820 (Arbitrary File Deletion vulnerability in XOS-Shop 
xos_shop_system 1.0. ...)
        NOT-FOR-US: XOS-Shop
 CVE-2020-36546
@@ -9679,8 +10339,8 @@ CVE-2022-2034
        RESERVED
 CVE-2022-2033
        RESERVED
-CVE-2022-2032
-       RESERVED
+CVE-2022-2032 (In Pandora FMS v7.0NG.761 and below, in the file manager 
section, the  ...)
+       TODO: check
 CVE-2022-2031
        RESERVED
 CVE-2022-2030 (A directory traversal vulnerability caused by specific 
character seque ...)
@@ -16917,8 +17577,8 @@ CVE-2022-30115 (Using its HSTS support, curl can be 
instructed to use HTTPS dire
        NOTE: https://curl.se/docs/CVE-2022-30115.html
        NOTE: Introduced by: 
https://github.com/curl/curl/commit/b27ad8e1d3e68eb3214fcbb398ca436873aa7c67 
(curl-7_82_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/fae6fea209a2d4db1582f608bd8cc8000721733a 
(curl-7_83_1)
-CVE-2022-1551
-       RESERVED
+CVE-2022-1551 (The SP Project &amp; Document Manager WordPress plugin through 
4.57 us ...)
+       TODO: check
 CVE-2022-1550
        REJECTED
 CVE-2022-1549 (The WP Athletics WordPress plugin through 1.1.7 does not 
sanitize para ...)
@@ -17441,8 +18101,8 @@ CVE-2022-1541 (The Video Slider WordPress plugin before 
1.4.8 does not sanitize
        NOT-FOR-US: WordPress plugin
 CVE-2022-1540
        RESERVED
-CVE-2022-1539
-       RESERVED
+CVE-2022-1539 (The Exports and Reports WordPress plugin before 0.9.2 does not 
sanitiz ...)
+       TODO: check
 CVE-2022-1538
        RESERVED
 CVE-2022-1537 (file.copy operations in GruntJS are vulnerable to a TOCTOU race 
condit ...)
@@ -18213,8 +18873,8 @@ CVE-2022-29711 (LibreNMS v22.3.0 was discovered to 
contain a cross-site scriptin
        NOT-FOR-US: LibreNMS
 CVE-2022-29710 (A cross-site scripting (XSS) vulnerability in 
uploadConfirm.php of Lim ...)
        - limesurvey <itp> (bug #472802)
-CVE-2022-29709
-       RESERVED
+CVE-2022-29709 (CommuniLink Internet Limited CLink Office v2.0 was discovered 
to conta ...)
+       TODO: check
 CVE-2022-29708
        RESERVED
 CVE-2022-29707
@@ -20133,62 +20793,52 @@ CVE-2022-29028 (A vulnerability has been identified 
in JT2Go (All versions &lt;
        NOT-FOR-US: JT2Go / Siemens
 CVE-2022-1315
        RESERVED
-CVE-2022-1314
-       RESERVED
+CVE-2022-1314 (Type confusion in V8 in Google Chrome prior to 100.0.4896.88 
allowed a ...)
        {DSA-5120-1}
        - chromium 100.0.4896.88-1
        [buster] - chromium <end-of-life> (see DSA 5046)
        [stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2022-1313
-       RESERVED
+CVE-2022-1313 (Use after free in tab groups in Google Chrome prior to 
100.0.4896.88 a ...)
        {DSA-5120-1}
        - chromium 100.0.4896.88-1
        [buster] - chromium <end-of-life> (see DSA 5046)
        [stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2022-1312
-       RESERVED
+CVE-2022-1312 (Use after free in storage in Google Chrome prior to 
100.0.4896.88 allo ...)
        {DSA-5120-1}
        - chromium 100.0.4896.88-1
        [buster] - chromium <end-of-life> (see DSA 5046)
        [stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2022-1311
-       RESERVED
+CVE-2022-1311 (Use after free in shell in Google Chrome on ChromeOS prior to 
100.0.48 ...)
        {DSA-5120-1}
        - chromium 100.0.4896.88-1
        [buster] - chromium <end-of-life> (see DSA 5046)
        [stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2022-1310
-       RESERVED
+CVE-2022-1310 (Use after free in regular expressions in Google Chrome prior to 
100.0. ...)
        {DSA-5120-1}
        - chromium 100.0.4896.88-1
        [buster] - chromium <end-of-life> (see DSA 5046)
        [stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2022-1309
-       RESERVED
+CVE-2022-1309 (Insufficient policy enforcement in developer tools in Google 
Chrome pr ...)
        {DSA-5120-1}
        - chromium 100.0.4896.88-1
        [buster] - chromium <end-of-life> (see DSA 5046)
        [stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2022-1308
-       RESERVED
+CVE-2022-1308 (Use after free in BFCache in Google Chrome prior to 
100.0.4896.88 allo ...)
        {DSA-5120-1}
        - chromium 100.0.4896.88-1
        [buster] - chromium <end-of-life> (see DSA 5046)
        [stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2022-1307
-       RESERVED
+CVE-2022-1307 (Inappropriate implementation in full screen in Google Chrome on 
Androi ...)
        {DSA-5120-1}
        - chromium 100.0.4896.88-1
        [buster] - chromium <end-of-life> (see DSA 5046)
        [stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2022-1306
-       RESERVED
+CVE-2022-1306 (Inappropriate implementation in compositing in Google Chrome 
prior to  ...)
        {DSA-5120-1}
        - chromium 100.0.4896.88-1
        [buster] - chromium <end-of-life> (see DSA 5046)
        [stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2022-1305
-       RESERVED
+CVE-2022-1305 (Use after free in storage in Google Chrome prior to 
100.0.4896.88 allo ...)
        {DSA-5120-1}
        - chromium 100.0.4896.88-1
        [buster] - chromium <end-of-life> (see DSA 5046)
@@ -21249,8 +21899,7 @@ CVE-2022-1234 (XSS in livehelperchat in GitHub 
repository livehelperchat/livehel
        NOT-FOR-US: livehelperchat
 CVE-2022-1233 (URL Confusion When Scheme Not Supplied in GitHub repository 
medialize/ ...)
        NOT-FOR-US: URI.js
-CVE-2022-1232
-       RESERVED
+CVE-2022-1232 (Type confusion in V8 in Google Chrome prior to 100.0.4896.75 
allowed a ...)
        {DSA-5114-1}
        - chromium 100.0.4896.75-1
        [buster] - chromium <end-of-life> (see DSA 5046)
@@ -26712,8 +27361,8 @@ CVE-2022-0901 (The Ad Inserter Free and Pro WordPress 
plugins before 2.7.12 do n
        NOT-FOR-US: WordPress plugins
 CVE-2022-0900 (A Stored Cross-Site Scripting (XSS) vulnerability in 
DivvyDrive's "aci ...)
        NOT-FOR-US: DivvyDrive
-CVE-2022-0899
-       RESERVED
+CVE-2022-0899 (The Header Footer Code Manager WordPress plugin before 1.1.24 
does not ...)
+       TODO: check
 CVE-2022-0898 (The IgniteUp WordPress plugin through 3.4.1 does not sanitise 
and esca ...)
        NOT-FOR-US: WordPress plugin
 CVE-2022-0897 (A flaw was found in the libvirt nwfilter driver. The 
virNWFilterObjLis ...)
@@ -28086,12 +28735,12 @@ CVE-2022-26309
        RESERVED
 CVE-2022-26308
        RESERVED
-CVE-2022-26307
-       RESERVED
-CVE-2022-26306
-       RESERVED
-CVE-2022-26305
-       RESERVED
+CVE-2022-26307 (LibreOffice supports the storage of passwords for web 
connections in t ...)
+       TODO: check
+CVE-2022-26306 (LibreOffice supports the storage of passwords for web 
connections in t ...)
+       TODO: check
+CVE-2022-26305 (An Improper Certificate Validation vulnerability in 
LibreOffice existe ...)
+       TODO: check
 CVE-2022-26301 (TuziCMS v2.0.6 was discovered to contain a SQL injection 
vulnerability ...)
        NOT-FOR-US: TuziCMS
 CVE-2022-26300 (EOS v2.1.0 was discovered to contain a heap-buffer-overflow 
via the fu ...)
@@ -29240,8 +29889,8 @@ CVE-2022-21810
        RESERVED
 CVE-2022-21803 (This affects the package nconf before 0.11.4. When using the 
memory en ...)
        NOT-FOR-US: node nconf
-CVE-2022-21802
-       RESERVED
+CVE-2022-21802 (The package grapesjs before 0.19.5 are vulnerable to 
Cross-site Script ...)
+       TODO: check
 CVE-2022-21797
        RESERVED
 CVE-2022-21235 (The package github.com/masterminds/vcs before 1.13.3 are 
vulnerable to ...)
@@ -30761,8 +31410,8 @@ CVE-2022-0672 (A flaw was found in LemMinX in versions 
prior to 0.19.0. Insecure
        NOT-FOR-US: LemMinX
 CVE-2022-0671 (A flaw was found in vscode-xml in versions prior to 0.19.0. 
Schema dow ...)
        NOT-FOR-US: vscode-xml
-CVE-2022-0670
-       RESERVED
+CVE-2022-0670 (A flaw was found in Openstack manilla owning a Ceph File system 
"share ...)
+       TODO: check
 CVE-2022-0669
        RESERVED
        {DSA-5130-1}
@@ -31368,8 +32017,8 @@ CVE-2022-0596 (Business Logic Errors in Packagist 
microweber/microweber prior to
        NOT-FOR-US: microweber
 CVE-2022-0595 (The Drag and Drop Multiple File Upload WordPress plugin before 
1.3.6.3 ...)
        NOT-FOR-US: WordPress plugin
-CVE-2022-0594
-       RESERVED
+CVE-2022-0594 (The Professional Social Sharing Buttons, Icons &amp; Related 
Posts Wor ...)
+       TODO: check
 CVE-2022-0593 (The Login with phone number WordPress plugin before 1.3.7 
includes a f ...)
        NOT-FOR-US: WordPress plugin
 CVE-2022-0592 (The MapSVG WordPress plugin before 6.2.20 does not validate and 
escape ...)
@@ -31718,8 +32367,8 @@ CVE-2022-24994
        RESERVED
 CVE-2022-24993
        RESERVED
-CVE-2022-24992
-       RESERVED
+CVE-2022-24992 (A vulnerability in the component process.php of QR Code 
Generator v5.2 ...)
+       TODO: check
 CVE-2022-24991
        RESERVED
 CVE-2022-24990
@@ -34751,8 +35400,8 @@ CVE-2022-24085
        RESERVED
 CVE-2022-24084
        RESERVED
-CVE-2022-24083
-       RESERVED
+CVE-2022-24083 (Password authentication bypass vulnerability for local 
accounts can be ...)
+       TODO: check
 CVE-2022-24082 (If an on-premise installation of the Pega Platform is 
configured with  ...)
        NOT-FOR-US: Pega Platform
 CVE-2022-24081
@@ -38359,7 +39008,7 @@ CVE-2022-0217 [Unauthenticated Remote Denial of Service 
Attack in the WebSocket
        NOTE: Regression fix: https://hg.prosody.im/trunk/rev/e5e0ab93d7f4
 CVE-2022-0210 (The Random Banner WordPress plugin is vulnerable to Stored 
Cross-Site  ...)
        NOT-FOR-US: WordPress plugin
-CVE-2022-0209 (The Mitsol Social Post Feed plugin for WordPress is vulnerable 
to Stor ...)
+CVE-2022-0209 (The Mitsol Social Post Feed WordPress plugin before 1.11 does 
not esca ...)
        NOT-FOR-US: Mitsol Social Post Feed plugin for WordPress
 CVE-2022-0208 (The MapPress Maps for WordPress plugin before 2.73.4 does not 
sanitise ...)
        NOT-FOR-US: WordPress plugin
@@ -61895,10 +62544,10 @@ CVE-2021-40338 (Hitachi Energy LinkOne product, has a 
vulnerability due to a web
        NOT-FOR-US: Hitachi
 CVE-2021-40337 (Cross-site Scripting (XSS) vulnerability in Hitachi Energy 
LinkOne all ...)
        NOT-FOR-US: Hitachi
-CVE-2021-40336
-       RESERVED
-CVE-2021-40335
-       RESERVED
+CVE-2021-40336 (A vulnerability exists in the http web interface where the web 
interfa ...)
+       TODO: check
+CVE-2021-40335 (A vulnerability exists in the HTTP web interface where the web 
interfa ...)
+       TODO: check
 CVE-2021-40334 (Missing Handler vulnerability in the proprietary management 
protocol ( ...)
        NOT-FOR-US: Hitachi
 CVE-2021-40333 (Weak Password Requirements vulnerability in Hitachi Energy 
FOX61x, XCM ...)
@@ -104300,8 +104949,8 @@ CVE-2021-23453
        RESERVED
 CVE-2021-23452 (This affects all versions of package x-assign. The global 
proto object ...)
        NOT-FOR-US: x-assign JS
-CVE-2021-23451
-       RESERVED
+CVE-2021-23451 (The package otp-generator before 3.0.0 are vulnerable to 
Insecure Rand ...)
+       TODO: check
 CVE-2021-23450 (All versions of package dojo are vulnerable to Prototype 
Pollution via ...)
        - dojo <unfixed> (bug #1014785)
        [bullseye] - dojo <no-dsa> (Minor issue)
@@ -104450,8 +105099,8 @@ CVE-2021-23399 (This affects all versions of package 
wincred. If attacker-contro
        NOT-FOR-US: wincred
 CVE-2021-23398 (All versions of package react-bootstrap-table are vulnerable 
to Cross- ...)
        NOT-FOR-US: react-bootstrap-table
-CVE-2021-23397
-       RESERVED
+CVE-2021-23397 (All versions of package @ianwalter/merge are vulnerable to 
Prototype P ...)
+       TODO: check
 CVE-2021-23396 (All versions of package lutils are vulnerable to Prototype 
Pollution v ...)
        NOT-FOR-US: Node lutils
 CVE-2021-23395 (This affects all versions of package nedb. The library could 
be tricke ...)
@@ -104506,8 +105155,8 @@ CVE-2021-23375 (This affects all versions of package 
psnode. If attacker-control
        NOT-FOR-US: Node psnode
 CVE-2021-23374 (This affects all versions of package ps-visitor. If 
attacker-controlle ...)
        NOT-FOR-US: Node ps-visitor
-CVE-2021-23373
-       RESERVED
+CVE-2021-23373 (All versions of package set-deep-prop are vulnerable to 
Prototype Poll ...)
+       TODO: check
 CVE-2021-23372 (All versions of package mongo-express are vulnerable to Denial 
of Serv ...)
        NOT-FOR-US: mongo-express
 CVE-2021-23371 (This affects the package chrono-node before 2.2.4. It hangs on 
a date- ...)
@@ -121545,8 +122194,8 @@ CVE-2020-28473 (The package bottle from 0 and before 
0.12.19 are vulnerable to W
        NOTE: Fixed by: 
https://github.com/bottlepy/bottle/commit/57a2f22e0c1d2b328c4f54bf75741d74f47f1a6b
 (0.12.19)
 CVE-2020-28472 (This affects the package @aws-sdk/shared-ini-file-loader 
before 1.0.0- ...)
        NOT-FOR-US: aws-sdk-js
-CVE-2020-28471
-       RESERVED
+CVE-2020-28471 (This affects the package properties-reader before 2.2.0. ...)
+       TODO: check
 CVE-2020-28470 (This affects the package @scullyio/scully before 1.0.9. The 
transfer s ...)
        NOT-FOR-US: scully
 CVE-2020-28469 (This affects the package glob-parent before 5.1.2. The 
enclosure regex ...)
@@ -121574,22 +122223,22 @@ CVE-2020-28463 (All versions of package reportlab 
are vulnerable to Server-side
        NOTE: https://snyk.io/vuln/SNYK-PYTHON-REPORTLAB-1022145
        NOTE: Starting in 3.5.55 trustedSchemes and trustedHosts rl_config 
variables are introduced
        NOTE: which can be used to mitigate the issue, treating this as the 
fixed version
-CVE-2020-28462
-       RESERVED
-CVE-2020-28461
-       RESERVED
+CVE-2020-28462 (This affects all versions of package ion-parser. If an 
attacker submit ...)
+       TODO: check
+CVE-2020-28461 (This affects the package js-ini before 1.3.0. If an attacker 
submits a ...)
+       TODO: check
 CVE-2020-28460 (This affects the package multi-ini before 2.1.2. It is 
possible to pol ...)
        NOT-FOR-US: Node multi-ini
-CVE-2020-28459
-       RESERVED
+CVE-2020-28459 (This affects all versions of package markdown-it-decorate. An 
attacker ...)
+       TODO: check
 CVE-2020-28458 (All versions of package datatables.net are vulnerable to 
Prototype Pol ...)
        NOT-FOR-US: Node datatables.net
 CVE-2020-28457 (This affects the package s-cart/core before 4.4. The search 
functional ...)
        NOT-FOR-US: s-cart/core
 CVE-2020-28456 (The package s-cart/core before 4.4 are vulnerable to 
Cross-site Script ...)
        NOT-FOR-US: s-cart/core
-CVE-2020-28455
-       RESERVED
+CVE-2020-28455 (This affects all versions of package markdown-it-toc. The 
title of the ...)
+       TODO: check
 CVE-2020-28454
        RESERVED
 CVE-2020-28453
@@ -121604,32 +122253,32 @@ CVE-2020-28449 (This affects all versions of 
package decal. The vulnerability is
        NOT-FOR-US: Node decal
 CVE-2020-28448 (This affects the package multi-ini before 2.1.1. It is 
possible to pol ...)
        NOT-FOR-US: Node multi-ini
-CVE-2020-28447
-       RESERVED
-CVE-2020-28446
-       RESERVED
-CVE-2020-28445
-       RESERVED
+CVE-2020-28447 (This affects all versions of package xopen. The injection 
point is loc ...)
+       TODO: check
+CVE-2020-28446 (The package ntesseract before 0.2.9 are vulnerable to Command 
Injectio ...)
+       TODO: check
+CVE-2020-28445 (This affects all versions of package npm-help. The injection 
point is  ...)
+       TODO: check
 CVE-2020-28444
        RESERVED
-CVE-2020-28443
-       RESERVED
+CVE-2020-28443 (This affects all versions of package sonar-wrapper. The 
injection poin ...)
+       TODO: check
 CVE-2020-28442 (All versions of package js-data are vulnerable to Prototype 
Pollution  ...)
        NOT-FOR-US: Node js-data
-CVE-2020-28441
-       RESERVED
+CVE-2020-28441 (This affects the package conf-cfg-ini before 1.2.2. If an 
attacker sub ...)
+       TODO: check
 CVE-2020-28440 (All versions of package corenlp-js-interface are vulnerable to 
Command ...)
        NOT-FOR-US: corenlp-js-interface
 CVE-2020-28439 (This affects all versions of package corenlp-js-prefab. The 
injection  ...)
        NOT-FOR-US: corenlp-js-prefab
-CVE-2020-28438
-       RESERVED
+CVE-2020-28438 (This affects all versions of package deferred-exec. The 
injection poin ...)
+       TODO: check
 CVE-2020-28437
        RESERVED
-CVE-2020-28436
-       RESERVED
-CVE-2020-28435
-       RESERVED
+CVE-2020-28436 (This affects all versions of package 
google-cloudstorage-commands. ...)
+       TODO: check
+CVE-2020-28435 (This affects all versions of package ffmpeg-sdk. The injection 
point i ...)
+       TODO: check
 CVE-2020-28434
        RESERVED
 CVE-2020-28433
@@ -121654,8 +122303,8 @@ CVE-2020-28424
        RESERVED
 CVE-2020-28423
        RESERVED
-CVE-2020-28422
-       RESERVED
+CVE-2020-28422 (All versions of package git-archive are vulnerable to Command 
Injectio ...)
+       TODO: check
 CVE-2020-28421 (CA Unified Infrastructure Management 20.1 and earlier contains 
a vulne ...)
        NOT-FOR-US: CA Unified Infrastructure Management
 CVE-2020-28420
@@ -175491,10 +176140,10 @@ CVE-2020-7680 (docsify prior to 4.11.4 is 
susceptible to Cross-site Scripting (X
        NOT-FOR-US: docsify
 CVE-2020-7679 (In all versions of package casperjs, the mergeObjects utility 
function ...)
        NOT-FOR-US: Node casperjs
-CVE-2020-7678
-       RESERVED
-CVE-2020-7677
-       RESERVED
+CVE-2020-7678 (This affects all versions of package node-import. The "params" 
argumen ...)
+       TODO: check
+CVE-2020-7677 (This affects the package thenify before 3.3.1. The name 
argument provi ...)
+       TODO: check
 CVE-2020-7676 (angular.js prior to 1.8.0 allows cross site scripting. The 
regex-based ...)
        - angular.js 1.8.0-1
        [buster] - angular.js <no-dsa> (Minor issue; can be fixed via point 
release)
@@ -175566,8 +176215,8 @@ CVE-2020-7651 (All versions of snyk-broker before 
4.79.0 are vulnerable to Arbit
        NOT-FOR-US: snyk-broker
 CVE-2020-7650 (All versions of snyk-broker after 4.72.0 including and before 
4.73.1 a ...)
        NOT-FOR-US: snyk-broker
-CVE-2020-7649
-       RESERVED
+CVE-2020-7649 (This affects the package snyk-broker before 4.73.0. It allows 
arbitrar ...)
+       TODO: check
 CVE-2020-7648 (All versions of snyk-broker before 4.72.2 are vulnerable to 
Arbitrary  ...)
        NOT-FOR-US: snyk-broker
 CVE-2020-7647 (All versions before 1.6.7 and all versions after 2.0.0 
inclusive and b ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e8d280a9e9da2355af26a6c6489d2cedf9dcefd6

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e8d280a9e9da2355af26a6c6489d2cedf9dcefd6
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to