[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 4 09:10:26 BST 2022
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0abb00eb by security tracker role at 2022-08-04T08:10:18+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,39 @@
+CVE-2022-37397
+ RESERVED
+CVE-2022-37345
+ RESERVED
+CVE-2022-37334
+ RESERVED
+CVE-2022-37327
+ RESERVED
+CVE-2022-36789
+ RESERVED
+CVE-2022-36391
+ RESERVED
+CVE-2022-36339
+ RESERVED
+CVE-2022-35400
+ RESERVED
+CVE-2022-35276
+ RESERVED
+CVE-2022-34152
+ RESERVED
+CVE-2022-32766
+ RESERVED
+CVE-2022-2646
+ RESERVED
+CVE-2022-2645
+ RESERVED
+CVE-2022-2644
+ RESERVED
+CVE-2022-2643
+ RESERVED
+CVE-2022-2642
+ RESERVED
+CVE-2022-2641
+ RESERVED
+CVE-2022-2640
+ RESERVED
CVE-2022-37396 (In JetBrains Rider before 2022.2 Trust and Open Project dialog could b ...)
TODO: check
CVE-2022-37395
@@ -3583,8 +3619,8 @@ CVE-2022-35930
RESERVED
CVE-2022-35929
RESERVED
-CVE-2022-35928
- RESERVED
+CVE-2022-35928 (AES Crypt is a file encryption software for multiple platforms. AES Cr ...)
+ TODO: check
CVE-2022-35927
RESERVED
CVE-2022-35926
@@ -4610,10 +4646,10 @@ CVE-2022-35508
RESERVED
CVE-2022-35507
RESERVED
-CVE-2022-35506
- RESERVED
-CVE-2022-35505
- RESERVED
+CVE-2022-35506 (TripleCross v0.1.0 was discovered to contain a stack overflow which oc ...)
+ TODO: check
+CVE-2022-35505 (A segmentation fault in TripleCross v0.1.0 occurs when sending a contr ...)
+ TODO: check
CVE-2022-35504
RESERVED
CVE-2022-35503
@@ -5457,14 +5493,14 @@ CVE-2022-35163
RESERVED
CVE-2022-35162
RESERVED
-CVE-2022-35161
- RESERVED
+CVE-2022-35161 (GVRET Stable Release as of Aug 15, 2015 was discovered to contain a bu ...)
+ TODO: check
CVE-2022-35160
RESERVED
CVE-2022-35159
RESERVED
-CVE-2022-35158
- RESERVED
+CVE-2022-35158 (A vulnerability in the lua parser of TscanCode tsclua v2.15.01 allows ...)
+ TODO: check
CVE-2022-35157
RESERVED
CVE-2022-35156
@@ -16036,8 +16072,8 @@ CVE-2022-1797 (A malformed Class 3 common industrial protocol message with a cac
NOT-FOR-US: Rockwell Automation
CVE-2022-31198 (OpenZeppelin Contracts is a library for secure smart contract developm ...)
NOT-FOR-US: OpenZeppelin
-CVE-2022-31197
- RESERVED
+CVE-2022-31197 (PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to conn ...)
+ TODO: check
CVE-2022-31196
RESERVED
CVE-2022-31195 (DSpace open source software is a repository application which provides ...)
@@ -16081,8 +16117,8 @@ CVE-2022-31177 (Flask-AppBuilder is an application development framework built o
NOTE: https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-32ff-4g79-vgfc
CVE-2022-31176
RESERVED
-CVE-2022-31175
- RESERVED
+CVE-2022-31175 (CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vu ...)
+ TODO: check
CVE-2022-31174
RESERVED
CVE-2022-31173 (Juniper is a GraphQL server library for Rust. Affected versions of Jun ...)
@@ -26837,8 +26873,8 @@ CVE-2022-27553
RESERVED
CVE-2022-27552
RESERVED
-CVE-2022-27551
- RESERVED
+CVE-2022-27551 (HCL Launch could allow an authenticated user to obtain sensitive infor ...)
+ TODO: check
CVE-2022-27550
RESERVED
CVE-2022-27549 (HCL Launch may store certain data for recurring activities in a plain ...)
@@ -55773,9 +55809,9 @@ CVE-2021-43181 (In JetBrains Hub before 2021.1.13690, stored XSS is possible. ..
CVE-2021-43180 (In JetBrains Hub before 2021.1.13690, information disclosure via avata ...)
NOT-FOR-US: JetBrains Hub
CVE-2021-43179
- RESERVED
+ REJECTED
CVE-2021-43178
- RESERVED
+ REJECTED
CVE-2021-43177 (As a result of an incomplete fix for CVE-2015-7225, in versions of dev ...)
- ruby-devise-two-factor 4.0.2-1 (bug #1009636)
NOTE: https://github.com/tinfoil/devise-two-factor/security/advisories/GHSA-jm35-h8q2-73mp
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0abb00eb7f533df449620ec22a0143704a5a2e28
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0abb00eb7f533df449620ec22a0143704a5a2e28
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220804/36c0cb91/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list