[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 4 09:10:26 BST 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0abb00eb by security tracker role at 2022-08-04T08:10:18+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,39 @@
+CVE-2022-37397
+	RESERVED
+CVE-2022-37345
+	RESERVED
+CVE-2022-37334
+	RESERVED
+CVE-2022-37327
+	RESERVED
+CVE-2022-36789
+	RESERVED
+CVE-2022-36391
+	RESERVED
+CVE-2022-36339
+	RESERVED
+CVE-2022-35400
+	RESERVED
+CVE-2022-35276
+	RESERVED
+CVE-2022-34152
+	RESERVED
+CVE-2022-32766
+	RESERVED
+CVE-2022-2646
+	RESERVED
+CVE-2022-2645
+	RESERVED
+CVE-2022-2644
+	RESERVED
+CVE-2022-2643
+	RESERVED
+CVE-2022-2642
+	RESERVED
+CVE-2022-2641
+	RESERVED
+CVE-2022-2640
+	RESERVED
 CVE-2022-37396 (In JetBrains Rider before 2022.2 Trust and Open Project dialog could b ...)
 	TODO: check
 CVE-2022-37395
@@ -3583,8 +3619,8 @@ CVE-2022-35930
 	RESERVED
 CVE-2022-35929
 	RESERVED
-CVE-2022-35928
-	RESERVED
+CVE-2022-35928 (AES Crypt is a file encryption software for multiple platforms. AES Cr ...)
+	TODO: check
 CVE-2022-35927
 	RESERVED
 CVE-2022-35926
@@ -4610,10 +4646,10 @@ CVE-2022-35508
 	RESERVED
 CVE-2022-35507
 	RESERVED
-CVE-2022-35506
-	RESERVED
-CVE-2022-35505
-	RESERVED
+CVE-2022-35506 (TripleCross v0.1.0 was discovered to contain a stack overflow which oc ...)
+	TODO: check
+CVE-2022-35505 (A segmentation fault in TripleCross v0.1.0 occurs when sending a contr ...)
+	TODO: check
 CVE-2022-35504
 	RESERVED
 CVE-2022-35503
@@ -5457,14 +5493,14 @@ CVE-2022-35163
 	RESERVED
 CVE-2022-35162
 	RESERVED
-CVE-2022-35161
-	RESERVED
+CVE-2022-35161 (GVRET Stable Release as of Aug 15, 2015 was discovered to contain a bu ...)
+	TODO: check
 CVE-2022-35160
 	RESERVED
 CVE-2022-35159
 	RESERVED
-CVE-2022-35158
-	RESERVED
+CVE-2022-35158 (A vulnerability in the lua parser of TscanCode tsclua v2.15.01 allows  ...)
+	TODO: check
 CVE-2022-35157
 	RESERVED
 CVE-2022-35156
@@ -16036,8 +16072,8 @@ CVE-2022-1797 (A malformed Class 3 common industrial protocol message with a cac
 	NOT-FOR-US: Rockwell Automation
 CVE-2022-31198 (OpenZeppelin Contracts is a library for secure smart contract developm ...)
 	NOT-FOR-US: OpenZeppelin
-CVE-2022-31197
-	RESERVED
+CVE-2022-31197 (PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to conn ...)
+	TODO: check
 CVE-2022-31196
 	RESERVED
 CVE-2022-31195 (DSpace open source software is a repository application which provides ...)
@@ -16081,8 +16117,8 @@ CVE-2022-31177 (Flask-AppBuilder is an application development framework built o
 	NOTE: https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-32ff-4g79-vgfc
 CVE-2022-31176
 	RESERVED
-CVE-2022-31175
-	RESERVED
+CVE-2022-31175 (CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vu ...)
+	TODO: check
 CVE-2022-31174
 	RESERVED
 CVE-2022-31173 (Juniper is a GraphQL server library for Rust. Affected versions of Jun ...)
@@ -26837,8 +26873,8 @@ CVE-2022-27553
 	RESERVED
 CVE-2022-27552
 	RESERVED
-CVE-2022-27551
-	RESERVED
+CVE-2022-27551 (HCL Launch could allow an authenticated user to obtain sensitive infor ...)
+	TODO: check
 CVE-2022-27550
 	RESERVED
 CVE-2022-27549 (HCL Launch may store certain data for recurring activities in a plain  ...)
@@ -55773,9 +55809,9 @@ CVE-2021-43181 (In JetBrains Hub before 2021.1.13690, stored XSS is possible. ..
 CVE-2021-43180 (In JetBrains Hub before 2021.1.13690, information disclosure via avata ...)
 	NOT-FOR-US: JetBrains Hub
 CVE-2021-43179
-	RESERVED
+	REJECTED
 CVE-2021-43178
-	RESERVED
+	REJECTED
 CVE-2021-43177 (As a result of an incomplete fix for CVE-2015-7225, in versions of dev ...)
 	- ruby-devise-two-factor 4.0.2-1 (bug #1009636)
 	NOTE: https://github.com/tinfoil/devise-two-factor/security/advisories/GHSA-jm35-h8q2-73mp



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0abb00eb7f533df449620ec22a0143704a5a2e28

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0abb00eb7f533df449620ec22a0143704a5a2e28
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220804/36c0cb91/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list