[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 25 21:10:26 BST 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e8d280a9 by security tracker role at 2022-07-25T20:10:18+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,665 @@
+CVE-2022-36760
+	RESERVED
+CVE-2022-36759
+	RESERVED
+CVE-2022-36758
+	RESERVED
+CVE-2022-36757
+	RESERVED
+CVE-2022-36756
+	RESERVED
+CVE-2022-36755
+	RESERVED
+CVE-2022-36754
+	RESERVED
+CVE-2022-36753
+	RESERVED
+CVE-2022-36752
+	RESERVED
+CVE-2022-36751
+	RESERVED
+CVE-2022-36750
+	RESERVED
+CVE-2022-36749
+	RESERVED
+CVE-2022-36748
+	RESERVED
+CVE-2022-36747
+	RESERVED
+CVE-2022-36746
+	RESERVED
+CVE-2022-36745
+	RESERVED
+CVE-2022-36744
+	RESERVED
+CVE-2022-36743
+	RESERVED
+CVE-2022-36742
+	RESERVED
+CVE-2022-36741
+	RESERVED
+CVE-2022-36740
+	RESERVED
+CVE-2022-36739
+	RESERVED
+CVE-2022-36738
+	RESERVED
+CVE-2022-36737
+	RESERVED
+CVE-2022-36736
+	RESERVED
+CVE-2022-36735
+	RESERVED
+CVE-2022-36734
+	RESERVED
+CVE-2022-36733
+	RESERVED
+CVE-2022-36732
+	RESERVED
+CVE-2022-36731
+	RESERVED
+CVE-2022-36730
+	RESERVED
+CVE-2022-36729
+	RESERVED
+CVE-2022-36728
+	RESERVED
+CVE-2022-36727
+	RESERVED
+CVE-2022-36726
+	RESERVED
+CVE-2022-36725
+	RESERVED
+CVE-2022-36724
+	RESERVED
+CVE-2022-36723
+	RESERVED
+CVE-2022-36722
+	RESERVED
+CVE-2022-36721
+	RESERVED
+CVE-2022-36720
+	RESERVED
+CVE-2022-36719
+	RESERVED
+CVE-2022-36718
+	RESERVED
+CVE-2022-36717
+	RESERVED
+CVE-2022-36716
+	RESERVED
+CVE-2022-36715
+	RESERVED
+CVE-2022-36714
+	RESERVED
+CVE-2022-36713
+	RESERVED
+CVE-2022-36712
+	RESERVED
+CVE-2022-36711
+	RESERVED
+CVE-2022-36710
+	RESERVED
+CVE-2022-36709
+	RESERVED
+CVE-2022-36708
+	RESERVED
+CVE-2022-36707
+	RESERVED
+CVE-2022-36706
+	RESERVED
+CVE-2022-36705
+	RESERVED
+CVE-2022-36704
+	RESERVED
+CVE-2022-36703
+	RESERVED
+CVE-2022-36702
+	RESERVED
+CVE-2022-36701
+	RESERVED
+CVE-2022-36700
+	RESERVED
+CVE-2022-36699
+	RESERVED
+CVE-2022-36698
+	RESERVED
+CVE-2022-36697
+	RESERVED
+CVE-2022-36696
+	RESERVED
+CVE-2022-36695
+	RESERVED
+CVE-2022-36694
+	RESERVED
+CVE-2022-36693
+	RESERVED
+CVE-2022-36692
+	RESERVED
+CVE-2022-36691
+	RESERVED
+CVE-2022-36690
+	RESERVED
+CVE-2022-36689
+	RESERVED
+CVE-2022-36688
+	RESERVED
+CVE-2022-36687
+	RESERVED
+CVE-2022-36686
+	RESERVED
+CVE-2022-36685
+	RESERVED
+CVE-2022-36684
+	RESERVED
+CVE-2022-36683
+	RESERVED
+CVE-2022-36682
+	RESERVED
+CVE-2022-36681
+	RESERVED
+CVE-2022-36680
+	RESERVED
+CVE-2022-36679
+	RESERVED
+CVE-2022-36678
+	RESERVED
+CVE-2022-36677
+	RESERVED
+CVE-2022-36676
+	RESERVED
+CVE-2022-36675
+	RESERVED
+CVE-2022-36674
+	RESERVED
+CVE-2022-36673
+	RESERVED
+CVE-2022-36672
+	RESERVED
+CVE-2022-36671
+	RESERVED
+CVE-2022-36670
+	RESERVED
+CVE-2022-36669
+	RESERVED
+CVE-2022-36668
+	RESERVED
+CVE-2022-36667
+	RESERVED
+CVE-2022-36666
+	RESERVED
+CVE-2022-36665
+	RESERVED
+CVE-2022-36664
+	RESERVED
+CVE-2022-36663
+	RESERVED
+CVE-2022-36662
+	RESERVED
+CVE-2022-36661
+	RESERVED
+CVE-2022-36660
+	RESERVED
+CVE-2022-36659
+	RESERVED
+CVE-2022-36658
+	RESERVED
+CVE-2022-36657
+	RESERVED
+CVE-2022-36656
+	RESERVED
+CVE-2022-36655
+	RESERVED
+CVE-2022-36654
+	RESERVED
+CVE-2022-36653
+	RESERVED
+CVE-2022-36652
+	RESERVED
+CVE-2022-36651
+	RESERVED
+CVE-2022-36650
+	RESERVED
+CVE-2022-36649
+	RESERVED
+CVE-2022-36648
+	RESERVED
+CVE-2022-36647
+	RESERVED
+CVE-2022-36646
+	RESERVED
+CVE-2022-36645
+	RESERVED
+CVE-2022-36644
+	RESERVED
+CVE-2022-36643
+	RESERVED
+CVE-2022-36642
+	RESERVED
+CVE-2022-36641
+	RESERVED
+CVE-2022-36640
+	RESERVED
+CVE-2022-36639
+	RESERVED
+CVE-2022-36638
+	RESERVED
+CVE-2022-36637
+	RESERVED
+CVE-2022-36636
+	RESERVED
+CVE-2022-36635
+	RESERVED
+CVE-2022-36634
+	RESERVED
+CVE-2022-36633
+	RESERVED
+CVE-2022-36632
+	RESERVED
+CVE-2022-36631
+	RESERVED
+CVE-2022-36630
+	RESERVED
+CVE-2022-36629
+	RESERVED
+CVE-2022-36628
+	RESERVED
+CVE-2022-36627
+	RESERVED
+CVE-2022-36626
+	RESERVED
+CVE-2022-36625
+	RESERVED
+CVE-2022-36624
+	RESERVED
+CVE-2022-36623
+	RESERVED
+CVE-2022-36622
+	RESERVED
+CVE-2022-36621
+	RESERVED
+CVE-2022-36620
+	RESERVED
+CVE-2022-36619
+	RESERVED
+CVE-2022-36618
+	RESERVED
+CVE-2022-36617
+	RESERVED
+CVE-2022-36616
+	RESERVED
+CVE-2022-36615
+	RESERVED
+CVE-2022-36614
+	RESERVED
+CVE-2022-36613
+	RESERVED
+CVE-2022-36612
+	RESERVED
+CVE-2022-36611
+	RESERVED
+CVE-2022-36610
+	RESERVED
+CVE-2022-36609
+	RESERVED
+CVE-2022-36608
+	RESERVED
+CVE-2022-36607
+	RESERVED
+CVE-2022-36606
+	RESERVED
+CVE-2022-36605
+	RESERVED
+CVE-2022-36604
+	RESERVED
+CVE-2022-36603
+	RESERVED
+CVE-2022-36602
+	RESERVED
+CVE-2022-36601
+	RESERVED
+CVE-2022-36600
+	RESERVED
+CVE-2022-36599
+	RESERVED
+CVE-2022-36598
+	RESERVED
+CVE-2022-36597
+	RESERVED
+CVE-2022-36596
+	RESERVED
+CVE-2022-36595
+	RESERVED
+CVE-2022-36594
+	RESERVED
+CVE-2022-36593
+	RESERVED
+CVE-2022-36592
+	RESERVED
+CVE-2022-36591
+	RESERVED
+CVE-2022-36590
+	RESERVED
+CVE-2022-36589
+	RESERVED
+CVE-2022-36588
+	RESERVED
+CVE-2022-36587
+	RESERVED
+CVE-2022-36586
+	RESERVED
+CVE-2022-36585
+	RESERVED
+CVE-2022-36584
+	RESERVED
+CVE-2022-36583
+	RESERVED
+CVE-2022-36582
+	RESERVED
+CVE-2022-36581
+	RESERVED
+CVE-2022-36580
+	RESERVED
+CVE-2022-36579
+	RESERVED
+CVE-2022-36578
+	RESERVED
+CVE-2022-36577
+	RESERVED
+CVE-2022-36576
+	RESERVED
+CVE-2022-36575
+	RESERVED
+CVE-2022-36574
+	RESERVED
+CVE-2022-36573
+	RESERVED
+CVE-2022-36572
+	RESERVED
+CVE-2022-36571
+	RESERVED
+CVE-2022-36570
+	RESERVED
+CVE-2022-36569
+	RESERVED
+CVE-2022-36568
+	RESERVED
+CVE-2022-36567
+	RESERVED
+CVE-2022-36566
+	RESERVED
+CVE-2022-36565
+	RESERVED
+CVE-2022-36564
+	RESERVED
+CVE-2022-36563
+	RESERVED
+CVE-2022-36562
+	RESERVED
+CVE-2022-36561
+	RESERVED
+CVE-2022-36560
+	RESERVED
+CVE-2022-36559
+	RESERVED
+CVE-2022-36558
+	RESERVED
+CVE-2022-36557
+	RESERVED
+CVE-2022-36556
+	RESERVED
+CVE-2022-36555
+	RESERVED
+CVE-2022-36554
+	RESERVED
+CVE-2022-36553
+	RESERVED
+CVE-2022-36552
+	RESERVED
+CVE-2022-36551
+	RESERVED
+CVE-2022-36550
+	RESERVED
+CVE-2022-36549
+	RESERVED
+CVE-2022-36548
+	RESERVED
+CVE-2022-36547
+	RESERVED
+CVE-2022-36546
+	RESERVED
+CVE-2022-36545
+	RESERVED
+CVE-2022-36544
+	RESERVED
+CVE-2022-36543
+	RESERVED
+CVE-2022-36542
+	RESERVED
+CVE-2022-36541
+	RESERVED
+CVE-2022-36540
+	RESERVED
+CVE-2022-36539
+	RESERVED
+CVE-2022-36538
+	RESERVED
+CVE-2022-36537
+	RESERVED
+CVE-2022-36536
+	RESERVED
+CVE-2022-36535
+	RESERVED
+CVE-2022-36534
+	RESERVED
+CVE-2022-36533
+	RESERVED
+CVE-2022-36532
+	RESERVED
+CVE-2022-36531
+	RESERVED
+CVE-2022-36530
+	RESERVED
+CVE-2022-36529
+	RESERVED
+CVE-2022-36528
+	RESERVED
+CVE-2022-36527
+	RESERVED
+CVE-2022-36526
+	RESERVED
+CVE-2022-36525
+	RESERVED
+CVE-2022-36524
+	RESERVED
+CVE-2022-36523
+	RESERVED
+CVE-2022-36522
+	RESERVED
+CVE-2022-36521
+	RESERVED
+CVE-2022-36520
+	RESERVED
+CVE-2022-36519
+	RESERVED
+CVE-2022-36518
+	RESERVED
+CVE-2022-36517
+	RESERVED
+CVE-2022-36516
+	RESERVED
+CVE-2022-36515
+	RESERVED
+CVE-2022-36514
+	RESERVED
+CVE-2022-36513
+	RESERVED
+CVE-2022-36512
+	RESERVED
+CVE-2022-36511
+	RESERVED
+CVE-2022-36510
+	RESERVED
+CVE-2022-36509
+	RESERVED
+CVE-2022-36508
+	RESERVED
+CVE-2022-36507
+	RESERVED
+CVE-2022-36506
+	RESERVED
+CVE-2022-36505
+	RESERVED
+CVE-2022-36504
+	RESERVED
+CVE-2022-36503
+	RESERVED
+CVE-2022-36502
+	RESERVED
+CVE-2022-36501
+	RESERVED
+CVE-2022-36500
+	RESERVED
+CVE-2022-36499
+	RESERVED
+CVE-2022-36498
+	RESERVED
+CVE-2022-36497
+	RESERVED
+CVE-2022-36496
+	RESERVED
+CVE-2022-36495
+	RESERVED
+CVE-2022-36494
+	RESERVED
+CVE-2022-36493
+	RESERVED
+CVE-2022-36492
+	RESERVED
+CVE-2022-36491
+	RESERVED
+CVE-2022-36490
+	RESERVED
+CVE-2022-36489
+	RESERVED
+CVE-2022-36488
+	RESERVED
+CVE-2022-36487
+	RESERVED
+CVE-2022-36486
+	RESERVED
+CVE-2022-36485
+	RESERVED
+CVE-2022-36484
+	RESERVED
+CVE-2022-36483
+	RESERVED
+CVE-2022-36482
+	RESERVED
+CVE-2022-36481
+	RESERVED
+CVE-2022-36480
+	RESERVED
+CVE-2022-36479
+	RESERVED
+CVE-2022-36478
+	RESERVED
+CVE-2022-36477
+	RESERVED
+CVE-2022-36476
+	RESERVED
+CVE-2022-36475
+	RESERVED
+CVE-2022-36474
+	RESERVED
+CVE-2022-36473
+	RESERVED
+CVE-2022-36472
+	RESERVED
+CVE-2022-36471
+	RESERVED
+CVE-2022-36470
+	RESERVED
+CVE-2022-36469
+	RESERVED
+CVE-2022-36468
+	RESERVED
+CVE-2022-36467
+	RESERVED
+CVE-2022-36466
+	RESERVED
+CVE-2022-36465
+	RESERVED
+CVE-2022-36464
+	RESERVED
+CVE-2022-36463
+	RESERVED
+CVE-2022-36462
+	RESERVED
+CVE-2022-36461
+	RESERVED
+CVE-2022-36460
+	RESERVED
+CVE-2022-36459
+	RESERVED
+CVE-2022-36458
+	RESERVED
+CVE-2022-36457
+	RESERVED
+CVE-2022-36456
+	RESERVED
+CVE-2022-36455
+	RESERVED
+CVE-2022-36454
+	RESERVED
+CVE-2022-36453
+	RESERVED
+CVE-2022-36452
+	RESERVED
+CVE-2022-36451
+	RESERVED
+CVE-2022-36450 (Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-ad ...)
+	TODO: check
+CVE-2022-36449
+	RESERVED
+CVE-2022-36448
+	RESERVED
+CVE-2022-36447
+	RESERVED
+CVE-2022-36446 (software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a U ...)
+	TODO: check
+CVE-2022-36445
+	RESERVED
+CVE-2022-36444 (An issue was discovered in Atos Unify OpenScape SBC 9 and 10 before 10 ...)
+	TODO: check
+CVE-2022-36443
+	RESERVED
+CVE-2022-36442
+	RESERVED
+CVE-2022-36441
+	RESERVED
+CVE-2022-36440
+	RESERVED
+CVE-2022-2537
+	RESERVED
+CVE-2022-2536
+	RESERVED
+CVE-2022-2535
+	RESERVED
+CVE-2022-2534
+	RESERVED
+CVE-2022-2533
+	RESERVED
+CVE-2022-2532
+	RESERVED
+CVE-2022-2531
+	RESERVED
+CVE-2022-2530
+	RESERVED
+CVE-2022-2529
+	RESERVED
+CVE-2022-2528
+	RESERVED
 CVE-2022-36439
 	RESERVED
 CVE-2022-36438
@@ -57,8 +719,8 @@ CVE-2022-34859
 	RESERVED
 CVE-2022-33963
 	RESERVED
-CVE-2022-2523
-	RESERVED
+CVE-2022-2523 (Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/ ...)
+	TODO: check
 CVE-2022-36381
 	RESERVED
 CVE-2022-36293
@@ -105,8 +767,8 @@ CVE-2022-34147
 	RESERVED
 CVE-2022-31137 (Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Kee ...)
 	NOT-FOR-US: Roxy-WI
-CVE-2022-2522
-	RESERVED
+CVE-2022-2522 (Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0 ...)
+	TODO: check
 CVE-2022-2521
 	RESERVED
 CVE-2022-2520
@@ -180,8 +842,8 @@ CVE-2022-34154
 	RESERVED
 CVE-2022-33970
 	RESERVED
-CVE-2022-33969
-	RESERVED
+CVE-2022-33969 (Authenticated WordPress Options Change vulnerability in Biplob Adhikar ...)
+	TODO: check
 CVE-2022-33943
 	RESERVED
 CVE-2022-33201
@@ -190,8 +852,8 @@ CVE-2022-33142
 	RESERVED
 CVE-2022-2515
 	RESERVED
-CVE-2022-2514
-	RESERVED
+CVE-2022-2514 (The time and filter parameters in Fava prior to v1.22 are vulnerable t ...)
+	TODO: check
 CVE-2022-2513
 	RESERVED
 CVE-2022-2512
@@ -1940,20 +2602,15 @@ CVE-2022-35655
 	RESERVED
 CVE-2022-35654
 	RESERVED
-CVE-2022-35653
-	RESERVED
+CVE-2022-35653 (A reflected XSS issue was identified in the LTI module of Moodle. The  ...)
 	- moodle <removed>
-CVE-2022-35652
-	RESERVED
+CVE-2022-35652 (An open redirect issue was found in Moodle due to improper sanitizatio ...)
 	- moodle <removed>
-CVE-2022-35651
-	RESERVED
+CVE-2022-35651 (A stored XSS and blind SSRF vulnerability was found in Moodle, occurs  ...)
 	- moodle <removed>
-CVE-2022-35650
-	RESERVED
+CVE-2022-35650 (The vulnerability was found in Moodle, occurs due to input validation  ...)
 	- moodle <removed>
-CVE-2022-35649
-	RESERVED
+CVE-2022-35649 (The vulnerability was found in Moodle, occurs due to improper input va ...)
 	- moodle <removed>
 CVE-2022-33977
 	RESERVED
@@ -2797,10 +3454,10 @@ CVE-2022-2343 (Heap-based Buffer Overflow in GitHub repository vim/vim prior to
 	NOTE: Crash in CLI tool, no security impact
 CVE-2022-2342 (Cross-site Scripting (XSS) - Stored in GitHub repository outline/outli ...)
 	NOT-FOR-US: outline
-CVE-2022-2341
-	RESERVED
-CVE-2022-2340
-	RESERVED
+CVE-2022-2341 (The Simple Page Transition WordPress plugin through 1.4.1 does not san ...)
+	TODO: check
+CVE-2022-2340 (The W-DALIL WordPress plugin through 2.0 does not sanitise and escape  ...)
+	TODO: check
 CVE-2022-35299
 	RESERVED
 CVE-2022-35298
@@ -2823,16 +3480,16 @@ CVE-2022-35290
 	RESERVED
 CVE-2022-35289
 	RESERVED
-CVE-2022-35288
-	RESERVED
-CVE-2022-35287
-	RESERVED
+CVE-2022-35288 (IBM Security Verify Information Queue 10.0.2 could allow a user to obt ...)
+	TODO: check
+CVE-2022-35287 (IBM Security Verify Information Queue 10.0.2 contains hard-coded crede ...)
+	TODO: check
 CVE-2022-35286
 	RESERVED
-CVE-2022-35285
-	RESERVED
-CVE-2022-35284
-	RESERVED
+CVE-2022-35285 (IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-si ...)
+	TODO: check
+CVE-2022-35284 (IBM Security Verify Information Queue 10.0.2 could disclose sensitive  ...)
+	TODO: check
 CVE-2022-35283 (IBM Security Verify Information Queue 10.0.2 could allow an authentica ...)
 	NOT-FOR-US: IBM
 CVE-2022-35282
@@ -3534,16 +4191,16 @@ CVE-2022-34967
 	RESERVED
 CVE-2022-34966
 	RESERVED
-CVE-2022-34965
-	RESERVED
-CVE-2022-34964
-	RESERVED
-CVE-2022-34963
-	RESERVED
-CVE-2022-34962
-	RESERVED
-CVE-2022-34961
-	RESERVED
+CVE-2022-34965 (OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered ...)
+	TODO: check
+CVE-2022-34964 (OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered ...)
+	TODO: check
+CVE-2022-34963 (OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered ...)
+	TODO: check
+CVE-2022-34962 (OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered ...)
+	TODO: check
+CVE-2022-34961 (OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered ...)
+	TODO: check
 CVE-2022-34960
 	RESERVED
 CVE-2022-34959
@@ -3660,8 +4317,8 @@ CVE-2022-2301 (Buffer Over-read in GitHub repository hpjansson/chafa prior to 1.
 	NOTE: Crash in CLI tool, no security impact
 CVE-2022-2300 (Cross-site Scripting (XSS) - Stored in GitHub repository microweber/mi ...)
 	NOT-FOR-US: microweber
-CVE-2022-2299
-	RESERVED
+CVE-2022-2299 (The Allow SVG Files WordPress plugin through 1.1 does not sanitise upl ...)
+	TODO: check
 CVE-2022-2298 (A vulnerability has been found in SourceCodester Clinics Patient Manag ...)
 	NOT-FOR-US: Clinics Patient Management System
 CVE-2022-2297 (A vulnerability, which was classified as critical, was found in Source ...)
@@ -3895,8 +4552,8 @@ CVE-2022-34148
 	RESERVED
 CVE-2022-33974
 	RESERVED
-CVE-2022-33965
-	RESERVED
+CVE-2022-33965 (Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osama ...)
+	TODO: check
 CVE-2022-33961
 	RESERVED
 CVE-2022-33960 (Multiple Authenticated (subscriber or higher user role) SQL Injection  ...)
@@ -4230,10 +4887,10 @@ CVE-2022-2242
 	RESERVED
 CVE-2022-2241
 	RESERVED
-CVE-2022-2240
-	RESERVED
-CVE-2022-2239
-	RESERVED
+CVE-2022-2240 (The Request a Quote WordPress plugin through 2.3.7 does not validate u ...)
+	TODO: check
+CVE-2022-2239 (The Request a Quote WordPress plugin through 2.3.7 does not sanitise a ...)
+	TODO: check
 CVE-2022-2238
 	RESERVED
 	NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes 2 / Stolostron
@@ -4468,8 +5125,8 @@ CVE-2022-2221 (Information Exposure vulnerability in My Account Settings of Devo
 CVE-2022-2220
 	RESERVED
 	NOT-FOR-US: OpenShift
-CVE-2022-2219
-	RESERVED
+CVE-2022-2219 (The Unyson WordPress plugin before 2.7.27 does not sanitise and escape ...)
+	TODO: check
 CVE-2022-2218 (Cross-site Scripting (XSS) - Stored in GitHub repository ionicabizau/p ...)
 	NOT-FOR-US: Node parse-url
 CVE-2022-2217 (Cross-site Scripting (XSS) - Generic in GitHub repository ionicabizau/ ...)
@@ -4879,7 +5536,8 @@ CVE-2022-2210 (Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. ..
 	NOTE: https://huntr.dev/bounties/020845f8-f047-4072-af0f-3726fe1aea25
 	NOTE: https://github.com/vim/vim/commit/c101abff4c6756db4f5e740fde289decb9452efa (v8.2.5164)
 	NOTE: Crash in CLI tool, no security impact
-CVE-2022-2209 (io_uring uses work_flags to determine which identity need to grab from ...)
+CVE-2022-2209
+	REJECTED
 	- linux <unfixed>
 CVE-2022-2208 (NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.516 ...)
 	- vim <unfixed> (unimportant)
@@ -5322,8 +5980,8 @@ CVE-2022-34348
 	RESERVED
 CVE-2022-2190
 	RESERVED
-CVE-2022-2189
-	RESERVED
+CVE-2022-2189 (The WP Video Lightbox WordPress plugin before 1.9.5 does not escape th ...)
+	TODO: check
 CVE-2022-2188
 	RESERVED
 CVE-2022-2187 (The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not esca ...)
@@ -5908,8 +6566,8 @@ CVE-2022-2133 (The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't v
 	NOT-FOR-US: WordPress plugin
 CVE-2022-2132
 	RESERVED
-CVE-2022-2131
-	RESERVED
+CVE-2022-2131 (OpenKM Community Edition in its 6.3.10 version and before was using XM ...)
+	TODO: check
 CVE-2022-2130 (Cross-site Scripting (XSS) - Reflected in GitHub repository microweber ...)
 	NOT-FOR-US: microweber
 CVE-2022-XXXX [vlc issues fixed in 3.0.13]
@@ -6611,8 +7269,8 @@ CVE-2022-2117 (The GiveWP plugin for WordPress is vulnerable to Sensitive Inform
 	NOT-FOR-US: WordPress plugin
 CVE-2022-2116
 	RESERVED
-CVE-2022-2115
-	RESERVED
+CVE-2022-2115 (The Popup Anything WordPress plugin before 2.1.7 does not sanitise and ...)
+	TODO: check
 CVE-2022-2114 (The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-2113 (Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inv ...)
@@ -8199,9 +8857,11 @@ CVE-2022-29472
 	RESERVED
 CVE-2022-27804
 	RESERVED
-CVE-2022-2077 (** DISPUTED ** A vulnerability was found in Microsoft O365 and classif ...)
+CVE-2022-2077
+	REJECTED
 	NOT-FOR-US: Microsoft
-CVE-2022-2076 (** DISPUTED ** A vulnerability has been found in Microsoft O365 and cl ...)
+CVE-2022-2076
+	REJECTED
 	NOT-FOR-US: Microsoft
 CVE-2022-2075
 	RESERVED
@@ -8651,10 +9311,10 @@ CVE-2022-28710
 	RESERVED
 CVE-2022-27805
 	RESERVED
-CVE-2022-2072
-	RESERVED
-CVE-2022-2071
-	RESERVED
+CVE-2022-2072 (The Name Directory WordPress plugin before 1.25.3 does not sanitise an ...)
+	TODO: check
+CVE-2022-2071 (The Name Directory WordPress plugin before 1.25.4 does not have CSRF c ...)
+	TODO: check
 CVE-2022-2070
 	RESERVED
 CVE-2022-2069
@@ -8685,8 +9345,8 @@ CVE-2022-2061 (Heap-based Buffer Overflow in GitHub repository hpjansson/chafa p
 	NOTE: Crash in CLI tool, no security impact
 CVE-2022-2060 (Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/doli ...)
 	- dolibarr <removed>
-CVE-2022-2059
-	RESERVED
+CVE-2022-2059 (In Pandora FMS v7.0NG.761 and below, in the agent creation section, th ...)
+	TODO: check
 CVE-2021-46820 (Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0. ...)
 	NOT-FOR-US: XOS-Shop
 CVE-2020-36546
@@ -9679,8 +10339,8 @@ CVE-2022-2034
 	RESERVED
 CVE-2022-2033
 	RESERVED
-CVE-2022-2032
-	RESERVED
+CVE-2022-2032 (In Pandora FMS v7.0NG.761 and below, in the file manager section, the  ...)
+	TODO: check
 CVE-2022-2031
 	RESERVED
 CVE-2022-2030 (A directory traversal vulnerability caused by specific character seque ...)
@@ -16917,8 +17577,8 @@ CVE-2022-30115 (Using its HSTS support, curl can be instructed to use HTTPS dire
 	NOTE: https://curl.se/docs/CVE-2022-30115.html
 	NOTE: Introduced by: https://github.com/curl/curl/commit/b27ad8e1d3e68eb3214fcbb398ca436873aa7c67 (curl-7_82_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/fae6fea209a2d4db1582f608bd8cc8000721733a (curl-7_83_1)
-CVE-2022-1551
-	RESERVED
+CVE-2022-1551 (The SP Project & Document Manager WordPress plugin through 4.57 us ...)
+	TODO: check
 CVE-2022-1550
 	REJECTED
 CVE-2022-1549 (The WP Athletics WordPress plugin through 1.1.7 does not sanitize para ...)
@@ -17441,8 +18101,8 @@ CVE-2022-1541 (The Video Slider WordPress plugin before 1.4.8 does not sanitize
 	NOT-FOR-US: WordPress plugin
 CVE-2022-1540
 	RESERVED
-CVE-2022-1539
-	RESERVED
+CVE-2022-1539 (The Exports and Reports WordPress plugin before 0.9.2 does not sanitiz ...)
+	TODO: check
 CVE-2022-1538
 	RESERVED
 CVE-2022-1537 (file.copy operations in GruntJS are vulnerable to a TOCTOU race condit ...)
@@ -18213,8 +18873,8 @@ CVE-2022-29711 (LibreNMS v22.3.0 was discovered to contain a cross-site scriptin
 	NOT-FOR-US: LibreNMS
 CVE-2022-29710 (A cross-site scripting (XSS) vulnerability in uploadConfirm.php of Lim ...)
 	- limesurvey <itp> (bug #472802)
-CVE-2022-29709
-	RESERVED
+CVE-2022-29709 (CommuniLink Internet Limited CLink Office v2.0 was discovered to conta ...)
+	TODO: check
 CVE-2022-29708
 	RESERVED
 CVE-2022-29707
@@ -20133,62 +20793,52 @@ CVE-2022-29028 (A vulnerability has been identified in JT2Go (All versions <
 	NOT-FOR-US: JT2Go / Siemens
 CVE-2022-1315
 	RESERVED
-CVE-2022-1314
-	RESERVED
+CVE-2022-1314 (Type confusion in V8 in Google Chrome prior to 100.0.4896.88 allowed a ...)
 	{DSA-5120-1}
 	- chromium 100.0.4896.88-1
 	[buster] - chromium <end-of-life> (see DSA 5046)
 	[stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2022-1313
-	RESERVED
+CVE-2022-1313 (Use after free in tab groups in Google Chrome prior to 100.0.4896.88 a ...)
 	{DSA-5120-1}
 	- chromium 100.0.4896.88-1
 	[buster] - chromium <end-of-life> (see DSA 5046)
 	[stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2022-1312
-	RESERVED
+CVE-2022-1312 (Use after free in storage in Google Chrome prior to 100.0.4896.88 allo ...)
 	{DSA-5120-1}
 	- chromium 100.0.4896.88-1
 	[buster] - chromium <end-of-life> (see DSA 5046)
 	[stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2022-1311
-	RESERVED
+CVE-2022-1311 (Use after free in shell in Google Chrome on ChromeOS prior to 100.0.48 ...)
 	{DSA-5120-1}
 	- chromium 100.0.4896.88-1
 	[buster] - chromium <end-of-life> (see DSA 5046)
 	[stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2022-1310
-	RESERVED
+CVE-2022-1310 (Use after free in regular expressions in Google Chrome prior to 100.0. ...)
 	{DSA-5120-1}
 	- chromium 100.0.4896.88-1
 	[buster] - chromium <end-of-life> (see DSA 5046)
 	[stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2022-1309
-	RESERVED
+CVE-2022-1309 (Insufficient policy enforcement in developer tools in Google Chrome pr ...)
 	{DSA-5120-1}
 	- chromium 100.0.4896.88-1
 	[buster] - chromium <end-of-life> (see DSA 5046)
 	[stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2022-1308
-	RESERVED
+CVE-2022-1308 (Use after free in BFCache in Google Chrome prior to 100.0.4896.88 allo ...)
 	{DSA-5120-1}
 	- chromium 100.0.4896.88-1
 	[buster] - chromium <end-of-life> (see DSA 5046)
 	[stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2022-1307
-	RESERVED
+CVE-2022-1307 (Inappropriate implementation in full screen in Google Chrome on Androi ...)
 	{DSA-5120-1}
 	- chromium 100.0.4896.88-1
 	[buster] - chromium <end-of-life> (see DSA 5046)
 	[stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2022-1306
-	RESERVED
+CVE-2022-1306 (Inappropriate implementation in compositing in Google Chrome prior to  ...)
 	{DSA-5120-1}
 	- chromium 100.0.4896.88-1
 	[buster] - chromium <end-of-life> (see DSA 5046)
 	[stretch] - chromium <end-of-life> (see DSA 4562)
-CVE-2022-1305
-	RESERVED
+CVE-2022-1305 (Use after free in storage in Google Chrome prior to 100.0.4896.88 allo ...)
 	{DSA-5120-1}
 	- chromium 100.0.4896.88-1
 	[buster] - chromium <end-of-life> (see DSA 5046)
@@ -21249,8 +21899,7 @@ CVE-2022-1234 (XSS in livehelperchat in GitHub repository livehelperchat/livehel
 	NOT-FOR-US: livehelperchat
 CVE-2022-1233 (URL Confusion When Scheme Not Supplied in GitHub repository medialize/ ...)
 	NOT-FOR-US: URI.js
-CVE-2022-1232
-	RESERVED
+CVE-2022-1232 (Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a ...)
 	{DSA-5114-1}
 	- chromium 100.0.4896.75-1
 	[buster] - chromium <end-of-life> (see DSA 5046)
@@ -26712,8 +27361,8 @@ CVE-2022-0901 (The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do n
 	NOT-FOR-US: WordPress plugins
 CVE-2022-0900 (A Stored Cross-Site Scripting (XSS) vulnerability in DivvyDrive's "aci ...)
 	NOT-FOR-US: DivvyDrive
-CVE-2022-0899
-	RESERVED
+CVE-2022-0899 (The Header Footer Code Manager WordPress plugin before 1.1.24 does not ...)
+	TODO: check
 CVE-2022-0898 (The IgniteUp WordPress plugin through 3.4.1 does not sanitise and esca ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-0897 (A flaw was found in the libvirt nwfilter driver. The virNWFilterObjLis ...)
@@ -28086,12 +28735,12 @@ CVE-2022-26309
 	RESERVED
 CVE-2022-26308
 	RESERVED
-CVE-2022-26307
-	RESERVED
-CVE-2022-26306
-	RESERVED
-CVE-2022-26305
-	RESERVED
+CVE-2022-26307 (LibreOffice supports the storage of passwords for web connections in t ...)
+	TODO: check
+CVE-2022-26306 (LibreOffice supports the storage of passwords for web connections in t ...)
+	TODO: check
+CVE-2022-26305 (An Improper Certificate Validation vulnerability in LibreOffice existe ...)
+	TODO: check
 CVE-2022-26301 (TuziCMS v2.0.6 was discovered to contain a SQL injection vulnerability ...)
 	NOT-FOR-US: TuziCMS
 CVE-2022-26300 (EOS v2.1.0 was discovered to contain a heap-buffer-overflow via the fu ...)
@@ -29240,8 +29889,8 @@ CVE-2022-21810
 	RESERVED
 CVE-2022-21803 (This affects the package nconf before 0.11.4. When using the memory en ...)
 	NOT-FOR-US: node nconf
-CVE-2022-21802
-	RESERVED
+CVE-2022-21802 (The package grapesjs before 0.19.5 are vulnerable to Cross-site Script ...)
+	TODO: check
 CVE-2022-21797
 	RESERVED
 CVE-2022-21235 (The package github.com/masterminds/vcs before 1.13.3 are vulnerable to ...)
@@ -30761,8 +31410,8 @@ CVE-2022-0672 (A flaw was found in LemMinX in versions prior to 0.19.0. Insecure
 	NOT-FOR-US: LemMinX
 CVE-2022-0671 (A flaw was found in vscode-xml in versions prior to 0.19.0. Schema dow ...)
 	NOT-FOR-US: vscode-xml
-CVE-2022-0670
-	RESERVED
+CVE-2022-0670 (A flaw was found in Openstack manilla owning a Ceph File system "share ...)
+	TODO: check
 CVE-2022-0669
 	RESERVED
 	{DSA-5130-1}
@@ -31368,8 +32017,8 @@ CVE-2022-0596 (Business Logic Errors in Packagist microweber/microweber prior to
 	NOT-FOR-US: microweber
 CVE-2022-0595 (The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2022-0594
-	RESERVED
+CVE-2022-0594 (The Professional Social Sharing Buttons, Icons & Related Posts Wor ...)
+	TODO: check
 CVE-2022-0593 (The Login with phone number WordPress plugin before 1.3.7 includes a f ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-0592 (The MapSVG WordPress plugin before 6.2.20 does not validate and escape ...)
@@ -31718,8 +32367,8 @@ CVE-2022-24994
 	RESERVED
 CVE-2022-24993
 	RESERVED
-CVE-2022-24992
-	RESERVED
+CVE-2022-24992 (A vulnerability in the component process.php of QR Code Generator v5.2 ...)
+	TODO: check
 CVE-2022-24991
 	RESERVED
 CVE-2022-24990
@@ -34751,8 +35400,8 @@ CVE-2022-24085
 	RESERVED
 CVE-2022-24084
 	RESERVED
-CVE-2022-24083
-	RESERVED
+CVE-2022-24083 (Password authentication bypass vulnerability for local accounts can be ...)
+	TODO: check
 CVE-2022-24082 (If an on-premise installation of the Pega Platform is configured with  ...)
 	NOT-FOR-US: Pega Platform
 CVE-2022-24081
@@ -38359,7 +39008,7 @@ CVE-2022-0217 [Unauthenticated Remote Denial of Service Attack in the WebSocket
 	NOTE: Regression fix: https://hg.prosody.im/trunk/rev/e5e0ab93d7f4
 CVE-2022-0210 (The Random Banner WordPress plugin is vulnerable to Stored Cross-Site  ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2022-0209 (The Mitsol Social Post Feed plugin for WordPress is vulnerable to Stor ...)
+CVE-2022-0209 (The Mitsol Social Post Feed WordPress plugin before 1.11 does not esca ...)
 	NOT-FOR-US: Mitsol Social Post Feed plugin for WordPress
 CVE-2022-0208 (The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise ...)
 	NOT-FOR-US: WordPress plugin
@@ -61895,10 +62544,10 @@ CVE-2021-40338 (Hitachi Energy LinkOne product, has a vulnerability due to a web
 	NOT-FOR-US: Hitachi
 CVE-2021-40337 (Cross-site Scripting (XSS) vulnerability in Hitachi Energy LinkOne all ...)
 	NOT-FOR-US: Hitachi
-CVE-2021-40336
-	RESERVED
-CVE-2021-40335
-	RESERVED
+CVE-2021-40336 (A vulnerability exists in the http web interface where the web interfa ...)
+	TODO: check
+CVE-2021-40335 (A vulnerability exists in the HTTP web interface where the web interfa ...)
+	TODO: check
 CVE-2021-40334 (Missing Handler vulnerability in the proprietary management protocol ( ...)
 	NOT-FOR-US: Hitachi
 CVE-2021-40333 (Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM ...)
@@ -104300,8 +104949,8 @@ CVE-2021-23453
 	RESERVED
 CVE-2021-23452 (This affects all versions of package x-assign. The global proto object ...)
 	NOT-FOR-US: x-assign JS
-CVE-2021-23451
-	RESERVED
+CVE-2021-23451 (The package otp-generator before 3.0.0 are vulnerable to Insecure Rand ...)
+	TODO: check
 CVE-2021-23450 (All versions of package dojo are vulnerable to Prototype Pollution via ...)
 	- dojo <unfixed> (bug #1014785)
 	[bullseye] - dojo <no-dsa> (Minor issue)
@@ -104450,8 +105099,8 @@ CVE-2021-23399 (This affects all versions of package wincred. If attacker-contro
 	NOT-FOR-US: wincred
 CVE-2021-23398 (All versions of package react-bootstrap-table are vulnerable to Cross- ...)
 	NOT-FOR-US: react-bootstrap-table
-CVE-2021-23397
-	RESERVED
+CVE-2021-23397 (All versions of package @ianwalter/merge are vulnerable to Prototype P ...)
+	TODO: check
 CVE-2021-23396 (All versions of package lutils are vulnerable to Prototype Pollution v ...)
 	NOT-FOR-US: Node lutils
 CVE-2021-23395 (This affects all versions of package nedb. The library could be tricke ...)
@@ -104506,8 +105155,8 @@ CVE-2021-23375 (This affects all versions of package psnode. If attacker-control
 	NOT-FOR-US: Node psnode
 CVE-2021-23374 (This affects all versions of package ps-visitor. If attacker-controlle ...)
 	NOT-FOR-US: Node ps-visitor
-CVE-2021-23373
-	RESERVED
+CVE-2021-23373 (All versions of package set-deep-prop are vulnerable to Prototype Poll ...)
+	TODO: check
 CVE-2021-23372 (All versions of package mongo-express are vulnerable to Denial of Serv ...)
 	NOT-FOR-US: mongo-express
 CVE-2021-23371 (This affects the package chrono-node before 2.2.4. It hangs on a date- ...)
@@ -121545,8 +122194,8 @@ CVE-2020-28473 (The package bottle from 0 and before 0.12.19 are vulnerable to W
 	NOTE: Fixed by: https://github.com/bottlepy/bottle/commit/57a2f22e0c1d2b328c4f54bf75741d74f47f1a6b (0.12.19)
 CVE-2020-28472 (This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0- ...)
 	NOT-FOR-US: aws-sdk-js
-CVE-2020-28471
-	RESERVED
+CVE-2020-28471 (This affects the package properties-reader before 2.2.0. ...)
+	TODO: check
 CVE-2020-28470 (This affects the package @scullyio/scully before 1.0.9. The transfer s ...)
 	NOT-FOR-US: scully
 CVE-2020-28469 (This affects the package glob-parent before 5.1.2. The enclosure regex ...)
@@ -121574,22 +122223,22 @@ CVE-2020-28463 (All versions of package reportlab are vulnerable to Server-side
 	NOTE: https://snyk.io/vuln/SNYK-PYTHON-REPORTLAB-1022145
 	NOTE: Starting in 3.5.55 trustedSchemes and trustedHosts rl_config variables are introduced
 	NOTE: which can be used to mitigate the issue, treating this as the fixed version
-CVE-2020-28462
-	RESERVED
-CVE-2020-28461
-	RESERVED
+CVE-2020-28462 (This affects all versions of package ion-parser. If an attacker submit ...)
+	TODO: check
+CVE-2020-28461 (This affects the package js-ini before 1.3.0. If an attacker submits a ...)
+	TODO: check
 CVE-2020-28460 (This affects the package multi-ini before 2.1.2. It is possible to pol ...)
 	NOT-FOR-US: Node multi-ini
-CVE-2020-28459
-	RESERVED
+CVE-2020-28459 (This affects all versions of package markdown-it-decorate. An attacker ...)
+	TODO: check
 CVE-2020-28458 (All versions of package datatables.net are vulnerable to Prototype Pol ...)
 	NOT-FOR-US: Node datatables.net
 CVE-2020-28457 (This affects the package s-cart/core before 4.4. The search functional ...)
 	NOT-FOR-US: s-cart/core
 CVE-2020-28456 (The package s-cart/core before 4.4 are vulnerable to Cross-site Script ...)
 	NOT-FOR-US: s-cart/core
-CVE-2020-28455
-	RESERVED
+CVE-2020-28455 (This affects all versions of package markdown-it-toc. The title of the ...)
+	TODO: check
 CVE-2020-28454
 	RESERVED
 CVE-2020-28453
@@ -121604,32 +122253,32 @@ CVE-2020-28449 (This affects all versions of package decal. The vulnerability is
 	NOT-FOR-US: Node decal
 CVE-2020-28448 (This affects the package multi-ini before 2.1.1. It is possible to pol ...)
 	NOT-FOR-US: Node multi-ini
-CVE-2020-28447
-	RESERVED
-CVE-2020-28446
-	RESERVED
-CVE-2020-28445
-	RESERVED
+CVE-2020-28447 (This affects all versions of package xopen. The injection point is loc ...)
+	TODO: check
+CVE-2020-28446 (The package ntesseract before 0.2.9 are vulnerable to Command Injectio ...)
+	TODO: check
+CVE-2020-28445 (This affects all versions of package npm-help. The injection point is  ...)
+	TODO: check
 CVE-2020-28444
 	RESERVED
-CVE-2020-28443
-	RESERVED
+CVE-2020-28443 (This affects all versions of package sonar-wrapper. The injection poin ...)
+	TODO: check
 CVE-2020-28442 (All versions of package js-data are vulnerable to Prototype Pollution  ...)
 	NOT-FOR-US: Node js-data
-CVE-2020-28441
-	RESERVED
+CVE-2020-28441 (This affects the package conf-cfg-ini before 1.2.2. If an attacker sub ...)
+	TODO: check
 CVE-2020-28440 (All versions of package corenlp-js-interface are vulnerable to Command ...)
 	NOT-FOR-US: corenlp-js-interface
 CVE-2020-28439 (This affects all versions of package corenlp-js-prefab. The injection  ...)
 	NOT-FOR-US: corenlp-js-prefab
-CVE-2020-28438
-	RESERVED
+CVE-2020-28438 (This affects all versions of package deferred-exec. The injection poin ...)
+	TODO: check
 CVE-2020-28437
 	RESERVED
-CVE-2020-28436
-	RESERVED
-CVE-2020-28435
-	RESERVED
+CVE-2020-28436 (This affects all versions of package google-cloudstorage-commands. ...)
+	TODO: check
+CVE-2020-28435 (This affects all versions of package ffmpeg-sdk. The injection point i ...)
+	TODO: check
 CVE-2020-28434
 	RESERVED
 CVE-2020-28433
@@ -121654,8 +122303,8 @@ CVE-2020-28424
 	RESERVED
 CVE-2020-28423
 	RESERVED
-CVE-2020-28422
-	RESERVED
+CVE-2020-28422 (All versions of package git-archive are vulnerable to Command Injectio ...)
+	TODO: check
 CVE-2020-28421 (CA Unified Infrastructure Management 20.1 and earlier contains a vulne ...)
 	NOT-FOR-US: CA Unified Infrastructure Management
 CVE-2020-28420
@@ -175491,10 +176140,10 @@ CVE-2020-7680 (docsify prior to 4.11.4 is susceptible to Cross-site Scripting (X
 	NOT-FOR-US: docsify
 CVE-2020-7679 (In all versions of package casperjs, the mergeObjects utility function ...)
 	NOT-FOR-US: Node casperjs
-CVE-2020-7678
-	RESERVED
-CVE-2020-7677
-	RESERVED
+CVE-2020-7678 (This affects all versions of package node-import. The "params" argumen ...)
+	TODO: check
+CVE-2020-7677 (This affects the package thenify before 3.3.1. The name argument provi ...)
+	TODO: check
 CVE-2020-7676 (angular.js prior to 1.8.0 allows cross site scripting. The regex-based ...)
 	- angular.js 1.8.0-1
 	[buster] - angular.js <no-dsa> (Minor issue; can be fixed via point release)
@@ -175566,8 +176215,8 @@ CVE-2020-7651 (All versions of snyk-broker before 4.79.0 are vulnerable to Arbit
 	NOT-FOR-US: snyk-broker
 CVE-2020-7650 (All versions of snyk-broker after 4.72.0 including and before 4.73.1 a ...)
 	NOT-FOR-US: snyk-broker
-CVE-2020-7649
-	RESERVED
+CVE-2020-7649 (This affects the package snyk-broker before 4.73.0. It allows arbitrar ...)
+	TODO: check
 CVE-2020-7648 (All versions of snyk-broker before 4.72.2 are vulnerable to Arbitrary  ...)
 	NOT-FOR-US: snyk-broker
 CVE-2020-7647 (All versions before 1.6.7 and all versions after 2.0.0 inclusive and b ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e8d280a9e9da2355af26a6c6489d2cedf9dcefd6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e8d280a9e9da2355af26a6c6489d2cedf9dcefd6
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220725/cf32dae2/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list