From 1203708441c2d712e738512f70a8d44961e09e42 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Tue, 22 Feb 2022 07:29:28 +0100 Subject: Track two issues in geckodriver, itp'ed --- data/CVE/2020.list | 2 +- data/CVE/2021.list | 1 + 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/data/CVE/2020.list b/data/CVE/2020.list index b906363eec..654068a6d0 100644 --- a/data/CVE/2020.list +++ b/data/CVE/2020.list @@ -35292,7 +35292,7 @@ CVE-2020-15661 (A rogue webpage could override the injected WKUserScript used by - firefox (Specific to Firefox for iOS) NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2020-34/#CVE-2020-15661 CVE-2020-15660 (Missing checks on Content-Type headers in geckodriver before 0.27.0 co ...) - NOT-FOR-US: geckodriver + - geckodriver (bug #989456) CVE-2020-15659 (Mozilla developers and community members reported memory safety bugs p ...) {DSA-4740-1 DSA-4736-1 DLA-2310-1 DLA-2297-1} - firefox 79.0-1 diff --git a/data/CVE/2021.list b/data/CVE/2021.list index 98f2a707c6..13bc719b4d 100644 --- a/data/CVE/2021.list +++ b/data/CVE/2021.list @@ -3788,6 +3788,7 @@ CVE-2021-4139 (pimcore is vulnerable to Improper Neutralization of Input During NOT-FOR-US: Pimcore CVE-2021-4138 RESERVED + - geckodriver (bug #989456) CVE-2021-45233 RESERVED CVE-2021-45232 (In Apache APISIX Dashboard before 2.10.1, the Manager API uses two fra ...) -- cgit v1.2.3