CVE-2019-9083: Blind SQL injection in SQLiteManager 1.2.4
Actually someone already reported same issue in: https://bugs.debian.org/889224
ASan: heap-buffer-overflow ./src/otsu.c:272 in thresholding
CVE-2018-14950: SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack. CVE-2018-14951: SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack. CVE-2018-14952: SquirrelMail through 1.4.22 has XSS via a "<math><maction xlink:href=" attack. CVE-2018-14953: SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack. CVE-2018-14954: The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute. CVE-2018-14955: SquirrelMail...
opngreduc.c:957: opng_reduce_to_palette: Assertion `index >= 0' failed.
Can we close this issue? Seems to be fixed already.
CVE-2017-11115, CVE-2017-11116, CVE-2017-11117, CVE-2017-11118
Moritz commented in IRC that starting with stretch the Debian packages uses libsndfile for parsing all that RIFF files, so it's not affected by all those upstream crashes in the internal parser. This might be the cause of the reproducing issues. In my 2017-09-07 comment I only tested with CVS version. This bug should be closed.