We have too many <unfixed> entries w/o bugs. Unless you specifically
know that the maintainer or the security team is working on a fix
(of if it's about the kernel) please always file bugs, maintainers of
our more obscure and junky packages typically don't know about many
security problems.
Moritz