diff --git a/advisories/github-reviewed/2022/04/GHSA-5hgm-qm5m-5vmw/GHSA-5hgm-qm5m-5vmw.json b/advisories/github-reviewed/2022/04/GHSA-5hgm-qm5m-5vmw/GHSA-5hgm-qm5m-5vmw.json index 74cc0de7b28..1d2efd61437 100644 --- a/advisories/github-reviewed/2022/04/GHSA-5hgm-qm5m-5vmw/GHSA-5hgm-qm5m-5vmw.json +++ b/advisories/github-reviewed/2022/04/GHSA-5hgm-qm5m-5vmw/GHSA-5hgm-qm5m-5vmw.json @@ -8,9 +8,7 @@ ], "summary": "Jakarta Tomcat cross-site scripting (XSS) vulnerability", "details": "Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-22v7-w6c5-v4rr/GHSA-22v7-w6c5-v4rr.json b/advisories/github-reviewed/2022/05/GHSA-22v7-w6c5-v4rr/GHSA-22v7-w6c5-v4rr.json index 4e86e84d05c..a2c2103fe31 100644 --- a/advisories/github-reviewed/2022/05/GHSA-22v7-w6c5-v4rr/GHSA-22v7-w6c5-v4rr.json +++ b/advisories/github-reviewed/2022/05/GHSA-22v7-w6c5-v4rr/GHSA-22v7-w6c5-v4rr.json @@ -54,9 +54,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-07-31T22:56:15Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-69q7-hww4-8pjq/GHSA-69q7-hww4-8pjq.json b/advisories/github-reviewed/2022/05/GHSA-69q7-hww4-8pjq/GHSA-69q7-hww4-8pjq.json index 1df277d7df3..ba5b1d34561 100644 --- a/advisories/github-reviewed/2022/05/GHSA-69q7-hww4-8pjq/GHSA-69q7-hww4-8pjq.json +++ b/advisories/github-reviewed/2022/05/GHSA-69q7-hww4-8pjq/GHSA-69q7-hww4-8pjq.json @@ -53,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-07-13T17:08:08Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-9cjh-qmvx-436c/GHSA-9cjh-qmvx-436c.json b/advisories/github-reviewed/2022/05/GHSA-9cjh-qmvx-436c/GHSA-9cjh-qmvx-436c.json index 70a28d385d2..79a5f1f1b6c 100644 --- a/advisories/github-reviewed/2022/05/GHSA-9cjh-qmvx-436c/GHSA-9cjh-qmvx-436c.json +++ b/advisories/github-reviewed/2022/05/GHSA-9cjh-qmvx-436c/GHSA-9cjh-qmvx-436c.json @@ -8,9 +8,7 @@ ], "summary": "Apache Struts Cross-site scripting Vulnerability", "details": "Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-cwq3-qp8v-w8q3/GHSA-cwq3-qp8v-w8q3.json b/advisories/github-reviewed/2022/05/GHSA-cwq3-qp8v-w8q3/GHSA-cwq3-qp8v-w8q3.json index 64f32c95bc6..b1e35b9543f 100644 --- a/advisories/github-reviewed/2022/05/GHSA-cwq3-qp8v-w8q3/GHSA-cwq3-qp8v-w8q3.json +++ b/advisories/github-reviewed/2022/05/GHSA-cwq3-qp8v-w8q3/GHSA-cwq3-qp8v-w8q3.json @@ -8,9 +8,7 @@ ], "summary": "Mortbay Jetty Discloses JSP Source Code", "details": "Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash (`%5C`) characters. NOTE: this might be the same issue as CVE-2006-2758.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-jcp9-796g-pv9p/GHSA-jcp9-796g-pv9p.json b/advisories/github-reviewed/2022/05/GHSA-jcp9-796g-pv9p/GHSA-jcp9-796g-pv9p.json index 4c5b20d7add..51b4e5b5d1b 100644 --- a/advisories/github-reviewed/2022/05/GHSA-jcp9-796g-pv9p/GHSA-jcp9-796g-pv9p.json +++ b/advisories/github-reviewed/2022/05/GHSA-jcp9-796g-pv9p/GHSA-jcp9-796g-pv9p.json @@ -8,9 +8,7 @@ ], "summary": "Missing Cryptographic Step in OWASP Enterprise Security API for Java", "details": "The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attackers to bypass intended cryptographic protection mechanisms via an attack against authenticity in the default configuration, involving a null MAC and a zero MAC length.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-qhqv-q4xg-f6g7/GHSA-qhqv-q4xg-f6g7.json b/advisories/github-reviewed/2022/05/GHSA-qhqv-q4xg-f6g7/GHSA-qhqv-q4xg-f6g7.json index 7aed58d6c30..059e42ed849 100644 --- a/advisories/github-reviewed/2022/05/GHSA-qhqv-q4xg-f6g7/GHSA-qhqv-q4xg-f6g7.json +++ b/advisories/github-reviewed/2022/05/GHSA-qhqv-q4xg-f6g7/GHSA-qhqv-q4xg-f6g7.json @@ -8,9 +8,7 @@ ], "summary": "Apache Tomcat AJP Connector Information Leak", "details": "The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when \"unsuitable request body data\" is used for a different request, possibly related to Java Servlet pages.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-wj42-52pv-wfj2/GHSA-wj42-52pv-wfj2.json b/advisories/github-reviewed/2022/05/GHSA-wj42-52pv-wfj2/GHSA-wj42-52pv-wfj2.json index c4f04a7c8df..d5024805a05 100644 --- a/advisories/github-reviewed/2022/05/GHSA-wj42-52pv-wfj2/GHSA-wj42-52pv-wfj2.json +++ b/advisories/github-reviewed/2022/05/GHSA-wj42-52pv-wfj2/GHSA-wj42-52pv-wfj2.json @@ -8,9 +8,7 @@ ], "summary": "phpMyAdmin CRLF Injection Vulnerability", "details": "CRLF injection vulnerability in phpMyAdmin before 2.6.4-pl4 allows remote attackers to conduct HTTP response splitting attacks via unspecified scripts.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-09-18T23:46:33Z", diff --git a/advisories/github-reviewed/2022/09/GHSA-f36p-42jv-8rh2/GHSA-f36p-42jv-8rh2.json b/advisories/github-reviewed/2022/09/GHSA-f36p-42jv-8rh2/GHSA-f36p-42jv-8rh2.json index d43ddee4a98..4c86f17f04a 100644 --- a/advisories/github-reviewed/2022/09/GHSA-f36p-42jv-8rh2/GHSA-f36p-42jv-8rh2.json +++ b/advisories/github-reviewed/2022/09/GHSA-f36p-42jv-8rh2/GHSA-f36p-42jv-8rh2.json @@ -3,9 +3,7 @@ "id": "GHSA-f36p-42jv-8rh2", "modified": "2022-10-05T22:00:04Z", "published": "2022-09-30T04:53:37Z", - "aliases": [ - - ], + "aliases": [], "summary": "Lithium vulnerable to Cross Site Scripting in provided Swagger-UI", "details": "### Impact\nA XSS vulnerability in the provided (outdated) Swagger-UI is exploitable in applications using lithium with Swagger-UI enabled.\nThis allows an attacker gain Remote Code Execution (RCE) and potentially exfiltrate secrets in the context of this swagger session.\n\n\n### Patches\nThe used swagger-ui was updated by switching to the latest version of dropwizard-swagger in 8b9b406d608fe482ec0e7adf8705834bca92d7df\n\n\n### Workarounds\nThe risk of injected external content can be reduced by setting up a [Content-Security-Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy).\n\n\n### References\n* https://www.vidocsecurity.com/blog/hacking-swagger-ui-from-xss-to-account-takeovers/\n\n\n### Credits\nWe thank [Mohit Kumar](https://www.linkedin.com/in/mohit-kumar-4ab6b3bb) for reporting this vulnerability!\n", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-25gq-jvx2-vg9x/GHSA-25gq-jvx2-vg9x.json b/advisories/github-reviewed/2024/05/GHSA-25gq-jvx2-vg9x/GHSA-25gq-jvx2-vg9x.json index c94cd8e547b..93426e92681 100644 --- a/advisories/github-reviewed/2024/05/GHSA-25gq-jvx2-vg9x/GHSA-25gq-jvx2-vg9x.json +++ b/advisories/github-reviewed/2024/05/GHSA-25gq-jvx2-vg9x/GHSA-25gq-jvx2-vg9x.json @@ -3,9 +3,7 @@ "id": "GHSA-25gq-jvx2-vg9x", "modified": "2024-05-23T16:59:26Z", "published": "2024-05-23T16:59:25Z", - "aliases": [ - - ], + "aliases": [], "summary": "Silverstripe X-Forwarded-Host request hostname injection", "details": "A potential hostname injection vulnerability has been found which could allow attackers to alter url resolution.\n\nIf a request contains the X-Forwarded-Host HTTP header a website would then use its value in place of the actual HTTP hostname. In cases where caching is enabled, this could allow an attacker to potentially embed a remote url as the base_url for any site. This would then cause other visitors to the site to be redirected unknowingly.\n\nThis header is necessary for servers running behind a reverse proxy (such as nginx). Such servers are likely not vulnerable to this risk.\n\nA fix has been merged into the default installer, although existing projects which do not run behind a reverse proxy should update their htaccess as below:\n```\n\n # Remove X-Forwarded-Host header sent as a part of any request from the web\n RequestHeader unset X-Forwarded-Host\n\n```", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-2hpc-mf4q-j885/GHSA-2hpc-mf4q-j885.json b/advisories/github-reviewed/2024/05/GHSA-2hpc-mf4q-j885/GHSA-2hpc-mf4q-j885.json index d8f662cbc09..90e18cf9015 100644 --- a/advisories/github-reviewed/2024/05/GHSA-2hpc-mf4q-j885/GHSA-2hpc-mf4q-j885.json +++ b/advisories/github-reviewed/2024/05/GHSA-2hpc-mf4q-j885/GHSA-2hpc-mf4q-j885.json @@ -3,9 +3,7 @@ "id": "GHSA-2hpc-mf4q-j885", "modified": "2024-05-23T19:19:33Z", "published": "2024-05-23T19:19:33Z", - "aliases": [ - - ], + "aliases": [], "summary": "Silverstripe CSRF vulnerability in GridFieldAddExistingAutocompleter", "details": "GridField does not have sufficient CSRF protection, meaning that in some cases users with CMS access can be tricked into posting unspecified data into the CMS from external websites. Amongst other default CMS interfaces, GridField is used for management of groups, users and permissions in the CMS.\n\nThe resolution for this issue is to ensure that all gridFieldAlterAction submissions are checked for the SecurityID token during submission.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-34q6-xqxh-gq39/GHSA-34q6-xqxh-gq39.json b/advisories/github-reviewed/2024/05/GHSA-34q6-xqxh-gq39/GHSA-34q6-xqxh-gq39.json index a8bbae6b7d4..72e34915522 100644 --- a/advisories/github-reviewed/2024/05/GHSA-34q6-xqxh-gq39/GHSA-34q6-xqxh-gq39.json +++ b/advisories/github-reviewed/2024/05/GHSA-34q6-xqxh-gq39/GHSA-34q6-xqxh-gq39.json @@ -3,9 +3,7 @@ "id": "GHSA-34q6-xqxh-gq39", "modified": "2024-05-23T15:21:44Z", "published": "2024-05-23T15:21:44Z", - "aliases": [ - - ], + "aliases": [], "summary": "Silverstripe XSS In rewritten hash links", "details": "A high level XSS vulnerability has been discovered in the SilverStripe framework which causes links containing hash anchors (E.g. href=\"#anchor\") to be rewritten in an unsafe way.\n\nThe rewriteHashlinks option on SSViewer will rewrite these to contain the current url, although without adequate escaping, meaning that HTML could be injected via injecting unsafe values to any page via the querystring.\n\nDue to the nature of this issue it is likely that a large number of SilverStripe sites are affected.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-4h54-vwx9-3vr3/GHSA-4h54-vwx9-3vr3.json b/advisories/github-reviewed/2024/05/GHSA-4h54-vwx9-3vr3/GHSA-4h54-vwx9-3vr3.json index 110260e5fce..e46bc9b4595 100644 --- a/advisories/github-reviewed/2024/05/GHSA-4h54-vwx9-3vr3/GHSA-4h54-vwx9-3vr3.json +++ b/advisories/github-reviewed/2024/05/GHSA-4h54-vwx9-3vr3/GHSA-4h54-vwx9-3vr3.json @@ -3,9 +3,7 @@ "id": "GHSA-4h54-vwx9-3vr3", "modified": "2024-05-23T15:23:50Z", "published": "2024-05-23T15:23:50Z", - "aliases": [ - - ], + "aliases": [], "summary": "Silverstripe XSS In FormAction", "details": "A cross-site scripting vulnerability has been discovered in the FormAction field where a user-specified title may be specified.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-5f5v-5c3v-gw5v/GHSA-5f5v-5c3v-gw5v.json b/advisories/github-reviewed/2024/05/GHSA-5f5v-5c3v-gw5v/GHSA-5f5v-5c3v-gw5v.json index b67cae5b378..b9062ed82a7 100644 --- a/advisories/github-reviewed/2024/05/GHSA-5f5v-5c3v-gw5v/GHSA-5f5v-5c3v-gw5v.json +++ b/advisories/github-reviewed/2024/05/GHSA-5f5v-5c3v-gw5v/GHSA-5f5v-5c3v-gw5v.json @@ -3,9 +3,7 @@ "id": "GHSA-5f5v-5c3v-gw5v", "modified": "2024-05-23T14:45:11Z", "published": "2024-05-23T14:45:11Z", - "aliases": [ - - ], + "aliases": [], "summary": "Silverstripe IE requests not properly behaving with rewritehashlinks", "details": "Non IE browsers don’t appear to be affected, but I haven’t tested a wide range of browsers to be sure \n\nRequests that come through from IE do NOT appear to encode all entities in the URL string, meaning they are inserted into output content directly by SSViewer::process() when rewriting hashlinks, as it directly outputs $_SERVER[‘REQUEST_URI’]\n\n**Example IE8 request**\n127.0.0.1 - - [18/Jun/2014:14:13:42 +1000] “GET /site/cars/brands/toyota?one=1\\”onmouseover=\\”alert(‘things’);\\” HTTP/1.1” 200\n\n**Example FF request**\n127.0.0.1 - - [18/Jun/2014:14:14:22 +1000] “GET /site/cars/brands/toyota?one=1\\%22onmouseover=\\%22alert(%27things%27);\\%22 HTTP/1.1” 200\n\nThis causes any hash anchor to have the JS code inserted into the page as-is.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-88jp-9jrv-6368/GHSA-88jp-9jrv-6368.json b/advisories/github-reviewed/2024/05/GHSA-88jp-9jrv-6368/GHSA-88jp-9jrv-6368.json index 1f776633866..cc5c307f971 100644 --- a/advisories/github-reviewed/2024/05/GHSA-88jp-9jrv-6368/GHSA-88jp-9jrv-6368.json +++ b/advisories/github-reviewed/2024/05/GHSA-88jp-9jrv-6368/GHSA-88jp-9jrv-6368.json @@ -3,9 +3,7 @@ "id": "GHSA-88jp-9jrv-6368", "modified": "2024-05-23T15:00:45Z", "published": "2024-05-23T15:00:45Z", - "aliases": [ - - ], + "aliases": [], "summary": "Silverstripe XSS In GridField print", "details": "A cross-site scripting vulnerability has been discovered in the print view of GridField.\n\nThis vulnerability can only be exploited if a user with CMS access has posted malicious or unescaped HTML into any field of an object in a GridField, and the print feature is used.\n\nThis has been resolved by ensuring that the print feature safely escapes all fields.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-f7cq-5v43-8pwp/GHSA-f7cq-5v43-8pwp.json b/advisories/github-reviewed/2024/05/GHSA-f7cq-5v43-8pwp/GHSA-f7cq-5v43-8pwp.json index 5fbface30d0..d0239f5e52c 100644 --- a/advisories/github-reviewed/2024/05/GHSA-f7cq-5v43-8pwp/GHSA-f7cq-5v43-8pwp.json +++ b/advisories/github-reviewed/2024/05/GHSA-f7cq-5v43-8pwp/GHSA-f7cq-5v43-8pwp.json @@ -3,9 +3,7 @@ "id": "GHSA-f7cq-5v43-8pwp", "modified": "2024-05-23T15:19:41Z", "published": "2024-05-23T15:19:41Z", - "aliases": [ - - ], + "aliases": [], "summary": "Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop", "details": "### Impact\n\nThere is a vulnerability in [GO managing malformed DNS message](https://groups.google.com/g/golang-announce/c/wkkO4P9stm0), which impacts Traefik.\nThis vulnerability could be exploited to cause a denial of service.\n\n### References\n\n- [CVE-2024-24788](https://www.cve.org/CVERecord?id=CVE-2024-24788)\n\n### Patches\n\n- https://github.com/traefik/traefik/releases/tag/v2.11.3\n- https://github.com/traefik/traefik/releases/tag/v3.0.1\n\n### Workarounds\n\nNo workaround.\n\n### For more information\n\nIf you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-g43w-98wp-m694/GHSA-g43w-98wp-m694.json b/advisories/github-reviewed/2024/05/GHSA-g43w-98wp-m694/GHSA-g43w-98wp-m694.json index 1e71ff77d9a..1b4fb7907b2 100644 --- a/advisories/github-reviewed/2024/05/GHSA-g43w-98wp-m694/GHSA-g43w-98wp-m694.json +++ b/advisories/github-reviewed/2024/05/GHSA-g43w-98wp-m694/GHSA-g43w-98wp-m694.json @@ -3,9 +3,7 @@ "id": "GHSA-g43w-98wp-m694", "modified": "2024-05-23T14:49:39Z", "published": "2024-05-23T14:49:39Z", - "aliases": [ - - ], + "aliases": [], "summary": "SilverStripe framework XML Quadratic Blowup Attack", "details": "A low level vulnerability has been found in the SilverStripe framework, where the Quadratic Blowup Attack could potentially be exploited to affect the performance of a site.\n\nSee http://mashable.com/2014/08/06/wordpress-xml-blowup-dos/ for a writeup.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-hq4p-5mpr-jj9m/GHSA-hq4p-5mpr-jj9m.json b/advisories/github-reviewed/2024/05/GHSA-hq4p-5mpr-jj9m/GHSA-hq4p-5mpr-jj9m.json index db5d5d2a2f5..cfa43f71df3 100644 --- a/advisories/github-reviewed/2024/05/GHSA-hq4p-5mpr-jj9m/GHSA-hq4p-5mpr-jj9m.json +++ b/advisories/github-reviewed/2024/05/GHSA-hq4p-5mpr-jj9m/GHSA-hq4p-5mpr-jj9m.json @@ -3,9 +3,7 @@ "id": "GHSA-hq4p-5mpr-jj9m", "modified": "2024-05-23T17:15:09Z", "published": "2024-05-23T17:15:09Z", - "aliases": [ - - ], + "aliases": [], "summary": "Silverstripe XSS in dev/build returnURL Parameter", "details": "A XSS risk exists in the returnURL parameter passed to dev/build. An unvalidated url could cause the user to redirect to an unverified third party url outside of the site.\n\nThis issue is resolved in framework 3.1.14 stable release.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-jqp8-v74p-g8px/GHSA-jqp8-v74p-g8px.json b/advisories/github-reviewed/2024/05/GHSA-jqp8-v74p-g8px/GHSA-jqp8-v74p-g8px.json index 489a8bc7768..3e277dd2a8a 100644 --- a/advisories/github-reviewed/2024/05/GHSA-jqp8-v74p-g8px/GHSA-jqp8-v74p-g8px.json +++ b/advisories/github-reviewed/2024/05/GHSA-jqp8-v74p-g8px/GHSA-jqp8-v74p-g8px.json @@ -3,9 +3,7 @@ "id": "GHSA-jqp8-v74p-g8px", "modified": "2024-05-23T16:48:11Z", "published": "2024-05-23T16:48:11Z", - "aliases": [ - - ], + "aliases": [], "summary": "Silverstripe XSS in Director::force_redirect()", "details": "A low level XSS vulnerability has been found in the Framework affecting http redirection via the Director::force_redirect method.\n\nAttempts to redirect to a url may generate HTML which is not safely escaped, and may pose a risk of XSS in some environments.\n\nThis vulnerability is marked low as it is difficult to exploit, as any injected HTML will only be returned from the server if the Location HTTP header is also sent, meaning that any user browsing the site would not be exposed to the body of the response before their browser redirects them.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-mqf5-275h-gf6r/GHSA-mqf5-275h-gf6r.json b/advisories/github-reviewed/2024/05/GHSA-mqf5-275h-gf6r/GHSA-mqf5-275h-gf6r.json index 7e3e8c370ea..3056926fabf 100644 --- a/advisories/github-reviewed/2024/05/GHSA-mqf5-275h-gf6r/GHSA-mqf5-275h-gf6r.json +++ b/advisories/github-reviewed/2024/05/GHSA-mqf5-275h-gf6r/GHSA-mqf5-275h-gf6r.json @@ -3,9 +3,7 @@ "id": "GHSA-mqf5-275h-gf6r", "modified": "2024-05-23T17:27:20Z", "published": "2024-05-23T17:27:19Z", - "aliases": [ - - ], + "aliases": [], "summary": "Silverstripe framework is vulnerable to XSS in install.php", "details": "During installation, certain parameters (admin_username and admin_password) are not escaped in the setup form.\n\nThis issue is resolved in 3.1.14 stable, although existing users are advised to remove this file prior to deploying to a production server.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-vj2j-6g3w-4662/GHSA-vj2j-6g3w-4662.json b/advisories/github-reviewed/2024/05/GHSA-vj2j-6g3w-4662/GHSA-vj2j-6g3w-4662.json index 33059bf768b..ef85d283819 100644 --- a/advisories/github-reviewed/2024/05/GHSA-vj2j-6g3w-4662/GHSA-vj2j-6g3w-4662.json +++ b/advisories/github-reviewed/2024/05/GHSA-vj2j-6g3w-4662/GHSA-vj2j-6g3w-4662.json @@ -3,9 +3,7 @@ "id": "GHSA-vj2j-6g3w-4662", "modified": "2024-05-23T19:41:41Z", "published": "2024-05-23T19:41:41Z", - "aliases": [ - - ], + "aliases": [], "summary": "Silverstripe Missing CSRF protection in login form", "details": "LoginForm calls disableSecurityToken(), which causes a \"shared host domain\" vulnerability: http://stackoverflow.com/a/15350123.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-vp8p-c6xj-xpj7/GHSA-vp8p-c6xj-xpj7.json b/advisories/github-reviewed/2024/05/GHSA-vp8p-c6xj-xpj7/GHSA-vp8p-c6xj-xpj7.json index 305d0df92fe..21c1eb5afe3 100644 --- a/advisories/github-reviewed/2024/05/GHSA-vp8p-c6xj-xpj7/GHSA-vp8p-c6xj-xpj7.json +++ b/advisories/github-reviewed/2024/05/GHSA-vp8p-c6xj-xpj7/GHSA-vp8p-c6xj-xpj7.json @@ -3,9 +3,7 @@ "id": "GHSA-vp8p-c6xj-xpj7", "modified": "2024-05-23T17:12:13Z", "published": "2024-05-23T17:12:13Z", - "aliases": [ - - ], + "aliases": [], "summary": "Silverstripe External redirection risk in Security?ReturnURL", "details": "A vulnerability has been found in the SilverStripe framework where a login url can be potentially redirected to an external site.\n\nFor example, the url http://www.my-silverstripe-site.com/Security/login?BackURL=/\\attacker-site.com will redirect successful logins to the page http://attacker-site.com. If that website were set up to look identical to the first with \"login failed\" then the user will likely just enter their user/pass again.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-x5w2-wcr8-9q45/GHSA-x5w2-wcr8-9q45.json b/advisories/github-reviewed/2024/05/GHSA-x5w2-wcr8-9q45/GHSA-x5w2-wcr8-9q45.json index e8fd57da066..09eec15f6bf 100644 --- a/advisories/github-reviewed/2024/05/GHSA-x5w2-wcr8-9q45/GHSA-x5w2-wcr8-9q45.json +++ b/advisories/github-reviewed/2024/05/GHSA-x5w2-wcr8-9q45/GHSA-x5w2-wcr8-9q45.json @@ -3,9 +3,7 @@ "id": "GHSA-x5w2-wcr8-9q45", "modified": "2024-05-23T19:17:22Z", "published": "2024-05-23T19:14:12Z", - "aliases": [ - - ], + "aliases": [], "summary": "Silverstripe Missing security check on dev/build/defaults", "details": "The buildDefaults method on DevelopmentAdmin is missing a permission check.\n\nIn live mode, if you access /dev/build, you are requested to login first. However, if you access /dev/build/defaults, then the action is performed without any login check. This should be protected in the same way that /dev/build is.\nThe buildDefaults view is requireDefaultRecords() on each DataObject class, and hence has the potential to modify database state. It also lists all modified tables, allowing attackers more insight into which modules are used, and how the database tables are structured.\n\n", "severity": [ diff --git a/advisories/unreviewed/2021/12/GHSA-3j2m-32hq-9hp8/GHSA-3j2m-32hq-9hp8.json b/advisories/unreviewed/2021/12/GHSA-3j2m-32hq-9hp8/GHSA-3j2m-32hq-9hp8.json index 117876072ea..8928909dc37 100644 --- a/advisories/unreviewed/2021/12/GHSA-3j2m-32hq-9hp8/GHSA-3j2m-32hq-9hp8.json +++ b/advisories/unreviewed/2021/12/GHSA-3j2m-32hq-9hp8/GHSA-3j2m-32hq-9hp8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-67q6-ppfr-h59c/GHSA-67q6-ppfr-h59c.json b/advisories/unreviewed/2021/12/GHSA-67q6-ppfr-h59c/GHSA-67q6-ppfr-h59c.json index db4ea6dad64..9188ee1d957 100644 --- a/advisories/unreviewed/2021/12/GHSA-67q6-ppfr-h59c/GHSA-67q6-ppfr-h59c.json +++ b/advisories/unreviewed/2021/12/GHSA-67q6-ppfr-h59c/GHSA-67q6-ppfr-h59c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-fvx8-gwc7-qjhw/GHSA-fvx8-gwc7-qjhw.json b/advisories/unreviewed/2021/12/GHSA-fvx8-gwc7-qjhw/GHSA-fvx8-gwc7-qjhw.json index 85792f74e01..98be4fabdc8 100644 --- a/advisories/unreviewed/2021/12/GHSA-fvx8-gwc7-qjhw/GHSA-fvx8-gwc7-qjhw.json +++ b/advisories/unreviewed/2021/12/GHSA-fvx8-gwc7-qjhw/GHSA-fvx8-gwc7-qjhw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-m2p2-7mfv-gh5x/GHSA-m2p2-7mfv-gh5x.json b/advisories/unreviewed/2021/12/GHSA-m2p2-7mfv-gh5x/GHSA-m2p2-7mfv-gh5x.json index 42a545ff51e..016ec2bb4d0 100644 --- a/advisories/unreviewed/2021/12/GHSA-m2p2-7mfv-gh5x/GHSA-m2p2-7mfv-gh5x.json +++ b/advisories/unreviewed/2021/12/GHSA-m2p2-7mfv-gh5x/GHSA-m2p2-7mfv-gh5x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-pvf9-7xmx-jpfw/GHSA-pvf9-7xmx-jpfw.json b/advisories/unreviewed/2021/12/GHSA-pvf9-7xmx-jpfw/GHSA-pvf9-7xmx-jpfw.json index 2ca01762490..755736137fc 100644 --- a/advisories/unreviewed/2021/12/GHSA-pvf9-7xmx-jpfw/GHSA-pvf9-7xmx-jpfw.json +++ b/advisories/unreviewed/2021/12/GHSA-pvf9-7xmx-jpfw/GHSA-pvf9-7xmx-jpfw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qx9g-fxwc-9vj6/GHSA-qx9g-fxwc-9vj6.json b/advisories/unreviewed/2021/12/GHSA-qx9g-fxwc-9vj6/GHSA-qx9g-fxwc-9vj6.json index feaf8510e7f..1eb68cd7c08 100644 --- a/advisories/unreviewed/2021/12/GHSA-qx9g-fxwc-9vj6/GHSA-qx9g-fxwc-9vj6.json +++ b/advisories/unreviewed/2021/12/GHSA-qx9g-fxwc-9vj6/GHSA-qx9g-fxwc-9vj6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-44hj-f354-82q3/GHSA-44hj-f354-82q3.json b/advisories/unreviewed/2022/01/GHSA-44hj-f354-82q3/GHSA-44hj-f354-82q3.json index 187309da0ba..739bfb2271c 100644 --- a/advisories/unreviewed/2022/01/GHSA-44hj-f354-82q3/GHSA-44hj-f354-82q3.json +++ b/advisories/unreviewed/2022/01/GHSA-44hj-f354-82q3/GHSA-44hj-f354-82q3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-4vf3-h7wh-ppjc/GHSA-4vf3-h7wh-ppjc.json b/advisories/unreviewed/2022/01/GHSA-4vf3-h7wh-ppjc/GHSA-4vf3-h7wh-ppjc.json index 24d113cff69..951c6ad0ee0 100644 --- a/advisories/unreviewed/2022/01/GHSA-4vf3-h7wh-ppjc/GHSA-4vf3-h7wh-ppjc.json +++ b/advisories/unreviewed/2022/01/GHSA-4vf3-h7wh-ppjc/GHSA-4vf3-h7wh-ppjc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-5444-33r6-wmw7/GHSA-5444-33r6-wmw7.json b/advisories/unreviewed/2022/01/GHSA-5444-33r6-wmw7/GHSA-5444-33r6-wmw7.json index 9b4098944a9..3803e7f5f46 100644 --- a/advisories/unreviewed/2022/01/GHSA-5444-33r6-wmw7/GHSA-5444-33r6-wmw7.json +++ b/advisories/unreviewed/2022/01/GHSA-5444-33r6-wmw7/GHSA-5444-33r6-wmw7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-5xr9-fwxj-j4r9/GHSA-5xr9-fwxj-j4r9.json b/advisories/unreviewed/2022/01/GHSA-5xr9-fwxj-j4r9/GHSA-5xr9-fwxj-j4r9.json index 17a98a19234..6628a07925b 100644 --- a/advisories/unreviewed/2022/01/GHSA-5xr9-fwxj-j4r9/GHSA-5xr9-fwxj-j4r9.json +++ b/advisories/unreviewed/2022/01/GHSA-5xr9-fwxj-j4r9/GHSA-5xr9-fwxj-j4r9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-75gp-4mqx-xmr6/GHSA-75gp-4mqx-xmr6.json b/advisories/unreviewed/2022/01/GHSA-75gp-4mqx-xmr6/GHSA-75gp-4mqx-xmr6.json index 491ef87aac2..72012a042c7 100644 --- a/advisories/unreviewed/2022/01/GHSA-75gp-4mqx-xmr6/GHSA-75gp-4mqx-xmr6.json +++ b/advisories/unreviewed/2022/01/GHSA-75gp-4mqx-xmr6/GHSA-75gp-4mqx-xmr6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-8g95-qfv7-r6w2/GHSA-8g95-qfv7-r6w2.json b/advisories/unreviewed/2022/01/GHSA-8g95-qfv7-r6w2/GHSA-8g95-qfv7-r6w2.json index 4a921e5dfe6..6db5bd03936 100644 --- a/advisories/unreviewed/2022/01/GHSA-8g95-qfv7-r6w2/GHSA-8g95-qfv7-r6w2.json +++ b/advisories/unreviewed/2022/01/GHSA-8g95-qfv7-r6w2/GHSA-8g95-qfv7-r6w2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-c6wp-8jc6-mjm8/GHSA-c6wp-8jc6-mjm8.json b/advisories/unreviewed/2022/01/GHSA-c6wp-8jc6-mjm8/GHSA-c6wp-8jc6-mjm8.json index 0a6d0861440..6505fb00e4f 100644 --- a/advisories/unreviewed/2022/01/GHSA-c6wp-8jc6-mjm8/GHSA-c6wp-8jc6-mjm8.json +++ b/advisories/unreviewed/2022/01/GHSA-c6wp-8jc6-mjm8/GHSA-c6wp-8jc6-mjm8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-grwf-p35f-373j/GHSA-grwf-p35f-373j.json b/advisories/unreviewed/2022/01/GHSA-grwf-p35f-373j/GHSA-grwf-p35f-373j.json index 9640dabe934..7ae991b9144 100644 --- a/advisories/unreviewed/2022/01/GHSA-grwf-p35f-373j/GHSA-grwf-p35f-373j.json +++ b/advisories/unreviewed/2022/01/GHSA-grwf-p35f-373j/GHSA-grwf-p35f-373j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-gvpq-hpvh-3qf9/GHSA-gvpq-hpvh-3qf9.json b/advisories/unreviewed/2022/01/GHSA-gvpq-hpvh-3qf9/GHSA-gvpq-hpvh-3qf9.json index 15dd6c335ef..d2083313f52 100644 --- a/advisories/unreviewed/2022/01/GHSA-gvpq-hpvh-3qf9/GHSA-gvpq-hpvh-3qf9.json +++ b/advisories/unreviewed/2022/01/GHSA-gvpq-hpvh-3qf9/GHSA-gvpq-hpvh-3qf9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-jfqx-ffq5-hw55/GHSA-jfqx-ffq5-hw55.json b/advisories/unreviewed/2022/01/GHSA-jfqx-ffq5-hw55/GHSA-jfqx-ffq5-hw55.json index 9eb6fa6c124..15acef7ac49 100644 --- a/advisories/unreviewed/2022/01/GHSA-jfqx-ffq5-hw55/GHSA-jfqx-ffq5-hw55.json +++ b/advisories/unreviewed/2022/01/GHSA-jfqx-ffq5-hw55/GHSA-jfqx-ffq5-hw55.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-p2pr-pr72-vg5h/GHSA-p2pr-pr72-vg5h.json b/advisories/unreviewed/2022/01/GHSA-p2pr-pr72-vg5h/GHSA-p2pr-pr72-vg5h.json index 6d0eb8741fb..effe22e9fa0 100644 --- a/advisories/unreviewed/2022/01/GHSA-p2pr-pr72-vg5h/GHSA-p2pr-pr72-vg5h.json +++ b/advisories/unreviewed/2022/01/GHSA-p2pr-pr72-vg5h/GHSA-p2pr-pr72-vg5h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-p8v4-4j5f-rg8w/GHSA-p8v4-4j5f-rg8w.json b/advisories/unreviewed/2022/01/GHSA-p8v4-4j5f-rg8w/GHSA-p8v4-4j5f-rg8w.json index a815c138a58..f61fbd29bdb 100644 --- a/advisories/unreviewed/2022/01/GHSA-p8v4-4j5f-rg8w/GHSA-p8v4-4j5f-rg8w.json +++ b/advisories/unreviewed/2022/01/GHSA-p8v4-4j5f-rg8w/GHSA-p8v4-4j5f-rg8w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-q48m-46mp-mhcx/GHSA-q48m-46mp-mhcx.json b/advisories/unreviewed/2022/01/GHSA-q48m-46mp-mhcx/GHSA-q48m-46mp-mhcx.json index f57b356b420..1a27ec251be 100644 --- a/advisories/unreviewed/2022/01/GHSA-q48m-46mp-mhcx/GHSA-q48m-46mp-mhcx.json +++ b/advisories/unreviewed/2022/01/GHSA-q48m-46mp-mhcx/GHSA-q48m-46mp-mhcx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-rqq2-jcpc-x7q4/GHSA-rqq2-jcpc-x7q4.json b/advisories/unreviewed/2022/01/GHSA-rqq2-jcpc-x7q4/GHSA-rqq2-jcpc-x7q4.json index 72031cab478..380df17bee4 100644 --- a/advisories/unreviewed/2022/01/GHSA-rqq2-jcpc-x7q4/GHSA-rqq2-jcpc-x7q4.json +++ b/advisories/unreviewed/2022/01/GHSA-rqq2-jcpc-x7q4/GHSA-rqq2-jcpc-x7q4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-v6vp-5x68-qqfc/GHSA-v6vp-5x68-qqfc.json b/advisories/unreviewed/2022/01/GHSA-v6vp-5x68-qqfc/GHSA-v6vp-5x68-qqfc.json index 894680eba90..bcd39feddf3 100644 --- a/advisories/unreviewed/2022/01/GHSA-v6vp-5x68-qqfc/GHSA-v6vp-5x68-qqfc.json +++ b/advisories/unreviewed/2022/01/GHSA-v6vp-5x68-qqfc/GHSA-v6vp-5x68-qqfc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-w347-hwc8-rvh5/GHSA-w347-hwc8-rvh5.json b/advisories/unreviewed/2022/01/GHSA-w347-hwc8-rvh5/GHSA-w347-hwc8-rvh5.json index 69ed7c4b98a..08200b64e53 100644 --- a/advisories/unreviewed/2022/01/GHSA-w347-hwc8-rvh5/GHSA-w347-hwc8-rvh5.json +++ b/advisories/unreviewed/2022/01/GHSA-w347-hwc8-rvh5/GHSA-w347-hwc8-rvh5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-w8rr-m9g7-26pr/GHSA-w8rr-m9g7-26pr.json b/advisories/unreviewed/2022/01/GHSA-w8rr-m9g7-26pr/GHSA-w8rr-m9g7-26pr.json index 9aa2bd4465c..ec584db28f5 100644 --- a/advisories/unreviewed/2022/01/GHSA-w8rr-m9g7-26pr/GHSA-w8rr-m9g7-26pr.json +++ b/advisories/unreviewed/2022/01/GHSA-w8rr-m9g7-26pr/GHSA-w8rr-m9g7-26pr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-wcrh-6vr6-xf25/GHSA-wcrh-6vr6-xf25.json b/advisories/unreviewed/2022/01/GHSA-wcrh-6vr6-xf25/GHSA-wcrh-6vr6-xf25.json index 9e8baba5e58..113a40e7bce 100644 --- a/advisories/unreviewed/2022/01/GHSA-wcrh-6vr6-xf25/GHSA-wcrh-6vr6-xf25.json +++ b/advisories/unreviewed/2022/01/GHSA-wcrh-6vr6-xf25/GHSA-wcrh-6vr6-xf25.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-wmcc-jccv-479c/GHSA-wmcc-jccv-479c.json b/advisories/unreviewed/2022/01/GHSA-wmcc-jccv-479c/GHSA-wmcc-jccv-479c.json index d0864bbbf16..f104a2913e6 100644 --- a/advisories/unreviewed/2022/01/GHSA-wmcc-jccv-479c/GHSA-wmcc-jccv-479c.json +++ b/advisories/unreviewed/2022/01/GHSA-wmcc-jccv-479c/GHSA-wmcc-jccv-479c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-xpjc-q6jh-h98h/GHSA-xpjc-q6jh-h98h.json b/advisories/unreviewed/2022/01/GHSA-xpjc-q6jh-h98h/GHSA-xpjc-q6jh-h98h.json index 053e8ea64e3..7262ed96ded 100644 --- a/advisories/unreviewed/2022/01/GHSA-xpjc-q6jh-h98h/GHSA-xpjc-q6jh-h98h.json +++ b/advisories/unreviewed/2022/01/GHSA-xpjc-q6jh-h98h/GHSA-xpjc-q6jh-h98h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-xwf7-ghx7-gwwp/GHSA-xwf7-ghx7-gwwp.json b/advisories/unreviewed/2022/01/GHSA-xwf7-ghx7-gwwp/GHSA-xwf7-ghx7-gwwp.json index a11f3b88ef0..49d4e7d8a21 100644 --- a/advisories/unreviewed/2022/01/GHSA-xwf7-ghx7-gwwp/GHSA-xwf7-ghx7-gwwp.json +++ b/advisories/unreviewed/2022/01/GHSA-xwf7-ghx7-gwwp/GHSA-xwf7-ghx7-gwwp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-jm63-cmh5-jrcj/GHSA-jm63-cmh5-jrcj.json b/advisories/unreviewed/2022/02/GHSA-jm63-cmh5-jrcj/GHSA-jm63-cmh5-jrcj.json index 63de5b04397..1e8cdd39552 100644 --- a/advisories/unreviewed/2022/02/GHSA-jm63-cmh5-jrcj/GHSA-jm63-cmh5-jrcj.json +++ b/advisories/unreviewed/2022/02/GHSA-jm63-cmh5-jrcj/GHSA-jm63-cmh5-jrcj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-25m3-g4xm-g7jw/GHSA-25m3-g4xm-g7jw.json b/advisories/unreviewed/2022/04/GHSA-25m3-g4xm-g7jw/GHSA-25m3-g4xm-g7jw.json index dcdde2fd3d4..f03edf7e8f2 100644 --- a/advisories/unreviewed/2022/04/GHSA-25m3-g4xm-g7jw/GHSA-25m3-g4xm-g7jw.json +++ b/advisories/unreviewed/2022/04/GHSA-25m3-g4xm-g7jw/GHSA-25m3-g4xm-g7jw.json @@ -7,12 +7,8 @@ "CVE-2003-0079" ], "details": "The DEC UDK processing feature in the hanterm (hanterm-xf) terminal emulator before 2.0.5 allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-26fp-mrfm-xgp8/GHSA-26fp-mrfm-xgp8.json b/advisories/unreviewed/2022/04/GHSA-26fp-mrfm-xgp8/GHSA-26fp-mrfm-xgp8.json index 19764a9c6cd..6ab1ab61eb2 100644 --- a/advisories/unreviewed/2022/04/GHSA-26fp-mrfm-xgp8/GHSA-26fp-mrfm-xgp8.json +++ b/advisories/unreviewed/2022/04/GHSA-26fp-mrfm-xgp8/GHSA-26fp-mrfm-xgp8.json @@ -7,12 +7,8 @@ "CVE-2003-0047" ], "details": "SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2cwg-9592-xc58/GHSA-2cwg-9592-xc58.json b/advisories/unreviewed/2022/04/GHSA-2cwg-9592-xc58/GHSA-2cwg-9592-xc58.json index aa2bf5941ac..335ca877f6d 100644 --- a/advisories/unreviewed/2022/04/GHSA-2cwg-9592-xc58/GHSA-2cwg-9592-xc58.json +++ b/advisories/unreviewed/2022/04/GHSA-2cwg-9592-xc58/GHSA-2cwg-9592-xc58.json @@ -7,12 +7,8 @@ "CVE-2003-0159" ], "details": "Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2frv-wg69-9638/GHSA-2frv-wg69-9638.json b/advisories/unreviewed/2022/04/GHSA-2frv-wg69-9638/GHSA-2frv-wg69-9638.json index f90d6f1dcb9..eadd3de3024 100644 --- a/advisories/unreviewed/2022/04/GHSA-2frv-wg69-9638/GHSA-2frv-wg69-9638.json +++ b/advisories/unreviewed/2022/04/GHSA-2frv-wg69-9638/GHSA-2frv-wg69-9638.json @@ -7,12 +7,8 @@ "CVE-2003-0080" ], "details": "The iptables ruleset in Gnome-lokkit in Red Hat Linux 8.0 does not include any rules in the FORWARD chain, which could allow attackers to bypass intended access restrictions if packet forwarding is enabled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2p86-fwpp-78jw/GHSA-2p86-fwpp-78jw.json b/advisories/unreviewed/2022/04/GHSA-2p86-fwpp-78jw/GHSA-2p86-fwpp-78jw.json index b953559acb6..ccf474dd8e8 100644 --- a/advisories/unreviewed/2022/04/GHSA-2p86-fwpp-78jw/GHSA-2p86-fwpp-78jw.json +++ b/advisories/unreviewed/2022/04/GHSA-2p86-fwpp-78jw/GHSA-2p86-fwpp-78jw.json @@ -7,12 +7,8 @@ "CVE-2003-0137" ], "details": "SNMP daemon in the DX200 based network element for Nokia Serving GPRS support node (SGSN) allows remote attackers to read SNMP options via arbitrary community strings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3hf6-9xf2-jh59/GHSA-3hf6-9xf2-jh59.json b/advisories/unreviewed/2022/04/GHSA-3hf6-9xf2-jh59/GHSA-3hf6-9xf2-jh59.json index 97cbfe5bf64..65eca435d00 100644 --- a/advisories/unreviewed/2022/04/GHSA-3hf6-9xf2-jh59/GHSA-3hf6-9xf2-jh59.json +++ b/advisories/unreviewed/2022/04/GHSA-3hf6-9xf2-jh59/GHSA-3hf6-9xf2-jh59.json @@ -7,12 +7,8 @@ "CVE-2003-0091" ], "details": "Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3vmv-j634-9wxq/GHSA-3vmv-j634-9wxq.json b/advisories/unreviewed/2022/04/GHSA-3vmv-j634-9wxq/GHSA-3vmv-j634-9wxq.json index df1d445f9d1..abe6ecfc31e 100644 --- a/advisories/unreviewed/2022/04/GHSA-3vmv-j634-9wxq/GHSA-3vmv-j634-9wxq.json +++ b/advisories/unreviewed/2022/04/GHSA-3vmv-j634-9wxq/GHSA-3vmv-j634-9wxq.json @@ -7,12 +7,8 @@ "CVE-2003-0106" ], "details": "The HTTP proxy for Symantec Enterprise Firewall (SEF) 7.0 allows proxy users to bypass pattern matching for blocked URLs via requests that are URL-encoded with escapes, Unicode, or UTF-8.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4336-c7qc-5ccc/GHSA-4336-c7qc-5ccc.json b/advisories/unreviewed/2022/04/GHSA-4336-c7qc-5ccc/GHSA-4336-c7qc-5ccc.json index c364eb6a06d..8433a8a403d 100644 --- a/advisories/unreviewed/2022/04/GHSA-4336-c7qc-5ccc/GHSA-4336-c7qc-5ccc.json +++ b/advisories/unreviewed/2022/04/GHSA-4336-c7qc-5ccc/GHSA-4336-c7qc-5ccc.json @@ -7,12 +7,8 @@ "CVE-2003-0087" ], "details": "Buffer overflow in libIM library (libIM.a) for National Language Support (NLS) on AIX 4.3 through 5.2 allows local users to gain privileges via several possible attack vectors, including a long -im argument to aixterm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-49gw-mv8v-c8mp/GHSA-49gw-mv8v-c8mp.json b/advisories/unreviewed/2022/04/GHSA-49gw-mv8v-c8mp/GHSA-49gw-mv8v-c8mp.json index 8a5d62757cd..03e153511f0 100644 --- a/advisories/unreviewed/2022/04/GHSA-49gw-mv8v-c8mp/GHSA-49gw-mv8v-c8mp.json +++ b/advisories/unreviewed/2022/04/GHSA-49gw-mv8v-c8mp/GHSA-49gw-mv8v-c8mp.json @@ -7,12 +7,8 @@ "CVE-2003-0072" ], "details": "The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an array (aka \"array overrun\").", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4c35-hp54-r4m7/GHSA-4c35-hp54-r4m7.json b/advisories/unreviewed/2022/04/GHSA-4c35-hp54-r4m7/GHSA-4c35-hp54-r4m7.json index 4848327b22f..a832b7626fc 100644 --- a/advisories/unreviewed/2022/04/GHSA-4c35-hp54-r4m7/GHSA-4c35-hp54-r4m7.json +++ b/advisories/unreviewed/2022/04/GHSA-4c35-hp54-r4m7/GHSA-4c35-hp54-r4m7.json @@ -7,12 +7,8 @@ "CVE-2003-0133" ], "details": "GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4fpc-mhq6-w7p7/GHSA-4fpc-mhq6-w7p7.json b/advisories/unreviewed/2022/04/GHSA-4fpc-mhq6-w7p7/GHSA-4fpc-mhq6-w7p7.json index 7613ccfd9ab..1041a44b77b 100644 --- a/advisories/unreviewed/2022/04/GHSA-4fpc-mhq6-w7p7/GHSA-4fpc-mhq6-w7p7.json +++ b/advisories/unreviewed/2022/04/GHSA-4fpc-mhq6-w7p7/GHSA-4fpc-mhq6-w7p7.json @@ -7,12 +7,8 @@ "CVE-2003-0067" ], "details": "The aterm terminal emulator 0.42 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4vwm-wf8m-g2v8/GHSA-4vwm-wf8m-g2v8.json b/advisories/unreviewed/2022/04/GHSA-4vwm-wf8m-g2v8/GHSA-4vwm-wf8m-g2v8.json index c9837401809..c331cc19d72 100644 --- a/advisories/unreviewed/2022/04/GHSA-4vwm-wf8m-g2v8/GHSA-4vwm-wf8m-g2v8.json +++ b/advisories/unreviewed/2022/04/GHSA-4vwm-wf8m-g2v8/GHSA-4vwm-wf8m-g2v8.json @@ -7,12 +7,8 @@ "CVE-2003-0128" ], "details": "The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4x7x-3r29-5pc7/GHSA-4x7x-3r29-5pc7.json b/advisories/unreviewed/2022/04/GHSA-4x7x-3r29-5pc7/GHSA-4x7x-3r29-5pc7.json index 5e176916a51..026a45a033b 100644 --- a/advisories/unreviewed/2022/04/GHSA-4x7x-3r29-5pc7/GHSA-4x7x-3r29-5pc7.json +++ b/advisories/unreviewed/2022/04/GHSA-4x7x-3r29-5pc7/GHSA-4x7x-3r29-5pc7.json @@ -7,12 +7,8 @@ "CVE-2003-0113" ], "details": "Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4xfp-7xc2-6c73/GHSA-4xfp-7xc2-6c73.json b/advisories/unreviewed/2022/04/GHSA-4xfp-7xc2-6c73/GHSA-4xfp-7xc2-6c73.json index 62f7af5daa8..d5556fe7c81 100644 --- a/advisories/unreviewed/2022/04/GHSA-4xfp-7xc2-6c73/GHSA-4xfp-7xc2-6c73.json +++ b/advisories/unreviewed/2022/04/GHSA-4xfp-7xc2-6c73/GHSA-4xfp-7xc2-6c73.json @@ -7,12 +7,8 @@ "CVE-2003-0166" ], "details": "Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4xh6-vg29-gg96/GHSA-4xh6-vg29-gg96.json b/advisories/unreviewed/2022/04/GHSA-4xh6-vg29-gg96/GHSA-4xh6-vg29-gg96.json index 121cf4cdabe..6e5780e69fb 100644 --- a/advisories/unreviewed/2022/04/GHSA-4xh6-vg29-gg96/GHSA-4xh6-vg29-gg96.json +++ b/advisories/unreviewed/2022/04/GHSA-4xh6-vg29-gg96/GHSA-4xh6-vg29-gg96.json @@ -7,12 +7,8 @@ "CVE-2003-0122" ], "details": "Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-55w6-2jgr-62jf/GHSA-55w6-2jgr-62jf.json b/advisories/unreviewed/2022/04/GHSA-55w6-2jgr-62jf/GHSA-55w6-2jgr-62jf.json index d8a6828deca..76cb6c76b16 100644 --- a/advisories/unreviewed/2022/04/GHSA-55w6-2jgr-62jf/GHSA-55w6-2jgr-62jf.json +++ b/advisories/unreviewed/2022/04/GHSA-55w6-2jgr-62jf/GHSA-55w6-2jgr-62jf.json @@ -7,12 +7,8 @@ "CVE-2003-0148" ], "details": "The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username and encrypted password in a configuration file from the ePO server using a certain request, (2) crack the password due to weak cryptography, and (3) use the password to pass commands through xp_cmdshell.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-57ch-4f4p-v65v/GHSA-57ch-4f4p-v65v.json b/advisories/unreviewed/2022/04/GHSA-57ch-4f4p-v65v/GHSA-57ch-4f4p-v65v.json index d22e36733b9..64ca252b7c5 100644 --- a/advisories/unreviewed/2022/04/GHSA-57ch-4f4p-v65v/GHSA-57ch-4f4p-v65v.json +++ b/advisories/unreviewed/2022/04/GHSA-57ch-4f4p-v65v/GHSA-57ch-4f4p-v65v.json @@ -7,12 +7,8 @@ "CVE-2003-0145" ], "details": "Unknown vulnerability in tcpdump before 3.7.2 related to an inability to \"Handle unknown RADIUS attributes properly,\" allows remote attackers to cause a denial of service (infinite loop), a different vulnerability than CAN-2003-0093.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5ggv-9h6j-2x36/GHSA-5ggv-9h6j-2x36.json b/advisories/unreviewed/2022/04/GHSA-5ggv-9h6j-2x36/GHSA-5ggv-9h6j-2x36.json index f7c2d76b324..7b06fc63798 100644 --- a/advisories/unreviewed/2022/04/GHSA-5ggv-9h6j-2x36/GHSA-5ggv-9h6j-2x36.json +++ b/advisories/unreviewed/2022/04/GHSA-5ggv-9h6j-2x36/GHSA-5ggv-9h6j-2x36.json @@ -7,12 +7,8 @@ "CVE-2003-0104" ], "details": "Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5h59-28rg-v4hv/GHSA-5h59-28rg-v4hv.json b/advisories/unreviewed/2022/04/GHSA-5h59-28rg-v4hv/GHSA-5h59-28rg-v4hv.json index 4be79f519ac..96e7f7919bf 100644 --- a/advisories/unreviewed/2022/04/GHSA-5h59-28rg-v4hv/GHSA-5h59-28rg-v4hv.json +++ b/advisories/unreviewed/2022/04/GHSA-5h59-28rg-v4hv/GHSA-5h59-28rg-v4hv.json @@ -7,12 +7,8 @@ "CVE-2003-0151" ], "details": "BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5p29-q2xp-v386/GHSA-5p29-q2xp-v386.json b/advisories/unreviewed/2022/04/GHSA-5p29-q2xp-v386/GHSA-5p29-q2xp-v386.json index 6584431e00b..23e04555c00 100644 --- a/advisories/unreviewed/2022/04/GHSA-5p29-q2xp-v386/GHSA-5p29-q2xp-v386.json +++ b/advisories/unreviewed/2022/04/GHSA-5p29-q2xp-v386/GHSA-5p29-q2xp-v386.json @@ -7,12 +7,8 @@ "CVE-2003-0088" ], "details": "TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that is used to write debugging information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5r59-c396-qwfm/GHSA-5r59-c396-qwfm.json b/advisories/unreviewed/2022/04/GHSA-5r59-c396-qwfm/GHSA-5r59-c396-qwfm.json index ecb8017dc81..4bb1078da73 100644 --- a/advisories/unreviewed/2022/04/GHSA-5r59-c396-qwfm/GHSA-5r59-c396-qwfm.json +++ b/advisories/unreviewed/2022/04/GHSA-5r59-c396-qwfm/GHSA-5r59-c396-qwfm.json @@ -7,12 +7,8 @@ "CVE-2003-0073" ], "details": "Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5wqg-rq3v-7fw3/GHSA-5wqg-rq3v-7fw3.json b/advisories/unreviewed/2022/04/GHSA-5wqg-rq3v-7fw3/GHSA-5wqg-rq3v-7fw3.json index 494ff570fd0..d94cc895f82 100644 --- a/advisories/unreviewed/2022/04/GHSA-5wqg-rq3v-7fw3/GHSA-5wqg-rq3v-7fw3.json +++ b/advisories/unreviewed/2022/04/GHSA-5wqg-rq3v-7fw3/GHSA-5wqg-rq3v-7fw3.json @@ -7,12 +7,8 @@ "CVE-2003-0082" ], "details": "The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka \"buffer underrun\").", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5xwf-7w8g-23wm/GHSA-5xwf-7w8g-23wm.json b/advisories/unreviewed/2022/04/GHSA-5xwf-7w8g-23wm/GHSA-5xwf-7w8g-23wm.json index ff5b2fa0779..4d1c725669a 100644 --- a/advisories/unreviewed/2022/04/GHSA-5xwf-7w8g-23wm/GHSA-5xwf-7w8g-23wm.json +++ b/advisories/unreviewed/2022/04/GHSA-5xwf-7w8g-23wm/GHSA-5xwf-7w8g-23wm.json @@ -7,12 +7,8 @@ "CVE-2003-0171" ], "details": "DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-63v6-h3h2-rxp5/GHSA-63v6-h3h2-rxp5.json b/advisories/unreviewed/2022/04/GHSA-63v6-h3h2-rxp5/GHSA-63v6-h3h2-rxp5.json index 938a758799a..9d19d0e2069 100644 --- a/advisories/unreviewed/2022/04/GHSA-63v6-h3h2-rxp5/GHSA-63v6-h3h2-rxp5.json +++ b/advisories/unreviewed/2022/04/GHSA-63v6-h3h2-rxp5/GHSA-63v6-h3h2-rxp5.json @@ -7,12 +7,8 @@ "CVE-2003-0060" ], "details": "Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-73v6-qr33-qrch/GHSA-73v6-qr33-qrch.json b/advisories/unreviewed/2022/04/GHSA-73v6-qr33-qrch/GHSA-73v6-qr33-qrch.json index d4f2d343213..4a790d7ac9f 100644 --- a/advisories/unreviewed/2022/04/GHSA-73v6-qr33-qrch/GHSA-73v6-qr33-qrch.json +++ b/advisories/unreviewed/2022/04/GHSA-73v6-qr33-qrch/GHSA-73v6-qr33-qrch.json @@ -7,12 +7,8 @@ "CVE-2003-0065" ], "details": "The uxterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-77cf-x762-rf78/GHSA-77cf-x762-rf78.json b/advisories/unreviewed/2022/04/GHSA-77cf-x762-rf78/GHSA-77cf-x762-rf78.json index 534e806818b..26443afb460 100644 --- a/advisories/unreviewed/2022/04/GHSA-77cf-x762-rf78/GHSA-77cf-x762-rf78.json +++ b/advisories/unreviewed/2022/04/GHSA-77cf-x762-rf78/GHSA-77cf-x762-rf78.json @@ -7,12 +7,8 @@ "CVE-2003-0134" ], "details": "Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-77fj-rrcm-ff2h/GHSA-77fj-rrcm-ff2h.json b/advisories/unreviewed/2022/04/GHSA-77fj-rrcm-ff2h/GHSA-77fj-rrcm-ff2h.json index eaa26a15082..46a7de5955f 100644 --- a/advisories/unreviewed/2022/04/GHSA-77fj-rrcm-ff2h/GHSA-77fj-rrcm-ff2h.json +++ b/advisories/unreviewed/2022/04/GHSA-77fj-rrcm-ff2h/GHSA-77fj-rrcm-ff2h.json @@ -7,12 +7,8 @@ "CVE-2003-0156" ], "details": "Directory traversal vulnerability in Cross-Referencing Linux (LXR) allows remote attackers to read arbitrary files via .. (dot dot) sequences in the v parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7c7p-xc22-ggr9/GHSA-7c7p-xc22-ggr9.json b/advisories/unreviewed/2022/04/GHSA-7c7p-xc22-ggr9/GHSA-7c7p-xc22-ggr9.json index 8f6fe3e8593..85faa2c8810 100644 --- a/advisories/unreviewed/2022/04/GHSA-7c7p-xc22-ggr9/GHSA-7c7p-xc22-ggr9.json +++ b/advisories/unreviewed/2022/04/GHSA-7c7p-xc22-ggr9/GHSA-7c7p-xc22-ggr9.json @@ -7,12 +7,8 @@ "CVE-2003-0062" ], "details": "Buffer overflow in Eset Software NOD32 for UNIX before 1.013 allows local users to execute arbitrary code via a long path name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7mvh-9mp8-7293/GHSA-7mvh-9mp8-7293.json b/advisories/unreviewed/2022/04/GHSA-7mvh-9mp8-7293/GHSA-7mvh-9mp8-7293.json index 3575563c98d..d139a61db05 100644 --- a/advisories/unreviewed/2022/04/GHSA-7mvh-9mp8-7293/GHSA-7mvh-9mp8-7293.json +++ b/advisories/unreviewed/2022/04/GHSA-7mvh-9mp8-7293/GHSA-7mvh-9mp8-7293.json @@ -7,12 +7,8 @@ "CVE-2003-0051" ], "details": "parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7q6h-c5j5-5wfm/GHSA-7q6h-c5j5-5wfm.json b/advisories/unreviewed/2022/04/GHSA-7q6h-c5j5-5wfm/GHSA-7q6h-c5j5-5wfm.json index 321b6726141..1fa4e630de6 100644 --- a/advisories/unreviewed/2022/04/GHSA-7q6h-c5j5-5wfm/GHSA-7q6h-c5j5-5wfm.json +++ b/advisories/unreviewed/2022/04/GHSA-7q6h-c5j5-5wfm/GHSA-7q6h-c5j5-5wfm.json @@ -7,12 +7,8 @@ "CVE-2003-0095" ], "details": "Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own authentication, as demonstrated using LOADPSP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-83gw-hr2p-gg57/GHSA-83gw-hr2p-gg57.json b/advisories/unreviewed/2022/04/GHSA-83gw-hr2p-gg57/GHSA-83gw-hr2p-gg57.json index 6fbb4639d1d..82c48cb6e49 100644 --- a/advisories/unreviewed/2022/04/GHSA-83gw-hr2p-gg57/GHSA-83gw-hr2p-gg57.json +++ b/advisories/unreviewed/2022/04/GHSA-83gw-hr2p-gg57/GHSA-83gw-hr2p-gg57.json @@ -7,12 +7,8 @@ "CVE-2003-0111" ], "details": "The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka \"Flaw in Microsoft VM Could Enable System Compromise.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-83mv-r2r9-9gx9/GHSA-83mv-r2r9-9gx9.json b/advisories/unreviewed/2022/04/GHSA-83mv-r2r9-9gx9/GHSA-83mv-r2r9-9gx9.json index 45ff5e3eb13..6342a8c7312 100644 --- a/advisories/unreviewed/2022/04/GHSA-83mv-r2r9-9gx9/GHSA-83mv-r2r9-9gx9.json +++ b/advisories/unreviewed/2022/04/GHSA-83mv-r2r9-9gx9/GHSA-83mv-r2r9-9gx9.json @@ -7,12 +7,8 @@ "CVE-2003-0118" ], "details": "SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-86m6-4fpw-74g7/GHSA-86m6-4fpw-74g7.json b/advisories/unreviewed/2022/04/GHSA-86m6-4fpw-74g7/GHSA-86m6-4fpw-74g7.json index 72b0c76f63f..97adc6f3115 100644 --- a/advisories/unreviewed/2022/04/GHSA-86m6-4fpw-74g7/GHSA-86m6-4fpw-74g7.json +++ b/advisories/unreviewed/2022/04/GHSA-86m6-4fpw-74g7/GHSA-86m6-4fpw-74g7.json @@ -7,12 +7,8 @@ "CVE-2003-0162" ], "details": "Ecartis 1.0.0 (formerly listar) before snapshot 20030227 allows remote attackers to reset passwords of other users and gain privileges by modifying hidden form fields in the HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8778-4253-2475/GHSA-8778-4253-2475.json b/advisories/unreviewed/2022/04/GHSA-8778-4253-2475/GHSA-8778-4253-2475.json index e021f28d36f..fc487cdb2a1 100644 --- a/advisories/unreviewed/2022/04/GHSA-8778-4253-2475/GHSA-8778-4253-2475.json +++ b/advisories/unreviewed/2022/04/GHSA-8778-4253-2475/GHSA-8778-4253-2475.json @@ -7,12 +7,8 @@ "CVE-2003-0076" ], "details": "Unknown vulnerability in the directory parser for Direct Connect 4 Linux (dcgui) before 0.2.2 allows remote attackers to read files outside the sharelist.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8jw5-95qp-5jf8/GHSA-8jw5-95qp-5jf8.json b/advisories/unreviewed/2022/04/GHSA-8jw5-95qp-5jf8/GHSA-8jw5-95qp-5jf8.json index f7150d19410..d76ef9b6118 100644 --- a/advisories/unreviewed/2022/04/GHSA-8jw5-95qp-5jf8/GHSA-8jw5-95qp-5jf8.json +++ b/advisories/unreviewed/2022/04/GHSA-8jw5-95qp-5jf8/GHSA-8jw5-95qp-5jf8.json @@ -7,12 +7,8 @@ "CVE-2003-0103" ], "details": "Format string vulnerability in Nokia 6210 handset allows remote attackers to cause a denial of service (crash, lockup, or restart) via a Multi-Part vCard with fields containing a large number of format string specifiers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8rrq-x6h3-fm8w/GHSA-8rrq-x6h3-fm8w.json b/advisories/unreviewed/2022/04/GHSA-8rrq-x6h3-fm8w/GHSA-8rrq-x6h3-fm8w.json index d93cfe18f23..4e8cd4de46a 100644 --- a/advisories/unreviewed/2022/04/GHSA-8rrq-x6h3-fm8w/GHSA-8rrq-x6h3-fm8w.json +++ b/advisories/unreviewed/2022/04/GHSA-8rrq-x6h3-fm8w/GHSA-8rrq-x6h3-fm8w.json @@ -7,12 +7,8 @@ "CVE-2003-0130" ], "details": "The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers to inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-93p7-mwq5-3h6c/GHSA-93p7-mwq5-3h6c.json b/advisories/unreviewed/2022/04/GHSA-93p7-mwq5-3h6c/GHSA-93p7-mwq5-3h6c.json index 1bc1b86c16d..e68e128ee25 100644 --- a/advisories/unreviewed/2022/04/GHSA-93p7-mwq5-3h6c/GHSA-93p7-mwq5-3h6c.json +++ b/advisories/unreviewed/2022/04/GHSA-93p7-mwq5-3h6c/GHSA-93p7-mwq5-3h6c.json @@ -7,12 +7,8 @@ "CVE-2003-0053" ], "details": "Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-949q-m2rc-xq42/GHSA-949q-m2rc-xq42.json b/advisories/unreviewed/2022/04/GHSA-949q-m2rc-xq42/GHSA-949q-m2rc-xq42.json index 641fe55df8d..f0503de3de7 100644 --- a/advisories/unreviewed/2022/04/GHSA-949q-m2rc-xq42/GHSA-949q-m2rc-xq42.json +++ b/advisories/unreviewed/2022/04/GHSA-949q-m2rc-xq42/GHSA-949q-m2rc-xq42.json @@ -7,12 +7,8 @@ "CVE-2003-0109" ], "details": "Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-96rc-4r3g-2j5f/GHSA-96rc-4r3g-2j5f.json b/advisories/unreviewed/2022/04/GHSA-96rc-4r3g-2j5f/GHSA-96rc-4r3g-2j5f.json index 61b2dfe6fd8..2fafde7de55 100644 --- a/advisories/unreviewed/2022/04/GHSA-96rc-4r3g-2j5f/GHSA-96rc-4r3g-2j5f.json +++ b/advisories/unreviewed/2022/04/GHSA-96rc-4r3g-2j5f/GHSA-96rc-4r3g-2j5f.json @@ -7,12 +7,8 @@ "CVE-2003-0187" ], "details": "The connection tracking core of Netfilter for Linux 2.4.20, with CONFIG_IP_NF_CONNTRACK enabled or the ip_conntrack module loaded, allows remote attackers to cause a denial of service (resource consumption) due to an inconsistency with Linux 2.4.20's support of linked lists, which causes Netfilter to fail to identify connections with an UNCONFIRMED status and use large timeouts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9fg3-x29w-7qw6/GHSA-9fg3-x29w-7qw6.json b/advisories/unreviewed/2022/04/GHSA-9fg3-x29w-7qw6/GHSA-9fg3-x29w-7qw6.json index 81eac41370d..5cae4a8cc4d 100644 --- a/advisories/unreviewed/2022/04/GHSA-9fg3-x29w-7qw6/GHSA-9fg3-x29w-7qw6.json +++ b/advisories/unreviewed/2022/04/GHSA-9fg3-x29w-7qw6/GHSA-9fg3-x29w-7qw6.json @@ -7,12 +7,8 @@ "CVE-2003-0117" ], "details": "Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9j44-fmv7-wm6r/GHSA-9j44-fmv7-wm6r.json b/advisories/unreviewed/2022/04/GHSA-9j44-fmv7-wm6r/GHSA-9j44-fmv7-wm6r.json index a9df78564e5..b4c7212b35a 100644 --- a/advisories/unreviewed/2022/04/GHSA-9j44-fmv7-wm6r/GHSA-9j44-fmv7-wm6r.json +++ b/advisories/unreviewed/2022/04/GHSA-9j44-fmv7-wm6r/GHSA-9j44-fmv7-wm6r.json @@ -7,12 +7,8 @@ "CVE-2003-0049" ], "details": "Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9pq5-6mmc-rqh3/GHSA-9pq5-6mmc-rqh3.json b/advisories/unreviewed/2022/04/GHSA-9pq5-6mmc-rqh3/GHSA-9pq5-6mmc-rqh3.json index 6ba5a27c12c..e3b58de86e6 100644 --- a/advisories/unreviewed/2022/04/GHSA-9pq5-6mmc-rqh3/GHSA-9pq5-6mmc-rqh3.json +++ b/advisories/unreviewed/2022/04/GHSA-9pq5-6mmc-rqh3/GHSA-9pq5-6mmc-rqh3.json @@ -7,12 +7,8 @@ "CVE-2003-0141" ], "details": "The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed data using fixed trees that contain the length values 286-287, which are treated as a very large length.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9vr2-m5jc-c7mv/GHSA-9vr2-m5jc-c7mv.json b/advisories/unreviewed/2022/04/GHSA-9vr2-m5jc-c7mv/GHSA-9vr2-m5jc-c7mv.json index 45d54ca9103..93b23faac83 100644 --- a/advisories/unreviewed/2022/04/GHSA-9vr2-m5jc-c7mv/GHSA-9vr2-m5jc-c7mv.json +++ b/advisories/unreviewed/2022/04/GHSA-9vr2-m5jc-c7mv/GHSA-9vr2-m5jc-c7mv.json @@ -7,12 +7,8 @@ "CVE-2003-0055" ], "details": "Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9x9m-c8vw-3q9c/GHSA-9x9m-c8vw-3q9c.json b/advisories/unreviewed/2022/04/GHSA-9x9m-c8vw-3q9c/GHSA-9x9m-c8vw-3q9c.json index e1d3b27f21c..976e435bb5d 100644 --- a/advisories/unreviewed/2022/04/GHSA-9x9m-c8vw-3q9c/GHSA-9x9m-c8vw-3q9c.json +++ b/advisories/unreviewed/2022/04/GHSA-9x9m-c8vw-3q9c/GHSA-9x9m-c8vw-3q9c.json @@ -7,12 +7,8 @@ "CVE-2003-0061" ], "details": "Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c53j-6qpq-4xm2/GHSA-c53j-6qpq-4xm2.json b/advisories/unreviewed/2022/04/GHSA-c53j-6qpq-4xm2/GHSA-c53j-6qpq-4xm2.json index 5610343b484..9e13992bf0c 100644 --- a/advisories/unreviewed/2022/04/GHSA-c53j-6qpq-4xm2/GHSA-c53j-6qpq-4xm2.json +++ b/advisories/unreviewed/2022/04/GHSA-c53j-6qpq-4xm2/GHSA-c53j-6qpq-4xm2.json @@ -7,12 +7,8 @@ "CVE-2003-0089" ], "details": "Buffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitrary code via a long LANG environment variable to setuid programs such as (1) swinstall and (2) swmodify.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c58p-f5rx-553c/GHSA-c58p-f5rx-553c.json b/advisories/unreviewed/2022/04/GHSA-c58p-f5rx-553c/GHSA-c58p-f5rx-553c.json index bad385851f4..16061810675 100644 --- a/advisories/unreviewed/2022/04/GHSA-c58p-f5rx-553c/GHSA-c58p-f5rx-553c.json +++ b/advisories/unreviewed/2022/04/GHSA-c58p-f5rx-553c/GHSA-c58p-f5rx-553c.json @@ -7,12 +7,8 @@ "CVE-2003-0123" ], "details": "Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cgv2-9m38-4jwr/GHSA-cgv2-9m38-4jwr.json b/advisories/unreviewed/2022/04/GHSA-cgv2-9m38-4jwr/GHSA-cgv2-9m38-4jwr.json index 877c6fe707f..ddbeed93515 100644 --- a/advisories/unreviewed/2022/04/GHSA-cgv2-9m38-4jwr/GHSA-cgv2-9m38-4jwr.json +++ b/advisories/unreviewed/2022/04/GHSA-cgv2-9m38-4jwr/GHSA-cgv2-9m38-4jwr.json @@ -7,12 +7,8 @@ "CVE-2003-0136" ], "details": "psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cqhr-cfp6-qx66/GHSA-cqhr-cfp6-qx66.json b/advisories/unreviewed/2022/04/GHSA-cqhr-cfp6-qx66/GHSA-cqhr-cfp6-qx66.json index 3f7e69389a2..fa38f51ecbd 100644 --- a/advisories/unreviewed/2022/04/GHSA-cqhr-cfp6-qx66/GHSA-cqhr-cfp6-qx66.json +++ b/advisories/unreviewed/2022/04/GHSA-cqhr-cfp6-qx66/GHSA-cqhr-cfp6-qx66.json @@ -7,12 +7,8 @@ "CVE-2003-0069" ], "details": "The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cvpf-93m7-95jr/GHSA-cvpf-93m7-95jr.json b/advisories/unreviewed/2022/04/GHSA-cvpf-93m7-95jr/GHSA-cvpf-93m7-95jr.json index ed1e8d178cf..1f2780230d0 100644 --- a/advisories/unreviewed/2022/04/GHSA-cvpf-93m7-95jr/GHSA-cvpf-93m7-95jr.json +++ b/advisories/unreviewed/2022/04/GHSA-cvpf-93m7-95jr/GHSA-cvpf-93m7-95jr.json @@ -7,12 +7,8 @@ "CVE-2003-0083" ], "details": "Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -108,9 +104,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cvx5-7vc7-rg77/GHSA-cvx5-7vc7-rg77.json b/advisories/unreviewed/2022/04/GHSA-cvx5-7vc7-rg77/GHSA-cvx5-7vc7-rg77.json index 99057b259b1..40f664c6803 100644 --- a/advisories/unreviewed/2022/04/GHSA-cvx5-7vc7-rg77/GHSA-cvx5-7vc7-rg77.json +++ b/advisories/unreviewed/2022/04/GHSA-cvx5-7vc7-rg77/GHSA-cvx5-7vc7-rg77.json @@ -7,12 +7,8 @@ "CVE-2003-0043" ], "details": "Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cxmw-24hm-2x99/GHSA-cxmw-24hm-2x99.json b/advisories/unreviewed/2022/04/GHSA-cxmw-24hm-2x99/GHSA-cxmw-24hm-2x99.json index 4c00a8e9e30..a6d69ac56b5 100644 --- a/advisories/unreviewed/2022/04/GHSA-cxmw-24hm-2x99/GHSA-cxmw-24hm-2x99.json +++ b/advisories/unreviewed/2022/04/GHSA-cxmw-24hm-2x99/GHSA-cxmw-24hm-2x99.json @@ -7,12 +7,8 @@ "CVE-2003-0152" ], "details": "Unknown vulnerability in bonsai Mozilla CVS query tool allows remote attackers to execute arbitrary commands as the www-data user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fhxw-vrjc-w6rv/GHSA-fhxw-vrjc-w6rv.json b/advisories/unreviewed/2022/04/GHSA-fhxw-vrjc-w6rv/GHSA-fhxw-vrjc-w6rv.json index ac0e041013e..90f3b875acf 100644 --- a/advisories/unreviewed/2022/04/GHSA-fhxw-vrjc-w6rv/GHSA-fhxw-vrjc-w6rv.json +++ b/advisories/unreviewed/2022/04/GHSA-fhxw-vrjc-w6rv/GHSA-fhxw-vrjc-w6rv.json @@ -7,12 +7,8 @@ "CVE-2003-0160" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client's web browser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-frx8-9fr9-73ww/GHSA-frx8-9fr9-73ww.json b/advisories/unreviewed/2022/04/GHSA-frx8-9fr9-73ww/GHSA-frx8-9fr9-73ww.json index 9365cc1d155..3227c758c74 100644 --- a/advisories/unreviewed/2022/04/GHSA-frx8-9fr9-73ww/GHSA-frx8-9fr9-73ww.json +++ b/advisories/unreviewed/2022/04/GHSA-frx8-9fr9-73ww/GHSA-frx8-9fr9-73ww.json @@ -7,12 +7,8 @@ "CVE-2003-0143" ], "details": "The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g3vc-c43j-gjjv/GHSA-g3vc-c43j-gjjv.json b/advisories/unreviewed/2022/04/GHSA-g3vc-c43j-gjjv/GHSA-g3vc-c43j-gjjv.json index 7f451868c95..cec657fc602 100644 --- a/advisories/unreviewed/2022/04/GHSA-g3vc-c43j-gjjv/GHSA-g3vc-c43j-gjjv.json +++ b/advisories/unreviewed/2022/04/GHSA-g3vc-c43j-gjjv/GHSA-g3vc-c43j-gjjv.json @@ -7,12 +7,8 @@ "CVE-2003-0132" ], "details": "A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-g437-46q6-xq6v/GHSA-g437-46q6-xq6v.json b/advisories/unreviewed/2022/04/GHSA-g437-46q6-xq6v/GHSA-g437-46q6-xq6v.json index 7ec01055b01..ed40c5a84b1 100644 --- a/advisories/unreviewed/2022/04/GHSA-g437-46q6-xq6v/GHSA-g437-46q6-xq6v.json +++ b/advisories/unreviewed/2022/04/GHSA-g437-46q6-xq6v/GHSA-g437-46q6-xq6v.json @@ -7,12 +7,8 @@ "CVE-2003-0124" ], "details": "man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf function to return a string with the value \"unsafe,\" which is then executed as a program via a system call if it is in the search path of the user who runs man.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gwqj-g44r-mg5c/GHSA-gwqj-g44r-mg5c.json b/advisories/unreviewed/2022/04/GHSA-gwqj-g44r-mg5c/GHSA-gwqj-g44r-mg5c.json index 0a6e6236014..9d00f6662f6 100644 --- a/advisories/unreviewed/2022/04/GHSA-gwqj-g44r-mg5c/GHSA-gwqj-g44r-mg5c.json +++ b/advisories/unreviewed/2022/04/GHSA-gwqj-g44r-mg5c/GHSA-gwqj-g44r-mg5c.json @@ -7,12 +7,8 @@ "CVE-2003-0077" ], "details": "The hanterm (hanterm-xf) terminal emulator 2.0.5 and earlier, and possibly later versions, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h3gx-6rc9-737v/GHSA-h3gx-6rc9-737v.json b/advisories/unreviewed/2022/04/GHSA-h3gx-6rc9-737v/GHSA-h3gx-6rc9-737v.json index 274c7ab52f8..89dbda25ba0 100644 --- a/advisories/unreviewed/2022/04/GHSA-h3gx-6rc9-737v/GHSA-h3gx-6rc9-737v.json +++ b/advisories/unreviewed/2022/04/GHSA-h3gx-6rc9-737v/GHSA-h3gx-6rc9-737v.json @@ -7,12 +7,8 @@ "CVE-2003-0114" ], "details": "The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h6r9-m8w5-h766/GHSA-h6r9-m8w5-h766.json b/advisories/unreviewed/2022/04/GHSA-h6r9-m8w5-h766/GHSA-h6r9-m8w5-h766.json index 29d1f78b73e..4306ed07f26 100644 --- a/advisories/unreviewed/2022/04/GHSA-h6r9-m8w5-h766/GHSA-h6r9-m8w5-h766.json +++ b/advisories/unreviewed/2022/04/GHSA-h6r9-m8w5-h766/GHSA-h6r9-m8w5-h766.json @@ -7,12 +7,8 @@ "CVE-2003-0139" ], "details": "Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and \"ticket splicing.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h9wv-gwf3-wm7q/GHSA-h9wv-gwf3-wm7q.json b/advisories/unreviewed/2022/04/GHSA-h9wv-gwf3-wm7q/GHSA-h9wv-gwf3-wm7q.json index 54df92a1739..dcb8c616290 100644 --- a/advisories/unreviewed/2022/04/GHSA-h9wv-gwf3-wm7q/GHSA-h9wv-gwf3-wm7q.json +++ b/advisories/unreviewed/2022/04/GHSA-h9wv-gwf3-wm7q/GHSA-h9wv-gwf3-wm7q.json @@ -7,12 +7,8 @@ "CVE-2003-0066" ], "details": "The rxvt terminal emulator 2.7.8 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hc9c-69xv-fwcq/GHSA-hc9c-69xv-fwcq.json b/advisories/unreviewed/2022/04/GHSA-hc9c-69xv-fwcq/GHSA-hc9c-69xv-fwcq.json index 24730957fa6..2d08c06303b 100644 --- a/advisories/unreviewed/2022/04/GHSA-hc9c-69xv-fwcq/GHSA-hc9c-69xv-fwcq.json +++ b/advisories/unreviewed/2022/04/GHSA-hc9c-69xv-fwcq/GHSA-hc9c-69xv-fwcq.json @@ -7,12 +7,8 @@ "CVE-2003-0149" ], "details": "Heap-based buffer overflow in ePO agent for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request containing long parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hp5x-32p6-6vcx/GHSA-hp5x-32p6-6vcx.json b/advisories/unreviewed/2022/04/GHSA-hp5x-32p6-6vcx/GHSA-hp5x-32p6-6vcx.json index 750edb969d6..13b43436eb1 100644 --- a/advisories/unreviewed/2022/04/GHSA-hp5x-32p6-6vcx/GHSA-hp5x-32p6-6vcx.json +++ b/advisories/unreviewed/2022/04/GHSA-hp5x-32p6-6vcx/GHSA-hp5x-32p6-6vcx.json @@ -7,12 +7,8 @@ "CVE-2003-0068" ], "details": "The Eterm terminal emulator 0.9.1 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hx3w-96xp-pcxm/GHSA-hx3w-96xp-pcxm.json b/advisories/unreviewed/2022/04/GHSA-hx3w-96xp-pcxm/GHSA-hx3w-96xp-pcxm.json index affb5bdeff5..e7f70de0734 100644 --- a/advisories/unreviewed/2022/04/GHSA-hx3w-96xp-pcxm/GHSA-hx3w-96xp-pcxm.json +++ b/advisories/unreviewed/2022/04/GHSA-hx3w-96xp-pcxm/GHSA-hx3w-96xp-pcxm.json @@ -7,12 +7,8 @@ "CVE-2003-0050" ], "details": "parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j7w7-v5fm-7hg5/GHSA-j7w7-v5fm-7hg5.json b/advisories/unreviewed/2022/04/GHSA-j7w7-v5fm-7hg5/GHSA-j7w7-v5fm-7hg5.json index 81b5b42cf47..7ef833224f8 100644 --- a/advisories/unreviewed/2022/04/GHSA-j7w7-v5fm-7hg5/GHSA-j7w7-v5fm-7hg5.json +++ b/advisories/unreviewed/2022/04/GHSA-j7w7-v5fm-7hg5/GHSA-j7w7-v5fm-7hg5.json @@ -7,12 +7,8 @@ "CVE-2003-0169" ], "details": "hpnst.exe in the GoAhead-Webs webserver for HP Instant TopTools before 5.55 allows remote attackers to cause a denial of service (CPU consumption) via a request to hpnst.exe that calls itself, which causes an infinite loop.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jg8q-x5wr-cvjx/GHSA-jg8q-x5wr-cvjx.json b/advisories/unreviewed/2022/04/GHSA-jg8q-x5wr-cvjx/GHSA-jg8q-x5wr-cvjx.json index b2fa19aa961..a3d72f1b495 100644 --- a/advisories/unreviewed/2022/04/GHSA-jg8q-x5wr-cvjx/GHSA-jg8q-x5wr-cvjx.json +++ b/advisories/unreviewed/2022/04/GHSA-jg8q-x5wr-cvjx/GHSA-jg8q-x5wr-cvjx.json @@ -7,12 +7,8 @@ "CVE-2003-0081" ], "details": "Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jjcp-54hc-j4ch/GHSA-jjcp-54hc-j4ch.json b/advisories/unreviewed/2022/04/GHSA-jjcp-54hc-j4ch/GHSA-jjcp-54hc-j4ch.json index 609b73b6b49..45f77168f6f 100644 --- a/advisories/unreviewed/2022/04/GHSA-jjcp-54hc-j4ch/GHSA-jjcp-54hc-j4ch.json +++ b/advisories/unreviewed/2022/04/GHSA-jjcp-54hc-j4ch/GHSA-jjcp-54hc-j4ch.json @@ -7,12 +7,8 @@ "CVE-2003-0163" ], "details": "decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a zero byte.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jwhh-h5m8-hcgh/GHSA-jwhh-h5m8-hcgh.json b/advisories/unreviewed/2022/04/GHSA-jwhh-h5m8-hcgh/GHSA-jwhh-h5m8-hcgh.json index 7d5b9339b73..15ceccfaaef 100644 --- a/advisories/unreviewed/2022/04/GHSA-jwhh-h5m8-hcgh/GHSA-jwhh-h5m8-hcgh.json +++ b/advisories/unreviewed/2022/04/GHSA-jwhh-h5m8-hcgh/GHSA-jwhh-h5m8-hcgh.json @@ -7,12 +7,8 @@ "CVE-2003-0172" ], "details": "Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote attackers to cause a crash and possibly execute arbitrary code via a long filename argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jx57-4j83-7ghw/GHSA-jx57-4j83-7ghw.json b/advisories/unreviewed/2022/04/GHSA-jx57-4j83-7ghw/GHSA-jx57-4j83-7ghw.json index 3b5693cd2c5..e60d0beb2f3 100644 --- a/advisories/unreviewed/2022/04/GHSA-jx57-4j83-7ghw/GHSA-jx57-4j83-7ghw.json +++ b/advisories/unreviewed/2022/04/GHSA-jx57-4j83-7ghw/GHSA-jx57-4j83-7ghw.json @@ -7,12 +7,8 @@ "CVE-2003-0116" ], "details": "Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and then accesses the target files, aka \"Modal Dialog script execution.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jxf4-6hgg-qvgr/GHSA-jxf4-6hgg-qvgr.json b/advisories/unreviewed/2022/04/GHSA-jxf4-6hgg-qvgr/GHSA-jxf4-6hgg-qvgr.json index 2bbf4687511..aa61bd527a9 100644 --- a/advisories/unreviewed/2022/04/GHSA-jxf4-6hgg-qvgr/GHSA-jxf4-6hgg-qvgr.json +++ b/advisories/unreviewed/2022/04/GHSA-jxf4-6hgg-qvgr/GHSA-jxf4-6hgg-qvgr.json @@ -7,12 +7,8 @@ "CVE-2003-0154" ], "details": "Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1) the file, root, or rev parameters to cvslog.cgi, (2) the file or root parameters to cvsblame.cgi, (3) various parameters to cvsquery.cgi, (4) the person parameter to showcheckins.cgi, (5) the module parameter to cvsqueryform.cgi, and (6) possibly other attack vectors as identified by Mozilla bug #146244.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m4cx-pcq9-ppj4/GHSA-m4cx-pcq9-ppj4.json b/advisories/unreviewed/2022/04/GHSA-m4cx-pcq9-ppj4/GHSA-m4cx-pcq9-ppj4.json index f8e9fca14fd..ad169be4bc6 100644 --- a/advisories/unreviewed/2022/04/GHSA-m4cx-pcq9-ppj4/GHSA-m4cx-pcq9-ppj4.json +++ b/advisories/unreviewed/2022/04/GHSA-m4cx-pcq9-ppj4/GHSA-m4cx-pcq9-ppj4.json @@ -7,12 +7,8 @@ "CVE-2003-0119" ], "details": "The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mf37-67gp-f2x6/GHSA-mf37-67gp-f2x6.json b/advisories/unreviewed/2022/04/GHSA-mf37-67gp-f2x6/GHSA-mf37-67gp-f2x6.json index 807da92bf65..d79dafa6385 100644 --- a/advisories/unreviewed/2022/04/GHSA-mf37-67gp-f2x6/GHSA-mf37-67gp-f2x6.json +++ b/advisories/unreviewed/2022/04/GHSA-mf37-67gp-f2x6/GHSA-mf37-67gp-f2x6.json @@ -7,12 +7,8 @@ "CVE-2003-0108" ], "details": "isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP packet to UDP port 500, which causes tcpdump to enter an infinite loop.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mfh7-xj2q-5w6v/GHSA-mfh7-xj2q-5w6v.json b/advisories/unreviewed/2022/04/GHSA-mfh7-xj2q-5w6v/GHSA-mfh7-xj2q-5w6v.json index 30b168af5fd..be3056961a4 100644 --- a/advisories/unreviewed/2022/04/GHSA-mfh7-xj2q-5w6v/GHSA-mfh7-xj2q-5w6v.json +++ b/advisories/unreviewed/2022/04/GHSA-mfh7-xj2q-5w6v/GHSA-mfh7-xj2q-5w6v.json @@ -7,12 +7,8 @@ "CVE-2003-0058" ], "details": "MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mhr9-3845-rrw9/GHSA-mhr9-3845-rrw9.json b/advisories/unreviewed/2022/04/GHSA-mhr9-3845-rrw9/GHSA-mhr9-3845-rrw9.json index 5d7013cc9cf..255c4a8e59e 100644 --- a/advisories/unreviewed/2022/04/GHSA-mhr9-3845-rrw9/GHSA-mhr9-3845-rrw9.json +++ b/advisories/unreviewed/2022/04/GHSA-mhr9-3845-rrw9/GHSA-mhr9-3845-rrw9.json @@ -7,12 +7,8 @@ "CVE-2003-0121" ], "details": "Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version header field, which is processed by some mail clients.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mj62-cjx7-r9r6/GHSA-mj62-cjx7-r9r6.json b/advisories/unreviewed/2022/04/GHSA-mj62-cjx7-r9r6/GHSA-mj62-cjx7-r9r6.json index 591bf13c449..1c3e20fc5e3 100644 --- a/advisories/unreviewed/2022/04/GHSA-mj62-cjx7-r9r6/GHSA-mj62-cjx7-r9r6.json +++ b/advisories/unreviewed/2022/04/GHSA-mj62-cjx7-r9r6/GHSA-mj62-cjx7-r9r6.json @@ -7,12 +7,8 @@ "CVE-2003-0129" ], "details": "Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mv26-jcw9-w5v8/GHSA-mv26-jcw9-w5v8.json b/advisories/unreviewed/2022/04/GHSA-mv26-jcw9-w5v8/GHSA-mv26-jcw9-w5v8.json index 88e6e510cd3..2c3372a1ea0 100644 --- a/advisories/unreviewed/2022/04/GHSA-mv26-jcw9-w5v8/GHSA-mv26-jcw9-w5v8.json +++ b/advisories/unreviewed/2022/04/GHSA-mv26-jcw9-w5v8/GHSA-mv26-jcw9-w5v8.json @@ -7,12 +7,8 @@ "CVE-2003-0070" ], "details": "VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p3ch-8ghm-h778/GHSA-p3ch-8ghm-h778.json b/advisories/unreviewed/2022/04/GHSA-p3ch-8ghm-h778/GHSA-p3ch-8ghm-h778.json index 42d033d8e5c..91b0627cc00 100644 --- a/advisories/unreviewed/2022/04/GHSA-p3ch-8ghm-h778/GHSA-p3ch-8ghm-h778.json +++ b/advisories/unreviewed/2022/04/GHSA-p3ch-8ghm-h778/GHSA-p3ch-8ghm-h778.json @@ -7,12 +7,8 @@ "CVE-2003-0057" ], "details": "Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p7j8-gg6m-f88m/GHSA-p7j8-gg6m-f88m.json b/advisories/unreviewed/2022/04/GHSA-p7j8-gg6m-f88m/GHSA-p7j8-gg6m-f88m.json index 6ffe1eca32b..e9531326881 100644 --- a/advisories/unreviewed/2022/04/GHSA-p7j8-gg6m-f88m/GHSA-p7j8-gg6m-f88m.json +++ b/advisories/unreviewed/2022/04/GHSA-p7j8-gg6m-f88m/GHSA-p7j8-gg6m-f88m.json @@ -7,12 +7,8 @@ "CVE-2003-0074" ], "details": "Format string vulnerability in mpmain.c for plpnfsd of the plptools package allows remote attackers to execute arbitrary code via the functions (1) debuglog, (2) errorlog, and (3) infolog.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p9j8-4q5m-jqv4/GHSA-p9j8-4q5m-jqv4.json b/advisories/unreviewed/2022/04/GHSA-p9j8-4q5m-jqv4/GHSA-p9j8-4q5m-jqv4.json index c4b40ac6799..3d98ff0eeee 100644 --- a/advisories/unreviewed/2022/04/GHSA-p9j8-4q5m-jqv4/GHSA-p9j8-4q5m-jqv4.json +++ b/advisories/unreviewed/2022/04/GHSA-p9j8-4q5m-jqv4/GHSA-p9j8-4q5m-jqv4.json @@ -7,12 +7,8 @@ "CVE-2003-0059" ], "details": "Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pg23-xpwh-jqj6/GHSA-pg23-xpwh-jqj6.json b/advisories/unreviewed/2022/04/GHSA-pg23-xpwh-jqj6/GHSA-pg23-xpwh-jqj6.json index 7cfe1829954..4bf594b8c78 100644 --- a/advisories/unreviewed/2022/04/GHSA-pg23-xpwh-jqj6/GHSA-pg23-xpwh-jqj6.json +++ b/advisories/unreviewed/2022/04/GHSA-pg23-xpwh-jqj6/GHSA-pg23-xpwh-jqj6.json @@ -7,12 +7,8 @@ "CVE-2003-0054" ], "details": "Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ppq9-fh4h-jp7j/GHSA-ppq9-fh4h-jp7j.json b/advisories/unreviewed/2022/04/GHSA-ppq9-fh4h-jp7j/GHSA-ppq9-fh4h-jp7j.json index 10c5f4103dc..2d9e1bd6487 100644 --- a/advisories/unreviewed/2022/04/GHSA-ppq9-fh4h-jp7j/GHSA-ppq9-fh4h-jp7j.json +++ b/advisories/unreviewed/2022/04/GHSA-ppq9-fh4h-jp7j/GHSA-ppq9-fh4h-jp7j.json @@ -7,12 +7,8 @@ "CVE-2003-0052" ], "details": "parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pq65-86r9-wp9r/GHSA-pq65-86r9-wp9r.json b/advisories/unreviewed/2022/04/GHSA-pq65-86r9-wp9r/GHSA-pq65-86r9-wp9r.json index cb64327cd0e..e0f95eae9a3 100644 --- a/advisories/unreviewed/2022/04/GHSA-pq65-86r9-wp9r/GHSA-pq65-86r9-wp9r.json +++ b/advisories/unreviewed/2022/04/GHSA-pq65-86r9-wp9r/GHSA-pq65-86r9-wp9r.json @@ -7,12 +7,8 @@ "CVE-2003-0046" ], "details": "AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q3h7-99f2-hhfv/GHSA-q3h7-99f2-hhfv.json b/advisories/unreviewed/2022/04/GHSA-q3h7-99f2-hhfv/GHSA-q3h7-99f2-hhfv.json index 04a8aad5b43..703704f9b57 100644 --- a/advisories/unreviewed/2022/04/GHSA-q3h7-99f2-hhfv/GHSA-q3h7-99f2-hhfv.json +++ b/advisories/unreviewed/2022/04/GHSA-q3h7-99f2-hhfv/GHSA-q3h7-99f2-hhfv.json @@ -7,12 +7,8 @@ "CVE-2003-0096" ], "details": "Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to the TZ_OFFSET function, or (3) a long DIRECTORY parameter to the BFILENAME function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-q6v5-5rq7-43w2/GHSA-q6v5-5rq7-43w2.json b/advisories/unreviewed/2022/04/GHSA-q6v5-5rq7-43w2/GHSA-q6v5-5rq7-43w2.json index 6163885249e..d16e1d1ad90 100644 --- a/advisories/unreviewed/2022/04/GHSA-q6v5-5rq7-43w2/GHSA-q6v5-5rq7-43w2.json +++ b/advisories/unreviewed/2022/04/GHSA-q6v5-5rq7-43w2/GHSA-q6v5-5rq7-43w2.json @@ -7,12 +7,8 @@ "CVE-2003-0120" ], "details": "adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qhmj-58g4-pcj3/GHSA-qhmj-58g4-pcj3.json b/advisories/unreviewed/2022/04/GHSA-qhmj-58g4-pcj3/GHSA-qhmj-58g4-pcj3.json index 6f93b4ee1c5..538ceb25f07 100644 --- a/advisories/unreviewed/2022/04/GHSA-qhmj-58g4-pcj3/GHSA-qhmj-58g4-pcj3.json +++ b/advisories/unreviewed/2022/04/GHSA-qhmj-58g4-pcj3/GHSA-qhmj-58g4-pcj3.json @@ -7,12 +7,8 @@ "CVE-2003-0135" ], "details": "vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restricting access as intended.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qj3j-m7h3-hrhc/GHSA-qj3j-m7h3-hrhc.json b/advisories/unreviewed/2022/04/GHSA-qj3j-m7h3-hrhc/GHSA-qj3j-m7h3-hrhc.json index 90fe2202cca..83c41bf9b31 100644 --- a/advisories/unreviewed/2022/04/GHSA-qj3j-m7h3-hrhc/GHSA-qj3j-m7h3-hrhc.json +++ b/advisories/unreviewed/2022/04/GHSA-qj3j-m7h3-hrhc/GHSA-qj3j-m7h3-hrhc.json @@ -7,12 +7,8 @@ "CVE-2003-0140" ], "details": "Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qqqr-r93w-v4pj/GHSA-qqqr-r93w-v4pj.json b/advisories/unreviewed/2022/04/GHSA-qqqr-r93w-v4pj/GHSA-qqqr-r93w-v4pj.json index 209b74a5e3f..4005d634726 100644 --- a/advisories/unreviewed/2022/04/GHSA-qqqr-r93w-v4pj/GHSA-qqqr-r93w-v4pj.json +++ b/advisories/unreviewed/2022/04/GHSA-qqqr-r93w-v4pj/GHSA-qqqr-r93w-v4pj.json @@ -7,12 +7,8 @@ "CVE-2003-0155" ], "details": "bonsai Mozilla CVS query tool allows remote attackers to gain access to the parameters page without authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qvf9-3jqp-93pc/GHSA-qvf9-3jqp-93pc.json b/advisories/unreviewed/2022/04/GHSA-qvf9-3jqp-93pc/GHSA-qvf9-3jqp-93pc.json index b1306e680e8..ddb766aa7a9 100644 --- a/advisories/unreviewed/2022/04/GHSA-qvf9-3jqp-93pc/GHSA-qvf9-3jqp-93pc.json +++ b/advisories/unreviewed/2022/04/GHSA-qvf9-3jqp-93pc/GHSA-qvf9-3jqp-93pc.json @@ -7,12 +7,8 @@ "CVE-2003-0092" ], "details": "Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qvpg-g989-h8h6/GHSA-qvpg-g989-h8h6.json b/advisories/unreviewed/2022/04/GHSA-qvpg-g989-h8h6/GHSA-qvpg-g989-h8h6.json index eec96d9859e..04a81bb80c2 100644 --- a/advisories/unreviewed/2022/04/GHSA-qvpg-g989-h8h6/GHSA-qvpg-g989-h8h6.json +++ b/advisories/unreviewed/2022/04/GHSA-qvpg-g989-h8h6/GHSA-qvpg-g989-h8h6.json @@ -7,12 +7,8 @@ "CVE-2003-0112" ], "details": "Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qxpj-m267-3648/GHSA-qxpj-m267-3648.json b/advisories/unreviewed/2022/04/GHSA-qxpj-m267-3648/GHSA-qxpj-m267-3648.json index b637c4c17c4..503d549cb44 100644 --- a/advisories/unreviewed/2022/04/GHSA-qxpj-m267-3648/GHSA-qxpj-m267-3648.json +++ b/advisories/unreviewed/2022/04/GHSA-qxpj-m267-3648/GHSA-qxpj-m267-3648.json @@ -7,12 +7,8 @@ "CVE-2003-0138" ], "details": "Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r22w-p944-mxwf/GHSA-r22w-p944-mxwf.json b/advisories/unreviewed/2022/04/GHSA-r22w-p944-mxwf/GHSA-r22w-p944-mxwf.json index 19f49bf9151..76dcd8d8c1a 100644 --- a/advisories/unreviewed/2022/04/GHSA-r22w-p944-mxwf/GHSA-r22w-p944-mxwf.json +++ b/advisories/unreviewed/2022/04/GHSA-r22w-p944-mxwf/GHSA-r22w-p944-mxwf.json @@ -7,12 +7,8 @@ "CVE-2003-0100" ], "details": "Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of OSPF neighbor announcements.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r3hh-vv32-g653/GHSA-r3hh-vv32-g653.json b/advisories/unreviewed/2022/04/GHSA-r3hh-vv32-g653/GHSA-r3hh-vv32-g653.json index 00e77659d64..f953e58cd8a 100644 --- a/advisories/unreviewed/2022/04/GHSA-r3hh-vv32-g653/GHSA-r3hh-vv32-g653.json +++ b/advisories/unreviewed/2022/04/GHSA-r3hh-vv32-g653/GHSA-r3hh-vv32-g653.json @@ -7,12 +7,8 @@ "CVE-2003-0030" ], "details": "Buffer overflows in protegrity.dll of Protegrity Secure.Data Extension Feature (SEF) before 2.2.3.9 allow attackers with SQL access to execute arbitrary code via the extended stored procedures (1) xp_pty_checkusers, (2) xp_pty_insert, or (3) xp_pty_select.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r49h-f389-j4hc/GHSA-r49h-f389-j4hc.json b/advisories/unreviewed/2022/04/GHSA-r49h-f389-j4hc/GHSA-r49h-f389-j4hc.json index 5d590eb7b18..75caf98e057 100644 --- a/advisories/unreviewed/2022/04/GHSA-r49h-f389-j4hc/GHSA-r49h-f389-j4hc.json +++ b/advisories/unreviewed/2022/04/GHSA-r49h-f389-j4hc/GHSA-r49h-f389-j4hc.json @@ -7,12 +7,8 @@ "CVE-2003-0126" ], "details": "The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default \"admin\" account with a blank password, which could allow attackers on the LAN side to conduct unauthorized activities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r77q-2w9x-9gcq/GHSA-r77q-2w9x-9gcq.json b/advisories/unreviewed/2022/04/GHSA-r77q-2w9x-9gcq/GHSA-r77q-2w9x-9gcq.json index 7bb6a634a9d..9f942059c0a 100644 --- a/advisories/unreviewed/2022/04/GHSA-r77q-2w9x-9gcq/GHSA-r77q-2w9x-9gcq.json +++ b/advisories/unreviewed/2022/04/GHSA-r77q-2w9x-9gcq/GHSA-r77q-2w9x-9gcq.json @@ -7,12 +7,8 @@ "CVE-2003-0142" ], "details": "Adobe Acrobat Reader (acroread) 6, under certain circumstances when running with the \"Certified plug-ins only\" option disabled, loads plug-ins with signatures used for older versions of Acrobat, which can allow attackers to cause Acrobat to enter Certified mode and run untrusted plugins by modifying the CTIsCertifiedMode function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rcwm-qwrf-r7p7/GHSA-rcwm-qwrf-r7p7.json b/advisories/unreviewed/2022/04/GHSA-rcwm-qwrf-r7p7/GHSA-rcwm-qwrf-r7p7.json index 7b8890cdd80..61d3ce78c78 100644 --- a/advisories/unreviewed/2022/04/GHSA-rcwm-qwrf-r7p7/GHSA-rcwm-qwrf-r7p7.json +++ b/advisories/unreviewed/2022/04/GHSA-rcwm-qwrf-r7p7/GHSA-rcwm-qwrf-r7p7.json @@ -7,12 +7,8 @@ "CVE-2003-0115" ], "details": "Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remote attackers to execute arbitrary web script, aka the \"Third Party Plugin Rendering\" vulnerability, a different vulnerability than CVE-2003-0233.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rj9f-x466-2vr9/GHSA-rj9f-x466-2vr9.json b/advisories/unreviewed/2022/04/GHSA-rj9f-x466-2vr9/GHSA-rj9f-x466-2vr9.json index f05617e12ab..39e0c177d8f 100644 --- a/advisories/unreviewed/2022/04/GHSA-rj9f-x466-2vr9/GHSA-rj9f-x466-2vr9.json +++ b/advisories/unreviewed/2022/04/GHSA-rj9f-x466-2vr9/GHSA-rj9f-x466-2vr9.json @@ -7,12 +7,8 @@ "CVE-2003-0110" ], "details": "The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rwp5-4g93-w88g/GHSA-rwp5-4g93-w88g.json b/advisories/unreviewed/2022/04/GHSA-rwp5-4g93-w88g/GHSA-rwp5-4g93-w88g.json index c29f3787ac1..6ab6f7e5772 100644 --- a/advisories/unreviewed/2022/04/GHSA-rwp5-4g93-w88g/GHSA-rwp5-4g93-w88g.json +++ b/advisories/unreviewed/2022/04/GHSA-rwp5-4g93-w88g/GHSA-rwp5-4g93-w88g.json @@ -7,12 +7,8 @@ "CVE-2003-0064" ], "details": "The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v7m5-jjhm-hp24/GHSA-v7m5-jjhm-hp24.json b/advisories/unreviewed/2022/04/GHSA-v7m5-jjhm-hp24/GHSA-v7m5-jjhm-hp24.json index e01f6ca1923..6cbb77e46ec 100644 --- a/advisories/unreviewed/2022/04/GHSA-v7m5-jjhm-hp24/GHSA-v7m5-jjhm-hp24.json +++ b/advisories/unreviewed/2022/04/GHSA-v7m5-jjhm-hp24/GHSA-v7m5-jjhm-hp24.json @@ -7,12 +7,8 @@ "CVE-2003-0167" ], "details": "Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and Balsa 1.2.4 and earlier, allow a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a specially crafted mail folder, a different vulnerability than CVE-2003-0140.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vfjj-wr2x-w2ch/GHSA-vfjj-wr2x-w2ch.json b/advisories/unreviewed/2022/04/GHSA-vfjj-wr2x-w2ch/GHSA-vfjj-wr2x-w2ch.json index ae4cf86931b..fb14e675d70 100644 --- a/advisories/unreviewed/2022/04/GHSA-vfjj-wr2x-w2ch/GHSA-vfjj-wr2x-w2ch.json +++ b/advisories/unreviewed/2022/04/GHSA-vfjj-wr2x-w2ch/GHSA-vfjj-wr2x-w2ch.json @@ -7,12 +7,8 @@ "CVE-2003-0075" ], "details": "Integer signedness error in the myFseek function of samplein.c for Blade encoder (BladeEnc) 0.94.2 and earlier allows remote attackers to execute arbitrary code via a negative offset value following a \"fmt\" wave chunk.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vhww-qqjw-px6w/GHSA-vhww-qqjw-px6w.json b/advisories/unreviewed/2022/04/GHSA-vhww-qqjw-px6w/GHSA-vhww-qqjw-px6w.json index be377e99daf..a0ce2609a40 100644 --- a/advisories/unreviewed/2022/04/GHSA-vhww-qqjw-px6w/GHSA-vhww-qqjw-px6w.json +++ b/advisories/unreviewed/2022/04/GHSA-vhww-qqjw-px6w/GHSA-vhww-qqjw-px6w.json @@ -7,12 +7,8 @@ "CVE-2003-0094" ], "details": "A patch for mcookie in the util-linux package for Mandrake Linux 8.2 and 9.0 uses /dev/urandom instead of /dev/random, which causes mcookie to use an entropy source that is more predictable than expected, which may make it easier for certain types of attacks to succeed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vqgf-8h52-rhrp/GHSA-vqgf-8h52-rhrp.json b/advisories/unreviewed/2022/04/GHSA-vqgf-8h52-rhrp/GHSA-vqgf-8h52-rhrp.json index 9269b23c58a..ee1c099e534 100644 --- a/advisories/unreviewed/2022/04/GHSA-vqgf-8h52-rhrp/GHSA-vqgf-8h52-rhrp.json +++ b/advisories/unreviewed/2022/04/GHSA-vqgf-8h52-rhrp/GHSA-vqgf-8h52-rhrp.json @@ -7,12 +7,8 @@ "CVE-2003-0048" ], "details": "PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vrgp-v3rr-v9mg/GHSA-vrgp-v3rr-v9mg.json b/advisories/unreviewed/2022/04/GHSA-vrgp-v3rr-v9mg/GHSA-vrgp-v3rr-v9mg.json index c3f1495e6c6..d9c18b3ebf0 100644 --- a/advisories/unreviewed/2022/04/GHSA-vrgp-v3rr-v9mg/GHSA-vrgp-v3rr-v9mg.json +++ b/advisories/unreviewed/2022/04/GHSA-vrgp-v3rr-v9mg/GHSA-vrgp-v3rr-v9mg.json @@ -7,12 +7,8 @@ "CVE-2003-0040" ], "details": "SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vw24-98xw-c2qv/GHSA-vw24-98xw-c2qv.json b/advisories/unreviewed/2022/04/GHSA-vw24-98xw-c2qv/GHSA-vw24-98xw-c2qv.json index 5d6fde9cbbb..7e6cb03024d 100644 --- a/advisories/unreviewed/2022/04/GHSA-vw24-98xw-c2qv/GHSA-vw24-98xw-c2qv.json +++ b/advisories/unreviewed/2022/04/GHSA-vw24-98xw-c2qv/GHSA-vw24-98xw-c2qv.json @@ -7,12 +7,8 @@ "CVE-2003-0150" ], "details": "MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the \"SELECT * INFO OUTFILE\" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w8mv-4w2v-qfg8/GHSA-w8mv-4w2v-qfg8.json b/advisories/unreviewed/2022/04/GHSA-w8mv-4w2v-qfg8/GHSA-w8mv-4w2v-qfg8.json index c3d5cda84ff..c15e6b05dad 100644 --- a/advisories/unreviewed/2022/04/GHSA-w8mv-4w2v-qfg8/GHSA-w8mv-4w2v-qfg8.json +++ b/advisories/unreviewed/2022/04/GHSA-w8mv-4w2v-qfg8/GHSA-w8mv-4w2v-qfg8.json @@ -7,12 +7,8 @@ "CVE-2003-0146" ], "details": "Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via \"maths overflow errors\" such as (1) integer signedness errors or (2) integer overflows, which lead to buffer overflows.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wcfm-6r83-67px/GHSA-wcfm-6r83-67px.json b/advisories/unreviewed/2022/04/GHSA-wcfm-6r83-67px/GHSA-wcfm-6r83-67px.json index da393d0f2af..db0b68ab7a6 100644 --- a/advisories/unreviewed/2022/04/GHSA-wcfm-6r83-67px/GHSA-wcfm-6r83-67px.json +++ b/advisories/unreviewed/2022/04/GHSA-wcfm-6r83-67px/GHSA-wcfm-6r83-67px.json @@ -7,12 +7,8 @@ "CVE-2003-0093" ], "details": "The RADIUS decoder in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service (crash) via an invalid RADIUS packet with a header length field of 0, which causes tcpdump to generate data within an infinite loop.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wfpc-v3c5-rxcq/GHSA-wfpc-v3c5-rxcq.json b/advisories/unreviewed/2022/04/GHSA-wfpc-v3c5-rxcq/GHSA-wfpc-v3c5-rxcq.json index 40dc0e2a1cd..48b2e0e49ac 100644 --- a/advisories/unreviewed/2022/04/GHSA-wfpc-v3c5-rxcq/GHSA-wfpc-v3c5-rxcq.json +++ b/advisories/unreviewed/2022/04/GHSA-wfpc-v3c5-rxcq/GHSA-wfpc-v3c5-rxcq.json @@ -7,12 +7,8 @@ "CVE-2003-0097" ], "details": "Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wxqm-488m-v2xg/GHSA-wxqm-488m-v2xg.json b/advisories/unreviewed/2022/04/GHSA-wxqm-488m-v2xg/GHSA-wxqm-488m-v2xg.json index 89b2a8f8f51..a5b86bdc52d 100644 --- a/advisories/unreviewed/2022/04/GHSA-wxqm-488m-v2xg/GHSA-wxqm-488m-v2xg.json +++ b/advisories/unreviewed/2022/04/GHSA-wxqm-488m-v2xg/GHSA-wxqm-488m-v2xg.json @@ -7,12 +7,8 @@ "CVE-2003-0165" ], "details": "Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xcjx-ph22-cf83/GHSA-xcjx-ph22-cf83.json b/advisories/unreviewed/2022/04/GHSA-xcjx-ph22-cf83/GHSA-xcjx-ph22-cf83.json index c19b85c4491..6860c8a541c 100644 --- a/advisories/unreviewed/2022/04/GHSA-xcjx-ph22-cf83/GHSA-xcjx-ph22-cf83.json +++ b/advisories/unreviewed/2022/04/GHSA-xcjx-ph22-cf83/GHSA-xcjx-ph22-cf83.json @@ -7,12 +7,8 @@ "CVE-2003-0153" ], "details": "bonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.cgi, (2) cvsview2.cgi, or (3) multidiff.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xjx4-phqj-92m5/GHSA-xjx4-phqj-92m5.json b/advisories/unreviewed/2022/04/GHSA-xjx4-phqj-92m5/GHSA-xjx4-phqj-92m5.json index 19dbd7c146d..93e9ba2d561 100644 --- a/advisories/unreviewed/2022/04/GHSA-xjx4-phqj-92m5/GHSA-xjx4-phqj-92m5.json +++ b/advisories/unreviewed/2022/04/GHSA-xjx4-phqj-92m5/GHSA-xjx4-phqj-92m5.json @@ -7,12 +7,8 @@ "CVE-2003-0084" ], "details": "mod_auth_any package in Red Hat Enterprise Linux 2.1 and other operating systems does not properly escape arguments when calling other programs, which allows attackers to execute arbitrary commands via shell metacharacters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xv76-8jhj-2c53/GHSA-xv76-8jhj-2c53.json b/advisories/unreviewed/2022/04/GHSA-xv76-8jhj-2c53/GHSA-xv76-8jhj-2c53.json index e926f05bdc2..11cad173165 100644 --- a/advisories/unreviewed/2022/04/GHSA-xv76-8jhj-2c53/GHSA-xv76-8jhj-2c53.json +++ b/advisories/unreviewed/2022/04/GHSA-xv76-8jhj-2c53/GHSA-xv76-8jhj-2c53.json @@ -7,12 +7,8 @@ "CVE-2003-0071" ], "details": "The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xx9h-hw83-5282/GHSA-xx9h-hw83-5282.json b/advisories/unreviewed/2022/04/GHSA-xx9h-hw83-5282/GHSA-xx9h-hw83-5282.json index 61c47441533..c1c916564b4 100644 --- a/advisories/unreviewed/2022/04/GHSA-xx9h-hw83-5282/GHSA-xx9h-hw83-5282.json +++ b/advisories/unreviewed/2022/04/GHSA-xx9h-hw83-5282/GHSA-xx9h-hw83-5282.json @@ -7,12 +7,8 @@ "CVE-2003-0105" ], "details": "ServerMask 2.2 and earlier does not obfuscate (1) ETag, (2) HTTP Status Message, or (3) Allow HTTP responses, which could tell remote attackers that the web server is an IIS server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2282-f329-v64x/GHSA-2282-f329-v64x.json b/advisories/unreviewed/2022/05/GHSA-2282-f329-v64x/GHSA-2282-f329-v64x.json index 296b10411dd..ab6e4f91485 100644 --- a/advisories/unreviewed/2022/05/GHSA-2282-f329-v64x/GHSA-2282-f329-v64x.json +++ b/advisories/unreviewed/2022/05/GHSA-2282-f329-v64x/GHSA-2282-f329-v64x.json @@ -7,12 +7,8 @@ "CVE-2020-2682" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-23g9-fmq6-8jfq/GHSA-23g9-fmq6-8jfq.json b/advisories/unreviewed/2022/05/GHSA-23g9-fmq6-8jfq/GHSA-23g9-fmq6-8jfq.json index 1ae22bac7f5..3b2a5f2219f 100644 --- a/advisories/unreviewed/2022/05/GHSA-23g9-fmq6-8jfq/GHSA-23g9-fmq6-8jfq.json +++ b/advisories/unreviewed/2022/05/GHSA-23g9-fmq6-8jfq/GHSA-23g9-fmq6-8jfq.json @@ -7,12 +7,8 @@ "CVE-2019-10579" ], "details": "Buffer over-read can occur while playing the video clip which is not standard in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA6574AU, QCS605, QM215, Rennell, SA6155P, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2427-rpxm-q3f4/GHSA-2427-rpxm-q3f4.json b/advisories/unreviewed/2022/05/GHSA-2427-rpxm-q3f4/GHSA-2427-rpxm-q3f4.json index 6b73db5e37d..c3e3293018f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2427-rpxm-q3f4/GHSA-2427-rpxm-q3f4.json +++ b/advisories/unreviewed/2022/05/GHSA-2427-rpxm-q3f4/GHSA-2427-rpxm-q3f4.json @@ -7,12 +7,8 @@ "CVE-2019-15707" ], "details": "An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to perform system backup config download they should not be authorized for.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-24g2-f5xv-hrqq/GHSA-24g2-f5xv-hrqq.json b/advisories/unreviewed/2022/05/GHSA-24g2-f5xv-hrqq/GHSA-24g2-f5xv-hrqq.json index e34dc02a36b..72817fd2176 100644 --- a/advisories/unreviewed/2022/05/GHSA-24g2-f5xv-hrqq/GHSA-24g2-f5xv-hrqq.json +++ b/advisories/unreviewed/2022/05/GHSA-24g2-f5xv-hrqq/GHSA-24g2-f5xv-hrqq.json @@ -7,12 +7,8 @@ "CVE-2019-10958" ], "details": "Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated attacker with access to network configuration to supply system commands to the server, leading to remote code execution as root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-26c5-vwmh-pc7q/GHSA-26c5-vwmh-pc7q.json b/advisories/unreviewed/2022/05/GHSA-26c5-vwmh-pc7q/GHSA-26c5-vwmh-pc7q.json index 24d9173299c..b69f0b78bbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-26c5-vwmh-pc7q/GHSA-26c5-vwmh-pc7q.json +++ b/advisories/unreviewed/2022/05/GHSA-26c5-vwmh-pc7q/GHSA-26c5-vwmh-pc7q.json @@ -7,12 +7,8 @@ "CVE-2019-14006" ], "details": "Buffer overflow occur while playing the clip which is nonstandard due to lack of offset length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, Nicobar, QCS605, QM215, Rennell, SA6155P, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-26h8-43q7-4r2w/GHSA-26h8-43q7-4r2w.json b/advisories/unreviewed/2022/05/GHSA-26h8-43q7-4r2w/GHSA-26h8-43q7-4r2w.json index 1d6af81f917..310144cc7b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-26h8-43q7-4r2w/GHSA-26h8-43q7-4r2w.json +++ b/advisories/unreviewed/2022/05/GHSA-26h8-43q7-4r2w/GHSA-26h8-43q7-4r2w.json @@ -7,12 +7,8 @@ "CVE-2015-8012" ], "details": "lldpd before 0.8.0 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via a malformed packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-26mq-j972-xv5x/GHSA-26mq-j972-xv5x.json b/advisories/unreviewed/2022/05/GHSA-26mq-j972-xv5x/GHSA-26mq-j972-xv5x.json index b971db4e09e..34cf4caa225 100644 --- a/advisories/unreviewed/2022/05/GHSA-26mq-j972-xv5x/GHSA-26mq-j972-xv5x.json +++ b/advisories/unreviewed/2022/05/GHSA-26mq-j972-xv5x/GHSA-26mq-j972-xv5x.json @@ -7,12 +7,8 @@ "CVE-2019-20097" ], "details": "Bitbucket Server and Bitbucket Data Center versions starting from 1.0.0 before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from version 6.7.0 before 6.7.3, from version 6.8.0 before 6.8.2, from version 6.9.0 before 6.9.1 had a Remote Code Execution vulnerability via the post-receive hook. A remote attacker with permission to clone and push files to a repository on the victim's Bitbucket Server or Bitbucket Data Center instance, can exploit this vulnerability to execute arbitrary commands on the Bitbucket Server or Bitbucket Data Center systems, using a file with specially crafted content.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-273f-4hpp-885q/GHSA-273f-4hpp-885q.json b/advisories/unreviewed/2022/05/GHSA-273f-4hpp-885q/GHSA-273f-4hpp-885q.json index 82115857962..0a7d5e8d07b 100644 --- a/advisories/unreviewed/2022/05/GHSA-273f-4hpp-885q/GHSA-273f-4hpp-885q.json +++ b/advisories/unreviewed/2022/05/GHSA-273f-4hpp-885q/GHSA-273f-4hpp-885q.json @@ -7,12 +7,8 @@ "CVE-2020-0653" ], "details": "A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0650, CVE-2020-0651.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-27q6-288h-36j9/GHSA-27q6-288h-36j9.json b/advisories/unreviewed/2022/05/GHSA-27q6-288h-36j9/GHSA-27q6-288h-36j9.json index 5c8906b84b9..7086cd608a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-27q6-288h-36j9/GHSA-27q6-288h-36j9.json +++ b/advisories/unreviewed/2022/05/GHSA-27q6-288h-36j9/GHSA-27q6-288h-36j9.json @@ -7,12 +7,8 @@ "CVE-2008-4977" ], "details": "** DISPUTED ** postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /tmp/postfix_groups.stderr, and (3) /tmp/postfix_groups.message temporary files. NOTE: the vendor disputes this vulnerability, stating \"This is not a real issue ... users would have to edit a script under /usr/lib to enable it.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2826-h3cg-5m6j/GHSA-2826-h3cg-5m6j.json b/advisories/unreviewed/2022/05/GHSA-2826-h3cg-5m6j/GHSA-2826-h3cg-5m6j.json index ed63507a429..4208792971d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2826-h3cg-5m6j/GHSA-2826-h3cg-5m6j.json +++ b/advisories/unreviewed/2022/05/GHSA-2826-h3cg-5m6j/GHSA-2826-h3cg-5m6j.json @@ -7,12 +7,8 @@ "CVE-2019-19895" ], "details": "In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system. An authenticated attacker can, by modifying %SYSTEMDRIVE%\\IXP\\SW\\[PACKAGE_CODE]\\EveryLogon.bat, achieve this movement and execute code in the context of other users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2974-6593-2jqm/GHSA-2974-6593-2jqm.json b/advisories/unreviewed/2022/05/GHSA-2974-6593-2jqm/GHSA-2974-6593-2jqm.json index d72a78c6181..165f0c6a0fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-2974-6593-2jqm/GHSA-2974-6593-2jqm.json +++ b/advisories/unreviewed/2022/05/GHSA-2974-6593-2jqm/GHSA-2974-6593-2jqm.json @@ -7,12 +7,8 @@ "CVE-2019-5124" ], "details": "An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.50005. A specially crafted pixel shader can cause a denial of service. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2c5m-w65p-6fhv/GHSA-2c5m-w65p-6fhv.json b/advisories/unreviewed/2022/05/GHSA-2c5m-w65p-6fhv/GHSA-2c5m-w65p-6fhv.json index 0a97cc6aed2..45f6a3c543e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c5m-w65p-6fhv/GHSA-2c5m-w65p-6fhv.json +++ b/advisories/unreviewed/2022/05/GHSA-2c5m-w65p-6fhv/GHSA-2c5m-w65p-6fhv.json @@ -7,12 +7,8 @@ "CVE-2010-4924" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in logic/controller.class.php in clearBudget 0.9.8 allows remote attackers to execute arbitrary PHP code via a URL in the actionPath parameter. NOTE: this issue has been disputed by a reliable third party.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fc8-2w75-6pjh/GHSA-2fc8-2w75-6pjh.json b/advisories/unreviewed/2022/05/GHSA-2fc8-2w75-6pjh/GHSA-2fc8-2w75-6pjh.json index f68d07a0841..e63395ca43d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fc8-2w75-6pjh/GHSA-2fc8-2w75-6pjh.json +++ b/advisories/unreviewed/2022/05/GHSA-2fc8-2w75-6pjh/GHSA-2fc8-2w75-6pjh.json @@ -7,12 +7,8 @@ "CVE-2019-8945" ], "details": "Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2fh4-cpv8-68hg/GHSA-2fh4-cpv8-68hg.json b/advisories/unreviewed/2022/05/GHSA-2fh4-cpv8-68hg/GHSA-2fh4-cpv8-68hg.json index 87bda0aad64..aa4ccdd1443 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fh4-cpv8-68hg/GHSA-2fh4-cpv8-68hg.json +++ b/advisories/unreviewed/2022/05/GHSA-2fh4-cpv8-68hg/GHSA-2fh4-cpv8-68hg.json @@ -7,12 +7,8 @@ "CVE-2010-5170" ], "details": "** DISPUTED ** Race condition in Online Solutions Security Suite 1.5.14905.0 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fjc-pm99-j2c2/GHSA-2fjc-pm99-j2c2.json b/advisories/unreviewed/2022/05/GHSA-2fjc-pm99-j2c2/GHSA-2fjc-pm99-j2c2.json index 1899df293c3..aab509469f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fjc-pm99-j2c2/GHSA-2fjc-pm99-j2c2.json +++ b/advisories/unreviewed/2022/05/GHSA-2fjc-pm99-j2c2/GHSA-2fjc-pm99-j2c2.json @@ -7,12 +7,8 @@ "CVE-2019-19856" ], "details": "An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. The User Type on the admin/list_user page allows stored XSS via the type parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2j93-mxgm-h8v9/GHSA-2j93-mxgm-h8v9.json b/advisories/unreviewed/2022/05/GHSA-2j93-mxgm-h8v9/GHSA-2j93-mxgm-h8v9.json index 49069ac0655..9de6dcc8836 100644 --- a/advisories/unreviewed/2022/05/GHSA-2j93-mxgm-h8v9/GHSA-2j93-mxgm-h8v9.json +++ b/advisories/unreviewed/2022/05/GHSA-2j93-mxgm-h8v9/GHSA-2j93-mxgm-h8v9.json @@ -7,12 +7,8 @@ "CVE-2020-2702" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2m5c-rmhj-5qvf/GHSA-2m5c-rmhj-5qvf.json b/advisories/unreviewed/2022/05/GHSA-2m5c-rmhj-5qvf/GHSA-2m5c-rmhj-5qvf.json index ab6bf6e7584..bfa1e5a4189 100644 --- a/advisories/unreviewed/2022/05/GHSA-2m5c-rmhj-5qvf/GHSA-2m5c-rmhj-5qvf.json +++ b/advisories/unreviewed/2022/05/GHSA-2m5c-rmhj-5qvf/GHSA-2m5c-rmhj-5qvf.json @@ -7,12 +7,8 @@ "CVE-2019-20427" ], "details": "In the Lustre file system before 2.12.3, the ptlrpc module has a buffer overflow and panic, and possibly remote code execution, due to the lack of validation for specific fields of packets sent by a client. Interaction between req_capsule_get_size and tgt_brw_write leads to a tgt_shortio2pages integer signedness error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2q8g-m887-7m34/GHSA-2q8g-m887-7m34.json b/advisories/unreviewed/2022/05/GHSA-2q8g-m887-7m34/GHSA-2q8g-m887-7m34.json index 5403287e0e2..2b381e74e71 100644 --- a/advisories/unreviewed/2022/05/GHSA-2q8g-m887-7m34/GHSA-2q8g-m887-7m34.json +++ b/advisories/unreviewed/2022/05/GHSA-2q8g-m887-7m34/GHSA-2q8g-m887-7m34.json @@ -7,12 +7,8 @@ "CVE-2019-19802" ], "details": "In Gallagher Command Centre Server v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prior to v7.80.960(MR2) and v7.70 or earlier, an authenticated user connecting to OPCUA can view all data that would be replicated in a multi-server setup without privilege checks being applied.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2r4w-c5qm-vpx8/GHSA-2r4w-c5qm-vpx8.json b/advisories/unreviewed/2022/05/GHSA-2r4w-c5qm-vpx8/GHSA-2r4w-c5qm-vpx8.json index 93d2cddaa91..4007d7f0776 100644 --- a/advisories/unreviewed/2022/05/GHSA-2r4w-c5qm-vpx8/GHSA-2r4w-c5qm-vpx8.json +++ b/advisories/unreviewed/2022/05/GHSA-2r4w-c5qm-vpx8/GHSA-2r4w-c5qm-vpx8.json @@ -7,12 +7,8 @@ "CVE-2014-1943" ], "details": "Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2r7w-r6xm-q2q9/GHSA-2r7w-r6xm-q2q9.json b/advisories/unreviewed/2022/05/GHSA-2r7w-r6xm-q2q9/GHSA-2r7w-r6xm-q2q9.json index 7f422ba4fc2..bd757b0d6cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-2r7w-r6xm-q2q9/GHSA-2r7w-r6xm-q2q9.json +++ b/advisories/unreviewed/2022/05/GHSA-2r7w-r6xm-q2q9/GHSA-2r7w-r6xm-q2q9.json @@ -7,12 +7,8 @@ "CVE-2019-19894" ], "details": "In IXP EasyInstall 6.2.13723, it is possible to temporarily disable UAC by using the Agent Service on a client system. An authenticated attacker (non-admin) can disable UAC for other users by renaming and replacing %SYSTEMDRIVE%\\IXP\\DATA\\IXPAS.IXP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2rp4-hm5g-p38j/GHSA-2rp4-hm5g-p38j.json b/advisories/unreviewed/2022/05/GHSA-2rp4-hm5g-p38j/GHSA-2rp4-hm5g-p38j.json index c29ec187e64..ac81488a1da 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rp4-hm5g-p38j/GHSA-2rp4-hm5g-p38j.json +++ b/advisories/unreviewed/2022/05/GHSA-2rp4-hm5g-p38j/GHSA-2rp4-hm5g-p38j.json @@ -7,12 +7,8 @@ "CVE-2019-19843" ], "details": "Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a symlink with /tmp and web/user/wps_tool_cache.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v9r-8543-48mw/GHSA-2v9r-8543-48mw.json b/advisories/unreviewed/2022/05/GHSA-2v9r-8543-48mw/GHSA-2v9r-8543-48mw.json index c18b20b504b..9e0725cfce3 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v9r-8543-48mw/GHSA-2v9r-8543-48mw.json +++ b/advisories/unreviewed/2022/05/GHSA-2v9r-8543-48mw/GHSA-2v9r-8543-48mw.json @@ -7,12 +7,8 @@ "CVE-2019-20425" ], "details": "In the Lustre file system before 2.12.3, the ptlrpc module has an out-of-bounds access and panic due to the lack of validation for specific fields of packets sent by a client. In the function lustre_msg_string, there is no validation of a certain length value derived from lustre_msg_buflen_v2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2w82-mm6w-3vc9/GHSA-2w82-mm6w-3vc9.json b/advisories/unreviewed/2022/05/GHSA-2w82-mm6w-3vc9/GHSA-2w82-mm6w-3vc9.json index fab822edabd..cfdc62beed2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w82-mm6w-3vc9/GHSA-2w82-mm6w-3vc9.json +++ b/advisories/unreviewed/2022/05/GHSA-2w82-mm6w-3vc9/GHSA-2w82-mm6w-3vc9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xqq-rhmm-h69h/GHSA-2xqq-rhmm-h69h.json b/advisories/unreviewed/2022/05/GHSA-2xqq-rhmm-h69h/GHSA-2xqq-rhmm-h69h.json index 439e520a234..3d8ff904f34 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xqq-rhmm-h69h/GHSA-2xqq-rhmm-h69h.json +++ b/advisories/unreviewed/2022/05/GHSA-2xqq-rhmm-h69h/GHSA-2xqq-rhmm-h69h.json @@ -7,12 +7,8 @@ "CVE-2019-19840" ], "details": "A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remote code execution via an unauthenticated HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-322g-3p44-gp9p/GHSA-322g-3p44-gp9p.json b/advisories/unreviewed/2022/05/GHSA-322g-3p44-gp9p/GHSA-322g-3p44-gp9p.json index 4fd29104366..3714b17394d 100644 --- a/advisories/unreviewed/2022/05/GHSA-322g-3p44-gp9p/GHSA-322g-3p44-gp9p.json +++ b/advisories/unreviewed/2022/05/GHSA-322g-3p44-gp9p/GHSA-322g-3p44-gp9p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-324m-p5mr-m7mp/GHSA-324m-p5mr-m7mp.json b/advisories/unreviewed/2022/05/GHSA-324m-p5mr-m7mp/GHSA-324m-p5mr-m7mp.json index 656303589e9..1678b1de0bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-324m-p5mr-m7mp/GHSA-324m-p5mr-m7mp.json +++ b/advisories/unreviewed/2022/05/GHSA-324m-p5mr-m7mp/GHSA-324m-p5mr-m7mp.json @@ -7,12 +7,8 @@ "CVE-2020-0625" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-325v-9p4r-7hxc/GHSA-325v-9p4r-7hxc.json b/advisories/unreviewed/2022/05/GHSA-325v-9p4r-7hxc/GHSA-325v-9p4r-7hxc.json index 44bd09ad07c..a61dfb632e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-325v-9p4r-7hxc/GHSA-325v-9p4r-7hxc.json +++ b/advisories/unreviewed/2022/05/GHSA-325v-9p4r-7hxc/GHSA-325v-9p4r-7hxc.json @@ -7,12 +7,8 @@ "CVE-2020-2692" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-32pg-9428-4x59/GHSA-32pg-9428-4x59.json b/advisories/unreviewed/2022/05/GHSA-32pg-9428-4x59/GHSA-32pg-9428-4x59.json index 6cd8f3e45ff..c80b7574dc8 100644 --- a/advisories/unreviewed/2022/05/GHSA-32pg-9428-4x59/GHSA-32pg-9428-4x59.json +++ b/advisories/unreviewed/2022/05/GHSA-32pg-9428-4x59/GHSA-32pg-9428-4x59.json @@ -7,12 +7,8 @@ "CVE-2019-20440" ], "details": "An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the update API documentation feature of the API Publisher.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3334-49c6-xvm9/GHSA-3334-49c6-xvm9.json b/advisories/unreviewed/2022/05/GHSA-3334-49c6-xvm9/GHSA-3334-49c6-xvm9.json index e1d185191ae..54bb93d3d7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3334-49c6-xvm9/GHSA-3334-49c6-xvm9.json +++ b/advisories/unreviewed/2022/05/GHSA-3334-49c6-xvm9/GHSA-3334-49c6-xvm9.json @@ -7,12 +7,8 @@ "CVE-2020-0644" ], "details": "An elevation of privilege vulnerability exists when Microsoft Windows implements predictable memory section names, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0635.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3368-9xhx-67cc/GHSA-3368-9xhx-67cc.json b/advisories/unreviewed/2022/05/GHSA-3368-9xhx-67cc/GHSA-3368-9xhx-67cc.json index e442ac82f59..eb03b5c42a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-3368-9xhx-67cc/GHSA-3368-9xhx-67cc.json +++ b/advisories/unreviewed/2022/05/GHSA-3368-9xhx-67cc/GHSA-3368-9xhx-67cc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-342r-hgrw-rv65/GHSA-342r-hgrw-rv65.json b/advisories/unreviewed/2022/05/GHSA-342r-hgrw-rv65/GHSA-342r-hgrw-rv65.json index a8c752251ee..e2d83696cda 100644 --- a/advisories/unreviewed/2022/05/GHSA-342r-hgrw-rv65/GHSA-342r-hgrw-rv65.json +++ b/advisories/unreviewed/2022/05/GHSA-342r-hgrw-rv65/GHSA-342r-hgrw-rv65.json @@ -7,12 +7,8 @@ "CVE-2016-4761" ], "details": "WebKitGTK+ before 2.14.0: A use-after-free vulnerability can allow remote attackers to cause a DoS", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3478-j759-vphx/GHSA-3478-j759-vphx.json b/advisories/unreviewed/2022/05/GHSA-3478-j759-vphx/GHSA-3478-j759-vphx.json index bdadca2a457..6c4f5323fe5 100644 --- a/advisories/unreviewed/2022/05/GHSA-3478-j759-vphx/GHSA-3478-j759-vphx.json +++ b/advisories/unreviewed/2022/05/GHSA-3478-j759-vphx/GHSA-3478-j759-vphx.json @@ -7,12 +7,8 @@ "CVE-2020-6959" ], "details": "The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch are vulnerable to an unsafe deserialization of untrusted data. An attacker may be able to remotely modify deserialized data without authentication using a specially crafted web request, resulting in remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-34wr-xg9w-2vh7/GHSA-34wr-xg9w-2vh7.json b/advisories/unreviewed/2022/05/GHSA-34wr-xg9w-2vh7/GHSA-34wr-xg9w-2vh7.json index e40d0151797..735f07a10f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-34wr-xg9w-2vh7/GHSA-34wr-xg9w-2vh7.json +++ b/advisories/unreviewed/2022/05/GHSA-34wr-xg9w-2vh7/GHSA-34wr-xg9w-2vh7.json @@ -7,12 +7,8 @@ "CVE-2019-5147" ], "details": "An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13003.1007. A specially crafted pixel shader can cause a denial of service. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-35rc-qr7q-j9jm/GHSA-35rc-qr7q-j9jm.json b/advisories/unreviewed/2022/05/GHSA-35rc-qr7q-j9jm/GHSA-35rc-qr7q-j9jm.json index b5557957940..f093bfbe274 100644 --- a/advisories/unreviewed/2022/05/GHSA-35rc-qr7q-j9jm/GHSA-35rc-qr7q-j9jm.json +++ b/advisories/unreviewed/2022/05/GHSA-35rc-qr7q-j9jm/GHSA-35rc-qr7q-j9jm.json @@ -7,12 +7,8 @@ "CVE-2019-10582" ], "details": "Use after free issue due to using of invalidated iterator to delete an object in sensors HAL in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8096AU, MSM8909W, Nicobar, QCS605, SA6155P, SDA845, SDM429W, SDM670, SDM710, SDM845, SM6150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-364v-6cqv-3xhx/GHSA-364v-6cqv-3xhx.json b/advisories/unreviewed/2022/05/GHSA-364v-6cqv-3xhx/GHSA-364v-6cqv-3xhx.json index 4fdbf648482..0a5e9ecf182 100644 --- a/advisories/unreviewed/2022/05/GHSA-364v-6cqv-3xhx/GHSA-364v-6cqv-3xhx.json +++ b/advisories/unreviewed/2022/05/GHSA-364v-6cqv-3xhx/GHSA-364v-6cqv-3xhx.json @@ -7,12 +7,8 @@ "CVE-2019-16015" ], "details": "A vulnerability in the web-based management interface of the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information on the affected system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-364x-r3f5-mp8c/GHSA-364x-r3f5-mp8c.json b/advisories/unreviewed/2022/05/GHSA-364x-r3f5-mp8c/GHSA-364x-r3f5-mp8c.json index 1548839ccea..6757990a591 100644 --- a/advisories/unreviewed/2022/05/GHSA-364x-r3f5-mp8c/GHSA-364x-r3f5-mp8c.json +++ b/advisories/unreviewed/2022/05/GHSA-364x-r3f5-mp8c/GHSA-364x-r3f5-mp8c.json @@ -7,12 +7,8 @@ "CVE-2019-14596" ], "details": "Improper access control in the installer for Intel(R) Chipset Device Software INF Utility before version 10.1.18 may allow an authenticated user to potentially enable denial of service via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-36xm-w97x-vmwh/GHSA-36xm-w97x-vmwh.json b/advisories/unreviewed/2022/05/GHSA-36xm-w97x-vmwh/GHSA-36xm-w97x-vmwh.json index b5fb136181e..f9dd4292f4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-36xm-w97x-vmwh/GHSA-36xm-w97x-vmwh.json +++ b/advisories/unreviewed/2022/05/GHSA-36xm-w97x-vmwh/GHSA-36xm-w97x-vmwh.json @@ -7,12 +7,8 @@ "CVE-2020-6965" ], "details": "In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, a vulnerability in the software update mechanism allows an authenticated attacker to upload arbitrary files on the system through a crafted update package.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-37jw-xgjq-3fmq/GHSA-37jw-xgjq-3fmq.json b/advisories/unreviewed/2022/05/GHSA-37jw-xgjq-3fmq/GHSA-37jw-xgjq-3fmq.json index f07ad23ad20..0d0a248e83b 100644 --- a/advisories/unreviewed/2022/05/GHSA-37jw-xgjq-3fmq/GHSA-37jw-xgjq-3fmq.json +++ b/advisories/unreviewed/2022/05/GHSA-37jw-xgjq-3fmq/GHSA-37jw-xgjq-3fmq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37xh-5x9q-v357/GHSA-37xh-5x9q-v357.json b/advisories/unreviewed/2022/05/GHSA-37xh-5x9q-v357/GHSA-37xh-5x9q-v357.json index b66559981af..7a4ef7a172d 100644 --- a/advisories/unreviewed/2022/05/GHSA-37xh-5x9q-v357/GHSA-37xh-5x9q-v357.json +++ b/advisories/unreviewed/2022/05/GHSA-37xh-5x9q-v357/GHSA-37xh-5x9q-v357.json @@ -7,12 +7,8 @@ "CVE-2019-20443" ], "details": "An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in mediaType has been identified in the registry UI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3848-jq8g-9mvf/GHSA-3848-jq8g-9mvf.json b/advisories/unreviewed/2022/05/GHSA-3848-jq8g-9mvf/GHSA-3848-jq8g-9mvf.json index a9edf3eb053..48c83b8e0c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-3848-jq8g-9mvf/GHSA-3848-jq8g-9mvf.json +++ b/advisories/unreviewed/2022/05/GHSA-3848-jq8g-9mvf/GHSA-3848-jq8g-9mvf.json @@ -7,12 +7,8 @@ "CVE-2019-19339" ], "details": "It was found that the Red Hat Enterprise Linux 8 kpatch update did not include the complete fix for CVE-2018-12207. A flaw was found in the way Intel CPUs handle inconsistency between, virtual to physical memory address translations in CPU's local cache and system software's Paging structure entries. A privileged guest user may use this flaw to induce a hardware Machine Check Error on the host processor, resulting in a severe DoS scenario by halting the processor. System software like OS OR Virtual Machine Monitor (VMM) use virtual memory system for storing program instructions and data in memory. Virtual Memory system uses Paging structures like Page Tables and Page Directories to manage system memory. The processor's Memory Management Unit (MMU) uses Paging structure entries to translate program's virtual memory addresses to physical memory addresses. The processor stores these address translations into its local cache buffer called - Translation Lookaside Buffer (TLB). TLB has two parts, one for instructions and other for data addresses. System software can modify its Paging structure entries to change address mappings OR certain attributes like page size etc. Upon such Paging structure alterations in memory, system software must invalidate the corresponding address translations in the processor's TLB cache. But before this TLB invalidation takes place, a privileged guest user may trigger an instruction fetch operation, which could use an already cached, but now invalid, virtual to physical address translation from Instruction TLB (ITLB). Thus accessing an invalid physical memory address and resulting in halting the processor due to the Machine Check Error (MCE) on Page Size Change.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-384c-r8hx-r986/GHSA-384c-r8hx-r986.json b/advisories/unreviewed/2022/05/GHSA-384c-r8hx-r986/GHSA-384c-r8hx-r986.json index b22180b0328..13aaf721f63 100644 --- a/advisories/unreviewed/2022/05/GHSA-384c-r8hx-r986/GHSA-384c-r8hx-r986.json +++ b/advisories/unreviewed/2022/05/GHSA-384c-r8hx-r986/GHSA-384c-r8hx-r986.json @@ -7,12 +7,8 @@ "CVE-2018-17981" ], "details": "Lifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-397r-9xj2-fj79/GHSA-397r-9xj2-fj79.json b/advisories/unreviewed/2022/05/GHSA-397r-9xj2-fj79/GHSA-397r-9xj2-fj79.json index 0bb3dc45926..69b677ccd20 100644 --- a/advisories/unreviewed/2022/05/GHSA-397r-9xj2-fj79/GHSA-397r-9xj2-fj79.json +++ b/advisories/unreviewed/2022/05/GHSA-397r-9xj2-fj79/GHSA-397r-9xj2-fj79.json @@ -7,12 +7,8 @@ "CVE-2019-15582" ], "details": "An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a maintainer to add any private group to a protected environment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-39p8-4c2v-frq6/GHSA-39p8-4c2v-frq6.json b/advisories/unreviewed/2022/05/GHSA-39p8-4c2v-frq6/GHSA-39p8-4c2v-frq6.json index c0a956b5a07..41a1c30205b 100644 --- a/advisories/unreviewed/2022/05/GHSA-39p8-4c2v-frq6/GHSA-39p8-4c2v-frq6.json +++ b/advisories/unreviewed/2022/05/GHSA-39p8-4c2v-frq6/GHSA-39p8-4c2v-frq6.json @@ -7,12 +7,8 @@ "CVE-2020-2573" ], "details": "Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.28 and prior and 8.0.18 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client. CVSS 3.0 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-39q9-mx6r-9h2r/GHSA-39q9-mx6r-9h2r.json b/advisories/unreviewed/2022/05/GHSA-39q9-mx6r-9h2r/GHSA-39q9-mx6r-9h2r.json index 95a00497fa2..ff0ed824962 100644 --- a/advisories/unreviewed/2022/05/GHSA-39q9-mx6r-9h2r/GHSA-39q9-mx6r-9h2r.json +++ b/advisories/unreviewed/2022/05/GHSA-39q9-mx6r-9h2r/GHSA-39q9-mx6r-9h2r.json @@ -7,12 +7,8 @@ "CVE-2020-2517" ], "details": "Vulnerability in the Database Gateway for ODBC component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows high privileged attacker having Create Procedure, Create Database Link privilege with network access via OracleNet to compromise Database Gateway for ODBC. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Database Gateway for ODBC accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Database Gateway for ODBC. CVSS 3.0 Base Score 3.3 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-39xw-g82r-qfvq/GHSA-39xw-g82r-qfvq.json b/advisories/unreviewed/2022/05/GHSA-39xw-g82r-qfvq/GHSA-39xw-g82r-qfvq.json index 213a00af86a..86987afd11d 100644 --- a/advisories/unreviewed/2022/05/GHSA-39xw-g82r-qfvq/GHSA-39xw-g82r-qfvq.json +++ b/advisories/unreviewed/2022/05/GHSA-39xw-g82r-qfvq/GHSA-39xw-g82r-qfvq.json @@ -7,12 +7,8 @@ "CVE-2020-7242" ], "details": "Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Diagnostics Trace Route page and entering shell metacharacters in the Target IP address field. (In some cases, authentication can be achieved with the comtech password for the comtech account.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3f9h-g4f4-pchh/GHSA-3f9h-g4f4-pchh.json b/advisories/unreviewed/2022/05/GHSA-3f9h-g4f4-pchh/GHSA-3f9h-g4f4-pchh.json index 906b37a5d62..1e01f839f6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f9h-g4f4-pchh/GHSA-3f9h-g4f4-pchh.json +++ b/advisories/unreviewed/2022/05/GHSA-3f9h-g4f4-pchh/GHSA-3f9h-g4f4-pchh.json @@ -7,12 +7,8 @@ "CVE-2019-16022" ], "details": "Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due to incorrect processing of BGP update messages that contain crafted EVPN attributes. An attacker could exploit these vulnerabilities by sending BGP EVPN update messages with malformed attributes to be processed by an affected system. A successful exploit could allow the attacker to cause the BGP process to restart unexpectedly, resulting in a DoS condition. The Cisco implementation of BGP accepts incoming BGP traffic only from explicitly defined peers. To exploit these vulnerabilities, the malicious BGP update message would need to come from a configured, valid BGP peer, or would need to be injected by the attacker into the victim's BGP network on an existing, valid TCP connection to a BGP peer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3fq5-c2gj-gmqj/GHSA-3fq5-c2gj-gmqj.json b/advisories/unreviewed/2022/05/GHSA-3fq5-c2gj-gmqj/GHSA-3fq5-c2gj-gmqj.json index b7636fcd625..d638c19f8b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fq5-c2gj-gmqj/GHSA-3fq5-c2gj-gmqj.json +++ b/advisories/unreviewed/2022/05/GHSA-3fq5-c2gj-gmqj/GHSA-3fq5-c2gj-gmqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3fvg-7mc6-3r87/GHSA-3fvg-7mc6-3r87.json b/advisories/unreviewed/2022/05/GHSA-3fvg-7mc6-3r87/GHSA-3fvg-7mc6-3r87.json index ef669ca9baa..11110e74b2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fvg-7mc6-3r87/GHSA-3fvg-7mc6-3r87.json +++ b/advisories/unreviewed/2022/05/GHSA-3fvg-7mc6-3r87/GHSA-3fvg-7mc6-3r87.json @@ -7,12 +7,8 @@ "CVE-2010-5171" ], "details": "** DISPUTED ** Race condition in Outpost Security Suite Pro 6.7.3.3063.452.0726 and 7.0.3330.505.1221 BETA on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3g24-4p5j-c5q8/GHSA-3g24-4p5j-c5q8.json b/advisories/unreviewed/2022/05/GHSA-3g24-4p5j-c5q8/GHSA-3g24-4p5j-c5q8.json index c5c5528aaa6..237890a7ff1 100644 --- a/advisories/unreviewed/2022/05/GHSA-3g24-4p5j-c5q8/GHSA-3g24-4p5j-c5q8.json +++ b/advisories/unreviewed/2022/05/GHSA-3g24-4p5j-c5q8/GHSA-3g24-4p5j-c5q8.json @@ -7,12 +7,8 @@ "CVE-2019-16154" ], "details": "An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3hjp-23xj-gxx4/GHSA-3hjp-23xj-gxx4.json b/advisories/unreviewed/2022/05/GHSA-3hjp-23xj-gxx4/GHSA-3hjp-23xj-gxx4.json index 317350b1978..124407700be 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hjp-23xj-gxx4/GHSA-3hjp-23xj-gxx4.json +++ b/advisories/unreviewed/2022/05/GHSA-3hjp-23xj-gxx4/GHSA-3hjp-23xj-gxx4.json @@ -7,12 +7,8 @@ "CVE-2019-5593" ], "details": "Improper permission or value checking in the CLI console may allow a non-privileged user to obtain Fortinet FortiOS plaint text private keys of system's builtin local certificates via unsetting the keys encryption password in FortiOS 6.2.0, 6.0.0 to 6.0.6, 5.6.10 and below or for user uploaded local certificates via setting an empty password in FortiOS 6.2.1, 6.2.0, 6.0.6 and below.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3hmf-fwjp-fj3m/GHSA-3hmf-fwjp-fj3m.json b/advisories/unreviewed/2022/05/GHSA-3hmf-fwjp-fj3m/GHSA-3hmf-fwjp-fj3m.json index d2d199e3893..201b784043d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hmf-fwjp-fj3m/GHSA-3hmf-fwjp-fj3m.json +++ b/advisories/unreviewed/2022/05/GHSA-3hmf-fwjp-fj3m/GHSA-3hmf-fwjp-fj3m.json @@ -7,12 +7,8 @@ "CVE-2019-14629" ], "details": "Improper permissions in Intel(R) DAAL before version 2020 Gold may allow an authenticated user to potentially enable information disclosure via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jr7-qj32-mq33/GHSA-3jr7-qj32-mq33.json b/advisories/unreviewed/2022/05/GHSA-3jr7-qj32-mq33/GHSA-3jr7-qj32-mq33.json index 9236815dd9a..f7d328db6b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jr7-qj32-mq33/GHSA-3jr7-qj32-mq33.json +++ b/advisories/unreviewed/2022/05/GHSA-3jr7-qj32-mq33/GHSA-3jr7-qj32-mq33.json @@ -7,12 +7,8 @@ "CVE-2019-18652" ], "details": "A DOM based XSS vulnerability has been identified on the WatchGuard XMT515 through 12.1.3, allowing a remote attacker to execute JavaScript in the victim's browser by tricking the victim into clicking on a crafted link. The payload was tested in Microsoft Internet Explorer 11.418.18362.0 and Microsoft Edge 44.18362.387.0 (Microsoft EdgeHTML 18.18362).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3m2c-mhw5-vh5c/GHSA-3m2c-mhw5-vh5c.json b/advisories/unreviewed/2022/05/GHSA-3m2c-mhw5-vh5c/GHSA-3m2c-mhw5-vh5c.json index 0f8a9aeb414..b3c65216c53 100644 --- a/advisories/unreviewed/2022/05/GHSA-3m2c-mhw5-vh5c/GHSA-3m2c-mhw5-vh5c.json +++ b/advisories/unreviewed/2022/05/GHSA-3m2c-mhw5-vh5c/GHSA-3m2c-mhw5-vh5c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mj4-2258-cj4p/GHSA-3mj4-2258-cj4p.json b/advisories/unreviewed/2022/05/GHSA-3mj4-2258-cj4p/GHSA-3mj4-2258-cj4p.json index d9a61049823..1a199cb13e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mj4-2258-cj4p/GHSA-3mj4-2258-cj4p.json +++ b/advisories/unreviewed/2022/05/GHSA-3mj4-2258-cj4p/GHSA-3mj4-2258-cj4p.json @@ -7,12 +7,8 @@ "CVE-2019-10956" ], "details": "Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated user, using a specially crafted URL command, to execute commands as root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3q2r-98pg-wrxg/GHSA-3q2r-98pg-wrxg.json b/advisories/unreviewed/2022/05/GHSA-3q2r-98pg-wrxg/GHSA-3q2r-98pg-wrxg.json index 7464c4db700..347802e7f4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3q2r-98pg-wrxg/GHSA-3q2r-98pg-wrxg.json +++ b/advisories/unreviewed/2022/05/GHSA-3q2r-98pg-wrxg/GHSA-3q2r-98pg-wrxg.json @@ -7,12 +7,8 @@ "CVE-2020-0629" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3q6g-2ch9-q6x7/GHSA-3q6g-2ch9-q6x7.json b/advisories/unreviewed/2022/05/GHSA-3q6g-2ch9-q6x7/GHSA-3q6g-2ch9-q6x7.json index 9c6539451e2..94fe4b47262 100644 --- a/advisories/unreviewed/2022/05/GHSA-3q6g-2ch9-q6x7/GHSA-3q6g-2ch9-q6x7.json +++ b/advisories/unreviewed/2022/05/GHSA-3q6g-2ch9-q6x7/GHSA-3q6g-2ch9-q6x7.json @@ -7,12 +7,8 @@ "CVE-2019-4632" ], "details": "IBM Security Secret Server 10.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170004.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3rjf-4xj2-6g8f/GHSA-3rjf-4xj2-6g8f.json b/advisories/unreviewed/2022/05/GHSA-3rjf-4xj2-6g8f/GHSA-3rjf-4xj2-6g8f.json index e3b581db08a..4576b8f8b69 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rjf-4xj2-6g8f/GHSA-3rjf-4xj2-6g8f.json +++ b/advisories/unreviewed/2022/05/GHSA-3rjf-4xj2-6g8f/GHSA-3rjf-4xj2-6g8f.json @@ -7,12 +7,8 @@ "CVE-2010-5167" ], "details": "** DISPUTED ** Race condition in Norman Security Suite PRO 8.0 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3rjq-9j9w-pxr3/GHSA-3rjq-9j9w-pxr3.json b/advisories/unreviewed/2022/05/GHSA-3rjq-9j9w-pxr3/GHSA-3rjq-9j9w-pxr3.json index 3e203f1cf14..e5c7ff7446e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rjq-9j9w-pxr3/GHSA-3rjq-9j9w-pxr3.json +++ b/advisories/unreviewed/2022/05/GHSA-3rjq-9j9w-pxr3/GHSA-3rjq-9j9w-pxr3.json @@ -7,12 +7,8 @@ "CVE-2019-18271" ], "details": "OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request forgery that may be introduced on the PI Vision administration site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3wvp-p4cg-5fwm/GHSA-3wvp-p4cg-5fwm.json b/advisories/unreviewed/2022/05/GHSA-3wvp-p4cg-5fwm/GHSA-3wvp-p4cg-5fwm.json index c8febce49ee..a9db7a296c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wvp-p4cg-5fwm/GHSA-3wvp-p4cg-5fwm.json +++ b/advisories/unreviewed/2022/05/GHSA-3wvp-p4cg-5fwm/GHSA-3wvp-p4cg-5fwm.json @@ -7,12 +7,8 @@ "CVE-2020-1611" ], "details": "A Local File Inclusion vulnerability in Juniper Networks Junos Space allows an attacker to view all files on the target when the device receives malicious HTTP packets. This issue affects: Juniper Networks Junos Space versions prior to 19.4R1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wwg-cr75-7x49/GHSA-3wwg-cr75-7x49.json b/advisories/unreviewed/2022/05/GHSA-3wwg-cr75-7x49/GHSA-3wwg-cr75-7x49.json index f70b901b953..f2cb2f0e45c 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wwg-cr75-7x49/GHSA-3wwg-cr75-7x49.json +++ b/advisories/unreviewed/2022/05/GHSA-3wwg-cr75-7x49/GHSA-3wwg-cr75-7x49.json @@ -7,12 +7,8 @@ "CVE-2019-16514" ], "details": "An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remote code execution. Administrative users could upload an unsigned extension ZIP file containing executable code that is subsequently executed by the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3xgx-wrc3-hjjj/GHSA-3xgx-wrc3-hjjj.json b/advisories/unreviewed/2022/05/GHSA-3xgx-wrc3-hjjj/GHSA-3xgx-wrc3-hjjj.json index af94685c916..1029786d655 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xgx-wrc3-hjjj/GHSA-3xgx-wrc3-hjjj.json +++ b/advisories/unreviewed/2022/05/GHSA-3xgx-wrc3-hjjj/GHSA-3xgx-wrc3-hjjj.json @@ -7,12 +7,8 @@ "CVE-2019-4635" ], "details": "IBM Security Secret Server 10.7 could allow a privileged user to perform unauthorized command injection due to imporoper input neutralization of special elements. IBM X-Force ID: 170011.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3xv5-p2rf-qvm6/GHSA-3xv5-p2rf-qvm6.json b/advisories/unreviewed/2022/05/GHSA-3xv5-p2rf-qvm6/GHSA-3xv5-p2rf-qvm6.json index 4b5066d8ab8..1bd43151178 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xv5-p2rf-qvm6/GHSA-3xv5-p2rf-qvm6.json +++ b/advisories/unreviewed/2022/05/GHSA-3xv5-p2rf-qvm6/GHSA-3xv5-p2rf-qvm6.json @@ -7,12 +7,8 @@ "CVE-2019-20442" ], "details": "An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in roleToAuthorize has been identified in the registry UI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3xw6-3pf3-2m73/GHSA-3xw6-3pf3-2m73.json b/advisories/unreviewed/2022/05/GHSA-3xw6-3pf3-2m73/GHSA-3xw6-3pf3-2m73.json index 503fc03d031..8d96054dd41 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xw6-3pf3-2m73/GHSA-3xw6-3pf3-2m73.json +++ b/advisories/unreviewed/2022/05/GHSA-3xw6-3pf3-2m73/GHSA-3xw6-3pf3-2m73.json @@ -7,12 +7,8 @@ "CVE-2019-14768" ], "details": "An Arbitrary File Upload issue in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to deploy a new WebApp WAR file to the Tomcat server via Path Traversal, allowing remote code execution with SYSTEM privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4352-v8x5-w2w2/GHSA-4352-v8x5-w2w2.json b/advisories/unreviewed/2022/05/GHSA-4352-v8x5-w2w2/GHSA-4352-v8x5-w2w2.json index 3e96c35f764..981d3bbeb10 100644 --- a/advisories/unreviewed/2022/05/GHSA-4352-v8x5-w2w2/GHSA-4352-v8x5-w2w2.json +++ b/advisories/unreviewed/2022/05/GHSA-4352-v8x5-w2w2/GHSA-4352-v8x5-w2w2.json @@ -7,12 +7,8 @@ "CVE-2020-0623" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44m4-f6m7-fx62/GHSA-44m4-f6m7-fx62.json b/advisories/unreviewed/2022/05/GHSA-44m4-f6m7-fx62/GHSA-44m4-f6m7-fx62.json index e4ba92c85cf..5d962fd0f71 100644 --- a/advisories/unreviewed/2022/05/GHSA-44m4-f6m7-fx62/GHSA-44m4-f6m7-fx62.json +++ b/advisories/unreviewed/2022/05/GHSA-44m4-f6m7-fx62/GHSA-44m4-f6m7-fx62.json @@ -7,12 +7,8 @@ "CVE-2019-16024" ], "details": "A vulnerability in the web-based management interface of Cisco Crosswork Change Automation could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4534-m3xx-hqqj/GHSA-4534-m3xx-hqqj.json b/advisories/unreviewed/2022/05/GHSA-4534-m3xx-hqqj/GHSA-4534-m3xx-hqqj.json index 172f1238dd6..43c178e4680 100644 --- a/advisories/unreviewed/2022/05/GHSA-4534-m3xx-hqqj/GHSA-4534-m3xx-hqqj.json +++ b/advisories/unreviewed/2022/05/GHSA-4534-m3xx-hqqj/GHSA-4534-m3xx-hqqj.json @@ -7,12 +7,8 @@ "CVE-2019-16005" ], "details": "A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary commands on the affected system. The vulnerability is due to improper validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by logging in to the web-based management interface with administrative privileges and supplying crafted requests to the application. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux operating system with root privileges on a targeted node.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-454x-hmf4-97vq/GHSA-454x-hmf4-97vq.json b/advisories/unreviewed/2022/05/GHSA-454x-hmf4-97vq/GHSA-454x-hmf4-97vq.json index a3ab2248644..b9ea5662342 100644 --- a/advisories/unreviewed/2022/05/GHSA-454x-hmf4-97vq/GHSA-454x-hmf4-97vq.json +++ b/advisories/unreviewed/2022/05/GHSA-454x-hmf4-97vq/GHSA-454x-hmf4-97vq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4573-64w5-5533/GHSA-4573-64w5-5533.json b/advisories/unreviewed/2022/05/GHSA-4573-64w5-5533/GHSA-4573-64w5-5533.json index 97133394a98..534d685f580 100644 --- a/advisories/unreviewed/2022/05/GHSA-4573-64w5-5533/GHSA-4573-64w5-5533.json +++ b/advisories/unreviewed/2022/05/GHSA-4573-64w5-5533/GHSA-4573-64w5-5533.json @@ -7,12 +7,8 @@ "CVE-2019-4707" ], "details": "IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172018.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-45j8-89gg-rc22/GHSA-45j8-89gg-rc22.json b/advisories/unreviewed/2022/05/GHSA-45j8-89gg-rc22/GHSA-45j8-89gg-rc22.json index 8eee850d48b..fa9f8ae427d 100644 --- a/advisories/unreviewed/2022/05/GHSA-45j8-89gg-rc22/GHSA-45j8-89gg-rc22.json +++ b/advisories/unreviewed/2022/05/GHSA-45j8-89gg-rc22/GHSA-45j8-89gg-rc22.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-484w-vg65-78pg/GHSA-484w-vg65-78pg.json b/advisories/unreviewed/2022/05/GHSA-484w-vg65-78pg/GHSA-484w-vg65-78pg.json index 5bbed1dd57b..04ce7f39521 100644 --- a/advisories/unreviewed/2022/05/GHSA-484w-vg65-78pg/GHSA-484w-vg65-78pg.json +++ b/advisories/unreviewed/2022/05/GHSA-484w-vg65-78pg/GHSA-484w-vg65-78pg.json @@ -7,12 +7,8 @@ "CVE-2015-0242" ], "details": "Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on a Windows system, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a floating point number with a large precision, as demonstrated by using the to_char function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-48w4-6959-hj9h/GHSA-48w4-6959-hj9h.json b/advisories/unreviewed/2022/05/GHSA-48w4-6959-hj9h/GHSA-48w4-6959-hj9h.json index bbb46e42049..322a08acb1e 100644 --- a/advisories/unreviewed/2022/05/GHSA-48w4-6959-hj9h/GHSA-48w4-6959-hj9h.json +++ b/advisories/unreviewed/2022/05/GHSA-48w4-6959-hj9h/GHSA-48w4-6959-hj9h.json @@ -7,12 +7,8 @@ "CVE-2010-5150" ], "details": "** DISPUTED ** Race condition in 3D EQSecure Professional Edition 4.2 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-49j8-c4pr-24h9/GHSA-49j8-c4pr-24h9.json b/advisories/unreviewed/2022/05/GHSA-49j8-c4pr-24h9/GHSA-49j8-c4pr-24h9.json index 7e588c48d91..e30992f3c6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-49j8-c4pr-24h9/GHSA-49j8-c4pr-24h9.json +++ b/advisories/unreviewed/2022/05/GHSA-49j8-c4pr-24h9/GHSA-49j8-c4pr-24h9.json @@ -7,12 +7,8 @@ "CVE-2010-5169" ], "details": "** DISPUTED ** Race condition in Online Armor Premium 4.0.0.35 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-49wp-pqpg-rf2j/GHSA-49wp-pqpg-rf2j.json b/advisories/unreviewed/2022/05/GHSA-49wp-pqpg-rf2j/GHSA-49wp-pqpg-rf2j.json index 95d513ad794..7b88cb3921f 100644 --- a/advisories/unreviewed/2022/05/GHSA-49wp-pqpg-rf2j/GHSA-49wp-pqpg-rf2j.json +++ b/advisories/unreviewed/2022/05/GHSA-49wp-pqpg-rf2j/GHSA-49wp-pqpg-rf2j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4c7q-44j3-76m6/GHSA-4c7q-44j3-76m6.json b/advisories/unreviewed/2022/05/GHSA-4c7q-44j3-76m6/GHSA-4c7q-44j3-76m6.json index 0685970ca87..912656b056f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c7q-44j3-76m6/GHSA-4c7q-44j3-76m6.json +++ b/advisories/unreviewed/2022/05/GHSA-4c7q-44j3-76m6/GHSA-4c7q-44j3-76m6.json @@ -7,12 +7,8 @@ "CVE-2015-0243" ], "details": "Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4ffp-5mr6-fv6x/GHSA-4ffp-5mr6-fv6x.json b/advisories/unreviewed/2022/05/GHSA-4ffp-5mr6-fv6x/GHSA-4ffp-5mr6-fv6x.json index 12c25b8b071..033e0cc125e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4ffp-5mr6-fv6x/GHSA-4ffp-5mr6-fv6x.json +++ b/advisories/unreviewed/2022/05/GHSA-4ffp-5mr6-fv6x/GHSA-4ffp-5mr6-fv6x.json @@ -7,12 +7,8 @@ "CVE-2014-7042" ], "details": "** DISPUTED ** The My nTelos (aka com.telespree.ntelospostpay) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. NOTE: nTelos Wireless has indicated that this vulnerability report is incorrect.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4fpp-pg83-3r3h/GHSA-4fpp-pg83-3r3h.json b/advisories/unreviewed/2022/05/GHSA-4fpp-pg83-3r3h/GHSA-4fpp-pg83-3r3h.json index 2273a60d842..5cbe6326202 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fpp-pg83-3r3h/GHSA-4fpp-pg83-3r3h.json +++ b/advisories/unreviewed/2022/05/GHSA-4fpp-pg83-3r3h/GHSA-4fpp-pg83-3r3h.json @@ -7,12 +7,8 @@ "CVE-2019-10581" ], "details": "NULL is assigned to local instance of audio device pointer after free instead of global static pointer and can lead to use after free issue in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8053, MDM9206, MDM9207C, MDM9607, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8998, Nicobar, QCS605, Rennell, SA6155P, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4fq8-gf9c-7p2w/GHSA-4fq8-gf9c-7p2w.json b/advisories/unreviewed/2022/05/GHSA-4fq8-gf9c-7p2w/GHSA-4fq8-gf9c-7p2w.json index 053facec048..571a3ae7f34 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fq8-gf9c-7p2w/GHSA-4fq8-gf9c-7p2w.json +++ b/advisories/unreviewed/2022/05/GHSA-4fq8-gf9c-7p2w/GHSA-4fq8-gf9c-7p2w.json @@ -7,12 +7,8 @@ "CVE-2013-4732" ], "details": "** DISPUTED ** The administrative web server on the Digital Alert Systems DASDEC EAS device through 2.0-2 and the Monroe Electronics R189 One-Net EAS device through 2.0-2 uses predictable session ID values, which makes it easier for remote attackers to hijack sessions by sniffing the network. NOTE: VU#662676 states \"Monroe Electronics could not reproduce this finding.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4frx-4mrc-562x/GHSA-4frx-4mrc-562x.json b/advisories/unreviewed/2022/05/GHSA-4frx-4mrc-562x/GHSA-4frx-4mrc-562x.json index ba7e8eabef9..b3cd701cd5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4frx-4mrc-562x/GHSA-4frx-4mrc-562x.json +++ b/advisories/unreviewed/2022/05/GHSA-4frx-4mrc-562x/GHSA-4frx-4mrc-562x.json @@ -7,12 +7,8 @@ "CVE-2020-1602" ], "details": "When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv4 packets who may remotely take over the code execution of the JDHDCP process. This issue affect IPv4 JDHCPD services. This issue affects: Juniper Networks Junos OS: 15.1 versions prior to 15.1R7-S6; 15.1X49 versions prior to 15.1X49-D200; 15.1X53 versions prior to 15.1X53-D592; 16.1 versions prior to 16.1R7-S6; 16.2 versions prior to 16.2R2-S11; 17.1 versions prior to 17.1R2-S11, 17.1R3-S1; 17.2 versions prior to 17.2R2-S8, 17.2R3-S3; 17.3 versions prior to 17.3R3-S6; 17.4 versions prior to 17.4R2-S7, 17.4R3; 18.1 versions prior to 18.1R3-S8; 18.2 versions prior to 18.2R3-S2; 18.2X75 versions prior to 18.2X75-D60; 18.3 versions prior to 18.3R1-S6, 18.3R2-S2, 18.3R3; 18.4 versions prior to 18.4R1-S5, 18.4R2-S3, 18.4R3; 19.1 versions prior to 19.1R1-S3, 19.1R2; 19.2 versions prior to 19.2R1-S3, 19.2R2*. and All versions prior to 19.3R1 on Junos OS Evolved. This issue do not affect versions of Junos OS prior to 15.1, or JDHCPD operating as a local server in non-relay mode.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4g2j-mrxv-xf4j/GHSA-4g2j-mrxv-xf4j.json b/advisories/unreviewed/2022/05/GHSA-4g2j-mrxv-xf4j/GHSA-4g2j-mrxv-xf4j.json index 61c6140d4c3..8da6be51dfd 100644 --- a/advisories/unreviewed/2022/05/GHSA-4g2j-mrxv-xf4j/GHSA-4g2j-mrxv-xf4j.json +++ b/advisories/unreviewed/2022/05/GHSA-4g2j-mrxv-xf4j/GHSA-4g2j-mrxv-xf4j.json @@ -7,12 +7,8 @@ "CVE-2020-2674" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4g9j-24m6-cjw4/GHSA-4g9j-24m6-cjw4.json b/advisories/unreviewed/2022/05/GHSA-4g9j-24m6-cjw4/GHSA-4g9j-24m6-cjw4.json index 5d21b5663b7..68c90a4e914 100644 --- a/advisories/unreviewed/2022/05/GHSA-4g9j-24m6-cjw4/GHSA-4g9j-24m6-cjw4.json +++ b/advisories/unreviewed/2022/05/GHSA-4g9j-24m6-cjw4/GHSA-4g9j-24m6-cjw4.json @@ -7,12 +7,8 @@ "CVE-2020-5204" ], "details": "In uftpd before 2.11, there is a buffer overflow vulnerability in handle_PORT in ftpcmd.c that is caused by a buffer that is 16 bytes large being filled via sprintf() with user input based on the format specifier string %d.%d.%d.%d. The 16 byte size is correct for valid IPv4 addresses (len('255.255.255.255') == 16), but the format specifier %d allows more than 3 digits. This has been fixed in version 2.11", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "WEB", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4grq-6mg5-mcqf/GHSA-4grq-6mg5-mcqf.json b/advisories/unreviewed/2022/05/GHSA-4grq-6mg5-mcqf/GHSA-4grq-6mg5-mcqf.json index c0b59a5e5ac..cf36b2f38d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4grq-6mg5-mcqf/GHSA-4grq-6mg5-mcqf.json +++ b/advisories/unreviewed/2022/05/GHSA-4grq-6mg5-mcqf/GHSA-4grq-6mg5-mcqf.json @@ -7,12 +7,8 @@ "CVE-2020-0612" ], "details": "A denial of service vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4h9h-37ch-jq2m/GHSA-4h9h-37ch-jq2m.json b/advisories/unreviewed/2022/05/GHSA-4h9h-37ch-jq2m/GHSA-4h9h-37ch-jq2m.json index 1e50f532ba1..cdcbadac179 100644 --- a/advisories/unreviewed/2022/05/GHSA-4h9h-37ch-jq2m/GHSA-4h9h-37ch-jq2m.json +++ b/advisories/unreviewed/2022/05/GHSA-4h9h-37ch-jq2m/GHSA-4h9h-37ch-jq2m.json @@ -7,12 +7,8 @@ "CVE-2016-6588" ], "details": "A Cross-Site Scripting (XSS) vulnerability exists in the ITMS workflow process manager console in Symantec IT Management Suite 8.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4hfv-698v-c974/GHSA-4hfv-698v-c974.json b/advisories/unreviewed/2022/05/GHSA-4hfv-698v-c974/GHSA-4hfv-698v-c974.json index 3231871a68c..97b9ce1b5c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hfv-698v-c974/GHSA-4hfv-698v-c974.json +++ b/advisories/unreviewed/2022/05/GHSA-4hfv-698v-c974/GHSA-4hfv-698v-c974.json @@ -7,12 +7,8 @@ "CVE-2019-15012" ], "details": "Bitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from version 6.7.0 before 6.7.3, from version 6.8.0 before 6.8.2, from version 6.9.0 before 6.9.1 had a Remote Code Execution vulnerability via the edit-file request. A remote attacker with write permission on a repository can write to any arbitrary file to the victims Bitbucket Server or Bitbucket Data Center instance using the edit-file endpoint, if the user has Bitbucket Server or Bitbucket Data Center running, and has the permission to write the file at that destination. In some cases, this can result in execution of arbitrary code by the victims Bitbucket Server or Bitbucket Data Center instance.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4j9x-m99x-9xm4/GHSA-4j9x-m99x-9xm4.json b/advisories/unreviewed/2022/05/GHSA-4j9x-m99x-9xm4/GHSA-4j9x-m99x-9xm4.json index 5f15b9d62cd..65ef6cf0175 100644 --- a/advisories/unreviewed/2022/05/GHSA-4j9x-m99x-9xm4/GHSA-4j9x-m99x-9xm4.json +++ b/advisories/unreviewed/2022/05/GHSA-4j9x-m99x-9xm4/GHSA-4j9x-m99x-9xm4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4jwq-xq2h-426q/GHSA-4jwq-xq2h-426q.json b/advisories/unreviewed/2022/05/GHSA-4jwq-xq2h-426q/GHSA-4jwq-xq2h-426q.json index d8e495a6b82..734744292cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jwq-xq2h-426q/GHSA-4jwq-xq2h-426q.json +++ b/advisories/unreviewed/2022/05/GHSA-4jwq-xq2h-426q/GHSA-4jwq-xq2h-426q.json @@ -7,12 +7,8 @@ "CVE-2018-16269" ], "details": "The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to improper D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4mgh-wqj7-785j/GHSA-4mgh-wqj7-785j.json b/advisories/unreviewed/2022/05/GHSA-4mgh-wqj7-785j/GHSA-4mgh-wqj7-785j.json index 716c1ba176c..8f0c66a8c54 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mgh-wqj7-785j/GHSA-4mgh-wqj7-785j.json +++ b/advisories/unreviewed/2022/05/GHSA-4mgh-wqj7-785j/GHSA-4mgh-wqj7-785j.json @@ -7,12 +7,8 @@ "CVE-2020-0627" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4mgp-5jjf-m73q/GHSA-4mgp-5jjf-m73q.json b/advisories/unreviewed/2022/05/GHSA-4mgp-5jjf-m73q/GHSA-4mgp-5jjf-m73q.json index d26e91c1d09..03a9bc28c49 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mgp-5jjf-m73q/GHSA-4mgp-5jjf-m73q.json +++ b/advisories/unreviewed/2022/05/GHSA-4mgp-5jjf-m73q/GHSA-4mgp-5jjf-m73q.json @@ -7,12 +7,8 @@ "CVE-2020-8009" ], "details": "AVB MOTU devices through 2020-01-22 allow /.. Directory Traversal, as demonstrated by reading the /etc/passwd file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4mj3-qm89-4qgh/GHSA-4mj3-qm89-4qgh.json b/advisories/unreviewed/2022/05/GHSA-4mj3-qm89-4qgh/GHSA-4mj3-qm89-4qgh.json index ba3f2b58eaa..a96c6fe27bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mj3-qm89-4qgh/GHSA-4mj3-qm89-4qgh.json +++ b/advisories/unreviewed/2022/05/GHSA-4mj3-qm89-4qgh/GHSA-4mj3-qm89-4qgh.json @@ -7,12 +7,8 @@ "CVE-2020-1603" ], "details": "Specific IPv6 packets sent by clients processed by the Routing Engine (RE) are improperly handled. These IPv6 packets are designed to be blocked by the RE from egressing the RE. Instead, the RE allows these specific IPv6 packets to egress the RE, at which point a mbuf memory leak occurs within the Juniper Networks Junos OS device. This memory leak eventually leads to a kernel crash (vmcore), or the device hanging and requiring a power cycle to restore service, creating a Denial of Service (DoS) condition. During the time where mbufs are rising, yet not fully filled, some traffic from client devices may begin to be black holed. To be black holed, this traffic must match the condition where this traffic must be processed by the RE. Continued receipt and attempted egress of these specific IPv6 packets from the Routing Engine (RE) will create an extended Denial of Service (DoS) condition. Scenarios which have been observed are: 1. In a single chassis, single RE scenario, the device will hang without vmcore, or a vmcore may occur and then hang. In this scenario the device needs to be power cycled. 2. In a single chassis, dual RE scenario, the device master RE will fail over to the backup RE. In this scenario, the master and the backup REs need to be reset from time to time when they vmcore. There is no need to power cycle the device. 3. In a dual chassis, single RE scenario, the device will hang without vmcore, or a vmcore may occur and then hang. In this scenario, the two chassis' design relies upon some type of network level redundancy - VRRP, GRES, NSR, etc. - 3.a In a commanded switchover, where nonstop active routing (NSR) is enabled no session loss is observed. 4. In a dual chassis, dual chassis scenario, rely upon the RE to RE failover as stated in the second scenario. In the unlikely event that the device does not switch RE to RE gracefully, then the fallback position is to the network level services scenario in the third scenario. This issue affects: Juniper Networks Junos OS 16.1 versions prior to 16.1R7-S6; 16.1 version 16.1X70-D10 and later; 16.2 versions prior to 16.2R2-S11; 17.1 versions prior to 17.1R2-S11, 17.1R3-S1; 17.2 versions prior to 17.2R1-S9, 17.2R2-S8, 17.2R3-S3; 17.3 versions prior to 17.3R3-S6; 17.4 versions prior to 17.4R2-S9, 17.4R3; 18.1 versions prior to 18.1R3-S7; 18.2 versions prior to 18.2R3-S2; 18.2X75 versions prior to 18.2X75-D50, 18.2X75-D410; 18.3 versions prior to 18.3R1-S6, 18.3R2-S2, 18.3R3; 18.4 versions prior to 18.4R1-S6, 18.4R2-S2, 18.4R3; 19.1 versions prior to 19.1R1-S3, 19.1R2; 19.2 versions prior to 19.2R1-S2, 19.2R2. This issue does not affect releases prior to Junos OS 16.1R1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4qpq-v2q4-wj9r/GHSA-4qpq-v2q4-wj9r.json b/advisories/unreviewed/2022/05/GHSA-4qpq-v2q4-wj9r/GHSA-4qpq-v2q4-wj9r.json index bc7a7bf6daf..25886c0c32a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qpq-v2q4-wj9r/GHSA-4qpq-v2q4-wj9r.json +++ b/advisories/unreviewed/2022/05/GHSA-4qpq-v2q4-wj9r/GHSA-4qpq-v2q4-wj9r.json @@ -7,12 +7,8 @@ "CVE-2019-5647" ], "details": "The Chrome Plugin for Rapid7 AppSpider can incorrectly keep browser sessions active after recording a macro, even after a restart of the Chrome browser. This behavior could make future session hijacking attempts easier, since the user could believe a session was closed when it was not. This issue affects Rapid7 AppSpider version 3.8.213 and prior versions, and is fixed in version 3.8.215.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4qqm-9p8q-xcfc/GHSA-4qqm-9p8q-xcfc.json b/advisories/unreviewed/2022/05/GHSA-4qqm-9p8q-xcfc/GHSA-4qqm-9p8q-xcfc.json index bbd98aeb69f..8bc3672882d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qqm-9p8q-xcfc/GHSA-4qqm-9p8q-xcfc.json +++ b/advisories/unreviewed/2022/05/GHSA-4qqm-9p8q-xcfc/GHSA-4qqm-9p8q-xcfc.json @@ -7,12 +7,8 @@ "CVE-2020-0617" ], "details": "A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Hyper-V Denial of Service Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4rxf-wvxr-7wq8/GHSA-4rxf-wvxr-7wq8.json b/advisories/unreviewed/2022/05/GHSA-4rxf-wvxr-7wq8/GHSA-4rxf-wvxr-7wq8.json index 6e1846ed334..de13f642b8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rxf-wvxr-7wq8/GHSA-4rxf-wvxr-7wq8.json +++ b/advisories/unreviewed/2022/05/GHSA-4rxf-wvxr-7wq8/GHSA-4rxf-wvxr-7wq8.json @@ -7,12 +7,8 @@ "CVE-2019-19897" ], "details": "In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service. An unauthenticated attacker can communicate with the Agent Service over TCP port 20051, and execute code in the NT AUTHORITY\\SYSTEM context of the target system by using the Execute Command Line function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4v46-g8g9-868m/GHSA-4v46-g8g9-868m.json b/advisories/unreviewed/2022/05/GHSA-4v46-g8g9-868m/GHSA-4v46-g8g9-868m.json index 77764e7a191..23cc1fd9265 100644 --- a/advisories/unreviewed/2022/05/GHSA-4v46-g8g9-868m/GHSA-4v46-g8g9-868m.json +++ b/advisories/unreviewed/2022/05/GHSA-4v46-g8g9-868m/GHSA-4v46-g8g9-868m.json @@ -7,12 +7,8 @@ "CVE-2019-15585" ], "details": "Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vf5-wq63-5f76/GHSA-4vf5-wq63-5f76.json b/advisories/unreviewed/2022/05/GHSA-4vf5-wq63-5f76/GHSA-4vf5-wq63-5f76.json index 577a20d851c..a15836fe9db 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vf5-wq63-5f76/GHSA-4vf5-wq63-5f76.json +++ b/advisories/unreviewed/2022/05/GHSA-4vf5-wq63-5f76/GHSA-4vf5-wq63-5f76.json @@ -7,12 +7,8 @@ "CVE-2019-8946" ], "details": "Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vv9-mmpc-qhcm/GHSA-4vv9-mmpc-qhcm.json b/advisories/unreviewed/2022/05/GHSA-4vv9-mmpc-qhcm/GHSA-4vv9-mmpc-qhcm.json index 41dfa7d56c1..5debb683ea1 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vv9-mmpc-qhcm/GHSA-4vv9-mmpc-qhcm.json +++ b/advisories/unreviewed/2022/05/GHSA-4vv9-mmpc-qhcm/GHSA-4vv9-mmpc-qhcm.json @@ -7,12 +7,8 @@ "CVE-2017-14807" ], "details": "An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in susestudio-ui-server of SUSE Studio onsite allows remote attackers with admin privileges in Studio to alter SQL statements, allowing for extraction and modification of data. This issue affects: SUSE Studio onsite susestudio-ui-server version 1.3.17-56.6.3 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4w8c-88r4-pgpj/GHSA-4w8c-88r4-pgpj.json b/advisories/unreviewed/2022/05/GHSA-4w8c-88r4-pgpj/GHSA-4w8c-88r4-pgpj.json index 6f1e90c8afa..6652e92faac 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w8c-88r4-pgpj/GHSA-4w8c-88r4-pgpj.json +++ b/advisories/unreviewed/2022/05/GHSA-4w8c-88r4-pgpj/GHSA-4w8c-88r4-pgpj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4wfp-xfpc-fxcp/GHSA-4wfp-xfpc-fxcp.json b/advisories/unreviewed/2022/05/GHSA-4wfp-xfpc-fxcp/GHSA-4wfp-xfpc-fxcp.json index f241564a004..eecd0c1350d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wfp-xfpc-fxcp/GHSA-4wfp-xfpc-fxcp.json +++ b/advisories/unreviewed/2022/05/GHSA-4wfp-xfpc-fxcp/GHSA-4wfp-xfpc-fxcp.json @@ -7,12 +7,8 @@ "CVE-2020-7237" ], "details": "Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php. OS commands are executed when a new poller cycle begins. The attacker must be authenticated, and must have access to modify the Performance Settings of the product.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4wv5-g426-4246/GHSA-4wv5-g426-4246.json b/advisories/unreviewed/2022/05/GHSA-4wv5-g426-4246/GHSA-4wv5-g426-4246.json index 484c23aebe1..cc1f42ab7a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wv5-g426-4246/GHSA-4wv5-g426-4246.json +++ b/advisories/unreviewed/2022/05/GHSA-4wv5-g426-4246/GHSA-4wv5-g426-4246.json @@ -7,12 +7,8 @@ "CVE-2019-17127" ], "details": "A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This can lead to privilege escalation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4x8f-h58h-jh6h/GHSA-4x8f-h58h-jh6h.json b/advisories/unreviewed/2022/05/GHSA-4x8f-h58h-jh6h/GHSA-4x8f-h58h-jh6h.json index 970d4984878..e2ce3dc964c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x8f-h58h-jh6h/GHSA-4x8f-h58h-jh6h.json +++ b/advisories/unreviewed/2022/05/GHSA-4x8f-h58h-jh6h/GHSA-4x8f-h58h-jh6h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4xhr-2rmp-vfjq/GHSA-4xhr-2rmp-vfjq.json b/advisories/unreviewed/2022/05/GHSA-4xhr-2rmp-vfjq/GHSA-4xhr-2rmp-vfjq.json index c5748ca75f7..ad1fdc6b8bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xhr-2rmp-vfjq/GHSA-4xhr-2rmp-vfjq.json +++ b/advisories/unreviewed/2022/05/GHSA-4xhr-2rmp-vfjq/GHSA-4xhr-2rmp-vfjq.json @@ -7,12 +7,8 @@ "CVE-2012-2213" ], "details": "** DISPUTED ** Squid 3.1.9 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reproducible, because the researcher is unable to provide a squid.conf file for a vulnerable system, and the observed behavior is consistent with a squid.conf file that was (perhaps inadvertently) designed to allow access based on a \"req_header Host\" acl regex that matches www.uol.com.br.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-52v5-4c5v-67f2/GHSA-52v5-4c5v-67f2.json b/advisories/unreviewed/2022/05/GHSA-52v5-4c5v-67f2/GHSA-52v5-4c5v-67f2.json index 6e5e15eaf29..40db4c5267d 100644 --- a/advisories/unreviewed/2022/05/GHSA-52v5-4c5v-67f2/GHSA-52v5-4c5v-67f2.json +++ b/advisories/unreviewed/2022/05/GHSA-52v5-4c5v-67f2/GHSA-52v5-4c5v-67f2.json @@ -7,12 +7,8 @@ "CVE-2019-10585" ], "details": "Possible integer overflow happens when mmap find function will increment refcount every time when it invokes and can lead to use after free issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8009, APQ8053, MDM9607, MDM9640, MSM8909W, MSM8917, MSM8953, Nicobar, QCS605, QM215, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM660, SDM670, SDM710, SDM845, SDX24, SDX55, SM6150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5397-mj74-4gf2/GHSA-5397-mj74-4gf2.json b/advisories/unreviewed/2022/05/GHSA-5397-mj74-4gf2/GHSA-5397-mj74-4gf2.json index e9cadaecad4..c0cf2953a95 100644 --- a/advisories/unreviewed/2022/05/GHSA-5397-mj74-4gf2/GHSA-5397-mj74-4gf2.json +++ b/advisories/unreviewed/2022/05/GHSA-5397-mj74-4gf2/GHSA-5397-mj74-4gf2.json @@ -7,12 +7,8 @@ "CVE-2020-2679" ], "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-53h8-m6rx-722f/GHSA-53h8-m6rx-722f.json b/advisories/unreviewed/2022/05/GHSA-53h8-m6rx-722f/GHSA-53h8-m6rx-722f.json index 7cbbc8cbc77..116c7927627 100644 --- a/advisories/unreviewed/2022/05/GHSA-53h8-m6rx-722f/GHSA-53h8-m6rx-722f.json +++ b/advisories/unreviewed/2022/05/GHSA-53h8-m6rx-722f/GHSA-53h8-m6rx-722f.json @@ -7,12 +7,8 @@ "CVE-2010-5096" ], "details": "** DISPUTED ** Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the keywords parameter in a (1) do_search action to search.php or (2) do_stuff action to private.php. NOTE: the vendor disputes this issue, saying \"Although this doesn't lead to an SQL injection, it does provide a general MyBB SQL error.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53p9-m4mr-wp8x/GHSA-53p9-m4mr-wp8x.json b/advisories/unreviewed/2022/05/GHSA-53p9-m4mr-wp8x/GHSA-53p9-m4mr-wp8x.json index 2ce5fe21fbe..3dc50249ded 100644 --- a/advisories/unreviewed/2022/05/GHSA-53p9-m4mr-wp8x/GHSA-53p9-m4mr-wp8x.json +++ b/advisories/unreviewed/2022/05/GHSA-53p9-m4mr-wp8x/GHSA-53p9-m4mr-wp8x.json @@ -7,12 +7,8 @@ "CVE-2020-0638" ], "details": "An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-542w-9rgx-v3rq/GHSA-542w-9rgx-v3rq.json b/advisories/unreviewed/2022/05/GHSA-542w-9rgx-v3rq/GHSA-542w-9rgx-v3rq.json index cc7924299c6..8de43e4282c 100644 --- a/advisories/unreviewed/2022/05/GHSA-542w-9rgx-v3rq/GHSA-542w-9rgx-v3rq.json +++ b/advisories/unreviewed/2022/05/GHSA-542w-9rgx-v3rq/GHSA-542w-9rgx-v3rq.json @@ -7,12 +7,8 @@ "CVE-2014-5160" ], "details": "** DISPUTED ** Multiple directory traversal vulnerabilities in crs.exe in the Cell Request Service in HP Data Protector allow remote attackers to create arbitrary files via an opcode-1091 request, or create or delete arbitrary files via an opcode-305 request. NOTE: the vendor reportedly asserts that this behavior is \"by design.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-544x-prqp-2fxc/GHSA-544x-prqp-2fxc.json b/advisories/unreviewed/2022/05/GHSA-544x-prqp-2fxc/GHSA-544x-prqp-2fxc.json index f6ba015c658..7eae8c08751 100644 --- a/advisories/unreviewed/2022/05/GHSA-544x-prqp-2fxc/GHSA-544x-prqp-2fxc.json +++ b/advisories/unreviewed/2022/05/GHSA-544x-prqp-2fxc/GHSA-544x-prqp-2fxc.json @@ -7,12 +7,8 @@ "CVE-2019-4637" ], "details": "IBM Security Secret Server 10.7 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 170043.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-552g-mhvj-f64v/GHSA-552g-mhvj-f64v.json b/advisories/unreviewed/2022/05/GHSA-552g-mhvj-f64v/GHSA-552g-mhvj-f64v.json index ab9c565da63..112a1ce2feb 100644 --- a/advisories/unreviewed/2022/05/GHSA-552g-mhvj-f64v/GHSA-552g-mhvj-f64v.json +++ b/advisories/unreviewed/2022/05/GHSA-552g-mhvj-f64v/GHSA-552g-mhvj-f64v.json @@ -7,12 +7,8 @@ "CVE-2019-19822" ], "details": "A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-578r-jv64-7v29/GHSA-578r-jv64-7v29.json b/advisories/unreviewed/2022/05/GHSA-578r-jv64-7v29/GHSA-578r-jv64-7v29.json index e14fa2efd01..870c28174b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-578r-jv64-7v29/GHSA-578r-jv64-7v29.json +++ b/advisories/unreviewed/2022/05/GHSA-578r-jv64-7v29/GHSA-578r-jv64-7v29.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-57mj-9r29-rj3q/GHSA-57mj-9r29-rj3q.json b/advisories/unreviewed/2022/05/GHSA-57mj-9r29-rj3q/GHSA-57mj-9r29-rj3q.json index c418547f763..1c86535561e 100644 --- a/advisories/unreviewed/2022/05/GHSA-57mj-9r29-rj3q/GHSA-57mj-9r29-rj3q.json +++ b/advisories/unreviewed/2022/05/GHSA-57mj-9r29-rj3q/GHSA-57mj-9r29-rj3q.json @@ -7,12 +7,8 @@ "CVE-2019-1354" ], "details": "A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1352, CVE-2019-1387.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-57rv-3w97-433r/GHSA-57rv-3w97-433r.json b/advisories/unreviewed/2022/05/GHSA-57rv-3w97-433r/GHSA-57rv-3w97-433r.json index 1b88336ce5b..1d70e185ea6 100644 --- a/advisories/unreviewed/2022/05/GHSA-57rv-3w97-433r/GHSA-57rv-3w97-433r.json +++ b/advisories/unreviewed/2022/05/GHSA-57rv-3w97-433r/GHSA-57rv-3w97-433r.json @@ -7,12 +7,8 @@ "CVE-2019-14765" ], "details": "Incorrect Access Control in AfficheExplorateurParam() in DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to use administrative controllers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-58r3-xwfg-7j3x/GHSA-58r3-xwfg-7j3x.json b/advisories/unreviewed/2022/05/GHSA-58r3-xwfg-7j3x/GHSA-58r3-xwfg-7j3x.json index e7422d40b51..fcdc4cfe018 100644 --- a/advisories/unreviewed/2022/05/GHSA-58r3-xwfg-7j3x/GHSA-58r3-xwfg-7j3x.json +++ b/advisories/unreviewed/2022/05/GHSA-58r3-xwfg-7j3x/GHSA-58r3-xwfg-7j3x.json @@ -7,12 +7,8 @@ "CVE-2020-3142" ], "details": "[CVE-2020-3142_su] A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated, remote attendee to join a password-protected meeting without providing the meeting password. The connection attempt must initiate from a Webex mobile application for either iOS or Android. The vulnerability is due to unintended meeting information exposure in a specific meeting join flow for mobile applications. An unauthorized attendee could exploit this vulnerability by accessing a known meeting ID or meeting URL from the mobile device’s web browser. The browser will then request to launch the device’s Webex mobile application. A successful exploit could allow the unauthorized attendee to join the password-protected meeting. The unauthorized attendee will be visible in the attendee list of the meeting as a mobile attendee. Cisco has applied updates that address this vulnerability and no user action is required.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5f47-39m4-vrw3/GHSA-5f47-39m4-vrw3.json b/advisories/unreviewed/2022/05/GHSA-5f47-39m4-vrw3/GHSA-5f47-39m4-vrw3.json index af242c4bada..b5477ab1e26 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f47-39m4-vrw3/GHSA-5f47-39m4-vrw3.json +++ b/advisories/unreviewed/2022/05/GHSA-5f47-39m4-vrw3/GHSA-5f47-39m4-vrw3.json @@ -7,12 +7,8 @@ "CVE-2019-16008" ], "details": "A vulnerability in the web-based GUI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-based GUI of an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5f4q-fmwx-64m4/GHSA-5f4q-fmwx-64m4.json b/advisories/unreviewed/2022/05/GHSA-5f4q-fmwx-64m4/GHSA-5f4q-fmwx-64m4.json index b2fbf4f719e..6fef12eb0bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f4q-fmwx-64m4/GHSA-5f4q-fmwx-64m4.json +++ b/advisories/unreviewed/2022/05/GHSA-5f4q-fmwx-64m4/GHSA-5f4q-fmwx-64m4.json @@ -7,12 +7,8 @@ "CVE-2016-5346" ], "details": "An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointer dereference when processing an accept system call by the user process on AF_MSM_IPC sockets, which could let a local malicious user obtain sensitive information (Android Bug ID A-32551280).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5h32-5fxq-gm74/GHSA-5h32-5fxq-gm74.json b/advisories/unreviewed/2022/05/GHSA-5h32-5fxq-gm74/GHSA-5h32-5fxq-gm74.json index e210486cc9c..87705a7f7be 100644 --- a/advisories/unreviewed/2022/05/GHSA-5h32-5fxq-gm74/GHSA-5h32-5fxq-gm74.json +++ b/advisories/unreviewed/2022/05/GHSA-5h32-5fxq-gm74/GHSA-5h32-5fxq-gm74.json @@ -7,12 +7,8 @@ "CVE-2019-16003" ], "details": "A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to download system log files from an affected device. The vulnerability is due to an issue in the authentication logic of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the web interface. A successful exploit could allow the attacker to download log files if they were previously generated by an administrator.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5h96-c4j5-cc68/GHSA-5h96-c4j5-cc68.json b/advisories/unreviewed/2022/05/GHSA-5h96-c4j5-cc68/GHSA-5h96-c4j5-cc68.json index 08f5e92a7bc..c230407eb60 100644 --- a/advisories/unreviewed/2022/05/GHSA-5h96-c4j5-cc68/GHSA-5h96-c4j5-cc68.json +++ b/advisories/unreviewed/2022/05/GHSA-5h96-c4j5-cc68/GHSA-5h96-c4j5-cc68.json @@ -7,12 +7,8 @@ "CVE-2018-16263" ], "details": "The PulseAudio system service in Tizen allows an unprivileged process to control its A2DP MediaEndpoint, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5hcq-w636-2w8h/GHSA-5hcq-w636-2w8h.json b/advisories/unreviewed/2022/05/GHSA-5hcq-w636-2w8h/GHSA-5hcq-w636-2w8h.json index 0d2eda8323b..cd802d72790 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hcq-w636-2w8h/GHSA-5hcq-w636-2w8h.json +++ b/advisories/unreviewed/2022/05/GHSA-5hcq-w636-2w8h/GHSA-5hcq-w636-2w8h.json @@ -7,12 +7,8 @@ "CVE-2008-4996" ], "details": "** DISPUTED ** init in initramfs-tools 0.92f allows local users to overwrite arbitrary files via a symlink attack on the /tmp/initramfs.debug temporary file. NOTE: the vendor disputes this vulnerability, stating that \"init is [used in] a single-user context; there's no possibility that this is exploitable.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5j48-84w8-gwmf/GHSA-5j48-84w8-gwmf.json b/advisories/unreviewed/2022/05/GHSA-5j48-84w8-gwmf/GHSA-5j48-84w8-gwmf.json index 5c9f0006d42..0d63c112f13 100644 --- a/advisories/unreviewed/2022/05/GHSA-5j48-84w8-gwmf/GHSA-5j48-84w8-gwmf.json +++ b/advisories/unreviewed/2022/05/GHSA-5j48-84w8-gwmf/GHSA-5j48-84w8-gwmf.json @@ -7,12 +7,8 @@ "CVE-2020-7234" ], "details": "Ruckus ZoneFlex R310 104.0.0.0.1347 devices allow Stored XSS via the SSID field on the Configuration > Radio 2.4G > Wireless X screen (after a successful login to the super account).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5j93-rp4g-9wxp/GHSA-5j93-rp4g-9wxp.json b/advisories/unreviewed/2022/05/GHSA-5j93-rp4g-9wxp/GHSA-5j93-rp4g-9wxp.json index 50dec9ff5e2..2422274aa67 100644 --- a/advisories/unreviewed/2022/05/GHSA-5j93-rp4g-9wxp/GHSA-5j93-rp4g-9wxp.json +++ b/advisories/unreviewed/2022/05/GHSA-5j93-rp4g-9wxp/GHSA-5j93-rp4g-9wxp.json @@ -7,12 +7,8 @@ "CVE-2015-5483" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add users, (2) delete posts, or (3) modify PHP files via unspecified vectors, or (4) conduct cross-site scripting (XSS) attacks via the po_logo parameter in the privateonly.php page to wp-admin/options-general.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5jgv-j5rm-268h/GHSA-5jgv-j5rm-268h.json b/advisories/unreviewed/2022/05/GHSA-5jgv-j5rm-268h/GHSA-5jgv-j5rm-268h.json index d25d9175ec4..be7f3159979 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jgv-j5rm-268h/GHSA-5jgv-j5rm-268h.json +++ b/advisories/unreviewed/2022/05/GHSA-5jgv-j5rm-268h/GHSA-5jgv-j5rm-268h.json @@ -7,12 +7,8 @@ "CVE-2019-19898" ], "details": "In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotely.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jh5-7283-3xvx/GHSA-5jh5-7283-3xvx.json b/advisories/unreviewed/2022/05/GHSA-5jh5-7283-3xvx/GHSA-5jh5-7283-3xvx.json index 6ff8f1d5a4c..4dc54a28642 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jh5-7283-3xvx/GHSA-5jh5-7283-3xvx.json +++ b/advisories/unreviewed/2022/05/GHSA-5jh5-7283-3xvx/GHSA-5jh5-7283-3xvx.json @@ -7,12 +7,8 @@ "CVE-2013-3735" ], "details": "** DISPUTED ** The Zend Engine in PHP before 5.4.16 RC1, and 5.5.0 before RC2, does not properly determine whether a parser error occurred, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted function definition, as demonstrated by an attack within a shared web-hosting environment. NOTE: the vendor's http://php.net/security-note.php page says \"for critical security situations you should be using OS-level security by running multiple web servers each as their own user id.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5p35-vxc4-5xrj/GHSA-5p35-vxc4-5xrj.json b/advisories/unreviewed/2022/05/GHSA-5p35-vxc4-5xrj/GHSA-5p35-vxc4-5xrj.json index 7407bcac59b..ae4f3edda6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-5p35-vxc4-5xrj/GHSA-5p35-vxc4-5xrj.json +++ b/advisories/unreviewed/2022/05/GHSA-5p35-vxc4-5xrj/GHSA-5p35-vxc4-5xrj.json @@ -7,12 +7,8 @@ "CVE-2020-2580" ], "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.17 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5rfr-mxwv-h8rg/GHSA-5rfr-mxwv-h8rg.json b/advisories/unreviewed/2022/05/GHSA-5rfr-mxwv-h8rg/GHSA-5rfr-mxwv-h8rg.json index 06f53a9c53e..41d92f068b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-5rfr-mxwv-h8rg/GHSA-5rfr-mxwv-h8rg.json +++ b/advisories/unreviewed/2022/05/GHSA-5rfr-mxwv-h8rg/GHSA-5rfr-mxwv-h8rg.json @@ -7,12 +7,8 @@ "CVE-2019-19839" ], "details": "emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=import-category to admin/_cmdstat.jsp via the uploadFile attribute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5rr8-65f3-j756/GHSA-5rr8-65f3-j756.json b/advisories/unreviewed/2022/05/GHSA-5rr8-65f3-j756/GHSA-5rr8-65f3-j756.json index f6e722edf4b..27fc0fc1518 100644 --- a/advisories/unreviewed/2022/05/GHSA-5rr8-65f3-j756/GHSA-5rr8-65f3-j756.json +++ b/advisories/unreviewed/2022/05/GHSA-5rr8-65f3-j756/GHSA-5rr8-65f3-j756.json @@ -7,12 +7,8 @@ "CVE-2020-7228" ], "details": "The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present in the input forms. These can be exploited by an authenticated user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5vqh-qmfx-36w2/GHSA-5vqh-qmfx-36w2.json b/advisories/unreviewed/2022/05/GHSA-5vqh-qmfx-36w2/GHSA-5vqh-qmfx-36w2.json index 48f1ccd0b11..8f4db835718 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vqh-qmfx-36w2/GHSA-5vqh-qmfx-36w2.json +++ b/advisories/unreviewed/2022/05/GHSA-5vqh-qmfx-36w2/GHSA-5vqh-qmfx-36w2.json @@ -7,12 +7,8 @@ "CVE-2020-7911" ], "details": "In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5vx5-pc42-77fx/GHSA-5vx5-pc42-77fx.json b/advisories/unreviewed/2022/05/GHSA-5vx5-pc42-77fx/GHSA-5vx5-pc42-77fx.json index 6f5cde19bb0..0f74cc0286a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vx5-pc42-77fx/GHSA-5vx5-pc42-77fx.json +++ b/advisories/unreviewed/2022/05/GHSA-5vx5-pc42-77fx/GHSA-5vx5-pc42-77fx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5w3g-8vcj-w28f/GHSA-5w3g-8vcj-w28f.json b/advisories/unreviewed/2022/05/GHSA-5w3g-8vcj-w28f/GHSA-5w3g-8vcj-w28f.json index bee96844abf..03c7f6a3ee6 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w3g-8vcj-w28f/GHSA-5w3g-8vcj-w28f.json +++ b/advisories/unreviewed/2022/05/GHSA-5w3g-8vcj-w28f/GHSA-5w3g-8vcj-w28f.json @@ -7,12 +7,8 @@ "CVE-2019-17125" ], "details": "A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5w44-6qm8-5cf9/GHSA-5w44-6qm8-5cf9.json b/advisories/unreviewed/2022/05/GHSA-5w44-6qm8-5cf9/GHSA-5w44-6qm8-5cf9.json index 92548ecd90c..a427d062ac8 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w44-6qm8-5cf9/GHSA-5w44-6qm8-5cf9.json +++ b/advisories/unreviewed/2022/05/GHSA-5w44-6qm8-5cf9/GHSA-5w44-6qm8-5cf9.json @@ -7,12 +7,8 @@ "CVE-2019-11318" ], "details": "Zimbra Collaboration before 8.8.12 Patch 1 has persistent XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5w6g-rp5j-mg2g/GHSA-5w6g-rp5j-mg2g.json b/advisories/unreviewed/2022/05/GHSA-5w6g-rp5j-mg2g/GHSA-5w6g-rp5j-mg2g.json index 1d1cf92b2f1..a4d9bb68e27 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w6g-rp5j-mg2g/GHSA-5w6g-rp5j-mg2g.json +++ b/advisories/unreviewed/2022/05/GHSA-5w6g-rp5j-mg2g/GHSA-5w6g-rp5j-mg2g.json @@ -7,12 +7,8 @@ "CVE-2020-6966" ], "details": "In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control, which may allow an attacker to obtain remote code execution of devices on the network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-62j2-rqpv-q83g/GHSA-62j2-rqpv-q83g.json b/advisories/unreviewed/2022/05/GHSA-62j2-rqpv-q83g/GHSA-62j2-rqpv-q83g.json index 02ebaddd936..28b57e72637 100644 --- a/advisories/unreviewed/2022/05/GHSA-62j2-rqpv-q83g/GHSA-62j2-rqpv-q83g.json +++ b/advisories/unreviewed/2022/05/GHSA-62j2-rqpv-q83g/GHSA-62j2-rqpv-q83g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-62qm-m6wg-jvqw/GHSA-62qm-m6wg-jvqw.json b/advisories/unreviewed/2022/05/GHSA-62qm-m6wg-jvqw/GHSA-62qm-m6wg-jvqw.json index d6497bda923..a92ef816ec1 100644 --- a/advisories/unreviewed/2022/05/GHSA-62qm-m6wg-jvqw/GHSA-62qm-m6wg-jvqw.json +++ b/advisories/unreviewed/2022/05/GHSA-62qm-m6wg-jvqw/GHSA-62qm-m6wg-jvqw.json @@ -7,12 +7,8 @@ "CVE-2019-19392" ], "details": "The forDNN.UsersExportImport module before 1.2.0 for DNN (formerly DotNetNuke) allows an unprivileged user to import (create) new users with Administrator privileges, as demonstrated by Roles=\"Administrators\" in XML or CSV data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-638h-mp9x-p4wm/GHSA-638h-mp9x-p4wm.json b/advisories/unreviewed/2022/05/GHSA-638h-mp9x-p4wm/GHSA-638h-mp9x-p4wm.json index 861a857b894..baa866fc9b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-638h-mp9x-p4wm/GHSA-638h-mp9x-p4wm.json +++ b/advisories/unreviewed/2022/05/GHSA-638h-mp9x-p4wm/GHSA-638h-mp9x-p4wm.json @@ -7,12 +7,8 @@ "CVE-2019-16018" ], "details": "A vulnerability in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of a BGP update message that contains crafted EVPN attributes. An attacker could indirectly exploit the vulnerability by sending BGP EVPN update messages with a specific, malformed attribute to an affected system and waiting for a user on the device to display the EVPN operational routes’ status. If successful, the attacker could cause the BGP process to restart unexpectedly, resulting in a DoS condition. The Cisco implementation of BGP accepts incoming BGP traffic only from explicitly defined peers. To exploit this vulnerability, the malicious BGP update message would need to come from a configured, valid BGP peer, or would need to be injected by the attacker into the victim's BGP network on an existing, valid TCP connection to a BGP peer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-63c5-w82h-wf43/GHSA-63c5-w82h-wf43.json b/advisories/unreviewed/2022/05/GHSA-63c5-w82h-wf43/GHSA-63c5-w82h-wf43.json index 47b9ff4d4a8..bf94a2264a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-63c5-w82h-wf43/GHSA-63c5-w82h-wf43.json +++ b/advisories/unreviewed/2022/05/GHSA-63c5-w82h-wf43/GHSA-63c5-w82h-wf43.json @@ -7,12 +7,8 @@ "CVE-2010-5183" ], "details": "** DISPUTED ** Race condition in Webroot Internet Security Essentials 6.1.0.145 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6485-232f-h4jw/GHSA-6485-232f-h4jw.json b/advisories/unreviewed/2022/05/GHSA-6485-232f-h4jw/GHSA-6485-232f-h4jw.json index f88083c0c77..0430863aafb 100644 --- a/advisories/unreviewed/2022/05/GHSA-6485-232f-h4jw/GHSA-6485-232f-h4jw.json +++ b/advisories/unreviewed/2022/05/GHSA-6485-232f-h4jw/GHSA-6485-232f-h4jw.json @@ -7,12 +7,8 @@ "CVE-2019-19414" ], "details": "There is an integer overflow vulnerability in LDAP server of some Huawei products. Due to insufficient input validation, a remote attacker could exploit this vulnerability by sending malformed packets to the target devices. Successful exploit could cause the affected system crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-64qw-gw3c-cgjv/GHSA-64qw-gw3c-cgjv.json b/advisories/unreviewed/2022/05/GHSA-64qw-gw3c-cgjv/GHSA-64qw-gw3c-cgjv.json index c16ef595c1e..9d2493e805b 100644 --- a/advisories/unreviewed/2022/05/GHSA-64qw-gw3c-cgjv/GHSA-64qw-gw3c-cgjv.json +++ b/advisories/unreviewed/2022/05/GHSA-64qw-gw3c-cgjv/GHSA-64qw-gw3c-cgjv.json @@ -7,12 +7,8 @@ "CVE-2018-16271" ], "details": "The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent from the mailbox via the paired smartphone. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-65vv-mx5f-jggq/GHSA-65vv-mx5f-jggq.json b/advisories/unreviewed/2022/05/GHSA-65vv-mx5f-jggq/GHSA-65vv-mx5f-jggq.json index b87c4d98fd7..32505c17f99 100644 --- a/advisories/unreviewed/2022/05/GHSA-65vv-mx5f-jggq/GHSA-65vv-mx5f-jggq.json +++ b/advisories/unreviewed/2022/05/GHSA-65vv-mx5f-jggq/GHSA-65vv-mx5f-jggq.json @@ -7,12 +7,8 @@ "CVE-2011-4451" ], "details": "** DISPUTED ** libs/Wakka.class.php in WikkaWiki 1.3.1 and 1.3.2, when the spam_logging option is enabled, allows remote attackers to write arbitrary PHP code to the spamlog_path file via the User-Agent HTTP header in an addcomment request. NOTE: the vendor disputes this issue because the rendering of the spamlog_path file never uses the PHP interpreter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6627-xq79-x5q7/GHSA-6627-xq79-x5q7.json b/advisories/unreviewed/2022/05/GHSA-6627-xq79-x5q7/GHSA-6627-xq79-x5q7.json index 372c75f1aed..de4a282416d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6627-xq79-x5q7/GHSA-6627-xq79-x5q7.json +++ b/advisories/unreviewed/2022/05/GHSA-6627-xq79-x5q7/GHSA-6627-xq79-x5q7.json @@ -7,12 +7,8 @@ "CVE-2020-7052" ], "details": "CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-666m-88c3-537x/GHSA-666m-88c3-537x.json b/advisories/unreviewed/2022/05/GHSA-666m-88c3-537x/GHSA-666m-88c3-537x.json index 60d7a8549c2..af8ed08a997 100644 --- a/advisories/unreviewed/2022/05/GHSA-666m-88c3-537x/GHSA-666m-88c3-537x.json +++ b/advisories/unreviewed/2022/05/GHSA-666m-88c3-537x/GHSA-666m-88c3-537x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67r8-22g4-5frw/GHSA-67r8-22g4-5frw.json b/advisories/unreviewed/2022/05/GHSA-67r8-22g4-5frw/GHSA-67r8-22g4-5frw.json index f8e868dd02a..363d19e17ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-67r8-22g4-5frw/GHSA-67r8-22g4-5frw.json +++ b/advisories/unreviewed/2022/05/GHSA-67r8-22g4-5frw/GHSA-67r8-22g4-5frw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-67rm-568x-hqvj/GHSA-67rm-568x-hqvj.json b/advisories/unreviewed/2022/05/GHSA-67rm-568x-hqvj/GHSA-67rm-568x-hqvj.json index 1ffc8de0f4b..f4bc5196e81 100644 --- a/advisories/unreviewed/2022/05/GHSA-67rm-568x-hqvj/GHSA-67rm-568x-hqvj.json +++ b/advisories/unreviewed/2022/05/GHSA-67rm-568x-hqvj/GHSA-67rm-568x-hqvj.json @@ -7,12 +7,8 @@ "CVE-2020-0640" ], "details": "A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-698r-78mf-5xwp/GHSA-698r-78mf-5xwp.json b/advisories/unreviewed/2022/05/GHSA-698r-78mf-5xwp/GHSA-698r-78mf-5xwp.json index 23bcb95e38c..c634bb29d8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-698r-78mf-5xwp/GHSA-698r-78mf-5xwp.json +++ b/advisories/unreviewed/2022/05/GHSA-698r-78mf-5xwp/GHSA-698r-78mf-5xwp.json @@ -7,12 +7,8 @@ "CVE-2012-5382" ], "details": "** DISPUTED ** Untrusted search path vulnerability in the installation functionality in Zend Server 5.6.0 SP4, when installed in the top-level C:\\ directory, might allow local users to gain privileges via a Trojan horse DLL in the C:\\Zend\\ZendServer\\share\\ZendFramework\\bin directory, which may be added to the PATH system environment variable by an administrator, as demonstrated by a Trojan horse wlbsctrl.dll file used by the \"IKE and AuthIP IPsec Keying Modules\" system service in Windows Vista SP1, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 Release Preview. NOTE: CVE disputes this issue because the choice of C:\\ (and the resulting unsafe PATH) is established by an administrative action that is not a default part of the Zend Server installation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-69gf-2w85-7g9q/GHSA-69gf-2w85-7g9q.json b/advisories/unreviewed/2022/05/GHSA-69gf-2w85-7g9q/GHSA-69gf-2w85-7g9q.json index 08eb70f59e6..fcdfef56c1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-69gf-2w85-7g9q/GHSA-69gf-2w85-7g9q.json +++ b/advisories/unreviewed/2022/05/GHSA-69gf-2w85-7g9q/GHSA-69gf-2w85-7g9q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6c2c-f6pf-7ghx/GHSA-6c2c-f6pf-7ghx.json b/advisories/unreviewed/2022/05/GHSA-6c2c-f6pf-7ghx/GHSA-6c2c-f6pf-7ghx.json index fb5175c435e..14057471258 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c2c-f6pf-7ghx/GHSA-6c2c-f6pf-7ghx.json +++ b/advisories/unreviewed/2022/05/GHSA-6c2c-f6pf-7ghx/GHSA-6c2c-f6pf-7ghx.json @@ -7,12 +7,8 @@ "CVE-2020-0615" ], "details": "An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0639.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6cf5-778v-wpvj/GHSA-6cf5-778v-wpvj.json b/advisories/unreviewed/2022/05/GHSA-6cf5-778v-wpvj/GHSA-6cf5-778v-wpvj.json index 2a9bb291f04..545f1cb746b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cf5-778v-wpvj/GHSA-6cf5-778v-wpvj.json +++ b/advisories/unreviewed/2022/05/GHSA-6cf5-778v-wpvj/GHSA-6cf5-778v-wpvj.json @@ -7,12 +7,8 @@ "CVE-2020-0641" ], "details": "An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6cr6-42wp-f2fm/GHSA-6cr6-42wp-f2fm.json b/advisories/unreviewed/2022/05/GHSA-6cr6-42wp-f2fm/GHSA-6cr6-42wp-f2fm.json index 0b41f079473..2067d893209 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cr6-42wp-f2fm/GHSA-6cr6-42wp-f2fm.json +++ b/advisories/unreviewed/2022/05/GHSA-6cr6-42wp-f2fm/GHSA-6cr6-42wp-f2fm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6ff8-jh7v-68j7/GHSA-6ff8-jh7v-68j7.json b/advisories/unreviewed/2022/05/GHSA-6ff8-jh7v-68j7/GHSA-6ff8-jh7v-68j7.json index bc1165d22c0..3cb74b9ef28 100644 --- a/advisories/unreviewed/2022/05/GHSA-6ff8-jh7v-68j7/GHSA-6ff8-jh7v-68j7.json +++ b/advisories/unreviewed/2022/05/GHSA-6ff8-jh7v-68j7/GHSA-6ff8-jh7v-68j7.json @@ -7,12 +7,8 @@ "CVE-2019-3700" ], "details": "yast2-security didn't use secure defaults to protect passwords. This became a problem on 2019-10-07 when configuration files that set secure settings were moved to a different location. As of the 20191022 snapshot the insecure default settings were used until yast2-security switched to stronger defaults in 4.2.6 and used the new configuration file locations. Password created during this time used DES password encryption and are not properly protected against attackers that are able to access the password hashes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6fx6-7h86-836f/GHSA-6fx6-7h86-836f.json b/advisories/unreviewed/2022/05/GHSA-6fx6-7h86-836f/GHSA-6fx6-7h86-836f.json index 934236b5734..3e0115d055a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fx6-7h86-836f/GHSA-6fx6-7h86-836f.json +++ b/advisories/unreviewed/2022/05/GHSA-6fx6-7h86-836f/GHSA-6fx6-7h86-836f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6g5g-jj2r-p5fv/GHSA-6g5g-jj2r-p5fv.json b/advisories/unreviewed/2022/05/GHSA-6g5g-jj2r-p5fv/GHSA-6g5g-jj2r-p5fv.json index 4822c8274ec..7a3ab577f9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6g5g-jj2r-p5fv/GHSA-6g5g-jj2r-p5fv.json +++ b/advisories/unreviewed/2022/05/GHSA-6g5g-jj2r-p5fv/GHSA-6g5g-jj2r-p5fv.json @@ -7,12 +7,8 @@ "CVE-2019-17099" ], "details": "An Untrusted Search Path vulnerability in EPSecurityService.exe as used in Bitdefender Endpoint Security Tools versions prior to 6.6.11.163 allows an attacker to load an arbitrary DLL file from the search path. This issue affects: Bitdefender EPSecurityService.exe versions prior to 6.6.11.163.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6g85-84jx-q393/GHSA-6g85-84jx-q393.json b/advisories/unreviewed/2022/05/GHSA-6g85-84jx-q393/GHSA-6g85-84jx-q393.json index a06efb568c3..5d0a0d5c214 100644 --- a/advisories/unreviewed/2022/05/GHSA-6g85-84jx-q393/GHSA-6g85-84jx-q393.json +++ b/advisories/unreviewed/2022/05/GHSA-6g85-84jx-q393/GHSA-6g85-84jx-q393.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6hgc-j2rf-mq69/GHSA-6hgc-j2rf-mq69.json b/advisories/unreviewed/2022/05/GHSA-6hgc-j2rf-mq69/GHSA-6hgc-j2rf-mq69.json index de7caa15338..c4dfe28efbc 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hgc-j2rf-mq69/GHSA-6hgc-j2rf-mq69.json +++ b/advisories/unreviewed/2022/05/GHSA-6hgc-j2rf-mq69/GHSA-6hgc-j2rf-mq69.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6j55-wpq4-gx68/GHSA-6j55-wpq4-gx68.json b/advisories/unreviewed/2022/05/GHSA-6j55-wpq4-gx68/GHSA-6j55-wpq4-gx68.json index f741f81db97..c3f58ab7466 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j55-wpq4-gx68/GHSA-6j55-wpq4-gx68.json +++ b/advisories/unreviewed/2022/05/GHSA-6j55-wpq4-gx68/GHSA-6j55-wpq4-gx68.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6jcp-4mfr-qvpm/GHSA-6jcp-4mfr-qvpm.json b/advisories/unreviewed/2022/05/GHSA-6jcp-4mfr-qvpm/GHSA-6jcp-4mfr-qvpm.json index 26ee3f4bc3e..dcb9a30e711 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jcp-4mfr-qvpm/GHSA-6jcp-4mfr-qvpm.json +++ b/advisories/unreviewed/2022/05/GHSA-6jcp-4mfr-qvpm/GHSA-6jcp-4mfr-qvpm.json @@ -7,12 +7,8 @@ "CVE-2008-5135" ], "details": "** DISPUTED ** os-prober in os-prober 1.17 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/mounted-map or (2) /tmp/raided-map temporary file. NOTE: the vendor disputes this issue, stating \"the insecure code path should only ever run inside a d-i environment, which has no non-root users.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6jq3-v9rf-xmwr/GHSA-6jq3-v9rf-xmwr.json b/advisories/unreviewed/2022/05/GHSA-6jq3-v9rf-xmwr/GHSA-6jq3-v9rf-xmwr.json index e7f8306a549..7e2fe84bac5 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jq3-v9rf-xmwr/GHSA-6jq3-v9rf-xmwr.json +++ b/advisories/unreviewed/2022/05/GHSA-6jq3-v9rf-xmwr/GHSA-6jq3-v9rf-xmwr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6m73-xcgm-75f2/GHSA-6m73-xcgm-75f2.json b/advisories/unreviewed/2022/05/GHSA-6m73-xcgm-75f2/GHSA-6m73-xcgm-75f2.json index c1fc46a12cd..3a1da20e6b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-6m73-xcgm-75f2/GHSA-6m73-xcgm-75f2.json +++ b/advisories/unreviewed/2022/05/GHSA-6m73-xcgm-75f2/GHSA-6m73-xcgm-75f2.json @@ -7,12 +7,8 @@ "CVE-2020-5514" ], "details": "Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6px4-w6j6-hcxv/GHSA-6px4-w6j6-hcxv.json b/advisories/unreviewed/2022/05/GHSA-6px4-w6j6-hcxv/GHSA-6px4-w6j6-hcxv.json index d9b8609b54f..4272b55eb2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6px4-w6j6-hcxv/GHSA-6px4-w6j6-hcxv.json +++ b/advisories/unreviewed/2022/05/GHSA-6px4-w6j6-hcxv/GHSA-6px4-w6j6-hcxv.json @@ -7,12 +7,8 @@ "CVE-2020-3940" ], "details": "VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6q9j-c3rh-x87m/GHSA-6q9j-c3rh-x87m.json b/advisories/unreviewed/2022/05/GHSA-6q9j-c3rh-x87m/GHSA-6q9j-c3rh-x87m.json index 39dd1183faa..eae57825117 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q9j-c3rh-x87m/GHSA-6q9j-c3rh-x87m.json +++ b/advisories/unreviewed/2022/05/GHSA-6q9j-c3rh-x87m/GHSA-6q9j-c3rh-x87m.json @@ -7,12 +7,8 @@ "CVE-2015-5334" ], "details": "Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible execute arbitrary code via a crafted X.509 certificate, which triggers a stack-based buffer overflow. Note: this vulnerability exists because of an incorrect fix for CVE-2014-3508.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6qq6-x75v-fgg7/GHSA-6qq6-x75v-fgg7.json b/advisories/unreviewed/2022/05/GHSA-6qq6-x75v-fgg7/GHSA-6qq6-x75v-fgg7.json index 9bc93a6636e..1bd3cf58de2 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qq6-x75v-fgg7/GHSA-6qq6-x75v-fgg7.json +++ b/advisories/unreviewed/2022/05/GHSA-6qq6-x75v-fgg7/GHSA-6qq6-x75v-fgg7.json @@ -7,12 +7,8 @@ "CVE-2014-2734" ], "details": "** DISPUTED ** The openssl extension in Ruby 2.x does not properly maintain the state of process memory after a file is reopened, which allows remote attackers to spoof signatures within the context of a Ruby script that attempts signature verification after performing a certain sequence of filesystem operations. NOTE: this issue has been disputed by the Ruby OpenSSL team and third parties, who state that the original demonstration PoC contains errors and redundant or unnecessarily-complex code that does not appear to be related to a demonstration of the issue. As of 20140502, CVE is not aware of any public comment by the original researcher.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6v4v-39c2-j8j9/GHSA-6v4v-39c2-j8j9.json b/advisories/unreviewed/2022/05/GHSA-6v4v-39c2-j8j9/GHSA-6v4v-39c2-j8j9.json index 20db13baae4..1028084cbd1 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v4v-39c2-j8j9/GHSA-6v4v-39c2-j8j9.json +++ b/advisories/unreviewed/2022/05/GHSA-6v4v-39c2-j8j9/GHSA-6v4v-39c2-j8j9.json @@ -7,12 +7,8 @@ "CVE-2020-2681" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6vj8-73gx-7pm7/GHSA-6vj8-73gx-7pm7.json b/advisories/unreviewed/2022/05/GHSA-6vj8-73gx-7pm7/GHSA-6vj8-73gx-7pm7.json index 8020d4c625e..7d661225dea 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vj8-73gx-7pm7/GHSA-6vj8-73gx-7pm7.json +++ b/advisories/unreviewed/2022/05/GHSA-6vj8-73gx-7pm7/GHSA-6vj8-73gx-7pm7.json @@ -7,12 +7,8 @@ "CVE-2019-19855" ], "details": "An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/list_user allows stored XSS via the auth_type parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6w26-hv7h-wwfq/GHSA-6w26-hv7h-wwfq.json b/advisories/unreviewed/2022/05/GHSA-6w26-hv7h-wwfq/GHSA-6w26-hv7h-wwfq.json index fe3fddff818..93f149374a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w26-hv7h-wwfq/GHSA-6w26-hv7h-wwfq.json +++ b/advisories/unreviewed/2022/05/GHSA-6w26-hv7h-wwfq/GHSA-6w26-hv7h-wwfq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xgr-c2pj-c8xx/GHSA-6xgr-c2pj-c8xx.json b/advisories/unreviewed/2022/05/GHSA-6xgr-c2pj-c8xx/GHSA-6xgr-c2pj-c8xx.json index 1896b58fb5e..63afa577cfb 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xgr-c2pj-c8xx/GHSA-6xgr-c2pj-c8xx.json +++ b/advisories/unreviewed/2022/05/GHSA-6xgr-c2pj-c8xx/GHSA-6xgr-c2pj-c8xx.json @@ -7,12 +7,8 @@ "CVE-2019-20441" ], "details": "An issue was discovered in WSO2 API Manager 2.6.0. A potential Stored Cross-Site Scripting (XSS) vulnerability has been identified in the 'implement phase' of the API Publisher.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-727r-ghq8-fgh9/GHSA-727r-ghq8-fgh9.json b/advisories/unreviewed/2022/05/GHSA-727r-ghq8-fgh9/GHSA-727r-ghq8-fgh9.json index 22eaf6095b3..02b62922b54 100644 --- a/advisories/unreviewed/2022/05/GHSA-727r-ghq8-fgh9/GHSA-727r-ghq8-fgh9.json +++ b/advisories/unreviewed/2022/05/GHSA-727r-ghq8-fgh9/GHSA-727r-ghq8-fgh9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-72gh-33g3-q3vw/GHSA-72gh-33g3-q3vw.json b/advisories/unreviewed/2022/05/GHSA-72gh-33g3-q3vw/GHSA-72gh-33g3-q3vw.json index 402b01900fe..85cc8eb0a73 100644 --- a/advisories/unreviewed/2022/05/GHSA-72gh-33g3-q3vw/GHSA-72gh-33g3-q3vw.json +++ b/advisories/unreviewed/2022/05/GHSA-72gh-33g3-q3vw/GHSA-72gh-33g3-q3vw.json @@ -7,12 +7,8 @@ "CVE-2010-5166" ], "details": "** DISPUTED ** Race condition in McAfee Total Protection 2010 10.0.580 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-72hv-gvjp-m2fx/GHSA-72hv-gvjp-m2fx.json b/advisories/unreviewed/2022/05/GHSA-72hv-gvjp-m2fx/GHSA-72hv-gvjp-m2fx.json index e8d5c415625..052f2006542 100644 --- a/advisories/unreviewed/2022/05/GHSA-72hv-gvjp-m2fx/GHSA-72hv-gvjp-m2fx.json +++ b/advisories/unreviewed/2022/05/GHSA-72hv-gvjp-m2fx/GHSA-72hv-gvjp-m2fx.json @@ -7,12 +7,8 @@ "CVE-2020-2530" ], "details": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle HTTP Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HTTP Server accessible data as well as unauthorized read access to a subset of Oracle HTTP Server accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7348-qhjj-7r42/GHSA-7348-qhjj-7r42.json b/advisories/unreviewed/2022/05/GHSA-7348-qhjj-7r42/GHSA-7348-qhjj-7r42.json index 10bb87c5aa0..f317d28106e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7348-qhjj-7r42/GHSA-7348-qhjj-7r42.json +++ b/advisories/unreviewed/2022/05/GHSA-7348-qhjj-7r42/GHSA-7348-qhjj-7r42.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-73x6-v3m8-f299/GHSA-73x6-v3m8-f299.json b/advisories/unreviewed/2022/05/GHSA-73x6-v3m8-f299/GHSA-73x6-v3m8-f299.json index 020b0c5cee1..ead970faf32 100644 --- a/advisories/unreviewed/2022/05/GHSA-73x6-v3m8-f299/GHSA-73x6-v3m8-f299.json +++ b/advisories/unreviewed/2022/05/GHSA-73x6-v3m8-f299/GHSA-73x6-v3m8-f299.json @@ -7,12 +7,8 @@ "CVE-2020-0609" ], "details": "A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0610.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-74fq-3g57-65f7/GHSA-74fq-3g57-65f7.json b/advisories/unreviewed/2022/05/GHSA-74fq-3g57-65f7/GHSA-74fq-3g57-65f7.json index 62dee6995f4..9997d87bd97 100644 --- a/advisories/unreviewed/2022/05/GHSA-74fq-3g57-65f7/GHSA-74fq-3g57-65f7.json +++ b/advisories/unreviewed/2022/05/GHSA-74fq-3g57-65f7/GHSA-74fq-3g57-65f7.json @@ -7,12 +7,8 @@ "CVE-2019-1352" ], "details": "A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1354, CVE-2019-1387.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-74p2-xjh7-9gv6/GHSA-74p2-xjh7-9gv6.json b/advisories/unreviewed/2022/05/GHSA-74p2-xjh7-9gv6/GHSA-74p2-xjh7-9gv6.json index 23782f14706..1a24e3c5db5 100644 --- a/advisories/unreviewed/2022/05/GHSA-74p2-xjh7-9gv6/GHSA-74p2-xjh7-9gv6.json +++ b/advisories/unreviewed/2022/05/GHSA-74p2-xjh7-9gv6/GHSA-74p2-xjh7-9gv6.json @@ -7,12 +7,8 @@ "CVE-2019-17634" ], "details": "Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a cross site scripting (XSS) vulnerability when generating an HTML report from a malicious heap dump. The user must chose todownload, open the malicious heap dump and generate an HTML report for the problem to occur. The heap dump could be specially crafted, or could come from a crafted application or from an application processing malicious data. The vulnerability is present whena report is generated and opened from the Memory Analyzer graphical user interface, or when a report generated in batch mode is then opened in Memory Analyzer or by a web browser. The vulnerability could possibly allow code execution on the local system whenthe report is opened in Memory Analyzer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-74x9-89m7-944x/GHSA-74x9-89m7-944x.json b/advisories/unreviewed/2022/05/GHSA-74x9-89m7-944x/GHSA-74x9-89m7-944x.json index 8e78eab5935..7a9807a24c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-74x9-89m7-944x/GHSA-74x9-89m7-944x.json +++ b/advisories/unreviewed/2022/05/GHSA-74x9-89m7-944x/GHSA-74x9-89m7-944x.json @@ -7,12 +7,8 @@ "CVE-2019-1351" ], "details": "A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-75cx-mgvw-f42h/GHSA-75cx-mgvw-f42h.json b/advisories/unreviewed/2022/05/GHSA-75cx-mgvw-f42h/GHSA-75cx-mgvw-f42h.json index 00486ed4d06..64c7edb43dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-75cx-mgvw-f42h/GHSA-75cx-mgvw-f42h.json +++ b/advisories/unreviewed/2022/05/GHSA-75cx-mgvw-f42h/GHSA-75cx-mgvw-f42h.json @@ -7,12 +7,8 @@ "CVE-2018-16267" ], "details": "The system-popup system service in Tizen allows an unprivileged process to perform popup-related system actions, due to improper D-Bus security policy configurations. Such actions include the triggering system poweroff menu, and prompting a popup with arbitrary strings. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-75qw-xjcp-vvmv/GHSA-75qw-xjcp-vvmv.json b/advisories/unreviewed/2022/05/GHSA-75qw-xjcp-vvmv/GHSA-75qw-xjcp-vvmv.json index 91d0bdc123e..f03ba597c05 100644 --- a/advisories/unreviewed/2022/05/GHSA-75qw-xjcp-vvmv/GHSA-75qw-xjcp-vvmv.json +++ b/advisories/unreviewed/2022/05/GHSA-75qw-xjcp-vvmv/GHSA-75qw-xjcp-vvmv.json @@ -7,12 +7,8 @@ "CVE-2011-4899" ], "details": "** DISPUTED ** wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database service is appropriate, which allows remote attackers to configure an arbitrary database via the dbhost and dbname parameters, and subsequently conduct static code injection and cross-site scripting (XSS) attacks via (1) an HTTP request or (2) a MySQL query. NOTE: the vendor disputes the significance of this issue; however, remote code execution makes the issue important in many realistic environments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-76cx-7rrw-h794/GHSA-76cx-7rrw-h794.json b/advisories/unreviewed/2022/05/GHSA-76cx-7rrw-h794/GHSA-76cx-7rrw-h794.json index 46e624b2a42..d8794714497 100644 --- a/advisories/unreviewed/2022/05/GHSA-76cx-7rrw-h794/GHSA-76cx-7rrw-h794.json +++ b/advisories/unreviewed/2022/05/GHSA-76cx-7rrw-h794/GHSA-76cx-7rrw-h794.json @@ -7,12 +7,8 @@ "CVE-2020-0643" ], "details": "An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI+ Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-777v-j39v-h8x4/GHSA-777v-j39v-h8x4.json b/advisories/unreviewed/2022/05/GHSA-777v-j39v-h8x4/GHSA-777v-j39v-h8x4.json index fb0dd6cc0cc..54b4ba7c60e 100644 --- a/advisories/unreviewed/2022/05/GHSA-777v-j39v-h8x4/GHSA-777v-j39v-h8x4.json +++ b/advisories/unreviewed/2022/05/GHSA-777v-j39v-h8x4/GHSA-777v-j39v-h8x4.json @@ -7,12 +7,8 @@ "CVE-2020-5513" ], "details": "Gila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7889-wv3h-p95v/GHSA-7889-wv3h-p95v.json b/advisories/unreviewed/2022/05/GHSA-7889-wv3h-p95v/GHSA-7889-wv3h-p95v.json index 36ad9aa93b7..579e98bbcf5 100644 --- a/advisories/unreviewed/2022/05/GHSA-7889-wv3h-p95v/GHSA-7889-wv3h-p95v.json +++ b/advisories/unreviewed/2022/05/GHSA-7889-wv3h-p95v/GHSA-7889-wv3h-p95v.json @@ -7,12 +7,8 @@ "CVE-2019-1460" ], "details": "A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages, aka 'Outlook for Android Spoofing Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-78px-5922-975f/GHSA-78px-5922-975f.json b/advisories/unreviewed/2022/05/GHSA-78px-5922-975f/GHSA-78px-5922-975f.json index 5c8d3a07fd0..df62352c2c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-78px-5922-975f/GHSA-78px-5922-975f.json +++ b/advisories/unreviewed/2022/05/GHSA-78px-5922-975f/GHSA-78px-5922-975f.json @@ -7,12 +7,8 @@ "CVE-2020-0633" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7953-6mhj-4r94/GHSA-7953-6mhj-4r94.json b/advisories/unreviewed/2022/05/GHSA-7953-6mhj-4r94/GHSA-7953-6mhj-4r94.json index 602ce9b9527..82232799716 100644 --- a/advisories/unreviewed/2022/05/GHSA-7953-6mhj-4r94/GHSA-7953-6mhj-4r94.json +++ b/advisories/unreviewed/2022/05/GHSA-7953-6mhj-4r94/GHSA-7953-6mhj-4r94.json @@ -7,12 +7,8 @@ "CVE-2010-5172" ], "details": "** DISPUTED ** Race condition in Panda Internet Security 2010 15.01.00 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-798h-7r68-cmhx/GHSA-798h-7r68-cmhx.json b/advisories/unreviewed/2022/05/GHSA-798h-7r68-cmhx/GHSA-798h-7r68-cmhx.json index 5d68a32ed31..3e513f84b90 100644 --- a/advisories/unreviewed/2022/05/GHSA-798h-7r68-cmhx/GHSA-798h-7r68-cmhx.json +++ b/advisories/unreviewed/2022/05/GHSA-798h-7r68-cmhx/GHSA-798h-7r68-cmhx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7c2v-cqrg-3pf6/GHSA-7c2v-cqrg-3pf6.json b/advisories/unreviewed/2022/05/GHSA-7c2v-cqrg-3pf6/GHSA-7c2v-cqrg-3pf6.json index c4f2b97cbd6..aee9d29ff81 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c2v-cqrg-3pf6/GHSA-7c2v-cqrg-3pf6.json +++ b/advisories/unreviewed/2022/05/GHSA-7c2v-cqrg-3pf6/GHSA-7c2v-cqrg-3pf6.json @@ -7,12 +7,8 @@ "CVE-2019-16517" ], "details": "An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected the Origin provided by incoming requests. This allowed JavaScript running on any domain to interact with the server APIs and perform administrative actions, without the victim's knowledge.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7g77-97mx-6jpp/GHSA-7g77-97mx-6jpp.json b/advisories/unreviewed/2022/05/GHSA-7g77-97mx-6jpp/GHSA-7g77-97mx-6jpp.json index 7c7adfdca40..4ced13cfc46 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g77-97mx-6jpp/GHSA-7g77-97mx-6jpp.json +++ b/advisories/unreviewed/2022/05/GHSA-7g77-97mx-6jpp/GHSA-7g77-97mx-6jpp.json @@ -7,12 +7,8 @@ "CVE-2016-6593" ], "details": "A code-execution vulnerability exists during startup in jhi.dll and otpiha.dll in Symantec VIP Access Desktop before 2.2.2, which could let local malicious users execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7hww-289f-rq2g/GHSA-7hww-289f-rq2g.json b/advisories/unreviewed/2022/05/GHSA-7hww-289f-rq2g/GHSA-7hww-289f-rq2g.json index 1000201a347..66e8c9770b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hww-289f-rq2g/GHSA-7hww-289f-rq2g.json +++ b/advisories/unreviewed/2022/05/GHSA-7hww-289f-rq2g/GHSA-7hww-289f-rq2g.json @@ -7,12 +7,8 @@ "CVE-2019-19893" ], "details": "In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated attacker, who can access the server's filesystem with the access rights of NT AUTHORITY\\SYSTEM.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7j42-ggv7-2p5p/GHSA-7j42-ggv7-2p5p.json b/advisories/unreviewed/2022/05/GHSA-7j42-ggv7-2p5p/GHSA-7j42-ggv7-2p5p.json index dce8e38877c..007538eac62 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j42-ggv7-2p5p/GHSA-7j42-ggv7-2p5p.json +++ b/advisories/unreviewed/2022/05/GHSA-7j42-ggv7-2p5p/GHSA-7j42-ggv7-2p5p.json @@ -7,12 +7,8 @@ "CVE-2016-6590" ], "details": "A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpoint Virtualization 7.x prior to 7.6 HF7, and Symantec Encryption Desktop 10.x prior to 10.4.1, which could let a local malicious user execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7jf8-9g4x-4g8x/GHSA-7jf8-9g4x-4g8x.json b/advisories/unreviewed/2022/05/GHSA-7jf8-9g4x-4g8x/GHSA-7jf8-9g4x-4g8x.json index a3f82f6ac68..a02534e1145 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jf8-9g4x-4g8x/GHSA-7jf8-9g4x-4g8x.json +++ b/advisories/unreviewed/2022/05/GHSA-7jf8-9g4x-4g8x/GHSA-7jf8-9g4x-4g8x.json @@ -7,12 +7,8 @@ "CVE-2019-14024" ], "details": "Possible stack-use-after-scope issue in NFC usecase for card emulation in Snapdragon Auto, Snapdragon Industrial IOT, Snapdragon Mobile in MSM8917, MSM8953, Nicobar, QM215, Rennell, SDM429, SDM439, SDM450, SDM632, SDM670, SDM710, SDM845, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7p49-67wq-cw28/GHSA-7p49-67wq-cw28.json b/advisories/unreviewed/2022/05/GHSA-7p49-67wq-cw28/GHSA-7p49-67wq-cw28.json index c55498417bd..620a3059c48 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p49-67wq-cw28/GHSA-7p49-67wq-cw28.json +++ b/advisories/unreviewed/2022/05/GHSA-7p49-67wq-cw28/GHSA-7p49-67wq-cw28.json @@ -7,12 +7,8 @@ "CVE-2020-7984" ], "details": "SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information. The attacker can use a customer ID to self register and read any aspects of the agent/appliance configuration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7pmj-9qvw-gf4w/GHSA-7pmj-9qvw-gf4w.json b/advisories/unreviewed/2022/05/GHSA-7pmj-9qvw-gf4w/GHSA-7pmj-9qvw-gf4w.json index 2689000b13b..44e1c7b002e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pmj-9qvw-gf4w/GHSA-7pmj-9qvw-gf4w.json +++ b/advisories/unreviewed/2022/05/GHSA-7pmj-9qvw-gf4w/GHSA-7pmj-9qvw-gf4w.json @@ -7,12 +7,8 @@ "CVE-2020-7215" ], "details": "An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External system configuration data (used for third party integrations such as DVR systems) were logged in the Command Centre event trail. Any authenticated operator with the 'view events' privilege could see the full configuration, including cleartext usernames and passwords, under the event details of a Modified DVR System event.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7qqq-6cxm-7rmg/GHSA-7qqq-6cxm-7rmg.json b/advisories/unreviewed/2022/05/GHSA-7qqq-6cxm-7rmg/GHSA-7qqq-6cxm-7rmg.json index 0d831dd1328..a398a0ecbcd 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qqq-6cxm-7rmg/GHSA-7qqq-6cxm-7rmg.json +++ b/advisories/unreviewed/2022/05/GHSA-7qqq-6cxm-7rmg/GHSA-7qqq-6cxm-7rmg.json @@ -7,12 +7,8 @@ "CVE-2020-3136" ], "details": "[CVE-2020-3136_su] A vulnerability in the web-based management interface of Cisco Jabber Guest could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability exists because the web-based management interface of the affected device does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or to access sensitive, browser-based information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7r2c-ch3m-w27x/GHSA-7r2c-ch3m-w27x.json b/advisories/unreviewed/2022/05/GHSA-7r2c-ch3m-w27x/GHSA-7r2c-ch3m-w27x.json index add361d5708..5e62c6c777a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7r2c-ch3m-w27x/GHSA-7r2c-ch3m-w27x.json +++ b/advisories/unreviewed/2022/05/GHSA-7r2c-ch3m-w27x/GHSA-7r2c-ch3m-w27x.json @@ -7,12 +7,8 @@ "CVE-2015-2689" ], "details": "Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7v7h-jwh9-69p4/GHSA-7v7h-jwh9-69p4.json b/advisories/unreviewed/2022/05/GHSA-7v7h-jwh9-69p4/GHSA-7v7h-jwh9-69p4.json index de494acac0e..b1681d149dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-7v7h-jwh9-69p4/GHSA-7v7h-jwh9-69p4.json +++ b/advisories/unreviewed/2022/05/GHSA-7v7h-jwh9-69p4/GHSA-7v7h-jwh9-69p4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7vq9-fwhq-w55p/GHSA-7vq9-fwhq-w55p.json b/advisories/unreviewed/2022/05/GHSA-7vq9-fwhq-w55p/GHSA-7vq9-fwhq-w55p.json index cdb35102959..970109835da 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vq9-fwhq-w55p/GHSA-7vq9-fwhq-w55p.json +++ b/advisories/unreviewed/2022/05/GHSA-7vq9-fwhq-w55p/GHSA-7vq9-fwhq-w55p.json @@ -7,12 +7,8 @@ "CVE-2018-12476" ], "details": "Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with control over a repository to overwrite files on the machine of the local user if a malicious service is executed. This issue affects: SUSE Linux Enterprise Server 15 obs-service-tar_scm versions prior to 0.9.2.1537788075.fefaa74:. openSUSE Factory obs-service-tar_scm versions prior to 0.9.2.1537788075.fefaa74.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7w65-667q-9p5w/GHSA-7w65-667q-9p5w.json b/advisories/unreviewed/2022/05/GHSA-7w65-667q-9p5w/GHSA-7w65-667q-9p5w.json index 3ec9942fa7d..6664427f038 100644 --- a/advisories/unreviewed/2022/05/GHSA-7w65-667q-9p5w/GHSA-7w65-667q-9p5w.json +++ b/advisories/unreviewed/2022/05/GHSA-7w65-667q-9p5w/GHSA-7w65-667q-9p5w.json @@ -7,12 +7,8 @@ "CVE-2019-10611" ], "details": "Buffer overflow can occur while processing clip due to lack of check of object size before parsing in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, Nicobar, QCS605, QM215, SA6155P, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7xqg-pcjp-rrvg/GHSA-7xqg-pcjp-rrvg.json b/advisories/unreviewed/2022/05/GHSA-7xqg-pcjp-rrvg/GHSA-7xqg-pcjp-rrvg.json index fcfcbf942ad..16948b1d203 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xqg-pcjp-rrvg/GHSA-7xqg-pcjp-rrvg.json +++ b/advisories/unreviewed/2022/05/GHSA-7xqg-pcjp-rrvg/GHSA-7xqg-pcjp-rrvg.json @@ -7,12 +7,8 @@ "CVE-2020-6960" ], "details": "The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch contain an SQL injection vulnerability that could give an attacker remote unauthenticated access to the web user interface with administrator-level privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-82cw-fg63-p5m3/GHSA-82cw-fg63-p5m3.json b/advisories/unreviewed/2022/05/GHSA-82cw-fg63-p5m3/GHSA-82cw-fg63-p5m3.json index 1ad77b0e902..d350ba9e061 100644 --- a/advisories/unreviewed/2022/05/GHSA-82cw-fg63-p5m3/GHSA-82cw-fg63-p5m3.json +++ b/advisories/unreviewed/2022/05/GHSA-82cw-fg63-p5m3/GHSA-82cw-fg63-p5m3.json @@ -7,12 +7,8 @@ "CVE-2008-4950" ], "details": "** DISPUTED ** gccross in dpkg-cross 2.3.0 allows local users to overwrite arbitrary files via a symlink attack on the tmp/gccross2.log temporary file. NOTE: the vendor disputes this vulnerability, stating that \"There is no sense in this bug - the script ... is called under specific cross-building environments within a chroot.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-83w3-58xf-86mr/GHSA-83w3-58xf-86mr.json b/advisories/unreviewed/2022/05/GHSA-83w3-58xf-86mr/GHSA-83w3-58xf-86mr.json index 023773b6f04..31233367797 100644 --- a/advisories/unreviewed/2022/05/GHSA-83w3-58xf-86mr/GHSA-83w3-58xf-86mr.json +++ b/advisories/unreviewed/2022/05/GHSA-83w3-58xf-86mr/GHSA-83w3-58xf-86mr.json @@ -7,12 +7,8 @@ "CVE-2019-15590" ], "details": "An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-84vc-6wwx-27rm/GHSA-84vc-6wwx-27rm.json b/advisories/unreviewed/2022/05/GHSA-84vc-6wwx-27rm/GHSA-84vc-6wwx-27rm.json index 63f42a8debb..2bcfe82fdb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-84vc-6wwx-27rm/GHSA-84vc-6wwx-27rm.json +++ b/advisories/unreviewed/2022/05/GHSA-84vc-6wwx-27rm/GHSA-84vc-6wwx-27rm.json @@ -7,12 +7,8 @@ "CVE-2010-4634" ], "details": "** DISPUTED ** Directory traversal vulnerability in osTicket 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to module.php, a different vector than CVE-2005-1439. NOTE: this issue has been disputed by a reliable third party.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8544-qhqp-jgww/GHSA-8544-qhqp-jgww.json b/advisories/unreviewed/2022/05/GHSA-8544-qhqp-jgww/GHSA-8544-qhqp-jgww.json index 97a659545e5..bf56df3cdcf 100644 --- a/advisories/unreviewed/2022/05/GHSA-8544-qhqp-jgww/GHSA-8544-qhqp-jgww.json +++ b/advisories/unreviewed/2022/05/GHSA-8544-qhqp-jgww/GHSA-8544-qhqp-jgww.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-864g-2436-49mm/GHSA-864g-2436-49mm.json b/advisories/unreviewed/2022/05/GHSA-864g-2436-49mm/GHSA-864g-2436-49mm.json index 559fa522903..92fb8926767 100644 --- a/advisories/unreviewed/2022/05/GHSA-864g-2436-49mm/GHSA-864g-2436-49mm.json +++ b/advisories/unreviewed/2022/05/GHSA-864g-2436-49mm/GHSA-864g-2436-49mm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-87jq-f9rw-6m54/GHSA-87jq-f9rw-6m54.json b/advisories/unreviewed/2022/05/GHSA-87jq-f9rw-6m54/GHSA-87jq-f9rw-6m54.json index d136e55e469..2dada1f4190 100644 --- a/advisories/unreviewed/2022/05/GHSA-87jq-f9rw-6m54/GHSA-87jq-f9rw-6m54.json +++ b/advisories/unreviewed/2022/05/GHSA-87jq-f9rw-6m54/GHSA-87jq-f9rw-6m54.json @@ -7,12 +7,8 @@ "CVE-2019-3697" ], "details": "UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of gnump3d in openSUSE Leap 15.1 allows local attackers to escalate from user gnump3d to root. This issue affects: openSUSE Leap 15.1 gnump3d version 3.0-lp151.2.1 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8879-68h8-54ph/GHSA-8879-68h8-54ph.json b/advisories/unreviewed/2022/05/GHSA-8879-68h8-54ph/GHSA-8879-68h8-54ph.json index dc56ac2ef92..2094ecdb562 100644 --- a/advisories/unreviewed/2022/05/GHSA-8879-68h8-54ph/GHSA-8879-68h8-54ph.json +++ b/advisories/unreviewed/2022/05/GHSA-8879-68h8-54ph/GHSA-8879-68h8-54ph.json @@ -7,12 +7,8 @@ "CVE-2020-7236" ], "details": "UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cw2?td= (Site Name field of the Site Setup section).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-887m-736w-hx58/GHSA-887m-736w-hx58.json b/advisories/unreviewed/2022/05/GHSA-887m-736w-hx58/GHSA-887m-736w-hx58.json index 2ca88ee1818..764bc316725 100644 --- a/advisories/unreviewed/2022/05/GHSA-887m-736w-hx58/GHSA-887m-736w-hx58.json +++ b/advisories/unreviewed/2022/05/GHSA-887m-736w-hx58/GHSA-887m-736w-hx58.json @@ -7,12 +7,8 @@ "CVE-2019-17094" ], "details": "A Stack-based Buffer Overflow vulnerability in libbelkin_api.so component of Belkin WeMo Insight Switch firmware allows a local attacker to obtain code execution on the device. This issue affects: Belkin WeMo Insight Switch firmware version 2.00.11396 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-88rm-g49p-m632/GHSA-88rm-g49p-m632.json b/advisories/unreviewed/2022/05/GHSA-88rm-g49p-m632/GHSA-88rm-g49p-m632.json index 410e02ba3dc..1f3d4084706 100644 --- a/advisories/unreviewed/2022/05/GHSA-88rm-g49p-m632/GHSA-88rm-g49p-m632.json +++ b/advisories/unreviewed/2022/05/GHSA-88rm-g49p-m632/GHSA-88rm-g49p-m632.json @@ -7,12 +7,8 @@ "CVE-2020-5519" ], "details": "The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the \"Server Configuration > External App\" screen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-894j-rjhh-8rx8/GHSA-894j-rjhh-8rx8.json b/advisories/unreviewed/2022/05/GHSA-894j-rjhh-8rx8/GHSA-894j-rjhh-8rx8.json index c575b5c8b8b..167c679ef9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-894j-rjhh-8rx8/GHSA-894j-rjhh-8rx8.json +++ b/advisories/unreviewed/2022/05/GHSA-894j-rjhh-8rx8/GHSA-894j-rjhh-8rx8.json @@ -7,12 +7,8 @@ "CVE-2016-11018" ], "details": "An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8cm8-87f4-pm26/GHSA-8cm8-87f4-pm26.json b/advisories/unreviewed/2022/05/GHSA-8cm8-87f4-pm26/GHSA-8cm8-87f4-pm26.json index aabf71fa4c7..2d05803e926 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cm8-87f4-pm26/GHSA-8cm8-87f4-pm26.json +++ b/advisories/unreviewed/2022/05/GHSA-8cm8-87f4-pm26/GHSA-8cm8-87f4-pm26.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8fvm-9x23-86pj/GHSA-8fvm-9x23-86pj.json b/advisories/unreviewed/2022/05/GHSA-8fvm-9x23-86pj/GHSA-8fvm-9x23-86pj.json index 9fbb59e9406..1f948a423b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fvm-9x23-86pj/GHSA-8fvm-9x23-86pj.json +++ b/advisories/unreviewed/2022/05/GHSA-8fvm-9x23-86pj/GHSA-8fvm-9x23-86pj.json @@ -7,12 +7,8 @@ "CVE-2019-19859" ], "details": "An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. The Add Collaborator allows unlimited data via the author parameter, even if the data does not match anything in the database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8gxh-mh59-jfvj/GHSA-8gxh-mh59-jfvj.json b/advisories/unreviewed/2022/05/GHSA-8gxh-mh59-jfvj/GHSA-8gxh-mh59-jfvj.json index 2553c456be8..423b37ddf4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gxh-mh59-jfvj/GHSA-8gxh-mh59-jfvj.json +++ b/advisories/unreviewed/2022/05/GHSA-8gxh-mh59-jfvj/GHSA-8gxh-mh59-jfvj.json @@ -7,12 +7,8 @@ "CVE-2020-0632" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0633.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hxm-3hf9-xxjx/GHSA-8hxm-3hf9-xxjx.json b/advisories/unreviewed/2022/05/GHSA-8hxm-3hf9-xxjx/GHSA-8hxm-3hf9-xxjx.json index 4c931fcbb38..f90327c096d 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hxm-3hf9-xxjx/GHSA-8hxm-3hf9-xxjx.json +++ b/advisories/unreviewed/2022/05/GHSA-8hxm-3hf9-xxjx/GHSA-8hxm-3hf9-xxjx.json @@ -7,12 +7,8 @@ "CVE-2019-4636" ], "details": "IBM Security Secret Server 10.7 could disclose sensitive information to an authenticated user from generated error messages. IBM X-Force ID: 170013.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8p3h-r9rm-jhvg/GHSA-8p3h-r9rm-jhvg.json b/advisories/unreviewed/2022/05/GHSA-8p3h-r9rm-jhvg/GHSA-8p3h-r9rm-jhvg.json index 74b1c7551e5..0e0a809359e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p3h-r9rm-jhvg/GHSA-8p3h-r9rm-jhvg.json +++ b/advisories/unreviewed/2022/05/GHSA-8p3h-r9rm-jhvg/GHSA-8p3h-r9rm-jhvg.json @@ -7,12 +7,8 @@ "CVE-2020-0650" ], "details": "A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0651, CVE-2020-0653.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8pvc-g7rq-m8cm/GHSA-8pvc-g7rq-m8cm.json b/advisories/unreviewed/2022/05/GHSA-8pvc-g7rq-m8cm/GHSA-8pvc-g7rq-m8cm.json index 2dd9bfdd3cb..c45b3b6728a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pvc-g7rq-m8cm/GHSA-8pvc-g7rq-m8cm.json +++ b/advisories/unreviewed/2022/05/GHSA-8pvc-g7rq-m8cm/GHSA-8pvc-g7rq-m8cm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8v5g-fq6x-6r4h/GHSA-8v5g-fq6x-6r4h.json b/advisories/unreviewed/2022/05/GHSA-8v5g-fq6x-6r4h/GHSA-8v5g-fq6x-6r4h.json index fe95b0d82ed..bb1109179ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v5g-fq6x-6r4h/GHSA-8v5g-fq6x-6r4h.json +++ b/advisories/unreviewed/2022/05/GHSA-8v5g-fq6x-6r4h/GHSA-8v5g-fq6x-6r4h.json @@ -7,12 +7,8 @@ "CVE-2020-7470" ], "details": "Sonoff TH 10 and 16 devices with firmware 6.6.0.21 allows XSS via the Friendly Name 1 field (after a successful login with the Web Admin Password).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8v76-643q-v8h8/GHSA-8v76-643q-v8h8.json b/advisories/unreviewed/2022/05/GHSA-8v76-643q-v8h8/GHSA-8v76-643q-v8h8.json index b04f01218eb..2501edccff4 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v76-643q-v8h8/GHSA-8v76-643q-v8h8.json +++ b/advisories/unreviewed/2022/05/GHSA-8v76-643q-v8h8/GHSA-8v76-643q-v8h8.json @@ -7,12 +7,8 @@ "CVE-2011-0736" ], "details": "** DISPUTED ** Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive information about the database structure via an id=- query to a .cfm file. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8vxr-h2m2-wf68/GHSA-8vxr-h2m2-wf68.json b/advisories/unreviewed/2022/05/GHSA-8vxr-h2m2-wf68/GHSA-8vxr-h2m2-wf68.json index 5a561f97cec..e2b0fb194d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vxr-h2m2-wf68/GHSA-8vxr-h2m2-wf68.json +++ b/advisories/unreviewed/2022/05/GHSA-8vxr-h2m2-wf68/GHSA-8vxr-h2m2-wf68.json @@ -7,12 +7,8 @@ "CVE-2019-10940" ], "details": "A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1). Incorrect session validation could allow an attacker with a valid session, with low privileges, to perform firmware updates and other administrative operations on connected devices. The security vulnerability could be exploited by an attacker with network access to the affected system. An attacker must have access to a low privileged account in order to exploit the vulnerability. An attacker could use the vulnerability to compromise confidentiality, integrity, and availability of the affected system and underlying components. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8w4x-w77h-fc8q/GHSA-8w4x-w77h-fc8q.json b/advisories/unreviewed/2022/05/GHSA-8w4x-w77h-fc8q/GHSA-8w4x-w77h-fc8q.json index 5ae8214bba2..c20c44dfb68 100644 --- a/advisories/unreviewed/2022/05/GHSA-8w4x-w77h-fc8q/GHSA-8w4x-w77h-fc8q.json +++ b/advisories/unreviewed/2022/05/GHSA-8w4x-w77h-fc8q/GHSA-8w4x-w77h-fc8q.json @@ -7,12 +7,8 @@ "CVE-2010-5182" ], "details": "** DISPUTED ** Race condition in VirusBuster Internet Security Suite 3.2 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8wj2-ww8w-44pr/GHSA-8wj2-ww8w-44pr.json b/advisories/unreviewed/2022/05/GHSA-8wj2-ww8w-44pr/GHSA-8wj2-ww8w-44pr.json index 6df60999a7a..a1ae56bbf0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wj2-ww8w-44pr/GHSA-8wj2-ww8w-44pr.json +++ b/advisories/unreviewed/2022/05/GHSA-8wj2-ww8w-44pr/GHSA-8wj2-ww8w-44pr.json @@ -7,12 +7,8 @@ "CVE-2020-1608" ], "details": "Receipt of a specific MPLS or IPv6 packet on the core facing interface of an MX Series device configured for Broadband Edge (BBE) service may trigger a kernel crash (vmcore), causing the device to reboot. The issue is specific to the processing of packets destined to BBE clients connected to MX Series subscriber management platforms. This issue affects MX Series running Juniper Networks Junos OS: 17.2 versions starting from17.2R2-S6, 17.2R3 and later releases, prior to 17.2R3-S3; 17.3 versions starting from 17.3R2-S4, 17.3R3-S2 and later releases, prior to 17.3R2-S5, 17.3R3-S5; 17.4 versions starting from 17.4R2 and later releases, prior to 17.4R2-S7,17.4R3; 18.1 versions starting from 18.1R2-S3, 18.1R3 and later releases, prior to 18.1R3-S6; 18.2 versions starting from18.2R1-S1, 18.2R2 and later releases, prior to 18.2R3-S2; 18.2X75 versions prior to 18.2X75-D51, 18.2X75-D60; 18.3 versions prior to 18.3R3; 18.4 versions prior to 18.4R2; 19.1 versions prior to 19.1R1-S3, 19.1R2; 19.2 versions prior to 19.2R1-S2, 19.2R2. This issue does not affect Juniper Networks Junos OS versions prior to 17.2R2-S6.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xjw-mv36-c7hq/GHSA-8xjw-mv36-c7hq.json b/advisories/unreviewed/2022/05/GHSA-8xjw-mv36-c7hq/GHSA-8xjw-mv36-c7hq.json index bb5a2852bcd..f47ba7c5049 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xjw-mv36-c7hq/GHSA-8xjw-mv36-c7hq.json +++ b/advisories/unreviewed/2022/05/GHSA-8xjw-mv36-c7hq/GHSA-8xjw-mv36-c7hq.json @@ -7,12 +7,8 @@ "CVE-2011-1652" ], "details": "** DISPUTED ** The default configuration of Microsoft Windows 7 immediately prefers a new IPv6 and DHCPv6 service over a currently used IPv4 and DHCPv4 service upon receipt of an IPv6 Router Advertisement (RA), and does not provide an option to ignore an unexpected RA, which allows remote attackers to conduct man-in-the-middle attacks on communication with external IPv4 servers via vectors involving RAs, a DHCPv6 server, and NAT-PT on the local network, aka a \"SLAAC Attack.\" NOTE: it can be argued that preferring IPv6 complies with RFC 3484, and that attempting to determine the legitimacy of an RA is currently outside the scope of recommended behavior of host operating systems.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8xr4-h8j2-5f7x/GHSA-8xr4-h8j2-5f7x.json b/advisories/unreviewed/2022/05/GHSA-8xr4-h8j2-5f7x/GHSA-8xr4-h8j2-5f7x.json index ad2b213c0c1..29deb2a3403 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xr4-h8j2-5f7x/GHSA-8xr4-h8j2-5f7x.json +++ b/advisories/unreviewed/2022/05/GHSA-8xr4-h8j2-5f7x/GHSA-8xr4-h8j2-5f7x.json @@ -7,12 +7,8 @@ "CVE-2020-2579" ], "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.46 and prior, 5.7.28 and prior and 8.0.18 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8xv3-84rr-j23r/GHSA-8xv3-84rr-j23r.json b/advisories/unreviewed/2022/05/GHSA-8xv3-84rr-j23r/GHSA-8xv3-84rr-j23r.json index 1f8645aa4dc..67c02215813 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xv3-84rr-j23r/GHSA-8xv3-84rr-j23r.json +++ b/advisories/unreviewed/2022/05/GHSA-8xv3-84rr-j23r/GHSA-8xv3-84rr-j23r.json @@ -7,12 +7,8 @@ "CVE-2019-14767" ], "details": "In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an unauthenticated user to download arbitrary files from the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9478-pvwh-fmh7/GHSA-9478-pvwh-fmh7.json b/advisories/unreviewed/2022/05/GHSA-9478-pvwh-fmh7/GHSA-9478-pvwh-fmh7.json index 0f03abccfa5..85a5ac9f5f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9478-pvwh-fmh7/GHSA-9478-pvwh-fmh7.json +++ b/advisories/unreviewed/2022/05/GHSA-9478-pvwh-fmh7/GHSA-9478-pvwh-fmh7.json @@ -7,12 +7,8 @@ "CVE-2020-3129" ], "details": "A vulnerability in the web-based management interface of Cisco Unity Connection Software could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by providing crafted data to a specific field within the interface. A successful exploit could allow the attacker to store an XSS attack within the interface. This stored XSS attack would then be executed on the system of any user viewing the attacker-supplied data element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-94gx-rm2c-cw59/GHSA-94gx-rm2c-cw59.json b/advisories/unreviewed/2022/05/GHSA-94gx-rm2c-cw59/GHSA-94gx-rm2c-cw59.json index 54d61ed9f86..8f22a9a446c 100644 --- a/advisories/unreviewed/2022/05/GHSA-94gx-rm2c-cw59/GHSA-94gx-rm2c-cw59.json +++ b/advisories/unreviewed/2022/05/GHSA-94gx-rm2c-cw59/GHSA-94gx-rm2c-cw59.json @@ -7,12 +7,8 @@ "CVE-2017-14806" ], "details": "A Improper Certificate Validation vulnerability in susestudio-common of SUSE Studio onsite allows remote attackers to MITM connections to the repositories, which allows the modification of packages received over these connections. This issue affects: SUSE Studio onsite susestudio-common version 1.3.17-56.6.3 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-955r-cpqg-mww2/GHSA-955r-cpqg-mww2.json b/advisories/unreviewed/2022/05/GHSA-955r-cpqg-mww2/GHSA-955r-cpqg-mww2.json index efda675016d..85ab017580d 100644 --- a/advisories/unreviewed/2022/05/GHSA-955r-cpqg-mww2/GHSA-955r-cpqg-mww2.json +++ b/advisories/unreviewed/2022/05/GHSA-955r-cpqg-mww2/GHSA-955r-cpqg-mww2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-966j-527f-vmhp/GHSA-966j-527f-vmhp.json b/advisories/unreviewed/2022/05/GHSA-966j-527f-vmhp/GHSA-966j-527f-vmhp.json index d4472f4486c..1b45e28cce2 100644 --- a/advisories/unreviewed/2022/05/GHSA-966j-527f-vmhp/GHSA-966j-527f-vmhp.json +++ b/advisories/unreviewed/2022/05/GHSA-966j-527f-vmhp/GHSA-966j-527f-vmhp.json @@ -7,12 +7,8 @@ "CVE-2010-5184" ], "details": "** DISPUTED ** Race condition in ZoneAlarm Extreme Security 9.1.507.000 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96rx-5v24-ww2j/GHSA-96rx-5v24-ww2j.json b/advisories/unreviewed/2022/05/GHSA-96rx-5v24-ww2j/GHSA-96rx-5v24-ww2j.json index 39ba96568b7..5670fdc1482 100644 --- a/advisories/unreviewed/2022/05/GHSA-96rx-5v24-ww2j/GHSA-96rx-5v24-ww2j.json +++ b/advisories/unreviewed/2022/05/GHSA-96rx-5v24-ww2j/GHSA-96rx-5v24-ww2j.json @@ -7,12 +7,8 @@ "CVE-2020-2627" ], "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.18 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-97v5-ggfx-g9wc/GHSA-97v5-ggfx-g9wc.json b/advisories/unreviewed/2022/05/GHSA-97v5-ggfx-g9wc/GHSA-97v5-ggfx-g9wc.json index f448e1c50f7..2f074453d5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-97v5-ggfx-g9wc/GHSA-97v5-ggfx-g9wc.json +++ b/advisories/unreviewed/2022/05/GHSA-97v5-ggfx-g9wc/GHSA-97v5-ggfx-g9wc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-988r-vp4w-29jx/GHSA-988r-vp4w-29jx.json b/advisories/unreviewed/2022/05/GHSA-988r-vp4w-29jx/GHSA-988r-vp4w-29jx.json index 6094ea36408..0b0c92e9299 100644 --- a/advisories/unreviewed/2022/05/GHSA-988r-vp4w-29jx/GHSA-988r-vp4w-29jx.json +++ b/advisories/unreviewed/2022/05/GHSA-988r-vp4w-29jx/GHSA-988r-vp4w-29jx.json @@ -7,12 +7,8 @@ "CVE-2010-5154" ], "details": "** DISPUTED ** Race condition in BitDefender Total Security 2010 13.0.20.347 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-98j3-78m4-jv68/GHSA-98j3-78m4-jv68.json b/advisories/unreviewed/2022/05/GHSA-98j3-78m4-jv68/GHSA-98j3-78m4-jv68.json index 279d3f369eb..9df87c718dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-98j3-78m4-jv68/GHSA-98j3-78m4-jv68.json +++ b/advisories/unreviewed/2022/05/GHSA-98j3-78m4-jv68/GHSA-98j3-78m4-jv68.json @@ -7,12 +7,8 @@ "CVE-2020-1788" ], "details": "Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) have an improper authentication vulnerability. Certain applications do not properly validate the identity of another application who would call its interface. An attacker could trick the user into installing a malicious application. Successful exploit could allow unauthorized actions leading to information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-98q7-c95r-v6vr/GHSA-98q7-c95r-v6vr.json b/advisories/unreviewed/2022/05/GHSA-98q7-c95r-v6vr/GHSA-98q7-c95r-v6vr.json index 5f99a45edc3..d5f28f6c6ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-98q7-c95r-v6vr/GHSA-98q7-c95r-v6vr.json +++ b/advisories/unreviewed/2022/05/GHSA-98q7-c95r-v6vr/GHSA-98q7-c95r-v6vr.json @@ -7,12 +7,8 @@ "CVE-2020-2588" ], "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-993f-36vw-6mhm/GHSA-993f-36vw-6mhm.json b/advisories/unreviewed/2022/05/GHSA-993f-36vw-6mhm/GHSA-993f-36vw-6mhm.json index c33006a7681..0649fd9784a 100644 --- a/advisories/unreviewed/2022/05/GHSA-993f-36vw-6mhm/GHSA-993f-36vw-6mhm.json +++ b/advisories/unreviewed/2022/05/GHSA-993f-36vw-6mhm/GHSA-993f-36vw-6mhm.json @@ -7,12 +7,8 @@ "CVE-2019-1349" ], "details": "A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-99mh-g2rh-jprg/GHSA-99mh-g2rh-jprg.json b/advisories/unreviewed/2022/05/GHSA-99mh-g2rh-jprg/GHSA-99mh-g2rh-jprg.json index f029f18d3f3..d8ba1e4c3c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-99mh-g2rh-jprg/GHSA-99mh-g2rh-jprg.json +++ b/advisories/unreviewed/2022/05/GHSA-99mh-g2rh-jprg/GHSA-99mh-g2rh-jprg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-99p3-qvxh-qjqh/GHSA-99p3-qvxh-qjqh.json b/advisories/unreviewed/2022/05/GHSA-99p3-qvxh-qjqh/GHSA-99p3-qvxh-qjqh.json index 52af0ce8fa9..0ff4c0eff63 100644 --- a/advisories/unreviewed/2022/05/GHSA-99p3-qvxh-qjqh/GHSA-99p3-qvxh-qjqh.json +++ b/advisories/unreviewed/2022/05/GHSA-99p3-qvxh-qjqh/GHSA-99p3-qvxh-qjqh.json @@ -7,12 +7,8 @@ "CVE-2020-7239" ], "details": "The conversation-watson plugin before 0.8.21 for WordPress has a DOM-based XSS vulnerability that is executed when a chat message containing JavaScript is sent.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9f6m-8x44-j5mr/GHSA-9f6m-8x44-j5mr.json b/advisories/unreviewed/2022/05/GHSA-9f6m-8x44-j5mr/GHSA-9f6m-8x44-j5mr.json index 763fb44e6b2..9ebb18e7868 100644 --- a/advisories/unreviewed/2022/05/GHSA-9f6m-8x44-j5mr/GHSA-9f6m-8x44-j5mr.json +++ b/advisories/unreviewed/2022/05/GHSA-9f6m-8x44-j5mr/GHSA-9f6m-8x44-j5mr.json @@ -7,12 +7,8 @@ "CVE-2020-7047" ], "details": "The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a simple wp-admin/admin.php?db-reset-tables[]=users request) to escalate their privileges to administrator while dropping all other users from the table.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9fh4-qmm7-wrrj/GHSA-9fh4-qmm7-wrrj.json b/advisories/unreviewed/2022/05/GHSA-9fh4-qmm7-wrrj/GHSA-9fh4-qmm7-wrrj.json index dac78e26572..8b1a322b023 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fh4-qmm7-wrrj/GHSA-9fh4-qmm7-wrrj.json +++ b/advisories/unreviewed/2022/05/GHSA-9fh4-qmm7-wrrj/GHSA-9fh4-qmm7-wrrj.json @@ -7,12 +7,8 @@ "CVE-2013-3926" ], "details": "** DISPUTED ** Atlassian Crowd 2.6.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to a \"symmetric backdoor.\" NOTE: as of 20130704, the vendor could not reproduce the issue, stating \"We've been unable to substantiate the existence of [CVE-2013-3926]. The author of the article has not contacted Atlassian and has provided no detail, making it difficult to validate the claim... If we can confirm that there is a vulnerability, a patch will be issued.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9fwv-5489-f4p3/GHSA-9fwv-5489-f4p3.json b/advisories/unreviewed/2022/05/GHSA-9fwv-5489-f4p3/GHSA-9fwv-5489-f4p3.json index ff9a28a95f9..034193fb9ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fwv-5489-f4p3/GHSA-9fwv-5489-f4p3.json +++ b/advisories/unreviewed/2022/05/GHSA-9fwv-5489-f4p3/GHSA-9fwv-5489-f4p3.json @@ -7,12 +7,8 @@ "CVE-2019-20426" ], "details": "In the Lustre file system before 2.12.3, the ptlrpc module has an out-of-bounds access and panic due to the lack of validation for specific fields of packets sent by a client. In the function ldlm_cancel_hpreq_check, there is no lock_count bounds check.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9h72-qxgr-5j87/GHSA-9h72-qxgr-5j87.json b/advisories/unreviewed/2022/05/GHSA-9h72-qxgr-5j87/GHSA-9h72-qxgr-5j87.json index 563cb952b42..4f1f9b63b4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9h72-qxgr-5j87/GHSA-9h72-qxgr-5j87.json +++ b/advisories/unreviewed/2022/05/GHSA-9h72-qxgr-5j87/GHSA-9h72-qxgr-5j87.json @@ -7,12 +7,8 @@ "CVE-2015-2688" ], "details": "buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layouts, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9hjc-v342-97r7/GHSA-9hjc-v342-97r7.json b/advisories/unreviewed/2022/05/GHSA-9hjc-v342-97r7/GHSA-9hjc-v342-97r7.json index 11918dfc805..6a95e78074a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hjc-v342-97r7/GHSA-9hjc-v342-97r7.json +++ b/advisories/unreviewed/2022/05/GHSA-9hjc-v342-97r7/GHSA-9hjc-v342-97r7.json @@ -7,12 +7,8 @@ "CVE-2016-6587" ], "details": "An Information Disclosure vulnerability exists in the mid.dat file stored on the SD card in Symantec Norton Mobile Security for Android before 3.16, which could let a local malicious user obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9mmr-pqm2-6vvf/GHSA-9mmr-pqm2-6vvf.json b/advisories/unreviewed/2022/05/GHSA-9mmr-pqm2-6vvf/GHSA-9mmr-pqm2-6vvf.json index d078525ea2e..0f4419bebb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mmr-pqm2-6vvf/GHSA-9mmr-pqm2-6vvf.json +++ b/advisories/unreviewed/2022/05/GHSA-9mmr-pqm2-6vvf/GHSA-9mmr-pqm2-6vvf.json @@ -7,12 +7,8 @@ "CVE-2020-8090" ], "details": "The Username field in the Storage Service settings of A1 WLAN Box ADB VV2220v2 devices allows stored XSS (after a successful Administrator login).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9q4w-jmgx-6765/GHSA-9q4w-jmgx-6765.json b/advisories/unreviewed/2022/05/GHSA-9q4w-jmgx-6765/GHSA-9q4w-jmgx-6765.json index cab32780def..04e7585d1f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q4w-jmgx-6765/GHSA-9q4w-jmgx-6765.json +++ b/advisories/unreviewed/2022/05/GHSA-9q4w-jmgx-6765/GHSA-9q4w-jmgx-6765.json @@ -7,12 +7,8 @@ "CVE-2010-5161" ], "details": "** DISPUTED ** Race condition in F-Secure Internet Security 2010 10.00 build 246 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9q57-prxv-8v77/GHSA-9q57-prxv-8v77.json b/advisories/unreviewed/2022/05/GHSA-9q57-prxv-8v77/GHSA-9q57-prxv-8v77.json index 5d61530a012..7b50a22e21e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q57-prxv-8v77/GHSA-9q57-prxv-8v77.json +++ b/advisories/unreviewed/2022/05/GHSA-9q57-prxv-8v77/GHSA-9q57-prxv-8v77.json @@ -7,12 +7,8 @@ "CVE-2019-14601" ], "details": "Improper permissions in the installer for Intel(R) RWC 3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9q7r-hh98-v46j/GHSA-9q7r-hh98-v46j.json b/advisories/unreviewed/2022/05/GHSA-9q7r-hh98-v46j/GHSA-9q7r-hh98-v46j.json index ddd70e28e02..b9e784d22b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q7r-hh98-v46j/GHSA-9q7r-hh98-v46j.json +++ b/advisories/unreviewed/2022/05/GHSA-9q7r-hh98-v46j/GHSA-9q7r-hh98-v46j.json @@ -7,12 +7,8 @@ "CVE-2020-2593" ], "details": "Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data as well as unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -124,9 +120,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9qf5-mg9m-h7pc/GHSA-9qf5-mg9m-h7pc.json b/advisories/unreviewed/2022/05/GHSA-9qf5-mg9m-h7pc/GHSA-9qf5-mg9m-h7pc.json index e2a5f2b84bd..a49f87df10c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qf5-mg9m-h7pc/GHSA-9qf5-mg9m-h7pc.json +++ b/advisories/unreviewed/2022/05/GHSA-9qf5-mg9m-h7pc/GHSA-9qf5-mg9m-h7pc.json @@ -7,12 +7,8 @@ "CVE-2012-3372" ], "details": "** DISPUTED ** The default configuration of Cyberoam UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Cyberoam_SSL_CA certificate in a list of trusted root certification authorities. NOTE: the vendor disputes the significance of this issue because the appliance \"does not allow import or export of the foresaid private key.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9qf5-wrp4-x43x/GHSA-9qf5-wrp4-x43x.json b/advisories/unreviewed/2022/05/GHSA-9qf5-wrp4-x43x/GHSA-9qf5-wrp4-x43x.json index dcbf07effa2..87804e66dd6 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qf5-wrp4-x43x/GHSA-9qf5-wrp4-x43x.json +++ b/advisories/unreviewed/2022/05/GHSA-9qf5-wrp4-x43x/GHSA-9qf5-wrp4-x43x.json @@ -7,12 +7,8 @@ "CVE-2020-5512" ], "details": "Gila CMS 1.11.8 allows /admin/media?path=../ Path Traversal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9rrp-35hw-cq78/GHSA-9rrp-35hw-cq78.json b/advisories/unreviewed/2022/05/GHSA-9rrp-35hw-cq78/GHSA-9rrp-35hw-cq78.json index f9ecf45c274..6deb1cbc11d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rrp-35hw-cq78/GHSA-9rrp-35hw-cq78.json +++ b/advisories/unreviewed/2022/05/GHSA-9rrp-35hw-cq78/GHSA-9rrp-35hw-cq78.json @@ -7,12 +7,8 @@ "CVE-2019-19838" ], "details": "emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=get-platform-depends to admin/_cmdstat.jsp via the uploadFile attribute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9wx3-2vc8-j97r/GHSA-9wx3-2vc8-j97r.json b/advisories/unreviewed/2022/05/GHSA-9wx3-2vc8-j97r/GHSA-9wx3-2vc8-j97r.json index decc3817874..467d04d6821 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wx3-2vc8-j97r/GHSA-9wx3-2vc8-j97r.json +++ b/advisories/unreviewed/2022/05/GHSA-9wx3-2vc8-j97r/GHSA-9wx3-2vc8-j97r.json @@ -7,12 +7,8 @@ "CVE-2016-6589" ], "details": "A Denial of Service vulnerability exists in the ITMS workflow process manager login window in Symantec IT Management Suite 8.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c2m7-2r7v-phq7/GHSA-c2m7-2r7v-phq7.json b/advisories/unreviewed/2022/05/GHSA-c2m7-2r7v-phq7/GHSA-c2m7-2r7v-phq7.json index 91403696663..867c424a869 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2m7-2r7v-phq7/GHSA-c2m7-2r7v-phq7.json +++ b/advisories/unreviewed/2022/05/GHSA-c2m7-2r7v-phq7/GHSA-c2m7-2r7v-phq7.json @@ -7,12 +7,8 @@ "CVE-2008-4998" ], "details": "** DISPUTED ** postinst in twiki 4.1.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/twiki temporary file. NOTE: the vendor disputes this vulnerability, stating \"this bug is invalid.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c3r6-j8rq-qj38/GHSA-c3r6-j8rq-qj38.json b/advisories/unreviewed/2022/05/GHSA-c3r6-j8rq-qj38/GHSA-c3r6-j8rq-qj38.json index 3ff3eb31593..b80a3a9d46e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3r6-j8rq-qj38/GHSA-c3r6-j8rq-qj38.json +++ b/advisories/unreviewed/2022/05/GHSA-c3r6-j8rq-qj38/GHSA-c3r6-j8rq-qj38.json @@ -7,12 +7,8 @@ "CVE-2019-15625" ], "details": "A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c3xg-pxh8-c9cg/GHSA-c3xg-pxh8-c9cg.json b/advisories/unreviewed/2022/05/GHSA-c3xg-pxh8-c9cg/GHSA-c3xg-pxh8-c9cg.json index e9581beea7a..38ef6ffd441 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3xg-pxh8-c9cg/GHSA-c3xg-pxh8-c9cg.json +++ b/advisories/unreviewed/2022/05/GHSA-c3xg-pxh8-c9cg/GHSA-c3xg-pxh8-c9cg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c5cf-6rq6-7pqr/GHSA-c5cf-6rq6-7pqr.json b/advisories/unreviewed/2022/05/GHSA-c5cf-6rq6-7pqr/GHSA-c5cf-6rq6-7pqr.json index 0048bf1861a..8780eeebe3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5cf-6rq6-7pqr/GHSA-c5cf-6rq6-7pqr.json +++ b/advisories/unreviewed/2022/05/GHSA-c5cf-6rq6-7pqr/GHSA-c5cf-6rq6-7pqr.json @@ -7,12 +7,8 @@ "CVE-2020-2690" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c5vp-96m5-r7fj/GHSA-c5vp-96m5-r7fj.json b/advisories/unreviewed/2022/05/GHSA-c5vp-96m5-r7fj/GHSA-c5vp-96m5-r7fj.json index e8fc2560cad..e22fa2b523f 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5vp-96m5-r7fj/GHSA-c5vp-96m5-r7fj.json +++ b/advisories/unreviewed/2022/05/GHSA-c5vp-96m5-r7fj/GHSA-c5vp-96m5-r7fj.json @@ -7,12 +7,8 @@ "CVE-2020-2577" ], "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.28 and prior and 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c6jh-8rwf-cj9m/GHSA-c6jh-8rwf-cj9m.json b/advisories/unreviewed/2022/05/GHSA-c6jh-8rwf-cj9m/GHSA-c6jh-8rwf-cj9m.json index 44317a44006..98b6a9d13a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6jh-8rwf-cj9m/GHSA-c6jh-8rwf-cj9m.json +++ b/advisories/unreviewed/2022/05/GHSA-c6jh-8rwf-cj9m/GHSA-c6jh-8rwf-cj9m.json @@ -7,12 +7,8 @@ "CVE-2019-14013" ], "details": "While parsing invalid super index table, elements within super index table may exceed total chunk size and invalid data is read into the table in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, Nicobar, QCM2150, QCS405, QCS605, QM215, Rennell, SA6155P, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c7g9-8j3x-8262/GHSA-c7g9-8j3x-8262.json b/advisories/unreviewed/2022/05/GHSA-c7g9-8j3x-8262/GHSA-c7g9-8j3x-8262.json index 217efbcca94..c0bfaec2392 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7g9-8j3x-8262/GHSA-c7g9-8j3x-8262.json +++ b/advisories/unreviewed/2022/05/GHSA-c7g9-8j3x-8262/GHSA-c7g9-8j3x-8262.json @@ -7,12 +7,8 @@ "CVE-2019-10558" ], "details": "While transferring data from APPS to DSP, Out of bound in FastRPC HLOS Driver due to the data buffer which can be controlled by DSP in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCN7605, QCS605, QM215, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SDX24, SDX55, SM6150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c7x9-8r9r-p4q3/GHSA-c7x9-8r9r-p4q3.json b/advisories/unreviewed/2022/05/GHSA-c7x9-8r9r-p4q3/GHSA-c7x9-8r9r-p4q3.json index 5b107cc8630..9d11c8ec50b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7x9-8r9r-p4q3/GHSA-c7x9-8r9r-p4q3.json +++ b/advisories/unreviewed/2022/05/GHSA-c7x9-8r9r-p4q3/GHSA-c7x9-8r9r-p4q3.json @@ -7,12 +7,8 @@ "CVE-2019-19842" ], "details": "emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=spectra-analysis to admin/_cmdstat.jsp via the mac attribute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c89p-wjj4-mr4g/GHSA-c89p-wjj4-mr4g.json b/advisories/unreviewed/2022/05/GHSA-c89p-wjj4-mr4g/GHSA-c89p-wjj4-mr4g.json index dbe882d5e4a..80a2c374aee 100644 --- a/advisories/unreviewed/2022/05/GHSA-c89p-wjj4-mr4g/GHSA-c89p-wjj4-mr4g.json +++ b/advisories/unreviewed/2022/05/GHSA-c89p-wjj4-mr4g/GHSA-c89p-wjj4-mr4g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c959-w274-v6px/GHSA-c959-w274-v6px.json b/advisories/unreviewed/2022/05/GHSA-c959-w274-v6px/GHSA-c959-w274-v6px.json index 8fd38775627..daef25eae1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c959-w274-v6px/GHSA-c959-w274-v6px.json +++ b/advisories/unreviewed/2022/05/GHSA-c959-w274-v6px/GHSA-c959-w274-v6px.json @@ -7,12 +7,8 @@ "CVE-2019-14600" ], "details": "Uncontrolled search path element in the installer for Intel(R) SNMP Subagent Stand-Alone for Windows* may allow an authenticated user to potentially enable escalation of privilege via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cc4p-4xpf-wqh4/GHSA-cc4p-4xpf-wqh4.json b/advisories/unreviewed/2022/05/GHSA-cc4p-4xpf-wqh4/GHSA-cc4p-4xpf-wqh4.json index 20edd256bb1..4f05b1ad469 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc4p-4xpf-wqh4/GHSA-cc4p-4xpf-wqh4.json +++ b/advisories/unreviewed/2022/05/GHSA-cc4p-4xpf-wqh4/GHSA-cc4p-4xpf-wqh4.json @@ -7,12 +7,8 @@ "CVE-2020-2584" ], "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 5.7.28 and prior and 8.0.18 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.0 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cf2f-f2vm-48vp/GHSA-cf2f-f2vm-48vp.json b/advisories/unreviewed/2022/05/GHSA-cf2f-f2vm-48vp/GHSA-cf2f-f2vm-48vp.json index 630e91e4e7d..c2462899972 100644 --- a/advisories/unreviewed/2022/05/GHSA-cf2f-f2vm-48vp/GHSA-cf2f-f2vm-48vp.json +++ b/advisories/unreviewed/2022/05/GHSA-cf2f-f2vm-48vp/GHSA-cf2f-f2vm-48vp.json @@ -7,12 +7,8 @@ "CVE-2019-3686" ], "details": "openQA before commit c172e8883d8f32fced5e02f9b6faaacc913df27b was vulnerable to XSS in the distri and version parameter. This was reported through the bug bounty program of Offensive Security", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cgw7-3hvq-6672/GHSA-cgw7-3hvq-6672.json b/advisories/unreviewed/2022/05/GHSA-cgw7-3hvq-6672/GHSA-cgw7-3hvq-6672.json index f2f90efc1fe..4d6f025b6d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgw7-3hvq-6672/GHSA-cgw7-3hvq-6672.json +++ b/advisories/unreviewed/2022/05/GHSA-cgw7-3hvq-6672/GHSA-cgw7-3hvq-6672.json @@ -7,12 +7,8 @@ "CVE-2019-14014" ], "details": "Possible buffer overflow when byte array receives incorrect input from reading source as array is not null terminated in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in Nicobar, SDM670, SDM710, SDM845, SM6150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cgxm-wh93-rcjc/GHSA-cgxm-wh93-rcjc.json b/advisories/unreviewed/2022/05/GHSA-cgxm-wh93-rcjc/GHSA-cgxm-wh93-rcjc.json index 3ff4466dc0f..99eca6d2a69 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgxm-wh93-rcjc/GHSA-cgxm-wh93-rcjc.json +++ b/advisories/unreviewed/2022/05/GHSA-cgxm-wh93-rcjc/GHSA-cgxm-wh93-rcjc.json @@ -7,12 +7,8 @@ "CVE-2019-1454" ], "details": "An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ch5h-mq67-vq6m/GHSA-ch5h-mq67-vq6m.json b/advisories/unreviewed/2022/05/GHSA-ch5h-mq67-vq6m/GHSA-ch5h-mq67-vq6m.json index 6304b822dba..2546604c16c 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch5h-mq67-vq6m/GHSA-ch5h-mq67-vq6m.json +++ b/advisories/unreviewed/2022/05/GHSA-ch5h-mq67-vq6m/GHSA-ch5h-mq67-vq6m.json @@ -7,12 +7,8 @@ "CVE-2018-16268" ], "details": "The SoundServer/FocusServer system services in Tizen allow an unprivileged process to perform media-related system actions, due to improper D-Bus security policy configurations. Such actions include playing an arbitrary sound file or DTMF tones. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ch83-44qh-wvxh/GHSA-ch83-44qh-wvxh.json b/advisories/unreviewed/2022/05/GHSA-ch83-44qh-wvxh/GHSA-ch83-44qh-wvxh.json index 9236c260fc1..abae7538517 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch83-44qh-wvxh/GHSA-ch83-44qh-wvxh.json +++ b/advisories/unreviewed/2022/05/GHSA-ch83-44qh-wvxh/GHSA-ch83-44qh-wvxh.json @@ -7,12 +7,8 @@ "CVE-2019-4631" ], "details": "IBM Security Secret Server 10.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 170001.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ch8v-p7rq-6xjw/GHSA-ch8v-p7rq-6xjw.json b/advisories/unreviewed/2022/05/GHSA-ch8v-p7rq-6xjw/GHSA-ch8v-p7rq-6xjw.json index 3d6f0b7c81d..7c0aa5f27e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch8v-p7rq-6xjw/GHSA-ch8v-p7rq-6xjw.json +++ b/advisories/unreviewed/2022/05/GHSA-ch8v-p7rq-6xjw/GHSA-ch8v-p7rq-6xjw.json @@ -7,12 +7,8 @@ "CVE-2019-14005" ], "details": "Buffer overflow occur while playing the clip which is nonstandard due to lack of check of size duration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, Nicobar, QCS605, QM215, Rennell, SA6155P, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cjvq-wqgq-vw9c/GHSA-cjvq-wqgq-vw9c.json b/advisories/unreviewed/2022/05/GHSA-cjvq-wqgq-vw9c/GHSA-cjvq-wqgq-vw9c.json index 06bbb2fb503..19da8350fd9 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjvq-wqgq-vw9c/GHSA-cjvq-wqgq-vw9c.json +++ b/advisories/unreviewed/2022/05/GHSA-cjvq-wqgq-vw9c/GHSA-cjvq-wqgq-vw9c.json @@ -7,12 +7,8 @@ "CVE-2019-14034" ], "details": "Use after free while processing eeprom query as there is a chance to not unlock mutex after error occurs in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8053, MSM8909W, MSM8917, MSM8953, Nicobar, QCS605, QM215, Rennell, SA6155P, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM670, SDM710, SDM845, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cm4v-gmv6-gf76/GHSA-cm4v-gmv6-gf76.json b/advisories/unreviewed/2022/05/GHSA-cm4v-gmv6-gf76/GHSA-cm4v-gmv6-gf76.json index 98728e0c5f9..9a6cfd2db95 100644 --- a/advisories/unreviewed/2022/05/GHSA-cm4v-gmv6-gf76/GHSA-cm4v-gmv6-gf76.json +++ b/advisories/unreviewed/2022/05/GHSA-cm4v-gmv6-gf76/GHSA-cm4v-gmv6-gf76.json @@ -7,12 +7,8 @@ "CVE-2020-7107" ], "details": "The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cmgf-vp4c-gh93/GHSA-cmgf-vp4c-gh93.json b/advisories/unreviewed/2022/05/GHSA-cmgf-vp4c-gh93/GHSA-cmgf-vp4c-gh93.json index a50c4c94e66..8d13b583d77 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmgf-vp4c-gh93/GHSA-cmgf-vp4c-gh93.json +++ b/advisories/unreviewed/2022/05/GHSA-cmgf-vp4c-gh93/GHSA-cmgf-vp4c-gh93.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cp35-58g8-mpmh/GHSA-cp35-58g8-mpmh.json b/advisories/unreviewed/2022/05/GHSA-cp35-58g8-mpmh/GHSA-cp35-58g8-mpmh.json index 4b1667ae0a1..143864f98ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-cp35-58g8-mpmh/GHSA-cp35-58g8-mpmh.json +++ b/advisories/unreviewed/2022/05/GHSA-cp35-58g8-mpmh/GHSA-cp35-58g8-mpmh.json @@ -7,12 +7,8 @@ "CVE-2019-20003" ], "details": "Feldtech easescreen Crystal 9.0 Web-Services 9.0.1.16265 allows Stored XSS via the Debug-Log and Display-Log components. This could be exploited when an attacker sends an crafted string for FTP authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cq7c-qhjc-7fr5/GHSA-cq7c-qhjc-7fr5.json b/advisories/unreviewed/2022/05/GHSA-cq7c-qhjc-7fr5/GHSA-cq7c-qhjc-7fr5.json index 567d6c4cab7..d8199e56221 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq7c-qhjc-7fr5/GHSA-cq7c-qhjc-7fr5.json +++ b/advisories/unreviewed/2022/05/GHSA-cq7c-qhjc-7fr5/GHSA-cq7c-qhjc-7fr5.json @@ -7,12 +7,8 @@ "CVE-2019-10578" ], "details": "Null pointer dereference can occur while parsing the clip which is nonstandard in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA6574AU, QCS605, QM215, Rennell, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cqpw-5cch-w85g/GHSA-cqpw-5cch-w85g.json b/advisories/unreviewed/2022/05/GHSA-cqpw-5cch-w85g/GHSA-cqpw-5cch-w85g.json index d7ad26081b0..8cd0371b42e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqpw-5cch-w85g/GHSA-cqpw-5cch-w85g.json +++ b/advisories/unreviewed/2022/05/GHSA-cqpw-5cch-w85g/GHSA-cqpw-5cch-w85g.json @@ -7,12 +7,8 @@ "CVE-2012-5381" ], "details": "** DISPUTED ** Untrusted search path vulnerability in the installation functionality in PHP 5.3.17, when installed in the top-level C:\\ directory, might allow local users to gain privileges via a Trojan horse DLL in the C:\\PHP directory, which may be added to the PATH system environment variable by an administrator, as demonstrated by a Trojan horse wlbsctrl.dll file used by the \"IKE and AuthIP IPsec Keying Modules\" system service in Windows Vista SP1, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 Release Preview. NOTE: CVE disputes this issue because the unsafe PATH is established only by a separate administrative action that is not a default part of the PHP installation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cr83-c6wf-x27w/GHSA-cr83-c6wf-x27w.json b/advisories/unreviewed/2022/05/GHSA-cr83-c6wf-x27w/GHSA-cr83-c6wf-x27w.json index 90bddb31dab..81af56fe6d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-cr83-c6wf-x27w/GHSA-cr83-c6wf-x27w.json +++ b/advisories/unreviewed/2022/05/GHSA-cr83-c6wf-x27w/GHSA-cr83-c6wf-x27w.json @@ -7,12 +7,8 @@ "CVE-2010-5177" ], "details": "** DISPUTED ** Race condition in Sophos Endpoint Security and Control 9.0.5 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: the vendor disputes this issue because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cv3v-qh4g-332m/GHSA-cv3v-qh4g-332m.json b/advisories/unreviewed/2022/05/GHSA-cv3v-qh4g-332m/GHSA-cv3v-qh4g-332m.json index 8dd4191c24b..8b745bc69f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv3v-qh4g-332m/GHSA-cv3v-qh4g-332m.json +++ b/advisories/unreviewed/2022/05/GHSA-cv3v-qh4g-332m/GHSA-cv3v-qh4g-332m.json @@ -7,12 +7,8 @@ "CVE-2020-5520" ], "details": "The netprint App for iOS 3.2.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cvqp-6rwh-x2fj/GHSA-cvqp-6rwh-x2fj.json b/advisories/unreviewed/2022/05/GHSA-cvqp-6rwh-x2fj/GHSA-cvqp-6rwh-x2fj.json index 6864358e786..ab6afc53147 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvqp-6rwh-x2fj/GHSA-cvqp-6rwh-x2fj.json +++ b/advisories/unreviewed/2022/05/GHSA-cvqp-6rwh-x2fj/GHSA-cvqp-6rwh-x2fj.json @@ -7,12 +7,8 @@ "CVE-2012-5613" ], "details": "** DISPUTED ** MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging the FILE privilege to create files as the MySQL administrator. NOTE: the vendor disputes this issue, stating that this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation. NOTE: it could be argued that this should not be included in CVE because it is a configuration issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cvvm-qm6p-fg85/GHSA-cvvm-qm6p-fg85.json b/advisories/unreviewed/2022/05/GHSA-cvvm-qm6p-fg85/GHSA-cvvm-qm6p-fg85.json index 4b7252dd7ba..8d739738588 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvvm-qm6p-fg85/GHSA-cvvm-qm6p-fg85.json +++ b/advisories/unreviewed/2022/05/GHSA-cvvm-qm6p-fg85/GHSA-cvvm-qm6p-fg85.json @@ -7,12 +7,8 @@ "CVE-2020-1606" ], "details": "A path traversal vulnerability in the Juniper Networks Junos OS device may allow an authenticated J-web user to read files with 'world' readable permission and delete files with 'world' writeable permission. This issue does not affect system files that can be accessed only by root user. This issue affects Juniper Networks Junos OS: 12.3 versions prior to 12.3R12-S13; 12.3X48 versions prior to 12.3X48-D85 on SRX Series; 14.1X53 versions prior to 14.1X53-D51; 15.1F6 versions prior to 15.1F6-S13; 15.1 versions prior to 15.1R7-S5; 15.1X49 versions prior to 15.1X49-D180 on SRX Series; 15.1X53 versions prior to 15.1X53-D238 on QFX5200/QFX5110 Series; 16.1 versions prior to 16.1R4-S13, 16.1R7-S5; 16.2 versions prior to 16.2R2-S10; 17.1 versions prior to 17.1R3-S1; 17.2 versions prior to 17.2R1-S9, 17.2R3-S2; 17.3 versions prior to 17.3R2-S5, 17.3R3-S5; 17.4 versions prior to 17.4R2-S9, 17.4R3; 18.1 versions prior to 18.1R3-S8; 18.2 versions prior to 18.2R3; 18.3 versions prior to 18.3R2-S3, 18.3R3; 18.4 versions prior to 18.4R2; 19.1 versions prior to 19.1R1-S4, 19.1R2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cx63-3qq4-2hvv/GHSA-cx63-3qq4-2hvv.json b/advisories/unreviewed/2022/05/GHSA-cx63-3qq4-2hvv/GHSA-cx63-3qq4-2hvv.json index ffac2ecd4ea..0477648bff9 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx63-3qq4-2hvv/GHSA-cx63-3qq4-2hvv.json +++ b/advisories/unreviewed/2022/05/GHSA-cx63-3qq4-2hvv/GHSA-cx63-3qq4-2hvv.json @@ -7,12 +7,8 @@ "CVE-2019-5146" ], "details": "An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13025.10004. A specially crafted pixel shader can cause a denial of service. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cxpp-v3rm-fq33/GHSA-cxpp-v3rm-fq33.json b/advisories/unreviewed/2022/05/GHSA-cxpp-v3rm-fq33/GHSA-cxpp-v3rm-fq33.json index 732668a211c..6dc2985d6f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxpp-v3rm-fq33/GHSA-cxpp-v3rm-fq33.json +++ b/advisories/unreviewed/2022/05/GHSA-cxpp-v3rm-fq33/GHSA-cxpp-v3rm-fq33.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f2f3-hcjw-63p3/GHSA-f2f3-hcjw-63p3.json b/advisories/unreviewed/2022/05/GHSA-f2f3-hcjw-63p3/GHSA-f2f3-hcjw-63p3.json index cacc2941974..570b8e678ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2f3-hcjw-63p3/GHSA-f2f3-hcjw-63p3.json +++ b/advisories/unreviewed/2022/05/GHSA-f2f3-hcjw-63p3/GHSA-f2f3-hcjw-63p3.json @@ -7,12 +7,8 @@ "CVE-2018-7794" ], "details": "A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service when reading data with invalid index using Modbus TCP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3wx-45hf-3hwx/GHSA-f3wx-45hf-3hwx.json b/advisories/unreviewed/2022/05/GHSA-f3wx-45hf-3hwx/GHSA-f3wx-45hf-3hwx.json index fe8d3cc76d3..176f00a49fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3wx-45hf-3hwx/GHSA-f3wx-45hf-3hwx.json +++ b/advisories/unreviewed/2022/05/GHSA-f3wx-45hf-3hwx/GHSA-f3wx-45hf-3hwx.json @@ -7,12 +7,8 @@ "CVE-2020-0605" ], "details": "A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0606.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f48h-2gff-477g/GHSA-f48h-2gff-477g.json b/advisories/unreviewed/2022/05/GHSA-f48h-2gff-477g/GHSA-f48h-2gff-477g.json index e6525a06ce3..905b82b2f1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-f48h-2gff-477g/GHSA-f48h-2gff-477g.json +++ b/advisories/unreviewed/2022/05/GHSA-f48h-2gff-477g/GHSA-f48h-2gff-477g.json @@ -7,12 +7,8 @@ "CVE-2015-2928" ], "details": "The Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f5pv-c7hr-3cx2/GHSA-f5pv-c7hr-3cx2.json b/advisories/unreviewed/2022/05/GHSA-f5pv-c7hr-3cx2/GHSA-f5pv-c7hr-3cx2.json index 16da0ed179f..eadb5a0fde3 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5pv-c7hr-3cx2/GHSA-f5pv-c7hr-3cx2.json +++ b/advisories/unreviewed/2022/05/GHSA-f5pv-c7hr-3cx2/GHSA-f5pv-c7hr-3cx2.json @@ -7,12 +7,8 @@ "CVE-2020-7951" ], "details": "meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is affected by memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f622-4fq2-v6m7/GHSA-f622-4fq2-v6m7.json b/advisories/unreviewed/2022/05/GHSA-f622-4fq2-v6m7/GHSA-f622-4fq2-v6m7.json index 0f66d49acd1..8c5e6138c96 100644 --- a/advisories/unreviewed/2022/05/GHSA-f622-4fq2-v6m7/GHSA-f622-4fq2-v6m7.json +++ b/advisories/unreviewed/2022/05/GHSA-f622-4fq2-v6m7/GHSA-f622-4fq2-v6m7.json @@ -7,12 +7,8 @@ "CVE-2020-2678" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data as well as unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f79p-hq3g-prjw/GHSA-f79p-hq3g-prjw.json b/advisories/unreviewed/2022/05/GHSA-f79p-hq3g-prjw/GHSA-f79p-hq3g-prjw.json index 4e049075668..48464c06391 100644 --- a/advisories/unreviewed/2022/05/GHSA-f79p-hq3g-prjw/GHSA-f79p-hq3g-prjw.json +++ b/advisories/unreviewed/2022/05/GHSA-f79p-hq3g-prjw/GHSA-f79p-hq3g-prjw.json @@ -7,12 +7,8 @@ "CVE-2019-6855" ], "details": "An Improper Authorization - CWE-285 vulnerability exists in EcoStruxure? Control Expert V14.0 and all versions of Unity Pro (previously calledEcoStruxure? Control Expert), which could allow a bypass of the authentication process between EcoStruxure Control Expert and the controller.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f7jp-x5vp-978r/GHSA-f7jp-x5vp-978r.json b/advisories/unreviewed/2022/05/GHSA-f7jp-x5vp-978r/GHSA-f7jp-x5vp-978r.json index 5f227ce784e..edc902f442a 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7jp-x5vp-978r/GHSA-f7jp-x5vp-978r.json +++ b/advisories/unreviewed/2022/05/GHSA-f7jp-x5vp-978r/GHSA-f7jp-x5vp-978r.json @@ -7,12 +7,8 @@ "CVE-2015-2929" ], "details": "The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote servers to cause a denial of service (assertion failure and application exit) via a malformed HS descriptor.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f8pr-x4hc-3mhf/GHSA-f8pr-x4hc-3mhf.json b/advisories/unreviewed/2022/05/GHSA-f8pr-x4hc-3mhf/GHSA-f8pr-x4hc-3mhf.json index 47f8482910c..52fdad6a875 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8pr-x4hc-3mhf/GHSA-f8pr-x4hc-3mhf.json +++ b/advisories/unreviewed/2022/05/GHSA-f8pr-x4hc-3mhf/GHSA-f8pr-x4hc-3mhf.json @@ -7,12 +7,8 @@ "CVE-2020-5221" ], "details": "In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple different FTP commands and read and write to arbitrary locations on the filesystem due to the lack of a well-written chroot jail in compose_abspath(). This has been fixed in version 2.11", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "WEB", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f95v-wr93-5m3v/GHSA-f95v-wr93-5m3v.json b/advisories/unreviewed/2022/05/GHSA-f95v-wr93-5m3v/GHSA-f95v-wr93-5m3v.json index 88358036360..62182bd5be6 100644 --- a/advisories/unreviewed/2022/05/GHSA-f95v-wr93-5m3v/GHSA-f95v-wr93-5m3v.json +++ b/advisories/unreviewed/2022/05/GHSA-f95v-wr93-5m3v/GHSA-f95v-wr93-5m3v.json @@ -7,12 +7,8 @@ "CVE-2018-16265" ], "details": "The bt/bt_core system service in Tizen allows an unprivileged process to create a system user interface and control the Bluetooth pairing process, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ff94-3j58-q72h/GHSA-ff94-3j58-q72h.json b/advisories/unreviewed/2022/05/GHSA-ff94-3j58-q72h/GHSA-ff94-3j58-q72h.json index 47b1430722a..f6ff2ff1778 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff94-3j58-q72h/GHSA-ff94-3j58-q72h.json +++ b/advisories/unreviewed/2022/05/GHSA-ff94-3j58-q72h/GHSA-ff94-3j58-q72h.json @@ -7,12 +7,8 @@ "CVE-2019-4614" ], "details": "IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS client connecting to a Queue Manager could cause a SIGSEGV denial of service caused by converting an invalid message. IBM X-Force ID: 168639.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ffc8-x782-pp9w/GHSA-ffc8-x782-pp9w.json b/advisories/unreviewed/2022/05/GHSA-ffc8-x782-pp9w/GHSA-ffc8-x782-pp9w.json index e086423e766..49e8797e902 100644 --- a/advisories/unreviewed/2022/05/GHSA-ffc8-x782-pp9w/GHSA-ffc8-x782-pp9w.json +++ b/advisories/unreviewed/2022/05/GHSA-ffc8-x782-pp9w/GHSA-ffc8-x782-pp9w.json @@ -7,12 +7,8 @@ "CVE-2019-16512" ], "details": "An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is stored XSS in the Appearance modifier.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fg57-3jwx-fwm8/GHSA-fg57-3jwx-fwm8.json b/advisories/unreviewed/2022/05/GHSA-fg57-3jwx-fwm8/GHSA-fg57-3jwx-fwm8.json index 509523cce96..044cb6bbfee 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg57-3jwx-fwm8/GHSA-fg57-3jwx-fwm8.json +++ b/advisories/unreviewed/2022/05/GHSA-fg57-3jwx-fwm8/GHSA-fg57-3jwx-fwm8.json @@ -7,12 +7,8 @@ "CVE-2020-2705" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fggm-cj33-4gmm/GHSA-fggm-cj33-4gmm.json b/advisories/unreviewed/2022/05/GHSA-fggm-cj33-4gmm/GHSA-fggm-cj33-4gmm.json index d5278ae4a26..5ec0fc5a7b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-fggm-cj33-4gmm/GHSA-fggm-cj33-4gmm.json +++ b/advisories/unreviewed/2022/05/GHSA-fggm-cj33-4gmm/GHSA-fggm-cj33-4gmm.json @@ -7,12 +7,8 @@ "CVE-2010-5179" ], "details": "** DISPUTED ** Race condition in Trend Micro Internet Security Pro 2010 17.50.1647.0000 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fgjc-45m5-mmhx/GHSA-fgjc-45m5-mmhx.json b/advisories/unreviewed/2022/05/GHSA-fgjc-45m5-mmhx/GHSA-fgjc-45m5-mmhx.json index b9560ba18d7..56c8c777a40 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgjc-45m5-mmhx/GHSA-fgjc-45m5-mmhx.json +++ b/advisories/unreviewed/2022/05/GHSA-fgjc-45m5-mmhx/GHSA-fgjc-45m5-mmhx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fhjc-mpvv-5r8g/GHSA-fhjc-mpvv-5r8g.json b/advisories/unreviewed/2022/05/GHSA-fhjc-mpvv-5r8g/GHSA-fhjc-mpvv-5r8g.json index 67b546019fa..9ddc78733ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhjc-mpvv-5r8g/GHSA-fhjc-mpvv-5r8g.json +++ b/advisories/unreviewed/2022/05/GHSA-fhjc-mpvv-5r8g/GHSA-fhjc-mpvv-5r8g.json @@ -7,12 +7,8 @@ "CVE-2019-16026" ], "details": "A vulnerability in the implementation of the Stream Control Transmission Protocol (SCTP) on Cisco Mobility Management Entity (MME) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an eNodeB that is connected to an affected device. The vulnerability is due to insufficient input validation of SCTP traffic. An attacker could exploit this vulnerability by leveraging a man-in-the-middle position between the eNodeB and the MME and then sending a crafted SCTP message to the MME. A successful exploit would cause the MME to stop sending SCTP messages to the eNodeB, triggering a DoS condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fhp7-78j6-88pw/GHSA-fhp7-78j6-88pw.json b/advisories/unreviewed/2022/05/GHSA-fhp7-78j6-88pw/GHSA-fhp7-78j6-88pw.json index 1da09a9d801..1d36a13b62e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhp7-78j6-88pw/GHSA-fhp7-78j6-88pw.json +++ b/advisories/unreviewed/2022/05/GHSA-fhp7-78j6-88pw/GHSA-fhp7-78j6-88pw.json @@ -7,12 +7,8 @@ "CVE-2018-16272" ], "details": "The wpa_supplicant system service in Samsung Galaxy Gear series allows an unprivileged process to fully control the Wi-Fi interface, due to the lack of its D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fp7r-722w-q34j/GHSA-fp7r-722w-q34j.json b/advisories/unreviewed/2022/05/GHSA-fp7r-722w-q34j/GHSA-fp7r-722w-q34j.json index 4f63d212bd2..b0edecbb2c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp7r-722w-q34j/GHSA-fp7r-722w-q34j.json +++ b/advisories/unreviewed/2022/05/GHSA-fp7r-722w-q34j/GHSA-fp7r-722w-q34j.json @@ -7,12 +7,8 @@ "CVE-2019-18900" ], "details": ": Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. This issue affects: SUSE CaaS Platform 3.0 libzypp versions prior to 16.21.2-27.68.1. SUSE Linux Enterprise Server 12 libzypp versions prior to 16.21.2-2.45.1. SUSE Linux Enterprise Server 15 17.19.0-3.34.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fpc6-xw6h-2mw7/GHSA-fpc6-xw6h-2mw7.json b/advisories/unreviewed/2022/05/GHSA-fpc6-xw6h-2mw7/GHSA-fpc6-xw6h-2mw7.json index 143f615bb79..47c76323004 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpc6-xw6h-2mw7/GHSA-fpc6-xw6h-2mw7.json +++ b/advisories/unreviewed/2022/05/GHSA-fpc6-xw6h-2mw7/GHSA-fpc6-xw6h-2mw7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fpr4-m35f-p9w5/GHSA-fpr4-m35f-p9w5.json b/advisories/unreviewed/2022/05/GHSA-fpr4-m35f-p9w5/GHSA-fpr4-m35f-p9w5.json index 2959e4ab7ec..5cfbf19373f 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpr4-m35f-p9w5/GHSA-fpr4-m35f-p9w5.json +++ b/advisories/unreviewed/2022/05/GHSA-fpr4-m35f-p9w5/GHSA-fpr4-m35f-p9w5.json @@ -7,12 +7,8 @@ "CVE-2016-6585" ], "details": "A Denial of Service vulnerability exists in Symantec Norton Mobile Security for Android prior to 3.16, which could let a remote malicious user conduct a man-in-the-middle attack via specially crafted JavaScript.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fq47-wg6h-8mxh/GHSA-fq47-wg6h-8mxh.json b/advisories/unreviewed/2022/05/GHSA-fq47-wg6h-8mxh/GHSA-fq47-wg6h-8mxh.json index d05d44bf6d0..65ecff658df 100644 --- a/advisories/unreviewed/2022/05/GHSA-fq47-wg6h-8mxh/GHSA-fq47-wg6h-8mxh.json +++ b/advisories/unreviewed/2022/05/GHSA-fq47-wg6h-8mxh/GHSA-fq47-wg6h-8mxh.json @@ -7,12 +7,8 @@ "CVE-2020-2570" ], "details": "Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.28 and prior and 8.0.18 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client. CVSS 3.0 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fr8m-vw66-8v9r/GHSA-fr8m-vw66-8v9r.json b/advisories/unreviewed/2022/05/GHSA-fr8m-vw66-8v9r/GHSA-fr8m-vw66-8v9r.json index 11d1bb84b52..392602ce886 100644 --- a/advisories/unreviewed/2022/05/GHSA-fr8m-vw66-8v9r/GHSA-fr8m-vw66-8v9r.json +++ b/advisories/unreviewed/2022/05/GHSA-fr8m-vw66-8v9r/GHSA-fr8m-vw66-8v9r.json @@ -7,12 +7,8 @@ "CVE-2020-7039" ], "details": "tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fw3h-pcxm-9jx2/GHSA-fw3h-pcxm-9jx2.json b/advisories/unreviewed/2022/05/GHSA-fw3h-pcxm-9jx2/GHSA-fw3h-pcxm-9jx2.json index 5474ee5b1ef..ea1782d9462 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw3h-pcxm-9jx2/GHSA-fw3h-pcxm-9jx2.json +++ b/advisories/unreviewed/2022/05/GHSA-fw3h-pcxm-9jx2/GHSA-fw3h-pcxm-9jx2.json @@ -7,12 +7,8 @@ "CVE-2019-20438" ], "details": "An issue was discovered in WSO2 API Manager 2.6.0. A potential stored Cross-Site Scripting (XSS) vulnerability has been identified in the inline API documentation editor page of the API Publisher.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwf5-32xc-rx62/GHSA-fwf5-32xc-rx62.json b/advisories/unreviewed/2022/05/GHSA-fwf5-32xc-rx62/GHSA-fwf5-32xc-rx62.json index a382f294efc..749241b6317 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwf5-32xc-rx62/GHSA-fwf5-32xc-rx62.json +++ b/advisories/unreviewed/2022/05/GHSA-fwf5-32xc-rx62/GHSA-fwf5-32xc-rx62.json @@ -7,12 +7,8 @@ "CVE-2018-16270" ], "details": "Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fwm5-h3g4-wvhr/GHSA-fwm5-h3g4-wvhr.json b/advisories/unreviewed/2022/05/GHSA-fwm5-h3g4-wvhr/GHSA-fwm5-h3g4-wvhr.json index 797bb6bcfd2..9a578f08de7 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwm5-h3g4-wvhr/GHSA-fwm5-h3g4-wvhr.json +++ b/advisories/unreviewed/2022/05/GHSA-fwm5-h3g4-wvhr/GHSA-fwm5-h3g4-wvhr.json @@ -7,12 +7,8 @@ "CVE-2012-0693" ], "details": "** DISPUTED ** submitticket.php in WHMCompleteSolution (WHMCS) 5.03 allows remote attackers to inject arbitrary code into a subject field via crafted ticket data, a different vulnerability than CVE-2011-5061. NOTE: the vendor disputes this issue, noting that some of the details overlap CVE-2011-5061, but that it \"says it affects V5.0.3, and the submitticket.php file, both of which are wrong.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g2j7-jqw5-568r/GHSA-g2j7-jqw5-568r.json b/advisories/unreviewed/2022/05/GHSA-g2j7-jqw5-568r/GHSA-g2j7-jqw5-568r.json index a5d5adc0604..e18faa761da 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2j7-jqw5-568r/GHSA-g2j7-jqw5-568r.json +++ b/advisories/unreviewed/2022/05/GHSA-g2j7-jqw5-568r/GHSA-g2j7-jqw5-568r.json @@ -7,12 +7,8 @@ "CVE-2019-19896" ], "details": "In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The default file permissions of the IXP$ share on the server allows modification of directories and files (e.g., bat-scripts), which allows execution of code in the context of NT AUTHORITY\\SYSTEM on the target server and clients.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g2x6-g872-cmqg/GHSA-g2x6-g872-cmqg.json b/advisories/unreviewed/2022/05/GHSA-g2x6-g872-cmqg/GHSA-g2x6-g872-cmqg.json index 9d012182438..b0d354f8639 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2x6-g872-cmqg/GHSA-g2x6-g872-cmqg.json +++ b/advisories/unreviewed/2022/05/GHSA-g2x6-g872-cmqg/GHSA-g2x6-g872-cmqg.json @@ -7,12 +7,8 @@ "CVE-2020-0635" ], "details": "An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0644.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g47q-59qr-8mqr/GHSA-g47q-59qr-8mqr.json b/advisories/unreviewed/2022/05/GHSA-g47q-59qr-8mqr/GHSA-g47q-59qr-8mqr.json index 0ed34d62933..debf50d8f1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-g47q-59qr-8mqr/GHSA-g47q-59qr-8mqr.json +++ b/advisories/unreviewed/2022/05/GHSA-g47q-59qr-8mqr/GHSA-g47q-59qr-8mqr.json @@ -7,12 +7,8 @@ "CVE-2019-14766" ], "details": "Path Traversal in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to browse the server filesystem.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g669-jwgh-qm4m/GHSA-g669-jwgh-qm4m.json b/advisories/unreviewed/2022/05/GHSA-g669-jwgh-qm4m/GHSA-g669-jwgh-qm4m.json index fd8279a8d45..445724c5b8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-g669-jwgh-qm4m/GHSA-g669-jwgh-qm4m.json +++ b/advisories/unreviewed/2022/05/GHSA-g669-jwgh-qm4m/GHSA-g669-jwgh-qm4m.json @@ -7,12 +7,8 @@ "CVE-2020-6849" ], "details": "The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with resultant XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g6ww-98w5-h2gm/GHSA-g6ww-98w5-h2gm.json b/advisories/unreviewed/2022/05/GHSA-g6ww-98w5-h2gm/GHSA-g6ww-98w5-h2gm.json index eb2ae63e2f3..b3c75d65a14 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6ww-98w5-h2gm/GHSA-g6ww-98w5-h2gm.json +++ b/advisories/unreviewed/2022/05/GHSA-g6ww-98w5-h2gm/GHSA-g6ww-98w5-h2gm.json @@ -7,12 +7,8 @@ "CVE-2020-7211" ], "details": "tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\\ directory traversal on Windows.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g766-3fwj-gpj8/GHSA-g766-3fwj-gpj8.json b/advisories/unreviewed/2022/05/GHSA-g766-3fwj-gpj8/GHSA-g766-3fwj-gpj8.json index 4a605ba35ea..8d94143fb33 100644 --- a/advisories/unreviewed/2022/05/GHSA-g766-3fwj-gpj8/GHSA-g766-3fwj-gpj8.json +++ b/advisories/unreviewed/2022/05/GHSA-g766-3fwj-gpj8/GHSA-g766-3fwj-gpj8.json @@ -7,12 +7,8 @@ "CVE-2019-19854" ], "details": "An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. It does not use CSRF Tokens to mitigate against CSRF; it uses the Origin header (which must match the request origin). This is problematic in conjunction with XSS: one can escalate privileges from User level to Administrator.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g97p-g75w-cw67/GHSA-g97p-g75w-cw67.json b/advisories/unreviewed/2022/05/GHSA-g97p-g75w-cw67/GHSA-g97p-g75w-cw67.json index f8703d9b639..b0ba16f106f 100644 --- a/advisories/unreviewed/2022/05/GHSA-g97p-g75w-cw67/GHSA-g97p-g75w-cw67.json +++ b/advisories/unreviewed/2022/05/GHSA-g97p-g75w-cw67/GHSA-g97p-g75w-cw67.json @@ -7,12 +7,8 @@ "CVE-2020-0628" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gc9j-xjc6-h7v6/GHSA-gc9j-xjc6-h7v6.json b/advisories/unreviewed/2022/05/GHSA-gc9j-xjc6-h7v6/GHSA-gc9j-xjc6-h7v6.json index 59322071e1b..bfcaea4cd88 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc9j-xjc6-h7v6/GHSA-gc9j-xjc6-h7v6.json +++ b/advisories/unreviewed/2022/05/GHSA-gc9j-xjc6-h7v6/GHSA-gc9j-xjc6-h7v6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gcq6-qg3m-6m3g/GHSA-gcq6-qg3m-6m3g.json b/advisories/unreviewed/2022/05/GHSA-gcq6-qg3m-6m3g/GHSA-gcq6-qg3m-6m3g.json index 5e2ff2cc7a1..803e95d67bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcq6-qg3m-6m3g/GHSA-gcq6-qg3m-6m3g.json +++ b/advisories/unreviewed/2022/05/GHSA-gcq6-qg3m-6m3g/GHSA-gcq6-qg3m-6m3g.json @@ -7,12 +7,8 @@ "CVE-2020-2590" ], "details": "Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -104,9 +100,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gcr3-7gvg-jhhf/GHSA-gcr3-7gvg-jhhf.json b/advisories/unreviewed/2022/05/GHSA-gcr3-7gvg-jhhf/GHSA-gcr3-7gvg-jhhf.json index 99840250b7f..0bf623c43fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcr3-7gvg-jhhf/GHSA-gcr3-7gvg-jhhf.json +++ b/advisories/unreviewed/2022/05/GHSA-gcr3-7gvg-jhhf/GHSA-gcr3-7gvg-jhhf.json @@ -7,12 +7,8 @@ "CVE-2018-16264" ], "details": "The BlueZ system service in Tizen allows an unprivileged process to partially control Bluetooth or acquire sensitive information, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gf92-7rqx-hgfc/GHSA-gf92-7rqx-hgfc.json b/advisories/unreviewed/2022/05/GHSA-gf92-7rqx-hgfc/GHSA-gf92-7rqx-hgfc.json index 2b8a51b4dd6..ad77e5288dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf92-7rqx-hgfc/GHSA-gf92-7rqx-hgfc.json +++ b/advisories/unreviewed/2022/05/GHSA-gf92-7rqx-hgfc/GHSA-gf92-7rqx-hgfc.json @@ -7,12 +7,8 @@ "CVE-2020-2655" ], "details": "Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.5 and 13.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data as well as unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gfwv-ggwh-qj2r/GHSA-gfwv-ggwh-qj2r.json b/advisories/unreviewed/2022/05/GHSA-gfwv-ggwh-qj2r/GHSA-gfwv-ggwh-qj2r.json index 7f578898f98..ea5fb4a3e72 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfwv-ggwh-qj2r/GHSA-gfwv-ggwh-qj2r.json +++ b/advisories/unreviewed/2022/05/GHSA-gfwv-ggwh-qj2r/GHSA-gfwv-ggwh-qj2r.json @@ -7,12 +7,8 @@ "CVE-2019-11288" ], "details": "In Pivotal tc Server, 3.x versions prior to 3.2.19 and 4.x versions prior to 4.0.10, and Pivotal tc Runtimes, 7.x versions prior to 7.0.99.B, 8.x versions prior to 8.5.47.A, and 9.x versions prior to 9.0.27.A, when a tc Runtime instance is configured with the JMX Socket Listener, a local attacker without access to the tc Runtime process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the tc Runtime instance.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ggjj-5q4c-mg3j/GHSA-ggjj-5q4c-mg3j.json b/advisories/unreviewed/2022/05/GHSA-ggjj-5q4c-mg3j/GHSA-ggjj-5q4c-mg3j.json index 28af3ff4ee5..a4a270dcc52 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggjj-5q4c-mg3j/GHSA-ggjj-5q4c-mg3j.json +++ b/advisories/unreviewed/2022/05/GHSA-ggjj-5q4c-mg3j/GHSA-ggjj-5q4c-mg3j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ghgr-295p-vw7v/GHSA-ghgr-295p-vw7v.json b/advisories/unreviewed/2022/05/GHSA-ghgr-295p-vw7v/GHSA-ghgr-295p-vw7v.json index 1adb9caba5a..18438161a0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghgr-295p-vw7v/GHSA-ghgr-295p-vw7v.json +++ b/advisories/unreviewed/2022/05/GHSA-ghgr-295p-vw7v/GHSA-ghgr-295p-vw7v.json @@ -7,12 +7,8 @@ "CVE-2011-4766" ], "details": "** DISPUTED ** The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allows remote attackers to obtain ASP source code via a direct request to wysiwyg/fckconfig.js. NOTE: CVE disputes this issue because ASP is only used in a JavaScript comment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gjj6-x35h-5jcg/GHSA-gjj6-x35h-5jcg.json b/advisories/unreviewed/2022/05/GHSA-gjj6-x35h-5jcg/GHSA-gjj6-x35h-5jcg.json index 18da2a50c1b..cb68aaca7a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjj6-x35h-5jcg/GHSA-gjj6-x35h-5jcg.json +++ b/advisories/unreviewed/2022/05/GHSA-gjj6-x35h-5jcg/GHSA-gjj6-x35h-5jcg.json @@ -7,12 +7,8 @@ "CVE-2019-19631" ], "details": "An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud Fabric 4.5 through 4.5.5, 4.7 through 4.7.7, 5.0 through 5.0.1, and 5.1 through 5.1.4; and Multi-Cloud Director through 1.1.0. A read-only user can access sensitive information via an API endpoint that reveals session cookies of authenticated administrators, leading to privilege escalation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gm75-8c8w-xvmw/GHSA-gm75-8c8w-xvmw.json b/advisories/unreviewed/2022/05/GHSA-gm75-8c8w-xvmw/GHSA-gm75-8c8w-xvmw.json index 3c0e8a7177f..f9f40efb694 100644 --- a/advisories/unreviewed/2022/05/GHSA-gm75-8c8w-xvmw/GHSA-gm75-8c8w-xvmw.json +++ b/advisories/unreviewed/2022/05/GHSA-gm75-8c8w-xvmw/GHSA-gm75-8c8w-xvmw.json @@ -7,12 +7,8 @@ "CVE-2019-15855" ], "details": "An issue was discovered in Maarch RM before 2.5. A path traversal vulnerability allows an unauthenticated remote attacker to overwrite any files with a crafted POST request if the default installation procedure was followed. This results in a permanent Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gm78-546w-wxp9/GHSA-gm78-546w-wxp9.json b/advisories/unreviewed/2022/05/GHSA-gm78-546w-wxp9/GHSA-gm78-546w-wxp9.json index 710267133bc..b3a5b09d025 100644 --- a/advisories/unreviewed/2022/05/GHSA-gm78-546w-wxp9/GHSA-gm78-546w-wxp9.json +++ b/advisories/unreviewed/2022/05/GHSA-gm78-546w-wxp9/GHSA-gm78-546w-wxp9.json @@ -7,12 +7,8 @@ "CVE-2020-0656" ], "details": "A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gmrf-44g4-wc8m/GHSA-gmrf-44g4-wc8m.json b/advisories/unreviewed/2022/05/GHSA-gmrf-44g4-wc8m/GHSA-gmrf-44g4-wc8m.json index 59e00c2c6d6..e588a97076d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmrf-44g4-wc8m/GHSA-gmrf-44g4-wc8m.json +++ b/advisories/unreviewed/2022/05/GHSA-gmrf-44g4-wc8m/GHSA-gmrf-44g4-wc8m.json @@ -7,12 +7,8 @@ "CVE-2019-15989" ], "details": "A vulnerability in the implementation of the Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of a BGP update message that contains a specific BGP attribute. An attacker could exploit this vulnerability by sending BGP update messages that include a specific, malformed attribute to be processed by an affected system. A successful exploit could allow the attacker to cause the BGP process to restart unexpectedly, resulting in a DoS condition. The Cisco implementation of BGP accepts incoming BGP traffic only from explicitly defined peers. To exploit this vulnerability, the malicious BGP update message would need to come from a configured, valid BGP peer or would need to be injected by the attacker into the victim’s BGP network on an existing, valid TCP connection to a BGP peer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gmvm-jpfj-v3f5/GHSA-gmvm-jpfj-v3f5.json b/advisories/unreviewed/2022/05/GHSA-gmvm-jpfj-v3f5/GHSA-gmvm-jpfj-v3f5.json index 6eea960d0e8..dffe9d54585 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmvm-jpfj-v3f5/GHSA-gmvm-jpfj-v3f5.json +++ b/advisories/unreviewed/2022/05/GHSA-gmvm-jpfj-v3f5/GHSA-gmvm-jpfj-v3f5.json @@ -7,12 +7,8 @@ "CVE-2019-11745" ], "details": "When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gpv8-9mxg-qp4r/GHSA-gpv8-9mxg-qp4r.json b/advisories/unreviewed/2022/05/GHSA-gpv8-9mxg-qp4r/GHSA-gpv8-9mxg-qp4r.json index 557b2d154cf..6343a259ca9 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpv8-9mxg-qp4r/GHSA-gpv8-9mxg-qp4r.json +++ b/advisories/unreviewed/2022/05/GHSA-gpv8-9mxg-qp4r/GHSA-gpv8-9mxg-qp4r.json @@ -7,12 +7,8 @@ "CVE-2019-9465" ], "details": "In the Titan M handling of cryptographic operations, there is a possible information disclosure due to an unusual root cause. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-133258003", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gq95-3482-fh74/GHSA-gq95-3482-fh74.json b/advisories/unreviewed/2022/05/GHSA-gq95-3482-fh74/GHSA-gq95-3482-fh74.json index 99b78f4ed46..35db137bdbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-gq95-3482-fh74/GHSA-gq95-3482-fh74.json +++ b/advisories/unreviewed/2022/05/GHSA-gq95-3482-fh74/GHSA-gq95-3482-fh74.json @@ -7,12 +7,8 @@ "CVE-2012-5383" ], "details": "** DISPUTED ** Untrusted search path vulnerability in the installation functionality in Oracle MySQL 5.5.28, when installed in the top-level C:\\ directory, might allow local users to gain privileges via a Trojan horse DLL in the \"C:\\MySQL\\MySQL Server 5.5\\bin\" directory, which may be added to the PATH system environment variable by an administrator, as demonstrated by a Trojan horse wlbsctrl.dll file used by the \"IKE and AuthIP IPsec Keying Modules\" system service in Windows Vista SP1, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 Release Preview. NOTE: CVE disputes this issue because the unsafe PATH is established only by a separate administrative action that is not a default part of the MySQL installation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gr4p-p93w-7rc9/GHSA-gr4p-p93w-7rc9.json b/advisories/unreviewed/2022/05/GHSA-gr4p-p93w-7rc9/GHSA-gr4p-p93w-7rc9.json index 8a49302c0ee..cb936bd4c56 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr4p-p93w-7rc9/GHSA-gr4p-p93w-7rc9.json +++ b/advisories/unreviewed/2022/05/GHSA-gr4p-p93w-7rc9/GHSA-gr4p-p93w-7rc9.json @@ -7,12 +7,8 @@ "CVE-2014-6392" ], "details": "** DISPUTED ** Cross-site scripting (XSS) vulnerability in the Facebook app 14.0 and the Facebook Messenger app 10.0 for iOS allows remote attackers to inject arbitrary web script or HTML via a crafted filename extension that is improperly handled during MIME sniffing of chat traffic. NOTE: the vendor disputes the significance of this report, because the user must accept an interstitial warning before the HTML file content is rendered, and because the HTML content's origin is a sandbox domain.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gvjh-v5q9-73c3/GHSA-gvjh-v5q9-73c3.json b/advisories/unreviewed/2022/05/GHSA-gvjh-v5q9-73c3/GHSA-gvjh-v5q9-73c3.json index 93c6a308a8e..2b2f464a4d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvjh-v5q9-73c3/GHSA-gvjh-v5q9-73c3.json +++ b/advisories/unreviewed/2022/05/GHSA-gvjh-v5q9-73c3/GHSA-gvjh-v5q9-73c3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gx8h-4x6m-jxm4/GHSA-gx8h-4x6m-jxm4.json b/advisories/unreviewed/2022/05/GHSA-gx8h-4x6m-jxm4/GHSA-gx8h-4x6m-jxm4.json index 43160f18505..1ba047487cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx8h-4x6m-jxm4/GHSA-gx8h-4x6m-jxm4.json +++ b/advisories/unreviewed/2022/05/GHSA-gx8h-4x6m-jxm4/GHSA-gx8h-4x6m-jxm4.json @@ -7,12 +7,8 @@ "CVE-2020-2693" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h3qm-pp82-wpc7/GHSA-h3qm-pp82-wpc7.json b/advisories/unreviewed/2022/05/GHSA-h3qm-pp82-wpc7/GHSA-h3qm-pp82-wpc7.json index 54929d3eb1d..775c7c6410c 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3qm-pp82-wpc7/GHSA-h3qm-pp82-wpc7.json +++ b/advisories/unreviewed/2022/05/GHSA-h3qm-pp82-wpc7/GHSA-h3qm-pp82-wpc7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h5jv-7mvc-m9hg/GHSA-h5jv-7mvc-m9hg.json b/advisories/unreviewed/2022/05/GHSA-h5jv-7mvc-m9hg/GHSA-h5jv-7mvc-m9hg.json index 9a3641178b7..14264f807d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5jv-7mvc-m9hg/GHSA-h5jv-7mvc-m9hg.json +++ b/advisories/unreviewed/2022/05/GHSA-h5jv-7mvc-m9hg/GHSA-h5jv-7mvc-m9hg.json @@ -7,12 +7,8 @@ "CVE-2020-6961" ], "details": "In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X, a vulnerability exists in the affected products that could allow an attacker to obtain access to the SSH private key in configuration files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h5xv-9vpq-r4gm/GHSA-h5xv-9vpq-r4gm.json b/advisories/unreviewed/2022/05/GHSA-h5xv-9vpq-r4gm/GHSA-h5xv-9vpq-r4gm.json index d3ba8a741c2..a146eb47271 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5xv-9vpq-r4gm/GHSA-h5xv-9vpq-r4gm.json +++ b/advisories/unreviewed/2022/05/GHSA-h5xv-9vpq-r4gm/GHSA-h5xv-9vpq-r4gm.json @@ -7,12 +7,8 @@ "CVE-2019-19592" ], "details": "Jama Connect 8.44.0 has XSS via the \"Import File and Destination\" tab on the \"Data import wizard\" screen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h76w-xp2h-9r2m/GHSA-h76w-xp2h-9r2m.json b/advisories/unreviewed/2022/05/GHSA-h76w-xp2h-9r2m/GHSA-h76w-xp2h-9r2m.json index e2bbb84b3eb..95a2c6b3720 100644 --- a/advisories/unreviewed/2022/05/GHSA-h76w-xp2h-9r2m/GHSA-h76w-xp2h-9r2m.json +++ b/advisories/unreviewed/2022/05/GHSA-h76w-xp2h-9r2m/GHSA-h76w-xp2h-9r2m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7qv-cfwh-6fxm/GHSA-h7qv-cfwh-6fxm.json b/advisories/unreviewed/2022/05/GHSA-h7qv-cfwh-6fxm/GHSA-h7qv-cfwh-6fxm.json index 557a4b52a81..d111e1d13a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7qv-cfwh-6fxm/GHSA-h7qv-cfwh-6fxm.json +++ b/advisories/unreviewed/2022/05/GHSA-h7qv-cfwh-6fxm/GHSA-h7qv-cfwh-6fxm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h9g7-7vx4-6649/GHSA-h9g7-7vx4-6649.json b/advisories/unreviewed/2022/05/GHSA-h9g7-7vx4-6649/GHSA-h9g7-7vx4-6649.json index 4bd71c13f81..b67c4f7136f 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9g7-7vx4-6649/GHSA-h9g7-7vx4-6649.json +++ b/advisories/unreviewed/2022/05/GHSA-h9g7-7vx4-6649/GHSA-h9g7-7vx4-6649.json @@ -7,12 +7,8 @@ "CVE-2020-2601" ], "details": "Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -100,9 +96,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h9x5-gf2g-5jfw/GHSA-h9x5-gf2g-5jfw.json b/advisories/unreviewed/2022/05/GHSA-h9x5-gf2g-5jfw/GHSA-h9x5-gf2g-5jfw.json index f4df5ef93e0..b7d3f7d93e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9x5-gf2g-5jfw/GHSA-h9x5-gf2g-5jfw.json +++ b/advisories/unreviewed/2022/05/GHSA-h9x5-gf2g-5jfw/GHSA-h9x5-gf2g-5jfw.json @@ -7,12 +7,8 @@ "CVE-2020-0614" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h9xw-2mh8-hx46/GHSA-h9xw-2mh8-hx46.json b/advisories/unreviewed/2022/05/GHSA-h9xw-2mh8-hx46/GHSA-h9xw-2mh8-hx46.json index fb865531b85..9b20ee546b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9xw-2mh8-hx46/GHSA-h9xw-2mh8-hx46.json +++ b/advisories/unreviewed/2022/05/GHSA-h9xw-2mh8-hx46/GHSA-h9xw-2mh8-hx46.json @@ -7,12 +7,8 @@ "CVE-2018-16266" ], "details": "The Enlightenment system service in Tizen allows an unprivileged process to fully control or capture windows, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hfvf-x5qf-mwmg/GHSA-hfvf-x5qf-mwmg.json b/advisories/unreviewed/2022/05/GHSA-hfvf-x5qf-mwmg/GHSA-hfvf-x5qf-mwmg.json index a9542c0e8a0..8e254f44b93 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfvf-x5qf-mwmg/GHSA-hfvf-x5qf-mwmg.json +++ b/advisories/unreviewed/2022/05/GHSA-hfvf-x5qf-mwmg/GHSA-hfvf-x5qf-mwmg.json @@ -7,12 +7,8 @@ "CVE-2020-1607" ], "details": "Insufficient Cross-Site Scripting (XSS) protection in J-Web may potentially allow a remote attacker to inject web script or HTML, hijack the target user's J-Web session and perform administrative actions on the Junos device as the targeted user. This issue affects Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S15; 12.3X48 versions prior to 12.3X48-D86, 12.3X48-D90 on SRX Series; 14.1X53 versions prior to 14.1X53-D51 on EX and QFX Series; 15.1F6 versions prior to 15.1F6-S13; 15.1 versions prior to 15.1R7-S5; 15.1X49 versions prior to 15.1X49-D181, 15.1X49-D190 on SRX Series; 15.1X53 versions prior to 15.1X53-D238 on QFX5200/QFX5110 Series; 15.1X53 versions prior to 15.1X53-D592 on EX2300/EX3400 Series; 16.1 versions prior to 16.1R4-S13, 16.1R7-S5; 16.2 versions prior to 16.2R2-S10; 17.1 versions prior to 17.1R2-S11, 17.1R3-S1; 17.2 versions prior to 17.2R1-S9, 17.2R3-S2; 17.3 versions prior to 17.3R2-S5, 17.3R3-S5; 17.4 versions prior to 17.4R2-S6, 17.4R3; 18.1 versions prior to 18.1R3-S7; 18.2 versions prior to 18.2R2-S5, 18.2R3; 18.3 versions prior to 18.3R1-S6, 18.3R2-S1, 18.3R3; 18.4 versions prior to 18.4R1-S5, 18.4R2; 19.1 versions prior to 19.1R1-S2, 19.1R2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hg3w-x3pv-cqqc/GHSA-hg3w-x3pv-cqqc.json b/advisories/unreviewed/2022/05/GHSA-hg3w-x3pv-cqqc/GHSA-hg3w-x3pv-cqqc.json index 1485179ff75..ab703193c31 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg3w-x3pv-cqqc/GHSA-hg3w-x3pv-cqqc.json +++ b/advisories/unreviewed/2022/05/GHSA-hg3w-x3pv-cqqc/GHSA-hg3w-x3pv-cqqc.json @@ -7,12 +7,8 @@ "CVE-2020-0621" ], "details": "A security feature bypass vulnerability exists in Windows 10 when third party filters are called during a password update, aka 'Windows Security Feature Bypass Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hhpc-f2cg-h393/GHSA-hhpc-f2cg-h393.json b/advisories/unreviewed/2022/05/GHSA-hhpc-f2cg-h393/GHSA-hhpc-f2cg-h393.json index 1e1236e106f..6ccacdf03d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhpc-f2cg-h393/GHSA-hhpc-f2cg-h393.json +++ b/advisories/unreviewed/2022/05/GHSA-hhpc-f2cg-h393/GHSA-hhpc-f2cg-h393.json @@ -7,12 +7,8 @@ "CVE-2020-7949" ], "details": "schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a GetValue call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hjqg-vhp3-pqqp/GHSA-hjqg-vhp3-pqqp.json b/advisories/unreviewed/2022/05/GHSA-hjqg-vhp3-pqqp/GHSA-hjqg-vhp3-pqqp.json index 18c9d551dcb..fbf7a722210 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjqg-vhp3-pqqp/GHSA-hjqg-vhp3-pqqp.json +++ b/advisories/unreviewed/2022/05/GHSA-hjqg-vhp3-pqqp/GHSA-hjqg-vhp3-pqqp.json @@ -7,12 +7,8 @@ "CVE-2019-17584" ], "details": "The Meinberg SyncBox/PTP/PTPv2 devices have default SSH keys which allow attackers to get root access to the devices. All firmware versions up to v5.34o, v5.34s, v5.32* or 5.34g are affected. The private key is also used in an internal interface of another Meinberg Device and can be extracted from a firmware update of this device. An update to fix the vulnerability was published by the vendor.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hqh5-6p8x-mqrv/GHSA-hqh5-6p8x-mqrv.json b/advisories/unreviewed/2022/05/GHSA-hqh5-6p8x-mqrv/GHSA-hqh5-6p8x-mqrv.json index 14867c6a073..514b2cd7103 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqh5-6p8x-mqrv/GHSA-hqh5-6p8x-mqrv.json +++ b/advisories/unreviewed/2022/05/GHSA-hqh5-6p8x-mqrv/GHSA-hqh5-6p8x-mqrv.json @@ -7,12 +7,8 @@ "CVE-2019-18273" ], "details": "OSIsoft PI Vision, PI Vision 2017 R2 and PI Vision 2017 R2 SP1. The affected product is vulnerable to cross-site scripting, which may allow invalid input to be introduced.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hwqh-393p-ff66/GHSA-hwqh-393p-ff66.json b/advisories/unreviewed/2022/05/GHSA-hwqh-393p-ff66/GHSA-hwqh-393p-ff66.json index 2a0a1db3919..295942a2ae1 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwqh-393p-ff66/GHSA-hwqh-393p-ff66.json +++ b/advisories/unreviewed/2022/05/GHSA-hwqh-393p-ff66/GHSA-hwqh-393p-ff66.json @@ -7,12 +7,8 @@ "CVE-2020-3941" ], "details": "The repair operation of VMware Tools for Windows 10.x.y has a race condition which may allow for privilege escalation in the Virtual Machine where Tools is installed. This vulnerability is not present in VMware Tools 11.x.y since the affected functionality is not present in VMware Tools 11.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hwwq-6fg7-74h6/GHSA-hwwq-6fg7-74h6.json b/advisories/unreviewed/2022/05/GHSA-hwwq-6fg7-74h6/GHSA-hwwq-6fg7-74h6.json index 52c8b02128d..209bfe8f30c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwwq-6fg7-74h6/GHSA-hwwq-6fg7-74h6.json +++ b/advisories/unreviewed/2022/05/GHSA-hwwq-6fg7-74h6/GHSA-hwwq-6fg7-74h6.json @@ -7,12 +7,8 @@ "CVE-2019-6854" ], "details": "A CWE-264 Permissions, Privileges, and Access Controls vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 January 2019- which could cause a low privilege user to delete or modify database, setting or certificate files. Those users must have access to the file system of that operating system to exploit this vulnerability. Affected versions in current support includes ClearSCADA 2017 R3, ClearSCADA 2017 R2, and ClearSCADA 2017.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hx2c-xvp4-cgw4/GHSA-hx2c-xvp4-cgw4.json b/advisories/unreviewed/2022/05/GHSA-hx2c-xvp4-cgw4/GHSA-hx2c-xvp4-cgw4.json index d974a140286..f0a88098845 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx2c-xvp4-cgw4/GHSA-hx2c-xvp4-cgw4.json +++ b/advisories/unreviewed/2022/05/GHSA-hx2c-xvp4-cgw4/GHSA-hx2c-xvp4-cgw4.json @@ -7,12 +7,8 @@ "CVE-2020-7045" ], "details": "In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by validating opcodes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hx94-4g78-82rr/GHSA-hx94-4g78-82rr.json b/advisories/unreviewed/2022/05/GHSA-hx94-4g78-82rr/GHSA-hx94-4g78-82rr.json index 3c3b4e7f857..4e0cf5ecbbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx94-4g78-82rr/GHSA-hx94-4g78-82rr.json +++ b/advisories/unreviewed/2022/05/GHSA-hx94-4g78-82rr/GHSA-hx94-4g78-82rr.json @@ -7,12 +7,8 @@ "CVE-2010-5158" ], "details": "** DISPUTED ** Race condition in DefenseWall Personal Firewall 3.00 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j26m-mhw3-8vc7/GHSA-j26m-mhw3-8vc7.json b/advisories/unreviewed/2022/05/GHSA-j26m-mhw3-8vc7/GHSA-j26m-mhw3-8vc7.json index ad4da27e49b..f5cd05f93a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-j26m-mhw3-8vc7/GHSA-j26m-mhw3-8vc7.json +++ b/advisories/unreviewed/2022/05/GHSA-j26m-mhw3-8vc7/GHSA-j26m-mhw3-8vc7.json @@ -7,12 +7,8 @@ "CVE-2019-16468" ], "details": "Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability. Successful exploitation could lead to sensitive information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j2h3-xh23-6v27/GHSA-j2h3-xh23-6v27.json b/advisories/unreviewed/2022/05/GHSA-j2h3-xh23-6v27/GHSA-j2h3-xh23-6v27.json index 7472b7c12bb..15c1c4a5386 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2h3-xh23-6v27/GHSA-j2h3-xh23-6v27.json +++ b/advisories/unreviewed/2022/05/GHSA-j2h3-xh23-6v27/GHSA-j2h3-xh23-6v27.json @@ -7,12 +7,8 @@ "CVE-2020-2659" ], "details": "Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u241 and 8u231; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -96,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j2jr-49q4-g8xh/GHSA-j2jr-49q4-g8xh.json b/advisories/unreviewed/2022/05/GHSA-j2jr-49q4-g8xh/GHSA-j2jr-49q4-g8xh.json index af3e8de3e74..5b57356c76d 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2jr-49q4-g8xh/GHSA-j2jr-49q4-g8xh.json +++ b/advisories/unreviewed/2022/05/GHSA-j2jr-49q4-g8xh/GHSA-j2jr-49q4-g8xh.json @@ -7,12 +7,8 @@ "CVE-2019-19834" ], "details": "Directory Traversal in ruckus_cli2 in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote attacker to jailbreak the CLI via enable->debug->script->exec with ../../../bin/sh as the parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j3jh-2qxv-87vp/GHSA-j3jh-2qxv-87vp.json b/advisories/unreviewed/2022/05/GHSA-j3jh-2qxv-87vp/GHSA-j3jh-2qxv-87vp.json index e60a290403d..f5793f26897 100644 --- a/advisories/unreviewed/2022/05/GHSA-j3jh-2qxv-87vp/GHSA-j3jh-2qxv-87vp.json +++ b/advisories/unreviewed/2022/05/GHSA-j3jh-2qxv-87vp/GHSA-j3jh-2qxv-87vp.json @@ -7,12 +7,8 @@ "CVE-2020-5521" ], "details": "The kantan netprint App for iOS 2.0.2 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j45j-w7qv-7r59/GHSA-j45j-w7qv-7r59.json b/advisories/unreviewed/2022/05/GHSA-j45j-w7qv-7r59/GHSA-j45j-w7qv-7r59.json index e86c2ac8204..d9636f61c80 100644 --- a/advisories/unreviewed/2022/05/GHSA-j45j-w7qv-7r59/GHSA-j45j-w7qv-7r59.json +++ b/advisories/unreviewed/2022/05/GHSA-j45j-w7qv-7r59/GHSA-j45j-w7qv-7r59.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j4cc-p6fj-6598/GHSA-j4cc-p6fj-6598.json b/advisories/unreviewed/2022/05/GHSA-j4cc-p6fj-6598/GHSA-j4cc-p6fj-6598.json index 483abd8bb75..bfda7663243 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4cc-p6fj-6598/GHSA-j4cc-p6fj-6598.json +++ b/advisories/unreviewed/2022/05/GHSA-j4cc-p6fj-6598/GHSA-j4cc-p6fj-6598.json @@ -7,12 +7,8 @@ "CVE-2018-20105" ], "details": "A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt versions prior to 1.2.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j4v4-83w4-ph37/GHSA-j4v4-83w4-ph37.json b/advisories/unreviewed/2022/05/GHSA-j4v4-83w4-ph37/GHSA-j4v4-83w4-ph37.json index cb220ee94a3..ad932aa6ed0 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4v4-83w4-ph37/GHSA-j4v4-83w4-ph37.json +++ b/advisories/unreviewed/2022/05/GHSA-j4v4-83w4-ph37/GHSA-j4v4-83w4-ph37.json @@ -7,12 +7,8 @@ "CVE-2019-16516" ], "details": "An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumeration vulnerability, allowing an unauthenticated attacker to determine with certainty if an account exists for a given username.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j5g5-24v2-cpf4/GHSA-j5g5-24v2-cpf4.json b/advisories/unreviewed/2022/05/GHSA-j5g5-24v2-cpf4/GHSA-j5g5-24v2-cpf4.json index ae2b2cf827d..a196cdcde72 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5g5-24v2-cpf4/GHSA-j5g5-24v2-cpf4.json +++ b/advisories/unreviewed/2022/05/GHSA-j5g5-24v2-cpf4/GHSA-j5g5-24v2-cpf4.json @@ -7,12 +7,8 @@ "CVE-2019-17102" ], "details": "An exploitable command execution vulnerability exists in the recovery partition of Bitdefender BOX 2, version 2.0.1.91. The API method `/api/update_setup` does not perform firmware signature checks atomically, leading to an exploitable race condition (TOCTTOU) that allows arbitrary execution of system commands. This issue affects: Bitdefender Bitdefender BOX 2 versions prior to 2.1.47.36.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j72w-hrcq-cmrg/GHSA-j72w-hrcq-cmrg.json b/advisories/unreviewed/2022/05/GHSA-j72w-hrcq-cmrg/GHSA-j72w-hrcq-cmrg.json index 96d95b77c75..d78904c4a4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j72w-hrcq-cmrg/GHSA-j72w-hrcq-cmrg.json +++ b/advisories/unreviewed/2022/05/GHSA-j72w-hrcq-cmrg/GHSA-j72w-hrcq-cmrg.json @@ -7,12 +7,8 @@ "CVE-2020-3139" ], "details": "[CVE-2020-3139_su] A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure Controller (APIC) could allow an unauthenticated, remote attacker to bypass configured deny entries for specific IP ports. These IP ports would be permitted to the OOB management interface when, in fact, the packets should be dropped. The vulnerability is due to the configuration of specific IP table entries for which there is a programming logic error that results in the IP port being permitted. An attacker could exploit this vulnerability by sending traffic to the OOB management interface on the targeted device. A successful exploit could allow the attacker to bypass configured IP table rules to drop specific IP port traffic. The attacker has no control over the configuration of the device itself.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j7fg-3jpp-jw6j/GHSA-j7fg-3jpp-jw6j.json b/advisories/unreviewed/2022/05/GHSA-j7fg-3jpp-jw6j/GHSA-j7fg-3jpp-jw6j.json index 0feedc4c666..90a1d0b6492 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7fg-3jpp-jw6j/GHSA-j7fg-3jpp-jw6j.json +++ b/advisories/unreviewed/2022/05/GHSA-j7fg-3jpp-jw6j/GHSA-j7fg-3jpp-jw6j.json @@ -7,12 +7,8 @@ "CVE-2020-0636" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Subsystem for Linux handles files, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j86q-w3f9-5q6c/GHSA-j86q-w3f9-5q6c.json b/advisories/unreviewed/2022/05/GHSA-j86q-w3f9-5q6c/GHSA-j86q-w3f9-5q6c.json index 1ce8d230948..1f2d5e52fd6 100644 --- a/advisories/unreviewed/2022/05/GHSA-j86q-w3f9-5q6c/GHSA-j86q-w3f9-5q6c.json +++ b/advisories/unreviewed/2022/05/GHSA-j86q-w3f9-5q6c/GHSA-j86q-w3f9-5q6c.json @@ -7,12 +7,8 @@ "CVE-2015-1571" ], "details": "** DISPUTED ** The CAPWAP DTLS protocol implementation in Fortinet FortiOS 5.0 Patch 7 build 4457 uses the same certificate and private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the Fortinet_Factory certificate and private key. NOTE: FG-IR-15-002 says \"The Fortinet_Factory certificate is unique to each device ... An attacker cannot therefore stage a MitM attack.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j987-p2x7-f5r3/GHSA-j987-p2x7-f5r3.json b/advisories/unreviewed/2022/05/GHSA-j987-p2x7-f5r3/GHSA-j987-p2x7-f5r3.json index 992b215d4f1..09567b00e4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-j987-p2x7-f5r3/GHSA-j987-p2x7-f5r3.json +++ b/advisories/unreviewed/2022/05/GHSA-j987-p2x7-f5r3/GHSA-j987-p2x7-f5r3.json @@ -7,12 +7,8 @@ "CVE-2019-19836" ], "details": "AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POST request that uses tools/_rcmdstat.jsp to write to a specified filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j9ww-72pm-37h3/GHSA-j9ww-72pm-37h3.json b/advisories/unreviewed/2022/05/GHSA-j9ww-72pm-37h3/GHSA-j9ww-72pm-37h3.json index 2b3bf194662..e8e59cb9149 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9ww-72pm-37h3/GHSA-j9ww-72pm-37h3.json +++ b/advisories/unreviewed/2022/05/GHSA-j9ww-72pm-37h3/GHSA-j9ww-72pm-37h3.json @@ -7,12 +7,8 @@ "CVE-2019-3699" ], "details": "UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15.1, Factory allows local attackers to escalate from user privoxy to root. This issue affects: openSUSE Leap 15.1 privoxy version 3.0.28-lp151.1.1 and prior versions. openSUSE Factory privoxy version 3.0.28-2.1 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jccc-2hj6-5h7m/GHSA-jccc-2hj6-5h7m.json b/advisories/unreviewed/2022/05/GHSA-jccc-2hj6-5h7m/GHSA-jccc-2hj6-5h7m.json index fea79135786..d3f27d43682 100644 --- a/advisories/unreviewed/2022/05/GHSA-jccc-2hj6-5h7m/GHSA-jccc-2hj6-5h7m.json +++ b/advisories/unreviewed/2022/05/GHSA-jccc-2hj6-5h7m/GHSA-jccc-2hj6-5h7m.json @@ -7,12 +7,8 @@ "CVE-2020-3115" ], "details": "A vulnerability in the CLI of the Cisco SD-WAN Solution vManage software could allow an authenticated, local attacker to elevate privileges to root-level privileges on the underlying operating system. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted file to the affected system. An exploit could allow the attacker to elevate privileges to root-level privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jf44-cqgv-7qmp/GHSA-jf44-cqgv-7qmp.json b/advisories/unreviewed/2022/05/GHSA-jf44-cqgv-7qmp/GHSA-jf44-cqgv-7qmp.json index 7f37cb6a0e0..b64184f6ca0 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf44-cqgv-7qmp/GHSA-jf44-cqgv-7qmp.json +++ b/advisories/unreviewed/2022/05/GHSA-jf44-cqgv-7qmp/GHSA-jf44-cqgv-7qmp.json @@ -7,12 +7,8 @@ "CVE-2010-5156" ], "details": "** DISPUTED ** Race condition in CA Internet Security Suite Plus 2010 6.0.0.272 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jf45-qwrv-p6f9/GHSA-jf45-qwrv-p6f9.json b/advisories/unreviewed/2022/05/GHSA-jf45-qwrv-p6f9/GHSA-jf45-qwrv-p6f9.json index 491da16a55f..b4351c607ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf45-qwrv-p6f9/GHSA-jf45-qwrv-p6f9.json +++ b/advisories/unreviewed/2022/05/GHSA-jf45-qwrv-p6f9/GHSA-jf45-qwrv-p6f9.json @@ -7,12 +7,8 @@ "CVE-2019-2267" ], "details": "Locked regions may be modified through other interfaces in secure boot loader image due to improper access control. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9205, QCS404, QCS605, SDA845, SDM670, SDM710, SDM845, SDM850, SM8150, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jfrx-jr32-9rx5/GHSA-jfrx-jr32-9rx5.json b/advisories/unreviewed/2022/05/GHSA-jfrx-jr32-9rx5/GHSA-jfrx-jr32-9rx5.json index 5521e99c8dd..e2619550ed7 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfrx-jr32-9rx5/GHSA-jfrx-jr32-9rx5.json +++ b/advisories/unreviewed/2022/05/GHSA-jfrx-jr32-9rx5/GHSA-jfrx-jr32-9rx5.json @@ -7,12 +7,8 @@ "CVE-2019-10602" ], "details": "Potential use-after-free heap error during Validate/Present calls on display HW composer in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, QCS605, SDA660, SDM845, SDX20, SM8150", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jg4r-x6fh-qvrv/GHSA-jg4r-x6fh-qvrv.json b/advisories/unreviewed/2022/05/GHSA-jg4r-x6fh-qvrv/GHSA-jg4r-x6fh-qvrv.json index 2f209d18a3d..f1aa130cf51 100644 --- a/advisories/unreviewed/2022/05/GHSA-jg4r-x6fh-qvrv/GHSA-jg4r-x6fh-qvrv.json +++ b/advisories/unreviewed/2022/05/GHSA-jg4r-x6fh-qvrv/GHSA-jg4r-x6fh-qvrv.json @@ -7,12 +7,8 @@ "CVE-2015-1525" ], "details": "audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy application outage) via a crafted application that provides a NULL device address.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jg67-mr48-c26q/GHSA-jg67-mr48-c26q.json b/advisories/unreviewed/2022/05/GHSA-jg67-mr48-c26q/GHSA-jg67-mr48-c26q.json index 0d64049c9b6..0a75ce8ee6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jg67-mr48-c26q/GHSA-jg67-mr48-c26q.json +++ b/advisories/unreviewed/2022/05/GHSA-jg67-mr48-c26q/GHSA-jg67-mr48-c26q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jgq4-w9g4-5f88/GHSA-jgq4-w9g4-5f88.json b/advisories/unreviewed/2022/05/GHSA-jgq4-w9g4-5f88/GHSA-jgq4-w9g4-5f88.json index a875b2e43e5..cc0d85884c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgq4-w9g4-5f88/GHSA-jgq4-w9g4-5f88.json +++ b/advisories/unreviewed/2022/05/GHSA-jgq4-w9g4-5f88/GHSA-jgq4-w9g4-5f88.json @@ -7,12 +7,8 @@ "CVE-2019-18386" ], "details": "Systems management on Unisys Libra and Libra Software Series, with MCP-FIRMWARE through 2019-10-23, can fault and have other unspecified impact when receiving specifically crafted message payloads over a systems management communication channel.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jh4h-8jgf-wfh2/GHSA-jh4h-8jgf-wfh2.json b/advisories/unreviewed/2022/05/GHSA-jh4h-8jgf-wfh2/GHSA-jh4h-8jgf-wfh2.json index c7e66c94827..396e2621a2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-jh4h-8jgf-wfh2/GHSA-jh4h-8jgf-wfh2.json +++ b/advisories/unreviewed/2022/05/GHSA-jh4h-8jgf-wfh2/GHSA-jh4h-8jgf-wfh2.json @@ -7,12 +7,8 @@ "CVE-2019-3682" ], "details": "The docker-kubic package in SUSE CaaS Platform 3.0 before 17.09.1_ce-7.6.1 provided access to an insecure API locally on the Kubernetes master node.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jh64-993m-m2g3/GHSA-jh64-993m-m2g3.json b/advisories/unreviewed/2022/05/GHSA-jh64-993m-m2g3/GHSA-jh64-993m-m2g3.json index 25d0caf4a85..eda4a7225f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-jh64-993m-m2g3/GHSA-jh64-993m-m2g3.json +++ b/advisories/unreviewed/2022/05/GHSA-jh64-993m-m2g3/GHSA-jh64-993m-m2g3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jjfx-w87c-q5r2/GHSA-jjfx-w87c-q5r2.json b/advisories/unreviewed/2022/05/GHSA-jjfx-w87c-q5r2/GHSA-jjfx-w87c-q5r2.json index 5527e3636bf..1f3cd54d4be 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjfx-w87c-q5r2/GHSA-jjfx-w87c-q5r2.json +++ b/advisories/unreviewed/2022/05/GHSA-jjfx-w87c-q5r2/GHSA-jjfx-w87c-q5r2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jmcq-qgf4-cr92/GHSA-jmcq-qgf4-cr92.json b/advisories/unreviewed/2022/05/GHSA-jmcq-qgf4-cr92/GHSA-jmcq-qgf4-cr92.json index c466820f67a..3b4f32d927a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmcq-qgf4-cr92/GHSA-jmcq-qgf4-cr92.json +++ b/advisories/unreviewed/2022/05/GHSA-jmcq-qgf4-cr92/GHSA-jmcq-qgf4-cr92.json @@ -7,12 +7,8 @@ "CVE-2019-12427" ], "details": "Zimbra Collaboration before 8.8.15 Patch 1 is vulnerable to a non-persistent XSS via the Admin Console.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jp3c-fw6r-qc9f/GHSA-jp3c-fw6r-qc9f.json b/advisories/unreviewed/2022/05/GHSA-jp3c-fw6r-qc9f/GHSA-jp3c-fw6r-qc9f.json index 1a716fc76d5..9e12a2c9a27 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp3c-fw6r-qc9f/GHSA-jp3c-fw6r-qc9f.json +++ b/advisories/unreviewed/2022/05/GHSA-jp3c-fw6r-qc9f/GHSA-jp3c-fw6r-qc9f.json @@ -7,12 +7,8 @@ "CVE-2020-0631" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0632, CVE-2020-0633.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jpvr-c9fc-2r4h/GHSA-jpvr-c9fc-2r4h.json b/advisories/unreviewed/2022/05/GHSA-jpvr-c9fc-2r4h/GHSA-jpvr-c9fc-2r4h.json index 6b9cb78769e..e8a372fa8d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-jpvr-c9fc-2r4h/GHSA-jpvr-c9fc-2r4h.json +++ b/advisories/unreviewed/2022/05/GHSA-jpvr-c9fc-2r4h/GHSA-jpvr-c9fc-2r4h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jq6q-rgpf-9wqr/GHSA-jq6q-rgpf-9wqr.json b/advisories/unreviewed/2022/05/GHSA-jq6q-rgpf-9wqr/GHSA-jq6q-rgpf-9wqr.json index 4ec22a35324..b5a56556109 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq6q-rgpf-9wqr/GHSA-jq6q-rgpf-9wqr.json +++ b/advisories/unreviewed/2022/05/GHSA-jq6q-rgpf-9wqr/GHSA-jq6q-rgpf-9wqr.json @@ -7,12 +7,8 @@ "CVE-2019-12619" ], "details": "A vulnerability in the web interface for Cisco SD-WAN Solution vManage could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input that includes SQL statements to an affected system. A successful exploit could allow the attacker to modify entries in some database tables, affecting the integrity of the data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jqfp-59mg-5whf/GHSA-jqfp-59mg-5whf.json b/advisories/unreviewed/2022/05/GHSA-jqfp-59mg-5whf/GHSA-jqfp-59mg-5whf.json index 98a20d90e7d..dc69524f76e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqfp-59mg-5whf/GHSA-jqfp-59mg-5whf.json +++ b/advisories/unreviewed/2022/05/GHSA-jqfp-59mg-5whf/GHSA-jqfp-59mg-5whf.json @@ -7,12 +7,8 @@ "CVE-2019-17338" ], "details": "The user interface component of TIBCO Software Inc.'s TIBCO Patterns - Search contains multiple vulnerabilities that theoretically allow authenticated users to perform persistent cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Patterns - Search: versions 5.4.0 and below.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jqvr-gmgr-wg44/GHSA-jqvr-gmgr-wg44.json b/advisories/unreviewed/2022/05/GHSA-jqvr-gmgr-wg44/GHSA-jqvr-gmgr-wg44.json index 2d9ba282492..330abd33ecf 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqvr-gmgr-wg44/GHSA-jqvr-gmgr-wg44.json +++ b/advisories/unreviewed/2022/05/GHSA-jqvr-gmgr-wg44/GHSA-jqvr-gmgr-wg44.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jv9q-g859-9p32/GHSA-jv9q-g859-9p32.json b/advisories/unreviewed/2022/05/GHSA-jv9q-g859-9p32/GHSA-jv9q-g859-9p32.json index b99e41d4432..aead4d91139 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv9q-g859-9p32/GHSA-jv9q-g859-9p32.json +++ b/advisories/unreviewed/2022/05/GHSA-jv9q-g859-9p32/GHSA-jv9q-g859-9p32.json @@ -7,12 +7,8 @@ "CVE-2020-6962" ], "details": "In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X CARESCAPE Central Station (CSCS) Versions 2.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, an input validation vulnerability exists in the web-based system configuration utility that could allow an attacker to obtain arbitrary remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jvrg-r8j7-vq2j/GHSA-jvrg-r8j7-vq2j.json b/advisories/unreviewed/2022/05/GHSA-jvrg-r8j7-vq2j/GHSA-jvrg-r8j7-vq2j.json index 485ef11652b..0f6d4d9a2a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvrg-r8j7-vq2j/GHSA-jvrg-r8j7-vq2j.json +++ b/advisories/unreviewed/2022/05/GHSA-jvrg-r8j7-vq2j/GHSA-jvrg-r8j7-vq2j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jw5h-8p55-p837/GHSA-jw5h-8p55-p837.json b/advisories/unreviewed/2022/05/GHSA-jw5h-8p55-p837/GHSA-jw5h-8p55-p837.json index 9dd97caf41c..86f9cce2797 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw5h-8p55-p837/GHSA-jw5h-8p55-p837.json +++ b/advisories/unreviewed/2022/05/GHSA-jw5h-8p55-p837/GHSA-jw5h-8p55-p837.json @@ -7,12 +7,8 @@ "CVE-2020-8001" ], "details": "The Intellian Aptus application 1.0.2 for Android has a hardcoded password of intellian for the masteruser FTP account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jwj5-6g58-pxcm/GHSA-jwj5-6g58-pxcm.json b/advisories/unreviewed/2022/05/GHSA-jwj5-6g58-pxcm/GHSA-jwj5-6g58-pxcm.json index d3b556e6cda..b342d9368aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwj5-6g58-pxcm/GHSA-jwj5-6g58-pxcm.json +++ b/advisories/unreviewed/2022/05/GHSA-jwj5-6g58-pxcm/GHSA-jwj5-6g58-pxcm.json @@ -7,12 +7,8 @@ "CVE-2010-5173" ], "details": "** DISPUTED ** Race condition in PC Tools Firewall Plus 6.0.0.88 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jx8v-m4fg-9p3q/GHSA-jx8v-m4fg-9p3q.json b/advisories/unreviewed/2022/05/GHSA-jx8v-m4fg-9p3q/GHSA-jx8v-m4fg-9p3q.json index b19bc7f3f31..cf153a92d1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-jx8v-m4fg-9p3q/GHSA-jx8v-m4fg-9p3q.json +++ b/advisories/unreviewed/2022/05/GHSA-jx8v-m4fg-9p3q/GHSA-jx8v-m4fg-9p3q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m25j-9vv7-x2px/GHSA-m25j-9vv7-x2px.json b/advisories/unreviewed/2022/05/GHSA-m25j-9vv7-x2px/GHSA-m25j-9vv7-x2px.json index e47293f3740..0e828f74998 100644 --- a/advisories/unreviewed/2022/05/GHSA-m25j-9vv7-x2px/GHSA-m25j-9vv7-x2px.json +++ b/advisories/unreviewed/2022/05/GHSA-m25j-9vv7-x2px/GHSA-m25j-9vv7-x2px.json @@ -7,12 +7,8 @@ "CVE-2019-14023" ], "details": "String format issue will occur while processing HLOS data as there is no user input validation to ensure inputs are properly NULL terminated before string copy in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, Nicobar, Rennell, SA6155P, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m25p-vj7m-w42v/GHSA-m25p-vj7m-w42v.json b/advisories/unreviewed/2022/05/GHSA-m25p-vj7m-w42v/GHSA-m25p-vj7m-w42v.json index 5478fe377d9..2195a42dca2 100644 --- a/advisories/unreviewed/2022/05/GHSA-m25p-vj7m-w42v/GHSA-m25p-vj7m-w42v.json +++ b/advisories/unreviewed/2022/05/GHSA-m25p-vj7m-w42v/GHSA-m25p-vj7m-w42v.json @@ -7,12 +7,8 @@ "CVE-2019-15579" ], "details": "An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) where the assignee(s) of a confidential issue in a private project would be disclosed to a guest via milestones.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m325-c3jh-4fj2/GHSA-m325-c3jh-4fj2.json b/advisories/unreviewed/2022/05/GHSA-m325-c3jh-4fj2/GHSA-m325-c3jh-4fj2.json index e40b5864dc9..f59f639e933 100644 --- a/advisories/unreviewed/2022/05/GHSA-m325-c3jh-4fj2/GHSA-m325-c3jh-4fj2.json +++ b/advisories/unreviewed/2022/05/GHSA-m325-c3jh-4fj2/GHSA-m325-c3jh-4fj2.json @@ -7,12 +7,8 @@ "CVE-2010-5168" ], "details": "** DISPUTED ** Race condition in Symantec Norton Internet Security 2010 17.5.0.127 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m3cf-7w8f-6xqq/GHSA-m3cf-7w8f-6xqq.json b/advisories/unreviewed/2022/05/GHSA-m3cf-7w8f-6xqq/GHSA-m3cf-7w8f-6xqq.json index 174f8580039..d86cef9feec 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3cf-7w8f-6xqq/GHSA-m3cf-7w8f-6xqq.json +++ b/advisories/unreviewed/2022/05/GHSA-m3cf-7w8f-6xqq/GHSA-m3cf-7w8f-6xqq.json @@ -7,12 +7,8 @@ "CVE-2019-14036" ], "details": "Possible buffer overflow issue in error processing due to improper validation of array index value in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8064, APQ8096AU, IPQ4019, IPQ8064, IPQ8074, MDM9607, MDM9615, MDM9640, MSM8996AU, QCN7605", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m3f5-3rcf-qv7q/GHSA-m3f5-3rcf-qv7q.json b/advisories/unreviewed/2022/05/GHSA-m3f5-3rcf-qv7q/GHSA-m3f5-3rcf-qv7q.json index 82225d5127d..56032b25568 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3f5-3rcf-qv7q/GHSA-m3f5-3rcf-qv7q.json +++ b/advisories/unreviewed/2022/05/GHSA-m3f5-3rcf-qv7q/GHSA-m3f5-3rcf-qv7q.json @@ -7,12 +7,8 @@ "CVE-2020-2510" ], "details": "Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via OracleNet to compromise Core RDBMS. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Core RDBMS. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m426-pvh6-58mh/GHSA-m426-pvh6-58mh.json b/advisories/unreviewed/2022/05/GHSA-m426-pvh6-58mh/GHSA-m426-pvh6-58mh.json index 3d0a79a32e2..9016a02a962 100644 --- a/advisories/unreviewed/2022/05/GHSA-m426-pvh6-58mh/GHSA-m426-pvh6-58mh.json +++ b/advisories/unreviewed/2022/05/GHSA-m426-pvh6-58mh/GHSA-m426-pvh6-58mh.json @@ -7,12 +7,8 @@ "CVE-2020-1609" ], "details": "When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv6 packets who may then arbitrarily execute commands as root on the target device. This issue affects IPv6 JDHCPD services. This issue affects: Juniper Networks Junos OS: 15.1 versions prior to 15.1R7-S6; 15.1X49 versions prior to 15.1X49-D200; 15.1X53 versions prior to 15.1X53-D592; 16.1 versions prior to 16.1R7-S6; 16.2 versions prior to 16.2R2-S11; 17.1 versions prior to 17.1R2-S11, 17.1R3-S1; 17.2 versions prior to 17.2R2-S8, 17.2R3-S3; 17.3 versions prior to 17.3R3-S6; 17.4 versions prior to 17.4R2-S7, 17.4R3; 18.1 versions prior to 18.1R3-S8; 18.2 versions prior to 18.2R3-S2; 18.2X75 versions prior to 18.2X75-D60; 18.3 versions prior to 18.3R1-S6, 18.3R2-S2, 18.3R3; 18.4 versions prior to 18.4R1-S5, 18.4R2-S3, 18.4R3; 19.1 versions prior to 19.1R1-S3, 19.1R2; 19.2 versions prior to 19.2R1-S3, 19.2R2*. and All versions prior to 19.3R1 on Junos OS Evolved. This issue do not affect versions of Junos OS prior to 15.1, or JDHCPD operating as a local server in non-relay mode.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m5gx-r8rq-3635/GHSA-m5gx-r8rq-3635.json b/advisories/unreviewed/2022/05/GHSA-m5gx-r8rq-3635/GHSA-m5gx-r8rq-3635.json index 9cdecec2f97..9bbbf742722 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5gx-r8rq-3635/GHSA-m5gx-r8rq-3635.json +++ b/advisories/unreviewed/2022/05/GHSA-m5gx-r8rq-3635/GHSA-m5gx-r8rq-3635.json @@ -7,12 +7,8 @@ "CVE-2019-15578" ], "details": "An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). The path of a private project, that used to be public, would be disclosed in the unsubscribe email link of issues and merge requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m5v4-45rr-7w82/GHSA-m5v4-45rr-7w82.json b/advisories/unreviewed/2022/05/GHSA-m5v4-45rr-7w82/GHSA-m5v4-45rr-7w82.json index b606452feb3..e62dcd22580 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5v4-45rr-7w82/GHSA-m5v4-45rr-7w82.json +++ b/advisories/unreviewed/2022/05/GHSA-m5v4-45rr-7w82/GHSA-m5v4-45rr-7w82.json @@ -7,12 +7,8 @@ "CVE-2019-15010" ], "details": "Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from version 6.7.0 before 6.7.3, from version 6.8.0 before 6.8.2, and from version 6.9.0 before 6.9.1 had a Remote Code Execution vulnerability via certain user input fields. A remote attacker with user level permissions can exploit this vulnerability to run arbitrary commands on the victim's systems. Using a specially crafted payload as user input, the attacker can execute arbitrary commands on the victim's Bitbucket Server or Bitbucket Data Center instance.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m72g-c559-jm3c/GHSA-m72g-c559-jm3c.json b/advisories/unreviewed/2022/05/GHSA-m72g-c559-jm3c/GHSA-m72g-c559-jm3c.json index 77144936972..3843bf1cdd5 100644 --- a/advisories/unreviewed/2022/05/GHSA-m72g-c559-jm3c/GHSA-m72g-c559-jm3c.json +++ b/advisories/unreviewed/2022/05/GHSA-m72g-c559-jm3c/GHSA-m72g-c559-jm3c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m7f5-359q-mv7c/GHSA-m7f5-359q-mv7c.json b/advisories/unreviewed/2022/05/GHSA-m7f5-359q-mv7c/GHSA-m7f5-359q-mv7c.json index b776ce931e6..c368a323f38 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7f5-359q-mv7c/GHSA-m7f5-359q-mv7c.json +++ b/advisories/unreviewed/2022/05/GHSA-m7f5-359q-mv7c/GHSA-m7f5-359q-mv7c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m7x5-4x88-qpg9/GHSA-m7x5-4x88-qpg9.json b/advisories/unreviewed/2022/05/GHSA-m7x5-4x88-qpg9/GHSA-m7x5-4x88-qpg9.json index f7cb2048985..c3ed8736771 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7x5-4x88-qpg9/GHSA-m7x5-4x88-qpg9.json +++ b/advisories/unreviewed/2022/05/GHSA-m7x5-4x88-qpg9/GHSA-m7x5-4x88-qpg9.json @@ -7,12 +7,8 @@ "CVE-2016-6586" ], "details": "A security bypass vulnerability exists in Symantec Norton Mobile Security for Android before 3.16, which could let a malicious user conduct a man-in-the-middle via specially crafted JavaScript to add arbitrary URLs to the URL whitelist.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m7xx-f5wc-r7rf/GHSA-m7xx-f5wc-r7rf.json b/advisories/unreviewed/2022/05/GHSA-m7xx-f5wc-r7rf/GHSA-m7xx-f5wc-r7rf.json index da8e7f4688f..d4751697070 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7xx-f5wc-r7rf/GHSA-m7xx-f5wc-r7rf.json +++ b/advisories/unreviewed/2022/05/GHSA-m7xx-f5wc-r7rf/GHSA-m7xx-f5wc-r7rf.json @@ -7,12 +7,8 @@ "CVE-2019-16513" ], "details": "An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to send API requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m896-wg3p-7ffv/GHSA-m896-wg3p-7ffv.json b/advisories/unreviewed/2022/05/GHSA-m896-wg3p-7ffv/GHSA-m896-wg3p-7ffv.json index b53fe6cb1b8..71073963865 100644 --- a/advisories/unreviewed/2022/05/GHSA-m896-wg3p-7ffv/GHSA-m896-wg3p-7ffv.json +++ b/advisories/unreviewed/2022/05/GHSA-m896-wg3p-7ffv/GHSA-m896-wg3p-7ffv.json @@ -7,12 +7,8 @@ "CVE-2011-5094" ], "details": "** DISPUTED ** Mozilla Network Security Services (NSS) 3.x, with certain settings of the SSL_ENABLE_RENEGOTIATION option, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection, a different vulnerability than CVE-2011-1473. NOTE: it can also be argued that it is the responsibility of server deployments, not a security library, to prevent or limit renegotiation when it is inappropriate within a specific environment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m9wr-4mrf-cqjr/GHSA-m9wr-4mrf-cqjr.json b/advisories/unreviewed/2022/05/GHSA-m9wr-4mrf-cqjr/GHSA-m9wr-4mrf-cqjr.json index b4b1c031e2a..bab5cbbfbd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9wr-4mrf-cqjr/GHSA-m9wr-4mrf-cqjr.json +++ b/advisories/unreviewed/2022/05/GHSA-m9wr-4mrf-cqjr/GHSA-m9wr-4mrf-cqjr.json @@ -7,12 +7,8 @@ "CVE-2019-16153" ], "details": "A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device database via the use of static credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mgr5-cghm-p294/GHSA-mgr5-cghm-p294.json b/advisories/unreviewed/2022/05/GHSA-mgr5-cghm-p294/GHSA-mgr5-cghm-p294.json index d80cabb79e5..c854f1ac8cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgr5-cghm-p294/GHSA-mgr5-cghm-p294.json +++ b/advisories/unreviewed/2022/05/GHSA-mgr5-cghm-p294/GHSA-mgr5-cghm-p294.json @@ -7,12 +7,8 @@ "CVE-2019-20422" ], "details": "In the Linux kernel before 5.3.4, fib6_rule_lookup in net/ipv6/ip6_fib.c mishandles the RT6_LOOKUP_F_DST_NOREF flag in a reference-count decision, leading to (for example) a crash that was identified by syzkaller, aka CID-7b09c2d052db.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mh9g-8cm9-c5wj/GHSA-mh9g-8cm9-c5wj.json b/advisories/unreviewed/2022/05/GHSA-mh9g-8cm9-c5wj/GHSA-mh9g-8cm9-c5wj.json index 5d1c81c2b98..21007d71587 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh9g-8cm9-c5wj/GHSA-mh9g-8cm9-c5wj.json +++ b/advisories/unreviewed/2022/05/GHSA-mh9g-8cm9-c5wj/GHSA-mh9g-8cm9-c5wj.json @@ -7,12 +7,8 @@ "CVE-2019-19539" ], "details": "An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading ADB or AADB file content within the Installation subvolume, a Guardian user can discover the password of the group.user or alias who acknowledges events from the WVP Events screen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mm94-7vgx-886f/GHSA-mm94-7vgx-886f.json b/advisories/unreviewed/2022/05/GHSA-mm94-7vgx-886f/GHSA-mm94-7vgx-886f.json index ccad83464c7..11cd9a32518 100644 --- a/advisories/unreviewed/2022/05/GHSA-mm94-7vgx-886f/GHSA-mm94-7vgx-886f.json +++ b/advisories/unreviewed/2022/05/GHSA-mm94-7vgx-886f/GHSA-mm94-7vgx-886f.json @@ -7,12 +7,8 @@ "CVE-2019-6858" ], "details": "A CWE-427:Uncontrolled Search Path Element vulnerability exists in MSX Configurator (Software Version prior to V1.0.8.1), which could cause privilege escalation when injecting a malicious DLL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mpp6-gpg9-88j7/GHSA-mpp6-gpg9-88j7.json b/advisories/unreviewed/2022/05/GHSA-mpp6-gpg9-88j7/GHSA-mpp6-gpg9-88j7.json index eae92b1c2ff..445f32ceb35 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpp6-gpg9-88j7/GHSA-mpp6-gpg9-88j7.json +++ b/advisories/unreviewed/2022/05/GHSA-mpp6-gpg9-88j7/GHSA-mpp6-gpg9-88j7.json @@ -7,12 +7,8 @@ "CVE-2019-9510" ], "details": "A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow authenticated RDP-connected clients to gain access to user sessions without needing to interact with the Windows lock screen. Should a network anomaly trigger a temporary RDP disconnect, Automatic Reconnection of the RDP session will be restored to an unlocked state, regardless of how the remote system was left. By interrupting network connectivity of a system, an attacker with access to a system being used as a Windows RDP client can gain access to a connected remote system, regardless of whether or not the remote system was locked. This issue affects Microsoft Windows 10, version 1803 and later, and Microsoft Windows Server 2019, version 2019 and later.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mqgr-236j-cjw3/GHSA-mqgr-236j-cjw3.json b/advisories/unreviewed/2022/05/GHSA-mqgr-236j-cjw3/GHSA-mqgr-236j-cjw3.json index 620a5918c5e..af7ddf51bea 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqgr-236j-cjw3/GHSA-mqgr-236j-cjw3.json +++ b/advisories/unreviewed/2022/05/GHSA-mqgr-236j-cjw3/GHSA-mqgr-236j-cjw3.json @@ -7,12 +7,8 @@ "CVE-2010-5178" ], "details": "** DISPUTED ** Race condition in ThreatFire 4.7.0.17 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mrq9-3vcx-54jj/GHSA-mrq9-3vcx-54jj.json b/advisories/unreviewed/2022/05/GHSA-mrq9-3vcx-54jj/GHSA-mrq9-3vcx-54jj.json index a074d2f20be..3f1d8230546 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrq9-3vcx-54jj/GHSA-mrq9-3vcx-54jj.json +++ b/advisories/unreviewed/2022/05/GHSA-mrq9-3vcx-54jj/GHSA-mrq9-3vcx-54jj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mvvw-jprx-cf6j/GHSA-mvvw-jprx-cf6j.json b/advisories/unreviewed/2022/05/GHSA-mvvw-jprx-cf6j/GHSA-mvvw-jprx-cf6j.json index 1e8b28c38d1..225221215bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvvw-jprx-cf6j/GHSA-mvvw-jprx-cf6j.json +++ b/advisories/unreviewed/2022/05/GHSA-mvvw-jprx-cf6j/GHSA-mvvw-jprx-cf6j.json @@ -7,12 +7,8 @@ "CVE-2020-2694" ], "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.18 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mx46-jh22-vrmf/GHSA-mx46-jh22-vrmf.json b/advisories/unreviewed/2022/05/GHSA-mx46-jh22-vrmf/GHSA-mx46-jh22-vrmf.json index 930bd7ec741..c39f0634973 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx46-jh22-vrmf/GHSA-mx46-jh22-vrmf.json +++ b/advisories/unreviewed/2022/05/GHSA-mx46-jh22-vrmf/GHSA-mx46-jh22-vrmf.json @@ -7,12 +7,8 @@ "CVE-2020-2727" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mx6q-9p52-pgfg/GHSA-mx6q-9p52-pgfg.json b/advisories/unreviewed/2022/05/GHSA-mx6q-9p52-pgfg/GHSA-mx6q-9p52-pgfg.json index 4b72b37e8fc..2133f7a40b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx6q-9p52-pgfg/GHSA-mx6q-9p52-pgfg.json +++ b/advisories/unreviewed/2022/05/GHSA-mx6q-9p52-pgfg/GHSA-mx6q-9p52-pgfg.json @@ -7,12 +7,8 @@ "CVE-2010-5162" ], "details": "** DISPUTED ** Race condition in G DATA TotalCare 2010 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mxqh-xqpx-hxg6/GHSA-mxqh-xqpx-hxg6.json b/advisories/unreviewed/2022/05/GHSA-mxqh-xqpx-hxg6/GHSA-mxqh-xqpx-hxg6.json index 51c8227fb11..4ab6478f59f 100644 --- a/advisories/unreviewed/2022/05/GHSA-mxqh-xqpx-hxg6/GHSA-mxqh-xqpx-hxg6.json +++ b/advisories/unreviewed/2022/05/GHSA-mxqh-xqpx-hxg6/GHSA-mxqh-xqpx-hxg6.json @@ -7,12 +7,8 @@ "CVE-2010-5174" ], "details": "** DISPUTED ** Race condition in Prevx 3.0.5.143 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mxrx-hwh2-j2jm/GHSA-mxrx-hwh2-j2jm.json b/advisories/unreviewed/2022/05/GHSA-mxrx-hwh2-j2jm/GHSA-mxrx-hwh2-j2jm.json index 6a7f03feafa..bcbe5e83d6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mxrx-hwh2-j2jm/GHSA-mxrx-hwh2-j2jm.json +++ b/advisories/unreviewed/2022/05/GHSA-mxrx-hwh2-j2jm/GHSA-mxrx-hwh2-j2jm.json @@ -7,12 +7,8 @@ "CVE-2019-17357" ], "details": "Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifiers are handled when a string and id composite value are used to identify the template type and id. An authenticated attacker can exploit this to extract data from the database, or an unauthenticated remote attacker could exploit this via Cross-Site Request Forgery.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p225-mhq8-69hw/GHSA-p225-mhq8-69hw.json b/advisories/unreviewed/2022/05/GHSA-p225-mhq8-69hw/GHSA-p225-mhq8-69hw.json index 458c5c7fcc3..1a3f2935323 100644 --- a/advisories/unreviewed/2022/05/GHSA-p225-mhq8-69hw/GHSA-p225-mhq8-69hw.json +++ b/advisories/unreviewed/2022/05/GHSA-p225-mhq8-69hw/GHSA-p225-mhq8-69hw.json @@ -7,12 +7,8 @@ "CVE-2019-15255" ], "details": "A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access sensitive information related to the device. The vulnerability exists because the software fails to sanitize URLs before it handles requests. An attacker could exploit this vulnerability by submitting a crafted URL. A successful exploit could allow the attacker to gain unauthorized access to sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p258-72gh-7cxv/GHSA-p258-72gh-7cxv.json b/advisories/unreviewed/2022/05/GHSA-p258-72gh-7cxv/GHSA-p258-72gh-7cxv.json index 426664fa6ac..41daf4761c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-p258-72gh-7cxv/GHSA-p258-72gh-7cxv.json +++ b/advisories/unreviewed/2022/05/GHSA-p258-72gh-7cxv/GHSA-p258-72gh-7cxv.json @@ -7,12 +7,8 @@ "CVE-2020-5842" ], "details": "Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. The payload is, for example, executed on the admin/index.php?page=users/manage page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p2gq-5gw7-3mp6/GHSA-p2gq-5gw7-3mp6.json b/advisories/unreviewed/2022/05/GHSA-p2gq-5gw7-3mp6/GHSA-p2gq-5gw7-3mp6.json index 948960fe830..00cdb36ec4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2gq-5gw7-3mp6/GHSA-p2gq-5gw7-3mp6.json +++ b/advisories/unreviewed/2022/05/GHSA-p2gq-5gw7-3mp6/GHSA-p2gq-5gw7-3mp6.json @@ -7,12 +7,8 @@ "CVE-2010-5152" ], "details": "** DISPUTED ** Race condition in AVG Internet Security 9.0.791 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p323-w8wx-j9rr/GHSA-p323-w8wx-j9rr.json b/advisories/unreviewed/2022/05/GHSA-p323-w8wx-j9rr/GHSA-p323-w8wx-j9rr.json index 1a13cbaf7fe..c80771d7c58 100644 --- a/advisories/unreviewed/2022/05/GHSA-p323-w8wx-j9rr/GHSA-p323-w8wx-j9rr.json +++ b/advisories/unreviewed/2022/05/GHSA-p323-w8wx-j9rr/GHSA-p323-w8wx-j9rr.json @@ -7,12 +7,8 @@ "CVE-2019-1414" ], "details": "An elevation of privilege vulnerability exists in Visual Studio Code when it exposes a debug listener to users of a local computer, aka 'Visual Studio Code Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p382-hh5c-h4rq/GHSA-p382-hh5c-h4rq.json b/advisories/unreviewed/2022/05/GHSA-p382-hh5c-h4rq/GHSA-p382-hh5c-h4rq.json index dfff4bde54d..d05cb2d94de 100644 --- a/advisories/unreviewed/2022/05/GHSA-p382-hh5c-h4rq/GHSA-p382-hh5c-h4rq.json +++ b/advisories/unreviewed/2022/05/GHSA-p382-hh5c-h4rq/GHSA-p382-hh5c-h4rq.json @@ -7,12 +7,8 @@ "CVE-2020-3121" ], "details": "A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link and access a specific page. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p3r5-5655-2pq8/GHSA-p3r5-5655-2pq8.json b/advisories/unreviewed/2022/05/GHSA-p3r5-5655-2pq8/GHSA-p3r5-5655-2pq8.json index 02e422008c2..239d78b3808 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3r5-5655-2pq8/GHSA-p3r5-5655-2pq8.json +++ b/advisories/unreviewed/2022/05/GHSA-p3r5-5655-2pq8/GHSA-p3r5-5655-2pq8.json @@ -7,12 +7,8 @@ "CVE-2020-7915" ], "details": "An issue was discovered on Eaton 5P 850 devices. The Ubicacion SAI field allows XSS attacks by an administrator.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p43q-wjv5-rf63/GHSA-p43q-wjv5-rf63.json b/advisories/unreviewed/2022/05/GHSA-p43q-wjv5-rf63/GHSA-p43q-wjv5-rf63.json index 0aebf6c79aa..04951eb67b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-p43q-wjv5-rf63/GHSA-p43q-wjv5-rf63.json +++ b/advisories/unreviewed/2022/05/GHSA-p43q-wjv5-rf63/GHSA-p43q-wjv5-rf63.json @@ -7,12 +7,8 @@ "CVE-2019-20327" ], "details": "Insecure permissions in cwrapper_perl in Centreon Infrastructure Monitoring Software through 19.10 allow local attackers to gain privileges. (cwrapper_perl is a setuid executable allowing execution of Perl scripts with root privileges.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p4gw-2vrq-j64q/GHSA-p4gw-2vrq-j64q.json b/advisories/unreviewed/2022/05/GHSA-p4gw-2vrq-j64q/GHSA-p4gw-2vrq-j64q.json index 85031d62d17..55820b72640 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4gw-2vrq-j64q/GHSA-p4gw-2vrq-j64q.json +++ b/advisories/unreviewed/2022/05/GHSA-p4gw-2vrq-j64q/GHSA-p4gw-2vrq-j64q.json @@ -7,12 +7,8 @@ "CVE-2019-20421" ], "details": "In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p4x7-xx93-8jx9/GHSA-p4x7-xx93-8jx9.json b/advisories/unreviewed/2022/05/GHSA-p4x7-xx93-8jx9/GHSA-p4x7-xx93-8jx9.json index fedf66e31e4..f824558b42b 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4x7-xx93-8jx9/GHSA-p4x7-xx93-8jx9.json +++ b/advisories/unreviewed/2022/05/GHSA-p4x7-xx93-8jx9/GHSA-p4x7-xx93-8jx9.json @@ -7,12 +7,8 @@ "CVE-2020-1604" ], "details": "On EX4300, EX4600, QFX3500, and QFX5100 Series, a vulnerability in the IP firewall filter component may cause the firewall filter evaluation of certain packets to fail. This issue only affects firewall filter evaluation of certain packets destined to the device Routing Engine (RE). This issue does not affect the Layer 2 firewall filter evaluation nor does it affect the Layer 3 firewall filter evaluation destined to connected hosts. This issue may occur when evaluating both IPv4 or IPv6 packets. This issue affects Juniper Networks Junos OS: 14.1X53 versions prior to 14.1X53-D12 on QFX5100 Series and EX4600 Series; 14.1X53 versions prior to 14.1X53-D52 on QFX3500 Series; 14.1X53 versions prior to 14.1X53-D48 on EX4300 Series; 15.1 versions prior to 15.1R7-S3 on EX4300 Series; 16.1 versions prior to 16.1R7 on EX4300 Series; 17.1 versions prior to 17.1R3 on EX4300 Series; 17.2 versions prior to 17.2R3 on EX4300 Series; 17.3 versions prior to 17.3R2-S5, 17.3R3 on EX4300 Series; 17.4 versions prior to 17.4R2 on EX4300 Series; 18.1 versions prior to 18.1R3 on EX4300 Series; 18.2 versions prior to 18.2R2 on EX4300 Series.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p5fw-27pc-f5xw/GHSA-p5fw-27pc-f5xw.json b/advisories/unreviewed/2022/05/GHSA-p5fw-27pc-f5xw/GHSA-p5fw-27pc-f5xw.json index 1bac27e4ac1..b780730e14a 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5fw-27pc-f5xw/GHSA-p5fw-27pc-f5xw.json +++ b/advisories/unreviewed/2022/05/GHSA-p5fw-27pc-f5xw/GHSA-p5fw-27pc-f5xw.json @@ -7,12 +7,8 @@ "CVE-2019-19801" ], "details": "In Gallagher Command Centre Server versions of v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prior to v7.80.960(MR2) and v7.70 or earlier, an unprivileged but authenticated user is able to perform a backup of the Command Centre databases.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p5ph-6r6q-v52v/GHSA-p5ph-6r6q-v52v.json b/advisories/unreviewed/2022/05/GHSA-p5ph-6r6q-v52v/GHSA-p5ph-6r6q-v52v.json index e4e4a7b1d0a..b2a14534c29 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5ph-6r6q-v52v/GHSA-p5ph-6r6q-v52v.json +++ b/advisories/unreviewed/2022/05/GHSA-p5ph-6r6q-v52v/GHSA-p5ph-6r6q-v52v.json @@ -7,12 +7,8 @@ "CVE-2019-15313" ], "details": "In Zimbra Collaboration before 8.8.15 Patch 1, there is a non-persistent XSS vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p7jq-xxp7-m959/GHSA-p7jq-xxp7-m959.json b/advisories/unreviewed/2022/05/GHSA-p7jq-xxp7-m959/GHSA-p7jq-xxp7-m959.json index 0d411c86b3c..c6a03ca97d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7jq-xxp7-m959/GHSA-p7jq-xxp7-m959.json +++ b/advisories/unreviewed/2022/05/GHSA-p7jq-xxp7-m959/GHSA-p7jq-xxp7-m959.json @@ -7,12 +7,8 @@ "CVE-2020-7235" ], "details": "UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cB3?ta= (profile title).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p8mr-8r67-3qg2/GHSA-p8mr-8r67-3qg2.json b/advisories/unreviewed/2022/05/GHSA-p8mr-8r67-3qg2/GHSA-p8mr-8r67-3qg2.json index 27533b29783..0544b432fa7 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8mr-8r67-3qg2/GHSA-p8mr-8r67-3qg2.json +++ b/advisories/unreviewed/2022/05/GHSA-p8mr-8r67-3qg2/GHSA-p8mr-8r67-3qg2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p8w7-f589-855p/GHSA-p8w7-f589-855p.json b/advisories/unreviewed/2022/05/GHSA-p8w7-f589-855p/GHSA-p8w7-f589-855p.json index b1c2faab3f7..bfe86687b82 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8w7-f589-855p/GHSA-p8w7-f589-855p.json +++ b/advisories/unreviewed/2022/05/GHSA-p8w7-f589-855p/GHSA-p8w7-f589-855p.json @@ -7,12 +7,8 @@ "CVE-2020-1601" ], "details": "Certain types of malformed Path Computation Element Protocol (PCEP) packets when received and processed by a Juniper Networks Junos OS device serving as a Path Computation Client (PCC) in a PCEP environment using Juniper's path computational element protocol daemon (pccd) process allows an attacker to cause the pccd process to crash and generate a core file thereby causing a Denial of Service (DoS). Continued receipt of this family of malformed PCEP packets will cause an extended Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS: 15.1 versions prior to 15.1F6-S13, 15.1R7-S4; 15.1X49 versions prior to 15.1X49-D180 on SRX Series; 15.1X53 versions prior to 15.1X53-D238, 15.1X53-D496, 15.1X53-D592; 16.1 versions prior to 16.1R7-S4; 16.2 versions prior to 16.2R2-S9; 17.1 versions prior to 17.1R2-S11, 17.1R3; 17.2 versions prior to 17.2R1-S9; 17.2 version 17.2R2 and later prior to 17.2R3-S2; 17.3 versions prior to 17.3R3-S3; 17.4 versions prior to 17.4R2-S2, 17.4R3; 18.1 versions prior to 18.1R3-S2; 18.2 versions prior to 18.2R2-S6, 18.2R3; 18.2X75 versions prior to 18.2X75-D40; 18.3 versions prior to 18.3R2; 18.4 versions prior to 18.4R1-S2, 18.4R2. This issue does not affect releases of Junos OS prior to 15.1R1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p94h-hv32-7pp5/GHSA-p94h-hv32-7pp5.json b/advisories/unreviewed/2022/05/GHSA-p94h-hv32-7pp5/GHSA-p94h-hv32-7pp5.json index b1cce044dfc..55fa217b727 100644 --- a/advisories/unreviewed/2022/05/GHSA-p94h-hv32-7pp5/GHSA-p94h-hv32-7pp5.json +++ b/advisories/unreviewed/2022/05/GHSA-p94h-hv32-7pp5/GHSA-p94h-hv32-7pp5.json @@ -7,12 +7,8 @@ "CVE-2019-16515" ], "details": "An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. Certain HTTP security headers are not used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pc6v-mhvm-cpxc/GHSA-pc6v-mhvm-cpxc.json b/advisories/unreviewed/2022/05/GHSA-pc6v-mhvm-cpxc/GHSA-pc6v-mhvm-cpxc.json index 21785b4b6b0..c1b619c9c0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc6v-mhvm-cpxc/GHSA-pc6v-mhvm-cpxc.json +++ b/advisories/unreviewed/2022/05/GHSA-pc6v-mhvm-cpxc/GHSA-pc6v-mhvm-cpxc.json @@ -7,12 +7,8 @@ "CVE-2020-7104" ], "details": "The chained-quiz plugin 1.1.8.1 for WordPress has reflected XSS via the wp-admin/admin-ajax.php total_questions parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pcxf-xvjr-2qpp/GHSA-pcxf-xvjr-2qpp.json b/advisories/unreviewed/2022/05/GHSA-pcxf-xvjr-2qpp/GHSA-pcxf-xvjr-2qpp.json index 09d33f0c29a..1f323fb8180 100644 --- a/advisories/unreviewed/2022/05/GHSA-pcxf-xvjr-2qpp/GHSA-pcxf-xvjr-2qpp.json +++ b/advisories/unreviewed/2022/05/GHSA-pcxf-xvjr-2qpp/GHSA-pcxf-xvjr-2qpp.json @@ -7,12 +7,8 @@ "CVE-2019-17001" ], "details": "A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-site scripting). This is a separate bypass from CVE-2019-17000.*Note: This flaw only affected Firefox 69 and was not present in earlier versions.*. This vulnerability affects Firefox < 70.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pf8r-qgp9-4jg6/GHSA-pf8r-qgp9-4jg6.json b/advisories/unreviewed/2022/05/GHSA-pf8r-qgp9-4jg6/GHSA-pf8r-qgp9-4jg6.json index a0d8feff0a2..a32e0dee198 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf8r-qgp9-4jg6/GHSA-pf8r-qgp9-4jg6.json +++ b/advisories/unreviewed/2022/05/GHSA-pf8r-qgp9-4jg6/GHSA-pf8r-qgp9-4jg6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pfwx-2ff5-2g47/GHSA-pfwx-2ff5-2g47.json b/advisories/unreviewed/2022/05/GHSA-pfwx-2ff5-2g47/GHSA-pfwx-2ff5-2g47.json index cd787ce529c..74ab2565b9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfwx-2ff5-2g47/GHSA-pfwx-2ff5-2g47.json +++ b/advisories/unreviewed/2022/05/GHSA-pfwx-2ff5-2g47/GHSA-pfwx-2ff5-2g47.json @@ -7,12 +7,8 @@ "CVE-2019-3683" ], "details": "The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full \"member\" role access to every project. This allowed these users to access, modify, create and delete arbitrary resources, contrary to expectations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-phw9-c32c-4w9f/GHSA-phw9-c32c-4w9f.json b/advisories/unreviewed/2022/05/GHSA-phw9-c32c-4w9f/GHSA-phw9-c32c-4w9f.json index 473e7f939f0..4484e66a739 100644 --- a/advisories/unreviewed/2022/05/GHSA-phw9-c32c-4w9f/GHSA-phw9-c32c-4w9f.json +++ b/advisories/unreviewed/2022/05/GHSA-phw9-c32c-4w9f/GHSA-phw9-c32c-4w9f.json @@ -7,12 +7,8 @@ "CVE-2010-5163" ], "details": "** DISPUTED ** Race condition in Kaspersky Internet Security 2010 9.0.0.736 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pj9f-2gxf-pvc4/GHSA-pj9f-2gxf-pvc4.json b/advisories/unreviewed/2022/05/GHSA-pj9f-2gxf-pvc4/GHSA-pj9f-2gxf-pvc4.json index 9db6181d9b8..65754d3434e 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj9f-2gxf-pvc4/GHSA-pj9f-2gxf-pvc4.json +++ b/advisories/unreviewed/2022/05/GHSA-pj9f-2gxf-pvc4/GHSA-pj9f-2gxf-pvc4.json @@ -7,12 +7,8 @@ "CVE-2020-0634" ], "details": "An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pjxv-9x67-5rmj/GHSA-pjxv-9x67-5rmj.json b/advisories/unreviewed/2022/05/GHSA-pjxv-9x67-5rmj/GHSA-pjxv-9x67-5rmj.json index 1154305d341..91772bd0b03 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjxv-9x67-5rmj/GHSA-pjxv-9x67-5rmj.json +++ b/advisories/unreviewed/2022/05/GHSA-pjxv-9x67-5rmj/GHSA-pjxv-9x67-5rmj.json @@ -7,12 +7,8 @@ "CVE-2019-15742" ], "details": "A local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application. A local attacker can exploit this issue to gain elevated privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pm6q-ff9r-9f8w/GHSA-pm6q-ff9r-9f8w.json b/advisories/unreviewed/2022/05/GHSA-pm6q-ff9r-9f8w/GHSA-pm6q-ff9r-9f8w.json index d298a155b26..7f2f771b70a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pm6q-ff9r-9f8w/GHSA-pm6q-ff9r-9f8w.json +++ b/advisories/unreviewed/2022/05/GHSA-pm6q-ff9r-9f8w/GHSA-pm6q-ff9r-9f8w.json @@ -7,12 +7,8 @@ "CVE-2018-16262" ], "details": "The pkgmgr system service in Tizen allows an unprivileged process to perform package management actions, due to improper D-Bus security policy configurations. Such actions include installing, decrypting, and killing other packages. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ppjv-mwcc-539j/GHSA-ppjv-mwcc-539j.json b/advisories/unreviewed/2022/05/GHSA-ppjv-mwcc-539j/GHSA-ppjv-mwcc-539j.json index 7e68afdce19..c4c6d03e458 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppjv-mwcc-539j/GHSA-ppjv-mwcc-539j.json +++ b/advisories/unreviewed/2022/05/GHSA-ppjv-mwcc-539j/GHSA-ppjv-mwcc-539j.json @@ -7,12 +7,8 @@ "CVE-2020-5202" ], "details": "apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port 3142, even if the explicit SocketPath=/var/run/apt-cacher-ng/socket command-line option is passed. The cron job /etc/cron.daily/apt-cacher-ng (which is active by default) attempts this periodically. Because 3142 is an unprivileged port, any local user can try to bind to this port and will receive requests from acngtool. There can be sensitive data in these requests, e.g., if AdminAuth is enabled in /etc/apt-cacher-ng/security.conf. This sensitive data can leak to unprivileged local users that manage to bind to this port before the apt-cacher-ng daemon can.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ppjx-8528-9c77/GHSA-ppjx-8528-9c77.json b/advisories/unreviewed/2022/05/GHSA-ppjx-8528-9c77/GHSA-ppjx-8528-9c77.json index a92406f8118..09df3740a62 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppjx-8528-9c77/GHSA-ppjx-8528-9c77.json +++ b/advisories/unreviewed/2022/05/GHSA-ppjx-8528-9c77/GHSA-ppjx-8528-9c77.json @@ -7,12 +7,8 @@ "CVE-2020-2704" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ppvv-3w29-f4j8/GHSA-ppvv-3w29-f4j8.json b/advisories/unreviewed/2022/05/GHSA-ppvv-3w29-f4j8/GHSA-ppvv-3w29-f4j8.json index 49b174d9386..aa2b7b5fc65 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppvv-3w29-f4j8/GHSA-ppvv-3w29-f4j8.json +++ b/advisories/unreviewed/2022/05/GHSA-ppvv-3w29-f4j8/GHSA-ppvv-3w29-f4j8.json @@ -7,12 +7,8 @@ "CVE-2019-5183" ], "details": "An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, versions 26.20.13031.10003, 26.20.13031.15006 and 26.20.13031.18002. A specially crafted pixel shader can cause a type confusion issue, leading to potential code execution. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-prjf-h86p-335v/GHSA-prjf-h86p-335v.json b/advisories/unreviewed/2022/05/GHSA-prjf-h86p-335v/GHSA-prjf-h86p-335v.json index de2a52967ed..f56fb0eeba9 100644 --- a/advisories/unreviewed/2022/05/GHSA-prjf-h86p-335v/GHSA-prjf-h86p-335v.json +++ b/advisories/unreviewed/2022/05/GHSA-prjf-h86p-335v/GHSA-prjf-h86p-335v.json @@ -7,12 +7,8 @@ "CVE-2020-7594" ], "details": "MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Debug Options page and entering shell metacharacters in the interface JSON field of the ping function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-prx4-w5qv-43g3/GHSA-prx4-w5qv-43g3.json b/advisories/unreviewed/2022/05/GHSA-prx4-w5qv-43g3/GHSA-prx4-w5qv-43g3.json index 5a14a0fd5a3..653a8d6102b 100644 --- a/advisories/unreviewed/2022/05/GHSA-prx4-w5qv-43g3/GHSA-prx4-w5qv-43g3.json +++ b/advisories/unreviewed/2022/05/GHSA-prx4-w5qv-43g3/GHSA-prx4-w5qv-43g3.json @@ -7,12 +7,8 @@ "CVE-2019-15278" ], "details": "A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to bypass authorization and access sensitive information related to the device. The vulnerability exists because the software fails to sanitize URLs before it handles requests. An attacker could exploit this vulnerability by submitting a crafted URL. A successful exploit could allow the attacker to gain unauthorized access to sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pv73-c93j-h78m/GHSA-pv73-c93j-h78m.json b/advisories/unreviewed/2022/05/GHSA-pv73-c93j-h78m/GHSA-pv73-c93j-h78m.json index 1c991c21ff0..cb27d070795 100644 --- a/advisories/unreviewed/2022/05/GHSA-pv73-c93j-h78m/GHSA-pv73-c93j-h78m.json +++ b/advisories/unreviewed/2022/05/GHSA-pv73-c93j-h78m/GHSA-pv73-c93j-h78m.json @@ -7,12 +7,8 @@ "CVE-2019-14615" ], "details": "Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pvfr-m224-2vm2/GHSA-pvfr-m224-2vm2.json b/advisories/unreviewed/2022/05/GHSA-pvfr-m224-2vm2/GHSA-pvfr-m224-2vm2.json index 522f357fe2e..30f83c382e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvfr-m224-2vm2/GHSA-pvfr-m224-2vm2.json +++ b/advisories/unreviewed/2022/05/GHSA-pvfr-m224-2vm2/GHSA-pvfr-m224-2vm2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pvw4-hjvm-ph77/GHSA-pvw4-hjvm-ph77.json b/advisories/unreviewed/2022/05/GHSA-pvw4-hjvm-ph77/GHSA-pvw4-hjvm-ph77.json index ebab7845fc4..8a6af401ea5 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvw4-hjvm-ph77/GHSA-pvw4-hjvm-ph77.json +++ b/advisories/unreviewed/2022/05/GHSA-pvw4-hjvm-ph77/GHSA-pvw4-hjvm-ph77.json @@ -7,12 +7,8 @@ "CVE-2019-10561" ], "details": "Improper initialization of local variables which are parameters to sfs api may cause invalid pointer dereference and leads to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096, APQ8096AU, APQ8098, MDM9206, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, QM215, SDA660, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pwc3-f5rp-xjcq/GHSA-pwc3-f5rp-xjcq.json b/advisories/unreviewed/2022/05/GHSA-pwc3-f5rp-xjcq/GHSA-pwc3-f5rp-xjcq.json index e3c12acf915..4af2f10a469 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwc3-f5rp-xjcq/GHSA-pwc3-f5rp-xjcq.json +++ b/advisories/unreviewed/2022/05/GHSA-pwc3-f5rp-xjcq/GHSA-pwc3-f5rp-xjcq.json @@ -7,12 +7,8 @@ "CVE-2019-17635" ], "details": "Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a deserialization vulnerability if an index file of a parsed heap dump is replaced by a malicious version and the heap dump is reopened in Memory Analyzer. The user must chose to reopen an already parsed heap dump with an untrusted index for the problem to occur. The problem can be averted if the index files from an untrusted source are deleted and the heap dump is opened and reparsed. Also some local configuration data is subject to a deserialization vulnerability if the local data were to be replaced with a malicious version. This can be averted if the local configuration data stored on the file system cannot be changed by an attacker. The vulnerability could possibly allow code execution on the local system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q2pp-q5j6-9xfm/GHSA-q2pp-q5j6-9xfm.json b/advisories/unreviewed/2022/05/GHSA-q2pp-q5j6-9xfm/GHSA-q2pp-q5j6-9xfm.json index 1f5177cc9dd..3d9ee755063 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2pp-q5j6-9xfm/GHSA-q2pp-q5j6-9xfm.json +++ b/advisories/unreviewed/2022/05/GHSA-q2pp-q5j6-9xfm/GHSA-q2pp-q5j6-9xfm.json @@ -7,12 +7,8 @@ "CVE-2019-4638" ], "details": "IBM Security Secret Server 10.7 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 170044.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q2qm-9w2w-5x96/GHSA-q2qm-9w2w-5x96.json b/advisories/unreviewed/2022/05/GHSA-q2qm-9w2w-5x96/GHSA-q2qm-9w2w-5x96.json index 91848b343a9..155fb3984a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2qm-9w2w-5x96/GHSA-q2qm-9w2w-5x96.json +++ b/advisories/unreviewed/2022/05/GHSA-q2qm-9w2w-5x96/GHSA-q2qm-9w2w-5x96.json @@ -7,12 +7,8 @@ "CVE-2011-4898" ], "details": "** DISPUTED ** wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier for remote attackers to conduct brute-force attacks via a series of requests with different uname and pwd parameters. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether providing intentionally vague error messages during installation would be reasonable from a usability perspective.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q2qv-648h-wcqp/GHSA-q2qv-648h-wcqp.json b/advisories/unreviewed/2022/05/GHSA-q2qv-648h-wcqp/GHSA-q2qv-648h-wcqp.json index 3983725d739..634330eee24 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2qv-648h-wcqp/GHSA-q2qv-648h-wcqp.json +++ b/advisories/unreviewed/2022/05/GHSA-q2qv-648h-wcqp/GHSA-q2qv-648h-wcqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q3ww-rvw8-54xp/GHSA-q3ww-rvw8-54xp.json b/advisories/unreviewed/2022/05/GHSA-q3ww-rvw8-54xp/GHSA-q3ww-rvw8-54xp.json index 5a959c35c9b..acbb6d4f0b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3ww-rvw8-54xp/GHSA-q3ww-rvw8-54xp.json +++ b/advisories/unreviewed/2022/05/GHSA-q3ww-rvw8-54xp/GHSA-q3ww-rvw8-54xp.json @@ -7,12 +7,8 @@ "CVE-2019-19413" ], "details": "There is an integer overflow vulnerability in LDAP client of some Huawei products. Due to insufficient input validation, a remote attacker could exploit this vulnerability by sending malformed packets to the target devices. Successful exploit could cause the affected system crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q44q-q2jg-3jv5/GHSA-q44q-q2jg-3jv5.json b/advisories/unreviewed/2022/05/GHSA-q44q-q2jg-3jv5/GHSA-q44q-q2jg-3jv5.json index f0d394a0188..946f306b6b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-q44q-q2jg-3jv5/GHSA-q44q-q2jg-3jv5.json +++ b/advisories/unreviewed/2022/05/GHSA-q44q-q2jg-3jv5/GHSA-q44q-q2jg-3jv5.json @@ -7,12 +7,8 @@ "CVE-2019-14010" ], "details": "The device may enter into error state when some tool or application gets failure at 1st buffer map all and performs 2nd buffer map which happens to be at same physical address in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, Nicobar, Rennell, SA6155P, SDM660, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q4cf-vq5x-23pq/GHSA-q4cf-vq5x-23pq.json b/advisories/unreviewed/2022/05/GHSA-q4cf-vq5x-23pq/GHSA-q4cf-vq5x-23pq.json index d3f3acc02ef..d6819de87e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4cf-vq5x-23pq/GHSA-q4cf-vq5x-23pq.json +++ b/advisories/unreviewed/2022/05/GHSA-q4cf-vq5x-23pq/GHSA-q4cf-vq5x-23pq.json @@ -7,12 +7,8 @@ "CVE-2019-3687" ], "details": "The permission package in SUSE Linux Enterprise Server allowed all local users to run dumpcap in the \"easy\" permission profile and sniff network traffic. This issue affects: SUSE Linux Enterprise Server permissions versions starting from 85c83fef7e017f8ab7f8602d3163786d57344439 to 081d081dcfaf61710bda34bc21c80c66276119aa.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q54h-j43g-gf22/GHSA-q54h-j43g-gf22.json b/advisories/unreviewed/2022/05/GHSA-q54h-j43g-gf22/GHSA-q54h-j43g-gf22.json index 7b5e4556750..2e249b47c00 100644 --- a/advisories/unreviewed/2022/05/GHSA-q54h-j43g-gf22/GHSA-q54h-j43g-gf22.json +++ b/advisories/unreviewed/2022/05/GHSA-q54h-j43g-gf22/GHSA-q54h-j43g-gf22.json @@ -7,12 +7,8 @@ "CVE-2020-7231" ], "details": "Evoko Home 1.31 devices provide different error messages for failed login requests depending on whether the username is valid.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q5v3-v9w6-hx5c/GHSA-q5v3-v9w6-hx5c.json b/advisories/unreviewed/2022/05/GHSA-q5v3-v9w6-hx5c/GHSA-q5v3-v9w6-hx5c.json index 4da885c7299..42293813a6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5v3-v9w6-hx5c/GHSA-q5v3-v9w6-hx5c.json +++ b/advisories/unreviewed/2022/05/GHSA-q5v3-v9w6-hx5c/GHSA-q5v3-v9w6-hx5c.json @@ -7,12 +7,8 @@ "CVE-2020-2730" ], "details": "Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: File Upload). Supported versions that are affected are 2.7.0.0, 2.7.0.1 and 2.8.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Revenue Management and Billing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Revenue Management and Billing accessible data as well as unauthorized read access to a subset of Oracle Financial Services Revenue Management and Billing accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7p8-h39r-cm7r/GHSA-q7p8-h39r-cm7r.json b/advisories/unreviewed/2022/05/GHSA-q7p8-h39r-cm7r/GHSA-q7p8-h39r-cm7r.json index 6caa8da0286..5f3dbaea9f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7p8-h39r-cm7r/GHSA-q7p8-h39r-cm7r.json +++ b/advisories/unreviewed/2022/05/GHSA-q7p8-h39r-cm7r/GHSA-q7p8-h39r-cm7r.json @@ -7,12 +7,8 @@ "CVE-2020-1600" ], "details": "In a Point-to-Multipoint (P2MP) Label Switched Path (LSP) scenario, an uncontrolled resource consumption vulnerability in the Routing Protocol Daemon (RPD) in Juniper Networks Junos OS allows a specific SNMP request to trigger an infinite loop causing a high CPU usage Denial of Service (DoS) condition. This issue affects both SNMP over IPv4 and IPv6. This issue affects: Juniper Networks Junos OS: 12.3X48 versions prior to 12.3X48-D90; 15.1 versions prior to 15.1R7-S6; 15.1X49 versions prior to 15.1X49-D200; 15.1X53 versions prior to 15.1X53-D238, 15.1X53-D592; 16.1 versions prior to 16.1R7-S5; 16.2 versions prior to 16.2R2-S11; 17.1 versions prior to 17.1R3-S1; 17.2 versions prior to 17.2R3-S2; 17.3 versions prior to 17.3R3-S7; 17.4 versions prior to 17.4R2-S4, 17.4R3; 18.1 versions prior to 18.1R3-S5; 18.2 versions prior to 18.2R3; 18.2X75 versions prior to 18.2X75-D50; 18.3 versions prior to 18.3R2; 18.4 versions prior to 18.4R2; 19.1 versions prior to 19.1R2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q8m4-8h6c-9669/GHSA-q8m4-8h6c-9669.json b/advisories/unreviewed/2022/05/GHSA-q8m4-8h6c-9669/GHSA-q8m4-8h6c-9669.json index 7f214869c78..ff812bfd6c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8m4-8h6c-9669/GHSA-q8m4-8h6c-9669.json +++ b/advisories/unreviewed/2022/05/GHSA-q8m4-8h6c-9669/GHSA-q8m4-8h6c-9669.json @@ -7,12 +7,8 @@ "CVE-2020-0620" ], "details": "An elevation of privilege vulnerability exists when Microsoft Cryptographic Services improperly handles files, aka 'Microsoft Cryptographic Services Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q967-h7g6-h4j3/GHSA-q967-h7g6-h4j3.json b/advisories/unreviewed/2022/05/GHSA-q967-h7g6-h4j3/GHSA-q967-h7g6-h4j3.json index bd68341bb34..d279ff5b0ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-q967-h7g6-h4j3/GHSA-q967-h7g6-h4j3.json +++ b/advisories/unreviewed/2022/05/GHSA-q967-h7g6-h4j3/GHSA-q967-h7g6-h4j3.json @@ -7,12 +7,8 @@ "CVE-2020-6964" ], "details": "In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X and CARESCAPE Central Station (CSCS) Versions 2.X, the integrated service for keyboard switching of the affected devices could allow attackers to obtain remote keyboard input access without authentication over the network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q9rx-vprp-mmrf/GHSA-q9rx-vprp-mmrf.json b/advisories/unreviewed/2022/05/GHSA-q9rx-vprp-mmrf/GHSA-q9rx-vprp-mmrf.json index d97e91ce00f..e773a9fd361 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9rx-vprp-mmrf/GHSA-q9rx-vprp-mmrf.json +++ b/advisories/unreviewed/2022/05/GHSA-q9rx-vprp-mmrf/GHSA-q9rx-vprp-mmrf.json @@ -7,12 +7,8 @@ "CVE-2020-2583" ], "details": "Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -124,9 +120,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qc6h-7rhw-3735/GHSA-qc6h-7rhw-3735.json b/advisories/unreviewed/2022/05/GHSA-qc6h-7rhw-3735/GHSA-qc6h-7rhw-3735.json index d3200d8cee8..d36fe197742 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc6h-7rhw-3735/GHSA-qc6h-7rhw-3735.json +++ b/advisories/unreviewed/2022/05/GHSA-qc6h-7rhw-3735/GHSA-qc6h-7rhw-3735.json @@ -7,12 +7,8 @@ "CVE-2020-0626" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qc8h-m9cf-7w7r/GHSA-qc8h-m9cf-7w7r.json b/advisories/unreviewed/2022/05/GHSA-qc8h-m9cf-7w7r/GHSA-qc8h-m9cf-7w7r.json index a5e1b969b24..832c175c3ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc8h-m9cf-7w7r/GHSA-qc8h-m9cf-7w7r.json +++ b/advisories/unreviewed/2022/05/GHSA-qc8h-m9cf-7w7r/GHSA-qc8h-m9cf-7w7r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qcm5-23xv-7r79/GHSA-qcm5-23xv-7r79.json b/advisories/unreviewed/2022/05/GHSA-qcm5-23xv-7r79/GHSA-qcm5-23xv-7r79.json index 827ae8c4f89..0785c5bbb11 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcm5-23xv-7r79/GHSA-qcm5-23xv-7r79.json +++ b/advisories/unreviewed/2022/05/GHSA-qcm5-23xv-7r79/GHSA-qcm5-23xv-7r79.json @@ -7,12 +7,8 @@ "CVE-2019-20433" ], "details": "libaspell.a in GNU Aspell before 0.60.8 has a buffer over-read for a string ending with a single '\\0' byte, if the encoding is set to ucs-2 or ucs-4 outside of the application, as demonstrated by the ASPELL_CONF environment variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qfm8-4r23-p449/GHSA-qfm8-4r23-p449.json b/advisories/unreviewed/2022/05/GHSA-qfm8-4r23-p449/GHSA-qfm8-4r23-p449.json index b76808dd208..a7569a59a0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfm8-4r23-p449/GHSA-qfm8-4r23-p449.json +++ b/advisories/unreviewed/2022/05/GHSA-qfm8-4r23-p449/GHSA-qfm8-4r23-p449.json @@ -7,12 +7,8 @@ "CVE-2020-5522" ], "details": "The kantan netprint App for Android 2.0.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qh65-w426-vjrh/GHSA-qh65-w426-vjrh.json b/advisories/unreviewed/2022/05/GHSA-qh65-w426-vjrh/GHSA-qh65-w426-vjrh.json index 73cf7e67448..c967676e0aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh65-w426-vjrh/GHSA-qh65-w426-vjrh.json +++ b/advisories/unreviewed/2022/05/GHSA-qh65-w426-vjrh/GHSA-qh65-w426-vjrh.json @@ -7,12 +7,8 @@ "CVE-2020-0611" ], "details": "A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qh85-2qpc-6734/GHSA-qh85-2qpc-6734.json b/advisories/unreviewed/2022/05/GHSA-qh85-2qpc-6734/GHSA-qh85-2qpc-6734.json index ead896a8abb..61fbd2da53d 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh85-2qpc-6734/GHSA-qh85-2qpc-6734.json +++ b/advisories/unreviewed/2022/05/GHSA-qh85-2qpc-6734/GHSA-qh85-2qpc-6734.json @@ -7,12 +7,8 @@ "CVE-2019-13519" ], "details": "A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation. Rockwell Automation has released version 16.00.01 of Arena Simulation Software to address the reported vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qjp3-3g79-p4v7/GHSA-qjp3-3g79-p4v7.json b/advisories/unreviewed/2022/05/GHSA-qjp3-3g79-p4v7/GHSA-qjp3-3g79-p4v7.json index 49947411175..57da79a2701 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjp3-3g79-p4v7/GHSA-qjp3-3g79-p4v7.json +++ b/advisories/unreviewed/2022/05/GHSA-qjp3-3g79-p4v7/GHSA-qjp3-3g79-p4v7.json @@ -7,12 +7,8 @@ "CVE-2020-7243" ], "details": "Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Fetch URL page and entering shell metacharacters in the URL field. (In some cases, authentication can be achieved with the comtech password for the comtech account.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qm2q-7f9f-m9jj/GHSA-qm2q-7f9f-m9jj.json b/advisories/unreviewed/2022/05/GHSA-qm2q-7f9f-m9jj/GHSA-qm2q-7f9f-m9jj.json index 7f17778c635..4ba9d780688 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm2q-7f9f-m9jj/GHSA-qm2q-7f9f-m9jj.json +++ b/advisories/unreviewed/2022/05/GHSA-qm2q-7f9f-m9jj/GHSA-qm2q-7f9f-m9jj.json @@ -7,12 +7,8 @@ "CVE-2019-19835" ], "details": "SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qm5m-j3mj-33hq/GHSA-qm5m-j3mj-33hq.json b/advisories/unreviewed/2022/05/GHSA-qm5m-j3mj-33hq/GHSA-qm5m-j3mj-33hq.json index 3764b79a795..79e932ee3af 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm5m-j3mj-33hq/GHSA-qm5m-j3mj-33hq.json +++ b/advisories/unreviewed/2022/05/GHSA-qm5m-j3mj-33hq/GHSA-qm5m-j3mj-33hq.json @@ -7,12 +7,8 @@ "CVE-2018-10465" ], "details": "Jamf Pro 10.x before 10.3.0 has Incorrect Access Control. Jamf Pro user accounts and groups with access to log in to Jamf Pro had full access to endpoints in the Universal API (UAPI), regardless of account privileges or privilege sets. An authenticated Jamf Pro account without required privileges could be used to perform CRUD actions (GET, POST, PUT, DELETE) on UAPI endpoints, which could result in unauthorized information disclosure, compromised data integrity, and data loss. For a full listing of available UAPI endpoints and associated CRUD actions you can navigate to /uapi/doc in your instance of Jamf Pro.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qr3c-c5p2-m2mf/GHSA-qr3c-c5p2-m2mf.json b/advisories/unreviewed/2022/05/GHSA-qr3c-c5p2-m2mf/GHSA-qr3c-c5p2-m2mf.json index e37c4ab14d4..6aec318d6af 100644 --- a/advisories/unreviewed/2022/05/GHSA-qr3c-c5p2-m2mf/GHSA-qr3c-c5p2-m2mf.json +++ b/advisories/unreviewed/2022/05/GHSA-qr3c-c5p2-m2mf/GHSA-qr3c-c5p2-m2mf.json @@ -7,12 +7,8 @@ "CVE-2010-5151" ], "details": "** DISPUTED ** Race condition in avast! Internet Security 5.0.462 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrhm-93gw-vg83/GHSA-qrhm-93gw-vg83.json b/advisories/unreviewed/2022/05/GHSA-qrhm-93gw-vg83/GHSA-qrhm-93gw-vg83.json index d601cd47324..299b59a4f9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrhm-93gw-vg83/GHSA-qrhm-93gw-vg83.json +++ b/advisories/unreviewed/2022/05/GHSA-qrhm-93gw-vg83/GHSA-qrhm-93gw-vg83.json @@ -7,12 +7,8 @@ "CVE-2020-7245" ], "details": "Incorrect username validation in the registration processes of CTFd through 2.2.2 allows a remote attacker to take over an arbitrary account after initiating a password reset. This is related to register() and reset_password() in auth.py. To exploit the vulnerability, one must register with a username similar to the admin, but with spaces inserted before and after the username. This will register the account with the same username as the admin. After a reset of the password for this new account, CTFd will reset the admin account's password due to the username collision.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qv2w-wwx5-95j2/GHSA-qv2w-wwx5-95j2.json b/advisories/unreviewed/2022/05/GHSA-qv2w-wwx5-95j2/GHSA-qv2w-wwx5-95j2.json index 682549c838e..5e83fe29907 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv2w-wwx5-95j2/GHSA-qv2w-wwx5-95j2.json +++ b/advisories/unreviewed/2022/05/GHSA-qv2w-wwx5-95j2/GHSA-qv2w-wwx5-95j2.json @@ -7,12 +7,8 @@ "CVE-2019-10583" ], "details": "Use after free issue occurs when camera access sensors data through direct report mode in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8096AU, MDM9607, MSM8909W, Nicobar, QCS605, SA6155P, SDA845, SDM429W, SDM670, SDM710, SDM845, SM6150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qvhp-g2m6-8r99/GHSA-qvhp-g2m6-8r99.json b/advisories/unreviewed/2022/05/GHSA-qvhp-g2m6-8r99/GHSA-qvhp-g2m6-8r99.json index 92357daf7e1..0c8bf564e05 100644 --- a/advisories/unreviewed/2022/05/GHSA-qvhp-g2m6-8r99/GHSA-qvhp-g2m6-8r99.json +++ b/advisories/unreviewed/2022/05/GHSA-qvhp-g2m6-8r99/GHSA-qvhp-g2m6-8r99.json @@ -7,12 +7,8 @@ "CVE-2019-12490" ], "details": "An issue was discovered in Simple Machines Forum (SMF) before 2.0.16. Reverse tabnabbing can occur because of use of _blank for external links.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qw29-j67m-632x/GHSA-qw29-j67m-632x.json b/advisories/unreviewed/2022/05/GHSA-qw29-j67m-632x/GHSA-qw29-j67m-632x.json index 069d4e8a093..e8293be06b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw29-j67m-632x/GHSA-qw29-j67m-632x.json +++ b/advisories/unreviewed/2022/05/GHSA-qw29-j67m-632x/GHSA-qw29-j67m-632x.json @@ -7,12 +7,8 @@ "CVE-2020-2703" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36 and prior to 6.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qw2c-6q5p-xwxj/GHSA-qw2c-6q5p-xwxj.json b/advisories/unreviewed/2022/05/GHSA-qw2c-6q5p-xwxj/GHSA-qw2c-6q5p-xwxj.json index 29aa76d44aa..e66fd2bb155 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw2c-6q5p-xwxj/GHSA-qw2c-6q5p-xwxj.json +++ b/advisories/unreviewed/2022/05/GHSA-qw2c-6q5p-xwxj/GHSA-qw2c-6q5p-xwxj.json @@ -7,12 +7,8 @@ "CVE-2019-16466" ], "details": "Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qw55-m3pm-vwhh/GHSA-qw55-m3pm-vwhh.json b/advisories/unreviewed/2022/05/GHSA-qw55-m3pm-vwhh/GHSA-qw55-m3pm-vwhh.json index dc219bf8dfb..55079b5c446 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw55-m3pm-vwhh/GHSA-qw55-m3pm-vwhh.json +++ b/advisories/unreviewed/2022/05/GHSA-qw55-m3pm-vwhh/GHSA-qw55-m3pm-vwhh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwqq-r334-mqgx/GHSA-qwqq-r334-mqgx.json b/advisories/unreviewed/2022/05/GHSA-qwqq-r334-mqgx/GHSA-qwqq-r334-mqgx.json index bab85f8f03d..9fe323ba23f 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwqq-r334-mqgx/GHSA-qwqq-r334-mqgx.json +++ b/advisories/unreviewed/2022/05/GHSA-qwqq-r334-mqgx/GHSA-qwqq-r334-mqgx.json @@ -7,12 +7,8 @@ "CVE-2019-4620" ], "details": "IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validation of environment variables. IBM X-Force ID: 168863.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qx9v-3w62-8wqf/GHSA-qx9v-3w62-8wqf.json b/advisories/unreviewed/2022/05/GHSA-qx9v-3w62-8wqf/GHSA-qx9v-3w62-8wqf.json index 09c8ae47461..562c2568581 100644 --- a/advisories/unreviewed/2022/05/GHSA-qx9v-3w62-8wqf/GHSA-qx9v-3w62-8wqf.json +++ b/advisories/unreviewed/2022/05/GHSA-qx9v-3w62-8wqf/GHSA-qx9v-3w62-8wqf.json @@ -7,12 +7,8 @@ "CVE-2019-19825" ], "details": "On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {\"topicurl\":\"setting/getSanvas\"} POST to the boafrm/formLogin URI, leading to a CAPTCHA bypass. (Also, the CAPTCHA text is not needed once the attacker has determined valid credentials. The attacker can perform router actions via HTTP requests with Basic Authentication.) This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qxjh-fmf7-r2v3/GHSA-qxjh-fmf7-r2v3.json b/advisories/unreviewed/2022/05/GHSA-qxjh-fmf7-r2v3/GHSA-qxjh-fmf7-r2v3.json index 909c9a2c43a..b6d24906cbe 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxjh-fmf7-r2v3/GHSA-qxjh-fmf7-r2v3.json +++ b/advisories/unreviewed/2022/05/GHSA-qxjh-fmf7-r2v3/GHSA-qxjh-fmf7-r2v3.json @@ -7,12 +7,8 @@ "CVE-2020-2589" ], "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.28 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r22m-cc5w-vgh3/GHSA-r22m-cc5w-vgh3.json b/advisories/unreviewed/2022/05/GHSA-r22m-cc5w-vgh3/GHSA-r22m-cc5w-vgh3.json index 90d27125530..067cadcc99b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r22m-cc5w-vgh3/GHSA-r22m-cc5w-vgh3.json +++ b/advisories/unreviewed/2022/05/GHSA-r22m-cc5w-vgh3/GHSA-r22m-cc5w-vgh3.json @@ -7,12 +7,8 @@ "CVE-2013-6357" ], "details": "** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a /manager/html/undeploy?path= URI. NOTE: the vendor disputes the significance of this report, stating that \"the Apache Tomcat Security team has not accepted any reports of CSRF attacks against the Manager application ... as they require a reckless system administrator.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r3cv-6vrm-m2pf/GHSA-r3cv-6vrm-m2pf.json b/advisories/unreviewed/2022/05/GHSA-r3cv-6vrm-m2pf/GHSA-r3cv-6vrm-m2pf.json index 0c903f892d1..bc280ef40d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3cv-6vrm-m2pf/GHSA-r3cv-6vrm-m2pf.json +++ b/advisories/unreviewed/2022/05/GHSA-r3cv-6vrm-m2pf/GHSA-r3cv-6vrm-m2pf.json @@ -7,12 +7,8 @@ "CVE-2020-0647" ], "details": "A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Spoofing Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r44m-x4hw-7wjr/GHSA-r44m-x4hw-7wjr.json b/advisories/unreviewed/2022/05/GHSA-r44m-x4hw-7wjr/GHSA-r44m-x4hw-7wjr.json index 71bf8b69156..c7d1103a0c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-r44m-x4hw-7wjr/GHSA-r44m-x4hw-7wjr.json +++ b/advisories/unreviewed/2022/05/GHSA-r44m-x4hw-7wjr/GHSA-r44m-x4hw-7wjr.json @@ -7,12 +7,8 @@ "CVE-2010-5181" ], "details": "** DISPUTED ** Race condition in VIPRE Antivirus Premium 4.0.3272 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r47r-pg9q-2h8m/GHSA-r47r-pg9q-2h8m.json b/advisories/unreviewed/2022/05/GHSA-r47r-pg9q-2h8m/GHSA-r47r-pg9q-2h8m.json index ef086721b02..28205baf44d 100644 --- a/advisories/unreviewed/2022/05/GHSA-r47r-pg9q-2h8m/GHSA-r47r-pg9q-2h8m.json +++ b/advisories/unreviewed/2022/05/GHSA-r47r-pg9q-2h8m/GHSA-r47r-pg9q-2h8m.json @@ -7,12 +7,8 @@ "CVE-2019-6036" ], "details": "Cross-site scripting vulnerability in F-RevoCRM 6.0 to F-RevoCRM 6.5 patch6 (version 6 series) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r5wv-5gpc-84mq/GHSA-r5wv-5gpc-84mq.json b/advisories/unreviewed/2022/05/GHSA-r5wv-5gpc-84mq/GHSA-r5wv-5gpc-84mq.json index bf3ca2bc066..dfd5875617a 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5wv-5gpc-84mq/GHSA-r5wv-5gpc-84mq.json +++ b/advisories/unreviewed/2022/05/GHSA-r5wv-5gpc-84mq/GHSA-r5wv-5gpc-84mq.json @@ -7,12 +7,8 @@ "CVE-2015-2249" ], "details": "Zimbra Collaboration before 8.6.0 patch5 has XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r6fc-r595-mg6f/GHSA-r6fc-r595-mg6f.json b/advisories/unreviewed/2022/05/GHSA-r6fc-r595-mg6f/GHSA-r6fc-r595-mg6f.json index 1d1bcf74b7b..a43e33e2f4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6fc-r595-mg6f/GHSA-r6fc-r595-mg6f.json +++ b/advisories/unreviewed/2022/05/GHSA-r6fc-r595-mg6f/GHSA-r6fc-r595-mg6f.json @@ -7,12 +7,8 @@ "CVE-2018-8654" ], "details": "An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Server, aka 'Microsoft Dynamics 365 Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r6m9-8p59-gmrj/GHSA-r6m9-8p59-gmrj.json b/advisories/unreviewed/2022/05/GHSA-r6m9-8p59-gmrj/GHSA-r6m9-8p59-gmrj.json index bd715413a6b..d05c1da8b04 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6m9-8p59-gmrj/GHSA-r6m9-8p59-gmrj.json +++ b/advisories/unreviewed/2022/05/GHSA-r6m9-8p59-gmrj/GHSA-r6m9-8p59-gmrj.json @@ -7,12 +7,8 @@ "CVE-2010-3387" ], "details": "** DISPUTED ** vdrleaktest in Video Disk Recorder (VDR) 1.6.0 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: a third party disputes this issue because the script erroneously uses a semicolon in a context where a colon was intended.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r7cm-r8x5-rq3w/GHSA-r7cm-r8x5-rq3w.json b/advisories/unreviewed/2022/05/GHSA-r7cm-r8x5-rq3w/GHSA-r7cm-r8x5-rq3w.json index 3f7891ea5f7..bbfc7448e3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7cm-r8x5-rq3w/GHSA-r7cm-r8x5-rq3w.json +++ b/advisories/unreviewed/2022/05/GHSA-r7cm-r8x5-rq3w/GHSA-r7cm-r8x5-rq3w.json @@ -7,12 +7,8 @@ "CVE-2019-12629" ], "details": "A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system. The vulnerability is due to insufficient input validation of data parameters for certain fields in the affected solution. An attacker could exploit this vulnerability by configuring a malicious username on the login page of the affected solution. A successful exploit could allow the attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rcxj-gjxv-rf5c/GHSA-rcxj-gjxv-rf5c.json b/advisories/unreviewed/2022/05/GHSA-rcxj-gjxv-rf5c/GHSA-rcxj-gjxv-rf5c.json index 94ee769f6ec..60f03c989c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcxj-gjxv-rf5c/GHSA-rcxj-gjxv-rf5c.json +++ b/advisories/unreviewed/2022/05/GHSA-rcxj-gjxv-rf5c/GHSA-rcxj-gjxv-rf5c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rf2x-8xmx-7qcx/GHSA-rf2x-8xmx-7qcx.json b/advisories/unreviewed/2022/05/GHSA-rf2x-8xmx-7qcx/GHSA-rf2x-8xmx-7qcx.json index e0b841b7031..a5e90a37d35 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf2x-8xmx-7qcx/GHSA-rf2x-8xmx-7qcx.json +++ b/advisories/unreviewed/2022/05/GHSA-rf2x-8xmx-7qcx/GHSA-rf2x-8xmx-7qcx.json @@ -7,12 +7,8 @@ "CVE-2020-2689" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rf34-g8gp-5vmp/GHSA-rf34-g8gp-5vmp.json b/advisories/unreviewed/2022/05/GHSA-rf34-g8gp-5vmp/GHSA-rf34-g8gp-5vmp.json index 02fbb566b05..fa12f8fff80 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf34-g8gp-5vmp/GHSA-rf34-g8gp-5vmp.json +++ b/advisories/unreviewed/2022/05/GHSA-rf34-g8gp-5vmp/GHSA-rf34-g8gp-5vmp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rf3j-pmqj-4m5q/GHSA-rf3j-pmqj-4m5q.json b/advisories/unreviewed/2022/05/GHSA-rf3j-pmqj-4m5q/GHSA-rf3j-pmqj-4m5q.json index 05965ab1c63..6dcfd4f2ac6 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf3j-pmqj-4m5q/GHSA-rf3j-pmqj-4m5q.json +++ b/advisories/unreviewed/2022/05/GHSA-rf3j-pmqj-4m5q/GHSA-rf3j-pmqj-4m5q.json @@ -7,12 +7,8 @@ "CVE-2020-1840" ], "details": "HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient authentication vulnerability. A local attacker with high privilege can execute a specific command to exploit this vulnerability. Successful exploitation may cause information leak and compromise the availability of the smart phones.Affected product versions include: HUAWEI Mate 20 versions Versions earlier than 10.0.0.175(C00E70R3P8)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rfpg-5qm4-95q2/GHSA-rfpg-5qm4-95q2.json b/advisories/unreviewed/2022/05/GHSA-rfpg-5qm4-95q2/GHSA-rfpg-5qm4-95q2.json index d387ae3a49c..de180325064 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfpg-5qm4-95q2/GHSA-rfpg-5qm4-95q2.json +++ b/advisories/unreviewed/2022/05/GHSA-rfpg-5qm4-95q2/GHSA-rfpg-5qm4-95q2.json @@ -7,12 +7,8 @@ "CVE-2020-5393" ], "details": "In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rh4r-j84g-8mcx/GHSA-rh4r-j84g-8mcx.json b/advisories/unreviewed/2022/05/GHSA-rh4r-j84g-8mcx/GHSA-rh4r-j84g-8mcx.json index 2df0c9ca89e..8d7d78b9911 100644 --- a/advisories/unreviewed/2022/05/GHSA-rh4r-j84g-8mcx/GHSA-rh4r-j84g-8mcx.json +++ b/advisories/unreviewed/2022/05/GHSA-rh4r-j84g-8mcx/GHSA-rh4r-j84g-8mcx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rhpx-cf93-fp5q/GHSA-rhpx-cf93-fp5q.json b/advisories/unreviewed/2022/05/GHSA-rhpx-cf93-fp5q/GHSA-rhpx-cf93-fp5q.json index faf7cbe3954..6089b8a5c43 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhpx-cf93-fp5q/GHSA-rhpx-cf93-fp5q.json +++ b/advisories/unreviewed/2022/05/GHSA-rhpx-cf93-fp5q/GHSA-rhpx-cf93-fp5q.json @@ -7,12 +7,8 @@ "CVE-2008-5186" ], "details": "** DISPUTED ** The set_language_path function in geshi.php in Generic Syntax Highlighter (GeSHi) before 1.0.8.1 might allow remote attackers to conduct file inclusion attacks via crafted inputs that influence the default language path ($path variable). NOTE: this issue has been disputed by a vendor, stating that only a static value is used, so this is not a vulnerability in GeSHi. Separate CVE identifiers would be created for web applications that integrate GeSHi in a way that allows control of the default language path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rpc9-q4wq-9649/GHSA-rpc9-q4wq-9649.json b/advisories/unreviewed/2022/05/GHSA-rpc9-q4wq-9649/GHSA-rpc9-q4wq-9649.json index 10a5e1c20f5..11294f49d11 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpc9-q4wq-9649/GHSA-rpc9-q4wq-9649.json +++ b/advisories/unreviewed/2022/05/GHSA-rpc9-q4wq-9649/GHSA-rpc9-q4wq-9649.json @@ -7,12 +7,8 @@ "CVE-2020-7229" ], "details": "An issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search engine. The parameter is landing_location. The function is countSearchedJobs(). The file is _lib/class.Job.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rpm2-phfh-m9m3/GHSA-rpm2-phfh-m9m3.json b/advisories/unreviewed/2022/05/GHSA-rpm2-phfh-m9m3/GHSA-rpm2-phfh-m9m3.json index bb4b6f7a32f..57c718247ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpm2-phfh-m9m3/GHSA-rpm2-phfh-m9m3.json +++ b/advisories/unreviewed/2022/05/GHSA-rpm2-phfh-m9m3/GHSA-rpm2-phfh-m9m3.json @@ -7,12 +7,8 @@ "CVE-2020-2691" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rq69-788x-22hh/GHSA-rq69-788x-22hh.json b/advisories/unreviewed/2022/05/GHSA-rq69-788x-22hh/GHSA-rq69-788x-22hh.json index 1f18ece8cac..47fb725785e 100644 --- a/advisories/unreviewed/2022/05/GHSA-rq69-788x-22hh/GHSA-rq69-788x-22hh.json +++ b/advisories/unreviewed/2022/05/GHSA-rq69-788x-22hh/GHSA-rq69-788x-22hh.json @@ -7,12 +7,8 @@ "CVE-2019-3864" ], "details": "A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which is used as a CSRF token. The token is not refreshed for every request or when a user logged out and in again. An attacker could use a leaked token to gain access to the system using the user's account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rr25-rmv3-92rm/GHSA-rr25-rmv3-92rm.json b/advisories/unreviewed/2022/05/GHSA-rr25-rmv3-92rm/GHSA-rr25-rmv3-92rm.json index e406525d683..6cddcbf5a57 100644 --- a/advisories/unreviewed/2022/05/GHSA-rr25-rmv3-92rm/GHSA-rr25-rmv3-92rm.json +++ b/advisories/unreviewed/2022/05/GHSA-rr25-rmv3-92rm/GHSA-rr25-rmv3-92rm.json @@ -7,12 +7,8 @@ "CVE-2019-13521" ], "details": "A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation. Rockwell Automation has released version 16.00.01 of Arena Simulation Software to address the reported vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rrrf-759h-mc79/GHSA-rrrf-759h-mc79.json b/advisories/unreviewed/2022/05/GHSA-rrrf-759h-mc79/GHSA-rrrf-759h-mc79.json index 9512679e553..199edfe4949 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrrf-759h-mc79/GHSA-rrrf-759h-mc79.json +++ b/advisories/unreviewed/2022/05/GHSA-rrrf-759h-mc79/GHSA-rrrf-759h-mc79.json @@ -7,12 +7,8 @@ "CVE-2012-0937" ], "details": "** DISPUTED ** wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external MySQL database servers, which allows remote attackers to use WordPress as a proxy for brute-force attacks or denial of service attacks via the dbhost parameter, a different vulnerability than CVE-2011-4898. NOTE: the vendor disputes the significance of this issue because an incomplete WordPress installation might be present on the network for only a short time.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rv97-m625-r8wh/GHSA-rv97-m625-r8wh.json b/advisories/unreviewed/2022/05/GHSA-rv97-m625-r8wh/GHSA-rv97-m625-r8wh.json index 6f4aa906b23..37c80fbeeb1 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv97-m625-r8wh/GHSA-rv97-m625-r8wh.json +++ b/advisories/unreviewed/2022/05/GHSA-rv97-m625-r8wh/GHSA-rv97-m625-r8wh.json @@ -7,12 +7,8 @@ "CVE-2019-20385" ], "details": "The CSV upload feature in /supervisor/procesa_carga.php on Logaritmo Aware CallManager 2012 devices allows upload of .php files with a text/* content type. The PHP code can then be executed by visiting a /supervisor/csv/ URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rv9c-rhmf-hq9h/GHSA-rv9c-rhmf-hq9h.json b/advisories/unreviewed/2022/05/GHSA-rv9c-rhmf-hq9h/GHSA-rv9c-rhmf-hq9h.json index 39095a32c97..9ccc0198dde 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv9c-rhmf-hq9h/GHSA-rv9c-rhmf-hq9h.json +++ b/advisories/unreviewed/2022/05/GHSA-rv9c-rhmf-hq9h/GHSA-rv9c-rhmf-hq9h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rvgf-qg2w-7jr4/GHSA-rvgf-qg2w-7jr4.json b/advisories/unreviewed/2022/05/GHSA-rvgf-qg2w-7jr4/GHSA-rvgf-qg2w-7jr4.json index e4ea96c4c8c..886b6e5ed29 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvgf-qg2w-7jr4/GHSA-rvgf-qg2w-7jr4.json +++ b/advisories/unreviewed/2022/05/GHSA-rvgf-qg2w-7jr4/GHSA-rvgf-qg2w-7jr4.json @@ -7,12 +7,8 @@ "CVE-2019-13524" ], "details": "GE PACSystems RX3i CPE100/115: All versions prior to R9.85,CPE302/305/310/330/400/410: All versions prior to R9.90,CRU/320 All versions(End of Life) may allow an attacker sending specially manipulated packets to cause the module state to change to halt-mode, resulting in a denial-of-service condition. An operator must reboot the CPU module after removing battery or energy pack to recover from halt-mode.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rvwp-x3pv-c87j/GHSA-rvwp-x3pv-c87j.json b/advisories/unreviewed/2022/05/GHSA-rvwp-x3pv-c87j/GHSA-rvwp-x3pv-c87j.json index e0dae5da2c9..eeca49c3cca 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvwp-x3pv-c87j/GHSA-rvwp-x3pv-c87j.json +++ b/advisories/unreviewed/2022/05/GHSA-rvwp-x3pv-c87j/GHSA-rvwp-x3pv-c87j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rwj4-3432-g97h/GHSA-rwj4-3432-g97h.json b/advisories/unreviewed/2022/05/GHSA-rwj4-3432-g97h/GHSA-rwj4-3432-g97h.json index 6edc028666d..64e9c831f1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwj4-3432-g97h/GHSA-rwj4-3432-g97h.json +++ b/advisories/unreviewed/2022/05/GHSA-rwj4-3432-g97h/GHSA-rwj4-3432-g97h.json @@ -7,12 +7,8 @@ "CVE-2019-10548" ], "details": "While trying to obtain datad ipc handle during DPL initialization, Heap use-after-free issue can occur if modem SSR occurs at same time in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables in APQ8009, APQ8053, APQ8096AU, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCA6574AU, QCS605, QM215, SDA660, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SM6150, SM7150, SM8150, SXR1130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rwmq-3523-q2pg/GHSA-rwmq-3523-q2pg.json b/advisories/unreviewed/2022/05/GHSA-rwmq-3523-q2pg/GHSA-rwmq-3523-q2pg.json index 22891fc5b47..6a97ee89295 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwmq-3523-q2pg/GHSA-rwmq-3523-q2pg.json +++ b/advisories/unreviewed/2022/05/GHSA-rwmq-3523-q2pg/GHSA-rwmq-3523-q2pg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rxgv-pwhv-x2rp/GHSA-rxgv-pwhv-x2rp.json b/advisories/unreviewed/2022/05/GHSA-rxgv-pwhv-x2rp/GHSA-rxgv-pwhv-x2rp.json index a078f0c76c4..7dce7ab9ddf 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxgv-pwhv-x2rp/GHSA-rxgv-pwhv-x2rp.json +++ b/advisories/unreviewed/2022/05/GHSA-rxgv-pwhv-x2rp/GHSA-rxgv-pwhv-x2rp.json @@ -7,12 +7,8 @@ "CVE-2020-2572" ], "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Audit Plugin). Supported versions that are affected are 5.7.28 and prior and 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 2.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v22g-96px-r35x/GHSA-v22g-96px-r35x.json b/advisories/unreviewed/2022/05/GHSA-v22g-96px-r35x/GHSA-v22g-96px-r35x.json index e091d9aba6e..1b3eca7a2bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-v22g-96px-r35x/GHSA-v22g-96px-r35x.json +++ b/advisories/unreviewed/2022/05/GHSA-v22g-96px-r35x/GHSA-v22g-96px-r35x.json @@ -7,12 +7,8 @@ "CVE-2020-7989" ], "details": "Adive Framework 2.0.8 has admin/user/add userUsername XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v2g8-4fgq-7rhx/GHSA-v2g8-4fgq-7rhx.json b/advisories/unreviewed/2022/05/GHSA-v2g8-4fgq-7rhx/GHSA-v2g8-4fgq-7rhx.json index fd323eeab10..5fc878787cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2g8-4fgq-7rhx/GHSA-v2g8-4fgq-7rhx.json +++ b/advisories/unreviewed/2022/05/GHSA-v2g8-4fgq-7rhx/GHSA-v2g8-4fgq-7rhx.json @@ -7,12 +7,8 @@ "CVE-2019-20386" ], "details": "An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2h7-ph6x-hrqm/GHSA-v2h7-ph6x-hrqm.json b/advisories/unreviewed/2022/05/GHSA-v2h7-ph6x-hrqm/GHSA-v2h7-ph6x-hrqm.json index c10858d5e21..11a58ac91df 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2h7-ph6x-hrqm/GHSA-v2h7-ph6x-hrqm.json +++ b/advisories/unreviewed/2022/05/GHSA-v2h7-ph6x-hrqm/GHSA-v2h7-ph6x-hrqm.json @@ -7,12 +7,8 @@ "CVE-2019-16029" ], "details": "A vulnerability in the application programming interface (API) of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacker to change user account information which can prevent users from logging in, resulting in a denial of service (DoS) condition of the web interface. The vulnerability is due to the lack of input validation in the API. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to change or corrupt user account information which could grant the attacker administrator access or prevent legitimate user access to the web interface, resulting in a denial of service (DoS) condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v2jw-9cf3-v6vg/GHSA-v2jw-9cf3-v6vg.json b/advisories/unreviewed/2022/05/GHSA-v2jw-9cf3-v6vg/GHSA-v2jw-9cf3-v6vg.json index ff5f22b636e..aa84f88fbe3 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2jw-9cf3-v6vg/GHSA-v2jw-9cf3-v6vg.json +++ b/advisories/unreviewed/2022/05/GHSA-v2jw-9cf3-v6vg/GHSA-v2jw-9cf3-v6vg.json @@ -7,12 +7,8 @@ "CVE-2019-15583" ], "details": "An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private labels and the private project namespace would be disclosed through the GitLab API.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v2qq-489m-745h/GHSA-v2qq-489m-745h.json b/advisories/unreviewed/2022/05/GHSA-v2qq-489m-745h/GHSA-v2qq-489m-745h.json index 11dfb554b7d..a5a642852f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2qq-489m-745h/GHSA-v2qq-489m-745h.json +++ b/advisories/unreviewed/2022/05/GHSA-v2qq-489m-745h/GHSA-v2qq-489m-745h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v34h-3hv8-mwm9/GHSA-v34h-3hv8-mwm9.json b/advisories/unreviewed/2022/05/GHSA-v34h-3hv8-mwm9/GHSA-v34h-3hv8-mwm9.json index 8a51e315594..3eeeae4c3eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-v34h-3hv8-mwm9/GHSA-v34h-3hv8-mwm9.json +++ b/advisories/unreviewed/2022/05/GHSA-v34h-3hv8-mwm9/GHSA-v34h-3hv8-mwm9.json @@ -7,12 +7,8 @@ "CVE-2019-19411" ], "details": "USG9500 with versions of V500R001C30SPC100, V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 have an information leakage vulnerability. Due to improper processing of the initialization vector used in a specific encryption algorithm, an attacker who gains access to this cryptographic primitive may exploit this vulnerability to cause the value of the confidentiality associated with its use to be diminished.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v3pw-85gv-xrjf/GHSA-v3pw-85gv-xrjf.json b/advisories/unreviewed/2022/05/GHSA-v3pw-85gv-xrjf/GHSA-v3pw-85gv-xrjf.json index 7e232e53a47..6deaad1615a 100644 --- a/advisories/unreviewed/2022/05/GHSA-v3pw-85gv-xrjf/GHSA-v3pw-85gv-xrjf.json +++ b/advisories/unreviewed/2022/05/GHSA-v3pw-85gv-xrjf/GHSA-v3pw-85gv-xrjf.json @@ -7,12 +7,8 @@ "CVE-2010-5159" ], "details": "** DISPUTED ** Race condition in Dr.Web Security Space Pro 6.0.0.03100 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v3vp-jhqc-89m6/GHSA-v3vp-jhqc-89m6.json b/advisories/unreviewed/2022/05/GHSA-v3vp-jhqc-89m6/GHSA-v3vp-jhqc-89m6.json index 544f380466c..de899bdf21d 100644 --- a/advisories/unreviewed/2022/05/GHSA-v3vp-jhqc-89m6/GHSA-v3vp-jhqc-89m6.json +++ b/advisories/unreviewed/2022/05/GHSA-v3vp-jhqc-89m6/GHSA-v3vp-jhqc-89m6.json @@ -7,12 +7,8 @@ "CVE-2019-14003" ], "details": "Null pointer exception can happen while parsing invalid MKV clip where cue information is parsed before segment information in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCS605, QM215, Rennell, SA6155P, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v4qc-j5rp-r38p/GHSA-v4qc-j5rp-r38p.json b/advisories/unreviewed/2022/05/GHSA-v4qc-j5rp-r38p/GHSA-v4qc-j5rp-r38p.json index b278b329c2a..ce9b6afb3c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4qc-j5rp-r38p/GHSA-v4qc-j5rp-r38p.json +++ b/advisories/unreviewed/2022/05/GHSA-v4qc-j5rp-r38p/GHSA-v4qc-j5rp-r38p.json @@ -7,12 +7,8 @@ "CVE-2020-0608" ], "details": "An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v56r-cxxj-7vxh/GHSA-v56r-cxxj-7vxh.json b/advisories/unreviewed/2022/05/GHSA-v56r-cxxj-7vxh/GHSA-v56r-cxxj-7vxh.json index 7d869fa6ad0..8ef85389bf1 100644 --- a/advisories/unreviewed/2022/05/GHSA-v56r-cxxj-7vxh/GHSA-v56r-cxxj-7vxh.json +++ b/advisories/unreviewed/2022/05/GHSA-v56r-cxxj-7vxh/GHSA-v56r-cxxj-7vxh.json @@ -7,12 +7,8 @@ "CVE-2020-8000" ], "details": "Intellian Aptus Web 1.24 has a hardcoded password of 12345678 for the intellian account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v592-hhw6-w7x7/GHSA-v592-hhw6-w7x7.json b/advisories/unreviewed/2022/05/GHSA-v592-hhw6-w7x7/GHSA-v592-hhw6-w7x7.json index 619a1bfcf26..b8dbff96d46 100644 --- a/advisories/unreviewed/2022/05/GHSA-v592-hhw6-w7x7/GHSA-v592-hhw6-w7x7.json +++ b/advisories/unreviewed/2022/05/GHSA-v592-hhw6-w7x7/GHSA-v592-hhw6-w7x7.json @@ -7,12 +7,8 @@ "CVE-2012-5379" ], "details": "** DISPUTED ** Untrusted search path vulnerability in the installation functionality in ActivePython 3.2.2.3, when installed in the top-level C:\\ directory, might allow local users to gain privileges via a Trojan horse DLL in the C:\\Python27 or C:\\Python27\\Scripts directory, which may be added to the PATH system environment variable by an administrator, as demonstrated by a Trojan horse wlbsctrl.dll file used by the \"IKE and AuthIP IPsec Keying Modules\" system service in Windows Vista SP1, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 Release Preview. NOTE: CVE disputes this issue because the unsafe PATH is established only by a separate administrative action that is not a default part of the ActivePython installation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v6pj-9m3q-j6m8/GHSA-v6pj-9m3q-j6m8.json b/advisories/unreviewed/2022/05/GHSA-v6pj-9m3q-j6m8/GHSA-v6pj-9m3q-j6m8.json index aa90a16fe68..85e8f826462 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6pj-9m3q-j6m8/GHSA-v6pj-9m3q-j6m8.json +++ b/advisories/unreviewed/2022/05/GHSA-v6pj-9m3q-j6m8/GHSA-v6pj-9m3q-j6m8.json @@ -7,12 +7,8 @@ "CVE-2008-5034" ], "details": "** DISPUTED ** master-filter in printfilters-ppd 2.13 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filter.debug temporary file. NOTE: the vendor disputes this vulnerability, stating 'this package does not have \" possibility of attack with the help of symlinks\"'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v78f-65qq-96m8/GHSA-v78f-65qq-96m8.json b/advisories/unreviewed/2022/05/GHSA-v78f-65qq-96m8/GHSA-v78f-65qq-96m8.json index c29a632c26b..f59df1e1c2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-v78f-65qq-96m8/GHSA-v78f-65qq-96m8.json +++ b/advisories/unreviewed/2022/05/GHSA-v78f-65qq-96m8/GHSA-v78f-65qq-96m8.json @@ -7,12 +7,8 @@ "CVE-2019-11756" ], "details": "Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of service). This vulnerability affects Firefox < 71.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v8x6-frf7-3g2h/GHSA-v8x6-frf7-3g2h.json b/advisories/unreviewed/2022/05/GHSA-v8x6-frf7-3g2h/GHSA-v8x6-frf7-3g2h.json index 109b622dda1..d0b6f43d66f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8x6-frf7-3g2h/GHSA-v8x6-frf7-3g2h.json +++ b/advisories/unreviewed/2022/05/GHSA-v8x6-frf7-3g2h/GHSA-v8x6-frf7-3g2h.json @@ -7,12 +7,8 @@ "CVE-2010-5165" ], "details": "** DISPUTED ** Race condition in Malware Defender 2.6.0 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v936-q998-9p85/GHSA-v936-q998-9p85.json b/advisories/unreviewed/2022/05/GHSA-v936-q998-9p85/GHSA-v936-q998-9p85.json index 8a3c4d98fe4..84caeb88f69 100644 --- a/advisories/unreviewed/2022/05/GHSA-v936-q998-9p85/GHSA-v936-q998-9p85.json +++ b/advisories/unreviewed/2022/05/GHSA-v936-q998-9p85/GHSA-v936-q998-9p85.json @@ -7,12 +7,8 @@ "CVE-2019-14016" ], "details": "Integer overflow occurs while playing the clip which is nonstandard in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, Nicobar, QCS605, QM215, SA6155P, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v94j-fmjr-xrgv/GHSA-v94j-fmjr-xrgv.json b/advisories/unreviewed/2022/05/GHSA-v94j-fmjr-xrgv/GHSA-v94j-fmjr-xrgv.json index e3f44f5a73f..830c46d4b9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-v94j-fmjr-xrgv/GHSA-v94j-fmjr-xrgv.json +++ b/advisories/unreviewed/2022/05/GHSA-v94j-fmjr-xrgv/GHSA-v94j-fmjr-xrgv.json @@ -7,12 +7,8 @@ "CVE-2019-1350" ], "details": "A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v9v6-v84v-99jp/GHSA-v9v6-v84v-99jp.json b/advisories/unreviewed/2022/05/GHSA-v9v6-v84v-99jp/GHSA-v9v6-v84v-99jp.json index 0f8d96f4c93..2ba7afa3c0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9v6-v84v-99jp/GHSA-v9v6-v84v-99jp.json +++ b/advisories/unreviewed/2022/05/GHSA-v9v6-v84v-99jp/GHSA-v9v6-v84v-99jp.json @@ -7,12 +7,8 @@ "CVE-2019-10532" ], "details": "Null-pointer dereference issue can occur while calculating string length when source string length is zero in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, Nicobar, QCS605, QM215, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vc62-7qvc-6jg4/GHSA-vc62-7qvc-6jg4.json b/advisories/unreviewed/2022/05/GHSA-vc62-7qvc-6jg4/GHSA-vc62-7qvc-6jg4.json index b84dec70990..aa1b7090753 100644 --- a/advisories/unreviewed/2022/05/GHSA-vc62-7qvc-6jg4/GHSA-vc62-7qvc-6jg4.json +++ b/advisories/unreviewed/2022/05/GHSA-vc62-7qvc-6jg4/GHSA-vc62-7qvc-6jg4.json @@ -7,12 +7,8 @@ "CVE-2019-16469" ], "details": "Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability. Successful exploitation could lead to sensitive information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vcxh-qw7p-r93v/GHSA-vcxh-qw7p-r93v.json b/advisories/unreviewed/2022/05/GHSA-vcxh-qw7p-r93v/GHSA-vcxh-qw7p-r93v.json index 2d1c74fe252..26b82106c88 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcxh-qw7p-r93v/GHSA-vcxh-qw7p-r93v.json +++ b/advisories/unreviewed/2022/05/GHSA-vcxh-qw7p-r93v/GHSA-vcxh-qw7p-r93v.json @@ -7,12 +7,8 @@ "CVE-2019-14008" ], "details": "Possible null pointer dereference issue in location assistance data processing due to missing null check on resources before using it in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9150, MDM9607, MDM9650, SDM660, SDM845, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vf3h-hp75-rg56/GHSA-vf3h-hp75-rg56.json b/advisories/unreviewed/2022/05/GHSA-vf3h-hp75-rg56/GHSA-vf3h-hp75-rg56.json index 8eba49b7216..ecac6a71450 100644 --- a/advisories/unreviewed/2022/05/GHSA-vf3h-hp75-rg56/GHSA-vf3h-hp75-rg56.json +++ b/advisories/unreviewed/2022/05/GHSA-vf3h-hp75-rg56/GHSA-vf3h-hp75-rg56.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vfx3-94gp-9qm7/GHSA-vfx3-94gp-9qm7.json b/advisories/unreviewed/2022/05/GHSA-vfx3-94gp-9qm7/GHSA-vfx3-94gp-9qm7.json index 79fecd6cc3f..35059983b9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfx3-94gp-9qm7/GHSA-vfx3-94gp-9qm7.json +++ b/advisories/unreviewed/2022/05/GHSA-vfx3-94gp-9qm7/GHSA-vfx3-94gp-9qm7.json @@ -7,12 +7,8 @@ "CVE-2020-2686" ], "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.18 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vfxc-55rc-5chh/GHSA-vfxc-55rc-5chh.json b/advisories/unreviewed/2022/05/GHSA-vfxc-55rc-5chh/GHSA-vfxc-55rc-5chh.json index 0684b2e58bd..2d22f102b5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfxc-55rc-5chh/GHSA-vfxc-55rc-5chh.json +++ b/advisories/unreviewed/2022/05/GHSA-vfxc-55rc-5chh/GHSA-vfxc-55rc-5chh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vh8c-wfv5-x468/GHSA-vh8c-wfv5-x468.json b/advisories/unreviewed/2022/05/GHSA-vh8c-wfv5-x468/GHSA-vh8c-wfv5-x468.json index 16c088203bc..7a3ac8345b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-vh8c-wfv5-x468/GHSA-vh8c-wfv5-x468.json +++ b/advisories/unreviewed/2022/05/GHSA-vh8c-wfv5-x468/GHSA-vh8c-wfv5-x468.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vj2g-8grq-fccw/GHSA-vj2g-8grq-fccw.json b/advisories/unreviewed/2022/05/GHSA-vj2g-8grq-fccw/GHSA-vj2g-8grq-fccw.json index e2750dc641e..ee91b1411e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-vj2g-8grq-fccw/GHSA-vj2g-8grq-fccw.json +++ b/advisories/unreviewed/2022/05/GHSA-vj2g-8grq-fccw/GHSA-vj2g-8grq-fccw.json @@ -7,12 +7,8 @@ "CVE-2019-19823" ], "details": "A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vj44-crwg-5f84/GHSA-vj44-crwg-5f84.json b/advisories/unreviewed/2022/05/GHSA-vj44-crwg-5f84/GHSA-vj44-crwg-5f84.json index 071b1be2be6..ec887e2cdcb 100644 --- a/advisories/unreviewed/2022/05/GHSA-vj44-crwg-5f84/GHSA-vj44-crwg-5f84.json +++ b/advisories/unreviewed/2022/05/GHSA-vj44-crwg-5f84/GHSA-vj44-crwg-5f84.json @@ -7,12 +7,8 @@ "CVE-2020-7999" ], "details": "The Intellian Aptus application 1.0.2 for Android has hardcoded values for DOWNLOAD_API_KEY and FILE_DOWNLOAD_API_KEY.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vm3p-xfv5-m8r3/GHSA-vm3p-xfv5-m8r3.json b/advisories/unreviewed/2022/05/GHSA-vm3p-xfv5-m8r3/GHSA-vm3p-xfv5-m8r3.json index 85f39c2721c..0219b7cbc53 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm3p-xfv5-m8r3/GHSA-vm3p-xfv5-m8r3.json +++ b/advisories/unreviewed/2022/05/GHSA-vm3p-xfv5-m8r3/GHSA-vm3p-xfv5-m8r3.json @@ -7,12 +7,8 @@ "CVE-2019-20423" ], "details": "In the Lustre file system before 2.12.3, the ptlrpc module has a buffer overflow and panic due to the lack of validation for specific fields of packets sent by a client. The function target_handle_connect() mishandles a certain size value when a client connects to a server, because of an integer signedness error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vm62-p48h-5h9h/GHSA-vm62-p48h-5h9h.json b/advisories/unreviewed/2022/05/GHSA-vm62-p48h-5h9h/GHSA-vm62-p48h-5h9h.json index e1dbf203ca3..a48a335c5a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm62-p48h-5h9h/GHSA-vm62-p48h-5h9h.json +++ b/advisories/unreviewed/2022/05/GHSA-vm62-p48h-5h9h/GHSA-vm62-p48h-5h9h.json @@ -7,12 +7,8 @@ "CVE-2019-15586" ], "details": "A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vmjf-ch8w-6hg5/GHSA-vmjf-ch8w-6hg5.json b/advisories/unreviewed/2022/05/GHSA-vmjf-ch8w-6hg5/GHSA-vmjf-ch8w-6hg5.json index bc4555541c4..44539c128cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmjf-ch8w-6hg5/GHSA-vmjf-ch8w-6hg5.json +++ b/advisories/unreviewed/2022/05/GHSA-vmjf-ch8w-6hg5/GHSA-vmjf-ch8w-6hg5.json @@ -7,12 +7,8 @@ "CVE-2020-0622" ], "details": "An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vmpx-5rfc-fgm5/GHSA-vmpx-5rfc-fgm5.json b/advisories/unreviewed/2022/05/GHSA-vmpx-5rfc-fgm5/GHSA-vmpx-5rfc-fgm5.json index 4f1bb4c29ff..12da57479ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmpx-5rfc-fgm5/GHSA-vmpx-5rfc-fgm5.json +++ b/advisories/unreviewed/2022/05/GHSA-vmpx-5rfc-fgm5/GHSA-vmpx-5rfc-fgm5.json @@ -7,12 +7,8 @@ "CVE-2020-7244" ], "details": "Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Poll Routes page and entering shell metacharacters in the Router IP Address field. (In some cases, authentication can be achieved with the comtech password for the comtech account.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vp29-6rcm-8jf5/GHSA-vp29-6rcm-8jf5.json b/advisories/unreviewed/2022/05/GHSA-vp29-6rcm-8jf5/GHSA-vp29-6rcm-8jf5.json index fbc493bbfb5..dafd310497d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vp29-6rcm-8jf5/GHSA-vp29-6rcm-8jf5.json +++ b/advisories/unreviewed/2022/05/GHSA-vp29-6rcm-8jf5/GHSA-vp29-6rcm-8jf5.json @@ -7,12 +7,8 @@ "CVE-2020-7931" ], "details": "In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modifying a .ssh/authorized_keys file. Patches are available for various versions between 5.11.8 and 6.16.0. The issue exists because use of the DefaultObjectWrapper class makes certain Java functions accessible to a template.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vp3x-6rvm-hm6v/GHSA-vp3x-6rvm-hm6v.json b/advisories/unreviewed/2022/05/GHSA-vp3x-6rvm-hm6v/GHSA-vp3x-6rvm-hm6v.json index ff2a8f42c0b..f823f1545f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-vp3x-6rvm-hm6v/GHSA-vp3x-6rvm-hm6v.json +++ b/advisories/unreviewed/2022/05/GHSA-vp3x-6rvm-hm6v/GHSA-vp3x-6rvm-hm6v.json @@ -7,12 +7,8 @@ "CVE-2019-10606" ], "details": "Out-of-bound access will occur in USB driver due to lack of check to validate the frame size passed by user in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, QCS605, SDX24", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vpfm-w32w-rrg8/GHSA-vpfm-w32w-rrg8.json b/advisories/unreviewed/2022/05/GHSA-vpfm-w32w-rrg8/GHSA-vpfm-w32w-rrg8.json index 4acbe5c72de..4f8aa773231 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpfm-w32w-rrg8/GHSA-vpfm-w32w-rrg8.json +++ b/advisories/unreviewed/2022/05/GHSA-vpfm-w32w-rrg8/GHSA-vpfm-w32w-rrg8.json @@ -7,12 +7,8 @@ "CVE-2020-7950" ], "details": "meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a vulnerable function call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vpjw-897g-6wwv/GHSA-vpjw-897g-6wwv.json b/advisories/unreviewed/2022/05/GHSA-vpjw-897g-6wwv/GHSA-vpjw-897g-6wwv.json index a38c33a49e7..9dfbca014d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpjw-897g-6wwv/GHSA-vpjw-897g-6wwv.json +++ b/advisories/unreviewed/2022/05/GHSA-vpjw-897g-6wwv/GHSA-vpjw-897g-6wwv.json @@ -7,12 +7,8 @@ "CVE-2020-7048" ], "details": "The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site content stored in that table), as demonstrated by a wp-admin/admin-post.php?db-reset-tables[]=comments URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vpwg-c4h3-2hjj/GHSA-vpwg-c4h3-2hjj.json b/advisories/unreviewed/2022/05/GHSA-vpwg-c4h3-2hjj/GHSA-vpwg-c4h3-2hjj.json index 5421ba2fc85..a4284cc0e20 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpwg-c4h3-2hjj/GHSA-vpwg-c4h3-2hjj.json +++ b/advisories/unreviewed/2022/05/GHSA-vpwg-c4h3-2hjj/GHSA-vpwg-c4h3-2hjj.json @@ -7,12 +7,8 @@ "CVE-2019-17651" ], "details": "An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5.2.5 and below may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious JavaScript code into the description field of a Device Maintenance schedule.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vq5p-6m46-5484/GHSA-vq5p-6m46-5484.json b/advisories/unreviewed/2022/05/GHSA-vq5p-6m46-5484/GHSA-vq5p-6m46-5484.json index 5165c0d2cb1..d484eff2d50 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq5p-6m46-5484/GHSA-vq5p-6m46-5484.json +++ b/advisories/unreviewed/2022/05/GHSA-vq5p-6m46-5484/GHSA-vq5p-6m46-5484.json @@ -7,12 +7,8 @@ "CVE-2019-14004" ], "details": "Buffer overflow occurs while processing invalid MKV clip, which has invalid EBML size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCS605, QM215, Rennell, SA6155P, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vq8v-gqr8-jrr5/GHSA-vq8v-gqr8-jrr5.json b/advisories/unreviewed/2022/05/GHSA-vq8v-gqr8-jrr5/GHSA-vq8v-gqr8-jrr5.json index ddab32f81d1..1bc147f0046 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq8v-gqr8-jrr5/GHSA-vq8v-gqr8-jrr5.json +++ b/advisories/unreviewed/2022/05/GHSA-vq8v-gqr8-jrr5/GHSA-vq8v-gqr8-jrr5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vqmw-m2f5-rq3c/GHSA-vqmw-m2f5-rq3c.json b/advisories/unreviewed/2022/05/GHSA-vqmw-m2f5-rq3c/GHSA-vqmw-m2f5-rq3c.json index 06e060464af..c22d41c72bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqmw-m2f5-rq3c/GHSA-vqmw-m2f5-rq3c.json +++ b/advisories/unreviewed/2022/05/GHSA-vqmw-m2f5-rq3c/GHSA-vqmw-m2f5-rq3c.json @@ -7,12 +7,8 @@ "CVE-2008-7258" ], "details": "** DISPUTED ** The standardise function in Anibal Monsalve Salazar sSMTP 2.61 and 2.62 allows local users to cause a denial of service (application exit) via an e-mail message containing a long line that begins with a . (dot) character. NOTE: CVE disputes this issue because it is solely a usability problem for senders of messages with certain long lines, and has no security impact.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vvg6-3mr2-4v6c/GHSA-vvg6-3mr2-4v6c.json b/advisories/unreviewed/2022/05/GHSA-vvg6-3mr2-4v6c/GHSA-vvg6-3mr2-4v6c.json index 84e07e996e1..b929321bd6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvg6-3mr2-4v6c/GHSA-vvg6-3mr2-4v6c.json +++ b/advisories/unreviewed/2022/05/GHSA-vvg6-3mr2-4v6c/GHSA-vvg6-3mr2-4v6c.json @@ -7,12 +7,8 @@ "CVE-2019-19858" ], "details": "An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/add_user/UID allows stored XSS via the author parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vwvw-vfgx-mxpp/GHSA-vwvw-vfgx-mxpp.json b/advisories/unreviewed/2022/05/GHSA-vwvw-vfgx-mxpp/GHSA-vwvw-vfgx-mxpp.json index 1ed5f700788..c4082b41f14 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwvw-vfgx-mxpp/GHSA-vwvw-vfgx-mxpp.json +++ b/advisories/unreviewed/2022/05/GHSA-vwvw-vfgx-mxpp/GHSA-vwvw-vfgx-mxpp.json @@ -7,12 +7,8 @@ "CVE-2019-4639" ], "details": "IBM Security Secret Server 10.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 170045.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vxrg-v6vf-8c93/GHSA-vxrg-v6vf-8c93.json b/advisories/unreviewed/2022/05/GHSA-vxrg-v6vf-8c93/GHSA-vxrg-v6vf-8c93.json index 82755778e42..f1f969c1cd0 100644 --- a/advisories/unreviewed/2022/05/GHSA-vxrg-v6vf-8c93/GHSA-vxrg-v6vf-8c93.json +++ b/advisories/unreviewed/2022/05/GHSA-vxrg-v6vf-8c93/GHSA-vxrg-v6vf-8c93.json @@ -7,12 +7,8 @@ "CVE-2013-6999" ], "details": "** DISPUTED ** The IsHandleEntrySecure function in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 SP2 does not properly validate the tagPROCESSINFO pW32Job field, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted NtUserValidateHandleSecure call for an owned object. NOTE: the vendor reportedly disputes the significance of this report, stating that \"it appears to be a local DOS ... we don't consider it a security vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w32q-hpg7-2g7r/GHSA-w32q-hpg7-2g7r.json b/advisories/unreviewed/2022/05/GHSA-w32q-hpg7-2g7r/GHSA-w32q-hpg7-2g7r.json index fe5354481cf..e562ad91f73 100644 --- a/advisories/unreviewed/2022/05/GHSA-w32q-hpg7-2g7r/GHSA-w32q-hpg7-2g7r.json +++ b/advisories/unreviewed/2022/05/GHSA-w32q-hpg7-2g7r/GHSA-w32q-hpg7-2g7r.json @@ -7,12 +7,8 @@ "CVE-2020-7233" ], "details": "KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Logon.swf file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w5vv-wfg6-5g78/GHSA-w5vv-wfg6-5g78.json b/advisories/unreviewed/2022/05/GHSA-w5vv-wfg6-5g78/GHSA-w5vv-wfg6-5g78.json index 9591195bcc3..a19787dbded 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5vv-wfg6-5g78/GHSA-w5vv-wfg6-5g78.json +++ b/advisories/unreviewed/2022/05/GHSA-w5vv-wfg6-5g78/GHSA-w5vv-wfg6-5g78.json @@ -7,12 +7,8 @@ "CVE-2019-19837" ], "details": "Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote information disclosure of bin/web.conf via HTTP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w72m-x68v-qfr2/GHSA-w72m-x68v-qfr2.json b/advisories/unreviewed/2022/05/GHSA-w72m-x68v-qfr2/GHSA-w72m-x68v-qfr2.json index 944122647f4..712c9187f5b 100644 --- a/advisories/unreviewed/2022/05/GHSA-w72m-x68v-qfr2/GHSA-w72m-x68v-qfr2.json +++ b/advisories/unreviewed/2022/05/GHSA-w72m-x68v-qfr2/GHSA-w72m-x68v-qfr2.json @@ -7,12 +7,8 @@ "CVE-2015-1530" ], "details": "media/libmedia/IAudioPolicyService.cpp in Android before 5.1 allows attackers to execute arbitrary code with media_server privileges or cause a denial of service (integer overflow) via a crafted application that provides an invalid array size.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w75g-4cx7-2225/GHSA-w75g-4cx7-2225.json b/advisories/unreviewed/2022/05/GHSA-w75g-4cx7-2225/GHSA-w75g-4cx7-2225.json index 6ceb1eb2876..53fac107054 100644 --- a/advisories/unreviewed/2022/05/GHSA-w75g-4cx7-2225/GHSA-w75g-4cx7-2225.json +++ b/advisories/unreviewed/2022/05/GHSA-w75g-4cx7-2225/GHSA-w75g-4cx7-2225.json @@ -7,12 +7,8 @@ "CVE-2010-4121" ], "details": "** DISPUTED ** The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the \"default Microsoft Access database is not password protected because it is intended to be used for evaluation purposes only.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w8v5-w883-3mh3/GHSA-w8v5-w883-3mh3.json b/advisories/unreviewed/2022/05/GHSA-w8v5-w883-3mh3/GHSA-w8v5-w883-3mh3.json index e2b4bb9bf64..a0987de2580 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8v5-w883-3mh3/GHSA-w8v5-w883-3mh3.json +++ b/advisories/unreviewed/2022/05/GHSA-w8v5-w883-3mh3/GHSA-w8v5-w883-3mh3.json @@ -7,12 +7,8 @@ "CVE-2015-5745" ], "details": "Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w952-587w-j326/GHSA-w952-587w-j326.json b/advisories/unreviewed/2022/05/GHSA-w952-587w-j326/GHSA-w952-587w-j326.json index 47024f1ad1d..24c3a810191 100644 --- a/advisories/unreviewed/2022/05/GHSA-w952-587w-j326/GHSA-w952-587w-j326.json +++ b/advisories/unreviewed/2022/05/GHSA-w952-587w-j326/GHSA-w952-587w-j326.json @@ -7,12 +7,8 @@ "CVE-2008-4997" ], "details": "** DISPUTED ** dfxml-invoice in datafreedom-perl 0.1.7 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/zenity temporary file. NOTE: the vendor disputes this vulnerability, stating that the vector is solely \"an EXAMPLE used in the manpage.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w99g-6248-fxm4/GHSA-w99g-6248-fxm4.json b/advisories/unreviewed/2022/05/GHSA-w99g-6248-fxm4/GHSA-w99g-6248-fxm4.json index 10bdbe99a5a..321d35a89b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-w99g-6248-fxm4/GHSA-w99g-6248-fxm4.json +++ b/advisories/unreviewed/2022/05/GHSA-w99g-6248-fxm4/GHSA-w99g-6248-fxm4.json @@ -7,12 +7,8 @@ "CVE-2010-5180" ], "details": "** DISPUTED ** Race condition in VBA32 Personal 3.12.12.4 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w9wq-p2wh-m5px/GHSA-w9wq-p2wh-m5px.json b/advisories/unreviewed/2022/05/GHSA-w9wq-p2wh-m5px/GHSA-w9wq-p2wh-m5px.json index 0234c81f7f9..f740ddc6646 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9wq-p2wh-m5px/GHSA-w9wq-p2wh-m5px.json +++ b/advisories/unreviewed/2022/05/GHSA-w9wq-p2wh-m5px/GHSA-w9wq-p2wh-m5px.json @@ -7,12 +7,8 @@ "CVE-2008-4953" ], "details": "** DISPUTED ** firehol in firehol 1.256 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/.firehol-tmp-#####-*-* and (2) /tmp/firehol.conf temporary files. NOTE: the vendor disputes this vulnerability, stating that an attack \"would require an attacker to create 1073741824*PID-RANGE symlinks.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wc23-6g3m-fg2v/GHSA-wc23-6g3m-fg2v.json b/advisories/unreviewed/2022/05/GHSA-wc23-6g3m-fg2v/GHSA-wc23-6g3m-fg2v.json index 28135d5a490..e2eff189457 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc23-6g3m-fg2v/GHSA-wc23-6g3m-fg2v.json +++ b/advisories/unreviewed/2022/05/GHSA-wc23-6g3m-fg2v/GHSA-wc23-6g3m-fg2v.json @@ -7,12 +7,8 @@ "CVE-2019-15854" ], "details": "An issue was discovered in Maarch RM before 2.5. A privilege escalation vulnerability allows an authenticated user with lowest privileges to give herself highest administration privileges via a crafted PUT request to an unauthorized resource.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wc2r-5r95-vqwr/GHSA-wc2r-5r95-vqwr.json b/advisories/unreviewed/2022/05/GHSA-wc2r-5r95-vqwr/GHSA-wc2r-5r95-vqwr.json index 84c3a06b4a5..5a3273d2c46 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc2r-5r95-vqwr/GHSA-wc2r-5r95-vqwr.json +++ b/advisories/unreviewed/2022/05/GHSA-wc2r-5r95-vqwr/GHSA-wc2r-5r95-vqwr.json @@ -7,12 +7,8 @@ "CVE-2019-20428" ], "details": "In the Lustre file system before 2.12.3, the ptlrpc module has an out-of-bounds read and panic due to the lack of validation for specific fields of packets sent by a client. The ldl_request_cancel function mishandles a large lock_count parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wcf4-rc2p-qxv8/GHSA-wcf4-rc2p-qxv8.json b/advisories/unreviewed/2022/05/GHSA-wcf4-rc2p-qxv8/GHSA-wcf4-rc2p-qxv8.json index fa2039e27e0..375e8b23a2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcf4-rc2p-qxv8/GHSA-wcf4-rc2p-qxv8.json +++ b/advisories/unreviewed/2022/05/GHSA-wcf4-rc2p-qxv8/GHSA-wcf4-rc2p-qxv8.json @@ -7,12 +7,8 @@ "CVE-2020-2660" ], "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.28 and prior and 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wf3w-m23x-pwh9/GHSA-wf3w-m23x-pwh9.json b/advisories/unreviewed/2022/05/GHSA-wf3w-m23x-pwh9/GHSA-wf3w-m23x-pwh9.json index 081faa2cd3f..397cfd1eaf2 100644 --- a/advisories/unreviewed/2022/05/GHSA-wf3w-m23x-pwh9/GHSA-wf3w-m23x-pwh9.json +++ b/advisories/unreviewed/2022/05/GHSA-wf3w-m23x-pwh9/GHSA-wf3w-m23x-pwh9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wffv-45fq-q499/GHSA-wffv-45fq-q499.json b/advisories/unreviewed/2022/05/GHSA-wffv-45fq-q499/GHSA-wffv-45fq-q499.json index ac32ebc02e6..8cde549d8ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-wffv-45fq-q499/GHSA-wffv-45fq-q499.json +++ b/advisories/unreviewed/2022/05/GHSA-wffv-45fq-q499/GHSA-wffv-45fq-q499.json @@ -7,12 +7,8 @@ "CVE-2020-0616" ], "details": "A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wfw8-m9f8-45p8/GHSA-wfw8-m9f8-45p8.json b/advisories/unreviewed/2022/05/GHSA-wfw8-m9f8-45p8/GHSA-wfw8-m9f8-45p8.json index 81b57108a02..2b76ac54eb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfw8-m9f8-45p8/GHSA-wfw8-m9f8-45p8.json +++ b/advisories/unreviewed/2022/05/GHSA-wfw8-m9f8-45p8/GHSA-wfw8-m9f8-45p8.json @@ -7,12 +7,8 @@ "CVE-2019-15712" ], "details": "An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to access web console they should not be authorized for.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wfx4-9gjq-7h6w/GHSA-wfx4-9gjq-7h6w.json b/advisories/unreviewed/2022/05/GHSA-wfx4-9gjq-7h6w/GHSA-wfx4-9gjq-7h6w.json index 85f556fa905..d839f96fdda 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfx4-9gjq-7h6w/GHSA-wfx4-9gjq-7h6w.json +++ b/advisories/unreviewed/2022/05/GHSA-wfx4-9gjq-7h6w/GHSA-wfx4-9gjq-7h6w.json @@ -7,12 +7,8 @@ "CVE-2019-16020" ], "details": "Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due to incorrect processing of BGP update messages that contain crafted EVPN attributes. An attacker could exploit these vulnerabilities by sending BGP EVPN update messages with malformed attributes to be processed by an affected system. A successful exploit could allow the attacker to cause the BGP process to restart unexpectedly, resulting in a DoS condition. The Cisco implementation of BGP accepts incoming BGP traffic only from explicitly defined peers. To exploit these vulnerabilities, the malicious BGP update message would need to come from a configured, valid BGP peer, or would need to be injected by the attacker into the victim's BGP network on an existing, valid TCP connection to a BGP peer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wh7g-493g-3x9x/GHSA-wh7g-493g-3x9x.json b/advisories/unreviewed/2022/05/GHSA-wh7g-493g-3x9x/GHSA-wh7g-493g-3x9x.json index 2514f03219e..d1d06c1e58a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh7g-493g-3x9x/GHSA-wh7g-493g-3x9x.json +++ b/advisories/unreviewed/2022/05/GHSA-wh7g-493g-3x9x/GHSA-wh7g-493g-3x9x.json @@ -7,12 +7,8 @@ "CVE-2020-0630" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-whf8-2944-v69h/GHSA-whf8-2944-v69h.json b/advisories/unreviewed/2022/05/GHSA-whf8-2944-v69h/GHSA-whf8-2944-v69h.json index fe1b7e97865..87c01a2d0cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-whf8-2944-v69h/GHSA-whf8-2944-v69h.json +++ b/advisories/unreviewed/2022/05/GHSA-whf8-2944-v69h/GHSA-whf8-2944-v69h.json @@ -7,12 +7,8 @@ "CVE-2012-0782" ], "details": "** DISPUTED ** Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dbhost, (2) dbname, or (3) uname parameter. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether this specific XSS scenario has security relevance.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-whhw-94p5-5pc4/GHSA-whhw-94p5-5pc4.json b/advisories/unreviewed/2022/05/GHSA-whhw-94p5-5pc4/GHSA-whhw-94p5-5pc4.json index 38289b170f7..193e01f83df 100644 --- a/advisories/unreviewed/2022/05/GHSA-whhw-94p5-5pc4/GHSA-whhw-94p5-5pc4.json +++ b/advisories/unreviewed/2022/05/GHSA-whhw-94p5-5pc4/GHSA-whhw-94p5-5pc4.json @@ -7,12 +7,8 @@ "CVE-2020-3131" ], "details": "[CVE-2020-3131_su] A vulnerability in the Cisco Webex Teams client for Windows could allow an authenticated, remote attacker to cause the client to crash, resulting in a denial of service (DoS) condition. The attacker needs a valid developer account to exploit this vulnerability. The vulnerability is due to insufficient input validation when processing received adaptive cards. The attacker could exploit this vulnerability by sending an adaptive card with malicious content to an existing user of the Cisco Webex Teams client for Windows. A successful exploit could allow the attacker to cause the targeted user's client to crash continuously.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wmc6-394v-6mrx/GHSA-wmc6-394v-6mrx.json b/advisories/unreviewed/2022/05/GHSA-wmc6-394v-6mrx/GHSA-wmc6-394v-6mrx.json index 195a1de196e..7db778886d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmc6-394v-6mrx/GHSA-wmc6-394v-6mrx.json +++ b/advisories/unreviewed/2022/05/GHSA-wmc6-394v-6mrx/GHSA-wmc6-394v-6mrx.json @@ -7,12 +7,8 @@ "CVE-2020-5846" ], "details": "An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a \"PUT /obs/obm7/file/upload\" request with the base64-encoded pathname in the X-RSW-custom-encode-path HTTP header, and the content in the HTTP request body. It is possible to upload a file into any directory of the server. One can insert a JSP shell into the web server's directory and execute it. This leads to full system access as the configured user (e.g., Administrator) when starting from any authenticated session (e.g., a trial account). This is fixed in the 83/830122/cbs-*-hotfix-task26000 builds.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wmwq-vq22-mv7h/GHSA-wmwq-vq22-mv7h.json b/advisories/unreviewed/2022/05/GHSA-wmwq-vq22-mv7h/GHSA-wmwq-vq22-mv7h.json index 195aa08da54..702e12ecbdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmwq-vq22-mv7h/GHSA-wmwq-vq22-mv7h.json +++ b/advisories/unreviewed/2022/05/GHSA-wmwq-vq22-mv7h/GHSA-wmwq-vq22-mv7h.json @@ -7,12 +7,8 @@ "CVE-2010-5155" ], "details": "** DISPUTED ** Race condition in Blink Professional 4.6.1 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wpcv-8qf5-rx6g/GHSA-wpcv-8qf5-rx6g.json b/advisories/unreviewed/2022/05/GHSA-wpcv-8qf5-rx6g/GHSA-wpcv-8qf5-rx6g.json index 1114aa67b5f..8d797e9050d 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpcv-8qf5-rx6g/GHSA-wpcv-8qf5-rx6g.json +++ b/advisories/unreviewed/2022/05/GHSA-wpcv-8qf5-rx6g/GHSA-wpcv-8qf5-rx6g.json @@ -7,12 +7,8 @@ "CVE-2020-7990" ], "details": "Adive Framework 2.0.8 has admin/user/add userName XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wpww-8h9p-w3wq/GHSA-wpww-8h9p-w3wq.json b/advisories/unreviewed/2022/05/GHSA-wpww-8h9p-w3wq/GHSA-wpww-8h9p-w3wq.json index a892cd1d269..03b845fe83d 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpww-8h9p-w3wq/GHSA-wpww-8h9p-w3wq.json +++ b/advisories/unreviewed/2022/05/GHSA-wpww-8h9p-w3wq/GHSA-wpww-8h9p-w3wq.json @@ -7,12 +7,8 @@ "CVE-2020-1605" ], "details": "When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv4 packets who may then arbitrarily execute commands as root on the target device. This issue affects IPv4 JDHCPD services. This issue affects: Juniper Networks Junos OS: 15.1 versions prior to 15.1R7-S6; 15.1X49 versions prior to 15.1X49-D200; 15.1X53 versions prior to 15.1X53-D592; 16.1 versions prior to 16.1R7-S6; 16.2 versions prior to 16.2R2-S11; 17.1 versions prior to 17.1R2-S11, 17.1R3-S1; 17.2 versions prior to 17.2R2-S8, 17.2R3-S3; 17.3 versions prior to 17.3R3-S6; 17.4 versions prior to 17.4R2-S7, 17.4R3; 18.1 versions prior to 18.1R3-S8; 18.2 versions prior to 18.2R3-S2; 18.2X75 versions prior to 18.2X75-D60; 18.3 versions prior to 18.3R1-S6, 18.3R2-S2, 18.3R3; 18.4 versions prior to 18.4R1-S5, 18.4R2-S3, 18.4R3; 19.1 versions prior to 19.1R1-S3, 19.1R2; 19.2 versions prior to 19.2R1-S3, 19.2R2*. and All versions prior to 19.3R1 on Junos OS Evolved. This issue do not affect versions of Junos OS prior to 15.1, or JDHCPD operating as a local server in non-relay mode.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wpx9-4c3x-px86/GHSA-wpx9-4c3x-px86.json b/advisories/unreviewed/2022/05/GHSA-wpx9-4c3x-px86/GHSA-wpx9-4c3x-px86.json index b79d832e332..62e9b6f378a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpx9-4c3x-px86/GHSA-wpx9-4c3x-px86.json +++ b/advisories/unreviewed/2022/05/GHSA-wpx9-4c3x-px86/GHSA-wpx9-4c3x-px86.json @@ -7,12 +7,8 @@ "CVE-2020-2725" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wq4r-h44x-wppw/GHSA-wq4r-h44x-wppw.json b/advisories/unreviewed/2022/05/GHSA-wq4r-h44x-wppw/GHSA-wq4r-h44x-wppw.json index 529c246c986..6ecad1f76be 100644 --- a/advisories/unreviewed/2022/05/GHSA-wq4r-h44x-wppw/GHSA-wq4r-h44x-wppw.json +++ b/advisories/unreviewed/2022/05/GHSA-wq4r-h44x-wppw/GHSA-wq4r-h44x-wppw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wrvq-g9w5-f3jj/GHSA-wrvq-g9w5-f3jj.json b/advisories/unreviewed/2022/05/GHSA-wrvq-g9w5-f3jj/GHSA-wrvq-g9w5-f3jj.json index 788357badb3..9f8a813a60f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrvq-g9w5-f3jj/GHSA-wrvq-g9w5-f3jj.json +++ b/advisories/unreviewed/2022/05/GHSA-wrvq-g9w5-f3jj/GHSA-wrvq-g9w5-f3jj.json @@ -7,12 +7,8 @@ "CVE-2020-0654" ], "details": "A security feature bypass vulnerability exists in Microsoft OneDrive App for Android.This could allow an attacker to bypass the passcode or fingerprint requirements of the App.The security update addresses the vulnerability by correcting the way Microsoft OneDrive App for Android handles sharing links., aka 'Microsoft OneDrive for Android Security Feature Bypass Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wrwc-vgm8-jp23/GHSA-wrwc-vgm8-jp23.json b/advisories/unreviewed/2022/05/GHSA-wrwc-vgm8-jp23/GHSA-wrwc-vgm8-jp23.json index 67d347d28b3..bac6c30a500 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrwc-vgm8-jp23/GHSA-wrwc-vgm8-jp23.json +++ b/advisories/unreviewed/2022/05/GHSA-wrwc-vgm8-jp23/GHSA-wrwc-vgm8-jp23.json @@ -7,12 +7,8 @@ "CVE-2019-8947" ], "details": "Zimbra Collaboration 8.7.x - 8.8.11P2 contains non-persistent XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wv39-gr2w-7565/GHSA-wv39-gr2w-7565.json b/advisories/unreviewed/2022/05/GHSA-wv39-gr2w-7565/GHSA-wv39-gr2w-7565.json index 23ccad4d453..62b65223414 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv39-gr2w-7565/GHSA-wv39-gr2w-7565.json +++ b/advisories/unreviewed/2022/05/GHSA-wv39-gr2w-7565/GHSA-wv39-gr2w-7565.json @@ -7,12 +7,8 @@ "CVE-2010-4001" ], "details": "** DISPUTED ** GMXRC.bash in Gromacs 4.5.1 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: CVE disputes this issue because the GMXLDLIB value is always added to the beginning of LD_LIBRARY_PATH at a later point in the script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wvw6-w9qq-28x5/GHSA-wvw6-w9qq-28x5.json b/advisories/unreviewed/2022/05/GHSA-wvw6-w9qq-28x5/GHSA-wvw6-w9qq-28x5.json index 5e91ca2e381..020fa79e7b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvw6-w9qq-28x5/GHSA-wvw6-w9qq-28x5.json +++ b/advisories/unreviewed/2022/05/GHSA-wvw6-w9qq-28x5/GHSA-wvw6-w9qq-28x5.json @@ -7,12 +7,8 @@ "CVE-2019-17146" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HNAP service, which listens on TCP port 80 by default. When parsing the SOAPAction request header, the process does not properly validate the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-8458.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ww5g-r4hh-gvmh/GHSA-ww5g-r4hh-gvmh.json b/advisories/unreviewed/2022/05/GHSA-ww5g-r4hh-gvmh/GHSA-ww5g-r4hh-gvmh.json index c5c4898c624..600a5603958 100644 --- a/advisories/unreviewed/2022/05/GHSA-ww5g-r4hh-gvmh/GHSA-ww5g-r4hh-gvmh.json +++ b/advisories/unreviewed/2022/05/GHSA-ww5g-r4hh-gvmh/GHSA-ww5g-r4hh-gvmh.json @@ -7,12 +7,8 @@ "CVE-2020-2698" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wwhr-xmj9-h562/GHSA-wwhr-xmj9-h562.json b/advisories/unreviewed/2022/05/GHSA-wwhr-xmj9-h562/GHSA-wwhr-xmj9-h562.json index e849b869f5f..587a36c3e36 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwhr-xmj9-h562/GHSA-wwhr-xmj9-h562.json +++ b/advisories/unreviewed/2022/05/GHSA-wwhr-xmj9-h562/GHSA-wwhr-xmj9-h562.json @@ -7,12 +7,8 @@ "CVE-2020-5305" ], "details": "Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wwhw-v77g-vr64/GHSA-wwhw-v77g-vr64.json b/advisories/unreviewed/2022/05/GHSA-wwhw-v77g-vr64/GHSA-wwhw-v77g-vr64.json index ee8d6afc47d..d3ae25d2f10 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwhw-v77g-vr64/GHSA-wwhw-v77g-vr64.json +++ b/advisories/unreviewed/2022/05/GHSA-wwhw-v77g-vr64/GHSA-wwhw-v77g-vr64.json @@ -7,12 +7,8 @@ "CVE-2008-6804" ], "details": "** DISPUTED ** Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOKIE_LAST_ADMIN_LANG cookies. NOTE: a third party reports that the vendor disputes the existence of this issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wwr9-73jw-v7jx/GHSA-wwr9-73jw-v7jx.json b/advisories/unreviewed/2022/05/GHSA-wwr9-73jw-v7jx/GHSA-wwr9-73jw-v7jx.json index 7d5d34bd960..896d96ecc80 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwr9-73jw-v7jx/GHSA-wwr9-73jw-v7jx.json +++ b/advisories/unreviewed/2022/05/GHSA-wwr9-73jw-v7jx/GHSA-wwr9-73jw-v7jx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wx33-6v5h-q453/GHSA-wx33-6v5h-q453.json b/advisories/unreviewed/2022/05/GHSA-wx33-6v5h-q453/GHSA-wx33-6v5h-q453.json index 45b88befa8e..4104a80f4f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx33-6v5h-q453/GHSA-wx33-6v5h-q453.json +++ b/advisories/unreviewed/2022/05/GHSA-wx33-6v5h-q453/GHSA-wx33-6v5h-q453.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wx3r-hh3w-28wg/GHSA-wx3r-hh3w-28wg.json b/advisories/unreviewed/2022/05/GHSA-wx3r-hh3w-28wg/GHSA-wx3r-hh3w-28wg.json index d21ba7fda73..135398d0b11 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx3r-hh3w-28wg/GHSA-wx3r-hh3w-28wg.json +++ b/advisories/unreviewed/2022/05/GHSA-wx3r-hh3w-28wg/GHSA-wx3r-hh3w-28wg.json @@ -7,12 +7,8 @@ "CVE-2020-2654" ], "details": "Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -104,9 +100,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wx76-mwfh-rpg8/GHSA-wx76-mwfh-rpg8.json b/advisories/unreviewed/2022/05/GHSA-wx76-mwfh-rpg8/GHSA-wx76-mwfh-rpg8.json index a11fd38f3ea..4002195370f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx76-mwfh-rpg8/GHSA-wx76-mwfh-rpg8.json +++ b/advisories/unreviewed/2022/05/GHSA-wx76-mwfh-rpg8/GHSA-wx76-mwfh-rpg8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wxcp-cj39-pgjw/GHSA-wxcp-cj39-pgjw.json b/advisories/unreviewed/2022/05/GHSA-wxcp-cj39-pgjw/GHSA-wxcp-cj39-pgjw.json index f39d6246503..5e1d9da8dd4 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxcp-cj39-pgjw/GHSA-wxcp-cj39-pgjw.json +++ b/advisories/unreviewed/2022/05/GHSA-wxcp-cj39-pgjw/GHSA-wxcp-cj39-pgjw.json @@ -7,12 +7,8 @@ "CVE-2019-19632" ], "details": "An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud Fabric 4.5 through 4.5.5, 4.7 through 4.7.7, 5.0 through 5.0.1, and 5.1 through 5.1.4; and Multi-Cloud Director through 1.1.0. An unauthenticated attacker may inject stored arbitrary JavaScript (XSS), and execute it in the content of authenticated administrators.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x239-hf9w-jv5x/GHSA-x239-hf9w-jv5x.json b/advisories/unreviewed/2022/05/GHSA-x239-hf9w-jv5x/GHSA-x239-hf9w-jv5x.json index 67f8de30323..57e3f23c186 100644 --- a/advisories/unreviewed/2022/05/GHSA-x239-hf9w-jv5x/GHSA-x239-hf9w-jv5x.json +++ b/advisories/unreviewed/2022/05/GHSA-x239-hf9w-jv5x/GHSA-x239-hf9w-jv5x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x2mw-32fv-cr72/GHSA-x2mw-32fv-cr72.json b/advisories/unreviewed/2022/05/GHSA-x2mw-32fv-cr72/GHSA-x2mw-32fv-cr72.json index 7323f92c9d6..f802eda5743 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2mw-32fv-cr72/GHSA-x2mw-32fv-cr72.json +++ b/advisories/unreviewed/2022/05/GHSA-x2mw-32fv-cr72/GHSA-x2mw-32fv-cr72.json @@ -7,12 +7,8 @@ "CVE-2019-6529" ], "details": "An attacker could specially craft an FTP request that could crash the PR100088 Modbus gateway versions prior to release R02 (or Software Version 1.1.13166).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x3x6-8w8x-2p8g/GHSA-x3x6-8w8x-2p8g.json b/advisories/unreviewed/2022/05/GHSA-x3x6-8w8x-2p8g/GHSA-x3x6-8w8x-2p8g.json index 5902e99af86..f458b3752fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3x6-8w8x-2p8g/GHSA-x3x6-8w8x-2p8g.json +++ b/advisories/unreviewed/2022/05/GHSA-x3x6-8w8x-2p8g/GHSA-x3x6-8w8x-2p8g.json @@ -7,12 +7,8 @@ "CVE-2020-7213" ], "details": "Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date versions are presented with a pop-up window for a parallels_updates.xml file on the http://update.parallels.com web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x4c3-wmc6-2mx9/GHSA-x4c3-wmc6-2mx9.json b/advisories/unreviewed/2022/05/GHSA-x4c3-wmc6-2mx9/GHSA-x4c3-wmc6-2mx9.json index 444b3d0e866..98657bbc5ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4c3-wmc6-2mx9/GHSA-x4c3-wmc6-2mx9.json +++ b/advisories/unreviewed/2022/05/GHSA-x4c3-wmc6-2mx9/GHSA-x4c3-wmc6-2mx9.json @@ -7,12 +7,8 @@ "CVE-2019-14613" ], "details": "Improper access control in driver for Intel(R) VTune(TM) Amplifier for Windows* before update 8 may allow an authenticated user to potentially enable escalation of privilege via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x4cg-7v4w-vqhc/GHSA-x4cg-7v4w-vqhc.json b/advisories/unreviewed/2022/05/GHSA-x4cg-7v4w-vqhc/GHSA-x4cg-7v4w-vqhc.json index 243807fecfe..61d5957a6ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4cg-7v4w-vqhc/GHSA-x4cg-7v4w-vqhc.json +++ b/advisories/unreviewed/2022/05/GHSA-x4cg-7v4w-vqhc/GHSA-x4cg-7v4w-vqhc.json @@ -7,12 +7,8 @@ "CVE-2019-19857" ], "details": "An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. An admin can change their password without providing the current password, by using interfaces outside the Change Password screen. Thus, requiring the admin to enter an Old Password value on the Change Password screen does not enhance security. This is problematic in conjunction with XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x849-q9fw-685q/GHSA-x849-q9fw-685q.json b/advisories/unreviewed/2022/05/GHSA-x849-q9fw-685q/GHSA-x849-q9fw-685q.json index 1e4a402922d..541c0c95e6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-x849-q9fw-685q/GHSA-x849-q9fw-685q.json +++ b/advisories/unreviewed/2022/05/GHSA-x849-q9fw-685q/GHSA-x849-q9fw-685q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x86q-4558-6wjx/GHSA-x86q-4558-6wjx.json b/advisories/unreviewed/2022/05/GHSA-x86q-4558-6wjx/GHSA-x86q-4558-6wjx.json index 426db198a43..81ae18e1db5 100644 --- a/advisories/unreviewed/2022/05/GHSA-x86q-4558-6wjx/GHSA-x86q-4558-6wjx.json +++ b/advisories/unreviewed/2022/05/GHSA-x86q-4558-6wjx/GHSA-x86q-4558-6wjx.json @@ -7,12 +7,8 @@ "CVE-2020-2726" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x8xw-3cm4-77vj/GHSA-x8xw-3cm4-77vj.json b/advisories/unreviewed/2022/05/GHSA-x8xw-3cm4-77vj/GHSA-x8xw-3cm4-77vj.json index 35422802c5c..c382eb141a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8xw-3cm4-77vj/GHSA-x8xw-3cm4-77vj.json +++ b/advisories/unreviewed/2022/05/GHSA-x8xw-3cm4-77vj/GHSA-x8xw-3cm4-77vj.json @@ -7,12 +7,8 @@ "CVE-2020-7249" ], "details": "SMC D3G0804W 3.5.2.5-LAT_GA devices allow XSS via the SSID field on the WiFi Network Configuration page (after a successful login to the admin account).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xc6w-68h5-xvr5/GHSA-xc6w-68h5-xvr5.json b/advisories/unreviewed/2022/05/GHSA-xc6w-68h5-xvr5/GHSA-xc6w-68h5-xvr5.json index 426577faae1..efd5a96407a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc6w-68h5-xvr5/GHSA-xc6w-68h5-xvr5.json +++ b/advisories/unreviewed/2022/05/GHSA-xc6w-68h5-xvr5/GHSA-xc6w-68h5-xvr5.json @@ -7,12 +7,8 @@ "CVE-2010-5176" ], "details": "** DISPUTED ** Race condition in Security Shield 2010 13.0.16.313 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xc99-5j7p-6hmp/GHSA-xc99-5j7p-6hmp.json b/advisories/unreviewed/2022/05/GHSA-xc99-5j7p-6hmp/GHSA-xc99-5j7p-6hmp.json index db2ce7f13bd..0cc4a98c017 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc99-5j7p-6hmp/GHSA-xc99-5j7p-6hmp.json +++ b/advisories/unreviewed/2022/05/GHSA-xc99-5j7p-6hmp/GHSA-xc99-5j7p-6hmp.json @@ -7,12 +7,8 @@ "CVE-2020-6843" ], "details": "Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xcqv-q27j-c7xx/GHSA-xcqv-q27j-c7xx.json b/advisories/unreviewed/2022/05/GHSA-xcqv-q27j-c7xx/GHSA-xcqv-q27j-c7xx.json index 9440135b08f..d2581f018c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcqv-q27j-c7xx/GHSA-xcqv-q27j-c7xx.json +++ b/advisories/unreviewed/2022/05/GHSA-xcqv-q27j-c7xx/GHSA-xcqv-q27j-c7xx.json @@ -7,12 +7,8 @@ "CVE-2020-5843" ], "details": "Codoforum 4.8.3 allows XSS in the admin dashboard via a category to the Manage Users screen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xf4q-mw4x-gjfq/GHSA-xf4q-mw4x-gjfq.json b/advisories/unreviewed/2022/05/GHSA-xf4q-mw4x-gjfq/GHSA-xf4q-mw4x-gjfq.json index 03ef2525b1c..98d1d219471 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf4q-mw4x-gjfq/GHSA-xf4q-mw4x-gjfq.json +++ b/advisories/unreviewed/2022/05/GHSA-xf4q-mw4x-gjfq/GHSA-xf4q-mw4x-gjfq.json @@ -7,12 +7,8 @@ "CVE-2019-3997" ], "details": "Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.0-1.3 allows a local, unauthenticated attacker to pair a rogue keypad to an armed system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xf6r-phj6-qr64/GHSA-xf6r-phj6-qr64.json b/advisories/unreviewed/2022/05/GHSA-xf6r-phj6-qr64/GHSA-xf6r-phj6-qr64.json index 0bef1ac0897..1d2a253ef0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf6r-phj6-qr64/GHSA-xf6r-phj6-qr64.json +++ b/advisories/unreviewed/2022/05/GHSA-xf6r-phj6-qr64/GHSA-xf6r-phj6-qr64.json @@ -7,12 +7,8 @@ "CVE-2019-14017" ], "details": "Heap buffer overflow can occur while parsing invalid MKV clip which is not standard and have invalid vorbis codec data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCS605, QM215, Rennell, SA6155P, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xfq6-5vx6-8f2c/GHSA-xfq6-5vx6-8f2c.json b/advisories/unreviewed/2022/05/GHSA-xfq6-5vx6-8f2c/GHSA-xfq6-5vx6-8f2c.json index 8d636b638fe..b8ce8ca6777 100644 --- a/advisories/unreviewed/2022/05/GHSA-xfq6-5vx6-8f2c/GHSA-xfq6-5vx6-8f2c.json +++ b/advisories/unreviewed/2022/05/GHSA-xfq6-5vx6-8f2c/GHSA-xfq6-5vx6-8f2c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xgqx-4642-r33v/GHSA-xgqx-4642-r33v.json b/advisories/unreviewed/2022/05/GHSA-xgqx-4642-r33v/GHSA-xgqx-4642-r33v.json index 3a714651f18..df0fec05b27 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgqx-4642-r33v/GHSA-xgqx-4642-r33v.json +++ b/advisories/unreviewed/2022/05/GHSA-xgqx-4642-r33v/GHSA-xgqx-4642-r33v.json @@ -7,12 +7,8 @@ "CVE-2020-0637" ], "details": "An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles credential information, aka 'Remote Desktop Web Access Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xhgj-59fx-f85c/GHSA-xhgj-59fx-f85c.json b/advisories/unreviewed/2022/05/GHSA-xhgj-59fx-f85c/GHSA-xhgj-59fx-f85c.json index d1daa4b740a..b091f14843c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xhgj-59fx-f85c/GHSA-xhgj-59fx-f85c.json +++ b/advisories/unreviewed/2022/05/GHSA-xhgj-59fx-f85c/GHSA-xhgj-59fx-f85c.json @@ -7,12 +7,8 @@ "CVE-2019-6856" ], "details": "A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service when writing specific physical memory blocks using Modbus TCP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjfr-h85m-v9c6/GHSA-xjfr-h85m-v9c6.json b/advisories/unreviewed/2022/05/GHSA-xjfr-h85m-v9c6/GHSA-xjfr-h85m-v9c6.json index 63b5f0d5185..806b0c6ccec 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjfr-h85m-v9c6/GHSA-xjfr-h85m-v9c6.json +++ b/advisories/unreviewed/2022/05/GHSA-xjfr-h85m-v9c6/GHSA-xjfr-h85m-v9c6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xm35-85mm-9382/GHSA-xm35-85mm-9382.json b/advisories/unreviewed/2022/05/GHSA-xm35-85mm-9382/GHSA-xm35-85mm-9382.json index dd79ce4752c..ec50b8f45b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm35-85mm-9382/GHSA-xm35-85mm-9382.json +++ b/advisories/unreviewed/2022/05/GHSA-xm35-85mm-9382/GHSA-xm35-85mm-9382.json @@ -7,12 +7,8 @@ "CVE-2016-6591" ], "details": "A security bypass vulnerability exists in Symantec Norton App Lock 1.0.3.186 and earlier if application pinning is enabled, which could let a local malicious user bypass security restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xm85-wv7w-pf5x/GHSA-xm85-wv7w-pf5x.json b/advisories/unreviewed/2022/05/GHSA-xm85-wv7w-pf5x/GHSA-xm85-wv7w-pf5x.json index f2bb796e6a8..f4240e81a62 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm85-wv7w-pf5x/GHSA-xm85-wv7w-pf5x.json +++ b/advisories/unreviewed/2022/05/GHSA-xm85-wv7w-pf5x/GHSA-xm85-wv7w-pf5x.json @@ -7,12 +7,8 @@ "CVE-2020-7952" ], "details": "rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is affected by memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xm8g-mhgj-5vhv/GHSA-xm8g-mhgj-5vhv.json b/advisories/unreviewed/2022/05/GHSA-xm8g-mhgj-5vhv/GHSA-xm8g-mhgj-5vhv.json index bcc931ef07e..acf7c265f3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm8g-mhgj-5vhv/GHSA-xm8g-mhgj-5vhv.json +++ b/advisories/unreviewed/2022/05/GHSA-xm8g-mhgj-5vhv/GHSA-xm8g-mhgj-5vhv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xp48-jwjq-3mmc/GHSA-xp48-jwjq-3mmc.json b/advisories/unreviewed/2022/05/GHSA-xp48-jwjq-3mmc/GHSA-xp48-jwjq-3mmc.json index df52a45d972..1450506a96f 100644 --- a/advisories/unreviewed/2022/05/GHSA-xp48-jwjq-3mmc/GHSA-xp48-jwjq-3mmc.json +++ b/advisories/unreviewed/2022/05/GHSA-xp48-jwjq-3mmc/GHSA-xp48-jwjq-3mmc.json @@ -7,12 +7,8 @@ "CVE-2020-2701" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xp8m-vj7j-cr35/GHSA-xp8m-vj7j-cr35.json b/advisories/unreviewed/2022/05/GHSA-xp8m-vj7j-cr35/GHSA-xp8m-vj7j-cr35.json index 34e556581fd..14b623dfb19 100644 --- a/advisories/unreviewed/2022/05/GHSA-xp8m-vj7j-cr35/GHSA-xp8m-vj7j-cr35.json +++ b/advisories/unreviewed/2022/05/GHSA-xp8m-vj7j-cr35/GHSA-xp8m-vj7j-cr35.json @@ -7,12 +7,8 @@ "CVE-2020-0613" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xrpc-f6j4-wmx4/GHSA-xrpc-f6j4-wmx4.json b/advisories/unreviewed/2022/05/GHSA-xrpc-f6j4-wmx4/GHSA-xrpc-f6j4-wmx4.json index 92b98956182..7fe90f0149b 100644 --- a/advisories/unreviewed/2022/05/GHSA-xrpc-f6j4-wmx4/GHSA-xrpc-f6j4-wmx4.json +++ b/advisories/unreviewed/2022/05/GHSA-xrpc-f6j4-wmx4/GHSA-xrpc-f6j4-wmx4.json @@ -7,12 +7,8 @@ "CVE-2020-6963" ], "details": "In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilized hard coded SMB credentials, which may allow an attacker to remotely execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xw6x-pgf8-fgw8/GHSA-xw6x-pgf8-fgw8.json b/advisories/unreviewed/2022/05/GHSA-xw6x-pgf8-fgw8/GHSA-xw6x-pgf8-fgw8.json index 41f2238548d..930b89190d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw6x-pgf8-fgw8/GHSA-xw6x-pgf8-fgw8.json +++ b/advisories/unreviewed/2022/05/GHSA-xw6x-pgf8-fgw8/GHSA-xw6x-pgf8-fgw8.json @@ -7,12 +7,8 @@ "CVE-2019-19278" ], "details": "A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 Drives MLFB 6SR32..-.....-.... MLFB 6SR4...-.....-.... MLFB 6SR5...-.....-.... With option A30 (HMIs 12 inches or larger) (All versions), SINAMICS PERFECT HARMONY GH180 Drives MLFB 6SR325.-.....-.... (High Availability) (All versions). The affected device contains a vulnerability that could allow an unauthenticated attacker to restore the affected device to a point where predefined application and operating system protection mechanisms are not in place. Successful exploitation requires physical access to the system, but no system privileges and no user interaction. An attacker could use the vulnerability to compromise confidentialiy, integrity and availability of the device. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-2997-6fq4-wwch/GHSA-2997-6fq4-wwch.json b/advisories/unreviewed/2022/09/GHSA-2997-6fq4-wwch/GHSA-2997-6fq4-wwch.json index 86a2ed211a8..a2d1fc8fbcb 100644 --- a/advisories/unreviewed/2022/09/GHSA-2997-6fq4-wwch/GHSA-2997-6fq4-wwch.json +++ b/advisories/unreviewed/2022/09/GHSA-2997-6fq4-wwch/GHSA-2997-6fq4-wwch.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-33v4-4p2r-hcrr/GHSA-33v4-4p2r-hcrr.json b/advisories/unreviewed/2022/09/GHSA-33v4-4p2r-hcrr/GHSA-33v4-4p2r-hcrr.json index d04ff4b2a16..03baf4a8c31 100644 --- a/advisories/unreviewed/2022/09/GHSA-33v4-4p2r-hcrr/GHSA-33v4-4p2r-hcrr.json +++ b/advisories/unreviewed/2022/09/GHSA-33v4-4p2r-hcrr/GHSA-33v4-4p2r-hcrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-3ww9-jwr8-mpg3/GHSA-3ww9-jwr8-mpg3.json b/advisories/unreviewed/2022/09/GHSA-3ww9-jwr8-mpg3/GHSA-3ww9-jwr8-mpg3.json index aea17d2e082..c2df1128495 100644 --- a/advisories/unreviewed/2022/09/GHSA-3ww9-jwr8-mpg3/GHSA-3ww9-jwr8-mpg3.json +++ b/advisories/unreviewed/2022/09/GHSA-3ww9-jwr8-mpg3/GHSA-3ww9-jwr8-mpg3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-4jcr-hxpf-rggc/GHSA-4jcr-hxpf-rggc.json b/advisories/unreviewed/2022/09/GHSA-4jcr-hxpf-rggc/GHSA-4jcr-hxpf-rggc.json index fe7811a38f8..c9770c5827c 100644 --- a/advisories/unreviewed/2022/09/GHSA-4jcr-hxpf-rggc/GHSA-4jcr-hxpf-rggc.json +++ b/advisories/unreviewed/2022/09/GHSA-4jcr-hxpf-rggc/GHSA-4jcr-hxpf-rggc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-4rhp-v69r-6w59/GHSA-4rhp-v69r-6w59.json b/advisories/unreviewed/2022/09/GHSA-4rhp-v69r-6w59/GHSA-4rhp-v69r-6w59.json index 11231b55951..9da7c91e8a9 100644 --- a/advisories/unreviewed/2022/09/GHSA-4rhp-v69r-6w59/GHSA-4rhp-v69r-6w59.json +++ b/advisories/unreviewed/2022/09/GHSA-4rhp-v69r-6w59/GHSA-4rhp-v69r-6w59.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-4x42-9v2h-3jxc/GHSA-4x42-9v2h-3jxc.json b/advisories/unreviewed/2022/09/GHSA-4x42-9v2h-3jxc/GHSA-4x42-9v2h-3jxc.json index e1e526e2c89..9ac34907b7e 100644 --- a/advisories/unreviewed/2022/09/GHSA-4x42-9v2h-3jxc/GHSA-4x42-9v2h-3jxc.json +++ b/advisories/unreviewed/2022/09/GHSA-4x42-9v2h-3jxc/GHSA-4x42-9v2h-3jxc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-5xc8-76fm-5jfw/GHSA-5xc8-76fm-5jfw.json b/advisories/unreviewed/2022/09/GHSA-5xc8-76fm-5jfw/GHSA-5xc8-76fm-5jfw.json index 23f8b617967..e1be03a271a 100644 --- a/advisories/unreviewed/2022/09/GHSA-5xc8-76fm-5jfw/GHSA-5xc8-76fm-5jfw.json +++ b/advisories/unreviewed/2022/09/GHSA-5xc8-76fm-5jfw/GHSA-5xc8-76fm-5jfw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-69hr-qqmq-cf8v/GHSA-69hr-qqmq-cf8v.json b/advisories/unreviewed/2022/09/GHSA-69hr-qqmq-cf8v/GHSA-69hr-qqmq-cf8v.json index a290578a94a..00540fcae33 100644 --- a/advisories/unreviewed/2022/09/GHSA-69hr-qqmq-cf8v/GHSA-69hr-qqmq-cf8v.json +++ b/advisories/unreviewed/2022/09/GHSA-69hr-qqmq-cf8v/GHSA-69hr-qqmq-cf8v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-76fw-v9wm-37cg/GHSA-76fw-v9wm-37cg.json b/advisories/unreviewed/2022/09/GHSA-76fw-v9wm-37cg/GHSA-76fw-v9wm-37cg.json index 00d0878b63a..bc6e1440de5 100644 --- a/advisories/unreviewed/2022/09/GHSA-76fw-v9wm-37cg/GHSA-76fw-v9wm-37cg.json +++ b/advisories/unreviewed/2022/09/GHSA-76fw-v9wm-37cg/GHSA-76fw-v9wm-37cg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-7hhj-936p-m562/GHSA-7hhj-936p-m562.json b/advisories/unreviewed/2022/09/GHSA-7hhj-936p-m562/GHSA-7hhj-936p-m562.json index db05b4080b4..8683cdbdd6f 100644 --- a/advisories/unreviewed/2022/09/GHSA-7hhj-936p-m562/GHSA-7hhj-936p-m562.json +++ b/advisories/unreviewed/2022/09/GHSA-7hhj-936p-m562/GHSA-7hhj-936p-m562.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-7mwp-rqrw-2vwh/GHSA-7mwp-rqrw-2vwh.json b/advisories/unreviewed/2022/09/GHSA-7mwp-rqrw-2vwh/GHSA-7mwp-rqrw-2vwh.json index 917197de6df..fa3fd8db3ad 100644 --- a/advisories/unreviewed/2022/09/GHSA-7mwp-rqrw-2vwh/GHSA-7mwp-rqrw-2vwh.json +++ b/advisories/unreviewed/2022/09/GHSA-7mwp-rqrw-2vwh/GHSA-7mwp-rqrw-2vwh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-8gc3-xq83-phww/GHSA-8gc3-xq83-phww.json b/advisories/unreviewed/2022/09/GHSA-8gc3-xq83-phww/GHSA-8gc3-xq83-phww.json index d721616dcbe..457f58f33b7 100644 --- a/advisories/unreviewed/2022/09/GHSA-8gc3-xq83-phww/GHSA-8gc3-xq83-phww.json +++ b/advisories/unreviewed/2022/09/GHSA-8gc3-xq83-phww/GHSA-8gc3-xq83-phww.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-9f53-qp4r-c23f/GHSA-9f53-qp4r-c23f.json b/advisories/unreviewed/2022/09/GHSA-9f53-qp4r-c23f/GHSA-9f53-qp4r-c23f.json index 29eb4332f4c..fd70df8bbb6 100644 --- a/advisories/unreviewed/2022/09/GHSA-9f53-qp4r-c23f/GHSA-9f53-qp4r-c23f.json +++ b/advisories/unreviewed/2022/09/GHSA-9f53-qp4r-c23f/GHSA-9f53-qp4r-c23f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-chv5-2f3c-f6gx/GHSA-chv5-2f3c-f6gx.json b/advisories/unreviewed/2022/09/GHSA-chv5-2f3c-f6gx/GHSA-chv5-2f3c-f6gx.json index eec749b3d9e..00684701bea 100644 --- a/advisories/unreviewed/2022/09/GHSA-chv5-2f3c-f6gx/GHSA-chv5-2f3c-f6gx.json +++ b/advisories/unreviewed/2022/09/GHSA-chv5-2f3c-f6gx/GHSA-chv5-2f3c-f6gx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-chwv-7q79-6cxm/GHSA-chwv-7q79-6cxm.json b/advisories/unreviewed/2022/09/GHSA-chwv-7q79-6cxm/GHSA-chwv-7q79-6cxm.json index 9947fac05f5..86da754457c 100644 --- a/advisories/unreviewed/2022/09/GHSA-chwv-7q79-6cxm/GHSA-chwv-7q79-6cxm.json +++ b/advisories/unreviewed/2022/09/GHSA-chwv-7q79-6cxm/GHSA-chwv-7q79-6cxm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-gxf3-5gjm-vcfh/GHSA-gxf3-5gjm-vcfh.json b/advisories/unreviewed/2022/09/GHSA-gxf3-5gjm-vcfh/GHSA-gxf3-5gjm-vcfh.json index 4eae688778f..7829bb55bfc 100644 --- a/advisories/unreviewed/2022/09/GHSA-gxf3-5gjm-vcfh/GHSA-gxf3-5gjm-vcfh.json +++ b/advisories/unreviewed/2022/09/GHSA-gxf3-5gjm-vcfh/GHSA-gxf3-5gjm-vcfh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-h6v4-9c8c-hxcj/GHSA-h6v4-9c8c-hxcj.json b/advisories/unreviewed/2022/09/GHSA-h6v4-9c8c-hxcj/GHSA-h6v4-9c8c-hxcj.json index da4a225d88b..f69c18b7ad8 100644 --- a/advisories/unreviewed/2022/09/GHSA-h6v4-9c8c-hxcj/GHSA-h6v4-9c8c-hxcj.json +++ b/advisories/unreviewed/2022/09/GHSA-h6v4-9c8c-hxcj/GHSA-h6v4-9c8c-hxcj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-hc5v-xhhc-fccp/GHSA-hc5v-xhhc-fccp.json b/advisories/unreviewed/2022/09/GHSA-hc5v-xhhc-fccp/GHSA-hc5v-xhhc-fccp.json index b3968ad3258..6419b9e7aac 100644 --- a/advisories/unreviewed/2022/09/GHSA-hc5v-xhhc-fccp/GHSA-hc5v-xhhc-fccp.json +++ b/advisories/unreviewed/2022/09/GHSA-hc5v-xhhc-fccp/GHSA-hc5v-xhhc-fccp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-hj7h-g298-7rxc/GHSA-hj7h-g298-7rxc.json b/advisories/unreviewed/2022/09/GHSA-hj7h-g298-7rxc/GHSA-hj7h-g298-7rxc.json index fe4170a1ad8..28e3862444a 100644 --- a/advisories/unreviewed/2022/09/GHSA-hj7h-g298-7rxc/GHSA-hj7h-g298-7rxc.json +++ b/advisories/unreviewed/2022/09/GHSA-hj7h-g298-7rxc/GHSA-hj7h-g298-7rxc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-j7p4-7jxx-qhpc/GHSA-j7p4-7jxx-qhpc.json b/advisories/unreviewed/2022/09/GHSA-j7p4-7jxx-qhpc/GHSA-j7p4-7jxx-qhpc.json index f7ce93c0e59..3309cc55c23 100644 --- a/advisories/unreviewed/2022/09/GHSA-j7p4-7jxx-qhpc/GHSA-j7p4-7jxx-qhpc.json +++ b/advisories/unreviewed/2022/09/GHSA-j7p4-7jxx-qhpc/GHSA-j7p4-7jxx-qhpc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-jjw5-mvr7-pj78/GHSA-jjw5-mvr7-pj78.json b/advisories/unreviewed/2022/09/GHSA-jjw5-mvr7-pj78/GHSA-jjw5-mvr7-pj78.json index fb1bcee8e6d..6029e170f0a 100644 --- a/advisories/unreviewed/2022/09/GHSA-jjw5-mvr7-pj78/GHSA-jjw5-mvr7-pj78.json +++ b/advisories/unreviewed/2022/09/GHSA-jjw5-mvr7-pj78/GHSA-jjw5-mvr7-pj78.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-m5cg-qjmp-pw59/GHSA-m5cg-qjmp-pw59.json b/advisories/unreviewed/2022/09/GHSA-m5cg-qjmp-pw59/GHSA-m5cg-qjmp-pw59.json index d4d3570d8ca..515b6e51ef4 100644 --- a/advisories/unreviewed/2022/09/GHSA-m5cg-qjmp-pw59/GHSA-m5cg-qjmp-pw59.json +++ b/advisories/unreviewed/2022/09/GHSA-m5cg-qjmp-pw59/GHSA-m5cg-qjmp-pw59.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-m5p3-4fgc-g573/GHSA-m5p3-4fgc-g573.json b/advisories/unreviewed/2022/09/GHSA-m5p3-4fgc-g573/GHSA-m5p3-4fgc-g573.json index eecfe058acc..0a8d5c723f7 100644 --- a/advisories/unreviewed/2022/09/GHSA-m5p3-4fgc-g573/GHSA-m5p3-4fgc-g573.json +++ b/advisories/unreviewed/2022/09/GHSA-m5p3-4fgc-g573/GHSA-m5p3-4fgc-g573.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-p9v8-9gv6-r54c/GHSA-p9v8-9gv6-r54c.json b/advisories/unreviewed/2022/09/GHSA-p9v8-9gv6-r54c/GHSA-p9v8-9gv6-r54c.json index af2e148fa2a..274da3c3c7c 100644 --- a/advisories/unreviewed/2022/09/GHSA-p9v8-9gv6-r54c/GHSA-p9v8-9gv6-r54c.json +++ b/advisories/unreviewed/2022/09/GHSA-p9v8-9gv6-r54c/GHSA-p9v8-9gv6-r54c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-pp4f-qmqh-44fx/GHSA-pp4f-qmqh-44fx.json b/advisories/unreviewed/2022/09/GHSA-pp4f-qmqh-44fx/GHSA-pp4f-qmqh-44fx.json index dd5e4e37f8b..24a3dc1997c 100644 --- a/advisories/unreviewed/2022/09/GHSA-pp4f-qmqh-44fx/GHSA-pp4f-qmqh-44fx.json +++ b/advisories/unreviewed/2022/09/GHSA-pp4f-qmqh-44fx/GHSA-pp4f-qmqh-44fx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-pqh4-f68f-fc23/GHSA-pqh4-f68f-fc23.json b/advisories/unreviewed/2022/09/GHSA-pqh4-f68f-fc23/GHSA-pqh4-f68f-fc23.json index e7a12c0ab5f..f3e1da02015 100644 --- a/advisories/unreviewed/2022/09/GHSA-pqh4-f68f-fc23/GHSA-pqh4-f68f-fc23.json +++ b/advisories/unreviewed/2022/09/GHSA-pqh4-f68f-fc23/GHSA-pqh4-f68f-fc23.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-q3pp-76rw-fqvm/GHSA-q3pp-76rw-fqvm.json b/advisories/unreviewed/2022/09/GHSA-q3pp-76rw-fqvm/GHSA-q3pp-76rw-fqvm.json index e683ef44727..e716993324d 100644 --- a/advisories/unreviewed/2022/09/GHSA-q3pp-76rw-fqvm/GHSA-q3pp-76rw-fqvm.json +++ b/advisories/unreviewed/2022/09/GHSA-q3pp-76rw-fqvm/GHSA-q3pp-76rw-fqvm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-q8m2-9wq9-fwhm/GHSA-q8m2-9wq9-fwhm.json b/advisories/unreviewed/2022/09/GHSA-q8m2-9wq9-fwhm/GHSA-q8m2-9wq9-fwhm.json index ea6e03eeb4e..5cbb49a798a 100644 --- a/advisories/unreviewed/2022/09/GHSA-q8m2-9wq9-fwhm/GHSA-q8m2-9wq9-fwhm.json +++ b/advisories/unreviewed/2022/09/GHSA-q8m2-9wq9-fwhm/GHSA-q8m2-9wq9-fwhm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-qgrc-hf25-rvv7/GHSA-qgrc-hf25-rvv7.json b/advisories/unreviewed/2022/09/GHSA-qgrc-hf25-rvv7/GHSA-qgrc-hf25-rvv7.json index ab5ab5bdd0a..8ce72b4e5b7 100644 --- a/advisories/unreviewed/2022/09/GHSA-qgrc-hf25-rvv7/GHSA-qgrc-hf25-rvv7.json +++ b/advisories/unreviewed/2022/09/GHSA-qgrc-hf25-rvv7/GHSA-qgrc-hf25-rvv7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-qqw6-c44g-58f2/GHSA-qqw6-c44g-58f2.json b/advisories/unreviewed/2022/09/GHSA-qqw6-c44g-58f2/GHSA-qqw6-c44g-58f2.json index bb1e67d2889..2baf3973678 100644 --- a/advisories/unreviewed/2022/09/GHSA-qqw6-c44g-58f2/GHSA-qqw6-c44g-58f2.json +++ b/advisories/unreviewed/2022/09/GHSA-qqw6-c44g-58f2/GHSA-qqw6-c44g-58f2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-v23c-hwjc-8qrh/GHSA-v23c-hwjc-8qrh.json b/advisories/unreviewed/2022/09/GHSA-v23c-hwjc-8qrh/GHSA-v23c-hwjc-8qrh.json index f698dad8987..57e6f4ebd30 100644 --- a/advisories/unreviewed/2022/09/GHSA-v23c-hwjc-8qrh/GHSA-v23c-hwjc-8qrh.json +++ b/advisories/unreviewed/2022/09/GHSA-v23c-hwjc-8qrh/GHSA-v23c-hwjc-8qrh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-v632-53j2-53ph/GHSA-v632-53j2-53ph.json b/advisories/unreviewed/2022/09/GHSA-v632-53j2-53ph/GHSA-v632-53j2-53ph.json index 1939b204e0c..d6234591083 100644 --- a/advisories/unreviewed/2022/09/GHSA-v632-53j2-53ph/GHSA-v632-53j2-53ph.json +++ b/advisories/unreviewed/2022/09/GHSA-v632-53j2-53ph/GHSA-v632-53j2-53ph.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-v7cg-cf6c-wpmp/GHSA-v7cg-cf6c-wpmp.json b/advisories/unreviewed/2022/09/GHSA-v7cg-cf6c-wpmp/GHSA-v7cg-cf6c-wpmp.json index 95e44a5ec03..9342ddad10b 100644 --- a/advisories/unreviewed/2022/09/GHSA-v7cg-cf6c-wpmp/GHSA-v7cg-cf6c-wpmp.json +++ b/advisories/unreviewed/2022/09/GHSA-v7cg-cf6c-wpmp/GHSA-v7cg-cf6c-wpmp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-w7p3-hmmp-qmx6/GHSA-w7p3-hmmp-qmx6.json b/advisories/unreviewed/2022/09/GHSA-w7p3-hmmp-qmx6/GHSA-w7p3-hmmp-qmx6.json index 0eef84c91f8..30c6a070e5c 100644 --- a/advisories/unreviewed/2022/09/GHSA-w7p3-hmmp-qmx6/GHSA-w7p3-hmmp-qmx6.json +++ b/advisories/unreviewed/2022/09/GHSA-w7p3-hmmp-qmx6/GHSA-w7p3-hmmp-qmx6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-wm38-5rh5-27ff/GHSA-wm38-5rh5-27ff.json b/advisories/unreviewed/2022/09/GHSA-wm38-5rh5-27ff/GHSA-wm38-5rh5-27ff.json index 9d1f14fc1c8..7ba8eb76e81 100644 --- a/advisories/unreviewed/2022/09/GHSA-wm38-5rh5-27ff/GHSA-wm38-5rh5-27ff.json +++ b/advisories/unreviewed/2022/09/GHSA-wm38-5rh5-27ff/GHSA-wm38-5rh5-27ff.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-wv76-cp7m-4v99/GHSA-wv76-cp7m-4v99.json b/advisories/unreviewed/2022/09/GHSA-wv76-cp7m-4v99/GHSA-wv76-cp7m-4v99.json index d91aa44d637..5c0b00ee259 100644 --- a/advisories/unreviewed/2022/09/GHSA-wv76-cp7m-4v99/GHSA-wv76-cp7m-4v99.json +++ b/advisories/unreviewed/2022/09/GHSA-wv76-cp7m-4v99/GHSA-wv76-cp7m-4v99.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-xjg2-7c9h-gr9w/GHSA-xjg2-7c9h-gr9w.json b/advisories/unreviewed/2022/09/GHSA-xjg2-7c9h-gr9w/GHSA-xjg2-7c9h-gr9w.json index 87dc18c2e12..93863e1fe96 100644 --- a/advisories/unreviewed/2022/09/GHSA-xjg2-7c9h-gr9w/GHSA-xjg2-7c9h-gr9w.json +++ b/advisories/unreviewed/2022/09/GHSA-xjg2-7c9h-gr9w/GHSA-xjg2-7c9h-gr9w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-2vh8-37v3-crfv/GHSA-2vh8-37v3-crfv.json b/advisories/unreviewed/2022/10/GHSA-2vh8-37v3-crfv/GHSA-2vh8-37v3-crfv.json index 1ce22fb1d2c..e9abafebd89 100644 --- a/advisories/unreviewed/2022/10/GHSA-2vh8-37v3-crfv/GHSA-2vh8-37v3-crfv.json +++ b/advisories/unreviewed/2022/10/GHSA-2vh8-37v3-crfv/GHSA-2vh8-37v3-crfv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-2x3m-h8fc-hm6p/GHSA-2x3m-h8fc-hm6p.json b/advisories/unreviewed/2022/10/GHSA-2x3m-h8fc-hm6p/GHSA-2x3m-h8fc-hm6p.json index fb0c84df8df..ed990cf234a 100644 --- a/advisories/unreviewed/2022/10/GHSA-2x3m-h8fc-hm6p/GHSA-2x3m-h8fc-hm6p.json +++ b/advisories/unreviewed/2022/10/GHSA-2x3m-h8fc-hm6p/GHSA-2x3m-h8fc-hm6p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-3362-fcx9-m9w5/GHSA-3362-fcx9-m9w5.json b/advisories/unreviewed/2022/10/GHSA-3362-fcx9-m9w5/GHSA-3362-fcx9-m9w5.json index 222b2c47e85..f01ef2aaf52 100644 --- a/advisories/unreviewed/2022/10/GHSA-3362-fcx9-m9w5/GHSA-3362-fcx9-m9w5.json +++ b/advisories/unreviewed/2022/10/GHSA-3362-fcx9-m9w5/GHSA-3362-fcx9-m9w5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-5v3h-r8cr-48wj/GHSA-5v3h-r8cr-48wj.json b/advisories/unreviewed/2022/10/GHSA-5v3h-r8cr-48wj/GHSA-5v3h-r8cr-48wj.json index 18038d64e25..967a81cac4a 100644 --- a/advisories/unreviewed/2022/10/GHSA-5v3h-r8cr-48wj/GHSA-5v3h-r8cr-48wj.json +++ b/advisories/unreviewed/2022/10/GHSA-5v3h-r8cr-48wj/GHSA-5v3h-r8cr-48wj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-66v9-vq83-62h5/GHSA-66v9-vq83-62h5.json b/advisories/unreviewed/2022/10/GHSA-66v9-vq83-62h5/GHSA-66v9-vq83-62h5.json index f426daffbee..1da32ff750a 100644 --- a/advisories/unreviewed/2022/10/GHSA-66v9-vq83-62h5/GHSA-66v9-vq83-62h5.json +++ b/advisories/unreviewed/2022/10/GHSA-66v9-vq83-62h5/GHSA-66v9-vq83-62h5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-7p78-28rx-wm6c/GHSA-7p78-28rx-wm6c.json b/advisories/unreviewed/2022/10/GHSA-7p78-28rx-wm6c/GHSA-7p78-28rx-wm6c.json index e13c4472369..b0fc8e29edd 100644 --- a/advisories/unreviewed/2022/10/GHSA-7p78-28rx-wm6c/GHSA-7p78-28rx-wm6c.json +++ b/advisories/unreviewed/2022/10/GHSA-7p78-28rx-wm6c/GHSA-7p78-28rx-wm6c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-85qp-4q9c-33vh/GHSA-85qp-4q9c-33vh.json b/advisories/unreviewed/2022/10/GHSA-85qp-4q9c-33vh/GHSA-85qp-4q9c-33vh.json index dc7581d893c..d7dcd3dbd93 100644 --- a/advisories/unreviewed/2022/10/GHSA-85qp-4q9c-33vh/GHSA-85qp-4q9c-33vh.json +++ b/advisories/unreviewed/2022/10/GHSA-85qp-4q9c-33vh/GHSA-85qp-4q9c-33vh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-f3wc-8274-674f/GHSA-f3wc-8274-674f.json b/advisories/unreviewed/2022/10/GHSA-f3wc-8274-674f/GHSA-f3wc-8274-674f.json index c6847853c34..80e5e562938 100644 --- a/advisories/unreviewed/2022/10/GHSA-f3wc-8274-674f/GHSA-f3wc-8274-674f.json +++ b/advisories/unreviewed/2022/10/GHSA-f3wc-8274-674f/GHSA-f3wc-8274-674f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-h43g-m94v-wfpv/GHSA-h43g-m94v-wfpv.json b/advisories/unreviewed/2022/10/GHSA-h43g-m94v-wfpv/GHSA-h43g-m94v-wfpv.json index 8ba37b6cef2..c70912f2912 100644 --- a/advisories/unreviewed/2022/10/GHSA-h43g-m94v-wfpv/GHSA-h43g-m94v-wfpv.json +++ b/advisories/unreviewed/2022/10/GHSA-h43g-m94v-wfpv/GHSA-h43g-m94v-wfpv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-jg3v-79gc-572m/GHSA-jg3v-79gc-572m.json b/advisories/unreviewed/2022/10/GHSA-jg3v-79gc-572m/GHSA-jg3v-79gc-572m.json index 8480b72a1df..f7b2ff9a719 100644 --- a/advisories/unreviewed/2022/10/GHSA-jg3v-79gc-572m/GHSA-jg3v-79gc-572m.json +++ b/advisories/unreviewed/2022/10/GHSA-jg3v-79gc-572m/GHSA-jg3v-79gc-572m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-m5vf-pfhq-wc74/GHSA-m5vf-pfhq-wc74.json b/advisories/unreviewed/2022/10/GHSA-m5vf-pfhq-wc74/GHSA-m5vf-pfhq-wc74.json index 86ade0b5d64..03abf855c50 100644 --- a/advisories/unreviewed/2022/10/GHSA-m5vf-pfhq-wc74/GHSA-m5vf-pfhq-wc74.json +++ b/advisories/unreviewed/2022/10/GHSA-m5vf-pfhq-wc74/GHSA-m5vf-pfhq-wc74.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-m974-9c77-6xhp/GHSA-m974-9c77-6xhp.json b/advisories/unreviewed/2022/10/GHSA-m974-9c77-6xhp/GHSA-m974-9c77-6xhp.json index b510666d6a3..9261d975360 100644 --- a/advisories/unreviewed/2022/10/GHSA-m974-9c77-6xhp/GHSA-m974-9c77-6xhp.json +++ b/advisories/unreviewed/2022/10/GHSA-m974-9c77-6xhp/GHSA-m974-9c77-6xhp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-mvqp-5v99-c8gp/GHSA-mvqp-5v99-c8gp.json b/advisories/unreviewed/2022/10/GHSA-mvqp-5v99-c8gp/GHSA-mvqp-5v99-c8gp.json index d8d8941f7d8..81bed2e2457 100644 --- a/advisories/unreviewed/2022/10/GHSA-mvqp-5v99-c8gp/GHSA-mvqp-5v99-c8gp.json +++ b/advisories/unreviewed/2022/10/GHSA-mvqp-5v99-c8gp/GHSA-mvqp-5v99-c8gp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-p2c9-6h79-p9j6/GHSA-p2c9-6h79-p9j6.json b/advisories/unreviewed/2022/10/GHSA-p2c9-6h79-p9j6/GHSA-p2c9-6h79-p9j6.json index 81583c8f9cb..83dc3fdb80d 100644 --- a/advisories/unreviewed/2022/10/GHSA-p2c9-6h79-p9j6/GHSA-p2c9-6h79-p9j6.json +++ b/advisories/unreviewed/2022/10/GHSA-p2c9-6h79-p9j6/GHSA-p2c9-6h79-p9j6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-pc9q-654c-78w3/GHSA-pc9q-654c-78w3.json b/advisories/unreviewed/2022/10/GHSA-pc9q-654c-78w3/GHSA-pc9q-654c-78w3.json index 15e650b37f6..4b827466923 100644 --- a/advisories/unreviewed/2022/10/GHSA-pc9q-654c-78w3/GHSA-pc9q-654c-78w3.json +++ b/advisories/unreviewed/2022/10/GHSA-pc9q-654c-78w3/GHSA-pc9q-654c-78w3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-pjp7-ffv7-qj9m/GHSA-pjp7-ffv7-qj9m.json b/advisories/unreviewed/2022/10/GHSA-pjp7-ffv7-qj9m/GHSA-pjp7-ffv7-qj9m.json index 221e5a03260..8d00530fa14 100644 --- a/advisories/unreviewed/2022/10/GHSA-pjp7-ffv7-qj9m/GHSA-pjp7-ffv7-qj9m.json +++ b/advisories/unreviewed/2022/10/GHSA-pjp7-ffv7-qj9m/GHSA-pjp7-ffv7-qj9m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-q6gp-rjmw-h7qw/GHSA-q6gp-rjmw-h7qw.json b/advisories/unreviewed/2022/10/GHSA-q6gp-rjmw-h7qw/GHSA-q6gp-rjmw-h7qw.json index b498b49e6b4..69459bc70b9 100644 --- a/advisories/unreviewed/2022/10/GHSA-q6gp-rjmw-h7qw/GHSA-q6gp-rjmw-h7qw.json +++ b/advisories/unreviewed/2022/10/GHSA-q6gp-rjmw-h7qw/GHSA-q6gp-rjmw-h7qw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-rhw3-c4r2-28c3/GHSA-rhw3-c4r2-28c3.json b/advisories/unreviewed/2022/10/GHSA-rhw3-c4r2-28c3/GHSA-rhw3-c4r2-28c3.json index dcff24efec8..a1ace750d3e 100644 --- a/advisories/unreviewed/2022/10/GHSA-rhw3-c4r2-28c3/GHSA-rhw3-c4r2-28c3.json +++ b/advisories/unreviewed/2022/10/GHSA-rhw3-c4r2-28c3/GHSA-rhw3-c4r2-28c3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-vr32-696f-rxpr/GHSA-vr32-696f-rxpr.json b/advisories/unreviewed/2022/10/GHSA-vr32-696f-rxpr/GHSA-vr32-696f-rxpr.json index 50508811f48..156f7d2bd05 100644 --- a/advisories/unreviewed/2022/10/GHSA-vr32-696f-rxpr/GHSA-vr32-696f-rxpr.json +++ b/advisories/unreviewed/2022/10/GHSA-vr32-696f-rxpr/GHSA-vr32-696f-rxpr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-wpjq-v255-668c/GHSA-wpjq-v255-668c.json b/advisories/unreviewed/2022/10/GHSA-wpjq-v255-668c/GHSA-wpjq-v255-668c.json index 19314a68c8c..4cf711fd49b 100644 --- a/advisories/unreviewed/2022/10/GHSA-wpjq-v255-668c/GHSA-wpjq-v255-668c.json +++ b/advisories/unreviewed/2022/10/GHSA-wpjq-v255-668c/GHSA-wpjq-v255-668c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-xvvh-jr39-p8rh/GHSA-xvvh-jr39-p8rh.json b/advisories/unreviewed/2022/10/GHSA-xvvh-jr39-p8rh/GHSA-xvvh-jr39-p8rh.json index 92cf4f65cbe..d2636311e86 100644 --- a/advisories/unreviewed/2022/10/GHSA-xvvh-jr39-p8rh/GHSA-xvvh-jr39-p8rh.json +++ b/advisories/unreviewed/2022/10/GHSA-xvvh-jr39-p8rh/GHSA-xvvh-jr39-p8rh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-5jxw-j59v-xhxg/GHSA-5jxw-j59v-xhxg.json b/advisories/unreviewed/2024/02/GHSA-5jxw-j59v-xhxg/GHSA-5jxw-j59v-xhxg.json index bfc3b9b9a99..7182a49bcbf 100644 --- a/advisories/unreviewed/2024/02/GHSA-5jxw-j59v-xhxg/GHSA-5jxw-j59v-xhxg.json +++ b/advisories/unreviewed/2024/02/GHSA-5jxw-j59v-xhxg/GHSA-5jxw-j59v-xhxg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-3427-99jp-r4g2/GHSA-3427-99jp-r4g2.json b/advisories/unreviewed/2024/03/GHSA-3427-99jp-r4g2/GHSA-3427-99jp-r4g2.json index 5e4a991304c..c68bfc16a5c 100644 --- a/advisories/unreviewed/2024/03/GHSA-3427-99jp-r4g2/GHSA-3427-99jp-r4g2.json +++ b/advisories/unreviewed/2024/03/GHSA-3427-99jp-r4g2/GHSA-3427-99jp-r4g2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-4jrj-86wm-m8wr/GHSA-4jrj-86wm-m8wr.json b/advisories/unreviewed/2024/03/GHSA-4jrj-86wm-m8wr/GHSA-4jrj-86wm-m8wr.json index 9a750a42634..ee116433422 100644 --- a/advisories/unreviewed/2024/03/GHSA-4jrj-86wm-m8wr/GHSA-4jrj-86wm-m8wr.json +++ b/advisories/unreviewed/2024/03/GHSA-4jrj-86wm-m8wr/GHSA-4jrj-86wm-m8wr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-4p27-6j8h-cjhw/GHSA-4p27-6j8h-cjhw.json b/advisories/unreviewed/2024/03/GHSA-4p27-6j8h-cjhw/GHSA-4p27-6j8h-cjhw.json index b2cd0526fc3..350a2f86457 100644 --- a/advisories/unreviewed/2024/03/GHSA-4p27-6j8h-cjhw/GHSA-4p27-6j8h-cjhw.json +++ b/advisories/unreviewed/2024/03/GHSA-4p27-6j8h-cjhw/GHSA-4p27-6j8h-cjhw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-5r5j-mwfc-hgxh/GHSA-5r5j-mwfc-hgxh.json b/advisories/unreviewed/2024/03/GHSA-5r5j-mwfc-hgxh/GHSA-5r5j-mwfc-hgxh.json index 01ee460a0ca..e4d5030237a 100644 --- a/advisories/unreviewed/2024/03/GHSA-5r5j-mwfc-hgxh/GHSA-5r5j-mwfc-hgxh.json +++ b/advisories/unreviewed/2024/03/GHSA-5r5j-mwfc-hgxh/GHSA-5r5j-mwfc-hgxh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-6f5r-w59m-9jm4/GHSA-6f5r-w59m-9jm4.json b/advisories/unreviewed/2024/03/GHSA-6f5r-w59m-9jm4/GHSA-6f5r-w59m-9jm4.json index 0840a50af5d..875316badfb 100644 --- a/advisories/unreviewed/2024/03/GHSA-6f5r-w59m-9jm4/GHSA-6f5r-w59m-9jm4.json +++ b/advisories/unreviewed/2024/03/GHSA-6f5r-w59m-9jm4/GHSA-6f5r-w59m-9jm4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-76j8-6c8j-572v/GHSA-76j8-6c8j-572v.json b/advisories/unreviewed/2024/03/GHSA-76j8-6c8j-572v/GHSA-76j8-6c8j-572v.json index c4146307df4..3840e84ae9c 100644 --- a/advisories/unreviewed/2024/03/GHSA-76j8-6c8j-572v/GHSA-76j8-6c8j-572v.json +++ b/advisories/unreviewed/2024/03/GHSA-76j8-6c8j-572v/GHSA-76j8-6c8j-572v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-82j9-mv5q-rfv9/GHSA-82j9-mv5q-rfv9.json b/advisories/unreviewed/2024/03/GHSA-82j9-mv5q-rfv9/GHSA-82j9-mv5q-rfv9.json index 77ef4cbb80d..61acafeab51 100644 --- a/advisories/unreviewed/2024/03/GHSA-82j9-mv5q-rfv9/GHSA-82j9-mv5q-rfv9.json +++ b/advisories/unreviewed/2024/03/GHSA-82j9-mv5q-rfv9/GHSA-82j9-mv5q-rfv9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-883r-qq2g-w5xj/GHSA-883r-qq2g-w5xj.json b/advisories/unreviewed/2024/03/GHSA-883r-qq2g-w5xj/GHSA-883r-qq2g-w5xj.json index afab9dd6ea6..e7d13d6ca8e 100644 --- a/advisories/unreviewed/2024/03/GHSA-883r-qq2g-w5xj/GHSA-883r-qq2g-w5xj.json +++ b/advisories/unreviewed/2024/03/GHSA-883r-qq2g-w5xj/GHSA-883r-qq2g-w5xj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-8vcm-r896-9gpj/GHSA-8vcm-r896-9gpj.json b/advisories/unreviewed/2024/03/GHSA-8vcm-r896-9gpj/GHSA-8vcm-r896-9gpj.json index 38f34316d48..21da94c0759 100644 --- a/advisories/unreviewed/2024/03/GHSA-8vcm-r896-9gpj/GHSA-8vcm-r896-9gpj.json +++ b/advisories/unreviewed/2024/03/GHSA-8vcm-r896-9gpj/GHSA-8vcm-r896-9gpj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-94h3-qpxm-r2mp/GHSA-94h3-qpxm-r2mp.json b/advisories/unreviewed/2024/03/GHSA-94h3-qpxm-r2mp/GHSA-94h3-qpxm-r2mp.json index 8cbebb802e8..3868bc0e5c6 100644 --- a/advisories/unreviewed/2024/03/GHSA-94h3-qpxm-r2mp/GHSA-94h3-qpxm-r2mp.json +++ b/advisories/unreviewed/2024/03/GHSA-94h3-qpxm-r2mp/GHSA-94h3-qpxm-r2mp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-cx25-cpw4-c882/GHSA-cx25-cpw4-c882.json b/advisories/unreviewed/2024/03/GHSA-cx25-cpw4-c882/GHSA-cx25-cpw4-c882.json index 9e5e31c01ee..0560c0a0ca0 100644 --- a/advisories/unreviewed/2024/03/GHSA-cx25-cpw4-c882/GHSA-cx25-cpw4-c882.json +++ b/advisories/unreviewed/2024/03/GHSA-cx25-cpw4-c882/GHSA-cx25-cpw4-c882.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-gmhh-c94r-5hfq/GHSA-gmhh-c94r-5hfq.json b/advisories/unreviewed/2024/03/GHSA-gmhh-c94r-5hfq/GHSA-gmhh-c94r-5hfq.json index 3876bf32cff..924bc6d87b2 100644 --- a/advisories/unreviewed/2024/03/GHSA-gmhh-c94r-5hfq/GHSA-gmhh-c94r-5hfq.json +++ b/advisories/unreviewed/2024/03/GHSA-gmhh-c94r-5hfq/GHSA-gmhh-c94r-5hfq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-j7wf-mfp9-jf55/GHSA-j7wf-mfp9-jf55.json b/advisories/unreviewed/2024/03/GHSA-j7wf-mfp9-jf55/GHSA-j7wf-mfp9-jf55.json index fd3ecf13222..0aeb84df68d 100644 --- a/advisories/unreviewed/2024/03/GHSA-j7wf-mfp9-jf55/GHSA-j7wf-mfp9-jf55.json +++ b/advisories/unreviewed/2024/03/GHSA-j7wf-mfp9-jf55/GHSA-j7wf-mfp9-jf55.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-ph92-w482-m4jj/GHSA-ph92-w482-m4jj.json b/advisories/unreviewed/2024/03/GHSA-ph92-w482-m4jj/GHSA-ph92-w482-m4jj.json index 205ba1b47f9..79319c22fae 100644 --- a/advisories/unreviewed/2024/03/GHSA-ph92-w482-m4jj/GHSA-ph92-w482-m4jj.json +++ b/advisories/unreviewed/2024/03/GHSA-ph92-w482-m4jj/GHSA-ph92-w482-m4jj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-pxv9-wjf4-mr7m/GHSA-pxv9-wjf4-mr7m.json b/advisories/unreviewed/2024/03/GHSA-pxv9-wjf4-mr7m/GHSA-pxv9-wjf4-mr7m.json index 2c7f5b59597..664ac0b05ce 100644 --- a/advisories/unreviewed/2024/03/GHSA-pxv9-wjf4-mr7m/GHSA-pxv9-wjf4-mr7m.json +++ b/advisories/unreviewed/2024/03/GHSA-pxv9-wjf4-mr7m/GHSA-pxv9-wjf4-mr7m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-qcf9-x527-mw6v/GHSA-qcf9-x527-mw6v.json b/advisories/unreviewed/2024/03/GHSA-qcf9-x527-mw6v/GHSA-qcf9-x527-mw6v.json index 31038623764..d403e0ba798 100644 --- a/advisories/unreviewed/2024/03/GHSA-qcf9-x527-mw6v/GHSA-qcf9-x527-mw6v.json +++ b/advisories/unreviewed/2024/03/GHSA-qcf9-x527-mw6v/GHSA-qcf9-x527-mw6v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-r4vh-7vvv-pvqr/GHSA-r4vh-7vvv-pvqr.json b/advisories/unreviewed/2024/03/GHSA-r4vh-7vvv-pvqr/GHSA-r4vh-7vvv-pvqr.json index 4d87b186b5e..0c365531806 100644 --- a/advisories/unreviewed/2024/03/GHSA-r4vh-7vvv-pvqr/GHSA-r4vh-7vvv-pvqr.json +++ b/advisories/unreviewed/2024/03/GHSA-r4vh-7vvv-pvqr/GHSA-r4vh-7vvv-pvqr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-vp94-mx6w-4h86/GHSA-vp94-mx6w-4h86.json b/advisories/unreviewed/2024/03/GHSA-vp94-mx6w-4h86/GHSA-vp94-mx6w-4h86.json index 3f3cf5799fb..ebd8a7f06f0 100644 --- a/advisories/unreviewed/2024/03/GHSA-vp94-mx6w-4h86/GHSA-vp94-mx6w-4h86.json +++ b/advisories/unreviewed/2024/03/GHSA-vp94-mx6w-4h86/GHSA-vp94-mx6w-4h86.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-wgrh-qrr7-qq96/GHSA-wgrh-qrr7-qq96.json b/advisories/unreviewed/2024/03/GHSA-wgrh-qrr7-qq96/GHSA-wgrh-qrr7-qq96.json index 6f2883703db..0adbb1d33b4 100644 --- a/advisories/unreviewed/2024/03/GHSA-wgrh-qrr7-qq96/GHSA-wgrh-qrr7-qq96.json +++ b/advisories/unreviewed/2024/03/GHSA-wgrh-qrr7-qq96/GHSA-wgrh-qrr7-qq96.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-3xmr-5wwh-fr8m/GHSA-3xmr-5wwh-fr8m.json b/advisories/unreviewed/2024/05/GHSA-3xmr-5wwh-fr8m/GHSA-3xmr-5wwh-fr8m.json index a1f46ca1cb1..c6225aa441a 100644 --- a/advisories/unreviewed/2024/05/GHSA-3xmr-5wwh-fr8m/GHSA-3xmr-5wwh-fr8m.json +++ b/advisories/unreviewed/2024/05/GHSA-3xmr-5wwh-fr8m/GHSA-3xmr-5wwh-fr8m.json @@ -7,12 +7,8 @@ "CVE-2024-27818" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An attacker may be able to cause unexpected app termination or arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xvcj-qw55-xx42/GHSA-xvcj-qw55-xx42.json b/advisories/unreviewed/2024/05/GHSA-xvcj-qw55-xx42/GHSA-xvcj-qw55-xx42.json index c1aff922068..322ce73cf38 100644 --- a/advisories/unreviewed/2024/05/GHSA-xvcj-qw55-xx42/GHSA-xvcj-qw55-xx42.json +++ b/advisories/unreviewed/2024/05/GHSA-xvcj-qw55-xx42/GHSA-xvcj-qw55-xx42.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "WEB", diff --git a/advisories/unreviewed/2024/06/GHSA-23gf-62w7-q77v/GHSA-23gf-62w7-q77v.json b/advisories/unreviewed/2024/06/GHSA-23gf-62w7-q77v/GHSA-23gf-62w7-q77v.json index 2c74678feca..c52f0f8804f 100644 --- a/advisories/unreviewed/2024/06/GHSA-23gf-62w7-q77v/GHSA-23gf-62w7-q77v.json +++ b/advisories/unreviewed/2024/06/GHSA-23gf-62w7-q77v/GHSA-23gf-62w7-q77v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-27r3-85x4-pfqv/GHSA-27r3-85x4-pfqv.json b/advisories/unreviewed/2024/06/GHSA-27r3-85x4-pfqv/GHSA-27r3-85x4-pfqv.json index 12906e53a5b..cc0be67b313 100644 --- a/advisories/unreviewed/2024/06/GHSA-27r3-85x4-pfqv/GHSA-27r3-85x4-pfqv.json +++ b/advisories/unreviewed/2024/06/GHSA-27r3-85x4-pfqv/GHSA-27r3-85x4-pfqv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-28hg-rww5-ghhq/GHSA-28hg-rww5-ghhq.json b/advisories/unreviewed/2024/06/GHSA-28hg-rww5-ghhq/GHSA-28hg-rww5-ghhq.json index 43762562900..a4090998a63 100644 --- a/advisories/unreviewed/2024/06/GHSA-28hg-rww5-ghhq/GHSA-28hg-rww5-ghhq.json +++ b/advisories/unreviewed/2024/06/GHSA-28hg-rww5-ghhq/GHSA-28hg-rww5-ghhq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-2r3h-3xfx-74q9/GHSA-2r3h-3xfx-74q9.json b/advisories/unreviewed/2024/06/GHSA-2r3h-3xfx-74q9/GHSA-2r3h-3xfx-74q9.json index f70390e6c5a..2a421406479 100644 --- a/advisories/unreviewed/2024/06/GHSA-2r3h-3xfx-74q9/GHSA-2r3h-3xfx-74q9.json +++ b/advisories/unreviewed/2024/06/GHSA-2r3h-3xfx-74q9/GHSA-2r3h-3xfx-74q9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-2vp4-2rgc-wf9w/GHSA-2vp4-2rgc-wf9w.json b/advisories/unreviewed/2024/06/GHSA-2vp4-2rgc-wf9w/GHSA-2vp4-2rgc-wf9w.json index 97609ac9310..e4f2f576b92 100644 --- a/advisories/unreviewed/2024/06/GHSA-2vp4-2rgc-wf9w/GHSA-2vp4-2rgc-wf9w.json +++ b/advisories/unreviewed/2024/06/GHSA-2vp4-2rgc-wf9w/GHSA-2vp4-2rgc-wf9w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-2w43-q3mm-rrgh/GHSA-2w43-q3mm-rrgh.json b/advisories/unreviewed/2024/06/GHSA-2w43-q3mm-rrgh/GHSA-2w43-q3mm-rrgh.json index 8a38c47f1e8..e5332450b8d 100644 --- a/advisories/unreviewed/2024/06/GHSA-2w43-q3mm-rrgh/GHSA-2w43-q3mm-rrgh.json +++ b/advisories/unreviewed/2024/06/GHSA-2w43-q3mm-rrgh/GHSA-2w43-q3mm-rrgh.json @@ -7,12 +7,8 @@ "CVE-2024-4155" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-34vg-2vxp-rvgw/GHSA-34vg-2vxp-rvgw.json b/advisories/unreviewed/2024/06/GHSA-34vg-2vxp-rvgw/GHSA-34vg-2vxp-rvgw.json index 73ae3837b3f..6388568963e 100644 --- a/advisories/unreviewed/2024/06/GHSA-34vg-2vxp-rvgw/GHSA-34vg-2vxp-rvgw.json +++ b/advisories/unreviewed/2024/06/GHSA-34vg-2vxp-rvgw/GHSA-34vg-2vxp-rvgw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-3794-gcgw-37cm/GHSA-3794-gcgw-37cm.json b/advisories/unreviewed/2024/06/GHSA-3794-gcgw-37cm/GHSA-3794-gcgw-37cm.json index f302f50e713..a1c93310c97 100644 --- a/advisories/unreviewed/2024/06/GHSA-3794-gcgw-37cm/GHSA-3794-gcgw-37cm.json +++ b/advisories/unreviewed/2024/06/GHSA-3794-gcgw-37cm/GHSA-3794-gcgw-37cm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-3c4q-vvc6-w82q/GHSA-3c4q-vvc6-w82q.json b/advisories/unreviewed/2024/06/GHSA-3c4q-vvc6-w82q/GHSA-3c4q-vvc6-w82q.json index ff6dfeba863..da113994fb6 100644 --- a/advisories/unreviewed/2024/06/GHSA-3c4q-vvc6-w82q/GHSA-3c4q-vvc6-w82q.json +++ b/advisories/unreviewed/2024/06/GHSA-3c4q-vvc6-w82q/GHSA-3c4q-vvc6-w82q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-3w78-v9jq-vw22/GHSA-3w78-v9jq-vw22.json b/advisories/unreviewed/2024/06/GHSA-3w78-v9jq-vw22/GHSA-3w78-v9jq-vw22.json index 8f2d0d9e471..84bdeb67bbd 100644 --- a/advisories/unreviewed/2024/06/GHSA-3w78-v9jq-vw22/GHSA-3w78-v9jq-vw22.json +++ b/advisories/unreviewed/2024/06/GHSA-3w78-v9jq-vw22/GHSA-3w78-v9jq-vw22.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-3w89-hgwc-85v8/GHSA-3w89-hgwc-85v8.json b/advisories/unreviewed/2024/06/GHSA-3w89-hgwc-85v8/GHSA-3w89-hgwc-85v8.json index 690d25b7cd9..da1c5d7efcb 100644 --- a/advisories/unreviewed/2024/06/GHSA-3w89-hgwc-85v8/GHSA-3w89-hgwc-85v8.json +++ b/advisories/unreviewed/2024/06/GHSA-3w89-hgwc-85v8/GHSA-3w89-hgwc-85v8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-42c4-g7jf-379h/GHSA-42c4-g7jf-379h.json b/advisories/unreviewed/2024/06/GHSA-42c4-g7jf-379h/GHSA-42c4-g7jf-379h.json index 34dee6a2a81..128cbe5b05b 100644 --- a/advisories/unreviewed/2024/06/GHSA-42c4-g7jf-379h/GHSA-42c4-g7jf-379h.json +++ b/advisories/unreviewed/2024/06/GHSA-42c4-g7jf-379h/GHSA-42c4-g7jf-379h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-43r8-23m5-329f/GHSA-43r8-23m5-329f.json b/advisories/unreviewed/2024/06/GHSA-43r8-23m5-329f/GHSA-43r8-23m5-329f.json index 567b016b685..9475fc495b6 100644 --- a/advisories/unreviewed/2024/06/GHSA-43r8-23m5-329f/GHSA-43r8-23m5-329f.json +++ b/advisories/unreviewed/2024/06/GHSA-43r8-23m5-329f/GHSA-43r8-23m5-329f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-47g9-gpgw-3pq5/GHSA-47g9-gpgw-3pq5.json b/advisories/unreviewed/2024/06/GHSA-47g9-gpgw-3pq5/GHSA-47g9-gpgw-3pq5.json index 61e5a1d2036..9b1f309957a 100644 --- a/advisories/unreviewed/2024/06/GHSA-47g9-gpgw-3pq5/GHSA-47g9-gpgw-3pq5.json +++ b/advisories/unreviewed/2024/06/GHSA-47g9-gpgw-3pq5/GHSA-47g9-gpgw-3pq5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-497q-xhqw-fw3m/GHSA-497q-xhqw-fw3m.json b/advisories/unreviewed/2024/06/GHSA-497q-xhqw-fw3m/GHSA-497q-xhqw-fw3m.json index af260ce7e8b..8adbe149ae6 100644 --- a/advisories/unreviewed/2024/06/GHSA-497q-xhqw-fw3m/GHSA-497q-xhqw-fw3m.json +++ b/advisories/unreviewed/2024/06/GHSA-497q-xhqw-fw3m/GHSA-497q-xhqw-fw3m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-4cv3-4q3c-54v6/GHSA-4cv3-4q3c-54v6.json b/advisories/unreviewed/2024/06/GHSA-4cv3-4q3c-54v6/GHSA-4cv3-4q3c-54v6.json index dbe02f906b6..cdae9037bf0 100644 --- a/advisories/unreviewed/2024/06/GHSA-4cv3-4q3c-54v6/GHSA-4cv3-4q3c-54v6.json +++ b/advisories/unreviewed/2024/06/GHSA-4cv3-4q3c-54v6/GHSA-4cv3-4q3c-54v6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-4cvv-4v6h-5hq7/GHSA-4cvv-4v6h-5hq7.json b/advisories/unreviewed/2024/06/GHSA-4cvv-4v6h-5hq7/GHSA-4cvv-4v6h-5hq7.json index 44f580927c2..de68855e730 100644 --- a/advisories/unreviewed/2024/06/GHSA-4cvv-4v6h-5hq7/GHSA-4cvv-4v6h-5hq7.json +++ b/advisories/unreviewed/2024/06/GHSA-4cvv-4v6h-5hq7/GHSA-4cvv-4v6h-5hq7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-4hgh-53h4-32cw/GHSA-4hgh-53h4-32cw.json b/advisories/unreviewed/2024/06/GHSA-4hgh-53h4-32cw/GHSA-4hgh-53h4-32cw.json index e9ca8fc0809..eb1f26f00ff 100644 --- a/advisories/unreviewed/2024/06/GHSA-4hgh-53h4-32cw/GHSA-4hgh-53h4-32cw.json +++ b/advisories/unreviewed/2024/06/GHSA-4hgh-53h4-32cw/GHSA-4hgh-53h4-32cw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-4jhp-wp6w-jm5x/GHSA-4jhp-wp6w-jm5x.json b/advisories/unreviewed/2024/06/GHSA-4jhp-wp6w-jm5x/GHSA-4jhp-wp6w-jm5x.json index b0c28be6b80..4a9d7374795 100644 --- a/advisories/unreviewed/2024/06/GHSA-4jhp-wp6w-jm5x/GHSA-4jhp-wp6w-jm5x.json +++ b/advisories/unreviewed/2024/06/GHSA-4jhp-wp6w-jm5x/GHSA-4jhp-wp6w-jm5x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-4p3j-h7w5-q76v/GHSA-4p3j-h7w5-q76v.json b/advisories/unreviewed/2024/06/GHSA-4p3j-h7w5-q76v/GHSA-4p3j-h7w5-q76v.json index d9cb19f3ed3..56acf9b21cf 100644 --- a/advisories/unreviewed/2024/06/GHSA-4p3j-h7w5-q76v/GHSA-4p3j-h7w5-q76v.json +++ b/advisories/unreviewed/2024/06/GHSA-4p3j-h7w5-q76v/GHSA-4p3j-h7w5-q76v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-4pgv-p58j-ghpx/GHSA-4pgv-p58j-ghpx.json b/advisories/unreviewed/2024/06/GHSA-4pgv-p58j-ghpx/GHSA-4pgv-p58j-ghpx.json index ab182c7108a..e12132aee1b 100644 --- a/advisories/unreviewed/2024/06/GHSA-4pgv-p58j-ghpx/GHSA-4pgv-p58j-ghpx.json +++ b/advisories/unreviewed/2024/06/GHSA-4pgv-p58j-ghpx/GHSA-4pgv-p58j-ghpx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-529f-v746-9vhc/GHSA-529f-v746-9vhc.json b/advisories/unreviewed/2024/06/GHSA-529f-v746-9vhc/GHSA-529f-v746-9vhc.json index a8f60c40a61..d98fbcf456b 100644 --- a/advisories/unreviewed/2024/06/GHSA-529f-v746-9vhc/GHSA-529f-v746-9vhc.json +++ b/advisories/unreviewed/2024/06/GHSA-529f-v746-9vhc/GHSA-529f-v746-9vhc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-52c2-xvqv-6rr4/GHSA-52c2-xvqv-6rr4.json b/advisories/unreviewed/2024/06/GHSA-52c2-xvqv-6rr4/GHSA-52c2-xvqv-6rr4.json index fc01f4b9135..55e5a750fbc 100644 --- a/advisories/unreviewed/2024/06/GHSA-52c2-xvqv-6rr4/GHSA-52c2-xvqv-6rr4.json +++ b/advisories/unreviewed/2024/06/GHSA-52c2-xvqv-6rr4/GHSA-52c2-xvqv-6rr4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-5527-jp3f-385g/GHSA-5527-jp3f-385g.json b/advisories/unreviewed/2024/06/GHSA-5527-jp3f-385g/GHSA-5527-jp3f-385g.json index a3ee2112d69..b8b7d6f4bae 100644 --- a/advisories/unreviewed/2024/06/GHSA-5527-jp3f-385g/GHSA-5527-jp3f-385g.json +++ b/advisories/unreviewed/2024/06/GHSA-5527-jp3f-385g/GHSA-5527-jp3f-385g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-559x-574p-gxh6/GHSA-559x-574p-gxh6.json b/advisories/unreviewed/2024/06/GHSA-559x-574p-gxh6/GHSA-559x-574p-gxh6.json index 5ca61b43fe9..e33c07de89e 100644 --- a/advisories/unreviewed/2024/06/GHSA-559x-574p-gxh6/GHSA-559x-574p-gxh6.json +++ b/advisories/unreviewed/2024/06/GHSA-559x-574p-gxh6/GHSA-559x-574p-gxh6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-564f-4f44-r6r6/GHSA-564f-4f44-r6r6.json b/advisories/unreviewed/2024/06/GHSA-564f-4f44-r6r6/GHSA-564f-4f44-r6r6.json index 0676c73428a..91ee9c49e99 100644 --- a/advisories/unreviewed/2024/06/GHSA-564f-4f44-r6r6/GHSA-564f-4f44-r6r6.json +++ b/advisories/unreviewed/2024/06/GHSA-564f-4f44-r6r6/GHSA-564f-4f44-r6r6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-57h7-78j2-gvm6/GHSA-57h7-78j2-gvm6.json b/advisories/unreviewed/2024/06/GHSA-57h7-78j2-gvm6/GHSA-57h7-78j2-gvm6.json index 7f28566fea8..9f8d6aeee19 100644 --- a/advisories/unreviewed/2024/06/GHSA-57h7-78j2-gvm6/GHSA-57h7-78j2-gvm6.json +++ b/advisories/unreviewed/2024/06/GHSA-57h7-78j2-gvm6/GHSA-57h7-78j2-gvm6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-58cj-373v-pc84/GHSA-58cj-373v-pc84.json b/advisories/unreviewed/2024/06/GHSA-58cj-373v-pc84/GHSA-58cj-373v-pc84.json index d68e5183e13..01cb5ccd8ee 100644 --- a/advisories/unreviewed/2024/06/GHSA-58cj-373v-pc84/GHSA-58cj-373v-pc84.json +++ b/advisories/unreviewed/2024/06/GHSA-58cj-373v-pc84/GHSA-58cj-373v-pc84.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-5cg4-pm73-p483/GHSA-5cg4-pm73-p483.json b/advisories/unreviewed/2024/06/GHSA-5cg4-pm73-p483/GHSA-5cg4-pm73-p483.json index 29643426077..0bacde35d99 100644 --- a/advisories/unreviewed/2024/06/GHSA-5cg4-pm73-p483/GHSA-5cg4-pm73-p483.json +++ b/advisories/unreviewed/2024/06/GHSA-5cg4-pm73-p483/GHSA-5cg4-pm73-p483.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-5cwx-g8mg-7v9c/GHSA-5cwx-g8mg-7v9c.json b/advisories/unreviewed/2024/06/GHSA-5cwx-g8mg-7v9c/GHSA-5cwx-g8mg-7v9c.json index 5965d08f78b..03d1cfbc82f 100644 --- a/advisories/unreviewed/2024/06/GHSA-5cwx-g8mg-7v9c/GHSA-5cwx-g8mg-7v9c.json +++ b/advisories/unreviewed/2024/06/GHSA-5cwx-g8mg-7v9c/GHSA-5cwx-g8mg-7v9c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-5h8m-gw93-f3w6/GHSA-5h8m-gw93-f3w6.json b/advisories/unreviewed/2024/06/GHSA-5h8m-gw93-f3w6/GHSA-5h8m-gw93-f3w6.json index 2d8ef2f82aa..b44d29d7070 100644 --- a/advisories/unreviewed/2024/06/GHSA-5h8m-gw93-f3w6/GHSA-5h8m-gw93-f3w6.json +++ b/advisories/unreviewed/2024/06/GHSA-5h8m-gw93-f3w6/GHSA-5h8m-gw93-f3w6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-5v9v-hvfp-8rmv/GHSA-5v9v-hvfp-8rmv.json b/advisories/unreviewed/2024/06/GHSA-5v9v-hvfp-8rmv/GHSA-5v9v-hvfp-8rmv.json index 6d78259a08f..6523e15be6a 100644 --- a/advisories/unreviewed/2024/06/GHSA-5v9v-hvfp-8rmv/GHSA-5v9v-hvfp-8rmv.json +++ b/advisories/unreviewed/2024/06/GHSA-5v9v-hvfp-8rmv/GHSA-5v9v-hvfp-8rmv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-5vw8-xp5w-956h/GHSA-5vw8-xp5w-956h.json b/advisories/unreviewed/2024/06/GHSA-5vw8-xp5w-956h/GHSA-5vw8-xp5w-956h.json index 03291f079e9..8e1ca8dfbb0 100644 --- a/advisories/unreviewed/2024/06/GHSA-5vw8-xp5w-956h/GHSA-5vw8-xp5w-956h.json +++ b/advisories/unreviewed/2024/06/GHSA-5vw8-xp5w-956h/GHSA-5vw8-xp5w-956h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-62pf-2c82-x5xc/GHSA-62pf-2c82-x5xc.json b/advisories/unreviewed/2024/06/GHSA-62pf-2c82-x5xc/GHSA-62pf-2c82-x5xc.json index 506de792c46..45fac93f98e 100644 --- a/advisories/unreviewed/2024/06/GHSA-62pf-2c82-x5xc/GHSA-62pf-2c82-x5xc.json +++ b/advisories/unreviewed/2024/06/GHSA-62pf-2c82-x5xc/GHSA-62pf-2c82-x5xc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-62pq-x59w-p9v7/GHSA-62pq-x59w-p9v7.json b/advisories/unreviewed/2024/06/GHSA-62pq-x59w-p9v7/GHSA-62pq-x59w-p9v7.json index bebfcccae7c..bf3a8e28df3 100644 --- a/advisories/unreviewed/2024/06/GHSA-62pq-x59w-p9v7/GHSA-62pq-x59w-p9v7.json +++ b/advisories/unreviewed/2024/06/GHSA-62pq-x59w-p9v7/GHSA-62pq-x59w-p9v7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-63mj-hr86-9cpw/GHSA-63mj-hr86-9cpw.json b/advisories/unreviewed/2024/06/GHSA-63mj-hr86-9cpw/GHSA-63mj-hr86-9cpw.json index a942da13e61..f0aee94e06e 100644 --- a/advisories/unreviewed/2024/06/GHSA-63mj-hr86-9cpw/GHSA-63mj-hr86-9cpw.json +++ b/advisories/unreviewed/2024/06/GHSA-63mj-hr86-9cpw/GHSA-63mj-hr86-9cpw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-67jv-rwrr-72fv/GHSA-67jv-rwrr-72fv.json b/advisories/unreviewed/2024/06/GHSA-67jv-rwrr-72fv/GHSA-67jv-rwrr-72fv.json index 173c1b54220..3067ad6b0d4 100644 --- a/advisories/unreviewed/2024/06/GHSA-67jv-rwrr-72fv/GHSA-67jv-rwrr-72fv.json +++ b/advisories/unreviewed/2024/06/GHSA-67jv-rwrr-72fv/GHSA-67jv-rwrr-72fv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-6889-wccr-m7x3/GHSA-6889-wccr-m7x3.json b/advisories/unreviewed/2024/06/GHSA-6889-wccr-m7x3/GHSA-6889-wccr-m7x3.json index f9b77d613de..c66616f141b 100644 --- a/advisories/unreviewed/2024/06/GHSA-6889-wccr-m7x3/GHSA-6889-wccr-m7x3.json +++ b/advisories/unreviewed/2024/06/GHSA-6889-wccr-m7x3/GHSA-6889-wccr-m7x3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-6g9j-jj95-v2qh/GHSA-6g9j-jj95-v2qh.json b/advisories/unreviewed/2024/06/GHSA-6g9j-jj95-v2qh/GHSA-6g9j-jj95-v2qh.json index 677936d6974..95373e03342 100644 --- a/advisories/unreviewed/2024/06/GHSA-6g9j-jj95-v2qh/GHSA-6g9j-jj95-v2qh.json +++ b/advisories/unreviewed/2024/06/GHSA-6g9j-jj95-v2qh/GHSA-6g9j-jj95-v2qh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-6h34-v4g3-cvj6/GHSA-6h34-v4g3-cvj6.json b/advisories/unreviewed/2024/06/GHSA-6h34-v4g3-cvj6/GHSA-6h34-v4g3-cvj6.json index 5c54de16bbd..e38ee29ede7 100644 --- a/advisories/unreviewed/2024/06/GHSA-6h34-v4g3-cvj6/GHSA-6h34-v4g3-cvj6.json +++ b/advisories/unreviewed/2024/06/GHSA-6h34-v4g3-cvj6/GHSA-6h34-v4g3-cvj6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-6p2f-8x9g-2qq8/GHSA-6p2f-8x9g-2qq8.json b/advisories/unreviewed/2024/06/GHSA-6p2f-8x9g-2qq8/GHSA-6p2f-8x9g-2qq8.json index 7493123f497..4df01fbb076 100644 --- a/advisories/unreviewed/2024/06/GHSA-6p2f-8x9g-2qq8/GHSA-6p2f-8x9g-2qq8.json +++ b/advisories/unreviewed/2024/06/GHSA-6p2f-8x9g-2qq8/GHSA-6p2f-8x9g-2qq8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-6pm8-gh62-gqgq/GHSA-6pm8-gh62-gqgq.json b/advisories/unreviewed/2024/06/GHSA-6pm8-gh62-gqgq/GHSA-6pm8-gh62-gqgq.json index d90ab85ada3..008f061cbf2 100644 --- a/advisories/unreviewed/2024/06/GHSA-6pm8-gh62-gqgq/GHSA-6pm8-gh62-gqgq.json +++ b/advisories/unreviewed/2024/06/GHSA-6pm8-gh62-gqgq/GHSA-6pm8-gh62-gqgq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-6qmc-84fw-65c9/GHSA-6qmc-84fw-65c9.json b/advisories/unreviewed/2024/06/GHSA-6qmc-84fw-65c9/GHSA-6qmc-84fw-65c9.json index 52089737334..06f583b3746 100644 --- a/advisories/unreviewed/2024/06/GHSA-6qmc-84fw-65c9/GHSA-6qmc-84fw-65c9.json +++ b/advisories/unreviewed/2024/06/GHSA-6qmc-84fw-65c9/GHSA-6qmc-84fw-65c9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-7223-6cmw-xwrj/GHSA-7223-6cmw-xwrj.json b/advisories/unreviewed/2024/06/GHSA-7223-6cmw-xwrj/GHSA-7223-6cmw-xwrj.json index e16d5975785..9123f27d3df 100644 --- a/advisories/unreviewed/2024/06/GHSA-7223-6cmw-xwrj/GHSA-7223-6cmw-xwrj.json +++ b/advisories/unreviewed/2024/06/GHSA-7223-6cmw-xwrj/GHSA-7223-6cmw-xwrj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-72f2-72h7-2m75/GHSA-72f2-72h7-2m75.json b/advisories/unreviewed/2024/06/GHSA-72f2-72h7-2m75/GHSA-72f2-72h7-2m75.json index e10c9f606a7..891c964f92c 100644 --- a/advisories/unreviewed/2024/06/GHSA-72f2-72h7-2m75/GHSA-72f2-72h7-2m75.json +++ b/advisories/unreviewed/2024/06/GHSA-72f2-72h7-2m75/GHSA-72f2-72h7-2m75.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-74g2-v5gc-hj7f/GHSA-74g2-v5gc-hj7f.json b/advisories/unreviewed/2024/06/GHSA-74g2-v5gc-hj7f/GHSA-74g2-v5gc-hj7f.json index fb34cc4d6cb..696463017f2 100644 --- a/advisories/unreviewed/2024/06/GHSA-74g2-v5gc-hj7f/GHSA-74g2-v5gc-hj7f.json +++ b/advisories/unreviewed/2024/06/GHSA-74g2-v5gc-hj7f/GHSA-74g2-v5gc-hj7f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-79m6-3vj5-mrf7/GHSA-79m6-3vj5-mrf7.json b/advisories/unreviewed/2024/06/GHSA-79m6-3vj5-mrf7/GHSA-79m6-3vj5-mrf7.json index 6ddf1097a51..fd409166058 100644 --- a/advisories/unreviewed/2024/06/GHSA-79m6-3vj5-mrf7/GHSA-79m6-3vj5-mrf7.json +++ b/advisories/unreviewed/2024/06/GHSA-79m6-3vj5-mrf7/GHSA-79m6-3vj5-mrf7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-7crr-rw95-x6c5/GHSA-7crr-rw95-x6c5.json b/advisories/unreviewed/2024/06/GHSA-7crr-rw95-x6c5/GHSA-7crr-rw95-x6c5.json index a98f51dae5a..d92a03af2bb 100644 --- a/advisories/unreviewed/2024/06/GHSA-7crr-rw95-x6c5/GHSA-7crr-rw95-x6c5.json +++ b/advisories/unreviewed/2024/06/GHSA-7crr-rw95-x6c5/GHSA-7crr-rw95-x6c5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-7fj9-wq6r-m3rf/GHSA-7fj9-wq6r-m3rf.json b/advisories/unreviewed/2024/06/GHSA-7fj9-wq6r-m3rf/GHSA-7fj9-wq6r-m3rf.json index 00e8d7485c2..c27118ed614 100644 --- a/advisories/unreviewed/2024/06/GHSA-7fj9-wq6r-m3rf/GHSA-7fj9-wq6r-m3rf.json +++ b/advisories/unreviewed/2024/06/GHSA-7fj9-wq6r-m3rf/GHSA-7fj9-wq6r-m3rf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-7rw2-4f63-2rgv/GHSA-7rw2-4f63-2rgv.json b/advisories/unreviewed/2024/06/GHSA-7rw2-4f63-2rgv/GHSA-7rw2-4f63-2rgv.json index 0fc00871a81..27cebfd93fd 100644 --- a/advisories/unreviewed/2024/06/GHSA-7rw2-4f63-2rgv/GHSA-7rw2-4f63-2rgv.json +++ b/advisories/unreviewed/2024/06/GHSA-7rw2-4f63-2rgv/GHSA-7rw2-4f63-2rgv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-7wvq-94hq-j88h/GHSA-7wvq-94hq-j88h.json b/advisories/unreviewed/2024/06/GHSA-7wvq-94hq-j88h/GHSA-7wvq-94hq-j88h.json index 68bba295ca8..4fba8963f0e 100644 --- a/advisories/unreviewed/2024/06/GHSA-7wvq-94hq-j88h/GHSA-7wvq-94hq-j88h.json +++ b/advisories/unreviewed/2024/06/GHSA-7wvq-94hq-j88h/GHSA-7wvq-94hq-j88h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-86xr-hhp2-92cj/GHSA-86xr-hhp2-92cj.json b/advisories/unreviewed/2024/06/GHSA-86xr-hhp2-92cj/GHSA-86xr-hhp2-92cj.json index 4270e138be1..a34c7fd9da9 100644 --- a/advisories/unreviewed/2024/06/GHSA-86xr-hhp2-92cj/GHSA-86xr-hhp2-92cj.json +++ b/advisories/unreviewed/2024/06/GHSA-86xr-hhp2-92cj/GHSA-86xr-hhp2-92cj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-89q4-gfxm-xg78/GHSA-89q4-gfxm-xg78.json b/advisories/unreviewed/2024/06/GHSA-89q4-gfxm-xg78/GHSA-89q4-gfxm-xg78.json index 59a5de74dec..f9b0e911391 100644 --- a/advisories/unreviewed/2024/06/GHSA-89q4-gfxm-xg78/GHSA-89q4-gfxm-xg78.json +++ b/advisories/unreviewed/2024/06/GHSA-89q4-gfxm-xg78/GHSA-89q4-gfxm-xg78.json @@ -7,12 +7,8 @@ "CVE-2024-2461" ], "details": "If exploited an attacker could traverse the file system to access \nfiles or directories that would otherwise be inaccessible", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-8frr-g94g-3xh7/GHSA-8frr-g94g-3xh7.json b/advisories/unreviewed/2024/06/GHSA-8frr-g94g-3xh7/GHSA-8frr-g94g-3xh7.json index 085e40445f7..04e285e37d9 100644 --- a/advisories/unreviewed/2024/06/GHSA-8frr-g94g-3xh7/GHSA-8frr-g94g-3xh7.json +++ b/advisories/unreviewed/2024/06/GHSA-8frr-g94g-3xh7/GHSA-8frr-g94g-3xh7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-8m9g-pfr8-r84c/GHSA-8m9g-pfr8-r84c.json b/advisories/unreviewed/2024/06/GHSA-8m9g-pfr8-r84c/GHSA-8m9g-pfr8-r84c.json index 29bd87ca0a3..d3255428087 100644 --- a/advisories/unreviewed/2024/06/GHSA-8m9g-pfr8-r84c/GHSA-8m9g-pfr8-r84c.json +++ b/advisories/unreviewed/2024/06/GHSA-8m9g-pfr8-r84c/GHSA-8m9g-pfr8-r84c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-8pcx-m7v6-p3gg/GHSA-8pcx-m7v6-p3gg.json b/advisories/unreviewed/2024/06/GHSA-8pcx-m7v6-p3gg/GHSA-8pcx-m7v6-p3gg.json index f4bd15802f6..b59ea1fcbfd 100644 --- a/advisories/unreviewed/2024/06/GHSA-8pcx-m7v6-p3gg/GHSA-8pcx-m7v6-p3gg.json +++ b/advisories/unreviewed/2024/06/GHSA-8pcx-m7v6-p3gg/GHSA-8pcx-m7v6-p3gg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-8rgr-7c79-w295/GHSA-8rgr-7c79-w295.json b/advisories/unreviewed/2024/06/GHSA-8rgr-7c79-w295/GHSA-8rgr-7c79-w295.json index 46cbc0970d9..c231a8c58d3 100644 --- a/advisories/unreviewed/2024/06/GHSA-8rgr-7c79-w295/GHSA-8rgr-7c79-w295.json +++ b/advisories/unreviewed/2024/06/GHSA-8rgr-7c79-w295/GHSA-8rgr-7c79-w295.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-8whg-5x3x-gjj9/GHSA-8whg-5x3x-gjj9.json b/advisories/unreviewed/2024/06/GHSA-8whg-5x3x-gjj9/GHSA-8whg-5x3x-gjj9.json index be296aa5317..f8a38b45ad3 100644 --- a/advisories/unreviewed/2024/06/GHSA-8whg-5x3x-gjj9/GHSA-8whg-5x3x-gjj9.json +++ b/advisories/unreviewed/2024/06/GHSA-8whg-5x3x-gjj9/GHSA-8whg-5x3x-gjj9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-8xv7-6vfw-wqrw/GHSA-8xv7-6vfw-wqrw.json b/advisories/unreviewed/2024/06/GHSA-8xv7-6vfw-wqrw/GHSA-8xv7-6vfw-wqrw.json index 27ce3c8f5f4..d020e506ae3 100644 --- a/advisories/unreviewed/2024/06/GHSA-8xv7-6vfw-wqrw/GHSA-8xv7-6vfw-wqrw.json +++ b/advisories/unreviewed/2024/06/GHSA-8xv7-6vfw-wqrw/GHSA-8xv7-6vfw-wqrw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-93h4-qrq6-q2vm/GHSA-93h4-qrq6-q2vm.json b/advisories/unreviewed/2024/06/GHSA-93h4-qrq6-q2vm/GHSA-93h4-qrq6-q2vm.json index 58d0c512964..770b5eca255 100644 --- a/advisories/unreviewed/2024/06/GHSA-93h4-qrq6-q2vm/GHSA-93h4-qrq6-q2vm.json +++ b/advisories/unreviewed/2024/06/GHSA-93h4-qrq6-q2vm/GHSA-93h4-qrq6-q2vm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-99gj-25m6-38xr/GHSA-99gj-25m6-38xr.json b/advisories/unreviewed/2024/06/GHSA-99gj-25m6-38xr/GHSA-99gj-25m6-38xr.json index e2b3c2e7a61..98146e0bc83 100644 --- a/advisories/unreviewed/2024/06/GHSA-99gj-25m6-38xr/GHSA-99gj-25m6-38xr.json +++ b/advisories/unreviewed/2024/06/GHSA-99gj-25m6-38xr/GHSA-99gj-25m6-38xr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-9cwp-4h4r-5573/GHSA-9cwp-4h4r-5573.json b/advisories/unreviewed/2024/06/GHSA-9cwp-4h4r-5573/GHSA-9cwp-4h4r-5573.json index dde9dc8cd4e..01dd84d9616 100644 --- a/advisories/unreviewed/2024/06/GHSA-9cwp-4h4r-5573/GHSA-9cwp-4h4r-5573.json +++ b/advisories/unreviewed/2024/06/GHSA-9cwp-4h4r-5573/GHSA-9cwp-4h4r-5573.json @@ -7,12 +7,8 @@ "CVE-2024-4387" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-9fqg-p2vg-mw8w/GHSA-9fqg-p2vg-mw8w.json b/advisories/unreviewed/2024/06/GHSA-9fqg-p2vg-mw8w/GHSA-9fqg-p2vg-mw8w.json index cd8f7ff5894..6fa66b175dc 100644 --- a/advisories/unreviewed/2024/06/GHSA-9fqg-p2vg-mw8w/GHSA-9fqg-p2vg-mw8w.json +++ b/advisories/unreviewed/2024/06/GHSA-9fqg-p2vg-mw8w/GHSA-9fqg-p2vg-mw8w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-9fr6-vrhc-9hmv/GHSA-9fr6-vrhc-9hmv.json b/advisories/unreviewed/2024/06/GHSA-9fr6-vrhc-9hmv/GHSA-9fr6-vrhc-9hmv.json index 5dc33361446..1d74b01e3c1 100644 --- a/advisories/unreviewed/2024/06/GHSA-9fr6-vrhc-9hmv/GHSA-9fr6-vrhc-9hmv.json +++ b/advisories/unreviewed/2024/06/GHSA-9fr6-vrhc-9hmv/GHSA-9fr6-vrhc-9hmv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-9h54-f8p4-357g/GHSA-9h54-f8p4-357g.json b/advisories/unreviewed/2024/06/GHSA-9h54-f8p4-357g/GHSA-9h54-f8p4-357g.json index a2e7482a11e..190461f2aba 100644 --- a/advisories/unreviewed/2024/06/GHSA-9h54-f8p4-357g/GHSA-9h54-f8p4-357g.json +++ b/advisories/unreviewed/2024/06/GHSA-9h54-f8p4-357g/GHSA-9h54-f8p4-357g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-9phr-94jp-gcrr/GHSA-9phr-94jp-gcrr.json b/advisories/unreviewed/2024/06/GHSA-9phr-94jp-gcrr/GHSA-9phr-94jp-gcrr.json index a9c2d153092..f57a86b5871 100644 --- a/advisories/unreviewed/2024/06/GHSA-9phr-94jp-gcrr/GHSA-9phr-94jp-gcrr.json +++ b/advisories/unreviewed/2024/06/GHSA-9phr-94jp-gcrr/GHSA-9phr-94jp-gcrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-c4w3-rhwj-fj85/GHSA-c4w3-rhwj-fj85.json b/advisories/unreviewed/2024/06/GHSA-c4w3-rhwj-fj85/GHSA-c4w3-rhwj-fj85.json index dd56ab50f9c..45b618d974b 100644 --- a/advisories/unreviewed/2024/06/GHSA-c4w3-rhwj-fj85/GHSA-c4w3-rhwj-fj85.json +++ b/advisories/unreviewed/2024/06/GHSA-c4w3-rhwj-fj85/GHSA-c4w3-rhwj-fj85.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-c6jw-39ph-m4hq/GHSA-c6jw-39ph-m4hq.json b/advisories/unreviewed/2024/06/GHSA-c6jw-39ph-m4hq/GHSA-c6jw-39ph-m4hq.json index 32ee5d92c7a..b3939be981c 100644 --- a/advisories/unreviewed/2024/06/GHSA-c6jw-39ph-m4hq/GHSA-c6jw-39ph-m4hq.json +++ b/advisories/unreviewed/2024/06/GHSA-c6jw-39ph-m4hq/GHSA-c6jw-39ph-m4hq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-c8cv-6hfh-6vj5/GHSA-c8cv-6hfh-6vj5.json b/advisories/unreviewed/2024/06/GHSA-c8cv-6hfh-6vj5/GHSA-c8cv-6hfh-6vj5.json index eac9667b2f7..1d687d658c0 100644 --- a/advisories/unreviewed/2024/06/GHSA-c8cv-6hfh-6vj5/GHSA-c8cv-6hfh-6vj5.json +++ b/advisories/unreviewed/2024/06/GHSA-c8cv-6hfh-6vj5/GHSA-c8cv-6hfh-6vj5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-c8mw-8525-7678/GHSA-c8mw-8525-7678.json b/advisories/unreviewed/2024/06/GHSA-c8mw-8525-7678/GHSA-c8mw-8525-7678.json index 5719b4c57e4..4e21f0320f2 100644 --- a/advisories/unreviewed/2024/06/GHSA-c8mw-8525-7678/GHSA-c8mw-8525-7678.json +++ b/advisories/unreviewed/2024/06/GHSA-c8mw-8525-7678/GHSA-c8mw-8525-7678.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-cf6f-2g38-8v75/GHSA-cf6f-2g38-8v75.json b/advisories/unreviewed/2024/06/GHSA-cf6f-2g38-8v75/GHSA-cf6f-2g38-8v75.json index d6d4b633442..47bb5020827 100644 --- a/advisories/unreviewed/2024/06/GHSA-cf6f-2g38-8v75/GHSA-cf6f-2g38-8v75.json +++ b/advisories/unreviewed/2024/06/GHSA-cf6f-2g38-8v75/GHSA-cf6f-2g38-8v75.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-cgmp-2p2c-jgf9/GHSA-cgmp-2p2c-jgf9.json b/advisories/unreviewed/2024/06/GHSA-cgmp-2p2c-jgf9/GHSA-cgmp-2p2c-jgf9.json index fd7b7dc0388..336c573e446 100644 --- a/advisories/unreviewed/2024/06/GHSA-cgmp-2p2c-jgf9/GHSA-cgmp-2p2c-jgf9.json +++ b/advisories/unreviewed/2024/06/GHSA-cgmp-2p2c-jgf9/GHSA-cgmp-2p2c-jgf9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-cgpx-jvx9-2gxw/GHSA-cgpx-jvx9-2gxw.json b/advisories/unreviewed/2024/06/GHSA-cgpx-jvx9-2gxw/GHSA-cgpx-jvx9-2gxw.json index be78fe68c7a..63340f5ae86 100644 --- a/advisories/unreviewed/2024/06/GHSA-cgpx-jvx9-2gxw/GHSA-cgpx-jvx9-2gxw.json +++ b/advisories/unreviewed/2024/06/GHSA-cgpx-jvx9-2gxw/GHSA-cgpx-jvx9-2gxw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-cjc4-92cq-3rh3/GHSA-cjc4-92cq-3rh3.json b/advisories/unreviewed/2024/06/GHSA-cjc4-92cq-3rh3/GHSA-cjc4-92cq-3rh3.json index 9948b12f56f..2fea3fabe21 100644 --- a/advisories/unreviewed/2024/06/GHSA-cjc4-92cq-3rh3/GHSA-cjc4-92cq-3rh3.json +++ b/advisories/unreviewed/2024/06/GHSA-cjc4-92cq-3rh3/GHSA-cjc4-92cq-3rh3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-cjg4-rgpv-wv5h/GHSA-cjg4-rgpv-wv5h.json b/advisories/unreviewed/2024/06/GHSA-cjg4-rgpv-wv5h/GHSA-cjg4-rgpv-wv5h.json index b4fa675a236..ec003f4c6e5 100644 --- a/advisories/unreviewed/2024/06/GHSA-cjg4-rgpv-wv5h/GHSA-cjg4-rgpv-wv5h.json +++ b/advisories/unreviewed/2024/06/GHSA-cjg4-rgpv-wv5h/GHSA-cjg4-rgpv-wv5h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-cx85-3x88-7h78/GHSA-cx85-3x88-7h78.json b/advisories/unreviewed/2024/06/GHSA-cx85-3x88-7h78/GHSA-cx85-3x88-7h78.json index 8fb65e4637c..8538a5c7231 100644 --- a/advisories/unreviewed/2024/06/GHSA-cx85-3x88-7h78/GHSA-cx85-3x88-7h78.json +++ b/advisories/unreviewed/2024/06/GHSA-cx85-3x88-7h78/GHSA-cx85-3x88-7h78.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-cxxg-wqvw-5gp8/GHSA-cxxg-wqvw-5gp8.json b/advisories/unreviewed/2024/06/GHSA-cxxg-wqvw-5gp8/GHSA-cxxg-wqvw-5gp8.json index f6c3d54b475..64091a70a13 100644 --- a/advisories/unreviewed/2024/06/GHSA-cxxg-wqvw-5gp8/GHSA-cxxg-wqvw-5gp8.json +++ b/advisories/unreviewed/2024/06/GHSA-cxxg-wqvw-5gp8/GHSA-cxxg-wqvw-5gp8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-f247-jmr8-598h/GHSA-f247-jmr8-598h.json b/advisories/unreviewed/2024/06/GHSA-f247-jmr8-598h/GHSA-f247-jmr8-598h.json index f1ff4c70855..f76f9b1cff7 100644 --- a/advisories/unreviewed/2024/06/GHSA-f247-jmr8-598h/GHSA-f247-jmr8-598h.json +++ b/advisories/unreviewed/2024/06/GHSA-f247-jmr8-598h/GHSA-f247-jmr8-598h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-f2cq-m485-xq43/GHSA-f2cq-m485-xq43.json b/advisories/unreviewed/2024/06/GHSA-f2cq-m485-xq43/GHSA-f2cq-m485-xq43.json index 5c014a6ce08..a97f3898e55 100644 --- a/advisories/unreviewed/2024/06/GHSA-f2cq-m485-xq43/GHSA-f2cq-m485-xq43.json +++ b/advisories/unreviewed/2024/06/GHSA-f2cq-m485-xq43/GHSA-f2cq-m485-xq43.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-f474-ggqf-8jp5/GHSA-f474-ggqf-8jp5.json b/advisories/unreviewed/2024/06/GHSA-f474-ggqf-8jp5/GHSA-f474-ggqf-8jp5.json index a7165eaa870..cd234e1929c 100644 --- a/advisories/unreviewed/2024/06/GHSA-f474-ggqf-8jp5/GHSA-f474-ggqf-8jp5.json +++ b/advisories/unreviewed/2024/06/GHSA-f474-ggqf-8jp5/GHSA-f474-ggqf-8jp5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-f58x-r563-jp48/GHSA-f58x-r563-jp48.json b/advisories/unreviewed/2024/06/GHSA-f58x-r563-jp48/GHSA-f58x-r563-jp48.json index 17f598b28c0..199670eacc9 100644 --- a/advisories/unreviewed/2024/06/GHSA-f58x-r563-jp48/GHSA-f58x-r563-jp48.json +++ b/advisories/unreviewed/2024/06/GHSA-f58x-r563-jp48/GHSA-f58x-r563-jp48.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-f7wm-449v-gc59/GHSA-f7wm-449v-gc59.json b/advisories/unreviewed/2024/06/GHSA-f7wm-449v-gc59/GHSA-f7wm-449v-gc59.json index e43c7da6db9..7cdb33355fd 100644 --- a/advisories/unreviewed/2024/06/GHSA-f7wm-449v-gc59/GHSA-f7wm-449v-gc59.json +++ b/advisories/unreviewed/2024/06/GHSA-f7wm-449v-gc59/GHSA-f7wm-449v-gc59.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-f9vg-6v95-272r/GHSA-f9vg-6v95-272r.json b/advisories/unreviewed/2024/06/GHSA-f9vg-6v95-272r/GHSA-f9vg-6v95-272r.json index ef277a2bbfc..166e2187c48 100644 --- a/advisories/unreviewed/2024/06/GHSA-f9vg-6v95-272r/GHSA-f9vg-6v95-272r.json +++ b/advisories/unreviewed/2024/06/GHSA-f9vg-6v95-272r/GHSA-f9vg-6v95-272r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-ffvv-9rpr-q6r5/GHSA-ffvv-9rpr-q6r5.json b/advisories/unreviewed/2024/06/GHSA-ffvv-9rpr-q6r5/GHSA-ffvv-9rpr-q6r5.json index 9cf99f25214..9d8aa2ccfb8 100644 --- a/advisories/unreviewed/2024/06/GHSA-ffvv-9rpr-q6r5/GHSA-ffvv-9rpr-q6r5.json +++ b/advisories/unreviewed/2024/06/GHSA-ffvv-9rpr-q6r5/GHSA-ffvv-9rpr-q6r5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-fj7x-4jpw-qx69/GHSA-fj7x-4jpw-qx69.json b/advisories/unreviewed/2024/06/GHSA-fj7x-4jpw-qx69/GHSA-fj7x-4jpw-qx69.json index 79164c55b0d..4f7541e9fa9 100644 --- a/advisories/unreviewed/2024/06/GHSA-fj7x-4jpw-qx69/GHSA-fj7x-4jpw-qx69.json +++ b/advisories/unreviewed/2024/06/GHSA-fj7x-4jpw-qx69/GHSA-fj7x-4jpw-qx69.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-fmhh-hvrg-38qc/GHSA-fmhh-hvrg-38qc.json b/advisories/unreviewed/2024/06/GHSA-fmhh-hvrg-38qc/GHSA-fmhh-hvrg-38qc.json index dc526e49c14..166126beba0 100644 --- a/advisories/unreviewed/2024/06/GHSA-fmhh-hvrg-38qc/GHSA-fmhh-hvrg-38qc.json +++ b/advisories/unreviewed/2024/06/GHSA-fmhh-hvrg-38qc/GHSA-fmhh-hvrg-38qc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-fpmj-g9m4-j4hg/GHSA-fpmj-g9m4-j4hg.json b/advisories/unreviewed/2024/06/GHSA-fpmj-g9m4-j4hg/GHSA-fpmj-g9m4-j4hg.json index b96989217dd..e3047559d34 100644 --- a/advisories/unreviewed/2024/06/GHSA-fpmj-g9m4-j4hg/GHSA-fpmj-g9m4-j4hg.json +++ b/advisories/unreviewed/2024/06/GHSA-fpmj-g9m4-j4hg/GHSA-fpmj-g9m4-j4hg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-fvp8-fq8f-59v8/GHSA-fvp8-fq8f-59v8.json b/advisories/unreviewed/2024/06/GHSA-fvp8-fq8f-59v8/GHSA-fvp8-fq8f-59v8.json index 63671f905c1..26e593b9a53 100644 --- a/advisories/unreviewed/2024/06/GHSA-fvp8-fq8f-59v8/GHSA-fvp8-fq8f-59v8.json +++ b/advisories/unreviewed/2024/06/GHSA-fvp8-fq8f-59v8/GHSA-fvp8-fq8f-59v8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-fwgg-ghmr-9fqp/GHSA-fwgg-ghmr-9fqp.json b/advisories/unreviewed/2024/06/GHSA-fwgg-ghmr-9fqp/GHSA-fwgg-ghmr-9fqp.json index da4fd5d9727..3712d9b6094 100644 --- a/advisories/unreviewed/2024/06/GHSA-fwgg-ghmr-9fqp/GHSA-fwgg-ghmr-9fqp.json +++ b/advisories/unreviewed/2024/06/GHSA-fwgg-ghmr-9fqp/GHSA-fwgg-ghmr-9fqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-fxj2-g5q3-j2f6/GHSA-fxj2-g5q3-j2f6.json b/advisories/unreviewed/2024/06/GHSA-fxj2-g5q3-j2f6/GHSA-fxj2-g5q3-j2f6.json index 7c36e694d4e..2a7e2f67ca1 100644 --- a/advisories/unreviewed/2024/06/GHSA-fxj2-g5q3-j2f6/GHSA-fxj2-g5q3-j2f6.json +++ b/advisories/unreviewed/2024/06/GHSA-fxj2-g5q3-j2f6/GHSA-fxj2-g5q3-j2f6.json @@ -7,12 +7,8 @@ "CVE-2024-5825" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-g4v9-xpcj-8262/GHSA-g4v9-xpcj-8262.json b/advisories/unreviewed/2024/06/GHSA-g4v9-xpcj-8262/GHSA-g4v9-xpcj-8262.json index 95612b21b10..f384a67d599 100644 --- a/advisories/unreviewed/2024/06/GHSA-g4v9-xpcj-8262/GHSA-g4v9-xpcj-8262.json +++ b/advisories/unreviewed/2024/06/GHSA-g4v9-xpcj-8262/GHSA-g4v9-xpcj-8262.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-g9vh-rmj6-m6r2/GHSA-g9vh-rmj6-m6r2.json b/advisories/unreviewed/2024/06/GHSA-g9vh-rmj6-m6r2/GHSA-g9vh-rmj6-m6r2.json index cc258f20094..5dd6d7e5ee0 100644 --- a/advisories/unreviewed/2024/06/GHSA-g9vh-rmj6-m6r2/GHSA-g9vh-rmj6-m6r2.json +++ b/advisories/unreviewed/2024/06/GHSA-g9vh-rmj6-m6r2/GHSA-g9vh-rmj6-m6r2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-ggc7-cfqq-7hf4/GHSA-ggc7-cfqq-7hf4.json b/advisories/unreviewed/2024/06/GHSA-ggc7-cfqq-7hf4/GHSA-ggc7-cfqq-7hf4.json index b2ddc798084..a92e722da5b 100644 --- a/advisories/unreviewed/2024/06/GHSA-ggc7-cfqq-7hf4/GHSA-ggc7-cfqq-7hf4.json +++ b/advisories/unreviewed/2024/06/GHSA-ggc7-cfqq-7hf4/GHSA-ggc7-cfqq-7hf4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-gjfr-8vgc-254w/GHSA-gjfr-8vgc-254w.json b/advisories/unreviewed/2024/06/GHSA-gjfr-8vgc-254w/GHSA-gjfr-8vgc-254w.json index 0c8f3dce438..9493dfd7a10 100644 --- a/advisories/unreviewed/2024/06/GHSA-gjfr-8vgc-254w/GHSA-gjfr-8vgc-254w.json +++ b/advisories/unreviewed/2024/06/GHSA-gjfr-8vgc-254w/GHSA-gjfr-8vgc-254w.json @@ -7,12 +7,8 @@ "CVE-2024-4206" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-gq45-c7rc-ffwq/GHSA-gq45-c7rc-ffwq.json b/advisories/unreviewed/2024/06/GHSA-gq45-c7rc-ffwq/GHSA-gq45-c7rc-ffwq.json index fa33c076fdd..14bd9876da4 100644 --- a/advisories/unreviewed/2024/06/GHSA-gq45-c7rc-ffwq/GHSA-gq45-c7rc-ffwq.json +++ b/advisories/unreviewed/2024/06/GHSA-gq45-c7rc-ffwq/GHSA-gq45-c7rc-ffwq.json @@ -7,12 +7,8 @@ "CVE-2024-5398" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-gxqg-7fh5-vvwm/GHSA-gxqg-7fh5-vvwm.json b/advisories/unreviewed/2024/06/GHSA-gxqg-7fh5-vvwm/GHSA-gxqg-7fh5-vvwm.json index 8a0ae8b1159..64723c16082 100644 --- a/advisories/unreviewed/2024/06/GHSA-gxqg-7fh5-vvwm/GHSA-gxqg-7fh5-vvwm.json +++ b/advisories/unreviewed/2024/06/GHSA-gxqg-7fh5-vvwm/GHSA-gxqg-7fh5-vvwm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-h438-86cm-g2q6/GHSA-h438-86cm-g2q6.json b/advisories/unreviewed/2024/06/GHSA-h438-86cm-g2q6/GHSA-h438-86cm-g2q6.json index 81556c9ca68..7c0571fac81 100644 --- a/advisories/unreviewed/2024/06/GHSA-h438-86cm-g2q6/GHSA-h438-86cm-g2q6.json +++ b/advisories/unreviewed/2024/06/GHSA-h438-86cm-g2q6/GHSA-h438-86cm-g2q6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-h9qx-m38j-p96f/GHSA-h9qx-m38j-p96f.json b/advisories/unreviewed/2024/06/GHSA-h9qx-m38j-p96f/GHSA-h9qx-m38j-p96f.json index 1bd1a827c06..bebb60a7dfe 100644 --- a/advisories/unreviewed/2024/06/GHSA-h9qx-m38j-p96f/GHSA-h9qx-m38j-p96f.json +++ b/advisories/unreviewed/2024/06/GHSA-h9qx-m38j-p96f/GHSA-h9qx-m38j-p96f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-hcfq-pvq6-64hg/GHSA-hcfq-pvq6-64hg.json b/advisories/unreviewed/2024/06/GHSA-hcfq-pvq6-64hg/GHSA-hcfq-pvq6-64hg.json index f2a79c208f9..70182eb6b50 100644 --- a/advisories/unreviewed/2024/06/GHSA-hcfq-pvq6-64hg/GHSA-hcfq-pvq6-64hg.json +++ b/advisories/unreviewed/2024/06/GHSA-hcfq-pvq6-64hg/GHSA-hcfq-pvq6-64hg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-hg9h-v98r-f5mq/GHSA-hg9h-v98r-f5mq.json b/advisories/unreviewed/2024/06/GHSA-hg9h-v98r-f5mq/GHSA-hg9h-v98r-f5mq.json index c4bbcfb7c7a..cdf32a65be1 100644 --- a/advisories/unreviewed/2024/06/GHSA-hg9h-v98r-f5mq/GHSA-hg9h-v98r-f5mq.json +++ b/advisories/unreviewed/2024/06/GHSA-hg9h-v98r-f5mq/GHSA-hg9h-v98r-f5mq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-hhrw-qrv8-cjmm/GHSA-hhrw-qrv8-cjmm.json b/advisories/unreviewed/2024/06/GHSA-hhrw-qrv8-cjmm/GHSA-hhrw-qrv8-cjmm.json index fc5fea929bd..5a064e15cb4 100644 --- a/advisories/unreviewed/2024/06/GHSA-hhrw-qrv8-cjmm/GHSA-hhrw-qrv8-cjmm.json +++ b/advisories/unreviewed/2024/06/GHSA-hhrw-qrv8-cjmm/GHSA-hhrw-qrv8-cjmm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-hxqx-mgwx-225x/GHSA-hxqx-mgwx-225x.json b/advisories/unreviewed/2024/06/GHSA-hxqx-mgwx-225x/GHSA-hxqx-mgwx-225x.json index 000c9435156..05db0e74cdd 100644 --- a/advisories/unreviewed/2024/06/GHSA-hxqx-mgwx-225x/GHSA-hxqx-mgwx-225x.json +++ b/advisories/unreviewed/2024/06/GHSA-hxqx-mgwx-225x/GHSA-hxqx-mgwx-225x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-j4qq-fq33-g7hw/GHSA-j4qq-fq33-g7hw.json b/advisories/unreviewed/2024/06/GHSA-j4qq-fq33-g7hw/GHSA-j4qq-fq33-g7hw.json index caedc537f1c..a2b122c3047 100644 --- a/advisories/unreviewed/2024/06/GHSA-j4qq-fq33-g7hw/GHSA-j4qq-fq33-g7hw.json +++ b/advisories/unreviewed/2024/06/GHSA-j4qq-fq33-g7hw/GHSA-j4qq-fq33-g7hw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-j5r5-r94m-6wjg/GHSA-j5r5-r94m-6wjg.json b/advisories/unreviewed/2024/06/GHSA-j5r5-r94m-6wjg/GHSA-j5r5-r94m-6wjg.json index d4173d6fe72..a9278c16143 100644 --- a/advisories/unreviewed/2024/06/GHSA-j5r5-r94m-6wjg/GHSA-j5r5-r94m-6wjg.json +++ b/advisories/unreviewed/2024/06/GHSA-j5r5-r94m-6wjg/GHSA-j5r5-r94m-6wjg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-j644-3879-5cgq/GHSA-j644-3879-5cgq.json b/advisories/unreviewed/2024/06/GHSA-j644-3879-5cgq/GHSA-j644-3879-5cgq.json index c177d9fc703..04c0f282747 100644 --- a/advisories/unreviewed/2024/06/GHSA-j644-3879-5cgq/GHSA-j644-3879-5cgq.json +++ b/advisories/unreviewed/2024/06/GHSA-j644-3879-5cgq/GHSA-j644-3879-5cgq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-j92m-cf34-p98w/GHSA-j92m-cf34-p98w.json b/advisories/unreviewed/2024/06/GHSA-j92m-cf34-p98w/GHSA-j92m-cf34-p98w.json index 23a9fb76c8b..c9a5cfa2b22 100644 --- a/advisories/unreviewed/2024/06/GHSA-j92m-cf34-p98w/GHSA-j92m-cf34-p98w.json +++ b/advisories/unreviewed/2024/06/GHSA-j92m-cf34-p98w/GHSA-j92m-cf34-p98w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-j96x-q273-mh9j/GHSA-j96x-q273-mh9j.json b/advisories/unreviewed/2024/06/GHSA-j96x-q273-mh9j/GHSA-j96x-q273-mh9j.json index 84c26a7badb..3a59f85b7b0 100644 --- a/advisories/unreviewed/2024/06/GHSA-j96x-q273-mh9j/GHSA-j96x-q273-mh9j.json +++ b/advisories/unreviewed/2024/06/GHSA-j96x-q273-mh9j/GHSA-j96x-q273-mh9j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-jggq-6mpj-9v53/GHSA-jggq-6mpj-9v53.json b/advisories/unreviewed/2024/06/GHSA-jggq-6mpj-9v53/GHSA-jggq-6mpj-9v53.json index dce9472e7e8..c748d9f585f 100644 --- a/advisories/unreviewed/2024/06/GHSA-jggq-6mpj-9v53/GHSA-jggq-6mpj-9v53.json +++ b/advisories/unreviewed/2024/06/GHSA-jggq-6mpj-9v53/GHSA-jggq-6mpj-9v53.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-jjx3-27m5-92gh/GHSA-jjx3-27m5-92gh.json b/advisories/unreviewed/2024/06/GHSA-jjx3-27m5-92gh/GHSA-jjx3-27m5-92gh.json index 35b52a317cc..1de1c24434b 100644 --- a/advisories/unreviewed/2024/06/GHSA-jjx3-27m5-92gh/GHSA-jjx3-27m5-92gh.json +++ b/advisories/unreviewed/2024/06/GHSA-jjx3-27m5-92gh/GHSA-jjx3-27m5-92gh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-m47j-h8wj-cg29/GHSA-m47j-h8wj-cg29.json b/advisories/unreviewed/2024/06/GHSA-m47j-h8wj-cg29/GHSA-m47j-h8wj-cg29.json index 4ffdc747d0e..9dee319413e 100644 --- a/advisories/unreviewed/2024/06/GHSA-m47j-h8wj-cg29/GHSA-m47j-h8wj-cg29.json +++ b/advisories/unreviewed/2024/06/GHSA-m47j-h8wj-cg29/GHSA-m47j-h8wj-cg29.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-mjwc-4vr5-7xr3/GHSA-mjwc-4vr5-7xr3.json b/advisories/unreviewed/2024/06/GHSA-mjwc-4vr5-7xr3/GHSA-mjwc-4vr5-7xr3.json index 58cc6051822..16af434f104 100644 --- a/advisories/unreviewed/2024/06/GHSA-mjwc-4vr5-7xr3/GHSA-mjwc-4vr5-7xr3.json +++ b/advisories/unreviewed/2024/06/GHSA-mjwc-4vr5-7xr3/GHSA-mjwc-4vr5-7xr3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-mrcq-5w4f-hvcr/GHSA-mrcq-5w4f-hvcr.json b/advisories/unreviewed/2024/06/GHSA-mrcq-5w4f-hvcr/GHSA-mrcq-5w4f-hvcr.json index 537d24ffd02..fc2f356f23f 100644 --- a/advisories/unreviewed/2024/06/GHSA-mrcq-5w4f-hvcr/GHSA-mrcq-5w4f-hvcr.json +++ b/advisories/unreviewed/2024/06/GHSA-mrcq-5w4f-hvcr/GHSA-mrcq-5w4f-hvcr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-mxcr-f478-crp2/GHSA-mxcr-f478-crp2.json b/advisories/unreviewed/2024/06/GHSA-mxcr-f478-crp2/GHSA-mxcr-f478-crp2.json index 0a3c6df8452..b226d1f5976 100644 --- a/advisories/unreviewed/2024/06/GHSA-mxcr-f478-crp2/GHSA-mxcr-f478-crp2.json +++ b/advisories/unreviewed/2024/06/GHSA-mxcr-f478-crp2/GHSA-mxcr-f478-crp2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-p4p8-443x-h6f3/GHSA-p4p8-443x-h6f3.json b/advisories/unreviewed/2024/06/GHSA-p4p8-443x-h6f3/GHSA-p4p8-443x-h6f3.json index 6de546fc48e..07bb9e416f8 100644 --- a/advisories/unreviewed/2024/06/GHSA-p4p8-443x-h6f3/GHSA-p4p8-443x-h6f3.json +++ b/advisories/unreviewed/2024/06/GHSA-p4p8-443x-h6f3/GHSA-p4p8-443x-h6f3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-p78r-j4mv-mv67/GHSA-p78r-j4mv-mv67.json b/advisories/unreviewed/2024/06/GHSA-p78r-j4mv-mv67/GHSA-p78r-j4mv-mv67.json index 9f3733f7e90..8aa9c8e42c6 100644 --- a/advisories/unreviewed/2024/06/GHSA-p78r-j4mv-mv67/GHSA-p78r-j4mv-mv67.json +++ b/advisories/unreviewed/2024/06/GHSA-p78r-j4mv-mv67/GHSA-p78r-j4mv-mv67.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-p82q-4g4j-x67h/GHSA-p82q-4g4j-x67h.json b/advisories/unreviewed/2024/06/GHSA-p82q-4g4j-x67h/GHSA-p82q-4g4j-x67h.json index 8a22c335d0e..21f7e3d53ce 100644 --- a/advisories/unreviewed/2024/06/GHSA-p82q-4g4j-x67h/GHSA-p82q-4g4j-x67h.json +++ b/advisories/unreviewed/2024/06/GHSA-p82q-4g4j-x67h/GHSA-p82q-4g4j-x67h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-pcr3-qchm-7gp3/GHSA-pcr3-qchm-7gp3.json b/advisories/unreviewed/2024/06/GHSA-pcr3-qchm-7gp3/GHSA-pcr3-qchm-7gp3.json index af915721076..17c16013038 100644 --- a/advisories/unreviewed/2024/06/GHSA-pcr3-qchm-7gp3/GHSA-pcr3-qchm-7gp3.json +++ b/advisories/unreviewed/2024/06/GHSA-pcr3-qchm-7gp3/GHSA-pcr3-qchm-7gp3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-pgqq-wq3j-8p74/GHSA-pgqq-wq3j-8p74.json b/advisories/unreviewed/2024/06/GHSA-pgqq-wq3j-8p74/GHSA-pgqq-wq3j-8p74.json index 68930a4ba25..4edafaf116f 100644 --- a/advisories/unreviewed/2024/06/GHSA-pgqq-wq3j-8p74/GHSA-pgqq-wq3j-8p74.json +++ b/advisories/unreviewed/2024/06/GHSA-pgqq-wq3j-8p74/GHSA-pgqq-wq3j-8p74.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-qgm3-fv3v-22gp/GHSA-qgm3-fv3v-22gp.json b/advisories/unreviewed/2024/06/GHSA-qgm3-fv3v-22gp/GHSA-qgm3-fv3v-22gp.json index 28341a280ae..ed039fa408b 100644 --- a/advisories/unreviewed/2024/06/GHSA-qgm3-fv3v-22gp/GHSA-qgm3-fv3v-22gp.json +++ b/advisories/unreviewed/2024/06/GHSA-qgm3-fv3v-22gp/GHSA-qgm3-fv3v-22gp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-qhx7-fh26-rx4j/GHSA-qhx7-fh26-rx4j.json b/advisories/unreviewed/2024/06/GHSA-qhx7-fh26-rx4j/GHSA-qhx7-fh26-rx4j.json index 0f35c0fb95b..f8b2abb7b63 100644 --- a/advisories/unreviewed/2024/06/GHSA-qhx7-fh26-rx4j/GHSA-qhx7-fh26-rx4j.json +++ b/advisories/unreviewed/2024/06/GHSA-qhx7-fh26-rx4j/GHSA-qhx7-fh26-rx4j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-qjp4-fmhh-wjw3/GHSA-qjp4-fmhh-wjw3.json b/advisories/unreviewed/2024/06/GHSA-qjp4-fmhh-wjw3/GHSA-qjp4-fmhh-wjw3.json index 60bc5aff5f3..77bb8b818c9 100644 --- a/advisories/unreviewed/2024/06/GHSA-qjp4-fmhh-wjw3/GHSA-qjp4-fmhh-wjw3.json +++ b/advisories/unreviewed/2024/06/GHSA-qjp4-fmhh-wjw3/GHSA-qjp4-fmhh-wjw3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-qpgp-vpmr-g2q2/GHSA-qpgp-vpmr-g2q2.json b/advisories/unreviewed/2024/06/GHSA-qpgp-vpmr-g2q2/GHSA-qpgp-vpmr-g2q2.json index 0ccb7b16da2..68eb16bb0bd 100644 --- a/advisories/unreviewed/2024/06/GHSA-qpgp-vpmr-g2q2/GHSA-qpgp-vpmr-g2q2.json +++ b/advisories/unreviewed/2024/06/GHSA-qpgp-vpmr-g2q2/GHSA-qpgp-vpmr-g2q2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-r5c3-c72q-m3f4/GHSA-r5c3-c72q-m3f4.json b/advisories/unreviewed/2024/06/GHSA-r5c3-c72q-m3f4/GHSA-r5c3-c72q-m3f4.json index 57b22e7f69d..a58a4b4f37e 100644 --- a/advisories/unreviewed/2024/06/GHSA-r5c3-c72q-m3f4/GHSA-r5c3-c72q-m3f4.json +++ b/advisories/unreviewed/2024/06/GHSA-r5c3-c72q-m3f4/GHSA-r5c3-c72q-m3f4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-r65c-cp46-xv46/GHSA-r65c-cp46-xv46.json b/advisories/unreviewed/2024/06/GHSA-r65c-cp46-xv46/GHSA-r65c-cp46-xv46.json index 814e8b768f3..2eea6881f8f 100644 --- a/advisories/unreviewed/2024/06/GHSA-r65c-cp46-xv46/GHSA-r65c-cp46-xv46.json +++ b/advisories/unreviewed/2024/06/GHSA-r65c-cp46-xv46/GHSA-r65c-cp46-xv46.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-r76f-2xpc-8q69/GHSA-r76f-2xpc-8q69.json b/advisories/unreviewed/2024/06/GHSA-r76f-2xpc-8q69/GHSA-r76f-2xpc-8q69.json index 90f3a9836ca..b64cba12562 100644 --- a/advisories/unreviewed/2024/06/GHSA-r76f-2xpc-8q69/GHSA-r76f-2xpc-8q69.json +++ b/advisories/unreviewed/2024/06/GHSA-r76f-2xpc-8q69/GHSA-r76f-2xpc-8q69.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-r7w3-w9rh-567f/GHSA-r7w3-w9rh-567f.json b/advisories/unreviewed/2024/06/GHSA-r7w3-w9rh-567f/GHSA-r7w3-w9rh-567f.json index 63fc0e74aea..ac699662354 100644 --- a/advisories/unreviewed/2024/06/GHSA-r7w3-w9rh-567f/GHSA-r7w3-w9rh-567f.json +++ b/advisories/unreviewed/2024/06/GHSA-r7w3-w9rh-567f/GHSA-r7w3-w9rh-567f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-r92q-jwg4-7cxv/GHSA-r92q-jwg4-7cxv.json b/advisories/unreviewed/2024/06/GHSA-r92q-jwg4-7cxv/GHSA-r92q-jwg4-7cxv.json index 1b49ba18fe3..430d5866656 100644 --- a/advisories/unreviewed/2024/06/GHSA-r92q-jwg4-7cxv/GHSA-r92q-jwg4-7cxv.json +++ b/advisories/unreviewed/2024/06/GHSA-r92q-jwg4-7cxv/GHSA-r92q-jwg4-7cxv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-r9cv-hj2f-58h4/GHSA-r9cv-hj2f-58h4.json b/advisories/unreviewed/2024/06/GHSA-r9cv-hj2f-58h4/GHSA-r9cv-hj2f-58h4.json index 2a2cc597f95..e2b075b726b 100644 --- a/advisories/unreviewed/2024/06/GHSA-r9cv-hj2f-58h4/GHSA-r9cv-hj2f-58h4.json +++ b/advisories/unreviewed/2024/06/GHSA-r9cv-hj2f-58h4/GHSA-r9cv-hj2f-58h4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-rcpr-pf4m-pw93/GHSA-rcpr-pf4m-pw93.json b/advisories/unreviewed/2024/06/GHSA-rcpr-pf4m-pw93/GHSA-rcpr-pf4m-pw93.json index bc4963586ee..474a26b7928 100644 --- a/advisories/unreviewed/2024/06/GHSA-rcpr-pf4m-pw93/GHSA-rcpr-pf4m-pw93.json +++ b/advisories/unreviewed/2024/06/GHSA-rcpr-pf4m-pw93/GHSA-rcpr-pf4m-pw93.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-rf2w-v629-wf4f/GHSA-rf2w-v629-wf4f.json b/advisories/unreviewed/2024/06/GHSA-rf2w-v629-wf4f/GHSA-rf2w-v629-wf4f.json index 8aa20292ff2..88386d2b41a 100644 --- a/advisories/unreviewed/2024/06/GHSA-rf2w-v629-wf4f/GHSA-rf2w-v629-wf4f.json +++ b/advisories/unreviewed/2024/06/GHSA-rf2w-v629-wf4f/GHSA-rf2w-v629-wf4f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-rfg3-rpcj-q476/GHSA-rfg3-rpcj-q476.json b/advisories/unreviewed/2024/06/GHSA-rfg3-rpcj-q476/GHSA-rfg3-rpcj-q476.json index fecea91fd80..5d091bef63b 100644 --- a/advisories/unreviewed/2024/06/GHSA-rfg3-rpcj-q476/GHSA-rfg3-rpcj-q476.json +++ b/advisories/unreviewed/2024/06/GHSA-rfg3-rpcj-q476/GHSA-rfg3-rpcj-q476.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-rmh4-wj7h-4cpw/GHSA-rmh4-wj7h-4cpw.json b/advisories/unreviewed/2024/06/GHSA-rmh4-wj7h-4cpw/GHSA-rmh4-wj7h-4cpw.json index c4fef14a40b..526b02f70db 100644 --- a/advisories/unreviewed/2024/06/GHSA-rmh4-wj7h-4cpw/GHSA-rmh4-wj7h-4cpw.json +++ b/advisories/unreviewed/2024/06/GHSA-rmh4-wj7h-4cpw/GHSA-rmh4-wj7h-4cpw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-rprf-7696-jjrj/GHSA-rprf-7696-jjrj.json b/advisories/unreviewed/2024/06/GHSA-rprf-7696-jjrj/GHSA-rprf-7696-jjrj.json index 526bee39d27..628ce3cdf32 100644 --- a/advisories/unreviewed/2024/06/GHSA-rprf-7696-jjrj/GHSA-rprf-7696-jjrj.json +++ b/advisories/unreviewed/2024/06/GHSA-rprf-7696-jjrj/GHSA-rprf-7696-jjrj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-rqqx-vwj3-25p4/GHSA-rqqx-vwj3-25p4.json b/advisories/unreviewed/2024/06/GHSA-rqqx-vwj3-25p4/GHSA-rqqx-vwj3-25p4.json index 11ac3bfc609..6279b009d87 100644 --- a/advisories/unreviewed/2024/06/GHSA-rqqx-vwj3-25p4/GHSA-rqqx-vwj3-25p4.json +++ b/advisories/unreviewed/2024/06/GHSA-rqqx-vwj3-25p4/GHSA-rqqx-vwj3-25p4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-v3v4-h24m-3cr8/GHSA-v3v4-h24m-3cr8.json b/advisories/unreviewed/2024/06/GHSA-v3v4-h24m-3cr8/GHSA-v3v4-h24m-3cr8.json index 8b7cc44b877..d2b24be0420 100644 --- a/advisories/unreviewed/2024/06/GHSA-v3v4-h24m-3cr8/GHSA-v3v4-h24m-3cr8.json +++ b/advisories/unreviewed/2024/06/GHSA-v3v4-h24m-3cr8/GHSA-v3v4-h24m-3cr8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-vfhg-qvc9-3fr9/GHSA-vfhg-qvc9-3fr9.json b/advisories/unreviewed/2024/06/GHSA-vfhg-qvc9-3fr9/GHSA-vfhg-qvc9-3fr9.json index 699afb5b880..d970b8cf239 100644 --- a/advisories/unreviewed/2024/06/GHSA-vfhg-qvc9-3fr9/GHSA-vfhg-qvc9-3fr9.json +++ b/advisories/unreviewed/2024/06/GHSA-vfhg-qvc9-3fr9/GHSA-vfhg-qvc9-3fr9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-vfmf-3vr6-j85g/GHSA-vfmf-3vr6-j85g.json b/advisories/unreviewed/2024/06/GHSA-vfmf-3vr6-j85g/GHSA-vfmf-3vr6-j85g.json index 9616b9fd853..9cbc5aa9695 100644 --- a/advisories/unreviewed/2024/06/GHSA-vfmf-3vr6-j85g/GHSA-vfmf-3vr6-j85g.json +++ b/advisories/unreviewed/2024/06/GHSA-vfmf-3vr6-j85g/GHSA-vfmf-3vr6-j85g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-vh49-h943-v4wx/GHSA-vh49-h943-v4wx.json b/advisories/unreviewed/2024/06/GHSA-vh49-h943-v4wx/GHSA-vh49-h943-v4wx.json index 56a4069a4bd..97c23a1f90a 100644 --- a/advisories/unreviewed/2024/06/GHSA-vh49-h943-v4wx/GHSA-vh49-h943-v4wx.json +++ b/advisories/unreviewed/2024/06/GHSA-vh49-h943-v4wx/GHSA-vh49-h943-v4wx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-vmx5-xfwf-9f82/GHSA-vmx5-xfwf-9f82.json b/advisories/unreviewed/2024/06/GHSA-vmx5-xfwf-9f82/GHSA-vmx5-xfwf-9f82.json index 1db7db47614..50f58ff00cb 100644 --- a/advisories/unreviewed/2024/06/GHSA-vmx5-xfwf-9f82/GHSA-vmx5-xfwf-9f82.json +++ b/advisories/unreviewed/2024/06/GHSA-vmx5-xfwf-9f82/GHSA-vmx5-xfwf-9f82.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-vrf4-hv45-fq4j/GHSA-vrf4-hv45-fq4j.json b/advisories/unreviewed/2024/06/GHSA-vrf4-hv45-fq4j/GHSA-vrf4-hv45-fq4j.json index 92225357d43..1560d22f103 100644 --- a/advisories/unreviewed/2024/06/GHSA-vrf4-hv45-fq4j/GHSA-vrf4-hv45-fq4j.json +++ b/advisories/unreviewed/2024/06/GHSA-vrf4-hv45-fq4j/GHSA-vrf4-hv45-fq4j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-vvcg-4m47-935g/GHSA-vvcg-4m47-935g.json b/advisories/unreviewed/2024/06/GHSA-vvcg-4m47-935g/GHSA-vvcg-4m47-935g.json index 43da2f4fa78..f593f538f50 100644 --- a/advisories/unreviewed/2024/06/GHSA-vvcg-4m47-935g/GHSA-vvcg-4m47-935g.json +++ b/advisories/unreviewed/2024/06/GHSA-vvcg-4m47-935g/GHSA-vvcg-4m47-935g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-vvfh-c922-h3gx/GHSA-vvfh-c922-h3gx.json b/advisories/unreviewed/2024/06/GHSA-vvfh-c922-h3gx/GHSA-vvfh-c922-h3gx.json index ed1b966f372..526dc100ed2 100644 --- a/advisories/unreviewed/2024/06/GHSA-vvfh-c922-h3gx/GHSA-vvfh-c922-h3gx.json +++ b/advisories/unreviewed/2024/06/GHSA-vvfh-c922-h3gx/GHSA-vvfh-c922-h3gx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-vx48-f47g-5gxg/GHSA-vx48-f47g-5gxg.json b/advisories/unreviewed/2024/06/GHSA-vx48-f47g-5gxg/GHSA-vx48-f47g-5gxg.json index ab5bb04d412..04ba40571c8 100644 --- a/advisories/unreviewed/2024/06/GHSA-vx48-f47g-5gxg/GHSA-vx48-f47g-5gxg.json +++ b/advisories/unreviewed/2024/06/GHSA-vx48-f47g-5gxg/GHSA-vx48-f47g-5gxg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-w966-799g-fp7v/GHSA-w966-799g-fp7v.json b/advisories/unreviewed/2024/06/GHSA-w966-799g-fp7v/GHSA-w966-799g-fp7v.json index 565c03cd87a..4b9a668cc2e 100644 --- a/advisories/unreviewed/2024/06/GHSA-w966-799g-fp7v/GHSA-w966-799g-fp7v.json +++ b/advisories/unreviewed/2024/06/GHSA-w966-799g-fp7v/GHSA-w966-799g-fp7v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-wf7h-7f7p-8g7g/GHSA-wf7h-7f7p-8g7g.json b/advisories/unreviewed/2024/06/GHSA-wf7h-7f7p-8g7g/GHSA-wf7h-7f7p-8g7g.json index 5978b9269da..0163c00027d 100644 --- a/advisories/unreviewed/2024/06/GHSA-wf7h-7f7p-8g7g/GHSA-wf7h-7f7p-8g7g.json +++ b/advisories/unreviewed/2024/06/GHSA-wf7h-7f7p-8g7g/GHSA-wf7h-7f7p-8g7g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-wpj8-988q-w333/GHSA-wpj8-988q-w333.json b/advisories/unreviewed/2024/06/GHSA-wpj8-988q-w333/GHSA-wpj8-988q-w333.json index cdd773ed70e..1a762cedeb7 100644 --- a/advisories/unreviewed/2024/06/GHSA-wpj8-988q-w333/GHSA-wpj8-988q-w333.json +++ b/advisories/unreviewed/2024/06/GHSA-wpj8-988q-w333/GHSA-wpj8-988q-w333.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-wxcg-26p8-gwp5/GHSA-wxcg-26p8-gwp5.json b/advisories/unreviewed/2024/06/GHSA-wxcg-26p8-gwp5/GHSA-wxcg-26p8-gwp5.json index f0e35489cb2..ae5116b83d9 100644 --- a/advisories/unreviewed/2024/06/GHSA-wxcg-26p8-gwp5/GHSA-wxcg-26p8-gwp5.json +++ b/advisories/unreviewed/2024/06/GHSA-wxcg-26p8-gwp5/GHSA-wxcg-26p8-gwp5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-x32g-hhg9-mgv8/GHSA-x32g-hhg9-mgv8.json b/advisories/unreviewed/2024/06/GHSA-x32g-hhg9-mgv8/GHSA-x32g-hhg9-mgv8.json index bb96bce82df..0220149bd62 100644 --- a/advisories/unreviewed/2024/06/GHSA-x32g-hhg9-mgv8/GHSA-x32g-hhg9-mgv8.json +++ b/advisories/unreviewed/2024/06/GHSA-x32g-hhg9-mgv8/GHSA-x32g-hhg9-mgv8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-x47x-f96m-j7gv/GHSA-x47x-f96m-j7gv.json b/advisories/unreviewed/2024/06/GHSA-x47x-f96m-j7gv/GHSA-x47x-f96m-j7gv.json index 100f640b709..34e4c54884e 100644 --- a/advisories/unreviewed/2024/06/GHSA-x47x-f96m-j7gv/GHSA-x47x-f96m-j7gv.json +++ b/advisories/unreviewed/2024/06/GHSA-x47x-f96m-j7gv/GHSA-x47x-f96m-j7gv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-x58r-7627-pg7c/GHSA-x58r-7627-pg7c.json b/advisories/unreviewed/2024/06/GHSA-x58r-7627-pg7c/GHSA-x58r-7627-pg7c.json index 3e251ae8ee1..909c7171f10 100644 --- a/advisories/unreviewed/2024/06/GHSA-x58r-7627-pg7c/GHSA-x58r-7627-pg7c.json +++ b/advisories/unreviewed/2024/06/GHSA-x58r-7627-pg7c/GHSA-x58r-7627-pg7c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-x5gf-69xm-cjxm/GHSA-x5gf-69xm-cjxm.json b/advisories/unreviewed/2024/06/GHSA-x5gf-69xm-cjxm/GHSA-x5gf-69xm-cjxm.json index ae456f4919d..4ab795edcee 100644 --- a/advisories/unreviewed/2024/06/GHSA-x5gf-69xm-cjxm/GHSA-x5gf-69xm-cjxm.json +++ b/advisories/unreviewed/2024/06/GHSA-x5gf-69xm-cjxm/GHSA-x5gf-69xm-cjxm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-x9jg-8xfj-3h48/GHSA-x9jg-8xfj-3h48.json b/advisories/unreviewed/2024/06/GHSA-x9jg-8xfj-3h48/GHSA-x9jg-8xfj-3h48.json index 4a650146bbe..4d4c3bb148f 100644 --- a/advisories/unreviewed/2024/06/GHSA-x9jg-8xfj-3h48/GHSA-x9jg-8xfj-3h48.json +++ b/advisories/unreviewed/2024/06/GHSA-x9jg-8xfj-3h48/GHSA-x9jg-8xfj-3h48.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-x9q2-9wf7-rmvq/GHSA-x9q2-9wf7-rmvq.json b/advisories/unreviewed/2024/06/GHSA-x9q2-9wf7-rmvq/GHSA-x9q2-9wf7-rmvq.json index ec94ccf7276..073602fcd85 100644 --- a/advisories/unreviewed/2024/06/GHSA-x9q2-9wf7-rmvq/GHSA-x9q2-9wf7-rmvq.json +++ b/advisories/unreviewed/2024/06/GHSA-x9q2-9wf7-rmvq/GHSA-x9q2-9wf7-rmvq.json @@ -7,12 +7,8 @@ "CVE-2024-2462" ], "details": "Allow attackers to intercept or falsify data exchanges between the client \nand the server", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-xj8x-rm7w-xfh4/GHSA-xj8x-rm7w-xfh4.json b/advisories/unreviewed/2024/06/GHSA-xj8x-rm7w-xfh4/GHSA-xj8x-rm7w-xfh4.json index 5e3ac57a57b..02899bc6213 100644 --- a/advisories/unreviewed/2024/06/GHSA-xj8x-rm7w-xfh4/GHSA-xj8x-rm7w-xfh4.json +++ b/advisories/unreviewed/2024/06/GHSA-xj8x-rm7w-xfh4/GHSA-xj8x-rm7w-xfh4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-xqxj-x89x-6rq4/GHSA-xqxj-x89x-6rq4.json b/advisories/unreviewed/2024/06/GHSA-xqxj-x89x-6rq4/GHSA-xqxj-x89x-6rq4.json index 10eb4b0503c..1ccefc72bed 100644 --- a/advisories/unreviewed/2024/06/GHSA-xqxj-x89x-6rq4/GHSA-xqxj-x89x-6rq4.json +++ b/advisories/unreviewed/2024/06/GHSA-xqxj-x89x-6rq4/GHSA-xqxj-x89x-6rq4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-xw65-8v8j-f5mq/GHSA-xw65-8v8j-f5mq.json b/advisories/unreviewed/2024/06/GHSA-xw65-8v8j-f5mq/GHSA-xw65-8v8j-f5mq.json index 1921743cd3d..39ece31beea 100644 --- a/advisories/unreviewed/2024/06/GHSA-xw65-8v8j-f5mq/GHSA-xw65-8v8j-f5mq.json +++ b/advisories/unreviewed/2024/06/GHSA-xw65-8v8j-f5mq/GHSA-xw65-8v8j-f5mq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",