From 0ec404861ab70cb10b64744a8d112f43347d5bfb Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 29 Nov 2024 05:15:47 +0000 Subject: [PATCH] Advisory Database Sync --- .../10/GHSA-gr44-7grc-37vq/GHSA-gr44-7grc-37vq.json | 4 +--- .../10/GHSA-h56m-vwxc-3qpw/GHSA-h56m-vwxc-3qpw.json | 4 +--- .../10/GHSA-h77x-m5q8-c29h/GHSA-h77x-m5q8-c29h.json | 4 +--- .../10/GHSA-hgpp-pp89-4fgf/GHSA-hgpp-pp89-4fgf.json | 4 +--- .../10/GHSA-mgx3-27hr-mfgp/GHSA-mgx3-27hr-mfgp.json | 4 +--- .../10/GHSA-q759-hwvc-m3jg/GHSA-q759-hwvc-m3jg.json | 4 +--- .../10/GHSA-r8fh-hq2p-7qhq/GHSA-r8fh-hq2p-7qhq.json | 4 +--- .../10/GHSA-v3rr-cph9-2g2q/GHSA-v3rr-cph9-2g2q.json | 4 +--- .../10/GHSA-wpw7-wxjm-cw8r/GHSA-wpw7-wxjm-cw8r.json | 4 +--- .../10/GHSA-xgr2-v94m-rc9g/GHSA-xgr2-v94m-rc9g.json | 4 +--- .../10/GHSA-xwr3-fmgj-mmfr/GHSA-xwr3-fmgj-mmfr.json | 4 +--- .../08/GHSA-q7wx-62r7-j2x7/GHSA-q7wx-62r7-j2x7.json | 4 +--- .../08/GHSA-xjqg-9jvg-fgx2/GHSA-xjqg-9jvg-fgx2.json | 4 +--- .../08/GHSA-45p7-c959-rgcm/GHSA-45p7-c959-rgcm.json | 12 +++--------- .../08/GHSA-48vq-8jqv-gm6f/GHSA-48vq-8jqv-gm6f.json | 8 ++------ .../08/GHSA-v666-6w97-pcwm/GHSA-v666-6w97-pcwm.json | 8 ++------ .../01/GHSA-qjm7-55vv-3c5f/GHSA-qjm7-55vv-3c5f.json | 4 +--- .../08/GHSA-857q-xmph-p2v5/GHSA-857q-xmph-p2v5.json | 4 +--- .../02/GHSA-wg28-p94j-5hp8/GHSA-wg28-p94j-5hp8.json | 4 +--- .../03/GHSA-vw87-2p2h-8rp3/GHSA-vw87-2p2h-8rp3.json | 4 +--- .../04/GHSA-222r-4v3h-874c/GHSA-222r-4v3h-874c.json | 12 +++--------- .../04/GHSA-225r-gcwx-jch9/GHSA-225r-gcwx-jch9.json | 12 +++--------- .../04/GHSA-22v9-p596-vfhg/GHSA-22v9-p596-vfhg.json | 12 +++--------- .../04/GHSA-286v-p4r7-vj8x/GHSA-286v-p4r7-vj8x.json | 12 +++--------- .../04/GHSA-2gf2-mh53-2r7m/GHSA-2gf2-mh53-2r7m.json | 12 +++--------- .../04/GHSA-2hg7-fwp9-5gj7/GHSA-2hg7-fwp9-5gj7.json | 12 +++--------- .../04/GHSA-2phm-q6hw-h5mw/GHSA-2phm-q6hw-h5mw.json | 12 +++--------- .../04/GHSA-2r9p-58g6-hvj9/GHSA-2r9p-58g6-hvj9.json | 8 ++------ .../04/GHSA-2v37-26xm-h4rf/GHSA-2v37-26xm-h4rf.json | 12 +++--------- .../04/GHSA-2xfg-qg29-hmjc/GHSA-2xfg-qg29-hmjc.json | 12 +++--------- .../04/GHSA-346g-3xvj-229v/GHSA-346g-3xvj-229v.json | 12 +++--------- .../04/GHSA-34pv-6c59-fw4x/GHSA-34pv-6c59-fw4x.json | 12 +++--------- .../04/GHSA-3528-g9ff-867j/GHSA-3528-g9ff-867j.json | 12 +++--------- .../04/GHSA-35rf-v5xv-3376/GHSA-35rf-v5xv-3376.json | 12 +++--------- .../04/GHSA-367q-j23v-q67j/GHSA-367q-j23v-q67j.json | 12 +++--------- .../04/GHSA-373p-qrfg-hfq4/GHSA-373p-qrfg-hfq4.json | 12 +++--------- .../04/GHSA-37q9-236v-5578/GHSA-37q9-236v-5578.json | 12 +++--------- .../04/GHSA-392m-pxgq-jvm8/GHSA-392m-pxgq-jvm8.json | 12 +++--------- .../04/GHSA-3ccc-c7wq-35g5/GHSA-3ccc-c7wq-35g5.json | 12 +++--------- .../04/GHSA-3h2g-8x7p-qmjq/GHSA-3h2g-8x7p-qmjq.json | 12 +++--------- .../04/GHSA-3jcv-mqf8-ww8q/GHSA-3jcv-mqf8-ww8q.json | 12 +++--------- .../04/GHSA-3m7c-89h2-3q7w/GHSA-3m7c-89h2-3q7w.json | 12 +++--------- .../04/GHSA-3mg6-g6r9-xm68/GHSA-3mg6-g6r9-xm68.json | 12 +++--------- .../04/GHSA-3mjq-qmqc-xrrv/GHSA-3mjq-qmqc-xrrv.json | 12 +++--------- .../04/GHSA-3pww-g69g-29xx/GHSA-3pww-g69g-29xx.json | 12 +++--------- .../04/GHSA-3r83-hcqh-gxqf/GHSA-3r83-hcqh-gxqf.json | 12 +++--------- .../04/GHSA-3v35-rfwh-3mc8/GHSA-3v35-rfwh-3mc8.json | 12 +++--------- .../04/GHSA-3x4g-qr6f-2pmw/GHSA-3x4g-qr6f-2pmw.json | 12 +++--------- .../04/GHSA-43mg-6cfc-53w7/GHSA-43mg-6cfc-53w7.json | 12 +++--------- .../04/GHSA-44h6-7xw4-35hg/GHSA-44h6-7xw4-35hg.json | 12 +++--------- .../04/GHSA-45q7-vcfp-hhr3/GHSA-45q7-vcfp-hhr3.json | 12 +++--------- .../04/GHSA-47vf-2cv8-2gw3/GHSA-47vf-2cv8-2gw3.json | 12 +++--------- .../04/GHSA-48p8-x75w-457x/GHSA-48p8-x75w-457x.json | 12 +++--------- .../04/GHSA-4f6g-grvj-2rjg/GHSA-4f6g-grvj-2rjg.json | 12 +++--------- .../04/GHSA-4fvq-q2rx-hw88/GHSA-4fvq-q2rx-hw88.json | 4 +--- .../04/GHSA-4hc4-4xrh-639q/GHSA-4hc4-4xrh-639q.json | 12 +++--------- .../04/GHSA-4hwr-6mhv-fvh3/GHSA-4hwr-6mhv-fvh3.json | 12 +++--------- .../04/GHSA-4v8m-4jjw-v3r5/GHSA-4v8m-4jjw-v3r5.json | 12 +++--------- .../04/GHSA-4w69-8ggm-7737/GHSA-4w69-8ggm-7737.json | 12 +++--------- .../04/GHSA-54fh-hpf3-3x2r/GHSA-54fh-hpf3-3x2r.json | 12 +++--------- .../04/GHSA-54g7-5765-8375/GHSA-54g7-5765-8375.json | 12 +++--------- .../04/GHSA-5576-9r4v-7ffw/GHSA-5576-9r4v-7ffw.json | 12 +++--------- .../04/GHSA-559q-jfjp-2w9j/GHSA-559q-jfjp-2w9j.json | 12 +++--------- .../04/GHSA-56gc-8w28-j7xm/GHSA-56gc-8w28-j7xm.json | 12 +++--------- .../04/GHSA-57c9-j2wv-xxm2/GHSA-57c9-j2wv-xxm2.json | 12 +++--------- .../04/GHSA-59hc-w7w5-7mwj/GHSA-59hc-w7w5-7mwj.json | 12 +++--------- .../04/GHSA-5mj4-f3x4-x486/GHSA-5mj4-f3x4-x486.json | 12 +++--------- .../04/GHSA-5pm6-j89m-8mmq/GHSA-5pm6-j89m-8mmq.json | 12 +++--------- .../04/GHSA-5v9r-wpqf-v2w9/GHSA-5v9r-wpqf-v2w9.json | 12 +++--------- .../04/GHSA-673q-v95c-q7mf/GHSA-673q-v95c-q7mf.json | 12 +++--------- .../04/GHSA-68vx-xw79-w5cg/GHSA-68vx-xw79-w5cg.json | 12 +++--------- .../04/GHSA-6hjc-hxpg-8q82/GHSA-6hjc-hxpg-8q82.json | 12 +++--------- .../04/GHSA-6jw8-7w6j-8fvp/GHSA-6jw8-7w6j-8fvp.json | 12 +++--------- .../04/GHSA-6pm9-q8g6-xp59/GHSA-6pm9-q8g6-xp59.json | 12 +++--------- .../04/GHSA-6q7f-6pgm-q59m/GHSA-6q7f-6pgm-q59m.json | 12 +++--------- .../04/GHSA-6rw8-gcfv-wh9c/GHSA-6rw8-gcfv-wh9c.json | 12 +++--------- .../04/GHSA-6rxm-4mhj-qqvc/GHSA-6rxm-4mhj-qqvc.json | 12 +++--------- .../04/GHSA-6v8c-3mh5-j3wq/GHSA-6v8c-3mh5-j3wq.json | 12 +++--------- .../04/GHSA-74jv-3pf7-q5p8/GHSA-74jv-3pf7-q5p8.json | 12 +++--------- .../04/GHSA-74wp-49jv-9x5m/GHSA-74wp-49jv-9x5m.json | 12 +++--------- .../04/GHSA-7753-m7xj-hvxr/GHSA-7753-m7xj-hvxr.json | 12 +++--------- .../04/GHSA-7774-m57j-3qmq/GHSA-7774-m57j-3qmq.json | 12 +++--------- .../04/GHSA-78mp-j9hf-999h/GHSA-78mp-j9hf-999h.json | 12 +++--------- .../04/GHSA-79g6-x9gh-wwqv/GHSA-79g6-x9gh-wwqv.json | 12 +++--------- .../04/GHSA-7c6m-w964-4jjh/GHSA-7c6m-w964-4jjh.json | 8 ++------ .../04/GHSA-7gg7-9cpw-h9r9/GHSA-7gg7-9cpw-h9r9.json | 12 +++--------- .../04/GHSA-7j25-vh8m-jjf9/GHSA-7j25-vh8m-jjf9.json | 12 +++--------- .../04/GHSA-7qjj-6hw3-3hc4/GHSA-7qjj-6hw3-3hc4.json | 12 +++--------- .../04/GHSA-7rc9-qwrm-pj39/GHSA-7rc9-qwrm-pj39.json | 12 +++--------- .../04/GHSA-7v9m-g864-6c85/GHSA-7v9m-g864-6c85.json | 12 +++--------- .../04/GHSA-7vhp-9g42-7c8w/GHSA-7vhp-9g42-7c8w.json | 12 +++--------- .../04/GHSA-7vq5-5wrf-3x9x/GHSA-7vq5-5wrf-3x9x.json | 12 +++--------- .../04/GHSA-7xfr-jcwg-59w6/GHSA-7xfr-jcwg-59w6.json | 12 +++--------- .../04/GHSA-7xj2-6g55-85x5/GHSA-7xj2-6g55-85x5.json | 12 +++--------- .../04/GHSA-86gg-6jj3-7gxr/GHSA-86gg-6jj3-7gxr.json | 12 +++--------- .../04/GHSA-86jg-3549-x2qh/GHSA-86jg-3549-x2qh.json | 12 +++--------- .../04/GHSA-86wp-r8x2-p694/GHSA-86wp-r8x2-p694.json | 12 +++--------- .../04/GHSA-88g6-h8fq-4gqq/GHSA-88g6-h8fq-4gqq.json | 12 +++--------- .../04/GHSA-88hx-73hq-hqfj/GHSA-88hx-73hq-hqfj.json | 12 +++--------- .../04/GHSA-8cmj-8gv7-x3wc/GHSA-8cmj-8gv7-x3wc.json | 12 +++--------- .../04/GHSA-8fc3-whhg-8qw8/GHSA-8fc3-whhg-8qw8.json | 12 +++--------- .../04/GHSA-8hx3-74gm-vfhh/GHSA-8hx3-74gm-vfhh.json | 12 +++--------- .../04/GHSA-8rmj-m7m9-7ph8/GHSA-8rmj-m7m9-7ph8.json | 12 +++--------- .../04/GHSA-8v75-gpj5-x889/GHSA-8v75-gpj5-x889.json | 12 +++--------- .../04/GHSA-8vvr-9c5j-9q97/GHSA-8vvr-9c5j-9q97.json | 12 +++--------- .../04/GHSA-8vx4-2r25-7xmp/GHSA-8vx4-2r25-7xmp.json | 12 +++--------- .../04/GHSA-8w27-q26q-hv6f/GHSA-8w27-q26q-hv6f.json | 12 +++--------- .../04/GHSA-8w32-x5px-mww7/GHSA-8w32-x5px-mww7.json | 12 +++--------- .../04/GHSA-8xcj-rh5m-9gwr/GHSA-8xcj-rh5m-9gwr.json | 12 +++--------- .../04/GHSA-92vr-7cqw-xc63/GHSA-92vr-7cqw-xc63.json | 12 +++--------- .../04/GHSA-93c3-33ph-vcvv/GHSA-93c3-33ph-vcvv.json | 12 +++--------- .../04/GHSA-9723-j4pc-8jhh/GHSA-9723-j4pc-8jhh.json | 12 +++--------- .../04/GHSA-97xg-79hm-5c93/GHSA-97xg-79hm-5c93.json | 8 ++------ .../04/GHSA-9c79-794f-fgpf/GHSA-9c79-794f-fgpf.json | 12 +++--------- .../04/GHSA-9ccp-985w-grj6/GHSA-9ccp-985w-grj6.json | 12 +++--------- .../04/GHSA-9g5p-gm42-j3hq/GHSA-9g5p-gm42-j3hq.json | 12 +++--------- .../04/GHSA-9g9j-gh9g-48x5/GHSA-9g9j-gh9g-48x5.json | 12 +++--------- .../04/GHSA-9gmh-g2w2-5jwr/GHSA-9gmh-g2w2-5jwr.json | 12 +++--------- .../04/GHSA-9jr7-h23f-xwrr/GHSA-9jr7-h23f-xwrr.json | 12 +++--------- .../04/GHSA-9p6g-hv89-h5mg/GHSA-9p6g-hv89-h5mg.json | 12 +++--------- .../04/GHSA-9q3h-6h4j-523q/GHSA-9q3h-6h4j-523q.json | 12 +++--------- .../04/GHSA-9v82-8g5x-9fg5/GHSA-9v82-8g5x-9fg5.json | 12 +++--------- .../04/GHSA-9xcw-j87f-mh2g/GHSA-9xcw-j87f-mh2g.json | 12 +++--------- .../04/GHSA-9xf3-j46h-rvq4/GHSA-9xf3-j46h-rvq4.json | 12 +++--------- .../04/GHSA-c5rg-f3hx-6hcg/GHSA-c5rg-f3hx-6hcg.json | 12 +++--------- .../04/GHSA-c5vm-cg9p-c7r9/GHSA-c5vm-cg9p-c7r9.json | 12 +++--------- .../04/GHSA-c67w-7c4h-rcfv/GHSA-c67w-7c4h-rcfv.json | 12 +++--------- .../04/GHSA-c835-vr4r-5hjm/GHSA-c835-vr4r-5hjm.json | 12 +++--------- .../04/GHSA-c88c-2pvm-pq8x/GHSA-c88c-2pvm-pq8x.json | 12 +++--------- .../04/GHSA-c8f7-vr5w-4grr/GHSA-c8f7-vr5w-4grr.json | 12 +++--------- .../04/GHSA-c8jj-cpv9-8p64/GHSA-c8jj-cpv9-8p64.json | 12 +++--------- .../04/GHSA-c8q2-5c9q-67pp/GHSA-c8q2-5c9q-67pp.json | 12 +++--------- .../04/GHSA-c929-49h9-7vjw/GHSA-c929-49h9-7vjw.json | 12 +++--------- .../04/GHSA-c9hw-vvq5-mgcp/GHSA-c9hw-vvq5-mgcp.json | 12 +++--------- .../04/GHSA-cg89-cjrh-9925/GHSA-cg89-cjrh-9925.json | 12 +++--------- .../04/GHSA-ch7q-c6xm-9wg7/GHSA-ch7q-c6xm-9wg7.json | 12 +++--------- .../04/GHSA-cj3q-54vp-7x82/GHSA-cj3q-54vp-7x82.json | 12 +++--------- .../04/GHSA-cpcw-2gx9-xcwx/GHSA-cpcw-2gx9-xcwx.json | 12 +++--------- .../04/GHSA-cr44-mv4m-96hc/GHSA-cr44-mv4m-96hc.json | 12 +++--------- .../04/GHSA-cwwh-357p-4xxx/GHSA-cwwh-357p-4xxx.json | 12 +++--------- .../04/GHSA-cx9f-78r3-35wj/GHSA-cx9f-78r3-35wj.json | 12 +++--------- .../04/GHSA-f26q-3x93-ffxm/GHSA-f26q-3x93-ffxm.json | 12 +++--------- .../04/GHSA-f298-64xr-j8x2/GHSA-f298-64xr-j8x2.json | 12 +++--------- .../04/GHSA-f2r2-4jrp-f3ph/GHSA-f2r2-4jrp-f3ph.json | 12 +++--------- .../04/GHSA-f89j-92rw-6x6x/GHSA-f89j-92rw-6x6x.json | 12 +++--------- .../04/GHSA-f8jq-wv2h-hqqm/GHSA-f8jq-wv2h-hqqm.json | 12 +++--------- .../04/GHSA-fcmp-4fvx-mvrf/GHSA-fcmp-4fvx-mvrf.json | 12 +++--------- .../04/GHSA-fm67-6f3q-6pqp/GHSA-fm67-6f3q-6pqp.json | 12 +++--------- .../04/GHSA-fp6p-43fg-5cj5/GHSA-fp6p-43fg-5cj5.json | 12 +++--------- .../04/GHSA-frjf-p4xm-rf24/GHSA-frjf-p4xm-rf24.json | 12 +++--------- .../04/GHSA-g2qx-p2rm-qq6g/GHSA-g2qx-p2rm-qq6g.json | 12 +++--------- .../04/GHSA-g32c-xj3w-479x/GHSA-g32c-xj3w-479x.json | 12 +++--------- .../04/GHSA-g5cf-8f24-p3pm/GHSA-g5cf-8f24-p3pm.json | 12 +++--------- .../04/GHSA-g7v5-rc2j-fqgg/GHSA-g7v5-rc2j-fqgg.json | 12 +++--------- .../04/GHSA-g8rh-37p9-m2xw/GHSA-g8rh-37p9-m2xw.json | 12 +++--------- .../04/GHSA-ghh8-v4ww-536g/GHSA-ghh8-v4ww-536g.json | 12 +++--------- .../04/GHSA-gjpv-7qjf-vj7x/GHSA-gjpv-7qjf-vj7x.json | 12 +++--------- .../04/GHSA-gm53-5grf-8hm4/GHSA-gm53-5grf-8hm4.json | 12 +++--------- .../04/GHSA-gm7x-33x3-3qg9/GHSA-gm7x-33x3-3qg9.json | 12 +++--------- .../04/GHSA-gq3c-qhph-m92g/GHSA-gq3c-qhph-m92g.json | 12 +++--------- .../04/GHSA-grp9-jgmj-h7px/GHSA-grp9-jgmj-h7px.json | 12 +++--------- .../04/GHSA-gvg8-m7rh-qfg2/GHSA-gvg8-m7rh-qfg2.json | 12 +++--------- .../04/GHSA-h3hr-frhw-fwq8/GHSA-h3hr-frhw-fwq8.json | 12 +++--------- .../04/GHSA-h5pq-5828-hr6x/GHSA-h5pq-5828-hr6x.json | 12 +++--------- .../04/GHSA-h6wp-g68c-q5j9/GHSA-h6wp-g68c-q5j9.json | 12 +++--------- .../04/GHSA-h963-7ffv-g7jf/GHSA-h963-7ffv-g7jf.json | 12 +++--------- .../04/GHSA-h9p6-q3mf-6wj3/GHSA-h9p6-q3mf-6wj3.json | 12 +++--------- .../04/GHSA-hjp2-87wj-g7c8/GHSA-hjp2-87wj-g7c8.json | 12 +++--------- .../04/GHSA-hmx2-378q-q7c3/GHSA-hmx2-378q-q7c3.json | 12 +++--------- .../04/GHSA-hr66-jxmg-86xm/GHSA-hr66-jxmg-86xm.json | 12 +++--------- .../04/GHSA-hr76-gm2q-68qr/GHSA-hr76-gm2q-68qr.json | 12 +++--------- .../04/GHSA-hrjf-28rx-wf7r/GHSA-hrjf-28rx-wf7r.json | 12 +++--------- .../04/GHSA-hv5v-h4qh-vgxj/GHSA-hv5v-h4qh-vgxj.json | 12 +++--------- .../04/GHSA-hw4c-6fxr-ghqh/GHSA-hw4c-6fxr-ghqh.json | 12 +++--------- .../04/GHSA-hwwv-vx36-7jpp/GHSA-hwwv-vx36-7jpp.json | 12 +++--------- .../04/GHSA-j274-79c7-46r9/GHSA-j274-79c7-46r9.json | 12 +++--------- .../04/GHSA-j27p-f9p3-c4mr/GHSA-j27p-f9p3-c4mr.json | 12 +++--------- .../04/GHSA-j52p-47c7-4w37/GHSA-j52p-47c7-4w37.json | 12 +++--------- .../04/GHSA-j648-847p-926p/GHSA-j648-847p-926p.json | 12 +++--------- .../04/GHSA-j64q-4qc2-c9v8/GHSA-j64q-4qc2-c9v8.json | 12 +++--------- .../04/GHSA-jg7j-cqjc-6cc3/GHSA-jg7j-cqjc-6cc3.json | 12 +++--------- .../04/GHSA-jh35-33g7-ghxr/GHSA-jh35-33g7-ghxr.json | 12 +++--------- .../04/GHSA-jh79-c7cc-fx5h/GHSA-jh79-c7cc-fx5h.json | 12 +++--------- .../04/GHSA-jp9p-3qm5-vq8x/GHSA-jp9p-3qm5-vq8x.json | 12 +++--------- .../04/GHSA-jpwg-qx54-r8vg/GHSA-jpwg-qx54-r8vg.json | 12 +++--------- .../04/GHSA-jrxr-vw4j-prv8/GHSA-jrxr-vw4j-prv8.json | 12 +++--------- .../04/GHSA-jx42-h6pp-7678/GHSA-jx42-h6pp-7678.json | 12 +++--------- .../04/GHSA-jxr7-cc77-4ch7/GHSA-jxr7-cc77-4ch7.json | 12 +++--------- .../04/GHSA-m5p8-8qj2-v775/GHSA-m5p8-8qj2-v775.json | 12 +++--------- .../04/GHSA-m8gw-x5jx-r3vm/GHSA-m8gw-x5jx-r3vm.json | 8 ++------ .../04/GHSA-m9g9-rq7f-5c46/GHSA-m9g9-rq7f-5c46.json | 12 +++--------- .../04/GHSA-mc6r-254j-5wx6/GHSA-mc6r-254j-5wx6.json | 12 +++--------- .../04/GHSA-mf6v-4fxg-pwvj/GHSA-mf6v-4fxg-pwvj.json | 12 +++--------- .../04/GHSA-mf97-3g2c-rccp/GHSA-mf97-3g2c-rccp.json | 12 +++--------- .../04/GHSA-mgx3-qmmm-64fp/GHSA-mgx3-qmmm-64fp.json | 12 +++--------- .../04/GHSA-mjqq-wq8f-g4cx/GHSA-mjqq-wq8f-g4cx.json | 12 +++--------- .../04/GHSA-mq8w-3qcq-f5hf/GHSA-mq8w-3qcq-f5hf.json | 12 +++--------- .../04/GHSA-mr3v-pmm4-26v3/GHSA-mr3v-pmm4-26v3.json | 12 +++--------- .../04/GHSA-mw37-2wq7-83rg/GHSA-mw37-2wq7-83rg.json | 12 +++--------- .../04/GHSA-mxff-qcf2-5cjv/GHSA-mxff-qcf2-5cjv.json | 12 +++--------- .../04/GHSA-p3mv-5j8q-vc32/GHSA-p3mv-5j8q-vc32.json | 12 +++--------- .../04/GHSA-p5x3-8ffv-76qr/GHSA-p5x3-8ffv-76qr.json | 12 +++--------- .../04/GHSA-p6j4-78m6-mrmc/GHSA-p6j4-78m6-mrmc.json | 12 +++--------- .../04/GHSA-p6wx-mvrf-wjw5/GHSA-p6wx-mvrf-wjw5.json | 12 +++--------- .../04/GHSA-p7qh-m3xx-q4cm/GHSA-p7qh-m3xx-q4cm.json | 12 +++--------- .../04/GHSA-pcqx-qgqf-w5jw/GHSA-pcqx-qgqf-w5jw.json | 12 +++--------- .../04/GHSA-php9-hw4x-p9pj/GHSA-php9-hw4x-p9pj.json | 12 +++--------- .../04/GHSA-pj32-r99j-9hr4/GHSA-pj32-r99j-9hr4.json | 12 +++--------- .../04/GHSA-pm4p-pvm5-c7wq/GHSA-pm4p-pvm5-c7wq.json | 12 +++--------- .../04/GHSA-pp2v-6wrc-g8x5/GHSA-pp2v-6wrc-g8x5.json | 12 +++--------- .../04/GHSA-pwgx-pv8v-3hcp/GHSA-pwgx-pv8v-3hcp.json | 12 +++--------- .../04/GHSA-pxq6-g7mh-m75f/GHSA-pxq6-g7mh-m75f.json | 12 +++--------- .../04/GHSA-pxxx-m8pv-jcgw/GHSA-pxxx-m8pv-jcgw.json | 12 +++--------- .../04/GHSA-q36p-w7jg-6243/GHSA-q36p-w7jg-6243.json | 12 +++--------- .../04/GHSA-q524-j64j-vqhj/GHSA-q524-j64j-vqhj.json | 12 +++--------- .../04/GHSA-q526-52p8-p826/GHSA-q526-52p8-p826.json | 12 +++--------- .../04/GHSA-q842-grxw-g4xw/GHSA-q842-grxw-g4xw.json | 12 +++--------- .../04/GHSA-q8hm-qxv3-j9xx/GHSA-q8hm-qxv3-j9xx.json | 12 +++--------- .../04/GHSA-q997-qgp7-2qxm/GHSA-q997-qgp7-2qxm.json | 12 +++--------- .../04/GHSA-qg65-w45w-rw2w/GHSA-qg65-w45w-rw2w.json | 12 +++--------- .../04/GHSA-qm34-w9p4-fxqv/GHSA-qm34-w9p4-fxqv.json | 12 +++--------- .../04/GHSA-qp9g-233f-wxgh/GHSA-qp9g-233f-wxgh.json | 12 +++--------- .../04/GHSA-qpw8-2v6f-pwj8/GHSA-qpw8-2v6f-pwj8.json | 12 +++--------- .../04/GHSA-qv5j-rh3g-jc8x/GHSA-qv5j-rh3g-jc8x.json | 8 ++------ .../04/GHSA-qw2v-5pqg-mc3r/GHSA-qw2v-5pqg-mc3r.json | 12 +++--------- .../04/GHSA-qxm8-736w-j46q/GHSA-qxm8-736w-j46q.json | 12 +++--------- .../04/GHSA-r2gx-qfm9-9rrq/GHSA-r2gx-qfm9-9rrq.json | 12 +++--------- .../04/GHSA-r4pg-4fjh-q6c6/GHSA-r4pg-4fjh-q6c6.json | 12 +++--------- .../04/GHSA-r56m-86mv-452f/GHSA-r56m-86mv-452f.json | 12 +++--------- .../04/GHSA-r69c-wm2r-fvc6/GHSA-r69c-wm2r-fvc6.json | 12 +++--------- .../04/GHSA-r6hg-vfqv-94j7/GHSA-r6hg-vfqv-94j7.json | 12 +++--------- .../04/GHSA-r7jj-pm2f-3h96/GHSA-r7jj-pm2f-3h96.json | 12 +++--------- .../04/GHSA-rf57-872p-6vwh/GHSA-rf57-872p-6vwh.json | 12 +++--------- .../04/GHSA-rg6w-mfrc-3cqm/GHSA-rg6w-mfrc-3cqm.json | 12 +++--------- .../04/GHSA-rggv-4m8c-3m5j/GHSA-rggv-4m8c-3m5j.json | 8 ++------ .../04/GHSA-rm82-qwv7-jmg6/GHSA-rm82-qwv7-jmg6.json | 12 +++--------- .../04/GHSA-rqm9-wg3h-56w8/GHSA-rqm9-wg3h-56w8.json | 12 +++--------- .../04/GHSA-rww9-f89w-6257/GHSA-rww9-f89w-6257.json | 12 +++--------- .../04/GHSA-rx2f-x8pw-rhg4/GHSA-rx2f-x8pw-rhg4.json | 12 +++--------- .../04/GHSA-v39x-qc8q-rh6g/GHSA-v39x-qc8q-rh6g.json | 12 +++--------- .../04/GHSA-v3rj-h78v-6rg2/GHSA-v3rj-h78v-6rg2.json | 12 +++--------- .../04/GHSA-v47q-96mv-8479/GHSA-v47q-96mv-8479.json | 12 +++--------- .../04/GHSA-v5g5-g755-gf4v/GHSA-v5g5-g755-gf4v.json | 12 +++--------- .../04/GHSA-v64h-8rq4-grgg/GHSA-v64h-8rq4-grgg.json | 12 +++--------- .../04/GHSA-vch7-4w8r-84c6/GHSA-vch7-4w8r-84c6.json | 12 +++--------- .../04/GHSA-vcxc-2pg3-26ww/GHSA-vcxc-2pg3-26ww.json | 12 +++--------- .../04/GHSA-vpmv-x387-37fq/GHSA-vpmv-x387-37fq.json | 12 +++--------- .../04/GHSA-vqp5-459c-mpqx/GHSA-vqp5-459c-mpqx.json | 12 +++--------- .../04/GHSA-w3c8-c6wv-46cf/GHSA-w3c8-c6wv-46cf.json | 12 +++--------- .../04/GHSA-w3j9-383p-8723/GHSA-w3j9-383p-8723.json | 12 +++--------- .../04/GHSA-w468-9c9j-8x8w/GHSA-w468-9c9j-8x8w.json | 12 +++--------- .../04/GHSA-w46j-qhph-4m5p/GHSA-w46j-qhph-4m5p.json | 12 +++--------- .../04/GHSA-w49w-x35m-8jvm/GHSA-w49w-x35m-8jvm.json | 12 +++--------- .../04/GHSA-wcg5-3v2j-2jwv/GHSA-wcg5-3v2j-2jwv.json | 12 +++--------- .../04/GHSA-wch8-9qmv-rh9x/GHSA-wch8-9qmv-rh9x.json | 12 +++--------- .../04/GHSA-wchf-87v9-mpjf/GHSA-wchf-87v9-mpjf.json | 12 +++--------- .../04/GHSA-wgg7-hq2q-9g57/GHSA-wgg7-hq2q-9g57.json | 12 +++--------- .../04/GHSA-wgvf-8g6v-pm8p/GHSA-wgvf-8g6v-pm8p.json | 12 +++--------- .../04/GHSA-wmq7-p773-jmqg/GHSA-wmq7-p773-jmqg.json | 12 +++--------- .../04/GHSA-wmwf-3w9p-w4cj/GHSA-wmwf-3w9p-w4cj.json | 12 +++--------- .../04/GHSA-wp4f-j236-w785/GHSA-wp4f-j236-w785.json | 12 +++--------- .../04/GHSA-wx56-xj4w-qc5p/GHSA-wx56-xj4w-qc5p.json | 12 +++--------- .../04/GHSA-wx88-723w-mp25/GHSA-wx88-723w-mp25.json | 12 +++--------- .../04/GHSA-wxg9-35f2-vw25/GHSA-wxg9-35f2-vw25.json | 8 ++------ .../04/GHSA-x2pj-7r2v-7334/GHSA-x2pj-7r2v-7334.json | 12 +++--------- .../04/GHSA-x37q-rf4q-x5w3/GHSA-x37q-rf4q-x5w3.json | 12 +++--------- .../04/GHSA-x3qm-9gh7-w9w5/GHSA-x3qm-9gh7-w9w5.json | 12 +++--------- .../04/GHSA-x4gh-8p78-vxxx/GHSA-x4gh-8p78-vxxx.json | 12 +++--------- .../04/GHSA-x4gm-q74w-h727/GHSA-x4gm-q74w-h727.json | 12 +++--------- .../04/GHSA-x8pj-r335-vm92/GHSA-x8pj-r335-vm92.json | 12 +++--------- .../04/GHSA-xch8-9g2h-gjrm/GHSA-xch8-9g2h-gjrm.json | 12 +++--------- .../04/GHSA-xh44-f8rg-h6h3/GHSA-xh44-f8rg-h6h3.json | 12 +++--------- .../04/GHSA-xh54-hh7j-wm53/GHSA-xh54-hh7j-wm53.json | 12 +++--------- .../04/GHSA-xm9q-wvh7-2637/GHSA-xm9q-wvh7-2637.json | 12 +++--------- .../04/GHSA-xmgq-gq24-73mw/GHSA-xmgq-gq24-73mw.json | 12 +++--------- .../04/GHSA-xr84-px4q-9chh/GHSA-xr84-px4q-9chh.json | 12 +++--------- .../04/GHSA-xvj4-j4pc-f2wp/GHSA-xvj4-j4pc-f2wp.json | 12 +++--------- .../04/GHSA-xvrp-vp23-p3wp/GHSA-xvrp-vp23-p3wp.json | 12 +++--------- .../04/GHSA-xw5j-6ccc-rwh9/GHSA-xw5j-6ccc-rwh9.json | 12 +++--------- .../04/GHSA-xwhm-gpc5-8rh4/GHSA-xwhm-gpc5-8rh4.json | 12 +++--------- .../05/GHSA-22vf-qc4p-vc3x/GHSA-22vf-qc4p-vc3x.json | 4 +--- .../05/GHSA-24c4-w46m-qj98/GHSA-24c4-w46m-qj98.json | 8 ++------ .../05/GHSA-25cq-vrf7-vjqr/GHSA-25cq-vrf7-vjqr.json | 8 ++------ .../05/GHSA-27xm-pjj9-xmm8/GHSA-27xm-pjj9-xmm8.json | 8 ++------ .../05/GHSA-28vx-6729-qmmp/GHSA-28vx-6729-qmmp.json | 8 ++------ .../05/GHSA-2cwm-q4rq-7594/GHSA-2cwm-q4rq-7594.json | 4 +--- .../05/GHSA-2fc5-f5mf-j7xp/GHSA-2fc5-f5mf-j7xp.json | 8 ++------ .../05/GHSA-2fh3-xg72-f7vx/GHSA-2fh3-xg72-f7vx.json | 8 ++------ .../05/GHSA-2fqw-v698-338m/GHSA-2fqw-v698-338m.json | 8 ++------ .../05/GHSA-2g4x-fv7q-8jrf/GHSA-2g4x-fv7q-8jrf.json | 8 ++------ .../05/GHSA-2jfm-367p-85fj/GHSA-2jfm-367p-85fj.json | 12 +++--------- .../05/GHSA-2q3x-mqw8-qf9r/GHSA-2q3x-mqw8-qf9r.json | 8 ++------ .../05/GHSA-2q4h-h5jp-942w/GHSA-2q4h-h5jp-942w.json | 4 +--- .../05/GHSA-2qp5-r446-qvgh/GHSA-2qp5-r446-qvgh.json | 8 ++------ .../05/GHSA-2r9h-7mx9-fq3w/GHSA-2r9h-7mx9-fq3w.json | 8 ++------ .../05/GHSA-2rff-cr3q-94jm/GHSA-2rff-cr3q-94jm.json | 8 ++------ .../05/GHSA-2vrq-x473-q93m/GHSA-2vrq-x473-q93m.json | 8 ++------ .../05/GHSA-2w55-f536-w4g7/GHSA-2w55-f536-w4g7.json | 12 +++--------- .../05/GHSA-2xjp-jvqv-hvj5/GHSA-2xjp-jvqv-hvj5.json | 8 ++------ .../05/GHSA-322w-f24m-rgpr/GHSA-322w-f24m-rgpr.json | 8 ++------ .../05/GHSA-3254-79q7-7q66/GHSA-3254-79q7-7q66.json | 8 ++------ .../05/GHSA-3267-pg8g-jq86/GHSA-3267-pg8g-jq86.json | 8 ++------ .../05/GHSA-333m-gvxr-m7wp/GHSA-333m-gvxr-m7wp.json | 8 ++------ .../05/GHSA-343m-7rjc-p5gc/GHSA-343m-7rjc-p5gc.json | 8 ++------ .../05/GHSA-34p8-x6j6-mmg5/GHSA-34p8-x6j6-mmg5.json | 8 ++------ .../05/GHSA-34v3-f2p3-76vj/GHSA-34v3-f2p3-76vj.json | 8 ++------ .../05/GHSA-3645-fcrm-r5v6/GHSA-3645-fcrm-r5v6.json | 8 ++------ .../05/GHSA-374q-g769-jjp8/GHSA-374q-g769-jjp8.json | 8 ++------ .../05/GHSA-377v-3m99-jhrj/GHSA-377v-3m99-jhrj.json | 8 ++------ .../05/GHSA-38pq-5c2r-6qhj/GHSA-38pq-5c2r-6qhj.json | 8 ++------ .../05/GHSA-39w5-xc9g-jj4c/GHSA-39w5-xc9g-jj4c.json | 8 ++------ .../05/GHSA-3c8w-cf3r-86mw/GHSA-3c8w-cf3r-86mw.json | 8 ++------ .../05/GHSA-3cqm-mf7h-prrj/GHSA-3cqm-mf7h-prrj.json | 8 ++------ .../05/GHSA-3f43-7g52-2f66/GHSA-3f43-7g52-2f66.json | 8 ++------ .../05/GHSA-3f4c-grv3-wwg8/GHSA-3f4c-grv3-wwg8.json | 8 ++------ .../05/GHSA-3g7h-g298-pwxf/GHSA-3g7h-g298-pwxf.json | 4 +--- .../05/GHSA-3gc8-mch5-55gq/GHSA-3gc8-mch5-55gq.json | 8 ++------ .../05/GHSA-3grx-q7gc-c986/GHSA-3grx-q7gc-c986.json | 4 +--- .../05/GHSA-3gx6-9g98-g4w5/GHSA-3gx6-9g98-g4w5.json | 8 ++------ .../05/GHSA-3hfm-p6g2-9fv7/GHSA-3hfm-p6g2-9fv7.json | 8 ++------ .../05/GHSA-3j62-674q-3jr2/GHSA-3j62-674q-3jr2.json | 8 ++------ .../05/GHSA-3jxg-43fv-33j7/GHSA-3jxg-43fv-33j7.json | 8 ++------ .../05/GHSA-3mch-rrc9-vx6v/GHSA-3mch-rrc9-vx6v.json | 8 ++------ .../05/GHSA-3mxg-74vr-rhx5/GHSA-3mxg-74vr-rhx5.json | 8 ++------ .../05/GHSA-3pr9-7mjx-7r2v/GHSA-3pr9-7mjx-7r2v.json | 12 +++--------- .../05/GHSA-3qgh-vv5w-v35w/GHSA-3qgh-vv5w-v35w.json | 12 +++--------- .../05/GHSA-3qr2-pmfh-6mrh/GHSA-3qr2-pmfh-6mrh.json | 4 +--- .../05/GHSA-3v34-4mg9-5rvc/GHSA-3v34-4mg9-5rvc.json | 8 ++------ .../05/GHSA-3v75-r9p2-79hc/GHSA-3v75-r9p2-79hc.json | 8 ++------ .../05/GHSA-3w29-4qp5-cwmc/GHSA-3w29-4qp5-cwmc.json | 8 ++------ .../05/GHSA-3xq9-pprq-hm99/GHSA-3xq9-pprq-hm99.json | 8 ++------ .../05/GHSA-43rc-rp87-3q62/GHSA-43rc-rp87-3q62.json | 8 ++------ .../05/GHSA-462j-78vj-jjpr/GHSA-462j-78vj-jjpr.json | 8 ++------ .../05/GHSA-46ch-m2h6-h4rg/GHSA-46ch-m2h6-h4rg.json | 8 ++------ .../05/GHSA-4gwr-3v6m-22jj/GHSA-4gwr-3v6m-22jj.json | 8 ++------ .../05/GHSA-4h45-9hf5-qr48/GHSA-4h45-9hf5-qr48.json | 8 ++------ .../05/GHSA-4j45-pxr4-w4g4/GHSA-4j45-pxr4-w4g4.json | 8 ++------ .../05/GHSA-4j5c-2m58-55rj/GHSA-4j5c-2m58-55rj.json | 8 ++------ .../05/GHSA-4jwv-8x37-cg8x/GHSA-4jwv-8x37-cg8x.json | 8 ++------ .../05/GHSA-4qgw-rh8c-x346/GHSA-4qgw-rh8c-x346.json | 8 ++------ .../05/GHSA-4rm9-2w34-7q9c/GHSA-4rm9-2w34-7q9c.json | 12 +++--------- .../05/GHSA-4rqr-r9fv-8h9h/GHSA-4rqr-r9fv-8h9h.json | 12 +++--------- .../05/GHSA-4vj5-f3fw-frfg/GHSA-4vj5-f3fw-frfg.json | 8 ++------ .../05/GHSA-4w3j-8fcj-qpw3/GHSA-4w3j-8fcj-qpw3.json | 8 ++------ .../05/GHSA-4whm-cvqv-v84q/GHSA-4whm-cvqv-v84q.json | 8 ++------ .../05/GHSA-4wpc-25h6-9fv9/GHSA-4wpc-25h6-9fv9.json | 12 +++--------- .../05/GHSA-4wv8-p854-pjqv/GHSA-4wv8-p854-pjqv.json | 8 ++------ .../05/GHSA-4x35-7764-9cfw/GHSA-4x35-7764-9cfw.json | 8 ++------ .../05/GHSA-4x8r-m22r-9c3q/GHSA-4x8r-m22r-9c3q.json | 8 ++------ .../05/GHSA-52j7-8765-3p92/GHSA-52j7-8765-3p92.json | 12 +++--------- .../05/GHSA-532m-87rc-7fjr/GHSA-532m-87rc-7fjr.json | 8 ++------ .../05/GHSA-53h4-8f3m-4f7g/GHSA-53h4-8f3m-4f7g.json | 8 ++------ .../05/GHSA-57c4-wp4f-79x5/GHSA-57c4-wp4f-79x5.json | 8 ++------ .../05/GHSA-58fg-773m-4wg4/GHSA-58fg-773m-4wg4.json | 8 ++------ .../05/GHSA-58vg-3p49-w6xp/GHSA-58vg-3p49-w6xp.json | 8 ++------ .../05/GHSA-5c78-cfx6-pmjr/GHSA-5c78-cfx6-pmjr.json | 8 ++------ .../05/GHSA-5fx6-f253-w3m2/GHSA-5fx6-f253-w3m2.json | 4 +--- .../05/GHSA-5gm6-26g2-phh5/GHSA-5gm6-26g2-phh5.json | 8 ++------ .../05/GHSA-5gvf-qj79-739q/GHSA-5gvf-qj79-739q.json | 8 ++------ .../05/GHSA-5gvx-3w5q-25pr/GHSA-5gvx-3w5q-25pr.json | 4 +--- .../05/GHSA-5gxr-gv2r-m44r/GHSA-5gxr-gv2r-m44r.json | 8 ++------ .../05/GHSA-5h52-gmwr-v7x9/GHSA-5h52-gmwr-v7x9.json | 8 ++------ .../05/GHSA-5h92-x9q3-8crw/GHSA-5h92-x9q3-8crw.json | 8 ++------ .../05/GHSA-5jqg-4r55-wmrg/GHSA-5jqg-4r55-wmrg.json | 8 ++------ .../05/GHSA-5jwx-hvg3-jjjv/GHSA-5jwx-hvg3-jjjv.json | 12 +++--------- .../05/GHSA-5q4j-m9xf-3h9q/GHSA-5q4j-m9xf-3h9q.json | 8 ++------ .../05/GHSA-5qwm-rcv7-qqcf/GHSA-5qwm-rcv7-qqcf.json | 8 ++------ .../05/GHSA-5v3r-grx9-p339/GHSA-5v3r-grx9-p339.json | 8 ++------ .../05/GHSA-5w8c-rf58-5848/GHSA-5w8c-rf58-5848.json | 8 ++------ .../05/GHSA-5wf6-65f3-xqcr/GHSA-5wf6-65f3-xqcr.json | 8 ++------ .../05/GHSA-5wmw-m5w7-7m5m/GHSA-5wmw-m5w7-7m5m.json | 4 +--- .../05/GHSA-5wq8-r82h-2qqc/GHSA-5wq8-r82h-2qqc.json | 8 ++------ .../05/GHSA-5x49-f55r-f2xh/GHSA-5x49-f55r-f2xh.json | 8 ++------ .../05/GHSA-63m6-f6rf-rv75/GHSA-63m6-f6rf-rv75.json | 4 +--- .../05/GHSA-65gq-4xqv-wqf4/GHSA-65gq-4xqv-wqf4.json | 8 ++------ .../05/GHSA-65mr-xqpw-r9xg/GHSA-65mr-xqpw-r9xg.json | 8 ++------ .../05/GHSA-66g6-j5w9-xwv2/GHSA-66g6-j5w9-xwv2.json | 8 ++------ .../05/GHSA-679f-x4g5-488c/GHSA-679f-x4g5-488c.json | 8 ++------ .../05/GHSA-67j3-q5rv-5gjr/GHSA-67j3-q5rv-5gjr.json | 8 ++------ .../05/GHSA-68cg-fr87-52jj/GHSA-68cg-fr87-52jj.json | 8 ++------ .../05/GHSA-68w8-f4j3-2jrq/GHSA-68w8-f4j3-2jrq.json | 8 ++------ .../05/GHSA-6c98-7x6w-rx39/GHSA-6c98-7x6w-rx39.json | 8 ++------ .../05/GHSA-6f25-qpmr-jpgc/GHSA-6f25-qpmr-jpgc.json | 8 ++------ .../05/GHSA-6f56-qgf6-vv2x/GHSA-6f56-qgf6-vv2x.json | 8 ++------ .../05/GHSA-6f5w-25p4-xq44/GHSA-6f5w-25p4-xq44.json | 8 ++------ .../05/GHSA-6f6h-7jf2-x4vp/GHSA-6f6h-7jf2-x4vp.json | 8 ++------ .../05/GHSA-6fjc-q4q2-mv97/GHSA-6fjc-q4q2-mv97.json | 8 ++------ .../05/GHSA-6fxj-c35j-cj8x/GHSA-6fxj-c35j-cj8x.json | 8 ++------ .../05/GHSA-6g6q-c7q8-8r7m/GHSA-6g6q-c7q8-8r7m.json | 8 ++------ .../05/GHSA-6gvq-w4vx-qjr3/GHSA-6gvq-w4vx-qjr3.json | 8 ++------ .../05/GHSA-6hqj-g24g-vjcr/GHSA-6hqj-g24g-vjcr.json | 4 +--- .../05/GHSA-6hx5-9q4p-p96w/GHSA-6hx5-9q4p-p96w.json | 8 ++------ .../05/GHSA-6phg-5gjc-53gj/GHSA-6phg-5gjc-53gj.json | 8 ++------ .../05/GHSA-6phq-rjgc-62hr/GHSA-6phq-rjgc-62hr.json | 4 +--- .../05/GHSA-6pmc-4qj8-52q7/GHSA-6pmc-4qj8-52q7.json | 8 ++------ .../05/GHSA-6qj7-98xg-fpgf/GHSA-6qj7-98xg-fpgf.json | 8 ++------ .../05/GHSA-6rg3-pxqw-2fqw/GHSA-6rg3-pxqw-2fqw.json | 8 ++------ .../05/GHSA-6vgx-p4v6-c459/GHSA-6vgx-p4v6-c459.json | 12 +++--------- .../05/GHSA-6vjm-mvmh-r6hx/GHSA-6vjm-mvmh-r6hx.json | 8 ++------ .../05/GHSA-6x7w-v26q-jfv3/GHSA-6x7w-v26q-jfv3.json | 8 ++------ .../05/GHSA-6xx4-8wj3-477v/GHSA-6xx4-8wj3-477v.json | 8 ++------ .../05/GHSA-74m2-4qpm-x6vm/GHSA-74m2-4qpm-x6vm.json | 8 ++------ .../05/GHSA-74wv-xgwp-h8mf/GHSA-74wv-xgwp-h8mf.json | 8 ++------ .../05/GHSA-75hw-pggw-3xwh/GHSA-75hw-pggw-3xwh.json | 8 ++------ .../05/GHSA-75j3-4jfq-x36j/GHSA-75j3-4jfq-x36j.json | 8 ++------ .../05/GHSA-76j8-m22q-r2r6/GHSA-76j8-m22q-r2r6.json | 8 ++------ .../05/GHSA-76q4-85fh-5fj7/GHSA-76q4-85fh-5fj7.json | 8 ++------ .../05/GHSA-77q3-9j2v-49q7/GHSA-77q3-9j2v-49q7.json | 8 ++------ .../05/GHSA-79c7-7x2r-rmwf/GHSA-79c7-7x2r-rmwf.json | 8 ++------ .../05/GHSA-7c3h-wh3g-298c/GHSA-7c3h-wh3g-298c.json | 8 ++------ .../05/GHSA-7f6f-mqg7-656v/GHSA-7f6f-mqg7-656v.json | 8 ++------ .../05/GHSA-7fjh-g2fp-mqf5/GHSA-7fjh-g2fp-mqf5.json | 12 +++--------- .../05/GHSA-7fjp-x968-hg59/GHSA-7fjp-x968-hg59.json | 8 ++------ .../05/GHSA-7fxc-vwm3-9www/GHSA-7fxc-vwm3-9www.json | 8 ++------ .../05/GHSA-7g5q-hmw7-26pf/GHSA-7g5q-hmw7-26pf.json | 12 +++--------- .../05/GHSA-7h6h-hrf8-cc7v/GHSA-7h6h-hrf8-cc7v.json | 8 ++------ .../05/GHSA-7h7m-5mrv-qfq7/GHSA-7h7m-5mrv-qfq7.json | 8 ++------ .../05/GHSA-7hf7-68wx-vrmr/GHSA-7hf7-68wx-vrmr.json | 8 ++------ .../05/GHSA-7hqh-xccf-8jp4/GHSA-7hqh-xccf-8jp4.json | 4 +--- .../05/GHSA-7hxp-qqjp-qjxm/GHSA-7hxp-qqjp-qjxm.json | 8 ++------ .../05/GHSA-7mrx-fcmq-phm5/GHSA-7mrx-fcmq-phm5.json | 8 ++------ .../05/GHSA-7p97-3339-fvgr/GHSA-7p97-3339-fvgr.json | 4 +--- .../05/GHSA-7pq5-98ww-5q49/GHSA-7pq5-98ww-5q49.json | 8 ++------ .../05/GHSA-7r29-w7vh-5p6q/GHSA-7r29-w7vh-5p6q.json | 8 ++------ .../05/GHSA-7v4q-3ch3-mjc7/GHSA-7v4q-3ch3-mjc7.json | 8 ++------ .../05/GHSA-7vqm-5368-jjhq/GHSA-7vqm-5368-jjhq.json | 8 ++------ .../05/GHSA-7wxw-m8h3-2r28/GHSA-7wxw-m8h3-2r28.json | 8 ++------ .../05/GHSA-8279-2hh7-mpv3/GHSA-8279-2hh7-mpv3.json | 8 ++------ .../05/GHSA-82wg-r3hg-qxj2/GHSA-82wg-r3hg-qxj2.json | 8 ++------ .../05/GHSA-83v3-rq53-m428/GHSA-83v3-rq53-m428.json | 8 ++------ .../05/GHSA-84v7-x658-c2jw/GHSA-84v7-x658-c2jw.json | 8 ++------ .../05/GHSA-85r2-3v9j-hfrq/GHSA-85r2-3v9j-hfrq.json | 8 ++------ .../05/GHSA-8768-8f2m-79g9/GHSA-8768-8f2m-79g9.json | 8 ++------ .../05/GHSA-8777-qhx4-g86w/GHSA-8777-qhx4-g86w.json | 8 ++------ .../05/GHSA-8899-pjpj-8p5v/GHSA-8899-pjpj-8p5v.json | 8 ++------ .../05/GHSA-88p8-mprp-j235/GHSA-88p8-mprp-j235.json | 8 ++------ .../05/GHSA-88w2-cjhc-67m3/GHSA-88w2-cjhc-67m3.json | 8 ++------ .../05/GHSA-88xq-4322-8jj4/GHSA-88xq-4322-8jj4.json | 8 ++------ .../05/GHSA-899f-9gpg-r429/GHSA-899f-9gpg-r429.json | 8 ++------ .../05/GHSA-89g3-4g4h-p92v/GHSA-89g3-4g4h-p92v.json | 8 ++------ .../05/GHSA-8c4j-frh5-89w4/GHSA-8c4j-frh5-89w4.json | 8 ++------ .../05/GHSA-8cg3-m5v9-gvh4/GHSA-8cg3-m5v9-gvh4.json | 4 +--- .../05/GHSA-8mmr-6pqj-frmr/GHSA-8mmr-6pqj-frmr.json | 12 +++--------- .../05/GHSA-8mvr-j92p-v42j/GHSA-8mvr-j92p-v42j.json | 8 ++------ .../05/GHSA-8p6j-7r63-99v9/GHSA-8p6j-7r63-99v9.json | 4 +--- .../05/GHSA-8pqc-794r-q3c3/GHSA-8pqc-794r-q3c3.json | 8 ++------ .../05/GHSA-8q43-j9qm-qm7q/GHSA-8q43-j9qm-qm7q.json | 8 ++------ .../05/GHSA-8q7x-wx54-w95j/GHSA-8q7x-wx54-w95j.json | 8 ++------ .../05/GHSA-8qcw-8pjv-4qj8/GHSA-8qcw-8pjv-4qj8.json | 8 ++------ .../05/GHSA-8qg8-6crq-4q3h/GHSA-8qg8-6crq-4q3h.json | 8 ++------ .../05/GHSA-8qwm-6624-jhvr/GHSA-8qwm-6624-jhvr.json | 8 ++------ .../05/GHSA-8r42-h5pm-2vw2/GHSA-8r42-h5pm-2vw2.json | 8 ++------ .../05/GHSA-8r95-q845-45m7/GHSA-8r95-q845-45m7.json | 8 ++------ .../05/GHSA-8vm8-c58w-96hq/GHSA-8vm8-c58w-96hq.json | 8 ++------ .../05/GHSA-8ww2-j39p-q769/GHSA-8ww2-j39p-q769.json | 8 ++------ .../05/GHSA-8wxp-wp4j-j684/GHSA-8wxp-wp4j-j684.json | 8 ++------ .../05/GHSA-8x6h-69qf-c7v6/GHSA-8x6h-69qf-c7v6.json | 8 ++------ .../05/GHSA-93r8-x5g7-g7fh/GHSA-93r8-x5g7-g7fh.json | 8 ++------ .../05/GHSA-972w-3xcp-6vcv/GHSA-972w-3xcp-6vcv.json | 4 +--- .../05/GHSA-977w-cv9x-3pr9/GHSA-977w-cv9x-3pr9.json | 8 ++------ .../05/GHSA-9978-p96m-85pj/GHSA-9978-p96m-85pj.json | 4 +--- .../05/GHSA-99j6-pf9p-h77c/GHSA-99j6-pf9p-h77c.json | 4 +--- .../05/GHSA-9c25-9784-774x/GHSA-9c25-9784-774x.json | 8 ++------ .../05/GHSA-9c64-5jjg-w2cj/GHSA-9c64-5jjg-w2cj.json | 8 ++------ .../05/GHSA-9cjc-gp3w-7hf2/GHSA-9cjc-gp3w-7hf2.json | 8 ++------ .../05/GHSA-9h57-vmqg-5rrw/GHSA-9h57-vmqg-5rrw.json | 8 ++------ .../05/GHSA-9hpv-r424-hr95/GHSA-9hpv-r424-hr95.json | 8 ++------ .../05/GHSA-9mrp-7cm9-xqxq/GHSA-9mrp-7cm9-xqxq.json | 8 ++------ .../05/GHSA-9pf8-h538-2p8j/GHSA-9pf8-h538-2p8j.json | 8 ++------ .../05/GHSA-9qvw-hfpr-cvx6/GHSA-9qvw-hfpr-cvx6.json | 4 +--- .../05/GHSA-9r6g-h7wj-fxhp/GHSA-9r6g-h7wj-fxhp.json | 8 ++------ .../05/GHSA-9rfj-vjc2-f7cj/GHSA-9rfj-vjc2-f7cj.json | 8 ++------ .../05/GHSA-9rrj-w544-7vw9/GHSA-9rrj-w544-7vw9.json | 8 ++------ .../05/GHSA-9v38-f7c4-w54w/GHSA-9v38-f7c4-w54w.json | 8 ++------ .../05/GHSA-9vc6-7g98-392v/GHSA-9vc6-7g98-392v.json | 8 ++------ .../05/GHSA-9vvj-c5q4-cg3m/GHSA-9vvj-c5q4-cg3m.json | 8 ++------ .../05/GHSA-9w8f-hpgh-vxjr/GHSA-9w8f-hpgh-vxjr.json | 8 ++------ .../05/GHSA-c258-vh6c-2m44/GHSA-c258-vh6c-2m44.json | 8 ++------ .../05/GHSA-c283-6775-92m9/GHSA-c283-6775-92m9.json | 8 ++------ .../05/GHSA-c375-qwv9-rx4w/GHSA-c375-qwv9-rx4w.json | 8 ++------ .../05/GHSA-c52j-mfvx-x96x/GHSA-c52j-mfvx-x96x.json | 8 ++------ .../05/GHSA-c54w-4pvq-9rmg/GHSA-c54w-4pvq-9rmg.json | 8 ++------ .../05/GHSA-c5c5-mvqf-5f35/GHSA-c5c5-mvqf-5f35.json | 8 ++------ .../05/GHSA-c5v8-j47m-hqhf/GHSA-c5v8-j47m-hqhf.json | 8 ++------ .../05/GHSA-c6h8-w7qx-qj83/GHSA-c6h8-w7qx-qj83.json | 8 ++------ .../05/GHSA-c845-j93q-wvrw/GHSA-c845-j93q-wvrw.json | 8 ++------ .../05/GHSA-c85w-5xgr-3j3p/GHSA-c85w-5xgr-3j3p.json | 8 ++------ .../05/GHSA-c9cq-84w8-7r7f/GHSA-c9cq-84w8-7r7f.json | 8 ++------ .../05/GHSA-c9qm-rxm9-v737/GHSA-c9qm-rxm9-v737.json | 8 ++------ .../05/GHSA-ccp4-42w5-9q8g/GHSA-ccp4-42w5-9q8g.json | 4 +--- .../05/GHSA-cf46-h25j-9pmq/GHSA-cf46-h25j-9pmq.json | 8 ++------ .../05/GHSA-cfw7-38q9-9h94/GHSA-cfw7-38q9-9h94.json | 8 ++------ .../05/GHSA-cj3p-75j4-74xf/GHSA-cj3p-75j4-74xf.json | 8 ++------ .../05/GHSA-cjg9-xxpr-fm5g/GHSA-cjg9-xxpr-fm5g.json | 8 ++------ .../05/GHSA-cjrm-ccjq-r9vp/GHSA-cjrm-ccjq-r9vp.json | 4 +--- .../05/GHSA-cmjw-x23c-76gc/GHSA-cmjw-x23c-76gc.json | 4 +--- .../05/GHSA-cmmp-cpgx-vg8v/GHSA-cmmp-cpgx-vg8v.json | 8 ++------ .../05/GHSA-cpp5-h3qh-vqxm/GHSA-cpp5-h3qh-vqxm.json | 8 ++------ .../05/GHSA-cpvw-q5q7-jhr2/GHSA-cpvw-q5q7-jhr2.json | 8 ++------ .../05/GHSA-cr6g-87jv-237p/GHSA-cr6g-87jv-237p.json | 8 ++------ .../05/GHSA-crh9-79wp-32wv/GHSA-crh9-79wp-32wv.json | 8 ++------ .../05/GHSA-cvwc-6hv2-wv97/GHSA-cvwc-6hv2-wv97.json | 8 ++------ .../05/GHSA-cw43-jrgf-36f3/GHSA-cw43-jrgf-36f3.json | 8 ++------ .../05/GHSA-cww6-qwhh-35x7/GHSA-cww6-qwhh-35x7.json | 8 ++------ .../05/GHSA-f2cr-m9p8-6vm2/GHSA-f2cr-m9p8-6vm2.json | 8 ++------ .../05/GHSA-f3f2-q9f6-v9qq/GHSA-f3f2-q9f6-v9qq.json | 8 ++------ .../05/GHSA-f3fh-qqx3-hv26/GHSA-f3fh-qqx3-hv26.json | 8 ++------ .../05/GHSA-f58x-232r-hg99/GHSA-f58x-232r-hg99.json | 8 ++------ .../05/GHSA-f5jj-fmp8-xqh3/GHSA-f5jj-fmp8-xqh3.json | 8 ++------ .../05/GHSA-f5wh-3c43-vf4p/GHSA-f5wh-3c43-vf4p.json | 8 ++------ .../05/GHSA-f7jw-wp22-5cv8/GHSA-f7jw-wp22-5cv8.json | 8 ++------ .../05/GHSA-f7q4-mhgv-m69x/GHSA-f7q4-mhgv-m69x.json | 4 +--- .../05/GHSA-f89f-668c-hrhg/GHSA-f89f-668c-hrhg.json | 8 ++------ .../05/GHSA-f8pq-r7mv-pvxm/GHSA-f8pq-r7mv-pvxm.json | 8 ++------ .../05/GHSA-f8xp-mvx7-pw9c/GHSA-f8xp-mvx7-pw9c.json | 8 ++------ .../05/GHSA-f935-fh29-4mfr/GHSA-f935-fh29-4mfr.json | 8 ++------ .../05/GHSA-f9rw-7p76-h888/GHSA-f9rw-7p76-h888.json | 8 ++------ .../05/GHSA-fcf3-mg82-5g5h/GHSA-fcf3-mg82-5g5h.json | 8 ++------ .../05/GHSA-fcrr-6fjg-7jpj/GHSA-fcrr-6fjg-7jpj.json | 8 ++------ .../05/GHSA-fffm-3rfw-h6pc/GHSA-fffm-3rfw-h6pc.json | 8 ++------ .../05/GHSA-fg9f-2rrg-653x/GHSA-fg9f-2rrg-653x.json | 8 ++------ .../05/GHSA-fg9m-gw92-f74h/GHSA-fg9m-gw92-f74h.json | 8 ++------ .../05/GHSA-fh7q-6m5q-xqp4/GHSA-fh7q-6m5q-xqp4.json | 8 ++------ .../05/GHSA-fjq4-gjv6-rcj2/GHSA-fjq4-gjv6-rcj2.json | 8 ++------ .../05/GHSA-fp2h-7c85-hmf9/GHSA-fp2h-7c85-hmf9.json | 8 ++------ .../05/GHSA-fp4p-g2rg-7x7r/GHSA-fp4p-g2rg-7x7r.json | 8 ++------ .../05/GHSA-fpwv-gp97-jc85/GHSA-fpwv-gp97-jc85.json | 8 ++------ .../05/GHSA-frr5-fmjm-627j/GHSA-frr5-fmjm-627j.json | 12 +++--------- .../05/GHSA-fv88-77rc-98g3/GHSA-fv88-77rc-98g3.json | 8 ++------ .../05/GHSA-fvj3-9fpr-ff7m/GHSA-fvj3-9fpr-ff7m.json | 8 ++------ .../05/GHSA-fx3j-9hj4-xrxm/GHSA-fx3j-9hj4-xrxm.json | 8 ++------ .../05/GHSA-g2hf-3hh4-qwxq/GHSA-g2hf-3hh4-qwxq.json | 8 ++------ .../05/GHSA-g2w2-8h95-w988/GHSA-g2w2-8h95-w988.json | 8 ++------ .../05/GHSA-g32x-jfqv-9fpx/GHSA-g32x-jfqv-9fpx.json | 8 ++------ .../05/GHSA-g437-q829-mh8h/GHSA-g437-q829-mh8h.json | 8 ++------ .../05/GHSA-g5mc-mhmx-jqjp/GHSA-g5mc-mhmx-jqjp.json | 4 +--- .../05/GHSA-g6g4-c6r4-f4jc/GHSA-g6g4-c6r4-f4jc.json | 8 ++------ .../05/GHSA-g7mx-vgq4-79gg/GHSA-g7mx-vgq4-79gg.json | 8 ++------ .../05/GHSA-g8rv-4ccg-wc6m/GHSA-g8rv-4ccg-wc6m.json | 8 ++------ .../05/GHSA-g985-xxfj-53g5/GHSA-g985-xxfj-53g5.json | 8 ++------ .../05/GHSA-gcqr-886q-fwf9/GHSA-gcqr-886q-fwf9.json | 8 ++------ .../05/GHSA-gfvh-r99j-x28p/GHSA-gfvh-r99j-x28p.json | 8 ++------ .../05/GHSA-gg53-8j8x-fvvp/GHSA-gg53-8j8x-fvvp.json | 8 ++------ .../05/GHSA-gg79-jh7g-xcx7/GHSA-gg79-jh7g-xcx7.json | 8 ++------ .../05/GHSA-gg7q-8hj5-8hp8/GHSA-gg7q-8hj5-8hp8.json | 8 ++------ .../05/GHSA-gh27-3g6v-xxcm/GHSA-gh27-3g6v-xxcm.json | 12 +++--------- .../05/GHSA-gh2p-5gr5-j5g9/GHSA-gh2p-5gr5-j5g9.json | 12 +++--------- .../05/GHSA-gjr3-77hh-vh3q/GHSA-gjr3-77hh-vh3q.json | 8 ++------ .../05/GHSA-gm38-v6gv-jm89/GHSA-gm38-v6gv-jm89.json | 8 ++------ .../05/GHSA-gm82-r7hx-vc9c/GHSA-gm82-r7hx-vc9c.json | 8 ++------ .../05/GHSA-gmfw-w846-fjh2/GHSA-gmfw-w846-fjh2.json | 8 ++------ .../05/GHSA-gmww-6r9f-5rpf/GHSA-gmww-6r9f-5rpf.json | 8 ++------ .../05/GHSA-gp7f-w798-4853/GHSA-gp7f-w798-4853.json | 8 ++------ .../05/GHSA-gr5v-7hm2-h3j8/GHSA-gr5v-7hm2-h3j8.json | 12 +++--------- .../05/GHSA-grv3-9mhw-h88m/GHSA-grv3-9mhw-h88m.json | 8 ++------ .../05/GHSA-grv9-44cv-g58h/GHSA-grv9-44cv-g58h.json | 8 ++------ .../05/GHSA-gvrm-92xp-96pf/GHSA-gvrm-92xp-96pf.json | 8 ++------ .../05/GHSA-gwpc-pw6r-jqv7/GHSA-gwpc-pw6r-jqv7.json | 8 ++------ .../05/GHSA-h25v-w22w-w3pj/GHSA-h25v-w22w-w3pj.json | 8 ++------ .../05/GHSA-h28g-q2hc-6vr6/GHSA-h28g-q2hc-6vr6.json | 8 ++------ .../05/GHSA-h376-c6p5-cxvw/GHSA-h376-c6p5-cxvw.json | 8 ++------ .../05/GHSA-h4mf-p43f-8979/GHSA-h4mf-p43f-8979.json | 8 ++------ .../05/GHSA-h583-hm8j-mpm8/GHSA-h583-hm8j-mpm8.json | 4 +--- .../05/GHSA-h76m-vvhh-g679/GHSA-h76m-vvhh-g679.json | 8 ++------ .../05/GHSA-h8q4-9ggw-gcm9/GHSA-h8q4-9ggw-gcm9.json | 8 ++------ .../05/GHSA-h8qj-5334-gf3v/GHSA-h8qj-5334-gf3v.json | 8 ++------ .../05/GHSA-h8qx-36w6-3rc4/GHSA-h8qx-36w6-3rc4.json | 4 +--- .../05/GHSA-h94v-c346-344v/GHSA-h94v-c346-344v.json | 8 ++------ .../05/GHSA-h9hf-qq5m-76px/GHSA-h9hf-qq5m-76px.json | 8 ++------ .../05/GHSA-h9wv-3h63-q247/GHSA-h9wv-3h63-q247.json | 8 ++------ .../05/GHSA-hccv-rqmr-8xqg/GHSA-hccv-rqmr-8xqg.json | 4 +--- .../05/GHSA-hcxg-m989-4j63/GHSA-hcxg-m989-4j63.json | 8 ++------ .../05/GHSA-hfq5-99r6-6f3w/GHSA-hfq5-99r6-6f3w.json | 8 ++------ .../05/GHSA-hg4f-66rp-9985/GHSA-hg4f-66rp-9985.json | 8 ++------ .../05/GHSA-hgpj-7pfx-q3m9/GHSA-hgpj-7pfx-q3m9.json | 8 ++------ .../05/GHSA-hhgr-rpp9-9whw/GHSA-hhgr-rpp9-9whw.json | 8 ++------ .../05/GHSA-hhm3-x3q6-2xcg/GHSA-hhm3-x3q6-2xcg.json | 8 ++------ .../05/GHSA-hhrw-95rc-7773/GHSA-hhrw-95rc-7773.json | 8 ++------ .../05/GHSA-hj7r-x65q-qw8p/GHSA-hj7r-x65q-qw8p.json | 8 ++------ .../05/GHSA-hj87-9mrp-3rp8/GHSA-hj87-9mrp-3rp8.json | 8 ++------ .../05/GHSA-hphj-4pmp-q6gf/GHSA-hphj-4pmp-q6gf.json | 8 ++------ .../05/GHSA-hpqm-3mvx-vj45/GHSA-hpqm-3mvx-vj45.json | 8 ++------ .../05/GHSA-hprp-8mpx-26q9/GHSA-hprp-8mpx-26q9.json | 8 ++------ .../05/GHSA-hqmr-r48f-jfqq/GHSA-hqmr-r48f-jfqq.json | 8 ++------ .../05/GHSA-hrm7-r95m-mcv4/GHSA-hrm7-r95m-mcv4.json | 8 ++------ .../05/GHSA-hvcx-w6jp-qm72/GHSA-hvcx-w6jp-qm72.json | 8 ++------ .../05/GHSA-hvg7-f66r-gm4v/GHSA-hvg7-f66r-gm4v.json | 8 ++------ .../05/GHSA-hwrm-p2xq-q6hh/GHSA-hwrm-p2xq-q6hh.json | 8 ++------ .../05/GHSA-hx4m-5mj9-4q84/GHSA-hx4m-5mj9-4q84.json | 4 +--- .../05/GHSA-hxf4-fh6h-hq94/GHSA-hxf4-fh6h-hq94.json | 8 ++------ .../05/GHSA-j542-2x58-5jg4/GHSA-j542-2x58-5jg4.json | 8 ++------ .../05/GHSA-j58q-jg6x-x4h9/GHSA-j58q-jg6x-x4h9.json | 8 ++------ .../05/GHSA-j599-c89v-j989/GHSA-j599-c89v-j989.json | 4 +--- .../05/GHSA-j5hw-64m5-6442/GHSA-j5hw-64m5-6442.json | 8 ++------ .../05/GHSA-j7hh-h4p5-vc2f/GHSA-j7hh-h4p5-vc2f.json | 8 ++------ .../05/GHSA-j8vm-wc3g-mg6q/GHSA-j8vm-wc3g-mg6q.json | 8 ++------ .../05/GHSA-jc6g-647j-w9g6/GHSA-jc6g-647j-w9g6.json | 8 ++------ .../05/GHSA-jf37-28x2-7p23/GHSA-jf37-28x2-7p23.json | 8 ++------ .../05/GHSA-jfrg-jw53-7cx6/GHSA-jfrg-jw53-7cx6.json | 8 ++------ .../05/GHSA-jg2g-jq85-v7jw/GHSA-jg2g-jq85-v7jw.json | 8 ++------ .../05/GHSA-jgrv-p7rc-9f92/GHSA-jgrv-p7rc-9f92.json | 8 ++------ .../05/GHSA-jj2g-rjph-qhjr/GHSA-jj2g-rjph-qhjr.json | 12 +++--------- .../05/GHSA-jj87-p2gw-m6qq/GHSA-jj87-p2gw-m6qq.json | 8 ++------ .../05/GHSA-jjwh-245w-f2xg/GHSA-jjwh-245w-f2xg.json | 8 ++------ .../05/GHSA-jm2j-8hvq-7r72/GHSA-jm2j-8hvq-7r72.json | 12 +++--------- .../05/GHSA-jmqg-77rm-wvw3/GHSA-jmqg-77rm-wvw3.json | 8 ++------ .../05/GHSA-jp35-qr97-xjcm/GHSA-jp35-qr97-xjcm.json | 4 +--- .../05/GHSA-jppm-4p62-v2cm/GHSA-jppm-4p62-v2cm.json | 8 ++------ .../05/GHSA-jpr2-8h3g-8rc7/GHSA-jpr2-8h3g-8rc7.json | 8 ++------ .../05/GHSA-jq4p-7627-9cwr/GHSA-jq4p-7627-9cwr.json | 12 +++--------- .../05/GHSA-jr6m-ghrv-gqr2/GHSA-jr6m-ghrv-gqr2.json | 8 ++------ .../05/GHSA-jvmc-mjgh-r2hj/GHSA-jvmc-mjgh-r2hj.json | 4 +--- .../05/GHSA-jvxj-9x2f-rj8h/GHSA-jvxj-9x2f-rj8h.json | 8 ++------ .../05/GHSA-m2cf-c967-wmcg/GHSA-m2cf-c967-wmcg.json | 8 ++------ .../05/GHSA-m2f3-4gc2-3wcw/GHSA-m2f3-4gc2-3wcw.json | 4 +--- .../05/GHSA-m2vv-94mg-crph/GHSA-m2vv-94mg-crph.json | 8 ++------ .../05/GHSA-m435-vjxm-8mmm/GHSA-m435-vjxm-8mmm.json | 8 ++------ .../05/GHSA-m459-j5mw-gjwx/GHSA-m459-j5mw-gjwx.json | 12 +++--------- .../05/GHSA-m46p-66jf-359p/GHSA-m46p-66jf-359p.json | 8 ++------ .../05/GHSA-m6m2-gp24-h5jf/GHSA-m6m2-gp24-h5jf.json | 8 ++------ .../05/GHSA-m6q8-v2r4-m7g8/GHSA-m6q8-v2r4-m7g8.json | 8 ++------ .../05/GHSA-m7gv-q624-c5p2/GHSA-m7gv-q624-c5p2.json | 8 ++------ .../05/GHSA-m963-w3jc-59w6/GHSA-m963-w3jc-59w6.json | 8 ++------ .../05/GHSA-mc4x-hxj7-qw79/GHSA-mc4x-hxj7-qw79.json | 8 ++------ .../05/GHSA-mc75-95xp-qm8h/GHSA-mc75-95xp-qm8h.json | 8 ++------ .../05/GHSA-mc8g-ggcr-f8mw/GHSA-mc8g-ggcr-f8mw.json | 8 ++------ .../05/GHSA-mcfg-rxc6-8cwx/GHSA-mcfg-rxc6-8cwx.json | 8 ++------ .../05/GHSA-mcj9-phjm-5g8v/GHSA-mcj9-phjm-5g8v.json | 8 ++------ .../05/GHSA-mf96-wwv9-c857/GHSA-mf96-wwv9-c857.json | 8 ++------ .../05/GHSA-mh5f-wj35-7j92/GHSA-mh5f-wj35-7j92.json | 8 ++------ .../05/GHSA-mj7w-qf57-2p89/GHSA-mj7w-qf57-2p89.json | 8 ++------ .../05/GHSA-mjfh-rmmm-2mm7/GHSA-mjfh-rmmm-2mm7.json | 8 ++------ .../05/GHSA-mpq7-9rx8-2r9g/GHSA-mpq7-9rx8-2r9g.json | 8 ++------ .../05/GHSA-mqxh-622h-wcpq/GHSA-mqxh-622h-wcpq.json | 8 ++------ .../05/GHSA-mrf7-f24r-vmc7/GHSA-mrf7-f24r-vmc7.json | 8 ++------ .../05/GHSA-mvjc-69q9-xg49/GHSA-mvjc-69q9-xg49.json | 12 +++--------- .../05/GHSA-mx9p-p4m9-xg4c/GHSA-mx9p-p4m9-xg4c.json | 8 ++------ .../05/GHSA-p269-cjrj-rq9c/GHSA-p269-cjrj-rq9c.json | 8 ++------ .../05/GHSA-p34g-h4wv-4pj4/GHSA-p34g-h4wv-4pj4.json | 8 ++------ .../05/GHSA-p43g-84w6-pq26/GHSA-p43g-84w6-pq26.json | 8 ++------ .../05/GHSA-p4gx-9mrp-846w/GHSA-p4gx-9mrp-846w.json | 8 ++------ .../05/GHSA-p4j3-3c38-6j6r/GHSA-p4j3-3c38-6j6r.json | 8 ++------ .../05/GHSA-p5r5-rf4r-f8jm/GHSA-p5r5-rf4r-f8jm.json | 4 +--- .../05/GHSA-p5wf-rj4w-hc7f/GHSA-p5wf-rj4w-hc7f.json | 8 ++------ .../05/GHSA-p6rx-8rvc-vf4p/GHSA-p6rx-8rvc-vf4p.json | 4 +--- .../05/GHSA-p8qp-fqw2-crxv/GHSA-p8qp-fqw2-crxv.json | 8 ++------ .../05/GHSA-p922-mm6q-mhxg/GHSA-p922-mm6q-mhxg.json | 8 ++------ .../05/GHSA-p9p8-p6wp-9g6c/GHSA-p9p8-p6wp-9g6c.json | 8 ++------ .../05/GHSA-pcjf-xrw4-4cc2/GHSA-pcjf-xrw4-4cc2.json | 4 +--- .../05/GHSA-pfm5-3wch-g359/GHSA-pfm5-3wch-g359.json | 8 ++------ .../05/GHSA-pgch-x9wq-2944/GHSA-pgch-x9wq-2944.json | 8 ++------ .../05/GHSA-pgg9-mmcg-8mxp/GHSA-pgg9-mmcg-8mxp.json | 8 ++------ .../05/GHSA-pgpr-gp52-wcw9/GHSA-pgpr-gp52-wcw9.json | 8 ++------ .../05/GHSA-phg2-9429-v8rx/GHSA-phg2-9429-v8rx.json | 8 ++------ .../05/GHSA-pj2v-j653-w9v8/GHSA-pj2v-j653-w9v8.json | 8 ++------ .../05/GHSA-pj4h-x8qh-45r9/GHSA-pj4h-x8qh-45r9.json | 8 ++------ .../05/GHSA-pjfv-c533-56m2/GHSA-pjfv-c533-56m2.json | 8 ++------ .../05/GHSA-pqq4-pgj5-fwxq/GHSA-pqq4-pgj5-fwxq.json | 12 +++--------- .../05/GHSA-pr3w-2ff8-48mm/GHSA-pr3w-2ff8-48mm.json | 12 +++--------- .../05/GHSA-prcr-frhq-gm4p/GHSA-prcr-frhq-gm4p.json | 8 ++------ .../05/GHSA-pvm2-wchq-hwv5/GHSA-pvm2-wchq-hwv5.json | 8 ++------ .../05/GHSA-pvwf-p3gj-cccj/GHSA-pvwf-p3gj-cccj.json | 4 +--- .../05/GHSA-pxp2-gjpv-xjrc/GHSA-pxp2-gjpv-xjrc.json | 8 ++------ .../05/GHSA-pxx4-4592-hf5h/GHSA-pxx4-4592-hf5h.json | 8 ++------ .../05/GHSA-q2v2-27xw-whh5/GHSA-q2v2-27xw-whh5.json | 8 ++------ .../05/GHSA-q2xf-jvwq-327h/GHSA-q2xf-jvwq-327h.json | 8 ++------ .../05/GHSA-q4x8-w6fw-v9hh/GHSA-q4x8-w6fw-v9hh.json | 8 ++------ .../05/GHSA-q6jw-34cj-733v/GHSA-q6jw-34cj-733v.json | 8 ++------ .../05/GHSA-q7q9-c33c-p6q4/GHSA-q7q9-c33c-p6q4.json | 8 ++------ .../05/GHSA-q894-2jhh-qq4h/GHSA-q894-2jhh-qq4h.json | 8 ++------ .../05/GHSA-q997-cggx-jg25/GHSA-q997-cggx-jg25.json | 8 ++------ .../05/GHSA-q9rw-rq8v-6r3f/GHSA-q9rw-rq8v-6r3f.json | 8 ++------ .../05/GHSA-qcqh-x84p-358v/GHSA-qcqh-x84p-358v.json | 8 ++------ .../05/GHSA-qfqh-45q8-8425/GHSA-qfqh-45q8-8425.json | 8 ++------ .../05/GHSA-qg9g-c5qj-x44r/GHSA-qg9g-c5qj-x44r.json | 8 ++------ .../05/GHSA-qgg8-6g36-jwfh/GHSA-qgg8-6g36-jwfh.json | 8 ++------ .../05/GHSA-qgx2-cvjx-6vhf/GHSA-qgx2-cvjx-6vhf.json | 8 ++------ .../05/GHSA-qh7g-hfr4-f2f4/GHSA-qh7g-hfr4-f2f4.json | 8 ++------ .../05/GHSA-qhg7-cqr2-qr57/GHSA-qhg7-cqr2-qr57.json | 8 ++------ .../05/GHSA-qhxx-g2fv-w3p4/GHSA-qhxx-g2fv-w3p4.json | 8 ++------ .../05/GHSA-qj3f-9v2m-79rj/GHSA-qj3f-9v2m-79rj.json | 8 ++------ .../05/GHSA-qjvv-qc9h-394h/GHSA-qjvv-qc9h-394h.json | 8 ++------ .../05/GHSA-qp58-fc8h-jpwx/GHSA-qp58-fc8h-jpwx.json | 8 ++------ .../05/GHSA-qppj-hcv6-9fcm/GHSA-qppj-hcv6-9fcm.json | 8 ++------ .../05/GHSA-qpr8-xrx4-f6mx/GHSA-qpr8-xrx4-f6mx.json | 8 ++------ .../05/GHSA-qq5h-7q3j-jh5p/GHSA-qq5h-7q3j-jh5p.json | 8 ++------ .../05/GHSA-qwpm-85r5-4m77/GHSA-qwpm-85r5-4m77.json | 8 ++------ .../05/GHSA-qxf7-8j2m-38vq/GHSA-qxf7-8j2m-38vq.json | 8 ++------ .../05/GHSA-r2f9-gjrv-w2m3/GHSA-r2f9-gjrv-w2m3.json | 8 ++------ .../05/GHSA-r2qw-p44h-79x6/GHSA-r2qw-p44h-79x6.json | 8 ++------ .../05/GHSA-r3vf-v8xh-pg2h/GHSA-r3vf-v8xh-pg2h.json | 8 ++------ .../05/GHSA-r437-7x7j-ph69/GHSA-r437-7x7j-ph69.json | 8 ++------ .../05/GHSA-r4gr-8frm-x929/GHSA-r4gr-8frm-x929.json | 8 ++------ .../05/GHSA-r69p-m96w-93pj/GHSA-r69p-m96w-93pj.json | 8 ++------ .../05/GHSA-r95g-ccc3-r2m4/GHSA-r95g-ccc3-r2m4.json | 4 +--- .../05/GHSA-r9ch-hjj5-v6pr/GHSA-r9ch-hjj5-v6pr.json | 8 ++------ .../05/GHSA-rcp2-2qxc-r85v/GHSA-rcp2-2qxc-r85v.json | 8 ++------ .../05/GHSA-rcpm-5qw3-5cwf/GHSA-rcpm-5qw3-5cwf.json | 8 ++------ .../05/GHSA-rcr6-jvpg-rgxq/GHSA-rcr6-jvpg-rgxq.json | 8 ++------ .../05/GHSA-rf52-3f4q-fcfq/GHSA-rf52-3f4q-fcfq.json | 12 +++--------- .../05/GHSA-rf6c-ww9j-gx78/GHSA-rf6c-ww9j-gx78.json | 4 +--- .../05/GHSA-rf7j-w28r-v7m8/GHSA-rf7j-w28r-v7m8.json | 8 ++------ .../05/GHSA-rfpv-wr89-rpq2/GHSA-rfpv-wr89-rpq2.json | 12 +++--------- .../05/GHSA-rgfr-7rr5-7928/GHSA-rgfr-7rr5-7928.json | 8 ++------ .../05/GHSA-rgx6-mrxh-v3pw/GHSA-rgx6-mrxh-v3pw.json | 8 ++------ .../05/GHSA-rjqp-837c-gqg6/GHSA-rjqp-837c-gqg6.json | 8 ++------ .../05/GHSA-rjwr-8pfc-m94f/GHSA-rjwr-8pfc-m94f.json | 8 ++------ .../05/GHSA-rmrp-r22g-jmmv/GHSA-rmrp-r22g-jmmv.json | 8 ++------ .../05/GHSA-rpjv-v6fq-qfwj/GHSA-rpjv-v6fq-qfwj.json | 8 ++------ .../05/GHSA-rq9w-g596-24v3/GHSA-rq9w-g596-24v3.json | 8 ++------ .../05/GHSA-rr5j-hx3c-x5p5/GHSA-rr5j-hx3c-x5p5.json | 8 ++------ .../05/GHSA-rr9f-vrp3-f94h/GHSA-rr9f-vrp3-f94h.json | 4 +--- .../05/GHSA-rvw7-mwvr-mmjr/GHSA-rvw7-mwvr-mmjr.json | 4 +--- .../05/GHSA-rw24-wp83-w826/GHSA-rw24-wp83-w826.json | 12 +++--------- .../05/GHSA-rw44-jmrm-m8qc/GHSA-rw44-jmrm-m8qc.json | 8 ++------ .../05/GHSA-rwpx-585c-m6rh/GHSA-rwpx-585c-m6rh.json | 8 ++------ .../05/GHSA-rxcr-7xjm-f9c9/GHSA-rxcr-7xjm-f9c9.json | 4 +--- .../05/GHSA-v28p-8jwp-98gh/GHSA-v28p-8jwp-98gh.json | 8 ++------ .../05/GHSA-v2fm-g8p8-hmh2/GHSA-v2fm-g8p8-hmh2.json | 8 ++------ .../05/GHSA-v2jr-9j8f-xxpp/GHSA-v2jr-9j8f-xxpp.json | 8 ++------ .../05/GHSA-v354-qw54-4f78/GHSA-v354-qw54-4f78.json | 8 ++------ .../05/GHSA-v56p-8m5q-738r/GHSA-v56p-8m5q-738r.json | 8 ++------ .../05/GHSA-v59p-pfh8-62m9/GHSA-v59p-pfh8-62m9.json | 8 ++------ .../05/GHSA-v5r5-m654-v47x/GHSA-v5r5-m654-v47x.json | 4 +--- .../05/GHSA-v82c-gv92-52wp/GHSA-v82c-gv92-52wp.json | 8 ++------ .../05/GHSA-v875-jf7g-hg8j/GHSA-v875-jf7g-hg8j.json | 8 ++------ .../05/GHSA-v8qq-whm6-fxjh/GHSA-v8qq-whm6-fxjh.json | 4 +--- .../05/GHSA-v9h8-hgfv-94v4/GHSA-v9h8-hgfv-94v4.json | 8 ++------ .../05/GHSA-vf7v-wqw9-gv37/GHSA-vf7v-wqw9-gv37.json | 8 ++------ .../05/GHSA-vffp-xx76-rfqc/GHSA-vffp-xx76-rfqc.json | 8 ++------ .../05/GHSA-vfrw-4wr4-4c85/GHSA-vfrw-4wr4-4c85.json | 8 ++------ .../05/GHSA-vg7p-2967-p5p3/GHSA-vg7p-2967-p5p3.json | 8 ++------ .../05/GHSA-vh3x-x68x-6r47/GHSA-vh3x-x68x-6r47.json | 8 ++------ .../05/GHSA-vhv9-x6wj-xx42/GHSA-vhv9-x6wj-xx42.json | 8 ++------ .../05/GHSA-vhw2-m627-4r89/GHSA-vhw2-m627-4r89.json | 8 ++------ .../05/GHSA-vm56-hj47-795x/GHSA-vm56-hj47-795x.json | 4 +--- .../05/GHSA-vm99-6cff-jpcq/GHSA-vm99-6cff-jpcq.json | 8 ++------ .../05/GHSA-vmjg-j3qq-h4fv/GHSA-vmjg-j3qq-h4fv.json | 8 ++------ .../05/GHSA-vqp5-86j6-8f36/GHSA-vqp5-86j6-8f36.json | 4 +--- .../05/GHSA-vqv8-75fg-f6w9/GHSA-vqv8-75fg-f6w9.json | 8 ++------ .../05/GHSA-vvx2-gqg8-pxgr/GHSA-vvx2-gqg8-pxgr.json | 12 +++--------- .../05/GHSA-vwqx-w7g5-rmqm/GHSA-vwqx-w7g5-rmqm.json | 8 ++------ .../05/GHSA-vwv9-76qv-g45f/GHSA-vwv9-76qv-g45f.json | 8 ++------ .../05/GHSA-vxv5-cwf3-9w9q/GHSA-vxv5-cwf3-9w9q.json | 8 ++------ .../05/GHSA-w3fw-6h3j-5r9q/GHSA-w3fw-6h3j-5r9q.json | 4 +--- .../05/GHSA-w3pj-9p3h-pxx8/GHSA-w3pj-9p3h-pxx8.json | 8 ++------ .../05/GHSA-w3q5-g4xc-24gf/GHSA-w3q5-g4xc-24gf.json | 8 ++------ .../05/GHSA-w3v3-4783-r6mv/GHSA-w3v3-4783-r6mv.json | 8 ++------ .../05/GHSA-w5p3-6pf5-78hg/GHSA-w5p3-6pf5-78hg.json | 4 +--- .../05/GHSA-w6r6-frp2-8r52/GHSA-w6r6-frp2-8r52.json | 4 +--- .../05/GHSA-w6vh-q47r-3xgq/GHSA-w6vh-q47r-3xgq.json | 8 ++------ .../05/GHSA-w82x-g35v-536x/GHSA-w82x-g35v-536x.json | 8 ++------ .../05/GHSA-w929-59q2-gfxf/GHSA-w929-59q2-gfxf.json | 8 ++------ .../05/GHSA-w93q-c5fh-q4hj/GHSA-w93q-c5fh-q4hj.json | 8 ++------ .../05/GHSA-w9pw-wrp2-gp5p/GHSA-w9pw-wrp2-gp5p.json | 8 ++------ .../05/GHSA-w9rg-m5v9-r8xf/GHSA-w9rg-m5v9-r8xf.json | 8 ++------ .../05/GHSA-wcc2-hgw8-8prx/GHSA-wcc2-hgw8-8prx.json | 8 ++------ .../05/GHSA-wfcg-xg9m-fp2f/GHSA-wfcg-xg9m-fp2f.json | 12 +++--------- .../05/GHSA-wfj8-v9x3-cw4h/GHSA-wfj8-v9x3-cw4h.json | 8 ++------ .../05/GHSA-wfwh-pmv6-rmqq/GHSA-wfwh-pmv6-rmqq.json | 8 ++------ .../05/GHSA-wg32-9vr9-f572/GHSA-wg32-9vr9-f572.json | 8 ++------ .../05/GHSA-wgq6-7gfw-mf96/GHSA-wgq6-7gfw-mf96.json | 8 ++------ .../05/GHSA-wgxr-4g2j-73wf/GHSA-wgxr-4g2j-73wf.json | 8 ++------ .../05/GHSA-wh55-mm7m-3cw6/GHSA-wh55-mm7m-3cw6.json | 8 ++------ .../05/GHSA-whgg-x7cg-v7r9/GHSA-whgg-x7cg-v7r9.json | 8 ++------ .../05/GHSA-wj28-g25v-jc4f/GHSA-wj28-g25v-jc4f.json | 8 ++------ .../05/GHSA-wjr5-3fx3-2rvx/GHSA-wjr5-3fx3-2rvx.json | 8 ++------ .../05/GHSA-wp4m-572g-9345/GHSA-wp4m-572g-9345.json | 8 ++------ .../05/GHSA-wpwr-fc52-h69c/GHSA-wpwr-fc52-h69c.json | 8 ++------ .../05/GHSA-wrq6-7947-r2fc/GHSA-wrq6-7947-r2fc.json | 8 ++------ .../05/GHSA-wvvr-q98h-37h6/GHSA-wvvr-q98h-37h6.json | 8 ++------ .../05/GHSA-ww6m-3fjc-mvfw/GHSA-ww6m-3fjc-mvfw.json | 4 +--- .../05/GHSA-x29m-vmxh-c2mf/GHSA-x29m-vmxh-c2mf.json | 8 ++------ .../05/GHSA-x47q-p47x-3235/GHSA-x47q-p47x-3235.json | 4 +--- .../05/GHSA-x4c3-xfxx-vh9f/GHSA-x4c3-xfxx-vh9f.json | 8 ++------ .../05/GHSA-x5pq-ph4c-8g27/GHSA-x5pq-ph4c-8g27.json | 8 ++------ .../05/GHSA-x633-mvxm-f9pp/GHSA-x633-mvxm-f9pp.json | 12 +++--------- .../05/GHSA-x69r-8f37-6mwc/GHSA-x69r-8f37-6mwc.json | 8 ++------ .../05/GHSA-x9r4-mg7m-xg3w/GHSA-x9r4-mg7m-xg3w.json | 8 ++------ .../05/GHSA-xcf5-m6c7-75hg/GHSA-xcf5-m6c7-75hg.json | 8 ++------ .../05/GHSA-xcrf-82h4-f366/GHSA-xcrf-82h4-f366.json | 8 ++------ .../05/GHSA-xcrp-9h4m-qq97/GHSA-xcrp-9h4m-qq97.json | 8 ++------ .../05/GHSA-xff9-cgjh-mvpp/GHSA-xff9-cgjh-mvpp.json | 8 ++------ .../05/GHSA-xh7c-xrrg-3jv2/GHSA-xh7c-xrrg-3jv2.json | 8 ++------ .../05/GHSA-xhqc-7m79-5gq4/GHSA-xhqc-7m79-5gq4.json | 8 ++------ .../05/GHSA-xhw7-9wqv-ffm2/GHSA-xhw7-9wqv-ffm2.json | 8 ++------ .../05/GHSA-xjfj-5c48-9853/GHSA-xjfj-5c48-9853.json | 8 ++------ .../05/GHSA-xp84-q6q5-7pv4/GHSA-xp84-q6q5-7pv4.json | 8 ++------ .../05/GHSA-xq55-4x3m-2f97/GHSA-xq55-4x3m-2f97.json | 8 ++------ .../05/GHSA-xw9h-8vfr-ppf5/GHSA-xw9h-8vfr-ppf5.json | 4 +--- .../05/GHSA-xwv3-xrx8-63rf/GHSA-xwv3-xrx8-63rf.json | 8 ++------ .../05/GHSA-xxcc-4hjx-8q5v/GHSA-xxcc-4hjx-8q5v.json | 8 ++------ .../05/GHSA-xxvc-26j5-3mg9/GHSA-xxvc-26j5-3mg9.json | 8 ++------ .../05/GHSA-xxwg-wfjg-vgjp/GHSA-xxwg-wfjg-vgjp.json | 8 ++------ .../06/GHSA-mh3r-vrg4-68p4/GHSA-mh3r-vrg4-68p4.json | 4 +--- .../06/GHSA-qq3x-ppcw-6fmq/GHSA-qq3x-ppcw-6fmq.json | 4 +--- .../06/GHSA-xfr9-hqm4-5288/GHSA-xfr9-hqm4-5288.json | 4 +--- .../07/GHSA-2c24-m9rj-gq8m/GHSA-2c24-m9rj-gq8m.json | 4 +--- .../07/GHSA-2h44-v83q-fj6m/GHSA-2h44-v83q-fj6m.json | 4 +--- .../07/GHSA-2pxw-qgwm-32jg/GHSA-2pxw-qgwm-32jg.json | 4 +--- .../07/GHSA-77f9-jv8v-xrjp/GHSA-77f9-jv8v-xrjp.json | 4 +--- .../07/GHSA-9fmj-x3g8-hmqv/GHSA-9fmj-x3g8-hmqv.json | 4 +--- .../07/GHSA-f5vc-gmmj-gpp6/GHSA-f5vc-gmmj-gpp6.json | 8 ++------ .../07/GHSA-g2cf-r83x-vvf5/GHSA-g2cf-r83x-vvf5.json | 4 +--- .../07/GHSA-g37v-jxpm-83fp/GHSA-g37v-jxpm-83fp.json | 4 +--- .../07/GHSA-rcwq-vxfc-36p5/GHSA-rcwq-vxfc-36p5.json | 4 +--- .../08/GHSA-8662-6hf9-cr47/GHSA-8662-6hf9-cr47.json | 4 +--- .../08/GHSA-gcvh-452x-5mh3/GHSA-gcvh-452x-5mh3.json | 4 +--- .../08/GHSA-h8mv-q3c4-8hw2/GHSA-h8mv-q3c4-8hw2.json | 4 +--- .../08/GHSA-r2vv-rr99-h5p9/GHSA-r2vv-rr99-h5p9.json | 4 +--- .../09/GHSA-29x2-p4f6-vfcw/GHSA-29x2-p4f6-vfcw.json | 8 ++------ .../09/GHSA-2xvj-f2r6-3cg7/GHSA-2xvj-f2r6-3cg7.json | 8 ++------ .../09/GHSA-3cjx-7cj6-qvq3/GHSA-3cjx-7cj6-qvq3.json | 4 +--- .../09/GHSA-4fq5-r4vp-7ph5/GHSA-4fq5-r4vp-7ph5.json | 8 ++------ .../09/GHSA-69f5-4grj-mqr7/GHSA-69f5-4grj-mqr7.json | 4 +--- .../09/GHSA-6mqc-jm93-59f3/GHSA-6mqc-jm93-59f3.json | 8 ++------ .../09/GHSA-779j-v68w-458w/GHSA-779j-v68w-458w.json | 4 +--- .../09/GHSA-8cmp-crm3-jrh4/GHSA-8cmp-crm3-jrh4.json | 4 +--- .../09/GHSA-99gj-9798-gpx5/GHSA-99gj-9798-gpx5.json | 4 +--- .../09/GHSA-9m56-6xhm-cg4f/GHSA-9m56-6xhm-cg4f.json | 4 +--- .../09/GHSA-f2hc-4phx-xcm3/GHSA-f2hc-4phx-xcm3.json | 4 +--- .../09/GHSA-p6mj-rqhq-7523/GHSA-p6mj-rqhq-7523.json | 4 +--- .../09/GHSA-r46x-xjwr-8v2g/GHSA-r46x-xjwr-8v2g.json | 4 +--- .../09/GHSA-rpc9-wm96-3rrj/GHSA-rpc9-wm96-3rrj.json | 4 +--- .../09/GHSA-vwr7-qp65-68hx/GHSA-vwr7-qp65-68hx.json | 4 +--- .../10/GHSA-hhm5-8mw4-m6fp/GHSA-hhm5-8mw4-m6fp.json | 4 +--- .../11/GHSA-223w-3rxg-p29x/GHSA-223w-3rxg-p29x.json | 4 +--- .../11/GHSA-2c8c-xhwv-r7h7/GHSA-2c8c-xhwv-r7h7.json | 4 +--- .../11/GHSA-2w3j-8r4x-f4mg/GHSA-2w3j-8r4x-f4mg.json | 4 +--- .../11/GHSA-64h5-qfvh-m2hc/GHSA-64h5-qfvh-m2hc.json | 4 +--- .../11/GHSA-79mx-4vf7-wqf7/GHSA-79mx-4vf7-wqf7.json | 8 ++------ .../11/GHSA-7c72-6v53-xq93/GHSA-7c72-6v53-xq93.json | 4 +--- .../11/GHSA-99cg-5xjc-jpvj/GHSA-99cg-5xjc-jpvj.json | 4 +--- .../11/GHSA-c9g6-7m2j-rfh8/GHSA-c9g6-7m2j-rfh8.json | 4 +--- .../11/GHSA-f4x4-cpmc-ghq4/GHSA-f4x4-cpmc-ghq4.json | 4 +--- .../11/GHSA-f6x7-qg62-r396/GHSA-f6x7-qg62-r396.json | 4 +--- .../11/GHSA-f988-q9m6-r9h6/GHSA-f988-q9m6-r9h6.json | 8 ++------ .../11/GHSA-hhjc-j2mm-6qxp/GHSA-hhjc-j2mm-6qxp.json | 8 ++------ .../11/GHSA-jfj7-7vp9-r7cf/GHSA-jfj7-7vp9-r7cf.json | 4 +--- .../11/GHSA-jgwp-h4gx-xm93/GHSA-jgwp-h4gx-xm93.json | 4 +--- .../11/GHSA-mfvg-p5qp-p4gm/GHSA-mfvg-p5qp-p4gm.json | 4 +--- .../11/GHSA-mgr9-pm96-3xmm/GHSA-mgr9-pm96-3xmm.json | 4 +--- .../11/GHSA-p22x-6r5h-g873/GHSA-p22x-6r5h-g873.json | 4 +--- .../11/GHSA-pm8g-g665-8r7q/GHSA-pm8g-g665-8r7q.json | 4 +--- .../11/GHSA-pmwg-pqhj-8m9m/GHSA-pmwg-pqhj-8m9m.json | 4 +--- .../11/GHSA-q7gf-qq2r-mhhf/GHSA-q7gf-qq2r-mhhf.json | 4 +--- .../12/GHSA-2777-r28v-7m99/GHSA-2777-r28v-7m99.json | 4 +--- .../12/GHSA-79hv-rqqf-c692/GHSA-79hv-rqqf-c692.json | 8 ++------ .../12/GHSA-cj4v-mx99-hg57/GHSA-cj4v-mx99-hg57.json | 4 +--- .../12/GHSA-fg7f-frxh-h6gr/GHSA-fg7f-frxh-h6gr.json | 4 +--- .../12/GHSA-r5q7-99jj-9rvq/GHSA-r5q7-99jj-9rvq.json | 4 +--- .../01/GHSA-32ph-rfjm-xcxh/GHSA-32ph-rfjm-xcxh.json | 4 +--- .../01/GHSA-52fh-7w4m-p9cx/GHSA-52fh-7w4m-p9cx.json | 4 +--- .../01/GHSA-7ghc-xw3w-fw2v/GHSA-7ghc-xw3w-fw2v.json | 4 +--- .../01/GHSA-86rp-q4q2-g9m2/GHSA-86rp-q4q2-g9m2.json | 4 +--- .../01/GHSA-8f85-82xx-w72x/GHSA-8f85-82xx-w72x.json | 4 +--- .../01/GHSA-8gg5-pvcf-9jwc/GHSA-8gg5-pvcf-9jwc.json | 4 +--- .../01/GHSA-jw92-fcgv-875g/GHSA-jw92-fcgv-875g.json | 4 +--- .../01/GHSA-mm7r-w5q4-7cc2/GHSA-mm7r-w5q4-7cc2.json | 4 +--- .../01/GHSA-mp34-w63c-4vpv/GHSA-mp34-w63c-4vpv.json | 4 +--- .../01/GHSA-pghc-cpgh-cpp9/GHSA-pghc-cpgh-cpp9.json | 4 +--- .../01/GHSA-v3wm-hvwx-j6vw/GHSA-v3wm-hvwx-j6vw.json | 4 +--- .../01/GHSA-v7m6-263w-8j68/GHSA-v7m6-263w-8j68.json | 4 +--- .../02/GHSA-q557-c2gh-wm95/GHSA-q557-c2gh-wm95.json | 4 +--- .../02/GHSA-v398-hxmw-7r4v/GHSA-v398-hxmw-7r4v.json | 4 +--- .../03/GHSA-whvh-7626-25qp/GHSA-whvh-7626-25qp.json | 4 +--- .../03/GHSA-wmpf-66f7-27p8/GHSA-wmpf-66f7-27p8.json | 4 +--- .../06/GHSA-9hrf-3267-3v6p/GHSA-9hrf-3267-3v6p.json | 4 +--- .../11/GHSA-7664-m5hw-r7q8/GHSA-7664-m5hw-r7q8.json | 4 +--- .../12/GHSA-xxjf-hhmr-jhmq/GHSA-xxjf-hhmr-jhmq.json | 4 +--- .../02/GHSA-5p7x-xg54-cjrq/GHSA-5p7x-xg54-cjrq.json | 4 +--- .../02/GHSA-6733-f273-8q48/GHSA-6733-f273-8q48.json | 4 +--- .../02/GHSA-6wxp-wm3f-vmr4/GHSA-6wxp-wm3f-vmr4.json | 4 +--- .../02/GHSA-m658-5f72-86ff/GHSA-m658-5f72-86ff.json | 4 +--- .../02/GHSA-p53g-6cxv-378j/GHSA-p53g-6cxv-378j.json | 8 ++------ .../02/GHSA-q25f-2gjj-7ppp/GHSA-q25f-2gjj-7ppp.json | 8 ++------ .../02/GHSA-v3xc-v2g4-h75g/GHSA-v3xc-v2g4-h75g.json | 4 +--- .../02/GHSA-vr7g-cxmj-9864/GHSA-vr7g-cxmj-9864.json | 4 +--- .../03/GHSA-37x3-hqf8-5w7p/GHSA-37x3-hqf8-5w7p.json | 8 ++------ .../03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json | 4 +--- .../03/GHSA-p8fm-626m-mf8v/GHSA-p8fm-626m-mf8v.json | 8 ++------ .../03/GHSA-r5xr-mfqp-qmrq/GHSA-r5xr-mfqp-qmrq.json | 8 ++------ .../03/GHSA-x3cr-crpx-mg4r/GHSA-x3cr-crpx-mg4r.json | 4 +--- .../04/GHSA-3vqr-5r5v-rhm8/GHSA-3vqr-5r5v-rhm8.json | 4 +--- .../04/GHSA-46vf-c8gj-2pgq/GHSA-46vf-c8gj-2pgq.json | 4 +--- .../04/GHSA-4q93-6p46-6x3h/GHSA-4q93-6p46-6x3h.json | 4 +--- .../04/GHSA-5h96-vc53-5mqg/GHSA-5h96-vc53-5mqg.json | 4 +--- .../04/GHSA-6w55-m9x6-7p2p/GHSA-6w55-m9x6-7p2p.json | 4 +--- .../04/GHSA-8673-r45m-47g8/GHSA-8673-r45m-47g8.json | 4 +--- .../04/GHSA-8j2w-2cpm-xpmr/GHSA-8j2w-2cpm-xpmr.json | 8 ++------ .../04/GHSA-8ppm-mwhc-2h38/GHSA-8ppm-mwhc-2h38.json | 4 +--- .../04/GHSA-94v3-rgqr-v5g3/GHSA-94v3-rgqr-v5g3.json | 4 +--- .../04/GHSA-gcfv-8g7p-w74j/GHSA-gcfv-8g7p-w74j.json | 4 +--- .../04/GHSA-gchv-5rxx-7j87/GHSA-gchv-5rxx-7j87.json | 4 +--- .../04/GHSA-hxvx-w43m-m8wv/GHSA-hxvx-w43m-m8wv.json | 4 +--- .../04/GHSA-jjv2-293m-3wrf/GHSA-jjv2-293m-3wrf.json | 8 ++------ .../04/GHSA-jw3q-hfmw-wpqw/GHSA-jw3q-hfmw-wpqw.json | 8 ++------ .../04/GHSA-p29c-5vv5-vh3p/GHSA-p29c-5vv5-vh3p.json | 8 ++------ .../04/GHSA-r9g8-4h9q-3jfp/GHSA-r9g8-4h9q-3jfp.json | 4 +--- .../04/GHSA-rq82-xjv7-57jq/GHSA-rq82-xjv7-57jq.json | 4 +--- .../04/GHSA-w249-f84q-3v47/GHSA-w249-f84q-3v47.json | 4 +--- .../04/GHSA-w3jf-rqmq-p89q/GHSA-w3jf-rqmq-p89q.json | 8 ++------ .../04/GHSA-x8mf-46wq-x274/GHSA-x8mf-46wq-x274.json | 8 ++------ .../04/GHSA-xcp9-jx79-m233/GHSA-xcp9-jx79-m233.json | 4 +--- .../05/GHSA-jj5x-5vg3-9m7f/GHSA-jj5x-5vg3-9m7f.json | 8 ++------ .../05/GHSA-pf9m-g9g6-cphc/GHSA-pf9m-g9g6-cphc.json | 4 +--- .../06/GHSA-2xhx-vgfw-g59c/GHSA-2xhx-vgfw-g59c.json | 4 +--- .../06/GHSA-3fxj-qpxv-j6qj/GHSA-3fxj-qpxv-j6qj.json | 4 +--- .../06/GHSA-59c6-mp6w-73hm/GHSA-59c6-mp6w-73hm.json | 4 +--- .../06/GHSA-962x-cm53-4293/GHSA-962x-cm53-4293.json | 4 +--- .../06/GHSA-f44r-hfph-3jh8/GHSA-f44r-hfph-3jh8.json | 4 +--- .../06/GHSA-prf2-4xjw-553w/GHSA-prf2-4xjw-553w.json | 4 +--- .../06/GHSA-qmg2-53h9-6g7h/GHSA-qmg2-53h9-6g7h.json | 4 +--- .../07/GHSA-459h-qwrj-j9gc/GHSA-459h-qwrj-j9gc.json | 8 ++------ .../07/GHSA-ghw9-6h55-qj7v/GHSA-ghw9-6h55-qj7v.json | 4 +--- .../07/GHSA-vp7x-cv58-7w74/GHSA-vp7x-cv58-7w74.json | 8 ++------ .../08/GHSA-25fr-px8w-jvcm/GHSA-25fr-px8w-jvcm.json | 4 +--- .../08/GHSA-29qp-r356-cgp5/GHSA-29qp-r356-cgp5.json | 4 +--- .../08/GHSA-2f7j-8pxq-5mww/GHSA-2f7j-8pxq-5mww.json | 4 +--- .../08/GHSA-2pv4-crr8-ffh9/GHSA-2pv4-crr8-ffh9.json | 4 +--- .../08/GHSA-2pxp-hm79-mvqx/GHSA-2pxp-hm79-mvqx.json | 4 +--- .../08/GHSA-3fr4-6j9r-w2r5/GHSA-3fr4-6j9r-w2r5.json | 4 +--- .../08/GHSA-3qv4-28q5-585p/GHSA-3qv4-28q5-585p.json | 4 +--- .../08/GHSA-3vf4-qf7v-8hwx/GHSA-3vf4-qf7v-8hwx.json | 4 +--- .../08/GHSA-4mjp-p7h5-xhfj/GHSA-4mjp-p7h5-xhfj.json | 4 +--- .../08/GHSA-4wqq-mhqm-j8fh/GHSA-4wqq-mhqm-j8fh.json | 4 +--- .../08/GHSA-5647-wrp8-rxf7/GHSA-5647-wrp8-rxf7.json | 4 +--- .../08/GHSA-6jr4-fv3f-vmgp/GHSA-6jr4-fv3f-vmgp.json | 4 +--- .../08/GHSA-6v5v-396j-6g9j/GHSA-6v5v-396j-6g9j.json | 4 +--- .../08/GHSA-756x-7gxj-qmpv/GHSA-756x-7gxj-qmpv.json | 4 +--- .../08/GHSA-7ph6-ch7r-f425/GHSA-7ph6-ch7r-f425.json | 8 ++------ .../08/GHSA-7vcj-8223-g52v/GHSA-7vcj-8223-g52v.json | 4 +--- .../08/GHSA-86vf-g5px-79j2/GHSA-86vf-g5px-79j2.json | 4 +--- .../08/GHSA-939p-28h4-46p5/GHSA-939p-28h4-46p5.json | 4 +--- .../08/GHSA-c627-r4px-c33f/GHSA-c627-r4px-c33f.json | 4 +--- .../08/GHSA-c7v9-gh22-gjq5/GHSA-c7v9-gh22-gjq5.json | 4 +--- .../08/GHSA-ccp2-8cqw-xhpw/GHSA-ccp2-8cqw-xhpw.json | 4 +--- .../08/GHSA-cvv3-vch8-mp39/GHSA-cvv3-vch8-mp39.json | 4 +--- .../08/GHSA-cwqj-wjpc-hr2x/GHSA-cwqj-wjpc-hr2x.json | 4 +--- .../08/GHSA-cxjm-x772-f6r9/GHSA-cxjm-x772-f6r9.json | 4 +--- .../08/GHSA-fgqh-mx4w-q7rr/GHSA-fgqh-mx4w-q7rr.json | 4 +--- .../08/GHSA-frwc-xr7f-wxx2/GHSA-frwc-xr7f-wxx2.json | 4 +--- .../08/GHSA-hj26-xxg9-8jhq/GHSA-hj26-xxg9-8jhq.json | 4 +--- .../08/GHSA-hphg-jf8m-wgxp/GHSA-hphg-jf8m-wgxp.json | 4 +--- .../08/GHSA-j4mv-2m42-3984/GHSA-j4mv-2m42-3984.json | 4 +--- .../08/GHSA-j8xm-x2w7-hmgh/GHSA-j8xm-x2w7-hmgh.json | 4 +--- .../08/GHSA-jjc3-cj6j-hw3v/GHSA-jjc3-cj6j-hw3v.json | 4 +--- .../08/GHSA-mc4q-hp46-qc8h/GHSA-mc4q-hp46-qc8h.json | 4 +--- .../08/GHSA-mh7g-3h8c-hq7m/GHSA-mh7g-3h8c-hq7m.json | 4 +--- .../08/GHSA-mq4f-wch7-8vf9/GHSA-mq4f-wch7-8vf9.json | 4 +--- .../08/GHSA-p7c5-whj7-83vc/GHSA-p7c5-whj7-83vc.json | 4 +--- .../08/GHSA-qf2x-cq7r-8263/GHSA-qf2x-cq7r-8263.json | 4 +--- .../08/GHSA-qhmw-cw2v-9499/GHSA-qhmw-cw2v-9499.json | 4 +--- .../08/GHSA-qqh7-j72m-6p4p/GHSA-qqh7-j72m-6p4p.json | 4 +--- .../08/GHSA-qx4x-h5xp-mmqx/GHSA-qx4x-h5xp-mmqx.json | 8 ++------ .../08/GHSA-rc9c-w737-83cm/GHSA-rc9c-w737-83cm.json | 4 +--- .../08/GHSA-rfcm-2r55-7fc2/GHSA-rfcm-2r55-7fc2.json | 4 +--- .../08/GHSA-rr6j-f8h9-f9mp/GHSA-rr6j-f8h9-f9mp.json | 4 +--- .../08/GHSA-w25h-8579-q2hj/GHSA-w25h-8579-q2hj.json | 4 +--- .../08/GHSA-w2v4-6c2x-p3qm/GHSA-w2v4-6c2x-p3qm.json | 4 +--- .../08/GHSA-ww3m-j46v-9wf2/GHSA-ww3m-j46v-9wf2.json | 4 +--- .../08/GHSA-x65v-v924-92w9/GHSA-x65v-v924-92w9.json | 4 +--- 962 files changed, 1994 insertions(+), 5982 deletions(-) diff --git a/advisories/github-reviewed/2017/10/GHSA-gr44-7grc-37vq/GHSA-gr44-7grc-37vq.json b/advisories/github-reviewed/2017/10/GHSA-gr44-7grc-37vq/GHSA-gr44-7grc-37vq.json index fbbb583f7f2..2ceb74c5c2d 100644 --- a/advisories/github-reviewed/2017/10/GHSA-gr44-7grc-37vq/GHSA-gr44-7grc-37vq.json +++ b/advisories/github-reviewed/2017/10/GHSA-gr44-7grc-37vq/GHSA-gr44-7grc-37vq.json @@ -8,9 +8,7 @@ ], "summary": "ActiveRecord vulnerable to modification of protected model attributes", "details": "ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the `attr_protected` protection mechanism and modify protected model attributes via a crafted request.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-h56m-vwxc-3qpw/GHSA-h56m-vwxc-3qpw.json b/advisories/github-reviewed/2017/10/GHSA-h56m-vwxc-3qpw/GHSA-h56m-vwxc-3qpw.json index ed3bff56262..e3b58caf82a 100644 --- a/advisories/github-reviewed/2017/10/GHSA-h56m-vwxc-3qpw/GHSA-h56m-vwxc-3qpw.json +++ b/advisories/github-reviewed/2017/10/GHSA-h56m-vwxc-3qpw/GHSA-h56m-vwxc-3qpw.json @@ -8,9 +8,7 @@ ], "summary": "Directory traversal vulnerability in actionpack", "details": "Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via vectors involving a \\ (backslash) character, a similar issue to CVE-2014-7818.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-h77x-m5q8-c29h/GHSA-h77x-m5q8-c29h.json b/advisories/github-reviewed/2017/10/GHSA-h77x-m5q8-c29h/GHSA-h77x-m5q8-c29h.json index c0e326335c7..23da4eeedd5 100644 --- a/advisories/github-reviewed/2017/10/GHSA-h77x-m5q8-c29h/GHSA-h77x-m5q8-c29h.json +++ b/advisories/github-reviewed/2017/10/GHSA-h77x-m5q8-c29h/GHSA-h77x-m5q8-c29h.json @@ -8,9 +8,7 @@ ], "summary": "Rack vulnerable to REDoS", "details": "`lib/rack/multipart.rb` in Rack before 1.1.4, 1.2.x before 1.2.6, 1.3.x before 1.3.7, and 1.4.x before 1.4.2 uses an incorrect regular expression, which allows remote attackers to cause a denial of service (infinite loop) via a crafted Content-Disposion header.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-hgpp-pp89-4fgf/GHSA-hgpp-pp89-4fgf.json b/advisories/github-reviewed/2017/10/GHSA-hgpp-pp89-4fgf/GHSA-hgpp-pp89-4fgf.json index 8d04b5faf2f..d26f857f872 100644 --- a/advisories/github-reviewed/2017/10/GHSA-hgpp-pp89-4fgf/GHSA-hgpp-pp89-4fgf.json +++ b/advisories/github-reviewed/2017/10/GHSA-hgpp-pp89-4fgf/GHSA-hgpp-pp89-4fgf.json @@ -8,9 +8,7 @@ ], "summary": "Action Pack contains database-query restrictions bypass", "details": "`actionpack/lib/action_dispatch/http/request.rb` in Ruby on Rails before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly consider differences in parameter handling between the Active Record component and the Rack interface, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks via a crafted request, as demonstrated by certain `[nil]` values, a related issue to CVE-2012-2694.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-mgx3-27hr-mfgp/GHSA-mgx3-27hr-mfgp.json b/advisories/github-reviewed/2017/10/GHSA-mgx3-27hr-mfgp/GHSA-mgx3-27hr-mfgp.json index 69df782f426..002878c206c 100644 --- a/advisories/github-reviewed/2017/10/GHSA-mgx3-27hr-mfgp/GHSA-mgx3-27hr-mfgp.json +++ b/advisories/github-reviewed/2017/10/GHSA-mgx3-27hr-mfgp/GHSA-mgx3-27hr-mfgp.json @@ -8,9 +8,7 @@ ], "summary": "HTTParty does not restrict casts of string values", "details": "The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for YAML type conversion, a similar vulnerability to CVE-2013-0156.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-q759-hwvc-m3jg/GHSA-q759-hwvc-m3jg.json b/advisories/github-reviewed/2017/10/GHSA-q759-hwvc-m3jg/GHSA-q759-hwvc-m3jg.json index 1c9b7f49162..a46a2679301 100644 --- a/advisories/github-reviewed/2017/10/GHSA-q759-hwvc-m3jg/GHSA-q759-hwvc-m3jg.json +++ b/advisories/github-reviewed/2017/10/GHSA-q759-hwvc-m3jg/GHSA-q759-hwvc-m3jg.json @@ -8,9 +8,7 @@ ], "summary": "actionpack Cross-site Scripting vulnerability", "details": "The `sanitize_css` method in `lib/action_controller/vendor/html-scanner/html/sanitizer.rb` in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle `\\n` (newline) characters, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-r8fh-hq2p-7qhq/GHSA-r8fh-hq2p-7qhq.json b/advisories/github-reviewed/2017/10/GHSA-r8fh-hq2p-7qhq/GHSA-r8fh-hq2p-7qhq.json index 891fc23e427..3bb67dac5cf 100644 --- a/advisories/github-reviewed/2017/10/GHSA-r8fh-hq2p-7qhq/GHSA-r8fh-hq2p-7qhq.json +++ b/advisories/github-reviewed/2017/10/GHSA-r8fh-hq2p-7qhq/GHSA-r8fh-hq2p-7qhq.json @@ -8,9 +8,7 @@ ], "summary": "Active Record contains SQL Injection via improper range quoting", "details": "SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-v3rr-cph9-2g2q/GHSA-v3rr-cph9-2g2q.json b/advisories/github-reviewed/2017/10/GHSA-v3rr-cph9-2g2q/GHSA-v3rr-cph9-2g2q.json index 7f23b4e81a3..014edef8586 100644 --- a/advisories/github-reviewed/2017/10/GHSA-v3rr-cph9-2g2q/GHSA-v3rr-cph9-2g2q.json +++ b/advisories/github-reviewed/2017/10/GHSA-v3rr-cph9-2g2q/GHSA-v3rr-cph9-2g2q.json @@ -8,9 +8,7 @@ ], "summary": "rack-ssl Cross-site Scripting vulnerability", "details": "Cross-site scripting (XSS) vulnerability in `lib/rack/ssl.rb` in the rack-ssl gem before 1.4.0 for Ruby allows remote attackers to inject arbitrary web script or HTML via a URI, which might not be properly handled by third-party adapters such as JRuby-Rack.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-wpw7-wxjm-cw8r/GHSA-wpw7-wxjm-cw8r.json b/advisories/github-reviewed/2017/10/GHSA-wpw7-wxjm-cw8r/GHSA-wpw7-wxjm-cw8r.json index 98eb12834f4..92e472be09e 100644 --- a/advisories/github-reviewed/2017/10/GHSA-wpw7-wxjm-cw8r/GHSA-wpw7-wxjm-cw8r.json +++ b/advisories/github-reviewed/2017/10/GHSA-wpw7-wxjm-cw8r/GHSA-wpw7-wxjm-cw8r.json @@ -8,9 +8,7 @@ ], "summary": "actionpack allows bypass of database-query restrictions", "details": "`actionpack/lib/action_dispatch/http/request.rb` in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request that leverages (1) third-party Rack middleware or (2) custom Rack middleware. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-0155.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-xgr2-v94m-rc9g/GHSA-xgr2-v94m-rc9g.json b/advisories/github-reviewed/2017/10/GHSA-xgr2-v94m-rc9g/GHSA-xgr2-v94m-rc9g.json index c50bcfe9dce..ea928b9bff2 100644 --- a/advisories/github-reviewed/2017/10/GHSA-xgr2-v94m-rc9g/GHSA-xgr2-v94m-rc9g.json +++ b/advisories/github-reviewed/2017/10/GHSA-xgr2-v94m-rc9g/GHSA-xgr2-v94m-rc9g.json @@ -8,9 +8,7 @@ ], "summary": "activesupport in Rails vulnerable to incorrect data conversion", "details": "`lib/active_support/json/backends/yaml.rb` in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML parser, which allows remote attackers to execute arbitrary code, conduct SQL injection attacks, or bypass authentication via crafted data that triggers unsafe decoding, a different vulnerability than CVE-2013-0156.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-xwr3-fmgj-mmfr/GHSA-xwr3-fmgj-mmfr.json b/advisories/github-reviewed/2017/10/GHSA-xwr3-fmgj-mmfr/GHSA-xwr3-fmgj-mmfr.json index d6231aaa912..2d6f365ff01 100644 --- a/advisories/github-reviewed/2017/10/GHSA-xwr3-fmgj-mmfr/GHSA-xwr3-fmgj-mmfr.json +++ b/advisories/github-reviewed/2017/10/GHSA-xwr3-fmgj-mmfr/GHSA-xwr3-fmgj-mmfr.json @@ -8,9 +8,7 @@ ], "summary": "Exposure of Sensitive Information in bio-basespace-sdk", "details": "The put_call function in the API client (`api/api_client.rb`) in the BaseSpace Ruby SDK (aka bio-basespace-sdk) gem 0.1.7 for Ruby uses the `API_KEY` on the command line, which allows remote attackers to obtain sensitive information by listing the processes.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/08/GHSA-q7wx-62r7-j2x7/GHSA-q7wx-62r7-j2x7.json b/advisories/github-reviewed/2018/08/GHSA-q7wx-62r7-j2x7/GHSA-q7wx-62r7-j2x7.json index 836f159c08a..790369ecafe 100644 --- a/advisories/github-reviewed/2018/08/GHSA-q7wx-62r7-j2x7/GHSA-q7wx-62r7-j2x7.json +++ b/advisories/github-reviewed/2018/08/GHSA-q7wx-62r7-j2x7/GHSA-q7wx-62r7-j2x7.json @@ -8,9 +8,7 @@ ], "summary": "Nokogiri vulnerable to libxml XML Entity Expansion", "details": "The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/08/GHSA-xjqg-9jvg-fgx2/GHSA-xjqg-9jvg-fgx2.json b/advisories/github-reviewed/2018/08/GHSA-xjqg-9jvg-fgx2/GHSA-xjqg-9jvg-fgx2.json index 68551468595..83e729b0a8a 100644 --- a/advisories/github-reviewed/2018/08/GHSA-xjqg-9jvg-fgx2/GHSA-xjqg-9jvg-fgx2.json +++ b/advisories/github-reviewed/2018/08/GHSA-xjqg-9jvg-fgx2/GHSA-xjqg-9jvg-fgx2.json @@ -8,9 +8,7 @@ ], "summary": "Nokogiri subject to DoS via libxml2 vulnerability", "details": "The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 (as used in nokogiri before 1.6.7.1) does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/08/GHSA-45p7-c959-rgcm/GHSA-45p7-c959-rgcm.json b/advisories/github-reviewed/2021/08/GHSA-45p7-c959-rgcm/GHSA-45p7-c959-rgcm.json index aa9353c636f..1638bf8b02b 100644 --- a/advisories/github-reviewed/2021/08/GHSA-45p7-c959-rgcm/GHSA-45p7-c959-rgcm.json +++ b/advisories/github-reviewed/2021/08/GHSA-45p7-c959-rgcm/GHSA-45p7-c959-rgcm.json @@ -3,14 +3,10 @@ "id": "GHSA-45p7-c959-rgcm", "modified": "2021-08-02T21:57:02Z", "published": "2021-08-25T21:01:18Z", - "aliases": [ - - ], + "aliases": [], "summary": "Process crashes when the cell used as DepGroup is not alive", "details": "### Impact\n\nIt's easy to create a malign transaction which uses the dead cell as the DepGroup in the DepCells. The transaction can crash all the receiving nodes.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -43,9 +39,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2021-08-02T21:57:02Z", diff --git a/advisories/github-reviewed/2021/08/GHSA-48vq-8jqv-gm6f/GHSA-48vq-8jqv-gm6f.json b/advisories/github-reviewed/2021/08/GHSA-48vq-8jqv-gm6f/GHSA-48vq-8jqv-gm6f.json index 297ebdbce8f..0ca0e1d80f2 100644 --- a/advisories/github-reviewed/2021/08/GHSA-48vq-8jqv-gm6f/GHSA-48vq-8jqv-gm6f.json +++ b/advisories/github-reviewed/2021/08/GHSA-48vq-8jqv-gm6f/GHSA-48vq-8jqv-gm6f.json @@ -3,14 +3,10 @@ "id": "GHSA-48vq-8jqv-gm6f", "modified": "2021-08-02T21:53:41Z", "published": "2021-08-25T21:01:23Z", - "aliases": [ - - ], + "aliases": [], "summary": "Remote memory exhaustion in ckb", "details": "In the ckb sync protocol, SyncState maintains a HashMap called 'misbehavior' that keeps a score of a peer's violations of the protocol. This HashMap is keyed to PeerIndex (an alias for SessionId), and entries are never removed from it. SessionId is an integer that increases monotonically with every new connection.\n\nA remote attacker can manipulate this HashMap to grow forever, resulting in degraded performance and ultimately a panic on allocation failure or being killed by the OS, depending on the platform.\n\nThis is a critical severity security bug. It could be exploited to create a targeted or network-wide denial of service, to reduce the hash power of the network as part of a 51% attack, and perhaps in other creative ways.\n\nAn attack is trivial:\n\n1. connect to another node\n2. send an invalid sync protocol request, such as `SendHeaders` for non-consecutive blocks\n3. disconnect\n4. repeat", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/08/GHSA-v666-6w97-pcwm/GHSA-v666-6w97-pcwm.json b/advisories/github-reviewed/2021/08/GHSA-v666-6w97-pcwm/GHSA-v666-6w97-pcwm.json index 7c0454ff4a7..b836e7a53a0 100644 --- a/advisories/github-reviewed/2021/08/GHSA-v666-6w97-pcwm/GHSA-v666-6w97-pcwm.json +++ b/advisories/github-reviewed/2021/08/GHSA-v666-6w97-pcwm/GHSA-v666-6w97-pcwm.json @@ -3,14 +3,10 @@ "id": "GHSA-v666-6w97-pcwm", "modified": "2021-08-02T21:55:20Z", "published": "2021-08-25T21:01:21Z", - "aliases": [ - - ], + "aliases": [], "summary": "Miner fails to get block template when a cell used as a cell dep has been destroyed.", "details": "### Impact\n\nThe RPC `get_block_template` fails when a cell has been used as a cell dep and an input in the different transactions.\n\nSay cell C is used as a dep group in the transaction A, and is destroyed in the transaction B.\n\nThe node adds transaction A first, then B into the transaction pool. They are both valid. But when generating the block template, if the fee rate of B is higher, it comes before A, which will invalidate A. Currently the RPC `get_block_template` will fail instead of dropping A.\n\n### Patch\n\nFirst, the `get_block_template` should not fail but dropping the conflict transactions.\n\nThen we can propose solution to this issue. Here is an example. When a transaction is added to the pool, the pool must consider it depending on all the transactions which dep cell (direct or indirect via dep group) has been destroyed in this transaction. Because future transactions using the destroyed cells as dep will be rejected, the spending transaction only need to wait for all the existing dep transactions on chain.\n\n### Workaround\n\n1. Submit transaction B when A is already on chain.\n2. Let B depend on A explicitly, there are several solutions:\n * a. Add any output cell on A as a dep cell or input in B.\n * b. Merge A and B. CKB allows using the same cell as both dep and input in the same transaction.\n3. Ensure the fee rate of B is less than A so A always has higher priority.\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2023/01/GHSA-qjm7-55vv-3c5f/GHSA-qjm7-55vv-3c5f.json b/advisories/github-reviewed/2023/01/GHSA-qjm7-55vv-3c5f/GHSA-qjm7-55vv-3c5f.json index 5fa77e7fba3..8d3278ddb2d 100644 --- a/advisories/github-reviewed/2023/01/GHSA-qjm7-55vv-3c5f/GHSA-qjm7-55vv-3c5f.json +++ b/advisories/github-reviewed/2023/01/GHSA-qjm7-55vv-3c5f/GHSA-qjm7-55vv-3c5f.json @@ -8,9 +8,7 @@ ], "summary": "mel-spintax has Inefficient Regular Expression Complexity", "details": "A vulnerability was found in melnaron mel-spintax. It has been rated as problematic. Affected by this issue is some unknown functionality of the file `lib/spintax.js`. The manipulation of the argument text leads to inefficient regular expression complexity. The name of the patch is 37767617846e27b87b63004e30216e8f919637d3. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218456.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/08/GHSA-857q-xmph-p2v5/GHSA-857q-xmph-p2v5.json b/advisories/github-reviewed/2024/08/GHSA-857q-xmph-p2v5/GHSA-857q-xmph-p2v5.json index ac61c0a6c72..2549db27341 100644 --- a/advisories/github-reviewed/2024/08/GHSA-857q-xmph-p2v5/GHSA-857q-xmph-p2v5.json +++ b/advisories/github-reviewed/2024/08/GHSA-857q-xmph-p2v5/GHSA-857q-xmph-p2v5.json @@ -3,9 +3,7 @@ "id": "GHSA-857q-xmph-p2v5", "modified": "2024-08-09T20:41:39Z", "published": "2024-08-09T20:41:38Z", - "aliases": [ - - ], + "aliases": [], "summary": "s2n-tls's mTLS API ordering may skip client authentication", "details": "### Impact\n\nAn API ordering issue in s2n-tls can cause client authentication to unexpectedly not be enabled on the server when it otherwise appears to be. Server applications are impacted if client authentication is enabled by calling s2n_connection_set_config() before calling s2n_connection_set_client_auth_type().\n\nApplications are not impacted if these APIs are called in the opposite order, or if client authentication is enabled on the config with s2n_config_set_client_auth_type(). s2n-tls clients verifying server certificates are not impacted.\n\nImpacted versions: < v1.5.0.\n\n\n### Patches\n\nThe patch is included in v1.5.0 [1].\n\n\n### Workarounds\n\nApplications can workaround this issue by calling s2n_connection_set_config() after calling s2n_connection_set_client_auth_type(), or by enabling client authentication on the config with s2n_config_set_client_auth_type().\n\nIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [2] or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.\n\n[1] https://github.com/aws/s2n-tls/releases/tag/v1.5.0\n\n[2] https://aws.amazon.com/security/vulnerability-reporting", "severity": [ diff --git a/advisories/unreviewed/2022/02/GHSA-wg28-p94j-5hp8/GHSA-wg28-p94j-5hp8.json b/advisories/unreviewed/2022/02/GHSA-wg28-p94j-5hp8/GHSA-wg28-p94j-5hp8.json index 0ed8012d0db..4a5e4e25255 100644 --- a/advisories/unreviewed/2022/02/GHSA-wg28-p94j-5hp8/GHSA-wg28-p94j-5hp8.json +++ b/advisories/unreviewed/2022/02/GHSA-wg28-p94j-5hp8/GHSA-wg28-p94j-5hp8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-vw87-2p2h-8rp3/GHSA-vw87-2p2h-8rp3.json b/advisories/unreviewed/2022/03/GHSA-vw87-2p2h-8rp3/GHSA-vw87-2p2h-8rp3.json index e6c3588b636..4cc31efd44b 100644 --- a/advisories/unreviewed/2022/03/GHSA-vw87-2p2h-8rp3/GHSA-vw87-2p2h-8rp3.json +++ b/advisories/unreviewed/2022/03/GHSA-vw87-2p2h-8rp3/GHSA-vw87-2p2h-8rp3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-222r-4v3h-874c/GHSA-222r-4v3h-874c.json b/advisories/unreviewed/2022/04/GHSA-222r-4v3h-874c/GHSA-222r-4v3h-874c.json index 2612f57eb4f..c74891aeb50 100644 --- a/advisories/unreviewed/2022/04/GHSA-222r-4v3h-874c/GHSA-222r-4v3h-874c.json +++ b/advisories/unreviewed/2022/04/GHSA-222r-4v3h-874c/GHSA-222r-4v3h-874c.json @@ -7,12 +7,8 @@ "CVE-2000-1077" ], "details": "Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filename with a .shtml extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-225r-gcwx-jch9/GHSA-225r-gcwx-jch9.json b/advisories/unreviewed/2022/04/GHSA-225r-gcwx-jch9/GHSA-225r-gcwx-jch9.json index 49b82f07b51..68827c0aa62 100644 --- a/advisories/unreviewed/2022/04/GHSA-225r-gcwx-jch9/GHSA-225r-gcwx-jch9.json +++ b/advisories/unreviewed/2022/04/GHSA-225r-gcwx-jch9/GHSA-225r-gcwx-jch9.json @@ -7,12 +7,8 @@ "CVE-2001-0104" ], "details": "MDaemon Pro 3.5.1 and earlier allows local users to bypass the \"lock server\" security setting by pressing the Cancel button at the password prompt, then pressing the enter key.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-22v9-p596-vfhg/GHSA-22v9-p596-vfhg.json b/advisories/unreviewed/2022/04/GHSA-22v9-p596-vfhg/GHSA-22v9-p596-vfhg.json index 6a55c30e0da..2e93e266c6b 100644 --- a/advisories/unreviewed/2022/04/GHSA-22v9-p596-vfhg/GHSA-22v9-p596-vfhg.json +++ b/advisories/unreviewed/2022/04/GHSA-22v9-p596-vfhg/GHSA-22v9-p596-vfhg.json @@ -7,12 +7,8 @@ "CVE-2000-1109" ], "details": "Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the commands to be executed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-286v-p4r7-vj8x/GHSA-286v-p4r7-vj8x.json b/advisories/unreviewed/2022/04/GHSA-286v-p4r7-vj8x/GHSA-286v-p4r7-vj8x.json index c833dd5bfb8..781e899221f 100644 --- a/advisories/unreviewed/2022/04/GHSA-286v-p4r7-vj8x/GHSA-286v-p4r7-vj8x.json +++ b/advisories/unreviewed/2022/04/GHSA-286v-p4r7-vj8x/GHSA-286v-p4r7-vj8x.json @@ -7,12 +7,8 @@ "CVE-2001-0101" ], "details": "Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2gf2-mh53-2r7m/GHSA-2gf2-mh53-2r7m.json b/advisories/unreviewed/2022/04/GHSA-2gf2-mh53-2r7m/GHSA-2gf2-mh53-2r7m.json index 373895983c7..b1b5e72135f 100644 --- a/advisories/unreviewed/2022/04/GHSA-2gf2-mh53-2r7m/GHSA-2gf2-mh53-2r7m.json +++ b/advisories/unreviewed/2022/04/GHSA-2gf2-mh53-2r7m/GHSA-2gf2-mh53-2r7m.json @@ -7,12 +7,8 @@ "CVE-2001-0025" ], "details": "ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2hg7-fwp9-5gj7/GHSA-2hg7-fwp9-5gj7.json b/advisories/unreviewed/2022/04/GHSA-2hg7-fwp9-5gj7/GHSA-2hg7-fwp9-5gj7.json index 70bd47ff1c5..e512febc2ed 100644 --- a/advisories/unreviewed/2022/04/GHSA-2hg7-fwp9-5gj7/GHSA-2hg7-fwp9-5gj7.json +++ b/advisories/unreviewed/2022/04/GHSA-2hg7-fwp9-5gj7/GHSA-2hg7-fwp9-5gj7.json @@ -7,12 +7,8 @@ "CVE-2001-0086" ], "details": "CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2phm-q6hw-h5mw/GHSA-2phm-q6hw-h5mw.json b/advisories/unreviewed/2022/04/GHSA-2phm-q6hw-h5mw/GHSA-2phm-q6hw-h5mw.json index 7be6f7a8a97..0da4c08f503 100644 --- a/advisories/unreviewed/2022/04/GHSA-2phm-q6hw-h5mw/GHSA-2phm-q6hw-h5mw.json +++ b/advisories/unreviewed/2022/04/GHSA-2phm-q6hw-h5mw/GHSA-2phm-q6hw-h5mw.json @@ -7,12 +7,8 @@ "CVE-2001-0013" ], "details": "Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2r9p-58g6-hvj9/GHSA-2r9p-58g6-hvj9.json b/advisories/unreviewed/2022/04/GHSA-2r9p-58g6-hvj9/GHSA-2r9p-58g6-hvj9.json index 6d804af1905..14f7941c18a 100644 --- a/advisories/unreviewed/2022/04/GHSA-2r9p-58g6-hvj9/GHSA-2r9p-58g6-hvj9.json +++ b/advisories/unreviewed/2022/04/GHSA-2r9p-58g6-hvj9/GHSA-2r9p-58g6-hvj9.json @@ -7,12 +7,8 @@ "CVE-2000-1139" ], "details": "The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the \"Exchange User Account\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-2v37-26xm-h4rf/GHSA-2v37-26xm-h4rf.json b/advisories/unreviewed/2022/04/GHSA-2v37-26xm-h4rf/GHSA-2v37-26xm-h4rf.json index 8ab32c02108..10cf00e8e99 100644 --- a/advisories/unreviewed/2022/04/GHSA-2v37-26xm-h4rf/GHSA-2v37-26xm-h4rf.json +++ b/advisories/unreviewed/2022/04/GHSA-2v37-26xm-h4rf/GHSA-2v37-26xm-h4rf.json @@ -7,12 +7,8 @@ "CVE-2000-1163" ], "details": "ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory, which could allow local users to execute commands as other users by placing a Trojan horse library into a directory from which another user executes ghostscript.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2xfg-qg29-hmjc/GHSA-2xfg-qg29-hmjc.json b/advisories/unreviewed/2022/04/GHSA-2xfg-qg29-hmjc/GHSA-2xfg-qg29-hmjc.json index 7ee2cd3c059..db5f8cba0d8 100644 --- a/advisories/unreviewed/2022/04/GHSA-2xfg-qg29-hmjc/GHSA-2xfg-qg29-hmjc.json +++ b/advisories/unreviewed/2022/04/GHSA-2xfg-qg29-hmjc/GHSA-2xfg-qg29-hmjc.json @@ -7,12 +7,8 @@ "CVE-2000-1098" ], "details": "The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via an empty GET or POST request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-346g-3xvj-229v/GHSA-346g-3xvj-229v.json b/advisories/unreviewed/2022/04/GHSA-346g-3xvj-229v/GHSA-346g-3xvj-229v.json index b57cbe10239..a3fcab8543b 100644 --- a/advisories/unreviewed/2022/04/GHSA-346g-3xvj-229v/GHSA-346g-3xvj-229v.json +++ b/advisories/unreviewed/2022/04/GHSA-346g-3xvj-229v/GHSA-346g-3xvj-229v.json @@ -7,12 +7,8 @@ "CVE-2000-1162" ], "details": "ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-34pv-6c59-fw4x/GHSA-34pv-6c59-fw4x.json b/advisories/unreviewed/2022/04/GHSA-34pv-6c59-fw4x/GHSA-34pv-6c59-fw4x.json index 01f2fb9d7bb..92793797710 100644 --- a/advisories/unreviewed/2022/04/GHSA-34pv-6c59-fw4x/GHSA-34pv-6c59-fw4x.json +++ b/advisories/unreviewed/2022/04/GHSA-34pv-6c59-fw4x/GHSA-34pv-6c59-fw4x.json @@ -7,12 +7,8 @@ "CVE-2000-1138" ], "details": "Lotus Notes R5 client R5.0.5 and earlier does not properly warn users when an S/MIME email message has been modified, which could allow an attacker to modify the email in transit without being detected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3528-g9ff-867j/GHSA-3528-g9ff-867j.json b/advisories/unreviewed/2022/04/GHSA-3528-g9ff-867j/GHSA-3528-g9ff-867j.json index 6f46984fb5c..186d5b00ad2 100644 --- a/advisories/unreviewed/2022/04/GHSA-3528-g9ff-867j/GHSA-3528-g9ff-867j.json +++ b/advisories/unreviewed/2022/04/GHSA-3528-g9ff-867j/GHSA-3528-g9ff-867j.json @@ -7,12 +7,8 @@ "CVE-2001-0055" ], "details": "CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-35rf-v5xv-3376/GHSA-35rf-v5xv-3376.json b/advisories/unreviewed/2022/04/GHSA-35rf-v5xv-3376/GHSA-35rf-v5xv-3376.json index 9ca0e775738..54768cb8b2d 100644 --- a/advisories/unreviewed/2022/04/GHSA-35rf-v5xv-3376/GHSA-35rf-v5xv-3376.json +++ b/advisories/unreviewed/2022/04/GHSA-35rf-v5xv-3376/GHSA-35rf-v5xv-3376.json @@ -7,12 +7,8 @@ "CVE-2000-1226" ], "details": "Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service (crash) by sending non-IP protocols that Snort does not know about, as demonstrated by an nmap protocol scan.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-367q-j23v-q67j/GHSA-367q-j23v-q67j.json b/advisories/unreviewed/2022/04/GHSA-367q-j23v-q67j/GHSA-367q-j23v-q67j.json index 2825493eba0..d9c946a8d67 100644 --- a/advisories/unreviewed/2022/04/GHSA-367q-j23v-q67j/GHSA-367q-j23v-q67j.json +++ b/advisories/unreviewed/2022/04/GHSA-367q-j23v-q67j/GHSA-367q-j23v-q67j.json @@ -7,12 +7,8 @@ "CVE-2000-1179" ], "details": "Netopia ISDN Router 650-ST before 4.3.5 allows remote attackers to read system logs without authentication by directly connecting to the login screen and typing certain control characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-373p-qrfg-hfq4/GHSA-373p-qrfg-hfq4.json b/advisories/unreviewed/2022/04/GHSA-373p-qrfg-hfq4/GHSA-373p-qrfg-hfq4.json index 4f6312621a4..d220ea67fdd 100644 --- a/advisories/unreviewed/2022/04/GHSA-373p-qrfg-hfq4/GHSA-373p-qrfg-hfq4.json +++ b/advisories/unreviewed/2022/04/GHSA-373p-qrfg-hfq4/GHSA-373p-qrfg-hfq4.json @@ -7,12 +7,8 @@ "CVE-2000-1108" ], "details": "cons.saver in Midnight Commander (mc) 4.5.42 and earlier does not properly verify if an output file descriptor is a TTY, which allows local users to corrupt files by creating a symbolic link to the target file, calling mc, and specifying that link as a TTY argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-37q9-236v-5578/GHSA-37q9-236v-5578.json b/advisories/unreviewed/2022/04/GHSA-37q9-236v-5578/GHSA-37q9-236v-5578.json index 2fe2e017416..b69b294fdb3 100644 --- a/advisories/unreviewed/2022/04/GHSA-37q9-236v-5578/GHSA-37q9-236v-5578.json +++ b/advisories/unreviewed/2022/04/GHSA-37q9-236v-5578/GHSA-37q9-236v-5578.json @@ -7,12 +7,8 @@ "CVE-2000-1093" ], "details": "Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long \"goim\" command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-392m-pxgq-jvm8/GHSA-392m-pxgq-jvm8.json b/advisories/unreviewed/2022/04/GHSA-392m-pxgq-jvm8/GHSA-392m-pxgq-jvm8.json index b627e54242f..737c5d8f948 100644 --- a/advisories/unreviewed/2022/04/GHSA-392m-pxgq-jvm8/GHSA-392m-pxgq-jvm8.json +++ b/advisories/unreviewed/2022/04/GHSA-392m-pxgq-jvm8/GHSA-392m-pxgq-jvm8.json @@ -7,12 +7,8 @@ "CVE-2000-1225" ], "details": "Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain sensitive configuration information about the web server by accessing the program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3ccc-c7wq-35g5/GHSA-3ccc-c7wq-35g5.json b/advisories/unreviewed/2022/04/GHSA-3ccc-c7wq-35g5/GHSA-3ccc-c7wq-35g5.json index d7c2b8f3088..0a9b6639f07 100644 --- a/advisories/unreviewed/2022/04/GHSA-3ccc-c7wq-35g5/GHSA-3ccc-c7wq-35g5.json +++ b/advisories/unreviewed/2022/04/GHSA-3ccc-c7wq-35g5/GHSA-3ccc-c7wq-35g5.json @@ -7,12 +7,8 @@ "CVE-2000-1235" ], "details": "The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3h2g-8x7p-qmjq/GHSA-3h2g-8x7p-qmjq.json b/advisories/unreviewed/2022/04/GHSA-3h2g-8x7p-qmjq/GHSA-3h2g-8x7p-qmjq.json index 76ac9e02dad..2333f5112c7 100644 --- a/advisories/unreviewed/2022/04/GHSA-3h2g-8x7p-qmjq/GHSA-3h2g-8x7p-qmjq.json +++ b/advisories/unreviewed/2022/04/GHSA-3h2g-8x7p-qmjq/GHSA-3h2g-8x7p-qmjq.json @@ -7,12 +7,8 @@ "CVE-2000-1096" ], "details": "crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by creating world-writeable temporary files and modifying them while the victim is editing the file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3jcv-mqf8-ww8q/GHSA-3jcv-mqf8-ww8q.json b/advisories/unreviewed/2022/04/GHSA-3jcv-mqf8-ww8q/GHSA-3jcv-mqf8-ww8q.json index d4e145abf74..44442e7fbd6 100644 --- a/advisories/unreviewed/2022/04/GHSA-3jcv-mqf8-ww8q/GHSA-3jcv-mqf8-ww8q.json +++ b/advisories/unreviewed/2022/04/GHSA-3jcv-mqf8-ww8q/GHSA-3jcv-mqf8-ww8q.json @@ -7,12 +7,8 @@ "CVE-2001-0056" ], "details": "The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3m7c-89h2-3q7w/GHSA-3m7c-89h2-3q7w.json b/advisories/unreviewed/2022/04/GHSA-3m7c-89h2-3q7w/GHSA-3m7c-89h2-3q7w.json index 19ed3e950ca..eb5808927da 100644 --- a/advisories/unreviewed/2022/04/GHSA-3m7c-89h2-3q7w/GHSA-3m7c-89h2-3q7w.json +++ b/advisories/unreviewed/2022/04/GHSA-3m7c-89h2-3q7w/GHSA-3m7c-89h2-3q7w.json @@ -7,12 +7,8 @@ "CVE-2001-0069" ], "details": "dialog before 0.9a-20000118-3bis in Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3mg6-g6r9-xm68/GHSA-3mg6-g6r9-xm68.json b/advisories/unreviewed/2022/04/GHSA-3mg6-g6r9-xm68/GHSA-3mg6-g6r9-xm68.json index 96ed908396a..91deabb36e3 100644 --- a/advisories/unreviewed/2022/04/GHSA-3mg6-g6r9-xm68/GHSA-3mg6-g6r9-xm68.json +++ b/advisories/unreviewed/2022/04/GHSA-3mg6-g6r9-xm68/GHSA-3mg6-g6r9-xm68.json @@ -7,12 +7,8 @@ "CVE-2000-1111" ], "details": "Telnet Service for Windows 2000 Professional does not properly terminate incomplete connection attempts, which allows remote attackers to cause a denial of service by connecting to the server and not providing any input.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3mjq-qmqc-xrrv/GHSA-3mjq-qmqc-xrrv.json b/advisories/unreviewed/2022/04/GHSA-3mjq-qmqc-xrrv/GHSA-3mjq-qmqc-xrrv.json index a1ee7ddf481..87708bf11c8 100644 --- a/advisories/unreviewed/2022/04/GHSA-3mjq-qmqc-xrrv/GHSA-3mjq-qmqc-xrrv.json +++ b/advisories/unreviewed/2022/04/GHSA-3mjq-qmqc-xrrv/GHSA-3mjq-qmqc-xrrv.json @@ -7,12 +7,8 @@ "CVE-2000-1112" ], "details": "Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the \".WMS Script Execution\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3pww-g69g-29xx/GHSA-3pww-g69g-29xx.json b/advisories/unreviewed/2022/04/GHSA-3pww-g69g-29xx/GHSA-3pww-g69g-29xx.json index 997b414674a..ec3b839b45d 100644 --- a/advisories/unreviewed/2022/04/GHSA-3pww-g69g-29xx/GHSA-3pww-g69g-29xx.json +++ b/advisories/unreviewed/2022/04/GHSA-3pww-g69g-29xx/GHSA-3pww-g69g-29xx.json @@ -7,12 +7,8 @@ "CVE-2001-0089" ], "details": "Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the \"File Upload via Form\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3r83-hcqh-gxqf/GHSA-3r83-hcqh-gxqf.json b/advisories/unreviewed/2022/04/GHSA-3r83-hcqh-gxqf/GHSA-3r83-hcqh-gxqf.json index 7eef0e18ad3..0ac470af1ac 100644 --- a/advisories/unreviewed/2022/04/GHSA-3r83-hcqh-gxqf/GHSA-3r83-hcqh-gxqf.json +++ b/advisories/unreviewed/2022/04/GHSA-3r83-hcqh-gxqf/GHSA-3r83-hcqh-gxqf.json @@ -7,12 +7,8 @@ "CVE-2001-0102" ], "details": "\"Multiple Users\" Control Panel in Mac OS 9 allows Normal users to gain Owner privileges by removing the Users & Groups Data File, which effectively removes the Owner password and allows the Normal user to log in as the Owner account without a password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3v35-rfwh-3mc8/GHSA-3v35-rfwh-3mc8.json b/advisories/unreviewed/2022/04/GHSA-3v35-rfwh-3mc8/GHSA-3v35-rfwh-3mc8.json index 05a21846c95..cb07af85c20 100644 --- a/advisories/unreviewed/2022/04/GHSA-3v35-rfwh-3mc8/GHSA-3v35-rfwh-3mc8.json +++ b/advisories/unreviewed/2022/04/GHSA-3v35-rfwh-3mc8/GHSA-3v35-rfwh-3mc8.json @@ -7,12 +7,8 @@ "CVE-2000-1175" ], "details": "Buffer overflow in Koules 1.4 allows local users to execute arbitrary commands via a long command line argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3x4g-qr6f-2pmw/GHSA-3x4g-qr6f-2pmw.json b/advisories/unreviewed/2022/04/GHSA-3x4g-qr6f-2pmw/GHSA-3x4g-qr6f-2pmw.json index d655de0111e..29e8c6e57fa 100644 --- a/advisories/unreviewed/2022/04/GHSA-3x4g-qr6f-2pmw/GHSA-3x4g-qr6f-2pmw.json +++ b/advisories/unreviewed/2022/04/GHSA-3x4g-qr6f-2pmw/GHSA-3x4g-qr6f-2pmw.json @@ -7,12 +7,8 @@ "CVE-2001-0087" ], "details": "itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-43mg-6cfc-53w7/GHSA-43mg-6cfc-53w7.json b/advisories/unreviewed/2022/04/GHSA-43mg-6cfc-53w7/GHSA-43mg-6cfc-53w7.json index 514ec6cf77f..e57c4189bd6 100644 --- a/advisories/unreviewed/2022/04/GHSA-43mg-6cfc-53w7/GHSA-43mg-6cfc-53w7.json +++ b/advisories/unreviewed/2022/04/GHSA-43mg-6cfc-53w7/GHSA-43mg-6cfc-53w7.json @@ -7,12 +7,8 @@ "CVE-2001-0065" ], "details": "Buffer overflow in bftpd 1.0.13 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long SITE CHOWN command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-44h6-7xw4-35hg/GHSA-44h6-7xw4-35hg.json b/advisories/unreviewed/2022/04/GHSA-44h6-7xw4-35hg/GHSA-44h6-7xw4-35hg.json index bb0d457dabe..6656304f035 100644 --- a/advisories/unreviewed/2022/04/GHSA-44h6-7xw4-35hg/GHSA-44h6-7xw4-35hg.json +++ b/advisories/unreviewed/2022/04/GHSA-44h6-7xw4-35hg/GHSA-44h6-7xw4-35hg.json @@ -7,12 +7,8 @@ "CVE-2000-1146" ], "details": "Recourse ManTrap 1.6 allows attackers to cause a denial of service via a sequence of commands that navigate into and out of the /proc/self directory and executing various commands such as ls or pwd.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-45q7-vcfp-hhr3/GHSA-45q7-vcfp-hhr3.json b/advisories/unreviewed/2022/04/GHSA-45q7-vcfp-hhr3/GHSA-45q7-vcfp-hhr3.json index 2d745032ee3..3fbc0e1470a 100644 --- a/advisories/unreviewed/2022/04/GHSA-45q7-vcfp-hhr3/GHSA-45q7-vcfp-hhr3.json +++ b/advisories/unreviewed/2022/04/GHSA-45q7-vcfp-hhr3/GHSA-45q7-vcfp-hhr3.json @@ -7,12 +7,8 @@ "CVE-2001-0014" ], "details": "Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the \"Invalid RDP Data\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-47vf-2cv8-2gw3/GHSA-47vf-2cv8-2gw3.json b/advisories/unreviewed/2022/04/GHSA-47vf-2cv8-2gw3/GHSA-47vf-2cv8-2gw3.json index c409c5db0fc..1de37b193a6 100644 --- a/advisories/unreviewed/2022/04/GHSA-47vf-2cv8-2gw3/GHSA-47vf-2cv8-2gw3.json +++ b/advisories/unreviewed/2022/04/GHSA-47vf-2cv8-2gw3/GHSA-47vf-2cv8-2gw3.json @@ -7,12 +7,8 @@ "CVE-2001-0045" ], "details": "The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the \"Registry Permissions\" vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-48p8-x75w-457x/GHSA-48p8-x75w-457x.json b/advisories/unreviewed/2022/04/GHSA-48p8-x75w-457x/GHSA-48p8-x75w-457x.json index 587173e4735..dfc6f7cc38a 100644 --- a/advisories/unreviewed/2022/04/GHSA-48p8-x75w-457x/GHSA-48p8-x75w-457x.json +++ b/advisories/unreviewed/2022/04/GHSA-48p8-x75w-457x/GHSA-48p8-x75w-457x.json @@ -7,12 +7,8 @@ "CVE-2000-1239" ], "details": "The HTTP interface of Tivoli Lightweight Client Framework (LCF) in IBM Tivoli Management Framework 3.7.1 sets http_disable to zero at install time, which allows remote authenticated users to bypass file permissions on Tivoli Endpoint Configuration data files via an unspecified manipulation of log files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4f6g-grvj-2rjg/GHSA-4f6g-grvj-2rjg.json b/advisories/unreviewed/2022/04/GHSA-4f6g-grvj-2rjg/GHSA-4f6g-grvj-2rjg.json index d011a4c8a76..eeb07b8cfad 100644 --- a/advisories/unreviewed/2022/04/GHSA-4f6g-grvj-2rjg/GHSA-4f6g-grvj-2rjg.json +++ b/advisories/unreviewed/2022/04/GHSA-4f6g-grvj-2rjg/GHSA-4f6g-grvj-2rjg.json @@ -7,12 +7,8 @@ "CVE-2001-0031" ], "details": "BroadVision One-To-One Enterprise allows remote attackers to determine the physical path of server files by requesting a .JSP file name that does not exist.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4fvq-q2rx-hw88/GHSA-4fvq-q2rx-hw88.json b/advisories/unreviewed/2022/04/GHSA-4fvq-q2rx-hw88/GHSA-4fvq-q2rx-hw88.json index 98f8e9beded..80fe2743461 100644 --- a/advisories/unreviewed/2022/04/GHSA-4fvq-q2rx-hw88/GHSA-4fvq-q2rx-hw88.json +++ b/advisories/unreviewed/2022/04/GHSA-4fvq-q2rx-hw88/GHSA-4fvq-q2rx-hw88.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4hc4-4xrh-639q/GHSA-4hc4-4xrh-639q.json b/advisories/unreviewed/2022/04/GHSA-4hc4-4xrh-639q/GHSA-4hc4-4xrh-639q.json index e80e4f33988..bcf6f134a1f 100644 --- a/advisories/unreviewed/2022/04/GHSA-4hc4-4xrh-639q/GHSA-4hc4-4xrh-639q.json +++ b/advisories/unreviewed/2022/04/GHSA-4hc4-4xrh-639q/GHSA-4hc4-4xrh-639q.json @@ -7,12 +7,8 @@ "CVE-2000-1160" ], "details": "NAI Sniffer Agent allows remote attackers to cause a denial of service (crash) by sending a large number of login requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4hwr-6mhv-fvh3/GHSA-4hwr-6mhv-fvh3.json b/advisories/unreviewed/2022/04/GHSA-4hwr-6mhv-fvh3/GHSA-4hwr-6mhv-fvh3.json index 3d8730e30e7..d162b50047d 100644 --- a/advisories/unreviewed/2022/04/GHSA-4hwr-6mhv-fvh3/GHSA-4hwr-6mhv-fvh3.json +++ b/advisories/unreviewed/2022/04/GHSA-4hwr-6mhv-fvh3/GHSA-4hwr-6mhv-fvh3.json @@ -7,12 +7,8 @@ "CVE-2000-1222" ], "details": "AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4v8m-4jjw-v3r5/GHSA-4v8m-4jjw-v3r5.json b/advisories/unreviewed/2022/04/GHSA-4v8m-4jjw-v3r5/GHSA-4v8m-4jjw-v3r5.json index a105c3549ff..0a3c50235e4 100644 --- a/advisories/unreviewed/2022/04/GHSA-4v8m-4jjw-v3r5/GHSA-4v8m-4jjw-v3r5.json +++ b/advisories/unreviewed/2022/04/GHSA-4v8m-4jjw-v3r5/GHSA-4v8m-4jjw-v3r5.json @@ -7,12 +7,8 @@ "CVE-2000-1240" ], "details": "Unspecified vulnerability in siteman.php3 in AnyPortal(php) before 22 APR 00 allows remote attackers to obtain sensitive information via unknown attack vectors, which reveal the absolute path. NOTE: the provenance of this information is unknown; the details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4w69-8ggm-7737/GHSA-4w69-8ggm-7737.json b/advisories/unreviewed/2022/04/GHSA-4w69-8ggm-7737/GHSA-4w69-8ggm-7737.json index 3a6953fa0ba..31666252b17 100644 --- a/advisories/unreviewed/2022/04/GHSA-4w69-8ggm-7737/GHSA-4w69-8ggm-7737.json +++ b/advisories/unreviewed/2022/04/GHSA-4w69-8ggm-7737/GHSA-4w69-8ggm-7737.json @@ -7,12 +7,8 @@ "CVE-2000-1237" ], "details": "The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote attackers to determine valid usernames and conduct brute force password guessing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-54fh-hpf3-3x2r/GHSA-54fh-hpf3-3x2r.json b/advisories/unreviewed/2022/04/GHSA-54fh-hpf3-3x2r/GHSA-54fh-hpf3-3x2r.json index 1140b58686a..3e71847e325 100644 --- a/advisories/unreviewed/2022/04/GHSA-54fh-hpf3-3x2r/GHSA-54fh-hpf3-3x2r.json +++ b/advisories/unreviewed/2022/04/GHSA-54fh-hpf3-3x2r/GHSA-54fh-hpf3-3x2r.json @@ -7,12 +7,8 @@ "CVE-2000-1247" ], "details": "The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an \"allow from 127.0.0.1\" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-54g7-5765-8375/GHSA-54g7-5765-8375.json b/advisories/unreviewed/2022/04/GHSA-54g7-5765-8375/GHSA-54g7-5765-8375.json index bb3314c19b6..f9f83437adb 100644 --- a/advisories/unreviewed/2022/04/GHSA-54g7-5765-8375/GHSA-54g7-5765-8375.json +++ b/advisories/unreviewed/2022/04/GHSA-54g7-5765-8375/GHSA-54g7-5765-8375.json @@ -7,12 +7,8 @@ "CVE-2000-1088" ], "details": "The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the \"Extended Stored Procedure Parameter Parsing\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5576-9r4v-7ffw/GHSA-5576-9r4v-7ffw.json b/advisories/unreviewed/2022/04/GHSA-5576-9r4v-7ffw/GHSA-5576-9r4v-7ffw.json index 63bf315291b..f8007610f54 100644 --- a/advisories/unreviewed/2022/04/GHSA-5576-9r4v-7ffw/GHSA-5576-9r4v-7ffw.json +++ b/advisories/unreviewed/2022/04/GHSA-5576-9r4v-7ffw/GHSA-5576-9r4v-7ffw.json @@ -7,12 +7,8 @@ "CVE-2000-1092" ], "details": "loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a \"/\" in front of the target filename in the \"file\" parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-559q-jfjp-2w9j/GHSA-559q-jfjp-2w9j.json b/advisories/unreviewed/2022/04/GHSA-559q-jfjp-2w9j/GHSA-559q-jfjp-2w9j.json index b49217ebb2e..a7648d8c081 100644 --- a/advisories/unreviewed/2022/04/GHSA-559q-jfjp-2w9j/GHSA-559q-jfjp-2w9j.json +++ b/advisories/unreviewed/2022/04/GHSA-559q-jfjp-2w9j/GHSA-559q-jfjp-2w9j.json @@ -7,12 +7,8 @@ "CVE-2000-1082" ], "details": "The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the \"Extended Stored Procedure Parameter Parsing\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-56gc-8w28-j7xm/GHSA-56gc-8w28-j7xm.json b/advisories/unreviewed/2022/04/GHSA-56gc-8w28-j7xm/GHSA-56gc-8w28-j7xm.json index 38e0a82465f..81ad1cab54f 100644 --- a/advisories/unreviewed/2022/04/GHSA-56gc-8w28-j7xm/GHSA-56gc-8w28-j7xm.json +++ b/advisories/unreviewed/2022/04/GHSA-56gc-8w28-j7xm/GHSA-56gc-8w28-j7xm.json @@ -7,12 +7,8 @@ "CVE-2000-1227" ], "details": "Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-57c9-j2wv-xxm2/GHSA-57c9-j2wv-xxm2.json b/advisories/unreviewed/2022/04/GHSA-57c9-j2wv-xxm2/GHSA-57c9-j2wv-xxm2.json index 538670e41d1..f02522826e8 100644 --- a/advisories/unreviewed/2022/04/GHSA-57c9-j2wv-xxm2/GHSA-57c9-j2wv-xxm2.json +++ b/advisories/unreviewed/2022/04/GHSA-57c9-j2wv-xxm2/GHSA-57c9-j2wv-xxm2.json @@ -7,12 +7,8 @@ "CVE-2000-1189" ], "details": "Buffer overflow in pam_localuser PAM module in Red Hat Linux 7.x and 6.x allows attackers to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-59hc-w7w5-7mwj/GHSA-59hc-w7w5-7mwj.json b/advisories/unreviewed/2022/04/GHSA-59hc-w7w5-7mwj/GHSA-59hc-w7w5-7mwj.json index ebea61372db..cc2de5d9b8a 100644 --- a/advisories/unreviewed/2022/04/GHSA-59hc-w7w5-7mwj/GHSA-59hc-w7w5-7mwj.json +++ b/advisories/unreviewed/2022/04/GHSA-59hc-w7w5-7mwj/GHSA-59hc-w7w5-7mwj.json @@ -7,12 +7,8 @@ "CVE-2000-1177" ], "details": "bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows remote attackers to determine the existence of files and user ID's by specifying the target file in the HISTFILE parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5mj4-f3x4-x486/GHSA-5mj4-f3x4-x486.json b/advisories/unreviewed/2022/04/GHSA-5mj4-f3x4-x486/GHSA-5mj4-f3x4-x486.json index c9db9f181f1..25dd629ffb3 100644 --- a/advisories/unreviewed/2022/04/GHSA-5mj4-f3x4-x486/GHSA-5mj4-f3x4-x486.json +++ b/advisories/unreviewed/2022/04/GHSA-5mj4-f3x4-x486/GHSA-5mj4-f3x4-x486.json @@ -7,12 +7,8 @@ "CVE-2000-1065" ], "details": "Vulnerability in IP implementation of HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service (printer crash) via a malformed packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5pm6-j89m-8mmq/GHSA-5pm6-j89m-8mmq.json b/advisories/unreviewed/2022/04/GHSA-5pm6-j89m-8mmq/GHSA-5pm6-j89m-8mmq.json index 811bd96f90f..5a91e0d1441 100644 --- a/advisories/unreviewed/2022/04/GHSA-5pm6-j89m-8mmq/GHSA-5pm6-j89m-8mmq.json +++ b/advisories/unreviewed/2022/04/GHSA-5pm6-j89m-8mmq/GHSA-5pm6-j89m-8mmq.json @@ -7,12 +7,8 @@ "CVE-2000-1124" ], "details": "Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5v9r-wpqf-v2w9/GHSA-5v9r-wpqf-v2w9.json b/advisories/unreviewed/2022/04/GHSA-5v9r-wpqf-v2w9/GHSA-5v9r-wpqf-v2w9.json index 28ab6feb8ba..162086c0c7c 100644 --- a/advisories/unreviewed/2022/04/GHSA-5v9r-wpqf-v2w9/GHSA-5v9r-wpqf-v2w9.json +++ b/advisories/unreviewed/2022/04/GHSA-5v9r-wpqf-v2w9/GHSA-5v9r-wpqf-v2w9.json @@ -7,12 +7,8 @@ "CVE-2000-1125" ], "details": "restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-673q-v95c-q7mf/GHSA-673q-v95c-q7mf.json b/advisories/unreviewed/2022/04/GHSA-673q-v95c-q7mf/GHSA-673q-v95c-q7mf.json index 7bda33eb143..5029460bd31 100644 --- a/advisories/unreviewed/2022/04/GHSA-673q-v95c-q7mf/GHSA-673q-v95c-q7mf.json +++ b/advisories/unreviewed/2022/04/GHSA-673q-v95c-q7mf/GHSA-673q-v95c-q7mf.json @@ -7,12 +7,8 @@ "CVE-2001-0088" ], "details": "common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-68vx-xw79-w5cg/GHSA-68vx-xw79-w5cg.json b/advisories/unreviewed/2022/04/GHSA-68vx-xw79-w5cg/GHSA-68vx-xw79-w5cg.json index ce6cf99f6c9..a2062502c21 100644 --- a/advisories/unreviewed/2022/04/GHSA-68vx-xw79-w5cg/GHSA-68vx-xw79-w5cg.json +++ b/advisories/unreviewed/2022/04/GHSA-68vx-xw79-w5cg/GHSA-68vx-xw79-w5cg.json @@ -7,12 +7,8 @@ "CVE-2000-1104" ], "details": "Variant of the \"IIS Cross-Site Scripting\" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6hjc-hxpg-8q82/GHSA-6hjc-hxpg-8q82.json b/advisories/unreviewed/2022/04/GHSA-6hjc-hxpg-8q82/GHSA-6hjc-hxpg-8q82.json index 6f4aea26177..d93649b7006 100644 --- a/advisories/unreviewed/2022/04/GHSA-6hjc-hxpg-8q82/GHSA-6hjc-hxpg-8q82.json +++ b/advisories/unreviewed/2022/04/GHSA-6hjc-hxpg-8q82/GHSA-6hjc-hxpg-8q82.json @@ -7,12 +7,8 @@ "CVE-2000-1102" ], "details": "PTlink IRCD 3.5.3 and PTlink Services 1.8.1 allow remote attackers to cause a denial of service (server crash) via \"mode +owgscfxeb\" and \"oper\" commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6jw8-7w6j-8fvp/GHSA-6jw8-7w6j-8fvp.json b/advisories/unreviewed/2022/04/GHSA-6jw8-7w6j-8fvp/GHSA-6jw8-7w6j-8fvp.json index b379ee52c70..a643f055ae0 100644 --- a/advisories/unreviewed/2022/04/GHSA-6jw8-7w6j-8fvp/GHSA-6jw8-7w6j-8fvp.json +++ b/advisories/unreviewed/2022/04/GHSA-6jw8-7w6j-8fvp/GHSA-6jw8-7w6j-8fvp.json @@ -7,12 +7,8 @@ "CVE-2000-1172" ], "details": "Buffer overflow in Gaim 0.10.3 and earlier using the OSCAR protocol allows remote attackers to conduct a denial of service and possibly execute arbitrary commands via a long HTML tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6pm9-q8g6-xp59/GHSA-6pm9-q8g6-xp59.json b/advisories/unreviewed/2022/04/GHSA-6pm9-q8g6-xp59/GHSA-6pm9-q8g6-xp59.json index 5f52c2ce6bc..e2df4f5c4f8 100644 --- a/advisories/unreviewed/2022/04/GHSA-6pm9-q8g6-xp59/GHSA-6pm9-q8g6-xp59.json +++ b/advisories/unreviewed/2022/04/GHSA-6pm9-q8g6-xp59/GHSA-6pm9-q8g6-xp59.json @@ -7,12 +7,8 @@ "CVE-2000-1081" ], "details": "The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the \"Extended Stored Procedure Parameter Parsing\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6q7f-6pgm-q59m/GHSA-6q7f-6pgm-q59m.json b/advisories/unreviewed/2022/04/GHSA-6q7f-6pgm-q59m/GHSA-6q7f-6pgm-q59m.json index e4c13f73b4a..393d8f9f728 100644 --- a/advisories/unreviewed/2022/04/GHSA-6q7f-6pgm-q59m/GHSA-6q7f-6pgm-q59m.json +++ b/advisories/unreviewed/2022/04/GHSA-6q7f-6pgm-q59m/GHSA-6q7f-6pgm-q59m.json @@ -7,12 +7,8 @@ "CVE-2001-0052" ], "details": "IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6rw8-gcfv-wh9c/GHSA-6rw8-gcfv-wh9c.json b/advisories/unreviewed/2022/04/GHSA-6rw8-gcfv-wh9c/GHSA-6rw8-gcfv-wh9c.json index 321ced914c4..21c606da361 100644 --- a/advisories/unreviewed/2022/04/GHSA-6rw8-gcfv-wh9c/GHSA-6rw8-gcfv-wh9c.json +++ b/advisories/unreviewed/2022/04/GHSA-6rw8-gcfv-wh9c/GHSA-6rw8-gcfv-wh9c.json @@ -7,12 +7,8 @@ "CVE-2001-0019" ], "details": "Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the \"show script,\" \"clear script,\" \"show archive,\" \"clear archive,\" \"show log,\" or \"clear log\" commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6rxm-4mhj-qqvc/GHSA-6rxm-4mhj-qqvc.json b/advisories/unreviewed/2022/04/GHSA-6rxm-4mhj-qqvc/GHSA-6rxm-4mhj-qqvc.json index 022b7cc1c4c..4c4af98a137 100644 --- a/advisories/unreviewed/2022/04/GHSA-6rxm-4mhj-qqvc/GHSA-6rxm-4mhj-qqvc.json +++ b/advisories/unreviewed/2022/04/GHSA-6rxm-4mhj-qqvc/GHSA-6rxm-4mhj-qqvc.json @@ -7,12 +7,8 @@ "CVE-2001-0030" ], "details": "FoolProof 3.9 allows local users to bypass program execution restrictions by downloading the restricted executables from another source and renaming them.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6v8c-3mh5-j3wq/GHSA-6v8c-3mh5-j3wq.json b/advisories/unreviewed/2022/04/GHSA-6v8c-3mh5-j3wq/GHSA-6v8c-3mh5-j3wq.json index 099bbda7a2f..7bc243e0df3 100644 --- a/advisories/unreviewed/2022/04/GHSA-6v8c-3mh5-j3wq/GHSA-6v8c-3mh5-j3wq.json +++ b/advisories/unreviewed/2022/04/GHSA-6v8c-3mh5-j3wq/GHSA-6v8c-3mh5-j3wq.json @@ -7,12 +7,8 @@ "CVE-2001-0066" ], "details": "Secure Locate (slocate) allows local users to corrupt memory via a malformed database file that specifies an offset value that accesses memory outside of the intended buffer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-74jv-3pf7-q5p8/GHSA-74jv-3pf7-q5p8.json b/advisories/unreviewed/2022/04/GHSA-74jv-3pf7-q5p8/GHSA-74jv-3pf7-q5p8.json index 57eb84ad9ab..2f817dbdd48 100644 --- a/advisories/unreviewed/2022/04/GHSA-74jv-3pf7-q5p8/GHSA-74jv-3pf7-q5p8.json +++ b/advisories/unreviewed/2022/04/GHSA-74jv-3pf7-q5p8/GHSA-74jv-3pf7-q5p8.json @@ -7,12 +7,8 @@ "CVE-2001-0017" ], "details": "Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka the \"Malformed PPTP Packet Stream\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-74wp-49jv-9x5m/GHSA-74wp-49jv-9x5m.json b/advisories/unreviewed/2022/04/GHSA-74wp-49jv-9x5m/GHSA-74wp-49jv-9x5m.json index c3971710163..925d6be0bb9 100644 --- a/advisories/unreviewed/2022/04/GHSA-74wp-49jv-9x5m/GHSA-74wp-49jv-9x5m.json +++ b/advisories/unreviewed/2022/04/GHSA-74wp-49jv-9x5m/GHSA-74wp-49jv-9x5m.json @@ -7,12 +7,8 @@ "CVE-2000-1217" ], "details": "Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login attempts, aka the \"Domain Account Lockout\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7753-m7xj-hvxr/GHSA-7753-m7xj-hvxr.json b/advisories/unreviewed/2022/04/GHSA-7753-m7xj-hvxr/GHSA-7753-m7xj-hvxr.json index 0d7fca4fc7d..2ac762ffae0 100644 --- a/advisories/unreviewed/2022/04/GHSA-7753-m7xj-hvxr/GHSA-7753-m7xj-hvxr.json +++ b/advisories/unreviewed/2022/04/GHSA-7753-m7xj-hvxr/GHSA-7753-m7xj-hvxr.json @@ -7,12 +7,8 @@ "CVE-2000-1095" ], "details": "modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7774-m57j-3qmq/GHSA-7774-m57j-3qmq.json b/advisories/unreviewed/2022/04/GHSA-7774-m57j-3qmq/GHSA-7774-m57j-3qmq.json index eb2bb0ee7fe..5dbf7a81491 100644 --- a/advisories/unreviewed/2022/04/GHSA-7774-m57j-3qmq/GHSA-7774-m57j-3qmq.json +++ b/advisories/unreviewed/2022/04/GHSA-7774-m57j-3qmq/GHSA-7774-m57j-3qmq.json @@ -7,12 +7,8 @@ "CVE-2001-0072" ], "details": "gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-78mp-j9hf-999h/GHSA-78mp-j9hf-999h.json b/advisories/unreviewed/2022/04/GHSA-78mp-j9hf-999h/GHSA-78mp-j9hf-999h.json index f0e866ca09b..eecd6f56d09 100644 --- a/advisories/unreviewed/2022/04/GHSA-78mp-j9hf-999h/GHSA-78mp-j9hf-999h.json +++ b/advisories/unreviewed/2022/04/GHSA-78mp-j9hf-999h/GHSA-78mp-j9hf-999h.json @@ -7,12 +7,8 @@ "CVE-2000-1245" ], "details": "Multiple unspecified vulnerabilities in NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allow remote attackers to bypass intended restrictions on anonymous access via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-79g6-x9gh-wwqv/GHSA-79g6-x9gh-wwqv.json b/advisories/unreviewed/2022/04/GHSA-79g6-x9gh-wwqv/GHSA-79g6-x9gh-wwqv.json index 7df26820508..c38757e0468 100644 --- a/advisories/unreviewed/2022/04/GHSA-79g6-x9gh-wwqv/GHSA-79g6-x9gh-wwqv.json +++ b/advisories/unreviewed/2022/04/GHSA-79g6-x9gh-wwqv/GHSA-79g6-x9gh-wwqv.json @@ -7,12 +7,8 @@ "CVE-2000-1071" ], "details": "The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an \"xhost +\" command, which allows remote attackers to monitor X Windows events and gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7c6m-w964-4jjh/GHSA-7c6m-w964-4jjh.json b/advisories/unreviewed/2022/04/GHSA-7c6m-w964-4jjh/GHSA-7c6m-w964-4jjh.json index 94e1b880192..c01af902aff 100644 --- a/advisories/unreviewed/2022/04/GHSA-7c6m-w964-4jjh/GHSA-7c6m-w964-4jjh.json +++ b/advisories/unreviewed/2022/04/GHSA-7c6m-w964-4jjh/GHSA-7c6m-w964-4jjh.json @@ -7,12 +7,8 @@ "CVE-2000-1191" ], "details": "htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-7gg7-9cpw-h9r9/GHSA-7gg7-9cpw-h9r9.json b/advisories/unreviewed/2022/04/GHSA-7gg7-9cpw-h9r9/GHSA-7gg7-9cpw-h9r9.json index b47365da297..c6f556625d4 100644 --- a/advisories/unreviewed/2022/04/GHSA-7gg7-9cpw-h9r9/GHSA-7gg7-9cpw-h9r9.json +++ b/advisories/unreviewed/2022/04/GHSA-7gg7-9cpw-h9r9/GHSA-7gg7-9cpw-h9r9.json @@ -7,12 +7,8 @@ "CVE-2001-0084" ], "details": "GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7j25-vh8m-jjf9/GHSA-7j25-vh8m-jjf9.json b/advisories/unreviewed/2022/04/GHSA-7j25-vh8m-jjf9/GHSA-7j25-vh8m-jjf9.json index 036f004432b..c614ba76a44 100644 --- a/advisories/unreviewed/2022/04/GHSA-7j25-vh8m-jjf9/GHSA-7j25-vh8m-jjf9.json +++ b/advisories/unreviewed/2022/04/GHSA-7j25-vh8m-jjf9/GHSA-7j25-vh8m-jjf9.json @@ -7,12 +7,8 @@ "CVE-2001-0018" ], "details": "Windows 2000 domain controller in Windows 2000 Server, Advanced Server, or Datacenter Server allows remote attackers to cause a denial of service via a flood of malformed service requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7qjj-6hw3-3hc4/GHSA-7qjj-6hw3-3hc4.json b/advisories/unreviewed/2022/04/GHSA-7qjj-6hw3-3hc4/GHSA-7qjj-6hw3-3hc4.json index ca5947a2a26..0773ade1ccc 100644 --- a/advisories/unreviewed/2022/04/GHSA-7qjj-6hw3-3hc4/GHSA-7qjj-6hw3-3hc4.json +++ b/advisories/unreviewed/2022/04/GHSA-7qjj-6hw3-3hc4/GHSA-7qjj-6hw3-3hc4.json @@ -7,12 +7,8 @@ "CVE-2000-1128" ], "details": "The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the search path and allows local users to place a Trojan horse \"common.exe\" program in the C:\\Program Files directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7rc9-qwrm-pj39/GHSA-7rc9-qwrm-pj39.json b/advisories/unreviewed/2022/04/GHSA-7rc9-qwrm-pj39/GHSA-7rc9-qwrm-pj39.json index 4998cbaffec..1cf2afd1908 100644 --- a/advisories/unreviewed/2022/04/GHSA-7rc9-qwrm-pj39/GHSA-7rc9-qwrm-pj39.json +++ b/advisories/unreviewed/2022/04/GHSA-7rc9-qwrm-pj39/GHSA-7rc9-qwrm-pj39.json @@ -7,12 +7,8 @@ "CVE-2000-1173" ], "details": "Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could allow attackers to sniff network traffic and obtain this sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7v9m-g864-6c85/GHSA-7v9m-g864-6c85.json b/advisories/unreviewed/2022/04/GHSA-7v9m-g864-6c85/GHSA-7v9m-g864-6c85.json index 8812c721cd5..617bea5e669 100644 --- a/advisories/unreviewed/2022/04/GHSA-7v9m-g864-6c85/GHSA-7v9m-g864-6c85.json +++ b/advisories/unreviewed/2022/04/GHSA-7v9m-g864-6c85/GHSA-7v9m-g864-6c85.json @@ -7,12 +7,8 @@ "CVE-2000-1131" ], "details": "Bill Kendrick web site guestbook (GBook) allows remote attackers to execute arbitrary commands via shell metacharacters in the _MAILTO form variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7vhp-9g42-7c8w/GHSA-7vhp-9g42-7c8w.json b/advisories/unreviewed/2022/04/GHSA-7vhp-9g42-7c8w/GHSA-7vhp-9g42-7c8w.json index a5fdd242340..e0137caf8e7 100644 --- a/advisories/unreviewed/2022/04/GHSA-7vhp-9g42-7c8w/GHSA-7vhp-9g42-7c8w.json +++ b/advisories/unreviewed/2022/04/GHSA-7vhp-9g42-7c8w/GHSA-7vhp-9g42-7c8w.json @@ -7,12 +7,8 @@ "CVE-2001-0044" ], "details": "Multiple buffer overflows in Lexmark MarkVision printer driver programs allows local users to gain privileges via long arguments to the cat_network, cat_paraller, and cat_serial commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7vq5-5wrf-3x9x/GHSA-7vq5-5wrf-3x9x.json b/advisories/unreviewed/2022/04/GHSA-7vq5-5wrf-3x9x/GHSA-7vq5-5wrf-3x9x.json index 19340787c11..9061a20c56e 100644 --- a/advisories/unreviewed/2022/04/GHSA-7vq5-5wrf-3x9x/GHSA-7vq5-5wrf-3x9x.json +++ b/advisories/unreviewed/2022/04/GHSA-7vq5-5wrf-3x9x/GHSA-7vq5-5wrf-3x9x.json @@ -7,12 +7,8 @@ "CVE-2000-1097" ], "details": "The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via a long username in the authentication page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7xfr-jcwg-59w6/GHSA-7xfr-jcwg-59w6.json b/advisories/unreviewed/2022/04/GHSA-7xfr-jcwg-59w6/GHSA-7xfr-jcwg-59w6.json index 799e38bcf61..e446ea35032 100644 --- a/advisories/unreviewed/2022/04/GHSA-7xfr-jcwg-59w6/GHSA-7xfr-jcwg-59w6.json +++ b/advisories/unreviewed/2022/04/GHSA-7xfr-jcwg-59w6/GHSA-7xfr-jcwg-59w6.json @@ -7,12 +7,8 @@ "CVE-2000-1231" ], "details": "code.php3 in Phorum 3.0.7 allows remote attackers to read arbitrary files in the phorum directory via the query string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7xj2-6g55-85x5/GHSA-7xj2-6g55-85x5.json b/advisories/unreviewed/2022/04/GHSA-7xj2-6g55-85x5/GHSA-7xj2-6g55-85x5.json index 989f8272f2f..293d55ffe22 100644 --- a/advisories/unreviewed/2022/04/GHSA-7xj2-6g55-85x5/GHSA-7xj2-6g55-85x5.json +++ b/advisories/unreviewed/2022/04/GHSA-7xj2-6g55-85x5/GHSA-7xj2-6g55-85x5.json @@ -7,12 +7,8 @@ "CVE-2001-0057" ], "details": "Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-86gg-6jj3-7gxr/GHSA-86gg-6jj3-7gxr.json b/advisories/unreviewed/2022/04/GHSA-86gg-6jj3-7gxr/GHSA-86gg-6jj3-7gxr.json index 0608ebd1d24..5aa8f5d0bdd 100644 --- a/advisories/unreviewed/2022/04/GHSA-86gg-6jj3-7gxr/GHSA-86gg-6jj3-7gxr.json +++ b/advisories/unreviewed/2022/04/GHSA-86gg-6jj3-7gxr/GHSA-86gg-6jj3-7gxr.json @@ -7,12 +7,8 @@ "CVE-2000-1083" ], "details": "The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the \"Extended Stored Procedure Parameter Parsing\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-86jg-3549-x2qh/GHSA-86jg-3549-x2qh.json b/advisories/unreviewed/2022/04/GHSA-86jg-3549-x2qh/GHSA-86jg-3549-x2qh.json index 0112ac64a08..942e6512a76 100644 --- a/advisories/unreviewed/2022/04/GHSA-86jg-3549-x2qh/GHSA-86jg-3549-x2qh.json +++ b/advisories/unreviewed/2022/04/GHSA-86jg-3549-x2qh/GHSA-86jg-3549-x2qh.json @@ -7,12 +7,8 @@ "CVE-2000-1151" ], "details": "Baxter IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-86wp-r8x2-p694/GHSA-86wp-r8x2-p694.json b/advisories/unreviewed/2022/04/GHSA-86wp-r8x2-p694/GHSA-86wp-r8x2-p694.json index 51052d740aa..72800b72b99 100644 --- a/advisories/unreviewed/2022/04/GHSA-86wp-r8x2-p694/GHSA-86wp-r8x2-p694.json +++ b/advisories/unreviewed/2022/04/GHSA-86wp-r8x2-p694/GHSA-86wp-r8x2-p694.json @@ -7,12 +7,8 @@ "CVE-2000-1234" ], "details": "violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a \"spam proxy\" by setting the Mod and ForumName parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-88g6-h8fq-4gqq/GHSA-88g6-h8fq-4gqq.json b/advisories/unreviewed/2022/04/GHSA-88g6-h8fq-4gqq/GHSA-88g6-h8fq-4gqq.json index fef6ac9a50e..7f1a2b89298 100644 --- a/advisories/unreviewed/2022/04/GHSA-88g6-h8fq-4gqq/GHSA-88g6-h8fq-4gqq.json +++ b/advisories/unreviewed/2022/04/GHSA-88g6-h8fq-4gqq/GHSA-88g6-h8fq-4gqq.json @@ -7,12 +7,8 @@ "CVE-2000-1181" ], "details": "Real Networks RealServer 7 and earlier allows remote attackers to obtain portions of RealServer's memory contents, possibly including sensitive information, by accessing the /admin/includes/ URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-88hx-73hq-hqfj/GHSA-88hx-73hq-hqfj.json b/advisories/unreviewed/2022/04/GHSA-88hx-73hq-hqfj/GHSA-88hx-73hq-hqfj.json index 838e1d533d1..f91d97c87be 100644 --- a/advisories/unreviewed/2022/04/GHSA-88hx-73hq-hqfj/GHSA-88hx-73hq-hqfj.json +++ b/advisories/unreviewed/2022/04/GHSA-88hx-73hq-hqfj/GHSA-88hx-73hq-hqfj.json @@ -7,12 +7,8 @@ "CVE-2000-1229" ], "details": "Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via \"..\" (dot dot) sequences in the default .langfile name field in the Master Settings administrative function, which causes the file to be displayed in admin.php3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8cmj-8gv7-x3wc/GHSA-8cmj-8gv7-x3wc.json b/advisories/unreviewed/2022/04/GHSA-8cmj-8gv7-x3wc/GHSA-8cmj-8gv7-x3wc.json index 6680de3752f..d73cd06b432 100644 --- a/advisories/unreviewed/2022/04/GHSA-8cmj-8gv7-x3wc/GHSA-8cmj-8gv7-x3wc.json +++ b/advisories/unreviewed/2022/04/GHSA-8cmj-8gv7-x3wc/GHSA-8cmj-8gv7-x3wc.json @@ -7,12 +7,8 @@ "CVE-2000-1123" ], "details": "Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8fc3-whhg-8qw8/GHSA-8fc3-whhg-8qw8.json b/advisories/unreviewed/2022/04/GHSA-8fc3-whhg-8qw8/GHSA-8fc3-whhg-8qw8.json index 657455f3c17..3cdafa6aaf0 100644 --- a/advisories/unreviewed/2022/04/GHSA-8fc3-whhg-8qw8/GHSA-8fc3-whhg-8qw8.json +++ b/advisories/unreviewed/2022/04/GHSA-8fc3-whhg-8qw8/GHSA-8fc3-whhg-8qw8.json @@ -7,12 +7,8 @@ "CVE-2001-0100" ], "details": "bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8hx3-74gm-vfhh/GHSA-8hx3-74gm-vfhh.json b/advisories/unreviewed/2022/04/GHSA-8hx3-74gm-vfhh/GHSA-8hx3-74gm-vfhh.json index d27c0a9f98e..91a3b8bcd4f 100644 --- a/advisories/unreviewed/2022/04/GHSA-8hx3-74gm-vfhh/GHSA-8hx3-74gm-vfhh.json +++ b/advisories/unreviewed/2022/04/GHSA-8hx3-74gm-vfhh/GHSA-8hx3-74gm-vfhh.json @@ -7,12 +7,8 @@ "CVE-2001-0016" ], "details": "NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8rmj-m7m9-7ph8/GHSA-8rmj-m7m9-7ph8.json b/advisories/unreviewed/2022/04/GHSA-8rmj-m7m9-7ph8/GHSA-8rmj-m7m9-7ph8.json index efb96a4e27f..3e4d10e6ac8 100644 --- a/advisories/unreviewed/2022/04/GHSA-8rmj-m7m9-7ph8/GHSA-8rmj-m7m9-7ph8.json +++ b/advisories/unreviewed/2022/04/GHSA-8rmj-m7m9-7ph8/GHSA-8rmj-m7m9-7ph8.json @@ -7,12 +7,8 @@ "CVE-2001-0026" ], "details": "rp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet with a zero-length TCP option.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8v75-gpj5-x889/GHSA-8v75-gpj5-x889.json b/advisories/unreviewed/2022/04/GHSA-8v75-gpj5-x889/GHSA-8v75-gpj5-x889.json index 88c97a7efc8..7d11848311b 100644 --- a/advisories/unreviewed/2022/04/GHSA-8v75-gpj5-x889/GHSA-8v75-gpj5-x889.json +++ b/advisories/unreviewed/2022/04/GHSA-8v75-gpj5-x889/GHSA-8v75-gpj5-x889.json @@ -7,12 +7,8 @@ "CVE-2000-1233" ], "details": "SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary SQL queries via the sSQL parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8vvr-9c5j-9q97/GHSA-8vvr-9c5j-9q97.json b/advisories/unreviewed/2022/04/GHSA-8vvr-9c5j-9q97/GHSA-8vvr-9c5j-9q97.json index 59e6f862752..12914a6ac48 100644 --- a/advisories/unreviewed/2022/04/GHSA-8vvr-9c5j-9q97/GHSA-8vvr-9c5j-9q97.json +++ b/advisories/unreviewed/2022/04/GHSA-8vvr-9c5j-9q97/GHSA-8vvr-9c5j-9q97.json @@ -7,12 +7,8 @@ "CVE-2000-1204" ], "details": "Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8vx4-2r25-7xmp/GHSA-8vx4-2r25-7xmp.json b/advisories/unreviewed/2022/04/GHSA-8vx4-2r25-7xmp/GHSA-8vx4-2r25-7xmp.json index c6bc6fc7b69..e9d2f3615ac 100644 --- a/advisories/unreviewed/2022/04/GHSA-8vx4-2r25-7xmp/GHSA-8vx4-2r25-7xmp.json +++ b/advisories/unreviewed/2022/04/GHSA-8vx4-2r25-7xmp/GHSA-8vx4-2r25-7xmp.json @@ -7,12 +7,8 @@ "CVE-2001-0024" ], "details": "simplestmail.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the MyEmail parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8w27-q26q-hv6f/GHSA-8w27-q26q-hv6f.json b/advisories/unreviewed/2022/04/GHSA-8w27-q26q-hv6f/GHSA-8w27-q26q-hv6f.json index c873c38a9c4..fbc2f1f0499 100644 --- a/advisories/unreviewed/2022/04/GHSA-8w27-q26q-hv6f/GHSA-8w27-q26q-hv6f.json +++ b/advisories/unreviewed/2022/04/GHSA-8w27-q26q-hv6f/GHSA-8w27-q26q-hv6f.json @@ -7,12 +7,8 @@ "CVE-2000-1241" ], "details": "Unspecified vulnerability in Haakon Nilsen simple, integrated publishing system (SIPS) before 0.2.4 has an unknown impact and attack vectors, related to a \"grave security fault.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8w32-x5px-mww7/GHSA-8w32-x5px-mww7.json b/advisories/unreviewed/2022/04/GHSA-8w32-x5px-mww7/GHSA-8w32-x5px-mww7.json index 05335c0877e..423afe0156c 100644 --- a/advisories/unreviewed/2022/04/GHSA-8w32-x5px-mww7/GHSA-8w32-x5px-mww7.json +++ b/advisories/unreviewed/2022/04/GHSA-8w32-x5px-mww7/GHSA-8w32-x5px-mww7.json @@ -7,12 +7,8 @@ "CVE-2000-1152" ], "details": "Browser IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8xcj-rh5m-9gwr/GHSA-8xcj-rh5m-9gwr.json b/advisories/unreviewed/2022/04/GHSA-8xcj-rh5m-9gwr/GHSA-8xcj-rh5m-9gwr.json index d62c9e78c44..6c818abc1cb 100644 --- a/advisories/unreviewed/2022/04/GHSA-8xcj-rh5m-9gwr/GHSA-8xcj-rh5m-9gwr.json +++ b/advisories/unreviewed/2022/04/GHSA-8xcj-rh5m-9gwr/GHSA-8xcj-rh5m-9gwr.json @@ -7,12 +7,8 @@ "CVE-2000-1148" ], "details": "The installation of VolanoChatPro chat server sets world-readable permissions for its configuration file and stores the server administrator passwords in plaintext, which allows local users to gain privileges on the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-92vr-7cqw-xc63/GHSA-92vr-7cqw-xc63.json b/advisories/unreviewed/2022/04/GHSA-92vr-7cqw-xc63/GHSA-92vr-7cqw-xc63.json index bc905be0141..665d5b088ac 100644 --- a/advisories/unreviewed/2022/04/GHSA-92vr-7cqw-xc63/GHSA-92vr-7cqw-xc63.json +++ b/advisories/unreviewed/2022/04/GHSA-92vr-7cqw-xc63/GHSA-92vr-7cqw-xc63.json @@ -7,12 +7,8 @@ "CVE-2000-1202" ], "details": "ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-93c3-33ph-vcvv/GHSA-93c3-33ph-vcvv.json b/advisories/unreviewed/2022/04/GHSA-93c3-33ph-vcvv/GHSA-93c3-33ph-vcvv.json index 067b8c3b0a9..1aba4ad58bb 100644 --- a/advisories/unreviewed/2022/04/GHSA-93c3-33ph-vcvv/GHSA-93c3-33ph-vcvv.json +++ b/advisories/unreviewed/2022/04/GHSA-93c3-33ph-vcvv/GHSA-93c3-33ph-vcvv.json @@ -7,12 +7,8 @@ "CVE-2000-1182" ], "details": "WatchGuard Firebox II allows remote attackers to cause a denial of service by flooding the Firebox with a large number of FTP or SMTP requests, which disables proxy handling.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9723-j4pc-8jhh/GHSA-9723-j4pc-8jhh.json b/advisories/unreviewed/2022/04/GHSA-9723-j4pc-8jhh/GHSA-9723-j4pc-8jhh.json index cb07226621b..93f6fb1f357 100644 --- a/advisories/unreviewed/2022/04/GHSA-9723-j4pc-8jhh/GHSA-9723-j4pc-8jhh.json +++ b/advisories/unreviewed/2022/04/GHSA-9723-j4pc-8jhh/GHSA-9723-j4pc-8jhh.json @@ -7,12 +7,8 @@ "CVE-2001-0070" ], "details": "Buffer overflow in 1st Up Mail Server 4.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long MAIL FROM command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-97xg-79hm-5c93/GHSA-97xg-79hm-5c93.json b/advisories/unreviewed/2022/04/GHSA-97xg-79hm-5c93/GHSA-97xg-79hm-5c93.json index 9f2b106b51e..28a1e9c4332 100644 --- a/advisories/unreviewed/2022/04/GHSA-97xg-79hm-5c93/GHSA-97xg-79hm-5c93.json +++ b/advisories/unreviewed/2022/04/GHSA-97xg-79hm-5c93/GHSA-97xg-79hm-5c93.json @@ -7,12 +7,8 @@ "CVE-2000-1246" ], "details": "NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allows remote authenticated users to cause a denial of service (abend) by sending an RNTO command after a failed RNFR command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-9c79-794f-fgpf/GHSA-9c79-794f-fgpf.json b/advisories/unreviewed/2022/04/GHSA-9c79-794f-fgpf/GHSA-9c79-794f-fgpf.json index 521fec1d2ae..a0d78fe3c68 100644 --- a/advisories/unreviewed/2022/04/GHSA-9c79-794f-fgpf/GHSA-9c79-794f-fgpf.json +++ b/advisories/unreviewed/2022/04/GHSA-9c79-794f-fgpf/GHSA-9c79-794f-fgpf.json @@ -7,12 +7,8 @@ "CVE-2000-1242" ], "details": "The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain system access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9ccp-985w-grj6/GHSA-9ccp-985w-grj6.json b/advisories/unreviewed/2022/04/GHSA-9ccp-985w-grj6/GHSA-9ccp-985w-grj6.json index 469df34d06f..e1e6c45ef68 100644 --- a/advisories/unreviewed/2022/04/GHSA-9ccp-985w-grj6/GHSA-9ccp-985w-grj6.json +++ b/advisories/unreviewed/2022/04/GHSA-9ccp-985w-grj6/GHSA-9ccp-985w-grj6.json @@ -7,12 +7,8 @@ "CVE-2000-1199" ], "details": "PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9g5p-gm42-j3hq/GHSA-9g5p-gm42-j3hq.json b/advisories/unreviewed/2022/04/GHSA-9g5p-gm42-j3hq/GHSA-9g5p-gm42-j3hq.json index 4a71fa4d344..165eeebdd8c 100644 --- a/advisories/unreviewed/2022/04/GHSA-9g5p-gm42-j3hq/GHSA-9g5p-gm42-j3hq.json +++ b/advisories/unreviewed/2022/04/GHSA-9g5p-gm42-j3hq/GHSA-9g5p-gm42-j3hq.json @@ -7,12 +7,8 @@ "CVE-2000-1159" ], "details": "NAI Sniffer Agent allows remote attackers to gain privileges on the agent by sniffing the initial UDP authentication packets and spoofing commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9g9j-gh9g-48x5/GHSA-9g9j-gh9g-48x5.json b/advisories/unreviewed/2022/04/GHSA-9g9j-gh9g-48x5/GHSA-9g9j-gh9g-48x5.json index 665202c2dac..fd94c601fa4 100644 --- a/advisories/unreviewed/2022/04/GHSA-9g9j-gh9g-48x5/GHSA-9g9j-gh9g-48x5.json +++ b/advisories/unreviewed/2022/04/GHSA-9g9j-gh9g-48x5/GHSA-9g9j-gh9g-48x5.json @@ -7,12 +7,8 @@ "CVE-2000-1069" ], "details": "pollit.cgi in Poll It 2.01 and earlier allows remote attackers to access administrative functions without knowing the real password by specifying the same value to the entered_password and admin_password parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9gmh-g2w2-5jwr/GHSA-9gmh-g2w2-5jwr.json b/advisories/unreviewed/2022/04/GHSA-9gmh-g2w2-5jwr/GHSA-9gmh-g2w2-5jwr.json index 4bf0b76b027..99099817314 100644 --- a/advisories/unreviewed/2022/04/GHSA-9gmh-g2w2-5jwr/GHSA-9gmh-g2w2-5jwr.json +++ b/advisories/unreviewed/2022/04/GHSA-9gmh-g2w2-5jwr/GHSA-9gmh-g2w2-5jwr.json @@ -7,12 +7,8 @@ "CVE-2001-0049" ], "details": "WatchGuard SOHO FireWall 2.2.1 and earlier allows remote attackers to cause a denial of service via a large number of GET requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9jr7-h23f-xwrr/GHSA-9jr7-h23f-xwrr.json b/advisories/unreviewed/2022/04/GHSA-9jr7-h23f-xwrr/GHSA-9jr7-h23f-xwrr.json index 48df3e2c3fb..22c83e96239 100644 --- a/advisories/unreviewed/2022/04/GHSA-9jr7-h23f-xwrr/GHSA-9jr7-h23f-xwrr.json +++ b/advisories/unreviewed/2022/04/GHSA-9jr7-h23f-xwrr/GHSA-9jr7-h23f-xwrr.json @@ -7,12 +7,8 @@ "CVE-2000-1192" ], "details": "Buffer overflow in BTT Software SNMP Trap Watcher 1.16 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string trap.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9p6g-hv89-h5mg/GHSA-9p6g-hv89-h5mg.json b/advisories/unreviewed/2022/04/GHSA-9p6g-hv89-h5mg/GHSA-9p6g-hv89-h5mg.json index 06f8994c3c6..1d5eee2ce89 100644 --- a/advisories/unreviewed/2022/04/GHSA-9p6g-hv89-h5mg/GHSA-9p6g-hv89-h5mg.json +++ b/advisories/unreviewed/2022/04/GHSA-9p6g-hv89-h5mg/GHSA-9p6g-hv89-h5mg.json @@ -7,12 +7,8 @@ "CVE-2000-1135" ], "details": "fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a symlink attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9q3h-6h4j-523q/GHSA-9q3h-6h4j-523q.json b/advisories/unreviewed/2022/04/GHSA-9q3h-6h4j-523q/GHSA-9q3h-6h4j-523q.json index 4dbe76b6130..2e439bd9861 100644 --- a/advisories/unreviewed/2022/04/GHSA-9q3h-6h4j-523q/GHSA-9q3h-6h4j-523q.json +++ b/advisories/unreviewed/2022/04/GHSA-9q3h-6h4j-523q/GHSA-9q3h-6h4j-523q.json @@ -7,12 +7,8 @@ "CVE-2001-0075" ], "details": "Directory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the filename parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9v82-8g5x-9fg5/GHSA-9v82-8g5x-9fg5.json b/advisories/unreviewed/2022/04/GHSA-9v82-8g5x-9fg5/GHSA-9v82-8g5x-9fg5.json index f49cbd647f9..d95bf874f19 100644 --- a/advisories/unreviewed/2022/04/GHSA-9v82-8g5x-9fg5/GHSA-9v82-8g5x-9fg5.json +++ b/advisories/unreviewed/2022/04/GHSA-9v82-8g5x-9fg5/GHSA-9v82-8g5x-9fg5.json @@ -7,12 +7,8 @@ "CVE-2001-0059" ], "details": "patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9xcw-j87f-mh2g/GHSA-9xcw-j87f-mh2g.json b/advisories/unreviewed/2022/04/GHSA-9xcw-j87f-mh2g/GHSA-9xcw-j87f-mh2g.json index cb3c302e861..e3c5b78c3d2 100644 --- a/advisories/unreviewed/2022/04/GHSA-9xcw-j87f-mh2g/GHSA-9xcw-j87f-mh2g.json +++ b/advisories/unreviewed/2022/04/GHSA-9xcw-j87f-mh2g/GHSA-9xcw-j87f-mh2g.json @@ -7,12 +7,8 @@ "CVE-2001-0064" ], "details": "Webconfig, IMAP, and other services in MDaemon 3.5.0 and earlier allows remote attackers to cause a denial of service via a long URL terminated by a \"\\r\\n\" string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9xf3-j46h-rvq4/GHSA-9xf3-j46h-rvq4.json b/advisories/unreviewed/2022/04/GHSA-9xf3-j46h-rvq4/GHSA-9xf3-j46h-rvq4.json index e1365c1bfef..028ed19b67e 100644 --- a/advisories/unreviewed/2022/04/GHSA-9xf3-j46h-rvq4/GHSA-9xf3-j46h-rvq4.json +++ b/advisories/unreviewed/2022/04/GHSA-9xf3-j46h-rvq4/GHSA-9xf3-j46h-rvq4.json @@ -7,12 +7,8 @@ "CVE-2001-0067" ], "details": "The installation of J-Pilot creates the .jpilot directory with the user's umask, which could allow local attackers to read other users' PalmOS backup information if their umasks are not securely set.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c5rg-f3hx-6hcg/GHSA-c5rg-f3hx-6hcg.json b/advisories/unreviewed/2022/04/GHSA-c5rg-f3hx-6hcg/GHSA-c5rg-f3hx-6hcg.json index 923a15b7f78..cd1911ced49 100644 --- a/advisories/unreviewed/2022/04/GHSA-c5rg-f3hx-6hcg/GHSA-c5rg-f3hx-6hcg.json +++ b/advisories/unreviewed/2022/04/GHSA-c5rg-f3hx-6hcg/GHSA-c5rg-f3hx-6hcg.json @@ -7,12 +7,8 @@ "CVE-2001-0029" ], "details": "Buffer overflow in oops WWW proxy server 1.4.6 (and possibly other versions) allows remote attackers to execute arbitrary commands via a long host or domain name that is obtained from a reverse DNS lookup.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c5vm-cg9p-c7r9/GHSA-c5vm-cg9p-c7r9.json b/advisories/unreviewed/2022/04/GHSA-c5vm-cg9p-c7r9/GHSA-c5vm-cg9p-c7r9.json index 2b9c286fa00..f9a3bdc3e47 100644 --- a/advisories/unreviewed/2022/04/GHSA-c5vm-cg9p-c7r9/GHSA-c5vm-cg9p-c7r9.json +++ b/advisories/unreviewed/2022/04/GHSA-c5vm-cg9p-c7r9/GHSA-c5vm-cg9p-c7r9.json @@ -7,12 +7,8 @@ "CVE-2000-1228" ], "details": "Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c67w-7c4h-rcfv/GHSA-c67w-7c4h-rcfv.json b/advisories/unreviewed/2022/04/GHSA-c67w-7c4h-rcfv/GHSA-c67w-7c4h-rcfv.json index 91544def5a3..f80ff2a8db4 100644 --- a/advisories/unreviewed/2022/04/GHSA-c67w-7c4h-rcfv/GHSA-c67w-7c4h-rcfv.json +++ b/advisories/unreviewed/2022/04/GHSA-c67w-7c4h-rcfv/GHSA-c67w-7c4h-rcfv.json @@ -7,12 +7,8 @@ "CVE-2000-1101" ], "details": "Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the \"Restrict to home directory\" option enabled allows local users to escape the home directory via a \"/../\" string, a variation of the .. (dot dot) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c835-vr4r-5hjm/GHSA-c835-vr4r-5hjm.json b/advisories/unreviewed/2022/04/GHSA-c835-vr4r-5hjm/GHSA-c835-vr4r-5hjm.json index cd65d59df61..a437e988325 100644 --- a/advisories/unreviewed/2022/04/GHSA-c835-vr4r-5hjm/GHSA-c835-vr4r-5hjm.json +++ b/advisories/unreviewed/2022/04/GHSA-c835-vr4r-5hjm/GHSA-c835-vr4r-5hjm.json @@ -7,12 +7,8 @@ "CVE-2000-1070" ], "details": "pollit.cgi in Poll It 2.01 and earlier uses data files that are located under the web document root, which allows remote attackers to access sensitive or private information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c88c-2pvm-pq8x/GHSA-c88c-2pvm-pq8x.json b/advisories/unreviewed/2022/04/GHSA-c88c-2pvm-pq8x/GHSA-c88c-2pvm-pq8x.json index 57bb84821bc..3044bfe86ff 100644 --- a/advisories/unreviewed/2022/04/GHSA-c88c-2pvm-pq8x/GHSA-c88c-2pvm-pq8x.json +++ b/advisories/unreviewed/2022/04/GHSA-c88c-2pvm-pq8x/GHSA-c88c-2pvm-pq8x.json @@ -7,12 +7,8 @@ "CVE-2000-1164" ], "details": "WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows users to read and modify sensitive information such as passwords and gain access to the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c8f7-vr5w-4grr/GHSA-c8f7-vr5w-4grr.json b/advisories/unreviewed/2022/04/GHSA-c8f7-vr5w-4grr/GHSA-c8f7-vr5w-4grr.json index 9f97cba750b..835bec44f19 100644 --- a/advisories/unreviewed/2022/04/GHSA-c8f7-vr5w-4grr/GHSA-c8f7-vr5w-4grr.json +++ b/advisories/unreviewed/2022/04/GHSA-c8f7-vr5w-4grr/GHSA-c8f7-vr5w-4grr.json @@ -7,12 +7,8 @@ "CVE-2000-1129" ], "details": "McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c8jj-cpv9-8p64/GHSA-c8jj-cpv9-8p64.json b/advisories/unreviewed/2022/04/GHSA-c8jj-cpv9-8p64/GHSA-c8jj-cpv9-8p64.json index e267dd5c949..ab03930aff1 100644 --- a/advisories/unreviewed/2022/04/GHSA-c8jj-cpv9-8p64/GHSA-c8jj-cpv9-8p64.json +++ b/advisories/unreviewed/2022/04/GHSA-c8jj-cpv9-8p64/GHSA-c8jj-cpv9-8p64.json @@ -7,12 +7,8 @@ "CVE-2001-0076" ], "details": "register.cgi in Ikonboard 2.1.7b and earlier allows remote attackers to execute arbitrary commands via the SEND_MAIL parameter, which overwrites an internal program variable that references a program to be executed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c8q2-5c9q-67pp/GHSA-c8q2-5c9q-67pp.json b/advisories/unreviewed/2022/04/GHSA-c8q2-5c9q-67pp/GHSA-c8q2-5c9q-67pp.json index e1e9d8e26c7..5771f58f069 100644 --- a/advisories/unreviewed/2022/04/GHSA-c8q2-5c9q-67pp/GHSA-c8q2-5c9q-67pp.json +++ b/advisories/unreviewed/2022/04/GHSA-c8q2-5c9q-67pp/GHSA-c8q2-5c9q-67pp.json @@ -7,12 +7,8 @@ "CVE-2000-1149" ], "details": "Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to execute arbitrary commands via a long username, aka the \"Terminal Server Login Buffer Overflow\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c929-49h9-7vjw/GHSA-c929-49h9-7vjw.json b/advisories/unreviewed/2022/04/GHSA-c929-49h9-7vjw/GHSA-c929-49h9-7vjw.json index 268d5a24ddd..b3f5ac95c48 100644 --- a/advisories/unreviewed/2022/04/GHSA-c929-49h9-7vjw/GHSA-c929-49h9-7vjw.json +++ b/advisories/unreviewed/2022/04/GHSA-c929-49h9-7vjw/GHSA-c929-49h9-7vjw.json @@ -7,12 +7,8 @@ "CVE-2001-0038" ], "details": "Offline Explorer 1.4 before Service Release 2 allows remote attackers to read arbitrary files by specifying the drive letter (e.g. C:) in the requested URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c9hw-vvq5-mgcp/GHSA-c9hw-vvq5-mgcp.json b/advisories/unreviewed/2022/04/GHSA-c9hw-vvq5-mgcp/GHSA-c9hw-vvq5-mgcp.json index 2725e6a8ce7..d97b7260311 100644 --- a/advisories/unreviewed/2022/04/GHSA-c9hw-vvq5-mgcp/GHSA-c9hw-vvq5-mgcp.json +++ b/advisories/unreviewed/2022/04/GHSA-c9hw-vvq5-mgcp/GHSA-c9hw-vvq5-mgcp.json @@ -7,12 +7,8 @@ "CVE-2001-0105" ], "details": "Vulnerability in top in HP-UX 11.04 and earlier allows local users to overwrite files owned by the \"sys\" group.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cg89-cjrh-9925/GHSA-cg89-cjrh-9925.json b/advisories/unreviewed/2022/04/GHSA-cg89-cjrh-9925/GHSA-cg89-cjrh-9925.json index bb763bd179e..db686c3a3f4 100644 --- a/advisories/unreviewed/2022/04/GHSA-cg89-cjrh-9925/GHSA-cg89-cjrh-9925.json +++ b/advisories/unreviewed/2022/04/GHSA-cg89-cjrh-9925/GHSA-cg89-cjrh-9925.json @@ -7,12 +7,8 @@ "CVE-2000-1068" ], "details": "pollit.cgi in Poll It 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the poll_options parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ch7q-c6xm-9wg7/GHSA-ch7q-c6xm-9wg7.json b/advisories/unreviewed/2022/04/GHSA-ch7q-c6xm-9wg7/GHSA-ch7q-c6xm-9wg7.json index eb1944e2f74..b23b8f46431 100644 --- a/advisories/unreviewed/2022/04/GHSA-ch7q-c6xm-9wg7/GHSA-ch7q-c6xm-9wg7.json +++ b/advisories/unreviewed/2022/04/GHSA-ch7q-c6xm-9wg7/GHSA-ch7q-c6xm-9wg7.json @@ -7,12 +7,8 @@ "CVE-2001-0043" ], "details": "phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info parameter of the phpgw.inc.php program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cj3q-54vp-7x82/GHSA-cj3q-54vp-7x82.json b/advisories/unreviewed/2022/04/GHSA-cj3q-54vp-7x82/GHSA-cj3q-54vp-7x82.json index 5e8b62cdc2a..a6e9ef218d1 100644 --- a/advisories/unreviewed/2022/04/GHSA-cj3q-54vp-7x82/GHSA-cj3q-54vp-7x82.json +++ b/advisories/unreviewed/2022/04/GHSA-cj3q-54vp-7x82/GHSA-cj3q-54vp-7x82.json @@ -7,12 +7,8 @@ "CVE-2001-0021" ], "details": "MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cpcw-2gx9-xcwx/GHSA-cpcw-2gx9-xcwx.json b/advisories/unreviewed/2022/04/GHSA-cpcw-2gx9-xcwx/GHSA-cpcw-2gx9-xcwx.json index e8e9d240cc4..2e4967b74b3 100644 --- a/advisories/unreviewed/2022/04/GHSA-cpcw-2gx9-xcwx/GHSA-cpcw-2gx9-xcwx.json +++ b/advisories/unreviewed/2022/04/GHSA-cpcw-2gx9-xcwx/GHSA-cpcw-2gx9-xcwx.json @@ -7,12 +7,8 @@ "CVE-2001-0060" ], "details": "Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cr44-mv4m-96hc/GHSA-cr44-mv4m-96hc.json b/advisories/unreviewed/2022/04/GHSA-cr44-mv4m-96hc/GHSA-cr44-mv4m-96hc.json index 45d8797031e..d5c637cc9cb 100644 --- a/advisories/unreviewed/2022/04/GHSA-cr44-mv4m-96hc/GHSA-cr44-mv4m-96hc.json +++ b/advisories/unreviewed/2022/04/GHSA-cr44-mv4m-96hc/GHSA-cr44-mv4m-96hc.json @@ -7,12 +7,8 @@ "CVE-2000-1223" ], "details": "quikstore.cgi in Quikstore Shopping Cart allows remote attackers to execute arbitrary commands via shell metacharacters in the URL portion of an HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cwwh-357p-4xxx/GHSA-cwwh-357p-4xxx.json b/advisories/unreviewed/2022/04/GHSA-cwwh-357p-4xxx/GHSA-cwwh-357p-4xxx.json index 29f3f306a1e..315195d9db0 100644 --- a/advisories/unreviewed/2022/04/GHSA-cwwh-357p-4xxx/GHSA-cwwh-357p-4xxx.json +++ b/advisories/unreviewed/2022/04/GHSA-cwwh-357p-4xxx/GHSA-cwwh-357p-4xxx.json @@ -7,12 +7,8 @@ "CVE-2000-1157" ], "details": "Buffer overflow in NAI Sniffer Agent allows remote attackers to execute arbitrary commands via a long SNMP community name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cx9f-78r3-35wj/GHSA-cx9f-78r3-35wj.json b/advisories/unreviewed/2022/04/GHSA-cx9f-78r3-35wj/GHSA-cx9f-78r3-35wj.json index 2e2e3a2dedb..1ad54630a61 100644 --- a/advisories/unreviewed/2022/04/GHSA-cx9f-78r3-35wj/GHSA-cx9f-78r3-35wj.json +++ b/advisories/unreviewed/2022/04/GHSA-cx9f-78r3-35wj/GHSA-cx9f-78r3-35wj.json @@ -7,12 +7,8 @@ "CVE-2000-1120" ], "details": "Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f26q-3x93-ffxm/GHSA-f26q-3x93-ffxm.json b/advisories/unreviewed/2022/04/GHSA-f26q-3x93-ffxm/GHSA-f26q-3x93-ffxm.json index db9d303e04a..d122a5560cc 100644 --- a/advisories/unreviewed/2022/04/GHSA-f26q-3x93-ffxm/GHSA-f26q-3x93-ffxm.json +++ b/advisories/unreviewed/2022/04/GHSA-f26q-3x93-ffxm/GHSA-f26q-3x93-ffxm.json @@ -7,12 +7,8 @@ "CVE-2000-1118" ], "details": "24Link 1.06 web server allows remote attackers to bypass access restrictions by prepending strings such as \"/+/\" or \"/.\" to the HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f298-64xr-j8x2/GHSA-f298-64xr-j8x2.json b/advisories/unreviewed/2022/04/GHSA-f298-64xr-j8x2/GHSA-f298-64xr-j8x2.json index 19483ce2ed9..e25701dde67 100644 --- a/advisories/unreviewed/2022/04/GHSA-f298-64xr-j8x2/GHSA-f298-64xr-j8x2.json +++ b/advisories/unreviewed/2022/04/GHSA-f298-64xr-j8x2/GHSA-f298-64xr-j8x2.json @@ -7,12 +7,8 @@ "CVE-2000-1076" ], "details": "Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f2r2-4jrp-f3ph/GHSA-f2r2-4jrp-f3ph.json b/advisories/unreviewed/2022/04/GHSA-f2r2-4jrp-f3ph/GHSA-f2r2-4jrp-f3ph.json index 73976268339..98ac67c5ba3 100644 --- a/advisories/unreviewed/2022/04/GHSA-f2r2-4jrp-f3ph/GHSA-f2r2-4jrp-f3ph.json +++ b/advisories/unreviewed/2022/04/GHSA-f2r2-4jrp-f3ph/GHSA-f2r2-4jrp-f3ph.json @@ -7,12 +7,8 @@ "CVE-2000-1206" ], "details": "Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f89j-92rw-6x6x/GHSA-f89j-92rw-6x6x.json b/advisories/unreviewed/2022/04/GHSA-f89j-92rw-6x6x/GHSA-f89j-92rw-6x6x.json index 889ae8ef8b6..19486b995af 100644 --- a/advisories/unreviewed/2022/04/GHSA-f89j-92rw-6x6x/GHSA-f89j-92rw-6x6x.json +++ b/advisories/unreviewed/2022/04/GHSA-f89j-92rw-6x6x/GHSA-f89j-92rw-6x6x.json @@ -7,12 +7,8 @@ "CVE-2000-1171" ], "details": "Directory traversal vulnerability in cgiforum.pl script in CGIForum 1.0 allows remote attackers to ready arbitrary files via a .. (dot dot) attack in the \"thesection\" parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f8jq-wv2h-hqqm/GHSA-f8jq-wv2h-hqqm.json b/advisories/unreviewed/2022/04/GHSA-f8jq-wv2h-hqqm/GHSA-f8jq-wv2h-hqqm.json index 90d9b123305..38774d68258 100644 --- a/advisories/unreviewed/2022/04/GHSA-f8jq-wv2h-hqqm/GHSA-f8jq-wv2h-hqqm.json +++ b/advisories/unreviewed/2022/04/GHSA-f8jq-wv2h-hqqm/GHSA-f8jq-wv2h-hqqm.json @@ -7,12 +7,8 @@ "CVE-2001-0023" ], "details": "everythingform.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fcmp-4fvx-mvrf/GHSA-fcmp-4fvx-mvrf.json b/advisories/unreviewed/2022/04/GHSA-fcmp-4fvx-mvrf/GHSA-fcmp-4fvx-mvrf.json index dc5df06490a..ca6946c05e4 100644 --- a/advisories/unreviewed/2022/04/GHSA-fcmp-4fvx-mvrf/GHSA-fcmp-4fvx-mvrf.json +++ b/advisories/unreviewed/2022/04/GHSA-fcmp-4fvx-mvrf/GHSA-fcmp-4fvx-mvrf.json @@ -7,12 +7,8 @@ "CVE-2000-1114" ], "details": "Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as \".\", or \"+\", or \"%20\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fm67-6f3q-6pqp/GHSA-fm67-6f3q-6pqp.json b/advisories/unreviewed/2022/04/GHSA-fm67-6f3q-6pqp/GHSA-fm67-6f3q-6pqp.json index 576280b18b8..d47094c1d38 100644 --- a/advisories/unreviewed/2022/04/GHSA-fm67-6f3q-6pqp/GHSA-fm67-6f3q-6pqp.json +++ b/advisories/unreviewed/2022/04/GHSA-fm67-6f3q-6pqp/GHSA-fm67-6f3q-6pqp.json @@ -7,12 +7,8 @@ "CVE-2000-1079" ], "details": "Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fp6p-43fg-5cj5/GHSA-fp6p-43fg-5cj5.json b/advisories/unreviewed/2022/04/GHSA-fp6p-43fg-5cj5/GHSA-fp6p-43fg-5cj5.json index 17cc0b37347..a8e3b45c490 100644 --- a/advisories/unreviewed/2022/04/GHSA-fp6p-43fg-5cj5/GHSA-fp6p-43fg-5cj5.json +++ b/advisories/unreviewed/2022/04/GHSA-fp6p-43fg-5cj5/GHSA-fp6p-43fg-5cj5.json @@ -7,12 +7,8 @@ "CVE-2001-0074" ], "details": "Directory traversal vulnerability in print.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the board parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-frjf-p4xm-rf24/GHSA-frjf-p4xm-rf24.json b/advisories/unreviewed/2022/04/GHSA-frjf-p4xm-rf24/GHSA-frjf-p4xm-rf24.json index ef151e5955c..ec669cb3ee3 100644 --- a/advisories/unreviewed/2022/04/GHSA-frjf-p4xm-rf24/GHSA-frjf-p4xm-rf24.json +++ b/advisories/unreviewed/2022/04/GHSA-frjf-p4xm-rf24/GHSA-frjf-p4xm-rf24.json @@ -7,12 +7,8 @@ "CVE-2000-1144" ], "details": "Recourse ManTrap 1.6 sets up a chroot environment to hide the fact that it is running, but the inode number for the resulting \"/\" file system is higher than normal, which allows attackers to determine that they are in a chroot environment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g2qx-p2rm-qq6g/GHSA-g2qx-p2rm-qq6g.json b/advisories/unreviewed/2022/04/GHSA-g2qx-p2rm-qq6g/GHSA-g2qx-p2rm-qq6g.json index 7652f87c022..9322282a7ef 100644 --- a/advisories/unreviewed/2022/04/GHSA-g2qx-p2rm-qq6g/GHSA-g2qx-p2rm-qq6g.json +++ b/advisories/unreviewed/2022/04/GHSA-g2qx-p2rm-qq6g/GHSA-g2qx-p2rm-qq6g.json @@ -7,12 +7,8 @@ "CVE-2001-0068" ], "details": "Mac OS Runtime for Java (MRJ) 2.2.3 allows remote attackers to use malicious applets to read files outside of the CODEBASE context via the ARCHIVE applet parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g32c-xj3w-479x/GHSA-g32c-xj3w-479x.json b/advisories/unreviewed/2022/04/GHSA-g32c-xj3w-479x/GHSA-g32c-xj3w-479x.json index 60a5ceb0b59..f0f515df505 100644 --- a/advisories/unreviewed/2022/04/GHSA-g32c-xj3w-479x/GHSA-g32c-xj3w-479x.json +++ b/advisories/unreviewed/2022/04/GHSA-g32c-xj3w-479x/GHSA-g32c-xj3w-479x.json @@ -7,12 +7,8 @@ "CVE-2001-0106" ], "details": "Vulnerability in inetd server in HP-UX 11.04 and earlier allows attackers to cause a denial of service when the \"swait\" state is used by a server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g5cf-8f24-p3pm/GHSA-g5cf-8f24-p3pm.json b/advisories/unreviewed/2022/04/GHSA-g5cf-8f24-p3pm/GHSA-g5cf-8f24-p3pm.json index 775f6af0dee..259d7ab47cb 100644 --- a/advisories/unreviewed/2022/04/GHSA-g5cf-8f24-p3pm/GHSA-g5cf-8f24-p3pm.json +++ b/advisories/unreviewed/2022/04/GHSA-g5cf-8f24-p3pm/GHSA-g5cf-8f24-p3pm.json @@ -7,12 +7,8 @@ "CVE-2001-0028" ], "details": "Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute arbitrary commands via a large number of \" (quotation) characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g7v5-rc2j-fqgg/GHSA-g7v5-rc2j-fqgg.json b/advisories/unreviewed/2022/04/GHSA-g7v5-rc2j-fqgg/GHSA-g7v5-rc2j-fqgg.json index 549b75a6316..5c847d96e7f 100644 --- a/advisories/unreviewed/2022/04/GHSA-g7v5-rc2j-fqgg/GHSA-g7v5-rc2j-fqgg.json +++ b/advisories/unreviewed/2022/04/GHSA-g7v5-rc2j-fqgg/GHSA-g7v5-rc2j-fqgg.json @@ -7,12 +7,8 @@ "CVE-2001-0003" ], "details": "Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the \"Web Client NTLM Authentication\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g8rh-37p9-m2xw/GHSA-g8rh-37p9-m2xw.json b/advisories/unreviewed/2022/04/GHSA-g8rh-37p9-m2xw/GHSA-g8rh-37p9-m2xw.json index 279c0899a05..c19a7d3d41b 100644 --- a/advisories/unreviewed/2022/04/GHSA-g8rh-37p9-m2xw/GHSA-g8rh-37p9-m2xw.json +++ b/advisories/unreviewed/2022/04/GHSA-g8rh-37p9-m2xw/GHSA-g8rh-37p9-m2xw.json @@ -7,12 +7,8 @@ "CVE-2000-1126" ], "details": "Vulnerability in auto_parms and set_parms in HP-UX 11.00 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ghh8-v4ww-536g/GHSA-ghh8-v4ww-536g.json b/advisories/unreviewed/2022/04/GHSA-ghh8-v4ww-536g/GHSA-ghh8-v4ww-536g.json index d84f83e8008..8eed39d0d06 100644 --- a/advisories/unreviewed/2022/04/GHSA-ghh8-v4ww-536g/GHSA-ghh8-v4ww-536g.json +++ b/advisories/unreviewed/2022/04/GHSA-ghh8-v4ww-536g/GHSA-ghh8-v4ww-536g.json @@ -7,12 +7,8 @@ "CVE-2000-1145" ], "details": "Recourse ManTrap 1.6 allows attackers who have gained root access to use utilities such as crash or fsdb to read /dev/mem and raw disk devices to identify ManTrap processes or modify arbitrary data files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gjpv-7qjf-vj7x/GHSA-gjpv-7qjf-vj7x.json b/advisories/unreviewed/2022/04/GHSA-gjpv-7qjf-vj7x/GHSA-gjpv-7qjf-vj7x.json index d61fc79ae98..7d54a502222 100644 --- a/advisories/unreviewed/2022/04/GHSA-gjpv-7qjf-vj7x/GHSA-gjpv-7qjf-vj7x.json +++ b/advisories/unreviewed/2022/04/GHSA-gjpv-7qjf-vj7x/GHSA-gjpv-7qjf-vj7x.json @@ -7,12 +7,8 @@ "CVE-2000-1085" ], "details": "The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the \"Extended Stored Procedure Parameter Parsing\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gm53-5grf-8hm4/GHSA-gm53-5grf-8hm4.json b/advisories/unreviewed/2022/04/GHSA-gm53-5grf-8hm4/GHSA-gm53-5grf-8hm4.json index 128eab874fa..a2e76c75865 100644 --- a/advisories/unreviewed/2022/04/GHSA-gm53-5grf-8hm4/GHSA-gm53-5grf-8hm4.json +++ b/advisories/unreviewed/2022/04/GHSA-gm53-5grf-8hm4/GHSA-gm53-5grf-8hm4.json @@ -7,12 +7,8 @@ "CVE-2000-1130" ], "details": "McAfee WebShield SMTP 4.5 allows remote attackers to bypass email content filtering rules by including Extended ASCII characters in name of the attachment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gm7x-33x3-3qg9/GHSA-gm7x-33x3-3qg9.json b/advisories/unreviewed/2022/04/GHSA-gm7x-33x3-3qg9/GHSA-gm7x-33x3-3qg9.json index 737a793aae2..2c70ed6634f 100644 --- a/advisories/unreviewed/2022/04/GHSA-gm7x-33x3-3qg9/GHSA-gm7x-33x3-3qg9.json +++ b/advisories/unreviewed/2022/04/GHSA-gm7x-33x3-3qg9/GHSA-gm7x-33x3-3qg9.json @@ -7,12 +7,8 @@ "CVE-2001-0042" ], "details": "PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing \"%5c\" (encoded backslash) sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gq3c-qhph-m92g/GHSA-gq3c-qhph-m92g.json b/advisories/unreviewed/2022/04/GHSA-gq3c-qhph-m92g/GHSA-gq3c-qhph-m92g.json index 2bafa240f1b..ded3524fb43 100644 --- a/advisories/unreviewed/2022/04/GHSA-gq3c-qhph-m92g/GHSA-gq3c-qhph-m92g.json +++ b/advisories/unreviewed/2022/04/GHSA-gq3c-qhph-m92g/GHSA-gq3c-qhph-m92g.json @@ -7,12 +7,8 @@ "CVE-2001-0032" ], "details": "Format string vulnerability in ssldump possibly allows remote attackers to cause a denial of service and possibly gain root privileges via malicious format string specifiers in a URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-grp9-jgmj-h7px/GHSA-grp9-jgmj-h7px.json b/advisories/unreviewed/2022/04/GHSA-grp9-jgmj-h7px/GHSA-grp9-jgmj-h7px.json index d36a9e54457..f772f9e1c4f 100644 --- a/advisories/unreviewed/2022/04/GHSA-grp9-jgmj-h7px/GHSA-grp9-jgmj-h7px.json +++ b/advisories/unreviewed/2022/04/GHSA-grp9-jgmj-h7px/GHSA-grp9-jgmj-h7px.json @@ -7,12 +7,8 @@ "CVE-2001-0081" ], "details": "swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to application keys.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gvg8-m7rh-qfg2/GHSA-gvg8-m7rh-qfg2.json b/advisories/unreviewed/2022/04/GHSA-gvg8-m7rh-qfg2/GHSA-gvg8-m7rh-qfg2.json index 09562ebb4d4..4cdf1ac83bc 100644 --- a/advisories/unreviewed/2022/04/GHSA-gvg8-m7rh-qfg2/GHSA-gvg8-m7rh-qfg2.json +++ b/advisories/unreviewed/2022/04/GHSA-gvg8-m7rh-qfg2/GHSA-gvg8-m7rh-qfg2.json @@ -7,12 +7,8 @@ "CVE-2000-1213" ], "details": "ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping's exposure to bugs that otherwise would occur at lower privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h3hr-frhw-fwq8/GHSA-h3hr-frhw-fwq8.json b/advisories/unreviewed/2022/04/GHSA-h3hr-frhw-fwq8/GHSA-h3hr-frhw-fwq8.json index 501687aab02..cd41d54e5c1 100644 --- a/advisories/unreviewed/2022/04/GHSA-h3hr-frhw-fwq8/GHSA-h3hr-frhw-fwq8.json +++ b/advisories/unreviewed/2022/04/GHSA-h3hr-frhw-fwq8/GHSA-h3hr-frhw-fwq8.json @@ -7,12 +7,8 @@ "CVE-2000-1166" ], "details": "Twig webmail system does not properly set the \"vhosts\" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h5pq-5828-hr6x/GHSA-h5pq-5828-hr6x.json b/advisories/unreviewed/2022/04/GHSA-h5pq-5828-hr6x/GHSA-h5pq-5828-hr6x.json index de27ae08c0e..8fc2e44413a 100644 --- a/advisories/unreviewed/2022/04/GHSA-h5pq-5828-hr6x/GHSA-h5pq-5828-hr6x.json +++ b/advisories/unreviewed/2022/04/GHSA-h5pq-5828-hr6x/GHSA-h5pq-5828-hr6x.json @@ -7,12 +7,8 @@ "CVE-2000-1106" ], "details": "Trend Micro InterScan VirusWall creates an \"Intscan\" share to the \"InterScan\" directory with permissions that grant Full Control permissions to the Everyone group, which allows attackers to gain privileges by modifying the VirusWall programs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h6wp-g68c-q5j9/GHSA-h6wp-g68c-q5j9.json b/advisories/unreviewed/2022/04/GHSA-h6wp-g68c-q5j9/GHSA-h6wp-g68c-q5j9.json index 1daee798196..caa83c5d9dd 100644 --- a/advisories/unreviewed/2022/04/GHSA-h6wp-g68c-q5j9/GHSA-h6wp-g68c-q5j9.json +++ b/advisories/unreviewed/2022/04/GHSA-h6wp-g68c-q5j9/GHSA-h6wp-g68c-q5j9.json @@ -7,12 +7,8 @@ "CVE-2001-0046" ], "details": "The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the \"Registry Permissions\" vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h963-7ffv-g7jf/GHSA-h963-7ffv-g7jf.json b/advisories/unreviewed/2022/04/GHSA-h963-7ffv-g7jf/GHSA-h963-7ffv-g7jf.json index b4d3f0fb04d..9cc64ac082f 100644 --- a/advisories/unreviewed/2022/04/GHSA-h963-7ffv-g7jf/GHSA-h963-7ffv-g7jf.json +++ b/advisories/unreviewed/2022/04/GHSA-h963-7ffv-g7jf/GHSA-h963-7ffv-g7jf.json @@ -7,12 +7,8 @@ "CVE-2001-0090" ], "details": "The Print Templates feature in Internet Explorer 5.5 executes arbitrary custom print templates without prompting the user, which could allow an attacker to execute arbitrary ActiveX controls, aka the \"Browser Print Template\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h9p6-q3mf-6wj3/GHSA-h9p6-q3mf-6wj3.json b/advisories/unreviewed/2022/04/GHSA-h9p6-q3mf-6wj3/GHSA-h9p6-q3mf-6wj3.json index d929df5d1c3..5b99f2cef9c 100644 --- a/advisories/unreviewed/2022/04/GHSA-h9p6-q3mf-6wj3/GHSA-h9p6-q3mf-6wj3.json +++ b/advisories/unreviewed/2022/04/GHSA-h9p6-q3mf-6wj3/GHSA-h9p6-q3mf-6wj3.json @@ -7,12 +7,8 @@ "CVE-2000-1230" ], "details": "Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to \"boogieman\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hjp2-87wj-g7c8/GHSA-hjp2-87wj-g7c8.json b/advisories/unreviewed/2022/04/GHSA-hjp2-87wj-g7c8/GHSA-hjp2-87wj-g7c8.json index 43df33c7a62..38519f14caa 100644 --- a/advisories/unreviewed/2022/04/GHSA-hjp2-87wj-g7c8/GHSA-hjp2-87wj-g7c8.json +++ b/advisories/unreviewed/2022/04/GHSA-hjp2-87wj-g7c8/GHSA-hjp2-87wj-g7c8.json @@ -7,12 +7,8 @@ "CVE-2001-0098" ], "details": "Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a \"..\" string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hmx2-378q-q7c3/GHSA-hmx2-378q-q7c3.json b/advisories/unreviewed/2022/04/GHSA-hmx2-378q-q7c3/GHSA-hmx2-378q-q7c3.json index d47118688c2..27680a13486 100644 --- a/advisories/unreviewed/2022/04/GHSA-hmx2-378q-q7c3/GHSA-hmx2-378q-q7c3.json +++ b/advisories/unreviewed/2022/04/GHSA-hmx2-378q-q7c3/GHSA-hmx2-378q-q7c3.json @@ -7,12 +7,8 @@ "CVE-2001-0035" ], "details": "Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long authentication request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hr66-jxmg-86xm/GHSA-hr66-jxmg-86xm.json b/advisories/unreviewed/2022/04/GHSA-hr66-jxmg-86xm/GHSA-hr66-jxmg-86xm.json index bdf244c5b6c..43aa8a01873 100644 --- a/advisories/unreviewed/2022/04/GHSA-hr66-jxmg-86xm/GHSA-hr66-jxmg-86xm.json +++ b/advisories/unreviewed/2022/04/GHSA-hr66-jxmg-86xm/GHSA-hr66-jxmg-86xm.json @@ -7,12 +7,8 @@ "CVE-2001-0027" ], "details": "mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the \"user\" command to change accounts, which allows authenticated attackers to gain privileges of other users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hr76-gm2q-68qr/GHSA-hr76-gm2q-68qr.json b/advisories/unreviewed/2022/04/GHSA-hr76-gm2q-68qr/GHSA-hr76-gm2q-68qr.json index 58703d90452..3930261ec29 100644 --- a/advisories/unreviewed/2022/04/GHSA-hr76-gm2q-68qr/GHSA-hr76-gm2q-68qr.json +++ b/advisories/unreviewed/2022/04/GHSA-hr76-gm2q-68qr/GHSA-hr76-gm2q-68qr.json @@ -7,12 +7,8 @@ "CVE-2000-1107" ], "details": "in.identd ident server in SuSE Linux 6.x and 7.0 allows remote attackers to cause a denial of service via a long request, which causes the server to access a NULL pointer and crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hrjf-28rx-wf7r/GHSA-hrjf-28rx-wf7r.json b/advisories/unreviewed/2022/04/GHSA-hrjf-28rx-wf7r/GHSA-hrjf-28rx-wf7r.json index 0ceebab4a2e..aa45ca58d09 100644 --- a/advisories/unreviewed/2022/04/GHSA-hrjf-28rx-wf7r/GHSA-hrjf-28rx-wf7r.json +++ b/advisories/unreviewed/2022/04/GHSA-hrjf-28rx-wf7r/GHSA-hrjf-28rx-wf7r.json @@ -7,12 +7,8 @@ "CVE-2000-1105" ], "details": "The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hv5v-h4qh-vgxj/GHSA-hv5v-h4qh-vgxj.json b/advisories/unreviewed/2022/04/GHSA-hv5v-h4qh-vgxj/GHSA-hv5v-h4qh-vgxj.json index 94fb8d34615..ff1467949dc 100644 --- a/advisories/unreviewed/2022/04/GHSA-hv5v-h4qh-vgxj/GHSA-hv5v-h4qh-vgxj.json +++ b/advisories/unreviewed/2022/04/GHSA-hv5v-h4qh-vgxj/GHSA-hv5v-h4qh-vgxj.json @@ -7,12 +7,8 @@ "CVE-2001-0073" ], "details": "Buffer overflow in the find_default_type function in libsecure in NSA Security-enhanced Linux, which may allow attackers to modify critical data in memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hw4c-6fxr-ghqh/GHSA-hw4c-6fxr-ghqh.json b/advisories/unreviewed/2022/04/GHSA-hw4c-6fxr-ghqh/GHSA-hw4c-6fxr-ghqh.json index 27907c53a15..9835165cd38 100644 --- a/advisories/unreviewed/2022/04/GHSA-hw4c-6fxr-ghqh/GHSA-hw4c-6fxr-ghqh.json +++ b/advisories/unreviewed/2022/04/GHSA-hw4c-6fxr-ghqh/GHSA-hw4c-6fxr-ghqh.json @@ -7,12 +7,8 @@ "CVE-2000-1158" ], "details": "NAI Sniffer Agent uses base64 encoding for authentication, which allows attackers to sniff the network and easily decrypt usernames and passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hwwv-vx36-7jpp/GHSA-hwwv-vx36-7jpp.json b/advisories/unreviewed/2022/04/GHSA-hwwv-vx36-7jpp/GHSA-hwwv-vx36-7jpp.json index 7fa5da1dc48..5221c911e50 100644 --- a/advisories/unreviewed/2022/04/GHSA-hwwv-vx36-7jpp/GHSA-hwwv-vx36-7jpp.json +++ b/advisories/unreviewed/2022/04/GHSA-hwwv-vx36-7jpp/GHSA-hwwv-vx36-7jpp.json @@ -7,12 +7,8 @@ "CVE-2000-1209" ], "details": "The \"sa\" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j274-79c7-46r9/GHSA-j274-79c7-46r9.json b/advisories/unreviewed/2022/04/GHSA-j274-79c7-46r9/GHSA-j274-79c7-46r9.json index d82b409e445..9ba4b34f006 100644 --- a/advisories/unreviewed/2022/04/GHSA-j274-79c7-46r9/GHSA-j274-79c7-46r9.json +++ b/advisories/unreviewed/2022/04/GHSA-j274-79c7-46r9/GHSA-j274-79c7-46r9.json @@ -7,12 +7,8 @@ "CVE-2000-1073" ], "details": "csstart program in iCal 2.1 Patch 2 searches for the cshttpd program in the current working directory, which allows local users to gain root privileges by creating a Trojan Horse cshttpd program in a directory and calling csstart from that directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j27p-f9p3-c4mr/GHSA-j27p-f9p3-c4mr.json b/advisories/unreviewed/2022/04/GHSA-j27p-f9p3-c4mr/GHSA-j27p-f9p3-c4mr.json index a54b8828e3a..e3241632c58 100644 --- a/advisories/unreviewed/2022/04/GHSA-j27p-f9p3-c4mr/GHSA-j27p-f9p3-c4mr.json +++ b/advisories/unreviewed/2022/04/GHSA-j27p-f9p3-c4mr/GHSA-j27p-f9p3-c4mr.json @@ -7,12 +7,8 @@ "CVE-2001-0103" ], "details": "CoffeeCup Direct and Free FTP clients uses weak encryption to store passwords in the FTPServers.ini file, which could allow attackers to easily decrypt the passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j52p-47c7-4w37/GHSA-j52p-47c7-4w37.json b/advisories/unreviewed/2022/04/GHSA-j52p-47c7-4w37/GHSA-j52p-47c7-4w37.json index b185a080a93..ec565bb9cea 100644 --- a/advisories/unreviewed/2022/04/GHSA-j52p-47c7-4w37/GHSA-j52p-47c7-4w37.json +++ b/advisories/unreviewed/2022/04/GHSA-j52p-47c7-4w37/GHSA-j52p-47c7-4w37.json @@ -7,12 +7,8 @@ "CVE-2000-1224" ], "details": "Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) \"..\", (2) \"%2e..\", (3) \"%81\", (4) \"%82\", and others.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j648-847p-926p/GHSA-j648-847p-926p.json b/advisories/unreviewed/2022/04/GHSA-j648-847p-926p/GHSA-j648-847p-926p.json index e50d9dc3313..2336464068e 100644 --- a/advisories/unreviewed/2022/04/GHSA-j648-847p-926p/GHSA-j648-847p-926p.json +++ b/advisories/unreviewed/2022/04/GHSA-j648-847p-926p/GHSA-j648-847p-926p.json @@ -7,12 +7,8 @@ "CVE-2000-1183" ], "details": "Buffer overflow in socks5 server on Linux allows attackers to execute arbitrary commands via a long connection request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j64q-4qc2-c9v8/GHSA-j64q-4qc2-c9v8.json b/advisories/unreviewed/2022/04/GHSA-j64q-4qc2-c9v8/GHSA-j64q-4qc2-c9v8.json index 25a2f7a394a..a49ec93c643 100644 --- a/advisories/unreviewed/2022/04/GHSA-j64q-4qc2-c9v8/GHSA-j64q-4qc2-c9v8.json +++ b/advisories/unreviewed/2022/04/GHSA-j64q-4qc2-c9v8/GHSA-j64q-4qc2-c9v8.json @@ -7,12 +7,8 @@ "CVE-2001-0099" ], "details": "bsguest.cgi guestbook script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jg7j-cqjc-6cc3/GHSA-jg7j-cqjc-6cc3.json b/advisories/unreviewed/2022/04/GHSA-jg7j-cqjc-6cc3/GHSA-jg7j-cqjc-6cc3.json index 0ad08ff75ff..348be49e7e3 100644 --- a/advisories/unreviewed/2022/04/GHSA-jg7j-cqjc-6cc3/GHSA-jg7j-cqjc-6cc3.json +++ b/advisories/unreviewed/2022/04/GHSA-jg7j-cqjc-6cc3/GHSA-jg7j-cqjc-6cc3.json @@ -7,12 +7,8 @@ "CVE-2000-1084" ], "details": "The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the \"Extended Stored Procedure Parameter Parsing\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jh35-33g7-ghxr/GHSA-jh35-33g7-ghxr.json b/advisories/unreviewed/2022/04/GHSA-jh35-33g7-ghxr/GHSA-jh35-33g7-ghxr.json index f765c4f501f..3ae8bb44dd5 100644 --- a/advisories/unreviewed/2022/04/GHSA-jh35-33g7-ghxr/GHSA-jh35-33g7-ghxr.json +++ b/advisories/unreviewed/2022/04/GHSA-jh35-33g7-ghxr/GHSA-jh35-33g7-ghxr.json @@ -7,12 +7,8 @@ "CVE-2000-1169" ], "details": "OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH server to gain access to the X11 display and sniff X11 events, or gain access to the ssh-agent.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jh79-c7cc-fx5h/GHSA-jh79-c7cc-fx5h.json b/advisories/unreviewed/2022/04/GHSA-jh79-c7cc-fx5h/GHSA-jh79-c7cc-fx5h.json index 04885c8b9d4..8e984030a40 100644 --- a/advisories/unreviewed/2022/04/GHSA-jh79-c7cc-fx5h/GHSA-jh79-c7cc-fx5h.json +++ b/advisories/unreviewed/2022/04/GHSA-jh79-c7cc-fx5h/GHSA-jh79-c7cc-fx5h.json @@ -7,12 +7,8 @@ "CVE-2000-1140" ], "details": "Recourse ManTrap 1.6 does not properly hide processes from attackers, which could allow attackers to determine that they are in a honeypot system by comparing the results from kill commands with the process listing in the /proc filesystem.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jp9p-3qm5-vq8x/GHSA-jp9p-3qm5-vq8x.json b/advisories/unreviewed/2022/04/GHSA-jp9p-3qm5-vq8x/GHSA-jp9p-3qm5-vq8x.json index 1018e541a27..1feac3c7b4f 100644 --- a/advisories/unreviewed/2022/04/GHSA-jp9p-3qm5-vq8x/GHSA-jp9p-3qm5-vq8x.json +++ b/advisories/unreviewed/2022/04/GHSA-jp9p-3qm5-vq8x/GHSA-jp9p-3qm5-vq8x.json @@ -7,12 +7,8 @@ "CVE-2000-1203" ], "details": "Lotus Domino SMTP server 4.63 through 5.08 allows remote attackers to cause a denial of service (CPU consumption) by forging an email message with the sender as bounce@[127.0.0.1] (localhost), which causes Domino to enter a mail loop.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jpwg-qx54-r8vg/GHSA-jpwg-qx54-r8vg.json b/advisories/unreviewed/2022/04/GHSA-jpwg-qx54-r8vg/GHSA-jpwg-qx54-r8vg.json index d66cb9b4c5e..205f995953f 100644 --- a/advisories/unreviewed/2022/04/GHSA-jpwg-qx54-r8vg/GHSA-jpwg-qx54-r8vg.json +++ b/advisories/unreviewed/2022/04/GHSA-jpwg-qx54-r8vg/GHSA-jpwg-qx54-r8vg.json @@ -7,12 +7,8 @@ "CVE-2000-1214" ], "details": "Buffer overflows in the (1) outpack or (2) buf variables of ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, may allow local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jrxr-vw4j-prv8/GHSA-jrxr-vw4j-prv8.json b/advisories/unreviewed/2022/04/GHSA-jrxr-vw4j-prv8/GHSA-jrxr-vw4j-prv8.json index 51436392da8..e711def381a 100644 --- a/advisories/unreviewed/2022/04/GHSA-jrxr-vw4j-prv8/GHSA-jrxr-vw4j-prv8.json +++ b/advisories/unreviewed/2022/04/GHSA-jrxr-vw4j-prv8/GHSA-jrxr-vw4j-prv8.json @@ -7,12 +7,8 @@ "CVE-2000-1236" ], "details": "SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jx42-h6pp-7678/GHSA-jx42-h6pp-7678.json b/advisories/unreviewed/2022/04/GHSA-jx42-h6pp-7678/GHSA-jx42-h6pp-7678.json index d47e7f9a6e5..16a30d45377 100644 --- a/advisories/unreviewed/2022/04/GHSA-jx42-h6pp-7678/GHSA-jx42-h6pp-7678.json +++ b/advisories/unreviewed/2022/04/GHSA-jx42-h6pp-7678/GHSA-jx42-h6pp-7678.json @@ -7,12 +7,8 @@ "CVE-2000-1185" ], "details": "The telnet proxy in RideWay PN proxy server allows remote attackers to cause a denial of service via a flood of connections that contain malformed requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jxr7-cc77-4ch7/GHSA-jxr7-cc77-4ch7.json b/advisories/unreviewed/2022/04/GHSA-jxr7-cc77-4ch7/GHSA-jxr7-cc77-4ch7.json index 3ca29da0fc8..3b56e891cb2 100644 --- a/advisories/unreviewed/2022/04/GHSA-jxr7-cc77-4ch7/GHSA-jxr7-cc77-4ch7.json +++ b/advisories/unreviewed/2022/04/GHSA-jxr7-cc77-4ch7/GHSA-jxr7-cc77-4ch7.json @@ -7,12 +7,8 @@ "CVE-2000-1119" ], "details": "Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long \"x=\" argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m5p8-8qj2-v775/GHSA-m5p8-8qj2-v775.json b/advisories/unreviewed/2022/04/GHSA-m5p8-8qj2-v775/GHSA-m5p8-8qj2-v775.json index ab8101ccf16..1dee306ddf8 100644 --- a/advisories/unreviewed/2022/04/GHSA-m5p8-8qj2-v775/GHSA-m5p8-8qj2-v775.json +++ b/advisories/unreviewed/2022/04/GHSA-m5p8-8qj2-v775/GHSA-m5p8-8qj2-v775.json @@ -7,12 +7,8 @@ "CVE-2000-1168" ], "details": "IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m8gw-x5jx-r3vm/GHSA-m8gw-x5jx-r3vm.json b/advisories/unreviewed/2022/04/GHSA-m8gw-x5jx-r3vm/GHSA-m8gw-x5jx-r3vm.json index 243c708df82..3863cdf8fcc 100644 --- a/advisories/unreviewed/2022/04/GHSA-m8gw-x5jx-r3vm/GHSA-m8gw-x5jx-r3vm.json +++ b/advisories/unreviewed/2022/04/GHSA-m8gw-x5jx-r3vm/GHSA-m8gw-x5jx-r3vm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m9g9-rq7f-5c46/GHSA-m9g9-rq7f-5c46.json b/advisories/unreviewed/2022/04/GHSA-m9g9-rq7f-5c46/GHSA-m9g9-rq7f-5c46.json index 8c335ce3ec2..69e2caa4778 100644 --- a/advisories/unreviewed/2022/04/GHSA-m9g9-rq7f-5c46/GHSA-m9g9-rq7f-5c46.json +++ b/advisories/unreviewed/2022/04/GHSA-m9g9-rq7f-5c46/GHSA-m9g9-rq7f-5c46.json @@ -7,12 +7,8 @@ "CVE-2000-1201" ], "details": "Check Point FireWall-1 allows remote attackers to cause a denial of service (high CPU) via a flood of packets to port 264.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mc6r-254j-5wx6/GHSA-mc6r-254j-5wx6.json b/advisories/unreviewed/2022/04/GHSA-mc6r-254j-5wx6/GHSA-mc6r-254j-5wx6.json index 615612415d0..a1fe47f3d31 100644 --- a/advisories/unreviewed/2022/04/GHSA-mc6r-254j-5wx6/GHSA-mc6r-254j-5wx6.json +++ b/advisories/unreviewed/2022/04/GHSA-mc6r-254j-5wx6/GHSA-mc6r-254j-5wx6.json @@ -7,12 +7,8 @@ "CVE-2001-0008" ], "details": "Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mf6v-4fxg-pwvj/GHSA-mf6v-4fxg-pwvj.json b/advisories/unreviewed/2022/04/GHSA-mf6v-4fxg-pwvj/GHSA-mf6v-4fxg-pwvj.json index 35a5a1c16b5..4af667c317d 100644 --- a/advisories/unreviewed/2022/04/GHSA-mf6v-4fxg-pwvj/GHSA-mf6v-4fxg-pwvj.json +++ b/advisories/unreviewed/2022/04/GHSA-mf6v-4fxg-pwvj/GHSA-mf6v-4fxg-pwvj.json @@ -7,12 +7,8 @@ "CVE-2000-1086" ], "details": "The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the \"Extended Stored Procedure Parameter Parsing\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mf97-3g2c-rccp/GHSA-mf97-3g2c-rccp.json b/advisories/unreviewed/2022/04/GHSA-mf97-3g2c-rccp/GHSA-mf97-3g2c-rccp.json index 564456b11eb..0e3a6d76903 100644 --- a/advisories/unreviewed/2022/04/GHSA-mf97-3g2c-rccp/GHSA-mf97-3g2c-rccp.json +++ b/advisories/unreviewed/2022/04/GHSA-mf97-3g2c-rccp/GHSA-mf97-3g2c-rccp.json @@ -7,12 +7,8 @@ "CVE-2000-1186" ], "details": "Buffer overflow in phf CGI program allows remote attackers to execute arbitrary commands by specifying a large number of arguments and including a long MIME header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mgx3-qmmm-64fp/GHSA-mgx3-qmmm-64fp.json b/advisories/unreviewed/2022/04/GHSA-mgx3-qmmm-64fp/GHSA-mgx3-qmmm-64fp.json index cd6ed17bef7..4ba72ae7b78 100644 --- a/advisories/unreviewed/2022/04/GHSA-mgx3-qmmm-64fp/GHSA-mgx3-qmmm-64fp.json +++ b/advisories/unreviewed/2022/04/GHSA-mgx3-qmmm-64fp/GHSA-mgx3-qmmm-64fp.json @@ -7,12 +7,8 @@ "CVE-2001-0047" ], "details": "The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the \"Registry Permissions\" vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mjqq-wq8f-g4cx/GHSA-mjqq-wq8f-g4cx.json b/advisories/unreviewed/2022/04/GHSA-mjqq-wq8f-g4cx/GHSA-mjqq-wq8f-g4cx.json index b1a1e895030..45c6589e169 100644 --- a/advisories/unreviewed/2022/04/GHSA-mjqq-wq8f-g4cx/GHSA-mjqq-wq8f-g4cx.json +++ b/advisories/unreviewed/2022/04/GHSA-mjqq-wq8f-g4cx/GHSA-mjqq-wq8f-g4cx.json @@ -7,12 +7,8 @@ "CVE-2000-1090" ], "details": "Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mq8w-3qcq-f5hf/GHSA-mq8w-3qcq-f5hf.json b/advisories/unreviewed/2022/04/GHSA-mq8w-3qcq-f5hf/GHSA-mq8w-3qcq-f5hf.json index 811aa2e7814..a377ad2749b 100644 --- a/advisories/unreviewed/2022/04/GHSA-mq8w-3qcq-f5hf/GHSA-mq8w-3qcq-f5hf.json +++ b/advisories/unreviewed/2022/04/GHSA-mq8w-3qcq-f5hf/GHSA-mq8w-3qcq-f5hf.json @@ -7,12 +7,8 @@ "CVE-2001-0034" ], "details": "KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false proxy responses and possibly gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mr3v-pmm4-26v3/GHSA-mr3v-pmm4-26v3.json b/advisories/unreviewed/2022/04/GHSA-mr3v-pmm4-26v3/GHSA-mr3v-pmm4-26v3.json index d225483e42b..afc8eaa4b73 100644 --- a/advisories/unreviewed/2022/04/GHSA-mr3v-pmm4-26v3/GHSA-mr3v-pmm4-26v3.json +++ b/advisories/unreviewed/2022/04/GHSA-mr3v-pmm4-26v3/GHSA-mr3v-pmm4-26v3.json @@ -7,12 +7,8 @@ "CVE-2001-0004" ], "details": "IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending \"%3F+.htr\" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the \"File Fragment Reading via .HTR\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mw37-2wq7-83rg/GHSA-mw37-2wq7-83rg.json b/advisories/unreviewed/2022/04/GHSA-mw37-2wq7-83rg/GHSA-mw37-2wq7-83rg.json index 2c27bdebf55..e43b56439f6 100644 --- a/advisories/unreviewed/2022/04/GHSA-mw37-2wq7-83rg/GHSA-mw37-2wq7-83rg.json +++ b/advisories/unreviewed/2022/04/GHSA-mw37-2wq7-83rg/GHSA-mw37-2wq7-83rg.json @@ -7,12 +7,8 @@ "CVE-2001-0012" ], "details": "BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mxff-qcf2-5cjv/GHSA-mxff-qcf2-5cjv.json b/advisories/unreviewed/2022/04/GHSA-mxff-qcf2-5cjv/GHSA-mxff-qcf2-5cjv.json index a4714f47435..ec904363d74 100644 --- a/advisories/unreviewed/2022/04/GHSA-mxff-qcf2-5cjv/GHSA-mxff-qcf2-5cjv.json +++ b/advisories/unreviewed/2022/04/GHSA-mxff-qcf2-5cjv/GHSA-mxff-qcf2-5cjv.json @@ -7,12 +7,8 @@ "CVE-2000-1110" ], "details": "document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p3mv-5j8q-vc32/GHSA-p3mv-5j8q-vc32.json b/advisories/unreviewed/2022/04/GHSA-p3mv-5j8q-vc32/GHSA-p3mv-5j8q-vc32.json index 091d999232c..aad9ad117ec 100644 --- a/advisories/unreviewed/2022/04/GHSA-p3mv-5j8q-vc32/GHSA-p3mv-5j8q-vc32.json +++ b/advisories/unreviewed/2022/04/GHSA-p3mv-5j8q-vc32/GHSA-p3mv-5j8q-vc32.json @@ -7,12 +7,8 @@ "CVE-2000-1072" ], "details": "iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p5x3-8ffv-76qr/GHSA-p5x3-8ffv-76qr.json b/advisories/unreviewed/2022/04/GHSA-p5x3-8ffv-76qr/GHSA-p5x3-8ffv-76qr.json index 78f39dc98df..f9c7bf02d91 100644 --- a/advisories/unreviewed/2022/04/GHSA-p5x3-8ffv-76qr/GHSA-p5x3-8ffv-76qr.json +++ b/advisories/unreviewed/2022/04/GHSA-p5x3-8ffv-76qr/GHSA-p5x3-8ffv-76qr.json @@ -7,12 +7,8 @@ "CVE-2000-1115" ], "details": "Buffer overflow in remote web administration component (webprox.dll) of 602Pro LAN SUITE before 2000.0.1.33 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p6j4-78m6-mrmc/GHSA-p6j4-78m6-mrmc.json b/advisories/unreviewed/2022/04/GHSA-p6j4-78m6-mrmc/GHSA-p6j4-78m6-mrmc.json index 37ddd7022b9..c3972c6872d 100644 --- a/advisories/unreviewed/2022/04/GHSA-p6j4-78m6-mrmc/GHSA-p6j4-78m6-mrmc.json +++ b/advisories/unreviewed/2022/04/GHSA-p6j4-78m6-mrmc/GHSA-p6j4-78m6-mrmc.json @@ -7,12 +7,8 @@ "CVE-2000-1147" ], "details": "Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to the \"LANGUAGE\" argument in a script tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p6wx-mvrf-wjw5/GHSA-p6wx-mvrf-wjw5.json b/advisories/unreviewed/2022/04/GHSA-p6wx-mvrf-wjw5/GHSA-p6wx-mvrf-wjw5.json index 8a2f18d1942..d5a9ddc1339 100644 --- a/advisories/unreviewed/2022/04/GHSA-p6wx-mvrf-wjw5/GHSA-p6wx-mvrf-wjw5.json +++ b/advisories/unreviewed/2022/04/GHSA-p6wx-mvrf-wjw5/GHSA-p6wx-mvrf-wjw5.json @@ -7,12 +7,8 @@ "CVE-2001-0079" ], "details": "Support Tools Manager (STM) A.22.00 for HP-UX allows local users to overwrite arbitrary files via a symlink attack on the tool_stat.txt log file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p7qh-m3xx-q4cm/GHSA-p7qh-m3xx-q4cm.json b/advisories/unreviewed/2022/04/GHSA-p7qh-m3xx-q4cm/GHSA-p7qh-m3xx-q4cm.json index 16165336a59..1a59f3532cb 100644 --- a/advisories/unreviewed/2022/04/GHSA-p7qh-m3xx-q4cm/GHSA-p7qh-m3xx-q4cm.json +++ b/advisories/unreviewed/2022/04/GHSA-p7qh-m3xx-q4cm/GHSA-p7qh-m3xx-q4cm.json @@ -7,12 +7,8 @@ "CVE-2000-1232" ], "details": "upgrade.php3 in Phorum 3.0.7 could allow remote attackers to modify certain Phorum database tables via an unknown method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pcqx-qgqf-w5jw/GHSA-pcqx-qgqf-w5jw.json b/advisories/unreviewed/2022/04/GHSA-pcqx-qgqf-w5jw/GHSA-pcqx-qgqf-w5jw.json index 3f45daa65fc..2fa9f985aab 100644 --- a/advisories/unreviewed/2022/04/GHSA-pcqx-qgqf-w5jw/GHSA-pcqx-qgqf-w5jw.json +++ b/advisories/unreviewed/2022/04/GHSA-pcqx-qgqf-w5jw/GHSA-pcqx-qgqf-w5jw.json @@ -7,12 +7,8 @@ "CVE-2000-1200" ], "details": "Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-php9-hw4x-p9pj/GHSA-php9-hw4x-p9pj.json b/advisories/unreviewed/2022/04/GHSA-php9-hw4x-p9pj/GHSA-php9-hw4x-p9pj.json index 4d4547a5e18..865bd91e991 100644 --- a/advisories/unreviewed/2022/04/GHSA-php9-hw4x-p9pj/GHSA-php9-hw4x-p9pj.json +++ b/advisories/unreviewed/2022/04/GHSA-php9-hw4x-p9pj/GHSA-php9-hw4x-p9pj.json @@ -7,12 +7,8 @@ "CVE-2000-1243" ], "details": "Privacy leak in Dansie Shopping Cart 3.04, and probably earlier versions, sends sensitive information such as user credentials to an e-mail address controlled by the product developers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pj32-r99j-9hr4/GHSA-pj32-r99j-9hr4.json b/advisories/unreviewed/2022/04/GHSA-pj32-r99j-9hr4/GHSA-pj32-r99j-9hr4.json index a19c2717a2a..b647ede0d3c 100644 --- a/advisories/unreviewed/2022/04/GHSA-pj32-r99j-9hr4/GHSA-pj32-r99j-9hr4.json +++ b/advisories/unreviewed/2022/04/GHSA-pj32-r99j-9hr4/GHSA-pj32-r99j-9hr4.json @@ -7,12 +7,8 @@ "CVE-2000-1089" ], "details": "Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the \"Phone Book Service Buffer Overflow\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pm4p-pvm5-c7wq/GHSA-pm4p-pvm5-c7wq.json b/advisories/unreviewed/2022/04/GHSA-pm4p-pvm5-c7wq/GHSA-pm4p-pvm5-c7wq.json index 8a3ab77edc6..c5f3e66ae04 100644 --- a/advisories/unreviewed/2022/04/GHSA-pm4p-pvm5-c7wq/GHSA-pm4p-pvm5-c7wq.json +++ b/advisories/unreviewed/2022/04/GHSA-pm4p-pvm5-c7wq/GHSA-pm4p-pvm5-c7wq.json @@ -7,12 +7,8 @@ "CVE-2000-1154" ], "details": "RHConsole in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pp2v-6wrc-g8x5/GHSA-pp2v-6wrc-g8x5.json b/advisories/unreviewed/2022/04/GHSA-pp2v-6wrc-g8x5/GHSA-pp2v-6wrc-g8x5.json index 03fd380a51c..e0bc22ffb4e 100644 --- a/advisories/unreviewed/2022/04/GHSA-pp2v-6wrc-g8x5/GHSA-pp2v-6wrc-g8x5.json +++ b/advisories/unreviewed/2022/04/GHSA-pp2v-6wrc-g8x5/GHSA-pp2v-6wrc-g8x5.json @@ -7,12 +7,8 @@ "CVE-2001-0095" ], "details": "catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pwgx-pv8v-3hcp/GHSA-pwgx-pv8v-3hcp.json b/advisories/unreviewed/2022/04/GHSA-pwgx-pv8v-3hcp/GHSA-pwgx-pv8v-3hcp.json index e28b672e3f8..fc7f17edbe8 100644 --- a/advisories/unreviewed/2022/04/GHSA-pwgx-pv8v-3hcp/GHSA-pwgx-pv8v-3hcp.json +++ b/advisories/unreviewed/2022/04/GHSA-pwgx-pv8v-3hcp/GHSA-pwgx-pv8v-3hcp.json @@ -7,12 +7,8 @@ "CVE-2000-1190" ], "details": "imwheel-solo in imwheel package allows local users to modify arbitrary files via a symlink attack from the .imwheelrc file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pxq6-g7mh-m75f/GHSA-pxq6-g7mh-m75f.json b/advisories/unreviewed/2022/04/GHSA-pxq6-g7mh-m75f/GHSA-pxq6-g7mh-m75f.json index 5bdfe0f7909..980c604e8dc 100644 --- a/advisories/unreviewed/2022/04/GHSA-pxq6-g7mh-m75f/GHSA-pxq6-g7mh-m75f.json +++ b/advisories/unreviewed/2022/04/GHSA-pxq6-g7mh-m75f/GHSA-pxq6-g7mh-m75f.json @@ -7,12 +7,8 @@ "CVE-2000-1196" ], "details": "PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pxxx-m8pv-jcgw/GHSA-pxxx-m8pv-jcgw.json b/advisories/unreviewed/2022/04/GHSA-pxxx-m8pv-jcgw/GHSA-pxxx-m8pv-jcgw.json index d6462014b96..21d6a7da143 100644 --- a/advisories/unreviewed/2022/04/GHSA-pxxx-m8pv-jcgw/GHSA-pxxx-m8pv-jcgw.json +++ b/advisories/unreviewed/2022/04/GHSA-pxxx-m8pv-jcgw/GHSA-pxxx-m8pv-jcgw.json @@ -7,12 +7,8 @@ "CVE-2000-1170" ], "details": "Buffer overflow in Netsnap webcam HTTP server before 1.2.9 allows remote attackers to execute arbitrary commands via a long GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q36p-w7jg-6243/GHSA-q36p-w7jg-6243.json b/advisories/unreviewed/2022/04/GHSA-q36p-w7jg-6243/GHSA-q36p-w7jg-6243.json index 725c3e0fd6b..afb226df9aa 100644 --- a/advisories/unreviewed/2022/04/GHSA-q36p-w7jg-6243/GHSA-q36p-w7jg-6243.json +++ b/advisories/unreviewed/2022/04/GHSA-q36p-w7jg-6243/GHSA-q36p-w7jg-6243.json @@ -7,12 +7,8 @@ "CVE-2001-0009" ], "details": "Directory traversal vulnerability in Lotus Domino 5.0.5 web server allows remote attackers to read arbitrary files via a .. attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q524-j64j-vqhj/GHSA-q524-j64j-vqhj.json b/advisories/unreviewed/2022/04/GHSA-q524-j64j-vqhj/GHSA-q524-j64j-vqhj.json index 6002cb3ab13..d27715004d8 100644 --- a/advisories/unreviewed/2022/04/GHSA-q524-j64j-vqhj/GHSA-q524-j64j-vqhj.json +++ b/advisories/unreviewed/2022/04/GHSA-q524-j64j-vqhj/GHSA-q524-j64j-vqhj.json @@ -7,12 +7,8 @@ "CVE-2000-1244" ], "details": "Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP header is missing the \"From\" field, which allows remote attackers to bypass virus protection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q526-52p8-p826/GHSA-q526-52p8-p826.json b/advisories/unreviewed/2022/04/GHSA-q526-52p8-p826/GHSA-q526-52p8-p826.json index 4eca3667d86..d10a8ae4022 100644 --- a/advisories/unreviewed/2022/04/GHSA-q526-52p8-p826/GHSA-q526-52p8-p826.json +++ b/advisories/unreviewed/2022/04/GHSA-q526-52p8-p826/GHSA-q526-52p8-p826.json @@ -7,12 +7,8 @@ "CVE-2000-1099" ], "details": "Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call into a disallowed class, which could allow an attacker to escape the Java sandbox and conduct unauthorized activities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q842-grxw-g4xw/GHSA-q842-grxw-g4xw.json b/advisories/unreviewed/2022/04/GHSA-q842-grxw-g4xw/GHSA-q842-grxw-g4xw.json index 71162b96b8c..2358546e159 100644 --- a/advisories/unreviewed/2022/04/GHSA-q842-grxw-g4xw/GHSA-q842-grxw-g4xw.json +++ b/advisories/unreviewed/2022/04/GHSA-q842-grxw-g4xw/GHSA-q842-grxw-g4xw.json @@ -7,12 +7,8 @@ "CVE-2000-1113" ], "details": "Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed Active Stream Redirector (.ASX) file, aka the \".ASX Buffer Overrun\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q8hm-qxv3-j9xx/GHSA-q8hm-qxv3-j9xx.json b/advisories/unreviewed/2022/04/GHSA-q8hm-qxv3-j9xx/GHSA-q8hm-qxv3-j9xx.json index 6880dbb8ff1..8f0fe3d382a 100644 --- a/advisories/unreviewed/2022/04/GHSA-q8hm-qxv3-j9xx/GHSA-q8hm-qxv3-j9xx.json +++ b/advisories/unreviewed/2022/04/GHSA-q8hm-qxv3-j9xx/GHSA-q8hm-qxv3-j9xx.json @@ -7,12 +7,8 @@ "CVE-2000-1080" ], "details": "Quake 1 (quake1) and ProQuake 1.01 and earlier allow remote attackers to cause a denial of service via a malformed (empty) UDP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q997-qgp7-2qxm/GHSA-q997-qgp7-2qxm.json b/advisories/unreviewed/2022/04/GHSA-q997-qgp7-2qxm/GHSA-q997-qgp7-2qxm.json index 31af05cb469..eb8d944042c 100644 --- a/advisories/unreviewed/2022/04/GHSA-q997-qgp7-2qxm/GHSA-q997-qgp7-2qxm.json +++ b/advisories/unreviewed/2022/04/GHSA-q997-qgp7-2qxm/GHSA-q997-qgp7-2qxm.json @@ -7,12 +7,8 @@ "CVE-2001-0077" ], "details": "The clustmon service in Sun Cluster 2.x does not require authentication, which allows remote attackers to obtain sensitive information such as system logs and cluster configurations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qg65-w45w-rw2w/GHSA-qg65-w45w-rw2w.json b/advisories/unreviewed/2022/04/GHSA-qg65-w45w-rw2w/GHSA-qg65-w45w-rw2w.json index 9a6efaa195a..47eb0984749 100644 --- a/advisories/unreviewed/2022/04/GHSA-qg65-w45w-rw2w/GHSA-qg65-w45w-rw2w.json +++ b/advisories/unreviewed/2022/04/GHSA-qg65-w45w-rw2w/GHSA-qg65-w45w-rw2w.json @@ -7,12 +7,8 @@ "CVE-2000-1122" ], "details": "Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qm34-w9p4-fxqv/GHSA-qm34-w9p4-fxqv.json b/advisories/unreviewed/2022/04/GHSA-qm34-w9p4-fxqv/GHSA-qm34-w9p4-fxqv.json index d48e88233dc..1915002f19e 100644 --- a/advisories/unreviewed/2022/04/GHSA-qm34-w9p4-fxqv/GHSA-qm34-w9p4-fxqv.json +++ b/advisories/unreviewed/2022/04/GHSA-qm34-w9p4-fxqv/GHSA-qm34-w9p4-fxqv.json @@ -7,12 +7,8 @@ "CVE-2001-0007" ], "details": "Buffer overflow in NetScreen Firewall WebUI allows remote attackers to cause a denial of service via a long URL request to the web administration interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qp9g-233f-wxgh/GHSA-qp9g-233f-wxgh.json b/advisories/unreviewed/2022/04/GHSA-qp9g-233f-wxgh/GHSA-qp9g-233f-wxgh.json index ef286b086de..ed9ac1dd5a8 100644 --- a/advisories/unreviewed/2022/04/GHSA-qp9g-233f-wxgh/GHSA-qp9g-233f-wxgh.json +++ b/advisories/unreviewed/2022/04/GHSA-qp9g-233f-wxgh/GHSA-qp9g-233f-wxgh.json @@ -7,12 +7,8 @@ "CVE-2001-0040" ], "details": "APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying the target process ID in the apcupsd.pid file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qpw8-2v6f-pwj8/GHSA-qpw8-2v6f-pwj8.json b/advisories/unreviewed/2022/04/GHSA-qpw8-2v6f-pwj8/GHSA-qpw8-2v6f-pwj8.json index 2977cf2eb71..957eaadf548 100644 --- a/advisories/unreviewed/2022/04/GHSA-qpw8-2v6f-pwj8/GHSA-qpw8-2v6f-pwj8.json +++ b/advisories/unreviewed/2022/04/GHSA-qpw8-2v6f-pwj8/GHSA-qpw8-2v6f-pwj8.json @@ -7,12 +7,8 @@ "CVE-2000-1137" ], "details": "GNU ed before 0.2-18.1 allows local users to overwrite the files of other users via a symlink attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qv5j-rh3g-jc8x/GHSA-qv5j-rh3g-jc8x.json b/advisories/unreviewed/2022/04/GHSA-qv5j-rh3g-jc8x/GHSA-qv5j-rh3g-jc8x.json index 72f69e9e4f3..92b4197725e 100644 --- a/advisories/unreviewed/2022/04/GHSA-qv5j-rh3g-jc8x/GHSA-qv5j-rh3g-jc8x.json +++ b/advisories/unreviewed/2022/04/GHSA-qv5j-rh3g-jc8x/GHSA-qv5j-rh3g-jc8x.json @@ -7,12 +7,8 @@ "CVE-2000-1205" ], "details": "Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code. NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache. The printenv.pl/acuparam vector, discloser on 20070724, is one such variant.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-qw2v-5pqg-mc3r/GHSA-qw2v-5pqg-mc3r.json b/advisories/unreviewed/2022/04/GHSA-qw2v-5pqg-mc3r/GHSA-qw2v-5pqg-mc3r.json index b66e868020c..e3ff9b1c7d5 100644 --- a/advisories/unreviewed/2022/04/GHSA-qw2v-5pqg-mc3r/GHSA-qw2v-5pqg-mc3r.json +++ b/advisories/unreviewed/2022/04/GHSA-qw2v-5pqg-mc3r/GHSA-qw2v-5pqg-mc3r.json @@ -7,12 +7,8 @@ "CVE-2000-1161" ], "details": "The installation of AdCycle banner management system leaves the build.cgi program in a web-accessible directory, which allows remote attackers to execute the program and view passwords or delete databases.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qxm8-736w-j46q/GHSA-qxm8-736w-j46q.json b/advisories/unreviewed/2022/04/GHSA-qxm8-736w-j46q/GHSA-qxm8-736w-j46q.json index 67b48af7213..ce231e36eae 100644 --- a/advisories/unreviewed/2022/04/GHSA-qxm8-736w-j46q/GHSA-qxm8-736w-j46q.json +++ b/advisories/unreviewed/2022/04/GHSA-qxm8-736w-j46q/GHSA-qxm8-736w-j46q.json @@ -7,12 +7,8 @@ "CVE-2000-1136" ], "details": "elvis-tiny before 1.4-10 in Debian GNU/Linux, and possibly other Linux operating systems, allows local users to overwrite files of other users via a symlink attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r2gx-qfm9-9rrq/GHSA-r2gx-qfm9-9rrq.json b/advisories/unreviewed/2022/04/GHSA-r2gx-qfm9-9rrq/GHSA-r2gx-qfm9-9rrq.json index 1b03ec15fb8..da02d72947f 100644 --- a/advisories/unreviewed/2022/04/GHSA-r2gx-qfm9-9rrq/GHSA-r2gx-qfm9-9rrq.json +++ b/advisories/unreviewed/2022/04/GHSA-r2gx-qfm9-9rrq/GHSA-r2gx-qfm9-9rrq.json @@ -7,12 +7,8 @@ "CVE-2000-1150" ], "details": "Felix IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r4pg-4fjh-q6c6/GHSA-r4pg-4fjh-q6c6.json b/advisories/unreviewed/2022/04/GHSA-r4pg-4fjh-q6c6/GHSA-r4pg-4fjh-q6c6.json index a8ecde7910f..37d35d3bdda 100644 --- a/advisories/unreviewed/2022/04/GHSA-r4pg-4fjh-q6c6/GHSA-r4pg-4fjh-q6c6.json +++ b/advisories/unreviewed/2022/04/GHSA-r4pg-4fjh-q6c6/GHSA-r4pg-4fjh-q6c6.json @@ -7,12 +7,8 @@ "CVE-2000-1074" ], "details": "csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to gain root privileges by creating a Trojan Horse library in the current or parent directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r56m-86mv-452f/GHSA-r56m-86mv-452f.json b/advisories/unreviewed/2022/04/GHSA-r56m-86mv-452f/GHSA-r56m-86mv-452f.json index 0917df4ad42..9760ad6cf48 100644 --- a/advisories/unreviewed/2022/04/GHSA-r56m-86mv-452f/GHSA-r56m-86mv-452f.json +++ b/advisories/unreviewed/2022/04/GHSA-r56m-86mv-452f/GHSA-r56m-86mv-452f.json @@ -7,12 +7,8 @@ "CVE-2000-1100" ], "details": "The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r69c-wm2r-fvc6/GHSA-r69c-wm2r-fvc6.json b/advisories/unreviewed/2022/04/GHSA-r69c-wm2r-fvc6/GHSA-r69c-wm2r-fvc6.json index 3a3c8810f95..8388e741610 100644 --- a/advisories/unreviewed/2022/04/GHSA-r69c-wm2r-fvc6/GHSA-r69c-wm2r-fvc6.json +++ b/advisories/unreviewed/2022/04/GHSA-r69c-wm2r-fvc6/GHSA-r69c-wm2r-fvc6.json @@ -7,12 +7,8 @@ "CVE-2001-0092" ], "details": "A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the \"Frame Domain Verification\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r6hg-vfqv-94j7/GHSA-r6hg-vfqv-94j7.json b/advisories/unreviewed/2022/04/GHSA-r6hg-vfqv-94j7/GHSA-r6hg-vfqv-94j7.json index 427ad8b3cb1..d010ddecb78 100644 --- a/advisories/unreviewed/2022/04/GHSA-r6hg-vfqv-94j7/GHSA-r6hg-vfqv-94j7.json +++ b/advisories/unreviewed/2022/04/GHSA-r6hg-vfqv-94j7/GHSA-r6hg-vfqv-94j7.json @@ -7,12 +7,8 @@ "CVE-2000-1127" ], "details": "registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the permissions to be world readable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r7jj-pm2f-3h96/GHSA-r7jj-pm2f-3h96.json b/advisories/unreviewed/2022/04/GHSA-r7jj-pm2f-3h96/GHSA-r7jj-pm2f-3h96.json index bddb6d72587..ab0e5ace0d4 100644 --- a/advisories/unreviewed/2022/04/GHSA-r7jj-pm2f-3h96/GHSA-r7jj-pm2f-3h96.json +++ b/advisories/unreviewed/2022/04/GHSA-r7jj-pm2f-3h96/GHSA-r7jj-pm2f-3h96.json @@ -7,12 +7,8 @@ "CVE-2001-0071" ], "details": "gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rf57-872p-6vwh/GHSA-rf57-872p-6vwh.json b/advisories/unreviewed/2022/04/GHSA-rf57-872p-6vwh/GHSA-rf57-872p-6vwh.json index 5cbb06241c5..a680317b6ee 100644 --- a/advisories/unreviewed/2022/04/GHSA-rf57-872p-6vwh/GHSA-rf57-872p-6vwh.json +++ b/advisories/unreviewed/2022/04/GHSA-rf57-872p-6vwh/GHSA-rf57-872p-6vwh.json @@ -7,12 +7,8 @@ "CVE-2001-0096" ], "details": "FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the \"Malformed Web Form Submission\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rg6w-mfrc-3cqm/GHSA-rg6w-mfrc-3cqm.json b/advisories/unreviewed/2022/04/GHSA-rg6w-mfrc-3cqm/GHSA-rg6w-mfrc-3cqm.json index 5e9a121aede..f38f3fc9a72 100644 --- a/advisories/unreviewed/2022/04/GHSA-rg6w-mfrc-3cqm/GHSA-rg6w-mfrc-3cqm.json +++ b/advisories/unreviewed/2022/04/GHSA-rg6w-mfrc-3cqm/GHSA-rg6w-mfrc-3cqm.json @@ -7,12 +7,8 @@ "CVE-2001-0058" ], "details": "The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rggv-4m8c-3m5j/GHSA-rggv-4m8c-3m5j.json b/advisories/unreviewed/2022/04/GHSA-rggv-4m8c-3m5j/GHSA-rggv-4m8c-3m5j.json index 08f53c3076f..ca25dd5aa3b 100644 --- a/advisories/unreviewed/2022/04/GHSA-rggv-4m8c-3m5j/GHSA-rggv-4m8c-3m5j.json +++ b/advisories/unreviewed/2022/04/GHSA-rggv-4m8c-3m5j/GHSA-rggv-4m8c-3m5j.json @@ -7,12 +7,8 @@ "CVE-2001-0054" ], "details": "Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as \"/..%20.\" to a CD command, a variant of a .. (dot dot) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-rm82-qwv7-jmg6/GHSA-rm82-qwv7-jmg6.json b/advisories/unreviewed/2022/04/GHSA-rm82-qwv7-jmg6/GHSA-rm82-qwv7-jmg6.json index 778a798882c..e42136f364f 100644 --- a/advisories/unreviewed/2022/04/GHSA-rm82-qwv7-jmg6/GHSA-rm82-qwv7-jmg6.json +++ b/advisories/unreviewed/2022/04/GHSA-rm82-qwv7-jmg6/GHSA-rm82-qwv7-jmg6.json @@ -7,12 +7,8 @@ "CVE-2001-0091" ], "details": "The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the \"Scriptlet Rendering\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rqm9-wg3h-56w8/GHSA-rqm9-wg3h-56w8.json b/advisories/unreviewed/2022/04/GHSA-rqm9-wg3h-56w8/GHSA-rqm9-wg3h-56w8.json index be417cddc59..5b215ca3360 100644 --- a/advisories/unreviewed/2022/04/GHSA-rqm9-wg3h-56w8/GHSA-rqm9-wg3h-56w8.json +++ b/advisories/unreviewed/2022/04/GHSA-rqm9-wg3h-56w8/GHSA-rqm9-wg3h-56w8.json @@ -7,12 +7,8 @@ "CVE-2000-1121" ], "details": "Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rww9-f89w-6257/GHSA-rww9-f89w-6257.json b/advisories/unreviewed/2022/04/GHSA-rww9-f89w-6257/GHSA-rww9-f89w-6257.json index d599e394d0d..edae68b11a7 100644 --- a/advisories/unreviewed/2022/04/GHSA-rww9-f89w-6257/GHSA-rww9-f89w-6257.json +++ b/advisories/unreviewed/2022/04/GHSA-rww9-f89w-6257/GHSA-rww9-f89w-6257.json @@ -7,12 +7,8 @@ "CVE-2001-0020" ], "details": "Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rx2f-x8pw-rhg4/GHSA-rx2f-x8pw-rhg4.json b/advisories/unreviewed/2022/04/GHSA-rx2f-x8pw-rhg4/GHSA-rx2f-x8pw-rhg4.json index 8ac834b707c..657a44d869d 100644 --- a/advisories/unreviewed/2022/04/GHSA-rx2f-x8pw-rhg4/GHSA-rx2f-x8pw-rhg4.json +++ b/advisories/unreviewed/2022/04/GHSA-rx2f-x8pw-rhg4/GHSA-rx2f-x8pw-rhg4.json @@ -7,12 +7,8 @@ "CVE-2001-0078" ], "details": "in.mond in Sun Cluster 2.x allows local users to read arbitrary files via a symlink attack on the status file of a host running HA-NFS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v39x-qc8q-rh6g/GHSA-v39x-qc8q-rh6g.json b/advisories/unreviewed/2022/04/GHSA-v39x-qc8q-rh6g/GHSA-v39x-qc8q-rh6g.json index f52c81a5385..7f220b01250 100644 --- a/advisories/unreviewed/2022/04/GHSA-v39x-qc8q-rh6g/GHSA-v39x-qc8q-rh6g.json +++ b/advisories/unreviewed/2022/04/GHSA-v39x-qc8q-rh6g/GHSA-v39x-qc8q-rh6g.json @@ -7,12 +7,8 @@ "CVE-2000-1132" ], "details": "DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a malformed \"forum\" variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v3rj-h78v-6rg2/GHSA-v3rj-h78v-6rg2.json b/advisories/unreviewed/2022/04/GHSA-v3rj-h78v-6rg2/GHSA-v3rj-h78v-6rg2.json index ca0152fb406..c3436ee0d5b 100644 --- a/advisories/unreviewed/2022/04/GHSA-v3rj-h78v-6rg2/GHSA-v3rj-h78v-6rg2.json +++ b/advisories/unreviewed/2022/04/GHSA-v3rj-h78v-6rg2/GHSA-v3rj-h78v-6rg2.json @@ -7,12 +7,8 @@ "CVE-2000-1215" ], "details": "The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote attackers to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v47q-96mv-8479/GHSA-v47q-96mv-8479.json b/advisories/unreviewed/2022/04/GHSA-v47q-96mv-8479/GHSA-v47q-96mv-8479.json index 7082075365f..9285800d929 100644 --- a/advisories/unreviewed/2022/04/GHSA-v47q-96mv-8479/GHSA-v47q-96mv-8479.json +++ b/advisories/unreviewed/2022/04/GHSA-v47q-96mv-8479/GHSA-v47q-96mv-8479.json @@ -7,12 +7,8 @@ "CVE-2000-1194" ], "details": "Argosoft FRP server 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to the (1) USER or (2) CWD commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v5g5-g755-gf4v/GHSA-v5g5-g755-gf4v.json b/advisories/unreviewed/2022/04/GHSA-v5g5-g755-gf4v/GHSA-v5g5-g755-gf4v.json index 3768c0dc1ca..bc5d6f5dd9c 100644 --- a/advisories/unreviewed/2022/04/GHSA-v5g5-g755-gf4v/GHSA-v5g5-g755-gf4v.json +++ b/advisories/unreviewed/2022/04/GHSA-v5g5-g755-gf4v/GHSA-v5g5-g755-gf4v.json @@ -7,12 +7,8 @@ "CVE-2001-0010" ], "details": "Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v64h-8rq4-grgg/GHSA-v64h-8rq4-grgg.json b/advisories/unreviewed/2022/04/GHSA-v64h-8rq4-grgg/GHSA-v64h-8rq4-grgg.json index 14bf4cf7d20..820e501b1b6 100644 --- a/advisories/unreviewed/2022/04/GHSA-v64h-8rq4-grgg/GHSA-v64h-8rq4-grgg.json +++ b/advisories/unreviewed/2022/04/GHSA-v64h-8rq4-grgg/GHSA-v64h-8rq4-grgg.json @@ -7,12 +7,8 @@ "CVE-2001-0083" ], "details": "Windows Media Unicast Service in Windows Media Services 4.0 and 4.1 does not properly shut down some types of connections, producing a memory leak that allows remote attackers to cause a denial of service via a series of severed connections, aka the \"Severed Windows Media Server Connection\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vch7-4w8r-84c6/GHSA-vch7-4w8r-84c6.json b/advisories/unreviewed/2022/04/GHSA-vch7-4w8r-84c6/GHSA-vch7-4w8r-84c6.json index a9dbcefec9a..343b6b0b64b 100644 --- a/advisories/unreviewed/2022/04/GHSA-vch7-4w8r-84c6/GHSA-vch7-4w8r-84c6.json +++ b/advisories/unreviewed/2022/04/GHSA-vch7-4w8r-84c6/GHSA-vch7-4w8r-84c6.json @@ -7,12 +7,8 @@ "CVE-2000-1143" ], "details": "Recourse ManTrap 1.6 hides the first 4 processes that run on a Solaris system, which allows attackers to determine that they are in a honeypot system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vcxc-2pg3-26ww/GHSA-vcxc-2pg3-26ww.json b/advisories/unreviewed/2022/04/GHSA-vcxc-2pg3-26ww/GHSA-vcxc-2pg3-26ww.json index 025108ffb18..ded69811c5a 100644 --- a/advisories/unreviewed/2022/04/GHSA-vcxc-2pg3-26ww/GHSA-vcxc-2pg3-26ww.json +++ b/advisories/unreviewed/2022/04/GHSA-vcxc-2pg3-26ww/GHSA-vcxc-2pg3-26ww.json @@ -7,12 +7,8 @@ "CVE-2000-1207" ], "details": "userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vpmv-x387-37fq/GHSA-vpmv-x387-37fq.json b/advisories/unreviewed/2022/04/GHSA-vpmv-x387-37fq/GHSA-vpmv-x387-37fq.json index 18d8f34cc22..e881eb0ceba 100644 --- a/advisories/unreviewed/2022/04/GHSA-vpmv-x387-37fq/GHSA-vpmv-x387-37fq.json +++ b/advisories/unreviewed/2022/04/GHSA-vpmv-x387-37fq/GHSA-vpmv-x387-37fq.json @@ -7,12 +7,8 @@ "CVE-2001-0011" ], "details": "Buffer overflow in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vqp5-459c-mpqx/GHSA-vqp5-459c-mpqx.json b/advisories/unreviewed/2022/04/GHSA-vqp5-459c-mpqx/GHSA-vqp5-459c-mpqx.json index cd5971d8fae..71f5e10a64b 100644 --- a/advisories/unreviewed/2022/04/GHSA-vqp5-459c-mpqx/GHSA-vqp5-459c-mpqx.json +++ b/advisories/unreviewed/2022/04/GHSA-vqp5-459c-mpqx/GHSA-vqp5-459c-mpqx.json @@ -7,12 +7,8 @@ "CVE-2000-1155" ], "details": "RHDaemon in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w3c8-c6wv-46cf/GHSA-w3c8-c6wv-46cf.json b/advisories/unreviewed/2022/04/GHSA-w3c8-c6wv-46cf/GHSA-w3c8-c6wv-46cf.json index 1397e0c8527..9d27eba4d64 100644 --- a/advisories/unreviewed/2022/04/GHSA-w3c8-c6wv-46cf/GHSA-w3c8-c6wv-46cf.json +++ b/advisories/unreviewed/2022/04/GHSA-w3c8-c6wv-46cf/GHSA-w3c8-c6wv-46cf.json @@ -7,12 +7,8 @@ "CVE-2001-0022" ], "details": "simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the guestbook parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w3j9-383p-8723/GHSA-w3j9-383p-8723.json b/advisories/unreviewed/2022/04/GHSA-w3j9-383p-8723/GHSA-w3j9-383p-8723.json index 665a6905f36..d7f8e37e1de 100644 --- a/advisories/unreviewed/2022/04/GHSA-w3j9-383p-8723/GHSA-w3j9-383p-8723.json +++ b/advisories/unreviewed/2022/04/GHSA-w3j9-383p-8723/GHSA-w3j9-383p-8723.json @@ -7,12 +7,8 @@ "CVE-2001-0041" ], "details": "Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w468-9c9j-8x8w/GHSA-w468-9c9j-8x8w.json b/advisories/unreviewed/2022/04/GHSA-w468-9c9j-8x8w/GHSA-w468-9c9j-8x8w.json index 92d1b951eca..8fcff1157c3 100644 --- a/advisories/unreviewed/2022/04/GHSA-w468-9c9j-8x8w/GHSA-w468-9c9j-8x8w.json +++ b/advisories/unreviewed/2022/04/GHSA-w468-9c9j-8x8w/GHSA-w468-9c9j-8x8w.json @@ -7,12 +7,8 @@ "CVE-2000-1075" ], "details": "Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w46j-qhph-4m5p/GHSA-w46j-qhph-4m5p.json b/advisories/unreviewed/2022/04/GHSA-w46j-qhph-4m5p/GHSA-w46j-qhph-4m5p.json index 52ae99e33eb..06923b40e6b 100644 --- a/advisories/unreviewed/2022/04/GHSA-w46j-qhph-4m5p/GHSA-w46j-qhph-4m5p.json +++ b/advisories/unreviewed/2022/04/GHSA-w46j-qhph-4m5p/GHSA-w46j-qhph-4m5p.json @@ -7,12 +7,8 @@ "CVE-2000-1156" ], "details": "StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a local user to read files of the user who is using StarOffice.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w49w-x35m-8jvm/GHSA-w49w-x35m-8jvm.json b/advisories/unreviewed/2022/04/GHSA-w49w-x35m-8jvm/GHSA-w49w-x35m-8jvm.json index 45fb3d246bc..bd6a1f8d570 100644 --- a/advisories/unreviewed/2022/04/GHSA-w49w-x35m-8jvm/GHSA-w49w-x35m-8jvm.json +++ b/advisories/unreviewed/2022/04/GHSA-w49w-x35m-8jvm/GHSA-w49w-x35m-8jvm.json @@ -7,12 +7,8 @@ "CVE-2000-1195" ], "details": "telnet daemon (telnetd) from the Linux netkit package before netkit-telnet-0.16 allows remote attackers to bypass authentication when telnetd is running with the -L command line option.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wcg5-3v2j-2jwv/GHSA-wcg5-3v2j-2jwv.json b/advisories/unreviewed/2022/04/GHSA-wcg5-3v2j-2jwv/GHSA-wcg5-3v2j-2jwv.json index 919a1c96f48..203164ccbb4 100644 --- a/advisories/unreviewed/2022/04/GHSA-wcg5-3v2j-2jwv/GHSA-wcg5-3v2j-2jwv.json +++ b/advisories/unreviewed/2022/04/GHSA-wcg5-3v2j-2jwv/GHSA-wcg5-3v2j-2jwv.json @@ -7,12 +7,8 @@ "CVE-2001-0033" ], "details": "KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the user to gain additional privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wch8-9qmv-rh9x/GHSA-wch8-9qmv-rh9x.json b/advisories/unreviewed/2022/04/GHSA-wch8-9qmv-rh9x/GHSA-wch8-9qmv-rh9x.json index a349201d69f..b42907b218e 100644 --- a/advisories/unreviewed/2022/04/GHSA-wch8-9qmv-rh9x/GHSA-wch8-9qmv-rh9x.json +++ b/advisories/unreviewed/2022/04/GHSA-wch8-9qmv-rh9x/GHSA-wch8-9qmv-rh9x.json @@ -7,12 +7,8 @@ "CVE-2001-0015" ], "details": "Network Dynamic Data Exchange (DDE) in Windows 2000 allows local users to gain SYSTEM privileges via a \"WM_COPYDATA\" message to an invisible window that is running with the privileges of the WINLOGON process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wchf-87v9-mpjf/GHSA-wchf-87v9-mpjf.json b/advisories/unreviewed/2022/04/GHSA-wchf-87v9-mpjf/GHSA-wchf-87v9-mpjf.json index edea4dff386..a1ecf229e4b 100644 --- a/advisories/unreviewed/2022/04/GHSA-wchf-87v9-mpjf/GHSA-wchf-87v9-mpjf.json +++ b/advisories/unreviewed/2022/04/GHSA-wchf-87v9-mpjf/GHSA-wchf-87v9-mpjf.json @@ -7,12 +7,8 @@ "CVE-2001-0005" ], "details": "Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wgg7-hq2q-9g57/GHSA-wgg7-hq2q-9g57.json b/advisories/unreviewed/2022/04/GHSA-wgg7-hq2q-9g57/GHSA-wgg7-hq2q-9g57.json index 813e4121410..899075765c9 100644 --- a/advisories/unreviewed/2022/04/GHSA-wgg7-hq2q-9g57/GHSA-wgg7-hq2q-9g57.json +++ b/advisories/unreviewed/2022/04/GHSA-wgg7-hq2q-9g57/GHSA-wgg7-hq2q-9g57.json @@ -7,12 +7,8 @@ "CVE-2001-0085" ], "details": "Buffer overflow in Kermit communications software in HP-UX 11.0 and earlier allows local users to cause a denial of service and possibly execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wgvf-8g6v-pm8p/GHSA-wgvf-8g6v-pm8p.json b/advisories/unreviewed/2022/04/GHSA-wgvf-8g6v-pm8p/GHSA-wgvf-8g6v-pm8p.json index 50d73bab70c..696b149a05e 100644 --- a/advisories/unreviewed/2022/04/GHSA-wgvf-8g6v-pm8p/GHSA-wgvf-8g6v-pm8p.json +++ b/advisories/unreviewed/2022/04/GHSA-wgvf-8g6v-pm8p/GHSA-wgvf-8g6v-pm8p.json @@ -7,12 +7,8 @@ "CVE-2001-0082" ], "details": "Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wmq7-p773-jmqg/GHSA-wmq7-p773-jmqg.json b/advisories/unreviewed/2022/04/GHSA-wmq7-p773-jmqg/GHSA-wmq7-p773-jmqg.json index c6b2d6ed052..a5a7a8d0446 100644 --- a/advisories/unreviewed/2022/04/GHSA-wmq7-p773-jmqg/GHSA-wmq7-p773-jmqg.json +++ b/advisories/unreviewed/2022/04/GHSA-wmq7-p773-jmqg/GHSA-wmq7-p773-jmqg.json @@ -7,12 +7,8 @@ "CVE-2001-0002" ], "details": "Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wmwf-3w9p-w4cj/GHSA-wmwf-3w9p-w4cj.json b/advisories/unreviewed/2022/04/GHSA-wmwf-3w9p-w4cj/GHSA-wmwf-3w9p-w4cj.json index 6e5e4185f4b..89af4d7fdbc 100644 --- a/advisories/unreviewed/2022/04/GHSA-wmwf-3w9p-w4cj/GHSA-wmwf-3w9p-w4cj.json +++ b/advisories/unreviewed/2022/04/GHSA-wmwf-3w9p-w4cj/GHSA-wmwf-3w9p-w4cj.json @@ -7,12 +7,8 @@ "CVE-2001-0080" ], "details": "Cisco Catalyst 6000, 5000, or 4000 switches allow remote attackers to cause a denial of service by connecting to the SSH service with a non-SSH client, which generates a protocol mismatch error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wp4f-j236-w785/GHSA-wp4f-j236-w785.json b/advisories/unreviewed/2022/04/GHSA-wp4f-j236-w785/GHSA-wp4f-j236-w785.json index 34c3ee8677e..6d0df203698 100644 --- a/advisories/unreviewed/2022/04/GHSA-wp4f-j236-w785/GHSA-wp4f-j236-w785.json +++ b/advisories/unreviewed/2022/04/GHSA-wp4f-j236-w785/GHSA-wp4f-j236-w785.json @@ -7,12 +7,8 @@ "CVE-2000-1219" ], "details": "The -ftrapv compiler option in gcc and g++ 3.3.3 and earlier does not handle all types of integer overflows, which may leave applications vulnerable to vulnerabilities related to overflows.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wx56-xj4w-qc5p/GHSA-wx56-xj4w-qc5p.json b/advisories/unreviewed/2022/04/GHSA-wx56-xj4w-qc5p/GHSA-wx56-xj4w-qc5p.json index 7856a6bf02f..413e8649d2b 100644 --- a/advisories/unreviewed/2022/04/GHSA-wx56-xj4w-qc5p/GHSA-wx56-xj4w-qc5p.json +++ b/advisories/unreviewed/2022/04/GHSA-wx56-xj4w-qc5p/GHSA-wx56-xj4w-qc5p.json @@ -7,12 +7,8 @@ "CVE-2001-0036" ], "details": "KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wx88-723w-mp25/GHSA-wx88-723w-mp25.json b/advisories/unreviewed/2022/04/GHSA-wx88-723w-mp25/GHSA-wx88-723w-mp25.json index eade90f8283..295cf02c5c1 100644 --- a/advisories/unreviewed/2022/04/GHSA-wx88-723w-mp25/GHSA-wx88-723w-mp25.json +++ b/advisories/unreviewed/2022/04/GHSA-wx88-723w-mp25/GHSA-wx88-723w-mp25.json @@ -7,12 +7,8 @@ "CVE-2001-0037" ], "details": "Directory traversal vulnerability in HomeSeer before 1.4.29 allows remote attackers to read arbitrary files via a URL containing .. (dot dot) specifiers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wxg9-35f2-vw25/GHSA-wxg9-35f2-vw25.json b/advisories/unreviewed/2022/04/GHSA-wxg9-35f2-vw25/GHSA-wxg9-35f2-vw25.json index 03ea91b5e52..e1bc9166859 100644 --- a/advisories/unreviewed/2022/04/GHSA-wxg9-35f2-vw25/GHSA-wxg9-35f2-vw25.json +++ b/advisories/unreviewed/2022/04/GHSA-wxg9-35f2-vw25/GHSA-wxg9-35f2-vw25.json @@ -7,12 +7,8 @@ "CVE-2000-1216" ], "details": "Buffer overflow in portmir for AIX 4.3.0 allows local users to corrupt lock files and gain root privileges via the echo_error routine.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-x2pj-7r2v-7334/GHSA-x2pj-7r2v-7334.json b/advisories/unreviewed/2022/04/GHSA-x2pj-7r2v-7334/GHSA-x2pj-7r2v-7334.json index 9a99950b5f9..14f023fd909 100644 --- a/advisories/unreviewed/2022/04/GHSA-x2pj-7r2v-7334/GHSA-x2pj-7r2v-7334.json +++ b/advisories/unreviewed/2022/04/GHSA-x2pj-7r2v-7334/GHSA-x2pj-7r2v-7334.json @@ -7,12 +7,8 @@ "CVE-2001-0051" ], "details": "IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x37q-rf4q-x5w3/GHSA-x37q-rf4q-x5w3.json b/advisories/unreviewed/2022/04/GHSA-x37q-rf4q-x5w3/GHSA-x37q-rf4q-x5w3.json index d0baaaa8f98..45042a36fbc 100644 --- a/advisories/unreviewed/2022/04/GHSA-x37q-rf4q-x5w3/GHSA-x37q-rf4q-x5w3.json +++ b/advisories/unreviewed/2022/04/GHSA-x37q-rf4q-x5w3/GHSA-x37q-rf4q-x5w3.json @@ -7,12 +7,8 @@ "CVE-2000-1103" ], "details": "rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x3qm-9gh7-w9w5/GHSA-x3qm-9gh7-w9w5.json b/advisories/unreviewed/2022/04/GHSA-x3qm-9gh7-w9w5/GHSA-x3qm-9gh7-w9w5.json index f834526f128..fa58a5ac9d1 100644 --- a/advisories/unreviewed/2022/04/GHSA-x3qm-9gh7-w9w5/GHSA-x3qm-9gh7-w9w5.json +++ b/advisories/unreviewed/2022/04/GHSA-x3qm-9gh7-w9w5/GHSA-x3qm-9gh7-w9w5.json @@ -7,12 +7,8 @@ "CVE-2000-1087" ], "details": "The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the \"Extended Stored Procedure Parameter Parsing\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x4gh-8p78-vxxx/GHSA-x4gh-8p78-vxxx.json b/advisories/unreviewed/2022/04/GHSA-x4gh-8p78-vxxx/GHSA-x4gh-8p78-vxxx.json index a3ed7351f67..12bf2d3664d 100644 --- a/advisories/unreviewed/2022/04/GHSA-x4gh-8p78-vxxx/GHSA-x4gh-8p78-vxxx.json +++ b/advisories/unreviewed/2022/04/GHSA-x4gh-8p78-vxxx/GHSA-x4gh-8p78-vxxx.json @@ -7,12 +7,8 @@ "CVE-2000-1176" ], "details": "Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the \"catsearch\" form field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x4gm-q74w-h727/GHSA-x4gm-q74w-h727.json b/advisories/unreviewed/2022/04/GHSA-x4gm-q74w-h727/GHSA-x4gm-q74w-h727.json index 9903b0d5d66..8e5c0f2df48 100644 --- a/advisories/unreviewed/2022/04/GHSA-x4gm-q74w-h727/GHSA-x4gm-q74w-h727.json +++ b/advisories/unreviewed/2022/04/GHSA-x4gm-q74w-h727/GHSA-x4gm-q74w-h727.json @@ -7,12 +7,8 @@ "CVE-2000-1188" ], "details": "Directory traversal vulnerability in Quikstore shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the \"page\" parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x8pj-r335-vm92/GHSA-x8pj-r335-vm92.json b/advisories/unreviewed/2022/04/GHSA-x8pj-r335-vm92/GHSA-x8pj-r335-vm92.json index 4c6ade97499..4a6f798c76e 100644 --- a/advisories/unreviewed/2022/04/GHSA-x8pj-r335-vm92/GHSA-x8pj-r335-vm92.json +++ b/advisories/unreviewed/2022/04/GHSA-x8pj-r335-vm92/GHSA-x8pj-r335-vm92.json @@ -7,12 +7,8 @@ "CVE-2000-1208" ], "details": "Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xch8-9g2h-gjrm/GHSA-xch8-9g2h-gjrm.json b/advisories/unreviewed/2022/04/GHSA-xch8-9g2h-gjrm/GHSA-xch8-9g2h-gjrm.json index ffe66ff976d..cf936613fbd 100644 --- a/advisories/unreviewed/2022/04/GHSA-xch8-9g2h-gjrm/GHSA-xch8-9g2h-gjrm.json +++ b/advisories/unreviewed/2022/04/GHSA-xch8-9g2h-gjrm/GHSA-xch8-9g2h-gjrm.json @@ -7,12 +7,8 @@ "CVE-2000-1133" ], "details": "Authentix Authentix100 allows remote attackers to bypass authentication by inserting a . (dot) into the URL for a protected directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xh44-f8rg-h6h3/GHSA-xh44-f8rg-h6h3.json b/advisories/unreviewed/2022/04/GHSA-xh44-f8rg-h6h3/GHSA-xh44-f8rg-h6h3.json index 4fda6232aac..4e28d7343dc 100644 --- a/advisories/unreviewed/2022/04/GHSA-xh44-f8rg-h6h3/GHSA-xh44-f8rg-h6h3.json +++ b/advisories/unreviewed/2022/04/GHSA-xh44-f8rg-h6h3/GHSA-xh44-f8rg-h6h3.json @@ -7,12 +7,8 @@ "CVE-2000-1117" ], "details": "The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xh54-hh7j-wm53/GHSA-xh54-hh7j-wm53.json b/advisories/unreviewed/2022/04/GHSA-xh54-hh7j-wm53/GHSA-xh54-hh7j-wm53.json index 35a13d2099a..9cf88be47dc 100644 --- a/advisories/unreviewed/2022/04/GHSA-xh54-hh7j-wm53/GHSA-xh54-hh7j-wm53.json +++ b/advisories/unreviewed/2022/04/GHSA-xh54-hh7j-wm53/GHSA-xh54-hh7j-wm53.json @@ -7,12 +7,8 @@ "CVE-2000-1078" ], "details": "ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a \"?\" character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xm9q-wvh7-2637/GHSA-xm9q-wvh7-2637.json b/advisories/unreviewed/2022/04/GHSA-xm9q-wvh7-2637/GHSA-xm9q-wvh7-2637.json index fa09c3f843a..bb198796e6f 100644 --- a/advisories/unreviewed/2022/04/GHSA-xm9q-wvh7-2637/GHSA-xm9q-wvh7-2637.json +++ b/advisories/unreviewed/2022/04/GHSA-xm9q-wvh7-2637/GHSA-xm9q-wvh7-2637.json @@ -7,12 +7,8 @@ "CVE-2000-1153" ], "details": "PostMaster 1.0 in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xmgq-gq24-73mw/GHSA-xmgq-gq24-73mw.json b/advisories/unreviewed/2022/04/GHSA-xmgq-gq24-73mw/GHSA-xmgq-gq24-73mw.json index 97592621e5a..47f164a75cc 100644 --- a/advisories/unreviewed/2022/04/GHSA-xmgq-gq24-73mw/GHSA-xmgq-gq24-73mw.json +++ b/advisories/unreviewed/2022/04/GHSA-xmgq-gq24-73mw/GHSA-xmgq-gq24-73mw.json @@ -7,12 +7,8 @@ "CVE-2000-1180" ], "details": "Buffer overflow in cmctl program in Oracle 8.1.5 Connection Manager Control allows local users to gain privileges via a long command line argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xr84-px4q-9chh/GHSA-xr84-px4q-9chh.json b/advisories/unreviewed/2022/04/GHSA-xr84-px4q-9chh/GHSA-xr84-px4q-9chh.json index a162a1dddd0..979651f20e3 100644 --- a/advisories/unreviewed/2022/04/GHSA-xr84-px4q-9chh/GHSA-xr84-px4q-9chh.json +++ b/advisories/unreviewed/2022/04/GHSA-xr84-px4q-9chh/GHSA-xr84-px4q-9chh.json @@ -7,12 +7,8 @@ "CVE-2000-1116" ], "details": "Buffer overflow in TransSoft Broker FTP Server before 4.3.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xvj4-j4pc-f2wp/GHSA-xvj4-j4pc-f2wp.json b/advisories/unreviewed/2022/04/GHSA-xvj4-j4pc-f2wp/GHSA-xvj4-j4pc-f2wp.json index 710e03c8b79..fc6e5e14e22 100644 --- a/advisories/unreviewed/2022/04/GHSA-xvj4-j4pc-f2wp/GHSA-xvj4-j4pc-f2wp.json +++ b/advisories/unreviewed/2022/04/GHSA-xvj4-j4pc-f2wp/GHSA-xvj4-j4pc-f2wp.json @@ -7,12 +7,8 @@ "CVE-2001-0048" ], "details": "The \"Configure Your Server\" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the \"Directory Service Restore Mode Password\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xvrp-vp23-p3wp/GHSA-xvrp-vp23-p3wp.json b/advisories/unreviewed/2022/04/GHSA-xvrp-vp23-p3wp/GHSA-xvrp-vp23-p3wp.json index 3c1a34c4e10..dc84fcc2c7c 100644 --- a/advisories/unreviewed/2022/04/GHSA-xvrp-vp23-p3wp/GHSA-xvrp-vp23-p3wp.json +++ b/advisories/unreviewed/2022/04/GHSA-xvrp-vp23-p3wp/GHSA-xvrp-vp23-p3wp.json @@ -7,12 +7,8 @@ "CVE-2000-1142" ], "details": "Recourse ManTrap 1.6 generates an error when an attacker cd's to /proc/self/cwd and executes the pwd command, which allows attackers to determine that they are in a honeypot system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xw5j-6ccc-rwh9/GHSA-xw5j-6ccc-rwh9.json b/advisories/unreviewed/2022/04/GHSA-xw5j-6ccc-rwh9/GHSA-xw5j-6ccc-rwh9.json index f4c42cd064b..3429bd06c0d 100644 --- a/advisories/unreviewed/2022/04/GHSA-xw5j-6ccc-rwh9/GHSA-xw5j-6ccc-rwh9.json +++ b/advisories/unreviewed/2022/04/GHSA-xw5j-6ccc-rwh9/GHSA-xw5j-6ccc-rwh9.json @@ -7,12 +7,8 @@ "CVE-2001-0039" ], "details": "IPSwitch IMail 6.0.5 allows remote attackers to cause a denial of service using the SMTP AUTH command by sending a base64-encoded user password whose length is between 80 and 136 bytes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xwhm-gpc5-8rh4/GHSA-xwhm-gpc5-8rh4.json b/advisories/unreviewed/2022/04/GHSA-xwhm-gpc5-8rh4/GHSA-xwhm-gpc5-8rh4.json index 05466b7800b..158657d7cd6 100644 --- a/advisories/unreviewed/2022/04/GHSA-xwhm-gpc5-8rh4/GHSA-xwhm-gpc5-8rh4.json +++ b/advisories/unreviewed/2022/04/GHSA-xwhm-gpc5-8rh4/GHSA-xwhm-gpc5-8rh4.json @@ -7,12 +7,8 @@ "CVE-2000-1141" ], "details": "Recourse ManTrap 1.6 modifies the kernel so that \"..\" does not appear in the /proc listing, which allows attackers to determine that they are in a honeypot system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-22vf-qc4p-vc3x/GHSA-22vf-qc4p-vc3x.json b/advisories/unreviewed/2022/05/GHSA-22vf-qc4p-vc3x/GHSA-22vf-qc4p-vc3x.json index 3392d4b8b2d..135ae23effe 100644 --- a/advisories/unreviewed/2022/05/GHSA-22vf-qc4p-vc3x/GHSA-22vf-qc4p-vc3x.json +++ b/advisories/unreviewed/2022/05/GHSA-22vf-qc4p-vc3x/GHSA-22vf-qc4p-vc3x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-24c4-w46m-qj98/GHSA-24c4-w46m-qj98.json b/advisories/unreviewed/2022/05/GHSA-24c4-w46m-qj98/GHSA-24c4-w46m-qj98.json index 84f0da5bdfb..efdc763262a 100644 --- a/advisories/unreviewed/2022/05/GHSA-24c4-w46m-qj98/GHSA-24c4-w46m-qj98.json +++ b/advisories/unreviewed/2022/05/GHSA-24c4-w46m-qj98/GHSA-24c4-w46m-qj98.json @@ -7,12 +7,8 @@ "CVE-2020-4081" ], "details": "In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-25cq-vrf7-vjqr/GHSA-25cq-vrf7-vjqr.json b/advisories/unreviewed/2022/05/GHSA-25cq-vrf7-vjqr/GHSA-25cq-vrf7-vjqr.json index 417be5a8ca8..d3ad8de46b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-25cq-vrf7-vjqr/GHSA-25cq-vrf7-vjqr.json +++ b/advisories/unreviewed/2022/05/GHSA-25cq-vrf7-vjqr/GHSA-25cq-vrf7-vjqr.json @@ -7,12 +7,8 @@ "CVE-2021-1344" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-27xm-pjj9-xmm8/GHSA-27xm-pjj9-xmm8.json b/advisories/unreviewed/2022/05/GHSA-27xm-pjj9-xmm8/GHSA-27xm-pjj9-xmm8.json index e40d92f6b96..4984df3e557 100644 --- a/advisories/unreviewed/2022/05/GHSA-27xm-pjj9-xmm8/GHSA-27xm-pjj9-xmm8.json +++ b/advisories/unreviewed/2022/05/GHSA-27xm-pjj9-xmm8/GHSA-27xm-pjj9-xmm8.json @@ -7,12 +7,8 @@ "CVE-2021-25125" ], "details": "The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spx_restservice delsolrecordedvideo_func function path traversal vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-28vx-6729-qmmp/GHSA-28vx-6729-qmmp.json b/advisories/unreviewed/2022/05/GHSA-28vx-6729-qmmp/GHSA-28vx-6729-qmmp.json index 75eec284247..8818ebf9e42 100644 --- a/advisories/unreviewed/2022/05/GHSA-28vx-6729-qmmp/GHSA-28vx-6729-qmmp.json +++ b/advisories/unreviewed/2022/05/GHSA-28vx-6729-qmmp/GHSA-28vx-6729-qmmp.json @@ -7,12 +7,8 @@ "CVE-2021-1348" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2cwm-q4rq-7594/GHSA-2cwm-q4rq-7594.json b/advisories/unreviewed/2022/05/GHSA-2cwm-q4rq-7594/GHSA-2cwm-q4rq-7594.json index 6ec7dc6b0b7..8354cc5e66e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cwm-q4rq-7594/GHSA-2cwm-q4rq-7594.json +++ b/advisories/unreviewed/2022/05/GHSA-2cwm-q4rq-7594/GHSA-2cwm-q4rq-7594.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fc5-f5mf-j7xp/GHSA-2fc5-f5mf-j7xp.json b/advisories/unreviewed/2022/05/GHSA-2fc5-f5mf-j7xp/GHSA-2fc5-f5mf-j7xp.json index afc354bf7a3..7d95cf9f239 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fc5-f5mf-j7xp/GHSA-2fc5-f5mf-j7xp.json +++ b/advisories/unreviewed/2022/05/GHSA-2fc5-f5mf-j7xp/GHSA-2fc5-f5mf-j7xp.json @@ -7,12 +7,8 @@ "CVE-2021-25169" ], "details": "The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so websetservicecfg function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fh3-xg72-f7vx/GHSA-2fh3-xg72-f7vx.json b/advisories/unreviewed/2022/05/GHSA-2fh3-xg72-f7vx/GHSA-2fh3-xg72-f7vx.json index b3d8e2f2048..87555dca8f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fh3-xg72-f7vx/GHSA-2fh3-xg72-f7vx.json +++ b/advisories/unreviewed/2022/05/GHSA-2fh3-xg72-f7vx/GHSA-2fh3-xg72-f7vx.json @@ -7,12 +7,8 @@ "CVE-2021-3378" ], "details": "FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a \"Content-Type: image/png\" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fqw-v698-338m/GHSA-2fqw-v698-338m.json b/advisories/unreviewed/2022/05/GHSA-2fqw-v698-338m/GHSA-2fqw-v698-338m.json index 3a22c4243cb..90bbb3a770c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fqw-v698-338m/GHSA-2fqw-v698-338m.json +++ b/advisories/unreviewed/2022/05/GHSA-2fqw-v698-338m/GHSA-2fqw-v698-338m.json @@ -7,12 +7,8 @@ "CVE-2020-20287" ], "details": "Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2g4x-fv7q-8jrf/GHSA-2g4x-fv7q-8jrf.json b/advisories/unreviewed/2022/05/GHSA-2g4x-fv7q-8jrf/GHSA-2g4x-fv7q-8jrf.json index 92c774ff483..40beebc22d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g4x-fv7q-8jrf/GHSA-2g4x-fv7q-8jrf.json +++ b/advisories/unreviewed/2022/05/GHSA-2g4x-fv7q-8jrf/GHSA-2g4x-fv7q-8jrf.json @@ -7,12 +7,8 @@ "CVE-2021-21123" ], "details": "Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2jfm-367p-85fj/GHSA-2jfm-367p-85fj.json b/advisories/unreviewed/2022/05/GHSA-2jfm-367p-85fj/GHSA-2jfm-367p-85fj.json index 919854b9d4c..c048b4390f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jfm-367p-85fj/GHSA-2jfm-367p-85fj.json +++ b/advisories/unreviewed/2022/05/GHSA-2jfm-367p-85fj/GHSA-2jfm-367p-85fj.json @@ -7,12 +7,8 @@ "CVE-2020-13857" ], "details": "An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They can be rebooted by sending an unauthenticated poof.cgi HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2q3x-mqw8-qf9r/GHSA-2q3x-mqw8-qf9r.json b/advisories/unreviewed/2022/05/GHSA-2q3x-mqw8-qf9r/GHSA-2q3x-mqw8-qf9r.json index 192137fe4d5..00d99f361a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-2q3x-mqw8-qf9r/GHSA-2q3x-mqw8-qf9r.json +++ b/advisories/unreviewed/2022/05/GHSA-2q3x-mqw8-qf9r/GHSA-2q3x-mqw8-qf9r.json @@ -7,12 +7,8 @@ "CVE-2021-25249" ], "details": "An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2q4h-h5jp-942w/GHSA-2q4h-h5jp-942w.json b/advisories/unreviewed/2022/05/GHSA-2q4h-h5jp-942w/GHSA-2q4h-h5jp-942w.json index 392cd220421..7034d3662bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-2q4h-h5jp-942w/GHSA-2q4h-h5jp-942w.json +++ b/advisories/unreviewed/2022/05/GHSA-2q4h-h5jp-942w/GHSA-2q4h-h5jp-942w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2qp5-r446-qvgh/GHSA-2qp5-r446-qvgh.json b/advisories/unreviewed/2022/05/GHSA-2qp5-r446-qvgh/GHSA-2qp5-r446-qvgh.json index 8f39d94112f..31db4e0e23b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qp5-r446-qvgh/GHSA-2qp5-r446-qvgh.json +++ b/advisories/unreviewed/2022/05/GHSA-2qp5-r446-qvgh/GHSA-2qp5-r446-qvgh.json @@ -7,12 +7,8 @@ "CVE-2021-1345" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2r9h-7mx9-fq3w/GHSA-2r9h-7mx9-fq3w.json b/advisories/unreviewed/2022/05/GHSA-2r9h-7mx9-fq3w/GHSA-2r9h-7mx9-fq3w.json index 70f8f55d736..04b7484e011 100644 --- a/advisories/unreviewed/2022/05/GHSA-2r9h-7mx9-fq3w/GHSA-2r9h-7mx9-fq3w.json +++ b/advisories/unreviewed/2022/05/GHSA-2r9h-7mx9-fq3w/GHSA-2r9h-7mx9-fq3w.json @@ -7,12 +7,8 @@ "CVE-2020-36148" ], "details": "Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protection or near NULL pointer overwrite in case of no memory restrictions (e.g. in embedded environments).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2rff-cr3q-94jm/GHSA-2rff-cr3q-94jm.json b/advisories/unreviewed/2022/05/GHSA-2rff-cr3q-94jm/GHSA-2rff-cr3q-94jm.json index f3301d770a0..820497d493a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rff-cr3q-94jm/GHSA-2rff-cr3q-94jm.json +++ b/advisories/unreviewed/2022/05/GHSA-2rff-cr3q-94jm/GHSA-2rff-cr3q-94jm.json @@ -7,12 +7,8 @@ "CVE-2021-21434" ], "details": "Survey administrator can craft a survey in such way that malicious code can be executed in the agent interface (i.e. another agent who wants to make changes in the survey). This issue affects: OTRS AG Survey 6.0.x version 6.0.20 and prior versions; 7.0.x version 7.0.19 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2vrq-x473-q93m/GHSA-2vrq-x473-q93m.json b/advisories/unreviewed/2022/05/GHSA-2vrq-x473-q93m/GHSA-2vrq-x473-q93m.json index 1fe45348125..77f4665b0ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vrq-x473-q93m/GHSA-2vrq-x473-q93m.json +++ b/advisories/unreviewed/2022/05/GHSA-2vrq-x473-q93m/GHSA-2vrq-x473-q93m.json @@ -7,12 +7,8 @@ "CVE-2021-27140" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to find passwords and authentication cookies stored in cleartext in the web.log HTTP logs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2w55-f536-w4g7/GHSA-2w55-f536-w4g7.json b/advisories/unreviewed/2022/05/GHSA-2w55-f536-w4g7/GHSA-2w55-f536-w4g7.json index f0cff6d9076..c7a03202be2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w55-f536-w4g7/GHSA-2w55-f536-w4g7.json +++ b/advisories/unreviewed/2022/05/GHSA-2w55-f536-w4g7/GHSA-2w55-f536-w4g7.json @@ -7,12 +7,8 @@ "CVE-2021-26687" ], "details": "An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. In preloaded applications, the HostnameVerified default is mishandled. The LG ID is LVE-SMP-200029 (February 2021).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2xjp-jvqv-hvj5/GHSA-2xjp-jvqv-hvj5.json b/advisories/unreviewed/2022/05/GHSA-2xjp-jvqv-hvj5/GHSA-2xjp-jvqv-hvj5.json index 75e085e60f3..18b6aa748b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xjp-jvqv-hvj5/GHSA-2xjp-jvqv-hvj5.json +++ b/advisories/unreviewed/2022/05/GHSA-2xjp-jvqv-hvj5/GHSA-2xjp-jvqv-hvj5.json @@ -7,12 +7,8 @@ "CVE-2021-22663" ], "details": "Cscape (All versions prior to 9.90 SP3.5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-322w-f24m-rgpr/GHSA-322w-f24m-rgpr.json b/advisories/unreviewed/2022/05/GHSA-322w-f24m-rgpr/GHSA-322w-f24m-rgpr.json index 3c8b9019caa..61ec09bb3a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-322w-f24m-rgpr/GHSA-322w-f24m-rgpr.json +++ b/advisories/unreviewed/2022/05/GHSA-322w-f24m-rgpr/GHSA-322w-f24m-rgpr.json @@ -7,12 +7,8 @@ "CVE-2021-20652" ], "details": "Cross-site request forgery (CSRF) vulnerability in Name Directory 1.17.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3254-79q7-7q66/GHSA-3254-79q7-7q66.json b/advisories/unreviewed/2022/05/GHSA-3254-79q7-7q66/GHSA-3254-79q7-7q66.json index 6767b9909a0..0e829fd9fd9 100644 --- a/advisories/unreviewed/2022/05/GHSA-3254-79q7-7q66/GHSA-3254-79q7-7q66.json +++ b/advisories/unreviewed/2022/05/GHSA-3254-79q7-7q66/GHSA-3254-79q7-7q66.json @@ -7,12 +7,8 @@ "CVE-2020-35547" ], "details": "A library index page in NuPoint Messenger in Mitel MiCollab before 9.2 FP1 could allow an unauthenticated attacker to gain access (view and modify) to user data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3267-pg8g-jq86/GHSA-3267-pg8g-jq86.json b/advisories/unreviewed/2022/05/GHSA-3267-pg8g-jq86/GHSA-3267-pg8g-jq86.json index 1c175bf0680..c3d9a3b4ac6 100644 --- a/advisories/unreviewed/2022/05/GHSA-3267-pg8g-jq86/GHSA-3267-pg8g-jq86.json +++ b/advisories/unreviewed/2022/05/GHSA-3267-pg8g-jq86/GHSA-3267-pg8g-jq86.json @@ -7,12 +7,8 @@ "CVE-2021-27169" ], "details": "An issue was discovered on FiberHome AN5506-04-FA devices with firmware RP2631. There is a gepon password for the gepon account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-333m-gvxr-m7wp/GHSA-333m-gvxr-m7wp.json b/advisories/unreviewed/2022/05/GHSA-333m-gvxr-m7wp/GHSA-333m-gvxr-m7wp.json index f9a0a51be81..2e5a131c8c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-333m-gvxr-m7wp/GHSA-333m-gvxr-m7wp.json +++ b/advisories/unreviewed/2022/05/GHSA-333m-gvxr-m7wp/GHSA-333m-gvxr-m7wp.json @@ -7,12 +7,8 @@ "CVE-2021-26573" ], "details": "The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgeneratesslcfg function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-343m-7rjc-p5gc/GHSA-343m-7rjc-p5gc.json b/advisories/unreviewed/2022/05/GHSA-343m-7rjc-p5gc/GHSA-343m-7rjc-p5gc.json index 8b42708a9d5..7029e5546f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-343m-7rjc-p5gc/GHSA-343m-7rjc-p5gc.json +++ b/advisories/unreviewed/2022/05/GHSA-343m-7rjc-p5gc/GHSA-343m-7rjc-p5gc.json @@ -7,12 +7,8 @@ "CVE-2020-18750" ], "details": "Buffer overflow in pdf2json 0.69 allows local users to execute arbitrary code by converting a crafted PDF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-34p8-x6j6-mmg5/GHSA-34p8-x6j6-mmg5.json b/advisories/unreviewed/2022/05/GHSA-34p8-x6j6-mmg5/GHSA-34p8-x6j6-mmg5.json index e53562ff686..13d6b77df55 100644 --- a/advisories/unreviewed/2022/05/GHSA-34p8-x6j6-mmg5/GHSA-34p8-x6j6-mmg5.json +++ b/advisories/unreviewed/2022/05/GHSA-34p8-x6j6-mmg5/GHSA-34p8-x6j6-mmg5.json @@ -7,12 +7,8 @@ "CVE-2021-22305" ], "details": "There is a buffer overflow vulnerability in Mate 30 10.1.0.126(C00E125R5P3). A module does not verify the some input when dealing with messages. Attackers can exploit this vulnerability by sending malicious input through specific module. This could cause buffer overflow, compromising normal service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-34v3-f2p3-76vj/GHSA-34v3-f2p3-76vj.json b/advisories/unreviewed/2022/05/GHSA-34v3-f2p3-76vj/GHSA-34v3-f2p3-76vj.json index 45459a30529..0dcc4bf16d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-34v3-f2p3-76vj/GHSA-34v3-f2p3-76vj.json +++ b/advisories/unreviewed/2022/05/GHSA-34v3-f2p3-76vj/GHSA-34v3-f2p3-76vj.json @@ -7,12 +7,8 @@ "CVE-2021-26912" ], "details": "NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in SupportRpcServlet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3645-fcrm-r5v6/GHSA-3645-fcrm-r5v6.json b/advisories/unreviewed/2022/05/GHSA-3645-fcrm-r5v6/GHSA-3645-fcrm-r5v6.json index 499d00f3b65..990721d6140 100644 --- a/advisories/unreviewed/2022/05/GHSA-3645-fcrm-r5v6/GHSA-3645-fcrm-r5v6.json +++ b/advisories/unreviewed/2022/05/GHSA-3645-fcrm-r5v6/GHSA-3645-fcrm-r5v6.json @@ -7,12 +7,8 @@ "CVE-2020-35765" ], "details": "doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-374q-g769-jjp8/GHSA-374q-g769-jjp8.json b/advisories/unreviewed/2022/05/GHSA-374q-g769-jjp8/GHSA-374q-g769-jjp8.json index 57c26b56f7f..ec7a62b9db1 100644 --- a/advisories/unreviewed/2022/05/GHSA-374q-g769-jjp8/GHSA-374q-g769-jjp8.json +++ b/advisories/unreviewed/2022/05/GHSA-374q-g769-jjp8/GHSA-374q-g769-jjp8.json @@ -7,12 +7,8 @@ "CVE-2021-1268" ], "details": "A vulnerability in the IPv6 protocol handling of the management interfaces of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause an IPv6 flood on the management interface network of an affected device. The vulnerability exists because the software incorrectly forwards IPv6 packets that have an IPv6 node-local multicast group address destination and are received on the management interfaces. An attacker could exploit this vulnerability by connecting to the same network as the management interfaces and injecting IPv6 packets that have an IPv6 node-local multicast group address destination. A successful exploit could allow the attacker to cause an IPv6 flood on the corresponding network. Depending on the number of Cisco IOS XR Software nodes on that network segment, exploitation could cause excessive network traffic, resulting in network degradation or a denial of service (DoS) condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-377v-3m99-jhrj/GHSA-377v-3m99-jhrj.json b/advisories/unreviewed/2022/05/GHSA-377v-3m99-jhrj/GHSA-377v-3m99-jhrj.json index f6b716279d3..ac5d6e24a0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-377v-3m99-jhrj/GHSA-377v-3m99-jhrj.json +++ b/advisories/unreviewed/2022/05/GHSA-377v-3m99-jhrj/GHSA-377v-3m99-jhrj.json @@ -7,12 +7,8 @@ "CVE-2020-13117" ], "details": "Wavlink WN575A4 and WN579X3 devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-38pq-5c2r-6qhj/GHSA-38pq-5c2r-6qhj.json b/advisories/unreviewed/2022/05/GHSA-38pq-5c2r-6qhj/GHSA-38pq-5c2r-6qhj.json index e4673b680b5..9c5b67653dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-38pq-5c2r-6qhj/GHSA-38pq-5c2r-6qhj.json +++ b/advisories/unreviewed/2022/05/GHSA-38pq-5c2r-6qhj/GHSA-38pq-5c2r-6qhj.json @@ -7,12 +7,8 @@ "CVE-2021-0332" ], "details": "In bootFinished of SurfaceFlinger.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-169256435", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-39w5-xc9g-jj4c/GHSA-39w5-xc9g-jj4c.json b/advisories/unreviewed/2022/05/GHSA-39w5-xc9g-jj4c/GHSA-39w5-xc9g-jj4c.json index 58f152ad23f..1459be3a728 100644 --- a/advisories/unreviewed/2022/05/GHSA-39w5-xc9g-jj4c/GHSA-39w5-xc9g-jj4c.json +++ b/advisories/unreviewed/2022/05/GHSA-39w5-xc9g-jj4c/GHSA-39w5-xc9g-jj4c.json @@ -7,12 +7,8 @@ "CVE-2020-17423" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of ARW files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11196.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3c8w-cf3r-86mw/GHSA-3c8w-cf3r-86mw.json b/advisories/unreviewed/2022/05/GHSA-3c8w-cf3r-86mw/GHSA-3c8w-cf3r-86mw.json index 7f89f2d4499..650ba158e01 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c8w-cf3r-86mw/GHSA-3c8w-cf3r-86mw.json +++ b/advisories/unreviewed/2022/05/GHSA-3c8w-cf3r-86mw/GHSA-3c8w-cf3r-86mw.json @@ -7,12 +7,8 @@ "CVE-2020-25245" ], "details": "A vulnerability has been identified in DIGSI 4 (All versions < V4.94 SP1 HF 1). Several folders in the %PATH% are writeable by normal users. As these folders are included in the search for dlls, an attacker could place dlls there with code executed by SYSTEM.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3cqm-mf7h-prrj/GHSA-3cqm-mf7h-prrj.json b/advisories/unreviewed/2022/05/GHSA-3cqm-mf7h-prrj/GHSA-3cqm-mf7h-prrj.json index 3e5b7410d15..0c621366ce2 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cqm-mf7h-prrj/GHSA-3cqm-mf7h-prrj.json +++ b/advisories/unreviewed/2022/05/GHSA-3cqm-mf7h-prrj/GHSA-3cqm-mf7h-prrj.json @@ -7,12 +7,8 @@ "CVE-2021-0341" ], "details": "In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-171980069", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3f43-7g52-2f66/GHSA-3f43-7g52-2f66.json b/advisories/unreviewed/2022/05/GHSA-3f43-7g52-2f66/GHSA-3f43-7g52-2f66.json index 3568932c5f5..4f9d47cb6db 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f43-7g52-2f66/GHSA-3f43-7g52-2f66.json +++ b/advisories/unreviewed/2022/05/GHSA-3f43-7g52-2f66/GHSA-3f43-7g52-2f66.json @@ -7,12 +7,8 @@ "CVE-2021-25136" ], "details": "The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice setsolvideoremotestorage_func function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3f4c-grv3-wwg8/GHSA-3f4c-grv3-wwg8.json b/advisories/unreviewed/2022/05/GHSA-3f4c-grv3-wwg8/GHSA-3f4c-grv3-wwg8.json index 83bb765dc6e..a4e8d8a18fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f4c-grv3-wwg8/GHSA-3f4c-grv3-wwg8.json +++ b/advisories/unreviewed/2022/05/GHSA-3f4c-grv3-wwg8/GHSA-3f4c-grv3-wwg8.json @@ -7,12 +7,8 @@ "CVE-2020-28645" ], "details": "Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the data directory in the web root. This affects ownCloud/core versions < 10.6.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3g7h-g298-pwxf/GHSA-3g7h-g298-pwxf.json b/advisories/unreviewed/2022/05/GHSA-3g7h-g298-pwxf/GHSA-3g7h-g298-pwxf.json index 4e8025249d4..b03645ef7e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-3g7h-g298-pwxf/GHSA-3g7h-g298-pwxf.json +++ b/advisories/unreviewed/2022/05/GHSA-3g7h-g298-pwxf/GHSA-3g7h-g298-pwxf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3gc8-mch5-55gq/GHSA-3gc8-mch5-55gq.json b/advisories/unreviewed/2022/05/GHSA-3gc8-mch5-55gq/GHSA-3gc8-mch5-55gq.json index bf30bc61c82..f3c03d2b382 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gc8-mch5-55gq/GHSA-3gc8-mch5-55gq.json +++ b/advisories/unreviewed/2022/05/GHSA-3gc8-mch5-55gq/GHSA-3gc8-mch5-55gq.json @@ -7,12 +7,8 @@ "CVE-2020-20295" ], "details": "An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3grx-q7gc-c986/GHSA-3grx-q7gc-c986.json b/advisories/unreviewed/2022/05/GHSA-3grx-q7gc-c986/GHSA-3grx-q7gc-c986.json index b614d2aa1a5..9787b111139 100644 --- a/advisories/unreviewed/2022/05/GHSA-3grx-q7gc-c986/GHSA-3grx-q7gc-c986.json +++ b/advisories/unreviewed/2022/05/GHSA-3grx-q7gc-c986/GHSA-3grx-q7gc-c986.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3gx6-9g98-g4w5/GHSA-3gx6-9g98-g4w5.json b/advisories/unreviewed/2022/05/GHSA-3gx6-9g98-g4w5/GHSA-3gx6-9g98-g4w5.json index 6cbdc1638d9..8c25c5f2925 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gx6-9g98-g4w5/GHSA-3gx6-9g98-g4w5.json +++ b/advisories/unreviewed/2022/05/GHSA-3gx6-9g98-g4w5/GHSA-3gx6-9g98-g4w5.json @@ -7,12 +7,8 @@ "CVE-2020-16044" ], "details": "Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3hfm-p6g2-9fv7/GHSA-3hfm-p6g2-9fv7.json b/advisories/unreviewed/2022/05/GHSA-3hfm-p6g2-9fv7/GHSA-3hfm-p6g2-9fv7.json index c6a0fd11254..8e998c63971 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hfm-p6g2-9fv7/GHSA-3hfm-p6g2-9fv7.json +++ b/advisories/unreviewed/2022/05/GHSA-3hfm-p6g2-9fv7/GHSA-3hfm-p6g2-9fv7.json @@ -7,12 +7,8 @@ "CVE-2020-8029" ], "details": "A Incorrect Permission Assignment for Critical Resource vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to gain access to the kublet key. This issue affects: SUSE CaaS Platform 4.5 skuba versions prior to https://github.com/SUSE/skuba/pull/1416.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3j62-674q-3jr2/GHSA-3j62-674q-3jr2.json b/advisories/unreviewed/2022/05/GHSA-3j62-674q-3jr2/GHSA-3j62-674q-3jr2.json index da15b2a0cf2..429b64c7eea 100644 --- a/advisories/unreviewed/2022/05/GHSA-3j62-674q-3jr2/GHSA-3j62-674q-3jr2.json +++ b/advisories/unreviewed/2022/05/GHSA-3j62-674q-3jr2/GHSA-3j62-674q-3jr2.json @@ -7,12 +7,8 @@ "CVE-2021-26576" ], "details": "The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so uploadsshkey function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3jxg-43fv-33j7/GHSA-3jxg-43fv-33j7.json b/advisories/unreviewed/2022/05/GHSA-3jxg-43fv-33j7/GHSA-3jxg-43fv-33j7.json index b798fe122f4..5f84748a56e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jxg-43fv-33j7/GHSA-3jxg-43fv-33j7.json +++ b/advisories/unreviewed/2022/05/GHSA-3jxg-43fv-33j7/GHSA-3jxg-43fv-33j7.json @@ -7,12 +7,8 @@ "CVE-2021-1337" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mch-rrc9-vx6v/GHSA-3mch-rrc9-vx6v.json b/advisories/unreviewed/2022/05/GHSA-3mch-rrc9-vx6v/GHSA-3mch-rrc9-vx6v.json index 711546f40a7..8a77cd1f3a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mch-rrc9-vx6v/GHSA-3mch-rrc9-vx6v.json +++ b/advisories/unreviewed/2022/05/GHSA-3mch-rrc9-vx6v/GHSA-3mch-rrc9-vx6v.json @@ -7,12 +7,8 @@ "CVE-2021-1334" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mxg-74vr-rhx5/GHSA-3mxg-74vr-rhx5.json b/advisories/unreviewed/2022/05/GHSA-3mxg-74vr-rhx5/GHSA-3mxg-74vr-rhx5.json index dbc19df0a5b..e7d98e24814 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mxg-74vr-rhx5/GHSA-3mxg-74vr-rhx5.json +++ b/advisories/unreviewed/2022/05/GHSA-3mxg-74vr-rhx5/GHSA-3mxg-74vr-rhx5.json @@ -7,12 +7,8 @@ "CVE-2020-8672" ], "details": "Out of bound read in BIOS firmware for 8th, 9th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 Series Processors may allow an unauthenticated user to potentially enable elevation of privilege or denial of service via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3pr9-7mjx-7r2v/GHSA-3pr9-7mjx-7r2v.json b/advisories/unreviewed/2022/05/GHSA-3pr9-7mjx-7r2v/GHSA-3pr9-7mjx-7r2v.json index 3c2440bf543..4254c588828 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pr9-7mjx-7r2v/GHSA-3pr9-7mjx-7r2v.json +++ b/advisories/unreviewed/2022/05/GHSA-3pr9-7mjx-7r2v/GHSA-3pr9-7mjx-7r2v.json @@ -7,12 +7,8 @@ "CVE-2021-0351" ], "details": "In wlan driver, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05412917.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3qgh-vv5w-v35w/GHSA-3qgh-vv5w-v35w.json b/advisories/unreviewed/2022/05/GHSA-3qgh-vv5w-v35w/GHSA-3qgh-vv5w-v35w.json index 44acf508f9b..6605df1ad91 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qgh-vv5w-v35w/GHSA-3qgh-vv5w-v35w.json +++ b/advisories/unreviewed/2022/05/GHSA-3qgh-vv5w-v35w/GHSA-3qgh-vv5w-v35w.json @@ -7,12 +7,8 @@ "CVE-2020-25035" ], "details": "UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with root privileges using chroothole_client's PHP call, a related issue to CVE-2017-11322.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3qr2-pmfh-6mrh/GHSA-3qr2-pmfh-6mrh.json b/advisories/unreviewed/2022/05/GHSA-3qr2-pmfh-6mrh/GHSA-3qr2-pmfh-6mrh.json index dd465153af8..df7967a0865 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qr2-pmfh-6mrh/GHSA-3qr2-pmfh-6mrh.json +++ b/advisories/unreviewed/2022/05/GHSA-3qr2-pmfh-6mrh/GHSA-3qr2-pmfh-6mrh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3v34-4mg9-5rvc/GHSA-3v34-4mg9-5rvc.json b/advisories/unreviewed/2022/05/GHSA-3v34-4mg9-5rvc/GHSA-3v34-4mg9-5rvc.json index 9acfbe966df..822a43c839a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3v34-4mg9-5rvc/GHSA-3v34-4mg9-5rvc.json +++ b/advisories/unreviewed/2022/05/GHSA-3v34-4mg9-5rvc/GHSA-3v34-4mg9-5rvc.json @@ -7,12 +7,8 @@ "CVE-2021-1322" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3v75-r9p2-79hc/GHSA-3v75-r9p2-79hc.json b/advisories/unreviewed/2022/05/GHSA-3v75-r9p2-79hc/GHSA-3v75-r9p2-79hc.json index 9354f53757c..ca38a705502 100644 --- a/advisories/unreviewed/2022/05/GHSA-3v75-r9p2-79hc/GHSA-3v75-r9p2-79hc.json +++ b/advisories/unreviewed/2022/05/GHSA-3v75-r9p2-79hc/GHSA-3v75-r9p2-79hc.json @@ -7,12 +7,8 @@ "CVE-2021-0350" ], "details": "In ged, there is a possible system crash due to an improper input validation. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05342338.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3w29-4qp5-cwmc/GHSA-3w29-4qp5-cwmc.json b/advisories/unreviewed/2022/05/GHSA-3w29-4qp5-cwmc/GHSA-3w29-4qp5-cwmc.json index 669a452aa52..f72d4a29042 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w29-4qp5-cwmc/GHSA-3w29-4qp5-cwmc.json +++ b/advisories/unreviewed/2022/05/GHSA-3w29-4qp5-cwmc/GHSA-3w29-4qp5-cwmc.json @@ -7,12 +7,8 @@ "CVE-2021-21122" ], "details": "Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3xq9-pprq-hm99/GHSA-3xq9-pprq-hm99.json b/advisories/unreviewed/2022/05/GHSA-3xq9-pprq-hm99/GHSA-3xq9-pprq-hm99.json index cee50deb200..0e6a2feba2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xq9-pprq-hm99/GHSA-3xq9-pprq-hm99.json +++ b/advisories/unreviewed/2022/05/GHSA-3xq9-pprq-hm99/GHSA-3xq9-pprq-hm99.json @@ -7,12 +7,8 @@ "CVE-2020-25237" ], "details": "A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1 Update 1), SINEMA Server (All versions < V14.0 SP2 Update 2). When uploading files to an affected system using a zip container, the system does not correctly check if the relative file path of the extracted files is still within the intended target directory. With this an attacker could create or overwrite arbitrary files on an affected system. This type of vulnerability is also known as 'Zip-Slip'. (ZDI-CAN-12054)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-43rc-rp87-3q62/GHSA-43rc-rp87-3q62.json b/advisories/unreviewed/2022/05/GHSA-43rc-rp87-3q62/GHSA-43rc-rp87-3q62.json index c836e2c254e..e4aaf18c18b 100644 --- a/advisories/unreviewed/2022/05/GHSA-43rc-rp87-3q62/GHSA-43rc-rp87-3q62.json +++ b/advisories/unreviewed/2022/05/GHSA-43rc-rp87-3q62/GHSA-43rc-rp87-3q62.json @@ -7,12 +7,8 @@ "CVE-2021-1339" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-462j-78vj-jjpr/GHSA-462j-78vj-jjpr.json b/advisories/unreviewed/2022/05/GHSA-462j-78vj-jjpr/GHSA-462j-78vj-jjpr.json index ba27c2b035e..a05b979f50d 100644 --- a/advisories/unreviewed/2022/05/GHSA-462j-78vj-jjpr/GHSA-462j-78vj-jjpr.json +++ b/advisories/unreviewed/2022/05/GHSA-462j-78vj-jjpr/GHSA-462j-78vj-jjpr.json @@ -7,12 +7,8 @@ "CVE-2021-25666" ], "details": "A vulnerability has been identified in SCALANCE W780 and W740 (IEEE 802.11n) family (All versions < V6.3). Sending specially crafted packets through the ARP protocol to an affected device could cause a partial denial-of-service, preventing the device to operate normally for a short period of time.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-46ch-m2h6-h4rg/GHSA-46ch-m2h6-h4rg.json b/advisories/unreviewed/2022/05/GHSA-46ch-m2h6-h4rg/GHSA-46ch-m2h6-h4rg.json index 25327e9aa7a..fcc3f061c2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-46ch-m2h6-h4rg/GHSA-46ch-m2h6-h4rg.json +++ b/advisories/unreviewed/2022/05/GHSA-46ch-m2h6-h4rg/GHSA-46ch-m2h6-h4rg.json @@ -7,12 +7,8 @@ "CVE-2021-3395" ], "details": "A cross-site scripting (XSS) vulnerability in Pryaniki 6.44.3 allows remote authenticated users to upload an arbitrary file. The JavaScript code will execute when someone visits the attachment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4gwr-3v6m-22jj/GHSA-4gwr-3v6m-22jj.json b/advisories/unreviewed/2022/05/GHSA-4gwr-3v6m-22jj/GHSA-4gwr-3v6m-22jj.json index 37bf05df2ba..ac8139c784d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gwr-3v6m-22jj/GHSA-4gwr-3v6m-22jj.json +++ b/advisories/unreviewed/2022/05/GHSA-4gwr-3v6m-22jj/GHSA-4gwr-3v6m-22jj.json @@ -7,12 +7,8 @@ "CVE-2020-35667" ], "details": "JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4h45-9hf5-qr48/GHSA-4h45-9hf5-qr48.json b/advisories/unreviewed/2022/05/GHSA-4h45-9hf5-qr48/GHSA-4h45-9hf5-qr48.json index cb07097fa31..323c165c2f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-4h45-9hf5-qr48/GHSA-4h45-9hf5-qr48.json +++ b/advisories/unreviewed/2022/05/GHSA-4h45-9hf5-qr48/GHSA-4h45-9hf5-qr48.json @@ -7,12 +7,8 @@ "CVE-2021-27156" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains credentials for an ISP that equal the last part of the MAC address of the br0 interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4j45-pxr4-w4g4/GHSA-4j45-pxr4-w4g4.json b/advisories/unreviewed/2022/05/GHSA-4j45-pxr4-w4g4/GHSA-4j45-pxr4-w4g4.json index b83d2b17167..8a88dece2e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-4j45-pxr4-w4g4/GHSA-4j45-pxr4-w4g4.json +++ b/advisories/unreviewed/2022/05/GHSA-4j45-pxr4-w4g4/GHSA-4j45-pxr4-w4g4.json @@ -7,12 +7,8 @@ "CVE-2020-4640" ], "details": "Certain IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 configurations can result in sensitive information in the URL fragment identifiers. This information can be cached in the intermediate nodes like proxy servers, cdn, logging platforms, etc. An attacker can make use of this information to perform attacks by impersonating a user. IBM X-Force ID: 185510.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4j5c-2m58-55rj/GHSA-4j5c-2m58-55rj.json b/advisories/unreviewed/2022/05/GHSA-4j5c-2m58-55rj/GHSA-4j5c-2m58-55rj.json index 388a4322816..7d3f86f29d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-4j5c-2m58-55rj/GHSA-4j5c-2m58-55rj.json +++ b/advisories/unreviewed/2022/05/GHSA-4j5c-2m58-55rj/GHSA-4j5c-2m58-55rj.json @@ -7,12 +7,8 @@ "CVE-2021-25172" ], "details": "The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so websetdefaultlangcfg function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4jwv-8x37-cg8x/GHSA-4jwv-8x37-cg8x.json b/advisories/unreviewed/2022/05/GHSA-4jwv-8x37-cg8x/GHSA-4jwv-8x37-cg8x.json index 82ff9bf7ebb..136bcb77078 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jwv-8x37-cg8x/GHSA-4jwv-8x37-cg8x.json +++ b/advisories/unreviewed/2022/05/GHSA-4jwv-8x37-cg8x/GHSA-4jwv-8x37-cg8x.json @@ -7,12 +7,8 @@ "CVE-2020-13460" ], "details": "Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to R20-2 GA.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4qgw-rh8c-x346/GHSA-4qgw-rh8c-x346.json b/advisories/unreviewed/2022/05/GHSA-4qgw-rh8c-x346/GHSA-4qgw-rh8c-x346.json index 5eae95bdf41..fb42c8eb901 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qgw-rh8c-x346/GHSA-4qgw-rh8c-x346.json +++ b/advisories/unreviewed/2022/05/GHSA-4qgw-rh8c-x346/GHSA-4qgw-rh8c-x346.json @@ -7,12 +7,8 @@ "CVE-2021-3298" ], "details": "Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4rm9-2w34-7q9c/GHSA-4rm9-2w34-7q9c.json b/advisories/unreviewed/2022/05/GHSA-4rm9-2w34-7q9c/GHSA-4rm9-2w34-7q9c.json index b4e8002932e..40df03df8cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rm9-2w34-7q9c/GHSA-4rm9-2w34-7q9c.json +++ b/advisories/unreviewed/2022/05/GHSA-4rm9-2w34-7q9c/GHSA-4rm9-2w34-7q9c.json @@ -7,12 +7,8 @@ "CVE-2021-26959" ], "details": "An issue was discovered in the hyper crate before 0.13.10 and 0.14.x before 0.14.3 for Rust. Request smuggling can occur when more than one Transfer-Encoding header is sent.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4rqr-r9fv-8h9h/GHSA-4rqr-r9fv-8h9h.json b/advisories/unreviewed/2022/05/GHSA-4rqr-r9fv-8h9h/GHSA-4rqr-r9fv-8h9h.json index 632820d521b..e301bef9932 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rqr-r9fv-8h9h/GHSA-4rqr-r9fv-8h9h.json +++ b/advisories/unreviewed/2022/05/GHSA-4rqr-r9fv-8h9h/GHSA-4rqr-r9fv-8h9h.json @@ -7,12 +7,8 @@ "CVE-2020-35481" ], "details": "SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vj5-f3fw-frfg/GHSA-4vj5-f3fw-frfg.json b/advisories/unreviewed/2022/05/GHSA-4vj5-f3fw-frfg/GHSA-4vj5-f3fw-frfg.json index 4c5cf5b4827..630cd151f6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vj5-f3fw-frfg/GHSA-4vj5-f3fw-frfg.json +++ b/advisories/unreviewed/2022/05/GHSA-4vj5-f3fw-frfg/GHSA-4vj5-f3fw-frfg.json @@ -7,12 +7,8 @@ "CVE-2021-26710" ], "details": "A cross-site scripting (XSS) issue in the login panel in Redwood Report2Web 4.3.4.5 and 4.5.3 allows remote attackers to inject JavaScript via the signIn.do urll parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4w3j-8fcj-qpw3/GHSA-4w3j-8fcj-qpw3.json b/advisories/unreviewed/2022/05/GHSA-4w3j-8fcj-qpw3/GHSA-4w3j-8fcj-qpw3.json index aaefdecd698..62343aee2ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w3j-8fcj-qpw3/GHSA-4w3j-8fcj-qpw3.json +++ b/advisories/unreviewed/2022/05/GHSA-4w3j-8fcj-qpw3/GHSA-4w3j-8fcj-qpw3.json @@ -7,12 +7,8 @@ "CVE-2021-26570" ], "details": "The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webifc_setadconfig function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4whm-cvqv-v84q/GHSA-4whm-cvqv-v84q.json b/advisories/unreviewed/2022/05/GHSA-4whm-cvqv-v84q/GHSA-4whm-cvqv-v84q.json index 50b1d26befc..aead0f231ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-4whm-cvqv-v84q/GHSA-4whm-cvqv-v84q.json +++ b/advisories/unreviewed/2022/05/GHSA-4whm-cvqv-v84q/GHSA-4whm-cvqv-v84q.json @@ -7,12 +7,8 @@ "CVE-2021-1244" ], "details": "Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local attacker to execute unsigned code during the boot process on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4wpc-25h6-9fv9/GHSA-4wpc-25h6-9fv9.json b/advisories/unreviewed/2022/05/GHSA-4wpc-25h6-9fv9/GHSA-4wpc-25h6-9fv9.json index 355398fd6d3..e234a16402a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wpc-25h6-9fv9/GHSA-4wpc-25h6-9fv9.json +++ b/advisories/unreviewed/2022/05/GHSA-4wpc-25h6-9fv9/GHSA-4wpc-25h6-9fv9.json @@ -7,12 +7,8 @@ "CVE-2020-27259" ], "details": "The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker to remotely execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4wv8-p854-pjqv/GHSA-4wv8-p854-pjqv.json b/advisories/unreviewed/2022/05/GHSA-4wv8-p854-pjqv/GHSA-4wv8-p854-pjqv.json index 3df4cc59f21..b624aaaf51a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wv8-p854-pjqv/GHSA-4wv8-p854-pjqv.json +++ b/advisories/unreviewed/2022/05/GHSA-4wv8-p854-pjqv/GHSA-4wv8-p854-pjqv.json @@ -7,12 +7,8 @@ "CVE-2021-0326" ], "details": "In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-172937525", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4x35-7764-9cfw/GHSA-4x35-7764-9cfw.json b/advisories/unreviewed/2022/05/GHSA-4x35-7764-9cfw/GHSA-4x35-7764-9cfw.json index 626831a79cb..271ae78c0b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x35-7764-9cfw/GHSA-4x35-7764-9cfw.json +++ b/advisories/unreviewed/2022/05/GHSA-4x35-7764-9cfw/GHSA-4x35-7764-9cfw.json @@ -7,12 +7,8 @@ "CVE-2020-25037" ], "details": "UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with admin user privileges via an escape from a restricted command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4x8r-m22r-9c3q/GHSA-4x8r-m22r-9c3q.json b/advisories/unreviewed/2022/05/GHSA-4x8r-m22r-9c3q/GHSA-4x8r-m22r-9c3q.json index de141cb7bdb..e93daa1987a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x8r-m22r-9c3q/GHSA-4x8r-m22r-9c3q.json +++ b/advisories/unreviewed/2022/05/GHSA-4x8r-m22r-9c3q/GHSA-4x8r-m22r-9c3q.json @@ -7,12 +7,8 @@ "CVE-2021-21136" ], "details": "Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-52j7-8765-3p92/GHSA-52j7-8765-3p92.json b/advisories/unreviewed/2022/05/GHSA-52j7-8765-3p92/GHSA-52j7-8765-3p92.json index 16600ee6f51..d2354c5ca41 100644 --- a/advisories/unreviewed/2022/05/GHSA-52j7-8765-3p92/GHSA-52j7-8765-3p92.json +++ b/advisories/unreviewed/2022/05/GHSA-52j7-8765-3p92/GHSA-52j7-8765-3p92.json @@ -7,12 +7,8 @@ "CVE-2021-0344" ], "details": "In mtkpower, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05437558.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-532m-87rc-7fjr/GHSA-532m-87rc-7fjr.json b/advisories/unreviewed/2022/05/GHSA-532m-87rc-7fjr/GHSA-532m-87rc-7fjr.json index 99eda953589..4c9df0ca8ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-532m-87rc-7fjr/GHSA-532m-87rc-7fjr.json +++ b/advisories/unreviewed/2022/05/GHSA-532m-87rc-7fjr/GHSA-532m-87rc-7fjr.json @@ -7,12 +7,8 @@ "CVE-2020-13860" ], "details": "An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. The one-time password algorithm for the undocumented system account mofidev generates a predictable six-digit password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53h4-8f3m-4f7g/GHSA-53h4-8f3m-4f7g.json b/advisories/unreviewed/2022/05/GHSA-53h4-8f3m-4f7g/GHSA-53h4-8f3m-4f7g.json index ab292177eb3..e9eae7188ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-53h4-8f3m-4f7g/GHSA-53h4-8f3m-4f7g.json +++ b/advisories/unreviewed/2022/05/GHSA-53h4-8f3m-4f7g/GHSA-53h4-8f3m-4f7g.json @@ -7,12 +7,8 @@ "CVE-2021-21135" ], "details": "Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-57c4-wp4f-79x5/GHSA-57c4-wp4f-79x5.json b/advisories/unreviewed/2022/05/GHSA-57c4-wp4f-79x5/GHSA-57c4-wp4f-79x5.json index 2a45cb7177b..cfb7f5c85e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-57c4-wp4f-79x5/GHSA-57c4-wp4f-79x5.json +++ b/advisories/unreviewed/2022/05/GHSA-57c4-wp4f-79x5/GHSA-57c4-wp4f-79x5.json @@ -7,12 +7,8 @@ "CVE-2021-27148" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded telecomadmin / nE7jA%5m credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-58fg-773m-4wg4/GHSA-58fg-773m-4wg4.json b/advisories/unreviewed/2022/05/GHSA-58fg-773m-4wg4/GHSA-58fg-773m-4wg4.json index 8318db87c1d..862c9b6b256 100644 --- a/advisories/unreviewed/2022/05/GHSA-58fg-773m-4wg4/GHSA-58fg-773m-4wg4.json +++ b/advisories/unreviewed/2022/05/GHSA-58fg-773m-4wg4/GHSA-58fg-773m-4wg4.json @@ -7,12 +7,8 @@ "CVE-2021-26916" ], "details": "In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary web script or HTML through the Filters/CheckDiscountCouponAttribute.cs discountcode parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-58vg-3p49-w6xp/GHSA-58vg-3p49-w6xp.json b/advisories/unreviewed/2022/05/GHSA-58vg-3p49-w6xp/GHSA-58vg-3p49-w6xp.json index 22d74600fb6..d0f2e93767d 100644 --- a/advisories/unreviewed/2022/05/GHSA-58vg-3p49-w6xp/GHSA-58vg-3p49-w6xp.json +++ b/advisories/unreviewed/2022/05/GHSA-58vg-3p49-w6xp/GHSA-58vg-3p49-w6xp.json @@ -7,12 +7,8 @@ "CVE-2020-13858" ], "details": "An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented administrator accounts. The sftp and mofidev accounts are defined in /etc/passwd and the password is not unique across installations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5c78-cfx6-pmjr/GHSA-5c78-cfx6-pmjr.json b/advisories/unreviewed/2022/05/GHSA-5c78-cfx6-pmjr/GHSA-5c78-cfx6-pmjr.json index 0e2439348e5..80baafc63d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c78-cfx6-pmjr/GHSA-5c78-cfx6-pmjr.json +++ b/advisories/unreviewed/2022/05/GHSA-5c78-cfx6-pmjr/GHSA-5c78-cfx6-pmjr.json @@ -7,12 +7,8 @@ "CVE-2020-26196" ], "details": "Dell EMC PowerScale OneFS versions 8.1.0-9.1.0 contain a Backup/Restore Privilege implementation issue. A user with the BackupAdmin role may potentially exploit this vulnerability resulting in the ability to write data outside of the intended file system location.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5fx6-f253-w3m2/GHSA-5fx6-f253-w3m2.json b/advisories/unreviewed/2022/05/GHSA-5fx6-f253-w3m2/GHSA-5fx6-f253-w3m2.json index 198cb90f217..7223f576d28 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fx6-f253-w3m2/GHSA-5fx6-f253-w3m2.json +++ b/advisories/unreviewed/2022/05/GHSA-5fx6-f253-w3m2/GHSA-5fx6-f253-w3m2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5gm6-26g2-phh5/GHSA-5gm6-26g2-phh5.json b/advisories/unreviewed/2022/05/GHSA-5gm6-26g2-phh5/GHSA-5gm6-26g2-phh5.json index 151582b5b9e..b64124649b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gm6-26g2-phh5/GHSA-5gm6-26g2-phh5.json +++ b/advisories/unreviewed/2022/05/GHSA-5gm6-26g2-phh5/GHSA-5gm6-26g2-phh5.json @@ -7,12 +7,8 @@ "CVE-2021-21134" ], "details": "Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remote attacker to spoof security UI via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5gvf-qj79-739q/GHSA-5gvf-qj79-739q.json b/advisories/unreviewed/2022/05/GHSA-5gvf-qj79-739q/GHSA-5gvf-qj79-739q.json index 074608b3b38..1b898c70041 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gvf-qj79-739q/GHSA-5gvf-qj79-739q.json +++ b/advisories/unreviewed/2022/05/GHSA-5gvf-qj79-739q/GHSA-5gvf-qj79-739q.json @@ -7,12 +7,8 @@ "CVE-2021-21436" ], "details": "Agents are able to see and link Config Items without permissions, which are defined in General Catalog. This issue affects: OTRS AG OTRSCIsInCustomerFrontend 7.0.x version 7.0.14 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5gvx-3w5q-25pr/GHSA-5gvx-3w5q-25pr.json b/advisories/unreviewed/2022/05/GHSA-5gvx-3w5q-25pr/GHSA-5gvx-3w5q-25pr.json index b5a7c94634c..523025b5bd6 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gvx-3w5q-25pr/GHSA-5gvx-3w5q-25pr.json +++ b/advisories/unreviewed/2022/05/GHSA-5gvx-3w5q-25pr/GHSA-5gvx-3w5q-25pr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5gxr-gv2r-m44r/GHSA-5gxr-gv2r-m44r.json b/advisories/unreviewed/2022/05/GHSA-5gxr-gv2r-m44r/GHSA-5gxr-gv2r-m44r.json index 6956d368d58..4cff6559598 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gxr-gv2r-m44r/GHSA-5gxr-gv2r-m44r.json +++ b/advisories/unreviewed/2022/05/GHSA-5gxr-gv2r-m44r/GHSA-5gxr-gv2r-m44r.json @@ -7,12 +7,8 @@ "CVE-2021-25124" ], "details": "The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spx_restservice deletevideo_func function path traversal vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5h52-gmwr-v7x9/GHSA-5h52-gmwr-v7x9.json b/advisories/unreviewed/2022/05/GHSA-5h52-gmwr-v7x9/GHSA-5h52-gmwr-v7x9.json index 6cf85d9b4ab..1facf720650 100644 --- a/advisories/unreviewed/2022/05/GHSA-5h52-gmwr-v7x9/GHSA-5h52-gmwr-v7x9.json +++ b/advisories/unreviewed/2022/05/GHSA-5h52-gmwr-v7x9/GHSA-5h52-gmwr-v7x9.json @@ -7,12 +7,8 @@ "CVE-2020-27856" ], "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CR2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-11434.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5h92-x9q3-8crw/GHSA-5h92-x9q3-8crw.json b/advisories/unreviewed/2022/05/GHSA-5h92-x9q3-8crw/GHSA-5h92-x9q3-8crw.json index bebc9c37a06..58b4f9d9721 100644 --- a/advisories/unreviewed/2022/05/GHSA-5h92-x9q3-8crw/GHSA-5h92-x9q3-8crw.json +++ b/advisories/unreviewed/2022/05/GHSA-5h92-x9q3-8crw/GHSA-5h92-x9q3-8crw.json @@ -7,12 +7,8 @@ "CVE-2021-25137" ], "details": "The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice startflash_func function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jqg-4r55-wmrg/GHSA-5jqg-4r55-wmrg.json b/advisories/unreviewed/2022/05/GHSA-5jqg-4r55-wmrg/GHSA-5jqg-4r55-wmrg.json index 823a00ce1c6..4603e87edfc 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jqg-4r55-wmrg/GHSA-5jqg-4r55-wmrg.json +++ b/advisories/unreviewed/2022/05/GHSA-5jqg-4r55-wmrg/GHSA-5jqg-4r55-wmrg.json @@ -7,12 +7,8 @@ "CVE-2021-27155" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 3UJUh2VemEfUtesEchEC2d2e credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jwx-hvg3-jjjv/GHSA-5jwx-hvg3-jjjv.json b/advisories/unreviewed/2022/05/GHSA-5jwx-hvg3-jjjv/GHSA-5jwx-hvg3-jjjv.json index 0de7d2a49a9..84484f2e977 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jwx-hvg3-jjjv/GHSA-5jwx-hvg3-jjjv.json +++ b/advisories/unreviewed/2022/05/GHSA-5jwx-hvg3-jjjv/GHSA-5jwx-hvg3-jjjv.json @@ -7,12 +7,8 @@ "CVE-2020-35652" ], "details": "An issue was discovered in res_pjsip_diversion.c in Sangoma Asterisk before 13.38.0, 14.x through 16.x before 16.15.0, 17.x before 17.9.0, and 18.x before 18.1.0. A crash can occur when a SIP message is received with a History-Info header that contains a tel-uri, or when a SIP 181 response is received that contains a tel-uri in the Diversion header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5q4j-m9xf-3h9q/GHSA-5q4j-m9xf-3h9q.json b/advisories/unreviewed/2022/05/GHSA-5q4j-m9xf-3h9q/GHSA-5q4j-m9xf-3h9q.json index 4ba101f4e54..a6c01c1a6e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-5q4j-m9xf-3h9q/GHSA-5q4j-m9xf-3h9q.json +++ b/advisories/unreviewed/2022/05/GHSA-5q4j-m9xf-3h9q/GHSA-5q4j-m9xf-3h9q.json @@ -7,12 +7,8 @@ "CVE-2020-10537" ], "details": "An issue was discovered in Epikur before 20.1.1. A Glassfish 4.1 server with a default configuration is running on TCP port 4848. No password is required to access it with the administrator account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5qwm-rcv7-qqcf/GHSA-5qwm-rcv7-qqcf.json b/advisories/unreviewed/2022/05/GHSA-5qwm-rcv7-qqcf/GHSA-5qwm-rcv7-qqcf.json index e4ba2dcb79f..8d346996f06 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qwm-rcv7-qqcf/GHSA-5qwm-rcv7-qqcf.json +++ b/advisories/unreviewed/2022/05/GHSA-5qwm-rcv7-qqcf/GHSA-5qwm-rcv7-qqcf.json @@ -7,12 +7,8 @@ "CVE-2021-27147" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / admin credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5v3r-grx9-p339/GHSA-5v3r-grx9-p339.json b/advisories/unreviewed/2022/05/GHSA-5v3r-grx9-p339/GHSA-5v3r-grx9-p339.json index 8220e236542..08254ab7c33 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v3r-grx9-p339/GHSA-5v3r-grx9-p339.json +++ b/advisories/unreviewed/2022/05/GHSA-5v3r-grx9-p339/GHSA-5v3r-grx9-p339.json @@ -7,12 +7,8 @@ "CVE-2020-4934" ], "details": "IBM Content Navigator 3.0.CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing \"dot dot\" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 191752.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5w8c-rf58-5848/GHSA-5w8c-rf58-5848.json b/advisories/unreviewed/2022/05/GHSA-5w8c-rf58-5848/GHSA-5w8c-rf58-5848.json index d8d972bd19f..b29773d4e5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w8c-rf58-5848/GHSA-5w8c-rf58-5848.json +++ b/advisories/unreviewed/2022/05/GHSA-5w8c-rf58-5848/GHSA-5w8c-rf58-5848.json @@ -7,12 +7,8 @@ "CVE-2021-1329" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5wf6-65f3-xqcr/GHSA-5wf6-65f3-xqcr.json b/advisories/unreviewed/2022/05/GHSA-5wf6-65f3-xqcr/GHSA-5wf6-65f3-xqcr.json index e6a17a87e0d..d987f883de2 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wf6-65f3-xqcr/GHSA-5wf6-65f3-xqcr.json +++ b/advisories/unreviewed/2022/05/GHSA-5wf6-65f3-xqcr/GHSA-5wf6-65f3-xqcr.json @@ -7,12 +7,8 @@ "CVE-2020-4832" ], "details": "IBM PowerHA 7.2 could allow a local attacker to obtain sensitive information from temporary directories after a discovery failure occurs. IBM X-Force ID: 189969.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5wmw-m5w7-7m5m/GHSA-5wmw-m5w7-7m5m.json b/advisories/unreviewed/2022/05/GHSA-5wmw-m5w7-7m5m/GHSA-5wmw-m5w7-7m5m.json index 0ceade49ffe..1bc069c2130 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wmw-m5w7-7m5m/GHSA-5wmw-m5w7-7m5m.json +++ b/advisories/unreviewed/2022/05/GHSA-5wmw-m5w7-7m5m/GHSA-5wmw-m5w7-7m5m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5wq8-r82h-2qqc/GHSA-5wq8-r82h-2qqc.json b/advisories/unreviewed/2022/05/GHSA-5wq8-r82h-2qqc/GHSA-5wq8-r82h-2qqc.json index bce5e8439c1..65e9f65a54a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wq8-r82h-2qqc/GHSA-5wq8-r82h-2qqc.json +++ b/advisories/unreviewed/2022/05/GHSA-5wq8-r82h-2qqc/GHSA-5wq8-r82h-2qqc.json @@ -7,12 +7,8 @@ "CVE-2021-22300" ], "details": "There is an information leak vulnerability in eCNS280_TD versions V100R005C00 and V100R005C10. A command does not have timeout exit mechanism. Temporary file contains sensitive information. This allows attackers to obtain information by inter-process access that requires other methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5x49-f55r-f2xh/GHSA-5x49-f55r-f2xh.json b/advisories/unreviewed/2022/05/GHSA-5x49-f55r-f2xh/GHSA-5x49-f55r-f2xh.json index 9a34d94f517..c842ee77877 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x49-f55r-f2xh/GHSA-5x49-f55r-f2xh.json +++ b/advisories/unreviewed/2022/05/GHSA-5x49-f55r-f2xh/GHSA-5x49-f55r-f2xh.json @@ -7,12 +7,8 @@ "CVE-2020-27261" ], "details": "The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-63m6-f6rf-rv75/GHSA-63m6-f6rf-rv75.json b/advisories/unreviewed/2022/05/GHSA-63m6-f6rf-rv75/GHSA-63m6-f6rf-rv75.json index c71f82ab03f..085d2d2fd4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-63m6-f6rf-rv75/GHSA-63m6-f6rf-rv75.json +++ b/advisories/unreviewed/2022/05/GHSA-63m6-f6rf-rv75/GHSA-63m6-f6rf-rv75.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-65gq-4xqv-wqf4/GHSA-65gq-4xqv-wqf4.json b/advisories/unreviewed/2022/05/GHSA-65gq-4xqv-wqf4/GHSA-65gq-4xqv-wqf4.json index 545fb0bc0df..346e0945dab 100644 --- a/advisories/unreviewed/2022/05/GHSA-65gq-4xqv-wqf4/GHSA-65gq-4xqv-wqf4.json +++ b/advisories/unreviewed/2022/05/GHSA-65gq-4xqv-wqf4/GHSA-65gq-4xqv-wqf4.json @@ -7,12 +7,8 @@ "CVE-2020-4791" ], "details": "IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to obtain sensitive information using main in the middle attacks due to improper certificate validation. IBM X-Force ID: 189379.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-65mr-xqpw-r9xg/GHSA-65mr-xqpw-r9xg.json b/advisories/unreviewed/2022/05/GHSA-65mr-xqpw-r9xg/GHSA-65mr-xqpw-r9xg.json index a9a058fde21..1b567d80101 100644 --- a/advisories/unreviewed/2022/05/GHSA-65mr-xqpw-r9xg/GHSA-65mr-xqpw-r9xg.json +++ b/advisories/unreviewed/2022/05/GHSA-65mr-xqpw-r9xg/GHSA-65mr-xqpw-r9xg.json @@ -7,12 +7,8 @@ "CVE-2021-20359" ], "details": "IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 - Business Automation Application Designer Component stores potentially sensitive information in log files that could be obtained by an unauthorized user. IBM X-Force ID: 194966.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-66g6-j5w9-xwv2/GHSA-66g6-j5w9-xwv2.json b/advisories/unreviewed/2022/05/GHSA-66g6-j5w9-xwv2/GHSA-66g6-j5w9-xwv2.json index 90c9f724bd2..59be7d00314 100644 --- a/advisories/unreviewed/2022/05/GHSA-66g6-j5w9-xwv2/GHSA-66g6-j5w9-xwv2.json +++ b/advisories/unreviewed/2022/05/GHSA-66g6-j5w9-xwv2/GHSA-66g6-j5w9-xwv2.json @@ -7,12 +7,8 @@ "CVE-2021-26936" ], "details": "The replay-sorcery program in ReplaySorcery 0.4.0 through 0.5.0, when using the default setuid-root configuration, allows a local attacker to escalate privileges to root by specifying video output paths in privileged locations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-679f-x4g5-488c/GHSA-679f-x4g5-488c.json b/advisories/unreviewed/2022/05/GHSA-679f-x4g5-488c/GHSA-679f-x4g5-488c.json index f38756c464a..79db8a1697b 100644 --- a/advisories/unreviewed/2022/05/GHSA-679f-x4g5-488c/GHSA-679f-x4g5-488c.json +++ b/advisories/unreviewed/2022/05/GHSA-679f-x4g5-488c/GHSA-679f-x4g5-488c.json @@ -7,12 +7,8 @@ "CVE-2021-1295" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These vulnerabilities exist because HTTP requests are not properly validated. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to remotely execute arbitrary code on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67j3-q5rv-5gjr/GHSA-67j3-q5rv-5gjr.json b/advisories/unreviewed/2022/05/GHSA-67j3-q5rv-5gjr/GHSA-67j3-q5rv-5gjr.json index 6ff4eab7ebc..f65c0f49c02 100644 --- a/advisories/unreviewed/2022/05/GHSA-67j3-q5rv-5gjr/GHSA-67j3-q5rv-5gjr.json +++ b/advisories/unreviewed/2022/05/GHSA-67j3-q5rv-5gjr/GHSA-67j3-q5rv-5gjr.json @@ -7,12 +7,8 @@ "CVE-2021-26843" ], "details": "An issue was discovered in sthttpd through 2.27.1. On systems where the strcpy function is implemented with memcpy, the de_dotdot function may cause a Denial-of-Service (daemon crash) due to overlapping memory ranges being passed to memcpy. This can triggered with an HTTP GET request for a crafted filename. NOTE: this is similar to CVE-2017-10671, but occurs in a different part of the de_dotdot function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68cg-fr87-52jj/GHSA-68cg-fr87-52jj.json b/advisories/unreviewed/2022/05/GHSA-68cg-fr87-52jj/GHSA-68cg-fr87-52jj.json index 17a3d2d931a..bb2f5c1dd05 100644 --- a/advisories/unreviewed/2022/05/GHSA-68cg-fr87-52jj/GHSA-68cg-fr87-52jj.json +++ b/advisories/unreviewed/2022/05/GHSA-68cg-fr87-52jj/GHSA-68cg-fr87-52jj.json @@ -7,12 +7,8 @@ "CVE-2021-1338" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68w8-f4j3-2jrq/GHSA-68w8-f4j3-2jrq.json b/advisories/unreviewed/2022/05/GHSA-68w8-f4j3-2jrq/GHSA-68w8-f4j3-2jrq.json index 81572110729..c2c054379eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-68w8-f4j3-2jrq/GHSA-68w8-f4j3-2jrq.json +++ b/advisories/unreviewed/2022/05/GHSA-68w8-f4j3-2jrq/GHSA-68w8-f4j3-2jrq.json @@ -7,12 +7,8 @@ "CVE-2021-1336" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6c98-7x6w-rx39/GHSA-6c98-7x6w-rx39.json b/advisories/unreviewed/2022/05/GHSA-6c98-7x6w-rx39/GHSA-6c98-7x6w-rx39.json index 5b8e18f7376..06616dfa8c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c98-7x6w-rx39/GHSA-6c98-7x6w-rx39.json +++ b/advisories/unreviewed/2022/05/GHSA-6c98-7x6w-rx39/GHSA-6c98-7x6w-rx39.json @@ -7,12 +7,8 @@ "CVE-2020-27874" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent WeChat 7.0.18. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the WXAM Decoder. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11580.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6f25-qpmr-jpgc/GHSA-6f25-qpmr-jpgc.json b/advisories/unreviewed/2022/05/GHSA-6f25-qpmr-jpgc/GHSA-6f25-qpmr-jpgc.json index 79c6749fbba..556f03803d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-6f25-qpmr-jpgc/GHSA-6f25-qpmr-jpgc.json +++ b/advisories/unreviewed/2022/05/GHSA-6f25-qpmr-jpgc/GHSA-6f25-qpmr-jpgc.json @@ -7,12 +7,8 @@ "CVE-2020-18713" ], "details": "SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in customerAction.php", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6f56-qgf6-vv2x/GHSA-6f56-qgf6-vv2x.json b/advisories/unreviewed/2022/05/GHSA-6f56-qgf6-vv2x/GHSA-6f56-qgf6-vv2x.json index b6f673e2475..38783722ae1 100644 --- a/advisories/unreviewed/2022/05/GHSA-6f56-qgf6-vv2x/GHSA-6f56-qgf6-vv2x.json +++ b/advisories/unreviewed/2022/05/GHSA-6f56-qgf6-vv2x/GHSA-6f56-qgf6-vv2x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6f5w-25p4-xq44/GHSA-6f5w-25p4-xq44.json b/advisories/unreviewed/2022/05/GHSA-6f5w-25p4-xq44/GHSA-6f5w-25p4-xq44.json index 33d22a21f8c..6926838b2c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-6f5w-25p4-xq44/GHSA-6f5w-25p4-xq44.json +++ b/advisories/unreviewed/2022/05/GHSA-6f5w-25p4-xq44/GHSA-6f5w-25p4-xq44.json @@ -7,12 +7,8 @@ "CVE-2021-1320" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6f6h-7jf2-x4vp/GHSA-6f6h-7jf2-x4vp.json b/advisories/unreviewed/2022/05/GHSA-6f6h-7jf2-x4vp/GHSA-6f6h-7jf2-x4vp.json index 2e4c1a1ed4f..0e1a669fcff 100644 --- a/advisories/unreviewed/2022/05/GHSA-6f6h-7jf2-x4vp/GHSA-6f6h-7jf2-x4vp.json +++ b/advisories/unreviewed/2022/05/GHSA-6f6h-7jf2-x4vp/GHSA-6f6h-7jf2-x4vp.json @@ -7,12 +7,8 @@ "CVE-2020-17435" ], "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CR2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-11358.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fjc-q4q2-mv97/GHSA-6fjc-q4q2-mv97.json b/advisories/unreviewed/2022/05/GHSA-6fjc-q4q2-mv97/GHSA-6fjc-q4q2-mv97.json index ffd1d55991e..297651a1ad5 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fjc-q4q2-mv97/GHSA-6fjc-q4q2-mv97.json +++ b/advisories/unreviewed/2022/05/GHSA-6fjc-q4q2-mv97/GHSA-6fjc-q4q2-mv97.json @@ -7,12 +7,8 @@ "CVE-2020-35943" ], "details": "A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fxj-c35j-cj8x/GHSA-6fxj-c35j-cj8x.json b/advisories/unreviewed/2022/05/GHSA-6fxj-c35j-cj8x/GHSA-6fxj-c35j-cj8x.json index 93c2d54a604..958233ca1d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fxj-c35j-cj8x/GHSA-6fxj-c35j-cj8x.json +++ b/advisories/unreviewed/2022/05/GHSA-6fxj-c35j-cj8x/GHSA-6fxj-c35j-cj8x.json @@ -7,12 +7,8 @@ "CVE-2021-21478" ], "details": "SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6g6q-c7q8-8r7m/GHSA-6g6q-c7q8-8r7m.json b/advisories/unreviewed/2022/05/GHSA-6g6q-c7q8-8r7m/GHSA-6g6q-c7q8-8r7m.json index 34690e89179..14def7520ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-6g6q-c7q8-8r7m/GHSA-6g6q-c7q8-8r7m.json +++ b/advisories/unreviewed/2022/05/GHSA-6g6q-c7q8-8r7m/GHSA-6g6q-c7q8-8r7m.json @@ -7,12 +7,8 @@ "CVE-2020-8031" ], "details": "A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Open Build Service allows remote attackers to store JS code in markdown that is not properly escaped, impacting confidentiality and integrity. This issue affects: Open Build Service versions prior to 2.10.8.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6gvq-w4vx-qjr3/GHSA-6gvq-w4vx-qjr3.json b/advisories/unreviewed/2022/05/GHSA-6gvq-w4vx-qjr3/GHSA-6gvq-w4vx-qjr3.json index d769e7a481f..bb0bc3d7c8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gvq-w4vx-qjr3/GHSA-6gvq-w4vx-qjr3.json +++ b/advisories/unreviewed/2022/05/GHSA-6gvq-w4vx-qjr3/GHSA-6gvq-w4vx-qjr3.json @@ -7,12 +7,8 @@ "CVE-2021-0349" ], "details": "In display driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05362646.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6hqj-g24g-vjcr/GHSA-6hqj-g24g-vjcr.json b/advisories/unreviewed/2022/05/GHSA-6hqj-g24g-vjcr/GHSA-6hqj-g24g-vjcr.json index 4e9869ff5f8..597cfb1b8f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hqj-g24g-vjcr/GHSA-6hqj-g24g-vjcr.json +++ b/advisories/unreviewed/2022/05/GHSA-6hqj-g24g-vjcr/GHSA-6hqj-g24g-vjcr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6hx5-9q4p-p96w/GHSA-6hx5-9q4p-p96w.json b/advisories/unreviewed/2022/05/GHSA-6hx5-9q4p-p96w/GHSA-6hx5-9q4p-p96w.json index c82684dd5d0..78307c44f2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hx5-9q4p-p96w/GHSA-6hx5-9q4p-p96w.json +++ b/advisories/unreviewed/2022/05/GHSA-6hx5-9q4p-p96w/GHSA-6hx5-9q4p-p96w.json @@ -7,12 +7,8 @@ "CVE-2021-25236" ], "details": "A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a specific sweep.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6phg-5gjc-53gj/GHSA-6phg-5gjc-53gj.json b/advisories/unreviewed/2022/05/GHSA-6phg-5gjc-53gj/GHSA-6phg-5gjc-53gj.json index 491ff517026..d784cc83c58 100644 --- a/advisories/unreviewed/2022/05/GHSA-6phg-5gjc-53gj/GHSA-6phg-5gjc-53gj.json +++ b/advisories/unreviewed/2022/05/GHSA-6phg-5gjc-53gj/GHSA-6phg-5gjc-53gj.json @@ -7,12 +7,8 @@ "CVE-2020-29171" ], "details": "Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6phq-rjgc-62hr/GHSA-6phq-rjgc-62hr.json b/advisories/unreviewed/2022/05/GHSA-6phq-rjgc-62hr/GHSA-6phq-rjgc-62hr.json index eb4bffc3889..938130dcf79 100644 --- a/advisories/unreviewed/2022/05/GHSA-6phq-rjgc-62hr/GHSA-6phq-rjgc-62hr.json +++ b/advisories/unreviewed/2022/05/GHSA-6phq-rjgc-62hr/GHSA-6phq-rjgc-62hr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6pmc-4qj8-52q7/GHSA-6pmc-4qj8-52q7.json b/advisories/unreviewed/2022/05/GHSA-6pmc-4qj8-52q7/GHSA-6pmc-4qj8-52q7.json index 220cfd41b0c..15808f656f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-6pmc-4qj8-52q7/GHSA-6pmc-4qj8-52q7.json +++ b/advisories/unreviewed/2022/05/GHSA-6pmc-4qj8-52q7/GHSA-6pmc-4qj8-52q7.json @@ -7,12 +7,8 @@ "CVE-2021-0355" ], "details": "In kisd, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05425581.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6qj7-98xg-fpgf/GHSA-6qj7-98xg-fpgf.json b/advisories/unreviewed/2022/05/GHSA-6qj7-98xg-fpgf/GHSA-6qj7-98xg-fpgf.json index 3da54e87f59..0bef3d77b09 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qj7-98xg-fpgf/GHSA-6qj7-98xg-fpgf.json +++ b/advisories/unreviewed/2022/05/GHSA-6qj7-98xg-fpgf/GHSA-6qj7-98xg-fpgf.json @@ -7,12 +7,8 @@ "CVE-2020-27872" ], "details": "This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. The issue results from improper state tracking in the password recovery process. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-11365.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6rg3-pxqw-2fqw/GHSA-6rg3-pxqw-2fqw.json b/advisories/unreviewed/2022/05/GHSA-6rg3-pxqw-2fqw/GHSA-6rg3-pxqw-2fqw.json index 7a07173cc10..019a5746380 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rg3-pxqw-2fqw/GHSA-6rg3-pxqw-2fqw.json +++ b/advisories/unreviewed/2022/05/GHSA-6rg3-pxqw-2fqw/GHSA-6rg3-pxqw-2fqw.json @@ -7,12 +7,8 @@ "CVE-2021-1325" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6vgx-p4v6-c459/GHSA-6vgx-p4v6-c459.json b/advisories/unreviewed/2022/05/GHSA-6vgx-p4v6-c459/GHSA-6vgx-p4v6-c459.json index d469a0f127e..10bccf279e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vgx-p4v6-c459/GHSA-6vgx-p4v6-c459.json +++ b/advisories/unreviewed/2022/05/GHSA-6vgx-p4v6-c459/GHSA-6vgx-p4v6-c459.json @@ -7,12 +7,8 @@ "CVE-2020-13461" ], "details": "Username enumeration in present in Tufin SecureTrack. It's affecting all versions of SecureTrack. The vendor has decided not to fix this vulnerability. Vendor's response: \"This attack requires access to the internal network. If an attacker is part of the internal network, they do not require access to TOS to know the usernames\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6vjm-mvmh-r6hx/GHSA-6vjm-mvmh-r6hx.json b/advisories/unreviewed/2022/05/GHSA-6vjm-mvmh-r6hx/GHSA-6vjm-mvmh-r6hx.json index 7c147593eb3..1bc9399dc1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vjm-mvmh-r6hx/GHSA-6vjm-mvmh-r6hx.json +++ b/advisories/unreviewed/2022/05/GHSA-6vjm-mvmh-r6hx/GHSA-6vjm-mvmh-r6hx.json @@ -7,12 +7,8 @@ "CVE-2021-0327" ], "details": "In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored binder identities. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-172935267", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6x7w-v26q-jfv3/GHSA-6x7w-v26q-jfv3.json b/advisories/unreviewed/2022/05/GHSA-6x7w-v26q-jfv3/GHSA-6x7w-v26q-jfv3.json index 72576bf3775..8b412975d85 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x7w-v26q-jfv3/GHSA-6x7w-v26q-jfv3.json +++ b/advisories/unreviewed/2022/05/GHSA-6x7w-v26q-jfv3/GHSA-6x7w-v26q-jfv3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -59,9 +57,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6xx4-8wj3-477v/GHSA-6xx4-8wj3-477v.json b/advisories/unreviewed/2022/05/GHSA-6xx4-8wj3-477v/GHSA-6xx4-8wj3-477v.json index 16eb96bf3e3..05087ecfbaf 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xx4-8wj3-477v/GHSA-6xx4-8wj3-477v.json +++ b/advisories/unreviewed/2022/05/GHSA-6xx4-8wj3-477v/GHSA-6xx4-8wj3-477v.json @@ -7,12 +7,8 @@ "CVE-2021-22122" ], "details": "An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload in different vulnerable API end-points.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-74m2-4qpm-x6vm/GHSA-74m2-4qpm-x6vm.json b/advisories/unreviewed/2022/05/GHSA-74m2-4qpm-x6vm/GHSA-74m2-4qpm-x6vm.json index 1e91ea4c7f9..86ebf9acd17 100644 --- a/advisories/unreviewed/2022/05/GHSA-74m2-4qpm-x6vm/GHSA-74m2-4qpm-x6vm.json +++ b/advisories/unreviewed/2022/05/GHSA-74m2-4qpm-x6vm/GHSA-74m2-4qpm-x6vm.json @@ -7,12 +7,8 @@ "CVE-2020-28870" ], "details": "In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /modules/sys/form_personalization/json_fp.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-74wv-xgwp-h8mf/GHSA-74wv-xgwp-h8mf.json b/advisories/unreviewed/2022/05/GHSA-74wv-xgwp-h8mf/GHSA-74wv-xgwp-h8mf.json index 10cb1a4c9cc..ebb6fff173c 100644 --- a/advisories/unreviewed/2022/05/GHSA-74wv-xgwp-h8mf/GHSA-74wv-xgwp-h8mf.json +++ b/advisories/unreviewed/2022/05/GHSA-74wv-xgwp-h8mf/GHSA-74wv-xgwp-h8mf.json @@ -7,12 +7,8 @@ "CVE-2021-27163" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / tele1234 credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-75hw-pggw-3xwh/GHSA-75hw-pggw-3xwh.json b/advisories/unreviewed/2022/05/GHSA-75hw-pggw-3xwh/GHSA-75hw-pggw-3xwh.json index c2a14168130..8ef75abe8fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-75hw-pggw-3xwh/GHSA-75hw-pggw-3xwh.json +++ b/advisories/unreviewed/2022/05/GHSA-75hw-pggw-3xwh/GHSA-75hw-pggw-3xwh.json @@ -7,12 +7,8 @@ "CVE-2020-4825" ], "details": "IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 189839.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-75j3-4jfq-x36j/GHSA-75j3-4jfq-x36j.json b/advisories/unreviewed/2022/05/GHSA-75j3-4jfq-x36j/GHSA-75j3-4jfq-x36j.json index 8cfa6bedb92..7c8f5f38e64 100644 --- a/advisories/unreviewed/2022/05/GHSA-75j3-4jfq-x36j/GHSA-75j3-4jfq-x36j.json +++ b/advisories/unreviewed/2022/05/GHSA-75j3-4jfq-x36j/GHSA-75j3-4jfq-x36j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-76j8-m22q-r2r6/GHSA-76j8-m22q-r2r6.json b/advisories/unreviewed/2022/05/GHSA-76j8-m22q-r2r6/GHSA-76j8-m22q-r2r6.json index 6261749795e..d999578e5cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-76j8-m22q-r2r6/GHSA-76j8-m22q-r2r6.json +++ b/advisories/unreviewed/2022/05/GHSA-76j8-m22q-r2r6/GHSA-76j8-m22q-r2r6.json @@ -7,12 +7,8 @@ "CVE-2020-27994" ], "details": "SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-76q4-85fh-5fj7/GHSA-76q4-85fh-5fj7.json b/advisories/unreviewed/2022/05/GHSA-76q4-85fh-5fj7/GHSA-76q4-85fh-5fj7.json index 25a33c572f6..7c872af73e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-76q4-85fh-5fj7/GHSA-76q4-85fh-5fj7.json +++ b/advisories/unreviewed/2022/05/GHSA-76q4-85fh-5fj7/GHSA-76q4-85fh-5fj7.json @@ -7,12 +7,8 @@ "CVE-2020-27005" ], "details": "A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing of TGA files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-12178)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-77q3-9j2v-49q7/GHSA-77q3-9j2v-49q7.json b/advisories/unreviewed/2022/05/GHSA-77q3-9j2v-49q7/GHSA-77q3-9j2v-49q7.json index bebee218a40..c2d8c8b099e 100644 --- a/advisories/unreviewed/2022/05/GHSA-77q3-9j2v-49q7/GHSA-77q3-9j2v-49q7.json +++ b/advisories/unreviewed/2022/05/GHSA-77q3-9j2v-49q7/GHSA-77q3-9j2v-49q7.json @@ -7,12 +7,8 @@ "CVE-2021-1292" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These vulnerabilities exist because HTTP requests are not properly validated. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to remotely execute arbitrary code on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-79c7-7x2r-rmwf/GHSA-79c7-7x2r-rmwf.json b/advisories/unreviewed/2022/05/GHSA-79c7-7x2r-rmwf/GHSA-79c7-7x2r-rmwf.json index f9a88284cec..159a5d5f045 100644 --- a/advisories/unreviewed/2022/05/GHSA-79c7-7x2r-rmwf/GHSA-79c7-7x2r-rmwf.json +++ b/advisories/unreviewed/2022/05/GHSA-79c7-7x2r-rmwf/GHSA-79c7-7x2r-rmwf.json @@ -7,12 +7,8 @@ "CVE-2021-26304" ], "details": "PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the add-expense.php Item parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7c3h-wh3g-298c/GHSA-7c3h-wh3g-298c.json b/advisories/unreviewed/2022/05/GHSA-7c3h-wh3g-298c/GHSA-7c3h-wh3g-298c.json index 728e9aec3fe..4e8aa4c262c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c3h-wh3g-298c/GHSA-7c3h-wh3g-298c.json +++ b/advisories/unreviewed/2022/05/GHSA-7c3h-wh3g-298c/GHSA-7c3h-wh3g-298c.json @@ -7,12 +7,8 @@ "CVE-2020-18723" ], "details": "Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side while forwarding an email to perform potentially malicious activities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7f6f-mqg7-656v/GHSA-7f6f-mqg7-656v.json b/advisories/unreviewed/2022/05/GHSA-7f6f-mqg7-656v/GHSA-7f6f-mqg7-656v.json index f4fb04acd10..68670307e2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f6f-mqg7-656v/GHSA-7f6f-mqg7-656v.json +++ b/advisories/unreviewed/2022/05/GHSA-7f6f-mqg7-656v/GHSA-7f6f-mqg7-656v.json @@ -7,12 +7,8 @@ "CVE-2021-27172" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. A hardcoded GEPON password for root is defined inside /etc/init.d/system-config.sh.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7fjh-g2fp-mqf5/GHSA-7fjh-g2fp-mqf5.json b/advisories/unreviewed/2022/05/GHSA-7fjh-g2fp-mqf5/GHSA-7fjh-g2fp-mqf5.json index 1c20bc3eead..7a0fd33f605 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fjh-g2fp-mqf5/GHSA-7fjh-g2fp-mqf5.json +++ b/advisories/unreviewed/2022/05/GHSA-7fjh-g2fp-mqf5/GHSA-7fjh-g2fp-mqf5.json @@ -7,12 +7,8 @@ "CVE-2020-10857" ], "details": "Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7fjp-x968-hg59/GHSA-7fjp-x968-hg59.json b/advisories/unreviewed/2022/05/GHSA-7fjp-x968-hg59/GHSA-7fjp-x968-hg59.json index e949aeb2935..f13dab30a45 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fjp-x968-hg59/GHSA-7fjp-x968-hg59.json +++ b/advisories/unreviewed/2022/05/GHSA-7fjp-x968-hg59/GHSA-7fjp-x968-hg59.json @@ -7,12 +7,8 @@ "CVE-2020-9118" ], "details": "There is an insufficient integrity check vulnerability in Huawei Sound X Product. The system does not check certain software package's integrity sufficiently. Successful exploit could allow an attacker to load a crafted software package to the device. Affected product versions include:AIS-BW80H-00 versions 9.0.3.1(H100SP13C00),9.0.3.1(H100SP18C00),9.0.3.1(H100SP3C00),9.0.3.1(H100SP9C00),9.0.3.2(H100SP1C00),9.0.3.2(H100SP2C00),9.0.3.2(H100SP5C00),9.0.3.2(H100SP8C00),9.0.3.3(H100SP1C00).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7fxc-vwm3-9www/GHSA-7fxc-vwm3-9www.json b/advisories/unreviewed/2022/05/GHSA-7fxc-vwm3-9www/GHSA-7fxc-vwm3-9www.json index cde3d9b99a7..b96e8954c17 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fxc-vwm3-9www/GHSA-7fxc-vwm3-9www.json +++ b/advisories/unreviewed/2022/05/GHSA-7fxc-vwm3-9www/GHSA-7fxc-vwm3-9www.json @@ -7,12 +7,8 @@ "CVE-2020-20290" ], "details": "Directory traversal vulnerability in the yccms 3.3 project. The delete, deletesite, and deleteAll functions' improper judgment of the request parameters, triggers a directory traversal vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g5q-hmw7-26pf/GHSA-7g5q-hmw7-26pf.json b/advisories/unreviewed/2022/05/GHSA-7g5q-hmw7-26pf/GHSA-7g5q-hmw7-26pf.json index 70e5c2acdf6..112f44a06cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g5q-hmw7-26pf/GHSA-7g5q-hmw7-26pf.json +++ b/advisories/unreviewed/2022/05/GHSA-7g5q-hmw7-26pf/GHSA-7g5q-hmw7-26pf.json @@ -7,12 +7,8 @@ "CVE-2020-4996" ], "details": "IBM Security Identity Governance and Intelligence 5.2.6 could allow a local user to obtain sensitive information via the capturing of screenshots of authentication credentials. IBM X-Force ID: 192913.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7h6h-hrf8-cc7v/GHSA-7h6h-hrf8-cc7v.json b/advisories/unreviewed/2022/05/GHSA-7h6h-hrf8-cc7v/GHSA-7h6h-hrf8-cc7v.json index 892642f1f35..2f7d71b8b93 100644 --- a/advisories/unreviewed/2022/05/GHSA-7h6h-hrf8-cc7v/GHSA-7h6h-hrf8-cc7v.json +++ b/advisories/unreviewed/2022/05/GHSA-7h6h-hrf8-cc7v/GHSA-7h6h-hrf8-cc7v.json @@ -7,12 +7,8 @@ "CVE-2020-36149" ], "details": "Incorrect handling of input data in changeAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protection or near NULL pointer overwrite in case of no memory restrictions (e.g. in embedded environments).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7h7m-5mrv-qfq7/GHSA-7h7m-5mrv-qfq7.json b/advisories/unreviewed/2022/05/GHSA-7h7m-5mrv-qfq7/GHSA-7h7m-5mrv-qfq7.json index ca15536833d..ea6b2010537 100644 --- a/advisories/unreviewed/2022/05/GHSA-7h7m-5mrv-qfq7/GHSA-7h7m-5mrv-qfq7.json +++ b/advisories/unreviewed/2022/05/GHSA-7h7m-5mrv-qfq7/GHSA-7h7m-5mrv-qfq7.json @@ -7,12 +7,8 @@ "CVE-2021-25127" ], "details": "The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice generatesslcertificate_func function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hf7-68wx-vrmr/GHSA-7hf7-68wx-vrmr.json b/advisories/unreviewed/2022/05/GHSA-7hf7-68wx-vrmr/GHSA-7hf7-68wx-vrmr.json index 87db63f013a..c1109923625 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hf7-68wx-vrmr/GHSA-7hf7-68wx-vrmr.json +++ b/advisories/unreviewed/2022/05/GHSA-7hf7-68wx-vrmr/GHSA-7hf7-68wx-vrmr.json @@ -7,12 +7,8 @@ "CVE-2021-27144" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded f~i!b@e#r$h%o^m*esuperadmin / s(f)u_h+g|u credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hqh-xccf-8jp4/GHSA-7hqh-xccf-8jp4.json b/advisories/unreviewed/2022/05/GHSA-7hqh-xccf-8jp4/GHSA-7hqh-xccf-8jp4.json index ee24c36fafb..a93451f9b74 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hqh-xccf-8jp4/GHSA-7hqh-xccf-8jp4.json +++ b/advisories/unreviewed/2022/05/GHSA-7hqh-xccf-8jp4/GHSA-7hqh-xccf-8jp4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hxp-qqjp-qjxm/GHSA-7hxp-qqjp-qjxm.json b/advisories/unreviewed/2022/05/GHSA-7hxp-qqjp-qjxm/GHSA-7hxp-qqjp-qjxm.json index dbc66c2a211..c56e0ca231a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hxp-qqjp-qjxm/GHSA-7hxp-qqjp-qjxm.json +++ b/advisories/unreviewed/2022/05/GHSA-7hxp-qqjp-qjxm/GHSA-7hxp-qqjp-qjxm.json @@ -7,12 +7,8 @@ "CVE-2021-27143" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / user1234 credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7mrx-fcmq-phm5/GHSA-7mrx-fcmq-phm5.json b/advisories/unreviewed/2022/05/GHSA-7mrx-fcmq-phm5/GHSA-7mrx-fcmq-phm5.json index 928020e504b..aa7f26b1e50 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mrx-fcmq-phm5/GHSA-7mrx-fcmq-phm5.json +++ b/advisories/unreviewed/2022/05/GHSA-7mrx-fcmq-phm5/GHSA-7mrx-fcmq-phm5.json @@ -7,12 +7,8 @@ "CVE-2020-8355" ], "details": "An internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows OS credentials provided by the LXCA user to perform driver updates of managed systems may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated while managed endpoints are updating. The service log is only generated when requested by a privileged LXCA user and it is only accessible to the privileged LXCA user that requested the file and is then deleted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7p97-3339-fvgr/GHSA-7p97-3339-fvgr.json b/advisories/unreviewed/2022/05/GHSA-7p97-3339-fvgr/GHSA-7p97-3339-fvgr.json index 5ee0b505daa..522f7fcf1ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p97-3339-fvgr/GHSA-7p97-3339-fvgr.json +++ b/advisories/unreviewed/2022/05/GHSA-7p97-3339-fvgr/GHSA-7p97-3339-fvgr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7pq5-98ww-5q49/GHSA-7pq5-98ww-5q49.json b/advisories/unreviewed/2022/05/GHSA-7pq5-98ww-5q49/GHSA-7pq5-98ww-5q49.json index 7bf59b1e330..54d07afcfbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pq5-98ww-5q49/GHSA-7pq5-98ww-5q49.json +++ b/advisories/unreviewed/2022/05/GHSA-7pq5-98ww-5q49/GHSA-7pq5-98ww-5q49.json @@ -7,12 +7,8 @@ "CVE-2020-10375" ], "details": "An issue was discovered in New Media Smarty before 9.10. Passwords are stored in the database in an obfuscated format that can be easily reversed. The file data.mdb contains these obfuscated passwords in the second column. NOTE: this is unrelated to the popular Smarty template engine product.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7r29-w7vh-5p6q/GHSA-7r29-w7vh-5p6q.json b/advisories/unreviewed/2022/05/GHSA-7r29-w7vh-5p6q/GHSA-7r29-w7vh-5p6q.json index ee8c0adfb7a..793ffd0107e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7r29-w7vh-5p6q/GHSA-7r29-w7vh-5p6q.json +++ b/advisories/unreviewed/2022/05/GHSA-7r29-w7vh-5p6q/GHSA-7r29-w7vh-5p6q.json @@ -7,12 +7,8 @@ "CVE-2020-2507" ], "details": "The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to obtain control of a QNAP device. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7v4q-3ch3-mjc7/GHSA-7v4q-3ch3-mjc7.json b/advisories/unreviewed/2022/05/GHSA-7v4q-3ch3-mjc7/GHSA-7v4q-3ch3-mjc7.json index 94183ddbf36..82577c40991 100644 --- a/advisories/unreviewed/2022/05/GHSA-7v4q-3ch3-mjc7/GHSA-7v4q-3ch3-mjc7.json +++ b/advisories/unreviewed/2022/05/GHSA-7v4q-3ch3-mjc7/GHSA-7v4q-3ch3-mjc7.json @@ -7,12 +7,8 @@ "CVE-2021-25777" ], "details": "In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7vqm-5368-jjhq/GHSA-7vqm-5368-jjhq.json b/advisories/unreviewed/2022/05/GHSA-7vqm-5368-jjhq/GHSA-7vqm-5368-jjhq.json index fe0700976ff..df88caede91 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vqm-5368-jjhq/GHSA-7vqm-5368-jjhq.json +++ b/advisories/unreviewed/2022/05/GHSA-7vqm-5368-jjhq/GHSA-7vqm-5368-jjhq.json @@ -7,12 +7,8 @@ "CVE-2021-26572" ], "details": "The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wxw-m8h3-2r28/GHSA-7wxw-m8h3-2r28.json b/advisories/unreviewed/2022/05/GHSA-7wxw-m8h3-2r28/GHSA-7wxw-m8h3-2r28.json index 4533bb4a922..af09c055be6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wxw-m8h3-2r28/GHSA-7wxw-m8h3-2r28.json +++ b/advisories/unreviewed/2022/05/GHSA-7wxw-m8h3-2r28/GHSA-7wxw-m8h3-2r28.json @@ -7,12 +7,8 @@ "CVE-2020-17427" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of NEF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11334.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8279-2hh7-mpv3/GHSA-8279-2hh7-mpv3.json b/advisories/unreviewed/2022/05/GHSA-8279-2hh7-mpv3/GHSA-8279-2hh7-mpv3.json index 605f7ec5ba7..db8b1e6a075 100644 --- a/advisories/unreviewed/2022/05/GHSA-8279-2hh7-mpv3/GHSA-8279-2hh7-mpv3.json +++ b/advisories/unreviewed/2022/05/GHSA-8279-2hh7-mpv3/GHSA-8279-2hh7-mpv3.json @@ -7,12 +7,8 @@ "CVE-2021-21476" ], "details": "SAP UI5, versions - 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1, allows an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82wg-r3hg-qxj2/GHSA-82wg-r3hg-qxj2.json b/advisories/unreviewed/2022/05/GHSA-82wg-r3hg-qxj2/GHSA-82wg-r3hg-qxj2.json index c5fddbfcd9c..bbc20888975 100644 --- a/advisories/unreviewed/2022/05/GHSA-82wg-r3hg-qxj2/GHSA-82wg-r3hg-qxj2.json +++ b/advisories/unreviewed/2022/05/GHSA-82wg-r3hg-qxj2/GHSA-82wg-r3hg-qxj2.json @@ -7,12 +7,8 @@ "CVE-2021-27161" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 1234 credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-83v3-rq53-m428/GHSA-83v3-rq53-m428.json b/advisories/unreviewed/2022/05/GHSA-83v3-rq53-m428/GHSA-83v3-rq53-m428.json index 3ae0f9b04c4..772c8d548e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-83v3-rq53-m428/GHSA-83v3-rq53-m428.json +++ b/advisories/unreviewed/2022/05/GHSA-83v3-rq53-m428/GHSA-83v3-rq53-m428.json @@ -7,12 +7,8 @@ "CVE-2021-27151" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded rootmet / m3tr0r00t credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-84v7-x658-c2jw/GHSA-84v7-x658-c2jw.json b/advisories/unreviewed/2022/05/GHSA-84v7-x658-c2jw/GHSA-84v7-x658-c2jw.json index 23a399c6318..c3be8a3127f 100644 --- a/advisories/unreviewed/2022/05/GHSA-84v7-x658-c2jw/GHSA-84v7-x658-c2jw.json +++ b/advisories/unreviewed/2022/05/GHSA-84v7-x658-c2jw/GHSA-84v7-x658-c2jw.json @@ -7,12 +7,8 @@ "CVE-2021-27178" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. Some passwords are stored in cleartext in nvram.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-85r2-3v9j-hfrq/GHSA-85r2-3v9j-hfrq.json b/advisories/unreviewed/2022/05/GHSA-85r2-3v9j-hfrq/GHSA-85r2-3v9j-hfrq.json index 0cddaa0604b..75ab61240ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-85r2-3v9j-hfrq/GHSA-85r2-3v9j-hfrq.json +++ b/advisories/unreviewed/2022/05/GHSA-85r2-3v9j-hfrq/GHSA-85r2-3v9j-hfrq.json @@ -7,12 +7,8 @@ "CVE-2020-24944" ], "details": "picoquic (before 3rd of July 2020) allows attackers to cause a denial of service (infinite loop) via a crafted QUIC frame, related to the picoquic_decode_frames and picoquic_decode_stream_frame functions and epoch==3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8768-8f2m-79g9/GHSA-8768-8f2m-79g9.json b/advisories/unreviewed/2022/05/GHSA-8768-8f2m-79g9/GHSA-8768-8f2m-79g9.json index b6dd46553e1..d09458d85d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8768-8f2m-79g9/GHSA-8768-8f2m-79g9.json +++ b/advisories/unreviewed/2022/05/GHSA-8768-8f2m-79g9/GHSA-8768-8f2m-79g9.json @@ -7,12 +7,8 @@ "CVE-2021-0364" ], "details": "In mobile_log_d, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05458478; Issue ID: ALPS05458503.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8777-qhx4-g86w/GHSA-8777-qhx4-g86w.json b/advisories/unreviewed/2022/05/GHSA-8777-qhx4-g86w/GHSA-8777-qhx4-g86w.json index aae8a994b36..257539b743a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8777-qhx4-g86w/GHSA-8777-qhx4-g86w.json +++ b/advisories/unreviewed/2022/05/GHSA-8777-qhx4-g86w/GHSA-8777-qhx4-g86w.json @@ -7,12 +7,8 @@ "CVE-2021-27168" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. There is a 6GFJdY4aAuUKJjdtSn7d password for the rdsadmin account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8899-pjpj-8p5v/GHSA-8899-pjpj-8p5v.json b/advisories/unreviewed/2022/05/GHSA-8899-pjpj-8p5v/GHSA-8899-pjpj-8p5v.json index d7f9c1437df..404b3e88bd9 100644 --- a/advisories/unreviewed/2022/05/GHSA-8899-pjpj-8p5v/GHSA-8899-pjpj-8p5v.json +++ b/advisories/unreviewed/2022/05/GHSA-8899-pjpj-8p5v/GHSA-8899-pjpj-8p5v.json @@ -7,12 +7,8 @@ "CVE-2021-1294" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These vulnerabilities exist because HTTP requests are not properly validated. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to remotely execute arbitrary code on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-88p8-mprp-j235/GHSA-88p8-mprp-j235.json b/advisories/unreviewed/2022/05/GHSA-88p8-mprp-j235/GHSA-88p8-mprp-j235.json index bb703f08868..81c51dcd560 100644 --- a/advisories/unreviewed/2022/05/GHSA-88p8-mprp-j235/GHSA-88p8-mprp-j235.json +++ b/advisories/unreviewed/2022/05/GHSA-88p8-mprp-j235/GHSA-88p8-mprp-j235.json @@ -7,12 +7,8 @@ "CVE-2020-17426" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of CR2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11230.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-88w2-cjhc-67m3/GHSA-88w2-cjhc-67m3.json b/advisories/unreviewed/2022/05/GHSA-88w2-cjhc-67m3/GHSA-88w2-cjhc-67m3.json index 50d24c75a5f..a665ddd1f76 100644 --- a/advisories/unreviewed/2022/05/GHSA-88w2-cjhc-67m3/GHSA-88w2-cjhc-67m3.json +++ b/advisories/unreviewed/2022/05/GHSA-88w2-cjhc-67m3/GHSA-88w2-cjhc-67m3.json @@ -7,12 +7,8 @@ "CVE-2020-29166" ], "details": "PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by file read/manipulation, which can result in remote information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-88xq-4322-8jj4/GHSA-88xq-4322-8jj4.json b/advisories/unreviewed/2022/05/GHSA-88xq-4322-8jj4/GHSA-88xq-4322-8jj4.json index af94058815a..d9ec911133f 100644 --- a/advisories/unreviewed/2022/05/GHSA-88xq-4322-8jj4/GHSA-88xq-4322-8jj4.json +++ b/advisories/unreviewed/2022/05/GHSA-88xq-4322-8jj4/GHSA-88xq-4322-8jj4.json @@ -7,12 +7,8 @@ "CVE-2020-14245" ], "details": "HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-899f-9gpg-r429/GHSA-899f-9gpg-r429.json b/advisories/unreviewed/2022/05/GHSA-899f-9gpg-r429/GHSA-899f-9gpg-r429.json index 411ff907fac..32c4085a140 100644 --- a/advisories/unreviewed/2022/05/GHSA-899f-9gpg-r429/GHSA-899f-9gpg-r429.json +++ b/advisories/unreviewed/2022/05/GHSA-899f-9gpg-r429/GHSA-899f-9gpg-r429.json @@ -7,12 +7,8 @@ "CVE-2021-0337" ], "details": "In moveInMediaStore of FileSystemProvider.java, there is a possible file exposure due to stale metadata. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-157474195", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-89g3-4g4h-p92v/GHSA-89g3-4g4h-p92v.json b/advisories/unreviewed/2022/05/GHSA-89g3-4g4h-p92v/GHSA-89g3-4g4h-p92v.json index 5ea695eae21..7cca1db3cfb 100644 --- a/advisories/unreviewed/2022/05/GHSA-89g3-4g4h-p92v/GHSA-89g3-4g4h-p92v.json +++ b/advisories/unreviewed/2022/05/GHSA-89g3-4g4h-p92v/GHSA-89g3-4g4h-p92v.json @@ -7,12 +7,8 @@ "CVE-2020-17434" ], "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ARW files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-11357.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8c4j-frh5-89w4/GHSA-8c4j-frh5-89w4.json b/advisories/unreviewed/2022/05/GHSA-8c4j-frh5-89w4/GHSA-8c4j-frh5-89w4.json index 596025ce486..c46ae571e9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8c4j-frh5-89w4/GHSA-8c4j-frh5-89w4.json +++ b/advisories/unreviewed/2022/05/GHSA-8c4j-frh5-89w4/GHSA-8c4j-frh5-89w4.json @@ -7,12 +7,8 @@ "CVE-2020-21179" ], "details": "Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to the signin page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cg3-m5v9-gvh4/GHSA-8cg3-m5v9-gvh4.json b/advisories/unreviewed/2022/05/GHSA-8cg3-m5v9-gvh4/GHSA-8cg3-m5v9-gvh4.json index 4f26ccf1907..586c1b48833 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cg3-m5v9-gvh4/GHSA-8cg3-m5v9-gvh4.json +++ b/advisories/unreviewed/2022/05/GHSA-8cg3-m5v9-gvh4/GHSA-8cg3-m5v9-gvh4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8mmr-6pqj-frmr/GHSA-8mmr-6pqj-frmr.json b/advisories/unreviewed/2022/05/GHSA-8mmr-6pqj-frmr/GHSA-8mmr-6pqj-frmr.json index 2dd27cab39c..3e5ee66ca56 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mmr-6pqj-frmr/GHSA-8mmr-6pqj-frmr.json +++ b/advisories/unreviewed/2022/05/GHSA-8mmr-6pqj-frmr/GHSA-8mmr-6pqj-frmr.json @@ -7,12 +7,8 @@ "CVE-2020-8589" ], "details": "Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15 are susceptible to a vulnerability which could allow unauthorized tenant users to discover the names of other Storage Virtual Machines (SVMs) and filenames on those SVMs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8mvr-j92p-v42j/GHSA-8mvr-j92p-v42j.json b/advisories/unreviewed/2022/05/GHSA-8mvr-j92p-v42j/GHSA-8mvr-j92p-v42j.json index dc587746530..a972a50e912 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mvr-j92p-v42j/GHSA-8mvr-j92p-v42j.json +++ b/advisories/unreviewed/2022/05/GHSA-8mvr-j92p-v42j/GHSA-8mvr-j92p-v42j.json @@ -7,12 +7,8 @@ "CVE-2021-21138" ], "details": "Use after free in DevTools in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform a sandbox escape via a crafted file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8p6j-7r63-99v9/GHSA-8p6j-7r63-99v9.json b/advisories/unreviewed/2022/05/GHSA-8p6j-7r63-99v9/GHSA-8p6j-7r63-99v9.json index 81d1ab983aa..1a63240148e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p6j-7r63-99v9/GHSA-8p6j-7r63-99v9.json +++ b/advisories/unreviewed/2022/05/GHSA-8p6j-7r63-99v9/GHSA-8p6j-7r63-99v9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8pqc-794r-q3c3/GHSA-8pqc-794r-q3c3.json b/advisories/unreviewed/2022/05/GHSA-8pqc-794r-q3c3/GHSA-8pqc-794r-q3c3.json index 95b2de96f4c..4e955840cf8 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pqc-794r-q3c3/GHSA-8pqc-794r-q3c3.json +++ b/advisories/unreviewed/2022/05/GHSA-8pqc-794r-q3c3/GHSA-8pqc-794r-q3c3.json @@ -7,12 +7,8 @@ "CVE-2021-0330" ], "details": "In add_user_ce and remove_user_ce of storaged.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in storaged with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-170732441", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8q43-j9qm-qm7q/GHSA-8q43-j9qm-qm7q.json b/advisories/unreviewed/2022/05/GHSA-8q43-j9qm-qm7q/GHSA-8q43-j9qm-qm7q.json index 0effb989108..aaf73ab90e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q43-j9qm-qm7q/GHSA-8q43-j9qm-qm7q.json +++ b/advisories/unreviewed/2022/05/GHSA-8q43-j9qm-qm7q/GHSA-8q43-j9qm-qm7q.json @@ -7,12 +7,8 @@ "CVE-2020-22839" ], "details": "Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8q7x-wx54-w95j/GHSA-8q7x-wx54-w95j.json b/advisories/unreviewed/2022/05/GHSA-8q7x-wx54-w95j/GHSA-8q7x-wx54-w95j.json index 71a6042c50d..628345b6f98 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q7x-wx54-w95j/GHSA-8q7x-wx54-w95j.json +++ b/advisories/unreviewed/2022/05/GHSA-8q7x-wx54-w95j/GHSA-8q7x-wx54-w95j.json @@ -7,12 +7,8 @@ "CVE-2020-25854" ], "details": "The function DecWPA2KeyData() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an internal function, rt_arc4_crypt_veneer() or _AES_UnWRAP_veneer(), resulting in a stack buffer overflow which can be exploited for remote code execution or denial of service. An attacker can impersonate an Access Point and attack a vulnerable Wi-Fi client, by injecting a crafted packet into the WPA2 handshake. The attacker needs to know the network's PSK in order to exploit this.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qcw-8pjv-4qj8/GHSA-8qcw-8pjv-4qj8.json b/advisories/unreviewed/2022/05/GHSA-8qcw-8pjv-4qj8/GHSA-8qcw-8pjv-4qj8.json index 0f425a354ff..41156b9387f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qcw-8pjv-4qj8/GHSA-8qcw-8pjv-4qj8.json +++ b/advisories/unreviewed/2022/05/GHSA-8qcw-8pjv-4qj8/GHSA-8qcw-8pjv-4qj8.json @@ -7,12 +7,8 @@ "CVE-2021-1327" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qg8-6crq-4q3h/GHSA-8qg8-6crq-4q3h.json b/advisories/unreviewed/2022/05/GHSA-8qg8-6crq-4q3h/GHSA-8qg8-6crq-4q3h.json index 070a8c9684d..8cac2bbae3f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qg8-6crq-4q3h/GHSA-8qg8-6crq-4q3h.json +++ b/advisories/unreviewed/2022/05/GHSA-8qg8-6crq-4q3h/GHSA-8qg8-6crq-4q3h.json @@ -7,12 +7,8 @@ "CVE-2020-13856" ], "details": "An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download the support file that contains sensitive information such as cleartext credentials and password hashes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qwm-6624-jhvr/GHSA-8qwm-6624-jhvr.json b/advisories/unreviewed/2022/05/GHSA-8qwm-6624-jhvr/GHSA-8qwm-6624-jhvr.json index 2f746a30cfd..0f556c53a3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qwm-6624-jhvr/GHSA-8qwm-6624-jhvr.json +++ b/advisories/unreviewed/2022/05/GHSA-8qwm-6624-jhvr/GHSA-8qwm-6624-jhvr.json @@ -7,12 +7,8 @@ "CVE-2021-22302" ], "details": "There is an out-of-bound read vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). A module does not verify the some input. Attackers can exploit this vulnerability by sending malicious input through specific app. This could cause out-of-bound, compromising normal service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8r42-h5pm-2vw2/GHSA-8r42-h5pm-2vw2.json b/advisories/unreviewed/2022/05/GHSA-8r42-h5pm-2vw2/GHSA-8r42-h5pm-2vw2.json index 4ae953af5b3..70805cf3751 100644 --- a/advisories/unreviewed/2022/05/GHSA-8r42-h5pm-2vw2/GHSA-8r42-h5pm-2vw2.json +++ b/advisories/unreviewed/2022/05/GHSA-8r42-h5pm-2vw2/GHSA-8r42-h5pm-2vw2.json @@ -7,12 +7,8 @@ "CVE-2021-3347" ], "details": "An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8r95-q845-45m7/GHSA-8r95-q845-45m7.json b/advisories/unreviewed/2022/05/GHSA-8r95-q845-45m7/GHSA-8r95-q845-45m7.json index 7b8b54abf90..395ae0a7818 100644 --- a/advisories/unreviewed/2022/05/GHSA-8r95-q845-45m7/GHSA-8r95-q845-45m7.json +++ b/advisories/unreviewed/2022/05/GHSA-8r95-q845-45m7/GHSA-8r95-q845-45m7.json @@ -7,12 +7,8 @@ "CVE-2021-27179" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to crash the telnet daemon by sending a certain 0a 65 6e 61 62 6c 65 0a 02 0a 1a 0a string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8vm8-c58w-96hq/GHSA-8vm8-c58w-96hq.json b/advisories/unreviewed/2022/05/GHSA-8vm8-c58w-96hq/GHSA-8vm8-c58w-96hq.json index 95e93d60598..3b43310f1b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vm8-c58w-96hq/GHSA-8vm8-c58w-96hq.json +++ b/advisories/unreviewed/2022/05/GHSA-8vm8-c58w-96hq/GHSA-8vm8-c58w-96hq.json @@ -7,12 +7,8 @@ "CVE-2021-1290" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These vulnerabilities exist because HTTP requests are not properly validated. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to remotely execute arbitrary code on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8ww2-j39p-q769/GHSA-8ww2-j39p-q769.json b/advisories/unreviewed/2022/05/GHSA-8ww2-j39p-q769/GHSA-8ww2-j39p-q769.json index da459017f68..b4a213f6ce5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8ww2-j39p-q769/GHSA-8ww2-j39p-q769.json +++ b/advisories/unreviewed/2022/05/GHSA-8ww2-j39p-q769/GHSA-8ww2-j39p-q769.json @@ -7,12 +7,8 @@ "CVE-2021-1340" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8wxp-wp4j-j684/GHSA-8wxp-wp4j-j684.json b/advisories/unreviewed/2022/05/GHSA-8wxp-wp4j-j684/GHSA-8wxp-wp4j-j684.json index a9a6712ce36..e85cf077c78 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wxp-wp4j-j684/GHSA-8wxp-wp4j-j684.json +++ b/advisories/unreviewed/2022/05/GHSA-8wxp-wp4j-j684/GHSA-8wxp-wp4j-j684.json @@ -7,12 +7,8 @@ "CVE-2021-22499" ], "details": "Persistent Cross-Site scripting vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could allow persistent XSS attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8x6h-69qf-c7v6/GHSA-8x6h-69qf-c7v6.json b/advisories/unreviewed/2022/05/GHSA-8x6h-69qf-c7v6/GHSA-8x6h-69qf-c7v6.json index ebf896aac19..ac7c9e4c2c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-8x6h-69qf-c7v6/GHSA-8x6h-69qf-c7v6.json +++ b/advisories/unreviewed/2022/05/GHSA-8x6h-69qf-c7v6/GHSA-8x6h-69qf-c7v6.json @@ -7,12 +7,8 @@ "CVE-2020-15834" ], "details": "An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The wireless network password is exposed in a QR encoded picture that an unauthenticated adversary can download via the web-management interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-93r8-x5g7-g7fh/GHSA-93r8-x5g7-g7fh.json b/advisories/unreviewed/2022/05/GHSA-93r8-x5g7-g7fh/GHSA-93r8-x5g7-g7fh.json index 181fdb63d76..fd633423fad 100644 --- a/advisories/unreviewed/2022/05/GHSA-93r8-x5g7-g7fh/GHSA-93r8-x5g7-g7fh.json +++ b/advisories/unreviewed/2022/05/GHSA-93r8-x5g7-g7fh/GHSA-93r8-x5g7-g7fh.json @@ -7,12 +7,8 @@ "CVE-2021-27152" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded awnfibre / fibre@dm!n credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-972w-3xcp-6vcv/GHSA-972w-3xcp-6vcv.json b/advisories/unreviewed/2022/05/GHSA-972w-3xcp-6vcv/GHSA-972w-3xcp-6vcv.json index af7f8da6efd..8655b19f9f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-972w-3xcp-6vcv/GHSA-972w-3xcp-6vcv.json +++ b/advisories/unreviewed/2022/05/GHSA-972w-3xcp-6vcv/GHSA-972w-3xcp-6vcv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-977w-cv9x-3pr9/GHSA-977w-cv9x-3pr9.json b/advisories/unreviewed/2022/05/GHSA-977w-cv9x-3pr9/GHSA-977w-cv9x-3pr9.json index edd22987a8c..e5014b5694f 100644 --- a/advisories/unreviewed/2022/05/GHSA-977w-cv9x-3pr9/GHSA-977w-cv9x-3pr9.json +++ b/advisories/unreviewed/2022/05/GHSA-977w-cv9x-3pr9/GHSA-977w-cv9x-3pr9.json @@ -7,12 +7,8 @@ "CVE-2020-18724" ], "details": "Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9978-p96m-85pj/GHSA-9978-p96m-85pj.json b/advisories/unreviewed/2022/05/GHSA-9978-p96m-85pj/GHSA-9978-p96m-85pj.json index 576bc9f365c..06e28b98d87 100644 --- a/advisories/unreviewed/2022/05/GHSA-9978-p96m-85pj/GHSA-9978-p96m-85pj.json +++ b/advisories/unreviewed/2022/05/GHSA-9978-p96m-85pj/GHSA-9978-p96m-85pj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-99j6-pf9p-h77c/GHSA-99j6-pf9p-h77c.json b/advisories/unreviewed/2022/05/GHSA-99j6-pf9p-h77c/GHSA-99j6-pf9p-h77c.json index d84996080d9..059fad87abb 100644 --- a/advisories/unreviewed/2022/05/GHSA-99j6-pf9p-h77c/GHSA-99j6-pf9p-h77c.json +++ b/advisories/unreviewed/2022/05/GHSA-99j6-pf9p-h77c/GHSA-99j6-pf9p-h77c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9c25-9784-774x/GHSA-9c25-9784-774x.json b/advisories/unreviewed/2022/05/GHSA-9c25-9784-774x/GHSA-9c25-9784-774x.json index 6d88caae89d..3b6330ffa05 100644 --- a/advisories/unreviewed/2022/05/GHSA-9c25-9784-774x/GHSA-9c25-9784-774x.json +++ b/advisories/unreviewed/2022/05/GHSA-9c25-9784-774x/GHSA-9c25-9784-774x.json @@ -7,12 +7,8 @@ "CVE-2021-21139" ], "details": "Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9c64-5jjg-w2cj/GHSA-9c64-5jjg-w2cj.json b/advisories/unreviewed/2022/05/GHSA-9c64-5jjg-w2cj/GHSA-9c64-5jjg-w2cj.json index 8cf8311dfb2..cb63b4a234f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9c64-5jjg-w2cj/GHSA-9c64-5jjg-w2cj.json +++ b/advisories/unreviewed/2022/05/GHSA-9c64-5jjg-w2cj/GHSA-9c64-5jjg-w2cj.json @@ -7,12 +7,8 @@ "CVE-2021-25170" ], "details": "The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so websetremoteimageinfo function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9cjc-gp3w-7hf2/GHSA-9cjc-gp3w-7hf2.json b/advisories/unreviewed/2022/05/GHSA-9cjc-gp3w-7hf2/GHSA-9cjc-gp3w-7hf2.json index ac2f5787077..62751814019 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cjc-gp3w-7hf2/GHSA-9cjc-gp3w-7hf2.json +++ b/advisories/unreviewed/2022/05/GHSA-9cjc-gp3w-7hf2/GHSA-9cjc-gp3w-7hf2.json @@ -7,12 +7,8 @@ "CVE-2021-1343" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9h57-vmqg-5rrw/GHSA-9h57-vmqg-5rrw.json b/advisories/unreviewed/2022/05/GHSA-9h57-vmqg-5rrw/GHSA-9h57-vmqg-5rrw.json index aa31b3e6dea..1388cc84c3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9h57-vmqg-5rrw/GHSA-9h57-vmqg-5rrw.json +++ b/advisories/unreviewed/2022/05/GHSA-9h57-vmqg-5rrw/GHSA-9h57-vmqg-5rrw.json @@ -7,12 +7,8 @@ "CVE-2021-26574" ], "details": "The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletevideofile function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9hpv-r424-hr95/GHSA-9hpv-r424-hr95.json b/advisories/unreviewed/2022/05/GHSA-9hpv-r424-hr95/GHSA-9hpv-r424-hr95.json index 0e987c51e0b..79626ae429e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hpv-r424-hr95/GHSA-9hpv-r424-hr95.json +++ b/advisories/unreviewed/2022/05/GHSA-9hpv-r424-hr95/GHSA-9hpv-r424-hr95.json @@ -7,12 +7,8 @@ "CVE-2020-1779" ], "details": "When dynamic templates are used (OTRSTicketForms), admin can use OTRS tags which are not masked properly and can reveal sensitive information. This issue affects: OTRS AG OTRSTicketForms 6.0.x version 6.0.40 and prior versions; 7.0.x version 7.0.29 and prior versions; 8.0.x version 8.0.3 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9mrp-7cm9-xqxq/GHSA-9mrp-7cm9-xqxq.json b/advisories/unreviewed/2022/05/GHSA-9mrp-7cm9-xqxq/GHSA-9mrp-7cm9-xqxq.json index 70ffb11093a..85681d64541 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mrp-7cm9-xqxq/GHSA-9mrp-7cm9-xqxq.json +++ b/advisories/unreviewed/2022/05/GHSA-9mrp-7cm9-xqxq/GHSA-9mrp-7cm9-xqxq.json @@ -7,12 +7,8 @@ "CVE-2020-17418" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of EZIX files. A crafted id in a channel element can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11197.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9pf8-h538-2p8j/GHSA-9pf8-h538-2p8j.json b/advisories/unreviewed/2022/05/GHSA-9pf8-h538-2p8j/GHSA-9pf8-h538-2p8j.json index 803082837ec..291a5f8279c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pf8-h538-2p8j/GHSA-9pf8-h538-2p8j.json +++ b/advisories/unreviewed/2022/05/GHSA-9pf8-h538-2p8j/GHSA-9pf8-h538-2p8j.json @@ -7,12 +7,8 @@ "CVE-2021-3033" ], "details": "An improper verification of cryptographic signature vulnerability exists in the Palo Alto Networks Prisma Cloud Compute console. This vulnerability enables an attacker to bypass signature validation during SAML authentication by logging in to the Prisma Cloud Compute console as any authorized user. This issue impacts: All versions of Prisma Cloud Compute 19.11, Prisma Cloud Compute 20.04, and Prisma Cloud Compute 20.09; Prisma Cloud Compute 20.12 before update 1. Prisma Cloud Compute SaaS version is not impacted by this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9qvw-hfpr-cvx6/GHSA-9qvw-hfpr-cvx6.json b/advisories/unreviewed/2022/05/GHSA-9qvw-hfpr-cvx6/GHSA-9qvw-hfpr-cvx6.json index 87abf71c3cd..d2cc4450b6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qvw-hfpr-cvx6/GHSA-9qvw-hfpr-cvx6.json +++ b/advisories/unreviewed/2022/05/GHSA-9qvw-hfpr-cvx6/GHSA-9qvw-hfpr-cvx6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9r6g-h7wj-fxhp/GHSA-9r6g-h7wj-fxhp.json b/advisories/unreviewed/2022/05/GHSA-9r6g-h7wj-fxhp/GHSA-9r6g-h7wj-fxhp.json index 1e30f101b71..6a720f7cccc 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r6g-h7wj-fxhp/GHSA-9r6g-h7wj-fxhp.json +++ b/advisories/unreviewed/2022/05/GHSA-9r6g-h7wj-fxhp/GHSA-9r6g-h7wj-fxhp.json @@ -7,12 +7,8 @@ "CVE-2021-25274" ], "details": "The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collector Service will process. Additionally, upon processing of such messages, the service deserializes them in insecure manner, allowing remote arbitrary code execution as LocalSystem.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rfj-vjc2-f7cj/GHSA-9rfj-vjc2-f7cj.json b/advisories/unreviewed/2022/05/GHSA-9rfj-vjc2-f7cj/GHSA-9rfj-vjc2-f7cj.json index 24ecf43f45e..23ff212f4f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rfj-vjc2-f7cj/GHSA-9rfj-vjc2-f7cj.json +++ b/advisories/unreviewed/2022/05/GHSA-9rfj-vjc2-f7cj/GHSA-9rfj-vjc2-f7cj.json @@ -7,12 +7,8 @@ "CVE-2020-8027" ], "details": "A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to overwrite arbitrary files and gain access to the openldap2 configuration This issue affects: SUSE Linux Enterprise Server 15-LTSS openldap2 versions prior to 2.4.46-9.37.1. SUSE Linux Enterprise Server for SAP 15 openldap2 versions prior to 2.4.46-9.37.1. openSUSE Leap 15.1 openldap2 versions prior to 2.4.46-lp151.10.18.1. openSUSE Leap 15.2 openldap2 versions prior to 2.4.46-lp152.14.9.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rrj-w544-7vw9/GHSA-9rrj-w544-7vw9.json b/advisories/unreviewed/2022/05/GHSA-9rrj-w544-7vw9/GHSA-9rrj-w544-7vw9.json index 9161a2cc454..9a64fe265ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rrj-w544-7vw9/GHSA-9rrj-w544-7vw9.json +++ b/advisories/unreviewed/2022/05/GHSA-9rrj-w544-7vw9/GHSA-9rrj-w544-7vw9.json @@ -7,12 +7,8 @@ "CVE-2020-25856" ], "details": "The function DecWPA2KeyData() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an rtl_memcpy() operation, resulting in a stack buffer overflow which can be exploited for remote code execution or denial of service. An attacker can impersonate an Access Point and attack a vulnerable Wi-Fi client, by injecting a crafted packet into the WPA2 handshake. The attacker needs to know the network's PSK in order to exploit this.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9v38-f7c4-w54w/GHSA-9v38-f7c4-w54w.json b/advisories/unreviewed/2022/05/GHSA-9v38-f7c4-w54w/GHSA-9v38-f7c4-w54w.json index e0eb66c008e..8bd6f2ee8f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v38-f7c4-w54w/GHSA-9v38-f7c4-w54w.json +++ b/advisories/unreviewed/2022/05/GHSA-9v38-f7c4-w54w/GHSA-9v38-f7c4-w54w.json @@ -7,12 +7,8 @@ "CVE-2021-26220" ], "details": "The ezxml_toxml function in ezxml 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9vc6-7g98-392v/GHSA-9vc6-7g98-392v.json b/advisories/unreviewed/2022/05/GHSA-9vc6-7g98-392v/GHSA-9vc6-7g98-392v.json index 70c21e9c787..06763941b49 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vc6-7g98-392v/GHSA-9vc6-7g98-392v.json +++ b/advisories/unreviewed/2022/05/GHSA-9vc6-7g98-392v/GHSA-9vc6-7g98-392v.json @@ -7,12 +7,8 @@ "CVE-2021-0331" ], "details": "In onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due to an insecure default value. This could lead to local escalation of privilege and notification access with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-170731783", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9vvj-c5q4-cg3m/GHSA-9vvj-c5q4-cg3m.json b/advisories/unreviewed/2022/05/GHSA-9vvj-c5q4-cg3m/GHSA-9vvj-c5q4-cg3m.json index f1ffdec93f8..cd1e49ab2fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vvj-c5q4-cg3m/GHSA-9vvj-c5q4-cg3m.json +++ b/advisories/unreviewed/2022/05/GHSA-9vvj-c5q4-cg3m/GHSA-9vvj-c5q4-cg3m.json @@ -7,12 +7,8 @@ "CVE-2021-22301" ], "details": "Mate 30 10.0.0.203(C00E201R7P2) have a buffer overflow vulnerability. After obtaining the root permission, an attacker can exploit the vulnerability to cause buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9w8f-hpgh-vxjr/GHSA-9w8f-hpgh-vxjr.json b/advisories/unreviewed/2022/05/GHSA-9w8f-hpgh-vxjr/GHSA-9w8f-hpgh-vxjr.json index 0e2941c5e28..3ab7ef6ee7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9w8f-hpgh-vxjr/GHSA-9w8f-hpgh-vxjr.json +++ b/advisories/unreviewed/2022/05/GHSA-9w8f-hpgh-vxjr/GHSA-9w8f-hpgh-vxjr.json @@ -7,12 +7,8 @@ "CVE-2020-36150" ], "details": "Incorrect handling of input data in loudness function in the libmysofa library 0.5 - 1.1 will lead to heap buffer overflow and access to unallocated memory block.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c258-vh6c-2m44/GHSA-c258-vh6c-2m44.json b/advisories/unreviewed/2022/05/GHSA-c258-vh6c-2m44/GHSA-c258-vh6c-2m44.json index 8245978cd68..e23e3f6d980 100644 --- a/advisories/unreviewed/2022/05/GHSA-c258-vh6c-2m44/GHSA-c258-vh6c-2m44.json +++ b/advisories/unreviewed/2022/05/GHSA-c258-vh6c-2m44/GHSA-c258-vh6c-2m44.json @@ -7,12 +7,8 @@ "CVE-2021-25133" ], "details": "The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice setradiusconfig_func function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c283-6775-92m9/GHSA-c283-6775-92m9.json b/advisories/unreviewed/2022/05/GHSA-c283-6775-92m9/GHSA-c283-6775-92m9.json index 7350c3439f4..c1b80a7d270 100644 --- a/advisories/unreviewed/2022/05/GHSA-c283-6775-92m9/GHSA-c283-6775-92m9.json +++ b/advisories/unreviewed/2022/05/GHSA-c283-6775-92m9/GHSA-c283-6775-92m9.json @@ -7,12 +7,8 @@ "CVE-2021-20016" ], "details": "A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c375-qwv9-rx4w/GHSA-c375-qwv9-rx4w.json b/advisories/unreviewed/2022/05/GHSA-c375-qwv9-rx4w/GHSA-c375-qwv9-rx4w.json index 8026a9ccd9c..80039407dec 100644 --- a/advisories/unreviewed/2022/05/GHSA-c375-qwv9-rx4w/GHSA-c375-qwv9-rx4w.json +++ b/advisories/unreviewed/2022/05/GHSA-c375-qwv9-rx4w/GHSA-c375-qwv9-rx4w.json @@ -7,12 +7,8 @@ "CVE-2021-25910" ], "details": "Improper Authentication vulnerability in the cookie parameter of ZIV AUTOMATION 4CCT-EA6-334126BF allows a local attacker to perform modifications in several parameters of the affected device as an authenticated user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c52j-mfvx-x96x/GHSA-c52j-mfvx-x96x.json b/advisories/unreviewed/2022/05/GHSA-c52j-mfvx-x96x/GHSA-c52j-mfvx-x96x.json index 111899d1a97..ba0c73e5b65 100644 --- a/advisories/unreviewed/2022/05/GHSA-c52j-mfvx-x96x/GHSA-c52j-mfvx-x96x.json +++ b/advisories/unreviewed/2022/05/GHSA-c52j-mfvx-x96x/GHSA-c52j-mfvx-x96x.json @@ -7,12 +7,8 @@ "CVE-2020-9205" ], "details": "There has a CSV injection vulnerability in ManageOne 8.0.1. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c54w-4pvq-9rmg/GHSA-c54w-4pvq-9rmg.json b/advisories/unreviewed/2022/05/GHSA-c54w-4pvq-9rmg/GHSA-c54w-4pvq-9rmg.json index 15c4f0893db..73e071c000e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c54w-4pvq-9rmg/GHSA-c54w-4pvq-9rmg.json +++ b/advisories/unreviewed/2022/05/GHSA-c54w-4pvq-9rmg/GHSA-c54w-4pvq-9rmg.json @@ -7,12 +7,8 @@ "CVE-2020-4790" ], "details": "IBM Security Identity Governance and Intelligence 5.2.6 could allow a user to cause a denial of service due to improperly validating a supplied URL, rendering the application unusuable. IBM X-Force ID: 189375.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5c5-mvqf-5f35/GHSA-c5c5-mvqf-5f35.json b/advisories/unreviewed/2022/05/GHSA-c5c5-mvqf-5f35/GHSA-c5c5-mvqf-5f35.json index 315cbd25133..0203b6d4937 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5c5-mvqf-5f35/GHSA-c5c5-mvqf-5f35.json +++ b/advisories/unreviewed/2022/05/GHSA-c5c5-mvqf-5f35/GHSA-c5c5-mvqf-5f35.json @@ -7,12 +7,8 @@ "CVE-2021-1346" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5v8-j47m-hqhf/GHSA-c5v8-j47m-hqhf.json b/advisories/unreviewed/2022/05/GHSA-c5v8-j47m-hqhf/GHSA-c5v8-j47m-hqhf.json index a05f81e2bd9..6ab558294d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5v8-j47m-hqhf/GHSA-c5v8-j47m-hqhf.json +++ b/advisories/unreviewed/2022/05/GHSA-c5v8-j47m-hqhf/GHSA-c5v8-j47m-hqhf.json @@ -7,12 +7,8 @@ "CVE-2020-26051" ], "details": "College Management System Php 1.0 suffers from SQL injection vulnerabilities in the index.php page from POST parameters 'unametxt' and 'pwdtxt', which are not filtered before passing a SQL query.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c6h8-w7qx-qj83/GHSA-c6h8-w7qx-qj83.json b/advisories/unreviewed/2022/05/GHSA-c6h8-w7qx-qj83/GHSA-c6h8-w7qx-qj83.json index 26c8a881f3f..6e8567757b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6h8-w7qx-qj83/GHSA-c6h8-w7qx-qj83.json +++ b/advisories/unreviewed/2022/05/GHSA-c6h8-w7qx-qj83/GHSA-c6h8-w7qx-qj83.json @@ -7,12 +7,8 @@ "CVE-2021-0339" ], "details": "In loadAnimation of WindowContainer.java, there is a possible way to keep displaying a malicious app while a target app is brought to the foreground. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-8.1 Android-9Android ID: A-145728687", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c845-j93q-wvrw/GHSA-c845-j93q-wvrw.json b/advisories/unreviewed/2022/05/GHSA-c845-j93q-wvrw/GHSA-c845-j93q-wvrw.json index c7b31c49219..c6446af591c 100644 --- a/advisories/unreviewed/2022/05/GHSA-c845-j93q-wvrw/GHSA-c845-j93q-wvrw.json +++ b/advisories/unreviewed/2022/05/GHSA-c845-j93q-wvrw/GHSA-c845-j93q-wvrw.json @@ -7,12 +7,8 @@ "CVE-2020-24842" ], "details": "PNPSCADA 2.200816204020 allows cross-site scripting (XSS), which can execute arbitrary JavaScript in the victim's browser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c85w-5xgr-3j3p/GHSA-c85w-5xgr-3j3p.json b/advisories/unreviewed/2022/05/GHSA-c85w-5xgr-3j3p/GHSA-c85w-5xgr-3j3p.json index cb1278c1af2..d11da124340 100644 --- a/advisories/unreviewed/2022/05/GHSA-c85w-5xgr-3j3p/GHSA-c85w-5xgr-3j3p.json +++ b/advisories/unreviewed/2022/05/GHSA-c85w-5xgr-3j3p/GHSA-c85w-5xgr-3j3p.json @@ -7,12 +7,8 @@ "CVE-2021-1324" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c9cq-84w8-7r7f/GHSA-c9cq-84w8-7r7f.json b/advisories/unreviewed/2022/05/GHSA-c9cq-84w8-7r7f/GHSA-c9cq-84w8-7r7f.json index 198233d6558..3b91c9b871f 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9cq-84w8-7r7f/GHSA-c9cq-84w8-7r7f.json +++ b/advisories/unreviewed/2022/05/GHSA-c9cq-84w8-7r7f/GHSA-c9cq-84w8-7r7f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -59,9 +57,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c9qm-rxm9-v737/GHSA-c9qm-rxm9-v737.json b/advisories/unreviewed/2022/05/GHSA-c9qm-rxm9-v737/GHSA-c9qm-rxm9-v737.json index e94233a9bb4..afc5449f298 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9qm-rxm9-v737/GHSA-c9qm-rxm9-v737.json +++ b/advisories/unreviewed/2022/05/GHSA-c9qm-rxm9-v737/GHSA-c9qm-rxm9-v737.json @@ -7,12 +7,8 @@ "CVE-2021-1319" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ccp4-42w5-9q8g/GHSA-ccp4-42w5-9q8g.json b/advisories/unreviewed/2022/05/GHSA-ccp4-42w5-9q8g/GHSA-ccp4-42w5-9q8g.json index 4fece162dd3..e8bca99c939 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccp4-42w5-9q8g/GHSA-ccp4-42w5-9q8g.json +++ b/advisories/unreviewed/2022/05/GHSA-ccp4-42w5-9q8g/GHSA-ccp4-42w5-9q8g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cf46-h25j-9pmq/GHSA-cf46-h25j-9pmq.json b/advisories/unreviewed/2022/05/GHSA-cf46-h25j-9pmq/GHSA-cf46-h25j-9pmq.json index e6e16b3c521..f0ce3e6e451 100644 --- a/advisories/unreviewed/2022/05/GHSA-cf46-h25j-9pmq/GHSA-cf46-h25j-9pmq.json +++ b/advisories/unreviewed/2022/05/GHSA-cf46-h25j-9pmq/GHSA-cf46-h25j-9pmq.json @@ -7,12 +7,8 @@ "CVE-2020-25853" ], "details": "The function CheckMic() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an internal function, _rt_md5_hmac_veneer() or _rt_hmac_sha1_veneer(), resulting in a stack buffer over-read which can be exploited for denial of service. An attacker can impersonate an Access Point and attack a vulnerable Wi-Fi client, by injecting a crafted packet into the WPA2 handshake. The attacker does not need to know the network's PSK.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfw7-38q9-9h94/GHSA-cfw7-38q9-9h94.json b/advisories/unreviewed/2022/05/GHSA-cfw7-38q9-9h94/GHSA-cfw7-38q9-9h94.json index 3dfa50a2e75..ded97fd3efd 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfw7-38q9-9h94/GHSA-cfw7-38q9-9h94.json +++ b/advisories/unreviewed/2022/05/GHSA-cfw7-38q9-9h94/GHSA-cfw7-38q9-9h94.json @@ -7,12 +7,8 @@ "CVE-2021-0353" ], "details": "In kisd, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05425247.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cj3p-75j4-74xf/GHSA-cj3p-75j4-74xf.json b/advisories/unreviewed/2022/05/GHSA-cj3p-75j4-74xf/GHSA-cj3p-75j4-74xf.json index 907b3a37b6f..07308d8c433 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj3p-75j4-74xf/GHSA-cj3p-75j4-74xf.json +++ b/advisories/unreviewed/2022/05/GHSA-cj3p-75j4-74xf/GHSA-cj3p-75j4-74xf.json @@ -7,12 +7,8 @@ "CVE-2020-27873" ], "details": "This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SOAP API endpoint, which listens on TCP port 80 by default. The issue results from the lack of proper access control. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-11559.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cjg9-xxpr-fm5g/GHSA-cjg9-xxpr-fm5g.json b/advisories/unreviewed/2022/05/GHSA-cjg9-xxpr-fm5g/GHSA-cjg9-xxpr-fm5g.json index a612a6f8fe7..e5c48ed7b80 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjg9-xxpr-fm5g/GHSA-cjg9-xxpr-fm5g.json +++ b/advisories/unreviewed/2022/05/GHSA-cjg9-xxpr-fm5g/GHSA-cjg9-xxpr-fm5g.json @@ -7,12 +7,8 @@ "CVE-2020-28001" ], "details": "SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cjrm-ccjq-r9vp/GHSA-cjrm-ccjq-r9vp.json b/advisories/unreviewed/2022/05/GHSA-cjrm-ccjq-r9vp/GHSA-cjrm-ccjq-r9vp.json index 8571442df75..799decf3d4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjrm-ccjq-r9vp/GHSA-cjrm-ccjq-r9vp.json +++ b/advisories/unreviewed/2022/05/GHSA-cjrm-ccjq-r9vp/GHSA-cjrm-ccjq-r9vp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cmjw-x23c-76gc/GHSA-cmjw-x23c-76gc.json b/advisories/unreviewed/2022/05/GHSA-cmjw-x23c-76gc/GHSA-cmjw-x23c-76gc.json index 006b2731add..6e0fc2fc121 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmjw-x23c-76gc/GHSA-cmjw-x23c-76gc.json +++ b/advisories/unreviewed/2022/05/GHSA-cmjw-x23c-76gc/GHSA-cmjw-x23c-76gc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cmmp-cpgx-vg8v/GHSA-cmmp-cpgx-vg8v.json b/advisories/unreviewed/2022/05/GHSA-cmmp-cpgx-vg8v/GHSA-cmmp-cpgx-vg8v.json index 42a4b273a22..609f77a9c90 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmmp-cpgx-vg8v/GHSA-cmmp-cpgx-vg8v.json +++ b/advisories/unreviewed/2022/05/GHSA-cmmp-cpgx-vg8v/GHSA-cmmp-cpgx-vg8v.json @@ -7,12 +7,8 @@ "CVE-2020-25208" ], "details": "In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cpp5-h3qh-vqxm/GHSA-cpp5-h3qh-vqxm.json b/advisories/unreviewed/2022/05/GHSA-cpp5-h3qh-vqxm/GHSA-cpp5-h3qh-vqxm.json index 70b666678bb..c41c83a691a 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpp5-h3qh-vqxm/GHSA-cpp5-h3qh-vqxm.json +++ b/advisories/unreviewed/2022/05/GHSA-cpp5-h3qh-vqxm/GHSA-cpp5-h3qh-vqxm.json @@ -7,12 +7,8 @@ "CVE-2021-26023" ], "details": "The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cpvw-q5q7-jhr2/GHSA-cpvw-q5q7-jhr2.json b/advisories/unreviewed/2022/05/GHSA-cpvw-q5q7-jhr2/GHSA-cpvw-q5q7-jhr2.json index 1246471c017..32bad158f27 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpvw-q5q7-jhr2/GHSA-cpvw-q5q7-jhr2.json +++ b/advisories/unreviewed/2022/05/GHSA-cpvw-q5q7-jhr2/GHSA-cpvw-q5q7-jhr2.json @@ -7,12 +7,8 @@ "CVE-2021-25689" ], "details": "An out of bounds write in Teradici PCoIP soft client versions prior to version 20.10.1 could allow an attacker to remotely execute code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cr6g-87jv-237p/GHSA-cr6g-87jv-237p.json b/advisories/unreviewed/2022/05/GHSA-cr6g-87jv-237p/GHSA-cr6g-87jv-237p.json index 4fa584ba19e..cc95898d292 100644 --- a/advisories/unreviewed/2022/05/GHSA-cr6g-87jv-237p/GHSA-cr6g-87jv-237p.json +++ b/advisories/unreviewed/2022/05/GHSA-cr6g-87jv-237p/GHSA-cr6g-87jv-237p.json @@ -7,12 +7,8 @@ "CVE-2020-10554" ], "details": "An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an obfuscated format, which can be easily reverted. For example, the password AAAAAAAA is stored in the database as MMMMMMMM.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-crh9-79wp-32wv/GHSA-crh9-79wp-32wv.json b/advisories/unreviewed/2022/05/GHSA-crh9-79wp-32wv/GHSA-crh9-79wp-32wv.json index 08c39b04d97..1c88b9fbf0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-crh9-79wp-32wv/GHSA-crh9-79wp-32wv.json +++ b/advisories/unreviewed/2022/05/GHSA-crh9-79wp-32wv/GHSA-crh9-79wp-32wv.json @@ -7,12 +7,8 @@ "CVE-2020-8734" ], "details": "Improper input validation in the firmware for Intel(R) Server Board M10JNP2SB before version 7.210 may allow a privileged user to potentially enable escalation of privilege via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cvwc-6hv2-wv97/GHSA-cvwc-6hv2-wv97.json b/advisories/unreviewed/2022/05/GHSA-cvwc-6hv2-wv97/GHSA-cvwc-6hv2-wv97.json index 153ae24f40a..0811e6d8c29 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvwc-6hv2-wv97/GHSA-cvwc-6hv2-wv97.json +++ b/advisories/unreviewed/2022/05/GHSA-cvwc-6hv2-wv97/GHSA-cvwc-6hv2-wv97.json @@ -7,12 +7,8 @@ "CVE-2020-24685" ], "details": "An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial-of-service (DoS) vulnerability. Vulnerability allows attacker to stop the PLC. After stopping (ERR LED flashing red), physical access to the PLC is required in order to restart the application. This issue affects: ABB AC500 V2 products with onboard Ethernet version 2.8.4 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cw43-jrgf-36f3/GHSA-cw43-jrgf-36f3.json b/advisories/unreviewed/2022/05/GHSA-cw43-jrgf-36f3/GHSA-cw43-jrgf-36f3.json index 42d3bbdc576..da7f6817884 100644 --- a/advisories/unreviewed/2022/05/GHSA-cw43-jrgf-36f3/GHSA-cw43-jrgf-36f3.json +++ b/advisories/unreviewed/2022/05/GHSA-cw43-jrgf-36f3/GHSA-cw43-jrgf-36f3.json @@ -7,12 +7,8 @@ "CVE-2021-27167" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. There is a password of four hexadecimal characters for the admin account. These characters are generated in init_3bb_password in libci_adaptation_layer.so.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cww6-qwhh-35x7/GHSA-cww6-qwhh-35x7.json b/advisories/unreviewed/2022/05/GHSA-cww6-qwhh-35x7/GHSA-cww6-qwhh-35x7.json index 5d04ac48a67..374edb8a322 100644 --- a/advisories/unreviewed/2022/05/GHSA-cww6-qwhh-35x7/GHSA-cww6-qwhh-35x7.json +++ b/advisories/unreviewed/2022/05/GHSA-cww6-qwhh-35x7/GHSA-cww6-qwhh-35x7.json @@ -7,12 +7,8 @@ "CVE-2021-1333" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f2cr-m9p8-6vm2/GHSA-f2cr-m9p8-6vm2.json b/advisories/unreviewed/2022/05/GHSA-f2cr-m9p8-6vm2/GHSA-f2cr-m9p8-6vm2.json index 3ab3599a26a..16c8d2e04c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2cr-m9p8-6vm2/GHSA-f2cr-m9p8-6vm2.json +++ b/advisories/unreviewed/2022/05/GHSA-f2cr-m9p8-6vm2/GHSA-f2cr-m9p8-6vm2.json @@ -7,12 +7,8 @@ "CVE-2020-27000" ], "details": "A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing BMP files. This can result in a memory corruption condition. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-12018)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3f2-q9f6-v9qq/GHSA-f3f2-q9f6-v9qq.json b/advisories/unreviewed/2022/05/GHSA-f3f2-q9f6-v9qq/GHSA-f3f2-q9f6-v9qq.json index 9df87969d7c..626a0e340bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3f2-q9f6-v9qq/GHSA-f3f2-q9f6-v9qq.json +++ b/advisories/unreviewed/2022/05/GHSA-f3f2-q9f6-v9qq/GHSA-f3f2-q9f6-v9qq.json @@ -7,12 +7,8 @@ "CVE-2021-26754" ], "details": "wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3fh-qqx3-hv26/GHSA-f3fh-qqx3-hv26.json b/advisories/unreviewed/2022/05/GHSA-f3fh-qqx3-hv26/GHSA-f3fh-qqx3-hv26.json index f0739f4ab25..6b88d54d9ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3fh-qqx3-hv26/GHSA-f3fh-qqx3-hv26.json +++ b/advisories/unreviewed/2022/05/GHSA-f3fh-qqx3-hv26/GHSA-f3fh-qqx3-hv26.json @@ -7,12 +7,8 @@ "CVE-2021-26571" ], "details": "The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f58x-232r-hg99/GHSA-f58x-232r-hg99.json b/advisories/unreviewed/2022/05/GHSA-f58x-232r-hg99/GHSA-f58x-232r-hg99.json index d51812380bd..81031767ff4 100644 --- a/advisories/unreviewed/2022/05/GHSA-f58x-232r-hg99/GHSA-f58x-232r-hg99.json +++ b/advisories/unreviewed/2022/05/GHSA-f58x-232r-hg99/GHSA-f58x-232r-hg99.json @@ -7,12 +7,8 @@ "CVE-2020-13859" ], "details": "An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface framework, allows the undocumented system account mofidev to login to the cgi-bin/luci/quick/wizard management interface without a password by abusing a forgotten-password feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f5jj-fmp8-xqh3/GHSA-f5jj-fmp8-xqh3.json b/advisories/unreviewed/2022/05/GHSA-f5jj-fmp8-xqh3/GHSA-f5jj-fmp8-xqh3.json index 4290ffb9995..ab65cd416f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5jj-fmp8-xqh3/GHSA-f5jj-fmp8-xqh3.json +++ b/advisories/unreviewed/2022/05/GHSA-f5jj-fmp8-xqh3/GHSA-f5jj-fmp8-xqh3.json @@ -7,12 +7,8 @@ "CVE-2021-3350" ], "details": "deleteaccount.php in the Delete Account plugin 1.4 for MyBB allows XSS via the deletereason parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f5wh-3c43-vf4p/GHSA-f5wh-3c43-vf4p.json b/advisories/unreviewed/2022/05/GHSA-f5wh-3c43-vf4p/GHSA-f5wh-3c43-vf4p.json index 87ad2affcd7..00e39b44d82 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5wh-3c43-vf4p/GHSA-f5wh-3c43-vf4p.json +++ b/advisories/unreviewed/2022/05/GHSA-f5wh-3c43-vf4p/GHSA-f5wh-3c43-vf4p.json @@ -7,12 +7,8 @@ "CVE-2021-0329" ], "details": "In several native functions called by AdvertiseManager.java, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the Bluetooth server with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-171400004", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f7jw-wp22-5cv8/GHSA-f7jw-wp22-5cv8.json b/advisories/unreviewed/2022/05/GHSA-f7jw-wp22-5cv8/GHSA-f7jw-wp22-5cv8.json index ac04418c4fe..0ef8634ef6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7jw-wp22-5cv8/GHSA-f7jw-wp22-5cv8.json +++ b/advisories/unreviewed/2022/05/GHSA-f7jw-wp22-5cv8/GHSA-f7jw-wp22-5cv8.json @@ -7,12 +7,8 @@ "CVE-2020-5023" ], "details": "IBM Spectrum Protect Plus 10.1.0 through 10.1.7 could allow a remote user to inject arbitrary data iwhich could cause the serivce to crash due to excess resource consumption. IBM X-Force ID: 193659.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f7q4-mhgv-m69x/GHSA-f7q4-mhgv-m69x.json b/advisories/unreviewed/2022/05/GHSA-f7q4-mhgv-m69x/GHSA-f7q4-mhgv-m69x.json index 8d1d57352a7..55c96fcb734 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7q4-mhgv-m69x/GHSA-f7q4-mhgv-m69x.json +++ b/advisories/unreviewed/2022/05/GHSA-f7q4-mhgv-m69x/GHSA-f7q4-mhgv-m69x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f89f-668c-hrhg/GHSA-f89f-668c-hrhg.json b/advisories/unreviewed/2022/05/GHSA-f89f-668c-hrhg/GHSA-f89f-668c-hrhg.json index 357f22f479f..f710bb469f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-f89f-668c-hrhg/GHSA-f89f-668c-hrhg.json +++ b/advisories/unreviewed/2022/05/GHSA-f89f-668c-hrhg/GHSA-f89f-668c-hrhg.json @@ -7,12 +7,8 @@ "CVE-2021-27165" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The telnet daemon on port 23/tcp can be abused with the gpon/gpon credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f8pq-r7mv-pvxm/GHSA-f8pq-r7mv-pvxm.json b/advisories/unreviewed/2022/05/GHSA-f8pq-r7mv-pvxm/GHSA-f8pq-r7mv-pvxm.json index f1932bd0eb6..e1004befe4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8pq-r7mv-pvxm/GHSA-f8pq-r7mv-pvxm.json +++ b/advisories/unreviewed/2022/05/GHSA-f8pq-r7mv-pvxm/GHSA-f8pq-r7mv-pvxm.json @@ -7,12 +7,8 @@ "CVE-2020-9389" ], "details": "A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented in a way that would enable a malicious user to guess valid username due to a different response time from invalid usernames.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f8xp-mvx7-pw9c/GHSA-f8xp-mvx7-pw9c.json b/advisories/unreviewed/2022/05/GHSA-f8xp-mvx7-pw9c/GHSA-f8xp-mvx7-pw9c.json index 7afcff24b5a..053a2d5df83 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8xp-mvx7-pw9c/GHSA-f8xp-mvx7-pw9c.json +++ b/advisories/unreviewed/2022/05/GHSA-f8xp-mvx7-pw9c/GHSA-f8xp-mvx7-pw9c.json @@ -7,12 +7,8 @@ "CVE-2021-25139" ], "details": "A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500 chassis. This vulnerability could be remotely exploited by an unauthenticated user to cause a stack based buffer overflow using user supplied input to the `khuploadfile.cgi` CGI ELF. The stack based buffer overflow could lead to Remote Code Execution, Denial of Service, and/or compromise system integrity. **Note:** HPE recommends that customers discontinue the use of the HPE Moonshot Provisioning Manager. The HPE Moonshot Provisioning Manager application is discontinued, no longer supported, is not available to download from the HPE Support Center, and no patch is available.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f935-fh29-4mfr/GHSA-f935-fh29-4mfr.json b/advisories/unreviewed/2022/05/GHSA-f935-fh29-4mfr/GHSA-f935-fh29-4mfr.json index 75dbf7b4f99..cfe9b84171d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f935-fh29-4mfr/GHSA-f935-fh29-4mfr.json +++ b/advisories/unreviewed/2022/05/GHSA-f935-fh29-4mfr/GHSA-f935-fh29-4mfr.json @@ -7,12 +7,8 @@ "CVE-2020-29165" ], "details": "PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotely gaining administrator privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f9rw-7p76-h888/GHSA-f9rw-7p76-h888.json b/advisories/unreviewed/2022/05/GHSA-f9rw-7p76-h888/GHSA-f9rw-7p76-h888.json index 86dd3e806c8..3c99a325f35 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9rw-7p76-h888/GHSA-f9rw-7p76-h888.json +++ b/advisories/unreviewed/2022/05/GHSA-f9rw-7p76-h888/GHSA-f9rw-7p76-h888.json @@ -7,12 +7,8 @@ "CVE-2020-14221" ], "details": "HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcf3-mg82-5g5h/GHSA-fcf3-mg82-5g5h.json b/advisories/unreviewed/2022/05/GHSA-fcf3-mg82-5g5h/GHSA-fcf3-mg82-5g5h.json index b679425aea8..792b604817f 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcf3-mg82-5g5h/GHSA-fcf3-mg82-5g5h.json +++ b/advisories/unreviewed/2022/05/GHSA-fcf3-mg82-5g5h/GHSA-fcf3-mg82-5g5h.json @@ -7,12 +7,8 @@ "CVE-2020-26999" ], "details": "A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing of PAR files. This could result in a memory access past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information. (ZDI-CAN-12042)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcrr-6fjg-7jpj/GHSA-fcrr-6fjg-7jpj.json b/advisories/unreviewed/2022/05/GHSA-fcrr-6fjg-7jpj/GHSA-fcrr-6fjg-7jpj.json index 79a62d730ab..889095d3912 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcrr-6fjg-7jpj/GHSA-fcrr-6fjg-7jpj.json +++ b/advisories/unreviewed/2022/05/GHSA-fcrr-6fjg-7jpj/GHSA-fcrr-6fjg-7jpj.json @@ -7,12 +7,8 @@ "CVE-2021-26826" ], "details": "A stack overflow issue exists in Godot Engine up to v3.2 and is caused by improper boundary checks when loading .TGA image files. Depending on the context of the application, attack vector can be local or remote, and can lead to code execution and/or system crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fffm-3rfw-h6pc/GHSA-fffm-3rfw-h6pc.json b/advisories/unreviewed/2022/05/GHSA-fffm-3rfw-h6pc/GHSA-fffm-3rfw-h6pc.json index dd59a774447..0cc546b9272 100644 --- a/advisories/unreviewed/2022/05/GHSA-fffm-3rfw-h6pc/GHSA-fffm-3rfw-h6pc.json +++ b/advisories/unreviewed/2022/05/GHSA-fffm-3rfw-h6pc/GHSA-fffm-3rfw-h6pc.json @@ -7,12 +7,8 @@ "CVE-2021-25774" ], "details": "In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fg9f-2rrg-653x/GHSA-fg9f-2rrg-653x.json b/advisories/unreviewed/2022/05/GHSA-fg9f-2rrg-653x/GHSA-fg9f-2rrg-653x.json index ac02def6256..ced9c161025 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg9f-2rrg-653x/GHSA-fg9f-2rrg-653x.json +++ b/advisories/unreviewed/2022/05/GHSA-fg9f-2rrg-653x/GHSA-fg9f-2rrg-653x.json @@ -7,12 +7,8 @@ "CVE-2021-26577" ], "details": "The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so uploadsshkey function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fg9m-gw92-f74h/GHSA-fg9m-gw92-f74h.json b/advisories/unreviewed/2022/05/GHSA-fg9m-gw92-f74h/GHSA-fg9m-gw92-f74h.json index a7125c13932..991796daf26 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg9m-gw92-f74h/GHSA-fg9m-gw92-f74h.json +++ b/advisories/unreviewed/2022/05/GHSA-fg9m-gw92-f74h/GHSA-fg9m-gw92-f74h.json @@ -7,12 +7,8 @@ "CVE-2020-13408" ], "details": "Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or also later by different users). Both stored, and reflected payloads are triggerable by admin, so malicious non-authenticated user could get admin level access. Even malicious low-privileged user can inject XSS, which can be executed by admin, potentially elevating privileges and obtaining admin access. (issue 2 of 3)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fh7q-6m5q-xqp4/GHSA-fh7q-6m5q-xqp4.json b/advisories/unreviewed/2022/05/GHSA-fh7q-6m5q-xqp4/GHSA-fh7q-6m5q-xqp4.json index b96bba5925c..6ba02fe0ffd 100644 --- a/advisories/unreviewed/2022/05/GHSA-fh7q-6m5q-xqp4/GHSA-fh7q-6m5q-xqp4.json +++ b/advisories/unreviewed/2022/05/GHSA-fh7q-6m5q-xqp4/GHSA-fh7q-6m5q-xqp4.json @@ -7,12 +7,8 @@ "CVE-2021-1291" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These vulnerabilities exist because HTTP requests are not properly validated. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to remotely execute arbitrary code on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fjq4-gjv6-rcj2/GHSA-fjq4-gjv6-rcj2.json b/advisories/unreviewed/2022/05/GHSA-fjq4-gjv6-rcj2/GHSA-fjq4-gjv6-rcj2.json index 318c5be18aa..d52129593a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjq4-gjv6-rcj2/GHSA-fjq4-gjv6-rcj2.json +++ b/advisories/unreviewed/2022/05/GHSA-fjq4-gjv6-rcj2/GHSA-fjq4-gjv6-rcj2.json @@ -7,12 +7,8 @@ "CVE-2020-29021" ], "details": "A vulnerability in web UI input field of GateManager allows authenticated attacker to enter script tags that could cause XSS. This issue affects: GateManager all versions prior to 9.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fp2h-7c85-hmf9/GHSA-fp2h-7c85-hmf9.json b/advisories/unreviewed/2022/05/GHSA-fp2h-7c85-hmf9/GHSA-fp2h-7c85-hmf9.json index c4f4e80ef30..407b5402484 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp2h-7c85-hmf9/GHSA-fp2h-7c85-hmf9.json +++ b/advisories/unreviewed/2022/05/GHSA-fp2h-7c85-hmf9/GHSA-fp2h-7c85-hmf9.json @@ -7,12 +7,8 @@ "CVE-2020-26193" ], "details": "Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain an improper input validation vulnerability. A user with the ISI_PRIV_CLUSTER privilege may exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fp4p-g2rg-7x7r/GHSA-fp4p-g2rg-7x7r.json b/advisories/unreviewed/2022/05/GHSA-fp4p-g2rg-7x7r/GHSA-fp4p-g2rg-7x7r.json index 8dab805cbaa..4c413d0c227 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp4p-g2rg-7x7r/GHSA-fp4p-g2rg-7x7r.json +++ b/advisories/unreviewed/2022/05/GHSA-fp4p-g2rg-7x7r/GHSA-fp4p-g2rg-7x7r.json @@ -7,12 +7,8 @@ "CVE-2020-27870" ], "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of SolarWinds Orion Platform 2020.2.1. Authentication is required to exploit this vulnerability. The specific flaw exists within ExportToPDF.aspx. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-11917.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpwv-gp97-jc85/GHSA-fpwv-gp97-jc85.json b/advisories/unreviewed/2022/05/GHSA-fpwv-gp97-jc85/GHSA-fpwv-gp97-jc85.json index cd834f8f238..6571379f683 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpwv-gp97-jc85/GHSA-fpwv-gp97-jc85.json +++ b/advisories/unreviewed/2022/05/GHSA-fpwv-gp97-jc85/GHSA-fpwv-gp97-jc85.json @@ -7,12 +7,8 @@ "CVE-2021-22304" ], "details": "There is a use after free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). A module may refer to some memory after it has been freed while dealing with some messages. Attackers can exploit this vulnerability by sending specific message to the affected module. This may lead to module crash, compromising normal service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frr5-fmjm-627j/GHSA-frr5-fmjm-627j.json b/advisories/unreviewed/2022/05/GHSA-frr5-fmjm-627j/GHSA-frr5-fmjm-627j.json index 35f162e9cd5..465940093f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-frr5-fmjm-627j/GHSA-frr5-fmjm-627j.json +++ b/advisories/unreviewed/2022/05/GHSA-frr5-fmjm-627j/GHSA-frr5-fmjm-627j.json @@ -7,12 +7,8 @@ "CVE-2020-12122" ], "details": "In Max Secure Max Spyware Detector 1.0.0.044, the driver file (MaxProc64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x2200019. (This also extends to the various other products from Max Secure that include MaxProc64.sys.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fv88-77rc-98g3/GHSA-fv88-77rc-98g3.json b/advisories/unreviewed/2022/05/GHSA-fv88-77rc-98g3/GHSA-fv88-77rc-98g3.json index 433ca1c4a80..01824a69a59 100644 --- a/advisories/unreviewed/2022/05/GHSA-fv88-77rc-98g3/GHSA-fv88-77rc-98g3.json +++ b/advisories/unreviewed/2022/05/GHSA-fv88-77rc-98g3/GHSA-fv88-77rc-98g3.json @@ -7,12 +7,8 @@ "CVE-2021-22267" ], "details": "Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows a remote replay attack for T0320L01^ABP through T0320L01^ABZ, T0952L01^AAH through T0952L01^AAR, T0986L01 through T0986L01^AAF, T0665L01^AAP, and T0662L01^AAP (L) and T0320H01^ABO through T0320H01^ABY, T0952H01^AAG through T0952H01^AAQ, T0986H01 through T0986H01^AAE, T0665H01^AAO, and T0662H01^AAO (J and H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fvj3-9fpr-ff7m/GHSA-fvj3-9fpr-ff7m.json b/advisories/unreviewed/2022/05/GHSA-fvj3-9fpr-ff7m/GHSA-fvj3-9fpr-ff7m.json index 6c44cfe9c2f..9e239ae9e78 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvj3-9fpr-ff7m/GHSA-fvj3-9fpr-ff7m.json +++ b/advisories/unreviewed/2022/05/GHSA-fvj3-9fpr-ff7m/GHSA-fvj3-9fpr-ff7m.json @@ -7,12 +7,8 @@ "CVE-2021-27176" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_5g.cfg has cleartext passwords and 0644 permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fx3j-9hj4-xrxm/GHSA-fx3j-9hj4-xrxm.json b/advisories/unreviewed/2022/05/GHSA-fx3j-9hj4-xrxm/GHSA-fx3j-9hj4-xrxm.json index 27a1c60025e..44265832cab 100644 --- a/advisories/unreviewed/2022/05/GHSA-fx3j-9hj4-xrxm/GHSA-fx3j-9hj4-xrxm.json +++ b/advisories/unreviewed/2022/05/GHSA-fx3j-9hj4-xrxm/GHSA-fx3j-9hj4-xrxm.json @@ -7,12 +7,8 @@ "CVE-2020-25857" ], "details": "The function ClientEAPOLKeyRecvd() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an rtl_memcpy() operation, resulting in a stack buffer overflow which can be exploited for denial of service. An attacker can impersonate an Access Point and attack a vulnerable Wi-Fi client, by injecting a crafted packet into the WPA2 handshake. The attacker does not need to know the network's PSK.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g2hf-3hh4-qwxq/GHSA-g2hf-3hh4-qwxq.json b/advisories/unreviewed/2022/05/GHSA-g2hf-3hh4-qwxq/GHSA-g2hf-3hh4-qwxq.json index baba976e821..17881216ac7 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2hf-3hh4-qwxq/GHSA-g2hf-3hh4-qwxq.json +++ b/advisories/unreviewed/2022/05/GHSA-g2hf-3hh4-qwxq/GHSA-g2hf-3hh4-qwxq.json @@ -7,12 +7,8 @@ "CVE-2021-1342" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g2w2-8h95-w988/GHSA-g2w2-8h95-w988.json b/advisories/unreviewed/2022/05/GHSA-g2w2-8h95-w988/GHSA-g2w2-8h95-w988.json index 306019d0e1b..36e36183e12 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2w2-8h95-w988/GHSA-g2w2-8h95-w988.json +++ b/advisories/unreviewed/2022/05/GHSA-g2w2-8h95-w988/GHSA-g2w2-8h95-w988.json @@ -7,12 +7,8 @@ "CVE-2021-1370" ], "details": "A vulnerability in a CLI command of Cisco IOS XR Software for the Cisco 8000 Series Routers and Network Convergence System 540 Series Routers running NCS540L software images could allow an authenticated, local attacker to elevate their privilege to root. To exploit this vulnerability, an attacker would need to have a valid account on an affected device. The vulnerability is due to insufficient validation of command line arguments. An attacker could exploit this vulnerability by authenticating to the device and entering a crafted command at the prompt. A successful exploit could allow an attacker with low-level privileges to escalate their privilege level to root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g32x-jfqv-9fpx/GHSA-g32x-jfqv-9fpx.json b/advisories/unreviewed/2022/05/GHSA-g32x-jfqv-9fpx/GHSA-g32x-jfqv-9fpx.json index 2ceb59ad162..81750712856 100644 --- a/advisories/unreviewed/2022/05/GHSA-g32x-jfqv-9fpx/GHSA-g32x-jfqv-9fpx.json +++ b/advisories/unreviewed/2022/05/GHSA-g32x-jfqv-9fpx/GHSA-g32x-jfqv-9fpx.json @@ -7,12 +7,8 @@ "CVE-2020-14255" ], "details": "HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These affect containers only. These do not affect traditional on-premise installations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g437-q829-mh8h/GHSA-g437-q829-mh8h.json b/advisories/unreviewed/2022/05/GHSA-g437-q829-mh8h/GHSA-g437-q829-mh8h.json index 6d6c06a267a..721065bcbcb 100644 --- a/advisories/unreviewed/2022/05/GHSA-g437-q829-mh8h/GHSA-g437-q829-mh8h.json +++ b/advisories/unreviewed/2022/05/GHSA-g437-q829-mh8h/GHSA-g437-q829-mh8h.json @@ -7,12 +7,8 @@ "CVE-2021-0343" ], "details": "In kisd, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05449962.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g5mc-mhmx-jqjp/GHSA-g5mc-mhmx-jqjp.json b/advisories/unreviewed/2022/05/GHSA-g5mc-mhmx-jqjp/GHSA-g5mc-mhmx-jqjp.json index 5c71313f85e..5cb49a3103b 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5mc-mhmx-jqjp/GHSA-g5mc-mhmx-jqjp.json +++ b/advisories/unreviewed/2022/05/GHSA-g5mc-mhmx-jqjp/GHSA-g5mc-mhmx-jqjp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6g4-c6r4-f4jc/GHSA-g6g4-c6r4-f4jc.json b/advisories/unreviewed/2022/05/GHSA-g6g4-c6r4-f4jc/GHSA-g6g4-c6r4-f4jc.json index f1c9932f61a..08734e39983 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6g4-c6r4-f4jc/GHSA-g6g4-c6r4-f4jc.json +++ b/advisories/unreviewed/2022/05/GHSA-g6g4-c6r4-f4jc/GHSA-g6g4-c6r4-f4jc.json @@ -7,12 +7,8 @@ "CVE-2020-26194" ], "details": "Dell EMC PowerScale OneFS versions 8.1.2 and 8.2.2 contain an Incorrect Permission Assignment for a Critical Resource vulnerability. This may allow a non-admin user with either ISI_PRIV_LOGIN_CONSOLE or ISI_PRIV_LOGIN_SSH privileges to exploit the vulnerability, leading to compromised cryptographic operations. Note: no non-admin users or roles have these privileges by default.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g7mx-vgq4-79gg/GHSA-g7mx-vgq4-79gg.json b/advisories/unreviewed/2022/05/GHSA-g7mx-vgq4-79gg/GHSA-g7mx-vgq4-79gg.json index e51f2eb0c96..cfaeb8946a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7mx-vgq4-79gg/GHSA-g7mx-vgq4-79gg.json +++ b/advisories/unreviewed/2022/05/GHSA-g7mx-vgq4-79gg/GHSA-g7mx-vgq4-79gg.json @@ -7,12 +7,8 @@ "CVE-2020-17429" ], "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of CMP files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-11337.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g8rv-4ccg-wc6m/GHSA-g8rv-4ccg-wc6m.json b/advisories/unreviewed/2022/05/GHSA-g8rv-4ccg-wc6m/GHSA-g8rv-4ccg-wc6m.json index 5c00e92d413..494cdb03ace 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8rv-4ccg-wc6m/GHSA-g8rv-4ccg-wc6m.json +++ b/advisories/unreviewed/2022/05/GHSA-g8rv-4ccg-wc6m/GHSA-g8rv-4ccg-wc6m.json @@ -7,12 +7,8 @@ "CVE-2020-13186" ], "details": "An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed an attacker with knowledge of both a machineID and user GUID to modify data if a user clicked a malicious link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g985-xxfj-53g5/GHSA-g985-xxfj-53g5.json b/advisories/unreviewed/2022/05/GHSA-g985-xxfj-53g5/GHSA-g985-xxfj-53g5.json index eee5e0b2d3a..4ad24df9949 100644 --- a/advisories/unreviewed/2022/05/GHSA-g985-xxfj-53g5/GHSA-g985-xxfj-53g5.json +++ b/advisories/unreviewed/2022/05/GHSA-g985-xxfj-53g5/GHSA-g985-xxfj-53g5.json @@ -7,12 +7,8 @@ "CVE-2020-29537" ], "details": "Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently authenticate them to the Archer application without the victims realizing an attack occurred.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gcqr-886q-fwf9/GHSA-gcqr-886q-fwf9.json b/advisories/unreviewed/2022/05/GHSA-gcqr-886q-fwf9/GHSA-gcqr-886q-fwf9.json index 982374a031b..0f6b52e6a0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcqr-886q-fwf9/GHSA-gcqr-886q-fwf9.json +++ b/advisories/unreviewed/2022/05/GHSA-gcqr-886q-fwf9/GHSA-gcqr-886q-fwf9.json @@ -7,12 +7,8 @@ "CVE-2021-21142" ], "details": "Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gfvh-r99j-x28p/GHSA-gfvh-r99j-x28p.json b/advisories/unreviewed/2022/05/GHSA-gfvh-r99j-x28p/GHSA-gfvh-r99j-x28p.json index 7d50bae7a1b..8a9e8a6502d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfvh-r99j-x28p/GHSA-gfvh-r99j-x28p.json +++ b/advisories/unreviewed/2022/05/GHSA-gfvh-r99j-x28p/GHSA-gfvh-r99j-x28p.json @@ -7,12 +7,8 @@ "CVE-2020-9307" ], "details": "Hirschmann OS2, RSP, and RSPE devices before HiOS 08.3.00 allow a denial of service. An unauthenticated, adjacent attacker can cause an infinite loop on one of the HSR ring ports of the device. This effectively breaks the redundancy of the HSR ring. If the attacker can perform the same attack on a second device, the ring is broken into two parts (thus disrupting communication between devices in the different parts).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gg53-8j8x-fvvp/GHSA-gg53-8j8x-fvvp.json b/advisories/unreviewed/2022/05/GHSA-gg53-8j8x-fvvp/GHSA-gg53-8j8x-fvvp.json index defa5709ba0..53102759629 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg53-8j8x-fvvp/GHSA-gg53-8j8x-fvvp.json +++ b/advisories/unreviewed/2022/05/GHSA-gg53-8j8x-fvvp/GHSA-gg53-8j8x-fvvp.json @@ -7,12 +7,8 @@ "CVE-2020-17420" ], "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of NEF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-11193.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gg79-jh7g-xcx7/GHSA-gg79-jh7g-xcx7.json b/advisories/unreviewed/2022/05/GHSA-gg79-jh7g-xcx7/GHSA-gg79-jh7g-xcx7.json index 98ab4dc459d..04213d66ff9 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg79-jh7g-xcx7/GHSA-gg79-jh7g-xcx7.json +++ b/advisories/unreviewed/2022/05/GHSA-gg79-jh7g-xcx7/GHSA-gg79-jh7g-xcx7.json @@ -7,12 +7,8 @@ "CVE-2021-25140" ], "details": "A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500 chassis. This vulnerability could be remotely exploited by an unauthenticated user to cause a directory traversal in user supplied input to the `khuploadfile.cgi` CGI ELF. The directory traversal could lead to Remote Code Execution, Denial of Service, and/or compromise system integrity. **Note:** HPE recommends that customers discontinue the use of the HPE Moonshot Provisioning Manager. The HPE Moonshot Provisioning Manager application is discontinued, no longer supported, is not available to download from the HPE Support Center, and no patch is available.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gg7q-8hj5-8hp8/GHSA-gg7q-8hj5-8hp8.json b/advisories/unreviewed/2022/05/GHSA-gg7q-8hj5-8hp8/GHSA-gg7q-8hj5-8hp8.json index aae6670ff8e..62aa4934772 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg7q-8hj5-8hp8/GHSA-gg7q-8hj5-8hp8.json +++ b/advisories/unreviewed/2022/05/GHSA-gg7q-8hj5-8hp8/GHSA-gg7q-8hj5-8hp8.json @@ -7,12 +7,8 @@ "CVE-2021-26221" ], "details": "The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gh27-3g6v-xxcm/GHSA-gh27-3g6v-xxcm.json b/advisories/unreviewed/2022/05/GHSA-gh27-3g6v-xxcm/GHSA-gh27-3g6v-xxcm.json index 6444d7734ab..ee89fcdf1a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-gh27-3g6v-xxcm/GHSA-gh27-3g6v-xxcm.json +++ b/advisories/unreviewed/2022/05/GHSA-gh27-3g6v-xxcm/GHSA-gh27-3g6v-xxcm.json @@ -7,12 +7,8 @@ "CVE-2021-25772" ], "details": "In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gh2p-5gr5-j5g9/GHSA-gh2p-5gr5-j5g9.json b/advisories/unreviewed/2022/05/GHSA-gh2p-5gr5-j5g9/GHSA-gh2p-5gr5-j5g9.json index c670e3533da..81f31b3e849 100644 --- a/advisories/unreviewed/2022/05/GHSA-gh2p-5gr5-j5g9/GHSA-gh2p-5gr5-j5g9.json +++ b/advisories/unreviewed/2022/05/GHSA-gh2p-5gr5-j5g9/GHSA-gh2p-5gr5-j5g9.json @@ -7,12 +7,8 @@ "CVE-2021-26688" ], "details": "An issue was discovered on LG Wing mobile devices with Android OS 10 software. The biometric sensor has weak security properties. The LG ID is LVE-SMP-200030 (February 2021).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gjr3-77hh-vh3q/GHSA-gjr3-77hh-vh3q.json b/advisories/unreviewed/2022/05/GHSA-gjr3-77hh-vh3q/GHSA-gjr3-77hh-vh3q.json index a066b6cc9a1..e73b685fd34 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjr3-77hh-vh3q/GHSA-gjr3-77hh-vh3q.json +++ b/advisories/unreviewed/2022/05/GHSA-gjr3-77hh-vh3q/GHSA-gjr3-77hh-vh3q.json @@ -7,12 +7,8 @@ "CVE-2021-20405" ], "details": "IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to perform unauthorized activities due to improper encoding of output. IBM X-Force ID: 196183.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gm38-v6gv-jm89/GHSA-gm38-v6gv-jm89.json b/advisories/unreviewed/2022/05/GHSA-gm38-v6gv-jm89/GHSA-gm38-v6gv-jm89.json index 7af23b184d2..52d46d31caf 100644 --- a/advisories/unreviewed/2022/05/GHSA-gm38-v6gv-jm89/GHSA-gm38-v6gv-jm89.json +++ b/advisories/unreviewed/2022/05/GHSA-gm38-v6gv-jm89/GHSA-gm38-v6gv-jm89.json @@ -7,12 +7,8 @@ "CVE-2020-17430" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CR2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11332.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gm82-r7hx-vc9c/GHSA-gm82-r7hx-vc9c.json b/advisories/unreviewed/2022/05/GHSA-gm82-r7hx-vc9c/GHSA-gm82-r7hx-vc9c.json index 013a61aebe7..1729aedb285 100644 --- a/advisories/unreviewed/2022/05/GHSA-gm82-r7hx-vc9c/GHSA-gm82-r7hx-vc9c.json +++ b/advisories/unreviewed/2022/05/GHSA-gm82-r7hx-vc9c/GHSA-gm82-r7hx-vc9c.json @@ -7,12 +7,8 @@ "CVE-2021-26914" ], "details": "NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gmfw-w846-fjh2/GHSA-gmfw-w846-fjh2.json b/advisories/unreviewed/2022/05/GHSA-gmfw-w846-fjh2/GHSA-gmfw-w846-fjh2.json index f00325edce6..73b8eb104ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmfw-w846-fjh2/GHSA-gmfw-w846-fjh2.json +++ b/advisories/unreviewed/2022/05/GHSA-gmfw-w846-fjh2/GHSA-gmfw-w846-fjh2.json @@ -7,12 +7,8 @@ "CVE-2020-10552" ], "details": "An issue was discovered in Psyprax before 3.2.2. The Firebird database is accessible with the default user sysdba and password masterke after installation. This allows any user to access it and read and modify the contents, including passwords. Local database files can be accessed directly as well.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gmww-6r9f-5rpf/GHSA-gmww-6r9f-5rpf.json b/advisories/unreviewed/2022/05/GHSA-gmww-6r9f-5rpf/GHSA-gmww-6r9f-5rpf.json index 4b12d35fd15..2a29a307cf1 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmww-6r9f-5rpf/GHSA-gmww-6r9f-5rpf.json +++ b/advisories/unreviewed/2022/05/GHSA-gmww-6r9f-5rpf/GHSA-gmww-6r9f-5rpf.json @@ -7,12 +7,8 @@ "CVE-2020-18737" ], "details": "An issue was discovered in Typora 0.9.67. There is an XSS vulnerability that causes Remote Code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gp7f-w798-4853/GHSA-gp7f-w798-4853.json b/advisories/unreviewed/2022/05/GHSA-gp7f-w798-4853/GHSA-gp7f-w798-4853.json index 06c8dbe2e05..6f45f24988d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gp7f-w798-4853/GHSA-gp7f-w798-4853.json +++ b/advisories/unreviewed/2022/05/GHSA-gp7f-w798-4853/GHSA-gp7f-w798-4853.json @@ -7,12 +7,8 @@ "CVE-2021-26825" ], "details": "An integer overflow issue exists in Godot Engine up to v3.2 that can be triggered when loading specially crafted.TGA image files. The vulnerability exists in ImageLoaderTGA::load_image() function at line: const size_t buffer_size = (tga_header.image_width * tga_header.image_height) * pixel_size; The bug leads to Dynamic stack buffer overflow. Depending on the context of the application, attack vector can be local or remote, and can lead to code execution and/or system crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gr5v-7hm2-h3j8/GHSA-gr5v-7hm2-h3j8.json b/advisories/unreviewed/2022/05/GHSA-gr5v-7hm2-h3j8/GHSA-gr5v-7hm2-h3j8.json index a0d1b648801..c8a343945cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr5v-7hm2-h3j8/GHSA-gr5v-7hm2-h3j8.json +++ b/advisories/unreviewed/2022/05/GHSA-gr5v-7hm2-h3j8/GHSA-gr5v-7hm2-h3j8.json @@ -7,12 +7,8 @@ "CVE-2021-22307" ], "details": "There is a weak algorithm vulnerability in Mate 3010.0.0.203(C00E201R7P2). The protection is insufficient for the modules that should be protected. Local attackers can exploit this vulnerability to affect the integrity of certain module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-grv3-9mhw-h88m/GHSA-grv3-9mhw-h88m.json b/advisories/unreviewed/2022/05/GHSA-grv3-9mhw-h88m/GHSA-grv3-9mhw-h88m.json index 0aefdc8beed..960c572956a 100644 --- a/advisories/unreviewed/2022/05/GHSA-grv3-9mhw-h88m/GHSA-grv3-9mhw-h88m.json +++ b/advisories/unreviewed/2022/05/GHSA-grv3-9mhw-h88m/GHSA-grv3-9mhw-h88m.json @@ -7,12 +7,8 @@ "CVE-2020-17422" ], "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of EPS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-11195.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-grv9-44cv-g58h/GHSA-grv9-44cv-g58h.json b/advisories/unreviewed/2022/05/GHSA-grv9-44cv-g58h/GHSA-grv9-44cv-g58h.json index 44546c8e75e..9db752dfe37 100644 --- a/advisories/unreviewed/2022/05/GHSA-grv9-44cv-g58h/GHSA-grv9-44cv-g58h.json +++ b/advisories/unreviewed/2022/05/GHSA-grv9-44cv-g58h/GHSA-grv9-44cv-g58h.json @@ -7,12 +7,8 @@ "CVE-2021-1354" ], "details": "A vulnerability in the certificate registration process of Cisco Unified Computing System (UCS) Central Software could allow an authenticated, adjacent attacker to register a rogue Cisco Unified Computing System Manager (UCSM). This vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability by sending a crafted HTTP request to the registration API. A successful exploit could allow the attacker to register a rogue Cisco UCSM and gain access to Cisco UCS Central Software data and Cisco UCSM inventory data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gvrm-92xp-96pf/GHSA-gvrm-92xp-96pf.json b/advisories/unreviewed/2022/05/GHSA-gvrm-92xp-96pf/GHSA-gvrm-92xp-96pf.json index ccfe5ea203e..f247fee1be9 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvrm-92xp-96pf/GHSA-gvrm-92xp-96pf.json +++ b/advisories/unreviewed/2022/05/GHSA-gvrm-92xp-96pf/GHSA-gvrm-92xp-96pf.json @@ -7,12 +7,8 @@ "CVE-2021-1347" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gwpc-pw6r-jqv7/GHSA-gwpc-pw6r-jqv7.json b/advisories/unreviewed/2022/05/GHSA-gwpc-pw6r-jqv7/GHSA-gwpc-pw6r-jqv7.json index 9e93bafb640..e3cd44113cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwpc-pw6r-jqv7/GHSA-gwpc-pw6r-jqv7.json +++ b/advisories/unreviewed/2022/05/GHSA-gwpc-pw6r-jqv7/GHSA-gwpc-pw6r-jqv7.json @@ -7,12 +7,8 @@ "CVE-2021-25132" ], "details": "The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice setmediaconfig_func function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h25v-w22w-w3pj/GHSA-h25v-w22w-w3pj.json b/advisories/unreviewed/2022/05/GHSA-h25v-w22w-w3pj/GHSA-h25v-w22w-w3pj.json index 4695a131da3..dbd2826f7fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-h25v-w22w-w3pj/GHSA-h25v-w22w-w3pj.json +++ b/advisories/unreviewed/2022/05/GHSA-h25v-w22w-w3pj/GHSA-h25v-w22w-w3pj.json @@ -7,12 +7,8 @@ "CVE-2019-19005" ], "details": "A bitmap double free in main.c in autotrace 0.31.1 allows attackers to cause an unspecified impact via a malformed bitmap image. This may occur after the use-after-free in CVE-2017-9182.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h28g-q2hc-6vr6/GHSA-h28g-q2hc-6vr6.json b/advisories/unreviewed/2022/05/GHSA-h28g-q2hc-6vr6/GHSA-h28g-q2hc-6vr6.json index b76473a1c66..0240d5acefb 100644 --- a/advisories/unreviewed/2022/05/GHSA-h28g-q2hc-6vr6/GHSA-h28g-q2hc-6vr6.json +++ b/advisories/unreviewed/2022/05/GHSA-h28g-q2hc-6vr6/GHSA-h28g-q2hc-6vr6.json @@ -7,12 +7,8 @@ "CVE-2020-4827" ], "details": "IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 189841.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h376-c6p5-cxvw/GHSA-h376-c6p5-cxvw.json b/advisories/unreviewed/2022/05/GHSA-h376-c6p5-cxvw/GHSA-h376-c6p5-cxvw.json index 5160cc902b4..09c2e5dc8c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-h376-c6p5-cxvw/GHSA-h376-c6p5-cxvw.json +++ b/advisories/unreviewed/2022/05/GHSA-h376-c6p5-cxvw/GHSA-h376-c6p5-cxvw.json @@ -7,12 +7,8 @@ "CVE-2020-27003" ], "details": "A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing TIFF files. This could lead to pointer dereferences of a value obtained from untrusted source. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-12158)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h4mf-p43f-8979/GHSA-h4mf-p43f-8979.json b/advisories/unreviewed/2022/05/GHSA-h4mf-p43f-8979/GHSA-h4mf-p43f-8979.json index fd54cc13182..75a7c27180a 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4mf-p43f-8979/GHSA-h4mf-p43f-8979.json +++ b/advisories/unreviewed/2022/05/GHSA-h4mf-p43f-8979/GHSA-h4mf-p43f-8979.json @@ -7,12 +7,8 @@ "CVE-2020-24335" ], "details": "An issue was discovered in uIP through 1.0, as used in Contiki and Contiki-NG. Domain name parsing lacks bounds checks, allowing an attacker to corrupt memory with crafted DNS packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h583-hm8j-mpm8/GHSA-h583-hm8j-mpm8.json b/advisories/unreviewed/2022/05/GHSA-h583-hm8j-mpm8/GHSA-h583-hm8j-mpm8.json index 559f14ffc95..53116677d09 100644 --- a/advisories/unreviewed/2022/05/GHSA-h583-hm8j-mpm8/GHSA-h583-hm8j-mpm8.json +++ b/advisories/unreviewed/2022/05/GHSA-h583-hm8j-mpm8/GHSA-h583-hm8j-mpm8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h76m-vvhh-g679/GHSA-h76m-vvhh-g679.json b/advisories/unreviewed/2022/05/GHSA-h76m-vvhh-g679/GHSA-h76m-vvhh-g679.json index dcb28a86376..0ac027dc226 100644 --- a/advisories/unreviewed/2022/05/GHSA-h76m-vvhh-g679/GHSA-h76m-vvhh-g679.json +++ b/advisories/unreviewed/2022/05/GHSA-h76m-vvhh-g679/GHSA-h76m-vvhh-g679.json @@ -7,12 +7,8 @@ "CVE-2020-25855" ], "details": "The function AES_UnWRAP() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for a memcpy() operation, resulting in a stack buffer overflow which can be exploited for remote code execution or denial of service. An attacker can impersonate an Access Point and attack a vulnerable Wi-Fi client, by injecting a crafted packet into the WPA2 handshake. The attacker needs to know the network's PSK in order to exploit this.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h8q4-9ggw-gcm9/GHSA-h8q4-9ggw-gcm9.json b/advisories/unreviewed/2022/05/GHSA-h8q4-9ggw-gcm9/GHSA-h8q4-9ggw-gcm9.json index f0a88efa7e6..2904157ef1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8q4-9ggw-gcm9/GHSA-h8q4-9ggw-gcm9.json +++ b/advisories/unreviewed/2022/05/GHSA-h8q4-9ggw-gcm9/GHSA-h8q4-9ggw-gcm9.json @@ -7,12 +7,8 @@ "CVE-2020-8030" ], "details": "A Insecure Temporary File vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to leak the bootstrapToken or modify the configuration file before it is processed, leading to arbitrary modifications of the machine/cluster.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h8qj-5334-gf3v/GHSA-h8qj-5334-gf3v.json b/advisories/unreviewed/2022/05/GHSA-h8qj-5334-gf3v/GHSA-h8qj-5334-gf3v.json index 1e33d8f3618..c27a87d433d 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8qj-5334-gf3v/GHSA-h8qj-5334-gf3v.json +++ b/advisories/unreviewed/2022/05/GHSA-h8qj-5334-gf3v/GHSA-h8qj-5334-gf3v.json @@ -7,12 +7,8 @@ "CVE-2020-24838" ], "details": "An integer overflow has been found in the the latest version of Issuer. The total issuedCount can be zero if the parameter is overly large. An attacker can obtain the private key of the owner issued with a certain 'amount', and the issuedCount can be zero if there is an overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h8qx-36w6-3rc4/GHSA-h8qx-36w6-3rc4.json b/advisories/unreviewed/2022/05/GHSA-h8qx-36w6-3rc4/GHSA-h8qx-36w6-3rc4.json index 4777f8689f7..f374ac73c1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8qx-36w6-3rc4/GHSA-h8qx-36w6-3rc4.json +++ b/advisories/unreviewed/2022/05/GHSA-h8qx-36w6-3rc4/GHSA-h8qx-36w6-3rc4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h94v-c346-344v/GHSA-h94v-c346-344v.json b/advisories/unreviewed/2022/05/GHSA-h94v-c346-344v/GHSA-h94v-c346-344v.json index aa64d7ae91b..0336c9bc5ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-h94v-c346-344v/GHSA-h94v-c346-344v.json +++ b/advisories/unreviewed/2022/05/GHSA-h94v-c346-344v/GHSA-h94v-c346-344v.json @@ -7,12 +7,8 @@ "CVE-2021-27164" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / aisadmin credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h9hf-qq5m-76px/GHSA-h9hf-qq5m-76px.json b/advisories/unreviewed/2022/05/GHSA-h9hf-qq5m-76px/GHSA-h9hf-qq5m-76px.json index eac16697f11..e5dc91e9054 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9hf-qq5m-76px/GHSA-h9hf-qq5m-76px.json +++ b/advisories/unreviewed/2022/05/GHSA-h9hf-qq5m-76px/GHSA-h9hf-qq5m-76px.json @@ -7,12 +7,8 @@ "CVE-2021-25168" ], "details": "The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webupdatecomponent function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h9wv-3h63-q247/GHSA-h9wv-3h63-q247.json b/advisories/unreviewed/2022/05/GHSA-h9wv-3h63-q247/GHSA-h9wv-3h63-q247.json index 6569b2c17c4..f604bf76180 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9wv-3h63-q247/GHSA-h9wv-3h63-q247.json +++ b/advisories/unreviewed/2022/05/GHSA-h9wv-3h63-q247/GHSA-h9wv-3h63-q247.json @@ -7,12 +7,8 @@ "CVE-2021-26529" ], "details": "The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable to remote OOB write attack via connection request after exhausting memory pool.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hccv-rqmr-8xqg/GHSA-hccv-rqmr-8xqg.json b/advisories/unreviewed/2022/05/GHSA-hccv-rqmr-8xqg/GHSA-hccv-rqmr-8xqg.json index 79d539bbc86..e5d0106bccf 100644 --- a/advisories/unreviewed/2022/05/GHSA-hccv-rqmr-8xqg/GHSA-hccv-rqmr-8xqg.json +++ b/advisories/unreviewed/2022/05/GHSA-hccv-rqmr-8xqg/GHSA-hccv-rqmr-8xqg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hcxg-m989-4j63/GHSA-hcxg-m989-4j63.json b/advisories/unreviewed/2022/05/GHSA-hcxg-m989-4j63/GHSA-hcxg-m989-4j63.json index 94b9858a187..62b1a3f1392 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcxg-m989-4j63/GHSA-hcxg-m989-4j63.json +++ b/advisories/unreviewed/2022/05/GHSA-hcxg-m989-4j63/GHSA-hcxg-m989-4j63.json @@ -7,12 +7,8 @@ "CVE-2021-1321" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hfq5-99r6-6f3w/GHSA-hfq5-99r6-6f3w.json b/advisories/unreviewed/2022/05/GHSA-hfq5-99r6-6f3w/GHSA-hfq5-99r6-6f3w.json index 86766417ec0..f7745d2b09a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfq5-99r6-6f3w/GHSA-hfq5-99r6-6f3w.json +++ b/advisories/unreviewed/2022/05/GHSA-hfq5-99r6-6f3w/GHSA-hfq5-99r6-6f3w.json @@ -7,12 +7,8 @@ "CVE-2021-1289" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These vulnerabilities exist because HTTP requests are not properly validated. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to remotely execute arbitrary code on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hg4f-66rp-9985/GHSA-hg4f-66rp-9985.json b/advisories/unreviewed/2022/05/GHSA-hg4f-66rp-9985/GHSA-hg4f-66rp-9985.json index 4f91fa116e5..d559e1a0027 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg4f-66rp-9985/GHSA-hg4f-66rp-9985.json +++ b/advisories/unreviewed/2022/05/GHSA-hg4f-66rp-9985/GHSA-hg4f-66rp-9985.json @@ -7,12 +7,8 @@ "CVE-2021-1326" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hgpj-7pfx-q3m9/GHSA-hgpj-7pfx-q3m9.json b/advisories/unreviewed/2022/05/GHSA-hgpj-7pfx-q3m9/GHSA-hgpj-7pfx-q3m9.json index 961fda9410e..397f607ffc8 100644 --- a/advisories/unreviewed/2022/05/GHSA-hgpj-7pfx-q3m9/GHSA-hgpj-7pfx-q3m9.json +++ b/advisories/unreviewed/2022/05/GHSA-hgpj-7pfx-q3m9/GHSA-hgpj-7pfx-q3m9.json @@ -7,12 +7,8 @@ "CVE-2021-0302" ], "details": "In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10Android ID: A-155287782", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hhgr-rpp9-9whw/GHSA-hhgr-rpp9-9whw.json b/advisories/unreviewed/2022/05/GHSA-hhgr-rpp9-9whw/GHSA-hhgr-rpp9-9whw.json index 0f6df8f5838..51487741159 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhgr-rpp9-9whw/GHSA-hhgr-rpp9-9whw.json +++ b/advisories/unreviewed/2022/05/GHSA-hhgr-rpp9-9whw/GHSA-hhgr-rpp9-9whw.json @@ -7,12 +7,8 @@ "CVE-2021-25275" ], "details": "SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database credentials to access this backend in a file readable by unprivileged users. As a result, any user having access to the filesystem can read database login details from that file, including the login name and its associated password. Then, the credentials can be used to get database owner access to the SWNetPerfMon.DB database. This gives access to the data collected by SolarWinds applications, and leads to admin access to the applications by inserting or changing authentication data stored in the Accounts table of the database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hhm3-x3q6-2xcg/GHSA-hhm3-x3q6-2xcg.json b/advisories/unreviewed/2022/05/GHSA-hhm3-x3q6-2xcg/GHSA-hhm3-x3q6-2xcg.json index 0697ced34ee..2e4b1da710b 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhm3-x3q6-2xcg/GHSA-hhm3-x3q6-2xcg.json +++ b/advisories/unreviewed/2022/05/GHSA-hhm3-x3q6-2xcg/GHSA-hhm3-x3q6-2xcg.json @@ -7,12 +7,8 @@ "CVE-2021-3340" ], "details": "A cross-site scripting (XSS) vulnerability in many forms of Wikindx before 5.7.0 and 6.x through 6.4.0 allows remote attackers to inject arbitrary web script or HTML via the message parameter to index.php?action=initLogon or modules/admin/DELETEIMAGES.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hhrw-95rc-7773/GHSA-hhrw-95rc-7773.json b/advisories/unreviewed/2022/05/GHSA-hhrw-95rc-7773/GHSA-hhrw-95rc-7773.json index 6b6a76d244c..8f6726b63ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhrw-95rc-7773/GHSA-hhrw-95rc-7773.json +++ b/advisories/unreviewed/2022/05/GHSA-hhrw-95rc-7773/GHSA-hhrw-95rc-7773.json @@ -7,12 +7,8 @@ "CVE-2020-17425" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EPS files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11259.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hj7r-x65q-qw8p/GHSA-hj7r-x65q-qw8p.json b/advisories/unreviewed/2022/05/GHSA-hj7r-x65q-qw8p/GHSA-hj7r-x65q-qw8p.json index 53b9be3ee4a..820eaae9951 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj7r-x65q-qw8p/GHSA-hj7r-x65q-qw8p.json +++ b/advisories/unreviewed/2022/05/GHSA-hj7r-x65q-qw8p/GHSA-hj7r-x65q-qw8p.json @@ -7,12 +7,8 @@ "CVE-2020-18717" ], "details": "SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hj87-9mrp-3rp8/GHSA-hj87-9mrp-3rp8.json b/advisories/unreviewed/2022/05/GHSA-hj87-9mrp-3rp8/GHSA-hj87-9mrp-3rp8.json index 381efa53570..ff5efecc126 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj87-9mrp-3rp8/GHSA-hj87-9mrp-3rp8.json +++ b/advisories/unreviewed/2022/05/GHSA-hj87-9mrp-3rp8/GHSA-hj87-9mrp-3rp8.json @@ -7,12 +7,8 @@ "CVE-2021-25241" ], "details": "A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a sweep.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hphj-4pmp-q6gf/GHSA-hphj-4pmp-q6gf.json b/advisories/unreviewed/2022/05/GHSA-hphj-4pmp-q6gf/GHSA-hphj-4pmp-q6gf.json index d2324ec1122..1ef9afd228e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hphj-4pmp-q6gf/GHSA-hphj-4pmp-q6gf.json +++ b/advisories/unreviewed/2022/05/GHSA-hphj-4pmp-q6gf/GHSA-hphj-4pmp-q6gf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hpqm-3mvx-vj45/GHSA-hpqm-3mvx-vj45.json b/advisories/unreviewed/2022/05/GHSA-hpqm-3mvx-vj45/GHSA-hpqm-3mvx-vj45.json index 71b5388483c..9d9f5231ea4 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpqm-3mvx-vj45/GHSA-hpqm-3mvx-vj45.json +++ b/advisories/unreviewed/2022/05/GHSA-hpqm-3mvx-vj45/GHSA-hpqm-3mvx-vj45.json @@ -7,12 +7,8 @@ "CVE-2020-13407" ], "details": "Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or also later by different users). Both stored, and reflected payloads are triggerable by admin, so malicious non-authenticated user could get admin level access. Even malicious low-privileged user can inject XSS, which can be executed by admin, potentially elevating privileges and obtaining admin access. (issue 1 of 3)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hprp-8mpx-26q9/GHSA-hprp-8mpx-26q9.json b/advisories/unreviewed/2022/05/GHSA-hprp-8mpx-26q9/GHSA-hprp-8mpx-26q9.json index 6023a4f327a..84ed16e2df7 100644 --- a/advisories/unreviewed/2022/05/GHSA-hprp-8mpx-26q9/GHSA-hprp-8mpx-26q9.json +++ b/advisories/unreviewed/2022/05/GHSA-hprp-8mpx-26q9/GHSA-hprp-8mpx-26q9.json @@ -7,12 +7,8 @@ "CVE-2021-26915" ], "details": "NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hqmr-r48f-jfqq/GHSA-hqmr-r48f-jfqq.json b/advisories/unreviewed/2022/05/GHSA-hqmr-r48f-jfqq/GHSA-hqmr-r48f-jfqq.json index 546206f6ef9..3429b7ea8f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqmr-r48f-jfqq/GHSA-hqmr-r48f-jfqq.json +++ b/advisories/unreviewed/2022/05/GHSA-hqmr-r48f-jfqq/GHSA-hqmr-r48f-jfqq.json @@ -7,12 +7,8 @@ "CVE-2020-16144" ], "details": "When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and another user uploads a virus the files antivirus app would detect the virus but fails to delete it due to permission issues. This affects the files_antivirus component versions before 0.15.2 for ownCloud.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hrm7-r95m-mcv4/GHSA-hrm7-r95m-mcv4.json b/advisories/unreviewed/2022/05/GHSA-hrm7-r95m-mcv4/GHSA-hrm7-r95m-mcv4.json index d759ef0ec21..628cc4caaf9 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrm7-r95m-mcv4/GHSA-hrm7-r95m-mcv4.json +++ b/advisories/unreviewed/2022/05/GHSA-hrm7-r95m-mcv4/GHSA-hrm7-r95m-mcv4.json @@ -7,12 +7,8 @@ "CVE-2021-1136" ], "details": "Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local attacker to execute unsigned code during the boot process on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvcx-w6jp-qm72/GHSA-hvcx-w6jp-qm72.json b/advisories/unreviewed/2022/05/GHSA-hvcx-w6jp-qm72/GHSA-hvcx-w6jp-qm72.json index a3b46ee453d..bcfd7c68bb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvcx-w6jp-qm72/GHSA-hvcx-w6jp-qm72.json +++ b/advisories/unreviewed/2022/05/GHSA-hvcx-w6jp-qm72/GHSA-hvcx-w6jp-qm72.json @@ -7,12 +7,8 @@ "CVE-2020-28144" ], "details": "Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower. Crafted requests sent to the device may allow remote arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvg7-f66r-gm4v/GHSA-hvg7-f66r-gm4v.json b/advisories/unreviewed/2022/05/GHSA-hvg7-f66r-gm4v/GHSA-hvg7-f66r-gm4v.json index 0466b9fff9a..a4e56baa15a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvg7-f66r-gm4v/GHSA-hvg7-f66r-gm4v.json +++ b/advisories/unreviewed/2022/05/GHSA-hvg7-f66r-gm4v/GHSA-hvg7-f66r-gm4v.json @@ -7,12 +7,8 @@ "CVE-2021-0347" ], "details": "In ccu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05377188.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hwrm-p2xq-q6hh/GHSA-hwrm-p2xq-q6hh.json b/advisories/unreviewed/2022/05/GHSA-hwrm-p2xq-q6hh/GHSA-hwrm-p2xq-q6hh.json index 15ef0c1efe9..9845cf1d451 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwrm-p2xq-q6hh/GHSA-hwrm-p2xq-q6hh.json +++ b/advisories/unreviewed/2022/05/GHSA-hwrm-p2xq-q6hh/GHSA-hwrm-p2xq-q6hh.json @@ -7,12 +7,8 @@ "CVE-2019-17582" ], "details": "A use-after-free in the _zip_dirent_read function of zip_dirent.c in libzip 1.2.0 allows attackers to have an unspecified impact by attempting to unzip a malformed ZIP archive. NOTE: the discoverer states \"This use-after-free is triggered prior to the double free reported in CVE-2017-12858.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hx4m-5mj9-4q84/GHSA-hx4m-5mj9-4q84.json b/advisories/unreviewed/2022/05/GHSA-hx4m-5mj9-4q84/GHSA-hx4m-5mj9-4q84.json index c9d402ed131..a5e54cc35c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx4m-5mj9-4q84/GHSA-hx4m-5mj9-4q84.json +++ b/advisories/unreviewed/2022/05/GHSA-hx4m-5mj9-4q84/GHSA-hx4m-5mj9-4q84.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hxf4-fh6h-hq94/GHSA-hxf4-fh6h-hq94.json b/advisories/unreviewed/2022/05/GHSA-hxf4-fh6h-hq94/GHSA-hxf4-fh6h-hq94.json index aab7966798e..887f51af9d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-hxf4-fh6h-hq94/GHSA-hxf4-fh6h-hq94.json +++ b/advisories/unreviewed/2022/05/GHSA-hxf4-fh6h-hq94/GHSA-hxf4-fh6h-hq94.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j542-2x58-5jg4/GHSA-j542-2x58-5jg4.json b/advisories/unreviewed/2022/05/GHSA-j542-2x58-5jg4/GHSA-j542-2x58-5jg4.json index 856b523668e..550471be515 100644 --- a/advisories/unreviewed/2022/05/GHSA-j542-2x58-5jg4/GHSA-j542-2x58-5jg4.json +++ b/advisories/unreviewed/2022/05/GHSA-j542-2x58-5jg4/GHSA-j542-2x58-5jg4.json @@ -7,12 +7,8 @@ "CVE-2020-15568" ], "details": "TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j58q-jg6x-x4h9/GHSA-j58q-jg6x-x4h9.json b/advisories/unreviewed/2022/05/GHSA-j58q-jg6x-x4h9/GHSA-j58q-jg6x-x4h9.json index 41fffb136f9..40556b989e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-j58q-jg6x-x4h9/GHSA-j58q-jg6x-x4h9.json +++ b/advisories/unreviewed/2022/05/GHSA-j58q-jg6x-x4h9/GHSA-j58q-jg6x-x4h9.json @@ -7,12 +7,8 @@ "CVE-2020-27257" ], "details": "This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type-confusion condition in the Omron CX-One Version 4.60 and prior devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j599-c89v-j989/GHSA-j599-c89v-j989.json b/advisories/unreviewed/2022/05/GHSA-j599-c89v-j989/GHSA-j599-c89v-j989.json index f1e437421aa..b372ec6f7ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-j599-c89v-j989/GHSA-j599-c89v-j989.json +++ b/advisories/unreviewed/2022/05/GHSA-j599-c89v-j989/GHSA-j599-c89v-j989.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j5hw-64m5-6442/GHSA-j5hw-64m5-6442.json b/advisories/unreviewed/2022/05/GHSA-j5hw-64m5-6442/GHSA-j5hw-64m5-6442.json index 805c00b0c2c..b96a34a81b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5hw-64m5-6442/GHSA-j5hw-64m5-6442.json +++ b/advisories/unreviewed/2022/05/GHSA-j5hw-64m5-6442/GHSA-j5hw-64m5-6442.json @@ -7,12 +7,8 @@ "CVE-2021-26530" ], "details": "The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 (compiled with OpenSSL support) is vulnerable to remote OOB write attack via connection request after exhausting memory pool.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j7hh-h4p5-vc2f/GHSA-j7hh-h4p5-vc2f.json b/advisories/unreviewed/2022/05/GHSA-j7hh-h4p5-vc2f/GHSA-j7hh-h4p5-vc2f.json index e70da50ce02..3b9c482708c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7hh-h4p5-vc2f/GHSA-j7hh-h4p5-vc2f.json +++ b/advisories/unreviewed/2022/05/GHSA-j7hh-h4p5-vc2f/GHSA-j7hh-h4p5-vc2f.json @@ -7,12 +7,8 @@ "CVE-2021-27171" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to start a Linux telnetd as root on port 26/tcp by using the CLI interface commands of ddd and shell (or tshell).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j8vm-wc3g-mg6q/GHSA-j8vm-wc3g-mg6q.json b/advisories/unreviewed/2022/05/GHSA-j8vm-wc3g-mg6q/GHSA-j8vm-wc3g-mg6q.json index d5e96c2a4bf..8540fdc3c3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8vm-wc3g-mg6q/GHSA-j8vm-wc3g-mg6q.json +++ b/advisories/unreviewed/2022/05/GHSA-j8vm-wc3g-mg6q/GHSA-j8vm-wc3g-mg6q.json @@ -7,12 +7,8 @@ "CVE-2021-21050" ], "details": "Adobe Photoshop versions 21.2.4 (and earlier) and 22.1.1 (and earlier) are affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jc6g-647j-w9g6/GHSA-jc6g-647j-w9g6.json b/advisories/unreviewed/2022/05/GHSA-jc6g-647j-w9g6/GHSA-jc6g-647j-w9g6.json index 6080cbbe7bf..5d2a36b3184 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc6g-647j-w9g6/GHSA-jc6g-647j-w9g6.json +++ b/advisories/unreviewed/2022/05/GHSA-jc6g-647j-w9g6/GHSA-jc6g-647j-w9g6.json @@ -7,12 +7,8 @@ "CVE-2021-26575" ], "details": "The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletesolvideofile function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jf37-28x2-7p23/GHSA-jf37-28x2-7p23.json b/advisories/unreviewed/2022/05/GHSA-jf37-28x2-7p23/GHSA-jf37-28x2-7p23.json index 77e82e99b60..2f6d6ca21e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf37-28x2-7p23/GHSA-jf37-28x2-7p23.json +++ b/advisories/unreviewed/2022/05/GHSA-jf37-28x2-7p23/GHSA-jf37-28x2-7p23.json @@ -7,12 +7,8 @@ "CVE-2020-17431" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CR2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11333.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jfrg-jw53-7cx6/GHSA-jfrg-jw53-7cx6.json b/advisories/unreviewed/2022/05/GHSA-jfrg-jw53-7cx6/GHSA-jfrg-jw53-7cx6.json index 5586ff4597c..e7363e5bbce 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfrg-jw53-7cx6/GHSA-jfrg-jw53-7cx6.json +++ b/advisories/unreviewed/2022/05/GHSA-jfrg-jw53-7cx6/GHSA-jfrg-jw53-7cx6.json @@ -7,12 +7,8 @@ "CVE-2021-25123" ], "details": "The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice addlicense_func function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jg2g-jq85-v7jw/GHSA-jg2g-jq85-v7jw.json b/advisories/unreviewed/2022/05/GHSA-jg2g-jq85-v7jw/GHSA-jg2g-jq85-v7jw.json index 35d0aca3cd3..ac82ebed90b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jg2g-jq85-v7jw/GHSA-jg2g-jq85-v7jw.json +++ b/advisories/unreviewed/2022/05/GHSA-jg2g-jq85-v7jw/GHSA-jg2g-jq85-v7jw.json @@ -7,12 +7,8 @@ "CVE-2021-21477" ], "details": "SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject malicious code in the drools rules which when executed leads to Remote Code Execution vulnerability enabling the attacker to compromise the underlying host enabling him to impair confidentiality, integrity and availability of the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jgrv-p7rc-9f92/GHSA-jgrv-p7rc-9f92.json b/advisories/unreviewed/2022/05/GHSA-jgrv-p7rc-9f92/GHSA-jgrv-p7rc-9f92.json index 68a8944ff9f..21e163f2ede 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgrv-p7rc-9f92/GHSA-jgrv-p7rc-9f92.json +++ b/advisories/unreviewed/2022/05/GHSA-jgrv-p7rc-9f92/GHSA-jgrv-p7rc-9f92.json @@ -7,12 +7,8 @@ "CVE-2021-26528" ], "details": "The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connection request after exhausting memory pool.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jj2g-rjph-qhjr/GHSA-jj2g-rjph-qhjr.json b/advisories/unreviewed/2022/05/GHSA-jj2g-rjph-qhjr/GHSA-jj2g-rjph-qhjr.json index f700c59db34..a1bb7037808 100644 --- a/advisories/unreviewed/2022/05/GHSA-jj2g-rjph-qhjr/GHSA-jj2g-rjph-qhjr.json +++ b/advisories/unreviewed/2022/05/GHSA-jj2g-rjph-qhjr/GHSA-jj2g-rjph-qhjr.json @@ -7,12 +7,8 @@ "CVE-2020-8587" ], "details": "OnCommand System Manager 9.x versions prior to 9.3P20 and 9.4 prior to 9.4P3 are susceptible to a vulnerability that could allow HTTP clients to cache sensitive responses making them accessible to an attacker who has access to the system where the client runs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jj87-p2gw-m6qq/GHSA-jj87-p2gw-m6qq.json b/advisories/unreviewed/2022/05/GHSA-jj87-p2gw-m6qq/GHSA-jj87-p2gw-m6qq.json index 3debe89df7c..700239cf8a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-jj87-p2gw-m6qq/GHSA-jj87-p2gw-m6qq.json +++ b/advisories/unreviewed/2022/05/GHSA-jj87-p2gw-m6qq/GHSA-jj87-p2gw-m6qq.json @@ -7,12 +7,8 @@ "CVE-2020-35482" ], "details": "SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jjwh-245w-f2xg/GHSA-jjwh-245w-f2xg.json b/advisories/unreviewed/2022/05/GHSA-jjwh-245w-f2xg/GHSA-jjwh-245w-f2xg.json index ba97cc0158b..c714dc35119 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjwh-245w-f2xg/GHSA-jjwh-245w-f2xg.json +++ b/advisories/unreviewed/2022/05/GHSA-jjwh-245w-f2xg/GHSA-jjwh-245w-f2xg.json @@ -7,12 +7,8 @@ "CVE-2021-26550" ], "details": "An issue was discovered in SmartFoxServer 2.17.0. Cleartext password disclosure can occur via /config/server.xml.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jm2j-8hvq-7r72/GHSA-jm2j-8hvq-7r72.json b/advisories/unreviewed/2022/05/GHSA-jm2j-8hvq-7r72/GHSA-jm2j-8hvq-7r72.json index b1350b0bae0..5f031885610 100644 --- a/advisories/unreviewed/2022/05/GHSA-jm2j-8hvq-7r72/GHSA-jm2j-8hvq-7r72.json +++ b/advisories/unreviewed/2022/05/GHSA-jm2j-8hvq-7r72/GHSA-jm2j-8hvq-7r72.json @@ -7,12 +7,8 @@ "CVE-2020-13462" ], "details": "Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in version R20-2 GA.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jmqg-77rm-wvw3/GHSA-jmqg-77rm-wvw3.json b/advisories/unreviewed/2022/05/GHSA-jmqg-77rm-wvw3/GHSA-jmqg-77rm-wvw3.json index 16f3448707e..6213a8d3e04 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmqg-77rm-wvw3/GHSA-jmqg-77rm-wvw3.json +++ b/advisories/unreviewed/2022/05/GHSA-jmqg-77rm-wvw3/GHSA-jmqg-77rm-wvw3.json @@ -7,12 +7,8 @@ "CVE-2020-13409" ], "details": "Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or also later by different users). Both stored, and reflected payloads are triggerable by admin, so malicious non-authenticated user could get admin level access. Even malicious low-privileged user can inject XSS, which can be executed by admin, potentially elevating privileges and obtaining admin access. (issue 3 of 3)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jp35-qr97-xjcm/GHSA-jp35-qr97-xjcm.json b/advisories/unreviewed/2022/05/GHSA-jp35-qr97-xjcm/GHSA-jp35-qr97-xjcm.json index 480477a9b11..080300d4703 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp35-qr97-xjcm/GHSA-jp35-qr97-xjcm.json +++ b/advisories/unreviewed/2022/05/GHSA-jp35-qr97-xjcm/GHSA-jp35-qr97-xjcm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jppm-4p62-v2cm/GHSA-jppm-4p62-v2cm.json b/advisories/unreviewed/2022/05/GHSA-jppm-4p62-v2cm/GHSA-jppm-4p62-v2cm.json index 824c05d5e4b..8f81422a2da 100644 --- a/advisories/unreviewed/2022/05/GHSA-jppm-4p62-v2cm/GHSA-jppm-4p62-v2cm.json +++ b/advisories/unreviewed/2022/05/GHSA-jppm-4p62-v2cm/GHSA-jppm-4p62-v2cm.json @@ -7,12 +7,8 @@ "CVE-2021-26303" ], "details": "PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jpr2-8h3g-8rc7/GHSA-jpr2-8h3g-8rc7.json b/advisories/unreviewed/2022/05/GHSA-jpr2-8h3g-8rc7/GHSA-jpr2-8h3g-8rc7.json index bd18d9d838c..b9dd52df4df 100644 --- a/advisories/unreviewed/2022/05/GHSA-jpr2-8h3g-8rc7/GHSA-jpr2-8h3g-8rc7.json +++ b/advisories/unreviewed/2022/05/GHSA-jpr2-8h3g-8rc7/GHSA-jpr2-8h3g-8rc7.json @@ -7,12 +7,8 @@ "CVE-2021-21057" ], "details": "Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a null pointer dereference vulnerability when parsing a specially crafted PDF file. An unauthenticated attacker could leverage this vulnerability to achieve denial of service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jq4p-7627-9cwr/GHSA-jq4p-7627-9cwr.json b/advisories/unreviewed/2022/05/GHSA-jq4p-7627-9cwr/GHSA-jq4p-7627-9cwr.json index 0b2c72081ec..da9b0bac14c 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq4p-7627-9cwr/GHSA-jq4p-7627-9cwr.json +++ b/advisories/unreviewed/2022/05/GHSA-jq4p-7627-9cwr/GHSA-jq4p-7627-9cwr.json @@ -7,12 +7,8 @@ "CVE-2021-27139" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to extract information from the device without authentication by disabling JavaScript and visiting /info.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jr6m-ghrv-gqr2/GHSA-jr6m-ghrv-gqr2.json b/advisories/unreviewed/2022/05/GHSA-jr6m-ghrv-gqr2/GHSA-jr6m-ghrv-gqr2.json index c91c1fc7181..9d3f90bca9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jr6m-ghrv-gqr2/GHSA-jr6m-ghrv-gqr2.json +++ b/advisories/unreviewed/2022/05/GHSA-jr6m-ghrv-gqr2/GHSA-jr6m-ghrv-gqr2.json @@ -7,12 +7,8 @@ "CVE-2021-25135" ], "details": "The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice setsmtp_func function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jvmc-mjgh-r2hj/GHSA-jvmc-mjgh-r2hj.json b/advisories/unreviewed/2022/05/GHSA-jvmc-mjgh-r2hj/GHSA-jvmc-mjgh-r2hj.json index 038f0a65f39..2ade3e2941b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvmc-mjgh-r2hj/GHSA-jvmc-mjgh-r2hj.json +++ b/advisories/unreviewed/2022/05/GHSA-jvmc-mjgh-r2hj/GHSA-jvmc-mjgh-r2hj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jvxj-9x2f-rj8h/GHSA-jvxj-9x2f-rj8h.json b/advisories/unreviewed/2022/05/GHSA-jvxj-9x2f-rj8h/GHSA-jvxj-9x2f-rj8h.json index 78aaa4fdf09..f2d4fb1641b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvxj-9x2f-rj8h/GHSA-jvxj-9x2f-rj8h.json +++ b/advisories/unreviewed/2022/05/GHSA-jvxj-9x2f-rj8h/GHSA-jvxj-9x2f-rj8h.json @@ -7,12 +7,8 @@ "CVE-2021-27174" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. wifi_custom.cfg has cleartext passwords and 0644 permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m2cf-c967-wmcg/GHSA-m2cf-c967-wmcg.json b/advisories/unreviewed/2022/05/GHSA-m2cf-c967-wmcg/GHSA-m2cf-c967-wmcg.json index cc45e8bf45f..4513ec3a8e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2cf-c967-wmcg/GHSA-m2cf-c967-wmcg.json +++ b/advisories/unreviewed/2022/05/GHSA-m2cf-c967-wmcg/GHSA-m2cf-c967-wmcg.json @@ -7,12 +7,8 @@ "CVE-2020-26192" ], "details": "Dell EMC PowerScale OneFS versions 8.2.0 - 9.1.0 contain a privilege escalation vulnerability. A non-admin user with either ISI_PRIV_LOGIN_CONSOLE or ISI_PRIV_LOGIN_SSH may potentially exploit this vulnerability to read arbitrary data, tamper with system software or deny service to users. Note: no non-admin users or roles have these privileges by default.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m2f3-4gc2-3wcw/GHSA-m2f3-4gc2-3wcw.json b/advisories/unreviewed/2022/05/GHSA-m2f3-4gc2-3wcw/GHSA-m2f3-4gc2-3wcw.json index f8b4a119bdc..107aea0b06d 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2f3-4gc2-3wcw/GHSA-m2f3-4gc2-3wcw.json +++ b/advisories/unreviewed/2022/05/GHSA-m2f3-4gc2-3wcw/GHSA-m2f3-4gc2-3wcw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m2vv-94mg-crph/GHSA-m2vv-94mg-crph.json b/advisories/unreviewed/2022/05/GHSA-m2vv-94mg-crph/GHSA-m2vv-94mg-crph.json index 1e285ff7c1f..90561810850 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2vv-94mg-crph/GHSA-m2vv-94mg-crph.json +++ b/advisories/unreviewed/2022/05/GHSA-m2vv-94mg-crph/GHSA-m2vv-94mg-crph.json @@ -7,12 +7,8 @@ "CVE-2021-3394" ], "details": "Millennium Millewin (also known as \"Cartella clinica\") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder permissions allowing a malicious user for a local privilege escalation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m435-vjxm-8mmm/GHSA-m435-vjxm-8mmm.json b/advisories/unreviewed/2022/05/GHSA-m435-vjxm-8mmm/GHSA-m435-vjxm-8mmm.json index eca382ff857..65a85f93894 100644 --- a/advisories/unreviewed/2022/05/GHSA-m435-vjxm-8mmm/GHSA-m435-vjxm-8mmm.json +++ b/advisories/unreviewed/2022/05/GHSA-m435-vjxm-8mmm/GHSA-m435-vjxm-8mmm.json @@ -7,12 +7,8 @@ "CVE-2021-27166" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The password for the enable command is gpon.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m459-j5mw-gjwx/GHSA-m459-j5mw-gjwx.json b/advisories/unreviewed/2022/05/GHSA-m459-j5mw-gjwx/GHSA-m459-j5mw-gjwx.json index 783258e16d8..1e332745d02 100644 --- a/advisories/unreviewed/2022/05/GHSA-m459-j5mw-gjwx/GHSA-m459-j5mw-gjwx.json +++ b/advisories/unreviewed/2022/05/GHSA-m459-j5mw-gjwx/GHSA-m459-j5mw-gjwx.json @@ -7,12 +7,8 @@ "CVE-2021-3191" ], "details": "Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows Remote Unauthorized Access for T0320L01^ABY and T0320L01^ACD, T0952L01^AAR through T0952L01^AAX, and T0986L01^AAD through T0986L01^AAJ (L) and T0320H01^ABW through T0320H01^ACC, T0952H01^AAQ through T0952H01^AAW, and T0986H01^AAC through T0986H01^AAI (J and H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m46p-66jf-359p/GHSA-m46p-66jf-359p.json b/advisories/unreviewed/2022/05/GHSA-m46p-66jf-359p/GHSA-m46p-66jf-359p.json index 51550cf99bc..35acabf7d6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-m46p-66jf-359p/GHSA-m46p-66jf-359p.json +++ b/advisories/unreviewed/2022/05/GHSA-m46p-66jf-359p/GHSA-m46p-66jf-359p.json @@ -7,12 +7,8 @@ "CVE-2021-1323" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m6m2-gp24-h5jf/GHSA-m6m2-gp24-h5jf.json b/advisories/unreviewed/2022/05/GHSA-m6m2-gp24-h5jf/GHSA-m6m2-gp24-h5jf.json index 3565762d758..c054054bc64 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6m2-gp24-h5jf/GHSA-m6m2-gp24-h5jf.json +++ b/advisories/unreviewed/2022/05/GHSA-m6m2-gp24-h5jf/GHSA-m6m2-gp24-h5jf.json @@ -7,12 +7,8 @@ "CVE-2021-1330" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m6q8-v2r4-m7g8/GHSA-m6q8-v2r4-m7g8.json b/advisories/unreviewed/2022/05/GHSA-m6q8-v2r4-m7g8/GHSA-m6q8-v2r4-m7g8.json index 45850b3c18a..ecf97fe7362 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6q8-v2r4-m7g8/GHSA-m6q8-v2r4-m7g8.json +++ b/advisories/unreviewed/2022/05/GHSA-m6q8-v2r4-m7g8/GHSA-m6q8-v2r4-m7g8.json @@ -7,12 +7,8 @@ "CVE-2021-25131" ], "details": "The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice setfwimagelocation_func function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m7gv-q624-c5p2/GHSA-m7gv-q624-c5p2.json b/advisories/unreviewed/2022/05/GHSA-m7gv-q624-c5p2/GHSA-m7gv-q624-c5p2.json index c49ae44527c..d8887502a8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7gv-q624-c5p2/GHSA-m7gv-q624-c5p2.json +++ b/advisories/unreviewed/2022/05/GHSA-m7gv-q624-c5p2/GHSA-m7gv-q624-c5p2.json @@ -7,12 +7,8 @@ "CVE-2021-1328" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m963-w3jc-59w6/GHSA-m963-w3jc-59w6.json b/advisories/unreviewed/2022/05/GHSA-m963-w3jc-59w6/GHSA-m963-w3jc-59w6.json index be7bf3ab4f3..b3436afe729 100644 --- a/advisories/unreviewed/2022/05/GHSA-m963-w3jc-59w6/GHSA-m963-w3jc-59w6.json +++ b/advisories/unreviewed/2022/05/GHSA-m963-w3jc-59w6/GHSA-m963-w3jc-59w6.json @@ -7,12 +7,8 @@ "CVE-2021-21119" ], "details": "Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mc4x-hxj7-qw79/GHSA-mc4x-hxj7-qw79.json b/advisories/unreviewed/2022/05/GHSA-mc4x-hxj7-qw79/GHSA-mc4x-hxj7-qw79.json index be1a55f9dc0..988b2f58180 100644 --- a/advisories/unreviewed/2022/05/GHSA-mc4x-hxj7-qw79/GHSA-mc4x-hxj7-qw79.json +++ b/advisories/unreviewed/2022/05/GHSA-mc4x-hxj7-qw79/GHSA-mc4x-hxj7-qw79.json @@ -7,12 +7,8 @@ "CVE-2021-26723" ], "details": "Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mc75-95xp-qm8h/GHSA-mc75-95xp-qm8h.json b/advisories/unreviewed/2022/05/GHSA-mc75-95xp-qm8h/GHSA-mc75-95xp-qm8h.json index 4a829b8517d..7e753dab7cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-mc75-95xp-qm8h/GHSA-mc75-95xp-qm8h.json +++ b/advisories/unreviewed/2022/05/GHSA-mc75-95xp-qm8h/GHSA-mc75-95xp-qm8h.json @@ -7,12 +7,8 @@ "CVE-2020-4828" ], "details": "IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to web cache poisoning, caused by improper input validation by modifying HTTP request headers. IBM X-Force ID: 189842.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mc8g-ggcr-f8mw/GHSA-mc8g-ggcr-f8mw.json b/advisories/unreviewed/2022/05/GHSA-mc8g-ggcr-f8mw/GHSA-mc8g-ggcr-f8mw.json index fa184da69d8..6dab22f5a2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mc8g-ggcr-f8mw/GHSA-mc8g-ggcr-f8mw.json +++ b/advisories/unreviewed/2022/05/GHSA-mc8g-ggcr-f8mw/GHSA-mc8g-ggcr-f8mw.json @@ -7,12 +7,8 @@ "CVE-2021-0333" ], "details": "In onCreate of BluetoothPermissionActivity.java, there is a possible permissions bypass due to a tapjacking overlay that obscures the phonebook permissions dialog when a Bluetooth device is connecting. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-168504491", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mcfg-rxc6-8cwx/GHSA-mcfg-rxc6-8cwx.json b/advisories/unreviewed/2022/05/GHSA-mcfg-rxc6-8cwx/GHSA-mcfg-rxc6-8cwx.json index 5eae35ae6e9..1b10d55b302 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcfg-rxc6-8cwx/GHSA-mcfg-rxc6-8cwx.json +++ b/advisories/unreviewed/2022/05/GHSA-mcfg-rxc6-8cwx/GHSA-mcfg-rxc6-8cwx.json @@ -7,12 +7,8 @@ "CVE-2021-21118" ], "details": "Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mcj9-phjm-5g8v/GHSA-mcj9-phjm-5g8v.json b/advisories/unreviewed/2022/05/GHSA-mcj9-phjm-5g8v/GHSA-mcj9-phjm-5g8v.json index 47fb7b59c98..20adb99f384 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcj9-phjm-5g8v/GHSA-mcj9-phjm-5g8v.json +++ b/advisories/unreviewed/2022/05/GHSA-mcj9-phjm-5g8v/GHSA-mcj9-phjm-5g8v.json @@ -7,12 +7,8 @@ "CVE-2020-36109" ], "details": "ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function of the httpd module that can cause code execution when an attacker constructs malicious data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mf96-wwv9-c857/GHSA-mf96-wwv9-c857.json b/advisories/unreviewed/2022/05/GHSA-mf96-wwv9-c857/GHSA-mf96-wwv9-c857.json index 8afa5547944..c6645c2c169 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf96-wwv9-c857/GHSA-mf96-wwv9-c857.json +++ b/advisories/unreviewed/2022/05/GHSA-mf96-wwv9-c857/GHSA-mf96-wwv9-c857.json @@ -7,12 +7,8 @@ "CVE-2020-25493" ], "details": "Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using XOR with a hardcoded key, which allows for the possibility to decode the traffic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mh5f-wj35-7j92/GHSA-mh5f-wj35-7j92.json b/advisories/unreviewed/2022/05/GHSA-mh5f-wj35-7j92/GHSA-mh5f-wj35-7j92.json index f8ab100e9e4..40ab7181393 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh5f-wj35-7j92/GHSA-mh5f-wj35-7j92.json +++ b/advisories/unreviewed/2022/05/GHSA-mh5f-wj35-7j92/GHSA-mh5f-wj35-7j92.json @@ -7,12 +7,8 @@ "CVE-2020-36151" ], "details": "Incorrect handling of input data in mysofa_resampler_reset_mem function in the libmysofa library 0.5 - 1.1 will lead to heap buffer overflow and overwriting large memory block.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mj7w-qf57-2p89/GHSA-mj7w-qf57-2p89.json b/advisories/unreviewed/2022/05/GHSA-mj7w-qf57-2p89/GHSA-mj7w-qf57-2p89.json index dc8979239de..ec8b843291f 100644 --- a/advisories/unreviewed/2022/05/GHSA-mj7w-qf57-2p89/GHSA-mj7w-qf57-2p89.json +++ b/advisories/unreviewed/2022/05/GHSA-mj7w-qf57-2p89/GHSA-mj7w-qf57-2p89.json @@ -7,12 +7,8 @@ "CVE-2021-27162" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / tattoo@home credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjfh-rmmm-2mm7/GHSA-mjfh-rmmm-2mm7.json b/advisories/unreviewed/2022/05/GHSA-mjfh-rmmm-2mm7/GHSA-mjfh-rmmm-2mm7.json index 059c284a039..4a51cddda64 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjfh-rmmm-2mm7/GHSA-mjfh-rmmm-2mm7.json +++ b/advisories/unreviewed/2022/05/GHSA-mjfh-rmmm-2mm7/GHSA-mjfh-rmmm-2mm7.json @@ -7,12 +7,8 @@ "CVE-2020-8294" ], "details": "A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when saving a 'javascript:' URL in markdown format.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mpq7-9rx8-2r9g/GHSA-mpq7-9rx8-2r9g.json b/advisories/unreviewed/2022/05/GHSA-mpq7-9rx8-2r9g/GHSA-mpq7-9rx8-2r9g.json index 2576d9e5723..f21ade6c98d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpq7-9rx8-2r9g/GHSA-mpq7-9rx8-2r9g.json +++ b/advisories/unreviewed/2022/05/GHSA-mpq7-9rx8-2r9g/GHSA-mpq7-9rx8-2r9g.json @@ -7,12 +7,8 @@ "CVE-2021-27175" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_2g.cfg has cleartext passwords and 0644 permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mqxh-622h-wcpq/GHSA-mqxh-622h-wcpq.json b/advisories/unreviewed/2022/05/GHSA-mqxh-622h-wcpq/GHSA-mqxh-622h-wcpq.json index 80e31be5d30..29069d6dc7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqxh-622h-wcpq/GHSA-mqxh-622h-wcpq.json +++ b/advisories/unreviewed/2022/05/GHSA-mqxh-622h-wcpq/GHSA-mqxh-622h-wcpq.json @@ -7,12 +7,8 @@ "CVE-2021-25138" ], "details": "The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice uploadsshkey function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mrf7-f24r-vmc7/GHSA-mrf7-f24r-vmc7.json b/advisories/unreviewed/2022/05/GHSA-mrf7-f24r-vmc7/GHSA-mrf7-f24r-vmc7.json index c36b846d6e1..24fe92d4a86 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrf7-f24r-vmc7/GHSA-mrf7-f24r-vmc7.json +++ b/advisories/unreviewed/2022/05/GHSA-mrf7-f24r-vmc7/GHSA-mrf7-f24r-vmc7.json @@ -7,12 +7,8 @@ "CVE-2020-8806" ], "details": "Electric Coin Company Zcashd before 2.1.1-1 allows attackers to trigger consensus failure and double spending. A valid chain could be incorrectly rejected because timestamp requirements on block headers were not properly enforced.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mvjc-69q9-xg49/GHSA-mvjc-69q9-xg49.json b/advisories/unreviewed/2022/05/GHSA-mvjc-69q9-xg49/GHSA-mvjc-69q9-xg49.json index 73b8408f9e3..8dd7d106097 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvjc-69q9-xg49/GHSA-mvjc-69q9-xg49.json +++ b/advisories/unreviewed/2022/05/GHSA-mvjc-69q9-xg49/GHSA-mvjc-69q9-xg49.json @@ -7,12 +7,8 @@ "CVE-2020-5032" ], "details": "IBM QRadar SIEM 7.3 and 7.4 in some configurations may be vulnerable to a temporary denial of service attack when sent particular payloads. IBM X-Force ID: 194178.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mx9p-p4m9-xg4c/GHSA-mx9p-p4m9-xg4c.json b/advisories/unreviewed/2022/05/GHSA-mx9p-p4m9-xg4c/GHSA-mx9p-p4m9-xg4c.json index 020d877360f..5294ac36c8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx9p-p4m9-xg4c/GHSA-mx9p-p4m9-xg4c.json +++ b/advisories/unreviewed/2022/05/GHSA-mx9p-p4m9-xg4c/GHSA-mx9p-p4m9-xg4c.json @@ -7,12 +7,8 @@ "CVE-2021-21435" ], "details": "Article Bcc fields and agent personal information are shown when customer prints the ticket (PDF) via external interface. This issue affects: OTRS AG OTRS 7.0.x version 7.0.23 and prior versions; 8.0.x version 8.0.10 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p269-cjrj-rq9c/GHSA-p269-cjrj-rq9c.json b/advisories/unreviewed/2022/05/GHSA-p269-cjrj-rq9c/GHSA-p269-cjrj-rq9c.json index a181933d238..06a5750a9fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-p269-cjrj-rq9c/GHSA-p269-cjrj-rq9c.json +++ b/advisories/unreviewed/2022/05/GHSA-p269-cjrj-rq9c/GHSA-p269-cjrj-rq9c.json @@ -7,12 +7,8 @@ "CVE-2021-22303" ], "details": "There is a pointer double free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). There is a lack of muti-thread protection when a function is called. Attackers can exploit this vulnerability by performing malicious operation to cause pointer double free. This may lead to module crash, compromising normal service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p34g-h4wv-4pj4/GHSA-p34g-h4wv-4pj4.json b/advisories/unreviewed/2022/05/GHSA-p34g-h4wv-4pj4/GHSA-p34g-h4wv-4pj4.json index 83dfb4ae51d..293ae660485 100644 --- a/advisories/unreviewed/2022/05/GHSA-p34g-h4wv-4pj4/GHSA-p34g-h4wv-4pj4.json +++ b/advisories/unreviewed/2022/05/GHSA-p34g-h4wv-4pj4/GHSA-p34g-h4wv-4pj4.json @@ -7,12 +7,8 @@ "CVE-2021-0352" ], "details": "In RT regmap driver, there is a possible memory corruption due to type confusion. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05453809.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p43g-84w6-pq26/GHSA-p43g-84w6-pq26.json b/advisories/unreviewed/2022/05/GHSA-p43g-84w6-pq26/GHSA-p43g-84w6-pq26.json index 10797795b9e..578713f28c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-p43g-84w6-pq26/GHSA-p43g-84w6-pq26.json +++ b/advisories/unreviewed/2022/05/GHSA-p43g-84w6-pq26/GHSA-p43g-84w6-pq26.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -71,9 +69,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p4gx-9mrp-846w/GHSA-p4gx-9mrp-846w.json b/advisories/unreviewed/2022/05/GHSA-p4gx-9mrp-846w/GHSA-p4gx-9mrp-846w.json index e8d235abccb..5ca63cab170 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4gx-9mrp-846w/GHSA-p4gx-9mrp-846w.json +++ b/advisories/unreviewed/2022/05/GHSA-p4gx-9mrp-846w/GHSA-p4gx-9mrp-846w.json @@ -7,12 +7,8 @@ "CVE-2021-27158" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded L1vt1m4eng / 888888 credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p4j3-3c38-6j6r/GHSA-p4j3-3c38-6j6r.json b/advisories/unreviewed/2022/05/GHSA-p4j3-3c38-6j6r/GHSA-p4j3-3c38-6j6r.json index 2a61d8e4944..3e56b03c395 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4j3-3c38-6j6r/GHSA-p4j3-3c38-6j6r.json +++ b/advisories/unreviewed/2022/05/GHSA-p4j3-3c38-6j6r/GHSA-p4j3-3c38-6j6r.json @@ -7,12 +7,8 @@ "CVE-2021-20654" ], "details": "Wekan, open source kanban board system, between version 3.12 and 4.11, is vulnerable to multiple stored cross-site scripting. This is named 'Fieldbleed' in the vendor's site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p5r5-rf4r-f8jm/GHSA-p5r5-rf4r-f8jm.json b/advisories/unreviewed/2022/05/GHSA-p5r5-rf4r-f8jm/GHSA-p5r5-rf4r-f8jm.json index b1270456d69..9df4c4c26dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5r5-rf4r-f8jm/GHSA-p5r5-rf4r-f8jm.json +++ b/advisories/unreviewed/2022/05/GHSA-p5r5-rf4r-f8jm/GHSA-p5r5-rf4r-f8jm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p5wf-rj4w-hc7f/GHSA-p5wf-rj4w-hc7f.json b/advisories/unreviewed/2022/05/GHSA-p5wf-rj4w-hc7f/GHSA-p5wf-rj4w-hc7f.json index 1eb40282102..0ce948eb7ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5wf-rj4w-hc7f/GHSA-p5wf-rj4w-hc7f.json +++ b/advisories/unreviewed/2022/05/GHSA-p5wf-rj4w-hc7f/GHSA-p5wf-rj4w-hc7f.json @@ -7,12 +7,8 @@ "CVE-2020-28644" ], "details": "The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p6rx-8rvc-vf4p/GHSA-p6rx-8rvc-vf4p.json b/advisories/unreviewed/2022/05/GHSA-p6rx-8rvc-vf4p/GHSA-p6rx-8rvc-vf4p.json index 97ca01be156..3422deb5c74 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6rx-8rvc-vf4p/GHSA-p6rx-8rvc-vf4p.json +++ b/advisories/unreviewed/2022/05/GHSA-p6rx-8rvc-vf4p/GHSA-p6rx-8rvc-vf4p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p8qp-fqw2-crxv/GHSA-p8qp-fqw2-crxv.json b/advisories/unreviewed/2022/05/GHSA-p8qp-fqw2-crxv/GHSA-p8qp-fqw2-crxv.json index c3d27ed7d8b..3fbefad89d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8qp-fqw2-crxv/GHSA-p8qp-fqw2-crxv.json +++ b/advisories/unreviewed/2022/05/GHSA-p8qp-fqw2-crxv/GHSA-p8qp-fqw2-crxv.json @@ -7,12 +7,8 @@ "CVE-2020-18215" ], "details": "Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters, which could let a remote malicious user execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p922-mm6q-mhxg/GHSA-p922-mm6q-mhxg.json b/advisories/unreviewed/2022/05/GHSA-p922-mm6q-mhxg/GHSA-p922-mm6q-mhxg.json index a010da95f15..0c383b89a73 100644 --- a/advisories/unreviewed/2022/05/GHSA-p922-mm6q-mhxg/GHSA-p922-mm6q-mhxg.json +++ b/advisories/unreviewed/2022/05/GHSA-p922-mm6q-mhxg/GHSA-p922-mm6q-mhxg.json @@ -7,12 +7,8 @@ "CVE-2020-27007" ], "details": "A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing of HPG files. This could result in a memory access past the end of an allocated buffer. An attacker could leverage this vulnerability to access data in the context of the current process. (ZDI-CAN-12207)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p9p8-p6wp-9g6c/GHSA-p9p8-p6wp-9g6c.json b/advisories/unreviewed/2022/05/GHSA-p9p8-p6wp-9g6c/GHSA-p9p8-p6wp-9g6c.json index 76054a255e2..69d427d6844 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9p8-p6wp-9g6c/GHSA-p9p8-p6wp-9g6c.json +++ b/advisories/unreviewed/2022/05/GHSA-p9p8-p6wp-9g6c/GHSA-p9p8-p6wp-9g6c.json @@ -7,12 +7,8 @@ "CVE-2021-22306" ], "details": "There is an out-of-bound read vulnerability in Mate 30 10.0.0.182(C00E180R6P2). A module does not verify the some input when dealing with messages. Attackers can exploit this vulnerability by sending malicious input through specific module. This could cause out-of-bound, compromising normal service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pcjf-xrw4-4cc2/GHSA-pcjf-xrw4-4cc2.json b/advisories/unreviewed/2022/05/GHSA-pcjf-xrw4-4cc2/GHSA-pcjf-xrw4-4cc2.json index e35f4beb5f2..7e75cc383e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-pcjf-xrw4-4cc2/GHSA-pcjf-xrw4-4cc2.json +++ b/advisories/unreviewed/2022/05/GHSA-pcjf-xrw4-4cc2/GHSA-pcjf-xrw4-4cc2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pfm5-3wch-g359/GHSA-pfm5-3wch-g359.json b/advisories/unreviewed/2022/05/GHSA-pfm5-3wch-g359/GHSA-pfm5-3wch-g359.json index b2ca2a696e4..98d239b04fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfm5-3wch-g359/GHSA-pfm5-3wch-g359.json +++ b/advisories/unreviewed/2022/05/GHSA-pfm5-3wch-g359/GHSA-pfm5-3wch-g359.json @@ -7,12 +7,8 @@ "CVE-2021-0335" ], "details": "In process of C2SoftHevcDec.cpp, there is a possible out of bounds write due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-160346309", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pgch-x9wq-2944/GHSA-pgch-x9wq-2944.json b/advisories/unreviewed/2022/05/GHSA-pgch-x9wq-2944/GHSA-pgch-x9wq-2944.json index 3f213eb8399..8fece7fe9ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgch-x9wq-2944/GHSA-pgch-x9wq-2944.json +++ b/advisories/unreviewed/2022/05/GHSA-pgch-x9wq-2944/GHSA-pgch-x9wq-2944.json @@ -7,12 +7,8 @@ "CVE-2021-21124" ], "details": "Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pgg9-mmcg-8mxp/GHSA-pgg9-mmcg-8mxp.json b/advisories/unreviewed/2022/05/GHSA-pgg9-mmcg-8mxp/GHSA-pgg9-mmcg-8mxp.json index 248daad063a..9e588de382e 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgg9-mmcg-8mxp/GHSA-pgg9-mmcg-8mxp.json +++ b/advisories/unreviewed/2022/05/GHSA-pgg9-mmcg-8mxp/GHSA-pgg9-mmcg-8mxp.json @@ -7,12 +7,8 @@ "CVE-2020-29605" ], "details": "An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the Summary fields of private Issues via bug_arr[]= in a crafted bug_actiongroup_page.php URL. (The target Issues can have Private view status, or belong to a private Project.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pgpr-gp52-wcw9/GHSA-pgpr-gp52-wcw9.json b/advisories/unreviewed/2022/05/GHSA-pgpr-gp52-wcw9/GHSA-pgpr-gp52-wcw9.json index 9444d2464bd..163a226918e 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgpr-gp52-wcw9/GHSA-pgpr-gp52-wcw9.json +++ b/advisories/unreviewed/2022/05/GHSA-pgpr-gp52-wcw9/GHSA-pgpr-gp52-wcw9.json @@ -7,12 +7,8 @@ "CVE-2020-18568" ], "details": "The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-phg2-9429-v8rx/GHSA-phg2-9429-v8rx.json b/advisories/unreviewed/2022/05/GHSA-phg2-9429-v8rx/GHSA-phg2-9429-v8rx.json index c132aed5983..2b9297c191f 100644 --- a/advisories/unreviewed/2022/05/GHSA-phg2-9429-v8rx/GHSA-phg2-9429-v8rx.json +++ b/advisories/unreviewed/2022/05/GHSA-phg2-9429-v8rx/GHSA-phg2-9429-v8rx.json @@ -7,12 +7,8 @@ "CVE-2020-35942" ], "details": "A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execution and XSS. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pj2v-j653-w9v8/GHSA-pj2v-j653-w9v8.json b/advisories/unreviewed/2022/05/GHSA-pj2v-j653-w9v8/GHSA-pj2v-j653-w9v8.json index 1b931aad57a..e89b59903a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj2v-j653-w9v8/GHSA-pj2v-j653-w9v8.json +++ b/advisories/unreviewed/2022/05/GHSA-pj2v-j653-w9v8/GHSA-pj2v-j653-w9v8.json @@ -7,12 +7,8 @@ "CVE-2020-17433" ], "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CMP files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-11356.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pj4h-x8qh-45r9/GHSA-pj4h-x8qh-45r9.json b/advisories/unreviewed/2022/05/GHSA-pj4h-x8qh-45r9/GHSA-pj4h-x8qh-45r9.json index ab46df7daa6..7b2d55a56a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj4h-x8qh-45r9/GHSA-pj4h-x8qh-45r9.json +++ b/advisories/unreviewed/2022/05/GHSA-pj4h-x8qh-45r9/GHSA-pj4h-x8qh-45r9.json @@ -7,12 +7,8 @@ "CVE-2021-26719" ], "details": "A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1.3.2, and gradle-enterprise-maven-extension before 1.8.2. A malicious actor (with certain credentials) can perform a registration step such that crafted TAR archives lead to extraction of files into arbitrary filesystem locations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pjfv-c533-56m2/GHSA-pjfv-c533-56m2.json b/advisories/unreviewed/2022/05/GHSA-pjfv-c533-56m2/GHSA-pjfv-c533-56m2.json index 9edd961793d..98b1476f62e 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjfv-c533-56m2/GHSA-pjfv-c533-56m2.json +++ b/advisories/unreviewed/2022/05/GHSA-pjfv-c533-56m2/GHSA-pjfv-c533-56m2.json @@ -7,12 +7,8 @@ "CVE-2021-27153" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded trueadmin / admintrue credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pqq4-pgj5-fwxq/GHSA-pqq4-pgj5-fwxq.json b/advisories/unreviewed/2022/05/GHSA-pqq4-pgj5-fwxq/GHSA-pqq4-pgj5-fwxq.json index bda693b871a..f2d2e96c2d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqq4-pgj5-fwxq/GHSA-pqq4-pgj5-fwxq.json +++ b/advisories/unreviewed/2022/05/GHSA-pqq4-pgj5-fwxq/GHSA-pqq4-pgj5-fwxq.json @@ -7,12 +7,8 @@ "CVE-2021-25141" ], "details": "A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error due to improper handling of an unexpected data type in user supplied information to the switch's management interface has been identified. The data processing error could be exploited to cause a crash or reboot in the switch management interface and/or possibly the switch itself leading to local denial of service (DoS). The user must have administrator privileges to exploit this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pr3w-2ff8-48mm/GHSA-pr3w-2ff8-48mm.json b/advisories/unreviewed/2022/05/GHSA-pr3w-2ff8-48mm/GHSA-pr3w-2ff8-48mm.json index 8529e7afe74..de6f3242545 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr3w-2ff8-48mm/GHSA-pr3w-2ff8-48mm.json +++ b/advisories/unreviewed/2022/05/GHSA-pr3w-2ff8-48mm/GHSA-pr3w-2ff8-48mm.json @@ -7,12 +7,8 @@ "CVE-2020-10234" ], "details": "The AscRegistryFilter.sys kernel driver in IObit Advanced SystemCare 13.2 allows an unprivileged user to send an IOCTL to the device driver. If the user provides a NULL entry for the dwIoControlCode parameter, a kernel panic (aka BSOD) follows. The IOCTL codes can be found in the dispatch function: 0x8001E000, 0x8001E004, 0x8001E008, 0x8001E00C, 0x8001E010, 0x8001E014, 0x8001E020, 0x8001E024, 0x8001E040, 0x8001E044, and 0x8001E048. \\DosDevices\\AscRegistryFilter and \\Device\\AscRegistryFilter are affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-prcr-frhq-gm4p/GHSA-prcr-frhq-gm4p.json b/advisories/unreviewed/2022/05/GHSA-prcr-frhq-gm4p/GHSA-prcr-frhq-gm4p.json index 0def3aa134e..542a56d318a 100644 --- a/advisories/unreviewed/2022/05/GHSA-prcr-frhq-gm4p/GHSA-prcr-frhq-gm4p.json +++ b/advisories/unreviewed/2022/05/GHSA-prcr-frhq-gm4p/GHSA-prcr-frhq-gm4p.json @@ -7,12 +7,8 @@ "CVE-2020-28394" ], "details": "A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing of RAS files. This could result in a memory access past the end of an allocated buffer. An attacker could leverage this vulnerability to access data in the context of the current process. (ZDI-CAN-12283)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pvm2-wchq-hwv5/GHSA-pvm2-wchq-hwv5.json b/advisories/unreviewed/2022/05/GHSA-pvm2-wchq-hwv5/GHSA-pvm2-wchq-hwv5.json index dd7ab55509a..0c9445f1c56 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvm2-wchq-hwv5/GHSA-pvm2-wchq-hwv5.json +++ b/advisories/unreviewed/2022/05/GHSA-pvm2-wchq-hwv5/GHSA-pvm2-wchq-hwv5.json @@ -7,12 +7,8 @@ "CVE-2020-15833" ], "details": "An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The Dropbear SSH daemon has been modified to accept an alternate hard-coded path to a public key that allows root access. This key is stored in a /rom location that cannot be modified by the device owner.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pvwf-p3gj-cccj/GHSA-pvwf-p3gj-cccj.json b/advisories/unreviewed/2022/05/GHSA-pvwf-p3gj-cccj/GHSA-pvwf-p3gj-cccj.json index f2c0c6c02d8..15dd09b9ac5 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvwf-p3gj-cccj/GHSA-pvwf-p3gj-cccj.json +++ b/advisories/unreviewed/2022/05/GHSA-pvwf-p3gj-cccj/GHSA-pvwf-p3gj-cccj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pxp2-gjpv-xjrc/GHSA-pxp2-gjpv-xjrc.json b/advisories/unreviewed/2022/05/GHSA-pxp2-gjpv-xjrc/GHSA-pxp2-gjpv-xjrc.json index b102bab4d61..8d1dafac931 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxp2-gjpv-xjrc/GHSA-pxp2-gjpv-xjrc.json +++ b/advisories/unreviewed/2022/05/GHSA-pxp2-gjpv-xjrc/GHSA-pxp2-gjpv-xjrc.json @@ -7,12 +7,8 @@ "CVE-2021-22293" ], "details": "Some Huawei products have an inconsistent interpretation of HTTP requests vulnerability. Attackers can exploit this vulnerability to cause information leak. Affected product versions include: CampusInsight versions V100R019C10; ManageOne versions 6.5.1.1, 6.5.1.SPC100, 6.5.1.SPC200, 6.5.1RC1, 6.5.1RC2, 8.0.RC2. Affected product versions include: Taurus-AL00A versions 10.0.0.1(C00E1R1P1).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pxx4-4592-hf5h/GHSA-pxx4-4592-hf5h.json b/advisories/unreviewed/2022/05/GHSA-pxx4-4592-hf5h/GHSA-pxx4-4592-hf5h.json index 81048c01174..566d5455c70 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxx4-4592-hf5h/GHSA-pxx4-4592-hf5h.json +++ b/advisories/unreviewed/2022/05/GHSA-pxx4-4592-hf5h/GHSA-pxx4-4592-hf5h.json @@ -7,12 +7,8 @@ "CVE-2021-0346" ], "details": "In vpu, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05371580.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q2v2-27xw-whh5/GHSA-q2v2-27xw-whh5.json b/advisories/unreviewed/2022/05/GHSA-q2v2-27xw-whh5/GHSA-q2v2-27xw-whh5.json index 5dc795b15f3..7ee616f19f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2v2-27xw-whh5/GHSA-q2v2-27xw-whh5.json +++ b/advisories/unreviewed/2022/05/GHSA-q2v2-27xw-whh5/GHSA-q2v2-27xw-whh5.json @@ -7,12 +7,8 @@ "CVE-2021-27170" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. By default, there are no firewall rules for IPv6 connectivity, exposing the internal management interfaces to the Internet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q2xf-jvwq-327h/GHSA-q2xf-jvwq-327h.json b/advisories/unreviewed/2022/05/GHSA-q2xf-jvwq-327h/GHSA-q2xf-jvwq-327h.json index a8338f325ad..09aac209100 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2xf-jvwq-327h/GHSA-q2xf-jvwq-327h.json +++ b/advisories/unreviewed/2022/05/GHSA-q2xf-jvwq-327h/GHSA-q2xf-jvwq-327h.json @@ -7,12 +7,8 @@ "CVE-2021-1266" ], "details": "A vulnerability in the REST API of Cisco Managed Services Accelerator (MSX) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the way that the affected software logs certain API requests. An attacker could exploit this vulnerability by sending a flood of crafted API requests to an affected device. A successful exploit could allow the attacker to cause a DoS condition on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q4x8-w6fw-v9hh/GHSA-q4x8-w6fw-v9hh.json b/advisories/unreviewed/2022/05/GHSA-q4x8-w6fw-v9hh/GHSA-q4x8-w6fw-v9hh.json index 83a1879922d..2c5679c71bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4x8-w6fw-v9hh/GHSA-q4x8-w6fw-v9hh.json +++ b/advisories/unreviewed/2022/05/GHSA-q4x8-w6fw-v9hh/GHSA-q4x8-w6fw-v9hh.json @@ -7,12 +7,8 @@ "CVE-2020-10539" ], "details": "An issue was discovered in Epikur before 20.1.1. The Epikur server contains the checkPasswort() function that, upon user login, checks the submitted password against the user password's MD5 hash stored in the database. It is also compared to a second MD5 hash, which is the same for every user (aka a \"Backdoor Password\" of 3p1kursupport). If the submitted password matches either one, access is granted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q6jw-34cj-733v/GHSA-q6jw-34cj-733v.json b/advisories/unreviewed/2022/05/GHSA-q6jw-34cj-733v/GHSA-q6jw-34cj-733v.json index 84f1b81367e..59197aa4c81 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6jw-34cj-733v/GHSA-q6jw-34cj-733v.json +++ b/advisories/unreviewed/2022/05/GHSA-q6jw-34cj-733v/GHSA-q6jw-34cj-733v.json @@ -7,12 +7,8 @@ "CVE-2020-16120" ], "details": "Overlayfs did not properly perform permission checking when copying up files in an overlayfs and could be exploited from within a user namespace, if, for example, unprivileged user namespaces were allowed. It was possible to have a file not readable by an unprivileged user to be copied to a mountpoint controlled by the user, like a removable device. This was introduced in kernel version 4.19 by commit d1d04ef (\"ovl: stack file ops\"). This was fixed in kernel version 5.8 by commits 56230d9 (\"ovl: verify permissions in ovl_path_open()\"), 48bd024 (\"ovl: switch to mounter creds in readdir\") and 05acefb (\"ovl: check permission to open real file\"). Additionally, commits 130fdbc (\"ovl: pass correct flags for opening real directory\") and 292f902 (\"ovl: call secutiry hook in ovl_real_ioctl()\") in kernel 5.8 might also be desired or necessary. These additional commits introduced a regression in overlay mounts within user namespaces which prevented access to files with ownership outside of the user namespace. This regression was mitigated by subsequent commit b6650da (\"ovl: do not fail because of O_NOATIMEi\") in kernel 5.11.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7q9-c33c-p6q4/GHSA-q7q9-c33c-p6q4.json b/advisories/unreviewed/2022/05/GHSA-q7q9-c33c-p6q4/GHSA-q7q9-c33c-p6q4.json index a0e4072f96f..028fe1b3569 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7q9-c33c-p6q4/GHSA-q7q9-c33c-p6q4.json +++ b/advisories/unreviewed/2022/05/GHSA-q7q9-c33c-p6q4/GHSA-q7q9-c33c-p6q4.json @@ -7,12 +7,8 @@ "CVE-2020-17436" ], "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CMP files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-11432.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q894-2jhh-qq4h/GHSA-q894-2jhh-qq4h.json b/advisories/unreviewed/2022/05/GHSA-q894-2jhh-qq4h/GHSA-q894-2jhh-qq4h.json index a47f30d4974..b9a0ab33dec 100644 --- a/advisories/unreviewed/2022/05/GHSA-q894-2jhh-qq4h/GHSA-q894-2jhh-qq4h.json +++ b/advisories/unreviewed/2022/05/GHSA-q894-2jhh-qq4h/GHSA-q894-2jhh-qq4h.json @@ -7,12 +7,8 @@ "CVE-2021-21120" ], "details": "Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q997-cggx-jg25/GHSA-q997-cggx-jg25.json b/advisories/unreviewed/2022/05/GHSA-q997-cggx-jg25/GHSA-q997-cggx-jg25.json index 0d7d9c4c3bd..88aed7f6a2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-q997-cggx-jg25/GHSA-q997-cggx-jg25.json +++ b/advisories/unreviewed/2022/05/GHSA-q997-cggx-jg25/GHSA-q997-cggx-jg25.json @@ -7,12 +7,8 @@ "CVE-2020-27008" ], "details": "A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing of PLT files. This could result in a memory access past the end of an allocated buffer. An attacker could leverage this vulnerability to access data in the context of the current process. (ZDI-CAN-12209)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q9rw-rq8v-6r3f/GHSA-q9rw-rq8v-6r3f.json b/advisories/unreviewed/2022/05/GHSA-q9rw-rq8v-6r3f/GHSA-q9rw-rq8v-6r3f.json index 914a2fb0ed4..a738645b4f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9rw-rq8v-6r3f/GHSA-q9rw-rq8v-6r3f.json +++ b/advisories/unreviewed/2022/05/GHSA-q9rw-rq8v-6r3f/GHSA-q9rw-rq8v-6r3f.json @@ -7,12 +7,8 @@ "CVE-2021-25248" ], "details": "An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose sensitive information about a named pipe.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qcqh-x84p-358v/GHSA-qcqh-x84p-358v.json b/advisories/unreviewed/2022/05/GHSA-qcqh-x84p-358v/GHSA-qcqh-x84p-358v.json index 8448a797302..f32995d83e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcqh-x84p-358v/GHSA-qcqh-x84p-358v.json +++ b/advisories/unreviewed/2022/05/GHSA-qcqh-x84p-358v/GHSA-qcqh-x84p-358v.json @@ -7,12 +7,8 @@ "CVE-2021-1331" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qfqh-45q8-8425/GHSA-qfqh-45q8-8425.json b/advisories/unreviewed/2022/05/GHSA-qfqh-45q8-8425/GHSA-qfqh-45q8-8425.json index d782700e094..19e448a17d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfqh-45q8-8425/GHSA-qfqh-45q8-8425.json +++ b/advisories/unreviewed/2022/05/GHSA-qfqh-45q8-8425/GHSA-qfqh-45q8-8425.json @@ -7,12 +7,8 @@ "CVE-2021-3336" ], "details": "DoTls13CertificateVerify in tls13.c in wolfSSL through 4.6.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or RSA signature without the corresponding certificate).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qg9g-c5qj-x44r/GHSA-qg9g-c5qj-x44r.json b/advisories/unreviewed/2022/05/GHSA-qg9g-c5qj-x44r/GHSA-qg9g-c5qj-x44r.json index 70e6db95cb8..be25803458a 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg9g-c5qj-x44r/GHSA-qg9g-c5qj-x44r.json +++ b/advisories/unreviewed/2022/05/GHSA-qg9g-c5qj-x44r/GHSA-qg9g-c5qj-x44r.json @@ -7,12 +7,8 @@ "CVE-2020-17424" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EZI files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11247.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qgg8-6g36-jwfh/GHSA-qgg8-6g36-jwfh.json b/advisories/unreviewed/2022/05/GHSA-qgg8-6g36-jwfh/GHSA-qgg8-6g36-jwfh.json index d76b455c785..ebf8f04326a 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgg8-6g36-jwfh/GHSA-qgg8-6g36-jwfh.json +++ b/advisories/unreviewed/2022/05/GHSA-qgg8-6g36-jwfh/GHSA-qgg8-6g36-jwfh.json @@ -7,12 +7,8 @@ "CVE-2020-27857" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of NEF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11488.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qgx2-cvjx-6vhf/GHSA-qgx2-cvjx-6vhf.json b/advisories/unreviewed/2022/05/GHSA-qgx2-cvjx-6vhf/GHSA-qgx2-cvjx-6vhf.json index 5c3966e8a57..474039f1166 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgx2-cvjx-6vhf/GHSA-qgx2-cvjx-6vhf.json +++ b/advisories/unreviewed/2022/05/GHSA-qgx2-cvjx-6vhf/GHSA-qgx2-cvjx-6vhf.json @@ -7,12 +7,8 @@ "CVE-2021-0348" ], "details": "In vpu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05349201.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qh7g-hfr4-f2f4/GHSA-qh7g-hfr4-f2f4.json b/advisories/unreviewed/2022/05/GHSA-qh7g-hfr4-f2f4/GHSA-qh7g-hfr4-f2f4.json index b6ede720bfa..29bb90ac58b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh7g-hfr4-f2f4/GHSA-qh7g-hfr4-f2f4.json +++ b/advisories/unreviewed/2022/05/GHSA-qh7g-hfr4-f2f4/GHSA-qh7g-hfr4-f2f4.json @@ -7,12 +7,8 @@ "CVE-2021-26711" ], "details": "A frame-injection issue in the online help in Redwood Report2Web 4.3.4.5 allows remote attackers to render an external resource inside a frame via the help/Online_Help/NetHelp/default.htm turl parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qhg7-cqr2-qr57/GHSA-qhg7-cqr2-qr57.json b/advisories/unreviewed/2022/05/GHSA-qhg7-cqr2-qr57/GHSA-qhg7-cqr2-qr57.json index b5ac6ebf6d8..c0d0566358f 100644 --- a/advisories/unreviewed/2022/05/GHSA-qhg7-cqr2-qr57/GHSA-qhg7-cqr2-qr57.json +++ b/advisories/unreviewed/2022/05/GHSA-qhg7-cqr2-qr57/GHSA-qhg7-cqr2-qr57.json @@ -7,12 +7,8 @@ "CVE-2021-0340" ], "details": "In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-134155286", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qhxx-g2fv-w3p4/GHSA-qhxx-g2fv-w3p4.json b/advisories/unreviewed/2022/05/GHSA-qhxx-g2fv-w3p4/GHSA-qhxx-g2fv-w3p4.json index 2d02759a01e..cc92ad48880 100644 --- a/advisories/unreviewed/2022/05/GHSA-qhxx-g2fv-w3p4/GHSA-qhxx-g2fv-w3p4.json +++ b/advisories/unreviewed/2022/05/GHSA-qhxx-g2fv-w3p4/GHSA-qhxx-g2fv-w3p4.json @@ -7,12 +7,8 @@ "CVE-2021-25134" ], "details": "The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice setremoteimageinfo_func function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qj3f-9v2m-79rj/GHSA-qj3f-9v2m-79rj.json b/advisories/unreviewed/2022/05/GHSA-qj3f-9v2m-79rj/GHSA-qj3f-9v2m-79rj.json index 8a113ac5fa7..d451e1981b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-qj3f-9v2m-79rj/GHSA-qj3f-9v2m-79rj.json +++ b/advisories/unreviewed/2022/05/GHSA-qj3f-9v2m-79rj/GHSA-qj3f-9v2m-79rj.json @@ -7,12 +7,8 @@ "CVE-2020-29164" ], "details": "PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qjvv-qc9h-394h/GHSA-qjvv-qc9h-394h.json b/advisories/unreviewed/2022/05/GHSA-qjvv-qc9h-394h/GHSA-qjvv-qc9h-394h.json index c1dda9011cd..604c64fe549 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjvv-qc9h-394h/GHSA-qjvv-qc9h-394h.json +++ b/advisories/unreviewed/2022/05/GHSA-qjvv-qc9h-394h/GHSA-qjvv-qc9h-394h.json @@ -7,12 +7,8 @@ "CVE-2020-26191" ], "details": "Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain a privilege escalation vulnerability. A user with ISI_PRIV_JOB_ENGINE may use the PermissionRepair job to grant themselves the highest level of RBAC privileges thus being able to read arbitrary data, tamper with system software or deny service to users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qp58-fc8h-jpwx/GHSA-qp58-fc8h-jpwx.json b/advisories/unreviewed/2022/05/GHSA-qp58-fc8h-jpwx/GHSA-qp58-fc8h-jpwx.json index 0195e98bf6c..d3491a73baa 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp58-fc8h-jpwx/GHSA-qp58-fc8h-jpwx.json +++ b/advisories/unreviewed/2022/05/GHSA-qp58-fc8h-jpwx/GHSA-qp58-fc8h-jpwx.json @@ -7,12 +7,8 @@ "CVE-2021-0305" ], "details": "In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10Android ID: A-154015447", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qppj-hcv6-9fcm/GHSA-qppj-hcv6-9fcm.json b/advisories/unreviewed/2022/05/GHSA-qppj-hcv6-9fcm/GHSA-qppj-hcv6-9fcm.json index 23764050315..18479c74f95 100644 --- a/advisories/unreviewed/2022/05/GHSA-qppj-hcv6-9fcm/GHSA-qppj-hcv6-9fcm.json +++ b/advisories/unreviewed/2022/05/GHSA-qppj-hcv6-9fcm/GHSA-qppj-hcv6-9fcm.json @@ -7,12 +7,8 @@ "CVE-2021-1293" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These vulnerabilities exist because HTTP requests are not properly validated. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to remotely execute arbitrary code on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qpr8-xrx4-f6mx/GHSA-qpr8-xrx4-f6mx.json b/advisories/unreviewed/2022/05/GHSA-qpr8-xrx4-f6mx/GHSA-qpr8-xrx4-f6mx.json index fce712dbc00..217b13dc327 100644 --- a/advisories/unreviewed/2022/05/GHSA-qpr8-xrx4-f6mx/GHSA-qpr8-xrx4-f6mx.json +++ b/advisories/unreviewed/2022/05/GHSA-qpr8-xrx4-f6mx/GHSA-qpr8-xrx4-f6mx.json @@ -7,12 +7,8 @@ "CVE-2021-0356" ], "details": "In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05442014.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qq5h-7q3j-jh5p/GHSA-qq5h-7q3j-jh5p.json b/advisories/unreviewed/2022/05/GHSA-qq5h-7q3j-jh5p/GHSA-qq5h-7q3j-jh5p.json index 26f7089bdf1..9aaf56eb08a 100644 --- a/advisories/unreviewed/2022/05/GHSA-qq5h-7q3j-jh5p/GHSA-qq5h-7q3j-jh5p.json +++ b/advisories/unreviewed/2022/05/GHSA-qq5h-7q3j-jh5p/GHSA-qq5h-7q3j-jh5p.json @@ -7,12 +7,8 @@ "CVE-2021-21444" ], "details": "SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added X-Frame-Options header leading to Clickjacking attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwpm-85r5-4m77/GHSA-qwpm-85r5-4m77.json b/advisories/unreviewed/2022/05/GHSA-qwpm-85r5-4m77/GHSA-qwpm-85r5-4m77.json index d90fd9c0958..152f69163a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwpm-85r5-4m77/GHSA-qwpm-85r5-4m77.json +++ b/advisories/unreviewed/2022/05/GHSA-qwpm-85r5-4m77/GHSA-qwpm-85r5-4m77.json @@ -7,12 +7,8 @@ "CVE-2020-24837" ], "details": "An integer underflow has been found in the latest version of ZCFees. The variables 'currPeriodIdx' and 'lastPeriodExecIdx' are both unsigned integers, and the result of the minus operation may be a negative integer which leads to an underflow. The attackers can modify the current timestamp of the transaction somehow and block the execution of the process function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qxf7-8j2m-38vq/GHSA-qxf7-8j2m-38vq.json b/advisories/unreviewed/2022/05/GHSA-qxf7-8j2m-38vq/GHSA-qxf7-8j2m-38vq.json index 9b5b2163cab..a9be9aefe36 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxf7-8j2m-38vq/GHSA-qxf7-8j2m-38vq.json +++ b/advisories/unreviewed/2022/05/GHSA-qxf7-8j2m-38vq/GHSA-qxf7-8j2m-38vq.json @@ -7,12 +7,8 @@ "CVE-2020-6649" ], "details": "An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID (via other, hypothetical attacks)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r2f9-gjrv-w2m3/GHSA-r2f9-gjrv-w2m3.json b/advisories/unreviewed/2022/05/GHSA-r2f9-gjrv-w2m3/GHSA-r2f9-gjrv-w2m3.json index 69b43bc8316..1978f810f2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2f9-gjrv-w2m3/GHSA-r2f9-gjrv-w2m3.json +++ b/advisories/unreviewed/2022/05/GHSA-r2f9-gjrv-w2m3/GHSA-r2f9-gjrv-w2m3.json @@ -7,12 +7,8 @@ "CVE-2020-26998" ], "details": "A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing of PAR files. This could result in a memory access past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information. (ZDI-CAN-12040)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r2qw-p44h-79x6/GHSA-r2qw-p44h-79x6.json b/advisories/unreviewed/2022/05/GHSA-r2qw-p44h-79x6/GHSA-r2qw-p44h-79x6.json index 11bd6db8642..ad031a43eda 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2qw-p44h-79x6/GHSA-r2qw-p44h-79x6.json +++ b/advisories/unreviewed/2022/05/GHSA-r2qw-p44h-79x6/GHSA-r2qw-p44h-79x6.json @@ -7,12 +7,8 @@ "CVE-2021-1332" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r3vf-v8xh-pg2h/GHSA-r3vf-v8xh-pg2h.json b/advisories/unreviewed/2022/05/GHSA-r3vf-v8xh-pg2h/GHSA-r3vf-v8xh-pg2h.json index e0ec63ebca1..f6cb95ac8d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3vf-v8xh-pg2h/GHSA-r3vf-v8xh-pg2h.json +++ b/advisories/unreviewed/2022/05/GHSA-r3vf-v8xh-pg2h/GHSA-r3vf-v8xh-pg2h.json @@ -7,12 +7,8 @@ "CVE-2020-20294" ], "details": "An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r437-7x7j-ph69/GHSA-r437-7x7j-ph69.json b/advisories/unreviewed/2022/05/GHSA-r437-7x7j-ph69/GHSA-r437-7x7j-ph69.json index f027589acb0..756479eb8a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-r437-7x7j-ph69/GHSA-r437-7x7j-ph69.json +++ b/advisories/unreviewed/2022/05/GHSA-r437-7x7j-ph69/GHSA-r437-7x7j-ph69.json @@ -7,12 +7,8 @@ "CVE-2021-27154" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / G0R2U1P2ag credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r4gr-8frm-x929/GHSA-r4gr-8frm-x929.json b/advisories/unreviewed/2022/05/GHSA-r4gr-8frm-x929/GHSA-r4gr-8frm-x929.json index 96749496adc..a523aa21f02 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4gr-8frm-x929/GHSA-r4gr-8frm-x929.json +++ b/advisories/unreviewed/2022/05/GHSA-r4gr-8frm-x929/GHSA-r4gr-8frm-x929.json @@ -7,12 +7,8 @@ "CVE-2020-16629" ], "details": "PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through api.php to write a PHP file to the target path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r69p-m96w-93pj/GHSA-r69p-m96w-93pj.json b/advisories/unreviewed/2022/05/GHSA-r69p-m96w-93pj/GHSA-r69p-m96w-93pj.json index 36a86d36fab..fc1bb5c87d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-r69p-m96w-93pj/GHSA-r69p-m96w-93pj.json +++ b/advisories/unreviewed/2022/05/GHSA-r69p-m96w-93pj/GHSA-r69p-m96w-93pj.json @@ -7,12 +7,8 @@ "CVE-2021-26222" ], "details": "The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r95g-ccc3-r2m4/GHSA-r95g-ccc3-r2m4.json b/advisories/unreviewed/2022/05/GHSA-r95g-ccc3-r2m4/GHSA-r95g-ccc3-r2m4.json index 2c94a094f41..f147675efd0 100644 --- a/advisories/unreviewed/2022/05/GHSA-r95g-ccc3-r2m4/GHSA-r95g-ccc3-r2m4.json +++ b/advisories/unreviewed/2022/05/GHSA-r95g-ccc3-r2m4/GHSA-r95g-ccc3-r2m4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r9ch-hjj5-v6pr/GHSA-r9ch-hjj5-v6pr.json b/advisories/unreviewed/2022/05/GHSA-r9ch-hjj5-v6pr/GHSA-r9ch-hjj5-v6pr.json index 43db12df5ea..3df5ffee621 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9ch-hjj5-v6pr/GHSA-r9ch-hjj5-v6pr.json +++ b/advisories/unreviewed/2022/05/GHSA-r9ch-hjj5-v6pr/GHSA-r9ch-hjj5-v6pr.json @@ -7,12 +7,8 @@ "CVE-2020-17432" ], "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CR2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-11335.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rcp2-2qxc-r85v/GHSA-rcp2-2qxc-r85v.json b/advisories/unreviewed/2022/05/GHSA-rcp2-2qxc-r85v/GHSA-rcp2-2qxc-r85v.json index 28b8e55358c..8b1a1728660 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcp2-2qxc-r85v/GHSA-rcp2-2qxc-r85v.json +++ b/advisories/unreviewed/2022/05/GHSA-rcp2-2qxc-r85v/GHSA-rcp2-2qxc-r85v.json @@ -7,12 +7,8 @@ "CVE-2021-21140" ], "details": "Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a USB device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rcpm-5qw3-5cwf/GHSA-rcpm-5qw3-5cwf.json b/advisories/unreviewed/2022/05/GHSA-rcpm-5qw3-5cwf/GHSA-rcpm-5qw3-5cwf.json index c95dd2235eb..34250958f0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcpm-5qw3-5cwf/GHSA-rcpm-5qw3-5cwf.json +++ b/advisories/unreviewed/2022/05/GHSA-rcpm-5qw3-5cwf/GHSA-rcpm-5qw3-5cwf.json @@ -7,12 +7,8 @@ "CVE-2021-1128" ], "details": "A vulnerability in the CLI parser of Cisco IOS XR Software could allow an authenticated, local attacker to view more information than their privileges allow. The vulnerability is due to insufficient application of restrictions during the execution of a specific command. An attacker could exploit this vulnerability by using a specific command at the command line. A successful exploit could allow the attacker to obtain sensitive information within the configuration that otherwise might not have been accessible beyond the privileges of the invoking user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rcr6-jvpg-rgxq/GHSA-rcr6-jvpg-rgxq.json b/advisories/unreviewed/2022/05/GHSA-rcr6-jvpg-rgxq/GHSA-rcr6-jvpg-rgxq.json index f4d101113b9..d28048cf777 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcr6-jvpg-rgxq/GHSA-rcr6-jvpg-rgxq.json +++ b/advisories/unreviewed/2022/05/GHSA-rcr6-jvpg-rgxq/GHSA-rcr6-jvpg-rgxq.json @@ -7,12 +7,8 @@ "CVE-2020-36152" ], "details": "Buffer overflow in readDataVar in hdf/dataobject.c in Symonics libmysofa 0.5 - 1.1 allows attackers to execute arbitrary code via a crafted SOFA.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rf52-3f4q-fcfq/GHSA-rf52-3f4q-fcfq.json b/advisories/unreviewed/2022/05/GHSA-rf52-3f4q-fcfq/GHSA-rf52-3f4q-fcfq.json index e703b324837..438c4c35b3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf52-3f4q-fcfq/GHSA-rf52-3f4q-fcfq.json +++ b/advisories/unreviewed/2022/05/GHSA-rf52-3f4q-fcfq/GHSA-rf52-3f4q-fcfq.json @@ -7,12 +7,8 @@ "CVE-2021-3229" ], "details": "Denial of service in ASUSWRT ASUS RT-AX3000 firmware versions 3.0.0.4.384_10177 and earlier versions allows an attacker to disrupt the use of device setup services via continuous login error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rf6c-ww9j-gx78/GHSA-rf6c-ww9j-gx78.json b/advisories/unreviewed/2022/05/GHSA-rf6c-ww9j-gx78/GHSA-rf6c-ww9j-gx78.json index 5b27587a993..12a27298e9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf6c-ww9j-gx78/GHSA-rf6c-ww9j-gx78.json +++ b/advisories/unreviewed/2022/05/GHSA-rf6c-ww9j-gx78/GHSA-rf6c-ww9j-gx78.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rf7j-w28r-v7m8/GHSA-rf7j-w28r-v7m8.json b/advisories/unreviewed/2022/05/GHSA-rf7j-w28r-v7m8/GHSA-rf7j-w28r-v7m8.json index 3bd0372cdd4..d2947757447 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf7j-w28r-v7m8/GHSA-rf7j-w28r-v7m8.json +++ b/advisories/unreviewed/2022/05/GHSA-rf7j-w28r-v7m8/GHSA-rf7j-w28r-v7m8.json @@ -7,12 +7,8 @@ "CVE-2020-26547" ], "details": "Monal before 4.9 does not implement proper sender verification on MAM and Message Carbon (XEP-0280) results. This allows a remote attacker (able to send stanzas to a victim) to inject arbitrary messages into the local history, with full control over the sender and receiver displayed to the victim.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rfpv-wr89-rpq2/GHSA-rfpv-wr89-rpq2.json b/advisories/unreviewed/2022/05/GHSA-rfpv-wr89-rpq2/GHSA-rfpv-wr89-rpq2.json index 054e96e07e3..4578c844a35 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfpv-wr89-rpq2/GHSA-rfpv-wr89-rpq2.json +++ b/advisories/unreviewed/2022/05/GHSA-rfpv-wr89-rpq2/GHSA-rfpv-wr89-rpq2.json @@ -7,12 +7,8 @@ "CVE-2021-1072" ], "details": "NVIDIA GeForce Experience, all versions prior to 3.21, contains a vulnerability in GameStream (rxdiag.dll) where an arbitrary file deletion due to improper handling of log files may lead to denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rgfr-7rr5-7928/GHSA-rgfr-7rr5-7928.json b/advisories/unreviewed/2022/05/GHSA-rgfr-7rr5-7928/GHSA-rgfr-7rr5-7928.json index 773a3b3ec46..89d18cf83a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-rgfr-7rr5-7928/GHSA-rgfr-7rr5-7928.json +++ b/advisories/unreviewed/2022/05/GHSA-rgfr-7rr5-7928/GHSA-rgfr-7rr5-7928.json @@ -7,12 +7,8 @@ "CVE-2020-13185" ], "details": "Certain web application pages in the authenticated section of the Teradici Cloud Access Connector prior to v18 were accessible without the need to specify authentication tokens, which allowed an attacker in the ability to execute sensitive functions without credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rgx6-mrxh-v3pw/GHSA-rgx6-mrxh-v3pw.json b/advisories/unreviewed/2022/05/GHSA-rgx6-mrxh-v3pw/GHSA-rgx6-mrxh-v3pw.json index 6f093675585..6d3ba535ee1 100644 --- a/advisories/unreviewed/2022/05/GHSA-rgx6-mrxh-v3pw/GHSA-rgx6-mrxh-v3pw.json +++ b/advisories/unreviewed/2022/05/GHSA-rgx6-mrxh-v3pw/GHSA-rgx6-mrxh-v3pw.json @@ -7,12 +7,8 @@ "CVE-2020-4826" ], "details": "IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 189840.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rjqp-837c-gqg6/GHSA-rjqp-837c-gqg6.json b/advisories/unreviewed/2022/05/GHSA-rjqp-837c-gqg6/GHSA-rjqp-837c-gqg6.json index df54d3f0d3e..511e41d0aaf 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjqp-837c-gqg6/GHSA-rjqp-837c-gqg6.json +++ b/advisories/unreviewed/2022/05/GHSA-rjqp-837c-gqg6/GHSA-rjqp-837c-gqg6.json @@ -7,12 +7,8 @@ "CVE-2021-3258" ], "details": "Question2Answer Q2A Ultimate SEO Version 1.3 is affected by cross-site scripting (XSS), which may lead to arbitrary remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rjwr-8pfc-m94f/GHSA-rjwr-8pfc-m94f.json b/advisories/unreviewed/2022/05/GHSA-rjwr-8pfc-m94f/GHSA-rjwr-8pfc-m94f.json index 46c8ed04c20..6a7fdc260d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjwr-8pfc-m94f/GHSA-rjwr-8pfc-m94f.json +++ b/advisories/unreviewed/2022/05/GHSA-rjwr-8pfc-m94f/GHSA-rjwr-8pfc-m94f.json @@ -7,12 +7,8 @@ "CVE-2019-19004" ], "details": "A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap image.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rmrp-r22g-jmmv/GHSA-rmrp-r22g-jmmv.json b/advisories/unreviewed/2022/05/GHSA-rmrp-r22g-jmmv/GHSA-rmrp-r22g-jmmv.json index 966fcf41751..4723cce2f57 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmrp-r22g-jmmv/GHSA-rmrp-r22g-jmmv.json +++ b/advisories/unreviewed/2022/05/GHSA-rmrp-r22g-jmmv/GHSA-rmrp-r22g-jmmv.json @@ -7,12 +7,8 @@ "CVE-2020-15835" ], "details": "An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocumented code that provides the ability to authenticate as root without knowing the actual root password. An adversary with the private key can remotely authenticate to the management interface as root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rpjv-v6fq-qfwj/GHSA-rpjv-v6fq-qfwj.json b/advisories/unreviewed/2022/05/GHSA-rpjv-v6fq-qfwj/GHSA-rpjv-v6fq-qfwj.json index b17c331bf34..e2a8cab5cc9 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpjv-v6fq-qfwj/GHSA-rpjv-v6fq-qfwj.json +++ b/advisories/unreviewed/2022/05/GHSA-rpjv-v6fq-qfwj/GHSA-rpjv-v6fq-qfwj.json @@ -7,12 +7,8 @@ "CVE-2021-27145" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / lnadmin credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rq9w-g596-24v3/GHSA-rq9w-g596-24v3.json b/advisories/unreviewed/2022/05/GHSA-rq9w-g596-24v3/GHSA-rq9w-g596-24v3.json index 039254d217c..721e297c787 100644 --- a/advisories/unreviewed/2022/05/GHSA-rq9w-g596-24v3/GHSA-rq9w-g596-24v3.json +++ b/advisories/unreviewed/2022/05/GHSA-rq9w-g596-24v3/GHSA-rq9w-g596-24v3.json @@ -7,12 +7,8 @@ "CVE-2020-14247" ], "details": "HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid session ID.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rr5j-hx3c-x5p5/GHSA-rr5j-hx3c-x5p5.json b/advisories/unreviewed/2022/05/GHSA-rr5j-hx3c-x5p5/GHSA-rr5j-hx3c-x5p5.json index 3dd784e6b48..61e3c7bf3b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-rr5j-hx3c-x5p5/GHSA-rr5j-hx3c-x5p5.json +++ b/advisories/unreviewed/2022/05/GHSA-rr5j-hx3c-x5p5/GHSA-rr5j-hx3c-x5p5.json @@ -7,12 +7,8 @@ "CVE-2020-10553" ], "details": "An issue was discovered in Psyprax before 3.2.2. The file %PROGRAMDATA%\\Psyprax32\\PPScreen.ini contains a hash for the lockscreen (aka screensaver) of the application. If that entry is removed, the lockscreen is no longer displayed and the app is no longer locked. All local users are able to modify that file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rr9f-vrp3-f94h/GHSA-rr9f-vrp3-f94h.json b/advisories/unreviewed/2022/05/GHSA-rr9f-vrp3-f94h/GHSA-rr9f-vrp3-f94h.json index dabdaf121fe..841d7a74aaa 100644 --- a/advisories/unreviewed/2022/05/GHSA-rr9f-vrp3-f94h/GHSA-rr9f-vrp3-f94h.json +++ b/advisories/unreviewed/2022/05/GHSA-rr9f-vrp3-f94h/GHSA-rr9f-vrp3-f94h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rvw7-mwvr-mmjr/GHSA-rvw7-mwvr-mmjr.json b/advisories/unreviewed/2022/05/GHSA-rvw7-mwvr-mmjr/GHSA-rvw7-mwvr-mmjr.json index 46cb088ba21..4be8a09dad4 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvw7-mwvr-mmjr/GHSA-rvw7-mwvr-mmjr.json +++ b/advisories/unreviewed/2022/05/GHSA-rvw7-mwvr-mmjr/GHSA-rvw7-mwvr-mmjr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rw24-wp83-w826/GHSA-rw24-wp83-w826.json b/advisories/unreviewed/2022/05/GHSA-rw24-wp83-w826/GHSA-rw24-wp83-w826.json index 47db2a41321..dad77af783b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rw24-wp83-w826/GHSA-rw24-wp83-w826.json +++ b/advisories/unreviewed/2022/05/GHSA-rw24-wp83-w826/GHSA-rw24-wp83-w826.json @@ -7,12 +7,8 @@ "CVE-2020-8588" ], "details": "Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15 are susceptible to a vulnerability which could allow unauthorized tenant users to discover the existence of data on other Storage Virtual Machines (SVMs).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rw44-jmrm-m8qc/GHSA-rw44-jmrm-m8qc.json b/advisories/unreviewed/2022/05/GHSA-rw44-jmrm-m8qc/GHSA-rw44-jmrm-m8qc.json index dfec38d1893..7dfc410b336 100644 --- a/advisories/unreviewed/2022/05/GHSA-rw44-jmrm-m8qc/GHSA-rw44-jmrm-m8qc.json +++ b/advisories/unreviewed/2022/05/GHSA-rw44-jmrm-m8qc/GHSA-rw44-jmrm-m8qc.json @@ -7,12 +7,8 @@ "CVE-2021-27160" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / 888888 credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rwpx-585c-m6rh/GHSA-rwpx-585c-m6rh.json b/advisories/unreviewed/2022/05/GHSA-rwpx-585c-m6rh/GHSA-rwpx-585c-m6rh.json index d4e66fae28a..05abf3924f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwpx-585c-m6rh/GHSA-rwpx-585c-m6rh.json +++ b/advisories/unreviewed/2022/05/GHSA-rwpx-585c-m6rh/GHSA-rwpx-585c-m6rh.json @@ -7,12 +7,8 @@ "CVE-2020-4795" ], "details": "IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information to an unauthorized user using a specially crafted HTTP request. IBM X-Force ID: 189446.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rxcr-7xjm-f9c9/GHSA-rxcr-7xjm-f9c9.json b/advisories/unreviewed/2022/05/GHSA-rxcr-7xjm-f9c9/GHSA-rxcr-7xjm-f9c9.json index 109a15d7a60..78728767552 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxcr-7xjm-f9c9/GHSA-rxcr-7xjm-f9c9.json +++ b/advisories/unreviewed/2022/05/GHSA-rxcr-7xjm-f9c9/GHSA-rxcr-7xjm-f9c9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v28p-8jwp-98gh/GHSA-v28p-8jwp-98gh.json b/advisories/unreviewed/2022/05/GHSA-v28p-8jwp-98gh/GHSA-v28p-8jwp-98gh.json index 2ba3ff5888f..d8b423c8cbd 100644 --- a/advisories/unreviewed/2022/05/GHSA-v28p-8jwp-98gh/GHSA-v28p-8jwp-98gh.json +++ b/advisories/unreviewed/2022/05/GHSA-v28p-8jwp-98gh/GHSA-v28p-8jwp-98gh.json @@ -7,12 +7,8 @@ "CVE-2020-20296" ], "details": "An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance parameter, malicious parameters can execute arbitrary SQL commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2fm-g8p8-hmh2/GHSA-v2fm-g8p8-hmh2.json b/advisories/unreviewed/2022/05/GHSA-v2fm-g8p8-hmh2/GHSA-v2fm-g8p8-hmh2.json index 99120d2a749..ea39e69e69c 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2fm-g8p8-hmh2/GHSA-v2fm-g8p8-hmh2.json +++ b/advisories/unreviewed/2022/05/GHSA-v2fm-g8p8-hmh2/GHSA-v2fm-g8p8-hmh2.json @@ -7,12 +7,8 @@ "CVE-2020-4768" ], "details": "IBM Case Manager 5.2 and 5.3 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188907.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2jr-9j8f-xxpp/GHSA-v2jr-9j8f-xxpp.json b/advisories/unreviewed/2022/05/GHSA-v2jr-9j8f-xxpp/GHSA-v2jr-9j8f-xxpp.json index c08a7458f7f..c81f63323df 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2jr-9j8f-xxpp/GHSA-v2jr-9j8f-xxpp.json +++ b/advisories/unreviewed/2022/05/GHSA-v2jr-9j8f-xxpp/GHSA-v2jr-9j8f-xxpp.json @@ -7,12 +7,8 @@ "CVE-2020-17421" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of NEF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11194.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v354-qw54-4f78/GHSA-v354-qw54-4f78.json b/advisories/unreviewed/2022/05/GHSA-v354-qw54-4f78/GHSA-v354-qw54-4f78.json index 97c98ca07b8..f26dadc03b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-v354-qw54-4f78/GHSA-v354-qw54-4f78.json +++ b/advisories/unreviewed/2022/05/GHSA-v354-qw54-4f78/GHSA-v354-qw54-4f78.json @@ -7,12 +7,8 @@ "CVE-2020-8101" ], "details": "Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in HTTP interface of ADT LifeShield DIY HD Video Doorbell allows an attacker on the same network to execute commands on the device. This issue affects: ADT LifeShield DIY HD Video Doorbell version 1.0.02R09 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v56p-8m5q-738r/GHSA-v56p-8m5q-738r.json b/advisories/unreviewed/2022/05/GHSA-v56p-8m5q-738r/GHSA-v56p-8m5q-738r.json index b8f0b280178..68c8b43ed3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-v56p-8m5q-738r/GHSA-v56p-8m5q-738r.json +++ b/advisories/unreviewed/2022/05/GHSA-v56p-8m5q-738r/GHSA-v56p-8m5q-738r.json @@ -7,12 +7,8 @@ "CVE-2020-22840" ], "details": "Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v59p-pfh8-62m9/GHSA-v59p-pfh8-62m9.json b/advisories/unreviewed/2022/05/GHSA-v59p-pfh8-62m9/GHSA-v59p-pfh8-62m9.json index e3b7701ba2c..0c13e5decc5 100644 --- a/advisories/unreviewed/2022/05/GHSA-v59p-pfh8-62m9/GHSA-v59p-pfh8-62m9.json +++ b/advisories/unreviewed/2022/05/GHSA-v59p-pfh8-62m9/GHSA-v59p-pfh8-62m9.json @@ -7,12 +7,8 @@ "CVE-2021-3333" ], "details": "Opmantek Open-AudIT 4.0.1 is affected by cross-site scripting (XSS). When outputting SQL statements for debugging, a maliciously crafted query can trigger an XSS attack. This attack only succeeds if the user is already logged in to Open-AudIT before they click the malicious link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v5r5-m654-v47x/GHSA-v5r5-m654-v47x.json b/advisories/unreviewed/2022/05/GHSA-v5r5-m654-v47x/GHSA-v5r5-m654-v47x.json index ce7814b43e5..3b5a3a632c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5r5-m654-v47x/GHSA-v5r5-m654-v47x.json +++ b/advisories/unreviewed/2022/05/GHSA-v5r5-m654-v47x/GHSA-v5r5-m654-v47x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v82c-gv92-52wp/GHSA-v82c-gv92-52wp.json b/advisories/unreviewed/2022/05/GHSA-v82c-gv92-52wp/GHSA-v82c-gv92-52wp.json index aacf8f0e597..eca685e2538 100644 --- a/advisories/unreviewed/2022/05/GHSA-v82c-gv92-52wp/GHSA-v82c-gv92-52wp.json +++ b/advisories/unreviewed/2022/05/GHSA-v82c-gv92-52wp/GHSA-v82c-gv92-52wp.json @@ -7,12 +7,8 @@ "CVE-2020-14246" ], "details": "HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak. An attacker could potentially decode the encoded credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v875-jf7g-hg8j/GHSA-v875-jf7g-hg8j.json b/advisories/unreviewed/2022/05/GHSA-v875-jf7g-hg8j/GHSA-v875-jf7g-hg8j.json index 0d1e5ddb185..1ebae8bbb3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-v875-jf7g-hg8j/GHSA-v875-jf7g-hg8j.json +++ b/advisories/unreviewed/2022/05/GHSA-v875-jf7g-hg8j/GHSA-v875-jf7g-hg8j.json @@ -7,12 +7,8 @@ "CVE-2021-21128" ], "details": "Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v8qq-whm6-fxjh/GHSA-v8qq-whm6-fxjh.json b/advisories/unreviewed/2022/05/GHSA-v8qq-whm6-fxjh/GHSA-v8qq-whm6-fxjh.json index 6e947b1b009..b7438a20699 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8qq-whm6-fxjh/GHSA-v8qq-whm6-fxjh.json +++ b/advisories/unreviewed/2022/05/GHSA-v8qq-whm6-fxjh/GHSA-v8qq-whm6-fxjh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v9h8-hgfv-94v4/GHSA-v9h8-hgfv-94v4.json b/advisories/unreviewed/2022/05/GHSA-v9h8-hgfv-94v4/GHSA-v9h8-hgfv-94v4.json index 618627719d1..e70390e7146 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9h8-hgfv-94v4/GHSA-v9h8-hgfv-94v4.json +++ b/advisories/unreviewed/2022/05/GHSA-v9h8-hgfv-94v4/GHSA-v9h8-hgfv-94v4.json @@ -7,12 +7,8 @@ "CVE-2021-25126" ], "details": "The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice downloadkvmjnlp_func function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vf7v-wqw9-gv37/GHSA-vf7v-wqw9-gv37.json b/advisories/unreviewed/2022/05/GHSA-vf7v-wqw9-gv37/GHSA-vf7v-wqw9-gv37.json index 78bf56c1abc..659ffd22e63 100644 --- a/advisories/unreviewed/2022/05/GHSA-vf7v-wqw9-gv37/GHSA-vf7v-wqw9-gv37.json +++ b/advisories/unreviewed/2022/05/GHSA-vf7v-wqw9-gv37/GHSA-vf7v-wqw9-gv37.json @@ -7,12 +7,8 @@ "CVE-2020-27004" ], "details": "A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing of CGM files. This could result in a memory access past the end of an allocated buffer. An attacker could leverage this vulnerability to access data in the context of the current process. (ZDI-CAN-12163)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vffp-xx76-rfqc/GHSA-vffp-xx76-rfqc.json b/advisories/unreviewed/2022/05/GHSA-vffp-xx76-rfqc/GHSA-vffp-xx76-rfqc.json index fa755922335..f4be0fa9e86 100644 --- a/advisories/unreviewed/2022/05/GHSA-vffp-xx76-rfqc/GHSA-vffp-xx76-rfqc.json +++ b/advisories/unreviewed/2022/05/GHSA-vffp-xx76-rfqc/GHSA-vffp-xx76-rfqc.json @@ -7,12 +7,8 @@ "CVE-2020-10538" ], "details": "An issue was discovered in Epikur before 20.1.1. It stores the secret passwords of the users as MD5 hashes in the database. MD5 can be brute-forced efficiently and should not be used for such purposes. Additionally, since no salt is used, rainbow tables can speed up the attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vfrw-4wr4-4c85/GHSA-vfrw-4wr4-4c85.json b/advisories/unreviewed/2022/05/GHSA-vfrw-4wr4-4c85/GHSA-vfrw-4wr4-4c85.json index 70efeb57689..1a5392b53aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfrw-4wr4-4c85/GHSA-vfrw-4wr4-4c85.json +++ b/advisories/unreviewed/2022/05/GHSA-vfrw-4wr4-4c85/GHSA-vfrw-4wr4-4c85.json @@ -7,12 +7,8 @@ "CVE-2020-25506" ], "details": "D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vg7p-2967-p5p3/GHSA-vg7p-2967-p5p3.json b/advisories/unreviewed/2022/05/GHSA-vg7p-2967-p5p3/GHSA-vg7p-2967-p5p3.json index bcba558083e..bab8ebcc5af 100644 --- a/advisories/unreviewed/2022/05/GHSA-vg7p-2967-p5p3/GHSA-vg7p-2967-p5p3.json +++ b/advisories/unreviewed/2022/05/GHSA-vg7p-2967-p5p3/GHSA-vg7p-2967-p5p3.json @@ -7,12 +7,8 @@ "CVE-2021-27177" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to bypass authentication by sending the decoded value of the GgpoZWxwCmxpc3QKd2hvCg== string to the telnet server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vh3x-x68x-6r47/GHSA-vh3x-x68x-6r47.json b/advisories/unreviewed/2022/05/GHSA-vh3x-x68x-6r47/GHSA-vh3x-x68x-6r47.json index d6584cbd2c9..47e60d313fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-vh3x-x68x-6r47/GHSA-vh3x-x68x-6r47.json +++ b/advisories/unreviewed/2022/05/GHSA-vh3x-x68x-6r47/GHSA-vh3x-x68x-6r47.json @@ -7,12 +7,8 @@ "CVE-2021-20353" ], "details": "IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 194882.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vhv9-x6wj-xx42/GHSA-vhv9-x6wj-xx42.json b/advisories/unreviewed/2022/05/GHSA-vhv9-x6wj-xx42/GHSA-vhv9-x6wj-xx42.json index 7c3dc6e564d..c8d2d03738d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhv9-x6wj-xx42/GHSA-vhv9-x6wj-xx42.json +++ b/advisories/unreviewed/2022/05/GHSA-vhv9-x6wj-xx42/GHSA-vhv9-x6wj-xx42.json @@ -7,12 +7,8 @@ "CVE-2020-20289" ], "details": "Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters, triggers a sql injection vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vhw2-m627-4r89/GHSA-vhw2-m627-4r89.json b/advisories/unreviewed/2022/05/GHSA-vhw2-m627-4r89/GHSA-vhw2-m627-4r89.json index 4c0330750a5..c5776337c53 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhw2-m627-4r89/GHSA-vhw2-m627-4r89.json +++ b/advisories/unreviewed/2022/05/GHSA-vhw2-m627-4r89/GHSA-vhw2-m627-4r89.json @@ -7,12 +7,8 @@ "CVE-2021-20358" ], "details": "IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 stores potentially sensitive information in clear text in API connection log files. This information could be obtained by a user with permissions to read log files. IBM X-Force ID: 194965.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vm56-hj47-795x/GHSA-vm56-hj47-795x.json b/advisories/unreviewed/2022/05/GHSA-vm56-hj47-795x/GHSA-vm56-hj47-795x.json index 9990dfee597..46829703fa2 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm56-hj47-795x/GHSA-vm56-hj47-795x.json +++ b/advisories/unreviewed/2022/05/GHSA-vm56-hj47-795x/GHSA-vm56-hj47-795x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vm99-6cff-jpcq/GHSA-vm99-6cff-jpcq.json b/advisories/unreviewed/2022/05/GHSA-vm99-6cff-jpcq/GHSA-vm99-6cff-jpcq.json index c60172bda36..4170ce56c4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm99-6cff-jpcq/GHSA-vm99-6cff-jpcq.json +++ b/advisories/unreviewed/2022/05/GHSA-vm99-6cff-jpcq/GHSA-vm99-6cff-jpcq.json @@ -7,12 +7,8 @@ "CVE-2020-25036" ], "details": "UCOPIA Wi-Fi appliances 6.0.5 allow authenticated remote attackers to escape the restricted administration shell CLI, and access a shell with admin user rights, via an unprotected less command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vmjg-j3qq-h4fv/GHSA-vmjg-j3qq-h4fv.json b/advisories/unreviewed/2022/05/GHSA-vmjg-j3qq-h4fv/GHSA-vmjg-j3qq-h4fv.json index 42e30728e16..458e0ffd8f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmjg-j3qq-h4fv/GHSA-vmjg-j3qq-h4fv.json +++ b/advisories/unreviewed/2022/05/GHSA-vmjg-j3qq-h4fv/GHSA-vmjg-j3qq-h4fv.json @@ -7,12 +7,8 @@ "CVE-2020-10048" ], "details": "A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verification process, an attacker could bypass the password protection set on protected files, thus being granted access to the protected content, circumventing authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vqp5-86j6-8f36/GHSA-vqp5-86j6-8f36.json b/advisories/unreviewed/2022/05/GHSA-vqp5-86j6-8f36/GHSA-vqp5-86j6-8f36.json index f9ef03bad7e..8daa96b48cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqp5-86j6-8f36/GHSA-vqp5-86j6-8f36.json +++ b/advisories/unreviewed/2022/05/GHSA-vqp5-86j6-8f36/GHSA-vqp5-86j6-8f36.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vqv8-75fg-f6w9/GHSA-vqv8-75fg-f6w9.json b/advisories/unreviewed/2022/05/GHSA-vqv8-75fg-f6w9/GHSA-vqv8-75fg-f6w9.json index 272e6fc89f2..0fe0d8d8878 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqv8-75fg-f6w9/GHSA-vqv8-75fg-f6w9.json +++ b/advisories/unreviewed/2022/05/GHSA-vqv8-75fg-f6w9/GHSA-vqv8-75fg-f6w9.json @@ -7,12 +7,8 @@ "CVE-2020-36243" ], "details": "The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can send a POST request that executes arbitrary OS commands via shell metacharacters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vvx2-gqg8-pxgr/GHSA-vvx2-gqg8-pxgr.json b/advisories/unreviewed/2022/05/GHSA-vvx2-gqg8-pxgr/GHSA-vvx2-gqg8-pxgr.json index 71a8d615ad7..71ac52b2e9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvx2-gqg8-pxgr/GHSA-vvx2-gqg8-pxgr.json +++ b/advisories/unreviewed/2022/05/GHSA-vvx2-gqg8-pxgr/GHSA-vvx2-gqg8-pxgr.json @@ -7,12 +7,8 @@ "CVE-2020-15836" ], "details": "An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function passes untrusted data to the operating system without proper sanitization. A crafted request can be sent to execute arbitrary commands as root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vwqx-w7g5-rmqm/GHSA-vwqx-w7g5-rmqm.json b/advisories/unreviewed/2022/05/GHSA-vwqx-w7g5-rmqm/GHSA-vwqx-w7g5-rmqm.json index 0c22bba10ed..a9061a4e675 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwqx-w7g5-rmqm/GHSA-vwqx-w7g5-rmqm.json +++ b/advisories/unreviewed/2022/05/GHSA-vwqx-w7g5-rmqm/GHSA-vwqx-w7g5-rmqm.json @@ -7,12 +7,8 @@ "CVE-2021-26689" ], "details": "An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. The USB laf gadget has a use-after-free. The LG ID is LVE-SMP-200031 (February 2021).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vwv9-76qv-g45f/GHSA-vwv9-76qv-g45f.json b/advisories/unreviewed/2022/05/GHSA-vwv9-76qv-g45f/GHSA-vwv9-76qv-g45f.json index 51fd7fcab96..c275eb0204d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwv9-76qv-g45f/GHSA-vwv9-76qv-g45f.json +++ b/advisories/unreviewed/2022/05/GHSA-vwv9-76qv-g45f/GHSA-vwv9-76qv-g45f.json @@ -7,12 +7,8 @@ "CVE-2021-21121" ], "details": "Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vxv5-cwf3-9w9q/GHSA-vxv5-cwf3-9w9q.json b/advisories/unreviewed/2022/05/GHSA-vxv5-cwf3-9w9q/GHSA-vxv5-cwf3-9w9q.json index afeb6ca4d20..20dcb6cc224 100644 --- a/advisories/unreviewed/2022/05/GHSA-vxv5-cwf3-9w9q/GHSA-vxv5-cwf3-9w9q.json +++ b/advisories/unreviewed/2022/05/GHSA-vxv5-cwf3-9w9q/GHSA-vxv5-cwf3-9w9q.json @@ -7,12 +7,8 @@ "CVE-2021-27159" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded useradmin / 888888 credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w3fw-6h3j-5r9q/GHSA-w3fw-6h3j-5r9q.json b/advisories/unreviewed/2022/05/GHSA-w3fw-6h3j-5r9q/GHSA-w3fw-6h3j-5r9q.json index db84d2911b1..103e23d0baf 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3fw-6h3j-5r9q/GHSA-w3fw-6h3j-5r9q.json +++ b/advisories/unreviewed/2022/05/GHSA-w3fw-6h3j-5r9q/GHSA-w3fw-6h3j-5r9q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w3pj-9p3h-pxx8/GHSA-w3pj-9p3h-pxx8.json b/advisories/unreviewed/2022/05/GHSA-w3pj-9p3h-pxx8/GHSA-w3pj-9p3h-pxx8.json index e59673638bf..16daa2c623a 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3pj-9p3h-pxx8/GHSA-w3pj-9p3h-pxx8.json +++ b/advisories/unreviewed/2022/05/GHSA-w3pj-9p3h-pxx8/GHSA-w3pj-9p3h-pxx8.json @@ -7,12 +7,8 @@ "CVE-2020-27871" ], "details": "This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within VulnerabilitySettings.aspx. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-11902.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w3q5-g4xc-24gf/GHSA-w3q5-g4xc-24gf.json b/advisories/unreviewed/2022/05/GHSA-w3q5-g4xc-24gf/GHSA-w3q5-g4xc-24gf.json index 0fd36467b91..5d20c64fdc8 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3q5-g4xc-24gf/GHSA-w3q5-g4xc-24gf.json +++ b/advisories/unreviewed/2022/05/GHSA-w3q5-g4xc-24gf/GHSA-w3q5-g4xc-24gf.json @@ -7,12 +7,8 @@ "CVE-2020-14418" ], "details": "A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges to SYSTEM. This occurs because path redirection can occur via vectors involving directory junctions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w3v3-4783-r6mv/GHSA-w3v3-4783-r6mv.json b/advisories/unreviewed/2022/05/GHSA-w3v3-4783-r6mv/GHSA-w3v3-4783-r6mv.json index 6964acddc86..1e016660cf8 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3v3-4783-r6mv/GHSA-w3v3-4783-r6mv.json +++ b/advisories/unreviewed/2022/05/GHSA-w3v3-4783-r6mv/GHSA-w3v3-4783-r6mv.json @@ -7,12 +7,8 @@ "CVE-2021-27150" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded gestiontelebucaramanga / t3l3buc4r4m4ng42013 credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w5p3-6pf5-78hg/GHSA-w5p3-6pf5-78hg.json b/advisories/unreviewed/2022/05/GHSA-w5p3-6pf5-78hg/GHSA-w5p3-6pf5-78hg.json index 17f90292869..3920740f735 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5p3-6pf5-78hg/GHSA-w5p3-6pf5-78hg.json +++ b/advisories/unreviewed/2022/05/GHSA-w5p3-6pf5-78hg/GHSA-w5p3-6pf5-78hg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w6r6-frp2-8r52/GHSA-w6r6-frp2-8r52.json b/advisories/unreviewed/2022/05/GHSA-w6r6-frp2-8r52/GHSA-w6r6-frp2-8r52.json index 24860f468dc..112fa4b1853 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6r6-frp2-8r52/GHSA-w6r6-frp2-8r52.json +++ b/advisories/unreviewed/2022/05/GHSA-w6r6-frp2-8r52/GHSA-w6r6-frp2-8r52.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w6vh-q47r-3xgq/GHSA-w6vh-q47r-3xgq.json b/advisories/unreviewed/2022/05/GHSA-w6vh-q47r-3xgq/GHSA-w6vh-q47r-3xgq.json index 61de7afd68f..5bcda88837f 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6vh-q47r-3xgq/GHSA-w6vh-q47r-3xgq.json +++ b/advisories/unreviewed/2022/05/GHSA-w6vh-q47r-3xgq/GHSA-w6vh-q47r-3xgq.json @@ -7,12 +7,8 @@ "CVE-2021-25773" ], "details": "JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w82x-g35v-536x/GHSA-w82x-g35v-536x.json b/advisories/unreviewed/2022/05/GHSA-w82x-g35v-536x/GHSA-w82x-g35v-536x.json index cb571d9712a..ae0fdb6e9fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-w82x-g35v-536x/GHSA-w82x-g35v-536x.json +++ b/advisories/unreviewed/2022/05/GHSA-w82x-g35v-536x/GHSA-w82x-g35v-536x.json @@ -7,12 +7,8 @@ "CVE-2021-23878" ], "details": "Clear text storage of sensitive Information in memory vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local user to view ENS settings and credentials via accessing process memory after the ENS administrator has performed specific actions. To exploit this, the local user has to access the relevant memory location immediately after an ENS administrator has made a configuration change through the console on their machine", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w929-59q2-gfxf/GHSA-w929-59q2-gfxf.json b/advisories/unreviewed/2022/05/GHSA-w929-59q2-gfxf/GHSA-w929-59q2-gfxf.json index c23602f4304..55350622df7 100644 --- a/advisories/unreviewed/2022/05/GHSA-w929-59q2-gfxf/GHSA-w929-59q2-gfxf.json +++ b/advisories/unreviewed/2022/05/GHSA-w929-59q2-gfxf/GHSA-w929-59q2-gfxf.json @@ -7,12 +7,8 @@ "CVE-2020-5812" ], "details": "Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w93q-c5fh-q4hj/GHSA-w93q-c5fh-q4hj.json b/advisories/unreviewed/2022/05/GHSA-w93q-c5fh-q4hj/GHSA-w93q-c5fh-q4hj.json index 376c4133448..62d642b33f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-w93q-c5fh-q4hj/GHSA-w93q-c5fh-q4hj.json +++ b/advisories/unreviewed/2022/05/GHSA-w93q-c5fh-q4hj/GHSA-w93q-c5fh-q4hj.json @@ -7,12 +7,8 @@ "CVE-2021-0325" ], "details": "In ih264d_parse_pslice of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-174238784", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w9pw-wrp2-gp5p/GHSA-w9pw-wrp2-gp5p.json b/advisories/unreviewed/2022/05/GHSA-w9pw-wrp2-gp5p/GHSA-w9pw-wrp2-gp5p.json index 3868472d8ab..efcb37d3a13 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9pw-wrp2-gp5p/GHSA-w9pw-wrp2-gp5p.json +++ b/advisories/unreviewed/2022/05/GHSA-w9pw-wrp2-gp5p/GHSA-w9pw-wrp2-gp5p.json @@ -7,12 +7,8 @@ "CVE-2021-27157" ], "details": "An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 888888 credentials for an ISP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w9rg-m5v9-r8xf/GHSA-w9rg-m5v9-r8xf.json b/advisories/unreviewed/2022/05/GHSA-w9rg-m5v9-r8xf/GHSA-w9rg-m5v9-r8xf.json index 304d3b389eb..30986d8c3f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9rg-m5v9-r8xf/GHSA-w9rg-m5v9-r8xf.json +++ b/advisories/unreviewed/2022/05/GHSA-w9rg-m5v9-r8xf/GHSA-w9rg-m5v9-r8xf.json @@ -7,12 +7,8 @@ "CVE-2021-0334" ], "details": "In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-163358811", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wcc2-hgw8-8prx/GHSA-wcc2-hgw8-8prx.json b/advisories/unreviewed/2022/05/GHSA-wcc2-hgw8-8prx/GHSA-wcc2-hgw8-8prx.json index fc090b587b2..2fd415acfba 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcc2-hgw8-8prx/GHSA-wcc2-hgw8-8prx.json +++ b/advisories/unreviewed/2022/05/GHSA-wcc2-hgw8-8prx/GHSA-wcc2-hgw8-8prx.json @@ -7,12 +7,8 @@ "CVE-2021-25171" ], "details": "The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so websetlicensecfg function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wfcg-xg9m-fp2f/GHSA-wfcg-xg9m-fp2f.json b/advisories/unreviewed/2022/05/GHSA-wfcg-xg9m-fp2f/GHSA-wfcg-xg9m-fp2f.json index 919ab63f180..d47f6ce55f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfcg-xg9m-fp2f/GHSA-wfcg-xg9m-fp2f.json +++ b/advisories/unreviewed/2022/05/GHSA-wfcg-xg9m-fp2f/GHSA-wfcg-xg9m-fp2f.json @@ -7,12 +7,8 @@ "CVE-2020-27222" ], "details": "In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because it sticks to a wrong internal state. That wrong internal state is set by a previous certificate based DTLS handshakes failure with TLS parameter mismatch. The server must be restarted to recover this. This allow clients to force a DoS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wfj8-v9x3-cw4h/GHSA-wfj8-v9x3-cw4h.json b/advisories/unreviewed/2022/05/GHSA-wfj8-v9x3-cw4h/GHSA-wfj8-v9x3-cw4h.json index 18e50e9d0a4..5fa3844c7a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfj8-v9x3-cw4h/GHSA-wfj8-v9x3-cw4h.json +++ b/advisories/unreviewed/2022/05/GHSA-wfj8-v9x3-cw4h/GHSA-wfj8-v9x3-cw4h.json @@ -7,12 +7,8 @@ "CVE-2020-24271" ], "details": "A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/insert/navTabId/rbacuser/callbackType/closeCurrent, then post username=***&password=***.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wfwh-pmv6-rmqq/GHSA-wfwh-pmv6-rmqq.json b/advisories/unreviewed/2022/05/GHSA-wfwh-pmv6-rmqq/GHSA-wfwh-pmv6-rmqq.json index 41ea0d4eccf..c54379cb9be 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfwh-pmv6-rmqq/GHSA-wfwh-pmv6-rmqq.json +++ b/advisories/unreviewed/2022/05/GHSA-wfwh-pmv6-rmqq/GHSA-wfwh-pmv6-rmqq.json @@ -7,12 +7,8 @@ "CVE-2020-22841" ], "details": "Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wg32-9vr9-f572/GHSA-wg32-9vr9-f572.json b/advisories/unreviewed/2022/05/GHSA-wg32-9vr9-f572/GHSA-wg32-9vr9-f572.json index 1912b06732a..e326cc5c11c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg32-9vr9-f572/GHSA-wg32-9vr9-f572.json +++ b/advisories/unreviewed/2022/05/GHSA-wg32-9vr9-f572/GHSA-wg32-9vr9-f572.json @@ -7,12 +7,8 @@ "CVE-2021-21475" ], "details": "Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs. Due to this Directory Traversal vulnerability the attacker could read content of arbitrary files on the remote server and expose sensitive data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wgq6-7gfw-mf96/GHSA-wgq6-7gfw-mf96.json b/advisories/unreviewed/2022/05/GHSA-wgq6-7gfw-mf96/GHSA-wgq6-7gfw-mf96.json index 95c96d9d2c6..6dbfefdd1dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgq6-7gfw-mf96/GHSA-wgq6-7gfw-mf96.json +++ b/advisories/unreviewed/2022/05/GHSA-wgq6-7gfw-mf96/GHSA-wgq6-7gfw-mf96.json @@ -7,12 +7,8 @@ "CVE-2021-25776" ], "details": "In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wgxr-4g2j-73wf/GHSA-wgxr-4g2j-73wf.json b/advisories/unreviewed/2022/05/GHSA-wgxr-4g2j-73wf/GHSA-wgxr-4g2j-73wf.json index 942ccff873a..d2bf233356e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgxr-4g2j-73wf/GHSA-wgxr-4g2j-73wf.json +++ b/advisories/unreviewed/2022/05/GHSA-wgxr-4g2j-73wf/GHSA-wgxr-4g2j-73wf.json @@ -7,12 +7,8 @@ "CVE-2020-29163" ], "details": "PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by SQL injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wh55-mm7m-3cw6/GHSA-wh55-mm7m-3cw6.json b/advisories/unreviewed/2022/05/GHSA-wh55-mm7m-3cw6/GHSA-wh55-mm7m-3cw6.json index 77012ba044d..c1f8d4153e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh55-mm7m-3cw6/GHSA-wh55-mm7m-3cw6.json +++ b/advisories/unreviewed/2022/05/GHSA-wh55-mm7m-3cw6/GHSA-wh55-mm7m-3cw6.json @@ -7,12 +7,8 @@ "CVE-2021-1341" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-whgg-x7cg-v7r9/GHSA-whgg-x7cg-v7r9.json b/advisories/unreviewed/2022/05/GHSA-whgg-x7cg-v7r9/GHSA-whgg-x7cg-v7r9.json index 557b103e80d..8036d7576e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-whgg-x7cg-v7r9/GHSA-whgg-x7cg-v7r9.json +++ b/advisories/unreviewed/2022/05/GHSA-whgg-x7cg-v7r9/GHSA-whgg-x7cg-v7r9.json @@ -7,12 +7,8 @@ "CVE-2020-4995" ], "details": "IBM Security Identity Governance and Intelligence 5.2.6 does not invalidate session after logout which could allow a user to obtain sensitive information from another users' session. IBM X-Force ID: 192912.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wj28-g25v-jc4f/GHSA-wj28-g25v-jc4f.json b/advisories/unreviewed/2022/05/GHSA-wj28-g25v-jc4f/GHSA-wj28-g25v-jc4f.json index 2401c8d5e8c..88239dd4605 100644 --- a/advisories/unreviewed/2022/05/GHSA-wj28-g25v-jc4f/GHSA-wj28-g25v-jc4f.json +++ b/advisories/unreviewed/2022/05/GHSA-wj28-g25v-jc4f/GHSA-wj28-g25v-jc4f.json @@ -7,12 +7,8 @@ "CVE-2020-18716" ], "details": "SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAction.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wjr5-3fx3-2rvx/GHSA-wjr5-3fx3-2rvx.json b/advisories/unreviewed/2022/05/GHSA-wjr5-3fx3-2rvx/GHSA-wjr5-3fx3-2rvx.json index fed1c332921..21d4b4347ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjr5-3fx3-2rvx/GHSA-wjr5-3fx3-2rvx.json +++ b/advisories/unreviewed/2022/05/GHSA-wjr5-3fx3-2rvx/GHSA-wjr5-3fx3-2rvx.json @@ -7,12 +7,8 @@ "CVE-2020-27006" ], "details": "A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing of PCT files. This could result in a memory corruption condition. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-12182)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wp4m-572g-9345/GHSA-wp4m-572g-9345.json b/advisories/unreviewed/2022/05/GHSA-wp4m-572g-9345/GHSA-wp4m-572g-9345.json index 86c036ab2d3..7f40360a826 100644 --- a/advisories/unreviewed/2022/05/GHSA-wp4m-572g-9345/GHSA-wp4m-572g-9345.json +++ b/advisories/unreviewed/2022/05/GHSA-wp4m-572g-9345/GHSA-wp4m-572g-9345.json @@ -7,12 +7,8 @@ "CVE-2020-18714" ], "details": "SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordModel.php's getdata function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wpwr-fc52-h69c/GHSA-wpwr-fc52-h69c.json b/advisories/unreviewed/2022/05/GHSA-wpwr-fc52-h69c/GHSA-wpwr-fc52-h69c.json index dac5a85bf3e..35968ed5778 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpwr-fc52-h69c/GHSA-wpwr-fc52-h69c.json +++ b/advisories/unreviewed/2022/05/GHSA-wpwr-fc52-h69c/GHSA-wpwr-fc52-h69c.json @@ -7,12 +7,8 @@ "CVE-2019-16268" ], "details": "Zoho ManageEngine Remote Access Plus 10.0.259 allows HTML injection via the Description field on the Admin - User Administration userMgmt.do?actionToCall=ShowUser screen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wrq6-7947-r2fc/GHSA-wrq6-7947-r2fc.json b/advisories/unreviewed/2022/05/GHSA-wrq6-7947-r2fc/GHSA-wrq6-7947-r2fc.json index 094b35ccc73..e65530a8d82 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrq6-7947-r2fc/GHSA-wrq6-7947-r2fc.json +++ b/advisories/unreviewed/2022/05/GHSA-wrq6-7947-r2fc/GHSA-wrq6-7947-r2fc.json @@ -7,12 +7,8 @@ "CVE-2020-10858" ], "details": "Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wvvr-q98h-37h6/GHSA-wvvr-q98h-37h6.json b/advisories/unreviewed/2022/05/GHSA-wvvr-q98h-37h6/GHSA-wvvr-q98h-37h6.json index f8fc12c03ec..45166006195 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvvr-q98h-37h6/GHSA-wvvr-q98h-37h6.json +++ b/advisories/unreviewed/2022/05/GHSA-wvvr-q98h-37h6/GHSA-wvvr-q98h-37h6.json @@ -7,12 +7,8 @@ "CVE-2020-21180" ], "details": "Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to the signup page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ww6m-3fjc-mvfw/GHSA-ww6m-3fjc-mvfw.json b/advisories/unreviewed/2022/05/GHSA-ww6m-3fjc-mvfw/GHSA-ww6m-3fjc-mvfw.json index 22128ba287d..330dc031668 100644 --- a/advisories/unreviewed/2022/05/GHSA-ww6m-3fjc-mvfw/GHSA-ww6m-3fjc-mvfw.json +++ b/advisories/unreviewed/2022/05/GHSA-ww6m-3fjc-mvfw/GHSA-ww6m-3fjc-mvfw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x29m-vmxh-c2mf/GHSA-x29m-vmxh-c2mf.json b/advisories/unreviewed/2022/05/GHSA-x29m-vmxh-c2mf/GHSA-x29m-vmxh-c2mf.json index 7cff004257b..24fd5939caa 100644 --- a/advisories/unreviewed/2022/05/GHSA-x29m-vmxh-c2mf/GHSA-x29m-vmxh-c2mf.json +++ b/advisories/unreviewed/2022/05/GHSA-x29m-vmxh-c2mf/GHSA-x29m-vmxh-c2mf.json @@ -7,12 +7,8 @@ "CVE-2021-3294" ], "details": "CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a cookie to perform user redirection to a malicious website.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x47q-p47x-3235/GHSA-x47q-p47x-3235.json b/advisories/unreviewed/2022/05/GHSA-x47q-p47x-3235/GHSA-x47q-p47x-3235.json index e11e82a84a2..428e158af89 100644 --- a/advisories/unreviewed/2022/05/GHSA-x47q-p47x-3235/GHSA-x47q-p47x-3235.json +++ b/advisories/unreviewed/2022/05/GHSA-x47q-p47x-3235/GHSA-x47q-p47x-3235.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x4c3-xfxx-vh9f/GHSA-x4c3-xfxx-vh9f.json b/advisories/unreviewed/2022/05/GHSA-x4c3-xfxx-vh9f/GHSA-x4c3-xfxx-vh9f.json index 08bea0a9bb9..6802beda9ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4c3-xfxx-vh9f/GHSA-x4c3-xfxx-vh9f.json +++ b/advisories/unreviewed/2022/05/GHSA-x4c3-xfxx-vh9f/GHSA-x4c3-xfxx-vh9f.json @@ -7,12 +7,8 @@ "CVE-2021-21055" ], "details": "Adobe Dreamweaver versions 21.0 (and earlier) and 20.2 (and earlier) is affected by an untrusted search path vulnerability that could result in information disclosure. An attacker with physical access to the system could replace certain configuration files and dynamic libraries that Dreamweaver references, potentially resulting in information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x5pq-ph4c-8g27/GHSA-x5pq-ph4c-8g27.json b/advisories/unreviewed/2022/05/GHSA-x5pq-ph4c-8g27/GHSA-x5pq-ph4c-8g27.json index d9215c9153f..a8d942f3f8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5pq-ph4c-8g27/GHSA-x5pq-ph4c-8g27.json +++ b/advisories/unreviewed/2022/05/GHSA-x5pq-ph4c-8g27/GHSA-x5pq-ph4c-8g27.json @@ -7,12 +7,8 @@ "CVE-2021-25130" ], "details": "The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice setactdir_func function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x633-mvxm-f9pp/GHSA-x633-mvxm-f9pp.json b/advisories/unreviewed/2022/05/GHSA-x633-mvxm-f9pp/GHSA-x633-mvxm-f9pp.json index b09a83982a4..1de22cff015 100644 --- a/advisories/unreviewed/2022/05/GHSA-x633-mvxm-f9pp/GHSA-x633-mvxm-f9pp.json +++ b/advisories/unreviewed/2022/05/GHSA-x633-mvxm-f9pp/GHSA-x633-mvxm-f9pp.json @@ -7,12 +7,8 @@ "CVE-2020-15832" ], "details": "An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The poof.cgi script contains undocumented code that provides the ability to remotely reboot the device. An adversary with the private key (but not the root password) can remotely reboot the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x69r-8f37-6mwc/GHSA-x69r-8f37-6mwc.json b/advisories/unreviewed/2022/05/GHSA-x69r-8f37-6mwc/GHSA-x69r-8f37-6mwc.json index ee6813a6fe9..eae78fc856f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x69r-8f37-6mwc/GHSA-x69r-8f37-6mwc.json +++ b/advisories/unreviewed/2022/05/GHSA-x69r-8f37-6mwc/GHSA-x69r-8f37-6mwc.json @@ -7,12 +7,8 @@ "CVE-2021-26913" ], "details": "NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in RpcServlet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x9r4-mg7m-xg3w/GHSA-x9r4-mg7m-xg3w.json b/advisories/unreviewed/2022/05/GHSA-x9r4-mg7m-xg3w/GHSA-x9r4-mg7m-xg3w.json index 3bf7f19c72c..7d8d177c4fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9r4-mg7m-xg3w/GHSA-x9r4-mg7m-xg3w.json +++ b/advisories/unreviewed/2022/05/GHSA-x9r4-mg7m-xg3w/GHSA-x9r4-mg7m-xg3w.json @@ -7,12 +7,8 @@ "CVE-2020-17428" ], "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of CMP files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-11336.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xcf5-m6c7-75hg/GHSA-xcf5-m6c7-75hg.json b/advisories/unreviewed/2022/05/GHSA-xcf5-m6c7-75hg/GHSA-xcf5-m6c7-75hg.json index 5c8528dc5cd..7fa60b434e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcf5-m6c7-75hg/GHSA-xcf5-m6c7-75hg.json +++ b/advisories/unreviewed/2022/05/GHSA-xcf5-m6c7-75hg/GHSA-xcf5-m6c7-75hg.json @@ -7,12 +7,8 @@ "CVE-2021-3122" ], "details": "CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to port 8089) that enables the remote, unauthenticated execution of an arbitrary command as SYSTEM, as exploited in the wild in 2020 and/or 2021. NOTE: the vendor's position is that exploitation occurs only on devices with a certain \"misconfiguration.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xcrf-82h4-f366/GHSA-xcrf-82h4-f366.json b/advisories/unreviewed/2022/05/GHSA-xcrf-82h4-f366/GHSA-xcrf-82h4-f366.json index bd8e9ac9aa4..ad574afbbdf 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcrf-82h4-f366/GHSA-xcrf-82h4-f366.json +++ b/advisories/unreviewed/2022/05/GHSA-xcrf-82h4-f366/GHSA-xcrf-82h4-f366.json @@ -7,12 +7,8 @@ "CVE-2020-27855" ], "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SR2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-11433.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xcrp-9h4m-qq97/GHSA-xcrp-9h4m-qq97.json b/advisories/unreviewed/2022/05/GHSA-xcrp-9h4m-qq97/GHSA-xcrp-9h4m-qq97.json index 7150e9c39b6..373ea4f013a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcrp-9h4m-qq97/GHSA-xcrp-9h4m-qq97.json +++ b/advisories/unreviewed/2022/05/GHSA-xcrp-9h4m-qq97/GHSA-xcrp-9h4m-qq97.json @@ -7,12 +7,8 @@ "CVE-2021-0314" ], "details": "In onCreate of UninstallerActivity, there is a possible way to uninstall an all without informed user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-171221302", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xff9-cgjh-mvpp/GHSA-xff9-cgjh-mvpp.json b/advisories/unreviewed/2022/05/GHSA-xff9-cgjh-mvpp/GHSA-xff9-cgjh-mvpp.json index 1efead05b42..f0dabcbaf19 100644 --- a/advisories/unreviewed/2022/05/GHSA-xff9-cgjh-mvpp/GHSA-xff9-cgjh-mvpp.json +++ b/advisories/unreviewed/2022/05/GHSA-xff9-cgjh-mvpp/GHSA-xff9-cgjh-mvpp.json @@ -7,12 +7,8 @@ "CVE-2020-29538" ], "details": "Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote authenticated malicious administrative user can potentially exploit this vulnerability to gather information about the system, and may use this information in subsequent attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xh7c-xrrg-3jv2/GHSA-xh7c-xrrg-3jv2.json b/advisories/unreviewed/2022/05/GHSA-xh7c-xrrg-3jv2/GHSA-xh7c-xrrg-3jv2.json index acdeab0194d..2d9a3f064bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-xh7c-xrrg-3jv2/GHSA-xh7c-xrrg-3jv2.json +++ b/advisories/unreviewed/2022/05/GHSA-xh7c-xrrg-3jv2/GHSA-xh7c-xrrg-3jv2.json @@ -7,12 +7,8 @@ "CVE-2020-16194" ], "details": "An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery address by exploiting an IDOR on the delivery_address and invoice_address fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xhqc-7m79-5gq4/GHSA-xhqc-7m79-5gq4.json b/advisories/unreviewed/2022/05/GHSA-xhqc-7m79-5gq4/GHSA-xhqc-7m79-5gq4.json index fdb40f1d281..0d8c1d60463 100644 --- a/advisories/unreviewed/2022/05/GHSA-xhqc-7m79-5gq4/GHSA-xhqc-7m79-5gq4.json +++ b/advisories/unreviewed/2022/05/GHSA-xhqc-7m79-5gq4/GHSA-xhqc-7m79-5gq4.json @@ -7,12 +7,8 @@ "CVE-2021-25128" ], "details": "The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spx_restservice gethelpdata_func function path traversal vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xhw7-9wqv-ffm2/GHSA-xhw7-9wqv-ffm2.json b/advisories/unreviewed/2022/05/GHSA-xhw7-9wqv-ffm2/GHSA-xhw7-9wqv-ffm2.json index 9dbb64501c4..f0ad5c2c732 100644 --- a/advisories/unreviewed/2022/05/GHSA-xhw7-9wqv-ffm2/GHSA-xhw7-9wqv-ffm2.json +++ b/advisories/unreviewed/2022/05/GHSA-xhw7-9wqv-ffm2/GHSA-xhw7-9wqv-ffm2.json @@ -7,12 +7,8 @@ "CVE-2021-25142" ], "details": "The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webstartflash function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjfj-5c48-9853/GHSA-xjfj-5c48-9853.json b/advisories/unreviewed/2022/05/GHSA-xjfj-5c48-9853/GHSA-xjfj-5c48-9853.json index f3df1424118..f77754083c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjfj-5c48-9853/GHSA-xjfj-5c48-9853.json +++ b/advisories/unreviewed/2022/05/GHSA-xjfj-5c48-9853/GHSA-xjfj-5c48-9853.json @@ -7,12 +7,8 @@ "CVE-2021-21132" ], "details": "Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xp84-q6q5-7pv4/GHSA-xp84-q6q5-7pv4.json b/advisories/unreviewed/2022/05/GHSA-xp84-q6q5-7pv4/GHSA-xp84-q6q5-7pv4.json index 238e5a8e7b5..125bbb0f6f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-xp84-q6q5-7pv4/GHSA-xp84-q6q5-7pv4.json +++ b/advisories/unreviewed/2022/05/GHSA-xp84-q6q5-7pv4/GHSA-xp84-q6q5-7pv4.json @@ -7,12 +7,8 @@ "CVE-2021-21053" ], "details": "Adobe Illustrator version 25.1 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xq55-4x3m-2f97/GHSA-xq55-4x3m-2f97.json b/advisories/unreviewed/2022/05/GHSA-xq55-4x3m-2f97/GHSA-xq55-4x3m-2f97.json index 2c1cd9b6460..5dba4b1130f 100644 --- a/advisories/unreviewed/2022/05/GHSA-xq55-4x3m-2f97/GHSA-xq55-4x3m-2f97.json +++ b/advisories/unreviewed/2022/05/GHSA-xq55-4x3m-2f97/GHSA-xq55-4x3m-2f97.json @@ -7,12 +7,8 @@ "CVE-2020-17419" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of NEF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11192.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xw9h-8vfr-ppf5/GHSA-xw9h-8vfr-ppf5.json b/advisories/unreviewed/2022/05/GHSA-xw9h-8vfr-ppf5/GHSA-xw9h-8vfr-ppf5.json index 666a48ba5aa..9d3c4d73d1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw9h-8vfr-ppf5/GHSA-xw9h-8vfr-ppf5.json +++ b/advisories/unreviewed/2022/05/GHSA-xw9h-8vfr-ppf5/GHSA-xw9h-8vfr-ppf5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xwv3-xrx8-63rf/GHSA-xwv3-xrx8-63rf.json b/advisories/unreviewed/2022/05/GHSA-xwv3-xrx8-63rf/GHSA-xwv3-xrx8-63rf.json index b9b35c588f6..302ce530afe 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwv3-xrx8-63rf/GHSA-xwv3-xrx8-63rf.json +++ b/advisories/unreviewed/2022/05/GHSA-xwv3-xrx8-63rf/GHSA-xwv3-xrx8-63rf.json @@ -7,12 +7,8 @@ "CVE-2020-1910" ], "details": "A missing bounds check in WhatsApp for Android prior to v2.21.1.13 and WhatsApp Business for Android prior to v2.21.1.13 could have allowed out-of-bounds read and write if a user applied specific image filters to a specially crafted image and sent the resulting image.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xxcc-4hjx-8q5v/GHSA-xxcc-4hjx-8q5v.json b/advisories/unreviewed/2022/05/GHSA-xxcc-4hjx-8q5v/GHSA-xxcc-4hjx-8q5v.json index 1ede3edab4a..537abe9e6bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxcc-4hjx-8q5v/GHSA-xxcc-4hjx-8q5v.json +++ b/advisories/unreviewed/2022/05/GHSA-xxcc-4hjx-8q5v/GHSA-xxcc-4hjx-8q5v.json @@ -7,12 +7,8 @@ "CVE-2021-1335" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xxvc-26j5-3mg9/GHSA-xxvc-26j5-3mg9.json b/advisories/unreviewed/2022/05/GHSA-xxvc-26j5-3mg9/GHSA-xxvc-26j5-3mg9.json index a6125494e4b..9a9bcec3143 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxvc-26j5-3mg9/GHSA-xxvc-26j5-3mg9.json +++ b/advisories/unreviewed/2022/05/GHSA-xxvc-26j5-3mg9/GHSA-xxvc-26j5-3mg9.json @@ -7,12 +7,8 @@ "CVE-2021-22500" ], "details": "Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could be exploited by attacker to trick the users into executing actions of the attacker's choosing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xxwg-wfjg-vgjp/GHSA-xxwg-wfjg-vgjp.json b/advisories/unreviewed/2022/05/GHSA-xxwg-wfjg-vgjp/GHSA-xxwg-wfjg-vgjp.json index 1375756e7ac..49ff7467847 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxwg-wfjg-vgjp/GHSA-xxwg-wfjg-vgjp.json +++ b/advisories/unreviewed/2022/05/GHSA-xxwg-wfjg-vgjp/GHSA-xxwg-wfjg-vgjp.json @@ -7,12 +7,8 @@ "CVE-2019-25018" ], "details": "In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the filename of . or an empty filename, similar to CVE-2018-20685 and CVE-2019-7282. The impact is modifying the permissions of the target directory on the client side. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/06/GHSA-mh3r-vrg4-68p4/GHSA-mh3r-vrg4-68p4.json b/advisories/unreviewed/2022/06/GHSA-mh3r-vrg4-68p4/GHSA-mh3r-vrg4-68p4.json index 3c2831a2355..3022a7a7721 100644 --- a/advisories/unreviewed/2022/06/GHSA-mh3r-vrg4-68p4/GHSA-mh3r-vrg4-68p4.json +++ b/advisories/unreviewed/2022/06/GHSA-mh3r-vrg4-68p4/GHSA-mh3r-vrg4-68p4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/06/GHSA-qq3x-ppcw-6fmq/GHSA-qq3x-ppcw-6fmq.json b/advisories/unreviewed/2022/06/GHSA-qq3x-ppcw-6fmq/GHSA-qq3x-ppcw-6fmq.json index 330257a8bf6..48f0ada26a5 100644 --- a/advisories/unreviewed/2022/06/GHSA-qq3x-ppcw-6fmq/GHSA-qq3x-ppcw-6fmq.json +++ b/advisories/unreviewed/2022/06/GHSA-qq3x-ppcw-6fmq/GHSA-qq3x-ppcw-6fmq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/06/GHSA-xfr9-hqm4-5288/GHSA-xfr9-hqm4-5288.json b/advisories/unreviewed/2022/06/GHSA-xfr9-hqm4-5288/GHSA-xfr9-hqm4-5288.json index 17315c77be2..9d9dbbc1cbf 100644 --- a/advisories/unreviewed/2022/06/GHSA-xfr9-hqm4-5288/GHSA-xfr9-hqm4-5288.json +++ b/advisories/unreviewed/2022/06/GHSA-xfr9-hqm4-5288/GHSA-xfr9-hqm4-5288.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-2c24-m9rj-gq8m/GHSA-2c24-m9rj-gq8m.json b/advisories/unreviewed/2022/07/GHSA-2c24-m9rj-gq8m/GHSA-2c24-m9rj-gq8m.json index 5a1c385a22c..8046713c844 100644 --- a/advisories/unreviewed/2022/07/GHSA-2c24-m9rj-gq8m/GHSA-2c24-m9rj-gq8m.json +++ b/advisories/unreviewed/2022/07/GHSA-2c24-m9rj-gq8m/GHSA-2c24-m9rj-gq8m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-2h44-v83q-fj6m/GHSA-2h44-v83q-fj6m.json b/advisories/unreviewed/2022/07/GHSA-2h44-v83q-fj6m/GHSA-2h44-v83q-fj6m.json index 74b9b9df87b..f154b593768 100644 --- a/advisories/unreviewed/2022/07/GHSA-2h44-v83q-fj6m/GHSA-2h44-v83q-fj6m.json +++ b/advisories/unreviewed/2022/07/GHSA-2h44-v83q-fj6m/GHSA-2h44-v83q-fj6m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-2pxw-qgwm-32jg/GHSA-2pxw-qgwm-32jg.json b/advisories/unreviewed/2022/07/GHSA-2pxw-qgwm-32jg/GHSA-2pxw-qgwm-32jg.json index de52dbdf38b..5e885adacc8 100644 --- a/advisories/unreviewed/2022/07/GHSA-2pxw-qgwm-32jg/GHSA-2pxw-qgwm-32jg.json +++ b/advisories/unreviewed/2022/07/GHSA-2pxw-qgwm-32jg/GHSA-2pxw-qgwm-32jg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-77f9-jv8v-xrjp/GHSA-77f9-jv8v-xrjp.json b/advisories/unreviewed/2022/07/GHSA-77f9-jv8v-xrjp/GHSA-77f9-jv8v-xrjp.json index c36cbd77f43..1ff19e0c25a 100644 --- a/advisories/unreviewed/2022/07/GHSA-77f9-jv8v-xrjp/GHSA-77f9-jv8v-xrjp.json +++ b/advisories/unreviewed/2022/07/GHSA-77f9-jv8v-xrjp/GHSA-77f9-jv8v-xrjp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-9fmj-x3g8-hmqv/GHSA-9fmj-x3g8-hmqv.json b/advisories/unreviewed/2022/07/GHSA-9fmj-x3g8-hmqv/GHSA-9fmj-x3g8-hmqv.json index 22e1d91df28..c7e71578f1f 100644 --- a/advisories/unreviewed/2022/07/GHSA-9fmj-x3g8-hmqv/GHSA-9fmj-x3g8-hmqv.json +++ b/advisories/unreviewed/2022/07/GHSA-9fmj-x3g8-hmqv/GHSA-9fmj-x3g8-hmqv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-f5vc-gmmj-gpp6/GHSA-f5vc-gmmj-gpp6.json b/advisories/unreviewed/2022/07/GHSA-f5vc-gmmj-gpp6/GHSA-f5vc-gmmj-gpp6.json index c247474d99b..fba0845c74a 100644 --- a/advisories/unreviewed/2022/07/GHSA-f5vc-gmmj-gpp6/GHSA-f5vc-gmmj-gpp6.json +++ b/advisories/unreviewed/2022/07/GHSA-f5vc-gmmj-gpp6/GHSA-f5vc-gmmj-gpp6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/07/GHSA-g2cf-r83x-vvf5/GHSA-g2cf-r83x-vvf5.json b/advisories/unreviewed/2022/07/GHSA-g2cf-r83x-vvf5/GHSA-g2cf-r83x-vvf5.json index 4527a320c84..1213379c7c9 100644 --- a/advisories/unreviewed/2022/07/GHSA-g2cf-r83x-vvf5/GHSA-g2cf-r83x-vvf5.json +++ b/advisories/unreviewed/2022/07/GHSA-g2cf-r83x-vvf5/GHSA-g2cf-r83x-vvf5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-g37v-jxpm-83fp/GHSA-g37v-jxpm-83fp.json b/advisories/unreviewed/2022/07/GHSA-g37v-jxpm-83fp/GHSA-g37v-jxpm-83fp.json index 05ef2902a7c..eac5db2d448 100644 --- a/advisories/unreviewed/2022/07/GHSA-g37v-jxpm-83fp/GHSA-g37v-jxpm-83fp.json +++ b/advisories/unreviewed/2022/07/GHSA-g37v-jxpm-83fp/GHSA-g37v-jxpm-83fp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-rcwq-vxfc-36p5/GHSA-rcwq-vxfc-36p5.json b/advisories/unreviewed/2022/07/GHSA-rcwq-vxfc-36p5/GHSA-rcwq-vxfc-36p5.json index 2ea8fc0c2ab..cea949a2cb5 100644 --- a/advisories/unreviewed/2022/07/GHSA-rcwq-vxfc-36p5/GHSA-rcwq-vxfc-36p5.json +++ b/advisories/unreviewed/2022/07/GHSA-rcwq-vxfc-36p5/GHSA-rcwq-vxfc-36p5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-8662-6hf9-cr47/GHSA-8662-6hf9-cr47.json b/advisories/unreviewed/2022/08/GHSA-8662-6hf9-cr47/GHSA-8662-6hf9-cr47.json index 2e93f854baf..8aa0712faf8 100644 --- a/advisories/unreviewed/2022/08/GHSA-8662-6hf9-cr47/GHSA-8662-6hf9-cr47.json +++ b/advisories/unreviewed/2022/08/GHSA-8662-6hf9-cr47/GHSA-8662-6hf9-cr47.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-gcvh-452x-5mh3/GHSA-gcvh-452x-5mh3.json b/advisories/unreviewed/2022/08/GHSA-gcvh-452x-5mh3/GHSA-gcvh-452x-5mh3.json index 2d79ba176ea..15d1ef3459d 100644 --- a/advisories/unreviewed/2022/08/GHSA-gcvh-452x-5mh3/GHSA-gcvh-452x-5mh3.json +++ b/advisories/unreviewed/2022/08/GHSA-gcvh-452x-5mh3/GHSA-gcvh-452x-5mh3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-h8mv-q3c4-8hw2/GHSA-h8mv-q3c4-8hw2.json b/advisories/unreviewed/2022/08/GHSA-h8mv-q3c4-8hw2/GHSA-h8mv-q3c4-8hw2.json index f39b5ab6235..40a5fb85570 100644 --- a/advisories/unreviewed/2022/08/GHSA-h8mv-q3c4-8hw2/GHSA-h8mv-q3c4-8hw2.json +++ b/advisories/unreviewed/2022/08/GHSA-h8mv-q3c4-8hw2/GHSA-h8mv-q3c4-8hw2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-r2vv-rr99-h5p9/GHSA-r2vv-rr99-h5p9.json b/advisories/unreviewed/2022/08/GHSA-r2vv-rr99-h5p9/GHSA-r2vv-rr99-h5p9.json index 67530a0caa5..8e52fab8142 100644 --- a/advisories/unreviewed/2022/08/GHSA-r2vv-rr99-h5p9/GHSA-r2vv-rr99-h5p9.json +++ b/advisories/unreviewed/2022/08/GHSA-r2vv-rr99-h5p9/GHSA-r2vv-rr99-h5p9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-29x2-p4f6-vfcw/GHSA-29x2-p4f6-vfcw.json b/advisories/unreviewed/2022/09/GHSA-29x2-p4f6-vfcw/GHSA-29x2-p4f6-vfcw.json index 70452c02f82..fc2e54a8401 100644 --- a/advisories/unreviewed/2022/09/GHSA-29x2-p4f6-vfcw/GHSA-29x2-p4f6-vfcw.json +++ b/advisories/unreviewed/2022/09/GHSA-29x2-p4f6-vfcw/GHSA-29x2-p4f6-vfcw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-2xvj-f2r6-3cg7/GHSA-2xvj-f2r6-3cg7.json b/advisories/unreviewed/2022/09/GHSA-2xvj-f2r6-3cg7/GHSA-2xvj-f2r6-3cg7.json index 52b4fea9758..9cd7591205b 100644 --- a/advisories/unreviewed/2022/09/GHSA-2xvj-f2r6-3cg7/GHSA-2xvj-f2r6-3cg7.json +++ b/advisories/unreviewed/2022/09/GHSA-2xvj-f2r6-3cg7/GHSA-2xvj-f2r6-3cg7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-3cjx-7cj6-qvq3/GHSA-3cjx-7cj6-qvq3.json b/advisories/unreviewed/2022/09/GHSA-3cjx-7cj6-qvq3/GHSA-3cjx-7cj6-qvq3.json index ceef44ace51..44e308f2a72 100644 --- a/advisories/unreviewed/2022/09/GHSA-3cjx-7cj6-qvq3/GHSA-3cjx-7cj6-qvq3.json +++ b/advisories/unreviewed/2022/09/GHSA-3cjx-7cj6-qvq3/GHSA-3cjx-7cj6-qvq3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-4fq5-r4vp-7ph5/GHSA-4fq5-r4vp-7ph5.json b/advisories/unreviewed/2022/09/GHSA-4fq5-r4vp-7ph5/GHSA-4fq5-r4vp-7ph5.json index 69b6e9f90f9..28eebcccfa0 100644 --- a/advisories/unreviewed/2022/09/GHSA-4fq5-r4vp-7ph5/GHSA-4fq5-r4vp-7ph5.json +++ b/advisories/unreviewed/2022/09/GHSA-4fq5-r4vp-7ph5/GHSA-4fq5-r4vp-7ph5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-69f5-4grj-mqr7/GHSA-69f5-4grj-mqr7.json b/advisories/unreviewed/2022/09/GHSA-69f5-4grj-mqr7/GHSA-69f5-4grj-mqr7.json index d113072bf5d..3effe9a0c28 100644 --- a/advisories/unreviewed/2022/09/GHSA-69f5-4grj-mqr7/GHSA-69f5-4grj-mqr7.json +++ b/advisories/unreviewed/2022/09/GHSA-69f5-4grj-mqr7/GHSA-69f5-4grj-mqr7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-6mqc-jm93-59f3/GHSA-6mqc-jm93-59f3.json b/advisories/unreviewed/2022/09/GHSA-6mqc-jm93-59f3/GHSA-6mqc-jm93-59f3.json index 6f98f3474aa..991686660e4 100644 --- a/advisories/unreviewed/2022/09/GHSA-6mqc-jm93-59f3/GHSA-6mqc-jm93-59f3.json +++ b/advisories/unreviewed/2022/09/GHSA-6mqc-jm93-59f3/GHSA-6mqc-jm93-59f3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-779j-v68w-458w/GHSA-779j-v68w-458w.json b/advisories/unreviewed/2022/09/GHSA-779j-v68w-458w/GHSA-779j-v68w-458w.json index fc16c7778f9..6765058f9a5 100644 --- a/advisories/unreviewed/2022/09/GHSA-779j-v68w-458w/GHSA-779j-v68w-458w.json +++ b/advisories/unreviewed/2022/09/GHSA-779j-v68w-458w/GHSA-779j-v68w-458w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-8cmp-crm3-jrh4/GHSA-8cmp-crm3-jrh4.json b/advisories/unreviewed/2022/09/GHSA-8cmp-crm3-jrh4/GHSA-8cmp-crm3-jrh4.json index 364d907cd89..c8c1f3739fa 100644 --- a/advisories/unreviewed/2022/09/GHSA-8cmp-crm3-jrh4/GHSA-8cmp-crm3-jrh4.json +++ b/advisories/unreviewed/2022/09/GHSA-8cmp-crm3-jrh4/GHSA-8cmp-crm3-jrh4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-99gj-9798-gpx5/GHSA-99gj-9798-gpx5.json b/advisories/unreviewed/2022/09/GHSA-99gj-9798-gpx5/GHSA-99gj-9798-gpx5.json index 366758b840d..4fbfa2542cb 100644 --- a/advisories/unreviewed/2022/09/GHSA-99gj-9798-gpx5/GHSA-99gj-9798-gpx5.json +++ b/advisories/unreviewed/2022/09/GHSA-99gj-9798-gpx5/GHSA-99gj-9798-gpx5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-9m56-6xhm-cg4f/GHSA-9m56-6xhm-cg4f.json b/advisories/unreviewed/2022/09/GHSA-9m56-6xhm-cg4f/GHSA-9m56-6xhm-cg4f.json index 17bf217809e..bc5d1a1ee1f 100644 --- a/advisories/unreviewed/2022/09/GHSA-9m56-6xhm-cg4f/GHSA-9m56-6xhm-cg4f.json +++ b/advisories/unreviewed/2022/09/GHSA-9m56-6xhm-cg4f/GHSA-9m56-6xhm-cg4f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-f2hc-4phx-xcm3/GHSA-f2hc-4phx-xcm3.json b/advisories/unreviewed/2022/09/GHSA-f2hc-4phx-xcm3/GHSA-f2hc-4phx-xcm3.json index 82ae024ef4e..b440610820a 100644 --- a/advisories/unreviewed/2022/09/GHSA-f2hc-4phx-xcm3/GHSA-f2hc-4phx-xcm3.json +++ b/advisories/unreviewed/2022/09/GHSA-f2hc-4phx-xcm3/GHSA-f2hc-4phx-xcm3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-p6mj-rqhq-7523/GHSA-p6mj-rqhq-7523.json b/advisories/unreviewed/2022/09/GHSA-p6mj-rqhq-7523/GHSA-p6mj-rqhq-7523.json index a8eea6adead..1f4ea02ea91 100644 --- a/advisories/unreviewed/2022/09/GHSA-p6mj-rqhq-7523/GHSA-p6mj-rqhq-7523.json +++ b/advisories/unreviewed/2022/09/GHSA-p6mj-rqhq-7523/GHSA-p6mj-rqhq-7523.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-r46x-xjwr-8v2g/GHSA-r46x-xjwr-8v2g.json b/advisories/unreviewed/2022/09/GHSA-r46x-xjwr-8v2g/GHSA-r46x-xjwr-8v2g.json index e8736c8e758..96733f3e728 100644 --- a/advisories/unreviewed/2022/09/GHSA-r46x-xjwr-8v2g/GHSA-r46x-xjwr-8v2g.json +++ b/advisories/unreviewed/2022/09/GHSA-r46x-xjwr-8v2g/GHSA-r46x-xjwr-8v2g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-rpc9-wm96-3rrj/GHSA-rpc9-wm96-3rrj.json b/advisories/unreviewed/2022/09/GHSA-rpc9-wm96-3rrj/GHSA-rpc9-wm96-3rrj.json index abaadf8acfd..8c1b26aa8d0 100644 --- a/advisories/unreviewed/2022/09/GHSA-rpc9-wm96-3rrj/GHSA-rpc9-wm96-3rrj.json +++ b/advisories/unreviewed/2022/09/GHSA-rpc9-wm96-3rrj/GHSA-rpc9-wm96-3rrj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-vwr7-qp65-68hx/GHSA-vwr7-qp65-68hx.json b/advisories/unreviewed/2022/09/GHSA-vwr7-qp65-68hx/GHSA-vwr7-qp65-68hx.json index 4bc001ef990..efa9c3de47c 100644 --- a/advisories/unreviewed/2022/09/GHSA-vwr7-qp65-68hx/GHSA-vwr7-qp65-68hx.json +++ b/advisories/unreviewed/2022/09/GHSA-vwr7-qp65-68hx/GHSA-vwr7-qp65-68hx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-hhm5-8mw4-m6fp/GHSA-hhm5-8mw4-m6fp.json b/advisories/unreviewed/2022/10/GHSA-hhm5-8mw4-m6fp/GHSA-hhm5-8mw4-m6fp.json index 7403d3fd6bc..b3de5107cd8 100644 --- a/advisories/unreviewed/2022/10/GHSA-hhm5-8mw4-m6fp/GHSA-hhm5-8mw4-m6fp.json +++ b/advisories/unreviewed/2022/10/GHSA-hhm5-8mw4-m6fp/GHSA-hhm5-8mw4-m6fp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-223w-3rxg-p29x/GHSA-223w-3rxg-p29x.json b/advisories/unreviewed/2022/11/GHSA-223w-3rxg-p29x/GHSA-223w-3rxg-p29x.json index 51ee1ad9386..98ad81efd5e 100644 --- a/advisories/unreviewed/2022/11/GHSA-223w-3rxg-p29x/GHSA-223w-3rxg-p29x.json +++ b/advisories/unreviewed/2022/11/GHSA-223w-3rxg-p29x/GHSA-223w-3rxg-p29x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-2c8c-xhwv-r7h7/GHSA-2c8c-xhwv-r7h7.json b/advisories/unreviewed/2022/11/GHSA-2c8c-xhwv-r7h7/GHSA-2c8c-xhwv-r7h7.json index fe97c6bcd16..8ea9da6604b 100644 --- a/advisories/unreviewed/2022/11/GHSA-2c8c-xhwv-r7h7/GHSA-2c8c-xhwv-r7h7.json +++ b/advisories/unreviewed/2022/11/GHSA-2c8c-xhwv-r7h7/GHSA-2c8c-xhwv-r7h7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-2w3j-8r4x-f4mg/GHSA-2w3j-8r4x-f4mg.json b/advisories/unreviewed/2022/11/GHSA-2w3j-8r4x-f4mg/GHSA-2w3j-8r4x-f4mg.json index e2369e99562..bb37a4578ec 100644 --- a/advisories/unreviewed/2022/11/GHSA-2w3j-8r4x-f4mg/GHSA-2w3j-8r4x-f4mg.json +++ b/advisories/unreviewed/2022/11/GHSA-2w3j-8r4x-f4mg/GHSA-2w3j-8r4x-f4mg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-64h5-qfvh-m2hc/GHSA-64h5-qfvh-m2hc.json b/advisories/unreviewed/2022/11/GHSA-64h5-qfvh-m2hc/GHSA-64h5-qfvh-m2hc.json index 13083d2929e..d4f1e23d99c 100644 --- a/advisories/unreviewed/2022/11/GHSA-64h5-qfvh-m2hc/GHSA-64h5-qfvh-m2hc.json +++ b/advisories/unreviewed/2022/11/GHSA-64h5-qfvh-m2hc/GHSA-64h5-qfvh-m2hc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-79mx-4vf7-wqf7/GHSA-79mx-4vf7-wqf7.json b/advisories/unreviewed/2022/11/GHSA-79mx-4vf7-wqf7/GHSA-79mx-4vf7-wqf7.json index c4e134f98dd..a82e195af45 100644 --- a/advisories/unreviewed/2022/11/GHSA-79mx-4vf7-wqf7/GHSA-79mx-4vf7-wqf7.json +++ b/advisories/unreviewed/2022/11/GHSA-79mx-4vf7-wqf7/GHSA-79mx-4vf7-wqf7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-7c72-6v53-xq93/GHSA-7c72-6v53-xq93.json b/advisories/unreviewed/2022/11/GHSA-7c72-6v53-xq93/GHSA-7c72-6v53-xq93.json index e1e96cd6c46..957ec845097 100644 --- a/advisories/unreviewed/2022/11/GHSA-7c72-6v53-xq93/GHSA-7c72-6v53-xq93.json +++ b/advisories/unreviewed/2022/11/GHSA-7c72-6v53-xq93/GHSA-7c72-6v53-xq93.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-99cg-5xjc-jpvj/GHSA-99cg-5xjc-jpvj.json b/advisories/unreviewed/2022/11/GHSA-99cg-5xjc-jpvj/GHSA-99cg-5xjc-jpvj.json index 44376f98c47..24257160a9f 100644 --- a/advisories/unreviewed/2022/11/GHSA-99cg-5xjc-jpvj/GHSA-99cg-5xjc-jpvj.json +++ b/advisories/unreviewed/2022/11/GHSA-99cg-5xjc-jpvj/GHSA-99cg-5xjc-jpvj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-c9g6-7m2j-rfh8/GHSA-c9g6-7m2j-rfh8.json b/advisories/unreviewed/2022/11/GHSA-c9g6-7m2j-rfh8/GHSA-c9g6-7m2j-rfh8.json index 8045f13b836..7c2dedb1a1f 100644 --- a/advisories/unreviewed/2022/11/GHSA-c9g6-7m2j-rfh8/GHSA-c9g6-7m2j-rfh8.json +++ b/advisories/unreviewed/2022/11/GHSA-c9g6-7m2j-rfh8/GHSA-c9g6-7m2j-rfh8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-f4x4-cpmc-ghq4/GHSA-f4x4-cpmc-ghq4.json b/advisories/unreviewed/2022/11/GHSA-f4x4-cpmc-ghq4/GHSA-f4x4-cpmc-ghq4.json index 5451ae3322a..42a8c5c57b4 100644 --- a/advisories/unreviewed/2022/11/GHSA-f4x4-cpmc-ghq4/GHSA-f4x4-cpmc-ghq4.json +++ b/advisories/unreviewed/2022/11/GHSA-f4x4-cpmc-ghq4/GHSA-f4x4-cpmc-ghq4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-f6x7-qg62-r396/GHSA-f6x7-qg62-r396.json b/advisories/unreviewed/2022/11/GHSA-f6x7-qg62-r396/GHSA-f6x7-qg62-r396.json index a8f8eb931fe..c9f7d5ef532 100644 --- a/advisories/unreviewed/2022/11/GHSA-f6x7-qg62-r396/GHSA-f6x7-qg62-r396.json +++ b/advisories/unreviewed/2022/11/GHSA-f6x7-qg62-r396/GHSA-f6x7-qg62-r396.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-f988-q9m6-r9h6/GHSA-f988-q9m6-r9h6.json b/advisories/unreviewed/2022/11/GHSA-f988-q9m6-r9h6/GHSA-f988-q9m6-r9h6.json index ba03549988f..6abd63aa6f1 100644 --- a/advisories/unreviewed/2022/11/GHSA-f988-q9m6-r9h6/GHSA-f988-q9m6-r9h6.json +++ b/advisories/unreviewed/2022/11/GHSA-f988-q9m6-r9h6/GHSA-f988-q9m6-r9h6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-hhjc-j2mm-6qxp/GHSA-hhjc-j2mm-6qxp.json b/advisories/unreviewed/2022/11/GHSA-hhjc-j2mm-6qxp/GHSA-hhjc-j2mm-6qxp.json index 1f9cc44ded7..53b4aa48e49 100644 --- a/advisories/unreviewed/2022/11/GHSA-hhjc-j2mm-6qxp/GHSA-hhjc-j2mm-6qxp.json +++ b/advisories/unreviewed/2022/11/GHSA-hhjc-j2mm-6qxp/GHSA-hhjc-j2mm-6qxp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-jfj7-7vp9-r7cf/GHSA-jfj7-7vp9-r7cf.json b/advisories/unreviewed/2022/11/GHSA-jfj7-7vp9-r7cf/GHSA-jfj7-7vp9-r7cf.json index b2e227c879d..297d30deb5f 100644 --- a/advisories/unreviewed/2022/11/GHSA-jfj7-7vp9-r7cf/GHSA-jfj7-7vp9-r7cf.json +++ b/advisories/unreviewed/2022/11/GHSA-jfj7-7vp9-r7cf/GHSA-jfj7-7vp9-r7cf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-jgwp-h4gx-xm93/GHSA-jgwp-h4gx-xm93.json b/advisories/unreviewed/2022/11/GHSA-jgwp-h4gx-xm93/GHSA-jgwp-h4gx-xm93.json index 1d0aa668d92..9fb953c46c6 100644 --- a/advisories/unreviewed/2022/11/GHSA-jgwp-h4gx-xm93/GHSA-jgwp-h4gx-xm93.json +++ b/advisories/unreviewed/2022/11/GHSA-jgwp-h4gx-xm93/GHSA-jgwp-h4gx-xm93.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-mfvg-p5qp-p4gm/GHSA-mfvg-p5qp-p4gm.json b/advisories/unreviewed/2022/11/GHSA-mfvg-p5qp-p4gm/GHSA-mfvg-p5qp-p4gm.json index 828ae226c99..7690d2c6327 100644 --- a/advisories/unreviewed/2022/11/GHSA-mfvg-p5qp-p4gm/GHSA-mfvg-p5qp-p4gm.json +++ b/advisories/unreviewed/2022/11/GHSA-mfvg-p5qp-p4gm/GHSA-mfvg-p5qp-p4gm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-mgr9-pm96-3xmm/GHSA-mgr9-pm96-3xmm.json b/advisories/unreviewed/2022/11/GHSA-mgr9-pm96-3xmm/GHSA-mgr9-pm96-3xmm.json index f1206fde7dc..57cb5c07c76 100644 --- a/advisories/unreviewed/2022/11/GHSA-mgr9-pm96-3xmm/GHSA-mgr9-pm96-3xmm.json +++ b/advisories/unreviewed/2022/11/GHSA-mgr9-pm96-3xmm/GHSA-mgr9-pm96-3xmm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-p22x-6r5h-g873/GHSA-p22x-6r5h-g873.json b/advisories/unreviewed/2022/11/GHSA-p22x-6r5h-g873/GHSA-p22x-6r5h-g873.json index dbe6bf9e095..ee8c8394077 100644 --- a/advisories/unreviewed/2022/11/GHSA-p22x-6r5h-g873/GHSA-p22x-6r5h-g873.json +++ b/advisories/unreviewed/2022/11/GHSA-p22x-6r5h-g873/GHSA-p22x-6r5h-g873.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-pm8g-g665-8r7q/GHSA-pm8g-g665-8r7q.json b/advisories/unreviewed/2022/11/GHSA-pm8g-g665-8r7q/GHSA-pm8g-g665-8r7q.json index 25da898acb0..2c3fdf29503 100644 --- a/advisories/unreviewed/2022/11/GHSA-pm8g-g665-8r7q/GHSA-pm8g-g665-8r7q.json +++ b/advisories/unreviewed/2022/11/GHSA-pm8g-g665-8r7q/GHSA-pm8g-g665-8r7q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-pmwg-pqhj-8m9m/GHSA-pmwg-pqhj-8m9m.json b/advisories/unreviewed/2022/11/GHSA-pmwg-pqhj-8m9m/GHSA-pmwg-pqhj-8m9m.json index f32736162ac..0bd09cee077 100644 --- a/advisories/unreviewed/2022/11/GHSA-pmwg-pqhj-8m9m/GHSA-pmwg-pqhj-8m9m.json +++ b/advisories/unreviewed/2022/11/GHSA-pmwg-pqhj-8m9m/GHSA-pmwg-pqhj-8m9m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-q7gf-qq2r-mhhf/GHSA-q7gf-qq2r-mhhf.json b/advisories/unreviewed/2022/11/GHSA-q7gf-qq2r-mhhf/GHSA-q7gf-qq2r-mhhf.json index ac042d49569..0d176271105 100644 --- a/advisories/unreviewed/2022/11/GHSA-q7gf-qq2r-mhhf/GHSA-q7gf-qq2r-mhhf.json +++ b/advisories/unreviewed/2022/11/GHSA-q7gf-qq2r-mhhf/GHSA-q7gf-qq2r-mhhf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-2777-r28v-7m99/GHSA-2777-r28v-7m99.json b/advisories/unreviewed/2022/12/GHSA-2777-r28v-7m99/GHSA-2777-r28v-7m99.json index 27bc466651b..483631f747a 100644 --- a/advisories/unreviewed/2022/12/GHSA-2777-r28v-7m99/GHSA-2777-r28v-7m99.json +++ b/advisories/unreviewed/2022/12/GHSA-2777-r28v-7m99/GHSA-2777-r28v-7m99.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-79hv-rqqf-c692/GHSA-79hv-rqqf-c692.json b/advisories/unreviewed/2022/12/GHSA-79hv-rqqf-c692/GHSA-79hv-rqqf-c692.json index 636a47058cb..22ce144f13f 100644 --- a/advisories/unreviewed/2022/12/GHSA-79hv-rqqf-c692/GHSA-79hv-rqqf-c692.json +++ b/advisories/unreviewed/2022/12/GHSA-79hv-rqqf-c692/GHSA-79hv-rqqf-c692.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-cj4v-mx99-hg57/GHSA-cj4v-mx99-hg57.json b/advisories/unreviewed/2022/12/GHSA-cj4v-mx99-hg57/GHSA-cj4v-mx99-hg57.json index 7612caa9ef1..86f612b7d55 100644 --- a/advisories/unreviewed/2022/12/GHSA-cj4v-mx99-hg57/GHSA-cj4v-mx99-hg57.json +++ b/advisories/unreviewed/2022/12/GHSA-cj4v-mx99-hg57/GHSA-cj4v-mx99-hg57.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-fg7f-frxh-h6gr/GHSA-fg7f-frxh-h6gr.json b/advisories/unreviewed/2022/12/GHSA-fg7f-frxh-h6gr/GHSA-fg7f-frxh-h6gr.json index 7e614636b80..f0d387c7663 100644 --- a/advisories/unreviewed/2022/12/GHSA-fg7f-frxh-h6gr/GHSA-fg7f-frxh-h6gr.json +++ b/advisories/unreviewed/2022/12/GHSA-fg7f-frxh-h6gr/GHSA-fg7f-frxh-h6gr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-r5q7-99jj-9rvq/GHSA-r5q7-99jj-9rvq.json b/advisories/unreviewed/2022/12/GHSA-r5q7-99jj-9rvq/GHSA-r5q7-99jj-9rvq.json index 22df2bbe7e9..45c5db47b39 100644 --- a/advisories/unreviewed/2022/12/GHSA-r5q7-99jj-9rvq/GHSA-r5q7-99jj-9rvq.json +++ b/advisories/unreviewed/2022/12/GHSA-r5q7-99jj-9rvq/GHSA-r5q7-99jj-9rvq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-32ph-rfjm-xcxh/GHSA-32ph-rfjm-xcxh.json b/advisories/unreviewed/2023/01/GHSA-32ph-rfjm-xcxh/GHSA-32ph-rfjm-xcxh.json index af88f8766ff..53548e72c4c 100644 --- a/advisories/unreviewed/2023/01/GHSA-32ph-rfjm-xcxh/GHSA-32ph-rfjm-xcxh.json +++ b/advisories/unreviewed/2023/01/GHSA-32ph-rfjm-xcxh/GHSA-32ph-rfjm-xcxh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-52fh-7w4m-p9cx/GHSA-52fh-7w4m-p9cx.json b/advisories/unreviewed/2023/01/GHSA-52fh-7w4m-p9cx/GHSA-52fh-7w4m-p9cx.json index a5c9d71a590..92b921db698 100644 --- a/advisories/unreviewed/2023/01/GHSA-52fh-7w4m-p9cx/GHSA-52fh-7w4m-p9cx.json +++ b/advisories/unreviewed/2023/01/GHSA-52fh-7w4m-p9cx/GHSA-52fh-7w4m-p9cx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-7ghc-xw3w-fw2v/GHSA-7ghc-xw3w-fw2v.json b/advisories/unreviewed/2023/01/GHSA-7ghc-xw3w-fw2v/GHSA-7ghc-xw3w-fw2v.json index afd6650fcc9..2959f455593 100644 --- a/advisories/unreviewed/2023/01/GHSA-7ghc-xw3w-fw2v/GHSA-7ghc-xw3w-fw2v.json +++ b/advisories/unreviewed/2023/01/GHSA-7ghc-xw3w-fw2v/GHSA-7ghc-xw3w-fw2v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-86rp-q4q2-g9m2/GHSA-86rp-q4q2-g9m2.json b/advisories/unreviewed/2023/01/GHSA-86rp-q4q2-g9m2/GHSA-86rp-q4q2-g9m2.json index e494d22ae0d..90029e88427 100644 --- a/advisories/unreviewed/2023/01/GHSA-86rp-q4q2-g9m2/GHSA-86rp-q4q2-g9m2.json +++ b/advisories/unreviewed/2023/01/GHSA-86rp-q4q2-g9m2/GHSA-86rp-q4q2-g9m2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-8f85-82xx-w72x/GHSA-8f85-82xx-w72x.json b/advisories/unreviewed/2023/01/GHSA-8f85-82xx-w72x/GHSA-8f85-82xx-w72x.json index d7335bd62a4..3ac1930b88b 100644 --- a/advisories/unreviewed/2023/01/GHSA-8f85-82xx-w72x/GHSA-8f85-82xx-w72x.json +++ b/advisories/unreviewed/2023/01/GHSA-8f85-82xx-w72x/GHSA-8f85-82xx-w72x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-8gg5-pvcf-9jwc/GHSA-8gg5-pvcf-9jwc.json b/advisories/unreviewed/2023/01/GHSA-8gg5-pvcf-9jwc/GHSA-8gg5-pvcf-9jwc.json index 8f9a3d9f7ce..320183364be 100644 --- a/advisories/unreviewed/2023/01/GHSA-8gg5-pvcf-9jwc/GHSA-8gg5-pvcf-9jwc.json +++ b/advisories/unreviewed/2023/01/GHSA-8gg5-pvcf-9jwc/GHSA-8gg5-pvcf-9jwc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-jw92-fcgv-875g/GHSA-jw92-fcgv-875g.json b/advisories/unreviewed/2023/01/GHSA-jw92-fcgv-875g/GHSA-jw92-fcgv-875g.json index 464edc98b7f..c52c60b718f 100644 --- a/advisories/unreviewed/2023/01/GHSA-jw92-fcgv-875g/GHSA-jw92-fcgv-875g.json +++ b/advisories/unreviewed/2023/01/GHSA-jw92-fcgv-875g/GHSA-jw92-fcgv-875g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-mm7r-w5q4-7cc2/GHSA-mm7r-w5q4-7cc2.json b/advisories/unreviewed/2023/01/GHSA-mm7r-w5q4-7cc2/GHSA-mm7r-w5q4-7cc2.json index 9262d2e8aa9..9fcfb0c8db1 100644 --- a/advisories/unreviewed/2023/01/GHSA-mm7r-w5q4-7cc2/GHSA-mm7r-w5q4-7cc2.json +++ b/advisories/unreviewed/2023/01/GHSA-mm7r-w5q4-7cc2/GHSA-mm7r-w5q4-7cc2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-mp34-w63c-4vpv/GHSA-mp34-w63c-4vpv.json b/advisories/unreviewed/2023/01/GHSA-mp34-w63c-4vpv/GHSA-mp34-w63c-4vpv.json index 3e7c71743a0..a48b835d528 100644 --- a/advisories/unreviewed/2023/01/GHSA-mp34-w63c-4vpv/GHSA-mp34-w63c-4vpv.json +++ b/advisories/unreviewed/2023/01/GHSA-mp34-w63c-4vpv/GHSA-mp34-w63c-4vpv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-pghc-cpgh-cpp9/GHSA-pghc-cpgh-cpp9.json b/advisories/unreviewed/2023/01/GHSA-pghc-cpgh-cpp9/GHSA-pghc-cpgh-cpp9.json index 191237691b3..4a2219b458f 100644 --- a/advisories/unreviewed/2023/01/GHSA-pghc-cpgh-cpp9/GHSA-pghc-cpgh-cpp9.json +++ b/advisories/unreviewed/2023/01/GHSA-pghc-cpgh-cpp9/GHSA-pghc-cpgh-cpp9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-v3wm-hvwx-j6vw/GHSA-v3wm-hvwx-j6vw.json b/advisories/unreviewed/2023/01/GHSA-v3wm-hvwx-j6vw/GHSA-v3wm-hvwx-j6vw.json index f3489cd8569..9235f59df4a 100644 --- a/advisories/unreviewed/2023/01/GHSA-v3wm-hvwx-j6vw/GHSA-v3wm-hvwx-j6vw.json +++ b/advisories/unreviewed/2023/01/GHSA-v3wm-hvwx-j6vw/GHSA-v3wm-hvwx-j6vw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-v7m6-263w-8j68/GHSA-v7m6-263w-8j68.json b/advisories/unreviewed/2023/01/GHSA-v7m6-263w-8j68/GHSA-v7m6-263w-8j68.json index 88abae6324b..e17c4097210 100644 --- a/advisories/unreviewed/2023/01/GHSA-v7m6-263w-8j68/GHSA-v7m6-263w-8j68.json +++ b/advisories/unreviewed/2023/01/GHSA-v7m6-263w-8j68/GHSA-v7m6-263w-8j68.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-q557-c2gh-wm95/GHSA-q557-c2gh-wm95.json b/advisories/unreviewed/2023/02/GHSA-q557-c2gh-wm95/GHSA-q557-c2gh-wm95.json index 328f90fd4a0..9c0db5f8022 100644 --- a/advisories/unreviewed/2023/02/GHSA-q557-c2gh-wm95/GHSA-q557-c2gh-wm95.json +++ b/advisories/unreviewed/2023/02/GHSA-q557-c2gh-wm95/GHSA-q557-c2gh-wm95.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-v398-hxmw-7r4v/GHSA-v398-hxmw-7r4v.json b/advisories/unreviewed/2023/02/GHSA-v398-hxmw-7r4v/GHSA-v398-hxmw-7r4v.json index f2fa8db541b..2ce52455789 100644 --- a/advisories/unreviewed/2023/02/GHSA-v398-hxmw-7r4v/GHSA-v398-hxmw-7r4v.json +++ b/advisories/unreviewed/2023/02/GHSA-v398-hxmw-7r4v/GHSA-v398-hxmw-7r4v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-whvh-7626-25qp/GHSA-whvh-7626-25qp.json b/advisories/unreviewed/2023/03/GHSA-whvh-7626-25qp/GHSA-whvh-7626-25qp.json index 77f7b278c85..4b9181a0851 100644 --- a/advisories/unreviewed/2023/03/GHSA-whvh-7626-25qp/GHSA-whvh-7626-25qp.json +++ b/advisories/unreviewed/2023/03/GHSA-whvh-7626-25qp/GHSA-whvh-7626-25qp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-wmpf-66f7-27p8/GHSA-wmpf-66f7-27p8.json b/advisories/unreviewed/2023/03/GHSA-wmpf-66f7-27p8/GHSA-wmpf-66f7-27p8.json index 7f5cc530bd9..2658dda8405 100644 --- a/advisories/unreviewed/2023/03/GHSA-wmpf-66f7-27p8/GHSA-wmpf-66f7-27p8.json +++ b/advisories/unreviewed/2023/03/GHSA-wmpf-66f7-27p8/GHSA-wmpf-66f7-27p8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-9hrf-3267-3v6p/GHSA-9hrf-3267-3v6p.json b/advisories/unreviewed/2023/06/GHSA-9hrf-3267-3v6p/GHSA-9hrf-3267-3v6p.json index b50e2e30f34..83eeb96b854 100644 --- a/advisories/unreviewed/2023/06/GHSA-9hrf-3267-3v6p/GHSA-9hrf-3267-3v6p.json +++ b/advisories/unreviewed/2023/06/GHSA-9hrf-3267-3v6p/GHSA-9hrf-3267-3v6p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-7664-m5hw-r7q8/GHSA-7664-m5hw-r7q8.json b/advisories/unreviewed/2023/11/GHSA-7664-m5hw-r7q8/GHSA-7664-m5hw-r7q8.json index 042fa9c01d6..f2129f6a094 100644 --- a/advisories/unreviewed/2023/11/GHSA-7664-m5hw-r7q8/GHSA-7664-m5hw-r7q8.json +++ b/advisories/unreviewed/2023/11/GHSA-7664-m5hw-r7q8/GHSA-7664-m5hw-r7q8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-xxjf-hhmr-jhmq/GHSA-xxjf-hhmr-jhmq.json b/advisories/unreviewed/2023/12/GHSA-xxjf-hhmr-jhmq/GHSA-xxjf-hhmr-jhmq.json index 994da57bdc3..50e66cba4bf 100644 --- a/advisories/unreviewed/2023/12/GHSA-xxjf-hhmr-jhmq/GHSA-xxjf-hhmr-jhmq.json +++ b/advisories/unreviewed/2023/12/GHSA-xxjf-hhmr-jhmq/GHSA-xxjf-hhmr-jhmq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-5p7x-xg54-cjrq/GHSA-5p7x-xg54-cjrq.json b/advisories/unreviewed/2024/02/GHSA-5p7x-xg54-cjrq/GHSA-5p7x-xg54-cjrq.json index d743e8710f5..71de01f1a65 100644 --- a/advisories/unreviewed/2024/02/GHSA-5p7x-xg54-cjrq/GHSA-5p7x-xg54-cjrq.json +++ b/advisories/unreviewed/2024/02/GHSA-5p7x-xg54-cjrq/GHSA-5p7x-xg54-cjrq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-6733-f273-8q48/GHSA-6733-f273-8q48.json b/advisories/unreviewed/2024/02/GHSA-6733-f273-8q48/GHSA-6733-f273-8q48.json index 60c1c4095aa..74a45ba32bd 100644 --- a/advisories/unreviewed/2024/02/GHSA-6733-f273-8q48/GHSA-6733-f273-8q48.json +++ b/advisories/unreviewed/2024/02/GHSA-6733-f273-8q48/GHSA-6733-f273-8q48.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-6wxp-wm3f-vmr4/GHSA-6wxp-wm3f-vmr4.json b/advisories/unreviewed/2024/02/GHSA-6wxp-wm3f-vmr4/GHSA-6wxp-wm3f-vmr4.json index cf4b449fefb..0cb54bed161 100644 --- a/advisories/unreviewed/2024/02/GHSA-6wxp-wm3f-vmr4/GHSA-6wxp-wm3f-vmr4.json +++ b/advisories/unreviewed/2024/02/GHSA-6wxp-wm3f-vmr4/GHSA-6wxp-wm3f-vmr4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-m658-5f72-86ff/GHSA-m658-5f72-86ff.json b/advisories/unreviewed/2024/02/GHSA-m658-5f72-86ff/GHSA-m658-5f72-86ff.json index 0db7911fb71..f0325da1941 100644 --- a/advisories/unreviewed/2024/02/GHSA-m658-5f72-86ff/GHSA-m658-5f72-86ff.json +++ b/advisories/unreviewed/2024/02/GHSA-m658-5f72-86ff/GHSA-m658-5f72-86ff.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-p53g-6cxv-378j/GHSA-p53g-6cxv-378j.json b/advisories/unreviewed/2024/02/GHSA-p53g-6cxv-378j/GHSA-p53g-6cxv-378j.json index c1fa68cda0d..cea4788d3a6 100644 --- a/advisories/unreviewed/2024/02/GHSA-p53g-6cxv-378j/GHSA-p53g-6cxv-378j.json +++ b/advisories/unreviewed/2024/02/GHSA-p53g-6cxv-378j/GHSA-p53g-6cxv-378j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-q25f-2gjj-7ppp/GHSA-q25f-2gjj-7ppp.json b/advisories/unreviewed/2024/02/GHSA-q25f-2gjj-7ppp/GHSA-q25f-2gjj-7ppp.json index 6386df3bbd6..3a3fd4b696e 100644 --- a/advisories/unreviewed/2024/02/GHSA-q25f-2gjj-7ppp/GHSA-q25f-2gjj-7ppp.json +++ b/advisories/unreviewed/2024/02/GHSA-q25f-2gjj-7ppp/GHSA-q25f-2gjj-7ppp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-v3xc-v2g4-h75g/GHSA-v3xc-v2g4-h75g.json b/advisories/unreviewed/2024/02/GHSA-v3xc-v2g4-h75g/GHSA-v3xc-v2g4-h75g.json index 6e2e99d1ba0..a803d0366e4 100644 --- a/advisories/unreviewed/2024/02/GHSA-v3xc-v2g4-h75g/GHSA-v3xc-v2g4-h75g.json +++ b/advisories/unreviewed/2024/02/GHSA-v3xc-v2g4-h75g/GHSA-v3xc-v2g4-h75g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-vr7g-cxmj-9864/GHSA-vr7g-cxmj-9864.json b/advisories/unreviewed/2024/02/GHSA-vr7g-cxmj-9864/GHSA-vr7g-cxmj-9864.json index ff9f60e051c..c4f3dfa94b4 100644 --- a/advisories/unreviewed/2024/02/GHSA-vr7g-cxmj-9864/GHSA-vr7g-cxmj-9864.json +++ b/advisories/unreviewed/2024/02/GHSA-vr7g-cxmj-9864/GHSA-vr7g-cxmj-9864.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-37x3-hqf8-5w7p/GHSA-37x3-hqf8-5w7p.json b/advisories/unreviewed/2024/03/GHSA-37x3-hqf8-5w7p/GHSA-37x3-hqf8-5w7p.json index b94b1e1d9ae..43352fe6e6d 100644 --- a/advisories/unreviewed/2024/03/GHSA-37x3-hqf8-5w7p/GHSA-37x3-hqf8-5w7p.json +++ b/advisories/unreviewed/2024/03/GHSA-37x3-hqf8-5w7p/GHSA-37x3-hqf8-5w7p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json b/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json index b9bbc18bfaf..204df63f88e 100644 --- a/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json +++ b/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-p8fm-626m-mf8v/GHSA-p8fm-626m-mf8v.json b/advisories/unreviewed/2024/03/GHSA-p8fm-626m-mf8v/GHSA-p8fm-626m-mf8v.json index 762492d61ff..5735a61ad3a 100644 --- a/advisories/unreviewed/2024/03/GHSA-p8fm-626m-mf8v/GHSA-p8fm-626m-mf8v.json +++ b/advisories/unreviewed/2024/03/GHSA-p8fm-626m-mf8v/GHSA-p8fm-626m-mf8v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-r5xr-mfqp-qmrq/GHSA-r5xr-mfqp-qmrq.json b/advisories/unreviewed/2024/03/GHSA-r5xr-mfqp-qmrq/GHSA-r5xr-mfqp-qmrq.json index 485b5dd37d3..b972034eaf8 100644 --- a/advisories/unreviewed/2024/03/GHSA-r5xr-mfqp-qmrq/GHSA-r5xr-mfqp-qmrq.json +++ b/advisories/unreviewed/2024/03/GHSA-r5xr-mfqp-qmrq/GHSA-r5xr-mfqp-qmrq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-x3cr-crpx-mg4r/GHSA-x3cr-crpx-mg4r.json b/advisories/unreviewed/2024/03/GHSA-x3cr-crpx-mg4r/GHSA-x3cr-crpx-mg4r.json index 587cf5f91ca..876e9670dd5 100644 --- a/advisories/unreviewed/2024/03/GHSA-x3cr-crpx-mg4r/GHSA-x3cr-crpx-mg4r.json +++ b/advisories/unreviewed/2024/03/GHSA-x3cr-crpx-mg4r/GHSA-x3cr-crpx-mg4r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-3vqr-5r5v-rhm8/GHSA-3vqr-5r5v-rhm8.json b/advisories/unreviewed/2024/04/GHSA-3vqr-5r5v-rhm8/GHSA-3vqr-5r5v-rhm8.json index 80bd5e3c291..52e359118ba 100644 --- a/advisories/unreviewed/2024/04/GHSA-3vqr-5r5v-rhm8/GHSA-3vqr-5r5v-rhm8.json +++ b/advisories/unreviewed/2024/04/GHSA-3vqr-5r5v-rhm8/GHSA-3vqr-5r5v-rhm8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-46vf-c8gj-2pgq/GHSA-46vf-c8gj-2pgq.json b/advisories/unreviewed/2024/04/GHSA-46vf-c8gj-2pgq/GHSA-46vf-c8gj-2pgq.json index b6cd742af31..df64ba34842 100644 --- a/advisories/unreviewed/2024/04/GHSA-46vf-c8gj-2pgq/GHSA-46vf-c8gj-2pgq.json +++ b/advisories/unreviewed/2024/04/GHSA-46vf-c8gj-2pgq/GHSA-46vf-c8gj-2pgq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-4q93-6p46-6x3h/GHSA-4q93-6p46-6x3h.json b/advisories/unreviewed/2024/04/GHSA-4q93-6p46-6x3h/GHSA-4q93-6p46-6x3h.json index d3c6ec916f4..3a9e2842385 100644 --- a/advisories/unreviewed/2024/04/GHSA-4q93-6p46-6x3h/GHSA-4q93-6p46-6x3h.json +++ b/advisories/unreviewed/2024/04/GHSA-4q93-6p46-6x3h/GHSA-4q93-6p46-6x3h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-5h96-vc53-5mqg/GHSA-5h96-vc53-5mqg.json b/advisories/unreviewed/2024/04/GHSA-5h96-vc53-5mqg/GHSA-5h96-vc53-5mqg.json index 0be6f7b21d4..b133e3d6ff2 100644 --- a/advisories/unreviewed/2024/04/GHSA-5h96-vc53-5mqg/GHSA-5h96-vc53-5mqg.json +++ b/advisories/unreviewed/2024/04/GHSA-5h96-vc53-5mqg/GHSA-5h96-vc53-5mqg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-6w55-m9x6-7p2p/GHSA-6w55-m9x6-7p2p.json b/advisories/unreviewed/2024/04/GHSA-6w55-m9x6-7p2p/GHSA-6w55-m9x6-7p2p.json index 66afa87b069..777a54e3f51 100644 --- a/advisories/unreviewed/2024/04/GHSA-6w55-m9x6-7p2p/GHSA-6w55-m9x6-7p2p.json +++ b/advisories/unreviewed/2024/04/GHSA-6w55-m9x6-7p2p/GHSA-6w55-m9x6-7p2p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-8673-r45m-47g8/GHSA-8673-r45m-47g8.json b/advisories/unreviewed/2024/04/GHSA-8673-r45m-47g8/GHSA-8673-r45m-47g8.json index ba61e6556f6..31f757ef683 100644 --- a/advisories/unreviewed/2024/04/GHSA-8673-r45m-47g8/GHSA-8673-r45m-47g8.json +++ b/advisories/unreviewed/2024/04/GHSA-8673-r45m-47g8/GHSA-8673-r45m-47g8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-8j2w-2cpm-xpmr/GHSA-8j2w-2cpm-xpmr.json b/advisories/unreviewed/2024/04/GHSA-8j2w-2cpm-xpmr/GHSA-8j2w-2cpm-xpmr.json index b664134369e..2451544b70b 100644 --- a/advisories/unreviewed/2024/04/GHSA-8j2w-2cpm-xpmr/GHSA-8j2w-2cpm-xpmr.json +++ b/advisories/unreviewed/2024/04/GHSA-8j2w-2cpm-xpmr/GHSA-8j2w-2cpm-xpmr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8ppm-mwhc-2h38/GHSA-8ppm-mwhc-2h38.json b/advisories/unreviewed/2024/04/GHSA-8ppm-mwhc-2h38/GHSA-8ppm-mwhc-2h38.json index 5196871abd5..437ddb8de35 100644 --- a/advisories/unreviewed/2024/04/GHSA-8ppm-mwhc-2h38/GHSA-8ppm-mwhc-2h38.json +++ b/advisories/unreviewed/2024/04/GHSA-8ppm-mwhc-2h38/GHSA-8ppm-mwhc-2h38.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-94v3-rgqr-v5g3/GHSA-94v3-rgqr-v5g3.json b/advisories/unreviewed/2024/04/GHSA-94v3-rgqr-v5g3/GHSA-94v3-rgqr-v5g3.json index 8736b96a9a0..234249db980 100644 --- a/advisories/unreviewed/2024/04/GHSA-94v3-rgqr-v5g3/GHSA-94v3-rgqr-v5g3.json +++ b/advisories/unreviewed/2024/04/GHSA-94v3-rgqr-v5g3/GHSA-94v3-rgqr-v5g3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-gcfv-8g7p-w74j/GHSA-gcfv-8g7p-w74j.json b/advisories/unreviewed/2024/04/GHSA-gcfv-8g7p-w74j/GHSA-gcfv-8g7p-w74j.json index 39eab4003cc..7f1f965947b 100644 --- a/advisories/unreviewed/2024/04/GHSA-gcfv-8g7p-w74j/GHSA-gcfv-8g7p-w74j.json +++ b/advisories/unreviewed/2024/04/GHSA-gcfv-8g7p-w74j/GHSA-gcfv-8g7p-w74j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-gchv-5rxx-7j87/GHSA-gchv-5rxx-7j87.json b/advisories/unreviewed/2024/04/GHSA-gchv-5rxx-7j87/GHSA-gchv-5rxx-7j87.json index 9eaa1246416..cbf68079e4b 100644 --- a/advisories/unreviewed/2024/04/GHSA-gchv-5rxx-7j87/GHSA-gchv-5rxx-7j87.json +++ b/advisories/unreviewed/2024/04/GHSA-gchv-5rxx-7j87/GHSA-gchv-5rxx-7j87.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-hxvx-w43m-m8wv/GHSA-hxvx-w43m-m8wv.json b/advisories/unreviewed/2024/04/GHSA-hxvx-w43m-m8wv/GHSA-hxvx-w43m-m8wv.json index 1658705edfa..a396006cfb8 100644 --- a/advisories/unreviewed/2024/04/GHSA-hxvx-w43m-m8wv/GHSA-hxvx-w43m-m8wv.json +++ b/advisories/unreviewed/2024/04/GHSA-hxvx-w43m-m8wv/GHSA-hxvx-w43m-m8wv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-jjv2-293m-3wrf/GHSA-jjv2-293m-3wrf.json b/advisories/unreviewed/2024/04/GHSA-jjv2-293m-3wrf/GHSA-jjv2-293m-3wrf.json index a6455e97dc4..fad8ef9e174 100644 --- a/advisories/unreviewed/2024/04/GHSA-jjv2-293m-3wrf/GHSA-jjv2-293m-3wrf.json +++ b/advisories/unreviewed/2024/04/GHSA-jjv2-293m-3wrf/GHSA-jjv2-293m-3wrf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jw3q-hfmw-wpqw/GHSA-jw3q-hfmw-wpqw.json b/advisories/unreviewed/2024/04/GHSA-jw3q-hfmw-wpqw/GHSA-jw3q-hfmw-wpqw.json index 635dcd9a9ba..c83d4c59ee1 100644 --- a/advisories/unreviewed/2024/04/GHSA-jw3q-hfmw-wpqw/GHSA-jw3q-hfmw-wpqw.json +++ b/advisories/unreviewed/2024/04/GHSA-jw3q-hfmw-wpqw/GHSA-jw3q-hfmw-wpqw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-p29c-5vv5-vh3p/GHSA-p29c-5vv5-vh3p.json b/advisories/unreviewed/2024/04/GHSA-p29c-5vv5-vh3p/GHSA-p29c-5vv5-vh3p.json index 9cffdfd6532..a48e0270110 100644 --- a/advisories/unreviewed/2024/04/GHSA-p29c-5vv5-vh3p/GHSA-p29c-5vv5-vh3p.json +++ b/advisories/unreviewed/2024/04/GHSA-p29c-5vv5-vh3p/GHSA-p29c-5vv5-vh3p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-r9g8-4h9q-3jfp/GHSA-r9g8-4h9q-3jfp.json b/advisories/unreviewed/2024/04/GHSA-r9g8-4h9q-3jfp/GHSA-r9g8-4h9q-3jfp.json index aa75069de7b..b722055d235 100644 --- a/advisories/unreviewed/2024/04/GHSA-r9g8-4h9q-3jfp/GHSA-r9g8-4h9q-3jfp.json +++ b/advisories/unreviewed/2024/04/GHSA-r9g8-4h9q-3jfp/GHSA-r9g8-4h9q-3jfp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-rq82-xjv7-57jq/GHSA-rq82-xjv7-57jq.json b/advisories/unreviewed/2024/04/GHSA-rq82-xjv7-57jq/GHSA-rq82-xjv7-57jq.json index 7124aefce0c..8cc3b520910 100644 --- a/advisories/unreviewed/2024/04/GHSA-rq82-xjv7-57jq/GHSA-rq82-xjv7-57jq.json +++ b/advisories/unreviewed/2024/04/GHSA-rq82-xjv7-57jq/GHSA-rq82-xjv7-57jq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-w249-f84q-3v47/GHSA-w249-f84q-3v47.json b/advisories/unreviewed/2024/04/GHSA-w249-f84q-3v47/GHSA-w249-f84q-3v47.json index bb40737247a..91cdc49720d 100644 --- a/advisories/unreviewed/2024/04/GHSA-w249-f84q-3v47/GHSA-w249-f84q-3v47.json +++ b/advisories/unreviewed/2024/04/GHSA-w249-f84q-3v47/GHSA-w249-f84q-3v47.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-w3jf-rqmq-p89q/GHSA-w3jf-rqmq-p89q.json b/advisories/unreviewed/2024/04/GHSA-w3jf-rqmq-p89q/GHSA-w3jf-rqmq-p89q.json index c749ce80728..320805455f2 100644 --- a/advisories/unreviewed/2024/04/GHSA-w3jf-rqmq-p89q/GHSA-w3jf-rqmq-p89q.json +++ b/advisories/unreviewed/2024/04/GHSA-w3jf-rqmq-p89q/GHSA-w3jf-rqmq-p89q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-x8mf-46wq-x274/GHSA-x8mf-46wq-x274.json b/advisories/unreviewed/2024/04/GHSA-x8mf-46wq-x274/GHSA-x8mf-46wq-x274.json index 91277d009c1..fd476958052 100644 --- a/advisories/unreviewed/2024/04/GHSA-x8mf-46wq-x274/GHSA-x8mf-46wq-x274.json +++ b/advisories/unreviewed/2024/04/GHSA-x8mf-46wq-x274/GHSA-x8mf-46wq-x274.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-xcp9-jx79-m233/GHSA-xcp9-jx79-m233.json b/advisories/unreviewed/2024/04/GHSA-xcp9-jx79-m233/GHSA-xcp9-jx79-m233.json index 0963bce5e05..3b2d8fae79e 100644 --- a/advisories/unreviewed/2024/04/GHSA-xcp9-jx79-m233/GHSA-xcp9-jx79-m233.json +++ b/advisories/unreviewed/2024/04/GHSA-xcp9-jx79-m233/GHSA-xcp9-jx79-m233.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-jj5x-5vg3-9m7f/GHSA-jj5x-5vg3-9m7f.json b/advisories/unreviewed/2024/05/GHSA-jj5x-5vg3-9m7f/GHSA-jj5x-5vg3-9m7f.json index 5790aa3266f..a9df303030f 100644 --- a/advisories/unreviewed/2024/05/GHSA-jj5x-5vg3-9m7f/GHSA-jj5x-5vg3-9m7f.json +++ b/advisories/unreviewed/2024/05/GHSA-jj5x-5vg3-9m7f/GHSA-jj5x-5vg3-9m7f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-pf9m-g9g6-cphc/GHSA-pf9m-g9g6-cphc.json b/advisories/unreviewed/2024/05/GHSA-pf9m-g9g6-cphc/GHSA-pf9m-g9g6-cphc.json index 376dad7b3fd..b81e8980e71 100644 --- a/advisories/unreviewed/2024/05/GHSA-pf9m-g9g6-cphc/GHSA-pf9m-g9g6-cphc.json +++ b/advisories/unreviewed/2024/05/GHSA-pf9m-g9g6-cphc/GHSA-pf9m-g9g6-cphc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-2xhx-vgfw-g59c/GHSA-2xhx-vgfw-g59c.json b/advisories/unreviewed/2024/06/GHSA-2xhx-vgfw-g59c/GHSA-2xhx-vgfw-g59c.json index 10e59e2b96b..3b4abd70360 100644 --- a/advisories/unreviewed/2024/06/GHSA-2xhx-vgfw-g59c/GHSA-2xhx-vgfw-g59c.json +++ b/advisories/unreviewed/2024/06/GHSA-2xhx-vgfw-g59c/GHSA-2xhx-vgfw-g59c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-3fxj-qpxv-j6qj/GHSA-3fxj-qpxv-j6qj.json b/advisories/unreviewed/2024/06/GHSA-3fxj-qpxv-j6qj/GHSA-3fxj-qpxv-j6qj.json index a515ac532e8..3e60a3e7ef4 100644 --- a/advisories/unreviewed/2024/06/GHSA-3fxj-qpxv-j6qj/GHSA-3fxj-qpxv-j6qj.json +++ b/advisories/unreviewed/2024/06/GHSA-3fxj-qpxv-j6qj/GHSA-3fxj-qpxv-j6qj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-59c6-mp6w-73hm/GHSA-59c6-mp6w-73hm.json b/advisories/unreviewed/2024/06/GHSA-59c6-mp6w-73hm/GHSA-59c6-mp6w-73hm.json index 18539f73f3c..349defc8115 100644 --- a/advisories/unreviewed/2024/06/GHSA-59c6-mp6w-73hm/GHSA-59c6-mp6w-73hm.json +++ b/advisories/unreviewed/2024/06/GHSA-59c6-mp6w-73hm/GHSA-59c6-mp6w-73hm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-962x-cm53-4293/GHSA-962x-cm53-4293.json b/advisories/unreviewed/2024/06/GHSA-962x-cm53-4293/GHSA-962x-cm53-4293.json index 2da740bd8ae..20e41c5b07b 100644 --- a/advisories/unreviewed/2024/06/GHSA-962x-cm53-4293/GHSA-962x-cm53-4293.json +++ b/advisories/unreviewed/2024/06/GHSA-962x-cm53-4293/GHSA-962x-cm53-4293.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-f44r-hfph-3jh8/GHSA-f44r-hfph-3jh8.json b/advisories/unreviewed/2024/06/GHSA-f44r-hfph-3jh8/GHSA-f44r-hfph-3jh8.json index b0766e19ab1..518f6615560 100644 --- a/advisories/unreviewed/2024/06/GHSA-f44r-hfph-3jh8/GHSA-f44r-hfph-3jh8.json +++ b/advisories/unreviewed/2024/06/GHSA-f44r-hfph-3jh8/GHSA-f44r-hfph-3jh8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-prf2-4xjw-553w/GHSA-prf2-4xjw-553w.json b/advisories/unreviewed/2024/06/GHSA-prf2-4xjw-553w/GHSA-prf2-4xjw-553w.json index d4d3873c311..64a1918cd71 100644 --- a/advisories/unreviewed/2024/06/GHSA-prf2-4xjw-553w/GHSA-prf2-4xjw-553w.json +++ b/advisories/unreviewed/2024/06/GHSA-prf2-4xjw-553w/GHSA-prf2-4xjw-553w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-qmg2-53h9-6g7h/GHSA-qmg2-53h9-6g7h.json b/advisories/unreviewed/2024/06/GHSA-qmg2-53h9-6g7h/GHSA-qmg2-53h9-6g7h.json index 7b601186092..a47631c668c 100644 --- a/advisories/unreviewed/2024/06/GHSA-qmg2-53h9-6g7h/GHSA-qmg2-53h9-6g7h.json +++ b/advisories/unreviewed/2024/06/GHSA-qmg2-53h9-6g7h/GHSA-qmg2-53h9-6g7h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-459h-qwrj-j9gc/GHSA-459h-qwrj-j9gc.json b/advisories/unreviewed/2024/07/GHSA-459h-qwrj-j9gc/GHSA-459h-qwrj-j9gc.json index 8195a4db484..7be2e1ec382 100644 --- a/advisories/unreviewed/2024/07/GHSA-459h-qwrj-j9gc/GHSA-459h-qwrj-j9gc.json +++ b/advisories/unreviewed/2024/07/GHSA-459h-qwrj-j9gc/GHSA-459h-qwrj-j9gc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-ghw9-6h55-qj7v/GHSA-ghw9-6h55-qj7v.json b/advisories/unreviewed/2024/07/GHSA-ghw9-6h55-qj7v/GHSA-ghw9-6h55-qj7v.json index e9528bcf4ba..e3749a6f5af 100644 --- a/advisories/unreviewed/2024/07/GHSA-ghw9-6h55-qj7v/GHSA-ghw9-6h55-qj7v.json +++ b/advisories/unreviewed/2024/07/GHSA-ghw9-6h55-qj7v/GHSA-ghw9-6h55-qj7v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-vp7x-cv58-7w74/GHSA-vp7x-cv58-7w74.json b/advisories/unreviewed/2024/07/GHSA-vp7x-cv58-7w74/GHSA-vp7x-cv58-7w74.json index f912bcf9fb9..88c284723f2 100644 --- a/advisories/unreviewed/2024/07/GHSA-vp7x-cv58-7w74/GHSA-vp7x-cv58-7w74.json +++ b/advisories/unreviewed/2024/07/GHSA-vp7x-cv58-7w74/GHSA-vp7x-cv58-7w74.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-25fr-px8w-jvcm/GHSA-25fr-px8w-jvcm.json b/advisories/unreviewed/2024/08/GHSA-25fr-px8w-jvcm/GHSA-25fr-px8w-jvcm.json index 2fb049e96c3..7b7dcda150d 100644 --- a/advisories/unreviewed/2024/08/GHSA-25fr-px8w-jvcm/GHSA-25fr-px8w-jvcm.json +++ b/advisories/unreviewed/2024/08/GHSA-25fr-px8w-jvcm/GHSA-25fr-px8w-jvcm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-29qp-r356-cgp5/GHSA-29qp-r356-cgp5.json b/advisories/unreviewed/2024/08/GHSA-29qp-r356-cgp5/GHSA-29qp-r356-cgp5.json index 94fb23d54fc..dcc3ce2a2c1 100644 --- a/advisories/unreviewed/2024/08/GHSA-29qp-r356-cgp5/GHSA-29qp-r356-cgp5.json +++ b/advisories/unreviewed/2024/08/GHSA-29qp-r356-cgp5/GHSA-29qp-r356-cgp5.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-2f7j-8pxq-5mww/GHSA-2f7j-8pxq-5mww.json b/advisories/unreviewed/2024/08/GHSA-2f7j-8pxq-5mww/GHSA-2f7j-8pxq-5mww.json index be50bec6193..fd59a6c1e5a 100644 --- a/advisories/unreviewed/2024/08/GHSA-2f7j-8pxq-5mww/GHSA-2f7j-8pxq-5mww.json +++ b/advisories/unreviewed/2024/08/GHSA-2f7j-8pxq-5mww/GHSA-2f7j-8pxq-5mww.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-2pv4-crr8-ffh9/GHSA-2pv4-crr8-ffh9.json b/advisories/unreviewed/2024/08/GHSA-2pv4-crr8-ffh9/GHSA-2pv4-crr8-ffh9.json index 44d9273fb18..f56ef766cc7 100644 --- a/advisories/unreviewed/2024/08/GHSA-2pv4-crr8-ffh9/GHSA-2pv4-crr8-ffh9.json +++ b/advisories/unreviewed/2024/08/GHSA-2pv4-crr8-ffh9/GHSA-2pv4-crr8-ffh9.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-2pxp-hm79-mvqx/GHSA-2pxp-hm79-mvqx.json b/advisories/unreviewed/2024/08/GHSA-2pxp-hm79-mvqx/GHSA-2pxp-hm79-mvqx.json index 571a41d2b85..1529bfc2ae8 100644 --- a/advisories/unreviewed/2024/08/GHSA-2pxp-hm79-mvqx/GHSA-2pxp-hm79-mvqx.json +++ b/advisories/unreviewed/2024/08/GHSA-2pxp-hm79-mvqx/GHSA-2pxp-hm79-mvqx.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-3fr4-6j9r-w2r5/GHSA-3fr4-6j9r-w2r5.json b/advisories/unreviewed/2024/08/GHSA-3fr4-6j9r-w2r5/GHSA-3fr4-6j9r-w2r5.json index a7e755894d3..203ac15b4c4 100644 --- a/advisories/unreviewed/2024/08/GHSA-3fr4-6j9r-w2r5/GHSA-3fr4-6j9r-w2r5.json +++ b/advisories/unreviewed/2024/08/GHSA-3fr4-6j9r-w2r5/GHSA-3fr4-6j9r-w2r5.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-3qv4-28q5-585p/GHSA-3qv4-28q5-585p.json b/advisories/unreviewed/2024/08/GHSA-3qv4-28q5-585p/GHSA-3qv4-28q5-585p.json index 24528c5630f..4f6c90d97b4 100644 --- a/advisories/unreviewed/2024/08/GHSA-3qv4-28q5-585p/GHSA-3qv4-28q5-585p.json +++ b/advisories/unreviewed/2024/08/GHSA-3qv4-28q5-585p/GHSA-3qv4-28q5-585p.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-3vf4-qf7v-8hwx/GHSA-3vf4-qf7v-8hwx.json b/advisories/unreviewed/2024/08/GHSA-3vf4-qf7v-8hwx/GHSA-3vf4-qf7v-8hwx.json index 5d9f43239d5..e0943d57635 100644 --- a/advisories/unreviewed/2024/08/GHSA-3vf4-qf7v-8hwx/GHSA-3vf4-qf7v-8hwx.json +++ b/advisories/unreviewed/2024/08/GHSA-3vf4-qf7v-8hwx/GHSA-3vf4-qf7v-8hwx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-4mjp-p7h5-xhfj/GHSA-4mjp-p7h5-xhfj.json b/advisories/unreviewed/2024/08/GHSA-4mjp-p7h5-xhfj/GHSA-4mjp-p7h5-xhfj.json index 991207d0c28..6d9416fd72f 100644 --- a/advisories/unreviewed/2024/08/GHSA-4mjp-p7h5-xhfj/GHSA-4mjp-p7h5-xhfj.json +++ b/advisories/unreviewed/2024/08/GHSA-4mjp-p7h5-xhfj/GHSA-4mjp-p7h5-xhfj.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-4wqq-mhqm-j8fh/GHSA-4wqq-mhqm-j8fh.json b/advisories/unreviewed/2024/08/GHSA-4wqq-mhqm-j8fh/GHSA-4wqq-mhqm-j8fh.json index 83f63e49d9e..fce0d21b87d 100644 --- a/advisories/unreviewed/2024/08/GHSA-4wqq-mhqm-j8fh/GHSA-4wqq-mhqm-j8fh.json +++ b/advisories/unreviewed/2024/08/GHSA-4wqq-mhqm-j8fh/GHSA-4wqq-mhqm-j8fh.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-5647-wrp8-rxf7/GHSA-5647-wrp8-rxf7.json b/advisories/unreviewed/2024/08/GHSA-5647-wrp8-rxf7/GHSA-5647-wrp8-rxf7.json index f0e3d661ab1..d6fafdb489c 100644 --- a/advisories/unreviewed/2024/08/GHSA-5647-wrp8-rxf7/GHSA-5647-wrp8-rxf7.json +++ b/advisories/unreviewed/2024/08/GHSA-5647-wrp8-rxf7/GHSA-5647-wrp8-rxf7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-6jr4-fv3f-vmgp/GHSA-6jr4-fv3f-vmgp.json b/advisories/unreviewed/2024/08/GHSA-6jr4-fv3f-vmgp/GHSA-6jr4-fv3f-vmgp.json index 08893be1aed..20a1798a910 100644 --- a/advisories/unreviewed/2024/08/GHSA-6jr4-fv3f-vmgp/GHSA-6jr4-fv3f-vmgp.json +++ b/advisories/unreviewed/2024/08/GHSA-6jr4-fv3f-vmgp/GHSA-6jr4-fv3f-vmgp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-6v5v-396j-6g9j/GHSA-6v5v-396j-6g9j.json b/advisories/unreviewed/2024/08/GHSA-6v5v-396j-6g9j/GHSA-6v5v-396j-6g9j.json index d62f5b7fd15..7beb561276d 100644 --- a/advisories/unreviewed/2024/08/GHSA-6v5v-396j-6g9j/GHSA-6v5v-396j-6g9j.json +++ b/advisories/unreviewed/2024/08/GHSA-6v5v-396j-6g9j/GHSA-6v5v-396j-6g9j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-756x-7gxj-qmpv/GHSA-756x-7gxj-qmpv.json b/advisories/unreviewed/2024/08/GHSA-756x-7gxj-qmpv/GHSA-756x-7gxj-qmpv.json index 3dedeecc2eb..f5f8decf2ba 100644 --- a/advisories/unreviewed/2024/08/GHSA-756x-7gxj-qmpv/GHSA-756x-7gxj-qmpv.json +++ b/advisories/unreviewed/2024/08/GHSA-756x-7gxj-qmpv/GHSA-756x-7gxj-qmpv.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-7ph6-ch7r-f425/GHSA-7ph6-ch7r-f425.json b/advisories/unreviewed/2024/08/GHSA-7ph6-ch7r-f425/GHSA-7ph6-ch7r-f425.json index cb57da06555..39bd18ff3f1 100644 --- a/advisories/unreviewed/2024/08/GHSA-7ph6-ch7r-f425/GHSA-7ph6-ch7r-f425.json +++ b/advisories/unreviewed/2024/08/GHSA-7ph6-ch7r-f425/GHSA-7ph6-ch7r-f425.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-7vcj-8223-g52v/GHSA-7vcj-8223-g52v.json b/advisories/unreviewed/2024/08/GHSA-7vcj-8223-g52v/GHSA-7vcj-8223-g52v.json index ccf6f188f8d..b04f9867108 100644 --- a/advisories/unreviewed/2024/08/GHSA-7vcj-8223-g52v/GHSA-7vcj-8223-g52v.json +++ b/advisories/unreviewed/2024/08/GHSA-7vcj-8223-g52v/GHSA-7vcj-8223-g52v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-86vf-g5px-79j2/GHSA-86vf-g5px-79j2.json b/advisories/unreviewed/2024/08/GHSA-86vf-g5px-79j2/GHSA-86vf-g5px-79j2.json index d4631660ac8..68c9e75f447 100644 --- a/advisories/unreviewed/2024/08/GHSA-86vf-g5px-79j2/GHSA-86vf-g5px-79j2.json +++ b/advisories/unreviewed/2024/08/GHSA-86vf-g5px-79j2/GHSA-86vf-g5px-79j2.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-939p-28h4-46p5/GHSA-939p-28h4-46p5.json b/advisories/unreviewed/2024/08/GHSA-939p-28h4-46p5/GHSA-939p-28h4-46p5.json index 884826fdefd..231e6e42c6f 100644 --- a/advisories/unreviewed/2024/08/GHSA-939p-28h4-46p5/GHSA-939p-28h4-46p5.json +++ b/advisories/unreviewed/2024/08/GHSA-939p-28h4-46p5/GHSA-939p-28h4-46p5.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-c627-r4px-c33f/GHSA-c627-r4px-c33f.json b/advisories/unreviewed/2024/08/GHSA-c627-r4px-c33f/GHSA-c627-r4px-c33f.json index 156227dc7d7..59d5d57ee37 100644 --- a/advisories/unreviewed/2024/08/GHSA-c627-r4px-c33f/GHSA-c627-r4px-c33f.json +++ b/advisories/unreviewed/2024/08/GHSA-c627-r4px-c33f/GHSA-c627-r4px-c33f.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-c7v9-gh22-gjq5/GHSA-c7v9-gh22-gjq5.json b/advisories/unreviewed/2024/08/GHSA-c7v9-gh22-gjq5/GHSA-c7v9-gh22-gjq5.json index 3ff0f85780a..44b508ed88c 100644 --- a/advisories/unreviewed/2024/08/GHSA-c7v9-gh22-gjq5/GHSA-c7v9-gh22-gjq5.json +++ b/advisories/unreviewed/2024/08/GHSA-c7v9-gh22-gjq5/GHSA-c7v9-gh22-gjq5.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-ccp2-8cqw-xhpw/GHSA-ccp2-8cqw-xhpw.json b/advisories/unreviewed/2024/08/GHSA-ccp2-8cqw-xhpw/GHSA-ccp2-8cqw-xhpw.json index 840d33d84dd..9d6938ec78b 100644 --- a/advisories/unreviewed/2024/08/GHSA-ccp2-8cqw-xhpw/GHSA-ccp2-8cqw-xhpw.json +++ b/advisories/unreviewed/2024/08/GHSA-ccp2-8cqw-xhpw/GHSA-ccp2-8cqw-xhpw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-cvv3-vch8-mp39/GHSA-cvv3-vch8-mp39.json b/advisories/unreviewed/2024/08/GHSA-cvv3-vch8-mp39/GHSA-cvv3-vch8-mp39.json index 47c404a93b4..dd0a9f2ad5e 100644 --- a/advisories/unreviewed/2024/08/GHSA-cvv3-vch8-mp39/GHSA-cvv3-vch8-mp39.json +++ b/advisories/unreviewed/2024/08/GHSA-cvv3-vch8-mp39/GHSA-cvv3-vch8-mp39.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-cwqj-wjpc-hr2x/GHSA-cwqj-wjpc-hr2x.json b/advisories/unreviewed/2024/08/GHSA-cwqj-wjpc-hr2x/GHSA-cwqj-wjpc-hr2x.json index 876e2565396..4ae965ef744 100644 --- a/advisories/unreviewed/2024/08/GHSA-cwqj-wjpc-hr2x/GHSA-cwqj-wjpc-hr2x.json +++ b/advisories/unreviewed/2024/08/GHSA-cwqj-wjpc-hr2x/GHSA-cwqj-wjpc-hr2x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-cxjm-x772-f6r9/GHSA-cxjm-x772-f6r9.json b/advisories/unreviewed/2024/08/GHSA-cxjm-x772-f6r9/GHSA-cxjm-x772-f6r9.json index 23dcbe0ceb0..3b16fd24e98 100644 --- a/advisories/unreviewed/2024/08/GHSA-cxjm-x772-f6r9/GHSA-cxjm-x772-f6r9.json +++ b/advisories/unreviewed/2024/08/GHSA-cxjm-x772-f6r9/GHSA-cxjm-x772-f6r9.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-fgqh-mx4w-q7rr/GHSA-fgqh-mx4w-q7rr.json b/advisories/unreviewed/2024/08/GHSA-fgqh-mx4w-q7rr/GHSA-fgqh-mx4w-q7rr.json index ccac2737c35..eec32299592 100644 --- a/advisories/unreviewed/2024/08/GHSA-fgqh-mx4w-q7rr/GHSA-fgqh-mx4w-q7rr.json +++ b/advisories/unreviewed/2024/08/GHSA-fgqh-mx4w-q7rr/GHSA-fgqh-mx4w-q7rr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-frwc-xr7f-wxx2/GHSA-frwc-xr7f-wxx2.json b/advisories/unreviewed/2024/08/GHSA-frwc-xr7f-wxx2/GHSA-frwc-xr7f-wxx2.json index 9beb56d26b7..0923bef22e0 100644 --- a/advisories/unreviewed/2024/08/GHSA-frwc-xr7f-wxx2/GHSA-frwc-xr7f-wxx2.json +++ b/advisories/unreviewed/2024/08/GHSA-frwc-xr7f-wxx2/GHSA-frwc-xr7f-wxx2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-hj26-xxg9-8jhq/GHSA-hj26-xxg9-8jhq.json b/advisories/unreviewed/2024/08/GHSA-hj26-xxg9-8jhq/GHSA-hj26-xxg9-8jhq.json index 97b1f86c25c..422f4db4f80 100644 --- a/advisories/unreviewed/2024/08/GHSA-hj26-xxg9-8jhq/GHSA-hj26-xxg9-8jhq.json +++ b/advisories/unreviewed/2024/08/GHSA-hj26-xxg9-8jhq/GHSA-hj26-xxg9-8jhq.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-hphg-jf8m-wgxp/GHSA-hphg-jf8m-wgxp.json b/advisories/unreviewed/2024/08/GHSA-hphg-jf8m-wgxp/GHSA-hphg-jf8m-wgxp.json index f94f2997b6a..4b39593ca4f 100644 --- a/advisories/unreviewed/2024/08/GHSA-hphg-jf8m-wgxp/GHSA-hphg-jf8m-wgxp.json +++ b/advisories/unreviewed/2024/08/GHSA-hphg-jf8m-wgxp/GHSA-hphg-jf8m-wgxp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-j4mv-2m42-3984/GHSA-j4mv-2m42-3984.json b/advisories/unreviewed/2024/08/GHSA-j4mv-2m42-3984/GHSA-j4mv-2m42-3984.json index 1d57b0b73c8..ab4b9373886 100644 --- a/advisories/unreviewed/2024/08/GHSA-j4mv-2m42-3984/GHSA-j4mv-2m42-3984.json +++ b/advisories/unreviewed/2024/08/GHSA-j4mv-2m42-3984/GHSA-j4mv-2m42-3984.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-j8xm-x2w7-hmgh/GHSA-j8xm-x2w7-hmgh.json b/advisories/unreviewed/2024/08/GHSA-j8xm-x2w7-hmgh/GHSA-j8xm-x2w7-hmgh.json index 97fecf1084c..4c0779a2d9d 100644 --- a/advisories/unreviewed/2024/08/GHSA-j8xm-x2w7-hmgh/GHSA-j8xm-x2w7-hmgh.json +++ b/advisories/unreviewed/2024/08/GHSA-j8xm-x2w7-hmgh/GHSA-j8xm-x2w7-hmgh.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-jjc3-cj6j-hw3v/GHSA-jjc3-cj6j-hw3v.json b/advisories/unreviewed/2024/08/GHSA-jjc3-cj6j-hw3v/GHSA-jjc3-cj6j-hw3v.json index 27b16c36f38..0823a5708d5 100644 --- a/advisories/unreviewed/2024/08/GHSA-jjc3-cj6j-hw3v/GHSA-jjc3-cj6j-hw3v.json +++ b/advisories/unreviewed/2024/08/GHSA-jjc3-cj6j-hw3v/GHSA-jjc3-cj6j-hw3v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-mc4q-hp46-qc8h/GHSA-mc4q-hp46-qc8h.json b/advisories/unreviewed/2024/08/GHSA-mc4q-hp46-qc8h/GHSA-mc4q-hp46-qc8h.json index f18edddea08..c27c31a971c 100644 --- a/advisories/unreviewed/2024/08/GHSA-mc4q-hp46-qc8h/GHSA-mc4q-hp46-qc8h.json +++ b/advisories/unreviewed/2024/08/GHSA-mc4q-hp46-qc8h/GHSA-mc4q-hp46-qc8h.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-mh7g-3h8c-hq7m/GHSA-mh7g-3h8c-hq7m.json b/advisories/unreviewed/2024/08/GHSA-mh7g-3h8c-hq7m/GHSA-mh7g-3h8c-hq7m.json index 71f650e6f07..2cfa10e383b 100644 --- a/advisories/unreviewed/2024/08/GHSA-mh7g-3h8c-hq7m/GHSA-mh7g-3h8c-hq7m.json +++ b/advisories/unreviewed/2024/08/GHSA-mh7g-3h8c-hq7m/GHSA-mh7g-3h8c-hq7m.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-mq4f-wch7-8vf9/GHSA-mq4f-wch7-8vf9.json b/advisories/unreviewed/2024/08/GHSA-mq4f-wch7-8vf9/GHSA-mq4f-wch7-8vf9.json index e2d5481c9b5..aa0ae11a605 100644 --- a/advisories/unreviewed/2024/08/GHSA-mq4f-wch7-8vf9/GHSA-mq4f-wch7-8vf9.json +++ b/advisories/unreviewed/2024/08/GHSA-mq4f-wch7-8vf9/GHSA-mq4f-wch7-8vf9.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-p7c5-whj7-83vc/GHSA-p7c5-whj7-83vc.json b/advisories/unreviewed/2024/08/GHSA-p7c5-whj7-83vc/GHSA-p7c5-whj7-83vc.json index f7c7811959f..ec71a134d3c 100644 --- a/advisories/unreviewed/2024/08/GHSA-p7c5-whj7-83vc/GHSA-p7c5-whj7-83vc.json +++ b/advisories/unreviewed/2024/08/GHSA-p7c5-whj7-83vc/GHSA-p7c5-whj7-83vc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-qf2x-cq7r-8263/GHSA-qf2x-cq7r-8263.json b/advisories/unreviewed/2024/08/GHSA-qf2x-cq7r-8263/GHSA-qf2x-cq7r-8263.json index 0ec89f3bd20..4caad99cdff 100644 --- a/advisories/unreviewed/2024/08/GHSA-qf2x-cq7r-8263/GHSA-qf2x-cq7r-8263.json +++ b/advisories/unreviewed/2024/08/GHSA-qf2x-cq7r-8263/GHSA-qf2x-cq7r-8263.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-qhmw-cw2v-9499/GHSA-qhmw-cw2v-9499.json b/advisories/unreviewed/2024/08/GHSA-qhmw-cw2v-9499/GHSA-qhmw-cw2v-9499.json index 8e7f9ec1935..61a41c2a365 100644 --- a/advisories/unreviewed/2024/08/GHSA-qhmw-cw2v-9499/GHSA-qhmw-cw2v-9499.json +++ b/advisories/unreviewed/2024/08/GHSA-qhmw-cw2v-9499/GHSA-qhmw-cw2v-9499.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-qqh7-j72m-6p4p/GHSA-qqh7-j72m-6p4p.json b/advisories/unreviewed/2024/08/GHSA-qqh7-j72m-6p4p/GHSA-qqh7-j72m-6p4p.json index 02d96c50b92..e89a3ccebc7 100644 --- a/advisories/unreviewed/2024/08/GHSA-qqh7-j72m-6p4p/GHSA-qqh7-j72m-6p4p.json +++ b/advisories/unreviewed/2024/08/GHSA-qqh7-j72m-6p4p/GHSA-qqh7-j72m-6p4p.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-qx4x-h5xp-mmqx/GHSA-qx4x-h5xp-mmqx.json b/advisories/unreviewed/2024/08/GHSA-qx4x-h5xp-mmqx/GHSA-qx4x-h5xp-mmqx.json index 806a6ed84ef..43575d1f2b5 100644 --- a/advisories/unreviewed/2024/08/GHSA-qx4x-h5xp-mmqx/GHSA-qx4x-h5xp-mmqx.json +++ b/advisories/unreviewed/2024/08/GHSA-qx4x-h5xp-mmqx/GHSA-qx4x-h5xp-mmqx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-rc9c-w737-83cm/GHSA-rc9c-w737-83cm.json b/advisories/unreviewed/2024/08/GHSA-rc9c-w737-83cm/GHSA-rc9c-w737-83cm.json index d71f7f62062..a7e1c8b0a8b 100644 --- a/advisories/unreviewed/2024/08/GHSA-rc9c-w737-83cm/GHSA-rc9c-w737-83cm.json +++ b/advisories/unreviewed/2024/08/GHSA-rc9c-w737-83cm/GHSA-rc9c-w737-83cm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-rfcm-2r55-7fc2/GHSA-rfcm-2r55-7fc2.json b/advisories/unreviewed/2024/08/GHSA-rfcm-2r55-7fc2/GHSA-rfcm-2r55-7fc2.json index 74b1ea40cef..75170c6c56c 100644 --- a/advisories/unreviewed/2024/08/GHSA-rfcm-2r55-7fc2/GHSA-rfcm-2r55-7fc2.json +++ b/advisories/unreviewed/2024/08/GHSA-rfcm-2r55-7fc2/GHSA-rfcm-2r55-7fc2.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-rr6j-f8h9-f9mp/GHSA-rr6j-f8h9-f9mp.json b/advisories/unreviewed/2024/08/GHSA-rr6j-f8h9-f9mp/GHSA-rr6j-f8h9-f9mp.json index d91f135c787..468d136b07c 100644 --- a/advisories/unreviewed/2024/08/GHSA-rr6j-f8h9-f9mp/GHSA-rr6j-f8h9-f9mp.json +++ b/advisories/unreviewed/2024/08/GHSA-rr6j-f8h9-f9mp/GHSA-rr6j-f8h9-f9mp.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-w25h-8579-q2hj/GHSA-w25h-8579-q2hj.json b/advisories/unreviewed/2024/08/GHSA-w25h-8579-q2hj/GHSA-w25h-8579-q2hj.json index 1c794a23e0e..eb2e1f3f5ea 100644 --- a/advisories/unreviewed/2024/08/GHSA-w25h-8579-q2hj/GHSA-w25h-8579-q2hj.json +++ b/advisories/unreviewed/2024/08/GHSA-w25h-8579-q2hj/GHSA-w25h-8579-q2hj.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-w2v4-6c2x-p3qm/GHSA-w2v4-6c2x-p3qm.json b/advisories/unreviewed/2024/08/GHSA-w2v4-6c2x-p3qm/GHSA-w2v4-6c2x-p3qm.json index d8f26068b66..091d8303a38 100644 --- a/advisories/unreviewed/2024/08/GHSA-w2v4-6c2x-p3qm/GHSA-w2v4-6c2x-p3qm.json +++ b/advisories/unreviewed/2024/08/GHSA-w2v4-6c2x-p3qm/GHSA-w2v4-6c2x-p3qm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-ww3m-j46v-9wf2/GHSA-ww3m-j46v-9wf2.json b/advisories/unreviewed/2024/08/GHSA-ww3m-j46v-9wf2/GHSA-ww3m-j46v-9wf2.json index 20ddaa3e5d1..708d3dd4311 100644 --- a/advisories/unreviewed/2024/08/GHSA-ww3m-j46v-9wf2/GHSA-ww3m-j46v-9wf2.json +++ b/advisories/unreviewed/2024/08/GHSA-ww3m-j46v-9wf2/GHSA-ww3m-j46v-9wf2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-x65v-v924-92w9/GHSA-x65v-v924-92w9.json b/advisories/unreviewed/2024/08/GHSA-x65v-v924-92w9/GHSA-x65v-v924-92w9.json index 2aa8945753b..a82aa441073 100644 --- a/advisories/unreviewed/2024/08/GHSA-x65v-v924-92w9/GHSA-x65v-v924-92w9.json +++ b/advisories/unreviewed/2024/08/GHSA-x65v-v924-92w9/GHSA-x65v-v924-92w9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",