diff --git a/advisories/github-reviewed/2017/10/GHSA-229r-pqp6-8w6g/GHSA-229r-pqp6-8w6g.json b/advisories/github-reviewed/2017/10/GHSA-229r-pqp6-8w6g/GHSA-229r-pqp6-8w6g.json index 5f4ed93a97a..53ea0c5fa3f 100644 --- a/advisories/github-reviewed/2017/10/GHSA-229r-pqp6-8w6g/GHSA-229r-pqp6-8w6g.json +++ b/advisories/github-reviewed/2017/10/GHSA-229r-pqp6-8w6g/GHSA-229r-pqp6-8w6g.json @@ -8,9 +8,7 @@ ], "summary": "sprout Arbitrary Code Execution vulnerability", "details": "The `unpack_zip` function in `archive_unpacker.rb` in the sprout gem 0.7.246 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a (1) filename or (2) path.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-c9c5-9fpr-m882/GHSA-c9c5-9fpr-m882.json b/advisories/github-reviewed/2017/10/GHSA-c9c5-9fpr-m882/GHSA-c9c5-9fpr-m882.json index 9eb28906dd9..c2ec0f1b923 100644 --- a/advisories/github-reviewed/2017/10/GHSA-c9c5-9fpr-m882/GHSA-c9c5-9fpr-m882.json +++ b/advisories/github-reviewed/2017/10/GHSA-c9c5-9fpr-m882/GHSA-c9c5-9fpr-m882.json @@ -8,9 +8,7 @@ ], "summary": "sentry-raven allows remote attackers to cause a denial of service via a large exponent value in a scientific number", "details": "The `numtok` function in `lib/raven/okjson.rb` in the raven-ruby gem before 0.12.2 for Ruby allows remote attackers to cause a denial of service via a large exponent value in a scientific number.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-fgmx-8h93-26fh/GHSA-fgmx-8h93-26fh.json b/advisories/github-reviewed/2017/10/GHSA-fgmx-8h93-26fh/GHSA-fgmx-8h93-26fh.json index 8a83e7f1955..4dfade8f5b5 100644 --- a/advisories/github-reviewed/2017/10/GHSA-fgmx-8h93-26fh/GHSA-fgmx-8h93-26fh.json +++ b/advisories/github-reviewed/2017/10/GHSA-fgmx-8h93-26fh/GHSA-fgmx-8h93-26fh.json @@ -8,9 +8,7 @@ ], "summary": "omniauth-oauth2 Cross-Site Request Forgery vulnerability", "details": "Cross-site request forgery (CSRF) vulnerability in the omniauth-oauth2 gem prior to 1.1.1 for Ruby allows remote attackers to hijack the authentication of users for requests that modify session state.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-g266-3crh-h7gj/GHSA-g266-3crh-h7gj.json b/advisories/github-reviewed/2017/10/GHSA-g266-3crh-h7gj/GHSA-g266-3crh-h7gj.json index d9389f302fb..bb2ad5010a8 100644 --- a/advisories/github-reviewed/2017/10/GHSA-g266-3crh-h7gj/GHSA-g266-3crh-h7gj.json +++ b/advisories/github-reviewed/2017/10/GHSA-g266-3crh-h7gj/GHSA-g266-3crh-h7gj.json @@ -8,9 +8,7 @@ ], "summary": "ldoce Gem Arbitrary Command Execution", "details": "`lib/ldoce/word.rb` in the ldoce 0.0.2 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in (1) an mp3 URL or (2) file name.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-hxx6-p24v-wg8c/GHSA-hxx6-p24v-wg8c.json b/advisories/github-reviewed/2017/10/GHSA-hxx6-p24v-wg8c/GHSA-hxx6-p24v-wg8c.json index 8d0ba5f0e68..f549a287afd 100644 --- a/advisories/github-reviewed/2017/10/GHSA-hxx6-p24v-wg8c/GHSA-hxx6-p24v-wg8c.json +++ b/advisories/github-reviewed/2017/10/GHSA-hxx6-p24v-wg8c/GHSA-hxx6-p24v-wg8c.json @@ -8,9 +8,7 @@ ], "summary": "Curl Gem insufficient URL escaping command injection", "details": "`lib/curl.rb` in the Curl Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-jg4m-q6w8-vrjp/GHSA-jg4m-q6w8-vrjp.json b/advisories/github-reviewed/2017/10/GHSA-jg4m-q6w8-vrjp/GHSA-jg4m-q6w8-vrjp.json index 02d19da9467..de15f392272 100644 --- a/advisories/github-reviewed/2017/10/GHSA-jg4m-q6w8-vrjp/GHSA-jg4m-q6w8-vrjp.json +++ b/advisories/github-reviewed/2017/10/GHSA-jg4m-q6w8-vrjp/GHSA-jg4m-q6w8-vrjp.json @@ -8,9 +8,7 @@ ], "summary": "rgpg Code Injection vulnerability", "details": "The `self.run_gpg` function in `lib/rgpg/gpg_helper.rb` in the rgpg gem before 0.2.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-jxx8-v83v-rhw3/GHSA-jxx8-v83v-rhw3.json b/advisories/github-reviewed/2017/10/GHSA-jxx8-v83v-rhw3/GHSA-jxx8-v83v-rhw3.json index 7100027800f..c88ddb1acf0 100644 --- a/advisories/github-reviewed/2017/10/GHSA-jxx8-v83v-rhw3/GHSA-jxx8-v83v-rhw3.json +++ b/advisories/github-reviewed/2017/10/GHSA-jxx8-v83v-rhw3/GHSA-jxx8-v83v-rhw3.json @@ -8,9 +8,7 @@ ], "summary": "Spree Improper Input Validation vulnerability", "details": "Spree Commerce 1.0.x before 2.0.0.rc1 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary commands via the (1) `payment_method` parameter to `core/app/controllers/spree/admin/payment_methods_controller.rb`; and the (2) `promotion_action parameter` to `promotion_actions_controller.rb`, (3) `promotion_rule parameter` to `promotion_rules_controller.rb`, and (4) `calculator_type` parameter to `promotions_controller.rb` in `promo/app/controllers/spree/admin/`, related to unsafe use of the constantize function.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-p65m-qr5x-rrqq/GHSA-p65m-qr5x-rrqq.json b/advisories/github-reviewed/2017/10/GHSA-p65m-qr5x-rrqq/GHSA-p65m-qr5x-rrqq.json index 920bc88d6e9..e5287d532d0 100644 --- a/advisories/github-reviewed/2017/10/GHSA-p65m-qr5x-rrqq/GHSA-p65m-qr5x-rrqq.json +++ b/advisories/github-reviewed/2017/10/GHSA-p65m-qr5x-rrqq/GHSA-p65m-qr5x-rrqq.json @@ -8,9 +8,7 @@ ], "summary": "Webbynode Code Injection vulnerability", "details": "The message function in `lib/webbynode/notify.rb` in the Webbynode gem 1.0.5.3 and earlier for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a growlnotify message.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-q6cw-2553-7837/GHSA-q6cw-2553-7837.json b/advisories/github-reviewed/2017/10/GHSA-q6cw-2553-7837/GHSA-q6cw-2553-7837.json index d418ecaa6ba..512f5ebd57e 100644 --- a/advisories/github-reviewed/2017/10/GHSA-q6cw-2553-7837/GHSA-q6cw-2553-7837.json +++ b/advisories/github-reviewed/2017/10/GHSA-q6cw-2553-7837/GHSA-q6cw-2553-7837.json @@ -8,9 +8,7 @@ ], "summary": "newrelic_rpm Gem Discloses Sensitive Information", "details": "Ruby agent 3.2.0 through 3.5.3.23 serializes sensitive data when communicating with servers operated by New Relic, which allows remote attackers to obtain sensitive information (database credentials and SQL statements) by sniffing the network and deserializing the data.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-w754-gq8r-pf5f/GHSA-w754-gq8r-pf5f.json b/advisories/github-reviewed/2017/10/GHSA-w754-gq8r-pf5f/GHSA-w754-gq8r-pf5f.json index 77b608aed17..526f1039d6a 100644 --- a/advisories/github-reviewed/2017/10/GHSA-w754-gq8r-pf5f/GHSA-w754-gq8r-pf5f.json +++ b/advisories/github-reviewed/2017/10/GHSA-w754-gq8r-pf5f/GHSA-w754-gq8r-pf5f.json @@ -8,9 +8,7 @@ ], "summary": "MiniMagick Gem for Ruby URI Handling Arbitrary Command Injection", "details": "`lib/mini_magick.rb` in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/02/GHSA-2m53-83f3-562j/GHSA-2m53-83f3-562j.json b/advisories/github-reviewed/2022/02/GHSA-2m53-83f3-562j/GHSA-2m53-83f3-562j.json index 1d315ef0ca7..77dcff7c0e9 100644 --- a/advisories/github-reviewed/2022/02/GHSA-2m53-83f3-562j/GHSA-2m53-83f3-562j.json +++ b/advisories/github-reviewed/2022/02/GHSA-2m53-83f3-562j/GHSA-2m53-83f3-562j.json @@ -3,14 +3,10 @@ "id": "GHSA-2m53-83f3-562j", "modified": "2022-01-27T23:11:40Z", "published": "2022-02-01T00:44:35Z", - "aliases": [ - - ], + "aliases": [], "summary": "Prototype pollution in min-dash < 3.8.1", "details": "### Impact\n\nThe `set` method is vulnerable to prototype pollution with specially crafted inputs.\n\n```javascript\n// insert the following into poc.js and run node poc,js (after installing the package)\n \nlet parser = require(\"min-dash\");\nparser.set({}, [[\"__proto__\"], \"polluted\"], \"success\");\nconsole.log(polluted);\n```\n\n### Patches\n\n`min-dash>=3.8.1` fix the issue.\n\n### Workarounds\n\nNo workarounds exist for the issue.\n\n### References\n\nClosed via https://github.com/bpmn-io/min-dash/pull/21.\n\n### Credits\n\nCredits to Cristian-Alexandru STAICU who found the vulnerability and to Idan Digmi from the Snyk Security Team who reported the vulnerability to us, responsibly. ", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-7f6w-fhmr-j8hq/GHSA-7f6w-fhmr-j8hq.json b/advisories/github-reviewed/2022/05/GHSA-7f6w-fhmr-j8hq/GHSA-7f6w-fhmr-j8hq.json index 82527560dc6..e9957990f60 100644 --- a/advisories/github-reviewed/2022/05/GHSA-7f6w-fhmr-j8hq/GHSA-7f6w-fhmr-j8hq.json +++ b/advisories/github-reviewed/2022/05/GHSA-7f6w-fhmr-j8hq/GHSA-7f6w-fhmr-j8hq.json @@ -70,9 +70,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-01-30T23:16:51Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-g4jg-gpwv-p7wv/GHSA-g4jg-gpwv-p7wv.json b/advisories/github-reviewed/2022/05/GHSA-g4jg-gpwv-p7wv/GHSA-g4jg-gpwv-p7wv.json index 3cb43084a0f..6aa8442307d 100644 --- a/advisories/github-reviewed/2022/05/GHSA-g4jg-gpwv-p7wv/GHSA-g4jg-gpwv-p7wv.json +++ b/advisories/github-reviewed/2022/05/GHSA-g4jg-gpwv-p7wv/GHSA-g4jg-gpwv-p7wv.json @@ -8,9 +8,7 @@ ], "summary": "Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy", "details": "The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-g7cf-wg27-qw87/GHSA-g7cf-wg27-qw87.json b/advisories/github-reviewed/2022/05/GHSA-g7cf-wg27-qw87/GHSA-g7cf-wg27-qw87.json index 24f25fba422..698d0b006d4 100644 --- a/advisories/github-reviewed/2022/05/GHSA-g7cf-wg27-qw87/GHSA-g7cf-wg27-qw87.json +++ b/advisories/github-reviewed/2022/05/GHSA-g7cf-wg27-qw87/GHSA-g7cf-wg27-qw87.json @@ -70,9 +70,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-01-30T23:17:03Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-pjmx-4gc6-hwv8/GHSA-pjmx-4gc6-hwv8.json b/advisories/github-reviewed/2022/05/GHSA-pjmx-4gc6-hwv8/GHSA-pjmx-4gc6-hwv8.json index efd62b43254..4c87ab72323 100644 --- a/advisories/github-reviewed/2022/05/GHSA-pjmx-4gc6-hwv8/GHSA-pjmx-4gc6-hwv8.json +++ b/advisories/github-reviewed/2022/05/GHSA-pjmx-4gc6-hwv8/GHSA-pjmx-4gc6-hwv8.json @@ -8,9 +8,7 @@ ], "summary": "Drupal cross-site scripting vulnerability via actions feature and trigger module", "details": "Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-qmqw-mpqp-mr54/GHSA-qmqw-mpqp-mr54.json b/advisories/github-reviewed/2022/05/GHSA-qmqw-mpqp-mr54/GHSA-qmqw-mpqp-mr54.json index 936e7f02324..f3bd2989f91 100644 --- a/advisories/github-reviewed/2022/05/GHSA-qmqw-mpqp-mr54/GHSA-qmqw-mpqp-mr54.json +++ b/advisories/github-reviewed/2022/05/GHSA-qmqw-mpqp-mr54/GHSA-qmqw-mpqp-mr54.json @@ -8,9 +8,7 @@ ], "summary": "Symfony Incorrect Access Control", "details": "FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the `_controller` attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to `/_fragment`.\n\nThis issue has been fixed in Symfony 2.3.29, 2.5.12, and 2.6.8. Note that no fixes are provided for Symfony 2.4 as it's not maintained anymore.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/unreviewed/2021/12/GHSA-566v-p4rc-c936/GHSA-566v-p4rc-c936.json b/advisories/unreviewed/2021/12/GHSA-566v-p4rc-c936/GHSA-566v-p4rc-c936.json index 6e48945a6e3..719896bea2e 100644 --- a/advisories/unreviewed/2021/12/GHSA-566v-p4rc-c936/GHSA-566v-p4rc-c936.json +++ b/advisories/unreviewed/2021/12/GHSA-566v-p4rc-c936/GHSA-566v-p4rc-c936.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-65v8-8343-jcqr/GHSA-65v8-8343-jcqr.json b/advisories/unreviewed/2021/12/GHSA-65v8-8343-jcqr/GHSA-65v8-8343-jcqr.json index 5a1aa89525b..feb80789832 100644 --- a/advisories/unreviewed/2021/12/GHSA-65v8-8343-jcqr/GHSA-65v8-8343-jcqr.json +++ b/advisories/unreviewed/2021/12/GHSA-65v8-8343-jcqr/GHSA-65v8-8343-jcqr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-8xm8-948r-wpjw/GHSA-8xm8-948r-wpjw.json b/advisories/unreviewed/2021/12/GHSA-8xm8-948r-wpjw/GHSA-8xm8-948r-wpjw.json index 4a95f003408..60c81950c92 100644 --- a/advisories/unreviewed/2021/12/GHSA-8xm8-948r-wpjw/GHSA-8xm8-948r-wpjw.json +++ b/advisories/unreviewed/2021/12/GHSA-8xm8-948r-wpjw/GHSA-8xm8-948r-wpjw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-286r-9gcv-cp56/GHSA-286r-9gcv-cp56.json b/advisories/unreviewed/2022/01/GHSA-286r-9gcv-cp56/GHSA-286r-9gcv-cp56.json index 964792defdc..3b4883d18a2 100644 --- a/advisories/unreviewed/2022/01/GHSA-286r-9gcv-cp56/GHSA-286r-9gcv-cp56.json +++ b/advisories/unreviewed/2022/01/GHSA-286r-9gcv-cp56/GHSA-286r-9gcv-cp56.json @@ -7,12 +7,8 @@ "CVE-2021-24733" ], "details": "The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view other users' draft and password-protected posts which they cannot view normally.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-29ch-3cxc-63fh/GHSA-29ch-3cxc-63fh.json b/advisories/unreviewed/2022/01/GHSA-29ch-3cxc-63fh/GHSA-29ch-3cxc-63fh.json index 05646286881..7dcfcd0d6a2 100644 --- a/advisories/unreviewed/2022/01/GHSA-29ch-3cxc-63fh/GHSA-29ch-3cxc-63fh.json +++ b/advisories/unreviewed/2022/01/GHSA-29ch-3cxc-63fh/GHSA-29ch-3cxc-63fh.json @@ -7,12 +7,8 @@ "CVE-2021-24936" ], "details": "The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which could allow attackers to make a logged in admin change them and perform Cross-Site Scripting attacks", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-29jq-4wjw-g2qv/GHSA-29jq-4wjw-g2qv.json b/advisories/unreviewed/2022/01/GHSA-29jq-4wjw-g2qv/GHSA-29jq-4wjw-g2qv.json index e56545c28b8..18a775c4cca 100644 --- a/advisories/unreviewed/2022/01/GHSA-29jq-4wjw-g2qv/GHSA-29jq-4wjw-g2qv.json +++ b/advisories/unreviewed/2022/01/GHSA-29jq-4wjw-g2qv/GHSA-29jq-4wjw-g2qv.json @@ -7,12 +7,8 @@ "CVE-2022-22888" ], "details": "Jerryscript 3.0.0 was discovered to contain a stack overflow via ecma_op_object_find_own in /ecma/operations/ecma-objects.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-2gwv-fv77-xfgx/GHSA-2gwv-fv77-xfgx.json b/advisories/unreviewed/2022/01/GHSA-2gwv-fv77-xfgx/GHSA-2gwv-fv77-xfgx.json index 8c104c2bf32..ebf18fa9389 100644 --- a/advisories/unreviewed/2022/01/GHSA-2gwv-fv77-xfgx/GHSA-2gwv-fv77-xfgx.json +++ b/advisories/unreviewed/2022/01/GHSA-2gwv-fv77-xfgx/GHSA-2gwv-fv77-xfgx.json @@ -7,12 +7,8 @@ "CVE-2022-23015" ], "details": "On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, and 14.1.2.6-14.1.4.4, when a Client SSL profile is configured on a virtual server with Client Certificate Authentication set to request/require and Session Ticket enabled and configured, processing SSL traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-2qxj-9jmr-f734/GHSA-2qxj-9jmr-f734.json b/advisories/unreviewed/2022/01/GHSA-2qxj-9jmr-f734/GHSA-2qxj-9jmr-f734.json index 7eb665ee73d..648ac04a78e 100644 --- a/advisories/unreviewed/2022/01/GHSA-2qxj-9jmr-f734/GHSA-2qxj-9jmr-f734.json +++ b/advisories/unreviewed/2022/01/GHSA-2qxj-9jmr-f734/GHSA-2qxj-9jmr-f734.json @@ -7,12 +7,8 @@ "CVE-2021-40908" ], "details": "SQL injection vulnerability in Login.php in Sourcecodester Purchase Order Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-35f3-jq7q-h55j/GHSA-35f3-jq7q-h55j.json b/advisories/unreviewed/2022/01/GHSA-35f3-jq7q-h55j/GHSA-35f3-jq7q-h55j.json index 86998de198a..b2bf3e849c5 100644 --- a/advisories/unreviewed/2022/01/GHSA-35f3-jq7q-h55j/GHSA-35f3-jq7q-h55j.json +++ b/advisories/unreviewed/2022/01/GHSA-35f3-jq7q-h55j/GHSA-35f3-jq7q-h55j.json @@ -7,12 +7,8 @@ "CVE-2021-42168" ], "details": "Cross Site Scripting (XSS) in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) by oretnom23, allows attackers to gain the PHPSESID or other unspecified impacts via the fullname parameter to the login_registration page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-387h-m4cp-4mwp/GHSA-387h-m4cp-4mwp.json b/advisories/unreviewed/2022/01/GHSA-387h-m4cp-4mwp/GHSA-387h-m4cp-4mwp.json index 96da0b6dd04..013ad23752b 100644 --- a/advisories/unreviewed/2022/01/GHSA-387h-m4cp-4mwp/GHSA-387h-m4cp-4mwp.json +++ b/advisories/unreviewed/2022/01/GHSA-387h-m4cp-4mwp/GHSA-387h-m4cp-4mwp.json @@ -7,12 +7,8 @@ "CVE-2021-40907" ], "details": "SQL injection vulnerability in Sourcecodester Storage Unit Rental Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /storage/classes/Login.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-38xv-grg9-f228/GHSA-38xv-grg9-f228.json b/advisories/unreviewed/2022/01/GHSA-38xv-grg9-f228/GHSA-38xv-grg9-f228.json index 72f0c7f55ef..7c42fd2453c 100644 --- a/advisories/unreviewed/2022/01/GHSA-38xv-grg9-f228/GHSA-38xv-grg9-f228.json +++ b/advisories/unreviewed/2022/01/GHSA-38xv-grg9-f228/GHSA-38xv-grg9-f228.json @@ -7,12 +7,8 @@ "CVE-2020-19858" ], "details": "Platinum Upnp SDK through 1.2.0 has a directory traversal vulnerability. The attack could remote attack victim by sending http://ip:port/../privacy.avi URL to compromise a victim's privacy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-3h92-ww52-p2xf/GHSA-3h92-ww52-p2xf.json b/advisories/unreviewed/2022/01/GHSA-3h92-ww52-p2xf/GHSA-3h92-ww52-p2xf.json index 4ceaf48de68..ea94be8b792 100644 --- a/advisories/unreviewed/2022/01/GHSA-3h92-ww52-p2xf/GHSA-3h92-ww52-p2xf.json +++ b/advisories/unreviewed/2022/01/GHSA-3h92-ww52-p2xf/GHSA-3h92-ww52-p2xf.json @@ -7,12 +7,8 @@ "CVE-2021-44994" ], "details": "There is an Assertion ''JERRY_CONTEXT (jmem_heap_allocated_size) == 0'' failed at /jerry-core/jmem/jmem-heap.c in Jerryscript 3.0.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-3jr5-px2c-8j7c/GHSA-3jr5-px2c-8j7c.json b/advisories/unreviewed/2022/01/GHSA-3jr5-px2c-8j7c/GHSA-3jr5-px2c-8j7c.json index 66ae4ae9e02..c711fa58d81 100644 --- a/advisories/unreviewed/2022/01/GHSA-3jr5-px2c-8j7c/GHSA-3jr5-px2c-8j7c.json +++ b/advisories/unreviewed/2022/01/GHSA-3jr5-px2c-8j7c/GHSA-3jr5-px2c-8j7c.json @@ -7,12 +7,8 @@ "CVE-2022-23009" ], "details": "On BIG-IQ Centralized Management 8.x before 8.1.0, an authenticated administrative role user on a BIG-IQ managed BIG-IP device can access other BIG-IP devices managed by the same BIG-IQ system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-3x5m-cprf-m4f4/GHSA-3x5m-cprf-m4f4.json b/advisories/unreviewed/2022/01/GHSA-3x5m-cprf-m4f4/GHSA-3x5m-cprf-m4f4.json index 618c792339c..e4b2b7e250d 100644 --- a/advisories/unreviewed/2022/01/GHSA-3x5m-cprf-m4f4/GHSA-3x5m-cprf-m4f4.json +++ b/advisories/unreviewed/2022/01/GHSA-3x5m-cprf-m4f4/GHSA-3x5m-cprf-m4f4.json @@ -7,12 +7,8 @@ "CVE-2022-23314" ], "details": "MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-3xxw-4ppg-gf75/GHSA-3xxw-4ppg-gf75.json b/advisories/unreviewed/2022/01/GHSA-3xxw-4ppg-gf75/GHSA-3xxw-4ppg-gf75.json index 1077dbdb1ae..26763452f56 100644 --- a/advisories/unreviewed/2022/01/GHSA-3xxw-4ppg-gf75/GHSA-3xxw-4ppg-gf75.json +++ b/advisories/unreviewed/2022/01/GHSA-3xxw-4ppg-gf75/GHSA-3xxw-4ppg-gf75.json @@ -7,12 +7,8 @@ "CVE-2022-23019" ], "details": "On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a message routing type virtual server is configured with both Diameter Session and Router Profiles, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-42xq-j3ww-cxh9/GHSA-42xq-j3ww-cxh9.json b/advisories/unreviewed/2022/01/GHSA-42xq-j3ww-cxh9/GHSA-42xq-j3ww-cxh9.json index 689ab082fcb..32b52558d8f 100644 --- a/advisories/unreviewed/2022/01/GHSA-42xq-j3ww-cxh9/GHSA-42xq-j3ww-cxh9.json +++ b/advisories/unreviewed/2022/01/GHSA-42xq-j3ww-cxh9/GHSA-42xq-j3ww-cxh9.json @@ -7,12 +7,8 @@ "CVE-2022-23026" ], "details": "On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, an authenticated user with low privileges, such as a guest, can upload data using an undisclosed REST endpoint causing an increase in disk resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-4392-jjcv-v827/GHSA-4392-jjcv-v827.json b/advisories/unreviewed/2022/01/GHSA-4392-jjcv-v827/GHSA-4392-jjcv-v827.json index 9b5e7f73f32..0fd2fab865f 100644 --- a/advisories/unreviewed/2022/01/GHSA-4392-jjcv-v827/GHSA-4392-jjcv-v827.json +++ b/advisories/unreviewed/2022/01/GHSA-4392-jjcv-v827/GHSA-4392-jjcv-v827.json @@ -7,12 +7,8 @@ "CVE-2021-46198" ], "details": "An SQL Injection vulnerability exists in Sourceodester Courier Management System 1.0 via the email parameter in /cms/ajax.php app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-43m3-7v7r-4vh7/GHSA-43m3-7v7r-4vh7.json b/advisories/unreviewed/2022/01/GHSA-43m3-7v7r-4vh7/GHSA-43m3-7v7r-4vh7.json index 7ddb865f3c4..f421450179d 100644 --- a/advisories/unreviewed/2022/01/GHSA-43m3-7v7r-4vh7/GHSA-43m3-7v7r-4vh7.json +++ b/advisories/unreviewed/2022/01/GHSA-43m3-7v7r-4vh7/GHSA-43m3-7v7r-4vh7.json @@ -7,12 +7,8 @@ "CVE-2021-45802" ], "details": "MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-4f8x-4r4g-29qq/GHSA-4f8x-4r4g-29qq.json b/advisories/unreviewed/2022/01/GHSA-4f8x-4r4g-29qq/GHSA-4f8x-4r4g-29qq.json index 5fdea33e2ff..f36239f0762 100644 --- a/advisories/unreviewed/2022/01/GHSA-4f8x-4r4g-29qq/GHSA-4f8x-4r4g-29qq.json +++ b/advisories/unreviewed/2022/01/GHSA-4f8x-4r4g-29qq/GHSA-4f8x-4r4g-29qq.json @@ -7,12 +7,8 @@ "CVE-2021-46475" ], "details": "Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsi_ArraySliceCmd in src/jsiArray.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-4gv3-7ccc-5mmq/GHSA-4gv3-7ccc-5mmq.json b/advisories/unreviewed/2022/01/GHSA-4gv3-7ccc-5mmq/GHSA-4gv3-7ccc-5mmq.json index 052dd5ece40..f598af7f195 100644 --- a/advisories/unreviewed/2022/01/GHSA-4gv3-7ccc-5mmq/GHSA-4gv3-7ccc-5mmq.json +++ b/advisories/unreviewed/2022/01/GHSA-4gv3-7ccc-5mmq/GHSA-4gv3-7ccc-5mmq.json @@ -7,12 +7,8 @@ "CVE-2022-23363" ], "details": "Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-4h5h-9xmm-3vcw/GHSA-4h5h-9xmm-3vcw.json b/advisories/unreviewed/2022/01/GHSA-4h5h-9xmm-3vcw/GHSA-4h5h-9xmm-3vcw.json index 7bfa8151f1d..f42848d23ee 100644 --- a/advisories/unreviewed/2022/01/GHSA-4h5h-9xmm-3vcw/GHSA-4h5h-9xmm-3vcw.json +++ b/advisories/unreviewed/2022/01/GHSA-4h5h-9xmm-3vcw/GHSA-4h5h-9xmm-3vcw.json @@ -7,12 +7,8 @@ "CVE-2022-23023" ], "details": "On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, and BIG-IQ all versions of 8.x and 7.x, undisclosed requests by an authenticated iControl REST user can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-4mvv-qq42-r8px/GHSA-4mvv-qq42-r8px.json b/advisories/unreviewed/2022/01/GHSA-4mvv-qq42-r8px/GHSA-4mvv-qq42-r8px.json index 6517aa626c5..36208e8fca8 100644 --- a/advisories/unreviewed/2022/01/GHSA-4mvv-qq42-r8px/GHSA-4mvv-qq42-r8px.json +++ b/advisories/unreviewed/2022/01/GHSA-4mvv-qq42-r8px/GHSA-4mvv-qq42-r8px.json @@ -7,12 +7,8 @@ "CVE-2022-23016" ], "details": "On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP SSL Forward Proxy with TLS 1.3 is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-4v9q-rjxq-3952/GHSA-4v9q-rjxq-3952.json b/advisories/unreviewed/2022/01/GHSA-4v9q-rjxq-3952/GHSA-4v9q-rjxq-3952.json index 0e8bae30b44..2e7178368a3 100644 --- a/advisories/unreviewed/2022/01/GHSA-4v9q-rjxq-3952/GHSA-4v9q-rjxq-3952.json +++ b/advisories/unreviewed/2022/01/GHSA-4v9q-rjxq-3952/GHSA-4v9q-rjxq-3952.json @@ -7,12 +7,8 @@ "CVE-2021-24423" ], "details": "The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-4vw4-hr9f-mq5c/GHSA-4vw4-hr9f-mq5c.json b/advisories/unreviewed/2022/01/GHSA-4vw4-hr9f-mq5c/GHSA-4vw4-hr9f-mq5c.json index ec343293e3a..285b13358bb 100644 --- a/advisories/unreviewed/2022/01/GHSA-4vw4-hr9f-mq5c/GHSA-4vw4-hr9f-mq5c.json +++ b/advisories/unreviewed/2022/01/GHSA-4vw4-hr9f-mq5c/GHSA-4vw4-hr9f-mq5c.json @@ -7,12 +7,8 @@ "CVE-2021-46201" ], "details": "An SQL Injection vulnerability exists in Sourcecodester Online Resort Management System 1.0 via the id parameterv in /orms/ node.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-4wcp-h664-5xc6/GHSA-4wcp-h664-5xc6.json b/advisories/unreviewed/2022/01/GHSA-4wcp-h664-5xc6/GHSA-4wcp-h664-5xc6.json index fde5e29cb01..6011f78c0d6 100644 --- a/advisories/unreviewed/2022/01/GHSA-4wcp-h664-5xc6/GHSA-4wcp-h664-5xc6.json +++ b/advisories/unreviewed/2022/01/GHSA-4wcp-h664-5xc6/GHSA-4wcp-h664-5xc6.json @@ -7,12 +7,8 @@ "CVE-2021-25074" ], "details": "The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-54p3-947h-6fpr/GHSA-54p3-947h-6fpr.json b/advisories/unreviewed/2022/01/GHSA-54p3-947h-6fpr/GHSA-54p3-947h-6fpr.json index 5cb91b79c2d..54de72d745c 100644 --- a/advisories/unreviewed/2022/01/GHSA-54p3-947h-6fpr/GHSA-54p3-947h-6fpr.json +++ b/advisories/unreviewed/2022/01/GHSA-54p3-947h-6fpr/GHSA-54p3-947h-6fpr.json @@ -7,12 +7,8 @@ "CVE-2022-0326" ], "details": "NULL Pointer Dereference in Homebrew mruby prior to 3.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-555p-jhmj-xhrc/GHSA-555p-jhmj-xhrc.json b/advisories/unreviewed/2022/01/GHSA-555p-jhmj-xhrc/GHSA-555p-jhmj-xhrc.json index 389c3971da1..1285092da64 100644 --- a/advisories/unreviewed/2022/01/GHSA-555p-jhmj-xhrc/GHSA-555p-jhmj-xhrc.json +++ b/advisories/unreviewed/2022/01/GHSA-555p-jhmj-xhrc/GHSA-555p-jhmj-xhrc.json @@ -7,12 +7,8 @@ "CVE-2021-24976" ], "details": "The Smart SEO Tool WordPress plugin before 3.0.6 does not sanitise and escape the search parameter before outputting it back in an attribute when the TDK optimisation setting is enabled, leading to a Reflected Cross-Site Scripting", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-57q9-jqvx-2qj7/GHSA-57q9-jqvx-2qj7.json b/advisories/unreviewed/2022/01/GHSA-57q9-jqvx-2qj7/GHSA-57q9-jqvx-2qj7.json index c74dc24ac97..599b25585d7 100644 --- a/advisories/unreviewed/2022/01/GHSA-57q9-jqvx-2qj7/GHSA-57q9-jqvx-2qj7.json +++ b/advisories/unreviewed/2022/01/GHSA-57q9-jqvx-2qj7/GHSA-57q9-jqvx-2qj7.json @@ -7,12 +7,8 @@ "CVE-2021-25083" ], "details": "The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-58fg-5cpg-7jjv/GHSA-58fg-5cpg-7jjv.json b/advisories/unreviewed/2022/01/GHSA-58fg-5cpg-7jjv/GHSA-58fg-5cpg-7jjv.json index 895b2cab725..ba412d19389 100644 --- a/advisories/unreviewed/2022/01/GHSA-58fg-5cpg-7jjv/GHSA-58fg-5cpg-7jjv.json +++ b/advisories/unreviewed/2022/01/GHSA-58fg-5cpg-7jjv/GHSA-58fg-5cpg-7jjv.json @@ -7,12 +7,8 @@ "CVE-2021-24696" ], "details": "The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-5pmg-vf2j-3wp3/GHSA-5pmg-vf2j-3wp3.json b/advisories/unreviewed/2022/01/GHSA-5pmg-vf2j-3wp3/GHSA-5pmg-vf2j-3wp3.json index 363f8c7299c..c42a6750454 100644 --- a/advisories/unreviewed/2022/01/GHSA-5pmg-vf2j-3wp3/GHSA-5pmg-vf2j-3wp3.json +++ b/advisories/unreviewed/2022/01/GHSA-5pmg-vf2j-3wp3/GHSA-5pmg-vf2j-3wp3.json @@ -7,12 +7,8 @@ "CVE-2021-25080" ], "details": "The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-5w3r-m428-9f9g/GHSA-5w3r-m428-9f9g.json b/advisories/unreviewed/2022/01/GHSA-5w3r-m428-9f9g/GHSA-5w3r-m428-9f9g.json index d3a6a675706..f2acd7a7085 100644 --- a/advisories/unreviewed/2022/01/GHSA-5w3r-m428-9f9g/GHSA-5w3r-m428-9f9g.json +++ b/advisories/unreviewed/2022/01/GHSA-5w3r-m428-9f9g/GHSA-5w3r-m428-9f9g.json @@ -7,12 +7,8 @@ "CVE-2022-23025" ], "details": "On BIG-IP version 16.1.x before 16.1.1, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, when a SIP ALG profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-5w6q-xrqg-g6cg/GHSA-5w6q-xrqg-g6cg.json b/advisories/unreviewed/2022/01/GHSA-5w6q-xrqg-g6cg/GHSA-5w6q-xrqg-g6cg.json index 3634ecacf46..984ee45ffd7 100644 --- a/advisories/unreviewed/2022/01/GHSA-5w6q-xrqg-g6cg/GHSA-5w6q-xrqg-g6cg.json +++ b/advisories/unreviewed/2022/01/GHSA-5w6q-xrqg-g6cg/GHSA-5w6q-xrqg-g6cg.json @@ -7,12 +7,8 @@ "CVE-2021-25015" ], "details": "The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the history dashboard page, leading to a Reflected Cross-Site Scripting issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-5xgj-6r9f-ph47/GHSA-5xgj-6r9f-ph47.json b/advisories/unreviewed/2022/01/GHSA-5xgj-6r9f-ph47/GHSA-5xgj-6r9f-ph47.json index 8eae73a2076..4f63a80710d 100644 --- a/advisories/unreviewed/2022/01/GHSA-5xgj-6r9f-ph47/GHSA-5xgj-6r9f-ph47.json +++ b/advisories/unreviewed/2022/01/GHSA-5xgj-6r9f-ph47/GHSA-5xgj-6r9f-ph47.json @@ -7,12 +7,8 @@ "CVE-2021-46482" ], "details": "Jsish v3.5.0 was discovered to contain a heap buffer overflow via NumberConstructor at src/jsiNumber.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-6328-q24x-5xmf/GHSA-6328-q24x-5xmf.json b/advisories/unreviewed/2022/01/GHSA-6328-q24x-5xmf/GHSA-6328-q24x-5xmf.json index 7217ea85979..1e8497474ab 100644 --- a/advisories/unreviewed/2022/01/GHSA-6328-q24x-5xmf/GHSA-6328-q24x-5xmf.json +++ b/advisories/unreviewed/2022/01/GHSA-6328-q24x-5xmf/GHSA-6328-q24x-5xmf.json @@ -7,12 +7,8 @@ "CVE-2022-22554" ], "details": "Dell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local attacker with user privleges could potentially exploit this vulnerability leading to the disclosure of user passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-64j4-qxf4-rh6w/GHSA-64j4-qxf4-rh6w.json b/advisories/unreviewed/2022/01/GHSA-64j4-qxf4-rh6w/GHSA-64j4-qxf4-rh6w.json index 51dce85fe9c..941512dcf87 100644 --- a/advisories/unreviewed/2022/01/GHSA-64j4-qxf4-rh6w/GHSA-64j4-qxf4-rh6w.json +++ b/advisories/unreviewed/2022/01/GHSA-64j4-qxf4-rh6w/GHSA-64j4-qxf4-rh6w.json @@ -7,12 +7,8 @@ "CVE-2021-43394" ], "details": "Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of an Authentication Algorithm. An LDAP password is not properly validated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-69h6-vqxf-rc54/GHSA-69h6-vqxf-rc54.json b/advisories/unreviewed/2022/01/GHSA-69h6-vqxf-rc54/GHSA-69h6-vqxf-rc54.json index 6097f82c561..050a728b752 100644 --- a/advisories/unreviewed/2022/01/GHSA-69h6-vqxf-rc54/GHSA-69h6-vqxf-rc54.json +++ b/advisories/unreviewed/2022/01/GHSA-69h6-vqxf-rc54/GHSA-69h6-vqxf-rc54.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-6f8p-g935-8f29/GHSA-6f8p-g935-8f29.json b/advisories/unreviewed/2022/01/GHSA-6f8p-g935-8f29/GHSA-6f8p-g935-8f29.json index 687ae52a3ee..6cd267f90c7 100644 --- a/advisories/unreviewed/2022/01/GHSA-6f8p-g935-8f29/GHSA-6f8p-g935-8f29.json +++ b/advisories/unreviewed/2022/01/GHSA-6f8p-g935-8f29/GHSA-6f8p-g935-8f29.json @@ -7,12 +7,8 @@ "CVE-2021-44123" ], "details": "SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-6hx8-38qq-7423/GHSA-6hx8-38qq-7423.json b/advisories/unreviewed/2022/01/GHSA-6hx8-38qq-7423/GHSA-6hx8-38qq-7423.json index ab9578c7278..9fd8fa1ee26 100644 --- a/advisories/unreviewed/2022/01/GHSA-6hx8-38qq-7423/GHSA-6hx8-38qq-7423.json +++ b/advisories/unreviewed/2022/01/GHSA-6hx8-38qq-7423/GHSA-6hx8-38qq-7423.json @@ -7,12 +7,8 @@ "CVE-2021-24694" ], "details": "The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) \"color\" or \"css_class\" argument of sdm_download shortcode, 2) \"class\" or \"placeholder\" argument of sdm_search_form shortcode.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-6j94-pvhj-7f99/GHSA-6j94-pvhj-7f99.json b/advisories/unreviewed/2022/01/GHSA-6j94-pvhj-7f99/GHSA-6j94-pvhj-7f99.json index 8ae086d942c..f23b14fb2f3 100644 --- a/advisories/unreviewed/2022/01/GHSA-6j94-pvhj-7f99/GHSA-6j94-pvhj-7f99.json +++ b/advisories/unreviewed/2022/01/GHSA-6j94-pvhj-7f99/GHSA-6j94-pvhj-7f99.json @@ -7,12 +7,8 @@ "CVE-2022-23031" ], "details": "On BIG-IP FPS, ASM, and Advanced WAF versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, and 14.1.x before 14.1.4.4, an XML External Entity (XXE) vulnerability exists in an undisclosed page of the F5 Advanced Web Application Firewall (Advanced WAF) and BIG-IP ASM Traffic Management User Interface (TMUI), also referred to as the Configuration utility, that allows an authenticated high-privileged attacker to read local files and force BIG-IP to send HTTP requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-6w93-9q6p-694x/GHSA-6w93-9q6p-694x.json b/advisories/unreviewed/2022/01/GHSA-6w93-9q6p-694x/GHSA-6w93-9q6p-694x.json index 0eaaa7d5910..0d16c8a46d2 100644 --- a/advisories/unreviewed/2022/01/GHSA-6w93-9q6p-694x/GHSA-6w93-9q6p-694x.json +++ b/advisories/unreviewed/2022/01/GHSA-6w93-9q6p-694x/GHSA-6w93-9q6p-694x.json @@ -7,12 +7,8 @@ "CVE-2021-41472" ], "details": "SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-72j5-838x-5995/GHSA-72j5-838x-5995.json b/advisories/unreviewed/2022/01/GHSA-72j5-838x-5995/GHSA-72j5-838x-5995.json index 2d0f25ed758..d5f2b85d01d 100644 --- a/advisories/unreviewed/2022/01/GHSA-72j5-838x-5995/GHSA-72j5-838x-5995.json +++ b/advisories/unreviewed/2022/01/GHSA-72j5-838x-5995/GHSA-72j5-838x-5995.json @@ -7,12 +7,8 @@ "CVE-2020-17383" ], "details": "A directory traversal vulnerability on Telos Z/IP One devices through 4.0.0r grants an unauthenticated individual root level access to the device's file system. This can be used to identify configuration settings, password hashes for built-in accounts, and the cleartext password for remote configuration of the device through the WebUI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-72q7-wrfg-g824/GHSA-72q7-wrfg-g824.json b/advisories/unreviewed/2022/01/GHSA-72q7-wrfg-g824/GHSA-72q7-wrfg-g824.json index ec2054434ef..e1899b8dcaa 100644 --- a/advisories/unreviewed/2022/01/GHSA-72q7-wrfg-g824/GHSA-72q7-wrfg-g824.json +++ b/advisories/unreviewed/2022/01/GHSA-72q7-wrfg-g824/GHSA-72q7-wrfg-g824.json @@ -7,12 +7,8 @@ "CVE-2021-46474" ], "details": "Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiEvalCodeSub in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-785g-rp7v-287f/GHSA-785g-rp7v-287f.json b/advisories/unreviewed/2022/01/GHSA-785g-rp7v-287f/GHSA-785g-rp7v-287f.json index 16b0de83d7c..c2c3e91a3e0 100644 --- a/advisories/unreviewed/2022/01/GHSA-785g-rp7v-287f/GHSA-785g-rp7v-287f.json +++ b/advisories/unreviewed/2022/01/GHSA-785g-rp7v-287f/GHSA-785g-rp7v-287f.json @@ -7,12 +7,8 @@ "CVE-2021-46118" ], "details": "jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-7f94-wghq-3rp7/GHSA-7f94-wghq-3rp7.json b/advisories/unreviewed/2022/01/GHSA-7f94-wghq-3rp7/GHSA-7f94-wghq-3rp7.json index 107d3ebad97..f36027e18ca 100644 --- a/advisories/unreviewed/2022/01/GHSA-7f94-wghq-3rp7/GHSA-7f94-wghq-3rp7.json +++ b/advisories/unreviewed/2022/01/GHSA-7f94-wghq-3rp7/GHSA-7f94-wghq-3rp7.json @@ -7,12 +7,8 @@ "CVE-2022-22789" ], "details": "Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and update) passwords file for all the users. The xx_users.ini file in the FormStorm folder contains usernames in cleartext and an obfuscated password. Malicious user can take over an account by replacing existing password in the file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-7j9p-4w63-5mq8/GHSA-7j9p-4w63-5mq8.json b/advisories/unreviewed/2022/01/GHSA-7j9p-4w63-5mq8/GHSA-7j9p-4w63-5mq8.json index 74328f45950..dae4d46527f 100644 --- a/advisories/unreviewed/2022/01/GHSA-7j9p-4w63-5mq8/GHSA-7j9p-4w63-5mq8.json +++ b/advisories/unreviewed/2022/01/GHSA-7j9p-4w63-5mq8/GHSA-7j9p-4w63-5mq8.json @@ -7,12 +7,8 @@ "CVE-2021-26706" ], "details": "An issue was discovered in lib_mem.c in Micrium uC/OS uC/LIB 1.38.x and 1.39.00. The following memory allocation functions do not check for integer overflow when allocating a pool whose size exceeds the address space: Mem_PoolCreate, Mem_DynPoolCreate, and Mem_DynPoolCreateHW. Because these functions use multiplication to calculate the pool sizes, the operation may cause an integer overflow if the arguments are large enough. The resulting memory pool will be smaller than expected and may be exploited by an attacker.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-7m9j-p3mv-mpfr/GHSA-7m9j-p3mv-mpfr.json b/advisories/unreviewed/2022/01/GHSA-7m9j-p3mv-mpfr/GHSA-7m9j-p3mv-mpfr.json index 425c725f090..0934bd971c3 100644 --- a/advisories/unreviewed/2022/01/GHSA-7m9j-p3mv-mpfr/GHSA-7m9j-p3mv-mpfr.json +++ b/advisories/unreviewed/2022/01/GHSA-7m9j-p3mv-mpfr/GHSA-7m9j-p3mv-mpfr.json @@ -7,12 +7,8 @@ "CVE-2021-25031" ], "details": "The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7.1 does not escape the effects parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-7pwr-5hfg-qhv4/GHSA-7pwr-5hfg-qhv4.json b/advisories/unreviewed/2022/01/GHSA-7pwr-5hfg-qhv4/GHSA-7pwr-5hfg-qhv4.json index d1489a23ac8..a4371dff99f 100644 --- a/advisories/unreviewed/2022/01/GHSA-7pwr-5hfg-qhv4/GHSA-7pwr-5hfg-qhv4.json +++ b/advisories/unreviewed/2022/01/GHSA-7pwr-5hfg-qhv4/GHSA-7pwr-5hfg-qhv4.json @@ -7,12 +7,8 @@ "CVE-2021-24858" ], "details": "The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before using it in a SQL statement, when retrieving the setting to edit in the admin dashboard, leading to an authenticated SQL Injection", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-7qx4-mvfm-598f/GHSA-7qx4-mvfm-598f.json b/advisories/unreviewed/2022/01/GHSA-7qx4-mvfm-598f/GHSA-7qx4-mvfm-598f.json index b766c9ee908..449702c098a 100644 --- a/advisories/unreviewed/2022/01/GHSA-7qx4-mvfm-598f/GHSA-7qx4-mvfm-598f.json +++ b/advisories/unreviewed/2022/01/GHSA-7qx4-mvfm-598f/GHSA-7qx4-mvfm-598f.json @@ -7,12 +7,8 @@ "CVE-2021-46481" ], "details": "Jsish v3.5.0 was discovered to contain a memory leak via linenoise at src/linenoise.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-7r8m-pjrv-v5hx/GHSA-7r8m-pjrv-v5hx.json b/advisories/unreviewed/2022/01/GHSA-7r8m-pjrv-v5hx/GHSA-7r8m-pjrv-v5hx.json index 4c842a7a617..2aea80fb8cb 100644 --- a/advisories/unreviewed/2022/01/GHSA-7r8m-pjrv-v5hx/GHSA-7r8m-pjrv-v5hx.json +++ b/advisories/unreviewed/2022/01/GHSA-7r8m-pjrv-v5hx/GHSA-7r8m-pjrv-v5hx.json @@ -7,12 +7,8 @@ "CVE-2022-23014" ], "details": "On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP APM portal access is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-7vm3-67hm-9frc/GHSA-7vm3-67hm-9frc.json b/advisories/unreviewed/2022/01/GHSA-7vm3-67hm-9frc/GHSA-7vm3-67hm-9frc.json index d6e37ec896b..59327fac854 100644 --- a/advisories/unreviewed/2022/01/GHSA-7vm3-67hm-9frc/GHSA-7vm3-67hm-9frc.json +++ b/advisories/unreviewed/2022/01/GHSA-7vm3-67hm-9frc/GHSA-7vm3-67hm-9frc.json @@ -7,12 +7,8 @@ "CVE-2021-46086" ], "details": "xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examination system. There is an unsafe vulnerability in the functional method of submitting examination papers. An attacker can use burpuite to modify parameters in the packet to destroy real data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-7xr9-9g9p-xmfp/GHSA-7xr9-9g9p-xmfp.json b/advisories/unreviewed/2022/01/GHSA-7xr9-9g9p-xmfp/GHSA-7xr9-9g9p-xmfp.json index b5d80f41f63..e5335f4b0f4 100644 --- a/advisories/unreviewed/2022/01/GHSA-7xr9-9g9p-xmfp/GHSA-7xr9-9g9p-xmfp.json +++ b/advisories/unreviewed/2022/01/GHSA-7xr9-9g9p-xmfp/GHSA-7xr9-9g9p-xmfp.json @@ -7,12 +7,8 @@ "CVE-2021-45340" ], "details": "In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-82pr-42q2-4qr6/GHSA-82pr-42q2-4qr6.json b/advisories/unreviewed/2022/01/GHSA-82pr-42q2-4qr6/GHSA-82pr-42q2-4qr6.json index 3d4e3b6d0fe..29a09be8493 100644 --- a/advisories/unreviewed/2022/01/GHSA-82pr-42q2-4qr6/GHSA-82pr-42q2-4qr6.json +++ b/advisories/unreviewed/2022/01/GHSA-82pr-42q2-4qr6/GHSA-82pr-42q2-4qr6.json @@ -7,12 +7,8 @@ "CVE-2021-46483" ], "details": "Jsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-897q-jpg9-v6xf/GHSA-897q-jpg9-v6xf.json b/advisories/unreviewed/2022/01/GHSA-897q-jpg9-v6xf/GHSA-897q-jpg9-v6xf.json index 43cbe09a4c6..8ec6e07db70 100644 --- a/advisories/unreviewed/2022/01/GHSA-897q-jpg9-v6xf/GHSA-897q-jpg9-v6xf.json +++ b/advisories/unreviewed/2022/01/GHSA-897q-jpg9-v6xf/GHSA-897q-jpg9-v6xf.json @@ -7,12 +7,8 @@ "CVE-2021-46087" ], "details": "In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not filter the parameters submitted by the user input form, any user with background permission can affect the system security by entering malicious code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-8c4m-pxfw-44ph/GHSA-8c4m-pxfw-44ph.json b/advisories/unreviewed/2022/01/GHSA-8c4m-pxfw-44ph/GHSA-8c4m-pxfw-44ph.json index f35483d57dd..eb4828b073a 100644 --- a/advisories/unreviewed/2022/01/GHSA-8c4m-pxfw-44ph/GHSA-8c4m-pxfw-44ph.json +++ b/advisories/unreviewed/2022/01/GHSA-8c4m-pxfw-44ph/GHSA-8c4m-pxfw-44ph.json @@ -7,12 +7,8 @@ "CVE-2022-23018" ], "details": "On BIG-IP AFM version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and 13.1.x beginning in 13.1.3.4, when a virtual server is configured with both HTTP protocol security and HTTP Proxy Connect profiles, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-8gxf-rfc3-w42v/GHSA-8gxf-rfc3-w42v.json b/advisories/unreviewed/2022/01/GHSA-8gxf-rfc3-w42v/GHSA-8gxf-rfc3-w42v.json index 2d4db931e84..afd8eaf86b4 100644 --- a/advisories/unreviewed/2022/01/GHSA-8gxf-rfc3-w42v/GHSA-8gxf-rfc3-w42v.json +++ b/advisories/unreviewed/2022/01/GHSA-8gxf-rfc3-w42v/GHSA-8gxf-rfc3-w42v.json @@ -7,12 +7,8 @@ "CVE-2022-23012" ], "details": "On BIG-IP versions 15.1.x before 15.1.4.1 and 14.1.x before 14.1.4.5, when the HTTP/2 profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-8vhh-3c8h-fwc3/GHSA-8vhh-3c8h-fwc3.json b/advisories/unreviewed/2022/01/GHSA-8vhh-3c8h-fwc3/GHSA-8vhh-3c8h-fwc3.json index 55f403e8fbd..f6a63bda969 100644 --- a/advisories/unreviewed/2022/01/GHSA-8vhh-3c8h-fwc3/GHSA-8vhh-3c8h-fwc3.json +++ b/advisories/unreviewed/2022/01/GHSA-8vhh-3c8h-fwc3/GHSA-8vhh-3c8h-fwc3.json @@ -7,12 +7,8 @@ "CVE-2021-34869" ], "details": "This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate component. The issue results from the lack of proper validation of user-supplied data, which can result in an uncontrolled memory allocation. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-13797.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-8vvh-6wqm-9fpw/GHSA-8vvh-6wqm-9fpw.json b/advisories/unreviewed/2022/01/GHSA-8vvh-6wqm-9fpw/GHSA-8vvh-6wqm-9fpw.json index 5013d06a283..87ecd702afd 100644 --- a/advisories/unreviewed/2022/01/GHSA-8vvh-6wqm-9fpw/GHSA-8vvh-6wqm-9fpw.json +++ b/advisories/unreviewed/2022/01/GHSA-8vvh-6wqm-9fpw/GHSA-8vvh-6wqm-9fpw.json @@ -7,12 +7,8 @@ "CVE-2021-34867" ], "details": "This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate component. The issue results from the lack of proper validation of user-supplied data, which can result in an uncontrolled memory allocation. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-13672.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-97cq-2mrv-v5wf/GHSA-97cq-2mrv-v5wf.json b/advisories/unreviewed/2022/01/GHSA-97cq-2mrv-v5wf/GHSA-97cq-2mrv-v5wf.json index 72f86495e03..929c8af069c 100644 --- a/advisories/unreviewed/2022/01/GHSA-97cq-2mrv-v5wf/GHSA-97cq-2mrv-v5wf.json +++ b/advisories/unreviewed/2022/01/GHSA-97cq-2mrv-v5wf/GHSA-97cq-2mrv-v5wf.json @@ -7,12 +7,8 @@ "CVE-2022-23010" ], "details": "On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 profile and an HTTP profile are configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-9rv9-qv4p-8cjw/GHSA-9rv9-qv4p-8cjw.json b/advisories/unreviewed/2022/01/GHSA-9rv9-qv4p-8cjw/GHSA-9rv9-qv4p-8cjw.json index 259b5d22c30..9d89bc9ee14 100644 --- a/advisories/unreviewed/2022/01/GHSA-9rv9-qv4p-8cjw/GHSA-9rv9-qv4p-8cjw.json +++ b/advisories/unreviewed/2022/01/GHSA-9rv9-qv4p-8cjw/GHSA-9rv9-qv4p-8cjw.json @@ -7,12 +7,8 @@ "CVE-2021-46117" ], "details": "jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-9vr7-rp6q-4v56/GHSA-9vr7-rp6q-4v56.json b/advisories/unreviewed/2022/01/GHSA-9vr7-rp6q-4v56/GHSA-9vr7-rp6q-4v56.json index 4a04a23c495..195ea2ddf6c 100644 --- a/advisories/unreviewed/2022/01/GHSA-9vr7-rp6q-4v56/GHSA-9vr7-rp6q-4v56.json +++ b/advisories/unreviewed/2022/01/GHSA-9vr7-rp6q-4v56/GHSA-9vr7-rp6q-4v56.json @@ -7,12 +7,8 @@ "CVE-2021-36342" ], "details": "Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-9w9q-ccjg-h8q7/GHSA-9w9q-ccjg-h8q7.json b/advisories/unreviewed/2022/01/GHSA-9w9q-ccjg-h8q7/GHSA-9w9q-ccjg-h8q7.json index 129a4398a04..75be5463fe6 100644 --- a/advisories/unreviewed/2022/01/GHSA-9w9q-ccjg-h8q7/GHSA-9w9q-ccjg-h8q7.json +++ b/advisories/unreviewed/2022/01/GHSA-9w9q-ccjg-h8q7/GHSA-9w9q-ccjg-h8q7.json @@ -7,12 +7,8 @@ "CVE-2021-46478" ], "details": "Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiClearStack in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-c453-g432-3m38/GHSA-c453-g432-3m38.json b/advisories/unreviewed/2022/01/GHSA-c453-g432-3m38/GHSA-c453-g432-3m38.json index 74f95ff290e..bf69f73d598 100644 --- a/advisories/unreviewed/2022/01/GHSA-c453-g432-3m38/GHSA-c453-g432-3m38.json +++ b/advisories/unreviewed/2022/01/GHSA-c453-g432-3m38/GHSA-c453-g432-3m38.json @@ -7,12 +7,8 @@ "CVE-2021-45803" ], "details": "MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is added to the SQL query without additional verification when viewing reservation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-c5v3-45qp-fm5g/GHSA-c5v3-45qp-fm5g.json b/advisories/unreviewed/2022/01/GHSA-c5v3-45qp-fm5g/GHSA-c5v3-45qp-fm5g.json index 5f7ff26c5dc..9de401bb808 100644 --- a/advisories/unreviewed/2022/01/GHSA-c5v3-45qp-fm5g/GHSA-c5v3-45qp-fm5g.json +++ b/advisories/unreviewed/2022/01/GHSA-c5v3-45qp-fm5g/GHSA-c5v3-45qp-fm5g.json @@ -7,12 +7,8 @@ "CVE-2022-22893" ], "details": "Jerryscript 3.0.0 was discovered to contain a stack overflow via vm_loop.lto_priv.304 in /jerry-core/vm/vm.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-c74j-rm4q-qm76/GHSA-c74j-rm4q-qm76.json b/advisories/unreviewed/2022/01/GHSA-c74j-rm4q-qm76/GHSA-c74j-rm4q-qm76.json index 4ac066485cb..bbf1cfcea30 100644 --- a/advisories/unreviewed/2022/01/GHSA-c74j-rm4q-qm76/GHSA-c74j-rm4q-qm76.json +++ b/advisories/unreviewed/2022/01/GHSA-c74j-rm4q-qm76/GHSA-c74j-rm4q-qm76.json @@ -7,12 +7,8 @@ "CVE-2021-46085" ], "details": "OneBlog <= 2.2.8 is vulnerable to Insecure Permissions. Low level administrators can delete high-level administrators beyond their authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-c7c7-5mrx-q5c2/GHSA-c7c7-5mrx-q5c2.json b/advisories/unreviewed/2022/01/GHSA-c7c7-5mrx-q5c2/GHSA-c7c7-5mrx-q5c2.json index b086822ed34..83e6bee6940 100644 --- a/advisories/unreviewed/2022/01/GHSA-c7c7-5mrx-q5c2/GHSA-c7c7-5mrx-q5c2.json +++ b/advisories/unreviewed/2022/01/GHSA-c7c7-5mrx-q5c2/GHSA-c7c7-5mrx-q5c2.json @@ -7,12 +7,8 @@ "CVE-2021-46307" ], "details": "An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-c7wm-r82f-gmxg/GHSA-c7wm-r82f-gmxg.json b/advisories/unreviewed/2022/01/GHSA-c7wm-r82f-gmxg/GHSA-c7wm-r82f-gmxg.json index 5ef0224454b..18bad0227fb 100644 --- a/advisories/unreviewed/2022/01/GHSA-c7wm-r82f-gmxg/GHSA-c7wm-r82f-gmxg.json +++ b/advisories/unreviewed/2022/01/GHSA-c7wm-r82f-gmxg/GHSA-c7wm-r82f-gmxg.json @@ -7,12 +7,8 @@ "CVE-2022-22852" ], "details": "A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the description parameter in room_list.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-cfh2-3f5r-4vf9/GHSA-cfh2-3f5r-4vf9.json b/advisories/unreviewed/2022/01/GHSA-cfh2-3f5r-4vf9/GHSA-cfh2-3f5r-4vf9.json index 41ac08355e5..b0bf3d00026 100644 --- a/advisories/unreviewed/2022/01/GHSA-cfh2-3f5r-4vf9/GHSA-cfh2-3f5r-4vf9.json +++ b/advisories/unreviewed/2022/01/GHSA-cfh2-3f5r-4vf9/GHSA-cfh2-3f5r-4vf9.json @@ -7,12 +7,8 @@ "CVE-2021-43298" ], "details": "The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This means that an unauthenticated network attacker can brute-force the HTTP basic password, byte-by-byte, by recording the webserver's response time until the unauthorized (401) response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-cjph-qx8q-wcx4/GHSA-cjph-qx8q-wcx4.json b/advisories/unreviewed/2022/01/GHSA-cjph-qx8q-wcx4/GHSA-cjph-qx8q-wcx4.json index 42c9c6c0dae..d85ecf71019 100644 --- a/advisories/unreviewed/2022/01/GHSA-cjph-qx8q-wcx4/GHSA-cjph-qx8q-wcx4.json +++ b/advisories/unreviewed/2022/01/GHSA-cjph-qx8q-wcx4/GHSA-cjph-qx8q-wcx4.json @@ -7,12 +7,8 @@ "CVE-2021-44993" ], "details": "There is an Assertion ''ecma_is_value_boolean (base_value)'' failed at /jerry-core/ecma/operations/ecma-get-put-value.c in Jerryscript 3.0.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-cm99-ww6p-q22x/GHSA-cm99-ww6p-q22x.json b/advisories/unreviewed/2022/01/GHSA-cm99-ww6p-q22x/GHSA-cm99-ww6p-q22x.json index 5abb150dd7b..a3e53c92a65 100644 --- a/advisories/unreviewed/2022/01/GHSA-cm99-ww6p-q22x/GHSA-cm99-ww6p-q22x.json +++ b/advisories/unreviewed/2022/01/GHSA-cm99-ww6p-q22x/GHSA-cm99-ww6p-q22x.json @@ -7,12 +7,8 @@ "CVE-2022-23967" ], "details": "In TightVNC 1.3.10, there is an integer signedness error and resultant heap-based buffer overflow in InitialiseRFBConnection in rfbproto.c (for the vncviewer component). There is no check on the size given to malloc, e.g., -1 is accepted. This allocates a chunk of size zero, which will give a heap pointer. However, one can send 0xffffffff bytes of data, which can have a DoS impact or lead to remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-cpw7-7r7p-h7xh/GHSA-cpw7-7r7p-h7xh.json b/advisories/unreviewed/2022/01/GHSA-cpw7-7r7p-h7xh/GHSA-cpw7-7r7p-h7xh.json index 06d3f56018c..d6308731f82 100644 --- a/advisories/unreviewed/2022/01/GHSA-cpw7-7r7p-h7xh/GHSA-cpw7-7r7p-h7xh.json +++ b/advisories/unreviewed/2022/01/GHSA-cpw7-7r7p-h7xh/GHSA-cpw7-7r7p-h7xh.json @@ -7,12 +7,8 @@ "CVE-2022-23020" ], "details": "On BIG-IP version 16.1.x before 16.1.2, when the 'Respond on Error' setting is enabled on the Request Logging profile and configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-cqp4-9vc9-xvcp/GHSA-cqp4-9vc9-xvcp.json b/advisories/unreviewed/2022/01/GHSA-cqp4-9vc9-xvcp/GHSA-cqp4-9vc9-xvcp.json index 40d6f86c2af..37f2312d0bb 100644 --- a/advisories/unreviewed/2022/01/GHSA-cqp4-9vc9-xvcp/GHSA-cqp4-9vc9-xvcp.json +++ b/advisories/unreviewed/2022/01/GHSA-cqp4-9vc9-xvcp/GHSA-cqp4-9vc9-xvcp.json @@ -7,12 +7,8 @@ "CVE-2021-35004" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link TL-WA1201 1.0.1 Build 20200709 rel.66244(5553) wireless access points. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses. A crafted DNS message can trigger an overflow of a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-14656.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-cwww-vcw4-xq3m/GHSA-cwww-vcw4-xq3m.json b/advisories/unreviewed/2022/01/GHSA-cwww-vcw4-xq3m/GHSA-cwww-vcw4-xq3m.json index e4af16cc83f..7ffb942a1bc 100644 --- a/advisories/unreviewed/2022/01/GHSA-cwww-vcw4-xq3m/GHSA-cwww-vcw4-xq3m.json +++ b/advisories/unreviewed/2022/01/GHSA-cwww-vcw4-xq3m/GHSA-cwww-vcw4-xq3m.json @@ -7,12 +7,8 @@ "CVE-2021-43589" ], "details": "Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection Vulnerability. A locally authenticated user with high privileges may potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the Unity underlying OS, with the privileges of the vulnerable application. Exploitation may lead to an elevation of privilege.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-f6wq-qfc5-9ggf/GHSA-f6wq-qfc5-9ggf.json b/advisories/unreviewed/2022/01/GHSA-f6wq-qfc5-9ggf/GHSA-f6wq-qfc5-9ggf.json index cb605a06b0d..9739925cf62 100644 --- a/advisories/unreviewed/2022/01/GHSA-f6wq-qfc5-9ggf/GHSA-f6wq-qfc5-9ggf.json +++ b/advisories/unreviewed/2022/01/GHSA-f6wq-qfc5-9ggf/GHSA-f6wq-qfc5-9ggf.json @@ -7,12 +7,8 @@ "CVE-2022-23365" ], "details": "HMS v1.0 was discovered to contain a SQL injection vulnerability via doctorlogin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-f9qq-9hf8-mpcj/GHSA-f9qq-9hf8-mpcj.json b/advisories/unreviewed/2022/01/GHSA-f9qq-9hf8-mpcj/GHSA-f9qq-9hf8-mpcj.json index 4dfdfacbbaa..a0fbe6ce4a5 100644 --- a/advisories/unreviewed/2022/01/GHSA-f9qq-9hf8-mpcj/GHSA-f9qq-9hf8-mpcj.json +++ b/advisories/unreviewed/2022/01/GHSA-f9qq-9hf8-mpcj/GHSA-f9qq-9hf8-mpcj.json @@ -7,12 +7,8 @@ "CVE-2021-46308" ], "details": "An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-fccg-878q-pgph/GHSA-fccg-878q-pgph.json b/advisories/unreviewed/2022/01/GHSA-fccg-878q-pgph/GHSA-fccg-878q-pgph.json index 7e2421637bb..192fdeddafb 100644 --- a/advisories/unreviewed/2022/01/GHSA-fccg-878q-pgph/GHSA-fccg-878q-pgph.json +++ b/advisories/unreviewed/2022/01/GHSA-fccg-878q-pgph/GHSA-fccg-878q-pgph.json @@ -7,12 +7,8 @@ "CVE-2021-41928" ], "details": "SQL injection in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) 1.0 by oretnom23, allows attackers to execute arbitrary code via the rid parameter to the view_recipe page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-fm8r-hhjh-xqg8/GHSA-fm8r-hhjh-xqg8.json b/advisories/unreviewed/2022/01/GHSA-fm8r-hhjh-xqg8/GHSA-fm8r-hhjh-xqg8.json index 7e7ce9447b1..75f73abcd5b 100644 --- a/advisories/unreviewed/2022/01/GHSA-fm8r-hhjh-xqg8/GHSA-fm8r-hhjh-xqg8.json +++ b/advisories/unreviewed/2022/01/GHSA-fm8r-hhjh-xqg8/GHSA-fm8r-hhjh-xqg8.json @@ -7,12 +7,8 @@ "CVE-2021-25078" ], "details": "The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-fmxv-g522-c3mw/GHSA-fmxv-g522-c3mw.json b/advisories/unreviewed/2022/01/GHSA-fmxv-g522-c3mw/GHSA-fmxv-g522-c3mw.json index 9e8977b1bcb..37ea5f121f0 100644 --- a/advisories/unreviewed/2022/01/GHSA-fmxv-g522-c3mw/GHSA-fmxv-g522-c3mw.json +++ b/advisories/unreviewed/2022/01/GHSA-fmxv-g522-c3mw/GHSA-fmxv-g522-c3mw.json @@ -7,12 +7,8 @@ "CVE-2022-23013" ], "details": "On BIG-IP DNS & GTM version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-fvf3-jrrp-pm9m/GHSA-fvf3-jrrp-pm9m.json b/advisories/unreviewed/2022/01/GHSA-fvf3-jrrp-pm9m/GHSA-fvf3-jrrp-pm9m.json index 8ceeaa0c4d5..48ff925e1d0 100644 --- a/advisories/unreviewed/2022/01/GHSA-fvf3-jrrp-pm9m/GHSA-fvf3-jrrp-pm9m.json +++ b/advisories/unreviewed/2022/01/GHSA-fvf3-jrrp-pm9m/GHSA-fvf3-jrrp-pm9m.json @@ -7,12 +7,8 @@ "CVE-2021-24985" ], "details": "The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-fvjh-pxch-48xx/GHSA-fvjh-pxch-48xx.json b/advisories/unreviewed/2022/01/GHSA-fvjh-pxch-48xx/GHSA-fvjh-pxch-48xx.json index a001326b609..f36e96d7925 100644 --- a/advisories/unreviewed/2022/01/GHSA-fvjh-pxch-48xx/GHSA-fvjh-pxch-48xx.json +++ b/advisories/unreviewed/2022/01/GHSA-fvjh-pxch-48xx/GHSA-fvjh-pxch-48xx.json @@ -7,12 +7,8 @@ "CVE-2021-24965" ], "details": "The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting attacks against logged in admins", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-g4j5-9jfg-qj9h/GHSA-g4j5-9jfg-qj9h.json b/advisories/unreviewed/2022/01/GHSA-g4j5-9jfg-qj9h/GHSA-g4j5-9jfg-qj9h.json index 46a0525d00d..a6978acbb78 100644 --- a/advisories/unreviewed/2022/01/GHSA-g4j5-9jfg-qj9h/GHSA-g4j5-9jfg-qj9h.json +++ b/advisories/unreviewed/2022/01/GHSA-g4j5-9jfg-qj9h/GHSA-g4j5-9jfg-qj9h.json @@ -7,12 +7,8 @@ "CVE-2021-25045" ], "details": "The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in a SQL statement when editing a forum, leading to an SQL injection issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-g65w-52r3-4hxv/GHSA-g65w-52r3-4hxv.json b/advisories/unreviewed/2022/01/GHSA-g65w-52r3-4hxv/GHSA-g65w-52r3-4hxv.json index 4704c8e2a8d..441a6931338 100644 --- a/advisories/unreviewed/2022/01/GHSA-g65w-52r3-4hxv/GHSA-g65w-52r3-4hxv.json +++ b/advisories/unreviewed/2022/01/GHSA-g65w-52r3-4hxv/GHSA-g65w-52r3-4hxv.json @@ -7,12 +7,8 @@ "CVE-2021-24865" ], "details": "The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-g7fp-8rpj-5fj2/GHSA-g7fp-8rpj-5fj2.json b/advisories/unreviewed/2022/01/GHSA-g7fp-8rpj-5fj2/GHSA-g7fp-8rpj-5fj2.json index de1d717b4ca..999f3f8d062 100644 --- a/advisories/unreviewed/2022/01/GHSA-g7fp-8rpj-5fj2/GHSA-g7fp-8rpj-5fj2.json +++ b/advisories/unreviewed/2022/01/GHSA-g7fp-8rpj-5fj2/GHSA-g7fp-8rpj-5fj2.json @@ -7,12 +7,8 @@ "CVE-2022-23022" ], "details": "On BIG-IP version 16.1.x before 16.1.2, when an HTTP profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-gm8c-j8vr-rg4j/GHSA-gm8c-j8vr-rg4j.json b/advisories/unreviewed/2022/01/GHSA-gm8c-j8vr-rg4j/GHSA-gm8c-j8vr-rg4j.json index d17cf417eb0..60eecfbde0b 100644 --- a/advisories/unreviewed/2022/01/GHSA-gm8c-j8vr-rg4j/GHSA-gm8c-j8vr-rg4j.json +++ b/advisories/unreviewed/2022/01/GHSA-gm8c-j8vr-rg4j/GHSA-gm8c-j8vr-rg4j.json @@ -7,12 +7,8 @@ "CVE-2021-41660" ], "details": "SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-gprf-mmv8-mpjg/GHSA-gprf-mmv8-mpjg.json b/advisories/unreviewed/2022/01/GHSA-gprf-mmv8-mpjg/GHSA-gprf-mmv8-mpjg.json index f1627a51c91..0f18e44b40a 100644 --- a/advisories/unreviewed/2022/01/GHSA-gprf-mmv8-mpjg/GHSA-gprf-mmv8-mpjg.json +++ b/advisories/unreviewed/2022/01/GHSA-gprf-mmv8-mpjg/GHSA-gprf-mmv8-mpjg.json @@ -7,12 +7,8 @@ "CVE-2021-46083" ], "details": "uscat, as of 2021-12-28, is vulnerable to Cross Site Scripting (XSS) via the input box of the statistical code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-gx4g-7h78-x658/GHSA-gx4g-7h78-x658.json b/advisories/unreviewed/2022/01/GHSA-gx4g-7h78-x658/GHSA-gx4g-7h78-x658.json index 6c68d47f927..aecc78bab28 100644 --- a/advisories/unreviewed/2022/01/GHSA-gx4g-7h78-x658/GHSA-gx4g-7h78-x658.json +++ b/advisories/unreviewed/2022/01/GHSA-gx4g-7h78-x658/GHSA-gx4g-7h78-x658.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-gxp2-f7vc-93jg/GHSA-gxp2-f7vc-93jg.json b/advisories/unreviewed/2022/01/GHSA-gxp2-f7vc-93jg/GHSA-gxp2-f7vc-93jg.json index 25090d71391..a02205d5473 100644 --- a/advisories/unreviewed/2022/01/GHSA-gxp2-f7vc-93jg/GHSA-gxp2-f7vc-93jg.json +++ b/advisories/unreviewed/2022/01/GHSA-gxp2-f7vc-93jg/GHSA-gxp2-f7vc-93jg.json @@ -7,12 +7,8 @@ "CVE-2022-22851" ], "details": "A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the specialization parameter in doctors.php", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-h3pw-423v-4h5j/GHSA-h3pw-423v-4h5j.json b/advisories/unreviewed/2022/01/GHSA-h3pw-423v-4h5j/GHSA-h3pw-423v-4h5j.json index b2ce1591b7d..310aa0bc178 100644 --- a/advisories/unreviewed/2022/01/GHSA-h3pw-423v-4h5j/GHSA-h3pw-423v-4h5j.json +++ b/advisories/unreviewed/2022/01/GHSA-h3pw-423v-4h5j/GHSA-h3pw-423v-4h5j.json @@ -7,12 +7,8 @@ "CVE-2022-23030" ], "details": "On version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when the BIG-IP Virtual Edition (VE) uses the ixlv driver (which is used in SR-IOV mode and requires Intel X710/XL710/XXV710 family of network adapters on the Hypervisor) and TCP Segmentation Offload configuration is enabled, undisclosed requests may cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-h6cj-7c5m-52v5/GHSA-h6cj-7c5m-52v5.json b/advisories/unreviewed/2022/01/GHSA-h6cj-7c5m-52v5/GHSA-h6cj-7c5m-52v5.json index ff32d7e7ed9..62dfe1dbdbd 100644 --- a/advisories/unreviewed/2022/01/GHSA-h6cj-7c5m-52v5/GHSA-h6cj-7c5m-52v5.json +++ b/advisories/unreviewed/2022/01/GHSA-h6cj-7c5m-52v5/GHSA-h6cj-7c5m-52v5.json @@ -7,12 +7,8 @@ "CVE-2021-34870" ], "details": "This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_1.0.38 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP messages. The issue results from a lack of authentication required for a privileged request. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-13325.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-hhcq-vjf5-gv22/GHSA-hhcq-vjf5-gv22.json b/advisories/unreviewed/2022/01/GHSA-hhcq-vjf5-gv22/GHSA-hhcq-vjf5-gv22.json index 26d3caa3339..0cb8c8738ca 100644 --- a/advisories/unreviewed/2022/01/GHSA-hhcq-vjf5-gv22/GHSA-hhcq-vjf5-gv22.json +++ b/advisories/unreviewed/2022/01/GHSA-hhcq-vjf5-gv22/GHSA-hhcq-vjf5-gv22.json @@ -7,12 +7,8 @@ "CVE-2021-25062" ], "details": "The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-hjqh-wfr8-g74q/GHSA-hjqh-wfr8-g74q.json b/advisories/unreviewed/2022/01/GHSA-hjqh-wfr8-g74q/GHSA-hjqh-wfr8-g74q.json index 14a9a3f77fd..a59d87623a9 100644 --- a/advisories/unreviewed/2022/01/GHSA-hjqh-wfr8-g74q/GHSA-hjqh-wfr8-g74q.json +++ b/advisories/unreviewed/2022/01/GHSA-hjqh-wfr8-g74q/GHSA-hjqh-wfr8-g74q.json @@ -7,12 +7,8 @@ "CVE-2021-41930" ], "details": "Cross site scripting (XSS) vulnerability in Sourcecodester Online Covid Vaccination Scheduler System v1 by oretnom23, allows attackers to execute arbitrary code via the lid parameter to /scheduler/addSchedule.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-hjwv-27qh-x9j5/GHSA-hjwv-27qh-x9j5.json b/advisories/unreviewed/2022/01/GHSA-hjwv-27qh-x9j5/GHSA-hjwv-27qh-x9j5.json index 92d08582d55..9cdfdae7251 100644 --- a/advisories/unreviewed/2022/01/GHSA-hjwv-27qh-x9j5/GHSA-hjwv-27qh-x9j5.json +++ b/advisories/unreviewed/2022/01/GHSA-hjwv-27qh-x9j5/GHSA-hjwv-27qh-x9j5.json @@ -7,12 +7,8 @@ "CVE-2022-23011" ], "details": "On certain hardware BIG-IP platforms, in version 15.1.x before 15.1.4 and 14.1.x before 14.1.3, virtual servers may stop responding while processing TCP traffic due to an issue in the SYN Cookie Protection feature. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-hm9p-f2cp-2w64/GHSA-hm9p-f2cp-2w64.json b/advisories/unreviewed/2022/01/GHSA-hm9p-f2cp-2w64/GHSA-hm9p-f2cp-2w64.json index f48083fb186..1ef7738bc96 100644 --- a/advisories/unreviewed/2022/01/GHSA-hm9p-f2cp-2w64/GHSA-hm9p-f2cp-2w64.json +++ b/advisories/unreviewed/2022/01/GHSA-hm9p-f2cp-2w64/GHSA-hm9p-f2cp-2w64.json @@ -7,12 +7,8 @@ "CVE-2021-46114" ], "details": "jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-hrv9-mrpf-2hcj/GHSA-hrv9-mrpf-2hcj.json b/advisories/unreviewed/2022/01/GHSA-hrv9-mrpf-2hcj/GHSA-hrv9-mrpf-2hcj.json index 4c457bbc263..25ddd4bb322 100644 --- a/advisories/unreviewed/2022/01/GHSA-hrv9-mrpf-2hcj/GHSA-hrv9-mrpf-2hcj.json +++ b/advisories/unreviewed/2022/01/GHSA-hrv9-mrpf-2hcj/GHSA-hrv9-mrpf-2hcj.json @@ -7,12 +7,8 @@ "CVE-2022-23029" ], "details": "On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-hx6g-qw96-p774/GHSA-hx6g-qw96-p774.json b/advisories/unreviewed/2022/01/GHSA-hx6g-qw96-p774/GHSA-hx6g-qw96-p774.json index 67aa4de265e..f2b13845922 100644 --- a/advisories/unreviewed/2022/01/GHSA-hx6g-qw96-p774/GHSA-hx6g-qw96-p774.json +++ b/advisories/unreviewed/2022/01/GHSA-hx6g-qw96-p774/GHSA-hx6g-qw96-p774.json @@ -7,12 +7,8 @@ "CVE-2022-22895" ], "details": "Jerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via ecma_utf8_string_to_number_by_radix in /jerry-core/ecma/base/ecma-helpers-conversion.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-hxm9-jr99-gcm5/GHSA-hxm9-jr99-gcm5.json b/advisories/unreviewed/2022/01/GHSA-hxm9-jr99-gcm5/GHSA-hxm9-jr99-gcm5.json index d2864250664..12a1c5e6094 100644 --- a/advisories/unreviewed/2022/01/GHSA-hxm9-jr99-gcm5/GHSA-hxm9-jr99-gcm5.json +++ b/advisories/unreviewed/2022/01/GHSA-hxm9-jr99-gcm5/GHSA-hxm9-jr99-gcm5.json @@ -7,12 +7,8 @@ "CVE-2021-43420" ], "details": "SQL injection vulnerability in Login.php in Sourcecodester Online Payment Hub v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-j3hm-7vj4-2c85/GHSA-j3hm-7vj4-2c85.json b/advisories/unreviewed/2022/01/GHSA-j3hm-7vj4-2c85/GHSA-j3hm-7vj4-2c85.json index 0fe7f174101..03ca960977a 100644 --- a/advisories/unreviewed/2022/01/GHSA-j3hm-7vj4-2c85/GHSA-j3hm-7vj4-2c85.json +++ b/advisories/unreviewed/2022/01/GHSA-j3hm-7vj4-2c85/GHSA-j3hm-7vj4-2c85.json @@ -7,12 +7,8 @@ "CVE-2021-41471" ], "details": "SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the email and Password parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-j64f-pwh4-gjqv/GHSA-j64f-pwh4-gjqv.json b/advisories/unreviewed/2022/01/GHSA-j64f-pwh4-gjqv/GHSA-j64f-pwh4-gjqv.json index abbfd5dbb28..4d7d6814a02 100644 --- a/advisories/unreviewed/2022/01/GHSA-j64f-pwh4-gjqv/GHSA-j64f-pwh4-gjqv.json +++ b/advisories/unreviewed/2022/01/GHSA-j64f-pwh4-gjqv/GHSA-j64f-pwh4-gjqv.json @@ -7,12 +7,8 @@ "CVE-2022-23028" ], "details": "On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when global AFM SYN cookie protection (TCP Half Open flood vector) is activated in the AFM Device Dos or DOS profile, certain types of TCP connections will fail. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-j79x-9j6v-g6m3/GHSA-j79x-9j6v-g6m3.json b/advisories/unreviewed/2022/01/GHSA-j79x-9j6v-g6m3/GHSA-j79x-9j6v-g6m3.json index bec4449b2a6..a1f74f3baa0 100644 --- a/advisories/unreviewed/2022/01/GHSA-j79x-9j6v-g6m3/GHSA-j79x-9j6v-g6m3.json +++ b/advisories/unreviewed/2022/01/GHSA-j79x-9j6v-g6m3/GHSA-j79x-9j6v-g6m3.json @@ -7,12 +7,8 @@ "CVE-2021-25017" ], "details": "The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-jf9r-rrpf-48jq/GHSA-jf9r-rrpf-48jq.json b/advisories/unreviewed/2022/01/GHSA-jf9r-rrpf-48jq/GHSA-jf9r-rrpf-48jq.json index 626a8cbab0b..adb9d296382 100644 --- a/advisories/unreviewed/2022/01/GHSA-jf9r-rrpf-48jq/GHSA-jf9r-rrpf-48jq.json +++ b/advisories/unreviewed/2022/01/GHSA-jf9r-rrpf-48jq/GHSA-jf9r-rrpf-48jq.json @@ -7,12 +7,8 @@ "CVE-2021-29845" ], "details": "IBM Security Guardium Insights 3.0 could allow an authenticated user to perform unauthorized actions due to improper input validation. IBM X-Force ID: 205255.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-jh7h-6j93-vqwx/GHSA-jh7h-6j93-vqwx.json b/advisories/unreviewed/2022/01/GHSA-jh7h-6j93-vqwx/GHSA-jh7h-6j93-vqwx.json index 02261592fe9..9047cb3d3a5 100644 --- a/advisories/unreviewed/2022/01/GHSA-jh7h-6j93-vqwx/GHSA-jh7h-6j93-vqwx.json +++ b/advisories/unreviewed/2022/01/GHSA-jh7h-6j93-vqwx/GHSA-jh7h-6j93-vqwx.json @@ -7,12 +7,8 @@ "CVE-2021-46200" ], "details": "An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-jrc6-w967-jvc8/GHSA-jrc6-w967-jvc8.json b/advisories/unreviewed/2022/01/GHSA-jrc6-w967-jvc8/GHSA-jrc6-w967-jvc8.json index 80c13450778..d2888f77759 100644 --- a/advisories/unreviewed/2022/01/GHSA-jrc6-w967-jvc8/GHSA-jrc6-w967-jvc8.json +++ b/advisories/unreviewed/2022/01/GHSA-jrc6-w967-jvc8/GHSA-jrc6-w967-jvc8.json @@ -7,12 +7,8 @@ "CVE-2021-46451" ], "details": "An SQL Injection vulnerabilty exists in Sourcecodester Online Project Time Management System 1.0 via the pid parameter in the load_file function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-m3hv-p839-hwv6/GHSA-m3hv-p839-hwv6.json b/advisories/unreviewed/2022/01/GHSA-m3hv-p839-hwv6/GHSA-m3hv-p839-hwv6.json index 2888fc299ae..b36ee3d78fc 100644 --- a/advisories/unreviewed/2022/01/GHSA-m3hv-p839-hwv6/GHSA-m3hv-p839-hwv6.json +++ b/advisories/unreviewed/2022/01/GHSA-m3hv-p839-hwv6/GHSA-m3hv-p839-hwv6.json @@ -7,12 +7,8 @@ "CVE-2021-25079" ], "details": "The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-m635-2g79-r433/GHSA-m635-2g79-r433.json b/advisories/unreviewed/2022/01/GHSA-m635-2g79-r433/GHSA-m635-2g79-r433.json index b8ae1b2aac5..37bcdaa0e65 100644 --- a/advisories/unreviewed/2022/01/GHSA-m635-2g79-r433/GHSA-m635-2g79-r433.json +++ b/advisories/unreviewed/2022/01/GHSA-m635-2g79-r433/GHSA-m635-2g79-r433.json @@ -7,12 +7,8 @@ "CVE-2021-41658" ], "details": "Cross Site Scripting (XSS) in Sourcecodester Student Quarterly Grading System by oretnom23, allows attackers to execute arbitrary code via the fullname and username parameters to the users page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-m6rx-82hw-rv4g/GHSA-m6rx-82hw-rv4g.json b/advisories/unreviewed/2022/01/GHSA-m6rx-82hw-rv4g/GHSA-m6rx-82hw-rv4g.json index 7ccab70f2e7..bcbebcc969a 100644 --- a/advisories/unreviewed/2022/01/GHSA-m6rx-82hw-rv4g/GHSA-m6rx-82hw-rv4g.json +++ b/advisories/unreviewed/2022/01/GHSA-m6rx-82hw-rv4g/GHSA-m6rx-82hw-rv4g.json @@ -7,12 +7,8 @@ "CVE-2022-23032" ], "details": "In all versions before 7.2.1.4, when proxy settings are configured in the network access resource of a BIG-IP APM system, connecting BIG-IP Edge Client on Mac and Windows is vulnerable to a DNS rebinding attack. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-m759-xq9x-mcpr/GHSA-m759-xq9x-mcpr.json b/advisories/unreviewed/2022/01/GHSA-m759-xq9x-mcpr/GHSA-m759-xq9x-mcpr.json index c747e68ac85..d9a87d02b0f 100644 --- a/advisories/unreviewed/2022/01/GHSA-m759-xq9x-mcpr/GHSA-m759-xq9x-mcpr.json +++ b/advisories/unreviewed/2022/01/GHSA-m759-xq9x-mcpr/GHSA-m759-xq9x-mcpr.json @@ -7,12 +7,8 @@ "CVE-2021-39031" ], "details": "IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 213875.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-m893-jcpr-3937/GHSA-m893-jcpr-3937.json b/advisories/unreviewed/2022/01/GHSA-m893-jcpr-3937/GHSA-m893-jcpr-3937.json index 3ea1c1573b5..4e8991eb747 100644 --- a/advisories/unreviewed/2022/01/GHSA-m893-jcpr-3937/GHSA-m893-jcpr-3937.json +++ b/advisories/unreviewed/2022/01/GHSA-m893-jcpr-3937/GHSA-m893-jcpr-3937.json @@ -7,12 +7,8 @@ "CVE-2022-22850" ], "details": "A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the description parameter in room_types.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-m9xh-h448-fgx2/GHSA-m9xh-h448-fgx2.json b/advisories/unreviewed/2022/01/GHSA-m9xh-h448-fgx2/GHSA-m9xh-h448-fgx2.json index dc64f57d318..588a0180095 100644 --- a/advisories/unreviewed/2022/01/GHSA-m9xh-h448-fgx2/GHSA-m9xh-h448-fgx2.json +++ b/advisories/unreviewed/2022/01/GHSA-m9xh-h448-fgx2/GHSA-m9xh-h448-fgx2.json @@ -7,12 +7,8 @@ "CVE-2021-43588" ], "details": "Dell EMC Data Protection Central version 19.5 contains an Improper Input Validation Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-mf96-763w-mh5v/GHSA-mf96-763w-mh5v.json b/advisories/unreviewed/2022/01/GHSA-mf96-763w-mh5v/GHSA-mf96-763w-mh5v.json index 6ae3969bbc6..c20b53bb0d6 100644 --- a/advisories/unreviewed/2022/01/GHSA-mf96-763w-mh5v/GHSA-mf96-763w-mh5v.json +++ b/advisories/unreviewed/2022/01/GHSA-mf96-763w-mh5v/GHSA-mf96-763w-mh5v.json @@ -7,12 +7,8 @@ "CVE-2021-25028" ], "details": "The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-mff7-887w-46j8/GHSA-mff7-887w-46j8.json b/advisories/unreviewed/2022/01/GHSA-mff7-887w-46j8/GHSA-mff7-887w-46j8.json index 83efd39ea2a..f76e327cfba 100644 --- a/advisories/unreviewed/2022/01/GHSA-mff7-887w-46j8/GHSA-mff7-887w-46j8.json +++ b/advisories/unreviewed/2022/01/GHSA-mff7-887w-46j8/GHSA-mff7-887w-46j8.json @@ -7,12 +7,8 @@ "CVE-2022-22894" ], "details": "Jerryscript 3.0.0 was discovered to contain a stack overflow via ecma_lcache_lookup in /jerry-core/ecma/base/ecma-lcache.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-mg2w-r86h-j6p6/GHSA-mg2w-r86h-j6p6.json b/advisories/unreviewed/2022/01/GHSA-mg2w-r86h-j6p6/GHSA-mg2w-r86h-j6p6.json index 2c1e20573ad..c4d6976165a 100644 --- a/advisories/unreviewed/2022/01/GHSA-mg2w-r86h-j6p6/GHSA-mg2w-r86h-j6p6.json +++ b/advisories/unreviewed/2022/01/GHSA-mg2w-r86h-j6p6/GHSA-mg2w-r86h-j6p6.json @@ -7,12 +7,8 @@ "CVE-2021-25035" ], "details": "The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-mg95-x73r-76mg/GHSA-mg95-x73r-76mg.json b/advisories/unreviewed/2022/01/GHSA-mg95-x73r-76mg/GHSA-mg95-x73r-76mg.json index 37be10fed0f..4402d822b51 100644 --- a/advisories/unreviewed/2022/01/GHSA-mg95-x73r-76mg/GHSA-mg95-x73r-76mg.json +++ b/advisories/unreviewed/2022/01/GHSA-mg95-x73r-76mg/GHSA-mg95-x73r-76mg.json @@ -7,12 +7,8 @@ "CVE-2021-45847" ], "details": "Several missing input validations in the 3MF parser component of Slic3r libslic3r 1.3.0 can each allow an attacker to cause an application crash using a crafted 3MF input file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-mhxx-c3gc-722v/GHSA-mhxx-c3gc-722v.json b/advisories/unreviewed/2022/01/GHSA-mhxx-c3gc-722v/GHSA-mhxx-c3gc-722v.json index 8a552061235..bcfb7bdb353 100644 --- a/advisories/unreviewed/2022/01/GHSA-mhxx-c3gc-722v/GHSA-mhxx-c3gc-722v.json +++ b/advisories/unreviewed/2022/01/GHSA-mhxx-c3gc-722v/GHSA-mhxx-c3gc-722v.json @@ -7,12 +7,8 @@ "CVE-2022-22891" ], "details": "Jerryscript 3.0.0 was discovered to contain a SEGV vulnerability via ecma_ref_object_inline in /jerry-core/ecma/base/ecma-gc.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-mmm4-rm7v-vv5f/GHSA-mmm4-rm7v-vv5f.json b/advisories/unreviewed/2022/01/GHSA-mmm4-rm7v-vv5f/GHSA-mmm4-rm7v-vv5f.json index d7de627e8e4..73b1ec56fbc 100644 --- a/advisories/unreviewed/2022/01/GHSA-mmm4-rm7v-vv5f/GHSA-mmm4-rm7v-vv5f.json +++ b/advisories/unreviewed/2022/01/GHSA-mmm4-rm7v-vv5f/GHSA-mmm4-rm7v-vv5f.json @@ -7,12 +7,8 @@ "CVE-2021-41929" ], "details": "Cross Site Scripting (XSS) in Sourcecodester The Electric Billing Management System 1.0 by oretnom23, allows attackers to execute arbitrary code via the about page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-mrjq-f7fw-fmg2/GHSA-mrjq-f7fw-fmg2.json b/advisories/unreviewed/2022/01/GHSA-mrjq-f7fw-fmg2/GHSA-mrjq-f7fw-fmg2.json index 43fa62240eb..ec4c1fb6c8f 100644 --- a/advisories/unreviewed/2022/01/GHSA-mrjq-f7fw-fmg2/GHSA-mrjq-f7fw-fmg2.json +++ b/advisories/unreviewed/2022/01/GHSA-mrjq-f7fw-fmg2/GHSA-mrjq-f7fw-fmg2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-mw2g-8699-96xp/GHSA-mw2g-8699-96xp.json b/advisories/unreviewed/2022/01/GHSA-mw2g-8699-96xp/GHSA-mw2g-8699-96xp.json index e9ffd53ea87..7daf827b664 100644 --- a/advisories/unreviewed/2022/01/GHSA-mw2g-8699-96xp/GHSA-mw2g-8699-96xp.json +++ b/advisories/unreviewed/2022/01/GHSA-mw2g-8699-96xp/GHSA-mw2g-8699-96xp.json @@ -7,12 +7,8 @@ "CVE-2022-23017" ], "details": "On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when a virtual server is configured with a DNS profile with the Rapid Response Mode setting enabled and is configured on a BIG-IP system, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-p26r-5492-x5wr/GHSA-p26r-5492-x5wr.json b/advisories/unreviewed/2022/01/GHSA-p26r-5492-x5wr/GHSA-p26r-5492-x5wr.json index 54ccfacb6ec..09f742a965e 100644 --- a/advisories/unreviewed/2022/01/GHSA-p26r-5492-x5wr/GHSA-p26r-5492-x5wr.json +++ b/advisories/unreviewed/2022/01/GHSA-p26r-5492-x5wr/GHSA-p26r-5492-x5wr.json @@ -7,12 +7,8 @@ "CVE-2021-40596" ], "details": "SQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to execute arbitrary SQL commands via the faculty_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-p2qj-27m8-pg3f/GHSA-p2qj-27m8-pg3f.json b/advisories/unreviewed/2022/01/GHSA-p2qj-27m8-pg3f/GHSA-p2qj-27m8-pg3f.json index 8d2c56653d4..b98e46357cc 100644 --- a/advisories/unreviewed/2022/01/GHSA-p2qj-27m8-pg3f/GHSA-p2qj-27m8-pg3f.json +++ b/advisories/unreviewed/2022/01/GHSA-p2qj-27m8-pg3f/GHSA-p2qj-27m8-pg3f.json @@ -7,12 +7,8 @@ "CVE-2022-22890" ], "details": "There is an Assertion 'arguments_type != SCANNER_ARGUMENTS_PRESENT && arguments_type != SCANNER_ARGUMENTS_PRESENT_NO_REG' failed at /jerry-core/parser/js/js-scanner-util.c in Jerryscript 3.0.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-p552-938q-8c73/GHSA-p552-938q-8c73.json b/advisories/unreviewed/2022/01/GHSA-p552-938q-8c73/GHSA-p552-938q-8c73.json index 8fb469ab493..21f71649824 100644 --- a/advisories/unreviewed/2022/01/GHSA-p552-938q-8c73/GHSA-p552-938q-8c73.json +++ b/advisories/unreviewed/2022/01/GHSA-p552-938q-8c73/GHSA-p552-938q-8c73.json @@ -7,12 +7,8 @@ "CVE-2021-44692" ], "details": "BuddyBoss Platform through 1.8.0 allows remote attackers to obtain the email address of each user. When creating a new user, it generates a Unique ID for their profile. This UID is their private email address with symbols removed and periods replaced with hyphens. For example. JohnDoe@example.com would become /members/johndoeexample-com and Jo.test@example.com would become /members/jo-testexample-com. The members list is available to everyone and (in a default configuration) often without authentication. It is therefore trivial to collect a list of email addresses.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-p6h3-9j5h-45m8/GHSA-p6h3-9j5h-45m8.json b/advisories/unreviewed/2022/01/GHSA-p6h3-9j5h-45m8/GHSA-p6h3-9j5h-45m8.json index 5ef863f4d59..5601001b746 100644 --- a/advisories/unreviewed/2022/01/GHSA-p6h3-9j5h-45m8/GHSA-p6h3-9j5h-45m8.json +++ b/advisories/unreviewed/2022/01/GHSA-p6h3-9j5h-45m8/GHSA-p6h3-9j5h-45m8.json @@ -7,12 +7,8 @@ "CVE-2021-46084" ], "details": "uscat, as of 2021-12-28, is vulnerable to Cross Site Scripting (XSS) via \"close registration information\" input box.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-p759-2vgj-jpmp/GHSA-p759-2vgj-jpmp.json b/advisories/unreviewed/2022/01/GHSA-p759-2vgj-jpmp/GHSA-p759-2vgj-jpmp.json index d5919ab777a..55a8225c1e6 100644 --- a/advisories/unreviewed/2022/01/GHSA-p759-2vgj-jpmp/GHSA-p759-2vgj-jpmp.json +++ b/advisories/unreviewed/2022/01/GHSA-p759-2vgj-jpmp/GHSA-p759-2vgj-jpmp.json @@ -7,12 +7,8 @@ "CVE-2021-45846" ], "details": "A flaw in the AMF parser of Slic3r libslic3r 1.3.0 allows an attacker to cause an application crash using a crafted AMF document, where a metadata tag lacks a \"type\" attribute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-pf8f-96rq-vxhx/GHSA-pf8f-96rq-vxhx.json b/advisories/unreviewed/2022/01/GHSA-pf8f-96rq-vxhx/GHSA-pf8f-96rq-vxhx.json index a4b0458c506..f2d285ff15b 100644 --- a/advisories/unreviewed/2022/01/GHSA-pf8f-96rq-vxhx/GHSA-pf8f-96rq-vxhx.json +++ b/advisories/unreviewed/2022/01/GHSA-pf8f-96rq-vxhx/GHSA-pf8f-96rq-vxhx.json @@ -7,12 +7,8 @@ "CVE-2021-46034" ], "details": "A problem was found in ForestBlog, as of 2021-12-29, there is a XSS vulnerability that can be injected through the nickname input box.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-pfrv-pm3h-c47p/GHSA-pfrv-pm3h-c47p.json b/advisories/unreviewed/2022/01/GHSA-pfrv-pm3h-c47p/GHSA-pfrv-pm3h-c47p.json index e1690d45d23..9a0727b7e9d 100644 --- a/advisories/unreviewed/2022/01/GHSA-pfrv-pm3h-c47p/GHSA-pfrv-pm3h-c47p.json +++ b/advisories/unreviewed/2022/01/GHSA-pfrv-pm3h-c47p/GHSA-pfrv-pm3h-c47p.json @@ -7,12 +7,8 @@ "CVE-2022-22892" ], "details": "There is an Assertion 'ecma_is_value_undefined (value) || ecma_is_value_null (value) || ecma_is_value_boolean (value) || ecma_is_value_number (value) || ecma_is_value_string (value) || ecma_is_value_bigint (value) || ecma_is_value_symbol (value) || ecma_is_value_object (value)' failed at jerry-core/ecma/base/ecma-helpers-value.c in Jerryscripts 3.0.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-pg55-hv8r-frmh/GHSA-pg55-hv8r-frmh.json b/advisories/unreviewed/2022/01/GHSA-pg55-hv8r-frmh/GHSA-pg55-hv8r-frmh.json index 3bc591d3db8..45926bd6806 100644 --- a/advisories/unreviewed/2022/01/GHSA-pg55-hv8r-frmh/GHSA-pg55-hv8r-frmh.json +++ b/advisories/unreviewed/2022/01/GHSA-pg55-hv8r-frmh/GHSA-pg55-hv8r-frmh.json @@ -7,12 +7,8 @@ "CVE-2022-22296" ], "details": "Sourcecodester Hospital's Patient Records Management System 1.0 is vulnerable to Insecure Permissions via the id parameter in manage_user endpoint. Simply change the value and data of other users can be displayed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-ph25-5x79-9jr6/GHSA-ph25-5x79-9jr6.json b/advisories/unreviewed/2022/01/GHSA-ph25-5x79-9jr6/GHSA-ph25-5x79-9jr6.json index 47e801ada4b..687305b82c4 100644 --- a/advisories/unreviewed/2022/01/GHSA-ph25-5x79-9jr6/GHSA-ph25-5x79-9jr6.json +++ b/advisories/unreviewed/2022/01/GHSA-ph25-5x79-9jr6/GHSA-ph25-5x79-9jr6.json @@ -7,12 +7,8 @@ "CVE-2021-46033" ], "details": "In ForestBlog, as of 2021-12-28, File upload can bypass verification.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-pqrf-2rwm-hmh7/GHSA-pqrf-2rwm-hmh7.json b/advisories/unreviewed/2022/01/GHSA-pqrf-2rwm-hmh7/GHSA-pqrf-2rwm-hmh7.json index b266a6d5778..387730bb0e6 100644 --- a/advisories/unreviewed/2022/01/GHSA-pqrf-2rwm-hmh7/GHSA-pqrf-2rwm-hmh7.json +++ b/advisories/unreviewed/2022/01/GHSA-pqrf-2rwm-hmh7/GHSA-pqrf-2rwm-hmh7.json @@ -7,12 +7,8 @@ "CVE-2021-41659" ], "details": "SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username or password field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-q5hg-99pq-rc8v/GHSA-q5hg-99pq-rc8v.json b/advisories/unreviewed/2022/01/GHSA-q5hg-99pq-rc8v/GHSA-q5hg-99pq-rc8v.json index 1b3441bcb1b..79bcebf4021 100644 --- a/advisories/unreviewed/2022/01/GHSA-q5hg-99pq-rc8v/GHSA-q5hg-99pq-rc8v.json +++ b/advisories/unreviewed/2022/01/GHSA-q5hg-99pq-rc8v/GHSA-q5hg-99pq-rc8v.json @@ -7,12 +7,8 @@ "CVE-2021-41598" ], "details": "A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than was displayed to the user during approval. To exploit this vulnerability, an attacker would need to create a GitHub App on the instance and have a user authorize the application through the web authentication flow. All permissions being granted would properly be shown during the first authorization, but if the user later updated the set of repositories the app was installed on after the GitHub App had configured additional user-level permissions, those additional permissions would not be displayed, leading to more permissions being granted than the user potentially intended. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.3 and was fixed in versions 3.2.5, 3.1.13, 3.0.21. This vulnerability was reported via the GitHub Bug Bounty program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-q727-99h7-2wcw/GHSA-q727-99h7-2wcw.json b/advisories/unreviewed/2022/01/GHSA-q727-99h7-2wcw/GHSA-q727-99h7-2wcw.json index e0bc3237e54..efc9232eed0 100644 --- a/advisories/unreviewed/2022/01/GHSA-q727-99h7-2wcw/GHSA-q727-99h7-2wcw.json +++ b/advisories/unreviewed/2022/01/GHSA-q727-99h7-2wcw/GHSA-q727-99h7-2wcw.json @@ -7,12 +7,8 @@ "CVE-2022-23024" ], "details": "On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.2, and all versions of 13.1.x, when the IPsec application layer gateway (ALG) logging profile is configured on an IPsec ALG virtual server, undisclosed IPsec traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-qx8q-6v87-v7f8/GHSA-qx8q-6v87-v7f8.json b/advisories/unreviewed/2022/01/GHSA-qx8q-6v87-v7f8/GHSA-qx8q-6v87-v7f8.json index 7385d28264e..bade0f07618 100644 --- a/advisories/unreviewed/2022/01/GHSA-qx8q-6v87-v7f8/GHSA-qx8q-6v87-v7f8.json +++ b/advisories/unreviewed/2022/01/GHSA-qx8q-6v87-v7f8/GHSA-qx8q-6v87-v7f8.json @@ -7,12 +7,8 @@ "CVE-2021-45380" ], "details": "AppCMS 2.0.101 has a XSS injection vulnerability in \\templates\\m\\inc_head.php", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-r5q9-m2x7-ffq7/GHSA-r5q9-m2x7-ffq7.json b/advisories/unreviewed/2022/01/GHSA-r5q9-m2x7-ffq7/GHSA-r5q9-m2x7-ffq7.json index 1a4ceb3a837..e77ed777d92 100644 --- a/advisories/unreviewed/2022/01/GHSA-r5q9-m2x7-ffq7/GHSA-r5q9-m2x7-ffq7.json +++ b/advisories/unreviewed/2022/01/GHSA-r5q9-m2x7-ffq7/GHSA-r5q9-m2x7-ffq7.json @@ -7,12 +7,8 @@ "CVE-2021-36343" ], "details": "Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-rfjg-x7jx-wfqj/GHSA-rfjg-x7jx-wfqj.json b/advisories/unreviewed/2022/01/GHSA-rfjg-x7jx-wfqj/GHSA-rfjg-x7jx-wfqj.json index e0de03bd0a8..73c1db6eee4 100644 --- a/advisories/unreviewed/2022/01/GHSA-rfjg-x7jx-wfqj/GHSA-rfjg-x7jx-wfqj.json +++ b/advisories/unreviewed/2022/01/GHSA-rfjg-x7jx-wfqj/GHSA-rfjg-x7jx-wfqj.json @@ -7,12 +7,8 @@ "CVE-2022-23364" ], "details": "HMS v1.0 was discovered to contain a SQL injection vulnerability via adminlogin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-rgw4-gm63-wqh6/GHSA-rgw4-gm63-wqh6.json b/advisories/unreviewed/2022/01/GHSA-rgw4-gm63-wqh6/GHSA-rgw4-gm63-wqh6.json index 9ed36f2e62f..9d7b881161a 100644 --- a/advisories/unreviewed/2022/01/GHSA-rgw4-gm63-wqh6/GHSA-rgw4-gm63-wqh6.json +++ b/advisories/unreviewed/2022/01/GHSA-rgw4-gm63-wqh6/GHSA-rgw4-gm63-wqh6.json @@ -7,12 +7,8 @@ "CVE-2021-46116" ], "details": "jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function through which attackers can install templates and inject some malicious code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-rh2r-r28r-f23q/GHSA-rh2r-r28r-f23q.json b/advisories/unreviewed/2022/01/GHSA-rh2r-r28r-f23q/GHSA-rh2r-r28r-f23q.json index 46c9cba7b2c..8985b47e1eb 100644 --- a/advisories/unreviewed/2022/01/GHSA-rh2r-r28r-f23q/GHSA-rh2r-r28r-f23q.json +++ b/advisories/unreviewed/2022/01/GHSA-rh2r-r28r-f23q/GHSA-rh2r-r28r-f23q.json @@ -7,12 +7,8 @@ "CVE-2021-46024" ], "details": "Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the \"id\" parameter in cart_add.php, No login is required.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-rhx8-wcjx-qf76/GHSA-rhx8-wcjx-qf76.json b/advisories/unreviewed/2022/01/GHSA-rhx8-wcjx-qf76/GHSA-rhx8-wcjx-qf76.json index 67bed522522..8acf8453dd8 100644 --- a/advisories/unreviewed/2022/01/GHSA-rhx8-wcjx-qf76/GHSA-rhx8-wcjx-qf76.json +++ b/advisories/unreviewed/2022/01/GHSA-rhx8-wcjx-qf76/GHSA-rhx8-wcjx-qf76.json @@ -7,12 +7,8 @@ "CVE-2021-35003" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer C90 1.0.6 Build 20200114 rel.73164(5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses. A crafted DNS message can trigger an overflow of a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-14655.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-rpjj-pchp-g423/GHSA-rpjj-pchp-g423.json b/advisories/unreviewed/2022/01/GHSA-rpjj-pchp-g423/GHSA-rpjj-pchp-g423.json index 82089dec821..4ca06c0a3e7 100644 --- a/advisories/unreviewed/2022/01/GHSA-rpjj-pchp-g423/GHSA-rpjj-pchp-g423.json +++ b/advisories/unreviewed/2022/01/GHSA-rpjj-pchp-g423/GHSA-rpjj-pchp-g423.json @@ -7,12 +7,8 @@ "CVE-2021-25073" ], "details": "The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, allowing attackers to make a logged in admin delete them via a CSRF attack", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-rqm3-q6wp-rx6g/GHSA-rqm3-q6wp-rx6g.json b/advisories/unreviewed/2022/01/GHSA-rqm3-q6wp-rx6g/GHSA-rqm3-q6wp-rx6g.json index 555eeb1b246..ea9e0815f07 100644 --- a/advisories/unreviewed/2022/01/GHSA-rqm3-q6wp-rx6g/GHSA-rqm3-q6wp-rx6g.json +++ b/advisories/unreviewed/2022/01/GHSA-rqm3-q6wp-rx6g/GHSA-rqm3-q6wp-rx6g.json @@ -7,12 +7,8 @@ "CVE-2021-46115" ], "details": "jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a function through which attackers can upload templates and inject some malicious code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-v25h-9x55-xfff/GHSA-v25h-9x55-xfff.json b/advisories/unreviewed/2022/01/GHSA-v25h-9x55-xfff/GHSA-v25h-9x55-xfff.json index 5fecbdbe6d5..bffe5e317bb 100644 --- a/advisories/unreviewed/2022/01/GHSA-v25h-9x55-xfff/GHSA-v25h-9x55-xfff.json +++ b/advisories/unreviewed/2022/01/GHSA-v25h-9x55-xfff/GHSA-v25h-9x55-xfff.json @@ -7,12 +7,8 @@ "CVE-2021-44992" ], "details": "There is an Assertion ''ecma_object_is_typedarray (obj_p)'' failed at /jerry-core/ecma/operations/ecma-typedarray-object.c in Jerryscript 3.0.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-v336-j6w6-qhrr/GHSA-v336-j6w6-qhrr.json b/advisories/unreviewed/2022/01/GHSA-v336-j6w6-qhrr/GHSA-v336-j6w6-qhrr.json index 75fa659278f..db7fdda7b6e 100644 --- a/advisories/unreviewed/2022/01/GHSA-v336-j6w6-qhrr/GHSA-v336-j6w6-qhrr.json +++ b/advisories/unreviewed/2022/01/GHSA-v336-j6w6-qhrr/GHSA-v336-j6w6-qhrr.json @@ -7,12 +7,8 @@ "CVE-2022-23126" ], "details": "TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and interfere with vehicle operation en route. This occurs because an attacker can leverage Grafana login access to obtain a token for Tesla API calls.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-v4gr-cw6x-c3jw/GHSA-v4gr-cw6x-c3jw.json b/advisories/unreviewed/2022/01/GHSA-v4gr-cw6x-c3jw/GHSA-v4gr-cw6x-c3jw.json index 5908aacc375..558a1d9677d 100644 --- a/advisories/unreviewed/2022/01/GHSA-v4gr-cw6x-c3jw/GHSA-v4gr-cw6x-c3jw.json +++ b/advisories/unreviewed/2022/01/GHSA-v4gr-cw6x-c3jw/GHSA-v4gr-cw6x-c3jw.json @@ -7,12 +7,8 @@ "CVE-2021-36349" ], "details": "Dell EMC Data Protection Central versions 19.5 and prior contain a Server Side Request Forgery vulnerability in the DPC DNS client processing. A remote malicious user could potentially exploit this vulnerability, allowing port scanning of external hosts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-v82p-7m9r-hmf6/GHSA-v82p-7m9r-hmf6.json b/advisories/unreviewed/2022/01/GHSA-v82p-7m9r-hmf6/GHSA-v82p-7m9r-hmf6.json index 014ad1c06ea..563040c4c0b 100644 --- a/advisories/unreviewed/2022/01/GHSA-v82p-7m9r-hmf6/GHSA-v82p-7m9r-hmf6.json +++ b/advisories/unreviewed/2022/01/GHSA-v82p-7m9r-hmf6/GHSA-v82p-7m9r-hmf6.json @@ -7,12 +7,8 @@ "CVE-2022-23027" ], "details": "On BIG-IP versions 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, 13.1.x beginning in 13.1.3.6, 12.1.5.3-12.1.6, and 11.6.5.2, when a FastL4 profile and an HTTP, FIX, and/or hash persistence profile are configured on the same virtual server, undisclosed requests can cause the virtual server to stop processing new client connections. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-vjqj-pvpp-7hh5/GHSA-vjqj-pvpp-7hh5.json b/advisories/unreviewed/2022/01/GHSA-vjqj-pvpp-7hh5/GHSA-vjqj-pvpp-7hh5.json index 30b1552430d..65e7dad8ee2 100644 --- a/advisories/unreviewed/2022/01/GHSA-vjqj-pvpp-7hh5/GHSA-vjqj-pvpp-7hh5.json +++ b/advisories/unreviewed/2022/01/GHSA-vjqj-pvpp-7hh5/GHSA-vjqj-pvpp-7hh5.json @@ -7,12 +7,8 @@ "CVE-2021-43334" ], "details": "BuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-vpr8-rx78-hh89/GHSA-vpr8-rx78-hh89.json b/advisories/unreviewed/2022/01/GHSA-vpr8-rx78-hh89/GHSA-vpr8-rx78-hh89.json index 4c4725af0d9..a03b96a4f4e 100644 --- a/advisories/unreviewed/2022/01/GHSA-vpr8-rx78-hh89/GHSA-vpr8-rx78-hh89.json +++ b/advisories/unreviewed/2022/01/GHSA-vpr8-rx78-hh89/GHSA-vpr8-rx78-hh89.json @@ -7,12 +7,8 @@ "CVE-2021-24989" ], "details": "The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-vqxh-g4gf-cp2w/GHSA-vqxh-g4gf-cp2w.json b/advisories/unreviewed/2022/01/GHSA-vqxh-g4gf-cp2w/GHSA-vqxh-g4gf-cp2w.json index f5a7dd94d6f..de0f9a9e703 100644 --- a/advisories/unreviewed/2022/01/GHSA-vqxh-g4gf-cp2w/GHSA-vqxh-g4gf-cp2w.json +++ b/advisories/unreviewed/2022/01/GHSA-vqxh-g4gf-cp2w/GHSA-vqxh-g4gf-cp2w.json @@ -7,12 +7,8 @@ "CVE-2021-40909" ], "details": "Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_name, and email parameters to /ajax_crud.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-vwrp-g292-cvrv/GHSA-vwrp-g292-cvrv.json b/advisories/unreviewed/2022/01/GHSA-vwrp-g292-cvrv/GHSA-vwrp-g292-cvrv.json index 02400917d53..c69de8e4a65 100644 --- a/advisories/unreviewed/2022/01/GHSA-vwrp-g292-cvrv/GHSA-vwrp-g292-cvrv.json +++ b/advisories/unreviewed/2022/01/GHSA-vwrp-g292-cvrv/GHSA-vwrp-g292-cvrv.json @@ -7,12 +7,8 @@ "CVE-2021-46480" ], "details": "Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiValueObjDelete in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-vwwf-8mvf-74w3/GHSA-vwwf-8mvf-74w3.json b/advisories/unreviewed/2022/01/GHSA-vwwf-8mvf-74w3/GHSA-vwwf-8mvf-74w3.json index e903b6e481b..2a178ec43b3 100644 --- a/advisories/unreviewed/2022/01/GHSA-vwwf-8mvf-74w3/GHSA-vwwf-8mvf-74w3.json +++ b/advisories/unreviewed/2022/01/GHSA-vwwf-8mvf-74w3/GHSA-vwwf-8mvf-74w3.json @@ -7,12 +7,8 @@ "CVE-2021-25008" ], "details": "The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-w343-x6rw-f2x7/GHSA-w343-x6rw-f2x7.json b/advisories/unreviewed/2022/01/GHSA-w343-x6rw-f2x7/GHSA-w343-x6rw-f2x7.json index 4eed407942c..b5e5cfb30f3 100644 --- a/advisories/unreviewed/2022/01/GHSA-w343-x6rw-f2x7/GHSA-w343-x6rw-f2x7.json +++ b/advisories/unreviewed/2022/01/GHSA-w343-x6rw-f2x7/GHSA-w343-x6rw-f2x7.json @@ -7,12 +7,8 @@ "CVE-2022-23021" ], "details": "On BIG-IP version 16.1.x before 16.1.2, when any of the following configurations are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate: HTTP redirect rule in an LTM policy, BIG-IP APM Access Profile, and Explicit HTTP Proxy in HTTP Profile. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-w5jp-93v7-x9q3/GHSA-w5jp-93v7-x9q3.json b/advisories/unreviewed/2022/01/GHSA-w5jp-93v7-x9q3/GHSA-w5jp-93v7-x9q3.json index 26c07f0f453..ead6b4cb57e 100644 --- a/advisories/unreviewed/2022/01/GHSA-w5jp-93v7-x9q3/GHSA-w5jp-93v7-x9q3.json +++ b/advisories/unreviewed/2022/01/GHSA-w5jp-93v7-x9q3/GHSA-w5jp-93v7-x9q3.json @@ -7,12 +7,8 @@ "CVE-2022-22928" ], "details": "MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-w66g-mfpq-g4x7/GHSA-w66g-mfpq-g4x7.json b/advisories/unreviewed/2022/01/GHSA-w66g-mfpq-g4x7/GHSA-w66g-mfpq-g4x7.json index 347695ba021..606a66be884 100644 --- a/advisories/unreviewed/2022/01/GHSA-w66g-mfpq-g4x7/GHSA-w66g-mfpq-g4x7.json +++ b/advisories/unreviewed/2022/01/GHSA-w66g-mfpq-g4x7/GHSA-w66g-mfpq-g4x7.json @@ -7,12 +7,8 @@ "CVE-2021-29838" ], "details": "IBM Security Guardium Insights 3.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-wj79-qqhx-jqhr/GHSA-wj79-qqhx-jqhr.json b/advisories/unreviewed/2022/01/GHSA-wj79-qqhx-jqhr/GHSA-wj79-qqhx-jqhr.json index 2bc4c92c3fd..4edb9c5f1b4 100644 --- a/advisories/unreviewed/2022/01/GHSA-wj79-qqhx-jqhr/GHSA-wj79-qqhx-jqhr.json +++ b/advisories/unreviewed/2022/01/GHSA-wj79-qqhx-jqhr/GHSA-wj79-qqhx-jqhr.json @@ -7,12 +7,8 @@ "CVE-2021-45975" ], "details": "In ListCheck.exe in Acer Care Center 4.x before 4.00.3038, a vulnerability in the loading mechanism of Windows DLLs could allow a local attacker to perform a DLL hijacking attack. This vulnerability is due to incorrect handling of directory search paths at run time. An attacker could exploit this vulnerability by placing a malicious DLL file on the targeted system. This file will execute when the vulnerable application launches. A successful exploit could allow the attacker to execute arbitrary code on the targeted system with local administrator privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-wv49-q2r3-4933/GHSA-wv49-q2r3-4933.json b/advisories/unreviewed/2022/01/GHSA-wv49-q2r3-4933/GHSA-wv49-q2r3-4933.json index 3ace7d29021..1af8e0c34a1 100644 --- a/advisories/unreviewed/2022/01/GHSA-wv49-q2r3-4933/GHSA-wv49-q2r3-4933.json +++ b/advisories/unreviewed/2022/01/GHSA-wv49-q2r3-4933/GHSA-wv49-q2r3-4933.json @@ -7,12 +7,8 @@ "CVE-2021-46477" ], "details": "Jsish v3.5.0 was discovered to contain a heap buffer overflow via RegExp_constructor in src/jsiRegexp.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-x32q-wrp4-v9x9/GHSA-x32q-wrp4-v9x9.json b/advisories/unreviewed/2022/01/GHSA-x32q-wrp4-v9x9/GHSA-x32q-wrp4-v9x9.json index 6e322a106c0..a8be4418260 100644 --- a/advisories/unreviewed/2022/01/GHSA-x32q-wrp4-v9x9/GHSA-x32q-wrp4-v9x9.json +++ b/advisories/unreviewed/2022/01/GHSA-x32q-wrp4-v9x9/GHSA-x32q-wrp4-v9x9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-x3mr-p889-7f32/GHSA-x3mr-p889-7f32.json b/advisories/unreviewed/2022/01/GHSA-x3mr-p889-7f32/GHSA-x3mr-p889-7f32.json index 0a07ce698e4..34b3b53f316 100644 --- a/advisories/unreviewed/2022/01/GHSA-x3mr-p889-7f32/GHSA-x3mr-p889-7f32.json +++ b/advisories/unreviewed/2022/01/GHSA-x3mr-p889-7f32/GHSA-x3mr-p889-7f32.json @@ -7,12 +7,8 @@ "CVE-2021-24974" ], "details": "The Product Feed PRO for WooCommerce WordPress plugin before 11.0.7 does not have authorisation and CSRF check in some of its AJAX actions, allowing any authenticated users to call then, which could lead to Stored Cross-Site Scripting issue (which will be triggered in the admin dashboard) due to the lack of escaping.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-x44j-rvwf-fj2w/GHSA-x44j-rvwf-fj2w.json b/advisories/unreviewed/2022/01/GHSA-x44j-rvwf-fj2w/GHSA-x44j-rvwf-fj2w.json index dd78db29aaf..d41450528d3 100644 --- a/advisories/unreviewed/2022/01/GHSA-x44j-rvwf-fj2w/GHSA-x44j-rvwf-fj2w.json +++ b/advisories/unreviewed/2022/01/GHSA-x44j-rvwf-fj2w/GHSA-x44j-rvwf-fj2w.json @@ -7,12 +7,8 @@ "CVE-2021-46113" ], "details": "In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-x6hf-28q4-37gq/GHSA-x6hf-28q4-37gq.json b/advisories/unreviewed/2022/01/GHSA-x6hf-28q4-37gq/GHSA-x6hf-28q4-37gq.json index a4ac8286142..40783eff77b 100644 --- a/advisories/unreviewed/2022/01/GHSA-x6hf-28q4-37gq/GHSA-x6hf-28q4-37gq.json +++ b/advisories/unreviewed/2022/01/GHSA-x6hf-28q4-37gq/GHSA-x6hf-28q4-37gq.json @@ -7,12 +7,8 @@ "CVE-2020-19860" ], "details": "When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zone file payload.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-xf28-6vg8-pmr9/GHSA-xf28-6vg8-pmr9.json b/advisories/unreviewed/2022/01/GHSA-xf28-6vg8-pmr9/GHSA-xf28-6vg8-pmr9.json index 587b8905c48..b990cb38257 100644 --- a/advisories/unreviewed/2022/01/GHSA-xf28-6vg8-pmr9/GHSA-xf28-6vg8-pmr9.json +++ b/advisories/unreviewed/2022/01/GHSA-xf28-6vg8-pmr9/GHSA-xf28-6vg8-pmr9.json @@ -7,12 +7,8 @@ "CVE-2021-40337" ], "details": "Cross-site Scripting (XSS) vulnerability in Hitachi Energy LinkOne allows an attacker that manages to exploit the vulnerability can take advantage to exploit multiple web attacks and stole sensitive information. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-xr5h-rxwf-6q73/GHSA-xr5h-rxwf-6q73.json b/advisories/unreviewed/2022/01/GHSA-xr5h-rxwf-6q73/GHSA-xr5h-rxwf-6q73.json index eb31d0460ef..fd8eb261216 100644 --- a/advisories/unreviewed/2022/01/GHSA-xr5h-rxwf-6q73/GHSA-xr5h-rxwf-6q73.json +++ b/advisories/unreviewed/2022/01/GHSA-xr5h-rxwf-6q73/GHSA-xr5h-rxwf-6q73.json @@ -7,12 +7,8 @@ "CVE-2021-34868" ], "details": "This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate component. The issue results from the lack of proper validation of user-supplied data, which can result in an uncontrolled memory allocation. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-13712.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-fcqv-r8cv-f88h/GHSA-fcqv-r8cv-f88h.json b/advisories/unreviewed/2022/02/GHSA-fcqv-r8cv-f88h/GHSA-fcqv-r8cv-f88h.json index e1285af9bb0..cfe2b7ee8a2 100644 --- a/advisories/unreviewed/2022/02/GHSA-fcqv-r8cv-f88h/GHSA-fcqv-r8cv-f88h.json +++ b/advisories/unreviewed/2022/02/GHSA-fcqv-r8cv-f88h/GHSA-fcqv-r8cv-f88h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-w6p2-hpr9-hmj8/GHSA-w6p2-hpr9-hmj8.json b/advisories/unreviewed/2022/02/GHSA-w6p2-hpr9-hmj8/GHSA-w6p2-hpr9-hmj8.json index 8ec3e78c1b0..3e48dea1c73 100644 --- a/advisories/unreviewed/2022/02/GHSA-w6p2-hpr9-hmj8/GHSA-w6p2-hpr9-hmj8.json +++ b/advisories/unreviewed/2022/02/GHSA-w6p2-hpr9-hmj8/GHSA-w6p2-hpr9-hmj8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-224m-8wrv-4v8r/GHSA-224m-8wrv-4v8r.json b/advisories/unreviewed/2022/05/GHSA-224m-8wrv-4v8r/GHSA-224m-8wrv-4v8r.json index fbf3139d420..353cd213c1e 100644 --- a/advisories/unreviewed/2022/05/GHSA-224m-8wrv-4v8r/GHSA-224m-8wrv-4v8r.json +++ b/advisories/unreviewed/2022/05/GHSA-224m-8wrv-4v8r/GHSA-224m-8wrv-4v8r.json @@ -7,12 +7,8 @@ "CVE-2010-2117" ], "details": "Mozilla Firefox 3.0.19, 3.5.x, and 3.6.x allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid (1) news:// or (2) nntp:// URIs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2592-27f9-rh84/GHSA-2592-27f9-rh84.json b/advisories/unreviewed/2022/05/GHSA-2592-27f9-rh84/GHSA-2592-27f9-rh84.json index 24bde84977f..31ed57c59fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-2592-27f9-rh84/GHSA-2592-27f9-rh84.json +++ b/advisories/unreviewed/2022/05/GHSA-2592-27f9-rh84/GHSA-2592-27f9-rh84.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-25fr-p9c4-3h4q/GHSA-25fr-p9c4-3h4q.json b/advisories/unreviewed/2022/05/GHSA-25fr-p9c4-3h4q/GHSA-25fr-p9c4-3h4q.json index 68366a0c6d7..d45124737eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-25fr-p9c4-3h4q/GHSA-25fr-p9c4-3h4q.json +++ b/advisories/unreviewed/2022/05/GHSA-25fr-p9c4-3h4q/GHSA-25fr-p9c4-3h4q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-263p-v3xc-qhqr/GHSA-263p-v3xc-qhqr.json b/advisories/unreviewed/2022/05/GHSA-263p-v3xc-qhqr/GHSA-263p-v3xc-qhqr.json index 9edc2a421c7..4c055584f44 100644 --- a/advisories/unreviewed/2022/05/GHSA-263p-v3xc-qhqr/GHSA-263p-v3xc-qhqr.json +++ b/advisories/unreviewed/2022/05/GHSA-263p-v3xc-qhqr/GHSA-263p-v3xc-qhqr.json @@ -7,12 +7,8 @@ "CVE-2015-2781" ], "details": "Cross-site scripting (XSS) vulnerability in cgi-bin/hotspotlogin.cgi in Hotspot Express hotEx Billing Manager 73 allows remote attackers to inject arbitrary web script or HTML via the reply parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26qc-f6w8-8qqq/GHSA-26qc-f6w8-8qqq.json b/advisories/unreviewed/2022/05/GHSA-26qc-f6w8-8qqq/GHSA-26qc-f6w8-8qqq.json index 88bbd1f3ec4..905e501ac59 100644 --- a/advisories/unreviewed/2022/05/GHSA-26qc-f6w8-8qqq/GHSA-26qc-f6w8-8qqq.json +++ b/advisories/unreviewed/2022/05/GHSA-26qc-f6w8-8qqq/GHSA-26qc-f6w8-8qqq.json @@ -7,12 +7,8 @@ "CVE-2010-3151" ], "details": "Untrusted search path vulnerability in Adobe On Location CS4 Build 315 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ibfs32.dll that is located in the same folder as an OLPROJ file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-27gw-h248-gvvq/GHSA-27gw-h248-gvvq.json b/advisories/unreviewed/2022/05/GHSA-27gw-h248-gvvq/GHSA-27gw-h248-gvvq.json index bac3cb15c45..b4e9a3e166e 100644 --- a/advisories/unreviewed/2022/05/GHSA-27gw-h248-gvvq/GHSA-27gw-h248-gvvq.json +++ b/advisories/unreviewed/2022/05/GHSA-27gw-h248-gvvq/GHSA-27gw-h248-gvvq.json @@ -7,12 +7,8 @@ "CVE-2015-2824" ], "details": "Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attackers to execute arbitrary SQL commands via a (1) hits[][] parameter in a sam_hits action to sam-ajax.php; the (2) cstr parameter in a load_posts action to sam-ajax-admin.php; the (3) searchTerm parameter in a load_combo_data action to sam-ajax-admin.php; or the (4) subscriber, (5) contributor, (6) author, (7) editor, (8) admin, or (9) sadmin parameter in a load_users action to sam-ajax-admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-282h-wh7g-68c6/GHSA-282h-wh7g-68c6.json b/advisories/unreviewed/2022/05/GHSA-282h-wh7g-68c6/GHSA-282h-wh7g-68c6.json index 4cf8a0f3b98..3a01f0d3e8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-282h-wh7g-68c6/GHSA-282h-wh7g-68c6.json +++ b/advisories/unreviewed/2022/05/GHSA-282h-wh7g-68c6/GHSA-282h-wh7g-68c6.json @@ -7,12 +7,8 @@ "CVE-2015-6545" ], "details": "Cross-site request forgery (CSRF) vulnerability in ajax.php in Cerb before 7.0.4 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a saveWorkerPeek action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-293m-43xj-42h4/GHSA-293m-43xj-42h4.json b/advisories/unreviewed/2022/05/GHSA-293m-43xj-42h4/GHSA-293m-43xj-42h4.json index 7d04821a7ab..c304cc82e23 100644 --- a/advisories/unreviewed/2022/05/GHSA-293m-43xj-42h4/GHSA-293m-43xj-42h4.json +++ b/advisories/unreviewed/2022/05/GHSA-293m-43xj-42h4/GHSA-293m-43xj-42h4.json @@ -7,12 +7,8 @@ "CVE-2010-2027" ], "details": "Mathematica 7, when running on Linux, allows local users to overwrite arbitrary files via a symlink attack on (1) files within /tmp/MathLink/ or (2) /tmp/fonts$$.conf.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-29f7-328x-f75h/GHSA-29f7-328x-f75h.json b/advisories/unreviewed/2022/05/GHSA-29f7-328x-f75h/GHSA-29f7-328x-f75h.json index 08118b20636..041e038b69d 100644 --- a/advisories/unreviewed/2022/05/GHSA-29f7-328x-f75h/GHSA-29f7-328x-f75h.json +++ b/advisories/unreviewed/2022/05/GHSA-29f7-328x-f75h/GHSA-29f7-328x-f75h.json @@ -7,12 +7,8 @@ "CVE-2015-8247" ], "details": "Cross-site scripting (XSS) vulnerability in synnefoclient in Synnefo Internet Management Software (IMS) 2015 allows remote attackers to inject arbitrary web script or HTML via the plan_name parameter to packagehistory/listusagesdata.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-29m6-68fv-pgx2/GHSA-29m6-68fv-pgx2.json b/advisories/unreviewed/2022/05/GHSA-29m6-68fv-pgx2/GHSA-29m6-68fv-pgx2.json index 1388e00101e..8a53d3f1d4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-29m6-68fv-pgx2/GHSA-29m6-68fv-pgx2.json +++ b/advisories/unreviewed/2022/05/GHSA-29m6-68fv-pgx2/GHSA-29m6-68fv-pgx2.json @@ -7,12 +7,8 @@ "CVE-2010-2952" ], "details": "Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-29x7-837g-j5vr/GHSA-29x7-837g-j5vr.json b/advisories/unreviewed/2022/05/GHSA-29x7-837g-j5vr/GHSA-29x7-837g-j5vr.json index 7d8c42dc320..81f4dddb399 100644 --- a/advisories/unreviewed/2022/05/GHSA-29x7-837g-j5vr/GHSA-29x7-837g-j5vr.json +++ b/advisories/unreviewed/2022/05/GHSA-29x7-837g-j5vr/GHSA-29x7-837g-j5vr.json @@ -7,12 +7,8 @@ "CVE-2015-7373" ], "details": "Cross-site scripting (XSS) vulnerability in the \"magic-macros\" feature in Revive Adserver before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via a GET parameter, which is not properly handled in a banner.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2c42-4jvc-gq6p/GHSA-2c42-4jvc-gq6p.json b/advisories/unreviewed/2022/05/GHSA-2c42-4jvc-gq6p/GHSA-2c42-4jvc-gq6p.json index 0960477a74b..ada951b21e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c42-4jvc-gq6p/GHSA-2c42-4jvc-gq6p.json +++ b/advisories/unreviewed/2022/05/GHSA-2c42-4jvc-gq6p/GHSA-2c42-4jvc-gq6p.json @@ -7,12 +7,8 @@ "CVE-2015-6923" ], "details": "The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x00000ffd ioctl call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2cph-p23w-fhfq/GHSA-2cph-p23w-fhfq.json b/advisories/unreviewed/2022/05/GHSA-2cph-p23w-fhfq/GHSA-2cph-p23w-fhfq.json index 95291ad2a82..81763e2bc3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cph-p23w-fhfq/GHSA-2cph-p23w-fhfq.json +++ b/advisories/unreviewed/2022/05/GHSA-2cph-p23w-fhfq/GHSA-2cph-p23w-fhfq.json @@ -7,12 +7,8 @@ "CVE-2015-4616" ], "details": "Directory traversal vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.2.5 for WordPress allows remote attackers to create arbitrary files via a .. (dot dot) in the map_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2cpw-8m4m-xr55/GHSA-2cpw-8m4m-xr55.json b/advisories/unreviewed/2022/05/GHSA-2cpw-8m4m-xr55/GHSA-2cpw-8m4m-xr55.json index 6726e7eb791..5647f873321 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cpw-8m4m-xr55/GHSA-2cpw-8m4m-xr55.json +++ b/advisories/unreviewed/2022/05/GHSA-2cpw-8m4m-xr55/GHSA-2cpw-8m4m-xr55.json @@ -7,12 +7,8 @@ "CVE-2010-2872" ], "details": "Adobe Shockwave Player before 11.5.8.612 does not properly validate an offset value in the pami RIFF chunk in a Director movie, which allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted movie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fmw-vp29-wcgf/GHSA-2fmw-vp29-wcgf.json b/advisories/unreviewed/2022/05/GHSA-2fmw-vp29-wcgf/GHSA-2fmw-vp29-wcgf.json index 566f96f2658..1725bca01c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fmw-vp29-wcgf/GHSA-2fmw-vp29-wcgf.json +++ b/advisories/unreviewed/2022/05/GHSA-2fmw-vp29-wcgf/GHSA-2fmw-vp29-wcgf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2g3x-26wj-3wgm/GHSA-2g3x-26wj-3wgm.json b/advisories/unreviewed/2022/05/GHSA-2g3x-26wj-3wgm/GHSA-2g3x-26wj-3wgm.json index a233235e543..0bfd7452a64 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g3x-26wj-3wgm/GHSA-2g3x-26wj-3wgm.json +++ b/advisories/unreviewed/2022/05/GHSA-2g3x-26wj-3wgm/GHSA-2g3x-26wj-3wgm.json @@ -7,12 +7,8 @@ "CVE-2010-3407" ], "details": "Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2 allows remote attackers to execute arbitrary code via a long e-mail address in an ORGANIZER:mailto header in an iCalendar calendar-invitation e-mail message, aka SPR NRBY7ZPJ9V.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2h66-v8cx-v4cx/GHSA-2h66-v8cx-v4cx.json b/advisories/unreviewed/2022/05/GHSA-2h66-v8cx-v4cx/GHSA-2h66-v8cx-v4cx.json index 7429bbe1070..0c263c2ecb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-2h66-v8cx-v4cx/GHSA-2h66-v8cx-v4cx.json +++ b/advisories/unreviewed/2022/05/GHSA-2h66-v8cx-v4cx/GHSA-2h66-v8cx-v4cx.json @@ -7,12 +7,8 @@ "CVE-2010-3463" ], "details": "Cross-site scripting (XSS) vulnerability in modules/search/search.class.php in SantaFox 2.02, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the search parameter to search.html.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2hmv-4fjm-5j4w/GHSA-2hmv-4fjm-5j4w.json b/advisories/unreviewed/2022/05/GHSA-2hmv-4fjm-5j4w/GHSA-2hmv-4fjm-5j4w.json index 51974d9e275..d48bcfb2911 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hmv-4fjm-5j4w/GHSA-2hmv-4fjm-5j4w.json +++ b/advisories/unreviewed/2022/05/GHSA-2hmv-4fjm-5j4w/GHSA-2hmv-4fjm-5j4w.json @@ -7,12 +7,8 @@ "CVE-2010-2882" ], "details": "DIRAPI.dll in Adobe Shockwave Player before 11.5.8.612 does not properly parse .dir files, which allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a malformed file containing an invalid value, as demonstrated by a value at position 0x3812 of a certain file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2jg5-qvhj-cg5g/GHSA-2jg5-qvhj-cg5g.json b/advisories/unreviewed/2022/05/GHSA-2jg5-qvhj-cg5g/GHSA-2jg5-qvhj-cg5g.json index 60017afedba..2e95bcd4689 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jg5-qvhj-cg5g/GHSA-2jg5-qvhj-cg5g.json +++ b/advisories/unreviewed/2022/05/GHSA-2jg5-qvhj-cg5g/GHSA-2jg5-qvhj-cg5g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2jm5-p544-m6xw/GHSA-2jm5-p544-m6xw.json b/advisories/unreviewed/2022/05/GHSA-2jm5-p544-m6xw/GHSA-2jm5-p544-m6xw.json index af8d8997594..3adf668563a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jm5-p544-m6xw/GHSA-2jm5-p544-m6xw.json +++ b/advisories/unreviewed/2022/05/GHSA-2jm5-p544-m6xw/GHSA-2jm5-p544-m6xw.json @@ -7,12 +7,8 @@ "CVE-2010-1523" ], "details": "Multiple heap-based buffer overflows in vp6.w5s (aka the VP6 codec) in Winamp before 5.59 Beta build 3033 might allow remote attackers to execute arbitrary code via a crafted VP6 (1) video file or (2) video stream.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2m48-jx4v-6c4h/GHSA-2m48-jx4v-6c4h.json b/advisories/unreviewed/2022/05/GHSA-2m48-jx4v-6c4h/GHSA-2m48-jx4v-6c4h.json index 94c6fb83bf8..58ff8bbebac 100644 --- a/advisories/unreviewed/2022/05/GHSA-2m48-jx4v-6c4h/GHSA-2m48-jx4v-6c4h.json +++ b/advisories/unreviewed/2022/05/GHSA-2m48-jx4v-6c4h/GHSA-2m48-jx4v-6c4h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2r97-vr7q-6pw9/GHSA-2r97-vr7q-6pw9.json b/advisories/unreviewed/2022/05/GHSA-2r97-vr7q-6pw9/GHSA-2r97-vr7q-6pw9.json index e2a87b9475c..7d2619a213d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2r97-vr7q-6pw9/GHSA-2r97-vr7q-6pw9.json +++ b/advisories/unreviewed/2022/05/GHSA-2r97-vr7q-6pw9/GHSA-2r97-vr7q-6pw9.json @@ -7,12 +7,8 @@ "CVE-2010-3275" ], "details": "libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an AMV file, related to a \"dangling pointer vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v3r-wf43-c9gh/GHSA-2v3r-wf43-c9gh.json b/advisories/unreviewed/2022/05/GHSA-2v3r-wf43-c9gh/GHSA-2v3r-wf43-c9gh.json index f3702c77346..520d0fa59b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v3r-wf43-c9gh/GHSA-2v3r-wf43-c9gh.json +++ b/advisories/unreviewed/2022/05/GHSA-2v3r-wf43-c9gh/GHSA-2v3r-wf43-c9gh.json @@ -7,12 +7,8 @@ "CVE-2015-5603" ], "details": "The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors, related to \"Velocity Template Injection Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v8h-q33q-c9qj/GHSA-2v8h-q33q-c9qj.json b/advisories/unreviewed/2022/05/GHSA-2v8h-q33q-c9qj/GHSA-2v8h-q33q-c9qj.json index 72c228354a5..f6699a8684b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v8h-q33q-c9qj/GHSA-2v8h-q33q-c9qj.json +++ b/advisories/unreviewed/2022/05/GHSA-2v8h-q33q-c9qj/GHSA-2v8h-q33q-c9qj.json @@ -7,12 +7,8 @@ "CVE-2015-5737" ], "details": "The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, (4) mdare64_52.sys, and (5) Fortishield.sys drivers in Fortinet FortiClient before 5.2.4 do not properly restrict access to the API for management of processes and the Windows registry, which allows local users to obtain a privileged handle to a PID and possibly have unspecified other impact, as demonstrated by a 0x2220c8 ioctl call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2vc8-2444-p3fm/GHSA-2vc8-2444-p3fm.json b/advisories/unreviewed/2022/05/GHSA-2vc8-2444-p3fm/GHSA-2vc8-2444-p3fm.json index 42798009a1a..eaf9f0290f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vc8-2444-p3fm/GHSA-2vc8-2444-p3fm.json +++ b/advisories/unreviewed/2022/05/GHSA-2vc8-2444-p3fm/GHSA-2vc8-2444-p3fm.json @@ -7,12 +7,8 @@ "CVE-2010-3599" ], "details": "Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect integrity and availability via unknown vectors related to Import Server. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from the original researcher that remote attackers can overwrite arbitrary files and execute arbitrary code via a full pathname in the first argument to the WriteJPG method in the NCSECWLib ActiveX control.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2vcm-2mcr-wmx7/GHSA-2vcm-2mcr-wmx7.json b/advisories/unreviewed/2022/05/GHSA-2vcm-2mcr-wmx7/GHSA-2vcm-2mcr-wmx7.json index 33d36ff3a41..1c4db3010b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vcm-2mcr-wmx7/GHSA-2vcm-2mcr-wmx7.json +++ b/advisories/unreviewed/2022/05/GHSA-2vcm-2mcr-wmx7/GHSA-2vcm-2mcr-wmx7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2wvv-6r6q-wwcj/GHSA-2wvv-6r6q-wwcj.json b/advisories/unreviewed/2022/05/GHSA-2wvv-6r6q-wwcj/GHSA-2wvv-6r6q-wwcj.json index 811b2b0fee1..8c8243ec800 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wvv-6r6q-wwcj/GHSA-2wvv-6r6q-wwcj.json +++ b/advisories/unreviewed/2022/05/GHSA-2wvv-6r6q-wwcj/GHSA-2wvv-6r6q-wwcj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xhc-m333-xphj/GHSA-2xhc-m333-xphj.json b/advisories/unreviewed/2022/05/GHSA-2xhc-m333-xphj/GHSA-2xhc-m333-xphj.json index adb46893b0e..ffb918f505f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xhc-m333-xphj/GHSA-2xhc-m333-xphj.json +++ b/advisories/unreviewed/2022/05/GHSA-2xhc-m333-xphj/GHSA-2xhc-m333-xphj.json @@ -7,12 +7,8 @@ "CVE-2015-2996" ], "details": "Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the fileName parameter to getGfiUpgradeFile or (2) cause a denial of service (CPU and memory consumption) via a .. (dot dot) in the fileName parameter to calculateRdsFileChecksum.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3252-v683-v8qv/GHSA-3252-v683-v8qv.json b/advisories/unreviewed/2022/05/GHSA-3252-v683-v8qv/GHSA-3252-v683-v8qv.json index f085a11cec9..2b7249923ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-3252-v683-v8qv/GHSA-3252-v683-v8qv.json +++ b/advisories/unreviewed/2022/05/GHSA-3252-v683-v8qv/GHSA-3252-v683-v8qv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3254-vqw5-4844/GHSA-3254-vqw5-4844.json b/advisories/unreviewed/2022/05/GHSA-3254-vqw5-4844/GHSA-3254-vqw5-4844.json index 646ea30fc1a..1f14e2acd27 100644 --- a/advisories/unreviewed/2022/05/GHSA-3254-vqw5-4844/GHSA-3254-vqw5-4844.json +++ b/advisories/unreviewed/2022/05/GHSA-3254-vqw5-4844/GHSA-3254-vqw5-4844.json @@ -7,12 +7,8 @@ "CVE-2010-1845" ], "details": "ImageIO in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PSD image.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-328f-6h62-x2vm/GHSA-328f-6h62-x2vm.json b/advisories/unreviewed/2022/05/GHSA-328f-6h62-x2vm/GHSA-328f-6h62-x2vm.json index 928806f20c9..0c89e0e740f 100644 --- a/advisories/unreviewed/2022/05/GHSA-328f-6h62-x2vm/GHSA-328f-6h62-x2vm.json +++ b/advisories/unreviewed/2022/05/GHSA-328f-6h62-x2vm/GHSA-328f-6h62-x2vm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-328f-8262-r864/GHSA-328f-8262-r864.json b/advisories/unreviewed/2022/05/GHSA-328f-8262-r864/GHSA-328f-8262-r864.json index a73feacf850..644caf5f166 100644 --- a/advisories/unreviewed/2022/05/GHSA-328f-8262-r864/GHSA-328f-8262-r864.json +++ b/advisories/unreviewed/2022/05/GHSA-328f-8262-r864/GHSA-328f-8262-r864.json @@ -7,12 +7,8 @@ "CVE-2010-2928" ], "details": "The vCenter Tomcat Management Application in VMware vCenter Server 4.1 before Update 1 stores log-on credentials in a configuration file, which allows local users to gain privileges by reading this file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-33v3-cfhx-7jr9/GHSA-33v3-cfhx-7jr9.json b/advisories/unreviewed/2022/05/GHSA-33v3-cfhx-7jr9/GHSA-33v3-cfhx-7jr9.json index 2c261d11223..566175da3cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-33v3-cfhx-7jr9/GHSA-33v3-cfhx-7jr9.json +++ b/advisories/unreviewed/2022/05/GHSA-33v3-cfhx-7jr9/GHSA-33v3-cfhx-7jr9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-34pj-48rw-2hgw/GHSA-34pj-48rw-2hgw.json b/advisories/unreviewed/2022/05/GHSA-34pj-48rw-2hgw/GHSA-34pj-48rw-2hgw.json index 0c03b50d57b..c510dd6990f 100644 --- a/advisories/unreviewed/2022/05/GHSA-34pj-48rw-2hgw/GHSA-34pj-48rw-2hgw.json +++ b/advisories/unreviewed/2022/05/GHSA-34pj-48rw-2hgw/GHSA-34pj-48rw-2hgw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3584-vv4v-x974/GHSA-3584-vv4v-x974.json b/advisories/unreviewed/2022/05/GHSA-3584-vv4v-x974/GHSA-3584-vv4v-x974.json index b6814a33f6c..1efd876107e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3584-vv4v-x974/GHSA-3584-vv4v-x974.json +++ b/advisories/unreviewed/2022/05/GHSA-3584-vv4v-x974/GHSA-3584-vv4v-x974.json @@ -7,12 +7,8 @@ "CVE-2010-1512" ], "details": "Directory traversal vulnerability in aria2 before 1.9.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35hw-wvqh-pff2/GHSA-35hw-wvqh-pff2.json b/advisories/unreviewed/2022/05/GHSA-35hw-wvqh-pff2/GHSA-35hw-wvqh-pff2.json index 0fb37db1c6d..4444ba3f017 100644 --- a/advisories/unreviewed/2022/05/GHSA-35hw-wvqh-pff2/GHSA-35hw-wvqh-pff2.json +++ b/advisories/unreviewed/2022/05/GHSA-35hw-wvqh-pff2/GHSA-35hw-wvqh-pff2.json @@ -7,12 +7,8 @@ "CVE-2010-1997" ], "details": "Cross-site scripting (XSS) vulnerability in admin/edit.php in Saurus CMS 4.7.0 allows remote authenticated users, with \"Article list\" edit privileges, to inject arbitrary web script or HTML via the pealkiri parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35mf-hw36-wj5c/GHSA-35mf-hw36-wj5c.json b/advisories/unreviewed/2022/05/GHSA-35mf-hw36-wj5c/GHSA-35mf-hw36-wj5c.json index dad42d20887..34700bca1c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-35mf-hw36-wj5c/GHSA-35mf-hw36-wj5c.json +++ b/advisories/unreviewed/2022/05/GHSA-35mf-hw36-wj5c/GHSA-35mf-hw36-wj5c.json @@ -7,12 +7,8 @@ "CVE-2010-2866" ], "details": "Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a count value associated with an \"undocumented structure\" and the tSAC chunk in a Director movie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-35wp-mq65-94rh/GHSA-35wp-mq65-94rh.json b/advisories/unreviewed/2022/05/GHSA-35wp-mq65-94rh/GHSA-35wp-mq65-94rh.json index 4881602eba5..bf59ac7e6da 100644 --- a/advisories/unreviewed/2022/05/GHSA-35wp-mq65-94rh/GHSA-35wp-mq65-94rh.json +++ b/advisories/unreviewed/2022/05/GHSA-35wp-mq65-94rh/GHSA-35wp-mq65-94rh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-36x5-f2vx-p4jf/GHSA-36x5-f2vx-p4jf.json b/advisories/unreviewed/2022/05/GHSA-36x5-f2vx-p4jf/GHSA-36x5-f2vx-p4jf.json index 21cd3c4974d..9f654dd1aa4 100644 --- a/advisories/unreviewed/2022/05/GHSA-36x5-f2vx-p4jf/GHSA-36x5-f2vx-p4jf.json +++ b/advisories/unreviewed/2022/05/GHSA-36x5-f2vx-p4jf/GHSA-36x5-f2vx-p4jf.json @@ -7,12 +7,8 @@ "CVE-2015-4427" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Test/WorkArea/workarea.aspx in Ektron Content Management System (CMS) before 9.10 SP1 (Build 9.1.0.184.1.114) allow remote authenticated users to inject arbitrary web script or HTML via the (1) page, (2) action, (3) folder_id, or (4) LangType parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-377q-pqm6-wg2h/GHSA-377q-pqm6-wg2h.json b/advisories/unreviewed/2022/05/GHSA-377q-pqm6-wg2h/GHSA-377q-pqm6-wg2h.json index c359014b498..f565efe1bcb 100644 --- a/advisories/unreviewed/2022/05/GHSA-377q-pqm6-wg2h/GHSA-377q-pqm6-wg2h.json +++ b/advisories/unreviewed/2022/05/GHSA-377q-pqm6-wg2h/GHSA-377q-pqm6-wg2h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-399r-wgcm-v67f/GHSA-399r-wgcm-v67f.json b/advisories/unreviewed/2022/05/GHSA-399r-wgcm-v67f/GHSA-399r-wgcm-v67f.json index 9b1dfd68627..9836ed3df66 100644 --- a/advisories/unreviewed/2022/05/GHSA-399r-wgcm-v67f/GHSA-399r-wgcm-v67f.json +++ b/advisories/unreviewed/2022/05/GHSA-399r-wgcm-v67f/GHSA-399r-wgcm-v67f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-399x-jvm3-qgch/GHSA-399x-jvm3-qgch.json b/advisories/unreviewed/2022/05/GHSA-399x-jvm3-qgch/GHSA-399x-jvm3-qgch.json index e309570f55e..f0fc7268799 100644 --- a/advisories/unreviewed/2022/05/GHSA-399x-jvm3-qgch/GHSA-399x-jvm3-qgch.json +++ b/advisories/unreviewed/2022/05/GHSA-399x-jvm3-qgch/GHSA-399x-jvm3-qgch.json @@ -7,12 +7,8 @@ "CVE-2010-2869" ], "details": "IML32.dll in Adobe Shockwave Player before 11.5.8.612 does not properly parse .dir files, which allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a malformed file containing an invalid value, as demonstrated by a value at position 0x3712 of a certain file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-39hg-v7pc-xq8h/GHSA-39hg-v7pc-xq8h.json b/advisories/unreviewed/2022/05/GHSA-39hg-v7pc-xq8h/GHSA-39hg-v7pc-xq8h.json index a87106c5c41..42562d20ee7 100644 --- a/advisories/unreviewed/2022/05/GHSA-39hg-v7pc-xq8h/GHSA-39hg-v7pc-xq8h.json +++ b/advisories/unreviewed/2022/05/GHSA-39hg-v7pc-xq8h/GHSA-39hg-v7pc-xq8h.json @@ -7,12 +7,8 @@ "CVE-2010-2013" ], "details": "Cross-site scripting (XSS) vulnerability in cp/edit_email.php in LiSK CMS 4.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3c6h-p7mj-5m9j/GHSA-3c6h-p7mj-5m9j.json b/advisories/unreviewed/2022/05/GHSA-3c6h-p7mj-5m9j/GHSA-3c6h-p7mj-5m9j.json index 1584573093a..c71dca7eb10 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c6h-p7mj-5m9j/GHSA-3c6h-p7mj-5m9j.json +++ b/advisories/unreviewed/2022/05/GHSA-3c6h-p7mj-5m9j/GHSA-3c6h-p7mj-5m9j.json @@ -7,12 +7,8 @@ "CVE-2010-2234" ], "details": "Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of administrators for direct requests to an installation URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3fff-mm56-4v59/GHSA-3fff-mm56-4v59.json b/advisories/unreviewed/2022/05/GHSA-3fff-mm56-4v59/GHSA-3fff-mm56-4v59.json index 6819d9c0df5..0fe8084777a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fff-mm56-4v59/GHSA-3fff-mm56-4v59.json +++ b/advisories/unreviewed/2022/05/GHSA-3fff-mm56-4v59/GHSA-3fff-mm56-4v59.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3fp6-mxrp-2j4g/GHSA-3fp6-mxrp-2j4g.json b/advisories/unreviewed/2022/05/GHSA-3fp6-mxrp-2j4g/GHSA-3fp6-mxrp-2j4g.json index c9e503180ba..0d9093a6138 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fp6-mxrp-2j4g/GHSA-3fp6-mxrp-2j4g.json +++ b/advisories/unreviewed/2022/05/GHSA-3fp6-mxrp-2j4g/GHSA-3fp6-mxrp-2j4g.json @@ -7,12 +7,8 @@ "CVE-2010-3128" ], "details": "Untrusted search path vulnerability in TeamViewer 5.0.8703 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .tvs or .tvc file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3frm-4j94-mj9p/GHSA-3frm-4j94-mj9p.json b/advisories/unreviewed/2022/05/GHSA-3frm-4j94-mj9p/GHSA-3frm-4j94-mj9p.json index ee3e76d5a92..e37cb67887a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3frm-4j94-mj9p/GHSA-3frm-4j94-mj9p.json +++ b/advisories/unreviewed/2022/05/GHSA-3frm-4j94-mj9p/GHSA-3frm-4j94-mj9p.json @@ -7,12 +7,8 @@ "CVE-2015-2843" ], "details": "Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute arbitrary SQL commands via the (1) user_name or (2) user_pass parameter in go_login.php or the PATH_INFO to (3) go_login/validate_credentials/admin/ or (4) index.php/go_site/go_get_user_info/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3g3v-97v3-vj6w/GHSA-3g3v-97v3-vj6w.json b/advisories/unreviewed/2022/05/GHSA-3g3v-97v3-vj6w/GHSA-3g3v-97v3-vj6w.json index 87b942849bc..792c5e17589 100644 --- a/advisories/unreviewed/2022/05/GHSA-3g3v-97v3-vj6w/GHSA-3g3v-97v3-vj6w.json +++ b/advisories/unreviewed/2022/05/GHSA-3g3v-97v3-vj6w/GHSA-3g3v-97v3-vj6w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3gxr-2xmf-3h63/GHSA-3gxr-2xmf-3h63.json b/advisories/unreviewed/2022/05/GHSA-3gxr-2xmf-3h63/GHSA-3gxr-2xmf-3h63.json index 89563c846ad..722414cd8c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gxr-2xmf-3h63/GHSA-3gxr-2xmf-3h63.json +++ b/advisories/unreviewed/2022/05/GHSA-3gxr-2xmf-3h63/GHSA-3gxr-2xmf-3h63.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3gxw-vqmh-cmf2/GHSA-3gxw-vqmh-cmf2.json b/advisories/unreviewed/2022/05/GHSA-3gxw-vqmh-cmf2/GHSA-3gxw-vqmh-cmf2.json index 68f000373db..cbfb042203d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gxw-vqmh-cmf2/GHSA-3gxw-vqmh-cmf2.json +++ b/advisories/unreviewed/2022/05/GHSA-3gxw-vqmh-cmf2/GHSA-3gxw-vqmh-cmf2.json @@ -7,12 +7,8 @@ "CVE-2010-3096" ], "details": "Directory traversal vulnerability in SoftX FTP Client 3.3 and possibly earlier allows remote FTP servers to write arbitrary files via \"..\\\" (dot dot backslash) sequences in a filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3j4m-97f8-qmph/GHSA-3j4m-97f8-qmph.json b/advisories/unreviewed/2022/05/GHSA-3j4m-97f8-qmph/GHSA-3j4m-97f8-qmph.json index 09a49c470e6..35128e1c377 100644 --- a/advisories/unreviewed/2022/05/GHSA-3j4m-97f8-qmph/GHSA-3j4m-97f8-qmph.json +++ b/advisories/unreviewed/2022/05/GHSA-3j4m-97f8-qmph/GHSA-3j4m-97f8-qmph.json @@ -7,12 +7,8 @@ "CVE-2010-1481" ], "details": "Cross-site scripting (XSS) vulnerability in the table feature in PmWiki 2.2.15 allows remote authenticated users to inject arbitrary web script or HTML via the width attribute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3jmx-8q3h-p8gc/GHSA-3jmx-8q3h-p8gc.json b/advisories/unreviewed/2022/05/GHSA-3jmx-8q3h-p8gc/GHSA-3jmx-8q3h-p8gc.json index 7c24f83cf1c..6240139b5ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jmx-8q3h-p8gc/GHSA-3jmx-8q3h-p8gc.json +++ b/advisories/unreviewed/2022/05/GHSA-3jmx-8q3h-p8gc/GHSA-3jmx-8q3h-p8gc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3jvv-r7g7-63qp/GHSA-3jvv-r7g7-63qp.json b/advisories/unreviewed/2022/05/GHSA-3jvv-r7g7-63qp/GHSA-3jvv-r7g7-63qp.json index e7956be0b40..2f1b56a5085 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jvv-r7g7-63qp/GHSA-3jvv-r7g7-63qp.json +++ b/advisories/unreviewed/2022/05/GHSA-3jvv-r7g7-63qp/GHSA-3jvv-r7g7-63qp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3pmj-224c-9qh2/GHSA-3pmj-224c-9qh2.json b/advisories/unreviewed/2022/05/GHSA-3pmj-224c-9qh2/GHSA-3pmj-224c-9qh2.json index 78a664171ed..30a1facaa74 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pmj-224c-9qh2/GHSA-3pmj-224c-9qh2.json +++ b/advisories/unreviewed/2022/05/GHSA-3pmj-224c-9qh2/GHSA-3pmj-224c-9qh2.json @@ -7,12 +7,8 @@ "CVE-2010-2914" ], "details": "Cross-site scripting (XSS) vulnerability in nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3pq5-p8h5-jfr8/GHSA-3pq5-p8h5-jfr8.json b/advisories/unreviewed/2022/05/GHSA-3pq5-p8h5-jfr8/GHSA-3pq5-p8h5-jfr8.json index b5ef730500a..f4b4c2c2962 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pq5-p8h5-jfr8/GHSA-3pq5-p8h5-jfr8.json +++ b/advisories/unreviewed/2022/05/GHSA-3pq5-p8h5-jfr8/GHSA-3pq5-p8h5-jfr8.json @@ -7,12 +7,8 @@ "CVE-2010-4675" ], "details": "Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) do not properly determine the interfaces for which TELNET connections should be permitted, which allows remote authenticated users to bypass intended access restrictions via vectors involving the \"lowest security level interface,\" aka Bug ID CSCsv40504.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3qc8-c2c9-9pgw/GHSA-3qc8-c2c9-9pgw.json b/advisories/unreviewed/2022/05/GHSA-3qc8-c2c9-9pgw/GHSA-3qc8-c2c9-9pgw.json index 26f0b81adc5..1e3dc2d0c4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qc8-c2c9-9pgw/GHSA-3qc8-c2c9-9pgw.json +++ b/advisories/unreviewed/2022/05/GHSA-3qc8-c2c9-9pgw/GHSA-3qc8-c2c9-9pgw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3rfx-p4vj-g7v6/GHSA-3rfx-p4vj-g7v6.json b/advisories/unreviewed/2022/05/GHSA-3rfx-p4vj-g7v6/GHSA-3rfx-p4vj-g7v6.json index 399d3e705f1..f0ffcfc3004 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rfx-p4vj-g7v6/GHSA-3rfx-p4vj-g7v6.json +++ b/advisories/unreviewed/2022/05/GHSA-3rfx-p4vj-g7v6/GHSA-3rfx-p4vj-g7v6.json @@ -7,12 +7,8 @@ "CVE-2015-8051" ], "details": "The Adobe Premiere Clip app before 1.2.1 for iOS mishandles unspecified input, which has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3rhg-qq6v-6gmc/GHSA-3rhg-qq6v-6gmc.json b/advisories/unreviewed/2022/05/GHSA-3rhg-qq6v-6gmc/GHSA-3rhg-qq6v-6gmc.json index 9cae475b372..a375793b1cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rhg-qq6v-6gmc/GHSA-3rhg-qq6v-6gmc.json +++ b/advisories/unreviewed/2022/05/GHSA-3rhg-qq6v-6gmc/GHSA-3rhg-qq6v-6gmc.json @@ -7,12 +7,8 @@ "CVE-2015-6306" ], "details": "Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions, which allows local users to obtain root privileges via a crafted installation file, aka Bug ID CSCuv11947.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3xpw-r9fx-85m3/GHSA-3xpw-r9fx-85m3.json b/advisories/unreviewed/2022/05/GHSA-3xpw-r9fx-85m3/GHSA-3xpw-r9fx-85m3.json index abc9e1cb626..be2a75f1e5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xpw-r9fx-85m3/GHSA-3xpw-r9fx-85m3.json +++ b/advisories/unreviewed/2022/05/GHSA-3xpw-r9fx-85m3/GHSA-3xpw-r9fx-85m3.json @@ -7,12 +7,8 @@ "CVE-2010-3756" ], "details": "The _CalcHashValueWithLength function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 does not properly validate an unspecified length value, which allows remote attackers to cause a denial of service (daemon crash) by sending data over TCP. NOTE: this might overlap CVE-2010-3060.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4386-3ggv-4ppc/GHSA-4386-3ggv-4ppc.json b/advisories/unreviewed/2022/05/GHSA-4386-3ggv-4ppc/GHSA-4386-3ggv-4ppc.json index a7336534bd5..261a5ececdb 100644 --- a/advisories/unreviewed/2022/05/GHSA-4386-3ggv-4ppc/GHSA-4386-3ggv-4ppc.json +++ b/advisories/unreviewed/2022/05/GHSA-4386-3ggv-4ppc/GHSA-4386-3ggv-4ppc.json @@ -7,12 +7,8 @@ "CVE-2015-2250" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) banned_word[] parameter to index.php/dashboard/system/conversations/bannedwords/success, (2) channel parameter to index.php/dashboard/reports/logs/view, (3) accessType parameter to index.php/tools/required/permissions/access_entity, (4) msCountry parameter to index.php/dashboard/system/multilingual/setup/load_icon, arHandle parameter to (5) design/submit or (6) design in index.php/ccm/system/dialogs/area/design/submit, (7) pageURL to index.php/dashboard/pages/single, (8) SEARCH_INDEX_AREA_METHOD parameter to index.php/dashboard/system/seo/searchindex/updated, (9) unit parameter to index.php/dashboard/system/optimization/jobs/job_scheduled, (10) register_notification_email parameter to index.php/dashboard/system/registration/open/1, or (11) PATH_INFO to index.php/dashboard/extend/connect/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4397-h7gg-cgr7/GHSA-4397-h7gg-cgr7.json b/advisories/unreviewed/2022/05/GHSA-4397-h7gg-cgr7/GHSA-4397-h7gg-cgr7.json index b9bc0718d73..b0a626c145e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4397-h7gg-cgr7/GHSA-4397-h7gg-cgr7.json +++ b/advisories/unreviewed/2022/05/GHSA-4397-h7gg-cgr7/GHSA-4397-h7gg-cgr7.json @@ -7,12 +7,8 @@ "CVE-2015-4108" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in Wing FTP Server before 4.4.7 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary code via a crafted request to admin_lua_script.html or (2) add a domain administrator via a crafted request to admin_addadmin.html.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-43wj-2j22-7v74/GHSA-43wj-2j22-7v74.json b/advisories/unreviewed/2022/05/GHSA-43wj-2j22-7v74/GHSA-43wj-2j22-7v74.json index c8e81523dbd..b1d924d22e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-43wj-2j22-7v74/GHSA-43wj-2j22-7v74.json +++ b/advisories/unreviewed/2022/05/GHSA-43wj-2j22-7v74/GHSA-43wj-2j22-7v74.json @@ -7,12 +7,8 @@ "CVE-2015-3995" ], "details": "SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to read arbitrary files via an IMPORT FROM SQL statement, aka SAP Security Note 2109565.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44jj-9jpw-493g/GHSA-44jj-9jpw-493g.json b/advisories/unreviewed/2022/05/GHSA-44jj-9jpw-493g/GHSA-44jj-9jpw-493g.json index 07339c43638..640463db17a 100644 --- a/advisories/unreviewed/2022/05/GHSA-44jj-9jpw-493g/GHSA-44jj-9jpw-493g.json +++ b/advisories/unreviewed/2022/05/GHSA-44jj-9jpw-493g/GHSA-44jj-9jpw-493g.json @@ -7,12 +7,8 @@ "CVE-2010-2436" ], "details": "SQL injection vulnerability in modules/blog/index.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44qg-j3rp-67rc/GHSA-44qg-j3rp-67rc.json b/advisories/unreviewed/2022/05/GHSA-44qg-j3rp-67rc/GHSA-44qg-j3rp-67rc.json index 1a4cefd85b3..8a7d77bdf85 100644 --- a/advisories/unreviewed/2022/05/GHSA-44qg-j3rp-67rc/GHSA-44qg-j3rp-67rc.json +++ b/advisories/unreviewed/2022/05/GHSA-44qg-j3rp-67rc/GHSA-44qg-j3rp-67rc.json @@ -7,12 +7,8 @@ "CVE-2015-3429" ], "details": "Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44r7-8q32-6cxx/GHSA-44r7-8q32-6cxx.json b/advisories/unreviewed/2022/05/GHSA-44r7-8q32-6cxx/GHSA-44r7-8q32-6cxx.json index 3081711b649..c0ce330b72e 100644 --- a/advisories/unreviewed/2022/05/GHSA-44r7-8q32-6cxx/GHSA-44r7-8q32-6cxx.json +++ b/advisories/unreviewed/2022/05/GHSA-44r7-8q32-6cxx/GHSA-44r7-8q32-6cxx.json @@ -7,12 +7,8 @@ "CVE-2015-2842" ], "details": "Unrestricted file upload vulnerability in go_audiostore.php in the audiostore (Voice Files) upload functionality in GoAutoDial GoAdmin CE 3.x before 3.3-1421902800 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in sounds/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-46vg-8qj8-j3fp/GHSA-46vg-8qj8-j3fp.json b/advisories/unreviewed/2022/05/GHSA-46vg-8qj8-j3fp/GHSA-46vg-8qj8-j3fp.json index b9a05e078ff..9a6ee2097a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-46vg-8qj8-j3fp/GHSA-46vg-8qj8-j3fp.json +++ b/advisories/unreviewed/2022/05/GHSA-46vg-8qj8-j3fp/GHSA-46vg-8qj8-j3fp.json @@ -7,12 +7,8 @@ "CVE-2010-1516" ], "details": "Multiple integer overflows in SWFTools 0.9.1 allow remote attackers to execute arbitrary code via (1) a crafted PNG file, related to the getPNG function in lib/png.c; or (2) a crafted JPEG file, related to the jpeg_load function in lib/jpeg.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-486g-jg8g-q4pg/GHSA-486g-jg8g-q4pg.json b/advisories/unreviewed/2022/05/GHSA-486g-jg8g-q4pg/GHSA-486g-jg8g-q4pg.json index e830a565183..e001fdf24e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-486g-jg8g-q4pg/GHSA-486g-jg8g-q4pg.json +++ b/advisories/unreviewed/2022/05/GHSA-486g-jg8g-q4pg/GHSA-486g-jg8g-q4pg.json @@ -7,12 +7,8 @@ "CVE-2015-4153" ], "details": "Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to include and execute arbitrary php files via a relative path in the template parameter in a load_template action to wp-admin/admin-ajax.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-49f8-wxc2-6w7h/GHSA-49f8-wxc2-6w7h.json b/advisories/unreviewed/2022/05/GHSA-49f8-wxc2-6w7h/GHSA-49f8-wxc2-6w7h.json index 73380448a36..3a18290f68c 100644 --- a/advisories/unreviewed/2022/05/GHSA-49f8-wxc2-6w7h/GHSA-49f8-wxc2-6w7h.json +++ b/advisories/unreviewed/2022/05/GHSA-49f8-wxc2-6w7h/GHSA-49f8-wxc2-6w7h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-49gh-f88v-9xqf/GHSA-49gh-f88v-9xqf.json b/advisories/unreviewed/2022/05/GHSA-49gh-f88v-9xqf/GHSA-49gh-f88v-9xqf.json index 32a840e156b..133f963f1ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-49gh-f88v-9xqf/GHSA-49gh-f88v-9xqf.json +++ b/advisories/unreviewed/2022/05/GHSA-49gh-f88v-9xqf/GHSA-49gh-f88v-9xqf.json @@ -7,12 +7,8 @@ "CVE-2015-2838" ], "details": "Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary commands as nsroot via shell metacharacters in the file_name JSON member in params/xen_hotfix/0 to nitro/v1/config/xen_hotfix.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4ffw-j96c-68cv/GHSA-4ffw-j96c-68cv.json b/advisories/unreviewed/2022/05/GHSA-4ffw-j96c-68cv/GHSA-4ffw-j96c-68cv.json index 419122578fe..a9d1aa407f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-4ffw-j96c-68cv/GHSA-4ffw-j96c-68cv.json +++ b/advisories/unreviewed/2022/05/GHSA-4ffw-j96c-68cv/GHSA-4ffw-j96c-68cv.json @@ -7,12 +7,8 @@ "CVE-2010-2308" ], "details": "Unspecified vulnerability in the filter driver (savonaccessfilter.sys) in Sophos Anti-Virus before 7.6.20 allows local users to gain privileges via crafted arguments to the NtQueryAttributesFile function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4gvg-45m6-hm4p/GHSA-4gvg-45m6-hm4p.json b/advisories/unreviewed/2022/05/GHSA-4gvg-45m6-hm4p/GHSA-4gvg-45m6-hm4p.json index d9e374acb62..f97bcd356c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gvg-45m6-hm4p/GHSA-4gvg-45m6-hm4p.json +++ b/advisories/unreviewed/2022/05/GHSA-4gvg-45m6-hm4p/GHSA-4gvg-45m6-hm4p.json @@ -7,12 +7,8 @@ "CVE-2015-2926" ], "details": "Cross-site scripting (XSS) vulnerability in Php/stats/statsRecent.inc.php in phpTrafficA 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTTP User-Agent header to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4h3h-4rf6-522r/GHSA-4h3h-4rf6-522r.json b/advisories/unreviewed/2022/05/GHSA-4h3h-4rf6-522r/GHSA-4h3h-4rf6-522r.json index b620e4ecb47..8bf784f6b9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4h3h-4rf6-522r/GHSA-4h3h-4rf6-522r.json +++ b/advisories/unreviewed/2022/05/GHSA-4h3h-4rf6-522r/GHSA-4h3h-4rf6-522r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4j56-gwfc-85w2/GHSA-4j56-gwfc-85w2.json b/advisories/unreviewed/2022/05/GHSA-4j56-gwfc-85w2/GHSA-4j56-gwfc-85w2.json index 140b54d0039..74d653abf9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4j56-gwfc-85w2/GHSA-4j56-gwfc-85w2.json +++ b/advisories/unreviewed/2022/05/GHSA-4j56-gwfc-85w2/GHSA-4j56-gwfc-85w2.json @@ -7,12 +7,8 @@ "CVE-2010-2145" ], "details": "Multiple PHP remote file inclusion vulnerabilities in ClearSite Beta 4.50, and possibly other versions, allow remote attackers to execute arbitrary PHP code via a URL in the cs_base_path parameter to (1) docs.php and (2) include/admin/device_admin.php. NOTE: the header.php vector is already covered by CVE-2009-3306. NOTE: this issue may be due to a variable extraction error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4j8w-22m8-f38g/GHSA-4j8w-22m8-f38g.json b/advisories/unreviewed/2022/05/GHSA-4j8w-22m8-f38g/GHSA-4j8w-22m8-f38g.json index c03213302b3..72884d1801a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4j8w-22m8-f38g/GHSA-4j8w-22m8-f38g.json +++ b/advisories/unreviewed/2022/05/GHSA-4j8w-22m8-f38g/GHSA-4j8w-22m8-f38g.json @@ -7,12 +7,8 @@ "CVE-2015-7372" ], "details": "Directory traversal vulnerability in delivery-dev/al.php in Revive Adserver before 3.2.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the layerstyle parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4jhx-hr8g-2cq8/GHSA-4jhx-hr8g-2cq8.json b/advisories/unreviewed/2022/05/GHSA-4jhx-hr8g-2cq8/GHSA-4jhx-hr8g-2cq8.json index d3a509c11dd..a56330b0c69 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jhx-hr8g-2cq8/GHSA-4jhx-hr8g-2cq8.json +++ b/advisories/unreviewed/2022/05/GHSA-4jhx-hr8g-2cq8/GHSA-4jhx-hr8g-2cq8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4mgc-gcxj-hf9r/GHSA-4mgc-gcxj-hf9r.json b/advisories/unreviewed/2022/05/GHSA-4mgc-gcxj-hf9r/GHSA-4mgc-gcxj-hf9r.json index 2e6510ef131..43fa12ab0e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mgc-gcxj-hf9r/GHSA-4mgc-gcxj-hf9r.json +++ b/advisories/unreviewed/2022/05/GHSA-4mgc-gcxj-hf9r/GHSA-4mgc-gcxj-hf9r.json @@ -7,12 +7,8 @@ "CVE-2015-2282" ], "details": "Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, aka SAP Security Note 2124806, 2121661, 2127995, and 2125316.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4mq8-fgx6-fqpv/GHSA-4mq8-fgx6-fqpv.json b/advisories/unreviewed/2022/05/GHSA-4mq8-fgx6-fqpv/GHSA-4mq8-fgx6-fqpv.json index d85b0e25345..5cfc6a4a564 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mq8-fgx6-fqpv/GHSA-4mq8-fgx6-fqpv.json +++ b/advisories/unreviewed/2022/05/GHSA-4mq8-fgx6-fqpv/GHSA-4mq8-fgx6-fqpv.json @@ -7,12 +7,8 @@ "CVE-2010-3567" ], "details": "Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this is related to a calculation error in right-to-left text character counts for the ICU OpenType font rendering implementation, which triggers an out-of-bounds memory access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -128,9 +124,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4q4q-gj6j-5g8p/GHSA-4q4q-gj6j-5g8p.json b/advisories/unreviewed/2022/05/GHSA-4q4q-gj6j-5g8p/GHSA-4q4q-gj6j-5g8p.json index 28fafa9186e..41b75da898c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4q4q-gj6j-5g8p/GHSA-4q4q-gj6j-5g8p.json +++ b/advisories/unreviewed/2022/05/GHSA-4q4q-gj6j-5g8p/GHSA-4q4q-gj6j-5g8p.json @@ -7,12 +7,8 @@ "CVE-2010-1964" ], "details": "Buffer overflow in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified parameters to jovgraph.exe, aka ZDI-CAN-683.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4qh5-p5x2-2wcj/GHSA-4qh5-p5x2-2wcj.json b/advisories/unreviewed/2022/05/GHSA-4qh5-p5x2-2wcj/GHSA-4qh5-p5x2-2wcj.json index e308dc40f70..f2b999da045 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qh5-p5x2-2wcj/GHSA-4qh5-p5x2-2wcj.json +++ b/advisories/unreviewed/2022/05/GHSA-4qh5-p5x2-2wcj/GHSA-4qh5-p5x2-2wcj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4qrh-29x8-rv94/GHSA-4qrh-29x8-rv94.json b/advisories/unreviewed/2022/05/GHSA-4qrh-29x8-rv94/GHSA-4qrh-29x8-rv94.json index e730e7d30bc..5f9dddfe37c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qrh-29x8-rv94/GHSA-4qrh-29x8-rv94.json +++ b/advisories/unreviewed/2022/05/GHSA-4qrh-29x8-rv94/GHSA-4qrh-29x8-rv94.json @@ -7,12 +7,8 @@ "CVE-2010-3131" ], "details": "Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .htm, .html, .jtx, .mfp, or .eml file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4v6r-qc3q-5hfm/GHSA-4v6r-qc3q-5hfm.json b/advisories/unreviewed/2022/05/GHSA-4v6r-qc3q-5hfm/GHSA-4v6r-qc3q-5hfm.json index a5c5935eb0a..d57c5acf264 100644 --- a/advisories/unreviewed/2022/05/GHSA-4v6r-qc3q-5hfm/GHSA-4v6r-qc3q-5hfm.json +++ b/advisories/unreviewed/2022/05/GHSA-4v6r-qc3q-5hfm/GHSA-4v6r-qc3q-5hfm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4x35-v2c7-mwxv/GHSA-4x35-v2c7-mwxv.json b/advisories/unreviewed/2022/05/GHSA-4x35-v2c7-mwxv/GHSA-4x35-v2c7-mwxv.json index 9412fc1cd91..06abb81c184 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x35-v2c7-mwxv/GHSA-4x35-v2c7-mwxv.json +++ b/advisories/unreviewed/2022/05/GHSA-4x35-v2c7-mwxv/GHSA-4x35-v2c7-mwxv.json @@ -7,12 +7,8 @@ "CVE-2015-2281" ], "details": "Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attackers to execute arbitrary code via a large PROCESS_HELLO message to the Message Dispatcher on TCP port 8000.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5258-w3fr-9pw8/GHSA-5258-w3fr-9pw8.json b/advisories/unreviewed/2022/05/GHSA-5258-w3fr-9pw8/GHSA-5258-w3fr-9pw8.json index a05caf59b08..f82218bc549 100644 --- a/advisories/unreviewed/2022/05/GHSA-5258-w3fr-9pw8/GHSA-5258-w3fr-9pw8.json +++ b/advisories/unreviewed/2022/05/GHSA-5258-w3fr-9pw8/GHSA-5258-w3fr-9pw8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-529x-f9rr-pg3j/GHSA-529x-f9rr-pg3j.json b/advisories/unreviewed/2022/05/GHSA-529x-f9rr-pg3j/GHSA-529x-f9rr-pg3j.json index 375ea128787..c3191581b5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-529x-f9rr-pg3j/GHSA-529x-f9rr-pg3j.json +++ b/advisories/unreviewed/2022/05/GHSA-529x-f9rr-pg3j/GHSA-529x-f9rr-pg3j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-52vq-vh7q-45mc/GHSA-52vq-vh7q-45mc.json b/advisories/unreviewed/2022/05/GHSA-52vq-vh7q-45mc/GHSA-52vq-vh7q-45mc.json index af6f3df7a1b..676b6079325 100644 --- a/advisories/unreviewed/2022/05/GHSA-52vq-vh7q-45mc/GHSA-52vq-vh7q-45mc.json +++ b/advisories/unreviewed/2022/05/GHSA-52vq-vh7q-45mc/GHSA-52vq-vh7q-45mc.json @@ -7,12 +7,8 @@ "CVE-2015-3647" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin before 6.1.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) comemail or (2) comname parameter in a wppa do-comment action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53cq-v8h5-f4v2/GHSA-53cq-v8h5-f4v2.json b/advisories/unreviewed/2022/05/GHSA-53cq-v8h5-f4v2/GHSA-53cq-v8h5-f4v2.json index ba80497ae9f..99f2595b99b 100644 --- a/advisories/unreviewed/2022/05/GHSA-53cq-v8h5-f4v2/GHSA-53cq-v8h5-f4v2.json +++ b/advisories/unreviewed/2022/05/GHSA-53cq-v8h5-f4v2/GHSA-53cq-v8h5-f4v2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53p6-5gx5-42m7/GHSA-53p6-5gx5-42m7.json b/advisories/unreviewed/2022/05/GHSA-53p6-5gx5-42m7/GHSA-53p6-5gx5-42m7.json index 95d893b00a6..c33078a2a0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-53p6-5gx5-42m7/GHSA-53p6-5gx5-42m7.json +++ b/advisories/unreviewed/2022/05/GHSA-53p6-5gx5-42m7/GHSA-53p6-5gx5-42m7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-545x-w5vx-gr54/GHSA-545x-w5vx-gr54.json b/advisories/unreviewed/2022/05/GHSA-545x-w5vx-gr54/GHSA-545x-w5vx-gr54.json index 0ed92627044..54d3b00347d 100644 --- a/advisories/unreviewed/2022/05/GHSA-545x-w5vx-gr54/GHSA-545x-w5vx-gr54.json +++ b/advisories/unreviewed/2022/05/GHSA-545x-w5vx-gr54/GHSA-545x-w5vx-gr54.json @@ -7,12 +7,8 @@ "CVE-2010-2347" ], "details": "The Telnet interface in the SAP J2EE Engine Core (SAP-JEECOR) 6.40 through 7.02, and Server Core (SERVERCORE) 7.10 through 7.30 allows remote authenticated users to bypass a security check and conduct SMB relay attacks via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5465-6fq8-4qjw/GHSA-5465-6fq8-4qjw.json b/advisories/unreviewed/2022/05/GHSA-5465-6fq8-4qjw/GHSA-5465-6fq8-4qjw.json index de72d6f8517..cbd711ff040 100644 --- a/advisories/unreviewed/2022/05/GHSA-5465-6fq8-4qjw/GHSA-5465-6fq8-4qjw.json +++ b/advisories/unreviewed/2022/05/GHSA-5465-6fq8-4qjw/GHSA-5465-6fq8-4qjw.json @@ -7,12 +7,8 @@ "CVE-2010-2877" ], "details": "Adobe Shockwave Player before 11.5.8.612 does not properly validate a count value in a Director movie, which allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted movie, related to IML32X.dll and DIRAPIX.dll.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-54m2-55jp-g5xr/GHSA-54m2-55jp-g5xr.json b/advisories/unreviewed/2022/05/GHSA-54m2-55jp-g5xr/GHSA-54m2-55jp-g5xr.json index 545d4cbb945..8c7a969d7ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-54m2-55jp-g5xr/GHSA-54m2-55jp-g5xr.json +++ b/advisories/unreviewed/2022/05/GHSA-54m2-55jp-g5xr/GHSA-54m2-55jp-g5xr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-55mg-c2vp-hrq8/GHSA-55mg-c2vp-hrq8.json b/advisories/unreviewed/2022/05/GHSA-55mg-c2vp-hrq8/GHSA-55mg-c2vp-hrq8.json index 82f0a221730..9729cdb612b 100644 --- a/advisories/unreviewed/2022/05/GHSA-55mg-c2vp-hrq8/GHSA-55mg-c2vp-hrq8.json +++ b/advisories/unreviewed/2022/05/GHSA-55mg-c2vp-hrq8/GHSA-55mg-c2vp-hrq8.json @@ -7,12 +7,8 @@ "CVE-2015-7527" ], "details": "lib/core.php in the Cool Video Gallery plugin 1.9 for WordPress allows remote attackers to execute arbitrary code via shell metacharacters in the \"Width of preview image\" and possibly other input fields in the \"Video Gallery Settings\" page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5738-w455-jqx4/GHSA-5738-w455-jqx4.json b/advisories/unreviewed/2022/05/GHSA-5738-w455-jqx4/GHSA-5738-w455-jqx4.json index 1dfbed2b2a6..f392c81de0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5738-w455-jqx4/GHSA-5738-w455-jqx4.json +++ b/advisories/unreviewed/2022/05/GHSA-5738-w455-jqx4/GHSA-5738-w455-jqx4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5873-v44v-5632/GHSA-5873-v44v-5632.json b/advisories/unreviewed/2022/05/GHSA-5873-v44v-5632/GHSA-5873-v44v-5632.json index 3f7121e08a6..faed150d7f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-5873-v44v-5632/GHSA-5873-v44v-5632.json +++ b/advisories/unreviewed/2022/05/GHSA-5873-v44v-5632/GHSA-5873-v44v-5632.json @@ -7,12 +7,8 @@ "CVE-2010-3200" ], "details": "MSO.dll in Microsoft Word 2003 SP3 11.8326.11.8324 allows remote attackers to cause a denial of service (NULL pointer dereference and multiple-instance application crash) via a crafted buffer in a Word document, as demonstrated by word_crash_11.8326.8324_poc.doc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-587j-cc5w-pqph/GHSA-587j-cc5w-pqph.json b/advisories/unreviewed/2022/05/GHSA-587j-cc5w-pqph/GHSA-587j-cc5w-pqph.json index 6fe2e8fc911..b8e804ea2d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-587j-cc5w-pqph/GHSA-587j-cc5w-pqph.json +++ b/advisories/unreviewed/2022/05/GHSA-587j-cc5w-pqph/GHSA-587j-cc5w-pqph.json @@ -7,12 +7,8 @@ "CVE-2015-5458" ], "details": "Session fixation vulnerability in fileupload.php in PivotX before 2.3.11 allows remote attackers to hijack web sessions via the sess parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-58q5-m5pm-jwpv/GHSA-58q5-m5pm-jwpv.json b/advisories/unreviewed/2022/05/GHSA-58q5-m5pm-jwpv/GHSA-58q5-m5pm-jwpv.json index 3d42bb5bd7d..b0b3779b2aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-58q5-m5pm-jwpv/GHSA-58q5-m5pm-jwpv.json +++ b/advisories/unreviewed/2022/05/GHSA-58q5-m5pm-jwpv/GHSA-58q5-m5pm-jwpv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-59hj-f6jm-h4j5/GHSA-59hj-f6jm-h4j5.json b/advisories/unreviewed/2022/05/GHSA-59hj-f6jm-h4j5/GHSA-59hj-f6jm-h4j5.json index 891d1e466c5..c7663d082b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-59hj-f6jm-h4j5/GHSA-59hj-f6jm-h4j5.json +++ b/advisories/unreviewed/2022/05/GHSA-59hj-f6jm-h4j5/GHSA-59hj-f6jm-h4j5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-59v2-j7v3-6gmx/GHSA-59v2-j7v3-6gmx.json b/advisories/unreviewed/2022/05/GHSA-59v2-j7v3-6gmx/GHSA-59v2-j7v3-6gmx.json index 6922205e2c7..ad73eae1fed 100644 --- a/advisories/unreviewed/2022/05/GHSA-59v2-j7v3-6gmx/GHSA-59v2-j7v3-6gmx.json +++ b/advisories/unreviewed/2022/05/GHSA-59v2-j7v3-6gmx/GHSA-59v2-j7v3-6gmx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5c25-ppjq-qcq8/GHSA-5c25-ppjq-qcq8.json b/advisories/unreviewed/2022/05/GHSA-5c25-ppjq-qcq8/GHSA-5c25-ppjq-qcq8.json index b635a4656a3..9e83abbfd49 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c25-ppjq-qcq8/GHSA-5c25-ppjq-qcq8.json +++ b/advisories/unreviewed/2022/05/GHSA-5c25-ppjq-qcq8/GHSA-5c25-ppjq-qcq8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5f23-7wg5-v6qm/GHSA-5f23-7wg5-v6qm.json b/advisories/unreviewed/2022/05/GHSA-5f23-7wg5-v6qm/GHSA-5f23-7wg5-v6qm.json index ec270929e9e..65da2c3b640 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f23-7wg5-v6qm/GHSA-5f23-7wg5-v6qm.json +++ b/advisories/unreviewed/2022/05/GHSA-5f23-7wg5-v6qm/GHSA-5f23-7wg5-v6qm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5f63-6j8r-v53q/GHSA-5f63-6j8r-v53q.json b/advisories/unreviewed/2022/05/GHSA-5f63-6j8r-v53q/GHSA-5f63-6j8r-v53q.json index dcc7857e263..850a25da803 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f63-6j8r-v53q/GHSA-5f63-6j8r-v53q.json +++ b/advisories/unreviewed/2022/05/GHSA-5f63-6j8r-v53q/GHSA-5f63-6j8r-v53q.json @@ -7,12 +7,8 @@ "CVE-2010-1988" ], "details": "Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via JavaScript code that performs certain string concatenation and substring operations, a different vulnerability than CVE-2009-1571.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5fg2-x272-mmwr/GHSA-5fg2-x272-mmwr.json b/advisories/unreviewed/2022/05/GHSA-5fg2-x272-mmwr/GHSA-5fg2-x272-mmwr.json index 40cd16a577f..a35a01e26f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fg2-x272-mmwr/GHSA-5fg2-x272-mmwr.json +++ b/advisories/unreviewed/2022/05/GHSA-5fg2-x272-mmwr/GHSA-5fg2-x272-mmwr.json @@ -7,12 +7,8 @@ "CVE-2010-1522" ], "details": "Multiple SQL injection vulnerabilities in the BookLibrary Basic (com_booklibrary) component 1.5.3 before 1.5.3_2010_06_20 for Joomla! allow remote attackers to execute arbitrary SQL commands via the bid[] parameter in a (1) lend_request or (2) save_lend_request action to index.php, the id parameter in a (3) mdownload or (4) downitsf action to index.php, or (5) the searchtext parameter in a search action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5fx4-rpw4-f5xm/GHSA-5fx4-rpw4-f5xm.json b/advisories/unreviewed/2022/05/GHSA-5fx4-rpw4-f5xm/GHSA-5fx4-rpw4-f5xm.json index 04e4bbd7416..6d90d5afd71 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fx4-rpw4-f5xm/GHSA-5fx4-rpw4-f5xm.json +++ b/advisories/unreviewed/2022/05/GHSA-5fx4-rpw4-f5xm/GHSA-5fx4-rpw4-f5xm.json @@ -7,12 +7,8 @@ "CVE-2015-5064" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in MySql Lite Administrator (mysql-lite-administrator) beta-1 allow remote attackers to inject arbitrary web script or HTML via the table_name parameter to (1) tabella.php, (2) coloni.php, or (3) insert.php or (4) num_row parameter to coloni.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5hj2-xjgf-w4w4/GHSA-5hj2-xjgf-w4w4.json b/advisories/unreviewed/2022/05/GHSA-5hj2-xjgf-w4w4/GHSA-5hj2-xjgf-w4w4.json index 3f380fce972..e0281c16e90 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hj2-xjgf-w4w4/GHSA-5hj2-xjgf-w4w4.json +++ b/advisories/unreviewed/2022/05/GHSA-5hj2-xjgf-w4w4/GHSA-5hj2-xjgf-w4w4.json @@ -7,12 +7,8 @@ "CVE-2010-2858" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in news.php in SimpNews 2.47.03 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) layout and (2) sortorder parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5j3c-8rmq-fp7f/GHSA-5j3c-8rmq-fp7f.json b/advisories/unreviewed/2022/05/GHSA-5j3c-8rmq-fp7f/GHSA-5j3c-8rmq-fp7f.json index 48b496d80e5..c2020fa60df 100644 --- a/advisories/unreviewed/2022/05/GHSA-5j3c-8rmq-fp7f/GHSA-5j3c-8rmq-fp7f.json +++ b/advisories/unreviewed/2022/05/GHSA-5j3c-8rmq-fp7f/GHSA-5j3c-8rmq-fp7f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5m9m-3wqm-g9m4/GHSA-5m9m-3wqm-g9m4.json b/advisories/unreviewed/2022/05/GHSA-5m9m-3wqm-g9m4/GHSA-5m9m-3wqm-g9m4.json index ea5a9af5090..7151b3fb37e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5m9m-3wqm-g9m4/GHSA-5m9m-3wqm-g9m4.json +++ b/advisories/unreviewed/2022/05/GHSA-5m9m-3wqm-g9m4/GHSA-5m9m-3wqm-g9m4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5qxr-ghw4-f8rh/GHSA-5qxr-ghw4-f8rh.json b/advisories/unreviewed/2022/05/GHSA-5qxr-ghw4-f8rh/GHSA-5qxr-ghw4-f8rh.json index 44e25d27e62..2aad5b7914e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qxr-ghw4-f8rh/GHSA-5qxr-ghw4-f8rh.json +++ b/advisories/unreviewed/2022/05/GHSA-5qxr-ghw4-f8rh/GHSA-5qxr-ghw4-f8rh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5r94-4p2v-j8wm/GHSA-5r94-4p2v-j8wm.json b/advisories/unreviewed/2022/05/GHSA-5r94-4p2v-j8wm/GHSA-5r94-4p2v-j8wm.json index 51d56f0d8ee..48639a51fbc 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r94-4p2v-j8wm/GHSA-5r94-4p2v-j8wm.json +++ b/advisories/unreviewed/2022/05/GHSA-5r94-4p2v-j8wm/GHSA-5r94-4p2v-j8wm.json @@ -7,12 +7,8 @@ "CVE-2010-3188" ], "details": "SQL injection vulnerability in search.aspx in BugTracker.NET 3.4.3 and earlier allows remote attackers to execute arbitrary SQL commands via a custom field to the search page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5rrj-r5cm-jm8g/GHSA-5rrj-r5cm-jm8g.json b/advisories/unreviewed/2022/05/GHSA-5rrj-r5cm-jm8g/GHSA-5rrj-r5cm-jm8g.json index c62f1f55b2a..5d655ffbc0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5rrj-r5cm-jm8g/GHSA-5rrj-r5cm-jm8g.json +++ b/advisories/unreviewed/2022/05/GHSA-5rrj-r5cm-jm8g/GHSA-5rrj-r5cm-jm8g.json @@ -7,12 +7,8 @@ "CVE-2010-3591" ], "details": "Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Internal Operations. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from the original researcher that remote attackers can overwrite or delete arbitrary files via a full pathname in the second argument to the DownloadSingleMessageToFile method in the EMPOP3Lib ActiveX component (empop3.dll).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5vgp-64gj-j392/GHSA-5vgp-64gj-j392.json b/advisories/unreviewed/2022/05/GHSA-5vgp-64gj-j392/GHSA-5vgp-64gj-j392.json index 371203c931f..ff214c73248 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vgp-64gj-j392/GHSA-5vgp-64gj-j392.json +++ b/advisories/unreviewed/2022/05/GHSA-5vgp-64gj-j392/GHSA-5vgp-64gj-j392.json @@ -7,12 +7,8 @@ "CVE-2015-8358" ], "details": "Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the element name of the \"work\" array parameter to admin/bitrix.mpbuilder_step2.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5wf5-2g8j-x4fv/GHSA-5wf5-2g8j-x4fv.json b/advisories/unreviewed/2022/05/GHSA-5wf5-2g8j-x4fv/GHSA-5wf5-2g8j-x4fv.json index e250d63ec9b..9fa5d978661 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wf5-2g8j-x4fv/GHSA-5wf5-2g8j-x4fv.json +++ b/advisories/unreviewed/2022/05/GHSA-5wf5-2g8j-x4fv/GHSA-5wf5-2g8j-x4fv.json @@ -7,12 +7,8 @@ "CVE-2010-2582" ], "details": "An unspecified function in TextXtra.x32 in Adobe Shockwave Player before 11.5.9.615 does not properly reallocate a buffer when processing a DEMX chunk in a Director file, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5wgw-7mqx-h773/GHSA-5wgw-7mqx-h773.json b/advisories/unreviewed/2022/05/GHSA-5wgw-7mqx-h773/GHSA-5wgw-7mqx-h773.json index 8d2127cb86a..c143f98b6b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wgw-7mqx-h773/GHSA-5wgw-7mqx-h773.json +++ b/advisories/unreviewed/2022/05/GHSA-5wgw-7mqx-h773/GHSA-5wgw-7mqx-h773.json @@ -7,12 +7,8 @@ "CVE-2010-1552" ], "details": "Stack-based buffer overflow in the doLoad function in snmpviewer.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via the act and app parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5whq-5j94-gxvc/GHSA-5whq-5j94-gxvc.json b/advisories/unreviewed/2022/05/GHSA-5whq-5j94-gxvc/GHSA-5whq-5j94-gxvc.json index 42f9a773c50..ead702c9edc 100644 --- a/advisories/unreviewed/2022/05/GHSA-5whq-5j94-gxvc/GHSA-5whq-5j94-gxvc.json +++ b/advisories/unreviewed/2022/05/GHSA-5whq-5j94-gxvc/GHSA-5whq-5j94-gxvc.json @@ -7,12 +7,8 @@ "CVE-2010-1929" ], "details": "Multiple stack-based buffer overflows in the jclient._Java_novell_jclient_JClient_defineClass@20 function in jclient.dll in the Tomcat web server in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allow remote authenticated users to execute arbitrary code via the (1) EnteredClassID or (2) NewClassName parameter to nps/servlet/webacc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6254-xw9g-fpq3/GHSA-6254-xw9g-fpq3.json b/advisories/unreviewed/2022/05/GHSA-6254-xw9g-fpq3/GHSA-6254-xw9g-fpq3.json index c44dbe5dcc4..3503dd99e06 100644 --- a/advisories/unreviewed/2022/05/GHSA-6254-xw9g-fpq3/GHSA-6254-xw9g-fpq3.json +++ b/advisories/unreviewed/2022/05/GHSA-6254-xw9g-fpq3/GHSA-6254-xw9g-fpq3.json @@ -7,12 +7,8 @@ "CVE-2015-6944" ], "details": "Cross-site request forgery (CSRF) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to hijack the authentication of users for requests that execute arbitrary SQL commands via the cmd parameter to sys/sys/listaBD2.jsp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-626q-gj8m-2m4w/GHSA-626q-gj8m-2m4w.json b/advisories/unreviewed/2022/05/GHSA-626q-gj8m-2m4w/GHSA-626q-gj8m-2m4w.json index c60f37f1d3e..4ffb106c13b 100644 --- a/advisories/unreviewed/2022/05/GHSA-626q-gj8m-2m4w/GHSA-626q-gj8m-2m4w.json +++ b/advisories/unreviewed/2022/05/GHSA-626q-gj8m-2m4w/GHSA-626q-gj8m-2m4w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-63f8-cmv9-r78g/GHSA-63f8-cmv9-r78g.json b/advisories/unreviewed/2022/05/GHSA-63f8-cmv9-r78g/GHSA-63f8-cmv9-r78g.json index 93b377c4597..bf1844589c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-63f8-cmv9-r78g/GHSA-63f8-cmv9-r78g.json +++ b/advisories/unreviewed/2022/05/GHSA-63f8-cmv9-r78g/GHSA-63f8-cmv9-r78g.json @@ -7,12 +7,8 @@ "CVE-2010-3026" ], "details": "Cross-site request forgery (CSRF) vulnerability in application/modules/admin/controllers/users.php in Tomaz Muraus Open Blog 1.2.1, and possibly earlier, allows remote attackers to hijack the authentication of administrators for requests to admin/users/edit that grant administrative privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-63fc-gfcm-9g58/GHSA-63fc-gfcm-9g58.json b/advisories/unreviewed/2022/05/GHSA-63fc-gfcm-9g58/GHSA-63fc-gfcm-9g58.json index f917e658e52..ca6adb8d11f 100644 --- a/advisories/unreviewed/2022/05/GHSA-63fc-gfcm-9g58/GHSA-63fc-gfcm-9g58.json +++ b/advisories/unreviewed/2022/05/GHSA-63fc-gfcm-9g58/GHSA-63fc-gfcm-9g58.json @@ -7,12 +7,8 @@ "CVE-2015-7365" ], "details": "Cross-site scripting (XSS) vulnerability in the plugin upgrade form in Revive Adserver before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via the filename of an uploaded file containing errors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-63v4-64x6-h6c2/GHSA-63v4-64x6-h6c2.json b/advisories/unreviewed/2022/05/GHSA-63v4-64x6-h6c2/GHSA-63v4-64x6-h6c2.json index ec65b294629..c2134eccab0 100644 --- a/advisories/unreviewed/2022/05/GHSA-63v4-64x6-h6c2/GHSA-63v4-64x6-h6c2.json +++ b/advisories/unreviewed/2022/05/GHSA-63v4-64x6-h6c2/GHSA-63v4-64x6-h6c2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6437-r6f2-89jm/GHSA-6437-r6f2-89jm.json b/advisories/unreviewed/2022/05/GHSA-6437-r6f2-89jm/GHSA-6437-r6f2-89jm.json index 17279c2f06d..eb2647dddff 100644 --- a/advisories/unreviewed/2022/05/GHSA-6437-r6f2-89jm/GHSA-6437-r6f2-89jm.json +++ b/advisories/unreviewed/2022/05/GHSA-6437-r6f2-89jm/GHSA-6437-r6f2-89jm.json @@ -7,12 +7,8 @@ "CVE-2015-5465" ], "details": "Silicon Integrated Systems WindowsXP Display Manager (aka VGA Driver Manager and VGA Display Manager) 6.14.10.3930 allows local users to gain privileges via a crafted (1) 0x96002400 or (2) 0x96002404 IOCTL call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-646w-wh89-prgp/GHSA-646w-wh89-prgp.json b/advisories/unreviewed/2022/05/GHSA-646w-wh89-prgp/GHSA-646w-wh89-prgp.json index f8342bd064f..e3fa60cd672 100644 --- a/advisories/unreviewed/2022/05/GHSA-646w-wh89-prgp/GHSA-646w-wh89-prgp.json +++ b/advisories/unreviewed/2022/05/GHSA-646w-wh89-prgp/GHSA-646w-wh89-prgp.json @@ -7,12 +7,8 @@ "CVE-2010-2288" ], "details": "Cross-site scripting (XSS) vulnerability in dana/nc/ncrun.cgi in Juniper Networks IVE 6.5R1 (Build 14599) and 6.5R2 (Build 14951) allows remote attackers to inject arbitrary web script or HTML via the DSSignInURL cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6536-qjrp-px99/GHSA-6536-qjrp-px99.json b/advisories/unreviewed/2022/05/GHSA-6536-qjrp-px99/GHSA-6536-qjrp-px99.json index 4e9ad0178f0..79b7349d1ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-6536-qjrp-px99/GHSA-6536-qjrp-px99.json +++ b/advisories/unreviewed/2022/05/GHSA-6536-qjrp-px99/GHSA-6536-qjrp-px99.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-65c2-q87w-94qp/GHSA-65c2-q87w-94qp.json b/advisories/unreviewed/2022/05/GHSA-65c2-q87w-94qp/GHSA-65c2-q87w-94qp.json index 86880f9b3a6..dd57c8d7d46 100644 --- a/advisories/unreviewed/2022/05/GHSA-65c2-q87w-94qp/GHSA-65c2-q87w-94qp.json +++ b/advisories/unreviewed/2022/05/GHSA-65c2-q87w-94qp/GHSA-65c2-q87w-94qp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-65pv-899r-xfp7/GHSA-65pv-899r-xfp7.json b/advisories/unreviewed/2022/05/GHSA-65pv-899r-xfp7/GHSA-65pv-899r-xfp7.json index 84a340615e5..39fb18213ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-65pv-899r-xfp7/GHSA-65pv-899r-xfp7.json +++ b/advisories/unreviewed/2022/05/GHSA-65pv-899r-xfp7/GHSA-65pv-899r-xfp7.json @@ -7,12 +7,8 @@ "CVE-2010-2506" ], "details": "Cross-site scripting (XSS) vulnerability in debug.cgi in Linksys WAP54Gv3 firmware 3.05.03 and 3.04.03 allows remote attackers to inject arbitrary web script or HTML via the data1 parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-65xx-2x9j-ccgr/GHSA-65xx-2x9j-ccgr.json b/advisories/unreviewed/2022/05/GHSA-65xx-2x9j-ccgr/GHSA-65xx-2x9j-ccgr.json index 641b3ee9a6a..279ddc6c17c 100644 --- a/advisories/unreviewed/2022/05/GHSA-65xx-2x9j-ccgr/GHSA-65xx-2x9j-ccgr.json +++ b/advisories/unreviewed/2022/05/GHSA-65xx-2x9j-ccgr/GHSA-65xx-2x9j-ccgr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6633-q8p9-q38v/GHSA-6633-q8p9-q38v.json b/advisories/unreviewed/2022/05/GHSA-6633-q8p9-q38v/GHSA-6633-q8p9-q38v.json index b8c117346af..b5befb0ed27 100644 --- a/advisories/unreviewed/2022/05/GHSA-6633-q8p9-q38v/GHSA-6633-q8p9-q38v.json +++ b/advisories/unreviewed/2022/05/GHSA-6633-q8p9-q38v/GHSA-6633-q8p9-q38v.json @@ -7,12 +7,8 @@ "CVE-2015-5912" ], "details": "The CFNetwork FTPProtocol component in Apple iOS before 9 allows remote FTP proxy servers to trigger TCP connection attempts to intranet hosts via crafted responses.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6634-p5wf-9mgr/GHSA-6634-p5wf-9mgr.json b/advisories/unreviewed/2022/05/GHSA-6634-p5wf-9mgr/GHSA-6634-p5wf-9mgr.json index 32ea50b61a2..7f29b293454 100644 --- a/advisories/unreviewed/2022/05/GHSA-6634-p5wf-9mgr/GHSA-6634-p5wf-9mgr.json +++ b/advisories/unreviewed/2022/05/GHSA-6634-p5wf-9mgr/GHSA-6634-p5wf-9mgr.json @@ -7,12 +7,8 @@ "CVE-2015-3319" ], "details": "Hotspot Express hotEx Billing Manager 73 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6773-9q85-x9gw/GHSA-6773-9q85-x9gw.json b/advisories/unreviewed/2022/05/GHSA-6773-9q85-x9gw/GHSA-6773-9q85-x9gw.json index d3ec896577f..c8446c08c69 100644 --- a/advisories/unreviewed/2022/05/GHSA-6773-9q85-x9gw/GHSA-6773-9q85-x9gw.json +++ b/advisories/unreviewed/2022/05/GHSA-6773-9q85-x9gw/GHSA-6773-9q85-x9gw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67mr-6f82-p9vq/GHSA-67mr-6f82-p9vq.json b/advisories/unreviewed/2022/05/GHSA-67mr-6f82-p9vq/GHSA-67mr-6f82-p9vq.json index 8497dffcbc7..5e078366a7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-67mr-6f82-p9vq/GHSA-67mr-6f82-p9vq.json +++ b/advisories/unreviewed/2022/05/GHSA-67mr-6f82-p9vq/GHSA-67mr-6f82-p9vq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67p4-cqhr-52f5/GHSA-67p4-cqhr-52f5.json b/advisories/unreviewed/2022/05/GHSA-67p4-cqhr-52f5/GHSA-67p4-cqhr-52f5.json index 08e14db904a..cb207e46c11 100644 --- a/advisories/unreviewed/2022/05/GHSA-67p4-cqhr-52f5/GHSA-67p4-cqhr-52f5.json +++ b/advisories/unreviewed/2022/05/GHSA-67p4-cqhr-52f5/GHSA-67p4-cqhr-52f5.json @@ -7,12 +7,8 @@ "CVE-2015-6529" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in phpipam 1.1.010 allow remote attackers to inject arbitrary web script or HTML via the (1) section parameter to site/error.php or (2) ip parameter to site/tools/searchResults.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67pq-r8mx-qppw/GHSA-67pq-r8mx-qppw.json b/advisories/unreviewed/2022/05/GHSA-67pq-r8mx-qppw/GHSA-67pq-r8mx-qppw.json index 7738a04f0e7..ed173ef748f 100644 --- a/advisories/unreviewed/2022/05/GHSA-67pq-r8mx-qppw/GHSA-67pq-r8mx-qppw.json +++ b/advisories/unreviewed/2022/05/GHSA-67pq-r8mx-qppw/GHSA-67pq-r8mx-qppw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67rg-j83g-ppg2/GHSA-67rg-j83g-ppg2.json b/advisories/unreviewed/2022/05/GHSA-67rg-j83g-ppg2/GHSA-67rg-j83g-ppg2.json index acbe98ca30b..0316382555f 100644 --- a/advisories/unreviewed/2022/05/GHSA-67rg-j83g-ppg2/GHSA-67rg-j83g-ppg2.json +++ b/advisories/unreviewed/2022/05/GHSA-67rg-j83g-ppg2/GHSA-67rg-j83g-ppg2.json @@ -7,12 +7,8 @@ "CVE-2010-1628" ], "details": "Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent attackers to execute arbitrary code via a PostScript file containing unlimited recursive procedure invocations, which trigger memory corruption in the stack of the interpreter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68hw-3j5m-5hrv/GHSA-68hw-3j5m-5hrv.json b/advisories/unreviewed/2022/05/GHSA-68hw-3j5m-5hrv/GHSA-68hw-3j5m-5hrv.json index a8ca77efe63..e741c8df4d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-68hw-3j5m-5hrv/GHSA-68hw-3j5m-5hrv.json +++ b/advisories/unreviewed/2022/05/GHSA-68hw-3j5m-5hrv/GHSA-68hw-3j5m-5hrv.json @@ -7,12 +7,8 @@ "CVE-2015-4038" ], "details": "The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_settings action to wp-admin/admin-ajax.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-68qg-cgxp-wxcf/GHSA-68qg-cgxp-wxcf.json b/advisories/unreviewed/2022/05/GHSA-68qg-cgxp-wxcf/GHSA-68qg-cgxp-wxcf.json index ef9ffcdd304..c2a070448fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-68qg-cgxp-wxcf/GHSA-68qg-cgxp-wxcf.json +++ b/advisories/unreviewed/2022/05/GHSA-68qg-cgxp-wxcf/GHSA-68qg-cgxp-wxcf.json @@ -7,12 +7,8 @@ "CVE-2015-3294" ], "details": "The tcp_request function in Dnsmasq before 2.73rc4 does not properly handle the return value of the setup_reply function, which allows remote attackers to read process memory and cause a denial of service (out-of-bounds read and crash) via a malformed DNS request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-69cp-8qx2-fq5h/GHSA-69cp-8qx2-fq5h.json b/advisories/unreviewed/2022/05/GHSA-69cp-8qx2-fq5h/GHSA-69cp-8qx2-fq5h.json index 5d0d2f94108..02c8093b3ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-69cp-8qx2-fq5h/GHSA-69cp-8qx2-fq5h.json +++ b/advisories/unreviewed/2022/05/GHSA-69cp-8qx2-fq5h/GHSA-69cp-8qx2-fq5h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6c5v-7rg2-fmv9/GHSA-6c5v-7rg2-fmv9.json b/advisories/unreviewed/2022/05/GHSA-6c5v-7rg2-fmv9/GHSA-6c5v-7rg2-fmv9.json index d948711bb64..b09bce1e697 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c5v-7rg2-fmv9/GHSA-6c5v-7rg2-fmv9.json +++ b/advisories/unreviewed/2022/05/GHSA-6c5v-7rg2-fmv9/GHSA-6c5v-7rg2-fmv9.json @@ -7,12 +7,8 @@ "CVE-2010-3273" ], "details": "ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allows remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, by providing a user id to accounts/ValidateUser, and then providing a new password to accounts/ResetResult.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6c8c-f2w2-jvjr/GHSA-6c8c-f2w2-jvjr.json b/advisories/unreviewed/2022/05/GHSA-6c8c-f2w2-jvjr/GHSA-6c8c-f2w2-jvjr.json index cf2c211851b..7be4da88c3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c8c-f2w2-jvjr/GHSA-6c8c-f2w2-jvjr.json +++ b/advisories/unreviewed/2022/05/GHSA-6c8c-f2w2-jvjr/GHSA-6c8c-f2w2-jvjr.json @@ -7,12 +7,8 @@ "CVE-2015-2351" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms 9.5.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) homelink parameter to system/modules/org.opencms.workplace.help/jsptemplates/help_head.jsp, (2) workplaceresource parameter to system/workplace/locales/en/help/index.html, (3) path parameter to system/workplace/views/admin/admin-main.jsp, (4) mode parameter to system/workplace/views/explorer/explorer_files.jsp, or (5) query parameter in a search action to system/modules/org.opencms.workplace.help/elements/search.jsp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6cwv-j9pr-gj3p/GHSA-6cwv-j9pr-gj3p.json b/advisories/unreviewed/2022/05/GHSA-6cwv-j9pr-gj3p/GHSA-6cwv-j9pr-gj3p.json index 70537829a0c..c74a33eeb64 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cwv-j9pr-gj3p/GHSA-6cwv-j9pr-gj3p.json +++ b/advisories/unreviewed/2022/05/GHSA-6cwv-j9pr-gj3p/GHSA-6cwv-j9pr-gj3p.json @@ -7,12 +7,8 @@ "CVE-2010-2864" ], "details": "IML32.dll in Adobe Shockwave Player before 11.5.8.612 does not properly parse .dir files, which allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a malformed file containing an invalid value, as demonstrated by a value at position 0x24C6 of a certain file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fcj-rv73-f37c/GHSA-6fcj-rv73-f37c.json b/advisories/unreviewed/2022/05/GHSA-6fcj-rv73-f37c/GHSA-6fcj-rv73-f37c.json index e4a3c3caadd..1bc57f3d99e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fcj-rv73-f37c/GHSA-6fcj-rv73-f37c.json +++ b/advisories/unreviewed/2022/05/GHSA-6fcj-rv73-f37c/GHSA-6fcj-rv73-f37c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fjg-xx96-px9q/GHSA-6fjg-xx96-px9q.json b/advisories/unreviewed/2022/05/GHSA-6fjg-xx96-px9q/GHSA-6fjg-xx96-px9q.json index a1e77bce47b..3d147c3e893 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fjg-xx96-px9q/GHSA-6fjg-xx96-px9q.json +++ b/advisories/unreviewed/2022/05/GHSA-6fjg-xx96-px9q/GHSA-6fjg-xx96-px9q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6fvr-rxw2-r84r/GHSA-6fvr-rxw2-r84r.json b/advisories/unreviewed/2022/05/GHSA-6fvr-rxw2-r84r/GHSA-6fvr-rxw2-r84r.json index 6d0815b639b..95bad23f190 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fvr-rxw2-r84r/GHSA-6fvr-rxw2-r84r.json +++ b/advisories/unreviewed/2022/05/GHSA-6fvr-rxw2-r84r/GHSA-6fvr-rxw2-r84r.json @@ -7,12 +7,8 @@ "CVE-2015-5066" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) content or (2) title field in an add action in the posts page to index.php or the (3) q parameter in the posts page to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6g39-3h52-rrwg/GHSA-6g39-3h52-rrwg.json b/advisories/unreviewed/2022/05/GHSA-6g39-3h52-rrwg/GHSA-6g39-3h52-rrwg.json index bc413a66e0f..075824eeda8 100644 --- a/advisories/unreviewed/2022/05/GHSA-6g39-3h52-rrwg/GHSA-6g39-3h52-rrwg.json +++ b/advisories/unreviewed/2022/05/GHSA-6g39-3h52-rrwg/GHSA-6g39-3h52-rrwg.json @@ -7,12 +7,8 @@ "CVE-2010-3684" ], "details": "The FTP authentication module in Synology Disk Station 2.x logs passwords to the web application interface in cases of incorrect login attempts, which allows local users to obtain sensitive information by reading a log, a different vulnerability than CVE-2010-2453.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6hpf-f449-cv2w/GHSA-6hpf-f449-cv2w.json b/advisories/unreviewed/2022/05/GHSA-6hpf-f449-cv2w/GHSA-6hpf-f449-cv2w.json index a14e8053ed6..8a5b946398a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hpf-f449-cv2w/GHSA-6hpf-f449-cv2w.json +++ b/advisories/unreviewed/2022/05/GHSA-6hpf-f449-cv2w/GHSA-6hpf-f449-cv2w.json @@ -7,12 +7,8 @@ "CVE-2015-2195" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the WP Media Cleaner plugin 2.2.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) view, (2) paged, or (3) s parameter in the wp-media-cleaner page to wp-admin/upload.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6hx8-gphh-c84p/GHSA-6hx8-gphh-c84p.json b/advisories/unreviewed/2022/05/GHSA-6hx8-gphh-c84p/GHSA-6hx8-gphh-c84p.json index feeeb7771fa..3a2fa77f90c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hx8-gphh-c84p/GHSA-6hx8-gphh-c84p.json +++ b/advisories/unreviewed/2022/05/GHSA-6hx8-gphh-c84p/GHSA-6hx8-gphh-c84p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6jrh-cqm6-j7wr/GHSA-6jrh-cqm6-j7wr.json b/advisories/unreviewed/2022/05/GHSA-6jrh-cqm6-j7wr/GHSA-6jrh-cqm6-j7wr.json index 1e6731c3a9f..3ac2748f96f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jrh-cqm6-j7wr/GHSA-6jrh-cqm6-j7wr.json +++ b/advisories/unreviewed/2022/05/GHSA-6jrh-cqm6-j7wr/GHSA-6jrh-cqm6-j7wr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6pc3-xrhg-jfj4/GHSA-6pc3-xrhg-jfj4.json b/advisories/unreviewed/2022/05/GHSA-6pc3-xrhg-jfj4/GHSA-6pc3-xrhg-jfj4.json index 8b66e62179e..e1fe7a8481c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6pc3-xrhg-jfj4/GHSA-6pc3-xrhg-jfj4.json +++ b/advisories/unreviewed/2022/05/GHSA-6pc3-xrhg-jfj4/GHSA-6pc3-xrhg-jfj4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6rpw-2w6h-fv58/GHSA-6rpw-2w6h-fv58.json b/advisories/unreviewed/2022/05/GHSA-6rpw-2w6h-fv58/GHSA-6rpw-2w6h-fv58.json index faf9d5f1ce8..1ea1851c731 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rpw-2w6h-fv58/GHSA-6rpw-2w6h-fv58.json +++ b/advisories/unreviewed/2022/05/GHSA-6rpw-2w6h-fv58/GHSA-6rpw-2w6h-fv58.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6v95-wqcc-pxgg/GHSA-6v95-wqcc-pxgg.json b/advisories/unreviewed/2022/05/GHSA-6v95-wqcc-pxgg/GHSA-6v95-wqcc-pxgg.json index 9672ab7a4b9..bd3d1b74d47 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v95-wqcc-pxgg/GHSA-6v95-wqcc-pxgg.json +++ b/advisories/unreviewed/2022/05/GHSA-6v95-wqcc-pxgg/GHSA-6v95-wqcc-pxgg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6x36-g6m4-vv49/GHSA-6x36-g6m4-vv49.json b/advisories/unreviewed/2022/05/GHSA-6x36-g6m4-vv49/GHSA-6x36-g6m4-vv49.json index cce0d32aba8..c513d09bc30 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x36-g6m4-vv49/GHSA-6x36-g6m4-vv49.json +++ b/advisories/unreviewed/2022/05/GHSA-6x36-g6m4-vv49/GHSA-6x36-g6m4-vv49.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7239-34h3-rfwm/GHSA-7239-34h3-rfwm.json b/advisories/unreviewed/2022/05/GHSA-7239-34h3-rfwm/GHSA-7239-34h3-rfwm.json index 3f29062e2f8..b764ae1563f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7239-34h3-rfwm/GHSA-7239-34h3-rfwm.json +++ b/advisories/unreviewed/2022/05/GHSA-7239-34h3-rfwm/GHSA-7239-34h3-rfwm.json @@ -7,12 +7,8 @@ "CVE-2010-2599" ], "details": "Unspecified vulnerability in Research In Motion (RIM) BlackBerry Device Software before 6.0.0 allows remote attackers to cause a denial of service (browser hang) via a crafted web page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-72hv-24f4-rg82/GHSA-72hv-24f4-rg82.json b/advisories/unreviewed/2022/05/GHSA-72hv-24f4-rg82/GHSA-72hv-24f4-rg82.json index 92c0aad9e70..d33f01b77bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-72hv-24f4-rg82/GHSA-72hv-24f4-rg82.json +++ b/advisories/unreviewed/2022/05/GHSA-72hv-24f4-rg82/GHSA-72hv-24f4-rg82.json @@ -7,12 +7,8 @@ "CVE-2010-2159" ], "details": "Dameng DM Database Server allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors related to the SP_DEL_BAK_EXPIRED procedure in wdm_dll.dll, which triggers memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-74v8-73cc-7h5v/GHSA-74v8-73cc-7h5v.json b/advisories/unreviewed/2022/05/GHSA-74v8-73cc-7h5v/GHSA-74v8-73cc-7h5v.json index 62af4aeb1f0..467f17b231a 100644 --- a/advisories/unreviewed/2022/05/GHSA-74v8-73cc-7h5v/GHSA-74v8-73cc-7h5v.json +++ b/advisories/unreviewed/2022/05/GHSA-74v8-73cc-7h5v/GHSA-74v8-73cc-7h5v.json @@ -7,12 +7,8 @@ "CVE-2015-5535" ], "details": "Cross-site scripting (XSS) vulnerability in the qTranslate plugin 2.5.39 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the edit parameter in the qtranslate page to wp-admin/options-general.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-74x2-79f4-hv52/GHSA-74x2-79f4-hv52.json b/advisories/unreviewed/2022/05/GHSA-74x2-79f4-hv52/GHSA-74x2-79f4-hv52.json index 862e9e4e7e7..d22ff5a7691 100644 --- a/advisories/unreviewed/2022/05/GHSA-74x2-79f4-hv52/GHSA-74x2-79f4-hv52.json +++ b/advisories/unreviewed/2022/05/GHSA-74x2-79f4-hv52/GHSA-74x2-79f4-hv52.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-74x7-mfvg-h2wf/GHSA-74x7-mfvg-h2wf.json b/advisories/unreviewed/2022/05/GHSA-74x7-mfvg-h2wf/GHSA-74x7-mfvg-h2wf.json index 27d48b58233..a107bdf772e 100644 --- a/advisories/unreviewed/2022/05/GHSA-74x7-mfvg-h2wf/GHSA-74x7-mfvg-h2wf.json +++ b/advisories/unreviewed/2022/05/GHSA-74x7-mfvg-h2wf/GHSA-74x7-mfvg-h2wf.json @@ -7,12 +7,8 @@ "CVE-2010-2574" ], "details": "Cross-site scripting (XSS) vulnerability in manage_proj_cat_add.php in MantisBT 1.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the name parameter in an Add Category action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-76fp-ch2g-r32f/GHSA-76fp-ch2g-r32f.json b/advisories/unreviewed/2022/05/GHSA-76fp-ch2g-r32f/GHSA-76fp-ch2g-r32f.json index f49783334c3..50d1672ca70 100644 --- a/advisories/unreviewed/2022/05/GHSA-76fp-ch2g-r32f/GHSA-76fp-ch2g-r32f.json +++ b/advisories/unreviewed/2022/05/GHSA-76fp-ch2g-r32f/GHSA-76fp-ch2g-r32f.json @@ -7,12 +7,8 @@ "CVE-2015-2803" ], "details": "SQL injection vulnerability in mod1/index.php in the Akronymmanager (sb_akronymmanager) extension before 7.0.0 for TYPO3 allows remote authenticated users with permission to maintain acronyms to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-76m8-jpg6-q7xf/GHSA-76m8-jpg6-q7xf.json b/advisories/unreviewed/2022/05/GHSA-76m8-jpg6-q7xf/GHSA-76m8-jpg6-q7xf.json index c9512033736..b4900f88546 100644 --- a/advisories/unreviewed/2022/05/GHSA-76m8-jpg6-q7xf/GHSA-76m8-jpg6-q7xf.json +++ b/advisories/unreviewed/2022/05/GHSA-76m8-jpg6-q7xf/GHSA-76m8-jpg6-q7xf.json @@ -7,12 +7,8 @@ "CVE-2015-6535" ], "details": "Cross-site scripting (XSS) vulnerability in includes/options-profiles.php in the YouTube Embed plugin before 3.3.3 for WordPress allows remote administrators to inject arbitrary web script or HTML via the Profile name field (youtube_embed_name parameter).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-76mr-hhhx-xpg8/GHSA-76mr-hhhx-xpg8.json b/advisories/unreviewed/2022/05/GHSA-76mr-hhhx-xpg8/GHSA-76mr-hhhx-xpg8.json index f45e4b910fc..a7bbae853c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-76mr-hhhx-xpg8/GHSA-76mr-hhhx-xpg8.json +++ b/advisories/unreviewed/2022/05/GHSA-76mr-hhhx-xpg8/GHSA-76mr-hhhx-xpg8.json @@ -7,12 +7,8 @@ "CVE-2015-2997" ], "details": "SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the accountid parameter to getAgentLogFile, as demonstrated by a large directory traversal sequence, which reveals the installation path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-772g-m8r9-pg2f/GHSA-772g-m8r9-pg2f.json b/advisories/unreviewed/2022/05/GHSA-772g-m8r9-pg2f/GHSA-772g-m8r9-pg2f.json index 7c7e1642cf9..b4c159a7cd6 100644 --- a/advisories/unreviewed/2022/05/GHSA-772g-m8r9-pg2f/GHSA-772g-m8r9-pg2f.json +++ b/advisories/unreviewed/2022/05/GHSA-772g-m8r9-pg2f/GHSA-772g-m8r9-pg2f.json @@ -7,12 +7,8 @@ "CVE-2010-1960" ], "details": "Buffer overflow in the error handling functionality in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long, invalid option to jovgraph.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-782c-7gx2-qx9f/GHSA-782c-7gx2-qx9f.json b/advisories/unreviewed/2022/05/GHSA-782c-7gx2-qx9f/GHSA-782c-7gx2-qx9f.json index 2365cd6f367..5b022f8ea58 100644 --- a/advisories/unreviewed/2022/05/GHSA-782c-7gx2-qx9f/GHSA-782c-7gx2-qx9f.json +++ b/advisories/unreviewed/2022/05/GHSA-782c-7gx2-qx9f/GHSA-782c-7gx2-qx9f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-789q-8xrh-w2rw/GHSA-789q-8xrh-w2rw.json b/advisories/unreviewed/2022/05/GHSA-789q-8xrh-w2rw/GHSA-789q-8xrh-w2rw.json index a74e86b31d4..3f677612c19 100644 --- a/advisories/unreviewed/2022/05/GHSA-789q-8xrh-w2rw/GHSA-789q-8xrh-w2rw.json +++ b/advisories/unreviewed/2022/05/GHSA-789q-8xrh-w2rw/GHSA-789q-8xrh-w2rw.json @@ -7,12 +7,8 @@ "CVE-2010-1913" ], "details": "The default configuration of pluginlicense.ini for the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance, when downloaded from a server operated by Telefonica or possibly other companies, contains an incorrect DNS whitelist that includes the DNS hostnames of home computers of many persons, which allows remote attackers to bypass intended restrictions on ActiveX execution by hosting an ActiveX control on an applicable home web server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-78jh-f62f-p5r6/GHSA-78jh-f62f-p5r6.json b/advisories/unreviewed/2022/05/GHSA-78jh-f62f-p5r6/GHSA-78jh-f62f-p5r6.json index cc7a48f12e7..f04b12930cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-78jh-f62f-p5r6/GHSA-78jh-f62f-p5r6.json +++ b/advisories/unreviewed/2022/05/GHSA-78jh-f62f-p5r6/GHSA-78jh-f62f-p5r6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-796c-c9w7-xqff/GHSA-796c-c9w7-xqff.json b/advisories/unreviewed/2022/05/GHSA-796c-c9w7-xqff/GHSA-796c-c9w7-xqff.json index 1beb9d0d28a..6a0264f4bd5 100644 --- a/advisories/unreviewed/2022/05/GHSA-796c-c9w7-xqff/GHSA-796c-c9w7-xqff.json +++ b/advisories/unreviewed/2022/05/GHSA-796c-c9w7-xqff/GHSA-796c-c9w7-xqff.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-79pv-jchp-q27m/GHSA-79pv-jchp-q27m.json b/advisories/unreviewed/2022/05/GHSA-79pv-jchp-q27m/GHSA-79pv-jchp-q27m.json index b0a6e79f5c1..75a05305914 100644 --- a/advisories/unreviewed/2022/05/GHSA-79pv-jchp-q27m/GHSA-79pv-jchp-q27m.json +++ b/advisories/unreviewed/2022/05/GHSA-79pv-jchp-q27m/GHSA-79pv-jchp-q27m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7c42-8pjf-wmc2/GHSA-7c42-8pjf-wmc2.json b/advisories/unreviewed/2022/05/GHSA-7c42-8pjf-wmc2/GHSA-7c42-8pjf-wmc2.json index 8edbfa2fc32..b9bfe9fab75 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c42-8pjf-wmc2/GHSA-7c42-8pjf-wmc2.json +++ b/advisories/unreviewed/2022/05/GHSA-7c42-8pjf-wmc2/GHSA-7c42-8pjf-wmc2.json @@ -7,12 +7,8 @@ "CVE-2010-2006" ], "details": "Directory traversal vulnerability in op/op.Login.php in LetoDMS (formerly MyDMS) 1.7.2 and earlier allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7c58-vxq5-5v66/GHSA-7c58-vxq5-5v66.json b/advisories/unreviewed/2022/05/GHSA-7c58-vxq5-5v66/GHSA-7c58-vxq5-5v66.json index b307951c6ab..d621e462472 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c58-vxq5-5v66/GHSA-7c58-vxq5-5v66.json +++ b/advisories/unreviewed/2022/05/GHSA-7c58-vxq5-5v66/GHSA-7c58-vxq5-5v66.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7gr8-w8hh-763m/GHSA-7gr8-w8hh-763m.json b/advisories/unreviewed/2022/05/GHSA-7gr8-w8hh-763m/GHSA-7gr8-w8hh-763m.json index 68cdfdf27b1..a7f8534ec39 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gr8-w8hh-763m/GHSA-7gr8-w8hh-763m.json +++ b/advisories/unreviewed/2022/05/GHSA-7gr8-w8hh-763m/GHSA-7gr8-w8hh-763m.json @@ -7,12 +7,8 @@ "CVE-2015-6911" ], "details": "SQL injection vulnerability in Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary SQL commands via the id parameter to watchstatus.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7gr9-9892-q2w9/GHSA-7gr9-9892-q2w9.json b/advisories/unreviewed/2022/05/GHSA-7gr9-9892-q2w9/GHSA-7gr9-9892-q2w9.json index 00fc32d693c..45d6c3642e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gr9-9892-q2w9/GHSA-7gr9-9892-q2w9.json +++ b/advisories/unreviewed/2022/05/GHSA-7gr9-9892-q2w9/GHSA-7gr9-9892-q2w9.json @@ -7,12 +7,8 @@ "CVE-2015-2998" ], "details": "SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensitive information, as demonstrated by decrypting the database password in WEB-INF/conf/serverConf.xml.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7h9j-vqvh-xx69/GHSA-7h9j-vqvh-xx69.json b/advisories/unreviewed/2022/05/GHSA-7h9j-vqvh-xx69/GHSA-7h9j-vqvh-xx69.json index c1645e6ffd7..63d3d9a9e45 100644 --- a/advisories/unreviewed/2022/05/GHSA-7h9j-vqvh-xx69/GHSA-7h9j-vqvh-xx69.json +++ b/advisories/unreviewed/2022/05/GHSA-7h9j-vqvh-xx69/GHSA-7h9j-vqvh-xx69.json @@ -7,12 +7,8 @@ "CVE-2010-2590" ], "details": "Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Reports 2008 SP3 Fix Pack 3.2 allows remote attackers to execute arbitrary code via a long ServerResourceVersion property value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hgg-3xq5-3f3h/GHSA-7hgg-3xq5-3f3h.json b/advisories/unreviewed/2022/05/GHSA-7hgg-3xq5-3f3h/GHSA-7hgg-3xq5-3f3h.json index ec5543852e7..2a3e34c9d6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hgg-3xq5-3f3h/GHSA-7hgg-3xq5-3f3h.json +++ b/advisories/unreviewed/2022/05/GHSA-7hgg-3xq5-3f3h/GHSA-7hgg-3xq5-3f3h.json @@ -7,12 +7,8 @@ "CVE-2015-7319" ], "details": "SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to updating the username.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hh4-vqqp-5g89/GHSA-7hh4-vqqp-5g89.json b/advisories/unreviewed/2022/05/GHSA-7hh4-vqqp-5g89/GHSA-7hh4-vqqp-5g89.json index 186def2032b..320367228fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hh4-vqqp-5g89/GHSA-7hh4-vqqp-5g89.json +++ b/advisories/unreviewed/2022/05/GHSA-7hh4-vqqp-5g89/GHSA-7hh4-vqqp-5g89.json @@ -7,12 +7,8 @@ "CVE-2010-3613" ], "details": "named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and corresponding RRSIG records in the cache, which allows remote attackers to cause a denial of service (daemon crash) via a query for cached data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -168,9 +164,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7j7c-3gw5-prfg/GHSA-7j7c-3gw5-prfg.json b/advisories/unreviewed/2022/05/GHSA-7j7c-3gw5-prfg/GHSA-7j7c-3gw5-prfg.json index 640ee70dc0c..d97bacc8914 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j7c-3gw5-prfg/GHSA-7j7c-3gw5-prfg.json +++ b/advisories/unreviewed/2022/05/GHSA-7j7c-3gw5-prfg/GHSA-7j7c-3gw5-prfg.json @@ -7,12 +7,8 @@ "CVE-2015-2840" ], "details": "Cross-site scripting (XSS) vulnerability in help/rt/large_search.html in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to inject arbitrary web script or HTML via the searchQuery parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7mxf-xfr7-2j2f/GHSA-7mxf-xfr7-2j2f.json b/advisories/unreviewed/2022/05/GHSA-7mxf-xfr7-2j2f/GHSA-7mxf-xfr7-2j2f.json index 1dbdeee6412..6304804d0be 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mxf-xfr7-2j2f/GHSA-7mxf-xfr7-2j2f.json +++ b/advisories/unreviewed/2022/05/GHSA-7mxf-xfr7-2j2f/GHSA-7mxf-xfr7-2j2f.json @@ -7,12 +7,8 @@ "CVE-2015-5718" ], "details": "Stack-based buffer overflow in the handle_debug_network function in the manager in Websense Content Gateway before 8.0.0 HF02 allows remote administrators to cause a denial of service (crash) via a crafted diagnostic command line request to submit_net_debug.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7pgq-9248-43gw/GHSA-7pgq-9248-43gw.json b/advisories/unreviewed/2022/05/GHSA-7pgq-9248-43gw/GHSA-7pgq-9248-43gw.json index f7fb6c1b449..16f9a91e9a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pgq-9248-43gw/GHSA-7pgq-9248-43gw.json +++ b/advisories/unreviewed/2022/05/GHSA-7pgq-9248-43gw/GHSA-7pgq-9248-43gw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7ph9-gcf6-q9w4/GHSA-7ph9-gcf6-q9w4.json b/advisories/unreviewed/2022/05/GHSA-7ph9-gcf6-q9w4/GHSA-7ph9-gcf6-q9w4.json index 52d2cd17096..9c7715080cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-7ph9-gcf6-q9w4/GHSA-7ph9-gcf6-q9w4.json +++ b/advisories/unreviewed/2022/05/GHSA-7ph9-gcf6-q9w4/GHSA-7ph9-gcf6-q9w4.json @@ -7,12 +7,8 @@ "CVE-2015-7377" ], "details": "Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7r78-jwvv-47q7/GHSA-7r78-jwvv-47q7.json b/advisories/unreviewed/2022/05/GHSA-7r78-jwvv-47q7/GHSA-7r78-jwvv-47q7.json index c71b2747d8a..c10752480ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-7r78-jwvv-47q7/GHSA-7r78-jwvv-47q7.json +++ b/advisories/unreviewed/2022/05/GHSA-7r78-jwvv-47q7/GHSA-7r78-jwvv-47q7.json @@ -7,12 +7,8 @@ "CVE-2015-7371" ], "details": "Revive Adserver before 3.2.2 does not restrict access to run-mpe.php, which allows remote attackers to run the Maintenance Priority Engine and possibly cause a denial of service (resource consumption) via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7r96-6597-rqx6/GHSA-7r96-6597-rqx6.json b/advisories/unreviewed/2022/05/GHSA-7r96-6597-rqx6/GHSA-7r96-6597-rqx6.json index 84697cd67ca..fc3fdce506f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7r96-6597-rqx6/GHSA-7r96-6597-rqx6.json +++ b/advisories/unreviewed/2022/05/GHSA-7r96-6597-rqx6/GHSA-7r96-6597-rqx6.json @@ -7,12 +7,8 @@ "CVE-2010-2032" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) digest_realm or (2) digest_username parameters. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7rgg-pch4-83jc/GHSA-7rgg-pch4-83jc.json b/advisories/unreviewed/2022/05/GHSA-7rgg-pch4-83jc/GHSA-7rgg-pch4-83jc.json index 943117de258..04758a280da 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rgg-pch4-83jc/GHSA-7rgg-pch4-83jc.json +++ b/advisories/unreviewed/2022/05/GHSA-7rgg-pch4-83jc/GHSA-7rgg-pch4-83jc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7vf3-wj79-c6q5/GHSA-7vf3-wj79-c6q5.json b/advisories/unreviewed/2022/05/GHSA-7vf3-wj79-c6q5/GHSA-7vf3-wj79-c6q5.json index 9f42d2a1c68..13fc66edd0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vf3-wj79-c6q5/GHSA-7vf3-wj79-c6q5.json +++ b/advisories/unreviewed/2022/05/GHSA-7vf3-wj79-c6q5/GHSA-7vf3-wj79-c6q5.json @@ -7,12 +7,8 @@ "CVE-2010-3201" ], "details": "Cross-site scripting (XSS) vulnerability in NetWin Surgemail before 4.3g allows remote attackers to inject arbitrary web script or HTML via the username_ex parameter to the surgeweb program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7vg8-m2g2-c979/GHSA-7vg8-m2g2-c979.json b/advisories/unreviewed/2022/05/GHSA-7vg8-m2g2-c979/GHSA-7vg8-m2g2-c979.json index 58d9feec862..b5c95c6413a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vg8-m2g2-c979/GHSA-7vg8-m2g2-c979.json +++ b/advisories/unreviewed/2022/05/GHSA-7vg8-m2g2-c979/GHSA-7vg8-m2g2-c979.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-828p-3vwg-wc22/GHSA-828p-3vwg-wc22.json b/advisories/unreviewed/2022/05/GHSA-828p-3vwg-wc22/GHSA-828p-3vwg-wc22.json index 296f5d20990..d5d8b7ce335 100644 --- a/advisories/unreviewed/2022/05/GHSA-828p-3vwg-wc22/GHSA-828p-3vwg-wc22.json +++ b/advisories/unreviewed/2022/05/GHSA-828p-3vwg-wc22/GHSA-828p-3vwg-wc22.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-839c-vxrv-chvh/GHSA-839c-vxrv-chvh.json b/advisories/unreviewed/2022/05/GHSA-839c-vxrv-chvh/GHSA-839c-vxrv-chvh.json index 58c6ad56d7d..9f2423a1b8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-839c-vxrv-chvh/GHSA-839c-vxrv-chvh.json +++ b/advisories/unreviewed/2022/05/GHSA-839c-vxrv-chvh/GHSA-839c-vxrv-chvh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-83g3-wqqh-89wg/GHSA-83g3-wqqh-89wg.json b/advisories/unreviewed/2022/05/GHSA-83g3-wqqh-89wg/GHSA-83g3-wqqh-89wg.json index f01708df418..07ab95eede8 100644 --- a/advisories/unreviewed/2022/05/GHSA-83g3-wqqh-89wg/GHSA-83g3-wqqh-89wg.json +++ b/advisories/unreviewed/2022/05/GHSA-83g3-wqqh-89wg/GHSA-83g3-wqqh-89wg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-83jm-v9m6-fc87/GHSA-83jm-v9m6-fc87.json b/advisories/unreviewed/2022/05/GHSA-83jm-v9m6-fc87/GHSA-83jm-v9m6-fc87.json index 592fccbd082..60fc40528dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-83jm-v9m6-fc87/GHSA-83jm-v9m6-fc87.json +++ b/advisories/unreviewed/2022/05/GHSA-83jm-v9m6-fc87/GHSA-83jm-v9m6-fc87.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8435-jjpf-8g76/GHSA-8435-jjpf-8g76.json b/advisories/unreviewed/2022/05/GHSA-8435-jjpf-8g76/GHSA-8435-jjpf-8g76.json index e76327a75e3..1ee901a9371 100644 --- a/advisories/unreviewed/2022/05/GHSA-8435-jjpf-8g76/GHSA-8435-jjpf-8g76.json +++ b/advisories/unreviewed/2022/05/GHSA-8435-jjpf-8g76/GHSA-8435-jjpf-8g76.json @@ -7,12 +7,8 @@ "CVE-2010-2629" ], "details": "The Cisco Content Services Switch (CSS) 11500 with software 8.20.4.02 and the Application Control Engine (ACE) 4710 with software A2(3.0) do not properly handle LF header terminators in situations where the GET line is terminated by CRLF, which allows remote attackers to conduct HTTP request smuggling attacks and possibly bypass intended header insertions via crafted header data, as demonstrated by an LF character between the ClientCert-Subject and ClientCert-Subject-CN headers. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1576.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8657-w7wc-ccqj/GHSA-8657-w7wc-ccqj.json b/advisories/unreviewed/2022/05/GHSA-8657-w7wc-ccqj/GHSA-8657-w7wc-ccqj.json index 126b9927afa..9ece85171ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-8657-w7wc-ccqj/GHSA-8657-w7wc-ccqj.json +++ b/advisories/unreviewed/2022/05/GHSA-8657-w7wc-ccqj/GHSA-8657-w7wc-ccqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-866r-fqxj-hjhv/GHSA-866r-fqxj-hjhv.json b/advisories/unreviewed/2022/05/GHSA-866r-fqxj-hjhv/GHSA-866r-fqxj-hjhv.json index 58207a2d79e..03152488028 100644 --- a/advisories/unreviewed/2022/05/GHSA-866r-fqxj-hjhv/GHSA-866r-fqxj-hjhv.json +++ b/advisories/unreviewed/2022/05/GHSA-866r-fqxj-hjhv/GHSA-866r-fqxj-hjhv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-86h5-7c4r-g3gh/GHSA-86h5-7c4r-g3gh.json b/advisories/unreviewed/2022/05/GHSA-86h5-7c4r-g3gh/GHSA-86h5-7c4r-g3gh.json index 342ba5fdcc7..8cfba5192b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-86h5-7c4r-g3gh/GHSA-86h5-7c4r-g3gh.json +++ b/advisories/unreviewed/2022/05/GHSA-86h5-7c4r-g3gh/GHSA-86h5-7c4r-g3gh.json @@ -7,12 +7,8 @@ "CVE-2015-2746" ], "details": "The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliances before 7.8.4 Hotfix 02 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the \"second\" parameter of a command, as demonstrated by the Destination parameter in the ping command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8745-gh37-x9mm/GHSA-8745-gh37-x9mm.json b/advisories/unreviewed/2022/05/GHSA-8745-gh37-x9mm/GHSA-8745-gh37-x9mm.json index 9d28cf531dd..bb5b55376ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-8745-gh37-x9mm/GHSA-8745-gh37-x9mm.json +++ b/advisories/unreviewed/2022/05/GHSA-8745-gh37-x9mm/GHSA-8745-gh37-x9mm.json @@ -7,12 +7,8 @@ "CVE-2010-1510" ], "details": "Heap-based buffer overflow in IrfanView before 4.27 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PSD image with RLE compression.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-87f3-mch4-jp25/GHSA-87f3-mch4-jp25.json b/advisories/unreviewed/2022/05/GHSA-87f3-mch4-jp25/GHSA-87f3-mch4-jp25.json index c1ef2151237..638598e2165 100644 --- a/advisories/unreviewed/2022/05/GHSA-87f3-mch4-jp25/GHSA-87f3-mch4-jp25.json +++ b/advisories/unreviewed/2022/05/GHSA-87f3-mch4-jp25/GHSA-87f3-mch4-jp25.json @@ -7,12 +7,8 @@ "CVE-2015-4080" ], "details": "The Kankun Smart Socket device and mobile application uses a hardcoded AES 256 bit key, which makes it easier for remote attackers to (1) obtain sensitive information by sniffing the network and (2) obtain access to the device by encrypting messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-87x6-r7ff-7gv7/GHSA-87x6-r7ff-7gv7.json b/advisories/unreviewed/2022/05/GHSA-87x6-r7ff-7gv7/GHSA-87x6-r7ff-7gv7.json index fd4dc2e6b04..71e5a75bddd 100644 --- a/advisories/unreviewed/2022/05/GHSA-87x6-r7ff-7gv7/GHSA-87x6-r7ff-7gv7.json +++ b/advisories/unreviewed/2022/05/GHSA-87x6-r7ff-7gv7/GHSA-87x6-r7ff-7gv7.json @@ -7,12 +7,8 @@ "CVE-2015-8320" ], "details": "Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for attackers to conduct bridge hijacking attacks by predicting a value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-88qq-68fm-2rxx/GHSA-88qq-68fm-2rxx.json b/advisories/unreviewed/2022/05/GHSA-88qq-68fm-2rxx/GHSA-88qq-68fm-2rxx.json index 805f59d2121..203f2e81ded 100644 --- a/advisories/unreviewed/2022/05/GHSA-88qq-68fm-2rxx/GHSA-88qq-68fm-2rxx.json +++ b/advisories/unreviewed/2022/05/GHSA-88qq-68fm-2rxx/GHSA-88qq-68fm-2rxx.json @@ -7,12 +7,8 @@ "CVE-2010-2956" ], "details": "Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a \"-u root\" sequence.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -108,9 +104,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-897j-59mc-qfvp/GHSA-897j-59mc-qfvp.json b/advisories/unreviewed/2022/05/GHSA-897j-59mc-qfvp/GHSA-897j-59mc-qfvp.json index 9c520532f1b..b9a134cd9c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-897j-59mc-qfvp/GHSA-897j-59mc-qfvp.json +++ b/advisories/unreviewed/2022/05/GHSA-897j-59mc-qfvp/GHSA-897j-59mc-qfvp.json @@ -7,12 +7,8 @@ "CVE-2010-3699" ], "details": "The backend driver in Xen 3.x allows guest OS users to cause a denial of service via a kernel thread leak, which prevents the device and guest OS from being shut down or create a zombie domain, causes a hang in zenwatch, or prevents unspecified xm commands from working properly, related to (1) netback, (2) blkback, or (3) blktap.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-89w2-9cpg-466m/GHSA-89w2-9cpg-466m.json b/advisories/unreviewed/2022/05/GHSA-89w2-9cpg-466m/GHSA-89w2-9cpg-466m.json index 8228e152018..9774cd87150 100644 --- a/advisories/unreviewed/2022/05/GHSA-89w2-9cpg-466m/GHSA-89w2-9cpg-466m.json +++ b/advisories/unreviewed/2022/05/GHSA-89w2-9cpg-466m/GHSA-89w2-9cpg-466m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8cc3-q3fm-w335/GHSA-8cc3-q3fm-w335.json b/advisories/unreviewed/2022/05/GHSA-8cc3-q3fm-w335/GHSA-8cc3-q3fm-w335.json index 66273ccb72a..e118173e8c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cc3-q3fm-w335/GHSA-8cc3-q3fm-w335.json +++ b/advisories/unreviewed/2022/05/GHSA-8cc3-q3fm-w335/GHSA-8cc3-q3fm-w335.json @@ -7,12 +7,8 @@ "CVE-2010-2667" ], "details": "Multiple unspecified vulnerabilities in the Virtual Appliance Management Infrastructure (VAMI) in VMware Studio 2.0 allow remote authenticated users to execute arbitrary commands via vectors involving (1) the Studio virtual appliance or (2) a virtual appliance created by the Studio virtual appliance.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8fr7-79w9-7h79/GHSA-8fr7-79w9-7h79.json b/advisories/unreviewed/2022/05/GHSA-8fr7-79w9-7h79/GHSA-8fr7-79w9-7h79.json index 85c66311b92..6cb33fc52d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fr7-79w9-7h79/GHSA-8fr7-79w9-7h79.json +++ b/advisories/unreviewed/2022/05/GHSA-8fr7-79w9-7h79/GHSA-8fr7-79w9-7h79.json @@ -7,12 +7,8 @@ "CVE-2010-1513" ], "details": "Multiple integer overflows in src/image.c in Ziproxy before 3.0.1 allow remote attackers to execute arbitrary code via (1) a large JPG image, related to the jpg2bitmap function or (2) a large PNG image, related to the png2bitmap function, leading to heap-based buffer overflows.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8gpj-ff3f-jff9/GHSA-8gpj-ff3f-jff9.json b/advisories/unreviewed/2022/05/GHSA-8gpj-ff3f-jff9/GHSA-8gpj-ff3f-jff9.json index ac49ad3c7f6..bfe079a0435 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gpj-ff3f-jff9/GHSA-8gpj-ff3f-jff9.json +++ b/advisories/unreviewed/2022/05/GHSA-8gpj-ff3f-jff9/GHSA-8gpj-ff3f-jff9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8h3g-rghh-7ggv/GHSA-8h3g-rghh-7ggv.json b/advisories/unreviewed/2022/05/GHSA-8h3g-rghh-7ggv/GHSA-8h3g-rghh-7ggv.json index da3bdee2391..e3213496b0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h3g-rghh-7ggv/GHSA-8h3g-rghh-7ggv.json +++ b/advisories/unreviewed/2022/05/GHSA-8h3g-rghh-7ggv/GHSA-8h3g-rghh-7ggv.json @@ -7,12 +7,8 @@ "CVE-2010-2583" ], "details": "Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hj6-5qrp-85j3/GHSA-8hj6-5qrp-85j3.json b/advisories/unreviewed/2022/05/GHSA-8hj6-5qrp-85j3/GHSA-8hj6-5qrp-85j3.json index 1236fbe49c5..8a8fb3829eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hj6-5qrp-85j3/GHSA-8hj6-5qrp-85j3.json +++ b/advisories/unreviewed/2022/05/GHSA-8hj6-5qrp-85j3/GHSA-8hj6-5qrp-85j3.json @@ -7,12 +7,8 @@ "CVE-2010-2614" ], "details": "SQL injection vulnerability in admin/admin.php in Grafik CMS 1.1.2, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit_page action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8j6f-39hh-f4v6/GHSA-8j6f-39hh-f4v6.json b/advisories/unreviewed/2022/05/GHSA-8j6f-39hh-f4v6/GHSA-8j6f-39hh-f4v6.json index fd6d1a0223d..321baf2e19c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8j6f-39hh-f4v6/GHSA-8j6f-39hh-f4v6.json +++ b/advisories/unreviewed/2022/05/GHSA-8j6f-39hh-f4v6/GHSA-8j6f-39hh-f4v6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8j79-x4hx-j6c3/GHSA-8j79-x4hx-j6c3.json b/advisories/unreviewed/2022/05/GHSA-8j79-x4hx-j6c3/GHSA-8j79-x4hx-j6c3.json index 78c430fe0ff..a5cf3e4756f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8j79-x4hx-j6c3/GHSA-8j79-x4hx-j6c3.json +++ b/advisories/unreviewed/2022/05/GHSA-8j79-x4hx-j6c3/GHSA-8j79-x4hx-j6c3.json @@ -7,12 +7,8 @@ "CVE-2015-6357" ], "details": "The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certificate of the support.sourcefire.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide an invalid package, and consequently execute arbitrary code, via a crafted certificate, aka Bug ID CSCuw06444.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8mm8-vfx7-wq27/GHSA-8mm8-vfx7-wq27.json b/advisories/unreviewed/2022/05/GHSA-8mm8-vfx7-wq27/GHSA-8mm8-vfx7-wq27.json index 22e25a667ff..61e47e4474e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mm8-vfx7-wq27/GHSA-8mm8-vfx7-wq27.json +++ b/advisories/unreviewed/2022/05/GHSA-8mm8-vfx7-wq27/GHSA-8mm8-vfx7-wq27.json @@ -7,12 +7,8 @@ "CVE-2015-2839" ], "details": "The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an incorrect Content-Type when returning an error message, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the file_name JSON member in params/xen_hotfix/0 to nitro/v1/config/xen_hotfix.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8p45-j278-685f/GHSA-8p45-j278-685f.json b/advisories/unreviewed/2022/05/GHSA-8p45-j278-685f/GHSA-8p45-j278-685f.json index 1e0589327ef..42dba4260ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p45-j278-685f/GHSA-8p45-j278-685f.json +++ b/advisories/unreviewed/2022/05/GHSA-8p45-j278-685f/GHSA-8p45-j278-685f.json @@ -7,12 +7,8 @@ "CVE-2010-2122" ], "details": "Directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8vc2-2rf2-3grw/GHSA-8vc2-2rf2-3grw.json b/advisories/unreviewed/2022/05/GHSA-8vc2-2rf2-3grw/GHSA-8vc2-2rf2-3grw.json index bb3344f6b62..a414ca30503 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vc2-2rf2-3grw/GHSA-8vc2-2rf2-3grw.json +++ b/advisories/unreviewed/2022/05/GHSA-8vc2-2rf2-3grw/GHSA-8vc2-2rf2-3grw.json @@ -7,12 +7,8 @@ "CVE-2010-2679" ], "details": "SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8wcq-mc5g-xcxh/GHSA-8wcq-mc5g-xcxh.json b/advisories/unreviewed/2022/05/GHSA-8wcq-mc5g-xcxh/GHSA-8wcq-mc5g-xcxh.json index 3b9c126d60c..0cc8fff7b5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wcq-mc5g-xcxh/GHSA-8wcq-mc5g-xcxh.json +++ b/advisories/unreviewed/2022/05/GHSA-8wcq-mc5g-xcxh/GHSA-8wcq-mc5g-xcxh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8www-9hq8-f2fw/GHSA-8www-9hq8-f2fw.json b/advisories/unreviewed/2022/05/GHSA-8www-9hq8-f2fw/GHSA-8www-9hq8-f2fw.json index 3b486334aba..e9f32b91b6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8www-9hq8-f2fw/GHSA-8www-9hq8-f2fw.json +++ b/advisories/unreviewed/2022/05/GHSA-8www-9hq8-f2fw/GHSA-8www-9hq8-f2fw.json @@ -7,12 +7,8 @@ "CVE-2010-2294" ], "details": "Cross-site request forgery (CSRF) vulnerability in Plume CMS 1.2.4 and possibly earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xcr-mvw7-586w/GHSA-8xcr-mvw7-586w.json b/advisories/unreviewed/2022/05/GHSA-8xcr-mvw7-586w/GHSA-8xcr-mvw7-586w.json index c97ec7ab5c0..4213f84e1bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xcr-mvw7-586w/GHSA-8xcr-mvw7-586w.json +++ b/advisories/unreviewed/2022/05/GHSA-8xcr-mvw7-586w/GHSA-8xcr-mvw7-586w.json @@ -7,12 +7,8 @@ "CVE-2010-2261" ], "details": "Linksys WAP54Gv3 firmware 3.04.03 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) data2 and (2) data3 parameters to (a) Debug_command_page.asp and (b) debug.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xq7-7hcx-8p8g/GHSA-8xq7-7hcx-8p8g.json b/advisories/unreviewed/2022/05/GHSA-8xq7-7hcx-8p8g/GHSA-8xq7-7hcx-8p8g.json index 6c7987c951a..76b6c42d2d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xq7-7hcx-8p8g/GHSA-8xq7-7hcx-8p8g.json +++ b/advisories/unreviewed/2022/05/GHSA-8xq7-7hcx-8p8g/GHSA-8xq7-7hcx-8p8g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-926w-5gcg-788g/GHSA-926w-5gcg-788g.json b/advisories/unreviewed/2022/05/GHSA-926w-5gcg-788g/GHSA-926w-5gcg-788g.json index ae25617f746..15937c3104f 100644 --- a/advisories/unreviewed/2022/05/GHSA-926w-5gcg-788g/GHSA-926w-5gcg-788g.json +++ b/advisories/unreviewed/2022/05/GHSA-926w-5gcg-788g/GHSA-926w-5gcg-788g.json @@ -7,12 +7,8 @@ "CVE-2010-1994" ], "details": "SQL injection vulnerability in index.php in TomatoCMS before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the q parameter in conjunction with a /news/search PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9293-6mw7-gq5j/GHSA-9293-6mw7-gq5j.json b/advisories/unreviewed/2022/05/GHSA-9293-6mw7-gq5j/GHSA-9293-6mw7-gq5j.json index 5d62c66f4c8..bb2115ddf2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9293-6mw7-gq5j/GHSA-9293-6mw7-gq5j.json +++ b/advisories/unreviewed/2022/05/GHSA-9293-6mw7-gq5j/GHSA-9293-6mw7-gq5j.json @@ -7,12 +7,8 @@ "CVE-2015-6973" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password via a crafted request to user-password.jsp, (2) add users via a crafted request to user-create.jsp, (3) edit server settings or (4) disable SSL on the server via a crafted request to server-props.jsp, or (5) add clients via a crafted request to plugins/clientcontrol/permitted-clients.jsp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-92g5-j3jv-wrg5/GHSA-92g5-j3jv-wrg5.json b/advisories/unreviewed/2022/05/GHSA-92g5-j3jv-wrg5/GHSA-92g5-j3jv-wrg5.json index 349b3d339d6..26f1bdd01d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-92g5-j3jv-wrg5/GHSA-92g5-j3jv-wrg5.json +++ b/advisories/unreviewed/2022/05/GHSA-92g5-j3jv-wrg5/GHSA-92g5-j3jv-wrg5.json @@ -7,12 +7,8 @@ "CVE-2010-1905" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allow remote attackers to inject arbitrary web script or HTML via crafted input to ASP pages, as demonstrated using the backurl parameter to sdccommon/verify/asp/n6plugindestructor.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9352-59w4-wf59/GHSA-9352-59w4-wf59.json b/advisories/unreviewed/2022/05/GHSA-9352-59w4-wf59/GHSA-9352-59w4-wf59.json index 8ede5e9be21..0e98ffbd34c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9352-59w4-wf59/GHSA-9352-59w4-wf59.json +++ b/advisories/unreviewed/2022/05/GHSA-9352-59w4-wf59/GHSA-9352-59w4-wf59.json @@ -7,12 +7,8 @@ "CVE-2016-0602" ], "details": "Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 5.0.14 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Windows Installer. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is an untrusted search path issue that allows local users to gain privileges via a Trojan horse dll in the \"application directory.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-93x2-2w8g-55m7/GHSA-93x2-2w8g-55m7.json b/advisories/unreviewed/2022/05/GHSA-93x2-2w8g-55m7/GHSA-93x2-2w8g-55m7.json index f48511895f0..8d9041d1970 100644 --- a/advisories/unreviewed/2022/05/GHSA-93x2-2w8g-55m7/GHSA-93x2-2w8g-55m7.json +++ b/advisories/unreviewed/2022/05/GHSA-93x2-2w8g-55m7/GHSA-93x2-2w8g-55m7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-94rv-c2g3-rhrg/GHSA-94rv-c2g3-rhrg.json b/advisories/unreviewed/2022/05/GHSA-94rv-c2g3-rhrg/GHSA-94rv-c2g3-rhrg.json index e2c7cac3d1b..5b3a1e25616 100644 --- a/advisories/unreviewed/2022/05/GHSA-94rv-c2g3-rhrg/GHSA-94rv-c2g3-rhrg.json +++ b/advisories/unreviewed/2022/05/GHSA-94rv-c2g3-rhrg/GHSA-94rv-c2g3-rhrg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-95wc-36p6-5x3p/GHSA-95wc-36p6-5x3p.json b/advisories/unreviewed/2022/05/GHSA-95wc-36p6-5x3p/GHSA-95wc-36p6-5x3p.json index 0fa6af7a6f1..c7f146c9818 100644 --- a/advisories/unreviewed/2022/05/GHSA-95wc-36p6-5x3p/GHSA-95wc-36p6-5x3p.json +++ b/advisories/unreviewed/2022/05/GHSA-95wc-36p6-5x3p/GHSA-95wc-36p6-5x3p.json @@ -7,12 +7,8 @@ "CVE-2010-3566" ], "details": "Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update and 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow that leads to a buffer overflow via a crafted devs (device information) tag structure in a color profile.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -128,9 +124,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9648-3rxj-pc93/GHSA-9648-3rxj-pc93.json b/advisories/unreviewed/2022/05/GHSA-9648-3rxj-pc93/GHSA-9648-3rxj-pc93.json index 9522bddd8bf..a684cfcbdbc 100644 --- a/advisories/unreviewed/2022/05/GHSA-9648-3rxj-pc93/GHSA-9648-3rxj-pc93.json +++ b/advisories/unreviewed/2022/05/GHSA-9648-3rxj-pc93/GHSA-9648-3rxj-pc93.json @@ -7,12 +7,8 @@ "CVE-2010-3023" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in DiamondList 0.1.6, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) category[description] parameter to user/main/update_category, which is not properly handled by _app/views/categories/index.html.erb; and the (2) setting[site_title] parameter to user/main/update_settings, which is not properly handled by _app/views/settings/_list_settings.rhtml.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96vc-4h75-gh5j/GHSA-96vc-4h75-gh5j.json b/advisories/unreviewed/2022/05/GHSA-96vc-4h75-gh5j/GHSA-96vc-4h75-gh5j.json index 1094e5f3e03..fa2e6803187 100644 --- a/advisories/unreviewed/2022/05/GHSA-96vc-4h75-gh5j/GHSA-96vc-4h75-gh5j.json +++ b/advisories/unreviewed/2022/05/GHSA-96vc-4h75-gh5j/GHSA-96vc-4h75-gh5j.json @@ -7,12 +7,8 @@ "CVE-2010-2251" ], "details": "The get1 command, as used by lftpget, in LFTP before 4.0.6 does not properly validate a server-provided filename before determining the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-97jq-93xr-g8h2/GHSA-97jq-93xr-g8h2.json b/advisories/unreviewed/2022/05/GHSA-97jq-93xr-g8h2/GHSA-97jq-93xr-g8h2.json index be52f4df576..0cb62c19031 100644 --- a/advisories/unreviewed/2022/05/GHSA-97jq-93xr-g8h2/GHSA-97jq-93xr-g8h2.json +++ b/advisories/unreviewed/2022/05/GHSA-97jq-93xr-g8h2/GHSA-97jq-93xr-g8h2.json @@ -7,12 +7,8 @@ "CVE-2010-3583" ], "details": "Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to ovs-agent. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a third party researcher that this is related to the exposure of multiple unspecified functions through XML-RPC that allow execution of arbitrary OS commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-98ff-jmw6-p767/GHSA-98ff-jmw6-p767.json b/advisories/unreviewed/2022/05/GHSA-98ff-jmw6-p767/GHSA-98ff-jmw6-p767.json index b94ff644954..475537ae181 100644 --- a/advisories/unreviewed/2022/05/GHSA-98ff-jmw6-p767/GHSA-98ff-jmw6-p767.json +++ b/advisories/unreviewed/2022/05/GHSA-98ff-jmw6-p767/GHSA-98ff-jmw6-p767.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-98vw-3fg8-6q23/GHSA-98vw-3fg8-6q23.json b/advisories/unreviewed/2022/05/GHSA-98vw-3fg8-6q23/GHSA-98vw-3fg8-6q23.json index 72171da58d2..41cf38820ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-98vw-3fg8-6q23/GHSA-98vw-3fg8-6q23.json +++ b/advisories/unreviewed/2022/05/GHSA-98vw-3fg8-6q23/GHSA-98vw-3fg8-6q23.json @@ -7,12 +7,8 @@ "CVE-2015-2702" ], "details": "Cross-site scripting (XSS) vulnerability in the Message Log in the Email Security Gateway in Websense TRITON AP-EMAIL before 8.0.0 and V-Series 7.7 appliances allows remote attackers to inject arbitrary web script or HTML via the sender address in an email.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9965-949q-q7q9/GHSA-9965-949q-q7q9.json b/advisories/unreviewed/2022/05/GHSA-9965-949q-q7q9/GHSA-9965-949q-q7q9.json index 6bb57191a28..2c1a4d82d84 100644 --- a/advisories/unreviewed/2022/05/GHSA-9965-949q-q7q9/GHSA-9965-949q-q7q9.json +++ b/advisories/unreviewed/2022/05/GHSA-9965-949q-q7q9/GHSA-9965-949q-q7q9.json @@ -7,12 +7,8 @@ "CVE-2015-4119" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication of (1) administrators for requests that create an administrator account via a request to admin/users_edit.php or (2) arbitrary users for requests that conduct SQL injection attacks via the server parameter to monitor/show_sys_state.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9cjj-33q2-5pjr/GHSA-9cjj-33q2-5pjr.json b/advisories/unreviewed/2022/05/GHSA-9cjj-33q2-5pjr/GHSA-9cjj-33q2-5pjr.json index 317b037da21..d4ee1f3768e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cjj-33q2-5pjr/GHSA-9cjj-33q2-5pjr.json +++ b/advisories/unreviewed/2022/05/GHSA-9cjj-33q2-5pjr/GHSA-9cjj-33q2-5pjr.json @@ -7,12 +7,8 @@ "CVE-2010-2938" ], "details": "arch/x86/hvm/vmx/vmcs.c in the virtual-machine control structure (VMCS) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when an Intel platform without Extended Page Tables (EPT) functionality is used, accesses VMCS fields without verifying hardware support for these fields, which allows local users to cause a denial of service (host OS crash) by requesting a VMCS dump for a fully virtualized Xen guest.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9f8x-24h4-4p65/GHSA-9f8x-24h4-4p65.json b/advisories/unreviewed/2022/05/GHSA-9f8x-24h4-4p65/GHSA-9f8x-24h4-4p65.json index b2d43f544ec..fe33ca52542 100644 --- a/advisories/unreviewed/2022/05/GHSA-9f8x-24h4-4p65/GHSA-9f8x-24h4-4p65.json +++ b/advisories/unreviewed/2022/05/GHSA-9f8x-24h4-4p65/GHSA-9f8x-24h4-4p65.json @@ -7,12 +7,8 @@ "CVE-2010-3757" ], "details": "Format string vulnerability in the _Eventlog function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to execute arbitrary code via format string specifiers located after a | (pipe) character in a string. NOTE: this might overlap CVE-2010-3059.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gqx-f57m-x5j2/GHSA-9gqx-f57m-x5j2.json b/advisories/unreviewed/2022/05/GHSA-9gqx-f57m-x5j2/GHSA-9gqx-f57m-x5j2.json index 808aec803d4..c054eb7a0a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gqx-f57m-x5j2/GHSA-9gqx-f57m-x5j2.json +++ b/advisories/unreviewed/2022/05/GHSA-9gqx-f57m-x5j2/GHSA-9gqx-f57m-x5j2.json @@ -7,12 +7,8 @@ "CVE-2010-1987" ], "details": "Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory consumption, out-of-bounds read, and application crash) via JavaScript code that appends long strings to the content of a P element, and performs certain other string concatenation and substring operations, related to the DoubleWideCharMappedString class in USP10.dll and the gfxWindowsFontGroup::GetUnderlineOffset function in xul.dll, a different vulnerability than CVE-2009-1571.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9gwc-j42j-2hxx/GHSA-9gwc-j42j-2hxx.json b/advisories/unreviewed/2022/05/GHSA-9gwc-j42j-2hxx/GHSA-9gwc-j42j-2hxx.json index 26a96ee07f5..14233fedb6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gwc-j42j-2hxx/GHSA-9gwc-j42j-2hxx.json +++ b/advisories/unreviewed/2022/05/GHSA-9gwc-j42j-2hxx/GHSA-9gwc-j42j-2hxx.json @@ -7,12 +7,8 @@ "CVE-2015-5353" ], "details": "Directory traversal vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tab parameter to admin/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9h3j-3m7p-vhgc/GHSA-9h3j-3m7p-vhgc.json b/advisories/unreviewed/2022/05/GHSA-9h3j-3m7p-vhgc/GHSA-9h3j-3m7p-vhgc.json index 35dc24add62..447bdaf1de4 100644 --- a/advisories/unreviewed/2022/05/GHSA-9h3j-3m7p-vhgc/GHSA-9h3j-3m7p-vhgc.json +++ b/advisories/unreviewed/2022/05/GHSA-9h3j-3m7p-vhgc/GHSA-9h3j-3m7p-vhgc.json @@ -7,12 +7,8 @@ "CVE-2015-6516" ], "details": "SQL injection vulnerability in cygnux.org sysPass 1.0.9 and earlier allows remote authenticated users to execute arbitrary SQL commands via the search parameter to ajax/ajax_search.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9j9q-pp23-rfvx/GHSA-9j9q-pp23-rfvx.json b/advisories/unreviewed/2022/05/GHSA-9j9q-pp23-rfvx/GHSA-9j9q-pp23-rfvx.json index afe53335dff..7b28bdd583c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j9q-pp23-rfvx/GHSA-9j9q-pp23-rfvx.json +++ b/advisories/unreviewed/2022/05/GHSA-9j9q-pp23-rfvx/GHSA-9j9q-pp23-rfvx.json @@ -7,12 +7,8 @@ "CVE-2010-3150" ], "details": "Untrusted search path vulnerability in Adobe Premier Pro CS4 4.0.0 (314 (MC: 160820)) allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ibfs32.dll that is located in the same folder as a .pproj, .prfpset, .prexport, .prm, .prmp, .prpreset, .prproj, .prsl, .prtl, or .vpr file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9mgc-jxh6-mqj2/GHSA-9mgc-jxh6-mqj2.json b/advisories/unreviewed/2022/05/GHSA-9mgc-jxh6-mqj2/GHSA-9mgc-jxh6-mqj2.json index fc30c35e01f..e58a6b1c55a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mgc-jxh6-mqj2/GHSA-9mgc-jxh6-mqj2.json +++ b/advisories/unreviewed/2022/05/GHSA-9mgc-jxh6-mqj2/GHSA-9mgc-jxh6-mqj2.json @@ -7,12 +7,8 @@ "CVE-2010-1681" ], "details": "Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to execute arbitrary code via a crafted DXF file, a different vulnerability than CVE-2010-0254 and CVE-2010-0256.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9mj9-6mfj-6q3h/GHSA-9mj9-6mfj-6q3h.json b/advisories/unreviewed/2022/05/GHSA-9mj9-6mfj-6q3h/GHSA-9mj9-6mfj-6q3h.json index 81068c5dc27..769f62e2760 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mj9-6mfj-6q3h/GHSA-9mj9-6mfj-6q3h.json +++ b/advisories/unreviewed/2022/05/GHSA-9mj9-6mfj-6q3h/GHSA-9mj9-6mfj-6q3h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9mw5-w2j2-3f45/GHSA-9mw5-w2j2-3f45.json b/advisories/unreviewed/2022/05/GHSA-9mw5-w2j2-3f45/GHSA-9mw5-w2j2-3f45.json index dabb36f66a6..0426e020a1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mw5-w2j2-3f45/GHSA-9mw5-w2j2-3f45.json +++ b/advisories/unreviewed/2022/05/GHSA-9mw5-w2j2-3f45/GHSA-9mw5-w2j2-3f45.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9qg2-923p-qj4p/GHSA-9qg2-923p-qj4p.json b/advisories/unreviewed/2022/05/GHSA-9qg2-923p-qj4p/GHSA-9qg2-923p-qj4p.json index 5bd97851f29..dd94d083d9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qg2-923p-qj4p/GHSA-9qg2-923p-qj4p.json +++ b/advisories/unreviewed/2022/05/GHSA-9qg2-923p-qj4p/GHSA-9qg2-923p-qj4p.json @@ -7,12 +7,8 @@ "CVE-2010-1509" ], "details": "IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow, related to a \"sign-extension error.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9qj6-548m-j6pf/GHSA-9qj6-548m-j6pf.json b/advisories/unreviewed/2022/05/GHSA-9qj6-548m-j6pf/GHSA-9qj6-548m-j6pf.json index 6d66bad7c5f..ca05525175a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qj6-548m-j6pf/GHSA-9qj6-548m-j6pf.json +++ b/advisories/unreviewed/2022/05/GHSA-9qj6-548m-j6pf/GHSA-9qj6-548m-j6pf.json @@ -7,12 +7,8 @@ "CVE-2010-2290" ], "details": "Cross-site scripting (XSS) vulnerability in cgi-bin/cgix/help in McAfee Unified Threat Management (UTM) Firewall (formerly SnapGear) firmware 3.0.0 through 4.0.6 allows remote attackers to inject arbitrary web script or HTML via the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9qwv-267r-c7fq/GHSA-9qwv-267r-c7fq.json b/advisories/unreviewed/2022/05/GHSA-9qwv-267r-c7fq/GHSA-9qwv-267r-c7fq.json index 9bddaeb90d8..48861bff280 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qwv-267r-c7fq/GHSA-9qwv-267r-c7fq.json +++ b/advisories/unreviewed/2022/05/GHSA-9qwv-267r-c7fq/GHSA-9qwv-267r-c7fq.json @@ -7,12 +7,8 @@ "CVE-2015-3903" ], "details": "libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9rm5-p28h-jx5q/GHSA-9rm5-p28h-jx5q.json b/advisories/unreviewed/2022/05/GHSA-9rm5-p28h-jx5q/GHSA-9rm5-p28h-jx5q.json index f5f9e5b07ab..eb886a8248b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rm5-p28h-jx5q/GHSA-9rm5-p28h-jx5q.json +++ b/advisories/unreviewed/2022/05/GHSA-9rm5-p28h-jx5q/GHSA-9rm5-p28h-jx5q.json @@ -7,12 +7,8 @@ "CVE-2015-4614" ], "details": "Multiple SQL injection vulnerabilities in includes/Function.php in the Easy2Map plugin before 1.2.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the mapName parameter in an e2m_img_save_map_name action to wp-admin/admin-ajax.php and other unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9vfr-62wr-64jc/GHSA-9vfr-62wr-64jc.json b/advisories/unreviewed/2022/05/GHSA-9vfr-62wr-64jc/GHSA-9vfr-62wr-64jc.json index 103de06531e..5d9c41f7bd8 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vfr-62wr-64jc/GHSA-9vfr-62wr-64jc.json +++ b/advisories/unreviewed/2022/05/GHSA-9vfr-62wr-64jc/GHSA-9vfr-62wr-64jc.json @@ -7,12 +7,8 @@ "CVE-2010-2909" ], "details": "SQL injection vulnerability in ttvideo.php in the TTVideo (com_ttvideo) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a video action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9wch-45vf-46vq/GHSA-9wch-45vf-46vq.json b/advisories/unreviewed/2022/05/GHSA-9wch-45vf-46vq/GHSA-9wch-45vf-46vq.json index 1a19b828212..6b4dcec934b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wch-45vf-46vq/GHSA-9wch-45vf-46vq.json +++ b/advisories/unreviewed/2022/05/GHSA-9wch-45vf-46vq/GHSA-9wch-45vf-46vq.json @@ -7,12 +7,8 @@ "CVE-2015-2683" ], "details": "Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 does not properly restrict access to the Advent Java Management Extensions (JMX) Servlet, which allows remote attackers to execute arbitrary code via unspecified vectors to servlets/Jmx_dynamic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9xfv-r389-8vvf/GHSA-9xfv-r389-8vvf.json b/advisories/unreviewed/2022/05/GHSA-9xfv-r389-8vvf/GHSA-9xfv-r389-8vvf.json index ed5e77a6107..c4374fe7f6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xfv-r389-8vvf/GHSA-9xfv-r389-8vvf.json +++ b/advisories/unreviewed/2022/05/GHSA-9xfv-r389-8vvf/GHSA-9xfv-r389-8vvf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9xpp-pm7c-3qwm/GHSA-9xpp-pm7c-3qwm.json b/advisories/unreviewed/2022/05/GHSA-9xpp-pm7c-3qwm/GHSA-9xpp-pm7c-3qwm.json index 02953d7ff89..d7a400aab0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xpp-pm7c-3qwm/GHSA-9xpp-pm7c-3qwm.json +++ b/advisories/unreviewed/2022/05/GHSA-9xpp-pm7c-3qwm/GHSA-9xpp-pm7c-3qwm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c2xv-cj4r-rwv7/GHSA-c2xv-cj4r-rwv7.json b/advisories/unreviewed/2022/05/GHSA-c2xv-cj4r-rwv7/GHSA-c2xv-cj4r-rwv7.json index 7dde62fc014..8ae853c847e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2xv-cj4r-rwv7/GHSA-c2xv-cj4r-rwv7.json +++ b/advisories/unreviewed/2022/05/GHSA-c2xv-cj4r-rwv7/GHSA-c2xv-cj4r-rwv7.json @@ -7,12 +7,8 @@ "CVE-2010-1550" ], "details": "Format string vulnerability in ovet_demandpoll.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via format string specifiers in the sel parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4ph-89p2-rmm3/GHSA-c4ph-89p2-rmm3.json b/advisories/unreviewed/2022/05/GHSA-c4ph-89p2-rmm3/GHSA-c4ph-89p2-rmm3.json index 31f95764e9d..00de188ed95 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4ph-89p2-rmm3/GHSA-c4ph-89p2-rmm3.json +++ b/advisories/unreviewed/2022/05/GHSA-c4ph-89p2-rmm3/GHSA-c4ph-89p2-rmm3.json @@ -7,12 +7,8 @@ "CVE-2010-3015" ], "details": "Integer overflow in the ext4_ext_get_blocks function in fs/ext4/extents.c in the Linux kernel before 2.6.34 allows local users to cause a denial of service (BUG and system crash) via a write operation on the last block of a large file, followed by a sync operation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -112,9 +108,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c5xw-x5m5-vx6w/GHSA-c5xw-x5m5-vx6w.json b/advisories/unreviewed/2022/05/GHSA-c5xw-x5m5-vx6w/GHSA-c5xw-x5m5-vx6w.json index f3fbf7a14cd..8558a3b439b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5xw-x5m5-vx6w/GHSA-c5xw-x5m5-vx6w.json +++ b/advisories/unreviewed/2022/05/GHSA-c5xw-x5m5-vx6w/GHSA-c5xw-x5m5-vx6w.json @@ -7,12 +7,8 @@ "CVE-2010-1908" ], "details": "The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance does not properly restrict access to the HTTPDownloadFile, HTTPGetFile, Install, and RunCmd methods, which allows remote attackers to execute arbitrary programs via a URL in the url argument to (1) HTTPDownloadFile or (2) HTTPGetFile.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c78m-h25c-7vj6/GHSA-c78m-h25c-7vj6.json b/advisories/unreviewed/2022/05/GHSA-c78m-h25c-7vj6/GHSA-c78m-h25c-7vj6.json index f7994ddd2aa..4bc9ef0ea60 100644 --- a/advisories/unreviewed/2022/05/GHSA-c78m-h25c-7vj6/GHSA-c78m-h25c-7vj6.json +++ b/advisories/unreviewed/2022/05/GHSA-c78m-h25c-7vj6/GHSA-c78m-h25c-7vj6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c865-vqrj-2g6m/GHSA-c865-vqrj-2g6m.json b/advisories/unreviewed/2022/05/GHSA-c865-vqrj-2g6m/GHSA-c865-vqrj-2g6m.json index 9fdc93b4109..92a37c5f671 100644 --- a/advisories/unreviewed/2022/05/GHSA-c865-vqrj-2g6m/GHSA-c865-vqrj-2g6m.json +++ b/advisories/unreviewed/2022/05/GHSA-c865-vqrj-2g6m/GHSA-c865-vqrj-2g6m.json @@ -7,12 +7,8 @@ "CVE-2010-2003" ], "details": "Cross-site scripting (XSS) vulnerability in misc/get_admin.php in Advanced Poll 2.08 allows remote attackers to inject arbitrary web script or HTML via the mysql_host parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c8xv-5cpm-rx3x/GHSA-c8xv-5cpm-rx3x.json b/advisories/unreviewed/2022/05/GHSA-c8xv-5cpm-rx3x/GHSA-c8xv-5cpm-rx3x.json index e5d3fd87d33..99b62b9cd23 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8xv-5cpm-rx3x/GHSA-c8xv-5cpm-rx3x.json +++ b/advisories/unreviewed/2022/05/GHSA-c8xv-5cpm-rx3x/GHSA-c8xv-5cpm-rx3x.json @@ -7,12 +7,8 @@ "CVE-2015-3994" ], "details": "The grant.xsfunc application in testApps/grantAccess/ in the XS Engine in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to spoof log entries via a crafted request, aka SAP Security Note 2109818.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c98j-mqm3-22r6/GHSA-c98j-mqm3-22r6.json b/advisories/unreviewed/2022/05/GHSA-c98j-mqm3-22r6/GHSA-c98j-mqm3-22r6.json index f87edd59b67..8b3c7f78968 100644 --- a/advisories/unreviewed/2022/05/GHSA-c98j-mqm3-22r6/GHSA-c98j-mqm3-22r6.json +++ b/advisories/unreviewed/2022/05/GHSA-c98j-mqm3-22r6/GHSA-c98j-mqm3-22r6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c9q3-7wj8-34wx/GHSA-c9q3-7wj8-34wx.json b/advisories/unreviewed/2022/05/GHSA-c9q3-7wj8-34wx/GHSA-c9q3-7wj8-34wx.json index 73f3e3239b4..28d745c6688 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9q3-7wj8-34wx/GHSA-c9q3-7wj8-34wx.json +++ b/advisories/unreviewed/2022/05/GHSA-c9q3-7wj8-34wx/GHSA-c9q3-7wj8-34wx.json @@ -7,12 +7,8 @@ "CVE-2010-3449" ], "details": "Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1; and Apache Continuum 1.3.6, 1.4.0, and 1.1 through 1.2.3.1; allows remote attackers to hijack the authentication of administrators for requests that modify credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfcj-w8c8-c2h9/GHSA-cfcj-w8c8-c2h9.json b/advisories/unreviewed/2022/05/GHSA-cfcj-w8c8-c2h9/GHSA-cfcj-w8c8-c2h9.json index e9e2b81d75c..b0b1806c808 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfcj-w8c8-c2h9/GHSA-cfcj-w8c8-c2h9.json +++ b/advisories/unreviewed/2022/05/GHSA-cfcj-w8c8-c2h9/GHSA-cfcj-w8c8-c2h9.json @@ -7,12 +7,8 @@ "CVE-2015-5074" ], "details": "Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM before 5.0.9 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a .pht extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfqr-rmf8-vqgf/GHSA-cfqr-rmf8-vqgf.json b/advisories/unreviewed/2022/05/GHSA-cfqr-rmf8-vqgf/GHSA-cfqr-rmf8-vqgf.json index 5fa6ef4d49b..d538fcaa64b 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfqr-rmf8-vqgf/GHSA-cfqr-rmf8-vqgf.json +++ b/advisories/unreviewed/2022/05/GHSA-cfqr-rmf8-vqgf/GHSA-cfqr-rmf8-vqgf.json @@ -7,12 +7,8 @@ "CVE-2015-7369" ], "details": "The default Flash cross-domain policy (crossdomain.xml) in Revive Adserver before 3.2.2 does not restrict access cross domain access, which allows remote attackers to conduct cross domain attacks via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfxh-r5jm-fqqv/GHSA-cfxh-r5jm-fqqv.json b/advisories/unreviewed/2022/05/GHSA-cfxh-r5jm-fqqv/GHSA-cfxh-r5jm-fqqv.json index 805b512e552..d3a87924ac2 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfxh-r5jm-fqqv/GHSA-cfxh-r5jm-fqqv.json +++ b/advisories/unreviewed/2022/05/GHSA-cfxh-r5jm-fqqv/GHSA-cfxh-r5jm-fqqv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cg99-cxj5-wq75/GHSA-cg99-cxj5-wq75.json b/advisories/unreviewed/2022/05/GHSA-cg99-cxj5-wq75/GHSA-cg99-cxj5-wq75.json index 7b96ab50947..036dc90ae82 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg99-cxj5-wq75/GHSA-cg99-cxj5-wq75.json +++ b/advisories/unreviewed/2022/05/GHSA-cg99-cxj5-wq75/GHSA-cg99-cxj5-wq75.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-chr6-gp8q-4835/GHSA-chr6-gp8q-4835.json b/advisories/unreviewed/2022/05/GHSA-chr6-gp8q-4835/GHSA-chr6-gp8q-4835.json index 4bee582bdb5..ad5379b6ac9 100644 --- a/advisories/unreviewed/2022/05/GHSA-chr6-gp8q-4835/GHSA-chr6-gp8q-4835.json +++ b/advisories/unreviewed/2022/05/GHSA-chr6-gp8q-4835/GHSA-chr6-gp8q-4835.json @@ -7,12 +7,8 @@ "CVE-2015-5703" ], "details": "SQL injection vulnerability in the public key discovery API call in Open-Xchange OX Guard before 2.0.0-rev8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cmjj-w6wr-cpwv/GHSA-cmjj-w6wr-cpwv.json b/advisories/unreviewed/2022/05/GHSA-cmjj-w6wr-cpwv/GHSA-cmjj-w6wr-cpwv.json index 34c661c1500..80c3e817c42 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmjj-w6wr-cpwv/GHSA-cmjj-w6wr-cpwv.json +++ b/advisories/unreviewed/2022/05/GHSA-cmjj-w6wr-cpwv/GHSA-cmjj-w6wr-cpwv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cmmh-vgv7-57gw/GHSA-cmmh-vgv7-57gw.json b/advisories/unreviewed/2022/05/GHSA-cmmh-vgv7-57gw/GHSA-cmmh-vgv7-57gw.json index 0517975d68e..e79defb925a 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmmh-vgv7-57gw/GHSA-cmmh-vgv7-57gw.json +++ b/advisories/unreviewed/2022/05/GHSA-cmmh-vgv7-57gw/GHSA-cmmh-vgv7-57gw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cmmq-h42r-ggfh/GHSA-cmmq-h42r-ggfh.json b/advisories/unreviewed/2022/05/GHSA-cmmq-h42r-ggfh/GHSA-cmmq-h42r-ggfh.json index b2d52029910..df5407f840a 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmmq-h42r-ggfh/GHSA-cmmq-h42r-ggfh.json +++ b/advisories/unreviewed/2022/05/GHSA-cmmq-h42r-ggfh/GHSA-cmmq-h42r-ggfh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cmxf-478f-2982/GHSA-cmxf-478f-2982.json b/advisories/unreviewed/2022/05/GHSA-cmxf-478f-2982/GHSA-cmxf-478f-2982.json index d6cbcc3717b..33a44f0d787 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmxf-478f-2982/GHSA-cmxf-478f-2982.json +++ b/advisories/unreviewed/2022/05/GHSA-cmxf-478f-2982/GHSA-cmxf-478f-2982.json @@ -7,12 +7,8 @@ "CVE-2010-2427" ], "details": "VMware Studio 2.0 does not properly write to temporary files, which allows local users to gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cp56-958r-w2vj/GHSA-cp56-958r-w2vj.json b/advisories/unreviewed/2022/05/GHSA-cp56-958r-w2vj/GHSA-cp56-958r-w2vj.json index a98cdade790..7436771a730 100644 --- a/advisories/unreviewed/2022/05/GHSA-cp56-958r-w2vj/GHSA-cp56-958r-w2vj.json +++ b/advisories/unreviewed/2022/05/GHSA-cp56-958r-w2vj/GHSA-cp56-958r-w2vj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cpf9-x6x7-j973/GHSA-cpf9-x6x7-j973.json b/advisories/unreviewed/2022/05/GHSA-cpf9-x6x7-j973/GHSA-cpf9-x6x7-j973.json index df0a1cdbfc2..f368c7b86fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpf9-x6x7-j973/GHSA-cpf9-x6x7-j973.json +++ b/advisories/unreviewed/2022/05/GHSA-cpf9-x6x7-j973/GHSA-cpf9-x6x7-j973.json @@ -7,12 +7,8 @@ "CVE-2010-2581" ], "details": "dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director file containing a crafted pamm chunk with an invalid (1) size and (2) number of sub-chunks, a different vulnerability than CVE-2010-4084, CVE-2010-4085, CVE-2010-4086, and CVE-2010-4088.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cpqp-qv9c-w5hq/GHSA-cpqp-qv9c-w5hq.json b/advisories/unreviewed/2022/05/GHSA-cpqp-qv9c-w5hq/GHSA-cpqp-qv9c-w5hq.json index 49a647ca20e..5f1025ab6c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpqp-qv9c-w5hq/GHSA-cpqp-qv9c-w5hq.json +++ b/advisories/unreviewed/2022/05/GHSA-cpqp-qv9c-w5hq/GHSA-cpqp-qv9c-w5hq.json @@ -7,12 +7,8 @@ "CVE-2015-3301" ], "details": "Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path parameter in the checkout_editor_settings page to wp-admin/admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cpw6-3m7w-xvrc/GHSA-cpw6-3m7w-xvrc.json b/advisories/unreviewed/2022/05/GHSA-cpw6-3m7w-xvrc/GHSA-cpw6-3m7w-xvrc.json index aea02583129..41af03e9976 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpw6-3m7w-xvrc/GHSA-cpw6-3m7w-xvrc.json +++ b/advisories/unreviewed/2022/05/GHSA-cpw6-3m7w-xvrc/GHSA-cpw6-3m7w-xvrc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cr32-cx2f-mfw5/GHSA-cr32-cx2f-mfw5.json b/advisories/unreviewed/2022/05/GHSA-cr32-cx2f-mfw5/GHSA-cr32-cx2f-mfw5.json index 0f7d5469037..2ca011ec047 100644 --- a/advisories/unreviewed/2022/05/GHSA-cr32-cx2f-mfw5/GHSA-cr32-cx2f-mfw5.json +++ b/advisories/unreviewed/2022/05/GHSA-cr32-cx2f-mfw5/GHSA-cr32-cx2f-mfw5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-crxp-64qq-hp9c/GHSA-crxp-64qq-hp9c.json b/advisories/unreviewed/2022/05/GHSA-crxp-64qq-hp9c/GHSA-crxp-64qq-hp9c.json index dda9c461ef9..541e8f69902 100644 --- a/advisories/unreviewed/2022/05/GHSA-crxp-64qq-hp9c/GHSA-crxp-64qq-hp9c.json +++ b/advisories/unreviewed/2022/05/GHSA-crxp-64qq-hp9c/GHSA-crxp-64qq-hp9c.json @@ -7,12 +7,8 @@ "CVE-2010-1575" ], "details": "The Cisco Content Services Switch (CSS) 11500 with software 08.20.1.01 conveys authentication data through ClientCert-* headers but does not delete client-supplied ClientCert-* headers, which might allow remote attackers to bypass authentication via crafted header data, as demonstrated by a ClientCert-Subject-CN header, aka Bug ID CSCsz04690.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cv3p-w7pm-g7qg/GHSA-cv3p-w7pm-g7qg.json b/advisories/unreviewed/2022/05/GHSA-cv3p-w7pm-g7qg/GHSA-cv3p-w7pm-g7qg.json index aab3ecabf99..d8bad239b9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv3p-w7pm-g7qg/GHSA-cv3p-w7pm-g7qg.json +++ b/advisories/unreviewed/2022/05/GHSA-cv3p-w7pm-g7qg/GHSA-cv3p-w7pm-g7qg.json @@ -7,12 +7,8 @@ "CVE-2010-2038" ], "details": "Cross-site scripting (XSS) vulnerability in include/tool/editing_files.php in gpEasy CMS 1.6.2 allows remote authenticated users, with Edit privileges, to inject arbitrary web script or HTML via the gpcontent parameter to index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cw5g-6vjh-8wpg/GHSA-cw5g-6vjh-8wpg.json b/advisories/unreviewed/2022/05/GHSA-cw5g-6vjh-8wpg/GHSA-cw5g-6vjh-8wpg.json index e190328469c..3d3abda541f 100644 --- a/advisories/unreviewed/2022/05/GHSA-cw5g-6vjh-8wpg/GHSA-cw5g-6vjh-8wpg.json +++ b/advisories/unreviewed/2022/05/GHSA-cw5g-6vjh-8wpg/GHSA-cw5g-6vjh-8wpg.json @@ -7,12 +7,8 @@ "CVE-2010-1612" ], "details": "The IBM WebSphere DataPower XML Accelerator XA35, Low Latency Appliance XM70, Integration Appliance XI50, B2B Appliance XB60, and XML Security Gateway XS40 SOA Appliances before 3.8.0.0, when a QLOGIC Ethernet interface is used, allow remote attackers to cause a denial of service (interface outage) via malformed ICMP packets to the 0.0.0.0 destination IP address.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cwwq-64rr-rv47/GHSA-cwwq-64rr-rv47.json b/advisories/unreviewed/2022/05/GHSA-cwwq-64rr-rv47/GHSA-cwwq-64rr-rv47.json index 5f61faca7a5..65fa9bc5311 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwwq-64rr-rv47/GHSA-cwwq-64rr-rv47.json +++ b/advisories/unreviewed/2022/05/GHSA-cwwq-64rr-rv47/GHSA-cwwq-64rr-rv47.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cx5g-qjmj-w6xf/GHSA-cx5g-qjmj-w6xf.json b/advisories/unreviewed/2022/05/GHSA-cx5g-qjmj-w6xf/GHSA-cx5g-qjmj-w6xf.json index 760b0a3b4b5..a89a4646f4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx5g-qjmj-w6xf/GHSA-cx5g-qjmj-w6xf.json +++ b/advisories/unreviewed/2022/05/GHSA-cx5g-qjmj-w6xf/GHSA-cx5g-qjmj-w6xf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cx6m-9875-mvh9/GHSA-cx6m-9875-mvh9.json b/advisories/unreviewed/2022/05/GHSA-cx6m-9875-mvh9/GHSA-cx6m-9875-mvh9.json index af912fb12e6..6169109ed37 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx6m-9875-mvh9/GHSA-cx6m-9875-mvh9.json +++ b/advisories/unreviewed/2022/05/GHSA-cx6m-9875-mvh9/GHSA-cx6m-9875-mvh9.json @@ -7,12 +7,8 @@ "CVE-2010-1931" ], "details": "SQL injection vulnerability in includes/content/cart.inc.php in CubeCart PHP Shopping cart 4.3.4 through 4.3.9 allows remote attackers to execute arbitrary SQL commands via the shipKey parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f25h-xfh5-gjqp/GHSA-f25h-xfh5-gjqp.json b/advisories/unreviewed/2022/05/GHSA-f25h-xfh5-gjqp/GHSA-f25h-xfh5-gjqp.json index fa3f9c53ea7..429cde127a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-f25h-xfh5-gjqp/GHSA-f25h-xfh5-gjqp.json +++ b/advisories/unreviewed/2022/05/GHSA-f25h-xfh5-gjqp/GHSA-f25h-xfh5-gjqp.json @@ -7,12 +7,8 @@ "CVE-2010-3000" ], "details": "Multiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allow remote attackers to execute arbitrary code via crafted (1) HX_FLV_META_AMF_TYPE_MIXEDARRAY or (2) HX_FLV_META_AMF_TYPE_ARRAY data in an FLV file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f32q-24fc-cjxj/GHSA-f32q-24fc-cjxj.json b/advisories/unreviewed/2022/05/GHSA-f32q-24fc-cjxj/GHSA-f32q-24fc-cjxj.json index 43c39ca37a8..314780d6dc8 100644 --- a/advisories/unreviewed/2022/05/GHSA-f32q-24fc-cjxj/GHSA-f32q-24fc-cjxj.json +++ b/advisories/unreviewed/2022/05/GHSA-f32q-24fc-cjxj/GHSA-f32q-24fc-cjxj.json @@ -7,12 +7,8 @@ "CVE-2015-2993" ], "details": "SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to /createnewaccount or (2) write to arbitrary files via the fileName parameter to /userentry.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f3pg-77wm-w58m/GHSA-f3pg-77wm-w58m.json b/advisories/unreviewed/2022/05/GHSA-f3pg-77wm-w58m/GHSA-f3pg-77wm-w58m.json index 88e72090e16..999f8136e5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3pg-77wm-w58m/GHSA-f3pg-77wm-w58m.json +++ b/advisories/unreviewed/2022/05/GHSA-f3pg-77wm-w58m/GHSA-f3pg-77wm-w58m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3x6-vj5j-c29m/GHSA-f3x6-vj5j-c29m.json b/advisories/unreviewed/2022/05/GHSA-f3x6-vj5j-c29m/GHSA-f3x6-vj5j-c29m.json index cb7ce241e52..1b679b40b8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3x6-vj5j-c29m/GHSA-f3x6-vj5j-c29m.json +++ b/advisories/unreviewed/2022/05/GHSA-f3x6-vj5j-c29m/GHSA-f3x6-vj5j-c29m.json @@ -7,12 +7,8 @@ "CVE-2015-7385" ], "details": "Cross-site scripting (XSS) vulnerability in Open-Xchange OX Guard before 2.0.0-rev11 allows remote attackers to inject arbitrary web script or HTML via the uid field in a PGP public key, which is not properly handled in \"Guard PGP Settings.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4f8-xfww-r4hf/GHSA-f4f8-xfww-r4hf.json b/advisories/unreviewed/2022/05/GHSA-f4f8-xfww-r4hf/GHSA-f4f8-xfww-r4hf.json index 4a255ec3005..e910083409d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4f8-xfww-r4hf/GHSA-f4f8-xfww-r4hf.json +++ b/advisories/unreviewed/2022/05/GHSA-f4f8-xfww-r4hf/GHSA-f4f8-xfww-r4hf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f533-g6c5-65cx/GHSA-f533-g6c5-65cx.json b/advisories/unreviewed/2022/05/GHSA-f533-g6c5-65cx/GHSA-f533-g6c5-65cx.json index e3796332cf5..4944e5a5f06 100644 --- a/advisories/unreviewed/2022/05/GHSA-f533-g6c5-65cx/GHSA-f533-g6c5-65cx.json +++ b/advisories/unreviewed/2022/05/GHSA-f533-g6c5-65cx/GHSA-f533-g6c5-65cx.json @@ -7,12 +7,8 @@ "CVE-2015-4036" ], "details": "Array index error in the tcm_vhost_make_tpg function in drivers/vhost/scsi.c in the Linux kernel before 4.0 might allow guest OS users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted VHOST_SCSI_SET_ENDPOINT ioctl call. NOTE: the affected function was renamed to vhost_scsi_make_tpg before the vulnerability was announced.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f55p-m2v7-m3pw/GHSA-f55p-m2v7-m3pw.json b/advisories/unreviewed/2022/05/GHSA-f55p-m2v7-m3pw/GHSA-f55p-m2v7-m3pw.json index c43aa3554e2..519210e6b69 100644 --- a/advisories/unreviewed/2022/05/GHSA-f55p-m2v7-m3pw/GHSA-f55p-m2v7-m3pw.json +++ b/advisories/unreviewed/2022/05/GHSA-f55p-m2v7-m3pw/GHSA-f55p-m2v7-m3pw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f5fp-r73r-m33f/GHSA-f5fp-r73r-m33f.json b/advisories/unreviewed/2022/05/GHSA-f5fp-r73r-m33f/GHSA-f5fp-r73r-m33f.json index 47b69527b6b..ec1f76e0beb 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5fp-r73r-m33f/GHSA-f5fp-r73r-m33f.json +++ b/advisories/unreviewed/2022/05/GHSA-f5fp-r73r-m33f/GHSA-f5fp-r73r-m33f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f78m-hq58-gcg7/GHSA-f78m-hq58-gcg7.json b/advisories/unreviewed/2022/05/GHSA-f78m-hq58-gcg7/GHSA-f78m-hq58-gcg7.json index 586094d9a00..e2d6fb4ba53 100644 --- a/advisories/unreviewed/2022/05/GHSA-f78m-hq58-gcg7/GHSA-f78m-hq58-gcg7.json +++ b/advisories/unreviewed/2022/05/GHSA-f78m-hq58-gcg7/GHSA-f78m-hq58-gcg7.json @@ -7,12 +7,8 @@ "CVE-2010-1555" ], "details": "Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid Hostname parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f7c4-r58g-c8jh/GHSA-f7c4-r58g-c8jh.json b/advisories/unreviewed/2022/05/GHSA-f7c4-r58g-c8jh/GHSA-f7c4-r58g-c8jh.json index 62b65aa26ae..6d94389aedf 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7c4-r58g-c8jh/GHSA-f7c4-r58g-c8jh.json +++ b/advisories/unreviewed/2022/05/GHSA-f7c4-r58g-c8jh/GHSA-f7c4-r58g-c8jh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f7x9-phc8-2ff5/GHSA-f7x9-phc8-2ff5.json b/advisories/unreviewed/2022/05/GHSA-f7x9-phc8-2ff5/GHSA-f7x9-phc8-2ff5.json index c3953e5793d..d8d8d5c0f86 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7x9-phc8-2ff5/GHSA-f7x9-phc8-2ff5.json +++ b/advisories/unreviewed/2022/05/GHSA-f7x9-phc8-2ff5/GHSA-f7x9-phc8-2ff5.json @@ -7,12 +7,8 @@ "CVE-2015-2845" ], "details": "The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arbitrary commands via the $type portion of the PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f8wx-h5g6-hjg3/GHSA-f8wx-h5g6-hjg3.json b/advisories/unreviewed/2022/05/GHSA-f8wx-h5g6-hjg3/GHSA-f8wx-h5g6-hjg3.json index 2a382290488..f9a580e288e 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8wx-h5g6-hjg3/GHSA-f8wx-h5g6-hjg3.json +++ b/advisories/unreviewed/2022/05/GHSA-f8wx-h5g6-hjg3/GHSA-f8wx-h5g6-hjg3.json @@ -7,12 +7,8 @@ "CVE-2015-7682" ], "details": "Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1) select_invitaion_code_bulk_option or (2) invi_del_id parameter in the pie-invitation-codes page to wp-admin/admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fc3h-fgjq-4hqp/GHSA-fc3h-fgjq-4hqp.json b/advisories/unreviewed/2022/05/GHSA-fc3h-fgjq-4hqp/GHSA-fc3h-fgjq-4hqp.json index 7c1fed3bc9b..b4553e65556 100644 --- a/advisories/unreviewed/2022/05/GHSA-fc3h-fgjq-4hqp/GHSA-fc3h-fgjq-4hqp.json +++ b/advisories/unreviewed/2022/05/GHSA-fc3h-fgjq-4hqp/GHSA-fc3h-fgjq-4hqp.json @@ -7,12 +7,8 @@ "CVE-2010-2859" ], "details": "news.php in SimpNews 2.47.3 and earlier allows remote attackers to obtain sensitive information via an invalid lang parameter, which reveals the installation path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcg6-9hqq-q764/GHSA-fcg6-9hqq-q764.json b/advisories/unreviewed/2022/05/GHSA-fcg6-9hqq-q764/GHSA-fcg6-9hqq-q764.json index ba68f1c74a0..fd098d57a43 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcg6-9hqq-q764/GHSA-fcg6-9hqq-q764.json +++ b/advisories/unreviewed/2022/05/GHSA-fcg6-9hqq-q764/GHSA-fcg6-9hqq-q764.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ff9h-44c8-h9qm/GHSA-ff9h-44c8-h9qm.json b/advisories/unreviewed/2022/05/GHSA-ff9h-44c8-h9qm/GHSA-ff9h-44c8-h9qm.json index db15ec34f57..69bfcfdcc93 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff9h-44c8-h9qm/GHSA-ff9h-44c8-h9qm.json +++ b/advisories/unreviewed/2022/05/GHSA-ff9h-44c8-h9qm/GHSA-ff9h-44c8-h9qm.json @@ -7,12 +7,8 @@ "CVE-2010-2990" ], "details": "Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA Client for Linux before 11.100, Citrix ICA Client for Solaris before 8.63, and Citrix Receiver for Windows Mobile before 11.5 allow remote attackers to execute arbitrary code via (1) a crafted HTML document, (2) a crafted .ICA file, or (3) a crafted type field in an ICA graphics packet, related to a \"heap offset overflow\" issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ffhh-fjrg-f4fj/GHSA-ffhh-fjrg-f4fj.json b/advisories/unreviewed/2022/05/GHSA-ffhh-fjrg-f4fj/GHSA-ffhh-fjrg-f4fj.json index 71dd0a3953b..3d4c4a34113 100644 --- a/advisories/unreviewed/2022/05/GHSA-ffhh-fjrg-f4fj/GHSA-ffhh-fjrg-f4fj.json +++ b/advisories/unreviewed/2022/05/GHSA-ffhh-fjrg-f4fj/GHSA-ffhh-fjrg-f4fj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fgfp-7wv2-mhgm/GHSA-fgfp-7wv2-mhgm.json b/advisories/unreviewed/2022/05/GHSA-fgfp-7wv2-mhgm/GHSA-fgfp-7wv2-mhgm.json index 0957ee1e075..b2b745526a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgfp-7wv2-mhgm/GHSA-fgfp-7wv2-mhgm.json +++ b/advisories/unreviewed/2022/05/GHSA-fgfp-7wv2-mhgm/GHSA-fgfp-7wv2-mhgm.json @@ -7,12 +7,8 @@ "CVE-2010-3755" ], "details": "The _DAS_ReadBlockReply function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via data in a TCP packet. NOTE: this might overlap CVE-2010-3060.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fh77-37q2-pf96/GHSA-fh77-37q2-pf96.json b/advisories/unreviewed/2022/05/GHSA-fh77-37q2-pf96/GHSA-fh77-37q2-pf96.json index 1c79d7d912a..ae1143397f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-fh77-37q2-pf96/GHSA-fh77-37q2-pf96.json +++ b/advisories/unreviewed/2022/05/GHSA-fh77-37q2-pf96/GHSA-fh77-37q2-pf96.json @@ -7,12 +7,8 @@ "CVE-2015-5075" ], "details": "Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of administrators for requests that create an administrative account via a crafted request to index.php/users/create.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fhw7-jcjc-3vxx/GHSA-fhw7-jcjc-3vxx.json b/advisories/unreviewed/2022/05/GHSA-fhw7-jcjc-3vxx/GHSA-fhw7-jcjc-3vxx.json index b60023fb7b2..920f6ce2db5 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhw7-jcjc-3vxx/GHSA-fhw7-jcjc-3vxx.json +++ b/advisories/unreviewed/2022/05/GHSA-fhw7-jcjc-3vxx/GHSA-fhw7-jcjc-3vxx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fm2p-cqm2-45gv/GHSA-fm2p-cqm2-45gv.json b/advisories/unreviewed/2022/05/GHSA-fm2p-cqm2-45gv/GHSA-fm2p-cqm2-45gv.json index b871c73e1d1..47a1455108c 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm2p-cqm2-45gv/GHSA-fm2p-cqm2-45gv.json +++ b/advisories/unreviewed/2022/05/GHSA-fm2p-cqm2-45gv/GHSA-fm2p-cqm2-45gv.json @@ -7,12 +7,8 @@ "CVE-2015-2237" ], "details": "Multiple SQL injection vulnerabilities in Betster (aka PHP Betoffice) 1.0.4 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) showprofile.php or (2) categoryedit.php or (3) username parameter in a login to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fm2w-6w3p-hhx6/GHSA-fm2w-6w3p-hhx6.json b/advisories/unreviewed/2022/05/GHSA-fm2w-6w3p-hhx6/GHSA-fm2w-6w3p-hhx6.json index 17e4866a12e..8ac08cd4594 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm2w-6w3p-hhx6/GHSA-fm2w-6w3p-hhx6.json +++ b/advisories/unreviewed/2022/05/GHSA-fm2w-6w3p-hhx6/GHSA-fm2w-6w3p-hhx6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fm3j-ghgj-fhvx/GHSA-fm3j-ghgj-fhvx.json b/advisories/unreviewed/2022/05/GHSA-fm3j-ghgj-fhvx/GHSA-fm3j-ghgj-fhvx.json index 8511224414e..7581e67b528 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm3j-ghgj-fhvx/GHSA-fm3j-ghgj-fhvx.json +++ b/advisories/unreviewed/2022/05/GHSA-fm3j-ghgj-fhvx/GHSA-fm3j-ghgj-fhvx.json @@ -7,12 +7,8 @@ "CVE-2015-2748" ], "details": "Websense TRITON AP-WEB before 8.0.0 does not properly restrict access to files in explorer_wse/, which allows remote attackers to obtain sensitive information via a direct request to a (1) Web Security incident report or the (2) Explorer configuration (websense.ini) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpf9-7pjp-4x5q/GHSA-fpf9-7pjp-4x5q.json b/advisories/unreviewed/2022/05/GHSA-fpf9-7pjp-4x5q/GHSA-fpf9-7pjp-4x5q.json index 746851b1cea..56100a61a02 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpf9-7pjp-4x5q/GHSA-fpf9-7pjp-4x5q.json +++ b/advisories/unreviewed/2022/05/GHSA-fpf9-7pjp-4x5q/GHSA-fpf9-7pjp-4x5q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpr2-2gg6-pf5c/GHSA-fpr2-2gg6-pf5c.json b/advisories/unreviewed/2022/05/GHSA-fpr2-2gg6-pf5c/GHSA-fpr2-2gg6-pf5c.json index c70a39ccc08..b25f4279f53 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpr2-2gg6-pf5c/GHSA-fpr2-2gg6-pf5c.json +++ b/advisories/unreviewed/2022/05/GHSA-fpr2-2gg6-pf5c/GHSA-fpr2-2gg6-pf5c.json @@ -7,12 +7,8 @@ "CVE-2015-7364" ], "details": "The HTML_Quickform library, as used in Revive Adserver before 3.2.2, allows remote attackers to bypass the CSRF protection mechanism via an empty token.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fqfw-xqpm-2238/GHSA-fqfw-xqpm-2238.json b/advisories/unreviewed/2022/05/GHSA-fqfw-xqpm-2238/GHSA-fqfw-xqpm-2238.json index 2846dfefd5a..63f2a3e099f 100644 --- a/advisories/unreviewed/2022/05/GHSA-fqfw-xqpm-2238/GHSA-fqfw-xqpm-2238.json +++ b/advisories/unreviewed/2022/05/GHSA-fqfw-xqpm-2238/GHSA-fqfw-xqpm-2238.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fqhq-pc8v-8xch/GHSA-fqhq-pc8v-8xch.json b/advisories/unreviewed/2022/05/GHSA-fqhq-pc8v-8xch/GHSA-fqhq-pc8v-8xch.json index c4364227af9..818d993de8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fqhq-pc8v-8xch/GHSA-fqhq-pc8v-8xch.json +++ b/advisories/unreviewed/2022/05/GHSA-fqhq-pc8v-8xch/GHSA-fqhq-pc8v-8xch.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frwp-8f86-7mhx/GHSA-frwp-8f86-7mhx.json b/advisories/unreviewed/2022/05/GHSA-frwp-8f86-7mhx/GHSA-frwp-8f86-7mhx.json index 140a4f74520..c03dfb651e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-frwp-8f86-7mhx/GHSA-frwp-8f86-7mhx.json +++ b/advisories/unreviewed/2022/05/GHSA-frwp-8f86-7mhx/GHSA-frwp-8f86-7mhx.json @@ -7,12 +7,8 @@ "CVE-2010-1511" ], "details": "KGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for remote attackers to overwrite arbitrary files via a crafted metalink file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-frwr-5jjw-jm5f/GHSA-frwr-5jjw-jm5f.json b/advisories/unreviewed/2022/05/GHSA-frwr-5jjw-jm5f/GHSA-frwr-5jjw-jm5f.json index d8309f14582..e84faa4d5e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-frwr-5jjw-jm5f/GHSA-frwr-5jjw-jm5f.json +++ b/advisories/unreviewed/2022/05/GHSA-frwr-5jjw-jm5f/GHSA-frwr-5jjw-jm5f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fw94-fp28-prw3/GHSA-fw94-fp28-prw3.json b/advisories/unreviewed/2022/05/GHSA-fw94-fp28-prw3/GHSA-fw94-fp28-prw3.json index 9bcca6813cf..d9c2045c342 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw94-fp28-prw3/GHSA-fw94-fp28-prw3.json +++ b/advisories/unreviewed/2022/05/GHSA-fw94-fp28-prw3/GHSA-fw94-fp28-prw3.json @@ -7,12 +7,8 @@ "CVE-2013-1860" ], "details": "Heap-based buffer overflow in the wdm_in_callback function in drivers/usb/class/cdc-wdm.c in the Linux kernel before 3.8.4 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted cdc-wdm USB device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwfj-vhw3-3v5v/GHSA-fwfj-vhw3-3v5v.json b/advisories/unreviewed/2022/05/GHSA-fwfj-vhw3-3v5v/GHSA-fwfj-vhw3-3v5v.json index 6f744823bcb..ff52c782968 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwfj-vhw3-3v5v/GHSA-fwfj-vhw3-3v5v.json +++ b/advisories/unreviewed/2022/05/GHSA-fwfj-vhw3-3v5v/GHSA-fwfj-vhw3-3v5v.json @@ -7,12 +7,8 @@ "CVE-2010-1609" ], "details": "Cross-site scripting (XSS) vulnerability in SAP NetWeaver 2004 before SP21 and 2004s before SP13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwmp-3wvg-jv2j/GHSA-fwmp-3wvg-jv2j.json b/advisories/unreviewed/2022/05/GHSA-fwmp-3wvg-jv2j/GHSA-fwmp-3wvg-jv2j.json index 2d41f98a6fd..ace60865c4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwmp-3wvg-jv2j/GHSA-fwmp-3wvg-jv2j.json +++ b/advisories/unreviewed/2022/05/GHSA-fwmp-3wvg-jv2j/GHSA-fwmp-3wvg-jv2j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g3v8-6wrr-5fpc/GHSA-g3v8-6wrr-5fpc.json b/advisories/unreviewed/2022/05/GHSA-g3v8-6wrr-5fpc/GHSA-g3v8-6wrr-5fpc.json index 2bd7a9f265b..7da2bc09b07 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3v8-6wrr-5fpc/GHSA-g3v8-6wrr-5fpc.json +++ b/advisories/unreviewed/2022/05/GHSA-g3v8-6wrr-5fpc/GHSA-g3v8-6wrr-5fpc.json @@ -7,12 +7,8 @@ "CVE-2010-2717" ], "details": "Cross-site scripting (XSS) vulnerability in manager/login.php in CruxSoftware CruxCMS 3.0, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the txtusername parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g48x-6c94-mxpc/GHSA-g48x-6c94-mxpc.json b/advisories/unreviewed/2022/05/GHSA-g48x-6c94-mxpc/GHSA-g48x-6c94-mxpc.json index da67156ace7..4c6766734bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-g48x-6c94-mxpc/GHSA-g48x-6c94-mxpc.json +++ b/advisories/unreviewed/2022/05/GHSA-g48x-6c94-mxpc/GHSA-g48x-6c94-mxpc.json @@ -7,12 +7,8 @@ "CVE-2015-3624" ], "details": "Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content Management System (CMS) before 9.10 SP1 (Build 9.1.0.184.1.120) allows remote attackers to hijack the authentication of content administrators for requests that delete content via a delete action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g763-4gcm-875f/GHSA-g763-4gcm-875f.json b/advisories/unreviewed/2022/05/GHSA-g763-4gcm-875f/GHSA-g763-4gcm-875f.json index 6fb75a5ac75..4437d211363 100644 --- a/advisories/unreviewed/2022/05/GHSA-g763-4gcm-875f/GHSA-g763-4gcm-875f.json +++ b/advisories/unreviewed/2022/05/GHSA-g763-4gcm-875f/GHSA-g763-4gcm-875f.json @@ -7,12 +7,8 @@ "CVE-2015-2994" ], "details": "Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators to execute arbitrary code by uploading a file with a .jsp extension, then accessing it via a direct request to the file in icons/user_photo/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g7jw-7782-jjv9/GHSA-g7jw-7782-jjv9.json b/advisories/unreviewed/2022/05/GHSA-g7jw-7782-jjv9/GHSA-g7jw-7782-jjv9.json index 472879cbd2e..469644bb918 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7jw-7782-jjv9/GHSA-g7jw-7782-jjv9.json +++ b/advisories/unreviewed/2022/05/GHSA-g7jw-7782-jjv9/GHSA-g7jw-7782-jjv9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g9g3-hphr-q46f/GHSA-g9g3-hphr-q46f.json b/advisories/unreviewed/2022/05/GHSA-g9g3-hphr-q46f/GHSA-g9g3-hphr-q46f.json index 79e10fe78ab..94c04ffef67 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9g3-hphr-q46f/GHSA-g9g3-hphr-q46f.json +++ b/advisories/unreviewed/2022/05/GHSA-g9g3-hphr-q46f/GHSA-g9g3-hphr-q46f.json @@ -7,12 +7,8 @@ "CVE-2010-3271" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that disable certain security options via an Edit action to console/adminSecurityDetail.do followed by a save action to console/syncworkspace.do.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gc7h-r8w4-m2m4/GHSA-gc7h-r8w4-m2m4.json b/advisories/unreviewed/2022/05/GHSA-gc7h-r8w4-m2m4/GHSA-gc7h-r8w4-m2m4.json index 5d94bf64828..f70505a7104 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc7h-r8w4-m2m4/GHSA-gc7h-r8w4-m2m4.json +++ b/advisories/unreviewed/2022/05/GHSA-gc7h-r8w4-m2m4/GHSA-gc7h-r8w4-m2m4.json @@ -7,12 +7,8 @@ "CVE-2010-1961" ], "details": "Buffer overflow in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified variables to jovgraph.exe, which are not properly handled in a call to the sprintf function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gf3m-gprc-v999/GHSA-gf3m-gprc-v999.json b/advisories/unreviewed/2022/05/GHSA-gf3m-gprc-v999/GHSA-gf3m-gprc-v999.json index 153753a866b..1bda6bd8071 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf3m-gprc-v999/GHSA-gf3m-gprc-v999.json +++ b/advisories/unreviewed/2022/05/GHSA-gf3m-gprc-v999/GHSA-gf3m-gprc-v999.json @@ -7,12 +7,8 @@ "CVE-2010-3270" ], "details": "Stack-based buffer overflow in Cisco WebEx Meeting Center T27LB before SP21 EP3 and T27LC before SP22 allows user-assisted remote authenticated users to execute arbitrary code by providing a crafted .atp file and then disconnecting from a meeting. NOTE: since this is a site-specific issue with no expected action for consumers, it might be REJECTed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gfjw-37rr-7cf3/GHSA-gfjw-37rr-7cf3.json b/advisories/unreviewed/2022/05/GHSA-gfjw-37rr-7cf3/GHSA-gfjw-37rr-7cf3.json index d0de71dedf9..0ee3f0d48b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfjw-37rr-7cf3/GHSA-gfjw-37rr-7cf3.json +++ b/advisories/unreviewed/2022/05/GHSA-gfjw-37rr-7cf3/GHSA-gfjw-37rr-7cf3.json @@ -7,12 +7,8 @@ "CVE-2010-1922" ], "details": "Multiple PHP remote file inclusion vulnerabilities in 29o3 CMS 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the LibDir parameter to (1) lib/page/pageDescriptionObject.php, and (2) layoutHeaderFuncs.php, (3) layoutManager.php, and (4) layoutParser.php in lib/layout/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ghj7-vrw2-gfqj/GHSA-ghj7-vrw2-gfqj.json b/advisories/unreviewed/2022/05/GHSA-ghj7-vrw2-gfqj/GHSA-ghj7-vrw2-gfqj.json index 8600e240418..a2fe6009ea9 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghj7-vrw2-gfqj/GHSA-ghj7-vrw2-gfqj.json +++ b/advisories/unreviewed/2022/05/GHSA-ghj7-vrw2-gfqj/GHSA-ghj7-vrw2-gfqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ghq7-vvp6-23x7/GHSA-ghq7-vvp6-23x7.json b/advisories/unreviewed/2022/05/GHSA-ghq7-vvp6-23x7/GHSA-ghq7-vvp6-23x7.json index 8864c4c6e56..83e4f4560da 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghq7-vvp6-23x7/GHSA-ghq7-vvp6-23x7.json +++ b/advisories/unreviewed/2022/05/GHSA-ghq7-vvp6-23x7/GHSA-ghq7-vvp6-23x7.json @@ -7,12 +7,8 @@ "CVE-2015-8357" ], "details": "Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary files, and consequently obtain sensitive information or cause a denial of service, via a .. (dot dot) in the file parameter to admin/bitrix.xscan_worker.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gj7j-hrqm-6x5q/GHSA-gj7j-hrqm-6x5q.json b/advisories/unreviewed/2022/05/GHSA-gj7j-hrqm-6x5q/GHSA-gj7j-hrqm-6x5q.json index 5eb68c37dfe..3006a1c32c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj7j-hrqm-6x5q/GHSA-gj7j-hrqm-6x5q.json +++ b/advisories/unreviewed/2022/05/GHSA-gj7j-hrqm-6x5q/GHSA-gj7j-hrqm-6x5q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gp5q-hh2p-748v/GHSA-gp5q-hh2p-748v.json b/advisories/unreviewed/2022/05/GHSA-gp5q-hh2p-748v/GHSA-gp5q-hh2p-748v.json index 4bc867f7c90..043c123ee70 100644 --- a/advisories/unreviewed/2022/05/GHSA-gp5q-hh2p-748v/GHSA-gp5q-hh2p-748v.json +++ b/advisories/unreviewed/2022/05/GHSA-gp5q-hh2p-748v/GHSA-gp5q-hh2p-748v.json @@ -7,12 +7,8 @@ "CVE-2010-2575" ], "details": "Heap-based buffer overflow in the RLE decompression functionality in the TranscribePalmImageToJPEG function in generators/plucker/inplug/image.cpp in Okular in KDE SC 4.3.0 through 4.5.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image in a PDB file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gpc6-3wm6-6hpw/GHSA-gpc6-3wm6-6hpw.json b/advisories/unreviewed/2022/05/GHSA-gpc6-3wm6-6hpw/GHSA-gpc6-3wm6-6hpw.json index 416928ed24b..3997343fc2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpc6-3wm6-6hpw/GHSA-gpc6-3wm6-6hpw.json +++ b/advisories/unreviewed/2022/05/GHSA-gpc6-3wm6-6hpw/GHSA-gpc6-3wm6-6hpw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gpcm-hmx8-j7h9/GHSA-gpcm-hmx8-j7h9.json b/advisories/unreviewed/2022/05/GHSA-gpcm-hmx8-j7h9/GHSA-gpcm-hmx8-j7h9.json index ba27a38eb49..da8729d9f19 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpcm-hmx8-j7h9/GHSA-gpcm-hmx8-j7h9.json +++ b/advisories/unreviewed/2022/05/GHSA-gpcm-hmx8-j7h9/GHSA-gpcm-hmx8-j7h9.json @@ -7,12 +7,8 @@ "CVE-2010-1869" ], "details": "Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gqjp-rg2w-6r7j/GHSA-gqjp-rg2w-6r7j.json b/advisories/unreviewed/2022/05/GHSA-gqjp-rg2w-6r7j/GHSA-gqjp-rg2w-6r7j.json index 19b479742b5..bbd0696942a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqjp-rg2w-6r7j/GHSA-gqjp-rg2w-6r7j.json +++ b/advisories/unreviewed/2022/05/GHSA-gqjp-rg2w-6r7j/GHSA-gqjp-rg2w-6r7j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gqjr-gcpj-h4ww/GHSA-gqjr-gcpj-h4ww.json b/advisories/unreviewed/2022/05/GHSA-gqjr-gcpj-h4ww/GHSA-gqjr-gcpj-h4ww.json index 801856bc4ce..94563ff455c 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqjr-gcpj-h4ww/GHSA-gqjr-gcpj-h4ww.json +++ b/advisories/unreviewed/2022/05/GHSA-gqjr-gcpj-h4ww/GHSA-gqjr-gcpj-h4ww.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gqpx-798c-8554/GHSA-gqpx-798c-8554.json b/advisories/unreviewed/2022/05/GHSA-gqpx-798c-8554/GHSA-gqpx-798c-8554.json index 9ecb1adb84c..197039a6e8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqpx-798c-8554/GHSA-gqpx-798c-8554.json +++ b/advisories/unreviewed/2022/05/GHSA-gqpx-798c-8554/GHSA-gqpx-798c-8554.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-grhv-p8rf-rc43/GHSA-grhv-p8rf-rc43.json b/advisories/unreviewed/2022/05/GHSA-grhv-p8rf-rc43/GHSA-grhv-p8rf-rc43.json index b0309ae88dc..da2f119d55e 100644 --- a/advisories/unreviewed/2022/05/GHSA-grhv-p8rf-rc43/GHSA-grhv-p8rf-rc43.json +++ b/advisories/unreviewed/2022/05/GHSA-grhv-p8rf-rc43/GHSA-grhv-p8rf-rc43.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-grrv-f2wh-rvgq/GHSA-grrv-f2wh-rvgq.json b/advisories/unreviewed/2022/05/GHSA-grrv-f2wh-rvgq/GHSA-grrv-f2wh-rvgq.json index 11ef1512228..d945af265e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-grrv-f2wh-rvgq/GHSA-grrv-f2wh-rvgq.json +++ b/advisories/unreviewed/2022/05/GHSA-grrv-f2wh-rvgq/GHSA-grrv-f2wh-rvgq.json @@ -7,12 +7,8 @@ "CVE-2010-3262" ], "details": "Cross-site scripting (XSS) vulnerability in Flock Browser 3.x before 3.0.0.4114 allows remote attackers to inject arbitrary web script or HTML via a crafted RSS feed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gv2x-87pj-2gw9/GHSA-gv2x-87pj-2gw9.json b/advisories/unreviewed/2022/05/GHSA-gv2x-87pj-2gw9/GHSA-gv2x-87pj-2gw9.json index 970ceefa235..427b3da4903 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv2x-87pj-2gw9/GHSA-gv2x-87pj-2gw9.json +++ b/advisories/unreviewed/2022/05/GHSA-gv2x-87pj-2gw9/GHSA-gv2x-87pj-2gw9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gv3r-q3q8-2h79/GHSA-gv3r-q3q8-2h79.json b/advisories/unreviewed/2022/05/GHSA-gv3r-q3q8-2h79/GHSA-gv3r-q3q8-2h79.json index 55d80385db2..f094e20bc03 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv3r-q3q8-2h79/GHSA-gv3r-q3q8-2h79.json +++ b/advisories/unreviewed/2022/05/GHSA-gv3r-q3q8-2h79/GHSA-gv3r-q3q8-2h79.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gvh3-6r75-35q8/GHSA-gvh3-6r75-35q8.json b/advisories/unreviewed/2022/05/GHSA-gvh3-6r75-35q8/GHSA-gvh3-6r75-35q8.json index 0e86950e0bf..4e7f58bff35 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvh3-6r75-35q8/GHSA-gvh3-6r75-35q8.json +++ b/advisories/unreviewed/2022/05/GHSA-gvh3-6r75-35q8/GHSA-gvh3-6r75-35q8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gvvw-2fw3-q5rv/GHSA-gvvw-2fw3-q5rv.json b/advisories/unreviewed/2022/05/GHSA-gvvw-2fw3-q5rv/GHSA-gvvw-2fw3-q5rv.json index d42294d2c91..092ba4a8127 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvvw-2fw3-q5rv/GHSA-gvvw-2fw3-q5rv.json +++ b/advisories/unreviewed/2022/05/GHSA-gvvw-2fw3-q5rv/GHSA-gvvw-2fw3-q5rv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gw3h-3jrx-85fr/GHSA-gw3h-3jrx-85fr.json b/advisories/unreviewed/2022/05/GHSA-gw3h-3jrx-85fr/GHSA-gw3h-3jrx-85fr.json index f82aa3ebb24..6cd02cf928b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw3h-3jrx-85fr/GHSA-gw3h-3jrx-85fr.json +++ b/advisories/unreviewed/2022/05/GHSA-gw3h-3jrx-85fr/GHSA-gw3h-3jrx-85fr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gw6h-6rx4-wcrj/GHSA-gw6h-6rx4-wcrj.json b/advisories/unreviewed/2022/05/GHSA-gw6h-6rx4-wcrj/GHSA-gw6h-6rx4-wcrj.json index c1940a99643..2df27abe1ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw6h-6rx4-wcrj/GHSA-gw6h-6rx4-wcrj.json +++ b/advisories/unreviewed/2022/05/GHSA-gw6h-6rx4-wcrj/GHSA-gw6h-6rx4-wcrj.json @@ -7,12 +7,8 @@ "CVE-2015-3620" ], "details": "Cross-site scripting (XSS) vulnerability in the advanced dataset reports page in Fortinet FortiAnalyzer 5.0.0 through 5.0.10 and 5.2.0 through 5.2.1 and FortiManager 5.0.3 through 5.0.10 and 5.2.0 through 5.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gwcv-mrcx-59x5/GHSA-gwcv-mrcx-59x5.json b/advisories/unreviewed/2022/05/GHSA-gwcv-mrcx-59x5/GHSA-gwcv-mrcx-59x5.json index 6b50e6d2862..909a926f9c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwcv-mrcx-59x5/GHSA-gwcv-mrcx-59x5.json +++ b/advisories/unreviewed/2022/05/GHSA-gwcv-mrcx-59x5/GHSA-gwcv-mrcx-59x5.json @@ -7,12 +7,8 @@ "CVE-2015-5735" ], "details": "The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to write to arbitrary memory locations via a 0x226108 ioctl call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gwp7-97j8-m79f/GHSA-gwp7-97j8-m79f.json b/advisories/unreviewed/2022/05/GHSA-gwp7-97j8-m79f/GHSA-gwp7-97j8-m79f.json index 1a42610db3d..8d23df9226c 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwp7-97j8-m79f/GHSA-gwp7-97j8-m79f.json +++ b/advisories/unreviewed/2022/05/GHSA-gwp7-97j8-m79f/GHSA-gwp7-97j8-m79f.json @@ -7,12 +7,8 @@ "CVE-2015-4674" ], "details": "The autoupdate implementation in TimeDoctor Pro 1.4.72.3 on Windows relies on unsigned installer files that are retrieved without use of SSL, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gwqp-8wjj-p3gj/GHSA-gwqp-8wjj-p3gj.json b/advisories/unreviewed/2022/05/GHSA-gwqp-8wjj-p3gj/GHSA-gwqp-8wjj-p3gj.json index d330d2f0fad..e39f99fc8ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwqp-8wjj-p3gj/GHSA-gwqp-8wjj-p3gj.json +++ b/advisories/unreviewed/2022/05/GHSA-gwqp-8wjj-p3gj/GHSA-gwqp-8wjj-p3gj.json @@ -7,12 +7,8 @@ "CVE-2010-2891" ], "details": "Buffer overflow in the smiGetNode function in lib/smi.c in libsmi 0.4.8 allows context-dependent attackers to execute arbitrary code via an Object Identifier (aka OID) represented as a numerical string containing many components separated by . (dot) characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxhr-vc26-3p89/GHSA-gxhr-vc26-3p89.json b/advisories/unreviewed/2022/05/GHSA-gxhr-vc26-3p89/GHSA-gxhr-vc26-3p89.json index 29acbd8e73f..53e306dac62 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxhr-vc26-3p89/GHSA-gxhr-vc26-3p89.json +++ b/advisories/unreviewed/2022/05/GHSA-gxhr-vc26-3p89/GHSA-gxhr-vc26-3p89.json @@ -7,12 +7,8 @@ "CVE-2010-4676" ], "details": "Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allows remote authenticated users to cause a denial of service (device crash) via a high volume of IPsec traffic, aka Bug ID CSCsx52748.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gxxm-8rj8-v8q7/GHSA-gxxm-8rj8-v8q7.json b/advisories/unreviewed/2022/05/GHSA-gxxm-8rj8-v8q7/GHSA-gxxm-8rj8-v8q7.json index 25ff3de88b7..17fd6e53823 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxxm-8rj8-v8q7/GHSA-gxxm-8rj8-v8q7.json +++ b/advisories/unreviewed/2022/05/GHSA-gxxm-8rj8-v8q7/GHSA-gxxm-8rj8-v8q7.json @@ -7,12 +7,8 @@ "CVE-2015-3885" ], "details": "Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h2p5-8h8f-7g53/GHSA-h2p5-8h8f-7g53.json b/advisories/unreviewed/2022/05/GHSA-h2p5-8h8f-7g53/GHSA-h2p5-8h8f-7g53.json index 7be53f5dd01..bdad3eab508 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2p5-8h8f-7g53/GHSA-h2p5-8h8f-7g53.json +++ b/advisories/unreviewed/2022/05/GHSA-h2p5-8h8f-7g53/GHSA-h2p5-8h8f-7g53.json @@ -7,12 +7,8 @@ "CVE-2015-7392" ], "details": "Heap-based buffer overflow in the parse_string function in libs/esl/src/esl_json.c in FreeSWITCH before 1.4.23 and 1.6.x before 1.6.2 allows remote attackers to execute arbitrary code via a trailing \\u in a json string to cJSON_Parse.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h2rp-j2g8-grv6/GHSA-h2rp-j2g8-grv6.json b/advisories/unreviewed/2022/05/GHSA-h2rp-j2g8-grv6/GHSA-h2rp-j2g8-grv6.json index 49600f05a14..9ef2abd71dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2rp-j2g8-grv6/GHSA-h2rp-j2g8-grv6.json +++ b/advisories/unreviewed/2022/05/GHSA-h2rp-j2g8-grv6/GHSA-h2rp-j2g8-grv6.json @@ -7,12 +7,8 @@ "CVE-2010-4670" ], "details": "The Neighbor Discovery (ND) protocol implementation in the IPv6 stack on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2(3) and earlier, and Cisco PIX Security Appliances devices, allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages with different source addresses, as demonstrated by the flood_router6 program in the thc-ipv6 package, aka Bug ID CSCti24526.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h33q-qxcf-7vxx/GHSA-h33q-qxcf-7vxx.json b/advisories/unreviewed/2022/05/GHSA-h33q-qxcf-7vxx/GHSA-h33q-qxcf-7vxx.json index 98bd528ac85..d6399da20a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-h33q-qxcf-7vxx/GHSA-h33q-qxcf-7vxx.json +++ b/advisories/unreviewed/2022/05/GHSA-h33q-qxcf-7vxx/GHSA-h33q-qxcf-7vxx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h34q-q3m4-h4x7/GHSA-h34q-q3m4-h4x7.json b/advisories/unreviewed/2022/05/GHSA-h34q-q3m4-h4x7/GHSA-h34q-q3m4-h4x7.json index 92fcaf91396..bc1fafe86a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-h34q-q3m4-h4x7/GHSA-h34q-q3m4-h4x7.json +++ b/advisories/unreviewed/2022/05/GHSA-h34q-q3m4-h4x7/GHSA-h34q-q3m4-h4x7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h374-v4jg-jmvr/GHSA-h374-v4jg-jmvr.json b/advisories/unreviewed/2022/05/GHSA-h374-v4jg-jmvr/GHSA-h374-v4jg-jmvr.json index 60ea7825106..2125a7d1c77 100644 --- a/advisories/unreviewed/2022/05/GHSA-h374-v4jg-jmvr/GHSA-h374-v4jg-jmvr.json +++ b/advisories/unreviewed/2022/05/GHSA-h374-v4jg-jmvr/GHSA-h374-v4jg-jmvr.json @@ -7,12 +7,8 @@ "CVE-2015-5456" ], "details": "Cross-site scripting (XSS) vulnerability in the form method in modules/formclass.php in PivotX before 2.3.11 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, related to the \"PHP_SELF\" variable and form actions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h3jx-wfwm-w7jp/GHSA-h3jx-wfwm-w7jp.json b/advisories/unreviewed/2022/05/GHSA-h3jx-wfwm-w7jp/GHSA-h3jx-wfwm-w7jp.json index 98f49d61cc2..6fe494c0e4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3jx-wfwm-w7jp/GHSA-h3jx-wfwm-w7jp.json +++ b/advisories/unreviewed/2022/05/GHSA-h3jx-wfwm-w7jp/GHSA-h3jx-wfwm-w7jp.json @@ -7,12 +7,8 @@ "CVE-2015-3897" ], "details": "Directory traversal vulnerability in Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the theme parameter and a file path in the location parameter to bonita/portal/themeResource.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h3p2-pf2r-9cvv/GHSA-h3p2-pf2r-9cvv.json b/advisories/unreviewed/2022/05/GHSA-h3p2-pf2r-9cvv/GHSA-h3p2-pf2r-9cvv.json index 362dd501c13..2150b0ebac9 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3p2-pf2r-9cvv/GHSA-h3p2-pf2r-9cvv.json +++ b/advisories/unreviewed/2022/05/GHSA-h3p2-pf2r-9cvv/GHSA-h3p2-pf2r-9cvv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h4h6-rmf6-5r65/GHSA-h4h6-rmf6-5r65.json b/advisories/unreviewed/2022/05/GHSA-h4h6-rmf6-5r65/GHSA-h4h6-rmf6-5r65.json index bec256010c0..15037777e5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4h6-rmf6-5r65/GHSA-h4h6-rmf6-5r65.json +++ b/advisories/unreviewed/2022/05/GHSA-h4h6-rmf6-5r65/GHSA-h4h6-rmf6-5r65.json @@ -7,12 +7,8 @@ "CVE-2015-2805" ], "details": "Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, 6855, 6900, 10K, and 6860 with firmware 6.4.5.R02, 6.4.6.R01, 6.6.4.R01, 6.6.5.R02, 7.3.2.R01, 7.3.3.R01, 7.3.4.R01, and 8.1.1.R01 allows remote attackers to hijack the authentication of administrators for requests that create users via a crafted request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h4xc-rp2v-7893/GHSA-h4xc-rp2v-7893.json b/advisories/unreviewed/2022/05/GHSA-h4xc-rp2v-7893/GHSA-h4xc-rp2v-7893.json index 4324459622b..ce800f40964 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4xc-rp2v-7893/GHSA-h4xc-rp2v-7893.json +++ b/advisories/unreviewed/2022/05/GHSA-h4xc-rp2v-7893/GHSA-h4xc-rp2v-7893.json @@ -7,12 +7,8 @@ "CVE-2015-7367" ], "details": "Revive Adserver before 3.2.2 allows remote attackers to perform unspecified actions by leveraging an unexpired session after the user has been (1) deleted or (2) unlinked.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h5c2-wmhg-q46m/GHSA-h5c2-wmhg-q46m.json b/advisories/unreviewed/2022/05/GHSA-h5c2-wmhg-q46m/GHSA-h5c2-wmhg-q46m.json index c6a64254cef..4e816e020b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5c2-wmhg-q46m/GHSA-h5c2-wmhg-q46m.json +++ b/advisories/unreviewed/2022/05/GHSA-h5c2-wmhg-q46m/GHSA-h5c2-wmhg-q46m.json @@ -7,12 +7,8 @@ "CVE-2010-1911" ], "details": "The site-locking implementation in the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance relies on a list of server domain names to restrict execution of ActiveX controls, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a DNS hijacking attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h5pw-cf2q-m8rq/GHSA-h5pw-cf2q-m8rq.json b/advisories/unreviewed/2022/05/GHSA-h5pw-cf2q-m8rq/GHSA-h5pw-cf2q-m8rq.json index 1dc693beecd..6bbf650079b 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5pw-cf2q-m8rq/GHSA-h5pw-cf2q-m8rq.json +++ b/advisories/unreviewed/2022/05/GHSA-h5pw-cf2q-m8rq/GHSA-h5pw-cf2q-m8rq.json @@ -7,12 +7,8 @@ "CVE-2015-7370" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in open-flash-chart.swf in Open Flash Chart 2, as used in the VideoAds plugin in Revive Adserver before 3.2.2 and CA Release Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5.1 before 5.5.1-1616, 5.5.2 before 5.5.2-434, and 6.1.0 before 6.1.0-1026, allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) data-file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h6ch-r6c4-wc9h/GHSA-h6ch-r6c4-wc9h.json b/advisories/unreviewed/2022/05/GHSA-h6ch-r6c4-wc9h/GHSA-h6ch-r6c4-wc9h.json index 58a99a92913..c104d6692bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6ch-r6c4-wc9h/GHSA-h6ch-r6c4-wc9h.json +++ b/advisories/unreviewed/2022/05/GHSA-h6ch-r6c4-wc9h/GHSA-h6ch-r6c4-wc9h.json @@ -7,12 +7,8 @@ "CVE-2010-3153" ], "details": "Untrusted search path vulnerability in Adobe InDesign CS4 6.0, InDesign CS5 7.0.2 and earlier, Adobe InDesign Server CS5 7.0.2 and earlier, and Adobe InCopy CS5 7.0.2 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ibfs32.dll that is located in the same folder as an .indl, .indp, .indt, or .inx file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h6ff-fwgf-7rmm/GHSA-h6ff-fwgf-7rmm.json b/advisories/unreviewed/2022/05/GHSA-h6ff-fwgf-7rmm/GHSA-h6ff-fwgf-7rmm.json index d72fc655c78..a0ad5503574 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6ff-fwgf-7rmm/GHSA-h6ff-fwgf-7rmm.json +++ b/advisories/unreviewed/2022/05/GHSA-h6ff-fwgf-7rmm/GHSA-h6ff-fwgf-7rmm.json @@ -7,12 +7,8 @@ "CVE-2015-6912" ], "details": "Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharacters in the subtitle_codepage parameter to subtitle.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h733-hjhg-3p5j/GHSA-h733-hjhg-3p5j.json b/advisories/unreviewed/2022/05/GHSA-h733-hjhg-3p5j/GHSA-h733-hjhg-3p5j.json index 8e781560e9d..52039bd35b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-h733-hjhg-3p5j/GHSA-h733-hjhg-3p5j.json +++ b/advisories/unreviewed/2022/05/GHSA-h733-hjhg-3p5j/GHSA-h733-hjhg-3p5j.json @@ -7,12 +7,8 @@ "CVE-2010-3609" ], "details": "The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol daemon (SLPD) in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.1, allows remote attackers to cause a denial of service (infinite loop) via a packet with a \"next extension offset\" that references this extension or a previous extension. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h743-8964-67h5/GHSA-h743-8964-67h5.json b/advisories/unreviewed/2022/05/GHSA-h743-8964-67h5/GHSA-h743-8964-67h5.json index d767cdfbe9f..3de730578b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-h743-8964-67h5/GHSA-h743-8964-67h5.json +++ b/advisories/unreviewed/2022/05/GHSA-h743-8964-67h5/GHSA-h743-8964-67h5.json @@ -7,12 +7,8 @@ "CVE-2010-3269" ], "details": "Multiple stack-based buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to execute arbitrary code via a crafted (1) .wrf or (2) .arf file, related to use of a function pointer in a callback mechanism.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h8h5-3q52-xm2p/GHSA-h8h5-3q52-xm2p.json b/advisories/unreviewed/2022/05/GHSA-h8h5-3q52-xm2p/GHSA-h8h5-3q52-xm2p.json index 1d10b342212..7ad7828f6b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8h5-3q52-xm2p/GHSA-h8h5-3q52-xm2p.json +++ b/advisories/unreviewed/2022/05/GHSA-h8h5-3q52-xm2p/GHSA-h8h5-3q52-xm2p.json @@ -7,12 +7,8 @@ "CVE-2010-2718" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in CruxSoftware CruxPA 2.00, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) txtusername parameter to login.php, (2) todo parameter to newtodo.php, and unspecified vectors to (3) newtelephone.php and (4) newappointment.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h93m-2hw4-98hv/GHSA-h93m-2hw4-98hv.json b/advisories/unreviewed/2022/05/GHSA-h93m-2hw4-98hv/GHSA-h93m-2hw4-98hv.json index 50ddc65489b..0b207afb2bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-h93m-2hw4-98hv/GHSA-h93m-2hw4-98hv.json +++ b/advisories/unreviewed/2022/05/GHSA-h93m-2hw4-98hv/GHSA-h93m-2hw4-98hv.json @@ -7,12 +7,8 @@ "CVE-2010-3266" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the pcd parameter to edit_bug.aspx, (2) the bug_id parameter to edit_comment.aspx, (3) the id parameter to edit_user_permissions2.aspx, or (4) the default_name parameter to edit_customfield.aspx. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h9rm-vp45-cf2x/GHSA-h9rm-vp45-cf2x.json b/advisories/unreviewed/2022/05/GHSA-h9rm-vp45-cf2x/GHSA-h9rm-vp45-cf2x.json index 5ebfed69c1c..844f7d8c200 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9rm-vp45-cf2x/GHSA-h9rm-vp45-cf2x.json +++ b/advisories/unreviewed/2022/05/GHSA-h9rm-vp45-cf2x/GHSA-h9rm-vp45-cf2x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hch2-7x9g-9622/GHSA-hch2-7x9g-9622.json b/advisories/unreviewed/2022/05/GHSA-hch2-7x9g-9622/GHSA-hch2-7x9g-9622.json index 789ec67a416..49c634434e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-hch2-7x9g-9622/GHSA-hch2-7x9g-9622.json +++ b/advisories/unreviewed/2022/05/GHSA-hch2-7x9g-9622/GHSA-hch2-7x9g-9622.json @@ -7,12 +7,8 @@ "CVE-2015-3422" ], "details": "Cross-site scripting (XSS) vulnerability in SearchBlox before 8.2.1 allows remote attackers to inject arbitrary web script or HTML via the menu2 parameter to admin/main.jsp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hcvg-vqp3-m7mq/GHSA-hcvg-vqp3-m7mq.json b/advisories/unreviewed/2022/05/GHSA-hcvg-vqp3-m7mq/GHSA-hcvg-vqp3-m7mq.json index eb345002b95..60877280669 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcvg-vqp3-m7mq/GHSA-hcvg-vqp3-m7mq.json +++ b/advisories/unreviewed/2022/05/GHSA-hcvg-vqp3-m7mq/GHSA-hcvg-vqp3-m7mq.json @@ -7,12 +7,8 @@ "CVE-2015-8096" ], "details": "Integer overflow in Google Picasa 3.9.140 Build 239 and Build 248 allows remote attackers to execute arbitrary code via unspecified vectors related to \"phase one 0x412 tag,\" which triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hfq5-cp94-28rv/GHSA-hfq5-cp94-28rv.json b/advisories/unreviewed/2022/05/GHSA-hfq5-cp94-28rv/GHSA-hfq5-cp94-28rv.json index ab4b7a184f8..ecfc4268b44 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfq5-cp94-28rv/GHSA-hfq5-cp94-28rv.json +++ b/advisories/unreviewed/2022/05/GHSA-hfq5-cp94-28rv/GHSA-hfq5-cp94-28rv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hfqh-rrp3-j2rh/GHSA-hfqh-rrp3-j2rh.json b/advisories/unreviewed/2022/05/GHSA-hfqh-rrp3-j2rh/GHSA-hfqh-rrp3-j2rh.json index 093ca7bb512..0c6e09a0cc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfqh-rrp3-j2rh/GHSA-hfqh-rrp3-j2rh.json +++ b/advisories/unreviewed/2022/05/GHSA-hfqh-rrp3-j2rh/GHSA-hfqh-rrp3-j2rh.json @@ -7,12 +7,8 @@ "CVE-2015-2275" ], "details": "Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to inject arbitrary web script or HTML via the parameters[data][7][title] parameter in a saveImageData action to index.php/AJAXProxy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hg4c-258g-x2wr/GHSA-hg4c-258g-x2wr.json b/advisories/unreviewed/2022/05/GHSA-hg4c-258g-x2wr/GHSA-hg4c-258g-x2wr.json index 8b128881f5e..b8f552d8a98 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg4c-258g-x2wr/GHSA-hg4c-258g-x2wr.json +++ b/advisories/unreviewed/2022/05/GHSA-hg4c-258g-x2wr/GHSA-hg4c-258g-x2wr.json @@ -7,12 +7,8 @@ "CVE-2015-4084" ], "details": "Cross-site scripting (XSS) vulnerability in the Free Counter plugin 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the value_ parameter in a check_stat action to wp-admin/admin-ajax.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hj64-pmxg-fcx3/GHSA-hj64-pmxg-fcx3.json b/advisories/unreviewed/2022/05/GHSA-hj64-pmxg-fcx3/GHSA-hj64-pmxg-fcx3.json index a19738c97ef..783d3d086f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj64-pmxg-fcx3/GHSA-hj64-pmxg-fcx3.json +++ b/advisories/unreviewed/2022/05/GHSA-hj64-pmxg-fcx3/GHSA-hj64-pmxg-fcx3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjh6-cq5x-wfcq/GHSA-hjh6-cq5x-wfcq.json b/advisories/unreviewed/2022/05/GHSA-hjh6-cq5x-wfcq/GHSA-hjh6-cq5x-wfcq.json index ae08cbecfed..baa139e1098 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjh6-cq5x-wfcq/GHSA-hjh6-cq5x-wfcq.json +++ b/advisories/unreviewed/2022/05/GHSA-hjh6-cq5x-wfcq/GHSA-hjh6-cq5x-wfcq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjjc-2jc4-2pq4/GHSA-hjjc-2jc4-2pq4.json b/advisories/unreviewed/2022/05/GHSA-hjjc-2jc4-2pq4/GHSA-hjjc-2jc4-2pq4.json index f8091fdb2c0..f735edbf2a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjjc-2jc4-2pq4/GHSA-hjjc-2jc4-2pq4.json +++ b/advisories/unreviewed/2022/05/GHSA-hjjc-2jc4-2pq4/GHSA-hjjc-2jc4-2pq4.json @@ -7,12 +7,8 @@ "CVE-2010-2453" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Synology Disk Station 2.x before DSM3.0-1337 allow remote attackers to inject arbitrary web script or HTML by connecting to the FTP server and providing a crafted (1) USER or (2) PASS command, which is written by the FTP logging module to a web-interface log window, related to a \"web commands injection\" issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hpfx-3gj7-8gfg/GHSA-hpfx-3gj7-8gfg.json b/advisories/unreviewed/2022/05/GHSA-hpfx-3gj7-8gfg/GHSA-hpfx-3gj7-8gfg.json index 5cc118ccbeb..88ed5ffebfa 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpfx-3gj7-8gfg/GHSA-hpfx-3gj7-8gfg.json +++ b/advisories/unreviewed/2022/05/GHSA-hpfx-3gj7-8gfg/GHSA-hpfx-3gj7-8gfg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hph9-364j-3q7q/GHSA-hph9-364j-3q7q.json b/advisories/unreviewed/2022/05/GHSA-hph9-364j-3q7q/GHSA-hph9-364j-3q7q.json index 1715008207a..0e29a2401b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-hph9-364j-3q7q/GHSA-hph9-364j-3q7q.json +++ b/advisories/unreviewed/2022/05/GHSA-hph9-364j-3q7q/GHSA-hph9-364j-3q7q.json @@ -7,12 +7,8 @@ "CVE-2015-2995" ], "details": "The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote attackers to upload and execute arbitrary files via a NULL byte after the extension, as demonstrated by a .war%00 file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hq5w-jxpr-6446/GHSA-hq5w-jxpr-6446.json b/advisories/unreviewed/2022/05/GHSA-hq5w-jxpr-6446/GHSA-hq5w-jxpr-6446.json index 43776d35af2..9d8e584fc8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hq5w-jxpr-6446/GHSA-hq5w-jxpr-6446.json +++ b/advisories/unreviewed/2022/05/GHSA-hq5w-jxpr-6446/GHSA-hq5w-jxpr-6446.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hqmq-gf3p-rvf7/GHSA-hqmq-gf3p-rvf7.json b/advisories/unreviewed/2022/05/GHSA-hqmq-gf3p-rvf7/GHSA-hqmq-gf3p-rvf7.json index 4003529ca4b..9e86a2dd874 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqmq-gf3p-rvf7/GHSA-hqmq-gf3p-rvf7.json +++ b/advisories/unreviewed/2022/05/GHSA-hqmq-gf3p-rvf7/GHSA-hqmq-gf3p-rvf7.json @@ -7,12 +7,8 @@ "CVE-2015-2999" ], "details": "Multiple SQL injection vulnerabilities in SysAid Help Desk before 15.2 allow remote administrators to execute arbitrary SQL commands via the (1) groupFilter parameter in an AssetDetails report to /genericreport, customSQL parameter in a (2) TopAdministratorsByAverageTimer report or an (3) ActiveRequests report to /genericreport, (4) dir parameter to HelpDesk.jsp, or (5) grantSQL parameter to RFCGantt.jsp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hqr8-89qv-3hxp/GHSA-hqr8-89qv-3hxp.json b/advisories/unreviewed/2022/05/GHSA-hqr8-89qv-3hxp/GHSA-hqr8-89qv-3hxp.json index 1053e1c18db..dd612409141 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqr8-89qv-3hxp/GHSA-hqr8-89qv-3hxp.json +++ b/advisories/unreviewed/2022/05/GHSA-hqr8-89qv-3hxp/GHSA-hqr8-89qv-3hxp.json @@ -7,12 +7,8 @@ "CVE-2015-6909" ], "details": "Cross-site scripting (XSS) vulnerability in the \"Create download task via file upload\" feature in Synology Download Station before 3.5-2962 allows remote attackers to inject arbitrary web script or HTML via the name element in the Info dictionary in a torrent file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hr3v-9w59-cq9c/GHSA-hr3v-9w59-cq9c.json b/advisories/unreviewed/2022/05/GHSA-hr3v-9w59-cq9c/GHSA-hr3v-9w59-cq9c.json index cf3c2536b4c..31fdc4327cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-hr3v-9w59-cq9c/GHSA-hr3v-9w59-cq9c.json +++ b/advisories/unreviewed/2022/05/GHSA-hr3v-9w59-cq9c/GHSA-hr3v-9w59-cq9c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hv45-8vp2-m2c8/GHSA-hv45-8vp2-m2c8.json b/advisories/unreviewed/2022/05/GHSA-hv45-8vp2-m2c8/GHSA-hv45-8vp2-m2c8.json index 1b6e4b15d18..55842cd589c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hv45-8vp2-m2c8/GHSA-hv45-8vp2-m2c8.json +++ b/advisories/unreviewed/2022/05/GHSA-hv45-8vp2-m2c8/GHSA-hv45-8vp2-m2c8.json @@ -7,12 +7,8 @@ "CVE-2010-3573" ], "details": "Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this is related to missing validation of request headers in the HttpURLConnection class when they are set by applets, which allows remote attackers to bypass the intended security policy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -136,9 +132,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hv57-2phm-3w47/GHSA-hv57-2phm-3w47.json b/advisories/unreviewed/2022/05/GHSA-hv57-2phm-3w47/GHSA-hv57-2phm-3w47.json index 49e662e449f..012593229ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-hv57-2phm-3w47/GHSA-hv57-2phm-3w47.json +++ b/advisories/unreviewed/2022/05/GHSA-hv57-2phm-3w47/GHSA-hv57-2phm-3w47.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hv89-w63p-3mf5/GHSA-hv89-w63p-3mf5.json b/advisories/unreviewed/2022/05/GHSA-hv89-w63p-3mf5/GHSA-hv89-w63p-3mf5.json index b5aec7d72d3..aa26dad4803 100644 --- a/advisories/unreviewed/2022/05/GHSA-hv89-w63p-3mf5/GHSA-hv89-w63p-3mf5.json +++ b/advisories/unreviewed/2022/05/GHSA-hv89-w63p-3mf5/GHSA-hv89-w63p-3mf5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvwv-jpfj-687p/GHSA-hvwv-jpfj-687p.json b/advisories/unreviewed/2022/05/GHSA-hvwv-jpfj-687p/GHSA-hvwv-jpfj-687p.json index 4f18962fc45..401d6e61fc9 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvwv-jpfj-687p/GHSA-hvwv-jpfj-687p.json +++ b/advisories/unreviewed/2022/05/GHSA-hvwv-jpfj-687p/GHSA-hvwv-jpfj-687p.json @@ -7,12 +7,8 @@ "CVE-2010-3014" ], "details": "The Coda filesystem kernel module, as used in NetBSD and FreeBSD, when Coda is loaded and Venus is running with /coda mounted, allows local users to read sensitive heap memory via a large out_size value in a ViceIoctl struct to a Coda ioctl, which triggers a buffer over-read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hw48-8j58-8vvg/GHSA-hw48-8j58-8vvg.json b/advisories/unreviewed/2022/05/GHSA-hw48-8j58-8vvg/GHSA-hw48-8j58-8vvg.json index ed91d196c49..ba512336c2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hw48-8j58-8vvg/GHSA-hw48-8j58-8vvg.json +++ b/advisories/unreviewed/2022/05/GHSA-hw48-8j58-8vvg/GHSA-hw48-8j58-8vvg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hwf6-mrmq-vv3x/GHSA-hwf6-mrmq-vv3x.json b/advisories/unreviewed/2022/05/GHSA-hwf6-mrmq-vv3x/GHSA-hwf6-mrmq-vv3x.json index 7d62544f80d..fd4e7be26fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwf6-mrmq-vv3x/GHSA-hwf6-mrmq-vv3x.json +++ b/advisories/unreviewed/2022/05/GHSA-hwf6-mrmq-vv3x/GHSA-hwf6-mrmq-vv3x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hx3v-mmq4-4qmx/GHSA-hx3v-mmq4-4qmx.json b/advisories/unreviewed/2022/05/GHSA-hx3v-mmq4-4qmx/GHSA-hx3v-mmq4-4qmx.json index 8f340026652..ca0ab1dc917 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx3v-mmq4-4qmx/GHSA-hx3v-mmq4-4qmx.json +++ b/advisories/unreviewed/2022/05/GHSA-hx3v-mmq4-4qmx/GHSA-hx3v-mmq4-4qmx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hx43-xr5v-rrcq/GHSA-hx43-xr5v-rrcq.json b/advisories/unreviewed/2022/05/GHSA-hx43-xr5v-rrcq/GHSA-hx43-xr5v-rrcq.json index 7386a991012..9165e43dc6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx43-xr5v-rrcq/GHSA-hx43-xr5v-rrcq.json +++ b/advisories/unreviewed/2022/05/GHSA-hx43-xr5v-rrcq/GHSA-hx43-xr5v-rrcq.json @@ -7,12 +7,8 @@ "CVE-2010-1904" ], "details": "SQL injection vulnerability in EMC RSA Key Manager (RKM) C Client 1.5.x allows user-assisted remote attackers to execute arbitrary SQL commands via the metadata section of encrypted key data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hxj2-q4hf-jmpf/GHSA-hxj2-q4hf-jmpf.json b/advisories/unreviewed/2022/05/GHSA-hxj2-q4hf-jmpf/GHSA-hxj2-q4hf-jmpf.json index d07686ecd73..13f88cac5f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-hxj2-q4hf-jmpf/GHSA-hxj2-q4hf-jmpf.json +++ b/advisories/unreviewed/2022/05/GHSA-hxj2-q4hf-jmpf/GHSA-hxj2-q4hf-jmpf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hxvc-gvxm-rjwq/GHSA-hxvc-gvxm-rjwq.json b/advisories/unreviewed/2022/05/GHSA-hxvc-gvxm-rjwq/GHSA-hxvc-gvxm-rjwq.json index 8cc448a0b9c..3d3e599a29c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hxvc-gvxm-rjwq/GHSA-hxvc-gvxm-rjwq.json +++ b/advisories/unreviewed/2022/05/GHSA-hxvc-gvxm-rjwq/GHSA-hxvc-gvxm-rjwq.json @@ -7,12 +7,8 @@ "CVE-2010-2704" ], "details": "Buffer overflow in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long HTTP request to nnmrptconfig.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j2p8-r653-mhwj/GHSA-j2p8-r653-mhwj.json b/advisories/unreviewed/2022/05/GHSA-j2p8-r653-mhwj/GHSA-j2p8-r653-mhwj.json index 972916721fe..f5ef59b25f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2p8-r653-mhwj/GHSA-j2p8-r653-mhwj.json +++ b/advisories/unreviewed/2022/05/GHSA-j2p8-r653-mhwj/GHSA-j2p8-r653-mhwj.json @@ -7,12 +7,8 @@ "CVE-2015-5256" ], "details": "Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript whitelist protection mechanism, which allows attackers to bypass intended access restrictions via a crafted URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j2rp-vprg-5m9q/GHSA-j2rp-vprg-5m9q.json b/advisories/unreviewed/2022/05/GHSA-j2rp-vprg-5m9q/GHSA-j2rp-vprg-5m9q.json index bd1fb59f259..2901484acff 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2rp-vprg-5m9q/GHSA-j2rp-vprg-5m9q.json +++ b/advisories/unreviewed/2022/05/GHSA-j2rp-vprg-5m9q/GHSA-j2rp-vprg-5m9q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j3c8-xv8h-h8mv/GHSA-j3c8-xv8h-h8mv.json b/advisories/unreviewed/2022/05/GHSA-j3c8-xv8h-h8mv/GHSA-j3c8-xv8h-h8mv.json index 8ce30f5e537..c421c262446 100644 --- a/advisories/unreviewed/2022/05/GHSA-j3c8-xv8h-h8mv/GHSA-j3c8-xv8h-h8mv.json +++ b/advisories/unreviewed/2022/05/GHSA-j3c8-xv8h-h8mv/GHSA-j3c8-xv8h-h8mv.json @@ -7,12 +7,8 @@ "CVE-2015-3008" ], "details": "Asterisk Open Source 1.8 before 1.8.32.3, 11.x before 11.17.1, 12.x before 12.8.2, and 13.x before 13.3.2 and Certified Asterisk 1.8.28 before 1.8.28-cert5, 11.6 before 11.6-cert11, and 13.1 before 13.1-cert2, when registering a SIP TLS device, does not properly handle a null byte in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j3q2-gpvv-p2cf/GHSA-j3q2-gpvv-p2cf.json b/advisories/unreviewed/2022/05/GHSA-j3q2-gpvv-p2cf/GHSA-j3q2-gpvv-p2cf.json index 0150b69d48b..3fea9e17555 100644 --- a/advisories/unreviewed/2022/05/GHSA-j3q2-gpvv-p2cf/GHSA-j3q2-gpvv-p2cf.json +++ b/advisories/unreviewed/2022/05/GHSA-j3q2-gpvv-p2cf/GHSA-j3q2-gpvv-p2cf.json @@ -7,12 +7,8 @@ "CVE-2010-2878" ], "details": "DIRAPIX.dll in Adobe Shockwave Player before 11.5.8.612 does not properly validate a value associated with a buffer seek for a Director movie, which allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted movie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j3q3-5985-p58m/GHSA-j3q3-5985-p58m.json b/advisories/unreviewed/2022/05/GHSA-j3q3-5985-p58m/GHSA-j3q3-5985-p58m.json index cb87f754ac8..a15d924237a 100644 --- a/advisories/unreviewed/2022/05/GHSA-j3q3-5985-p58m/GHSA-j3q3-5985-p58m.json +++ b/advisories/unreviewed/2022/05/GHSA-j3q3-5985-p58m/GHSA-j3q3-5985-p58m.json @@ -7,12 +7,8 @@ "CVE-2010-3754" ], "details": "The FXCLI_OraBR_Exec_Command function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 uses values of packet fields to determine the content and length of data copied to memory, which allows remote attackers to execute arbitrary code via a crafted packet. NOTE: this might overlap CVE-2010-3059.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j48j-5jcm-qmx8/GHSA-j48j-5jcm-qmx8.json b/advisories/unreviewed/2022/05/GHSA-j48j-5jcm-qmx8/GHSA-j48j-5jcm-qmx8.json index 5b28ca533c7..b674d366100 100644 --- a/advisories/unreviewed/2022/05/GHSA-j48j-5jcm-qmx8/GHSA-j48j-5jcm-qmx8.json +++ b/advisories/unreviewed/2022/05/GHSA-j48j-5jcm-qmx8/GHSA-j48j-5jcm-qmx8.json @@ -7,12 +7,8 @@ "CVE-2010-3585" ], "details": "Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to ovs-agent. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a third party researcher that this is related to the exposure of unspecified functions using XML-RPC.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j4pr-v554-qjg5/GHSA-j4pr-v554-qjg5.json b/advisories/unreviewed/2022/05/GHSA-j4pr-v554-qjg5/GHSA-j4pr-v554-qjg5.json index 03ce0bea10e..b43296c71f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4pr-v554-qjg5/GHSA-j4pr-v554-qjg5.json +++ b/advisories/unreviewed/2022/05/GHSA-j4pr-v554-qjg5/GHSA-j4pr-v554-qjg5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j5qf-h49p-8722/GHSA-j5qf-h49p-8722.json b/advisories/unreviewed/2022/05/GHSA-j5qf-h49p-8722/GHSA-j5qf-h49p-8722.json index 4f8c765c20b..93941b81b3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5qf-h49p-8722/GHSA-j5qf-h49p-8722.json +++ b/advisories/unreviewed/2022/05/GHSA-j5qf-h49p-8722/GHSA-j5qf-h49p-8722.json @@ -7,12 +7,8 @@ "CVE-2010-3743" ], "details": "Directory traversal vulnerability in Visual Synapse HTTP Server 1.0 RC1 through RC3, and 0.60 and earlier, allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j677-8364-49vm/GHSA-j677-8364-49vm.json b/advisories/unreviewed/2022/05/GHSA-j677-8364-49vm/GHSA-j677-8364-49vm.json index 1fe53052bbb..f2fbeca3051 100644 --- a/advisories/unreviewed/2022/05/GHSA-j677-8364-49vm/GHSA-j677-8364-49vm.json +++ b/advisories/unreviewed/2022/05/GHSA-j677-8364-49vm/GHSA-j677-8364-49vm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j759-j745-p8g8/GHSA-j759-j745-p8g8.json b/advisories/unreviewed/2022/05/GHSA-j759-j745-p8g8/GHSA-j759-j745-p8g8.json index 0190e6dc26d..52150497624 100644 --- a/advisories/unreviewed/2022/05/GHSA-j759-j745-p8g8/GHSA-j759-j745-p8g8.json +++ b/advisories/unreviewed/2022/05/GHSA-j759-j745-p8g8/GHSA-j759-j745-p8g8.json @@ -7,12 +7,8 @@ "CVE-2010-2892" ], "details": "gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request forgery (CSRF) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j7hg-q2fc-mphj/GHSA-j7hg-q2fc-mphj.json b/advisories/unreviewed/2022/05/GHSA-j7hg-q2fc-mphj/GHSA-j7hg-q2fc-mphj.json index 45f4f408a89..7301f798867 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7hg-q2fc-mphj/GHSA-j7hg-q2fc-mphj.json +++ b/advisories/unreviewed/2022/05/GHSA-j7hg-q2fc-mphj/GHSA-j7hg-q2fc-mphj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j8q7-5rjg-hm38/GHSA-j8q7-5rjg-hm38.json b/advisories/unreviewed/2022/05/GHSA-j8q7-5rjg-hm38/GHSA-j8q7-5rjg-hm38.json index 1c6247117fc..18da6a2ed97 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8q7-5rjg-hm38/GHSA-j8q7-5rjg-hm38.json +++ b/advisories/unreviewed/2022/05/GHSA-j8q7-5rjg-hm38/GHSA-j8q7-5rjg-hm38.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j8wq-qrfv-42q5/GHSA-j8wq-qrfv-42q5.json b/advisories/unreviewed/2022/05/GHSA-j8wq-qrfv-42q5/GHSA-j8wq-qrfv-42q5.json index d8c3dbd27ee..e2f03e16bdf 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8wq-qrfv-42q5/GHSA-j8wq-qrfv-42q5.json +++ b/advisories/unreviewed/2022/05/GHSA-j8wq-qrfv-42q5/GHSA-j8wq-qrfv-42q5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jcgx-f9p7-q72g/GHSA-jcgx-f9p7-q72g.json b/advisories/unreviewed/2022/05/GHSA-jcgx-f9p7-q72g/GHSA-jcgx-f9p7-q72g.json index 0264807e30b..0b59388429f 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcgx-f9p7-q72g/GHSA-jcgx-f9p7-q72g.json +++ b/advisories/unreviewed/2022/05/GHSA-jcgx-f9p7-q72g/GHSA-jcgx-f9p7-q72g.json @@ -7,12 +7,8 @@ "CVE-2010-2104" ], "details": "Directory traversal vulnerability in Orbit Downloader 3.0.0.4 and 3.0.0.5 allows user-assisted remote attackers to write arbitrary files via a metalink file containing directory traversal sequences in the name attribute of a file element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jcm8-jgjm-3q85/GHSA-jcm8-jgjm-3q85.json b/advisories/unreviewed/2022/05/GHSA-jcm8-jgjm-3q85/GHSA-jcm8-jgjm-3q85.json index 0ad4829a12f..ad4eed1e761 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcm8-jgjm-3q85/GHSA-jcm8-jgjm-3q85.json +++ b/advisories/unreviewed/2022/05/GHSA-jcm8-jgjm-3q85/GHSA-jcm8-jgjm-3q85.json @@ -7,12 +7,8 @@ "CVE-2010-3189" ], "details": "The extSetOwner function in the UfProxyBrowserCtrl ActiveX control (UfPBCtrl.dll) in Trend Micro Internet Security Pro 2010 allows remote attackers to execute arbitrary code via an invalid address that is dereferenced as a pointer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jcpf-wpvf-wp62/GHSA-jcpf-wpvf-wp62.json b/advisories/unreviewed/2022/05/GHSA-jcpf-wpvf-wp62/GHSA-jcpf-wpvf-wp62.json index 6711cee0153..38eeac869db 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcpf-wpvf-wp62/GHSA-jcpf-wpvf-wp62.json +++ b/advisories/unreviewed/2022/05/GHSA-jcpf-wpvf-wp62/GHSA-jcpf-wpvf-wp62.json @@ -7,12 +7,8 @@ "CVE-2010-2989" ], "details": "nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to obtain sensitive information via a request to the /feed method, which reveals the version in a response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jcxm-4ggm-g3qw/GHSA-jcxm-4ggm-g3qw.json b/advisories/unreviewed/2022/05/GHSA-jcxm-4ggm-g3qw/GHSA-jcxm-4ggm-g3qw.json index 6f3c423cd3f..124e02df66d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcxm-4ggm-g3qw/GHSA-jcxm-4ggm-g3qw.json +++ b/advisories/unreviewed/2022/05/GHSA-jcxm-4ggm-g3qw/GHSA-jcxm-4ggm-g3qw.json @@ -7,12 +7,8 @@ "CVE-2010-1794" ], "details": "The webdav_mount function in webdav_vfsops.c in the WebDAV kernel extension (aka webdav_fs.kext) for Mac OS X 10.6 allows local users to cause a denial of service (panic) via a mount request with a large integer in the pa_socket_namelen field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jf48-446q-8cg5/GHSA-jf48-446q-8cg5.json b/advisories/unreviewed/2022/05/GHSA-jf48-446q-8cg5/GHSA-jf48-446q-8cg5.json index bfab3c0d072..b673e942334 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf48-446q-8cg5/GHSA-jf48-446q-8cg5.json +++ b/advisories/unreviewed/2022/05/GHSA-jf48-446q-8cg5/GHSA-jf48-446q-8cg5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jf7f-x93v-jf47/GHSA-jf7f-x93v-jf47.json b/advisories/unreviewed/2022/05/GHSA-jf7f-x93v-jf47/GHSA-jf7f-x93v-jf47.json index a5683fcdbf0..5754d7932ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf7f-x93v-jf47/GHSA-jf7f-x93v-jf47.json +++ b/advisories/unreviewed/2022/05/GHSA-jf7f-x93v-jf47/GHSA-jf7f-x93v-jf47.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jf7w-5c6x-8f53/GHSA-jf7w-5c6x-8f53.json b/advisories/unreviewed/2022/05/GHSA-jf7w-5c6x-8f53/GHSA-jf7w-5c6x-8f53.json index 2d157a365be..f31cef295b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf7w-5c6x-8f53/GHSA-jf7w-5c6x-8f53.json +++ b/advisories/unreviewed/2022/05/GHSA-jf7w-5c6x-8f53/GHSA-jf7w-5c6x-8f53.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jfjq-q734-3ppx/GHSA-jfjq-q734-3ppx.json b/advisories/unreviewed/2022/05/GHSA-jfjq-q734-3ppx/GHSA-jfjq-q734-3ppx.json index fd0e6b5e371..608d9711f71 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfjq-q734-3ppx/GHSA-jfjq-q734-3ppx.json +++ b/advisories/unreviewed/2022/05/GHSA-jfjq-q734-3ppx/GHSA-jfjq-q734-3ppx.json @@ -7,12 +7,8 @@ "CVE-2010-1610" ], "details": "Cross-site request forgery (CSRF) vulnerability in index.php in OpenCart 1.4 allows remote attackers to hijack the authentication of an application administrator for requests that create an administrative account via a POST request with the route parameter set to \"user/user/insert.\" NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jh3f-mjpv-3xf2/GHSA-jh3f-mjpv-3xf2.json b/advisories/unreviewed/2022/05/GHSA-jh3f-mjpv-3xf2/GHSA-jh3f-mjpv-3xf2.json index 7b5fa9071ad..90164b23cf1 100644 --- a/advisories/unreviewed/2022/05/GHSA-jh3f-mjpv-3xf2/GHSA-jh3f-mjpv-3xf2.json +++ b/advisories/unreviewed/2022/05/GHSA-jh3f-mjpv-3xf2/GHSA-jh3f-mjpv-3xf2.json @@ -7,12 +7,8 @@ "CVE-2015-7712" ], "details": "Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remote authenticated users with the AT_PRIV_GRADEBOOK privilege to execute arbitrary PHP code via the (1) asc or (2) desc parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jjvr-cr6v-6j24/GHSA-jjvr-cr6v-6j24.json b/advisories/unreviewed/2022/05/GHSA-jjvr-cr6v-6j24/GHSA-jjvr-cr6v-6j24.json index 2424142f6be..7cf85163200 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjvr-cr6v-6j24/GHSA-jjvr-cr6v-6j24.json +++ b/advisories/unreviewed/2022/05/GHSA-jjvr-cr6v-6j24/GHSA-jjvr-cr6v-6j24.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jmc5-w94v-7p94/GHSA-jmc5-w94v-7p94.json b/advisories/unreviewed/2022/05/GHSA-jmc5-w94v-7p94/GHSA-jmc5-w94v-7p94.json index d4961bc68e6..636e2c9625f 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmc5-w94v-7p94/GHSA-jmc5-w94v-7p94.json +++ b/advisories/unreviewed/2022/05/GHSA-jmc5-w94v-7p94/GHSA-jmc5-w94v-7p94.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jmfh-h6p2-h9hg/GHSA-jmfh-h6p2-h9hg.json b/advisories/unreviewed/2022/05/GHSA-jmfh-h6p2-h9hg/GHSA-jmfh-h6p2-h9hg.json index af57bde40de..a401d4d018e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmfh-h6p2-h9hg/GHSA-jmfh-h6p2-h9hg.json +++ b/advisories/unreviewed/2022/05/GHSA-jmfh-h6p2-h9hg/GHSA-jmfh-h6p2-h9hg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jmhr-w45r-wv9q/GHSA-jmhr-w45r-wv9q.json b/advisories/unreviewed/2022/05/GHSA-jmhr-w45r-wv9q/GHSA-jmhr-w45r-wv9q.json index 547e09efd25..9355ff1f4d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmhr-w45r-wv9q/GHSA-jmhr-w45r-wv9q.json +++ b/advisories/unreviewed/2022/05/GHSA-jmhr-w45r-wv9q/GHSA-jmhr-w45r-wv9q.json @@ -7,12 +7,8 @@ "CVE-2010-3561" ], "details": "Unspecified vulnerability in the CORBA component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this involves the use of the privileged accept method in the ServerSocket class, which does not limit which hosts can connect and allows remote attackers to bypass intended network access restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -128,9 +124,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jq5m-m9q5-jj6q/GHSA-jq5m-m9q5-jj6q.json b/advisories/unreviewed/2022/05/GHSA-jq5m-m9q5-jj6q/GHSA-jq5m-m9q5-jj6q.json index 3a43d198067..36a7783edda 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq5m-m9q5-jj6q/GHSA-jq5m-m9q5-jj6q.json +++ b/advisories/unreviewed/2022/05/GHSA-jq5m-m9q5-jj6q/GHSA-jq5m-m9q5-jj6q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jqcm-9pcm-mhqr/GHSA-jqcm-9pcm-mhqr.json b/advisories/unreviewed/2022/05/GHSA-jqcm-9pcm-mhqr/GHSA-jqcm-9pcm-mhqr.json index e823cd72532..084bc08d7ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqcm-9pcm-mhqr/GHSA-jqcm-9pcm-mhqr.json +++ b/advisories/unreviewed/2022/05/GHSA-jqcm-9pcm-mhqr/GHSA-jqcm-9pcm-mhqr.json @@ -7,12 +7,8 @@ "CVE-2010-2193" ], "details": "Multiple unspecified vulnerabilities in the CA (1) PSFormX and (2) WebScan ActiveX controls, as distributed on the CA Global Advisor web site until May 2009, allow remote attackers to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrg8-c34p-wgmf/GHSA-jrg8-c34p-wgmf.json b/advisories/unreviewed/2022/05/GHSA-jrg8-c34p-wgmf/GHSA-jrg8-c34p-wgmf.json index f0e8274a126..65a80cba338 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrg8-c34p-wgmf/GHSA-jrg8-c34p-wgmf.json +++ b/advisories/unreviewed/2022/05/GHSA-jrg8-c34p-wgmf/GHSA-jrg8-c34p-wgmf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jvqc-5hhq-rvwf/GHSA-jvqc-5hhq-rvwf.json b/advisories/unreviewed/2022/05/GHSA-jvqc-5hhq-rvwf/GHSA-jvqc-5hhq-rvwf.json index 40cc3542d40..750bd7e78b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvqc-5hhq-rvwf/GHSA-jvqc-5hhq-rvwf.json +++ b/advisories/unreviewed/2022/05/GHSA-jvqc-5hhq-rvwf/GHSA-jvqc-5hhq-rvwf.json @@ -7,12 +7,8 @@ "CVE-2015-5949" ], "details": "VideoLAN VLC media player 2.2.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP file, which triggers the freeing of arbitrary pointers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jvw3-45p9-fr63/GHSA-jvw3-45p9-fr63.json b/advisories/unreviewed/2022/05/GHSA-jvw3-45p9-fr63/GHSA-jvw3-45p9-fr63.json index 066e40a130e..a8d54c9d45d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvw3-45p9-fr63/GHSA-jvw3-45p9-fr63.json +++ b/advisories/unreviewed/2022/05/GHSA-jvw3-45p9-fr63/GHSA-jvw3-45p9-fr63.json @@ -7,12 +7,8 @@ "CVE-2015-5534" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall before 1.8 allow remote attackers to hijack the authentication of administrators for requests that (1) put the website under maintenance via the maintenance_enable parameter or (2) conduct cross-site scripting (XSS) attacks via the maintenance_text parameter to admin/pages/maintenance.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m3f3-25f6-6qrr/GHSA-m3f3-25f6-6qrr.json b/advisories/unreviewed/2022/05/GHSA-m3f3-25f6-6qrr/GHSA-m3f3-25f6-6qrr.json index b8ea81559cd..1befa119690 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3f3-25f6-6qrr/GHSA-m3f3-25f6-6qrr.json +++ b/advisories/unreviewed/2022/05/GHSA-m3f3-25f6-6qrr/GHSA-m3f3-25f6-6qrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m3h2-w8h6-2j5q/GHSA-m3h2-w8h6-2j5q.json b/advisories/unreviewed/2022/05/GHSA-m3h2-w8h6-2j5q/GHSA-m3h2-w8h6-2j5q.json index 0d964fdfc1b..750a9a417ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3h2-w8h6-2j5q/GHSA-m3h2-w8h6-2j5q.json +++ b/advisories/unreviewed/2022/05/GHSA-m3h2-w8h6-2j5q/GHSA-m3h2-w8h6-2j5q.json @@ -7,12 +7,8 @@ "CVE-2010-2879" ], "details": "Multiple integer overflows in the allocator in the TextXtra.x32 module in Adobe Shockwave Player before 11.5.8.612 allow remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted (1) element count or (2) element size value in a file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m3qj-gw3q-pq38/GHSA-m3qj-gw3q-pq38.json b/advisories/unreviewed/2022/05/GHSA-m3qj-gw3q-pq38/GHSA-m3qj-gw3q-pq38.json index 30ad6783e6e..34d6a6bbea5 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3qj-gw3q-pq38/GHSA-m3qj-gw3q-pq38.json +++ b/advisories/unreviewed/2022/05/GHSA-m3qj-gw3q-pq38/GHSA-m3qj-gw3q-pq38.json @@ -7,12 +7,8 @@ "CVE-2010-1909" ], "details": "Buffer overflow in the RunCmd method in the SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to execute arbitrary code via vectors involving \"CreateProcess params.\" NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m3r6-pwx8-f7qx/GHSA-m3r6-pwx8-f7qx.json b/advisories/unreviewed/2022/05/GHSA-m3r6-pwx8-f7qx/GHSA-m3r6-pwx8-f7qx.json index 4e1adc865b0..66aa6b042dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3r6-pwx8-f7qx/GHSA-m3r6-pwx8-f7qx.json +++ b/advisories/unreviewed/2022/05/GHSA-m3r6-pwx8-f7qx/GHSA-m3r6-pwx8-f7qx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m4f8-7fcf-cw56/GHSA-m4f8-7fcf-cw56.json b/advisories/unreviewed/2022/05/GHSA-m4f8-7fcf-cw56/GHSA-m4f8-7fcf-cw56.json index 6eac1563a6f..4515ac7e642 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4f8-7fcf-cw56/GHSA-m4f8-7fcf-cw56.json +++ b/advisories/unreviewed/2022/05/GHSA-m4f8-7fcf-cw56/GHSA-m4f8-7fcf-cw56.json @@ -7,12 +7,8 @@ "CVE-2010-2848" ], "details": "Directory traversal vulnerability in assets/captcha/includes/alikon/playcode.php in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m58f-5mcm-c967/GHSA-m58f-5mcm-c967.json b/advisories/unreviewed/2022/05/GHSA-m58f-5mcm-c967/GHSA-m58f-5mcm-c967.json index c955c78edc7..09451e149be 100644 --- a/advisories/unreviewed/2022/05/GHSA-m58f-5mcm-c967/GHSA-m58f-5mcm-c967.json +++ b/advisories/unreviewed/2022/05/GHSA-m58f-5mcm-c967/GHSA-m58f-5mcm-c967.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m5mf-qr76-39fc/GHSA-m5mf-qr76-39fc.json b/advisories/unreviewed/2022/05/GHSA-m5mf-qr76-39fc/GHSA-m5mf-qr76-39fc.json index 1743135c6c7..055f9183f76 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5mf-qr76-39fc/GHSA-m5mf-qr76-39fc.json +++ b/advisories/unreviewed/2022/05/GHSA-m5mf-qr76-39fc/GHSA-m5mf-qr76-39fc.json @@ -7,12 +7,8 @@ "CVE-2015-4878" ], "details": "Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-4877.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m6fp-vqq2-v9hm/GHSA-m6fp-vqq2-v9hm.json b/advisories/unreviewed/2022/05/GHSA-m6fp-vqq2-v9hm/GHSA-m6fp-vqq2-v9hm.json index 20516434c41..343722be8cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6fp-vqq2-v9hm/GHSA-m6fp-vqq2-v9hm.json +++ b/advisories/unreviewed/2022/05/GHSA-m6fp-vqq2-v9hm/GHSA-m6fp-vqq2-v9hm.json @@ -7,12 +7,8 @@ "CVE-2010-3025" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Tomaz Muraus Open Blog 1.2.1, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) excerpt parameter to application/modules/admin/controllers/posts.php, as reachable by admin/posts/edit; and the (2) content parameter to application/modules/admin/controllers/pages.php, as reachable by admin/posts/edit.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m6fr-478g-xrmj/GHSA-m6fr-478g-xrmj.json b/advisories/unreviewed/2022/05/GHSA-m6fr-478g-xrmj/GHSA-m6fr-478g-xrmj.json index d0decdf93dd..00edcf8ed0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6fr-478g-xrmj/GHSA-m6fr-478g-xrmj.json +++ b/advisories/unreviewed/2022/05/GHSA-m6fr-478g-xrmj/GHSA-m6fr-478g-xrmj.json @@ -7,12 +7,8 @@ "CVE-2010-3550" ], "details": "Unspecified vulnerability in the Java Web Start component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m6wv-v8c4-f6qc/GHSA-m6wv-v8c4-f6qc.json b/advisories/unreviewed/2022/05/GHSA-m6wv-v8c4-f6qc/GHSA-m6wv-v8c4-f6qc.json index d0c0d0c4ca4..64cb03bbe01 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6wv-v8c4-f6qc/GHSA-m6wv-v8c4-f6qc.json +++ b/advisories/unreviewed/2022/05/GHSA-m6wv-v8c4-f6qc/GHSA-m6wv-v8c4-f6qc.json @@ -7,12 +7,8 @@ "CVE-2010-2986" ], "details": "Cross-site scripting (XSS) vulnerability in webacs/QuickSearchAction.do in the search feature in the web interface in Cisco Wireless Control System (WCS) before 6.0(194.0) and 7.x before 7.0.164 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter, aka Bug ID CSCtf14288.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m744-256w-pg4q/GHSA-m744-256w-pg4q.json b/advisories/unreviewed/2022/05/GHSA-m744-256w-pg4q/GHSA-m744-256w-pg4q.json index d8b5f2734da..2d5da892f02 100644 --- a/advisories/unreviewed/2022/05/GHSA-m744-256w-pg4q/GHSA-m744-256w-pg4q.json +++ b/advisories/unreviewed/2022/05/GHSA-m744-256w-pg4q/GHSA-m744-256w-pg4q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m7mr-jwvj-gjjr/GHSA-m7mr-jwvj-gjjr.json b/advisories/unreviewed/2022/05/GHSA-m7mr-jwvj-gjjr/GHSA-m7mr-jwvj-gjjr.json index 7842c5ff399..cbed0a90466 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7mr-jwvj-gjjr/GHSA-m7mr-jwvj-gjjr.json +++ b/advisories/unreviewed/2022/05/GHSA-m7mr-jwvj-gjjr/GHSA-m7mr-jwvj-gjjr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m7x6-w8mx-7jxr/GHSA-m7x6-w8mx-7jxr.json b/advisories/unreviewed/2022/05/GHSA-m7x6-w8mx-7jxr/GHSA-m7x6-w8mx-7jxr.json index 2b5c97f2926..d71de6c3639 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7x6-w8mx-7jxr/GHSA-m7x6-w8mx-7jxr.json +++ b/advisories/unreviewed/2022/05/GHSA-m7x6-w8mx-7jxr/GHSA-m7x6-w8mx-7jxr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m8jr-7683-whmm/GHSA-m8jr-7683-whmm.json b/advisories/unreviewed/2022/05/GHSA-m8jr-7683-whmm/GHSA-m8jr-7683-whmm.json index b7822dfa97c..22c0b71e7e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8jr-7683-whmm/GHSA-m8jr-7683-whmm.json +++ b/advisories/unreviewed/2022/05/GHSA-m8jr-7683-whmm/GHSA-m8jr-7683-whmm.json @@ -7,12 +7,8 @@ "CVE-2010-3152" ], "details": "Untrusted search path vulnerability in Adobe Illustrator CS4 14.0.0, CS5 15.0.1 and earlier, and possibly other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or aires.dll that is located in the same folder as an .ait or .eps file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m8r3-7cw4-x3mh/GHSA-m8r3-7cw4-x3mh.json b/advisories/unreviewed/2022/05/GHSA-m8r3-7cw4-x3mh/GHSA-m8r3-7cw4-x3mh.json index 360f3e4408c..7603505c8aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8r3-7cw4-x3mh/GHSA-m8r3-7cw4-x3mh.json +++ b/advisories/unreviewed/2022/05/GHSA-m8r3-7cw4-x3mh/GHSA-m8r3-7cw4-x3mh.json @@ -7,12 +7,8 @@ "CVE-2010-2615" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in admin/admin.php in Grafik CMS 1.1.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) page_menu and (2) description parameters in an edit_page action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m945-cp8g-j6x8/GHSA-m945-cp8g-j6x8.json b/advisories/unreviewed/2022/05/GHSA-m945-cp8g-j6x8/GHSA-m945-cp8g-j6x8.json index bf3cf129dac..b235296cc61 100644 --- a/advisories/unreviewed/2022/05/GHSA-m945-cp8g-j6x8/GHSA-m945-cp8g-j6x8.json +++ b/advisories/unreviewed/2022/05/GHSA-m945-cp8g-j6x8/GHSA-m945-cp8g-j6x8.json @@ -7,12 +7,8 @@ "CVE-2015-3623" ], "details": "XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server-side request forgery (SSRF) attacks and read arbitrary files via crafted XML data in a request to AccessPoint.aspx.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m9ph-84w3-989x/GHSA-m9ph-84w3-989x.json b/advisories/unreviewed/2022/05/GHSA-m9ph-84w3-989x/GHSA-m9ph-84w3-989x.json index 8f7f8b56762..5c14f0f038a 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9ph-84w3-989x/GHSA-m9ph-84w3-989x.json +++ b/advisories/unreviewed/2022/05/GHSA-m9ph-84w3-989x/GHSA-m9ph-84w3-989x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m9w9-g6vx-mxgc/GHSA-m9w9-g6vx-mxgc.json b/advisories/unreviewed/2022/05/GHSA-m9w9-g6vx-mxgc/GHSA-m9w9-g6vx-mxgc.json index 74a0664caf9..b0b8f569cdf 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9w9-g6vx-mxgc/GHSA-m9w9-g6vx-mxgc.json +++ b/advisories/unreviewed/2022/05/GHSA-m9w9-g6vx-mxgc/GHSA-m9w9-g6vx-mxgc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mf3f-w6v8-55pg/GHSA-mf3f-w6v8-55pg.json b/advisories/unreviewed/2022/05/GHSA-mf3f-w6v8-55pg/GHSA-mf3f-w6v8-55pg.json index e9dd7bc85ed..f53bb9761be 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf3f-w6v8-55pg/GHSA-mf3f-w6v8-55pg.json +++ b/advisories/unreviewed/2022/05/GHSA-mf3f-w6v8-55pg/GHSA-mf3f-w6v8-55pg.json @@ -7,12 +7,8 @@ "CVE-2010-2102" ], "details": "Buffer overflow in Webby Webserver 1.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mf45-g8hg-p9g4/GHSA-mf45-g8hg-p9g4.json b/advisories/unreviewed/2022/05/GHSA-mf45-g8hg-p9g4/GHSA-mf45-g8hg-p9g4.json index 7177f3a8faf..2e1447c30e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf45-g8hg-p9g4/GHSA-mf45-g8hg-p9g4.json +++ b/advisories/unreviewed/2022/05/GHSA-mf45-g8hg-p9g4/GHSA-mf45-g8hg-p9g4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mg6h-rr5v-5cx6/GHSA-mg6h-rr5v-5cx6.json b/advisories/unreviewed/2022/05/GHSA-mg6h-rr5v-5cx6/GHSA-mg6h-rr5v-5cx6.json index 72d786c49cc..97b839dd3e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-mg6h-rr5v-5cx6/GHSA-mg6h-rr5v-5cx6.json +++ b/advisories/unreviewed/2022/05/GHSA-mg6h-rr5v-5cx6/GHSA-mg6h-rr5v-5cx6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mh8p-wwgw-w9wc/GHSA-mh8p-wwgw-w9wc.json b/advisories/unreviewed/2022/05/GHSA-mh8p-wwgw-w9wc/GHSA-mh8p-wwgw-w9wc.json index 8d804ae3f17..910dd281c58 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh8p-wwgw-w9wc/GHSA-mh8p-wwgw-w9wc.json +++ b/advisories/unreviewed/2022/05/GHSA-mh8p-wwgw-w9wc/GHSA-mh8p-wwgw-w9wc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mjp2-jc3f-fh7r/GHSA-mjp2-jc3f-fh7r.json b/advisories/unreviewed/2022/05/GHSA-mjp2-jc3f-fh7r/GHSA-mjp2-jc3f-fh7r.json index 3c1bfebe479..cd414aea9e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjp2-jc3f-fh7r/GHSA-mjp2-jc3f-fh7r.json +++ b/advisories/unreviewed/2022/05/GHSA-mjp2-jc3f-fh7r/GHSA-mjp2-jc3f-fh7r.json @@ -7,12 +7,8 @@ "CVE-2015-5375" ], "details": "Cross-site scripting (XSS) vulnerability in unspecified dialogs for printing content in the Front End in Open-Xchange Server 6 and OX App Suite before 6.22.8-rev8, 6.22.9 before 6.22.9-rev15m, 7.x before 7.6.1-rev25, and 7.6.2 before 7.6.2-rev20 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to object properties.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjrq-24m2-vm45/GHSA-mjrq-24m2-vm45.json b/advisories/unreviewed/2022/05/GHSA-mjrq-24m2-vm45/GHSA-mjrq-24m2-vm45.json index 88efe27ed32..544d89a5e97 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjrq-24m2-vm45/GHSA-mjrq-24m2-vm45.json +++ b/advisories/unreviewed/2022/05/GHSA-mjrq-24m2-vm45/GHSA-mjrq-24m2-vm45.json @@ -7,12 +7,8 @@ "CVE-2010-2289" ], "details": "Open redirect vulnerability in dana/home/homepage.cgi in Juniper Networks IVE 6.5R1 (Build 14599) and 6.5R2 (Build 14951) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Location parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjww-vqqw-v78q/GHSA-mjww-vqqw-v78q.json b/advisories/unreviewed/2022/05/GHSA-mjww-vqqw-v78q/GHSA-mjww-vqqw-v78q.json index 6ccca193cb0..e8e255cb385 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjww-vqqw-v78q/GHSA-mjww-vqqw-v78q.json +++ b/advisories/unreviewed/2022/05/GHSA-mjww-vqqw-v78q/GHSA-mjww-vqqw-v78q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mm84-f7fc-q3fw/GHSA-mm84-f7fc-q3fw.json b/advisories/unreviewed/2022/05/GHSA-mm84-f7fc-q3fw/GHSA-mm84-f7fc-q3fw.json index deec169ba39..845f97c40b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-mm84-f7fc-q3fw/GHSA-mm84-f7fc-q3fw.json +++ b/advisories/unreviewed/2022/05/GHSA-mm84-f7fc-q3fw/GHSA-mm84-f7fc-q3fw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mmjg-9xh9-64mx/GHSA-mmjg-9xh9-64mx.json b/advisories/unreviewed/2022/05/GHSA-mmjg-9xh9-64mx/GHSA-mmjg-9xh9-64mx.json index 07599124326..2de31d002b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmjg-9xh9-64mx/GHSA-mmjg-9xh9-64mx.json +++ b/advisories/unreviewed/2022/05/GHSA-mmjg-9xh9-64mx/GHSA-mmjg-9xh9-64mx.json @@ -7,12 +7,8 @@ "CVE-2010-2867" ], "details": "DIRAPIX.dll in Adobe Shockwave Player before 11.5.8.612 does not properly handle a certain return value associated with the rcsL chunk in a Director movie, which allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted movie, related to a \"pointer offset vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mp8j-698r-2p98/GHSA-mp8j-698r-2p98.json b/advisories/unreviewed/2022/05/GHSA-mp8j-698r-2p98/GHSA-mp8j-698r-2p98.json index b62ad2d582a..5d7f76dfe2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-mp8j-698r-2p98/GHSA-mp8j-698r-2p98.json +++ b/advisories/unreviewed/2022/05/GHSA-mp8j-698r-2p98/GHSA-mp8j-698r-2p98.json @@ -7,12 +7,8 @@ "CVE-2010-2292" ], "details": "Cross-site scripting (XSS) vulnerability in the Ping tools web interface in Dlink Di-604 router allows remote attackers to inject arbitrary web script or HTML via the IP field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mpvf-ccw8-mq8c/GHSA-mpvf-ccw8-mq8c.json b/advisories/unreviewed/2022/05/GHSA-mpvf-ccw8-mq8c/GHSA-mpvf-ccw8-mq8c.json index a2be5b4a2c6..f28cf876a6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpvf-ccw8-mq8c/GHSA-mpvf-ccw8-mq8c.json +++ b/advisories/unreviewed/2022/05/GHSA-mpvf-ccw8-mq8c/GHSA-mpvf-ccw8-mq8c.json @@ -7,12 +7,8 @@ "CVE-2010-1520" ], "details": "Cross-site scripting (XSS) vulnerability in logout.php in TaskFreak! Original multi user before 0.6.4 allows remote attackers to inject arbitrary web script or HTML via the tznMessage parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mqmf-7h6w-h2r4/GHSA-mqmf-7h6w-h2r4.json b/advisories/unreviewed/2022/05/GHSA-mqmf-7h6w-h2r4/GHSA-mqmf-7h6w-h2r4.json index fe421426af7..d0056fafd2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqmf-7h6w-h2r4/GHSA-mqmf-7h6w-h2r4.json +++ b/advisories/unreviewed/2022/05/GHSA-mqmf-7h6w-h2r4/GHSA-mqmf-7h6w-h2r4.json @@ -7,12 +7,8 @@ "CVE-2010-2624" ], "details": "Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) comment parameter to add_comments.php, (2) values parameter to tags_details.php, or (3) begin parameter to greetings.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mqp7-mpjg-72pw/GHSA-mqp7-mpjg-72pw.json b/advisories/unreviewed/2022/05/GHSA-mqp7-mpjg-72pw/GHSA-mqp7-mpjg-72pw.json index d433be0740b..23475850bdf 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqp7-mpjg-72pw/GHSA-mqp7-mpjg-72pw.json +++ b/advisories/unreviewed/2022/05/GHSA-mqp7-mpjg-72pw/GHSA-mqp7-mpjg-72pw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mqrf-j5vq-j64f/GHSA-mqrf-j5vq-j64f.json b/advisories/unreviewed/2022/05/GHSA-mqrf-j5vq-j64f/GHSA-mqrf-j5vq-j64f.json index 5856e24c0b3..9c6f68a27f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqrf-j5vq-j64f/GHSA-mqrf-j5vq-j64f.json +++ b/advisories/unreviewed/2022/05/GHSA-mqrf-j5vq-j64f/GHSA-mqrf-j5vq-j64f.json @@ -7,12 +7,8 @@ "CVE-2010-1986" ], "details": "Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory consumption and application crash) via JavaScript code that creates multiple arrays containing elements with long string values, and then appends long strings to the content of a P element, related to the gfxWindowsFontGroup::MakeTextRun function in xul.dll, a different vulnerability than CVE-2009-1571.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mr9w-cm2q-46cm/GHSA-mr9w-cm2q-46cm.json b/advisories/unreviewed/2022/05/GHSA-mr9w-cm2q-46cm/GHSA-mr9w-cm2q-46cm.json index e4620af8e3a..d78ab29e1fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-mr9w-cm2q-46cm/GHSA-mr9w-cm2q-46cm.json +++ b/advisories/unreviewed/2022/05/GHSA-mr9w-cm2q-46cm/GHSA-mr9w-cm2q-46cm.json @@ -7,12 +7,8 @@ "CVE-2010-3719" ], "details": "Eval injection vulnerability in IMAdminSchedTask.asp in the administrative interface for Symantec IM Manager 8.4.16 and earlier allows remote attackers to execute arbitrary code via unspecified parameters to the ScheduleTask method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mrq8-8w45-6xcj/GHSA-mrq8-8w45-6xcj.json b/advisories/unreviewed/2022/05/GHSA-mrq8-8w45-6xcj/GHSA-mrq8-8w45-6xcj.json index e960e3950fa..da314a594cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrq8-8w45-6xcj/GHSA-mrq8-8w45-6xcj.json +++ b/advisories/unreviewed/2022/05/GHSA-mrq8-8w45-6xcj/GHSA-mrq8-8w45-6xcj.json @@ -7,12 +7,8 @@ "CVE-2015-2315" ], "details": "Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the target parameter in a reminder_popup action to the default URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mv57-p7w6-3hwg/GHSA-mv57-p7w6-3hwg.json b/advisories/unreviewed/2022/05/GHSA-mv57-p7w6-3hwg/GHSA-mv57-p7w6-3hwg.json index 8f7a0c9a38b..2d736d4827c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv57-p7w6-3hwg/GHSA-mv57-p7w6-3hwg.json +++ b/advisories/unreviewed/2022/05/GHSA-mv57-p7w6-3hwg/GHSA-mv57-p7w6-3hwg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mwvc-gfrx-j34p/GHSA-mwvc-gfrx-j34p.json b/advisories/unreviewed/2022/05/GHSA-mwvc-gfrx-j34p/GHSA-mwvc-gfrx-j34p.json index 4de3add5205..50a6a565f8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwvc-gfrx-j34p/GHSA-mwvc-gfrx-j34p.json +++ b/advisories/unreviewed/2022/05/GHSA-mwvc-gfrx-j34p/GHSA-mwvc-gfrx-j34p.json @@ -7,12 +7,8 @@ "CVE-2015-5696" ], "details": "Dell Netvault Backup before 10.0.5 allows remote attackers to cause a denial of service (crash) via a crafted request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p22p-j88v-8qc2/GHSA-p22p-j88v-8qc2.json b/advisories/unreviewed/2022/05/GHSA-p22p-j88v-8qc2/GHSA-p22p-j88v-8qc2.json index 25f3dd539e6..644fabf005f 100644 --- a/advisories/unreviewed/2022/05/GHSA-p22p-j88v-8qc2/GHSA-p22p-j88v-8qc2.json +++ b/advisories/unreviewed/2022/05/GHSA-p22p-j88v-8qc2/GHSA-p22p-j88v-8qc2.json @@ -7,12 +7,8 @@ "CVE-2010-2880" ], "details": "DIRAPI.dll in Adobe Shockwave Player before 11.5.8.612 does not properly parse .dir files, which allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a malformed file containing an invalid value, as demonstrated by a value at position 0x47 of a certain file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p2jm-wp8p-wh7g/GHSA-p2jm-wp8p-wh7g.json b/advisories/unreviewed/2022/05/GHSA-p2jm-wp8p-wh7g/GHSA-p2jm-wp8p-wh7g.json index e695210b336..1ef4b73e924 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2jm-wp8p-wh7g/GHSA-p2jm-wp8p-wh7g.json +++ b/advisories/unreviewed/2022/05/GHSA-p2jm-wp8p-wh7g/GHSA-p2jm-wp8p-wh7g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p2w4-6crq-85gc/GHSA-p2w4-6crq-85gc.json b/advisories/unreviewed/2022/05/GHSA-p2w4-6crq-85gc/GHSA-p2w4-6crq-85gc.json index b83a8e6c961..d5a3532cccd 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2w4-6crq-85gc/GHSA-p2w4-6crq-85gc.json +++ b/advisories/unreviewed/2022/05/GHSA-p2w4-6crq-85gc/GHSA-p2w4-6crq-85gc.json @@ -7,12 +7,8 @@ "CVE-2015-6940" ], "details": "The GetResource servlet in Pentaho Business Analytics (BA) Suite 4.5.x, 4.8.x, and 5.0.x through 5.2.x and Pentaho Data Integration (PDI) Suite 4.3.x, 4.4.x, and 5.0.x through 5.2.x does not restrict access to files in the pentaho-solutions/system folder, which allows remote attackers to obtain passwords and other sensitive information via a file name in the resource parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p336-q5gx-939v/GHSA-p336-q5gx-939v.json b/advisories/unreviewed/2022/05/GHSA-p336-q5gx-939v/GHSA-p336-q5gx-939v.json index 732da4f0105..9ebe7522741 100644 --- a/advisories/unreviewed/2022/05/GHSA-p336-q5gx-939v/GHSA-p336-q5gx-939v.json +++ b/advisories/unreviewed/2022/05/GHSA-p336-q5gx-939v/GHSA-p336-q5gx-939v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p3wm-jpp9-fx43/GHSA-p3wm-jpp9-fx43.json b/advisories/unreviewed/2022/05/GHSA-p3wm-jpp9-fx43/GHSA-p3wm-jpp9-fx43.json index 37a120b989f..6319e56361a 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3wm-jpp9-fx43/GHSA-p3wm-jpp9-fx43.json +++ b/advisories/unreviewed/2022/05/GHSA-p3wm-jpp9-fx43/GHSA-p3wm-jpp9-fx43.json @@ -7,12 +7,8 @@ "CVE-2012-0710" ], "details": "IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Distributed Relational Database Architecture (DRDA) request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p43p-rc8p-qq76/GHSA-p43p-rc8p-qq76.json b/advisories/unreviewed/2022/05/GHSA-p43p-rc8p-qq76/GHSA-p43p-rc8p-qq76.json index 7f2af5aacf8..5fa84fc5d4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-p43p-rc8p-qq76/GHSA-p43p-rc8p-qq76.json +++ b/advisories/unreviewed/2022/05/GHSA-p43p-rc8p-qq76/GHSA-p43p-rc8p-qq76.json @@ -7,12 +7,8 @@ "CVE-2010-3455" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in AChecker 1.0 allows remote attackers to inject arbitrary web script or HTML via the uri parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p536-w4x8-3xwr/GHSA-p536-w4x8-3xwr.json b/advisories/unreviewed/2022/05/GHSA-p536-w4x8-3xwr/GHSA-p536-w4x8-3xwr.json index b75c2e2b097..908c6d83aef 100644 --- a/advisories/unreviewed/2022/05/GHSA-p536-w4x8-3xwr/GHSA-p536-w4x8-3xwr.json +++ b/advisories/unreviewed/2022/05/GHSA-p536-w4x8-3xwr/GHSA-p536-w4x8-3xwr.json @@ -7,12 +7,8 @@ "CVE-2010-3149" ], "details": "Untrusted search path vulnerability in Adobe Device Central CS5 3.0.0(376), 3.0.1.0 (3027), and probably other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse qtcf.dll that is located in the same folder as an ADCP file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p635-3wgg-xwf4/GHSA-p635-3wgg-xwf4.json b/advisories/unreviewed/2022/05/GHSA-p635-3wgg-xwf4/GHSA-p635-3wgg-xwf4.json index f66a05eb087..8fe4bedb762 100644 --- a/advisories/unreviewed/2022/05/GHSA-p635-3wgg-xwf4/GHSA-p635-3wgg-xwf4.json +++ b/advisories/unreviewed/2022/05/GHSA-p635-3wgg-xwf4/GHSA-p635-3wgg-xwf4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p6mv-98h5-3r5j/GHSA-p6mv-98h5-3r5j.json b/advisories/unreviewed/2022/05/GHSA-p6mv-98h5-3r5j/GHSA-p6mv-98h5-3r5j.json index c1cd4780cd3..f0172fd51f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6mv-98h5-3r5j/GHSA-p6mv-98h5-3r5j.json +++ b/advisories/unreviewed/2022/05/GHSA-p6mv-98h5-3r5j/GHSA-p6mv-98h5-3r5j.json @@ -7,12 +7,8 @@ "CVE-2015-2564" ], "details": "SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to users-edit.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p7fx-9frv-pfx7/GHSA-p7fx-9frv-pfx7.json b/advisories/unreviewed/2022/05/GHSA-p7fx-9frv-pfx7/GHSA-p7fx-9frv-pfx7.json index 43c90c51fd2..31da5444ce0 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7fx-9frv-pfx7/GHSA-p7fx-9frv-pfx7.json +++ b/advisories/unreviewed/2022/05/GHSA-p7fx-9frv-pfx7/GHSA-p7fx-9frv-pfx7.json @@ -7,12 +7,8 @@ "CVE-2010-2580" ], "details": "The SMTP service (MESMTPC.exe) in MailEnable 3.x and 4.25 does not properly perform a length check, which allows remote attackers to cause a denial of service (crash) via a long (1) email address in the MAIL FROM command, or (2) domain name in the RCPT TO command, which triggers an \"unhandled invalid parameter error.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p7rv-pxf2-6jmq/GHSA-p7rv-pxf2-6jmq.json b/advisories/unreviewed/2022/05/GHSA-p7rv-pxf2-6jmq/GHSA-p7rv-pxf2-6jmq.json index 5948076b18f..4dd00f58723 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7rv-pxf2-6jmq/GHSA-p7rv-pxf2-6jmq.json +++ b/advisories/unreviewed/2022/05/GHSA-p7rv-pxf2-6jmq/GHSA-p7rv-pxf2-6jmq.json @@ -7,12 +7,8 @@ "CVE-2010-2437" ], "details": "Cross-site scripting (XSS) vulnerability in class/tools.class.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the comment variable to modules/blog/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p8ff-7f8p-6244/GHSA-p8ff-7f8p-6244.json b/advisories/unreviewed/2022/05/GHSA-p8ff-7f8p-6244/GHSA-p8ff-7f8p-6244.json index 5f6b9fd389d..129e1f1fcb1 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8ff-7f8p-6244/GHSA-p8ff-7f8p-6244.json +++ b/advisories/unreviewed/2022/05/GHSA-p8ff-7f8p-6244/GHSA-p8ff-7f8p-6244.json @@ -7,12 +7,8 @@ "CVE-2010-2851" ], "details": "SQL injection vulnerability in the BookLibrary From Same Author (com_booklibrary) module 1.5 and possibly earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p93v-grp7-c85h/GHSA-p93v-grp7-c85h.json b/advisories/unreviewed/2022/05/GHSA-p93v-grp7-c85h/GHSA-p93v-grp7-c85h.json index 084c8995467..82111122220 100644 --- a/advisories/unreviewed/2022/05/GHSA-p93v-grp7-c85h/GHSA-p93v-grp7-c85h.json +++ b/advisories/unreviewed/2022/05/GHSA-p93v-grp7-c85h/GHSA-p93v-grp7-c85h.json @@ -7,12 +7,8 @@ "CVE-2015-3001" ], "details": "SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p9jv-fhh5-g9mh/GHSA-p9jv-fhh5-g9mh.json b/advisories/unreviewed/2022/05/GHSA-p9jv-fhh5-g9mh/GHSA-p9jv-fhh5-g9mh.json index f8d18e9403d..62f4f83dd15 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9jv-fhh5-g9mh/GHSA-p9jv-fhh5-g9mh.json +++ b/advisories/unreviewed/2022/05/GHSA-p9jv-fhh5-g9mh/GHSA-p9jv-fhh5-g9mh.json @@ -7,12 +7,8 @@ "CVE-2010-1993" ], "details": "Opera 9.52 does not properly handle an IFRAME element with a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (resource consumption) via an HTML document with many IFRAME elements.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p9wv-xg3r-33r2/GHSA-p9wv-xg3r-33r2.json b/advisories/unreviewed/2022/05/GHSA-p9wv-xg3r-33r2/GHSA-p9wv-xg3r-33r2.json index cd264cc745a..adab362b964 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9wv-xg3r-33r2/GHSA-p9wv-xg3r-33r2.json +++ b/advisories/unreviewed/2022/05/GHSA-p9wv-xg3r-33r2/GHSA-p9wv-xg3r-33r2.json @@ -7,12 +7,8 @@ "CVE-2010-2873" ], "details": "Adobe Shockwave Player before 11.5.8.612 does not properly validate offset values in the rcsL RIFF chunks of (1) .DIR and (2) .DCR Director movies, which allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted movie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pccq-v233-rx3q/GHSA-pccq-v233-rx3q.json b/advisories/unreviewed/2022/05/GHSA-pccq-v233-rx3q/GHSA-pccq-v233-rx3q.json index 4b4754eb6c8..0a0a9fcbc3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-pccq-v233-rx3q/GHSA-pccq-v233-rx3q.json +++ b/advisories/unreviewed/2022/05/GHSA-pccq-v233-rx3q/GHSA-pccq-v233-rx3q.json @@ -7,12 +7,8 @@ "CVE-2015-8562" ], "details": "Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pcpw-qmpx-2hr8/GHSA-pcpw-qmpx-2hr8.json b/advisories/unreviewed/2022/05/GHSA-pcpw-qmpx-2hr8/GHSA-pcpw-qmpx-2hr8.json index 38aa1593087..cb985573553 100644 --- a/advisories/unreviewed/2022/05/GHSA-pcpw-qmpx-2hr8/GHSA-pcpw-qmpx-2hr8.json +++ b/advisories/unreviewed/2022/05/GHSA-pcpw-qmpx-2hr8/GHSA-pcpw-qmpx-2hr8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pfm9-r9qx-fqwf/GHSA-pfm9-r9qx-fqwf.json b/advisories/unreviewed/2022/05/GHSA-pfm9-r9qx-fqwf/GHSA-pfm9-r9qx-fqwf.json index 37eb02c6792..c96db933ff9 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfm9-r9qx-fqwf/GHSA-pfm9-r9qx-fqwf.json +++ b/advisories/unreviewed/2022/05/GHSA-pfm9-r9qx-fqwf/GHSA-pfm9-r9qx-fqwf.json @@ -7,12 +7,8 @@ "CVE-2015-7320" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in cpabc_appointments_admin_int_bookings_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pfv7-c6xr-gq92/GHSA-pfv7-c6xr-gq92.json b/advisories/unreviewed/2022/05/GHSA-pfv7-c6xr-gq92/GHSA-pfv7-c6xr-gq92.json index f08ec7ba3df..f8c4850da6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfv7-c6xr-gq92/GHSA-pfv7-c6xr-gq92.json +++ b/advisories/unreviewed/2022/05/GHSA-pfv7-c6xr-gq92/GHSA-pfv7-c6xr-gq92.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-phvx-f7h4-rfc8/GHSA-phvx-f7h4-rfc8.json b/advisories/unreviewed/2022/05/GHSA-phvx-f7h4-rfc8/GHSA-phvx-f7h4-rfc8.json index 6479a2f939b..90466e6d4ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-phvx-f7h4-rfc8/GHSA-phvx-f7h4-rfc8.json +++ b/advisories/unreviewed/2022/05/GHSA-phvx-f7h4-rfc8/GHSA-phvx-f7h4-rfc8.json @@ -7,12 +7,8 @@ "CVE-2010-1749" ], "details": "Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the Cascading Style Sheets (CSS) run-in property and multiple invocations of a destructor for a child element that has been referenced multiple times.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pjj3-h7w2-44v7/GHSA-pjj3-h7w2-44v7.json b/advisories/unreviewed/2022/05/GHSA-pjj3-h7w2-44v7/GHSA-pjj3-h7w2-44v7.json index 1fc763375d4..41800909346 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjj3-h7w2-44v7/GHSA-pjj3-h7w2-44v7.json +++ b/advisories/unreviewed/2022/05/GHSA-pjj3-h7w2-44v7/GHSA-pjj3-h7w2-44v7.json @@ -7,12 +7,8 @@ "CVE-2015-4109" ], "details": "Multiple SQL injection vulnerabilities in the ratings module in the Users Ultra plugin before 1.5.16 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) data_target or (2) data_vote parameter in a rating_vote (wp_ajax_nopriv_rating_vote) action to wp-admin/admin-ajax.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pq7r-cj5m-jgr5/GHSA-pq7r-cj5m-jgr5.json b/advisories/unreviewed/2022/05/GHSA-pq7r-cj5m-jgr5/GHSA-pq7r-cj5m-jgr5.json index 7055f8b1dc2..9223902ecf7 100644 --- a/advisories/unreviewed/2022/05/GHSA-pq7r-cj5m-jgr5/GHSA-pq7r-cj5m-jgr5.json +++ b/advisories/unreviewed/2022/05/GHSA-pq7r-cj5m-jgr5/GHSA-pq7r-cj5m-jgr5.json @@ -7,12 +7,8 @@ "CVE-2015-7683" ], "details": "Absolute path traversal vulnerability in Font.php in the Font plugin before 7.5.1 for WordPress allows remote administrators to read arbitrary files via a full pathname in the url parameter to AjaxProxy.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pqvr-gchh-537x/GHSA-pqvr-gchh-537x.json b/advisories/unreviewed/2022/05/GHSA-pqvr-gchh-537x/GHSA-pqvr-gchh-537x.json index 9a3d4ae3d51..14d345395eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqvr-gchh-537x/GHSA-pqvr-gchh-537x.json +++ b/advisories/unreviewed/2022/05/GHSA-pqvr-gchh-537x/GHSA-pqvr-gchh-537x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pqx7-h7jx-cfmc/GHSA-pqx7-h7jx-cfmc.json b/advisories/unreviewed/2022/05/GHSA-pqx7-h7jx-cfmc/GHSA-pqx7-h7jx-cfmc.json index 6d6a87c6ba7..1ec5196ea29 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqx7-h7jx-cfmc/GHSA-pqx7-h7jx-cfmc.json +++ b/advisories/unreviewed/2022/05/GHSA-pqx7-h7jx-cfmc/GHSA-pqx7-h7jx-cfmc.json @@ -7,12 +7,8 @@ "CVE-2015-2314" ], "details": "SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pqxh-2px8-rqhh/GHSA-pqxh-2px8-rqhh.json b/advisories/unreviewed/2022/05/GHSA-pqxh-2px8-rqhh/GHSA-pqxh-2px8-rqhh.json index d15708ef9a1..70bb1c8bdb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqxh-2px8-rqhh/GHSA-pqxh-2px8-rqhh.json +++ b/advisories/unreviewed/2022/05/GHSA-pqxh-2px8-rqhh/GHSA-pqxh-2px8-rqhh.json @@ -7,12 +7,8 @@ "CVE-2010-2425" ], "details": "Directory traversal vulnerability in TitanFTPd in South River Technologies Titan FTP Server 8.10.1125, and probably earlier versions, allows remote authenticated users to read or delete arbitrary files via \"..//\" sequences in a COMB command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pr7j-fgfx-9p8x/GHSA-pr7j-fgfx-9p8x.json b/advisories/unreviewed/2022/05/GHSA-pr7j-fgfx-9p8x/GHSA-pr7j-fgfx-9p8x.json index 7cdea7cbd3b..aa3075efb2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr7j-fgfx-9p8x/GHSA-pr7j-fgfx-9p8x.json +++ b/advisories/unreviewed/2022/05/GHSA-pr7j-fgfx-9p8x/GHSA-pr7j-fgfx-9p8x.json @@ -7,12 +7,8 @@ "CVE-2015-6910" ], "details": "SQL injection vulnerability in Synology Video Station before 1.5-0757 allows remote attackers to execute arbitrary SQL commands via the id parameter to audiotrack.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-prg5-hcg4-g7jm/GHSA-prg5-hcg4-g7jm.json b/advisories/unreviewed/2022/05/GHSA-prg5-hcg4-g7jm/GHSA-prg5-hcg4-g7jm.json index 907e524e3ea..452a9ede249 100644 --- a/advisories/unreviewed/2022/05/GHSA-prg5-hcg4-g7jm/GHSA-prg5-hcg4-g7jm.json +++ b/advisories/unreviewed/2022/05/GHSA-prg5-hcg4-g7jm/GHSA-prg5-hcg4-g7jm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pv2m-9fcc-3fv8/GHSA-pv2m-9fcc-3fv8.json b/advisories/unreviewed/2022/05/GHSA-pv2m-9fcc-3fv8/GHSA-pv2m-9fcc-3fv8.json index 2cb9eb2b52f..3fe220d8646 100644 --- a/advisories/unreviewed/2022/05/GHSA-pv2m-9fcc-3fv8/GHSA-pv2m-9fcc-3fv8.json +++ b/advisories/unreviewed/2022/05/GHSA-pv2m-9fcc-3fv8/GHSA-pv2m-9fcc-3fv8.json @@ -7,12 +7,8 @@ "CVE-2010-2881" ], "details": "IML32.dll in Adobe Shockwave Player before 11.5.8.612 does not properly parse .dir files, which allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a malformed file containing an invalid value, as demonstrated by a value at position 0x24C0 of a certain file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pw74-pgq8-hrj7/GHSA-pw74-pgq8-hrj7.json b/advisories/unreviewed/2022/05/GHSA-pw74-pgq8-hrj7/GHSA-pw74-pgq8-hrj7.json index e228df54b96..5ddf9bd34a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw74-pgq8-hrj7/GHSA-pw74-pgq8-hrj7.json +++ b/advisories/unreviewed/2022/05/GHSA-pw74-pgq8-hrj7/GHSA-pw74-pgq8-hrj7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pwh6-hx6p-h68f/GHSA-pwh6-hx6p-h68f.json b/advisories/unreviewed/2022/05/GHSA-pwh6-hx6p-h68f/GHSA-pwh6-hx6p-h68f.json index 275973167f7..03787ce4af9 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwh6-hx6p-h68f/GHSA-pwh6-hx6p-h68f.json +++ b/advisories/unreviewed/2022/05/GHSA-pwh6-hx6p-h68f/GHSA-pwh6-hx6p-h68f.json @@ -7,12 +7,8 @@ "CVE-2010-2846" ], "details": "Cross-site scripting (XSS) vulnerability in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the afmsg parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pwp9-wc2j-35m6/GHSA-pwp9-wc2j-35m6.json b/advisories/unreviewed/2022/05/GHSA-pwp9-wc2j-35m6/GHSA-pwp9-wc2j-35m6.json index 3c9b890cbfd..acafa8dcaf6 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwp9-wc2j-35m6/GHSA-pwp9-wc2j-35m6.json +++ b/advisories/unreviewed/2022/05/GHSA-pwp9-wc2j-35m6/GHSA-pwp9-wc2j-35m6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-px54-5fmq-rf2f/GHSA-px54-5fmq-rf2f.json b/advisories/unreviewed/2022/05/GHSA-px54-5fmq-rf2f/GHSA-px54-5fmq-rf2f.json index 457b6fff478..0871b972202 100644 --- a/advisories/unreviewed/2022/05/GHSA-px54-5fmq-rf2f/GHSA-px54-5fmq-rf2f.json +++ b/advisories/unreviewed/2022/05/GHSA-px54-5fmq-rf2f/GHSA-px54-5fmq-rf2f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q2mj-96fr-cgg8/GHSA-q2mj-96fr-cgg8.json b/advisories/unreviewed/2022/05/GHSA-q2mj-96fr-cgg8/GHSA-q2mj-96fr-cgg8.json index eb00a5c1de8..0b3b98496bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2mj-96fr-cgg8/GHSA-q2mj-96fr-cgg8.json +++ b/advisories/unreviewed/2022/05/GHSA-q2mj-96fr-cgg8/GHSA-q2mj-96fr-cgg8.json @@ -7,12 +7,8 @@ "CVE-2015-2677" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ocPortal before 9.0.17 allow remote authenticated users to inject arbitrary web script or HTML via the (1) title or (2) text field in the cms_calendar page to cms/index.php; unspecified fields in (3) the cms_polls page to cms/index.php or (4) a new topic in the topics page to forum/index.php; or (5) a new PT (private topic/private message) in the topics page to forum/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q2xc-gqrr-xffx/GHSA-q2xc-gqrr-xffx.json b/advisories/unreviewed/2022/05/GHSA-q2xc-gqrr-xffx/GHSA-q2xc-gqrr-xffx.json index 744005534ca..d59a41b6cf5 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2xc-gqrr-xffx/GHSA-q2xc-gqrr-xffx.json +++ b/advisories/unreviewed/2022/05/GHSA-q2xc-gqrr-xffx/GHSA-q2xc-gqrr-xffx.json @@ -7,12 +7,8 @@ "CVE-2015-2289" ], "details": "Cross-site scripting (XSS) vulnerability in templates/2k11/admin/entries.tpl in Serendipity before 2.0.1 allows remote authenticated editors to inject arbitrary web script or HTML via the serendipity[cat][name] parameter to serendipity_admin.php, when creating a new category.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q3xp-wrf7-p8pf/GHSA-q3xp-wrf7-p8pf.json b/advisories/unreviewed/2022/05/GHSA-q3xp-wrf7-p8pf/GHSA-q3xp-wrf7-p8pf.json index 8b155275b58..5a01c03d40c 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3xp-wrf7-p8pf/GHSA-q3xp-wrf7-p8pf.json +++ b/advisories/unreviewed/2022/05/GHSA-q3xp-wrf7-p8pf/GHSA-q3xp-wrf7-p8pf.json @@ -7,12 +7,8 @@ "CVE-2015-4118" ], "details": "SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permissions to execute arbitrary SQL commands via the server parameter. NOTE: this can be leveraged by remote attackers using CVE-2015-4119.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q43h-4xr8-j6fq/GHSA-q43h-4xr8-j6fq.json b/advisories/unreviewed/2022/05/GHSA-q43h-4xr8-j6fq/GHSA-q43h-4xr8-j6fq.json index 5bc59ae04f5..05a8ef5f42d 100644 --- a/advisories/unreviewed/2022/05/GHSA-q43h-4xr8-j6fq/GHSA-q43h-4xr8-j6fq.json +++ b/advisories/unreviewed/2022/05/GHSA-q43h-4xr8-j6fq/GHSA-q43h-4xr8-j6fq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q464-c6w6-9rm7/GHSA-q464-c6w6-9rm7.json b/advisories/unreviewed/2022/05/GHSA-q464-c6w6-9rm7/GHSA-q464-c6w6-9rm7.json index 0c76a5231a7..43297b7b9b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-q464-c6w6-9rm7/GHSA-q464-c6w6-9rm7.json +++ b/advisories/unreviewed/2022/05/GHSA-q464-c6w6-9rm7/GHSA-q464-c6w6-9rm7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q4q5-jq84-74pm/GHSA-q4q5-jq84-74pm.json b/advisories/unreviewed/2022/05/GHSA-q4q5-jq84-74pm/GHSA-q4q5-jq84-74pm.json index ef87f3adda5..42aa5ec49d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4q5-jq84-74pm/GHSA-q4q5-jq84-74pm.json +++ b/advisories/unreviewed/2022/05/GHSA-q4q5-jq84-74pm/GHSA-q4q5-jq84-74pm.json @@ -7,12 +7,8 @@ "CVE-2010-3464" ], "details": "Cross-site request forgery (CSRF) vulnerability in admin/manager_users.class.php in SantaFox 2.02, and possibly earlier, allows remote attackers to hijack the authentication of administrators for requests, as demonstrated by adding administrative users via the save_admin action to admin/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q52g-hj2m-whj8/GHSA-q52g-hj2m-whj8.json b/advisories/unreviewed/2022/05/GHSA-q52g-hj2m-whj8/GHSA-q52g-hj2m-whj8.json index 6eb64c09f79..347453b095e 100644 --- a/advisories/unreviewed/2022/05/GHSA-q52g-hj2m-whj8/GHSA-q52g-hj2m-whj8.json +++ b/advisories/unreviewed/2022/05/GHSA-q52g-hj2m-whj8/GHSA-q52g-hj2m-whj8.json @@ -7,12 +7,8 @@ "CVE-2010-2868" ], "details": "IML32.dll in Adobe Shockwave Player before 11.5.8.612 does not properly parse .dir files, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a malformed file containing an invalid value, as demonstrated by a value at position 0x320D of a certain file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q5j8-mj88-p78h/GHSA-q5j8-mj88-p78h.json b/advisories/unreviewed/2022/05/GHSA-q5j8-mj88-p78h/GHSA-q5j8-mj88-p78h.json index 0b46586b3ae..a0a5f27101f 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5j8-mj88-p78h/GHSA-q5j8-mj88-p78h.json +++ b/advisories/unreviewed/2022/05/GHSA-q5j8-mj88-p78h/GHSA-q5j8-mj88-p78h.json @@ -7,12 +7,8 @@ "CVE-2015-6913" ], "details": "Cross-site scripting (XSS) vulnerability in the \"Create download task via URL\" feature in Synology Download Station before 3.5-2967 allows remote attackers to inject arbitrary web script or HTML via the urls parameter in an add_url_task action to dlm/downloadman.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q66x-vm73-35xj/GHSA-q66x-vm73-35xj.json b/advisories/unreviewed/2022/05/GHSA-q66x-vm73-35xj/GHSA-q66x-vm73-35xj.json index 79bfe479e16..21fe93b0846 100644 --- a/advisories/unreviewed/2022/05/GHSA-q66x-vm73-35xj/GHSA-q66x-vm73-35xj.json +++ b/advisories/unreviewed/2022/05/GHSA-q66x-vm73-35xj/GHSA-q66x-vm73-35xj.json @@ -7,12 +7,8 @@ "CVE-2010-1989" ], "details": "Opera 9.52 executes a mail application in situations where an IMG element has a SRC attribute that is a redirect to a mailto: URL, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many images, a related issue to CVE-2010-0181.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q6c6-rp2h-6254/GHSA-q6c6-rp2h-6254.json b/advisories/unreviewed/2022/05/GHSA-q6c6-rp2h-6254/GHSA-q6c6-rp2h-6254.json index d52967f792f..8a8e5d223b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6c6-rp2h-6254/GHSA-q6c6-rp2h-6254.json +++ b/advisories/unreviewed/2022/05/GHSA-q6c6-rp2h-6254/GHSA-q6c6-rp2h-6254.json @@ -7,12 +7,8 @@ "CVE-2010-3584" ], "details": "Unspecified vulnerability in the Oracle VM component in Oracle VM 2.2.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to ovs-agent. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a third party researcher that this is related to the storage of passwords and password hashes in cleartext in files with insecure permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q6q8-c8x8-qcx7/GHSA-q6q8-c8x8-qcx7.json b/advisories/unreviewed/2022/05/GHSA-q6q8-c8x8-qcx7/GHSA-q6q8-c8x8-qcx7.json index 338bee9bbac..f4983912c9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6q8-c8x8-qcx7/GHSA-q6q8-c8x8-qcx7.json +++ b/advisories/unreviewed/2022/05/GHSA-q6q8-c8x8-qcx7/GHSA-q6q8-c8x8-qcx7.json @@ -7,12 +7,8 @@ "CVE-2010-3595" ], "details": "Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect confidentiality via unknown vectors related to Import Server. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from the original researcher that remote attackers can read arbitrary files via a full pathname in the first argument to the ImportBodyText method in the EasyMail ActiveX control (emsmtp.dll).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q6q9-w26g-c8vj/GHSA-q6q9-w26g-c8vj.json b/advisories/unreviewed/2022/05/GHSA-q6q9-w26g-c8vj/GHSA-q6q9-w26g-c8vj.json index e6571f5addc..21eeca01165 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6q9-w26g-c8vj/GHSA-q6q9-w26g-c8vj.json +++ b/advisories/unreviewed/2022/05/GHSA-q6q9-w26g-c8vj/GHSA-q6q9-w26g-c8vj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q6xw-8r38-j7rr/GHSA-q6xw-8r38-j7rr.json b/advisories/unreviewed/2022/05/GHSA-q6xw-8r38-j7rr/GHSA-q6xw-8r38-j7rr.json index 56b9217a34f..ba6f8bd97b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6xw-8r38-j7rr/GHSA-q6xw-8r38-j7rr.json +++ b/advisories/unreviewed/2022/05/GHSA-q6xw-8r38-j7rr/GHSA-q6xw-8r38-j7rr.json @@ -7,12 +7,8 @@ "CVE-2010-2586" ], "details": "Multiple integer overflows in in_nsv.dll in the in_nsv plugin in Winamp before 5.6 allow remote attackers to execute arbitrary code via a crafted Table of Contents (TOC) in a (1) NSV stream or (2) NSV file that triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q7qv-8phg-j77g/GHSA-q7qv-8phg-j77g.json b/advisories/unreviewed/2022/05/GHSA-q7qv-8phg-j77g/GHSA-q7qv-8phg-j77g.json index 48fdf054442..541395c7a12 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7qv-8phg-j77g/GHSA-q7qv-8phg-j77g.json +++ b/advisories/unreviewed/2022/05/GHSA-q7qv-8phg-j77g/GHSA-q7qv-8phg-j77g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7w5-jvgc-gcf2/GHSA-q7w5-jvgc-gcf2.json b/advisories/unreviewed/2022/05/GHSA-q7w5-jvgc-gcf2/GHSA-q7w5-jvgc-gcf2.json index 0b4dfe7da89..11a189da197 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7w5-jvgc-gcf2/GHSA-q7w5-jvgc-gcf2.json +++ b/advisories/unreviewed/2022/05/GHSA-q7w5-jvgc-gcf2/GHSA-q7w5-jvgc-gcf2.json @@ -7,12 +7,8 @@ "CVE-2010-1576" ], "details": "The Cisco Content Services Switch (CSS) 11500 with software before 8.20.4.02 and the Application Control Engine (ACE) 4710 with software before A2(3.0) do not properly handle use of LF, CR, and LFCR as alternatives to the standard CRLF sequence between HTTP headers, which allows remote attackers to bypass intended header insertions or conduct HTTP request smuggling attacks via crafted header data, as demonstrated by LF characters preceding ClientCert-Subject and ClientCert-Subject-CN headers, aka Bug ID CSCta04885.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q8mm-64pp-462q/GHSA-q8mm-64pp-462q.json b/advisories/unreviewed/2022/05/GHSA-q8mm-64pp-462q/GHSA-q8mm-64pp-462q.json index eb84adec488..6ea84753fdb 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8mm-64pp-462q/GHSA-q8mm-64pp-462q.json +++ b/advisories/unreviewed/2022/05/GHSA-q8mm-64pp-462q/GHSA-q8mm-64pp-462q.json @@ -7,12 +7,8 @@ "CVE-2010-2070" ], "details": "arch/ia64/xen/faults.c in Xen 3.4 and 4.0 in Linux kernel 2.6.18, and possibly other kernel versions, when running on IA-64 architectures, allows local users to cause a denial of service and \"turn on BE by modifying the user mask of the PSR,\" as demonstrated via exploitation of CVE-2006-0742.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q948-rx7v-7pjc/GHSA-q948-rx7v-7pjc.json b/advisories/unreviewed/2022/05/GHSA-q948-rx7v-7pjc/GHSA-q948-rx7v-7pjc.json index 8ec5278a2c8..ee0645134ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-q948-rx7v-7pjc/GHSA-q948-rx7v-7pjc.json +++ b/advisories/unreviewed/2022/05/GHSA-q948-rx7v-7pjc/GHSA-q948-rx7v-7pjc.json @@ -7,12 +7,8 @@ "CVE-2010-1992" ], "details": "Google Chrome 1.0.154.48 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q9hf-xxg3-957g/GHSA-q9hf-xxg3-957g.json b/advisories/unreviewed/2022/05/GHSA-q9hf-xxg3-957g/GHSA-q9hf-xxg3-957g.json index 10edccb85c0..50f37d6b661 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9hf-xxg3-957g/GHSA-q9hf-xxg3-957g.json +++ b/advisories/unreviewed/2022/05/GHSA-q9hf-xxg3-957g/GHSA-q9hf-xxg3-957g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qc44-rrqj-mm4p/GHSA-qc44-rrqj-mm4p.json b/advisories/unreviewed/2022/05/GHSA-qc44-rrqj-mm4p/GHSA-qc44-rrqj-mm4p.json index 93002a925ac..deb1ef63019 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc44-rrqj-mm4p/GHSA-qc44-rrqj-mm4p.json +++ b/advisories/unreviewed/2022/05/GHSA-qc44-rrqj-mm4p/GHSA-qc44-rrqj-mm4p.json @@ -7,12 +7,8 @@ "CVE-2010-2996" ], "details": "Array index error in RealNetworks RealPlayer 11.0 through 11.1 on Windows allows remote attackers to execute arbitrary code via a malformed header in a RealMedia .IVR file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qf6j-fwrq-x6wp/GHSA-qf6j-fwrq-x6wp.json b/advisories/unreviewed/2022/05/GHSA-qf6j-fwrq-x6wp/GHSA-qf6j-fwrq-x6wp.json index e384c2eabb2..35cbecd5c8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-qf6j-fwrq-x6wp/GHSA-qf6j-fwrq-x6wp.json +++ b/advisories/unreviewed/2022/05/GHSA-qf6j-fwrq-x6wp/GHSA-qf6j-fwrq-x6wp.json @@ -7,12 +7,8 @@ "CVE-2010-2686" ], "details": "Multiple SQL injection vulnerabilities in clientes.asp in the TopManage OLK module 1.91.30 for SAP allow remote attackers to execute arbitrary SQL commands via the (1) PriceFrom, (2) PriceTo, and (3) InvFrom parameters, as reachable from olk/c_p/searchCart.asp, and other unspecified vectors when performing an advanced search. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qf6p-46w9-4mmp/GHSA-qf6p-46w9-4mmp.json b/advisories/unreviewed/2022/05/GHSA-qf6p-46w9-4mmp/GHSA-qf6p-46w9-4mmp.json index 1c1c448dcc6..aa1f9729c38 100644 --- a/advisories/unreviewed/2022/05/GHSA-qf6p-46w9-4mmp/GHSA-qf6p-46w9-4mmp.json +++ b/advisories/unreviewed/2022/05/GHSA-qf6p-46w9-4mmp/GHSA-qf6p-46w9-4mmp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qf7x-5whr-gj84/GHSA-qf7x-5whr-gj84.json b/advisories/unreviewed/2022/05/GHSA-qf7x-5whr-gj84/GHSA-qf7x-5whr-gj84.json index 3d1c3dec148..a4f210d0e4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qf7x-5whr-gj84/GHSA-qf7x-5whr-gj84.json +++ b/advisories/unreviewed/2022/05/GHSA-qf7x-5whr-gj84/GHSA-qf7x-5whr-gj84.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qfw8-j8v2-95qr/GHSA-qfw8-j8v2-95qr.json b/advisories/unreviewed/2022/05/GHSA-qfw8-j8v2-95qr/GHSA-qfw8-j8v2-95qr.json index 79a2711919d..4c379a669d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfw8-j8v2-95qr/GHSA-qfw8-j8v2-95qr.json +++ b/advisories/unreviewed/2022/05/GHSA-qfw8-j8v2-95qr/GHSA-qfw8-j8v2-95qr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qg2q-g744-m7q9/GHSA-qg2q-g744-m7q9.json b/advisories/unreviewed/2022/05/GHSA-qg2q-g744-m7q9/GHSA-qg2q-g744-m7q9.json index 1ac6c8f6cd6..a4a73a94819 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg2q-g744-m7q9/GHSA-qg2q-g744-m7q9.json +++ b/advisories/unreviewed/2022/05/GHSA-qg2q-g744-m7q9/GHSA-qg2q-g744-m7q9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qgqh-ff3h-gmfq/GHSA-qgqh-ff3h-gmfq.json b/advisories/unreviewed/2022/05/GHSA-qgqh-ff3h-gmfq/GHSA-qgqh-ff3h-gmfq.json index 0202683f6bb..6e7058229b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgqh-ff3h-gmfq/GHSA-qgqh-ff3h-gmfq.json +++ b/advisories/unreviewed/2022/05/GHSA-qgqh-ff3h-gmfq/GHSA-qgqh-ff3h-gmfq.json @@ -7,12 +7,8 @@ "CVE-2010-2426" ], "details": "Directory traversal vulnerability in TitanFTPd in South River Technologies Titan FTP Server 8.10.1125, and probably earlier versions, allows remote authenticated users to read arbitrary files, determine file size, via \"..//\" sequences in the xcrc command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qh28-4wq7-xmcj/GHSA-qh28-4wq7-xmcj.json b/advisories/unreviewed/2022/05/GHSA-qh28-4wq7-xmcj/GHSA-qh28-4wq7-xmcj.json index c10a05790d6..55335555e03 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh28-4wq7-xmcj/GHSA-qh28-4wq7-xmcj.json +++ b/advisories/unreviewed/2022/05/GHSA-qh28-4wq7-xmcj/GHSA-qh28-4wq7-xmcj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qh63-cgwm-3qjp/GHSA-qh63-cgwm-3qjp.json b/advisories/unreviewed/2022/05/GHSA-qh63-cgwm-3qjp/GHSA-qh63-cgwm-3qjp.json index b73b13d5e20..bd2b5f9d103 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh63-cgwm-3qjp/GHSA-qh63-cgwm-3qjp.json +++ b/advisories/unreviewed/2022/05/GHSA-qh63-cgwm-3qjp/GHSA-qh63-cgwm-3qjp.json @@ -7,12 +7,8 @@ "CVE-2010-3274" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in the Employee Search Engine in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allow remote attackers to inject arbitrary web script or HTML via the searchString parameter in a (1) showList or (2) Search action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qhfv-pjhr-x49x/GHSA-qhfv-pjhr-x49x.json b/advisories/unreviewed/2022/05/GHSA-qhfv-pjhr-x49x/GHSA-qhfv-pjhr-x49x.json index 250f13d617b..c3d25fcd05f 100644 --- a/advisories/unreviewed/2022/05/GHSA-qhfv-pjhr-x49x/GHSA-qhfv-pjhr-x49x.json +++ b/advisories/unreviewed/2022/05/GHSA-qhfv-pjhr-x49x/GHSA-qhfv-pjhr-x49x.json @@ -7,12 +7,8 @@ "CVE-2010-1553" ], "details": "Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid MaxAge parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qjfj-8r88-5cc8/GHSA-qjfj-8r88-5cc8.json b/advisories/unreviewed/2022/05/GHSA-qjfj-8r88-5cc8/GHSA-qjfj-8r88-5cc8.json index 998350728a2..4abcf8329fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjfj-8r88-5cc8/GHSA-qjfj-8r88-5cc8.json +++ b/advisories/unreviewed/2022/05/GHSA-qjfj-8r88-5cc8/GHSA-qjfj-8r88-5cc8.json @@ -7,12 +7,8 @@ "CVE-2010-2041" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP-Calendar before 2.0 Beta7 allow remote attackers to inject arbitrary web script or HTML via the (1) description and (2) lastaction parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qjjg-j867-2gqq/GHSA-qjjg-j867-2gqq.json b/advisories/unreviewed/2022/05/GHSA-qjjg-j867-2gqq/GHSA-qjjg-j867-2gqq.json index c36319f6124..3e5249b6d2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjjg-j867-2gqq/GHSA-qjjg-j867-2gqq.json +++ b/advisories/unreviewed/2022/05/GHSA-qjjg-j867-2gqq/GHSA-qjjg-j867-2gqq.json @@ -7,12 +7,8 @@ "CVE-2010-1930" ], "details": "Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (daemon crash) via a long tree parameter in a login request to nps/servlet/webacc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qjr8-p3mq-88g5/GHSA-qjr8-p3mq-88g5.json b/advisories/unreviewed/2022/05/GHSA-qjr8-p3mq-88g5/GHSA-qjr8-p3mq-88g5.json index d599268149f..6706b7619e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjr8-p3mq-88g5/GHSA-qjr8-p3mq-88g5.json +++ b/advisories/unreviewed/2022/05/GHSA-qjr8-p3mq-88g5/GHSA-qjr8-p3mq-88g5.json @@ -7,12 +7,8 @@ "CVE-2010-2870" ], "details": "DIRAPIX.dll in Adobe Shockwave Player before 11.5.8.612 does not properly validate a certain chunk size in the mmap chunk in a Director movie, which allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted movie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qmg9-6p3v-cmj4/GHSA-qmg9-6p3v-cmj4.json b/advisories/unreviewed/2022/05/GHSA-qmg9-6p3v-cmj4/GHSA-qmg9-6p3v-cmj4.json index 4dfb82e35f4..f8c00af06e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmg9-6p3v-cmj4/GHSA-qmg9-6p3v-cmj4.json +++ b/advisories/unreviewed/2022/05/GHSA-qmg9-6p3v-cmj4/GHSA-qmg9-6p3v-cmj4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qmh3-wcgj-6fqq/GHSA-qmh3-wcgj-6fqq.json b/advisories/unreviewed/2022/05/GHSA-qmh3-wcgj-6fqq/GHSA-qmh3-wcgj-6fqq.json index 2d7f2d0c446..00693145262 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmh3-wcgj-6fqq/GHSA-qmh3-wcgj-6fqq.json +++ b/advisories/unreviewed/2022/05/GHSA-qmh3-wcgj-6fqq/GHSA-qmh3-wcgj-6fqq.json @@ -7,12 +7,8 @@ "CVE-2015-2804" ], "details": "The management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, and 6855 with firmware before 6.6.4.309.R01 and 6.6.5.x before 6.6.5.80.R02 generates weak session identifiers, which allows remote attackers to hijack arbitrary sessions via a brute force attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qp35-w8hh-2rj9/GHSA-qp35-w8hh-2rj9.json b/advisories/unreviewed/2022/05/GHSA-qp35-w8hh-2rj9/GHSA-qp35-w8hh-2rj9.json index 95651cd65a5..04232918ae2 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp35-w8hh-2rj9/GHSA-qp35-w8hh-2rj9.json +++ b/advisories/unreviewed/2022/05/GHSA-qp35-w8hh-2rj9/GHSA-qp35-w8hh-2rj9.json @@ -7,12 +7,8 @@ "CVE-2010-2120" ], "details": "Google Chrome 1.0.154.48 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid news:// URIs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qqpw-v685-55rr/GHSA-qqpw-v685-55rr.json b/advisories/unreviewed/2022/05/GHSA-qqpw-v685-55rr/GHSA-qqpw-v685-55rr.json index 5cc2b69b559..fe12d60e766 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqpw-v685-55rr/GHSA-qqpw-v685-55rr.json +++ b/advisories/unreviewed/2022/05/GHSA-qqpw-v685-55rr/GHSA-qqpw-v685-55rr.json @@ -7,12 +7,8 @@ "CVE-2010-4674" ], "details": "Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2(4) and earlier allows remote attackers to cause a denial of service (block exhaustion) via multicast traffic, aka Bug ID CSCtg63992.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qrcj-mq48-333m/GHSA-qrcj-mq48-333m.json b/advisories/unreviewed/2022/05/GHSA-qrcj-mq48-333m/GHSA-qrcj-mq48-333m.json index 9a493088aa2..c455de4da04 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrcj-mq48-333m/GHSA-qrcj-mq48-333m.json +++ b/advisories/unreviewed/2022/05/GHSA-qrcj-mq48-333m/GHSA-qrcj-mq48-333m.json @@ -7,12 +7,8 @@ "CVE-2010-2023" ], "details": "transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another user's file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrj4-68mq-fwp3/GHSA-qrj4-68mq-fwp3.json b/advisories/unreviewed/2022/05/GHSA-qrj4-68mq-fwp3/GHSA-qrj4-68mq-fwp3.json index 4e970b87b7f..cd162e6dde8 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrj4-68mq-fwp3/GHSA-qrj4-68mq-fwp3.json +++ b/advisories/unreviewed/2022/05/GHSA-qrj4-68mq-fwp3/GHSA-qrj4-68mq-fwp3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qw7r-4xg5-247x/GHSA-qw7r-4xg5-247x.json b/advisories/unreviewed/2022/05/GHSA-qw7r-4xg5-247x/GHSA-qw7r-4xg5-247x.json index 06efe7f770a..b39767707db 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw7r-4xg5-247x/GHSA-qw7r-4xg5-247x.json +++ b/advisories/unreviewed/2022/05/GHSA-qw7r-4xg5-247x/GHSA-qw7r-4xg5-247x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwj7-5rx8-4p92/GHSA-qwj7-5rx8-4p92.json b/advisories/unreviewed/2022/05/GHSA-qwj7-5rx8-4p92/GHSA-qwj7-5rx8-4p92.json index f1a16e3c7cb..e3cd7eab777 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwj7-5rx8-4p92/GHSA-qwj7-5rx8-4p92.json +++ b/advisories/unreviewed/2022/05/GHSA-qwj7-5rx8-4p92/GHSA-qwj7-5rx8-4p92.json @@ -7,12 +7,8 @@ "CVE-2015-6530" ], "details": "Cross-site scripting (XSS) vulnerability in OpenText Secure MFT 2013 before 2013 R3 P6 and 2014 before 2014 R2 P2 allows remote attackers to inject arbitrary web script or HTML via the querytext parameter to userdashboard.jsp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qxf4-6479-8vm5/GHSA-qxf4-6479-8vm5.json b/advisories/unreviewed/2022/05/GHSA-qxf4-6479-8vm5/GHSA-qxf4-6479-8vm5.json index 6d3d7e0549b..a0597d89d0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxf4-6479-8vm5/GHSA-qxf4-6479-8vm5.json +++ b/advisories/unreviewed/2022/05/GHSA-qxf4-6479-8vm5/GHSA-qxf4-6479-8vm5.json @@ -7,12 +7,8 @@ "CVE-2010-2435" ], "details": "Weborf HTTP Server 0.12.1 and earlier allows remote attackers to cause a denial of service (crash) via Unicode characters in a Connection HTTP header, and possibly other headers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r2gg-8r9m-h694/GHSA-r2gg-8r9m-h694.json b/advisories/unreviewed/2022/05/GHSA-r2gg-8r9m-h694/GHSA-r2gg-8r9m-h694.json index d776c09969c..0cfb9d79716 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2gg-8r9m-h694/GHSA-r2gg-8r9m-h694.json +++ b/advisories/unreviewed/2022/05/GHSA-r2gg-8r9m-h694/GHSA-r2gg-8r9m-h694.json @@ -7,12 +7,8 @@ "CVE-2015-6945" ], "details": "Cross-site scripting (XSS) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to inject arbitrary web script or HTML via the bd parameter to sys/sys/listaBD2.jsp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r2rq-46jr-gmf4/GHSA-r2rq-46jr-gmf4.json b/advisories/unreviewed/2022/05/GHSA-r2rq-46jr-gmf4/GHSA-r2rq-46jr-gmf4.json index 5f1345c83a0..062c9f2e897 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2rq-46jr-gmf4/GHSA-r2rq-46jr-gmf4.json +++ b/advisories/unreviewed/2022/05/GHSA-r2rq-46jr-gmf4/GHSA-r2rq-46jr-gmf4.json @@ -7,12 +7,8 @@ "CVE-2010-2121" ], "details": "Opera 9.52 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid (1) news:// or (2) nntp:// URIs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r37f-74v3-cc63/GHSA-r37f-74v3-cc63.json b/advisories/unreviewed/2022/05/GHSA-r37f-74v3-cc63/GHSA-r37f-74v3-cc63.json index 47cc61c959f..8ca9ffc1074 100644 --- a/advisories/unreviewed/2022/05/GHSA-r37f-74v3-cc63/GHSA-r37f-74v3-cc63.json +++ b/advisories/unreviewed/2022/05/GHSA-r37f-74v3-cc63/GHSA-r37f-74v3-cc63.json @@ -7,12 +7,8 @@ "CVE-2010-1910" ], "details": "The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to reset passwords of accounts with blank Hint questions and Hint answers by sending an empty value for each of these two Hint fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r3c6-fm33-9gfg/GHSA-r3c6-fm33-9gfg.json b/advisories/unreviewed/2022/05/GHSA-r3c6-fm33-9gfg/GHSA-r3c6-fm33-9gfg.json index b84d1832d91..05c729dbf11 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3c6-fm33-9gfg/GHSA-r3c6-fm33-9gfg.json +++ b/advisories/unreviewed/2022/05/GHSA-r3c6-fm33-9gfg/GHSA-r3c6-fm33-9gfg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r477-2fhj-xjjw/GHSA-r477-2fhj-xjjw.json b/advisories/unreviewed/2022/05/GHSA-r477-2fhj-xjjw/GHSA-r477-2fhj-xjjw.json index 8021753a760..f89c8b9b15f 100644 --- a/advisories/unreviewed/2022/05/GHSA-r477-2fhj-xjjw/GHSA-r477-2fhj-xjjw.json +++ b/advisories/unreviewed/2022/05/GHSA-r477-2fhj-xjjw/GHSA-r477-2fhj-xjjw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r4g6-w8x4-v5v5/GHSA-r4g6-w8x4-v5v5.json b/advisories/unreviewed/2022/05/GHSA-r4g6-w8x4-v5v5/GHSA-r4g6-w8x4-v5v5.json index a0acb8aada2..175a28a9e68 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4g6-w8x4-v5v5/GHSA-r4g6-w8x4-v5v5.json +++ b/advisories/unreviewed/2022/05/GHSA-r4g6-w8x4-v5v5/GHSA-r4g6-w8x4-v5v5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r4j5-63wj-7p3r/GHSA-r4j5-63wj-7p3r.json b/advisories/unreviewed/2022/05/GHSA-r4j5-63wj-7p3r/GHSA-r4j5-63wj-7p3r.json index 4480068750c..44d60ded7d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4j5-63wj-7p3r/GHSA-r4j5-63wj-7p3r.json +++ b/advisories/unreviewed/2022/05/GHSA-r4j5-63wj-7p3r/GHSA-r4j5-63wj-7p3r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r549-wwpp-pwm2/GHSA-r549-wwpp-pwm2.json b/advisories/unreviewed/2022/05/GHSA-r549-wwpp-pwm2/GHSA-r549-wwpp-pwm2.json index 95dfd865093..f1595ec1fa0 100644 --- a/advisories/unreviewed/2022/05/GHSA-r549-wwpp-pwm2/GHSA-r549-wwpp-pwm2.json +++ b/advisories/unreviewed/2022/05/GHSA-r549-wwpp-pwm2/GHSA-r549-wwpp-pwm2.json @@ -7,12 +7,8 @@ "CVE-2015-7368" ], "details": "Revive Adserver before 3.2.2 does not send the appropriate Cache-Control HTTP headers in responses for admin UI pages, which allows local users to obtain sensitive information via the web browser cache.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r59j-864f-vpv5/GHSA-r59j-864f-vpv5.json b/advisories/unreviewed/2022/05/GHSA-r59j-864f-vpv5/GHSA-r59j-864f-vpv5.json index 96e11526a2a..e1c64a73b0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-r59j-864f-vpv5/GHSA-r59j-864f-vpv5.json +++ b/advisories/unreviewed/2022/05/GHSA-r59j-864f-vpv5/GHSA-r59j-864f-vpv5.json @@ -7,12 +7,8 @@ "CVE-2010-1519" ], "details": "Multiple integer overflows in glpng.c in glpng 1.45 allow context-dependent attackers to execute arbitrary code via a crafted PNG image, related to (1) the pngLoadRawF function and (2) the pngLoadF function, leading to heap-based buffer overflows.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r5j2-wcxv-vfx3/GHSA-r5j2-wcxv-vfx3.json b/advisories/unreviewed/2022/05/GHSA-r5j2-wcxv-vfx3/GHSA-r5j2-wcxv-vfx3.json index c268abb5726..12caba209d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5j2-wcxv-vfx3/GHSA-r5j2-wcxv-vfx3.json +++ b/advisories/unreviewed/2022/05/GHSA-r5j2-wcxv-vfx3/GHSA-r5j2-wcxv-vfx3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r5j6-vjxh-3v3w/GHSA-r5j6-vjxh-3v3w.json b/advisories/unreviewed/2022/05/GHSA-r5j6-vjxh-3v3w/GHSA-r5j6-vjxh-3v3w.json index d20c6008d29..37f4e463f89 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5j6-vjxh-3v3w/GHSA-r5j6-vjxh-3v3w.json +++ b/advisories/unreviewed/2022/05/GHSA-r5j6-vjxh-3v3w/GHSA-r5j6-vjxh-3v3w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r66r-3mhf-j6vm/GHSA-r66r-3mhf-j6vm.json b/advisories/unreviewed/2022/05/GHSA-r66r-3mhf-j6vm/GHSA-r66r-3mhf-j6vm.json index edfebd8ce7f..66afeecbbd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-r66r-3mhf-j6vm/GHSA-r66r-3mhf-j6vm.json +++ b/advisories/unreviewed/2022/05/GHSA-r66r-3mhf-j6vm/GHSA-r66r-3mhf-j6vm.json @@ -7,12 +7,8 @@ "CVE-2010-2130" ], "details": "Cross-site scripting (XSS) vulnerability in wflogin.jsp in Aris Global ARISg 5.0 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r6jr-r827-mr54/GHSA-r6jr-r827-mr54.json b/advisories/unreviewed/2022/05/GHSA-r6jr-r827-mr54/GHSA-r6jr-r827-mr54.json index 4f1eef6e039..92f0560b0ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6jr-r827-mr54/GHSA-r6jr-r827-mr54.json +++ b/advisories/unreviewed/2022/05/GHSA-r6jr-r827-mr54/GHSA-r6jr-r827-mr54.json @@ -7,12 +7,8 @@ "CVE-2010-3614" ], "details": "named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY algorithm rollover, which might allow remote attackers to cause a denial of service (DNSSEC validation error) by triggering a rollover.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r6jw-4qph-m95f/GHSA-r6jw-4qph-m95f.json b/advisories/unreviewed/2022/05/GHSA-r6jw-4qph-m95f/GHSA-r6jw-4qph-m95f.json index e46e5c3adb6..cee98eb974b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6jw-4qph-m95f/GHSA-r6jw-4qph-m95f.json +++ b/advisories/unreviewed/2022/05/GHSA-r6jw-4qph-m95f/GHSA-r6jw-4qph-m95f.json @@ -7,12 +7,8 @@ "CVE-2015-3648" ], "details": "Directory traversal vulnerability in pages/setup.php in Montala Limited ResourceSpace before 7.2.6727 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the defaultlanguage parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r8xv-6785-4jvr/GHSA-r8xv-6785-4jvr.json b/advisories/unreviewed/2022/05/GHSA-r8xv-6785-4jvr/GHSA-r8xv-6785-4jvr.json index e51ddfd9619..675c4c4fe26 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8xv-6785-4jvr/GHSA-r8xv-6785-4jvr.json +++ b/advisories/unreviewed/2022/05/GHSA-r8xv-6785-4jvr/GHSA-r8xv-6785-4jvr.json @@ -7,12 +7,8 @@ "CVE-2012-0711" ], "details": "Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through FP5 on UNIX platforms allows remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r929-5x66-fmvp/GHSA-r929-5x66-fmvp.json b/advisories/unreviewed/2022/05/GHSA-r929-5x66-fmvp/GHSA-r929-5x66-fmvp.json index 3cf1632c7ef..74d1caf431b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r929-5x66-fmvp/GHSA-r929-5x66-fmvp.json +++ b/advisories/unreviewed/2022/05/GHSA-r929-5x66-fmvp/GHSA-r929-5x66-fmvp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r945-w37w-79vf/GHSA-r945-w37w-79vf.json b/advisories/unreviewed/2022/05/GHSA-r945-w37w-79vf/GHSA-r945-w37w-79vf.json index 1628d4caa40..5e983e4eb0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-r945-w37w-79vf/GHSA-r945-w37w-79vf.json +++ b/advisories/unreviewed/2022/05/GHSA-r945-w37w-79vf/GHSA-r945-w37w-79vf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r97q-42f3-866f/GHSA-r97q-42f3-866f.json b/advisories/unreviewed/2022/05/GHSA-r97q-42f3-866f/GHSA-r97q-42f3-866f.json index c906f39f5f0..e0c1b48b537 100644 --- a/advisories/unreviewed/2022/05/GHSA-r97q-42f3-866f/GHSA-r97q-42f3-866f.json +++ b/advisories/unreviewed/2022/05/GHSA-r97q-42f3-866f/GHSA-r97q-42f3-866f.json @@ -7,12 +7,8 @@ "CVE-2015-5372" ], "details": "The SAML 2.0 implementation in AdNovum nevisAuth 4.13.0.0 before 4.18.3.1, when using SAML POST-Binding, does not match all attributes of the X.509 certificate embedded in the assertion against the certificate from the identity provider (IdP), which allows remote attackers to inject arbitrary SAML assertions via a crafted certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rcv5-53xq-8xw7/GHSA-rcv5-53xq-8xw7.json b/advisories/unreviewed/2022/05/GHSA-rcv5-53xq-8xw7/GHSA-rcv5-53xq-8xw7.json index 7f4c3efe54d..5dfe1532600 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcv5-53xq-8xw7/GHSA-rcv5-53xq-8xw7.json +++ b/advisories/unreviewed/2022/05/GHSA-rcv5-53xq-8xw7/GHSA-rcv5-53xq-8xw7.json @@ -7,12 +7,8 @@ "CVE-2010-2703" ], "details": "Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when running on Windows, allows remote attackers to execute arbitrary code via a long HTTP request to webappmon.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rg35-3gfr-j5rq/GHSA-rg35-3gfr-j5rq.json b/advisories/unreviewed/2022/05/GHSA-rg35-3gfr-j5rq/GHSA-rg35-3gfr-j5rq.json index 905def3f140..cf545746a79 100644 --- a/advisories/unreviewed/2022/05/GHSA-rg35-3gfr-j5rq/GHSA-rg35-3gfr-j5rq.json +++ b/advisories/unreviewed/2022/05/GHSA-rg35-3gfr-j5rq/GHSA-rg35-3gfr-j5rq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rg4q-5h97-4mhq/GHSA-rg4q-5h97-4mhq.json b/advisories/unreviewed/2022/05/GHSA-rg4q-5h97-4mhq/GHSA-rg4q-5h97-4mhq.json index b2ed47c2314..a072cb352bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-rg4q-5h97-4mhq/GHSA-rg4q-5h97-4mhq.json +++ b/advisories/unreviewed/2022/05/GHSA-rg4q-5h97-4mhq/GHSA-rg4q-5h97-4mhq.json @@ -7,12 +7,8 @@ "CVE-2015-2844" ], "details": "The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1420434000 allows remote attackers to execute arbitrary commands via the $action portion of the PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rh2h-wrf9-gh69/GHSA-rh2h-wrf9-gh69.json b/advisories/unreviewed/2022/05/GHSA-rh2h-wrf9-gh69/GHSA-rh2h-wrf9-gh69.json index 92f44760787..df3c28ddb42 100644 --- a/advisories/unreviewed/2022/05/GHSA-rh2h-wrf9-gh69/GHSA-rh2h-wrf9-gh69.json +++ b/advisories/unreviewed/2022/05/GHSA-rh2h-wrf9-gh69/GHSA-rh2h-wrf9-gh69.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rjjr-365w-f42w/GHSA-rjjr-365w-f42w.json b/advisories/unreviewed/2022/05/GHSA-rjjr-365w-f42w/GHSA-rjjr-365w-f42w.json index f607e8eba8d..b5f4ed3368d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjjr-365w-f42w/GHSA-rjjr-365w-f42w.json +++ b/advisories/unreviewed/2022/05/GHSA-rjjr-365w-f42w/GHSA-rjjr-365w-f42w.json @@ -7,12 +7,8 @@ "CVE-2015-7366" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in Revive Adserver before 3.2.2 allow remote attackers to hijack the authentication of users for requests that (1) perform certain plugin actions and possibly cause a denial of service (disabled core plugins) via unknown vectors or (2) change the contact name and language or possibly have unspecified other impact via a crafted POST request to an account-user-*.php script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rmvh-6pm7-9q3c/GHSA-rmvh-6pm7-9q3c.json b/advisories/unreviewed/2022/05/GHSA-rmvh-6pm7-9q3c/GHSA-rmvh-6pm7-9q3c.json index 7b5e4625184..5130d006d1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmvh-6pm7-9q3c/GHSA-rmvh-6pm7-9q3c.json +++ b/advisories/unreviewed/2022/05/GHSA-rmvh-6pm7-9q3c/GHSA-rmvh-6pm7-9q3c.json @@ -7,12 +7,8 @@ "CVE-2010-1655" ], "details": "Cross-site scripting (XSS) vulnerability in User/User_ChkLogin.asp in PowerEasy 2006 and PowerEasy SiteWeaver 6.8 allows remote attackers to inject arbitrary web script or HTML via the ComeUrl parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rr2v-rm35-c7f7/GHSA-rr2v-rm35-c7f7.json b/advisories/unreviewed/2022/05/GHSA-rr2v-rm35-c7f7/GHSA-rr2v-rm35-c7f7.json index a1e0a9b645f..ba640a2e18a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rr2v-rm35-c7f7/GHSA-rr2v-rm35-c7f7.json +++ b/advisories/unreviewed/2022/05/GHSA-rr2v-rm35-c7f7/GHSA-rr2v-rm35-c7f7.json @@ -7,12 +7,8 @@ "CVE-2010-2007" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in LetoDMS (formerly MyDMS) 1.7.2 and earlier allow remote attackers to hijack the authentication of administrators for requests that use (1) op/op.EditUserData.php, (2) op/op.UsrMgr.php, (3) out/out.RemoveVersion.php, (4) op/op.RemoveFolder.php, (5) op/op.DefaultKeywords.php, (6) op/op.GroupMgr.php, (7) op/op.FolderAccess.php, (8) op/op.FolderNotify.php, or (9) op.MoveFolder.php in mydms.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rrfq-3wrx-cpcp/GHSA-rrfq-3wrx-cpcp.json b/advisories/unreviewed/2022/05/GHSA-rrfq-3wrx-cpcp/GHSA-rrfq-3wrx-cpcp.json index ffd349963aa..84dfb910edb 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrfq-3wrx-cpcp/GHSA-rrfq-3wrx-cpcp.json +++ b/advisories/unreviewed/2022/05/GHSA-rrfq-3wrx-cpcp/GHSA-rrfq-3wrx-cpcp.json @@ -7,12 +7,8 @@ "CVE-2015-3300" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allow remote attackers to inject arbitrary web script or HTML via the (1) billing_firstname, (2) billing_lastname, (3) billing_company, (4) billing_tax_id_number, (5) billing_city, (6) billing_street, (7) billing_street_2, (8) billing_postcode, (9) billing_telephone_1, (10) billing_telephone_2, (11) billing_fax, (12) shipping_firstname, (13) shipping_lastname, (14) shipping_company, (15) shipping_tax_id_number, (16) shipping_city, (17) shipping_street, (18) shipping_street_2, (19) shipping_postcode, (20) shipping_telephone_1, (21) shipping_telephone_2, or (22) shipping_fax parameter to shopping-cart/checkout/; the (23) search_by parameter in the admin/AddressesList.php page to wp-admin/admin.php; the (24) address_id, (25) address_name, (26) firstname, (27) lastname, (28) street, (29) city, (30) postcode, or (31) email parameter in the admin/AddressEdit.php page to wp-admin/admin.php; the (32) post_id or (33) rel_type parameter in the admin/AssignedCategoriesList.php page to wp-admin/admin.php; or the (34) post_type parameter in the admin/CustomFieldsList.php page to wp-admin/admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rrpj-43vg-95p8/GHSA-rrpj-43vg-95p8.json b/advisories/unreviewed/2022/05/GHSA-rrpj-43vg-95p8/GHSA-rrpj-43vg-95p8.json index 52e47024e6d..4c0ca21b7a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrpj-43vg-95p8/GHSA-rrpj-43vg-95p8.json +++ b/advisories/unreviewed/2022/05/GHSA-rrpj-43vg-95p8/GHSA-rrpj-43vg-95p8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rrxx-xr46-4hv7/GHSA-rrxx-xr46-4hv7.json b/advisories/unreviewed/2022/05/GHSA-rrxx-xr46-4hv7/GHSA-rrxx-xr46-4hv7.json index 7e49280998a..928d5a1ed9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrxx-xr46-4hv7/GHSA-rrxx-xr46-4hv7.json +++ b/advisories/unreviewed/2022/05/GHSA-rrxx-xr46-4hv7/GHSA-rrxx-xr46-4hv7.json @@ -7,12 +7,8 @@ "CVE-2015-4877" ], "details": "Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-4878.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rvj2-jr49-7hc2/GHSA-rvj2-jr49-7hc2.json b/advisories/unreviewed/2022/05/GHSA-rvj2-jr49-7hc2/GHSA-rvj2-jr49-7hc2.json index beef73d4f53..516601470e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvj2-jr49-7hc2/GHSA-rvj2-jr49-7hc2.json +++ b/advisories/unreviewed/2022/05/GHSA-rvj2-jr49-7hc2/GHSA-rvj2-jr49-7hc2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rw94-pr63-5frw/GHSA-rw94-pr63-5frw.json b/advisories/unreviewed/2022/05/GHSA-rw94-pr63-5frw/GHSA-rw94-pr63-5frw.json index 8f65f2b784b..b0c2c642c16 100644 --- a/advisories/unreviewed/2022/05/GHSA-rw94-pr63-5frw/GHSA-rw94-pr63-5frw.json +++ b/advisories/unreviewed/2022/05/GHSA-rw94-pr63-5frw/GHSA-rw94-pr63-5frw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rwch-4jch-mjx7/GHSA-rwch-4jch-mjx7.json b/advisories/unreviewed/2022/05/GHSA-rwch-4jch-mjx7/GHSA-rwch-4jch-mjx7.json index 07b71fb5e87..619cb348353 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwch-4jch-mjx7/GHSA-rwch-4jch-mjx7.json +++ b/advisories/unreviewed/2022/05/GHSA-rwch-4jch-mjx7/GHSA-rwch-4jch-mjx7.json @@ -7,12 +7,8 @@ "CVE-2010-2024" ], "details": "transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possibly gain privileges, via a symlink attack on a lockfile in /tmp/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rx7g-4gvj-h8m6/GHSA-rx7g-4gvj-h8m6.json b/advisories/unreviewed/2022/05/GHSA-rx7g-4gvj-h8m6/GHSA-rx7g-4gvj-h8m6.json index 9477b70225d..eb0654a6c01 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx7g-4gvj-h8m6/GHSA-rx7g-4gvj-h8m6.json +++ b/advisories/unreviewed/2022/05/GHSA-rx7g-4gvj-h8m6/GHSA-rx7g-4gvj-h8m6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rx9x-6579-mmvf/GHSA-rx9x-6579-mmvf.json b/advisories/unreviewed/2022/05/GHSA-rx9x-6579-mmvf/GHSA-rx9x-6579-mmvf.json index 8f4ca7bfceb..4553c20b416 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx9x-6579-mmvf/GHSA-rx9x-6579-mmvf.json +++ b/advisories/unreviewed/2022/05/GHSA-rx9x-6579-mmvf/GHSA-rx9x-6579-mmvf.json @@ -7,12 +7,8 @@ "CVE-2010-2678" ], "details": "SQL injection vulnerability in xmap (com_xmap) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rxqc-fvv8-gx29/GHSA-rxqc-fvv8-gx29.json b/advisories/unreviewed/2022/05/GHSA-rxqc-fvv8-gx29/GHSA-rxqc-fvv8-gx29.json index c975e12b5c4..8b839ff2031 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxqc-fvv8-gx29/GHSA-rxqc-fvv8-gx29.json +++ b/advisories/unreviewed/2022/05/GHSA-rxqc-fvv8-gx29/GHSA-rxqc-fvv8-gx29.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rxw2-fh82-mfcc/GHSA-rxw2-fh82-mfcc.json b/advisories/unreviewed/2022/05/GHSA-rxw2-fh82-mfcc/GHSA-rxw2-fh82-mfcc.json index 27807137751..99169d87897 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxw2-fh82-mfcc/GHSA-rxw2-fh82-mfcc.json +++ b/advisories/unreviewed/2022/05/GHSA-rxw2-fh82-mfcc/GHSA-rxw2-fh82-mfcc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2fh-3p9g-5253/GHSA-v2fh-3p9g-5253.json b/advisories/unreviewed/2022/05/GHSA-v2fh-3p9g-5253/GHSA-v2fh-3p9g-5253.json index d89fd995f53..15bc27de867 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2fh-3p9g-5253/GHSA-v2fh-3p9g-5253.json +++ b/advisories/unreviewed/2022/05/GHSA-v2fh-3p9g-5253/GHSA-v2fh-3p9g-5253.json @@ -7,12 +7,8 @@ "CVE-2015-8221" ], "details": "Integer overflow in Google Picasa before 3.9.140 Build 259 allows remote attackers to execute arbitrary code via the CAMF section in a FOVb image, which triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2jx-hxfp-h5qq/GHSA-v2jx-hxfp-h5qq.json b/advisories/unreviewed/2022/05/GHSA-v2jx-hxfp-h5qq/GHSA-v2jx-hxfp-h5qq.json index caf05e936a9..e78bbf6c3e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2jx-hxfp-h5qq/GHSA-v2jx-hxfp-h5qq.json +++ b/advisories/unreviewed/2022/05/GHSA-v2jx-hxfp-h5qq/GHSA-v2jx-hxfp-h5qq.json @@ -7,12 +7,8 @@ "CVE-2015-5736" ], "details": "The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel privileges by setting the callback function in a (1) 0x220024 or (2) 0x220028 ioctl call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v38f-5hv3-pw6r/GHSA-v38f-5hv3-pw6r.json b/advisories/unreviewed/2022/05/GHSA-v38f-5hv3-pw6r/GHSA-v38f-5hv3-pw6r.json index 7d4fc918efa..890cd2bab85 100644 --- a/advisories/unreviewed/2022/05/GHSA-v38f-5hv3-pw6r/GHSA-v38f-5hv3-pw6r.json +++ b/advisories/unreviewed/2022/05/GHSA-v38f-5hv3-pw6r/GHSA-v38f-5hv3-pw6r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v47f-cq78-vjx4/GHSA-v47f-cq78-vjx4.json b/advisories/unreviewed/2022/05/GHSA-v47f-cq78-vjx4/GHSA-v47f-cq78-vjx4.json index a6cd01334d8..c357c7c68a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-v47f-cq78-vjx4/GHSA-v47f-cq78-vjx4.json +++ b/advisories/unreviewed/2022/05/GHSA-v47f-cq78-vjx4/GHSA-v47f-cq78-vjx4.json @@ -7,12 +7,8 @@ "CVE-2010-1907" ], "details": "The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to discover the username of the client user, and consequently determine a pathname to a certain user directory, via a call to the GetUserName method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v4jw-6942-wg6v/GHSA-v4jw-6942-wg6v.json b/advisories/unreviewed/2022/05/GHSA-v4jw-6942-wg6v/GHSA-v4jw-6942-wg6v.json index 21ae235ef29..6f711c7c71c 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4jw-6942-wg6v/GHSA-v4jw-6942-wg6v.json +++ b/advisories/unreviewed/2022/05/GHSA-v4jw-6942-wg6v/GHSA-v4jw-6942-wg6v.json @@ -7,12 +7,8 @@ "CVE-2010-1724" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) func parameter to index.php, or the (2) lang parameter to index.php, which is not properly handled by ZLanguage.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v4w7-93hw-57v7/GHSA-v4w7-93hw-57v7.json b/advisories/unreviewed/2022/05/GHSA-v4w7-93hw-57v7/GHSA-v4w7-93hw-57v7.json index 8e1a8359ae6..a9cc20ad24a 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4w7-93hw-57v7/GHSA-v4w7-93hw-57v7.json +++ b/advisories/unreviewed/2022/05/GHSA-v4w7-93hw-57v7/GHSA-v4w7-93hw-57v7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v57h-pf83-q527/GHSA-v57h-pf83-q527.json b/advisories/unreviewed/2022/05/GHSA-v57h-pf83-q527/GHSA-v57h-pf83-q527.json index f196155b7ce..9d2297598e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-v57h-pf83-q527/GHSA-v57h-pf83-q527.json +++ b/advisories/unreviewed/2022/05/GHSA-v57h-pf83-q527/GHSA-v57h-pf83-q527.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v59g-ff34-qq7w/GHSA-v59g-ff34-qq7w.json b/advisories/unreviewed/2022/05/GHSA-v59g-ff34-qq7w/GHSA-v59g-ff34-qq7w.json index 67822e49e7e..dfb221fec57 100644 --- a/advisories/unreviewed/2022/05/GHSA-v59g-ff34-qq7w/GHSA-v59g-ff34-qq7w.json +++ b/advisories/unreviewed/2022/05/GHSA-v59g-ff34-qq7w/GHSA-v59g-ff34-qq7w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v5cw-cpx9-97fv/GHSA-v5cw-cpx9-97fv.json b/advisories/unreviewed/2022/05/GHSA-v5cw-cpx9-97fv/GHSA-v5cw-cpx9-97fv.json index c6ac8206aad..05a1ec2e07e 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5cw-cpx9-97fv/GHSA-v5cw-cpx9-97fv.json +++ b/advisories/unreviewed/2022/05/GHSA-v5cw-cpx9-97fv/GHSA-v5cw-cpx9-97fv.json @@ -7,12 +7,8 @@ "CVE-2015-5076" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in X2Engine X2CRM before 5.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) version parameter in protected/views/admin/formEditor.php; the (2) importId parameter in protected/views/admin/rollbackImport.php; the (3) bc, (4) fg, (5) bgc, or (6) font parameter in protected/views/site/listener.php; the (7) Services[*] parameter in protected/components/views/webForm.php; the (8) file parameter in protected/components/TranslationManager.php; the (9) x2_key parameter in protected/tests/webscripts/x2WebTrackingTestPages/customWebLeadCaptureScriptTest.php; the (10) id parameter in protected/modules/contacts/controllers/ContactsController.php; or the (11) lastEventId parameter to index.php/profile/getEvents.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v5g6-m3jf-5wxq/GHSA-v5g6-m3jf-5wxq.json b/advisories/unreviewed/2022/05/GHSA-v5g6-m3jf-5wxq/GHSA-v5g6-m3jf-5wxq.json index 948fe2e9805..c2766483b27 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5g6-m3jf-5wxq/GHSA-v5g6-m3jf-5wxq.json +++ b/advisories/unreviewed/2022/05/GHSA-v5g6-m3jf-5wxq/GHSA-v5g6-m3jf-5wxq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v5vm-78qg-9j5r/GHSA-v5vm-78qg-9j5r.json b/advisories/unreviewed/2022/05/GHSA-v5vm-78qg-9j5r/GHSA-v5vm-78qg-9j5r.json index f788790ee31..9b79d8812a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5vm-78qg-9j5r/GHSA-v5vm-78qg-9j5r.json +++ b/advisories/unreviewed/2022/05/GHSA-v5vm-78qg-9j5r/GHSA-v5vm-78qg-9j5r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v73j-5247-67hg/GHSA-v73j-5247-67hg.json b/advisories/unreviewed/2022/05/GHSA-v73j-5247-67hg/GHSA-v73j-5247-67hg.json index 68a086ae88d..3e268e07ddc 100644 --- a/advisories/unreviewed/2022/05/GHSA-v73j-5247-67hg/GHSA-v73j-5247-67hg.json +++ b/advisories/unreviewed/2022/05/GHSA-v73j-5247-67hg/GHSA-v73j-5247-67hg.json @@ -7,12 +7,8 @@ "CVE-2010-3429" ], "details": "flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used in MPlayer and other products, allows remote attackers to execute arbitrary code via a crafted flic file, related to an \"arbitrary offset dereference vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v7v8-f46h-v388/GHSA-v7v8-f46h-v388.json b/advisories/unreviewed/2022/05/GHSA-v7v8-f46h-v388/GHSA-v7v8-f46h-v388.json index c24d1867184..2b410603842 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7v8-f46h-v388/GHSA-v7v8-f46h-v388.json +++ b/advisories/unreviewed/2022/05/GHSA-v7v8-f46h-v388/GHSA-v7v8-f46h-v388.json @@ -7,12 +7,8 @@ "CVE-2010-1795" ], "details": "Untrusted search path vulnerability in Apple iTunes before 9.1, when running on Windows 7, Vista, and XP, allows local users and possibly remote attackers to gain privileges via a Trojan horse DLL in the current working directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v952-72f4-84gw/GHSA-v952-72f4-84gw.json b/advisories/unreviewed/2022/05/GHSA-v952-72f4-84gw/GHSA-v952-72f4-84gw.json index e2665303ac1..bf8573d3596 100644 --- a/advisories/unreviewed/2022/05/GHSA-v952-72f4-84gw/GHSA-v952-72f4-84gw.json +++ b/advisories/unreviewed/2022/05/GHSA-v952-72f4-84gw/GHSA-v952-72f4-84gw.json @@ -7,12 +7,8 @@ "CVE-2010-1912" ], "details": "The SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to bypass intended restrictions on ActiveX execution via \"instantiation/free attacks.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vc7v-9ghj-gp9f/GHSA-vc7v-9ghj-gp9f.json b/advisories/unreviewed/2022/05/GHSA-vc7v-9ghj-gp9f/GHSA-vc7v-9ghj-gp9f.json index 6fcdd945914..99bdfd31411 100644 --- a/advisories/unreviewed/2022/05/GHSA-vc7v-9ghj-gp9f/GHSA-vc7v-9ghj-gp9f.json +++ b/advisories/unreviewed/2022/05/GHSA-vc7v-9ghj-gp9f/GHSA-vc7v-9ghj-gp9f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vccg-x753-gj7q/GHSA-vccg-x753-gj7q.json b/advisories/unreviewed/2022/05/GHSA-vccg-x753-gj7q/GHSA-vccg-x753-gj7q.json index bad82979558..beac14f8bdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-vccg-x753-gj7q/GHSA-vccg-x753-gj7q.json +++ b/advisories/unreviewed/2022/05/GHSA-vccg-x753-gj7q/GHSA-vccg-x753-gj7q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vfrp-379g-5hwr/GHSA-vfrp-379g-5hwr.json b/advisories/unreviewed/2022/05/GHSA-vfrp-379g-5hwr/GHSA-vfrp-379g-5hwr.json index e68e4cc4cd0..066db2f1095 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfrp-379g-5hwr/GHSA-vfrp-379g-5hwr.json +++ b/advisories/unreviewed/2022/05/GHSA-vfrp-379g-5hwr/GHSA-vfrp-379g-5hwr.json @@ -7,12 +7,8 @@ "CVE-2015-3443" ], "details": "Cross-site scripting (XSS) vulnerability in the basic dashboard in Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before 8.8.000005 allows remote authenticated users to inject arbitrary web script or HTML via a password entry, which is not properly handled when toggling the password mask.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vj84-vh8m-pr8h/GHSA-vj84-vh8m-pr8h.json b/advisories/unreviewed/2022/05/GHSA-vj84-vh8m-pr8h/GHSA-vj84-vh8m-pr8h.json index 87a11ad51bc..6d8008c60c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-vj84-vh8m-pr8h/GHSA-vj84-vh8m-pr8h.json +++ b/advisories/unreviewed/2022/05/GHSA-vj84-vh8m-pr8h/GHSA-vj84-vh8m-pr8h.json @@ -7,12 +7,8 @@ "CVE-2015-5063" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS & Framework 3.1.13 allow remote attackers to inject arbitrary web script or HTML via the (1) admin_username or (2) admin_password parameter to install.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vm6p-3gwg-gqqj/GHSA-vm6p-3gwg-gqqj.json b/advisories/unreviewed/2022/05/GHSA-vm6p-3gwg-gqqj/GHSA-vm6p-3gwg-gqqj.json index a771ddbf42a..d8ec7fa4d0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm6p-3gwg-gqqj/GHSA-vm6p-3gwg-gqqj.json +++ b/advisories/unreviewed/2022/05/GHSA-vm6p-3gwg-gqqj/GHSA-vm6p-3gwg-gqqj.json @@ -7,12 +7,8 @@ "CVE-2010-3267" ], "details": "Multiple SQL injection vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the qu_id parameter to bugs.aspx, (2) the row_id parameter to delete_query.aspx, the (3) new_project or (4) us_id parameter to edit_bug.aspx, or (5) the bug_list parameter to massedit.aspx. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vmrh-jw9r-5h7h/GHSA-vmrh-jw9r-5h7h.json b/advisories/unreviewed/2022/05/GHSA-vmrh-jw9r-5h7h/GHSA-vmrh-jw9r-5h7h.json index 1e9ecff27b9..380589f759b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmrh-jw9r-5h7h/GHSA-vmrh-jw9r-5h7h.json +++ b/advisories/unreviewed/2022/05/GHSA-vmrh-jw9r-5h7h/GHSA-vmrh-jw9r-5h7h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -59,9 +57,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vmvh-fm3r-475p/GHSA-vmvh-fm3r-475p.json b/advisories/unreviewed/2022/05/GHSA-vmvh-fm3r-475p/GHSA-vmvh-fm3r-475p.json index ecd2478e5a8..e1fb3ec4fa3 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmvh-fm3r-475p/GHSA-vmvh-fm3r-475p.json +++ b/advisories/unreviewed/2022/05/GHSA-vmvh-fm3r-475p/GHSA-vmvh-fm3r-475p.json @@ -7,12 +7,8 @@ "CVE-2010-2634" ], "details": "RSA enVision before 3.7 SP1 allows remote authenticated users to cause a denial of service via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vp6q-h4rp-4q4g/GHSA-vp6q-h4rp-4q4g.json b/advisories/unreviewed/2022/05/GHSA-vp6q-h4rp-4q4g/GHSA-vp6q-h4rp-4q4g.json index b1890e4982b..f810bb72912 100644 --- a/advisories/unreviewed/2022/05/GHSA-vp6q-h4rp-4q4g/GHSA-vp6q-h4rp-4q4g.json +++ b/advisories/unreviewed/2022/05/GHSA-vp6q-h4rp-4q4g/GHSA-vp6q-h4rp-4q4g.json @@ -7,12 +7,8 @@ "CVE-2010-2695" ], "details": "Directory traversal vulnerability in the SFTP/SSH2 virtual server in Xlight FTP Server 3.5.0, 3.5.5, and possibly other versions before 3.6 allows remote authenticated users to read, overwrite, or delete arbitrary files via .. (dot dot) sequences in the (1) ls, (2) rm, (3) rename, and other unspecified commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vppr-9j2x-vp8j/GHSA-vppr-9j2x-vp8j.json b/advisories/unreviewed/2022/05/GHSA-vppr-9j2x-vp8j/GHSA-vppr-9j2x-vp8j.json index d4bf98d39e9..274f4bef83f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vppr-9j2x-vp8j/GHSA-vppr-9j2x-vp8j.json +++ b/advisories/unreviewed/2022/05/GHSA-vppr-9j2x-vp8j/GHSA-vppr-9j2x-vp8j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vq2h-6r6j-7wj3/GHSA-vq2h-6r6j-7wj3.json b/advisories/unreviewed/2022/05/GHSA-vq2h-6r6j-7wj3/GHSA-vq2h-6r6j-7wj3.json index 7af906e812b..598b62f0804 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq2h-6r6j-7wj3/GHSA-vq2h-6r6j-7wj3.json +++ b/advisories/unreviewed/2022/05/GHSA-vq2h-6r6j-7wj3/GHSA-vq2h-6r6j-7wj3.json @@ -7,12 +7,8 @@ "CVE-2010-2293" ], "details": "The Ping tools web interface in Dlink Di-604 router allows remote authenticated users to cause a denial of service via a large \"ip textfield\" size.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vqcg-wwv2-x86g/GHSA-vqcg-wwv2-x86g.json b/advisories/unreviewed/2022/05/GHSA-vqcg-wwv2-x86g/GHSA-vqcg-wwv2-x86g.json index b364841233a..58cd1f69200 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqcg-wwv2-x86g/GHSA-vqcg-wwv2-x86g.json +++ b/advisories/unreviewed/2022/05/GHSA-vqcg-wwv2-x86g/GHSA-vqcg-wwv2-x86g.json @@ -7,12 +7,8 @@ "CVE-2015-2223" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the web-based console management interface in Palo Alto Networks Traps (formerly Cyvera Endpoint Protection) 3.1.2.1546 allow remote attackers to inject arbitrary web script or HTML via the (1) Arguments, (2) FileName, or (3) URL parameter in a SOAP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vqcq-324h-446p/GHSA-vqcq-324h-446p.json b/advisories/unreviewed/2022/05/GHSA-vqcq-324h-446p/GHSA-vqcq-324h-446p.json index 26898641b0d..401a3d61554 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqcq-324h-446p/GHSA-vqcq-324h-446p.json +++ b/advisories/unreviewed/2022/05/GHSA-vqcq-324h-446p/GHSA-vqcq-324h-446p.json @@ -7,12 +7,8 @@ "CVE-2010-2847" ], "details": "Multiple SQL injection vulnerabilities in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allow remote attackers to execute arbitrary SQL commands via the viewform parameter in a (1) ferforms or (2) tferforms action to index.php, and the (3) id parameter in a vferforms action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vqp7-6hqw-v8m9/GHSA-vqp7-6hqw-v8m9.json b/advisories/unreviewed/2022/05/GHSA-vqp7-6hqw-v8m9/GHSA-vqp7-6hqw-v8m9.json index d3fc0e23536..9e0c9911241 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqp7-6hqw-v8m9/GHSA-vqp7-6hqw-v8m9.json +++ b/advisories/unreviewed/2022/05/GHSA-vqp7-6hqw-v8m9/GHSA-vqp7-6hqw-v8m9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vvfr-mrxv-rv8w/GHSA-vvfr-mrxv-rv8w.json b/advisories/unreviewed/2022/05/GHSA-vvfr-mrxv-rv8w/GHSA-vvfr-mrxv-rv8w.json index 9dd91d700a0..ba71520939e 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvfr-mrxv-rv8w/GHSA-vvfr-mrxv-rv8w.json +++ b/advisories/unreviewed/2022/05/GHSA-vvfr-mrxv-rv8w/GHSA-vvfr-mrxv-rv8w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vwjv-28f3-j79g/GHSA-vwjv-28f3-j79g.json b/advisories/unreviewed/2022/05/GHSA-vwjv-28f3-j79g/GHSA-vwjv-28f3-j79g.json index 144ff2653a9..ba6460429c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwjv-28f3-j79g/GHSA-vwjv-28f3-j79g.json +++ b/advisories/unreviewed/2022/05/GHSA-vwjv-28f3-j79g/GHSA-vwjv-28f3-j79g.json @@ -7,12 +7,8 @@ "CVE-2010-1906" ], "details": "tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timestamp field to validate input to the \\\\.\\pipe\\__RepairService_pipe__company named pipe, which allows remote authenticated users to execute arbitrary code by obtaining the current time from (1) tcpip.sys or (2) an SMB2 service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vwmr-hgcv-r475/GHSA-vwmr-hgcv-r475.json b/advisories/unreviewed/2022/05/GHSA-vwmr-hgcv-r475/GHSA-vwmr-hgcv-r475.json index 33c72f07ec0..9cfd7c0b564 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwmr-hgcv-r475/GHSA-vwmr-hgcv-r475.json +++ b/advisories/unreviewed/2022/05/GHSA-vwmr-hgcv-r475/GHSA-vwmr-hgcv-r475.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vx88-5hj8-432c/GHSA-vx88-5hj8-432c.json b/advisories/unreviewed/2022/05/GHSA-vx88-5hj8-432c/GHSA-vx88-5hj8-432c.json index 505e59694e5..5988897f0c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-vx88-5hj8-432c/GHSA-vx88-5hj8-432c.json +++ b/advisories/unreviewed/2022/05/GHSA-vx88-5hj8-432c/GHSA-vx88-5hj8-432c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vx8c-r97v-p2vc/GHSA-vx8c-r97v-p2vc.json b/advisories/unreviewed/2022/05/GHSA-vx8c-r97v-p2vc/GHSA-vx8c-r97v-p2vc.json index 32265edddd5..457ba5461fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-vx8c-r97v-p2vc/GHSA-vx8c-r97v-p2vc.json +++ b/advisories/unreviewed/2022/05/GHSA-vx8c-r97v-p2vc/GHSA-vx8c-r97v-p2vc.json @@ -7,12 +7,8 @@ "CVE-2010-3261" ], "details": "Directory traversal vulnerability in RSA Authentication Agent 7.0 before P2 for Web allows remote attackers to read unspecified data via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vxx4-cx7p-j268/GHSA-vxx4-cx7p-j268.json b/advisories/unreviewed/2022/05/GHSA-vxx4-cx7p-j268/GHSA-vxx4-cx7p-j268.json index b03d7db6f34..ff7dab84aa6 100644 --- a/advisories/unreviewed/2022/05/GHSA-vxx4-cx7p-j268/GHSA-vxx4-cx7p-j268.json +++ b/advisories/unreviewed/2022/05/GHSA-vxx4-cx7p-j268/GHSA-vxx4-cx7p-j268.json @@ -7,12 +7,8 @@ "CVE-2015-4670" ], "details": "Directory traversal vulnerability in the AjaxFileUpload control in DevExpress AJAX Control Toolkit (aka AjaxControlToolkit) before 15.1 allows remote attackers to write to arbitrary files via a .. (dot dot) in the fileId parameter to AjaxFileUploadHandler.axd.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w343-46q8-7x26/GHSA-w343-46q8-7x26.json b/advisories/unreviewed/2022/05/GHSA-w343-46q8-7x26/GHSA-w343-46q8-7x26.json index d4ffbf299f8..e81bc5bfca4 100644 --- a/advisories/unreviewed/2022/05/GHSA-w343-46q8-7x26/GHSA-w343-46q8-7x26.json +++ b/advisories/unreviewed/2022/05/GHSA-w343-46q8-7x26/GHSA-w343-46q8-7x26.json @@ -7,12 +7,8 @@ "CVE-2015-2278" ], "details": "The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to look-ups of non-simple codes, aka SAP Security Note 2124806, 2121661, 2127995, and 2125316.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w4rw-xxg9-4xcp/GHSA-w4rw-xxg9-4xcp.json b/advisories/unreviewed/2022/05/GHSA-w4rw-xxg9-4xcp/GHSA-w4rw-xxg9-4xcp.json index 20628544a25..e49f926353d 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4rw-xxg9-4xcp/GHSA-w4rw-xxg9-4xcp.json +++ b/advisories/unreviewed/2022/05/GHSA-w4rw-xxg9-4xcp/GHSA-w4rw-xxg9-4xcp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w5fj-785g-f8cw/GHSA-w5fj-785g-f8cw.json b/advisories/unreviewed/2022/05/GHSA-w5fj-785g-f8cw/GHSA-w5fj-785g-f8cw.json index 787a1444358..c667f071940 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5fj-785g-f8cw/GHSA-w5fj-785g-f8cw.json +++ b/advisories/unreviewed/2022/05/GHSA-w5fj-785g-f8cw/GHSA-w5fj-785g-f8cw.json @@ -7,12 +7,8 @@ "CVE-2010-2306" ], "details": "The default installation of Sourcefire 3D Sensor 1000, 2000, and 9900; and Defense Center 1000; uses the same static, private SSL keys for multiple devices and installations, which allows remote attackers to decrypt SSL traffic via a man-in-the-middle (MITM) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w5g4-64r6-254q/GHSA-w5g4-64r6-254q.json b/advisories/unreviewed/2022/05/GHSA-w5g4-64r6-254q/GHSA-w5g4-64r6-254q.json index 1e637e67ae5..a3d376ca3ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5g4-64r6-254q/GHSA-w5g4-64r6-254q.json +++ b/advisories/unreviewed/2022/05/GHSA-w5g4-64r6-254q/GHSA-w5g4-64r6-254q.json @@ -7,12 +7,8 @@ "CVE-2010-2871" ], "details": "Integer overflow in the 3D object functionality in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted size value in a 0xFFFFFF45 RIFF record in a Director movie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w67j-pm6m-f39v/GHSA-w67j-pm6m-f39v.json b/advisories/unreviewed/2022/05/GHSA-w67j-pm6m-f39v/GHSA-w67j-pm6m-f39v.json index c970366fdbf..7ec5c25b109 100644 --- a/advisories/unreviewed/2022/05/GHSA-w67j-pm6m-f39v/GHSA-w67j-pm6m-f39v.json +++ b/advisories/unreviewed/2022/05/GHSA-w67j-pm6m-f39v/GHSA-w67j-pm6m-f39v.json @@ -7,12 +7,8 @@ "CVE-2010-1995" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS before 2.0.5 allow remote authenticated users, with \"Add new article\" privileges, to inject arbitrary web script or HTML via the (1) title, (2) subTitle, and (3) author parameters in conjunction with a /admin/news/article/add PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w72v-g7rw-wxjf/GHSA-w72v-g7rw-wxjf.json b/advisories/unreviewed/2022/05/GHSA-w72v-g7rw-wxjf/GHSA-w72v-g7rw-wxjf.json index fbc34b24cb8..d8cb5513df9 100644 --- a/advisories/unreviewed/2022/05/GHSA-w72v-g7rw-wxjf/GHSA-w72v-g7rw-wxjf.json +++ b/advisories/unreviewed/2022/05/GHSA-w72v-g7rw-wxjf/GHSA-w72v-g7rw-wxjf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w7cc-jv4p-qccr/GHSA-w7cc-jv4p-qccr.json b/advisories/unreviewed/2022/05/GHSA-w7cc-jv4p-qccr/GHSA-w7cc-jv4p-qccr.json index 53aa1bcb9ba..0e378236033 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7cc-jv4p-qccr/GHSA-w7cc-jv4p-qccr.json +++ b/advisories/unreviewed/2022/05/GHSA-w7cc-jv4p-qccr/GHSA-w7cc-jv4p-qccr.json @@ -7,12 +7,8 @@ "CVE-2015-5621" ], "details": "The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w8v6-3q9c-7754/GHSA-w8v6-3q9c-7754.json b/advisories/unreviewed/2022/05/GHSA-w8v6-3q9c-7754/GHSA-w8v6-3q9c-7754.json index c8641219335..291548b103f 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8v6-3q9c-7754/GHSA-w8v6-3q9c-7754.json +++ b/advisories/unreviewed/2022/05/GHSA-w8v6-3q9c-7754/GHSA-w8v6-3q9c-7754.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w95f-c925-pwx7/GHSA-w95f-c925-pwx7.json b/advisories/unreviewed/2022/05/GHSA-w95f-c925-pwx7/GHSA-w95f-c925-pwx7.json index 3de6ae16e95..45906dbcfdb 100644 --- a/advisories/unreviewed/2022/05/GHSA-w95f-c925-pwx7/GHSA-w95f-c925-pwx7.json +++ b/advisories/unreviewed/2022/05/GHSA-w95f-c925-pwx7/GHSA-w95f-c925-pwx7.json @@ -7,12 +7,8 @@ "CVE-2010-1521" ], "details": "SQL injection vulnerability in include/classes/tzn_user.php in TaskFreak! Original multi user before 0.6.4 allows remote attackers to execute arbitrary SQL commands via the password parameter to login.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wc5v-293f-m852/GHSA-wc5v-293f-m852.json b/advisories/unreviewed/2022/05/GHSA-wc5v-293f-m852/GHSA-wc5v-293f-m852.json index 68bf91fff81..b7343f024f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc5v-293f-m852/GHSA-wc5v-293f-m852.json +++ b/advisories/unreviewed/2022/05/GHSA-wc5v-293f-m852/GHSA-wc5v-293f-m852.json @@ -7,12 +7,8 @@ "CVE-2010-1551" ], "details": "Stack-based buffer overflow in the _OVParseLLA function in ov.dll in netmon.exe in Network Monitor in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via the sel parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wcxv-ff2g-c9qw/GHSA-wcxv-ff2g-c9qw.json b/advisories/unreviewed/2022/05/GHSA-wcxv-ff2g-c9qw/GHSA-wcxv-ff2g-c9qw.json index db83b7a64f2..1869ebcf643 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcxv-ff2g-c9qw/GHSA-wcxv-ff2g-c9qw.json +++ b/advisories/unreviewed/2022/05/GHSA-wcxv-ff2g-c9qw/GHSA-wcxv-ff2g-c9qw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wg4m-vvp6-2hc5/GHSA-wg4m-vvp6-2hc5.json b/advisories/unreviewed/2022/05/GHSA-wg4m-vvp6-2hc5/GHSA-wg4m-vvp6-2hc5.json index 71e4e06394f..2c4aae329ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg4m-vvp6-2hc5/GHSA-wg4m-vvp6-2hc5.json +++ b/advisories/unreviewed/2022/05/GHSA-wg4m-vvp6-2hc5/GHSA-wg4m-vvp6-2hc5.json @@ -7,12 +7,8 @@ "CVE-2010-1593" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (1) the CommenterURL parameter to PostCommentForm, and in the Forum module before 0.2.5 in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (2) the Search parameter to forums/search (aka the search script).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wg84-xv5x-v36x/GHSA-wg84-xv5x-v36x.json b/advisories/unreviewed/2022/05/GHSA-wg84-xv5x-v36x/GHSA-wg84-xv5x-v36x.json index 086f1f4fb65..faa7bd0aa00 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg84-xv5x-v36x/GHSA-wg84-xv5x-v36x.json +++ b/advisories/unreviewed/2022/05/GHSA-wg84-xv5x-v36x/GHSA-wg84-xv5x-v36x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -131,9 +129,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-whrh-29g4-mq5m/GHSA-whrh-29g4-mq5m.json b/advisories/unreviewed/2022/05/GHSA-whrh-29g4-mq5m/GHSA-whrh-29g4-mq5m.json index 5f928077a63..7733fcbb41f 100644 --- a/advisories/unreviewed/2022/05/GHSA-whrh-29g4-mq5m/GHSA-whrh-29g4-mq5m.json +++ b/advisories/unreviewed/2022/05/GHSA-whrh-29g4-mq5m/GHSA-whrh-29g4-mq5m.json @@ -7,12 +7,8 @@ "CVE-2015-2220" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 parameter in a ninja_forms_ajax_submit action to wp-admin/admin-ajax.php or (2) remote administrators to inject arbitrary web script or HTML via the fields[1] parameter to wp-admin/post.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wjhh-pcvh-43xr/GHSA-wjhh-pcvh-43xr.json b/advisories/unreviewed/2022/05/GHSA-wjhh-pcvh-43xr/GHSA-wjhh-pcvh-43xr.json index 92580aa6a61..83b166d0a35 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjhh-pcvh-43xr/GHSA-wjhh-pcvh-43xr.json +++ b/advisories/unreviewed/2022/05/GHSA-wjhh-pcvh-43xr/GHSA-wjhh-pcvh-43xr.json @@ -7,12 +7,8 @@ "CVE-2010-3032" ], "details": "Integer overflow in the OBGIOPServerWorker::extractHeader function in the ebus-3-3-2-6.dll module in SAP Crystal Reports 2008 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GIOP packet with a crafted size, which triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wmmq-22w7-cvf3/GHSA-wmmq-22w7-cvf3.json b/advisories/unreviewed/2022/05/GHSA-wmmq-22w7-cvf3/GHSA-wmmq-22w7-cvf3.json index 6cb1bfd1110..55db7c58a55 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmmq-22w7-cvf3/GHSA-wmmq-22w7-cvf3.json +++ b/advisories/unreviewed/2022/05/GHSA-wmmq-22w7-cvf3/GHSA-wmmq-22w7-cvf3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wqm3-6h48-8p64/GHSA-wqm3-6h48-8p64.json b/advisories/unreviewed/2022/05/GHSA-wqm3-6h48-8p64/GHSA-wqm3-6h48-8p64.json index 818a2f889cd..3e1973fd3a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqm3-6h48-8p64/GHSA-wqm3-6h48-8p64.json +++ b/advisories/unreviewed/2022/05/GHSA-wqm3-6h48-8p64/GHSA-wqm3-6h48-8p64.json @@ -7,12 +7,8 @@ "CVE-2015-2747" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the data loss prevention (DLP) incident Forensics Preview in Websense Triton 7.8.3 and V-Series 7.7 appliances allow remote attackers to inject arbitrary web script or HTML via a crafted (1) email or (2) HTTP request, which triggers a DLP Policy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wr4v-3vj7-6wg6/GHSA-wr4v-3vj7-6wg6.json b/advisories/unreviewed/2022/05/GHSA-wr4v-3vj7-6wg6/GHSA-wr4v-3vj7-6wg6.json index 494dc947dea..16325da4055 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr4v-3vj7-6wg6/GHSA-wr4v-3vj7-6wg6.json +++ b/advisories/unreviewed/2022/05/GHSA-wr4v-3vj7-6wg6/GHSA-wr4v-3vj7-6wg6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wrp6-hppf-h4vm/GHSA-wrp6-hppf-h4vm.json b/advisories/unreviewed/2022/05/GHSA-wrp6-hppf-h4vm/GHSA-wrp6-hppf-h4vm.json index 8575ae8db1a..335423311ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrp6-hppf-h4vm/GHSA-wrp6-hppf-h4vm.json +++ b/advisories/unreviewed/2022/05/GHSA-wrp6-hppf-h4vm/GHSA-wrp6-hppf-h4vm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wv6m-w8jv-x79q/GHSA-wv6m-w8jv-x79q.json b/advisories/unreviewed/2022/05/GHSA-wv6m-w8jv-x79q/GHSA-wv6m-w8jv-x79q.json index 918ff45a998..599a7573b46 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv6m-w8jv-x79q/GHSA-wv6m-w8jv-x79q.json +++ b/advisories/unreviewed/2022/05/GHSA-wv6m-w8jv-x79q/GHSA-wv6m-w8jv-x79q.json @@ -7,12 +7,8 @@ "CVE-2015-3986" ], "details": "Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to hijack the authentication of administrators for requests that conduct directory traversal attacks via the tcp_box_path parameter in the checkout_editor_settings page to wp-admin/admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wvf6-cqwc-cf6x/GHSA-wvf6-cqwc-cf6x.json b/advisories/unreviewed/2022/05/GHSA-wvf6-cqwc-cf6x/GHSA-wvf6-cqwc-cf6x.json index 952be6ecb3f..7d142182ab9 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvf6-cqwc-cf6x/GHSA-wvf6-cqwc-cf6x.json +++ b/advisories/unreviewed/2022/05/GHSA-wvf6-cqwc-cf6x/GHSA-wvf6-cqwc-cf6x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wx33-xfw6-fh7w/GHSA-wx33-xfw6-fh7w.json b/advisories/unreviewed/2022/05/GHSA-wx33-xfw6-fh7w/GHSA-wx33-xfw6-fh7w.json index 9c4c6825b5a..1703145c7b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx33-xfw6-fh7w/GHSA-wx33-xfw6-fh7w.json +++ b/advisories/unreviewed/2022/05/GHSA-wx33-xfw6-fh7w/GHSA-wx33-xfw6-fh7w.json @@ -7,12 +7,8 @@ "CVE-2010-2876" ], "details": "Adobe Shockwave Player before 11.5.8.612 does not properly validate values associated with buffer-size calculation for a 0xFFFFFFF8 record in a (1) .dir or (2) .dcr Director movie, which allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted movie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxmr-mcvm-5j4v/GHSA-wxmr-mcvm-5j4v.json b/advisories/unreviewed/2022/05/GHSA-wxmr-mcvm-5j4v/GHSA-wxmr-mcvm-5j4v.json index b52c0d2f08a..cc526a50113 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxmr-mcvm-5j4v/GHSA-wxmr-mcvm-5j4v.json +++ b/advisories/unreviewed/2022/05/GHSA-wxmr-mcvm-5j4v/GHSA-wxmr-mcvm-5j4v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3h5-6rj4-3qh9/GHSA-x3h5-6rj4-3qh9.json b/advisories/unreviewed/2022/05/GHSA-x3h5-6rj4-3qh9/GHSA-x3h5-6rj4-3qh9.json index dcbb9125fd8..3a5e04a1afe 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3h5-6rj4-3qh9/GHSA-x3h5-6rj4-3qh9.json +++ b/advisories/unreviewed/2022/05/GHSA-x3h5-6rj4-3qh9/GHSA-x3h5-6rj4-3qh9.json @@ -7,12 +7,8 @@ "CVE-2015-2755" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) lat (Latitude), (2) long (Longitude), (3) map_width, (4) map_height, or (5) zoom (Map Zoom) parameter in the ab_map_options page to wp-admin/admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3r9-8qrf-5hff/GHSA-x3r9-8qrf-5hff.json b/advisories/unreviewed/2022/05/GHSA-x3r9-8qrf-5hff/GHSA-x3r9-8qrf-5hff.json index 39238840b37..b77a69dda46 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3r9-8qrf-5hff/GHSA-x3r9-8qrf-5hff.json +++ b/advisories/unreviewed/2022/05/GHSA-x3r9-8qrf-5hff/GHSA-x3r9-8qrf-5hff.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x6rf-v7rx-4h25/GHSA-x6rf-v7rx-4h25.json b/advisories/unreviewed/2022/05/GHSA-x6rf-v7rx-4h25/GHSA-x6rf-v7rx-4h25.json index e435ca8aa34..7227f7ed163 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6rf-v7rx-4h25/GHSA-x6rf-v7rx-4h25.json +++ b/advisories/unreviewed/2022/05/GHSA-x6rf-v7rx-4h25/GHSA-x6rf-v7rx-4h25.json @@ -7,12 +7,8 @@ "CVE-2010-3321" ], "details": "RSA Authentication Client 2.0.x, 3.0, and 3.5.x before 3.5.3 does not properly handle a SENSITIVE or NON-EXTRACTABLE tag on a secret key object that is stored on a SecurID 800 authenticator, which allows local users to bypass intended access restrictions and read keys via unspecified PKCS#11 API requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x7h9-4jcm-r6qh/GHSA-x7h9-4jcm-r6qh.json b/advisories/unreviewed/2022/05/GHSA-x7h9-4jcm-r6qh/GHSA-x7h9-4jcm-r6qh.json index c1c7124c3b8..94dfa2f3df3 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7h9-4jcm-r6qh/GHSA-x7h9-4jcm-r6qh.json +++ b/advisories/unreviewed/2022/05/GHSA-x7h9-4jcm-r6qh/GHSA-x7h9-4jcm-r6qh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x7qx-qqfv-f6qw/GHSA-x7qx-qqfv-f6qw.json b/advisories/unreviewed/2022/05/GHSA-x7qx-qqfv-f6qw/GHSA-x7qx-qqfv-f6qw.json index e1b74ee96d5..2e157ac4baf 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7qx-qqfv-f6qw/GHSA-x7qx-qqfv-f6qw.json +++ b/advisories/unreviewed/2022/05/GHSA-x7qx-qqfv-f6qw/GHSA-x7qx-qqfv-f6qw.json @@ -7,12 +7,8 @@ "CVE-2010-2576" ], "details": "Opera before 10.61 does not properly suppress clicks on download dialogs that became visible after a recent tab change, which allows remote attackers to conduct clickjacking attacks, and consequently execute arbitrary code, via vectors involving (1) closing a tab or (2) hiding a tab, a related issue to CVE-2005-2407.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x7vp-7c3f-rr2j/GHSA-x7vp-7c3f-rr2j.json b/advisories/unreviewed/2022/05/GHSA-x7vp-7c3f-rr2j/GHSA-x7vp-7c3f-rr2j.json index b91444979f5..1e0c987ed77 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7vp-7c3f-rr2j/GHSA-x7vp-7c3f-rr2j.json +++ b/advisories/unreviewed/2022/05/GHSA-x7vp-7c3f-rr2j/GHSA-x7vp-7c3f-rr2j.json @@ -7,12 +7,8 @@ "CVE-2010-2860" ], "details": "The EMC Celerra Network Attached Storage (NAS) appliance accepts external network traffic to IP addresses intended for an intranet network within the appliance, which allows remote attackers to read, create, or modify arbitrary files in the user data directory via NFS requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x8gw-g3jh-3xww/GHSA-x8gw-g3jh-3xww.json b/advisories/unreviewed/2022/05/GHSA-x8gw-g3jh-3xww/GHSA-x8gw-g3jh-3xww.json index 522b9248dfe..7c2097570e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8gw-g3jh-3xww/GHSA-x8gw-g3jh-3xww.json +++ b/advisories/unreviewed/2022/05/GHSA-x8gw-g3jh-3xww/GHSA-x8gw-g3jh-3xww.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xc26-wfvp-2xpj/GHSA-xc26-wfvp-2xpj.json b/advisories/unreviewed/2022/05/GHSA-xc26-wfvp-2xpj/GHSA-xc26-wfvp-2xpj.json index db4660db596..b349745940c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc26-wfvp-2xpj/GHSA-xc26-wfvp-2xpj.json +++ b/advisories/unreviewed/2022/05/GHSA-xc26-wfvp-2xpj/GHSA-xc26-wfvp-2xpj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xc32-5f4v-7g6x/GHSA-xc32-5f4v-7g6x.json b/advisories/unreviewed/2022/05/GHSA-xc32-5f4v-7g6x/GHSA-xc32-5f4v-7g6x.json index 511e9066a5f..c08f8be32ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc32-5f4v-7g6x/GHSA-xc32-5f4v-7g6x.json +++ b/advisories/unreviewed/2022/05/GHSA-xc32-5f4v-7g6x/GHSA-xc32-5f4v-7g6x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xc6r-xw3r-wm8f/GHSA-xc6r-xw3r-wm8f.json b/advisories/unreviewed/2022/05/GHSA-xc6r-xw3r-wm8f/GHSA-xc6r-xw3r-wm8f.json index 9b5965eb460..47dd9356748 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc6r-xw3r-wm8f/GHSA-xc6r-xw3r-wm8f.json +++ b/advisories/unreviewed/2022/05/GHSA-xc6r-xw3r-wm8f/GHSA-xc6r-xw3r-wm8f.json @@ -7,12 +7,8 @@ "CVE-2015-3447" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in macIpSpoofView.html in Dell SonicWall SonicOS 7.5.0.12 and 6.x allow remote attackers to inject arbitrary web script or HTML via the (1) searchSpoof or (2) searchSpoofIpDet parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xcj8-64wc-2v2p/GHSA-xcj8-64wc-2v2p.json b/advisories/unreviewed/2022/05/GHSA-xcj8-64wc-2v2p/GHSA-xcj8-64wc-2v2p.json index a61a38b830c..9c899c51345 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcj8-64wc-2v2p/GHSA-xcj8-64wc-2v2p.json +++ b/advisories/unreviewed/2022/05/GHSA-xcj8-64wc-2v2p/GHSA-xcj8-64wc-2v2p.json @@ -7,12 +7,8 @@ "CVE-2015-3000" ], "details": "SysAid Help Desk before 15.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of nested entity references in an XML document to (1) /agententry, (2) /rdsmonitoringresponse, or (3) /androidactions, aka an XML Entity Expansion (XEE) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xf4x-rm5j-3f4c/GHSA-xf4x-rm5j-3f4c.json b/advisories/unreviewed/2022/05/GHSA-xf4x-rm5j-3f4c/GHSA-xf4x-rm5j-3f4c.json index 1226faca480..997bb88a094 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf4x-rm5j-3f4c/GHSA-xf4x-rm5j-3f4c.json +++ b/advisories/unreviewed/2022/05/GHSA-xf4x-rm5j-3f4c/GHSA-xf4x-rm5j-3f4c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xh3h-35f7-mgq7/GHSA-xh3h-35f7-mgq7.json b/advisories/unreviewed/2022/05/GHSA-xh3h-35f7-mgq7/GHSA-xh3h-35f7-mgq7.json index 4408504671d..9fd85cb5db7 100644 --- a/advisories/unreviewed/2022/05/GHSA-xh3h-35f7-mgq7/GHSA-xh3h-35f7-mgq7.json +++ b/advisories/unreviewed/2022/05/GHSA-xh3h-35f7-mgq7/GHSA-xh3h-35f7-mgq7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xhpv-gh4w-v5jf/GHSA-xhpv-gh4w-v5jf.json b/advisories/unreviewed/2022/05/GHSA-xhpv-gh4w-v5jf/GHSA-xhpv-gh4w-v5jf.json index b797ec1f102..30a033be742 100644 --- a/advisories/unreviewed/2022/05/GHSA-xhpv-gh4w-v5jf/GHSA-xhpv-gh4w-v5jf.json +++ b/advisories/unreviewed/2022/05/GHSA-xhpv-gh4w-v5jf/GHSA-xhpv-gh4w-v5jf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjjc-8jjh-rwv3/GHSA-xjjc-8jjh-rwv3.json b/advisories/unreviewed/2022/05/GHSA-xjjc-8jjh-rwv3/GHSA-xjjc-8jjh-rwv3.json index 6a8c1428d8e..84acfb9fe1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjjc-8jjh-rwv3/GHSA-xjjc-8jjh-rwv3.json +++ b/advisories/unreviewed/2022/05/GHSA-xjjc-8jjh-rwv3/GHSA-xjjc-8jjh-rwv3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xjr4-8c62-v64c/GHSA-xjr4-8c62-v64c.json b/advisories/unreviewed/2022/05/GHSA-xjr4-8c62-v64c/GHSA-xjr4-8c62-v64c.json index 9c2a9a779b2..80d3516e3d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjr4-8c62-v64c/GHSA-xjr4-8c62-v64c.json +++ b/advisories/unreviewed/2022/05/GHSA-xjr4-8c62-v64c/GHSA-xjr4-8c62-v64c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xmc4-vj3p-mc7g/GHSA-xmc4-vj3p-mc7g.json b/advisories/unreviewed/2022/05/GHSA-xmc4-vj3p-mc7g/GHSA-xmc4-vj3p-mc7g.json index a6d3befdb70..f67393191ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-xmc4-vj3p-mc7g/GHSA-xmc4-vj3p-mc7g.json +++ b/advisories/unreviewed/2022/05/GHSA-xmc4-vj3p-mc7g/GHSA-xmc4-vj3p-mc7g.json @@ -7,12 +7,8 @@ "CVE-2010-3272" ], "details": "accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, via a modified (1) Hide_Captcha or (2) quesList parameter in a validateAll action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xp93-22jw-4857/GHSA-xp93-22jw-4857.json b/advisories/unreviewed/2022/05/GHSA-xp93-22jw-4857/GHSA-xp93-22jw-4857.json index 0ed3bfee518..79bae961ba8 100644 --- a/advisories/unreviewed/2022/05/GHSA-xp93-22jw-4857/GHSA-xp93-22jw-4857.json +++ b/advisories/unreviewed/2022/05/GHSA-xp93-22jw-4857/GHSA-xp93-22jw-4857.json @@ -7,12 +7,8 @@ "CVE-2010-1585" ], "details": "The nsIScriptableUnescapeHTML.parseFragment method in the ParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 does not properly sanitize HTML in a chrome document, which makes it easier for remote attackers to execute arbitrary JavaScript with chrome privileges via a javascript: URI in input to an extension, as demonstrated by a javascript:alert sequence in (1) the HREF attribute of an A element or (2) the ACTION attribute of a FORM element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xpfc-5pgf-2vp4/GHSA-xpfc-5pgf-2vp4.json b/advisories/unreviewed/2022/05/GHSA-xpfc-5pgf-2vp4/GHSA-xpfc-5pgf-2vp4.json index ac7ffeaace6..0aeeb3de626 100644 --- a/advisories/unreviewed/2022/05/GHSA-xpfc-5pgf-2vp4/GHSA-xpfc-5pgf-2vp4.json +++ b/advisories/unreviewed/2022/05/GHSA-xpfc-5pgf-2vp4/GHSA-xpfc-5pgf-2vp4.json @@ -7,12 +7,8 @@ "CVE-2015-5457" ], "details": "PivotX before 2.3.11 does not validate the new file extension when renaming a file with multiple extensions, which allows remote attackers to execute arbitrary code by uploading a crafted file, as demonstrated by a file named foo.php.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xq99-f7r4-hp52/GHSA-xq99-f7r4-hp52.json b/advisories/unreviewed/2022/05/GHSA-xq99-f7r4-hp52/GHSA-xq99-f7r4-hp52.json index f4bacb067dc..7de04af895d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xq99-f7r4-hp52/GHSA-xq99-f7r4-hp52.json +++ b/advisories/unreviewed/2022/05/GHSA-xq99-f7r4-hp52/GHSA-xq99-f7r4-hp52.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xqh3-mrp7-2g29/GHSA-xqh3-mrp7-2g29.json b/advisories/unreviewed/2022/05/GHSA-xqh3-mrp7-2g29/GHSA-xqh3-mrp7-2g29.json index c1363a1256c..7bcd0d8eb95 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqh3-mrp7-2g29/GHSA-xqh3-mrp7-2g29.json +++ b/advisories/unreviewed/2022/05/GHSA-xqh3-mrp7-2g29/GHSA-xqh3-mrp7-2g29.json @@ -7,12 +7,8 @@ "CVE-2010-1549" ], "details": "Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xrvh-hj29-j7h9/GHSA-xrvh-hj29-j7h9.json b/advisories/unreviewed/2022/05/GHSA-xrvh-hj29-j7h9/GHSA-xrvh-hj29-j7h9.json index aa3a91cfdb4..58865ad349a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xrvh-hj29-j7h9/GHSA-xrvh-hj29-j7h9.json +++ b/advisories/unreviewed/2022/05/GHSA-xrvh-hj29-j7h9/GHSA-xrvh-hj29-j7h9.json @@ -7,12 +7,8 @@ "CVE-2010-3039" ], "details": "/usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in a request to the administrative interface, aka Bug IDs CSCti52041 and CSCti74930.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xw38-r5v4-92p9/GHSA-xw38-r5v4-92p9.json b/advisories/unreviewed/2022/05/GHSA-xw38-r5v4-92p9/GHSA-xw38-r5v4-92p9.json index 68b52235424..8ee1da16706 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw38-r5v4-92p9/GHSA-xw38-r5v4-92p9.json +++ b/advisories/unreviewed/2022/05/GHSA-xw38-r5v4-92p9/GHSA-xw38-r5v4-92p9.json @@ -7,12 +7,8 @@ "CVE-2010-2668" ], "details": "Unspecified vulnerability in Adaptive Micro Systems ALPHA Ethernet Adapter II Web-Manager 3.40.2 allows remote attackers to bypass authentication and read or write configuration files via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xww5-hh94-wcq9/GHSA-xww5-hh94-wcq9.json b/advisories/unreviewed/2022/05/GHSA-xww5-hh94-wcq9/GHSA-xww5-hh94-wcq9.json index 707e2f05ab0..7fca7f181b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-xww5-hh94-wcq9/GHSA-xww5-hh94-wcq9.json +++ b/advisories/unreviewed/2022/05/GHSA-xww5-hh94-wcq9/GHSA-xww5-hh94-wcq9.json @@ -7,12 +7,8 @@ "CVE-2010-1646" ], "details": "The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -136,9 +132,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/06/GHSA-mvxc-gq7m-366h/GHSA-mvxc-gq7m-366h.json b/advisories/unreviewed/2022/06/GHSA-mvxc-gq7m-366h/GHSA-mvxc-gq7m-366h.json index 069dcf5cd43..342f940a422 100644 --- a/advisories/unreviewed/2022/06/GHSA-mvxc-gq7m-366h/GHSA-mvxc-gq7m-366h.json +++ b/advisories/unreviewed/2022/06/GHSA-mvxc-gq7m-366h/GHSA-mvxc-gq7m-366h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-2mwm-hhv7-v7hx/GHSA-2mwm-hhv7-v7hx.json b/advisories/unreviewed/2022/08/GHSA-2mwm-hhv7-v7hx/GHSA-2mwm-hhv7-v7hx.json index 4a69ff17096..4cfac025ec1 100644 --- a/advisories/unreviewed/2022/08/GHSA-2mwm-hhv7-v7hx/GHSA-2mwm-hhv7-v7hx.json +++ b/advisories/unreviewed/2022/08/GHSA-2mwm-hhv7-v7hx/GHSA-2mwm-hhv7-v7hx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-gmq2-cvj2-8hwx/GHSA-gmq2-cvj2-8hwx.json b/advisories/unreviewed/2022/08/GHSA-gmq2-cvj2-8hwx/GHSA-gmq2-cvj2-8hwx.json index 961e8fcaa56..1d2715444f9 100644 --- a/advisories/unreviewed/2022/08/GHSA-gmq2-cvj2-8hwx/GHSA-gmq2-cvj2-8hwx.json +++ b/advisories/unreviewed/2022/08/GHSA-gmq2-cvj2-8hwx/GHSA-gmq2-cvj2-8hwx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-rr22-pq25-c964/GHSA-rr22-pq25-c964.json b/advisories/unreviewed/2022/08/GHSA-rr22-pq25-c964/GHSA-rr22-pq25-c964.json index b4d8fdb3c97..2b4ff86c388 100644 --- a/advisories/unreviewed/2022/08/GHSA-rr22-pq25-c964/GHSA-rr22-pq25-c964.json +++ b/advisories/unreviewed/2022/08/GHSA-rr22-pq25-c964/GHSA-rr22-pq25-c964.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-85q4-vgvj-3q28/GHSA-85q4-vgvj-3q28.json b/advisories/unreviewed/2022/09/GHSA-85q4-vgvj-3q28/GHSA-85q4-vgvj-3q28.json index 08e5975e92b..64e43770d73 100644 --- a/advisories/unreviewed/2022/09/GHSA-85q4-vgvj-3q28/GHSA-85q4-vgvj-3q28.json +++ b/advisories/unreviewed/2022/09/GHSA-85q4-vgvj-3q28/GHSA-85q4-vgvj-3q28.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-5rf9-q3f5-rc77/GHSA-5rf9-q3f5-rc77.json b/advisories/unreviewed/2022/10/GHSA-5rf9-q3f5-rc77/GHSA-5rf9-q3f5-rc77.json index 7eb7665e501..0c08e20c658 100644 --- a/advisories/unreviewed/2022/10/GHSA-5rf9-q3f5-rc77/GHSA-5rf9-q3f5-rc77.json +++ b/advisories/unreviewed/2022/10/GHSA-5rf9-q3f5-rc77/GHSA-5rf9-q3f5-rc77.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-8whp-gj34-8pwr/GHSA-8whp-gj34-8pwr.json b/advisories/unreviewed/2022/10/GHSA-8whp-gj34-8pwr/GHSA-8whp-gj34-8pwr.json index 7eb62367c95..b145538e86f 100644 --- a/advisories/unreviewed/2022/10/GHSA-8whp-gj34-8pwr/GHSA-8whp-gj34-8pwr.json +++ b/advisories/unreviewed/2022/10/GHSA-8whp-gj34-8pwr/GHSA-8whp-gj34-8pwr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-cqv7-6595-m97v/GHSA-cqv7-6595-m97v.json b/advisories/unreviewed/2022/10/GHSA-cqv7-6595-m97v/GHSA-cqv7-6595-m97v.json index 9621952decc..c8f790c1ff3 100644 --- a/advisories/unreviewed/2022/10/GHSA-cqv7-6595-m97v/GHSA-cqv7-6595-m97v.json +++ b/advisories/unreviewed/2022/10/GHSA-cqv7-6595-m97v/GHSA-cqv7-6595-m97v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-h482-v3jv-v33c/GHSA-h482-v3jv-v33c.json b/advisories/unreviewed/2022/10/GHSA-h482-v3jv-v33c/GHSA-h482-v3jv-v33c.json index 684fda5c7c2..628f855f0bd 100644 --- a/advisories/unreviewed/2022/10/GHSA-h482-v3jv-v33c/GHSA-h482-v3jv-v33c.json +++ b/advisories/unreviewed/2022/10/GHSA-h482-v3jv-v33c/GHSA-h482-v3jv-v33c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-x65r-rvgh-v43v/GHSA-x65r-rvgh-v43v.json b/advisories/unreviewed/2022/10/GHSA-x65r-rvgh-v43v/GHSA-x65r-rvgh-v43v.json index 7a1812b372c..d3b500d613b 100644 --- a/advisories/unreviewed/2022/10/GHSA-x65r-rvgh-v43v/GHSA-x65r-rvgh-v43v.json +++ b/advisories/unreviewed/2022/10/GHSA-x65r-rvgh-v43v/GHSA-x65r-rvgh-v43v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "WEB", diff --git a/advisories/unreviewed/2022/11/GHSA-57jq-6mm4-q8pw/GHSA-57jq-6mm4-q8pw.json b/advisories/unreviewed/2022/11/GHSA-57jq-6mm4-q8pw/GHSA-57jq-6mm4-q8pw.json index 0462c98cdd8..f74655cda27 100644 --- a/advisories/unreviewed/2022/11/GHSA-57jq-6mm4-q8pw/GHSA-57jq-6mm4-q8pw.json +++ b/advisories/unreviewed/2022/11/GHSA-57jq-6mm4-q8pw/GHSA-57jq-6mm4-q8pw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-jpmj-jj69-x4jp/GHSA-jpmj-jj69-x4jp.json b/advisories/unreviewed/2022/11/GHSA-jpmj-jj69-x4jp/GHSA-jpmj-jj69-x4jp.json index ef966e87903..32f319cab9c 100644 --- a/advisories/unreviewed/2022/11/GHSA-jpmj-jj69-x4jp/GHSA-jpmj-jj69-x4jp.json +++ b/advisories/unreviewed/2022/11/GHSA-jpmj-jj69-x4jp/GHSA-jpmj-jj69-x4jp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-mhp9-hc33-rqwj/GHSA-mhp9-hc33-rqwj.json b/advisories/unreviewed/2022/11/GHSA-mhp9-hc33-rqwj/GHSA-mhp9-hc33-rqwj.json index fed0142344e..bb1b213e7e8 100644 --- a/advisories/unreviewed/2022/11/GHSA-mhp9-hc33-rqwj/GHSA-mhp9-hc33-rqwj.json +++ b/advisories/unreviewed/2022/11/GHSA-mhp9-hc33-rqwj/GHSA-mhp9-hc33-rqwj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-34j8-gp4f-rgwg/GHSA-34j8-gp4f-rgwg.json b/advisories/unreviewed/2022/12/GHSA-34j8-gp4f-rgwg/GHSA-34j8-gp4f-rgwg.json index d07cd92061c..79677ac0306 100644 --- a/advisories/unreviewed/2022/12/GHSA-34j8-gp4f-rgwg/GHSA-34j8-gp4f-rgwg.json +++ b/advisories/unreviewed/2022/12/GHSA-34j8-gp4f-rgwg/GHSA-34j8-gp4f-rgwg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-3mmq-4r29-8xqf/GHSA-3mmq-4r29-8xqf.json b/advisories/unreviewed/2022/12/GHSA-3mmq-4r29-8xqf/GHSA-3mmq-4r29-8xqf.json index fa811fa8976..9011173303b 100644 --- a/advisories/unreviewed/2022/12/GHSA-3mmq-4r29-8xqf/GHSA-3mmq-4r29-8xqf.json +++ b/advisories/unreviewed/2022/12/GHSA-3mmq-4r29-8xqf/GHSA-3mmq-4r29-8xqf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -71,9 +69,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-3p9p-h6x6-85gg/GHSA-3p9p-h6x6-85gg.json b/advisories/unreviewed/2022/12/GHSA-3p9p-h6x6-85gg/GHSA-3p9p-h6x6-85gg.json index f846ebaed0b..7890aa48058 100644 --- a/advisories/unreviewed/2022/12/GHSA-3p9p-h6x6-85gg/GHSA-3p9p-h6x6-85gg.json +++ b/advisories/unreviewed/2022/12/GHSA-3p9p-h6x6-85gg/GHSA-3p9p-h6x6-85gg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -75,9 +73,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-66xw-mfrq-qf6g/GHSA-66xw-mfrq-qf6g.json b/advisories/unreviewed/2022/12/GHSA-66xw-mfrq-qf6g/GHSA-66xw-mfrq-qf6g.json index 96cf6e50fe5..c7039949e7d 100644 --- a/advisories/unreviewed/2022/12/GHSA-66xw-mfrq-qf6g/GHSA-66xw-mfrq-qf6g.json +++ b/advisories/unreviewed/2022/12/GHSA-66xw-mfrq-qf6g/GHSA-66xw-mfrq-qf6g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-7vvx-67x5-5jw2/GHSA-7vvx-67x5-5jw2.json b/advisories/unreviewed/2022/12/GHSA-7vvx-67x5-5jw2/GHSA-7vvx-67x5-5jw2.json index a66a5806a4d..7cb03630bb3 100644 --- a/advisories/unreviewed/2022/12/GHSA-7vvx-67x5-5jw2/GHSA-7vvx-67x5-5jw2.json +++ b/advisories/unreviewed/2022/12/GHSA-7vvx-67x5-5jw2/GHSA-7vvx-67x5-5jw2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-9qwf-rgvm-3vxv/GHSA-9qwf-rgvm-3vxv.json b/advisories/unreviewed/2022/12/GHSA-9qwf-rgvm-3vxv/GHSA-9qwf-rgvm-3vxv.json index e478c9a592d..03a1e3ccf40 100644 --- a/advisories/unreviewed/2022/12/GHSA-9qwf-rgvm-3vxv/GHSA-9qwf-rgvm-3vxv.json +++ b/advisories/unreviewed/2022/12/GHSA-9qwf-rgvm-3vxv/GHSA-9qwf-rgvm-3vxv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-gg8p-2j6g-g8mc/GHSA-gg8p-2j6g-g8mc.json b/advisories/unreviewed/2022/12/GHSA-gg8p-2j6g-g8mc/GHSA-gg8p-2j6g-g8mc.json index e07511ff27b..0720587a82e 100644 --- a/advisories/unreviewed/2022/12/GHSA-gg8p-2j6g-g8mc/GHSA-gg8p-2j6g-g8mc.json +++ b/advisories/unreviewed/2022/12/GHSA-gg8p-2j6g-g8mc/GHSA-gg8p-2j6g-g8mc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -75,9 +73,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-hjxr-6xqh-hj22/GHSA-hjxr-6xqh-hj22.json b/advisories/unreviewed/2022/12/GHSA-hjxr-6xqh-hj22/GHSA-hjxr-6xqh-hj22.json index 5ac5ec595dd..db549a36c10 100644 --- a/advisories/unreviewed/2022/12/GHSA-hjxr-6xqh-hj22/GHSA-hjxr-6xqh-hj22.json +++ b/advisories/unreviewed/2022/12/GHSA-hjxr-6xqh-hj22/GHSA-hjxr-6xqh-hj22.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-j7wh-9q3q-qcg6/GHSA-j7wh-9q3q-qcg6.json b/advisories/unreviewed/2022/12/GHSA-j7wh-9q3q-qcg6/GHSA-j7wh-9q3q-qcg6.json index b51fd25c161..56d959a957d 100644 --- a/advisories/unreviewed/2022/12/GHSA-j7wh-9q3q-qcg6/GHSA-j7wh-9q3q-qcg6.json +++ b/advisories/unreviewed/2022/12/GHSA-j7wh-9q3q-qcg6/GHSA-j7wh-9q3q-qcg6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-j94m-6fwj-5pv8/GHSA-j94m-6fwj-5pv8.json b/advisories/unreviewed/2022/12/GHSA-j94m-6fwj-5pv8/GHSA-j94m-6fwj-5pv8.json index e4fbd0af6a2..276701cba93 100644 --- a/advisories/unreviewed/2022/12/GHSA-j94m-6fwj-5pv8/GHSA-j94m-6fwj-5pv8.json +++ b/advisories/unreviewed/2022/12/GHSA-j94m-6fwj-5pv8/GHSA-j94m-6fwj-5pv8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-jhmj-whj3-74pr/GHSA-jhmj-whj3-74pr.json b/advisories/unreviewed/2022/12/GHSA-jhmj-whj3-74pr/GHSA-jhmj-whj3-74pr.json index 8a6f8e4967a..8ede0c7c0f8 100644 --- a/advisories/unreviewed/2022/12/GHSA-jhmj-whj3-74pr/GHSA-jhmj-whj3-74pr.json +++ b/advisories/unreviewed/2022/12/GHSA-jhmj-whj3-74pr/GHSA-jhmj-whj3-74pr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-jm5g-c2v4-w5fp/GHSA-jm5g-c2v4-w5fp.json b/advisories/unreviewed/2022/12/GHSA-jm5g-c2v4-w5fp/GHSA-jm5g-c2v4-w5fp.json index 4e218766c99..11cc5598c55 100644 --- a/advisories/unreviewed/2022/12/GHSA-jm5g-c2v4-w5fp/GHSA-jm5g-c2v4-w5fp.json +++ b/advisories/unreviewed/2022/12/GHSA-jm5g-c2v4-w5fp/GHSA-jm5g-c2v4-w5fp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-p4fx-x9cg-v98g/GHSA-p4fx-x9cg-v98g.json b/advisories/unreviewed/2022/12/GHSA-p4fx-x9cg-v98g/GHSA-p4fx-x9cg-v98g.json index 275827d4746..cecaf339782 100644 --- a/advisories/unreviewed/2022/12/GHSA-p4fx-x9cg-v98g/GHSA-p4fx-x9cg-v98g.json +++ b/advisories/unreviewed/2022/12/GHSA-p4fx-x9cg-v98g/GHSA-p4fx-x9cg-v98g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-q99x-rwh5-433q/GHSA-q99x-rwh5-433q.json b/advisories/unreviewed/2022/12/GHSA-q99x-rwh5-433q/GHSA-q99x-rwh5-433q.json index e1bdc645685..04750984a98 100644 --- a/advisories/unreviewed/2022/12/GHSA-q99x-rwh5-433q/GHSA-q99x-rwh5-433q.json +++ b/advisories/unreviewed/2022/12/GHSA-q99x-rwh5-433q/GHSA-q99x-rwh5-433q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-qh2r-8xvg-hm24/GHSA-qh2r-8xvg-hm24.json b/advisories/unreviewed/2022/12/GHSA-qh2r-8xvg-hm24/GHSA-qh2r-8xvg-hm24.json index bf427624986..2c02c35c2c4 100644 --- a/advisories/unreviewed/2022/12/GHSA-qh2r-8xvg-hm24/GHSA-qh2r-8xvg-hm24.json +++ b/advisories/unreviewed/2022/12/GHSA-qh2r-8xvg-hm24/GHSA-qh2r-8xvg-hm24.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-35c2-3wwv-hfxv/GHSA-35c2-3wwv-hfxv.json b/advisories/unreviewed/2023/01/GHSA-35c2-3wwv-hfxv/GHSA-35c2-3wwv-hfxv.json index 86cd2986d6a..bd69a46cd09 100644 --- a/advisories/unreviewed/2023/01/GHSA-35c2-3wwv-hfxv/GHSA-35c2-3wwv-hfxv.json +++ b/advisories/unreviewed/2023/01/GHSA-35c2-3wwv-hfxv/GHSA-35c2-3wwv-hfxv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-476q-p4g6-6rx2/GHSA-476q-p4g6-6rx2.json b/advisories/unreviewed/2023/01/GHSA-476q-p4g6-6rx2/GHSA-476q-p4g6-6rx2.json index b1e6ae6bb28..309acce3ae4 100644 --- a/advisories/unreviewed/2023/01/GHSA-476q-p4g6-6rx2/GHSA-476q-p4g6-6rx2.json +++ b/advisories/unreviewed/2023/01/GHSA-476q-p4g6-6rx2/GHSA-476q-p4g6-6rx2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-4rq4-8r9h-8884/GHSA-4rq4-8r9h-8884.json b/advisories/unreviewed/2023/01/GHSA-4rq4-8r9h-8884/GHSA-4rq4-8r9h-8884.json index 2d74ca9e985..4307049241d 100644 --- a/advisories/unreviewed/2023/01/GHSA-4rq4-8r9h-8884/GHSA-4rq4-8r9h-8884.json +++ b/advisories/unreviewed/2023/01/GHSA-4rq4-8r9h-8884/GHSA-4rq4-8r9h-8884.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-9447-mqqf-hxwj/GHSA-9447-mqqf-hxwj.json b/advisories/unreviewed/2023/01/GHSA-9447-mqqf-hxwj/GHSA-9447-mqqf-hxwj.json index 89e36bb6443..b8861478f60 100644 --- a/advisories/unreviewed/2023/01/GHSA-9447-mqqf-hxwj/GHSA-9447-mqqf-hxwj.json +++ b/advisories/unreviewed/2023/01/GHSA-9447-mqqf-hxwj/GHSA-9447-mqqf-hxwj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-97q8-3wfg-pv8m/GHSA-97q8-3wfg-pv8m.json b/advisories/unreviewed/2023/01/GHSA-97q8-3wfg-pv8m/GHSA-97q8-3wfg-pv8m.json index bd58d89ea54..27812ad30c0 100644 --- a/advisories/unreviewed/2023/01/GHSA-97q8-3wfg-pv8m/GHSA-97q8-3wfg-pv8m.json +++ b/advisories/unreviewed/2023/01/GHSA-97q8-3wfg-pv8m/GHSA-97q8-3wfg-pv8m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-chmh-mcvp-rwfv/GHSA-chmh-mcvp-rwfv.json b/advisories/unreviewed/2023/01/GHSA-chmh-mcvp-rwfv/GHSA-chmh-mcvp-rwfv.json index aa22a09f3da..e22b6931768 100644 --- a/advisories/unreviewed/2023/01/GHSA-chmh-mcvp-rwfv/GHSA-chmh-mcvp-rwfv.json +++ b/advisories/unreviewed/2023/01/GHSA-chmh-mcvp-rwfv/GHSA-chmh-mcvp-rwfv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-fh83-fh6p-94qw/GHSA-fh83-fh6p-94qw.json b/advisories/unreviewed/2023/01/GHSA-fh83-fh6p-94qw/GHSA-fh83-fh6p-94qw.json index 00e0115803f..82f84760f41 100644 --- a/advisories/unreviewed/2023/01/GHSA-fh83-fh6p-94qw/GHSA-fh83-fh6p-94qw.json +++ b/advisories/unreviewed/2023/01/GHSA-fh83-fh6p-94qw/GHSA-fh83-fh6p-94qw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-frmg-377c-8r42/GHSA-frmg-377c-8r42.json b/advisories/unreviewed/2023/01/GHSA-frmg-377c-8r42/GHSA-frmg-377c-8r42.json index 2904fdff013..a505351d115 100644 --- a/advisories/unreviewed/2023/01/GHSA-frmg-377c-8r42/GHSA-frmg-377c-8r42.json +++ b/advisories/unreviewed/2023/01/GHSA-frmg-377c-8r42/GHSA-frmg-377c-8r42.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-gqq3-j944-f364/GHSA-gqq3-j944-f364.json b/advisories/unreviewed/2023/01/GHSA-gqq3-j944-f364/GHSA-gqq3-j944-f364.json index 11fe3bb1ce1..db741ec47c0 100644 --- a/advisories/unreviewed/2023/01/GHSA-gqq3-j944-f364/GHSA-gqq3-j944-f364.json +++ b/advisories/unreviewed/2023/01/GHSA-gqq3-j944-f364/GHSA-gqq3-j944-f364.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-gr7w-282r-wq4h/GHSA-gr7w-282r-wq4h.json b/advisories/unreviewed/2023/01/GHSA-gr7w-282r-wq4h/GHSA-gr7w-282r-wq4h.json index a2214759f36..c6d427568be 100644 --- a/advisories/unreviewed/2023/01/GHSA-gr7w-282r-wq4h/GHSA-gr7w-282r-wq4h.json +++ b/advisories/unreviewed/2023/01/GHSA-gr7w-282r-wq4h/GHSA-gr7w-282r-wq4h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-gx2w-5rxr-3xm3/GHSA-gx2w-5rxr-3xm3.json b/advisories/unreviewed/2023/01/GHSA-gx2w-5rxr-3xm3/GHSA-gx2w-5rxr-3xm3.json index 0522a3d492a..5b136960d1a 100644 --- a/advisories/unreviewed/2023/01/GHSA-gx2w-5rxr-3xm3/GHSA-gx2w-5rxr-3xm3.json +++ b/advisories/unreviewed/2023/01/GHSA-gx2w-5rxr-3xm3/GHSA-gx2w-5rxr-3xm3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-h2c6-38hv-3jwx/GHSA-h2c6-38hv-3jwx.json b/advisories/unreviewed/2023/01/GHSA-h2c6-38hv-3jwx/GHSA-h2c6-38hv-3jwx.json index f09cbea5524..75e277e5483 100644 --- a/advisories/unreviewed/2023/01/GHSA-h2c6-38hv-3jwx/GHSA-h2c6-38hv-3jwx.json +++ b/advisories/unreviewed/2023/01/GHSA-h2c6-38hv-3jwx/GHSA-h2c6-38hv-3jwx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-hp3q-747r-8rpp/GHSA-hp3q-747r-8rpp.json b/advisories/unreviewed/2023/01/GHSA-hp3q-747r-8rpp/GHSA-hp3q-747r-8rpp.json index f0051053986..14eb5c3f9fd 100644 --- a/advisories/unreviewed/2023/01/GHSA-hp3q-747r-8rpp/GHSA-hp3q-747r-8rpp.json +++ b/advisories/unreviewed/2023/01/GHSA-hp3q-747r-8rpp/GHSA-hp3q-747r-8rpp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-r3f8-wm7p-pf3g/GHSA-r3f8-wm7p-pf3g.json b/advisories/unreviewed/2023/01/GHSA-r3f8-wm7p-pf3g/GHSA-r3f8-wm7p-pf3g.json index c3fb9a72da6..d3ea86a677f 100644 --- a/advisories/unreviewed/2023/01/GHSA-r3f8-wm7p-pf3g/GHSA-r3f8-wm7p-pf3g.json +++ b/advisories/unreviewed/2023/01/GHSA-r3f8-wm7p-pf3g/GHSA-r3f8-wm7p-pf3g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-r3mf-hxp8-46h8/GHSA-r3mf-hxp8-46h8.json b/advisories/unreviewed/2023/01/GHSA-r3mf-hxp8-46h8/GHSA-r3mf-hxp8-46h8.json index 8db22a4f4f2..156e105815d 100644 --- a/advisories/unreviewed/2023/01/GHSA-r3mf-hxp8-46h8/GHSA-r3mf-hxp8-46h8.json +++ b/advisories/unreviewed/2023/01/GHSA-r3mf-hxp8-46h8/GHSA-r3mf-hxp8-46h8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-rh8m-jh32-vpcr/GHSA-rh8m-jh32-vpcr.json b/advisories/unreviewed/2023/01/GHSA-rh8m-jh32-vpcr/GHSA-rh8m-jh32-vpcr.json index aa04348af49..0af48aef63d 100644 --- a/advisories/unreviewed/2023/01/GHSA-rh8m-jh32-vpcr/GHSA-rh8m-jh32-vpcr.json +++ b/advisories/unreviewed/2023/01/GHSA-rh8m-jh32-vpcr/GHSA-rh8m-jh32-vpcr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-25pf-crf2-9cqg/GHSA-25pf-crf2-9cqg.json b/advisories/unreviewed/2024/04/GHSA-25pf-crf2-9cqg/GHSA-25pf-crf2-9cqg.json index 0945bc05282..ac22347967d 100644 --- a/advisories/unreviewed/2024/04/GHSA-25pf-crf2-9cqg/GHSA-25pf-crf2-9cqg.json +++ b/advisories/unreviewed/2024/04/GHSA-25pf-crf2-9cqg/GHSA-25pf-crf2-9cqg.json @@ -7,12 +7,8 @@ "CVE-2024-26699" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix array-index-out-of-bounds in dcn35_clkmgr\n\n[Why]\nThere is a potential memory access violation while\niterating through array of dcn35 clks.\n\n[How]\nLimit iteration per array size.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2g7p-7mvp-pw7m/GHSA-2g7p-7mvp-pw7m.json b/advisories/unreviewed/2024/04/GHSA-2g7p-7mvp-pw7m/GHSA-2g7p-7mvp-pw7m.json index cee08aa2178..a000c86912c 100644 --- a/advisories/unreviewed/2024/04/GHSA-2g7p-7mvp-pw7m/GHSA-2g7p-7mvp-pw7m.json +++ b/advisories/unreviewed/2024/04/GHSA-2g7p-7mvp-pw7m/GHSA-2g7p-7mvp-pw7m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-4fj7-85cf-9m8p/GHSA-4fj7-85cf-9m8p.json b/advisories/unreviewed/2024/04/GHSA-4fj7-85cf-9m8p/GHSA-4fj7-85cf-9m8p.json index d5837d73418..9d658c3d41d 100644 --- a/advisories/unreviewed/2024/04/GHSA-4fj7-85cf-9m8p/GHSA-4fj7-85cf-9m8p.json +++ b/advisories/unreviewed/2024/04/GHSA-4fj7-85cf-9m8p/GHSA-4fj7-85cf-9m8p.json @@ -7,12 +7,8 @@ "CVE-2024-26706" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nparisc: Fix random data corruption from exception handler\n\nThe current exception handler implementation, which assists when accessing\nuser space memory, may exhibit random data corruption if the compiler decides\nto use a different register than the specified register %r29 (defined in\nASM_EXCEPTIONTABLE_REG) for the error code. If the compiler choose another\nregister, the fault handler will nevertheless store -EFAULT into %r29 and thus\ntrash whatever this register is used for.\nLooking at the assembly I found that this happens sometimes in emulate_ldd().\n\nTo solve the issue, the easiest solution would be if it somehow is\npossible to tell the fault handler which register is used to hold the error\ncode. Using %0 or %1 in the inline assembly is not posssible as it will show\nup as e.g. %r29 (with the \"%r\" prefix), which the GNU assembler can not\nconvert to an integer.\n\nThis patch takes another, better and more flexible approach:\nWe extend the __ex_table (which is out of the execution path) by one 32-word.\nIn this word we tell the compiler to insert the assembler instruction\n\"or %r0,%r0,%reg\", where %reg references the register which the compiler\nchoosed for the error return code.\nIn case of an access failure, the fault handler finds the __ex_table entry and\ncan examine the opcode. The used register is encoded in the lowest 5 bits, and\nthe fault handler can then store -EFAULT into this register.\n\nSince we extend the __ex_table to 3 words we can't use the BUILDTIME_TABLE_SORT\nconfig option any longer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5fg3-793p-9qxp/GHSA-5fg3-793p-9qxp.json b/advisories/unreviewed/2024/04/GHSA-5fg3-793p-9qxp/GHSA-5fg3-793p-9qxp.json index 34afe3ab734..8ae14e198ee 100644 --- a/advisories/unreviewed/2024/04/GHSA-5fg3-793p-9qxp/GHSA-5fg3-793p-9qxp.json +++ b/advisories/unreviewed/2024/04/GHSA-5fg3-793p-9qxp/GHSA-5fg3-793p-9qxp.json @@ -7,12 +7,8 @@ "CVE-2024-30571" ], "details": "An information leak in the BRS_top.html component of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-6x84-2fmj-5fc8/GHSA-6x84-2fmj-5fc8.json b/advisories/unreviewed/2024/04/GHSA-6x84-2fmj-5fc8/GHSA-6x84-2fmj-5fc8.json index 248bf7af492..ec4565c33ea 100644 --- a/advisories/unreviewed/2024/04/GHSA-6x84-2fmj-5fc8/GHSA-6x84-2fmj-5fc8.json +++ b/advisories/unreviewed/2024/04/GHSA-6x84-2fmj-5fc8/GHSA-6x84-2fmj-5fc8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-7pq6-8v5c-6wmr/GHSA-7pq6-8v5c-6wmr.json b/advisories/unreviewed/2024/04/GHSA-7pq6-8v5c-6wmr/GHSA-7pq6-8v5c-6wmr.json index 2cc75e01390..f77934a79b9 100644 --- a/advisories/unreviewed/2024/04/GHSA-7pq6-8v5c-6wmr/GHSA-7pq6-8v5c-6wmr.json +++ b/advisories/unreviewed/2024/04/GHSA-7pq6-8v5c-6wmr/GHSA-7pq6-8v5c-6wmr.json @@ -7,12 +7,8 @@ "CVE-2024-26653" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: misc: ljca: Fix double free in error handling path\n\nWhen auxiliary_device_add() returns error and then calls\nauxiliary_device_uninit(), callback function ljca_auxdev_release\ncalls kfree(auxdev->dev.platform_data) to free the parameter data\nof the function ljca_new_client_device. The callers of\nljca_new_client_device shouldn't call kfree() again\nin the error handling path to free the platform data.\n\nFix this by cleaning up the redundant kfree() in all callers and\nadding kfree() the passed in platform_data on errors which happen\nbefore auxiliary_device_init() succeeds .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-7r36-7f54-54ff/GHSA-7r36-7f54-54ff.json b/advisories/unreviewed/2024/04/GHSA-7r36-7f54-54ff/GHSA-7r36-7f54-54ff.json index 920fb4e7989..f590195e2aa 100644 --- a/advisories/unreviewed/2024/04/GHSA-7r36-7f54-54ff/GHSA-7r36-7f54-54ff.json +++ b/advisories/unreviewed/2024/04/GHSA-7r36-7f54-54ff/GHSA-7r36-7f54-54ff.json @@ -7,12 +7,8 @@ "CVE-2024-30572" ], "details": "Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-94xq-wrrp-5jr6/GHSA-94xq-wrrp-5jr6.json b/advisories/unreviewed/2024/04/GHSA-94xq-wrrp-5jr6/GHSA-94xq-wrrp-5jr6.json index c718838b240..c15c41f66c3 100644 --- a/advisories/unreviewed/2024/04/GHSA-94xq-wrrp-5jr6/GHSA-94xq-wrrp-5jr6.json +++ b/advisories/unreviewed/2024/04/GHSA-94xq-wrrp-5jr6/GHSA-94xq-wrrp-5jr6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-9rrq-j2f6-qpvg/GHSA-9rrq-j2f6-qpvg.json b/advisories/unreviewed/2024/04/GHSA-9rrq-j2f6-qpvg/GHSA-9rrq-j2f6-qpvg.json index 3c2cd5ae6d0..5b151f5ec3e 100644 --- a/advisories/unreviewed/2024/04/GHSA-9rrq-j2f6-qpvg/GHSA-9rrq-j2f6-qpvg.json +++ b/advisories/unreviewed/2024/04/GHSA-9rrq-j2f6-qpvg/GHSA-9rrq-j2f6-qpvg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-cmmv-w3j8-5hm4/GHSA-cmmv-w3j8-5hm4.json b/advisories/unreviewed/2024/04/GHSA-cmmv-w3j8-5hm4/GHSA-cmmv-w3j8-5hm4.json index 293c06e923c..112b99e6b73 100644 --- a/advisories/unreviewed/2024/04/GHSA-cmmv-w3j8-5hm4/GHSA-cmmv-w3j8-5hm4.json +++ b/advisories/unreviewed/2024/04/GHSA-cmmv-w3j8-5hm4/GHSA-cmmv-w3j8-5hm4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-cmxf-xmv7-xjq8/GHSA-cmxf-xmv7-xjq8.json b/advisories/unreviewed/2024/04/GHSA-cmxf-xmv7-xjq8/GHSA-cmxf-xmv7-xjq8.json index c98c25a8099..c5a75fec52c 100644 --- a/advisories/unreviewed/2024/04/GHSA-cmxf-xmv7-xjq8/GHSA-cmxf-xmv7-xjq8.json +++ b/advisories/unreviewed/2024/04/GHSA-cmxf-xmv7-xjq8/GHSA-cmxf-xmv7-xjq8.json @@ -7,12 +7,8 @@ "CVE-2024-26656" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix use-after-free bug\n\nThe bug can be triggered by sending a single amdgpu_gem_userptr_ioctl\nto the AMDGPU DRM driver on any ASICs with an invalid address and size.\nThe bug was reported by Joonkyo Jung .\nFor example the following code:\n\nstatic void Syzkaller1(int fd)\n{\n\tstruct drm_amdgpu_gem_userptr arg;\n\tint ret;\n\n\targ.addr = 0xffffffffffff0000;\n\targ.size = 0x80000000; /*2 Gb*/\n\targ.flags = 0x7;\n\tret = drmIoctl(fd, 0xc1186451/*amdgpu_gem_userptr_ioctl*/, &arg);\n}\n\nDue to the address and size are not valid there is a failure in\namdgpu_hmm_register->mmu_interval_notifier_insert->__mmu_interval_notifier_insert->\ncheck_shl_overflow, but we even the amdgpu_hmm_register failure we still call\namdgpu_hmm_unregister into amdgpu_gem_object_free which causes access to a bad address.\nThe following stack is below when the issue is reproduced when Kazan is enabled:\n\n[ +0.000014] Hardware name: ASUS System Product Name/ROG STRIX B550-F GAMING (WI-FI), BIOS 1401 12/03/2020\n[ +0.000009] RIP: 0010:mmu_interval_notifier_remove+0x327/0x340\n[ +0.000017] Code: ff ff 49 89 44 24 08 48 b8 00 01 00 00 00 00 ad de 4c 89 f7 49 89 47 40 48 83 c0 22 49 89 47 48 e8 ce d1 2d 01 e9 32 ff ff ff <0f> 0b e9 16 ff ff ff 4c 89 ef e8 fa 14 b3 ff e9 36 ff ff ff e8 80\n[ +0.000014] RSP: 0018:ffffc90002657988 EFLAGS: 00010246\n[ +0.000013] RAX: 0000000000000000 RBX: 1ffff920004caf35 RCX: ffffffff8160565b\n[ +0.000011] RDX: dffffc0000000000 RSI: 0000000000000004 RDI: ffff8881a9f78260\n[ +0.000010] RBP: ffffc90002657a70 R08: 0000000000000001 R09: fffff520004caf25\n[ +0.000010] R10: 0000000000000003 R11: ffffffff8161d1d6 R12: ffff88810e988c00\n[ +0.000010] R13: ffff888126fb5a00 R14: ffff88810e988c0c R15: ffff8881a9f78260\n[ +0.000011] FS: 00007ff9ec848540(0000) GS:ffff8883cc880000(0000) knlGS:0000000000000000\n[ +0.000012] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ +0.000010] CR2: 000055b3f7e14328 CR3: 00000001b5770000 CR4: 0000000000350ef0\n[ +0.000010] Call Trace:\n[ +0.000006] \n[ +0.000007] ? show_regs+0x6a/0x80\n[ +0.000018] ? __warn+0xa5/0x1b0\n[ +0.000019] ? mmu_interval_notifier_remove+0x327/0x340\n[ +0.000018] ? report_bug+0x24a/0x290\n[ +0.000022] ? handle_bug+0x46/0x90\n[ +0.000015] ? exc_invalid_op+0x19/0x50\n[ +0.000016] ? asm_exc_invalid_op+0x1b/0x20\n[ +0.000017] ? kasan_save_stack+0x26/0x50\n[ +0.000017] ? mmu_interval_notifier_remove+0x23b/0x340\n[ +0.000019] ? mmu_interval_notifier_remove+0x327/0x340\n[ +0.000019] ? mmu_interval_notifier_remove+0x23b/0x340\n[ +0.000020] ? __pfx_mmu_interval_notifier_remove+0x10/0x10\n[ +0.000017] ? kasan_save_alloc_info+0x1e/0x30\n[ +0.000018] ? srso_return_thunk+0x5/0x5f\n[ +0.000014] ? __kasan_kmalloc+0xb1/0xc0\n[ +0.000018] ? srso_return_thunk+0x5/0x5f\n[ +0.000013] ? __kasan_check_read+0x11/0x20\n[ +0.000020] amdgpu_hmm_unregister+0x34/0x50 [amdgpu]\n[ +0.004695] amdgpu_gem_object_free+0x66/0xa0 [amdgpu]\n[ +0.004534] ? __pfx_amdgpu_gem_object_free+0x10/0x10 [amdgpu]\n[ +0.004291] ? do_syscall_64+0x5f/0xe0\n[ +0.000023] ? srso_return_thunk+0x5/0x5f\n[ +0.000017] drm_gem_object_free+0x3b/0x50 [drm]\n[ +0.000489] amdgpu_gem_userptr_ioctl+0x306/0x500 [amdgpu]\n[ +0.004295] ? __pfx_amdgpu_gem_userptr_ioctl+0x10/0x10 [amdgpu]\n[ +0.004270] ? srso_return_thunk+0x5/0x5f\n[ +0.000014] ? __this_cpu_preempt_check+0x13/0x20\n[ +0.000015] ? srso_return_thunk+0x5/0x5f\n[ +0.000013] ? sysvec_apic_timer_interrupt+0x57/0xc0\n[ +0.000020] ? srso_return_thunk+0x5/0x5f\n[ +0.000014] ? asm_sysvec_apic_timer_interrupt+0x1b/0x20\n[ +0.000022] ? drm_ioctl_kernel+0x17b/0x1f0 [drm]\n[ +0.000496] ? __pfx_amdgpu_gem_userptr_ioctl+0x10/0x10 [amdgpu]\n[ +0.004272] ? drm_ioctl_kernel+0x190/0x1f0 [drm]\n[ +0.000492] drm_ioctl_kernel+0x140/0x1f0 [drm]\n[ +0.000497] ? __pfx_amdgpu_gem_userptr_ioctl+0x10/0x10 [amdgpu]\n[ +0.004297] ? __pfx_drm_ioctl_kernel+0x10/0x10 [d\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-fr3q-v98q-fwq5/GHSA-fr3q-v98q-fwq5.json b/advisories/unreviewed/2024/04/GHSA-fr3q-v98q-fwq5/GHSA-fr3q-v98q-fwq5.json index 3d6f2bc7e81..e15d8438c0b 100644 --- a/advisories/unreviewed/2024/04/GHSA-fr3q-v98q-fwq5/GHSA-fr3q-v98q-fwq5.json +++ b/advisories/unreviewed/2024/04/GHSA-fr3q-v98q-fwq5/GHSA-fr3q-v98q-fwq5.json @@ -7,12 +7,8 @@ "CVE-2024-26657" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/sched: fix null-ptr-deref in init entity\n\nThe bug can be triggered by sending an amdgpu_cs_wait_ioctl\nto the AMDGPU DRM driver on any ASICs with valid context.\nThe bug was reported by Joonkyo Jung .\nFor example the following code:\n\n static void Syzkaller2(int fd)\n {\n\tunion drm_amdgpu_ctx arg1;\n\tunion drm_amdgpu_wait_cs arg2;\n\n\targ1.in.op = AMDGPU_CTX_OP_ALLOC_CTX;\n\tret = drmIoctl(fd, 0x140106442 /* amdgpu_ctx_ioctl */, &arg1);\n\n\targ2.in.handle = 0x0;\n\targ2.in.timeout = 0x2000000000000;\n\targ2.in.ip_type = AMD_IP_VPE /* 0x9 */;\n\targ2->in.ip_instance = 0x0;\n\targ2.in.ring = 0x0;\n\targ2.in.ctx_id = arg1.out.alloc.ctx_id;\n\n\tdrmIoctl(fd, 0xc0206449 /* AMDGPU_WAIT_CS * /, &arg2);\n }\n\nThe ioctl AMDGPU_WAIT_CS without previously submitted job could be assumed that\nthe error should be returned, but the following commit 1decbf6bb0b4dc56c9da6c5e57b994ebfc2be3aa\nmodified the logic and allowed to have sched_rq equal to NULL.\n\nAs a result when there is no job the ioctl AMDGPU_WAIT_CS returns success.\nThe change fixes null-ptr-deref in init entity and the stack below demonstrates\nthe error condition:\n\n[ +0.000007] BUG: kernel NULL pointer dereference, address: 0000000000000028\n[ +0.007086] #PF: supervisor read access in kernel mode\n[ +0.005234] #PF: error_code(0x0000) - not-present page\n[ +0.005232] PGD 0 P4D 0\n[ +0.002501] Oops: 0000 [#1] PREEMPT SMP KASAN NOPTI\n[ +0.005034] CPU: 10 PID: 9229 Comm: amd_basic Tainted: G B W L 6.7.0+ #4\n[ +0.007797] Hardware name: ASUS System Product Name/ROG STRIX B550-F GAMING (WI-FI), BIOS 1401 12/03/2020\n[ +0.009798] RIP: 0010:drm_sched_entity_init+0x2d3/0x420 [gpu_sched]\n[ +0.006426] Code: 80 00 00 00 00 00 00 00 e8 1a 81 82 e0 49 89 9c 24 c0 00 00 00 4c 89 ef e8 4a 80 82 e0 49 8b 5d 00 48 8d 7b 28 e8 3d 80 82 e0 <48> 83 7b 28 00 0f 84 28 01 00 00 4d 8d ac 24 98 00 00 00 49 8d 5c\n[ +0.019094] RSP: 0018:ffffc90014c1fa40 EFLAGS: 00010282\n[ +0.005237] RAX: 0000000000000001 RBX: 0000000000000000 RCX: ffffffff8113f3fa\n[ +0.007326] RDX: fffffbfff0a7889d RSI: 0000000000000008 RDI: ffffffff853c44e0\n[ +0.007264] RBP: ffffc90014c1fa80 R08: 0000000000000001 R09: fffffbfff0a7889c\n[ +0.007266] R10: ffffffff853c44e7 R11: 0000000000000001 R12: ffff8881a719b010\n[ +0.007263] R13: ffff88810d412748 R14: 0000000000000002 R15: 0000000000000000\n[ +0.007264] FS: 00007ffff7045540(0000) GS:ffff8883cc900000(0000) knlGS:0000000000000000\n[ +0.008236] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ +0.005851] CR2: 0000000000000028 CR3: 000000011912e000 CR4: 0000000000350ef0\n[ +0.007175] Call Trace:\n[ +0.002561] \n[ +0.002141] ? show_regs+0x6a/0x80\n[ +0.003473] ? __die+0x25/0x70\n[ +0.003124] ? page_fault_oops+0x214/0x720\n[ +0.004179] ? preempt_count_sub+0x18/0xc0\n[ +0.004093] ? __pfx_page_fault_oops+0x10/0x10\n[ +0.004590] ? srso_return_thunk+0x5/0x5f\n[ +0.004000] ? vprintk_default+0x1d/0x30\n[ +0.004063] ? srso_return_thunk+0x5/0x5f\n[ +0.004087] ? vprintk+0x5c/0x90\n[ +0.003296] ? drm_sched_entity_init+0x2d3/0x420 [gpu_sched]\n[ +0.005807] ? srso_return_thunk+0x5/0x5f\n[ +0.004090] ? _printk+0xb3/0xe0\n[ +0.003293] ? __pfx__printk+0x10/0x10\n[ +0.003735] ? asm_sysvec_apic_timer_interrupt+0x1b/0x20\n[ +0.005482] ? do_user_addr_fault+0x345/0x770\n[ +0.004361] ? exc_page_fault+0x64/0xf0\n[ +0.003972] ? asm_exc_page_fault+0x27/0x30\n[ +0.004271] ? add_taint+0x2a/0xa0\n[ +0.003476] ? drm_sched_entity_init+0x2d3/0x420 [gpu_sched]\n[ +0.005812] amdgpu_ctx_get_entity+0x3f9/0x770 [amdgpu]\n[ +0.009530] ? finish_task_switch.isra.0+0x129/0x470\n[ +0.005068] ? __pfx_amdgpu_ctx_get_entity+0x10/0x10 [amdgpu]\n[ +0.010063] ? __kasan_check_write+0x14/0x20\n[ +0.004356] ? srso_return_thunk+0x5/0x5f\n[ +0.004001] ? mutex_unlock+0x81/0xd0\n[ +0.003802] ? srso_return_thunk+0x5/0x5f\n[ +0.004096] amdgpu_cs_wait_ioctl+0xf6/0x270 [amdgpu]\n[ +0.009355] ? __pfx_\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-gw4j-wq88-96mq/GHSA-gw4j-wq88-96mq.json b/advisories/unreviewed/2024/04/GHSA-gw4j-wq88-96mq/GHSA-gw4j-wq88-96mq.json index 756ccd3eec8..53071ad3f1c 100644 --- a/advisories/unreviewed/2024/04/GHSA-gw4j-wq88-96mq/GHSA-gw4j-wq88-96mq.json +++ b/advisories/unreviewed/2024/04/GHSA-gw4j-wq88-96mq/GHSA-gw4j-wq88-96mq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-h7gp-37f7-qxv5/GHSA-h7gp-37f7-qxv5.json b/advisories/unreviewed/2024/04/GHSA-h7gp-37f7-qxv5/GHSA-h7gp-37f7-qxv5.json index 46bb79769a2..ac59365d28f 100644 --- a/advisories/unreviewed/2024/04/GHSA-h7gp-37f7-qxv5/GHSA-h7gp-37f7-qxv5.json +++ b/advisories/unreviewed/2024/04/GHSA-h7gp-37f7-qxv5/GHSA-h7gp-37f7-qxv5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-m586-22m6-88g8/GHSA-m586-22m6-88g8.json b/advisories/unreviewed/2024/04/GHSA-m586-22m6-88g8/GHSA-m586-22m6-88g8.json index 6ca55770b7f..faa79f0d588 100644 --- a/advisories/unreviewed/2024/04/GHSA-m586-22m6-88g8/GHSA-m586-22m6-88g8.json +++ b/advisories/unreviewed/2024/04/GHSA-m586-22m6-88g8/GHSA-m586-22m6-88g8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-mccq-9gc6-hm85/GHSA-mccq-9gc6-hm85.json b/advisories/unreviewed/2024/04/GHSA-mccq-9gc6-hm85/GHSA-mccq-9gc6-hm85.json index 0468ed04dfd..4b501720c18 100644 --- a/advisories/unreviewed/2024/04/GHSA-mccq-9gc6-hm85/GHSA-mccq-9gc6-hm85.json +++ b/advisories/unreviewed/2024/04/GHSA-mccq-9gc6-hm85/GHSA-mccq-9gc6-hm85.json @@ -7,12 +7,8 @@ "CVE-2024-26703" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/timerlat: Move hrtimer_init to timerlat_fd open()\n\nCurrently, the timerlat's hrtimer is initialized at the first read of\ntimerlat_fd, and destroyed at close(). It works, but it causes an error\nif the user program open() and close() the file without reading.\n\nHere's an example:\n\n # echo NO_OSNOISE_WORKLOAD > /sys/kernel/debug/tracing/osnoise/options\n # echo timerlat > /sys/kernel/debug/tracing/current_tracer\n\n # cat < ./timerlat_load.py\n # !/usr/bin/env python3\n\n timerlat_fd = open(\"/sys/kernel/tracing/osnoise/per_cpu/cpu0/timerlat_fd\", 'r')\n timerlat_fd.close();\n EOF\n\n # ./taskset -c 0 ./timerlat_load.py\n\n\n BUG: kernel NULL pointer dereference, address: 0000000000000010\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 1 PID: 2673 Comm: python3 Not tainted 6.6.13-200.fc39.x86_64 #1\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-1.fc39 04/01/2014\n RIP: 0010:hrtimer_active+0xd/0x50\n Code: 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 0f 1f 44 00 00 48 8b 57 30 <8b> 42 10 a8 01 74 09 f3 90 8b 42 10 a8 01 75 f7 80 7f 38 00 75 1d\n RSP: 0018:ffffb031009b7e10 EFLAGS: 00010286\n RAX: 000000000002db00 RBX: ffff9118f786db08 RCX: 0000000000000000\n RDX: 0000000000000000 RSI: ffff9117a0e64400 RDI: ffff9118f786db08\n RBP: ffff9118f786db80 R08: ffff9117a0ddd420 R09: ffff9117804d4f70\n R10: 0000000000000000 R11: 0000000000000000 R12: ffff9118f786db08\n R13: ffff91178fdd5e20 R14: ffff9117840978c0 R15: 0000000000000000\n FS: 00007f2ffbab1740(0000) GS:ffff9118f7840000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000010 CR3: 00000001b402e000 CR4: 0000000000750ee0\n PKRU: 55555554\n Call Trace:\n \n ? __die+0x23/0x70\n ? page_fault_oops+0x171/0x4e0\n ? srso_alias_return_thunk+0x5/0x7f\n ? avc_has_extended_perms+0x237/0x520\n ? exc_page_fault+0x7f/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? hrtimer_active+0xd/0x50\n hrtimer_cancel+0x15/0x40\n timerlat_fd_release+0x48/0xe0\n __fput+0xf5/0x290\n __x64_sys_close+0x3d/0x80\n do_syscall_64+0x60/0x90\n ? srso_alias_return_thunk+0x5/0x7f\n ? __x64_sys_ioctl+0x72/0xd0\n ? srso_alias_return_thunk+0x5/0x7f\n ? syscall_exit_to_user_mode+0x2b/0x40\n ? srso_alias_return_thunk+0x5/0x7f\n ? do_syscall_64+0x6c/0x90\n ? srso_alias_return_thunk+0x5/0x7f\n ? exit_to_user_mode_prepare+0x142/0x1f0\n ? srso_alias_return_thunk+0x5/0x7f\n ? syscall_exit_to_user_mode+0x2b/0x40\n ? srso_alias_return_thunk+0x5/0x7f\n ? do_syscall_64+0x6c/0x90\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n RIP: 0033:0x7f2ffb321594\n Code: 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 80 3d d5 cd 0d 00 00 74 13 b8 03 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 3c c3 0f 1f 00 55 48 89 e5 48 83 ec 10 89 7d\n RSP: 002b:00007ffe8d8eef18 EFLAGS: 00000202 ORIG_RAX: 0000000000000003\n RAX: ffffffffffffffda RBX: 00007f2ffba4e668 RCX: 00007f2ffb321594\n RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000003\n RBP: 00007ffe8d8eef40 R08: 0000000000000000 R09: 0000000000000000\n R10: 55c926e3167eae79 R11: 0000000000000202 R12: 0000000000000003\n R13: 00007ffe8d8ef030 R14: 0000000000000000 R15: 00007f2ffba4e668\n \n CR2: 0000000000000010\n ---[ end trace 0000000000000000 ]---\n\nMove hrtimer_init to timerlat_fd open() to avoid this problem.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-mf4j-qfjr-8mhr/GHSA-mf4j-qfjr-8mhr.json b/advisories/unreviewed/2024/04/GHSA-mf4j-qfjr-8mhr/GHSA-mf4j-qfjr-8mhr.json index 2ddf7d6f1da..9bbb3cca439 100644 --- a/advisories/unreviewed/2024/04/GHSA-mf4j-qfjr-8mhr/GHSA-mf4j-qfjr-8mhr.json +++ b/advisories/unreviewed/2024/04/GHSA-mf4j-qfjr-8mhr/GHSA-mf4j-qfjr-8mhr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-mq9q-ghqw-348q/GHSA-mq9q-ghqw-348q.json b/advisories/unreviewed/2024/04/GHSA-mq9q-ghqw-348q/GHSA-mq9q-ghqw-348q.json index fc92e6ef17e..13ec33f3b19 100644 --- a/advisories/unreviewed/2024/04/GHSA-mq9q-ghqw-348q/GHSA-mq9q-ghqw-348q.json +++ b/advisories/unreviewed/2024/04/GHSA-mq9q-ghqw-348q/GHSA-mq9q-ghqw-348q.json @@ -7,12 +7,8 @@ "CVE-2024-26709" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/iommu: Fix the missing iommu_group_put() during platform domain attach\n\nThe function spapr_tce_platform_iommu_attach_dev() is missing to call\niommu_group_put() when the domain is already set. This refcount leak\nshows up with BUG_ON() during DLPAR remove operation as:\n\n KernelBug: Kernel bug in state 'None': kernel BUG at arch/powerpc/platforms/pseries/iommu.c:100!\n Oops: Exception in kernel mode, sig: 5 [#1]\n LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=8192 NUMA pSeries\n \n Hardware name: IBM,9080-HEX POWER10 (raw) 0x800200 0xf000006 of:IBM,FW1060.00 (NH1060_016) hv:phyp pSeries\n NIP: c0000000000ff4d4 LR: c0000000000ff4cc CTR: 0000000000000000\n REGS: c0000013aed5f840 TRAP: 0700 Tainted: G I (6.8.0-rc3-autotest-g99bd3cb0d12e)\n MSR: 8000000000029033 CR: 44002402 XER: 20040000\n CFAR: c000000000a0d170 IRQMASK: 0\n ...\n NIP iommu_reconfig_notifier+0x94/0x200\n LR iommu_reconfig_notifier+0x8c/0x200\n Call Trace:\n iommu_reconfig_notifier+0x8c/0x200 (unreliable)\n notifier_call_chain+0xb8/0x19c\n blocking_notifier_call_chain+0x64/0x98\n of_reconfig_notify+0x44/0xdc\n of_detach_node+0x78/0xb0\n ofdt_write.part.0+0x86c/0xbb8\n proc_reg_write+0xf4/0x150\n vfs_write+0xf8/0x488\n ksys_write+0x84/0x140\n system_call_exception+0x138/0x330\n system_call_vectored_common+0x15c/0x2ec\n\nThe patch adds the missing iommu_group_put() call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-p587-g8pc-4qg6/GHSA-p587-g8pc-4qg6.json b/advisories/unreviewed/2024/04/GHSA-p587-g8pc-4qg6/GHSA-p587-g8pc-4qg6.json index 889a72b4200..8ead5cf1477 100644 --- a/advisories/unreviewed/2024/04/GHSA-p587-g8pc-4qg6/GHSA-p587-g8pc-4qg6.json +++ b/advisories/unreviewed/2024/04/GHSA-p587-g8pc-4qg6/GHSA-p587-g8pc-4qg6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-p9j3-r5pw-645f/GHSA-p9j3-r5pw-645f.json b/advisories/unreviewed/2024/04/GHSA-p9j3-r5pw-645f/GHSA-p9j3-r5pw-645f.json index 573b744af7e..f98d43f6897 100644 --- a/advisories/unreviewed/2024/04/GHSA-p9j3-r5pw-645f/GHSA-p9j3-r5pw-645f.json +++ b/advisories/unreviewed/2024/04/GHSA-p9j3-r5pw-645f/GHSA-p9j3-r5pw-645f.json @@ -7,12 +7,8 @@ "CVE-2024-26691" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Fix circular locking dependency\n\nThe rule inside kvm enforces that the vcpu->mutex is taken *inside*\nkvm->lock. The rule is violated by the pkvm_create_hyp_vm() which acquires\nthe kvm->lock while already holding the vcpu->mutex lock from\nkvm_vcpu_ioctl(). Avoid the circular locking dependency altogether by\nprotecting the hyp vm handle with the config_lock, much like we already\ndo for other forms of VM-scoped data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qc38-w33g-cp7m/GHSA-qc38-w33g-cp7m.json b/advisories/unreviewed/2024/04/GHSA-qc38-w33g-cp7m/GHSA-qc38-w33g-cp7m.json index 79c310b5fcf..23ea99c7b79 100644 --- a/advisories/unreviewed/2024/04/GHSA-qc38-w33g-cp7m/GHSA-qc38-w33g-cp7m.json +++ b/advisories/unreviewed/2024/04/GHSA-qc38-w33g-cp7m/GHSA-qc38-w33g-cp7m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-qpw5-gvf2-cq42/GHSA-qpw5-gvf2-cq42.json b/advisories/unreviewed/2024/04/GHSA-qpw5-gvf2-cq42/GHSA-qpw5-gvf2-cq42.json index 314616b3aa3..37eadcc07e0 100644 --- a/advisories/unreviewed/2024/04/GHSA-qpw5-gvf2-cq42/GHSA-qpw5-gvf2-cq42.json +++ b/advisories/unreviewed/2024/04/GHSA-qpw5-gvf2-cq42/GHSA-qpw5-gvf2-cq42.json @@ -7,12 +7,8 @@ "CVE-2024-26655" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nFix memory leak in posix_clock_open()\n\nIf the clk ops.open() function returns an error, we don't release the\npccontext we allocated for this clock.\n\nRe-organize the code slightly to make it all more obvious.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qrpr-37g9-38rr/GHSA-qrpr-37g9-38rr.json b/advisories/unreviewed/2024/04/GHSA-qrpr-37g9-38rr/GHSA-qrpr-37g9-38rr.json index f82f72151a4..759c206d6db 100644 --- a/advisories/unreviewed/2024/04/GHSA-qrpr-37g9-38rr/GHSA-qrpr-37g9-38rr.json +++ b/advisories/unreviewed/2024/04/GHSA-qrpr-37g9-38rr/GHSA-qrpr-37g9-38rr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-rfj8-v7wf-3hfc/GHSA-rfj8-v7wf-3hfc.json b/advisories/unreviewed/2024/04/GHSA-rfj8-v7wf-3hfc/GHSA-rfj8-v7wf-3hfc.json index af3368ceff5..daf1f32cef2 100644 --- a/advisories/unreviewed/2024/04/GHSA-rfj8-v7wf-3hfc/GHSA-rfj8-v7wf-3hfc.json +++ b/advisories/unreviewed/2024/04/GHSA-rfj8-v7wf-3hfc/GHSA-rfj8-v7wf-3hfc.json @@ -7,12 +7,8 @@ "CVE-2024-2322" ], "details": "The WooCommerce Cart Abandonment Recovery WordPress plugin before 1.2.27 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admins delete arbitrary email templates as well as delete and unsubscribe users from abandoned orders via CSRF attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-vxrg-576c-83m9/GHSA-vxrg-576c-83m9.json b/advisories/unreviewed/2024/04/GHSA-vxrg-576c-83m9/GHSA-vxrg-576c-83m9.json index b1a26f96579..ec03f251c00 100644 --- a/advisories/unreviewed/2024/04/GHSA-vxrg-576c-83m9/GHSA-vxrg-576c-83m9.json +++ b/advisories/unreviewed/2024/04/GHSA-vxrg-576c-83m9/GHSA-vxrg-576c-83m9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-wq2g-ccx9-4w35/GHSA-wq2g-ccx9-4w35.json b/advisories/unreviewed/2024/04/GHSA-wq2g-ccx9-4w35/GHSA-wq2g-ccx9-4w35.json index 20bf52dff52..62ac05ce3bb 100644 --- a/advisories/unreviewed/2024/04/GHSA-wq2g-ccx9-4w35/GHSA-wq2g-ccx9-4w35.json +++ b/advisories/unreviewed/2024/04/GHSA-wq2g-ccx9-4w35/GHSA-wq2g-ccx9-4w35.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-wvfw-6rv6-rmwc/GHSA-wvfw-6rv6-rmwc.json b/advisories/unreviewed/2024/04/GHSA-wvfw-6rv6-rmwc/GHSA-wvfw-6rv6-rmwc.json index bd2051f1e95..7025be7662d 100644 --- a/advisories/unreviewed/2024/04/GHSA-wvfw-6rv6-rmwc/GHSA-wvfw-6rv6-rmwc.json +++ b/advisories/unreviewed/2024/04/GHSA-wvfw-6rv6-rmwc/GHSA-wvfw-6rv6-rmwc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-xrr8-23jx-fjvc/GHSA-xrr8-23jx-fjvc.json b/advisories/unreviewed/2024/04/GHSA-xrr8-23jx-fjvc/GHSA-xrr8-23jx-fjvc.json index 271b974608a..a387494456f 100644 --- a/advisories/unreviewed/2024/04/GHSA-xrr8-23jx-fjvc/GHSA-xrr8-23jx-fjvc.json +++ b/advisories/unreviewed/2024/04/GHSA-xrr8-23jx-fjvc/GHSA-xrr8-23jx-fjvc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-xv6f-4q9w-8q96/GHSA-xv6f-4q9w-8q96.json b/advisories/unreviewed/2024/04/GHSA-xv6f-4q9w-8q96/GHSA-xv6f-4q9w-8q96.json index 89b160cbb59..b528aa6c25e 100644 --- a/advisories/unreviewed/2024/04/GHSA-xv6f-4q9w-8q96/GHSA-xv6f-4q9w-8q96.json +++ b/advisories/unreviewed/2024/04/GHSA-xv6f-4q9w-8q96/GHSA-xv6f-4q9w-8q96.json @@ -7,12 +7,8 @@ "CVE-2024-26705" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nparisc: BTLB: Fix crash when setting up BTLB at CPU bringup\n\nWhen using hotplug and bringing up a 32-bit CPU, ask the firmware about the\nBTLB information to set up the static (block) TLB entries.\n\nFor that write access to the static btlb_info struct is needed, but\nsince it is marked __ro_after_init the kernel segfaults with missing\nwrite permissions.\n\nFix the crash by dropping the __ro_after_init annotation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-2256-7f8q-qjm9/GHSA-2256-7f8q-qjm9.json b/advisories/unreviewed/2024/05/GHSA-2256-7f8q-qjm9/GHSA-2256-7f8q-qjm9.json index f15dc016cb2..a33d5337191 100644 --- a/advisories/unreviewed/2024/05/GHSA-2256-7f8q-qjm9/GHSA-2256-7f8q-qjm9.json +++ b/advisories/unreviewed/2024/05/GHSA-2256-7f8q-qjm9/GHSA-2256-7f8q-qjm9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-49gp-r5pw-pqg8/GHSA-49gp-r5pw-pqg8.json b/advisories/unreviewed/2024/05/GHSA-49gp-r5pw-pqg8/GHSA-49gp-r5pw-pqg8.json index 42cf5f66061..ce0af9c3621 100644 --- a/advisories/unreviewed/2024/05/GHSA-49gp-r5pw-pqg8/GHSA-49gp-r5pw-pqg8.json +++ b/advisories/unreviewed/2024/05/GHSA-49gp-r5pw-pqg8/GHSA-49gp-r5pw-pqg8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-4v4w-p37f-qvm2/GHSA-4v4w-p37f-qvm2.json b/advisories/unreviewed/2024/05/GHSA-4v4w-p37f-qvm2/GHSA-4v4w-p37f-qvm2.json index cbf948acaa1..ccc0d6555bd 100644 --- a/advisories/unreviewed/2024/05/GHSA-4v4w-p37f-qvm2/GHSA-4v4w-p37f-qvm2.json +++ b/advisories/unreviewed/2024/05/GHSA-4v4w-p37f-qvm2/GHSA-4v4w-p37f-qvm2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-57w2-qxwq-vw95/GHSA-57w2-qxwq-vw95.json b/advisories/unreviewed/2024/05/GHSA-57w2-qxwq-vw95/GHSA-57w2-qxwq-vw95.json index 5b7ee50ff12..69d06b5ed6d 100644 --- a/advisories/unreviewed/2024/05/GHSA-57w2-qxwq-vw95/GHSA-57w2-qxwq-vw95.json +++ b/advisories/unreviewed/2024/05/GHSA-57w2-qxwq-vw95/GHSA-57w2-qxwq-vw95.json @@ -7,12 +7,8 @@ "CVE-2024-27035" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: compress: fix to guarantee persisting compressed blocks by CP\n\nIf data block in compressed cluster is not persisted with metadata\nduring checkpoint, after SPOR, the data may be corrupted, let's\nguarantee to write compressed page by checkpoint.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-5hxm-7v87-m497/GHSA-5hxm-7v87-m497.json b/advisories/unreviewed/2024/05/GHSA-5hxm-7v87-m497/GHSA-5hxm-7v87-m497.json index db39d5a00db..5c5b00e9805 100644 --- a/advisories/unreviewed/2024/05/GHSA-5hxm-7v87-m497/GHSA-5hxm-7v87-m497.json +++ b/advisories/unreviewed/2024/05/GHSA-5hxm-7v87-m497/GHSA-5hxm-7v87-m497.json @@ -7,12 +7,8 @@ "CVE-2024-27392" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: host: fix double-free of struct nvme_id_ns in ns_update_nuse()\n\nWhen nvme_identify_ns() fails, it frees the pointer to the struct\nnvme_id_ns before it returns. However, ns_update_nuse() calls kfree()\nfor the pointer even when nvme_identify_ns() fails. This results in\nKASAN double-free, which was observed with blktests nvme/045 with\nproposed patches [1] on the kernel v6.8-rc7. Fix the double-free by\nskipping kfree() when nvme_identify_ns() fails.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-5mg2-xwpp-qvmq/GHSA-5mg2-xwpp-qvmq.json b/advisories/unreviewed/2024/05/GHSA-5mg2-xwpp-qvmq/GHSA-5mg2-xwpp-qvmq.json index e565e596038..e77f45929eb 100644 --- a/advisories/unreviewed/2024/05/GHSA-5mg2-xwpp-qvmq/GHSA-5mg2-xwpp-qvmq.json +++ b/advisories/unreviewed/2024/05/GHSA-5mg2-xwpp-qvmq/GHSA-5mg2-xwpp-qvmq.json @@ -7,12 +7,8 @@ "CVE-2024-27064" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: Fix a memory leak in nf_tables_updchain\n\nIf nft_netdev_register_hooks() fails, the memory associated with\nnft_stats is not freed, causing a memory leak.\n\nThis patch fixes it by moving nft_stats_alloc() down after\nnft_netdev_register_hooks() succeeds.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7vvw-vrgm-xw8c/GHSA-7vvw-vrgm-xw8c.json b/advisories/unreviewed/2024/05/GHSA-7vvw-vrgm-xw8c/GHSA-7vvw-vrgm-xw8c.json index dc33a3615d3..cfdfb59bd45 100644 --- a/advisories/unreviewed/2024/05/GHSA-7vvw-vrgm-xw8c/GHSA-7vvw-vrgm-xw8c.json +++ b/advisories/unreviewed/2024/05/GHSA-7vvw-vrgm-xw8c/GHSA-7vvw-vrgm-xw8c.json @@ -7,12 +7,8 @@ "CVE-2024-27057" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: ipc4-pcm: Workaround for crashed firmware on system suspend\n\nWhen the system is suspended while audio is active, the\nsof_ipc4_pcm_hw_free() is invoked to reset the pipelines since during\nsuspend the DSP is turned off, streams will be re-started after resume.\n\nIf the firmware crashes during while audio is running (or when we reset\nthe stream before suspend) then the sof_ipc4_set_multi_pipeline_state()\nwill fail with IPC error and the state change is interrupted.\nThis will cause misalignment between the kernel and firmware state on next\nDSP boot resulting errors returned by firmware for IPC messages, eventually\nfailing the audio resume.\nOn stream close the errors are ignored so the kernel state will be\ncorrected on the next DSP boot, so the second boot after the DSP panic.\n\nIf sof_ipc4_trigger_pipelines() is called from sof_ipc4_pcm_hw_free() then\nstate parameter is SOF_IPC4_PIPE_RESET and only in this case.\n\nTreat a forced pipeline reset similarly to how we treat a pcm_free by\nignoring error on state sending to allow the kernel's state to be\nconsistent with the state the firmware will have after the next boot.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-857r-xmrg-gj95/GHSA-857r-xmrg-gj95.json b/advisories/unreviewed/2024/05/GHSA-857r-xmrg-gj95/GHSA-857r-xmrg-gj95.json index 3d5c87994db..ff5cf48770f 100644 --- a/advisories/unreviewed/2024/05/GHSA-857r-xmrg-gj95/GHSA-857r-xmrg-gj95.json +++ b/advisories/unreviewed/2024/05/GHSA-857r-xmrg-gj95/GHSA-857r-xmrg-gj95.json @@ -7,12 +7,8 @@ "CVE-2024-27066" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio: packed: fix unmap leak for indirect desc table\n\nWhen use_dma_api and premapped are true, then the do_unmap is false.\n\nBecause the do_unmap is false, vring_unmap_extra_packed is not called by\ndetach_buf_packed.\n\n if (unlikely(vq->do_unmap)) {\n curr = id;\n for (i = 0; i < state->num; i++) {\n vring_unmap_extra_packed(vq,\n &vq->packed.desc_extra[curr]);\n curr = vq->packed.desc_extra[curr].next;\n }\n }\n\nSo the indirect desc table is not unmapped. This causes the unmap leak.\n\nSo here, we check vq->use_dma_api instead. Synchronously, dma info is\nupdated based on use_dma_api judgment\n\nThis bug does not occur, because no driver use the premapped with\nindirect.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8hp7-p44f-w939/GHSA-8hp7-p44f-w939.json b/advisories/unreviewed/2024/05/GHSA-8hp7-p44f-w939/GHSA-8hp7-p44f-w939.json index c82d1103a48..c9b463c75ed 100644 --- a/advisories/unreviewed/2024/05/GHSA-8hp7-p44f-w939/GHSA-8hp7-p44f-w939.json +++ b/advisories/unreviewed/2024/05/GHSA-8hp7-p44f-w939/GHSA-8hp7-p44f-w939.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-8xwv-9gjh-23gh/GHSA-8xwv-9gjh-23gh.json b/advisories/unreviewed/2024/05/GHSA-8xwv-9gjh-23gh/GHSA-8xwv-9gjh-23gh.json index 9f3b7df2a83..8b139e1f4b0 100644 --- a/advisories/unreviewed/2024/05/GHSA-8xwv-9gjh-23gh/GHSA-8xwv-9gjh-23gh.json +++ b/advisories/unreviewed/2024/05/GHSA-8xwv-9gjh-23gh/GHSA-8xwv-9gjh-23gh.json @@ -7,12 +7,8 @@ "CVE-2024-27070" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid use-after-free issue in f2fs_filemap_fault\n\nsyzbot reports a f2fs bug as below:\n\nBUG: KASAN: slab-use-after-free in f2fs_filemap_fault+0xd1/0x2c0 fs/f2fs/file.c:49\nRead of size 8 at addr ffff88807bb22680 by task syz-executor184/5058\n\nCPU: 0 PID: 5058 Comm: syz-executor184 Not tainted 6.7.0-syzkaller-09928-g052d534373b7 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x1e7/0x2d0 lib/dump_stack.c:106\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x163/0x540 mm/kasan/report.c:488\n kasan_report+0x142/0x170 mm/kasan/report.c:601\n f2fs_filemap_fault+0xd1/0x2c0 fs/f2fs/file.c:49\n __do_fault+0x131/0x450 mm/memory.c:4376\n do_shared_fault mm/memory.c:4798 [inline]\n do_fault mm/memory.c:4872 [inline]\n do_pte_missing mm/memory.c:3745 [inline]\n handle_pte_fault mm/memory.c:5144 [inline]\n __handle_mm_fault+0x23b7/0x72b0 mm/memory.c:5285\n handle_mm_fault+0x27e/0x770 mm/memory.c:5450\n do_user_addr_fault arch/x86/mm/fault.c:1364 [inline]\n handle_page_fault arch/x86/mm/fault.c:1507 [inline]\n exc_page_fault+0x456/0x870 arch/x86/mm/fault.c:1563\n asm_exc_page_fault+0x26/0x30 arch/x86/include/asm/idtentry.h:570\n\nThe root cause is: in f2fs_filemap_fault(), vmf->vma may be not alive after\nfilemap_fault(), so it may cause use-after-free issue when accessing\nvmf->vma->vm_flags in trace_f2fs_filemap_fault(). So it needs to keep vm_flags\nin separated temporary variable for tracepoint use.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-963g-qffh-rx88/GHSA-963g-qffh-rx88.json b/advisories/unreviewed/2024/05/GHSA-963g-qffh-rx88/GHSA-963g-qffh-rx88.json index 32e0f9cd583..f349a33b448 100644 --- a/advisories/unreviewed/2024/05/GHSA-963g-qffh-rx88/GHSA-963g-qffh-rx88.json +++ b/advisories/unreviewed/2024/05/GHSA-963g-qffh-rx88/GHSA-963g-qffh-rx88.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-f487-f23r-hjx6/GHSA-f487-f23r-hjx6.json b/advisories/unreviewed/2024/05/GHSA-f487-f23r-hjx6/GHSA-f487-f23r-hjx6.json index 8c6648a3596..a0eeb24950f 100644 --- a/advisories/unreviewed/2024/05/GHSA-f487-f23r-hjx6/GHSA-f487-f23r-hjx6.json +++ b/advisories/unreviewed/2024/05/GHSA-f487-f23r-hjx6/GHSA-f487-f23r-hjx6.json @@ -7,12 +7,8 @@ "CVE-2024-27056" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: ensure offloading TID queue exists\n\nThe resume code path assumes that the TX queue for the offloading TID\nhas been configured. At resume time it then tries to sync the write\npointer as it may have been updated by the firmware.\n\nIn the unusual event that no packets have been send on TID 0, the queue\nwill not have been allocated and this causes a crash. Fix this by\nensuring the queue exist at suspend time.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-fvx9-q8pv-wxv9/GHSA-fvx9-q8pv-wxv9.json b/advisories/unreviewed/2024/05/GHSA-fvx9-q8pv-wxv9/GHSA-fvx9-q8pv-wxv9.json index 96f0c96c27a..ced879dc66c 100644 --- a/advisories/unreviewed/2024/05/GHSA-fvx9-q8pv-wxv9/GHSA-fvx9-q8pv-wxv9.json +++ b/advisories/unreviewed/2024/05/GHSA-fvx9-q8pv-wxv9/GHSA-fvx9-q8pv-wxv9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-g3jj-jjrf-q5mw/GHSA-g3jj-jjrf-q5mw.json b/advisories/unreviewed/2024/05/GHSA-g3jj-jjrf-q5mw/GHSA-g3jj-jjrf-q5mw.json index f7ee975434e..537d4d21d39 100644 --- a/advisories/unreviewed/2024/05/GHSA-g3jj-jjrf-q5mw/GHSA-g3jj-jjrf-q5mw.json +++ b/advisories/unreviewed/2024/05/GHSA-g3jj-jjrf-q5mw/GHSA-g3jj-jjrf-q5mw.json @@ -7,12 +7,8 @@ "CVE-2024-27391" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wilc1000: do not realloc workqueue everytime an interface is added\n\nCommit 09ed8bfc5215 (\"wilc1000: Rename workqueue from \"WILC_wq\" to\n\"NETDEV-wq\"\") moved workqueue creation in wilc_netdev_ifc_init in order to\nset the interface name in the workqueue name. However, while the driver\nneeds only one workqueue, the wilc_netdev_ifc_init is called each time we\nadd an interface over a phy, which in turns overwrite the workqueue with a\nnew one. This can be observed with the following commands:\n\nfor i in $(seq 0 10)\ndo\n iw phy phy0 interface add wlan1 type managed\n iw dev wlan1 del\ndone\nps -eo pid,comm|grep wlan\n\n 39 kworker/R-wlan0\n 98 kworker/R-wlan1\n102 kworker/R-wlan1\n105 kworker/R-wlan1\n108 kworker/R-wlan1\n111 kworker/R-wlan1\n114 kworker/R-wlan1\n117 kworker/R-wlan1\n120 kworker/R-wlan1\n123 kworker/R-wlan1\n126 kworker/R-wlan1\n129 kworker/R-wlan1\n\nFix this leakage by putting back hif_workqueue allocation in\nwilc_cfg80211_init. Regarding the workqueue name, it is indeed relevant to\nset it lowercase, however it is not attached to a specific netdev, so\nenforcing netdev name in the name is not so relevant. Still, enrich the\nname with the wiphy name to make it clear which phy is using the workqueue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gvpq-95j2-mc36/GHSA-gvpq-95j2-mc36.json b/advisories/unreviewed/2024/05/GHSA-gvpq-95j2-mc36/GHSA-gvpq-95j2-mc36.json index 0715cb50289..d94d99481d6 100644 --- a/advisories/unreviewed/2024/05/GHSA-gvpq-95j2-mc36/GHSA-gvpq-95j2-mc36.json +++ b/advisories/unreviewed/2024/05/GHSA-gvpq-95j2-mc36/GHSA-gvpq-95j2-mc36.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-gwcp-9x74-j757/GHSA-gwcp-9x74-j757.json b/advisories/unreviewed/2024/05/GHSA-gwcp-9x74-j757/GHSA-gwcp-9x74-j757.json index a456691e231..3e442fd2aae 100644 --- a/advisories/unreviewed/2024/05/GHSA-gwcp-9x74-j757/GHSA-gwcp-9x74-j757.json +++ b/advisories/unreviewed/2024/05/GHSA-gwcp-9x74-j757/GHSA-gwcp-9x74-j757.json @@ -7,12 +7,8 @@ "CVE-2024-27079" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix NULL domain on device release\n\nIn the kdump kernel, the IOMMU operates in deferred_attach mode. In this\nmode, info->domain may not yet be assigned by the time the release_device\nfunction is called. It leads to the following crash in the crash kernel:\n\n BUG: kernel NULL pointer dereference, address: 000000000000003c\n ...\n RIP: 0010:do_raw_spin_lock+0xa/0xa0\n ...\n _raw_spin_lock_irqsave+0x1b/0x30\n intel_iommu_release_device+0x96/0x170\n iommu_deinit_device+0x39/0xf0\n __iommu_group_remove_device+0xa0/0xd0\n iommu_bus_notifier+0x55/0xb0\n notifier_call_chain+0x5a/0xd0\n blocking_notifier_call_chain+0x41/0x60\n bus_notify+0x34/0x50\n device_del+0x269/0x3d0\n pci_remove_bus_device+0x77/0x100\n p2sb_bar+0xae/0x1d0\n ...\n i801_probe+0x423/0x740\n\nUse the release_domain mechanism to fix it. The scalable mode context\nentry which is not part of release domain should be cleared in\nrelease_device().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-j54f-72m2-vvmr/GHSA-j54f-72m2-vvmr.json b/advisories/unreviewed/2024/05/GHSA-j54f-72m2-vvmr/GHSA-j54f-72m2-vvmr.json index 80ccbb905be..61ef0179402 100644 --- a/advisories/unreviewed/2024/05/GHSA-j54f-72m2-vvmr/GHSA-j54f-72m2-vvmr.json +++ b/advisories/unreviewed/2024/05/GHSA-j54f-72m2-vvmr/GHSA-j54f-72m2-vvmr.json @@ -7,12 +7,8 @@ "CVE-2024-27389" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npstore: inode: Only d_invalidate() is needed\n\nUnloading a modular pstore backend with records in pstorefs would\ntrigger the dput() double-drop warning:\n\n WARNING: CPU: 0 PID: 2569 at fs/dcache.c:762 dput.part.0+0x3f3/0x410\n\nUsing the combo of d_drop()/dput() (as mentioned in\nDocumentation/filesystems/vfs.rst) isn't the right approach here, and\nleads to the reference counting problem seen above. Use d_invalidate()\nand update the code to not bother checking for error codes that can\nnever happen.\n\n---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-j5v2-r4pg-j7h4/GHSA-j5v2-r4pg-j7h4.json b/advisories/unreviewed/2024/05/GHSA-j5v2-r4pg-j7h4/GHSA-j5v2-r4pg-j7h4.json index 8c7fc02a410..4eb70304c53 100644 --- a/advisories/unreviewed/2024/05/GHSA-j5v2-r4pg-j7h4/GHSA-j5v2-r4pg-j7h4.json +++ b/advisories/unreviewed/2024/05/GHSA-j5v2-r4pg-j7h4/GHSA-j5v2-r4pg-j7h4.json @@ -7,12 +7,8 @@ "CVE-2024-27080" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix race when detecting delalloc ranges during fiemap\n\nFor fiemap we recently stopped locking the target extent range for the\nwhole duration of the fiemap call, in order to avoid a deadlock in a\nscenario where the fiemap buffer happens to be a memory mapped range of\nthe same file. This use case is very unlikely to be useful in practice but\nit may be triggered by fuzz testing (syzbot, etc).\n\nThis however introduced a race that makes us miss delalloc ranges for\nfile regions that are currently holes, so the caller of fiemap will not\nbe aware that there's data for some file regions. This can be quite\nserious for some use cases - for example in coreutils versions before 9.0,\nthe cp program used fiemap to detect holes and data in the source file,\ncopying only regions with data (extents or delalloc) from the source file\nto the destination file in order to preserve holes (see the documentation\nfor its --sparse command line option). This means that if cp was used\nwith a source file that had delalloc in a hole, the destination file could\nend up without that data, which is effectively a data loss issue, if it\nhappened to hit the race described below.\n\nThe race happens like this:\n\n1) Fiemap is called, without the FIEMAP_FLAG_SYNC flag, for a file that\n has delalloc in the file range [64M, 65M[, which is currently a hole;\n\n2) Fiemap locks the inode in shared mode, then starts iterating the\n inode's subvolume tree searching for file extent items, without having\n the whole fiemap target range locked in the inode's io tree - the\n change introduced recently by commit b0ad381fa769 (\"btrfs: fix\n deadlock with fiemap and extent locking\"). It only locks ranges in\n the io tree when it finds a hole or prealloc extent since that\n commit;\n\n3) Note that fiemap clones each leaf before using it, and this is to\n avoid deadlocks when locking a file range in the inode's io tree and\n the fiemap buffer is memory mapped to some file, because writing\n to the page with btrfs_page_mkwrite() will wait on any ordered extent\n for the page's range and the ordered extent needs to lock the range\n and may need to modify the same leaf, therefore leading to a deadlock\n on the leaf;\n\n4) While iterating the file extent items in the cloned leaf before\n finding the hole in the range [64M, 65M[, the delalloc in that range\n is flushed and its ordered extent completes - meaning the corresponding\n file extent item is in the inode's subvolume tree, but not present in\n the cloned leaf that fiemap is iterating over;\n\n5) When fiemap finds the hole in the [64M, 65M[ range by seeing the gap in\n the cloned leaf (or a file extent item with disk_bytenr == 0 in case\n the NO_HOLES feature is not enabled), it will lock that file range in\n the inode's io tree and then search for delalloc by checking for the\n EXTENT_DELALLOC bit in the io tree for that range and ordered extents\n (with btrfs_find_delalloc_in_range()). But it finds nothing since the\n delalloc in that range was already flushed and the ordered extent\n completed and is gone - as a result fiemap will not report that there's\n delalloc or an extent for the range [64M, 65M[, so user space will be\n mislead into thinking that there's a hole in that range.\n\nThis could actually be sporadically triggered with test case generic/094\nfrom fstests, which reports a missing extent/delalloc range like this:\n\n generic/094 2s ... - output mismatch (see /home/fdmanana/git/hub/xfstests/results//generic/094.out.bad)\n --- tests/generic/094.out\t2020-06-10 19:29:03.830519425 +0100\n +++ /home/fdmanana/git/hub/xfstests/results//generic/094.out.bad\t2024-02-28 11:00:00.381071525 +0000\n @@ -1,3 +1,9 @@\n QA output created by 094\n fiemap run with sync\n fiemap run without sync\n +ERROR: couldn't find extent at 7\n +map is 'HHDDHPPDPHPH'\n +logical: [ 5.. 6] phys:\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-m9j8-mv47-xw7c/GHSA-m9j8-mv47-xw7c.json b/advisories/unreviewed/2024/05/GHSA-m9j8-mv47-xw7c/GHSA-m9j8-mv47-xw7c.json index 5a62d89ba2e..51df88ea45c 100644 --- a/advisories/unreviewed/2024/05/GHSA-m9j8-mv47-xw7c/GHSA-m9j8-mv47-xw7c.json +++ b/advisories/unreviewed/2024/05/GHSA-m9j8-mv47-xw7c/GHSA-m9j8-mv47-xw7c.json @@ -7,12 +7,8 @@ "CVE-2024-27063" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nleds: trigger: netdev: Fix kernel panic on interface rename trig notify\n\nCommit d5e01266e7f5 (\"leds: trigger: netdev: add additional specific link\nspeed mode\") in the various changes, reworked the way to set the LINKUP\nmode in commit cee4bd16c319 (\"leds: trigger: netdev: Recheck\nNETDEV_LED_MODE_LINKUP on dev rename\") and moved it to a generic function.\n\nThis changed the logic where, in the previous implementation the dev\nfrom the trigger event was used to check if the carrier was ok, but in\nthe new implementation with the generic function, the dev in\ntrigger_data is used instead.\n\nThis is problematic and cause a possible kernel panic due to the fact\nthat the dev in the trigger_data still reference the old one as the\nnew one (passed from the trigger event) still has to be hold and saved\nin the trigger_data struct (done in the NETDEV_REGISTER case).\n\nOn calling of get_device_state(), an invalid net_dev is used and this\ncause a kernel panic.\n\nTo handle this correctly, move the call to get_device_state() after the\nnew net_dev is correctly set in trigger_data (in the NETDEV_REGISTER\ncase) and correctly parse the new dev.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-q87c-gjjf-xqfw/GHSA-q87c-gjjf-xqfw.json b/advisories/unreviewed/2024/05/GHSA-q87c-gjjf-xqfw/GHSA-q87c-gjjf-xqfw.json index 3dfe92fe10e..9dcd53a3bc5 100644 --- a/advisories/unreviewed/2024/05/GHSA-q87c-gjjf-xqfw/GHSA-q87c-gjjf-xqfw.json +++ b/advisories/unreviewed/2024/05/GHSA-q87c-gjjf-xqfw/GHSA-q87c-gjjf-xqfw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-r62c-wwjg-222r/GHSA-r62c-wwjg-222r.json b/advisories/unreviewed/2024/05/GHSA-r62c-wwjg-222r/GHSA-r62c-wwjg-222r.json index bcb90b7f94b..4998899a09d 100644 --- a/advisories/unreviewed/2024/05/GHSA-r62c-wwjg-222r/GHSA-r62c-wwjg-222r.json +++ b/advisories/unreviewed/2024/05/GHSA-r62c-wwjg-222r/GHSA-r62c-wwjg-222r.json @@ -7,12 +7,8 @@ "CVE-2024-24403" ], "details": "Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-30176. Reason: This record is a reservation duplicate of CVE-2024-30176. Notes: All CVE users should reference CVE-2024-30176 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-wr42-h5m2-qmx6/GHSA-wr42-h5m2-qmx6.json b/advisories/unreviewed/2024/05/GHSA-wr42-h5m2-qmx6/GHSA-wr42-h5m2-qmx6.json index 4f9769e95d5..ed32b5fce59 100644 --- a/advisories/unreviewed/2024/05/GHSA-wr42-h5m2-qmx6/GHSA-wr42-h5m2-qmx6.json +++ b/advisories/unreviewed/2024/05/GHSA-wr42-h5m2-qmx6/GHSA-wr42-h5m2-qmx6.json @@ -7,12 +7,8 @@ "CVE-2024-27071" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbacklight: hx8357: Fix potential NULL pointer dereference\n\nThe \"im\" pins are optional. Add missing check in the hx8357_probe().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xf23-pxxh-7q46/GHSA-xf23-pxxh-7q46.json b/advisories/unreviewed/2024/05/GHSA-xf23-pxxh-7q46/GHSA-xf23-pxxh-7q46.json index bbb0d9c4d37..9c141a50aa8 100644 --- a/advisories/unreviewed/2024/05/GHSA-xf23-pxxh-7q46/GHSA-xf23-pxxh-7q46.json +++ b/advisories/unreviewed/2024/05/GHSA-xf23-pxxh-7q46/GHSA-xf23-pxxh-7q46.json @@ -7,12 +7,8 @@ "CVE-2024-27067" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxen/evtchn: avoid WARN() when unbinding an event channel\n\nWhen unbinding a user event channel, the related handler might be\ncalled a last time in case the kernel was built with\nCONFIG_DEBUG_SHIRQ. This might cause a WARN() in the handler.\n\nAvoid that by adding an \"unbinding\" flag to struct user_event which\nwill short circuit the handler.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-295x-34p8-7q26/GHSA-295x-34p8-7q26.json b/advisories/unreviewed/2024/07/GHSA-295x-34p8-7q26/GHSA-295x-34p8-7q26.json index 555672dec4f..d30dfdaee1e 100644 --- a/advisories/unreviewed/2024/07/GHSA-295x-34p8-7q26/GHSA-295x-34p8-7q26.json +++ b/advisories/unreviewed/2024/07/GHSA-295x-34p8-7q26/GHSA-295x-34p8-7q26.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-2f5p-xhq6-2f67/GHSA-2f5p-xhq6-2f67.json b/advisories/unreviewed/2024/07/GHSA-2f5p-xhq6-2f67/GHSA-2f5p-xhq6-2f67.json index 507f56e3fa7..8e5be20baf0 100644 --- a/advisories/unreviewed/2024/07/GHSA-2f5p-xhq6-2f67/GHSA-2f5p-xhq6-2f67.json +++ b/advisories/unreviewed/2024/07/GHSA-2f5p-xhq6-2f67/GHSA-2f5p-xhq6-2f67.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-37rp-g4f8-jx53/GHSA-37rp-g4f8-jx53.json b/advisories/unreviewed/2024/07/GHSA-37rp-g4f8-jx53/GHSA-37rp-g4f8-jx53.json index 0927fb55155..6c11716aef9 100644 --- a/advisories/unreviewed/2024/07/GHSA-37rp-g4f8-jx53/GHSA-37rp-g4f8-jx53.json +++ b/advisories/unreviewed/2024/07/GHSA-37rp-g4f8-jx53/GHSA-37rp-g4f8-jx53.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-3jg8-8v5h-478h/GHSA-3jg8-8v5h-478h.json b/advisories/unreviewed/2024/07/GHSA-3jg8-8v5h-478h/GHSA-3jg8-8v5h-478h.json index 25958911b32..ad69d4a0122 100644 --- a/advisories/unreviewed/2024/07/GHSA-3jg8-8v5h-478h/GHSA-3jg8-8v5h-478h.json +++ b/advisories/unreviewed/2024/07/GHSA-3jg8-8v5h-478h/GHSA-3jg8-8v5h-478h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-48mq-mj2m-9cjq/GHSA-48mq-mj2m-9cjq.json b/advisories/unreviewed/2024/07/GHSA-48mq-mj2m-9cjq/GHSA-48mq-mj2m-9cjq.json index 3f3cba28ecd..898158ce610 100644 --- a/advisories/unreviewed/2024/07/GHSA-48mq-mj2m-9cjq/GHSA-48mq-mj2m-9cjq.json +++ b/advisories/unreviewed/2024/07/GHSA-48mq-mj2m-9cjq/GHSA-48mq-mj2m-9cjq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-4h57-3gmx-g682/GHSA-4h57-3gmx-g682.json b/advisories/unreviewed/2024/07/GHSA-4h57-3gmx-g682/GHSA-4h57-3gmx-g682.json index 3d28f2b2aae..e5e6f2f5c1d 100644 --- a/advisories/unreviewed/2024/07/GHSA-4h57-3gmx-g682/GHSA-4h57-3gmx-g682.json +++ b/advisories/unreviewed/2024/07/GHSA-4h57-3gmx-g682/GHSA-4h57-3gmx-g682.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-5m9v-g6cg-987g/GHSA-5m9v-g6cg-987g.json b/advisories/unreviewed/2024/07/GHSA-5m9v-g6cg-987g/GHSA-5m9v-g6cg-987g.json index 3a4d65a3a1e..aba0dbcb1d9 100644 --- a/advisories/unreviewed/2024/07/GHSA-5m9v-g6cg-987g/GHSA-5m9v-g6cg-987g.json +++ b/advisories/unreviewed/2024/07/GHSA-5m9v-g6cg-987g/GHSA-5m9v-g6cg-987g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-7q38-5rfp-3g7q/GHSA-7q38-5rfp-3g7q.json b/advisories/unreviewed/2024/07/GHSA-7q38-5rfp-3g7q/GHSA-7q38-5rfp-3g7q.json index 06123348727..2de09205b50 100644 --- a/advisories/unreviewed/2024/07/GHSA-7q38-5rfp-3g7q/GHSA-7q38-5rfp-3g7q.json +++ b/advisories/unreviewed/2024/07/GHSA-7q38-5rfp-3g7q/GHSA-7q38-5rfp-3g7q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-87fp-vpx2-6v83/GHSA-87fp-vpx2-6v83.json b/advisories/unreviewed/2024/07/GHSA-87fp-vpx2-6v83/GHSA-87fp-vpx2-6v83.json index d520d51eca2..418bdb6bfa5 100644 --- a/advisories/unreviewed/2024/07/GHSA-87fp-vpx2-6v83/GHSA-87fp-vpx2-6v83.json +++ b/advisories/unreviewed/2024/07/GHSA-87fp-vpx2-6v83/GHSA-87fp-vpx2-6v83.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-c8f7-58h9-9239/GHSA-c8f7-58h9-9239.json b/advisories/unreviewed/2024/07/GHSA-c8f7-58h9-9239/GHSA-c8f7-58h9-9239.json index c47094fbd90..080017cfa72 100644 --- a/advisories/unreviewed/2024/07/GHSA-c8f7-58h9-9239/GHSA-c8f7-58h9-9239.json +++ b/advisories/unreviewed/2024/07/GHSA-c8f7-58h9-9239/GHSA-c8f7-58h9-9239.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-cpm6-fp82-cq6m/GHSA-cpm6-fp82-cq6m.json b/advisories/unreviewed/2024/07/GHSA-cpm6-fp82-cq6m/GHSA-cpm6-fp82-cq6m.json index bb9188431db..079210d9cf4 100644 --- a/advisories/unreviewed/2024/07/GHSA-cpm6-fp82-cq6m/GHSA-cpm6-fp82-cq6m.json +++ b/advisories/unreviewed/2024/07/GHSA-cpm6-fp82-cq6m/GHSA-cpm6-fp82-cq6m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-gv82-rp99-r5wq/GHSA-gv82-rp99-r5wq.json b/advisories/unreviewed/2024/07/GHSA-gv82-rp99-r5wq/GHSA-gv82-rp99-r5wq.json index ec70a7b846e..a4d576b4322 100644 --- a/advisories/unreviewed/2024/07/GHSA-gv82-rp99-r5wq/GHSA-gv82-rp99-r5wq.json +++ b/advisories/unreviewed/2024/07/GHSA-gv82-rp99-r5wq/GHSA-gv82-rp99-r5wq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-j2wf-m2jr-hvfv/GHSA-j2wf-m2jr-hvfv.json b/advisories/unreviewed/2024/07/GHSA-j2wf-m2jr-hvfv/GHSA-j2wf-m2jr-hvfv.json index 59d609feabe..4b63b22e25b 100644 --- a/advisories/unreviewed/2024/07/GHSA-j2wf-m2jr-hvfv/GHSA-j2wf-m2jr-hvfv.json +++ b/advisories/unreviewed/2024/07/GHSA-j2wf-m2jr-hvfv/GHSA-j2wf-m2jr-hvfv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-j7v6-jr86-53j7/GHSA-j7v6-jr86-53j7.json b/advisories/unreviewed/2024/07/GHSA-j7v6-jr86-53j7/GHSA-j7v6-jr86-53j7.json index f1a814c6425..19fe1bca2bc 100644 --- a/advisories/unreviewed/2024/07/GHSA-j7v6-jr86-53j7/GHSA-j7v6-jr86-53j7.json +++ b/advisories/unreviewed/2024/07/GHSA-j7v6-jr86-53j7/GHSA-j7v6-jr86-53j7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-jjch-jw9j-6v52/GHSA-jjch-jw9j-6v52.json b/advisories/unreviewed/2024/07/GHSA-jjch-jw9j-6v52/GHSA-jjch-jw9j-6v52.json index 31338d396b8..b8fe1cc62f3 100644 --- a/advisories/unreviewed/2024/07/GHSA-jjch-jw9j-6v52/GHSA-jjch-jw9j-6v52.json +++ b/advisories/unreviewed/2024/07/GHSA-jjch-jw9j-6v52/GHSA-jjch-jw9j-6v52.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-mf5r-6f88-q9xf/GHSA-mf5r-6f88-q9xf.json b/advisories/unreviewed/2024/07/GHSA-mf5r-6f88-q9xf/GHSA-mf5r-6f88-q9xf.json index ae5ffc40f1f..e8737ed7053 100644 --- a/advisories/unreviewed/2024/07/GHSA-mf5r-6f88-q9xf/GHSA-mf5r-6f88-q9xf.json +++ b/advisories/unreviewed/2024/07/GHSA-mf5r-6f88-q9xf/GHSA-mf5r-6f88-q9xf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-p66q-q6cx-6j4r/GHSA-p66q-q6cx-6j4r.json b/advisories/unreviewed/2024/07/GHSA-p66q-q6cx-6j4r/GHSA-p66q-q6cx-6j4r.json index 0f6998d1833..3811c31b818 100644 --- a/advisories/unreviewed/2024/07/GHSA-p66q-q6cx-6j4r/GHSA-p66q-q6cx-6j4r.json +++ b/advisories/unreviewed/2024/07/GHSA-p66q-q6cx-6j4r/GHSA-p66q-q6cx-6j4r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-qjv4-hpch-c87f/GHSA-qjv4-hpch-c87f.json b/advisories/unreviewed/2024/07/GHSA-qjv4-hpch-c87f/GHSA-qjv4-hpch-c87f.json index 51e4e14b418..5fde3c48430 100644 --- a/advisories/unreviewed/2024/07/GHSA-qjv4-hpch-c87f/GHSA-qjv4-hpch-c87f.json +++ b/advisories/unreviewed/2024/07/GHSA-qjv4-hpch-c87f/GHSA-qjv4-hpch-c87f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-qp6p-mh4h-gm5g/GHSA-qp6p-mh4h-gm5g.json b/advisories/unreviewed/2024/07/GHSA-qp6p-mh4h-gm5g/GHSA-qp6p-mh4h-gm5g.json index cc248c64a1f..fc223023f85 100644 --- a/advisories/unreviewed/2024/07/GHSA-qp6p-mh4h-gm5g/GHSA-qp6p-mh4h-gm5g.json +++ b/advisories/unreviewed/2024/07/GHSA-qp6p-mh4h-gm5g/GHSA-qp6p-mh4h-gm5g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-v7jf-39f3-5f5c/GHSA-v7jf-39f3-5f5c.json b/advisories/unreviewed/2024/07/GHSA-v7jf-39f3-5f5c/GHSA-v7jf-39f3-5f5c.json index f451f9ec4b1..f496e59ca19 100644 --- a/advisories/unreviewed/2024/07/GHSA-v7jf-39f3-5f5c/GHSA-v7jf-39f3-5f5c.json +++ b/advisories/unreviewed/2024/07/GHSA-v7jf-39f3-5f5c/GHSA-v7jf-39f3-5f5c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-vjq5-pfrc-9vjr/GHSA-vjq5-pfrc-9vjr.json b/advisories/unreviewed/2024/07/GHSA-vjq5-pfrc-9vjr/GHSA-vjq5-pfrc-9vjr.json index db685c83fb6..9e233493605 100644 --- a/advisories/unreviewed/2024/07/GHSA-vjq5-pfrc-9vjr/GHSA-vjq5-pfrc-9vjr.json +++ b/advisories/unreviewed/2024/07/GHSA-vjq5-pfrc-9vjr/GHSA-vjq5-pfrc-9vjr.json @@ -7,12 +7,8 @@ "CVE-2022-48805" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup\n\nax88179_rx_fixup() contains several out-of-bounds accesses that can be\ntriggered by a malicious (or defective) USB device, in particular:\n\n - The metadata array (hdr_off..hdr_off+2*pkt_cnt) can be out of bounds,\n causing OOB reads and (on big-endian systems) OOB endianness flips.\n - A packet can overlap the metadata array, causing a later OOB\n endianness flip to corrupt data used by a cloned SKB that has already\n been handed off into the network stack.\n - A packet SKB can be constructed whose tail is far beyond its end,\n causing out-of-bounds heap data to be considered part of the SKB's\n data.\n\nI have tested that this can be used by a malicious USB device to send a\nbogus ICMPv6 Echo Request and receive an ICMPv6 Echo Reply in response\nthat contains random kernel heap data.\nIt's probably also possible to get OOB writes from this on a\nlittle-endian system somehow - maybe by triggering skb_cow() via IP\noptions processing -, but I haven't tested that.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-x5q7-p9g5-58x7/GHSA-x5q7-p9g5-58x7.json b/advisories/unreviewed/2024/07/GHSA-x5q7-p9g5-58x7/GHSA-x5q7-p9g5-58x7.json index 1740cca684c..5345cfcc1ab 100644 --- a/advisories/unreviewed/2024/07/GHSA-x5q7-p9g5-58x7/GHSA-x5q7-p9g5-58x7.json +++ b/advisories/unreviewed/2024/07/GHSA-x5q7-p9g5-58x7/GHSA-x5q7-p9g5-58x7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-xq9p-hq98-j4x4/GHSA-xq9p-hq98-j4x4.json b/advisories/unreviewed/2024/07/GHSA-xq9p-hq98-j4x4/GHSA-xq9p-hq98-j4x4.json index f9697890d46..39fbb6cb10d 100644 --- a/advisories/unreviewed/2024/07/GHSA-xq9p-hq98-j4x4/GHSA-xq9p-hq98-j4x4.json +++ b/advisories/unreviewed/2024/07/GHSA-xq9p-hq98-j4x4/GHSA-xq9p-hq98-j4x4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",