diff --git a/advisories/github-reviewed/2020/09/GHSA-46m8-42hm-wvvw/GHSA-46m8-42hm-wvvw.json b/advisories/github-reviewed/2020/09/GHSA-46m8-42hm-wvvw/GHSA-46m8-42hm-wvvw.json index 3e8ddafe1e8..c6755486c55 100644 --- a/advisories/github-reviewed/2020/09/GHSA-46m8-42hm-wvvw/GHSA-46m8-42hm-wvvw.json +++ b/advisories/github-reviewed/2020/09/GHSA-46m8-42hm-wvvw/GHSA-46m8-42hm-wvvw.json @@ -8,9 +8,7 @@ ], "summary": "Cross-Site Scripting in emojione", "details": "Affected versions of `emojione` are vulnerable to cross-site scripting when user input is passed into the `toShort()`, `shortnameToImage()`, `unicodeToImage()`, and `toImage()` functions.\n\n\n\n## Recommendation\n\nUpdate to version 1.3.1 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-8px5-63x9-5c7p/GHSA-8px5-63x9-5c7p.json b/advisories/github-reviewed/2020/09/GHSA-8px5-63x9-5c7p/GHSA-8px5-63x9-5c7p.json index e0843eef2db..35a81552bae 100644 --- a/advisories/github-reviewed/2020/09/GHSA-8px5-63x9-5c7p/GHSA-8px5-63x9-5c7p.json +++ b/advisories/github-reviewed/2020/09/GHSA-8px5-63x9-5c7p/GHSA-8px5-63x9-5c7p.json @@ -8,9 +8,7 @@ ], "summary": "pullit vulnerable to command injection", "details": "Versions of `pullit` prior to 1.4.0 are vulnerable to Command Injection. The package does not validate input on git branch names and concatenates it to an exec call, allowing attackers to run arbitrary commands in the system.\n\n## Recommendation\n\nUpgrade to version 1.4.0 or later.\n\n## Credits\n\nThis vulnerability was discovered by @lirantal", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/06/GHSA-243q-g9j3-qf6r/GHSA-243q-g9j3-qf6r.json b/advisories/github-reviewed/2021/06/GHSA-243q-g9j3-qf6r/GHSA-243q-g9j3-qf6r.json index 54dc22cfc44..87d99bad3f7 100644 --- a/advisories/github-reviewed/2021/06/GHSA-243q-g9j3-qf6r/GHSA-243q-g9j3-qf6r.json +++ b/advisories/github-reviewed/2021/06/GHSA-243q-g9j3-qf6r/GHSA-243q-g9j3-qf6r.json @@ -3,14 +3,10 @@ "id": "GHSA-243q-g9j3-qf6r", "modified": "2021-06-24T19:31:03Z", "published": "2021-06-28T18:21:01Z", - "aliases": [ - - ], + "aliases": [], "summary": "non-admin users can create integration role with administrator role", "details": "### Impact\nnon-admin users can create integration role with administrator role\n\n### Patches\nWe recommend updating to the current version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download overview.\n\nhttps://www.shopware.com/en/download/#shopware-6\n\n### Workarounds\nFor older versions of 6.1, 6.2, and 6.3 corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.\n\nhttps://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2021-06-24T19:31:03Z", diff --git a/advisories/github-reviewed/2021/06/GHSA-6rg3-8h8x-5xfv/GHSA-6rg3-8h8x-5xfv.json b/advisories/github-reviewed/2021/06/GHSA-6rg3-8h8x-5xfv/GHSA-6rg3-8h8x-5xfv.json index 830fbfc1a1e..8c16b3ebcc5 100644 --- a/advisories/github-reviewed/2021/06/GHSA-6rg3-8h8x-5xfv/GHSA-6rg3-8h8x-5xfv.json +++ b/advisories/github-reviewed/2021/06/GHSA-6rg3-8h8x-5xfv/GHSA-6rg3-8h8x-5xfv.json @@ -3,9 +3,7 @@ "id": "GHSA-6rg3-8h8x-5xfv", "modified": "2021-10-05T17:24:11Z", "published": "2021-06-23T18:04:50Z", - "aliases": [ - - ], + "aliases": [], "summary": "Unchecked hostname resolution could allow access to local network resources by users outside the local network", "details": "### Impact\nA newly implemented route allowing users to download files from remote endpoints was not properly verifying the destination hostname for user provided URLs. This would allow malicious users to potentially access resources on local networks that would otherwise be inaccessible.\n\nThis vulnerability requires valid authentication credentials and is therefore **not exploitable by unauthenticated users**. If you are running an instance for yourself or other trusted individuals this impact is unlikely to be of major concern to you. However, you should still upgrade for security sake.\n\n### Patches\nUsers should upgrade to the latest version of Wings.\n\n### Workarounds\nThere is no workaround available that does not involve modifying Panel or Wings code.\n", "severity": [ diff --git a/advisories/github-reviewed/2021/06/GHSA-7r96-8g3x-g36m/GHSA-7r96-8g3x-g36m.json b/advisories/github-reviewed/2021/06/GHSA-7r96-8g3x-g36m/GHSA-7r96-8g3x-g36m.json index f5ada33b2ff..3b67543d8d8 100644 --- a/advisories/github-reviewed/2021/06/GHSA-7r96-8g3x-g36m/GHSA-7r96-8g3x-g36m.json +++ b/advisories/github-reviewed/2021/06/GHSA-7r96-8g3x-g36m/GHSA-7r96-8g3x-g36m.json @@ -3,9 +3,7 @@ "id": "GHSA-7r96-8g3x-g36m", "modified": "2022-01-04T19:36:52Z", "published": "2021-06-28T17:16:56Z", - "aliases": [ - - ], + "aliases": [], "summary": "Improper Verification of Cryptographic Signature", "details": "### Impact\nThe `verifyWithMessage` method of `tEnvoyNaClSigningKey` always returns `true` for any signature of a SHA-512 hash matching the SHA-512 hash of the message even if the signature is invalid.\n\n### Patches\nUpgrade to `v7.0.3` immediately to resolve this issue. Since the vulnerability lies within the verification method, the previous signatures are still valid. We highly recommend reverifying any signatures that were previously verified with the vulnerable `verifyWithMessage` method.\n\n### Workarounds\nIn `tenvoy.js` under the `verifyWithMessage` method definition within the `tEnvoyNaClSigningKey` class, ensure that the return statement call to `this.verify` ends in `.verified`. For example, the return statement should start with `return this.verify(signed, password).verified && ` instead of `return this.verify(signed, password) && `.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [github.com/TogaTech/tEnvoy](https://github.com/TogaTech/tEnvoy)\n", "severity": [ diff --git a/advisories/github-reviewed/2021/06/GHSA-8vfw-v2jv-9hwc/GHSA-8vfw-v2jv-9hwc.json b/advisories/github-reviewed/2021/06/GHSA-8vfw-v2jv-9hwc/GHSA-8vfw-v2jv-9hwc.json index 0a14e8998e2..6f795cb2793 100644 --- a/advisories/github-reviewed/2021/06/GHSA-8vfw-v2jv-9hwc/GHSA-8vfw-v2jv-9hwc.json +++ b/advisories/github-reviewed/2021/06/GHSA-8vfw-v2jv-9hwc/GHSA-8vfw-v2jv-9hwc.json @@ -3,9 +3,7 @@ "id": "GHSA-8vfw-v2jv-9hwc", "modified": "2021-06-24T19:39:30Z", "published": "2021-06-28T16:52:45Z", - "aliases": [ - - ], + "aliases": [], "summary": "Reflected cross-site scripting in development mode handler in Vaadin", "details": "URL encoding error in development mode handler in `com.vaadin:flow-server` versions 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows local user to execute arbitrary JavaScript code by opening crafted URL in browser.\n\n- https://vaadin.com/security/cve-2021-33604", "severity": [ diff --git a/advisories/github-reviewed/2021/06/GHSA-g7w8-pp9w-7p32/GHSA-g7w8-pp9w-7p32.json b/advisories/github-reviewed/2021/06/GHSA-g7w8-pp9w-7p32/GHSA-g7w8-pp9w-7p32.json index 5c905c50216..1331e771692 100644 --- a/advisories/github-reviewed/2021/06/GHSA-g7w8-pp9w-7p32/GHSA-g7w8-pp9w-7p32.json +++ b/advisories/github-reviewed/2021/06/GHSA-g7w8-pp9w-7p32/GHSA-g7w8-pp9w-7p32.json @@ -3,14 +3,10 @@ "id": "GHSA-g7w8-pp9w-7p32", "modified": "2021-10-05T17:26:03Z", "published": "2021-06-28T16:57:32Z", - "aliases": [ - - ], + "aliases": [], "summary": "Creation of order credits was not validated by acl in admin orders", "details": "### Impact\nCreation of order credits was not validated by ACL in admin orders\n\n### Patches\nWe recommend updating to the current version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download overview.\n\nhttps://www.shopware.com/en/download/#shopware-6\n\n### Workarounds\nFor older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.\n\nhttps://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/06/GHSA-gpmh-g94g-qrhr/GHSA-gpmh-g94g-qrhr.json b/advisories/github-reviewed/2021/06/GHSA-gpmh-g94g-qrhr/GHSA-gpmh-g94g-qrhr.json index 8106a51f6a9..7e78073c7f8 100644 --- a/advisories/github-reviewed/2021/06/GHSA-gpmh-g94g-qrhr/GHSA-gpmh-g94g-qrhr.json +++ b/advisories/github-reviewed/2021/06/GHSA-gpmh-g94g-qrhr/GHSA-gpmh-g94g-qrhr.json @@ -3,14 +3,10 @@ "id": "GHSA-gpmh-g94g-qrhr", "modified": "2021-06-24T19:20:56Z", "published": "2021-06-28T18:20:53Z", - "aliases": [ - - ], + "aliases": [], "summary": "Internal hidden fields are visible on to many associations in admin api", "details": "### Impact\nThe admin api has exposed some internal hidden fields when an association has been loaded with a to many reference\n\n### Patches\nWe recommend updating to the current version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download overview.\n\nhttps://www.shopware.com/en/download/#shopware-6\n\n### Workarounds\nFor older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.\n\nhttps://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2021-06-24T19:20:56Z", diff --git a/advisories/github-reviewed/2021/06/GHSA-qvp4-rpmr-xwrr/GHSA-qvp4-rpmr-xwrr.json b/advisories/github-reviewed/2021/06/GHSA-qvp4-rpmr-xwrr/GHSA-qvp4-rpmr-xwrr.json index ab84539b612..a30003ee529 100644 --- a/advisories/github-reviewed/2021/06/GHSA-qvp4-rpmr-xwrr/GHSA-qvp4-rpmr-xwrr.json +++ b/advisories/github-reviewed/2021/06/GHSA-qvp4-rpmr-xwrr/GHSA-qvp4-rpmr-xwrr.json @@ -3,9 +3,7 @@ "id": "GHSA-qvp4-rpmr-xwrr", "modified": "2021-06-22T20:50:44Z", "published": "2021-06-23T18:00:20Z", - "aliases": [ - - ], + "aliases": [], "summary": "Possible bypass of token claim validation when OAuth2 Introspection caching is enabled", "details": "### Impact\n\nWhen you make a request to an endpoint that requires the scope `foo` using an access token granted with that `foo` scope, introspection will be valid and that token will be cached. The problem comes when a second requests to an endpoint that requires the scope `bar` is made before the cache has expired. Whether the token is granted or not to the `bar` scope, introspection will be valid.\n\n### Patches\n\nA patch will be released with `v0.38.12-beta.1`.\n\n### Workarounds\n\nPer default, caching is disabled for the `oauth2_introspection` authenticator. When caching is disabled, this vulnerability does not exist.\n\n### Trace\n\nThe cache is checked in [`func (a *AuthenticatorOAuth2Introspection) Authenticate(...)`](https://github.com/ory/oathkeeper/blob/6a31df1c3779425e05db1c2a381166b087cb29a4/pipeline/authn/authenticator_oauth2_introspection.go#L152). From [`tokenFromCache()`](https://github.com/ory/oathkeeper/blob/6a31df1c3779425e05db1c2a381166b087cb29a4/pipeline/authn/authenticator_oauth2_introspection.go#L97) it seems that it only validates the token expiration date, but ignores whether the token has or not the proper scopes.\n\n### Post-Mortem\n\nThe vulnerability was introduced in PR #424. During review, we failed to require appropriate test coverage by the submitter which is the primary reason that the vulnerability passed the review process.\n\nTo avoid this from happening again we enabled codecov with a strict policy on the Ory Oathkeeper repository: Without an increase in code coverage the PR can not be merged.\n\nTo address this issue and any regressions we have added a test suite ensuring that the cache behaviour is correct in the different scenarios:\n\n- Scope strategy is `none`, cache is enabled, and `requested_scope` is not empty -> cache will not be used;\n- Scope strategy is `none`, cache is enabled, and `requested_scope` is empty -> cache will be used;\n- Scope strategy is not `none`, cache is enabled, and `requested_scope` is not empty -> cache will be used;\n\nas well as validating if `iss`, `aud`, `exp`, `token_use`, and scope are validated.\n\nAdditionally, we added [CodeQL scanning](https://github.com/ory/oathkeeper/commit/64ac7562669287d391cd72dfd43c5d71ff9f89a1) to the CI.", "severity": [ diff --git a/advisories/github-reviewed/2021/06/GHSA-vrf2-xghr-j52v/GHSA-vrf2-xghr-j52v.json b/advisories/github-reviewed/2021/06/GHSA-vrf2-xghr-j52v/GHSA-vrf2-xghr-j52v.json index 811a12e1651..7c9e98b8445 100644 --- a/advisories/github-reviewed/2021/06/GHSA-vrf2-xghr-j52v/GHSA-vrf2-xghr-j52v.json +++ b/advisories/github-reviewed/2021/06/GHSA-vrf2-xghr-j52v/GHSA-vrf2-xghr-j52v.json @@ -3,9 +3,7 @@ "id": "GHSA-vrf2-xghr-j52v", "modified": "2021-10-05T17:26:41Z", "published": "2021-06-28T18:20:42Z", - "aliases": [ - - ], + "aliases": [], "summary": "Private files publicly accessible with Cloud Storage providers", "details": "### Impact\n\nPrivate files publicly accessible with Cloud Storage providers when the hashed URL is known\n\n### Patches\n\nWe recommend first changing your configuration to set the correct visibility according to the documentation. The visibility must be at the same level as `type`.\n\nWhen the Storage is saved on Amazon AWS we recommending disabling public access to the bucket containing the private files: https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html\n\nOtherwise, update to Shopware 6.4.1.1 or install or update the Security plugin (https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659) and run the command `./bin/console s3:set-visibility` to correct your cloud file visibilities \n", "severity": [ diff --git a/advisories/github-reviewed/2021/06/GHSA-wq3r-jwrq-xg6w/GHSA-wq3r-jwrq-xg6w.json b/advisories/github-reviewed/2021/06/GHSA-wq3r-jwrq-xg6w/GHSA-wq3r-jwrq-xg6w.json index 1d16c77763a..cb049cec51f 100644 --- a/advisories/github-reviewed/2021/06/GHSA-wq3r-jwrq-xg6w/GHSA-wq3r-jwrq-xg6w.json +++ b/advisories/github-reviewed/2021/06/GHSA-wq3r-jwrq-xg6w/GHSA-wq3r-jwrq-xg6w.json @@ -3,14 +3,10 @@ "id": "GHSA-wq3r-jwrq-xg6w", "modified": "2021-06-24T18:04:47Z", "published": "2021-06-28T16:57:23Z", - "aliases": [ - - ], + "aliases": [], "summary": "Canceling of orders not related to the logged-in user", "details": "### Impact\nCanceling of orders not related to the logged-in user\n\n### Patches\nWe recommend updating to the current version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download overview.\n\nhttps://www.shopware.com/en/download/#shopware-6\n\n### Workarounds\nFor older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.\n\nhttps://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2021-06-24T18:04:47Z", diff --git a/advisories/github-reviewed/2021/08/GHSA-7qfm-6m33-rgg9/GHSA-7qfm-6m33-rgg9.json b/advisories/github-reviewed/2021/08/GHSA-7qfm-6m33-rgg9/GHSA-7qfm-6m33-rgg9.json index f9fe6b7019f..5f6fb0fdd1b 100644 --- a/advisories/github-reviewed/2021/08/GHSA-7qfm-6m33-rgg9/GHSA-7qfm-6m33-rgg9.json +++ b/advisories/github-reviewed/2021/08/GHSA-7qfm-6m33-rgg9/GHSA-7qfm-6m33-rgg9.json @@ -3,9 +3,7 @@ "id": "GHSA-7qfm-6m33-rgg9", "modified": "2021-06-28T19:08:40Z", "published": "2021-08-13T15:21:59Z", - "aliases": [ - - ], + "aliases": [], "summary": "XML External Entity Reference", "details": "An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resultant secrets disclosure and SSRF, via JUnit XML launch import.", "severity": [ diff --git a/advisories/github-reviewed/2021/08/GHSA-rc7p-gmvh-xfx2/GHSA-rc7p-gmvh-xfx2.json b/advisories/github-reviewed/2021/08/GHSA-rc7p-gmvh-xfx2/GHSA-rc7p-gmvh-xfx2.json index 76c264121f1..6656c193257 100644 --- a/advisories/github-reviewed/2021/08/GHSA-rc7p-gmvh-xfx2/GHSA-rc7p-gmvh-xfx2.json +++ b/advisories/github-reviewed/2021/08/GHSA-rc7p-gmvh-xfx2/GHSA-rc7p-gmvh-xfx2.json @@ -3,14 +3,10 @@ "id": "GHSA-rc7p-gmvh-xfx2", "modified": "2021-08-02T17:18:32Z", "published": "2021-08-02T17:19:52Z", - "aliases": [ - - ], + "aliases": [], "summary": "Attack on Kubernetes via Misconfigured Argo Workflows", "details": "### Impact\n\nUsers running using the Argo Server with `--auth-mode=server` (which is the default < v3.0.0) AND have exposed their UI to the Internet may allow remote users to execute arbitrary code on their cluster, e.g. crypto-mining.\n\n### Resolution\n\n* Do not expose your user interface to the Internet. \n* Change configuration. `--auth-mode=client`. \n\nFor users using an older 2.x version of Argo Server, consider upgrading to Argo Server version 3.x or later.\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -43,9 +39,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2021-07-22T20:25:42Z", diff --git a/advisories/github-reviewed/2022/02/GHSA-44gg-pmqr-4669/GHSA-44gg-pmqr-4669.json b/advisories/github-reviewed/2022/02/GHSA-44gg-pmqr-4669/GHSA-44gg-pmqr-4669.json index b1f385e4f16..e3a02c95af1 100644 --- a/advisories/github-reviewed/2022/02/GHSA-44gg-pmqr-4669/GHSA-44gg-pmqr-4669.json +++ b/advisories/github-reviewed/2022/02/GHSA-44gg-pmqr-4669/GHSA-44gg-pmqr-4669.json @@ -8,9 +8,7 @@ ], "summary": "Access Restriction Bypass in Docker", "details": "Docker 1.3.0 through 1.3.1 allows remote attackers to modify the default run profile of image containers and possibly bypass the container by applying unspecified security options to an image.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/02/GHSA-57q7-rxqq-7vgp/GHSA-57q7-rxqq-7vgp.json b/advisories/github-reviewed/2022/02/GHSA-57q7-rxqq-7vgp/GHSA-57q7-rxqq-7vgp.json index 2948976ddf7..6411d957579 100644 --- a/advisories/github-reviewed/2022/02/GHSA-57q7-rxqq-7vgp/GHSA-57q7-rxqq-7vgp.json +++ b/advisories/github-reviewed/2022/02/GHSA-57q7-rxqq-7vgp/GHSA-57q7-rxqq-7vgp.json @@ -3,14 +3,10 @@ "id": "GHSA-57q7-rxqq-7vgp", "modified": "2021-05-18T21:39:10Z", "published": "2022-02-15T01:57:18Z", - "aliases": [ - - ], + "aliases": [], "summary": "On Windows, `git-sizer` might run a `git` executable within the repository being analyzed", "details": "### Impact\nOn Windows, if `git-sizer` is run against a non-bare repository, and that repository has an executable called `git.exe`, `git.bat`, etc., then that executable might be run by `git-sizer` rather than the system `git` executable. An attacker could try to use social engineering to get a victim to run `git-sizer` against a hostile repository and thereby get the victim to run arbitrary code.\n\nOn Linux or other Unix-derived platforms, a similar problem could occur if the user's `PATH` has the current directory before the path to the standard `git` executable, but this is would be a very unusual configuration that has been known for decades to lead to all kinds of security problems.\n\n### Patches\nUsers should update to git-sizer v1.4.0\n\n### Workarounds\nIf you are on Windows, then either\n* Don't run `git-sizer` against a repository that might contain hostile code, or, if you must…\n* Run `git-sizer` against a bare clone of the hostile repository, or, if that is not possible…\n* Make sure that the hostile repository doesn't have an executable in its top-level directory before running `git-sizer`.\n\nIf you are on Linux or other Unix-based system, then (for myriad reasons!) don't add the current directory to your `PATH`.\n\n### References\n* [Command PATH security in Go](https://blog.golang.org/path-security)\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [the `git-sizer` project](https://github.com/github/git-sizer).\n* Email us at [GitHub support](mailto:support@github.com).", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -46,9 +42,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2021-05-18T21:39:10Z", diff --git a/advisories/github-reviewed/2022/03/GHSA-fm35-jgg3-3grx/GHSA-fm35-jgg3-3grx.json b/advisories/github-reviewed/2022/03/GHSA-fm35-jgg3-3grx/GHSA-fm35-jgg3-3grx.json index 2eb60e4d07a..0af0109f5f7 100644 --- a/advisories/github-reviewed/2022/03/GHSA-fm35-jgg3-3grx/GHSA-fm35-jgg3-3grx.json +++ b/advisories/github-reviewed/2022/03/GHSA-fm35-jgg3-3grx/GHSA-fm35-jgg3-3grx.json @@ -3,9 +3,7 @@ "id": "GHSA-fm35-jgg3-3grx", "modified": "2022-03-18T17:54:38Z", "published": "2022-03-18T17:54:38Z", - "aliases": [ - - ], + "aliases": [], "summary": "NaN/INF in serverbound movement packets can crash clients and servers", "details": "### Impact\nA malicious client may send a `MovePlayerPacket` to the server whose position or rotation contains NaN or INF. Since neither the server nor vanilla client handles this properly, a number of interesting side effects come into play.\n\n- The server may crash in various ways if this exploit is used, because some mathematical operations on NaN/INF generate PHP warnings, which are converted into exceptions.\n- Clients may not be able to see other clients who have a NaN/INF rotation.\n- Clients may also crash in such cases.\n\n### Patches\nA patch for this was included in the 3.18.1 release: https://github.com/pmmp/PocketMine-MP/commit/fb20bb38327b4c08ee3976640cd0dd547388a638\n\n### Workarounds\nWorkarounds could be implemented as plugins using `DataPacketReceiveEvent` to block any inbound movement packets containing bogus values.\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n- Open an issue in [pmmp/PocketMine-MP](https://github.com/pmmp/PocketMine-MP)\n- Email us at [team@pmmp.io](mailto:team@pmmp.io)", "severity": [ diff --git a/advisories/github-reviewed/2022/05/GHSA-xh22-fw58-56pp/GHSA-xh22-fw58-56pp.json b/advisories/github-reviewed/2022/05/GHSA-xh22-fw58-56pp/GHSA-xh22-fw58-56pp.json index 2817cfbd3a6..468e91822c3 100644 --- a/advisories/github-reviewed/2022/05/GHSA-xh22-fw58-56pp/GHSA-xh22-fw58-56pp.json +++ b/advisories/github-reviewed/2022/05/GHSA-xh22-fw58-56pp/GHSA-xh22-fw58-56pp.json @@ -8,9 +8,7 @@ ], "summary": "Robocode Arbitrary Code Execution", "details": "The Event Dispatch Thread in Robocode before 1.5.1 allows remote attackers to execute arbitrary Java code by using a robot to invoke the `SwingUtilities.invokeLater` method.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/08/GHSA-8cwq-4cmf-px73/GHSA-8cwq-4cmf-px73.json b/advisories/github-reviewed/2022/08/GHSA-8cwq-4cmf-px73/GHSA-8cwq-4cmf-px73.json index 355d60ad013..53d5c64ab0f 100644 --- a/advisories/github-reviewed/2022/08/GHSA-8cwq-4cmf-px73/GHSA-8cwq-4cmf-px73.json +++ b/advisories/github-reviewed/2022/08/GHSA-8cwq-4cmf-px73/GHSA-8cwq-4cmf-px73.json @@ -3,9 +3,7 @@ "id": "GHSA-8cwq-4cmf-px73", "modified": "2022-08-18T19:19:21Z", "published": "2022-08-18T19:19:21Z", - "aliases": [ - - ], + "aliases": [], "summary": "PocketMine-MP invalid skin geometry JSON data leading to server crash", "details": "### Impact\n`pocketmine\\entity\\Skin` doesn't correctly handle errors produced by `adhocore/json-comment`, which throws `RuntimeException` rather than returning `false` as PocketMine-MP expects.\n\nThis leads to a server crash if the skin geometry data is invalid for some reason (e.g. a syntax error).\n\n### Patches\nc9626c610b8f6810c8c987559c9197b2a291f0bb\n\n### Workarounds\nA plugin could handle `LoginPacket` and `PlayerSkinPacket` to verify the skin geometry data can be parsed correctly, so that the error condition in the core code is never reached.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [security@pmmp.io](mailto:security@example.com)\n", "severity": [ @@ -50,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-08-18T19:19:21Z", diff --git a/advisories/github-reviewed/2022/09/GHSA-w8v7-c7pm-7wfr/GHSA-w8v7-c7pm-7wfr.json b/advisories/github-reviewed/2022/09/GHSA-w8v7-c7pm-7wfr/GHSA-w8v7-c7pm-7wfr.json index 6151fd02377..a874b966f50 100644 --- a/advisories/github-reviewed/2022/09/GHSA-w8v7-c7pm-7wfr/GHSA-w8v7-c7pm-7wfr.json +++ b/advisories/github-reviewed/2022/09/GHSA-w8v7-c7pm-7wfr/GHSA-w8v7-c7pm-7wfr.json @@ -4,9 +4,7 @@ "modified": "2022-09-23T16:29:56Z", "published": "2022-09-02T00:01:02Z", "withdrawn": "2022-09-23T16:29:56Z", - "aliases": [ - - ], + "aliases": [], "summary": "Duplicate Advisory: Keycloak vulnerable to Cross-Site Scripting (XSS)", "details": "## Duplicate Advisory\nThis advisory is a duplicate of [GHSA-w9mf-83w3-fv49](https://github.com/advisories/GHSA-w9mf-83w3-fv49). This link is maintained to preserve external references.\n\n## Original Description\nA stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This flaw allows a privileged attacker to execute malicious scripts in the admin console, abusing the default roles functionality.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-468j-6jrc-2rjx/GHSA-468j-6jrc-2rjx.json b/advisories/github-reviewed/2024/05/GHSA-468j-6jrc-2rjx/GHSA-468j-6jrc-2rjx.json index 69580f8357a..d075dcc9845 100644 --- a/advisories/github-reviewed/2024/05/GHSA-468j-6jrc-2rjx/GHSA-468j-6jrc-2rjx.json +++ b/advisories/github-reviewed/2024/05/GHSA-468j-6jrc-2rjx/GHSA-468j-6jrc-2rjx.json @@ -3,9 +3,7 @@ "id": "GHSA-468j-6jrc-2rjx", "modified": "2024-05-27T19:09:53Z", "published": "2024-05-27T19:09:53Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework vulnerable to Cross-site Scripting In `OptionsetField` and `CheckboxSetField`", "details": "List of key / value pairs assigned to `OptionsetField` or `CheckboxSetField` do not have a default casting assigned to them. The effect of this is a potential XSS vulnerability in lists where either key or value contain unescaped HTML.\n\n", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-4qx8-j9vh-2628/GHSA-4qx8-j9vh-2628.json b/advisories/github-reviewed/2024/05/GHSA-4qx8-j9vh-2628/GHSA-4qx8-j9vh-2628.json index 9dcb0ef2d16..7aede34be6a 100644 --- a/advisories/github-reviewed/2024/05/GHSA-4qx8-j9vh-2628/GHSA-4qx8-j9vh-2628.json +++ b/advisories/github-reviewed/2024/05/GHSA-4qx8-j9vh-2628/GHSA-4qx8-j9vh-2628.json @@ -3,9 +3,7 @@ "id": "GHSA-4qx8-j9vh-2628", "modified": "2024-05-27T20:35:31Z", "published": "2024-05-27T20:35:31Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework's User-Agent header not correctly invalidating user session", "details": "A security protection device in Session designed to protect session hijacking was not correctly functioning. This function intended to protect user sessions by detecting changes in the User-Agent header, but modifications to this header were not correctly invalidating the user session.\n\n", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-52cx-hpc5-cxwc/GHSA-52cx-hpc5-cxwc.json b/advisories/github-reviewed/2024/05/GHSA-52cx-hpc5-cxwc/GHSA-52cx-hpc5-cxwc.json index 4eef116d39f..d9f03d7f41a 100644 --- a/advisories/github-reviewed/2024/05/GHSA-52cx-hpc5-cxwc/GHSA-52cx-hpc5-cxwc.json +++ b/advisories/github-reviewed/2024/05/GHSA-52cx-hpc5-cxwc/GHSA-52cx-hpc5-cxwc.json @@ -3,9 +3,7 @@ "id": "GHSA-52cx-hpc5-cxwc", "modified": "2024-05-27T18:44:47Z", "published": "2024-05-27T18:44:47Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework missing ACL on reports", "details": "The SS_Report, and the reports CMS section only checks `canView()` when listing the reports that can be viewed by the current user.\n\nIt does not (and should) perform `canView` checks when the report is actually viewed, so if you know the URL to a report and can otherwise access the Reports section of the CMS, you can view any report.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-55qg-6c4m-mw6g/GHSA-55qg-6c4m-mw6g.json b/advisories/github-reviewed/2024/05/GHSA-55qg-6c4m-mw6g/GHSA-55qg-6c4m-mw6g.json index 37c82602896..5adace76fbe 100644 --- a/advisories/github-reviewed/2024/05/GHSA-55qg-6c4m-mw6g/GHSA-55qg-6c4m-mw6g.json +++ b/advisories/github-reviewed/2024/05/GHSA-55qg-6c4m-mw6g/GHSA-55qg-6c4m-mw6g.json @@ -3,9 +3,7 @@ "id": "GHSA-55qg-6c4m-mw6g", "modified": "2024-05-27T22:02:02Z", "published": "2024-05-27T22:02:02Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework's URL parameters `isDev` and `isTest` unguarded", "details": "The URL parameters `isDev` and `isTest` are accessible to unauthenticated users who access a SilverStripe website or application. This allows unauthorised users to expose information that is usually hidden on production environments such as verbose errors (including backtraces) and other debugging tools only available to sites running in \"dev mode\". Core functionality does not expose user data through these methods. Depending on your website configuration, community modules might have added more specific functionality which can be used to either access or alter user data.\n\nWe have fixed the usage of isDev and isTest in SilverStripe 4.x, and removed the URL parameters in the next major release of SilverStripe.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-5r8w-66hq-rc39/GHSA-5r8w-66hq-rc39.json b/advisories/github-reviewed/2024/05/GHSA-5r8w-66hq-rc39/GHSA-5r8w-66hq-rc39.json index a5611aefd40..613a63c1469 100644 --- a/advisories/github-reviewed/2024/05/GHSA-5r8w-66hq-rc39/GHSA-5r8w-66hq-rc39.json +++ b/advisories/github-reviewed/2024/05/GHSA-5r8w-66hq-rc39/GHSA-5r8w-66hq-rc39.json @@ -3,9 +3,7 @@ "id": "GHSA-5r8w-66hq-rc39", "modified": "2024-05-27T18:53:40Z", "published": "2024-05-27T18:53:40Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework's pre-existing alc_enc cookies log users in if remember me is disabled", "details": "If remember me is on and users log in with the box checked, if the developer then disabled \"remember me\" function, any pre-existing cookies will continue to authenticate users.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-7m2v-x7rg-5hm5/GHSA-7m2v-x7rg-5hm5.json b/advisories/github-reviewed/2024/05/GHSA-7m2v-x7rg-5hm5/GHSA-7m2v-x7rg-5hm5.json index 07c86d20589..39a37793973 100644 --- a/advisories/github-reviewed/2024/05/GHSA-7m2v-x7rg-5hm5/GHSA-7m2v-x7rg-5hm5.json +++ b/advisories/github-reviewed/2024/05/GHSA-7m2v-x7rg-5hm5/GHSA-7m2v-x7rg-5hm5.json @@ -3,14 +3,10 @@ "id": "GHSA-7m2v-x7rg-5hm5", "modified": "2024-05-27T21:45:27Z", "published": "2024-05-27T21:45:27Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework vulnerable to user enumeration via timing attack on login and password reset forms", "details": "User enumeration is possible by performing a timing attack on the login or password reset pages with user credentials.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -70,9 +66,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-05-27T21:45:27Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-c4c3-j73v-634r/GHSA-c4c3-j73v-634r.json b/advisories/github-reviewed/2024/05/GHSA-c4c3-j73v-634r/GHSA-c4c3-j73v-634r.json index 1a5f23d17e4..7c77d2db33f 100644 --- a/advisories/github-reviewed/2024/05/GHSA-c4c3-j73v-634r/GHSA-c4c3-j73v-634r.json +++ b/advisories/github-reviewed/2024/05/GHSA-c4c3-j73v-634r/GHSA-c4c3-j73v-634r.json @@ -3,14 +3,10 @@ "id": "GHSA-c4c3-j73v-634r", "modified": "2024-05-27T20:31:59Z", "published": "2024-05-27T20:31:59Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework has Cross-site Scripting vulnerability in page history comparison", "details": "Authenticated user with page edit permission can craft HTML, which when rendered in a page history comparison can execute client scripts.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -70,9 +66,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-05-27T20:31:59Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-crr3-h4m8-7f56/GHSA-crr3-h4m8-7f56.json b/advisories/github-reviewed/2024/05/GHSA-crr3-h4m8-7f56/GHSA-crr3-h4m8-7f56.json index 8c6c76f46a5..73fdd8ccd5a 100644 --- a/advisories/github-reviewed/2024/05/GHSA-crr3-h4m8-7f56/GHSA-crr3-h4m8-7f56.json +++ b/advisories/github-reviewed/2024/05/GHSA-crr3-h4m8-7f56/GHSA-crr3-h4m8-7f56.json @@ -3,9 +3,7 @@ "id": "GHSA-crr3-h4m8-7f56", "modified": "2024-05-27T23:23:51Z", "published": "2024-05-27T23:23:51Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework vulnerable to member disclosure in login form", "details": "There is a user ID enumeration vulnerability in our brute force error messages.\n\n- Users that don't exist in will never get a locked out message\n- Users that do exist, will get a locked out message\n\nThis means an attacker can infer or confirm user details that exist in the member table.\n\nThis issue has been resolved by ensuring that login attempt logging and lockout process works equivalently for non-existent users as it does for existant users.\n\nThis is a regression of [SS-2017-002](https://www.silverstripe.org/download/security-releases/ss-2017-002).", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-f3wp-xpv2-6vmg/GHSA-f3wp-xpv2-6vmg.json b/advisories/github-reviewed/2024/05/GHSA-f3wp-xpv2-6vmg/GHSA-f3wp-xpv2-6vmg.json index 2b254a3b2f2..fcb62532a25 100644 --- a/advisories/github-reviewed/2024/05/GHSA-f3wp-xpv2-6vmg/GHSA-f3wp-xpv2-6vmg.json +++ b/advisories/github-reviewed/2024/05/GHSA-f3wp-xpv2-6vmg/GHSA-f3wp-xpv2-6vmg.json @@ -3,14 +3,10 @@ "id": "GHSA-f3wp-xpv2-6vmg", "modified": "2024-05-27T18:33:04Z", "published": "2024-05-27T18:33:04Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework password encryption salt not updated", "details": "When a user changes their password, the internal salt used for hashing their password is not updated.\n\nAlthough this is not considered a security vulnerability, this behaviour has been improved to ensure the salt is reset on change of password.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -120,9 +116,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-05-27T18:33:04Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-f43j-8hq4-2xj9/GHSA-f43j-8hq4-2xj9.json b/advisories/github-reviewed/2024/05/GHSA-f43j-8hq4-2xj9/GHSA-f43j-8hq4-2xj9.json index ce0d66428b9..3850af97292 100644 --- a/advisories/github-reviewed/2024/05/GHSA-f43j-8hq4-2xj9/GHSA-f43j-8hq4-2xj9.json +++ b/advisories/github-reviewed/2024/05/GHSA-f43j-8hq4-2xj9/GHSA-f43j-8hq4-2xj9.json @@ -3,14 +3,10 @@ "id": "GHSA-f43j-8hq4-2xj9", "modified": "2024-05-27T23:16:00Z", "published": "2024-05-27T23:16:00Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework uploaded PHP script execution in assets", "details": "A weakness in the .htaccess rules preventing requests to uploaded PHP scripts allows PHP scripts that had made their way into the assets directory to be successfully executed through the use of a specially crafted URL. There are protections in place to disallow upload of PHP scripts through the CMS, meaning this weakness does not lead to direct vulnerabilities.\n\nIn addition, sites hosted on the New Zealand Common Web Platform or SilverStripe Platform have additional configuration in place which prevents PHP script execution in assets, even in a malicious party manages to upload these into the folder.\n\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/05/GHSA-frm9-7pm9-5rgc/GHSA-frm9-7pm9-5rgc.json b/advisories/github-reviewed/2024/05/GHSA-frm9-7pm9-5rgc/GHSA-frm9-7pm9-5rgc.json index a0c23e91c8b..6feefd7de2a 100644 --- a/advisories/github-reviewed/2024/05/GHSA-frm9-7pm9-5rgc/GHSA-frm9-7pm9-5rgc.json +++ b/advisories/github-reviewed/2024/05/GHSA-frm9-7pm9-5rgc/GHSA-frm9-7pm9-5rgc.json @@ -3,9 +3,7 @@ "id": "GHSA-frm9-7pm9-5rgc", "modified": "2024-05-27T18:24:02Z", "published": "2024-05-27T18:24:02Z", - "aliases": [ - - ], + "aliases": [], "summary": "SilverStripe comments module includes version of jQuery vulnerable to Cross-site Scripting", "details": "The silverstripe/comments module, the cwp/starter-theme and the cwp/watea-theme include an outdated version of jQuery by default, which contains XSS vulnerabilities if user input is used in certain contexts. Though no known exploit has been found for these in the existing usage, user customisation to these themes could have made them exploitable.\n\nCWP 2.0.0 has been released with the fixed cwp/stater-theme and silverstripe/comments module, and SilverStripe 4.2.0 will be released with the fixed silverstripe-themes/simple theme.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-g84q-cq55-xwgp/GHSA-g84q-cq55-xwgp.json b/advisories/github-reviewed/2024/05/GHSA-g84q-cq55-xwgp/GHSA-g84q-cq55-xwgp.json index 98458b18b55..b2b04e2a228 100644 --- a/advisories/github-reviewed/2024/05/GHSA-g84q-cq55-xwgp/GHSA-g84q-cq55-xwgp.json +++ b/advisories/github-reviewed/2024/05/GHSA-g84q-cq55-xwgp/GHSA-g84q-cq55-xwgp.json @@ -3,9 +3,7 @@ "id": "GHSA-g84q-cq55-xwgp", "modified": "2024-05-27T19:16:12Z", "published": "2024-05-27T19:16:12Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework member disclosure in login form", "details": "There is a user ID enumeration vulnerability in our brute force error messages.\n\n- Users that don't exist in will never get a locked out message\n- Users that do exist, will get a locked out message\n\nThis means an attacker can infer or confirm user details that exist in the member table.\n\nThis issue has been resolved by ensuring that login attempt logging and lockout process works equivalently for non-existent users as it does for existant users.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-hhvj-mcrx-3vcf/GHSA-hhvj-mcrx-3vcf.json b/advisories/github-reviewed/2024/05/GHSA-hhvj-mcrx-3vcf/GHSA-hhvj-mcrx-3vcf.json index 99455bcf8ec..1a9ff2677f8 100644 --- a/advisories/github-reviewed/2024/05/GHSA-hhvj-mcrx-3vcf/GHSA-hhvj-mcrx-3vcf.json +++ b/advisories/github-reviewed/2024/05/GHSA-hhvj-mcrx-3vcf/GHSA-hhvj-mcrx-3vcf.json @@ -3,9 +3,7 @@ "id": "GHSA-hhvj-mcrx-3vcf", "modified": "2024-05-27T19:32:44Z", "published": "2024-05-27T19:32:44Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework has Cross-site Scripting vulnerability in page name", "details": "silverstripe/framework is vulnerable to XSS in Page name where the payload `\">` will trigger an XSS alert.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-m5q3-mvcr-gc5m/GHSA-m5q3-mvcr-gc5m.json b/advisories/github-reviewed/2024/05/GHSA-m5q3-mvcr-gc5m/GHSA-m5q3-mvcr-gc5m.json index 80b582f76bc..53232673410 100644 --- a/advisories/github-reviewed/2024/05/GHSA-m5q3-mvcr-gc5m/GHSA-m5q3-mvcr-gc5m.json +++ b/advisories/github-reviewed/2024/05/GHSA-m5q3-mvcr-gc5m/GHSA-m5q3-mvcr-gc5m.json @@ -3,9 +3,7 @@ "id": "GHSA-m5q3-mvcr-gc5m", "modified": "2024-05-27T23:02:56Z", "published": "2024-05-27T23:02:56Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework BackURL validation bypass with malformed URLs", "details": "A carefully constructed malformed URL can be used to circumvent the offsite redirection protection used on `BackURL` parameters. This could lead to users entering sensitive data in malicious websites instead of the intended one.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-mqjc-x563-c9q8/GHSA-mqjc-x563-c9q8.json b/advisories/github-reviewed/2024/05/GHSA-mqjc-x563-c9q8/GHSA-mqjc-x563-c9q8.json index 16bdf86196c..bc8174d3908 100644 --- a/advisories/github-reviewed/2024/05/GHSA-mqjc-x563-c9q8/GHSA-mqjc-x563-c9q8.json +++ b/advisories/github-reviewed/2024/05/GHSA-mqjc-x563-c9q8/GHSA-mqjc-x563-c9q8.json @@ -3,9 +3,7 @@ "id": "GHSA-mqjc-x563-c9q8", "modified": "2024-05-27T21:48:19Z", "published": "2024-05-27T21:47:49Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework CSV Excel Macro Injection", "details": "In the CSV export feature of the CMS it's possible for the output to contain macros and scripts, which if imported without sanitisation into software (including Microsoft Excel) may be executed.\n\nIn order to safeguard against this threat all potentially executable cell values exported from CSV will be prepended with a literal tab character.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-p5h2-vr99-xm99/GHSA-p5h2-vr99-xm99.json b/advisories/github-reviewed/2024/05/GHSA-p5h2-vr99-xm99/GHSA-p5h2-vr99-xm99.json index 1e26d615310..b4a89bbb2d0 100644 --- a/advisories/github-reviewed/2024/05/GHSA-p5h2-vr99-xm99/GHSA-p5h2-vr99-xm99.json +++ b/advisories/github-reviewed/2024/05/GHSA-p5h2-vr99-xm99/GHSA-p5h2-vr99-xm99.json @@ -3,9 +3,7 @@ "id": "GHSA-p5h2-vr99-xm99", "modified": "2024-05-27T18:37:00Z", "published": "2024-05-27T18:36:59Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework ChangePasswordForm does not check `Member::canLogIn()`", "details": "After performing a password reset, `ChangePasswordForm::doChangePassword()` logs in the user without checking `Member::canLogIn()`. This presents an issue for sites that are using the extension point in that method to deny access to users (for example members that have not been “approved”, or members that have had their access revoked temporarily). It looks like `Member::canLogIn()` was originally designed to only be used for checking whether the user is locked out (due to too many incorrect login attempts) but has been opened up to other uses.\n\n", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-ph62-fv59-vf9h/GHSA-ph62-fv59-vf9h.json b/advisories/github-reviewed/2024/05/GHSA-ph62-fv59-vf9h/GHSA-ph62-fv59-vf9h.json index 018bdc40580..a23ef987bb2 100644 --- a/advisories/github-reviewed/2024/05/GHSA-ph62-fv59-vf9h/GHSA-ph62-fv59-vf9h.json +++ b/advisories/github-reviewed/2024/05/GHSA-ph62-fv59-vf9h/GHSA-ph62-fv59-vf9h.json @@ -3,9 +3,7 @@ "id": "GHSA-ph62-fv59-vf9h", "modified": "2024-05-27T21:50:44Z", "published": "2024-05-27T21:50:43Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework users inadvertently passing sensitive data to LoginAttempt", "details": "All user login attempts are logged in the database in the LoginAttempt table. However, this table contains information in plain text, and may possible contain sensitive information, such as user passwords mis-typed into the username field.\n\nIn order to address this a one-way hash is applied to the Email field before being stored.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-pp7q-6j3f-74vj/GHSA-pp7q-6j3f-74vj.json b/advisories/github-reviewed/2024/05/GHSA-pp7q-6j3f-74vj/GHSA-pp7q-6j3f-74vj.json index 7991127948f..f8517f39cf6 100644 --- a/advisories/github-reviewed/2024/05/GHSA-pp7q-6j3f-74vj/GHSA-pp7q-6j3f-74vj.json +++ b/advisories/github-reviewed/2024/05/GHSA-pp7q-6j3f-74vj/GHSA-pp7q-6j3f-74vj.json @@ -3,9 +3,7 @@ "id": "GHSA-pp7q-6j3f-74vj", "modified": "2024-05-27T20:05:34Z", "published": "2024-05-27T20:05:34Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework has Cross-site Scripting vulnerability in RedirectorPage", "details": "RedirectorPage will allow users to specify a non-url malicious script as the redirection path without validation. Users which follow this url may allow this script to execute within their browser.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-r3pr-fh25-wrfc/GHSA-r3pr-fh25-wrfc.json b/advisories/github-reviewed/2024/05/GHSA-r3pr-fh25-wrfc/GHSA-r3pr-fh25-wrfc.json index 708d6251b2c..3251d2f1dde 100644 --- a/advisories/github-reviewed/2024/05/GHSA-r3pr-fh25-wrfc/GHSA-r3pr-fh25-wrfc.json +++ b/advisories/github-reviewed/2024/05/GHSA-r3pr-fh25-wrfc/GHSA-r3pr-fh25-wrfc.json @@ -3,9 +3,7 @@ "id": "GHSA-r3pr-fh25-wrfc", "modified": "2024-05-27T22:54:06Z", "published": "2024-05-27T22:54:06Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework's install.php script discloses sensitive data by pre-populating DB credential forms", "details": "When accessing the `install.php` script it is possible to extract any pre-configured database or default admin account password by viewing the source of the page, and inspecting the `value` property of the password fields.\n\n", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-r85g-7jpv-8xrx/GHSA-r85g-7jpv-8xrx.json b/advisories/github-reviewed/2024/05/GHSA-r85g-7jpv-8xrx/GHSA-r85g-7jpv-8xrx.json index 876df9f2902..0aa1a1a17af 100644 --- a/advisories/github-reviewed/2024/05/GHSA-r85g-7jpv-8xrx/GHSA-r85g-7jpv-8xrx.json +++ b/advisories/github-reviewed/2024/05/GHSA-r85g-7jpv-8xrx/GHSA-r85g-7jpv-8xrx.json @@ -3,9 +3,7 @@ "id": "GHSA-r85g-7jpv-8xrx", "modified": "2024-05-27T20:05:27Z", "published": "2024-05-27T19:44:40Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework has Cross-site Scripting vulnerability in CMSSecurity BackURL", "details": "In follow up to [SS-2016-001](https://www.silverstripe.org/download/security-releases/ss-2016-001/) there is yet a minor unresolved fix to incorrectly encoded URL.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-r9vp-fp72-xgf7/GHSA-r9vp-fp72-xgf7.json b/advisories/github-reviewed/2024/05/GHSA-r9vp-fp72-xgf7/GHSA-r9vp-fp72-xgf7.json index a581d84253c..56766c6930f 100644 --- a/advisories/github-reviewed/2024/05/GHSA-r9vp-fp72-xgf7/GHSA-r9vp-fp72-xgf7.json +++ b/advisories/github-reviewed/2024/05/GHSA-r9vp-fp72-xgf7/GHSA-r9vp-fp72-xgf7.json @@ -3,9 +3,7 @@ "id": "GHSA-r9vp-fp72-xgf7", "modified": "2024-05-27T18:58:08Z", "published": "2024-05-27T18:58:08Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework's `Member.Name` is not escaped", "details": "The core template `framework/templates/Includes/GridField_print.ss` uses \"Printed by $Member.Name\".\n\nIf the currently logged in members first name or surname contain XSS, this prints the raw HTML out, because Member->getName() just returns the raw FirstName + Surname as a string, which is injected directly.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-vcg6-8fxc-x5cq/GHSA-vcg6-8fxc-x5cq.json b/advisories/github-reviewed/2024/05/GHSA-vcg6-8fxc-x5cq/GHSA-vcg6-8fxc-x5cq.json index bcf215abda4..cba97b408f3 100644 --- a/advisories/github-reviewed/2024/05/GHSA-vcg6-8fxc-x5cq/GHSA-vcg6-8fxc-x5cq.json +++ b/advisories/github-reviewed/2024/05/GHSA-vcg6-8fxc-x5cq/GHSA-vcg6-8fxc-x5cq.json @@ -3,9 +3,7 @@ "id": "GHSA-vcg6-8fxc-x5cq", "modified": "2024-05-27T23:35:14Z", "published": "2024-05-27T23:35:14Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework allows upload of dangerous file types", "details": "Some potentially dangerous file types exist in File.allowed_extensions which could allow a malicious CMS user to upload files that then get executed in the security context of the website. We have removed the ability to upload .css, .js, .potm, .dotm, .xltm and .jar files in the default configuration. Since allowed_extensions are synced to webserver configuration (in assets/.htaccess) automatically, this will also deny access to any existing uploads with these extensions.\n\nReview our security guidelines for the Common Web Platform and the File Security guide for SilverStripe 4 to find out how to add or remove extensions. ", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-vgxh-x8jv-hmff/GHSA-vgxh-x8jv-hmff.json b/advisories/github-reviewed/2024/05/GHSA-vgxh-x8jv-hmff/GHSA-vgxh-x8jv-hmff.json index 5ec3d68d7ed..b6a58db7310 100644 --- a/advisories/github-reviewed/2024/05/GHSA-vgxh-x8jv-hmff/GHSA-vgxh-x8jv-hmff.json +++ b/advisories/github-reviewed/2024/05/GHSA-vgxh-x8jv-hmff/GHSA-vgxh-x8jv-hmff.json @@ -3,9 +3,7 @@ "id": "GHSA-vgxh-x8jv-hmff", "modified": "2024-05-27T23:07:35Z", "published": "2024-05-27T23:07:35Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework code execution vulnerability", "details": "There is a vulnerability whereby arbitrary global functions may be executed if malicious user input is passed through to in the second argument of `ViewableData::renderWith`. This argument resolves associative arrays as template placeholders. This exploit requires that user code has been written which makes use of the second argument in `renderWith` and where user input is passed directly as a value in an associative array without sanitisation such as `Convert::raw2xml()`.\n\n`ViewableData::customise` is not vulnerable.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-vh7q-j8p5-2h4h/GHSA-vh7q-j8p5-2h4h.json b/advisories/github-reviewed/2024/05/GHSA-vh7q-j8p5-2h4h/GHSA-vh7q-j8p5-2h4h.json index 11c61c8da52..b11cf74cfdf 100644 --- a/advisories/github-reviewed/2024/05/GHSA-vh7q-j8p5-2h4h/GHSA-vh7q-j8p5-2h4h.json +++ b/advisories/github-reviewed/2024/05/GHSA-vh7q-j8p5-2h4h/GHSA-vh7q-j8p5-2h4h.json @@ -3,9 +3,7 @@ "id": "GHSA-vh7q-j8p5-2h4h", "modified": "2024-05-27T23:21:53Z", "published": "2024-05-27T23:21:53Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework sends passwords back to browsers under some circumstances", "details": "Under some circumstances a form may populate a PasswordField with submitted data, reflecting submitted data back to a user. The user will only see their own submissions for password data, which is not considered best practice. We are not aware of data leaks to other users, devices or sessions.", "severity": [ @@ -96,9 +94,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-05-27T23:21:53Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-xpff-c35g-j3cr/GHSA-xpff-c35g-j3cr.json b/advisories/github-reviewed/2024/05/GHSA-xpff-c35g-j3cr/GHSA-xpff-c35g-j3cr.json index 1ce0fada700..49b9a6c2b2e 100644 --- a/advisories/github-reviewed/2024/05/GHSA-xpff-c35g-j3cr/GHSA-xpff-c35g-j3cr.json +++ b/advisories/github-reviewed/2024/05/GHSA-xpff-c35g-j3cr/GHSA-xpff-c35g-j3cr.json @@ -3,9 +3,7 @@ "id": "GHSA-xpff-c35g-j3cr", "modified": "2024-05-27T22:28:13Z", "published": "2024-05-27T22:28:13Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework Privilege Escalation Risk in Member Edit form", "details": "A member with the permission `EDIT_PERMISSIONS` and access to the \"Security\" section is able to re-assign themselves (or another member) to `ADMIN` level.\n\nCMS Fields for the member are constructed using DirectGroups instead of Groups relation which results in bypassing security logic preventing privilege escalation.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-xx4r-5265-48j6/GHSA-xx4r-5265-48j6.json b/advisories/github-reviewed/2024/05/GHSA-xx4r-5265-48j6/GHSA-xx4r-5265-48j6.json index 71952ca86fd..05b4c7cb1b1 100644 --- a/advisories/github-reviewed/2024/05/GHSA-xx4r-5265-48j6/GHSA-xx4r-5265-48j6.json +++ b/advisories/github-reviewed/2024/05/GHSA-xx4r-5265-48j6/GHSA-xx4r-5265-48j6.json @@ -3,9 +3,7 @@ "id": "GHSA-xx4r-5265-48j6", "modified": "2024-05-27T21:53:33Z", "published": "2024-05-27T21:53:32Z", - "aliases": [ - - ], + "aliases": [], "summary": "silverstripe/framework SQL injection in full text search ", "details": "When performing a fulltext search in SilverStripe 4.0.0 the 'start' querystring parameter is never escaped safely. This exposes a possible SQL injection vulnerability.\n\nThe issue exists in 3.5 and 3.6 but is less vulnerable, as SearchForm sanitises these variables prior to passing to mysql.", "severity": [ diff --git a/advisories/unreviewed/2021/05/GHSA-m2h6-jxj8-4jqf/GHSA-m2h6-jxj8-4jqf.json b/advisories/unreviewed/2021/05/GHSA-m2h6-jxj8-4jqf/GHSA-m2h6-jxj8-4jqf.json index 9fd48bc7fc5..8016d197d59 100644 --- a/advisories/unreviewed/2021/05/GHSA-m2h6-jxj8-4jqf/GHSA-m2h6-jxj8-4jqf.json +++ b/advisories/unreviewed/2021/05/GHSA-m2h6-jxj8-4jqf/GHSA-m2h6-jxj8-4jqf.json @@ -14,9 +14,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:R" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-22j4-xx7v-8r2r/GHSA-22j4-xx7v-8r2r.json b/advisories/unreviewed/2022/05/GHSA-22j4-xx7v-8r2r/GHSA-22j4-xx7v-8r2r.json index 08a74fd3d80..32f6a98d9ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-22j4-xx7v-8r2r/GHSA-22j4-xx7v-8r2r.json +++ b/advisories/unreviewed/2022/05/GHSA-22j4-xx7v-8r2r/GHSA-22j4-xx7v-8r2r.json @@ -7,12 +7,8 @@ "CVE-2008-3752" ], "details": "SQL injection vulnerability in tr.php in YourFreeWorld Ad-Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-22p2-wgx4-4rg8/GHSA-22p2-wgx4-4rg8.json b/advisories/unreviewed/2022/05/GHSA-22p2-wgx4-4rg8/GHSA-22p2-wgx4-4rg8.json index e7ac2ac9f42..19386faf08d 100644 --- a/advisories/unreviewed/2022/05/GHSA-22p2-wgx4-4rg8/GHSA-22p2-wgx4-4rg8.json +++ b/advisories/unreviewed/2022/05/GHSA-22p2-wgx4-4rg8/GHSA-22p2-wgx4-4rg8.json @@ -7,12 +7,8 @@ "CVE-2008-4350" ], "details": "SQL injection vulnerability in main.php in vbLOGIX Tutorial Script 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-23r7-45cv-87cf/GHSA-23r7-45cv-87cf.json b/advisories/unreviewed/2022/05/GHSA-23r7-45cv-87cf/GHSA-23r7-45cv-87cf.json index 6825e405dc0..4410d7d983e 100644 --- a/advisories/unreviewed/2022/05/GHSA-23r7-45cv-87cf/GHSA-23r7-45cv-87cf.json +++ b/advisories/unreviewed/2022/05/GHSA-23r7-45cv-87cf/GHSA-23r7-45cv-87cf.json @@ -7,12 +7,8 @@ "CVE-2008-4170" ], "details": "create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob parameter, which reveals the installation path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2433-jm2h-c4v9/GHSA-2433-jm2h-c4v9.json b/advisories/unreviewed/2022/05/GHSA-2433-jm2h-c4v9/GHSA-2433-jm2h-c4v9.json index a1a81feaf5e..af5dcffe00e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2433-jm2h-c4v9/GHSA-2433-jm2h-c4v9.json +++ b/advisories/unreviewed/2022/05/GHSA-2433-jm2h-c4v9/GHSA-2433-jm2h-c4v9.json @@ -7,12 +7,8 @@ "CVE-2008-4327" ], "details": "gdiplus.dll in GDI+ in Microsoft Windows XP SP3 does not properly handle crafted .ico files, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a certain crash.ico file on a web site, and allows user-assisted attackers to cause a denial of service (divide-by-zero error and persistent application crash) via this crash.ico file on the desktop, a different vulnerability than CVE-2007-2237.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-244h-xwm8-582w/GHSA-244h-xwm8-582w.json b/advisories/unreviewed/2022/05/GHSA-244h-xwm8-582w/GHSA-244h-xwm8-582w.json index a5c424ac514..c9199dce5d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-244h-xwm8-582w/GHSA-244h-xwm8-582w.json +++ b/advisories/unreviewed/2022/05/GHSA-244h-xwm8-582w/GHSA-244h-xwm8-582w.json @@ -7,12 +7,8 @@ "CVE-2008-4346" ], "details": "Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.6.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to comments.php, a different vector than CVE-2008-3371.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-248c-9vj8-9325/GHSA-248c-9vj8-9325.json b/advisories/unreviewed/2022/05/GHSA-248c-9vj8-9325/GHSA-248c-9vj8-9325.json index 32ade239c35..923e1b7a147 100644 --- a/advisories/unreviewed/2022/05/GHSA-248c-9vj8-9325/GHSA-248c-9vj8-9325.json +++ b/advisories/unreviewed/2022/05/GHSA-248c-9vj8-9325/GHSA-248c-9vj8-9325.json @@ -7,12 +7,8 @@ "CVE-2008-4418" ], "details": "Unspecified vulnerability in DCE in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-254v-xjfq-x8gj/GHSA-254v-xjfq-x8gj.json b/advisories/unreviewed/2022/05/GHSA-254v-xjfq-x8gj/GHSA-254v-xjfq-x8gj.json index 33218c4fef1..1303301ca89 100644 --- a/advisories/unreviewed/2022/05/GHSA-254v-xjfq-x8gj/GHSA-254v-xjfq-x8gj.json +++ b/advisories/unreviewed/2022/05/GHSA-254v-xjfq-x8gj/GHSA-254v-xjfq-x8gj.json @@ -7,12 +7,8 @@ "CVE-2008-4334" ], "details": "PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the infouser cookie to 1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-26mj-pvmw-qq79/GHSA-26mj-pvmw-qq79.json b/advisories/unreviewed/2022/05/GHSA-26mj-pvmw-qq79/GHSA-26mj-pvmw-qq79.json index 4191efecbf4..f16e5dff49a 100644 --- a/advisories/unreviewed/2022/05/GHSA-26mj-pvmw-qq79/GHSA-26mj-pvmw-qq79.json +++ b/advisories/unreviewed/2022/05/GHSA-26mj-pvmw-qq79/GHSA-26mj-pvmw-qq79.json @@ -7,12 +7,8 @@ "CVE-2008-4281" ], "details": "Directory traversal vulnerability in VMWare ESXi 3.5 before ESXe350-200810401-O-UG and ESX 3.5 before ESX350-200810201-UG allows administrators with the Datastore.FileManagement privilege to gain privileges via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26wh-hvvw-2vc6/GHSA-26wh-hvvw-2vc6.json b/advisories/unreviewed/2022/05/GHSA-26wh-hvvw-2vc6/GHSA-26wh-hvvw-2vc6.json index fd92a8a6c30..fa49264cba0 100644 --- a/advisories/unreviewed/2022/05/GHSA-26wh-hvvw-2vc6/GHSA-26wh-hvvw-2vc6.json +++ b/advisories/unreviewed/2022/05/GHSA-26wh-hvvw-2vc6/GHSA-26wh-hvvw-2vc6.json @@ -7,12 +7,8 @@ "CVE-2008-3992" ], "details": "Unspecified vulnerability in the Oracle Data Mining component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related to DMSYS.DBMS_DM_EXP_INTERNAL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-279p-29gw-62v2/GHSA-279p-29gw-62v2.json b/advisories/unreviewed/2022/05/GHSA-279p-29gw-62v2/GHSA-279p-29gw-62v2.json index 034370b5df1..aea7327cbc5 100644 --- a/advisories/unreviewed/2022/05/GHSA-279p-29gw-62v2/GHSA-279p-29gw-62v2.json +++ b/advisories/unreviewed/2022/05/GHSA-279p-29gw-62v2/GHSA-279p-29gw-62v2.json @@ -7,12 +7,8 @@ "CVE-2008-4138" ], "details": "PHP remote file inclusion vulnerability in skin_shop/standard/3_plugin_twindow/twindow_notice.php in TECHNOTE 7 allows remote attackers to execute arbitrary PHP code via a URL in the shop_this_skin_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-27x4-2pj4-vg94/GHSA-27x4-2pj4-vg94.json b/advisories/unreviewed/2022/05/GHSA-27x4-2pj4-vg94/GHSA-27x4-2pj4-vg94.json index 7b8901aceea..f33bf7ccae8 100644 --- a/advisories/unreviewed/2022/05/GHSA-27x4-2pj4-vg94/GHSA-27x4-2pj4-vg94.json +++ b/advisories/unreviewed/2022/05/GHSA-27x4-2pj4-vg94/GHSA-27x4-2pj4-vg94.json @@ -7,12 +7,8 @@ "CVE-2008-4127" ], "details": "Mshtml.dll in Microsoft Internet Explorer 7 Gold 7.0.5730 and 8 Beta 8.0.6001 on Windows XP SP2 allows remote attackers to cause a denial of service (failure of subsequent image rendering) via a crafted PNG file, related to an infinite loop in the CDwnTaskExec::ThreadExec function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-284r-cvrc-f2f2/GHSA-284r-cvrc-f2f2.json b/advisories/unreviewed/2022/05/GHSA-284r-cvrc-f2f2/GHSA-284r-cvrc-f2f2.json index c49a8e09c15..e83be72d060 100644 --- a/advisories/unreviewed/2022/05/GHSA-284r-cvrc-f2f2/GHSA-284r-cvrc-f2f2.json +++ b/advisories/unreviewed/2022/05/GHSA-284r-cvrc-f2f2/GHSA-284r-cvrc-f2f2.json @@ -7,12 +7,8 @@ "CVE-2008-4110" ], "details": "Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\\Binn\\sqlvdir.dll in Microsoft SQL Server 2000 (aka SQL Server 8.0) allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long URL in the second argument to the Connect method. NOTE: this issue is not a vulnerability in many environments, since the control is not marked as safe for scripting and would not execute with default Internet Explorer settings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2893-m78m-w7qf/GHSA-2893-m78m-w7qf.json b/advisories/unreviewed/2022/05/GHSA-2893-m78m-w7qf/GHSA-2893-m78m-w7qf.json index 3f67185fd75..0b8fcfbce57 100644 --- a/advisories/unreviewed/2022/05/GHSA-2893-m78m-w7qf/GHSA-2893-m78m-w7qf.json +++ b/advisories/unreviewed/2022/05/GHSA-2893-m78m-w7qf/GHSA-2893-m78m-w7qf.json @@ -7,12 +7,8 @@ "CVE-2008-4296" ], "details": "The Cisco Linksys WRT350N with firmware 1.0.3.7 has \"admin\" as its default password for the \"admin\" account, which makes it easier for remote attackers to obtain access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-29rj-2cw9-cfcm/GHSA-29rj-2cw9-cfcm.json b/advisories/unreviewed/2022/05/GHSA-29rj-2cw9-cfcm/GHSA-29rj-2cw9-cfcm.json index f46b0009077..c8bd510da18 100644 --- a/advisories/unreviewed/2022/05/GHSA-29rj-2cw9-cfcm/GHSA-29rj-2cw9-cfcm.json +++ b/advisories/unreviewed/2022/05/GHSA-29rj-2cw9-cfcm/GHSA-29rj-2cw9-cfcm.json @@ -7,12 +7,8 @@ "CVE-2008-4322" ], "details": "Stack-based buffer overflow in RealFlex Technologies Ltd. RealWin Server 2.0, as distributed by DATAC, allows remote attackers to execute arbitrary code via a crafted FC_INFOTAG/SET_CONTROL packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2cgv-7m8h-63j7/GHSA-2cgv-7m8h-63j7.json b/advisories/unreviewed/2022/05/GHSA-2cgv-7m8h-63j7/GHSA-2cgv-7m8h-63j7.json index 11525c52652..df17a45fd1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cgv-7m8h-63j7/GHSA-2cgv-7m8h-63j7.json +++ b/advisories/unreviewed/2022/05/GHSA-2cgv-7m8h-63j7/GHSA-2cgv-7m8h-63j7.json @@ -7,12 +7,8 @@ "CVE-2008-4295" ], "details": "Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot) by configuring a Bluetooth device with a long hci name and (1) connecting directly to the Windows Mobile system or (2) waiting for the Windows Mobile system to scan for nearby devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2chw-fcm5-6h7p/GHSA-2chw-fcm5-6h7p.json b/advisories/unreviewed/2022/05/GHSA-2chw-fcm5-6h7p/GHSA-2chw-fcm5-6h7p.json index 7fd3c2ff205..2bf245f897f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2chw-fcm5-6h7p/GHSA-2chw-fcm5-6h7p.json +++ b/advisories/unreviewed/2022/05/GHSA-2chw-fcm5-6h7p/GHSA-2chw-fcm5-6h7p.json @@ -7,12 +7,8 @@ "CVE-2008-3727" ], "details": "Directory traversal vulnerability in Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2crh-858w-x2v9/GHSA-2crh-858w-x2v9.json b/advisories/unreviewed/2022/05/GHSA-2crh-858w-x2v9/GHSA-2crh-858w-x2v9.json index bfacaeb412b..6f117a761ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-2crh-858w-x2v9/GHSA-2crh-858w-x2v9.json +++ b/advisories/unreviewed/2022/05/GHSA-2crh-858w-x2v9/GHSA-2crh-858w-x2v9.json @@ -7,12 +7,8 @@ "CVE-2008-3955" ], "details": "SQL injection vulnerability in index.php in Masir Camp E-Shop Module 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ordercode parameter in a veiworderstatus page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fqf-xc87-725c/GHSA-2fqf-xc87-725c.json b/advisories/unreviewed/2022/05/GHSA-2fqf-xc87-725c/GHSA-2fqf-xc87-725c.json index 3ef1af5036b..60b62d350e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fqf-xc87-725c/GHSA-2fqf-xc87-725c.json +++ b/advisories/unreviewed/2022/05/GHSA-2fqf-xc87-725c/GHSA-2fqf-xc87-725c.json @@ -7,12 +7,8 @@ "CVE-2008-3744" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.10 and 6.x before 6.4 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) delete user access rules.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fxq-9xq8-p8r9/GHSA-2fxq-9xq8-p8r9.json b/advisories/unreviewed/2022/05/GHSA-2fxq-9xq8-p8r9/GHSA-2fxq-9xq8-p8r9.json index 02f4fab86b7..6e9c63456cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fxq-9xq8-p8r9/GHSA-2fxq-9xq8-p8r9.json +++ b/advisories/unreviewed/2022/05/GHSA-2fxq-9xq8-p8r9/GHSA-2fxq-9xq8-p8r9.json @@ -7,12 +7,8 @@ "CVE-2008-4003" ], "details": "Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.18 and 8.49.14 allows remote attackers to affect confidentiality via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2gqj-jjm7-f6m7/GHSA-2gqj-jjm7-f6m7.json b/advisories/unreviewed/2022/05/GHSA-2gqj-jjm7-f6m7/GHSA-2gqj-jjm7-f6m7.json index 784b4590bde..f360de6a17f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gqj-jjm7-f6m7/GHSA-2gqj-jjm7-f6m7.json +++ b/advisories/unreviewed/2022/05/GHSA-2gqj-jjm7-f6m7/GHSA-2gqj-jjm7-f6m7.json @@ -7,12 +7,8 @@ "CVE-2008-4101" ], "details": "Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a \";\" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) \"Ctrl-]\" (control close-square-bracket) or (3) \"g]\" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2jg2-7q2w-m8v7/GHSA-2jg2-7q2w-m8v7.json b/advisories/unreviewed/2022/05/GHSA-2jg2-7q2w-m8v7/GHSA-2jg2-7q2w-m8v7.json index f6577660186..2822b674a13 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jg2-7q2w-m8v7/GHSA-2jg2-7q2w-m8v7.json +++ b/advisories/unreviewed/2022/05/GHSA-2jg2-7q2w-m8v7/GHSA-2jg2-7q2w-m8v7.json @@ -7,12 +7,8 @@ "CVE-2008-3937" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) user_id parameter in an edit action to user_admin.php, the (2) title parameter to listings.php, and the (3) redirect_url parameter to user_profile.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2jjh-v97q-pjgc/GHSA-2jjh-v97q-pjgc.json b/advisories/unreviewed/2022/05/GHSA-2jjh-v97q-pjgc/GHSA-2jjh-v97q-pjgc.json index 5a5dbea41b7..b6a95e9db59 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jjh-v97q-pjgc/GHSA-2jjh-v97q-pjgc.json +++ b/advisories/unreviewed/2022/05/GHSA-2jjh-v97q-pjgc/GHSA-2jjh-v97q-pjgc.json @@ -7,12 +7,8 @@ "CVE-2008-3898" ], "details": "Secu Star DriveCrypt Plus Pack 3.9 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2m26-jxg5-74r8/GHSA-2m26-jxg5-74r8.json b/advisories/unreviewed/2022/05/GHSA-2m26-jxg5-74r8/GHSA-2m26-jxg5-74r8.json index eb4c30dbc07..a4a1d96de00 100644 --- a/advisories/unreviewed/2022/05/GHSA-2m26-jxg5-74r8/GHSA-2m26-jxg5-74r8.json +++ b/advisories/unreviewed/2022/05/GHSA-2m26-jxg5-74r8/GHSA-2m26-jxg5-74r8.json @@ -7,12 +7,8 @@ "CVE-2008-3873" ], "details": "The System.setClipboard method in ActionScript in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to populate the clipboard with a URL that is difficult to delete and does not require user interaction to populate the clipboard, as exploited in the wild in August 2008.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -108,9 +104,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2mrq-pgfw-gj9v/GHSA-2mrq-pgfw-gj9v.json b/advisories/unreviewed/2022/05/GHSA-2mrq-pgfw-gj9v/GHSA-2mrq-pgfw-gj9v.json index 9d59836a66b..c0ea808e37f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mrq-pgfw-gj9v/GHSA-2mrq-pgfw-gj9v.json +++ b/advisories/unreviewed/2022/05/GHSA-2mrq-pgfw-gj9v/GHSA-2mrq-pgfw-gj9v.json @@ -7,12 +7,8 @@ "CVE-2008-4202" ], "details": "SQL injection vulnerability in index.php in Gonafish LinksCaffePRO 4.5 allows remote attackers to execute arbitrary SQL commands via the idd parameter in a deadlink action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2p5r-59p2-7m73/GHSA-2p5r-59p2-7m73.json b/advisories/unreviewed/2022/05/GHSA-2p5r-59p2-7m73/GHSA-2p5r-59p2-7m73.json index bec13032b57..73e19daf1d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-2p5r-59p2-7m73/GHSA-2p5r-59p2-7m73.json +++ b/advisories/unreviewed/2022/05/GHSA-2p5r-59p2-7m73/GHSA-2p5r-59p2-7m73.json @@ -7,12 +7,8 @@ "CVE-2008-4232" ], "details": "Safari in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.1 through 2.1 does not restrict an IFRAME's content display to the boundaries of the IFRAME, which allows remote attackers to spoof a user interface via a crafted HTML document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2rw3-m7rg-9xch/GHSA-2rw3-m7rg-9xch.json b/advisories/unreviewed/2022/05/GHSA-2rw3-m7rg-9xch/GHSA-2rw3-m7rg-9xch.json index a87441eaacd..4a0b3be396c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rw3-m7rg-9xch/GHSA-2rw3-m7rg-9xch.json +++ b/advisories/unreviewed/2022/05/GHSA-2rw3-m7rg-9xch/GHSA-2rw3-m7rg-9xch.json @@ -7,12 +7,8 @@ "CVE-2008-3823" ], "details": "Cross-site scripting (XSS) vulnerability in MIME/MIME/Contents.php in the MIME library in Horde 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via the filename of a MIME attachment in an e-mail message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2vvw-3422-x4g5/GHSA-2vvw-3422-x4g5.json b/advisories/unreviewed/2022/05/GHSA-2vvw-3422-x4g5/GHSA-2vvw-3422-x4g5.json index fca7d5a6185..ad7bd08471f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vvw-3422-x4g5/GHSA-2vvw-3422-x4g5.json +++ b/advisories/unreviewed/2022/05/GHSA-2vvw-3422-x4g5/GHSA-2vvw-3422-x4g5.json @@ -7,12 +7,8 @@ "CVE-2008-4132" ], "details": "Stack-based buffer overflow in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne VSFlexGrid 7.0.1.151 and 8.0.20072.239 allows remote attackers to execute arbitrary code via a long first argument to the Archive method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2wcv-w38q-52h8/GHSA-2wcv-w38q-52h8.json b/advisories/unreviewed/2022/05/GHSA-2wcv-w38q-52h8/GHSA-2wcv-w38q-52h8.json index e2c27f1a5b6..8e988ef266e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wcv-w38q-52h8/GHSA-2wcv-w38q-52h8.json +++ b/advisories/unreviewed/2022/05/GHSA-2wcv-w38q-52h8/GHSA-2wcv-w38q-52h8.json @@ -7,12 +7,8 @@ "CVE-2008-3803" ], "details": "A \"logic error\" in Cisco IOS 12.0 through 12.4, when a Multiprotocol Label Switching (MPLS) VPN with extended communities is configured, sometimes causes a corrupted route target (RT) to be used, which allows remote attackers to read traffic from other VPNs in opportunistic circumstances.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-32v4-2939-6235/GHSA-32v4-2939-6235.json b/advisories/unreviewed/2022/05/GHSA-32v4-2939-6235/GHSA-32v4-2939-6235.json index 72ddd2c3e56..077d76026eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-32v4-2939-6235/GHSA-32v4-2939-6235.json +++ b/advisories/unreviewed/2022/05/GHSA-32v4-2939-6235/GHSA-32v4-2939-6235.json @@ -7,12 +7,8 @@ "CVE-2008-3734" ], "details": "Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP servers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in a connection greeting (response).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-337j-2h57-4h8m/GHSA-337j-2h57-4h8m.json b/advisories/unreviewed/2022/05/GHSA-337j-2h57-4h8m/GHSA-337j-2h57-4h8m.json index b02bd511d49..3d2be039175 100644 --- a/advisories/unreviewed/2022/05/GHSA-337j-2h57-4h8m/GHSA-337j-2h57-4h8m.json +++ b/advisories/unreviewed/2022/05/GHSA-337j-2h57-4h8m/GHSA-337j-2h57-4h8m.json @@ -7,12 +7,8 @@ "CVE-2008-3741" ], "details": "The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTML.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-34h5-p5c9-pjw6/GHSA-34h5-p5c9-pjw6.json b/advisories/unreviewed/2022/05/GHSA-34h5-p5c9-pjw6/GHSA-34h5-p5c9-pjw6.json index f58b58ff67d..5dc1741285e 100644 --- a/advisories/unreviewed/2022/05/GHSA-34h5-p5c9-pjw6/GHSA-34h5-p5c9-pjw6.json +++ b/advisories/unreviewed/2022/05/GHSA-34h5-p5c9-pjw6/GHSA-34h5-p5c9-pjw6.json @@ -7,12 +7,8 @@ "CVE-2008-4409" ], "details": "libxml2 2.7.0 and 2.7.1 does not properly handle \"predefined entities definitions\" in entities, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash), as demonstrated by use of xmllint on a certain XML document, a different vulnerability than CVE-2003-1564 and CVE-2008-3281.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-34mg-6ppq-mw32/GHSA-34mg-6ppq-mw32.json b/advisories/unreviewed/2022/05/GHSA-34mg-6ppq-mw32/GHSA-34mg-6ppq-mw32.json index 0354624881f..309ccd6874d 100644 --- a/advisories/unreviewed/2022/05/GHSA-34mg-6ppq-mw32/GHSA-34mg-6ppq-mw32.json +++ b/advisories/unreviewed/2022/05/GHSA-34mg-6ppq-mw32/GHSA-34mg-6ppq-mw32.json @@ -7,12 +7,8 @@ "CVE-2008-4148" ], "details": "SQL injection vulnerability in the Mailhandler module 5.x before 5.x-1.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to composing queries without using the Drupal database API.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-357w-9vjc-5qxw/GHSA-357w-9vjc-5qxw.json b/advisories/unreviewed/2022/05/GHSA-357w-9vjc-5qxw/GHSA-357w-9vjc-5qxw.json index cc0a19e7afc..d1128f954fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-357w-9vjc-5qxw/GHSA-357w-9vjc-5qxw.json +++ b/advisories/unreviewed/2022/05/GHSA-357w-9vjc-5qxw/GHSA-357w-9vjc-5qxw.json @@ -7,12 +7,8 @@ "CVE-2008-4111" ], "details": "Unspecified vulnerability in Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when the FileServing feature is enabled, has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-359f-mc8p-j8g3/GHSA-359f-mc8p-j8g3.json b/advisories/unreviewed/2022/05/GHSA-359f-mc8p-j8g3/GHSA-359f-mc8p-j8g3.json index c890f3297b2..03773d47ad1 100644 --- a/advisories/unreviewed/2022/05/GHSA-359f-mc8p-j8g3/GHSA-359f-mc8p-j8g3.json +++ b/advisories/unreviewed/2022/05/GHSA-359f-mc8p-j8g3/GHSA-359f-mc8p-j8g3.json @@ -7,12 +7,8 @@ "CVE-2008-3835" ], "details": "The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -196,9 +192,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-35fc-6m3p-h4pm/GHSA-35fc-6m3p-h4pm.json b/advisories/unreviewed/2022/05/GHSA-35fc-6m3p-h4pm/GHSA-35fc-6m3p-h4pm.json index 57bd0dd3af8..0db82fc21a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-35fc-6m3p-h4pm/GHSA-35fc-6m3p-h4pm.json +++ b/advisories/unreviewed/2022/05/GHSA-35fc-6m3p-h4pm/GHSA-35fc-6m3p-h4pm.json @@ -7,12 +7,8 @@ "CVE-2008-3843" ], "details": "Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework with the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a query string containing a \"<~/\" (less-than tilde slash) sequence followed by a crafted STYLE element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35vx-q8fx-9jg2/GHSA-35vx-q8fx-9jg2.json b/advisories/unreviewed/2022/05/GHSA-35vx-q8fx-9jg2/GHSA-35vx-q8fx-9jg2.json index fac618307d2..353b43b4188 100644 --- a/advisories/unreviewed/2022/05/GHSA-35vx-q8fx-9jg2/GHSA-35vx-q8fx-9jg2.json +++ b/advisories/unreviewed/2022/05/GHSA-35vx-q8fx-9jg2/GHSA-35vx-q8fx-9jg2.json @@ -7,12 +7,8 @@ "CVE-2008-4146" ], "details": "Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field and (2) change the visit-counter value via a modified counter field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35wv-xg96-7j37/GHSA-35wv-xg96-7j37.json b/advisories/unreviewed/2022/05/GHSA-35wv-xg96-7j37/GHSA-35wv-xg96-7j37.json index 8e74b74a13f..140a6876ef1 100644 --- a/advisories/unreviewed/2022/05/GHSA-35wv-xg96-7j37/GHSA-35wv-xg96-7j37.json +++ b/advisories/unreviewed/2022/05/GHSA-35wv-xg96-7j37/GHSA-35wv-xg96-7j37.json @@ -7,12 +7,8 @@ "CVE-2008-4095" ], "details": "Multiple unspecified vulnerabilities in the Importer in Flip4Mac WMV before 2.2.1 have unknown impact and attack vectors, different vulnerabilities than CVE-2007-6713.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-365m-qv8p-499g/GHSA-365m-qv8p-499g.json b/advisories/unreviewed/2022/05/GHSA-365m-qv8p-499g/GHSA-365m-qv8p-499g.json index 037ff97db17..01e83f17801 100644 --- a/advisories/unreviewed/2022/05/GHSA-365m-qv8p-499g/GHSA-365m-qv8p-499g.json +++ b/advisories/unreviewed/2022/05/GHSA-365m-qv8p-499g/GHSA-365m-qv8p-499g.json @@ -7,12 +7,8 @@ "CVE-2008-3977" ], "details": "Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3 and 10.1.2.3 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2008-3975.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-36pp-4rh2-v5mh/GHSA-36pp-4rh2-v5mh.json b/advisories/unreviewed/2022/05/GHSA-36pp-4rh2-v5mh/GHSA-36pp-4rh2-v5mh.json index 4bd58e5aef2..6ce72084322 100644 --- a/advisories/unreviewed/2022/05/GHSA-36pp-4rh2-v5mh/GHSA-36pp-4rh2-v5mh.json +++ b/advisories/unreviewed/2022/05/GHSA-36pp-4rh2-v5mh/GHSA-36pp-4rh2-v5mh.json @@ -7,12 +7,8 @@ "CVE-2008-3925" ], "details": "Cross-site request forgery (CSRF) vulnerability in admin.php in Content Management Made Easy (CMME) 1.12 allows remote attackers to trigger the logout of an administrative user via a logout action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-385r-vgx4-4g7p/GHSA-385r-vgx4-4g7p.json b/advisories/unreviewed/2022/05/GHSA-385r-vgx4-4g7p/GHSA-385r-vgx4-4g7p.json index 2f1f7f11f09..7c88a05cdf5 100644 --- a/advisories/unreviewed/2022/05/GHSA-385r-vgx4-4g7p/GHSA-385r-vgx4-4g7p.json +++ b/advisories/unreviewed/2022/05/GHSA-385r-vgx4-4g7p/GHSA-385r-vgx4-4g7p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-388g-xpph-h5rv/GHSA-388g-xpph-h5rv.json b/advisories/unreviewed/2022/05/GHSA-388g-xpph-h5rv/GHSA-388g-xpph-h5rv.json index bda8586f0ce..4fe1d474faf 100644 --- a/advisories/unreviewed/2022/05/GHSA-388g-xpph-h5rv/GHSA-388g-xpph-h5rv.json +++ b/advisories/unreviewed/2022/05/GHSA-388g-xpph-h5rv/GHSA-388g-xpph-h5rv.json @@ -7,12 +7,8 @@ "CVE-2008-4318" ], "details": "Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter to (1) whois.php or (2) netcmd.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-38w6-5xg5-v683/GHSA-38w6-5xg5-v683.json b/advisories/unreviewed/2022/05/GHSA-38w6-5xg5-v683/GHSA-38w6-5xg5-v683.json index 2328819660f..f00d7960ebe 100644 --- a/advisories/unreviewed/2022/05/GHSA-38w6-5xg5-v683/GHSA-38w6-5xg5-v683.json +++ b/advisories/unreviewed/2022/05/GHSA-38w6-5xg5-v683/GHSA-38w6-5xg5-v683.json @@ -7,12 +7,8 @@ "CVE-2008-3895" ], "details": "LILO 22.6.1 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-39jc-3grc-wm33/GHSA-39jc-3grc-wm33.json b/advisories/unreviewed/2022/05/GHSA-39jc-3grc-wm33/GHSA-39jc-3grc-wm33.json index c3d0dc413de..51e69ab620c 100644 --- a/advisories/unreviewed/2022/05/GHSA-39jc-3grc-wm33/GHSA-39jc-3grc-wm33.json +++ b/advisories/unreviewed/2022/05/GHSA-39jc-3grc-wm33/GHSA-39jc-3grc-wm33.json @@ -7,12 +7,8 @@ "CVE-2008-4314" ], "details": "smbd in Samba 3.0.29 through 3.2.4 might allow remote attackers to read arbitrary memory and cause a denial of service via crafted (1) trans, (2) trans2, and (3) nttrans requests, related to a \"cut&paste error\" that causes an improper bounds check to be performed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3cg3-w3v4-rw4g/GHSA-3cg3-w3v4-rw4g.json b/advisories/unreviewed/2022/05/GHSA-3cg3-w3v4-rw4g/GHSA-3cg3-w3v4-rw4g.json index 65272018001..cacc9bf08e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cg3-w3v4-rw4g/GHSA-3cg3-w3v4-rw4g.json +++ b/advisories/unreviewed/2022/05/GHSA-3cg3-w3v4-rw4g/GHSA-3cg3-w3v4-rw4g.json @@ -7,12 +7,8 @@ "CVE-2008-3890" ], "details": "The kernel in FreeBSD 6.3 through 7.0 on amd64 platforms can make an extra swapgs call after a General Protection Fault (GPF), which allows local users to gain privileges by triggering a GPF during the kernel's return from (1) an interrupt, (2) a trap, or (3) a system call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3cvq-c558-wxw2/GHSA-3cvq-c558-wxw2.json b/advisories/unreviewed/2022/05/GHSA-3cvq-c558-wxw2/GHSA-3cvq-c558-wxw2.json index 65bece0c11a..0dd45b7327b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cvq-c558-wxw2/GHSA-3cvq-c558-wxw2.json +++ b/advisories/unreviewed/2022/05/GHSA-3cvq-c558-wxw2/GHSA-3cvq-c558-wxw2.json @@ -7,12 +7,8 @@ "CVE-2008-4410" ], "details": "The vmi_write_ldt_entry function in arch/x86/kernel/vmi_32.c in the Virtual Machine Interface (VMI) in the Linux kernel 2.6.26.5 invokes write_idt_entry where write_ldt_entry was intended, which allows local users to cause a denial of service (persistent application failure) via crafted function calls, related to the Java Runtime Environment (JRE) experiencing improper LDT selector state, a different vulnerability than CVE-2008-3247.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3f52-g2gw-29vq/GHSA-3f52-g2gw-29vq.json b/advisories/unreviewed/2022/05/GHSA-3f52-g2gw-29vq/GHSA-3f52-g2gw-29vq.json index 729a6ba39ae..9df26d4e127 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f52-g2gw-29vq/GHSA-3f52-g2gw-29vq.json +++ b/advisories/unreviewed/2022/05/GHSA-3f52-g2gw-29vq/GHSA-3f52-g2gw-29vq.json @@ -7,12 +7,8 @@ "CVE-2008-4397" ], "details": "Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to execute arbitrary commands via a .. (dot dot) in an RPC call with opnum 0x10A.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3j28-7p57-m6c7/GHSA-3j28-7p57-m6c7.json b/advisories/unreviewed/2022/05/GHSA-3j28-7p57-m6c7/GHSA-3j28-7p57-m6c7.json index d033e746956..a0f8bc2a313 100644 --- a/advisories/unreviewed/2022/05/GHSA-3j28-7p57-m6c7/GHSA-3j28-7p57-m6c7.json +++ b/advisories/unreviewed/2022/05/GHSA-3j28-7p57-m6c7/GHSA-3j28-7p57-m6c7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jpr-9ppp-96gp/GHSA-3jpr-9ppp-96gp.json b/advisories/unreviewed/2022/05/GHSA-3jpr-9ppp-96gp/GHSA-3jpr-9ppp-96gp.json index 262044cbfee..7db2f29b717 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jpr-9ppp-96gp/GHSA-3jpr-9ppp-96gp.json +++ b/advisories/unreviewed/2022/05/GHSA-3jpr-9ppp-96gp/GHSA-3jpr-9ppp-96gp.json @@ -7,12 +7,8 @@ "CVE-2008-4164" ], "details": "cron.php in MemHT Portal 3.9.0 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3m66-pp93-mgcg/GHSA-3m66-pp93-mgcg.json b/advisories/unreviewed/2022/05/GHSA-3m66-pp93-mgcg/GHSA-3m66-pp93-mgcg.json index a322f6c2ae9..5233e668dfb 100644 --- a/advisories/unreviewed/2022/05/GHSA-3m66-pp93-mgcg/GHSA-3m66-pp93-mgcg.json +++ b/advisories/unreviewed/2022/05/GHSA-3m66-pp93-mgcg/GHSA-3m66-pp93-mgcg.json @@ -7,12 +7,8 @@ "CVE-2008-4181" ], "details": "Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for cPanel, when cPanel PHP Register Globals is enabled, allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) or absolute pathname in the fantasticopath parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3p4h-q8jp-6m7v/GHSA-3p4h-q8jp-6m7v.json b/advisories/unreviewed/2022/05/GHSA-3p4h-q8jp-6m7v/GHSA-3p4h-q8jp-6m7v.json index 71d62947982..713ffd4fb7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3p4h-q8jp-6m7v/GHSA-3p4h-q8jp-6m7v.json +++ b/advisories/unreviewed/2022/05/GHSA-3p4h-q8jp-6m7v/GHSA-3p4h-q8jp-6m7v.json @@ -7,12 +7,8 @@ "CVE-2008-4320" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.5.94 allow remote attackers to inject arbitrary web script or HTML via (1) the j_username parameter to j_acegi_security_check, (2) the username parameter to notification/list.jsp, and (3) the filter parameter to event/list.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qp2-xpxj-256j/GHSA-3qp2-xpxj-256j.json b/advisories/unreviewed/2022/05/GHSA-3qp2-xpxj-256j/GHSA-3qp2-xpxj-256j.json index ac39a562706..c6a328ec719 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qp2-xpxj-256j/GHSA-3qp2-xpxj-256j.json +++ b/advisories/unreviewed/2022/05/GHSA-3qp2-xpxj-256j/GHSA-3qp2-xpxj-256j.json @@ -7,12 +7,8 @@ "CVE-2008-4191" ], "details": "extract-table.pl in Emacspeak 26 and 28 allows local users to overwrite arbitrary files via a symlink attack on the extract-table.csv temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qqv-3pw4-j3wj/GHSA-3qqv-3pw4-j3wj.json b/advisories/unreviewed/2022/05/GHSA-3qqv-3pw4-j3wj/GHSA-3qqv-3pw4-j3wj.json index 7f5785ca980..85785505792 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qqv-3pw4-j3wj/GHSA-3qqv-3pw4-j3wj.json +++ b/advisories/unreviewed/2022/05/GHSA-3qqv-3pw4-j3wj/GHSA-3qqv-3pw4-j3wj.json @@ -7,12 +7,8 @@ "CVE-2008-4224" ], "details": "UDF in Apple Mac OS X before 10.5.6 allows user-assisted attackers to cause a denial of service (system crash) via a malformed UDF volume in a crafted ISO file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qxg-frxh-f5j5/GHSA-3qxg-frxh-f5j5.json b/advisories/unreviewed/2022/05/GHSA-3qxg-frxh-f5j5/GHSA-3qxg-frxh-f5j5.json index f80a1f3c4e7..fdbb78b1cc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qxg-frxh-f5j5/GHSA-3qxg-frxh-f5j5.json +++ b/advisories/unreviewed/2022/05/GHSA-3qxg-frxh-f5j5/GHSA-3qxg-frxh-f5j5.json @@ -7,12 +7,8 @@ "CVE-2008-3914" ], "details": "Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the \"error path\" in (1) libclamav/others.c and (2) libclamav/sis.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3r3r-2438-9jg4/GHSA-3r3r-2438-9jg4.json b/advisories/unreviewed/2022/05/GHSA-3r3r-2438-9jg4/GHSA-3r3r-2438-9jg4.json index a7dc859cf1d..ccd4927df37 100644 --- a/advisories/unreviewed/2022/05/GHSA-3r3r-2438-9jg4/GHSA-3r3r-2438-9jg4.json +++ b/advisories/unreviewed/2022/05/GHSA-3r3r-2438-9jg4/GHSA-3r3r-2438-9jg4.json @@ -7,12 +7,8 @@ "CVE-2008-3739" ], "details": "Cross-site scripting (XSS) vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving upload of files containing XSS sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3rfr-67g3-3ffq/GHSA-3rfr-67g3-3ffq.json b/advisories/unreviewed/2022/05/GHSA-3rfr-67g3-3ffq/GHSA-3rfr-67g3-3ffq.json index 778ad1f0bec..2a55cc4220a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rfr-67g3-3ffq/GHSA-3rfr-67g3-3ffq.json +++ b/advisories/unreviewed/2022/05/GHSA-3rfr-67g3-3ffq/GHSA-3rfr-67g3-3ffq.json @@ -7,12 +7,8 @@ "CVE-2008-4141" ], "details": "Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the web_root parameter to (1) includes/function_core.php and (2) templates/layout_lyrics.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3v68-r58v-m4c2/GHSA-3v68-r58v-m4c2.json b/advisories/unreviewed/2022/05/GHSA-3v68-r58v-m4c2/GHSA-3v68-r58v-m4c2.json index ddafaaec687..dd53afea049 100644 --- a/advisories/unreviewed/2022/05/GHSA-3v68-r58v-m4c2/GHSA-3v68-r58v-m4c2.json +++ b/advisories/unreviewed/2022/05/GHSA-3v68-r58v-m4c2/GHSA-3v68-r58v-m4c2.json @@ -7,12 +7,8 @@ "CVE-2008-4250" ], "details": "The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka \"Server Service Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wj5-57jg-38cx/GHSA-3wj5-57jg-38cx.json b/advisories/unreviewed/2022/05/GHSA-3wj5-57jg-38cx/GHSA-3wj5-57jg-38cx.json index b732ac27117..737522c8fcd 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wj5-57jg-38cx/GHSA-3wj5-57jg-38cx.json +++ b/advisories/unreviewed/2022/05/GHSA-3wj5-57jg-38cx/GHSA-3wj5-57jg-38cx.json @@ -7,12 +7,8 @@ "CVE-2008-4062" ], "details": "Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine and (1) misinterpretation of the characteristics of Namespace and QName in jsxml.c, (2) misuse of signed integers in the nsEscapeCount function in nsEscape.cpp, and (3) interaction of JavaScript garbage collection with certain use of an NPObject in the nsNPObjWrapper::GetNewOrUsed function in nsJSNPRuntime.cpp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -232,9 +228,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3wvh-ff74-hr6f/GHSA-3wvh-ff74-hr6f.json b/advisories/unreviewed/2022/05/GHSA-3wvh-ff74-hr6f/GHSA-3wvh-ff74-hr6f.json index 29d9d4bd330..7bdac40e938 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wvh-ff74-hr6f/GHSA-3wvh-ff74-hr6f.json +++ b/advisories/unreviewed/2022/05/GHSA-3wvh-ff74-hr6f/GHSA-3wvh-ff74-hr6f.json @@ -7,12 +7,8 @@ "CVE-2008-4005" ], "details": "Unspecified vulnerability in the Oracle Application Express component in Oracle Database 11.1.0.6 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-42x2-f5xm-rg4h/GHSA-42x2-f5xm-rg4h.json b/advisories/unreviewed/2022/05/GHSA-42x2-f5xm-rg4h/GHSA-42x2-f5xm-rg4h.json index 4698f24e177..1013698afb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-42x2-f5xm-rg4h/GHSA-42x2-f5xm-rg4h.json +++ b/advisories/unreviewed/2022/05/GHSA-42x2-f5xm-rg4h/GHSA-42x2-f5xm-rg4h.json @@ -7,12 +7,8 @@ "CVE-2008-4229" ], "details": "Race condition in the Passcode Lock feature in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.0 through 2.1 allows physically proximate attackers to remove the lock and launch arbitrary applications by restoring the device from a backup.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-435q-7mpf-fcmp/GHSA-435q-7mpf-fcmp.json b/advisories/unreviewed/2022/05/GHSA-435q-7mpf-fcmp/GHSA-435q-7mpf-fcmp.json index 930b7b06429..856c1da62d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-435q-7mpf-fcmp/GHSA-435q-7mpf-fcmp.json +++ b/advisories/unreviewed/2022/05/GHSA-435q-7mpf-fcmp/GHSA-435q-7mpf-fcmp.json @@ -7,12 +7,8 @@ "CVE-2008-4260" ], "details": "Microsoft Internet Explorer 7 sometimes attempts to access a deleted object, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka \"Uninitialized Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-43wv-g93j-pw44/GHSA-43wv-g93j-pw44.json b/advisories/unreviewed/2022/05/GHSA-43wv-g93j-pw44/GHSA-43wv-g93j-pw44.json index 21e66be0970..e6b103f9656 100644 --- a/advisories/unreviewed/2022/05/GHSA-43wv-g93j-pw44/GHSA-43wv-g93j-pw44.json +++ b/advisories/unreviewed/2022/05/GHSA-43wv-g93j-pw44/GHSA-43wv-g93j-pw44.json @@ -7,12 +7,8 @@ "CVE-2008-3731" ], "details": "Unspecified vulnerability in Serv-U File Server 7.0.0.1, and other versions before 7.2.0.1, allows remote authenticated users to cause a denial of service (daemon crash) via an SSH session with SFTP commands for directory creation and logging.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-445m-8qw7-7x42/GHSA-445m-8qw7-7x42.json b/advisories/unreviewed/2022/05/GHSA-445m-8qw7-7x42/GHSA-445m-8qw7-7x42.json index 08412072aca..66e20631031 100644 --- a/advisories/unreviewed/2022/05/GHSA-445m-8qw7-7x42/GHSA-445m-8qw7-7x42.json +++ b/advisories/unreviewed/2022/05/GHSA-445m-8qw7-7x42/GHSA-445m-8qw7-7x42.json @@ -7,12 +7,8 @@ "CVE-2008-4332" ], "details": "SQL injection vulnerability in the showjavatopic function in func.php in PHP infoBoard V.7 Plus allows remote attackers to execute arbitrary SQL commands via the idcat parameter to showtopic.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-445p-3crg-24jx/GHSA-445p-3crg-24jx.json b/advisories/unreviewed/2022/05/GHSA-445p-3crg-24jx/GHSA-445p-3crg-24jx.json index 713ffbd84b2..9888cfc78ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-445p-3crg-24jx/GHSA-445p-3crg-24jx.json +++ b/advisories/unreviewed/2022/05/GHSA-445p-3crg-24jx/GHSA-445p-3crg-24jx.json @@ -7,12 +7,8 @@ "CVE-2008-3972" ], "details": "pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card's label matches the \"OpenSC\" string, which might allow physically proximate attackers to exploit vulnerabilities that the card owner expected were patched, as demonstrated by exploitation of CVE-2008-2235.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-452f-6cjx-8x7j/GHSA-452f-6cjx-8x7j.json b/advisories/unreviewed/2022/05/GHSA-452f-6cjx-8x7j/GHSA-452f-6cjx-8x7j.json index c3fd441fb12..f8a83d21c3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-452f-6cjx-8x7j/GHSA-452f-6cjx-8x7j.json +++ b/advisories/unreviewed/2022/05/GHSA-452f-6cjx-8x7j/GHSA-452f-6cjx-8x7j.json @@ -7,12 +7,8 @@ "CVE-2008-3858" ], "details": "The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT data stream that simulates a V7 client connect request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4682-r8pf-c5pm/GHSA-4682-r8pf-c5pm.json b/advisories/unreviewed/2022/05/GHSA-4682-r8pf-c5pm/GHSA-4682-r8pf-c5pm.json index 19817c31dfa..97e81b2004b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4682-r8pf-c5pm/GHSA-4682-r8pf-c5pm.json +++ b/advisories/unreviewed/2022/05/GHSA-4682-r8pf-c5pm/GHSA-4682-r8pf-c5pm.json @@ -7,12 +7,8 @@ "CVE-2008-3931" ], "details": "javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-46f2-w34r-pqj8/GHSA-46f2-w34r-pqj8.json b/advisories/unreviewed/2022/05/GHSA-46f2-w34r-pqj8/GHSA-46f2-w34r-pqj8.json index 93863d1d133..b7788076463 100644 --- a/advisories/unreviewed/2022/05/GHSA-46f2-w34r-pqj8/GHSA-46f2-w34r-pqj8.json +++ b/advisories/unreviewed/2022/05/GHSA-46f2-w34r-pqj8/GHSA-46f2-w34r-pqj8.json @@ -7,12 +7,8 @@ "CVE-2008-4387" ], "details": "Unspecified vulnerability in the Simba MDrmSap ActiveX control in mdrmsap.dll in SAP SAPgui allows remote attackers to execute arbitrary code via unknown vectors involving instantiation by Internet Explorer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-47qh-xg57-3fg9/GHSA-47qh-xg57-3fg9.json b/advisories/unreviewed/2022/05/GHSA-47qh-xg57-3fg9/GHSA-47qh-xg57-3fg9.json index 7d2ccb81e81..c2fb9fa3e30 100644 --- a/advisories/unreviewed/2022/05/GHSA-47qh-xg57-3fg9/GHSA-47qh-xg57-3fg9.json +++ b/advisories/unreviewed/2022/05/GHSA-47qh-xg57-3fg9/GHSA-47qh-xg57-3fg9.json @@ -7,12 +7,8 @@ "CVE-2008-4323" ], "details": "Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application crash) via a crafted .ZIP file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-47xq-mwq7-mw56/GHSA-47xq-mwq7-mw56.json b/advisories/unreviewed/2022/05/GHSA-47xq-mwq7-mw56/GHSA-47xq-mwq7-mw56.json index cc0f84f481b..94c6806a998 100644 --- a/advisories/unreviewed/2022/05/GHSA-47xq-mwq7-mw56/GHSA-47xq-mwq7-mw56.json +++ b/advisories/unreviewed/2022/05/GHSA-47xq-mwq7-mw56/GHSA-47xq-mwq7-mw56.json @@ -7,12 +7,8 @@ "CVE-2008-4070" ], "details": "Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long header in a news article, related to \"canceling [a] newsgroup message\" and \"cancelled newsgroup messages.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-49m6-w46f-fp87/GHSA-49m6-w46f-fp87.json b/advisories/unreviewed/2022/05/GHSA-49m6-w46f-fp87/GHSA-49m6-w46f-fp87.json index 92951efba16..bff5cb4368c 100644 --- a/advisories/unreviewed/2022/05/GHSA-49m6-w46f-fp87/GHSA-49m6-w46f-fp87.json +++ b/advisories/unreviewed/2022/05/GHSA-49m6-w46f-fp87/GHSA-49m6-w46f-fp87.json @@ -7,12 +7,8 @@ "CVE-2008-4219" ], "details": "The kernel in Apple Mac OS X before 10.5.6 allows local users to cause a denial of service (infinite loop and system halt) by running an application that is dynamically linked to libraries on an NFS server, related to occurrence of an exception in this application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-49vg-6g45-5h6j/GHSA-49vg-6g45-5h6j.json b/advisories/unreviewed/2022/05/GHSA-49vg-6g45-5h6j/GHSA-49vg-6g45-5h6j.json index a509672f064..6e88a1e6cf9 100644 --- a/advisories/unreviewed/2022/05/GHSA-49vg-6g45-5h6j/GHSA-49vg-6g45-5h6j.json +++ b/advisories/unreviewed/2022/05/GHSA-49vg-6g45-5h6j/GHSA-49vg-6g45-5h6j.json @@ -7,12 +7,8 @@ "CVE-2008-4032" ], "details": "Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for administrative functions, which allows remote attackers to cause a denial of service (server load), obtain sensitive information, and \"create scripts that would run in the context of the site\" via requests to administrative URIs, aka \"Access Control Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4c94-7fpq-w2p5/GHSA-4c94-7fpq-w2p5.json b/advisories/unreviewed/2022/05/GHSA-4c94-7fpq-w2p5/GHSA-4c94-7fpq-w2p5.json index f81f169ade7..9fc6441a3d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c94-7fpq-w2p5/GHSA-4c94-7fpq-w2p5.json +++ b/advisories/unreviewed/2022/05/GHSA-4c94-7fpq-w2p5/GHSA-4c94-7fpq-w2p5.json @@ -7,12 +7,8 @@ "CVE-2008-4186" ], "details": "SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id_doc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4chj-f27h-99gr/GHSA-4chj-f27h-99gr.json b/advisories/unreviewed/2022/05/GHSA-4chj-f27h-99gr/GHSA-4chj-f27h-99gr.json index 2e5432f7721..254527965c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-4chj-f27h-99gr/GHSA-4chj-f27h-99gr.json +++ b/advisories/unreviewed/2022/05/GHSA-4chj-f27h-99gr/GHSA-4chj-f27h-99gr.json @@ -7,12 +7,8 @@ "CVE-2008-3859" ], "details": "Davlin Thickbox Gallery 2 allows remote attackers to obtain the administrative username and MD5 password hash via a direct request to conf/admins.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4cmc-7p42-35cm/GHSA-4cmc-7p42-35cm.json b/advisories/unreviewed/2022/05/GHSA-4cmc-7p42-35cm/GHSA-4cmc-7p42-35cm.json index 56ea9721eb6..ae0ede027f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cmc-7p42-35cm/GHSA-4cmc-7p42-35cm.json +++ b/advisories/unreviewed/2022/05/GHSA-4cmc-7p42-35cm/GHSA-4cmc-7p42-35cm.json @@ -7,12 +7,8 @@ "CVE-2008-4016" ], "details": "Unspecified vulnerability in the Collaborative Workspaces component in Oracle Collaboration Suite 10.1.2 allows remote authenticated users to affect confidentiality via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4fcg-8w49-fpj6/GHSA-4fcg-8w49-fpj6.json b/advisories/unreviewed/2022/05/GHSA-4fcg-8w49-fpj6/GHSA-4fcg-8w49-fpj6.json index 2725992a020..b7d4eeb011c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fcg-8w49-fpj6/GHSA-4fcg-8w49-fpj6.json +++ b/advisories/unreviewed/2022/05/GHSA-4fcg-8w49-fpj6/GHSA-4fcg-8w49-fpj6.json @@ -7,12 +7,8 @@ "CVE-2008-3870" ], "details": "Integer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted RPC request that triggers a heap-based buffer overflow, related to improper memory allocation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4hj9-rwwj-2hgv/GHSA-4hj9-rwwj-2hgv.json b/advisories/unreviewed/2022/05/GHSA-4hj9-rwwj-2hgv/GHSA-4hj9-rwwj-2hgv.json index 6d6cd3d297b..2820a79bcc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hj9-rwwj-2hgv/GHSA-4hj9-rwwj-2hgv.json +++ b/advisories/unreviewed/2022/05/GHSA-4hj9-rwwj-2hgv/GHSA-4hj9-rwwj-2hgv.json @@ -7,12 +7,8 @@ "CVE-2008-4210" ], "details": "fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -144,9 +140,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4hq2-rvjr-cg35/GHSA-4hq2-rvjr-cg35.json b/advisories/unreviewed/2022/05/GHSA-4hq2-rvjr-cg35/GHSA-4hq2-rvjr-cg35.json index b3f613b1adb..44419e221cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hq2-rvjr-cg35/GHSA-4hq2-rvjr-cg35.json +++ b/advisories/unreviewed/2022/05/GHSA-4hq2-rvjr-cg35/GHSA-4hq2-rvjr-cg35.json @@ -7,12 +7,8 @@ "CVE-2008-4142" ], "details": "SQL injection vulnerability in article.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via the es_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4hxm-vghg-cgj3/GHSA-4hxm-vghg-cgj3.json b/advisories/unreviewed/2022/05/GHSA-4hxm-vghg-cgj3/GHSA-4hxm-vghg-cgj3.json index 7351e4c6a58..2a35beda8f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hxm-vghg-cgj3/GHSA-4hxm-vghg-cgj3.json +++ b/advisories/unreviewed/2022/05/GHSA-4hxm-vghg-cgj3/GHSA-4hxm-vghg-cgj3.json @@ -7,12 +7,8 @@ "CVE-2008-4393" ], "details": "Cross-site scripting (XSS) vulnerability in VeriSign Kontiki Delivery Management System (DMS) 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to zodiac/servlet/zodiac.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4j8p-jwwx-692v/GHSA-4j8p-jwwx-692v.json b/advisories/unreviewed/2022/05/GHSA-4j8p-jwwx-692v/GHSA-4j8p-jwwx-692v.json index 063fabdb349..6ed8ea85aba 100644 --- a/advisories/unreviewed/2022/05/GHSA-4j8p-jwwx-692v/GHSA-4j8p-jwwx-692v.json +++ b/advisories/unreviewed/2022/05/GHSA-4j8p-jwwx-692v/GHSA-4j8p-jwwx-692v.json @@ -7,12 +7,8 @@ "CVE-2008-4057" ], "details": "Unspecified vulnerability in Objective Development Sharity 3 before 3.5 has unknown impact and attack vectors, related to a \"serious security problem.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4jhm-crx9-7qmm/GHSA-4jhm-crx9-7qmm.json b/advisories/unreviewed/2022/05/GHSA-4jhm-crx9-7qmm/GHSA-4jhm-crx9-7qmm.json index fb9174d48c0..a07a3c976ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jhm-crx9-7qmm/GHSA-4jhm-crx9-7qmm.json +++ b/advisories/unreviewed/2022/05/GHSA-4jhm-crx9-7qmm/GHSA-4jhm-crx9-7qmm.json @@ -7,12 +7,8 @@ "CVE-2008-3990" ], "details": "Unspecified vulnerability in the Oracle OLAP component in Oracle Database 9.2.08, 9.2.0.8DV, and 10.1.0.5 allows remote authenticated users to affect availability, related to OLAPSYS.CWM2_OLAP_AW_AWUTIL, a different vulnerability than CVE-2008-3991.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4m28-vhw4-r5mc/GHSA-4m28-vhw4-r5mc.json b/advisories/unreviewed/2022/05/GHSA-4m28-vhw4-r5mc/GHSA-4m28-vhw4-r5mc.json index 00bbc02d8f0..ba62ea11424 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m28-vhw4-r5mc/GHSA-4m28-vhw4-r5mc.json +++ b/advisories/unreviewed/2022/05/GHSA-4m28-vhw4-r5mc/GHSA-4m28-vhw4-r5mc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4m75-9x23-cwq6/GHSA-4m75-9x23-cwq6.json b/advisories/unreviewed/2022/05/GHSA-4m75-9x23-cwq6/GHSA-4m75-9x23-cwq6.json index bf6d8282603..68ec5bda59b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m75-9x23-cwq6/GHSA-4m75-9x23-cwq6.json +++ b/advisories/unreviewed/2022/05/GHSA-4m75-9x23-cwq6/GHSA-4m75-9x23-cwq6.json @@ -7,12 +7,8 @@ "CVE-2008-3756" ], "details": "SQL injection vulnerability in tr.php in YourFreeWorld Viral Marketing Script allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4rv4-vpmj-m97r/GHSA-4rv4-vpmj-m97r.json b/advisories/unreviewed/2022/05/GHSA-4rv4-vpmj-m97r/GHSA-4rv4-vpmj-m97r.json index 8c202879b0c..5664181c068 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rv4-vpmj-m97r/GHSA-4rv4-vpmj-m97r.json +++ b/advisories/unreviewed/2022/05/GHSA-4rv4-vpmj-m97r/GHSA-4rv4-vpmj-m97r.json @@ -7,12 +7,8 @@ "CVE-2008-4156" ], "details": "SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4x5v-8mq8-g9hp/GHSA-4x5v-8mq8-g9hp.json b/advisories/unreviewed/2022/05/GHSA-4x5v-8mq8-g9hp/GHSA-4x5v-8mq8-g9hp.json index 625e2156892..e30cc675b7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x5v-8mq8-g9hp/GHSA-4x5v-8mq8-g9hp.json +++ b/advisories/unreviewed/2022/05/GHSA-4x5v-8mq8-g9hp/GHSA-4x5v-8mq8-g9hp.json @@ -7,12 +7,8 @@ "CVE-2008-3852" ], "details": "Unspecified vulnerability in the CLR stored procedure deployment from IBM Database Add-Ins for Visual Studio in the Visual Studio Net component in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 2 allows remote authenticated users to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-52q4-558x-f9rv/GHSA-52q4-558x-f9rv.json b/advisories/unreviewed/2022/05/GHSA-52q4-558x-f9rv/GHSA-52q4-558x-f9rv.json index 913adb127b4..400c5c7a48a 100644 --- a/advisories/unreviewed/2022/05/GHSA-52q4-558x-f9rv/GHSA-52q4-558x-f9rv.json +++ b/advisories/unreviewed/2022/05/GHSA-52q4-558x-f9rv/GHSA-52q4-558x-f9rv.json @@ -7,12 +7,8 @@ "CVE-2008-3966" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via (1) a certain referrer field in usercp2.php, (2) a certain location field in inc/functions_online.php, and certain (3) tsubject and (4) psubject fields in moderation.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-52qw-pvqg-c2g3/GHSA-52qw-pvqg-c2g3.json b/advisories/unreviewed/2022/05/GHSA-52qw-pvqg-c2g3/GHSA-52qw-pvqg-c2g3.json index 9693cc872e5..e75e1c3cfb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-52qw-pvqg-c2g3/GHSA-52qw-pvqg-c2g3.json +++ b/advisories/unreviewed/2022/05/GHSA-52qw-pvqg-c2g3/GHSA-52qw-pvqg-c2g3.json @@ -7,12 +7,8 @@ "CVE-2008-4115" ], "details": "TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5345-wpqm-6qgf/GHSA-5345-wpqm-6qgf.json b/advisories/unreviewed/2022/05/GHSA-5345-wpqm-6qgf/GHSA-5345-wpqm-6qgf.json index a40fb6a4f88..7710a4644b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-5345-wpqm-6qgf/GHSA-5345-wpqm-6qgf.json +++ b/advisories/unreviewed/2022/05/GHSA-5345-wpqm-6qgf/GHSA-5345-wpqm-6qgf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-55g3-v56r-3g2g/GHSA-55g3-v56r-3g2g.json b/advisories/unreviewed/2022/05/GHSA-55g3-v56r-3g2g/GHSA-55g3-v56r-3g2g.json index 30d7fd023e1..2779a94cbda 100644 --- a/advisories/unreviewed/2022/05/GHSA-55g3-v56r-3g2g/GHSA-55g3-v56r-3g2g.json +++ b/advisories/unreviewed/2022/05/GHSA-55g3-v56r-3g2g/GHSA-55g3-v56r-3g2g.json @@ -7,12 +7,8 @@ "CVE-2008-4114" ], "details": "srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via an SMB WRITE_ANDX packet with an offset that is inconsistent with the packet size, related to \"insufficiently validating the buffer size,\" as demonstrated by a request to the \\PIPE\\lsarpc named pipe, aka \"SMB Validation Denial of Service Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-565r-9fh3-r5f7/GHSA-565r-9fh3-r5f7.json b/advisories/unreviewed/2022/05/GHSA-565r-9fh3-r5f7/GHSA-565r-9fh3-r5f7.json index 69f34bf253b..3aa5f88e86d 100644 --- a/advisories/unreviewed/2022/05/GHSA-565r-9fh3-r5f7/GHSA-565r-9fh3-r5f7.json +++ b/advisories/unreviewed/2022/05/GHSA-565r-9fh3-r5f7/GHSA-565r-9fh3-r5f7.json @@ -7,12 +7,8 @@ "CVE-2008-4414" ], "details": "Unspecified vulnerability in the AdvFS showfile command in HP Tru64 UNIX 5.1B-3 and 5.1B-4 allows local users to gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-56hh-jx7w-mxrr/GHSA-56hh-jx7w-mxrr.json b/advisories/unreviewed/2022/05/GHSA-56hh-jx7w-mxrr/GHSA-56hh-jx7w-mxrr.json index 15e5ae9ad65..ceb0d3d2a1e 100644 --- a/advisories/unreviewed/2022/05/GHSA-56hh-jx7w-mxrr/GHSA-56hh-jx7w-mxrr.json +++ b/advisories/unreviewed/2022/05/GHSA-56hh-jx7w-mxrr/GHSA-56hh-jx7w-mxrr.json @@ -7,12 +7,8 @@ "CVE-2008-4195" ], "details": "Opera before 9.52 does not properly restrict the ability of a framed web page to change the address associated with a different frame, which allows remote attackers to trigger the display of an arbitrary address in a frame via unspecified use of web script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-572x-qwvm-6cq9/GHSA-572x-qwvm-6cq9.json b/advisories/unreviewed/2022/05/GHSA-572x-qwvm-6cq9/GHSA-572x-qwvm-6cq9.json index 6cb43c905e3..893d24fe64e 100644 --- a/advisories/unreviewed/2022/05/GHSA-572x-qwvm-6cq9/GHSA-572x-qwvm-6cq9.json +++ b/advisories/unreviewed/2022/05/GHSA-572x-qwvm-6cq9/GHSA-572x-qwvm-6cq9.json @@ -7,12 +7,8 @@ "CVE-2008-3855" ], "details": "Unspecified vulnerability in the DB2 Administration Server (DAS) in the Core DAS function component in IBM DB2 9.1 before Fixpak 5 allows local users to gain privileges, aka a \"FILE CREATION VULNERABILITY.\" NOTE: this may be the same as CVE-2007-5664.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-578w-wh4j-4rmg/GHSA-578w-wh4j-4rmg.json b/advisories/unreviewed/2022/05/GHSA-578w-wh4j-4rmg/GHSA-578w-wh4j-4rmg.json index ceb46761c40..24859fa5ee4 100644 --- a/advisories/unreviewed/2022/05/GHSA-578w-wh4j-4rmg/GHSA-578w-wh4j-4rmg.json +++ b/advisories/unreviewed/2022/05/GHSA-578w-wh4j-4rmg/GHSA-578w-wh4j-4rmg.json @@ -7,12 +7,8 @@ "CVE-2008-3729" ], "details": "Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to bypass authentication and obtain administrative access via a direct request with (1) an IsAdmin=true cookie value or (2) no cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5794-ph65-rm7m/GHSA-5794-ph65-rm7m.json b/advisories/unreviewed/2022/05/GHSA-5794-ph65-rm7m/GHSA-5794-ph65-rm7m.json index 687c76f8cdd..1a96211a0a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-5794-ph65-rm7m/GHSA-5794-ph65-rm7m.json +++ b/advisories/unreviewed/2022/05/GHSA-5794-ph65-rm7m/GHSA-5794-ph65-rm7m.json @@ -7,12 +7,8 @@ "CVE-2008-3920" ], "details": "Unspecified vulnerability in BitlBee before 1.2.2 allows remote attackers to \"recreate\" and \"hijack\" existing accounts via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-57gv-rf6j-586p/GHSA-57gv-rf6j-586p.json b/advisories/unreviewed/2022/05/GHSA-57gv-rf6j-586p/GHSA-57gv-rf6j-586p.json index a229b742922..af544c975a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-57gv-rf6j-586p/GHSA-57gv-rf6j-586p.json +++ b/advisories/unreviewed/2022/05/GHSA-57gv-rf6j-586p/GHSA-57gv-rf6j-586p.json @@ -7,12 +7,8 @@ "CVE-2008-3875" ], "details": "The kernel in Sun Solaris 8 through 10 and OpenSolaris before snv_90 allows local users to bypass chroot, zones, and the Solaris Trusted Extensions multi-level security policy, and establish a covert communication channel, via unspecified vectors involving system calls.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-59jh-qxwp-hpc6/GHSA-59jh-qxwp-hpc6.json b/advisories/unreviewed/2022/05/GHSA-59jh-qxwp-hpc6/GHSA-59jh-qxwp-hpc6.json index 5b858a0f6ff..604fb0672cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-59jh-qxwp-hpc6/GHSA-59jh-qxwp-hpc6.json +++ b/advisories/unreviewed/2022/05/GHSA-59jh-qxwp-hpc6/GHSA-59jh-qxwp-hpc6.json @@ -7,12 +7,8 @@ "CVE-2008-4402" ], "details": "Multiple buffer overflows in CGI modules in the server in Trend Micro OfficeScan 8.0 SP1 before build 2439 and 8.0 SP1 Patch 1 before build 3087 allow remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5c3c-54fj-wg2v/GHSA-5c3c-54fj-wg2v.json b/advisories/unreviewed/2022/05/GHSA-5c3c-54fj-wg2v/GHSA-5c3c-54fj-wg2v.json index 984da818297..cd2d0fe405f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c3c-54fj-wg2v/GHSA-5c3c-54fj-wg2v.json +++ b/advisories/unreviewed/2022/05/GHSA-5c3c-54fj-wg2v/GHSA-5c3c-54fj-wg2v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5c3c-7jv4-fwmm/GHSA-5c3c-7jv4-fwmm.json b/advisories/unreviewed/2022/05/GHSA-5c3c-7jv4-fwmm/GHSA-5c3c-7jv4-fwmm.json index e3e7143951a..2f1bfcfac78 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c3c-7jv4-fwmm/GHSA-5c3c-7jv4-fwmm.json +++ b/advisories/unreviewed/2022/05/GHSA-5c3c-7jv4-fwmm/GHSA-5c3c-7jv4-fwmm.json @@ -7,12 +7,8 @@ "CVE-2008-4031" ], "details": "Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a malformed string in (1) an RTF file or (2) a rich text e-mail message, which triggers incorrect memory allocation and memory corruption, aka \"Word RTF Object Parsing Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5c8h-74jm-rr6m/GHSA-5c8h-74jm-rr6m.json b/advisories/unreviewed/2022/05/GHSA-5c8h-74jm-rr6m/GHSA-5c8h-74jm-rr6m.json index 174709bd063..6b5d380fb64 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c8h-74jm-rr6m/GHSA-5c8h-74jm-rr6m.json +++ b/advisories/unreviewed/2022/05/GHSA-5c8h-74jm-rr6m/GHSA-5c8h-74jm-rr6m.json @@ -7,12 +7,8 @@ "CVE-2008-4404" ], "details": "The IPv6 Neighbor Discovery Protocol (NDP) implementation on IBM zSeries servers does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic via a spoofed message that modifies the Forward Information Base (FIB), a related issue to CVE-2008-2476.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5f79-rpp2-frq6/GHSA-5f79-rpp2-frq6.json b/advisories/unreviewed/2022/05/GHSA-5f79-rpp2-frq6/GHSA-5f79-rpp2-frq6.json index d5a0b60ba65..c709f4a1281 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f79-rpp2-frq6/GHSA-5f79-rpp2-frq6.json +++ b/advisories/unreviewed/2022/05/GHSA-5f79-rpp2-frq6/GHSA-5f79-rpp2-frq6.json @@ -7,12 +7,8 @@ "CVE-2008-4043" ], "details": "Multiple SQL injection vulnerabilities in AJ Square AJ HYIP Acme allow remote attackers to execute arbitrary SQL commands via the artid parameter to (1) acme/article/comment.php and (2) prime/article/comment.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5gfr-74f6-qqgh/GHSA-5gfr-74f6-qqgh.json b/advisories/unreviewed/2022/05/GHSA-5gfr-74f6-qqgh/GHSA-5gfr-74f6-qqgh.json index 35c9647f1fc..e7586351047 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gfr-74f6-qqgh/GHSA-5gfr-74f6-qqgh.json +++ b/advisories/unreviewed/2022/05/GHSA-5gfr-74f6-qqgh/GHSA-5gfr-74f6-qqgh.json @@ -7,12 +7,8 @@ "CVE-2008-4252" ], "details": "The DataGrid ActiveX control in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the \"system state,\" aka \"DataGrid Control Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5hgv-r2hx-8534/GHSA-5hgv-r2hx-8534.json b/advisories/unreviewed/2022/05/GHSA-5hgv-r2hx-8534/GHSA-5hgv-r2hx-8534.json index 464248161f2..2ca29dda046 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hgv-r2hx-8534/GHSA-5hgv-r2hx-8534.json +++ b/advisories/unreviewed/2022/05/GHSA-5hgv-r2hx-8534/GHSA-5hgv-r2hx-8534.json @@ -7,12 +7,8 @@ "CVE-2008-3824" ], "details": "Cross-site scripting (XSS) vulnerability in (1) Text_Filter/Filter/xss.php in Horde 3.1.x before 3.1.9 and 3.2.x before 3.2.2 and (2) externalinput.php in Popoon r22196 and earlier allows remote attackers to inject arbitrary web script or HTML by using / (slash) characters as replacements for spaces in an HTML e-mail message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5hm4-3x9h-jh72/GHSA-5hm4-3x9h-jh72.json b/advisories/unreviewed/2022/05/GHSA-5hm4-3x9h-jh72/GHSA-5hm4-3x9h-jh72.json index 16f7e71b2cf..cec17837afc 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hm4-3x9h-jh72/GHSA-5hm4-3x9h-jh72.json +++ b/advisories/unreviewed/2022/05/GHSA-5hm4-3x9h-jh72/GHSA-5hm4-3x9h-jh72.json @@ -7,12 +7,8 @@ "CVE-2008-4134" ], "details": "PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other versions before 0.05, allows remote attackers to execute arbitrary PHP code via a URL in the INC parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jjm-c9v5-p5gc/GHSA-5jjm-c9v5-p5gc.json b/advisories/unreviewed/2022/05/GHSA-5jjm-c9v5-p5gc/GHSA-5jjm-c9v5-p5gc.json index 026144d128b..75c17084280 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jjm-c9v5-p5gc/GHSA-5jjm-c9v5-p5gc.json +++ b/advisories/unreviewed/2022/05/GHSA-5jjm-c9v5-p5gc/GHSA-5jjm-c9v5-p5gc.json @@ -7,12 +7,8 @@ "CVE-2008-4339" ], "details": "Unspecified vulnerability in the Java Administration GUI (jnbSA) in Symantec Veritas NetBackup Server and NetBackup Enterprise Server 5.1 before MP7, 6.0 before MP7, and 6.5 before 6.5.2 allows remote authenticated users to gain privileges via unknown attack vectors related to \"bpjava* binaries.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5mww-3q9c-mhp5/GHSA-5mww-3q9c-mhp5.json b/advisories/unreviewed/2022/05/GHSA-5mww-3q9c-mhp5/GHSA-5mww-3q9c-mhp5.json index 13161990cac..6cfc8069994 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mww-3q9c-mhp5/GHSA-5mww-3q9c-mhp5.json +++ b/advisories/unreviewed/2022/05/GHSA-5mww-3q9c-mhp5/GHSA-5mww-3q9c-mhp5.json @@ -7,12 +7,8 @@ "CVE-2008-3995" ], "details": "Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to DBMS_CDC_PUBLISH.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5pcw-47jc-ccp5/GHSA-5pcw-47jc-ccp5.json b/advisories/unreviewed/2022/05/GHSA-5pcw-47jc-ccp5/GHSA-5pcw-47jc-ccp5.json index 8c41cd81872..a3f86225863 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pcw-47jc-ccp5/GHSA-5pcw-47jc-ccp5.json +++ b/advisories/unreviewed/2022/05/GHSA-5pcw-47jc-ccp5/GHSA-5pcw-47jc-ccp5.json @@ -7,12 +7,8 @@ "CVE-2008-4258" ], "details": "Microsoft Internet Explorer 5.01 SP4 and 6 SP1 does not properly validate parameters during calls to navigation methods, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka \"Parameter Validation Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5q4g-m8fp-qww7/GHSA-5q4g-m8fp-qww7.json b/advisories/unreviewed/2022/05/GHSA-5q4g-m8fp-qww7/GHSA-5q4g-m8fp-qww7.json index d4a6acfa878..b07c4401af5 100644 --- a/advisories/unreviewed/2022/05/GHSA-5q4g-m8fp-qww7/GHSA-5q4g-m8fp-qww7.json +++ b/advisories/unreviewed/2022/05/GHSA-5q4g-m8fp-qww7/GHSA-5q4g-m8fp-qww7.json @@ -7,12 +7,8 @@ "CVE-2008-4234" ], "details": "Incomplete blacklist vulnerability in the Quarantine feature in CoreTypes in Apple Mac OS X 10.5 before 10.5.6 allows user-assisted remote attackers to execute arbitrary code via an executable file with the content type indicating no application association for the file, which does not trigger a \"potentially unsafe\" warning message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5rjc-vv8g-cr5q/GHSA-5rjc-vv8g-cr5q.json b/advisories/unreviewed/2022/05/GHSA-5rjc-vv8g-cr5q/GHSA-5rjc-vv8g-cr5q.json index 2a20aaa01a4..bd034bbe20e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5rjc-vv8g-cr5q/GHSA-5rjc-vv8g-cr5q.json +++ b/advisories/unreviewed/2022/05/GHSA-5rjc-vv8g-cr5q/GHSA-5rjc-vv8g-cr5q.json @@ -7,12 +7,8 @@ "CVE-2008-4259" ], "details": "Microsoft Internet Explorer 7 sometimes attempts to access uninitialized memory locations, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, related to a WebDAV request for a file with a long name, aka \"HTML Objects Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5www-2q34-5r5q/GHSA-5www-2q34-5r5q.json b/advisories/unreviewed/2022/05/GHSA-5www-2q34-5r5q/GHSA-5www-2q34-5r5q.json index 0c787b84fcf..a101ca2b97b 100644 --- a/advisories/unreviewed/2022/05/GHSA-5www-2q34-5r5q/GHSA-5www-2q34-5r5q.json +++ b/advisories/unreviewed/2022/05/GHSA-5www-2q34-5r5q/GHSA-5www-2q34-5r5q.json @@ -7,12 +7,8 @@ "CVE-2008-3736" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that (a) change passwords or (b) change configurations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5x69-q27x-jmpr/GHSA-5x69-q27x-jmpr.json b/advisories/unreviewed/2022/05/GHSA-5x69-q27x-jmpr/GHSA-5x69-q27x-jmpr.json index 10fe78923b5..455024f438f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x69-q27x-jmpr/GHSA-5x69-q27x-jmpr.json +++ b/advisories/unreviewed/2022/05/GHSA-5x69-q27x-jmpr/GHSA-5x69-q27x-jmpr.json @@ -7,12 +7,8 @@ "CVE-2008-3991" ], "details": "Unspecified vulnerability in the Oracle OLAP component in Oracle Database 9.2.08, 9.2.0.8DV, and 10.1.0.5 allows remote authenticated users to affect availability, related to OLAPSYS.CWM2_OLAP_AW_AWUTIL, a different vulnerability than CVE-2008-3990.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5xwv-48x7-34wp/GHSA-5xwv-48x7-34wp.json b/advisories/unreviewed/2022/05/GHSA-5xwv-48x7-34wp/GHSA-5xwv-48x7-34wp.json index 851c277e7eb..2199fbd39b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xwv-48x7-34wp/GHSA-5xwv-48x7-34wp.json +++ b/advisories/unreviewed/2022/05/GHSA-5xwv-48x7-34wp/GHSA-5xwv-48x7-34wp.json @@ -7,12 +7,8 @@ "CVE-2008-4396" ], "details": "Stack-based buffer overflow in Safer Networking FileAlyzer 1.6.0.0 and 1.6.0.4 beta, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via an executable with malformed version data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-62rc-gc2g-m9pr/GHSA-62rc-gc2g-m9pr.json b/advisories/unreviewed/2022/05/GHSA-62rc-gc2g-m9pr/GHSA-62rc-gc2g-m9pr.json index 8e6dabc6932..9ca15e842d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-62rc-gc2g-m9pr/GHSA-62rc-gc2g-m9pr.json +++ b/advisories/unreviewed/2022/05/GHSA-62rc-gc2g-m9pr/GHSA-62rc-gc2g-m9pr.json @@ -7,12 +7,8 @@ "CVE-2008-4130" ], "details": "Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted Flash animation, related to the ability of the animation to \"interact with the embedding page.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-63q6-hp4x-52r6/GHSA-63q6-hp4x-52r6.json b/advisories/unreviewed/2022/05/GHSA-63q6-hp4x-52r6/GHSA-63q6-hp4x-52r6.json index 5842359a2c5..13462609fdf 100644 --- a/advisories/unreviewed/2022/05/GHSA-63q6-hp4x-52r6/GHSA-63q6-hp4x-52r6.json +++ b/advisories/unreviewed/2022/05/GHSA-63q6-hp4x-52r6/GHSA-63q6-hp4x-52r6.json @@ -7,12 +7,8 @@ "CVE-2008-1544" ], "details": "The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 5.01, 6, and 7 does not block dangerous HTTP request headers when certain 8-bit character sequences are appended to a header name, which allows remote attackers to (1) conduct HTTP request splitting and HTTP request smuggling attacks via an incorrect Content-Length header, (2) access arbitrary virtual hosts via a modified Host header, (3) bypass referrer restrictions via an incorrect Referer header, and (4) bypass the same-origin policy and obtain sensitive information via a crafted request header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-64cv-wcr4-h9fw/GHSA-64cv-wcr4-h9fw.json b/advisories/unreviewed/2022/05/GHSA-64cv-wcr4-h9fw/GHSA-64cv-wcr4-h9fw.json index 3b38a6e0582..e80c5bf7693 100644 --- a/advisories/unreviewed/2022/05/GHSA-64cv-wcr4-h9fw/GHSA-64cv-wcr4-h9fw.json +++ b/advisories/unreviewed/2022/05/GHSA-64cv-wcr4-h9fw/GHSA-64cv-wcr4-h9fw.json @@ -7,12 +7,8 @@ "CVE-2008-3874" ], "details": "Cross-site scripting (XSS) vulnerability in account.php in Lussumo Vanilla 1.1.5-rc1, 1.1.4, and earlier allows remote authenticated users to inject arbitrary web script or HTML via the Value field (aka Label ==> Value pairs). NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-65h5-7wf2-rcj3/GHSA-65h5-7wf2-rcj3.json b/advisories/unreviewed/2022/05/GHSA-65h5-7wf2-rcj3/GHSA-65h5-7wf2-rcj3.json index ee4b603db1a..ad61190d062 100644 --- a/advisories/unreviewed/2022/05/GHSA-65h5-7wf2-rcj3/GHSA-65h5-7wf2-rcj3.json +++ b/advisories/unreviewed/2022/05/GHSA-65h5-7wf2-rcj3/GHSA-65h5-7wf2-rcj3.json @@ -7,12 +7,8 @@ "CVE-2008-4033" ], "details": "Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka \"MSXML Header Request Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-65hm-pfc7-5f2p/GHSA-65hm-pfc7-5f2p.json b/advisories/unreviewed/2022/05/GHSA-65hm-pfc7-5f2p/GHSA-65hm-pfc7-5f2p.json index ceede31a77c..b50215ebf5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-65hm-pfc7-5f2p/GHSA-65hm-pfc7-5f2p.json +++ b/advisories/unreviewed/2022/05/GHSA-65hm-pfc7-5f2p/GHSA-65hm-pfc7-5f2p.json @@ -7,12 +7,8 @@ "CVE-2008-4129" ], "details": "Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-668c-m73x-9945/GHSA-668c-m73x-9945.json b/advisories/unreviewed/2022/05/GHSA-668c-m73x-9945/GHSA-668c-m73x-9945.json index e9ec9c16bef..0650cbf735e 100644 --- a/advisories/unreviewed/2022/05/GHSA-668c-m73x-9945/GHSA-668c-m73x-9945.json +++ b/advisories/unreviewed/2022/05/GHSA-668c-m73x-9945/GHSA-668c-m73x-9945.json @@ -7,12 +7,8 @@ "CVE-2008-4373" ], "details": "SQL injection vulnerability in job_seeker/applynow.php in AvailScript Job Portal Script allows remote attackers to execute arbitrary SQL commands via the jid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-66x6-fmcf-6c88/GHSA-66x6-fmcf-6c88.json b/advisories/unreviewed/2022/05/GHSA-66x6-fmcf-6c88/GHSA-66x6-fmcf-6c88.json index 5a54a982bb3..b699090f92c 100644 --- a/advisories/unreviewed/2022/05/GHSA-66x6-fmcf-6c88/GHSA-66x6-fmcf-6c88.json +++ b/advisories/unreviewed/2022/05/GHSA-66x6-fmcf-6c88/GHSA-66x6-fmcf-6c88.json @@ -7,12 +7,8 @@ "CVE-2008-4231" ], "details": "Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not properly handle HTML TABLE elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-678f-9vf2-6652/GHSA-678f-9vf2-6652.json b/advisories/unreviewed/2022/05/GHSA-678f-9vf2-6652/GHSA-678f-9vf2-6652.json index 34e0466247f..7cf7b691459 100644 --- a/advisories/unreviewed/2022/05/GHSA-678f-9vf2-6652/GHSA-678f-9vf2-6652.json +++ b/advisories/unreviewed/2022/05/GHSA-678f-9vf2-6652/GHSA-678f-9vf2-6652.json @@ -7,12 +7,8 @@ "CVE-2008-4341" ], "details": "add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by setting a cookie with admin=yes and login=admin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-683g-4vqr-5fqc/GHSA-683g-4vqr-5fqc.json b/advisories/unreviewed/2022/05/GHSA-683g-4vqr-5fqc/GHSA-683g-4vqr-5fqc.json index f1eefa54f4c..c52100902fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-683g-4vqr-5fqc/GHSA-683g-4vqr-5fqc.json +++ b/advisories/unreviewed/2022/05/GHSA-683g-4vqr-5fqc/GHSA-683g-4vqr-5fqc.json @@ -7,12 +7,8 @@ "CVE-2013-6763" ], "details": "The uio_mmap_physical function in drivers/uio/uio.c in the Linux kernel before 3.12 does not validate the size of a memory block, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via crafted mmap operations, a different vulnerability than CVE-2013-4511.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68m2-fcjx-qwm7/GHSA-68m2-fcjx-qwm7.json b/advisories/unreviewed/2022/05/GHSA-68m2-fcjx-qwm7/GHSA-68m2-fcjx-qwm7.json index 52e3842b6d0..1d2960582ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-68m2-fcjx-qwm7/GHSA-68m2-fcjx-qwm7.json +++ b/advisories/unreviewed/2022/05/GHSA-68m2-fcjx-qwm7/GHSA-68m2-fcjx-qwm7.json @@ -7,12 +7,8 @@ "CVE-2008-4143" ], "details": "SQL injection vulnerability in category_search.php in RazorCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68p5-3q65-cx3v/GHSA-68p5-3q65-cx3v.json b/advisories/unreviewed/2022/05/GHSA-68p5-3q65-cx3v/GHSA-68p5-3q65-cx3v.json index 3ae82259355..888278f1f39 100644 --- a/advisories/unreviewed/2022/05/GHSA-68p5-3q65-cx3v/GHSA-68p5-3q65-cx3v.json +++ b/advisories/unreviewed/2022/05/GHSA-68p5-3q65-cx3v/GHSA-68p5-3q65-cx3v.json @@ -7,12 +7,8 @@ "CVE-2008-3838" ], "details": "Unspecified vulnerability in the NFS Remote Procedure Calls (RPC) zones implementation in Sun Solaris 10 and OpenSolaris before snv_88 allows local administrators of non-global zones to read and modify NFS traffic for arbitrary non-global zones, possibly leading to file modifications or a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68pp-2ghp-2458/GHSA-68pp-2ghp-2458.json b/advisories/unreviewed/2022/05/GHSA-68pp-2ghp-2458/GHSA-68pp-2ghp-2458.json index b2bff73bea3..621a7dee8de 100644 --- a/advisories/unreviewed/2022/05/GHSA-68pp-2ghp-2458/GHSA-68pp-2ghp-2458.json +++ b/advisories/unreviewed/2022/05/GHSA-68pp-2ghp-2458/GHSA-68pp-2ghp-2458.json @@ -7,12 +7,8 @@ "CVE-2008-4174" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in Dynamic MP3 Lister 2.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) currentpath, (2) invert, (3) search, and (4) sort parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-694p-gxgr-87cq/GHSA-694p-gxgr-87cq.json b/advisories/unreviewed/2022/05/GHSA-694p-gxgr-87cq/GHSA-694p-gxgr-87cq.json index bd388fea368..24f043b5574 100644 --- a/advisories/unreviewed/2022/05/GHSA-694p-gxgr-87cq/GHSA-694p-gxgr-87cq.json +++ b/advisories/unreviewed/2022/05/GHSA-694p-gxgr-87cq/GHSA-694p-gxgr-87cq.json @@ -7,12 +7,8 @@ "CVE-2008-3979" ], "details": "Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. NOTE: the previous information was obtained from the January 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is a SQL injection vulnerability that allows remote authenticated users to gain MDSYS privileges via the MDSYS.SDO_TOPO_DROP_FTBL trigger.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-69cc-ph75-44g2/GHSA-69cc-ph75-44g2.json b/advisories/unreviewed/2022/05/GHSA-69cc-ph75-44g2/GHSA-69cc-ph75-44g2.json index 90b7d0891d4..21e1759318a 100644 --- a/advisories/unreviewed/2022/05/GHSA-69cc-ph75-44g2/GHSA-69cc-ph75-44g2.json +++ b/advisories/unreviewed/2022/05/GHSA-69cc-ph75-44g2/GHSA-69cc-ph75-44g2.json @@ -7,12 +7,8 @@ "CVE-2008-3757" ], "details": "SQL injection vulnerability in tr1.php in YourFreeWorld Forced Matrix Script allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6cm5-fvqr-8cxh/GHSA-6cm5-fvqr-8cxh.json b/advisories/unreviewed/2022/05/GHSA-6cm5-fvqr-8cxh/GHSA-6cm5-fvqr-8cxh.json index 039c364a0e4..808925be45c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cm5-fvqr-8cxh/GHSA-6cm5-fvqr-8cxh.json +++ b/advisories/unreviewed/2022/05/GHSA-6cm5-fvqr-8cxh/GHSA-6cm5-fvqr-8cxh.json @@ -7,12 +7,8 @@ "CVE-2008-4018" ], "details": "swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local users in the system group to create or overwrite an arbitrary file, and establish weak permissions and root ownership for this file, via unspecified vectors. NOTE: this can be leveraged to gain privileges. NOTE: this issue exists because of an incomplete fix for CVE-2007-5805.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6gww-pqcg-wr93/GHSA-6gww-pqcg-wr93.json b/advisories/unreviewed/2022/05/GHSA-6gww-pqcg-wr93/GHSA-6gww-pqcg-wr93.json index 50b952d799c..5e205346ead 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gww-pqcg-wr93/GHSA-6gww-pqcg-wr93.json +++ b/advisories/unreviewed/2022/05/GHSA-6gww-pqcg-wr93/GHSA-6gww-pqcg-wr93.json @@ -7,12 +7,8 @@ "CVE-2008-4198" ], "details": "Opera before 9.52, when rendering an http page that has loaded an https page into a frame, displays a padlock icon and offers a security information dialog reporting a secure connection, which might allow remote attackers to trick a user into performing unsafe actions on the http page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6j2v-43m9-c4m7/GHSA-6j2v-43m9-c4m7.json b/advisories/unreviewed/2022/05/GHSA-6j2v-43m9-c4m7/GHSA-6j2v-43m9-c4m7.json index f90261e44fb..87c921cb7fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j2v-43m9-c4m7/GHSA-6j2v-43m9-c4m7.json +++ b/advisories/unreviewed/2022/05/GHSA-6j2v-43m9-c4m7/GHSA-6j2v-43m9-c4m7.json @@ -7,12 +7,8 @@ "CVE-2008-3848" ], "details": "SQL injection vulnerability in single.php in Z-Breaknews 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6j5j-5wvh-853p/GHSA-6j5j-5wvh-853p.json b/advisories/unreviewed/2022/05/GHSA-6j5j-5wvh-853p/GHSA-6j5j-5wvh-853p.json index 02e28f791dc..62a3e7ab874 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j5j-5wvh-853p/GHSA-6j5j-5wvh-853p.json +++ b/advisories/unreviewed/2022/05/GHSA-6j5j-5wvh-853p/GHSA-6j5j-5wvh-853p.json @@ -7,12 +7,8 @@ "CVE-2008-3847" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in AN Guestbook (ANG) before 0.7.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6jm8-c42c-7cvc/GHSA-6jm8-c42c-7cvc.json b/advisories/unreviewed/2022/05/GHSA-6jm8-c42c-7cvc/GHSA-6jm8-c42c-7cvc.json index 8f4c278808f..e4112861bf1 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jm8-c42c-7cvc/GHSA-6jm8-c42c-7cvc.json +++ b/advisories/unreviewed/2022/05/GHSA-6jm8-c42c-7cvc/GHSA-6jm8-c42c-7cvc.json @@ -7,12 +7,8 @@ "CVE-2008-3952" ], "details": "SQL injection vulnerability in questions.php in EsFaq 2.0 allows remote attackers to execute arbitrary SQL commands via the idcat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6px2-f4fc-3m96/GHSA-6px2-f4fc-3m96.json b/advisories/unreviewed/2022/05/GHSA-6px2-f4fc-3m96/GHSA-6px2-f4fc-3m96.json index 11d3bd8ce47..2acd58e8352 100644 --- a/advisories/unreviewed/2022/05/GHSA-6px2-f4fc-3m96/GHSA-6px2-f4fc-3m96.json +++ b/advisories/unreviewed/2022/05/GHSA-6px2-f4fc-3m96/GHSA-6px2-f4fc-3m96.json @@ -7,12 +7,8 @@ "CVE-2008-4113" ], "details": "The sctp_getsockopt_hmac_ident function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, relies on an untrusted length value to limit copying of data from kernel memory, which allows local users to obtain sensitive information via a crafted SCTP_HMAC_IDENT IOCTL request involving the sctp_getsockopt function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6q28-5xfg-cr7c/GHSA-6q28-5xfg-cr7c.json b/advisories/unreviewed/2022/05/GHSA-6q28-5xfg-cr7c/GHSA-6q28-5xfg-cr7c.json index f3e4d85f2ac..961fcdaaa61 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q28-5xfg-cr7c/GHSA-6q28-5xfg-cr7c.json +++ b/advisories/unreviewed/2022/05/GHSA-6q28-5xfg-cr7c/GHSA-6q28-5xfg-cr7c.json @@ -7,12 +7,8 @@ "CVE-2008-4293" ], "details": "Unspecified vulnerability in Opera before 9.52 on Windows, when registered as a protocol handler, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors in which Opera is launched by other applications.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6qp5-5fjv-f6jv/GHSA-6qp5-5fjv-f6jv.json b/advisories/unreviewed/2022/05/GHSA-6qp5-5fjv-f6jv/GHSA-6qp5-5fjv-f6jv.json index 6cef65ec96d..49385ad98ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qp5-5fjv-f6jv/GHSA-6qp5-5fjv-f6jv.json +++ b/advisories/unreviewed/2022/05/GHSA-6qp5-5fjv-f6jv/GHSA-6qp5-5fjv-f6jv.json @@ -7,12 +7,8 @@ "CVE-2008-3997" ], "details": "Unspecified vulnerability in the Oracle OLAP component in Oracle Database 10.1.0.5 and 10.2.0.3 allows remote authenticated users to affect availability, related to SYS.DBMS_XSOQ_ODBO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6qx9-873m-3jxj/GHSA-6qx9-873m-3jxj.json b/advisories/unreviewed/2022/05/GHSA-6qx9-873m-3jxj/GHSA-6qx9-873m-3jxj.json index aaff5d15149..e5e1b799e6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qx9-873m-3jxj/GHSA-6qx9-873m-3jxj.json +++ b/advisories/unreviewed/2022/05/GHSA-6qx9-873m-3jxj/GHSA-6qx9-873m-3jxj.json @@ -7,12 +7,8 @@ "CVE-2008-3891" ], "details": "The SAML Single Sign-On (SSO) Service for Google Apps allows remote service providers to impersonate users at arbitrary service providers via vectors related to authentication responses that lack a request identifier and recipient field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6r95-g7rg-6qwp/GHSA-6r95-g7rg-6qwp.json b/advisories/unreviewed/2022/05/GHSA-6r95-g7rg-6qwp/GHSA-6r95-g7rg-6qwp.json index af6d58f168b..accb0c31edc 100644 --- a/advisories/unreviewed/2022/05/GHSA-6r95-g7rg-6qwp/GHSA-6r95-g7rg-6qwp.json +++ b/advisories/unreviewed/2022/05/GHSA-6r95-g7rg-6qwp/GHSA-6r95-g7rg-6qwp.json @@ -7,12 +7,8 @@ "CVE-2008-4185" ], "details": "SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id parameter in a documentos action, a different vector than CVE-2008-3213.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6v67-8hw7-636g/GHSA-6v67-8hw7-636g.json b/advisories/unreviewed/2022/05/GHSA-6v67-8hw7-636g/GHSA-6v67-8hw7-636g.json index d74bb7de421..6cd265b895f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v67-8hw7-636g/GHSA-6v67-8hw7-636g.json +++ b/advisories/unreviewed/2022/05/GHSA-6v67-8hw7-636g/GHSA-6v67-8hw7-636g.json @@ -7,12 +7,8 @@ "CVE-2008-3935" ], "details": "Cross-site scripting (XSS) vulnerability in DIC shop_v50 3.0 and earlier and shop_v52 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6vj4-8grf-m438/GHSA-6vj4-8grf-m438.json b/advisories/unreviewed/2022/05/GHSA-6vj4-8grf-m438/GHSA-6vj4-8grf-m438.json index b9eb9b1a456..49855ec9346 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vj4-8grf-m438/GHSA-6vj4-8grf-m438.json +++ b/advisories/unreviewed/2022/05/GHSA-6vj4-8grf-m438/GHSA-6vj4-8grf-m438.json @@ -7,12 +7,8 @@ "CVE-2008-4299" ], "details": "A certain ActiveX control in the Microsoft Internet Authentication Service (IAS) Helper COM Component in iashlpr.dll allows remote attackers to cause a denial of service (browser crash) via a large integer value in the first argument to the PutProperty method. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6w42-v427-rmcm/GHSA-6w42-v427-rmcm.json b/advisories/unreviewed/2022/05/GHSA-6w42-v427-rmcm/GHSA-6w42-v427-rmcm.json index 3eaafabd838..10b22c08252 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w42-v427-rmcm/GHSA-6w42-v427-rmcm.json +++ b/advisories/unreviewed/2022/05/GHSA-6w42-v427-rmcm/GHSA-6w42-v427-rmcm.json @@ -7,12 +7,8 @@ "CVE-2008-4246" ], "details": "Unspecified vulnerability in Denora IRC Stats Server before 1.4.1 allows remote IRC servers to cause a denial of service (application crash) via a crafted CTCP response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6w6j-pxvf-wrx2/GHSA-6w6j-pxvf-wrx2.json b/advisories/unreviewed/2022/05/GHSA-6w6j-pxvf-wrx2/GHSA-6w6j-pxvf-wrx2.json index 575dfa4290f..7fc80673739 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w6j-pxvf-wrx2/GHSA-6w6j-pxvf-wrx2.json +++ b/advisories/unreviewed/2022/05/GHSA-6w6j-pxvf-wrx2/GHSA-6w6j-pxvf-wrx2.json @@ -7,12 +7,8 @@ "CVE-2008-4368" ], "details": "The default configuration of Java 1.5 on Apple Mac OS X 10.5.4 and 10.5.5 contains a jurisdiction policy that limits Java Cryptography Extension (JCE) key sizes to 128 bits, which makes it easier for attackers to decrypt ciphertext produced by JCE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6w96-g7qx-g62r/GHSA-6w96-g7qx-g62r.json b/advisories/unreviewed/2022/05/GHSA-6w96-g7qx-g62r/GHSA-6w96-g7qx-g62r.json index d3d6a031e09..1b6c0d0fbeb 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w96-g7qx-g62r/GHSA-6w96-g7qx-g62r.json +++ b/advisories/unreviewed/2022/05/GHSA-6w96-g7qx-g62r/GHSA-6w96-g7qx-g62r.json @@ -7,12 +7,8 @@ "CVE-2008-4363" ], "details": "DLMFENC.sys 1.0.0.28 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) or potentially execute arbitrary code via a certain DLMFENC_IOCTL request to \\\\.\\DLKPFSD_Device that overwrites a pointer, probably related to use of the ProbeForRead function when ProbeForWrite was intended.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6x5f-79qf-m4q2/GHSA-6x5f-79qf-m4q2.json b/advisories/unreviewed/2022/05/GHSA-6x5f-79qf-m4q2/GHSA-6x5f-79qf-m4q2.json index 37a1f7a830e..80e24fc335b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x5f-79qf-m4q2/GHSA-6x5f-79qf-m4q2.json +++ b/advisories/unreviewed/2022/05/GHSA-6x5f-79qf-m4q2/GHSA-6x5f-79qf-m4q2.json @@ -7,12 +7,8 @@ "CVE-2008-4336" ], "details": "Cross-site scripting (XSS) vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to inject arbitrary web script or HTML via the apa_album_ID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6x74-h8w8-x4pj/GHSA-6x74-h8w8-x4pj.json b/advisories/unreviewed/2022/05/GHSA-6x74-h8w8-x4pj/GHSA-6x74-h8w8-x4pj.json index 2e240527f66..0417f3994dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x74-h8w8-x4pj/GHSA-6x74-h8w8-x4pj.json +++ b/advisories/unreviewed/2022/05/GHSA-6x74-h8w8-x4pj/GHSA-6x74-h8w8-x4pj.json @@ -7,12 +7,8 @@ "CVE-2008-3915" ], "details": "Buffer overflow in nfsd in the Linux kernel before 2.6.26.4, when NFSv4 is enabled, allows remote attackers to have an unknown impact via vectors related to decoding an NFSv4 acl.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xgc-7p5v-c5hp/GHSA-6xgc-7p5v-c5hp.json b/advisories/unreviewed/2022/05/GHSA-6xgc-7p5v-c5hp/GHSA-6xgc-7p5v-c5hp.json index b96954ca3be..64ede55211d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xgc-7p5v-c5hp/GHSA-6xgc-7p5v-c5hp.json +++ b/advisories/unreviewed/2022/05/GHSA-6xgc-7p5v-c5hp/GHSA-6xgc-7p5v-c5hp.json @@ -7,12 +7,8 @@ "CVE-2008-4261" ], "details": "Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Windows XP and Server 2003 does not properly handle extraneous data associated with an object embedded in a web page, which allows remote attackers to execute arbitrary code via crafted HTML tags that trigger memory corruption, aka \"HTML Rendering Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6xx6-6pvv-vpr6/GHSA-6xx6-6pvv-vpr6.json b/advisories/unreviewed/2022/05/GHSA-6xx6-6pvv-vpr6/GHSA-6xx6-6pvv-vpr6.json index d15b849195c..dddefc7fe7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xx6-6pvv-vpr6/GHSA-6xx6-6pvv-vpr6.json +++ b/advisories/unreviewed/2022/05/GHSA-6xx6-6pvv-vpr6/GHSA-6xx6-6pvv-vpr6.json @@ -7,12 +7,8 @@ "CVE-2008-4007" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise Components component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9.18 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73r4-8h5j-2cjg/GHSA-73r4-8h5j-2cjg.json b/advisories/unreviewed/2022/05/GHSA-73r4-8h5j-2cjg/GHSA-73r4-8h5j-2cjg.json index b9d10f69562..51e59e4c15a 100644 --- a/advisories/unreviewed/2022/05/GHSA-73r4-8h5j-2cjg/GHSA-73r4-8h5j-2cjg.json +++ b/advisories/unreviewed/2022/05/GHSA-73r4-8h5j-2cjg/GHSA-73r4-8h5j-2cjg.json @@ -7,12 +7,8 @@ "CVE-2008-4360" ], "details": "mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there is a configuration rule for .php files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-73w2-627h-gg55/GHSA-73w2-627h-gg55.json b/advisories/unreviewed/2022/05/GHSA-73w2-627h-gg55/GHSA-73w2-627h-gg55.json index a03eeb7a73b..cdc14efbd39 100644 --- a/advisories/unreviewed/2022/05/GHSA-73w2-627h-gg55/GHSA-73w2-627h-gg55.json +++ b/advisories/unreviewed/2022/05/GHSA-73w2-627h-gg55/GHSA-73w2-627h-gg55.json @@ -7,12 +7,8 @@ "CVE-2008-4380" ], "details": "The web interface in Samsung DVR SHR2040 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, related to the filter for configuration properties and \"/x\" characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-74wm-5wpv-xxh5/GHSA-74wm-5wpv-xxh5.json b/advisories/unreviewed/2022/05/GHSA-74wm-5wpv-xxh5/GHSA-74wm-5wpv-xxh5.json index 6b32b00156d..172f5444366 100644 --- a/advisories/unreviewed/2022/05/GHSA-74wm-5wpv-xxh5/GHSA-74wm-5wpv-xxh5.json +++ b/advisories/unreviewed/2022/05/GHSA-74wm-5wpv-xxh5/GHSA-74wm-5wpv-xxh5.json @@ -7,12 +7,8 @@ "CVE-2008-3961" ], "details": "Multiple unspecified vulnerabilities in Adobe Illustrator CS2 on Macintosh allow user-assisted attackers to execute arbitrary code via a crafted AI file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7777-pw9w-4gm5/GHSA-7777-pw9w-4gm5.json b/advisories/unreviewed/2022/05/GHSA-7777-pw9w-4gm5/GHSA-7777-pw9w-4gm5.json index 46911f97b1a..02b03cea91a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7777-pw9w-4gm5/GHSA-7777-pw9w-4gm5.json +++ b/advisories/unreviewed/2022/05/GHSA-7777-pw9w-4gm5/GHSA-7777-pw9w-4gm5.json @@ -7,12 +7,8 @@ "CVE-2008-4166" ], "details": "Integer overflow in the JavaScript engine in Avant Browser 11.7 Build 9 and earlier allows remote attackers to cause a denial of service (application crash) by attempting to URL encode a string containing many instances of an invalid character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-77p7-3v27-ccgp/GHSA-77p7-3v27-ccgp.json b/advisories/unreviewed/2022/05/GHSA-77p7-3v27-ccgp/GHSA-77p7-3v27-ccgp.json index c4dda02c65b..e53d9662a70 100644 --- a/advisories/unreviewed/2022/05/GHSA-77p7-3v27-ccgp/GHSA-77p7-3v27-ccgp.json +++ b/advisories/unreviewed/2022/05/GHSA-77p7-3v27-ccgp/GHSA-77p7-3v27-ccgp.json @@ -7,12 +7,8 @@ "CVE-2008-4208" ], "details": "Unspecified vulnerability in OSADS Alliance Database before 2.1 has unknown impact and attack vectors, possibly related to includes/functions.php, a different issue than CVE-2006-2874.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-78jx-8j72-c76r/GHSA-78jx-8j72-c76r.json b/advisories/unreviewed/2022/05/GHSA-78jx-8j72-c76r/GHSA-78jx-8j72-c76r.json index 374b42f7e40..a7babde1407 100644 --- a/advisories/unreviewed/2022/05/GHSA-78jx-8j72-c76r/GHSA-78jx-8j72-c76r.json +++ b/advisories/unreviewed/2022/05/GHSA-78jx-8j72-c76r/GHSA-78jx-8j72-c76r.json @@ -7,12 +7,8 @@ "CVE-2008-3981" ], "details": "Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.1.0.1 allows remote attackers to affect confidentiality via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-78mj-jxw8-78gg/GHSA-78mj-jxw8-78gg.json b/advisories/unreviewed/2022/05/GHSA-78mj-jxw8-78gg/GHSA-78mj-jxw8-78gg.json index b92e75b54ec..63be4da2d59 100644 --- a/advisories/unreviewed/2022/05/GHSA-78mj-jxw8-78gg/GHSA-78mj-jxw8-78gg.json +++ b/advisories/unreviewed/2022/05/GHSA-78mj-jxw8-78gg/GHSA-78mj-jxw8-78gg.json @@ -7,12 +7,8 @@ "CVE-2008-3984" ], "details": "Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LT and WMSYS.LT, a different vulnerability than CVE-2008-3982 and CVE-2008-3983.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-78pm-hxfh-3jvg/GHSA-78pm-hxfh-3jvg.json b/advisories/unreviewed/2022/05/GHSA-78pm-hxfh-3jvg/GHSA-78pm-hxfh-3jvg.json index 753c0032ea4..e4e912fb884 100644 --- a/advisories/unreviewed/2022/05/GHSA-78pm-hxfh-3jvg/GHSA-78pm-hxfh-3jvg.json +++ b/advisories/unreviewed/2022/05/GHSA-78pm-hxfh-3jvg/GHSA-78pm-hxfh-3jvg.json @@ -7,12 +7,8 @@ "CVE-2008-3967" ], "details": "moderation.php in MyBB (aka MyBulletinBoard) before 1.4.1 does not properly check for moderator privileges, which has unknown impact and remote attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-793g-58hv-53ff/GHSA-793g-58hv-53ff.json b/advisories/unreviewed/2022/05/GHSA-793g-58hv-53ff/GHSA-793g-58hv-53ff.json index 1981e3dfd4c..b37611a08b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-793g-58hv-53ff/GHSA-793g-58hv-53ff.json +++ b/advisories/unreviewed/2022/05/GHSA-793g-58hv-53ff/GHSA-793g-58hv-53ff.json @@ -7,12 +7,8 @@ "CVE-2008-4056" ], "details": "Cross-site scripting (XSS) vulnerability in admin/login.php in Matterdaddy Market 1.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-798c-3j4f-v9pj/GHSA-798c-3j4f-v9pj.json b/advisories/unreviewed/2022/05/GHSA-798c-3j4f-v9pj/GHSA-798c-3j4f-v9pj.json index b5772a456fd..f41b42bc1c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-798c-3j4f-v9pj/GHSA-798c-3j4f-v9pj.json +++ b/advisories/unreviewed/2022/05/GHSA-798c-3j4f-v9pj/GHSA-798c-3j4f-v9pj.json @@ -7,12 +7,8 @@ "CVE-2008-3861" ], "details": "Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in pages.php and (2) the price_max parameter in search.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7c7f-876r-777q/GHSA-7c7f-876r-777q.json b/advisories/unreviewed/2022/05/GHSA-7c7f-876r-777q/GHSA-7c7f-876r-777q.json index 216b4239821..a07b2afa58b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c7f-876r-777q/GHSA-7c7f-876r-777q.json +++ b/advisories/unreviewed/2022/05/GHSA-7c7f-876r-777q/GHSA-7c7f-876r-777q.json @@ -7,12 +7,8 @@ "CVE-2008-3677" ], "details": "Directory traversal vulnerability in includes/events_application_top.php in Freeway before 1.4.2.197 allows remote attackers to include and execute arbitrary local files via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7fqv-r2rr-7j5v/GHSA-7fqv-r2rr-7j5v.json b/advisories/unreviewed/2022/05/GHSA-7fqv-r2rr-7j5v/GHSA-7fqv-r2rr-7j5v.json index 463572c0857..7b96dfdc7b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fqv-r2rr-7j5v/GHSA-7fqv-r2rr-7j5v.json +++ b/advisories/unreviewed/2022/05/GHSA-7fqv-r2rr-7j5v/GHSA-7fqv-r2rr-7j5v.json @@ -7,12 +7,8 @@ "CVE-2008-4091" ], "details": "SQL injection vulnerability in index.php in Web Directory Script 1.5.3 allows remote attackers to execute arbitrary SQL commands via the site parameter in an open action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g5q-fwvw-j3vm/GHSA-7g5q-fwvw-j3vm.json b/advisories/unreviewed/2022/05/GHSA-7g5q-fwvw-j3vm/GHSA-7g5q-fwvw-j3vm.json index 0b18308a3d0..d83fa9bd7dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g5q-fwvw-j3vm/GHSA-7g5q-fwvw-j3vm.json +++ b/advisories/unreviewed/2022/05/GHSA-7g5q-fwvw-j3vm/GHSA-7g5q-fwvw-j3vm.json @@ -7,12 +7,8 @@ "CVE-2008-4411" ], "details": "Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 2.1.15.210 on Linux and Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2008-1663.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7gp8-9gjg-f43h/GHSA-7gp8-9gjg-f43h.json b/advisories/unreviewed/2022/05/GHSA-7gp8-9gjg-f43h/GHSA-7gp8-9gjg-f43h.json index 4685d9ad531..0b514c3f6f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gp8-9gjg-f43h/GHSA-7gp8-9gjg-f43h.json +++ b/advisories/unreviewed/2022/05/GHSA-7gp8-9gjg-f43h/GHSA-7gp8-9gjg-f43h.json @@ -7,12 +7,8 @@ "CVE-2008-4392" ], "details": "dnscache in Daniel J. Bernstein djbdns 1.05 does not prevent simultaneous identical outbound DNS queries, which makes it easier for remote attackers to spoof DNS responses, as demonstrated by a spoofed A record in the Additional section of a response to a Start of Authority (SOA) query.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7h25-phc4-5m3h/GHSA-7h25-phc4-5m3h.json b/advisories/unreviewed/2022/05/GHSA-7h25-phc4-5m3h/GHSA-7h25-phc4-5m3h.json index ee496684beb..51dfefcac46 100644 --- a/advisories/unreviewed/2022/05/GHSA-7h25-phc4-5m3h/GHSA-7h25-phc4-5m3h.json +++ b/advisories/unreviewed/2022/05/GHSA-7h25-phc4-5m3h/GHSA-7h25-phc4-5m3h.json @@ -7,12 +7,8 @@ "CVE-2008-3817" ], "details": "Memory leak in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 8.0 before 8.0(4) and 8.1 before 8.1(2) allows remote attackers to cause a denial of service (memory consumption) via an unspecified sequence of packets, related to the \"initialization code for the hardware crypto accelerator.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7h2j-3ff7-3r95/GHSA-7h2j-3ff7-3r95.json b/advisories/unreviewed/2022/05/GHSA-7h2j-3ff7-3r95/GHSA-7h2j-3ff7-3r95.json index 0471704acad..0bd38ea88fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-7h2j-3ff7-3r95/GHSA-7h2j-3ff7-3r95.json +++ b/advisories/unreviewed/2022/05/GHSA-7h2j-3ff7-3r95/GHSA-7h2j-3ff7-3r95.json @@ -7,12 +7,8 @@ "CVE-2008-3846" ], "details": "Cross-site scripting (XSS) vulnerability in mysql-lists 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hcj-vrw6-f4m4/GHSA-7hcj-vrw6-f4m4.json b/advisories/unreviewed/2022/05/GHSA-7hcj-vrw6-f4m4/GHSA-7hcj-vrw6-f4m4.json index e3a76e397f4..89effe4512f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hcj-vrw6-f4m4/GHSA-7hcj-vrw6-f4m4.json +++ b/advisories/unreviewed/2022/05/GHSA-7hcj-vrw6-f4m4/GHSA-7hcj-vrw6-f4m4.json @@ -7,12 +7,8 @@ "CVE-2008-4092" ], "details": "SQL injection vulnerability in printfeature.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute arbitrary SQL commands via the artid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7jw6-96x5-9376/GHSA-7jw6-96x5-9376.json b/advisories/unreviewed/2022/05/GHSA-7jw6-96x5-9376/GHSA-7jw6-96x5-9376.json index 7af69574657..455485f0393 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jw6-96x5-9376/GHSA-7jw6-96x5-9376.json +++ b/advisories/unreviewed/2022/05/GHSA-7jw6-96x5-9376/GHSA-7jw6-96x5-9376.json @@ -7,12 +7,8 @@ "CVE-2008-4306" ], "details": "Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, possibly related to the font escape sequence.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7mp9-mc39-h253/GHSA-7mp9-mc39-h253.json b/advisories/unreviewed/2022/05/GHSA-7mp9-mc39-h253/GHSA-7mp9-mc39-h253.json index 6f8094070c6..a02c8552851 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mp9-mc39-h253/GHSA-7mp9-mc39-h253.json +++ b/advisories/unreviewed/2022/05/GHSA-7mp9-mc39-h253/GHSA-7mp9-mc39-h253.json @@ -7,12 +7,8 @@ "CVE-2008-4255" ], "details": "Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2003 SP3 and 2007 Gold and SP1 allows remote attackers to execute arbitrary code via an AVI file with a crafted stream length, which triggers an \"allocation error\" and memory corruption, aka \"Windows Common AVI Parsing Overflow Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7mvj-f88g-7mgj/GHSA-7mvj-f88g-7mgj.json b/advisories/unreviewed/2022/05/GHSA-7mvj-f88g-7mgj/GHSA-7mvj-f88g-7mgj.json index 2f6832ab4f4..47120d27a56 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mvj-f88g-7mgj/GHSA-7mvj-f88g-7mgj.json +++ b/advisories/unreviewed/2022/05/GHSA-7mvj-f88g-7mgj/GHSA-7mvj-f88g-7mgj.json @@ -7,12 +7,8 @@ "CVE-2008-3825" ], "details": "pam_krb5 2.2.14 in Red Hat Enterprise Linux (RHEL) 5 and earlier, when the existing_ticket option is enabled, uses incorrect privileges when reading a Kerberos credential cache, which allows local users to gain privileges by setting the KRB5CCNAME environment variable to an arbitrary cache filename and running the (1) su or (2) sudo program. NOTE: there may be a related vector involving sshd that has limited relevance.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7pqh-mwfx-x6jc/GHSA-7pqh-mwfx-x6jc.json b/advisories/unreviewed/2022/05/GHSA-7pqh-mwfx-x6jc/GHSA-7pqh-mwfx-x6jc.json index 2bf889588f5..d311c65e342 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pqh-mwfx-x6jc/GHSA-7pqh-mwfx-x6jc.json +++ b/advisories/unreviewed/2022/05/GHSA-7pqh-mwfx-x6jc/GHSA-7pqh-mwfx-x6jc.json @@ -7,12 +7,8 @@ "CVE-2008-4204" ], "details": "SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute arbitrary SQL commands via the city parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7q6f-575j-qw45/GHSA-7q6f-575j-qw45.json b/advisories/unreviewed/2022/05/GHSA-7q6f-575j-qw45/GHSA-7q6f-575j-qw45.json index 853d9ea47f0..519e0794a1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7q6f-575j-qw45/GHSA-7q6f-575j-qw45.json +++ b/advisories/unreviewed/2022/05/GHSA-7q6f-575j-qw45/GHSA-7q6f-575j-qw45.json @@ -7,12 +7,8 @@ "CVE-2008-3883" ], "details": "configvar in Caudium 1.4.12 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/roken#####.pike temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7qfh-vrpj-2j69/GHSA-7qfh-vrpj-2j69.json b/advisories/unreviewed/2022/05/GHSA-7qfh-vrpj-2j69/GHSA-7qfh-vrpj-2j69.json index b28abae9480..1d065052480 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qfh-vrpj-2j69/GHSA-7qfh-vrpj-2j69.json +++ b/advisories/unreviewed/2022/05/GHSA-7qfh-vrpj-2j69/GHSA-7qfh-vrpj-2j69.json @@ -7,12 +7,8 @@ "CVE-2008-3962" ], "details": "The from_format function in ssmtp.c in ssmtp 2.61 and 2.62, in certain configurations, uses uninitialized memory for the From: field of an e-mail message, which might allow remote attackers to obtain sensitive information (memory contents) in opportunistic circumstances by reading a message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7qgq-w6fc-rgcq/GHSA-7qgq-w6fc-rgcq.json b/advisories/unreviewed/2022/05/GHSA-7qgq-w6fc-rgcq/GHSA-7qgq-w6fc-rgcq.json index b97a9132651..909beba3426 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qgq-w6fc-rgcq/GHSA-7qgq-w6fc-rgcq.json +++ b/advisories/unreviewed/2022/05/GHSA-7qgq-w6fc-rgcq/GHSA-7qgq-w6fc-rgcq.json @@ -7,12 +7,8 @@ "CVE-2008-4053" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Bluemoon PopnupBLOG module 3.20 and 3.30 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the (1) param, (2) cat_id, and (3) view parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7qq2-c67v-p27j/GHSA-7qq2-c67v-p27j.json b/advisories/unreviewed/2022/05/GHSA-7qq2-c67v-p27j/GHSA-7qq2-c67v-p27j.json index b747ccf2e8b..ed8980fd25e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qq2-c67v-p27j/GHSA-7qq2-c67v-p27j.json +++ b/advisories/unreviewed/2022/05/GHSA-7qq2-c67v-p27j/GHSA-7qq2-c67v-p27j.json @@ -7,12 +7,8 @@ "CVE-2008-3938" ], "details": "Cross-site request forgery (CSRF) vulnerability in user_admin.php in Open Media Collectors Database (OpenDb) 1.0.6 allows remote attackers to change arbitrary passwords via an update_password action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7qxc-654w-j5p7/GHSA-7qxc-654w-j5p7.json b/advisories/unreviewed/2022/05/GHSA-7qxc-654w-j5p7/GHSA-7qxc-654w-j5p7.json index 7fdf32094ed..7445702b49b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qxc-654w-j5p7/GHSA-7qxc-654w-j5p7.json +++ b/advisories/unreviewed/2022/05/GHSA-7qxc-654w-j5p7/GHSA-7qxc-654w-j5p7.json @@ -7,12 +7,8 @@ "CVE-2008-3829" ], "details": "Unspecified vulnerability in the condor_ schedd daemon in Condor before 7.0.5 allows attackers to cause a denial of service (crash) via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7r4m-p2w9-fj4x/GHSA-7r4m-p2w9-fj4x.json b/advisories/unreviewed/2022/05/GHSA-7r4m-p2w9-fj4x/GHSA-7r4m-p2w9-fj4x.json index 7189cdc99ca..56d7d04f925 100644 --- a/advisories/unreviewed/2022/05/GHSA-7r4m-p2w9-fj4x/GHSA-7r4m-p2w9-fj4x.json +++ b/advisories/unreviewed/2022/05/GHSA-7r4m-p2w9-fj4x/GHSA-7r4m-p2w9-fj4x.json @@ -7,12 +7,8 @@ "CVE-2008-3802" ], "details": "Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4, when VoIP is configured, allows remote attackers to cause a denial of service (device reload) via unspecified valid SIP messages, aka Cisco bug ID CSCsk42759, a different vulnerability than CVE-2008-3800 and CVE-2008-3801.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7rh6-v5xq-4587/GHSA-7rh6-v5xq-4587.json b/advisories/unreviewed/2022/05/GHSA-7rh6-v5xq-4587/GHSA-7rh6-v5xq-4587.json index 83732cbb6e1..9f19cf2b836 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rh6-v5xq-4587/GHSA-7rh6-v5xq-4587.json +++ b/advisories/unreviewed/2022/05/GHSA-7rh6-v5xq-4587/GHSA-7rh6-v5xq-4587.json @@ -7,12 +7,8 @@ "CVE-2008-3908" ], "details": "Multiple buffer overflows in Princeton WordNet (wn) 3.0 allow context-dependent attackers to execute arbitrary code via (1) a long argument on the command line; a long (2) WNSEARCHDIR, (3) WNHOME, or (4) WNDBVERSION environment variable; or (5) a user-supplied dictionary (aka data file). NOTE: since WordNet itself does not run with special privileges, this issue only crosses privilege boundaries when WordNet is invoked as a third party component.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7rrm-hfg9-x3rc/GHSA-7rrm-hfg9-x3rc.json b/advisories/unreviewed/2022/05/GHSA-7rrm-hfg9-x3rc/GHSA-7rrm-hfg9-x3rc.json index d08be2ed48a..b458b5d1a32 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rrm-hfg9-x3rc/GHSA-7rrm-hfg9-x3rc.json +++ b/advisories/unreviewed/2022/05/GHSA-7rrm-hfg9-x3rc/GHSA-7rrm-hfg9-x3rc.json @@ -7,12 +7,8 @@ "CVE-2008-4407" ], "details": "XRunSabre in sabre (aka xsabre) 0.2.4b relies on the ability to create /tmp/sabre.log, which allows local users to cause a denial of service (application unavailability) by creating a /tmp/sabre.log file that cannot be overwritten.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7v43-h52m-h23c/GHSA-7v43-h52m-h23c.json b/advisories/unreviewed/2022/05/GHSA-7v43-h52m-h23c/GHSA-7v43-h52m-h23c.json index 4ee1afd6741..9dad886095e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7v43-h52m-h23c/GHSA-7v43-h52m-h23c.json +++ b/advisories/unreviewed/2022/05/GHSA-7v43-h52m-h23c/GHSA-7v43-h52m-h23c.json @@ -7,12 +7,8 @@ "CVE-2008-3888" ], "details": "SQL injection vulnerability in members.asp in Mini-NUKE Freehost 2.3 allows remote attackers to execute arbitrary SQL commands via the uid parameter in a member_details action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7w3j-vpf8-8c58/GHSA-7w3j-vpf8-8c58.json b/advisories/unreviewed/2022/05/GHSA-7w3j-vpf8-8c58/GHSA-7w3j-vpf8-8c58.json index a96509246ed..d71d1a30d02 100644 --- a/advisories/unreviewed/2022/05/GHSA-7w3j-vpf8-8c58/GHSA-7w3j-vpf8-8c58.json +++ b/advisories/unreviewed/2022/05/GHSA-7w3j-vpf8-8c58/GHSA-7w3j-vpf8-8c58.json @@ -7,12 +7,8 @@ "CVE-2008-3737" ], "details": "Unspecified vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to execute arbitrary PHP scripts, and delete files, read files, and possibly have unknown other impact.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7w9p-q9qx-67hm/GHSA-7w9p-q9qx-67hm.json b/advisories/unreviewed/2022/05/GHSA-7w9p-q9qx-67hm/GHSA-7w9p-q9qx-67hm.json index deaeef5f4c2..e2e4e4914cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-7w9p-q9qx-67hm/GHSA-7w9p-q9qx-67hm.json +++ b/advisories/unreviewed/2022/05/GHSA-7w9p-q9qx-67hm/GHSA-7w9p-q9qx-67hm.json @@ -7,12 +7,8 @@ "CVE-2008-4087" ], "details": "Stack-based buffer overflow in Acoustica Beatcraft 1.02 Build 19 allows user-assisted attackers to cause a denial of service or execute arbitrary code via a Beatcraft Project (aka bcproj) file with a long string in a certain instruments title field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wq7-qjqv-2q8f/GHSA-7wq7-qjqv-2q8f.json b/advisories/unreviewed/2022/05/GHSA-7wq7-qjqv-2q8f/GHSA-7wq7-qjqv-2q8f.json index 5e88c1fdc00..bf0cee4a6b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wq7-qjqv-2q8f/GHSA-7wq7-qjqv-2q8f.json +++ b/advisories/unreviewed/2022/05/GHSA-7wq7-qjqv-2q8f/GHSA-7wq7-qjqv-2q8f.json @@ -7,12 +7,8 @@ "CVE-2008-4206" ], "details": "PHP remote file inclusion vulnerability in config.php in Attachmax Dolphin 2.1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rel_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wvg-9w7x-48xm/GHSA-7wvg-9w7x-48xm.json b/advisories/unreviewed/2022/05/GHSA-7wvg-9w7x-48xm/GHSA-7wvg-9w7x-48xm.json index c2fa26d0bc2..3910a93e8f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wvg-9w7x-48xm/GHSA-7wvg-9w7x-48xm.json +++ b/advisories/unreviewed/2022/05/GHSA-7wvg-9w7x-48xm/GHSA-7wvg-9w7x-48xm.json @@ -7,12 +7,8 @@ "CVE-2008-3893" ], "details": "Microsoft Bitlocker in Windows Vista before SP1 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer during boot, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7xrx-q4w8-34vh/GHSA-7xrx-q4w8-34vh.json b/advisories/unreviewed/2022/05/GHSA-7xrx-q4w8-34vh/GHSA-7xrx-q4w8-34vh.json index 3cd1fdae7e8..30c85f2e708 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xrx-q4w8-34vh/GHSA-7xrx-q4w8-34vh.json +++ b/advisories/unreviewed/2022/05/GHSA-7xrx-q4w8-34vh/GHSA-7xrx-q4w8-34vh.json @@ -7,12 +7,8 @@ "CVE-2008-4054" ], "details": "SQL injection vulnerability in indir.php in Kolifa.net Download Script 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8254-vfjx-phm7/GHSA-8254-vfjx-phm7.json b/advisories/unreviewed/2022/05/GHSA-8254-vfjx-phm7/GHSA-8254-vfjx-phm7.json index 3fb60773dc6..7ab8e2f1cbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-8254-vfjx-phm7/GHSA-8254-vfjx-phm7.json +++ b/advisories/unreviewed/2022/05/GHSA-8254-vfjx-phm7/GHSA-8254-vfjx-phm7.json @@ -7,12 +7,8 @@ "CVE-2008-3867" ], "details": "SQL injection vulnerability in spaces/emailuser.php in Interact 2.4.1 allows remote attackers to execute arbitrary SQL commands via the email_user_key parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8283-hqqx-hv7g/GHSA-8283-hqqx-hv7g.json b/advisories/unreviewed/2022/05/GHSA-8283-hqqx-hv7g/GHSA-8283-hqqx-hv7g.json index 1010a27cf37..10355abbb0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8283-hqqx-hv7g/GHSA-8283-hqqx-hv7g.json +++ b/advisories/unreviewed/2022/05/GHSA-8283-hqqx-hv7g/GHSA-8283-hqqx-hv7g.json @@ -7,12 +7,8 @@ "CVE-2008-4029" ], "details": "Cross-domain vulnerability in Microsoft XML Core Services 3.0 and 4.0, as used in Internet Explorer, allows remote attackers to obtain sensitive information from another domain via a crafted XML document, related to improper error checks for external DTDs, aka \"MSXML DTD Cross-Domain Scripting Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82c6-j98m-2vfw/GHSA-82c6-j98m-2vfw.json b/advisories/unreviewed/2022/05/GHSA-82c6-j98m-2vfw/GHSA-82c6-j98m-2vfw.json index b89eb7bde1b..aa10f4ebf64 100644 --- a/advisories/unreviewed/2022/05/GHSA-82c6-j98m-2vfw/GHSA-82c6-j98m-2vfw.json +++ b/advisories/unreviewed/2022/05/GHSA-82c6-j98m-2vfw/GHSA-82c6-j98m-2vfw.json @@ -7,12 +7,8 @@ "CVE-2008-3743" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in forms in Drupal 6.x before 6.4 allow remote attackers to perform unspecified actions via unknown vectors, related to improper token validation for (1) cached forms and (2) forms with AHAH elements.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82gx-pjww-97hm/GHSA-82gx-pjww-97hm.json b/advisories/unreviewed/2022/05/GHSA-82gx-pjww-97hm/GHSA-82gx-pjww-97hm.json index 39d3193308c..a22b6023ab4 100644 --- a/advisories/unreviewed/2022/05/GHSA-82gx-pjww-97hm/GHSA-82gx-pjww-97hm.json +++ b/advisories/unreviewed/2022/05/GHSA-82gx-pjww-97hm/GHSA-82gx-pjww-97hm.json @@ -7,12 +7,8 @@ "CVE-2008-4376" ], "details": "SQL injection vulnerability in index.php in Live TV Script allows remote attackers to execute arbitrary SQL commands via the mid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82jg-g6qh-25mv/GHSA-82jg-g6qh-25mv.json b/advisories/unreviewed/2022/05/GHSA-82jg-g6qh-25mv/GHSA-82jg-g6qh-25mv.json index 63cf14a9db2..c9cbfab60f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-82jg-g6qh-25mv/GHSA-82jg-g6qh-25mv.json +++ b/advisories/unreviewed/2022/05/GHSA-82jg-g6qh-25mv/GHSA-82jg-g6qh-25mv.json @@ -7,12 +7,8 @@ "CVE-2008-3850" ], "details": "Cross-site scripting (XSS) vulnerability in Accellion File Transfer FTA_7_0_135 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to courier/forgot_password.html.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-837w-7698-945q/GHSA-837w-7698-945q.json b/advisories/unreviewed/2022/05/GHSA-837w-7698-945q/GHSA-837w-7698-945q.json index cf36cd666fe..bf142c57a44 100644 --- a/advisories/unreviewed/2022/05/GHSA-837w-7698-945q/GHSA-837w-7698-945q.json +++ b/advisories/unreviewed/2022/05/GHSA-837w-7698-945q/GHSA-837w-7698-945q.json @@ -7,12 +7,8 @@ "CVE-2008-4325" ], "details": "lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which allows remote attackers to cause content to be misinterpreted by the browser via a content-type parameter that is inconsistent with the requested object. NOTE: this issue might not be a vulnerability, since it requires attacker access to the repository that is being viewed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-83wq-g434-8r6h/GHSA-83wq-g434-8r6h.json b/advisories/unreviewed/2022/05/GHSA-83wq-g434-8r6h/GHSA-83wq-g434-8r6h.json index b5780253195..e270815b2d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-83wq-g434-8r6h/GHSA-83wq-g434-8r6h.json +++ b/advisories/unreviewed/2022/05/GHSA-83wq-g434-8r6h/GHSA-83wq-g434-8r6h.json @@ -7,12 +7,8 @@ "CVE-2008-3965" ], "details": "SQL injection vulnerability in misc.php in MyBB (aka MyBulletinBoard) before 1.4.1 allows remote attackers to execute arbitrary SQL commands via a certain editor field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-869h-8gqv-xgpj/GHSA-869h-8gqv-xgpj.json b/advisories/unreviewed/2022/05/GHSA-869h-8gqv-xgpj/GHSA-869h-8gqv-xgpj.json index 2dd71e30c0f..32ddb77e661 100644 --- a/advisories/unreviewed/2022/05/GHSA-869h-8gqv-xgpj/GHSA-869h-8gqv-xgpj.json +++ b/advisories/unreviewed/2022/05/GHSA-869h-8gqv-xgpj/GHSA-869h-8gqv-xgpj.json @@ -7,12 +7,8 @@ "CVE-2008-3998" ], "details": "Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 12.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-86c8-rrq8-65q9/GHSA-86c8-rrq8-65q9.json b/advisories/unreviewed/2022/05/GHSA-86c8-rrq8-65q9/GHSA-86c8-rrq8-65q9.json index 5cde5d731b5..0c4f90621b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-86c8-rrq8-65q9/GHSA-86c8-rrq8-65q9.json +++ b/advisories/unreviewed/2022/05/GHSA-86c8-rrq8-65q9/GHSA-86c8-rrq8-65q9.json @@ -7,12 +7,8 @@ "CVE-2008-4354" ], "details": "SQL injection vulnerability in the products module in NetArt Media iBoutique 4.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-86mv-r2r6-8463/GHSA-86mv-r2r6-8463.json b/advisories/unreviewed/2022/05/GHSA-86mv-r2r6-8463/GHSA-86mv-r2r6-8463.json index 49b4aeb0c99..af54eebbf47 100644 --- a/advisories/unreviewed/2022/05/GHSA-86mv-r2r6-8463/GHSA-86mv-r2r6-8463.json +++ b/advisories/unreviewed/2022/05/GHSA-86mv-r2r6-8463/GHSA-86mv-r2r6-8463.json @@ -7,12 +7,8 @@ "CVE-2008-4084" ], "details": "SQL injection vulnerability in staticpages/easyclassifields/index.php in MyioSoft EasyClassifields 3.0 allows remote attackers to execute arbitrary SQL commands via the go parameter in a browse action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-86p9-275j-mv7g/GHSA-86p9-275j-mv7g.json b/advisories/unreviewed/2022/05/GHSA-86p9-275j-mv7g/GHSA-86p9-275j-mv7g.json index e6e2975e3fd..2a5039640b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-86p9-275j-mv7g/GHSA-86p9-275j-mv7g.json +++ b/advisories/unreviewed/2022/05/GHSA-86p9-275j-mv7g/GHSA-86p9-275j-mv7g.json @@ -7,12 +7,8 @@ "CVE-2008-4072" ], "details": "Multiple SQL injection vulnerabilities in index.php in phsBlog 0.2 allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter in a pickup action or (2) the sql_cid parameter, different vectors than CVE-2008-3588.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-87xj-5h7p-x95f/GHSA-87xj-5h7p-x95f.json b/advisories/unreviewed/2022/05/GHSA-87xj-5h7p-x95f/GHSA-87xj-5h7p-x95f.json index 8e75c8f4285..fe876d5adcf 100644 --- a/advisories/unreviewed/2022/05/GHSA-87xj-5h7p-x95f/GHSA-87xj-5h7p-x95f.json +++ b/advisories/unreviewed/2022/05/GHSA-87xj-5h7p-x95f/GHSA-87xj-5h7p-x95f.json @@ -7,12 +7,8 @@ "CVE-2008-4384" ], "details": "Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and iseemedia, allow remote attackers to execute arbitrary code via the (1) url, (2) toolbar, and (3) enableZoomPastMax methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-888r-9q72-mx98/GHSA-888r-9q72-mx98.json b/advisories/unreviewed/2022/05/GHSA-888r-9q72-mx98/GHSA-888r-9q72-mx98.json index 65e20a8c5ae..aee83e341c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-888r-9q72-mx98/GHSA-888r-9q72-mx98.json +++ b/advisories/unreviewed/2022/05/GHSA-888r-9q72-mx98/GHSA-888r-9q72-mx98.json @@ -7,12 +7,8 @@ "CVE-2008-4342" ], "details": "NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers to overwrite and create arbitrary files via calls to the EnableLog and LogMessage methods. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-889x-p8ww-5fp4/GHSA-889x-p8ww-5fp4.json b/advisories/unreviewed/2022/05/GHSA-889x-p8ww-5fp4/GHSA-889x-p8ww-5fp4.json index a4c5dbb3f92..48f6815f360 100644 --- a/advisories/unreviewed/2022/05/GHSA-889x-p8ww-5fp4/GHSA-889x-p8ww-5fp4.json +++ b/advisories/unreviewed/2022/05/GHSA-889x-p8ww-5fp4/GHSA-889x-p8ww-5fp4.json @@ -7,12 +7,8 @@ "CVE-2008-3892" ], "details": "Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a call to the GuestInfo method in which there is a long string argument, and an assignment of a long string value to the result of this call. NOTE: this may overlap CVE-2008-3691, CVE-2008-3692, CVE-2008-3693, CVE-2008-3694, CVE-2008-3695, or CVE-2008-3696.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-88vx-35q9-m425/GHSA-88vx-35q9-m425.json b/advisories/unreviewed/2022/05/GHSA-88vx-35q9-m425/GHSA-88vx-35q9-m425.json index 8bf9f93ad3b..0f449010190 100644 --- a/advisories/unreviewed/2022/05/GHSA-88vx-35q9-m425/GHSA-88vx-35q9-m425.json +++ b/advisories/unreviewed/2022/05/GHSA-88vx-35q9-m425/GHSA-88vx-35q9-m425.json @@ -7,12 +7,8 @@ "CVE-2008-3948" ], "details": "SQL injection vulnerability in admin/users/self-2.php in XRMS allows remote attackers to execute arbitrary SQL commands and modify name and email fields via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8f83-rp39-99mx/GHSA-8f83-rp39-99mx.json b/advisories/unreviewed/2022/05/GHSA-8f83-rp39-99mx/GHSA-8f83-rp39-99mx.json index 6602ca3ed64..882f5b0beb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-8f83-rp39-99mx/GHSA-8f83-rp39-99mx.json +++ b/advisories/unreviewed/2022/05/GHSA-8f83-rp39-99mx/GHSA-8f83-rp39-99mx.json @@ -7,12 +7,8 @@ "CVE-2008-4158" ], "details": "Multiple directory traversal vulnerabilities in index.php in Zanfi CMS lite 1.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) flag and (2) inc parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8frf-6p5f-hq7h/GHSA-8frf-6p5f-hq7h.json b/advisories/unreviewed/2022/05/GHSA-8frf-6p5f-hq7h/GHSA-8frf-6p5f-hq7h.json index 7c8235db9f3..4ff00922c59 100644 --- a/advisories/unreviewed/2022/05/GHSA-8frf-6p5f-hq7h/GHSA-8frf-6p5f-hq7h.json +++ b/advisories/unreviewed/2022/05/GHSA-8frf-6p5f-hq7h/GHSA-8frf-6p5f-hq7h.json @@ -7,12 +7,8 @@ "CVE-2008-3926" ], "details": "Multiple directory traversal vulnerabilities in Content Management Made Easy (CMME) 1.12 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the env parameter in a weblog action to index.php, or (2) create arbitrary directories via a .. (dot dot) in the env parameter in a login action to admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8g4r-xvwf-h866/GHSA-8g4r-xvwf-h866.json b/advisories/unreviewed/2022/05/GHSA-8g4r-xvwf-h866/GHSA-8g4r-xvwf-h866.json index ae085fc9dc5..11f41be5e04 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g4r-xvwf-h866/GHSA-8g4r-xvwf-h866.json +++ b/advisories/unreviewed/2022/05/GHSA-8g4r-xvwf-h866/GHSA-8g4r-xvwf-h866.json @@ -7,12 +7,8 @@ "CVE-2008-4017" ], "details": "Unspecified vulnerability in the OC4J component in Oracle Application Server 10.1.2.3 allows remote attackers to affect confidentiality via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8r3h-pvpj-hhcg/GHSA-8r3h-pvpj-hhcg.json b/advisories/unreviewed/2022/05/GHSA-8r3h-pvpj-hhcg/GHSA-8r3h-pvpj-hhcg.json index 25506dbd92d..ed8c748daae 100644 --- a/advisories/unreviewed/2022/05/GHSA-8r3h-pvpj-hhcg/GHSA-8r3h-pvpj-hhcg.json +++ b/advisories/unreviewed/2022/05/GHSA-8r3h-pvpj-hhcg/GHSA-8r3h-pvpj-hhcg.json @@ -7,12 +7,8 @@ "CVE-2008-3940" ], "details": "Format string vulnerability in the finger client in HP TCP/IP Services for OpenVMS 5.x allows local users to gain privileges via format string specifiers in a (1) .plan or (2) .project file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8vc3-xjw8-wgr3/GHSA-8vc3-xjw8-wgr3.json b/advisories/unreviewed/2022/05/GHSA-8vc3-xjw8-wgr3/GHSA-8vc3-xjw8-wgr3.json index 26caffff32f..8d1f433b059 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vc3-xjw8-wgr3/GHSA-8vc3-xjw8-wgr3.json +++ b/advisories/unreviewed/2022/05/GHSA-8vc3-xjw8-wgr3/GHSA-8vc3-xjw8-wgr3.json @@ -7,12 +7,8 @@ "CVE-2008-3857" ], "details": "The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the database connection that sent the password is fully established, which might allow local users to obtain sensitive information by reading a memory dump.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8vqq-hvqj-qc49/GHSA-8vqq-hvqj-qc49.json b/advisories/unreviewed/2022/05/GHSA-8vqq-hvqj-qc49/GHSA-8vqq-hvqj-qc49.json index fc8d02f2fea..ffa6fe32e11 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vqq-hvqj-qc49/GHSA-8vqq-hvqj-qc49.json +++ b/advisories/unreviewed/2022/05/GHSA-8vqq-hvqj-qc49/GHSA-8vqq-hvqj-qc49.json @@ -7,12 +7,8 @@ "CVE-2008-3878" ], "details": "Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware Ultra Office Control allows remote attackers to execute arbitrary code via long strUrl, strFile, and strPostData parameters to the HttpUpload method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xh8-2w7w-92cr/GHSA-8xh8-2w7w-92cr.json b/advisories/unreviewed/2022/05/GHSA-8xh8-2w7w-92cr/GHSA-8xh8-2w7w-92cr.json index d3e7a54f93d..2236c8ba31b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xh8-2w7w-92cr/GHSA-8xh8-2w7w-92cr.json +++ b/advisories/unreviewed/2022/05/GHSA-8xh8-2w7w-92cr/GHSA-8xh8-2w7w-92cr.json @@ -7,12 +7,8 @@ "CVE-2008-4139" ], "details": "Cross-site scripting (XSS) vulnerability in admin.php in OpenSolution Quick.Cms.Lite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xmx-3rx4-2jm7/GHSA-8xmx-3rx4-2jm7.json b/advisories/unreviewed/2022/05/GHSA-8xmx-3rx4-2jm7/GHSA-8xmx-3rx4-2jm7.json index 6581be48566..888706afada 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xmx-3rx4-2jm7/GHSA-8xmx-3rx4-2jm7.json +++ b/advisories/unreviewed/2022/05/GHSA-8xmx-3rx4-2jm7/GHSA-8xmx-3rx4-2jm7.json @@ -7,12 +7,8 @@ "CVE-2008-4030" ], "details": "Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1 allow remote attackers to execute arbitrary code via crafted control words in (1) an RTF file or (2) a rich text e-mail message, which triggers incorrect memory allocation and memory corruption, aka \"Word RTF Object Parsing Vulnerability,\" a different vulnerability than CVE-2008-4028.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8xvf-8g8c-ggcr/GHSA-8xvf-8g8c-ggcr.json b/advisories/unreviewed/2022/05/GHSA-8xvf-8g8c-ggcr/GHSA-8xvf-8g8c-ggcr.json index 9446fca06eb..8c710de77fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xvf-8g8c-ggcr/GHSA-8xvf-8g8c-ggcr.json +++ b/advisories/unreviewed/2022/05/GHSA-8xvf-8g8c-ggcr/GHSA-8xvf-8g8c-ggcr.json @@ -7,12 +7,8 @@ "CVE-2008-4137" ], "details": "PHP remote file inclusion vulnerability in footer.php in PHP-Crawler 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the footer_file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-92p7-hgp5-68xh/GHSA-92p7-hgp5-68xh.json b/advisories/unreviewed/2022/05/GHSA-92p7-hgp5-68xh/GHSA-92p7-hgp5-68xh.json index 1fb9088b4e2..230a804232c 100644 --- a/advisories/unreviewed/2022/05/GHSA-92p7-hgp5-68xh/GHSA-92p7-hgp5-68xh.json +++ b/advisories/unreviewed/2022/05/GHSA-92p7-hgp5-68xh/GHSA-92p7-hgp5-68xh.json @@ -7,12 +7,8 @@ "CVE-2008-4303" ], "details": "Multiple SQL injection vulnerabilities in phpCollab 2.5 rc3, 2.4, and earlier allow remote attackers to execute arbitrary SQL commands via the loginForm parameter to general/login.php, and unspecified other vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-936r-ppwc-wcpc/GHSA-936r-ppwc-wcpc.json b/advisories/unreviewed/2022/05/GHSA-936r-ppwc-wcpc/GHSA-936r-ppwc-wcpc.json index 6841b9263f1..a7d78a2f446 100644 --- a/advisories/unreviewed/2022/05/GHSA-936r-ppwc-wcpc/GHSA-936r-ppwc-wcpc.json +++ b/advisories/unreviewed/2022/05/GHSA-936r-ppwc-wcpc/GHSA-936r-ppwc-wcpc.json @@ -7,12 +7,8 @@ "CVE-2008-3808" ], "details": "Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via a crafted Protocol Independent Multicast (PIM) packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9547-8gx6-787g/GHSA-9547-8gx6-787g.json b/advisories/unreviewed/2022/05/GHSA-9547-8gx6-787g/GHSA-9547-8gx6-787g.json index fd2ece8d939..8e2cf82507a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9547-8gx6-787g/GHSA-9547-8gx6-787g.json +++ b/advisories/unreviewed/2022/05/GHSA-9547-8gx6-787g/GHSA-9547-8gx6-787g.json @@ -7,12 +7,8 @@ "CVE-2008-4099" ], "details": "PyDNS (aka python-dns) before 2.3.1-4 in Debian GNU/Linux does not use random source ports or transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-95rw-gm23-wxwq/GHSA-95rw-gm23-wxwq.json b/advisories/unreviewed/2022/05/GHSA-95rw-gm23-wxwq/GHSA-95rw-gm23-wxwq.json index 643b76081bb..2aa27617b4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-95rw-gm23-wxwq/GHSA-95rw-gm23-wxwq.json +++ b/advisories/unreviewed/2022/05/GHSA-95rw-gm23-wxwq/GHSA-95rw-gm23-wxwq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-985h-qhqc-c368/GHSA-985h-qhqc-c368.json b/advisories/unreviewed/2022/05/GHSA-985h-qhqc-c368/GHSA-985h-qhqc-c368.json index 21686515035..3363c049298 100644 --- a/advisories/unreviewed/2022/05/GHSA-985h-qhqc-c368/GHSA-985h-qhqc-c368.json +++ b/advisories/unreviewed/2022/05/GHSA-985h-qhqc-c368/GHSA-985h-qhqc-c368.json @@ -7,12 +7,8 @@ "CVE-2008-3897" ], "details": "DiskCryptor 0.2.6 on Windows stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-98w9-9xc5-rh5r/GHSA-98w9-9xc5-rh5r.json b/advisories/unreviewed/2022/05/GHSA-98w9-9xc5-rh5r/GHSA-98w9-9xc5-rh5r.json index a2f0d910f21..85a1f0cd692 100644 --- a/advisories/unreviewed/2022/05/GHSA-98w9-9xc5-rh5r/GHSA-98w9-9xc5-rh5r.json +++ b/advisories/unreviewed/2022/05/GHSA-98w9-9xc5-rh5r/GHSA-98w9-9xc5-rh5r.json @@ -7,12 +7,8 @@ "CVE-2008-4313" ], "details": "A certain Red Hat patch for tog-pegasus in OpenGroup Pegasus 2.7.0 does not properly configure the PAM tty name, which allows remote authenticated users to bypass intended access restrictions and send requests to OpenPegasus WBEM services.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-994f-hjm2-v98x/GHSA-994f-hjm2-v98x.json b/advisories/unreviewed/2022/05/GHSA-994f-hjm2-v98x/GHSA-994f-hjm2-v98x.json index 87b0f603acf..c38513d9c9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-994f-hjm2-v98x/GHSA-994f-hjm2-v98x.json +++ b/advisories/unreviewed/2022/05/GHSA-994f-hjm2-v98x/GHSA-994f-hjm2-v98x.json @@ -7,12 +7,8 @@ "CVE-2008-3840" ], "details": "Crafty Syntax Live Help (CSLH) 2.14.6 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-99g7-p93q-wxmp/GHSA-99g7-p93q-wxmp.json b/advisories/unreviewed/2022/05/GHSA-99g7-p93q-wxmp/GHSA-99g7-p93q-wxmp.json index 2e9631eaae4..4f19d46898c 100644 --- a/advisories/unreviewed/2022/05/GHSA-99g7-p93q-wxmp/GHSA-99g7-p93q-wxmp.json +++ b/advisories/unreviewed/2022/05/GHSA-99g7-p93q-wxmp/GHSA-99g7-p93q-wxmp.json @@ -7,12 +7,8 @@ "CVE-2008-4348" ], "details": "SQL injection vulnerability in photo.php in PHPortfolio, possibly 1.3, allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9c49-89g5-wcx6/GHSA-9c49-89g5-wcx6.json b/advisories/unreviewed/2022/05/GHSA-9c49-89g5-wcx6/GHSA-9c49-89g5-wcx6.json index fc18454e3d0..cb96fdc9256 100644 --- a/advisories/unreviewed/2022/05/GHSA-9c49-89g5-wcx6/GHSA-9c49-89g5-wcx6.json +++ b/advisories/unreviewed/2022/05/GHSA-9c49-89g5-wcx6/GHSA-9c49-89g5-wcx6.json @@ -7,12 +7,8 @@ "CVE-2008-3930" ], "details": "migrate_aliases.sh in Citadel Server 7.37 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9f3x-wrx8-8wqp/GHSA-9f3x-wrx8-8wqp.json b/advisories/unreviewed/2022/05/GHSA-9f3x-wrx8-8wqp/GHSA-9f3x-wrx8-8wqp.json index a2fc9749685..36a7c2be71d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9f3x-wrx8-8wqp/GHSA-9f3x-wrx8-8wqp.json +++ b/advisories/unreviewed/2022/05/GHSA-9f3x-wrx8-8wqp/GHSA-9f3x-wrx8-8wqp.json @@ -7,12 +7,8 @@ "CVE-2008-4214" ], "details": "Unspecified vulnerability in Script Editor in Mac OS X 10.4.11 and 10.5.5 allows local users to cause the scripting dictionary to be written to arbitrary locations, related to an \"insecure file operation\" on temporary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9gcq-w2xv-xvf8/GHSA-9gcq-w2xv-xvf8.json b/advisories/unreviewed/2022/05/GHSA-9gcq-w2xv-xvf8/GHSA-9gcq-w2xv-xvf8.json index 5c93c82ebd1..a260743d42b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gcq-w2xv-xvf8/GHSA-9gcq-w2xv-xvf8.json +++ b/advisories/unreviewed/2022/05/GHSA-9gcq-w2xv-xvf8/GHSA-9gcq-w2xv-xvf8.json @@ -7,12 +7,8 @@ "CVE-2008-3801" ], "details": "Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4 and Unified Communications Manager 4.1 through 6.1, when VoIP is configured, allows remote attackers to cause a denial of service (device or process reload) via unspecified valid SIP messages, aka Cisco Bug ID CSCsm46064, a different vulnerability than CVE-2008-3800 and CVE-2008-3802.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9jq6-xfgg-9267/GHSA-9jq6-xfgg-9267.json b/advisories/unreviewed/2022/05/GHSA-9jq6-xfgg-9267/GHSA-9jq6-xfgg-9267.json index aa320f1a2b6..24257c2e725 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jq6-xfgg-9267/GHSA-9jq6-xfgg-9267.json +++ b/advisories/unreviewed/2022/05/GHSA-9jq6-xfgg-9267/GHSA-9jq6-xfgg-9267.json @@ -7,12 +7,8 @@ "CVE-2008-4215" ], "details": "Weblog in Mac OS X Server 10.4.11 does not properly check an error condition when a weblog posting access control list is specified for a user that has multiple short names, which might allow attackers to bypass intended access restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9mmr-29h4-xffm/GHSA-9mmr-29h4-xffm.json b/advisories/unreviewed/2022/05/GHSA-9mmr-29h4-xffm/GHSA-9mmr-29h4-xffm.json index c25af69c607..148d6162950 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mmr-29h4-xffm/GHSA-9mmr-29h4-xffm.json +++ b/advisories/unreviewed/2022/05/GHSA-9mmr-29h4-xffm/GHSA-9mmr-29h4-xffm.json @@ -7,12 +7,8 @@ "CVE-2008-3725" ], "details": "SQL injection vulnerability in trr.php in YourFreeWorld Ad Board Script allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9p55-7x58-8jfh/GHSA-9p55-7x58-8jfh.json b/advisories/unreviewed/2022/05/GHSA-9p55-7x58-8jfh/GHSA-9p55-7x58-8jfh.json index 1bb33e269b3..b7aee474ed2 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p55-7x58-8jfh/GHSA-9p55-7x58-8jfh.json +++ b/advisories/unreviewed/2022/05/GHSA-9p55-7x58-8jfh/GHSA-9p55-7x58-8jfh.json @@ -7,12 +7,8 @@ "CVE-2008-3987" ], "details": "Unspecified vulnerability in the Oracle Discoverer Desktop component in Oracle Application Server 10.1.2.3 allows local users to affect confidentiality via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9pv8-whmh-9q87/GHSA-9pv8-whmh-9q87.json b/advisories/unreviewed/2022/05/GHSA-9pv8-whmh-9q87/GHSA-9pv8-whmh-9q87.json index 53156d0ffdd..821989bc970 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pv8-whmh-9q87/GHSA-9pv8-whmh-9q87.json +++ b/advisories/unreviewed/2022/05/GHSA-9pv8-whmh-9q87/GHSA-9pv8-whmh-9q87.json @@ -7,12 +7,8 @@ "CVE-2008-3949" ], "details": "emacs/lisp/progmodes/python.el in Emacs 22.1 and 22.2 imports Python script from the current working directory during editing of a Python file, which allows local users to execute arbitrary code via a Trojan horse Python file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9qqc-cwxq-gc75/GHSA-9qqc-cwxq-gc75.json b/advisories/unreviewed/2022/05/GHSA-9qqc-cwxq-gc75/GHSA-9qqc-cwxq-gc75.json index 3c418b11380..a18985ea23b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qqc-cwxq-gc75/GHSA-9qqc-cwxq-gc75.json +++ b/advisories/unreviewed/2022/05/GHSA-9qqc-cwxq-gc75/GHSA-9qqc-cwxq-gc75.json @@ -7,12 +7,8 @@ "CVE-2008-3922" ], "details": "awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which is used by the multisort function when dynamically creating an anonymous PHP function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9qxp-4454-64h6/GHSA-9qxp-4454-64h6.json b/advisories/unreviewed/2022/05/GHSA-9qxp-4454-64h6/GHSA-9qxp-4454-64h6.json index c2d44147d5d..b517ff4dbcc 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qxp-4454-64h6/GHSA-9qxp-4454-64h6.json +++ b/advisories/unreviewed/2022/05/GHSA-9qxp-4454-64h6/GHSA-9qxp-4454-64h6.json @@ -7,12 +7,8 @@ "CVE-2008-3815" ], "details": "Unspecified vulnerability in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)3, 7.1 before 7.1(2)78, 7.2 before 7.2(4)16, 8.0 before 8.0(4)6, and 8.1 before 8.1(1)13, when configured as a VPN using Microsoft Windows NT Domain authentication, allows remote attackers to bypass VPN authentication via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9r9h-5xq6-44jp/GHSA-9r9h-5xq6-44jp.json b/advisories/unreviewed/2022/05/GHSA-9r9h-5xq6-44jp/GHSA-9r9h-5xq6-44jp.json index 9c1301706ac..4c7f7a2aea7 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r9h-5xq6-44jp/GHSA-9r9h-5xq6-44jp.json +++ b/advisories/unreviewed/2022/05/GHSA-9r9h-5xq6-44jp/GHSA-9r9h-5xq6-44jp.json @@ -7,12 +7,8 @@ "CVE-2008-4180" ], "details": "Unspecified vulnerability in db.php in NooMS 1.1 allows remote attackers to conduct brute force attacks against passwords via a username in the g_dbuser parameter and a password in the g_dbpwd parameter, and possibly a \"localhost\" g_dbhost parameter value, related to a \"Mysql Remote Brute Force Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9v5x-c64h-25w9/GHSA-9v5x-c64h-25w9.json b/advisories/unreviewed/2022/05/GHSA-9v5x-c64h-25w9/GHSA-9v5x-c64h-25w9.json index b36d1868923..0851a8ccabf 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v5x-c64h-25w9/GHSA-9v5x-c64h-25w9.json +++ b/advisories/unreviewed/2022/05/GHSA-9v5x-c64h-25w9/GHSA-9v5x-c64h-25w9.json @@ -7,12 +7,8 @@ "CVE-2008-4145" ], "details": "SQL injection vulnerability in user_read_links.php in Addalink 1.0 beta 4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the category_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9vvj-7q58-pch2/GHSA-9vvj-7q58-pch2.json b/advisories/unreviewed/2022/05/GHSA-9vvj-7q58-pch2/GHSA-9vvj-7q58-pch2.json index e6fa01285b8..8dc197f0c06 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vvj-7q58-pch2/GHSA-9vvj-7q58-pch2.json +++ b/advisories/unreviewed/2022/05/GHSA-9vvj-7q58-pch2/GHSA-9vvj-7q58-pch2.json @@ -7,12 +7,8 @@ "CVE-2008-3869" ], "details": "Heap-based buffer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted RPC request, related to improper decoding of request parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9w4j-8mgg-w792/GHSA-9w4j-8mgg-w792.json b/advisories/unreviewed/2022/05/GHSA-9w4j-8mgg-w792/GHSA-9w4j-8mgg-w792.json index a8f1bb24c26..e3bc0343176 100644 --- a/advisories/unreviewed/2022/05/GHSA-9w4j-8mgg-w792/GHSA-9w4j-8mgg-w792.json +++ b/advisories/unreviewed/2022/05/GHSA-9w4j-8mgg-w792/GHSA-9w4j-8mgg-w792.json @@ -7,12 +7,8 @@ "CVE-2008-3849" ], "details": "Cross-site scripting (XSS) vulnerability in the calendar controller in Civic Website Manager before 1.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably involving (1) month, (2) day, and (3) year fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9x94-g556-7x2c/GHSA-9x94-g556-7x2c.json b/advisories/unreviewed/2022/05/GHSA-9x94-g556-7x2c/GHSA-9x94-g556-7x2c.json index 72325129f1a..a18c925984c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x94-g556-7x2c/GHSA-9x94-g556-7x2c.json +++ b/advisories/unreviewed/2022/05/GHSA-9x94-g556-7x2c/GHSA-9x94-g556-7x2c.json @@ -7,12 +7,8 @@ "CVE-2008-4051" ], "details": "Cross-site scripting (XSS) vulnerability in surveyresults.asp in Smart Survey 1.0 allows remote attackers to inject arbitrary web script or HTML via the sid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c24p-p34c-x969/GHSA-c24p-p34c-x969.json b/advisories/unreviewed/2022/05/GHSA-c24p-p34c-x969/GHSA-c24p-p34c-x969.json index e60661f1c05..b465a8540b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-c24p-p34c-x969/GHSA-c24p-p34c-x969.json +++ b/advisories/unreviewed/2022/05/GHSA-c24p-p34c-x969/GHSA-c24p-p34c-x969.json @@ -7,12 +7,8 @@ "CVE-2008-3907" ], "details": "The open-in-browser command in newsbeuter before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a feed URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c24w-g444-4cpf/GHSA-c24w-g444-4cpf.json b/advisories/unreviewed/2022/05/GHSA-c24w-g444-4cpf/GHSA-c24w-g444-4cpf.json index 579e3c722d9..a1bbecaf22d 100644 --- a/advisories/unreviewed/2022/05/GHSA-c24w-g444-4cpf/GHSA-c24w-g444-4cpf.json +++ b/advisories/unreviewed/2022/05/GHSA-c24w-g444-4cpf/GHSA-c24w-g444-4cpf.json @@ -7,12 +7,8 @@ "CVE-2008-4044" ], "details": "SQL injection vulnerability in article/readarticle.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the artid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c2cw-3wxx-2cxv/GHSA-c2cw-3wxx-2cxv.json b/advisories/unreviewed/2022/05/GHSA-c2cw-3wxx-2cxv/GHSA-c2cw-3wxx-2cxv.json index 4bfa0eff690..13c02b4433e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2cw-3wxx-2cxv/GHSA-c2cw-3wxx-2cxv.json +++ b/advisories/unreviewed/2022/05/GHSA-c2cw-3wxx-2cxv/GHSA-c2cw-3wxx-2cxv.json @@ -7,12 +7,8 @@ "CVE-2008-3723" ], "details": "Directory traversal vulnerability in index.php in PHPizabi 0.848b C1 HFP3 allows remote authenticated administrators to read arbitrary files via (1) a .. (dot dot), (2) a URL, or possibly (3) a full pathname in the id parameter in an admin.templates.edittemplate action. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c3qm-3j85-q4w6/GHSA-c3qm-3j85-q4w6.json b/advisories/unreviewed/2022/05/GHSA-c3qm-3j85-q4w6/GHSA-c3qm-3j85-q4w6.json index 8f6467956b2..6ee8f790beb 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3qm-3j85-q4w6/GHSA-c3qm-3j85-q4w6.json +++ b/advisories/unreviewed/2022/05/GHSA-c3qm-3j85-q4w6/GHSA-c3qm-3j85-q4w6.json @@ -7,12 +7,8 @@ "CVE-2008-4415" ], "details": "Unspecified vulnerability in HP Service Manager (HPSM) before 7.01.71 allows remote authenticated users to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c427-p67m-j336/GHSA-c427-p67m-j336.json b/advisories/unreviewed/2022/05/GHSA-c427-p67m-j336/GHSA-c427-p67m-j336.json index 2b6a9a83d43..415c944f1f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-c427-p67m-j336/GHSA-c427-p67m-j336.json +++ b/advisories/unreviewed/2022/05/GHSA-c427-p67m-j336/GHSA-c427-p67m-j336.json @@ -7,12 +7,8 @@ "CVE-2008-4364" ], "details": "SQL injection vulnerability in default.aspx in ParsaGostar ParsaWeb CMS allows remote attackers to execute arbitrary SQL commands via the (1) id parameter in the \"page\" page and (2) txtSearch parameter in the \"Search\" page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4xj-289h-xhv9/GHSA-c4xj-289h-xhv9.json b/advisories/unreviewed/2022/05/GHSA-c4xj-289h-xhv9/GHSA-c4xj-289h-xhv9.json index 3be9bce7709..1ca4b17bc20 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4xj-289h-xhv9/GHSA-c4xj-289h-xhv9.json +++ b/advisories/unreviewed/2022/05/GHSA-c4xj-289h-xhv9/GHSA-c4xj-289h-xhv9.json @@ -7,12 +7,8 @@ "CVE-2008-3996" ], "details": "Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_CDC_IPUBLISH.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c5x7-f22c-pvgh/GHSA-c5x7-f22c-pvgh.json b/advisories/unreviewed/2022/05/GHSA-c5x7-f22c-pvgh/GHSA-c5x7-f22c-pvgh.json index f1ab65c34df..7ac848bb051 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5x7-f22c-pvgh/GHSA-c5x7-f22c-pvgh.json +++ b/advisories/unreviewed/2022/05/GHSA-c5x7-f22c-pvgh/GHSA-c5x7-f22c-pvgh.json @@ -7,12 +7,8 @@ "CVE-2008-4150" ], "details": "SQL injection vulnerability in picture_category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-3763.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c69p-28r6-q952/GHSA-c69p-28r6-q952.json b/advisories/unreviewed/2022/05/GHSA-c69p-28r6-q952/GHSA-c69p-28r6-q952.json index 1059dc6b5ae..cce7eac98d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-c69p-28r6-q952/GHSA-c69p-28r6-q952.json +++ b/advisories/unreviewed/2022/05/GHSA-c69p-28r6-q952/GHSA-c69p-28r6-q952.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c6gv-4hpw-7xg8/GHSA-c6gv-4hpw-7xg8.json b/advisories/unreviewed/2022/05/GHSA-c6gv-4hpw-7xg8/GHSA-c6gv-4hpw-7xg8.json index 74e3a704be0..cef3d1c029f 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6gv-4hpw-7xg8/GHSA-c6gv-4hpw-7xg8.json +++ b/advisories/unreviewed/2022/05/GHSA-c6gv-4hpw-7xg8/GHSA-c6gv-4hpw-7xg8.json @@ -7,12 +7,8 @@ "CVE-2008-3884" ], "details": "Cross-site scripting (XSS) vulnerability in Blogn (BURO GUN) 1.9.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2006-6176.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c782-xvfc-6mgg/GHSA-c782-xvfc-6mgg.json b/advisories/unreviewed/2022/05/GHSA-c782-xvfc-6mgg/GHSA-c782-xvfc-6mgg.json index 322b61093e3..e3ce160199b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c782-xvfc-6mgg/GHSA-c782-xvfc-6mgg.json +++ b/advisories/unreviewed/2022/05/GHSA-c782-xvfc-6mgg/GHSA-c782-xvfc-6mgg.json @@ -7,12 +7,8 @@ "CVE-2008-4345" ], "details": "SQL injection vulnerability in download.php in WebPortal CMS 0.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the aid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c8x9-94v9-jvwf/GHSA-c8x9-94v9-jvwf.json b/advisories/unreviewed/2022/05/GHSA-c8x9-94v9-jvwf/GHSA-c8x9-94v9-jvwf.json index 37a695b6bf4..2d31ff90d9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8x9-94v9-jvwf/GHSA-c8x9-94v9-jvwf.json +++ b/advisories/unreviewed/2022/05/GHSA-c8x9-94v9-jvwf/GHSA-c8x9-94v9-jvwf.json @@ -7,12 +7,8 @@ "CVE-2008-4079" ], "details": "Cross-site scripting (XSS) vulnerability in Movable Type (MT) 4.x through 4.20, and 3.36 and earlier; Movable Type Enterprise 4.x through 4.20, and 1.54 and earlier; and Movable Type Community Solution allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cchp-g24m-g4jm/GHSA-cchp-g24m-g4jm.json b/advisories/unreviewed/2022/05/GHSA-cchp-g24m-g4jm/GHSA-cchp-g24m-g4jm.json index 461e8fa4ed9..e12368f5102 100644 --- a/advisories/unreviewed/2022/05/GHSA-cchp-g24m-g4jm/GHSA-cchp-g24m-g4jm.json +++ b/advisories/unreviewed/2022/05/GHSA-cchp-g24m-g4jm/GHSA-cchp-g24m-g4jm.json @@ -7,12 +7,8 @@ "CVE-2008-4178" ], "details": "SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and Downline Goldmine Builder allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ccv4-6623-442v/GHSA-ccv4-6623-442v.json b/advisories/unreviewed/2022/05/GHSA-ccv4-6623-442v/GHSA-ccv4-6623-442v.json index 1e4e8f12282..a956dddd446 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccv4-6623-442v/GHSA-ccv4-6623-442v.json +++ b/advisories/unreviewed/2022/05/GHSA-ccv4-6623-442v/GHSA-ccv4-6623-442v.json @@ -7,12 +7,8 @@ "CVE-2008-4012" ], "details": "Unspecified vulnerability in the WebLogic Workshop component in BEA Product Suite WLW 8.1SP5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to \"some NetUI pageflows.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cfmc-g2m2-7ffx/GHSA-cfmc-g2m2-7ffx.json b/advisories/unreviewed/2022/05/GHSA-cfmc-g2m2-7ffx/GHSA-cfmc-g2m2-7ffx.json index c6ac7dd825b..d660d529c7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfmc-g2m2-7ffx/GHSA-cfmc-g2m2-7ffx.json +++ b/advisories/unreviewed/2022/05/GHSA-cfmc-g2m2-7ffx/GHSA-cfmc-g2m2-7ffx.json @@ -7,12 +7,8 @@ "CVE-2008-4395" ], "details": "Multiple buffer overflows in the ndiswrapper module 1.53 for the Linux kernel 2.6 allow remote attackers to execute arbitrary code by sending packets over a local wireless network that specify long ESSIDs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cg7x-wpjc-28wr/GHSA-cg7x-wpjc-28wr.json b/advisories/unreviewed/2022/05/GHSA-cg7x-wpjc-28wr/GHSA-cg7x-wpjc-28wr.json index 1af5b34147e..1d29a0a3159 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg7x-wpjc-28wr/GHSA-cg7x-wpjc-28wr.json +++ b/advisories/unreviewed/2022/05/GHSA-cg7x-wpjc-28wr/GHSA-cg7x-wpjc-28wr.json @@ -7,12 +7,8 @@ "CVE-2008-4278" ], "details": "VMware VirtualCenter 2.5 before Update 3 build 119838 on Windows displays a user's password in cleartext when the password contains unspecified special characters, which allows physically proximate attackers to steal the password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cgmg-28mj-xfpc/GHSA-cgmg-28mj-xfpc.json b/advisories/unreviewed/2022/05/GHSA-cgmg-28mj-xfpc/GHSA-cgmg-28mj-xfpc.json index 46a4c6a2023..ea1377b16c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgmg-28mj-xfpc/GHSA-cgmg-28mj-xfpc.json +++ b/advisories/unreviewed/2022/05/GHSA-cgmg-28mj-xfpc/GHSA-cgmg-28mj-xfpc.json @@ -7,12 +7,8 @@ "CVE-2008-3811" ], "details": "Cisco IOS 12.2 and 12.4, when NAT Skinny Call Control Protocol (SCCP) Fragmentation Support is enabled, allows remote attackers to cause a denial of service (device reload) via segmented SCCP messages, aka Cisco Bug ID CSCsi17020, a different vulnerability than CVE-2008-3810.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ch44-mjv9-gpxr/GHSA-ch44-mjv9-gpxr.json b/advisories/unreviewed/2022/05/GHSA-ch44-mjv9-gpxr/GHSA-ch44-mjv9-gpxr.json index b98bc905c7f..39f71807ac6 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch44-mjv9-gpxr/GHSA-ch44-mjv9-gpxr.json +++ b/advisories/unreviewed/2022/05/GHSA-ch44-mjv9-gpxr/GHSA-ch44-mjv9-gpxr.json @@ -7,12 +7,8 @@ "CVE-2008-3982" ], "details": "Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LT and WMSYS.LT, a different vulnerability than CVE-2008-3983 and CVE-2008-3984.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-chjq-hm23-jp3m/GHSA-chjq-hm23-jp3m.json b/advisories/unreviewed/2022/05/GHSA-chjq-hm23-jp3m/GHSA-chjq-hm23-jp3m.json index 5f8aad4cbc6..a8968724f6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-chjq-hm23-jp3m/GHSA-chjq-hm23-jp3m.json +++ b/advisories/unreviewed/2022/05/GHSA-chjq-hm23-jp3m/GHSA-chjq-hm23-jp3m.json @@ -7,12 +7,8 @@ "CVE-2008-3809" ], "details": "Cisco IOS 12.0 through 12.4 on Gigabit Switch Router (GSR) devices (aka 12000 Series routers) allows remote attackers to cause a denial of service (device crash) via a malformed Protocol Independent Multicast (PIM) packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-chmv-527h-xmg2/GHSA-chmv-527h-xmg2.json b/advisories/unreviewed/2022/05/GHSA-chmv-527h-xmg2/GHSA-chmv-527h-xmg2.json index eca8a8a52bb..4e084e3ad16 100644 --- a/advisories/unreviewed/2022/05/GHSA-chmv-527h-xmg2/GHSA-chmv-527h-xmg2.json +++ b/advisories/unreviewed/2022/05/GHSA-chmv-527h-xmg2/GHSA-chmv-527h-xmg2.json @@ -7,12 +7,8 @@ "CVE-2008-3805" ], "details": "Cisco IOS 12.0 through 12.4 on Cisco 10000, uBR10012 and uBR7200 series devices handles external UDP packets that are sent to 127.0.0.0/8 addresses intended for IPC communication within the device, which allows remote attackers to cause a denial of service (device or linecard reload) via crafted UDP packets, a different vulnerability than CVE-2008-3806.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-chp9-r3p9-57jf/GHSA-chp9-r3p9-57jf.json b/advisories/unreviewed/2022/05/GHSA-chp9-r3p9-57jf/GHSA-chp9-r3p9-57jf.json index 7183f618f6f..251877faac4 100644 --- a/advisories/unreviewed/2022/05/GHSA-chp9-r3p9-57jf/GHSA-chp9-r3p9-57jf.json +++ b/advisories/unreviewed/2022/05/GHSA-chp9-r3p9-57jf/GHSA-chp9-r3p9-57jf.json @@ -7,12 +7,8 @@ "CVE-2008-3936" ], "details": "The web interface in Dreambox DM500C allows remote attackers to cause a denial of service (application hang) via a long URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cjrf-3f4f-xp9j/GHSA-cjrf-3f4f-xp9j.json b/advisories/unreviewed/2022/05/GHSA-cjrf-3f4f-xp9j/GHSA-cjrf-3f4f-xp9j.json index 4b839a42d8c..7c8cc32178b 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjrf-3f4f-xp9j/GHSA-cjrf-3f4f-xp9j.json +++ b/advisories/unreviewed/2022/05/GHSA-cjrf-3f4f-xp9j/GHSA-cjrf-3f4f-xp9j.json @@ -7,12 +7,8 @@ "CVE-2008-4217" ], "details": "Integer signedness error in BOM in Apple Mac OS X before 10.5.6 allows remote attackers to execute arbitrary code via the headers in a crafted CPIO archive, leading to a stack-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cjv7-fhgm-wvpp/GHSA-cjv7-fhgm-wvpp.json b/advisories/unreviewed/2022/05/GHSA-cjv7-fhgm-wvpp/GHSA-cjv7-fhgm-wvpp.json index 483abeca4da..de095a70fb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjv7-fhgm-wvpp/GHSA-cjv7-fhgm-wvpp.json +++ b/advisories/unreviewed/2022/05/GHSA-cjv7-fhgm-wvpp/GHSA-cjv7-fhgm-wvpp.json @@ -7,12 +7,8 @@ "CVE-2008-4171" ], "details": "SQL injection vulnerability in xmlout.php in Invision Power Board (IP.Board or IPB) 2.2.x and 2.3.x allows remote attackers to execute arbitrary SQL commands via the name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cm46-p4pg-4w4f/GHSA-cm46-p4pg-4w4f.json b/advisories/unreviewed/2022/05/GHSA-cm46-p4pg-4w4f/GHSA-cm46-p4pg-4w4f.json index 463ccd1032d..76ec4fd816c 100644 --- a/advisories/unreviewed/2022/05/GHSA-cm46-p4pg-4w4f/GHSA-cm46-p4pg-4w4f.json +++ b/advisories/unreviewed/2022/05/GHSA-cm46-p4pg-4w4f/GHSA-cm46-p4pg-4w4f.json @@ -7,12 +7,8 @@ "CVE-2008-3969" ], "details": "Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to \"overwrite\" and \"hijack\" existing accounts via unknown vectors related to \"inconsistent handling of the USTATUS_IDENTIFIED state.\" NOTE: this issue exists because of an incomplete fix for CVE-2008-3920.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cmx5-3883-g73v/GHSA-cmx5-3883-g73v.json b/advisories/unreviewed/2022/05/GHSA-cmx5-3883-g73v/GHSA-cmx5-3883-g73v.json index 70a65610739..49dd27f4162 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmx5-3883-g73v/GHSA-cmx5-3883-g73v.json +++ b/advisories/unreviewed/2022/05/GHSA-cmx5-3883-g73v/GHSA-cmx5-3883-g73v.json @@ -7,12 +7,8 @@ "CVE-2008-4333" ], "details": "Cross-site scripting (XSS) vulnerability in PHP infoBoard V.7 Plus allows remote attackers to inject arbitrary web script or HTML via the isname parameter in a newtopic action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cp48-2wcf-rx78/GHSA-cp48-2wcf-rx78.json b/advisories/unreviewed/2022/05/GHSA-cp48-2wcf-rx78/GHSA-cp48-2wcf-rx78.json index 8c750775f3f..b8897099b1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-cp48-2wcf-rx78/GHSA-cp48-2wcf-rx78.json +++ b/advisories/unreviewed/2022/05/GHSA-cp48-2wcf-rx78/GHSA-cp48-2wcf-rx78.json @@ -7,12 +7,8 @@ "CVE-2008-4102" ], "details": "Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_rand function, as demonstrated by guessing password reset tokens, a different vulnerability than CVE-2008-3681.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cpqh-mhhx-jwmj/GHSA-cpqh-mhhx-jwmj.json b/advisories/unreviewed/2022/05/GHSA-cpqh-mhhx-jwmj/GHSA-cpqh-mhhx-jwmj.json index 5086ae9f8b6..459842f5e53 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpqh-mhhx-jwmj/GHSA-cpqh-mhhx-jwmj.json +++ b/advisories/unreviewed/2022/05/GHSA-cpqh-mhhx-jwmj/GHSA-cpqh-mhhx-jwmj.json @@ -7,12 +7,8 @@ "CVE-2008-4064" ], "details": "Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to graphics rendering and (1) handling of a long alert messagebox in the cairo_surface_set_device_offset function, (2) integer overflows when handling animated PNG data in the info_callback function in nsPNGDecoder.cpp, and (3) an integer overflow when handling SVG data in the nsSVGFEGaussianBlurElement::SetupPredivide function in nsSVGFilters.cpp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -140,9 +136,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cq38-9q33-xgmr/GHSA-cq38-9q33-xgmr.json b/advisories/unreviewed/2022/05/GHSA-cq38-9q33-xgmr/GHSA-cq38-9q33-xgmr.json index 2b38c02f718..465ddc43273 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq38-9q33-xgmr/GHSA-cq38-9q33-xgmr.json +++ b/advisories/unreviewed/2022/05/GHSA-cq38-9q33-xgmr/GHSA-cq38-9q33-xgmr.json @@ -7,12 +7,8 @@ "CVE-2008-4365" ], "details": "Cross-site scripting (XSS) vulnerability in search.php in Siteman 1.1.11 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cq8w-h669-78g5/GHSA-cq8w-h669-78g5.json b/advisories/unreviewed/2022/05/GHSA-cq8w-h669-78g5/GHSA-cq8w-h669-78g5.json index 232b05e3e10..db1dd459281 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq8w-h669-78g5/GHSA-cq8w-h669-78g5.json +++ b/advisories/unreviewed/2022/05/GHSA-cq8w-h669-78g5/GHSA-cq8w-h669-78g5.json @@ -7,12 +7,8 @@ "CVE-2008-4050" ], "details": "A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to (1) create and read arbitrary registry values via the RegistryValue method, and (2) read arbitrary files via the GetTextFile method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cqrh-v7qh-v682/GHSA-cqrh-v7qh-v682.json b/advisories/unreviewed/2022/05/GHSA-cqrh-v7qh-v682/GHSA-cqrh-v7qh-v682.json index 0ce06d97b5a..d3d446d61f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqrh-v7qh-v682/GHSA-cqrh-v7qh-v682.json +++ b/advisories/unreviewed/2022/05/GHSA-cqrh-v7qh-v682/GHSA-cqrh-v7qh-v682.json @@ -7,12 +7,8 @@ "CVE-2013-6786" ], "details": "Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the \"forbidden author header\" protection mechanism is bypassed, allows remote attackers to inject arbitrary web script or HTML by requesting a nonexistent URI in conjunction with a crafted HTTP Referer header that is not properly handled in a 404 page. NOTE: there is no CVE for a \"URL redirection\" issue that some sources list separately.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cr36-9r2x-97q5/GHSA-cr36-9r2x-97q5.json b/advisories/unreviewed/2022/05/GHSA-cr36-9r2x-97q5/GHSA-cr36-9r2x-97q5.json index ddafe432f8b..53a88a96f7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-cr36-9r2x-97q5/GHSA-cr36-9r2x-97q5.json +++ b/advisories/unreviewed/2022/05/GHSA-cr36-9r2x-97q5/GHSA-cr36-9r2x-97q5.json @@ -7,12 +7,8 @@ "CVE-2008-4047" ], "details": "Unspecified vulnerability in Novell Forum (formerly SiteScape Forum) 7.0, 7.1, 7.2, 7.3, and 8.0 allows remote attackers to execute arbitrary TCL code via a modified URL. NOTE: this might overlap CVE-2007-6515.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cr5r-q6mh-hr56/GHSA-cr5r-q6mh-hr56.json b/advisories/unreviewed/2022/05/GHSA-cr5r-q6mh-hr56/GHSA-cr5r-q6mh-hr56.json index 75a41ee0d72..8980a556d2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-cr5r-q6mh-hr56/GHSA-cr5r-q6mh-hr56.json +++ b/advisories/unreviewed/2022/05/GHSA-cr5r-q6mh-hr56/GHSA-cr5r-q6mh-hr56.json @@ -7,12 +7,8 @@ "CVE-2008-3913" ], "details": "Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to \"error handling logic\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-crw4-5c7w-w3j2/GHSA-crw4-5c7w-w3j2.json b/advisories/unreviewed/2022/05/GHSA-crw4-5c7w-w3j2/GHSA-crw4-5c7w-w3j2.json index cff9387b38f..d4452998121 100644 --- a/advisories/unreviewed/2022/05/GHSA-crw4-5c7w-w3j2/GHSA-crw4-5c7w-w3j2.json +++ b/advisories/unreviewed/2022/05/GHSA-crw4-5c7w-w3j2/GHSA-crw4-5c7w-w3j2.json @@ -7,12 +7,8 @@ "CVE-2008-4225" ], "details": "Integer overflow in the xmlBufferResize function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (infinite loop) via a large XML document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -224,9 +220,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cv35-jxpg-6g7r/GHSA-cv35-jxpg-6g7r.json b/advisories/unreviewed/2022/05/GHSA-cv35-jxpg-6g7r/GHSA-cv35-jxpg-6g7r.json index 76eef49bb35..e4c7242b55a 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv35-jxpg-6g7r/GHSA-cv35-jxpg-6g7r.json +++ b/advisories/unreviewed/2022/05/GHSA-cv35-jxpg-6g7r/GHSA-cv35-jxpg-6g7r.json @@ -7,12 +7,8 @@ "CVE-2008-3921" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in AWStats Totals 1.0 through 1.14 allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cvgp-9gf8-257q/GHSA-cvgp-9gf8-257q.json b/advisories/unreviewed/2022/05/GHSA-cvgp-9gf8-257q/GHSA-cvgp-9gf8-257q.json index 3c224e432f6..15c9cdc55d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvgp-9gf8-257q/GHSA-cvgp-9gf8-257q.json +++ b/advisories/unreviewed/2022/05/GHSA-cvgp-9gf8-257q/GHSA-cvgp-9gf8-257q.json @@ -7,12 +7,8 @@ "CVE-2008-3882" ], "details": "Unspecified \"Command Injection\" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1) the executeFilter function in zm_html_view_events.php and (2) the run_state parameter to zm_html_view_state.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cvhh-gq6m-x64f/GHSA-cvhh-gq6m-x64f.json b/advisories/unreviewed/2022/05/GHSA-cvhh-gq6m-x64f/GHSA-cvhh-gq6m-x64f.json index c6ca96bbb73..8149a5defa1 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvhh-gq6m-x64f/GHSA-cvhh-gq6m-x64f.json +++ b/advisories/unreviewed/2022/05/GHSA-cvhh-gq6m-x64f/GHSA-cvhh-gq6m-x64f.json @@ -7,12 +7,8 @@ "CVE-2008-4329" ], "details": "PHP remote file inclusion vulnerability in cms/system/openengine.php in openEngine 2.0 beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the oe_classpath parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cwr2-c5mc-rxv6/GHSA-cwr2-c5mc-rxv6.json b/advisories/unreviewed/2022/05/GHSA-cwr2-c5mc-rxv6/GHSA-cwr2-c5mc-rxv6.json index 8fb70372c82..a1cca48b734 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwr2-c5mc-rxv6/GHSA-cwr2-c5mc-rxv6.json +++ b/advisories/unreviewed/2022/05/GHSA-cwr2-c5mc-rxv6/GHSA-cwr2-c5mc-rxv6.json @@ -7,12 +7,8 @@ "CVE-2008-4098" ], "details": "MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cwx3-9c5v-p3h3/GHSA-cwx3-9c5v-p3h3.json b/advisories/unreviewed/2022/05/GHSA-cwx3-9c5v-p3h3/GHSA-cwx3-9c5v-p3h3.json index e303cd8cfd2..4f73cba405a 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwx3-9c5v-p3h3/GHSA-cwx3-9c5v-p3h3.json +++ b/advisories/unreviewed/2022/05/GHSA-cwx3-9c5v-p3h3/GHSA-cwx3-9c5v-p3h3.json @@ -7,12 +7,8 @@ "CVE-2008-4328" ], "details": "SQL injection vulnerability in site_search.php in EasyRealtorPRO 2008 allows remote attackers to execute arbitrary SQL commands via the (1) item, (2) search_ordermethod, and (3) search_order parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cxgw-6684-hhgv/GHSA-cxgw-6684-hhgv.json b/advisories/unreviewed/2022/05/GHSA-cxgw-6684-hhgv/GHSA-cxgw-6684-hhgv.json index 5c140c0218c..0c51dbcdab2 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxgw-6684-hhgv/GHSA-cxgw-6684-hhgv.json +++ b/advisories/unreviewed/2022/05/GHSA-cxgw-6684-hhgv/GHSA-cxgw-6684-hhgv.json @@ -7,12 +7,8 @@ "CVE-2008-3943" ], "details": "SQL injection vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to execute arbitrary SQL commands via the r parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f29q-27qw-5hqg/GHSA-f29q-27qw-5hqg.json b/advisories/unreviewed/2022/05/GHSA-f29q-27qw-5hqg/GHSA-f29q-27qw-5hqg.json index a5f7b436171..405c0c9cf25 100644 --- a/advisories/unreviewed/2022/05/GHSA-f29q-27qw-5hqg/GHSA-f29q-27qw-5hqg.json +++ b/advisories/unreviewed/2022/05/GHSA-f29q-27qw-5hqg/GHSA-f29q-27qw-5hqg.json @@ -7,12 +7,8 @@ "CVE-2008-3813" ], "details": "Unspecified vulnerability in Cisco IOS 12.2 and 12.4, when the L2TP mgmt daemon process is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted L2TP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f2cw-4jjq-5crf/GHSA-f2cw-4jjq-5crf.json b/advisories/unreviewed/2022/05/GHSA-f2cw-4jjq-5crf/GHSA-f2cw-4jjq-5crf.json index e86d243255e..314023064d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2cw-4jjq-5crf/GHSA-f2cw-4jjq-5crf.json +++ b/advisories/unreviewed/2022/05/GHSA-f2cw-4jjq-5crf/GHSA-f2cw-4jjq-5crf.json @@ -7,12 +7,8 @@ "CVE-2008-4179" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in NooMS 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) page_id parameter to smileys.php and the (2) q parameter to search.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f2rq-rvpq-f26q/GHSA-f2rq-rvpq-f26q.json b/advisories/unreviewed/2022/05/GHSA-f2rq-rvpq-f26q/GHSA-f2rq-rvpq-f26q.json index 23c8f581bcf..8a7e8b4b40d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2rq-rvpq-f26q/GHSA-f2rq-rvpq-f26q.json +++ b/advisories/unreviewed/2022/05/GHSA-f2rq-rvpq-f26q/GHSA-f2rq-rvpq-f26q.json @@ -7,12 +7,8 @@ "CVE-2008-3735" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in PHPizabi before 848 Core HotFix Pack 3 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a blogs.search action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f2xc-h3r6-w96x/GHSA-f2xc-h3r6-w96x.json b/advisories/unreviewed/2022/05/GHSA-f2xc-h3r6-w96x/GHSA-f2xc-h3r6-w96x.json index ebb850c1c6f..d2763149329 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2xc-h3r6-w96x/GHSA-f2xc-h3r6-w96x.json +++ b/advisories/unreviewed/2022/05/GHSA-f2xc-h3r6-w96x/GHSA-f2xc-h3r6-w96x.json @@ -7,12 +7,8 @@ "CVE-2008-4184" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in webCMS Portal Edition allows remote attackers to inject arbitrary web script or HTML via the patron parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f389-mwxq-2mj4/GHSA-f389-mwxq-2mj4.json b/advisories/unreviewed/2022/05/GHSA-f389-mwxq-2mj4/GHSA-f389-mwxq-2mj4.json index 22a1ddb6824..10d71aacbae 100644 --- a/advisories/unreviewed/2022/05/GHSA-f389-mwxq-2mj4/GHSA-f389-mwxq-2mj4.json +++ b/advisories/unreviewed/2022/05/GHSA-f389-mwxq-2mj4/GHSA-f389-mwxq-2mj4.json @@ -7,12 +7,8 @@ "CVE-2008-3951" ], "details": "SQL injection vulnerability in view_ann.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the ann_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6wq-25v5-wmh5/GHSA-f6wq-25v5-wmh5.json b/advisories/unreviewed/2022/05/GHSA-f6wq-25v5-wmh5/GHSA-f6wq-25v5-wmh5.json index 4d863ed5600..8b58edfc1b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6wq-25v5-wmh5/GHSA-f6wq-25v5-wmh5.json +++ b/advisories/unreviewed/2022/05/GHSA-f6wq-25v5-wmh5/GHSA-f6wq-25v5-wmh5.json @@ -7,12 +7,8 @@ "CVE-2008-3747" ], "details": "The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f73g-4ffh-f84r/GHSA-f73g-4ffh-f84r.json b/advisories/unreviewed/2022/05/GHSA-f73g-4ffh-f84r/GHSA-f73g-4ffh-f84r.json index ae43f82798a..f697f63877d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f73g-4ffh-f84r/GHSA-f73g-4ffh-f84r.json +++ b/advisories/unreviewed/2022/05/GHSA-f73g-4ffh-f84r/GHSA-f73g-4ffh-f84r.json @@ -7,12 +7,8 @@ "CVE-2008-4305" ], "details": "Static code injection vulnerability in installation/setup.php in phpCollab 2.5 rc3 and earlier allows remote authenticated administrators to inject arbitrary PHP code into include/settings.php via the URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f82v-mcfc-hrmc/GHSA-f82v-mcfc-hrmc.json b/advisories/unreviewed/2022/05/GHSA-f82v-mcfc-hrmc/GHSA-f82v-mcfc-hrmc.json index 9962d51f1b3..f706024f440 100644 --- a/advisories/unreviewed/2022/05/GHSA-f82v-mcfc-hrmc/GHSA-f82v-mcfc-hrmc.json +++ b/advisories/unreviewed/2022/05/GHSA-f82v-mcfc-hrmc/GHSA-f82v-mcfc-hrmc.json @@ -7,12 +7,8 @@ "CVE-2008-3732" ], "details": "Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TTA file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f8j2-9mw8-mxr6/GHSA-f8j2-9mw8-mxr6.json b/advisories/unreviewed/2022/05/GHSA-f8j2-9mw8-mxr6/GHSA-f8j2-9mw8-mxr6.json index fe7f09947db..161915fab6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8j2-9mw8-mxr6/GHSA-f8j2-9mw8-mxr6.json +++ b/advisories/unreviewed/2022/05/GHSA-f8j2-9mw8-mxr6/GHSA-f8j2-9mw8-mxr6.json @@ -7,12 +7,8 @@ "CVE-2008-4378" ], "details": "SQL injection vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f8xq-rp24-pxq8/GHSA-f8xq-rp24-pxq8.json b/advisories/unreviewed/2022/05/GHSA-f8xq-rp24-pxq8/GHSA-f8xq-rp24-pxq8.json index 32b1cf8c34f..137b9d468c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8xq-rp24-pxq8/GHSA-f8xq-rp24-pxq8.json +++ b/advisories/unreviewed/2022/05/GHSA-f8xq-rp24-pxq8/GHSA-f8xq-rp24-pxq8.json @@ -7,12 +7,8 @@ "CVE-2008-3900" ], "details": "Intel firmware PE94510M.86A.0050.2007.0710.1559 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f945-m2g3-2wxw/GHSA-f945-m2g3-2wxw.json b/advisories/unreviewed/2022/05/GHSA-f945-m2g3-2wxw/GHSA-f945-m2g3-2wxw.json index d1068155360..5a76c19a6fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-f945-m2g3-2wxw/GHSA-f945-m2g3-2wxw.json +++ b/advisories/unreviewed/2022/05/GHSA-f945-m2g3-2wxw/GHSA-f945-m2g3-2wxw.json @@ -7,12 +7,8 @@ "CVE-2008-4006" ], "details": "Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.1.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f9gf-w2r7-5cgq/GHSA-f9gf-w2r7-5cgq.json b/advisories/unreviewed/2022/05/GHSA-f9gf-w2r7-5cgq/GHSA-f9gf-w2r7-5cgq.json index ce5fd96cd4e..10d3ac9253d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9gf-w2r7-5cgq/GHSA-f9gf-w2r7-5cgq.json +++ b/advisories/unreviewed/2022/05/GHSA-f9gf-w2r7-5cgq/GHSA-f9gf-w2r7-5cgq.json @@ -7,12 +7,8 @@ "CVE-2008-4330" ], "details": "Directory traversal vulnerability in index.php in LanSuite 3.3.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the design parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f9h9-6j2w-gm67/GHSA-f9h9-6j2w-gm67.json b/advisories/unreviewed/2022/05/GHSA-f9h9-6j2w-gm67/GHSA-f9h9-6j2w-gm67.json index 30a505068b7..5c978756db6 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9h9-6j2w-gm67/GHSA-f9h9-6j2w-gm67.json +++ b/advisories/unreviewed/2022/05/GHSA-f9h9-6j2w-gm67/GHSA-f9h9-6j2w-gm67.json @@ -7,12 +7,8 @@ "CVE-2008-3941" ], "details": "Cross-site scripting (XSS) vulnerability in BizDirectory 2.04 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter in a search action to the default URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f9wh-r74m-7mrv/GHSA-f9wh-r74m-7mrv.json b/advisories/unreviewed/2022/05/GHSA-f9wh-r74m-7mrv/GHSA-f9wh-r74m-7mrv.json index f7148bf3563..eb86d6c86ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9wh-r74m-7mrv/GHSA-f9wh-r74m-7mrv.json +++ b/advisories/unreviewed/2022/05/GHSA-f9wh-r74m-7mrv/GHSA-f9wh-r74m-7mrv.json @@ -7,12 +7,8 @@ "CVE-2008-3894" ], "details": "IBM Lenovo firmware 7CETB5WW 2.05 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ffpp-v4vp-9vvh/GHSA-ffpp-v4vp-9vvh.json b/advisories/unreviewed/2022/05/GHSA-ffpp-v4vp-9vvh/GHSA-ffpp-v4vp-9vvh.json index c8d0fdf50e1..009dd156b9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-ffpp-v4vp-9vvh/GHSA-ffpp-v4vp-9vvh.json +++ b/advisories/unreviewed/2022/05/GHSA-ffpp-v4vp-9vvh/GHSA-ffpp-v4vp-9vvh.json @@ -7,12 +7,8 @@ "CVE-2008-4405" ], "details": "xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's write access within this tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue was originally reported as an issue in libvirt 0.3.3 and xenstore, but CVE is considering the core issue to be related to Xen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ffqx-8c7j-w3c7/GHSA-ffqx-8c7j-w3c7.json b/advisories/unreviewed/2022/05/GHSA-ffqx-8c7j-w3c7/GHSA-ffqx-8c7j-w3c7.json index 4869de5e6b0..670699e6ea3 100644 --- a/advisories/unreviewed/2022/05/GHSA-ffqx-8c7j-w3c7/GHSA-ffqx-8c7j-w3c7.json +++ b/advisories/unreviewed/2022/05/GHSA-ffqx-8c7j-w3c7/GHSA-ffqx-8c7j-w3c7.json @@ -7,12 +7,8 @@ "CVE-2008-4151" ], "details": "Directory traversal vulnerability in collect.php in CYASK 3.x allows remote attackers to read arbitrary files via a .. (dot dot) in the neturl parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fg4c-q4wp-fvrw/GHSA-fg4c-q4wp-fvrw.json b/advisories/unreviewed/2022/05/GHSA-fg4c-q4wp-fvrw/GHSA-fg4c-q4wp-fvrw.json index 83e9019657b..bf601ec4e95 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg4c-q4wp-fvrw/GHSA-fg4c-q4wp-fvrw.json +++ b/advisories/unreviewed/2022/05/GHSA-fg4c-q4wp-fvrw/GHSA-fg4c-q4wp-fvrw.json @@ -7,12 +7,8 @@ "CVE-2008-3880" ], "details": "SQL injection vulnerability in zm_html_view_event.php in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary SQL commands via the filter array parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fg84-7476-jjh7/GHSA-fg84-7476-jjh7.json b/advisories/unreviewed/2022/05/GHSA-fg84-7476-jjh7/GHSA-fg84-7476-jjh7.json index 0811222562c..de5f2450873 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg84-7476-jjh7/GHSA-fg84-7476-jjh7.json +++ b/advisories/unreviewed/2022/05/GHSA-fg84-7476-jjh7/GHSA-fg84-7476-jjh7.json @@ -7,12 +7,8 @@ "CVE-2008-3976" ], "details": "Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-3413 and CVE-2009-3414.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fh38-4q99-7449/GHSA-fh38-4q99-7449.json b/advisories/unreviewed/2022/05/GHSA-fh38-4q99-7449/GHSA-fh38-4q99-7449.json index c0c8d8f3009..dab01586a69 100644 --- a/advisories/unreviewed/2022/05/GHSA-fh38-4q99-7449/GHSA-fh38-4q99-7449.json +++ b/advisories/unreviewed/2022/05/GHSA-fh38-4q99-7449/GHSA-fh38-4q99-7449.json @@ -7,12 +7,8 @@ "CVE-2008-3946" ], "details": "The finger client in HP TCP/IP Services for OpenVMS 5.x allows local users to read arbitrary files via a link corresponding to a (1) .plan or (2) .project file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fj2p-r342-gx3m/GHSA-fj2p-r342-gx3m.json b/advisories/unreviewed/2022/05/GHSA-fj2p-r342-gx3m/GHSA-fj2p-r342-gx3m.json index 1966392401a..6f66832ad46 100644 --- a/advisories/unreviewed/2022/05/GHSA-fj2p-r342-gx3m/GHSA-fj2p-r342-gx3m.json +++ b/advisories/unreviewed/2022/05/GHSA-fj2p-r342-gx3m/GHSA-fj2p-r342-gx3m.json @@ -7,12 +7,8 @@ "CVE-2008-3964" ], "details": "Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted zTXt chunks, related to (1) the png_push_read_zTXt function in pngread.c, and possibly related to (2) pngtest.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpfc-23vv-2cfh/GHSA-fpfc-23vv-2cfh.json b/advisories/unreviewed/2022/05/GHSA-fpfc-23vv-2cfh/GHSA-fpfc-23vv-2cfh.json index ee0c88b5a9c..f1494356d4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpfc-23vv-2cfh/GHSA-fpfc-23vv-2cfh.json +++ b/advisories/unreviewed/2022/05/GHSA-fpfc-23vv-2cfh/GHSA-fpfc-23vv-2cfh.json @@ -7,12 +7,8 @@ "CVE-2008-4121" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in cpCommerce before 1.2.4 allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter in a search.quick action to search.php and (2) the name parameter in a sendtofriend action to sendtofriend.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpgr-7j4x-rw8m/GHSA-fpgr-7j4x-rw8m.json b/advisories/unreviewed/2022/05/GHSA-fpgr-7j4x-rw8m/GHSA-fpgr-7j4x-rw8m.json index bfa5741cc8c..3dfb8244c03 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpgr-7j4x-rw8m/GHSA-fpgr-7j4x-rw8m.json +++ b/advisories/unreviewed/2022/05/GHSA-fpgr-7j4x-rw8m/GHSA-fpgr-7j4x-rw8m.json @@ -7,12 +7,8 @@ "CVE-2008-3993" ], "details": "Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2 and 12.0.4 allows remote authenticated users to affect integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fq24-8rh6-w2ch/GHSA-fq24-8rh6-w2ch.json b/advisories/unreviewed/2022/05/GHSA-fq24-8rh6-w2ch/GHSA-fq24-8rh6-w2ch.json index 57de67c78be..32ae0015e65 100644 --- a/advisories/unreviewed/2022/05/GHSA-fq24-8rh6-w2ch/GHSA-fq24-8rh6-w2ch.json +++ b/advisories/unreviewed/2022/05/GHSA-fq24-8rh6-w2ch/GHSA-fq24-8rh6-w2ch.json @@ -7,12 +7,8 @@ "CVE-2008-3971" ], "details": "Heap-based buffer overflow in the open_man_file function in callbacks.c in gmanedit 0.4.1 allows remote attackers to execute arbitrary code via a crafted man page, which is not properly handled during utf8 conversion. NOTE: another overflow was reported using a configuration file, but that vector does not have a scenario that crosses privilege boundaries.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fq3m-2532-mwjq/GHSA-fq3m-2532-mwjq.json b/advisories/unreviewed/2022/05/GHSA-fq3m-2532-mwjq/GHSA-fq3m-2532-mwjq.json index 5f20a44b385..eff7e2018e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-fq3m-2532-mwjq/GHSA-fq3m-2532-mwjq.json +++ b/advisories/unreviewed/2022/05/GHSA-fq3m-2532-mwjq/GHSA-fq3m-2532-mwjq.json @@ -7,12 +7,8 @@ "CVE-2008-4086" ], "details": "SQL injection vulnerability in index.php in Reciprocal Links Manager 1.1 allows remote attackers to execute arbitrary SQL commands via the site parameter in an open action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fqgf-h56q-h3fr/GHSA-fqgf-h56q-h3fr.json b/advisories/unreviewed/2022/05/GHSA-fqgf-h56q-h3fr/GHSA-fqgf-h56q-h3fr.json index c99d5527efe..4406b7f36c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-fqgf-h56q-h3fr/GHSA-fqgf-h56q-h3fr.json +++ b/advisories/unreviewed/2022/05/GHSA-fqgf-h56q-h3fr/GHSA-fqgf-h56q-h3fr.json @@ -7,12 +7,8 @@ "CVE-2008-3806" ], "details": "Cisco IOS 12.0 through 12.4 on Cisco 10000, uBR10012 and uBR7200 series devices handles external UDP packets that are sent to 127.0.0.0/8 addresses intended for IPC communication within the device, which allows remote attackers to cause a denial of service (device or linecard reload) via crafted UDP packets, a different vulnerability than CVE-2008-3805.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fr66-q3h8-gpgg/GHSA-fr66-q3h8-gpgg.json b/advisories/unreviewed/2022/05/GHSA-fr66-q3h8-gpgg/GHSA-fr66-q3h8-gpgg.json index 85183e2c8d6..166fe5a9381 100644 --- a/advisories/unreviewed/2022/05/GHSA-fr66-q3h8-gpgg/GHSA-fr66-q3h8-gpgg.json +++ b/advisories/unreviewed/2022/05/GHSA-fr66-q3h8-gpgg/GHSA-fr66-q3h8-gpgg.json @@ -7,12 +7,8 @@ "CVE-2008-3820" ], "details": "Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes TCP ports used by the MySQL daemon and IEV server, which allows remote attackers to obtain \"root access\" to IEV via unspecified use of TCP sessions to these ports.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-frc3-5qxf-hxg5/GHSA-frc3-5qxf-hxg5.json b/advisories/unreviewed/2022/05/GHSA-frc3-5qxf-hxg5/GHSA-frc3-5qxf-hxg5.json index 5d0ff4197af..3b3e843e57b 100644 --- a/advisories/unreviewed/2022/05/GHSA-frc3-5qxf-hxg5/GHSA-frc3-5qxf-hxg5.json +++ b/advisories/unreviewed/2022/05/GHSA-frc3-5qxf-hxg5/GHSA-frc3-5qxf-hxg5.json @@ -7,12 +7,8 @@ "CVE-2008-4048" ], "details": "Heap-based buffer overflow in a certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to execute arbitrary code via a long third argument to the CreateURLShortcut method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fw27-96f7-xwpc/GHSA-fw27-96f7-xwpc.json b/advisories/unreviewed/2022/05/GHSA-fw27-96f7-xwpc/GHSA-fw27-96f7-xwpc.json index 82db1a089e6..d6ab9d8a4b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw27-96f7-xwpc/GHSA-fw27-96f7-xwpc.json +++ b/advisories/unreviewed/2022/05/GHSA-fw27-96f7-xwpc/GHSA-fw27-96f7-xwpc.json @@ -7,12 +7,8 @@ "CVE-2008-4369" ], "details": "SQL injection vulnerability in pics.php in Availscript Photo Album allows remote attackers to execute arbitrary SQL commands via the sid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fw8j-hgr2-4336/GHSA-fw8j-hgr2-4336.json b/advisories/unreviewed/2022/05/GHSA-fw8j-hgr2-4336/GHSA-fw8j-hgr2-4336.json index 41ce7e22c73..08fcfa0ffda 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw8j-hgr2-4336/GHSA-fw8j-hgr2-4336.json +++ b/advisories/unreviewed/2022/05/GHSA-fw8j-hgr2-4336/GHSA-fw8j-hgr2-4336.json @@ -7,12 +7,8 @@ "CVE-2008-4015" ], "details": "Unspecified vulnerability in the Oracle Streams component in Oracle Database 10.1.0.5 allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_STREAMS_AUTH.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fwxc-72gp-54jq/GHSA-fwxc-72gp-54jq.json b/advisories/unreviewed/2022/05/GHSA-fwxc-72gp-54jq/GHSA-fwxc-72gp-54jq.json index 75a493e6374..d0332c721da 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwxc-72gp-54jq/GHSA-fwxc-72gp-54jq.json +++ b/advisories/unreviewed/2022/05/GHSA-fwxc-72gp-54jq/GHSA-fwxc-72gp-54jq.json @@ -7,12 +7,8 @@ "CVE-2008-3906" ], "details": "CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fx67-f89m-hrfr/GHSA-fx67-f89m-hrfr.json b/advisories/unreviewed/2022/05/GHSA-fx67-f89m-hrfr/GHSA-fx67-f89m-hrfr.json index 0fb0ee6d924..f071b14a9f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-fx67-f89m-hrfr/GHSA-fx67-f89m-hrfr.json +++ b/advisories/unreviewed/2022/05/GHSA-fx67-f89m-hrfr/GHSA-fx67-f89m-hrfr.json @@ -7,12 +7,8 @@ "CVE-2008-3862" ], "details": "Stack-based buffer overflow in CGI programs in the server in Trend Micro OfficeScan 7.3 Patch 4 build 1367 and other builds before 1374, and 8.0 SP1 Patch 1 before build 3110, allows remote attackers to execute arbitrary code via an HTTP POST request containing crafted form data, related to \"parsing CGI requests.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fx93-653r-c2p5/GHSA-fx93-653r-c2p5.json b/advisories/unreviewed/2022/05/GHSA-fx93-653r-c2p5/GHSA-fx93-653r-c2p5.json index 500a02895b0..bf33903c085 100644 --- a/advisories/unreviewed/2022/05/GHSA-fx93-653r-c2p5/GHSA-fx93-653r-c2p5.json +++ b/advisories/unreviewed/2022/05/GHSA-fx93-653r-c2p5/GHSA-fx93-653r-c2p5.json @@ -7,12 +7,8 @@ "CVE-2008-3877" ], "details": "Stack-based buffer overflow in Acoustica Mixcraft 4.1 Build 96 and 4.2 Build 98 allows user-assisted attackers to execute arbitrary code via a crafted .mx4 file. NOTE: it was later reported that version 3 is also affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fxqq-w589-c8v4/GHSA-fxqq-w589-c8v4.json b/advisories/unreviewed/2022/05/GHSA-fxqq-w589-c8v4/GHSA-fxqq-w589-c8v4.json index 8e4bc1cc240..780162af22a 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxqq-w589-c8v4/GHSA-fxqq-w589-c8v4.json +++ b/advisories/unreviewed/2022/05/GHSA-fxqq-w589-c8v4/GHSA-fxqq-w589-c8v4.json @@ -7,12 +7,8 @@ "CVE-2008-4366" ], "details": "Unrestricted file upload vulnerability in the image upload component in Camera Life 2.6.2b4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in a user directory under images/photos/upload.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g2xj-f72j-cf22/GHSA-g2xj-f72j-cf22.json b/advisories/unreviewed/2022/05/GHSA-g2xj-f72j-cf22/GHSA-g2xj-f72j-cf22.json index 440f11989cc..b3f4162c3e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2xj-f72j-cf22/GHSA-g2xj-f72j-cf22.json +++ b/advisories/unreviewed/2022/05/GHSA-g2xj-f72j-cf22/GHSA-g2xj-f72j-cf22.json @@ -7,12 +7,8 @@ "CVE-2008-4163" ], "details": "Unspecified vulnerability in ISC BIND 9.3.5-P2-W1, 9.4.2-P2-W1, and 9.5.0-P2-W1 on Windows allows remote attackers to cause a denial of service (UDP client handler termination) via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g33c-xmc8-j87j/GHSA-g33c-xmc8-j87j.json b/advisories/unreviewed/2022/05/GHSA-g33c-xmc8-j87j/GHSA-g33c-xmc8-j87j.json index 79c4063b426..028cc7c923f 100644 --- a/advisories/unreviewed/2022/05/GHSA-g33c-xmc8-j87j/GHSA-g33c-xmc8-j87j.json +++ b/advisories/unreviewed/2022/05/GHSA-g33c-xmc8-j87j/GHSA-g33c-xmc8-j87j.json @@ -7,12 +7,8 @@ "CVE-2008-4337" ], "details": "Cross-site scripting (XSS) vulnerability in Bitweaver 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the URL parameter to (1) edit.php and (2) list.php in articles/; (3) list_blogs.php and (4) rankings.php in blogs/; (5) calendar/index.php; (6) calendar.php, (7) index.php, and (8) list_events.php in events/; (9) index.php and (10) list_galleries.php in fisheye/; (11) liberty/list_content.php; (12) newsletters/edition.php; (13) pigeonholes/list.php; (14) recommends/index.php; (15) rss/index.php; (16) stars/index.php; (17) users/remind_password.php; (18) wiki/orphan_pages.php; and (19) stats/index.php, different vectors than CVE-2007-0526 and CVE-2005-4379. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g42p-2gq8-x2p3/GHSA-g42p-2gq8-x2p3.json b/advisories/unreviewed/2022/05/GHSA-g42p-2gq8-x2p3/GHSA-g42p-2gq8-x2p3.json index d090477ad0b..a74a0f8b4a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-g42p-2gq8-x2p3/GHSA-g42p-2gq8-x2p3.json +++ b/advisories/unreviewed/2022/05/GHSA-g42p-2gq8-x2p3/GHSA-g42p-2gq8-x2p3.json @@ -7,12 +7,8 @@ "CVE-2008-4037" ], "details": "Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka \"SMB Credential Reflection Vulnerability.\" NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g42q-2rgq-rrmv/GHSA-g42q-2rgq-rrmv.json b/advisories/unreviewed/2022/05/GHSA-g42q-2rgq-rrmv/GHSA-g42q-2rgq-rrmv.json index 74f2986f459..916e8cff775 100644 --- a/advisories/unreviewed/2022/05/GHSA-g42q-2rgq-rrmv/GHSA-g42q-2rgq-rrmv.json +++ b/advisories/unreviewed/2022/05/GHSA-g42q-2rgq-rrmv/GHSA-g42q-2rgq-rrmv.json @@ -7,12 +7,8 @@ "CVE-2008-3988" ], "details": "Unspecified vulnerability in the iSupplier Portal component in Oracle E-Business Suite 11.5.10.2 and 12.0.4 allows remote attackers to affect confidentiality via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g472-458r-vx2g/GHSA-g472-458r-vx2g.json b/advisories/unreviewed/2022/05/GHSA-g472-458r-vx2g/GHSA-g472-458r-vx2g.json index 5418a32e33f..0a623ba4f76 100644 --- a/advisories/unreviewed/2022/05/GHSA-g472-458r-vx2g/GHSA-g472-458r-vx2g.json +++ b/advisories/unreviewed/2022/05/GHSA-g472-458r-vx2g/GHSA-g472-458r-vx2g.json @@ -7,12 +7,8 @@ "CVE-2008-4168" ], "details": "Cross-site scripting (XSS) vulnerability in verify_login.jsp in Pro2col Stingray FTS allows remote attackers to inject arbitrary web script or HTML via the form_username parameter (aka user name field).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g497-qrwv-f7wh/GHSA-g497-qrwv-f7wh.json b/advisories/unreviewed/2022/05/GHSA-g497-qrwv-f7wh/GHSA-g497-qrwv-f7wh.json index d0559b9fc3b..f957567a5ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-g497-qrwv-f7wh/GHSA-g497-qrwv-f7wh.json +++ b/advisories/unreviewed/2022/05/GHSA-g497-qrwv-f7wh/GHSA-g497-qrwv-f7wh.json @@ -7,12 +7,8 @@ "CVE-2008-4155" ], "details": "Multiple directory traversal vulnerabilities in EasySite 2.3 allow remote attackers to read arbitrary files or list directories via a .. (dot dot) in the (1) module or (2) action parameter in (a) www/index.php; the (3) module, (4) ss_module, or (5) ss_action parameter in (b) modules/Module/index.php or (c) modules/Themes/index.php; or the (6) module parameter in (d) inc/vmenu.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g4pf-rq76-fcx3/GHSA-g4pf-rq76-fcx3.json b/advisories/unreviewed/2022/05/GHSA-g4pf-rq76-fcx3/GHSA-g4pf-rq76-fcx3.json index 6e24c3a2e3a..7248e4c5580 100644 --- a/advisories/unreviewed/2022/05/GHSA-g4pf-rq76-fcx3/GHSA-g4pf-rq76-fcx3.json +++ b/advisories/unreviewed/2022/05/GHSA-g4pf-rq76-fcx3/GHSA-g4pf-rq76-fcx3.json @@ -7,12 +7,8 @@ "CVE-2008-4221" ], "details": "The strptime API in Libsystem in Apple Mac OS X before 10.5.6 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted date string, related to improper memory allocation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g567-gmj2-gq25/GHSA-g567-gmj2-gq25.json b/advisories/unreviewed/2022/05/GHSA-g567-gmj2-gq25/GHSA-g567-gmj2-gq25.json index 1352ff0f9b0..8f1aa344965 100644 --- a/advisories/unreviewed/2022/05/GHSA-g567-gmj2-gq25/GHSA-g567-gmj2-gq25.json +++ b/advisories/unreviewed/2022/05/GHSA-g567-gmj2-gq25/GHSA-g567-gmj2-gq25.json @@ -7,12 +7,8 @@ "CVE-2008-3851" ], "details": "Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute arbitrary local files via a ..\\ (dot dot backslash) in the (1) blogpost, (2) cat, and (3) file parameters to data/inc/themes/predefined_variables.php, as reachable through index.php; and the (4) blogpost and (5) cat parameters to data/inc/blog_include_react.php, as reachable through index.php. NOTE: the issue involving vectors 1 through 3 reportedly exists because of an incomplete fix for CVE-2008-3194.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g5cg-2mj2-5gf4/GHSA-g5cg-2mj2-5gf4.json b/advisories/unreviewed/2022/05/GHSA-g5cg-2mj2-5gf4/GHSA-g5cg-2mj2-5gf4.json index 51f043c77c3..d8d56910fe1 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5cg-2mj2-5gf4/GHSA-g5cg-2mj2-5gf4.json +++ b/advisories/unreviewed/2022/05/GHSA-g5cg-2mj2-5gf4/GHSA-g5cg-2mj2-5gf4.json @@ -7,12 +7,8 @@ "CVE-2008-4169" ], "details": "SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute arbitrary SQL commands via the produid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g5gg-m44h-f465/GHSA-g5gg-m44h-f465.json b/advisories/unreviewed/2022/05/GHSA-g5gg-m44h-f465/GHSA-g5gg-m44h-f465.json index 66f0fa4829e..f57213dd13a 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5gg-m44h-f465/GHSA-g5gg-m44h-f465.json +++ b/advisories/unreviewed/2022/05/GHSA-g5gg-m44h-f465/GHSA-g5gg-m44h-f465.json @@ -7,12 +7,8 @@ "CVE-2008-4244" ], "details": "Rianxosencabos CMS 0.9 allows remote attackers to bypass authentication and gain administrative access by setting the usuario and pass cookies to 1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g5vp-64cj-5h7f/GHSA-g5vp-64cj-5h7f.json b/advisories/unreviewed/2022/05/GHSA-g5vp-64cj-5h7f/GHSA-g5vp-64cj-5h7f.json index 6a7373a9498..b076eb02f93 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5vp-64cj-5h7f/GHSA-g5vp-64cj-5h7f.json +++ b/advisories/unreviewed/2022/05/GHSA-g5vp-64cj-5h7f/GHSA-g5vp-64cj-5h7f.json @@ -7,12 +7,8 @@ "CVE-2008-3942" ], "details": "SQL injection vulnerability in landsee.php in Full PHP Emlak Script allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g7gq-8xmf-48g9/GHSA-g7gq-8xmf-48g9.json b/advisories/unreviewed/2022/05/GHSA-g7gq-8xmf-48g9/GHSA-g7gq-8xmf-48g9.json index 4e5ebb0bf57..e0eb33b6387 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7gq-8xmf-48g9/GHSA-g7gq-8xmf-48g9.json +++ b/advisories/unreviewed/2022/05/GHSA-g7gq-8xmf-48g9/GHSA-g7gq-8xmf-48g9.json @@ -7,12 +7,8 @@ "CVE-2008-4200" ], "details": "Opera before 9.52 does not ensure that the address field of a news feed represents the feed's actual URL, which allows remote attackers to change this field to display the URL of a page containing web script controlled by the attacker.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g7rm-p4gv-mhwp/GHSA-g7rm-p4gv-mhwp.json b/advisories/unreviewed/2022/05/GHSA-g7rm-p4gv-mhwp/GHSA-g7rm-p4gv-mhwp.json index ed477dcbfd8..1324b1cde21 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7rm-p4gv-mhwp/GHSA-g7rm-p4gv-mhwp.json +++ b/advisories/unreviewed/2022/05/GHSA-g7rm-p4gv-mhwp/GHSA-g7rm-p4gv-mhwp.json @@ -7,12 +7,8 @@ "CVE-2008-4172" ], "details": "SQL injection vulnerability in page.php in Cars & Vehicle (aka Cars-Vehicle Script) allows remote attackers to execute arbitrary SQL commands via the lnkid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g85g-p29m-3jgf/GHSA-g85g-p29m-3jgf.json b/advisories/unreviewed/2022/05/GHSA-g85g-p29m-3jgf/GHSA-g85g-p29m-3jgf.json index 4916b68d42e..cc14de85d1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-g85g-p29m-3jgf/GHSA-g85g-p29m-3jgf.json +++ b/advisories/unreviewed/2022/05/GHSA-g85g-p29m-3jgf/GHSA-g85g-p29m-3jgf.json @@ -7,12 +7,8 @@ "CVE-2008-3983" ], "details": "Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LT and WMSYS.LT, a different vulnerability than CVE-2008-3982 and CVE-2008-3984.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gcc8-9gxh-w296/GHSA-gcc8-9gxh-w296.json b/advisories/unreviewed/2022/05/GHSA-gcc8-9gxh-w296/GHSA-gcc8-9gxh-w296.json index 44c12d19da1..11878b411ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcc8-9gxh-w296/GHSA-gcc8-9gxh-w296.json +++ b/advisories/unreviewed/2022/05/GHSA-gcc8-9gxh-w296/GHSA-gcc8-9gxh-w296.json @@ -7,12 +7,8 @@ "CVE-2008-4353" ], "details": "SQL injection vulnerability in link.php in Linkarity allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. NOTE: although one component of Linkarity is distributable PHP code, this issue might be site-specific. If so, it should not be included in CVE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gf78-5j37-4gfv/GHSA-gf78-5j37-4gfv.json b/advisories/unreviewed/2022/05/GHSA-gf78-5j37-4gfv/GHSA-gf78-5j37-4gfv.json index ddd95243b5a..5be1dd078f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf78-5j37-4gfv/GHSA-gf78-5j37-4gfv.json +++ b/advisories/unreviewed/2022/05/GHSA-gf78-5j37-4gfv/GHSA-gf78-5j37-4gfv.json @@ -7,12 +7,8 @@ "CVE-2008-3927" ], "details": "genmsgidx in Tiger 3.2.2 allows local users to overwrite or delete arbitrary files via a symlink attack on temporary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gg32-r459-85xc/GHSA-gg32-r459-85xc.json b/advisories/unreviewed/2022/05/GHSA-gg32-r459-85xc/GHSA-gg32-r459-85xc.json index a4e9d3f57c9..b54c44d3044 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg32-r459-85xc/GHSA-gg32-r459-85xc.json +++ b/advisories/unreviewed/2022/05/GHSA-gg32-r459-85xc/GHSA-gg32-r459-85xc.json @@ -7,12 +7,8 @@ "CVE-2008-3720" ], "details": "SQL injection vulnerability in index.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the id vector is already covered by CVE-2007-5679.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gg7f-mrmc-j93p/GHSA-gg7f-mrmc-j93p.json b/advisories/unreviewed/2022/05/GHSA-gg7f-mrmc-j93p/GHSA-gg7f-mrmc-j93p.json index b02ef20e819..49cbbcc18ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg7f-mrmc-j93p/GHSA-gg7f-mrmc-j93p.json +++ b/advisories/unreviewed/2022/05/GHSA-gg7f-mrmc-j93p/GHSA-gg7f-mrmc-j93p.json @@ -7,12 +7,8 @@ "CVE-2008-4106" ], "details": "WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers to change an arbitrary user's password to a random value by registering a similar username and then requesting a password reset, related to a \"SQL column truncation vulnerability.\" NOTE: the attacker can discover the random password by also exploiting CVE-2008-4107.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ghgp-8h5v-83fv/GHSA-ghgp-8h5v-83fv.json b/advisories/unreviewed/2022/05/GHSA-ghgp-8h5v-83fv/GHSA-ghgp-8h5v-83fv.json index 065a72abe51..214a9a991bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghgp-8h5v-83fv/GHSA-ghgp-8h5v-83fv.json +++ b/advisories/unreviewed/2022/05/GHSA-ghgp-8h5v-83fv/GHSA-ghgp-8h5v-83fv.json @@ -7,12 +7,8 @@ "CVE-2008-3748" ], "details": "SQL injection vulnerability in view_group.php in Active PHP Bookmarks (APB) 1.1.02 and 1.2.06 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ghgw-wvjx-6m5j/GHSA-ghgw-wvjx-6m5j.json b/advisories/unreviewed/2022/05/GHSA-ghgw-wvjx-6m5j/GHSA-ghgw-wvjx-6m5j.json index b341045f910..91f4fe50ff8 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghgw-wvjx-6m5j/GHSA-ghgw-wvjx-6m5j.json +++ b/advisories/unreviewed/2022/05/GHSA-ghgw-wvjx-6m5j/GHSA-ghgw-wvjx-6m5j.json @@ -7,12 +7,8 @@ "CVE-2008-4220" ], "details": "Integer overflow in the inet_net_pton API in Libsystem in Apple Mac OS X before 10.5.6 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors. NOTE: this may be related to the WLB-2008080064 advisory published by SecurityReason on 20080822; however, as of 20081216, there are insufficient details to be sure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gj57-mhm5-rfch/GHSA-gj57-mhm5-rfch.json b/advisories/unreviewed/2022/05/GHSA-gj57-mhm5-rfch/GHSA-gj57-mhm5-rfch.json index 9b8b1f07f47..b956fc3a092 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj57-mhm5-rfch/GHSA-gj57-mhm5-rfch.json +++ b/advisories/unreviewed/2022/05/GHSA-gj57-mhm5-rfch/GHSA-gj57-mhm5-rfch.json @@ -7,12 +7,8 @@ "CVE-2008-3854" ], "details": "Multiple stack-based buffer overflows in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 1 allow remote attackers to cause a denial of service (system outage) via vectors related to (1) use of XQuery to issue statements; the (2) XMLQUERY, (3) XMLEXISTS, and (4) XMLTABLE statements; and the (5) sqlrlaka function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gj5v-p4xc-f8gc/GHSA-gj5v-p4xc-f8gc.json b/advisories/unreviewed/2022/05/GHSA-gj5v-p4xc-f8gc/GHSA-gj5v-p4xc-f8gc.json index ca96d7c3740..4a8272f8f21 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj5v-p4xc-f8gc/GHSA-gj5v-p4xc-f8gc.json +++ b/advisories/unreviewed/2022/05/GHSA-gj5v-p4xc-f8gc/GHSA-gj5v-p4xc-f8gc.json @@ -7,12 +7,8 @@ "CVE-2008-3762" ], "details": "SQL injection vulnerability in onlinestatus_html.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the dep parameter, related to lack of input sanitization in the get function in global.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gj85-jjqm-mm4g/GHSA-gj85-jjqm-mm4g.json b/advisories/unreviewed/2022/05/GHSA-gj85-jjqm-mm4g/GHSA-gj85-jjqm-mm4g.json index de7faca3511..11eff78101c 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj85-jjqm-mm4g/GHSA-gj85-jjqm-mm4g.json +++ b/advisories/unreviewed/2022/05/GHSA-gj85-jjqm-mm4g/GHSA-gj85-jjqm-mm4g.json @@ -7,12 +7,8 @@ "CVE-2008-3902" ], "details": "HP firmware 68DTT F.0D stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer, aka SSRT080104.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gm62-6g3h-grcx/GHSA-gm62-6g3h-grcx.json b/advisories/unreviewed/2022/05/GHSA-gm62-6g3h-grcx/GHSA-gm62-6g3h-grcx.json index 4d4bd1816fe..a9e29b0cd8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gm62-6g3h-grcx/GHSA-gm62-6g3h-grcx.json +++ b/advisories/unreviewed/2022/05/GHSA-gm62-6g3h-grcx/GHSA-gm62-6g3h-grcx.json @@ -7,12 +7,8 @@ "CVE-2008-4207" ], "details": "Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers to obtain sensitive information via a direct request, which invokes the phpinfo function. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gm92-x63w-j26f/GHSA-gm92-x63w-j26f.json b/advisories/unreviewed/2022/05/GHSA-gm92-x63w-j26f/GHSA-gm92-x63w-j26f.json index dc96456d169..3ebce49090d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gm92-x63w-j26f/GHSA-gm92-x63w-j26f.json +++ b/advisories/unreviewed/2022/05/GHSA-gm92-x63w-j26f/GHSA-gm92-x63w-j26f.json @@ -7,12 +7,8 @@ "CVE-2008-3872" ], "details": "Adobe Flash Player 8.0.39.0 and earlier, and 9.x up to 9.0.115.0, allows remote attackers to bypass the allowScriptAccess parameter setting via a crafted SWF file with unspecified \"Filter evasion\" manipulations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gmgf-h273-29pw/GHSA-gmgf-h273-29pw.json b/advisories/unreviewed/2022/05/GHSA-gmgf-h273-29pw/GHSA-gmgf-h273-29pw.json index bb0d68423f4..bd55dd6ec26 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmgf-h273-29pw/GHSA-gmgf-h273-29pw.json +++ b/advisories/unreviewed/2022/05/GHSA-gmgf-h273-29pw/GHSA-gmgf-h273-29pw.json @@ -7,12 +7,8 @@ "CVE-2008-4188" ], "details": "Unspecified vulnerability in the TYPO3 Secure Directory (kw_secdir) extension before 1.0.2 allows remote attackers to execute arbitrary code via unknown vectors related to \"injection of control characters.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gmxw-wf52-2vxp/GHSA-gmxw-wf52-2vxp.json b/advisories/unreviewed/2022/05/GHSA-gmxw-wf52-2vxp/GHSA-gmxw-wf52-2vxp.json index 0bf092754ef..4b45aaa5654 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmxw-wf52-2vxp/GHSA-gmxw-wf52-2vxp.json +++ b/advisories/unreviewed/2022/05/GHSA-gmxw-wf52-2vxp/GHSA-gmxw-wf52-2vxp.json @@ -7,12 +7,8 @@ "CVE-2008-4389" ], "details": "Symantec AppStream 5.2.x and Symantec Workspace Streaming (SWS) 6.1.x before 6.1 SP4 do not properly perform authentication, which allows remote Workspace Streaming servers and man-in-the-middle attackers to download arbitrary executable files onto a client system, and execute these files, via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gp44-m8rj-664r/GHSA-gp44-m8rj-664r.json b/advisories/unreviewed/2022/05/GHSA-gp44-m8rj-664r/GHSA-gp44-m8rj-664r.json index 83248527152..dac3e813622 100644 --- a/advisories/unreviewed/2022/05/GHSA-gp44-m8rj-664r/GHSA-gp44-m8rj-664r.json +++ b/advisories/unreviewed/2022/05/GHSA-gp44-m8rj-664r/GHSA-gp44-m8rj-664r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gpqj-cp2v-g673/GHSA-gpqj-cp2v-g673.json b/advisories/unreviewed/2022/05/GHSA-gpqj-cp2v-g673/GHSA-gpqj-cp2v-g673.json index f1c5bc1ba0c..2533ebe6aa6 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpqj-cp2v-g673/GHSA-gpqj-cp2v-g673.json +++ b/advisories/unreviewed/2022/05/GHSA-gpqj-cp2v-g673/GHSA-gpqj-cp2v-g673.json @@ -7,12 +7,8 @@ "CVE-2008-3999" ], "details": "Unspecified vulnerability in the Oracle OLAP component in Oracle Database 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 allows remote authenticated users to affect availability, related to SYS.OLAPIMPL_T.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gq2r-cfxv-jhvj/GHSA-gq2r-cfxv-jhvj.json b/advisories/unreviewed/2022/05/GHSA-gq2r-cfxv-jhvj/GHSA-gq2r-cfxv-jhvj.json index 48730eb5668..fe76c4ce237 100644 --- a/advisories/unreviewed/2022/05/GHSA-gq2r-cfxv-jhvj/GHSA-gq2r-cfxv-jhvj.json +++ b/advisories/unreviewed/2022/05/GHSA-gq2r-cfxv-jhvj/GHSA-gq2r-cfxv-jhvj.json @@ -7,12 +7,8 @@ "CVE-2008-3876" ], "details": "Apple iPhone 2.0.2, in some configurations, allows physically proximate attackers to bypass intended access restrictions, and obtain sensitive information or make arbitrary use of the device, via an Emergency Call tap and a Home double-tap, followed by a tap of any contact's blue arrow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gr4q-ffwp-cmhv/GHSA-gr4q-ffwp-cmhv.json b/advisories/unreviewed/2022/05/GHSA-gr4q-ffwp-cmhv/GHSA-gr4q-ffwp-cmhv.json index 3a6d81780aa..d89ec7eea78 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr4q-ffwp-cmhv/GHSA-gr4q-ffwp-cmhv.json +++ b/advisories/unreviewed/2022/05/GHSA-gr4q-ffwp-cmhv/GHSA-gr4q-ffwp-cmhv.json @@ -7,12 +7,8 @@ "CVE-2008-4222" ], "details": "natd in network_cmds in Apple Mac OS X before 10.5.6, when Internet Sharing is enabled, allows remote attackers to cause a denial of service (infinite loop) via a crafted TCP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gr92-9rhc-rfgp/GHSA-gr92-9rhc-rfgp.json b/advisories/unreviewed/2022/05/GHSA-gr92-9rhc-rfgp/GHSA-gr92-9rhc-rfgp.json index 34dfa7aff30..dcea1b6c560 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr92-9rhc-rfgp/GHSA-gr92-9rhc-rfgp.json +++ b/advisories/unreviewed/2022/05/GHSA-gr92-9rhc-rfgp/GHSA-gr92-9rhc-rfgp.json @@ -7,12 +7,8 @@ "CVE-2008-3899" ], "details": "TrueCrypt 5.0 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer. NOTE: the researcher mentions a response from the vendor denying the vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gv3q-8cfx-q99h/GHSA-gv3q-8cfx-q99h.json b/advisories/unreviewed/2022/05/GHSA-gv3q-8cfx-q99h/GHSA-gv3q-8cfx-q99h.json index d394a5ec53d..6ed692b8422 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv3q-8cfx-q99h/GHSA-gv3q-8cfx-q99h.json +++ b/advisories/unreviewed/2022/05/GHSA-gv3q-8cfx-q99h/GHSA-gv3q-8cfx-q99h.json @@ -7,12 +7,8 @@ "CVE-2008-3713" ], "details": "SQL injection vulnerability in product.php in PHPBasket allows remote attackers to execute arbitrary SQL commands via the pro_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gw6p-34jh-g7qg/GHSA-gw6p-34jh-g7qg.json b/advisories/unreviewed/2022/05/GHSA-gw6p-34jh-g7qg/GHSA-gw6p-34jh-g7qg.json index be829b5f9e5..01cab067c6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw6p-34jh-g7qg/GHSA-gw6p-34jh-g7qg.json +++ b/advisories/unreviewed/2022/05/GHSA-gw6p-34jh-g7qg/GHSA-gw6p-34jh-g7qg.json @@ -7,12 +7,8 @@ "CVE-2008-4245" ], "details": "The Admin Control Panel in Rianxosencabos CMS 0.9 does not require administrator privileges, which allows remote authenticated users to (1) change a user's privileges, (2) delete a user account, or perform unspecified other administrative actions via vectors involving an admin lista action to the default URI, possibly related to useradmin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gwh9-rg87-g28p/GHSA-gwh9-rg87-g28p.json b/advisories/unreviewed/2022/05/GHSA-gwh9-rg87-g28p/GHSA-gwh9-rg87-g28p.json index 52c7c9347b0..10c48b0223a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwh9-rg87-g28p/GHSA-gwh9-rg87-g28p.json +++ b/advisories/unreviewed/2022/05/GHSA-gwh9-rg87-g28p/GHSA-gwh9-rg87-g28p.json @@ -7,12 +7,8 @@ "CVE-2008-4194" ], "details": "The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of service (daemon crash) via a long DNS reply with many entries in the answer section, related to a \"dangling pointer bug.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gwx9-m5g5-6rhm/GHSA-gwx9-m5g5-6rhm.json b/advisories/unreviewed/2022/05/GHSA-gwx9-m5g5-6rhm/GHSA-gwx9-m5g5-6rhm.json index 6d5ef647e93..8d7a3c81411 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwx9-m5g5-6rhm/GHSA-gwx9-m5g5-6rhm.json +++ b/advisories/unreviewed/2022/05/GHSA-gwx9-m5g5-6rhm/GHSA-gwx9-m5g5-6rhm.json @@ -7,12 +7,8 @@ "CVE-2008-3986" ], "details": "Unspecified vulnerability in the Oracle Discoverer Administrator component in Oracle Application Server 9.0.4.3 and 10.1.2.2 allows local users to affect confidentiality via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h3c5-f6mh-jrq6/GHSA-h3c5-f6mh-jrq6.json b/advisories/unreviewed/2022/05/GHSA-h3c5-f6mh-jrq6/GHSA-h3c5-f6mh-jrq6.json index d67559460c5..5e1d72d39dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3c5-f6mh-jrq6/GHSA-h3c5-f6mh-jrq6.json +++ b/advisories/unreviewed/2022/05/GHSA-h3c5-f6mh-jrq6/GHSA-h3c5-f6mh-jrq6.json @@ -7,12 +7,8 @@ "CVE-2008-3956" ], "details": "orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .opx file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h454-7w34-3fjm/GHSA-h454-7w34-3fjm.json b/advisories/unreviewed/2022/05/GHSA-h454-7w34-3fjm/GHSA-h454-7w34-3fjm.json index ce0fc1a0a90..9219d184b40 100644 --- a/advisories/unreviewed/2022/05/GHSA-h454-7w34-3fjm/GHSA-h454-7w34-3fjm.json +++ b/advisories/unreviewed/2022/05/GHSA-h454-7w34-3fjm/GHSA-h454-7w34-3fjm.json @@ -7,12 +7,8 @@ "CVE-2008-3918" ], "details": "SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands via the field parameter in a search action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h4f2-63f6-jv7q/GHSA-h4f2-63f6-jv7q.json b/advisories/unreviewed/2022/05/GHSA-h4f2-63f6-jv7q/GHSA-h4f2-63f6-jv7q.json index f555df7d2fa..28d4633d917 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4f2-63f6-jv7q/GHSA-h4f2-63f6-jv7q.json +++ b/advisories/unreviewed/2022/05/GHSA-h4f2-63f6-jv7q/GHSA-h4f2-63f6-jv7q.json @@ -7,12 +7,8 @@ "CVE-2008-4362" ], "details": "The Virtual Token driver (vdlptokn.sys) 1.0.2.43 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) via a crafted IOCTL request to \\Device\\DLPTokenWalter0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h4hw-9hxp-g377/GHSA-h4hw-9hxp-g377.json b/advisories/unreviewed/2022/05/GHSA-h4hw-9hxp-g377/GHSA-h4hw-9hxp-g377.json index 7abba7b7501..0352ac1b8d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4hw-9hxp-g377/GHSA-h4hw-9hxp-g377.json +++ b/advisories/unreviewed/2022/05/GHSA-h4hw-9hxp-g377/GHSA-h4hw-9hxp-g377.json @@ -7,12 +7,8 @@ "CVE-2008-3724" ], "details": "SQL injection vulnerability in index.php in Papoo before 3.7.2 allows remote attackers to execute arbitrary SQL commands via the suchanzahl parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h4mg-3p7c-m68q/GHSA-h4mg-3p7c-m68q.json b/advisories/unreviewed/2022/05/GHSA-h4mg-3p7c-m68q/GHSA-h4mg-3p7c-m68q.json index 7dbae90f5c4..c4c94e12913 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4mg-3p7c-m68q/GHSA-h4mg-3p7c-m68q.json +++ b/advisories/unreviewed/2022/05/GHSA-h4mg-3p7c-m68q/GHSA-h4mg-3p7c-m68q.json @@ -7,12 +7,8 @@ "CVE-2008-3733" ], "details": "Stack-based buffer overflow in EO Video (eo-video) 1.36 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a .eop (aka playlist) file with a ProjectElement element that contains a long Name element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h59h-44cg-5vq7/GHSA-h59h-44cg-5vq7.json b/advisories/unreviewed/2022/05/GHSA-h59h-44cg-5vq7/GHSA-h59h-44cg-5vq7.json index 1baae71ed4c..ac128ad1164 100644 --- a/advisories/unreviewed/2022/05/GHSA-h59h-44cg-5vq7/GHSA-h59h-44cg-5vq7.json +++ b/advisories/unreviewed/2022/05/GHSA-h59h-44cg-5vq7/GHSA-h59h-44cg-5vq7.json @@ -7,12 +7,8 @@ "CVE-2008-4300" ], "details": "A certain ActiveX control in adsiis.dll in Microsoft Internet Information Services (IIS) allows remote attackers to cause a denial of service (browser crash) via a long string in the second argument to the GetObject method. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h5r2-rjjw-28mj/GHSA-h5r2-rjjw-28mj.json b/advisories/unreviewed/2022/05/GHSA-h5r2-rjjw-28mj/GHSA-h5r2-rjjw-28mj.json index 167862226ae..103316d06cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5r2-rjjw-28mj/GHSA-h5r2-rjjw-28mj.json +++ b/advisories/unreviewed/2022/05/GHSA-h5r2-rjjw-28mj/GHSA-h5r2-rjjw-28mj.json @@ -7,12 +7,8 @@ "CVE-2008-3959" ], "details": "IBM DB2 UDB 8.1 before FixPak 16, 8.2 before FixPak 9, and 9.1 before FixPak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted SQLJRA packet within a CONNECT/ATTACH data stream that simulates a V7 client connect/attach request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h6g6-vxrv-5jwg/GHSA-h6g6-vxrv-5jwg.json b/advisories/unreviewed/2022/05/GHSA-h6g6-vxrv-5jwg/GHSA-h6g6-vxrv-5jwg.json index eb1ea23acce..cc81fbcc348 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6g6-vxrv-5jwg/GHSA-h6g6-vxrv-5jwg.json +++ b/advisories/unreviewed/2022/05/GHSA-h6g6-vxrv-5jwg/GHSA-h6g6-vxrv-5jwg.json @@ -7,12 +7,8 @@ "CVE-2008-3954" ], "details": "SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange allows remote attackers to execute arbitrary SQL commands via the cat parameter in a showcat action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h6w3-vjv8-9p4h/GHSA-h6w3-vjv8-9p4h.json b/advisories/unreviewed/2022/05/GHSA-h6w3-vjv8-9p4h/GHSA-h6w3-vjv8-9p4h.json index 54846d44bb7..7b8917468ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6w3-vjv8-9p4h/GHSA-h6w3-vjv8-9p4h.json +++ b/advisories/unreviewed/2022/05/GHSA-h6w3-vjv8-9p4h/GHSA-h6w3-vjv8-9p4h.json @@ -7,12 +7,8 @@ "CVE-2008-3740" ], "details": "Cross-site scripting (XSS) vulnerability in the output filter in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h75c-9g7p-45jj/GHSA-h75c-9g7p-45jj.json b/advisories/unreviewed/2022/05/GHSA-h75c-9g7p-45jj/GHSA-h75c-9g7p-45jj.json index 34a1a5d9801..b1082e81ca3 100644 --- a/advisories/unreviewed/2022/05/GHSA-h75c-9g7p-45jj/GHSA-h75c-9g7p-45jj.json +++ b/advisories/unreviewed/2022/05/GHSA-h75c-9g7p-45jj/GHSA-h75c-9g7p-45jj.json @@ -7,12 +7,8 @@ "CVE-2008-4010" ], "details": "Unspecified vulnerability in the WebLogic Workshop component in BEA Product Suite 10.3, 10.2, 10.0 MP1, 9.2 MP3, and 8.1 SP6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to \"some NetUI tags.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h869-6f3g-rg4p/GHSA-h869-6f3g-rg4p.json b/advisories/unreviewed/2022/05/GHSA-h869-6f3g-rg4p/GHSA-h869-6f3g-rg4p.json index 5d36591cbcf..7ee56787ec1 100644 --- a/advisories/unreviewed/2022/05/GHSA-h869-6f3g-rg4p/GHSA-h869-6f3g-rg4p.json +++ b/advisories/unreviewed/2022/05/GHSA-h869-6f3g-rg4p/GHSA-h869-6f3g-rg4p.json @@ -7,12 +7,8 @@ "CVE-2008-3947" ], "details": "DCL (aka the CLI) in OpenVMS Alpha 8.3 allows local users to gain privileges via a long command line.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h94v-hj96-5w55/GHSA-h94v-hj96-5w55.json b/advisories/unreviewed/2022/05/GHSA-h94v-hj96-5w55/GHSA-h94v-hj96-5w55.json index b5e79b48dee..c559ae48e38 100644 --- a/advisories/unreviewed/2022/05/GHSA-h94v-hj96-5w55/GHSA-h94v-hj96-5w55.json +++ b/advisories/unreviewed/2022/05/GHSA-h94v-hj96-5w55/GHSA-h94v-hj96-5w55.json @@ -7,12 +7,8 @@ "CVE-2008-3812" ], "details": "Cisco IOS 12.4, when IOS firewall Application Inspection Control (AIC) with HTTP Deep Packet Inspection is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed HTTP transit packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hfq5-47x3-ghhc/GHSA-hfq5-47x3-ghhc.json b/advisories/unreviewed/2022/05/GHSA-hfq5-47x3-ghhc/GHSA-hfq5-47x3-ghhc.json index 2606ad1777a..d0bbaede043 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfq5-47x3-ghhc/GHSA-hfq5-47x3-ghhc.json +++ b/advisories/unreviewed/2022/05/GHSA-hfq5-47x3-ghhc/GHSA-hfq5-47x3-ghhc.json @@ -7,12 +7,8 @@ "CVE-2008-4324" ], "details": "The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a series of keypress, click, onkeydown, onkeyup, onmousedown, and onmouseup events. NOTE: it was later reported that Firefox 3.0.2 on Mac OS X 10.5 is also affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hg65-qj29-qxp5/GHSA-hg65-qj29-qxp5.json b/advisories/unreviewed/2022/05/GHSA-hg65-qj29-qxp5/GHSA-hg65-qj29-qxp5.json index 2756ecdc1f0..7c3150b1c54 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg65-qj29-qxp5/GHSA-hg65-qj29-qxp5.json +++ b/advisories/unreviewed/2022/05/GHSA-hg65-qj29-qxp5/GHSA-hg65-qj29-qxp5.json @@ -7,12 +7,8 @@ "CVE-2008-3814" ], "details": "Unspecified vulnerability in Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication (aka native Unity authentication), allows remote attackers to bypass authentication and read or modify system configuration parameters by going to a specific link more than once.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hhrq-f8g9-5m25/GHSA-hhrq-f8g9-5m25.json b/advisories/unreviewed/2022/05/GHSA-hhrq-f8g9-5m25/GHSA-hhrq-f8g9-5m25.json index 5399ac3469d..c8b7d30df07 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhrq-f8g9-5m25/GHSA-hhrq-f8g9-5m25.json +++ b/advisories/unreviewed/2022/05/GHSA-hhrq-f8g9-5m25/GHSA-hhrq-f8g9-5m25.json @@ -7,12 +7,8 @@ "CVE-2008-4421" ], "details": "Directory traversal vulnerability in MetaGauge 1.0.0.17, and probably other versions before 1.0.3.38, allows remote attackers to read arbitrary files via a \"..\\\" (dot dot backslash) in the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjfr-hcjv-f23h/GHSA-hjfr-hcjv-f23h.json b/advisories/unreviewed/2022/05/GHSA-hjfr-hcjv-f23h/GHSA-hjfr-hcjv-f23h.json index 3ee9833da8f..d145ee5287a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjfr-hcjv-f23h/GHSA-hjfr-hcjv-f23h.json +++ b/advisories/unreviewed/2022/05/GHSA-hjfr-hcjv-f23h/GHSA-hjfr-hcjv-f23h.json @@ -7,12 +7,8 @@ "CVE-2008-4269" ], "details": "The search-ms protocol handler in Windows Explorer in Microsoft Windows Vista Gold and SP1 and Server 2008 uses untrusted parameter data obtained from incorrect parsing, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka \"Windows Search Parsing Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hmhj-jwx3-6q6x/GHSA-hmhj-jwx3-6q6x.json b/advisories/unreviewed/2022/05/GHSA-hmhj-jwx3-6q6x/GHSA-hmhj-jwx3-6q6x.json index 74dee66905c..3ad426bc535 100644 --- a/advisories/unreviewed/2022/05/GHSA-hmhj-jwx3-6q6x/GHSA-hmhj-jwx3-6q6x.json +++ b/advisories/unreviewed/2022/05/GHSA-hmhj-jwx3-6q6x/GHSA-hmhj-jwx3-6q6x.json @@ -7,12 +7,8 @@ "CVE-2008-4020" ], "details": "Cross-site scripting (XSS) vulnerability in Microsoft Office XP SP3 allows remote attackers to inject arbitrary web script or HTML via a document that contains a \"Content-Disposition: attachment\" header and is accessed through a cdo: URL, which renders the content instead of raising a File Download dialog box, aka \"Vulnerability in Content-Disposition Header Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hp64-jg7m-f9mq/GHSA-hp64-jg7m-f9mq.json b/advisories/unreviewed/2022/05/GHSA-hp64-jg7m-f9mq/GHSA-hp64-jg7m-f9mq.json index afe02a91a70..b57d5852cd4 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp64-jg7m-f9mq/GHSA-hp64-jg7m-f9mq.json +++ b/advisories/unreviewed/2022/05/GHSA-hp64-jg7m-f9mq/GHSA-hp64-jg7m-f9mq.json @@ -7,12 +7,8 @@ "CVE-2008-3963" ], "details": "MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows remote attackers to cause a denial of service (daemon crash) by using this token in a SQL statement.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hp9f-9w77-qm8f/GHSA-hp9f-9w77-qm8f.json b/advisories/unreviewed/2022/05/GHSA-hp9f-9w77-qm8f/GHSA-hp9f-9w77-qm8f.json index 735690f6e0d..e15d9551c61 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp9f-9w77-qm8f/GHSA-hp9f-9w77-qm8f.json +++ b/advisories/unreviewed/2022/05/GHSA-hp9f-9w77-qm8f/GHSA-hp9f-9w77-qm8f.json @@ -7,12 +7,8 @@ "CVE-2008-4125" ], "details": "The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially sensitive information, as demonstrated by a cross-application attack against WordPress, a different vulnerability than CVE-2006-0632.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hpmr-9r6f-w2rr/GHSA-hpmr-9r6f-w2rr.json b/advisories/unreviewed/2022/05/GHSA-hpmr-9r6f-w2rr/GHSA-hpmr-9r6f-w2rr.json index 26dd3788a50..a3fe264a13e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpmr-9r6f-w2rr/GHSA-hpmr-9r6f-w2rr.json +++ b/advisories/unreviewed/2022/05/GHSA-hpmr-9r6f-w2rr/GHSA-hpmr-9r6f-w2rr.json @@ -7,12 +7,8 @@ "CVE-2008-4311" ], "details": "The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restrictions by (1) sending messages, related to send_requested_reply; and possibly (2) receiving messages, related to receive_requested_reply.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hpx5-6mfx-fq22/GHSA-hpx5-6mfx-fq22.json b/advisories/unreviewed/2022/05/GHSA-hpx5-6mfx-fq22/GHSA-hpx5-6mfx-fq22.json index 95a334c34cb..04a9ba53ffd 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpx5-6mfx-fq22/GHSA-hpx5-6mfx-fq22.json +++ b/advisories/unreviewed/2022/05/GHSA-hpx5-6mfx-fq22/GHSA-hpx5-6mfx-fq22.json @@ -7,12 +7,8 @@ "CVE-2008-4192" ], "details": "The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/eglog temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hpxj-gcgj-phqm/GHSA-hpxj-gcgj-phqm.json b/advisories/unreviewed/2022/05/GHSA-hpxj-gcgj-phqm/GHSA-hpxj-gcgj-phqm.json index 1b5d855e76a..0e852b4ac18 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpxj-gcgj-phqm/GHSA-hpxj-gcgj-phqm.json +++ b/advisories/unreviewed/2022/05/GHSA-hpxj-gcgj-phqm/GHSA-hpxj-gcgj-phqm.json @@ -7,12 +7,8 @@ "CVE-2008-4160" ], "details": "Unspecified vulnerability in the UFS module in Sun Solaris 8 through 10 and OpenSolaris allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via unknown vectors related to the Solaris Access Control List (ACL) implementation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hqh2-cq22-337c/GHSA-hqh2-cq22-337c.json b/advisories/unreviewed/2022/05/GHSA-hqh2-cq22-337c/GHSA-hqh2-cq22-337c.json index 217fd05301b..a38041e0f40 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqh2-cq22-337c/GHSA-hqh2-cq22-337c.json +++ b/advisories/unreviewed/2022/05/GHSA-hqh2-cq22-337c/GHSA-hqh2-cq22-337c.json @@ -7,12 +7,8 @@ "CVE-2008-4089" ], "details": "Cross-site scripting (XSS) vulnerability in print.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to inject arbitrary web script or HTML via the sid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvcx-qqg5-776h/GHSA-hvcx-qqg5-776h.json b/advisories/unreviewed/2022/05/GHSA-hvcx-qqg5-776h/GHSA-hvcx-qqg5-776h.json index 271ee428c85..014831a5a6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvcx-qqg5-776h/GHSA-hvcx-qqg5-776h.json +++ b/advisories/unreviewed/2022/05/GHSA-hvcx-qqg5-776h/GHSA-hvcx-qqg5-776h.json @@ -7,12 +7,8 @@ "CVE-2008-4105" ], "details": "JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct \"variable injection\" attacks and have unspecified other impact.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvr6-6w44-9wq6/GHSA-hvr6-6w44-9wq6.json b/advisories/unreviewed/2022/05/GHSA-hvr6-6w44-9wq6/GHSA-hvr6-6w44-9wq6.json index 456ee2cb185..f1b4e5f8b36 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvr6-6w44-9wq6/GHSA-hvr6-6w44-9wq6.json +++ b/advisories/unreviewed/2022/05/GHSA-hvr6-6w44-9wq6/GHSA-hvr6-6w44-9wq6.json @@ -7,12 +7,8 @@ "CVE-2008-4242" ], "details": "ProFTPD 1.3.1 interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hxvh-x39f-f92f/GHSA-hxvh-x39f-f92f.json b/advisories/unreviewed/2022/05/GHSA-hxvh-x39f-f92f/GHSA-hxvh-x39f-f92f.json index c6db7d7915b..96cebc36dcf 100644 --- a/advisories/unreviewed/2022/05/GHSA-hxvh-x39f-f92f/GHSA-hxvh-x39f-f92f.json +++ b/advisories/unreviewed/2022/05/GHSA-hxvh-x39f-f92f/GHSA-hxvh-x39f-f92f.json @@ -7,12 +7,8 @@ "CVE-2008-3865" ], "details": "Multiple heap-based buffer overflows in the ApiThread function in the firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, allow remote attackers to execute arbitrary code via a packet with a small value in an unspecified size field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j337-fxmh-5v7h/GHSA-j337-fxmh-5v7h.json b/advisories/unreviewed/2022/05/GHSA-j337-fxmh-5v7h/GHSA-j337-fxmh-5v7h.json index f796a8a23e9..cb38e3a43d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-j337-fxmh-5v7h/GHSA-j337-fxmh-5v7h.json +++ b/advisories/unreviewed/2022/05/GHSA-j337-fxmh-5v7h/GHSA-j337-fxmh-5v7h.json @@ -7,12 +7,8 @@ "CVE-2008-4377" ], "details": "SQL injection vulnerability in index.asp in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the sideid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j3mx-h938-wf9r/GHSA-j3mx-h938-wf9r.json b/advisories/unreviewed/2022/05/GHSA-j3mx-h938-wf9r/GHSA-j3mx-h938-wf9r.json index 40b4c1d846e..cba9df2538f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j3mx-h938-wf9r/GHSA-j3mx-h938-wf9r.json +++ b/advisories/unreviewed/2022/05/GHSA-j3mx-h938-wf9r/GHSA-j3mx-h938-wf9r.json @@ -7,12 +7,8 @@ "CVE-2008-4046" ], "details": "SQL injection vulnerability in index.php in eliteCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j55v-8789-5phj/GHSA-j55v-8789-5phj.json b/advisories/unreviewed/2022/05/GHSA-j55v-8789-5phj/GHSA-j55v-8789-5phj.json index f1840e98579..1d9c34c1fb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-j55v-8789-5phj/GHSA-j55v-8789-5phj.json +++ b/advisories/unreviewed/2022/05/GHSA-j55v-8789-5phj/GHSA-j55v-8789-5phj.json @@ -7,12 +7,8 @@ "CVE-2008-3916" ], "details": "Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to execute arbitrary code via a long filename. NOTE: since ed itself does not typically run with special privileges, this issue only crosses privilege boundaries when ed is invoked as a third-party component.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j5gf-xm48-6399/GHSA-j5gf-xm48-6399.json b/advisories/unreviewed/2022/05/GHSA-j5gf-xm48-6399/GHSA-j5gf-xm48-6399.json index e21f86453f2..0821f61e440 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5gf-xm48-6399/GHSA-j5gf-xm48-6399.json +++ b/advisories/unreviewed/2022/05/GHSA-j5gf-xm48-6399/GHSA-j5gf-xm48-6399.json @@ -7,12 +7,8 @@ "CVE-2008-4074" ], "details": "SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j65h-5648-cmqw/GHSA-j65h-5648-cmqw.json b/advisories/unreviewed/2022/05/GHSA-j65h-5648-cmqw/GHSA-j65h-5648-cmqw.json index 85d627e4b3d..7c2c3f1ea5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-j65h-5648-cmqw/GHSA-j65h-5648-cmqw.json +++ b/advisories/unreviewed/2022/05/GHSA-j65h-5648-cmqw/GHSA-j65h-5648-cmqw.json @@ -7,12 +7,8 @@ "CVE-2008-3730" ], "details": "Cross-site scripting (XSS) vulnerability in Nordicwind Document Management System (NOAH) before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j6pr-3gfh-7g78/GHSA-j6pr-3gfh-7g78.json b/advisories/unreviewed/2022/05/GHSA-j6pr-3gfh-7g78/GHSA-j6pr-3gfh-7g78.json index 4916fac0baa..2d8c14ee09c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6pr-3gfh-7g78/GHSA-j6pr-3gfh-7g78.json +++ b/advisories/unreviewed/2022/05/GHSA-j6pr-3gfh-7g78/GHSA-j6pr-3gfh-7g78.json @@ -7,12 +7,8 @@ "CVE-2008-3879" ], "details": "The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument (SaveAsDocument argument) to the Save method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j736-75m4-cm43/GHSA-j736-75m4-cm43.json b/advisories/unreviewed/2022/05/GHSA-j736-75m4-cm43/GHSA-j736-75m4-cm43.json index 7b6d0f57d81..aa654b9a5cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-j736-75m4-cm43/GHSA-j736-75m4-cm43.json +++ b/advisories/unreviewed/2022/05/GHSA-j736-75m4-cm43/GHSA-j736-75m4-cm43.json @@ -7,12 +7,8 @@ "CVE-2008-4216" ], "details": "The plug-in interface in WebKit in Apple Safari before 3.2 does not prevent plug-ins from accessing local URLs, which allows remote attackers to obtain sensitive information via vectors that \"launch local files.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j7hh-6fv3-pr3p/GHSA-j7hh-6fv3-pr3p.json b/advisories/unreviewed/2022/05/GHSA-j7hh-6fv3-pr3p/GHSA-j7hh-6fv3-pr3p.json index 67911293922..e7ac1552a8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7hh-6fv3-pr3p/GHSA-j7hh-6fv3-pr3p.json +++ b/advisories/unreviewed/2022/05/GHSA-j7hh-6fv3-pr3p/GHSA-j7hh-6fv3-pr3p.json @@ -7,12 +7,8 @@ "CVE-2008-4069" ], "details": "The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in opportunistic circumstances, via a crafted XBM image file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j7hx-35fh-hv99/GHSA-j7hx-35fh-hv99.json b/advisories/unreviewed/2022/05/GHSA-j7hx-35fh-hv99/GHSA-j7hx-35fh-hv99.json index 83962222a0f..7cef5960743 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7hx-35fh-hv99/GHSA-j7hx-35fh-hv99.json +++ b/advisories/unreviewed/2022/05/GHSA-j7hx-35fh-hv99/GHSA-j7hx-35fh-hv99.json @@ -7,12 +7,8 @@ "CVE-2008-4161" ], "details": "SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands and conduct session fixation attacks via a combination of crafted order and order_by parameters in a search_all action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j82h-q99p-6xcc/GHSA-j82h-q99p-6xcc.json b/advisories/unreviewed/2022/05/GHSA-j82h-q99p-6xcc/GHSA-j82h-q99p-6xcc.json index 7d4ee587656..3b9648236e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-j82h-q99p-6xcc/GHSA-j82h-q99p-6xcc.json +++ b/advisories/unreviewed/2022/05/GHSA-j82h-q99p-6xcc/GHSA-j82h-q99p-6xcc.json @@ -7,12 +7,8 @@ "CVE-2008-4335" ], "details": "SQL injection vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to execute arbitrary SQL commands via the apa_album_ID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j88g-9fp9-644j/GHSA-j88g-9fp9-644j.json b/advisories/unreviewed/2022/05/GHSA-j88g-9fp9-644j/GHSA-j88g-9fp9-644j.json index 8c58a6fc97e..58470669361 100644 --- a/advisories/unreviewed/2022/05/GHSA-j88g-9fp9-644j/GHSA-j88g-9fp9-644j.json +++ b/advisories/unreviewed/2022/05/GHSA-j88g-9fp9-644j/GHSA-j88g-9fp9-644j.json @@ -7,12 +7,8 @@ "CVE-2008-4108" ], "details": "Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files via a symlink attack on a tmp$RANDOM.tmp temporary file. NOTE: there may not be common usage scenarios in which tmp$RANDOM.tmp is located in an untrusted directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j8gj-jg8j-7gq7/GHSA-j8gj-jg8j-7gq7.json b/advisories/unreviewed/2022/05/GHSA-j8gj-jg8j-7gq7/GHSA-j8gj-jg8j-7gq7.json index 3195332e2a0..3df52bddb29 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8gj-jg8j-7gq7/GHSA-j8gj-jg8j-7gq7.json +++ b/advisories/unreviewed/2022/05/GHSA-j8gj-jg8j-7gq7/GHSA-j8gj-jg8j-7gq7.json @@ -7,12 +7,8 @@ "CVE-2008-3968" ], "details": "Cross-site scripting (XSS) vulnerability in userlist.php in PunBB before 1.2.20 allows remote attackers to inject arbitrary web script or HTML via the p parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j99q-43xw-28f9/GHSA-j99q-43xw-28f9.json b/advisories/unreviewed/2022/05/GHSA-j99q-43xw-28f9/GHSA-j99q-43xw-28f9.json index 47288d086ab..bd8a9ad7717 100644 --- a/advisories/unreviewed/2022/05/GHSA-j99q-43xw-28f9/GHSA-j99q-43xw-28f9.json +++ b/advisories/unreviewed/2022/05/GHSA-j99q-43xw-28f9/GHSA-j99q-43xw-28f9.json @@ -7,12 +7,8 @@ "CVE-2008-4096" ], "details": "libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j9m4-5ccq-7q33/GHSA-j9m4-5ccq-7q33.json b/advisories/unreviewed/2022/05/GHSA-j9m4-5ccq-7q33/GHSA-j9m4-5ccq-7q33.json index 0b17d8b14ae..fee9d25c830 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9m4-5ccq-7q33/GHSA-j9m4-5ccq-7q33.json +++ b/advisories/unreviewed/2022/05/GHSA-j9m4-5ccq-7q33/GHSA-j9m4-5ccq-7q33.json @@ -7,12 +7,8 @@ "CVE-2008-4233" ], "details": "Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not isolate the call-approval dialog from the process of launching new applications, which allows remote attackers to make arbitrary phone calls via a crafted HTML document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jc59-w8vh-r622/GHSA-jc59-w8vh-r622.json b/advisories/unreviewed/2022/05/GHSA-jc59-w8vh-r622/GHSA-jc59-w8vh-r622.json index eae21127c8b..262b2484ef2 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc59-w8vh-r622/GHSA-jc59-w8vh-r622.json +++ b/advisories/unreviewed/2022/05/GHSA-jc59-w8vh-r622/GHSA-jc59-w8vh-r622.json @@ -7,12 +7,8 @@ "CVE-2008-3842" ], "details": "Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework without the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a query string containing a \" using sprintf(). This command is later executed via a call to system().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-whg3-7342-p9mg/GHSA-whg3-7342-p9mg.json b/advisories/unreviewed/2022/05/GHSA-whg3-7342-p9mg/GHSA-whg3-7342-p9mg.json index 36f591e6f1f..eda97b29d89 100644 --- a/advisories/unreviewed/2022/05/GHSA-whg3-7342-p9mg/GHSA-whg3-7342-p9mg.json +++ b/advisories/unreviewed/2022/05/GHSA-whg3-7342-p9mg/GHSA-whg3-7342-p9mg.json @@ -7,12 +7,8 @@ "CVE-2021-22860" ], "details": "EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vulnerability allows remote attacker to obtain users’ credential information without logging in the system, and further acquire the privileged permissions and execute arbitrary commends.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-whh9-9pwv-px65/GHSA-whh9-9pwv-px65.json b/advisories/unreviewed/2022/05/GHSA-whh9-9pwv-px65/GHSA-whh9-9pwv-px65.json index 1168b8061dc..d8294093875 100644 --- a/advisories/unreviewed/2022/05/GHSA-whh9-9pwv-px65/GHSA-whh9-9pwv-px65.json +++ b/advisories/unreviewed/2022/05/GHSA-whh9-9pwv-px65/GHSA-whh9-9pwv-px65.json @@ -7,12 +7,8 @@ "CVE-2021-37152" ], "details": "Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-whj6-8xvc-hmjm/GHSA-whj6-8xvc-hmjm.json b/advisories/unreviewed/2022/05/GHSA-whj6-8xvc-hmjm/GHSA-whj6-8xvc-hmjm.json index 640f63da68f..439a1b3d315 100644 --- a/advisories/unreviewed/2022/05/GHSA-whj6-8xvc-hmjm/GHSA-whj6-8xvc-hmjm.json +++ b/advisories/unreviewed/2022/05/GHSA-whj6-8xvc-hmjm/GHSA-whj6-8xvc-hmjm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wp5r-8r3m-3pvc/GHSA-wp5r-8r3m-3pvc.json b/advisories/unreviewed/2022/05/GHSA-wp5r-8r3m-3pvc/GHSA-wp5r-8r3m-3pvc.json index 3adaeeea9bd..1b606cee902 100644 --- a/advisories/unreviewed/2022/05/GHSA-wp5r-8r3m-3pvc/GHSA-wp5r-8r3m-3pvc.json +++ b/advisories/unreviewed/2022/05/GHSA-wp5r-8r3m-3pvc/GHSA-wp5r-8r3m-3pvc.json @@ -7,12 +7,8 @@ "CVE-2008-4236" ], "details": "Apple Type Services (ATS) in Apple Mac OS X 10.5 before 10.5.6 allows remote attackers to cause a denial of service (infinite loop) via a crafted embedded font in a PDF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wp92-87r8-55v9/GHSA-wp92-87r8-55v9.json b/advisories/unreviewed/2022/05/GHSA-wp92-87r8-55v9/GHSA-wp92-87r8-55v9.json index d0117a7395a..4168e219b2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wp92-87r8-55v9/GHSA-wp92-87r8-55v9.json +++ b/advisories/unreviewed/2022/05/GHSA-wp92-87r8-55v9/GHSA-wp92-87r8-55v9.json @@ -7,12 +7,8 @@ "CVE-2008-3863" ], "details": "Stack-based buffer overflow in the read_special_escape function in src/psgen.c in GNU Enscript 1.6.1 and 1.6.4 beta, when the -e (aka special escapes processing) option is enabled, allows user-assisted remote attackers to execute arbitrary code via a crafted ASCII file, related to the setfilename command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wpr7-r9cj-c64p/GHSA-wpr7-r9cj-c64p.json b/advisories/unreviewed/2022/05/GHSA-wpr7-r9cj-c64p/GHSA-wpr7-r9cj-c64p.json index 2efefcd5e54..c79a8c657b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpr7-r9cj-c64p/GHSA-wpr7-r9cj-c64p.json +++ b/advisories/unreviewed/2022/05/GHSA-wpr7-r9cj-c64p/GHSA-wpr7-r9cj-c64p.json @@ -7,12 +7,8 @@ "CVE-2008-4183" ], "details": "IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup via a direct request to a backup/backup-yyyy-dd-mm.sql filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wvfg-7crv-xg2v/GHSA-wvfg-7crv-xg2v.json b/advisories/unreviewed/2022/05/GHSA-wvfg-7crv-xg2v/GHSA-wvfg-7crv-xg2v.json index 0e8c21dbaf8..d5d801f606a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvfg-7crv-xg2v/GHSA-wvfg-7crv-xg2v.json +++ b/advisories/unreviewed/2022/05/GHSA-wvfg-7crv-xg2v/GHSA-wvfg-7crv-xg2v.json @@ -7,12 +7,8 @@ "CVE-2020-15592" ], "details": "SteelCentral Aternity Agent before 11.0.0.120 on Windows allows Privilege Escalation via a crafted file. It uses an executable running as a high privileged Windows service to perform administrative tasks and collect data from other processes. It distributes functionality among different processes and uses IPC (Inter-Process Communication) primitives to enable the processes to cooperate. The remotely callable methods from remotable objects available through interprocess communication allow loading of arbitrary plugins (i.e., C# assemblies) from the \"%PROGRAMFILES(X86)%/Aternity Information Systems/Assistant/plugins” directory, where the name of the plugin is passed as part of an XML-serialized object. However, because the name of the DLL is concatenated with the “.\\plugins” string, a directory traversal vulnerability exists in the way plugins are resolved.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wvmh-jv7f-qwwp/GHSA-wvmh-jv7f-qwwp.json b/advisories/unreviewed/2022/05/GHSA-wvmh-jv7f-qwwp/GHSA-wvmh-jv7f-qwwp.json index 2d57f3e61e3..e3e1fe1621a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvmh-jv7f-qwwp/GHSA-wvmh-jv7f-qwwp.json +++ b/advisories/unreviewed/2022/05/GHSA-wvmh-jv7f-qwwp/GHSA-wvmh-jv7f-qwwp.json @@ -7,12 +7,8 @@ "CVE-2008-3755" ], "details": "SQL injection vulnerability in view.php in YourFreeWorld Classifieds Script allows remote attackers to execute arbitrary SQL commands via the category parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wvr7-39mh-vvr4/GHSA-wvr7-39mh-vvr4.json b/advisories/unreviewed/2022/05/GHSA-wvr7-39mh-vvr4/GHSA-wvr7-39mh-vvr4.json index acb7bdcc528..a8e4371db1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvr7-39mh-vvr4/GHSA-wvr7-39mh-vvr4.json +++ b/advisories/unreviewed/2022/05/GHSA-wvr7-39mh-vvr4/GHSA-wvr7-39mh-vvr4.json @@ -7,12 +7,8 @@ "CVE-2008-4025" ], "details": "Integer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via (1) an RTF file or (2) a rich text e-mail message containing an invalid number of points for a polyline or polygon, which triggers a heap-based buffer overflow, aka \"Word RTF Object Parsing Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wwjw-jrgv-wj9c/GHSA-wwjw-jrgv-wj9c.json b/advisories/unreviewed/2022/05/GHSA-wwjw-jrgv-wj9c/GHSA-wwjw-jrgv-wj9c.json index 1a14d14061e..c1679faf8db 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwjw-jrgv-wj9c/GHSA-wwjw-jrgv-wj9c.json +++ b/advisories/unreviewed/2022/05/GHSA-wwjw-jrgv-wj9c/GHSA-wwjw-jrgv-wj9c.json @@ -7,12 +7,8 @@ "CVE-2008-4375" ], "details": "SQL injection vulnerability in viewprofile.php in Availscript Classmate Script allows remote attackers to execute arbitrary SQL commands via the p parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wx53-938v-jqvg/GHSA-wx53-938v-jqvg.json b/advisories/unreviewed/2022/05/GHSA-wx53-938v-jqvg/GHSA-wx53-938v-jqvg.json index 58f1abdc0ed..dccaa10cef4 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx53-938v-jqvg/GHSA-wx53-938v-jqvg.json +++ b/advisories/unreviewed/2022/05/GHSA-wx53-938v-jqvg/GHSA-wx53-938v-jqvg.json @@ -7,12 +7,8 @@ "CVE-2008-4382" ], "details": "Konqueror in KDE 3.5.9 allows remote attackers to cause a denial of service (application crash) via Javascript that calls the alert function with a URL-encoded string of a large number of invalid characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x2c4-vpc7-ffhg/GHSA-x2c4-vpc7-ffhg.json b/advisories/unreviewed/2022/05/GHSA-x2c4-vpc7-ffhg/GHSA-x2c4-vpc7-ffhg.json index 54f07266c7c..f0a700155d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2c4-vpc7-ffhg/GHSA-x2c4-vpc7-ffhg.json +++ b/advisories/unreviewed/2022/05/GHSA-x2c4-vpc7-ffhg/GHSA-x2c4-vpc7-ffhg.json @@ -7,12 +7,8 @@ "CVE-2008-4176" ], "details": "SQL injection vulnerability in izle.asp in FoT Video scripti 1.1 beta allows remote attackers to execute arbitrary SQL commands via the oyun parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x2j6-7f76-j3jf/GHSA-x2j6-7f76-j3jf.json b/advisories/unreviewed/2022/05/GHSA-x2j6-7f76-j3jf/GHSA-x2j6-7f76-j3jf.json index 77c022788c2..6d1fcf293d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2j6-7f76-j3jf/GHSA-x2j6-7f76-j3jf.json +++ b/advisories/unreviewed/2022/05/GHSA-x2j6-7f76-j3jf/GHSA-x2j6-7f76-j3jf.json @@ -7,12 +7,8 @@ "CVE-2008-4388" ], "details": "The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly validate downloaded files, which allows remote attackers to execute arbitrary code via the installAppMgr method and unspecified other methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x2x8-px8r-428r/GHSA-x2x8-px8r-428r.json b/advisories/unreviewed/2022/05/GHSA-x2x8-px8r-428r/GHSA-x2x8-px8r-428r.json index c1e14f2df0e..1825838dc7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2x8-px8r-428r/GHSA-x2x8-px8r-428r.json +++ b/advisories/unreviewed/2022/05/GHSA-x2x8-px8r-428r/GHSA-x2x8-px8r-428r.json @@ -7,12 +7,8 @@ "CVE-2008-3945" ], "details": "SQL injection vulnerability in index.php in Words tag 1.2 allows remote attackers to execute arbitrary SQL commands via the word parameter in a claim action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x362-hgrj-5pw9/GHSA-x362-hgrj-5pw9.json b/advisories/unreviewed/2022/05/GHSA-x362-hgrj-5pw9/GHSA-x362-hgrj-5pw9.json index e63d2334a5c..abc08047c8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-x362-hgrj-5pw9/GHSA-x362-hgrj-5pw9.json +++ b/advisories/unreviewed/2022/05/GHSA-x362-hgrj-5pw9/GHSA-x362-hgrj-5pw9.json @@ -7,12 +7,8 @@ "CVE-2008-4401" ], "details": "ActionScript in Adobe Flash Player 9.0.124.0 and earlier does not require user interaction in conjunction with (1) the FileReference.browse operation in the FileReference upload API or (2) the FileReference.download operation in the FileReference download API, which allows remote attackers to create a browse dialog box, and possibly have unspecified other impact, via an SWF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x3hp-v67w-2vc2/GHSA-x3hp-v67w-2vc2.json b/advisories/unreviewed/2022/05/GHSA-x3hp-v67w-2vc2/GHSA-x3hp-v67w-2vc2.json index 29a40437d8b..26baa93bdfa 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3hp-v67w-2vc2/GHSA-x3hp-v67w-2vc2.json +++ b/advisories/unreviewed/2022/05/GHSA-x3hp-v67w-2vc2/GHSA-x3hp-v67w-2vc2.json @@ -7,12 +7,8 @@ "CVE-2008-4326" ], "details": "The PMA_escapeJsString function in libraries/js_escape.lib.php in phpMyAdmin before 2.11.9.2, when Internet Explorer is used, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via a NUL byte inside a \"\n mptcp_set_rcvlowat+0x79/0x1d0\n sk_setsockopt+0x6c0/0x1540\n __bpf_setsockopt+0x6f/0x90\n bpf_sock_ops_setsockopt+0x3c/0x90\n bpf_prog_509ce5db2c7f9981_bpf_test_sockopt_int+0xb4/0x11b\n bpf_prog_dce07e362d941d2b_bpf_test_socket_sockopt+0x12b/0x132\n bpf_prog_348c9b5faaf10092_skops_sockopt+0x954/0xe86\n __cgroup_bpf_run_filter_sock_ops+0xbc/0x250\n tcp_connect+0x879/0x1160\n tcp_v6_connect+0x50c/0x870\n mptcp_connect+0x129/0x280\n __inet_stream_connect+0xce/0x370\n inet_stream_connect+0x36/0x50\n bpf_trampoline_6442491565+0x49/0xef\n inet_stream_connect+0x5/0x50\n __sys_connect+0x63/0x90\n __x64_sys_connect+0x14/0x20\n\nThe root cause of the issue is that bpf allows accessing mptcp-level\nproto_ops from a tcp subflow scope.\n\nFix the issue detecting the problematic call and preventing any action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-2258-2x7m-c8q2/GHSA-2258-2x7m-c8q2.json b/advisories/unreviewed/2024/07/GHSA-2258-2x7m-c8q2/GHSA-2258-2x7m-c8q2.json index b3e6a576e08..66335eaefa0 100644 --- a/advisories/unreviewed/2024/07/GHSA-2258-2x7m-c8q2/GHSA-2258-2x7m-c8q2.json +++ b/advisories/unreviewed/2024/07/GHSA-2258-2x7m-c8q2/GHSA-2258-2x7m-c8q2.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-26qv-3573-wxg2/GHSA-26qv-3573-wxg2.json b/advisories/unreviewed/2024/07/GHSA-26qv-3573-wxg2/GHSA-26qv-3573-wxg2.json index f66c73cfe31..39326f68152 100644 --- a/advisories/unreviewed/2024/07/GHSA-26qv-3573-wxg2/GHSA-26qv-3573-wxg2.json +++ b/advisories/unreviewed/2024/07/GHSA-26qv-3573-wxg2/GHSA-26qv-3573-wxg2.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-3f24-4xhj-mpvj/GHSA-3f24-4xhj-mpvj.json b/advisories/unreviewed/2024/07/GHSA-3f24-4xhj-mpvj/GHSA-3f24-4xhj-mpvj.json index 40741007044..6575d9d9d5d 100644 --- a/advisories/unreviewed/2024/07/GHSA-3f24-4xhj-mpvj/GHSA-3f24-4xhj-mpvj.json +++ b/advisories/unreviewed/2024/07/GHSA-3f24-4xhj-mpvj/GHSA-3f24-4xhj-mpvj.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-3px4-37qg-4m28/GHSA-3px4-37qg-4m28.json b/advisories/unreviewed/2024/07/GHSA-3px4-37qg-4m28/GHSA-3px4-37qg-4m28.json index 22e7d0fc7da..4d6f9d3bc1b 100644 --- a/advisories/unreviewed/2024/07/GHSA-3px4-37qg-4m28/GHSA-3px4-37qg-4m28.json +++ b/advisories/unreviewed/2024/07/GHSA-3px4-37qg-4m28/GHSA-3px4-37qg-4m28.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-4g4c-285h-w45p/GHSA-4g4c-285h-w45p.json b/advisories/unreviewed/2024/07/GHSA-4g4c-285h-w45p/GHSA-4g4c-285h-w45p.json index b3b5c2a91e4..804607bbb1a 100644 --- a/advisories/unreviewed/2024/07/GHSA-4g4c-285h-w45p/GHSA-4g4c-285h-w45p.json +++ b/advisories/unreviewed/2024/07/GHSA-4g4c-285h-w45p/GHSA-4g4c-285h-w45p.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-4mr2-m258-8523/GHSA-4mr2-m258-8523.json b/advisories/unreviewed/2024/07/GHSA-4mr2-m258-8523/GHSA-4mr2-m258-8523.json index 0da646a02a1..35f33e64664 100644 --- a/advisories/unreviewed/2024/07/GHSA-4mr2-m258-8523/GHSA-4mr2-m258-8523.json +++ b/advisories/unreviewed/2024/07/GHSA-4mr2-m258-8523/GHSA-4mr2-m258-8523.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -63,9 +61,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-c4hf-x9gr-w5f8/GHSA-c4hf-x9gr-w5f8.json b/advisories/unreviewed/2024/07/GHSA-c4hf-x9gr-w5f8/GHSA-c4hf-x9gr-w5f8.json index 99492c87c24..da46601cb33 100644 --- a/advisories/unreviewed/2024/07/GHSA-c4hf-x9gr-w5f8/GHSA-c4hf-x9gr-w5f8.json +++ b/advisories/unreviewed/2024/07/GHSA-c4hf-x9gr-w5f8/GHSA-c4hf-x9gr-w5f8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-cwwg-wc3x-x7gv/GHSA-cwwg-wc3x-x7gv.json b/advisories/unreviewed/2024/07/GHSA-cwwg-wc3x-x7gv/GHSA-cwwg-wc3x-x7gv.json index 242840a5fd7..0d95e708080 100644 --- a/advisories/unreviewed/2024/07/GHSA-cwwg-wc3x-x7gv/GHSA-cwwg-wc3x-x7gv.json +++ b/advisories/unreviewed/2024/07/GHSA-cwwg-wc3x-x7gv/GHSA-cwwg-wc3x-x7gv.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-f6px-65hq-2r49/GHSA-f6px-65hq-2r49.json b/advisories/unreviewed/2024/07/GHSA-f6px-65hq-2r49/GHSA-f6px-65hq-2r49.json index 878acc4f3c2..184e5bf0ebb 100644 --- a/advisories/unreviewed/2024/07/GHSA-f6px-65hq-2r49/GHSA-f6px-65hq-2r49.json +++ b/advisories/unreviewed/2024/07/GHSA-f6px-65hq-2r49/GHSA-f6px-65hq-2r49.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-fmj4-wqjv-w8v5/GHSA-fmj4-wqjv-w8v5.json b/advisories/unreviewed/2024/07/GHSA-fmj4-wqjv-w8v5/GHSA-fmj4-wqjv-w8v5.json index c6c2d5b6a5e..d8c01a06370 100644 --- a/advisories/unreviewed/2024/07/GHSA-fmj4-wqjv-w8v5/GHSA-fmj4-wqjv-w8v5.json +++ b/advisories/unreviewed/2024/07/GHSA-fmj4-wqjv-w8v5/GHSA-fmj4-wqjv-w8v5.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-gh56-vm3x-wfmw/GHSA-gh56-vm3x-wfmw.json b/advisories/unreviewed/2024/07/GHSA-gh56-vm3x-wfmw/GHSA-gh56-vm3x-wfmw.json index 724f1dcf344..1377bbb4657 100644 --- a/advisories/unreviewed/2024/07/GHSA-gh56-vm3x-wfmw/GHSA-gh56-vm3x-wfmw.json +++ b/advisories/unreviewed/2024/07/GHSA-gh56-vm3x-wfmw/GHSA-gh56-vm3x-wfmw.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-h78c-qhqh-fvgw/GHSA-h78c-qhqh-fvgw.json b/advisories/unreviewed/2024/07/GHSA-h78c-qhqh-fvgw/GHSA-h78c-qhqh-fvgw.json index 85684ca4a1b..30499ede499 100644 --- a/advisories/unreviewed/2024/07/GHSA-h78c-qhqh-fvgw/GHSA-h78c-qhqh-fvgw.json +++ b/advisories/unreviewed/2024/07/GHSA-h78c-qhqh-fvgw/GHSA-h78c-qhqh-fvgw.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-m23c-995x-54xh/GHSA-m23c-995x-54xh.json b/advisories/unreviewed/2024/07/GHSA-m23c-995x-54xh/GHSA-m23c-995x-54xh.json index 1c4cb794090..6c36c181b0a 100644 --- a/advisories/unreviewed/2024/07/GHSA-m23c-995x-54xh/GHSA-m23c-995x-54xh.json +++ b/advisories/unreviewed/2024/07/GHSA-m23c-995x-54xh/GHSA-m23c-995x-54xh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-m34f-x8c7-qwxf/GHSA-m34f-x8c7-qwxf.json b/advisories/unreviewed/2024/07/GHSA-m34f-x8c7-qwxf/GHSA-m34f-x8c7-qwxf.json index 6229d01511d..97b00c41fc6 100644 --- a/advisories/unreviewed/2024/07/GHSA-m34f-x8c7-qwxf/GHSA-m34f-x8c7-qwxf.json +++ b/advisories/unreviewed/2024/07/GHSA-m34f-x8c7-qwxf/GHSA-m34f-x8c7-qwxf.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-mm8h-h7mm-pwwr/GHSA-mm8h-h7mm-pwwr.json b/advisories/unreviewed/2024/07/GHSA-mm8h-h7mm-pwwr/GHSA-mm8h-h7mm-pwwr.json index 721da224a7d..7c5851e70ad 100644 --- a/advisories/unreviewed/2024/07/GHSA-mm8h-h7mm-pwwr/GHSA-mm8h-h7mm-pwwr.json +++ b/advisories/unreviewed/2024/07/GHSA-mm8h-h7mm-pwwr/GHSA-mm8h-h7mm-pwwr.json @@ -7,12 +7,8 @@ "CVE-2024-41021" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/mm: Fix VM_FAULT_HWPOISON handling in do_exception()\n\nThere is no support for HWPOISON, MEMORY_FAILURE, or ARCH_HAS_COPY_MC on\ns390. Therefore we do not expect to see VM_FAULT_HWPOISON in\ndo_exception().\n\nHowever, since commit af19487f00f3 (\"mm: make PTE_MARKER_SWAPIN_ERROR more\ngeneral\"), it is possible to see VM_FAULT_HWPOISON in combination with\nPTE_MARKER_POISONED, even on architectures that do not support HWPOISON\notherwise. In this case, we will end up on the BUG() in do_exception().\n\nFix this by treating VM_FAULT_HWPOISON the same as VM_FAULT_SIGBUS, similar\nto x86 when MEMORY_FAILURE is not configured. Also print unexpected fault\nflags, for easier debugging.\n\nNote that VM_FAULT_HWPOISON_LARGE is not expected, because s390 cannot\nsupport swap entries on other levels than PTE level.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-mmcm-8vr2-mmc9/GHSA-mmcm-8vr2-mmc9.json b/advisories/unreviewed/2024/07/GHSA-mmcm-8vr2-mmc9/GHSA-mmcm-8vr2-mmc9.json index 8b84e0c451e..7b8adbe22a0 100644 --- a/advisories/unreviewed/2024/07/GHSA-mmcm-8vr2-mmc9/GHSA-mmcm-8vr2-mmc9.json +++ b/advisories/unreviewed/2024/07/GHSA-mmcm-8vr2-mmc9/GHSA-mmcm-8vr2-mmc9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-pmrv-fmw3-5h6p/GHSA-pmrv-fmw3-5h6p.json b/advisories/unreviewed/2024/07/GHSA-pmrv-fmw3-5h6p/GHSA-pmrv-fmw3-5h6p.json index 2b91b99d558..eece4209b10 100644 --- a/advisories/unreviewed/2024/07/GHSA-pmrv-fmw3-5h6p/GHSA-pmrv-fmw3-5h6p.json +++ b/advisories/unreviewed/2024/07/GHSA-pmrv-fmw3-5h6p/GHSA-pmrv-fmw3-5h6p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-pv7w-569p-ww5f/GHSA-pv7w-569p-ww5f.json b/advisories/unreviewed/2024/07/GHSA-pv7w-569p-ww5f/GHSA-pv7w-569p-ww5f.json index 5086c115fbc..5061b172d6e 100644 --- a/advisories/unreviewed/2024/07/GHSA-pv7w-569p-ww5f/GHSA-pv7w-569p-ww5f.json +++ b/advisories/unreviewed/2024/07/GHSA-pv7w-569p-ww5f/GHSA-pv7w-569p-ww5f.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-q8rm-pcmh-259p/GHSA-q8rm-pcmh-259p.json b/advisories/unreviewed/2024/07/GHSA-q8rm-pcmh-259p/GHSA-q8rm-pcmh-259p.json index b84534bb453..c7cbbb6f117 100644 --- a/advisories/unreviewed/2024/07/GHSA-q8rm-pcmh-259p/GHSA-q8rm-pcmh-259p.json +++ b/advisories/unreviewed/2024/07/GHSA-q8rm-pcmh-259p/GHSA-q8rm-pcmh-259p.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-rqgm-57h6-qgc4/GHSA-rqgm-57h6-qgc4.json b/advisories/unreviewed/2024/07/GHSA-rqgm-57h6-qgc4/GHSA-rqgm-57h6-qgc4.json index 8e67bec19d3..9e35ed9dd21 100644 --- a/advisories/unreviewed/2024/07/GHSA-rqgm-57h6-qgc4/GHSA-rqgm-57h6-qgc4.json +++ b/advisories/unreviewed/2024/07/GHSA-rqgm-57h6-qgc4/GHSA-rqgm-57h6-qgc4.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-v2fj-xrgw-4h7q/GHSA-v2fj-xrgw-4h7q.json b/advisories/unreviewed/2024/07/GHSA-v2fj-xrgw-4h7q/GHSA-v2fj-xrgw-4h7q.json index 24914d08001..e1cde255c48 100644 --- a/advisories/unreviewed/2024/07/GHSA-v2fj-xrgw-4h7q/GHSA-v2fj-xrgw-4h7q.json +++ b/advisories/unreviewed/2024/07/GHSA-v2fj-xrgw-4h7q/GHSA-v2fj-xrgw-4h7q.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-x5fg-377f-962v/GHSA-x5fg-377f-962v.json b/advisories/unreviewed/2024/07/GHSA-x5fg-377f-962v/GHSA-x5fg-377f-962v.json index d189de35d59..eb0e6b037a5 100644 --- a/advisories/unreviewed/2024/07/GHSA-x5fg-377f-962v/GHSA-x5fg-377f-962v.json +++ b/advisories/unreviewed/2024/07/GHSA-x5fg-377f-962v/GHSA-x5fg-377f-962v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-22m6-3h9c-gw7v/GHSA-22m6-3h9c-gw7v.json b/advisories/unreviewed/2024/08/GHSA-22m6-3h9c-gw7v/GHSA-22m6-3h9c-gw7v.json index d38ded0378c..06f7eb4fd8a 100644 --- a/advisories/unreviewed/2024/08/GHSA-22m6-3h9c-gw7v/GHSA-22m6-3h9c-gw7v.json +++ b/advisories/unreviewed/2024/08/GHSA-22m6-3h9c-gw7v/GHSA-22m6-3h9c-gw7v.json @@ -7,12 +7,8 @@ "CVE-2022-38322" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-3hfh-c9pr-r52q/GHSA-3hfh-c9pr-r52q.json b/advisories/unreviewed/2024/08/GHSA-3hfh-c9pr-r52q/GHSA-3hfh-c9pr-r52q.json index 56ed3f6bc29..ca83a92d2a6 100644 --- a/advisories/unreviewed/2024/08/GHSA-3hfh-c9pr-r52q/GHSA-3hfh-c9pr-r52q.json +++ b/advisories/unreviewed/2024/08/GHSA-3hfh-c9pr-r52q/GHSA-3hfh-c9pr-r52q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-3q27-8g46-2vwm/GHSA-3q27-8g46-2vwm.json b/advisories/unreviewed/2024/08/GHSA-3q27-8g46-2vwm/GHSA-3q27-8g46-2vwm.json index a65d7aacc1f..5f273ae81b0 100644 --- a/advisories/unreviewed/2024/08/GHSA-3q27-8g46-2vwm/GHSA-3q27-8g46-2vwm.json +++ b/advisories/unreviewed/2024/08/GHSA-3q27-8g46-2vwm/GHSA-3q27-8g46-2vwm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-3wch-5xm2-547f/GHSA-3wch-5xm2-547f.json b/advisories/unreviewed/2024/08/GHSA-3wch-5xm2-547f/GHSA-3wch-5xm2-547f.json index 5fbbaab8d5b..249badadf3e 100644 --- a/advisories/unreviewed/2024/08/GHSA-3wch-5xm2-547f/GHSA-3wch-5xm2-547f.json +++ b/advisories/unreviewed/2024/08/GHSA-3wch-5xm2-547f/GHSA-3wch-5xm2-547f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-4589-q5rf-w7g2/GHSA-4589-q5rf-w7g2.json b/advisories/unreviewed/2024/08/GHSA-4589-q5rf-w7g2/GHSA-4589-q5rf-w7g2.json index 1692a1f3a34..9bee645fbeb 100644 --- a/advisories/unreviewed/2024/08/GHSA-4589-q5rf-w7g2/GHSA-4589-q5rf-w7g2.json +++ b/advisories/unreviewed/2024/08/GHSA-4589-q5rf-w7g2/GHSA-4589-q5rf-w7g2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-4q2c-288h-f42x/GHSA-4q2c-288h-f42x.json b/advisories/unreviewed/2024/08/GHSA-4q2c-288h-f42x/GHSA-4q2c-288h-f42x.json index e078beb6300..979af7ff840 100644 --- a/advisories/unreviewed/2024/08/GHSA-4q2c-288h-f42x/GHSA-4q2c-288h-f42x.json +++ b/advisories/unreviewed/2024/08/GHSA-4q2c-288h-f42x/GHSA-4q2c-288h-f42x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-6w5f-w9gf-qv9r/GHSA-6w5f-w9gf-qv9r.json b/advisories/unreviewed/2024/08/GHSA-6w5f-w9gf-qv9r/GHSA-6w5f-w9gf-qv9r.json index cbfdc34d762..19cd18b5055 100644 --- a/advisories/unreviewed/2024/08/GHSA-6w5f-w9gf-qv9r/GHSA-6w5f-w9gf-qv9r.json +++ b/advisories/unreviewed/2024/08/GHSA-6w5f-w9gf-qv9r/GHSA-6w5f-w9gf-qv9r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-7q95-85ph-5grx/GHSA-7q95-85ph-5grx.json b/advisories/unreviewed/2024/08/GHSA-7q95-85ph-5grx/GHSA-7q95-85ph-5grx.json index 0d9bc7c756d..e25a197e295 100644 --- a/advisories/unreviewed/2024/08/GHSA-7q95-85ph-5grx/GHSA-7q95-85ph-5grx.json +++ b/advisories/unreviewed/2024/08/GHSA-7q95-85ph-5grx/GHSA-7q95-85ph-5grx.json @@ -13,9 +13,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:I/V:C/RE:H/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-7w94-mp6m-pfq8/GHSA-7w94-mp6m-pfq8.json b/advisories/unreviewed/2024/08/GHSA-7w94-mp6m-pfq8/GHSA-7w94-mp6m-pfq8.json index eb8da79a622..bf13a4383d3 100644 --- a/advisories/unreviewed/2024/08/GHSA-7w94-mp6m-pfq8/GHSA-7w94-mp6m-pfq8.json +++ b/advisories/unreviewed/2024/08/GHSA-7w94-mp6m-pfq8/GHSA-7w94-mp6m-pfq8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-853r-xr2f-r2x6/GHSA-853r-xr2f-r2x6.json b/advisories/unreviewed/2024/08/GHSA-853r-xr2f-r2x6/GHSA-853r-xr2f-r2x6.json index 22242a31571..2b59117e1ce 100644 --- a/advisories/unreviewed/2024/08/GHSA-853r-xr2f-r2x6/GHSA-853r-xr2f-r2x6.json +++ b/advisories/unreviewed/2024/08/GHSA-853r-xr2f-r2x6/GHSA-853r-xr2f-r2x6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-8mm7-xxcv-xpvr/GHSA-8mm7-xxcv-xpvr.json b/advisories/unreviewed/2024/08/GHSA-8mm7-xxcv-xpvr/GHSA-8mm7-xxcv-xpvr.json index 3500619dd1b..3d05a5b049a 100644 --- a/advisories/unreviewed/2024/08/GHSA-8mm7-xxcv-xpvr/GHSA-8mm7-xxcv-xpvr.json +++ b/advisories/unreviewed/2024/08/GHSA-8mm7-xxcv-xpvr/GHSA-8mm7-xxcv-xpvr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-8rqq-pq2c-29q4/GHSA-8rqq-pq2c-29q4.json b/advisories/unreviewed/2024/08/GHSA-8rqq-pq2c-29q4/GHSA-8rqq-pq2c-29q4.json index 5d8bd010136..60744375e2a 100644 --- a/advisories/unreviewed/2024/08/GHSA-8rqq-pq2c-29q4/GHSA-8rqq-pq2c-29q4.json +++ b/advisories/unreviewed/2024/08/GHSA-8rqq-pq2c-29q4/GHSA-8rqq-pq2c-29q4.json @@ -13,9 +13,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:X/RE:X/U:Red" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-96xq-492q-g359/GHSA-96xq-492q-g359.json b/advisories/unreviewed/2024/08/GHSA-96xq-492q-g359/GHSA-96xq-492q-g359.json index 46bc3b978a2..9d976ba2710 100644 --- a/advisories/unreviewed/2024/08/GHSA-96xq-492q-g359/GHSA-96xq-492q-g359.json +++ b/advisories/unreviewed/2024/08/GHSA-96xq-492q-g359/GHSA-96xq-492q-g359.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-9mq7-8hm8-q3mp/GHSA-9mq7-8hm8-q3mp.json b/advisories/unreviewed/2024/08/GHSA-9mq7-8hm8-q3mp/GHSA-9mq7-8hm8-q3mp.json index 9ade1eaf2a8..d7486aa40f5 100644 --- a/advisories/unreviewed/2024/08/GHSA-9mq7-8hm8-q3mp/GHSA-9mq7-8hm8-q3mp.json +++ b/advisories/unreviewed/2024/08/GHSA-9mq7-8hm8-q3mp/GHSA-9mq7-8hm8-q3mp.json @@ -13,9 +13,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-f8mp-x4p7-qqwp/GHSA-f8mp-x4p7-qqwp.json b/advisories/unreviewed/2024/08/GHSA-f8mp-x4p7-qqwp/GHSA-f8mp-x4p7-qqwp.json index c6addd55a2f..c795e5f81f8 100644 --- a/advisories/unreviewed/2024/08/GHSA-f8mp-x4p7-qqwp/GHSA-f8mp-x4p7-qqwp.json +++ b/advisories/unreviewed/2024/08/GHSA-f8mp-x4p7-qqwp/GHSA-f8mp-x4p7-qqwp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-frr6-4w4r-wrwv/GHSA-frr6-4w4r-wrwv.json b/advisories/unreviewed/2024/08/GHSA-frr6-4w4r-wrwv/GHSA-frr6-4w4r-wrwv.json index 3912d742388..4bd728850d6 100644 --- a/advisories/unreviewed/2024/08/GHSA-frr6-4w4r-wrwv/GHSA-frr6-4w4r-wrwv.json +++ b/advisories/unreviewed/2024/08/GHSA-frr6-4w4r-wrwv/GHSA-frr6-4w4r-wrwv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-fx2m-xj8m-g5xr/GHSA-fx2m-xj8m-g5xr.json b/advisories/unreviewed/2024/08/GHSA-fx2m-xj8m-g5xr/GHSA-fx2m-xj8m-g5xr.json index 68116d1ebd0..b20ac407fe8 100644 --- a/advisories/unreviewed/2024/08/GHSA-fx2m-xj8m-g5xr/GHSA-fx2m-xj8m-g5xr.json +++ b/advisories/unreviewed/2024/08/GHSA-fx2m-xj8m-g5xr/GHSA-fx2m-xj8m-g5xr.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-j3gj-rx67-762c/GHSA-j3gj-rx67-762c.json b/advisories/unreviewed/2024/08/GHSA-j3gj-rx67-762c/GHSA-j3gj-rx67-762c.json index 24f246a14d6..bc226fcb3df 100644 --- a/advisories/unreviewed/2024/08/GHSA-j3gj-rx67-762c/GHSA-j3gj-rx67-762c.json +++ b/advisories/unreviewed/2024/08/GHSA-j3gj-rx67-762c/GHSA-j3gj-rx67-762c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-jq88-xg24-9pch/GHSA-jq88-xg24-9pch.json b/advisories/unreviewed/2024/08/GHSA-jq88-xg24-9pch/GHSA-jq88-xg24-9pch.json index 11a48656b27..3c72639a432 100644 --- a/advisories/unreviewed/2024/08/GHSA-jq88-xg24-9pch/GHSA-jq88-xg24-9pch.json +++ b/advisories/unreviewed/2024/08/GHSA-jq88-xg24-9pch/GHSA-jq88-xg24-9pch.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-m34r-jrv8-mwmv/GHSA-m34r-jrv8-mwmv.json b/advisories/unreviewed/2024/08/GHSA-m34r-jrv8-mwmv/GHSA-m34r-jrv8-mwmv.json index d7cfdf7c10b..6d876b86ec1 100644 --- a/advisories/unreviewed/2024/08/GHSA-m34r-jrv8-mwmv/GHSA-m34r-jrv8-mwmv.json +++ b/advisories/unreviewed/2024/08/GHSA-m34r-jrv8-mwmv/GHSA-m34r-jrv8-mwmv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-m54w-mhp6-x65m/GHSA-m54w-mhp6-x65m.json b/advisories/unreviewed/2024/08/GHSA-m54w-mhp6-x65m/GHSA-m54w-mhp6-x65m.json index 062ba046ce6..bbe589e6887 100644 --- a/advisories/unreviewed/2024/08/GHSA-m54w-mhp6-x65m/GHSA-m54w-mhp6-x65m.json +++ b/advisories/unreviewed/2024/08/GHSA-m54w-mhp6-x65m/GHSA-m54w-mhp6-x65m.json @@ -13,9 +13,7 @@ "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-mmh3-p6qg-xhw2/GHSA-mmh3-p6qg-xhw2.json b/advisories/unreviewed/2024/08/GHSA-mmh3-p6qg-xhw2/GHSA-mmh3-p6qg-xhw2.json index 7797265355c..4ae7182cf0b 100644 --- a/advisories/unreviewed/2024/08/GHSA-mmh3-p6qg-xhw2/GHSA-mmh3-p6qg-xhw2.json +++ b/advisories/unreviewed/2024/08/GHSA-mmh3-p6qg-xhw2/GHSA-mmh3-p6qg-xhw2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-p66m-cfp6-v6jq/GHSA-p66m-cfp6-v6jq.json b/advisories/unreviewed/2024/08/GHSA-p66m-cfp6-v6jq/GHSA-p66m-cfp6-v6jq.json index 191a2deefa1..11fa6738c6c 100644 --- a/advisories/unreviewed/2024/08/GHSA-p66m-cfp6-v6jq/GHSA-p66m-cfp6-v6jq.json +++ b/advisories/unreviewed/2024/08/GHSA-p66m-cfp6-v6jq/GHSA-p66m-cfp6-v6jq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-p859-wc97-3523/GHSA-p859-wc97-3523.json b/advisories/unreviewed/2024/08/GHSA-p859-wc97-3523/GHSA-p859-wc97-3523.json index c19d360ce76..2a058a7f6bf 100644 --- a/advisories/unreviewed/2024/08/GHSA-p859-wc97-3523/GHSA-p859-wc97-3523.json +++ b/advisories/unreviewed/2024/08/GHSA-p859-wc97-3523/GHSA-p859-wc97-3523.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-pgr9-55pc-cmx2/GHSA-pgr9-55pc-cmx2.json b/advisories/unreviewed/2024/08/GHSA-pgr9-55pc-cmx2/GHSA-pgr9-55pc-cmx2.json index b58c197b7df..96ffdf105e0 100644 --- a/advisories/unreviewed/2024/08/GHSA-pgr9-55pc-cmx2/GHSA-pgr9-55pc-cmx2.json +++ b/advisories/unreviewed/2024/08/GHSA-pgr9-55pc-cmx2/GHSA-pgr9-55pc-cmx2.json @@ -13,9 +13,7 @@ "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-q7g5-2mg7-m2r3/GHSA-q7g5-2mg7-m2r3.json b/advisories/unreviewed/2024/08/GHSA-q7g5-2mg7-m2r3/GHSA-q7g5-2mg7-m2r3.json index 631031ea055..c5cc02ada5a 100644 --- a/advisories/unreviewed/2024/08/GHSA-q7g5-2mg7-m2r3/GHSA-q7g5-2mg7-m2r3.json +++ b/advisories/unreviewed/2024/08/GHSA-q7g5-2mg7-m2r3/GHSA-q7g5-2mg7-m2r3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-qxrq-fp7f-qqh5/GHSA-qxrq-fp7f-qqh5.json b/advisories/unreviewed/2024/08/GHSA-qxrq-fp7f-qqh5/GHSA-qxrq-fp7f-qqh5.json index 97e94649451..1af17947130 100644 --- a/advisories/unreviewed/2024/08/GHSA-qxrq-fp7f-qqh5/GHSA-qxrq-fp7f-qqh5.json +++ b/advisories/unreviewed/2024/08/GHSA-qxrq-fp7f-qqh5/GHSA-qxrq-fp7f-qqh5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-rrpm-pxv9-75vx/GHSA-rrpm-pxv9-75vx.json b/advisories/unreviewed/2024/08/GHSA-rrpm-pxv9-75vx/GHSA-rrpm-pxv9-75vx.json index ebeebec01d7..32e9183be94 100644 --- a/advisories/unreviewed/2024/08/GHSA-rrpm-pxv9-75vx/GHSA-rrpm-pxv9-75vx.json +++ b/advisories/unreviewed/2024/08/GHSA-rrpm-pxv9-75vx/GHSA-rrpm-pxv9-75vx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-vv3h-2qxx-g79m/GHSA-vv3h-2qxx-g79m.json b/advisories/unreviewed/2024/08/GHSA-vv3h-2qxx-g79m/GHSA-vv3h-2qxx-g79m.json index 81d088b7ef9..34bdfea930d 100644 --- a/advisories/unreviewed/2024/08/GHSA-vv3h-2qxx-g79m/GHSA-vv3h-2qxx-g79m.json +++ b/advisories/unreviewed/2024/08/GHSA-vv3h-2qxx-g79m/GHSA-vv3h-2qxx-g79m.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-x73h-483r-8x6h/GHSA-x73h-483r-8x6h.json b/advisories/unreviewed/2024/08/GHSA-x73h-483r-8x6h/GHSA-x73h-483r-8x6h.json index 33872e8bd74..08d93d00890 100644 --- a/advisories/unreviewed/2024/08/GHSA-x73h-483r-8x6h/GHSA-x73h-483r-8x6h.json +++ b/advisories/unreviewed/2024/08/GHSA-x73h-483r-8x6h/GHSA-x73h-483r-8x6h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-xvx6-rgcr-cjh6/GHSA-xvx6-rgcr-cjh6.json b/advisories/unreviewed/2024/08/GHSA-xvx6-rgcr-cjh6/GHSA-xvx6-rgcr-cjh6.json index 1a202216913..73f3d7b7306 100644 --- a/advisories/unreviewed/2024/08/GHSA-xvx6-rgcr-cjh6/GHSA-xvx6-rgcr-cjh6.json +++ b/advisories/unreviewed/2024/08/GHSA-xvx6-rgcr-cjh6/GHSA-xvx6-rgcr-cjh6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",