From 1fd32d0629d387856492f41f696b8ce9741cc684 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 29 Nov 2024 05:07:31 +0000 Subject: [PATCH] Advisory Database Sync --- .../04/GHSA-gvj8-4cj4-h776/GHSA-gvj8-4cj4-h776.json | 8 ++------ .../04/GHSA-w8qp-hmh5-4v9v/GHSA-w8qp-hmh5-4v9v.json | 8 ++------ .../02/GHSA-22q8-ghmq-63vf/GHSA-22q8-ghmq-63vf.json | 8 ++------ .../02/GHSA-6ccv-8fgf-cjpw/GHSA-6ccv-8fgf-cjpw.json | 12 +++--------- .../01/GHSA-244j-xp9p-xr45/GHSA-244j-xp9p-xr45.json | 4 +--- .../01/GHSA-2522-v35m-2r22/GHSA-2522-v35m-2r22.json | 4 +--- .../01/GHSA-2829-f4q2-487p/GHSA-2829-f4q2-487p.json | 4 +--- .../01/GHSA-34vx-3926-gfg8/GHSA-34vx-3926-gfg8.json | 4 +--- .../01/GHSA-38r5-jq63-gvw6/GHSA-38r5-jq63-gvw6.json | 4 +--- .../01/GHSA-3f3x-x2x3-wvhg/GHSA-3f3x-x2x3-wvhg.json | 4 +--- .../01/GHSA-3wpw-8xfm-9j79/GHSA-3wpw-8xfm-9j79.json | 8 ++------ .../01/GHSA-44x5-vv7x-rxj5/GHSA-44x5-vv7x-rxj5.json | 4 +--- .../01/GHSA-45mw-x2rr-9wpc/GHSA-45mw-x2rr-9wpc.json | 4 +--- .../01/GHSA-4vj4-c65w-6944/GHSA-4vj4-c65w-6944.json | 4 +--- .../01/GHSA-5qxw-jpqh-h83p/GHSA-5qxw-jpqh-h83p.json | 4 +--- .../01/GHSA-624j-wgxh-4x2w/GHSA-624j-wgxh-4x2w.json | 4 +--- .../01/GHSA-6mww-ch69-p82p/GHSA-6mww-ch69-p82p.json | 4 +--- .../01/GHSA-6qgv-gg3v-w69g/GHSA-6qgv-gg3v-w69g.json | 4 +--- .../01/GHSA-74f6-jp2h-2vw3/GHSA-74f6-jp2h-2vw3.json | 4 +--- .../01/GHSA-75xf-j8f2-9vxq/GHSA-75xf-j8f2-9vxq.json | 4 +--- .../01/GHSA-7668-4r26-7chc/GHSA-7668-4r26-7chc.json | 4 +--- .../01/GHSA-78wc-5whv-3wwg/GHSA-78wc-5whv-3wwg.json | 4 +--- .../01/GHSA-8fq4-c2f3-pq2m/GHSA-8fq4-c2f3-pq2m.json | 4 +--- .../01/GHSA-8qvj-hvvg-8w4c/GHSA-8qvj-hvvg-8w4c.json | 4 +--- .../01/GHSA-9gjj-g26q-4xmj/GHSA-9gjj-g26q-4xmj.json | 4 +--- .../01/GHSA-c6m3-26jj-88r9/GHSA-c6m3-26jj-88r9.json | 4 +--- .../01/GHSA-c8mf-xmr4-fx64/GHSA-c8mf-xmr4-fx64.json | 4 +--- .../01/GHSA-cqqw-769j-6gm9/GHSA-cqqw-769j-6gm9.json | 4 +--- .../01/GHSA-fc93-89fq-8669/GHSA-fc93-89fq-8669.json | 4 +--- .../01/GHSA-fhmq-5697-m94q/GHSA-fhmq-5697-m94q.json | 4 +--- .../01/GHSA-fpm5-5f53-975w/GHSA-fpm5-5f53-975w.json | 4 +--- .../01/GHSA-gg45-6m56-hjqc/GHSA-gg45-6m56-hjqc.json | 4 +--- .../01/GHSA-gq64-xh72-gm28/GHSA-gq64-xh72-gm28.json | 4 +--- .../01/GHSA-hh9q-3234-5wjp/GHSA-hh9q-3234-5wjp.json | 4 +--- .../01/GHSA-hvh7-f5p9-68g8/GHSA-hvh7-f5p9-68g8.json | 4 +--- .../01/GHSA-j6rg-mpmv-h73q/GHSA-j6rg-mpmv-h73q.json | 4 +--- .../01/GHSA-j7c5-g427-27ch/GHSA-j7c5-g427-27ch.json | 4 +--- .../01/GHSA-jm36-4mv9-x2pw/GHSA-jm36-4mv9-x2pw.json | 4 +--- .../01/GHSA-jx53-3cxj-386g/GHSA-jx53-3cxj-386g.json | 4 +--- .../01/GHSA-jxv7-pgr4-p3g5/GHSA-jxv7-pgr4-p3g5.json | 4 +--- .../01/GHSA-mp4c-vqqf-2qxg/GHSA-mp4c-vqqf-2qxg.json | 4 +--- .../01/GHSA-phg8-x4rr-qpgf/GHSA-phg8-x4rr-qpgf.json | 4 +--- .../01/GHSA-qcmm-58xj-wh4r/GHSA-qcmm-58xj-wh4r.json | 4 +--- .../01/GHSA-qf8x-c298-x5pj/GHSA-qf8x-c298-x5pj.json | 4 +--- .../01/GHSA-qx9v-9g4v-j92f/GHSA-qx9v-9g4v-j92f.json | 4 +--- .../01/GHSA-r8rw-g922-j95j/GHSA-r8rw-g922-j95j.json | 4 +--- .../01/GHSA-r9gp-v7qw-28p5/GHSA-r9gp-v7qw-28p5.json | 4 +--- .../01/GHSA-rgf9-28hg-x4c8/GHSA-rgf9-28hg-x4c8.json | 4 +--- .../01/GHSA-v63v-32vm-px2m/GHSA-v63v-32vm-px2m.json | 4 +--- .../01/GHSA-v6rf-w7jv-9fmc/GHSA-v6rf-w7jv-9fmc.json | 4 +--- .../01/GHSA-w6w3-wf72-pc3c/GHSA-w6w3-wf72-pc3c.json | 4 +--- .../01/GHSA-wrgg-vhm7-9frx/GHSA-wrgg-vhm7-9frx.json | 4 +--- .../01/GHSA-x96q-w32v-vmr6/GHSA-x96q-w32v-vmr6.json | 4 +--- .../01/GHSA-xcjr-gm58-gw5q/GHSA-xcjr-gm58-gw5q.json | 4 +--- .../01/GHSA-xqcg-xx67-m64q/GHSA-xqcg-xx67-m64q.json | 4 +--- .../02/GHSA-2vw5-8fhm-cvqc/GHSA-2vw5-8fhm-cvqc.json | 4 +--- .../02/GHSA-3mj9-r4cx-8mx5/GHSA-3mj9-r4cx-8mx5.json | 4 +--- .../02/GHSA-56jf-qqrc-2h69/GHSA-56jf-qqrc-2h69.json | 4 +--- .../02/GHSA-59h2-qw44-f67r/GHSA-59h2-qw44-f67r.json | 4 +--- .../02/GHSA-6c2j-x443-7jc3/GHSA-6c2j-x443-7jc3.json | 4 +--- .../02/GHSA-6xjp-85f8-j93c/GHSA-6xjp-85f8-j93c.json | 4 +--- .../02/GHSA-84hw-gj94-jqrm/GHSA-84hw-gj94-jqrm.json | 4 +--- .../02/GHSA-c3p4-6x5w-74fx/GHSA-c3p4-6x5w-74fx.json | 4 +--- .../02/GHSA-cwhj-hjpj-c7pg/GHSA-cwhj-hjpj-c7pg.json | 4 +--- .../02/GHSA-f9cx-48m4-2xp7/GHSA-f9cx-48m4-2xp7.json | 4 +--- .../02/GHSA-f9wp-vh4x-jjw7/GHSA-f9wp-vh4x-jjw7.json | 4 +--- .../02/GHSA-hfj6-rq3w-f48r/GHSA-hfj6-rq3w-f48r.json | 4 +--- .../02/GHSA-hgww-4988-8569/GHSA-hgww-4988-8569.json | 4 +--- .../02/GHSA-hmx6-wg4q-3825/GHSA-hmx6-wg4q-3825.json | 4 +--- .../02/GHSA-jjh6-7r67-w858/GHSA-jjh6-7r67-w858.json | 4 +--- .../02/GHSA-mqcr-p73p-f4gw/GHSA-mqcr-p73p-f4gw.json | 8 ++------ .../02/GHSA-pjg5-4frx-8m6r/GHSA-pjg5-4frx-8m6r.json | 4 +--- .../02/GHSA-pm6q-mcg4-jmhv/GHSA-pm6q-mcg4-jmhv.json | 8 ++------ .../02/GHSA-pvxv-cw79-c2x3/GHSA-pvxv-cw79-c2x3.json | 8 ++------ .../02/GHSA-pwhp-6h3m-r2xh/GHSA-pwhp-6h3m-r2xh.json | 4 +--- .../02/GHSA-qhx3-4p72-9vg9/GHSA-qhx3-4p72-9vg9.json | 8 ++------ .../02/GHSA-qhxw-jx34-g2pf/GHSA-qhxw-jx34-g2pf.json | 4 +--- .../02/GHSA-rcf2-975r-j599/GHSA-rcf2-975r-j599.json | 4 +--- .../02/GHSA-v4wx-vjh5-hw9r/GHSA-v4wx-vjh5-hw9r.json | 4 +--- .../02/GHSA-vcm5-6w8c-v573/GHSA-vcm5-6w8c-v573.json | 4 +--- .../02/GHSA-xg7w-9w3p-gqx3/GHSA-xg7w-9w3p-gqx3.json | 4 +--- .../02/GHSA-xmgg-9fr8-3f5f/GHSA-xmgg-9fr8-3f5f.json | 4 +--- .../02/GHSA-xxh4-49r4-6rx5/GHSA-xxh4-49r4-6rx5.json | 4 +--- .../04/GHSA-2375-ph49-69c5/GHSA-2375-ph49-69c5.json | 4 +--- .../04/GHSA-23w8-jcvm-j4jg/GHSA-23w8-jcvm-j4jg.json | 8 ++------ .../04/GHSA-26fg-x3pj-c24v/GHSA-26fg-x3pj-c24v.json | 12 +++--------- .../04/GHSA-26r4-3m3w-c772/GHSA-26r4-3m3w-c772.json | 12 +++--------- .../04/GHSA-2jm4-cm7h-hghg/GHSA-2jm4-cm7h-hghg.json | 12 +++--------- .../04/GHSA-2q4p-93p8-q2j6/GHSA-2q4p-93p8-q2j6.json | 12 +++--------- .../04/GHSA-2qh3-fm9g-rf2x/GHSA-2qh3-fm9g-rf2x.json | 12 +++--------- .../04/GHSA-2qvr-2h7g-c4xv/GHSA-2qvr-2h7g-c4xv.json | 12 +++--------- .../04/GHSA-2rfr-226c-v52m/GHSA-2rfr-226c-v52m.json | 12 +++--------- .../04/GHSA-2rgg-v6c8-mc7v/GHSA-2rgg-v6c8-mc7v.json | 12 +++--------- .../04/GHSA-2v5r-gc72-7xcw/GHSA-2v5r-gc72-7xcw.json | 12 +++--------- .../04/GHSA-2v8x-qgh9-phcv/GHSA-2v8x-qgh9-phcv.json | 12 +++--------- .../04/GHSA-2v97-q484-q665/GHSA-2v97-q484-q665.json | 12 +++--------- .../04/GHSA-2w96-x49m-vc2j/GHSA-2w96-x49m-vc2j.json | 12 +++--------- .../04/GHSA-2xmw-23qh-mjvr/GHSA-2xmw-23qh-mjvr.json | 12 +++--------- .../04/GHSA-33w2-v4x9-r4gw/GHSA-33w2-v4x9-r4gw.json | 12 +++--------- .../04/GHSA-3432-988g-mrrm/GHSA-3432-988g-mrrm.json | 4 +--- .../04/GHSA-37f6-2x94-2r9p/GHSA-37f6-2x94-2r9p.json | 12 +++--------- .../04/GHSA-37j4-jj4f-rgwh/GHSA-37j4-jj4f-rgwh.json | 8 ++------ .../04/GHSA-38vj-q4h7-q9qr/GHSA-38vj-q4h7-q9qr.json | 12 +++--------- .../04/GHSA-3cw3-m7gv-grjw/GHSA-3cw3-m7gv-grjw.json | 12 +++--------- .../04/GHSA-3gmr-q2mv-97r5/GHSA-3gmr-q2mv-97r5.json | 12 +++--------- .../04/GHSA-3gpj-j7q9-9qp4/GHSA-3gpj-j7q9-9qp4.json | 12 +++--------- .../04/GHSA-3hm7-25rv-3whx/GHSA-3hm7-25rv-3whx.json | 12 +++--------- .../04/GHSA-3j78-fv9c-9gh2/GHSA-3j78-fv9c-9gh2.json | 12 +++--------- .../04/GHSA-3mrf-6r8f-wh4j/GHSA-3mrf-6r8f-wh4j.json | 4 +--- .../04/GHSA-3p24-gwpr-5f2q/GHSA-3p24-gwpr-5f2q.json | 12 +++--------- .../04/GHSA-3pc8-5mmp-rgj7/GHSA-3pc8-5mmp-rgj7.json | 12 +++--------- .../04/GHSA-3pq4-c488-v2m4/GHSA-3pq4-c488-v2m4.json | 12 +++--------- .../04/GHSA-3pxq-5cc9-p3hw/GHSA-3pxq-5cc9-p3hw.json | 8 ++------ .../04/GHSA-3qq6-672j-jx3v/GHSA-3qq6-672j-jx3v.json | 8 ++------ .../04/GHSA-3w87-5jwj-39vh/GHSA-3w87-5jwj-39vh.json | 4 +--- .../04/GHSA-3xp2-vcr5-r48r/GHSA-3xp2-vcr5-r48r.json | 8 ++------ .../04/GHSA-3xpm-4m85-6353/GHSA-3xpm-4m85-6353.json | 4 +--- .../04/GHSA-435x-xc34-27p6/GHSA-435x-xc34-27p6.json | 12 +++--------- .../04/GHSA-45hc-2hjf-p969/GHSA-45hc-2hjf-p969.json | 8 ++------ .../04/GHSA-4839-775x-j3vf/GHSA-4839-775x-j3vf.json | 12 +++--------- .../04/GHSA-49h7-mvgr-p5p6/GHSA-49h7-mvgr-p5p6.json | 12 +++--------- .../04/GHSA-4f48-w364-xw45/GHSA-4f48-w364-xw45.json | 4 +--- .../04/GHSA-4h4f-vwmm-9jhr/GHSA-4h4f-vwmm-9jhr.json | 12 +++--------- .../04/GHSA-4h82-3wj3-6799/GHSA-4h82-3wj3-6799.json | 12 +++--------- .../04/GHSA-4j28-rvvh-wc2q/GHSA-4j28-rvvh-wc2q.json | 12 +++--------- .../04/GHSA-4pwf-7qrc-mcqp/GHSA-4pwf-7qrc-mcqp.json | 12 +++--------- .../04/GHSA-4qvp-jp63-2mpf/GHSA-4qvp-jp63-2mpf.json | 12 +++--------- .../04/GHSA-4r9w-xpf5-xm4g/GHSA-4r9w-xpf5-xm4g.json | 8 ++------ .../04/GHSA-4rg9-9m3h-2wgj/GHSA-4rg9-9m3h-2wgj.json | 12 +++--------- .../04/GHSA-4vfw-6c9m-chgp/GHSA-4vfw-6c9m-chgp.json | 8 ++------ .../04/GHSA-4w92-vgp9-22jp/GHSA-4w92-vgp9-22jp.json | 12 +++--------- .../04/GHSA-4wcx-7mj5-65f6/GHSA-4wcx-7mj5-65f6.json | 8 ++------ .../04/GHSA-52c4-mqqm-x3xx/GHSA-52c4-mqqm-x3xx.json | 4 +--- .../04/GHSA-547m-mqmc-2jqg/GHSA-547m-mqmc-2jqg.json | 8 ++------ .../04/GHSA-54jx-rwf9-488w/GHSA-54jx-rwf9-488w.json | 8 ++------ .../04/GHSA-55mq-4v94-5jrj/GHSA-55mq-4v94-5jrj.json | 12 +++--------- .../04/GHSA-57w7-wq63-9jwj/GHSA-57w7-wq63-9jwj.json | 12 +++--------- .../04/GHSA-5824-6p3v-vcx4/GHSA-5824-6p3v-vcx4.json | 8 ++------ .../04/GHSA-5872-q7c3-cvqr/GHSA-5872-q7c3-cvqr.json | 12 +++--------- .../04/GHSA-58v3-hf8m-w67r/GHSA-58v3-hf8m-w67r.json | 12 +++--------- .../04/GHSA-5fhp-v5ch-jvfc/GHSA-5fhp-v5ch-jvfc.json | 12 +++--------- .../04/GHSA-5gr4-pm92-g66w/GHSA-5gr4-pm92-g66w.json | 12 +++--------- .../04/GHSA-5grx-hv66-36gf/GHSA-5grx-hv66-36gf.json | 12 +++--------- .../04/GHSA-5hgg-xq5w-5m82/GHSA-5hgg-xq5w-5m82.json | 8 ++------ .../04/GHSA-5pqp-qchf-c8x3/GHSA-5pqp-qchf-c8x3.json | 8 ++------ .../04/GHSA-5wmr-53xq-5m6r/GHSA-5wmr-53xq-5m6r.json | 12 +++--------- .../04/GHSA-62jm-23c8-x8jq/GHSA-62jm-23c8-x8jq.json | 12 +++--------- .../04/GHSA-64gr-p8q7-hc37/GHSA-64gr-p8q7-hc37.json | 8 ++------ .../04/GHSA-6679-7c96-f9mj/GHSA-6679-7c96-f9mj.json | 12 +++--------- .../04/GHSA-6684-xr7v-79r6/GHSA-6684-xr7v-79r6.json | 12 +++--------- .../04/GHSA-66jf-hpv3-xqhq/GHSA-66jf-hpv3-xqhq.json | 12 +++--------- .../04/GHSA-679x-cxhr-6g88/GHSA-679x-cxhr-6g88.json | 12 +++--------- .../04/GHSA-685v-wjj6-4qpx/GHSA-685v-wjj6-4qpx.json | 12 +++--------- .../04/GHSA-692q-6xmm-qwr4/GHSA-692q-6xmm-qwr4.json | 8 ++------ .../04/GHSA-6mqq-2gc9-7j3v/GHSA-6mqq-2gc9-7j3v.json | 4 +--- .../04/GHSA-6p5f-vq8j-gwq7/GHSA-6p5f-vq8j-gwq7.json | 12 +++--------- .../04/GHSA-6rch-h7pj-5838/GHSA-6rch-h7pj-5838.json | 8 ++------ .../04/GHSA-6vgj-39gw-mxw3/GHSA-6vgj-39gw-mxw3.json | 12 +++--------- .../04/GHSA-6xqv-7w4h-6vqr/GHSA-6xqv-7w4h-6vqr.json | 8 ++------ .../04/GHSA-7348-84cp-xjx4/GHSA-7348-84cp-xjx4.json | 12 +++--------- .../04/GHSA-7527-xrwh-9cq5/GHSA-7527-xrwh-9cq5.json | 8 ++------ .../04/GHSA-758w-3fxj-83wq/GHSA-758w-3fxj-83wq.json | 8 ++------ .../04/GHSA-79p6-hxp5-mfcw/GHSA-79p6-hxp5-mfcw.json | 12 +++--------- .../04/GHSA-7c7w-55fc-fhgw/GHSA-7c7w-55fc-fhgw.json | 12 +++--------- .../04/GHSA-7fhq-48rw-37c8/GHSA-7fhq-48rw-37c8.json | 12 +++--------- .../04/GHSA-7g72-46j8-2p2r/GHSA-7g72-46j8-2p2r.json | 12 +++--------- .../04/GHSA-7gj2-q7q5-28j5/GHSA-7gj2-q7q5-28j5.json | 12 +++--------- .../04/GHSA-7j2q-p7jf-5f7p/GHSA-7j2q-p7jf-5f7p.json | 12 +++--------- .../04/GHSA-7jg9-96gf-f4px/GHSA-7jg9-96gf-f4px.json | 12 +++--------- .../04/GHSA-7mcr-wpqh-pp73/GHSA-7mcr-wpqh-pp73.json | 12 +++--------- .../04/GHSA-7pq9-p77x-p4hf/GHSA-7pq9-p77x-p4hf.json | 12 +++--------- .../04/GHSA-7qpr-6vx9-c755/GHSA-7qpr-6vx9-c755.json | 12 +++--------- .../04/GHSA-7w59-vwgr-5pgr/GHSA-7w59-vwgr-5pgr.json | 12 +++--------- .../04/GHSA-86jg-c9mr-jw7m/GHSA-86jg-c9mr-jw7m.json | 12 +++--------- .../04/GHSA-86w6-qr9g-m66p/GHSA-86w6-qr9g-m66p.json | 12 +++--------- .../04/GHSA-88vv-hvrc-733q/GHSA-88vv-hvrc-733q.json | 12 +++--------- .../04/GHSA-8924-w9cg-j6hh/GHSA-8924-w9cg-j6hh.json | 12 +++--------- .../04/GHSA-896f-4xcx-6p32/GHSA-896f-4xcx-6p32.json | 8 ++------ .../04/GHSA-8f2r-wvm7-v573/GHSA-8f2r-wvm7-v573.json | 12 +++--------- .../04/GHSA-8f69-wvhw-fqc8/GHSA-8f69-wvhw-fqc8.json | 12 +++--------- .../04/GHSA-8gx2-4pf6-cr9q/GHSA-8gx2-4pf6-cr9q.json | 12 +++--------- .../04/GHSA-8mv9-p6wj-fc88/GHSA-8mv9-p6wj-fc88.json | 12 +++--------- .../04/GHSA-8ppj-m7pv-xfgv/GHSA-8ppj-m7pv-xfgv.json | 8 ++------ .../04/GHSA-8q7c-xwf8-vm5r/GHSA-8q7c-xwf8-vm5r.json | 12 +++--------- .../04/GHSA-8qp8-665c-7xjf/GHSA-8qp8-665c-7xjf.json | 12 +++--------- .../04/GHSA-8rwx-4596-hpv5/GHSA-8rwx-4596-hpv5.json | 8 ++------ .../04/GHSA-8v2x-hr7h-j8qx/GHSA-8v2x-hr7h-j8qx.json | 12 +++--------- .../04/GHSA-8w9h-6c6m-8g5q/GHSA-8w9h-6c6m-8g5q.json | 12 +++--------- .../04/GHSA-8xj6-6239-7mwx/GHSA-8xj6-6239-7mwx.json | 8 ++------ .../04/GHSA-93h5-jmg6-mmph/GHSA-93h5-jmg6-mmph.json | 12 +++--------- .../04/GHSA-944q-gmcx-pp5j/GHSA-944q-gmcx-pp5j.json | 12 +++--------- .../04/GHSA-968h-qw7j-96w3/GHSA-968h-qw7j-96w3.json | 12 +++--------- .../04/GHSA-98j3-g9mx-9rxh/GHSA-98j3-g9mx-9rxh.json | 12 +++--------- .../04/GHSA-9cgp-mfwv-fgfw/GHSA-9cgp-mfwv-fgfw.json | 12 +++--------- .../04/GHSA-9cmf-77hw-89cq/GHSA-9cmf-77hw-89cq.json | 12 +++--------- .../04/GHSA-9gjm-q5qg-hm29/GHSA-9gjm-q5qg-hm29.json | 12 +++--------- .../04/GHSA-9h2x-7449-7c5m/GHSA-9h2x-7449-7c5m.json | 12 +++--------- .../04/GHSA-9qj7-66wc-7r4j/GHSA-9qj7-66wc-7r4j.json | 4 +--- .../04/GHSA-9qmw-v2p2-gwc6/GHSA-9qmw-v2p2-gwc6.json | 12 +++--------- .../04/GHSA-9w4c-j8rv-92hw/GHSA-9w4c-j8rv-92hw.json | 4 +--- .../04/GHSA-9w4v-gj4q-78jc/GHSA-9w4v-gj4q-78jc.json | 12 +++--------- .../04/GHSA-9wfg-2349-2vfw/GHSA-9wfg-2349-2vfw.json | 12 +++--------- .../04/GHSA-9wwc-xv4f-3h57/GHSA-9wwc-xv4f-3h57.json | 12 +++--------- .../04/GHSA-c246-vh69-9f94/GHSA-c246-vh69-9f94.json | 8 ++------ .../04/GHSA-c2p4-pf84-gvqv/GHSA-c2p4-pf84-gvqv.json | 8 ++------ .../04/GHSA-c36f-rpx7-9qq3/GHSA-c36f-rpx7-9qq3.json | 12 +++--------- .../04/GHSA-c5x8-wmm9-q2mc/GHSA-c5x8-wmm9-q2mc.json | 12 +++--------- .../04/GHSA-c6m7-4rrm-9vfv/GHSA-c6m7-4rrm-9vfv.json | 12 +++--------- .../04/GHSA-c6r9-fwjp-wq6g/GHSA-c6r9-fwjp-wq6g.json | 12 +++--------- .../04/GHSA-c6v6-cvxf-8hr8/GHSA-c6v6-cvxf-8hr8.json | 12 +++--------- .../04/GHSA-c993-69wp-v2c4/GHSA-c993-69wp-v2c4.json | 12 +++--------- .../04/GHSA-cc5r-5c3q-fh45/GHSA-cc5r-5c3q-fh45.json | 12 +++--------- .../04/GHSA-cc6v-6qwr-m66x/GHSA-cc6v-6qwr-m66x.json | 12 +++--------- .../04/GHSA-cf28-6v7w-9rcf/GHSA-cf28-6v7w-9rcf.json | 12 +++--------- .../04/GHSA-cg58-pmcc-63vj/GHSA-cg58-pmcc-63vj.json | 12 +++--------- .../04/GHSA-cgvr-863q-564c/GHSA-cgvr-863q-564c.json | 8 ++------ .../04/GHSA-cjpf-wj6v-f529/GHSA-cjpf-wj6v-f529.json | 8 ++------ .../04/GHSA-cp69-hrg6-gmgh/GHSA-cp69-hrg6-gmgh.json | 12 +++--------- .../04/GHSA-cpgf-j9v7-ww54/GHSA-cpgf-j9v7-ww54.json | 12 +++--------- .../04/GHSA-cpj4-3r8w-83gx/GHSA-cpj4-3r8w-83gx.json | 12 +++--------- .../04/GHSA-cqc6-fxcv-hqmx/GHSA-cqc6-fxcv-hqmx.json | 12 +++--------- .../04/GHSA-cqf6-wpgm-m6gf/GHSA-cqf6-wpgm-m6gf.json | 12 +++--------- .../04/GHSA-crx7-hrf2-c28r/GHSA-crx7-hrf2-c28r.json | 12 +++--------- .../04/GHSA-f2r6-2mvm-7f46/GHSA-f2r6-2mvm-7f46.json | 12 +++--------- .../04/GHSA-f5h7-rm4x-whwq/GHSA-f5h7-rm4x-whwq.json | 12 +++--------- .../04/GHSA-f7mm-qr3m-2g22/GHSA-f7mm-qr3m-2g22.json | 12 +++--------- .../04/GHSA-f879-gmxv-6jv3/GHSA-f879-gmxv-6jv3.json | 8 ++------ .../04/GHSA-f8j6-4qph-j87f/GHSA-f8j6-4qph-j87f.json | 12 +++--------- .../04/GHSA-ff3x-v55h-wqx3/GHSA-ff3x-v55h-wqx3.json | 12 +++--------- .../04/GHSA-ff8f-mh53-xcq3/GHSA-ff8f-mh53-xcq3.json | 12 +++--------- .../04/GHSA-fjqq-wrxc-5qvx/GHSA-fjqq-wrxc-5qvx.json | 12 +++--------- .../04/GHSA-fp4j-7xhw-chrp/GHSA-fp4j-7xhw-chrp.json | 12 +++--------- .../04/GHSA-fp5p-25cc-hp7j/GHSA-fp5p-25cc-hp7j.json | 12 +++--------- .../04/GHSA-fpgc-v2fw-7f2p/GHSA-fpgc-v2fw-7f2p.json | 12 +++--------- .../04/GHSA-fv44-gp5g-m9h3/GHSA-fv44-gp5g-m9h3.json | 12 +++--------- .../04/GHSA-fwj2-255f-vxp9/GHSA-fwj2-255f-vxp9.json | 12 +++--------- .../04/GHSA-fx6v-xw9x-mhc6/GHSA-fx6v-xw9x-mhc6.json | 12 +++--------- .../04/GHSA-g2m2-6496-28r3/GHSA-g2m2-6496-28r3.json | 12 +++--------- .../04/GHSA-g4c4-m88p-5c36/GHSA-g4c4-m88p-5c36.json | 12 +++--------- .../04/GHSA-g4jw-q5gf-chg4/GHSA-g4jw-q5gf-chg4.json | 12 +++--------- .../04/GHSA-g4q6-2x5x-hq8g/GHSA-g4q6-2x5x-hq8g.json | 12 +++--------- .../04/GHSA-g543-9hw2-5g6m/GHSA-g543-9hw2-5g6m.json | 8 ++------ .../04/GHSA-g5qc-7g3j-pw49/GHSA-g5qc-7g3j-pw49.json | 8 ++------ .../04/GHSA-g5xj-mf6c-gv67/GHSA-g5xj-mf6c-gv67.json | 12 +++--------- .../04/GHSA-g84j-7f78-5x36/GHSA-g84j-7f78-5x36.json | 4 +--- .../04/GHSA-g87x-9qg3-cfrp/GHSA-g87x-9qg3-cfrp.json | 4 +--- .../04/GHSA-g89x-ccw9-3vqf/GHSA-g89x-ccw9-3vqf.json | 12 +++--------- .../04/GHSA-g8xp-6gmf-pqc7/GHSA-g8xp-6gmf-pqc7.json | 12 +++--------- .../04/GHSA-gcch-vrjw-qccj/GHSA-gcch-vrjw-qccj.json | 8 ++------ .../04/GHSA-gfv9-5vjp-wj62/GHSA-gfv9-5vjp-wj62.json | 12 +++--------- .../04/GHSA-gghw-gggj-qg54/GHSA-gghw-gggj-qg54.json | 12 +++--------- .../04/GHSA-ghgp-g378-8742/GHSA-ghgp-g378-8742.json | 12 +++--------- .../04/GHSA-ghqp-x4m8-m9f7/GHSA-ghqp-x4m8-m9f7.json | 12 +++--------- .../04/GHSA-ghxr-vr43-7gg4/GHSA-ghxr-vr43-7gg4.json | 12 +++--------- .../04/GHSA-gjj5-323w-prhc/GHSA-gjj5-323w-prhc.json | 12 +++--------- .../04/GHSA-gp45-h6r6-g3h7/GHSA-gp45-h6r6-g3h7.json | 12 +++--------- .../04/GHSA-gqc9-fvxf-ch49/GHSA-gqc9-fvxf-ch49.json | 8 ++------ .../04/GHSA-gqxw-w7hq-j9fr/GHSA-gqxw-w7hq-j9fr.json | 12 +++--------- .../04/GHSA-h268-8cw3-p2xg/GHSA-h268-8cw3-p2xg.json | 12 +++--------- .../04/GHSA-h2mv-7266-r4gv/GHSA-h2mv-7266-r4gv.json | 12 +++--------- .../04/GHSA-h4wm-jrw8-h7r4/GHSA-h4wm-jrw8-h7r4.json | 12 +++--------- .../04/GHSA-h7gq-ccp9-7hgx/GHSA-h7gq-ccp9-7hgx.json | 12 +++--------- .../04/GHSA-h7h5-28w5-gr84/GHSA-h7h5-28w5-gr84.json | 12 +++--------- .../04/GHSA-h8rm-hh3j-prg6/GHSA-h8rm-hh3j-prg6.json | 12 +++--------- .../04/GHSA-hc22-c689-gw4r/GHSA-hc22-c689-gw4r.json | 8 ++------ .../04/GHSA-hff4-446w-6w6j/GHSA-hff4-446w-6w6j.json | 12 +++--------- .../04/GHSA-hg8p-7r5h-9pfp/GHSA-hg8p-7r5h-9pfp.json | 8 ++------ .../04/GHSA-hhph-jxcg-589h/GHSA-hhph-jxcg-589h.json | 12 +++--------- .../04/GHSA-hjf4-6f96-j975/GHSA-hjf4-6f96-j975.json | 12 +++--------- .../04/GHSA-hjgf-wjp7-2h46/GHSA-hjgf-wjp7-2h46.json | 12 +++--------- .../04/GHSA-hm4q-jhq3-x3jc/GHSA-hm4q-jhq3-x3jc.json | 12 +++--------- .../04/GHSA-hw95-r563-xw3w/GHSA-hw95-r563-xw3w.json | 8 ++------ .../04/GHSA-hx5v-g4q9-47jf/GHSA-hx5v-g4q9-47jf.json | 12 +++--------- .../04/GHSA-hxrh-xvf9-9m4h/GHSA-hxrh-xvf9-9m4h.json | 12 +++--------- .../04/GHSA-j29v-fw26-7w36/GHSA-j29v-fw26-7w36.json | 12 +++--------- .../04/GHSA-j2vj-gfj2-r9pm/GHSA-j2vj-gfj2-r9pm.json | 12 +++--------- .../04/GHSA-j32q-7w48-vjx5/GHSA-j32q-7w48-vjx5.json | 12 +++--------- .../04/GHSA-j3wc-p3gm-2hvr/GHSA-j3wc-p3gm-2hvr.json | 12 +++--------- .../04/GHSA-j7p5-665x-j6hw/GHSA-j7p5-665x-j6hw.json | 12 +++--------- .../04/GHSA-j7wr-9pp4-rh9g/GHSA-j7wr-9pp4-rh9g.json | 12 +++--------- .../04/GHSA-j8qf-3qcm-gp2f/GHSA-j8qf-3qcm-gp2f.json | 8 ++------ .../04/GHSA-j959-4486-mmwm/GHSA-j959-4486-mmwm.json | 12 +++--------- .../04/GHSA-j9xv-rfg5-qr77/GHSA-j9xv-rfg5-qr77.json | 12 +++--------- .../04/GHSA-jcr8-6hcp-xjf9/GHSA-jcr8-6hcp-xjf9.json | 12 +++--------- .../04/GHSA-jh5c-8fq7-5f53/GHSA-jh5c-8fq7-5f53.json | 12 +++--------- .../04/GHSA-jh7r-26mr-38jg/GHSA-jh7r-26mr-38jg.json | 12 +++--------- .../04/GHSA-jqff-mwp3-mx4x/GHSA-jqff-mwp3-mx4x.json | 8 ++------ .../04/GHSA-jr28-ffrh-246w/GHSA-jr28-ffrh-246w.json | 8 ++------ .../04/GHSA-jx5f-jm5c-889j/GHSA-jx5f-jm5c-889j.json | 12 +++--------- .../04/GHSA-jx9w-xpj8-hj9j/GHSA-jx9w-xpj8-hj9j.json | 12 +++--------- .../04/GHSA-jxhx-rppc-gf4x/GHSA-jxhx-rppc-gf4x.json | 12 +++--------- .../04/GHSA-m23p-w4r4-w6qp/GHSA-m23p-w4r4-w6qp.json | 8 ++------ .../04/GHSA-mcvw-pw2f-v47r/GHSA-mcvw-pw2f-v47r.json | 12 +++--------- .../04/GHSA-mg4c-x8gf-gw7m/GHSA-mg4c-x8gf-gw7m.json | 8 ++------ .../04/GHSA-mhc5-27v4-8w9g/GHSA-mhc5-27v4-8w9g.json | 12 +++--------- .../04/GHSA-mhfj-c75x-2vfv/GHSA-mhfj-c75x-2vfv.json | 12 +++--------- .../04/GHSA-mhv2-672p-f8h4/GHSA-mhv2-672p-f8h4.json | 12 +++--------- .../04/GHSA-mmjh-9xp6-78rw/GHSA-mmjh-9xp6-78rw.json | 12 +++--------- .../04/GHSA-p2v3-9pr5-prv3/GHSA-p2v3-9pr5-prv3.json | 12 +++--------- .../04/GHSA-p353-rwc3-5p7v/GHSA-p353-rwc3-5p7v.json | 12 +++--------- .../04/GHSA-p449-wm4r-3ph2/GHSA-p449-wm4r-3ph2.json | 12 +++--------- .../04/GHSA-p4fm-7w3j-8656/GHSA-p4fm-7w3j-8656.json | 8 ++------ .../04/GHSA-p72x-wpgm-6rr5/GHSA-p72x-wpgm-6rr5.json | 12 +++--------- .../04/GHSA-p894-4749-f3jh/GHSA-p894-4749-f3jh.json | 8 ++------ .../04/GHSA-pc2q-8rgh-2998/GHSA-pc2q-8rgh-2998.json | 12 +++--------- .../04/GHSA-pc6j-99x3-m7cv/GHSA-pc6j-99x3-m7cv.json | 8 ++------ .../04/GHSA-pcpj-8874-w5qg/GHSA-pcpj-8874-w5qg.json | 12 +++--------- .../04/GHSA-pg9f-hrgx-gm27/GHSA-pg9f-hrgx-gm27.json | 8 ++------ .../04/GHSA-pgc8-5qmg-9q4q/GHSA-pgc8-5qmg-9q4q.json | 8 ++------ .../04/GHSA-pjgq-j3j9-v9h8/GHSA-pjgq-j3j9-v9h8.json | 12 +++--------- .../04/GHSA-pv6r-rmp3-mw8c/GHSA-pv6r-rmp3-mw8c.json | 12 +++--------- .../04/GHSA-pw85-4jwp-m329/GHSA-pw85-4jwp-m329.json | 12 +++--------- .../04/GHSA-pw8g-g9xc-q9hq/GHSA-pw8g-g9xc-q9hq.json | 8 ++------ .../04/GHSA-q49p-4xg9-93q2/GHSA-q49p-4xg9-93q2.json | 12 +++--------- .../04/GHSA-q4w7-77p6-6mqm/GHSA-q4w7-77p6-6mqm.json | 12 +++--------- .../04/GHSA-q4x9-xj49-44vc/GHSA-q4x9-xj49-44vc.json | 12 +++--------- .../04/GHSA-q6f4-32m8-8m5c/GHSA-q6f4-32m8-8m5c.json | 8 ++------ .../04/GHSA-q6fr-pmm3-pp3p/GHSA-q6fr-pmm3-pp3p.json | 12 +++--------- .../04/GHSA-q6j8-f7cj-r8m7/GHSA-q6j8-f7cj-r8m7.json | 12 +++--------- .../04/GHSA-q953-qm86-wxwh/GHSA-q953-qm86-wxwh.json | 8 ++------ .../04/GHSA-qc6j-jv93-f7h8/GHSA-qc6j-jv93-f7h8.json | 12 +++--------- .../04/GHSA-qgjx-vfjf-jmpv/GHSA-qgjx-vfjf-jmpv.json | 12 +++--------- .../04/GHSA-qj6h-mm42-877r/GHSA-qj6h-mm42-877r.json | 12 +++--------- .../04/GHSA-qmxf-7p2j-5hvr/GHSA-qmxf-7p2j-5hvr.json | 12 +++--------- .../04/GHSA-qp43-f5rv-7r4g/GHSA-qp43-f5rv-7r4g.json | 8 ++------ .../04/GHSA-qpq7-jj5h-mc5q/GHSA-qpq7-jj5h-mc5q.json | 12 +++--------- .../04/GHSA-qq2w-99pw-p7w5/GHSA-qq2w-99pw-p7w5.json | 12 +++--------- .../04/GHSA-qqgf-6922-rxxc/GHSA-qqgf-6922-rxxc.json | 12 +++--------- .../04/GHSA-qr26-8475-q4qg/GHSA-qr26-8475-q4qg.json | 8 ++------ .../04/GHSA-qr2h-xwqr-8rf4/GHSA-qr2h-xwqr-8rf4.json | 12 +++--------- .../04/GHSA-qr4x-6cmr-2rc9/GHSA-qr4x-6cmr-2rc9.json | 12 +++--------- .../04/GHSA-qrp8-65v4-pc63/GHSA-qrp8-65v4-pc63.json | 12 +++--------- .../04/GHSA-qvqg-r2p8-5rp6/GHSA-qvqg-r2p8-5rp6.json | 12 +++--------- .../04/GHSA-r3xr-78mf-93cp/GHSA-r3xr-78mf-93cp.json | 8 ++------ .../04/GHSA-r8q3-xj3m-hq8q/GHSA-r8q3-xj3m-hq8q.json | 12 +++--------- .../04/GHSA-r9vf-x8x5-4p2c/GHSA-r9vf-x8x5-4p2c.json | 8 ++------ .../04/GHSA-rcmv-9x8c-5v8x/GHSA-rcmv-9x8c-5v8x.json | 12 +++--------- .../04/GHSA-rcrv-mvrm-ghx8/GHSA-rcrv-mvrm-ghx8.json | 12 +++--------- .../04/GHSA-rfhr-47j6-q56h/GHSA-rfhr-47j6-q56h.json | 12 +++--------- .../04/GHSA-rfvj-m3h5-jvf2/GHSA-rfvj-m3h5-jvf2.json | 12 +++--------- .../04/GHSA-rg5q-w7qj-gw3c/GHSA-rg5q-w7qj-gw3c.json | 12 +++--------- .../04/GHSA-rhg2-2jf9-5p9w/GHSA-rhg2-2jf9-5p9w.json | 12 +++--------- .../04/GHSA-rmv6-xq8c-gmp5/GHSA-rmv6-xq8c-gmp5.json | 12 +++--------- .../04/GHSA-rqvp-h98w-9g7q/GHSA-rqvp-h98w-9g7q.json | 12 +++--------- .../04/GHSA-rr96-8f9f-cppq/GHSA-rr96-8f9f-cppq.json | 12 +++--------- .../04/GHSA-rrp2-4g3f-vv2g/GHSA-rrp2-4g3f-vv2g.json | 12 +++--------- .../04/GHSA-rrwg-cv62-hrxc/GHSA-rrwg-cv62-hrxc.json | 12 +++--------- .../04/GHSA-rv84-9j9f-rfxp/GHSA-rv84-9j9f-rfxp.json | 12 +++--------- .../04/GHSA-rw75-g77q-qm9m/GHSA-rw75-g77q-qm9m.json | 12 +++--------- .../04/GHSA-rwg3-w9r2-cx93/GHSA-rwg3-w9r2-cx93.json | 12 +++--------- .../04/GHSA-v2hf-gpg2-hm9f/GHSA-v2hf-gpg2-hm9f.json | 8 ++------ .../04/GHSA-v5r7-gp5q-w3fh/GHSA-v5r7-gp5q-w3fh.json | 12 +++--------- .../04/GHSA-v5xr-gjjf-rhqc/GHSA-v5xr-gjjf-rhqc.json | 12 +++--------- .../04/GHSA-v78w-74x8-ppvv/GHSA-v78w-74x8-ppvv.json | 12 +++--------- .../04/GHSA-v935-c7vg-r239/GHSA-v935-c7vg-r239.json | 12 +++--------- .../04/GHSA-vcc9-7w4c-j47m/GHSA-vcc9-7w4c-j47m.json | 12 +++--------- .../04/GHSA-vf95-35wr-4pfv/GHSA-vf95-35wr-4pfv.json | 12 +++--------- .../04/GHSA-vfjp-q2j5-26qc/GHSA-vfjp-q2j5-26qc.json | 12 +++--------- .../04/GHSA-vwvq-g57j-fg4q/GHSA-vwvq-g57j-fg4q.json | 12 +++--------- .../04/GHSA-w6p4-h264-pgp8/GHSA-w6p4-h264-pgp8.json | 12 +++--------- .../04/GHSA-w84c-j5hg-h3mx/GHSA-w84c-j5hg-h3mx.json | 12 +++--------- .../04/GHSA-w84v-vmqq-p8vc/GHSA-w84v-vmqq-p8vc.json | 8 ++------ .../04/GHSA-w8j7-864p-92c6/GHSA-w8j7-864p-92c6.json | 8 ++------ .../04/GHSA-w98r-ffjg-68q7/GHSA-w98r-ffjg-68q7.json | 12 +++--------- .../04/GHSA-wf7x-gjvh-m5r3/GHSA-wf7x-gjvh-m5r3.json | 12 +++--------- .../04/GHSA-wfc5-6r3q-mv26/GHSA-wfc5-6r3q-mv26.json | 12 +++--------- .../04/GHSA-wjrq-3hqr-vp6g/GHSA-wjrq-3hqr-vp6g.json | 12 +++--------- .../04/GHSA-wm5h-c9q7-gpcx/GHSA-wm5h-c9q7-gpcx.json | 12 +++--------- .../04/GHSA-wpx6-f5m4-qjwq/GHSA-wpx6-f5m4-qjwq.json | 8 ++------ .../04/GHSA-wvcr-r9cr-2xrh/GHSA-wvcr-r9cr-2xrh.json | 12 +++--------- .../04/GHSA-x36q-879q-h59v/GHSA-x36q-879q-h59v.json | 12 +++--------- .../04/GHSA-x4pg-475r-rqf2/GHSA-x4pg-475r-rqf2.json | 12 +++--------- .../04/GHSA-x5w8-45xj-42q9/GHSA-x5w8-45xj-42q9.json | 8 ++------ .../04/GHSA-x62x-33c9-999r/GHSA-x62x-33c9-999r.json | 12 +++--------- .../04/GHSA-x6p9-5hpx-q6qq/GHSA-x6p9-5hpx-q6qq.json | 12 +++--------- .../04/GHSA-x85h-h5r6-5rh8/GHSA-x85h-h5r6-5rh8.json | 12 +++--------- .../04/GHSA-x8q9-wj85-wrcw/GHSA-x8q9-wj85-wrcw.json | 12 +++--------- .../04/GHSA-xcgv-26c6-gm5c/GHSA-xcgv-26c6-gm5c.json | 12 +++--------- .../04/GHSA-xf68-pxg8-qfjf/GHSA-xf68-pxg8-qfjf.json | 8 ++------ .../04/GHSA-xgmx-762m-r89c/GHSA-xgmx-762m-r89c.json | 12 +++--------- .../04/GHSA-xj5p-xp2f-36x3/GHSA-xj5p-xp2f-36x3.json | 12 +++--------- .../04/GHSA-xjvg-3p2h-qwh5/GHSA-xjvg-3p2h-qwh5.json | 12 +++--------- .../04/GHSA-xpmv-55r3-vww6/GHSA-xpmv-55r3-vww6.json | 12 +++--------- .../04/GHSA-xqff-x4hf-x674/GHSA-xqff-x4hf-x674.json | 12 +++--------- .../04/GHSA-xv6r-hw9g-7g96/GHSA-xv6r-hw9g-7g96.json | 12 +++--------- .../04/GHSA-xwcj-5r58-c5mv/GHSA-xwcj-5r58-c5mv.json | 12 +++--------- .../04/GHSA-xxv2-wv26-x9v9/GHSA-xxv2-wv26-x9v9.json | 12 +++--------- .../05/GHSA-2277-2f9f-59cc/GHSA-2277-2f9f-59cc.json | 4 +--- .../05/GHSA-233h-674c-hxmw/GHSA-233h-674c-hxmw.json | 8 ++------ .../05/GHSA-24q8-rjjm-c7vv/GHSA-24q8-rjjm-c7vv.json | 4 +--- .../05/GHSA-289p-hp9m-rp88/GHSA-289p-hp9m-rp88.json | 4 +--- .../05/GHSA-2c53-hhhc-ffc7/GHSA-2c53-hhhc-ffc7.json | 12 +++--------- .../05/GHSA-2f6p-fvp2-42p6/GHSA-2f6p-fvp2-42p6.json | 12 +++--------- .../05/GHSA-2fmg-qfp6-p727/GHSA-2fmg-qfp6-p727.json | 12 +++--------- .../05/GHSA-2gcq-qrr4-wc8f/GHSA-2gcq-qrr4-wc8f.json | 8 ++------ .../05/GHSA-2jc5-w7hj-r4r8/GHSA-2jc5-w7hj-r4r8.json | 12 +++--------- .../05/GHSA-2jhm-h3h6-8pq5/GHSA-2jhm-h3h6-8pq5.json | 12 +++--------- .../05/GHSA-2mfc-2chj-fv4h/GHSA-2mfc-2chj-fv4h.json | 8 ++------ .../05/GHSA-2ppg-66j5-9h8g/GHSA-2ppg-66j5-9h8g.json | 12 +++--------- .../05/GHSA-2qfq-4hw9-7rpg/GHSA-2qfq-4hw9-7rpg.json | 12 +++--------- .../05/GHSA-2qp6-q6vf-5x4c/GHSA-2qp6-q6vf-5x4c.json | 12 +++--------- .../05/GHSA-2rp2-rw4v-352c/GHSA-2rp2-rw4v-352c.json | 4 +--- .../05/GHSA-2vph-2j96-4ghq/GHSA-2vph-2j96-4ghq.json | 4 +--- .../05/GHSA-2x7q-r588-836j/GHSA-2x7q-r588-836j.json | 8 ++------ .../05/GHSA-2xw2-mmrg-qmgq/GHSA-2xw2-mmrg-qmgq.json | 8 ++------ .../05/GHSA-33mp-cm7f-r29g/GHSA-33mp-cm7f-r29g.json | 8 ++------ .../05/GHSA-33qq-wfvm-3749/GHSA-33qq-wfvm-3749.json | 12 +++--------- .../05/GHSA-347c-p8v4-7hp9/GHSA-347c-p8v4-7hp9.json | 8 ++------ .../05/GHSA-356r-hh49-wcj9/GHSA-356r-hh49-wcj9.json | 12 +++--------- .../05/GHSA-3584-m2p9-p3w8/GHSA-3584-m2p9-p3w8.json | 12 +++--------- .../05/GHSA-368p-hj7r-f6v7/GHSA-368p-hj7r-f6v7.json | 12 +++--------- .../05/GHSA-374g-65fj-w32x/GHSA-374g-65fj-w32x.json | 12 +++--------- .../05/GHSA-38rq-33wv-8xmv/GHSA-38rq-33wv-8xmv.json | 8 ++------ .../05/GHSA-38w5-3vjp-rwhg/GHSA-38w5-3vjp-rwhg.json | 8 ++------ .../05/GHSA-3997-6wvq-mg36/GHSA-3997-6wvq-mg36.json | 8 ++------ .../05/GHSA-39r5-v68g-9x33/GHSA-39r5-v68g-9x33.json | 8 ++------ .../05/GHSA-39rh-q4pp-qc6p/GHSA-39rh-q4pp-qc6p.json | 8 ++------ .../05/GHSA-3c6j-x3h2-c2j2/GHSA-3c6j-x3h2-c2j2.json | 12 +++--------- .../05/GHSA-3f7r-vf78-cvh3/GHSA-3f7r-vf78-cvh3.json | 8 ++------ .../05/GHSA-3hh4-vmx3-9xp9/GHSA-3hh4-vmx3-9xp9.json | 8 ++------ .../05/GHSA-3mwh-xgcp-8q55/GHSA-3mwh-xgcp-8q55.json | 12 +++--------- .../05/GHSA-3rfj-rp8x-285j/GHSA-3rfj-rp8x-285j.json | 4 +--- .../05/GHSA-3rpg-jfvw-x748/GHSA-3rpg-jfvw-x748.json | 12 +++--------- .../05/GHSA-3v57-962h-6rcp/GHSA-3v57-962h-6rcp.json | 12 +++--------- .../05/GHSA-3x74-wgfj-fp94/GHSA-3x74-wgfj-fp94.json | 8 ++------ .../05/GHSA-424j-x9c2-7hg5/GHSA-424j-x9c2-7hg5.json | 12 +++--------- .../05/GHSA-43wv-9cr7-p3pg/GHSA-43wv-9cr7-p3pg.json | 4 +--- .../05/GHSA-483f-26r4-2fvr/GHSA-483f-26r4-2fvr.json | 4 +--- .../05/GHSA-4853-rc4g-fhg8/GHSA-4853-rc4g-fhg8.json | 12 +++--------- .../05/GHSA-4c4v-9xr2-899m/GHSA-4c4v-9xr2-899m.json | 12 +++--------- .../05/GHSA-4cpc-j329-wv69/GHSA-4cpc-j329-wv69.json | 12 +++--------- .../05/GHSA-4ffh-54c8-m8qq/GHSA-4ffh-54c8-m8qq.json | 12 +++--------- .../05/GHSA-4fg3-3f6v-rq8c/GHSA-4fg3-3f6v-rq8c.json | 8 ++------ .../05/GHSA-4fq4-48p4-4c29/GHSA-4fq4-48p4-4c29.json | 12 +++--------- .../05/GHSA-4ghg-p426-jc5w/GHSA-4ghg-p426-jc5w.json | 4 +--- .../05/GHSA-4gvj-r54v-28c6/GHSA-4gvj-r54v-28c6.json | 12 +++--------- .../05/GHSA-4p72-53xh-hr8g/GHSA-4p72-53xh-hr8g.json | 12 +++--------- .../05/GHSA-4r3v-pr3q-qvw9/GHSA-4r3v-pr3q-qvw9.json | 8 ++------ .../05/GHSA-4rmw-pmhj-w226/GHSA-4rmw-pmhj-w226.json | 12 +++--------- .../05/GHSA-4vw6-7m58-5hqv/GHSA-4vw6-7m58-5hqv.json | 8 ++------ .../05/GHSA-4xcq-53qf-r7r5/GHSA-4xcq-53qf-r7r5.json | 12 +++--------- .../05/GHSA-4xqv-wh6m-q95v/GHSA-4xqv-wh6m-q95v.json | 8 ++------ .../05/GHSA-52qc-8hxh-757m/GHSA-52qc-8hxh-757m.json | 12 +++--------- .../05/GHSA-559w-3846-g7jq/GHSA-559w-3846-g7jq.json | 12 +++--------- .../05/GHSA-55c9-4ccx-936v/GHSA-55c9-4ccx-936v.json | 12 +++--------- .../05/GHSA-585q-pfmf-wx3m/GHSA-585q-pfmf-wx3m.json | 12 +++--------- .../05/GHSA-586v-g7r5-mhgp/GHSA-586v-g7r5-mhgp.json | 12 +++--------- .../05/GHSA-5f3v-3wp6-f5wm/GHSA-5f3v-3wp6-f5wm.json | 4 +--- .../05/GHSA-5fm5-f5m7-88f4/GHSA-5fm5-f5m7-88f4.json | 12 +++--------- .../05/GHSA-5g3m-ghqj-8gwf/GHSA-5g3m-ghqj-8gwf.json | 8 ++------ .../05/GHSA-5h6f-94qc-p3v7/GHSA-5h6f-94qc-p3v7.json | 4 +--- .../05/GHSA-5hg9-992p-865c/GHSA-5hg9-992p-865c.json | 12 +++--------- .../05/GHSA-5j4v-g55f-qpxj/GHSA-5j4v-g55f-qpxj.json | 4 +--- .../05/GHSA-5pxr-wcq7-hjpx/GHSA-5pxr-wcq7-hjpx.json | 12 +++--------- .../05/GHSA-5v5x-gcg4-wrf3/GHSA-5v5x-gcg4-wrf3.json | 8 ++------ .../05/GHSA-5vc9-3jgc-ch89/GHSA-5vc9-3jgc-ch89.json | 4 +--- .../05/GHSA-5wcp-726c-4jpf/GHSA-5wcp-726c-4jpf.json | 8 ++------ .../05/GHSA-5wm3-vq8v-xjjj/GHSA-5wm3-vq8v-xjjj.json | 4 +--- .../05/GHSA-5x6x-jmv8-vh4f/GHSA-5x6x-jmv8-vh4f.json | 12 +++--------- .../05/GHSA-625f-424x-6j4w/GHSA-625f-424x-6j4w.json | 8 ++------ .../05/GHSA-666m-7m3w-f97c/GHSA-666m-7m3w-f97c.json | 12 +++--------- .../05/GHSA-6895-cxrm-x3p4/GHSA-6895-cxrm-x3p4.json | 12 +++--------- .../05/GHSA-6936-rmm6-9pq6/GHSA-6936-rmm6-9pq6.json | 12 +++--------- .../05/GHSA-6c92-g9wf-978j/GHSA-6c92-g9wf-978j.json | 4 +--- .../05/GHSA-6cmx-4cq4-q68g/GHSA-6cmx-4cq4-q68g.json | 12 +++--------- .../05/GHSA-6cw8-rf2j-hfqv/GHSA-6cw8-rf2j-hfqv.json | 8 ++------ .../05/GHSA-6fvc-pc2f-vcp7/GHSA-6fvc-pc2f-vcp7.json | 12 +++--------- .../05/GHSA-6fxx-g64m-phpw/GHSA-6fxx-g64m-phpw.json | 12 +++--------- .../05/GHSA-6gvc-rc8p-3485/GHSA-6gvc-rc8p-3485.json | 12 +++--------- .../05/GHSA-6rjj-pr45-qcv8/GHSA-6rjj-pr45-qcv8.json | 12 +++--------- .../05/GHSA-6x4g-3g6f-c363/GHSA-6x4g-3g6f-c363.json | 8 ++------ .../05/GHSA-6xfq-7wh8-vrjj/GHSA-6xfq-7wh8-vrjj.json | 8 ++------ .../05/GHSA-6xpw-chm5-x9v3/GHSA-6xpw-chm5-x9v3.json | 4 +--- .../05/GHSA-729f-wr46-h749/GHSA-729f-wr46-h749.json | 12 +++--------- .../05/GHSA-72g7-hpv6-j389/GHSA-72g7-hpv6-j389.json | 8 ++------ .../05/GHSA-753f-5cv5-8fxc/GHSA-753f-5cv5-8fxc.json | 12 +++--------- .../05/GHSA-755m-3mmw-86vc/GHSA-755m-3mmw-86vc.json | 12 +++--------- .../05/GHSA-76r8-wr7m-q22f/GHSA-76r8-wr7m-q22f.json | 12 +++--------- .../05/GHSA-77f6-gh77-3f4f/GHSA-77f6-gh77-3f4f.json | 12 +++--------- .../05/GHSA-7cj4-x7wr-qf2p/GHSA-7cj4-x7wr-qf2p.json | 4 +--- .../05/GHSA-7frm-g428-7p37/GHSA-7frm-g428-7p37.json | 8 ++------ .../05/GHSA-7gqf-f3cw-8pvr/GHSA-7gqf-f3cw-8pvr.json | 8 ++------ .../05/GHSA-7p3m-596h-f4vx/GHSA-7p3m-596h-f4vx.json | 8 ++------ .../05/GHSA-7p43-3rw5-j59j/GHSA-7p43-3rw5-j59j.json | 12 +++--------- .../05/GHSA-7pp4-qxpv-rc2r/GHSA-7pp4-qxpv-rc2r.json | 12 +++--------- .../05/GHSA-7pq8-3c67-xq6r/GHSA-7pq8-3c67-xq6r.json | 12 +++--------- .../05/GHSA-7qj7-wvx2-qxqv/GHSA-7qj7-wvx2-qxqv.json | 8 ++------ .../05/GHSA-7vpq-xcrf-9qvc/GHSA-7vpq-xcrf-9qvc.json | 12 +++--------- .../05/GHSA-82cp-p788-5r5g/GHSA-82cp-p788-5r5g.json | 12 +++--------- .../05/GHSA-82q3-wxfg-rg6w/GHSA-82q3-wxfg-rg6w.json | 12 +++--------- .../05/GHSA-834g-xv52-7q24/GHSA-834g-xv52-7q24.json | 12 +++--------- .../05/GHSA-835c-5hqw-748h/GHSA-835c-5hqw-748h.json | 12 +++--------- .../05/GHSA-8372-62j2-5947/GHSA-8372-62j2-5947.json | 8 ++------ .../05/GHSA-8427-cq28-9xqm/GHSA-8427-cq28-9xqm.json | 12 +++--------- .../05/GHSA-857m-9c4p-fvf4/GHSA-857m-9c4p-fvf4.json | 4 +--- .../05/GHSA-858v-pcfh-p8xg/GHSA-858v-pcfh-p8xg.json | 8 ++------ .../05/GHSA-85p3-g932-hx25/GHSA-85p3-g932-hx25.json | 12 +++--------- .../05/GHSA-8743-86pf-fx3j/GHSA-8743-86pf-fx3j.json | 12 +++--------- .../05/GHSA-8793-frgg-7jvv/GHSA-8793-frgg-7jvv.json | 12 +++--------- .../05/GHSA-87g6-m2cw-w39m/GHSA-87g6-m2cw-w39m.json | 8 ++------ .../05/GHSA-87p9-xf94-p7qh/GHSA-87p9-xf94-p7qh.json | 8 ++------ .../05/GHSA-88vv-mqm2-ch6r/GHSA-88vv-mqm2-ch6r.json | 12 +++--------- .../05/GHSA-88xv-4j49-xfpj/GHSA-88xv-4j49-xfpj.json | 12 +++--------- .../05/GHSA-896p-r2jm-x733/GHSA-896p-r2jm-x733.json | 12 +++--------- .../05/GHSA-8crw-6mr7-v864/GHSA-8crw-6mr7-v864.json | 12 +++--------- .../05/GHSA-8fxq-6rpx-4cxp/GHSA-8fxq-6rpx-4cxp.json | 8 ++------ .../05/GHSA-8ggp-4pf2-5mgh/GHSA-8ggp-4pf2-5mgh.json | 12 +++--------- .../05/GHSA-8h22-fc39-v23w/GHSA-8h22-fc39-v23w.json | 4 +--- .../05/GHSA-8hvh-4cv6-h6v3/GHSA-8hvh-4cv6-h6v3.json | 8 ++------ .../05/GHSA-8qxp-fp5j-5wxj/GHSA-8qxp-fp5j-5wxj.json | 8 ++------ .../05/GHSA-8rhj-vff2-27m7/GHSA-8rhj-vff2-27m7.json | 4 +--- .../05/GHSA-8rpf-h452-4m5v/GHSA-8rpf-h452-4m5v.json | 12 +++--------- .../05/GHSA-8v8j-5gpm-fvqv/GHSA-8v8j-5gpm-fvqv.json | 12 +++--------- .../05/GHSA-8wjf-7pjq-2695/GHSA-8wjf-7pjq-2695.json | 8 ++------ .../05/GHSA-8xr9-2r57-gg3h/GHSA-8xr9-2r57-gg3h.json | 12 +++--------- .../05/GHSA-924w-c7p6-hr3m/GHSA-924w-c7p6-hr3m.json | 8 ++------ .../05/GHSA-92gg-745w-464g/GHSA-92gg-745w-464g.json | 8 ++------ .../05/GHSA-93vf-4x6g-q64v/GHSA-93vf-4x6g-q64v.json | 4 +--- .../05/GHSA-95fj-4hcc-xv2c/GHSA-95fj-4hcc-xv2c.json | 8 ++------ .../05/GHSA-95hf-gv4r-6jjr/GHSA-95hf-gv4r-6jjr.json | 12 +++--------- .../05/GHSA-99fc-5rrq-7p52/GHSA-99fc-5rrq-7p52.json | 12 +++--------- .../05/GHSA-9c96-fgqh-c568/GHSA-9c96-fgqh-c568.json | 12 +++--------- .../05/GHSA-9g5w-q3pg-gr6h/GHSA-9g5w-q3pg-gr6h.json | 8 ++------ .../05/GHSA-9g6r-m8wp-hqcv/GHSA-9g6r-m8wp-hqcv.json | 4 +--- .../05/GHSA-9gvv-jxrj-2xcq/GHSA-9gvv-jxrj-2xcq.json | 4 +--- .../05/GHSA-9hp3-3v8x-gvhx/GHSA-9hp3-3v8x-gvhx.json | 8 ++------ .../05/GHSA-9j29-262r-8x2g/GHSA-9j29-262r-8x2g.json | 12 +++--------- .../05/GHSA-9j84-h9rr-927m/GHSA-9j84-h9rr-927m.json | 8 ++------ .../05/GHSA-9m99-vg2m-7qx3/GHSA-9m99-vg2m-7qx3.json | 8 ++------ .../05/GHSA-9mw4-fp5g-pcj4/GHSA-9mw4-fp5g-pcj4.json | 12 +++--------- .../05/GHSA-9pmj-qm26-jq78/GHSA-9pmj-qm26-jq78.json | 12 +++--------- .../05/GHSA-9pq6-xhx5-v6v6/GHSA-9pq6-xhx5-v6v6.json | 12 +++--------- .../05/GHSA-9r7r-57fg-wq6g/GHSA-9r7r-57fg-wq6g.json | 8 ++------ .../05/GHSA-9vhh-7m5h-q2cr/GHSA-9vhh-7m5h-q2cr.json | 12 +++--------- .../05/GHSA-9w4c-84x2-59qr/GHSA-9w4c-84x2-59qr.json | 4 +--- .../05/GHSA-c4p9-w9gc-7j5g/GHSA-c4p9-w9gc-7j5g.json | 12 +++--------- .../05/GHSA-c4pp-v922-7762/GHSA-c4pp-v922-7762.json | 4 +--- .../05/GHSA-c5px-g3pm-787c/GHSA-c5px-g3pm-787c.json | 8 ++------ .../05/GHSA-c5r3-9g4g-r6vr/GHSA-c5r3-9g4g-r6vr.json | 12 +++--------- .../05/GHSA-c5x3-6f7p-wf2v/GHSA-c5x3-6f7p-wf2v.json | 8 ++------ .../05/GHSA-c5x8-pj63-gw3w/GHSA-c5x8-pj63-gw3w.json | 12 +++--------- .../05/GHSA-c67h-6v76-w36x/GHSA-c67h-6v76-w36x.json | 8 ++------ .../05/GHSA-c6rp-5g6v-mj33/GHSA-c6rp-5g6v-mj33.json | 8 ++------ .../05/GHSA-c87p-h49c-qjmw/GHSA-c87p-h49c-qjmw.json | 12 +++--------- .../05/GHSA-c8c8-39vg-wgv8/GHSA-c8c8-39vg-wgv8.json | 8 ++------ .../05/GHSA-c8fh-jgqg-54pp/GHSA-c8fh-jgqg-54pp.json | 12 +++--------- .../05/GHSA-c9p3-9xjw-7q44/GHSA-c9p3-9xjw-7q44.json | 12 +++--------- .../05/GHSA-ccgh-w4m9-4w8h/GHSA-ccgh-w4m9-4w8h.json | 12 +++--------- .../05/GHSA-cfhj-wmq5-2vrv/GHSA-cfhj-wmq5-2vrv.json | 12 +++--------- .../05/GHSA-cfp6-wq22-gv3m/GHSA-cfp6-wq22-gv3m.json | 12 +++--------- .../05/GHSA-cggp-hg98-4chw/GHSA-cggp-hg98-4chw.json | 12 +++--------- .../05/GHSA-cgxq-2fvp-jvhm/GHSA-cgxq-2fvp-jvhm.json | 8 ++------ .../05/GHSA-ch45-w4cr-rvq6/GHSA-ch45-w4cr-rvq6.json | 8 ++------ .../05/GHSA-chgx-prw4-5h2x/GHSA-chgx-prw4-5h2x.json | 8 ++------ .../05/GHSA-cj3p-fc7w-fx87/GHSA-cj3p-fc7w-fx87.json | 12 +++--------- .../05/GHSA-cjqm-pc48-gq5m/GHSA-cjqm-pc48-gq5m.json | 12 +++--------- .../05/GHSA-cph4-fpfm-5h8w/GHSA-cph4-fpfm-5h8w.json | 4 +--- .../05/GHSA-cpq2-ppf5-mpjp/GHSA-cpq2-ppf5-mpjp.json | 12 +++--------- .../05/GHSA-cwhg-93qp-c6pg/GHSA-cwhg-93qp-c6pg.json | 12 +++--------- .../05/GHSA-cxvc-q3cv-wf7w/GHSA-cxvc-q3cv-wf7w.json | 12 +++--------- .../05/GHSA-f435-r8xf-rc9w/GHSA-f435-r8xf-rc9w.json | 12 +++--------- .../05/GHSA-f488-435f-fcqm/GHSA-f488-435f-fcqm.json | 8 ++------ .../05/GHSA-f4xr-xwq3-38fv/GHSA-f4xr-xwq3-38fv.json | 8 ++------ .../05/GHSA-f5xq-vjwc-pqqj/GHSA-f5xq-vjwc-pqqj.json | 4 +--- .../05/GHSA-f6xv-m775-pjr5/GHSA-f6xv-m775-pjr5.json | 8 ++------ .../05/GHSA-f8jg-xpjx-j54w/GHSA-f8jg-xpjx-j54w.json | 8 ++------ .../05/GHSA-f9pr-qq7v-xmfj/GHSA-f9pr-qq7v-xmfj.json | 8 ++------ .../05/GHSA-fcc5-x3g2-xc22/GHSA-fcc5-x3g2-xc22.json | 4 +--- .../05/GHSA-ff95-chf7-569x/GHSA-ff95-chf7-569x.json | 12 +++--------- .../05/GHSA-ffvh-x5cw-294c/GHSA-ffvh-x5cw-294c.json | 12 +++--------- .../05/GHSA-fg6m-whg2-v39j/GHSA-fg6m-whg2-v39j.json | 12 +++--------- .../05/GHSA-fhhq-g694-vvfc/GHSA-fhhq-g694-vvfc.json | 12 +++--------- .../05/GHSA-fj2j-8cg9-vrj8/GHSA-fj2j-8cg9-vrj8.json | 12 +++--------- .../05/GHSA-fjmh-g39v-6932/GHSA-fjmh-g39v-6932.json | 4 +--- .../05/GHSA-fm3h-87mp-cxq6/GHSA-fm3h-87mp-cxq6.json | 12 +++--------- .../05/GHSA-fm45-4rvc-p4fj/GHSA-fm45-4rvc-p4fj.json | 12 +++--------- .../05/GHSA-fm67-vpp9-99gh/GHSA-fm67-vpp9-99gh.json | 12 +++--------- .../05/GHSA-fp7j-v4gh-x2v3/GHSA-fp7j-v4gh-x2v3.json | 8 ++------ .../05/GHSA-fpc4-498c-4336/GHSA-fpc4-498c-4336.json | 8 ++------ .../05/GHSA-fpqw-rp77-mwjr/GHSA-fpqw-rp77-mwjr.json | 12 +++--------- .../05/GHSA-fr6g-wwff-7837/GHSA-fr6g-wwff-7837.json | 8 ++------ .../05/GHSA-fvgh-hcc6-c2q5/GHSA-fvgh-hcc6-c2q5.json | 12 +++--------- .../05/GHSA-fw2x-mx3p-5gr5/GHSA-fw2x-mx3p-5gr5.json | 8 ++------ .../05/GHSA-fwp6-grrh-7hj9/GHSA-fwp6-grrh-7hj9.json | 8 ++------ .../05/GHSA-g2x3-q23p-vv87/GHSA-g2x3-q23p-vv87.json | 8 ++------ .../05/GHSA-g2xv-m9xg-ww4x/GHSA-g2xv-m9xg-ww4x.json | 12 +++--------- .../05/GHSA-g434-x599-83p4/GHSA-g434-x599-83p4.json | 12 +++--------- .../05/GHSA-g5gf-f7rm-39qx/GHSA-g5gf-f7rm-39qx.json | 4 +--- .../05/GHSA-g64w-x6g2-6j38/GHSA-g64w-x6g2-6j38.json | 12 +++--------- .../05/GHSA-g6jf-362c-2h5x/GHSA-g6jf-362c-2h5x.json | 8 ++------ .../05/GHSA-g82p-qfjv-w56j/GHSA-g82p-qfjv-w56j.json | 12 +++--------- .../05/GHSA-g854-fc3p-gq33/GHSA-g854-fc3p-gq33.json | 4 +--- .../05/GHSA-g897-jj46-x2pc/GHSA-g897-jj46-x2pc.json | 12 +++--------- .../05/GHSA-g8f7-67xp-2h72/GHSA-g8f7-67xp-2h72.json | 12 +++--------- .../05/GHSA-g8jr-rhv6-h7cj/GHSA-g8jr-rhv6-h7cj.json | 4 +--- .../05/GHSA-g97f-pgv6-f75q/GHSA-g97f-pgv6-f75q.json | 12 +++--------- .../05/GHSA-gc37-937w-g8g4/GHSA-gc37-937w-g8g4.json | 8 ++------ .../05/GHSA-gch3-m29m-g8x5/GHSA-gch3-m29m-g8x5.json | 12 +++--------- .../05/GHSA-gcmp-gqmg-54q5/GHSA-gcmp-gqmg-54q5.json | 12 +++--------- .../05/GHSA-gcx8-mff3-89cc/GHSA-gcx8-mff3-89cc.json | 8 ++------ .../05/GHSA-gg39-h2qq-j648/GHSA-gg39-h2qq-j648.json | 4 +--- .../05/GHSA-gg7x-fw4x-98xm/GHSA-gg7x-fw4x-98xm.json | 8 ++------ .../05/GHSA-gggv-m5vq-8f9m/GHSA-gggv-m5vq-8f9m.json | 8 ++------ .../05/GHSA-ggpp-fxg5-wp87/GHSA-ggpp-fxg5-wp87.json | 4 +--- .../05/GHSA-gjg7-84q3-g73j/GHSA-gjg7-84q3-g73j.json | 8 ++------ .../05/GHSA-gjg9-57mm-9w78/GHSA-gjg9-57mm-9w78.json | 12 +++--------- .../05/GHSA-gjrf-43fc-j4c9/GHSA-gjrf-43fc-j4c9.json | 8 ++------ .../05/GHSA-gqwc-24f2-x3gv/GHSA-gqwc-24f2-x3gv.json | 8 ++------ .../05/GHSA-grrv-5267-gqgj/GHSA-grrv-5267-gqgj.json | 8 ++------ .../05/GHSA-gvcw-4w76-f962/GHSA-gvcw-4w76-f962.json | 8 ++------ .../05/GHSA-gvwj-prfg-6229/GHSA-gvwj-prfg-6229.json | 12 +++--------- .../05/GHSA-gw77-j7h4-w4jv/GHSA-gw77-j7h4-w4jv.json | 4 +--- .../05/GHSA-gwfc-jmfj-45pc/GHSA-gwfc-jmfj-45pc.json | 8 ++------ .../05/GHSA-gwrq-4r66-jcc3/GHSA-gwrq-4r66-jcc3.json | 12 +++--------- .../05/GHSA-gxx3-mxqr-fwjw/GHSA-gxx3-mxqr-fwjw.json | 12 +++--------- .../05/GHSA-h338-j65w-58xw/GHSA-h338-j65w-58xw.json | 12 +++--------- .../05/GHSA-h394-hp3g-742p/GHSA-h394-hp3g-742p.json | 8 ++------ .../05/GHSA-h3cc-g2jj-55gh/GHSA-h3cc-g2jj-55gh.json | 8 ++------ .../05/GHSA-h42v-738f-q57f/GHSA-h42v-738f-q57f.json | 12 +++--------- .../05/GHSA-h436-m63j-57vj/GHSA-h436-m63j-57vj.json | 8 ++------ .../05/GHSA-h4c3-p5w7-477x/GHSA-h4c3-p5w7-477x.json | 12 +++--------- .../05/GHSA-h4q5-8rrj-hrj2/GHSA-h4q5-8rrj-hrj2.json | 8 ++------ .../05/GHSA-h4wq-q9hr-ffm6/GHSA-h4wq-q9hr-ffm6.json | 12 +++--------- .../05/GHSA-h5m3-8vhj-cgjg/GHSA-h5m3-8vhj-cgjg.json | 8 ++------ .../05/GHSA-h5r8-fvh2-9qxg/GHSA-h5r8-fvh2-9qxg.json | 12 +++--------- .../05/GHSA-h6wh-5wqm-h86w/GHSA-h6wh-5wqm-h86w.json | 12 +++--------- .../05/GHSA-h74r-xh5r-h54x/GHSA-h74r-xh5r-h54x.json | 8 ++------ .../05/GHSA-hcrp-2jqr-cf9w/GHSA-hcrp-2jqr-cf9w.json | 12 +++--------- .../05/GHSA-hcwc-2gm5-v9g6/GHSA-hcwc-2gm5-v9g6.json | 12 +++--------- .../05/GHSA-hfhh-qrv3-cq79/GHSA-hfhh-qrv3-cq79.json | 12 +++--------- .../05/GHSA-hfpp-6hrw-77h9/GHSA-hfpp-6hrw-77h9.json | 8 ++------ .../05/GHSA-hfqh-j6f7-843f/GHSA-hfqh-j6f7-843f.json | 8 ++------ .../05/GHSA-hj38-v83c-6gx2/GHSA-hj38-v83c-6gx2.json | 8 ++------ .../05/GHSA-hjhv-rf4c-xwpv/GHSA-hjhv-rf4c-xwpv.json | 12 +++--------- .../05/GHSA-hm8v-p29w-fjv8/GHSA-hm8v-p29w-fjv8.json | 8 ++------ .../05/GHSA-hmrm-3xmg-v873/GHSA-hmrm-3xmg-v873.json | 12 +++--------- .../05/GHSA-hqvx-g6jw-22pw/GHSA-hqvx-g6jw-22pw.json | 8 ++------ .../05/GHSA-hqx3-2rj3-qx6v/GHSA-hqx3-2rj3-qx6v.json | 12 +++--------- .../05/GHSA-hr2h-x3c6-5767/GHSA-hr2h-x3c6-5767.json | 4 +--- .../05/GHSA-hvg4-4g92-cp78/GHSA-hvg4-4g92-cp78.json | 8 ++------ .../05/GHSA-hw3r-8g7v-p8rq/GHSA-hw3r-8g7v-p8rq.json | 8 ++------ .../05/GHSA-hwmg-8436-r7fw/GHSA-hwmg-8436-r7fw.json | 12 +++--------- .../05/GHSA-hx54-chxq-7878/GHSA-hx54-chxq-7878.json | 8 ++------ .../05/GHSA-j25r-mrm6-h8pw/GHSA-j25r-mrm6-h8pw.json | 12 +++--------- .../05/GHSA-j5fp-59mp-fgm2/GHSA-j5fp-59mp-fgm2.json | 8 ++------ .../05/GHSA-j624-g6fh-22pc/GHSA-j624-g6fh-22pc.json | 12 +++--------- .../05/GHSA-j645-wj56-g5fv/GHSA-j645-wj56-g5fv.json | 8 ++------ .../05/GHSA-j657-99m2-wp3h/GHSA-j657-99m2-wp3h.json | 12 +++--------- .../05/GHSA-j695-8pfm-q8q9/GHSA-j695-8pfm-q8q9.json | 12 +++--------- .../05/GHSA-j6wf-jr95-r768/GHSA-j6wf-jr95-r768.json | 12 +++--------- .../05/GHSA-j7h4-v6c8-pwrx/GHSA-j7h4-v6c8-pwrx.json | 4 +--- .../05/GHSA-j9fm-2qf2-5gjm/GHSA-j9fm-2qf2-5gjm.json | 12 +++--------- .../05/GHSA-j9wh-q5x6-q8gp/GHSA-j9wh-q5x6-q8gp.json | 4 +--- .../05/GHSA-jc3m-3wcx-qq62/GHSA-jc3m-3wcx-qq62.json | 12 +++--------- .../05/GHSA-jc42-35xx-59vv/GHSA-jc42-35xx-59vv.json | 8 ++------ .../05/GHSA-jc73-84rr-2mcp/GHSA-jc73-84rr-2mcp.json | 8 ++------ .../05/GHSA-jcrh-hfqv-cr47/GHSA-jcrh-hfqv-cr47.json | 12 +++--------- .../05/GHSA-jf57-f8jq-wjg2/GHSA-jf57-f8jq-wjg2.json | 12 +++--------- .../05/GHSA-jfxm-7j25-cffr/GHSA-jfxm-7j25-cffr.json | 12 +++--------- .../05/GHSA-jgjp-57q6-q7hv/GHSA-jgjp-57q6-q7hv.json | 4 +--- .../05/GHSA-jgx3-5crp-mxjw/GHSA-jgx3-5crp-mxjw.json | 12 +++--------- .../05/GHSA-jh9f-947r-wfrf/GHSA-jh9f-947r-wfrf.json | 4 +--- .../05/GHSA-jm56-mq2p-7c4g/GHSA-jm56-mq2p-7c4g.json | 12 +++--------- .../05/GHSA-jmmv-5xg4-p56f/GHSA-jmmv-5xg4-p56f.json | 12 +++--------- .../05/GHSA-jp5w-5x2h-hp6v/GHSA-jp5w-5x2h-hp6v.json | 8 ++------ .../05/GHSA-jpq8-q698-27vp/GHSA-jpq8-q698-27vp.json | 12 +++--------- .../05/GHSA-jq52-3fww-m362/GHSA-jq52-3fww-m362.json | 12 +++--------- .../05/GHSA-jqc9-prwj-qrwj/GHSA-jqc9-prwj-qrwj.json | 8 ++------ .../05/GHSA-jqf5-5c3v-wj97/GHSA-jqf5-5c3v-wj97.json | 8 ++------ .../05/GHSA-jr48-437x-gh24/GHSA-jr48-437x-gh24.json | 8 ++------ .../05/GHSA-jrgf-mmc9-3pr7/GHSA-jrgf-mmc9-3pr7.json | 8 ++------ .../05/GHSA-jrgp-f5cx-xhh6/GHSA-jrgp-f5cx-xhh6.json | 12 +++--------- .../05/GHSA-jv7f-8q8r-cr3q/GHSA-jv7f-8q8r-cr3q.json | 8 ++------ .../05/GHSA-jvj7-xhrw-68x6/GHSA-jvj7-xhrw-68x6.json | 12 +++--------- .../05/GHSA-jw7f-q78h-423m/GHSA-jw7f-q78h-423m.json | 8 ++------ .../05/GHSA-m2mx-5gcx-j288/GHSA-m2mx-5gcx-j288.json | 4 +--- .../05/GHSA-m2q3-43wc-p9w4/GHSA-m2q3-43wc-p9w4.json | 12 +++--------- .../05/GHSA-m4f8-m4jg-vm84/GHSA-m4f8-m4jg-vm84.json | 8 ++------ .../05/GHSA-m4v5-m876-34f5/GHSA-m4v5-m876-34f5.json | 8 ++------ .../05/GHSA-m697-r4gm-82f3/GHSA-m697-r4gm-82f3.json | 12 +++--------- .../05/GHSA-m69w-8p53-w8cx/GHSA-m69w-8p53-w8cx.json | 12 +++--------- .../05/GHSA-m6xf-x3pm-6ffw/GHSA-m6xf-x3pm-6ffw.json | 8 ++------ .../05/GHSA-m955-8c8p-f9h8/GHSA-m955-8c8p-f9h8.json | 12 +++--------- .../05/GHSA-m95j-3vpr-rhr4/GHSA-m95j-3vpr-rhr4.json | 12 +++--------- .../05/GHSA-mf64-j3g8-vgpj/GHSA-mf64-j3g8-vgpj.json | 8 ++------ .../05/GHSA-mf95-6qmf-q4f9/GHSA-mf95-6qmf-q4f9.json | 12 +++--------- .../05/GHSA-mg4q-7wrp-v22h/GHSA-mg4q-7wrp-v22h.json | 8 ++------ .../05/GHSA-mh2j-r8qm-xj6j/GHSA-mh2j-r8qm-xj6j.json | 12 +++--------- .../05/GHSA-mhc5-f7x7-jfpg/GHSA-mhc5-f7x7-jfpg.json | 12 +++--------- .../05/GHSA-mhpx-2qw7-qwqp/GHSA-mhpx-2qw7-qwqp.json | 8 ++------ .../05/GHSA-mhvm-7v69-2hr4/GHSA-mhvm-7v69-2hr4.json | 12 +++--------- .../05/GHSA-mm32-rj9g-9ffc/GHSA-mm32-rj9g-9ffc.json | 12 +++--------- .../05/GHSA-mmh8-c5c3-4mw5/GHSA-mmh8-c5c3-4mw5.json | 8 ++------ .../05/GHSA-mp5p-8378-g7pw/GHSA-mp5p-8378-g7pw.json | 12 +++--------- .../05/GHSA-mp8w-5ccr-gf45/GHSA-mp8w-5ccr-gf45.json | 12 +++--------- .../05/GHSA-mv65-7xv7-wp7j/GHSA-mv65-7xv7-wp7j.json | 8 ++------ .../05/GHSA-mxr8-pvvp-fw5r/GHSA-mxr8-pvvp-fw5r.json | 12 +++--------- .../05/GHSA-p22x-x8mg-qrqm/GHSA-p22x-x8mg-qrqm.json | 4 +--- .../05/GHSA-p2q5-r29q-m7gv/GHSA-p2q5-r29q-m7gv.json | 8 ++------ .../05/GHSA-p3mr-f49r-753g/GHSA-p3mr-f49r-753g.json | 12 +++--------- .../05/GHSA-p443-fjqf-h82p/GHSA-p443-fjqf-h82p.json | 12 +++--------- .../05/GHSA-p56m-hx7c-pjv5/GHSA-p56m-hx7c-pjv5.json | 12 +++--------- .../05/GHSA-p87v-mmg4-w93p/GHSA-p87v-mmg4-w93p.json | 12 +++--------- .../05/GHSA-p975-9mr6-3gg6/GHSA-p975-9mr6-3gg6.json | 12 +++--------- .../05/GHSA-p9x8-8fhr-66mg/GHSA-p9x8-8fhr-66mg.json | 12 +++--------- .../05/GHSA-pf79-9hv7-chg5/GHSA-pf79-9hv7-chg5.json | 12 +++--------- .../05/GHSA-pfj3-f63g-8pwm/GHSA-pfj3-f63g-8pwm.json | 12 +++--------- .../05/GHSA-pfr3-j9r8-5229/GHSA-pfr3-j9r8-5229.json | 8 ++------ .../05/GHSA-pfv6-m4rh-76wr/GHSA-pfv6-m4rh-76wr.json | 12 +++--------- .../05/GHSA-phhj-vpf5-5666/GHSA-phhj-vpf5-5666.json | 4 +--- .../05/GHSA-pj93-8v65-p9w3/GHSA-pj93-8v65-p9w3.json | 4 +--- .../05/GHSA-pjcw-v852-66p8/GHSA-pjcw-v852-66p8.json | 8 ++------ .../05/GHSA-pp62-f72p-x838/GHSA-pp62-f72p-x838.json | 12 +++--------- .../05/GHSA-pph2-ccpg-crg3/GHSA-pph2-ccpg-crg3.json | 12 +++--------- .../05/GHSA-prx2-4v64-2j7p/GHSA-prx2-4v64-2j7p.json | 12 +++--------- .../05/GHSA-pvj6-h4hj-8v43/GHSA-pvj6-h4hj-8v43.json | 8 ++------ .../05/GHSA-pw98-cq7c-645p/GHSA-pw98-cq7c-645p.json | 8 ++------ .../05/GHSA-q27w-wp82-7w7w/GHSA-q27w-wp82-7w7w.json | 8 ++------ .../05/GHSA-q34r-wxv2-gwvr/GHSA-q34r-wxv2-gwvr.json | 12 +++--------- .../05/GHSA-q3w6-vxrx-4g94/GHSA-q3w6-vxrx-4g94.json | 12 +++--------- .../05/GHSA-q4x3-5q32-g3h6/GHSA-q4x3-5q32-g3h6.json | 8 ++------ .../05/GHSA-q56m-mx82-79xw/GHSA-q56m-mx82-79xw.json | 8 ++------ .../05/GHSA-q57h-w83p-m8hx/GHSA-q57h-w83p-m8hx.json | 8 ++------ .../05/GHSA-q699-f9h8-7v6p/GHSA-q699-f9h8-7v6p.json | 12 +++--------- .../05/GHSA-q6rc-73hq-57jq/GHSA-q6rc-73hq-57jq.json | 8 ++------ .../05/GHSA-q72h-v4jg-pwvv/GHSA-q72h-v4jg-pwvv.json | 4 +--- .../05/GHSA-q75j-83jm-892x/GHSA-q75j-83jm-892x.json | 8 ++------ .../05/GHSA-q7qw-4c2f-p3rj/GHSA-q7qw-4c2f-p3rj.json | 12 +++--------- .../05/GHSA-q9cg-2gwc-x6xh/GHSA-q9cg-2gwc-x6xh.json | 12 +++--------- .../05/GHSA-q9qr-vfrw-vgjq/GHSA-q9qr-vfrw-vgjq.json | 12 +++--------- .../05/GHSA-q9ww-5345-v56q/GHSA-q9ww-5345-v56q.json | 8 ++------ .../05/GHSA-qc34-jwcm-8qfc/GHSA-qc34-jwcm-8qfc.json | 12 +++--------- .../05/GHSA-qc3j-p935-x73x/GHSA-qc3j-p935-x73x.json | 12 +++--------- .../05/GHSA-qc83-fm35-h9f4/GHSA-qc83-fm35-h9f4.json | 12 +++--------- .../05/GHSA-qcj8-gp4q-v8r2/GHSA-qcj8-gp4q-v8r2.json | 12 +++--------- .../05/GHSA-qcq5-vfmc-qgpp/GHSA-qcq5-vfmc-qgpp.json | 12 +++--------- .../05/GHSA-qf6w-rfjw-57c3/GHSA-qf6w-rfjw-57c3.json | 8 ++------ .../05/GHSA-qf8w-r56m-c9xh/GHSA-qf8w-r56m-c9xh.json | 12 +++--------- .../05/GHSA-qfrg-7c28-7q8x/GHSA-qfrg-7c28-7q8x.json | 12 +++--------- .../05/GHSA-qg98-9h5g-6p53/GHSA-qg98-9h5g-6p53.json | 8 ++------ .../05/GHSA-qm3v-8cq5-mxv7/GHSA-qm3v-8cq5-mxv7.json | 12 +++--------- .../05/GHSA-qm8h-fvrp-9pr9/GHSA-qm8h-fvrp-9pr9.json | 4 +--- .../05/GHSA-qmwg-hw9q-xg39/GHSA-qmwg-hw9q-xg39.json | 8 ++------ .../05/GHSA-qp4q-4p6v-w368/GHSA-qp4q-4p6v-w368.json | 8 ++------ .../05/GHSA-qp75-7qjq-q8m4/GHSA-qp75-7qjq-q8m4.json | 12 +++--------- .../05/GHSA-qqcr-rg66-5jpm/GHSA-qqcr-rg66-5jpm.json | 12 +++--------- .../05/GHSA-qr9q-882c-gv4j/GHSA-qr9q-882c-gv4j.json | 4 +--- .../05/GHSA-qvxf-gr3j-5qw7/GHSA-qvxf-gr3j-5qw7.json | 4 +--- .../05/GHSA-qwh9-c7jr-5v9g/GHSA-qwh9-c7jr-5v9g.json | 8 ++------ .../05/GHSA-qxgw-h378-xhrw/GHSA-qxgw-h378-xhrw.json | 12 +++--------- .../05/GHSA-r23m-244x-c4vq/GHSA-r23m-244x-c4vq.json | 12 +++--------- .../05/GHSA-r2p6-249c-3h56/GHSA-r2p6-249c-3h56.json | 8 ++------ .../05/GHSA-r365-86rw-9xxw/GHSA-r365-86rw-9xxw.json | 12 +++--------- .../05/GHSA-r449-4m6g-rp77/GHSA-r449-4m6g-rp77.json | 4 +--- .../05/GHSA-r48j-3399-5rmj/GHSA-r48j-3399-5rmj.json | 12 +++--------- .../05/GHSA-r75c-w926-gc25/GHSA-r75c-w926-gc25.json | 12 +++--------- .../05/GHSA-r88h-whf8-g952/GHSA-r88h-whf8-g952.json | 8 ++------ .../05/GHSA-r9cq-9m7w-wx27/GHSA-r9cq-9m7w-wx27.json | 8 ++------ .../05/GHSA-rcpf-fw5j-h8rw/GHSA-rcpf-fw5j-h8rw.json | 12 +++--------- .../05/GHSA-rcv9-9vhw-rmqr/GHSA-rcv9-9vhw-rmqr.json | 12 +++--------- .../05/GHSA-rf2c-rjfm-w7w2/GHSA-rf2c-rjfm-w7w2.json | 12 +++--------- .../05/GHSA-rg23-p49x-87gc/GHSA-rg23-p49x-87gc.json | 12 +++--------- .../05/GHSA-rh33-j243-53gw/GHSA-rh33-j243-53gw.json | 8 ++------ .../05/GHSA-rh49-4r53-hgxv/GHSA-rh49-4r53-hgxv.json | 12 +++--------- .../05/GHSA-rhr6-wq97-prx6/GHSA-rhr6-wq97-prx6.json | 12 +++--------- .../05/GHSA-rppr-4h7c-mc9c/GHSA-rppr-4h7c-mc9c.json | 4 +--- .../05/GHSA-rq95-33vv-7jxc/GHSA-rq95-33vv-7jxc.json | 12 +++--------- .../05/GHSA-rq9j-q9jw-98mf/GHSA-rq9j-q9jw-98mf.json | 8 ++------ .../05/GHSA-rq9v-5pfm-x4vf/GHSA-rq9v-5pfm-x4vf.json | 12 +++--------- .../05/GHSA-rwf2-mvgx-r834/GHSA-rwf2-mvgx-r834.json | 12 +++--------- .../05/GHSA-rx37-23pf-h4vh/GHSA-rx37-23pf-h4vh.json | 12 +++--------- .../05/GHSA-rxxr-9pqj-xw7v/GHSA-rxxr-9pqj-xw7v.json | 12 +++--------- .../05/GHSA-v53h-89xp-f8xj/GHSA-v53h-89xp-f8xj.json | 12 +++--------- .../05/GHSA-v6mq-89c8-6ff4/GHSA-v6mq-89c8-6ff4.json | 12 +++--------- .../05/GHSA-v7f9-3v82-w67w/GHSA-v7f9-3v82-w67w.json | 8 ++------ .../05/GHSA-v8mw-xqhr-2vqp/GHSA-v8mw-xqhr-2vqp.json | 8 ++------ .../05/GHSA-v8qg-gvfx-g8vq/GHSA-v8qg-gvfx-g8vq.json | 8 ++------ .../05/GHSA-v95m-8wq8-p4r8/GHSA-v95m-8wq8-p4r8.json | 8 ++------ .../05/GHSA-v9wg-q5vm-7g4w/GHSA-v9wg-q5vm-7g4w.json | 12 +++--------- .../05/GHSA-vcr6-44f9-7v58/GHSA-vcr6-44f9-7v58.json | 8 ++------ .../05/GHSA-vfqm-4cxm-qpxr/GHSA-vfqm-4cxm-qpxr.json | 8 ++------ .../05/GHSA-vgwx-h8vg-v6jx/GHSA-vgwx-h8vg-v6jx.json | 12 +++--------- .../05/GHSA-vjgc-v7h9-phhc/GHSA-vjgc-v7h9-phhc.json | 8 ++------ .../05/GHSA-vp93-pr49-f4r2/GHSA-vp93-pr49-f4r2.json | 12 +++--------- .../05/GHSA-vpqv-7qjc-x42g/GHSA-vpqv-7qjc-x42g.json | 8 ++------ .../05/GHSA-vqh2-672q-h5xp/GHSA-vqh2-672q-h5xp.json | 4 +--- .../05/GHSA-vr6x-m59x-pq35/GHSA-vr6x-m59x-pq35.json | 12 +++--------- .../05/GHSA-vrc8-63q3-rgq3/GHSA-vrc8-63q3-rgq3.json | 8 ++------ .../05/GHSA-vvm8-37ch-xp6p/GHSA-vvm8-37ch-xp6p.json | 8 ++------ .../05/GHSA-vx8r-4fwr-hc2v/GHSA-vx8r-4fwr-hc2v.json | 12 +++--------- .../05/GHSA-vxw3-96f4-67xp/GHSA-vxw3-96f4-67xp.json | 8 ++------ .../05/GHSA-w35w-5rg7-v2c5/GHSA-w35w-5rg7-v2c5.json | 8 ++------ .../05/GHSA-w452-97x5-fxw2/GHSA-w452-97x5-fxw2.json | 8 ++------ .../05/GHSA-w49v-8458-hh85/GHSA-w49v-8458-hh85.json | 12 +++--------- .../05/GHSA-w56x-hj26-mq65/GHSA-w56x-hj26-mq65.json | 4 +--- .../05/GHSA-w63g-378w-5j6f/GHSA-w63g-378w-5j6f.json | 8 ++------ .../05/GHSA-w7hh-546g-p758/GHSA-w7hh-546g-p758.json | 8 ++------ .../05/GHSA-w97r-xg4x-xx2r/GHSA-w97r-xg4x-xx2r.json | 12 +++--------- .../05/GHSA-wc24-5j7x-rp2x/GHSA-wc24-5j7x-rp2x.json | 4 +--- .../05/GHSA-wc59-9v92-fgr3/GHSA-wc59-9v92-fgr3.json | 12 +++--------- .../05/GHSA-wc5h-vpgx-mqjw/GHSA-wc5h-vpgx-mqjw.json | 8 ++------ .../05/GHSA-wfvm-4gxx-hpcr/GHSA-wfvm-4gxx-hpcr.json | 12 +++--------- .../05/GHSA-wfwj-6wvw-xhcw/GHSA-wfwj-6wvw-xhcw.json | 4 +--- .../05/GHSA-wh2h-r4h5-rjx4/GHSA-wh2h-r4h5-rjx4.json | 12 +++--------- .../05/GHSA-wh9c-c583-h226/GHSA-wh9c-c583-h226.json | 8 ++------ .../05/GHSA-wh9w-pc8q-w744/GHSA-wh9w-pc8q-w744.json | 8 ++------ .../05/GHSA-wj74-9qqx-pg4x/GHSA-wj74-9qqx-pg4x.json | 8 ++------ .../05/GHSA-wjc6-gjj8-cjmf/GHSA-wjc6-gjj8-cjmf.json | 4 +--- .../05/GHSA-wmxr-q76g-c3rw/GHSA-wmxr-q76g-c3rw.json | 12 +++--------- .../05/GHSA-wqcp-rc88-3mjf/GHSA-wqcp-rc88-3mjf.json | 12 +++--------- .../05/GHSA-wqwx-hvg4-2wh9/GHSA-wqwx-hvg4-2wh9.json | 12 +++--------- .../05/GHSA-wrjw-6w8m-xcwh/GHSA-wrjw-6w8m-xcwh.json | 8 ++------ .../05/GHSA-wrr9-hwhq-cmwg/GHSA-wrr9-hwhq-cmwg.json | 8 ++------ .../05/GHSA-wrx5-q6rx-f5p3/GHSA-wrx5-q6rx-f5p3.json | 12 +++--------- .../05/GHSA-wv8f-fxfc-vvj4/GHSA-wv8f-fxfc-vvj4.json | 12 +++--------- .../05/GHSA-wwgg-2c86-7h3q/GHSA-wwgg-2c86-7h3q.json | 4 +--- .../05/GHSA-wxhm-qq5v-rf47/GHSA-wxhm-qq5v-rf47.json | 8 ++------ .../05/GHSA-x3vr-p44r-4h38/GHSA-x3vr-p44r-4h38.json | 8 ++------ .../05/GHSA-x42c-7gjh-r9fx/GHSA-x42c-7gjh-r9fx.json | 12 +++--------- .../05/GHSA-x4jp-r3j2-5jxx/GHSA-x4jp-r3j2-5jxx.json | 8 ++------ .../05/GHSA-x4rf-jx7j-r49m/GHSA-x4rf-jx7j-r49m.json | 4 +--- .../05/GHSA-x545-vr57-rgh9/GHSA-x545-vr57-rgh9.json | 8 ++------ .../05/GHSA-x634-f296-rwgv/GHSA-x634-f296-rwgv.json | 4 +--- .../05/GHSA-x884-xw28-vpw4/GHSA-x884-xw28-vpw4.json | 12 +++--------- .../05/GHSA-x8mp-jv75-5hrp/GHSA-x8mp-jv75-5hrp.json | 8 ++------ .../05/GHSA-x8v2-f8hm-jwjh/GHSA-x8v2-f8hm-jwjh.json | 8 ++------ .../05/GHSA-xc45-gmq4-mwpv/GHSA-xc45-gmq4-mwpv.json | 12 +++--------- .../05/GHSA-xf5g-q7vm-4fg3/GHSA-xf5g-q7vm-4fg3.json | 12 +++--------- .../05/GHSA-xg8m-gfp3-4fv6/GHSA-xg8m-gfp3-4fv6.json | 8 ++------ .../05/GHSA-xj2w-7m9r-98q7/GHSA-xj2w-7m9r-98q7.json | 8 ++------ .../05/GHSA-xjqp-g574-g782/GHSA-xjqp-g574-g782.json | 12 +++--------- .../05/GHSA-xm43-qc4p-9f7j/GHSA-xm43-qc4p-9f7j.json | 8 ++------ .../05/GHSA-xmvc-mhq7-5v2v/GHSA-xmvc-mhq7-5v2v.json | 12 +++--------- .../05/GHSA-xp3q-55jv-wpp2/GHSA-xp3q-55jv-wpp2.json | 12 +++--------- .../05/GHSA-xpxh-fh9m-hf5v/GHSA-xpxh-fh9m-hf5v.json | 8 ++------ .../05/GHSA-xr8r-7f7p-x5r5/GHSA-xr8r-7f7p-x5r5.json | 8 ++------ .../05/GHSA-xv63-838w-fgf7/GHSA-xv63-838w-fgf7.json | 8 ++------ .../05/GHSA-xv7h-qpjm-g3jp/GHSA-xv7h-qpjm-g3jp.json | 12 +++--------- .../05/GHSA-xvh3-fg8j-wp79/GHSA-xvh3-fg8j-wp79.json | 8 ++------ .../07/GHSA-8rvm-f29f-fjx6/GHSA-8rvm-f29f-fjx6.json | 4 +--- .../08/GHSA-2h4c-86hw-hmr7/GHSA-2h4c-86hw-hmr7.json | 4 +--- .../08/GHSA-3qmv-v22h-rc37/GHSA-3qmv-v22h-rc37.json | 4 +--- .../08/GHSA-4586-3c3g-jv96/GHSA-4586-3c3g-jv96.json | 4 +--- .../08/GHSA-5wj6-fpjf-5rfv/GHSA-5wj6-fpjf-5rfv.json | 4 +--- .../08/GHSA-83mh-8mgc-grcj/GHSA-83mh-8mgc-grcj.json | 4 +--- .../08/GHSA-9xf8-6p87-ww99/GHSA-9xf8-6p87-ww99.json | 4 +--- .../08/GHSA-hpww-gcq4-rc3c/GHSA-hpww-gcq4-rc3c.json | 4 +--- .../08/GHSA-j928-ww9w-w7hg/GHSA-j928-ww9w-w7hg.json | 4 +--- .../08/GHSA-jw85-mc7h-c36v/GHSA-jw85-mc7h-c36v.json | 4 +--- .../08/GHSA-mq67-2w77-w276/GHSA-mq67-2w77-w276.json | 8 ++------ .../08/GHSA-pg49-p7jf-3q72/GHSA-pg49-p7jf-3q72.json | 4 +--- .../08/GHSA-v9gp-cm5m-f2c5/GHSA-v9gp-cm5m-f2c5.json | 4 +--- .../08/GHSA-vc8q-vv59-f54c/GHSA-vc8q-vv59-f54c.json | 4 +--- .../08/GHSA-vhpq-rmjq-cgrp/GHSA-vhpq-rmjq-cgrp.json | 4 +--- .../08/GHSA-xfcr-fmp2-xwhr/GHSA-xfcr-fmp2-xwhr.json | 4 +--- .../08/GHSA-xqgw-r8h6-587w/GHSA-xqgw-r8h6-587w.json | 4 +--- .../12/GHSA-9w34-3vc7-7786/GHSA-9w34-3vc7-7786.json | 4 +--- .../01/GHSA-269f-c6h8-6gv2/GHSA-269f-c6h8-6gv2.json | 4 +--- .../01/GHSA-2hwr-88h3-g5j5/GHSA-2hwr-88h3-g5j5.json | 4 +--- .../01/GHSA-342c-w38f-j4wc/GHSA-342c-w38f-j4wc.json | 4 +--- .../01/GHSA-3j3x-f853-j95p/GHSA-3j3x-f853-j95p.json | 4 +--- .../01/GHSA-3j59-wr8c-7648/GHSA-3j59-wr8c-7648.json | 4 +--- .../01/GHSA-4w9g-pxjp-v6rx/GHSA-4w9g-pxjp-v6rx.json | 4 +--- .../01/GHSA-5q85-v6f3-x49m/GHSA-5q85-v6f3-x49m.json | 4 +--- .../01/GHSA-7j4m-g687-74qh/GHSA-7j4m-g687-74qh.json | 8 ++------ .../01/GHSA-7w2m-f6qv-243x/GHSA-7w2m-f6qv-243x.json | 4 +--- .../01/GHSA-8cv3-mr7x-wh73/GHSA-8cv3-mr7x-wh73.json | 4 +--- .../01/GHSA-8jgg-mxr5-h7mf/GHSA-8jgg-mxr5-h7mf.json | 4 +--- .../01/GHSA-9m22-9pp9-3gwc/GHSA-9m22-9pp9-3gwc.json | 4 +--- .../01/GHSA-9rmx-2mjp-5w4j/GHSA-9rmx-2mjp-5w4j.json | 4 +--- .../01/GHSA-c4gj-hh7r-67qf/GHSA-c4gj-hh7r-67qf.json | 4 +--- .../01/GHSA-c74p-x565-fv2v/GHSA-c74p-x565-fv2v.json | 4 +--- .../01/GHSA-f637-4v2p-h3qv/GHSA-f637-4v2p-h3qv.json | 4 +--- .../01/GHSA-f6c3-2788-h964/GHSA-f6c3-2788-h964.json | 4 +--- .../01/GHSA-f73m-w3jg-64qm/GHSA-f73m-w3jg-64qm.json | 4 +--- .../01/GHSA-gpfm-wj7m-f7jj/GHSA-gpfm-wj7m-f7jj.json | 4 +--- .../01/GHSA-gqx3-wh79-gf57/GHSA-gqx3-wh79-gf57.json | 4 +--- .../01/GHSA-grcq-2f23-7prp/GHSA-grcq-2f23-7prp.json | 4 +--- .../01/GHSA-jmcg-v3wf-g69g/GHSA-jmcg-v3wf-g69g.json | 4 +--- .../01/GHSA-mr22-3rrp-47cx/GHSA-mr22-3rrp-47cx.json | 4 +--- .../01/GHSA-mw5v-w29j-c9g9/GHSA-mw5v-w29j-c9g9.json | 4 +--- .../01/GHSA-p7v6-2vr2-6qpq/GHSA-p7v6-2vr2-6qpq.json | 4 +--- .../01/GHSA-q6ff-9vgw-842x/GHSA-q6ff-9vgw-842x.json | 4 +--- .../01/GHSA-rj5f-wj63-xvgc/GHSA-rj5f-wj63-xvgc.json | 4 +--- .../01/GHSA-vgr9-35rp-jw4x/GHSA-vgr9-35rp-jw4x.json | 4 +--- .../01/GHSA-x42v-2793-x54w/GHSA-x42v-2793-x54w.json | 4 +--- .../01/GHSA-x63v-xw79-mw5j/GHSA-x63v-xw79-mw5j.json | 4 +--- .../01/GHSA-x7rx-9g3w-62mw/GHSA-x7rx-9g3w-62mw.json | 4 +--- .../03/GHSA-gv85-xg33-553c/GHSA-gv85-xg33-553c.json | 4 +--- .../08/GHSA-wpm6-6374-m3g5/GHSA-wpm6-6374-m3g5.json | 4 +--- .../10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json | 4 +--- .../10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json | 4 +--- .../10/GHSA-q6jg-9395-p66m/GHSA-q6jg-9395-p66m.json | 4 +--- .../01/GHSA-cxjh-j6f8-vrmf/GHSA-cxjh-j6f8-vrmf.json | 4 +--- .../02/GHSA-2569-97m4-w479/GHSA-2569-97m4-w479.json | 4 +--- .../02/GHSA-2mw7-f37q-33mg/GHSA-2mw7-f37q-33mg.json | 4 +--- .../02/GHSA-3q83-x89h-m869/GHSA-3q83-x89h-m869.json | 12 +++--------- .../02/GHSA-53p9-pvv8-g92g/GHSA-53p9-pvv8-g92g.json | 12 +++--------- .../02/GHSA-554r-mhfh-g54g/GHSA-554r-mhfh-g54g.json | 4 +--- .../02/GHSA-5pf8-g8g3-8798/GHSA-5pf8-g8g3-8798.json | 4 +--- .../02/GHSA-5r44-g6v6-6h2w/GHSA-5r44-g6v6-6h2w.json | 4 +--- .../02/GHSA-6hv8-6fgh-mjj5/GHSA-6hv8-6fgh-mjj5.json | 4 +--- .../02/GHSA-6j8w-8cxv-823q/GHSA-6j8w-8cxv-823q.json | 4 +--- .../02/GHSA-7m32-w789-g7x4/GHSA-7m32-w789-g7x4.json | 4 +--- .../02/GHSA-8h8w-85rq-cgp4/GHSA-8h8w-85rq-cgp4.json | 4 +--- .../02/GHSA-8v7m-h3c9-88g7/GHSA-8v7m-h3c9-88g7.json | 4 +--- .../02/GHSA-94x4-fq94-5wwx/GHSA-94x4-fq94-5wwx.json | 4 +--- .../02/GHSA-97wx-j5qg-q792/GHSA-97wx-j5qg-q792.json | 4 +--- .../02/GHSA-c27w-rp5h-g734/GHSA-c27w-rp5h-g734.json | 4 +--- .../02/GHSA-c6rw-7vmm-m3h7/GHSA-c6rw-7vmm-m3h7.json | 4 +--- .../02/GHSA-cc59-mwcm-hxv4/GHSA-cc59-mwcm-hxv4.json | 4 +--- .../02/GHSA-cmg9-p9gp-g7mr/GHSA-cmg9-p9gp-g7mr.json | 4 +--- .../02/GHSA-f2cw-fq5w-55f8/GHSA-f2cw-fq5w-55f8.json | 4 +--- .../02/GHSA-f6q6-67qx-rv6q/GHSA-f6q6-67qx-rv6q.json | 12 +++--------- .../02/GHSA-f846-m55f-g9fw/GHSA-f846-m55f-g9fw.json | 4 +--- .../02/GHSA-f8gm-9px2-mw95/GHSA-f8gm-9px2-mw95.json | 4 +--- .../02/GHSA-f9hf-4fvc-mjjv/GHSA-f9hf-4fvc-mjjv.json | 4 +--- .../02/GHSA-h66f-8xvf-h765/GHSA-h66f-8xvf-h765.json | 4 +--- .../02/GHSA-h7x2-hfmv-h4xf/GHSA-h7x2-hfmv-h4xf.json | 4 +--- .../02/GHSA-jmc4-fgf5-jp55/GHSA-jmc4-fgf5-jp55.json | 4 +--- .../02/GHSA-mjfr-hgmr-g3rv/GHSA-mjfr-hgmr-g3rv.json | 4 +--- .../02/GHSA-p93q-jr7q-q29w/GHSA-p93q-jr7q-q29w.json | 4 +--- .../02/GHSA-p9mc-3cgc-v8h2/GHSA-p9mc-3cgc-v8h2.json | 4 +--- .../02/GHSA-pqrw-mpmw-gp6m/GHSA-pqrw-mpmw-gp6m.json | 4 +--- .../02/GHSA-qf63-rfv8-f92j/GHSA-qf63-rfv8-f92j.json | 4 +--- .../02/GHSA-r3c3-f9mx-3phh/GHSA-r3c3-f9mx-3phh.json | 4 +--- .../02/GHSA-r4h7-p578-p9gv/GHSA-r4h7-p578-p9gv.json | 4 +--- .../02/GHSA-vmw7-gx6r-25fh/GHSA-vmw7-gx6r-25fh.json | 4 +--- .../02/GHSA-w598-9rgj-7mq4/GHSA-w598-9rgj-7mq4.json | 4 +--- .../02/GHSA-wq5x-2c58-p48w/GHSA-wq5x-2c58-p48w.json | 4 +--- .../02/GHSA-xqwj-7jph-vrcj/GHSA-xqwj-7jph-vrcj.json | 4 +--- .../03/GHSA-2c52-g67x-6vf3/GHSA-2c52-g67x-6vf3.json | 4 +--- .../03/GHSA-39x5-gqgg-68v8/GHSA-39x5-gqgg-68v8.json | 4 +--- .../03/GHSA-3hpx-5vcc-5jw2/GHSA-3hpx-5vcc-5jw2.json | 4 +--- .../03/GHSA-3m2p-xpv4-jfjm/GHSA-3m2p-xpv4-jfjm.json | 4 +--- .../03/GHSA-3p89-8hm7-44h4/GHSA-3p89-8hm7-44h4.json | 8 ++------ .../03/GHSA-3rqr-p9xj-863f/GHSA-3rqr-p9xj-863f.json | 4 +--- .../03/GHSA-4g86-mfr6-26v9/GHSA-4g86-mfr6-26v9.json | 4 +--- .../03/GHSA-567q-hq5r-pw43/GHSA-567q-hq5r-pw43.json | 4 +--- .../03/GHSA-5gxq-j292-75cc/GHSA-5gxq-j292-75cc.json | 12 +++--------- .../03/GHSA-683m-h868-4cxr/GHSA-683m-h868-4cxr.json | 12 +++--------- .../03/GHSA-8v58-wvr2-fj59/GHSA-8v58-wvr2-fj59.json | 4 +--- .../03/GHSA-93jv-fpc3-9m4w/GHSA-93jv-fpc3-9m4w.json | 8 ++------ .../03/GHSA-99h3-vvc6-h7gh/GHSA-99h3-vvc6-h7gh.json | 12 +++--------- .../03/GHSA-9jr7-gg57-r7pf/GHSA-9jr7-gg57-r7pf.json | 8 ++------ .../03/GHSA-9jv3-jc56-rv4g/GHSA-9jv3-jc56-rv4g.json | 12 +++--------- .../03/GHSA-fc5p-vfgp-xc5m/GHSA-fc5p-vfgp-xc5m.json | 8 ++------ .../03/GHSA-fc7v-6h7h-m2w9/GHSA-fc7v-6h7h-m2w9.json | 4 +--- .../03/GHSA-g4p6-wj2c-46f6/GHSA-g4p6-wj2c-46f6.json | 8 ++------ .../03/GHSA-gx2g-vf96-qjwv/GHSA-gx2g-vf96-qjwv.json | 4 +--- .../03/GHSA-hw3g-x69p-f6rq/GHSA-hw3g-x69p-f6rq.json | 8 ++------ .../03/GHSA-j4qq-hcfp-m638/GHSA-j4qq-hcfp-m638.json | 12 +++--------- .../03/GHSA-m7gg-q7qj-3r2r/GHSA-m7gg-q7qj-3r2r.json | 4 +--- .../03/GHSA-mq62-5vgw-569m/GHSA-mq62-5vgw-569m.json | 8 ++------ .../03/GHSA-q2qw-486m-j3c6/GHSA-q2qw-486m-j3c6.json | 12 +++--------- .../03/GHSA-q98h-hc6w-gjhg/GHSA-q98h-hc6w-gjhg.json | 12 +++--------- .../03/GHSA-qxmq-f8x5-rfg3/GHSA-qxmq-f8x5-rfg3.json | 8 ++------ .../03/GHSA-w45h-9jvc-v65p/GHSA-w45h-9jvc-v65p.json | 4 +--- .../03/GHSA-wfc2-g4f8-v6c3/GHSA-wfc2-g4f8-v6c3.json | 8 ++------ .../03/GHSA-whgx-jw4g-48ph/GHSA-whgx-jw4g-48ph.json | 12 +++--------- .../03/GHSA-wq2q-fqq7-mgvw/GHSA-wq2q-fqq7-mgvw.json | 8 ++------ .../03/GHSA-x5f4-w9r3-6rpq/GHSA-x5f4-w9r3-6rpq.json | 4 +--- .../03/GHSA-x8vw-5hgg-p3q8/GHSA-x8vw-5hgg-p3q8.json | 4 +--- 963 files changed, 2154 insertions(+), 6462 deletions(-) diff --git a/advisories/github-reviewed/2022/04/GHSA-gvj8-4cj4-h776/GHSA-gvj8-4cj4-h776.json b/advisories/github-reviewed/2022/04/GHSA-gvj8-4cj4-h776/GHSA-gvj8-4cj4-h776.json index 2a896620270..e24e596f254 100644 --- a/advisories/github-reviewed/2022/04/GHSA-gvj8-4cj4-h776/GHSA-gvj8-4cj4-h776.json +++ b/advisories/github-reviewed/2022/04/GHSA-gvj8-4cj4-h776/GHSA-gvj8-4cj4-h776.json @@ -3,14 +3,10 @@ "id": "GHSA-gvj8-4cj4-h776", "modified": "2022-04-29T15:40:48Z", "published": "2022-04-29T15:40:48Z", - "aliases": [ - - ], + "aliases": [], "summary": "Object state limitation has no effect", "details": "Object state limitation is a policy you can use in your roles to limit access to content based on specific object state values. Due to a flawed earlier update, these limitations were ineffective in releases made since February 16th 2022. They would grant access to the given content regardless of the object state. Depending on how your frontent is designed, knowing the URL to the content may or may not be required to access it. If you are using object state limitations in your roles, this issue is critical. Please apply the fix as soon as possible.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/04/GHSA-w8qp-hmh5-4v9v/GHSA-w8qp-hmh5-4v9v.json b/advisories/github-reviewed/2022/04/GHSA-w8qp-hmh5-4v9v/GHSA-w8qp-hmh5-4v9v.json index 547c5282822..e3ec738d5e6 100644 --- a/advisories/github-reviewed/2022/04/GHSA-w8qp-hmh5-4v9v/GHSA-w8qp-hmh5-4v9v.json +++ b/advisories/github-reviewed/2022/04/GHSA-w8qp-hmh5-4v9v/GHSA-w8qp-hmh5-4v9v.json @@ -3,14 +3,10 @@ "id": "GHSA-w8qp-hmh5-4v9v", "modified": "2022-04-29T16:22:58Z", "published": "2022-04-29T16:22:58Z", - "aliases": [ - - ], + "aliases": [], "summary": "Object state limitation has no effect", "details": "Object state limitation is a policy you can use in your roles to limit access to content based on specific object state values. Due to a flawed earlier update, these limitations were ineffective in releases made since February 16th 2022. They would grant access to the given content regardless of the object state. Depending on how your frontent is designed, knowing the URL to the content may or may not be required to access it. If you are using object state limitations in your roles, this issue is critical. Please apply the fix as soon as possible.\n\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/02/GHSA-22q8-ghmq-63vf/GHSA-22q8-ghmq-63vf.json b/advisories/github-reviewed/2024/02/GHSA-22q8-ghmq-63vf/GHSA-22q8-ghmq-63vf.json index 3e4b5d68eba..400e1485b50 100644 --- a/advisories/github-reviewed/2024/02/GHSA-22q8-ghmq-63vf/GHSA-22q8-ghmq-63vf.json +++ b/advisories/github-reviewed/2024/02/GHSA-22q8-ghmq-63vf/GHSA-22q8-ghmq-63vf.json @@ -3,9 +3,7 @@ "id": "GHSA-22q8-ghmq-63vf", "modified": "2024-02-12T15:42:14Z", "published": "2024-02-12T15:42:14Z", - "aliases": [ - - ], + "aliases": [], "summary": "libgit2-sys affected by memory corruption, denial of service, and arbitrary code execution in libgit2", "details": "The [libgit2](https://github.com/libgit2/libgit2/) project fixed three security issues in the 1.7.2 release. These issues are:\n\n* The `git_revparse_single` function can potentially enter an infinite loop on a well-crafted input, potentially causing a Denial of Service. This function is exposed in the `git2` crate via the [`Repository::revparse_single`](https://docs.rs/git2/latest/git2/struct.Repository.html#method.revparse_single) method.\n* The `git_index_add` function may cause heap corruption and possibly lead to arbitrary code execution. This function is exposed in the `git2` crate via the [`Index::add`](https://docs.rs/git2/latest/git2/struct.Index.html#method.add) method.\n* The smart transport negotiation may experience an out-of-bounds read when a remote server did not advertise capabilities.\n\nThe `libgit2-sys` crate bundles libgit2, or optionally links to a system libgit2 library. In either case, versions of the libgit2 library less than 1.7.2 are vulnerable. The 0.16.2 release of `libgit2-sys` bundles the fixed version of 1.7.2, and requires a system libgit2 version of at least 1.7.2.\n\nIt is recommended that all users upgrade.\n", "severity": [ @@ -60,9 +58,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-02-12T15:42:14Z", diff --git a/advisories/github-reviewed/2024/02/GHSA-6ccv-8fgf-cjpw/GHSA-6ccv-8fgf-cjpw.json b/advisories/github-reviewed/2024/02/GHSA-6ccv-8fgf-cjpw/GHSA-6ccv-8fgf-cjpw.json index 0b7c06d40f7..3afbc98c243 100644 --- a/advisories/github-reviewed/2024/02/GHSA-6ccv-8fgf-cjpw/GHSA-6ccv-8fgf-cjpw.json +++ b/advisories/github-reviewed/2024/02/GHSA-6ccv-8fgf-cjpw/GHSA-6ccv-8fgf-cjpw.json @@ -3,14 +3,10 @@ "id": "GHSA-6ccv-8fgf-cjpw", "modified": "2024-02-12T22:31:34Z", "published": "2024-02-12T22:31:34Z", - "aliases": [ - - ], + "aliases": [], "summary": "Drupal core Denial of Service vulnerability", "details": "The Comment module allows users to reply to comments. In certain cases, an attacker could make comment reply requests that would trigger a denial of service (DOS).\n\nSites that do not use the Comment module are not affected.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -74,9 +70,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-02-12T22:31:34Z", diff --git a/advisories/unreviewed/2022/01/GHSA-244j-xp9p-xr45/GHSA-244j-xp9p-xr45.json b/advisories/unreviewed/2022/01/GHSA-244j-xp9p-xr45/GHSA-244j-xp9p-xr45.json index 2022ae09daa..96c2f10162e 100644 --- a/advisories/unreviewed/2022/01/GHSA-244j-xp9p-xr45/GHSA-244j-xp9p-xr45.json +++ b/advisories/unreviewed/2022/01/GHSA-244j-xp9p-xr45/GHSA-244j-xp9p-xr45.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-2522-v35m-2r22/GHSA-2522-v35m-2r22.json b/advisories/unreviewed/2022/01/GHSA-2522-v35m-2r22/GHSA-2522-v35m-2r22.json index 70b5b77e17f..09cf2a70fcd 100644 --- a/advisories/unreviewed/2022/01/GHSA-2522-v35m-2r22/GHSA-2522-v35m-2r22.json +++ b/advisories/unreviewed/2022/01/GHSA-2522-v35m-2r22/GHSA-2522-v35m-2r22.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-2829-f4q2-487p/GHSA-2829-f4q2-487p.json b/advisories/unreviewed/2022/01/GHSA-2829-f4q2-487p/GHSA-2829-f4q2-487p.json index 134965727d9..0aaa38f3497 100644 --- a/advisories/unreviewed/2022/01/GHSA-2829-f4q2-487p/GHSA-2829-f4q2-487p.json +++ b/advisories/unreviewed/2022/01/GHSA-2829-f4q2-487p/GHSA-2829-f4q2-487p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-34vx-3926-gfg8/GHSA-34vx-3926-gfg8.json b/advisories/unreviewed/2022/01/GHSA-34vx-3926-gfg8/GHSA-34vx-3926-gfg8.json index e2b0f976552..495cf8a28d8 100644 --- a/advisories/unreviewed/2022/01/GHSA-34vx-3926-gfg8/GHSA-34vx-3926-gfg8.json +++ b/advisories/unreviewed/2022/01/GHSA-34vx-3926-gfg8/GHSA-34vx-3926-gfg8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-38r5-jq63-gvw6/GHSA-38r5-jq63-gvw6.json b/advisories/unreviewed/2022/01/GHSA-38r5-jq63-gvw6/GHSA-38r5-jq63-gvw6.json index a4354f0a7b5..0aa6f11ca77 100644 --- a/advisories/unreviewed/2022/01/GHSA-38r5-jq63-gvw6/GHSA-38r5-jq63-gvw6.json +++ b/advisories/unreviewed/2022/01/GHSA-38r5-jq63-gvw6/GHSA-38r5-jq63-gvw6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-3f3x-x2x3-wvhg/GHSA-3f3x-x2x3-wvhg.json b/advisories/unreviewed/2022/01/GHSA-3f3x-x2x3-wvhg/GHSA-3f3x-x2x3-wvhg.json index 03dc4907e56..06c2d01c883 100644 --- a/advisories/unreviewed/2022/01/GHSA-3f3x-x2x3-wvhg/GHSA-3f3x-x2x3-wvhg.json +++ b/advisories/unreviewed/2022/01/GHSA-3f3x-x2x3-wvhg/GHSA-3f3x-x2x3-wvhg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-3wpw-8xfm-9j79/GHSA-3wpw-8xfm-9j79.json b/advisories/unreviewed/2022/01/GHSA-3wpw-8xfm-9j79/GHSA-3wpw-8xfm-9j79.json index e34753d8fba..77057cedb38 100644 --- a/advisories/unreviewed/2022/01/GHSA-3wpw-8xfm-9j79/GHSA-3wpw-8xfm-9j79.json +++ b/advisories/unreviewed/2022/01/GHSA-3wpw-8xfm-9j79/GHSA-3wpw-8xfm-9j79.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-44x5-vv7x-rxj5/GHSA-44x5-vv7x-rxj5.json b/advisories/unreviewed/2022/01/GHSA-44x5-vv7x-rxj5/GHSA-44x5-vv7x-rxj5.json index b2820eb1ab0..19a880ab2a5 100644 --- a/advisories/unreviewed/2022/01/GHSA-44x5-vv7x-rxj5/GHSA-44x5-vv7x-rxj5.json +++ b/advisories/unreviewed/2022/01/GHSA-44x5-vv7x-rxj5/GHSA-44x5-vv7x-rxj5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-45mw-x2rr-9wpc/GHSA-45mw-x2rr-9wpc.json b/advisories/unreviewed/2022/01/GHSA-45mw-x2rr-9wpc/GHSA-45mw-x2rr-9wpc.json index a6f7b7baefb..47d7d1f464c 100644 --- a/advisories/unreviewed/2022/01/GHSA-45mw-x2rr-9wpc/GHSA-45mw-x2rr-9wpc.json +++ b/advisories/unreviewed/2022/01/GHSA-45mw-x2rr-9wpc/GHSA-45mw-x2rr-9wpc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-4vj4-c65w-6944/GHSA-4vj4-c65w-6944.json b/advisories/unreviewed/2022/01/GHSA-4vj4-c65w-6944/GHSA-4vj4-c65w-6944.json index 3f82d60e829..b0ac2fee821 100644 --- a/advisories/unreviewed/2022/01/GHSA-4vj4-c65w-6944/GHSA-4vj4-c65w-6944.json +++ b/advisories/unreviewed/2022/01/GHSA-4vj4-c65w-6944/GHSA-4vj4-c65w-6944.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-5qxw-jpqh-h83p/GHSA-5qxw-jpqh-h83p.json b/advisories/unreviewed/2022/01/GHSA-5qxw-jpqh-h83p/GHSA-5qxw-jpqh-h83p.json index f0a2aca3c59..b6acb7cfb08 100644 --- a/advisories/unreviewed/2022/01/GHSA-5qxw-jpqh-h83p/GHSA-5qxw-jpqh-h83p.json +++ b/advisories/unreviewed/2022/01/GHSA-5qxw-jpqh-h83p/GHSA-5qxw-jpqh-h83p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-624j-wgxh-4x2w/GHSA-624j-wgxh-4x2w.json b/advisories/unreviewed/2022/01/GHSA-624j-wgxh-4x2w/GHSA-624j-wgxh-4x2w.json index 3a4514f4376..6e781aadbea 100644 --- a/advisories/unreviewed/2022/01/GHSA-624j-wgxh-4x2w/GHSA-624j-wgxh-4x2w.json +++ b/advisories/unreviewed/2022/01/GHSA-624j-wgxh-4x2w/GHSA-624j-wgxh-4x2w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-6mww-ch69-p82p/GHSA-6mww-ch69-p82p.json b/advisories/unreviewed/2022/01/GHSA-6mww-ch69-p82p/GHSA-6mww-ch69-p82p.json index 8ee14680040..8442bfa99c7 100644 --- a/advisories/unreviewed/2022/01/GHSA-6mww-ch69-p82p/GHSA-6mww-ch69-p82p.json +++ b/advisories/unreviewed/2022/01/GHSA-6mww-ch69-p82p/GHSA-6mww-ch69-p82p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-6qgv-gg3v-w69g/GHSA-6qgv-gg3v-w69g.json b/advisories/unreviewed/2022/01/GHSA-6qgv-gg3v-w69g/GHSA-6qgv-gg3v-w69g.json index f303dbb7256..75816647bdf 100644 --- a/advisories/unreviewed/2022/01/GHSA-6qgv-gg3v-w69g/GHSA-6qgv-gg3v-w69g.json +++ b/advisories/unreviewed/2022/01/GHSA-6qgv-gg3v-w69g/GHSA-6qgv-gg3v-w69g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-74f6-jp2h-2vw3/GHSA-74f6-jp2h-2vw3.json b/advisories/unreviewed/2022/01/GHSA-74f6-jp2h-2vw3/GHSA-74f6-jp2h-2vw3.json index 0c02ae8e64b..0881c03241f 100644 --- a/advisories/unreviewed/2022/01/GHSA-74f6-jp2h-2vw3/GHSA-74f6-jp2h-2vw3.json +++ b/advisories/unreviewed/2022/01/GHSA-74f6-jp2h-2vw3/GHSA-74f6-jp2h-2vw3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-75xf-j8f2-9vxq/GHSA-75xf-j8f2-9vxq.json b/advisories/unreviewed/2022/01/GHSA-75xf-j8f2-9vxq/GHSA-75xf-j8f2-9vxq.json index c7ae81c1d7a..f2783419c5c 100644 --- a/advisories/unreviewed/2022/01/GHSA-75xf-j8f2-9vxq/GHSA-75xf-j8f2-9vxq.json +++ b/advisories/unreviewed/2022/01/GHSA-75xf-j8f2-9vxq/GHSA-75xf-j8f2-9vxq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-7668-4r26-7chc/GHSA-7668-4r26-7chc.json b/advisories/unreviewed/2022/01/GHSA-7668-4r26-7chc/GHSA-7668-4r26-7chc.json index 374d2983af1..7fe96220aaf 100644 --- a/advisories/unreviewed/2022/01/GHSA-7668-4r26-7chc/GHSA-7668-4r26-7chc.json +++ b/advisories/unreviewed/2022/01/GHSA-7668-4r26-7chc/GHSA-7668-4r26-7chc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-78wc-5whv-3wwg/GHSA-78wc-5whv-3wwg.json b/advisories/unreviewed/2022/01/GHSA-78wc-5whv-3wwg/GHSA-78wc-5whv-3wwg.json index 09521f43ebb..23793b5724a 100644 --- a/advisories/unreviewed/2022/01/GHSA-78wc-5whv-3wwg/GHSA-78wc-5whv-3wwg.json +++ b/advisories/unreviewed/2022/01/GHSA-78wc-5whv-3wwg/GHSA-78wc-5whv-3wwg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-8fq4-c2f3-pq2m/GHSA-8fq4-c2f3-pq2m.json b/advisories/unreviewed/2022/01/GHSA-8fq4-c2f3-pq2m/GHSA-8fq4-c2f3-pq2m.json index c61006b552e..765948ff9d8 100644 --- a/advisories/unreviewed/2022/01/GHSA-8fq4-c2f3-pq2m/GHSA-8fq4-c2f3-pq2m.json +++ b/advisories/unreviewed/2022/01/GHSA-8fq4-c2f3-pq2m/GHSA-8fq4-c2f3-pq2m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-8qvj-hvvg-8w4c/GHSA-8qvj-hvvg-8w4c.json b/advisories/unreviewed/2022/01/GHSA-8qvj-hvvg-8w4c/GHSA-8qvj-hvvg-8w4c.json index 94faeea15c0..14341673424 100644 --- a/advisories/unreviewed/2022/01/GHSA-8qvj-hvvg-8w4c/GHSA-8qvj-hvvg-8w4c.json +++ b/advisories/unreviewed/2022/01/GHSA-8qvj-hvvg-8w4c/GHSA-8qvj-hvvg-8w4c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-9gjj-g26q-4xmj/GHSA-9gjj-g26q-4xmj.json b/advisories/unreviewed/2022/01/GHSA-9gjj-g26q-4xmj/GHSA-9gjj-g26q-4xmj.json index d01ece4626e..d718d2bb60c 100644 --- a/advisories/unreviewed/2022/01/GHSA-9gjj-g26q-4xmj/GHSA-9gjj-g26q-4xmj.json +++ b/advisories/unreviewed/2022/01/GHSA-9gjj-g26q-4xmj/GHSA-9gjj-g26q-4xmj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-c6m3-26jj-88r9/GHSA-c6m3-26jj-88r9.json b/advisories/unreviewed/2022/01/GHSA-c6m3-26jj-88r9/GHSA-c6m3-26jj-88r9.json index 8124d008018..a01a11f7173 100644 --- a/advisories/unreviewed/2022/01/GHSA-c6m3-26jj-88r9/GHSA-c6m3-26jj-88r9.json +++ b/advisories/unreviewed/2022/01/GHSA-c6m3-26jj-88r9/GHSA-c6m3-26jj-88r9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-c8mf-xmr4-fx64/GHSA-c8mf-xmr4-fx64.json b/advisories/unreviewed/2022/01/GHSA-c8mf-xmr4-fx64/GHSA-c8mf-xmr4-fx64.json index a85e0f866b4..9bbb3c37b33 100644 --- a/advisories/unreviewed/2022/01/GHSA-c8mf-xmr4-fx64/GHSA-c8mf-xmr4-fx64.json +++ b/advisories/unreviewed/2022/01/GHSA-c8mf-xmr4-fx64/GHSA-c8mf-xmr4-fx64.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-cqqw-769j-6gm9/GHSA-cqqw-769j-6gm9.json b/advisories/unreviewed/2022/01/GHSA-cqqw-769j-6gm9/GHSA-cqqw-769j-6gm9.json index ff76f11e082..96da4723e70 100644 --- a/advisories/unreviewed/2022/01/GHSA-cqqw-769j-6gm9/GHSA-cqqw-769j-6gm9.json +++ b/advisories/unreviewed/2022/01/GHSA-cqqw-769j-6gm9/GHSA-cqqw-769j-6gm9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-fc93-89fq-8669/GHSA-fc93-89fq-8669.json b/advisories/unreviewed/2022/01/GHSA-fc93-89fq-8669/GHSA-fc93-89fq-8669.json index 790b18c4452..0a1781d8a00 100644 --- a/advisories/unreviewed/2022/01/GHSA-fc93-89fq-8669/GHSA-fc93-89fq-8669.json +++ b/advisories/unreviewed/2022/01/GHSA-fc93-89fq-8669/GHSA-fc93-89fq-8669.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-fhmq-5697-m94q/GHSA-fhmq-5697-m94q.json b/advisories/unreviewed/2022/01/GHSA-fhmq-5697-m94q/GHSA-fhmq-5697-m94q.json index c91f843e8ed..11ac89b2c19 100644 --- a/advisories/unreviewed/2022/01/GHSA-fhmq-5697-m94q/GHSA-fhmq-5697-m94q.json +++ b/advisories/unreviewed/2022/01/GHSA-fhmq-5697-m94q/GHSA-fhmq-5697-m94q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-fpm5-5f53-975w/GHSA-fpm5-5f53-975w.json b/advisories/unreviewed/2022/01/GHSA-fpm5-5f53-975w/GHSA-fpm5-5f53-975w.json index b65c63875a8..759b5978a63 100644 --- a/advisories/unreviewed/2022/01/GHSA-fpm5-5f53-975w/GHSA-fpm5-5f53-975w.json +++ b/advisories/unreviewed/2022/01/GHSA-fpm5-5f53-975w/GHSA-fpm5-5f53-975w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-gg45-6m56-hjqc/GHSA-gg45-6m56-hjqc.json b/advisories/unreviewed/2022/01/GHSA-gg45-6m56-hjqc/GHSA-gg45-6m56-hjqc.json index 0fa33e6c6e6..439eec4aab0 100644 --- a/advisories/unreviewed/2022/01/GHSA-gg45-6m56-hjqc/GHSA-gg45-6m56-hjqc.json +++ b/advisories/unreviewed/2022/01/GHSA-gg45-6m56-hjqc/GHSA-gg45-6m56-hjqc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-gq64-xh72-gm28/GHSA-gq64-xh72-gm28.json b/advisories/unreviewed/2022/01/GHSA-gq64-xh72-gm28/GHSA-gq64-xh72-gm28.json index 7b5b6ac88f8..bd82cf2715a 100644 --- a/advisories/unreviewed/2022/01/GHSA-gq64-xh72-gm28/GHSA-gq64-xh72-gm28.json +++ b/advisories/unreviewed/2022/01/GHSA-gq64-xh72-gm28/GHSA-gq64-xh72-gm28.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-hh9q-3234-5wjp/GHSA-hh9q-3234-5wjp.json b/advisories/unreviewed/2022/01/GHSA-hh9q-3234-5wjp/GHSA-hh9q-3234-5wjp.json index c37712d6763..bde44dcf38b 100644 --- a/advisories/unreviewed/2022/01/GHSA-hh9q-3234-5wjp/GHSA-hh9q-3234-5wjp.json +++ b/advisories/unreviewed/2022/01/GHSA-hh9q-3234-5wjp/GHSA-hh9q-3234-5wjp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-hvh7-f5p9-68g8/GHSA-hvh7-f5p9-68g8.json b/advisories/unreviewed/2022/01/GHSA-hvh7-f5p9-68g8/GHSA-hvh7-f5p9-68g8.json index 3b61c993389..91893490c78 100644 --- a/advisories/unreviewed/2022/01/GHSA-hvh7-f5p9-68g8/GHSA-hvh7-f5p9-68g8.json +++ b/advisories/unreviewed/2022/01/GHSA-hvh7-f5p9-68g8/GHSA-hvh7-f5p9-68g8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-j6rg-mpmv-h73q/GHSA-j6rg-mpmv-h73q.json b/advisories/unreviewed/2022/01/GHSA-j6rg-mpmv-h73q/GHSA-j6rg-mpmv-h73q.json index 63d7dcea887..343e336eab2 100644 --- a/advisories/unreviewed/2022/01/GHSA-j6rg-mpmv-h73q/GHSA-j6rg-mpmv-h73q.json +++ b/advisories/unreviewed/2022/01/GHSA-j6rg-mpmv-h73q/GHSA-j6rg-mpmv-h73q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-j7c5-g427-27ch/GHSA-j7c5-g427-27ch.json b/advisories/unreviewed/2022/01/GHSA-j7c5-g427-27ch/GHSA-j7c5-g427-27ch.json index 6f1cb8e28bc..0359988133d 100644 --- a/advisories/unreviewed/2022/01/GHSA-j7c5-g427-27ch/GHSA-j7c5-g427-27ch.json +++ b/advisories/unreviewed/2022/01/GHSA-j7c5-g427-27ch/GHSA-j7c5-g427-27ch.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-jm36-4mv9-x2pw/GHSA-jm36-4mv9-x2pw.json b/advisories/unreviewed/2022/01/GHSA-jm36-4mv9-x2pw/GHSA-jm36-4mv9-x2pw.json index 9d0832a8508..059fd73210d 100644 --- a/advisories/unreviewed/2022/01/GHSA-jm36-4mv9-x2pw/GHSA-jm36-4mv9-x2pw.json +++ b/advisories/unreviewed/2022/01/GHSA-jm36-4mv9-x2pw/GHSA-jm36-4mv9-x2pw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-jx53-3cxj-386g/GHSA-jx53-3cxj-386g.json b/advisories/unreviewed/2022/01/GHSA-jx53-3cxj-386g/GHSA-jx53-3cxj-386g.json index eb1c6f6a97f..26751bc939f 100644 --- a/advisories/unreviewed/2022/01/GHSA-jx53-3cxj-386g/GHSA-jx53-3cxj-386g.json +++ b/advisories/unreviewed/2022/01/GHSA-jx53-3cxj-386g/GHSA-jx53-3cxj-386g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-jxv7-pgr4-p3g5/GHSA-jxv7-pgr4-p3g5.json b/advisories/unreviewed/2022/01/GHSA-jxv7-pgr4-p3g5/GHSA-jxv7-pgr4-p3g5.json index 819b8e1a51e..45e21d1f674 100644 --- a/advisories/unreviewed/2022/01/GHSA-jxv7-pgr4-p3g5/GHSA-jxv7-pgr4-p3g5.json +++ b/advisories/unreviewed/2022/01/GHSA-jxv7-pgr4-p3g5/GHSA-jxv7-pgr4-p3g5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-mp4c-vqqf-2qxg/GHSA-mp4c-vqqf-2qxg.json b/advisories/unreviewed/2022/01/GHSA-mp4c-vqqf-2qxg/GHSA-mp4c-vqqf-2qxg.json index d19ca3e1607..110db915837 100644 --- a/advisories/unreviewed/2022/01/GHSA-mp4c-vqqf-2qxg/GHSA-mp4c-vqqf-2qxg.json +++ b/advisories/unreviewed/2022/01/GHSA-mp4c-vqqf-2qxg/GHSA-mp4c-vqqf-2qxg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-phg8-x4rr-qpgf/GHSA-phg8-x4rr-qpgf.json b/advisories/unreviewed/2022/01/GHSA-phg8-x4rr-qpgf/GHSA-phg8-x4rr-qpgf.json index 08cc9a38cfc..e7cf1959a7d 100644 --- a/advisories/unreviewed/2022/01/GHSA-phg8-x4rr-qpgf/GHSA-phg8-x4rr-qpgf.json +++ b/advisories/unreviewed/2022/01/GHSA-phg8-x4rr-qpgf/GHSA-phg8-x4rr-qpgf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-qcmm-58xj-wh4r/GHSA-qcmm-58xj-wh4r.json b/advisories/unreviewed/2022/01/GHSA-qcmm-58xj-wh4r/GHSA-qcmm-58xj-wh4r.json index 414e74f2296..51f1d7ba7f1 100644 --- a/advisories/unreviewed/2022/01/GHSA-qcmm-58xj-wh4r/GHSA-qcmm-58xj-wh4r.json +++ b/advisories/unreviewed/2022/01/GHSA-qcmm-58xj-wh4r/GHSA-qcmm-58xj-wh4r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-qf8x-c298-x5pj/GHSA-qf8x-c298-x5pj.json b/advisories/unreviewed/2022/01/GHSA-qf8x-c298-x5pj/GHSA-qf8x-c298-x5pj.json index 7b6cae691a5..548f25cab3d 100644 --- a/advisories/unreviewed/2022/01/GHSA-qf8x-c298-x5pj/GHSA-qf8x-c298-x5pj.json +++ b/advisories/unreviewed/2022/01/GHSA-qf8x-c298-x5pj/GHSA-qf8x-c298-x5pj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-qx9v-9g4v-j92f/GHSA-qx9v-9g4v-j92f.json b/advisories/unreviewed/2022/01/GHSA-qx9v-9g4v-j92f/GHSA-qx9v-9g4v-j92f.json index c8985628680..99be0a5b867 100644 --- a/advisories/unreviewed/2022/01/GHSA-qx9v-9g4v-j92f/GHSA-qx9v-9g4v-j92f.json +++ b/advisories/unreviewed/2022/01/GHSA-qx9v-9g4v-j92f/GHSA-qx9v-9g4v-j92f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-r8rw-g922-j95j/GHSA-r8rw-g922-j95j.json b/advisories/unreviewed/2022/01/GHSA-r8rw-g922-j95j/GHSA-r8rw-g922-j95j.json index 78de28390c2..74db077db53 100644 --- a/advisories/unreviewed/2022/01/GHSA-r8rw-g922-j95j/GHSA-r8rw-g922-j95j.json +++ b/advisories/unreviewed/2022/01/GHSA-r8rw-g922-j95j/GHSA-r8rw-g922-j95j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-r9gp-v7qw-28p5/GHSA-r9gp-v7qw-28p5.json b/advisories/unreviewed/2022/01/GHSA-r9gp-v7qw-28p5/GHSA-r9gp-v7qw-28p5.json index d847954390d..118b0ae0626 100644 --- a/advisories/unreviewed/2022/01/GHSA-r9gp-v7qw-28p5/GHSA-r9gp-v7qw-28p5.json +++ b/advisories/unreviewed/2022/01/GHSA-r9gp-v7qw-28p5/GHSA-r9gp-v7qw-28p5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-rgf9-28hg-x4c8/GHSA-rgf9-28hg-x4c8.json b/advisories/unreviewed/2022/01/GHSA-rgf9-28hg-x4c8/GHSA-rgf9-28hg-x4c8.json index 03e1ee4140a..99ee49b5de4 100644 --- a/advisories/unreviewed/2022/01/GHSA-rgf9-28hg-x4c8/GHSA-rgf9-28hg-x4c8.json +++ b/advisories/unreviewed/2022/01/GHSA-rgf9-28hg-x4c8/GHSA-rgf9-28hg-x4c8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-v63v-32vm-px2m/GHSA-v63v-32vm-px2m.json b/advisories/unreviewed/2022/01/GHSA-v63v-32vm-px2m/GHSA-v63v-32vm-px2m.json index fe225017533..b91c53e9eb7 100644 --- a/advisories/unreviewed/2022/01/GHSA-v63v-32vm-px2m/GHSA-v63v-32vm-px2m.json +++ b/advisories/unreviewed/2022/01/GHSA-v63v-32vm-px2m/GHSA-v63v-32vm-px2m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-v6rf-w7jv-9fmc/GHSA-v6rf-w7jv-9fmc.json b/advisories/unreviewed/2022/01/GHSA-v6rf-w7jv-9fmc/GHSA-v6rf-w7jv-9fmc.json index 2006cee5ad6..d9b4c6a8f22 100644 --- a/advisories/unreviewed/2022/01/GHSA-v6rf-w7jv-9fmc/GHSA-v6rf-w7jv-9fmc.json +++ b/advisories/unreviewed/2022/01/GHSA-v6rf-w7jv-9fmc/GHSA-v6rf-w7jv-9fmc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-w6w3-wf72-pc3c/GHSA-w6w3-wf72-pc3c.json b/advisories/unreviewed/2022/01/GHSA-w6w3-wf72-pc3c/GHSA-w6w3-wf72-pc3c.json index 35369969bab..d71bed39d1d 100644 --- a/advisories/unreviewed/2022/01/GHSA-w6w3-wf72-pc3c/GHSA-w6w3-wf72-pc3c.json +++ b/advisories/unreviewed/2022/01/GHSA-w6w3-wf72-pc3c/GHSA-w6w3-wf72-pc3c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-wrgg-vhm7-9frx/GHSA-wrgg-vhm7-9frx.json b/advisories/unreviewed/2022/01/GHSA-wrgg-vhm7-9frx/GHSA-wrgg-vhm7-9frx.json index e03214f4fba..346647d4d79 100644 --- a/advisories/unreviewed/2022/01/GHSA-wrgg-vhm7-9frx/GHSA-wrgg-vhm7-9frx.json +++ b/advisories/unreviewed/2022/01/GHSA-wrgg-vhm7-9frx/GHSA-wrgg-vhm7-9frx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-x96q-w32v-vmr6/GHSA-x96q-w32v-vmr6.json b/advisories/unreviewed/2022/01/GHSA-x96q-w32v-vmr6/GHSA-x96q-w32v-vmr6.json index 97f8e9808bf..52ad41aad4e 100644 --- a/advisories/unreviewed/2022/01/GHSA-x96q-w32v-vmr6/GHSA-x96q-w32v-vmr6.json +++ b/advisories/unreviewed/2022/01/GHSA-x96q-w32v-vmr6/GHSA-x96q-w32v-vmr6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-xcjr-gm58-gw5q/GHSA-xcjr-gm58-gw5q.json b/advisories/unreviewed/2022/01/GHSA-xcjr-gm58-gw5q/GHSA-xcjr-gm58-gw5q.json index 7938cb2ee43..2cf88a37f8d 100644 --- a/advisories/unreviewed/2022/01/GHSA-xcjr-gm58-gw5q/GHSA-xcjr-gm58-gw5q.json +++ b/advisories/unreviewed/2022/01/GHSA-xcjr-gm58-gw5q/GHSA-xcjr-gm58-gw5q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-xqcg-xx67-m64q/GHSA-xqcg-xx67-m64q.json b/advisories/unreviewed/2022/01/GHSA-xqcg-xx67-m64q/GHSA-xqcg-xx67-m64q.json index 740d1912684..1d92ad4f831 100644 --- a/advisories/unreviewed/2022/01/GHSA-xqcg-xx67-m64q/GHSA-xqcg-xx67-m64q.json +++ b/advisories/unreviewed/2022/01/GHSA-xqcg-xx67-m64q/GHSA-xqcg-xx67-m64q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-2vw5-8fhm-cvqc/GHSA-2vw5-8fhm-cvqc.json b/advisories/unreviewed/2022/02/GHSA-2vw5-8fhm-cvqc/GHSA-2vw5-8fhm-cvqc.json index ecd7be8cb21..3b54a26fecf 100644 --- a/advisories/unreviewed/2022/02/GHSA-2vw5-8fhm-cvqc/GHSA-2vw5-8fhm-cvqc.json +++ b/advisories/unreviewed/2022/02/GHSA-2vw5-8fhm-cvqc/GHSA-2vw5-8fhm-cvqc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-3mj9-r4cx-8mx5/GHSA-3mj9-r4cx-8mx5.json b/advisories/unreviewed/2022/02/GHSA-3mj9-r4cx-8mx5/GHSA-3mj9-r4cx-8mx5.json index 0c8475a0c79..dff4ebabda9 100644 --- a/advisories/unreviewed/2022/02/GHSA-3mj9-r4cx-8mx5/GHSA-3mj9-r4cx-8mx5.json +++ b/advisories/unreviewed/2022/02/GHSA-3mj9-r4cx-8mx5/GHSA-3mj9-r4cx-8mx5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-56jf-qqrc-2h69/GHSA-56jf-qqrc-2h69.json b/advisories/unreviewed/2022/02/GHSA-56jf-qqrc-2h69/GHSA-56jf-qqrc-2h69.json index 5c10e5a8019..54e5ef0d5d8 100644 --- a/advisories/unreviewed/2022/02/GHSA-56jf-qqrc-2h69/GHSA-56jf-qqrc-2h69.json +++ b/advisories/unreviewed/2022/02/GHSA-56jf-qqrc-2h69/GHSA-56jf-qqrc-2h69.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-59h2-qw44-f67r/GHSA-59h2-qw44-f67r.json b/advisories/unreviewed/2022/02/GHSA-59h2-qw44-f67r/GHSA-59h2-qw44-f67r.json index 767e0429e83..c8f8777aeca 100644 --- a/advisories/unreviewed/2022/02/GHSA-59h2-qw44-f67r/GHSA-59h2-qw44-f67r.json +++ b/advisories/unreviewed/2022/02/GHSA-59h2-qw44-f67r/GHSA-59h2-qw44-f67r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-6c2j-x443-7jc3/GHSA-6c2j-x443-7jc3.json b/advisories/unreviewed/2022/02/GHSA-6c2j-x443-7jc3/GHSA-6c2j-x443-7jc3.json index 53817c41757..a857da27607 100644 --- a/advisories/unreviewed/2022/02/GHSA-6c2j-x443-7jc3/GHSA-6c2j-x443-7jc3.json +++ b/advisories/unreviewed/2022/02/GHSA-6c2j-x443-7jc3/GHSA-6c2j-x443-7jc3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-6xjp-85f8-j93c/GHSA-6xjp-85f8-j93c.json b/advisories/unreviewed/2022/02/GHSA-6xjp-85f8-j93c/GHSA-6xjp-85f8-j93c.json index 27235cf1f76..6c33dcc61a1 100644 --- a/advisories/unreviewed/2022/02/GHSA-6xjp-85f8-j93c/GHSA-6xjp-85f8-j93c.json +++ b/advisories/unreviewed/2022/02/GHSA-6xjp-85f8-j93c/GHSA-6xjp-85f8-j93c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-84hw-gj94-jqrm/GHSA-84hw-gj94-jqrm.json b/advisories/unreviewed/2022/02/GHSA-84hw-gj94-jqrm/GHSA-84hw-gj94-jqrm.json index b15bc3f988a..2b6a8f9e370 100644 --- a/advisories/unreviewed/2022/02/GHSA-84hw-gj94-jqrm/GHSA-84hw-gj94-jqrm.json +++ b/advisories/unreviewed/2022/02/GHSA-84hw-gj94-jqrm/GHSA-84hw-gj94-jqrm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-c3p4-6x5w-74fx/GHSA-c3p4-6x5w-74fx.json b/advisories/unreviewed/2022/02/GHSA-c3p4-6x5w-74fx/GHSA-c3p4-6x5w-74fx.json index 93f9fd89deb..2c6a2da6b7f 100644 --- a/advisories/unreviewed/2022/02/GHSA-c3p4-6x5w-74fx/GHSA-c3p4-6x5w-74fx.json +++ b/advisories/unreviewed/2022/02/GHSA-c3p4-6x5w-74fx/GHSA-c3p4-6x5w-74fx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-cwhj-hjpj-c7pg/GHSA-cwhj-hjpj-c7pg.json b/advisories/unreviewed/2022/02/GHSA-cwhj-hjpj-c7pg/GHSA-cwhj-hjpj-c7pg.json index fd38d2b44cf..31da2868a09 100644 --- a/advisories/unreviewed/2022/02/GHSA-cwhj-hjpj-c7pg/GHSA-cwhj-hjpj-c7pg.json +++ b/advisories/unreviewed/2022/02/GHSA-cwhj-hjpj-c7pg/GHSA-cwhj-hjpj-c7pg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-f9cx-48m4-2xp7/GHSA-f9cx-48m4-2xp7.json b/advisories/unreviewed/2022/02/GHSA-f9cx-48m4-2xp7/GHSA-f9cx-48m4-2xp7.json index cb597c3aee6..e193f28e582 100644 --- a/advisories/unreviewed/2022/02/GHSA-f9cx-48m4-2xp7/GHSA-f9cx-48m4-2xp7.json +++ b/advisories/unreviewed/2022/02/GHSA-f9cx-48m4-2xp7/GHSA-f9cx-48m4-2xp7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-f9wp-vh4x-jjw7/GHSA-f9wp-vh4x-jjw7.json b/advisories/unreviewed/2022/02/GHSA-f9wp-vh4x-jjw7/GHSA-f9wp-vh4x-jjw7.json index d15ef39aeaa..18ca545996b 100644 --- a/advisories/unreviewed/2022/02/GHSA-f9wp-vh4x-jjw7/GHSA-f9wp-vh4x-jjw7.json +++ b/advisories/unreviewed/2022/02/GHSA-f9wp-vh4x-jjw7/GHSA-f9wp-vh4x-jjw7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-hfj6-rq3w-f48r/GHSA-hfj6-rq3w-f48r.json b/advisories/unreviewed/2022/02/GHSA-hfj6-rq3w-f48r/GHSA-hfj6-rq3w-f48r.json index ca6fb5dc4dd..ae2c27cbe2a 100644 --- a/advisories/unreviewed/2022/02/GHSA-hfj6-rq3w-f48r/GHSA-hfj6-rq3w-f48r.json +++ b/advisories/unreviewed/2022/02/GHSA-hfj6-rq3w-f48r/GHSA-hfj6-rq3w-f48r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-hgww-4988-8569/GHSA-hgww-4988-8569.json b/advisories/unreviewed/2022/02/GHSA-hgww-4988-8569/GHSA-hgww-4988-8569.json index 7d8df164138..6cb51121ed9 100644 --- a/advisories/unreviewed/2022/02/GHSA-hgww-4988-8569/GHSA-hgww-4988-8569.json +++ b/advisories/unreviewed/2022/02/GHSA-hgww-4988-8569/GHSA-hgww-4988-8569.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-hmx6-wg4q-3825/GHSA-hmx6-wg4q-3825.json b/advisories/unreviewed/2022/02/GHSA-hmx6-wg4q-3825/GHSA-hmx6-wg4q-3825.json index 0e93ca78386..894c3fda4cd 100644 --- a/advisories/unreviewed/2022/02/GHSA-hmx6-wg4q-3825/GHSA-hmx6-wg4q-3825.json +++ b/advisories/unreviewed/2022/02/GHSA-hmx6-wg4q-3825/GHSA-hmx6-wg4q-3825.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-jjh6-7r67-w858/GHSA-jjh6-7r67-w858.json b/advisories/unreviewed/2022/02/GHSA-jjh6-7r67-w858/GHSA-jjh6-7r67-w858.json index e546035ab72..e88facd32b5 100644 --- a/advisories/unreviewed/2022/02/GHSA-jjh6-7r67-w858/GHSA-jjh6-7r67-w858.json +++ b/advisories/unreviewed/2022/02/GHSA-jjh6-7r67-w858/GHSA-jjh6-7r67-w858.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-mqcr-p73p-f4gw/GHSA-mqcr-p73p-f4gw.json b/advisories/unreviewed/2022/02/GHSA-mqcr-p73p-f4gw/GHSA-mqcr-p73p-f4gw.json index 691ce7a32e0..228cf07b57a 100644 --- a/advisories/unreviewed/2022/02/GHSA-mqcr-p73p-f4gw/GHSA-mqcr-p73p-f4gw.json +++ b/advisories/unreviewed/2022/02/GHSA-mqcr-p73p-f4gw/GHSA-mqcr-p73p-f4gw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-pjg5-4frx-8m6r/GHSA-pjg5-4frx-8m6r.json b/advisories/unreviewed/2022/02/GHSA-pjg5-4frx-8m6r/GHSA-pjg5-4frx-8m6r.json index 225b3575c18..c4432c807cb 100644 --- a/advisories/unreviewed/2022/02/GHSA-pjg5-4frx-8m6r/GHSA-pjg5-4frx-8m6r.json +++ b/advisories/unreviewed/2022/02/GHSA-pjg5-4frx-8m6r/GHSA-pjg5-4frx-8m6r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-pm6q-mcg4-jmhv/GHSA-pm6q-mcg4-jmhv.json b/advisories/unreviewed/2022/02/GHSA-pm6q-mcg4-jmhv/GHSA-pm6q-mcg4-jmhv.json index 69037a8bf37..b5994daf757 100644 --- a/advisories/unreviewed/2022/02/GHSA-pm6q-mcg4-jmhv/GHSA-pm6q-mcg4-jmhv.json +++ b/advisories/unreviewed/2022/02/GHSA-pm6q-mcg4-jmhv/GHSA-pm6q-mcg4-jmhv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-pvxv-cw79-c2x3/GHSA-pvxv-cw79-c2x3.json b/advisories/unreviewed/2022/02/GHSA-pvxv-cw79-c2x3/GHSA-pvxv-cw79-c2x3.json index eff7b458325..524b7dee006 100644 --- a/advisories/unreviewed/2022/02/GHSA-pvxv-cw79-c2x3/GHSA-pvxv-cw79-c2x3.json +++ b/advisories/unreviewed/2022/02/GHSA-pvxv-cw79-c2x3/GHSA-pvxv-cw79-c2x3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-pwhp-6h3m-r2xh/GHSA-pwhp-6h3m-r2xh.json b/advisories/unreviewed/2022/02/GHSA-pwhp-6h3m-r2xh/GHSA-pwhp-6h3m-r2xh.json index 4ee3be9fc29..ab2235b6752 100644 --- a/advisories/unreviewed/2022/02/GHSA-pwhp-6h3m-r2xh/GHSA-pwhp-6h3m-r2xh.json +++ b/advisories/unreviewed/2022/02/GHSA-pwhp-6h3m-r2xh/GHSA-pwhp-6h3m-r2xh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-qhx3-4p72-9vg9/GHSA-qhx3-4p72-9vg9.json b/advisories/unreviewed/2022/02/GHSA-qhx3-4p72-9vg9/GHSA-qhx3-4p72-9vg9.json index c816de6a43e..07670dc0e57 100644 --- a/advisories/unreviewed/2022/02/GHSA-qhx3-4p72-9vg9/GHSA-qhx3-4p72-9vg9.json +++ b/advisories/unreviewed/2022/02/GHSA-qhx3-4p72-9vg9/GHSA-qhx3-4p72-9vg9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-qhxw-jx34-g2pf/GHSA-qhxw-jx34-g2pf.json b/advisories/unreviewed/2022/02/GHSA-qhxw-jx34-g2pf/GHSA-qhxw-jx34-g2pf.json index 040dac07c07..214b0e02da1 100644 --- a/advisories/unreviewed/2022/02/GHSA-qhxw-jx34-g2pf/GHSA-qhxw-jx34-g2pf.json +++ b/advisories/unreviewed/2022/02/GHSA-qhxw-jx34-g2pf/GHSA-qhxw-jx34-g2pf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-rcf2-975r-j599/GHSA-rcf2-975r-j599.json b/advisories/unreviewed/2022/02/GHSA-rcf2-975r-j599/GHSA-rcf2-975r-j599.json index be65d8bbbbc..59928c5abce 100644 --- a/advisories/unreviewed/2022/02/GHSA-rcf2-975r-j599/GHSA-rcf2-975r-j599.json +++ b/advisories/unreviewed/2022/02/GHSA-rcf2-975r-j599/GHSA-rcf2-975r-j599.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-v4wx-vjh5-hw9r/GHSA-v4wx-vjh5-hw9r.json b/advisories/unreviewed/2022/02/GHSA-v4wx-vjh5-hw9r/GHSA-v4wx-vjh5-hw9r.json index e54c7026f36..37a45cd211a 100644 --- a/advisories/unreviewed/2022/02/GHSA-v4wx-vjh5-hw9r/GHSA-v4wx-vjh5-hw9r.json +++ b/advisories/unreviewed/2022/02/GHSA-v4wx-vjh5-hw9r/GHSA-v4wx-vjh5-hw9r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-vcm5-6w8c-v573/GHSA-vcm5-6w8c-v573.json b/advisories/unreviewed/2022/02/GHSA-vcm5-6w8c-v573/GHSA-vcm5-6w8c-v573.json index f5f3ad2dab0..a8fcf9a6546 100644 --- a/advisories/unreviewed/2022/02/GHSA-vcm5-6w8c-v573/GHSA-vcm5-6w8c-v573.json +++ b/advisories/unreviewed/2022/02/GHSA-vcm5-6w8c-v573/GHSA-vcm5-6w8c-v573.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-xg7w-9w3p-gqx3/GHSA-xg7w-9w3p-gqx3.json b/advisories/unreviewed/2022/02/GHSA-xg7w-9w3p-gqx3/GHSA-xg7w-9w3p-gqx3.json index 800db211a59..1f7ff4a3980 100644 --- a/advisories/unreviewed/2022/02/GHSA-xg7w-9w3p-gqx3/GHSA-xg7w-9w3p-gqx3.json +++ b/advisories/unreviewed/2022/02/GHSA-xg7w-9w3p-gqx3/GHSA-xg7w-9w3p-gqx3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-xmgg-9fr8-3f5f/GHSA-xmgg-9fr8-3f5f.json b/advisories/unreviewed/2022/02/GHSA-xmgg-9fr8-3f5f/GHSA-xmgg-9fr8-3f5f.json index dd9e80d87a4..679a53dbce5 100644 --- a/advisories/unreviewed/2022/02/GHSA-xmgg-9fr8-3f5f/GHSA-xmgg-9fr8-3f5f.json +++ b/advisories/unreviewed/2022/02/GHSA-xmgg-9fr8-3f5f/GHSA-xmgg-9fr8-3f5f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-xxh4-49r4-6rx5/GHSA-xxh4-49r4-6rx5.json b/advisories/unreviewed/2022/02/GHSA-xxh4-49r4-6rx5/GHSA-xxh4-49r4-6rx5.json index 7bd272c9e53..53e5f488737 100644 --- a/advisories/unreviewed/2022/02/GHSA-xxh4-49r4-6rx5/GHSA-xxh4-49r4-6rx5.json +++ b/advisories/unreviewed/2022/02/GHSA-xxh4-49r4-6rx5/GHSA-xxh4-49r4-6rx5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-2375-ph49-69c5/GHSA-2375-ph49-69c5.json b/advisories/unreviewed/2022/04/GHSA-2375-ph49-69c5/GHSA-2375-ph49-69c5.json index 53c6affa5cf..b22d13c74a6 100644 --- a/advisories/unreviewed/2022/04/GHSA-2375-ph49-69c5/GHSA-2375-ph49-69c5.json +++ b/advisories/unreviewed/2022/04/GHSA-2375-ph49-69c5/GHSA-2375-ph49-69c5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-23w8-jcvm-j4jg/GHSA-23w8-jcvm-j4jg.json b/advisories/unreviewed/2022/04/GHSA-23w8-jcvm-j4jg/GHSA-23w8-jcvm-j4jg.json index d0fbeafb784..4f28d05d038 100644 --- a/advisories/unreviewed/2022/04/GHSA-23w8-jcvm-j4jg/GHSA-23w8-jcvm-j4jg.json +++ b/advisories/unreviewed/2022/04/GHSA-23w8-jcvm-j4jg/GHSA-23w8-jcvm-j4jg.json @@ -7,12 +7,8 @@ "CVE-2004-2533" ], "details": "Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a \"\\\\...\\\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-26fg-x3pj-c24v/GHSA-26fg-x3pj-c24v.json b/advisories/unreviewed/2022/04/GHSA-26fg-x3pj-c24v/GHSA-26fg-x3pj-c24v.json index 273425d72b3..7bba2331e88 100644 --- a/advisories/unreviewed/2022/04/GHSA-26fg-x3pj-c24v/GHSA-26fg-x3pj-c24v.json +++ b/advisories/unreviewed/2022/04/GHSA-26fg-x3pj-c24v/GHSA-26fg-x3pj-c24v.json @@ -7,12 +7,8 @@ "CVE-2004-2511" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the year, (2) month, and (3) day parameters in calendar.php; (4) the cid and (5) url parameters in index.php; (6) the cid parameter in annoucement.php; (7) the cid parameter in news.php; (8) the cid parameter in contents.php; (9) the q parameter in search.php; and (10) the country parameter in register.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-26r4-3m3w-c772/GHSA-26r4-3m3w-c772.json b/advisories/unreviewed/2022/04/GHSA-26r4-3m3w-c772/GHSA-26r4-3m3w-c772.json index 19abe25e7a6..8b2db372dd3 100644 --- a/advisories/unreviewed/2022/04/GHSA-26r4-3m3w-c772/GHSA-26r4-3m3w-c772.json +++ b/advisories/unreviewed/2022/04/GHSA-26r4-3m3w-c772/GHSA-26r4-3m3w-c772.json @@ -7,12 +7,8 @@ "CVE-2004-2526" ], "details": "Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2jm4-cm7h-hghg/GHSA-2jm4-cm7h-hghg.json b/advisories/unreviewed/2022/04/GHSA-2jm4-cm7h-hghg/GHSA-2jm4-cm7h-hghg.json index da8a888a475..41ac2e9c760 100644 --- a/advisories/unreviewed/2022/04/GHSA-2jm4-cm7h-hghg/GHSA-2jm4-cm7h-hghg.json +++ b/advisories/unreviewed/2022/04/GHSA-2jm4-cm7h-hghg/GHSA-2jm4-cm7h-hghg.json @@ -7,12 +7,8 @@ "CVE-2004-2703" ], "details": "Clearswift MIMEsweeper 5.0.5, when it has been upgraded from MAILsweeper for SMTP version 4.3 or MAILsweeper Business Suite I or II, allows remote attackers to bypass scanning by including encrypted data in a mail message, which causes the message to be marked as \"Clean\" instead of \"Encrypted\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2q4p-93p8-q2j6/GHSA-2q4p-93p8-q2j6.json b/advisories/unreviewed/2022/04/GHSA-2q4p-93p8-q2j6/GHSA-2q4p-93p8-q2j6.json index 228cad0ac62..ec8486a2c01 100644 --- a/advisories/unreviewed/2022/04/GHSA-2q4p-93p8-q2j6/GHSA-2q4p-93p8-q2j6.json +++ b/advisories/unreviewed/2022/04/GHSA-2q4p-93p8-q2j6/GHSA-2q4p-93p8-q2j6.json @@ -7,12 +7,8 @@ "CVE-2004-2761" ], "details": "The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509 certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -124,9 +120,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2qh3-fm9g-rf2x/GHSA-2qh3-fm9g-rf2x.json b/advisories/unreviewed/2022/04/GHSA-2qh3-fm9g-rf2x/GHSA-2qh3-fm9g-rf2x.json index d3abae67b25..92240e6127d 100644 --- a/advisories/unreviewed/2022/04/GHSA-2qh3-fm9g-rf2x/GHSA-2qh3-fm9g-rf2x.json +++ b/advisories/unreviewed/2022/04/GHSA-2qh3-fm9g-rf2x/GHSA-2qh3-fm9g-rf2x.json @@ -7,12 +7,8 @@ "CVE-2004-2554" ], "details": "Novell Client Firewall (NCF) 2.0, as based on the Agnitum Outpost Firewall, allows local users to execute arbitrary code with SYSTEM privileges by opening the NCF tray icon and using the Help functionality to launch programs with SYSTEM privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2qvr-2h7g-c4xv/GHSA-2qvr-2h7g-c4xv.json b/advisories/unreviewed/2022/04/GHSA-2qvr-2h7g-c4xv/GHSA-2qvr-2h7g-c4xv.json index a5edc7fe034..f86e61c6ffc 100644 --- a/advisories/unreviewed/2022/04/GHSA-2qvr-2h7g-c4xv/GHSA-2qvr-2h7g-c4xv.json +++ b/advisories/unreviewed/2022/04/GHSA-2qvr-2h7g-c4xv/GHSA-2qvr-2h7g-c4xv.json @@ -7,12 +7,8 @@ "CVE-2004-2681" ], "details": "PeerSec MatrixSSL before 1.1 caches session keys for an indefinitely long time, which might make it easier for remote attackers to hijack a session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2rfr-226c-v52m/GHSA-2rfr-226c-v52m.json b/advisories/unreviewed/2022/04/GHSA-2rfr-226c-v52m/GHSA-2rfr-226c-v52m.json index 91a32be1e80..662176ba261 100644 --- a/advisories/unreviewed/2022/04/GHSA-2rfr-226c-v52m/GHSA-2rfr-226c-v52m.json +++ b/advisories/unreviewed/2022/04/GHSA-2rfr-226c-v52m/GHSA-2rfr-226c-v52m.json @@ -7,12 +7,8 @@ "CVE-2004-2618" ], "details": "Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the URI, directly after the initial '/' (slash).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2rgg-v6c8-mc7v/GHSA-2rgg-v6c8-mc7v.json b/advisories/unreviewed/2022/04/GHSA-2rgg-v6c8-mc7v/GHSA-2rgg-v6c8-mc7v.json index bd4447db757..868c9ee6640 100644 --- a/advisories/unreviewed/2022/04/GHSA-2rgg-v6c8-mc7v/GHSA-2rgg-v6c8-mc7v.json +++ b/advisories/unreviewed/2022/04/GHSA-2rgg-v6c8-mc7v/GHSA-2rgg-v6c8-mc7v.json @@ -7,12 +7,8 @@ "CVE-2004-2622" ], "details": "AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2v5r-gc72-7xcw/GHSA-2v5r-gc72-7xcw.json b/advisories/unreviewed/2022/04/GHSA-2v5r-gc72-7xcw/GHSA-2v5r-gc72-7xcw.json index c28a97e5e47..a6431397c0c 100644 --- a/advisories/unreviewed/2022/04/GHSA-2v5r-gc72-7xcw/GHSA-2v5r-gc72-7xcw.json +++ b/advisories/unreviewed/2022/04/GHSA-2v5r-gc72-7xcw/GHSA-2v5r-gc72-7xcw.json @@ -7,12 +7,8 @@ "CVE-2004-2689" ], "details": "NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the \"autorized=admin; root=admin\" value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2v8x-qgh9-phcv/GHSA-2v8x-qgh9-phcv.json b/advisories/unreviewed/2022/04/GHSA-2v8x-qgh9-phcv/GHSA-2v8x-qgh9-phcv.json index 7779046eb07..e52a11501e5 100644 --- a/advisories/unreviewed/2022/04/GHSA-2v8x-qgh9-phcv/GHSA-2v8x-qgh9-phcv.json +++ b/advisories/unreviewed/2022/04/GHSA-2v8x-qgh9-phcv/GHSA-2v8x-qgh9-phcv.json @@ -7,12 +7,8 @@ "CVE-2004-2529" ], "details": "Gadu-Gadu allows remote attackers to bypass the \"image send\" option by sending a very small image file, which could be used in conjunction with image-related vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2v97-q484-q665/GHSA-2v97-q484-q665.json b/advisories/unreviewed/2022/04/GHSA-2v97-q484-q665/GHSA-2v97-q484-q665.json index 3b278dec138..ec9d4fb44c7 100644 --- a/advisories/unreviewed/2022/04/GHSA-2v97-q484-q665/GHSA-2v97-q484-q665.json +++ b/advisories/unreviewed/2022/04/GHSA-2v97-q484-q665/GHSA-2v97-q484-q665.json @@ -7,12 +7,8 @@ "CVE-2004-2564" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in show.asp and (2) the title parameter in showperf.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2w96-x49m-vc2j/GHSA-2w96-x49m-vc2j.json b/advisories/unreviewed/2022/04/GHSA-2w96-x49m-vc2j/GHSA-2w96-x49m-vc2j.json index 1b537029d3d..fee488c771b 100644 --- a/advisories/unreviewed/2022/04/GHSA-2w96-x49m-vc2j/GHSA-2w96-x49m-vc2j.json +++ b/advisories/unreviewed/2022/04/GHSA-2w96-x49m-vc2j/GHSA-2w96-x49m-vc2j.json @@ -7,12 +7,8 @@ "CVE-2004-2500" ], "details": "Unknown vulnerability in IlohaMail before 0.8.14-rc1 has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2xmw-23qh-mjvr/GHSA-2xmw-23qh-mjvr.json b/advisories/unreviewed/2022/04/GHSA-2xmw-23qh-mjvr/GHSA-2xmw-23qh-mjvr.json index 35507ed6828..019487d612f 100644 --- a/advisories/unreviewed/2022/04/GHSA-2xmw-23qh-mjvr/GHSA-2xmw-23qh-mjvr.json +++ b/advisories/unreviewed/2022/04/GHSA-2xmw-23qh-mjvr/GHSA-2xmw-23qh-mjvr.json @@ -7,12 +7,8 @@ "CVE-2004-2531" ], "details": "X.509 Certificate Signature Verification in Gnu transport layer security library (GnuTLS) 1.0.16 allows remote attackers to cause a denial of service (CPU consumption) via certificates containing long chains and signed with large RSA keys.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-33w2-v4x9-r4gw/GHSA-33w2-v4x9-r4gw.json b/advisories/unreviewed/2022/04/GHSA-33w2-v4x9-r4gw/GHSA-33w2-v4x9-r4gw.json index 6131d36c222..1284a057615 100644 --- a/advisories/unreviewed/2022/04/GHSA-33w2-v4x9-r4gw/GHSA-33w2-v4x9-r4gw.json +++ b/advisories/unreviewed/2022/04/GHSA-33w2-v4x9-r4gw/GHSA-33w2-v4x9-r4gw.json @@ -7,12 +7,8 @@ "CVE-2004-2639" ], "details": "Unspecified vulnerability in Journalness 3.0.7 and earlier allows remote attackers to create or modify posts via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3432-988g-mrrm/GHSA-3432-988g-mrrm.json b/advisories/unreviewed/2022/04/GHSA-3432-988g-mrrm/GHSA-3432-988g-mrrm.json index 44c5d383fb1..6cced847401 100644 --- a/advisories/unreviewed/2022/04/GHSA-3432-988g-mrrm/GHSA-3432-988g-mrrm.json +++ b/advisories/unreviewed/2022/04/GHSA-3432-988g-mrrm/GHSA-3432-988g-mrrm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-37f6-2x94-2r9p/GHSA-37f6-2x94-2r9p.json b/advisories/unreviewed/2022/04/GHSA-37f6-2x94-2r9p/GHSA-37f6-2x94-2r9p.json index 7b27ee0b3a7..7b6d8458b61 100644 --- a/advisories/unreviewed/2022/04/GHSA-37f6-2x94-2r9p/GHSA-37f6-2x94-2r9p.json +++ b/advisories/unreviewed/2022/04/GHSA-37f6-2x94-2r9p/GHSA-37f6-2x94-2r9p.json @@ -7,12 +7,8 @@ "CVE-2004-2515" ], "details": "Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users to execute arbitrary code via format string specifiers in command line arguments. NOTE: it is not clear if there are any default or typical circumstances under which VMware would be running with privileges beyond those already available to the attackers, so this might not be a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-37j4-jj4f-rgwh/GHSA-37j4-jj4f-rgwh.json b/advisories/unreviewed/2022/04/GHSA-37j4-jj4f-rgwh/GHSA-37j4-jj4f-rgwh.json index d0ad7694d5c..7e52a5ae2cd 100644 --- a/advisories/unreviewed/2022/04/GHSA-37j4-jj4f-rgwh/GHSA-37j4-jj4f-rgwh.json +++ b/advisories/unreviewed/2022/04/GHSA-37j4-jj4f-rgwh/GHSA-37j4-jj4f-rgwh.json @@ -7,12 +7,8 @@ "CVE-2004-2688" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. NOTE: this issue might overlap vector 3 in CVE-2006-3358.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-38vj-q4h7-q9qr/GHSA-38vj-q4h7-q9qr.json b/advisories/unreviewed/2022/04/GHSA-38vj-q4h7-q9qr/GHSA-38vj-q4h7-q9qr.json index ce8e2d48a63..1c64b6a1548 100644 --- a/advisories/unreviewed/2022/04/GHSA-38vj-q4h7-q9qr/GHSA-38vj-q4h7-q9qr.json +++ b/advisories/unreviewed/2022/04/GHSA-38vj-q4h7-q9qr/GHSA-38vj-q4h7-q9qr.json @@ -7,12 +7,8 @@ "CVE-2004-2729" ], "details": "Inetd32 Administration Tool of Hummingbird Connectivity 7.1 and 9.0 allows local users to execute arbitrary code by changing the program for handling incoming connections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3cw3-m7gv-grjw/GHSA-3cw3-m7gv-grjw.json b/advisories/unreviewed/2022/04/GHSA-3cw3-m7gv-grjw/GHSA-3cw3-m7gv-grjw.json index aaab3ca40ed..f45190c1fe7 100644 --- a/advisories/unreviewed/2022/04/GHSA-3cw3-m7gv-grjw/GHSA-3cw3-m7gv-grjw.json +++ b/advisories/unreviewed/2022/04/GHSA-3cw3-m7gv-grjw/GHSA-3cw3-m7gv-grjw.json @@ -7,12 +7,8 @@ "CVE-2004-2583" ], "details": "SMTP service in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous open connections to TCP port 25.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3gmr-q2mv-97r5/GHSA-3gmr-q2mv-97r5.json b/advisories/unreviewed/2022/04/GHSA-3gmr-q2mv-97r5/GHSA-3gmr-q2mv-97r5.json index 9ff2922abb8..1272dc5081a 100644 --- a/advisories/unreviewed/2022/04/GHSA-3gmr-q2mv-97r5/GHSA-3gmr-q2mv-97r5.json +++ b/advisories/unreviewed/2022/04/GHSA-3gmr-q2mv-97r5/GHSA-3gmr-q2mv-97r5.json @@ -7,12 +7,8 @@ "CVE-2004-2524" ], "details": "clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read the plaintext values in the resulting form.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3gpj-j7q9-9qp4/GHSA-3gpj-j7q9-9qp4.json b/advisories/unreviewed/2022/04/GHSA-3gpj-j7q9-9qp4/GHSA-3gpj-j7q9-9qp4.json index 6d2954333dc..2163a666a6b 100644 --- a/advisories/unreviewed/2022/04/GHSA-3gpj-j7q9-9qp4/GHSA-3gpj-j7q9-9qp4.json +++ b/advisories/unreviewed/2022/04/GHSA-3gpj-j7q9-9qp4/GHSA-3gpj-j7q9-9qp4.json @@ -7,12 +7,8 @@ "CVE-2004-2510" ], "details": "Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to inject arbitrary web script or HTML via the Cat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3hm7-25rv-3whx/GHSA-3hm7-25rv-3whx.json b/advisories/unreviewed/2022/04/GHSA-3hm7-25rv-3whx/GHSA-3hm7-25rv-3whx.json index 1a94b5539e5..605022ca9c8 100644 --- a/advisories/unreviewed/2022/04/GHSA-3hm7-25rv-3whx/GHSA-3hm7-25rv-3whx.json +++ b/advisories/unreviewed/2022/04/GHSA-3hm7-25rv-3whx/GHSA-3hm7-25rv-3whx.json @@ -7,12 +7,8 @@ "CVE-2004-2764" ], "details": "Sun SDK and Java Runtime Environment (JRE) 1.4.2 through 1.4.2_04, 1.4.1 through 1.4.1_07, and 1.4.0 through 1.4.0_04 allows untrusted applets and unprivileged servlets to gain privileges and read data from other applets via unspecified vectors related to classes in the XSLT processor, aka \"XML sniffing.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3j78-fv9c-9gh2/GHSA-3j78-fv9c-9gh2.json b/advisories/unreviewed/2022/04/GHSA-3j78-fv9c-9gh2/GHSA-3j78-fv9c-9gh2.json index a83395e8186..0b827e1b697 100644 --- a/advisories/unreviewed/2022/04/GHSA-3j78-fv9c-9gh2/GHSA-3j78-fv9c-9gh2.json +++ b/advisories/unreviewed/2022/04/GHSA-3j78-fv9c-9gh2/GHSA-3j78-fv9c-9gh2.json @@ -7,12 +7,8 @@ "CVE-2004-2619" ], "details": "ripMIME 1.3.2.3 and earlier allows remote attackers to bypass e-mail protection via a base64 MIME encoded attachment containing invalid characters that are not properly extracted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3mrf-6r8f-wh4j/GHSA-3mrf-6r8f-wh4j.json b/advisories/unreviewed/2022/04/GHSA-3mrf-6r8f-wh4j/GHSA-3mrf-6r8f-wh4j.json index d30f2fc5665..88c173bdb05 100644 --- a/advisories/unreviewed/2022/04/GHSA-3mrf-6r8f-wh4j/GHSA-3mrf-6r8f-wh4j.json +++ b/advisories/unreviewed/2022/04/GHSA-3mrf-6r8f-wh4j/GHSA-3mrf-6r8f-wh4j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "WEB", diff --git a/advisories/unreviewed/2022/04/GHSA-3p24-gwpr-5f2q/GHSA-3p24-gwpr-5f2q.json b/advisories/unreviewed/2022/04/GHSA-3p24-gwpr-5f2q/GHSA-3p24-gwpr-5f2q.json index 2f36f844922..a5a4ecdd570 100644 --- a/advisories/unreviewed/2022/04/GHSA-3p24-gwpr-5f2q/GHSA-3p24-gwpr-5f2q.json +++ b/advisories/unreviewed/2022/04/GHSA-3p24-gwpr-5f2q/GHSA-3p24-gwpr-5f2q.json @@ -7,12 +7,8 @@ "CVE-2004-2616" ], "details": "The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information by uploading a file, which reveals the path in a success message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3pc8-5mmp-rgj7/GHSA-3pc8-5mmp-rgj7.json b/advisories/unreviewed/2022/04/GHSA-3pc8-5mmp-rgj7/GHSA-3pc8-5mmp-rgj7.json index e728f4481c4..d48820a9304 100644 --- a/advisories/unreviewed/2022/04/GHSA-3pc8-5mmp-rgj7/GHSA-3pc8-5mmp-rgj7.json +++ b/advisories/unreviewed/2022/04/GHSA-3pc8-5mmp-rgj7/GHSA-3pc8-5mmp-rgj7.json @@ -7,12 +7,8 @@ "CVE-2004-2482" ], "details": "Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3pq4-c488-v2m4/GHSA-3pq4-c488-v2m4.json b/advisories/unreviewed/2022/04/GHSA-3pq4-c488-v2m4/GHSA-3pq4-c488-v2m4.json index 22ef521b3fb..c0c4ffdb4c5 100644 --- a/advisories/unreviewed/2022/04/GHSA-3pq4-c488-v2m4/GHSA-3pq4-c488-v2m4.json +++ b/advisories/unreviewed/2022/04/GHSA-3pq4-c488-v2m4/GHSA-3pq4-c488-v2m4.json @@ -7,12 +7,8 @@ "CVE-2004-2480" ], "details": "Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via \"@@\" sequences in a URL within Internet Explorer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3pxq-5cc9-p3hw/GHSA-3pxq-5cc9-p3hw.json b/advisories/unreviewed/2022/04/GHSA-3pxq-5cc9-p3hw/GHSA-3pxq-5cc9-p3hw.json index 8bf30b409a1..752faa45908 100644 --- a/advisories/unreviewed/2022/04/GHSA-3pxq-5cc9-p3hw/GHSA-3pxq-5cc9-p3hw.json +++ b/advisories/unreviewed/2022/04/GHSA-3pxq-5cc9-p3hw/GHSA-3pxq-5cc9-p3hw.json @@ -7,12 +7,8 @@ "CVE-2004-2596" ], "details": "Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections from the same IP address.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-3qq6-672j-jx3v/GHSA-3qq6-672j-jx3v.json b/advisories/unreviewed/2022/04/GHSA-3qq6-672j-jx3v/GHSA-3qq6-672j-jx3v.json index 6c1804fb233..7cb80305804 100644 --- a/advisories/unreviewed/2022/04/GHSA-3qq6-672j-jx3v/GHSA-3qq6-672j-jx3v.json +++ b/advisories/unreviewed/2022/04/GHSA-3qq6-672j-jx3v/GHSA-3qq6-672j-jx3v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3w87-5jwj-39vh/GHSA-3w87-5jwj-39vh.json b/advisories/unreviewed/2022/04/GHSA-3w87-5jwj-39vh/GHSA-3w87-5jwj-39vh.json index da83c4655d2..f136d0a16f7 100644 --- a/advisories/unreviewed/2022/04/GHSA-3w87-5jwj-39vh/GHSA-3w87-5jwj-39vh.json +++ b/advisories/unreviewed/2022/04/GHSA-3w87-5jwj-39vh/GHSA-3w87-5jwj-39vh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "WEB", diff --git a/advisories/unreviewed/2022/04/GHSA-3xp2-vcr5-r48r/GHSA-3xp2-vcr5-r48r.json b/advisories/unreviewed/2022/04/GHSA-3xp2-vcr5-r48r/GHSA-3xp2-vcr5-r48r.json index 149acd3263b..34a4b401203 100644 --- a/advisories/unreviewed/2022/04/GHSA-3xp2-vcr5-r48r/GHSA-3xp2-vcr5-r48r.json +++ b/advisories/unreviewed/2022/04/GHSA-3xp2-vcr5-r48r/GHSA-3xp2-vcr5-r48r.json @@ -7,12 +7,8 @@ "CVE-2004-2748" ], "details": "viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid profileid parameter, which leaks the pathname in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-3xpm-4m85-6353/GHSA-3xpm-4m85-6353.json b/advisories/unreviewed/2022/04/GHSA-3xpm-4m85-6353/GHSA-3xpm-4m85-6353.json index 4432616103c..5154e96531f 100644 --- a/advisories/unreviewed/2022/04/GHSA-3xpm-4m85-6353/GHSA-3xpm-4m85-6353.json +++ b/advisories/unreviewed/2022/04/GHSA-3xpm-4m85-6353/GHSA-3xpm-4m85-6353.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-435x-xc34-27p6/GHSA-435x-xc34-27p6.json b/advisories/unreviewed/2022/04/GHSA-435x-xc34-27p6/GHSA-435x-xc34-27p6.json index 2e7592d36e2..224dfcf9275 100644 --- a/advisories/unreviewed/2022/04/GHSA-435x-xc34-27p6/GHSA-435x-xc34-27p6.json +++ b/advisories/unreviewed/2022/04/GHSA-435x-xc34-27p6/GHSA-435x-xc34-27p6.json @@ -7,12 +7,8 @@ "CVE-2004-2670" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in mod.php in eNdonesia 8.3 allow remote attackers to inject arbitrary web script or HTML via (1) the mod parameter in a viewcat operation or (2) the query parameter in a search operation in the publisher module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-45hc-2hjf-p969/GHSA-45hc-2hjf-p969.json b/advisories/unreviewed/2022/04/GHSA-45hc-2hjf-p969/GHSA-45hc-2hjf-p969.json index 245cb2a21da..709e36fdacd 100644 --- a/advisories/unreviewed/2022/04/GHSA-45hc-2hjf-p969/GHSA-45hc-2hjf-p969.json +++ b/advisories/unreviewed/2022/04/GHSA-45hc-2hjf-p969/GHSA-45hc-2hjf-p969.json @@ -7,12 +7,8 @@ "CVE-2004-2754" ], "details": "SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the ID_MEMBER parameter to the (1) recentTopics and (2) welcome functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4839-775x-j3vf/GHSA-4839-775x-j3vf.json b/advisories/unreviewed/2022/04/GHSA-4839-775x-j3vf/GHSA-4839-775x-j3vf.json index e55249bc2e2..8a18b196925 100644 --- a/advisories/unreviewed/2022/04/GHSA-4839-775x-j3vf/GHSA-4839-775x-j3vf.json +++ b/advisories/unreviewed/2022/04/GHSA-4839-775x-j3vf/GHSA-4839-775x-j3vf.json @@ -7,12 +7,8 @@ "CVE-2004-2594" ], "details": "Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to read arbitrary files via a \"\\/\" in a pathname argument, as demonstrated by \"download \\/server.cfg\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-49h7-mvgr-p5p6/GHSA-49h7-mvgr-p5p6.json b/advisories/unreviewed/2022/04/GHSA-49h7-mvgr-p5p6/GHSA-49h7-mvgr-p5p6.json index 9cae0ebbd2e..1c478906010 100644 --- a/advisories/unreviewed/2022/04/GHSA-49h7-mvgr-p5p6/GHSA-49h7-mvgr-p5p6.json +++ b/advisories/unreviewed/2022/04/GHSA-49h7-mvgr-p5p6/GHSA-49h7-mvgr-p5p6.json @@ -7,12 +7,8 @@ "CVE-2004-2571" ], "details": "Multiple buffer overflows in EnderUNIX isoqlog 2.1.1 allow remote attackers to execute arbitrary code via the (1) parseQmailFromBytesLine, (2) parseQmailToRemoteLine, (3) parseQmailToLocalLine, (4) parseSendmailFromBytesLine, (5) parseSendmailToLine, (6) parseEximFromBytesLine, and (7) parseEximToLine functions in Parser.c; allow local users to execute arbitrary code via the (8) lowercase and (9) check_syslog_date functions in Parser.c, and (10) unspecified functions in Dir.c; and allow unspecified attackers to execute arbitrary code via the (11) loadconfig and (12) removespaces functions in loadconfig.c, the (13) loadLang function in LangCfg.c, and (14) unspecified functions in Html.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4f48-w364-xw45/GHSA-4f48-w364-xw45.json b/advisories/unreviewed/2022/04/GHSA-4f48-w364-xw45/GHSA-4f48-w364-xw45.json index 24da9afe072..7b0225b0e9e 100644 --- a/advisories/unreviewed/2022/04/GHSA-4f48-w364-xw45/GHSA-4f48-w364-xw45.json +++ b/advisories/unreviewed/2022/04/GHSA-4f48-w364-xw45/GHSA-4f48-w364-xw45.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4h4f-vwmm-9jhr/GHSA-4h4f-vwmm-9jhr.json b/advisories/unreviewed/2022/04/GHSA-4h4f-vwmm-9jhr/GHSA-4h4f-vwmm-9jhr.json index 4350d1e4d4b..ef90e2e4ccf 100644 --- a/advisories/unreviewed/2022/04/GHSA-4h4f-vwmm-9jhr/GHSA-4h4f-vwmm-9jhr.json +++ b/advisories/unreviewed/2022/04/GHSA-4h4f-vwmm-9jhr/GHSA-4h4f-vwmm-9jhr.json @@ -7,12 +7,8 @@ "CVE-2004-2487" ], "details": "Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) \"..\", (2) \"\\..\\\" (backslash dot dot), or (3) \"/../\" sequences in (a) RETR (get), (b) NLST (ls), (c) LIST (ls), (d) RNFR, or (e) RNTO FTP commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4h82-3wj3-6799/GHSA-4h82-3wj3-6799.json b/advisories/unreviewed/2022/04/GHSA-4h82-3wj3-6799/GHSA-4h82-3wj3-6799.json index 4cdb1c65e50..1e6b7d001f1 100644 --- a/advisories/unreviewed/2022/04/GHSA-4h82-3wj3-6799/GHSA-4h82-3wj3-6799.json +++ b/advisories/unreviewed/2022/04/GHSA-4h82-3wj3-6799/GHSA-4h82-3wj3-6799.json @@ -7,12 +7,8 @@ "CVE-2004-2692" ], "details": "The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass restrictions and execute arbitrary commands via a backtick operator, which is not handled using the php_escape_shell_cmd function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4j28-rvvh-wc2q/GHSA-4j28-rvvh-wc2q.json b/advisories/unreviewed/2022/04/GHSA-4j28-rvvh-wc2q/GHSA-4j28-rvvh-wc2q.json index 275ae39b5d6..c03fa575489 100644 --- a/advisories/unreviewed/2022/04/GHSA-4j28-rvvh-wc2q/GHSA-4j28-rvvh-wc2q.json +++ b/advisories/unreviewed/2022/04/GHSA-4j28-rvvh-wc2q/GHSA-4j28-rvvh-wc2q.json @@ -7,12 +7,8 @@ "CVE-2004-2509" ], "details": "Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads 6.2.3 and 6.5 allow remote attackers to inject arbitrary web script or HTML via the Cat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4pwf-7qrc-mcqp/GHSA-4pwf-7qrc-mcqp.json b/advisories/unreviewed/2022/04/GHSA-4pwf-7qrc-mcqp/GHSA-4pwf-7qrc-mcqp.json index aeda1ea16e2..4aee03ff67f 100644 --- a/advisories/unreviewed/2022/04/GHSA-4pwf-7qrc-mcqp/GHSA-4pwf-7qrc-mcqp.json +++ b/advisories/unreviewed/2022/04/GHSA-4pwf-7qrc-mcqp/GHSA-4pwf-7qrc-mcqp.json @@ -7,12 +7,8 @@ "CVE-2004-2520" ], "details": "POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (application crash) via a large numeric value in the (1) LIST, (2) RETR, or (3) UIDL commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4qvp-jp63-2mpf/GHSA-4qvp-jp63-2mpf.json b/advisories/unreviewed/2022/04/GHSA-4qvp-jp63-2mpf/GHSA-4qvp-jp63-2mpf.json index 2d2de87f009..51d721b0383 100644 --- a/advisories/unreviewed/2022/04/GHSA-4qvp-jp63-2mpf/GHSA-4qvp-jp63-2mpf.json +++ b/advisories/unreviewed/2022/04/GHSA-4qvp-jp63-2mpf/GHSA-4qvp-jp63-2mpf.json @@ -7,12 +7,8 @@ "CVE-2004-2586" ], "details": "Directory traversal vulnerability in frmGetAttachment.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to read arbitrary files via the filename parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4r9w-xpf5-xm4g/GHSA-4r9w-xpf5-xm4g.json b/advisories/unreviewed/2022/04/GHSA-4r9w-xpf5-xm4g/GHSA-4r9w-xpf5-xm4g.json index 96b27556be3..e0eefe49ade 100644 --- a/advisories/unreviewed/2022/04/GHSA-4r9w-xpf5-xm4g/GHSA-4r9w-xpf5-xm4g.json +++ b/advisories/unreviewed/2022/04/GHSA-4r9w-xpf5-xm4g/GHSA-4r9w-xpf5-xm4g.json @@ -7,12 +7,8 @@ "CVE-2004-2724" ], "details": "LionMax Software Chat Anywhere 2.72a allows remote attackers to cause a denial of service (server crash and client CPU consumption) via a username beginning with percent (%) followed by a null character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4rg9-9m3h-2wgj/GHSA-4rg9-9m3h-2wgj.json b/advisories/unreviewed/2022/04/GHSA-4rg9-9m3h-2wgj/GHSA-4rg9-9m3h-2wgj.json index 69208d0c7c0..e431eae308a 100644 --- a/advisories/unreviewed/2022/04/GHSA-4rg9-9m3h-2wgj/GHSA-4rg9-9m3h-2wgj.json +++ b/advisories/unreviewed/2022/04/GHSA-4rg9-9m3h-2wgj/GHSA-4rg9-9m3h-2wgj.json @@ -7,12 +7,8 @@ "CVE-2004-2518" ], "details": "Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte (\"%00\") to a URL or (2) an invalid LANGUAGE parameter to web.tmpl, which reveals the full installation path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4vfw-6c9m-chgp/GHSA-4vfw-6c9m-chgp.json b/advisories/unreviewed/2022/04/GHSA-4vfw-6c9m-chgp/GHSA-4vfw-6c9m-chgp.json index af7f7ed668f..6da3bec0165 100644 --- a/advisories/unreviewed/2022/04/GHSA-4vfw-6c9m-chgp/GHSA-4vfw-6c9m-chgp.json +++ b/advisories/unreviewed/2022/04/GHSA-4vfw-6c9m-chgp/GHSA-4vfw-6c9m-chgp.json @@ -7,12 +7,8 @@ "CVE-2004-2750" ], "details": "Directory traversal vulnerability in browser.php in JBrowser 1.0 through 2.1 allows remote attackers to read arbitrary files via the directory parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4w92-vgp9-22jp/GHSA-4w92-vgp9-22jp.json b/advisories/unreviewed/2022/04/GHSA-4w92-vgp9-22jp/GHSA-4w92-vgp9-22jp.json index 24f473702b1..1f67ffecedd 100644 --- a/advisories/unreviewed/2022/04/GHSA-4w92-vgp9-22jp/GHSA-4w92-vgp9-22jp.json +++ b/advisories/unreviewed/2022/04/GHSA-4w92-vgp9-22jp/GHSA-4w92-vgp9-22jp.json @@ -7,12 +7,8 @@ "CVE-2004-2661" ], "details": "Soft3304 04WebServer before 1.41 does not properly check file names, which allows remote attackers to obtain sensitive information (CGI source code).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4wcx-7mj5-65f6/GHSA-4wcx-7mj5-65f6.json b/advisories/unreviewed/2022/04/GHSA-4wcx-7mj5-65f6/GHSA-4wcx-7mj5-65f6.json index e2755875b2c..aede282667e 100644 --- a/advisories/unreviewed/2022/04/GHSA-4wcx-7mj5-65f6/GHSA-4wcx-7mj5-65f6.json +++ b/advisories/unreviewed/2022/04/GHSA-4wcx-7mj5-65f6/GHSA-4wcx-7mj5-65f6.json @@ -7,12 +7,8 @@ "CVE-2004-2737" ], "details": "SQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary SQL commands via the where parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-52c4-mqqm-x3xx/GHSA-52c4-mqqm-x3xx.json b/advisories/unreviewed/2022/04/GHSA-52c4-mqqm-x3xx/GHSA-52c4-mqqm-x3xx.json index 8c134a01517..4c9842c4888 100644 --- a/advisories/unreviewed/2022/04/GHSA-52c4-mqqm-x3xx/GHSA-52c4-mqqm-x3xx.json +++ b/advisories/unreviewed/2022/04/GHSA-52c4-mqqm-x3xx/GHSA-52c4-mqqm-x3xx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-547m-mqmc-2jqg/GHSA-547m-mqmc-2jqg.json b/advisories/unreviewed/2022/04/GHSA-547m-mqmc-2jqg/GHSA-547m-mqmc-2jqg.json index c20e8b08ddf..daf00255774 100644 --- a/advisories/unreviewed/2022/04/GHSA-547m-mqmc-2jqg/GHSA-547m-mqmc-2jqg.json +++ b/advisories/unreviewed/2022/04/GHSA-547m-mqmc-2jqg/GHSA-547m-mqmc-2jqg.json @@ -7,12 +7,8 @@ "CVE-2004-2765" ], "details": "Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, a different vulnerability than CVE-2005-2022 and CVE-2006-5486.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-54jx-rwf9-488w/GHSA-54jx-rwf9-488w.json b/advisories/unreviewed/2022/04/GHSA-54jx-rwf9-488w/GHSA-54jx-rwf9-488w.json index 82b44f005f8..5286b768700 100644 --- a/advisories/unreviewed/2022/04/GHSA-54jx-rwf9-488w/GHSA-54jx-rwf9-488w.json +++ b/advisories/unreviewed/2022/04/GHSA-54jx-rwf9-488w/GHSA-54jx-rwf9-488w.json @@ -7,12 +7,8 @@ "CVE-2004-2649" ], "details": "Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of characters (e.g. spaces coded as \" \") in the middle of the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-55mq-4v94-5jrj/GHSA-55mq-4v94-5jrj.json b/advisories/unreviewed/2022/04/GHSA-55mq-4v94-5jrj/GHSA-55mq-4v94-5jrj.json index f7d2f3a1658..87aad61d35f 100644 --- a/advisories/unreviewed/2022/04/GHSA-55mq-4v94-5jrj/GHSA-55mq-4v94-5jrj.json +++ b/advisories/unreviewed/2022/04/GHSA-55mq-4v94-5jrj/GHSA-55mq-4v94-5jrj.json @@ -7,12 +7,8 @@ "CVE-2004-2660" ], "details": "Memory leak in direct-io.c in Linux kernel 2.6.x before 2.6.10 allows local users to cause a denial of service (memory consumption) via certain O_DIRECT (direct IO) write requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-57w7-wq63-9jwj/GHSA-57w7-wq63-9jwj.json b/advisories/unreviewed/2022/04/GHSA-57w7-wq63-9jwj/GHSA-57w7-wq63-9jwj.json index c74b40716a8..779a416cdfa 100644 --- a/advisories/unreviewed/2022/04/GHSA-57w7-wq63-9jwj/GHSA-57w7-wq63-9jwj.json +++ b/advisories/unreviewed/2022/04/GHSA-57w7-wq63-9jwj/GHSA-57w7-wq63-9jwj.json @@ -7,12 +7,8 @@ "CVE-2004-2591" ], "details": "The data-overwrite capability of ButtUglySoftware CleanCache 2.19 does not properly overwrite data in files, which allows attackers to recover the data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5824-6p3v-vcx4/GHSA-5824-6p3v-vcx4.json b/advisories/unreviewed/2022/04/GHSA-5824-6p3v-vcx4/GHSA-5824-6p3v-vcx4.json index d0e1a070bde..b35cdc25e10 100644 --- a/advisories/unreviewed/2022/04/GHSA-5824-6p3v-vcx4/GHSA-5824-6p3v-vcx4.json +++ b/advisories/unreviewed/2022/04/GHSA-5824-6p3v-vcx4/GHSA-5824-6p3v-vcx4.json @@ -7,12 +7,8 @@ "CVE-2004-2734" ], "details": "webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access control to the WEB-INF folder.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-5872-q7c3-cvqr/GHSA-5872-q7c3-cvqr.json b/advisories/unreviewed/2022/04/GHSA-5872-q7c3-cvqr/GHSA-5872-q7c3-cvqr.json index 18d79c00ea6..1cf09b05d38 100644 --- a/advisories/unreviewed/2022/04/GHSA-5872-q7c3-cvqr/GHSA-5872-q7c3-cvqr.json +++ b/advisories/unreviewed/2022/04/GHSA-5872-q7c3-cvqr/GHSA-5872-q7c3-cvqr.json @@ -7,12 +7,8 @@ "CVE-2004-2506" ], "details": "Unparsed web content delivery vulnerability in WIKINDX before 0.9.9g allows remote attackers to obtain sensitive information via a direct HTTP request to the config.inc file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-58v3-hf8m-w67r/GHSA-58v3-hf8m-w67r.json b/advisories/unreviewed/2022/04/GHSA-58v3-hf8m-w67r/GHSA-58v3-hf8m-w67r.json index ce1cea8b58b..2f07a49808b 100644 --- a/advisories/unreviewed/2022/04/GHSA-58v3-hf8m-w67r/GHSA-58v3-hf8m-w67r.json +++ b/advisories/unreviewed/2022/04/GHSA-58v3-hf8m-w67r/GHSA-58v3-hf8m-w67r.json @@ -7,12 +7,8 @@ "CVE-2004-2633" ], "details": "Unspecified vulnerability in Sesamie 1.0 allows remote anonymous attackers to gain access to repositories of other users via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5fhp-v5ch-jvfc/GHSA-5fhp-v5ch-jvfc.json b/advisories/unreviewed/2022/04/GHSA-5fhp-v5ch-jvfc/GHSA-5fhp-v5ch-jvfc.json index 2f8d73c4a91..d59d307ced4 100644 --- a/advisories/unreviewed/2022/04/GHSA-5fhp-v5ch-jvfc/GHSA-5fhp-v5ch-jvfc.json +++ b/advisories/unreviewed/2022/04/GHSA-5fhp-v5ch-jvfc/GHSA-5fhp-v5ch-jvfc.json @@ -7,12 +7,8 @@ "CVE-2004-2721" ], "details": "The CheckGroup function in openSkat VTMF before 2.1 generates public key pairs in which the \"p\" variable might not be prime, which allows remote attackers to determine the private key and decrypt messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5gr4-pm92-g66w/GHSA-5gr4-pm92-g66w.json b/advisories/unreviewed/2022/04/GHSA-5gr4-pm92-g66w/GHSA-5gr4-pm92-g66w.json index 7bc6d6506c0..c097cfdae03 100644 --- a/advisories/unreviewed/2022/04/GHSA-5gr4-pm92-g66w/GHSA-5gr4-pm92-g66w.json +++ b/advisories/unreviewed/2022/04/GHSA-5gr4-pm92-g66w/GHSA-5gr4-pm92-g66w.json @@ -7,12 +7,8 @@ "CVE-2004-2597" ], "details": "Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo string that already contains an \"ip\" key/value pair but is also long enough to cause a new key/value pair to be truncated, which interferes with the server's ability to find the client's IP address.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5grx-hv66-36gf/GHSA-5grx-hv66-36gf.json b/advisories/unreviewed/2022/04/GHSA-5grx-hv66-36gf/GHSA-5grx-hv66-36gf.json index 866edee189b..4ce405aeb58 100644 --- a/advisories/unreviewed/2022/04/GHSA-5grx-hv66-36gf/GHSA-5grx-hv66-36gf.json +++ b/advisories/unreviewed/2022/04/GHSA-5grx-hv66-36gf/GHSA-5grx-hv66-36gf.json @@ -7,12 +7,8 @@ "CVE-2004-2658" ], "details": "resmgr in SUSE CORE 9 does not properly identify terminal names, which allows local users to spoof terminals and login types.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5hgg-xq5w-5m82/GHSA-5hgg-xq5w-5m82.json b/advisories/unreviewed/2022/04/GHSA-5hgg-xq5w-5m82/GHSA-5hgg-xq5w-5m82.json index 7be0302b7ef..a3ab10088d4 100644 --- a/advisories/unreviewed/2022/04/GHSA-5hgg-xq5w-5m82/GHSA-5hgg-xq5w-5m82.json +++ b/advisories/unreviewed/2022/04/GHSA-5hgg-xq5w-5m82/GHSA-5hgg-xq5w-5m82.json @@ -7,12 +7,8 @@ "CVE-2004-2659" ], "details": "Opera offers an Open button to verify that a user wishes to execute a downloaded file, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking Open via a request for a different mouse or keyboard action very shortly before the Open dialog appears. NOTE: this is a different issue than CVE-2005-2407.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-5pqp-qchf-c8x3/GHSA-5pqp-qchf-c8x3.json b/advisories/unreviewed/2022/04/GHSA-5pqp-qchf-c8x3/GHSA-5pqp-qchf-c8x3.json index 4c135116dd0..31ede9d611e 100644 --- a/advisories/unreviewed/2022/04/GHSA-5pqp-qchf-c8x3/GHSA-5pqp-qchf-c8x3.json +++ b/advisories/unreviewed/2022/04/GHSA-5pqp-qchf-c8x3/GHSA-5pqp-qchf-c8x3.json @@ -7,12 +7,8 @@ "CVE-2004-2727" ], "details": "Buffer overflow in MEHTTPS (HTTPMail) of MailEnable Professional 1.5 through 1.7 allows remote attackers to cause a denial of service (application crash) via a long HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-5wmr-53xq-5m6r/GHSA-5wmr-53xq-5m6r.json b/advisories/unreviewed/2022/04/GHSA-5wmr-53xq-5m6r/GHSA-5wmr-53xq-5m6r.json index d8c626c445c..6e23f64e3db 100644 --- a/advisories/unreviewed/2022/04/GHSA-5wmr-53xq-5m6r/GHSA-5wmr-53xq-5m6r.json +++ b/advisories/unreviewed/2022/04/GHSA-5wmr-53xq-5m6r/GHSA-5wmr-53xq-5m6r.json @@ -7,12 +7,8 @@ "CVE-2004-2537" ], "details": "Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a \"Webmail security bug.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-62jm-23c8-x8jq/GHSA-62jm-23c8-x8jq.json b/advisories/unreviewed/2022/04/GHSA-62jm-23c8-x8jq/GHSA-62jm-23c8-x8jq.json index b43753d4f23..bc052cbedea 100644 --- a/advisories/unreviewed/2022/04/GHSA-62jm-23c8-x8jq/GHSA-62jm-23c8-x8jq.json +++ b/advisories/unreviewed/2022/04/GHSA-62jm-23c8-x8jq/GHSA-62jm-23c8-x8jq.json @@ -7,12 +7,8 @@ "CVE-2004-2502" ], "details": "im-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the imswitcher[PID] temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-64gr-p8q7-hc37/GHSA-64gr-p8q7-hc37.json b/advisories/unreviewed/2022/04/GHSA-64gr-p8q7-hc37/GHSA-64gr-p8q7-hc37.json index ec3999abf2a..08c832a2ca8 100644 --- a/advisories/unreviewed/2022/04/GHSA-64gr-p8q7-hc37/GHSA-64gr-p8q7-hc37.json +++ b/advisories/unreviewed/2022/04/GHSA-64gr-p8q7-hc37/GHSA-64gr-p8q7-hc37.json @@ -7,12 +7,8 @@ "CVE-2004-2698" ], "details": "Race condition in IMWheel 1.0.0pre11 and earlier, when running with the -k option, allows local users to cause a denial of service (IMWheel crash) and possibly modify arbitrary files via a symlink attack on the imwheel.pid file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-6679-7c96-f9mj/GHSA-6679-7c96-f9mj.json b/advisories/unreviewed/2022/04/GHSA-6679-7c96-f9mj/GHSA-6679-7c96-f9mj.json index 8ff5711b760..665d939d841 100644 --- a/advisories/unreviewed/2022/04/GHSA-6679-7c96-f9mj/GHSA-6679-7c96-f9mj.json +++ b/advisories/unreviewed/2022/04/GHSA-6679-7c96-f9mj/GHSA-6679-7c96-f9mj.json @@ -7,12 +7,8 @@ "CVE-2004-2645" ], "details": "Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing \"CHOICE\" types with \"indefinite length structures.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6684-xr7v-79r6/GHSA-6684-xr7v-79r6.json b/advisories/unreviewed/2022/04/GHSA-6684-xr7v-79r6/GHSA-6684-xr7v-79r6.json index c17ca364cc8..1228e00c66f 100644 --- a/advisories/unreviewed/2022/04/GHSA-6684-xr7v-79r6/GHSA-6684-xr7v-79r6.json +++ b/advisories/unreviewed/2022/04/GHSA-6684-xr7v-79r6/GHSA-6684-xr7v-79r6.json @@ -7,12 +7,8 @@ "CVE-2004-2674" ], "details": "Directory traversal vulnerability in ArGoSoft FTP Server before 1.4.1.6 allows remote authenticated users to determine the existence of arbitrary files via \"..\" sequences in the SITE UNZIP argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-66jf-hpv3-xqhq/GHSA-66jf-hpv3-xqhq.json b/advisories/unreviewed/2022/04/GHSA-66jf-hpv3-xqhq/GHSA-66jf-hpv3-xqhq.json index c9cbdf37c63..46921735c0e 100644 --- a/advisories/unreviewed/2022/04/GHSA-66jf-hpv3-xqhq/GHSA-66jf-hpv3-xqhq.json +++ b/advisories/unreviewed/2022/04/GHSA-66jf-hpv3-xqhq/GHSA-66jf-hpv3-xqhq.json @@ -7,12 +7,8 @@ "CVE-2004-2601" ], "details": "PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) allows remote attackers to read local files and possibly execute PHP code via a URL in the SKIN_inner parameter to inc/skin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-679x-cxhr-6g88/GHSA-679x-cxhr-6g88.json b/advisories/unreviewed/2022/04/GHSA-679x-cxhr-6g88/GHSA-679x-cxhr-6g88.json index 878f6fd9e43..9428ac01ec1 100644 --- a/advisories/unreviewed/2022/04/GHSA-679x-cxhr-6g88/GHSA-679x-cxhr-6g88.json +++ b/advisories/unreviewed/2022/04/GHSA-679x-cxhr-6g88/GHSA-679x-cxhr-6g88.json @@ -7,12 +7,8 @@ "CVE-2004-2730" ], "details": "Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not properly disconnect from remote IPC$ and ADMIN$ shares, which allows local users to access the shares with elevated privileges by using the existing share mapping.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-685v-wjj6-4qpx/GHSA-685v-wjj6-4qpx.json b/advisories/unreviewed/2022/04/GHSA-685v-wjj6-4qpx/GHSA-685v-wjj6-4qpx.json index 760c8b652fd..fab75def769 100644 --- a/advisories/unreviewed/2022/04/GHSA-685v-wjj6-4qpx/GHSA-685v-wjj6-4qpx.json +++ b/advisories/unreviewed/2022/04/GHSA-685v-wjj6-4qpx/GHSA-685v-wjj6-4qpx.json @@ -7,12 +7,8 @@ "CVE-2004-2679" ], "details": "Check Point Firewall-1 4.1 up to NG AI R55 allows remote attackers to obtain potentially sensitive information by sending an Internet Key Exchange (IKE) with a certain Vendor ID payload that causes Firewall-1 to return a response containing version and other information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-692q-6xmm-qwr4/GHSA-692q-6xmm-qwr4.json b/advisories/unreviewed/2022/04/GHSA-692q-6xmm-qwr4/GHSA-692q-6xmm-qwr4.json index 2ae9107ec4b..89343b8c663 100644 --- a/advisories/unreviewed/2022/04/GHSA-692q-6xmm-qwr4/GHSA-692q-6xmm-qwr4.json +++ b/advisories/unreviewed/2022/04/GHSA-692q-6xmm-qwr4/GHSA-692q-6xmm-qwr4.json @@ -7,12 +7,8 @@ "CVE-2004-2695" ], "details": "SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows remote attackers to execute arbitrary SQL statements via the x_invoice_num parameter. NOTE: this issue might be related to CVE-2006-4267.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-6mqq-2gc9-7j3v/GHSA-6mqq-2gc9-7j3v.json b/advisories/unreviewed/2022/04/GHSA-6mqq-2gc9-7j3v/GHSA-6mqq-2gc9-7j3v.json index a2be8fc33b7..f42d524b947 100644 --- a/advisories/unreviewed/2022/04/GHSA-6mqq-2gc9-7j3v/GHSA-6mqq-2gc9-7j3v.json +++ b/advisories/unreviewed/2022/04/GHSA-6mqq-2gc9-7j3v/GHSA-6mqq-2gc9-7j3v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "WEB", diff --git a/advisories/unreviewed/2022/04/GHSA-6p5f-vq8j-gwq7/GHSA-6p5f-vq8j-gwq7.json b/advisories/unreviewed/2022/04/GHSA-6p5f-vq8j-gwq7/GHSA-6p5f-vq8j-gwq7.json index 4c12fb05153..39b8fec9ef6 100644 --- a/advisories/unreviewed/2022/04/GHSA-6p5f-vq8j-gwq7/GHSA-6p5f-vq8j-gwq7.json +++ b/advisories/unreviewed/2022/04/GHSA-6p5f-vq8j-gwq7/GHSA-6p5f-vq8j-gwq7.json @@ -7,12 +7,8 @@ "CVE-2004-2555" ], "details": "Riverdeep FoolProof Security 3.9.x on Windows 98 and Windows ME uses weak cryptography (arithmetic and XOR operations) to relate the Control password to the Administrator password, which allows local users to calculate the Administrator password if they know the Control password and password recovery key.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6rch-h7pj-5838/GHSA-6rch-h7pj-5838.json b/advisories/unreviewed/2022/04/GHSA-6rch-h7pj-5838/GHSA-6rch-h7pj-5838.json index 159711619e5..704af9851ed 100644 --- a/advisories/unreviewed/2022/04/GHSA-6rch-h7pj-5838/GHSA-6rch-h7pj-5838.json +++ b/advisories/unreviewed/2022/04/GHSA-6rch-h7pj-5838/GHSA-6rch-h7pj-5838.json @@ -7,12 +7,8 @@ "CVE-2004-2491" ], "details": "A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which allows remote attackers to spoof the URL in the address bar via the window.open and location.replace HTML parameters, which facilitates phishing attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-6vgj-39gw-mxw3/GHSA-6vgj-39gw-mxw3.json b/advisories/unreviewed/2022/04/GHSA-6vgj-39gw-mxw3/GHSA-6vgj-39gw-mxw3.json index b77acbc82a7..90fa890b63f 100644 --- a/advisories/unreviewed/2022/04/GHSA-6vgj-39gw-mxw3/GHSA-6vgj-39gw-mxw3.json +++ b/advisories/unreviewed/2022/04/GHSA-6vgj-39gw-mxw3/GHSA-6vgj-39gw-mxw3.json @@ -7,12 +7,8 @@ "CVE-2004-2682" ], "details": "PeerSec MatrixSSL before 1.1 does not implement RSA blinding, which allows context-dependent attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms (\"Karatsuba\" and normal), a related issue to CVE-2003-0147.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6xqv-7w4h-6vqr/GHSA-6xqv-7w4h-6vqr.json b/advisories/unreviewed/2022/04/GHSA-6xqv-7w4h-6vqr/GHSA-6xqv-7w4h-6vqr.json index f76989699a9..ee46fc18fe5 100644 --- a/advisories/unreviewed/2022/04/GHSA-6xqv-7w4h-6vqr/GHSA-6xqv-7w4h-6vqr.json +++ b/advisories/unreviewed/2022/04/GHSA-6xqv-7w4h-6vqr/GHSA-6xqv-7w4h-6vqr.json @@ -7,12 +7,8 @@ "CVE-2004-2738" ], "details": "Cross-site scripting (XSS) vulnerability in check_user_id.php in ZeroBoard 4.1pl4 and earlier allows remote attackers to inject arbitrary web script or HTML via the user_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-7348-84cp-xjx4/GHSA-7348-84cp-xjx4.json b/advisories/unreviewed/2022/04/GHSA-7348-84cp-xjx4/GHSA-7348-84cp-xjx4.json index 646fc00905c..6d1abc8bdb5 100644 --- a/advisories/unreviewed/2022/04/GHSA-7348-84cp-xjx4/GHSA-7348-84cp-xjx4.json +++ b/advisories/unreviewed/2022/04/GHSA-7348-84cp-xjx4/GHSA-7348-84cp-xjx4.json @@ -7,12 +7,8 @@ "CVE-2004-2700" ], "details": "Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7527-xrwh-9cq5/GHSA-7527-xrwh-9cq5.json b/advisories/unreviewed/2022/04/GHSA-7527-xrwh-9cq5/GHSA-7527-xrwh-9cq5.json index 543adaed263..8fbd97ea4a1 100644 --- a/advisories/unreviewed/2022/04/GHSA-7527-xrwh-9cq5/GHSA-7527-xrwh-9cq5.json +++ b/advisories/unreviewed/2022/04/GHSA-7527-xrwh-9cq5/GHSA-7527-xrwh-9cq5.json @@ -7,12 +7,8 @@ "CVE-2004-2756" ], "details": "Cross-site scripting (XSS) vulnerability in viewtopic.php in Xoops 2.x, possibly 2 through 2.0.5, allows remote attackers to inject arbitrary web script or HTML via the (1) forum and (2) topic_id parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-758w-3fxj-83wq/GHSA-758w-3fxj-83wq.json b/advisories/unreviewed/2022/04/GHSA-758w-3fxj-83wq/GHSA-758w-3fxj-83wq.json index ece0129fea7..9229b2bf7cd 100644 --- a/advisories/unreviewed/2022/04/GHSA-758w-3fxj-83wq/GHSA-758w-3fxj-83wq.json +++ b/advisories/unreviewed/2022/04/GHSA-758w-3fxj-83wq/GHSA-758w-3fxj-83wq.json @@ -7,12 +7,8 @@ "CVE-2004-2711" ], "details": "Multiple buffer overflows in Gyach Enhanced (Gyach-E) before 1.0.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to \"avatar retrieval.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-79p6-hxp5-mfcw/GHSA-79p6-hxp5-mfcw.json b/advisories/unreviewed/2022/04/GHSA-79p6-hxp5-mfcw/GHSA-79p6-hxp5-mfcw.json index 16c6f718086..0b5bb304956 100644 --- a/advisories/unreviewed/2022/04/GHSA-79p6-hxp5-mfcw/GHSA-79p6-hxp5-mfcw.json +++ b/advisories/unreviewed/2022/04/GHSA-79p6-hxp5-mfcw/GHSA-79p6-hxp5-mfcw.json @@ -7,12 +7,8 @@ "CVE-2004-2763" ], "details": "The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7c7w-55fc-fhgw/GHSA-7c7w-55fc-fhgw.json b/advisories/unreviewed/2022/04/GHSA-7c7w-55fc-fhgw/GHSA-7c7w-55fc-fhgw.json index 2045a03045a..91a423857be 100644 --- a/advisories/unreviewed/2022/04/GHSA-7c7w-55fc-fhgw/GHSA-7c7w-55fc-fhgw.json +++ b/advisories/unreviewed/2022/04/GHSA-7c7w-55fc-fhgw/GHSA-7c7w-55fc-fhgw.json @@ -7,12 +7,8 @@ "CVE-2004-2743" ], "details": "upload.cgi in Mega Upload Progress Bar before 1.45 allows remote attackers to copy or overwrite arbitrary files via unspecified parameters related to names of uploaded files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7fhq-48rw-37c8/GHSA-7fhq-48rw-37c8.json b/advisories/unreviewed/2022/04/GHSA-7fhq-48rw-37c8/GHSA-7fhq-48rw-37c8.json index 5a5035a634f..8a0a8aa4b5a 100644 --- a/advisories/unreviewed/2022/04/GHSA-7fhq-48rw-37c8/GHSA-7fhq-48rw-37c8.json +++ b/advisories/unreviewed/2022/04/GHSA-7fhq-48rw-37c8/GHSA-7fhq-48rw-37c8.json @@ -7,12 +7,8 @@ "CVE-2004-2562" ], "details": "SQL injection vulnerability in jobedit.asp in Leigh Business Enterprises (LBE) Web Helpdesk before 4.0.0.81 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7g72-46j8-2p2r/GHSA-7g72-46j8-2p2r.json b/advisories/unreviewed/2022/04/GHSA-7g72-46j8-2p2r/GHSA-7g72-46j8-2p2r.json index ef3c83d7b2f..6edafe53dfb 100644 --- a/advisories/unreviewed/2022/04/GHSA-7g72-46j8-2p2r/GHSA-7g72-46j8-2p2r.json +++ b/advisories/unreviewed/2022/04/GHSA-7g72-46j8-2p2r/GHSA-7g72-46j8-2p2r.json @@ -7,12 +7,8 @@ "CVE-2004-2609" ], "details": "The stuffit.com executable on Symantec PowerQuest DeployCenter 5.5 boot disks allows local users to obtain sensitive information (an unencrypted password for a Windows domain account) via four \"stuffit /f:stuffit.dat\" invocations, possibly due to a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7gj2-q7q5-28j5/GHSA-7gj2-q7q5-28j5.json b/advisories/unreviewed/2022/04/GHSA-7gj2-q7q5-28j5/GHSA-7gj2-q7q5-28j5.json index f536aa03b38..73fb6e10079 100644 --- a/advisories/unreviewed/2022/04/GHSA-7gj2-q7q5-28j5/GHSA-7gj2-q7q5-28j5.json +++ b/advisories/unreviewed/2022/04/GHSA-7gj2-q7q5-28j5/GHSA-7gj2-q7q5-28j5.json @@ -7,12 +7,8 @@ "CVE-2004-2523" ], "details": "Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in the message argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7j2q-p7jf-5f7p/GHSA-7j2q-p7jf-5f7p.json b/advisories/unreviewed/2022/04/GHSA-7j2q-p7jf-5f7p/GHSA-7j2q-p7jf-5f7p.json index e9f6eac5729..f39f7b4ff2b 100644 --- a/advisories/unreviewed/2022/04/GHSA-7j2q-p7jf-5f7p/GHSA-7j2q-p7jf-5f7p.json +++ b/advisories/unreviewed/2022/04/GHSA-7j2q-p7jf-5f7p/GHSA-7j2q-p7jf-5f7p.json @@ -7,12 +7,8 @@ "CVE-2004-2543" ], "details": "Secure Computing Corporation Sidewinder G2 6.1.0.01 might allow remote attackers to cause a denial of service (proxy failure) via invalid traffic to the (1) T.120 or (2) RTSP proxy, or (3) invalid MIME messages to the mail filter. NOTE: this might not be a vulnerability because the embedded monitoring sub-system automatically restarts after the failure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7jg9-96gf-f4px/GHSA-7jg9-96gf-f4px.json b/advisories/unreviewed/2022/04/GHSA-7jg9-96gf-f4px/GHSA-7jg9-96gf-f4px.json index 759cdd5f4da..75d7f5df55a 100644 --- a/advisories/unreviewed/2022/04/GHSA-7jg9-96gf-f4px/GHSA-7jg9-96gf-f4px.json +++ b/advisories/unreviewed/2022/04/GHSA-7jg9-96gf-f4px/GHSA-7jg9-96gf-f4px.json @@ -7,12 +7,8 @@ "CVE-2004-2542" ], "details": "Multiple SQL injection vulnerabilities in Dynix (formerly known as epixtech) WebPAC allow remote attackers to execute arbitrary SQL commands via unknown attack vectors, resulting in an ability to execute stored procedures, bypass login authentication, and cause an unspecified denial of service to backend databases.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7mcr-wpqh-pp73/GHSA-7mcr-wpqh-pp73.json b/advisories/unreviewed/2022/04/GHSA-7mcr-wpqh-pp73/GHSA-7mcr-wpqh-pp73.json index 0ea17acbe50..2b193e7d6dd 100644 --- a/advisories/unreviewed/2022/04/GHSA-7mcr-wpqh-pp73/GHSA-7mcr-wpqh-pp73.json +++ b/advisories/unreviewed/2022/04/GHSA-7mcr-wpqh-pp73/GHSA-7mcr-wpqh-pp73.json @@ -7,12 +7,8 @@ "CVE-2004-2636" ], "details": "TinyWeb 1.9 allows remote attackers to read source code of scripts via \"/./\" in the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7pq9-p77x-p4hf/GHSA-7pq9-p77x-p4hf.json b/advisories/unreviewed/2022/04/GHSA-7pq9-p77x-p4hf/GHSA-7pq9-p77x-p4hf.json index 5c1224af746..07f72d14111 100644 --- a/advisories/unreviewed/2022/04/GHSA-7pq9-p77x-p4hf/GHSA-7pq9-p77x-p4hf.json +++ b/advisories/unreviewed/2022/04/GHSA-7pq9-p77x-p4hf/GHSA-7pq9-p77x-p4hf.json @@ -7,12 +7,8 @@ "CVE-2004-2567" ], "details": "Multiple SQL injection vulnerabilities in ReciPants 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) user id, (2) recipe id, (3) category id, and (4) other ID number fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7qpr-6vx9-c755/GHSA-7qpr-6vx9-c755.json b/advisories/unreviewed/2022/04/GHSA-7qpr-6vx9-c755/GHSA-7qpr-6vx9-c755.json index 2bce6f15ebc..96ec5bf6d5e 100644 --- a/advisories/unreviewed/2022/04/GHSA-7qpr-6vx9-c755/GHSA-7qpr-6vx9-c755.json +++ b/advisories/unreviewed/2022/04/GHSA-7qpr-6vx9-c755/GHSA-7qpr-6vx9-c755.json @@ -7,12 +7,8 @@ "CVE-2004-2496" ], "details": "The HTTP daemon in OpenText FirstClass 7.1 and 8.0 allows remote attackers to cause a denial of service (service availability loss) via a large number of POST requests to /Search.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7w59-vwgr-5pgr/GHSA-7w59-vwgr-5pgr.json b/advisories/unreviewed/2022/04/GHSA-7w59-vwgr-5pgr/GHSA-7w59-vwgr-5pgr.json index 7ba105c27f5..ad4283ab8dd 100644 --- a/advisories/unreviewed/2022/04/GHSA-7w59-vwgr-5pgr/GHSA-7w59-vwgr-5pgr.json +++ b/advisories/unreviewed/2022/04/GHSA-7w59-vwgr-5pgr/GHSA-7w59-vwgr-5pgr.json @@ -7,12 +7,8 @@ "CVE-2004-2643" ], "details": "Directory traversal vulnerability in Microsoft cabarc allows remote attackers to overwrite files via \"../\" sequences in file names in a CAB archive.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-86jg-c9mr-jw7m/GHSA-86jg-c9mr-jw7m.json b/advisories/unreviewed/2022/04/GHSA-86jg-c9mr-jw7m/GHSA-86jg-c9mr-jw7m.json index 904783d0dfe..c86a7260440 100644 --- a/advisories/unreviewed/2022/04/GHSA-86jg-c9mr-jw7m/GHSA-86jg-c9mr-jw7m.json +++ b/advisories/unreviewed/2022/04/GHSA-86jg-c9mr-jw7m/GHSA-86jg-c9mr-jw7m.json @@ -7,12 +7,8 @@ "CVE-2004-2612" ], "details": "BNC 2.9.0 only grants access when an incorrect password is provided, which allows remote attackers to use the functionality intended for authorized users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-86w6-qr9g-m66p/GHSA-86w6-qr9g-m66p.json b/advisories/unreviewed/2022/04/GHSA-86w6-qr9g-m66p/GHSA-86w6-qr9g-m66p.json index 2158a121e6f..ae7dcfabee3 100644 --- a/advisories/unreviewed/2022/04/GHSA-86w6-qr9g-m66p/GHSA-86w6-qr9g-m66p.json +++ b/advisories/unreviewed/2022/04/GHSA-86w6-qr9g-m66p/GHSA-86w6-qr9g-m66p.json @@ -7,12 +7,8 @@ "CVE-2004-2527" ], "details": "The local and remote desktop login screens in Microsoft Windows XP before SP2 and 2003 allow remote attackers to cause a denial of service (CPU and memory consumption) by repeatedly using the WinKey+\"U\" key combination, which causes multiple copies of Windows Utility Manager to be loaded more quickly than they can be closed when the copies detect that another instance is running.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-88vv-hvrc-733q/GHSA-88vv-hvrc-733q.json b/advisories/unreviewed/2022/04/GHSA-88vv-hvrc-733q/GHSA-88vv-hvrc-733q.json index eb84a39de07..aa52b7d7440 100644 --- a/advisories/unreviewed/2022/04/GHSA-88vv-hvrc-733q/GHSA-88vv-hvrc-733q.json +++ b/advisories/unreviewed/2022/04/GHSA-88vv-hvrc-733q/GHSA-88vv-hvrc-733q.json @@ -7,12 +7,8 @@ "CVE-2004-2687" ], "details": "distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8924-w9cg-j6hh/GHSA-8924-w9cg-j6hh.json b/advisories/unreviewed/2022/04/GHSA-8924-w9cg-j6hh/GHSA-8924-w9cg-j6hh.json index 908139d2109..2b6170ef632 100644 --- a/advisories/unreviewed/2022/04/GHSA-8924-w9cg-j6hh/GHSA-8924-w9cg-j6hh.json +++ b/advisories/unreviewed/2022/04/GHSA-8924-w9cg-j6hh/GHSA-8924-w9cg-j6hh.json @@ -7,12 +7,8 @@ "CVE-2004-2696" ], "details": "BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, when using Remote Method Invocation (RMI) over Internet Inter-ORB Protocol (IIOP), does not properly handle when multiple logins for different users coming from the same client, which could cause an \"unexpected user identity\" to be used in an RMI call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-896f-4xcx-6p32/GHSA-896f-4xcx-6p32.json b/advisories/unreviewed/2022/04/GHSA-896f-4xcx-6p32/GHSA-896f-4xcx-6p32.json index b25b7d6b8d6..16f9e84f8b2 100644 --- a/advisories/unreviewed/2022/04/GHSA-896f-4xcx-6p32/GHSA-896f-4xcx-6p32.json +++ b/advisories/unreviewed/2022/04/GHSA-896f-4xcx-6p32/GHSA-896f-4xcx-6p32.json @@ -7,12 +7,8 @@ "CVE-2004-2757" ], "details": "Cross-site scripting (XSS) vulnerability in the failed login page in Novell iChain before 2.2 build 2.2.113 and 2.3 First Customer Ship (FCS) allows remote attackers to inject arbitrary web script or HTML via url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-8f2r-wvm7-v573/GHSA-8f2r-wvm7-v573.json b/advisories/unreviewed/2022/04/GHSA-8f2r-wvm7-v573/GHSA-8f2r-wvm7-v573.json index 5d58bc57d32..73a4540a231 100644 --- a/advisories/unreviewed/2022/04/GHSA-8f2r-wvm7-v573/GHSA-8f2r-wvm7-v573.json +++ b/advisories/unreviewed/2022/04/GHSA-8f2r-wvm7-v573/GHSA-8f2r-wvm7-v573.json @@ -7,12 +7,8 @@ "CVE-2004-2615" ], "details": "The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8f69-wvhw-fqc8/GHSA-8f69-wvhw-fqc8.json b/advisories/unreviewed/2022/04/GHSA-8f69-wvhw-fqc8/GHSA-8f69-wvhw-fqc8.json index 5d7f5cd200e..f465e7159ad 100644 --- a/advisories/unreviewed/2022/04/GHSA-8f69-wvhw-fqc8/GHSA-8f69-wvhw-fqc8.json +++ b/advisories/unreviewed/2022/04/GHSA-8f69-wvhw-fqc8/GHSA-8f69-wvhw-fqc8.json @@ -7,12 +7,8 @@ "CVE-2004-2621" ], "details": "Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway certificate until after a dialog box has been displayed to the user, which creates a race condition that allows remote attackers to perform a man-in-the-middle (MITM) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8gx2-4pf6-cr9q/GHSA-8gx2-4pf6-cr9q.json b/advisories/unreviewed/2022/04/GHSA-8gx2-4pf6-cr9q/GHSA-8gx2-4pf6-cr9q.json index 6e79f6d37ae..a2ccffe2050 100644 --- a/advisories/unreviewed/2022/04/GHSA-8gx2-4pf6-cr9q/GHSA-8gx2-4pf6-cr9q.json +++ b/advisories/unreviewed/2022/04/GHSA-8gx2-4pf6-cr9q/GHSA-8gx2-4pf6-cr9q.json @@ -7,12 +7,8 @@ "CVE-2004-2582" ], "details": "Novell iChain 2.3 includes the build number in the VIA line of the proxy server's HTTP headers, which allows remote attackers to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8mv9-p6wj-fc88/GHSA-8mv9-p6wj-fc88.json b/advisories/unreviewed/2022/04/GHSA-8mv9-p6wj-fc88/GHSA-8mv9-p6wj-fc88.json index 2d950ae368a..2378b048451 100644 --- a/advisories/unreviewed/2022/04/GHSA-8mv9-p6wj-fc88/GHSA-8mv9-p6wj-fc88.json +++ b/advisories/unreviewed/2022/04/GHSA-8mv9-p6wj-fc88/GHSA-8mv9-p6wj-fc88.json @@ -7,12 +7,8 @@ "CVE-2004-2522" ], "details": "Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject arbitrary web script or HTML via the (1) template or (2) language parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8ppj-m7pv-xfgv/GHSA-8ppj-m7pv-xfgv.json b/advisories/unreviewed/2022/04/GHSA-8ppj-m7pv-xfgv/GHSA-8ppj-m7pv-xfgv.json index ce723c9cd97..ec9246bd8a3 100644 --- a/advisories/unreviewed/2022/04/GHSA-8ppj-m7pv-xfgv/GHSA-8ppj-m7pv-xfgv.json +++ b/advisories/unreviewed/2022/04/GHSA-8ppj-m7pv-xfgv/GHSA-8ppj-m7pv-xfgv.json @@ -7,12 +7,8 @@ "CVE-2004-2747" ], "details": "Directory traversal vulnerability in Pablo Software Solutions Quick 'n Easy FTP Server 1.77, and possibly earlier versions, allows remote authenticated users to determine the existence of arbitrary files via a .. (dot dot) in the DEL command, which triggers different error messages depending on whether the file exists or not.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-8q7c-xwf8-vm5r/GHSA-8q7c-xwf8-vm5r.json b/advisories/unreviewed/2022/04/GHSA-8q7c-xwf8-vm5r/GHSA-8q7c-xwf8-vm5r.json index 04c36530814..da999c0c933 100644 --- a/advisories/unreviewed/2022/04/GHSA-8q7c-xwf8-vm5r/GHSA-8q7c-xwf8-vm5r.json +++ b/advisories/unreviewed/2022/04/GHSA-8q7c-xwf8-vm5r/GHSA-8q7c-xwf8-vm5r.json @@ -7,12 +7,8 @@ "CVE-2004-2677" ], "details": "Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format specifiers in the (1) clientRcptTo array, and the (2) Received and (3) messageID variables, possibly involving HELO and hostname arguments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8qp8-665c-7xjf/GHSA-8qp8-665c-7xjf.json b/advisories/unreviewed/2022/04/GHSA-8qp8-665c-7xjf/GHSA-8qp8-665c-7xjf.json index 5acbf9ffc96..5316e25bc12 100644 --- a/advisories/unreviewed/2022/04/GHSA-8qp8-665c-7xjf/GHSA-8qp8-665c-7xjf.json +++ b/advisories/unreviewed/2022/04/GHSA-8qp8-665c-7xjf/GHSA-8qp8-665c-7xjf.json @@ -7,12 +7,8 @@ "CVE-2004-2628" ], "details": "Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence (\"%5C..\") or (2) a drive letter (such as \"C:\").", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8rwx-4596-hpv5/GHSA-8rwx-4596-hpv5.json b/advisories/unreviewed/2022/04/GHSA-8rwx-4596-hpv5/GHSA-8rwx-4596-hpv5.json index 3e4d2848bec..51360fb76a8 100644 --- a/advisories/unreviewed/2022/04/GHSA-8rwx-4596-hpv5/GHSA-8rwx-4596-hpv5.json +++ b/advisories/unreviewed/2022/04/GHSA-8rwx-4596-hpv5/GHSA-8rwx-4596-hpv5.json @@ -7,12 +7,8 @@ "CVE-2004-2725" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Aztek Forum 4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter in (a) search.php, (2) the email parameter in (b) subscribe.php, and (3) the return and (4) title parameters in (c) forum_2.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-8v2x-hr7h-j8qx/GHSA-8v2x-hr7h-j8qx.json b/advisories/unreviewed/2022/04/GHSA-8v2x-hr7h-j8qx/GHSA-8v2x-hr7h-j8qx.json index cc41448cb3c..0eb8c4ac719 100644 --- a/advisories/unreviewed/2022/04/GHSA-8v2x-hr7h-j8qx/GHSA-8v2x-hr7h-j8qx.json +++ b/advisories/unreviewed/2022/04/GHSA-8v2x-hr7h-j8qx/GHSA-8v2x-hr7h-j8qx.json @@ -7,12 +7,8 @@ "CVE-2004-2546" ], "details": "Multiple memory leaks in Samba before 3.0.6 allow attackers to cause a denial of service (memory consumption).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8w9h-6c6m-8g5q/GHSA-8w9h-6c6m-8g5q.json b/advisories/unreviewed/2022/04/GHSA-8w9h-6c6m-8g5q/GHSA-8w9h-6c6m-8g5q.json index 535f5c08b19..928cdd0aea8 100644 --- a/advisories/unreviewed/2022/04/GHSA-8w9h-6c6m-8g5q/GHSA-8w9h-6c6m-8g5q.json +++ b/advisories/unreviewed/2022/04/GHSA-8w9h-6c6m-8g5q/GHSA-8w9h-6c6m-8g5q.json @@ -7,12 +7,8 @@ "CVE-2004-2602" ], "details": "PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) before 1.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the HCL_path parameter to pipe.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8xj6-6239-7mwx/GHSA-8xj6-6239-7mwx.json b/advisories/unreviewed/2022/04/GHSA-8xj6-6239-7mwx/GHSA-8xj6-6239-7mwx.json index 5afa7955bf5..b35f95cf21c 100644 --- a/advisories/unreviewed/2022/04/GHSA-8xj6-6239-7mwx/GHSA-8xj6-6239-7mwx.json +++ b/advisories/unreviewed/2022/04/GHSA-8xj6-6239-7mwx/GHSA-8xj6-6239-7mwx.json @@ -7,12 +7,8 @@ "CVE-2004-2709" ], "details": "Buffer overflow in the strip_html_tags method for Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown vectors involving HTML tags.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-93h5-jmg6-mmph/GHSA-93h5-jmg6-mmph.json b/advisories/unreviewed/2022/04/GHSA-93h5-jmg6-mmph/GHSA-93h5-jmg6-mmph.json index 31cfd45c6e8..819455463d0 100644 --- a/advisories/unreviewed/2022/04/GHSA-93h5-jmg6-mmph/GHSA-93h5-jmg6-mmph.json +++ b/advisories/unreviewed/2022/04/GHSA-93h5-jmg6-mmph/GHSA-93h5-jmg6-mmph.json @@ -7,12 +7,8 @@ "CVE-2004-2536" ], "details": "The exit_thread function (process.c) in Linux kernel 2.6 through 2.6.5 does not invalidate the per-TSS io_bitmap pointers if a process obtains IO access permissions from the ioperm function but does not drop those permissions when it exits, which allows other processes to access the per-TSS pointers, access restricted memory locations, and possibly gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-944q-gmcx-pp5j/GHSA-944q-gmcx-pp5j.json b/advisories/unreviewed/2022/04/GHSA-944q-gmcx-pp5j/GHSA-944q-gmcx-pp5j.json index 08a9f9feb44..b1c874e7af5 100644 --- a/advisories/unreviewed/2022/04/GHSA-944q-gmcx-pp5j/GHSA-944q-gmcx-pp5j.json +++ b/advisories/unreviewed/2022/04/GHSA-944q-gmcx-pp5j/GHSA-944q-gmcx-pp5j.json @@ -7,12 +7,8 @@ "CVE-2004-2585" ], "details": "Cross-site scripting (XSS) vulnerability in frmCompose.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to inject arbitrary web script or HTML via Javascript to the \"check spelling\" feature in the compose area.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-968h-qw7j-96w3/GHSA-968h-qw7j-96w3.json b/advisories/unreviewed/2022/04/GHSA-968h-qw7j-96w3/GHSA-968h-qw7j-96w3.json index d96a8e420d3..ec2a7dd61b6 100644 --- a/advisories/unreviewed/2022/04/GHSA-968h-qw7j-96w3/GHSA-968h-qw7j-96w3.json +++ b/advisories/unreviewed/2022/04/GHSA-968h-qw7j-96w3/GHSA-968h-qw7j-96w3.json @@ -7,12 +7,8 @@ "CVE-2004-2489" ], "details": "Format string vulnerability in IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to execute arbitrary code via a modified INFORMIXDIR environment variable that points to a file with format string specifiers in the filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-98j3-g9mx-9rxh/GHSA-98j3-g9mx-9rxh.json b/advisories/unreviewed/2022/04/GHSA-98j3-g9mx-9rxh/GHSA-98j3-g9mx-9rxh.json index 8b82e54bfad..002b7f26a7f 100644 --- a/advisories/unreviewed/2022/04/GHSA-98j3-g9mx-9rxh/GHSA-98j3-g9mx-9rxh.json +++ b/advisories/unreviewed/2022/04/GHSA-98j3-g9mx-9rxh/GHSA-98j3-g9mx-9rxh.json @@ -7,12 +7,8 @@ "CVE-2004-2477" ], "details": "DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in \\device\\physicalmemory with the original SDT found in ntoskrnl.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9cgp-mfwv-fgfw/GHSA-9cgp-mfwv-fgfw.json b/advisories/unreviewed/2022/04/GHSA-9cgp-mfwv-fgfw/GHSA-9cgp-mfwv-fgfw.json index bfdc293cecd..1b541cb526b 100644 --- a/advisories/unreviewed/2022/04/GHSA-9cgp-mfwv-fgfw/GHSA-9cgp-mfwv-fgfw.json +++ b/advisories/unreviewed/2022/04/GHSA-9cgp-mfwv-fgfw/GHSA-9cgp-mfwv-fgfw.json @@ -7,12 +7,8 @@ "CVE-2004-2577" ], "details": "The acl_check function in phpGroupWare 0.9.16RC2 always returns True, even when mkdir does not behave as expected, which could allow remote attackers to obtain sensitive information via WebDAV from users' home directories that lack .htaccess files, and possibly has other unknown impacts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9cmf-77hw-89cq/GHSA-9cmf-77hw-89cq.json b/advisories/unreviewed/2022/04/GHSA-9cmf-77hw-89cq/GHSA-9cmf-77hw-89cq.json index 4861cfc3042..6855fbe6eac 100644 --- a/advisories/unreviewed/2022/04/GHSA-9cmf-77hw-89cq/GHSA-9cmf-77hw-89cq.json +++ b/advisories/unreviewed/2022/04/GHSA-9cmf-77hw-89cq/GHSA-9cmf-77hw-89cq.json @@ -7,12 +7,8 @@ "CVE-2004-2505" ], "details": "Macromedia ColdFusion MX before 6.1 does not restrict the size of error messages, which allows remote attackers to cause a denial of service (memory consumption and crash) by sending repeated GET or POST requests that trigger error messages that use long strings of data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9gjm-q5qg-hm29/GHSA-9gjm-q5qg-hm29.json b/advisories/unreviewed/2022/04/GHSA-9gjm-q5qg-hm29/GHSA-9gjm-q5qg-hm29.json index 567d54798fe..bc49addc4bb 100644 --- a/advisories/unreviewed/2022/04/GHSA-9gjm-q5qg-hm29/GHSA-9gjm-q5qg-hm29.json +++ b/advisories/unreviewed/2022/04/GHSA-9gjm-q5qg-hm29/GHSA-9gjm-q5qg-hm29.json @@ -7,12 +7,8 @@ "CVE-2004-2514" ], "details": "Cross-site scripting (XSS) vulnerability in modules/private_messages/index.php in PowerPortal 1.x allows remote attackers to inject arbitrary web script or HTML via the (1) SUBJECT or (2) MESSAGE field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9h2x-7449-7c5m/GHSA-9h2x-7449-7c5m.json b/advisories/unreviewed/2022/04/GHSA-9h2x-7449-7c5m/GHSA-9h2x-7449-7c5m.json index 1e9c8486d26..a0eaa4ecd18 100644 --- a/advisories/unreviewed/2022/04/GHSA-9h2x-7449-7c5m/GHSA-9h2x-7449-7c5m.json +++ b/advisories/unreviewed/2022/04/GHSA-9h2x-7449-7c5m/GHSA-9h2x-7449-7c5m.json @@ -7,12 +7,8 @@ "CVE-2004-2638" ], "details": "The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the \"admin/\" directory by modifying the in_login parameter to a non-zero value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9qj7-66wc-7r4j/GHSA-9qj7-66wc-7r4j.json b/advisories/unreviewed/2022/04/GHSA-9qj7-66wc-7r4j/GHSA-9qj7-66wc-7r4j.json index 89548157a37..739f9ac1c79 100644 --- a/advisories/unreviewed/2022/04/GHSA-9qj7-66wc-7r4j/GHSA-9qj7-66wc-7r4j.json +++ b/advisories/unreviewed/2022/04/GHSA-9qj7-66wc-7r4j/GHSA-9qj7-66wc-7r4j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-9qmw-v2p2-gwc6/GHSA-9qmw-v2p2-gwc6.json b/advisories/unreviewed/2022/04/GHSA-9qmw-v2p2-gwc6/GHSA-9qmw-v2p2-gwc6.json index 63b49ca1c89..be8e785a31a 100644 --- a/advisories/unreviewed/2022/04/GHSA-9qmw-v2p2-gwc6/GHSA-9qmw-v2p2-gwc6.json +++ b/advisories/unreviewed/2022/04/GHSA-9qmw-v2p2-gwc6/GHSA-9qmw-v2p2-gwc6.json @@ -7,12 +7,8 @@ "CVE-2004-2590" ], "details": "Unspecified vulnerability in meindlSOFT Cute PHP Library (aka cphplib) 0.46 has unknown impact and attack vectors, related to regular expressions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9w4c-j8rv-92hw/GHSA-9w4c-j8rv-92hw.json b/advisories/unreviewed/2022/04/GHSA-9w4c-j8rv-92hw/GHSA-9w4c-j8rv-92hw.json index 44949122dbf..cee34782672 100644 --- a/advisories/unreviewed/2022/04/GHSA-9w4c-j8rv-92hw/GHSA-9w4c-j8rv-92hw.json +++ b/advisories/unreviewed/2022/04/GHSA-9w4c-j8rv-92hw/GHSA-9w4c-j8rv-92hw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-9w4v-gj4q-78jc/GHSA-9w4v-gj4q-78jc.json b/advisories/unreviewed/2022/04/GHSA-9w4v-gj4q-78jc/GHSA-9w4v-gj4q-78jc.json index df70125de48..128fba3d110 100644 --- a/advisories/unreviewed/2022/04/GHSA-9w4v-gj4q-78jc/GHSA-9w4v-gj4q-78jc.json +++ b/advisories/unreviewed/2022/04/GHSA-9w4v-gj4q-78jc/GHSA-9w4v-gj4q-78jc.json @@ -7,12 +7,8 @@ "CVE-2004-2690" ], "details": "Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrators to upload and execute arbitrary code instead of video files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9wfg-2349-2vfw/GHSA-9wfg-2349-2vfw.json b/advisories/unreviewed/2022/04/GHSA-9wfg-2349-2vfw/GHSA-9wfg-2349-2vfw.json index 01c4a3f590e..313c3a0a0b1 100644 --- a/advisories/unreviewed/2022/04/GHSA-9wfg-2349-2vfw/GHSA-9wfg-2349-2vfw.json +++ b/advisories/unreviewed/2022/04/GHSA-9wfg-2349-2vfw/GHSA-9wfg-2349-2vfw.json @@ -7,12 +7,8 @@ "CVE-2004-2667" ], "details": "Cross-site scripting (XSS) vulnerability in Lotus Domino 6.0.x before 6.0.4 and 6.5.x before 6.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9wwc-xv4f-3h57/GHSA-9wwc-xv4f-3h57.json b/advisories/unreviewed/2022/04/GHSA-9wwc-xv4f-3h57/GHSA-9wwc-xv4f-3h57.json index 647cc9bbcd0..025995970bd 100644 --- a/advisories/unreviewed/2022/04/GHSA-9wwc-xv4f-3h57/GHSA-9wwc-xv4f-3h57.json +++ b/advisories/unreviewed/2022/04/GHSA-9wwc-xv4f-3h57/GHSA-9wwc-xv4f-3h57.json @@ -7,12 +7,8 @@ "CVE-2004-2563" ], "details": "Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and database information, and conduct cross-site scripting (XSS) attacks, via a direct request to tmtrack.dll with modified LoginPage and Template parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c246-vh69-9f94/GHSA-c246-vh69-9f94.json b/advisories/unreviewed/2022/04/GHSA-c246-vh69-9f94/GHSA-c246-vh69-9f94.json index c04d08f89b9..7e40db1969e 100644 --- a/advisories/unreviewed/2022/04/GHSA-c246-vh69-9f94/GHSA-c246-vh69-9f94.json +++ b/advisories/unreviewed/2022/04/GHSA-c246-vh69-9f94/GHSA-c246-vh69-9f94.json @@ -7,12 +7,8 @@ "CVE-2004-2736" ], "details": "Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-c2p4-pf84-gvqv/GHSA-c2p4-pf84-gvqv.json b/advisories/unreviewed/2022/04/GHSA-c2p4-pf84-gvqv/GHSA-c2p4-pf84-gvqv.json index 3d7c4cefbbc..0c7c7387dcc 100644 --- a/advisories/unreviewed/2022/04/GHSA-c2p4-pf84-gvqv/GHSA-c2p4-pf84-gvqv.json +++ b/advisories/unreviewed/2022/04/GHSA-c2p4-pf84-gvqv/GHSA-c2p4-pf84-gvqv.json @@ -7,12 +7,8 @@ "CVE-2004-2720" ], "details": "Cross-site scripting (XSS) vulnerability in register.asp in Snitz Forums 2000 3.4.04 and earlier allows remote attackers to inject arbitrary web script or HTML via javascript events in the Email parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-c36f-rpx7-9qq3/GHSA-c36f-rpx7-9qq3.json b/advisories/unreviewed/2022/04/GHSA-c36f-rpx7-9qq3/GHSA-c36f-rpx7-9qq3.json index d18d77a448f..63d95361b47 100644 --- a/advisories/unreviewed/2022/04/GHSA-c36f-rpx7-9qq3/GHSA-c36f-rpx7-9qq3.json +++ b/advisories/unreviewed/2022/04/GHSA-c36f-rpx7-9qq3/GHSA-c36f-rpx7-9qq3.json @@ -7,12 +7,8 @@ "CVE-2004-2664" ], "details": "John Lim ADOdb Library for PHP before 4.23 allows remote attackers to obtain sensitive information via direct requests to certain scripts that result in an undefined value of ADODB_DIR, which reveals the installation path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c5x8-wmm9-q2mc/GHSA-c5x8-wmm9-q2mc.json b/advisories/unreviewed/2022/04/GHSA-c5x8-wmm9-q2mc/GHSA-c5x8-wmm9-q2mc.json index 55fad4fba43..f05699cc38a 100644 --- a/advisories/unreviewed/2022/04/GHSA-c5x8-wmm9-q2mc/GHSA-c5x8-wmm9-q2mc.json +++ b/advisories/unreviewed/2022/04/GHSA-c5x8-wmm9-q2mc/GHSA-c5x8-wmm9-q2mc.json @@ -7,12 +7,8 @@ "CVE-2004-2493" ], "details": "Directory traversal vulnerability in Groupmax World Wide Web (GmaxWWW) 2 and 3, and Desktop 5, 6, and Desktop for Jichitai allows remote authenticated users to read arbitrary .html files via the template name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c6m7-4rrm-9vfv/GHSA-c6m7-4rrm-9vfv.json b/advisories/unreviewed/2022/04/GHSA-c6m7-4rrm-9vfv/GHSA-c6m7-4rrm-9vfv.json index 74c7f7606db..89ddf0f8bbb 100644 --- a/advisories/unreviewed/2022/04/GHSA-c6m7-4rrm-9vfv/GHSA-c6m7-4rrm-9vfv.json +++ b/advisories/unreviewed/2022/04/GHSA-c6m7-4rrm-9vfv/GHSA-c6m7-4rrm-9vfv.json @@ -7,12 +7,8 @@ "CVE-2004-2483" ], "details": "Kerio WinRoute Firewall before 6.0.9 uses information from PTR queries in response to A queries, which allows remote attackers to poison the DNS cache or cause a denial of service (connection loss).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c6r9-fwjp-wq6g/GHSA-c6r9-fwjp-wq6g.json b/advisories/unreviewed/2022/04/GHSA-c6r9-fwjp-wq6g/GHSA-c6r9-fwjp-wq6g.json index 852bbb8495b..1699306d724 100644 --- a/advisories/unreviewed/2022/04/GHSA-c6r9-fwjp-wq6g/GHSA-c6r9-fwjp-wq6g.json +++ b/advisories/unreviewed/2022/04/GHSA-c6r9-fwjp-wq6g/GHSA-c6r9-fwjp-wq6g.json @@ -7,12 +7,8 @@ "CVE-2004-2517" ], "details": "myServer 0.7.1 allows remote attackers to cause a denial of service (crash) via a long HTTP POST request in a View=Logon operation to index.html.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c6v6-cvxf-8hr8/GHSA-c6v6-cvxf-8hr8.json b/advisories/unreviewed/2022/04/GHSA-c6v6-cvxf-8hr8/GHSA-c6v6-cvxf-8hr8.json index def2fe5d62f..7559b86dfa2 100644 --- a/advisories/unreviewed/2022/04/GHSA-c6v6-cvxf-8hr8/GHSA-c6v6-cvxf-8hr8.json +++ b/advisories/unreviewed/2022/04/GHSA-c6v6-cvxf-8hr8/GHSA-c6v6-cvxf-8hr8.json @@ -7,12 +7,8 @@ "CVE-2004-2580" ], "details": "Cross-site scripting (XSS) vulnerability in Novell iChain 2.3 allows remote attackers to obtain login credentials via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c993-69wp-v2c4/GHSA-c993-69wp-v2c4.json b/advisories/unreviewed/2022/04/GHSA-c993-69wp-v2c4/GHSA-c993-69wp-v2c4.json index f75949366b6..a0d935d49bc 100644 --- a/advisories/unreviewed/2022/04/GHSA-c993-69wp-v2c4/GHSA-c993-69wp-v2c4.json +++ b/advisories/unreviewed/2022/04/GHSA-c993-69wp-v2c4/GHSA-c993-69wp-v2c4.json @@ -7,12 +7,8 @@ "CVE-2004-2767" ], "details": "NWFTPD.nlm before 5.04.25 in the FTP server in Novell NetWare does not promptly close DS sessions, which allows remote attackers to cause a denial of service (connection slot exhaustion) by establishing many FTP sessions that persist for the lifetime of a DS session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cc5r-5c3q-fh45/GHSA-cc5r-5c3q-fh45.json b/advisories/unreviewed/2022/04/GHSA-cc5r-5c3q-fh45/GHSA-cc5r-5c3q-fh45.json index 73f2834c20e..1c676a1545c 100644 --- a/advisories/unreviewed/2022/04/GHSA-cc5r-5c3q-fh45/GHSA-cc5r-5c3q-fh45.json +++ b/advisories/unreviewed/2022/04/GHSA-cc5r-5c3q-fh45/GHSA-cc5r-5c3q-fh45.json @@ -7,12 +7,8 @@ "CVE-2004-2576" ], "details": "class.vfs_dav.inc.php in phpGroupWare 0.9.16.000 does not create .htaccess files to enable authorization checks for access to users' home-directory files, which allows remote attackers to obtain sensitive information from these files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cc6v-6qwr-m66x/GHSA-cc6v-6qwr-m66x.json b/advisories/unreviewed/2022/04/GHSA-cc6v-6qwr-m66x/GHSA-cc6v-6qwr-m66x.json index c81bc69c63f..a10c3510e38 100644 --- a/advisories/unreviewed/2022/04/GHSA-cc6v-6qwr-m66x/GHSA-cc6v-6qwr-m66x.json +++ b/advisories/unreviewed/2022/04/GHSA-cc6v-6qwr-m66x/GHSA-cc6v-6qwr-m66x.json @@ -7,12 +7,8 @@ "CVE-2004-2641" ], "details": "Unspecified vulnerability in Sun Fire 3800/4800/4810/6800, Sun Fire V1280, and Netra 1280 allows remote attackers to cause a denial of service (system controller hang) via IP Packets With Type of Service (TOS) Bits set.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cf28-6v7w-9rcf/GHSA-cf28-6v7w-9rcf.json b/advisories/unreviewed/2022/04/GHSA-cf28-6v7w-9rcf/GHSA-cf28-6v7w-9rcf.json index 4f60c76a87a..a5fe8131397 100644 --- a/advisories/unreviewed/2022/04/GHSA-cf28-6v7w-9rcf/GHSA-cf28-6v7w-9rcf.json +++ b/advisories/unreviewed/2022/04/GHSA-cf28-6v7w-9rcf/GHSA-cf28-6v7w-9rcf.json @@ -7,12 +7,8 @@ "CVE-2004-2492" ], "details": "Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web (GmaxWWW) Desktop 5, 6, and Desktop for Jichitai 6, allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cg58-pmcc-63vj/GHSA-cg58-pmcc-63vj.json b/advisories/unreviewed/2022/04/GHSA-cg58-pmcc-63vj/GHSA-cg58-pmcc-63vj.json index 96ca718061d..2bcf59947b0 100644 --- a/advisories/unreviewed/2022/04/GHSA-cg58-pmcc-63vj/GHSA-cg58-pmcc-63vj.json +++ b/advisories/unreviewed/2022/04/GHSA-cg58-pmcc-63vj/GHSA-cg58-pmcc-63vj.json @@ -7,12 +7,8 @@ "CVE-2004-2693" ], "details": "HP-UX B.11.00 and B.11.11 with B6848AB GTK+ Support Libraries installed uses insecure directory permissions, which allows local users to gain privileges via files in /opt/gnome/src/GLib/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cgvr-863q-564c/GHSA-cgvr-863q-564c.json b/advisories/unreviewed/2022/04/GHSA-cgvr-863q-564c/GHSA-cgvr-863q-564c.json index 9e60fea5b5a..a9b36024e99 100644 --- a/advisories/unreviewed/2022/04/GHSA-cgvr-863q-564c/GHSA-cgvr-863q-564c.json +++ b/advisories/unreviewed/2022/04/GHSA-cgvr-863q-564c/GHSA-cgvr-863q-564c.json @@ -7,12 +7,8 @@ "CVE-2004-2702" ], "details": "Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter. NOTE: this might be the same vector as CVE-2006-6451.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-cjpf-wj6v-f529/GHSA-cjpf-wj6v-f529.json b/advisories/unreviewed/2022/04/GHSA-cjpf-wj6v-f529/GHSA-cjpf-wj6v-f529.json index c6a4526ee2a..94f8fb76d35 100644 --- a/advisories/unreviewed/2022/04/GHSA-cjpf-wj6v-f529/GHSA-cjpf-wj6v-f529.json +++ b/advisories/unreviewed/2022/04/GHSA-cjpf-wj6v-f529/GHSA-cjpf-wj6v-f529.json @@ -7,12 +7,8 @@ "CVE-2004-2570" ], "details": "Opera before 7.54 allows remote attackers to modify properties and methods of the location object and execute Javascript to read arbitrary files from the client's local filesystem or display a false URL to the user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-cp69-hrg6-gmgh/GHSA-cp69-hrg6-gmgh.json b/advisories/unreviewed/2022/04/GHSA-cp69-hrg6-gmgh/GHSA-cp69-hrg6-gmgh.json index 07d88b447ba..d59b1a87f20 100644 --- a/advisories/unreviewed/2022/04/GHSA-cp69-hrg6-gmgh/GHSA-cp69-hrg6-gmgh.json +++ b/advisories/unreviewed/2022/04/GHSA-cp69-hrg6-gmgh/GHSA-cp69-hrg6-gmgh.json @@ -7,12 +7,8 @@ "CVE-2004-2662" ], "details": "Soft3304 04WebServer before 1.41 allows remote attackers to cause a denial of service (resource consumption or crash) via certain data related to OpenSSL, which causes a thread to terminate but continue to hold resources.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cpgf-j9v7-ww54/GHSA-cpgf-j9v7-ww54.json b/advisories/unreviewed/2022/04/GHSA-cpgf-j9v7-ww54/GHSA-cpgf-j9v7-ww54.json index 910a34da1df..4f14c1f3d8a 100644 --- a/advisories/unreviewed/2022/04/GHSA-cpgf-j9v7-ww54/GHSA-cpgf-j9v7-ww54.json +++ b/advisories/unreviewed/2022/04/GHSA-cpgf-j9v7-ww54/GHSA-cpgf-j9v7-ww54.json @@ -7,12 +7,8 @@ "CVE-2004-2739" ], "details": "The setup routine (setup.php) in PHProjekt 4.2.1 and earlier allows remote attackers to modify system configuration via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cpj4-3r8w-83gx/GHSA-cpj4-3r8w-83gx.json b/advisories/unreviewed/2022/04/GHSA-cpj4-3r8w-83gx/GHSA-cpj4-3r8w-83gx.json index 2c623cb2726..c58f8acc1b8 100644 --- a/advisories/unreviewed/2022/04/GHSA-cpj4-3r8w-83gx/GHSA-cpj4-3r8w-83gx.json +++ b/advisories/unreviewed/2022/04/GHSA-cpj4-3r8w-83gx/GHSA-cpj4-3r8w-83gx.json @@ -7,12 +7,8 @@ "CVE-2004-2651" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in YaCy before 0.32 allow remote attackers to inject arbitrary web script or HTML via the (1) urlmaskfilter parameter to index.html or the (2) page parameter to Wiki.html.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cqc6-fxcv-hqmx/GHSA-cqc6-fxcv-hqmx.json b/advisories/unreviewed/2022/04/GHSA-cqc6-fxcv-hqmx/GHSA-cqc6-fxcv-hqmx.json index 4b46bf083cb..03fa2abc826 100644 --- a/advisories/unreviewed/2022/04/GHSA-cqc6-fxcv-hqmx/GHSA-cqc6-fxcv-hqmx.json +++ b/advisories/unreviewed/2022/04/GHSA-cqc6-fxcv-hqmx/GHSA-cqc6-fxcv-hqmx.json @@ -7,12 +7,8 @@ "CVE-2004-2587" ], "details": "login.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service via a long txtusername parameter, possibly due to a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cqf6-wpgm-m6gf/GHSA-cqf6-wpgm-m6gf.json b/advisories/unreviewed/2022/04/GHSA-cqf6-wpgm-m6gf/GHSA-cqf6-wpgm-m6gf.json index 9eed4fa06e2..116db631472 100644 --- a/advisories/unreviewed/2022/04/GHSA-cqf6-wpgm-m6gf/GHSA-cqf6-wpgm-m6gf.json +++ b/advisories/unreviewed/2022/04/GHSA-cqf6-wpgm-m6gf/GHSA-cqf6-wpgm-m6gf.json @@ -7,12 +7,8 @@ "CVE-2004-2551" ], "details": "Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the sys_comment_id parameter in editcommentenduser.asp, (2) the sys_suspend_id parameter in editsuspensionuser.asp, (3) the table parameter in export_data.asp, (4) the sys_analgroup parameter in manageanalgrouppreference.asp, (5) the sys_asset_id parameter in quickinfoassetrequests.asp, (6) the sys_eusername parameter in quickinfoenduserrequests.asp, and the sys_request_id parameter in (7) requestauditlog.asp, (8) requestcommentsenduser.asp, (9) selectrequestapplytemplate.asp, and (10) selectrequestlink.asp, resulting in an ability to create a new HelpBox user account and read, modify, or delete data from the backend database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-crx7-hrf2-c28r/GHSA-crx7-hrf2-c28r.json b/advisories/unreviewed/2022/04/GHSA-crx7-hrf2-c28r/GHSA-crx7-hrf2-c28r.json index acf32f504f4..28d8f35e253 100644 --- a/advisories/unreviewed/2022/04/GHSA-crx7-hrf2-c28r/GHSA-crx7-hrf2-c28r.json +++ b/advisories/unreviewed/2022/04/GHSA-crx7-hrf2-c28r/GHSA-crx7-hrf2-c28r.json @@ -7,12 +7,8 @@ "CVE-2004-2777" ], "details": "GE Healthcare Centricity Image Vault 3.x has a password of (1) gemnet for the administrator account, (2) webadmin for the webadmin administrator account of the ASACA DVD library, (3) an empty value for the gemsservice account of the Ultrasound Database, and possibly (4) gemnet2002 for the gemnet2002 account of the GEMNet license server, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f2r6-2mvm-7f46/GHSA-f2r6-2mvm-7f46.json b/advisories/unreviewed/2022/04/GHSA-f2r6-2mvm-7f46/GHSA-f2r6-2mvm-7f46.json index 24eeca5091f..84de69f052b 100644 --- a/advisories/unreviewed/2022/04/GHSA-f2r6-2mvm-7f46/GHSA-f2r6-2mvm-7f46.json +++ b/advisories/unreviewed/2022/04/GHSA-f2r6-2mvm-7f46/GHSA-f2r6-2mvm-7f46.json @@ -7,12 +7,8 @@ "CVE-2004-2519" ], "details": "Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specifiers in the LANGUAGE parameter to (1) index.tmpl and (2) web.tmpl, such as (a) slash \"/\", (b) backslash \"\\\", (c) dot \".\",, (d) dot dot \"..\", and (e) internal slash \"lang//en\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f5h7-rm4x-whwq/GHSA-f5h7-rm4x-whwq.json b/advisories/unreviewed/2022/04/GHSA-f5h7-rm4x-whwq/GHSA-f5h7-rm4x-whwq.json index c2c1e4646e9..02480ee300e 100644 --- a/advisories/unreviewed/2022/04/GHSA-f5h7-rm4x-whwq/GHSA-f5h7-rm4x-whwq.json +++ b/advisories/unreviewed/2022/04/GHSA-f5h7-rm4x-whwq/GHSA-f5h7-rm4x-whwq.json @@ -7,12 +7,8 @@ "CVE-2004-2613" ], "details": "Unspecified vulnerability in procfs in the Linux-VServer stable branch for the 2.4 kernel before 1.23 and Linux-VServer development branch for the 2.4 kernel before 1.3.5 has unspecified impact and attack vectors, related to \"write access to specific proc entries from a vserver context\", a different vulnerability than CVE-2004-2408.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f7mm-qr3m-2g22/GHSA-f7mm-qr3m-2g22.json b/advisories/unreviewed/2022/04/GHSA-f7mm-qr3m-2g22/GHSA-f7mm-qr3m-2g22.json index 19bca8cfa3d..7ff5e0f4bc1 100644 --- a/advisories/unreviewed/2022/04/GHSA-f7mm-qr3m-2g22/GHSA-f7mm-qr3m-2g22.json +++ b/advisories/unreviewed/2022/04/GHSA-f7mm-qr3m-2g22/GHSA-f7mm-qr3m-2g22.json @@ -7,12 +7,8 @@ "CVE-2004-2684" ], "details": "Unspecified vulnerability in the %template package in InterSystems Cache' 5.0 allows attackers to access certain files on a server, including (1) cache.key and (2) cache.dat, related to .csp files under (a) Dev\\studio\\templates and (b) Devuser\\studio\\templates.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f879-gmxv-6jv3/GHSA-f879-gmxv-6jv3.json b/advisories/unreviewed/2022/04/GHSA-f879-gmxv-6jv3/GHSA-f879-gmxv-6jv3.json index 6292dafc574..d890cf590ec 100644 --- a/advisories/unreviewed/2022/04/GHSA-f879-gmxv-6jv3/GHSA-f879-gmxv-6jv3.json +++ b/advisories/unreviewed/2022/04/GHSA-f879-gmxv-6jv3/GHSA-f879-gmxv-6jv3.json @@ -7,12 +7,8 @@ "CVE-2004-2714" ], "details": "Unspecified vulnerability in Window Maker 0.80.2 and earlier allows attackers to perform unknown actions via format string specifiers in a font specification in WMGLOBAL, probably a format string vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-f8j6-4qph-j87f/GHSA-f8j6-4qph-j87f.json b/advisories/unreviewed/2022/04/GHSA-f8j6-4qph-j87f/GHSA-f8j6-4qph-j87f.json index 5eb634209f1..96e0d5bf772 100644 --- a/advisories/unreviewed/2022/04/GHSA-f8j6-4qph-j87f/GHSA-f8j6-4qph-j87f.json +++ b/advisories/unreviewed/2022/04/GHSA-f8j6-4qph-j87f/GHSA-f8j6-4qph-j87f.json @@ -7,12 +7,8 @@ "CVE-2004-2568" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ReciPants 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) user id, (2) recipe id, (3) category id, and (4) other ID number fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ff3x-v55h-wqx3/GHSA-ff3x-v55h-wqx3.json b/advisories/unreviewed/2022/04/GHSA-ff3x-v55h-wqx3/GHSA-ff3x-v55h-wqx3.json index afa84981807..6d10365eafd 100644 --- a/advisories/unreviewed/2022/04/GHSA-ff3x-v55h-wqx3/GHSA-ff3x-v55h-wqx3.json +++ b/advisories/unreviewed/2022/04/GHSA-ff3x-v55h-wqx3/GHSA-ff3x-v55h-wqx3.json @@ -7,12 +7,8 @@ "CVE-2004-2652" ], "details": "The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ff8f-mh53-xcq3/GHSA-ff8f-mh53-xcq3.json b/advisories/unreviewed/2022/04/GHSA-ff8f-mh53-xcq3/GHSA-ff8f-mh53-xcq3.json index fa2ec695973..68b26f6ca8b 100644 --- a/advisories/unreviewed/2022/04/GHSA-ff8f-mh53-xcq3/GHSA-ff8f-mh53-xcq3.json +++ b/advisories/unreviewed/2022/04/GHSA-ff8f-mh53-xcq3/GHSA-ff8f-mh53-xcq3.json @@ -7,12 +7,8 @@ "CVE-2004-2593" ], "details": "Buffer overflow in command-packet processing of Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a packet with a long cmd_args buffer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fjqq-wrxc-5qvx/GHSA-fjqq-wrxc-5qvx.json b/advisories/unreviewed/2022/04/GHSA-fjqq-wrxc-5qvx/GHSA-fjqq-wrxc-5qvx.json index f414fe205c7..38dce22d6e0 100644 --- a/advisories/unreviewed/2022/04/GHSA-fjqq-wrxc-5qvx/GHSA-fjqq-wrxc-5qvx.json +++ b/advisories/unreviewed/2022/04/GHSA-fjqq-wrxc-5qvx/GHSA-fjqq-wrxc-5qvx.json @@ -7,12 +7,8 @@ "CVE-2004-2637" ], "details": "The NAT implementation in Zonet ZSR1104WE Wireless Router Runtime Code Version 2.41 converts IP addresses of inbound connections to the IP address of the router, which allows remote attackers to bypass intended security restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fp4j-7xhw-chrp/GHSA-fp4j-7xhw-chrp.json b/advisories/unreviewed/2022/04/GHSA-fp4j-7xhw-chrp/GHSA-fp4j-7xhw-chrp.json index f05b0b49fea..87bff46f5de 100644 --- a/advisories/unreviewed/2022/04/GHSA-fp4j-7xhw-chrp/GHSA-fp4j-7xhw-chrp.json +++ b/advisories/unreviewed/2022/04/GHSA-fp4j-7xhw-chrp/GHSA-fp4j-7xhw-chrp.json @@ -7,12 +7,8 @@ "CVE-2004-2669" ], "details": "Multiple SQL injection vulnerabilities in Land Down Under (LDU) v701 allow remote attackers to execute arbitrary SQL commands or obtain the installation path via parameters including (1) s, w, and d in users.php, (2) id in comments.php, (3) rusername in auth.php, or (4) h in plug.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fp5p-25cc-hp7j/GHSA-fp5p-25cc-hp7j.json b/advisories/unreviewed/2022/04/GHSA-fp5p-25cc-hp7j/GHSA-fp5p-25cc-hp7j.json index 74f24b337e8..e206f490b3b 100644 --- a/advisories/unreviewed/2022/04/GHSA-fp5p-25cc-hp7j/GHSA-fp5p-25cc-hp7j.json +++ b/advisories/unreviewed/2022/04/GHSA-fp5p-25cc-hp7j/GHSA-fp5p-25cc-hp7j.json @@ -7,12 +7,8 @@ "CVE-2004-2733" ], "details": "Web Wiz Forums 7.7a uses invalid logic to determine user privileges, which allows remote attackers to (1) block arbitrary IP addresses via pop_up_ip_blocking.asp or (2) modify topics via pop_up_topic_admin.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fpgc-v2fw-7f2p/GHSA-fpgc-v2fw-7f2p.json b/advisories/unreviewed/2022/04/GHSA-fpgc-v2fw-7f2p/GHSA-fpgc-v2fw-7f2p.json index 5ab631a4618..c0e3b37c5bf 100644 --- a/advisories/unreviewed/2022/04/GHSA-fpgc-v2fw-7f2p/GHSA-fpgc-v2fw-7f2p.json +++ b/advisories/unreviewed/2022/04/GHSA-fpgc-v2fw-7f2p/GHSA-fpgc-v2fw-7f2p.json @@ -7,12 +7,8 @@ "CVE-2004-2560" ], "details": "DokuWiki before 2004-10-19, when used on a web server that permits execution based on file extension, allows remote attackers to execute arbitrary code by uploading a file with an appropriate extension such as \".php\" or \".cgi\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fv44-gp5g-m9h3/GHSA-fv44-gp5g-m9h3.json b/advisories/unreviewed/2022/04/GHSA-fv44-gp5g-m9h3/GHSA-fv44-gp5g-m9h3.json index 6a8c8357b98..77ada890203 100644 --- a/advisories/unreviewed/2022/04/GHSA-fv44-gp5g-m9h3/GHSA-fv44-gp5g-m9h3.json +++ b/advisories/unreviewed/2022/04/GHSA-fv44-gp5g-m9h3/GHSA-fv44-gp5g-m9h3.json @@ -7,12 +7,8 @@ "CVE-2004-2769" ], "details": "Cerberus FTP Server before 4.0.3.0 allows remote authenticated users to list hidden files, even when the \"Display hidden files\" option is enabled, via the (1) MLSD or (2) MLST commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fwj2-255f-vxp9/GHSA-fwj2-255f-vxp9.json b/advisories/unreviewed/2022/04/GHSA-fwj2-255f-vxp9/GHSA-fwj2-255f-vxp9.json index bd24221e7a1..e59d4627d3a 100644 --- a/advisories/unreviewed/2022/04/GHSA-fwj2-255f-vxp9/GHSA-fwj2-255f-vxp9.json +++ b/advisories/unreviewed/2022/04/GHSA-fwj2-255f-vxp9/GHSA-fwj2-255f-vxp9.json @@ -7,12 +7,8 @@ "CVE-2004-2566" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat, and (4) LiveFocusGroup, allow remote attackers to inject arbitrary web script or HTML via the q parameter in (a) search.jsp, (b) findclub!execute.jspa, and (c) search!execute.jspa.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fx6v-xw9x-mhc6/GHSA-fx6v-xw9x-mhc6.json b/advisories/unreviewed/2022/04/GHSA-fx6v-xw9x-mhc6/GHSA-fx6v-xw9x-mhc6.json index 8d20bc3d9c1..ed1b0c5b0d2 100644 --- a/advisories/unreviewed/2022/04/GHSA-fx6v-xw9x-mhc6/GHSA-fx6v-xw9x-mhc6.json +++ b/advisories/unreviewed/2022/04/GHSA-fx6v-xw9x-mhc6/GHSA-fx6v-xw9x-mhc6.json @@ -7,12 +7,8 @@ "CVE-2004-2673" ], "details": "Multiple buffer overflows in ArGoSoft FTP Server before 1.4.1.6 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a SITE ZIP command with a long first or second argument, or (2) a SITE COPY with a long argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g2m2-6496-28r3/GHSA-g2m2-6496-28r3.json b/advisories/unreviewed/2022/04/GHSA-g2m2-6496-28r3/GHSA-g2m2-6496-28r3.json index c4ec6ce3c8c..347e64292cc 100644 --- a/advisories/unreviewed/2022/04/GHSA-g2m2-6496-28r3/GHSA-g2m2-6496-28r3.json +++ b/advisories/unreviewed/2022/04/GHSA-g2m2-6496-28r3/GHSA-g2m2-6496-28r3.json @@ -7,12 +7,8 @@ "CVE-2004-2647" ], "details": "Free Web Chat 2.0 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections from the same user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g4c4-m88p-5c36/GHSA-g4c4-m88p-5c36.json b/advisories/unreviewed/2022/04/GHSA-g4c4-m88p-5c36/GHSA-g4c4-m88p-5c36.json index 14ddc75b306..9d81a338d1c 100644 --- a/advisories/unreviewed/2022/04/GHSA-g4c4-m88p-5c36/GHSA-g4c4-m88p-5c36.json +++ b/advisories/unreviewed/2022/04/GHSA-g4c4-m88p-5c36/GHSA-g4c4-m88p-5c36.json @@ -7,12 +7,8 @@ "CVE-2004-2627" ], "details": "Java 2 Micro Edition (J2ME) does not properly validate bytecode, which allows remote attackers to escape the Kilobyte Virtual Machine (KVM) sandbox and execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g4jw-q5gf-chg4/GHSA-g4jw-q5gf-chg4.json b/advisories/unreviewed/2022/04/GHSA-g4jw-q5gf-chg4/GHSA-g4jw-q5gf-chg4.json index 8dd09571b37..e8d02646628 100644 --- a/advisories/unreviewed/2022/04/GHSA-g4jw-q5gf-chg4/GHSA-g4jw-q5gf-chg4.json +++ b/advisories/unreviewed/2022/04/GHSA-g4jw-q5gf-chg4/GHSA-g4jw-q5gf-chg4.json @@ -7,12 +7,8 @@ "CVE-2004-2744" ], "details": "Unspecified vulnerability in Tincan Limited PHPlist before 2.8.12 has unknown impact and attack vectors, related to a \"security update release.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g4q6-2x5x-hq8g/GHSA-g4q6-2x5x-hq8g.json b/advisories/unreviewed/2022/04/GHSA-g4q6-2x5x-hq8g/GHSA-g4q6-2x5x-hq8g.json index 9e3f1da31a3..1af2326dad2 100644 --- a/advisories/unreviewed/2022/04/GHSA-g4q6-2x5x-hq8g/GHSA-g4q6-2x5x-hq8g.json +++ b/advisories/unreviewed/2022/04/GHSA-g4q6-2x5x-hq8g/GHSA-g4q6-2x5x-hq8g.json @@ -7,12 +7,8 @@ "CVE-2004-2545" ], "details": "Secure Computing Corporation Sidewinder G2 6.1.0.01 allows remote attackers to cause a denial of service (SMTP proxy failure) via unknown attack vendors involving an \"extremely busy network.\" NOTE: this might not be a vulnerability because the embedded monitoring sub-system automatically restarts after the failure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g543-9hw2-5g6m/GHSA-g543-9hw2-5g6m.json b/advisories/unreviewed/2022/04/GHSA-g543-9hw2-5g6m/GHSA-g543-9hw2-5g6m.json index 7b4aaf38378..7d910058238 100644 --- a/advisories/unreviewed/2022/04/GHSA-g543-9hw2-5g6m/GHSA-g543-9hw2-5g6m.json +++ b/advisories/unreviewed/2022/04/GHSA-g543-9hw2-5g6m/GHSA-g543-9hw2-5g6m.json @@ -7,12 +7,8 @@ "CVE-2004-2742" ], "details": "Cross-site scripting (XSS) vulnerability in the report viewer in Crystal Enterprise 8.5, 9, and 10 allows remote attackers to inject arbitrary web script or HTML via script in the URL to a report (RPT) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-g5qc-7g3j-pw49/GHSA-g5qc-7g3j-pw49.json b/advisories/unreviewed/2022/04/GHSA-g5qc-7g3j-pw49/GHSA-g5qc-7g3j-pw49.json index 277db8b6118..3a703aca6f6 100644 --- a/advisories/unreviewed/2022/04/GHSA-g5qc-7g3j-pw49/GHSA-g5qc-7g3j-pw49.json +++ b/advisories/unreviewed/2022/04/GHSA-g5qc-7g3j-pw49/GHSA-g5qc-7g3j-pw49.json @@ -7,12 +7,8 @@ "CVE-2004-2712" ], "details": "Buffer overflow in Gyach Enhanced (Gyach-E) before 1.0.0-SneakPeek-3 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to \"URL data.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-g5xj-mf6c-gv67/GHSA-g5xj-mf6c-gv67.json b/advisories/unreviewed/2022/04/GHSA-g5xj-mf6c-gv67/GHSA-g5xj-mf6c-gv67.json index 412238517ce..93dc7d948ce 100644 --- a/advisories/unreviewed/2022/04/GHSA-g5xj-mf6c-gv67/GHSA-g5xj-mf6c-gv67.json +++ b/advisories/unreviewed/2022/04/GHSA-g5xj-mf6c-gv67/GHSA-g5xj-mf6c-gv67.json @@ -7,12 +7,8 @@ "CVE-2004-2626" ], "details": "GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SMS messages by overlaying a confirmation message with a malicious message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g84j-7f78-5x36/GHSA-g84j-7f78-5x36.json b/advisories/unreviewed/2022/04/GHSA-g84j-7f78-5x36/GHSA-g84j-7f78-5x36.json index 0c4a3a5e53d..52404ac6578 100644 --- a/advisories/unreviewed/2022/04/GHSA-g84j-7f78-5x36/GHSA-g84j-7f78-5x36.json +++ b/advisories/unreviewed/2022/04/GHSA-g84j-7f78-5x36/GHSA-g84j-7f78-5x36.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-g87x-9qg3-cfrp/GHSA-g87x-9qg3-cfrp.json b/advisories/unreviewed/2022/04/GHSA-g87x-9qg3-cfrp/GHSA-g87x-9qg3-cfrp.json index 9d93e3c7e55..3077b13c3d5 100644 --- a/advisories/unreviewed/2022/04/GHSA-g87x-9qg3-cfrp/GHSA-g87x-9qg3-cfrp.json +++ b/advisories/unreviewed/2022/04/GHSA-g87x-9qg3-cfrp/GHSA-g87x-9qg3-cfrp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-g89x-ccw9-3vqf/GHSA-g89x-ccw9-3vqf.json b/advisories/unreviewed/2022/04/GHSA-g89x-ccw9-3vqf/GHSA-g89x-ccw9-3vqf.json index e79a0475bad..f9207a5a5ce 100644 --- a/advisories/unreviewed/2022/04/GHSA-g89x-ccw9-3vqf/GHSA-g89x-ccw9-3vqf.json +++ b/advisories/unreviewed/2022/04/GHSA-g89x-ccw9-3vqf/GHSA-g89x-ccw9-3vqf.json @@ -7,12 +7,8 @@ "CVE-2004-2632" ], "details": "phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g8xp-6gmf-pqc7/GHSA-g8xp-6gmf-pqc7.json b/advisories/unreviewed/2022/04/GHSA-g8xp-6gmf-pqc7/GHSA-g8xp-6gmf-pqc7.json index febe6f04afb..7937b33d851 100644 --- a/advisories/unreviewed/2022/04/GHSA-g8xp-6gmf-pqc7/GHSA-g8xp-6gmf-pqc7.json +++ b/advisories/unreviewed/2022/04/GHSA-g8xp-6gmf-pqc7/GHSA-g8xp-6gmf-pqc7.json @@ -7,12 +7,8 @@ "CVE-2004-2575" ], "details": "phpGroupWare 0.9.14.005 and earlier allow remote attackers to obtain sensitive information via a direct request to (1) hook_admin.inc.php, (2) hook_home.inc.php, (3) class.holidaycalc.inc.php, and (4) setup.inc.php.sample, which reveals the path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gcch-vrjw-qccj/GHSA-gcch-vrjw-qccj.json b/advisories/unreviewed/2022/04/GHSA-gcch-vrjw-qccj/GHSA-gcch-vrjw-qccj.json index d25607af129..e6af14675b5 100644 --- a/advisories/unreviewed/2022/04/GHSA-gcch-vrjw-qccj/GHSA-gcch-vrjw-qccj.json +++ b/advisories/unreviewed/2022/04/GHSA-gcch-vrjw-qccj/GHSA-gcch-vrjw-qccj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gfv9-5vjp-wj62/GHSA-gfv9-5vjp-wj62.json b/advisories/unreviewed/2022/04/GHSA-gfv9-5vjp-wj62/GHSA-gfv9-5vjp-wj62.json index e3bce3ef9a9..b88f11ed547 100644 --- a/advisories/unreviewed/2022/04/GHSA-gfv9-5vjp-wj62/GHSA-gfv9-5vjp-wj62.json +++ b/advisories/unreviewed/2022/04/GHSA-gfv9-5vjp-wj62/GHSA-gfv9-5vjp-wj62.json @@ -7,12 +7,8 @@ "CVE-2004-2656" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) before R_2_5_0_41 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in search.pl and (2) the filter parameter in submit.pl.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gghw-gggj-qg54/GHSA-gghw-gggj-qg54.json b/advisories/unreviewed/2022/04/GHSA-gghw-gggj-qg54/GHSA-gghw-gggj-qg54.json index a7d4abdaeab..b92ac86618f 100644 --- a/advisories/unreviewed/2022/04/GHSA-gghw-gggj-qg54/GHSA-gghw-gggj-qg54.json +++ b/advisories/unreviewed/2022/04/GHSA-gghw-gggj-qg54/GHSA-gghw-gggj-qg54.json @@ -7,12 +7,8 @@ "CVE-2004-2614" ], "details": "Buffer overflow in MyWeb 3.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ghgp-g378-8742/GHSA-ghgp-g378-8742.json b/advisories/unreviewed/2022/04/GHSA-ghgp-g378-8742/GHSA-ghgp-g378-8742.json index c6d5bfbf191..030538c07cd 100644 --- a/advisories/unreviewed/2022/04/GHSA-ghgp-g378-8742/GHSA-ghgp-g378-8742.json +++ b/advisories/unreviewed/2022/04/GHSA-ghgp-g378-8742/GHSA-ghgp-g378-8742.json @@ -7,12 +7,8 @@ "CVE-2004-2530" ], "details": "Visual truncation vulnerability in Gadu-Gadu allows remote attackers to spoof the file extension on transmitted files via a filename with a large number of spaces followed by the real extension, which is not displayed in the dialog box.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ghqp-x4m8-m9f7/GHSA-ghqp-x4m8-m9f7.json b/advisories/unreviewed/2022/04/GHSA-ghqp-x4m8-m9f7/GHSA-ghqp-x4m8-m9f7.json index 63a9919cf9c..a7b29c7cf62 100644 --- a/advisories/unreviewed/2022/04/GHSA-ghqp-x4m8-m9f7/GHSA-ghqp-x4m8-m9f7.json +++ b/advisories/unreviewed/2022/04/GHSA-ghqp-x4m8-m9f7/GHSA-ghqp-x4m8-m9f7.json @@ -7,12 +7,8 @@ "CVE-2004-2671" ], "details": "mod.php in eNdonesia 8.3 allows remote attackers to obtain sensitive information via certain direct requests, and certain requests with invalid parameter values, which reveal the path in various error messages, as demonstrated by the (1) mod and (2) cid parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ghxr-vr43-7gg4/GHSA-ghxr-vr43-7gg4.json b/advisories/unreviewed/2022/04/GHSA-ghxr-vr43-7gg4/GHSA-ghxr-vr43-7gg4.json index 9f20c6a1795..6500c69ab64 100644 --- a/advisories/unreviewed/2022/04/GHSA-ghxr-vr43-7gg4/GHSA-ghxr-vr43-7gg4.json +++ b/advisories/unreviewed/2022/04/GHSA-ghxr-vr43-7gg4/GHSA-ghxr-vr43-7gg4.json @@ -7,12 +7,8 @@ "CVE-2004-2573" ], "details": "PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute arbitrary PHP code via an external URL in the appdir parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gjj5-323w-prhc/GHSA-gjj5-323w-prhc.json b/advisories/unreviewed/2022/04/GHSA-gjj5-323w-prhc/GHSA-gjj5-323w-prhc.json index 349901983ef..aa32edb5405 100644 --- a/advisories/unreviewed/2022/04/GHSA-gjj5-323w-prhc/GHSA-gjj5-323w-prhc.json +++ b/advisories/unreviewed/2022/04/GHSA-gjj5-323w-prhc/GHSA-gjj5-323w-prhc.json @@ -7,12 +7,8 @@ "CVE-2004-2589" ], "details": "Gaim before 0.82 allows remote servers to cause a denial of service (application crash) via a long HTTP Content-Length header, which causes Gaim to abort when attempting to allocate memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gp45-h6r6-g3h7/GHSA-gp45-h6r6-g3h7.json b/advisories/unreviewed/2022/04/GHSA-gp45-h6r6-g3h7/GHSA-gp45-h6r6-g3h7.json index 1424fa1dca5..57aa2dceb22 100644 --- a/advisories/unreviewed/2022/04/GHSA-gp45-h6r6-g3h7/GHSA-gp45-h6r6-g3h7.json +++ b/advisories/unreviewed/2022/04/GHSA-gp45-h6r6-g3h7/GHSA-gp45-h6r6-g3h7.json @@ -7,12 +7,8 @@ "CVE-2004-2634" ], "details": "The (1) bos.rte.serv_aid or (2) bos.rte.console filesets in IBM AIX 5.1 and 5.2 allow local users to overwrite arbitrary files via a symlink attack on temporary files via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gqc9-fvxf-ch49/GHSA-gqc9-fvxf-ch49.json b/advisories/unreviewed/2022/04/GHSA-gqc9-fvxf-ch49/GHSA-gqc9-fvxf-ch49.json index 5fc0f1dd70a..a98e4fd69fe 100644 --- a/advisories/unreviewed/2022/04/GHSA-gqc9-fvxf-ch49/GHSA-gqc9-fvxf-ch49.json +++ b/advisories/unreviewed/2022/04/GHSA-gqc9-fvxf-ch49/GHSA-gqc9-fvxf-ch49.json @@ -7,12 +7,8 @@ "CVE-2004-2717" ], "details": "Multiple directory traversal vulnerabilities in admin.php3 in PHPMyChat 0.14.5 allow remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the (1) sheet and (2) What parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-gqxw-w7hq-j9fr/GHSA-gqxw-w7hq-j9fr.json b/advisories/unreviewed/2022/04/GHSA-gqxw-w7hq-j9fr/GHSA-gqxw-w7hq-j9fr.json index 70568523ad9..e901e1a3282 100644 --- a/advisories/unreviewed/2022/04/GHSA-gqxw-w7hq-j9fr/GHSA-gqxw-w7hq-j9fr.json +++ b/advisories/unreviewed/2022/04/GHSA-gqxw-w7hq-j9fr/GHSA-gqxw-w7hq-j9fr.json @@ -7,12 +7,8 @@ "CVE-2004-2630" ], "details": "The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h268-8cw3-p2xg/GHSA-h268-8cw3-p2xg.json b/advisories/unreviewed/2022/04/GHSA-h268-8cw3-p2xg/GHSA-h268-8cw3-p2xg.json index 95beb4cf83f..f35c9752db7 100644 --- a/advisories/unreviewed/2022/04/GHSA-h268-8cw3-p2xg/GHSA-h268-8cw3-p2xg.json +++ b/advisories/unreviewed/2022/04/GHSA-h268-8cw3-p2xg/GHSA-h268-8cw3-p2xg.json @@ -7,12 +7,8 @@ "CVE-2004-2663" ], "details": "The (1) SetDebugging and (2) RunEgatherer methods in IBM Access Support eGatherer ActiveX control 2.0.0.16 allow remote attackers to create files with arbitrary content, as demonstrated by creating a .hta file in a Startup folder.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h2mv-7266-r4gv/GHSA-h2mv-7266-r4gv.json b/advisories/unreviewed/2022/04/GHSA-h2mv-7266-r4gv/GHSA-h2mv-7266-r4gv.json index d95c3c53329..b2aff4b622c 100644 --- a/advisories/unreviewed/2022/04/GHSA-h2mv-7266-r4gv/GHSA-h2mv-7266-r4gv.json +++ b/advisories/unreviewed/2022/04/GHSA-h2mv-7266-r4gv/GHSA-h2mv-7266-r4gv.json @@ -7,12 +7,8 @@ "CVE-2004-2540" ], "details": "readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 through 1.4.2_05 allows remote attackers to cause a denial of service (JVM unresponsive) via crafted serialized data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h4wm-jrw8-h7r4/GHSA-h4wm-jrw8-h7r4.json b/advisories/unreviewed/2022/04/GHSA-h4wm-jrw8-h7r4/GHSA-h4wm-jrw8-h7r4.json index f76dac9ca0f..e8509add22c 100644 --- a/advisories/unreviewed/2022/04/GHSA-h4wm-jrw8-h7r4/GHSA-h4wm-jrw8-h7r4.json +++ b/advisories/unreviewed/2022/04/GHSA-h4wm-jrw8-h7r4/GHSA-h4wm-jrw8-h7r4.json @@ -7,12 +7,8 @@ "CVE-2004-2548" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h7gq-ccp9-7hgx/GHSA-h7gq-ccp9-7hgx.json b/advisories/unreviewed/2022/04/GHSA-h7gq-ccp9-7hgx/GHSA-h7gq-ccp9-7hgx.json index 6d4322ebf17..66dcdd90c21 100644 --- a/advisories/unreviewed/2022/04/GHSA-h7gq-ccp9-7hgx/GHSA-h7gq-ccp9-7hgx.json +++ b/advisories/unreviewed/2022/04/GHSA-h7gq-ccp9-7hgx/GHSA-h7gq-ccp9-7hgx.json @@ -7,12 +7,8 @@ "CVE-2004-2579" ], "details": "ACLCHECK module in Novell iChain 2.3 allows attackers to bypass access control rules of an unspecified component via an unspecified attack vector involving a string that contains escape sequences represented with \"overlong UTF-8 encoding.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h7h5-28w5-gr84/GHSA-h7h5-28w5-gr84.json b/advisories/unreviewed/2022/04/GHSA-h7h5-28w5-gr84/GHSA-h7h5-28w5-gr84.json index c291e3a9109..a233608a002 100644 --- a/advisories/unreviewed/2022/04/GHSA-h7h5-28w5-gr84/GHSA-h7h5-28w5-gr84.json +++ b/advisories/unreviewed/2022/04/GHSA-h7h5-28w5-gr84/GHSA-h7h5-28w5-gr84.json @@ -7,12 +7,8 @@ "CVE-2004-2558" ], "details": "Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manager 4.2, Configuration Manager for Automated Teller Machines 2.1.0, and IBM WebSphere Everyplace Server, Service Provider Offering for Multi-platforms 2.1.3 to 2.15 allow remote attackers to hijack sessions of authenticated users via unknown attack vectors involving certain cookies, aka \"Potential Credential Impersonation Attack.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h8rm-hh3j-prg6/GHSA-h8rm-hh3j-prg6.json b/advisories/unreviewed/2022/04/GHSA-h8rm-hh3j-prg6/GHSA-h8rm-hh3j-prg6.json index e4335284c4d..2b1592609d5 100644 --- a/advisories/unreviewed/2022/04/GHSA-h8rm-hh3j-prg6/GHSA-h8rm-hh3j-prg6.json +++ b/advisories/unreviewed/2022/04/GHSA-h8rm-hh3j-prg6/GHSA-h8rm-hh3j-prg6.json @@ -7,12 +7,8 @@ "CVE-2004-2678" ], "details": "Unspecified vulnerability in HP Tru64 UNIX 5.1B PK2(BL22) and PK3(BL24), and 5.1A PK6(BL24), when using IPsec/IKE (Internet Key Exchange) with Certificates, allows remote attackers to gain privileges via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hc22-c689-gw4r/GHSA-hc22-c689-gw4r.json b/advisories/unreviewed/2022/04/GHSA-hc22-c689-gw4r/GHSA-hc22-c689-gw4r.json index 373466ce8d9..f27cb5cdd99 100644 --- a/advisories/unreviewed/2022/04/GHSA-hc22-c689-gw4r/GHSA-hc22-c689-gw4r.json +++ b/advisories/unreviewed/2022/04/GHSA-hc22-c689-gw4r/GHSA-hc22-c689-gw4r.json @@ -7,12 +7,8 @@ "CVE-2004-2719" ], "details": "Buffer overflow in the UrlToLocal function in PunyLib.dll of Foxmail 5.0.300 allows remote attackers to execute arbitrary code via a mail message with a long From field, a different issue than CVE-2005-0339.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-hff4-446w-6w6j/GHSA-hff4-446w-6w6j.json b/advisories/unreviewed/2022/04/GHSA-hff4-446w-6w6j/GHSA-hff4-446w-6w6j.json index 2cb526384bf..a68cc922dac 100644 --- a/advisories/unreviewed/2022/04/GHSA-hff4-446w-6w6j/GHSA-hff4-446w-6w6j.json +++ b/advisories/unreviewed/2022/04/GHSA-hff4-446w-6w6j/GHSA-hff4-446w-6w6j.json @@ -7,12 +7,8 @@ "CVE-2004-2723" ], "details": "NessusWX 1.4.4 stores account passwords in plaintext in .session files, which allows local users to obtain passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hg8p-7r5h-9pfp/GHSA-hg8p-7r5h-9pfp.json b/advisories/unreviewed/2022/04/GHSA-hg8p-7r5h-9pfp/GHSA-hg8p-7r5h-9pfp.json index 927b941a302..593fc812bca 100644 --- a/advisories/unreviewed/2022/04/GHSA-hg8p-7r5h-9pfp/GHSA-hg8p-7r5h-9pfp.json +++ b/advisories/unreviewed/2022/04/GHSA-hg8p-7r5h-9pfp/GHSA-hg8p-7r5h-9pfp.json @@ -7,12 +7,8 @@ "CVE-2004-2735" ], "details": "Cross-site scripting (XSS) vulnerability in P4DB 2.01 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) SET_PREFERENCES parameter in SetPreferences.cgi; (2) BRANCH parameter in branchView.cgi; (3) FSPC and (4) COMPLETE parameters in changeByUsers.cgi; (5) FSPC, (6) LABEL, (7) EXLABEL, (8) STATUS, (9) MAXCH, (10) FIRSTCH, (11) CHOFFSETDISP, (12) SEARCHDESC, (13) SEARCH_INVERT, (14) USER, (15) GROUP, and (16) CLIENT parameters in changeList.cgi; (17) CH parameter in changeView.cgi; (18) USER parameter in clientList.cgi; (19) CLIENT parameter in clientView.cgi; (20) FSPC parameter in depotTreeBrowser.cgi; (21) FSPC parameter in depotStats.cgi; (22) FSPC, (23) REV, (24) ACT, (25) FSPC2, (26) REV2, (27) CH, and (28) CONTEXT parameters in fileDiffView.cgi; (29) FSPC and (30) REV parameters in fileDownLoad.cgi; (31) FSPC, (32) LISTLAB, and (33) SHOWBRANCH parameters in fileLogView.cgi; (34) FSPC and (35) LABEL parameters in fileSearch.cgi; (36) FSPC, (37) REV, and (38) FORCE parameters in fileViewer.cgi; (39) FSPC parameter in filesChangedSince.cgi; (40) GROUP parameter in groupView.cgi; (41) TYPE, (42) FSPC, and (43) REV parameters in htmlFileView.cgi; (44) CMD parameter in javaDataView.cgi; (45) JOBVIEW and (46) FLD parameters in jobList.cgi; (47) JOB parameter in jobView.cgi; (48) LABEL1 and (49) LABEL2 parameters in labelDiffView.cgi; (50) LABEL parameter in labelView.cgi; (51) FSPC parameter in searchPattern.cgi; (52) TYPE, (53) FSPC, and (54) REV parameters in specialFileView.cgi; (55) GROUPSONLY parameter in userList.cgi; or (56) USER parameter in userView.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-hhph-jxcg-589h/GHSA-hhph-jxcg-589h.json b/advisories/unreviewed/2022/04/GHSA-hhph-jxcg-589h/GHSA-hhph-jxcg-589h.json index 30f1e471c33..aee78bc532c 100644 --- a/advisories/unreviewed/2022/04/GHSA-hhph-jxcg-589h/GHSA-hhph-jxcg-589h.json +++ b/advisories/unreviewed/2022/04/GHSA-hhph-jxcg-589h/GHSA-hhph-jxcg-589h.json @@ -7,12 +7,8 @@ "CVE-2004-2648" ], "details": "FreezeX 1.00.100.0666 allows local users with administrator privileges to cause a denial of service (FreezeX application) by overwriting the db.fzx file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hjf4-6f96-j975/GHSA-hjf4-6f96-j975.json b/advisories/unreviewed/2022/04/GHSA-hjf4-6f96-j975/GHSA-hjf4-6f96-j975.json index 524007ebeb8..e4a98b2a125 100644 --- a/advisories/unreviewed/2022/04/GHSA-hjf4-6f96-j975/GHSA-hjf4-6f96-j975.json +++ b/advisories/unreviewed/2022/04/GHSA-hjf4-6f96-j975/GHSA-hjf4-6f96-j975.json @@ -7,12 +7,8 @@ "CVE-2004-2549" ], "details": "Nortel Wireless LAN (WLAN) Access Point (AP) 2220, 2221, and 2225 allow remote attackers to cause a denial of service (service crash) via a TCP request with a large string, followed by 8 newline characters, to (1) the Telnet service on TCP port 23 and (2) the HTTP service on TCP port 80, possibly due to a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hjgf-wjp7-2h46/GHSA-hjgf-wjp7-2h46.json b/advisories/unreviewed/2022/04/GHSA-hjgf-wjp7-2h46/GHSA-hjgf-wjp7-2h46.json index 77fc5871cf4..0fb53e13e28 100644 --- a/advisories/unreviewed/2022/04/GHSA-hjgf-wjp7-2h46/GHSA-hjgf-wjp7-2h46.json +++ b/advisories/unreviewed/2022/04/GHSA-hjgf-wjp7-2h46/GHSA-hjgf-wjp7-2h46.json @@ -7,12 +7,8 @@ "CVE-2004-2680" ], "details": "mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of previously freed memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hm4q-jhq3-x3jc/GHSA-hm4q-jhq3-x3jc.json b/advisories/unreviewed/2022/04/GHSA-hm4q-jhq3-x3jc/GHSA-hm4q-jhq3-x3jc.json index 54444682b6a..7f8b5135a3b 100644 --- a/advisories/unreviewed/2022/04/GHSA-hm4q-jhq3-x3jc/GHSA-hm4q-jhq3-x3jc.json +++ b/advisories/unreviewed/2022/04/GHSA-hm4q-jhq3-x3jc/GHSA-hm4q-jhq3-x3jc.json @@ -7,12 +7,8 @@ "CVE-2004-2532" ], "details": "Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server using the default administrator account, creating a new user, logging in as that new user, and then using the SITE EXEC command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hw95-r563-xw3w/GHSA-hw95-r563-xw3w.json b/advisories/unreviewed/2022/04/GHSA-hw95-r563-xw3w/GHSA-hw95-r563-xw3w.json index f72efa61a12..0a71c5ba8b4 100644 --- a/advisories/unreviewed/2022/04/GHSA-hw95-r563-xw3w/GHSA-hw95-r563-xw3w.json +++ b/advisories/unreviewed/2022/04/GHSA-hw95-r563-xw3w/GHSA-hw95-r563-xw3w.json @@ -7,12 +7,8 @@ "CVE-2004-2741" ], "details": "Cross-site scripting (XSS) vulnerability in the \"help window\" (help.php) in Horde Application Framework 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) module, (2) topic, or (3) module parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-hx5v-g4q9-47jf/GHSA-hx5v-g4q9-47jf.json b/advisories/unreviewed/2022/04/GHSA-hx5v-g4q9-47jf/GHSA-hx5v-g4q9-47jf.json index b638e706bc1..3ce5be788a4 100644 --- a/advisories/unreviewed/2022/04/GHSA-hx5v-g4q9-47jf/GHSA-hx5v-g4q9-47jf.json +++ b/advisories/unreviewed/2022/04/GHSA-hx5v-g4q9-47jf/GHSA-hx5v-g4q9-47jf.json @@ -7,12 +7,8 @@ "CVE-2004-2528" ], "details": "Cross-site scripting (XSS) vulnerability in sresult.exe in Webcam Watchdog 4.0.1a allows remote attackers to inject arbitrary web script or HTML via the cam parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hxrh-xvf9-9m4h/GHSA-hxrh-xvf9-9m4h.json b/advisories/unreviewed/2022/04/GHSA-hxrh-xvf9-9m4h/GHSA-hxrh-xvf9-9m4h.json index d6b066a5087..8ffd3e7ed1d 100644 --- a/advisories/unreviewed/2022/04/GHSA-hxrh-xvf9-9m4h/GHSA-hxrh-xvf9-9m4h.json +++ b/advisories/unreviewed/2022/04/GHSA-hxrh-xvf9-9m4h/GHSA-hxrh-xvf9-9m4h.json @@ -7,12 +7,8 @@ "CVE-2004-2572" ], "details": "AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) invalid characters such as \"()\" or (2) a large number of characters in the Lookup field on the netaddressbook.php web form, which reveals the path in an ldaplib.php error message when the ldap_search function fails, due to improper processing of the $keyword variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j29v-fw26-7w36/GHSA-j29v-fw26-7w36.json b/advisories/unreviewed/2022/04/GHSA-j29v-fw26-7w36/GHSA-j29v-fw26-7w36.json index ad362f12988..19f4e1c33d6 100644 --- a/advisories/unreviewed/2022/04/GHSA-j29v-fw26-7w36/GHSA-j29v-fw26-7w36.json +++ b/advisories/unreviewed/2022/04/GHSA-j29v-fw26-7w36/GHSA-j29v-fw26-7w36.json @@ -7,12 +7,8 @@ "CVE-2004-2668" ], "details": "SQL injection vulnerability in Interchange before 4.8.9 allows remote attackers to execute arbitrary SQL commands via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j2vj-gfj2-r9pm/GHSA-j2vj-gfj2-r9pm.json b/advisories/unreviewed/2022/04/GHSA-j2vj-gfj2-r9pm/GHSA-j2vj-gfj2-r9pm.json index 62525d6ffc1..8fe3c26694a 100644 --- a/advisories/unreviewed/2022/04/GHSA-j2vj-gfj2-r9pm/GHSA-j2vj-gfj2-r9pm.json +++ b/advisories/unreviewed/2022/04/GHSA-j2vj-gfj2-r9pm/GHSA-j2vj-gfj2-r9pm.json @@ -7,12 +7,8 @@ "CVE-2004-2559" ], "details": "DokuWiki before 2004-10-19 allows remote attackers to access administrative functionality including (1) Mediaselectiondialog, (2) Recent changes, (3) feed, and (4) search, possibly due to the lack of ACL checks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j32q-7w48-vjx5/GHSA-j32q-7w48-vjx5.json b/advisories/unreviewed/2022/04/GHSA-j32q-7w48-vjx5/GHSA-j32q-7w48-vjx5.json index 9c19646d288..2ecd92dd84a 100644 --- a/advisories/unreviewed/2022/04/GHSA-j32q-7w48-vjx5/GHSA-j32q-7w48-vjx5.json +++ b/advisories/unreviewed/2022/04/GHSA-j32q-7w48-vjx5/GHSA-j32q-7w48-vjx5.json @@ -7,12 +7,8 @@ "CVE-2004-2484" ], "details": "Cross-site scripting (XSS) vulnerability in PHP Gift Registry 1.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter to (1) event.php or (2) index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j3wc-p3gm-2hvr/GHSA-j3wc-p3gm-2hvr.json b/advisories/unreviewed/2022/04/GHSA-j3wc-p3gm-2hvr/GHSA-j3wc-p3gm-2hvr.json index 03d2c583456..08f5fde0f65 100644 --- a/advisories/unreviewed/2022/04/GHSA-j3wc-p3gm-2hvr/GHSA-j3wc-p3gm-2hvr.json +++ b/advisories/unreviewed/2022/04/GHSA-j3wc-p3gm-2hvr/GHSA-j3wc-p3gm-2hvr.json @@ -7,12 +7,8 @@ "CVE-2004-2503" ], "details": "INweb Mail Server 2.40 allows remote attackers to cause a denial of service (crash) via a large number of connect/disconnect actions to the (1) POP3 and (2) SMTP services.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j7p5-665x-j6hw/GHSA-j7p5-665x-j6hw.json b/advisories/unreviewed/2022/04/GHSA-j7p5-665x-j6hw/GHSA-j7p5-665x-j6hw.json index 472d8b7acb7..676b1d248bb 100644 --- a/advisories/unreviewed/2022/04/GHSA-j7p5-665x-j6hw/GHSA-j7p5-665x-j6hw.json +++ b/advisories/unreviewed/2022/04/GHSA-j7p5-665x-j6hw/GHSA-j7p5-665x-j6hw.json @@ -7,12 +7,8 @@ "CVE-2004-2499" ], "details": "Unspecified vulnerability in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier allows remote attackers to cause a denial of service via unknown attack vectors when a web site is \"improperly accessed.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j7wr-9pp4-rh9g/GHSA-j7wr-9pp4-rh9g.json b/advisories/unreviewed/2022/04/GHSA-j7wr-9pp4-rh9g/GHSA-j7wr-9pp4-rh9g.json index de4821b078a..f8c0da08c30 100644 --- a/advisories/unreviewed/2022/04/GHSA-j7wr-9pp4-rh9g/GHSA-j7wr-9pp4-rh9g.json +++ b/advisories/unreviewed/2022/04/GHSA-j7wr-9pp4-rh9g/GHSA-j7wr-9pp4-rh9g.json @@ -7,12 +7,8 @@ "CVE-2004-2521" ], "details": "Mail server in Gattaca Server 2003 1.1.10.0 allows remote attackers to perform a denial of service (application crash) via a large number of connections to TCP port (1) 25 (SMTP) or (2) 110 (POP).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j8qf-3qcm-gp2f/GHSA-j8qf-3qcm-gp2f.json b/advisories/unreviewed/2022/04/GHSA-j8qf-3qcm-gp2f/GHSA-j8qf-3qcm-gp2f.json index bca39ea461a..f9b7496c393 100644 --- a/advisories/unreviewed/2022/04/GHSA-j8qf-3qcm-gp2f/GHSA-j8qf-3qcm-gp2f.json +++ b/advisories/unreviewed/2022/04/GHSA-j8qf-3qcm-gp2f/GHSA-j8qf-3qcm-gp2f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j959-4486-mmwm/GHSA-j959-4486-mmwm.json b/advisories/unreviewed/2022/04/GHSA-j959-4486-mmwm/GHSA-j959-4486-mmwm.json index ea05462a5b9..d1fdb38b499 100644 --- a/advisories/unreviewed/2022/04/GHSA-j959-4486-mmwm/GHSA-j959-4486-mmwm.json +++ b/advisories/unreviewed/2022/04/GHSA-j959-4486-mmwm/GHSA-j959-4486-mmwm.json @@ -7,12 +7,8 @@ "CVE-2004-2625" ], "details": "Cross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTML via Javascript in an attribute of an IMG tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j9xv-rfg5-qr77/GHSA-j9xv-rfg5-qr77.json b/advisories/unreviewed/2022/04/GHSA-j9xv-rfg5-qr77/GHSA-j9xv-rfg5-qr77.json index 741ac8bf659..3a2250c4a15 100644 --- a/advisories/unreviewed/2022/04/GHSA-j9xv-rfg5-qr77/GHSA-j9xv-rfg5-qr77.json +++ b/advisories/unreviewed/2022/04/GHSA-j9xv-rfg5-qr77/GHSA-j9xv-rfg5-qr77.json @@ -7,12 +7,8 @@ "CVE-2004-2603" ], "details": "Cross-site scripting (XSS) vulnerability in the Search module in UberTec Help Center Live (HCL) allows remote attackers to inject arbitrary web script or HTML via the find parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jcr8-6hcp-xjf9/GHSA-jcr8-6hcp-xjf9.json b/advisories/unreviewed/2022/04/GHSA-jcr8-6hcp-xjf9/GHSA-jcr8-6hcp-xjf9.json index 80e378b7c96..441e944653a 100644 --- a/advisories/unreviewed/2022/04/GHSA-jcr8-6hcp-xjf9/GHSA-jcr8-6hcp-xjf9.json +++ b/advisories/unreviewed/2022/04/GHSA-jcr8-6hcp-xjf9/GHSA-jcr8-6hcp-xjf9.json @@ -7,12 +7,8 @@ "CVE-2004-2608" ], "details": "SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the \"news database\") under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the unencrypted username and password of the administrator's account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jh5c-8fq7-5f53/GHSA-jh5c-8fq7-5f53.json b/advisories/unreviewed/2022/04/GHSA-jh5c-8fq7-5f53/GHSA-jh5c-8fq7-5f53.json index 6f097ca6f0e..3f0c988ad5d 100644 --- a/advisories/unreviewed/2022/04/GHSA-jh5c-8fq7-5f53/GHSA-jh5c-8fq7-5f53.json +++ b/advisories/unreviewed/2022/04/GHSA-jh5c-8fq7-5f53/GHSA-jh5c-8fq7-5f53.json @@ -7,12 +7,8 @@ "CVE-2004-2588" ], "details": "Intentional information leak in phpinfo.php in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allows remote attackers to obtain sensitive information such as the configuration of the web server and the PHP application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jh7r-26mr-38jg/GHSA-jh7r-26mr-38jg.json b/advisories/unreviewed/2022/04/GHSA-jh7r-26mr-38jg/GHSA-jh7r-26mr-38jg.json index b1e7ce861a0..003a1d3d2f6 100644 --- a/advisories/unreviewed/2022/04/GHSA-jh7r-26mr-38jg/GHSA-jh7r-26mr-38jg.json +++ b/advisories/unreviewed/2022/04/GHSA-jh7r-26mr-38jg/GHSA-jh7r-26mr-38jg.json @@ -7,12 +7,8 @@ "CVE-2004-2666" ], "details": "Mantis before 20041016 provides a complete Issue History (Bug History) in the web interface regardless of view_history_threshold, which allows remote attackers to obtain sensitive information (private bug details) by visiting a bug's web page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jqff-mwp3-mx4x/GHSA-jqff-mwp3-mx4x.json b/advisories/unreviewed/2022/04/GHSA-jqff-mwp3-mx4x/GHSA-jqff-mwp3-mx4x.json index 7c3510405b3..913201eaced 100644 --- a/advisories/unreviewed/2022/04/GHSA-jqff-mwp3-mx4x/GHSA-jqff-mwp3-mx4x.json +++ b/advisories/unreviewed/2022/04/GHSA-jqff-mwp3-mx4x/GHSA-jqff-mwp3-mx4x.json @@ -7,12 +7,8 @@ "CVE-2004-2541" ], "details": "Buffer overflow in Cscope 15.5, and possibly multiple overflows, allows remote attackers to execute arbitrary code via a C file with a long #include line that is later browsed by the target.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-jr28-ffrh-246w/GHSA-jr28-ffrh-246w.json b/advisories/unreviewed/2022/04/GHSA-jr28-ffrh-246w/GHSA-jr28-ffrh-246w.json index af7c87496d3..5ac7f374905 100644 --- a/advisories/unreviewed/2022/04/GHSA-jr28-ffrh-246w/GHSA-jr28-ffrh-246w.json +++ b/advisories/unreviewed/2022/04/GHSA-jr28-ffrh-246w/GHSA-jr28-ffrh-246w.json @@ -7,12 +7,8 @@ "CVE-2004-2740" ], "details": "PHP remote file inclusion vulnerability in authform.inc.php in PHProjekt 4.2.3 and earlier allows remote attackers to include arbitrary PHP code via a URL in the path_pre parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-jx5f-jm5c-889j/GHSA-jx5f-jm5c-889j.json b/advisories/unreviewed/2022/04/GHSA-jx5f-jm5c-889j/GHSA-jx5f-jm5c-889j.json index a9947a2fc90..40ec9eefa3b 100644 --- a/advisories/unreviewed/2022/04/GHSA-jx5f-jm5c-889j/GHSA-jx5f-jm5c-889j.json +++ b/advisories/unreviewed/2022/04/GHSA-jx5f-jm5c-889j/GHSA-jx5f-jm5c-889j.json @@ -7,12 +7,8 @@ "CVE-2004-2578" ], "details": "phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote attackers to sniff passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jx9w-xpj8-hj9j/GHSA-jx9w-xpj8-hj9j.json b/advisories/unreviewed/2022/04/GHSA-jx9w-xpj8-hj9j/GHSA-jx9w-xpj8-hj9j.json index e00f8ec47ed..82c95b487aa 100644 --- a/advisories/unreviewed/2022/04/GHSA-jx9w-xpj8-hj9j/GHSA-jx9w-xpj8-hj9j.json +++ b/advisories/unreviewed/2022/04/GHSA-jx9w-xpj8-hj9j/GHSA-jx9w-xpj8-hj9j.json @@ -7,12 +7,8 @@ "CVE-2004-2607" ], "details": "A numeric casting discrepancy in sdla_xfer in Linux kernel 2.6.x up to 2.6.5 and 2.4 up to 2.4.29-rc1 allows local users to read portions of kernel memory via a large len argument, which is received as an int but cast to a short, which prevents a read loop from filling a buffer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jxhx-rppc-gf4x/GHSA-jxhx-rppc-gf4x.json b/advisories/unreviewed/2022/04/GHSA-jxhx-rppc-gf4x/GHSA-jxhx-rppc-gf4x.json index 4df4434a419..76415f30b3c 100644 --- a/advisories/unreviewed/2022/04/GHSA-jxhx-rppc-gf4x/GHSA-jxhx-rppc-gf4x.json +++ b/advisories/unreviewed/2022/04/GHSA-jxhx-rppc-gf4x/GHSA-jxhx-rppc-gf4x.json @@ -7,12 +7,8 @@ "CVE-2004-2654" ], "details": "The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2.6 STABLE6 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors that trigger a null dereference. NOTE: in a followup advisory, a researcher claimed that the issue was a buffer overflow that was not fixed in STABLE6. However, the vendor's bug report clearly shows that the researcher later retracted this claim, because the tested product was actually STABLE5.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m23p-w4r4-w6qp/GHSA-m23p-w4r4-w6qp.json b/advisories/unreviewed/2022/04/GHSA-m23p-w4r4-w6qp/GHSA-m23p-w4r4-w6qp.json index 7204eca15c1..91df680ad57 100644 --- a/advisories/unreviewed/2022/04/GHSA-m23p-w4r4-w6qp/GHSA-m23p-w4r4-w6qp.json +++ b/advisories/unreviewed/2022/04/GHSA-m23p-w4r4-w6qp/GHSA-m23p-w4r4-w6qp.json @@ -7,12 +7,8 @@ "CVE-2004-2752" ], "details": "Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote attackers to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-mcvw-pw2f-v47r/GHSA-mcvw-pw2f-v47r.json b/advisories/unreviewed/2022/04/GHSA-mcvw-pw2f-v47r/GHSA-mcvw-pw2f-v47r.json index 7ce781aa735..7e711f10e4e 100644 --- a/advisories/unreviewed/2022/04/GHSA-mcvw-pw2f-v47r/GHSA-mcvw-pw2f-v47r.json +++ b/advisories/unreviewed/2022/04/GHSA-mcvw-pw2f-v47r/GHSA-mcvw-pw2f-v47r.json @@ -7,12 +7,8 @@ "CVE-2004-2478" ], "details": "Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mg4c-x8gf-gw7m/GHSA-mg4c-x8gf-gw7m.json b/advisories/unreviewed/2022/04/GHSA-mg4c-x8gf-gw7m/GHSA-mg4c-x8gf-gw7m.json index 7cb431a7f38..2b95c66a3e6 100644 --- a/advisories/unreviewed/2022/04/GHSA-mg4c-x8gf-gw7m/GHSA-mg4c-x8gf-gw7m.json +++ b/advisories/unreviewed/2022/04/GHSA-mg4c-x8gf-gw7m/GHSA-mg4c-x8gf-gw7m.json @@ -7,12 +7,8 @@ "CVE-2004-2715" ], "details": "edituser.php3 in PHPMyChat 0.14.5 allow remote attackers to bypass authentication and gain administrative privileges by setting the do_not_login parameter to false.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-mhc5-27v4-8w9g/GHSA-mhc5-27v4-8w9g.json b/advisories/unreviewed/2022/04/GHSA-mhc5-27v4-8w9g/GHSA-mhc5-27v4-8w9g.json index 3769798d7ea..d44f4ed33bf 100644 --- a/advisories/unreviewed/2022/04/GHSA-mhc5-27v4-8w9g/GHSA-mhc5-27v4-8w9g.json +++ b/advisories/unreviewed/2022/04/GHSA-mhc5-27v4-8w9g/GHSA-mhc5-27v4-8w9g.json @@ -7,12 +7,8 @@ "CVE-2004-2556" ], "details": "NetGear WG602 (aka WG602v1) Wireless Access Point firmware 1.04.0 and 1.5.67 has a hardcoded account of username \"super\" and password \"5777364\", which allows remote attackers to modify the configuration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mhfj-c75x-2vfv/GHSA-mhfj-c75x-2vfv.json b/advisories/unreviewed/2022/04/GHSA-mhfj-c75x-2vfv/GHSA-mhfj-c75x-2vfv.json index aa72e1c59de..1094c14f0bd 100644 --- a/advisories/unreviewed/2022/04/GHSA-mhfj-c75x-2vfv/GHSA-mhfj-c75x-2vfv.json +++ b/advisories/unreviewed/2022/04/GHSA-mhfj-c75x-2vfv/GHSA-mhfj-c75x-2vfv.json @@ -7,12 +7,8 @@ "CVE-2004-2550" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in unspecified Perl scripts in SandSurfer before 1.7.1 allow remote attackers to inject arbitrary web script or HTML, which is later executed by a target who views reports containing the injected data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mhv2-672p-f8h4/GHSA-mhv2-672p-f8h4.json b/advisories/unreviewed/2022/04/GHSA-mhv2-672p-f8h4/GHSA-mhv2-672p-f8h4.json index 8b910d33808..cb92495402d 100644 --- a/advisories/unreviewed/2022/04/GHSA-mhv2-672p-f8h4/GHSA-mhv2-672p-f8h4.json +++ b/advisories/unreviewed/2022/04/GHSA-mhv2-672p-f8h4/GHSA-mhv2-672p-f8h4.json @@ -7,12 +7,8 @@ "CVE-2004-2507" ], "details": "Absolute path traversal vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to read arbitrary files via an absolute pathname in the next_file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mmjh-9xp6-78rw/GHSA-mmjh-9xp6-78rw.json b/advisories/unreviewed/2022/04/GHSA-mmjh-9xp6-78rw/GHSA-mmjh-9xp6-78rw.json index e045b2b5c64..d1b14287f8d 100644 --- a/advisories/unreviewed/2022/04/GHSA-mmjh-9xp6-78rw/GHSA-mmjh-9xp6-78rw.json +++ b/advisories/unreviewed/2022/04/GHSA-mmjh-9xp6-78rw/GHSA-mmjh-9xp6-78rw.json @@ -7,12 +7,8 @@ "CVE-2004-2617" ], "details": "Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the web root via a .. (dot dot) directly after the initial '/' (slash) in the URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p2v3-9pr5-prv3/GHSA-p2v3-9pr5-prv3.json b/advisories/unreviewed/2022/04/GHSA-p2v3-9pr5-prv3/GHSA-p2v3-9pr5-prv3.json index 2e282f11d33..89d9d22e85f 100644 --- a/advisories/unreviewed/2022/04/GHSA-p2v3-9pr5-prv3/GHSA-p2v3-9pr5-prv3.json +++ b/advisories/unreviewed/2022/04/GHSA-p2v3-9pr5-prv3/GHSA-p2v3-9pr5-prv3.json @@ -7,12 +7,8 @@ "CVE-2004-2762" ], "details": "The server in IBM Tivoli Storage Manager (TSM) 4.2.x on MVS, 5.1.9.x before 5.1.9.1, 5.1.x before 5.1.10, 5.2.2.x before 5.2.2.3, 5.2.x before 5.2.3, 5.3.x before 5.3.0, and 6.x before 6.1, when the HTTP communication method is enabled, allows remote attackers to cause a denial of service (daemon crash or hang) via unspecified HTTP traffic, as demonstrated by the IBM port scanner 1.3.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p353-rwc3-5p7v/GHSA-p353-rwc3-5p7v.json b/advisories/unreviewed/2022/04/GHSA-p353-rwc3-5p7v/GHSA-p353-rwc3-5p7v.json index 7abd8534af5..0e41035a729 100644 --- a/advisories/unreviewed/2022/04/GHSA-p353-rwc3-5p7v/GHSA-p353-rwc3-5p7v.json +++ b/advisories/unreviewed/2022/04/GHSA-p353-rwc3-5p7v/GHSA-p353-rwc3-5p7v.json @@ -7,12 +7,8 @@ "CVE-2004-2604" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in PHProxy allows remote attackers to inject arbitrary web script or HTML via the error parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p449-wm4r-3ph2/GHSA-p449-wm4r-3ph2.json b/advisories/unreviewed/2022/04/GHSA-p449-wm4r-3ph2/GHSA-p449-wm4r-3ph2.json index f4a271feeb3..33aae86cd95 100644 --- a/advisories/unreviewed/2022/04/GHSA-p449-wm4r-3ph2/GHSA-p449-wm4r-3ph2.json +++ b/advisories/unreviewed/2022/04/GHSA-p449-wm4r-3ph2/GHSA-p449-wm4r-3ph2.json @@ -7,12 +7,8 @@ "CVE-2004-2708" ], "details": "Gyach Enhanced (Gyach-E) before 1.0.0 stores passwords in plaintext, which allows attackers to obtain user passwords by reading the configuration file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p4fm-7w3j-8656/GHSA-p4fm-7w3j-8656.json b/advisories/unreviewed/2022/04/GHSA-p4fm-7w3j-8656/GHSA-p4fm-7w3j-8656.json index fd201a7318a..b8542dde08f 100644 --- a/advisories/unreviewed/2022/04/GHSA-p4fm-7w3j-8656/GHSA-p4fm-7w3j-8656.json +++ b/advisories/unreviewed/2022/04/GHSA-p4fm-7w3j-8656/GHSA-p4fm-7w3j-8656.json @@ -7,12 +7,8 @@ "CVE-2004-2749" ], "details": "Directory traversal vulnerability in wra/public/wralogin in 2Wire Gateway, possibly as used in HomePortal and other product lines, allows remote attackers to read arbitrary files via a .. (dot dot) in the return parameter. NOTE: this issue was reported as XSS, but this might be a terminology error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-p72x-wpgm-6rr5/GHSA-p72x-wpgm-6rr5.json b/advisories/unreviewed/2022/04/GHSA-p72x-wpgm-6rr5/GHSA-p72x-wpgm-6rr5.json index 70279102ed9..391d20b7b2f 100644 --- a/advisories/unreviewed/2022/04/GHSA-p72x-wpgm-6rr5/GHSA-p72x-wpgm-6rr5.json +++ b/advisories/unreviewed/2022/04/GHSA-p72x-wpgm-6rr5/GHSA-p72x-wpgm-6rr5.json @@ -7,12 +7,8 @@ "CVE-2004-2547" ], "details": "NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p894-4749-f3jh/GHSA-p894-4749-f3jh.json b/advisories/unreviewed/2022/04/GHSA-p894-4749-f3jh/GHSA-p894-4749-f3jh.json index b176b976289..f140408df57 100644 --- a/advisories/unreviewed/2022/04/GHSA-p894-4749-f3jh/GHSA-p894-4749-f3jh.json +++ b/advisories/unreviewed/2022/04/GHSA-p894-4749-f3jh/GHSA-p894-4749-f3jh.json @@ -7,12 +7,8 @@ "CVE-2004-2732" ], "details": "nbmember.cgi in Netbilling 2.0 allows remote attackers to obtain sensitive information via the cmd=test option, which can be leveraged to determine the access key.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-pc2q-8rgh-2998/GHSA-pc2q-8rgh-2998.json b/advisories/unreviewed/2022/04/GHSA-pc2q-8rgh-2998/GHSA-pc2q-8rgh-2998.json index b7f3fdb8586..786a40db6ed 100644 --- a/advisories/unreviewed/2022/04/GHSA-pc2q-8rgh-2998/GHSA-pc2q-8rgh-2998.json +++ b/advisories/unreviewed/2022/04/GHSA-pc2q-8rgh-2998/GHSA-pc2q-8rgh-2998.json @@ -7,12 +7,8 @@ "CVE-2004-2552" ], "details": "Buffer overflow in XBoard 4.2.7 and earlier might allow local users to execute arbitrary code via a long -icshost command line argument. NOTE: since the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pc6j-99x3-m7cv/GHSA-pc6j-99x3-m7cv.json b/advisories/unreviewed/2022/04/GHSA-pc6j-99x3-m7cv/GHSA-pc6j-99x3-m7cv.json index cb0b1daeb11..a6d591089ce 100644 --- a/advisories/unreviewed/2022/04/GHSA-pc6j-99x3-m7cv/GHSA-pc6j-99x3-m7cv.json +++ b/advisories/unreviewed/2022/04/GHSA-pc6j-99x3-m7cv/GHSA-pc6j-99x3-m7cv.json @@ -7,12 +7,8 @@ "CVE-2004-2716" ], "details": "Multiple SQL injection vulnerabilities in usersL.php3 in PHPMyChat 0.14.5 allow remote attackers to execute arbitrary SQL commands via the (1) sortBy, (2) sortOrder, (3) startReg, (4) U, (5) LastCheck , and (6) R parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-pcpj-8874-w5qg/GHSA-pcpj-8874-w5qg.json b/advisories/unreviewed/2022/04/GHSA-pcpj-8874-w5qg/GHSA-pcpj-8874-w5qg.json index bcc29269653..03c33d37f11 100644 --- a/advisories/unreviewed/2022/04/GHSA-pcpj-8874-w5qg/GHSA-pcpj-8874-w5qg.json +++ b/advisories/unreviewed/2022/04/GHSA-pcpj-8874-w5qg/GHSA-pcpj-8874-w5qg.json @@ -7,12 +7,8 @@ "CVE-2004-2495" ], "details": "The (1) Webmail, (2) admin, and (3) SMTP services in Ability Mail Server 1.18 allow remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous connections to the service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pg9f-hrgx-gm27/GHSA-pg9f-hrgx-gm27.json b/advisories/unreviewed/2022/04/GHSA-pg9f-hrgx-gm27/GHSA-pg9f-hrgx-gm27.json index d0d17221915..ecdba2a8333 100644 --- a/advisories/unreviewed/2022/04/GHSA-pg9f-hrgx-gm27/GHSA-pg9f-hrgx-gm27.json +++ b/advisories/unreviewed/2022/04/GHSA-pg9f-hrgx-gm27/GHSA-pg9f-hrgx-gm27.json @@ -7,12 +7,8 @@ "CVE-2004-2701" ], "details": "Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-pgc8-5qmg-9q4q/GHSA-pgc8-5qmg-9q4q.json b/advisories/unreviewed/2022/04/GHSA-pgc8-5qmg-9q4q/GHSA-pgc8-5qmg-9q4q.json index 02a05931cd6..684d92a80ad 100644 --- a/advisories/unreviewed/2022/04/GHSA-pgc8-5qmg-9q4q/GHSA-pgc8-5qmg-9q4q.json +++ b/advisories/unreviewed/2022/04/GHSA-pgc8-5qmg-9q4q/GHSA-pgc8-5qmg-9q4q.json @@ -7,12 +7,8 @@ "CVE-2004-2746" ], "details": "SQL injection vulnerability in adminlogin.asp in XTREME ASP Photo Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-pjgq-j3j9-v9h8/GHSA-pjgq-j3j9-v9h8.json b/advisories/unreviewed/2022/04/GHSA-pjgq-j3j9-v9h8/GHSA-pjgq-j3j9-v9h8.json index 625b669a128..8784e04c645 100644 --- a/advisories/unreviewed/2022/04/GHSA-pjgq-j3j9-v9h8/GHSA-pjgq-j3j9-v9h8.json +++ b/advisories/unreviewed/2022/04/GHSA-pjgq-j3j9-v9h8/GHSA-pjgq-j3j9-v9h8.json @@ -7,12 +7,8 @@ "CVE-2004-2512" ], "details": "CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP response splitting attacks to spoof web content and poison web caches via CRLF (\"%0d%0a\") sequences in the PHPSESSID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pv6r-rmp3-mw8c/GHSA-pv6r-rmp3-mw8c.json b/advisories/unreviewed/2022/04/GHSA-pv6r-rmp3-mw8c/GHSA-pv6r-rmp3-mw8c.json index 5668cb68a94..58de8a0ccb9 100644 --- a/advisories/unreviewed/2022/04/GHSA-pv6r-rmp3-mw8c/GHSA-pv6r-rmp3-mw8c.json +++ b/advisories/unreviewed/2022/04/GHSA-pv6r-rmp3-mw8c/GHSA-pv6r-rmp3-mw8c.json @@ -7,12 +7,8 @@ "CVE-2004-2508" ], "details": "Cross-site scripting (XSS) vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to inject arbitrary web script or HTML via the next_file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pw85-4jwp-m329/GHSA-pw85-4jwp-m329.json b/advisories/unreviewed/2022/04/GHSA-pw85-4jwp-m329/GHSA-pw85-4jwp-m329.json index 09900d9eda4..1f26723075b 100644 --- a/advisories/unreviewed/2022/04/GHSA-pw85-4jwp-m329/GHSA-pw85-4jwp-m329.json +++ b/advisories/unreviewed/2022/04/GHSA-pw85-4jwp-m329/GHSA-pw85-4jwp-m329.json @@ -7,12 +7,8 @@ "CVE-2004-2726" ], "details": "HTTPMail service in MailEnable Professional 1.18 does not properly handle arguments to the Authorization header, which allows remote attackers to cause a denial of service (null dereference and application crash). NOTE: This is a different vulnerability than CVE-2005-1348.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pw8g-g9xc-q9hq/GHSA-pw8g-g9xc-q9hq.json b/advisories/unreviewed/2022/04/GHSA-pw8g-g9xc-q9hq/GHSA-pw8g-g9xc-q9hq.json index 98737815c23..d78b38e0af5 100644 --- a/advisories/unreviewed/2022/04/GHSA-pw8g-g9xc-q9hq/GHSA-pw8g-g9xc-q9hq.json +++ b/advisories/unreviewed/2022/04/GHSA-pw8g-g9xc-q9hq/GHSA-pw8g-g9xc-q9hq.json @@ -7,12 +7,8 @@ "CVE-2004-2592" ], "details": "Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a modified client that asks the server to send data stored at a negative array offset, which is not handled when processing Configstrings and Baselines.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-q49p-4xg9-93q2/GHSA-q49p-4xg9-93q2.json b/advisories/unreviewed/2022/04/GHSA-q49p-4xg9-93q2/GHSA-q49p-4xg9-93q2.json index af1011abcd4..8e5ebe29685 100644 --- a/advisories/unreviewed/2022/04/GHSA-q49p-4xg9-93q2/GHSA-q49p-4xg9-93q2.json +++ b/advisories/unreviewed/2022/04/GHSA-q49p-4xg9-93q2/GHSA-q49p-4xg9-93q2.json @@ -7,12 +7,8 @@ "CVE-2004-2759" ], "details": "Shared Sun StorEdge QFS and SAM-QFS file systems, as used in Utilization Suite 4.0 through 4.1 and Performance Suite 4.0 through 4.1, might allow local users to read portions of deleted files by accessing data within sparse files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q4w7-77p6-6mqm/GHSA-q4w7-77p6-6mqm.json b/advisories/unreviewed/2022/04/GHSA-q4w7-77p6-6mqm/GHSA-q4w7-77p6-6mqm.json index 4ceda3f9bdd..a8efff71989 100644 --- a/advisories/unreviewed/2022/04/GHSA-q4w7-77p6-6mqm/GHSA-q4w7-77p6-6mqm.json +++ b/advisories/unreviewed/2022/04/GHSA-q4w7-77p6-6mqm/GHSA-q4w7-77p6-6mqm.json @@ -7,12 +7,8 @@ "CVE-2004-2486" ], "details": "The DSS verification code in Dropbear SSH Server before 0.43 frees uninitialized variables, which might allow remote attackers to gain access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q4x9-xj49-44vc/GHSA-q4x9-xj49-44vc.json b/advisories/unreviewed/2022/04/GHSA-q4x9-xj49-44vc/GHSA-q4x9-xj49-44vc.json index 8d4bd9f2921..b9f073b5b25 100644 --- a/advisories/unreviewed/2022/04/GHSA-q4x9-xj49-44vc/GHSA-q4x9-xj49-44vc.json +++ b/advisories/unreviewed/2022/04/GHSA-q4x9-xj49-44vc/GHSA-q4x9-xj49-44vc.json @@ -7,12 +7,8 @@ "CVE-2004-2534" ], "details": "Fastream NETFile Server 7.1.2 does not properly handle keep-alive connection timeouts and does not close the connection after a HEAD request, which allows remote attackers to perform a denial of service (connection consumption) by sending a large number HTTP HEAD requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q6f4-32m8-8m5c/GHSA-q6f4-32m8-8m5c.json b/advisories/unreviewed/2022/04/GHSA-q6f4-32m8-8m5c/GHSA-q6f4-32m8-8m5c.json index a65915458a8..386a5862db3 100644 --- a/advisories/unreviewed/2022/04/GHSA-q6f4-32m8-8m5c/GHSA-q6f4-32m8-8m5c.json +++ b/advisories/unreviewed/2022/04/GHSA-q6f4-32m8-8m5c/GHSA-q6f4-32m8-8m5c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q6fr-pmm3-pp3p/GHSA-q6fr-pmm3-pp3p.json b/advisories/unreviewed/2022/04/GHSA-q6fr-pmm3-pp3p/GHSA-q6fr-pmm3-pp3p.json index 0da3152903b..53a479e84a1 100644 --- a/advisories/unreviewed/2022/04/GHSA-q6fr-pmm3-pp3p/GHSA-q6fr-pmm3-pp3p.json +++ b/advisories/unreviewed/2022/04/GHSA-q6fr-pmm3-pp3p/GHSA-q6fr-pmm3-pp3p.json @@ -7,12 +7,8 @@ "CVE-2004-2513" ], "details": "Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via a long SELECT command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q6j8-f7cj-r8m7/GHSA-q6j8-f7cj-r8m7.json b/advisories/unreviewed/2022/04/GHSA-q6j8-f7cj-r8m7/GHSA-q6j8-f7cj-r8m7.json index 7b44bc9dc47..7b3eb5d701f 100644 --- a/advisories/unreviewed/2022/04/GHSA-q6j8-f7cj-r8m7/GHSA-q6j8-f7cj-r8m7.json +++ b/advisories/unreviewed/2022/04/GHSA-q6j8-f7cj-r8m7/GHSA-q6j8-f7cj-r8m7.json @@ -7,12 +7,8 @@ "CVE-2004-2581" ], "details": "Novell iChain 2.3 allows attackers to cause a denial of service via a URL with a \"specific string.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q953-qm86-wxwh/GHSA-q953-qm86-wxwh.json b/advisories/unreviewed/2022/04/GHSA-q953-qm86-wxwh/GHSA-q953-qm86-wxwh.json index db9e957fac1..1ad61f6d692 100644 --- a/advisories/unreviewed/2022/04/GHSA-q953-qm86-wxwh/GHSA-q953-qm86-wxwh.json +++ b/advisories/unreviewed/2022/04/GHSA-q953-qm86-wxwh/GHSA-q953-qm86-wxwh.json @@ -7,12 +7,8 @@ "CVE-2004-2704" ], "details": "Hastymail 1.0.1 and earlier (stable) and 1.1 and earlier (development) does not send the \"attachment\" parameter in the Content-Disposition field for attachments, which causes the attachment to be rendered inline by Internet Explorer when the victim clicks the download link, which facilitates cross-site scripting (XSS) and possibly other attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-qc6j-jv93-f7h8/GHSA-qc6j-jv93-f7h8.json b/advisories/unreviewed/2022/04/GHSA-qc6j-jv93-f7h8/GHSA-qc6j-jv93-f7h8.json index 03cab8d8b31..90b0686b7e1 100644 --- a/advisories/unreviewed/2022/04/GHSA-qc6j-jv93-f7h8/GHSA-qc6j-jv93-f7h8.json +++ b/advisories/unreviewed/2022/04/GHSA-qc6j-jv93-f7h8/GHSA-qc6j-jv93-f7h8.json @@ -7,12 +7,8 @@ "CVE-2004-2675" ], "details": "ArGoSoft FTP Server before 1.4.1.6 allows remote authenticated users to cause a denial of service (crash) via a SITE PASS command with a long password parameter, which causes the database to be corrupted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qgjx-vfjf-jmpv/GHSA-qgjx-vfjf-jmpv.json b/advisories/unreviewed/2022/04/GHSA-qgjx-vfjf-jmpv/GHSA-qgjx-vfjf-jmpv.json index ba80e477756..6184f2cf71d 100644 --- a/advisories/unreviewed/2022/04/GHSA-qgjx-vfjf-jmpv/GHSA-qgjx-vfjf-jmpv.json +++ b/advisories/unreviewed/2022/04/GHSA-qgjx-vfjf-jmpv/GHSA-qgjx-vfjf-jmpv.json @@ -7,12 +7,8 @@ "CVE-2004-2699" ], "details": "deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qj6h-mm42-877r/GHSA-qj6h-mm42-877r.json b/advisories/unreviewed/2022/04/GHSA-qj6h-mm42-877r/GHSA-qj6h-mm42-877r.json index 02b663a49bd..679c2885d00 100644 --- a/advisories/unreviewed/2022/04/GHSA-qj6h-mm42-877r/GHSA-qj6h-mm42-877r.json +++ b/advisories/unreviewed/2022/04/GHSA-qj6h-mm42-877r/GHSA-qj6h-mm42-877r.json @@ -7,12 +7,8 @@ "CVE-2004-2620" ], "details": "The MIMEH_read_headers function in ripMIME 1.3.1.0 does not properly handle trailing \"\\r\" and \"\\n\" characters in headers, which leads to a buffer underflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qmxf-7p2j-5hvr/GHSA-qmxf-7p2j-5hvr.json b/advisories/unreviewed/2022/04/GHSA-qmxf-7p2j-5hvr/GHSA-qmxf-7p2j-5hvr.json index e3ce74176a6..f0b211c9303 100644 --- a/advisories/unreviewed/2022/04/GHSA-qmxf-7p2j-5hvr/GHSA-qmxf-7p2j-5hvr.json +++ b/advisories/unreviewed/2022/04/GHSA-qmxf-7p2j-5hvr/GHSA-qmxf-7p2j-5hvr.json @@ -7,12 +7,8 @@ "CVE-2004-2624" ], "details": "Cross-site scripting (XSS) vulnerability in \"TextSearch\" in WackoWiki 3.5 allows remote attackers to inject arbitrary web script or HTML via the \"phrase\" parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qp43-f5rv-7r4g/GHSA-qp43-f5rv-7r4g.json b/advisories/unreviewed/2022/04/GHSA-qp43-f5rv-7r4g/GHSA-qp43-f5rv-7r4g.json index 906b9283f46..37866b99c16 100644 --- a/advisories/unreviewed/2022/04/GHSA-qp43-f5rv-7r4g/GHSA-qp43-f5rv-7r4g.json +++ b/advisories/unreviewed/2022/04/GHSA-qp43-f5rv-7r4g/GHSA-qp43-f5rv-7r4g.json @@ -7,12 +7,8 @@ "CVE-2004-2728" ], "details": "Buffer overflow in the FTP server of Hummingbird Connectivity 7.1 and 9.0 allows remote, authenticated users to cause a denial of service (application crash) via a long argument to the XCWD command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-qpq7-jj5h-mc5q/GHSA-qpq7-jj5h-mc5q.json b/advisories/unreviewed/2022/04/GHSA-qpq7-jj5h-mc5q/GHSA-qpq7-jj5h-mc5q.json index 5c170eaa1e3..c69ffd2146d 100644 --- a/advisories/unreviewed/2022/04/GHSA-qpq7-jj5h-mc5q/GHSA-qpq7-jj5h-mc5q.json +++ b/advisories/unreviewed/2022/04/GHSA-qpq7-jj5h-mc5q/GHSA-qpq7-jj5h-mc5q.json @@ -7,12 +7,8 @@ "CVE-2004-2629" ], "details": "Multiple vulnerabilities in the H.323 protocol implementation for First Virtual Communications Click to Meet Express (when used with H.323 conferencing endpoints), Click to Meet Premier, Conference Server, and V-Gate allow remote attackers to cause a denial of service, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qq2w-99pw-p7w5/GHSA-qq2w-99pw-p7w5.json b/advisories/unreviewed/2022/04/GHSA-qq2w-99pw-p7w5/GHSA-qq2w-99pw-p7w5.json index b142eb42964..8c47f57242c 100644 --- a/advisories/unreviewed/2022/04/GHSA-qq2w-99pw-p7w5/GHSA-qq2w-99pw-p7w5.json +++ b/advisories/unreviewed/2022/04/GHSA-qq2w-99pw-p7w5/GHSA-qq2w-99pw-p7w5.json @@ -7,12 +7,8 @@ "CVE-2004-2644" ], "details": "Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing \"ANY\" type tags.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qqgf-6922-rxxc/GHSA-qqgf-6922-rxxc.json b/advisories/unreviewed/2022/04/GHSA-qqgf-6922-rxxc/GHSA-qqgf-6922-rxxc.json index 5d7a287b752..9cece47cde4 100644 --- a/advisories/unreviewed/2022/04/GHSA-qqgf-6922-rxxc/GHSA-qqgf-6922-rxxc.json +++ b/advisories/unreviewed/2022/04/GHSA-qqgf-6922-rxxc/GHSA-qqgf-6922-rxxc.json @@ -7,12 +7,8 @@ "CVE-2004-2631" ], "details": "Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qr26-8475-q4qg/GHSA-qr26-8475-q4qg.json b/advisories/unreviewed/2022/04/GHSA-qr26-8475-q4qg/GHSA-qr26-8475-q4qg.json index 79b42b6f2b6..159f75fc87a 100644 --- a/advisories/unreviewed/2022/04/GHSA-qr26-8475-q4qg/GHSA-qr26-8475-q4qg.json +++ b/advisories/unreviewed/2022/04/GHSA-qr26-8475-q4qg/GHSA-qr26-8475-q4qg.json @@ -7,12 +7,8 @@ "CVE-2004-2685" ], "details": "Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long address in a ping (p) command to the Telnet proxy service, a different vector than CVE-2004-2416.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-qr2h-xwqr-8rf4/GHSA-qr2h-xwqr-8rf4.json b/advisories/unreviewed/2022/04/GHSA-qr2h-xwqr-8rf4/GHSA-qr2h-xwqr-8rf4.json index 77bd71b5cb6..cf6e1f2f7b6 100644 --- a/advisories/unreviewed/2022/04/GHSA-qr2h-xwqr-8rf4/GHSA-qr2h-xwqr-8rf4.json +++ b/advisories/unreviewed/2022/04/GHSA-qr2h-xwqr-8rf4/GHSA-qr2h-xwqr-8rf4.json @@ -7,12 +7,8 @@ "CVE-2004-2516" ], "details": "Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET command with a large number of \"./\" sequences followed by \"../\" sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qr4x-6cmr-2rc9/GHSA-qr4x-6cmr-2rc9.json b/advisories/unreviewed/2022/04/GHSA-qr4x-6cmr-2rc9/GHSA-qr4x-6cmr-2rc9.json index 878628a057f..993274bc9cf 100644 --- a/advisories/unreviewed/2022/04/GHSA-qr4x-6cmr-2rc9/GHSA-qr4x-6cmr-2rc9.json +++ b/advisories/unreviewed/2022/04/GHSA-qr4x-6cmr-2rc9/GHSA-qr4x-6cmr-2rc9.json @@ -7,12 +7,8 @@ "CVE-2004-2605" ], "details": "aStats 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on (1) the aStats-Graphic-Signature-Generation file and (2) certain PNG image files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qrp8-65v4-pc63/GHSA-qrp8-65v4-pc63.json b/advisories/unreviewed/2022/04/GHSA-qrp8-65v4-pc63/GHSA-qrp8-65v4-pc63.json index ff76f6d7509..d9f5403f606 100644 --- a/advisories/unreviewed/2022/04/GHSA-qrp8-65v4-pc63/GHSA-qrp8-65v4-pc63.json +++ b/advisories/unreviewed/2022/04/GHSA-qrp8-65v4-pc63/GHSA-qrp8-65v4-pc63.json @@ -7,12 +7,8 @@ "CVE-2004-2768" ], "details": "dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid file, (2) setgid file, or (3) device, a related issue to CVE-2010-2059.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qvqg-r2p8-5rp6/GHSA-qvqg-r2p8-5rp6.json b/advisories/unreviewed/2022/04/GHSA-qvqg-r2p8-5rp6/GHSA-qvqg-r2p8-5rp6.json index 1eeac8c7065..def3b5ca6cd 100644 --- a/advisories/unreviewed/2022/04/GHSA-qvqg-r2p8-5rp6/GHSA-qvqg-r2p8-5rp6.json +++ b/advisories/unreviewed/2022/04/GHSA-qvqg-r2p8-5rp6/GHSA-qvqg-r2p8-5rp6.json @@ -7,12 +7,8 @@ "CVE-2004-2642" ], "details": "Yeemp 0.9.9 and earlier does not properly encrypt inbound files, which allows remote attackers to spoof the identity of the sender.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r3xr-78mf-93cp/GHSA-r3xr-78mf-93cp.json b/advisories/unreviewed/2022/04/GHSA-r3xr-78mf-93cp/GHSA-r3xr-78mf-93cp.json index 0c2ed294742..eb232022256 100644 --- a/advisories/unreviewed/2022/04/GHSA-r3xr-78mf-93cp/GHSA-r3xr-78mf-93cp.json +++ b/advisories/unreviewed/2022/04/GHSA-r3xr-78mf-93cp/GHSA-r3xr-78mf-93cp.json @@ -7,12 +7,8 @@ "CVE-2004-2751" ], "details": "SQL injection vulnerability in the members_list module in PostNuke 0.726, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the sortby parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-r8q3-xj3m-hq8q/GHSA-r8q3-xj3m-hq8q.json b/advisories/unreviewed/2022/04/GHSA-r8q3-xj3m-hq8q/GHSA-r8q3-xj3m-hq8q.json index 67c22c7c7da..edec1959378 100644 --- a/advisories/unreviewed/2022/04/GHSA-r8q3-xj3m-hq8q/GHSA-r8q3-xj3m-hq8q.json +++ b/advisories/unreviewed/2022/04/GHSA-r8q3-xj3m-hq8q/GHSA-r8q3-xj3m-hq8q.json @@ -7,12 +7,8 @@ "CVE-2004-2544" ], "details": "Admin Console in Secure Computing Corporation Sidewinder G2 6.1.0.01 exports private keys when exporting firewall certificates, which might allow attackers to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r9vf-x8x5-4p2c/GHSA-r9vf-x8x5-4p2c.json b/advisories/unreviewed/2022/04/GHSA-r9vf-x8x5-4p2c/GHSA-r9vf-x8x5-4p2c.json index f7d6d4e2d22..a3bcda4df6e 100644 --- a/advisories/unreviewed/2022/04/GHSA-r9vf-x8x5-4p2c/GHSA-r9vf-x8x5-4p2c.json +++ b/advisories/unreviewed/2022/04/GHSA-r9vf-x8x5-4p2c/GHSA-r9vf-x8x5-4p2c.json @@ -7,12 +7,8 @@ "CVE-2004-2745" ], "details": "Directory traversal vulnerability in Anteco Visual Technologies OwnServer 1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-rcmv-9x8c-5v8x/GHSA-rcmv-9x8c-5v8x.json b/advisories/unreviewed/2022/04/GHSA-rcmv-9x8c-5v8x/GHSA-rcmv-9x8c-5v8x.json index 755610cdebd..77c24011eaf 100644 --- a/advisories/unreviewed/2022/04/GHSA-rcmv-9x8c-5v8x/GHSA-rcmv-9x8c-5v8x.json +++ b/advisories/unreviewed/2022/04/GHSA-rcmv-9x8c-5v8x/GHSA-rcmv-9x8c-5v8x.json @@ -7,12 +7,8 @@ "CVE-2004-2665" ], "details": "Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport software in HP-UX B.11.00, B.11.04, and B.11.11 before 20040628 allows local users to cause a denial of service via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rcrv-mvrm-ghx8/GHSA-rcrv-mvrm-ghx8.json b/advisories/unreviewed/2022/04/GHSA-rcrv-mvrm-ghx8/GHSA-rcrv-mvrm-ghx8.json index 4b3dca9e13a..11f424f1f87 100644 --- a/advisories/unreviewed/2022/04/GHSA-rcrv-mvrm-ghx8/GHSA-rcrv-mvrm-ghx8.json +++ b/advisories/unreviewed/2022/04/GHSA-rcrv-mvrm-ghx8/GHSA-rcrv-mvrm-ghx8.json @@ -7,12 +7,8 @@ "CVE-2004-2481" ], "details": "MyProxy 6.58 allows remote authenticated users in the Users Tab to connect to arbitrary hosts from the MyProxy server, possibly bypassing access restrictions, by connecting to the proxy and issuing a CONNECT command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rfhr-47j6-q56h/GHSA-rfhr-47j6-q56h.json b/advisories/unreviewed/2022/04/GHSA-rfhr-47j6-q56h/GHSA-rfhr-47j6-q56h.json index 386bb65a1ce..5ec52f1e882 100644 --- a/advisories/unreviewed/2022/04/GHSA-rfhr-47j6-q56h/GHSA-rfhr-47j6-q56h.json +++ b/advisories/unreviewed/2022/04/GHSA-rfhr-47j6-q56h/GHSA-rfhr-47j6-q56h.json @@ -7,12 +7,8 @@ "CVE-2004-2574" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary web script or HTML via the date parameter in a calendar.uicalendar.planner menuaction.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rfvj-m3h5-jvf2/GHSA-rfvj-m3h5-jvf2.json b/advisories/unreviewed/2022/04/GHSA-rfvj-m3h5-jvf2/GHSA-rfvj-m3h5-jvf2.json index f73c3a13168..a95b402f795 100644 --- a/advisories/unreviewed/2022/04/GHSA-rfvj-m3h5-jvf2/GHSA-rfvj-m3h5-jvf2.json +++ b/advisories/unreviewed/2022/04/GHSA-rfvj-m3h5-jvf2/GHSA-rfvj-m3h5-jvf2.json @@ -7,12 +7,8 @@ "CVE-2004-2569" ], "details": "ipmenu 0.0.3 before Debian GNU/Linux ipmenu_0.0.3-5 allows local users to overwrite arbitrary files via a symlink attack on the ipmenu.log temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rg5q-w7qj-gw3c/GHSA-rg5q-w7qj-gw3c.json b/advisories/unreviewed/2022/04/GHSA-rg5q-w7qj-gw3c/GHSA-rg5q-w7qj-gw3c.json index 17501eb4fae..7106840a196 100644 --- a/advisories/unreviewed/2022/04/GHSA-rg5q-w7qj-gw3c/GHSA-rg5q-w7qj-gw3c.json +++ b/advisories/unreviewed/2022/04/GHSA-rg5q-w7qj-gw3c/GHSA-rg5q-w7qj-gw3c.json @@ -7,12 +7,8 @@ "CVE-2004-2731" ], "details": "Multiple integer overflows in Sbus PROM driver (drivers/sbus/char/openprom.c) for the Linux kernel 2.4.x up to 2.4.27, 2.6.x up to 2.6.7, and possibly later versions, allow local users to execute arbitrary code by specifying (1) a small buffer size to the copyin_string function or (2) a negative buffer size to the copyin function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rhg2-2jf9-5p9w/GHSA-rhg2-2jf9-5p9w.json b/advisories/unreviewed/2022/04/GHSA-rhg2-2jf9-5p9w/GHSA-rhg2-2jf9-5p9w.json index 4e0d950f7fa..7a9f9279bd6 100644 --- a/advisories/unreviewed/2022/04/GHSA-rhg2-2jf9-5p9w/GHSA-rhg2-2jf9-5p9w.json +++ b/advisories/unreviewed/2022/04/GHSA-rhg2-2jf9-5p9w/GHSA-rhg2-2jf9-5p9w.json @@ -7,12 +7,8 @@ "CVE-2004-2611" ], "details": "The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophster, FreeSophster, and FreeSophsterPAM, removes the (1) setuid, (2) setgid, and (3) sticky bits when changing a file, which might allow attackers to gain privileges or conduct other unauthorized activities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rmv6-xq8c-gmp5/GHSA-rmv6-xq8c-gmp5.json b/advisories/unreviewed/2022/04/GHSA-rmv6-xq8c-gmp5/GHSA-rmv6-xq8c-gmp5.json index 5f59c6960fd..96619499e1f 100644 --- a/advisories/unreviewed/2022/04/GHSA-rmv6-xq8c-gmp5/GHSA-rmv6-xq8c-gmp5.json +++ b/advisories/unreviewed/2022/04/GHSA-rmv6-xq8c-gmp5/GHSA-rmv6-xq8c-gmp5.json @@ -7,12 +7,8 @@ "CVE-2004-2485" ], "details": "Unspecified vulnerability in PHP Live! before 2.8.2, due to a \"major security problem,\" allows remote attackers to include arbitrary files and directories via unspecified attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rqvp-h98w-9g7q/GHSA-rqvp-h98w-9g7q.json b/advisories/unreviewed/2022/04/GHSA-rqvp-h98w-9g7q/GHSA-rqvp-h98w-9g7q.json index 4ba742bc319..7886652f51e 100644 --- a/advisories/unreviewed/2022/04/GHSA-rqvp-h98w-9g7q/GHSA-rqvp-h98w-9g7q.json +++ b/advisories/unreviewed/2022/04/GHSA-rqvp-h98w-9g7q/GHSA-rqvp-h98w-9g7q.json @@ -7,12 +7,8 @@ "CVE-2004-2640" ], "details": "Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequences or (2) absolute paths to the template parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rr96-8f9f-cppq/GHSA-rr96-8f9f-cppq.json b/advisories/unreviewed/2022/04/GHSA-rr96-8f9f-cppq/GHSA-rr96-8f9f-cppq.json index e813cb6c6aa..73cf125185a 100644 --- a/advisories/unreviewed/2022/04/GHSA-rr96-8f9f-cppq/GHSA-rr96-8f9f-cppq.json +++ b/advisories/unreviewed/2022/04/GHSA-rr96-8f9f-cppq/GHSA-rr96-8f9f-cppq.json @@ -7,12 +7,8 @@ "CVE-2004-2672" ], "details": "Unspecified vulnerability in ArGoSoft FTP server before 1.4.2.2 allows attackers to upload .lnk files via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rrp2-4g3f-vv2g/GHSA-rrp2-4g3f-vv2g.json b/advisories/unreviewed/2022/04/GHSA-rrp2-4g3f-vv2g/GHSA-rrp2-4g3f-vv2g.json index 6b683bda22e..76a4e7fdcc7 100644 --- a/advisories/unreviewed/2022/04/GHSA-rrp2-4g3f-vv2g/GHSA-rrp2-4g3f-vv2g.json +++ b/advisories/unreviewed/2022/04/GHSA-rrp2-4g3f-vv2g/GHSA-rrp2-4g3f-vv2g.json @@ -7,12 +7,8 @@ "CVE-2004-2525" ], "details": "Cross-site scripting (XSS) vulnerability in compat.php in Serendipity before 0.7.1 allows remote attackers to inject arbitrary web script or HTML via the searchTerm variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rrwg-cv62-hrxc/GHSA-rrwg-cv62-hrxc.json b/advisories/unreviewed/2022/04/GHSA-rrwg-cv62-hrxc/GHSA-rrwg-cv62-hrxc.json index 571a5498a55..ab4047c8e71 100644 --- a/advisories/unreviewed/2022/04/GHSA-rrwg-cv62-hrxc/GHSA-rrwg-cv62-hrxc.json +++ b/advisories/unreviewed/2022/04/GHSA-rrwg-cv62-hrxc/GHSA-rrwg-cv62-hrxc.json @@ -7,12 +7,8 @@ "CVE-2004-2705" ], "details": "Unspecified vulnerability in Player vs. Player Gaming Network (PvPGN) before 1.6.4 allows remote attackers to obtain attributes of arbitrary accounts, including the password hash, via certain statsreq packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rv84-9j9f-rfxp/GHSA-rv84-9j9f-rfxp.json b/advisories/unreviewed/2022/04/GHSA-rv84-9j9f-rfxp/GHSA-rv84-9j9f-rfxp.json index aa80418406c..9a91426440c 100644 --- a/advisories/unreviewed/2022/04/GHSA-rv84-9j9f-rfxp/GHSA-rv84-9j9f-rfxp.json +++ b/advisories/unreviewed/2022/04/GHSA-rv84-9j9f-rfxp/GHSA-rv84-9j9f-rfxp.json @@ -7,12 +7,8 @@ "CVE-2004-2758" ], "details": "Multiple unspecified vulnerabilities in the H.323 protocol implementation for Sun SunForum 3.2 and 3D 1.0 allow remote attackers to cause a denial of service (segmentation fault and process crash), as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rw75-g77q-qm9m/GHSA-rw75-g77q-qm9m.json b/advisories/unreviewed/2022/04/GHSA-rw75-g77q-qm9m/GHSA-rw75-g77q-qm9m.json index 6859631c609..1eb2afd112d 100644 --- a/advisories/unreviewed/2022/04/GHSA-rw75-g77q-qm9m/GHSA-rw75-g77q-qm9m.json +++ b/advisories/unreviewed/2022/04/GHSA-rw75-g77q-qm9m/GHSA-rw75-g77q-qm9m.json @@ -7,12 +7,8 @@ "CVE-2004-2676" ], "details": "The Spy Sweeper Enterprise Client (SpySweeperTray.exe) in WebRoot Spy Sweeper before 2.0 does not drop privileges when using the help functionality, which allows local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rwg3-w9r2-cx93/GHSA-rwg3-w9r2-cx93.json b/advisories/unreviewed/2022/04/GHSA-rwg3-w9r2-cx93/GHSA-rwg3-w9r2-cx93.json index 1692c194c13..0cf714f8fdb 100644 --- a/advisories/unreviewed/2022/04/GHSA-rwg3-w9r2-cx93/GHSA-rwg3-w9r2-cx93.json +++ b/advisories/unreviewed/2022/04/GHSA-rwg3-w9r2-cx93/GHSA-rwg3-w9r2-cx93.json @@ -7,12 +7,8 @@ "CVE-2004-2610" ], "details": "mntd_mount.c in mntd before 0.4.2 might allow local users to gain privileges via shell metacharacters in a remount option in the configuration file. NOTE: It is not clear whether this is a vulnerability because there is not necessarily any common usage in which privilege boundaries are crossed. Typical usage would restrict write access to the configuration file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v2hf-gpg2-hm9f/GHSA-v2hf-gpg2-hm9f.json b/advisories/unreviewed/2022/04/GHSA-v2hf-gpg2-hm9f/GHSA-v2hf-gpg2-hm9f.json index 16a3813cd1e..cac7bbc84cd 100644 --- a/advisories/unreviewed/2022/04/GHSA-v2hf-gpg2-hm9f/GHSA-v2hf-gpg2-hm9f.json +++ b/advisories/unreviewed/2022/04/GHSA-v2hf-gpg2-hm9f/GHSA-v2hf-gpg2-hm9f.json @@ -7,12 +7,8 @@ "CVE-2004-2706" ], "details": "Unspecified vulnerability in Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service (crash) via conference packets with error messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-v5r7-gp5q-w3fh/GHSA-v5r7-gp5q-w3fh.json b/advisories/unreviewed/2022/04/GHSA-v5r7-gp5q-w3fh/GHSA-v5r7-gp5q-w3fh.json index a913e81d89b..90c864f7417 100644 --- a/advisories/unreviewed/2022/04/GHSA-v5r7-gp5q-w3fh/GHSA-v5r7-gp5q-w3fh.json +++ b/advisories/unreviewed/2022/04/GHSA-v5r7-gp5q-w3fh/GHSA-v5r7-gp5q-w3fh.json @@ -7,12 +7,8 @@ "CVE-2004-2707" ], "details": "Multiple unspecified vulnerabilities in Gyach Enhanced (Gyach-E) before 1.0.5 have unknown impact and attack vectors related to \"several security flaws,\" probably related to buffer overflows in HTTP server responses.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v5xr-gjjf-rhqc/GHSA-v5xr-gjjf-rhqc.json b/advisories/unreviewed/2022/04/GHSA-v5xr-gjjf-rhqc/GHSA-v5xr-gjjf-rhqc.json index 28619859a7e..c968122f9c5 100644 --- a/advisories/unreviewed/2022/04/GHSA-v5xr-gjjf-rhqc/GHSA-v5xr-gjjf-rhqc.json +++ b/advisories/unreviewed/2022/04/GHSA-v5xr-gjjf-rhqc/GHSA-v5xr-gjjf-rhqc.json @@ -7,12 +7,8 @@ "CVE-2004-2539" ], "details": "Unknown vulnerability in Network Appliance NetCache 5.2 and Data ONTAP 6.0 allows remote attackers to cause a denial of service (panic and reboot) and possibly other impacts via unknown attack vectors, possibly related to unspecified worms, as identified by bug ID", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v78w-74x8-ppvv/GHSA-v78w-74x8-ppvv.json b/advisories/unreviewed/2022/04/GHSA-v78w-74x8-ppvv/GHSA-v78w-74x8-ppvv.json index f2a2392beab..eaa1aa2e125 100644 --- a/advisories/unreviewed/2022/04/GHSA-v78w-74x8-ppvv/GHSA-v78w-74x8-ppvv.json +++ b/advisories/unreviewed/2022/04/GHSA-v78w-74x8-ppvv/GHSA-v78w-74x8-ppvv.json @@ -7,12 +7,8 @@ "CVE-2004-2683" ], "details": "Unspecified vulnerability in the %XML.Utils.SchemaServer class in InterSystems Cache' 5.0 allows attackers to access arbitrary files on a server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v935-c7vg-r239/GHSA-v935-c7vg-r239.json b/advisories/unreviewed/2022/04/GHSA-v935-c7vg-r239/GHSA-v935-c7vg-r239.json index d5ab37337aa..d68fc25bbdc 100644 --- a/advisories/unreviewed/2022/04/GHSA-v935-c7vg-r239/GHSA-v935-c7vg-r239.json +++ b/advisories/unreviewed/2022/04/GHSA-v935-c7vg-r239/GHSA-v935-c7vg-r239.json @@ -7,12 +7,8 @@ "CVE-2004-2557" ], "details": "NetGear WG602 (aka WG602v1) Wireless Access Point 1.7.14 has a hardcoded account of username \"superman\" and password \"21241036\", which allows remote attackers to modify the configuration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vcc9-7w4c-j47m/GHSA-vcc9-7w4c-j47m.json b/advisories/unreviewed/2022/04/GHSA-vcc9-7w4c-j47m/GHSA-vcc9-7w4c-j47m.json index 7bd0eb476dc..ec255d7da8c 100644 --- a/advisories/unreviewed/2022/04/GHSA-vcc9-7w4c-j47m/GHSA-vcc9-7w4c-j47m.json +++ b/advisories/unreviewed/2022/04/GHSA-vcc9-7w4c-j47m/GHSA-vcc9-7w4c-j47m.json @@ -7,12 +7,8 @@ "CVE-2004-2753" ], "details": "Unspecified vulnerability in SharedX in HP-UX B.11.00, B.11.11, and B.11.22 allows local users to access unspecified files or cause a denial of service via unknown vectors related to handling of \"files in a potentially insecure manner.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vf95-35wr-4pfv/GHSA-vf95-35wr-4pfv.json b/advisories/unreviewed/2022/04/GHSA-vf95-35wr-4pfv/GHSA-vf95-35wr-4pfv.json index bec03c0a0fa..650815c0004 100644 --- a/advisories/unreviewed/2022/04/GHSA-vf95-35wr-4pfv/GHSA-vf95-35wr-4pfv.json +++ b/advisories/unreviewed/2022/04/GHSA-vf95-35wr-4pfv/GHSA-vf95-35wr-4pfv.json @@ -7,12 +7,8 @@ "CVE-2004-2538" ], "details": "Direct static code injection vulnerability in the PCG simple application generation in phpCodeGenie before 3.0.2 allows remote authenticated users to execute arbitrary code via the (1) header or (2) footer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vfjp-q2j5-26qc/GHSA-vfjp-q2j5-26qc.json b/advisories/unreviewed/2022/04/GHSA-vfjp-q2j5-26qc/GHSA-vfjp-q2j5-26qc.json index 41551a4f6f7..6670ba6c07c 100644 --- a/advisories/unreviewed/2022/04/GHSA-vfjp-q2j5-26qc/GHSA-vfjp-q2j5-26qc.json +++ b/advisories/unreviewed/2022/04/GHSA-vfjp-q2j5-26qc/GHSA-vfjp-q2j5-26qc.json @@ -7,12 +7,8 @@ "CVE-2004-2501" ], "details": "Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute arbitrary code via (1) a long command string or (2) a long string to the MEIMAP service and then terminating the connection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vwvq-g57j-fg4q/GHSA-vwvq-g57j-fg4q.json b/advisories/unreviewed/2022/04/GHSA-vwvq-g57j-fg4q/GHSA-vwvq-g57j-fg4q.json index 0bb2f52f163..b49006968ac 100644 --- a/advisories/unreviewed/2022/04/GHSA-vwvq-g57j-fg4q/GHSA-vwvq-g57j-fg4q.json +++ b/advisories/unreviewed/2022/04/GHSA-vwvq-g57j-fg4q/GHSA-vwvq-g57j-fg4q.json @@ -7,12 +7,8 @@ "CVE-2004-2488" ], "details": "Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via \"C:\" sequences in the (1) RETR (get), (2) NLST (ls), (3) LIST (ls), (4) RNFR, or (5) RNTO FTP commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w6p4-h264-pgp8/GHSA-w6p4-h264-pgp8.json b/advisories/unreviewed/2022/04/GHSA-w6p4-h264-pgp8/GHSA-w6p4-h264-pgp8.json index ddff1de2834..a671a0e3959 100644 --- a/advisories/unreviewed/2022/04/GHSA-w6p4-h264-pgp8/GHSA-w6p4-h264-pgp8.json +++ b/advisories/unreviewed/2022/04/GHSA-w6p4-h264-pgp8/GHSA-w6p4-h264-pgp8.json @@ -7,12 +7,8 @@ "CVE-2004-2694" ], "details": "Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook context, and facilitate phishing attacks via a \"BASE HREF\" with the target set to \"_top\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w84c-j5hg-h3mx/GHSA-w84c-j5hg-h3mx.json b/advisories/unreviewed/2022/04/GHSA-w84c-j5hg-h3mx/GHSA-w84c-j5hg-h3mx.json index cce4886cf40..e069138a353 100644 --- a/advisories/unreviewed/2022/04/GHSA-w84c-j5hg-h3mx/GHSA-w84c-j5hg-h3mx.json +++ b/advisories/unreviewed/2022/04/GHSA-w84c-j5hg-h3mx/GHSA-w84c-j5hg-h3mx.json @@ -7,12 +7,8 @@ "CVE-2004-2561" ], "details": "Multiple SQL injection vulnerabilities in Internet Software Sciences Web+Center 4.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the ISS_TECH_CENTER_LOGIN cookie in search.asp and (2) one or more cookies in DoCustomerOptions.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w84v-vmqq-p8vc/GHSA-w84v-vmqq-p8vc.json b/advisories/unreviewed/2022/04/GHSA-w84v-vmqq-p8vc/GHSA-w84v-vmqq-p8vc.json index addc64b8e5f..5a0abedd453 100644 --- a/advisories/unreviewed/2022/04/GHSA-w84v-vmqq-p8vc/GHSA-w84v-vmqq-p8vc.json +++ b/advisories/unreviewed/2022/04/GHSA-w84v-vmqq-p8vc/GHSA-w84v-vmqq-p8vc.json @@ -7,12 +7,8 @@ "CVE-2004-2697" ], "details": "The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a command line argument (log file). NOTE: this might be related to CVE-2006-5002.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-w8j7-864p-92c6/GHSA-w8j7-864p-92c6.json b/advisories/unreviewed/2022/04/GHSA-w8j7-864p-92c6/GHSA-w8j7-864p-92c6.json index a7c8dd36dd2..870d9d4caf2 100644 --- a/advisories/unreviewed/2022/04/GHSA-w8j7-864p-92c6/GHSA-w8j7-864p-92c6.json +++ b/advisories/unreviewed/2022/04/GHSA-w8j7-864p-92c6/GHSA-w8j7-864p-92c6.json @@ -7,12 +7,8 @@ "CVE-2004-2686" ], "details": "Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-w98r-ffjg-68q7/GHSA-w98r-ffjg-68q7.json b/advisories/unreviewed/2022/04/GHSA-w98r-ffjg-68q7/GHSA-w98r-ffjg-68q7.json index b2a12c623a6..8c8ae6c321e 100644 --- a/advisories/unreviewed/2022/04/GHSA-w98r-ffjg-68q7/GHSA-w98r-ffjg-68q7.json +++ b/advisories/unreviewed/2022/04/GHSA-w98r-ffjg-68q7/GHSA-w98r-ffjg-68q7.json @@ -7,12 +7,8 @@ "CVE-2004-2553" ], "details": "The Ignition Project ignitionServer 0.1.2 through 0.1.2-R2 allows remote authenticated users with local IRC operator privileges to obtain global IRC operator privileges by using the unofficial umode command with the +ORD argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wf7x-gjvh-m5r3/GHSA-wf7x-gjvh-m5r3.json b/advisories/unreviewed/2022/04/GHSA-wf7x-gjvh-m5r3/GHSA-wf7x-gjvh-m5r3.json index 9f89ac4a1d7..d5f8ad7376d 100644 --- a/advisories/unreviewed/2022/04/GHSA-wf7x-gjvh-m5r3/GHSA-wf7x-gjvh-m5r3.json +++ b/advisories/unreviewed/2022/04/GHSA-wf7x-gjvh-m5r3/GHSA-wf7x-gjvh-m5r3.json @@ -7,12 +7,8 @@ "CVE-2004-2479" ], "details": "Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wfc5-6r3q-mv26/GHSA-wfc5-6r3q-mv26.json b/advisories/unreviewed/2022/04/GHSA-wfc5-6r3q-mv26/GHSA-wfc5-6r3q-mv26.json index de5cbb8722b..bf49ba560a5 100644 --- a/advisories/unreviewed/2022/04/GHSA-wfc5-6r3q-mv26/GHSA-wfc5-6r3q-mv26.json +++ b/advisories/unreviewed/2022/04/GHSA-wfc5-6r3q-mv26/GHSA-wfc5-6r3q-mv26.json @@ -7,12 +7,8 @@ "CVE-2004-2498" ], "details": "Unspecified vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to determine internal directory structures via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wjrq-3hqr-vp6g/GHSA-wjrq-3hqr-vp6g.json b/advisories/unreviewed/2022/04/GHSA-wjrq-3hqr-vp6g/GHSA-wjrq-3hqr-vp6g.json index aceb3f2f67c..8a02131a824 100644 --- a/advisories/unreviewed/2022/04/GHSA-wjrq-3hqr-vp6g/GHSA-wjrq-3hqr-vp6g.json +++ b/advisories/unreviewed/2022/04/GHSA-wjrq-3hqr-vp6g/GHSA-wjrq-3hqr-vp6g.json @@ -7,12 +7,8 @@ "CVE-2004-2646" ], "details": "The addUser function in UserManager.java in Free Web Chat 2.0 allows remote attackers to cause a denial of service (uncaught NullPointerException) via unknown attack vectors that cause the usrName variable to be null.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wm5h-c9q7-gpcx/GHSA-wm5h-c9q7-gpcx.json b/advisories/unreviewed/2022/04/GHSA-wm5h-c9q7-gpcx/GHSA-wm5h-c9q7-gpcx.json index 85f869a605b..70f42403000 100644 --- a/advisories/unreviewed/2022/04/GHSA-wm5h-c9q7-gpcx/GHSA-wm5h-c9q7-gpcx.json +++ b/advisories/unreviewed/2022/04/GHSA-wm5h-c9q7-gpcx/GHSA-wm5h-c9q7-gpcx.json @@ -7,12 +7,8 @@ "CVE-2004-2476" ], "details": "Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IFRAME with \"?\" as the file source.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wpx6-f5m4-qjwq/GHSA-wpx6-f5m4-qjwq.json b/advisories/unreviewed/2022/04/GHSA-wpx6-f5m4-qjwq/GHSA-wpx6-f5m4-qjwq.json index dcd6167276e..f018d83e267 100644 --- a/advisories/unreviewed/2022/04/GHSA-wpx6-f5m4-qjwq/GHSA-wpx6-f5m4-qjwq.json +++ b/advisories/unreviewed/2022/04/GHSA-wpx6-f5m4-qjwq/GHSA-wpx6-f5m4-qjwq.json @@ -7,12 +7,8 @@ "CVE-2004-2710" ], "details": "Multiple buffer overflows in Gyach Enhanced (Gyach-E) before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) sending certain typing statuses or (2) setting the chat room status bar to the current chat room name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-wvcr-r9cr-2xrh/GHSA-wvcr-r9cr-2xrh.json b/advisories/unreviewed/2022/04/GHSA-wvcr-r9cr-2xrh/GHSA-wvcr-r9cr-2xrh.json index 90805b55c1c..d2322f10230 100644 --- a/advisories/unreviewed/2022/04/GHSA-wvcr-r9cr-2xrh/GHSA-wvcr-r9cr-2xrh.json +++ b/advisories/unreviewed/2022/04/GHSA-wvcr-r9cr-2xrh/GHSA-wvcr-r9cr-2xrh.json @@ -7,12 +7,8 @@ "CVE-2004-2504" ], "details": "The GUI in Alt-N Technologies MDaemon 7.2 and earlier, including 6.8, executes child processes such as NOTEPAD.EXE with SYSTEM privileges when users create new files, which allows local users with physical access to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x36q-879q-h59v/GHSA-x36q-879q-h59v.json b/advisories/unreviewed/2022/04/GHSA-x36q-879q-h59v/GHSA-x36q-879q-h59v.json index f21de64c871..bf490e59145 100644 --- a/advisories/unreviewed/2022/04/GHSA-x36q-879q-h59v/GHSA-x36q-879q-h59v.json +++ b/advisories/unreviewed/2022/04/GHSA-x36q-879q-h59v/GHSA-x36q-879q-h59v.json @@ -7,12 +7,8 @@ "CVE-2004-2490" ], "details": "Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.xC1 and 9.40.xC2 allows local users to execute arbitrary code via a long GL_PATH environment variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x4pg-475r-rqf2/GHSA-x4pg-475r-rqf2.json b/advisories/unreviewed/2022/04/GHSA-x4pg-475r-rqf2/GHSA-x4pg-475r-rqf2.json index f9731927a14..fc47c363042 100644 --- a/advisories/unreviewed/2022/04/GHSA-x4pg-475r-rqf2/GHSA-x4pg-475r-rqf2.json +++ b/advisories/unreviewed/2022/04/GHSA-x4pg-475r-rqf2/GHSA-x4pg-475r-rqf2.json @@ -7,12 +7,8 @@ "CVE-2004-2535" ], "details": "The person-to-person secure messaging feature in Sticker before 3.1.0 beta 2 allows remote attackers to post messages to unauthorized private groups by using the group's public encryption key.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x5w8-45xj-42q9/GHSA-x5w8-45xj-42q9.json b/advisories/unreviewed/2022/04/GHSA-x5w8-45xj-42q9/GHSA-x5w8-45xj-42q9.json index a6c938c2bb3..9da57aee116 100644 --- a/advisories/unreviewed/2022/04/GHSA-x5w8-45xj-42q9/GHSA-x5w8-45xj-42q9.json +++ b/advisories/unreviewed/2022/04/GHSA-x5w8-45xj-42q9/GHSA-x5w8-45xj-42q9.json @@ -7,12 +7,8 @@ "CVE-2004-2755" ], "details": "Cross-site scripting (XSS) vulnerability in Symantec Web Security 2.5, 3.0.0, and 3.0.1 before build 62 allows remote attackers to inject arbitrary web script or HTML via the query string in blocked URLs that are listed in (1) error or (2) block page messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-x62x-33c9-999r/GHSA-x62x-33c9-999r.json b/advisories/unreviewed/2022/04/GHSA-x62x-33c9-999r/GHSA-x62x-33c9-999r.json index c25fc15b2d2..a99c04255f3 100644 --- a/advisories/unreviewed/2022/04/GHSA-x62x-33c9-999r/GHSA-x62x-33c9-999r.json +++ b/advisories/unreviewed/2022/04/GHSA-x62x-33c9-999r/GHSA-x62x-33c9-999r.json @@ -7,12 +7,8 @@ "CVE-2004-2595" ], "details": "Absolute path traversal vulnerability in Quake II server before R1Q2 on Linux, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a download command with a full pathname for a directory in the argument, which causes the server to crash when it cannot read data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x6p9-5hpx-q6qq/GHSA-x6p9-5hpx-q6qq.json b/advisories/unreviewed/2022/04/GHSA-x6p9-5hpx-q6qq/GHSA-x6p9-5hpx-q6qq.json index 263b4a9b350..23c29928ba3 100644 --- a/advisories/unreviewed/2022/04/GHSA-x6p9-5hpx-q6qq/GHSA-x6p9-5hpx-q6qq.json +++ b/advisories/unreviewed/2022/04/GHSA-x6p9-5hpx-q6qq/GHSA-x6p9-5hpx-q6qq.json @@ -7,12 +7,8 @@ "CVE-2004-2565" ], "details": "Multiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, when the administrative IP address restrictions have been modified from the default, allow remote authenticated users to read arbitrary files via (1) a \"..\\\" (dot dot backslash) in the file parameter to showini.asp, or (2) an absolute path with drive letter in the log parameter to showlog.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x85h-h5r6-5rh8/GHSA-x85h-h5r6-5rh8.json b/advisories/unreviewed/2022/04/GHSA-x85h-h5r6-5rh8/GHSA-x85h-h5r6-5rh8.json index 8d9fa131599..602585970e1 100644 --- a/advisories/unreviewed/2022/04/GHSA-x85h-h5r6-5rh8/GHSA-x85h-h5r6-5rh8.json +++ b/advisories/unreviewed/2022/04/GHSA-x85h-h5r6-5rh8/GHSA-x85h-h5r6-5rh8.json @@ -7,12 +7,8 @@ "CVE-2004-2635" ], "details": "An ActiveX control for McAfee Security Installer Control System 4.0.0.81 allows remote attackers to access the Windows registry via web pages that use the control's RegQueryValue() method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x8q9-wj85-wrcw/GHSA-x8q9-wj85-wrcw.json b/advisories/unreviewed/2022/04/GHSA-x8q9-wj85-wrcw/GHSA-x8q9-wj85-wrcw.json index 79d48d87ec0..5051e5a2261 100644 --- a/advisories/unreviewed/2022/04/GHSA-x8q9-wj85-wrcw/GHSA-x8q9-wj85-wrcw.json +++ b/advisories/unreviewed/2022/04/GHSA-x8q9-wj85-wrcw/GHSA-x8q9-wj85-wrcw.json @@ -7,12 +7,8 @@ "CVE-2004-2691" ], "details": "Unspecified vulnerability in 3Com SuperStack 3 4400 switches with firmware version before 3.31 allows remote attackers to cause a denial of service (device reset) via a crafted request to the web management interface. NOTE: the provenance of this information is unknown; details are obtained from third party reports.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xcgv-26c6-gm5c/GHSA-xcgv-26c6-gm5c.json b/advisories/unreviewed/2022/04/GHSA-xcgv-26c6-gm5c/GHSA-xcgv-26c6-gm5c.json index bef8f68054f..368b47e54ca 100644 --- a/advisories/unreviewed/2022/04/GHSA-xcgv-26c6-gm5c/GHSA-xcgv-26c6-gm5c.json +++ b/advisories/unreviewed/2022/04/GHSA-xcgv-26c6-gm5c/GHSA-xcgv-26c6-gm5c.json @@ -7,12 +7,8 @@ "CVE-2004-2497" ], "details": "Cross-site scripting (XSS) vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xf68-pxg8-qfjf/GHSA-xf68-pxg8-qfjf.json b/advisories/unreviewed/2022/04/GHSA-xf68-pxg8-qfjf/GHSA-xf68-pxg8-qfjf.json index b7d4f4a0b76..3ea0bef1494 100644 --- a/advisories/unreviewed/2022/04/GHSA-xf68-pxg8-qfjf/GHSA-xf68-pxg8-qfjf.json +++ b/advisories/unreviewed/2022/04/GHSA-xf68-pxg8-qfjf/GHSA-xf68-pxg8-qfjf.json @@ -7,12 +7,8 @@ "CVE-2004-2766" ], "details": "Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02 allows remote attackers to obtain unspecified \"access\" to e-mail via a crafted e-mail message, related to a \"session hijacking\" issue, a different vulnerability than CVE-2005-2022 and CVE-2006-5486.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-xgmx-762m-r89c/GHSA-xgmx-762m-r89c.json b/advisories/unreviewed/2022/04/GHSA-xgmx-762m-r89c/GHSA-xgmx-762m-r89c.json index ab4511d8a2d..3b3bb2435da 100644 --- a/advisories/unreviewed/2022/04/GHSA-xgmx-762m-r89c/GHSA-xgmx-762m-r89c.json +++ b/advisories/unreviewed/2022/04/GHSA-xgmx-762m-r89c/GHSA-xgmx-762m-r89c.json @@ -7,12 +7,8 @@ "CVE-2004-2718" ], "details": "PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database passwords via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xj5p-xp2f-36x3/GHSA-xj5p-xp2f-36x3.json b/advisories/unreviewed/2022/04/GHSA-xj5p-xp2f-36x3/GHSA-xj5p-xp2f-36x3.json index 6696e9ca118..a2e79125165 100644 --- a/advisories/unreviewed/2022/04/GHSA-xj5p-xp2f-36x3/GHSA-xj5p-xp2f-36x3.json +++ b/advisories/unreviewed/2022/04/GHSA-xj5p-xp2f-36x3/GHSA-xj5p-xp2f-36x3.json @@ -7,12 +7,8 @@ "CVE-2004-2653" ], "details": "Unspecified vulnerability in PD9 Software MegaBBS 2.0 and 2.1 allows attackers to gain privileges via unknown vectors involving (1) admin/userlevelmembers-edit.asp and (2) admin/edit-groups.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xjvg-3p2h-qwh5/GHSA-xjvg-3p2h-qwh5.json b/advisories/unreviewed/2022/04/GHSA-xjvg-3p2h-qwh5/GHSA-xjvg-3p2h-qwh5.json index d6a066896f3..0a8396b2915 100644 --- a/advisories/unreviewed/2022/04/GHSA-xjvg-3p2h-qwh5/GHSA-xjvg-3p2h-qwh5.json +++ b/advisories/unreviewed/2022/04/GHSA-xjvg-3p2h-qwh5/GHSA-xjvg-3p2h-qwh5.json @@ -7,12 +7,8 @@ "CVE-2004-2599" ], "details": "Multiple buffer overflows in Quake II server before R1Q2, as used in multiple products, allow local users to cause a denial of service (application crash) via the server console or rcon.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xpmv-55r3-vww6/GHSA-xpmv-55r3-vww6.json b/advisories/unreviewed/2022/04/GHSA-xpmv-55r3-vww6/GHSA-xpmv-55r3-vww6.json index 736e70746fd..903e5aa0ffb 100644 --- a/advisories/unreviewed/2022/04/GHSA-xpmv-55r3-vww6/GHSA-xpmv-55r3-vww6.json +++ b/advisories/unreviewed/2022/04/GHSA-xpmv-55r3-vww6/GHSA-xpmv-55r3-vww6.json @@ -7,12 +7,8 @@ "CVE-2004-2584" ], "details": "frmAddfolder.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote authenticated users to create a folder that SmarterMail cannot delete or rename via a folder name with a null byte (\"%00\"). NOTE: it is not clear whether this issue poses a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xqff-x4hf-x674/GHSA-xqff-x4hf-x674.json b/advisories/unreviewed/2022/04/GHSA-xqff-x4hf-x674/GHSA-xqff-x4hf-x674.json index df5913a8041..5acdc7230a0 100644 --- a/advisories/unreviewed/2022/04/GHSA-xqff-x4hf-x674/GHSA-xqff-x4hf-x674.json +++ b/advisories/unreviewed/2022/04/GHSA-xqff-x4hf-x674/GHSA-xqff-x4hf-x674.json @@ -7,12 +7,8 @@ "CVE-2004-2598" ], "details": "Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exiting a session without a valid disconnect command, then reconnecting, which prevents a mod from being notified of changes in the client state. NOTE: the impact of this issue will vary depending on which mod is being used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xv6r-hw9g-7g96/GHSA-xv6r-hw9g-7g96.json b/advisories/unreviewed/2022/04/GHSA-xv6r-hw9g-7g96/GHSA-xv6r-hw9g-7g96.json index aadae9104cc..ccdbc5ff85c 100644 --- a/advisories/unreviewed/2022/04/GHSA-xv6r-hw9g-7g96/GHSA-xv6r-hw9g-7g96.json +++ b/advisories/unreviewed/2022/04/GHSA-xv6r-hw9g-7g96/GHSA-xv6r-hw9g-7g96.json @@ -7,12 +7,8 @@ "CVE-2004-2760" ], "details": "sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after a root login attempt with the correct password, but leaves the connection open after an attempt with an incorrect password, which makes it easier for remote attackers to guess the password by observing the connection state, a different vulnerability than CVE-2003-0190. NOTE: it could be argued that in most environments, this does not cross privilege boundaries without requiring leverage of a separate vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xwcj-5r58-c5mv/GHSA-xwcj-5r58-c5mv.json b/advisories/unreviewed/2022/04/GHSA-xwcj-5r58-c5mv/GHSA-xwcj-5r58-c5mv.json index a4772a72c99..50b3454f136 100644 --- a/advisories/unreviewed/2022/04/GHSA-xwcj-5r58-c5mv/GHSA-xwcj-5r58-c5mv.json +++ b/advisories/unreviewed/2022/04/GHSA-xwcj-5r58-c5mv/GHSA-xwcj-5r58-c5mv.json @@ -7,12 +7,8 @@ "CVE-2004-2494" ], "details": "Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or HTML via the erromsg parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xxv2-wv26-x9v9/GHSA-xxv2-wv26-x9v9.json b/advisories/unreviewed/2022/04/GHSA-xxv2-wv26-x9v9/GHSA-xxv2-wv26-x9v9.json index d550770a098..08ef530b4fd 100644 --- a/advisories/unreviewed/2022/04/GHSA-xxv2-wv26-x9v9/GHSA-xxv2-wv26-x9v9.json +++ b/advisories/unreviewed/2022/04/GHSA-xxv2-wv26-x9v9/GHSA-xxv2-wv26-x9v9.json @@ -7,12 +7,8 @@ "CVE-2004-2623" ], "details": "Unknown vulnerability in Rippy the Aggregator before 0.10, when register_globals is enabled, has unknown attack vectors and impact, possibly related to the \"user-controlled filter.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2277-2f9f-59cc/GHSA-2277-2f9f-59cc.json b/advisories/unreviewed/2022/05/GHSA-2277-2f9f-59cc/GHSA-2277-2f9f-59cc.json index a8a6540fd3b..c2754a5d895 100644 --- a/advisories/unreviewed/2022/05/GHSA-2277-2f9f-59cc/GHSA-2277-2f9f-59cc.json +++ b/advisories/unreviewed/2022/05/GHSA-2277-2f9f-59cc/GHSA-2277-2f9f-59cc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-233h-674c-hxmw/GHSA-233h-674c-hxmw.json b/advisories/unreviewed/2022/05/GHSA-233h-674c-hxmw/GHSA-233h-674c-hxmw.json index a07cd146b20..9edf6faad25 100644 --- a/advisories/unreviewed/2022/05/GHSA-233h-674c-hxmw/GHSA-233h-674c-hxmw.json +++ b/advisories/unreviewed/2022/05/GHSA-233h-674c-hxmw/GHSA-233h-674c-hxmw.json @@ -7,12 +7,8 @@ "CVE-2020-11684" ], "details": "AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component. This can be exploited to disclose these keys and subsequently encrypt and sign the next boot stage (such as the bootloader).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-24q8-rjjm-c7vv/GHSA-24q8-rjjm-c7vv.json b/advisories/unreviewed/2022/05/GHSA-24q8-rjjm-c7vv/GHSA-24q8-rjjm-c7vv.json index 3b246150e1a..709ff4ec4f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-24q8-rjjm-c7vv/GHSA-24q8-rjjm-c7vv.json +++ b/advisories/unreviewed/2022/05/GHSA-24q8-rjjm-c7vv/GHSA-24q8-rjjm-c7vv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-289p-hp9m-rp88/GHSA-289p-hp9m-rp88.json b/advisories/unreviewed/2022/05/GHSA-289p-hp9m-rp88/GHSA-289p-hp9m-rp88.json index a4ce715a950..07ded2cbe12 100644 --- a/advisories/unreviewed/2022/05/GHSA-289p-hp9m-rp88/GHSA-289p-hp9m-rp88.json +++ b/advisories/unreviewed/2022/05/GHSA-289p-hp9m-rp88/GHSA-289p-hp9m-rp88.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2c53-hhhc-ffc7/GHSA-2c53-hhhc-ffc7.json b/advisories/unreviewed/2022/05/GHSA-2c53-hhhc-ffc7/GHSA-2c53-hhhc-ffc7.json index 376da8e49c7..3918dcc262a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c53-hhhc-ffc7/GHSA-2c53-hhhc-ffc7.json +++ b/advisories/unreviewed/2022/05/GHSA-2c53-hhhc-ffc7/GHSA-2c53-hhhc-ffc7.json @@ -7,12 +7,8 @@ "CVE-2020-0345" ], "details": "In DocumentsUI, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-144286721", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2f6p-fvp2-42p6/GHSA-2f6p-fvp2-42p6.json b/advisories/unreviewed/2022/05/GHSA-2f6p-fvp2-42p6/GHSA-2f6p-fvp2-42p6.json index 461eb62505e..3a6e84eb445 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f6p-fvp2-42p6/GHSA-2f6p-fvp2-42p6.json +++ b/advisories/unreviewed/2022/05/GHSA-2f6p-fvp2-42p6/GHSA-2f6p-fvp2-42p6.json @@ -7,12 +7,8 @@ "CVE-2020-24355" ], "details": "Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows regular and other users to create new users with elevated privileges. This is done by changing \"FirstIndex\" field in JSON that is POST-ed during account creation. Similar may also be possible with account deletion.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2fmg-qfp6-p727/GHSA-2fmg-qfp6-p727.json b/advisories/unreviewed/2022/05/GHSA-2fmg-qfp6-p727/GHSA-2fmg-qfp6-p727.json index 0c08c9c5fb8..79faaa9c51e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fmg-qfp6-p727/GHSA-2fmg-qfp6-p727.json +++ b/advisories/unreviewed/2022/05/GHSA-2fmg-qfp6-p727/GHSA-2fmg-qfp6-p727.json @@ -7,12 +7,8 @@ "CVE-2020-24963" ], "details": "An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2gcq-qrr4-wc8f/GHSA-2gcq-qrr4-wc8f.json b/advisories/unreviewed/2022/05/GHSA-2gcq-qrr4-wc8f/GHSA-2gcq-qrr4-wc8f.json index 061141018b8..db630821412 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gcq-qrr4-wc8f/GHSA-2gcq-qrr4-wc8f.json +++ b/advisories/unreviewed/2022/05/GHSA-2gcq-qrr4-wc8f/GHSA-2gcq-qrr4-wc8f.json @@ -7,12 +7,8 @@ "CVE-2020-6320" ], "details": "SAP Marketing (Servlet), version-130,140,150, allows an authenticated attacker to invoke certain functions that are restricted. Limited knowledge of payload is required for an attacker to exploit the vulnerability and perform tasks related to contact and interaction data which impacts Confidentiality and Integrity of data in the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2jc5-w7hj-r4r8/GHSA-2jc5-w7hj-r4r8.json b/advisories/unreviewed/2022/05/GHSA-2jc5-w7hj-r4r8/GHSA-2jc5-w7hj-r4r8.json index cf27d95d793..999b2754513 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jc5-w7hj-r4r8/GHSA-2jc5-w7hj-r4r8.json +++ b/advisories/unreviewed/2022/05/GHSA-2jc5-w7hj-r4r8/GHSA-2jc5-w7hj-r4r8.json @@ -7,12 +7,8 @@ "CVE-2020-25379" ], "details": "Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 fails to sanitize input from the 'Manufacturer[]' parameter which allows an authenticated attacker to inject a malicious SQL query.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2jhm-h3h6-8pq5/GHSA-2jhm-h3h6-8pq5.json b/advisories/unreviewed/2022/05/GHSA-2jhm-h3h6-8pq5/GHSA-2jhm-h3h6-8pq5.json index 93af92f88d9..afc4ae70c57 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jhm-h3h6-8pq5/GHSA-2jhm-h3h6-8pq5.json +++ b/advisories/unreviewed/2022/05/GHSA-2jhm-h3h6-8pq5/GHSA-2jhm-h3h6-8pq5.json @@ -7,12 +7,8 @@ "CVE-2020-4698" ], "details": "IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186841.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2mfc-2chj-fv4h/GHSA-2mfc-2chj-fv4h.json b/advisories/unreviewed/2022/05/GHSA-2mfc-2chj-fv4h/GHSA-2mfc-2chj-fv4h.json index f930ef1db42..f550bd93dba 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mfc-2chj-fv4h/GHSA-2mfc-2chj-fv4h.json +++ b/advisories/unreviewed/2022/05/GHSA-2mfc-2chj-fv4h/GHSA-2mfc-2chj-fv4h.json @@ -7,12 +7,8 @@ "CVE-2020-6344" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2ppg-66j5-9h8g/GHSA-2ppg-66j5-9h8g.json b/advisories/unreviewed/2022/05/GHSA-2ppg-66j5-9h8g/GHSA-2ppg-66j5-9h8g.json index 4862ee86804..8d1a594ab66 100644 --- a/advisories/unreviewed/2022/05/GHSA-2ppg-66j5-9h8g/GHSA-2ppg-66j5-9h8g.json +++ b/advisories/unreviewed/2022/05/GHSA-2ppg-66j5-9h8g/GHSA-2ppg-66j5-9h8g.json @@ -7,12 +7,8 @@ "CVE-2020-25291" ], "details": "GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Word document. This is related to QBrush::setMatrix in gui/painting/qbrush.cpp in Qt 4.x.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2qfq-4hw9-7rpg/GHSA-2qfq-4hw9-7rpg.json b/advisories/unreviewed/2022/05/GHSA-2qfq-4hw9-7rpg/GHSA-2qfq-4hw9-7rpg.json index 0026f4ad243..50c6f815dab 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qfq-4hw9-7rpg/GHSA-2qfq-4hw9-7rpg.json +++ b/advisories/unreviewed/2022/05/GHSA-2qfq-4hw9-7rpg/GHSA-2qfq-4hw9-7rpg.json @@ -7,12 +7,8 @@ "CVE-2019-14756" ], "details": "An issue was discovered in KaiOS 1.0, 2.5, and 2.5.12.5. The pre-installed Email application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a specially crafted email to the victim that will inject HTML into the email application's UI as soon as the email is opened. At a bare minimum, this allows an attacker to take control over the Email application's UI (e.g., display a malicious prompt to the user asking them to re-enter their email credentials) and also allows an attacker to abuse any of the privileges available to the mobile application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2qp6-q6vf-5x4c/GHSA-2qp6-q6vf-5x4c.json b/advisories/unreviewed/2022/05/GHSA-2qp6-q6vf-5x4c/GHSA-2qp6-q6vf-5x4c.json index b4373b4ba52..bb6cab15394 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qp6-q6vf-5x4c/GHSA-2qp6-q6vf-5x4c.json +++ b/advisories/unreviewed/2022/05/GHSA-2qp6-q6vf-5x4c/GHSA-2qp6-q6vf-5x4c.json @@ -7,12 +7,8 @@ "CVE-2020-25045" ], "details": "Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges in the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2rp2-rw4v-352c/GHSA-2rp2-rw4v-352c.json b/advisories/unreviewed/2022/05/GHSA-2rp2-rw4v-352c/GHSA-2rp2-rw4v-352c.json index 77add8bb7a4..e826d4b3a73 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rp2-rw4v-352c/GHSA-2rp2-rw4v-352c.json +++ b/advisories/unreviewed/2022/05/GHSA-2rp2-rw4v-352c/GHSA-2rp2-rw4v-352c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2vph-2j96-4ghq/GHSA-2vph-2j96-4ghq.json b/advisories/unreviewed/2022/05/GHSA-2vph-2j96-4ghq/GHSA-2vph-2j96-4ghq.json index df76fc7aeeb..96c4c941bdf 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vph-2j96-4ghq/GHSA-2vph-2j96-4ghq.json +++ b/advisories/unreviewed/2022/05/GHSA-2vph-2j96-4ghq/GHSA-2vph-2j96-4ghq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2x7q-r588-836j/GHSA-2x7q-r588-836j.json b/advisories/unreviewed/2022/05/GHSA-2x7q-r588-836j/GHSA-2x7q-r588-836j.json index dd1cb0680f5..30d0198ae64 100644 --- a/advisories/unreviewed/2022/05/GHSA-2x7q-r588-836j/GHSA-2x7q-r588-836j.json +++ b/advisories/unreviewed/2022/05/GHSA-2x7q-r588-836j/GHSA-2x7q-r588-836j.json @@ -7,12 +7,8 @@ "CVE-2020-6332" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated HPGL file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xw2-mmrg-qmgq/GHSA-2xw2-mmrg-qmgq.json b/advisories/unreviewed/2022/05/GHSA-2xw2-mmrg-qmgq/GHSA-2xw2-mmrg-qmgq.json index 8538363fe88..8b14324f564 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xw2-mmrg-qmgq/GHSA-2xw2-mmrg-qmgq.json +++ b/advisories/unreviewed/2022/05/GHSA-2xw2-mmrg-qmgq/GHSA-2xw2-mmrg-qmgq.json @@ -7,12 +7,8 @@ "CVE-2020-6359" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PLT file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-33mp-cm7f-r29g/GHSA-33mp-cm7f-r29g.json b/advisories/unreviewed/2022/05/GHSA-33mp-cm7f-r29g/GHSA-33mp-cm7f-r29g.json index 8b3881c0bb5..dc358967cd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-33mp-cm7f-r29g/GHSA-33mp-cm7f-r29g.json +++ b/advisories/unreviewed/2022/05/GHSA-33mp-cm7f-r29g/GHSA-33mp-cm7f-r29g.json @@ -7,12 +7,8 @@ "CVE-2020-6349" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-33qq-wfvm-3749/GHSA-33qq-wfvm-3749.json b/advisories/unreviewed/2022/05/GHSA-33qq-wfvm-3749/GHSA-33qq-wfvm-3749.json index 18015d1e43b..0425fe907c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-33qq-wfvm-3749/GHSA-33qq-wfvm-3749.json +++ b/advisories/unreviewed/2022/05/GHSA-33qq-wfvm-3749/GHSA-33qq-wfvm-3749.json @@ -7,12 +7,8 @@ "CVE-2020-3987" ], "details": "VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMR STRETCHDIBITS parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak memory from TPView process running on the system where Workstation or Horizon Client for Windows is installed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-347c-p8v4-7hp9/GHSA-347c-p8v4-7hp9.json b/advisories/unreviewed/2022/05/GHSA-347c-p8v4-7hp9/GHSA-347c-p8v4-7hp9.json index 4c90b1f449f..88d0225ba98 100644 --- a/advisories/unreviewed/2022/05/GHSA-347c-p8v4-7hp9/GHSA-347c-p8v4-7hp9.json +++ b/advisories/unreviewed/2022/05/GHSA-347c-p8v4-7hp9/GHSA-347c-p8v4-7hp9.json @@ -7,12 +7,8 @@ "CVE-2020-6346" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated BMP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-356r-hh49-wcj9/GHSA-356r-hh49-wcj9.json b/advisories/unreviewed/2022/05/GHSA-356r-hh49-wcj9/GHSA-356r-hh49-wcj9.json index 6206393c805..ba1d18156a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-356r-hh49-wcj9/GHSA-356r-hh49-wcj9.json +++ b/advisories/unreviewed/2022/05/GHSA-356r-hh49-wcj9/GHSA-356r-hh49-wcj9.json @@ -7,12 +7,8 @@ "CVE-2020-0354" ], "details": "In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-143604331", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3584-m2p9-p3w8/GHSA-3584-m2p9-p3w8.json b/advisories/unreviewed/2022/05/GHSA-3584-m2p9-p3w8/GHSA-3584-m2p9-p3w8.json index d4b76ea2e69..b6e88340108 100644 --- a/advisories/unreviewed/2022/05/GHSA-3584-m2p9-p3w8/GHSA-3584-m2p9-p3w8.json +++ b/advisories/unreviewed/2022/05/GHSA-3584-m2p9-p3w8/GHSA-3584-m2p9-p3w8.json @@ -7,12 +7,8 @@ "CVE-2019-14056" ], "details": "u'Possible integer overflow in API due to lack of check on large oid range count in cert extension field' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Kamorta, MDM9150, MDM9205, MDM9607, MDM9650, Nicobar, QCS404, QCS405, QCS605, QCS610, Rennell, SA6155P, SC7180, SC8180X, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX55, SM6150, SM7150, SM8150, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-368p-hj7r-f6v7/GHSA-368p-hj7r-f6v7.json b/advisories/unreviewed/2022/05/GHSA-368p-hj7r-f6v7/GHSA-368p-hj7r-f6v7.json index 8e749d07f81..cb30eb068a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-368p-hj7r-f6v7/GHSA-368p-hj7r-f6v7.json +++ b/advisories/unreviewed/2022/05/GHSA-368p-hj7r-f6v7/GHSA-368p-hj7r-f6v7.json @@ -7,12 +7,8 @@ "CVE-2020-10229" ], "details": "A CSRF issue in vtecrm vtenext 19 CE allows attackers to carry out unwanted actions on an administrator's behalf, such as uploading files, adding users, and deleting accounts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-374g-65fj-w32x/GHSA-374g-65fj-w32x.json b/advisories/unreviewed/2022/05/GHSA-374g-65fj-w32x/GHSA-374g-65fj-w32x.json index ff5fc46f88f..b0d0d971276 100644 --- a/advisories/unreviewed/2022/05/GHSA-374g-65fj-w32x/GHSA-374g-65fj-w32x.json +++ b/advisories/unreviewed/2022/05/GHSA-374g-65fj-w32x/GHSA-374g-65fj-w32x.json @@ -7,12 +7,8 @@ "CVE-2020-11158" ], "details": "u'Null pointer dereference in HP OfficeJet Pro 8210 jbig2 filter due to lack of check of PDF font array leads to denial of service' in IPS PDF releases prior to IPS System 2020.2", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-38rq-33wv-8xmv/GHSA-38rq-33wv-8xmv.json b/advisories/unreviewed/2022/05/GHSA-38rq-33wv-8xmv/GHSA-38rq-33wv-8xmv.json index a10e777eb99..eed1c4ba99f 100644 --- a/advisories/unreviewed/2022/05/GHSA-38rq-33wv-8xmv/GHSA-38rq-33wv-8xmv.json +++ b/advisories/unreviewed/2022/05/GHSA-38rq-33wv-8xmv/GHSA-38rq-33wv-8xmv.json @@ -7,12 +7,8 @@ "CVE-2020-25283" ], "details": "An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. BT manager allows attackers to bypass intended access restrictions on a certain mode. The LG ID is LVE-SMP-200021 (September 2020).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-38w5-3vjp-rwhg/GHSA-38w5-3vjp-rwhg.json b/advisories/unreviewed/2022/05/GHSA-38w5-3vjp-rwhg/GHSA-38w5-3vjp-rwhg.json index 7335b8be188..470094551db 100644 --- a/advisories/unreviewed/2022/05/GHSA-38w5-3vjp-rwhg/GHSA-38w5-3vjp-rwhg.json +++ b/advisories/unreviewed/2022/05/GHSA-38w5-3vjp-rwhg/GHSA-38w5-3vjp-rwhg.json @@ -7,12 +7,8 @@ "CVE-2020-6354" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated SKP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3997-6wvq-mg36/GHSA-3997-6wvq-mg36.json b/advisories/unreviewed/2022/05/GHSA-3997-6wvq-mg36/GHSA-3997-6wvq-mg36.json index 062f35da5b8..7aa02bc7739 100644 --- a/advisories/unreviewed/2022/05/GHSA-3997-6wvq-mg36/GHSA-3997-6wvq-mg36.json +++ b/advisories/unreviewed/2022/05/GHSA-3997-6wvq-mg36/GHSA-3997-6wvq-mg36.json @@ -7,12 +7,8 @@ "CVE-2020-7319" ], "details": "Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to an unintended file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-39r5-v68g-9x33/GHSA-39r5-v68g-9x33.json b/advisories/unreviewed/2022/05/GHSA-39r5-v68g-9x33/GHSA-39r5-v68g-9x33.json index 32a82197f70..992980e524f 100644 --- a/advisories/unreviewed/2022/05/GHSA-39r5-v68g-9x33/GHSA-39r5-v68g-9x33.json +++ b/advisories/unreviewed/2022/05/GHSA-39r5-v68g-9x33/GHSA-39r5-v68g-9x33.json @@ -7,12 +7,8 @@ "CVE-2020-6874" ], "details": "A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use this vulnerability for account credential enumeration attack or brute-force attack for password guessing. This affects: ZXIPTV, ZXIPTV-WEB-PV5.09.08.04.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-39rh-q4pp-qc6p/GHSA-39rh-q4pp-qc6p.json b/advisories/unreviewed/2022/05/GHSA-39rh-q4pp-qc6p/GHSA-39rh-q4pp-qc6p.json index 2c78f788722..ac2bf6ff11b 100644 --- a/advisories/unreviewed/2022/05/GHSA-39rh-q4pp-qc6p/GHSA-39rh-q4pp-qc6p.json +++ b/advisories/unreviewed/2022/05/GHSA-39rh-q4pp-qc6p/GHSA-39rh-q4pp-qc6p.json @@ -7,12 +7,8 @@ "CVE-2020-6329" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated SKP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3c6j-x3h2-c2j2/GHSA-3c6j-x3h2-c2j2.json b/advisories/unreviewed/2022/05/GHSA-3c6j-x3h2-c2j2/GHSA-3c6j-x3h2-c2j2.json index 3d07e425ff9..fb7509c7942 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c6j-x3h2-c2j2/GHSA-3c6j-x3h2-c2j2.json +++ b/advisories/unreviewed/2022/05/GHSA-3c6j-x3h2-c2j2/GHSA-3c6j-x3h2-c2j2.json @@ -7,12 +7,8 @@ "CVE-2019-20918" ], "details": "An issue was discovered in InspIRCd 3 before 3.1.0. The silence module contains a use after free vulnerability. This vulnerability can be used for remote crashing of an InspIRCd server by any user able to fully connect to a server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3f7r-vf78-cvh3/GHSA-3f7r-vf78-cvh3.json b/advisories/unreviewed/2022/05/GHSA-3f7r-vf78-cvh3/GHSA-3f7r-vf78-cvh3.json index 2a09214bde1..3a7915b1c89 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f7r-vf78-cvh3/GHSA-3f7r-vf78-cvh3.json +++ b/advisories/unreviewed/2022/05/GHSA-3f7r-vf78-cvh3/GHSA-3f7r-vf78-cvh3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3hh4-vmx3-9xp9/GHSA-3hh4-vmx3-9xp9.json b/advisories/unreviewed/2022/05/GHSA-3hh4-vmx3-9xp9/GHSA-3hh4-vmx3-9xp9.json index 65406b682fd..8116382e3db 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hh4-vmx3-9xp9/GHSA-3hh4-vmx3-9xp9.json +++ b/advisories/unreviewed/2022/05/GHSA-3hh4-vmx3-9xp9/GHSA-3hh4-vmx3-9xp9.json @@ -7,12 +7,8 @@ "CVE-2020-0316" ], "details": "In Telephony, there is a missing permission check. This could lead to local information disclosure of radio data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154934919", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mwh-xgcp-8q55/GHSA-3mwh-xgcp-8q55.json b/advisories/unreviewed/2022/05/GHSA-3mwh-xgcp-8q55/GHSA-3mwh-xgcp-8q55.json index d45416d915e..977e832ce89 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mwh-xgcp-8q55/GHSA-3mwh-xgcp-8q55.json +++ b/advisories/unreviewed/2022/05/GHSA-3mwh-xgcp-8q55/GHSA-3mwh-xgcp-8q55.json @@ -7,12 +7,8 @@ "CVE-2020-24195" ], "details": "An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated administrator to conduct remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3rfj-rp8x-285j/GHSA-3rfj-rp8x-285j.json b/advisories/unreviewed/2022/05/GHSA-3rfj-rp8x-285j/GHSA-3rfj-rp8x-285j.json index f04702b837a..0a9633d69a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rfj-rp8x-285j/GHSA-3rfj-rp8x-285j.json +++ b/advisories/unreviewed/2022/05/GHSA-3rfj-rp8x-285j/GHSA-3rfj-rp8x-285j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3rpg-jfvw-x748/GHSA-3rpg-jfvw-x748.json b/advisories/unreviewed/2022/05/GHSA-3rpg-jfvw-x748/GHSA-3rpg-jfvw-x748.json index 2cf07370277..77df117d486 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rpg-jfvw-x748/GHSA-3rpg-jfvw-x748.json +++ b/advisories/unreviewed/2022/05/GHSA-3rpg-jfvw-x748/GHSA-3rpg-jfvw-x748.json @@ -7,12 +7,8 @@ "CVE-2020-13301" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a stored XSS on the standalone vulnerability page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3v57-962h-6rcp/GHSA-3v57-962h-6rcp.json b/advisories/unreviewed/2022/05/GHSA-3v57-962h-6rcp/GHSA-3v57-962h-6rcp.json index 2bf5f87acb3..aa4278c1da0 100644 --- a/advisories/unreviewed/2022/05/GHSA-3v57-962h-6rcp/GHSA-3v57-962h-6rcp.json +++ b/advisories/unreviewed/2022/05/GHSA-3v57-962h-6rcp/GHSA-3v57-962h-6rcp.json @@ -7,12 +7,8 @@ "CVE-2020-20406" ], "details": "A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 and earlier versions. It is caused by inadequate filtering on the link custom attributes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3x74-wgfj-fp94/GHSA-3x74-wgfj-fp94.json b/advisories/unreviewed/2022/05/GHSA-3x74-wgfj-fp94/GHSA-3x74-wgfj-fp94.json index a257135d138..f43037aa761 100644 --- a/advisories/unreviewed/2022/05/GHSA-3x74-wgfj-fp94/GHSA-3x74-wgfj-fp94.json +++ b/advisories/unreviewed/2022/05/GHSA-3x74-wgfj-fp94/GHSA-3x74-wgfj-fp94.json @@ -7,12 +7,8 @@ "CVE-2020-25282" ], "details": "An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Integrated Circuit Card) allows attackers to bypass intended access restrictions on property values. The LG ID is LVE-SMP-200020 (September 2020).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-424j-x9c2-7hg5/GHSA-424j-x9c2-7hg5.json b/advisories/unreviewed/2022/05/GHSA-424j-x9c2-7hg5/GHSA-424j-x9c2-7hg5.json index 9e53ab70d93..4bd7bedc64a 100644 --- a/advisories/unreviewed/2022/05/GHSA-424j-x9c2-7hg5/GHSA-424j-x9c2-7hg5.json +++ b/advisories/unreviewed/2022/05/GHSA-424j-x9c2-7hg5/GHSA-424j-x9c2-7hg5.json @@ -7,12 +7,8 @@ "CVE-2020-0245" ], "details": "In DecodeFrameCombinedMode of combined_decode.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-152496149", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-43wv-9cr7-p3pg/GHSA-43wv-9cr7-p3pg.json b/advisories/unreviewed/2022/05/GHSA-43wv-9cr7-p3pg/GHSA-43wv-9cr7-p3pg.json index c991c72fcd4..908582b9cb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-43wv-9cr7-p3pg/GHSA-43wv-9cr7-p3pg.json +++ b/advisories/unreviewed/2022/05/GHSA-43wv-9cr7-p3pg/GHSA-43wv-9cr7-p3pg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-483f-26r4-2fvr/GHSA-483f-26r4-2fvr.json b/advisories/unreviewed/2022/05/GHSA-483f-26r4-2fvr/GHSA-483f-26r4-2fvr.json index 2205b2e11bd..af36c5d5db1 100644 --- a/advisories/unreviewed/2022/05/GHSA-483f-26r4-2fvr/GHSA-483f-26r4-2fvr.json +++ b/advisories/unreviewed/2022/05/GHSA-483f-26r4-2fvr/GHSA-483f-26r4-2fvr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4853-rc4g-fhg8/GHSA-4853-rc4g-fhg8.json b/advisories/unreviewed/2022/05/GHSA-4853-rc4g-fhg8/GHSA-4853-rc4g-fhg8.json index 630ab9f3078..ca504870f43 100644 --- a/advisories/unreviewed/2022/05/GHSA-4853-rc4g-fhg8/GHSA-4853-rc4g-fhg8.json +++ b/advisories/unreviewed/2022/05/GHSA-4853-rc4g-fhg8/GHSA-4853-rc4g-fhg8.json @@ -7,12 +7,8 @@ "CVE-2020-3667" ], "details": "u'Buffer Overflow in mic calculation for WPA due to copying data into buffer without validating the length of buffer' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8098, IPQ5018, IPQ6018, IPQ8074, Kamorta, MSM8998, Nicobar, QCA6390, QCA8081, QCS404, QCS405, QCS605, Rennell, SA415M, Saipan, SC7180, SC8180X, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SM8250, SXR1130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4c4v-9xr2-899m/GHSA-4c4v-9xr2-899m.json b/advisories/unreviewed/2022/05/GHSA-4c4v-9xr2-899m/GHSA-4c4v-9xr2-899m.json index f9ddd38f523..26e10e9ce3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c4v-9xr2-899m/GHSA-4c4v-9xr2-899m.json +++ b/advisories/unreviewed/2022/05/GHSA-4c4v-9xr2-899m/GHSA-4c4v-9xr2-899m.json @@ -7,12 +7,8 @@ "CVE-2020-0383" ], "details": "In Parse_ins of eas_mdls.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure in the media extractor process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-150160279", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4cpc-j329-wv69/GHSA-4cpc-j329-wv69.json b/advisories/unreviewed/2022/05/GHSA-4cpc-j329-wv69/GHSA-4cpc-j329-wv69.json index 47a51544a84..66553857be3 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cpc-j329-wv69/GHSA-4cpc-j329-wv69.json +++ b/advisories/unreviewed/2022/05/GHSA-4cpc-j329-wv69/GHSA-4cpc-j329-wv69.json @@ -7,12 +7,8 @@ "CVE-2020-11124" ], "details": "u'Possible use-after-free while accessing diag client map table since list can be reallocated due to exceeding max client limit.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, Nicobar, QCS404, QCS405, QCS610, Rennell, SA6155P, SA8155P, Saipan, SC8180X, SDM660, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4ffh-54c8-m8qq/GHSA-4ffh-54c8-m8qq.json b/advisories/unreviewed/2022/05/GHSA-4ffh-54c8-m8qq/GHSA-4ffh-54c8-m8qq.json index 40f0dbdebc5..add7bcca0fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-4ffh-54c8-m8qq/GHSA-4ffh-54c8-m8qq.json +++ b/advisories/unreviewed/2022/05/GHSA-4ffh-54c8-m8qq/GHSA-4ffh-54c8-m8qq.json @@ -7,12 +7,8 @@ "CVE-2020-17408" ], "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the clpwebmc executable. Due to the improper restriction of XML External Entity (XXE) references, a specially-crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-10801.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4fg3-3f6v-rq8c/GHSA-4fg3-3f6v-rq8c.json b/advisories/unreviewed/2022/05/GHSA-4fg3-3f6v-rq8c/GHSA-4fg3-3f6v-rq8c.json index 9c74698e323..f098356fb8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fg3-3f6v-rq8c/GHSA-4fg3-3f6v-rq8c.json +++ b/advisories/unreviewed/2022/05/GHSA-4fg3-3f6v-rq8c/GHSA-4fg3-3f6v-rq8c.json @@ -7,12 +7,8 @@ "CVE-2020-6336" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4fq4-48p4-4c29/GHSA-4fq4-48p4-4c29.json b/advisories/unreviewed/2022/05/GHSA-4fq4-48p4-4c29/GHSA-4fq4-48p4-4c29.json index 7fa0b98edbd..1a399529233 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fq4-48p4-4c29/GHSA-4fq4-48p4-4c29.json +++ b/advisories/unreviewed/2022/05/GHSA-4fq4-48p4-4c29/GHSA-4fq4-48p4-4c29.json @@ -7,12 +7,8 @@ "CVE-2020-0356" ], "details": "In the Audio HAL, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-143787559", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4ghg-p426-jc5w/GHSA-4ghg-p426-jc5w.json b/advisories/unreviewed/2022/05/GHSA-4ghg-p426-jc5w/GHSA-4ghg-p426-jc5w.json index 0a45cf95b75..3bfb46a1acf 100644 --- a/advisories/unreviewed/2022/05/GHSA-4ghg-p426-jc5w/GHSA-4ghg-p426-jc5w.json +++ b/advisories/unreviewed/2022/05/GHSA-4ghg-p426-jc5w/GHSA-4ghg-p426-jc5w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4gvj-r54v-28c6/GHSA-4gvj-r54v-28c6.json b/advisories/unreviewed/2022/05/GHSA-4gvj-r54v-28c6/GHSA-4gvj-r54v-28c6.json index eea196e957e..427f2cb291b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gvj-r54v-28c6/GHSA-4gvj-r54v-28c6.json +++ b/advisories/unreviewed/2022/05/GHSA-4gvj-r54v-28c6/GHSA-4gvj-r54v-28c6.json @@ -7,12 +7,8 @@ "CVE-2020-0278" ], "details": "There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-160812574", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4p72-53xh-hr8g/GHSA-4p72-53xh-hr8g.json b/advisories/unreviewed/2022/05/GHSA-4p72-53xh-hr8g/GHSA-4p72-53xh-hr8g.json index d362000d6ae..3076e3d9731 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p72-53xh-hr8g/GHSA-4p72-53xh-hr8g.json +++ b/advisories/unreviewed/2022/05/GHSA-4p72-53xh-hr8g/GHSA-4p72-53xh-hr8g.json @@ -7,12 +7,8 @@ "CVE-2020-14021" ], "details": "An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The ASP.net SMS module can be used to read and validate the source code of ASP files. By altering the path, it can be made to read any file on the Operating System, usually with NT AUTHORITY\\SYSTEM privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4r3v-pr3q-qvw9/GHSA-4r3v-pr3q-qvw9.json b/advisories/unreviewed/2022/05/GHSA-4r3v-pr3q-qvw9/GHSA-4r3v-pr3q-qvw9.json index 7048691a00e..0a1d065f907 100644 --- a/advisories/unreviewed/2022/05/GHSA-4r3v-pr3q-qvw9/GHSA-4r3v-pr3q-qvw9.json +++ b/advisories/unreviewed/2022/05/GHSA-4r3v-pr3q-qvw9/GHSA-4r3v-pr3q-qvw9.json @@ -7,12 +7,8 @@ "CVE-2020-3980" ], "details": "VMware Fusion (11.x) contains a privilege escalation vulnerability due to the way it allows configuring the system wide path. An attacker with normal user privileges may exploit this issue to trick an admin user into executing malicious code on the system where Fusion is installed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4rmw-pmhj-w226/GHSA-4rmw-pmhj-w226.json b/advisories/unreviewed/2022/05/GHSA-4rmw-pmhj-w226/GHSA-4rmw-pmhj-w226.json index 7bbec6c99f9..a9084d42858 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rmw-pmhj-w226/GHSA-4rmw-pmhj-w226.json +++ b/advisories/unreviewed/2022/05/GHSA-4rmw-pmhj-w226/GHSA-4rmw-pmhj-w226.json @@ -7,12 +7,8 @@ "CVE-2020-13307" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current user sessions when 2 factor authentication was activated allowing a malicious user to maintain their access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vw6-7m58-5hqv/GHSA-4vw6-7m58-5hqv.json b/advisories/unreviewed/2022/05/GHSA-4vw6-7m58-5hqv/GHSA-4vw6-7m58-5hqv.json index 4eeb98e7548..3b85bc14905 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vw6-7m58-5hqv/GHSA-4vw6-7m58-5hqv.json +++ b/advisories/unreviewed/2022/05/GHSA-4vw6-7m58-5hqv/GHSA-4vw6-7m58-5hqv.json @@ -7,12 +7,8 @@ "CVE-2020-3679" ], "details": "u'During execution after Address Space Layout Randomization is turned on for QTEE, part of code is still mapped at known address including code segments' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Bitra, Kamorta, Nicobar, QCS404, QCS610, Rennell, SA6155P, SA8155P, Saipan, SC7180, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4xcq-53qf-r7r5/GHSA-4xcq-53qf-r7r5.json b/advisories/unreviewed/2022/05/GHSA-4xcq-53qf-r7r5/GHSA-4xcq-53qf-r7r5.json index 95bae117983..29df2c7ef30 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xcq-53qf-r7r5/GHSA-4xcq-53qf-r7r5.json +++ b/advisories/unreviewed/2022/05/GHSA-4xcq-53qf-r7r5/GHSA-4xcq-53qf-r7r5.json @@ -7,12 +7,8 @@ "CVE-2020-21732" ], "details": "Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). An attacker can add JavaScript code to the filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4xqv-wh6m-q95v/GHSA-4xqv-wh6m-q95v.json b/advisories/unreviewed/2022/05/GHSA-4xqv-wh6m-q95v/GHSA-4xqv-wh6m-q95v.json index f7516a6680c..53d1f6c2e4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xqv-wh6m-q95v/GHSA-4xqv-wh6m-q95v.json +++ b/advisories/unreviewed/2022/05/GHSA-4xqv-wh6m-q95v/GHSA-4xqv-wh6m-q95v.json @@ -7,12 +7,8 @@ "CVE-2020-6313" ], "details": "SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user controlled inputs, which allows an authenticated User with special roles to store malicious content, that when accessed by a victim, can perform malicious actions by executing JavaScript, leading to Stored Cross-Site Scripting.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-52qc-8hxh-757m/GHSA-52qc-8hxh-757m.json b/advisories/unreviewed/2022/05/GHSA-52qc-8hxh-757m/GHSA-52qc-8hxh-757m.json index ce4bdc65efc..c3c73171436 100644 --- a/advisories/unreviewed/2022/05/GHSA-52qc-8hxh-757m/GHSA-52qc-8hxh-757m.json +++ b/advisories/unreviewed/2022/05/GHSA-52qc-8hxh-757m/GHSA-52qc-8hxh-757m.json @@ -7,12 +7,8 @@ "CVE-2020-3624" ], "details": "u'A potential buffer overflow exists due to integer overflow when parsing handler options due to wrong data type usage in operation' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Kamorta, MDM9150, MDM9205, MDM9206, MDM9207C, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCM2150, QCN7605, QCS605, QCS610, QM215, Rennell, SA415M, SA515M, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-559w-3846-g7jq/GHSA-559w-3846-g7jq.json b/advisories/unreviewed/2022/05/GHSA-559w-3846-g7jq/GHSA-559w-3846-g7jq.json index 98f3a5136ab..9b0e3ee6082 100644 --- a/advisories/unreviewed/2022/05/GHSA-559w-3846-g7jq/GHSA-559w-3846-g7jq.json +++ b/advisories/unreviewed/2022/05/GHSA-559w-3846-g7jq/GHSA-559w-3846-g7jq.json @@ -7,12 +7,8 @@ "CVE-2020-7532" ], "details": "A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitrary code execution when an attacker builds a custom .SDB file containing a malicious serialized buffer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-55c9-4ccx-936v/GHSA-55c9-4ccx-936v.json b/advisories/unreviewed/2022/05/GHSA-55c9-4ccx-936v/GHSA-55c9-4ccx-936v.json index 24b27466078..e30cb7dbdd3 100644 --- a/advisories/unreviewed/2022/05/GHSA-55c9-4ccx-936v/GHSA-55c9-4ccx-936v.json +++ b/advisories/unreviewed/2022/05/GHSA-55c9-4ccx-936v/GHSA-55c9-4ccx-936v.json @@ -7,12 +7,8 @@ "CVE-2020-0266" ], "details": "In factory reset protection, there is a possible FRP bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-111086459", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-585q-pfmf-wx3m/GHSA-585q-pfmf-wx3m.json b/advisories/unreviewed/2022/05/GHSA-585q-pfmf-wx3m/GHSA-585q-pfmf-wx3m.json index fe586cda995..9f6be661906 100644 --- a/advisories/unreviewed/2022/05/GHSA-585q-pfmf-wx3m/GHSA-585q-pfmf-wx3m.json +++ b/advisories/unreviewed/2022/05/GHSA-585q-pfmf-wx3m/GHSA-585q-pfmf-wx3m.json @@ -7,12 +7,8 @@ "CVE-2020-23833" ], "details": "Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary code on the hosting webserver via a malicious index.php POST request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-586v-g7r5-mhgp/GHSA-586v-g7r5-mhgp.json b/advisories/unreviewed/2022/05/GHSA-586v-g7r5-mhgp/GHSA-586v-g7r5-mhgp.json index 240fa30cade..71fe8b69c95 100644 --- a/advisories/unreviewed/2022/05/GHSA-586v-g7r5-mhgp/GHSA-586v-g7r5-mhgp.json +++ b/advisories/unreviewed/2022/05/GHSA-586v-g7r5-mhgp/GHSA-586v-g7r5-mhgp.json @@ -7,12 +7,8 @@ "CVE-2020-11991" ], "details": "When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5f3v-3wp6-f5wm/GHSA-5f3v-3wp6-f5wm.json b/advisories/unreviewed/2022/05/GHSA-5f3v-3wp6-f5wm/GHSA-5f3v-3wp6-f5wm.json index 70ecbe5baa9..56bc04fdcde 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f3v-3wp6-f5wm/GHSA-5f3v-3wp6-f5wm.json +++ b/advisories/unreviewed/2022/05/GHSA-5f3v-3wp6-f5wm/GHSA-5f3v-3wp6-f5wm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5fm5-f5m7-88f4/GHSA-5fm5-f5m7-88f4.json b/advisories/unreviewed/2022/05/GHSA-5fm5-f5m7-88f4/GHSA-5fm5-f5m7-88f4.json index 39d84c1caeb..27912006f32 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fm5-f5m7-88f4/GHSA-5fm5-f5m7-88f4.json +++ b/advisories/unreviewed/2022/05/GHSA-5fm5-f5m7-88f4/GHSA-5fm5-f5m7-88f4.json @@ -7,12 +7,8 @@ "CVE-2020-15790" ], "details": "A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). If configured in an insecure manner, the web server might be susceptible to a directory listing attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5g3m-ghqj-8gwf/GHSA-5g3m-ghqj-8gwf.json b/advisories/unreviewed/2022/05/GHSA-5g3m-ghqj-8gwf/GHSA-5g3m-ghqj-8gwf.json index e346bdcea15..e77511c3595 100644 --- a/advisories/unreviewed/2022/05/GHSA-5g3m-ghqj-8gwf/GHSA-5g3m-ghqj-8gwf.json +++ b/advisories/unreviewed/2022/05/GHSA-5g3m-ghqj-8gwf/GHSA-5g3m-ghqj-8gwf.json @@ -7,12 +7,8 @@ "CVE-2020-13297" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. When 2 factor authentication was enabled for groups, a malicious user could bypass that restriction by sending a specific query to the API endpoint.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5h6f-94qc-p3v7/GHSA-5h6f-94qc-p3v7.json b/advisories/unreviewed/2022/05/GHSA-5h6f-94qc-p3v7/GHSA-5h6f-94qc-p3v7.json index e22277be588..fe13e8d0880 100644 --- a/advisories/unreviewed/2022/05/GHSA-5h6f-94qc-p3v7/GHSA-5h6f-94qc-p3v7.json +++ b/advisories/unreviewed/2022/05/GHSA-5h6f-94qc-p3v7/GHSA-5h6f-94qc-p3v7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5hg9-992p-865c/GHSA-5hg9-992p-865c.json b/advisories/unreviewed/2022/05/GHSA-5hg9-992p-865c/GHSA-5hg9-992p-865c.json index 6904ed03c74..54989df5557 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hg9-992p-865c/GHSA-5hg9-992p-865c.json +++ b/advisories/unreviewed/2022/05/GHSA-5hg9-992p-865c/GHSA-5hg9-992p-865c.json @@ -7,12 +7,8 @@ "CVE-2020-10768" ], "details": "A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, where it can be used to enable indirect branch speculation after it has been disabled. This call incorrectly reports it as being 'force disabled' when it is not and opens the system to Spectre v2 attacks. The highest threat from this vulnerability is to confidentiality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5j4v-g55f-qpxj/GHSA-5j4v-g55f-qpxj.json b/advisories/unreviewed/2022/05/GHSA-5j4v-g55f-qpxj/GHSA-5j4v-g55f-qpxj.json index cfcfe512db8..0af30cf9c8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5j4v-g55f-qpxj/GHSA-5j4v-g55f-qpxj.json +++ b/advisories/unreviewed/2022/05/GHSA-5j4v-g55f-qpxj/GHSA-5j4v-g55f-qpxj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5pxr-wcq7-hjpx/GHSA-5pxr-wcq7-hjpx.json b/advisories/unreviewed/2022/05/GHSA-5pxr-wcq7-hjpx/GHSA-5pxr-wcq7-hjpx.json index bde7cef14a8..e13998aecf7 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pxr-wcq7-hjpx/GHSA-5pxr-wcq7-hjpx.json +++ b/advisories/unreviewed/2022/05/GHSA-5pxr-wcq7-hjpx/GHSA-5pxr-wcq7-hjpx.json @@ -7,12 +7,8 @@ "CVE-2019-14065" ], "details": "u'Pointer double free in HavenSvc due to not setting the pointer to NULL after freeing it' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8098, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9650, MSM8905, MSM8909, MSM8998, Nicobar, QCS404, QCS405, QCS605, QCS610, Rennell, SA515M, SA6155P, SC7180, SC8180X, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5v5x-gcg4-wrf3/GHSA-5v5x-gcg4-wrf3.json b/advisories/unreviewed/2022/05/GHSA-5v5x-gcg4-wrf3/GHSA-5v5x-gcg4-wrf3.json index 55bd0783578..f0a9f0065c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v5x-gcg4-wrf3/GHSA-5v5x-gcg4-wrf3.json +++ b/advisories/unreviewed/2022/05/GHSA-5v5x-gcg4-wrf3/GHSA-5v5x-gcg4-wrf3.json @@ -7,12 +7,8 @@ "CVE-2020-6342" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated U3D file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5vc9-3jgc-ch89/GHSA-5vc9-3jgc-ch89.json b/advisories/unreviewed/2022/05/GHSA-5vc9-3jgc-ch89/GHSA-5vc9-3jgc-ch89.json index fd725adf567..4c096480986 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vc9-3jgc-ch89/GHSA-5vc9-3jgc-ch89.json +++ b/advisories/unreviewed/2022/05/GHSA-5vc9-3jgc-ch89/GHSA-5vc9-3jgc-ch89.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5wcp-726c-4jpf/GHSA-5wcp-726c-4jpf.json b/advisories/unreviewed/2022/05/GHSA-5wcp-726c-4jpf/GHSA-5wcp-726c-4jpf.json index 675b5efc903..a25f027b3f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wcp-726c-4jpf/GHSA-5wcp-726c-4jpf.json +++ b/advisories/unreviewed/2022/05/GHSA-5wcp-726c-4jpf/GHSA-5wcp-726c-4jpf.json @@ -7,12 +7,8 @@ "CVE-2020-6352" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated FBX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5wm3-vq8v-xjjj/GHSA-5wm3-vq8v-xjjj.json b/advisories/unreviewed/2022/05/GHSA-5wm3-vq8v-xjjj/GHSA-5wm3-vq8v-xjjj.json index 2273f89c121..ff81a8ef0c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wm3-vq8v-xjjj/GHSA-5wm3-vq8v-xjjj.json +++ b/advisories/unreviewed/2022/05/GHSA-5wm3-vq8v-xjjj/GHSA-5wm3-vq8v-xjjj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5x6x-jmv8-vh4f/GHSA-5x6x-jmv8-vh4f.json b/advisories/unreviewed/2022/05/GHSA-5x6x-jmv8-vh4f/GHSA-5x6x-jmv8-vh4f.json index 1b7c9f83c17..a35cc2b1ac0 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x6x-jmv8-vh4f/GHSA-5x6x-jmv8-vh4f.json +++ b/advisories/unreviewed/2022/05/GHSA-5x6x-jmv8-vh4f/GHSA-5x6x-jmv8-vh4f.json @@ -7,12 +7,8 @@ "CVE-2020-4344" ], "details": "IBM Tivoli Business Service Manager 6.2.0.0 - 6.2.0.2 IF 1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 178247.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-625f-424x-6j4w/GHSA-625f-424x-6j4w.json b/advisories/unreviewed/2022/05/GHSA-625f-424x-6j4w/GHSA-625f-424x-6j4w.json index ee30e8a13e7..57b09a63b69 100644 --- a/advisories/unreviewed/2022/05/GHSA-625f-424x-6j4w/GHSA-625f-424x-6j4w.json +++ b/advisories/unreviewed/2022/05/GHSA-625f-424x-6j4w/GHSA-625f-424x-6j4w.json @@ -7,12 +7,8 @@ "CVE-2020-15787" ], "details": "A vulnerability has been identified in SIMATIC HMI United Comfort Panels (All versions). Affected devices insufficiently validate authentication attempts as the information given can be truncated to match only a set number of characters versus the whole provided string. This could allow a remote attacker to discover user passwords and obtain access to the Sm@rt Server via a brute-force attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-666m-7m3w-f97c/GHSA-666m-7m3w-f97c.json b/advisories/unreviewed/2022/05/GHSA-666m-7m3w-f97c/GHSA-666m-7m3w-f97c.json index 81bb7a39303..85f0c1519a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-666m-7m3w-f97c/GHSA-666m-7m3w-f97c.json +++ b/advisories/unreviewed/2022/05/GHSA-666m-7m3w-f97c/GHSA-666m-7m3w-f97c.json @@ -7,12 +7,8 @@ "CVE-2020-10050" ], "details": "A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The directory of service executables of the affected application could allow a local attacker to include arbitrary commands that are executed with SYSTEM privileges when the system restarts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6895-cxrm-x3p4/GHSA-6895-cxrm-x3p4.json b/advisories/unreviewed/2022/05/GHSA-6895-cxrm-x3p4/GHSA-6895-cxrm-x3p4.json index 9fda6222bce..bac5de62814 100644 --- a/advisories/unreviewed/2022/05/GHSA-6895-cxrm-x3p4/GHSA-6895-cxrm-x3p4.json +++ b/advisories/unreviewed/2022/05/GHSA-6895-cxrm-x3p4/GHSA-6895-cxrm-x3p4.json @@ -7,12 +7,8 @@ "CVE-2020-2041" ], "details": "An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 allows a remote unauthenticated user to send a specifically crafted request to the device that causes the appweb service to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode. This issue impacts all versions of PAN-OS 8.0, and PAN-OS 8.1 versions earlier than 8.1.16.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6936-rmm6-9pq6/GHSA-6936-rmm6-9pq6.json b/advisories/unreviewed/2022/05/GHSA-6936-rmm6-9pq6/GHSA-6936-rmm6-9pq6.json index 24e17fedbe7..746a1865aed 100644 --- a/advisories/unreviewed/2022/05/GHSA-6936-rmm6-9pq6/GHSA-6936-rmm6-9pq6.json +++ b/advisories/unreviewed/2022/05/GHSA-6936-rmm6-9pq6/GHSA-6936-rmm6-9pq6.json @@ -7,12 +7,8 @@ "CVE-2019-13992" ], "details": "u'Out of bound memory access if stack push and pop operation are performed without doing a bound check on stack top' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Bitra, IPQ6018, IPQ8074, MDM9205, Nicobar, QCA8081, QCN7605, QCS404, QCS405, QCS605, QCS610, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA845, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6c92-g9wf-978j/GHSA-6c92-g9wf-978j.json b/advisories/unreviewed/2022/05/GHSA-6c92-g9wf-978j/GHSA-6c92-g9wf-978j.json index 6732570f453..b8575c21553 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c92-g9wf-978j/GHSA-6c92-g9wf-978j.json +++ b/advisories/unreviewed/2022/05/GHSA-6c92-g9wf-978j/GHSA-6c92-g9wf-978j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6cmx-4cq4-q68g/GHSA-6cmx-4cq4-q68g.json b/advisories/unreviewed/2022/05/GHSA-6cmx-4cq4-q68g/GHSA-6cmx-4cq4-q68g.json index 5f08350b144..79fc1a805ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cmx-4cq4-q68g/GHSA-6cmx-4cq4-q68g.json +++ b/advisories/unreviewed/2022/05/GHSA-6cmx-4cq4-q68g/GHSA-6cmx-4cq4-q68g.json @@ -7,12 +7,8 @@ "CVE-2020-24199" ], "details": "Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6cw8-rf2j-hfqv/GHSA-6cw8-rf2j-hfqv.json b/advisories/unreviewed/2022/05/GHSA-6cw8-rf2j-hfqv/GHSA-6cw8-rf2j-hfqv.json index b6177a2a63d..50e46952a9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cw8-rf2j-hfqv/GHSA-6cw8-rf2j-hfqv.json +++ b/advisories/unreviewed/2022/05/GHSA-6cw8-rf2j-hfqv/GHSA-6cw8-rf2j-hfqv.json @@ -7,12 +7,8 @@ "CVE-2020-6340" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fvc-pc2f-vcp7/GHSA-6fvc-pc2f-vcp7.json b/advisories/unreviewed/2022/05/GHSA-6fvc-pc2f-vcp7/GHSA-6fvc-pc2f-vcp7.json index ee836fb43c5..62c093869cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fvc-pc2f-vcp7/GHSA-6fvc-pc2f-vcp7.json +++ b/advisories/unreviewed/2022/05/GHSA-6fvc-pc2f-vcp7/GHSA-6fvc-pc2f-vcp7.json @@ -7,12 +7,8 @@ "CVE-2020-13308" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 factor authentication inheritance.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6fxx-g64m-phpw/GHSA-6fxx-g64m-phpw.json b/advisories/unreviewed/2022/05/GHSA-6fxx-g64m-phpw/GHSA-6fxx-g64m-phpw.json index 64ea4ce223e..b5a874a5c7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fxx-g64m-phpw/GHSA-6fxx-g64m-phpw.json +++ b/advisories/unreviewed/2022/05/GHSA-6fxx-g64m-phpw/GHSA-6fxx-g64m-phpw.json @@ -7,12 +7,8 @@ "CVE-2020-0262" ], "details": "In WiFi tethering, there is a possible attacker controlled intent due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156353008", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6gvc-rc8p-3485/GHSA-6gvc-rc8p-3485.json b/advisories/unreviewed/2022/05/GHSA-6gvc-rc8p-3485/GHSA-6gvc-rc8p-3485.json index ff07a3e529f..e9809289232 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gvc-rc8p-3485/GHSA-6gvc-rc8p-3485.json +++ b/advisories/unreviewed/2022/05/GHSA-6gvc-rc8p-3485/GHSA-6gvc-rc8p-3485.json @@ -7,12 +7,8 @@ "CVE-2019-14757" ], "details": "An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed Contacts application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a vCard file to the victim that will inject HTML into the Contacts application (assuming the victim chooses to import the file). At a bare minimum, this allows an attacker to take control over the Contacts application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6rjj-pr45-qcv8/GHSA-6rjj-pr45-qcv8.json b/advisories/unreviewed/2022/05/GHSA-6rjj-pr45-qcv8/GHSA-6rjj-pr45-qcv8.json index cc09b303d74..96a3188d004 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rjj-pr45-qcv8/GHSA-6rjj-pr45-qcv8.json +++ b/advisories/unreviewed/2022/05/GHSA-6rjj-pr45-qcv8/GHSA-6rjj-pr45-qcv8.json @@ -7,12 +7,8 @@ "CVE-2020-25375" ], "details": "Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM V1.8.7 is affected by: Cross Site Scripting via the Business Name field, Tax Code field, First Name field, Address field, Town field, Phone field, Mobile field, Place of Birth field, Web Site field, VAT Number field, Last Name field, Fax field, Email field, and Skype field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6x4g-3g6f-c363/GHSA-6x4g-3g6f-c363.json b/advisories/unreviewed/2022/05/GHSA-6x4g-3g6f-c363/GHSA-6x4g-3g6f-c363.json index 16447a0abae..620c1f49419 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x4g-3g6f-c363/GHSA-6x4g-3g6f-c363.json +++ b/advisories/unreviewed/2022/05/GHSA-6x4g-3g6f-c363/GHSA-6x4g-3g6f-c363.json @@ -7,12 +7,8 @@ "CVE-2020-13298" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which resulted in the limited files disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xfq-7wh8-vrjj/GHSA-6xfq-7wh8-vrjj.json b/advisories/unreviewed/2022/05/GHSA-6xfq-7wh8-vrjj/GHSA-6xfq-7wh8-vrjj.json index 95588d79b4c..cf05a83bcaf 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xfq-7wh8-vrjj/GHSA-6xfq-7wh8-vrjj.json +++ b/advisories/unreviewed/2022/05/GHSA-6xfq-7wh8-vrjj/GHSA-6xfq-7wh8-vrjj.json @@ -7,12 +7,8 @@ "CVE-2019-14759" ], "details": "An issue was discovered in KaiOS 1.0, 2.5, and 2.5.1. The pre-installed Radio application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Radio application. At a bare minimum, this allows an attacker to take control over the Radio application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xpw-chm5-x9v3/GHSA-6xpw-chm5-x9v3.json b/advisories/unreviewed/2022/05/GHSA-6xpw-chm5-x9v3/GHSA-6xpw-chm5-x9v3.json index 7deedff166d..52a93335a4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xpw-chm5-x9v3/GHSA-6xpw-chm5-x9v3.json +++ b/advisories/unreviewed/2022/05/GHSA-6xpw-chm5-x9v3/GHSA-6xpw-chm5-x9v3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-729f-wr46-h749/GHSA-729f-wr46-h749.json b/advisories/unreviewed/2022/05/GHSA-729f-wr46-h749/GHSA-729f-wr46-h749.json index 433fc3c06a4..508e0fb0407 100644 --- a/advisories/unreviewed/2022/05/GHSA-729f-wr46-h749/GHSA-729f-wr46-h749.json +++ b/advisories/unreviewed/2022/05/GHSA-729f-wr46-h749/GHSA-729f-wr46-h749.json @@ -7,12 +7,8 @@ "CVE-2019-14758" ], "details": "An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed File Manager application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a file via email to the victim that will inject HTML into the File Manager application (assuming the victim chooses to download the email attachment). At a bare minimum, this allows an attacker to take control over the File Manager application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-72g7-hpv6-j389/GHSA-72g7-hpv6-j389.json b/advisories/unreviewed/2022/05/GHSA-72g7-hpv6-j389/GHSA-72g7-hpv6-j389.json index 1650a5a72f4..d215fe306d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-72g7-hpv6-j389/GHSA-72g7-hpv6-j389.json +++ b/advisories/unreviewed/2022/05/GHSA-72g7-hpv6-j389/GHSA-72g7-hpv6-j389.json @@ -7,12 +7,8 @@ "CVE-2020-0269" ], "details": "In Android Auto Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151645626", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-753f-5cv5-8fxc/GHSA-753f-5cv5-8fxc.json b/advisories/unreviewed/2022/05/GHSA-753f-5cv5-8fxc/GHSA-753f-5cv5-8fxc.json index ab7d534038d..6cd7f60314f 100644 --- a/advisories/unreviewed/2022/05/GHSA-753f-5cv5-8fxc/GHSA-753f-5cv5-8fxc.json +++ b/advisories/unreviewed/2022/05/GHSA-753f-5cv5-8fxc/GHSA-753f-5cv5-8fxc.json @@ -7,12 +7,8 @@ "CVE-2019-4671" ], "details": "IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 171437.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-755m-3mmw-86vc/GHSA-755m-3mmw-86vc.json b/advisories/unreviewed/2022/05/GHSA-755m-3mmw-86vc/GHSA-755m-3mmw-86vc.json index 56ef010d077..9d5161abc00 100644 --- a/advisories/unreviewed/2022/05/GHSA-755m-3mmw-86vc/GHSA-755m-3mmw-86vc.json +++ b/advisories/unreviewed/2022/05/GHSA-755m-3mmw-86vc/GHSA-755m-3mmw-86vc.json @@ -7,12 +7,8 @@ "CVE-2020-5627" ], "details": "Yodobashi App for Android versions 1.8.7 and earlier allows remote attackers to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-76r8-wr7m-q22f/GHSA-76r8-wr7m-q22f.json b/advisories/unreviewed/2022/05/GHSA-76r8-wr7m-q22f/GHSA-76r8-wr7m-q22f.json index 95c1619682f..599b84e8d79 100644 --- a/advisories/unreviewed/2022/05/GHSA-76r8-wr7m-q22f/GHSA-76r8-wr7m-q22f.json +++ b/advisories/unreviewed/2022/05/GHSA-76r8-wr7m-q22f/GHSA-76r8-wr7m-q22f.json @@ -7,12 +7,8 @@ "CVE-2020-24552" ], "details": "Atop Technology industrial 3G/4G gateway contains Command Injection vulnerability. Due to insufficient input validation, the device's web management interface allows attackers to inject specific code and execute system commands without privilege.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-77f6-gh77-3f4f/GHSA-77f6-gh77-3f4f.json b/advisories/unreviewed/2022/05/GHSA-77f6-gh77-3f4f/GHSA-77f6-gh77-3f4f.json index c126c19c045..9cb383a09cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-77f6-gh77-3f4f/GHSA-77f6-gh77-3f4f.json +++ b/advisories/unreviewed/2022/05/GHSA-77f6-gh77-3f4f/GHSA-77f6-gh77-3f4f.json @@ -7,12 +7,8 @@ "CVE-2020-14515" ], "details": "CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license files, including forging a valid license file as if it were a valid license file of an existing vendor. Only CmActLicense update files with CmActLicense Firm Code are affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7cj4-x7wr-qf2p/GHSA-7cj4-x7wr-qf2p.json b/advisories/unreviewed/2022/05/GHSA-7cj4-x7wr-qf2p/GHSA-7cj4-x7wr-qf2p.json index cd5d956e827..3454ca315ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-7cj4-x7wr-qf2p/GHSA-7cj4-x7wr-qf2p.json +++ b/advisories/unreviewed/2022/05/GHSA-7cj4-x7wr-qf2p/GHSA-7cj4-x7wr-qf2p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7frm-g428-7p37/GHSA-7frm-g428-7p37.json b/advisories/unreviewed/2022/05/GHSA-7frm-g428-7p37/GHSA-7frm-g428-7p37.json index aa148a66ecc..e10c2153186 100644 --- a/advisories/unreviewed/2022/05/GHSA-7frm-g428-7p37/GHSA-7frm-g428-7p37.json +++ b/advisories/unreviewed/2022/05/GHSA-7frm-g428-7p37/GHSA-7frm-g428-7p37.json @@ -7,12 +7,8 @@ "CVE-2020-6327" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated 3DM file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7gqf-f3cw-8pvr/GHSA-7gqf-f3cw-8pvr.json b/advisories/unreviewed/2022/05/GHSA-7gqf-f3cw-8pvr/GHSA-7gqf-f3cw-8pvr.json index c7fca7a6a6c..ba4ffa08dbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gqf-f3cw-8pvr/GHSA-7gqf-f3cw-8pvr.json +++ b/advisories/unreviewed/2022/05/GHSA-7gqf-f3cw-8pvr/GHSA-7gqf-f3cw-8pvr.json @@ -7,12 +7,8 @@ "CVE-2020-6361" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE files received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7p3m-596h-f4vx/GHSA-7p3m-596h-f4vx.json b/advisories/unreviewed/2022/05/GHSA-7p3m-596h-f4vx/GHSA-7p3m-596h-f4vx.json index ca6e4ecf9e9..25d1b9a160f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p3m-596h-f4vx/GHSA-7p3m-596h-f4vx.json +++ b/advisories/unreviewed/2022/05/GHSA-7p3m-596h-f4vx/GHSA-7p3m-596h-f4vx.json @@ -7,12 +7,8 @@ "CVE-2020-6347" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated HDR file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7p43-3rw5-j59j/GHSA-7p43-3rw5-j59j.json b/advisories/unreviewed/2022/05/GHSA-7p43-3rw5-j59j/GHSA-7p43-3rw5-j59j.json index f68a70404e9..8f798ca8f68 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p43-3rw5-j59j/GHSA-7p43-3rw5-j59j.json +++ b/advisories/unreviewed/2022/05/GHSA-7p43-3rw5-j59j/GHSA-7p43-3rw5-j59j.json @@ -7,12 +7,8 @@ "CVE-2020-10715" ], "details": "A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x. This flaw allows an attacker to craft a URL and inject arbitrary text onto the error page that appears to be from the OpenShift instance. This attack could potentially convince a user that the inserted text is legitimate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7pp4-qxpv-rc2r/GHSA-7pp4-qxpv-rc2r.json b/advisories/unreviewed/2022/05/GHSA-7pp4-qxpv-rc2r/GHSA-7pp4-qxpv-rc2r.json index 30f08ab34bd..2d5651e5d13 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pp4-qxpv-rc2r/GHSA-7pp4-qxpv-rc2r.json +++ b/advisories/unreviewed/2022/05/GHSA-7pp4-qxpv-rc2r/GHSA-7pp4-qxpv-rc2r.json @@ -7,12 +7,8 @@ "CVE-2020-25044" ], "details": "Kaspersky Virus Removal Tool (KVRT) prior to 15.0.23.0 was vulnerable to arbitrary file corruption that could provide an attacker with the opportunity to eliminate content of any file in the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7pq8-3c67-xq6r/GHSA-7pq8-3c67-xq6r.json b/advisories/unreviewed/2022/05/GHSA-7pq8-3c67-xq6r/GHSA-7pq8-3c67-xq6r.json index cae46dde095..e0e5144aeb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pq8-3c67-xq6r/GHSA-7pq8-3c67-xq6r.json +++ b/advisories/unreviewed/2022/05/GHSA-7pq8-3c67-xq6r/GHSA-7pq8-3c67-xq6r.json @@ -7,12 +7,8 @@ "CVE-2020-12788" ], "details": "CMAC verification functionality in Microchip Atmel ATSAMA5 products is vulnerable to vulnerable to timing and power analysis attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7qj7-wvx2-qxqv/GHSA-7qj7-wvx2-qxqv.json b/advisories/unreviewed/2022/05/GHSA-7qj7-wvx2-qxqv/GHSA-7qj7-wvx2-qxqv.json index d66a0479841..fcbdd6cf56b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qj7-wvx2-qxqv/GHSA-7qj7-wvx2-qxqv.json +++ b/advisories/unreviewed/2022/05/GHSA-7qj7-wvx2-qxqv/GHSA-7qj7-wvx2-qxqv.json @@ -7,12 +7,8 @@ "CVE-2020-9728" ], "details": "A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7vpq-xcrf-9qvc/GHSA-7vpq-xcrf-9qvc.json b/advisories/unreviewed/2022/05/GHSA-7vpq-xcrf-9qvc/GHSA-7vpq-xcrf-9qvc.json index 6e775212205..fb131b7cdd8 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vpq-xcrf-9qvc/GHSA-7vpq-xcrf-9qvc.json +++ b/advisories/unreviewed/2022/05/GHSA-7vpq-xcrf-9qvc/GHSA-7vpq-xcrf-9qvc.json @@ -7,12 +7,8 @@ "CVE-2020-0273" ], "details": "In hwservicemanager, there is a possible out of bounds write due to freeing a wild pointer. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155646800", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-82cp-p788-5r5g/GHSA-82cp-p788-5r5g.json b/advisories/unreviewed/2022/05/GHSA-82cp-p788-5r5g/GHSA-82cp-p788-5r5g.json index 2c7f06fe9a2..d55b3ed0c1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-82cp-p788-5r5g/GHSA-82cp-p788-5r5g.json +++ b/advisories/unreviewed/2022/05/GHSA-82cp-p788-5r5g/GHSA-82cp-p788-5r5g.json @@ -7,12 +7,8 @@ "CVE-2020-23830" ], "details": "A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 allows remote attackers to deny future logins by changing an authenticated victim's username when they visit a third-party site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-82q3-wxfg-rg6w/GHSA-82q3-wxfg-rg6w.json b/advisories/unreviewed/2022/05/GHSA-82q3-wxfg-rg6w/GHSA-82q3-wxfg-rg6w.json index 902e52b3dfa..ec56c188724 100644 --- a/advisories/unreviewed/2022/05/GHSA-82q3-wxfg-rg6w/GHSA-82q3-wxfg-rg6w.json +++ b/advisories/unreviewed/2022/05/GHSA-82q3-wxfg-rg6w/GHSA-82q3-wxfg-rg6w.json @@ -7,12 +7,8 @@ "CVE-2020-2042" ], "details": "A buffer overflow vulnerability in the PAN-OS management web interface allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges. This issue impacts only PAN-OS 10.0 versions earlier than PAN-OS 10.0.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-834g-xv52-7q24/GHSA-834g-xv52-7q24.json b/advisories/unreviewed/2022/05/GHSA-834g-xv52-7q24/GHSA-834g-xv52-7q24.json index 55d9e2093f8..bfa9113c2f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-834g-xv52-7q24/GHSA-834g-xv52-7q24.json +++ b/advisories/unreviewed/2022/05/GHSA-834g-xv52-7q24/GHSA-834g-xv52-7q24.json @@ -7,12 +7,8 @@ "CVE-2020-0074" ], "details": "In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-146204120", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-835c-5hqw-748h/GHSA-835c-5hqw-748h.json b/advisories/unreviewed/2022/05/GHSA-835c-5hqw-748h/GHSA-835c-5hqw-748h.json index 70d25b8e47e..545e74d29bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-835c-5hqw-748h/GHSA-835c-5hqw-748h.json +++ b/advisories/unreviewed/2022/05/GHSA-835c-5hqw-748h/GHSA-835c-5hqw-748h.json @@ -7,12 +7,8 @@ "CVE-2020-14096" ], "details": "Memory overflow in Xiaomi AI speaker Rom version <1.59.6 can happen when the speaker verifying a malicious firmware during OTA process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8372-62j2-5947/GHSA-8372-62j2-5947.json b/advisories/unreviewed/2022/05/GHSA-8372-62j2-5947/GHSA-8372-62j2-5947.json index 72be2f3041c..64379fa6fc9 100644 --- a/advisories/unreviewed/2022/05/GHSA-8372-62j2-5947/GHSA-8372-62j2-5947.json +++ b/advisories/unreviewed/2022/05/GHSA-8372-62j2-5947/GHSA-8372-62j2-5947.json @@ -7,12 +7,8 @@ "CVE-2020-24955" ], "details": "SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory junction, as demonstrated by a crafted ualapi.dll file that is detected as malware.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8427-cq28-9xqm/GHSA-8427-cq28-9xqm.json b/advisories/unreviewed/2022/05/GHSA-8427-cq28-9xqm/GHSA-8427-cq28-9xqm.json index f13b07532ed..0770a89f5bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-8427-cq28-9xqm/GHSA-8427-cq28-9xqm.json +++ b/advisories/unreviewed/2022/05/GHSA-8427-cq28-9xqm/GHSA-8427-cq28-9xqm.json @@ -7,12 +7,8 @@ "CVE-2020-15784" ], "details": "A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). Insecure storage of sensitive information in the configuration files could allow the retrieval of user names.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-857m-9c4p-fvf4/GHSA-857m-9c4p-fvf4.json b/advisories/unreviewed/2022/05/GHSA-857m-9c4p-fvf4/GHSA-857m-9c4p-fvf4.json index 19bd310c478..8f2c49e82c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-857m-9c4p-fvf4/GHSA-857m-9c4p-fvf4.json +++ b/advisories/unreviewed/2022/05/GHSA-857m-9c4p-fvf4/GHSA-857m-9c4p-fvf4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-858v-pcfh-p8xg/GHSA-858v-pcfh-p8xg.json b/advisories/unreviewed/2022/05/GHSA-858v-pcfh-p8xg/GHSA-858v-pcfh-p8xg.json index ea2220f1fb7..a1889f84657 100644 --- a/advisories/unreviewed/2022/05/GHSA-858v-pcfh-p8xg/GHSA-858v-pcfh-p8xg.json +++ b/advisories/unreviewed/2022/05/GHSA-858v-pcfh-p8xg/GHSA-858v-pcfh-p8xg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-85p3-g932-hx25/GHSA-85p3-g932-hx25.json b/advisories/unreviewed/2022/05/GHSA-85p3-g932-hx25/GHSA-85p3-g932-hx25.json index 23f77b92fbb..36c7ac09843 100644 --- a/advisories/unreviewed/2022/05/GHSA-85p3-g932-hx25/GHSA-85p3-g932-hx25.json +++ b/advisories/unreviewed/2022/05/GHSA-85p3-g932-hx25/GHSA-85p3-g932-hx25.json @@ -7,12 +7,8 @@ "CVE-2020-24655" ], "details": "A race condition in the Twilio Authy 2-Factor Authentication application before 24.3.7 for Android allows a user to potentially approve/deny an access request prior to unlocking the application with a PIN on older Android devices (effectively bypassing the PIN requirement).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8743-86pf-fx3j/GHSA-8743-86pf-fx3j.json b/advisories/unreviewed/2022/05/GHSA-8743-86pf-fx3j/GHSA-8743-86pf-fx3j.json index 85eeb1a6aaf..82835683ba8 100644 --- a/advisories/unreviewed/2022/05/GHSA-8743-86pf-fx3j/GHSA-8743-86pf-fx3j.json +++ b/advisories/unreviewed/2022/05/GHSA-8743-86pf-fx3j/GHSA-8743-86pf-fx3j.json @@ -7,12 +7,8 @@ "CVE-2020-2043" ], "details": "An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Palo Alto Networks PAN-OS software when the after-change-detail custom syslog field is enabled for configuration logs and the sensitive field appears multiple times in one log entry. The first instance of the sensitive field is masked but subsequent instances are left in clear text. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PAN-OS 9.0 versions earlier than PAN-OS 9.0.10; PAN-OS 9.1 versions earlier than PAN-OS 9.1.4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8793-frgg-7jvv/GHSA-8793-frgg-7jvv.json b/advisories/unreviewed/2022/05/GHSA-8793-frgg-7jvv/GHSA-8793-frgg-7jvv.json index b2e79f075f5..48f294ecabd 100644 --- a/advisories/unreviewed/2022/05/GHSA-8793-frgg-7jvv/GHSA-8793-frgg-7jvv.json +++ b/advisories/unreviewed/2022/05/GHSA-8793-frgg-7jvv/GHSA-8793-frgg-7jvv.json @@ -7,12 +7,8 @@ "CVE-2020-14384" ], "details": "A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable to a denial of service attack when sending multiple requests with invalid payload length in a WebSocket frame. The highest threat from this vulnerability is to system availability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-87g6-m2cw-w39m/GHSA-87g6-m2cw-w39m.json b/advisories/unreviewed/2022/05/GHSA-87g6-m2cw-w39m/GHSA-87g6-m2cw-w39m.json index 3ca5d587d3a..7b369fcb9e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-87g6-m2cw-w39m/GHSA-87g6-m2cw-w39m.json +++ b/advisories/unreviewed/2022/05/GHSA-87g6-m2cw-w39m/GHSA-87g6-m2cw-w39m.json @@ -7,12 +7,8 @@ "CVE-2020-3674" ], "details": "u'Information can leak into userspace due to improper transfer of data from kernel to userspace' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in Nicobar, QCS405, Saipan, SC8180X, SDX55, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-87p9-xf94-p7qh/GHSA-87p9-xf94-p7qh.json b/advisories/unreviewed/2022/05/GHSA-87p9-xf94-p7qh/GHSA-87p9-xf94-p7qh.json index 594614b21a7..9dce229ebb8 100644 --- a/advisories/unreviewed/2022/05/GHSA-87p9-xf94-p7qh/GHSA-87p9-xf94-p7qh.json +++ b/advisories/unreviewed/2022/05/GHSA-87p9-xf94-p7qh/GHSA-87p9-xf94-p7qh.json @@ -7,12 +7,8 @@ "CVE-2020-24925" ], "details": "A Sensitive Source Code Path Disclosure vulnerability is found in ElkarBackup v1.3.3. An attacker is able to view the path of the source code jobs/sort where entire source code path is displayed in the browser itself helping the attacker identify the code structure /app/elkarbackup/src/Binovo/ElkarBackupBundle/Controller/DefaultController.php", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-88vv-mqm2-ch6r/GHSA-88vv-mqm2-ch6r.json b/advisories/unreviewed/2022/05/GHSA-88vv-mqm2-ch6r/GHSA-88vv-mqm2-ch6r.json index c5f27d6e4d2..dbc2d5cfb9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-88vv-mqm2-ch6r/GHSA-88vv-mqm2-ch6r.json +++ b/advisories/unreviewed/2022/05/GHSA-88vv-mqm2-ch6r/GHSA-88vv-mqm2-ch6r.json @@ -7,12 +7,8 @@ "CVE-2020-13259" ], "details": "A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. This could be exploited in conjunction with CVE-2020-13260.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-88xv-4j49-xfpj/GHSA-88xv-4j49-xfpj.json b/advisories/unreviewed/2022/05/GHSA-88xv-4j49-xfpj/GHSA-88xv-4j49-xfpj.json index f2e12322226..13216ce728a 100644 --- a/advisories/unreviewed/2022/05/GHSA-88xv-4j49-xfpj/GHSA-88xv-4j49-xfpj.json +++ b/advisories/unreviewed/2022/05/GHSA-88xv-4j49-xfpj/GHSA-88xv-4j49-xfpj.json @@ -7,12 +7,8 @@ "CVE-2018-17772" ], "details": "Ingenico Telium 2 POS terminals allow arbitrary code execution via the TRACE protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-896p-r2jm-x733/GHSA-896p-r2jm-x733.json b/advisories/unreviewed/2022/05/GHSA-896p-r2jm-x733/GHSA-896p-r2jm-x733.json index f5512b73e25..e5ba8726014 100644 --- a/advisories/unreviewed/2022/05/GHSA-896p-r2jm-x733/GHSA-896p-r2jm-x733.json +++ b/advisories/unreviewed/2022/05/GHSA-896p-r2jm-x733/GHSA-896p-r2jm-x733.json @@ -7,12 +7,8 @@ "CVE-2020-23824" ], "details": "ArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code execution. The component is the Administration dashboard. When using admin/user credentials, if the admin/user admin opens a website with the malicious page that will run the CSRF.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8crw-6mr7-v864/GHSA-8crw-6mr7-v864.json b/advisories/unreviewed/2022/05/GHSA-8crw-6mr7-v864/GHSA-8crw-6mr7-v864.json index f89a5bd21a6..39e24ac82d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8crw-6mr7-v864/GHSA-8crw-6mr7-v864.json +++ b/advisories/unreviewed/2022/05/GHSA-8crw-6mr7-v864/GHSA-8crw-6mr7-v864.json @@ -7,12 +7,8 @@ "CVE-2020-0290" ], "details": "In PackageManager, there is a missing permission check. This could lead to local information disclosure across users with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153996866", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8fxq-6rpx-4cxp/GHSA-8fxq-6rpx-4cxp.json b/advisories/unreviewed/2022/05/GHSA-8fxq-6rpx-4cxp/GHSA-8fxq-6rpx-4cxp.json index 8faa1d760d5..7ae840cad9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fxq-6rpx-4cxp/GHSA-8fxq-6rpx-4cxp.json +++ b/advisories/unreviewed/2022/05/GHSA-8fxq-6rpx-4cxp/GHSA-8fxq-6rpx-4cxp.json @@ -7,12 +7,8 @@ "CVE-2020-0429" ], "details": "In l2tp_session_delete and related functions of l2tp_core.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-152735806", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8ggp-4pf2-5mgh/GHSA-8ggp-4pf2-5mgh.json b/advisories/unreviewed/2022/05/GHSA-8ggp-4pf2-5mgh/GHSA-8ggp-4pf2-5mgh.json index e13ea4f90c9..d7ed4dc3b8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8ggp-4pf2-5mgh/GHSA-8ggp-4pf2-5mgh.json +++ b/advisories/unreviewed/2022/05/GHSA-8ggp-4pf2-5mgh/GHSA-8ggp-4pf2-5mgh.json @@ -7,12 +7,8 @@ "CVE-2020-25286" ], "details": "In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8h22-fc39-v23w/GHSA-8h22-fc39-v23w.json b/advisories/unreviewed/2022/05/GHSA-8h22-fc39-v23w/GHSA-8h22-fc39-v23w.json index d0f7d9821f2..10fc92fd6e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h22-fc39-v23w/GHSA-8h22-fc39-v23w.json +++ b/advisories/unreviewed/2022/05/GHSA-8h22-fc39-v23w/GHSA-8h22-fc39-v23w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hvh-4cv6-h6v3/GHSA-8hvh-4cv6-h6v3.json b/advisories/unreviewed/2022/05/GHSA-8hvh-4cv6-h6v3/GHSA-8hvh-4cv6-h6v3.json index fea5e608558..61e496b879b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hvh-4cv6-h6v3/GHSA-8hvh-4cv6-h6v3.json +++ b/advisories/unreviewed/2022/05/GHSA-8hvh-4cv6-h6v3/GHSA-8hvh-4cv6-h6v3.json @@ -7,12 +7,8 @@ "CVE-2019-13998" ], "details": "u'Lack of check that the TX FIFO write and read indices that are read from shared RAM are less than the FIFO size results into memory corruption and potential information leakage' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA515M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qxp-fp5j-5wxj/GHSA-8qxp-fp5j-5wxj.json b/advisories/unreviewed/2022/05/GHSA-8qxp-fp5j-5wxj/GHSA-8qxp-fp5j-5wxj.json index 74498717dcb..87e71bc0290 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qxp-fp5j-5wxj/GHSA-8qxp-fp5j-5wxj.json +++ b/advisories/unreviewed/2022/05/GHSA-8qxp-fp5j-5wxj/GHSA-8qxp-fp5j-5wxj.json @@ -7,12 +7,8 @@ "CVE-2020-15791" ], "details": "A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 CPU family (incl. SIPLUS variants) (All versions). The authentication protocol between a client and a PLC via port 102/tcp (ISO-TSAP) insufficiently protects the transmitted password. This could allow an attacker that is able to intercept the network traffic to obtain valid PLC credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8rhj-vff2-27m7/GHSA-8rhj-vff2-27m7.json b/advisories/unreviewed/2022/05/GHSA-8rhj-vff2-27m7/GHSA-8rhj-vff2-27m7.json index 25eea5a9c6d..5da984250bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rhj-vff2-27m7/GHSA-8rhj-vff2-27m7.json +++ b/advisories/unreviewed/2022/05/GHSA-8rhj-vff2-27m7/GHSA-8rhj-vff2-27m7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8rpf-h452-4m5v/GHSA-8rpf-h452-4m5v.json b/advisories/unreviewed/2022/05/GHSA-8rpf-h452-4m5v/GHSA-8rpf-h452-4m5v.json index fd30c71bbe4..e2b98848af7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rpf-h452-4m5v/GHSA-8rpf-h452-4m5v.json +++ b/advisories/unreviewed/2022/05/GHSA-8rpf-h452-4m5v/GHSA-8rpf-h452-4m5v.json @@ -7,12 +7,8 @@ "CVE-2020-25287" ], "details": "Pligg 2.0.3 allows remote authenticated users to execute arbitrary commands because the template editor can edit any file, as demonstrated by an admin/admin_editor.php the_file=..%2Findex.php&open=Open request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8v8j-5gpm-fvqv/GHSA-8v8j-5gpm-fvqv.json b/advisories/unreviewed/2022/05/GHSA-8v8j-5gpm-fvqv/GHSA-8v8j-5gpm-fvqv.json index 14ab98502b9..db691e88860 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v8j-5gpm-fvqv/GHSA-8v8j-5gpm-fvqv.json +++ b/advisories/unreviewed/2022/05/GHSA-8v8j-5gpm-fvqv/GHSA-8v8j-5gpm-fvqv.json @@ -7,12 +7,8 @@ "CVE-2020-25043" ], "details": "The installer of Kaspersky VPN Secure Connection prior to 5.0 was vulnerable to arbitrary file deletion that could allow an attacker to delete any file in the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8wjf-7pjq-2695/GHSA-8wjf-7pjq-2695.json b/advisories/unreviewed/2022/05/GHSA-8wjf-7pjq-2695/GHSA-8wjf-7pjq-2695.json index c49f57ea4a6..3a93d874a11 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wjf-7pjq-2695/GHSA-8wjf-7pjq-2695.json +++ b/advisories/unreviewed/2022/05/GHSA-8wjf-7pjq-2695/GHSA-8wjf-7pjq-2695.json @@ -7,12 +7,8 @@ "CVE-2020-13318" ], "details": "A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xr9-2r57-gg3h/GHSA-8xr9-2r57-gg3h.json b/advisories/unreviewed/2022/05/GHSA-8xr9-2r57-gg3h/GHSA-8xr9-2r57-gg3h.json index 437da69804b..09c315731ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xr9-2r57-gg3h/GHSA-8xr9-2r57-gg3h.json +++ b/advisories/unreviewed/2022/05/GHSA-8xr9-2r57-gg3h/GHSA-8xr9-2r57-gg3h.json @@ -7,12 +7,8 @@ "CVE-2020-16233" ], "details": "An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packets containing data from the heap.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-924w-c7p6-hr3m/GHSA-924w-c7p6-hr3m.json b/advisories/unreviewed/2022/05/GHSA-924w-c7p6-hr3m/GHSA-924w-c7p6-hr3m.json index 25c77d6697d..46dd1e57c16 100644 --- a/advisories/unreviewed/2022/05/GHSA-924w-c7p6-hr3m/GHSA-924w-c7p6-hr3m.json +++ b/advisories/unreviewed/2022/05/GHSA-924w-c7p6-hr3m/GHSA-924w-c7p6-hr3m.json @@ -7,12 +7,8 @@ "CVE-2020-4708" ], "details": "IBM Security Trusteer Pinpoint Detect 11.6.5 could disclose some information due to using a wildcard in the Access-Control-Allow-Origin header. IBM X-Force ID: 187371.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-92gg-745w-464g/GHSA-92gg-745w-464g.json b/advisories/unreviewed/2022/05/GHSA-92gg-745w-464g/GHSA-92gg-745w-464g.json index 6cb96d2ddc7..708dc91f9c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-92gg-745w-464g/GHSA-92gg-745w-464g.json +++ b/advisories/unreviewed/2022/05/GHSA-92gg-745w-464g/GHSA-92gg-745w-464g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-93vf-4x6g-q64v/GHSA-93vf-4x6g-q64v.json b/advisories/unreviewed/2022/05/GHSA-93vf-4x6g-q64v/GHSA-93vf-4x6g-q64v.json index f43912455ef..f17bfefdcd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-93vf-4x6g-q64v/GHSA-93vf-4x6g-q64v.json +++ b/advisories/unreviewed/2022/05/GHSA-93vf-4x6g-q64v/GHSA-93vf-4x6g-q64v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-95fj-4hcc-xv2c/GHSA-95fj-4hcc-xv2c.json b/advisories/unreviewed/2022/05/GHSA-95fj-4hcc-xv2c/GHSA-95fj-4hcc-xv2c.json index b13e47717af..7bf2225cc61 100644 --- a/advisories/unreviewed/2022/05/GHSA-95fj-4hcc-xv2c/GHSA-95fj-4hcc-xv2c.json +++ b/advisories/unreviewed/2022/05/GHSA-95fj-4hcc-xv2c/GHSA-95fj-4hcc-xv2c.json @@ -7,12 +7,8 @@ "CVE-2020-0326" ], "details": "In NFC, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-146453119", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-95hf-gv4r-6jjr/GHSA-95hf-gv4r-6jjr.json b/advisories/unreviewed/2022/05/GHSA-95hf-gv4r-6jjr/GHSA-95hf-gv4r-6jjr.json index 7aac92e0e86..29d755eaaa9 100644 --- a/advisories/unreviewed/2022/05/GHSA-95hf-gv4r-6jjr/GHSA-95hf-gv4r-6jjr.json +++ b/advisories/unreviewed/2022/05/GHSA-95hf-gv4r-6jjr/GHSA-95hf-gv4r-6jjr.json @@ -7,12 +7,8 @@ "CVE-2020-16096" ], "details": "In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to 7.80.960(MR2), 7.70 and earlier, any operator account has access to all data that would be replicated if the system were to be (or is) attached to a multi-server environment. This can include plain text credentials for DVR systems and card details used for physical access/alarm/perimeter components.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-99fc-5rrq-7p52/GHSA-99fc-5rrq-7p52.json b/advisories/unreviewed/2022/05/GHSA-99fc-5rrq-7p52/GHSA-99fc-5rrq-7p52.json index 36a5d4a2ba9..e4f6402497a 100644 --- a/advisories/unreviewed/2022/05/GHSA-99fc-5rrq-7p52/GHSA-99fc-5rrq-7p52.json +++ b/advisories/unreviewed/2022/05/GHSA-99fc-5rrq-7p52/GHSA-99fc-5rrq-7p52.json @@ -7,12 +7,8 @@ "CVE-2020-16101" ], "details": "It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out-of-bounds buffer access. Affected versions are v8.20 prior to v8.20.1166(MR3), v8.10 prior to v8.10.1211(MR5), v8.00 prior to v8.00.1228(MR6), all versions of 7.90 and earlier.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9c96-fgqh-c568/GHSA-9c96-fgqh-c568.json b/advisories/unreviewed/2022/05/GHSA-9c96-fgqh-c568/GHSA-9c96-fgqh-c568.json index 7a6383c7327..92737463553 100644 --- a/advisories/unreviewed/2022/05/GHSA-9c96-fgqh-c568/GHSA-9c96-fgqh-c568.json +++ b/advisories/unreviewed/2022/05/GHSA-9c96-fgqh-c568/GHSA-9c96-fgqh-c568.json @@ -7,12 +7,8 @@ "CVE-2020-24561" ], "details": "A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrary code on an affected system. An attacker must first obtain admin/root privileges on the SPLX console to exploit this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9g5w-q3pg-gr6h/GHSA-9g5w-q3pg-gr6h.json b/advisories/unreviewed/2022/05/GHSA-9g5w-q3pg-gr6h/GHSA-9g5w-q3pg-gr6h.json index cf5b1c51cd2..3a5e3265b72 100644 --- a/advisories/unreviewed/2022/05/GHSA-9g5w-q3pg-gr6h/GHSA-9g5w-q3pg-gr6h.json +++ b/advisories/unreviewed/2022/05/GHSA-9g5w-q3pg-gr6h/GHSA-9g5w-q3pg-gr6h.json @@ -7,12 +7,8 @@ "CVE-2020-0276" ], "details": "In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156253586", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9g6r-m8wp-hqcv/GHSA-9g6r-m8wp-hqcv.json b/advisories/unreviewed/2022/05/GHSA-9g6r-m8wp-hqcv/GHSA-9g6r-m8wp-hqcv.json index ba02d22650b..df9d5bc0318 100644 --- a/advisories/unreviewed/2022/05/GHSA-9g6r-m8wp-hqcv/GHSA-9g6r-m8wp-hqcv.json +++ b/advisories/unreviewed/2022/05/GHSA-9g6r-m8wp-hqcv/GHSA-9g6r-m8wp-hqcv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gvv-jxrj-2xcq/GHSA-9gvv-jxrj-2xcq.json b/advisories/unreviewed/2022/05/GHSA-9gvv-jxrj-2xcq/GHSA-9gvv-jxrj-2xcq.json index 102821d88a5..3a256604a5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gvv-jxrj-2xcq/GHSA-9gvv-jxrj-2xcq.json +++ b/advisories/unreviewed/2022/05/GHSA-9gvv-jxrj-2xcq/GHSA-9gvv-jxrj-2xcq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9hp3-3v8x-gvhx/GHSA-9hp3-3v8x-gvhx.json b/advisories/unreviewed/2022/05/GHSA-9hp3-3v8x-gvhx/GHSA-9hp3-3v8x-gvhx.json index 1353531b8d4..82be89c2f94 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hp3-3v8x-gvhx/GHSA-9hp3-3v8x-gvhx.json +++ b/advisories/unreviewed/2022/05/GHSA-9hp3-3v8x-gvhx/GHSA-9hp3-3v8x-gvhx.json @@ -7,12 +7,8 @@ "CVE-2020-15786" ], "details": "A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions >= 14 and V < XX), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions), SIMATIC HMI Mobile Panels (All versions), SIMATIC HMI United Comfort Panels (All versions). Affected devices insufficiently block excessive authentication attempts. This could allow a remote attacker to discover user passwords and obtain access to the Sm@rt Server via a brute-force attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9j29-262r-8x2g/GHSA-9j29-262r-8x2g.json b/advisories/unreviewed/2022/05/GHSA-9j29-262r-8x2g/GHSA-9j29-262r-8x2g.json index 81044b9688c..aaaf253fafd 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j29-262r-8x2g/GHSA-9j29-262r-8x2g.json +++ b/advisories/unreviewed/2022/05/GHSA-9j29-262r-8x2g/GHSA-9j29-262r-8x2g.json @@ -7,12 +7,8 @@ "CVE-2020-24029" ], "details": "Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a simple request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9j84-h9rr-927m/GHSA-9j84-h9rr-927m.json b/advisories/unreviewed/2022/05/GHSA-9j84-h9rr-927m/GHSA-9j84-h9rr-927m.json index 5e49f428710..8159ceee92d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j84-h9rr-927m/GHSA-9j84-h9rr-927m.json +++ b/advisories/unreviewed/2022/05/GHSA-9j84-h9rr-927m/GHSA-9j84-h9rr-927m.json @@ -7,12 +7,8 @@ "CVE-2020-0570" ], "details": "Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9m99-vg2m-7qx3/GHSA-9m99-vg2m-7qx3.json b/advisories/unreviewed/2022/05/GHSA-9m99-vg2m-7qx3/GHSA-9m99-vg2m-7qx3.json index 5a555ff7525..9cf69a885d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m99-vg2m-7qx3/GHSA-9m99-vg2m-7qx3.json +++ b/advisories/unreviewed/2022/05/GHSA-9m99-vg2m-7qx3/GHSA-9m99-vg2m-7qx3.json @@ -7,12 +7,8 @@ "CVE-2020-6351" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated FBX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9mw4-fp5g-pcj4/GHSA-9mw4-fp5g-pcj4.json b/advisories/unreviewed/2022/05/GHSA-9mw4-fp5g-pcj4/GHSA-9mw4-fp5g-pcj4.json index 0cd6fbf072e..bd1639c6afa 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mw4-fp5g-pcj4/GHSA-9mw4-fp5g-pcj4.json +++ b/advisories/unreviewed/2022/05/GHSA-9mw4-fp5g-pcj4/GHSA-9mw4-fp5g-pcj4.json @@ -7,12 +7,8 @@ "CVE-2020-23451" ], "details": "Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via \"/settings/v1/users\" function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9pmj-qm26-jq78/GHSA-9pmj-qm26-jq78.json b/advisories/unreviewed/2022/05/GHSA-9pmj-qm26-jq78/GHSA-9pmj-qm26-jq78.json index ea273678051..0c6d1cf1915 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pmj-qm26-jq78/GHSA-9pmj-qm26-jq78.json +++ b/advisories/unreviewed/2022/05/GHSA-9pmj-qm26-jq78/GHSA-9pmj-qm26-jq78.json @@ -7,12 +7,8 @@ "CVE-2020-7312" ], "details": "DLL Search Order Hijacking Vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9pq6-xhx5-v6v6/GHSA-9pq6-xhx5-v6v6.json b/advisories/unreviewed/2022/05/GHSA-9pq6-xhx5-v6v6/GHSA-9pq6-xhx5-v6v6.json index 23d3bd098e3..85901f7e829 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pq6-xhx5-v6v6/GHSA-9pq6-xhx5-v6v6.json +++ b/advisories/unreviewed/2022/05/GHSA-9pq6-xhx5-v6v6/GHSA-9pq6-xhx5-v6v6.json @@ -7,12 +7,8 @@ "CVE-2020-24739" ], "details": "A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN and can still request normally, all administrators except the initial administrator will be deleted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9r7r-57fg-wq6g/GHSA-9r7r-57fg-wq6g.json b/advisories/unreviewed/2022/05/GHSA-9r7r-57fg-wq6g/GHSA-9r7r-57fg-wq6g.json index f0e07a3d0cf..aab63686a2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r7r-57fg-wq6g/GHSA-9r7r-57fg-wq6g.json +++ b/advisories/unreviewed/2022/05/GHSA-9r7r-57fg-wq6g/GHSA-9r7r-57fg-wq6g.json @@ -7,12 +7,8 @@ "CVE-2019-13994" ], "details": "u'Lack of check that the current received data fragment size of a particular packet that are read from shared memory are less than the actual packet size can lead to memory corruption and potential information leakage' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9vhh-7m5h-q2cr/GHSA-9vhh-7m5h-q2cr.json b/advisories/unreviewed/2022/05/GHSA-9vhh-7m5h-q2cr/GHSA-9vhh-7m5h-q2cr.json index f112d7b10c6..652d7e0ac38 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vhh-7m5h-q2cr/GHSA-9vhh-7m5h-q2cr.json +++ b/advisories/unreviewed/2022/05/GHSA-9vhh-7m5h-q2cr/GHSA-9vhh-7m5h-q2cr.json @@ -7,12 +7,8 @@ "CVE-2020-11881" ], "details": "An array index error in MikroTik RouterOS 6.41.3 through 6.46.5, and 7.x through 7.0 Beta5, allows an unauthenticated remote attacker to crash the SMB server via modified setup-request packets, aka SUP-12964.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9w4c-84x2-59qr/GHSA-9w4c-84x2-59qr.json b/advisories/unreviewed/2022/05/GHSA-9w4c-84x2-59qr/GHSA-9w4c-84x2-59qr.json index afd007a8c71..ab5635e5e55 100644 --- a/advisories/unreviewed/2022/05/GHSA-9w4c-84x2-59qr/GHSA-9w4c-84x2-59qr.json +++ b/advisories/unreviewed/2022/05/GHSA-9w4c-84x2-59qr/GHSA-9w4c-84x2-59qr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4p9-w9gc-7j5g/GHSA-c4p9-w9gc-7j5g.json b/advisories/unreviewed/2022/05/GHSA-c4p9-w9gc-7j5g/GHSA-c4p9-w9gc-7j5g.json index fdbd585561b..fb6e07e895d 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4p9-w9gc-7j5g/GHSA-c4p9-w9gc-7j5g.json +++ b/advisories/unreviewed/2022/05/GHSA-c4p9-w9gc-7j5g/GHSA-c4p9-w9gc-7j5g.json @@ -7,12 +7,8 @@ "CVE-2020-13305" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not invalidating project invitation link upon removing a user from a project.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c4pp-v922-7762/GHSA-c4pp-v922-7762.json b/advisories/unreviewed/2022/05/GHSA-c4pp-v922-7762/GHSA-c4pp-v922-7762.json index 5e29f96f70f..d0a3c23886b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4pp-v922-7762/GHSA-c4pp-v922-7762.json +++ b/advisories/unreviewed/2022/05/GHSA-c4pp-v922-7762/GHSA-c4pp-v922-7762.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5px-g3pm-787c/GHSA-c5px-g3pm-787c.json b/advisories/unreviewed/2022/05/GHSA-c5px-g3pm-787c/GHSA-c5px-g3pm-787c.json index d6a9d4440a8..f1e8415b823 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5px-g3pm-787c/GHSA-c5px-g3pm-787c.json +++ b/advisories/unreviewed/2022/05/GHSA-c5px-g3pm-787c/GHSA-c5px-g3pm-787c.json @@ -7,12 +7,8 @@ "CVE-2020-13312" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5r3-9g4g-r6vr/GHSA-c5r3-9g4g-r6vr.json b/advisories/unreviewed/2022/05/GHSA-c5r3-9g4g-r6vr/GHSA-c5r3-9g4g-r6vr.json index db035989b3a..dfbf0242574 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5r3-9g4g-r6vr/GHSA-c5r3-9g4g-r6vr.json +++ b/advisories/unreviewed/2022/05/GHSA-c5r3-9g4g-r6vr/GHSA-c5r3-9g4g-r6vr.json @@ -7,12 +7,8 @@ "CVE-2020-0125" ], "details": "In mediadrm, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137282168", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c5x3-6f7p-wf2v/GHSA-c5x3-6f7p-wf2v.json b/advisories/unreviewed/2022/05/GHSA-c5x3-6f7p-wf2v/GHSA-c5x3-6f7p-wf2v.json index 1e0e9c20cc3..12eeee77029 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5x3-6f7p-wf2v/GHSA-c5x3-6f7p-wf2v.json +++ b/advisories/unreviewed/2022/05/GHSA-c5x3-6f7p-wf2v/GHSA-c5x3-6f7p-wf2v.json @@ -7,12 +7,8 @@ "CVE-2020-0089" ], "details": "In the audio server, there is a missing permission check. This could lead to local escalation of privilege regarding audio settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137015603", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5x8-pj63-gw3w/GHSA-c5x8-pj63-gw3w.json b/advisories/unreviewed/2022/05/GHSA-c5x8-pj63-gw3w/GHSA-c5x8-pj63-gw3w.json index 4cf2a20ee1b..658d3c41aef 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5x8-pj63-gw3w/GHSA-c5x8-pj63-gw3w.json +++ b/advisories/unreviewed/2022/05/GHSA-c5x8-pj63-gw3w/GHSA-c5x8-pj63-gw3w.json @@ -7,12 +7,8 @@ "CVE-2020-0277" ], "details": "In NetworkPolicyManagerService, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing a malicious app to modify the device's data plan with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-148627993", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c67h-6v76-w36x/GHSA-c67h-6v76-w36x.json b/advisories/unreviewed/2022/05/GHSA-c67h-6v76-w36x/GHSA-c67h-6v76-w36x.json index bf76f5ced69..230061fdd3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c67h-6v76-w36x/GHSA-c67h-6v76-w36x.json +++ b/advisories/unreviewed/2022/05/GHSA-c67h-6v76-w36x/GHSA-c67h-6v76-w36x.json @@ -7,12 +7,8 @@ "CVE-2020-6337" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated HDR file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c6rp-5g6v-mj33/GHSA-c6rp-5g6v-mj33.json b/advisories/unreviewed/2022/05/GHSA-c6rp-5g6v-mj33/GHSA-c6rp-5g6v-mj33.json index 971ab52036b..76edb68ec6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6rp-5g6v-mj33/GHSA-c6rp-5g6v-mj33.json +++ b/advisories/unreviewed/2022/05/GHSA-c6rp-5g6v-mj33/GHSA-c6rp-5g6v-mj33.json @@ -7,12 +7,8 @@ "CVE-2020-6348" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c87p-h49c-qjmw/GHSA-c87p-h49c-qjmw.json b/advisories/unreviewed/2022/05/GHSA-c87p-h49c-qjmw/GHSA-c87p-h49c-qjmw.json index 59f87db2af0..1358c5fe47b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c87p-h49c-qjmw/GHSA-c87p-h49c-qjmw.json +++ b/advisories/unreviewed/2022/05/GHSA-c87p-h49c-qjmw/GHSA-c87p-h49c-qjmw.json @@ -7,12 +7,8 @@ "CVE-2020-10766" ], "details": "A logic bug flaw was found in Linux kernel before 5.8-rc1 in the implementation of SSBD. A bug in the logic handling allows an attacker with a local account to disable SSBD protection during a context switch when additional speculative execution mitigations are in place. This issue was introduced when the per task/process conditional STIPB switching was added on top of the existing SSBD switching. The highest threat from this vulnerability is to confidentiality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c8c8-39vg-wgv8/GHSA-c8c8-39vg-wgv8.json b/advisories/unreviewed/2022/05/GHSA-c8c8-39vg-wgv8/GHSA-c8c8-39vg-wgv8.json index 1434e27aeab..e6e3024cbe5 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8c8-39vg-wgv8/GHSA-c8c8-39vg-wgv8.json +++ b/advisories/unreviewed/2022/05/GHSA-c8c8-39vg-wgv8/GHSA-c8c8-39vg-wgv8.json @@ -7,12 +7,8 @@ "CVE-2020-7323" ], "details": "Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows physical local users to bypass the Windows lock screen via triggering certain detection events while the computer screen is locked and the McTray.exe is running with elevated privileges. This issue is timing dependent and requires physical access to the machine.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c8fh-jgqg-54pp/GHSA-c8fh-jgqg-54pp.json b/advisories/unreviewed/2022/05/GHSA-c8fh-jgqg-54pp/GHSA-c8fh-jgqg-54pp.json index 07504c62972..b2f866d8893 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8fh-jgqg-54pp/GHSA-c8fh-jgqg-54pp.json +++ b/advisories/unreviewed/2022/05/GHSA-c8fh-jgqg-54pp/GHSA-c8fh-jgqg-54pp.json @@ -7,12 +7,8 @@ "CVE-2020-0314" ], "details": "In AudioService, there are missing permission checks. This could lead to local information disclosure of audio configuration with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154934920", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c9p3-9xjw-7q44/GHSA-c9p3-9xjw-7q44.json b/advisories/unreviewed/2022/05/GHSA-c9p3-9xjw-7q44/GHSA-c9p3-9xjw-7q44.json index 85fe9da1f32..b44b32ab484 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9p3-9xjw-7q44/GHSA-c9p3-9xjw-7q44.json +++ b/advisories/unreviewed/2022/05/GHSA-c9p3-9xjw-7q44/GHSA-c9p3-9xjw-7q44.json @@ -7,12 +7,8 @@ "CVE-2020-0123" ], "details": "There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-149871374", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ccgh-w4m9-4w8h/GHSA-ccgh-w4m9-4w8h.json b/advisories/unreviewed/2022/05/GHSA-ccgh-w4m9-4w8h/GHSA-ccgh-w4m9-4w8h.json index 33c7eaa2a58..aadc22b59d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccgh-w4m9-4w8h/GHSA-ccgh-w4m9-4w8h.json +++ b/advisories/unreviewed/2022/05/GHSA-ccgh-w4m9-4w8h/GHSA-ccgh-w4m9-4w8h.json @@ -7,12 +7,8 @@ "CVE-2019-14025" ], "details": "u'When a new session is created, Object is returned that contains TZ addresses and it get passed to HLOS as an handle to refer to a particular session and can cause TZ to jump to a invalid address' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, QCS404, QCS610, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cfhj-wmq5-2vrv/GHSA-cfhj-wmq5-2vrv.json b/advisories/unreviewed/2022/05/GHSA-cfhj-wmq5-2vrv/GHSA-cfhj-wmq5-2vrv.json index 2f774f97269..ece0d702c90 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfhj-wmq5-2vrv/GHSA-cfhj-wmq5-2vrv.json +++ b/advisories/unreviewed/2022/05/GHSA-cfhj-wmq5-2vrv/GHSA-cfhj-wmq5-2vrv.json @@ -7,12 +7,8 @@ "CVE-2020-13314" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Omniauth endpoint allowed a malicious user to submit content to be displayed back to the user within error messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cfp6-wq22-gv3m/GHSA-cfp6-wq22-gv3m.json b/advisories/unreviewed/2022/05/GHSA-cfp6-wq22-gv3m/GHSA-cfp6-wq22-gv3m.json index c49711a0791..12c7ead837c 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfp6-wq22-gv3m/GHSA-cfp6-wq22-gv3m.json +++ b/advisories/unreviewed/2022/05/GHSA-cfp6-wq22-gv3m/GHSA-cfp6-wq22-gv3m.json @@ -7,12 +7,8 @@ "CVE-2020-13310" ], "details": "A vulnerability was discovered in GitLab runner versions before 13.1.3, 13.2.3 and 13.3.1. It was possible to make the gitlab-runner process crash by sending malformed queries, resulting in a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cggp-hg98-4chw/GHSA-cggp-hg98-4chw.json b/advisories/unreviewed/2022/05/GHSA-cggp-hg98-4chw/GHSA-cggp-hg98-4chw.json index d9d6434a057..27fd3cb020f 100644 --- a/advisories/unreviewed/2022/05/GHSA-cggp-hg98-4chw/GHSA-cggp-hg98-4chw.json +++ b/advisories/unreviewed/2022/05/GHSA-cggp-hg98-4chw/GHSA-cggp-hg98-4chw.json @@ -7,12 +7,8 @@ "CVE-2020-4521" ], "details": "IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization in Java. By sending specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 182396.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cgxq-2fvp-jvhm/GHSA-cgxq-2fvp-jvhm.json b/advisories/unreviewed/2022/05/GHSA-cgxq-2fvp-jvhm/GHSA-cgxq-2fvp-jvhm.json index a9ef6f56204..c27ddf45ffc 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgxq-2fvp-jvhm/GHSA-cgxq-2fvp-jvhm.json +++ b/advisories/unreviewed/2022/05/GHSA-cgxq-2fvp-jvhm/GHSA-cgxq-2fvp-jvhm.json @@ -7,12 +7,8 @@ "CVE-2020-0321" ], "details": "In the mp3 extractor, there is a possible out of bounds write due to uninitialized data. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155171907", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ch45-w4cr-rvq6/GHSA-ch45-w4cr-rvq6.json b/advisories/unreviewed/2022/05/GHSA-ch45-w4cr-rvq6/GHSA-ch45-w4cr-rvq6.json index ce95b6b945d..5ff7f951235 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch45-w4cr-rvq6/GHSA-ch45-w4cr-rvq6.json +++ b/advisories/unreviewed/2022/05/GHSA-ch45-w4cr-rvq6/GHSA-ch45-w4cr-rvq6.json @@ -7,12 +7,8 @@ "CVE-2020-6350" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated BMP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-chgx-prw4-5h2x/GHSA-chgx-prw4-5h2x.json b/advisories/unreviewed/2022/05/GHSA-chgx-prw4-5h2x/GHSA-chgx-prw4-5h2x.json index 7ff9773150a..c190429888b 100644 --- a/advisories/unreviewed/2022/05/GHSA-chgx-prw4-5h2x/GHSA-chgx-prw4-5h2x.json +++ b/advisories/unreviewed/2022/05/GHSA-chgx-prw4-5h2x/GHSA-chgx-prw4-5h2x.json @@ -7,12 +7,8 @@ "CVE-2020-0130" ], "details": "In screencap, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege in a system process with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-123230379", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cj3p-fc7w-fx87/GHSA-cj3p-fc7w-fx87.json b/advisories/unreviewed/2022/05/GHSA-cj3p-fc7w-fx87/GHSA-cj3p-fc7w-fx87.json index 3b7889056dd..64d973eeb58 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj3p-fc7w-fx87/GHSA-cj3p-fc7w-fx87.json +++ b/advisories/unreviewed/2022/05/GHSA-cj3p-fc7w-fx87/GHSA-cj3p-fc7w-fx87.json @@ -7,12 +7,8 @@ "CVE-2020-11986" ], "details": "To be able to analyze gradle projects, the build scripts need to be executed. Apache NetBeans follows this pattern. This causes the code of the build script to be invoked at load time of the project. Apache NetBeans up to and including 12.0 did not request consent from the user for the analysis of the project at load time. This in turn will run potentially malicious code, from an external source, without the consent of the user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cjqm-pc48-gq5m/GHSA-cjqm-pc48-gq5m.json b/advisories/unreviewed/2022/05/GHSA-cjqm-pc48-gq5m/GHSA-cjqm-pc48-gq5m.json index 24795772a22..e1bc653c9f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjqm-pc48-gq5m/GHSA-cjqm-pc48-gq5m.json +++ b/advisories/unreviewed/2022/05/GHSA-cjqm-pc48-gq5m/GHSA-cjqm-pc48-gq5m.json @@ -7,12 +7,8 @@ "CVE-2020-12787" ], "details": "Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to applet handling.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cph4-fpfm-5h8w/GHSA-cph4-fpfm-5h8w.json b/advisories/unreviewed/2022/05/GHSA-cph4-fpfm-5h8w/GHSA-cph4-fpfm-5h8w.json index 55357cd1943..89a7b2acf1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-cph4-fpfm-5h8w/GHSA-cph4-fpfm-5h8w.json +++ b/advisories/unreviewed/2022/05/GHSA-cph4-fpfm-5h8w/GHSA-cph4-fpfm-5h8w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cpq2-ppf5-mpjp/GHSA-cpq2-ppf5-mpjp.json b/advisories/unreviewed/2022/05/GHSA-cpq2-ppf5-mpjp/GHSA-cpq2-ppf5-mpjp.json index 3d43e1af01f..c95245826f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpq2-ppf5-mpjp/GHSA-cpq2-ppf5-mpjp.json +++ b/advisories/unreviewed/2022/05/GHSA-cpq2-ppf5-mpjp/GHSA-cpq2-ppf5-mpjp.json @@ -7,12 +7,8 @@ "CVE-2020-21731" ], "details": "Gazie 7.29 is affected by: Cross Site Scripting (XSS) via http://192.168.100.7/gazie/modules/config/admin_utente.php?user_name=amministratore&Update. An attacker can inject JavaScript code, and the webapplication stores the injected code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cwhg-93qp-c6pg/GHSA-cwhg-93qp-c6pg.json b/advisories/unreviewed/2022/05/GHSA-cwhg-93qp-c6pg/GHSA-cwhg-93qp-c6pg.json index 3ca7ebb8e10..a7c9bd77337 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwhg-93qp-c6pg/GHSA-cwhg-93qp-c6pg.json +++ b/advisories/unreviewed/2022/05/GHSA-cwhg-93qp-c6pg/GHSA-cwhg-93qp-c6pg.json @@ -7,12 +7,8 @@ "CVE-2020-3620" ], "details": "u'Lack of check of integer overflow while doing a round up operation for data read from shared memory for G-link SMEM transport can lead to corruption and potential information leak' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cxvc-q3cv-wf7w/GHSA-cxvc-q3cv-wf7w.json b/advisories/unreviewed/2022/05/GHSA-cxvc-q3cv-wf7w/GHSA-cxvc-q3cv-wf7w.json index 1ef3ee8c939..58b9f035dae 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxvc-q3cv-wf7w/GHSA-cxvc-q3cv-wf7w.json +++ b/advisories/unreviewed/2022/05/GHSA-cxvc-q3cv-wf7w/GHSA-cxvc-q3cv-wf7w.json @@ -7,12 +7,8 @@ "CVE-2020-7320" ], "details": "Protection Mechanism Failure vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local administrator to temporarily reduce the detection capability allowing otherwise detected malware to run via stopping certain Microsoft services.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f435-r8xf-rc9w/GHSA-f435-r8xf-rc9w.json b/advisories/unreviewed/2022/05/GHSA-f435-r8xf-rc9w/GHSA-f435-r8xf-rc9w.json index 45b5d17aaa7..dc038b82170 100644 --- a/advisories/unreviewed/2022/05/GHSA-f435-r8xf-rc9w/GHSA-f435-r8xf-rc9w.json +++ b/advisories/unreviewed/2022/05/GHSA-f435-r8xf-rc9w/GHSA-f435-r8xf-rc9w.json @@ -7,12 +7,8 @@ "CVE-2020-13309" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the repository mirroring feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f488-435f-fcqm/GHSA-f488-435f-fcqm.json b/advisories/unreviewed/2022/05/GHSA-f488-435f-fcqm/GHSA-f488-435f-fcqm.json index 77a7a0a741a..2ab542490e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-f488-435f-fcqm/GHSA-f488-435f-fcqm.json +++ b/advisories/unreviewed/2022/05/GHSA-f488-435f-fcqm/GHSA-f488-435f-fcqm.json @@ -7,12 +7,8 @@ "CVE-2020-0353" ], "details": "In libmp4extractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124777526", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4xr-xwq3-38fv/GHSA-f4xr-xwq3-38fv.json b/advisories/unreviewed/2022/05/GHSA-f4xr-xwq3-38fv/GHSA-f4xr-xwq3-38fv.json index 5cab7222007..c827ebaf634 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4xr-xwq3-38fv/GHSA-f4xr-xwq3-38fv.json +++ b/advisories/unreviewed/2022/05/GHSA-f4xr-xwq3-38fv/GHSA-f4xr-xwq3-38fv.json @@ -7,12 +7,8 @@ "CVE-2020-6330" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated 3DM file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f5xq-vjwc-pqqj/GHSA-f5xq-vjwc-pqqj.json b/advisories/unreviewed/2022/05/GHSA-f5xq-vjwc-pqqj/GHSA-f5xq-vjwc-pqqj.json index 4bae7c612ee..51fd41ac7c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5xq-vjwc-pqqj/GHSA-f5xq-vjwc-pqqj.json +++ b/advisories/unreviewed/2022/05/GHSA-f5xq-vjwc-pqqj/GHSA-f5xq-vjwc-pqqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6xv-m775-pjr5/GHSA-f6xv-m775-pjr5.json b/advisories/unreviewed/2022/05/GHSA-f6xv-m775-pjr5/GHSA-f6xv-m775-pjr5.json index dcbfd943b40..c5635019483 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6xv-m775-pjr5/GHSA-f6xv-m775-pjr5.json +++ b/advisories/unreviewed/2022/05/GHSA-f6xv-m775-pjr5/GHSA-f6xv-m775-pjr5.json @@ -7,12 +7,8 @@ "CVE-2020-0307" ], "details": "In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151645867", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f8jg-xpjx-j54w/GHSA-f8jg-xpjx-j54w.json b/advisories/unreviewed/2022/05/GHSA-f8jg-xpjx-j54w/GHSA-f8jg-xpjx-j54w.json index 7c7c3adb3b2..dc9ba6602b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8jg-xpjx-j54w/GHSA-f8jg-xpjx-j54w.json +++ b/advisories/unreviewed/2022/05/GHSA-f8jg-xpjx-j54w/GHSA-f8jg-xpjx-j54w.json @@ -7,12 +7,8 @@ "CVE-2020-9239" ], "details": "Huawei smartphones BLA-A09 versions 8.0.0.123(C212),versions earlier than 8.0.0.123(C567),versions earlier than 8.0.0.123(C797);BLA-TL00B versions earlier than 8.1.0.326(C01);Berkeley-L09 versions earlier than 8.0.0.163(C10),versions earlier than 8.0.0.163(C432),Versions earlier than 8.0.0.163(C636),Versions earlier than 8.0.0.172(C10);Duke-L09 versions Duke-L09C10B187, versions Duke-L09C432B189, versions Duke-L09C636B189;HUAWEI P20 versions earlier than 8.0.1.16(C00);HUAWEI P20 Pro versions earlier than 8.1.0.152(C00);Jimmy-AL00A versions earlier than Jimmy-AL00AC00B172;LON-L29D versions LON-L29DC721B192;NEO-AL00D versions earlier than 8.1.0.172(C786);Stanford-AL00 versions Stanford-AL00C00B123;Toronto-AL00 versions earlier than Toronto-AL00AC00B225;Toronto-AL00A versions earlier than Toronto-AL00AC00B225;Toronto-TL10 versions earlier than Toronto-TL10C01B225 have an information vulnerability. A module has a design error that is lack of control of input. Attackers can exploit this vulnerab", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f9pr-qq7v-xmfj/GHSA-f9pr-qq7v-xmfj.json b/advisories/unreviewed/2022/05/GHSA-f9pr-qq7v-xmfj/GHSA-f9pr-qq7v-xmfj.json index 9d5c0a383f6..f9301a81616 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9pr-qq7v-xmfj/GHSA-f9pr-qq7v-xmfj.json +++ b/advisories/unreviewed/2022/05/GHSA-f9pr-qq7v-xmfj/GHSA-f9pr-qq7v-xmfj.json @@ -7,12 +7,8 @@ "CVE-2020-6356" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated BMP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcc5-x3g2-xc22/GHSA-fcc5-x3g2-xc22.json b/advisories/unreviewed/2022/05/GHSA-fcc5-x3g2-xc22/GHSA-fcc5-x3g2-xc22.json index 4bd78a166b0..65afe8df811 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcc5-x3g2-xc22/GHSA-fcc5-x3g2-xc22.json +++ b/advisories/unreviewed/2022/05/GHSA-fcc5-x3g2-xc22/GHSA-fcc5-x3g2-xc22.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ff95-chf7-569x/GHSA-ff95-chf7-569x.json b/advisories/unreviewed/2022/05/GHSA-ff95-chf7-569x/GHSA-ff95-chf7-569x.json index b67644e1427..0a60f996d87 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff95-chf7-569x/GHSA-ff95-chf7-569x.json +++ b/advisories/unreviewed/2022/05/GHSA-ff95-chf7-569x/GHSA-ff95-chf7-569x.json @@ -7,12 +7,8 @@ "CVE-2020-7529" ], "details": "A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place content in any unprotected folder on the target system using a crafted .RCZ file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ffvh-x5cw-294c/GHSA-ffvh-x5cw-294c.json b/advisories/unreviewed/2022/05/GHSA-ffvh-x5cw-294c/GHSA-ffvh-x5cw-294c.json index 8b7510dcbef..5a5092c1091 100644 --- a/advisories/unreviewed/2022/05/GHSA-ffvh-x5cw-294c/GHSA-ffvh-x5cw-294c.json +++ b/advisories/unreviewed/2022/05/GHSA-ffvh-x5cw-294c/GHSA-ffvh-x5cw-294c.json @@ -7,12 +7,8 @@ "CVE-2020-24162" ], "details": "The Shenzhen Tencent app 5.8.2.5300 for PC platforms (from Tencent App Center) has a DLL hijacking vulnerability. Attackers can use this vulnerability to execute malicious code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fg6m-whg2-v39j/GHSA-fg6m-whg2-v39j.json b/advisories/unreviewed/2022/05/GHSA-fg6m-whg2-v39j/GHSA-fg6m-whg2-v39j.json index 35c01ccfccb..733df2ab957 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg6m-whg2-v39j/GHSA-fg6m-whg2-v39j.json +++ b/advisories/unreviewed/2022/05/GHSA-fg6m-whg2-v39j/GHSA-fg6m-whg2-v39j.json @@ -7,12 +7,8 @@ "CVE-2020-8346" ], "details": "A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 that could allow configuration files to be written to non-standard locations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fhhq-g694-vvfc/GHSA-fhhq-g694-vvfc.json b/advisories/unreviewed/2022/05/GHSA-fhhq-g694-vvfc/GHSA-fhhq-g694-vvfc.json index 3254c2d988e..71231578efe 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhhq-g694-vvfc/GHSA-fhhq-g694-vvfc.json +++ b/advisories/unreviewed/2022/05/GHSA-fhhq-g694-vvfc/GHSA-fhhq-g694-vvfc.json @@ -7,12 +7,8 @@ "CVE-2020-12789" ], "details": "The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fj2j-8cg9-vrj8/GHSA-fj2j-8cg9-vrj8.json b/advisories/unreviewed/2022/05/GHSA-fj2j-8cg9-vrj8/GHSA-fj2j-8cg9-vrj8.json index a57b8ddb71c..225252eaabe 100644 --- a/advisories/unreviewed/2022/05/GHSA-fj2j-8cg9-vrj8/GHSA-fj2j-8cg9-vrj8.json +++ b/advisories/unreviewed/2022/05/GHSA-fj2j-8cg9-vrj8/GHSA-fj2j-8cg9-vrj8.json @@ -7,12 +7,8 @@ "CVE-2020-13802" ], "details": "The rebar3 tool 3.0.0-beta.3 through 3.13.2 for Erlang allows remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fjmh-g39v-6932/GHSA-fjmh-g39v-6932.json b/advisories/unreviewed/2022/05/GHSA-fjmh-g39v-6932/GHSA-fjmh-g39v-6932.json index b56b199731d..0fe75baa539 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjmh-g39v-6932/GHSA-fjmh-g39v-6932.json +++ b/advisories/unreviewed/2022/05/GHSA-fjmh-g39v-6932/GHSA-fjmh-g39v-6932.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fm3h-87mp-cxq6/GHSA-fm3h-87mp-cxq6.json b/advisories/unreviewed/2022/05/GHSA-fm3h-87mp-cxq6/GHSA-fm3h-87mp-cxq6.json index c14fee82751..3f8ba63947e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm3h-87mp-cxq6/GHSA-fm3h-87mp-cxq6.json +++ b/advisories/unreviewed/2022/05/GHSA-fm3h-87mp-cxq6/GHSA-fm3h-87mp-cxq6.json @@ -7,12 +7,8 @@ "CVE-2020-24197" ], "details": "A SQL injection vulnerability in the login component in Stock Management System v1.0 allows remote attacker to execute arbitrary SQL commands via the username parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fm45-4rvc-p4fj/GHSA-fm45-4rvc-p4fj.json b/advisories/unreviewed/2022/05/GHSA-fm45-4rvc-p4fj/GHSA-fm45-4rvc-p4fj.json index fb435e9f6a8..81a08dfd283 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm45-4rvc-p4fj/GHSA-fm45-4rvc-p4fj.json +++ b/advisories/unreviewed/2022/05/GHSA-fm45-4rvc-p4fj/GHSA-fm45-4rvc-p4fj.json @@ -7,12 +7,8 @@ "CVE-2020-0274" ], "details": "In the OMX parser, there is a possible information disclosure due to a returned raw pointer. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-120781925", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fm67-vpp9-99gh/GHSA-fm67-vpp9-99gh.json b/advisories/unreviewed/2022/05/GHSA-fm67-vpp9-99gh/GHSA-fm67-vpp9-99gh.json index c2482309a4f..80171f5f5c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm67-vpp9-99gh/GHSA-fm67-vpp9-99gh.json +++ b/advisories/unreviewed/2022/05/GHSA-fm67-vpp9-99gh/GHSA-fm67-vpp9-99gh.json @@ -7,12 +7,8 @@ "CVE-2020-13287" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could see confidential EPIC attached to confidential issues", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fp7j-v4gh-x2v3/GHSA-fp7j-v4gh-x2v3.json b/advisories/unreviewed/2022/05/GHSA-fp7j-v4gh-x2v3/GHSA-fp7j-v4gh-x2v3.json index e9db3defb95..fef87b43450 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp7j-v4gh-x2v3/GHSA-fp7j-v4gh-x2v3.json +++ b/advisories/unreviewed/2022/05/GHSA-fp7j-v4gh-x2v3/GHSA-fp7j-v4gh-x2v3.json @@ -7,12 +7,8 @@ "CVE-2020-0426" ], "details": "In SyncManager, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154921790", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpc4-498c-4336/GHSA-fpc4-498c-4336.json b/advisories/unreviewed/2022/05/GHSA-fpc4-498c-4336/GHSA-fpc4-498c-4336.json index ffcdebddd0d..f5e6fe9f9d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpc4-498c-4336/GHSA-fpc4-498c-4336.json +++ b/advisories/unreviewed/2022/05/GHSA-fpc4-498c-4336/GHSA-fpc4-498c-4336.json @@ -7,12 +7,8 @@ "CVE-2020-3619" ], "details": "u'Non-secure memory is touched multiple times during TrustZone\\u2019s execution and can lead to privilege escalation or memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8098, IPQ8074, Kamorta, MDM9150, MDM9206, MDM9607, MDM9650, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8998, QCA8081, QCS404, QCS605, QCS610, QM215, Rennell, SA415M, SC7180, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SM6150, SM7150, SM8150, SXR1130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpqw-rp77-mwjr/GHSA-fpqw-rp77-mwjr.json b/advisories/unreviewed/2022/05/GHSA-fpqw-rp77-mwjr/GHSA-fpqw-rp77-mwjr.json index 71279834411..69d7b5b4f0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpqw-rp77-mwjr/GHSA-fpqw-rp77-mwjr.json +++ b/advisories/unreviewed/2022/05/GHSA-fpqw-rp77-mwjr/GHSA-fpqw-rp77-mwjr.json @@ -7,12 +7,8 @@ "CVE-2020-4516" ], "details": "IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182371.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fr6g-wwff-7837/GHSA-fr6g-wwff-7837.json b/advisories/unreviewed/2022/05/GHSA-fr6g-wwff-7837/GHSA-fr6g-wwff-7837.json index e99a5960a76..a6d4a948f88 100644 --- a/advisories/unreviewed/2022/05/GHSA-fr6g-wwff-7837/GHSA-fr6g-wwff-7837.json +++ b/advisories/unreviewed/2022/05/GHSA-fr6g-wwff-7837/GHSA-fr6g-wwff-7837.json @@ -7,12 +7,8 @@ "CVE-2020-6334" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated SKP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fvgh-hcc6-c2q5/GHSA-fvgh-hcc6-c2q5.json b/advisories/unreviewed/2022/05/GHSA-fvgh-hcc6-c2q5/GHSA-fvgh-hcc6-c2q5.json index 628292cb390..158c46025b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvgh-hcc6-c2q5/GHSA-fvgh-hcc6-c2q5.json +++ b/advisories/unreviewed/2022/05/GHSA-fvgh-hcc6-c2q5/GHSA-fvgh-hcc6-c2q5.json @@ -7,12 +7,8 @@ "CVE-2020-2037" ], "details": "An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PAN-OS 9.0 versions earlier than PAN-OS 9.0.10; PAN-OS 9.1 versions earlier than PAN-OS 9.1.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fw2x-mx3p-5gr5/GHSA-fw2x-mx3p-5gr5.json b/advisories/unreviewed/2022/05/GHSA-fw2x-mx3p-5gr5/GHSA-fw2x-mx3p-5gr5.json index 6a8d4df9f9c..9513c364259 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw2x-mx3p-5gr5/GHSA-fw2x-mx3p-5gr5.json +++ b/advisories/unreviewed/2022/05/GHSA-fw2x-mx3p-5gr5/GHSA-fw2x-mx3p-5gr5.json @@ -7,12 +7,8 @@ "CVE-2020-25412" ], "details": "gnuplot 5.4 is affected by a segmentation fault in com_line () at command.c, which may result in context-dependent arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwp6-grrh-7hj9/GHSA-fwp6-grrh-7hj9.json b/advisories/unreviewed/2022/05/GHSA-fwp6-grrh-7hj9/GHSA-fwp6-grrh-7hj9.json index eef17d1dc81..9a6322ab9a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwp6-grrh-7hj9/GHSA-fwp6-grrh-7hj9.json +++ b/advisories/unreviewed/2022/05/GHSA-fwp6-grrh-7hj9/GHSA-fwp6-grrh-7hj9.json @@ -7,12 +7,8 @@ "CVE-2020-11699" ], "details": "An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execute remote code on the target server. The user has to be authenticated before interacting with this page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g2x3-q23p-vv87/GHSA-g2x3-q23p-vv87.json b/advisories/unreviewed/2022/05/GHSA-g2x3-q23p-vv87/GHSA-g2x3-q23p-vv87.json index bd74748455c..cc01d8a012a 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2x3-q23p-vv87/GHSA-g2x3-q23p-vv87.json +++ b/advisories/unreviewed/2022/05/GHSA-g2x3-q23p-vv87/GHSA-g2x3-q23p-vv87.json @@ -7,12 +7,8 @@ "CVE-2020-11118" ], "details": "u'Information exposure issues while processing IE header due to improper check of beacon IE frame' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, Kamorta, MDM9150, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8998, Nicobar, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCM2150, QCN7605, QCS405, QCS605, QCS610, QM215, Rennell, Saipan, SC8180X, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g2xv-m9xg-ww4x/GHSA-g2xv-m9xg-ww4x.json b/advisories/unreviewed/2022/05/GHSA-g2xv-m9xg-ww4x/GHSA-g2xv-m9xg-ww4x.json index 067e9d73d9b..b3d12eb8029 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2xv-m9xg-ww4x/GHSA-g2xv-m9xg-ww4x.json +++ b/advisories/unreviewed/2022/05/GHSA-g2xv-m9xg-ww4x/GHSA-g2xv-m9xg-ww4x.json @@ -7,12 +7,8 @@ "CVE-2020-0270" ], "details": "In tremolo, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-145790628", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g434-x599-83p4/GHSA-g434-x599-83p4.json b/advisories/unreviewed/2022/05/GHSA-g434-x599-83p4/GHSA-g434-x599-83p4.json index fda3b17f6c7..997fe6b8383 100644 --- a/advisories/unreviewed/2022/05/GHSA-g434-x599-83p4/GHSA-g434-x599-83p4.json +++ b/advisories/unreviewed/2022/05/GHSA-g434-x599-83p4/GHSA-g434-x599-83p4.json @@ -7,12 +7,8 @@ "CVE-2020-6288" ], "details": "SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to upload any file (including script files) without proper file format validation leading to Unrestricted upload of file with dangerous type vulnerability. The attacker can modify some formulas and display erroneous content. The server is not affected only the current user browser session, that can easily be closed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g5gf-f7rm-39qx/GHSA-g5gf-f7rm-39qx.json b/advisories/unreviewed/2022/05/GHSA-g5gf-f7rm-39qx/GHSA-g5gf-f7rm-39qx.json index 8213491b20f..bd7d3ca9fa0 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5gf-f7rm-39qx/GHSA-g5gf-f7rm-39qx.json +++ b/advisories/unreviewed/2022/05/GHSA-g5gf-f7rm-39qx/GHSA-g5gf-f7rm-39qx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g64w-x6g2-6j38/GHSA-g64w-x6g2-6j38.json b/advisories/unreviewed/2022/05/GHSA-g64w-x6g2-6j38/GHSA-g64w-x6g2-6j38.json index d4fa8184598..5156d8c1909 100644 --- a/advisories/unreviewed/2022/05/GHSA-g64w-x6g2-6j38/GHSA-g64w-x6g2-6j38.json +++ b/advisories/unreviewed/2022/05/GHSA-g64w-x6g2-6j38/GHSA-g64w-x6g2-6j38.json @@ -7,12 +7,8 @@ "CVE-2020-6283" ], "details": "SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, resulting in reflected Cross-Site Scripting (XSS) vulnerability. With a successful attack, the attacker can steal authentication information of the user, such as data relating to his or her current session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g6jf-362c-2h5x/GHSA-g6jf-362c-2h5x.json b/advisories/unreviewed/2022/05/GHSA-g6jf-362c-2h5x/GHSA-g6jf-362c-2h5x.json index fbbf42d61f3..a40041ff009 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6jf-362c-2h5x/GHSA-g6jf-362c-2h5x.json +++ b/advisories/unreviewed/2022/05/GHSA-g6jf-362c-2h5x/GHSA-g6jf-362c-2h5x.json @@ -7,12 +7,8 @@ "CVE-2019-13995" ], "details": "u'Lack of integer overflow check for addition of fragment size and remaining size that are read from shared memory can lead to memory corruption and potential information leakage' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g82p-qfjv-w56j/GHSA-g82p-qfjv-w56j.json b/advisories/unreviewed/2022/05/GHSA-g82p-qfjv-w56j/GHSA-g82p-qfjv-w56j.json index 4bfe2c0cf0e..9e11dc63d40 100644 --- a/advisories/unreviewed/2022/05/GHSA-g82p-qfjv-w56j/GHSA-g82p-qfjv-w56j.json +++ b/advisories/unreviewed/2022/05/GHSA-g82p-qfjv-w56j/GHSA-g82p-qfjv-w56j.json @@ -7,12 +7,8 @@ "CVE-2020-25380" ], "details": "Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 is affected by: Cross Site Scripting (XSS) via the 'Recall Settings' field in admin.php. An attacker can inject JavaScript code that will be stored and executed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g854-fc3p-gq33/GHSA-g854-fc3p-gq33.json b/advisories/unreviewed/2022/05/GHSA-g854-fc3p-gq33/GHSA-g854-fc3p-gq33.json index 5fb7afbf39f..7cf0667c774 100644 --- a/advisories/unreviewed/2022/05/GHSA-g854-fc3p-gq33/GHSA-g854-fc3p-gq33.json +++ b/advisories/unreviewed/2022/05/GHSA-g854-fc3p-gq33/GHSA-g854-fc3p-gq33.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g897-jj46-x2pc/GHSA-g897-jj46-x2pc.json b/advisories/unreviewed/2022/05/GHSA-g897-jj46-x2pc/GHSA-g897-jj46-x2pc.json index 15aa30187f8..b73e35ca89a 100644 --- a/advisories/unreviewed/2022/05/GHSA-g897-jj46-x2pc/GHSA-g897-jj46-x2pc.json +++ b/advisories/unreviewed/2022/05/GHSA-g897-jj46-x2pc/GHSA-g897-jj46-x2pc.json @@ -7,12 +7,8 @@ "CVE-2020-0292" ], "details": "In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges and a compromised Firmware needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-110107252", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g8f7-67xp-2h72/GHSA-g8f7-67xp-2h72.json b/advisories/unreviewed/2022/05/GHSA-g8f7-67xp-2h72/GHSA-g8f7-67xp-2h72.json index a2c567b0ea0..8ffce2d2e98 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8f7-67xp-2h72/GHSA-g8f7-67xp-2h72.json +++ b/advisories/unreviewed/2022/05/GHSA-g8f7-67xp-2h72/GHSA-g8f7-67xp-2h72.json @@ -7,12 +7,8 @@ "CVE-2020-24457" ], "details": "Logic error in BIOS firmware for 8th, 9th and 10th Generation Intel(R) Core(TM) Processors may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g8jr-rhv6-h7cj/GHSA-g8jr-rhv6-h7cj.json b/advisories/unreviewed/2022/05/GHSA-g8jr-rhv6-h7cj/GHSA-g8jr-rhv6-h7cj.json index 19da8fa07ec..40714b1d637 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8jr-rhv6-h7cj/GHSA-g8jr-rhv6-h7cj.json +++ b/advisories/unreviewed/2022/05/GHSA-g8jr-rhv6-h7cj/GHSA-g8jr-rhv6-h7cj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g97f-pgv6-f75q/GHSA-g97f-pgv6-f75q.json b/advisories/unreviewed/2022/05/GHSA-g97f-pgv6-f75q/GHSA-g97f-pgv6-f75q.json index 131db61f0f1..3de65f72dfc 100644 --- a/advisories/unreviewed/2022/05/GHSA-g97f-pgv6-f75q/GHSA-g97f-pgv6-f75q.json +++ b/advisories/unreviewed/2022/05/GHSA-g97f-pgv6-f75q/GHSA-g97f-pgv6-f75q.json @@ -7,12 +7,8 @@ "CVE-2020-0385" ], "details": "In Parse_insh of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote information disclosure in the media extractor with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.0 Android-8.1Android ID: A-150160041", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gc37-937w-g8g4/GHSA-gc37-937w-g8g4.json b/advisories/unreviewed/2022/05/GHSA-gc37-937w-g8g4/GHSA-gc37-937w-g8g4.json index b115d09538e..cf740edbbbd 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc37-937w-g8g4/GHSA-gc37-937w-g8g4.json +++ b/advisories/unreviewed/2022/05/GHSA-gc37-937w-g8g4/GHSA-gc37-937w-g8g4.json @@ -7,12 +7,8 @@ "CVE-2020-0387" ], "details": "In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. This could lead to local escalation of privilege and account hijacking with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-156046804", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gch3-m29m-g8x5/GHSA-gch3-m29m-g8x5.json b/advisories/unreviewed/2022/05/GHSA-gch3-m29m-g8x5/GHSA-gch3-m29m-g8x5.json index 5ce3c245370..da3cf765296 100644 --- a/advisories/unreviewed/2022/05/GHSA-gch3-m29m-g8x5/GHSA-gch3-m29m-g8x5.json +++ b/advisories/unreviewed/2022/05/GHSA-gch3-m29m-g8x5/GHSA-gch3-m29m-g8x5.json @@ -7,12 +7,8 @@ "CVE-2020-16100" ], "details": "It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websocket thread due to improper shutdown of closed websocket connections, preventing it from accepting future DCOM websocket (Configuration Client) connections. Affected versions are v8.20 prior to v8.20.1166(MR3), v8.10 prior to v8.10.1211(MR5), v8.00 prior to v8.00.1228(MR6), all versions of 7.90 and earlier.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gcmp-gqmg-54q5/GHSA-gcmp-gqmg-54q5.json b/advisories/unreviewed/2022/05/GHSA-gcmp-gqmg-54q5/GHSA-gcmp-gqmg-54q5.json index 7a5d524e1c7..eb8a4d5e1ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcmp-gqmg-54q5/GHSA-gcmp-gqmg-54q5.json +++ b/advisories/unreviewed/2022/05/GHSA-gcmp-gqmg-54q5/GHSA-gcmp-gqmg-54q5.json @@ -7,12 +7,8 @@ "CVE-2020-25378" ], "details": "Wordpress Plugin Store / AccessPress Themes WP Floating Menu V1.3.0 is affected by: Cross Site Scripting (XSS) via the id GET parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gcx8-mff3-89cc/GHSA-gcx8-mff3-89cc.json b/advisories/unreviewed/2022/05/GHSA-gcx8-mff3-89cc/GHSA-gcx8-mff3-89cc.json index a00c80cec3c..06e4b8dd160 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcx8-mff3-89cc/GHSA-gcx8-mff3-89cc.json +++ b/advisories/unreviewed/2022/05/GHSA-gcx8-mff3-89cc/GHSA-gcx8-mff3-89cc.json @@ -7,12 +7,8 @@ "CVE-2020-0434" ], "details": "In Pixel's use of the Catpipe library, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-150730508", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gg39-h2qq-j648/GHSA-gg39-h2qq-j648.json b/advisories/unreviewed/2022/05/GHSA-gg39-h2qq-j648/GHSA-gg39-h2qq-j648.json index c9bc9438881..795d5f2c425 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg39-h2qq-j648/GHSA-gg39-h2qq-j648.json +++ b/advisories/unreviewed/2022/05/GHSA-gg39-h2qq-j648/GHSA-gg39-h2qq-j648.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gg7x-fw4x-98xm/GHSA-gg7x-fw4x-98xm.json b/advisories/unreviewed/2022/05/GHSA-gg7x-fw4x-98xm/GHSA-gg7x-fw4x-98xm.json index 00c8c7aae1f..5b64092f3e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg7x-fw4x-98xm/GHSA-gg7x-fw4x-98xm.json +++ b/advisories/unreviewed/2022/05/GHSA-gg7x-fw4x-98xm/GHSA-gg7x-fw4x-98xm.json @@ -7,12 +7,8 @@ "CVE-2020-6339" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated BMP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gggv-m5vq-8f9m/GHSA-gggv-m5vq-8f9m.json b/advisories/unreviewed/2022/05/GHSA-gggv-m5vq-8f9m/GHSA-gggv-m5vq-8f9m.json index 94ebcbe0797..a49b7b71365 100644 --- a/advisories/unreviewed/2022/05/GHSA-gggv-m5vq-8f9m/GHSA-gggv-m5vq-8f9m.json +++ b/advisories/unreviewed/2022/05/GHSA-gggv-m5vq-8f9m/GHSA-gggv-m5vq-8f9m.json @@ -7,12 +7,8 @@ "CVE-2019-14074" ], "details": "u'Heap overflow in diag command handler due to lack of check of packet length received from user' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8076, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9207C, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ggpp-fxg5-wp87/GHSA-ggpp-fxg5-wp87.json b/advisories/unreviewed/2022/05/GHSA-ggpp-fxg5-wp87/GHSA-ggpp-fxg5-wp87.json index 2d0f8df8d3a..989ca8d8507 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggpp-fxg5-wp87/GHSA-ggpp-fxg5-wp87.json +++ b/advisories/unreviewed/2022/05/GHSA-ggpp-fxg5-wp87/GHSA-ggpp-fxg5-wp87.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gjg7-84q3-g73j/GHSA-gjg7-84q3-g73j.json b/advisories/unreviewed/2022/05/GHSA-gjg7-84q3-g73j/GHSA-gjg7-84q3-g73j.json index 6b8b5faa031..10f50369fb3 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjg7-84q3-g73j/GHSA-gjg7-84q3-g73j.json +++ b/advisories/unreviewed/2022/05/GHSA-gjg7-84q3-g73j/GHSA-gjg7-84q3-g73j.json @@ -7,12 +7,8 @@ "CVE-2020-9731" ], "details": "A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gjg9-57mm-9w78/GHSA-gjg9-57mm-9w78.json b/advisories/unreviewed/2022/05/GHSA-gjg9-57mm-9w78/GHSA-gjg9-57mm-9w78.json index f4f44f3e433..aaffd2542e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjg9-57mm-9w78/GHSA-gjg9-57mm-9w78.json +++ b/advisories/unreviewed/2022/05/GHSA-gjg9-57mm-9w78/GHSA-gjg9-57mm-9w78.json @@ -7,12 +7,8 @@ "CVE-2020-0229" ], "details": "There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-156333725", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gjrf-43fc-j4c9/GHSA-gjrf-43fc-j4c9.json b/advisories/unreviewed/2022/05/GHSA-gjrf-43fc-j4c9/GHSA-gjrf-43fc-j4c9.json index b85c3e53970..34709ac346d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjrf-43fc-j4c9/GHSA-gjrf-43fc-j4c9.json +++ b/advisories/unreviewed/2022/05/GHSA-gjrf-43fc-j4c9/GHSA-gjrf-43fc-j4c9.json @@ -7,12 +7,8 @@ "CVE-2020-6322" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated 3DM file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gqwc-24f2-x3gv/GHSA-gqwc-24f2-x3gv.json b/advisories/unreviewed/2022/05/GHSA-gqwc-24f2-x3gv/GHSA-gqwc-24f2-x3gv.json index 8bc6b9356d5..1e1808881d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqwc-24f2-x3gv/GHSA-gqwc-24f2-x3gv.json +++ b/advisories/unreviewed/2022/05/GHSA-gqwc-24f2-x3gv/GHSA-gqwc-24f2-x3gv.json @@ -7,12 +7,8 @@ "CVE-2020-11122" ], "details": "u'Null Pointer exception while playing crafted mkv file as data stream get deleted on secondary invalid configuration' in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile in APQ8098, Bitra, Kamorta, SA6155P, Saipan, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-grrv-5267-gqgj/GHSA-grrv-5267-gqgj.json b/advisories/unreviewed/2022/05/GHSA-grrv-5267-gqgj/GHSA-grrv-5267-gqgj.json index 9970d6985e9..c4727d4a50b 100644 --- a/advisories/unreviewed/2022/05/GHSA-grrv-5267-gqgj/GHSA-grrv-5267-gqgj.json +++ b/advisories/unreviewed/2022/05/GHSA-grrv-5267-gqgj/GHSA-grrv-5267-gqgj.json @@ -7,12 +7,8 @@ "CVE-2020-0369" ], "details": "In libavb, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-130231426", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gvcw-4w76-f962/GHSA-gvcw-4w76-f962.json b/advisories/unreviewed/2022/05/GHSA-gvcw-4w76-f962/GHSA-gvcw-4w76-f962.json index de9f01e02ac..3646ea45296 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvcw-4w76-f962/GHSA-gvcw-4w76-f962.json +++ b/advisories/unreviewed/2022/05/GHSA-gvcw-4w76-f962/GHSA-gvcw-4w76-f962.json @@ -7,12 +7,8 @@ "CVE-2020-24159" ], "details": "NetEase Youdao Dictionary has a DLL hijacking vulnerability, which can be exploited by attackers to gain server permissions. This affects Guangzhou NetEase Youdao Dictionary 8.9.2.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gvwj-prfg-6229/GHSA-gvwj-prfg-6229.json b/advisories/unreviewed/2022/05/GHSA-gvwj-prfg-6229/GHSA-gvwj-prfg-6229.json index 52dae46538c..ccab6293b5b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvwj-prfg-6229/GHSA-gvwj-prfg-6229.json +++ b/advisories/unreviewed/2022/05/GHSA-gvwj-prfg-6229/GHSA-gvwj-prfg-6229.json @@ -7,12 +7,8 @@ "CVE-2020-9725" ], "details": "Adobe FrameMaker version 2019.0.6 (and earlier versions) lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. This could be exploited to execute arbitrary code with the privileges of the current user. User interaction is required to exploit this vulnerability in that the target must open a malicious FrameMaker file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gw77-j7h4-w4jv/GHSA-gw77-j7h4-w4jv.json b/advisories/unreviewed/2022/05/GHSA-gw77-j7h4-w4jv/GHSA-gw77-j7h4-w4jv.json index eab75e55e45..d2a5211beef 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw77-j7h4-w4jv/GHSA-gw77-j7h4-w4jv.json +++ b/advisories/unreviewed/2022/05/GHSA-gw77-j7h4-w4jv/GHSA-gw77-j7h4-w4jv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gwfc-jmfj-45pc/GHSA-gwfc-jmfj-45pc.json b/advisories/unreviewed/2022/05/GHSA-gwfc-jmfj-45pc/GHSA-gwfc-jmfj-45pc.json index 2ad71947d2b..9cff052be1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwfc-jmfj-45pc/GHSA-gwfc-jmfj-45pc.json +++ b/advisories/unreviewed/2022/05/GHSA-gwfc-jmfj-45pc/GHSA-gwfc-jmfj-45pc.json @@ -7,12 +7,8 @@ "CVE-2020-9729" ], "details": "A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gwrq-4r66-jcc3/GHSA-gwrq-4r66-jcc3.json b/advisories/unreviewed/2022/05/GHSA-gwrq-4r66-jcc3/GHSA-gwrq-4r66-jcc3.json index b68673ff6ee..b6bfcaed5cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwrq-4r66-jcc3/GHSA-gwrq-4r66-jcc3.json +++ b/advisories/unreviewed/2022/05/GHSA-gwrq-4r66-jcc3/GHSA-gwrq-4r66-jcc3.json @@ -7,12 +7,8 @@ "CVE-2020-11128" ], "details": "u'Possible out of bound access while copying the mask file content into the buffer without checking the buffer size' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8096AU, APQ8098, Bitra, Kamorta, MDM9150, MDM9607, MDM9650, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8998, QCM2150, QCS405, QCS605, QCS610, QM215, Rennell, SA515M, SA6155P, Saipan, SC8180X, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM660, SDM670, SDM710, SDM845, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gxx3-mxqr-fwjw/GHSA-gxx3-mxqr-fwjw.json b/advisories/unreviewed/2022/05/GHSA-gxx3-mxqr-fwjw/GHSA-gxx3-mxqr-fwjw.json index 5f06d0bdcc5..4620b8352ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxx3-mxqr-fwjw/GHSA-gxx3-mxqr-fwjw.json +++ b/advisories/unreviewed/2022/05/GHSA-gxx3-mxqr-fwjw/GHSA-gxx3-mxqr-fwjw.json @@ -7,12 +7,8 @@ "CVE-2019-14052" ], "details": "u'Accessing an uninitialized data structure could result in partially copying of contents and thus incorrect processing' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QCS610, QM215, SA415M, SC8180X, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SM6150, SM7150, SM8150, SXR1130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h338-j65w-58xw/GHSA-h338-j65w-58xw.json b/advisories/unreviewed/2022/05/GHSA-h338-j65w-58xw/GHSA-h338-j65w-58xw.json index fa8ac45d558..ebb27480401 100644 --- a/advisories/unreviewed/2022/05/GHSA-h338-j65w-58xw/GHSA-h338-j65w-58xw.json +++ b/advisories/unreviewed/2022/05/GHSA-h338-j65w-58xw/GHSA-h338-j65w-58xw.json @@ -7,12 +7,8 @@ "CVE-2020-25280" ], "details": "An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos and MediaTek chipsets) software. Unauthenticated attackers can execute LTE/5G commands by sending a debugging command over USB. The Samsung ID is SVE-2020-16979 (September 2020).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h394-hp3g-742p/GHSA-h394-hp3g-742p.json b/advisories/unreviewed/2022/05/GHSA-h394-hp3g-742p/GHSA-h394-hp3g-742p.json index 161befbe280..28750c62fce 100644 --- a/advisories/unreviewed/2022/05/GHSA-h394-hp3g-742p/GHSA-h394-hp3g-742p.json +++ b/advisories/unreviewed/2022/05/GHSA-h394-hp3g-742p/GHSA-h394-hp3g-742p.json @@ -7,12 +7,8 @@ "CVE-2020-9730" ], "details": "A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h3cc-g2jj-55gh/GHSA-h3cc-g2jj-55gh.json b/advisories/unreviewed/2022/05/GHSA-h3cc-g2jj-55gh/GHSA-h3cc-g2jj-55gh.json index cf642621bbe..cc139cd7710 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3cc-g2jj-55gh/GHSA-h3cc-g2jj-55gh.json +++ b/advisories/unreviewed/2022/05/GHSA-h3cc-g2jj-55gh/GHSA-h3cc-g2jj-55gh.json @@ -7,12 +7,8 @@ "CVE-2020-14292" ], "details": "In the COVIDSafe application through 1.0.21 for Android, unsafe use of the Bluetooth transport option in the GATT connection allows attackers to trick the application into establishing a connection over Bluetooth BR/EDR transport, which reveals the public Bluetooth address of the victim's phone without authorisation, bypassing the Bluetooth address randomisation protection in the user's phone.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h42v-738f-q57f/GHSA-h42v-738f-q57f.json b/advisories/unreviewed/2022/05/GHSA-h42v-738f-q57f/GHSA-h42v-738f-q57f.json index 06dfe0bcf39..249b4d10ec9 100644 --- a/advisories/unreviewed/2022/05/GHSA-h42v-738f-q57f/GHSA-h42v-738f-q57f.json +++ b/advisories/unreviewed/2022/05/GHSA-h42v-738f-q57f/GHSA-h42v-738f-q57f.json @@ -7,12 +7,8 @@ "CVE-2020-13302" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h436-m63j-57vj/GHSA-h436-m63j-57vj.json b/advisories/unreviewed/2022/05/GHSA-h436-m63j-57vj/GHSA-h436-m63j-57vj.json index 337ff9c4cdf..4bf10c16e8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-h436-m63j-57vj/GHSA-h436-m63j-57vj.json +++ b/advisories/unreviewed/2022/05/GHSA-h436-m63j-57vj/GHSA-h436-m63j-57vj.json @@ -7,12 +7,8 @@ "CVE-2020-6328" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h4c3-p5w7-477x/GHSA-h4c3-p5w7-477x.json b/advisories/unreviewed/2022/05/GHSA-h4c3-p5w7-477x/GHSA-h4c3-p5w7-477x.json index 487acd66e17..bade9c64acb 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4c3-p5w7-477x/GHSA-h4c3-p5w7-477x.json +++ b/advisories/unreviewed/2022/05/GHSA-h4c3-p5w7-477x/GHSA-h4c3-p5w7-477x.json @@ -7,12 +7,8 @@ "CVE-2020-25276" ], "details": "An issue was discovered in PrimeKey EJBCA 6.x and 7.x before 7.4.1. When using a client certificate to enroll over the EST protocol, no revocation check is performed on that certificate. This vulnerability can only affect a system that has EST configured, uses client certificates to authenticate enrollment, and has had such a certificate revoked. This certificate needs to belong to a role that is authorized to enroll new end entities. (To completely mitigate this problem prior to upgrade, remove any revoked client certificates from their respective roles.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h4q5-8rrj-hrj2/GHSA-h4q5-8rrj-hrj2.json b/advisories/unreviewed/2022/05/GHSA-h4q5-8rrj-hrj2/GHSA-h4q5-8rrj-hrj2.json index cc00b1c09e0..b93a0cb7d78 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4q5-8rrj-hrj2/GHSA-h4q5-8rrj-hrj2.json +++ b/advisories/unreviewed/2022/05/GHSA-h4q5-8rrj-hrj2/GHSA-h4q5-8rrj-hrj2.json @@ -7,12 +7,8 @@ "CVE-2020-3702" ], "details": "u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8053, IPQ4019, IPQ8064, MSM8909W, MSM8996AU, QCA9531, QCN5502, QCS405, SDX20, SM6150, SM7150", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h4wq-q9hr-ffm6/GHSA-h4wq-q9hr-ffm6.json b/advisories/unreviewed/2022/05/GHSA-h4wq-q9hr-ffm6/GHSA-h4wq-q9hr-ffm6.json index 6d35813e367..508ac952e91 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4wq-q9hr-ffm6/GHSA-h4wq-q9hr-ffm6.json +++ b/advisories/unreviewed/2022/05/GHSA-h4wq-q9hr-ffm6/GHSA-h4wq-q9hr-ffm6.json @@ -7,12 +7,8 @@ "CVE-2018-19947" ], "details": "The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h5m3-8vhj-cgjg/GHSA-h5m3-8vhj-cgjg.json b/advisories/unreviewed/2022/05/GHSA-h5m3-8vhj-cgjg/GHSA-h5m3-8vhj-cgjg.json index bbc8bd77b9b..8cdf9dee2dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5m3-8vhj-cgjg/GHSA-h5m3-8vhj-cgjg.json +++ b/advisories/unreviewed/2022/05/GHSA-h5m3-8vhj-cgjg/GHSA-h5m3-8vhj-cgjg.json @@ -7,12 +7,8 @@ "CVE-2020-9743" ], "details": "AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by an HTML injection vulnerability in the content editor component that allows unauthenticated users to craft an HTTP request that includes arbitrary HTML code in a parameter value. An attacker could then use the malicious GET request to lure victims to perform unsafe actions in the page (ex. phishing).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h5r8-fvh2-9qxg/GHSA-h5r8-fvh2-9qxg.json b/advisories/unreviewed/2022/05/GHSA-h5r8-fvh2-9qxg/GHSA-h5r8-fvh2-9qxg.json index f53115a6f82..a0ed502733b 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5r8-fvh2-9qxg/GHSA-h5r8-fvh2-9qxg.json +++ b/advisories/unreviewed/2022/05/GHSA-h5r8-fvh2-9qxg/GHSA-h5r8-fvh2-9qxg.json @@ -7,12 +7,8 @@ "CVE-2020-0279" ], "details": "In the AAC parser, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-131430997", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h6wh-5wqm-h86w/GHSA-h6wh-5wqm-h86w.json b/advisories/unreviewed/2022/05/GHSA-h6wh-5wqm-h86w/GHSA-h6wh-5wqm-h86w.json index ad8716732e7..20eb0b402bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6wh-5wqm-h86w/GHSA-h6wh-5wqm-h86w.json +++ b/advisories/unreviewed/2022/05/GHSA-h6wh-5wqm-h86w/GHSA-h6wh-5wqm-h86w.json @@ -7,12 +7,8 @@ "CVE-2020-10228" ], "details": "A file upload vulnerability in vtecrm vtenext 19 CE allows authenticated users to upload files with a .pht extension, resulting in remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h74r-xh5r-h54x/GHSA-h74r-xh5r-h54x.json b/advisories/unreviewed/2022/05/GHSA-h74r-xh5r-h54x/GHSA-h74r-xh5r-h54x.json index d41bf87a670..98cc224c8c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-h74r-xh5r-h54x/GHSA-h74r-xh5r-h54x.json +++ b/advisories/unreviewed/2022/05/GHSA-h74r-xh5r-h54x/GHSA-h74r-xh5r-h54x.json @@ -7,12 +7,8 @@ "CVE-2020-0265" ], "details": "In Telephony, there are possible leaks of sensitive data due to missing permission checks. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150155839", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hcrp-2jqr-cf9w/GHSA-hcrp-2jqr-cf9w.json b/advisories/unreviewed/2022/05/GHSA-hcrp-2jqr-cf9w/GHSA-hcrp-2jqr-cf9w.json index f20b72a19f5..685bb333829 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcrp-2jqr-cf9w/GHSA-hcrp-2jqr-cf9w.json +++ b/advisories/unreviewed/2022/05/GHSA-hcrp-2jqr-cf9w/GHSA-hcrp-2jqr-cf9w.json @@ -7,12 +7,8 @@ "CVE-2020-3640" ], "details": "u'Resizing the usage table header before passing all the checks leads to the function exiting with a usage table in invalid state when a HLOS adversary calls the function with wrong input' in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Bitra, Kamorta, QCS404, QCS610, Rennell, Saipan, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hcwc-2gm5-v9g6/GHSA-hcwc-2gm5-v9g6.json b/advisories/unreviewed/2022/05/GHSA-hcwc-2gm5-v9g6/GHSA-hcwc-2gm5-v9g6.json index 25962fce65a..2088c2ee3d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcwc-2gm5-v9g6/GHSA-hcwc-2gm5-v9g6.json +++ b/advisories/unreviewed/2022/05/GHSA-hcwc-2gm5-v9g6/GHSA-hcwc-2gm5-v9g6.json @@ -7,12 +7,8 @@ "CVE-2020-13315" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The profile activity page was not restricting the amount of results one could request, potentially resulting in a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hfhh-qrv3-cq79/GHSA-hfhh-qrv3-cq79.json b/advisories/unreviewed/2022/05/GHSA-hfhh-qrv3-cq79/GHSA-hfhh-qrv3-cq79.json index cd1d7c013c7..cc740b337e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfhh-qrv3-cq79/GHSA-hfhh-qrv3-cq79.json +++ b/advisories/unreviewed/2022/05/GHSA-hfhh-qrv3-cq79/GHSA-hfhh-qrv3-cq79.json @@ -7,12 +7,8 @@ "CVE-2020-24924" ], "details": "A Persistent Cross-site Scripting vulnerability is found in ElkarBackup v1.3.3, where an attacker can steal the user session cookie using this vulnerability present on Policies >> action >> Name Parameter", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hfpp-6hrw-77h9/GHSA-hfpp-6hrw-77h9.json b/advisories/unreviewed/2022/05/GHSA-hfpp-6hrw-77h9/GHSA-hfpp-6hrw-77h9.json index 6f90711168d..6f6d25d5419 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfpp-6hrw-77h9/GHSA-hfpp-6hrw-77h9.json +++ b/advisories/unreviewed/2022/05/GHSA-hfpp-6hrw-77h9/GHSA-hfpp-6hrw-77h9.json @@ -7,12 +7,8 @@ "CVE-2020-11803" ], "details": "An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could lead to PHP code evaluation server-side, because the user-provided input is passed directly to the php eval() function. The user has to be authenticated on the web platform before interacting with the page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hfqh-j6f7-843f/GHSA-hfqh-j6f7-843f.json b/advisories/unreviewed/2022/05/GHSA-hfqh-j6f7-843f/GHSA-hfqh-j6f7-843f.json index c7ea5defa41..1560dcb2943 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfqh-j6f7-843f/GHSA-hfqh-j6f7-843f.json +++ b/advisories/unreviewed/2022/05/GHSA-hfqh-j6f7-843f/GHSA-hfqh-j6f7-843f.json @@ -7,12 +7,8 @@ "CVE-2020-6333" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated 3DM file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hj38-v83c-6gx2/GHSA-hj38-v83c-6gx2.json b/advisories/unreviewed/2022/05/GHSA-hj38-v83c-6gx2/GHSA-hj38-v83c-6gx2.json index 0875c580a17..ae49a46eea1 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj38-v83c-6gx2/GHSA-hj38-v83c-6gx2.json +++ b/advisories/unreviewed/2022/05/GHSA-hj38-v83c-6gx2/GHSA-hj38-v83c-6gx2.json @@ -7,12 +7,8 @@ "CVE-2020-12621" ], "details": "The Teamwire application 5.3.0 for Android allows physically proximate attackers to exploit a flaw related to the pass-code component.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjhv-rf4c-xwpv/GHSA-hjhv-rf4c-xwpv.json b/advisories/unreviewed/2022/05/GHSA-hjhv-rf4c-xwpv/GHSA-hjhv-rf4c-xwpv.json index 6ff278fcaac..c8b5842a49f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjhv-rf4c-xwpv/GHSA-hjhv-rf4c-xwpv.json +++ b/advisories/unreviewed/2022/05/GHSA-hjhv-rf4c-xwpv/GHSA-hjhv-rf4c-xwpv.json @@ -7,12 +7,8 @@ "CVE-2020-4530" ], "details": "IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-ForceID: 182714.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hm8v-p29w-fjv8/GHSA-hm8v-p29w-fjv8.json b/advisories/unreviewed/2022/05/GHSA-hm8v-p29w-fjv8/GHSA-hm8v-p29w-fjv8.json index 87df855217c..3eeefa64943 100644 --- a/advisories/unreviewed/2022/05/GHSA-hm8v-p29w-fjv8/GHSA-hm8v-p29w-fjv8.json +++ b/advisories/unreviewed/2022/05/GHSA-hm8v-p29w-fjv8/GHSA-hm8v-p29w-fjv8.json @@ -7,12 +7,8 @@ "CVE-2020-24376" ], "details": "A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox Server before 4.2.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hmrm-3xmg-v873/GHSA-hmrm-3xmg-v873.json b/advisories/unreviewed/2022/05/GHSA-hmrm-3xmg-v873/GHSA-hmrm-3xmg-v873.json index 51db42df49f..0fef4d9b9eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-hmrm-3xmg-v873/GHSA-hmrm-3xmg-v873.json +++ b/advisories/unreviewed/2022/05/GHSA-hmrm-3xmg-v873/GHSA-hmrm-3xmg-v873.json @@ -7,12 +7,8 @@ "CVE-2020-10767" ], "details": "A flaw was found in the Linux kernel before 5.8-rc1 in the implementation of the Enhanced IBPB (Indirect Branch Prediction Barrier). The IBPB mitigation will be disabled when STIBP is not available or when the Enhanced Indirect Branch Restricted Speculation (IBRS) is available. This flaw allows a local attacker to perform a Spectre V2 style attack when this configuration is active. The highest threat from this vulnerability is to confidentiality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hqvx-g6jw-22pw/GHSA-hqvx-g6jw-22pw.json b/advisories/unreviewed/2022/05/GHSA-hqvx-g6jw-22pw/GHSA-hqvx-g6jw-22pw.json index 38b4c916cec..abce2f9d76f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqvx-g6jw-22pw/GHSA-hqvx-g6jw-22pw.json +++ b/advisories/unreviewed/2022/05/GHSA-hqvx-g6jw-22pw/GHSA-hqvx-g6jw-22pw.json @@ -7,12 +7,8 @@ "CVE-2020-14517" ], "details": "Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hqx3-2rj3-qx6v/GHSA-hqx3-2rj3-qx6v.json b/advisories/unreviewed/2022/05/GHSA-hqx3-2rj3-qx6v/GHSA-hqx3-2rj3-qx6v.json index d10f6202ca9..e212353f013 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqx3-2rj3-qx6v/GHSA-hqx3-2rj3-qx6v.json +++ b/advisories/unreviewed/2022/05/GHSA-hqx3-2rj3-qx6v/GHSA-hqx3-2rj3-qx6v.json @@ -7,12 +7,8 @@ "CVE-2020-7528" ], "details": "A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which could allow arbitrary code execution when an attacker builds a custom .PRJ file containing a malicious serialized buffer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hr2h-x3c6-5767/GHSA-hr2h-x3c6-5767.json b/advisories/unreviewed/2022/05/GHSA-hr2h-x3c6-5767/GHSA-hr2h-x3c6-5767.json index 6d393d3eace..284b5971ba3 100644 --- a/advisories/unreviewed/2022/05/GHSA-hr2h-x3c6-5767/GHSA-hr2h-x3c6-5767.json +++ b/advisories/unreviewed/2022/05/GHSA-hr2h-x3c6-5767/GHSA-hr2h-x3c6-5767.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvg4-4g92-cp78/GHSA-hvg4-4g92-cp78.json b/advisories/unreviewed/2022/05/GHSA-hvg4-4g92-cp78/GHSA-hvg4-4g92-cp78.json index e0f69057877..34916145472 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvg4-4g92-cp78/GHSA-hvg4-4g92-cp78.json +++ b/advisories/unreviewed/2022/05/GHSA-hvg4-4g92-cp78/GHSA-hvg4-4g92-cp78.json @@ -7,12 +7,8 @@ "CVE-2020-3644" ], "details": "u'Information disclosure issue occurs as in current logic Secure Touch session is released without terminating display session' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8096AU, APQ8098, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9650, MSM8905, MSM8909, MSM8996, MSM8996AU, MSM8998, Nicobar, QCS404, QCS405, QCS605, QCS610, Rennell, SA415M, SA515M, SA6155P, SC7180, SC8180X, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hw3r-8g7v-p8rq/GHSA-hw3r-8g7v-p8rq.json b/advisories/unreviewed/2022/05/GHSA-hw3r-8g7v-p8rq/GHSA-hw3r-8g7v-p8rq.json index 0675bb319fc..8db4ed69095 100644 --- a/advisories/unreviewed/2022/05/GHSA-hw3r-8g7v-p8rq/GHSA-hw3r-8g7v-p8rq.json +++ b/advisories/unreviewed/2022/05/GHSA-hw3r-8g7v-p8rq/GHSA-hw3r-8g7v-p8rq.json @@ -7,12 +7,8 @@ "CVE-2020-7293" ], "details": "Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user with low permissions to change the system's root password via improper access controls in the user interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hwmg-8436-r7fw/GHSA-hwmg-8436-r7fw.json b/advisories/unreviewed/2022/05/GHSA-hwmg-8436-r7fw/GHSA-hwmg-8436-r7fw.json index 862142627e0..0112dc02ab7 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwmg-8436-r7fw/GHSA-hwmg-8436-r7fw.json +++ b/advisories/unreviewed/2022/05/GHSA-hwmg-8436-r7fw/GHSA-hwmg-8436-r7fw.json @@ -7,12 +7,8 @@ "CVE-2019-14117" ], "details": "u'Whenever the page list is updated via privileged user, the previous list elements are freed but are not deleted from the list which results in a use after free causing an unhandled page fault exception in rmnet driver' in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in Bitra, MDM9607, QCS405, Saipan, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hx54-chxq-7878/GHSA-hx54-chxq-7878.json b/advisories/unreviewed/2022/05/GHSA-hx54-chxq-7878/GHSA-hx54-chxq-7878.json index 92474aee576..63cb7927b0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx54-chxq-7878/GHSA-hx54-chxq-7878.json +++ b/advisories/unreviewed/2022/05/GHSA-hx54-chxq-7878/GHSA-hx54-chxq-7878.json @@ -7,12 +7,8 @@ "CVE-2018-17770" ], "details": "Ingenico Telium 2 POS terminals have a buffer overflow via the RemotePutFile command of the NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j25r-mrm6-h8pw/GHSA-j25r-mrm6-h8pw.json b/advisories/unreviewed/2022/05/GHSA-j25r-mrm6-h8pw/GHSA-j25r-mrm6-h8pw.json index 12c316ddda2..6af4bfe4b8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-j25r-mrm6-h8pw/GHSA-j25r-mrm6-h8pw.json +++ b/advisories/unreviewed/2022/05/GHSA-j25r-mrm6-h8pw/GHSA-j25r-mrm6-h8pw.json @@ -7,12 +7,8 @@ "CVE-2020-5780" ], "details": "Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated attacker to conduct unauthenticated email forgery/spoofing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j5fp-59mp-fgm2/GHSA-j5fp-59mp-fgm2.json b/advisories/unreviewed/2022/05/GHSA-j5fp-59mp-fgm2/GHSA-j5fp-59mp-fgm2.json index 7283e77c293..0060bb0d1c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5fp-59mp-fgm2/GHSA-j5fp-59mp-fgm2.json +++ b/advisories/unreviewed/2022/05/GHSA-j5fp-59mp-fgm2/GHSA-j5fp-59mp-fgm2.json @@ -7,12 +7,8 @@ "CVE-2020-3617" ], "details": "u'Buffer over-read Issue in Q6 testbus framework due to diag packet length is not completely validated before accessing the field and leads to Information disclosure.' in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in Kamorta, Nicobar, QCS605, QCS610, Rennell, SC7180, SDA660, SDM630, SDM636, SDM660, SDM670, SDM710, SM6150, SM7150, SM8150, SXR1130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j624-g6fh-22pc/GHSA-j624-g6fh-22pc.json b/advisories/unreviewed/2022/05/GHSA-j624-g6fh-22pc/GHSA-j624-g6fh-22pc.json index d30cb421e2f..953c18f57a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-j624-g6fh-22pc/GHSA-j624-g6fh-22pc.json +++ b/advisories/unreviewed/2022/05/GHSA-j624-g6fh-22pc/GHSA-j624-g6fh-22pc.json @@ -7,12 +7,8 @@ "CVE-2020-0347" ], "details": "In iptables, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-136658008", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j645-wj56-g5fv/GHSA-j645-wj56-g5fv.json b/advisories/unreviewed/2022/05/GHSA-j645-wj56-g5fv/GHSA-j645-wj56-g5fv.json index 1a122506b72..c9ce70d0693 100644 --- a/advisories/unreviewed/2022/05/GHSA-j645-wj56-g5fv/GHSA-j645-wj56-g5fv.json +++ b/advisories/unreviewed/2022/05/GHSA-j645-wj56-g5fv/GHSA-j645-wj56-g5fv.json @@ -7,12 +7,8 @@ "CVE-2020-0286" ], "details": "In Bluetooth AVRCP, there is a possible leak of audio metadata due to residual data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150214479", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j657-99m2-wp3h/GHSA-j657-99m2-wp3h.json b/advisories/unreviewed/2022/05/GHSA-j657-99m2-wp3h/GHSA-j657-99m2-wp3h.json index 85570b04d41..81ec5252d50 100644 --- a/advisories/unreviewed/2022/05/GHSA-j657-99m2-wp3h/GHSA-j657-99m2-wp3h.json +++ b/advisories/unreviewed/2022/05/GHSA-j657-99m2-wp3h/GHSA-j657-99m2-wp3h.json @@ -7,12 +7,8 @@ "CVE-2020-3656" ], "details": "u'Out of bound access can happen in MHI command process due to lack of check of command channel id value received from MHI devices' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, Kamorta, MDM9607, MSM8917, MSM8953, Nicobar, QCM2150, QCS405, QCS605, QM215, Rennell, SA6155P, SA8155P, Saipan, SC8180X, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM710, SDM845, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j695-8pfm-q8q9/GHSA-j695-8pfm-q8q9.json b/advisories/unreviewed/2022/05/GHSA-j695-8pfm-q8q9/GHSA-j695-8pfm-q8q9.json index 68d72817dce..f9759b46d09 100644 --- a/advisories/unreviewed/2022/05/GHSA-j695-8pfm-q8q9/GHSA-j695-8pfm-q8q9.json +++ b/advisories/unreviewed/2022/05/GHSA-j695-8pfm-q8q9/GHSA-j695-8pfm-q8q9.json @@ -7,12 +7,8 @@ "CVE-2020-0267" ], "details": "In WindowManager, there is a possible launch of an unexpected app due to a confused deputy. This could lead to local escalation of privilege due to launching a malicious app instead of the one the user intended, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139128211", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j6wf-jr95-r768/GHSA-j6wf-jr95-r768.json b/advisories/unreviewed/2022/05/GHSA-j6wf-jr95-r768/GHSA-j6wf-jr95-r768.json index 79d8029e63f..b8723db099d 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6wf-jr95-r768/GHSA-j6wf-jr95-r768.json +++ b/advisories/unreviewed/2022/05/GHSA-j6wf-jr95-r768/GHSA-j6wf-jr95-r768.json @@ -7,12 +7,8 @@ "CVE-2018-19946" ], "details": "The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j7h4-v6c8-pwrx/GHSA-j7h4-v6c8-pwrx.json b/advisories/unreviewed/2022/05/GHSA-j7h4-v6c8-pwrx/GHSA-j7h4-v6c8-pwrx.json index bcd7cfba635..bc02ff890ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7h4-v6c8-pwrx/GHSA-j7h4-v6c8-pwrx.json +++ b/advisories/unreviewed/2022/05/GHSA-j7h4-v6c8-pwrx/GHSA-j7h4-v6c8-pwrx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j9fm-2qf2-5gjm/GHSA-j9fm-2qf2-5gjm.json b/advisories/unreviewed/2022/05/GHSA-j9fm-2qf2-5gjm/GHSA-j9fm-2qf2-5gjm.json index d212ca37e3a..9f1789ad401 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9fm-2qf2-5gjm/GHSA-j9fm-2qf2-5gjm.json +++ b/advisories/unreviewed/2022/05/GHSA-j9fm-2qf2-5gjm/GHSA-j9fm-2qf2-5gjm.json @@ -7,12 +7,8 @@ "CVE-2020-4711" ], "details": "IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing \"dot dot\" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 187501.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j9wh-q5x6-q8gp/GHSA-j9wh-q5x6-q8gp.json b/advisories/unreviewed/2022/05/GHSA-j9wh-q5x6-q8gp/GHSA-j9wh-q5x6-q8gp.json index 99ae3e0ad5b..e52e3433f72 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9wh-q5x6-q8gp/GHSA-j9wh-q5x6-q8gp.json +++ b/advisories/unreviewed/2022/05/GHSA-j9wh-q5x6-q8gp/GHSA-j9wh-q5x6-q8gp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jc3m-3wcx-qq62/GHSA-jc3m-3wcx-qq62.json b/advisories/unreviewed/2022/05/GHSA-jc3m-3wcx-qq62/GHSA-jc3m-3wcx-qq62.json index b0f2276e5eb..86e32c7d01c 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc3m-3wcx-qq62/GHSA-jc3m-3wcx-qq62.json +++ b/advisories/unreviewed/2022/05/GHSA-jc3m-3wcx-qq62/GHSA-jc3m-3wcx-qq62.json @@ -7,12 +7,8 @@ "CVE-2020-15789" ], "details": "A vulnerability has been identified in Polarion Subversion Webclient (All versions). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requires user interaction by a legitimate user, who must be authenticated to the web interface. A successful attack could allow an attacker to trigger actions via the web interface that the legitimate user is allowed to perform. This could allow the attacker to read or modify contents of the web application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jc42-35xx-59vv/GHSA-jc42-35xx-59vv.json b/advisories/unreviewed/2022/05/GHSA-jc42-35xx-59vv/GHSA-jc42-35xx-59vv.json index 16f38e9b783..edfd9ded147 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc42-35xx-59vv/GHSA-jc42-35xx-59vv.json +++ b/advisories/unreviewed/2022/05/GHSA-jc42-35xx-59vv/GHSA-jc42-35xx-59vv.json @@ -7,12 +7,8 @@ "CVE-2020-6335" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated HPGL file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jc73-84rr-2mcp/GHSA-jc73-84rr-2mcp.json b/advisories/unreviewed/2022/05/GHSA-jc73-84rr-2mcp/GHSA-jc73-84rr-2mcp.json index 0f003e23e1f..53bb2218dfb 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc73-84rr-2mcp/GHSA-jc73-84rr-2mcp.json +++ b/advisories/unreviewed/2022/05/GHSA-jc73-84rr-2mcp/GHSA-jc73-84rr-2mcp.json @@ -7,12 +7,8 @@ "CVE-2020-6357" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated U3D file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jcrh-hfqv-cr47/GHSA-jcrh-hfqv-cr47.json b/advisories/unreviewed/2022/05/GHSA-jcrh-hfqv-cr47/GHSA-jcrh-hfqv-cr47.json index 761763a492a..7f3807ce2fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcrh-hfqv-cr47/GHSA-jcrh-hfqv-cr47.json +++ b/advisories/unreviewed/2022/05/GHSA-jcrh-hfqv-cr47/GHSA-jcrh-hfqv-cr47.json @@ -7,12 +7,8 @@ "CVE-2020-13306" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Webhook feature could be abused to perform denial of service attacks due to the lack of rate limitation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jf57-f8jq-wjg2/GHSA-jf57-f8jq-wjg2.json b/advisories/unreviewed/2022/05/GHSA-jf57-f8jq-wjg2/GHSA-jf57-f8jq-wjg2.json index 2781f09fe26..3f8aa7048cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf57-f8jq-wjg2/GHSA-jf57-f8jq-wjg2.json +++ b/advisories/unreviewed/2022/05/GHSA-jf57-f8jq-wjg2/GHSA-jf57-f8jq-wjg2.json @@ -7,12 +7,8 @@ "CVE-2019-10628" ], "details": "u'Memory can be potentially corrupted if random index is allowed to manipulate TLB entries in Kernel from user library' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8098, Bitra, MDM9205, MDM9650, MSM8998, Nicobar, QCA6390, QCN7605, QCS404, QCS405, QCS605, QCS610, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jfxm-7j25-cffr/GHSA-jfxm-7j25-cffr.json b/advisories/unreviewed/2022/05/GHSA-jfxm-7j25-cffr/GHSA-jfxm-7j25-cffr.json index 548baef24ba..fced110b4e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfxm-7j25-cffr/GHSA-jfxm-7j25-cffr.json +++ b/advisories/unreviewed/2022/05/GHSA-jfxm-7j25-cffr/GHSA-jfxm-7j25-cffr.json @@ -7,12 +7,8 @@ "CVE-2020-3986" ], "details": "VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMF Parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak memory from TPView process running on the system where Workstation or Horizon Client for Windows is installed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jgjp-57q6-q7hv/GHSA-jgjp-57q6-q7hv.json b/advisories/unreviewed/2022/05/GHSA-jgjp-57q6-q7hv/GHSA-jgjp-57q6-q7hv.json index 8b9a7b41350..1aa315fe4a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgjp-57q6-q7hv/GHSA-jgjp-57q6-q7hv.json +++ b/advisories/unreviewed/2022/05/GHSA-jgjp-57q6-q7hv/GHSA-jgjp-57q6-q7hv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jgx3-5crp-mxjw/GHSA-jgx3-5crp-mxjw.json b/advisories/unreviewed/2022/05/GHSA-jgx3-5crp-mxjw/GHSA-jgx3-5crp-mxjw.json index 97c4ddccd29..ee40be0c3b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgx3-5crp-mxjw/GHSA-jgx3-5crp-mxjw.json +++ b/advisories/unreviewed/2022/05/GHSA-jgx3-5crp-mxjw/GHSA-jgx3-5crp-mxjw.json @@ -7,12 +7,8 @@ "CVE-2020-17458" ], "details": "A post-authenticated stored XSS was found in MultiUx v.3.1.12.0 via the /multiux/SaveMailbox LastName field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jh9f-947r-wfrf/GHSA-jh9f-947r-wfrf.json b/advisories/unreviewed/2022/05/GHSA-jh9f-947r-wfrf/GHSA-jh9f-947r-wfrf.json index aa03018e808..7ed0417c635 100644 --- a/advisories/unreviewed/2022/05/GHSA-jh9f-947r-wfrf/GHSA-jh9f-947r-wfrf.json +++ b/advisories/unreviewed/2022/05/GHSA-jh9f-947r-wfrf/GHSA-jh9f-947r-wfrf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jm56-mq2p-7c4g/GHSA-jm56-mq2p-7c4g.json b/advisories/unreviewed/2022/05/GHSA-jm56-mq2p-7c4g/GHSA-jm56-mq2p-7c4g.json index e7ada46e1cf..4f13b96b190 100644 --- a/advisories/unreviewed/2022/05/GHSA-jm56-mq2p-7c4g/GHSA-jm56-mq2p-7c4g.json +++ b/advisories/unreviewed/2022/05/GHSA-jm56-mq2p-7c4g/GHSA-jm56-mq2p-7c4g.json @@ -7,12 +7,8 @@ "CVE-2020-0384" ], "details": "In Parse_art of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote information disclosure in the media extractor with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-150159906", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jmmv-5xg4-p56f/GHSA-jmmv-5xg4-p56f.json b/advisories/unreviewed/2022/05/GHSA-jmmv-5xg4-p56f/GHSA-jmmv-5xg4-p56f.json index 79c28eb8c40..f3d50231a5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmmv-5xg4-p56f/GHSA-jmmv-5xg4-p56f.json +++ b/advisories/unreviewed/2022/05/GHSA-jmmv-5xg4-p56f/GHSA-jmmv-5xg4-p56f.json @@ -7,12 +7,8 @@ "CVE-2020-24566" ], "details": "In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure steps and sets the step's execution location to run on the server/worker, then (under certain circumstances) the account password is exposed in cleartext in the verbose task logs output.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jp5w-5x2h-hp6v/GHSA-jp5w-5x2h-hp6v.json b/advisories/unreviewed/2022/05/GHSA-jp5w-5x2h-hp6v/GHSA-jp5w-5x2h-hp6v.json index 68148c1ed2d..b8525f58c97 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp5w-5x2h-hp6v/GHSA-jp5w-5x2h-hp6v.json +++ b/advisories/unreviewed/2022/05/GHSA-jp5w-5x2h-hp6v/GHSA-jp5w-5x2h-hp6v.json @@ -7,12 +7,8 @@ "CVE-2020-7295" ], "details": "Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to delete or download protected log data via improper access controls in the user interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jpq8-q698-27vp/GHSA-jpq8-q698-27vp.json b/advisories/unreviewed/2022/05/GHSA-jpq8-q698-27vp/GHSA-jpq8-q698-27vp.json index 8399b66bd1b..03defdb478e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jpq8-q698-27vp/GHSA-jpq8-q698-27vp.json +++ b/advisories/unreviewed/2022/05/GHSA-jpq8-q698-27vp/GHSA-jpq8-q698-27vp.json @@ -7,12 +7,8 @@ "CVE-2020-8023" ], "details": "A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SECURITY, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux Enterprise Server 12-SP3-LTSS, SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 12-SP2, SUSE Linux Enterprise Server for SAP 12-SP3, SUSE Linux Enterprise Server for SAP 15, SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud Crowbar 8; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to escalate privileges from user ldap to root. This issue affects: SUSE Enterprise Storage 5 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Debuginfo 11-SP3 openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Debuginfo 11-SP4 openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Point of Sale 11-SP3 openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Server 11-SECURITY openldap2-client-openssl1 versions prior to 2.4.26-0.74.13.1. SUSE Linux Enterprise Server 11-SP4-LTSS openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Server 12-SP2-BCL openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP2-LTSS openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP3-BCL openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP3-LTSS openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP4 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP5 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 15-LTSS openldap2 versions prior to 2.4.46-9.31.1. SUSE Linux Enterprise Server for SAP 12-SP2 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server for SAP 12-SP3 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server for SAP 15 openldap2 versions prior to 2.4.46-9.31.1. SUSE OpenStack Cloud 7 openldap2 versions prior to 2.4.41-18.71.2. SUSE OpenStack Cloud 8 openldap2 versions prior to 2.4.41-18.71.2. SUSE OpenStack Cloud Crowbar 8 openldap2 versions prior to 2.4.41-18.71.2. openSUSE Leap 15.1 openldap2 versions prior to 2.4.46-lp151.10.12.1. openSUSE Leap 15.2 openldap2 versions prior to 2.4.46-lp152.14.3.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jq52-3fww-m362/GHSA-jq52-3fww-m362.json b/advisories/unreviewed/2022/05/GHSA-jq52-3fww-m362/GHSA-jq52-3fww-m362.json index 4c808df1f23..587e9ae6f4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq52-3fww-m362/GHSA-jq52-3fww-m362.json +++ b/advisories/unreviewed/2022/05/GHSA-jq52-3fww-m362/GHSA-jq52-3fww-m362.json @@ -7,12 +7,8 @@ "CVE-2020-21733" ], "details": "Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jqc9-prwj-qrwj/GHSA-jqc9-prwj-qrwj.json b/advisories/unreviewed/2022/05/GHSA-jqc9-prwj-qrwj/GHSA-jqc9-prwj-qrwj.json index acf32786562..39a8eaeaf8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqc9-prwj-qrwj/GHSA-jqc9-prwj-qrwj.json +++ b/advisories/unreviewed/2022/05/GHSA-jqc9-prwj-qrwj/GHSA-jqc9-prwj-qrwj.json @@ -7,12 +7,8 @@ "CVE-2020-0294" ], "details": "In the wallpaper manager, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154915372", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jqf5-5c3v-wj97/GHSA-jqf5-5c3v-wj97.json b/advisories/unreviewed/2022/05/GHSA-jqf5-5c3v-wj97/GHSA-jqf5-5c3v-wj97.json index 4bb6a3a7961..2b8957dd298 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqf5-5c3v-wj97/GHSA-jqf5-5c3v-wj97.json +++ b/advisories/unreviewed/2022/05/GHSA-jqf5-5c3v-wj97/GHSA-jqf5-5c3v-wj97.json @@ -7,12 +7,8 @@ "CVE-2020-13303" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jr48-437x-gh24/GHSA-jr48-437x-gh24.json b/advisories/unreviewed/2022/05/GHSA-jr48-437x-gh24/GHSA-jr48-437x-gh24.json index 1a0d55446d7..c5968817f57 100644 --- a/advisories/unreviewed/2022/05/GHSA-jr48-437x-gh24/GHSA-jr48-437x-gh24.json +++ b/advisories/unreviewed/2022/05/GHSA-jr48-437x-gh24/GHSA-jr48-437x-gh24.json @@ -7,12 +7,8 @@ "CVE-2019-14761" ], "details": "An issue was discovered in KaiOS 2.5. The pre-installed Note application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Note application. At a bare minimum, this allows an attacker to take control over the Note application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrgf-mmc9-3pr7/GHSA-jrgf-mmc9-3pr7.json b/advisories/unreviewed/2022/05/GHSA-jrgf-mmc9-3pr7/GHSA-jrgf-mmc9-3pr7.json index d4502c3b2af..d001f971f75 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrgf-mmc9-3pr7/GHSA-jrgf-mmc9-3pr7.json +++ b/advisories/unreviewed/2022/05/GHSA-jrgf-mmc9-3pr7/GHSA-jrgf-mmc9-3pr7.json @@ -7,12 +7,8 @@ "CVE-2020-6314" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated HPGL file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrgp-f5cx-xhh6/GHSA-jrgp-f5cx-xhh6.json b/advisories/unreviewed/2022/05/GHSA-jrgp-f5cx-xhh6/GHSA-jrgp-f5cx-xhh6.json index d009d75bd3c..171a131e14e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrgp-f5cx-xhh6/GHSA-jrgp-f5cx-xhh6.json +++ b/advisories/unreviewed/2022/05/GHSA-jrgp-f5cx-xhh6/GHSA-jrgp-f5cx-xhh6.json @@ -7,12 +7,8 @@ "CVE-2020-3647" ], "details": "u'Potential buffer overflow when accessing npu debugfs node \"off\"/\"log\" with large buffer size' in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, QCS405, SC8180X, SDX55, SM6150, SM7150, SM8150", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jv7f-8q8r-cr3q/GHSA-jv7f-8q8r-cr3q.json b/advisories/unreviewed/2022/05/GHSA-jv7f-8q8r-cr3q/GHSA-jv7f-8q8r-cr3q.json index 9366639ae17..d51e632309a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv7f-8q8r-cr3q/GHSA-jv7f-8q8r-cr3q.json +++ b/advisories/unreviewed/2022/05/GHSA-jv7f-8q8r-cr3q/GHSA-jv7f-8q8r-cr3q.json @@ -7,12 +7,8 @@ "CVE-2020-24602" ], "details": "Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URL via the vulnerable GET parameter searchName\", \"searchValue\", \"searchDescription\", \"searchDefaultValue\",\"searchPlugin\", \"searchDescription\" and \"searchDynamic\" in the Server Properties and Security Audit Viewer JSP page", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jvj7-xhrw-68x6/GHSA-jvj7-xhrw-68x6.json b/advisories/unreviewed/2022/05/GHSA-jvj7-xhrw-68x6/GHSA-jvj7-xhrw-68x6.json index 262f5c53a09..5b63f1dae2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvj7-xhrw-68x6/GHSA-jvj7-xhrw-68x6.json +++ b/advisories/unreviewed/2022/05/GHSA-jvj7-xhrw-68x6/GHSA-jvj7-xhrw-68x6.json @@ -7,12 +7,8 @@ "CVE-2020-11135" ], "details": "u'Reachable assertion when wrong data size is returned by parser for ape clips' in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8098, Kamorta, MSM8917, MSM8953, Nicobar, QCM2150, QCS605, QM215, Rennell, SA6155P, SA8155P, Saipan, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jw7f-q78h-423m/GHSA-jw7f-q78h-423m.json b/advisories/unreviewed/2022/05/GHSA-jw7f-q78h-423m/GHSA-jw7f-q78h-423m.json index 4a14733ee03..e600b6389eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw7f-q78h-423m/GHSA-jw7f-q78h-423m.json +++ b/advisories/unreviewed/2022/05/GHSA-jw7f-q78h-423m/GHSA-jw7f-q78h-423m.json @@ -7,12 +7,8 @@ "CVE-2020-23512" ], "details": "VR CAM P1 Model P1 v1 has an incorrect access control vulnerability where an attacker can obtain complete access of the device from web (remote) without authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m2mx-5gcx-j288/GHSA-m2mx-5gcx-j288.json b/advisories/unreviewed/2022/05/GHSA-m2mx-5gcx-j288/GHSA-m2mx-5gcx-j288.json index 0226e35bc2f..66b37e2576e 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2mx-5gcx-j288/GHSA-m2mx-5gcx-j288.json +++ b/advisories/unreviewed/2022/05/GHSA-m2mx-5gcx-j288/GHSA-m2mx-5gcx-j288.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m2q3-43wc-p9w4/GHSA-m2q3-43wc-p9w4.json b/advisories/unreviewed/2022/05/GHSA-m2q3-43wc-p9w4/GHSA-m2q3-43wc-p9w4.json index b849540f8e9..9792e2b2379 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2q3-43wc-p9w4/GHSA-m2q3-43wc-p9w4.json +++ b/advisories/unreviewed/2022/05/GHSA-m2q3-43wc-p9w4/GHSA-m2q3-43wc-p9w4.json @@ -7,12 +7,8 @@ "CVE-2018-19948" ], "details": "The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions through a web application. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m4f8-m4jg-vm84/GHSA-m4f8-m4jg-vm84.json b/advisories/unreviewed/2022/05/GHSA-m4f8-m4jg-vm84/GHSA-m4f8-m4jg-vm84.json index 786db36ed1f..3f8284e9be3 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4f8-m4jg-vm84/GHSA-m4f8-m4jg-vm84.json +++ b/advisories/unreviewed/2022/05/GHSA-m4f8-m4jg-vm84/GHSA-m4f8-m4jg-vm84.json @@ -7,12 +7,8 @@ "CVE-2020-25220" ], "details": "The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because skcd->no_refcnt was not considered during a backport of a CVE-2020-14356 patch. This is related to the cgroups feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m4v5-m876-34f5/GHSA-m4v5-m876-34f5.json b/advisories/unreviewed/2022/05/GHSA-m4v5-m876-34f5/GHSA-m4v5-m876-34f5.json index 4e6bf840a5e..4c93287b57a 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4v5-m876-34f5/GHSA-m4v5-m876-34f5.json +++ b/advisories/unreviewed/2022/05/GHSA-m4v5-m876-34f5/GHSA-m4v5-m876-34f5.json @@ -7,12 +7,8 @@ "CVE-2020-0264" ], "details": "In libstagefright, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-116718596", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m697-r4gm-82f3/GHSA-m697-r4gm-82f3.json b/advisories/unreviewed/2022/05/GHSA-m697-r4gm-82f3/GHSA-m697-r4gm-82f3.json index fd14dc0cc16..bca3d128742 100644 --- a/advisories/unreviewed/2022/05/GHSA-m697-r4gm-82f3/GHSA-m697-r4gm-82f3.json +++ b/advisories/unreviewed/2022/05/GHSA-m697-r4gm-82f3/GHSA-m697-r4gm-82f3.json @@ -7,12 +7,8 @@ "CVE-2020-6302" ], "details": "SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacker can get this session ID via shoulder surfing or man in the middle attack and subsequently get access to admin user accounts, leading to Session Fixation and complete compromise of the confidentiality, integrity and availability of the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m69w-8p53-w8cx/GHSA-m69w-8p53-w8cx.json b/advisories/unreviewed/2022/05/GHSA-m69w-8p53-w8cx/GHSA-m69w-8p53-w8cx.json index 30ea92c233d..b4aafed25f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-m69w-8p53-w8cx/GHSA-m69w-8p53-w8cx.json +++ b/advisories/unreviewed/2022/05/GHSA-m69w-8p53-w8cx/GHSA-m69w-8p53-w8cx.json @@ -7,12 +7,8 @@ "CVE-2020-3646" ], "details": "u'Buffer overflow seen as the destination buffer size is lesser than the source buffer size in video application' in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in Bitra, MSM8909W, QCM2150, QCS405, QCS605, Saipan, SC8180X, SDA845, SDM429W, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m6xf-x3pm-6ffw/GHSA-m6xf-x3pm-6ffw.json b/advisories/unreviewed/2022/05/GHSA-m6xf-x3pm-6ffw/GHSA-m6xf-x3pm-6ffw.json index 61a948c5872..462531c9a79 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6xf-x3pm-6ffw/GHSA-m6xf-x3pm-6ffw.json +++ b/advisories/unreviewed/2022/05/GHSA-m6xf-x3pm-6ffw/GHSA-m6xf-x3pm-6ffw.json @@ -7,12 +7,8 @@ "CVE-2020-7294" ], "details": "Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to delete or download protected files via improper access controls in the REST interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m955-8c8p-f9h8/GHSA-m955-8c8p-f9h8.json b/advisories/unreviewed/2022/05/GHSA-m955-8c8p-f9h8/GHSA-m955-8c8p-f9h8.json index d18de6d3ac6..b724bbb510c 100644 --- a/advisories/unreviewed/2022/05/GHSA-m955-8c8p-f9h8/GHSA-m955-8c8p-f9h8.json +++ b/advisories/unreviewed/2022/05/GHSA-m955-8c8p-f9h8/GHSA-m955-8c8p-f9h8.json @@ -7,12 +7,8 @@ "CVE-2020-0352" ], "details": "In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-132074310", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m95j-3vpr-rhr4/GHSA-m95j-3vpr-rhr4.json b/advisories/unreviewed/2022/05/GHSA-m95j-3vpr-rhr4/GHSA-m95j-3vpr-rhr4.json index b0611821ee7..d13ca158542 100644 --- a/advisories/unreviewed/2022/05/GHSA-m95j-3vpr-rhr4/GHSA-m95j-3vpr-rhr4.json +++ b/advisories/unreviewed/2022/05/GHSA-m95j-3vpr-rhr4/GHSA-m95j-3vpr-rhr4.json @@ -7,12 +7,8 @@ "CVE-2020-16099" ], "details": "In Gallagher Command Centre v8.20 prior to v8.20.1093(MR2) it is possible to create Guard Tour events that when accessed via things like reporting cause clients to temporarily hang or disconnect.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mf64-j3g8-vgpj/GHSA-mf64-j3g8-vgpj.json b/advisories/unreviewed/2022/05/GHSA-mf64-j3g8-vgpj/GHSA-mf64-j3g8-vgpj.json index 5f88948bda2..53e23d46773 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf64-j3g8-vgpj/GHSA-mf64-j3g8-vgpj.json +++ b/advisories/unreviewed/2022/05/GHSA-mf64-j3g8-vgpj/GHSA-mf64-j3g8-vgpj.json @@ -7,12 +7,8 @@ "CVE-2020-15903" ], "details": "An issue was found in Nagios XI before 5.7.3. There is a privilege escalation vulnerability in backend scripts that ran as root where some included files were editable by nagios user. This issue was fixed in version 5.7.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mf95-6qmf-q4f9/GHSA-mf95-6qmf-q4f9.json b/advisories/unreviewed/2022/05/GHSA-mf95-6qmf-q4f9/GHSA-mf95-6qmf-q4f9.json index 45a802d23c0..551d47add1e 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf95-6qmf-q4f9/GHSA-mf95-6qmf-q4f9.json +++ b/advisories/unreviewed/2022/05/GHSA-mf95-6qmf-q4f9/GHSA-mf95-6qmf-q4f9.json @@ -7,12 +7,8 @@ "CVE-2020-7324" ], "details": "Improper Access Control vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to bypass security mechanisms and deny access to the SYSTEM folder via incorrectly applied permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mg4q-7wrp-v22h/GHSA-mg4q-7wrp-v22h.json b/advisories/unreviewed/2022/05/GHSA-mg4q-7wrp-v22h/GHSA-mg4q-7wrp-v22h.json index f970372963e..d3101f9c824 100644 --- a/advisories/unreviewed/2022/05/GHSA-mg4q-7wrp-v22h/GHSA-mg4q-7wrp-v22h.json +++ b/advisories/unreviewed/2022/05/GHSA-mg4q-7wrp-v22h/GHSA-mg4q-7wrp-v22h.json @@ -7,12 +7,8 @@ "CVE-2020-0285" ], "details": "In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156253479", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mh2j-r8qm-xj6j/GHSA-mh2j-r8qm-xj6j.json b/advisories/unreviewed/2022/05/GHSA-mh2j-r8qm-xj6j/GHSA-mh2j-r8qm-xj6j.json index 9d30f8999bd..a7c61bed80b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh2j-r8qm-xj6j/GHSA-mh2j-r8qm-xj6j.json +++ b/advisories/unreviewed/2022/05/GHSA-mh2j-r8qm-xj6j/GHSA-mh2j-r8qm-xj6j.json @@ -7,12 +7,8 @@ "CVE-2020-25281" ], "details": "An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Applications with sensitive security settings (such as the package verifier application) mishandle unknown-source installations. The LG ID is LVE-SMP-190002 (September 2020).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mhc5-f7x7-jfpg/GHSA-mhc5-f7x7-jfpg.json b/advisories/unreviewed/2022/05/GHSA-mhc5-f7x7-jfpg/GHSA-mhc5-f7x7-jfpg.json index 8bc23f74933..71450810de6 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhc5-f7x7-jfpg/GHSA-mhc5-f7x7-jfpg.json +++ b/advisories/unreviewed/2022/05/GHSA-mhc5-f7x7-jfpg/GHSA-mhc5-f7x7-jfpg.json @@ -7,12 +7,8 @@ "CVE-2020-14513" ], "details": "CodeMeter (All versions prior to 6.81) and the software using it may crash while processing a specifically crafted license file due to unverified length fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mhpx-2qw7-qwqp/GHSA-mhpx-2qw7-qwqp.json b/advisories/unreviewed/2022/05/GHSA-mhpx-2qw7-qwqp/GHSA-mhpx-2qw7-qwqp.json index 05923a21ecd..780771108c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhpx-2qw7-qwqp/GHSA-mhpx-2qw7-qwqp.json +++ b/advisories/unreviewed/2022/05/GHSA-mhpx-2qw7-qwqp/GHSA-mhpx-2qw7-qwqp.json @@ -7,12 +7,8 @@ "CVE-2020-0272" ], "details": "In libhwbinder, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-130166487", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mhvm-7v69-2hr4/GHSA-mhvm-7v69-2hr4.json b/advisories/unreviewed/2022/05/GHSA-mhvm-7v69-2hr4/GHSA-mhvm-7v69-2hr4.json index 9a8dfe92a30..a1b6e54115d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhvm-7v69-2hr4/GHSA-mhvm-7v69-2hr4.json +++ b/advisories/unreviewed/2022/05/GHSA-mhvm-7v69-2hr4/GHSA-mhvm-7v69-2hr4.json @@ -7,12 +7,8 @@ "CVE-2020-0281" ], "details": "In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure. System execution privileges, a Firmware compromise, and User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137857778", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mm32-rj9g-9ffc/GHSA-mm32-rj9g-9ffc.json b/advisories/unreviewed/2022/05/GHSA-mm32-rj9g-9ffc/GHSA-mm32-rj9g-9ffc.json index 4e6732a8818..92cb8c53e58 100644 --- a/advisories/unreviewed/2022/05/GHSA-mm32-rj9g-9ffc/GHSA-mm32-rj9g-9ffc.json +++ b/advisories/unreviewed/2022/05/GHSA-mm32-rj9g-9ffc/GHSA-mm32-rj9g-9ffc.json @@ -7,12 +7,8 @@ "CVE-2020-4409" ], "details": "IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 179537.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mmh8-c5c3-4mw5/GHSA-mmh8-c5c3-4mw5.json b/advisories/unreviewed/2022/05/GHSA-mmh8-c5c3-4mw5/GHSA-mmh8-c5c3-4mw5.json index c95e27f208c..1affaee0fd5 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmh8-c5c3-4mw5/GHSA-mmh8-c5c3-4mw5.json +++ b/advisories/unreviewed/2022/05/GHSA-mmh8-c5c3-4mw5/GHSA-mmh8-c5c3-4mw5.json @@ -7,12 +7,8 @@ "CVE-2020-24074" ], "details": "The decode program in silk-v3-decoder Version:20160922 Build By kn007 does not strictly check data, resulting in a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mp5p-8378-g7pw/GHSA-mp5p-8378-g7pw.json b/advisories/unreviewed/2022/05/GHSA-mp5p-8378-g7pw/GHSA-mp5p-8378-g7pw.json index 7cff8c470c1..e75a6b30a7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mp5p-8378-g7pw/GHSA-mp5p-8378-g7pw.json +++ b/advisories/unreviewed/2022/05/GHSA-mp5p-8378-g7pw/GHSA-mp5p-8378-g7pw.json @@ -7,12 +7,8 @@ "CVE-2020-11120" ], "details": "u'Calling thread may free the data buffer pointer that was passed to the callback and later when event loop executes the callback, data buffer may not be valid and will lead to use after free scenario' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8096AU, APQ8098, Bitra, Kamorta, MSM8917, MSM8953, MSM8998, QCM2150, QCS405, QCS605, QM215, Rennell, Saipan, SDM429, SDM439, SDM450, SDM632, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mp8w-5ccr-gf45/GHSA-mp8w-5ccr-gf45.json b/advisories/unreviewed/2022/05/GHSA-mp8w-5ccr-gf45/GHSA-mp8w-5ccr-gf45.json index a9fd6647952..69f26cb03c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-mp8w-5ccr-gf45/GHSA-mp8w-5ccr-gf45.json +++ b/advisories/unreviewed/2022/05/GHSA-mp8w-5ccr-gf45/GHSA-mp8w-5ccr-gf45.json @@ -7,12 +7,8 @@ "CVE-2020-11115" ], "details": "u'Buffer over read occurs while processing information element from beacon due to lack of check of data received from beacon' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8053, APQ8096AU, APQ8098, Bitra, Kamorta, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCM2150, QCN7605, QCS405, QCS605, QM215, Rennell, SA415M, Saipan, SC8180X, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM660, SDM845, SDX20, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mv65-7xv7-wp7j/GHSA-mv65-7xv7-wp7j.json b/advisories/unreviewed/2022/05/GHSA-mv65-7xv7-wp7j/GHSA-mv65-7xv7-wp7j.json index bfce852e1b2..bd97f5cc3ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv65-7xv7-wp7j/GHSA-mv65-7xv7-wp7j.json +++ b/advisories/unreviewed/2022/05/GHSA-mv65-7xv7-wp7j/GHSA-mv65-7xv7-wp7j.json @@ -7,12 +7,8 @@ "CVE-2020-15024" ], "details": "An issue was discovered in the Login Password feature of the Password Manager component in Avast Antivirus 20.1.5069.562. An entered password continues to be stored in Windows main memory after a logout, and after a Lock Vault operation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mxr8-pvvp-fw5r/GHSA-mxr8-pvvp-fw5r.json b/advisories/unreviewed/2022/05/GHSA-mxr8-pvvp-fw5r/GHSA-mxr8-pvvp-fw5r.json index dea204bc547..640ac39a1b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-mxr8-pvvp-fw5r/GHSA-mxr8-pvvp-fw5r.json +++ b/advisories/unreviewed/2022/05/GHSA-mxr8-pvvp-fw5r/GHSA-mxr8-pvvp-fw5r.json @@ -7,12 +7,8 @@ "CVE-2020-3989" ], "details": "VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain a denial of service vulnerability due to an out-of-bounds write issue in Cortado ThinPrint component. A malicious actor with normal access to a virtual machine may be able to exploit this issue to create a partial denial-of-service condition on the system where Workstation or Horizon Client for Windows is installed. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon Client.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p22x-x8mg-qrqm/GHSA-p22x-x8mg-qrqm.json b/advisories/unreviewed/2022/05/GHSA-p22x-x8mg-qrqm/GHSA-p22x-x8mg-qrqm.json index 22bd9020cd1..4107cce3a6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-p22x-x8mg-qrqm/GHSA-p22x-x8mg-qrqm.json +++ b/advisories/unreviewed/2022/05/GHSA-p22x-x8mg-qrqm/GHSA-p22x-x8mg-qrqm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p2q5-r29q-m7gv/GHSA-p2q5-r29q-m7gv.json b/advisories/unreviewed/2022/05/GHSA-p2q5-r29q-m7gv/GHSA-p2q5-r29q-m7gv.json index 41ab2fab1c7..1d3f2f2b075 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2q5-r29q-m7gv/GHSA-p2q5-r29q-m7gv.json +++ b/advisories/unreviewed/2022/05/GHSA-p2q5-r29q-m7gv/GHSA-p2q5-r29q-m7gv.json @@ -7,12 +7,8 @@ "CVE-2020-6343" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated EPS file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p3mr-f49r-753g/GHSA-p3mr-f49r-753g.json b/advisories/unreviewed/2022/05/GHSA-p3mr-f49r-753g/GHSA-p3mr-f49r-753g.json index 5f72b0afe35..3f95a8f46b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3mr-f49r-753g/GHSA-p3mr-f49r-753g.json +++ b/advisories/unreviewed/2022/05/GHSA-p3mr-f49r-753g/GHSA-p3mr-f49r-753g.json @@ -7,12 +7,8 @@ "CVE-2020-4578" ], "details": "IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 184433.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p443-fjqf-h82p/GHSA-p443-fjqf-h82p.json b/advisories/unreviewed/2022/05/GHSA-p443-fjqf-h82p/GHSA-p443-fjqf-h82p.json index f92c120fbc3..825d98899d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-p443-fjqf-h82p/GHSA-p443-fjqf-h82p.json +++ b/advisories/unreviewed/2022/05/GHSA-p443-fjqf-h82p/GHSA-p443-fjqf-h82p.json @@ -7,12 +7,8 @@ "CVE-2020-7325" ], "details": "Privilege Escalation vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to an unintended file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p56m-hx7c-pjv5/GHSA-p56m-hx7c-pjv5.json b/advisories/unreviewed/2022/05/GHSA-p56m-hx7c-pjv5/GHSA-p56m-hx7c-pjv5.json index 870f601959e..bb802f32050 100644 --- a/advisories/unreviewed/2022/05/GHSA-p56m-hx7c-pjv5/GHSA-p56m-hx7c-pjv5.json +++ b/advisories/unreviewed/2022/05/GHSA-p56m-hx7c-pjv5/GHSA-p56m-hx7c-pjv5.json @@ -7,12 +7,8 @@ "CVE-2020-15961" ], "details": "Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p87v-mmg4-w93p/GHSA-p87v-mmg4-w93p.json b/advisories/unreviewed/2022/05/GHSA-p87v-mmg4-w93p/GHSA-p87v-mmg4-w93p.json index 0b64ccba5d5..ea803127985 100644 --- a/advisories/unreviewed/2022/05/GHSA-p87v-mmg4-w93p/GHSA-p87v-mmg4-w93p.json +++ b/advisories/unreviewed/2022/05/GHSA-p87v-mmg4-w93p/GHSA-p87v-mmg4-w93p.json @@ -7,12 +7,8 @@ "CVE-2020-25289" ], "details": "The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Manager symbolic link from the log directory (which has weak permissions).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p975-9mr6-3gg6/GHSA-p975-9mr6-3gg6.json b/advisories/unreviewed/2022/05/GHSA-p975-9mr6-3gg6/GHSA-p975-9mr6-3gg6.json index de125ac859c..1bbf848a1a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-p975-9mr6-3gg6/GHSA-p975-9mr6-3gg6.json +++ b/advisories/unreviewed/2022/05/GHSA-p975-9mr6-3gg6/GHSA-p975-9mr6-3gg6.json @@ -7,12 +7,8 @@ "CVE-2020-23828" ], "details": "A File Upload vulnerability in SourceCodester Online Course Registration v1.0 allows remote attackers to achieve Remote Code Execution (RCE) on the hosting webserver by uploading a crafted PHP web-shell that bypasses the image upload filters. An attack uses /Online%20Course%20Registration/my-profile.php with the POST parameter photo.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p9x8-8fhr-66mg/GHSA-p9x8-8fhr-66mg.json b/advisories/unreviewed/2022/05/GHSA-p9x8-8fhr-66mg/GHSA-p9x8-8fhr-66mg.json index a6d6f387dc8..0ab5c3292b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9x8-8fhr-66mg/GHSA-p9x8-8fhr-66mg.json +++ b/advisories/unreviewed/2022/05/GHSA-p9x8-8fhr-66mg/GHSA-p9x8-8fhr-66mg.json @@ -7,12 +7,8 @@ "CVE-2020-24385" ], "details": "In MidnightBSD before 1.2.6 and 1.3 before August 2020, and FreeBSD before 7, a NULL pointer dereference was found in the Linux emulation layer that allows attackers to crash the running kernel. During binary interaction, td->td_emuldata in sys/compat/linux/linux_emul.h is not getting initialized and returns NULL from em_find().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pf79-9hv7-chg5/GHSA-pf79-9hv7-chg5.json b/advisories/unreviewed/2022/05/GHSA-pf79-9hv7-chg5/GHSA-pf79-9hv7-chg5.json index e992afc7134..5fb419f6e2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf79-9hv7-chg5/GHSA-pf79-9hv7-chg5.json +++ b/advisories/unreviewed/2022/05/GHSA-pf79-9hv7-chg5/GHSA-pf79-9hv7-chg5.json @@ -7,12 +7,8 @@ "CVE-2020-2040" ], "details": "A buffer overflow vulnerability in PAN-OS allows an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface. This issue impacts: All versions of PAN-OS 8.0; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; PAN-OS 9.1 versions earlier than PAN-OS 9.1.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pfj3-f63g-8pwm/GHSA-pfj3-f63g-8pwm.json b/advisories/unreviewed/2022/05/GHSA-pfj3-f63g-8pwm/GHSA-pfj3-f63g-8pwm.json index a18513a9bf7..92407393003 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfj3-f63g-8pwm/GHSA-pfj3-f63g-8pwm.json +++ b/advisories/unreviewed/2022/05/GHSA-pfj3-f63g-8pwm/GHSA-pfj3-f63g-8pwm.json @@ -7,12 +7,8 @@ "CVE-2020-10049" ], "details": "A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The start-stop scripts for the services of the affected application could allow a local attacker to include arbitrary commands that are executed when services are started or stopped interactively by system administrators.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pfr3-j9r8-5229/GHSA-pfr3-j9r8-5229.json b/advisories/unreviewed/2022/05/GHSA-pfr3-j9r8-5229/GHSA-pfr3-j9r8-5229.json index 3efa15e1d2d..0fbf6c6f384 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfr3-j9r8-5229/GHSA-pfr3-j9r8-5229.json +++ b/advisories/unreviewed/2022/05/GHSA-pfr3-j9r8-5229/GHSA-pfr3-j9r8-5229.json @@ -7,12 +7,8 @@ "CVE-2020-24553" ], "details": "Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pfv6-m4rh-76wr/GHSA-pfv6-m4rh-76wr.json b/advisories/unreviewed/2022/05/GHSA-pfv6-m4rh-76wr/GHSA-pfv6-m4rh-76wr.json index 11841cace18..cfa22146361 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfv6-m4rh-76wr/GHSA-pfv6-m4rh-76wr.json +++ b/advisories/unreviewed/2022/05/GHSA-pfv6-m4rh-76wr/GHSA-pfv6-m4rh-76wr.json @@ -7,12 +7,8 @@ "CVE-2020-0275" ], "details": "In MediaProvider, there is a possible way to access ContentResolver and MediaStore entries the app shouldn't have access to due to a permissions bypass. This could lead to local escalation of privilege, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150507736", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-phhj-vpf5-5666/GHSA-phhj-vpf5-5666.json b/advisories/unreviewed/2022/05/GHSA-phhj-vpf5-5666/GHSA-phhj-vpf5-5666.json index a3e955d77a1..db0964c0bc8 100644 --- a/advisories/unreviewed/2022/05/GHSA-phhj-vpf5-5666/GHSA-phhj-vpf5-5666.json +++ b/advisories/unreviewed/2022/05/GHSA-phhj-vpf5-5666/GHSA-phhj-vpf5-5666.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pj93-8v65-p9w3/GHSA-pj93-8v65-p9w3.json b/advisories/unreviewed/2022/05/GHSA-pj93-8v65-p9w3/GHSA-pj93-8v65-p9w3.json index b865ef704d0..1dd50d8309b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj93-8v65-p9w3/GHSA-pj93-8v65-p9w3.json +++ b/advisories/unreviewed/2022/05/GHSA-pj93-8v65-p9w3/GHSA-pj93-8v65-p9w3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pjcw-v852-66p8/GHSA-pjcw-v852-66p8.json b/advisories/unreviewed/2022/05/GHSA-pjcw-v852-66p8/GHSA-pjcw-v852-66p8.json index 669b6f9dbcc..dbd30f86b98 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjcw-v852-66p8/GHSA-pjcw-v852-66p8.json +++ b/advisories/unreviewed/2022/05/GHSA-pjcw-v852-66p8/GHSA-pjcw-v852-66p8.json @@ -7,12 +7,8 @@ "CVE-2020-6353" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated SKP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pp62-f72p-x838/GHSA-pp62-f72p-x838.json b/advisories/unreviewed/2022/05/GHSA-pp62-f72p-x838/GHSA-pp62-f72p-x838.json index 465039c2e34..5104938729c 100644 --- a/advisories/unreviewed/2022/05/GHSA-pp62-f72p-x838/GHSA-pp62-f72p-x838.json +++ b/advisories/unreviewed/2022/05/GHSA-pp62-f72p-x838/GHSA-pp62-f72p-x838.json @@ -7,12 +7,8 @@ "CVE-2019-10629" ], "details": "u'User Process can potentially corrupt kernel virtual page by passing a crafted page in API' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Bitra, IPQ6018, IPQ8074, MDM9205, Nicobar, QCA8081, QCN7605, QCS404, QCS405, QCS605, QCS610, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA845, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pph2-ccpg-crg3/GHSA-pph2-ccpg-crg3.json b/advisories/unreviewed/2022/05/GHSA-pph2-ccpg-crg3/GHSA-pph2-ccpg-crg3.json index 1343811b5d3..46eb58d85d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-pph2-ccpg-crg3/GHSA-pph2-ccpg-crg3.json +++ b/advisories/unreviewed/2022/05/GHSA-pph2-ccpg-crg3/GHSA-pph2-ccpg-crg3.json @@ -7,12 +7,8 @@ "CVE-2020-0320" ], "details": "In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-129282427", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-prx2-4v64-2j7p/GHSA-prx2-4v64-2j7p.json b/advisories/unreviewed/2022/05/GHSA-prx2-4v64-2j7p/GHSA-prx2-4v64-2j7p.json index 8c02a31854c..908cf00eec6 100644 --- a/advisories/unreviewed/2022/05/GHSA-prx2-4v64-2j7p/GHSA-prx2-4v64-2j7p.json +++ b/advisories/unreviewed/2022/05/GHSA-prx2-4v64-2j7p/GHSA-prx2-4v64-2j7p.json @@ -7,12 +7,8 @@ "CVE-2020-0319" ], "details": "In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137868765", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pvj6-h4hj-8v43/GHSA-pvj6-h4hj-8v43.json b/advisories/unreviewed/2022/05/GHSA-pvj6-h4hj-8v43/GHSA-pvj6-h4hj-8v43.json index 39bd1f5e44f..78b874e7c40 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvj6-h4hj-8v43/GHSA-pvj6-h4hj-8v43.json +++ b/advisories/unreviewed/2022/05/GHSA-pvj6-h4hj-8v43/GHSA-pvj6-h4hj-8v43.json @@ -7,12 +7,8 @@ "CVE-2020-3990" ], "details": "VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an information disclosure vulnerability due to an integer overflow issue in Cortado ThinPrint component. A malicious actor with normal access to a virtual machine may be able to exploit this issue to leak memory from TPView process running on the system where Workstation or Horizon Client for Windows is installed. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon Client.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pw98-cq7c-645p/GHSA-pw98-cq7c-645p.json b/advisories/unreviewed/2022/05/GHSA-pw98-cq7c-645p/GHSA-pw98-cq7c-645p.json index af23053276e..7c4099713c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw98-cq7c-645p/GHSA-pw98-cq7c-645p.json +++ b/advisories/unreviewed/2022/05/GHSA-pw98-cq7c-645p/GHSA-pw98-cq7c-645p.json @@ -7,12 +7,8 @@ "CVE-2020-1749" ], "details": "A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. When an encrypted tunnel is created between two hosts, the kernel isn't correctly routing tunneled data over the encrypted link; rather sending the data unencrypted. This would allow anyone in between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q27w-wp82-7w7w/GHSA-q27w-wp82-7w7w.json b/advisories/unreviewed/2022/05/GHSA-q27w-wp82-7w7w/GHSA-q27w-wp82-7w7w.json index 782b70dae89..0c9fbb6d437 100644 --- a/advisories/unreviewed/2022/05/GHSA-q27w-wp82-7w7w/GHSA-q27w-wp82-7w7w.json +++ b/advisories/unreviewed/2022/05/GHSA-q27w-wp82-7w7w/GHSA-q27w-wp82-7w7w.json @@ -7,12 +7,8 @@ "CVE-2020-0425" ], "details": "There is a possible way to view notifications even when the \"Lockdown\" feature is on. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124000380", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q34r-wxv2-gwvr/GHSA-q34r-wxv2-gwvr.json b/advisories/unreviewed/2022/05/GHSA-q34r-wxv2-gwvr/GHSA-q34r-wxv2-gwvr.json index 75e7ddb81b0..b399023d002 100644 --- a/advisories/unreviewed/2022/05/GHSA-q34r-wxv2-gwvr/GHSA-q34r-wxv2-gwvr.json +++ b/advisories/unreviewed/2022/05/GHSA-q34r-wxv2-gwvr/GHSA-q34r-wxv2-gwvr.json @@ -7,12 +7,8 @@ "CVE-2020-0401" ], "details": "In setInstallerPackageName of PackageManagerService.java, there is a missing permission check. This could lead to local escalation of privilege and granting spurious permissions with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-150857253", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q3w6-vxrx-4g94/GHSA-q3w6-vxrx-4g94.json b/advisories/unreviewed/2022/05/GHSA-q3w6-vxrx-4g94/GHSA-q3w6-vxrx-4g94.json index e15988a2848..da519012034 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3w6-vxrx-4g94/GHSA-q3w6-vxrx-4g94.json +++ b/advisories/unreviewed/2022/05/GHSA-q3w6-vxrx-4g94/GHSA-q3w6-vxrx-4g94.json @@ -7,12 +7,8 @@ "CVE-2020-6312" ], "details": "SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), versions - 4.1, 4.2, allows an attacker with a non-administrative user account that can edit certain web page properties, can modify how a browser processes particular page elements, leading to stored Cross Site Scripting. In certain situations, when a user accesses an affected web page element, the attacker will be able to access or modify metadata for which they are not authorized.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q4x3-5q32-g3h6/GHSA-q4x3-5q32-g3h6.json b/advisories/unreviewed/2022/05/GHSA-q4x3-5q32-g3h6/GHSA-q4x3-5q32-g3h6.json index 3d9812c7175..4856e809b83 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4x3-5q32-g3h6/GHSA-q4x3-5q32-g3h6.json +++ b/advisories/unreviewed/2022/05/GHSA-q4x3-5q32-g3h6/GHSA-q4x3-5q32-g3h6.json @@ -7,12 +7,8 @@ "CVE-2020-15964" ], "details": "Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q56m-mx82-79xw/GHSA-q56m-mx82-79xw.json b/advisories/unreviewed/2022/05/GHSA-q56m-mx82-79xw/GHSA-q56m-mx82-79xw.json index 33f42a8c706..b14332daa1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-q56m-mx82-79xw/GHSA-q56m-mx82-79xw.json +++ b/advisories/unreviewed/2022/05/GHSA-q56m-mx82-79xw/GHSA-q56m-mx82-79xw.json @@ -7,12 +7,8 @@ "CVE-2020-14100" ], "details": "In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator can gain root access from this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q57h-w83p-m8hx/GHSA-q57h-w83p-m8hx.json b/advisories/unreviewed/2022/05/GHSA-q57h-w83p-m8hx/GHSA-q57h-w83p-m8hx.json index f09df1b27b3..2a606c05da3 100644 --- a/advisories/unreviewed/2022/05/GHSA-q57h-w83p-m8hx/GHSA-q57h-w83p-m8hx.json +++ b/advisories/unreviewed/2022/05/GHSA-q57h-w83p-m8hx/GHSA-q57h-w83p-m8hx.json @@ -7,12 +7,8 @@ "CVE-2020-0349" ], "details": "In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139188779", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q699-f9h8-7v6p/GHSA-q699-f9h8-7v6p.json b/advisories/unreviewed/2022/05/GHSA-q699-f9h8-7v6p/GHSA-q699-f9h8-7v6p.json index 629cb5d1f63..7f2719b4336 100644 --- a/advisories/unreviewed/2022/05/GHSA-q699-f9h8-7v6p/GHSA-q699-f9h8-7v6p.json +++ b/advisories/unreviewed/2022/05/GHSA-q699-f9h8-7v6p/GHSA-q699-f9h8-7v6p.json @@ -7,12 +7,8 @@ "CVE-2020-7531" ], "details": "A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place executables in a specific folder and run code whenever RemoteConnect is executed by the user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q6rc-73hq-57jq/GHSA-q6rc-73hq-57jq.json b/advisories/unreviewed/2022/05/GHSA-q6rc-73hq-57jq/GHSA-q6rc-73hq-57jq.json index 798886bbf77..1b687f01111 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6rc-73hq-57jq/GHSA-q6rc-73hq-57jq.json +++ b/advisories/unreviewed/2022/05/GHSA-q6rc-73hq-57jq/GHSA-q6rc-73hq-57jq.json @@ -7,12 +7,8 @@ "CVE-2020-24161" ], "details": "Guangzhou NetEase Mail Master 4.14.1.1004 on Windows has a DLL hijacking vulnerability. Attackers can use this vulnerability to execute malicious code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q72h-v4jg-pwvv/GHSA-q72h-v4jg-pwvv.json b/advisories/unreviewed/2022/05/GHSA-q72h-v4jg-pwvv/GHSA-q72h-v4jg-pwvv.json index 583f0d09cd6..dba8c805828 100644 --- a/advisories/unreviewed/2022/05/GHSA-q72h-v4jg-pwvv/GHSA-q72h-v4jg-pwvv.json +++ b/advisories/unreviewed/2022/05/GHSA-q72h-v4jg-pwvv/GHSA-q72h-v4jg-pwvv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q75j-83jm-892x/GHSA-q75j-83jm-892x.json b/advisories/unreviewed/2022/05/GHSA-q75j-83jm-892x/GHSA-q75j-83jm-892x.json index 1ed0f1f4371..fd17d19b866 100644 --- a/advisories/unreviewed/2022/05/GHSA-q75j-83jm-892x/GHSA-q75j-83jm-892x.json +++ b/advisories/unreviewed/2022/05/GHSA-q75j-83jm-892x/GHSA-q75j-83jm-892x.json @@ -7,12 +7,8 @@ "CVE-2020-6358" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated FBX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7qw-4c2f-p3rj/GHSA-q7qw-4c2f-p3rj.json b/advisories/unreviewed/2022/05/GHSA-q7qw-4c2f-p3rj/GHSA-q7qw-4c2f-p3rj.json index ac5d131f3a2..a7b10220d79 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7qw-4c2f-p3rj/GHSA-q7qw-4c2f-p3rj.json +++ b/advisories/unreviewed/2022/05/GHSA-q7qw-4c2f-p3rj/GHSA-q7qw-4c2f-p3rj.json @@ -7,12 +7,8 @@ "CVE-2020-13289" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q9cg-2gwc-x6xh/GHSA-q9cg-2gwc-x6xh.json b/advisories/unreviewed/2022/05/GHSA-q9cg-2gwc-x6xh/GHSA-q9cg-2gwc-x6xh.json index c860321f497..8806ced97f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9cg-2gwc-x6xh/GHSA-q9cg-2gwc-x6xh.json +++ b/advisories/unreviewed/2022/05/GHSA-q9cg-2gwc-x6xh/GHSA-q9cg-2gwc-x6xh.json @@ -7,12 +7,8 @@ "CVE-2020-0271" ], "details": "In the Settings app, there is an insecure default value. This could lead to local escalation of privilege and tapjacking with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-144507081", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q9qr-vfrw-vgjq/GHSA-q9qr-vfrw-vgjq.json b/advisories/unreviewed/2022/05/GHSA-q9qr-vfrw-vgjq/GHSA-q9qr-vfrw-vgjq.json index ee3b333507f..2e1e1bbdc42 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9qr-vfrw-vgjq/GHSA-q9qr-vfrw-vgjq.json +++ b/advisories/unreviewed/2022/05/GHSA-q9qr-vfrw-vgjq/GHSA-q9qr-vfrw-vgjq.json @@ -7,12 +7,8 @@ "CVE-2020-0291" ], "details": "In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges and a compromised Firmware needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-146032016", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q9ww-5345-v56q/GHSA-q9ww-5345-v56q.json b/advisories/unreviewed/2022/05/GHSA-q9ww-5345-v56q/GHSA-q9ww-5345-v56q.json index 24edb3cc886..f6f88d0a955 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9ww-5345-v56q/GHSA-q9ww-5345-v56q.json +++ b/advisories/unreviewed/2022/05/GHSA-q9ww-5345-v56q/GHSA-q9ww-5345-v56q.json @@ -7,12 +7,8 @@ "CVE-2020-0284" ], "details": "In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156253784", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qc34-jwcm-8qfc/GHSA-qc34-jwcm-8qfc.json b/advisories/unreviewed/2022/05/GHSA-qc34-jwcm-8qfc/GHSA-qc34-jwcm-8qfc.json index 1494e305e43..1259fa79b02 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc34-jwcm-8qfc/GHSA-qc34-jwcm-8qfc.json +++ b/advisories/unreviewed/2022/05/GHSA-qc34-jwcm-8qfc/GHSA-qc34-jwcm-8qfc.json @@ -7,12 +7,8 @@ "CVE-2020-2036" ], "details": "A reflected cross-site scripting (XSS) vulnerability exists in the PAN-OS management web interface. A remote attacker able to convince an administrator with an active authenticated session on the firewall management interface to click on a crafted link to that management web interface could potentially execute arbitrary JavaScript code in the administrator's browser and perform administrative actions. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qc3j-p935-x73x/GHSA-qc3j-p935-x73x.json b/advisories/unreviewed/2022/05/GHSA-qc3j-p935-x73x/GHSA-qc3j-p935-x73x.json index 38bd8500d22..3558ea7a3aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc3j-p935-x73x/GHSA-qc3j-p935-x73x.json +++ b/advisories/unreviewed/2022/05/GHSA-qc3j-p935-x73x/GHSA-qc3j-p935-x73x.json @@ -7,12 +7,8 @@ "CVE-2020-9726" ], "details": "Adobe FrameMaker version 2019.0.6 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious FrameMaker file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qc83-fm35-h9f4/GHSA-qc83-fm35-h9f4.json b/advisories/unreviewed/2022/05/GHSA-qc83-fm35-h9f4/GHSA-qc83-fm35-h9f4.json index 497e12b52f9..f226beffd02 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc83-fm35-h9f4/GHSA-qc83-fm35-h9f4.json +++ b/advisories/unreviewed/2022/05/GHSA-qc83-fm35-h9f4/GHSA-qc83-fm35-h9f4.json @@ -7,12 +7,8 @@ "CVE-2020-4703" ], "details": "IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. This vulnerability is due to an incomplete fix for CVE-2020-4470. IBM X-Force ID: 187188.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qcj8-gp4q-v8r2/GHSA-qcj8-gp4q-v8r2.json b/advisories/unreviewed/2022/05/GHSA-qcj8-gp4q-v8r2/GHSA-qcj8-gp4q-v8r2.json index 13c45c74057..c36cc0d8f6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcj8-gp4q-v8r2/GHSA-qcj8-gp4q-v8r2.json +++ b/advisories/unreviewed/2022/05/GHSA-qcj8-gp4q-v8r2/GHSA-qcj8-gp4q-v8r2.json @@ -7,12 +7,8 @@ "CVE-2020-13284" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qcq5-vfmc-qgpp/GHSA-qcq5-vfmc-qgpp.json b/advisories/unreviewed/2022/05/GHSA-qcq5-vfmc-qgpp/GHSA-qcq5-vfmc-qgpp.json index 56da26d2ee0..9f9e56f4e8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcq5-vfmc-qgpp/GHSA-qcq5-vfmc-qgpp.json +++ b/advisories/unreviewed/2022/05/GHSA-qcq5-vfmc-qgpp/GHSA-qcq5-vfmc-qgpp.json @@ -7,12 +7,8 @@ "CVE-2020-6781" ], "details": "Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17.1 potentially allows to intercept video contents by performing a man-in-the-middle attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qf6w-rfjw-57c3/GHSA-qf6w-rfjw-57c3.json b/advisories/unreviewed/2022/05/GHSA-qf6w-rfjw-57c3/GHSA-qf6w-rfjw-57c3.json index ac5fad40fad..f5f35d41992 100644 --- a/advisories/unreviewed/2022/05/GHSA-qf6w-rfjw-57c3/GHSA-qf6w-rfjw-57c3.json +++ b/advisories/unreviewed/2022/05/GHSA-qf6w-rfjw-57c3/GHSA-qf6w-rfjw-57c3.json @@ -7,12 +7,8 @@ "CVE-2020-7296" ], "details": "Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected configuration files via improper access control in the user interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qf8w-r56m-c9xh/GHSA-qf8w-r56m-c9xh.json b/advisories/unreviewed/2022/05/GHSA-qf8w-r56m-c9xh/GHSA-qf8w-r56m-c9xh.json index aa59bc5b63d..fab6d2f6308 100644 --- a/advisories/unreviewed/2022/05/GHSA-qf8w-r56m-c9xh/GHSA-qf8w-r56m-c9xh.json +++ b/advisories/unreviewed/2022/05/GHSA-qf8w-r56m-c9xh/GHSA-qf8w-r56m-c9xh.json @@ -7,12 +7,8 @@ "CVE-2020-14519" ], "details": "This vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are affected, including Version 7.0 or newer with the affected WebSockets API still enabled. This is especially relevant for systems or devices where a web browser is used to access a web server) via a specifically crafted Java Script payload, which may allow alteration or creation of license files for when combined with CVE-2020-14515.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qfrg-7c28-7q8x/GHSA-qfrg-7c28-7q8x.json b/advisories/unreviewed/2022/05/GHSA-qfrg-7c28-7q8x/GHSA-qfrg-7c28-7q8x.json index 0417928c039..ebb9534d981 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfrg-7c28-7q8x/GHSA-qfrg-7c28-7q8x.json +++ b/advisories/unreviewed/2022/05/GHSA-qfrg-7c28-7q8x/GHSA-qfrg-7c28-7q8x.json @@ -7,12 +7,8 @@ "CVE-2020-11129" ], "details": "u'During the error occurrence in capture request, the buffer is freed and later accessed causing the camera APP to fail due to memory use-after-free' in Snapdragon Consumer IOT, Snapdragon Mobile in Bitra, Kamorta, QCS605, Saipan, SDM710, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qg98-9h5g-6p53/GHSA-qg98-9h5g-6p53.json b/advisories/unreviewed/2022/05/GHSA-qg98-9h5g-6p53/GHSA-qg98-9h5g-6p53.json index b3c981e6f50..d401a9bbeb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg98-9h5g-6p53/GHSA-qg98-9h5g-6p53.json +++ b/advisories/unreviewed/2022/05/GHSA-qg98-9h5g-6p53/GHSA-qg98-9h5g-6p53.json @@ -7,12 +7,8 @@ "CVE-2020-0428" ], "details": "In CamX code, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-123999783", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qm3v-8cq5-mxv7/GHSA-qm3v-8cq5-mxv7.json b/advisories/unreviewed/2022/05/GHSA-qm3v-8cq5-mxv7/GHSA-qm3v-8cq5-mxv7.json index f605327cb0b..d1758d0015d 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm3v-8cq5-mxv7/GHSA-qm3v-8cq5-mxv7.json +++ b/advisories/unreviewed/2022/05/GHSA-qm3v-8cq5-mxv7/GHSA-qm3v-8cq5-mxv7.json @@ -7,12 +7,8 @@ "CVE-2020-0282" ], "details": "In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure. System execution privileges, a Firmware compromise, and User interaction are needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-144506224", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qm8h-fvrp-9pr9/GHSA-qm8h-fvrp-9pr9.json b/advisories/unreviewed/2022/05/GHSA-qm8h-fvrp-9pr9/GHSA-qm8h-fvrp-9pr9.json index 8165e50939e..d98b33e30ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm8h-fvrp-9pr9/GHSA-qm8h-fvrp-9pr9.json +++ b/advisories/unreviewed/2022/05/GHSA-qm8h-fvrp-9pr9/GHSA-qm8h-fvrp-9pr9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qmwg-hw9q-xg39/GHSA-qmwg-hw9q-xg39.json b/advisories/unreviewed/2022/05/GHSA-qmwg-hw9q-xg39/GHSA-qmwg-hw9q-xg39.json index 42abb799246..df45cc79b66 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmwg-hw9q-xg39/GHSA-qmwg-hw9q-xg39.json +++ b/advisories/unreviewed/2022/05/GHSA-qmwg-hw9q-xg39/GHSA-qmwg-hw9q-xg39.json @@ -7,12 +7,8 @@ "CVE-2020-14363" ], "details": "An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases, result in arbitrary code execution. The highest threat from this flaw is to confidentiality, integrity as well as system availability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qp4q-4p6v-w368/GHSA-qp4q-4p6v-w368.json b/advisories/unreviewed/2022/05/GHSA-qp4q-4p6v-w368/GHSA-qp4q-4p6v-w368.json index e396cbb34c1..3a9c06e8b47 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp4q-4p6v-w368/GHSA-qp4q-4p6v-w368.json +++ b/advisories/unreviewed/2022/05/GHSA-qp4q-4p6v-w368/GHSA-qp4q-4p6v-w368.json @@ -7,12 +7,8 @@ "CVE-2019-14760" ], "details": "An issue was discovered in KaiOS 2.5. The pre-installed Recorder application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Recorder application. At a bare minimum, this allows an attacker to take control over the Recorder application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qp75-7qjq-q8m4/GHSA-qp75-7qjq-q8m4.json b/advisories/unreviewed/2022/05/GHSA-qp75-7qjq-q8m4/GHSA-qp75-7qjq-q8m4.json index 7acb28fb184..f2dc86fd27f 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp75-7qjq-q8m4/GHSA-qp75-7qjq-q8m4.json +++ b/advisories/unreviewed/2022/05/GHSA-qp75-7qjq-q8m4/GHSA-qp75-7qjq-q8m4.json @@ -7,12 +7,8 @@ "CVE-2020-0289" ], "details": "In PackageManager, there is a missing permission check. This could lead to local information disclosure across users with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153996872", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qqcr-rg66-5jpm/GHSA-qqcr-rg66-5jpm.json b/advisories/unreviewed/2022/05/GHSA-qqcr-rg66-5jpm/GHSA-qqcr-rg66-5jpm.json index 02a73c5d552..6244c17fce2 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqcr-rg66-5jpm/GHSA-qqcr-rg66-5jpm.json +++ b/advisories/unreviewed/2022/05/GHSA-qqcr-rg66-5jpm/GHSA-qqcr-rg66-5jpm.json @@ -7,12 +7,8 @@ "CVE-2020-3666" ], "details": "u'Out of bounds memory access during memory copy while processing Host command' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, IPQ4019, IPQ6018, IPQ8064, IPQ8074, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8996AU, MSM8998, QCA6174A, QCA6574, QCA6574AU, QCA6584AU, QCA8081, QCA9377, QCA9379, QCA9531, QCA9558, QCA9563, QCA9880, QCA9886, QCA9980, QCN5500, QCN5502, QCS404, QCS405, QCS605, SA6155P, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SXR1130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qr9q-882c-gv4j/GHSA-qr9q-882c-gv4j.json b/advisories/unreviewed/2022/05/GHSA-qr9q-882c-gv4j/GHSA-qr9q-882c-gv4j.json index 2c35f582777..773d51fb20a 100644 --- a/advisories/unreviewed/2022/05/GHSA-qr9q-882c-gv4j/GHSA-qr9q-882c-gv4j.json +++ b/advisories/unreviewed/2022/05/GHSA-qr9q-882c-gv4j/GHSA-qr9q-882c-gv4j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qvxf-gr3j-5qw7/GHSA-qvxf-gr3j-5qw7.json b/advisories/unreviewed/2022/05/GHSA-qvxf-gr3j-5qw7/GHSA-qvxf-gr3j-5qw7.json index b3bd2447f97..b486dbe56dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-qvxf-gr3j-5qw7/GHSA-qvxf-gr3j-5qw7.json +++ b/advisories/unreviewed/2022/05/GHSA-qvxf-gr3j-5qw7/GHSA-qvxf-gr3j-5qw7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwh9-c7jr-5v9g/GHSA-qwh9-c7jr-5v9g.json b/advisories/unreviewed/2022/05/GHSA-qwh9-c7jr-5v9g/GHSA-qwh9-c7jr-5v9g.json index 3e307226681..f4e4a45ae01 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwh9-c7jr-5v9g/GHSA-qwh9-c7jr-5v9g.json +++ b/advisories/unreviewed/2022/05/GHSA-qwh9-c7jr-5v9g/GHSA-qwh9-c7jr-5v9g.json @@ -7,12 +7,8 @@ "CVE-2020-7268" ], "details": "Path Traversal vulnerability in McAfee McAfee Email Gateway (MEG) prior to 7.6.406 allows remote attackers to traverse the file system to access files or directories that are outside of the restricted directory via external input to construct a path name that should be within a restricted directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qxgw-h378-xhrw/GHSA-qxgw-h378-xhrw.json b/advisories/unreviewed/2022/05/GHSA-qxgw-h378-xhrw/GHSA-qxgw-h378-xhrw.json index c60973e33e2..e334b443ddc 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxgw-h378-xhrw/GHSA-qxgw-h378-xhrw.json +++ b/advisories/unreviewed/2022/05/GHSA-qxgw-h378-xhrw/GHSA-qxgw-h378-xhrw.json @@ -7,12 +7,8 @@ "CVE-2020-13317" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. An insufficient check in the GraphQL api allowed a maintainer to delete a repository.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r23m-244x-c4vq/GHSA-r23m-244x-c4vq.json b/advisories/unreviewed/2022/05/GHSA-r23m-244x-c4vq/GHSA-r23m-244x-c4vq.json index 6f3954076f2..f6c9c0f3a16 100644 --- a/advisories/unreviewed/2022/05/GHSA-r23m-244x-c4vq/GHSA-r23m-244x-c4vq.json +++ b/advisories/unreviewed/2022/05/GHSA-r23m-244x-c4vq/GHSA-r23m-244x-c4vq.json @@ -7,12 +7,8 @@ "CVE-2020-3636" ], "details": "u'Out of bound writes happen when accessing usage_table header entry beyond the memory allocated for the header' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, QCS404, QCS610, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r2p6-249c-3h56/GHSA-r2p6-249c-3h56.json b/advisories/unreviewed/2022/05/GHSA-r2p6-249c-3h56/GHSA-r2p6-249c-3h56.json index 19d3d569189..54ced2e6ae7 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2p6-249c-3h56/GHSA-r2p6-249c-3h56.json +++ b/advisories/unreviewed/2022/05/GHSA-r2p6-249c-3h56/GHSA-r2p6-249c-3h56.json @@ -7,12 +7,8 @@ "CVE-2020-10733" ], "details": "The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r365-86rw-9xxw/GHSA-r365-86rw-9xxw.json b/advisories/unreviewed/2022/05/GHSA-r365-86rw-9xxw/GHSA-r365-86rw-9xxw.json index 279c7ab068e..f1d2edf3a95 100644 --- a/advisories/unreviewed/2022/05/GHSA-r365-86rw-9xxw/GHSA-r365-86rw-9xxw.json +++ b/advisories/unreviewed/2022/05/GHSA-r365-86rw-9xxw/GHSA-r365-86rw-9xxw.json @@ -7,12 +7,8 @@ "CVE-2020-2044" ], "details": "An information exposure through log file vulnerability where an administrator's password or other sensitive information may be logged in cleartext while using the CLI in Palo Alto Networks PAN-OS software. The opcmdhistory.log file was introduced to track operational command (op-command) usage but did not mask all sensitive information. The opcmdhistory.log file is removed in PAN-OS 9.1 and later PAN-OS versions. Command usage is recorded, instead, in the req_stats.log file in PAN-OS 9.1 and later PAN-OS versions. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PAN-OS 9.0 versions earlier than PAN-OS 9.0.10; PAN-OS 9.1 versions earlier than PAN-OS 9.1.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r449-4m6g-rp77/GHSA-r449-4m6g-rp77.json b/advisories/unreviewed/2022/05/GHSA-r449-4m6g-rp77/GHSA-r449-4m6g-rp77.json index 6d95403819c..40667c0261d 100644 --- a/advisories/unreviewed/2022/05/GHSA-r449-4m6g-rp77/GHSA-r449-4m6g-rp77.json +++ b/advisories/unreviewed/2022/05/GHSA-r449-4m6g-rp77/GHSA-r449-4m6g-rp77.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r48j-3399-5rmj/GHSA-r48j-3399-5rmj.json b/advisories/unreviewed/2022/05/GHSA-r48j-3399-5rmj/GHSA-r48j-3399-5rmj.json index f808cda6b6c..d2317de9d18 100644 --- a/advisories/unreviewed/2022/05/GHSA-r48j-3399-5rmj/GHSA-r48j-3399-5rmj.json +++ b/advisories/unreviewed/2022/05/GHSA-r48j-3399-5rmj/GHSA-r48j-3399-5rmj.json @@ -7,12 +7,8 @@ "CVE-2020-11133" ], "details": "u'Possible out of bound array write in rxdco cal utility due to lack of array bound check' in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MSM8998, QCS605, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SXR1130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r75c-w926-gc25/GHSA-r75c-w926-gc25.json b/advisories/unreviewed/2022/05/GHSA-r75c-w926-gc25/GHSA-r75c-w926-gc25.json index 7f8e994e4c4..849189edfec 100644 --- a/advisories/unreviewed/2022/05/GHSA-r75c-w926-gc25/GHSA-r75c-w926-gc25.json +++ b/advisories/unreviewed/2022/05/GHSA-r75c-w926-gc25/GHSA-r75c-w926-gc25.json @@ -7,12 +7,8 @@ "CVE-2020-0364" ], "details": "In libDRCdec, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137282770", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r88h-whf8-g952/GHSA-r88h-whf8-g952.json b/advisories/unreviewed/2022/05/GHSA-r88h-whf8-g952/GHSA-r88h-whf8-g952.json index 05e361b9e63..259f657d6c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-r88h-whf8-g952/GHSA-r88h-whf8-g952.json +++ b/advisories/unreviewed/2022/05/GHSA-r88h-whf8-g952/GHSA-r88h-whf8-g952.json @@ -7,12 +7,8 @@ "CVE-2020-16098" ], "details": "It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior to v8.20.1166(MR3), versions of 8.10 prior to v8.10.1211(MR5), versions of 8.00 prior to v8.00.1228(MR6), all versions of 7.90 and earlier. These credentials can then be used to encode low security cards to be used by the system where insecure card technologies are supported.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r9cq-9m7w-wx27/GHSA-r9cq-9m7w-wx27.json b/advisories/unreviewed/2022/05/GHSA-r9cq-9m7w-wx27/GHSA-r9cq-9m7w-wx27.json index 8ff92940429..93735f316b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9cq-9m7w-wx27/GHSA-r9cq-9m7w-wx27.json +++ b/advisories/unreviewed/2022/05/GHSA-r9cq-9m7w-wx27/GHSA-r9cq-9m7w-wx27.json @@ -7,12 +7,8 @@ "CVE-2020-0346" ], "details": "In Mediaserver, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if integer sanitization were not enabled (which it is by default), with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-147002762", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rcpf-fw5j-h8rw/GHSA-rcpf-fw5j-h8rw.json b/advisories/unreviewed/2022/05/GHSA-rcpf-fw5j-h8rw/GHSA-rcpf-fw5j-h8rw.json index d206921135b..ce2781454c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcpf-fw5j-h8rw/GHSA-rcpf-fw5j-h8rw.json +++ b/advisories/unreviewed/2022/05/GHSA-rcpf-fw5j-h8rw/GHSA-rcpf-fw5j-h8rw.json @@ -7,12 +7,8 @@ "CVE-2020-24193" ], "details": "A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rcv9-9vhw-rmqr/GHSA-rcv9-9vhw-rmqr.json b/advisories/unreviewed/2022/05/GHSA-rcv9-9vhw-rmqr/GHSA-rcv9-9vhw-rmqr.json index 279d34c8219..b3057aea53e 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcv9-9vhw-rmqr/GHSA-rcv9-9vhw-rmqr.json +++ b/advisories/unreviewed/2022/05/GHSA-rcv9-9vhw-rmqr/GHSA-rcv9-9vhw-rmqr.json @@ -7,12 +7,8 @@ "CVE-2020-0435" ], "details": "In inline_data_addr of f2fs.h, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-133762747", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rf2c-rjfm-w7w2/GHSA-rf2c-rjfm-w7w2.json b/advisories/unreviewed/2022/05/GHSA-rf2c-rjfm-w7w2/GHSA-rf2c-rjfm-w7w2.json index 070a6506e7e..a68dd388506 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf2c-rjfm-w7w2/GHSA-rf2c-rjfm-w7w2.json +++ b/advisories/unreviewed/2022/05/GHSA-rf2c-rjfm-w7w2/GHSA-rf2c-rjfm-w7w2.json @@ -7,12 +7,8 @@ "CVE-2020-4526" ], "details": "IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 182436.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rg23-p49x-87gc/GHSA-rg23-p49x-87gc.json b/advisories/unreviewed/2022/05/GHSA-rg23-p49x-87gc/GHSA-rg23-p49x-87gc.json index 6220a25e9cf..67cc157a9a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-rg23-p49x-87gc/GHSA-rg23-p49x-87gc.json +++ b/advisories/unreviewed/2022/05/GHSA-rg23-p49x-87gc/GHSA-rg23-p49x-87gc.json @@ -7,12 +7,8 @@ "CVE-2020-13313" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgroup badges due to the lack of authorization control.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rh33-j243-53gw/GHSA-rh33-j243-53gw.json b/advisories/unreviewed/2022/05/GHSA-rh33-j243-53gw/GHSA-rh33-j243-53gw.json index 27947814f91..663fde41b86 100644 --- a/advisories/unreviewed/2022/05/GHSA-rh33-j243-53gw/GHSA-rh33-j243-53gw.json +++ b/advisories/unreviewed/2022/05/GHSA-rh33-j243-53gw/GHSA-rh33-j243-53gw.json @@ -7,12 +7,8 @@ "CVE-2020-6321" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated U3D file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rh49-4r53-hgxv/GHSA-rh49-4r53-hgxv.json b/advisories/unreviewed/2022/05/GHSA-rh49-4r53-hgxv/GHSA-rh49-4r53-hgxv.json index c5714af8ae0..9ad058cd193 100644 --- a/advisories/unreviewed/2022/05/GHSA-rh49-4r53-hgxv/GHSA-rh49-4r53-hgxv.json +++ b/advisories/unreviewed/2022/05/GHSA-rh49-4r53-hgxv/GHSA-rh49-4r53-hgxv.json @@ -7,12 +7,8 @@ "CVE-2020-0372" ], "details": "In ActivityManager, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-119673147", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rhr6-wq97-prx6/GHSA-rhr6-wq97-prx6.json b/advisories/unreviewed/2022/05/GHSA-rhr6-wq97-prx6/GHSA-rhr6-wq97-prx6.json index 5a96426420c..ede50fd8a20 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhr6-wq97-prx6/GHSA-rhr6-wq97-prx6.json +++ b/advisories/unreviewed/2022/05/GHSA-rhr6-wq97-prx6/GHSA-rhr6-wq97-prx6.json @@ -7,12 +7,8 @@ "CVE-2020-21845" ], "details": "Codoforum 4.8.3 allows HTML Injection in the 'admin dashboard Manage users Section.'", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rppr-4h7c-mc9c/GHSA-rppr-4h7c-mc9c.json b/advisories/unreviewed/2022/05/GHSA-rppr-4h7c-mc9c/GHSA-rppr-4h7c-mc9c.json index e0a62f566e6..95c0c6cd3bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-rppr-4h7c-mc9c/GHSA-rppr-4h7c-mc9c.json +++ b/advisories/unreviewed/2022/05/GHSA-rppr-4h7c-mc9c/GHSA-rppr-4h7c-mc9c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rq95-33vv-7jxc/GHSA-rq95-33vv-7jxc.json b/advisories/unreviewed/2022/05/GHSA-rq95-33vv-7jxc/GHSA-rq95-33vv-7jxc.json index ce781915f47..9d215c7356d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rq95-33vv-7jxc/GHSA-rq95-33vv-7jxc.json +++ b/advisories/unreviewed/2022/05/GHSA-rq95-33vv-7jxc/GHSA-rq95-33vv-7jxc.json @@ -7,12 +7,8 @@ "CVE-2020-16097" ], "details": "On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed in v8.10.1211(MR5)), v8.00 prior to vGR8.00.165 (Distributed in v8.00.1228(MR6)), v7.90 prior to vGR7.90.165 (distributed in v7.90.1038(MRX)), v7.80 or earlier, It is possible to retrieve site keys used for securing MIFARE Plus and Desfire using debug ports on T Series readers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rq9j-q9jw-98mf/GHSA-rq9j-q9jw-98mf.json b/advisories/unreviewed/2022/05/GHSA-rq9j-q9jw-98mf/GHSA-rq9j-q9jw-98mf.json index 74b7fa316d4..04c643fc9e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-rq9j-q9jw-98mf/GHSA-rq9j-q9jw-98mf.json +++ b/advisories/unreviewed/2022/05/GHSA-rq9j-q9jw-98mf/GHSA-rq9j-q9jw-98mf.json @@ -7,12 +7,8 @@ "CVE-2020-0328" ], "details": "In the camera, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150156131", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rq9v-5pfm-x4vf/GHSA-rq9v-5pfm-x4vf.json b/advisories/unreviewed/2022/05/GHSA-rq9v-5pfm-x4vf/GHSA-rq9v-5pfm-x4vf.json index 47886420477..f5684e58907 100644 --- a/advisories/unreviewed/2022/05/GHSA-rq9v-5pfm-x4vf/GHSA-rq9v-5pfm-x4vf.json +++ b/advisories/unreviewed/2022/05/GHSA-rq9v-5pfm-x4vf/GHSA-rq9v-5pfm-x4vf.json @@ -7,12 +7,8 @@ "CVE-2020-3675" ], "details": "u'Potential integer underflow while parsing Service Info and IPv6 link-local TLVs that comes as part of NDPE attribute' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ5018, IPQ6018, IPQ8074, Kamorta, Nicobar, QCA6390, QCN7605, QCS404, QCS405, Rennell, SA415M, Saipan, SC7180, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rwf2-mvgx-r834/GHSA-rwf2-mvgx-r834.json b/advisories/unreviewed/2022/05/GHSA-rwf2-mvgx-r834/GHSA-rwf2-mvgx-r834.json index e00d587ed69..f171b3e9286 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwf2-mvgx-r834/GHSA-rwf2-mvgx-r834.json +++ b/advisories/unreviewed/2022/05/GHSA-rwf2-mvgx-r834/GHSA-rwf2-mvgx-r834.json @@ -7,12 +7,8 @@ "CVE-2019-14089" ], "details": "u'Keymaster attestation key and device IDs provisioning which is a one time process is incorrectly allowed to be re-provisioned after a user data erase or a factory reset' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Kamorta, Nicobar, QCS404, QCS610, Rennell, SA515M, SA6155P, SC7180, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rx37-23pf-h4vh/GHSA-rx37-23pf-h4vh.json b/advisories/unreviewed/2022/05/GHSA-rx37-23pf-h4vh/GHSA-rx37-23pf-h4vh.json index 0c29c8d86ee..a45ad626220 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx37-23pf-h4vh/GHSA-rx37-23pf-h4vh.json +++ b/advisories/unreviewed/2022/05/GHSA-rx37-23pf-h4vh/GHSA-rx37-23pf-h4vh.json @@ -7,12 +7,8 @@ "CVE-2020-25073" ], "details": "FreedomBox through 20.13 allows remote attackers to obtain sensitive information from the /server-status page of the Apache HTTP Server, because a connection from the Tor onion service (or from PageKite) is considered a local connection. This affects both the freedombox and plinth packages of some Linux distributions, but only if the Apache mod_status module is enabled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rxxr-9pqj-xw7v/GHSA-rxxr-9pqj-xw7v.json b/advisories/unreviewed/2022/05/GHSA-rxxr-9pqj-xw7v/GHSA-rxxr-9pqj-xw7v.json index 6cf7d167662..7494859c3a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxxr-9pqj-xw7v/GHSA-rxxr-9pqj-xw7v.json +++ b/advisories/unreviewed/2022/05/GHSA-rxxr-9pqj-xw7v/GHSA-rxxr-9pqj-xw7v.json @@ -7,12 +7,8 @@ "CVE-2020-3668" ], "details": "u'Buffer overflow while parsing PMF enabled MCBC frames due to frame length being lesser than what is expected while parsing' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ6018, IPQ8074, Kamorta, Nicobar, QCA6390, QCA8081, QCN7605, QCS404, QCS405, QCS605, Rennell, SA415M, SC7180, SC8180X, SDA845, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SXR1130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v53h-89xp-f8xj/GHSA-v53h-89xp-f8xj.json b/advisories/unreviewed/2022/05/GHSA-v53h-89xp-f8xj/GHSA-v53h-89xp-f8xj.json index 4369b150717..7af28e35c1e 100644 --- a/advisories/unreviewed/2022/05/GHSA-v53h-89xp-f8xj/GHSA-v53h-89xp-f8xj.json +++ b/advisories/unreviewed/2022/05/GHSA-v53h-89xp-f8xj/GHSA-v53h-89xp-f8xj.json @@ -7,12 +7,8 @@ "CVE-2020-10051" ], "details": "A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). Multiple services of the affected application are executed with SYSTEM privileges while the call path is not quoted. This could allow a local attacker to inject arbitrary commands that are execeuted instead of the legitimate service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v6mq-89c8-6ff4/GHSA-v6mq-89c8-6ff4.json b/advisories/unreviewed/2022/05/GHSA-v6mq-89c8-6ff4/GHSA-v6mq-89c8-6ff4.json index d7f31f27d98..6b78c0d5093 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6mq-89c8-6ff4/GHSA-v6mq-89c8-6ff4.json +++ b/advisories/unreviewed/2022/05/GHSA-v6mq-89c8-6ff4/GHSA-v6mq-89c8-6ff4.json @@ -7,12 +7,8 @@ "CVE-2020-25559" ], "details": "gnuplot 5.5 is affected by double free when executing print_set_output. This may result in context-dependent arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v7f9-3v82-w67w/GHSA-v7f9-3v82-w67w.json b/advisories/unreviewed/2022/05/GHSA-v7f9-3v82-w67w/GHSA-v7f9-3v82-w67w.json index 38548c695da..45532c249cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7f9-3v82-w67w/GHSA-v7f9-3v82-w67w.json +++ b/advisories/unreviewed/2022/05/GHSA-v7f9-3v82-w67w/GHSA-v7f9-3v82-w67w.json @@ -7,12 +7,8 @@ "CVE-2020-0300" ], "details": "In NFC, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-148736216", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v8mw-xqhr-2vqp/GHSA-v8mw-xqhr-2vqp.json b/advisories/unreviewed/2022/05/GHSA-v8mw-xqhr-2vqp/GHSA-v8mw-xqhr-2vqp.json index d7d3e6876c4..29ed66e1a26 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8mw-xqhr-2vqp/GHSA-v8mw-xqhr-2vqp.json +++ b/advisories/unreviewed/2022/05/GHSA-v8mw-xqhr-2vqp/GHSA-v8mw-xqhr-2vqp.json @@ -7,12 +7,8 @@ "CVE-2020-14382" ], "details": "A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, that is effectively invoked on every device/image presenting itself as LUKS2 container. The bug is in segments validation code in file 'lib/luks2/luks2_json_metadata.c' in function hdr_validate_segments(struct crypt_device *cd, json_object *hdr_jobj) where the code does not check for possible overflow on memory allocation used for intervals array (see statement \"intervals = malloc(first_backup * sizeof(*intervals));\"). Due to the bug, library can be *tricked* to expect such allocation was successful but for far less memory then originally expected. Later it may read data FROM image crafted by an attacker and actually write such data BEYOND allocated memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v8qg-gvfx-g8vq/GHSA-v8qg-gvfx-g8vq.json b/advisories/unreviewed/2022/05/GHSA-v8qg-gvfx-g8vq/GHSA-v8qg-gvfx-g8vq.json index 8f7d6cee21b..6ea3337ac79 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8qg-gvfx-g8vq/GHSA-v8qg-gvfx-g8vq.json +++ b/advisories/unreviewed/2022/05/GHSA-v8qg-gvfx-g8vq/GHSA-v8qg-gvfx-g8vq.json @@ -7,12 +7,8 @@ "CVE-2020-3611" ], "details": "u'XBL SEC clears only ZI region when loading Qualcomm-signed segments can lead to improper access issue' in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in APQ8098, Kamorta, MSM8998, QCS404, QCS605, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SXR1130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v95m-8wq8-p4r8/GHSA-v95m-8wq8-p4r8.json b/advisories/unreviewed/2022/05/GHSA-v95m-8wq8-p4r8/GHSA-v95m-8wq8-p4r8.json index cb9fd7d5026..e8407cf03fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-v95m-8wq8-p4r8/GHSA-v95m-8wq8-p4r8.json +++ b/advisories/unreviewed/2022/05/GHSA-v95m-8wq8-p4r8/GHSA-v95m-8wq8-p4r8.json @@ -7,12 +7,8 @@ "CVE-2020-6331" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated HPGL file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v9wg-q5vm-7g4w/GHSA-v9wg-q5vm-7g4w.json b/advisories/unreviewed/2022/05/GHSA-v9wg-q5vm-7g4w/GHSA-v9wg-q5vm-7g4w.json index d18c9712e29..31a2ee4748c 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9wg-q5vm-7g4w/GHSA-v9wg-q5vm-7g4w.json +++ b/advisories/unreviewed/2022/05/GHSA-v9wg-q5vm-7g4w/GHSA-v9wg-q5vm-7g4w.json @@ -7,12 +7,8 @@ "CVE-2020-25279" ], "details": "An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The baseband component has a buffer overflow via an abnormal SETUP message, leading to execution of arbitrary code. The Samsung ID is SVE-2020-18098 (September 2020).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vcr6-44f9-7v58/GHSA-vcr6-44f9-7v58.json b/advisories/unreviewed/2022/05/GHSA-vcr6-44f9-7v58/GHSA-vcr6-44f9-7v58.json index 05d3a66a755..99053081b52 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcr6-44f9-7v58/GHSA-vcr6-44f9-7v58.json +++ b/advisories/unreviewed/2022/05/GHSA-vcr6-44f9-7v58/GHSA-vcr6-44f9-7v58.json @@ -7,12 +7,8 @@ "CVE-2020-6355" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated TGA file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vfqm-4cxm-qpxr/GHSA-vfqm-4cxm-qpxr.json b/advisories/unreviewed/2022/05/GHSA-vfqm-4cxm-qpxr/GHSA-vfqm-4cxm-qpxr.json index e7befeb9b64..1303974b8d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfqm-4cxm-qpxr/GHSA-vfqm-4cxm-qpxr.json +++ b/advisories/unreviewed/2022/05/GHSA-vfqm-4cxm-qpxr/GHSA-vfqm-4cxm-qpxr.json @@ -7,12 +7,8 @@ "CVE-2020-0336" ], "details": "In SurfaceFlinger, there is possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153467444", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vgwx-h8vg-v6jx/GHSA-vgwx-h8vg-v6jx.json b/advisories/unreviewed/2022/05/GHSA-vgwx-h8vg-v6jx/GHSA-vgwx-h8vg-v6jx.json index 29b498e85bb..e572f7566ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-vgwx-h8vg-v6jx/GHSA-vgwx-h8vg-v6jx.json +++ b/advisories/unreviewed/2022/05/GHSA-vgwx-h8vg-v6jx/GHSA-vgwx-h8vg-v6jx.json @@ -7,12 +7,8 @@ "CVE-2020-3634" ], "details": "u'Multiple Read overflows issue due to improper length check while decoding Generic NAS transport/EMM info' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ8096AU, APQ8098, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909W, MSM8917, MSM8953, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QCS610, QM215, Rennell, SA415M, Saipan, SC7180, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vjgc-v7h9-phhc/GHSA-vjgc-v7h9-phhc.json b/advisories/unreviewed/2022/05/GHSA-vjgc-v7h9-phhc/GHSA-vjgc-v7h9-phhc.json index 3c2ee59a170..3679daa8896 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjgc-v7h9-phhc/GHSA-vjgc-v7h9-phhc.json +++ b/advisories/unreviewed/2022/05/GHSA-vjgc-v7h9-phhc/GHSA-vjgc-v7h9-phhc.json @@ -7,12 +7,8 @@ "CVE-2020-3643" ], "details": "u'Information disclosure issue can occur due to partial secure display-touch session tear-down' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8076, APQ8096AU, APQ8098, IPQ6018, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9650, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA515M, SA6155P, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vp93-pr49-f4r2/GHSA-vp93-pr49-f4r2.json b/advisories/unreviewed/2022/05/GHSA-vp93-pr49-f4r2/GHSA-vp93-pr49-f4r2.json index 1866688fab2..c83d623124a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vp93-pr49-f4r2/GHSA-vp93-pr49-f4r2.json +++ b/advisories/unreviewed/2022/05/GHSA-vp93-pr49-f4r2/GHSA-vp93-pr49-f4r2.json @@ -7,12 +7,8 @@ "CVE-2020-6326" ], "details": "SAP NetWeaver (Knowledge Management), version-7.30,7.31,7.40,7.50, allows an authenticated attacker to create malicious links in the UI, when clicked by victim, will execute arbitrary java scripts thus extracting or modifying information otherwise restricted leading to Stored Cross Site Scripting.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vpqv-7qjc-x42g/GHSA-vpqv-7qjc-x42g.json b/advisories/unreviewed/2022/05/GHSA-vpqv-7qjc-x42g/GHSA-vpqv-7qjc-x42g.json index 1d634afbc32..414cedf2ba1 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpqv-7qjc-x42g/GHSA-vpqv-7qjc-x42g.json +++ b/advisories/unreviewed/2022/05/GHSA-vpqv-7qjc-x42g/GHSA-vpqv-7qjc-x42g.json @@ -7,12 +7,8 @@ "CVE-2020-25453" ], "details": "An issue was discovered in BlackCat CMS v.1.3.6. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vqh2-672q-h5xp/GHSA-vqh2-672q-h5xp.json b/advisories/unreviewed/2022/05/GHSA-vqh2-672q-h5xp/GHSA-vqh2-672q-h5xp.json index cd5c5386974..c71f31b7fbe 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqh2-672q-h5xp/GHSA-vqh2-672q-h5xp.json +++ b/advisories/unreviewed/2022/05/GHSA-vqh2-672q-h5xp/GHSA-vqh2-672q-h5xp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vr6x-m59x-pq35/GHSA-vr6x-m59x-pq35.json b/advisories/unreviewed/2022/05/GHSA-vr6x-m59x-pq35/GHSA-vr6x-m59x-pq35.json index 44e5744c8a8..c24c7286fc3 100644 --- a/advisories/unreviewed/2022/05/GHSA-vr6x-m59x-pq35/GHSA-vr6x-m59x-pq35.json +++ b/advisories/unreviewed/2022/05/GHSA-vr6x-m59x-pq35/GHSA-vr6x-m59x-pq35.json @@ -7,12 +7,8 @@ "CVE-2020-13127" ], "details": "A SQL injection vulnerability at a tpf URI in Loway QueueMetrics before 19.04.1 allows remote authenticated attackers to execute arbitrary SQL commands via the TASKS_LIST__pt.querystring parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vrc8-63q3-rgq3/GHSA-vrc8-63q3-rgq3.json b/advisories/unreviewed/2022/05/GHSA-vrc8-63q3-rgq3/GHSA-vrc8-63q3-rgq3.json index 9d7da61fc60..5064e1f8394 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrc8-63q3-rgq3/GHSA-vrc8-63q3-rgq3.json +++ b/advisories/unreviewed/2022/05/GHSA-vrc8-63q3-rgq3/GHSA-vrc8-63q3-rgq3.json @@ -7,12 +7,8 @@ "CVE-2020-6360" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vvm8-37ch-xp6p/GHSA-vvm8-37ch-xp6p.json b/advisories/unreviewed/2022/05/GHSA-vvm8-37ch-xp6p/GHSA-vvm8-37ch-xp6p.json index 1ed5271a671..45cd167a554 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvm8-37ch-xp6p/GHSA-vvm8-37ch-xp6p.json +++ b/advisories/unreviewed/2022/05/GHSA-vvm8-37ch-xp6p/GHSA-vvm8-37ch-xp6p.json @@ -7,12 +7,8 @@ "CVE-2019-13999" ], "details": "u'Lack of check for integer overflow for round up and addition operations result into memory corruption and potential information leakage' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA515M, SA6155P, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vx8r-4fwr-hc2v/GHSA-vx8r-4fwr-hc2v.json b/advisories/unreviewed/2022/05/GHSA-vx8r-4fwr-hc2v/GHSA-vx8r-4fwr-hc2v.json index 677d3e3c2ca..da8bc622221 100644 --- a/advisories/unreviewed/2022/05/GHSA-vx8r-4fwr-hc2v/GHSA-vx8r-4fwr-hc2v.json +++ b/advisories/unreviewed/2022/05/GHSA-vx8r-4fwr-hc2v/GHSA-vx8r-4fwr-hc2v.json @@ -7,12 +7,8 @@ "CVE-2020-9416" ], "details": "The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, and TIBCO Spotfire Server contains a vulnerability that theoretically allows a legitimate user to inject scripts. If executed by a victim authenticated to the affected system these scripts will be executed at the privileges of the victim. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions 10.7.0, 10.8.0, 10.9.0, and 10.10.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: versions 10.7.0, 10.8.0, 10.8.1, 10.9.0, 10.10.0, and 10.10.1, TIBCO Spotfire Desktop: versions 10.7.0, 10.8.0, 10.9.0, and 10.10.0, and TIBCO Spotfire Server: versions 10.7.0, 10.8.0, 10.8.1, 10.9.0, 10.10.0, and 10.10.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vxw3-96f4-67xp/GHSA-vxw3-96f4-67xp.json b/advisories/unreviewed/2022/05/GHSA-vxw3-96f4-67xp/GHSA-vxw3-96f4-67xp.json index 8090e333d2e..c2eeb755e41 100644 --- a/advisories/unreviewed/2022/05/GHSA-vxw3-96f4-67xp/GHSA-vxw3-96f4-67xp.json +++ b/advisories/unreviewed/2022/05/GHSA-vxw3-96f4-67xp/GHSA-vxw3-96f4-67xp.json @@ -7,12 +7,8 @@ "CVE-2020-3648" ], "details": "u'Possible out of bound write in DSP driver code due to lack of check of data received from user' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w35w-5rg7-v2c5/GHSA-w35w-5rg7-v2c5.json b/advisories/unreviewed/2022/05/GHSA-w35w-5rg7-v2c5/GHSA-w35w-5rg7-v2c5.json index 198db650fa9..af7b8763969 100644 --- a/advisories/unreviewed/2022/05/GHSA-w35w-5rg7-v2c5/GHSA-w35w-5rg7-v2c5.json +++ b/advisories/unreviewed/2022/05/GHSA-w35w-5rg7-v2c5/GHSA-w35w-5rg7-v2c5.json @@ -7,12 +7,8 @@ "CVE-2020-6338" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RH file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w452-97x5-fxw2/GHSA-w452-97x5-fxw2.json b/advisories/unreviewed/2022/05/GHSA-w452-97x5-fxw2/GHSA-w452-97x5-fxw2.json index eaeb3447f3a..1bf9ee33efe 100644 --- a/advisories/unreviewed/2022/05/GHSA-w452-97x5-fxw2/GHSA-w452-97x5-fxw2.json +++ b/advisories/unreviewed/2022/05/GHSA-w452-97x5-fxw2/GHSA-w452-97x5-fxw2.json @@ -7,12 +7,8 @@ "CVE-2020-0302" ], "details": "In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151646375", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w49v-8458-hh85/GHSA-w49v-8458-hh85.json b/advisories/unreviewed/2022/05/GHSA-w49v-8458-hh85/GHSA-w49v-8458-hh85.json index fa007d48c34..9a141d51099 100644 --- a/advisories/unreviewed/2022/05/GHSA-w49v-8458-hh85/GHSA-w49v-8458-hh85.json +++ b/advisories/unreviewed/2022/05/GHSA-w49v-8458-hh85/GHSA-w49v-8458-hh85.json @@ -7,12 +7,8 @@ "CVE-2020-25079" ], "details": "An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w56x-hj26-mq65/GHSA-w56x-hj26-mq65.json b/advisories/unreviewed/2022/05/GHSA-w56x-hj26-mq65/GHSA-w56x-hj26-mq65.json index 9c576934650..26796660268 100644 --- a/advisories/unreviewed/2022/05/GHSA-w56x-hj26-mq65/GHSA-w56x-hj26-mq65.json +++ b/advisories/unreviewed/2022/05/GHSA-w56x-hj26-mq65/GHSA-w56x-hj26-mq65.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w63g-378w-5j6f/GHSA-w63g-378w-5j6f.json b/advisories/unreviewed/2022/05/GHSA-w63g-378w-5j6f/GHSA-w63g-378w-5j6f.json index 354f8c30d5a..2ff3dd8b4a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-w63g-378w-5j6f/GHSA-w63g-378w-5j6f.json +++ b/advisories/unreviewed/2022/05/GHSA-w63g-378w-5j6f/GHSA-w63g-378w-5j6f.json @@ -7,12 +7,8 @@ "CVE-2020-24604" ], "details": "A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request \"searchName\", \"searchValue\", \"searchDescription\", \"searchDefaultValue\",\"searchPlugin\", \"searchDescription\" and \"searchDynamic\" in server-properties.jsp and security-audit-viewer.jsp", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w7hh-546g-p758/GHSA-w7hh-546g-p758.json b/advisories/unreviewed/2022/05/GHSA-w7hh-546g-p758/GHSA-w7hh-546g-p758.json index 73257d61b4b..600ab629261 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7hh-546g-p758/GHSA-w7hh-546g-p758.json +++ b/advisories/unreviewed/2022/05/GHSA-w7hh-546g-p758/GHSA-w7hh-546g-p758.json @@ -7,12 +7,8 @@ "CVE-2020-13304" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated which resulted an attacker to maintain access under certain conditions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w97r-xg4x-xx2r/GHSA-w97r-xg4x-xx2r.json b/advisories/unreviewed/2022/05/GHSA-w97r-xg4x-xx2r/GHSA-w97r-xg4x-xx2r.json index d5e89f926f2..4f9996be942 100644 --- a/advisories/unreviewed/2022/05/GHSA-w97r-xg4x-xx2r/GHSA-w97r-xg4x-xx2r.json +++ b/advisories/unreviewed/2022/05/GHSA-w97r-xg4x-xx2r/GHSA-w97r-xg4x-xx2r.json @@ -7,12 +7,8 @@ "CVE-2020-14509" ], "details": "Multiple memory corruption vulnerabilities exist in CodeMeter (All versions prior to 7.10) where the packet parser mechanism does not verify length fields. An attacker could send specially crafted packets to exploit these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wc24-5j7x-rp2x/GHSA-wc24-5j7x-rp2x.json b/advisories/unreviewed/2022/05/GHSA-wc24-5j7x-rp2x/GHSA-wc24-5j7x-rp2x.json index 57951359e22..cfea1c1506a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc24-5j7x-rp2x/GHSA-wc24-5j7x-rp2x.json +++ b/advisories/unreviewed/2022/05/GHSA-wc24-5j7x-rp2x/GHSA-wc24-5j7x-rp2x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wc59-9v92-fgr3/GHSA-wc59-9v92-fgr3.json b/advisories/unreviewed/2022/05/GHSA-wc59-9v92-fgr3/GHSA-wc59-9v92-fgr3.json index e936a426123..6d0ba347881 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc59-9v92-fgr3/GHSA-wc59-9v92-fgr3.json +++ b/advisories/unreviewed/2022/05/GHSA-wc59-9v92-fgr3/GHSA-wc59-9v92-fgr3.json @@ -7,12 +7,8 @@ "CVE-2020-0333" ], "details": "In UrlQuerySanitizer, there is a possible improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-73822755", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wc5h-vpgx-mqjw/GHSA-wc5h-vpgx-mqjw.json b/advisories/unreviewed/2022/05/GHSA-wc5h-vpgx-mqjw/GHSA-wc5h-vpgx-mqjw.json index 45b2be17d58..9de4e8f6863 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc5h-vpgx-mqjw/GHSA-wc5h-vpgx-mqjw.json +++ b/advisories/unreviewed/2022/05/GHSA-wc5h-vpgx-mqjw/GHSA-wc5h-vpgx-mqjw.json @@ -7,12 +7,8 @@ "CVE-2020-3621" ], "details": "u'Lack of check to ensure that the TX read index & RX write index that are read from shared memory are less than the FIFO size results into memory corruption and potential information leakage' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wfvm-4gxx-hpcr/GHSA-wfvm-4gxx-hpcr.json b/advisories/unreviewed/2022/05/GHSA-wfvm-4gxx-hpcr/GHSA-wfvm-4gxx-hpcr.json index 140f3e2ab52..c9820f9e58c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfvm-4gxx-hpcr/GHSA-wfvm-4gxx-hpcr.json +++ b/advisories/unreviewed/2022/05/GHSA-wfvm-4gxx-hpcr/GHSA-wfvm-4gxx-hpcr.json @@ -7,12 +7,8 @@ "CVE-2020-10227" ], "details": "A cross-site scripting (XSS) vulnerability in the messages module of vtecrm vtenext 19 CE allows attackers to inject arbitrary JavaScript code via the From field of an email.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wfwj-6wvw-xhcw/GHSA-wfwj-6wvw-xhcw.json b/advisories/unreviewed/2022/05/GHSA-wfwj-6wvw-xhcw/GHSA-wfwj-6wvw-xhcw.json index 893402a0c93..c4e129f9874 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfwj-6wvw-xhcw/GHSA-wfwj-6wvw-xhcw.json +++ b/advisories/unreviewed/2022/05/GHSA-wfwj-6wvw-xhcw/GHSA-wfwj-6wvw-xhcw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wh2h-r4h5-rjx4/GHSA-wh2h-r4h5-rjx4.json b/advisories/unreviewed/2022/05/GHSA-wh2h-r4h5-rjx4/GHSA-wh2h-r4h5-rjx4.json index afc80f28f1b..b32cdb11a55 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh2h-r4h5-rjx4/GHSA-wh2h-r4h5-rjx4.json +++ b/advisories/unreviewed/2022/05/GHSA-wh2h-r4h5-rjx4/GHSA-wh2h-r4h5-rjx4.json @@ -7,12 +7,8 @@ "CVE-2020-12058" ], "details": "Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php, catalog/admin/languages.php, catalog/admin/countries.php, catalog/admin/tax_classes.php, catalog/admin/reviews.php, or catalog/admin/zones.php; or the zpage or spage parameter to catalog/admin/geo_zones.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wh9c-c583-h226/GHSA-wh9c-c583-h226.json b/advisories/unreviewed/2022/05/GHSA-wh9c-c583-h226/GHSA-wh9c-c583-h226.json index 6835371df05..ae49f909531 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh9c-c583-h226/GHSA-wh9c-c583-h226.json +++ b/advisories/unreviewed/2022/05/GHSA-wh9c-c583-h226/GHSA-wh9c-c583-h226.json @@ -7,12 +7,8 @@ "CVE-2020-6341" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated EPS file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wh9w-pc8q-w744/GHSA-wh9w-pc8q-w744.json b/advisories/unreviewed/2022/05/GHSA-wh9w-pc8q-w744/GHSA-wh9w-pc8q-w744.json index 61c583ed440..de13c350a81 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh9w-pc8q-w744/GHSA-wh9w-pc8q-w744.json +++ b/advisories/unreviewed/2022/05/GHSA-wh9w-pc8q-w744/GHSA-wh9w-pc8q-w744.json @@ -7,12 +7,8 @@ "CVE-2020-0407" ], "details": "In various functions in fscrypt_ice.c and related files in some implementations of f2fs encryption that use encryption hardware which only supports 32-bit IVs (Initialization Vectors), 64-bit IVs are used and later are truncated to 32 bits. This may cause IV reuse and thus weakened disk encryption. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-153450752References: N/A", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wj74-9qqx-pg4x/GHSA-wj74-9qqx-pg4x.json b/advisories/unreviewed/2022/05/GHSA-wj74-9qqx-pg4x/GHSA-wj74-9qqx-pg4x.json index 792d7fb838f..9a814bee7ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-wj74-9qqx-pg4x/GHSA-wj74-9qqx-pg4x.json +++ b/advisories/unreviewed/2022/05/GHSA-wj74-9qqx-pg4x/GHSA-wj74-9qqx-pg4x.json @@ -7,12 +7,8 @@ "CVE-2020-22158" ], "details": "Ericsson RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has to inject JavaScript code directly in the \"path\" or \"Services+ID\" parameters and send the URL to a user in order to exploit reflected XSS. In the case of stored XSS, an attacker must modify the \"name\" parameter with the malicious code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wjc6-gjj8-cjmf/GHSA-wjc6-gjj8-cjmf.json b/advisories/unreviewed/2022/05/GHSA-wjc6-gjj8-cjmf/GHSA-wjc6-gjj8-cjmf.json index 715bf7b6f41..a6e7b4066a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjc6-gjj8-cjmf/GHSA-wjc6-gjj8-cjmf.json +++ b/advisories/unreviewed/2022/05/GHSA-wjc6-gjj8-cjmf/GHSA-wjc6-gjj8-cjmf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmxr-q76g-c3rw/GHSA-wmxr-q76g-c3rw.json b/advisories/unreviewed/2022/05/GHSA-wmxr-q76g-c3rw/GHSA-wmxr-q76g-c3rw.json index d09a2ea8e62..cd285ee3d75 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmxr-q76g-c3rw/GHSA-wmxr-q76g-c3rw.json +++ b/advisories/unreviewed/2022/05/GHSA-wmxr-q76g-c3rw/GHSA-wmxr-q76g-c3rw.json @@ -7,12 +7,8 @@ "CVE-2020-0268" ], "details": "In NFC, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-148294643", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wqcp-rc88-3mjf/GHSA-wqcp-rc88-3mjf.json b/advisories/unreviewed/2022/05/GHSA-wqcp-rc88-3mjf/GHSA-wqcp-rc88-3mjf.json index cdc8f3a34a7..c6e659b6c52 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqcp-rc88-3mjf/GHSA-wqcp-rc88-3mjf.json +++ b/advisories/unreviewed/2022/05/GHSA-wqcp-rc88-3mjf/GHSA-wqcp-rc88-3mjf.json @@ -7,12 +7,8 @@ "CVE-2020-3629" ], "details": "u'Stack out of bound issue occurs when making query to DSP capabilities due to wrong assumption was made on determining the buffer size for the DSP attributes' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in Bitra, Kamorta, Rennell, SC7180, SDM845, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wqwx-hvg4-2wh9/GHSA-wqwx-hvg4-2wh9.json b/advisories/unreviewed/2022/05/GHSA-wqwx-hvg4-2wh9/GHSA-wqwx-hvg4-2wh9.json index bb74bedfd11..93483d22b21 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqwx-hvg4-2wh9/GHSA-wqwx-hvg4-2wh9.json +++ b/advisories/unreviewed/2022/05/GHSA-wqwx-hvg4-2wh9/GHSA-wqwx-hvg4-2wh9.json @@ -7,12 +7,8 @@ "CVE-2020-10718" ], "details": "A flaw was found in Wildfly before wildfly-embedded-13.0.0.Final, where the embedded managed process API has an exposed setting of the Thread Context Classloader (TCCL). This setting is exposed as a public method, which can bypass the security manager. The highest threat from this vulnerability is to confidentiality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wrjw-6w8m-xcwh/GHSA-wrjw-6w8m-xcwh.json b/advisories/unreviewed/2022/05/GHSA-wrjw-6w8m-xcwh/GHSA-wrjw-6w8m-xcwh.json index c0f9ce04b34..46c49622e2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrjw-6w8m-xcwh/GHSA-wrjw-6w8m-xcwh.json +++ b/advisories/unreviewed/2022/05/GHSA-wrjw-6w8m-xcwh/GHSA-wrjw-6w8m-xcwh.json @@ -7,12 +7,8 @@ "CVE-2020-11683" ], "details": "A timing side channel was discovered in AT91bootstrap before 3.9.2. It can be exploited by attackers with physical access to forge CMAC values and subsequently boot arbitrary code on an affected system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wrr9-hwhq-cmwg/GHSA-wrr9-hwhq-cmwg.json b/advisories/unreviewed/2022/05/GHSA-wrr9-hwhq-cmwg/GHSA-wrr9-hwhq-cmwg.json index 42bf5ccaf69..e18bb8c7956 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrr9-hwhq-cmwg/GHSA-wrr9-hwhq-cmwg.json +++ b/advisories/unreviewed/2022/05/GHSA-wrr9-hwhq-cmwg/GHSA-wrr9-hwhq-cmwg.json @@ -7,12 +7,8 @@ "CVE-2020-9733" ], "details": "An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If exploited, this could lead to read-only access to sensitive data in an AEM repository.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wrx5-q6rx-f5p3/GHSA-wrx5-q6rx-f5p3.json b/advisories/unreviewed/2022/05/GHSA-wrx5-q6rx-f5p3/GHSA-wrx5-q6rx-f5p3.json index fa30e187b81..47e7dcb1fcb 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrx5-q6rx-f5p3/GHSA-wrx5-q6rx-f5p3.json +++ b/advisories/unreviewed/2022/05/GHSA-wrx5-q6rx-f5p3/GHSA-wrx5-q6rx-f5p3.json @@ -7,12 +7,8 @@ "CVE-2020-3669" ], "details": "u'Buffer Overflow issue in WLAN tcp ip verification due to usage of out of range pointer offset' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8098, IPQ5018, IPQ6018, IPQ8074, Kamorta, MSM8998, Nicobar, QCA6390, QCA8081, QCN7605, QCS404, QCS405, QCS605, Rennell, SA415M, SC7180, SC8180X, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SM8250, SXR1130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wv8f-fxfc-vvj4/GHSA-wv8f-fxfc-vvj4.json b/advisories/unreviewed/2022/05/GHSA-wv8f-fxfc-vvj4/GHSA-wv8f-fxfc-vvj4.json index 4606e061f56..b0c36c60155 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv8f-fxfc-vvj4/GHSA-wv8f-fxfc-vvj4.json +++ b/advisories/unreviewed/2022/05/GHSA-wv8f-fxfc-vvj4/GHSA-wv8f-fxfc-vvj4.json @@ -7,12 +7,8 @@ "CVE-2020-25278" ], "details": "An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The Quram image codec library allows attackers to overwrite memory and execute arbitrary code via crafted JPEG data that is mishandled during decoding. The Samsung IDs are SVE-2020-18088, SVE-2020-18225, SVE-2020-18301 (September 2020).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wwgg-2c86-7h3q/GHSA-wwgg-2c86-7h3q.json b/advisories/unreviewed/2022/05/GHSA-wwgg-2c86-7h3q/GHSA-wwgg-2c86-7h3q.json index 3578aba3a25..2f234afc849 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwgg-2c86-7h3q/GHSA-wwgg-2c86-7h3q.json +++ b/advisories/unreviewed/2022/05/GHSA-wwgg-2c86-7h3q/GHSA-wwgg-2c86-7h3q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxhm-qq5v-rf47/GHSA-wxhm-qq5v-rf47.json b/advisories/unreviewed/2022/05/GHSA-wxhm-qq5v-rf47/GHSA-wxhm-qq5v-rf47.json index f52ef24b55e..1f03732c151 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxhm-qq5v-rf47/GHSA-wxhm-qq5v-rf47.json +++ b/advisories/unreviewed/2022/05/GHSA-wxhm-qq5v-rf47/GHSA-wxhm-qq5v-rf47.json @@ -7,12 +7,8 @@ "CVE-2020-3622" ], "details": "u'Channel name string which has been read from shared memory is potentially subjected to string manipulations but not validated for NULL termination can results into memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3vr-p44r-4h38/GHSA-x3vr-p44r-4h38.json b/advisories/unreviewed/2022/05/GHSA-x3vr-p44r-4h38/GHSA-x3vr-p44r-4h38.json index 6475814f728..41d89b70bd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3vr-p44r-4h38/GHSA-x3vr-p44r-4h38.json +++ b/advisories/unreviewed/2022/05/GHSA-x3vr-p44r-4h38/GHSA-x3vr-p44r-4h38.json @@ -7,12 +7,8 @@ "CVE-2019-14115" ], "details": "u'Information disclosure issue occurs as in current logic as secure touch is released without clearing the display session which can result in user reading the secure input while touch is in non-secure domain as secure display is active' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8076, APQ8096AU, APQ8098, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9650, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA515M, SA6155P, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x42c-7gjh-r9fx/GHSA-x42c-7gjh-r9fx.json b/advisories/unreviewed/2022/05/GHSA-x42c-7gjh-r9fx/GHSA-x42c-7gjh-r9fx.json index f69a77eeb39..6f99a826db0 100644 --- a/advisories/unreviewed/2022/05/GHSA-x42c-7gjh-r9fx/GHSA-x42c-7gjh-r9fx.json +++ b/advisories/unreviewed/2022/05/GHSA-x42c-7gjh-r9fx/GHSA-x42c-7gjh-r9fx.json @@ -7,12 +7,8 @@ "CVE-2020-2039" ], "details": "An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user to upload temporary files through the management web interface that are not properly deleted after the request is finished. It is possible for an attacker to disrupt the availability of the management web interface by repeatedly uploading files until available disk space is exhausted. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PAN-OS 9.0 versions earlier than PAN-OS 9.0.10; PAN-OS 9.1 versions earlier than PAN-OS 9.1.4; PAN-OS 10.0 versions earlier than PAN-OS 10.0.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x4jp-r3j2-5jxx/GHSA-x4jp-r3j2-5jxx.json b/advisories/unreviewed/2022/05/GHSA-x4jp-r3j2-5jxx/GHSA-x4jp-r3j2-5jxx.json index afb36ceb938..f6f154c73bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4jp-r3j2-5jxx/GHSA-x4jp-r3j2-5jxx.json +++ b/advisories/unreviewed/2022/05/GHSA-x4jp-r3j2-5jxx/GHSA-x4jp-r3j2-5jxx.json @@ -7,12 +7,8 @@ "CVE-2020-0263" ], "details": "In the Accessibility service, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154913130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x4rf-jx7j-r49m/GHSA-x4rf-jx7j-r49m.json b/advisories/unreviewed/2022/05/GHSA-x4rf-jx7j-r49m/GHSA-x4rf-jx7j-r49m.json index bd299ade101..7ab553cd7ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4rf-jx7j-r49m/GHSA-x4rf-jx7j-r49m.json +++ b/advisories/unreviewed/2022/05/GHSA-x4rf-jx7j-r49m/GHSA-x4rf-jx7j-r49m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x545-vr57-rgh9/GHSA-x545-vr57-rgh9.json b/advisories/unreviewed/2022/05/GHSA-x545-vr57-rgh9/GHSA-x545-vr57-rgh9.json index c62342dd4c8..4ce50e2d9c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-x545-vr57-rgh9/GHSA-x545-vr57-rgh9.json +++ b/advisories/unreviewed/2022/05/GHSA-x545-vr57-rgh9/GHSA-x545-vr57-rgh9.json @@ -7,12 +7,8 @@ "CVE-2020-0391" ], "details": "In applyPolicy of PackageManagerService.java, there is possible arbitrary command execution as System due to an unenforced protected-broadcast. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-158570769", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x634-f296-rwgv/GHSA-x634-f296-rwgv.json b/advisories/unreviewed/2022/05/GHSA-x634-f296-rwgv/GHSA-x634-f296-rwgv.json index f50b1ba6787..3d7637f2817 100644 --- a/advisories/unreviewed/2022/05/GHSA-x634-f296-rwgv/GHSA-x634-f296-rwgv.json +++ b/advisories/unreviewed/2022/05/GHSA-x634-f296-rwgv/GHSA-x634-f296-rwgv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x884-xw28-vpw4/GHSA-x884-xw28-vpw4.json b/advisories/unreviewed/2022/05/GHSA-x884-xw28-vpw4/GHSA-x884-xw28-vpw4.json index 43f29fd9974..d99a7a5fb63 100644 --- a/advisories/unreviewed/2022/05/GHSA-x884-xw28-vpw4/GHSA-x884-xw28-vpw4.json +++ b/advisories/unreviewed/2022/05/GHSA-x884-xw28-vpw4/GHSA-x884-xw28-vpw4.json @@ -7,12 +7,8 @@ "CVE-2020-7807" ], "details": "A vulnerability that can hijack a DLL file that is loaded during products(LGPCSuite_Setup, IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup) installation into a DLL file that the hacker wants. Missing Support for Integrity Check vulnerability in ____COMPONENT____ of LG Electronics (LGPCSuite_Setup), (IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup) allows ____ATTACKER/ATTACK____ to cause ____IMPACT____. This issue affects: LG Electronics; LGPCSuite_Setup : 1.0.0.3 on Windows(x86, x64); IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup : 1.0.0.9 on Windows(x86, x64).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x8mp-jv75-5hrp/GHSA-x8mp-jv75-5hrp.json b/advisories/unreviewed/2022/05/GHSA-x8mp-jv75-5hrp/GHSA-x8mp-jv75-5hrp.json index c26505afd5e..de85a951449 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8mp-jv75-5hrp/GHSA-x8mp-jv75-5hrp.json +++ b/advisories/unreviewed/2022/05/GHSA-x8mp-jv75-5hrp/GHSA-x8mp-jv75-5hrp.json @@ -7,12 +7,8 @@ "CVE-2020-13316" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a git command line.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x8v2-f8hm-jwjh/GHSA-x8v2-f8hm-jwjh.json b/advisories/unreviewed/2022/05/GHSA-x8v2-f8hm-jwjh/GHSA-x8v2-f8hm-jwjh.json index 9e7ba5e4c52..80d169743df 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8v2-f8hm-jwjh/GHSA-x8v2-f8hm-jwjh.json +++ b/advisories/unreviewed/2022/05/GHSA-x8v2-f8hm-jwjh/GHSA-x8v2-f8hm-jwjh.json @@ -7,12 +7,8 @@ "CVE-2020-0303" ], "details": "In the Media extractor, there is a possible use after free due to improper locking. This could lead to remote code execution in the media extractor with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-148223229", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xc45-gmq4-mwpv/GHSA-xc45-gmq4-mwpv.json b/advisories/unreviewed/2022/05/GHSA-xc45-gmq4-mwpv/GHSA-xc45-gmq4-mwpv.json index 5ee854bc070..809c1ba14b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc45-gmq4-mwpv/GHSA-xc45-gmq4-mwpv.json +++ b/advisories/unreviewed/2022/05/GHSA-xc45-gmq4-mwpv/GHSA-xc45-gmq4-mwpv.json @@ -7,12 +7,8 @@ "CVE-2020-24794" ], "details": "Cross Site Scripting (XSS) vulnerability in Kentico before 12.0.75.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xf5g-q7vm-4fg3/GHSA-xf5g-q7vm-4fg3.json b/advisories/unreviewed/2022/05/GHSA-xf5g-q7vm-4fg3/GHSA-xf5g-q7vm-4fg3.json index 6b4e85114d5..36287db881d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf5g-q7vm-4fg3/GHSA-xf5g-q7vm-4fg3.json +++ b/advisories/unreviewed/2022/05/GHSA-xf5g-q7vm-4fg3/GHSA-xf5g-q7vm-4fg3.json @@ -7,12 +7,8 @@ "CVE-2020-3988" ], "details": "VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (JPEG2000 parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak memory from TPView process running on the system where Workstation or Horizon Client for Windows is installed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xg8m-gfp3-4fv6/GHSA-xg8m-gfp3-4fv6.json b/advisories/unreviewed/2022/05/GHSA-xg8m-gfp3-4fv6/GHSA-xg8m-gfp3-4fv6.json index 98bf8694168..8938174efc2 100644 --- a/advisories/unreviewed/2022/05/GHSA-xg8m-gfp3-4fv6/GHSA-xg8m-gfp3-4fv6.json +++ b/advisories/unreviewed/2022/05/GHSA-xg8m-gfp3-4fv6/GHSA-xg8m-gfp3-4fv6.json @@ -7,12 +7,8 @@ "CVE-2020-13311" ], "details": "A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits anyone from accessing the Wiki functionality through the user interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xj2w-7m9r-98q7/GHSA-xj2w-7m9r-98q7.json b/advisories/unreviewed/2022/05/GHSA-xj2w-7m9r-98q7/GHSA-xj2w-7m9r-98q7.json index aa1188eec40..313e9eabef9 100644 --- a/advisories/unreviewed/2022/05/GHSA-xj2w-7m9r-98q7/GHSA-xj2w-7m9r-98q7.json +++ b/advisories/unreviewed/2022/05/GHSA-xj2w-7m9r-98q7/GHSA-xj2w-7m9r-98q7.json @@ -7,12 +7,8 @@ "CVE-2020-24601" ], "details": "In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameter searchName\", \"alias\" in the import certificate trusted page", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjqp-g574-g782/GHSA-xjqp-g574-g782.json b/advisories/unreviewed/2022/05/GHSA-xjqp-g574-g782/GHSA-xjqp-g574-g782.json index 1b94cd3c49e..52840723681 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjqp-g574-g782/GHSA-xjqp-g574-g782.json +++ b/advisories/unreviewed/2022/05/GHSA-xjqp-g574-g782/GHSA-xjqp-g574-g782.json @@ -7,12 +7,8 @@ "CVE-2020-11116" ], "details": "u'Possible out of bound write while processing association response received from host due to lack of check of IE length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8053, APQ8096AU, APQ8098, Bitra, Kamorta, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCM2150, QCN7605, QCS405, QCS605, QCS610, QM215, SA6155P, Saipan, SC8180X, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xm43-qc4p-9f7j/GHSA-xm43-qc4p-9f7j.json b/advisories/unreviewed/2022/05/GHSA-xm43-qc4p-9f7j/GHSA-xm43-qc4p-9f7j.json index 314a0479c3a..e752f644430 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm43-qc4p-9f7j/GHSA-xm43-qc4p-9f7j.json +++ b/advisories/unreviewed/2022/05/GHSA-xm43-qc4p-9f7j/GHSA-xm43-qc4p-9f7j.json @@ -7,12 +7,8 @@ "CVE-2020-14392" ], "details": "An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xmvc-mhq7-5v2v/GHSA-xmvc-mhq7-5v2v.json b/advisories/unreviewed/2022/05/GHSA-xmvc-mhq7-5v2v/GHSA-xmvc-mhq7-5v2v.json index 86abfa1af33..120b2862f01 100644 --- a/advisories/unreviewed/2022/05/GHSA-xmvc-mhq7-5v2v/GHSA-xmvc-mhq7-5v2v.json +++ b/advisories/unreviewed/2022/05/GHSA-xmvc-mhq7-5v2v/GHSA-xmvc-mhq7-5v2v.json @@ -7,12 +7,8 @@ "CVE-2020-24194" ], "details": "A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xp3q-55jv-wpp2/GHSA-xp3q-55jv-wpp2.json b/advisories/unreviewed/2022/05/GHSA-xp3q-55jv-wpp2/GHSA-xp3q-55jv-wpp2.json index 190c9f6d697..a213103703f 100644 --- a/advisories/unreviewed/2022/05/GHSA-xp3q-55jv-wpp2/GHSA-xp3q-55jv-wpp2.json +++ b/advisories/unreviewed/2022/05/GHSA-xp3q-55jv-wpp2/GHSA-xp3q-55jv-wpp2.json @@ -7,12 +7,8 @@ "CVE-2020-5379" ], "details": "Dell Inspiron 7352 BIOS versions prior to A12 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management Mode (SMM).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xpxh-fh9m-hf5v/GHSA-xpxh-fh9m-hf5v.json b/advisories/unreviewed/2022/05/GHSA-xpxh-fh9m-hf5v/GHSA-xpxh-fh9m-hf5v.json index 016e3f53e49..aa2cf6c2907 100644 --- a/advisories/unreviewed/2022/05/GHSA-xpxh-fh9m-hf5v/GHSA-xpxh-fh9m-hf5v.json +++ b/advisories/unreviewed/2022/05/GHSA-xpxh-fh9m-hf5v/GHSA-xpxh-fh9m-hf5v.json @@ -7,12 +7,8 @@ "CVE-2020-6345" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated TGA file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xr8r-7f7p-x5r5/GHSA-xr8r-7f7p-x5r5.json b/advisories/unreviewed/2022/05/GHSA-xr8r-7f7p-x5r5/GHSA-xr8r-7f7p-x5r5.json index 4daaef02429..faf08698920 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr8r-7f7p-x5r5/GHSA-xr8r-7f7p-x5r5.json +++ b/advisories/unreviewed/2022/05/GHSA-xr8r-7f7p-x5r5/GHSA-xr8r-7f7p-x5r5.json @@ -7,12 +7,8 @@ "CVE-2020-9727" ], "details": "A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xv63-838w-fgf7/GHSA-xv63-838w-fgf7.json b/advisories/unreviewed/2022/05/GHSA-xv63-838w-fgf7/GHSA-xv63-838w-fgf7.json index ece5e692ed1..3e0f83f430e 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv63-838w-fgf7/GHSA-xv63-838w-fgf7.json +++ b/advisories/unreviewed/2022/05/GHSA-xv63-838w-fgf7/GHSA-xv63-838w-fgf7.json @@ -7,12 +7,8 @@ "CVE-2020-24028" ], "details": "ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xv7h-qpjm-g3jp/GHSA-xv7h-qpjm-g3jp.json b/advisories/unreviewed/2022/05/GHSA-xv7h-qpjm-g3jp/GHSA-xv7h-qpjm-g3jp.json index 71715cea154..a680dd0e537 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv7h-qpjm-g3jp/GHSA-xv7h-qpjm-g3jp.json +++ b/advisories/unreviewed/2022/05/GHSA-xv7h-qpjm-g3jp/GHSA-xv7h-qpjm-g3jp.json @@ -7,12 +7,8 @@ "CVE-2020-0405" ], "details": "In NetworkStackNotifier, there is a possible permissions bypass due to an unsafe implicit PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157475111", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xvh3-fg8j-wp79/GHSA-xvh3-fg8j-wp79.json b/advisories/unreviewed/2022/05/GHSA-xvh3-fg8j-wp79/GHSA-xvh3-fg8j-wp79.json index 4229302883f..1a39a5ed842 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvh3-fg8j-wp79/GHSA-xvh3-fg8j-wp79.json +++ b/advisories/unreviewed/2022/05/GHSA-xvh3-fg8j-wp79/GHSA-xvh3-fg8j-wp79.json @@ -7,12 +7,8 @@ "CVE-2019-14119" ], "details": "u'While processing SMCInvoke asynchronous message header, message count is modified leading to a TOCTOU race condition and lead to memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ6018, Kamorta, MDM9205, MDM9607, Nicobar, QCS404, QCS405, QCS605, QCS610, Rennell, SA415M, SA515M, SA6155P, SC7180, SC8180X, SDM670, SDM710, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-8rvm-f29f-fjx6/GHSA-8rvm-f29f-fjx6.json b/advisories/unreviewed/2022/07/GHSA-8rvm-f29f-fjx6/GHSA-8rvm-f29f-fjx6.json index 839a2b3556b..4f4395a17cf 100644 --- a/advisories/unreviewed/2022/07/GHSA-8rvm-f29f-fjx6/GHSA-8rvm-f29f-fjx6.json +++ b/advisories/unreviewed/2022/07/GHSA-8rvm-f29f-fjx6/GHSA-8rvm-f29f-fjx6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-2h4c-86hw-hmr7/GHSA-2h4c-86hw-hmr7.json b/advisories/unreviewed/2022/08/GHSA-2h4c-86hw-hmr7/GHSA-2h4c-86hw-hmr7.json index 6b4c3c4ddbd..c7afee85cc3 100644 --- a/advisories/unreviewed/2022/08/GHSA-2h4c-86hw-hmr7/GHSA-2h4c-86hw-hmr7.json +++ b/advisories/unreviewed/2022/08/GHSA-2h4c-86hw-hmr7/GHSA-2h4c-86hw-hmr7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-3qmv-v22h-rc37/GHSA-3qmv-v22h-rc37.json b/advisories/unreviewed/2022/08/GHSA-3qmv-v22h-rc37/GHSA-3qmv-v22h-rc37.json index efe21d467b8..f46b9978ad4 100644 --- a/advisories/unreviewed/2022/08/GHSA-3qmv-v22h-rc37/GHSA-3qmv-v22h-rc37.json +++ b/advisories/unreviewed/2022/08/GHSA-3qmv-v22h-rc37/GHSA-3qmv-v22h-rc37.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-4586-3c3g-jv96/GHSA-4586-3c3g-jv96.json b/advisories/unreviewed/2022/08/GHSA-4586-3c3g-jv96/GHSA-4586-3c3g-jv96.json index a37b4932336..a70cbd5b14c 100644 --- a/advisories/unreviewed/2022/08/GHSA-4586-3c3g-jv96/GHSA-4586-3c3g-jv96.json +++ b/advisories/unreviewed/2022/08/GHSA-4586-3c3g-jv96/GHSA-4586-3c3g-jv96.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-5wj6-fpjf-5rfv/GHSA-5wj6-fpjf-5rfv.json b/advisories/unreviewed/2022/08/GHSA-5wj6-fpjf-5rfv/GHSA-5wj6-fpjf-5rfv.json index 793e3ed1c16..c52ef7ef965 100644 --- a/advisories/unreviewed/2022/08/GHSA-5wj6-fpjf-5rfv/GHSA-5wj6-fpjf-5rfv.json +++ b/advisories/unreviewed/2022/08/GHSA-5wj6-fpjf-5rfv/GHSA-5wj6-fpjf-5rfv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-83mh-8mgc-grcj/GHSA-83mh-8mgc-grcj.json b/advisories/unreviewed/2022/08/GHSA-83mh-8mgc-grcj/GHSA-83mh-8mgc-grcj.json index c13cbcd8ccf..aa2a8afca9c 100644 --- a/advisories/unreviewed/2022/08/GHSA-83mh-8mgc-grcj/GHSA-83mh-8mgc-grcj.json +++ b/advisories/unreviewed/2022/08/GHSA-83mh-8mgc-grcj/GHSA-83mh-8mgc-grcj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-9xf8-6p87-ww99/GHSA-9xf8-6p87-ww99.json b/advisories/unreviewed/2022/08/GHSA-9xf8-6p87-ww99/GHSA-9xf8-6p87-ww99.json index 9dda0484f53..587091ddf54 100644 --- a/advisories/unreviewed/2022/08/GHSA-9xf8-6p87-ww99/GHSA-9xf8-6p87-ww99.json +++ b/advisories/unreviewed/2022/08/GHSA-9xf8-6p87-ww99/GHSA-9xf8-6p87-ww99.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-hpww-gcq4-rc3c/GHSA-hpww-gcq4-rc3c.json b/advisories/unreviewed/2022/08/GHSA-hpww-gcq4-rc3c/GHSA-hpww-gcq4-rc3c.json index be67be6cdf8..fec272f7f95 100644 --- a/advisories/unreviewed/2022/08/GHSA-hpww-gcq4-rc3c/GHSA-hpww-gcq4-rc3c.json +++ b/advisories/unreviewed/2022/08/GHSA-hpww-gcq4-rc3c/GHSA-hpww-gcq4-rc3c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-j928-ww9w-w7hg/GHSA-j928-ww9w-w7hg.json b/advisories/unreviewed/2022/08/GHSA-j928-ww9w-w7hg/GHSA-j928-ww9w-w7hg.json index 09548f1ab7f..dbd95ef5c56 100644 --- a/advisories/unreviewed/2022/08/GHSA-j928-ww9w-w7hg/GHSA-j928-ww9w-w7hg.json +++ b/advisories/unreviewed/2022/08/GHSA-j928-ww9w-w7hg/GHSA-j928-ww9w-w7hg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-jw85-mc7h-c36v/GHSA-jw85-mc7h-c36v.json b/advisories/unreviewed/2022/08/GHSA-jw85-mc7h-c36v/GHSA-jw85-mc7h-c36v.json index 028a2f3938f..3dd0ea4ec60 100644 --- a/advisories/unreviewed/2022/08/GHSA-jw85-mc7h-c36v/GHSA-jw85-mc7h-c36v.json +++ b/advisories/unreviewed/2022/08/GHSA-jw85-mc7h-c36v/GHSA-jw85-mc7h-c36v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-mq67-2w77-w276/GHSA-mq67-2w77-w276.json b/advisories/unreviewed/2022/08/GHSA-mq67-2w77-w276/GHSA-mq67-2w77-w276.json index ccb66009e2a..cdb89b3b867 100644 --- a/advisories/unreviewed/2022/08/GHSA-mq67-2w77-w276/GHSA-mq67-2w77-w276.json +++ b/advisories/unreviewed/2022/08/GHSA-mq67-2w77-w276/GHSA-mq67-2w77-w276.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-pg49-p7jf-3q72/GHSA-pg49-p7jf-3q72.json b/advisories/unreviewed/2022/08/GHSA-pg49-p7jf-3q72/GHSA-pg49-p7jf-3q72.json index 89d0cbe8e58..fc07a714f4f 100644 --- a/advisories/unreviewed/2022/08/GHSA-pg49-p7jf-3q72/GHSA-pg49-p7jf-3q72.json +++ b/advisories/unreviewed/2022/08/GHSA-pg49-p7jf-3q72/GHSA-pg49-p7jf-3q72.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-v9gp-cm5m-f2c5/GHSA-v9gp-cm5m-f2c5.json b/advisories/unreviewed/2022/08/GHSA-v9gp-cm5m-f2c5/GHSA-v9gp-cm5m-f2c5.json index 94a9ad51463..cb6ee3f7a78 100644 --- a/advisories/unreviewed/2022/08/GHSA-v9gp-cm5m-f2c5/GHSA-v9gp-cm5m-f2c5.json +++ b/advisories/unreviewed/2022/08/GHSA-v9gp-cm5m-f2c5/GHSA-v9gp-cm5m-f2c5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-vc8q-vv59-f54c/GHSA-vc8q-vv59-f54c.json b/advisories/unreviewed/2022/08/GHSA-vc8q-vv59-f54c/GHSA-vc8q-vv59-f54c.json index 7e3f0686e5a..2b16af0ee7b 100644 --- a/advisories/unreviewed/2022/08/GHSA-vc8q-vv59-f54c/GHSA-vc8q-vv59-f54c.json +++ b/advisories/unreviewed/2022/08/GHSA-vc8q-vv59-f54c/GHSA-vc8q-vv59-f54c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-vhpq-rmjq-cgrp/GHSA-vhpq-rmjq-cgrp.json b/advisories/unreviewed/2022/08/GHSA-vhpq-rmjq-cgrp/GHSA-vhpq-rmjq-cgrp.json index 945899374eb..a47a06a65c4 100644 --- a/advisories/unreviewed/2022/08/GHSA-vhpq-rmjq-cgrp/GHSA-vhpq-rmjq-cgrp.json +++ b/advisories/unreviewed/2022/08/GHSA-vhpq-rmjq-cgrp/GHSA-vhpq-rmjq-cgrp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-xfcr-fmp2-xwhr/GHSA-xfcr-fmp2-xwhr.json b/advisories/unreviewed/2022/08/GHSA-xfcr-fmp2-xwhr/GHSA-xfcr-fmp2-xwhr.json index e04a831bb73..d5b167d8125 100644 --- a/advisories/unreviewed/2022/08/GHSA-xfcr-fmp2-xwhr/GHSA-xfcr-fmp2-xwhr.json +++ b/advisories/unreviewed/2022/08/GHSA-xfcr-fmp2-xwhr/GHSA-xfcr-fmp2-xwhr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-xqgw-r8h6-587w/GHSA-xqgw-r8h6-587w.json b/advisories/unreviewed/2022/08/GHSA-xqgw-r8h6-587w/GHSA-xqgw-r8h6-587w.json index 07015df4b8e..dee9a4331a6 100644 --- a/advisories/unreviewed/2022/08/GHSA-xqgw-r8h6-587w/GHSA-xqgw-r8h6-587w.json +++ b/advisories/unreviewed/2022/08/GHSA-xqgw-r8h6-587w/GHSA-xqgw-r8h6-587w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-9w34-3vc7-7786/GHSA-9w34-3vc7-7786.json b/advisories/unreviewed/2022/12/GHSA-9w34-3vc7-7786/GHSA-9w34-3vc7-7786.json index 725a8cc6148..ed3a4669ab0 100644 --- a/advisories/unreviewed/2022/12/GHSA-9w34-3vc7-7786/GHSA-9w34-3vc7-7786.json +++ b/advisories/unreviewed/2022/12/GHSA-9w34-3vc7-7786/GHSA-9w34-3vc7-7786.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-269f-c6h8-6gv2/GHSA-269f-c6h8-6gv2.json b/advisories/unreviewed/2023/01/GHSA-269f-c6h8-6gv2/GHSA-269f-c6h8-6gv2.json index 176c18e2296..f72bf5e6637 100644 --- a/advisories/unreviewed/2023/01/GHSA-269f-c6h8-6gv2/GHSA-269f-c6h8-6gv2.json +++ b/advisories/unreviewed/2023/01/GHSA-269f-c6h8-6gv2/GHSA-269f-c6h8-6gv2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-2hwr-88h3-g5j5/GHSA-2hwr-88h3-g5j5.json b/advisories/unreviewed/2023/01/GHSA-2hwr-88h3-g5j5/GHSA-2hwr-88h3-g5j5.json index 5e63aae8321..7c14efcaabd 100644 --- a/advisories/unreviewed/2023/01/GHSA-2hwr-88h3-g5j5/GHSA-2hwr-88h3-g5j5.json +++ b/advisories/unreviewed/2023/01/GHSA-2hwr-88h3-g5j5/GHSA-2hwr-88h3-g5j5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-342c-w38f-j4wc/GHSA-342c-w38f-j4wc.json b/advisories/unreviewed/2023/01/GHSA-342c-w38f-j4wc/GHSA-342c-w38f-j4wc.json index 082d26bc782..61f02ff006e 100644 --- a/advisories/unreviewed/2023/01/GHSA-342c-w38f-j4wc/GHSA-342c-w38f-j4wc.json +++ b/advisories/unreviewed/2023/01/GHSA-342c-w38f-j4wc/GHSA-342c-w38f-j4wc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-3j3x-f853-j95p/GHSA-3j3x-f853-j95p.json b/advisories/unreviewed/2023/01/GHSA-3j3x-f853-j95p/GHSA-3j3x-f853-j95p.json index 6dd0235b50c..fd5f7b894db 100644 --- a/advisories/unreviewed/2023/01/GHSA-3j3x-f853-j95p/GHSA-3j3x-f853-j95p.json +++ b/advisories/unreviewed/2023/01/GHSA-3j3x-f853-j95p/GHSA-3j3x-f853-j95p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-3j59-wr8c-7648/GHSA-3j59-wr8c-7648.json b/advisories/unreviewed/2023/01/GHSA-3j59-wr8c-7648/GHSA-3j59-wr8c-7648.json index 087b467b505..dd69ca6f4ca 100644 --- a/advisories/unreviewed/2023/01/GHSA-3j59-wr8c-7648/GHSA-3j59-wr8c-7648.json +++ b/advisories/unreviewed/2023/01/GHSA-3j59-wr8c-7648/GHSA-3j59-wr8c-7648.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-4w9g-pxjp-v6rx/GHSA-4w9g-pxjp-v6rx.json b/advisories/unreviewed/2023/01/GHSA-4w9g-pxjp-v6rx/GHSA-4w9g-pxjp-v6rx.json index e16e5d8c970..88add08f9bc 100644 --- a/advisories/unreviewed/2023/01/GHSA-4w9g-pxjp-v6rx/GHSA-4w9g-pxjp-v6rx.json +++ b/advisories/unreviewed/2023/01/GHSA-4w9g-pxjp-v6rx/GHSA-4w9g-pxjp-v6rx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-5q85-v6f3-x49m/GHSA-5q85-v6f3-x49m.json b/advisories/unreviewed/2023/01/GHSA-5q85-v6f3-x49m/GHSA-5q85-v6f3-x49m.json index 5f52d5865a4..199a0294075 100644 --- a/advisories/unreviewed/2023/01/GHSA-5q85-v6f3-x49m/GHSA-5q85-v6f3-x49m.json +++ b/advisories/unreviewed/2023/01/GHSA-5q85-v6f3-x49m/GHSA-5q85-v6f3-x49m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-7j4m-g687-74qh/GHSA-7j4m-g687-74qh.json b/advisories/unreviewed/2023/01/GHSA-7j4m-g687-74qh/GHSA-7j4m-g687-74qh.json index 71588f59215..7e0ab588c0d 100644 --- a/advisories/unreviewed/2023/01/GHSA-7j4m-g687-74qh/GHSA-7j4m-g687-74qh.json +++ b/advisories/unreviewed/2023/01/GHSA-7j4m-g687-74qh/GHSA-7j4m-g687-74qh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-7w2m-f6qv-243x/GHSA-7w2m-f6qv-243x.json b/advisories/unreviewed/2023/01/GHSA-7w2m-f6qv-243x/GHSA-7w2m-f6qv-243x.json index fb91e09251f..fe43ce7f08e 100644 --- a/advisories/unreviewed/2023/01/GHSA-7w2m-f6qv-243x/GHSA-7w2m-f6qv-243x.json +++ b/advisories/unreviewed/2023/01/GHSA-7w2m-f6qv-243x/GHSA-7w2m-f6qv-243x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-8cv3-mr7x-wh73/GHSA-8cv3-mr7x-wh73.json b/advisories/unreviewed/2023/01/GHSA-8cv3-mr7x-wh73/GHSA-8cv3-mr7x-wh73.json index bfb204016d8..a04e2bf6156 100644 --- a/advisories/unreviewed/2023/01/GHSA-8cv3-mr7x-wh73/GHSA-8cv3-mr7x-wh73.json +++ b/advisories/unreviewed/2023/01/GHSA-8cv3-mr7x-wh73/GHSA-8cv3-mr7x-wh73.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-8jgg-mxr5-h7mf/GHSA-8jgg-mxr5-h7mf.json b/advisories/unreviewed/2023/01/GHSA-8jgg-mxr5-h7mf/GHSA-8jgg-mxr5-h7mf.json index 1637834c5c3..1e0d38352c3 100644 --- a/advisories/unreviewed/2023/01/GHSA-8jgg-mxr5-h7mf/GHSA-8jgg-mxr5-h7mf.json +++ b/advisories/unreviewed/2023/01/GHSA-8jgg-mxr5-h7mf/GHSA-8jgg-mxr5-h7mf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-9m22-9pp9-3gwc/GHSA-9m22-9pp9-3gwc.json b/advisories/unreviewed/2023/01/GHSA-9m22-9pp9-3gwc/GHSA-9m22-9pp9-3gwc.json index 39725bc1fe5..ff54591a0e7 100644 --- a/advisories/unreviewed/2023/01/GHSA-9m22-9pp9-3gwc/GHSA-9m22-9pp9-3gwc.json +++ b/advisories/unreviewed/2023/01/GHSA-9m22-9pp9-3gwc/GHSA-9m22-9pp9-3gwc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-9rmx-2mjp-5w4j/GHSA-9rmx-2mjp-5w4j.json b/advisories/unreviewed/2023/01/GHSA-9rmx-2mjp-5w4j/GHSA-9rmx-2mjp-5w4j.json index dc64c7bd7d0..f08dc5bc0cb 100644 --- a/advisories/unreviewed/2023/01/GHSA-9rmx-2mjp-5w4j/GHSA-9rmx-2mjp-5w4j.json +++ b/advisories/unreviewed/2023/01/GHSA-9rmx-2mjp-5w4j/GHSA-9rmx-2mjp-5w4j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-c4gj-hh7r-67qf/GHSA-c4gj-hh7r-67qf.json b/advisories/unreviewed/2023/01/GHSA-c4gj-hh7r-67qf/GHSA-c4gj-hh7r-67qf.json index aa5cfa925aa..2d54f61c17a 100644 --- a/advisories/unreviewed/2023/01/GHSA-c4gj-hh7r-67qf/GHSA-c4gj-hh7r-67qf.json +++ b/advisories/unreviewed/2023/01/GHSA-c4gj-hh7r-67qf/GHSA-c4gj-hh7r-67qf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-c74p-x565-fv2v/GHSA-c74p-x565-fv2v.json b/advisories/unreviewed/2023/01/GHSA-c74p-x565-fv2v/GHSA-c74p-x565-fv2v.json index de3e6e96c36..e87aba6e02e 100644 --- a/advisories/unreviewed/2023/01/GHSA-c74p-x565-fv2v/GHSA-c74p-x565-fv2v.json +++ b/advisories/unreviewed/2023/01/GHSA-c74p-x565-fv2v/GHSA-c74p-x565-fv2v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-f637-4v2p-h3qv/GHSA-f637-4v2p-h3qv.json b/advisories/unreviewed/2023/01/GHSA-f637-4v2p-h3qv/GHSA-f637-4v2p-h3qv.json index 7828575979e..93fdfc4cee1 100644 --- a/advisories/unreviewed/2023/01/GHSA-f637-4v2p-h3qv/GHSA-f637-4v2p-h3qv.json +++ b/advisories/unreviewed/2023/01/GHSA-f637-4v2p-h3qv/GHSA-f637-4v2p-h3qv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-f6c3-2788-h964/GHSA-f6c3-2788-h964.json b/advisories/unreviewed/2023/01/GHSA-f6c3-2788-h964/GHSA-f6c3-2788-h964.json index 1aa4b497287..538033958b0 100644 --- a/advisories/unreviewed/2023/01/GHSA-f6c3-2788-h964/GHSA-f6c3-2788-h964.json +++ b/advisories/unreviewed/2023/01/GHSA-f6c3-2788-h964/GHSA-f6c3-2788-h964.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-f73m-w3jg-64qm/GHSA-f73m-w3jg-64qm.json b/advisories/unreviewed/2023/01/GHSA-f73m-w3jg-64qm/GHSA-f73m-w3jg-64qm.json index 3012bc2b50f..8b8750a5c08 100644 --- a/advisories/unreviewed/2023/01/GHSA-f73m-w3jg-64qm/GHSA-f73m-w3jg-64qm.json +++ b/advisories/unreviewed/2023/01/GHSA-f73m-w3jg-64qm/GHSA-f73m-w3jg-64qm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-gpfm-wj7m-f7jj/GHSA-gpfm-wj7m-f7jj.json b/advisories/unreviewed/2023/01/GHSA-gpfm-wj7m-f7jj/GHSA-gpfm-wj7m-f7jj.json index 1df586019e9..34741dc37bf 100644 --- a/advisories/unreviewed/2023/01/GHSA-gpfm-wj7m-f7jj/GHSA-gpfm-wj7m-f7jj.json +++ b/advisories/unreviewed/2023/01/GHSA-gpfm-wj7m-f7jj/GHSA-gpfm-wj7m-f7jj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-gqx3-wh79-gf57/GHSA-gqx3-wh79-gf57.json b/advisories/unreviewed/2023/01/GHSA-gqx3-wh79-gf57/GHSA-gqx3-wh79-gf57.json index 80d537e7ee0..81b0c60532c 100644 --- a/advisories/unreviewed/2023/01/GHSA-gqx3-wh79-gf57/GHSA-gqx3-wh79-gf57.json +++ b/advisories/unreviewed/2023/01/GHSA-gqx3-wh79-gf57/GHSA-gqx3-wh79-gf57.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-grcq-2f23-7prp/GHSA-grcq-2f23-7prp.json b/advisories/unreviewed/2023/01/GHSA-grcq-2f23-7prp/GHSA-grcq-2f23-7prp.json index 37980f14dee..e06ea4f828e 100644 --- a/advisories/unreviewed/2023/01/GHSA-grcq-2f23-7prp/GHSA-grcq-2f23-7prp.json +++ b/advisories/unreviewed/2023/01/GHSA-grcq-2f23-7prp/GHSA-grcq-2f23-7prp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-jmcg-v3wf-g69g/GHSA-jmcg-v3wf-g69g.json b/advisories/unreviewed/2023/01/GHSA-jmcg-v3wf-g69g/GHSA-jmcg-v3wf-g69g.json index 72b17a76cf2..8aa38999ef3 100644 --- a/advisories/unreviewed/2023/01/GHSA-jmcg-v3wf-g69g/GHSA-jmcg-v3wf-g69g.json +++ b/advisories/unreviewed/2023/01/GHSA-jmcg-v3wf-g69g/GHSA-jmcg-v3wf-g69g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-mr22-3rrp-47cx/GHSA-mr22-3rrp-47cx.json b/advisories/unreviewed/2023/01/GHSA-mr22-3rrp-47cx/GHSA-mr22-3rrp-47cx.json index 8d6dc559e77..dafbe2cdfa9 100644 --- a/advisories/unreviewed/2023/01/GHSA-mr22-3rrp-47cx/GHSA-mr22-3rrp-47cx.json +++ b/advisories/unreviewed/2023/01/GHSA-mr22-3rrp-47cx/GHSA-mr22-3rrp-47cx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-mw5v-w29j-c9g9/GHSA-mw5v-w29j-c9g9.json b/advisories/unreviewed/2023/01/GHSA-mw5v-w29j-c9g9/GHSA-mw5v-w29j-c9g9.json index 34b0752d389..730bfbf7cf2 100644 --- a/advisories/unreviewed/2023/01/GHSA-mw5v-w29j-c9g9/GHSA-mw5v-w29j-c9g9.json +++ b/advisories/unreviewed/2023/01/GHSA-mw5v-w29j-c9g9/GHSA-mw5v-w29j-c9g9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-p7v6-2vr2-6qpq/GHSA-p7v6-2vr2-6qpq.json b/advisories/unreviewed/2023/01/GHSA-p7v6-2vr2-6qpq/GHSA-p7v6-2vr2-6qpq.json index 420a00387ed..94b19c38c1e 100644 --- a/advisories/unreviewed/2023/01/GHSA-p7v6-2vr2-6qpq/GHSA-p7v6-2vr2-6qpq.json +++ b/advisories/unreviewed/2023/01/GHSA-p7v6-2vr2-6qpq/GHSA-p7v6-2vr2-6qpq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-q6ff-9vgw-842x/GHSA-q6ff-9vgw-842x.json b/advisories/unreviewed/2023/01/GHSA-q6ff-9vgw-842x/GHSA-q6ff-9vgw-842x.json index 9814d220b6f..ab980be488d 100644 --- a/advisories/unreviewed/2023/01/GHSA-q6ff-9vgw-842x/GHSA-q6ff-9vgw-842x.json +++ b/advisories/unreviewed/2023/01/GHSA-q6ff-9vgw-842x/GHSA-q6ff-9vgw-842x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-rj5f-wj63-xvgc/GHSA-rj5f-wj63-xvgc.json b/advisories/unreviewed/2023/01/GHSA-rj5f-wj63-xvgc/GHSA-rj5f-wj63-xvgc.json index 82278c611e7..5871b696a0f 100644 --- a/advisories/unreviewed/2023/01/GHSA-rj5f-wj63-xvgc/GHSA-rj5f-wj63-xvgc.json +++ b/advisories/unreviewed/2023/01/GHSA-rj5f-wj63-xvgc/GHSA-rj5f-wj63-xvgc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-vgr9-35rp-jw4x/GHSA-vgr9-35rp-jw4x.json b/advisories/unreviewed/2023/01/GHSA-vgr9-35rp-jw4x/GHSA-vgr9-35rp-jw4x.json index 0dcd728a673..1836d3ebf40 100644 --- a/advisories/unreviewed/2023/01/GHSA-vgr9-35rp-jw4x/GHSA-vgr9-35rp-jw4x.json +++ b/advisories/unreviewed/2023/01/GHSA-vgr9-35rp-jw4x/GHSA-vgr9-35rp-jw4x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-x42v-2793-x54w/GHSA-x42v-2793-x54w.json b/advisories/unreviewed/2023/01/GHSA-x42v-2793-x54w/GHSA-x42v-2793-x54w.json index e6bf93951bf..75a2ef41ce8 100644 --- a/advisories/unreviewed/2023/01/GHSA-x42v-2793-x54w/GHSA-x42v-2793-x54w.json +++ b/advisories/unreviewed/2023/01/GHSA-x42v-2793-x54w/GHSA-x42v-2793-x54w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-x63v-xw79-mw5j/GHSA-x63v-xw79-mw5j.json b/advisories/unreviewed/2023/01/GHSA-x63v-xw79-mw5j/GHSA-x63v-xw79-mw5j.json index 651d7042b65..4496e6f370b 100644 --- a/advisories/unreviewed/2023/01/GHSA-x63v-xw79-mw5j/GHSA-x63v-xw79-mw5j.json +++ b/advisories/unreviewed/2023/01/GHSA-x63v-xw79-mw5j/GHSA-x63v-xw79-mw5j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-x7rx-9g3w-62mw/GHSA-x7rx-9g3w-62mw.json b/advisories/unreviewed/2023/01/GHSA-x7rx-9g3w-62mw/GHSA-x7rx-9g3w-62mw.json index c138ffe7279..c637f3a8de8 100644 --- a/advisories/unreviewed/2023/01/GHSA-x7rx-9g3w-62mw/GHSA-x7rx-9g3w-62mw.json +++ b/advisories/unreviewed/2023/01/GHSA-x7rx-9g3w-62mw/GHSA-x7rx-9g3w-62mw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-gv85-xg33-553c/GHSA-gv85-xg33-553c.json b/advisories/unreviewed/2023/03/GHSA-gv85-xg33-553c/GHSA-gv85-xg33-553c.json index 4faa67618db..ab31f2d5aff 100644 --- a/advisories/unreviewed/2023/03/GHSA-gv85-xg33-553c/GHSA-gv85-xg33-553c.json +++ b/advisories/unreviewed/2023/03/GHSA-gv85-xg33-553c/GHSA-gv85-xg33-553c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "WEB", diff --git a/advisories/unreviewed/2023/08/GHSA-wpm6-6374-m3g5/GHSA-wpm6-6374-m3g5.json b/advisories/unreviewed/2023/08/GHSA-wpm6-6374-m3g5/GHSA-wpm6-6374-m3g5.json index 538175b293d..b6da2812654 100644 --- a/advisories/unreviewed/2023/08/GHSA-wpm6-6374-m3g5/GHSA-wpm6-6374-m3g5.json +++ b/advisories/unreviewed/2023/08/GHSA-wpm6-6374-m3g5/GHSA-wpm6-6374-m3g5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json b/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json index 94fa745697f..996809051b0 100644 --- a/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json +++ b/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json b/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json index e682834b2e4..3359a842dc4 100644 --- a/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json +++ b/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-q6jg-9395-p66m/GHSA-q6jg-9395-p66m.json b/advisories/unreviewed/2023/10/GHSA-q6jg-9395-p66m/GHSA-q6jg-9395-p66m.json index 65f395ef0a4..de46b2ecdeb 100644 --- a/advisories/unreviewed/2023/10/GHSA-q6jg-9395-p66m/GHSA-q6jg-9395-p66m.json +++ b/advisories/unreviewed/2023/10/GHSA-q6jg-9395-p66m/GHSA-q6jg-9395-p66m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-cxjh-j6f8-vrmf/GHSA-cxjh-j6f8-vrmf.json b/advisories/unreviewed/2024/01/GHSA-cxjh-j6f8-vrmf/GHSA-cxjh-j6f8-vrmf.json index 869dbb0396e..adaac1c8992 100644 --- a/advisories/unreviewed/2024/01/GHSA-cxjh-j6f8-vrmf/GHSA-cxjh-j6f8-vrmf.json +++ b/advisories/unreviewed/2024/01/GHSA-cxjh-j6f8-vrmf/GHSA-cxjh-j6f8-vrmf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-2569-97m4-w479/GHSA-2569-97m4-w479.json b/advisories/unreviewed/2024/02/GHSA-2569-97m4-w479/GHSA-2569-97m4-w479.json index 7312737ace3..4b25395fd0f 100644 --- a/advisories/unreviewed/2024/02/GHSA-2569-97m4-w479/GHSA-2569-97m4-w479.json +++ b/advisories/unreviewed/2024/02/GHSA-2569-97m4-w479/GHSA-2569-97m4-w479.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-2mw7-f37q-33mg/GHSA-2mw7-f37q-33mg.json b/advisories/unreviewed/2024/02/GHSA-2mw7-f37q-33mg/GHSA-2mw7-f37q-33mg.json index 51b01337e6a..2335db61a3d 100644 --- a/advisories/unreviewed/2024/02/GHSA-2mw7-f37q-33mg/GHSA-2mw7-f37q-33mg.json +++ b/advisories/unreviewed/2024/02/GHSA-2mw7-f37q-33mg/GHSA-2mw7-f37q-33mg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-3q83-x89h-m869/GHSA-3q83-x89h-m869.json b/advisories/unreviewed/2024/02/GHSA-3q83-x89h-m869/GHSA-3q83-x89h-m869.json index 639b539f1be..c70884969bf 100644 --- a/advisories/unreviewed/2024/02/GHSA-3q83-x89h-m869/GHSA-3q83-x89h-m869.json +++ b/advisories/unreviewed/2024/02/GHSA-3q83-x89h-m869/GHSA-3q83-x89h-m869.json @@ -7,12 +7,8 @@ "CVE-2024-26284" ], "details": "Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a link to the attacker's website. This vulnerability affects Focus for iOS < 123.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-53p9-pvv8-g92g/GHSA-53p9-pvv8-g92g.json b/advisories/unreviewed/2024/02/GHSA-53p9-pvv8-g92g/GHSA-53p9-pvv8-g92g.json index e51123928d6..3989a6860be 100644 --- a/advisories/unreviewed/2024/02/GHSA-53p9-pvv8-g92g/GHSA-53p9-pvv8-g92g.json +++ b/advisories/unreviewed/2024/02/GHSA-53p9-pvv8-g92g/GHSA-53p9-pvv8-g92g.json @@ -7,12 +7,8 @@ "CVE-2024-0707" ], "details": "Rejected reason: **REJECT** Not a valid vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-554r-mhfh-g54g/GHSA-554r-mhfh-g54g.json b/advisories/unreviewed/2024/02/GHSA-554r-mhfh-g54g/GHSA-554r-mhfh-g54g.json index 0110f19d3a5..1ef629ac135 100644 --- a/advisories/unreviewed/2024/02/GHSA-554r-mhfh-g54g/GHSA-554r-mhfh-g54g.json +++ b/advisories/unreviewed/2024/02/GHSA-554r-mhfh-g54g/GHSA-554r-mhfh-g54g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-5pf8-g8g3-8798/GHSA-5pf8-g8g3-8798.json b/advisories/unreviewed/2024/02/GHSA-5pf8-g8g3-8798/GHSA-5pf8-g8g3-8798.json index 973a9764b5f..378d9dd4566 100644 --- a/advisories/unreviewed/2024/02/GHSA-5pf8-g8g3-8798/GHSA-5pf8-g8g3-8798.json +++ b/advisories/unreviewed/2024/02/GHSA-5pf8-g8g3-8798/GHSA-5pf8-g8g3-8798.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-5r44-g6v6-6h2w/GHSA-5r44-g6v6-6h2w.json b/advisories/unreviewed/2024/02/GHSA-5r44-g6v6-6h2w/GHSA-5r44-g6v6-6h2w.json index 5100c13a160..ef801512ea5 100644 --- a/advisories/unreviewed/2024/02/GHSA-5r44-g6v6-6h2w/GHSA-5r44-g6v6-6h2w.json +++ b/advisories/unreviewed/2024/02/GHSA-5r44-g6v6-6h2w/GHSA-5r44-g6v6-6h2w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-6hv8-6fgh-mjj5/GHSA-6hv8-6fgh-mjj5.json b/advisories/unreviewed/2024/02/GHSA-6hv8-6fgh-mjj5/GHSA-6hv8-6fgh-mjj5.json index 07883f2a418..b5a8cd8ea86 100644 --- a/advisories/unreviewed/2024/02/GHSA-6hv8-6fgh-mjj5/GHSA-6hv8-6fgh-mjj5.json +++ b/advisories/unreviewed/2024/02/GHSA-6hv8-6fgh-mjj5/GHSA-6hv8-6fgh-mjj5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-6j8w-8cxv-823q/GHSA-6j8w-8cxv-823q.json b/advisories/unreviewed/2024/02/GHSA-6j8w-8cxv-823q/GHSA-6j8w-8cxv-823q.json index fc172e4d679..f6a29f07a74 100644 --- a/advisories/unreviewed/2024/02/GHSA-6j8w-8cxv-823q/GHSA-6j8w-8cxv-823q.json +++ b/advisories/unreviewed/2024/02/GHSA-6j8w-8cxv-823q/GHSA-6j8w-8cxv-823q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-7m32-w789-g7x4/GHSA-7m32-w789-g7x4.json b/advisories/unreviewed/2024/02/GHSA-7m32-w789-g7x4/GHSA-7m32-w789-g7x4.json index 00a2288e822..f487779059b 100644 --- a/advisories/unreviewed/2024/02/GHSA-7m32-w789-g7x4/GHSA-7m32-w789-g7x4.json +++ b/advisories/unreviewed/2024/02/GHSA-7m32-w789-g7x4/GHSA-7m32-w789-g7x4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-8h8w-85rq-cgp4/GHSA-8h8w-85rq-cgp4.json b/advisories/unreviewed/2024/02/GHSA-8h8w-85rq-cgp4/GHSA-8h8w-85rq-cgp4.json index fab97e72761..f271f28a47c 100644 --- a/advisories/unreviewed/2024/02/GHSA-8h8w-85rq-cgp4/GHSA-8h8w-85rq-cgp4.json +++ b/advisories/unreviewed/2024/02/GHSA-8h8w-85rq-cgp4/GHSA-8h8w-85rq-cgp4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-8v7m-h3c9-88g7/GHSA-8v7m-h3c9-88g7.json b/advisories/unreviewed/2024/02/GHSA-8v7m-h3c9-88g7/GHSA-8v7m-h3c9-88g7.json index 8ed104c9939..afa9ea6cb77 100644 --- a/advisories/unreviewed/2024/02/GHSA-8v7m-h3c9-88g7/GHSA-8v7m-h3c9-88g7.json +++ b/advisories/unreviewed/2024/02/GHSA-8v7m-h3c9-88g7/GHSA-8v7m-h3c9-88g7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-94x4-fq94-5wwx/GHSA-94x4-fq94-5wwx.json b/advisories/unreviewed/2024/02/GHSA-94x4-fq94-5wwx/GHSA-94x4-fq94-5wwx.json index 531ad9ae884..d82cd955ed2 100644 --- a/advisories/unreviewed/2024/02/GHSA-94x4-fq94-5wwx/GHSA-94x4-fq94-5wwx.json +++ b/advisories/unreviewed/2024/02/GHSA-94x4-fq94-5wwx/GHSA-94x4-fq94-5wwx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-97wx-j5qg-q792/GHSA-97wx-j5qg-q792.json b/advisories/unreviewed/2024/02/GHSA-97wx-j5qg-q792/GHSA-97wx-j5qg-q792.json index f484760e32b..5bdab6ec93b 100644 --- a/advisories/unreviewed/2024/02/GHSA-97wx-j5qg-q792/GHSA-97wx-j5qg-q792.json +++ b/advisories/unreviewed/2024/02/GHSA-97wx-j5qg-q792/GHSA-97wx-j5qg-q792.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-c27w-rp5h-g734/GHSA-c27w-rp5h-g734.json b/advisories/unreviewed/2024/02/GHSA-c27w-rp5h-g734/GHSA-c27w-rp5h-g734.json index b09a3a801af..7584f6d4e3d 100644 --- a/advisories/unreviewed/2024/02/GHSA-c27w-rp5h-g734/GHSA-c27w-rp5h-g734.json +++ b/advisories/unreviewed/2024/02/GHSA-c27w-rp5h-g734/GHSA-c27w-rp5h-g734.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-c6rw-7vmm-m3h7/GHSA-c6rw-7vmm-m3h7.json b/advisories/unreviewed/2024/02/GHSA-c6rw-7vmm-m3h7/GHSA-c6rw-7vmm-m3h7.json index f2dc848c0ff..4382aca6b2b 100644 --- a/advisories/unreviewed/2024/02/GHSA-c6rw-7vmm-m3h7/GHSA-c6rw-7vmm-m3h7.json +++ b/advisories/unreviewed/2024/02/GHSA-c6rw-7vmm-m3h7/GHSA-c6rw-7vmm-m3h7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-cc59-mwcm-hxv4/GHSA-cc59-mwcm-hxv4.json b/advisories/unreviewed/2024/02/GHSA-cc59-mwcm-hxv4/GHSA-cc59-mwcm-hxv4.json index 6d4bf53fb61..62ca77493ac 100644 --- a/advisories/unreviewed/2024/02/GHSA-cc59-mwcm-hxv4/GHSA-cc59-mwcm-hxv4.json +++ b/advisories/unreviewed/2024/02/GHSA-cc59-mwcm-hxv4/GHSA-cc59-mwcm-hxv4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-cmg9-p9gp-g7mr/GHSA-cmg9-p9gp-g7mr.json b/advisories/unreviewed/2024/02/GHSA-cmg9-p9gp-g7mr/GHSA-cmg9-p9gp-g7mr.json index 2d552e68b70..e9ebe46ac25 100644 --- a/advisories/unreviewed/2024/02/GHSA-cmg9-p9gp-g7mr/GHSA-cmg9-p9gp-g7mr.json +++ b/advisories/unreviewed/2024/02/GHSA-cmg9-p9gp-g7mr/GHSA-cmg9-p9gp-g7mr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-f2cw-fq5w-55f8/GHSA-f2cw-fq5w-55f8.json b/advisories/unreviewed/2024/02/GHSA-f2cw-fq5w-55f8/GHSA-f2cw-fq5w-55f8.json index 13d6ecae8c4..0087c4fa75c 100644 --- a/advisories/unreviewed/2024/02/GHSA-f2cw-fq5w-55f8/GHSA-f2cw-fq5w-55f8.json +++ b/advisories/unreviewed/2024/02/GHSA-f2cw-fq5w-55f8/GHSA-f2cw-fq5w-55f8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-f6q6-67qx-rv6q/GHSA-f6q6-67qx-rv6q.json b/advisories/unreviewed/2024/02/GHSA-f6q6-67qx-rv6q/GHSA-f6q6-67qx-rv6q.json index 7305d7ba3db..dfa43574699 100644 --- a/advisories/unreviewed/2024/02/GHSA-f6q6-67qx-rv6q/GHSA-f6q6-67qx-rv6q.json +++ b/advisories/unreviewed/2024/02/GHSA-f6q6-67qx-rv6q/GHSA-f6q6-67qx-rv6q.json @@ -7,12 +7,8 @@ "CVE-2024-1420" ], "details": "Rejected reason: **REJECT** This is a duplicate of CVE-2024-1049. Please use CVE-2024-1049 instead.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-f846-m55f-g9fw/GHSA-f846-m55f-g9fw.json b/advisories/unreviewed/2024/02/GHSA-f846-m55f-g9fw/GHSA-f846-m55f-g9fw.json index a0dfc1faf2c..1012605fe3c 100644 --- a/advisories/unreviewed/2024/02/GHSA-f846-m55f-g9fw/GHSA-f846-m55f-g9fw.json +++ b/advisories/unreviewed/2024/02/GHSA-f846-m55f-g9fw/GHSA-f846-m55f-g9fw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-f8gm-9px2-mw95/GHSA-f8gm-9px2-mw95.json b/advisories/unreviewed/2024/02/GHSA-f8gm-9px2-mw95/GHSA-f8gm-9px2-mw95.json index 86291cc2da7..aa42f4eeacb 100644 --- a/advisories/unreviewed/2024/02/GHSA-f8gm-9px2-mw95/GHSA-f8gm-9px2-mw95.json +++ b/advisories/unreviewed/2024/02/GHSA-f8gm-9px2-mw95/GHSA-f8gm-9px2-mw95.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-f9hf-4fvc-mjjv/GHSA-f9hf-4fvc-mjjv.json b/advisories/unreviewed/2024/02/GHSA-f9hf-4fvc-mjjv/GHSA-f9hf-4fvc-mjjv.json index f0166e018b5..4f87f2f8967 100644 --- a/advisories/unreviewed/2024/02/GHSA-f9hf-4fvc-mjjv/GHSA-f9hf-4fvc-mjjv.json +++ b/advisories/unreviewed/2024/02/GHSA-f9hf-4fvc-mjjv/GHSA-f9hf-4fvc-mjjv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-h66f-8xvf-h765/GHSA-h66f-8xvf-h765.json b/advisories/unreviewed/2024/02/GHSA-h66f-8xvf-h765/GHSA-h66f-8xvf-h765.json index a122b06261b..15d9ca01165 100644 --- a/advisories/unreviewed/2024/02/GHSA-h66f-8xvf-h765/GHSA-h66f-8xvf-h765.json +++ b/advisories/unreviewed/2024/02/GHSA-h66f-8xvf-h765/GHSA-h66f-8xvf-h765.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-h7x2-hfmv-h4xf/GHSA-h7x2-hfmv-h4xf.json b/advisories/unreviewed/2024/02/GHSA-h7x2-hfmv-h4xf/GHSA-h7x2-hfmv-h4xf.json index 7ae35bef037..18e7125d0bb 100644 --- a/advisories/unreviewed/2024/02/GHSA-h7x2-hfmv-h4xf/GHSA-h7x2-hfmv-h4xf.json +++ b/advisories/unreviewed/2024/02/GHSA-h7x2-hfmv-h4xf/GHSA-h7x2-hfmv-h4xf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-jmc4-fgf5-jp55/GHSA-jmc4-fgf5-jp55.json b/advisories/unreviewed/2024/02/GHSA-jmc4-fgf5-jp55/GHSA-jmc4-fgf5-jp55.json index 9ddc891e4b5..b32792614aa 100644 --- a/advisories/unreviewed/2024/02/GHSA-jmc4-fgf5-jp55/GHSA-jmc4-fgf5-jp55.json +++ b/advisories/unreviewed/2024/02/GHSA-jmc4-fgf5-jp55/GHSA-jmc4-fgf5-jp55.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-mjfr-hgmr-g3rv/GHSA-mjfr-hgmr-g3rv.json b/advisories/unreviewed/2024/02/GHSA-mjfr-hgmr-g3rv/GHSA-mjfr-hgmr-g3rv.json index 1c4da7b9f53..5e1db83817b 100644 --- a/advisories/unreviewed/2024/02/GHSA-mjfr-hgmr-g3rv/GHSA-mjfr-hgmr-g3rv.json +++ b/advisories/unreviewed/2024/02/GHSA-mjfr-hgmr-g3rv/GHSA-mjfr-hgmr-g3rv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-p93q-jr7q-q29w/GHSA-p93q-jr7q-q29w.json b/advisories/unreviewed/2024/02/GHSA-p93q-jr7q-q29w/GHSA-p93q-jr7q-q29w.json index 75c6430559c..ffee3047e5d 100644 --- a/advisories/unreviewed/2024/02/GHSA-p93q-jr7q-q29w/GHSA-p93q-jr7q-q29w.json +++ b/advisories/unreviewed/2024/02/GHSA-p93q-jr7q-q29w/GHSA-p93q-jr7q-q29w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-p9mc-3cgc-v8h2/GHSA-p9mc-3cgc-v8h2.json b/advisories/unreviewed/2024/02/GHSA-p9mc-3cgc-v8h2/GHSA-p9mc-3cgc-v8h2.json index 08182625e30..a5cd6c54caf 100644 --- a/advisories/unreviewed/2024/02/GHSA-p9mc-3cgc-v8h2/GHSA-p9mc-3cgc-v8h2.json +++ b/advisories/unreviewed/2024/02/GHSA-p9mc-3cgc-v8h2/GHSA-p9mc-3cgc-v8h2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-pqrw-mpmw-gp6m/GHSA-pqrw-mpmw-gp6m.json b/advisories/unreviewed/2024/02/GHSA-pqrw-mpmw-gp6m/GHSA-pqrw-mpmw-gp6m.json index c3bd2ae8bdb..fa8e2dbcd82 100644 --- a/advisories/unreviewed/2024/02/GHSA-pqrw-mpmw-gp6m/GHSA-pqrw-mpmw-gp6m.json +++ b/advisories/unreviewed/2024/02/GHSA-pqrw-mpmw-gp6m/GHSA-pqrw-mpmw-gp6m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-qf63-rfv8-f92j/GHSA-qf63-rfv8-f92j.json b/advisories/unreviewed/2024/02/GHSA-qf63-rfv8-f92j/GHSA-qf63-rfv8-f92j.json index 3050e8b7256..b2a91c71e81 100644 --- a/advisories/unreviewed/2024/02/GHSA-qf63-rfv8-f92j/GHSA-qf63-rfv8-f92j.json +++ b/advisories/unreviewed/2024/02/GHSA-qf63-rfv8-f92j/GHSA-qf63-rfv8-f92j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-r3c3-f9mx-3phh/GHSA-r3c3-f9mx-3phh.json b/advisories/unreviewed/2024/02/GHSA-r3c3-f9mx-3phh/GHSA-r3c3-f9mx-3phh.json index 6c6c5e1bcbe..f469e7c6099 100644 --- a/advisories/unreviewed/2024/02/GHSA-r3c3-f9mx-3phh/GHSA-r3c3-f9mx-3phh.json +++ b/advisories/unreviewed/2024/02/GHSA-r3c3-f9mx-3phh/GHSA-r3c3-f9mx-3phh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-r4h7-p578-p9gv/GHSA-r4h7-p578-p9gv.json b/advisories/unreviewed/2024/02/GHSA-r4h7-p578-p9gv/GHSA-r4h7-p578-p9gv.json index cbd37989eb3..39ba955354a 100644 --- a/advisories/unreviewed/2024/02/GHSA-r4h7-p578-p9gv/GHSA-r4h7-p578-p9gv.json +++ b/advisories/unreviewed/2024/02/GHSA-r4h7-p578-p9gv/GHSA-r4h7-p578-p9gv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-vmw7-gx6r-25fh/GHSA-vmw7-gx6r-25fh.json b/advisories/unreviewed/2024/02/GHSA-vmw7-gx6r-25fh/GHSA-vmw7-gx6r-25fh.json index b030c9a5d25..216c517942c 100644 --- a/advisories/unreviewed/2024/02/GHSA-vmw7-gx6r-25fh/GHSA-vmw7-gx6r-25fh.json +++ b/advisories/unreviewed/2024/02/GHSA-vmw7-gx6r-25fh/GHSA-vmw7-gx6r-25fh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-w598-9rgj-7mq4/GHSA-w598-9rgj-7mq4.json b/advisories/unreviewed/2024/02/GHSA-w598-9rgj-7mq4/GHSA-w598-9rgj-7mq4.json index 202e686f48c..a90bd1bec8e 100644 --- a/advisories/unreviewed/2024/02/GHSA-w598-9rgj-7mq4/GHSA-w598-9rgj-7mq4.json +++ b/advisories/unreviewed/2024/02/GHSA-w598-9rgj-7mq4/GHSA-w598-9rgj-7mq4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-wq5x-2c58-p48w/GHSA-wq5x-2c58-p48w.json b/advisories/unreviewed/2024/02/GHSA-wq5x-2c58-p48w/GHSA-wq5x-2c58-p48w.json index b3a0cdf4c5c..7fe95159c0b 100644 --- a/advisories/unreviewed/2024/02/GHSA-wq5x-2c58-p48w/GHSA-wq5x-2c58-p48w.json +++ b/advisories/unreviewed/2024/02/GHSA-wq5x-2c58-p48w/GHSA-wq5x-2c58-p48w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-xqwj-7jph-vrcj/GHSA-xqwj-7jph-vrcj.json b/advisories/unreviewed/2024/02/GHSA-xqwj-7jph-vrcj/GHSA-xqwj-7jph-vrcj.json index 2e559e275b7..4dcf71eef76 100644 --- a/advisories/unreviewed/2024/02/GHSA-xqwj-7jph-vrcj/GHSA-xqwj-7jph-vrcj.json +++ b/advisories/unreviewed/2024/02/GHSA-xqwj-7jph-vrcj/GHSA-xqwj-7jph-vrcj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-2c52-g67x-6vf3/GHSA-2c52-g67x-6vf3.json b/advisories/unreviewed/2024/03/GHSA-2c52-g67x-6vf3/GHSA-2c52-g67x-6vf3.json index 143fbb72a3f..fe02b541ff7 100644 --- a/advisories/unreviewed/2024/03/GHSA-2c52-g67x-6vf3/GHSA-2c52-g67x-6vf3.json +++ b/advisories/unreviewed/2024/03/GHSA-2c52-g67x-6vf3/GHSA-2c52-g67x-6vf3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-39x5-gqgg-68v8/GHSA-39x5-gqgg-68v8.json b/advisories/unreviewed/2024/03/GHSA-39x5-gqgg-68v8/GHSA-39x5-gqgg-68v8.json index b74ddefa06e..1236a08552b 100644 --- a/advisories/unreviewed/2024/03/GHSA-39x5-gqgg-68v8/GHSA-39x5-gqgg-68v8.json +++ b/advisories/unreviewed/2024/03/GHSA-39x5-gqgg-68v8/GHSA-39x5-gqgg-68v8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-3hpx-5vcc-5jw2/GHSA-3hpx-5vcc-5jw2.json b/advisories/unreviewed/2024/03/GHSA-3hpx-5vcc-5jw2/GHSA-3hpx-5vcc-5jw2.json index bd6586ed681..1142fc28553 100644 --- a/advisories/unreviewed/2024/03/GHSA-3hpx-5vcc-5jw2/GHSA-3hpx-5vcc-5jw2.json +++ b/advisories/unreviewed/2024/03/GHSA-3hpx-5vcc-5jw2/GHSA-3hpx-5vcc-5jw2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-3m2p-xpv4-jfjm/GHSA-3m2p-xpv4-jfjm.json b/advisories/unreviewed/2024/03/GHSA-3m2p-xpv4-jfjm/GHSA-3m2p-xpv4-jfjm.json index d974e35c66e..455522ab352 100644 --- a/advisories/unreviewed/2024/03/GHSA-3m2p-xpv4-jfjm/GHSA-3m2p-xpv4-jfjm.json +++ b/advisories/unreviewed/2024/03/GHSA-3m2p-xpv4-jfjm/GHSA-3m2p-xpv4-jfjm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-3p89-8hm7-44h4/GHSA-3p89-8hm7-44h4.json b/advisories/unreviewed/2024/03/GHSA-3p89-8hm7-44h4/GHSA-3p89-8hm7-44h4.json index 4d22847c798..17a850682d8 100644 --- a/advisories/unreviewed/2024/03/GHSA-3p89-8hm7-44h4/GHSA-3p89-8hm7-44h4.json +++ b/advisories/unreviewed/2024/03/GHSA-3p89-8hm7-44h4/GHSA-3p89-8hm7-44h4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-3rqr-p9xj-863f/GHSA-3rqr-p9xj-863f.json b/advisories/unreviewed/2024/03/GHSA-3rqr-p9xj-863f/GHSA-3rqr-p9xj-863f.json index be9572ed30b..a486461ed40 100644 --- a/advisories/unreviewed/2024/03/GHSA-3rqr-p9xj-863f/GHSA-3rqr-p9xj-863f.json +++ b/advisories/unreviewed/2024/03/GHSA-3rqr-p9xj-863f/GHSA-3rqr-p9xj-863f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-4g86-mfr6-26v9/GHSA-4g86-mfr6-26v9.json b/advisories/unreviewed/2024/03/GHSA-4g86-mfr6-26v9/GHSA-4g86-mfr6-26v9.json index e4fa0cb987b..709f5477d32 100644 --- a/advisories/unreviewed/2024/03/GHSA-4g86-mfr6-26v9/GHSA-4g86-mfr6-26v9.json +++ b/advisories/unreviewed/2024/03/GHSA-4g86-mfr6-26v9/GHSA-4g86-mfr6-26v9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-567q-hq5r-pw43/GHSA-567q-hq5r-pw43.json b/advisories/unreviewed/2024/03/GHSA-567q-hq5r-pw43/GHSA-567q-hq5r-pw43.json index 0ec7159da77..0cdea024c28 100644 --- a/advisories/unreviewed/2024/03/GHSA-567q-hq5r-pw43/GHSA-567q-hq5r-pw43.json +++ b/advisories/unreviewed/2024/03/GHSA-567q-hq5r-pw43/GHSA-567q-hq5r-pw43.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-5gxq-j292-75cc/GHSA-5gxq-j292-75cc.json b/advisories/unreviewed/2024/03/GHSA-5gxq-j292-75cc/GHSA-5gxq-j292-75cc.json index 7a3a5c3c8bf..97921378242 100644 --- a/advisories/unreviewed/2024/03/GHSA-5gxq-j292-75cc/GHSA-5gxq-j292-75cc.json +++ b/advisories/unreviewed/2024/03/GHSA-5gxq-j292-75cc/GHSA-5gxq-j292-75cc.json @@ -7,12 +7,8 @@ "CVE-2024-26617" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/proc/task_mmu: move mmu notification mechanism inside mm lock\n\nMove mmu notification mechanism inside mm lock to prevent race condition\nin other components which depend on it. The notifier will invalidate\nmemory range. Depending upon the number of iterations, different memory\nranges would be invalidated.\n\nThe following warning would be removed by this patch:\nWARNING: CPU: 0 PID: 5067 at arch/x86/kvm/../../../virt/kvm/kvm_main.c:734 kvm_mmu_notifier_change_pte+0x860/0x960 arch/x86/kvm/../../../virt/kvm/kvm_main.c:734\n\nThere is no behavioural and performance change with this patch when\nthere is no component registered with the mmu notifier.\n\n[akpm@linux-foundation.org: narrow the scope of `range', per Sean]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-683m-h868-4cxr/GHSA-683m-h868-4cxr.json b/advisories/unreviewed/2024/03/GHSA-683m-h868-4cxr/GHSA-683m-h868-4cxr.json index 98271efb141..73f5b9fe111 100644 --- a/advisories/unreviewed/2024/03/GHSA-683m-h868-4cxr/GHSA-683m-h868-4cxr.json +++ b/advisories/unreviewed/2024/03/GHSA-683m-h868-4cxr/GHSA-683m-h868-4cxr.json @@ -7,12 +7,8 @@ "CVE-2024-1279" ], "details": "The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-8v58-wvr2-fj59/GHSA-8v58-wvr2-fj59.json b/advisories/unreviewed/2024/03/GHSA-8v58-wvr2-fj59/GHSA-8v58-wvr2-fj59.json index 466e57696d0..e3aef97a2d6 100644 --- a/advisories/unreviewed/2024/03/GHSA-8v58-wvr2-fj59/GHSA-8v58-wvr2-fj59.json +++ b/advisories/unreviewed/2024/03/GHSA-8v58-wvr2-fj59/GHSA-8v58-wvr2-fj59.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-93jv-fpc3-9m4w/GHSA-93jv-fpc3-9m4w.json b/advisories/unreviewed/2024/03/GHSA-93jv-fpc3-9m4w/GHSA-93jv-fpc3-9m4w.json index 59684ace6dd..4c3a5c9f262 100644 --- a/advisories/unreviewed/2024/03/GHSA-93jv-fpc3-9m4w/GHSA-93jv-fpc3-9m4w.json +++ b/advisories/unreviewed/2024/03/GHSA-93jv-fpc3-9m4w/GHSA-93jv-fpc3-9m4w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-99h3-vvc6-h7gh/GHSA-99h3-vvc6-h7gh.json b/advisories/unreviewed/2024/03/GHSA-99h3-vvc6-h7gh/GHSA-99h3-vvc6-h7gh.json index 0850611e061..07702af4072 100644 --- a/advisories/unreviewed/2024/03/GHSA-99h3-vvc6-h7gh/GHSA-99h3-vvc6-h7gh.json +++ b/advisories/unreviewed/2024/03/GHSA-99h3-vvc6-h7gh/GHSA-99h3-vvc6-h7gh.json @@ -7,12 +7,8 @@ "CVE-2023-52487" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix peer flow lists handling\n\nThe cited change refactored mlx5e_tc_del_fdb_peer_flow() to only clear DUP\nflag when list of peer flows has become empty. However, if any concurrent\nuser holds a reference to a peer flow (for example, the neighbor update\nworkqueue task is updating peer flow's parent encap entry concurrently),\nthen the flow will not be removed from the peer list and, consecutively,\nDUP flag will remain set. Since mlx5e_tc_del_fdb_peers_flow() calls\nmlx5e_tc_del_fdb_peer_flow() for every possible peer index the algorithm\nwill try to remove the flow from eswitch instances that it has never peered\nwith causing either NULL pointer dereference when trying to remove the flow\npeer list head of peer_index that was never initialized or a warning if the\nlist debug config is enabled[0].\n\nFix the issue by always removing the peer flow from the list even when not\nreleasing the last reference to it.\n\n[0]:\n\n[ 3102.985806] ------------[ cut here ]------------\n[ 3102.986223] list_del corruption, ffff888139110698->next is NULL\n[ 3102.986757] WARNING: CPU: 2 PID: 22109 at lib/list_debug.c:53 __list_del_entry_valid_or_report+0x4f/0xc0\n[ 3102.987561] Modules linked in: act_ct nf_flow_table bonding act_tunnel_key act_mirred act_skbedit vxlan cls_matchall nfnetlink_cttimeout act_gact cls_flower sch_ingress mlx5_vdpa vringh vhost_iotlb vdpa openvswitch nsh xt_MASQUERADE nf_conntrack_netlink nfnetlink iptable_nat xt_addrtype xt_conntrack nf_nat br_netfilter rpcsec_gss_krb5 auth_rpcg\nss oid_registry overlay rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi ib_umad rdma_cm ib_ipoib iw_cm ib_cm mlx5_ib ib_uverbs ib_core mlx5_core [last unloaded: bonding]\n[ 3102.991113] CPU: 2 PID: 22109 Comm: revalidator28 Not tainted 6.6.0-rc6+ #3\n[ 3102.991695] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n[ 3102.992605] RIP: 0010:__list_del_entry_valid_or_report+0x4f/0xc0\n[ 3102.993122] Code: 39 c2 74 56 48 8b 32 48 39 fe 75 62 48 8b 51 08 48 39 f2 75 73 b8 01 00 00 00 c3 48 89 fe 48 c7 c7 48 fd 0a 82 e8 41 0b ad ff <0f> 0b 31 c0 c3 48 89 fe 48 c7 c7 70 fd 0a 82 e8 2d 0b ad ff 0f 0b\n[ 3102.994615] RSP: 0018:ffff8881383e7710 EFLAGS: 00010286\n[ 3102.995078] RAX: 0000000000000000 RBX: 0000000000000002 RCX: 0000000000000000\n[ 3102.995670] RDX: 0000000000000001 RSI: ffff88885f89b640 RDI: ffff88885f89b640\n[ 3102.997188] DEL flow 00000000be367878 on port 0\n[ 3102.998594] RBP: dead000000000122 R08: 0000000000000000 R09: c0000000ffffdfff\n[ 3102.999604] R10: 0000000000000008 R11: ffff8881383e7598 R12: dead000000000100\n[ 3103.000198] R13: 0000000000000002 R14: ffff888139110000 R15: ffff888101901240\n[ 3103.000790] FS: 00007f424cde4700(0000) GS:ffff88885f880000(0000) knlGS:0000000000000000\n[ 3103.001486] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 3103.001986] CR2: 00007fd42e8dcb70 CR3: 000000011e68a003 CR4: 0000000000370ea0\n[ 3103.002596] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 3103.003190] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 3103.003787] Call Trace:\n[ 3103.004055] \n[ 3103.004297] ? __warn+0x7d/0x130\n[ 3103.004623] ? __list_del_entry_valid_or_report+0x4f/0xc0\n[ 3103.005094] ? report_bug+0xf1/0x1c0\n[ 3103.005439] ? console_unlock+0x4a/0xd0\n[ 3103.005806] ? handle_bug+0x3f/0x70\n[ 3103.006149] ? exc_invalid_op+0x13/0x60\n[ 3103.006531] ? asm_exc_invalid_op+0x16/0x20\n[ 3103.007430] ? __list_del_entry_valid_or_report+0x4f/0xc0\n[ 3103.007910] mlx5e_tc_del_fdb_peers_flow+0xcf/0x240 [mlx5_core]\n[ 3103.008463] mlx5e_tc_del_flow+0x46/0x270 [mlx5_core]\n[ 3103.008944] mlx5e_flow_put+0x26/0x50 [mlx5_core]\n[ 3103.009401] mlx5e_delete_flower+0x25f/0x380 [mlx5_core]\n[ 3103.009901] tc_setup_cb_destroy+0xab/0x180\n[ 3103.010292] fl_hw_destroy_filter+0x99/0xc0 [cls_flower]\n[ 3103.010779] __fl_delete+0x2d4/0x2f0 [cls_flower]\n[ 3103.0\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-9jr7-gg57-r7pf/GHSA-9jr7-gg57-r7pf.json b/advisories/unreviewed/2024/03/GHSA-9jr7-gg57-r7pf/GHSA-9jr7-gg57-r7pf.json index 3f5597b1c10..5355a3ea37f 100644 --- a/advisories/unreviewed/2024/03/GHSA-9jr7-gg57-r7pf/GHSA-9jr7-gg57-r7pf.json +++ b/advisories/unreviewed/2024/03/GHSA-9jr7-gg57-r7pf/GHSA-9jr7-gg57-r7pf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-9jv3-jc56-rv4g/GHSA-9jv3-jc56-rv4g.json b/advisories/unreviewed/2024/03/GHSA-9jv3-jc56-rv4g/GHSA-9jv3-jc56-rv4g.json index 67c25aaeef5..32bc6294900 100644 --- a/advisories/unreviewed/2024/03/GHSA-9jv3-jc56-rv4g/GHSA-9jv3-jc56-rv4g.json +++ b/advisories/unreviewed/2024/03/GHSA-9jv3-jc56-rv4g/GHSA-9jv3-jc56-rv4g.json @@ -7,12 +7,8 @@ "CVE-2023-52573" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: rds: Fix possible NULL-pointer dereference\n\nIn rds_rdma_cm_event_handler_cmn() check, if conn pointer exists\nbefore dereferencing it as rdma_set_service_type() argument\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-fc5p-vfgp-xc5m/GHSA-fc5p-vfgp-xc5m.json b/advisories/unreviewed/2024/03/GHSA-fc5p-vfgp-xc5m/GHSA-fc5p-vfgp-xc5m.json index e4a72b6ee3b..fc698bce471 100644 --- a/advisories/unreviewed/2024/03/GHSA-fc5p-vfgp-xc5m/GHSA-fc5p-vfgp-xc5m.json +++ b/advisories/unreviewed/2024/03/GHSA-fc5p-vfgp-xc5m/GHSA-fc5p-vfgp-xc5m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-fc7v-6h7h-m2w9/GHSA-fc7v-6h7h-m2w9.json b/advisories/unreviewed/2024/03/GHSA-fc7v-6h7h-m2w9/GHSA-fc7v-6h7h-m2w9.json index 122135fe485..09cdbfc4d16 100644 --- a/advisories/unreviewed/2024/03/GHSA-fc7v-6h7h-m2w9/GHSA-fc7v-6h7h-m2w9.json +++ b/advisories/unreviewed/2024/03/GHSA-fc7v-6h7h-m2w9/GHSA-fc7v-6h7h-m2w9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-g4p6-wj2c-46f6/GHSA-g4p6-wj2c-46f6.json b/advisories/unreviewed/2024/03/GHSA-g4p6-wj2c-46f6/GHSA-g4p6-wj2c-46f6.json index 86fa64b8cac..d2c7d3443de 100644 --- a/advisories/unreviewed/2024/03/GHSA-g4p6-wj2c-46f6/GHSA-g4p6-wj2c-46f6.json +++ b/advisories/unreviewed/2024/03/GHSA-g4p6-wj2c-46f6/GHSA-g4p6-wj2c-46f6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-gx2g-vf96-qjwv/GHSA-gx2g-vf96-qjwv.json b/advisories/unreviewed/2024/03/GHSA-gx2g-vf96-qjwv/GHSA-gx2g-vf96-qjwv.json index 258464fa400..fbc9052ac6f 100644 --- a/advisories/unreviewed/2024/03/GHSA-gx2g-vf96-qjwv/GHSA-gx2g-vf96-qjwv.json +++ b/advisories/unreviewed/2024/03/GHSA-gx2g-vf96-qjwv/GHSA-gx2g-vf96-qjwv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-hw3g-x69p-f6rq/GHSA-hw3g-x69p-f6rq.json b/advisories/unreviewed/2024/03/GHSA-hw3g-x69p-f6rq/GHSA-hw3g-x69p-f6rq.json index 34a95bfbe2a..8aa9bfff8e4 100644 --- a/advisories/unreviewed/2024/03/GHSA-hw3g-x69p-f6rq/GHSA-hw3g-x69p-f6rq.json +++ b/advisories/unreviewed/2024/03/GHSA-hw3g-x69p-f6rq/GHSA-hw3g-x69p-f6rq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-j4qq-hcfp-m638/GHSA-j4qq-hcfp-m638.json b/advisories/unreviewed/2024/03/GHSA-j4qq-hcfp-m638/GHSA-j4qq-hcfp-m638.json index e47d088a4c7..2989da05f4a 100644 --- a/advisories/unreviewed/2024/03/GHSA-j4qq-hcfp-m638/GHSA-j4qq-hcfp-m638.json +++ b/advisories/unreviewed/2024/03/GHSA-j4qq-hcfp-m638/GHSA-j4qq-hcfp-m638.json @@ -7,12 +7,8 @@ "CVE-2023-52490" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: migrate: fix getting incorrect page mapping during page migration\n\nWhen running stress-ng testing, we found below kernel crash after a few hours:\n\nUnable to handle kernel NULL pointer dereference at virtual address 0000000000000000\npc : dentry_name+0xd8/0x224\nlr : pointer+0x22c/0x370\nsp : ffff800025f134c0\n......\nCall trace:\n dentry_name+0xd8/0x224\n pointer+0x22c/0x370\n vsnprintf+0x1ec/0x730\n vscnprintf+0x2c/0x60\n vprintk_store+0x70/0x234\n vprintk_emit+0xe0/0x24c\n vprintk_default+0x3c/0x44\n vprintk_func+0x84/0x2d0\n printk+0x64/0x88\n __dump_page+0x52c/0x530\n dump_page+0x14/0x20\n set_migratetype_isolate+0x110/0x224\n start_isolate_page_range+0xc4/0x20c\n offline_pages+0x124/0x474\n memory_block_offline+0x44/0xf4\n memory_subsys_offline+0x3c/0x70\n device_offline+0xf0/0x120\n ......\n\nAfter analyzing the vmcore, I found this issue is caused by page migration.\nThe scenario is that, one thread is doing page migration, and we will use the\ntarget page's ->mapping field to save 'anon_vma' pointer between page unmap and\npage move, and now the target page is locked and refcount is 1.\n\nCurrently, there is another stress-ng thread performing memory hotplug,\nattempting to offline the target page that is being migrated. It discovers that\nthe refcount of this target page is 1, preventing the offline operation, thus\nproceeding to dump the page. However, page_mapping() of the target page may\nreturn an incorrect file mapping to crash the system in dump_mapping(), since\nthe target page->mapping only saves 'anon_vma' pointer without setting\nPAGE_MAPPING_ANON flag.\n\nThere are seveval ways to fix this issue:\n(1) Setting the PAGE_MAPPING_ANON flag for target page's ->mapping when saving\n'anon_vma', but this can confuse PageAnon() for PFN walkers, since the target\npage has not built mappings yet.\n(2) Getting the page lock to call page_mapping() in __dump_page() to avoid crashing\nthe system, however, there are still some PFN walkers that call page_mapping()\nwithout holding the page lock, such as compaction.\n(3) Using target page->private field to save the 'anon_vma' pointer and 2 bits\npage state, just as page->mapping records an anonymous page, which can remove\nthe page_mapping() impact for PFN walkers and also seems a simple way.\n\nSo I choose option 3 to fix this issue, and this can also fix other potential\nissues for PFN walkers, such as compaction.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-m7gg-q7qj-3r2r/GHSA-m7gg-q7qj-3r2r.json b/advisories/unreviewed/2024/03/GHSA-m7gg-q7qj-3r2r/GHSA-m7gg-q7qj-3r2r.json index be364d306b0..7efb2956304 100644 --- a/advisories/unreviewed/2024/03/GHSA-m7gg-q7qj-3r2r/GHSA-m7gg-q7qj-3r2r.json +++ b/advisories/unreviewed/2024/03/GHSA-m7gg-q7qj-3r2r/GHSA-m7gg-q7qj-3r2r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-mq62-5vgw-569m/GHSA-mq62-5vgw-569m.json b/advisories/unreviewed/2024/03/GHSA-mq62-5vgw-569m/GHSA-mq62-5vgw-569m.json index 767c767c574..9b65882a314 100644 --- a/advisories/unreviewed/2024/03/GHSA-mq62-5vgw-569m/GHSA-mq62-5vgw-569m.json +++ b/advisories/unreviewed/2024/03/GHSA-mq62-5vgw-569m/GHSA-mq62-5vgw-569m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-q2qw-486m-j3c6/GHSA-q2qw-486m-j3c6.json b/advisories/unreviewed/2024/03/GHSA-q2qw-486m-j3c6/GHSA-q2qw-486m-j3c6.json index 6315c6c227a..8fea6f20493 100644 --- a/advisories/unreviewed/2024/03/GHSA-q2qw-486m-j3c6/GHSA-q2qw-486m-j3c6.json +++ b/advisories/unreviewed/2024/03/GHSA-q2qw-486m-j3c6/GHSA-q2qw-486m-j3c6.json @@ -7,12 +7,8 @@ "CVE-2024-26619" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: Fix module loading free order\n\nReverse order of kfree calls to resolve use-after-free error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-q98h-hc6w-gjhg/GHSA-q98h-hc6w-gjhg.json b/advisories/unreviewed/2024/03/GHSA-q98h-hc6w-gjhg/GHSA-q98h-hc6w-gjhg.json index b3fb5711013..aabaf717735 100644 --- a/advisories/unreviewed/2024/03/GHSA-q98h-hc6w-gjhg/GHSA-q98h-hc6w-gjhg.json +++ b/advisories/unreviewed/2024/03/GHSA-q98h-hc6w-gjhg/GHSA-q98h-hc6w-gjhg.json @@ -7,12 +7,8 @@ "CVE-2024-26616" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: scrub: avoid use-after-free when chunk length is not 64K aligned\n\n[BUG]\nThere is a bug report that, on a ext4-converted btrfs, scrub leads to\nvarious problems, including:\n\n- \"unable to find chunk map\" errors\n BTRFS info (device vdb): scrub: started on devid 1\n BTRFS critical (device vdb): unable to find chunk map for logical 2214744064 length 4096\n BTRFS critical (device vdb): unable to find chunk map for logical 2214744064 length 45056\n\n This would lead to unrepariable errors.\n\n- Use-after-free KASAN reports:\n ==================================================================\n BUG: KASAN: slab-use-after-free in __blk_rq_map_sg+0x18f/0x7c0\n Read of size 8 at addr ffff8881013c9040 by task btrfs/909\n CPU: 0 PID: 909 Comm: btrfs Not tainted 6.7.0-x64v3-dbg #11 c50636e9419a8354555555245df535e380563b2b\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 2023.11-2 12/24/2023\n Call Trace:\n \n dump_stack_lvl+0x43/0x60\n print_report+0xcf/0x640\n kasan_report+0xa6/0xd0\n __blk_rq_map_sg+0x18f/0x7c0\n virtblk_prep_rq.isra.0+0x215/0x6a0 [virtio_blk 19a65eeee9ae6fcf02edfad39bb9ddee07dcdaff]\n virtio_queue_rqs+0xc4/0x310 [virtio_blk 19a65eeee9ae6fcf02edfad39bb9ddee07dcdaff]\n blk_mq_flush_plug_list.part.0+0x780/0x860\n __blk_flush_plug+0x1ba/0x220\n blk_finish_plug+0x3b/0x60\n submit_initial_group_read+0x10a/0x290 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965]\n flush_scrub_stripes+0x38e/0x430 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965]\n scrub_stripe+0x82a/0xae0 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965]\n scrub_chunk+0x178/0x200 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965]\n scrub_enumerate_chunks+0x4bc/0xa30 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965]\n btrfs_scrub_dev+0x398/0x810 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965]\n btrfs_ioctl+0x4b9/0x3020 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965]\n __x64_sys_ioctl+0xbd/0x100\n do_syscall_64+0x5d/0xe0\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n RIP: 0033:0x7f47e5e0952b\n\n- Crash, mostly due to above use-after-free\n\n[CAUSE]\nThe converted fs has the following data chunk layout:\n\n item 2 key (FIRST_CHUNK_TREE CHUNK_ITEM 2214658048) itemoff 16025 itemsize 80\n length 86016 owner 2 stripe_len 65536 type DATA|single\n\nFor above logical bytenr 2214744064, it's at the chunk end\n(2214658048 + 86016 = 2214744064).\n\nThis means btrfs_submit_bio() would split the bio, and trigger endio\nfunction for both of the two halves.\n\nHowever scrub_submit_initial_read() would only expect the endio function\nto be called once, not any more.\nThis means the first endio function would already free the bbio::bio,\nleaving the bvec freed, thus the 2nd endio call would lead to\nuse-after-free.\n\n[FIX]\n- Make sure scrub_read_endio() only updates bits in its range\n Since we may read less than 64K at the end of the chunk, we should not\n touch the bits beyond chunk boundary.\n\n- Make sure scrub_submit_initial_read() only to read the chunk range\n This is done by calculating the real number of sectors we need to\n read, and add sector-by-sector to the bio.\n\nThankfully the scrub read repair path won't need extra fixes:\n\n- scrub_stripe_submit_repair_read()\n With above fixes, we won't update error bit for range beyond chunk,\n thus scrub_stripe_submit_repair_read() should never submit any read\n beyond the chunk.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-qxmq-f8x5-rfg3/GHSA-qxmq-f8x5-rfg3.json b/advisories/unreviewed/2024/03/GHSA-qxmq-f8x5-rfg3/GHSA-qxmq-f8x5-rfg3.json index de2596dd321..fff16a64bb6 100644 --- a/advisories/unreviewed/2024/03/GHSA-qxmq-f8x5-rfg3/GHSA-qxmq-f8x5-rfg3.json +++ b/advisories/unreviewed/2024/03/GHSA-qxmq-f8x5-rfg3/GHSA-qxmq-f8x5-rfg3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-w45h-9jvc-v65p/GHSA-w45h-9jvc-v65p.json b/advisories/unreviewed/2024/03/GHSA-w45h-9jvc-v65p/GHSA-w45h-9jvc-v65p.json index 61fc2c2ce9f..64d27a08781 100644 --- a/advisories/unreviewed/2024/03/GHSA-w45h-9jvc-v65p/GHSA-w45h-9jvc-v65p.json +++ b/advisories/unreviewed/2024/03/GHSA-w45h-9jvc-v65p/GHSA-w45h-9jvc-v65p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-wfc2-g4f8-v6c3/GHSA-wfc2-g4f8-v6c3.json b/advisories/unreviewed/2024/03/GHSA-wfc2-g4f8-v6c3/GHSA-wfc2-g4f8-v6c3.json index 3bd476e16e9..2952e45503b 100644 --- a/advisories/unreviewed/2024/03/GHSA-wfc2-g4f8-v6c3/GHSA-wfc2-g4f8-v6c3.json +++ b/advisories/unreviewed/2024/03/GHSA-wfc2-g4f8-v6c3/GHSA-wfc2-g4f8-v6c3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-whgx-jw4g-48ph/GHSA-whgx-jw4g-48ph.json b/advisories/unreviewed/2024/03/GHSA-whgx-jw4g-48ph/GHSA-whgx-jw4g-48ph.json index da39c5f8ac4..2d666a052d8 100644 --- a/advisories/unreviewed/2024/03/GHSA-whgx-jw4g-48ph/GHSA-whgx-jw4g-48ph.json +++ b/advisories/unreviewed/2024/03/GHSA-whgx-jw4g-48ph/GHSA-whgx-jw4g-48ph.json @@ -7,12 +7,8 @@ "CVE-2023-52495" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: pmic_glink_altmode: fix port sanity check\n\nThe PMIC GLINK altmode driver currently supports at most two ports.\n\nFix the incomplete port sanity check on notifications to avoid\naccessing and corrupting memory beyond the port array if we ever get a\nnotification for an unsupported port.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-wq2q-fqq7-mgvw/GHSA-wq2q-fqq7-mgvw.json b/advisories/unreviewed/2024/03/GHSA-wq2q-fqq7-mgvw/GHSA-wq2q-fqq7-mgvw.json index c83de11066e..51827c2fcbd 100644 --- a/advisories/unreviewed/2024/03/GHSA-wq2q-fqq7-mgvw/GHSA-wq2q-fqq7-mgvw.json +++ b/advisories/unreviewed/2024/03/GHSA-wq2q-fqq7-mgvw/GHSA-wq2q-fqq7-mgvw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-x5f4-w9r3-6rpq/GHSA-x5f4-w9r3-6rpq.json b/advisories/unreviewed/2024/03/GHSA-x5f4-w9r3-6rpq/GHSA-x5f4-w9r3-6rpq.json index d489938719b..41be89647d6 100644 --- a/advisories/unreviewed/2024/03/GHSA-x5f4-w9r3-6rpq/GHSA-x5f4-w9r3-6rpq.json +++ b/advisories/unreviewed/2024/03/GHSA-x5f4-w9r3-6rpq/GHSA-x5f4-w9r3-6rpq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-x8vw-5hgg-p3q8/GHSA-x8vw-5hgg-p3q8.json b/advisories/unreviewed/2024/03/GHSA-x8vw-5hgg-p3q8/GHSA-x8vw-5hgg-p3q8.json index 1fe460fc6bc..57c51f6e957 100644 --- a/advisories/unreviewed/2024/03/GHSA-x8vw-5hgg-p3q8/GHSA-x8vw-5hgg-p3q8.json +++ b/advisories/unreviewed/2024/03/GHSA-x8vw-5hgg-p3q8/GHSA-x8vw-5hgg-p3q8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",