diff --git a/advisories/github-reviewed/2021/12/GHSA-gfhx-jjwq-63gv/GHSA-gfhx-jjwq-63gv.json b/advisories/github-reviewed/2021/12/GHSA-gfhx-jjwq-63gv/GHSA-gfhx-jjwq-63gv.json index ce9947e9f50..9eae4d0da07 100644 --- a/advisories/github-reviewed/2021/12/GHSA-gfhx-jjwq-63gv/GHSA-gfhx-jjwq-63gv.json +++ b/advisories/github-reviewed/2021/12/GHSA-gfhx-jjwq-63gv/GHSA-gfhx-jjwq-63gv.json @@ -8,9 +8,7 @@ ], "summary": "Cross-site Scripting in Apereo CAS", "details": "Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/04/GHSA-jm35-h8q2-73mp/GHSA-jm35-h8q2-73mp.json b/advisories/github-reviewed/2022/04/GHSA-jm35-h8q2-73mp/GHSA-jm35-h8q2-73mp.json index baf3787e50e..dd6ac175306 100644 --- a/advisories/github-reviewed/2022/04/GHSA-jm35-h8q2-73mp/GHSA-jm35-h8q2-73mp.json +++ b/advisories/github-reviewed/2022/04/GHSA-jm35-h8q2-73mp/GHSA-jm35-h8q2-73mp.json @@ -58,9 +58,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2022-04-07T22:09:03Z", diff --git a/advisories/github-reviewed/2023/10/GHSA-m6vm-37g8-gqvh/GHSA-m6vm-37g8-gqvh.json b/advisories/github-reviewed/2023/10/GHSA-m6vm-37g8-gqvh/GHSA-m6vm-37g8-gqvh.json index df66f0d48d6..c5561d3bde7 100644 --- a/advisories/github-reviewed/2023/10/GHSA-m6vm-37g8-gqvh/GHSA-m6vm-37g8-gqvh.json +++ b/advisories/github-reviewed/2023/10/GHSA-m6vm-37g8-gqvh/GHSA-m6vm-37g8-gqvh.json @@ -81,9 +81,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-08-29T18:32:05Z", diff --git a/advisories/github-reviewed/2024/06/GHSA-5j86-5xvg-7q93/GHSA-5j86-5xvg-7q93.json b/advisories/github-reviewed/2024/06/GHSA-5j86-5xvg-7q93/GHSA-5j86-5xvg-7q93.json index 5deb6d44fe3..92ed57a6035 100644 --- a/advisories/github-reviewed/2024/06/GHSA-5j86-5xvg-7q93/GHSA-5j86-5xvg-7q93.json +++ b/advisories/github-reviewed/2024/06/GHSA-5j86-5xvg-7q93/GHSA-5j86-5xvg-7q93.json @@ -3,14 +3,10 @@ "id": "GHSA-5j86-5xvg-7q93", "modified": "2024-06-03T19:42:12Z", "published": "2024-06-03T19:42:12Z", - "aliases": [ - - ], + "aliases": [], "summary": "TYPO3 Cross-Site Scripting (XSS) in form component", "details": "Failing to sanitize content from unauthenticated website visitors, the form component is susceptible to Cross-Site Scripting.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -47,9 +43,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-06-03T19:42:12Z", diff --git a/advisories/github-reviewed/2024/06/GHSA-vgm8-r9gm-fw59/GHSA-vgm8-r9gm-fw59.json b/advisories/github-reviewed/2024/06/GHSA-vgm8-r9gm-fw59/GHSA-vgm8-r9gm-fw59.json index 5329ef9aded..e70ae6c7562 100644 --- a/advisories/github-reviewed/2024/06/GHSA-vgm8-r9gm-fw59/GHSA-vgm8-r9gm-fw59.json +++ b/advisories/github-reviewed/2024/06/GHSA-vgm8-r9gm-fw59/GHSA-vgm8-r9gm-fw59.json @@ -3,14 +3,10 @@ "id": "GHSA-vgm8-r9gm-fw59", "modified": "2024-06-03T19:41:40Z", "published": "2024-06-03T19:41:40Z", - "aliases": [ - - ], + "aliases": [], "summary": "TYPO3 Cross-Site Scripting in legacy form component", "details": "Failing to sanitize content from editors, the legacy form component is susceptible to Cross-Site Scripting. A valid editor account with access to a form content element is required to exploit this vulnerability.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -47,9 +43,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-06-03T19:41:40Z", diff --git a/advisories/unreviewed/2021/12/GHSA-3pcx-vgx2-j88m/GHSA-3pcx-vgx2-j88m.json b/advisories/unreviewed/2021/12/GHSA-3pcx-vgx2-j88m/GHSA-3pcx-vgx2-j88m.json index c4410441598..dd0e20edf97 100644 --- a/advisories/unreviewed/2021/12/GHSA-3pcx-vgx2-j88m/GHSA-3pcx-vgx2-j88m.json +++ b/advisories/unreviewed/2021/12/GHSA-3pcx-vgx2-j88m/GHSA-3pcx-vgx2-j88m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-fgh6-7vq6-4p7f/GHSA-fgh6-7vq6-4p7f.json b/advisories/unreviewed/2021/12/GHSA-fgh6-7vq6-4p7f/GHSA-fgh6-7vq6-4p7f.json index cac6206bc92..425f3077728 100644 --- a/advisories/unreviewed/2021/12/GHSA-fgh6-7vq6-4p7f/GHSA-fgh6-7vq6-4p7f.json +++ b/advisories/unreviewed/2021/12/GHSA-fgh6-7vq6-4p7f/GHSA-fgh6-7vq6-4p7f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-pxx7-h693-qm6h/GHSA-pxx7-h693-qm6h.json b/advisories/unreviewed/2021/12/GHSA-pxx7-h693-qm6h/GHSA-pxx7-h693-qm6h.json index 7f9f9e3b00e..79e700888f8 100644 --- a/advisories/unreviewed/2021/12/GHSA-pxx7-h693-qm6h/GHSA-pxx7-h693-qm6h.json +++ b/advisories/unreviewed/2021/12/GHSA-pxx7-h693-qm6h/GHSA-pxx7-h693-qm6h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-q82x-fpcf-f854/GHSA-q82x-fpcf-f854.json b/advisories/unreviewed/2021/12/GHSA-q82x-fpcf-f854/GHSA-q82x-fpcf-f854.json index 589c023fff6..90a746bccad 100644 --- a/advisories/unreviewed/2021/12/GHSA-q82x-fpcf-f854/GHSA-q82x-fpcf-f854.json +++ b/advisories/unreviewed/2021/12/GHSA-q82x-fpcf-f854/GHSA-q82x-fpcf-f854.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-5g2c-wqm3-5vm3/GHSA-5g2c-wqm3-5vm3.json b/advisories/unreviewed/2022/01/GHSA-5g2c-wqm3-5vm3/GHSA-5g2c-wqm3-5vm3.json index 873ed9bc2b3..a2debe42d99 100644 --- a/advisories/unreviewed/2022/01/GHSA-5g2c-wqm3-5vm3/GHSA-5g2c-wqm3-5vm3.json +++ b/advisories/unreviewed/2022/01/GHSA-5g2c-wqm3-5vm3/GHSA-5g2c-wqm3-5vm3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-2php-7prq-766p/GHSA-2php-7prq-766p.json b/advisories/unreviewed/2022/02/GHSA-2php-7prq-766p/GHSA-2php-7prq-766p.json index b3f4c48e053..9f7432c7d0d 100644 --- a/advisories/unreviewed/2022/02/GHSA-2php-7prq-766p/GHSA-2php-7prq-766p.json +++ b/advisories/unreviewed/2022/02/GHSA-2php-7prq-766p/GHSA-2php-7prq-766p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-74g3-jv9w-535w/GHSA-74g3-jv9w-535w.json b/advisories/unreviewed/2022/02/GHSA-74g3-jv9w-535w/GHSA-74g3-jv9w-535w.json index ce6702ceac3..478368a9c75 100644 --- a/advisories/unreviewed/2022/02/GHSA-74g3-jv9w-535w/GHSA-74g3-jv9w-535w.json +++ b/advisories/unreviewed/2022/02/GHSA-74g3-jv9w-535w/GHSA-74g3-jv9w-535w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-8p5x-c2fg-f7h9/GHSA-8p5x-c2fg-f7h9.json b/advisories/unreviewed/2022/02/GHSA-8p5x-c2fg-f7h9/GHSA-8p5x-c2fg-f7h9.json index 912d29b3817..3c8dc614b27 100644 --- a/advisories/unreviewed/2022/02/GHSA-8p5x-c2fg-f7h9/GHSA-8p5x-c2fg-f7h9.json +++ b/advisories/unreviewed/2022/02/GHSA-8p5x-c2fg-f7h9/GHSA-8p5x-c2fg-f7h9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-ff7h-w5rr-x7jc/GHSA-ff7h-w5rr-x7jc.json b/advisories/unreviewed/2022/02/GHSA-ff7h-w5rr-x7jc/GHSA-ff7h-w5rr-x7jc.json index 544d3590aaf..99a3a6e8cef 100644 --- a/advisories/unreviewed/2022/02/GHSA-ff7h-w5rr-x7jc/GHSA-ff7h-w5rr-x7jc.json +++ b/advisories/unreviewed/2022/02/GHSA-ff7h-w5rr-x7jc/GHSA-ff7h-w5rr-x7jc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-mq88-wc55-whqv/GHSA-mq88-wc55-whqv.json b/advisories/unreviewed/2022/02/GHSA-mq88-wc55-whqv/GHSA-mq88-wc55-whqv.json index 62288c22aae..54d05613652 100644 --- a/advisories/unreviewed/2022/02/GHSA-mq88-wc55-whqv/GHSA-mq88-wc55-whqv.json +++ b/advisories/unreviewed/2022/02/GHSA-mq88-wc55-whqv/GHSA-mq88-wc55-whqv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-4p6x-85ff-qrhc/GHSA-4p6x-85ff-qrhc.json b/advisories/unreviewed/2022/03/GHSA-4p6x-85ff-qrhc/GHSA-4p6x-85ff-qrhc.json index 60013a7667b..e6089369c7e 100644 --- a/advisories/unreviewed/2022/03/GHSA-4p6x-85ff-qrhc/GHSA-4p6x-85ff-qrhc.json +++ b/advisories/unreviewed/2022/03/GHSA-4p6x-85ff-qrhc/GHSA-4p6x-85ff-qrhc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-8v39-xghj-fqh4/GHSA-8v39-xghj-fqh4.json b/advisories/unreviewed/2022/03/GHSA-8v39-xghj-fqh4/GHSA-8v39-xghj-fqh4.json index d96da047396..62240a0fc12 100644 --- a/advisories/unreviewed/2022/03/GHSA-8v39-xghj-fqh4/GHSA-8v39-xghj-fqh4.json +++ b/advisories/unreviewed/2022/03/GHSA-8v39-xghj-fqh4/GHSA-8v39-xghj-fqh4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-974c-m3vw-pwx2/GHSA-974c-m3vw-pwx2.json b/advisories/unreviewed/2022/03/GHSA-974c-m3vw-pwx2/GHSA-974c-m3vw-pwx2.json index 3e7e9cd153c..22814dc76e0 100644 --- a/advisories/unreviewed/2022/03/GHSA-974c-m3vw-pwx2/GHSA-974c-m3vw-pwx2.json +++ b/advisories/unreviewed/2022/03/GHSA-974c-m3vw-pwx2/GHSA-974c-m3vw-pwx2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-hhh9-rwf2-2pp5/GHSA-hhh9-rwf2-2pp5.json b/advisories/unreviewed/2022/03/GHSA-hhh9-rwf2-2pp5/GHSA-hhh9-rwf2-2pp5.json index 9d253f01e92..d23d7cabdf0 100644 --- a/advisories/unreviewed/2022/03/GHSA-hhh9-rwf2-2pp5/GHSA-hhh9-rwf2-2pp5.json +++ b/advisories/unreviewed/2022/03/GHSA-hhh9-rwf2-2pp5/GHSA-hhh9-rwf2-2pp5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-qf97-3r3x-x56v/GHSA-qf97-3r3x-x56v.json b/advisories/unreviewed/2022/03/GHSA-qf97-3r3x-x56v/GHSA-qf97-3r3x-x56v.json index 21c96daec47..ab1c30b3d1d 100644 --- a/advisories/unreviewed/2022/03/GHSA-qf97-3r3x-x56v/GHSA-qf97-3r3x-x56v.json +++ b/advisories/unreviewed/2022/03/GHSA-qf97-3r3x-x56v/GHSA-qf97-3r3x-x56v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-223r-j88r-q3hw/GHSA-223r-j88r-q3hw.json b/advisories/unreviewed/2022/04/GHSA-223r-j88r-q3hw/GHSA-223r-j88r-q3hw.json index 994cafcfcca..2fc798a7caa 100644 --- a/advisories/unreviewed/2022/04/GHSA-223r-j88r-q3hw/GHSA-223r-j88r-q3hw.json +++ b/advisories/unreviewed/2022/04/GHSA-223r-j88r-q3hw/GHSA-223r-j88r-q3hw.json @@ -7,12 +7,8 @@ "CVE-2002-1310" ], "details": "Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia JRun 4.0 and earlier allows remote attackers to execute arbitrary via an HTTP GET request with a long .jsp file name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-224v-g4hw-hwxj/GHSA-224v-g4hw-hwxj.json b/advisories/unreviewed/2022/04/GHSA-224v-g4hw-hwxj/GHSA-224v-g4hw-hwxj.json index 9e492afe3bb..bca19e250f0 100644 --- a/advisories/unreviewed/2022/04/GHSA-224v-g4hw-hwxj/GHSA-224v-g4hw-hwxj.json +++ b/advisories/unreviewed/2022/04/GHSA-224v-g4hw-hwxj/GHSA-224v-g4hw-hwxj.json @@ -7,12 +7,8 @@ "CVE-2002-1441" ], "details": "Multiple buffer overflows in Tomahawk SteelArrow before 4.5 allow remote attackers to execute arbitrary code via (1) the Steelarrow Service (Steelarrow.exe) using a long UserIdent Cookie header, (2) DLLHOST.EXE (Steelarrow.dll) via a request for a long .aro file, or (3) DLLHOST.EXE via a Chunked Transfer-Encoding request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-22c7-cppf-fmqm/GHSA-22c7-cppf-fmqm.json b/advisories/unreviewed/2022/04/GHSA-22c7-cppf-fmqm/GHSA-22c7-cppf-fmqm.json index ac303c6b9c3..b569b914b27 100644 --- a/advisories/unreviewed/2022/04/GHSA-22c7-cppf-fmqm/GHSA-22c7-cppf-fmqm.json +++ b/advisories/unreviewed/2022/04/GHSA-22c7-cppf-fmqm/GHSA-22c7-cppf-fmqm.json @@ -7,12 +7,8 @@ "CVE-2002-1185" ], "details": "Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka \"Malformed PNG Image File Failure.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2424-29jp-qgw2/GHSA-2424-29jp-qgw2.json b/advisories/unreviewed/2022/04/GHSA-2424-29jp-qgw2/GHSA-2424-29jp-qgw2.json index 4e3b954f77f..414e1df624d 100644 --- a/advisories/unreviewed/2022/04/GHSA-2424-29jp-qgw2/GHSA-2424-29jp-qgw2.json +++ b/advisories/unreviewed/2022/04/GHSA-2424-29jp-qgw2/GHSA-2424-29jp-qgw2.json @@ -7,12 +7,8 @@ "CVE-2002-0943" ], "details": "MetaCart2.sql stores the user database under the web document root without access controls, which allows remote attackers to obtain sensitive information such as passwords and credit card numbers via a direct request for metacart.mdb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-254g-h6q6-4fxv/GHSA-254g-h6q6-4fxv.json b/advisories/unreviewed/2022/04/GHSA-254g-h6q6-4fxv/GHSA-254g-h6q6-4fxv.json index dbd514d975e..92025955514 100644 --- a/advisories/unreviewed/2022/04/GHSA-254g-h6q6-4fxv/GHSA-254g-h6q6-4fxv.json +++ b/advisories/unreviewed/2022/04/GHSA-254g-h6q6-4fxv/GHSA-254g-h6q6-4fxv.json @@ -7,12 +7,8 @@ "CVE-2002-1253" ], "details": "Abuse 2.00 and earlier allows local users to gain privileges via command line arguments that specify alternate Lisp scripts that run at escalated privileges, which can contain functions that execute commands or modify files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2623-fqch-p6pf/GHSA-2623-fqch-p6pf.json b/advisories/unreviewed/2022/04/GHSA-2623-fqch-p6pf/GHSA-2623-fqch-p6pf.json index 74bf6983476..b7d1ae1a0de 100644 --- a/advisories/unreviewed/2022/04/GHSA-2623-fqch-p6pf/GHSA-2623-fqch-p6pf.json +++ b/advisories/unreviewed/2022/04/GHSA-2623-fqch-p6pf/GHSA-2623-fqch-p6pf.json @@ -7,12 +7,8 @@ "CVE-2002-0933" ], "details": "Datalex PLC BookIt! Consumer before 2.2 stores usernames and passwords in plaintext in a cookie, which could allow remote attackers to gain privileges via Cross-site scripting or sniffing attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-263v-qw54-cmjj/GHSA-263v-qw54-cmjj.json b/advisories/unreviewed/2022/04/GHSA-263v-qw54-cmjj/GHSA-263v-qw54-cmjj.json index b67bd9b7bba..150d0a305c3 100644 --- a/advisories/unreviewed/2022/04/GHSA-263v-qw54-cmjj/GHSA-263v-qw54-cmjj.json +++ b/advisories/unreviewed/2022/04/GHSA-263v-qw54-cmjj/GHSA-263v-qw54-cmjj.json @@ -7,12 +7,8 @@ "CVE-2002-1462" ], "details": "details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-27c5-3v5f-m49w/GHSA-27c5-3v5f-m49w.json b/advisories/unreviewed/2022/04/GHSA-27c5-3v5f-m49w/GHSA-27c5-3v5f-m49w.json index c065333625d..8f2489f0d61 100644 --- a/advisories/unreviewed/2022/04/GHSA-27c5-3v5f-m49w/GHSA-27c5-3v5f-m49w.json +++ b/advisories/unreviewed/2022/04/GHSA-27c5-3v5f-m49w/GHSA-27c5-3v5f-m49w.json @@ -7,12 +7,8 @@ "CVE-2002-1046" ], "details": "Dynamic VPN Configuration Protocol service (DVCP) in Watchguard Firebox firmware 5.x.x allows remote attackers to cause a denial of service (crash) via a malformed packet containing tab characters to TCP port 4110.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-29pg-f8vr-x2wh/GHSA-29pg-f8vr-x2wh.json b/advisories/unreviewed/2022/04/GHSA-29pg-f8vr-x2wh/GHSA-29pg-f8vr-x2wh.json index 5d535be7095..493139ece7e 100644 --- a/advisories/unreviewed/2022/04/GHSA-29pg-f8vr-x2wh/GHSA-29pg-f8vr-x2wh.json +++ b/advisories/unreviewed/2022/04/GHSA-29pg-f8vr-x2wh/GHSA-29pg-f8vr-x2wh.json @@ -7,12 +7,8 @@ "CVE-2002-1216" ], "details": "GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modification that effectively disabled the security check.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2c64-8vwr-5pjm/GHSA-2c64-8vwr-5pjm.json b/advisories/unreviewed/2022/04/GHSA-2c64-8vwr-5pjm/GHSA-2c64-8vwr-5pjm.json index cd3aad40cb4..1230eedefb8 100644 --- a/advisories/unreviewed/2022/04/GHSA-2c64-8vwr-5pjm/GHSA-2c64-8vwr-5pjm.json +++ b/advisories/unreviewed/2022/04/GHSA-2c64-8vwr-5pjm/GHSA-2c64-8vwr-5pjm.json @@ -7,12 +7,8 @@ "CVE-2002-0929" ], "details": "Buffer overflows in the DHCP server for NetWare 6.0 SP1 allow remote attackers to cause a denial of service (reboot) via long DHCP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2c89-h2r9-m4fw/GHSA-2c89-h2r9-m4fw.json b/advisories/unreviewed/2022/04/GHSA-2c89-h2r9-m4fw/GHSA-2c89-h2r9-m4fw.json index bba424e9b52..700683951ee 100644 --- a/advisories/unreviewed/2022/04/GHSA-2c89-h2r9-m4fw/GHSA-2c89-h2r9-m4fw.json +++ b/advisories/unreviewed/2022/04/GHSA-2c89-h2r9-m4fw/GHSA-2c89-h2r9-m4fw.json @@ -7,12 +7,8 @@ "CVE-2002-0979" ], "details": "The Java logging feature for the Java Virtual Machine in Internet Explorer writes output from functions such as System.out.println to a known pathname, which can be used to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2fjq-9whp-5fvh/GHSA-2fjq-9whp-5fvh.json b/advisories/unreviewed/2022/04/GHSA-2fjq-9whp-5fvh/GHSA-2fjq-9whp-5fvh.json index 0e9a034d8e1..4d06e20a3c0 100644 --- a/advisories/unreviewed/2022/04/GHSA-2fjq-9whp-5fvh/GHSA-2fjq-9whp-5fvh.json +++ b/advisories/unreviewed/2022/04/GHSA-2fjq-9whp-5fvh/GHSA-2fjq-9whp-5fvh.json @@ -7,12 +7,8 @@ "CVE-2002-1357" ], "details": "Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-2fx9-2g54-566x/GHSA-2fx9-2g54-566x.json b/advisories/unreviewed/2022/04/GHSA-2fx9-2g54-566x/GHSA-2fx9-2g54-566x.json index 3e37b797667..bf04a89996b 100644 --- a/advisories/unreviewed/2022/04/GHSA-2fx9-2g54-566x/GHSA-2fx9-2g54-566x.json +++ b/advisories/unreviewed/2022/04/GHSA-2fx9-2g54-566x/GHSA-2fx9-2g54-566x.json @@ -7,12 +7,8 @@ "CVE-2002-0914" ], "details": "Double Precision Courier e-mail MTA allows remote attackers to cause a denial of service (CPU consumption) via a message with an extremely large or negative value for the year, which causes a tight loop.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2g3m-fq88-fm9q/GHSA-2g3m-fq88-fm9q.json b/advisories/unreviewed/2022/04/GHSA-2g3m-fq88-fm9q/GHSA-2g3m-fq88-fm9q.json index 3ab7f18c73b..e70968a494b 100644 --- a/advisories/unreviewed/2022/04/GHSA-2g3m-fq88-fm9q/GHSA-2g3m-fq88-fm9q.json +++ b/advisories/unreviewed/2022/04/GHSA-2g3m-fq88-fm9q/GHSA-2g3m-fq88-fm9q.json @@ -7,12 +7,8 @@ "CVE-2002-1294" ], "details": "The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to illegal memory accesses) and possibly conduct other unauthorized activities via an applet that uses those references to access proprietary Microsoft methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2h6x-rf29-p2gv/GHSA-2h6x-rf29-p2gv.json b/advisories/unreviewed/2022/04/GHSA-2h6x-rf29-p2gv/GHSA-2h6x-rf29-p2gv.json index f8f7205dc55..549cacf15b1 100644 --- a/advisories/unreviewed/2022/04/GHSA-2h6x-rf29-p2gv/GHSA-2h6x-rf29-p2gv.json +++ b/advisories/unreviewed/2022/04/GHSA-2h6x-rf29-p2gv/GHSA-2h6x-rf29-p2gv.json @@ -7,12 +7,8 @@ "CVE-2002-0976" ], "details": "Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the applet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2h9x-x82w-69cq/GHSA-2h9x-x82w-69cq.json b/advisories/unreviewed/2022/04/GHSA-2h9x-x82w-69cq/GHSA-2h9x-x82w-69cq.json index 75106274bb2..8b57b5484d3 100644 --- a/advisories/unreviewed/2022/04/GHSA-2h9x-x82w-69cq/GHSA-2h9x-x82w-69cq.json +++ b/advisories/unreviewed/2022/04/GHSA-2h9x-x82w-69cq/GHSA-2h9x-x82w-69cq.json @@ -7,12 +7,8 @@ "CVE-2002-0961" ], "details": "Vulnerabilities in Voxel Dot Net CBMS 0.7 and earlier allow remote attackers to conduct unauthorized operations as other users, e.g. by deleting clients via dltclnt.php, possibly in a SQL injection attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2jp2-c8rx-5w8j/GHSA-2jp2-c8rx-5w8j.json b/advisories/unreviewed/2022/04/GHSA-2jp2-c8rx-5w8j/GHSA-2jp2-c8rx-5w8j.json index c390b471e32..674bcdf2c41 100644 --- a/advisories/unreviewed/2022/04/GHSA-2jp2-c8rx-5w8j/GHSA-2jp2-c8rx-5w8j.json +++ b/advisories/unreviewed/2022/04/GHSA-2jp2-c8rx-5w8j/GHSA-2jp2-c8rx-5w8j.json @@ -7,12 +7,8 @@ "CVE-2002-1287" ], "details": "Stack-based buffer overflow in the Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service via a long class name through (1) Class.forName or (2) ClassLoader.loadClass.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2jpc-hvvc-26mm/GHSA-2jpc-hvvc-26mm.json b/advisories/unreviewed/2022/04/GHSA-2jpc-hvvc-26mm/GHSA-2jpc-hvvc-26mm.json index ce16b7538ad..63d5e5836a2 100644 --- a/advisories/unreviewed/2022/04/GHSA-2jpc-hvvc-26mm/GHSA-2jpc-hvvc-26mm.json +++ b/advisories/unreviewed/2022/04/GHSA-2jpc-hvvc-26mm/GHSA-2jpc-hvvc-26mm.json @@ -7,12 +7,8 @@ "CVE-2002-1094" ], "details": "Information leaks in Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.5.4 allow remote attackers to obtain potentially sensitive information via the (1) SSH banner, (2) FTP banner, or (3) an incorrect HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2pqf-f6j5-7m26/GHSA-2pqf-f6j5-7m26.json b/advisories/unreviewed/2022/04/GHSA-2pqf-f6j5-7m26/GHSA-2pqf-f6j5-7m26.json index 1ab1912a254..a535d23317b 100644 --- a/advisories/unreviewed/2022/04/GHSA-2pqf-f6j5-7m26/GHSA-2pqf-f6j5-7m26.json +++ b/advisories/unreviewed/2022/04/GHSA-2pqf-f6j5-7m26/GHSA-2pqf-f6j5-7m26.json @@ -7,12 +7,8 @@ "CVE-2002-0930" ], "details": "Format string vulnerability in the FTP server for Novell Netware 6.0 SP1 (NWFTPD) allows remote attackers to cause a denial of service (ABEND) via format strings in the USER command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2qfv-hf75-cqrh/GHSA-2qfv-hf75-cqrh.json b/advisories/unreviewed/2022/04/GHSA-2qfv-hf75-cqrh/GHSA-2qfv-hf75-cqrh.json index bc2c09ea74d..2242a158e6a 100644 --- a/advisories/unreviewed/2022/04/GHSA-2qfv-hf75-cqrh/GHSA-2qfv-hf75-cqrh.json +++ b/advisories/unreviewed/2022/04/GHSA-2qfv-hf75-cqrh/GHSA-2qfv-hf75-cqrh.json @@ -7,12 +7,8 @@ "CVE-2002-1049" ], "details": "Format string vulnerability in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service (crash) via the TSI data element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2r2c-grqr-jcvc/GHSA-2r2c-grqr-jcvc.json b/advisories/unreviewed/2022/04/GHSA-2r2c-grqr-jcvc/GHSA-2r2c-grqr-jcvc.json index e16b82349a7..331df625768 100644 --- a/advisories/unreviewed/2022/04/GHSA-2r2c-grqr-jcvc/GHSA-2r2c-grqr-jcvc.json +++ b/advisories/unreviewed/2022/04/GHSA-2r2c-grqr-jcvc/GHSA-2r2c-grqr-jcvc.json @@ -7,12 +7,8 @@ "CVE-2002-1296" ], "details": "Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via \"..\" sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2rcj-xpff-488p/GHSA-2rcj-xpff-488p.json b/advisories/unreviewed/2022/04/GHSA-2rcj-xpff-488p/GHSA-2rcj-xpff-488p.json index c25a36523cd..8f2782f1cd4 100644 --- a/advisories/unreviewed/2022/04/GHSA-2rcj-xpff-488p/GHSA-2rcj-xpff-488p.json +++ b/advisories/unreviewed/2022/04/GHSA-2rcj-xpff-488p/GHSA-2rcj-xpff-488p.json @@ -7,12 +7,8 @@ "CVE-2002-0950" ], "details": "Cross-site scripting vulnerability in TransWARE Active! mail 1.422 and 2.0 allows remote attackers to execute arbitrary code via a certain e-mail header, which is not properly filtered.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2rjx-xh92-v9vw/GHSA-2rjx-xh92-v9vw.json b/advisories/unreviewed/2022/04/GHSA-2rjx-xh92-v9vw/GHSA-2rjx-xh92-v9vw.json index ba6f0d93d16..27ce3678db7 100644 --- a/advisories/unreviewed/2022/04/GHSA-2rjx-xh92-v9vw/GHSA-2rjx-xh92-v9vw.json +++ b/advisories/unreviewed/2022/04/GHSA-2rjx-xh92-v9vw/GHSA-2rjx-xh92-v9vw.json @@ -7,12 +7,8 @@ "CVE-2002-1097" ], "details": "Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2v3g-7257-hfv5/GHSA-2v3g-7257-hfv5.json b/advisories/unreviewed/2022/04/GHSA-2v3g-7257-hfv5/GHSA-2v3g-7257-hfv5.json index 54b46c39336..c9ee5e41007 100644 --- a/advisories/unreviewed/2022/04/GHSA-2v3g-7257-hfv5/GHSA-2v3g-7257-hfv5.json +++ b/advisories/unreviewed/2022/04/GHSA-2v3g-7257-hfv5/GHSA-2v3g-7257-hfv5.json @@ -7,12 +7,8 @@ "CVE-2002-1188" ], "details": "Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka \"Temporary Internet Files folders Name Reading.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2wfw-9jvf-2687/GHSA-2wfw-9jvf-2687.json b/advisories/unreviewed/2022/04/GHSA-2wfw-9jvf-2687/GHSA-2wfw-9jvf-2687.json index 5b128a26955..2beb24a1696 100644 --- a/advisories/unreviewed/2022/04/GHSA-2wfw-9jvf-2687/GHSA-2wfw-9jvf-2687.json +++ b/advisories/unreviewed/2022/04/GHSA-2wfw-9jvf-2687/GHSA-2wfw-9jvf-2687.json @@ -7,12 +7,8 @@ "CVE-2002-1354" ], "details": "Directory traversal vulnerability in TYPSoft FTP Server 0.99.8 allows local users to list the contents of arbitrary directories via a ... (dot dot dot) in the cd/CWD command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2x63-j65f-cq7x/GHSA-2x63-j65f-cq7x.json b/advisories/unreviewed/2022/04/GHSA-2x63-j65f-cq7x/GHSA-2x63-j65f-cq7x.json index 3da2a00ea8c..835d61c7077 100644 --- a/advisories/unreviewed/2022/04/GHSA-2x63-j65f-cq7x/GHSA-2x63-j65f-cq7x.json +++ b/advisories/unreviewed/2022/04/GHSA-2x63-j65f-cq7x/GHSA-2x63-j65f-cq7x.json @@ -7,12 +7,8 @@ "CVE-2002-0954" ], "details": "The encryption algorithms for enable and passwd commands on Cisco PIX Firewall can be executed quickly due to a limited number of rounds, which make it easier for an attacker to decrypt the passwords using brute force techniques.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2xh5-hg2x-chwv/GHSA-2xh5-hg2x-chwv.json b/advisories/unreviewed/2022/04/GHSA-2xh5-hg2x-chwv/GHSA-2xh5-hg2x-chwv.json index 975d03440d9..2864501e3ed 100644 --- a/advisories/unreviewed/2022/04/GHSA-2xh5-hg2x-chwv/GHSA-2xh5-hg2x-chwv.json +++ b/advisories/unreviewed/2022/04/GHSA-2xh5-hg2x-chwv/GHSA-2xh5-hg2x-chwv.json @@ -7,12 +7,8 @@ "CVE-2002-1182" ], "details": "IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-32rp-cfpc-888v/GHSA-32rp-cfpc-888v.json b/advisories/unreviewed/2022/04/GHSA-32rp-cfpc-888v/GHSA-32rp-cfpc-888v.json index 0846f2e7114..a6e612f4bc2 100644 --- a/advisories/unreviewed/2022/04/GHSA-32rp-cfpc-888v/GHSA-32rp-cfpc-888v.json +++ b/advisories/unreviewed/2022/04/GHSA-32rp-cfpc-888v/GHSA-32rp-cfpc-888v.json @@ -7,12 +7,8 @@ "CVE-2002-1070" ], "details": "Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-33hc-jm79-92r9/GHSA-33hc-jm79-92r9.json b/advisories/unreviewed/2022/04/GHSA-33hc-jm79-92r9/GHSA-33hc-jm79-92r9.json index 51a93153c64..99d44cd8d74 100644 --- a/advisories/unreviewed/2022/04/GHSA-33hc-jm79-92r9/GHSA-33hc-jm79-92r9.json +++ b/advisories/unreviewed/2022/04/GHSA-33hc-jm79-92r9/GHSA-33hc-jm79-92r9.json @@ -7,12 +7,8 @@ "CVE-2002-1175" ], "details": "The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a malicious DNS server, which allows remote attackers to cause a denial of service (crash) when Fetchmail attempts to read data beyond the expected boundary.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-35x5-g32v-j75x/GHSA-35x5-g32v-j75x.json b/advisories/unreviewed/2022/04/GHSA-35x5-g32v-j75x/GHSA-35x5-g32v-j75x.json index ea78f506a10..50dc6d9a30b 100644 --- a/advisories/unreviewed/2022/04/GHSA-35x5-g32v-j75x/GHSA-35x5-g32v-j75x.json +++ b/advisories/unreviewed/2022/04/GHSA-35x5-g32v-j75x/GHSA-35x5-g32v-j75x.json @@ -7,12 +7,8 @@ "CVE-2002-1222" ], "details": "Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-36qm-778g-vmx5/GHSA-36qm-778g-vmx5.json b/advisories/unreviewed/2022/04/GHSA-36qm-778g-vmx5/GHSA-36qm-778g-vmx5.json index e880d40dd6e..47c925f8cad 100644 --- a/advisories/unreviewed/2022/04/GHSA-36qm-778g-vmx5/GHSA-36qm-778g-vmx5.json +++ b/advisories/unreviewed/2022/04/GHSA-36qm-778g-vmx5/GHSA-36qm-778g-vmx5.json @@ -7,12 +7,8 @@ "CVE-2002-0958" ], "details": "Cross-site scripting vulnerability in browse.php for PHP(Reactor) 1.2.7 allows remote attackers to execute script as other users via the go parameter in the comments section.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-37hc-xgcp-m6w2/GHSA-37hc-xgcp-m6w2.json b/advisories/unreviewed/2022/04/GHSA-37hc-xgcp-m6w2/GHSA-37hc-xgcp-m6w2.json index 2998da3d337..380075b8efc 100644 --- a/advisories/unreviewed/2022/04/GHSA-37hc-xgcp-m6w2/GHSA-37hc-xgcp-m6w2.json +++ b/advisories/unreviewed/2022/04/GHSA-37hc-xgcp-m6w2/GHSA-37hc-xgcp-m6w2.json @@ -7,12 +7,8 @@ "CVE-2002-1079" ], "details": "Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\\ (dot-dot backslash) sequences in an HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-37hr-rhw9-q43g/GHSA-37hr-rhw9-q43g.json b/advisories/unreviewed/2022/04/GHSA-37hr-rhw9-q43g/GHSA-37hr-rhw9-q43g.json index 7c2b5fb0148..59bcf989340 100644 --- a/advisories/unreviewed/2022/04/GHSA-37hr-rhw9-q43g/GHSA-37hr-rhw9-q43g.json +++ b/advisories/unreviewed/2022/04/GHSA-37hr-rhw9-q43g/GHSA-37hr-rhw9-q43g.json @@ -7,12 +7,8 @@ "CVE-2002-1051" ], "details": "Format string vulnerability in TrACESroute 6.0 GOLD (aka NANOG traceroute) allows local users to execute arbitrary code via the -T (terminator) command line argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-396q-87hm-3pmr/GHSA-396q-87hm-3pmr.json b/advisories/unreviewed/2022/04/GHSA-396q-87hm-3pmr/GHSA-396q-87hm-3pmr.json index ab02a52d16d..89e45da508b 100644 --- a/advisories/unreviewed/2022/04/GHSA-396q-87hm-3pmr/GHSA-396q-87hm-3pmr.json +++ b/advisories/unreviewed/2022/04/GHSA-396q-87hm-3pmr/GHSA-396q-87hm-3pmr.json @@ -7,12 +7,8 @@ "CVE-2002-1184" ], "details": "The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-39pv-3mw4-29pm/GHSA-39pv-3mw4-29pm.json b/advisories/unreviewed/2022/04/GHSA-39pv-3mw4-29pm/GHSA-39pv-3mw4-29pm.json index 37984103454..89c07389e16 100644 --- a/advisories/unreviewed/2022/04/GHSA-39pv-3mw4-29pm/GHSA-39pv-3mw4-29pm.json +++ b/advisories/unreviewed/2022/04/GHSA-39pv-3mw4-29pm/GHSA-39pv-3mw4-29pm.json @@ -7,12 +7,8 @@ "CVE-2002-1072" ], "details": "ZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized, fragmented \"jolt\" style ICMP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3c6p-m5wm-96c3/GHSA-3c6p-m5wm-96c3.json b/advisories/unreviewed/2022/04/GHSA-3c6p-m5wm-96c3/GHSA-3c6p-m5wm-96c3.json index 8bc64c3d59c..2c21042fc8f 100644 --- a/advisories/unreviewed/2022/04/GHSA-3c6p-m5wm-96c3/GHSA-3c6p-m5wm-96c3.json +++ b/advisories/unreviewed/2022/04/GHSA-3c6p-m5wm-96c3/GHSA-3c6p-m5wm-96c3.json @@ -7,12 +7,8 @@ "CVE-2002-1139" ], "details": "The Compressed Folders feature in Microsoft Windows 98 with Plus! Pack, Windows Me, and Windows XP does not properly check the destination folder during the decompression of ZIP files, which allows attackers to place an executable file in a known location on a user's system, aka \"Incorrect Target Path for Zipped File Decompression.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3cqw-4qwf-ghv9/GHSA-3cqw-4qwf-ghv9.json b/advisories/unreviewed/2022/04/GHSA-3cqw-4qwf-ghv9/GHSA-3cqw-4qwf-ghv9.json index 0b68f857427..3f7c51b8ffd 100644 --- a/advisories/unreviewed/2022/04/GHSA-3cqw-4qwf-ghv9/GHSA-3cqw-4qwf-ghv9.json +++ b/advisories/unreviewed/2022/04/GHSA-3cqw-4qwf-ghv9/GHSA-3cqw-4qwf-ghv9.json @@ -7,12 +7,8 @@ "CVE-2002-1293" ], "details": "The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com.ms.vm.loader.CabCracker), which allows remote attackers to bypass the security checks that are performed by the load() method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3g7x-qmj2-jxwp/GHSA-3g7x-qmj2-jxwp.json b/advisories/unreviewed/2022/04/GHSA-3g7x-qmj2-jxwp/GHSA-3g7x-qmj2-jxwp.json index 332d1c90779..6524423c2bd 100644 --- a/advisories/unreviewed/2022/04/GHSA-3g7x-qmj2-jxwp/GHSA-3g7x-qmj2-jxwp.json +++ b/advisories/unreviewed/2022/04/GHSA-3g7x-qmj2-jxwp/GHSA-3g7x-qmj2-jxwp.json @@ -7,12 +7,8 @@ "CVE-2002-1176" ], "details": "Buffer overflow in Winamp 2.81 allows remote attackers to execute arbitrary code via a long Artist ID3v2 tag in an MP3 file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3g8f-84mq-ghvw/GHSA-3g8f-84mq-ghvw.json b/advisories/unreviewed/2022/04/GHSA-3g8f-84mq-ghvw/GHSA-3g8f-84mq-ghvw.json index 346afee66e6..94ebfd0355c 100644 --- a/advisories/unreviewed/2022/04/GHSA-3g8f-84mq-ghvw/GHSA-3g8f-84mq-ghvw.json +++ b/advisories/unreviewed/2022/04/GHSA-3g8f-84mq-ghvw/GHSA-3g8f-84mq-ghvw.json @@ -7,12 +7,8 @@ "CVE-2002-1377" ], "details": "vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed when vim is used to edit a malicious file, as demonstrated using mutt.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3mpp-xh9p-vf59/GHSA-3mpp-xh9p-vf59.json b/advisories/unreviewed/2022/04/GHSA-3mpp-xh9p-vf59/GHSA-3mpp-xh9p-vf59.json index 5d2fa671c1a..a5e3c6935a5 100644 --- a/advisories/unreviewed/2022/04/GHSA-3mpp-xh9p-vf59/GHSA-3mpp-xh9p-vf59.json +++ b/advisories/unreviewed/2022/04/GHSA-3mpp-xh9p-vf59/GHSA-3mpp-xh9p-vf59.json @@ -7,12 +7,8 @@ "CVE-2002-1101" ], "details": "Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3pfq-9fq5-mfj5/GHSA-3pfq-9fq5-mfj5.json b/advisories/unreviewed/2022/04/GHSA-3pfq-9fq5-mfj5/GHSA-3pfq-9fq5-mfj5.json index f1b6cede0fb..c4c4897b145 100644 --- a/advisories/unreviewed/2022/04/GHSA-3pfq-9fq5-mfj5/GHSA-3pfq-9fq5-mfj5.json +++ b/advisories/unreviewed/2022/04/GHSA-3pfq-9fq5-mfj5/GHSA-3pfq-9fq5-mfj5.json @@ -7,12 +7,8 @@ "CVE-2002-0934" ], "details": "Directory traversal vulnerability in Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) allows remote attackers to read or modify arbitrary files via an illegal character in the middle of a .. (dot dot) sequence in the parameters (1) _browser_out or (2) _out_file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3qpv-3xc9-766w/GHSA-3qpv-3xc9-766w.json b/advisories/unreviewed/2022/04/GHSA-3qpv-3xc9-766w/GHSA-3qpv-3xc9-766w.json index e961f60f1aa..14087373152 100644 --- a/advisories/unreviewed/2022/04/GHSA-3qpv-3xc9-766w/GHSA-3qpv-3xc9-766w.json +++ b/advisories/unreviewed/2022/04/GHSA-3qpv-3xc9-766w/GHSA-3qpv-3xc9-766w.json @@ -7,12 +7,8 @@ "CVE-2002-1156" ], "details": "Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3rm9-cf6f-q696/GHSA-3rm9-cf6f-q696.json b/advisories/unreviewed/2022/04/GHSA-3rm9-cf6f-q696/GHSA-3rm9-cf6f-q696.json index 2ff6dc81c39..c0132d3c4e9 100644 --- a/advisories/unreviewed/2022/04/GHSA-3rm9-cf6f-q696/GHSA-3rm9-cf6f-q696.json +++ b/advisories/unreviewed/2022/04/GHSA-3rm9-cf6f-q696/GHSA-3rm9-cf6f-q696.json @@ -7,12 +7,8 @@ "CVE-2002-1280" ], "details": "Memory leak in RealSecure Event Collector 6.5 allows attackers to cause a denial of service (memory consumption and crash).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3vxf-84gf-58q9/GHSA-3vxf-84gf-58q9.json b/advisories/unreviewed/2022/04/GHSA-3vxf-84gf-58q9/GHSA-3vxf-84gf-58q9.json index 128141ac9d3..2127eff4686 100644 --- a/advisories/unreviewed/2022/04/GHSA-3vxf-84gf-58q9/GHSA-3vxf-84gf-58q9.json +++ b/advisories/unreviewed/2022/04/GHSA-3vxf-84gf-58q9/GHSA-3vxf-84gf-58q9.json @@ -7,12 +7,8 @@ "CVE-2002-1339" ], "details": "The \"XMLURL\" property in the Spreadsheet component of Office Web Components (OWC) 10 follows redirections, which allows remote attackers to determine the existence of local files based on exceptions, or to read WorkSheet XML files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3x48-6948-gjj7/GHSA-3x48-6948-gjj7.json b/advisories/unreviewed/2022/04/GHSA-3x48-6948-gjj7/GHSA-3x48-6948-gjj7.json index 6592985f68d..e2462c310c1 100644 --- a/advisories/unreviewed/2022/04/GHSA-3x48-6948-gjj7/GHSA-3x48-6948-gjj7.json +++ b/advisories/unreviewed/2022/04/GHSA-3x48-6948-gjj7/GHSA-3x48-6948-gjj7.json @@ -7,12 +7,8 @@ "CVE-2002-1138" ], "details": "Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka \"Flaw in Output File Handling for Scheduled Jobs.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-42fg-866w-8hxj/GHSA-42fg-866w-8hxj.json b/advisories/unreviewed/2022/04/GHSA-42fg-866w-8hxj/GHSA-42fg-866w-8hxj.json index 233e9421e85..0a6a8b22a23 100644 --- a/advisories/unreviewed/2022/04/GHSA-42fg-866w-8hxj/GHSA-42fg-866w-8hxj.json +++ b/advisories/unreviewed/2022/04/GHSA-42fg-866w-8hxj/GHSA-42fg-866w-8hxj.json @@ -7,12 +7,8 @@ "CVE-2002-1179" ], "details": "Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long \"From\" address, which triggers the overflow when the user views or previews the message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-42vq-2xjj-6g8w/GHSA-42vq-2xjj-6g8w.json b/advisories/unreviewed/2022/04/GHSA-42vq-2xjj-6g8w/GHSA-42vq-2xjj-6g8w.json index efd97d6fb3d..2a57697f686 100644 --- a/advisories/unreviewed/2022/04/GHSA-42vq-2xjj-6g8w/GHSA-42vq-2xjj-6g8w.json +++ b/advisories/unreviewed/2022/04/GHSA-42vq-2xjj-6g8w/GHSA-42vq-2xjj-6g8w.json @@ -7,12 +7,8 @@ "CVE-2002-1157" ], "details": "Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-42x8-vcr5-wvrc/GHSA-42x8-vcr5-wvrc.json b/advisories/unreviewed/2022/04/GHSA-42x8-vcr5-wvrc/GHSA-42x8-vcr5-wvrc.json index ff36c89cf36..178a76a2a75 100644 --- a/advisories/unreviewed/2022/04/GHSA-42x8-vcr5-wvrc/GHSA-42x8-vcr5-wvrc.json +++ b/advisories/unreviewed/2022/04/GHSA-42x8-vcr5-wvrc/GHSA-42x8-vcr5-wvrc.json @@ -7,12 +7,8 @@ "CVE-2002-0925" ], "details": "Format string vulnerability in mmsyslog function allows remote attackers to execute arbitrary code via (1) the USER command to mmpop3d for mmmail 0.0.13 and earlier, (2) the HELO command to mmsmtpd for mmmail 0.0.13 and earlier, or (3) the USER command to mmftpd 0.0.7 and earlier.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4395-98rh-2625/GHSA-4395-98rh-2625.json b/advisories/unreviewed/2022/04/GHSA-4395-98rh-2625/GHSA-4395-98rh-2625.json index f27203bbd32..9863978ec7d 100644 --- a/advisories/unreviewed/2022/04/GHSA-4395-98rh-2625/GHSA-4395-98rh-2625.json +++ b/advisories/unreviewed/2022/04/GHSA-4395-98rh-2625/GHSA-4395-98rh-2625.json @@ -7,12 +7,8 @@ "CVE-2002-1387" ], "details": "The spray mode in traceroute-nanog (aka traceroute-ng) may allow local users to overwrite arbitrary memory locations via an array index overflow using the nprobes (number of probes) argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-44gh-mpm8-5jhq/GHSA-44gh-mpm8-5jhq.json b/advisories/unreviewed/2022/04/GHSA-44gh-mpm8-5jhq/GHSA-44gh-mpm8-5jhq.json index de1c0b4ee04..bc8b3fcfcd7 100644 --- a/advisories/unreviewed/2022/04/GHSA-44gh-mpm8-5jhq/GHSA-44gh-mpm8-5jhq.json +++ b/advisories/unreviewed/2022/04/GHSA-44gh-mpm8-5jhq/GHSA-44gh-mpm8-5jhq.json @@ -7,12 +7,8 @@ "CVE-2002-1358" ], "details": "Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-468j-gfpv-g4hr/GHSA-468j-gfpv-g4hr.json b/advisories/unreviewed/2022/04/GHSA-468j-gfpv-g4hr/GHSA-468j-gfpv-g4hr.json index 9685682ecdb..4812f896fd6 100644 --- a/advisories/unreviewed/2022/04/GHSA-468j-gfpv-g4hr/GHSA-468j-gfpv-g4hr.json +++ b/advisories/unreviewed/2022/04/GHSA-468j-gfpv-g4hr/GHSA-468j-gfpv-g4hr.json @@ -7,12 +7,8 @@ "CVE-2002-1090" ], "details": "Buffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 allows a remote SMTP server to (1) execute arbitrary code via a certain response or (2) cause a denial of service via long server responses.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-46p7-9x6f-9v2j/GHSA-46p7-9x6f-9v2j.json b/advisories/unreviewed/2022/04/GHSA-46p7-9x6f-9v2j/GHSA-46p7-9x6f-9v2j.json index a807186be7b..3d03af971e1 100644 --- a/advisories/unreviewed/2022/04/GHSA-46p7-9x6f-9v2j/GHSA-46p7-9x6f-9v2j.json +++ b/advisories/unreviewed/2022/04/GHSA-46p7-9x6f-9v2j/GHSA-46p7-9x6f-9v2j.json @@ -7,12 +7,8 @@ "CVE-2002-1236" ], "details": "The remote management web server for Linksys BEFSR41 EtherFast Cable/DSL Router before firmware 1.42.7 allows remote attackers to cause a denial of service (crash) via an HTTP request to Gozila.cgi without any arguments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-477w-g2w2-h4mg/GHSA-477w-g2w2-h4mg.json b/advisories/unreviewed/2022/04/GHSA-477w-g2w2-h4mg/GHSA-477w-g2w2-h4mg.json index 65f670ea244..758e0042183 100644 --- a/advisories/unreviewed/2022/04/GHSA-477w-g2w2-h4mg/GHSA-477w-g2w2-h4mg.json +++ b/advisories/unreviewed/2022/04/GHSA-477w-g2w2-h4mg/GHSA-477w-g2w2-h4mg.json @@ -7,12 +7,8 @@ "CVE-2002-1353" ], "details": "LocalWEB2000 HTTP server 2.1.0 stores passwords in plain text under the web document root in users.lst, which allows remote attackers to obtain the passwords via a direct request to users.lst.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-48m5-rj8r-v57w/GHSA-48m5-rj8r-v57w.json b/advisories/unreviewed/2022/04/GHSA-48m5-rj8r-v57w/GHSA-48m5-rj8r-v57w.json index b9d226727cd..ddba51e95dd 100644 --- a/advisories/unreviewed/2022/04/GHSA-48m5-rj8r-v57w/GHSA-48m5-rj8r-v57w.json +++ b/advisories/unreviewed/2022/04/GHSA-48m5-rj8r-v57w/GHSA-48m5-rj8r-v57w.json @@ -7,12 +7,8 @@ "CVE-2002-1230" ], "details": "NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem via \"shatter\" style attack by sending a WM_COPYDATA message followed by a WM_TIMER message, as demonstrated by GetAd, aka \"Flaw in Windows WM_TIMER Message Handling Could Enable Privilege Elevation.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4ghg-jxgx-f5gm/GHSA-4ghg-jxgx-f5gm.json b/advisories/unreviewed/2022/04/GHSA-4ghg-jxgx-f5gm/GHSA-4ghg-jxgx-f5gm.json index 89af1157448..4e4597c8947 100644 --- a/advisories/unreviewed/2022/04/GHSA-4ghg-jxgx-f5gm/GHSA-4ghg-jxgx-f5gm.json +++ b/advisories/unreviewed/2022/04/GHSA-4ghg-jxgx-f5gm/GHSA-4ghg-jxgx-f5gm.json @@ -7,12 +7,8 @@ "CVE-2002-1307" ], "details": "Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML via an email message with the script in a MIME header name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4grx-q9r6-m7hw/GHSA-4grx-q9r6-m7hw.json b/advisories/unreviewed/2022/04/GHSA-4grx-q9r6-m7hw/GHSA-4grx-q9r6-m7hw.json index bff139328a0..8e0856fad9d 100644 --- a/advisories/unreviewed/2022/04/GHSA-4grx-q9r6-m7hw/GHSA-4grx-q9r6-m7hw.json +++ b/advisories/unreviewed/2022/04/GHSA-4grx-q9r6-m7hw/GHSA-4grx-q9r6-m7hw.json @@ -7,12 +7,8 @@ "CVE-2002-1081" ], "details": "The Administration console for Abyss Web Server 1.0.3 allows remote attackers to read files without providing login credentials via an HTTP request to a target file that ends in a \"+\" character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4h7v-2vgp-qh2w/GHSA-4h7v-2vgp-qh2w.json b/advisories/unreviewed/2022/04/GHSA-4h7v-2vgp-qh2w/GHSA-4h7v-2vgp-qh2w.json index 2fd958bf29b..bf50043e0d1 100644 --- a/advisories/unreviewed/2022/04/GHSA-4h7v-2vgp-qh2w/GHSA-4h7v-2vgp-qh2w.json +++ b/advisories/unreviewed/2022/04/GHSA-4h7v-2vgp-qh2w/GHSA-4h7v-2vgp-qh2w.json @@ -7,12 +7,8 @@ "CVE-2002-1360" ], "details": "Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4h92-xm55-vg77/GHSA-4h92-xm55-vg77.json b/advisories/unreviewed/2022/04/GHSA-4h92-xm55-vg77/GHSA-4h92-xm55-vg77.json index 3f578c13b52..0d4894f71cf 100644 --- a/advisories/unreviewed/2022/04/GHSA-4h92-xm55-vg77/GHSA-4h92-xm55-vg77.json +++ b/advisories/unreviewed/2022/04/GHSA-4h92-xm55-vg77/GHSA-4h92-xm55-vg77.json @@ -7,12 +7,8 @@ "CVE-2002-1118" ], "details": "TNS Listener in Oracle Net Services for Oracle 9i 9.2.x and 9.0.x, and Oracle 8i 8.1.x, allows remote attackers to cause a denial of service (hang or crash) via a SERVICE_CURLOAD command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4j38-r6gm-8xqf/GHSA-4j38-r6gm-8xqf.json b/advisories/unreviewed/2022/04/GHSA-4j38-r6gm-8xqf/GHSA-4j38-r6gm-8xqf.json index 3a554de7711..3da6523d121 100644 --- a/advisories/unreviewed/2022/04/GHSA-4j38-r6gm-8xqf/GHSA-4j38-r6gm-8xqf.json +++ b/advisories/unreviewed/2022/04/GHSA-4j38-r6gm-8xqf/GHSA-4j38-r6gm-8xqf.json @@ -7,12 +7,8 @@ "CVE-2002-1117" ], "details": "Veritas Backup Exec 8.5 and earlier requires that the \"RestrictAnonymous\" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4jf6-93vm-4232/GHSA-4jf6-93vm-4232.json b/advisories/unreviewed/2022/04/GHSA-4jf6-93vm-4232/GHSA-4jf6-93vm-4232.json index 87d5b664071..5a12dbf67ee 100644 --- a/advisories/unreviewed/2022/04/GHSA-4jf6-93vm-4232/GHSA-4jf6-93vm-4232.json +++ b/advisories/unreviewed/2022/04/GHSA-4jf6-93vm-4232/GHSA-4jf6-93vm-4232.json @@ -7,12 +7,8 @@ "CVE-2002-1203" ], "details": "IBM SecureWay Firewall before 4.2.2 performs extra processing before determining that a packet is invalid and dropping it, which allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed TCP packets without any flags set.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4p57-4p6j-fcjj/GHSA-4p57-4p6j-fcjj.json b/advisories/unreviewed/2022/04/GHSA-4p57-4p6j-fcjj/GHSA-4p57-4p6j-fcjj.json index 02767ba3c9f..33c3a8a3871 100644 --- a/advisories/unreviewed/2022/04/GHSA-4p57-4p6j-fcjj/GHSA-4p57-4p6j-fcjj.json +++ b/advisories/unreviewed/2022/04/GHSA-4p57-4p6j-fcjj/GHSA-4p57-4p6j-fcjj.json @@ -7,12 +7,8 @@ "CVE-2002-0948" ], "details": "Scripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute server-side includes (SSI) as the web server, via the (1) Name or (2) Email parameters, which are not properly filtered.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-533f-wwqv-3vxw/GHSA-533f-wwqv-3vxw.json b/advisories/unreviewed/2022/04/GHSA-533f-wwqv-3vxw/GHSA-533f-wwqv-3vxw.json index c61fd3445cc..ecb2faa62e7 100644 --- a/advisories/unreviewed/2022/04/GHSA-533f-wwqv-3vxw/GHSA-533f-wwqv-3vxw.json +++ b/advisories/unreviewed/2022/04/GHSA-533f-wwqv-3vxw/GHSA-533f-wwqv-3vxw.json @@ -7,12 +7,8 @@ "CVE-2002-1128" ], "details": "Buffer overflow in inc mail utility for Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long MH environment variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-54hw-pp59-j3rc/GHSA-54hw-pp59-j3rc.json b/advisories/unreviewed/2022/04/GHSA-54hw-pp59-j3rc/GHSA-54hw-pp59-j3rc.json index 5a659964520..2a16a5d03e9 100644 --- a/advisories/unreviewed/2022/04/GHSA-54hw-pp59-j3rc/GHSA-54hw-pp59-j3rc.json +++ b/advisories/unreviewed/2022/04/GHSA-54hw-pp59-j3rc/GHSA-54hw-pp59-j3rc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-5758-64jw-p45j/GHSA-5758-64jw-p45j.json b/advisories/unreviewed/2022/04/GHSA-5758-64jw-p45j/GHSA-5758-64jw-p45j.json index 682028a5030..0ea67aeab6b 100644 --- a/advisories/unreviewed/2022/04/GHSA-5758-64jw-p45j/GHSA-5758-64jw-p45j.json +++ b/advisories/unreviewed/2022/04/GHSA-5758-64jw-p45j/GHSA-5758-64jw-p45j.json @@ -7,12 +7,8 @@ "CVE-2002-1268" ], "details": "Mac OS X 10.2.2 allows local users to gain privileges via a mounted ISO 9600 CD, aka \"User Privilege Elevation via Mounting an ISO 9600 CD.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-57m8-3xxg-m3v2/GHSA-57m8-3xxg-m3v2.json b/advisories/unreviewed/2022/04/GHSA-57m8-3xxg-m3v2/GHSA-57m8-3xxg-m3v2.json index af58e9c10ce..b76fbb59ca5 100644 --- a/advisories/unreviewed/2022/04/GHSA-57m8-3xxg-m3v2/GHSA-57m8-3xxg-m3v2.json +++ b/advisories/unreviewed/2022/04/GHSA-57m8-3xxg-m3v2/GHSA-57m8-3xxg-m3v2.json @@ -7,12 +7,8 @@ "CVE-2002-1210" ], "details": "Qualcomm Eudora 5.1.1, 5.2, and possibly other versions stores email attachments in a predictable location, which allows remote attackers to read arbitrary files via a link that loads an attachment with malicious script into a frame, which then executes the script in the local browser context.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-583g-5332-v4w5/GHSA-583g-5332-v4w5.json b/advisories/unreviewed/2022/04/GHSA-583g-5332-v4w5/GHSA-583g-5332-v4w5.json index e4f1202c6a3..7b3c20a5431 100644 --- a/advisories/unreviewed/2022/04/GHSA-583g-5332-v4w5/GHSA-583g-5332-v4w5.json +++ b/advisories/unreviewed/2022/04/GHSA-583g-5332-v4w5/GHSA-583g-5332-v4w5.json @@ -7,12 +7,8 @@ "CVE-2002-0931" ], "details": "Cross-site scripting vulnerabilities in MyHelpDesk 20020509, and possibly other versions, allows remote attackers to execute script as other users via a (1) Title or (2) Description when a new ticket is created by a support assistant, via the \"id\" parameter to the index.php script with the (3) tickettime, (4) ticketfiles, or (5) updateticketlog operations, or (6) via the update section when a ticket is edited.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-58rv-83jv-c4fg/GHSA-58rv-83jv-c4fg.json b/advisories/unreviewed/2022/04/GHSA-58rv-83jv-c4fg/GHSA-58rv-83jv-c4fg.json index eabc56d1a00..4e2a59ed933 100644 --- a/advisories/unreviewed/2022/04/GHSA-58rv-83jv-c4fg/GHSA-58rv-83jv-c4fg.json +++ b/advisories/unreviewed/2022/04/GHSA-58rv-83jv-c4fg/GHSA-58rv-83jv-c4fg.json @@ -7,12 +7,8 @@ "CVE-2002-1147" ], "details": "The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remote administration enabled, does not authenticate requests to reset the device, which allows remote attackers to cause a denial of service via a direct request to the device_reset CGI program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5cc9-22f6-38c6/GHSA-5cc9-22f6-38c6.json b/advisories/unreviewed/2022/04/GHSA-5cc9-22f6-38c6/GHSA-5cc9-22f6-38c6.json index efb53cc49ae..f25b97dbccd 100644 --- a/advisories/unreviewed/2022/04/GHSA-5cc9-22f6-38c6/GHSA-5cc9-22f6-38c6.json +++ b/advisories/unreviewed/2022/04/GHSA-5cc9-22f6-38c6/GHSA-5cc9-22f6-38c6.json @@ -7,12 +7,8 @@ "CVE-2002-1245" ], "details": "Maped in LuxMan 0.41 uses the user-provided search path to find and execute the gzip program, which allows local users to modify /dev/mem and gain privileges via a modified PATH environment variable that points to a Trojan horse gzip program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5cm6-6924-hvfr/GHSA-5cm6-6924-hvfr.json b/advisories/unreviewed/2022/04/GHSA-5cm6-6924-hvfr/GHSA-5cm6-6924-hvfr.json index 957de9aa479..0806e27b02b 100644 --- a/advisories/unreviewed/2022/04/GHSA-5cm6-6924-hvfr/GHSA-5cm6-6924-hvfr.json +++ b/advisories/unreviewed/2022/04/GHSA-5cm6-6924-hvfr/GHSA-5cm6-6924-hvfr.json @@ -7,12 +7,8 @@ "CVE-2002-1050" ], "details": "Buffer overflow in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long line of image data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5cxp-435r-p4f2/GHSA-5cxp-435r-p4f2.json b/advisories/unreviewed/2022/04/GHSA-5cxp-435r-p4f2/GHSA-5cxp-435r-p4f2.json index c0764c6da9e..b86ab355144 100644 --- a/advisories/unreviewed/2022/04/GHSA-5cxp-435r-p4f2/GHSA-5cxp-435r-p4f2.json +++ b/advisories/unreviewed/2022/04/GHSA-5cxp-435r-p4f2/GHSA-5cxp-435r-p4f2.json @@ -7,12 +7,8 @@ "CVE-2002-0971" ], "details": "Vulnerability in VNC, TightVNC, and TridiaVNC allows local users to execute arbitrary code as LocalSystem by using the Win32 Messaging System to bypass the VNC GUI and access the \"Add new clients\" dialogue box.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5j2h-hjvf-wxv7/GHSA-5j2h-hjvf-wxv7.json b/advisories/unreviewed/2022/04/GHSA-5j2h-hjvf-wxv7/GHSA-5j2h-hjvf-wxv7.json index 686beb4c8a1..2758cce7484 100644 --- a/advisories/unreviewed/2022/04/GHSA-5j2h-hjvf-wxv7/GHSA-5j2h-hjvf-wxv7.json +++ b/advisories/unreviewed/2022/04/GHSA-5j2h-hjvf-wxv7/GHSA-5j2h-hjvf-wxv7.json @@ -7,12 +7,8 @@ "CVE-2002-0957" ], "details": "The default configuration of BlackICE Agent 3.1.eal and 3.1.ebh has a high tcp.maxconnections setting, which could allow remote attackers to cause a denial of service (memory consumption) via a large number of connections to the BlackICE system that consumes more resources than intended by the user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5j37-qvcv-4rf2/GHSA-5j37-qvcv-4rf2.json b/advisories/unreviewed/2022/04/GHSA-5j37-qvcv-4rf2/GHSA-5j37-qvcv-4rf2.json index 9b9c8d777fd..b5b7d684e69 100644 --- a/advisories/unreviewed/2022/04/GHSA-5j37-qvcv-4rf2/GHSA-5j37-qvcv-4rf2.json +++ b/advisories/unreviewed/2022/04/GHSA-5j37-qvcv-4rf2/GHSA-5j37-qvcv-4rf2.json @@ -7,12 +7,8 @@ "CVE-2002-1170" ], "details": "The handle_var_requests function in snmp_agent.c for the SNMP daemon in the Net-SNMP (formerly ucd-snmp) package 5.0.1 through 5.0.5 allows remote attackers to cause a denial of service (crash) via a NULL dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5jm3-4wj9-623c/GHSA-5jm3-4wj9-623c.json b/advisories/unreviewed/2022/04/GHSA-5jm3-4wj9-623c/GHSA-5jm3-4wj9-623c.json index fc3eba42478..b713e76bf6d 100644 --- a/advisories/unreviewed/2022/04/GHSA-5jm3-4wj9-623c/GHSA-5jm3-4wj9-623c.json +++ b/advisories/unreviewed/2022/04/GHSA-5jm3-4wj9-623c/GHSA-5jm3-4wj9-623c.json @@ -7,12 +7,8 @@ "CVE-2002-1143" ], "details": "Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka \"Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5p5h-r77x-vq6v/GHSA-5p5h-r77x-vq6v.json b/advisories/unreviewed/2022/04/GHSA-5p5h-r77x-vq6v/GHSA-5p5h-r77x-vq6v.json index 8b44efbc380..bdc609bbed3 100644 --- a/advisories/unreviewed/2022/04/GHSA-5p5h-r77x-vq6v/GHSA-5p5h-r77x-vq6v.json +++ b/advisories/unreviewed/2022/04/GHSA-5p5h-r77x-vq6v/GHSA-5p5h-r77x-vq6v.json @@ -7,12 +7,8 @@ "CVE-2002-1211" ], "details": "Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE that points to code stored on a remote server, which is then used in (1) index.php, (2) install.php, or (3) various test_*.php scripts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5r8j-f593-7fqq/GHSA-5r8j-f593-7fqq.json b/advisories/unreviewed/2022/04/GHSA-5r8j-f593-7fqq/GHSA-5r8j-f593-7fqq.json index 55f0a204a2e..890e4ee67f7 100644 --- a/advisories/unreviewed/2022/04/GHSA-5r8j-f593-7fqq/GHSA-5r8j-f593-7fqq.json +++ b/advisories/unreviewed/2022/04/GHSA-5r8j-f593-7fqq/GHSA-5r8j-f593-7fqq.json @@ -7,12 +7,8 @@ "CVE-2002-1223" ], "details": "Buffer overflow in DSC 3.0 parser from GSview, as used in KGhostView in KDE 1.1 and KDE 3.0.3a, may allow attackers to cause a denial of service or execute arbitrary code via a modified .ps (PostScript) input file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5v9x-cwp3-pcqj/GHSA-5v9x-cwp3-pcqj.json b/advisories/unreviewed/2022/04/GHSA-5v9x-cwp3-pcqj/GHSA-5v9x-cwp3-pcqj.json index 3cbccc07f7f..caec5489225 100644 --- a/advisories/unreviewed/2022/04/GHSA-5v9x-cwp3-pcqj/GHSA-5v9x-cwp3-pcqj.json +++ b/advisories/unreviewed/2022/04/GHSA-5v9x-cwp3-pcqj/GHSA-5v9x-cwp3-pcqj.json @@ -7,12 +7,8 @@ "CVE-2002-1058" ], "details": "Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin via .. (dot dot) sequences in the sessionId cookie that point to an alternate session file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5vxf-2qrj-pr33/GHSA-5vxf-2qrj-pr33.json b/advisories/unreviewed/2022/04/GHSA-5vxf-2qrj-pr33/GHSA-5vxf-2qrj-pr33.json index f1cb1dd299e..d8a647c7642 100644 --- a/advisories/unreviewed/2022/04/GHSA-5vxf-2qrj-pr33/GHSA-5vxf-2qrj-pr33.json +++ b/advisories/unreviewed/2022/04/GHSA-5vxf-2qrj-pr33/GHSA-5vxf-2qrj-pr33.json @@ -7,12 +7,8 @@ "CVE-2002-1137" ], "details": "Buffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, allows attackers to execute arbitrary code via a long SourceDB argument in a \"non-SQL OLEDB data source\" such as FoxPro, a variant of CAN-2002-0644.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5wf4-xwv9-52f5/GHSA-5wf4-xwv9-52f5.json b/advisories/unreviewed/2022/04/GHSA-5wf4-xwv9-52f5/GHSA-5wf4-xwv9-52f5.json index 5666d617581..c0f68cb2cfb 100644 --- a/advisories/unreviewed/2022/04/GHSA-5wf4-xwv9-52f5/GHSA-5wf4-xwv9-52f5.json +++ b/advisories/unreviewed/2022/04/GHSA-5wf4-xwv9-52f5/GHSA-5wf4-xwv9-52f5.json @@ -7,12 +7,8 @@ "CVE-2002-1238" ], "details": "Peter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via an HTTP request with a sequence of multiple / (slash) characters such as http://www.example.com///file/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5x6v-v8hw-r85j/GHSA-5x6v-v8hw-r85j.json b/advisories/unreviewed/2022/04/GHSA-5x6v-v8hw-r85j/GHSA-5x6v-v8hw-r85j.json index 3151f3bdd91..b91483250d8 100644 --- a/advisories/unreviewed/2022/04/GHSA-5x6v-v8hw-r85j/GHSA-5x6v-v8hw-r85j.json +++ b/advisories/unreviewed/2022/04/GHSA-5x6v-v8hw-r85j/GHSA-5x6v-v8hw-r85j.json @@ -7,12 +7,8 @@ "CVE-2002-1099" ], "details": "Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to obtain potentially sensitive information without authentication by directly accessing certain HTML pages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-63p4-p8mv-xhx7/GHSA-63p4-p8mv-xhx7.json b/advisories/unreviewed/2022/04/GHSA-63p4-p8mv-xhx7/GHSA-63p4-p8mv-xhx7.json index 4471fedf768..564c17bfa5e 100644 --- a/advisories/unreviewed/2022/04/GHSA-63p4-p8mv-xhx7/GHSA-63p4-p8mv-xhx7.json +++ b/advisories/unreviewed/2022/04/GHSA-63p4-p8mv-xhx7/GHSA-63p4-p8mv-xhx7.json @@ -7,12 +7,8 @@ "CVE-2002-1379" ], "details": "OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads the .ldaprc file within applications that are running with extra privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-63rm-wj2q-ggp8/GHSA-63rm-wj2q-ggp8.json b/advisories/unreviewed/2022/04/GHSA-63rm-wj2q-ggp8/GHSA-63rm-wj2q-ggp8.json index 6a0a1119685..408718bdabf 100644 --- a/advisories/unreviewed/2022/04/GHSA-63rm-wj2q-ggp8/GHSA-63rm-wj2q-ggp8.json +++ b/advisories/unreviewed/2022/04/GHSA-63rm-wj2q-ggp8/GHSA-63rm-wj2q-ggp8.json @@ -7,12 +7,8 @@ "CVE-2002-1285" ], "details": "runlpr in the LPRng package allows the local lp user to gain root privileges via certain command line arguments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-66g3-vg2q-cqjg/GHSA-66g3-vg2q-cqjg.json b/advisories/unreviewed/2022/04/GHSA-66g3-vg2q-cqjg/GHSA-66g3-vg2q-cqjg.json index 7a11a7f8d70..3321b423ed3 100644 --- a/advisories/unreviewed/2022/04/GHSA-66g3-vg2q-cqjg/GHSA-66g3-vg2q-cqjg.json +++ b/advisories/unreviewed/2022/04/GHSA-66g3-vg2q-cqjg/GHSA-66g3-vg2q-cqjg.json @@ -7,12 +7,8 @@ "CVE-2002-1239" ], "details": "QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows local users to gain privileges by modifying the PATH to point to a malicious cp program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-66mj-m7pw-m3fx/GHSA-66mj-m7pw-m3fx.json b/advisories/unreviewed/2022/04/GHSA-66mj-m7pw-m3fx/GHSA-66mj-m7pw-m3fx.json index ecbdd346031..fc8d542cebe 100644 --- a/advisories/unreviewed/2022/04/GHSA-66mj-m7pw-m3fx/GHSA-66mj-m7pw-m3fx.json +++ b/advisories/unreviewed/2022/04/GHSA-66mj-m7pw-m3fx/GHSA-66mj-m7pw-m3fx.json @@ -7,12 +7,8 @@ "CVE-2002-1278" ], "details": "The mailconf module in Linuxconf 1.24, and other versions before 1.28, on Conectiva Linux 6.0 through 8, and possibly other distributions, generates the Sendmail configuration file (sendmail.cf) in a way that configures Sendmail to run as an open mail relay, which allows remote attackers to send Spam email.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6fq3-j78p-69pv/GHSA-6fq3-j78p-69pv.json b/advisories/unreviewed/2022/04/GHSA-6fq3-j78p-69pv/GHSA-6fq3-j78p-69pv.json index 87c42635684..54404718a84 100644 --- a/advisories/unreviewed/2022/04/GHSA-6fq3-j78p-69pv/GHSA-6fq3-j78p-69pv.json +++ b/advisories/unreviewed/2022/04/GHSA-6fq3-j78p-69pv/GHSA-6fq3-j78p-69pv.json @@ -7,12 +7,8 @@ "CVE-2002-1073" ], "details": "Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6g3c-9q4h-j586/GHSA-6g3c-9q4h-j586.json b/advisories/unreviewed/2022/04/GHSA-6g3c-9q4h-j586/GHSA-6g3c-9q4h-j586.json index ea0dd8fe2d4..178be0f6546 100644 --- a/advisories/unreviewed/2022/04/GHSA-6g3c-9q4h-j586/GHSA-6g3c-9q4h-j586.json +++ b/advisories/unreviewed/2022/04/GHSA-6g3c-9q4h-j586/GHSA-6g3c-9q4h-j586.json @@ -7,12 +7,8 @@ "CVE-2002-1053" ], "details": "Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a URL that contains a reference to a nonexistent host followed by the script, which is included in the resulting error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6gm6-fh7w-6j3g/GHSA-6gm6-fh7w-6j3g.json b/advisories/unreviewed/2022/04/GHSA-6gm6-fh7w-6j3g/GHSA-6gm6-fh7w-6j3g.json index 7e3bb2a65cb..4e3410d2fcc 100644 --- a/advisories/unreviewed/2022/04/GHSA-6gm6-fh7w-6j3g/GHSA-6gm6-fh7w-6j3g.json +++ b/advisories/unreviewed/2022/04/GHSA-6gm6-fh7w-6j3g/GHSA-6gm6-fh7w-6j3g.json @@ -7,12 +7,8 @@ "CVE-2002-1113" ], "details": "summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_path parameter to reference the location of the PHP code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6j9f-c956-rhqf/GHSA-6j9f-c956-rhqf.json b/advisories/unreviewed/2022/04/GHSA-6j9f-c956-rhqf/GHSA-6j9f-c956-rhqf.json index 43c64e59b8b..87ccec4fdc6 100644 --- a/advisories/unreviewed/2022/04/GHSA-6j9f-c956-rhqf/GHSA-6j9f-c956-rhqf.json +++ b/advisories/unreviewed/2022/04/GHSA-6j9f-c956-rhqf/GHSA-6j9f-c956-rhqf.json @@ -7,12 +7,8 @@ "CVE-2002-1315" ], "details": "Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6pjp-9q5v-gp94/GHSA-6pjp-9q5v-gp94.json b/advisories/unreviewed/2022/04/GHSA-6pjp-9q5v-gp94/GHSA-6pjp-9q5v-gp94.json index 9c3164b36a8..4f510a1bb36 100644 --- a/advisories/unreviewed/2022/04/GHSA-6pjp-9q5v-gp94/GHSA-6pjp-9q5v-gp94.json +++ b/advisories/unreviewed/2022/04/GHSA-6pjp-9q5v-gp94/GHSA-6pjp-9q5v-gp94.json @@ -7,12 +7,8 @@ "CVE-2002-1047" ], "details": "The FTP service in Watchguard Soho Firewall 5.0.35a allows remote attackers to gain privileges with a correct password but an incorrect user name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6q7q-pxq9-gvhp/GHSA-6q7q-pxq9-gvhp.json b/advisories/unreviewed/2022/04/GHSA-6q7q-pxq9-gvhp/GHSA-6q7q-pxq9-gvhp.json index dc112d2c7c4..5ecfc164187 100644 --- a/advisories/unreviewed/2022/04/GHSA-6q7q-pxq9-gvhp/GHSA-6q7q-pxq9-gvhp.json +++ b/advisories/unreviewed/2022/04/GHSA-6q7q-pxq9-gvhp/GHSA-6q7q-pxq9-gvhp.json @@ -7,12 +7,8 @@ "CVE-2002-1369" ], "details": "jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attackers to execute arbitrary code via a buffer overflow attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6qgf-gfj4-gj5c/GHSA-6qgf-gfj4-gj5c.json b/advisories/unreviewed/2022/04/GHSA-6qgf-gfj4-gj5c/GHSA-6qgf-gfj4-gj5c.json index 8a47e2c6aae..634aa63370c 100644 --- a/advisories/unreviewed/2022/04/GHSA-6qgf-gfj4-gj5c/GHSA-6qgf-gfj4-gj5c.json +++ b/advisories/unreviewed/2022/04/GHSA-6qgf-gfj4-gj5c/GHSA-6qgf-gfj4-gj5c.json @@ -7,12 +7,8 @@ "CVE-2002-1221" ], "details": "BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6vrr-4rgh-cr8p/GHSA-6vrr-4rgh-cr8p.json b/advisories/unreviewed/2022/04/GHSA-6vrr-4rgh-cr8p/GHSA-6vrr-4rgh-cr8p.json index 9767df3594a..16ac74f55ea 100644 --- a/advisories/unreviewed/2022/04/GHSA-6vrr-4rgh-cr8p/GHSA-6vrr-4rgh-cr8p.json +++ b/advisories/unreviewed/2022/04/GHSA-6vrr-4rgh-cr8p/GHSA-6vrr-4rgh-cr8p.json @@ -7,12 +7,8 @@ "CVE-2002-1083" ], "details": "Directory traversal vulnerabilities in ezContents 1.41 and earlier allow remote attackers to cause ezContents to (1) create directories using the Maintain Images:Add New:Create Subdirectory item, or (2) list directories using the Maintain Images file listing, via .. (dot dot) sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7633-2p6v-h7c8/GHSA-7633-2p6v-h7c8.json b/advisories/unreviewed/2022/04/GHSA-7633-2p6v-h7c8/GHSA-7633-2p6v-h7c8.json index a4f9ab770c2..9f4a2da1577 100644 --- a/advisories/unreviewed/2022/04/GHSA-7633-2p6v-h7c8/GHSA-7633-2p6v-h7c8.json +++ b/advisories/unreviewed/2022/04/GHSA-7633-2p6v-h7c8/GHSA-7633-2p6v-h7c8.json @@ -7,12 +7,8 @@ "CVE-2002-1286" ], "details": "The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies and execute script in a different security context via a URL that contains a colon in the domain portion, which is not properly parsed and loads an applet from a malicious site within the security context of the site that is being visited by the user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-76mc-v2gg-8554/GHSA-76mc-v2gg-8554.json b/advisories/unreviewed/2022/04/GHSA-76mc-v2gg-8554/GHSA-76mc-v2gg-8554.json index 9dc097c97df..a9a5d014e55 100644 --- a/advisories/unreviewed/2022/04/GHSA-76mc-v2gg-8554/GHSA-76mc-v2gg-8554.json +++ b/advisories/unreviewed/2022/04/GHSA-76mc-v2gg-8554/GHSA-76mc-v2gg-8554.json @@ -7,12 +7,8 @@ "CVE-2002-1124" ], "details": "Multiple buffer overflows in purity 1-16 allow local users to gain privileges and modify high scores tables.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-76w6-94xw-vqgv/GHSA-76w6-94xw-vqgv.json b/advisories/unreviewed/2022/04/GHSA-76w6-94xw-vqgv/GHSA-76w6-94xw-vqgv.json index 2ae2adb2d2c..68ab4ffd353 100644 --- a/advisories/unreviewed/2022/04/GHSA-76w6-94xw-vqgv/GHSA-76w6-94xw-vqgv.json +++ b/advisories/unreviewed/2022/04/GHSA-76w6-94xw-vqgv/GHSA-76w6-94xw-vqgv.json @@ -7,12 +7,8 @@ "CVE-2002-1283" ], "details": "Buffer overflow in Novell iManager (eMFrame) before 1.5 allows remote attackers to cause a denial of service via an authentication request with a long Distinguished Name (DN) attribute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7776-85fj-fv28/GHSA-7776-85fj-fv28.json b/advisories/unreviewed/2022/04/GHSA-7776-85fj-fv28/GHSA-7776-85fj-fv28.json index 10489594eb3..46fae3b5826 100644 --- a/advisories/unreviewed/2022/04/GHSA-7776-85fj-fv28/GHSA-7776-85fj-fv28.json +++ b/advisories/unreviewed/2022/04/GHSA-7776-85fj-fv28/GHSA-7776-85fj-fv28.json @@ -7,12 +7,8 @@ "CVE-2002-1378" ], "details": "Multiple buffer overflows in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allow remote attackers to execute arbitrary code via (1) long -t or -r parameters to slurpd, (2) a malicious ldapfilter.conf file that is not properly handled by getfilter functions, (3) a malicious ldaptemplates.conf that causes an overflow in libldap, (4) a certain access control list that causes an overflow in slapd, or (5) a long generated filename for logging rejected replication requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-77px-37x7-938j/GHSA-77px-37x7-938j.json b/advisories/unreviewed/2022/04/GHSA-77px-37x7-938j/GHSA-77px-37x7-938j.json index e9d7638497f..a88ebded728 100644 --- a/advisories/unreviewed/2022/04/GHSA-77px-37x7-938j/GHSA-77px-37x7-938j.json +++ b/advisories/unreviewed/2022/04/GHSA-77px-37x7-938j/GHSA-77px-37x7-938j.json @@ -7,12 +7,8 @@ "CVE-2002-1386" ], "details": "Buffer overflow in traceroute-nanog (aka traceroute-ng) may allow local users to execute arbitrary code via a long hostname argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7gh5-g6w7-v7hq/GHSA-7gh5-g6w7-v7hq.json b/advisories/unreviewed/2022/04/GHSA-7gh5-g6w7-v7hq/GHSA-7gh5-g6w7-v7hq.json index 2f95fd91a7c..4bf4269f786 100644 --- a/advisories/unreviewed/2022/04/GHSA-7gh5-g6w7-v7hq/GHSA-7gh5-g6w7-v7hq.json +++ b/advisories/unreviewed/2022/04/GHSA-7gh5-g6w7-v7hq/GHSA-7gh5-g6w7-v7hq.json @@ -7,12 +7,8 @@ "CVE-2002-1225" ], "details": "Multiple buffer overflows in Heimdal before 0.5, possibly in both the (1) kadmind and (2) kdc servers, may allow remote attackers to gain root access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7gmr-wpjj-v99f/GHSA-7gmr-wpjj-v99f.json b/advisories/unreviewed/2022/04/GHSA-7gmr-wpjj-v99f/GHSA-7gmr-wpjj-v99f.json index 5c1cadd68ed..95e349292f6 100644 --- a/advisories/unreviewed/2022/04/GHSA-7gmr-wpjj-v99f/GHSA-7gmr-wpjj-v99f.json +++ b/advisories/unreviewed/2022/04/GHSA-7gmr-wpjj-v99f/GHSA-7gmr-wpjj-v99f.json @@ -7,12 +7,8 @@ "CVE-2002-1191" ], "details": "The Sabserv client component in Sabre Desktop Reservation Software 4.2 through 4.4 allows remote attackers to cause a denial of service via malformed input to TCP port 1001.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7m69-56cv-963j/GHSA-7m69-56cv-963j.json b/advisories/unreviewed/2022/04/GHSA-7m69-56cv-963j/GHSA-7m69-56cv-963j.json index a7d39119794..ed01d9ff197 100644 --- a/advisories/unreviewed/2022/04/GHSA-7m69-56cv-963j/GHSA-7m69-56cv-963j.json +++ b/advisories/unreviewed/2022/04/GHSA-7m69-56cv-963j/GHSA-7m69-56cv-963j.json @@ -7,12 +7,8 @@ "CVE-2002-1115" ], "details": "Mantis 0.17.4a and earlier allows remote attackers to view private bugs by modifying the f_id bug ID parameter to (1) bug_update_advanced_page.php, (2) bug_update_page.php, (3) view_bug_advanced_page.php, or (4) view_bug_page.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7mfp-q9xp-qq39/GHSA-7mfp-q9xp-qq39.json b/advisories/unreviewed/2022/04/GHSA-7mfp-q9xp-qq39/GHSA-7mfp-q9xp-qq39.json index 8d2f9cf724a..33be455f029 100644 --- a/advisories/unreviewed/2022/04/GHSA-7mfp-q9xp-qq39/GHSA-7mfp-q9xp-qq39.json +++ b/advisories/unreviewed/2022/04/GHSA-7mfp-q9xp-qq39/GHSA-7mfp-q9xp-qq39.json @@ -7,12 +7,8 @@ "CVE-2002-1376" ], "details": "libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routines, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7w4g-93q4-x56p/GHSA-7w4g-93q4-x56p.json b/advisories/unreviewed/2022/04/GHSA-7w4g-93q4-x56p/GHSA-7w4g-93q4-x56p.json index be9ec35d997..80e8be63057 100644 --- a/advisories/unreviewed/2022/04/GHSA-7w4g-93q4-x56p/GHSA-7w4g-93q4-x56p.json +++ b/advisories/unreviewed/2022/04/GHSA-7w4g-93q4-x56p/GHSA-7w4g-93q4-x56p.json @@ -7,12 +7,8 @@ "CVE-2002-1443" ], "details": "The Google toolbar 1.1.58 and earlier allows remote web sites to monitor a user's input into the toolbar via an \"onkeydown\" event handler.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-83vj-f354-6mrp/GHSA-83vj-f354-6mrp.json b/advisories/unreviewed/2022/04/GHSA-83vj-f354-6mrp/GHSA-83vj-f354-6mrp.json index a34808d23c2..7219cf3c3c2 100644 --- a/advisories/unreviewed/2022/04/GHSA-83vj-f354-6mrp/GHSA-83vj-f354-6mrp.json +++ b/advisories/unreviewed/2022/04/GHSA-83vj-f354-6mrp/GHSA-83vj-f354-6mrp.json @@ -7,12 +7,8 @@ "CVE-2002-1289" ], "details": "The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read restricted process memory, cause a denial of service (crash), and possibly execute arbitrary code via the getNativeServices function, which creates an instance of the com.ms.awt.peer.INativeServices (INativeServices) class, whose methods do not verify the memory addresses that are passed as parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-83w9-cgv7-27qx/GHSA-83w9-cgv7-27qx.json b/advisories/unreviewed/2022/04/GHSA-83w9-cgv7-27qx/GHSA-83w9-cgv7-27qx.json index 0930b141600..f234acf52a7 100644 --- a/advisories/unreviewed/2022/04/GHSA-83w9-cgv7-27qx/GHSA-83w9-cgv7-27qx.json +++ b/advisories/unreviewed/2022/04/GHSA-83w9-cgv7-27qx/GHSA-83w9-cgv7-27qx.json @@ -7,12 +7,8 @@ "CVE-2002-1104" ], "details": "Cisco Virtual Private Network (VPN) Client software 2.x.x and 3.x before 3.0.5 allows remote attackers to cause a denial of service (crash) via TCP packets with source and destination ports of 137 (NETBIOS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-84jw-5rpw-29g3/GHSA-84jw-5rpw-29g3.json b/advisories/unreviewed/2022/04/GHSA-84jw-5rpw-29g3/GHSA-84jw-5rpw-29g3.json index 304e3ff8d93..aba15f23eb6 100644 --- a/advisories/unreviewed/2022/04/GHSA-84jw-5rpw-29g3/GHSA-84jw-5rpw-29g3.json +++ b/advisories/unreviewed/2022/04/GHSA-84jw-5rpw-29g3/GHSA-84jw-5rpw-29g3.json @@ -7,12 +7,8 @@ "CVE-2002-1270" ], "details": "Mac OS X 10.2.2 allows local users to read files that only allow write access via the map_fd() Mach system call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-85vx-vq88-55q2/GHSA-85vx-vq88-55q2.json b/advisories/unreviewed/2022/04/GHSA-85vx-vq88-55q2/GHSA-85vx-vq88-55q2.json index 668951e0d08..8f71e402d46 100644 --- a/advisories/unreviewed/2022/04/GHSA-85vx-vq88-55q2/GHSA-85vx-vq88-55q2.json +++ b/advisories/unreviewed/2022/04/GHSA-85vx-vq88-55q2/GHSA-85vx-vq88-55q2.json @@ -7,12 +7,8 @@ "CVE-2002-1158" ], "details": "Buffer overflow in the irw_through function for Canna 3.5b2 and earlier allows local users to execute arbitrary code as the bin user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-86qq-pxxj-cq4f/GHSA-86qq-pxxj-cq4f.json b/advisories/unreviewed/2022/04/GHSA-86qq-pxxj-cq4f/GHSA-86qq-pxxj-cq4f.json index a05009641f2..b338b7d69ff 100644 --- a/advisories/unreviewed/2022/04/GHSA-86qq-pxxj-cq4f/GHSA-86qq-pxxj-cq4f.json +++ b/advisories/unreviewed/2022/04/GHSA-86qq-pxxj-cq4f/GHSA-86qq-pxxj-cq4f.json @@ -7,12 +7,8 @@ "CVE-2002-1177" ], "details": "Multiple buffer overflows in Winamp 3.0, when displaying an MP3 in the Media Library window, allows remote attackers to execute arbitrary code via an MP3 file containing a long (1) Artist or (2) Album ID3v2 tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-88qq-cpf5-5jr8/GHSA-88qq-cpf5-5jr8.json b/advisories/unreviewed/2022/04/GHSA-88qq-cpf5-5jr8/GHSA-88qq-cpf5-5jr8.json index f8d2d3caa26..40032f2eefa 100644 --- a/advisories/unreviewed/2022/04/GHSA-88qq-cpf5-5jr8/GHSA-88qq-cpf5-5jr8.json +++ b/advisories/unreviewed/2022/04/GHSA-88qq-cpf5-5jr8/GHSA-88qq-cpf5-5jr8.json @@ -7,12 +7,8 @@ "CVE-2002-1264" ], "details": "Buffer overflow in Oracle iSQL*Plus web application of the Oracle 9 database server allows remote attackers to execute arbitrary code via a long USERID parameter in the isqlplus URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-89mg-cv67-4w52/GHSA-89mg-cv67-4w52.json b/advisories/unreviewed/2022/04/GHSA-89mg-cv67-4w52/GHSA-89mg-cv67-4w52.json index beb3ddd0490..b1a56d95ffe 100644 --- a/advisories/unreviewed/2022/04/GHSA-89mg-cv67-4w52/GHSA-89mg-cv67-4w52.json +++ b/advisories/unreviewed/2022/04/GHSA-89mg-cv67-4w52/GHSA-89mg-cv67-4w52.json @@ -7,12 +7,8 @@ "CVE-2002-1180" ], "details": "A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka \"Script Source Access Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8cgw-2jw6-65ph/GHSA-8cgw-2jw6-65ph.json b/advisories/unreviewed/2022/04/GHSA-8cgw-2jw6-65ph/GHSA-8cgw-2jw6-65ph.json index 1c667233837..2c4abe32a99 100644 --- a/advisories/unreviewed/2022/04/GHSA-8cgw-2jw6-65ph/GHSA-8cgw-2jw6-65ph.json +++ b/advisories/unreviewed/2022/04/GHSA-8cgw-2jw6-65ph/GHSA-8cgw-2jw6-65ph.json @@ -7,12 +7,8 @@ "CVE-2002-1077" ], "details": "IPSwitch IMail Web Calendaring service (iwebcal) allows remote attackers to cause a denial of service (crash) via an HTTP POST request without a Content-Length field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8f3x-2hfc-r4x5/GHSA-8f3x-2hfc-r4x5.json b/advisories/unreviewed/2022/04/GHSA-8f3x-2hfc-r4x5/GHSA-8f3x-2hfc-r4x5.json index 26d7d39e2ba..7f7af4fb991 100644 --- a/advisories/unreviewed/2022/04/GHSA-8f3x-2hfc-r4x5/GHSA-8f3x-2hfc-r4x5.json +++ b/advisories/unreviewed/2022/04/GHSA-8f3x-2hfc-r4x5/GHSA-8f3x-2hfc-r4x5.json @@ -7,12 +7,8 @@ "CVE-2002-1168" ], "details": "Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a \"%0a%0d\" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8fpj-4vr6-7x7f/GHSA-8fpj-4vr6-7x7f.json b/advisories/unreviewed/2022/04/GHSA-8fpj-4vr6-7x7f/GHSA-8fpj-4vr6-7x7f.json index 1117ee7a818..fbcf1297d21 100644 --- a/advisories/unreviewed/2022/04/GHSA-8fpj-4vr6-7x7f/GHSA-8fpj-4vr6-7x7f.json +++ b/advisories/unreviewed/2022/04/GHSA-8fpj-4vr6-7x7f/GHSA-8fpj-4vr6-7x7f.json @@ -7,12 +7,8 @@ "CVE-2002-1382" ], "details": "Macromedia Flash Player before 6.0.65.0 allows remote attackers to execute arbitrary code via certain malformed data headers in Shockwave Flash file format (SWF) files, a different issue than CAN-2002-0846.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8gp3-9ghw-c8p7/GHSA-8gp3-9ghw-c8p7.json b/advisories/unreviewed/2022/04/GHSA-8gp3-9ghw-c8p7/GHSA-8gp3-9ghw-c8p7.json index dab750f79fe..457215013e2 100644 --- a/advisories/unreviewed/2022/04/GHSA-8gp3-9ghw-c8p7/GHSA-8gp3-9ghw-c8p7.json +++ b/advisories/unreviewed/2022/04/GHSA-8gp3-9ghw-c8p7/GHSA-8gp3-9ghw-c8p7.json @@ -7,12 +7,8 @@ "CVE-2002-0920" ], "details": "CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which could allow local users (and possibly remote attackers) to gain privileges by stealing the file before it has been processed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8mrp-mc3j-4vqv/GHSA-8mrp-mc3j-4vqv.json b/advisories/unreviewed/2022/04/GHSA-8mrp-mc3j-4vqv/GHSA-8mrp-mc3j-4vqv.json index dba08df8060..a5aeee68619 100644 --- a/advisories/unreviewed/2022/04/GHSA-8mrp-mc3j-4vqv/GHSA-8mrp-mc3j-4vqv.json +++ b/advisories/unreviewed/2022/04/GHSA-8mrp-mc3j-4vqv/GHSA-8mrp-mc3j-4vqv.json @@ -7,12 +7,8 @@ "CVE-2002-1121" ], "details": "SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and possibly other products, do not detect fragmented emails as defined in RFC2046 (\"Message Fragmentation and Reassembly\") and supported in such products as Outlook Express, which allows remote attackers to bypass content filtering, including virus checking, via fragmented emails of the message/partial content type.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8p3v-g4jm-c2m8/GHSA-8p3v-g4jm-c2m8.json b/advisories/unreviewed/2022/04/GHSA-8p3v-g4jm-c2m8/GHSA-8p3v-g4jm-c2m8.json index 7e47bdd50e3..d9771e6611a 100644 --- a/advisories/unreviewed/2022/04/GHSA-8p3v-g4jm-c2m8/GHSA-8p3v-g4jm-c2m8.json +++ b/advisories/unreviewed/2022/04/GHSA-8p3v-g4jm-c2m8/GHSA-8p3v-g4jm-c2m8.json @@ -7,12 +7,8 @@ "CVE-2002-1098" ], "details": "Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an \"HTTPS on Public Inbound (XML-Auto)(forward/in)\" rule but sets the protocol to \"ANY\" when the XML filter configuration is enabled, which ultimately allows arbitrary traffic to pass through the concentrator.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8p4f-w37p-53vv/GHSA-8p4f-w37p-53vv.json b/advisories/unreviewed/2022/04/GHSA-8p4f-w37p-53vv/GHSA-8p4f-w37p-53vv.json index 539c72363aa..6261e79b939 100644 --- a/advisories/unreviewed/2022/04/GHSA-8p4f-w37p-53vv/GHSA-8p4f-w37p-53vv.json +++ b/advisories/unreviewed/2022/04/GHSA-8p4f-w37p-53vv/GHSA-8p4f-w37p-53vv.json @@ -7,12 +7,8 @@ "CVE-2002-1228" ], "details": "Unknown vulnerability in NFS on Solaris 2.5.1 through Solaris 9 allows an NFS client to cause a denial of service by killing the lockd daemon.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8rc3-4pw7-pqp3/GHSA-8rc3-4pw7-pqp3.json b/advisories/unreviewed/2022/04/GHSA-8rc3-4pw7-pqp3/GHSA-8rc3-4pw7-pqp3.json index c48b3503f88..b4122e214b1 100644 --- a/advisories/unreviewed/2022/04/GHSA-8rc3-4pw7-pqp3/GHSA-8rc3-4pw7-pqp3.json +++ b/advisories/unreviewed/2022/04/GHSA-8rc3-4pw7-pqp3/GHSA-8rc3-4pw7-pqp3.json @@ -7,12 +7,8 @@ "CVE-2002-1031" ], "details": "KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request containing a %00 (null) character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8v5h-xrqm-qgff/GHSA-8v5h-xrqm-qgff.json b/advisories/unreviewed/2022/04/GHSA-8v5h-xrqm-qgff/GHSA-8v5h-xrqm-qgff.json index fa88f39c339..9513087e683 100644 --- a/advisories/unreviewed/2022/04/GHSA-8v5h-xrqm-qgff/GHSA-8v5h-xrqm-qgff.json +++ b/advisories/unreviewed/2022/04/GHSA-8v5h-xrqm-qgff/GHSA-8v5h-xrqm-qgff.json @@ -7,12 +7,8 @@ "CVE-2002-1076" ], "details": "Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HTTP/1.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8vx7-569q-v8fx/GHSA-8vx7-569q-v8fx.json b/advisories/unreviewed/2022/04/GHSA-8vx7-569q-v8fx/GHSA-8vx7-569q-v8fx.json index de02a61e8e2..bd254144bfa 100644 --- a/advisories/unreviewed/2022/04/GHSA-8vx7-569q-v8fx/GHSA-8vx7-569q-v8fx.json +++ b/advisories/unreviewed/2022/04/GHSA-8vx7-569q-v8fx/GHSA-8vx7-569q-v8fx.json @@ -7,12 +7,8 @@ "CVE-2002-1060" ], "details": "Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security Gateway 2.1.02, and Server Accelerator 4.1.06 allows remote attackers to inject arbitrary web script or HTML via a URL to a nonexistent hostname that includes the HTML, which is inserted into the resulting error page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8wqg-hpmc-35r4/GHSA-8wqg-hpmc-35r4.json b/advisories/unreviewed/2022/04/GHSA-8wqg-hpmc-35r4/GHSA-8wqg-hpmc-35r4.json index c50fdb58b13..a4d481b20e7 100644 --- a/advisories/unreviewed/2022/04/GHSA-8wqg-hpmc-35r4/GHSA-8wqg-hpmc-35r4.json +++ b/advisories/unreviewed/2022/04/GHSA-8wqg-hpmc-35r4/GHSA-8wqg-hpmc-35r4.json @@ -7,12 +7,8 @@ "CVE-2002-1260" ], "details": "The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks and access database contents via an untrusted Java applet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-932g-jw4h-6cmm/GHSA-932g-jw4h-6cmm.json b/advisories/unreviewed/2022/04/GHSA-932g-jw4h-6cmm/GHSA-932g-jw4h-6cmm.json index 6623c9effb9..4424c6c090b 100644 --- a/advisories/unreviewed/2022/04/GHSA-932g-jw4h-6cmm/GHSA-932g-jw4h-6cmm.json +++ b/advisories/unreviewed/2022/04/GHSA-932g-jw4h-6cmm/GHSA-932g-jw4h-6cmm.json @@ -7,12 +7,8 @@ "CVE-2002-1071" ], "details": "ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet with both the SYN and ACK flags set.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-94r6-2p96-fcrh/GHSA-94r6-2p96-fcrh.json b/advisories/unreviewed/2022/04/GHSA-94r6-2p96-fcrh/GHSA-94r6-2p96-fcrh.json index 798b4ae2809..ea986184911 100644 --- a/advisories/unreviewed/2022/04/GHSA-94r6-2p96-fcrh/GHSA-94r6-2p96-fcrh.json +++ b/advisories/unreviewed/2022/04/GHSA-94r6-2p96-fcrh/GHSA-94r6-2p96-fcrh.json @@ -7,12 +7,8 @@ "CVE-2002-1288" ], "details": "The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to determine the current directory of the Internet Explorer process via the getAbsolutePath() method in a File() call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9542-fgmx-fggg/GHSA-9542-fgmx-fggg.json b/advisories/unreviewed/2022/04/GHSA-9542-fgmx-fggg/GHSA-9542-fgmx-fggg.json index 66fe42446b2..9ca4c2c25c2 100644 --- a/advisories/unreviewed/2022/04/GHSA-9542-fgmx-fggg/GHSA-9542-fgmx-fggg.json +++ b/advisories/unreviewed/2022/04/GHSA-9542-fgmx-fggg/GHSA-9542-fgmx-fggg.json @@ -7,12 +7,8 @@ "CVE-2002-1384" ], "details": "Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-95f4-q7vm-hf54/GHSA-95f4-q7vm-hf54.json b/advisories/unreviewed/2022/04/GHSA-95f4-q7vm-hf54/GHSA-95f4-q7vm-hf54.json index 96403ffdc1c..7a1e150c8cd 100644 --- a/advisories/unreviewed/2022/04/GHSA-95f4-q7vm-hf54/GHSA-95f4-q7vm-hf54.json +++ b/advisories/unreviewed/2022/04/GHSA-95f4-q7vm-hf54/GHSA-95f4-q7vm-hf54.json @@ -7,12 +7,8 @@ "CVE-2002-0945" ], "details": "Buffer overflow in SeaNox Devwex allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-95g5-p5xc-vf52/GHSA-95g5-p5xc-vf52.json b/advisories/unreviewed/2022/04/GHSA-95g5-p5xc-vf52/GHSA-95g5-p5xc-vf52.json index 080531a0fbf..aac888fc32d 100644 --- a/advisories/unreviewed/2022/04/GHSA-95g5-p5xc-vf52/GHSA-95g5-p5xc-vf52.json +++ b/advisories/unreviewed/2022/04/GHSA-95g5-p5xc-vf52/GHSA-95g5-p5xc-vf52.json @@ -7,12 +7,8 @@ "CVE-2002-1187" ], "details": "Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the or