From 2729b00122d8afbfebdf8b566e67b85f9a6a83bd Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 6 Dec 2024 05:10:53 +0000 Subject: [PATCH] Advisory Database Sync --- .../10/GHSA-h835-75hw-pj89/GHSA-h835-75hw-pj89.json | 4 +--- .../11/GHSA-9ggp-4jpr-7ppj/GHSA-9ggp-4jpr-7ppj.json | 12 +++--------- .../10/GHSA-pjwm-rvh2-c87w/GHSA-pjwm-rvh2-c87w.json | 4 +--- .../11/GHSA-9wx7-jrvc-28mm/GHSA-9wx7-jrvc-28mm.json | 8 ++------ .../12/GHSA-qrmm-w75w-3wpx/GHSA-qrmm-w75w-3wpx.json | 8 ++------ .../05/GHSA-7372-q459-jxhr/GHSA-7372-q459-jxhr.json | 4 +--- .../05/GHSA-g283-88v5-rmq2/GHSA-g283-88v5-rmq2.json | 4 +--- .../05/GHSA-rhcg-rwhx-qj3j/GHSA-rhcg-rwhx-qj3j.json | 4 +--- .../02/GHSA-22cc-w7xm-rfhx/GHSA-22cc-w7xm-rfhx.json | 8 ++------ .../04/GHSA-rqgv-292v-5qgr/GHSA-rqgv-292v-5qgr.json | 4 +--- .../04/GHSA-w228-rfpx-fhm4/GHSA-w228-rfpx-fhm4.json | 4 +--- .../05/GHSA-83jv-4prm-34g7/GHSA-83jv-4prm-34g7.json | 4 +--- .../11/GHSA-3jrq-x5vv-pvcw/GHSA-3jrq-x5vv-pvcw.json | 4 +--- .../11/GHSA-fp8m-q3h7-6ww8/GHSA-fp8m-q3h7-6ww8.json | 4 +--- .../11/GHSA-jf2c-v9v9-9r3w/GHSA-jf2c-v9v9-9r3w.json | 4 +--- .../01/GHSA-hmgv-4jwm-xc9x/GHSA-hmgv-4jwm-xc9x.json | 4 +--- .../01/GHSA-pfq2-x69w-983r/GHSA-pfq2-x69w-983r.json | 4 +--- .../01/GHSA-q3cw-hwhf-x8fr/GHSA-q3cw-hwhf-x8fr.json | 4 +--- .../02/GHSA-2hcr-94vw-mxjh/GHSA-2hcr-94vw-mxjh.json | 4 +--- .../02/GHSA-pfmv-2r4f-j9mj/GHSA-pfmv-2r4f-j9mj.json | 4 +--- .../03/GHSA-38pg-fhjw-6gv5/GHSA-38pg-fhjw-6gv5.json | 4 +--- .../05/GHSA-228f-32pf-6cc9/GHSA-228f-32pf-6cc9.json | 8 ++------ .../05/GHSA-22xm-47fv-r79q/GHSA-22xm-47fv-r79q.json | 4 +--- .../05/GHSA-236h-5c6c-jrfx/GHSA-236h-5c6c-jrfx.json | 8 ++------ .../05/GHSA-236w-f35g-f339/GHSA-236w-f35g-f339.json | 12 +++--------- .../05/GHSA-23g2-8rfg-4ppg/GHSA-23g2-8rfg-4ppg.json | 8 ++------ .../05/GHSA-23gh-5xvj-6hr9/GHSA-23gh-5xvj-6hr9.json | 12 +++--------- .../05/GHSA-25f3-2w4g-m595/GHSA-25f3-2w4g-m595.json | 8 ++------ .../05/GHSA-25mc-rjmh-r6x4/GHSA-25mc-rjmh-r6x4.json | 8 ++------ .../05/GHSA-274w-x34j-q3q6/GHSA-274w-x34j-q3q6.json | 12 +++--------- .../05/GHSA-29mr-mxx6-f3f5/GHSA-29mr-mxx6-f3f5.json | 8 ++------ .../05/GHSA-2cxm-7f99-2c44/GHSA-2cxm-7f99-2c44.json | 8 ++------ .../05/GHSA-2f84-jw6x-ffwh/GHSA-2f84-jw6x-ffwh.json | 8 ++------ .../05/GHSA-2g25-9rg6-j46q/GHSA-2g25-9rg6-j46q.json | 8 ++------ .../05/GHSA-2g43-c47m-wpf4/GHSA-2g43-c47m-wpf4.json | 12 +++--------- .../05/GHSA-2h4h-6mrx-52ff/GHSA-2h4h-6mrx-52ff.json | 8 ++------ .../05/GHSA-2h5c-85wg-jwx8/GHSA-2h5c-85wg-jwx8.json | 12 +++--------- .../05/GHSA-2hcx-274x-74jw/GHSA-2hcx-274x-74jw.json | 12 +++--------- .../05/GHSA-2hvv-h4pw-wcm2/GHSA-2hvv-h4pw-wcm2.json | 8 ++------ .../05/GHSA-2j92-9gm3-m87q/GHSA-2j92-9gm3-m87q.json | 8 ++------ .../05/GHSA-2mw7-77qm-cmxc/GHSA-2mw7-77qm-cmxc.json | 8 ++------ .../05/GHSA-2p45-c9hc-p9hf/GHSA-2p45-c9hc-p9hf.json | 8 ++------ .../05/GHSA-2p73-r6vf-7hjq/GHSA-2p73-r6vf-7hjq.json | 8 ++------ .../05/GHSA-2pqj-vff5-fgh2/GHSA-2pqj-vff5-fgh2.json | 8 ++------ .../05/GHSA-2qvm-65xp-25xh/GHSA-2qvm-65xp-25xh.json | 8 ++------ .../05/GHSA-2rg5-632f-rr5j/GHSA-2rg5-632f-rr5j.json | 8 ++------ .../05/GHSA-2w78-874w-f3gw/GHSA-2w78-874w-f3gw.json | 12 +++--------- .../05/GHSA-2x7c-3vq5-3crp/GHSA-2x7c-3vq5-3crp.json | 8 ++------ .../05/GHSA-2xq2-3xwx-xh4v/GHSA-2xq2-3xwx-xh4v.json | 8 ++------ .../05/GHSA-2xvq-8gjc-grfh/GHSA-2xvq-8gjc-grfh.json | 8 ++------ .../05/GHSA-2xwm-mmjj-m5x4/GHSA-2xwm-mmjj-m5x4.json | 8 ++------ .../05/GHSA-3276-rg2h-3pr3/GHSA-3276-rg2h-3pr3.json | 8 ++------ .../05/GHSA-3284-h9vj-jh4g/GHSA-3284-h9vj-jh4g.json | 8 ++------ .../05/GHSA-33mp-r2vv-f8h8/GHSA-33mp-r2vv-f8h8.json | 12 +++--------- .../05/GHSA-34g2-p88j-292j/GHSA-34g2-p88j-292j.json | 8 ++------ .../05/GHSA-356w-fr64-xq5w/GHSA-356w-fr64-xq5w.json | 8 ++------ .../05/GHSA-3834-xp98-q4q8/GHSA-3834-xp98-q4q8.json | 12 +++--------- .../05/GHSA-3843-wc38-gc2j/GHSA-3843-wc38-gc2j.json | 8 ++------ .../05/GHSA-39hc-fpg9-qhmv/GHSA-39hc-fpg9-qhmv.json | 8 ++------ .../05/GHSA-3f9c-f8wr-33fq/GHSA-3f9c-f8wr-33fq.json | 12 +++--------- .../05/GHSA-3gmf-2qwv-jgjx/GHSA-3gmf-2qwv-jgjx.json | 8 ++------ .../05/GHSA-3h26-w882-gmrp/GHSA-3h26-w882-gmrp.json | 12 +++--------- .../05/GHSA-3h72-w58w-hgvg/GHSA-3h72-w58w-hgvg.json | 8 ++------ .../05/GHSA-3jgj-6r4f-qgcx/GHSA-3jgj-6r4f-qgcx.json | 8 ++------ .../05/GHSA-3jh4-xfq2-x9w9/GHSA-3jh4-xfq2-x9w9.json | 8 ++------ .../05/GHSA-3mgv-3m44-369m/GHSA-3mgv-3m44-369m.json | 8 ++------ .../05/GHSA-3p3f-hgmm-72qv/GHSA-3p3f-hgmm-72qv.json | 12 +++--------- .../05/GHSA-3q32-62mw-rw5g/GHSA-3q32-62mw-rw5g.json | 8 ++------ .../05/GHSA-3q9m-cg52-56rj/GHSA-3q9m-cg52-56rj.json | 12 +++--------- .../05/GHSA-3rcv-jp3w-f98g/GHSA-3rcv-jp3w-f98g.json | 12 +++--------- .../05/GHSA-3rp2-pwr4-xjcw/GHSA-3rp2-pwr4-xjcw.json | 8 ++------ .../05/GHSA-3vf7-wf97-3857/GHSA-3vf7-wf97-3857.json | 12 +++--------- .../05/GHSA-3w5g-8rr6-f44g/GHSA-3w5g-8rr6-f44g.json | 8 ++------ .../05/GHSA-3w5q-79rf-8vf9/GHSA-3w5q-79rf-8vf9.json | 8 ++------ .../05/GHSA-3wjw-f8gp-589c/GHSA-3wjw-f8gp-589c.json | 8 ++------ .../05/GHSA-3xrm-g354-vfw9/GHSA-3xrm-g354-vfw9.json | 8 ++------ .../05/GHSA-444r-jhgm-mr5f/GHSA-444r-jhgm-mr5f.json | 12 +++--------- .../05/GHSA-44g8-q969-2xj9/GHSA-44g8-q969-2xj9.json | 8 ++------ .../05/GHSA-44gx-rvj5-7hc2/GHSA-44gx-rvj5-7hc2.json | 8 ++------ .../05/GHSA-452f-rx2g-gx8c/GHSA-452f-rx2g-gx8c.json | 12 +++--------- .../05/GHSA-45pg-g48p-xcpm/GHSA-45pg-g48p-xcpm.json | 12 +++--------- .../05/GHSA-477r-rmrp-5834/GHSA-477r-rmrp-5834.json | 8 ++------ .../05/GHSA-48v8-cjg7-hh69/GHSA-48v8-cjg7-hh69.json | 8 ++------ .../05/GHSA-48vq-m47w-3x7g/GHSA-48vq-m47w-3x7g.json | 8 ++------ .../05/GHSA-49vq-qc87-chpf/GHSA-49vq-qc87-chpf.json | 8 ++------ .../05/GHSA-4c52-gf37-2pfp/GHSA-4c52-gf37-2pfp.json | 4 +--- .../05/GHSA-4gp2-553h-2rmm/GHSA-4gp2-553h-2rmm.json | 8 ++------ .../05/GHSA-4jg3-45hc-h63q/GHSA-4jg3-45hc-h63q.json | 8 ++------ .../05/GHSA-4jpm-9h3f-25gq/GHSA-4jpm-9h3f-25gq.json | 8 ++------ .../05/GHSA-4jqc-6m5c-wg7v/GHSA-4jqc-6m5c-wg7v.json | 12 +++--------- .../05/GHSA-4m9g-w7wc-fj28/GHSA-4m9g-w7wc-fj28.json | 8 ++------ .../05/GHSA-4mw2-9w62-mvpx/GHSA-4mw2-9w62-mvpx.json | 8 ++------ .../05/GHSA-4r36-c55m-fp5v/GHSA-4r36-c55m-fp5v.json | 8 ++------ .../05/GHSA-4r4v-5gvp-ww57/GHSA-4r4v-5gvp-ww57.json | 8 ++------ .../05/GHSA-4r6q-r4w3-542r/GHSA-4r6q-r4w3-542r.json | 12 +++--------- .../05/GHSA-4vw6-c9w3-qj7g/GHSA-4vw6-c9w3-qj7g.json | 8 ++------ .../05/GHSA-4xqh-x493-83xm/GHSA-4xqh-x493-83xm.json | 12 +++--------- .../05/GHSA-532r-m868-3f7q/GHSA-532r-m868-3f7q.json | 12 +++--------- .../05/GHSA-53g7-wg5x-3j59/GHSA-53g7-wg5x-3j59.json | 8 ++------ .../05/GHSA-5469-vf4f-5v5j/GHSA-5469-vf4f-5v5j.json | 12 +++--------- .../05/GHSA-55m2-3xw2-r6v4/GHSA-55m2-3xw2-r6v4.json | 8 ++------ .../05/GHSA-55r3-cchv-jc6q/GHSA-55r3-cchv-jc6q.json | 8 ++------ .../05/GHSA-56gp-vg62-4mff/GHSA-56gp-vg62-4mff.json | 8 ++------ .../05/GHSA-579f-rm77-fpx9/GHSA-579f-rm77-fpx9.json | 8 ++------ .../05/GHSA-584j-wcxv-phqw/GHSA-584j-wcxv-phqw.json | 12 +++--------- .../05/GHSA-5cr6-f74m-mvgp/GHSA-5cr6-f74m-mvgp.json | 12 +++--------- .../05/GHSA-5fjr-xvv2-4qf4/GHSA-5fjr-xvv2-4qf4.json | 8 ++------ .../05/GHSA-5j27-hjpv-hq78/GHSA-5j27-hjpv-hq78.json | 12 +++--------- .../05/GHSA-5j8g-v93x-4959/GHSA-5j8g-v93x-4959.json | 8 ++------ .../05/GHSA-5mhf-ffc5-mcv4/GHSA-5mhf-ffc5-mcv4.json | 8 ++------ .../05/GHSA-5pc4-3627-qr4j/GHSA-5pc4-3627-qr4j.json | 8 ++------ .../05/GHSA-5pgp-g2r8-7gjv/GHSA-5pgp-g2r8-7gjv.json | 8 ++------ .../05/GHSA-5v5r-2x79-f5wc/GHSA-5v5r-2x79-f5wc.json | 8 ++------ .../05/GHSA-5x5p-c5pf-7mmq/GHSA-5x5p-c5pf-7mmq.json | 8 ++------ .../05/GHSA-5xrr-g352-hq7j/GHSA-5xrr-g352-hq7j.json | 12 +++--------- .../05/GHSA-6546-f3c3-rp4g/GHSA-6546-f3c3-rp4g.json | 8 ++------ .../05/GHSA-6737-58mm-3gwv/GHSA-6737-58mm-3gwv.json | 8 ++------ .../05/GHSA-692p-j7fj-c497/GHSA-692p-j7fj-c497.json | 12 +++--------- .../05/GHSA-69j8-3jrp-rcv2/GHSA-69j8-3jrp-rcv2.json | 8 ++------ .../05/GHSA-6c98-qgjr-fc37/GHSA-6c98-qgjr-fc37.json | 8 ++------ .../05/GHSA-6gj2-w23f-chf3/GHSA-6gj2-w23f-chf3.json | 12 +++--------- .../05/GHSA-6gj8-xjr6-v47j/GHSA-6gj8-xjr6-v47j.json | 12 +++--------- .../05/GHSA-6gmg-vxx6-mrxx/GHSA-6gmg-vxx6-mrxx.json | 8 ++------ .../05/GHSA-6h59-cw63-73qp/GHSA-6h59-cw63-73qp.json | 8 ++------ .../05/GHSA-6jgq-cppp-pvm8/GHSA-6jgq-cppp-pvm8.json | 8 ++------ .../05/GHSA-6q5h-57mm-c99g/GHSA-6q5h-57mm-c99g.json | 8 ++------ .../05/GHSA-6r7f-rwvw-h287/GHSA-6r7f-rwvw-h287.json | 8 ++------ .../05/GHSA-6rp6-x94v-92vx/GHSA-6rp6-x94v-92vx.json | 12 +++--------- .../05/GHSA-6rpw-6v52-q2ff/GHSA-6rpw-6v52-q2ff.json | 8 ++------ .../05/GHSA-6rr4-jv72-pv85/GHSA-6rr4-jv72-pv85.json | 8 ++------ .../05/GHSA-6v9h-97q3-6h22/GHSA-6v9h-97q3-6h22.json | 12 +++--------- .../05/GHSA-6vmf-4ghh-8g4r/GHSA-6vmf-4ghh-8g4r.json | 12 +++--------- .../05/GHSA-6w68-xh9m-j92v/GHSA-6w68-xh9m-j92v.json | 8 ++------ .../05/GHSA-6x64-rm6c-4p72/GHSA-6x64-rm6c-4p72.json | 8 ++------ .../05/GHSA-6x9c-w5j8-8h3x/GHSA-6x9c-w5j8-8h3x.json | 8 ++------ .../05/GHSA-6xh6-hvhw-h658/GHSA-6xh6-hvhw-h658.json | 12 +++--------- .../05/GHSA-7273-4xcg-4p5f/GHSA-7273-4xcg-4p5f.json | 8 ++------ .../05/GHSA-729q-jrf3-mhg8/GHSA-729q-jrf3-mhg8.json | 8 ++------ .../05/GHSA-748g-m8cr-v48g/GHSA-748g-m8cr-v48g.json | 12 +++--------- .../05/GHSA-75pm-pvvg-r2qr/GHSA-75pm-pvvg-r2qr.json | 12 +++--------- .../05/GHSA-7742-43c4-2h75/GHSA-7742-43c4-2h75.json | 8 ++------ .../05/GHSA-78rr-56jm-2q7g/GHSA-78rr-56jm-2q7g.json | 8 ++------ .../05/GHSA-79pf-r6gg-vhxx/GHSA-79pf-r6gg-vhxx.json | 8 ++------ .../05/GHSA-7cgc-jmfj-p9wc/GHSA-7cgc-jmfj-p9wc.json | 8 ++------ .../05/GHSA-7f48-gjxv-cppw/GHSA-7f48-gjxv-cppw.json | 8 ++------ .../05/GHSA-7fh4-f65w-5p7x/GHSA-7fh4-f65w-5p7x.json | 8 ++------ .../05/GHSA-7gwq-jm8c-29xc/GHSA-7gwq-jm8c-29xc.json | 8 ++------ .../05/GHSA-7j49-g4cp-8h6j/GHSA-7j49-g4cp-8h6j.json | 12 +++--------- .../05/GHSA-7jqj-9w6c-j4v9/GHSA-7jqj-9w6c-j4v9.json | 8 ++------ .../05/GHSA-7m4g-qfmm-hx4m/GHSA-7m4g-qfmm-hx4m.json | 8 ++------ .../05/GHSA-7m99-hppq-9pj6/GHSA-7m99-hppq-9pj6.json | 8 ++------ .../05/GHSA-7pq7-q7xj-fgj3/GHSA-7pq7-q7xj-fgj3.json | 8 ++------ .../05/GHSA-7rvv-4q2j-9cv9/GHSA-7rvv-4q2j-9cv9.json | 8 ++------ .../05/GHSA-7v29-vf8p-2rvp/GHSA-7v29-vf8p-2rvp.json | 12 +++--------- .../05/GHSA-7vgg-x2f9-c6c5/GHSA-7vgg-x2f9-c6c5.json | 8 ++------ .../05/GHSA-7w2g-gjg9-qhmc/GHSA-7w2g-gjg9-qhmc.json | 8 ++------ .../05/GHSA-7wcv-wc37-6cpx/GHSA-7wcv-wc37-6cpx.json | 8 ++------ .../05/GHSA-7wg6-9cv7-mw4w/GHSA-7wg6-9cv7-mw4w.json | 8 ++------ .../05/GHSA-7wj4-6jr7-34qw/GHSA-7wj4-6jr7-34qw.json | 8 ++------ .../05/GHSA-7wqq-c2xh-9759/GHSA-7wqq-c2xh-9759.json | 8 ++------ .../05/GHSA-7x7r-vg2m-69cm/GHSA-7x7r-vg2m-69cm.json | 8 ++------ .../05/GHSA-7xvv-8f53-f3jr/GHSA-7xvv-8f53-f3jr.json | 8 ++------ .../05/GHSA-8385-4jvx-fwmx/GHSA-8385-4jvx-fwmx.json | 8 ++------ .../05/GHSA-83r4-5rh2-7679/GHSA-83r4-5rh2-7679.json | 8 ++------ .../05/GHSA-85v4-r279-j4ww/GHSA-85v4-r279-j4ww.json | 8 ++------ .../05/GHSA-8668-w4w3-r36q/GHSA-8668-w4w3-r36q.json | 8 ++------ .../05/GHSA-86c8-5m9f-52c3/GHSA-86c8-5m9f-52c3.json | 8 ++------ .../05/GHSA-873w-8wmr-67j9/GHSA-873w-8wmr-67j9.json | 12 +++--------- .../05/GHSA-8765-h9hh-rh5j/GHSA-8765-h9hh-rh5j.json | 12 +++--------- .../05/GHSA-8g2r-5pm7-653f/GHSA-8g2r-5pm7-653f.json | 8 ++------ .../05/GHSA-8h49-6g8c-82vj/GHSA-8h49-6g8c-82vj.json | 12 +++--------- .../05/GHSA-8h8c-6943-5984/GHSA-8h8c-6943-5984.json | 12 +++--------- .../05/GHSA-8jx6-3v53-6qmh/GHSA-8jx6-3v53-6qmh.json | 8 ++------ .../05/GHSA-8p5g-5vh8-4rwm/GHSA-8p5g-5vh8-4rwm.json | 8 ++------ .../05/GHSA-8q39-6pgq-m9mv/GHSA-8q39-6pgq-m9mv.json | 8 ++------ .../05/GHSA-8vfp-xjc3-jjvc/GHSA-8vfp-xjc3-jjvc.json | 8 ++------ .../05/GHSA-8vqc-r2hm-5662/GHSA-8vqc-r2hm-5662.json | 8 ++------ .../05/GHSA-8vqf-2mgv-72m8/GHSA-8vqf-2mgv-72m8.json | 12 +++--------- .../05/GHSA-8vvp-pmvm-x49v/GHSA-8vvp-pmvm-x49v.json | 12 +++--------- .../05/GHSA-8wgh-rhq6-89pj/GHSA-8wgh-rhq6-89pj.json | 8 ++------ .../05/GHSA-8xf2-9w2x-9w9x/GHSA-8xf2-9w2x-9w9x.json | 8 ++------ .../05/GHSA-8xq7-gqj3-mh42/GHSA-8xq7-gqj3-mh42.json | 8 ++------ .../05/GHSA-922g-35pj-pv6f/GHSA-922g-35pj-pv6f.json | 12 +++--------- .../05/GHSA-92xw-jc8h-7jc6/GHSA-92xw-jc8h-7jc6.json | 12 +++--------- .../05/GHSA-93g6-7v2r-h2r4/GHSA-93g6-7v2r-h2r4.json | 8 ++------ .../05/GHSA-9595-rj38-7f63/GHSA-9595-rj38-7f63.json | 8 ++------ .../05/GHSA-95qf-v6r5-2v3v/GHSA-95qf-v6r5-2v3v.json | 8 ++------ .../05/GHSA-963q-pv8m-wcgg/GHSA-963q-pv8m-wcgg.json | 8 ++------ .../05/GHSA-98fv-x3p6-qjrq/GHSA-98fv-x3p6-qjrq.json | 8 ++------ .../05/GHSA-9929-5m98-qfvf/GHSA-9929-5m98-qfvf.json | 8 ++------ .../05/GHSA-99jw-r98g-wv3r/GHSA-99jw-r98g-wv3r.json | 8 ++------ .../05/GHSA-9c9p-hhrq-f5v5/GHSA-9c9p-hhrq-f5v5.json | 8 ++------ .../05/GHSA-9h32-4549-r88j/GHSA-9h32-4549-r88j.json | 8 ++------ .../05/GHSA-9h97-c3c6-r77v/GHSA-9h97-c3c6-r77v.json | 8 ++------ .../05/GHSA-9jcf-26mj-wqj2/GHSA-9jcf-26mj-wqj2.json | 8 ++------ .../05/GHSA-9jq8-pf78-365m/GHSA-9jq8-pf78-365m.json | 8 ++------ .../05/GHSA-9mqf-8hq3-g769/GHSA-9mqf-8hq3-g769.json | 12 +++--------- .../05/GHSA-9p22-mxrj-58pq/GHSA-9p22-mxrj-58pq.json | 8 ++------ .../05/GHSA-9pjx-6wmc-cjx8/GHSA-9pjx-6wmc-cjx8.json | 8 ++------ .../05/GHSA-9pmr-c76h-69jv/GHSA-9pmr-c76h-69jv.json | 8 ++------ .../05/GHSA-9q85-v4x8-53m9/GHSA-9q85-v4x8-53m9.json | 12 +++--------- .../05/GHSA-9qg7-2pr2-fwxx/GHSA-9qg7-2pr2-fwxx.json | 12 +++--------- .../05/GHSA-9qpg-8qf4-xcm3/GHSA-9qpg-8qf4-xcm3.json | 8 ++------ .../05/GHSA-9wfh-rmwp-2j6f/GHSA-9wfh-rmwp-2j6f.json | 12 +++--------- .../05/GHSA-9x36-6xcq-gx68/GHSA-9x36-6xcq-gx68.json | 8 ++------ .../05/GHSA-c447-89c9-f6qg/GHSA-c447-89c9-f6qg.json | 8 ++------ .../05/GHSA-c4r6-5789-m28r/GHSA-c4r6-5789-m28r.json | 8 ++------ .../05/GHSA-c4xf-g2x3-xwj3/GHSA-c4xf-g2x3-xwj3.json | 8 ++------ .../05/GHSA-c58j-fj65-hr85/GHSA-c58j-fj65-hr85.json | 8 ++------ .../05/GHSA-c5g4-vv54-c9mx/GHSA-c5g4-vv54-c9mx.json | 8 ++------ .../05/GHSA-c6wm-439x-m8c5/GHSA-c6wm-439x-m8c5.json | 12 +++--------- .../05/GHSA-c7c4-gg8f-6972/GHSA-c7c4-gg8f-6972.json | 12 +++--------- .../05/GHSA-c7jp-mf9p-5jw3/GHSA-c7jp-mf9p-5jw3.json | 8 ++------ .../05/GHSA-c7p9-7r66-m278/GHSA-c7p9-7r66-m278.json | 8 ++------ .../05/GHSA-c8c6-gph2-8xgc/GHSA-c8c6-gph2-8xgc.json | 8 ++------ .../05/GHSA-c8r5-4v73-vfrf/GHSA-c8r5-4v73-vfrf.json | 8 ++------ .../05/GHSA-c9xc-56mr-2w4p/GHSA-c9xc-56mr-2w4p.json | 12 +++--------- .../05/GHSA-cc87-ccgm-46gj/GHSA-cc87-ccgm-46gj.json | 8 ++------ .../05/GHSA-cff7-mg33-3hwg/GHSA-cff7-mg33-3hwg.json | 8 ++------ .../05/GHSA-cfrp-668w-c627/GHSA-cfrp-668w-c627.json | 12 +++--------- .../05/GHSA-cgw6-gwvc-637r/GHSA-cgw6-gwvc-637r.json | 12 +++--------- .../05/GHSA-cjw8-32q9-h987/GHSA-cjw8-32q9-h987.json | 8 ++------ .../05/GHSA-cp55-63r2-rcpp/GHSA-cp55-63r2-rcpp.json | 8 ++------ .../05/GHSA-cpqc-x3qr-2fr9/GHSA-cpqc-x3qr-2fr9.json | 8 ++------ .../05/GHSA-cq98-4r72-wm2g/GHSA-cq98-4r72-wm2g.json | 8 ++------ .../05/GHSA-crgx-9757-wppq/GHSA-crgx-9757-wppq.json | 8 ++------ .../05/GHSA-cwfr-j24c-gpv5/GHSA-cwfr-j24c-gpv5.json | 12 +++--------- .../05/GHSA-cwqr-wx5w-x96j/GHSA-cwqr-wx5w-x96j.json | 8 ++------ .../05/GHSA-cwvc-h2j5-j87h/GHSA-cwvc-h2j5-j87h.json | 8 ++------ .../05/GHSA-cx22-p5qf-h4w5/GHSA-cx22-p5qf-h4w5.json | 8 ++------ .../05/GHSA-cxj5-9j38-qv4q/GHSA-cxj5-9j38-qv4q.json | 8 ++------ .../05/GHSA-f2r3-9369-56wc/GHSA-f2r3-9369-56wc.json | 8 ++------ .../05/GHSA-f2w7-6hg5-cm53/GHSA-f2w7-6hg5-cm53.json | 8 ++------ .../05/GHSA-f32v-f53x-625g/GHSA-f32v-f53x-625g.json | 8 ++------ .../05/GHSA-f3fr-c2xj-gmgh/GHSA-f3fr-c2xj-gmgh.json | 8 ++------ .../05/GHSA-f5rg-3x57-9mv4/GHSA-f5rg-3x57-9mv4.json | 8 ++------ .../05/GHSA-f68p-8hwp-w826/GHSA-f68p-8hwp-w826.json | 8 ++------ .../05/GHSA-f6mg-fwxg-7jhc/GHSA-f6mg-fwxg-7jhc.json | 8 ++------ .../05/GHSA-f7cj-p2gc-6mpq/GHSA-f7cj-p2gc-6mpq.json | 12 +++--------- .../05/GHSA-f7f9-2whw-qx53/GHSA-f7f9-2whw-qx53.json | 12 +++--------- .../05/GHSA-f9pg-qgmm-v967/GHSA-f9pg-qgmm-v967.json | 8 ++------ .../05/GHSA-ffmr-3456-95g2/GHSA-ffmr-3456-95g2.json | 8 ++------ .../05/GHSA-fh4p-65g7-4cxw/GHSA-fh4p-65g7-4cxw.json | 8 ++------ .../05/GHSA-fj6x-fvp6-8xpx/GHSA-fj6x-fvp6-8xpx.json | 12 +++--------- .../05/GHSA-fm3q-mpvm-v84g/GHSA-fm3q-mpvm-v84g.json | 8 ++------ .../05/GHSA-fm76-g8pj-f24f/GHSA-fm76-g8pj-f24f.json | 8 ++------ .../05/GHSA-fmmr-m43m-x2x8/GHSA-fmmr-m43m-x2x8.json | 8 ++------ .../05/GHSA-fp8m-5h9q-mjmp/GHSA-fp8m-5h9q-mjmp.json | 4 +--- .../05/GHSA-fpfj-66xm-fh42/GHSA-fpfj-66xm-fh42.json | 8 ++------ .../05/GHSA-fpxv-5mjh-r2rq/GHSA-fpxv-5mjh-r2rq.json | 4 +--- .../05/GHSA-frxf-86wq-56jg/GHSA-frxf-86wq-56jg.json | 8 ++------ .../05/GHSA-fv6h-j25m-44r8/GHSA-fv6h-j25m-44r8.json | 12 +++--------- .../05/GHSA-fvfr-2wj6-cpjw/GHSA-fvfr-2wj6-cpjw.json | 8 ++------ .../05/GHSA-fvpf-jrm8-v7p6/GHSA-fvpf-jrm8-v7p6.json | 8 ++------ .../05/GHSA-fvpq-4888-9x4p/GHSA-fvpq-4888-9x4p.json | 8 ++------ .../05/GHSA-fw7j-37p2-4j4w/GHSA-fw7j-37p2-4j4w.json | 8 ++------ .../05/GHSA-fxg8-p79j-qgvc/GHSA-fxg8-p79j-qgvc.json | 12 +++--------- .../05/GHSA-g2m6-fh3h-866m/GHSA-g2m6-fh3h-866m.json | 8 ++------ .../05/GHSA-g37h-m5cc-48wj/GHSA-g37h-m5cc-48wj.json | 8 ++------ .../05/GHSA-g38c-rrvw-cg3q/GHSA-g38c-rrvw-cg3q.json | 12 +++--------- .../05/GHSA-g3jm-cg9g-h67v/GHSA-g3jm-cg9g-h67v.json | 8 ++------ .../05/GHSA-g5xq-3448-3grg/GHSA-g5xq-3448-3grg.json | 8 ++------ .../05/GHSA-g6wr-xh7r-qh7r/GHSA-g6wr-xh7r-qh7r.json | 12 +++--------- .../05/GHSA-g74x-8276-gw6g/GHSA-g74x-8276-gw6g.json | 8 ++------ .../05/GHSA-g87h-m2mj-j8xg/GHSA-g87h-m2mj-j8xg.json | 8 ++------ .../05/GHSA-g8gg-rcmj-jj2r/GHSA-g8gg-rcmj-jj2r.json | 12 +++--------- .../05/GHSA-g9m3-q24q-m9q6/GHSA-g9m3-q24q-m9q6.json | 12 +++--------- .../05/GHSA-gf36-rwr4-jchr/GHSA-gf36-rwr4-jchr.json | 12 +++--------- .../05/GHSA-gf95-p6g7-5745/GHSA-gf95-p6g7-5745.json | 12 +++--------- .../05/GHSA-gh64-r29h-qrp4/GHSA-gh64-r29h-qrp4.json | 12 +++--------- .../05/GHSA-ghpw-v274-x8mh/GHSA-ghpw-v274-x8mh.json | 12 +++--------- .../05/GHSA-gj9w-hmvj-m22x/GHSA-gj9w-hmvj-m22x.json | 12 +++--------- .../05/GHSA-gm26-863f-73h9/GHSA-gm26-863f-73h9.json | 8 ++------ .../05/GHSA-gp27-5qqj-ww24/GHSA-gp27-5qqj-ww24.json | 8 ++------ .../05/GHSA-gqj3-w7c6-64hm/GHSA-gqj3-w7c6-64hm.json | 8 ++------ .../05/GHSA-gqwx-r9ff-8pph/GHSA-gqwx-r9ff-8pph.json | 8 ++------ .../05/GHSA-gr46-rm4c-r88p/GHSA-gr46-rm4c-r88p.json | 8 ++------ .../05/GHSA-gr4w-3rcg-cq27/GHSA-gr4w-3rcg-cq27.json | 8 ++------ .../05/GHSA-gr52-m656-xvfr/GHSA-gr52-m656-xvfr.json | 8 ++------ .../05/GHSA-gvrc-33rc-wf3c/GHSA-gvrc-33rc-wf3c.json | 8 ++------ .../05/GHSA-gw52-6qvc-qghx/GHSA-gw52-6qvc-qghx.json | 8 ++------ .../05/GHSA-gx4x-mg2h-gqh7/GHSA-gx4x-mg2h-gqh7.json | 8 ++------ .../05/GHSA-h3qm-57f6-w9vc/GHSA-h3qm-57f6-w9vc.json | 8 ++------ .../05/GHSA-h3v9-chrp-f4j9/GHSA-h3v9-chrp-f4j9.json | 12 +++--------- .../05/GHSA-h5qj-6vv9-f5jh/GHSA-h5qj-6vv9-f5jh.json | 8 ++------ .../05/GHSA-h6f2-m5v7-5p44/GHSA-h6f2-m5v7-5p44.json | 12 +++--------- .../05/GHSA-h6v7-5393-j43m/GHSA-h6v7-5393-j43m.json | 8 ++------ .../05/GHSA-h6wg-55h3-3874/GHSA-h6wg-55h3-3874.json | 8 ++------ .../05/GHSA-h7qm-8pq2-ffp8/GHSA-h7qm-8pq2-ffp8.json | 8 ++------ .../05/GHSA-h8r9-6h89-2cmf/GHSA-h8r9-6h89-2cmf.json | 8 ++------ .../05/GHSA-hfrg-fh8r-qfqx/GHSA-hfrg-fh8r-qfqx.json | 12 +++--------- .../05/GHSA-hg3m-wq4w-f682/GHSA-hg3m-wq4w-f682.json | 8 ++------ .../05/GHSA-hg7f-ch82-693x/GHSA-hg7f-ch82-693x.json | 8 ++------ .../05/GHSA-hgp2-5f7q-m5jp/GHSA-hgp2-5f7q-m5jp.json | 8 ++------ .../05/GHSA-hh3q-37j7-xw97/GHSA-hh3q-37j7-xw97.json | 8 ++------ .../05/GHSA-hhcq-96ph-hc6g/GHSA-hhcq-96ph-hc6g.json | 8 ++------ .../05/GHSA-hhr4-5gv9-vmp2/GHSA-hhr4-5gv9-vmp2.json | 8 ++------ .../05/GHSA-hj7g-953m-g64c/GHSA-hj7g-953m-g64c.json | 12 +++--------- .../05/GHSA-hq62-5x3m-5577/GHSA-hq62-5x3m-5577.json | 12 +++--------- .../05/GHSA-hq74-v35j-jc5r/GHSA-hq74-v35j-jc5r.json | 8 ++------ .../05/GHSA-hvw3-wqpj-8g42/GHSA-hvw3-wqpj-8g42.json | 8 ++------ .../05/GHSA-hw3j-2ppx-mp2f/GHSA-hw3j-2ppx-mp2f.json | 8 ++------ .../05/GHSA-hxvx-q4xc-7x53/GHSA-hxvx-q4xc-7x53.json | 8 ++------ .../05/GHSA-j26h-pv9m-hqv4/GHSA-j26h-pv9m-hqv4.json | 8 ++------ .../05/GHSA-j347-f3mw-c7pr/GHSA-j347-f3mw-c7pr.json | 8 ++------ .../05/GHSA-j366-xcc9-rmr5/GHSA-j366-xcc9-rmr5.json | 8 ++------ .../05/GHSA-j3h2-rjr7-w6j2/GHSA-j3h2-rjr7-w6j2.json | 12 +++--------- .../05/GHSA-j4g2-269c-vp7g/GHSA-j4g2-269c-vp7g.json | 8 ++------ .../05/GHSA-j4jf-g93f-79pj/GHSA-j4jf-g93f-79pj.json | 8 ++------ .../05/GHSA-j4r6-3gh8-mr87/GHSA-j4r6-3gh8-mr87.json | 8 ++------ .../05/GHSA-j8hx-xmv6-rgjh/GHSA-j8hx-xmv6-rgjh.json | 8 ++------ .../05/GHSA-j8w7-wm55-74qc/GHSA-j8w7-wm55-74qc.json | 8 ++------ .../05/GHSA-j97w-8mcp-pr5v/GHSA-j97w-8mcp-pr5v.json | 12 +++--------- .../05/GHSA-jcvj-9pfw-q2cg/GHSA-jcvj-9pfw-q2cg.json | 8 ++------ .../05/GHSA-jf64-vfp6-7x6v/GHSA-jf64-vfp6-7x6v.json | 8 ++------ .../05/GHSA-jf83-r388-q6j5/GHSA-jf83-r388-q6j5.json | 8 ++------ .../05/GHSA-jgvj-fxm7-hppf/GHSA-jgvj-fxm7-hppf.json | 8 ++------ .../05/GHSA-jgw8-64jm-9x2f/GHSA-jgw8-64jm-9x2f.json | 8 ++------ .../05/GHSA-jgxf-vg8g-7f9c/GHSA-jgxf-vg8g-7f9c.json | 8 ++------ .../05/GHSA-jh8v-m7x2-75f6/GHSA-jh8v-m7x2-75f6.json | 12 +++--------- .../05/GHSA-jhwj-rxcc-56mw/GHSA-jhwj-rxcc-56mw.json | 12 +++--------- .../05/GHSA-jj8p-vp76-pwxh/GHSA-jj8p-vp76-pwxh.json | 8 ++------ .../05/GHSA-jm6w-xv7f-69rg/GHSA-jm6w-xv7f-69rg.json | 12 +++--------- .../05/GHSA-jmw9-7c66-65cm/GHSA-jmw9-7c66-65cm.json | 8 ++------ .../05/GHSA-jq6p-4382-pqcc/GHSA-jq6p-4382-pqcc.json | 12 +++--------- .../05/GHSA-jrhc-49g7-pg3c/GHSA-jrhc-49g7-pg3c.json | 12 +++--------- .../05/GHSA-jw3p-6pw3-8hmm/GHSA-jw3p-6pw3-8hmm.json | 8 ++------ .../05/GHSA-jwh7-cj9w-f3p3/GHSA-jwh7-cj9w-f3p3.json | 12 +++--------- .../05/GHSA-jwqf-9f82-j3jg/GHSA-jwqf-9f82-j3jg.json | 12 +++--------- .../05/GHSA-jx78-jgwx-p7fv/GHSA-jx78-jgwx-p7fv.json | 8 ++------ .../05/GHSA-jxqf-38mj-cx5m/GHSA-jxqf-38mj-cx5m.json | 12 +++--------- .../05/GHSA-m2g8-857v-hv6m/GHSA-m2g8-857v-hv6m.json | 8 ++------ .../05/GHSA-m4wr-7q8r-j9w6/GHSA-m4wr-7q8r-j9w6.json | 8 ++------ .../05/GHSA-mjch-7g5x-p6j8/GHSA-mjch-7g5x-p6j8.json | 8 ++------ .../05/GHSA-mjpc-3jv3-gwf3/GHSA-mjpc-3jv3-gwf3.json | 8 ++------ .../05/GHSA-mmvj-pjr9-mgcp/GHSA-mmvj-pjr9-mgcp.json | 8 ++------ .../05/GHSA-mp4f-9pjq-jgc3/GHSA-mp4f-9pjq-jgc3.json | 8 ++------ .../05/GHSA-mp89-6v8w-j8gv/GHSA-mp89-6v8w-j8gv.json | 8 ++------ .../05/GHSA-mqhw-5r33-x99w/GHSA-mqhw-5r33-x99w.json | 8 ++------ .../05/GHSA-mqqh-4pfq-f7mp/GHSA-mqqh-4pfq-f7mp.json | 8 ++------ .../05/GHSA-mr2f-cw7q-5j4f/GHSA-mr2f-cw7q-5j4f.json | 8 ++------ .../05/GHSA-mr44-mp3p-wc79/GHSA-mr44-mp3p-wc79.json | 8 ++------ .../05/GHSA-mrhj-qvw9-qpwx/GHSA-mrhj-qvw9-qpwx.json | 8 ++------ .../05/GHSA-mrw8-gpwg-9pjg/GHSA-mrw8-gpwg-9pjg.json | 8 ++------ .../05/GHSA-mvgf-43cx-7vh6/GHSA-mvgf-43cx-7vh6.json | 8 ++------ .../05/GHSA-mvr4-323r-rh68/GHSA-mvr4-323r-rh68.json | 8 ++------ .../05/GHSA-mx9q-gcm7-q3r8/GHSA-mx9q-gcm7-q3r8.json | 8 ++------ .../05/GHSA-p2fc-fp67-8xv9/GHSA-p2fc-fp67-8xv9.json | 8 ++------ .../05/GHSA-p2ff-59f4-vxff/GHSA-p2ff-59f4-vxff.json | 12 +++--------- .../05/GHSA-p2fg-pc9g-5cq8/GHSA-p2fg-pc9g-5cq8.json | 12 +++--------- .../05/GHSA-p4cc-ww2x-83fj/GHSA-p4cc-ww2x-83fj.json | 8 ++------ .../05/GHSA-p4pr-p87r-mxm8/GHSA-p4pr-p87r-mxm8.json | 8 ++------ .../05/GHSA-p4wf-p7fg-ghq6/GHSA-p4wf-p7fg-ghq6.json | 8 ++------ .../05/GHSA-p5h3-4856-8937/GHSA-p5h3-4856-8937.json | 8 ++------ .../05/GHSA-p5q9-c64v-86cv/GHSA-p5q9-c64v-86cv.json | 12 +++--------- .../05/GHSA-p5ww-ppr2-h64x/GHSA-p5ww-ppr2-h64x.json | 8 ++------ .../05/GHSA-p6fw-jhvr-w5xg/GHSA-p6fw-jhvr-w5xg.json | 8 ++------ .../05/GHSA-p6p9-cj4h-xmqp/GHSA-p6p9-cj4h-xmqp.json | 12 +++--------- .../05/GHSA-p74c-gqrv-v859/GHSA-p74c-gqrv-v859.json | 8 ++------ .../05/GHSA-p7c2-7f6q-f6m2/GHSA-p7c2-7f6q-f6m2.json | 12 +++--------- .../05/GHSA-p8mc-767v-qwwh/GHSA-p8mc-767v-qwwh.json | 12 +++--------- .../05/GHSA-p94m-p5xc-rjpp/GHSA-p94m-p5xc-rjpp.json | 12 +++--------- .../05/GHSA-pc8j-pfcg-w3f2/GHSA-pc8j-pfcg-w3f2.json | 8 ++------ .../05/GHSA-pcvq-3c52-8x6w/GHSA-pcvq-3c52-8x6w.json | 12 +++--------- .../05/GHSA-pj28-mx3m-9668/GHSA-pj28-mx3m-9668.json | 8 ++------ .../05/GHSA-pm2h-5fwq-4g6q/GHSA-pm2h-5fwq-4g6q.json | 8 ++------ .../05/GHSA-pp9j-974q-cm92/GHSA-pp9j-974q-cm92.json | 12 +++--------- .../05/GHSA-pqg3-798q-wvr8/GHSA-pqg3-798q-wvr8.json | 8 ++------ .../05/GHSA-prgm-px5q-c9h6/GHSA-prgm-px5q-c9h6.json | 8 ++------ .../05/GHSA-q2jx-hgv6-67hh/GHSA-q2jx-hgv6-67hh.json | 12 +++--------- .../05/GHSA-q57r-8v39-g8f8/GHSA-q57r-8v39-g8f8.json | 8 ++------ .../05/GHSA-q5j9-7x8j-95mg/GHSA-q5j9-7x8j-95mg.json | 8 ++------ .../05/GHSA-q62m-m86m-99hc/GHSA-q62m-m86m-99hc.json | 8 ++------ .../05/GHSA-q76f-hqqv-cqmv/GHSA-q76f-hqqv-cqmv.json | 12 +++--------- .../05/GHSA-q9p3-383j-jvqg/GHSA-q9p3-383j-jvqg.json | 12 +++--------- .../05/GHSA-qfqv-cr9x-27pg/GHSA-qfqv-cr9x-27pg.json | 12 +++--------- .../05/GHSA-qg27-wh8f-4pvh/GHSA-qg27-wh8f-4pvh.json | 8 ++------ .../05/GHSA-qgqh-rgf4-cmxj/GHSA-qgqh-rgf4-cmxj.json | 8 ++------ .../05/GHSA-qhrg-rwr6-hrvj/GHSA-qhrg-rwr6-hrvj.json | 8 ++------ .../05/GHSA-qhwr-8w6q-ccrf/GHSA-qhwr-8w6q-ccrf.json | 8 ++------ .../05/GHSA-qj32-xx7f-66p6/GHSA-qj32-xx7f-66p6.json | 12 +++--------- .../05/GHSA-qjw3-gg35-j8hf/GHSA-qjw3-gg35-j8hf.json | 8 ++------ .../05/GHSA-qmhf-38fc-rg36/GHSA-qmhf-38fc-rg36.json | 12 +++--------- .../05/GHSA-qq8x-fmp6-3285/GHSA-qq8x-fmp6-3285.json | 8 ++------ .../05/GHSA-qqq7-ff89-5hxp/GHSA-qqq7-ff89-5hxp.json | 12 +++--------- .../05/GHSA-qrfq-jhxg-f23h/GHSA-qrfq-jhxg-f23h.json | 12 +++--------- .../05/GHSA-qrp2-qxjh-p3w7/GHSA-qrp2-qxjh-p3w7.json | 12 +++--------- .../05/GHSA-qrxr-jvmh-w76v/GHSA-qrxr-jvmh-w76v.json | 12 +++--------- .../05/GHSA-qw4m-f928-rmxw/GHSA-qw4m-f928-rmxw.json | 8 ++------ .../05/GHSA-qwhv-gv46-cghm/GHSA-qwhv-gv46-cghm.json | 12 +++--------- .../05/GHSA-qwr4-pw8f-65fh/GHSA-qwr4-pw8f-65fh.json | 8 ++------ .../05/GHSA-qwwx-r45m-fccp/GHSA-qwwx-r45m-fccp.json | 8 ++------ .../05/GHSA-qxp2-gg8v-38j7/GHSA-qxp2-gg8v-38j7.json | 8 ++------ .../05/GHSA-r3rv-6724-59xh/GHSA-r3rv-6724-59xh.json | 8 ++------ .../05/GHSA-r4qf-qv9j-pfh2/GHSA-r4qf-qv9j-pfh2.json | 8 ++------ .../05/GHSA-r5vv-cfcv-fxgg/GHSA-r5vv-cfcv-fxgg.json | 8 ++------ .../05/GHSA-r638-cc42-fmm8/GHSA-r638-cc42-fmm8.json | 8 ++------ .../05/GHSA-r6q2-r6w9-r68w/GHSA-r6q2-r6w9-r68w.json | 8 ++------ .../05/GHSA-r739-rgx6-8fvc/GHSA-r739-rgx6-8fvc.json | 12 +++--------- .../05/GHSA-r85p-x73w-j6w7/GHSA-r85p-x73w-j6w7.json | 8 ++------ .../05/GHSA-r8gc-4gr6-4vf3/GHSA-r8gc-4gr6-4vf3.json | 8 ++------ .../05/GHSA-r9m4-pj3v-82vg/GHSA-r9m4-pj3v-82vg.json | 8 ++------ .../05/GHSA-rffm-4cpf-5232/GHSA-rffm-4cpf-5232.json | 8 ++------ .../05/GHSA-rgx2-hj64-5vc5/GHSA-rgx2-hj64-5vc5.json | 8 ++------ .../05/GHSA-rh22-qpv4-cr2w/GHSA-rh22-qpv4-cr2w.json | 8 ++------ .../05/GHSA-rh33-jwjp-gp57/GHSA-rh33-jwjp-gp57.json | 12 +++--------- .../05/GHSA-rh6v-2j3r-hcr7/GHSA-rh6v-2j3r-hcr7.json | 8 ++------ .../05/GHSA-rhfm-3h2p-hpj5/GHSA-rhfm-3h2p-hpj5.json | 8 ++------ .../05/GHSA-rmph-rx97-825x/GHSA-rmph-rx97-825x.json | 8 ++------ .../05/GHSA-rqvx-64rw-7qf7/GHSA-rqvx-64rw-7qf7.json | 8 ++------ .../05/GHSA-rrmh-22f3-jwvm/GHSA-rrmh-22f3-jwvm.json | 8 ++------ .../05/GHSA-rrv6-v26v-p7x6/GHSA-rrv6-v26v-p7x6.json | 8 ++------ .../05/GHSA-rrx5-gxgm-9hrg/GHSA-rrx5-gxgm-9hrg.json | 12 +++--------- .../05/GHSA-rvrf-fv66-542r/GHSA-rvrf-fv66-542r.json | 8 ++------ .../05/GHSA-rx67-45qh-rq2f/GHSA-rx67-45qh-rq2f.json | 8 ++------ .../05/GHSA-v298-4xpp-8q7w/GHSA-v298-4xpp-8q7w.json | 4 +--- .../05/GHSA-v2px-6v66-28pr/GHSA-v2px-6v66-28pr.json | 12 +++--------- .../05/GHSA-v38m-g35p-gq23/GHSA-v38m-g35p-gq23.json | 8 ++------ .../05/GHSA-v42x-2p48-wv3h/GHSA-v42x-2p48-wv3h.json | 12 +++--------- .../05/GHSA-v4vh-ww37-cwf9/GHSA-v4vh-ww37-cwf9.json | 12 +++--------- .../05/GHSA-v546-xgjm-f26m/GHSA-v546-xgjm-f26m.json | 8 ++------ .../05/GHSA-v5c5-v293-v6pr/GHSA-v5c5-v293-v6pr.json | 8 ++------ .../05/GHSA-v624-m74f-mvr7/GHSA-v624-m74f-mvr7.json | 12 +++--------- .../05/GHSA-v7m3-8qcv-rghh/GHSA-v7m3-8qcv-rghh.json | 12 +++--------- .../05/GHSA-v7mv-48xw-jjpg/GHSA-v7mv-48xw-jjpg.json | 12 +++--------- .../05/GHSA-v7x3-9cqm-7f9x/GHSA-v7x3-9cqm-7f9x.json | 8 ++------ .../05/GHSA-v883-mm2p-25jv/GHSA-v883-mm2p-25jv.json | 8 ++------ .../05/GHSA-v94c-xcvw-4cjr/GHSA-v94c-xcvw-4cjr.json | 8 ++------ .../05/GHSA-v98p-5p6g-589f/GHSA-v98p-5p6g-589f.json | 12 +++--------- .../05/GHSA-v9g4-4g73-5g38/GHSA-v9g4-4g73-5g38.json | 8 ++------ .../05/GHSA-v9rq-6m39-qhfv/GHSA-v9rq-6m39-qhfv.json | 8 ++------ .../05/GHSA-v9rw-6hcx-4xmj/GHSA-v9rw-6hcx-4xmj.json | 8 ++------ .../05/GHSA-vcv4-f36j-f989/GHSA-vcv4-f36j-f989.json | 8 ++------ .../05/GHSA-vhj4-xvq7-8jwv/GHSA-vhj4-xvq7-8jwv.json | 8 ++------ .../05/GHSA-vmc5-rw2x-673r/GHSA-vmc5-rw2x-673r.json | 8 ++------ .../05/GHSA-vmfq-82qr-6c52/GHSA-vmfq-82qr-6c52.json | 8 ++------ .../05/GHSA-vmph-29gv-pcc6/GHSA-vmph-29gv-pcc6.json | 8 ++------ .../05/GHSA-vmpv-2fcj-wmfj/GHSA-vmpv-2fcj-wmfj.json | 12 +++--------- .../05/GHSA-vpc6-xqq7-xh2q/GHSA-vpc6-xqq7-xh2q.json | 12 +++--------- .../05/GHSA-vpg5-v686-gf7m/GHSA-vpg5-v686-gf7m.json | 8 ++------ .../05/GHSA-vpjv-r4xm-v9c6/GHSA-vpjv-r4xm-v9c6.json | 8 ++------ .../05/GHSA-vqr2-3g8r-vf72/GHSA-vqr2-3g8r-vf72.json | 12 +++--------- .../05/GHSA-vr3x-5p25-4vw9/GHSA-vr3x-5p25-4vw9.json | 8 ++------ .../05/GHSA-vv36-cxp3-6vh8/GHSA-vv36-cxp3-6vh8.json | 8 ++------ .../05/GHSA-vvcj-m38q-p82v/GHSA-vvcj-m38q-p82v.json | 8 ++------ .../05/GHSA-vxfc-p6m6-vprf/GHSA-vxfc-p6m6-vprf.json | 12 +++--------- .../05/GHSA-w28m-9f8c-36p9/GHSA-w28m-9f8c-36p9.json | 8 ++------ .../05/GHSA-w292-3r2c-wh6c/GHSA-w292-3r2c-wh6c.json | 8 ++------ .../05/GHSA-w44h-7mvx-cpmp/GHSA-w44h-7mvx-cpmp.json | 8 ++------ .../05/GHSA-w478-8x45-v99x/GHSA-w478-8x45-v99x.json | 12 +++--------- .../05/GHSA-w496-4p5w-36v4/GHSA-w496-4p5w-36v4.json | 8 ++------ .../05/GHSA-w4hc-vqpp-rj57/GHSA-w4hc-vqpp-rj57.json | 8 ++------ .../05/GHSA-w59f-66x7-v8wv/GHSA-w59f-66x7-v8wv.json | 12 +++--------- .../05/GHSA-w5g5-g39g-7p84/GHSA-w5g5-g39g-7p84.json | 8 ++------ .../05/GHSA-w6h2-q33g-f7x5/GHSA-w6h2-q33g-f7x5.json | 8 ++------ .../05/GHSA-w6v4-7gww-w8wm/GHSA-w6v4-7gww-w8wm.json | 8 ++------ .../05/GHSA-w7xq-m6vj-6xpf/GHSA-w7xq-m6vj-6xpf.json | 12 +++--------- .../05/GHSA-w854-jxf9-rc9g/GHSA-w854-jxf9-rc9g.json | 8 ++------ .../05/GHSA-w8h2-5xj2-2jrx/GHSA-w8h2-5xj2-2jrx.json | 8 ++------ .../05/GHSA-w9fq-cmgx-h44f/GHSA-w9fq-cmgx-h44f.json | 8 ++------ .../05/GHSA-wf3w-5q4p-4cq8/GHSA-wf3w-5q4p-4cq8.json | 8 ++------ .../05/GHSA-wh68-278m-77rw/GHSA-wh68-278m-77rw.json | 8 ++------ .../05/GHSA-wj7f-q5c3-fxrc/GHSA-wj7f-q5c3-fxrc.json | 8 ++------ .../05/GHSA-wjwg-g3q4-3f25/GHSA-wjwg-g3q4-3f25.json | 8 ++------ .../05/GHSA-wjww-x723-mj8v/GHSA-wjww-x723-mj8v.json | 12 +++--------- .../05/GHSA-wmqv-c3qg-w3wr/GHSA-wmqv-c3qg-w3wr.json | 8 ++------ .../05/GHSA-wmv2-59jq-vhm3/GHSA-wmv2-59jq-vhm3.json | 8 ++------ .../05/GHSA-wmx4-5cjv-hcj2/GHSA-wmx4-5cjv-hcj2.json | 8 ++------ .../05/GHSA-wp98-jr7w-5jhh/GHSA-wp98-jr7w-5jhh.json | 8 ++------ .../05/GHSA-wphw-2cf9-9fxg/GHSA-wphw-2cf9-9fxg.json | 8 ++------ .../05/GHSA-wpph-jwhf-rw82/GHSA-wpph-jwhf-rw82.json | 12 +++--------- .../05/GHSA-wvch-gg24-mw28/GHSA-wvch-gg24-mw28.json | 8 ++------ .../05/GHSA-wvm8-ghrc-v96m/GHSA-wvm8-ghrc-v96m.json | 12 +++--------- .../05/GHSA-wwv3-h536-qwmv/GHSA-wwv3-h536-qwmv.json | 8 ++------ .../05/GHSA-x2fr-qhgr-p5jc/GHSA-x2fr-qhgr-p5jc.json | 8 ++------ .../05/GHSA-x2gf-mx86-8jq7/GHSA-x2gf-mx86-8jq7.json | 8 ++------ .../05/GHSA-x32m-pghh-vxqf/GHSA-x32m-pghh-vxqf.json | 8 ++------ .../05/GHSA-x3gf-fpp5-65hp/GHSA-x3gf-fpp5-65hp.json | 8 ++------ .../05/GHSA-x3m3-q3xc-8m5j/GHSA-x3m3-q3xc-8m5j.json | 12 +++--------- .../05/GHSA-x743-h4cc-mxrh/GHSA-x743-h4cc-mxrh.json | 8 ++------ .../05/GHSA-x745-x857-q9jc/GHSA-x745-x857-q9jc.json | 8 ++------ .../05/GHSA-x7q5-98p8-3gx3/GHSA-x7q5-98p8-3gx3.json | 8 ++------ .../05/GHSA-x7rm-43v9-j38p/GHSA-x7rm-43v9-j38p.json | 12 +++--------- .../05/GHSA-x82x-3qv6-2c36/GHSA-x82x-3qv6-2c36.json | 8 ++------ .../05/GHSA-x8mf-jq4w-r293/GHSA-x8mf-jq4w-r293.json | 12 +++--------- .../05/GHSA-x993-w3pv-6hmf/GHSA-x993-w3pv-6hmf.json | 8 ++------ .../05/GHSA-x9h2-w394-8fv9/GHSA-x9h2-w394-8fv9.json | 8 ++------ .../05/GHSA-xc55-j8g3-8x83/GHSA-xc55-j8g3-8x83.json | 8 ++------ .../05/GHSA-xf8m-j9rp-c8f4/GHSA-xf8m-j9rp-c8f4.json | 8 ++------ .../05/GHSA-xg5x-96p3-r774/GHSA-xg5x-96p3-r774.json | 8 ++------ .../05/GHSA-xgq3-h8hp-5qjg/GHSA-xgq3-h8hp-5qjg.json | 8 ++------ .../05/GHSA-xh3j-cw8c-mh94/GHSA-xh3j-cw8c-mh94.json | 8 ++------ .../05/GHSA-xhw4-5qgr-c2w2/GHSA-xhw4-5qgr-c2w2.json | 8 ++------ .../05/GHSA-xqr2-7pjv-2gjp/GHSA-xqr2-7pjv-2gjp.json | 8 ++------ .../05/GHSA-xr49-pr22-vxc8/GHSA-xr49-pr22-vxc8.json | 8 ++------ .../05/GHSA-xv49-2wgv-qvc2/GHSA-xv49-2wgv-qvc2.json | 8 ++------ .../05/GHSA-xv69-hhpr-w3r5/GHSA-xv69-hhpr-w3r5.json | 8 ++------ .../05/GHSA-xvhq-v5ww-mmhx/GHSA-xvhq-v5ww-mmhx.json | 8 ++------ .../05/GHSA-xw9f-r7rv-2cfw/GHSA-xw9f-r7rv-2cfw.json | 12 +++--------- .../05/GHSA-xxf2-85hh-x424/GHSA-xxf2-85hh-x424.json | 8 ++------ .../07/GHSA-6578-hf9h-23c9/GHSA-6578-hf9h-23c9.json | 4 +--- .../07/GHSA-mgcr-5hwm-m58m/GHSA-mgcr-5hwm-m58m.json | 4 +--- .../02/GHSA-278m-rc9v-hf3c/GHSA-278m-rc9v-hf3c.json | 4 +--- .../02/GHSA-327h-468p-mffv/GHSA-327h-468p-mffv.json | 4 +--- .../02/GHSA-38g6-vx2q-23wm/GHSA-38g6-vx2q-23wm.json | 8 ++------ .../02/GHSA-397m-2h32-p5j6/GHSA-397m-2h32-p5j6.json | 8 ++------ .../02/GHSA-42jj-9j7q-98jv/GHSA-42jj-9j7q-98jv.json | 4 +--- .../02/GHSA-528v-fv7h-v892/GHSA-528v-fv7h-v892.json | 4 +--- .../02/GHSA-5pjp-x72x-j9r3/GHSA-5pjp-x72x-j9r3.json | 8 ++------ .../02/GHSA-5vcj-fx4r-4xrv/GHSA-5vcj-fx4r-4xrv.json | 4 +--- .../02/GHSA-6hcj-xq8v-5j7j/GHSA-6hcj-xq8v-5j7j.json | 12 +++--------- .../02/GHSA-6pc7-4x73-wwc6/GHSA-6pc7-4x73-wwc6.json | 8 ++------ .../02/GHSA-747m-qmxp-h92f/GHSA-747m-qmxp-h92f.json | 4 +--- .../02/GHSA-7pp5-c4g8-xxc4/GHSA-7pp5-c4g8-xxc4.json | 4 +--- .../02/GHSA-8pq4-pmqh-grvh/GHSA-8pq4-pmqh-grvh.json | 4 +--- .../02/GHSA-8xf7-6cv9-64f7/GHSA-8xf7-6cv9-64f7.json | 4 +--- .../02/GHSA-92f7-c7hw-58cr/GHSA-92f7-c7hw-58cr.json | 4 +--- .../02/GHSA-92q5-jqvg-mhwp/GHSA-92q5-jqvg-mhwp.json | 12 +++--------- .../02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json | 8 ++------ .../02/GHSA-cf5h-fpjr-xpm5/GHSA-cf5h-fpjr-xpm5.json | 8 ++------ .../02/GHSA-f54m-q836-9rr6/GHSA-f54m-q836-9rr6.json | 4 +--- .../02/GHSA-frwj-xv69-m7pr/GHSA-frwj-xv69-m7pr.json | 8 ++------ .../02/GHSA-gp6j-7c6x-xpmx/GHSA-gp6j-7c6x-xpmx.json | 4 +--- .../02/GHSA-hxqj-hr64-7vf7/GHSA-hxqj-hr64-7vf7.json | 4 +--- .../02/GHSA-j3p2-wv5r-9x82/GHSA-j3p2-wv5r-9x82.json | 4 +--- .../02/GHSA-jhxw-wgr6-6rqc/GHSA-jhxw-wgr6-6rqc.json | 4 +--- .../02/GHSA-m32w-wmcr-wvxf/GHSA-m32w-wmcr-wvxf.json | 4 +--- .../02/GHSA-mcfj-9jjf-96q9/GHSA-mcfj-9jjf-96q9.json | 8 ++------ .../02/GHSA-p9j3-jrc9-jv9h/GHSA-p9j3-jrc9-jv9h.json | 4 +--- .../02/GHSA-pp3r-rxpr-h8mc/GHSA-pp3r-rxpr-h8mc.json | 12 +++--------- .../02/GHSA-prhj-8562-p8gj/GHSA-prhj-8562-p8gj.json | 4 +--- .../02/GHSA-prwg-rhfj-26j7/GHSA-prwg-rhfj-26j7.json | 8 ++------ .../02/GHSA-r5qg-76hh-gr9p/GHSA-r5qg-76hh-gr9p.json | 4 +--- .../02/GHSA-rfw9-hv5h-2w85/GHSA-rfw9-hv5h-2w85.json | 12 +++--------- .../02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json | 4 +--- .../02/GHSA-xfvp-h462-p6q2/GHSA-xfvp-h462-p6q2.json | 4 +--- .../03/GHSA-2cpc-3p3h-5rwq/GHSA-2cpc-3p3h-5rwq.json | 8 ++------ .../03/GHSA-2fv8-55wf-gg3v/GHSA-2fv8-55wf-gg3v.json | 4 +--- .../03/GHSA-2v7w-v8fj-mf99/GHSA-2v7w-v8fj-mf99.json | 4 +--- .../03/GHSA-33v3-2qxj-vgv5/GHSA-33v3-2qxj-vgv5.json | 12 +++--------- .../03/GHSA-35c8-rp3m-p5v6/GHSA-35c8-rp3m-p5v6.json | 8 ++------ .../03/GHSA-3gf3-x9x8-839v/GHSA-3gf3-x9x8-839v.json | 4 +--- .../03/GHSA-3pmw-h7mc-vxxq/GHSA-3pmw-h7mc-vxxq.json | 12 +++--------- .../03/GHSA-3q2c-pvp5-3cqp/GHSA-3q2c-pvp5-3cqp.json | 4 +--- .../03/GHSA-3q9p-96fp-f2w2/GHSA-3q9p-96fp-f2w2.json | 4 +--- .../03/GHSA-48q5-x6fp-8893/GHSA-48q5-x6fp-8893.json | 8 ++------ .../03/GHSA-49h9-qx93-p659/GHSA-49h9-qx93-p659.json | 4 +--- .../03/GHSA-52jg-m3rm-ch68/GHSA-52jg-m3rm-ch68.json | 4 +--- .../03/GHSA-5gr3-55rj-mm4c/GHSA-5gr3-55rj-mm4c.json | 8 ++------ .../03/GHSA-5q32-895v-vf2f/GHSA-5q32-895v-vf2f.json | 4 +--- .../03/GHSA-6847-vh78-7f9c/GHSA-6847-vh78-7f9c.json | 4 +--- .../03/GHSA-6pc8-76w2-c62h/GHSA-6pc8-76w2-c62h.json | 4 +--- .../03/GHSA-6q28-45j9-263v/GHSA-6q28-45j9-263v.json | 12 +++--------- .../03/GHSA-6xfp-26pf-r3p6/GHSA-6xfp-26pf-r3p6.json | 4 +--- .../03/GHSA-79wp-fmwh-x929/GHSA-79wp-fmwh-x929.json | 12 +++--------- .../03/GHSA-7xrf-xg7m-8rqp/GHSA-7xrf-xg7m-8rqp.json | 12 +++--------- .../03/GHSA-8p4p-wmq5-rmgp/GHSA-8p4p-wmq5-rmgp.json | 8 ++------ .../03/GHSA-8q2g-9f98-xxwf/GHSA-8q2g-9f98-xxwf.json | 4 +--- .../03/GHSA-9rrq-f95g-4wmq/GHSA-9rrq-f95g-4wmq.json | 12 +++--------- .../03/GHSA-9wr4-x5hv-2rw2/GHSA-9wr4-x5hv-2rw2.json | 8 ++------ .../03/GHSA-c23g-g2cr-qgh6/GHSA-c23g-g2cr-qgh6.json | 12 +++--------- .../03/GHSA-c52j-w2rg-37q5/GHSA-c52j-w2rg-37q5.json | 8 ++------ .../03/GHSA-c534-6v46-r777/GHSA-c534-6v46-r777.json | 8 ++------ .../03/GHSA-cf55-f79q-6cgp/GHSA-cf55-f79q-6cgp.json | 12 +++--------- .../03/GHSA-fq59-hfgc-4xp6/GHSA-fq59-hfgc-4xp6.json | 4 +--- .../03/GHSA-fvc5-hrmq-8hx4/GHSA-fvc5-hrmq-8hx4.json | 4 +--- .../03/GHSA-g754-37wh-7wv7/GHSA-g754-37wh-7wv7.json | 8 ++------ .../03/GHSA-gmmm-pvv4-ww8g/GHSA-gmmm-pvv4-ww8g.json | 4 +--- .../03/GHSA-h4rp-4mpv-g4rm/GHSA-h4rp-4mpv-g4rm.json | 4 +--- .../03/GHSA-hmvg-cx6j-hfj7/GHSA-hmvg-cx6j-hfj7.json | 12 +++--------- .../03/GHSA-hwc8-wrmm-ch4w/GHSA-hwc8-wrmm-ch4w.json | 12 +++--------- .../03/GHSA-j32g-85qg-wf4w/GHSA-j32g-85qg-wf4w.json | 4 +--- .../03/GHSA-j64p-69wq-hp65/GHSA-j64p-69wq-hp65.json | 4 +--- .../03/GHSA-j9cg-5w44-72xh/GHSA-j9cg-5w44-72xh.json | 12 +++--------- .../03/GHSA-mf3p-gmch-hc8x/GHSA-mf3p-gmch-hc8x.json | 4 +--- .../03/GHSA-mfjq-7ffc-qgmv/GHSA-mfjq-7ffc-qgmv.json | 4 +--- .../03/GHSA-mxh6-2xpg-m77w/GHSA-mxh6-2xpg-m77w.json | 8 ++------ .../03/GHSA-ph5r-c8gc-xg6f/GHSA-ph5r-c8gc-xg6f.json | 12 +++--------- .../03/GHSA-pj2q-rq9j-ffq5/GHSA-pj2q-rq9j-ffq5.json | 12 +++--------- .../03/GHSA-pjqv-pvfh-2w6m/GHSA-pjqv-pvfh-2w6m.json | 12 +++--------- .../03/GHSA-pp36-2qc2-w4hw/GHSA-pp36-2qc2-w4hw.json | 8 ++------ .../03/GHSA-pqvp-7fm6-8x84/GHSA-pqvp-7fm6-8x84.json | 4 +--- .../03/GHSA-vc6j-mx82-hrhh/GHSA-vc6j-mx82-hrhh.json | 4 +--- .../03/GHSA-vfgc-wr54-m4r5/GHSA-vfgc-wr54-m4r5.json | 4 +--- .../03/GHSA-vpgg-8ccq-gwhg/GHSA-vpgg-8ccq-gwhg.json | 8 ++------ .../03/GHSA-ww23-hvpx-hvvc/GHSA-ww23-hvpx-hvvc.json | 8 ++------ .../03/GHSA-x7cq-pgcc-cqqm/GHSA-x7cq-pgcc-cqqm.json | 4 +--- .../03/GHSA-xhm6-wpwj-qm56/GHSA-xhm6-wpwj-qm56.json | 12 +++--------- .../03/GHSA-xqc9-rv8w-5v6g/GHSA-xqc9-rv8w-5v6g.json | 4 +--- .../03/GHSA-xr82-8hm6-h468/GHSA-xr82-8hm6-h468.json | 12 +++--------- .../04/GHSA-2252-87pv-34g4/GHSA-2252-87pv-34g4.json | 12 +++--------- .../04/GHSA-29f2-7m5v-qfqv/GHSA-29f2-7m5v-qfqv.json | 4 +--- .../04/GHSA-2fv8-4462-wxh7/GHSA-2fv8-4462-wxh7.json | 12 +++--------- .../04/GHSA-2mrh-g8f4-xvjv/GHSA-2mrh-g8f4-xvjv.json | 12 +++--------- .../04/GHSA-2vqj-rxh7-chjw/GHSA-2vqj-rxh7-chjw.json | 12 +++--------- .../04/GHSA-2vvj-hm96-cr7r/GHSA-2vvj-hm96-cr7r.json | 12 +++--------- .../04/GHSA-389h-6rjg-wxc9/GHSA-389h-6rjg-wxc9.json | 12 +++--------- .../04/GHSA-3976-477p-x267/GHSA-3976-477p-x267.json | 12 +++--------- .../04/GHSA-3cm8-rv8m-x9gf/GHSA-3cm8-rv8m-x9gf.json | 4 +--- .../04/GHSA-3v83-crv9-cf9p/GHSA-3v83-crv9-cf9p.json | 12 +++--------- .../04/GHSA-3vwc-j35j-g8jv/GHSA-3vwc-j35j-g8jv.json | 4 +--- .../04/GHSA-3w4p-cp93-7566/GHSA-3w4p-cp93-7566.json | 12 +++--------- .../04/GHSA-488v-m6fm-php4/GHSA-488v-m6fm-php4.json | 8 ++------ .../04/GHSA-4965-8838-r53x/GHSA-4965-8838-r53x.json | 4 +--- .../04/GHSA-49g6-x26j-85g3/GHSA-49g6-x26j-85g3.json | 12 +++--------- .../04/GHSA-4jw4-4g69-7273/GHSA-4jw4-4g69-7273.json | 4 +--- .../04/GHSA-4m6c-v88j-qqxh/GHSA-4m6c-v88j-qqxh.json | 12 +++--------- .../04/GHSA-4p7x-7wc6-4gf5/GHSA-4p7x-7wc6-4gf5.json | 4 +--- .../04/GHSA-4r5c-7wgh-g673/GHSA-4r5c-7wgh-g673.json | 4 +--- .../04/GHSA-4wch-q26f-448q/GHSA-4wch-q26f-448q.json | 4 +--- .../04/GHSA-4xxr-7xxv-w3hj/GHSA-4xxr-7xxv-w3hj.json | 12 +++--------- .../04/GHSA-57mj-8cw4-cm9w/GHSA-57mj-8cw4-cm9w.json | 4 +--- .../04/GHSA-5cg8-xmcq-jx69/GHSA-5cg8-xmcq-jx69.json | 4 +--- .../04/GHSA-5fvw-q4g6-wqf7/GHSA-5fvw-q4g6-wqf7.json | 4 +--- .../04/GHSA-5mg2-h7qv-m552/GHSA-5mg2-h7qv-m552.json | 12 +++--------- .../04/GHSA-5r2r-xpfw-pmxc/GHSA-5r2r-xpfw-pmxc.json | 12 +++--------- .../04/GHSA-68mg-2p5r-x33h/GHSA-68mg-2p5r-x33h.json | 12 +++--------- .../04/GHSA-69h6-fpm9-fc3r/GHSA-69h6-fpm9-fc3r.json | 12 +++--------- .../04/GHSA-6fm7-55mm-8gfh/GHSA-6fm7-55mm-8gfh.json | 12 +++--------- .../04/GHSA-6m7r-j2xg-cvhq/GHSA-6m7r-j2xg-cvhq.json | 12 +++--------- .../04/GHSA-6r45-w96c-v9jx/GHSA-6r45-w96c-v9jx.json | 12 +++--------- .../04/GHSA-6vh7-f36j-r556/GHSA-6vh7-f36j-r556.json | 4 +--- .../04/GHSA-7257-c3g3-gcf6/GHSA-7257-c3g3-gcf6.json | 12 +++--------- .../04/GHSA-728g-23p2-mf29/GHSA-728g-23p2-mf29.json | 12 +++--------- .../04/GHSA-744q-w332-xxx3/GHSA-744q-w332-xxx3.json | 12 +++--------- .../04/GHSA-77mf-44mv-3m36/GHSA-77mf-44mv-3m36.json | 12 +++--------- .../04/GHSA-782j-786c-25hh/GHSA-782j-786c-25hh.json | 12 +++--------- .../04/GHSA-7g56-3wmh-7x3p/GHSA-7g56-3wmh-7x3p.json | 12 +++--------- .../04/GHSA-7j5c-w63j-h48p/GHSA-7j5c-w63j-h48p.json | 4 +--- .../04/GHSA-7mjh-m8r7-cjw8/GHSA-7mjh-m8r7-cjw8.json | 12 +++--------- .../04/GHSA-7vqv-4gqw-665q/GHSA-7vqv-4gqw-665q.json | 12 +++--------- .../04/GHSA-7xpv-78qx-q843/GHSA-7xpv-78qx-q843.json | 12 +++--------- .../04/GHSA-7xq6-jm62-ww8g/GHSA-7xq6-jm62-ww8g.json | 12 +++--------- .../04/GHSA-825r-gh5g-48mg/GHSA-825r-gh5g-48mg.json | 12 +++--------- .../04/GHSA-8cvr-95g2-c2x2/GHSA-8cvr-95g2-c2x2.json | 4 +--- .../04/GHSA-8f6m-26fj-7fm5/GHSA-8f6m-26fj-7fm5.json | 12 +++--------- .../04/GHSA-8mj5-8fhj-855x/GHSA-8mj5-8fhj-855x.json | 12 +++--------- .../04/GHSA-8p54-55f6-pg9j/GHSA-8p54-55f6-pg9j.json | 4 +--- .../04/GHSA-8vch-c6pw-5chh/GHSA-8vch-c6pw-5chh.json | 8 ++------ .../04/GHSA-8vf4-q8g2-79g5/GHSA-8vf4-q8g2-79g5.json | 12 +++--------- .../04/GHSA-9493-4f82-9rx5/GHSA-9493-4f82-9rx5.json | 12 +++--------- .../04/GHSA-96gr-7mgw-2637/GHSA-96gr-7mgw-2637.json | 12 +++--------- .../04/GHSA-98m4-jppc-qq3m/GHSA-98m4-jppc-qq3m.json | 12 +++--------- .../04/GHSA-9fvf-9v35-97qv/GHSA-9fvf-9v35-97qv.json | 4 +--- .../04/GHSA-9pfj-cx2g-pfp8/GHSA-9pfj-cx2g-pfp8.json | 4 +--- .../04/GHSA-9q92-r559-g8xx/GHSA-9q92-r559-g8xx.json | 12 +++--------- .../04/GHSA-9r85-wp9w-jjwp/GHSA-9r85-wp9w-jjwp.json | 4 +--- .../04/GHSA-9rp8-67w7-gf47/GHSA-9rp8-67w7-gf47.json | 8 ++------ .../04/GHSA-9xp8-8c5r-6wfh/GHSA-9xp8-8c5r-6wfh.json | 12 +++--------- .../04/GHSA-c8f2-2f6p-gpgc/GHSA-c8f2-2f6p-gpgc.json | 12 +++--------- .../04/GHSA-c8hq-5hxw-3w26/GHSA-c8hq-5hxw-3w26.json | 8 ++------ .../04/GHSA-c8v3-wvcw-2g23/GHSA-c8v3-wvcw-2g23.json | 8 ++------ .../04/GHSA-cw6h-gvcj-ww9c/GHSA-cw6h-gvcj-ww9c.json | 4 +--- .../04/GHSA-cwr2-26gq-v2xr/GHSA-cwr2-26gq-v2xr.json | 12 +++--------- .../04/GHSA-f34w-8j75-rh85/GHSA-f34w-8j75-rh85.json | 12 +++--------- .../04/GHSA-fp6w-hx4c-x44g/GHSA-fp6w-hx4c-x44g.json | 12 +++--------- .../04/GHSA-fvq5-hfcg-2qjg/GHSA-fvq5-hfcg-2qjg.json | 12 +++--------- .../04/GHSA-g2rp-ppxj-jr95/GHSA-g2rp-ppxj-jr95.json | 4 +--- .../04/GHSA-g638-g65r-64rm/GHSA-g638-g65r-64rm.json | 12 +++--------- .../04/GHSA-g65w-rrjg-vx49/GHSA-g65w-rrjg-vx49.json | 12 +++--------- .../04/GHSA-g993-hcw2-pmmf/GHSA-g993-hcw2-pmmf.json | 12 +++--------- .../04/GHSA-gr67-xmxc-qw6m/GHSA-gr67-xmxc-qw6m.json | 8 ++------ .../04/GHSA-gvgx-pcvr-3pc4/GHSA-gvgx-pcvr-3pc4.json | 12 +++--------- .../04/GHSA-h38m-55w3-wc8q/GHSA-h38m-55w3-wc8q.json | 8 ++------ .../04/GHSA-h4jh-5vqp-vw3p/GHSA-h4jh-5vqp-vw3p.json | 12 +++--------- .../04/GHSA-h63r-7v46-7432/GHSA-h63r-7v46-7432.json | 4 +--- .../04/GHSA-hpjm-r5wj-2jq3/GHSA-hpjm-r5wj-2jq3.json | 12 +++--------- .../04/GHSA-hq4g-8jp3-v42r/GHSA-hq4g-8jp3-v42r.json | 4 +--- .../04/GHSA-j648-rgv6-ccc8/GHSA-j648-rgv6-ccc8.json | 12 +++--------- .../04/GHSA-j68j-2qh2-c4cq/GHSA-j68j-2qh2-c4cq.json | 8 ++------ .../04/GHSA-jg3j-8qg2-gph3/GHSA-jg3j-8qg2-gph3.json | 12 +++--------- .../04/GHSA-jg7c-h6xh-f8hr/GHSA-jg7c-h6xh-f8hr.json | 12 +++--------- .../04/GHSA-jj2v-2j63-rcwf/GHSA-jj2v-2j63-rcwf.json | 12 +++--------- .../04/GHSA-jv96-qfmj-26f9/GHSA-jv96-qfmj-26f9.json | 12 +++--------- .../04/GHSA-jwqh-57hr-2ggg/GHSA-jwqh-57hr-2ggg.json | 4 +--- .../04/GHSA-m6wx-5x43-45rq/GHSA-m6wx-5x43-45rq.json | 4 +--- .../04/GHSA-mhpf-x66q-8p92/GHSA-mhpf-x66q-8p92.json | 8 ++------ .../04/GHSA-mqqf-w892-86vp/GHSA-mqqf-w892-86vp.json | 4 +--- .../04/GHSA-mvgr-2rgh-283w/GHSA-mvgr-2rgh-283w.json | 4 +--- .../04/GHSA-mw2r-2h6j-6g7v/GHSA-mw2r-2h6j-6g7v.json | 12 +++--------- .../04/GHSA-mw3g-jr7f-3gg4/GHSA-mw3g-jr7f-3gg4.json | 12 +++--------- .../04/GHSA-p33p-qh45-v5wf/GHSA-p33p-qh45-v5wf.json | 4 +--- .../04/GHSA-p37h-v38c-f75w/GHSA-p37h-v38c-f75w.json | 4 +--- .../04/GHSA-p46w-8mq5-8mgj/GHSA-p46w-8mq5-8mgj.json | 12 +++--------- .../04/GHSA-p8g6-7v7w-4whg/GHSA-p8g6-7v7w-4whg.json | 12 +++--------- .../04/GHSA-pfjp-fv5p-fjx7/GHSA-pfjp-fv5p-fjx7.json | 12 +++--------- .../04/GHSA-pgc5-vrj2-c9w5/GHSA-pgc5-vrj2-c9w5.json | 12 +++--------- .../04/GHSA-pvq9-49j8-h86c/GHSA-pvq9-49j8-h86c.json | 8 ++------ .../04/GHSA-pxc4-f9p3-54rp/GHSA-pxc4-f9p3-54rp.json | 8 ++------ .../04/GHSA-q342-fw2j-5cj8/GHSA-q342-fw2j-5cj8.json | 12 +++--------- .../04/GHSA-qg9h-x99x-fcvh/GHSA-qg9h-x99x-fcvh.json | 12 +++--------- .../04/GHSA-qjvp-25fj-gf6v/GHSA-qjvp-25fj-gf6v.json | 12 +++--------- .../04/GHSA-qp44-g28j-qgqp/GHSA-qp44-g28j-qgqp.json | 4 +--- .../04/GHSA-qp64-mm58-qpcj/GHSA-qp64-mm58-qpcj.json | 12 +++--------- .../04/GHSA-qv7c-pjpr-grqx/GHSA-qv7c-pjpr-grqx.json | 12 +++--------- .../04/GHSA-qvjm-pcpv-593p/GHSA-qvjm-pcpv-593p.json | 12 +++--------- .../04/GHSA-r74x-hfrh-mh6j/GHSA-r74x-hfrh-mh6j.json | 4 +--- .../04/GHSA-rm2h-rx39-6fc3/GHSA-rm2h-rx39-6fc3.json | 12 +++--------- .../04/GHSA-rvjh-mwxw-g897/GHSA-rvjh-mwxw-g897.json | 4 +--- .../04/GHSA-rw75-4jcc-fx6w/GHSA-rw75-4jcc-fx6w.json | 12 +++--------- .../04/GHSA-v6fp-9fjm-v48v/GHSA-v6fp-9fjm-v48v.json | 4 +--- .../04/GHSA-v854-7g2j-4x32/GHSA-v854-7g2j-4x32.json | 12 +++--------- .../04/GHSA-vh2f-wj96-fxxh/GHSA-vh2f-wj96-fxxh.json | 4 +--- .../04/GHSA-vmh5-6rg4-ggmq/GHSA-vmh5-6rg4-ggmq.json | 4 +--- .../04/GHSA-vmhf-rfw6-gg6x/GHSA-vmhf-rfw6-gg6x.json | 12 +++--------- .../04/GHSA-vrrq-3f8j-8672/GHSA-vrrq-3f8j-8672.json | 12 +++--------- .../04/GHSA-vx76-2j88-69mq/GHSA-vx76-2j88-69mq.json | 12 +++--------- .../04/GHSA-w255-5hjq-7p69/GHSA-w255-5hjq-7p69.json | 12 +++--------- .../04/GHSA-w69g-9g23-pfwc/GHSA-w69g-9g23-pfwc.json | 4 +--- .../04/GHSA-w9mj-34hr-82rj/GHSA-w9mj-34hr-82rj.json | 12 +++--------- .../04/GHSA-wfcg-p9mh-53w7/GHSA-wfcg-p9mh-53w7.json | 12 +++--------- .../04/GHSA-wm8x-c4gv-vvw5/GHSA-wm8x-c4gv-vvw5.json | 12 +++--------- .../04/GHSA-wvf9-x8f3-rgpr/GHSA-wvf9-x8f3-rgpr.json | 8 ++------ .../04/GHSA-wwjm-jqc7-c985/GHSA-wwjm-jqc7-c985.json | 4 +--- .../04/GHSA-x246-w3fc-9p6h/GHSA-x246-w3fc-9p6h.json | 4 +--- .../04/GHSA-x8m6-m5rq-285x/GHSA-x8m6-m5rq-285x.json | 4 +--- .../04/GHSA-xfq9-hwv6-6j67/GHSA-xfq9-hwv6-6j67.json | 4 +--- .../04/GHSA-xg7r-7865-v6c7/GHSA-xg7r-7865-v6c7.json | 12 +++--------- .../04/GHSA-xhg5-m3mp-pf34/GHSA-xhg5-m3mp-pf34.json | 4 +--- .../04/GHSA-xhj3-2vvm-6mr5/GHSA-xhj3-2vvm-6mr5.json | 12 +++--------- .../04/GHSA-xqrq-q336-f78g/GHSA-xqrq-q336-f78g.json | 12 +++--------- .../04/GHSA-xqvp-j58f-pjf5/GHSA-xqvp-j58f-pjf5.json | 12 +++--------- .../04/GHSA-xvjp-2q6g-h878/GHSA-xvjp-2q6g-h878.json | 12 +++--------- .../05/GHSA-2cf6-4ffg-wwcf/GHSA-2cf6-4ffg-wwcf.json | 12 +++--------- .../05/GHSA-2fxm-8374-c95m/GHSA-2fxm-8374-c95m.json | 4 +--- .../05/GHSA-2gxx-2hcr-3whr/GHSA-2gxx-2hcr-3whr.json | 12 +++--------- .../05/GHSA-2j3v-48pv-mvcj/GHSA-2j3v-48pv-mvcj.json | 12 +++--------- .../05/GHSA-2pp7-rwqg-2gcx/GHSA-2pp7-rwqg-2gcx.json | 12 +++--------- .../05/GHSA-2wxq-wgqp-xrwm/GHSA-2wxq-wgqp-xrwm.json | 12 +++--------- .../05/GHSA-2x59-7x95-wr65/GHSA-2x59-7x95-wr65.json | 12 +++--------- .../05/GHSA-2xv3-4xmw-7ff2/GHSA-2xv3-4xmw-7ff2.json | 12 +++--------- .../05/GHSA-3cff-7cgm-mf7g/GHSA-3cff-7cgm-mf7g.json | 12 +++--------- .../05/GHSA-3p2h-8x46-gvg6/GHSA-3p2h-8x46-gvg6.json | 12 +++--------- .../05/GHSA-3pwm-r3r4-xpvf/GHSA-3pwm-r3r4-xpvf.json | 12 +++--------- .../05/GHSA-3qr9-g9f2-22xh/GHSA-3qr9-g9f2-22xh.json | 12 +++--------- .../05/GHSA-3r4r-jmwh-rccm/GHSA-3r4r-jmwh-rccm.json | 12 +++--------- .../05/GHSA-576q-7774-8vcq/GHSA-576q-7774-8vcq.json | 12 +++--------- .../05/GHSA-58c4-h2gx-8qfv/GHSA-58c4-h2gx-8qfv.json | 4 +--- .../05/GHSA-5h68-7cjq-vgrx/GHSA-5h68-7cjq-vgrx.json | 4 +--- .../05/GHSA-5hhv-hrg6-cwc7/GHSA-5hhv-hrg6-cwc7.json | 12 +++--------- .../05/GHSA-5jrf-78p7-hw2r/GHSA-5jrf-78p7-hw2r.json | 12 +++--------- .../05/GHSA-5xmm-chg9-ppmr/GHSA-5xmm-chg9-ppmr.json | 12 +++--------- .../05/GHSA-68x5-x32c-8c8w/GHSA-68x5-x32c-8c8w.json | 12 +++--------- .../05/GHSA-6f8x-5hmv-67rj/GHSA-6f8x-5hmv-67rj.json | 12 +++--------- .../05/GHSA-6wq5-2j9j-6rvr/GHSA-6wq5-2j9j-6rvr.json | 4 +--- .../05/GHSA-72f9-x2qq-3795/GHSA-72f9-x2qq-3795.json | 12 +++--------- .../05/GHSA-733v-mpm2-5g48/GHSA-733v-mpm2-5g48.json | 12 +++--------- .../05/GHSA-7533-c28p-jp9p/GHSA-7533-c28p-jp9p.json | 12 +++--------- .../05/GHSA-767c-45p6-hv5q/GHSA-767c-45p6-hv5q.json | 12 +++--------- .../05/GHSA-76g6-5v2w-pw2h/GHSA-76g6-5v2w-pw2h.json | 12 +++--------- .../05/GHSA-7grp-x8pq-wh35/GHSA-7grp-x8pq-wh35.json | 12 +++--------- .../05/GHSA-7hxp-v79h-r4fw/GHSA-7hxp-v79h-r4fw.json | 12 +++--------- .../05/GHSA-7prj-h6r4-gh9j/GHSA-7prj-h6r4-gh9j.json | 12 +++--------- .../05/GHSA-7prp-hfw8-9qcp/GHSA-7prp-hfw8-9qcp.json | 12 +++--------- .../05/GHSA-7wx4-4999-cgfj/GHSA-7wx4-4999-cgfj.json | 12 +++--------- .../05/GHSA-7x33-7jjx-2gmh/GHSA-7x33-7jjx-2gmh.json | 8 ++------ .../05/GHSA-8crr-8542-6rh6/GHSA-8crr-8542-6rh6.json | 12 +++--------- .../05/GHSA-8j29-hrg8-7mvc/GHSA-8j29-hrg8-7mvc.json | 12 +++--------- .../05/GHSA-8j5q-6cq4-63x9/GHSA-8j5q-6cq4-63x9.json | 4 +--- .../05/GHSA-8r5m-pqvh-q2vm/GHSA-8r5m-pqvh-q2vm.json | 12 +++--------- .../05/GHSA-8r78-c2f2-82qm/GHSA-8r78-c2f2-82qm.json | 8 ++------ .../05/GHSA-8v7x-4vvg-pgr3/GHSA-8v7x-4vvg-pgr3.json | 12 +++--------- .../05/GHSA-93cv-5m73-q9h8/GHSA-93cv-5m73-q9h8.json | 12 +++--------- .../05/GHSA-97fh-3x83-fvh6/GHSA-97fh-3x83-fvh6.json | 12 +++--------- .../05/GHSA-9mvv-jgf2-gj5c/GHSA-9mvv-jgf2-gj5c.json | 12 +++--------- .../05/GHSA-9qcj-9374-gfhc/GHSA-9qcj-9374-gfhc.json | 12 +++--------- .../05/GHSA-9vv7-jc87-x8x5/GHSA-9vv7-jc87-x8x5.json | 12 +++--------- .../05/GHSA-9vvj-gw7c-qgmh/GHSA-9vvj-gw7c-qgmh.json | 12 +++--------- .../05/GHSA-c352-9339-wrc2/GHSA-c352-9339-wrc2.json | 12 +++--------- .../05/GHSA-cf9c-p3v8-r72c/GHSA-cf9c-p3v8-r72c.json | 12 +++--------- .../05/GHSA-chwm-xp9x-8vv7/GHSA-chwm-xp9x-8vv7.json | 12 +++--------- .../05/GHSA-cw5r-8wj2-xpqf/GHSA-cw5r-8wj2-xpqf.json | 12 +++--------- .../05/GHSA-cwq4-fr9x-6844/GHSA-cwq4-fr9x-6844.json | 12 +++--------- .../05/GHSA-frc8-7f65-3g5r/GHSA-frc8-7f65-3g5r.json | 12 +++--------- .../05/GHSA-fvjh-jw4x-5w6j/GHSA-fvjh-jw4x-5w6j.json | 12 +++--------- .../05/GHSA-fwq5-vg2m-5cr5/GHSA-fwq5-vg2m-5cr5.json | 12 +++--------- .../05/GHSA-g77r-j94w-3wm3/GHSA-g77r-j94w-3wm3.json | 8 ++------ .../05/GHSA-g8c8-mwvp-jcrr/GHSA-g8c8-mwvp-jcrr.json | 12 +++--------- .../05/GHSA-gcw5-rpqg-f587/GHSA-gcw5-rpqg-f587.json | 12 +++--------- .../05/GHSA-gmgh-9qgw-5r7q/GHSA-gmgh-9qgw-5r7q.json | 12 +++--------- .../05/GHSA-gpvh-jcjq-x69v/GHSA-gpvh-jcjq-x69v.json | 12 +++--------- .../05/GHSA-gv6c-55ww-r8wv/GHSA-gv6c-55ww-r8wv.json | 12 +++--------- .../05/GHSA-gw29-2hc7-pv7h/GHSA-gw29-2hc7-pv7h.json | 12 +++--------- .../05/GHSA-h2gq-cg6c-vh9c/GHSA-h2gq-cg6c-vh9c.json | 12 +++--------- .../05/GHSA-h37j-8pp8-r22g/GHSA-h37j-8pp8-r22g.json | 4 +--- .../05/GHSA-h5cg-5c4w-8jch/GHSA-h5cg-5c4w-8jch.json | 12 +++--------- .../05/GHSA-h7cv-m349-g3xp/GHSA-h7cv-m349-g3xp.json | 12 +++--------- .../05/GHSA-h8c3-hrx9-cf8g/GHSA-h8c3-hrx9-cf8g.json | 12 +++--------- .../05/GHSA-h938-55xf-p3vh/GHSA-h938-55xf-p3vh.json | 12 +++--------- .../05/GHSA-h98m-4vr6-fqjf/GHSA-h98m-4vr6-fqjf.json | 4 +--- .../05/GHSA-hgcx-34qp-j38m/GHSA-hgcx-34qp-j38m.json | 12 +++--------- .../05/GHSA-hh96-p296-x7m4/GHSA-hh96-p296-x7m4.json | 4 +--- .../05/GHSA-hm85-cqwx-6v52/GHSA-hm85-cqwx-6v52.json | 4 +--- .../05/GHSA-hmqq-g55h-wvgf/GHSA-hmqq-g55h-wvgf.json | 12 +++--------- .../05/GHSA-hwgv-6mjr-cw48/GHSA-hwgv-6mjr-cw48.json | 12 +++--------- .../05/GHSA-hxgr-6xc2-q9mv/GHSA-hxgr-6xc2-q9mv.json | 12 +++--------- .../05/GHSA-j77x-x992-6j7f/GHSA-j77x-x992-6j7f.json | 12 +++--------- .../05/GHSA-jgx8-h977-4wfh/GHSA-jgx8-h977-4wfh.json | 12 +++--------- .../05/GHSA-jhvm-33ww-x3q9/GHSA-jhvm-33ww-x3q9.json | 12 +++--------- .../05/GHSA-jp9q-c7f4-2fxf/GHSA-jp9q-c7f4-2fxf.json | 12 +++--------- .../05/GHSA-jv5m-87g4-wp39/GHSA-jv5m-87g4-wp39.json | 12 +++--------- .../05/GHSA-m923-55g6-m66q/GHSA-m923-55g6-m66q.json | 12 +++--------- .../05/GHSA-mfqx-8929-rf3c/GHSA-mfqx-8929-rf3c.json | 12 +++--------- .../05/GHSA-mvq3-v998-w43f/GHSA-mvq3-v998-w43f.json | 12 +++--------- .../05/GHSA-mxqp-c4m3-mg6r/GHSA-mxqp-c4m3-mg6r.json | 12 +++--------- .../05/GHSA-p3gx-mhhh-v7wr/GHSA-p3gx-mhhh-v7wr.json | 12 +++--------- .../05/GHSA-p672-9qr7-4cmf/GHSA-p672-9qr7-4cmf.json | 8 ++------ .../05/GHSA-p6xg-gj77-6vpg/GHSA-p6xg-gj77-6vpg.json | 12 +++--------- .../05/GHSA-p9xp-vch3-fpjp/GHSA-p9xp-vch3-fpjp.json | 12 +++--------- .../05/GHSA-pcw4-494r-vqvf/GHSA-pcw4-494r-vqvf.json | 12 +++--------- .../05/GHSA-pxvx-632v-2p4v/GHSA-pxvx-632v-2p4v.json | 12 +++--------- .../05/GHSA-q2m9-j68q-x65j/GHSA-q2m9-j68q-x65j.json | 12 +++--------- .../05/GHSA-q557-gm3j-fg4w/GHSA-q557-gm3j-fg4w.json | 12 +++--------- .../05/GHSA-qc4m-rx2p-hrfv/GHSA-qc4m-rx2p-hrfv.json | 4 +--- .../05/GHSA-qfqw-rh34-r78m/GHSA-qfqw-rh34-r78m.json | 4 +--- .../05/GHSA-qgwv-qgmf-mmf4/GHSA-qgwv-qgmf-mmf4.json | 12 +++--------- .../05/GHSA-qppw-2696-658w/GHSA-qppw-2696-658w.json | 4 +--- .../05/GHSA-qrj2-26jq-rq86/GHSA-qrj2-26jq-rq86.json | 4 +--- .../05/GHSA-qrxg-6w43-8h52/GHSA-qrxg-6w43-8h52.json | 12 +++--------- .../05/GHSA-qwvj-5fwc-qxf7/GHSA-qwvj-5fwc-qxf7.json | 8 ++------ .../05/GHSA-r5hp-gwxj-3824/GHSA-r5hp-gwxj-3824.json | 12 +++--------- .../05/GHSA-r823-qmw9-v7xf/GHSA-r823-qmw9-v7xf.json | 12 +++--------- .../05/GHSA-rc69-h6px-vf8q/GHSA-rc69-h6px-vf8q.json | 12 +++--------- .../05/GHSA-rhrr-35q8-4p7f/GHSA-rhrr-35q8-4p7f.json | 4 +--- .../05/GHSA-rq88-rprp-wpfq/GHSA-rq88-rprp-wpfq.json | 12 +++--------- .../05/GHSA-rqgx-53jr-xx5j/GHSA-rqgx-53jr-xx5j.json | 12 +++--------- .../05/GHSA-rv5x-862j-q6f6/GHSA-rv5x-862j-q6f6.json | 12 +++--------- .../05/GHSA-rwq9-67rv-755x/GHSA-rwq9-67rv-755x.json | 12 +++--------- .../05/GHSA-rwr5-hmxr-6v8j/GHSA-rwr5-hmxr-6v8j.json | 12 +++--------- .../05/GHSA-w8h9-x2qc-v5qf/GHSA-w8h9-x2qc-v5qf.json | 4 +--- .../05/GHSA-w8wx-3v4m-pwrr/GHSA-w8wx-3v4m-pwrr.json | 12 +++--------- .../05/GHSA-w9fv-gm94-h938/GHSA-w9fv-gm94-h938.json | 12 +++--------- .../05/GHSA-wmmp-mchh-75gf/GHSA-wmmp-mchh-75gf.json | 12 +++--------- .../05/GHSA-wpg8-rfjm-9g3w/GHSA-wpg8-rfjm-9g3w.json | 12 +++--------- .../05/GHSA-ww8p-33xg-gvhc/GHSA-ww8p-33xg-gvhc.json | 12 +++--------- .../05/GHSA-x5rp-2v68-jcgf/GHSA-x5rp-2v68-jcgf.json | 12 +++--------- .../05/GHSA-x5vm-26pp-xff5/GHSA-x5vm-26pp-xff5.json | 12 +++--------- .../05/GHSA-x632-g56x-qcm8/GHSA-x632-g56x-qcm8.json | 8 ++------ .../05/GHSA-xchp-7x95-36g7/GHSA-xchp-7x95-36g7.json | 12 +++--------- .../05/GHSA-xhh8-8jq9-8vf6/GHSA-xhh8-8jq9-8vf6.json | 12 +++--------- .../05/GHSA-xj3r-45pc-vrfq/GHSA-xj3r-45pc-vrfq.json | 12 +++--------- .../05/GHSA-xwvh-fxhh-3qrr/GHSA-xwvh-fxhh-3qrr.json | 12 +++--------- .../06/GHSA-4x39-cp3h-x8w9/GHSA-4x39-cp3h-x8w9.json | 4 +--- .../06/GHSA-7g9c-87vj-jrwv/GHSA-7g9c-87vj-jrwv.json | 4 +--- .../06/GHSA-7rxg-g96w-25cm/GHSA-7rxg-g96w-25cm.json | 4 +--- .../06/GHSA-8g25-xmmm-86qm/GHSA-8g25-xmmm-86qm.json | 4 +--- .../06/GHSA-9jv6-43px-5ccm/GHSA-9jv6-43px-5ccm.json | 4 +--- .../06/GHSA-f44g-xj93-9xvh/GHSA-f44g-xj93-9xvh.json | 4 +--- .../06/GHSA-g43w-r373-4crq/GHSA-g43w-r373-4crq.json | 4 +--- .../06/GHSA-g8hw-97v7-43q8/GHSA-g8hw-97v7-43q8.json | 4 +--- .../06/GHSA-m35v-cvxx-vrm6/GHSA-m35v-cvxx-vrm6.json | 4 +--- .../06/GHSA-p4gw-x82g-6gc3/GHSA-p4gw-x82g-6gc3.json | 4 +--- .../06/GHSA-vhcq-jvfq-4j3q/GHSA-vhcq-jvfq-4j3q.json | 4 +--- .../06/GHSA-w6v3-mr4g-vph6/GHSA-w6v3-mr4g-vph6.json | 4 +--- .../06/GHSA-wqp4-7xmq-ww2w/GHSA-wqp4-7xmq-ww2w.json | 4 +--- .../07/GHSA-jjpv-jrvp-jwr3/GHSA-jjpv-jrvp-jwr3.json | 4 +--- .../08/GHSA-2m3v-5ccr-mrmf/GHSA-2m3v-5ccr-mrmf.json | 4 +--- .../08/GHSA-2xh5-xw95-xh7p/GHSA-2xh5-xw95-xh7p.json | 4 +--- .../08/GHSA-3p4c-mxjg-9xjw/GHSA-3p4c-mxjg-9xjw.json | 4 +--- .../08/GHSA-455v-j4c3-4fqr/GHSA-455v-j4c3-4fqr.json | 4 +--- .../08/GHSA-4g6m-wpfm-pfxv/GHSA-4g6m-wpfm-pfxv.json | 4 +--- .../08/GHSA-7q35-9gpc-jf7h/GHSA-7q35-9gpc-jf7h.json | 4 +--- .../08/GHSA-7xq9-rvv2-9fv6/GHSA-7xq9-rvv2-9fv6.json | 4 +--- .../08/GHSA-97qg-qg86-6rpm/GHSA-97qg-qg86-6rpm.json | 4 +--- .../08/GHSA-pvqw-crx4-ggmg/GHSA-pvqw-crx4-ggmg.json | 4 +--- .../08/GHSA-qhg4-f6mr-54g9/GHSA-qhg4-f6mr-54g9.json | 4 +--- .../08/GHSA-qq6w-9496-259j/GHSA-qq6w-9496-259j.json | 4 +--- .../09/GHSA-259g-6529-jqq8/GHSA-259g-6529-jqq8.json | 4 +--- .../09/GHSA-279c-3782-hjv5/GHSA-279c-3782-hjv5.json | 4 +--- .../09/GHSA-2x6j-v6mv-vf98/GHSA-2x6j-v6mv-vf98.json | 4 +--- .../09/GHSA-36pg-hxf8-378v/GHSA-36pg-hxf8-378v.json | 4 +--- .../09/GHSA-3cmw-x7g9-558m/GHSA-3cmw-x7g9-558m.json | 4 +--- .../09/GHSA-3ffp-ffxg-jv46/GHSA-3ffp-ffxg-jv46.json | 4 +--- .../09/GHSA-3j8x-8x9q-3m4r/GHSA-3j8x-8x9q-3m4r.json | 4 +--- .../09/GHSA-52r8-phxr-cfq6/GHSA-52r8-phxr-cfq6.json | 4 +--- .../09/GHSA-55jp-9v82-mrww/GHSA-55jp-9v82-mrww.json | 4 +--- .../09/GHSA-5rpv-45rh-6r87/GHSA-5rpv-45rh-6r87.json | 4 +--- .../09/GHSA-5wmr-r266-pc3m/GHSA-5wmr-r266-pc3m.json | 8 ++------ .../09/GHSA-65wq-28c3-vwcw/GHSA-65wq-28c3-vwcw.json | 4 +--- .../09/GHSA-6f83-4pfw-m3vj/GHSA-6f83-4pfw-m3vj.json | 4 +--- .../09/GHSA-6m68-q6g7-pg37/GHSA-6m68-q6g7-pg37.json | 4 +--- .../09/GHSA-6p4p-f7m9-43rh/GHSA-6p4p-f7m9-43rh.json | 4 +--- .../09/GHSA-6pj4-296c-2375/GHSA-6pj4-296c-2375.json | 4 +--- .../09/GHSA-7q39-g4rg-578j/GHSA-7q39-g4rg-578j.json | 4 +--- .../09/GHSA-7r6c-3p49-xqvv/GHSA-7r6c-3p49-xqvv.json | 4 +--- .../09/GHSA-88gp-qchm-x67w/GHSA-88gp-qchm-x67w.json | 4 +--- .../09/GHSA-8vp8-g29r-fxpf/GHSA-8vp8-g29r-fxpf.json | 4 +--- .../09/GHSA-8x2h-c9mx-cx2j/GHSA-8x2h-c9mx-cx2j.json | 4 +--- .../09/GHSA-9362-9gf3-j66g/GHSA-9362-9gf3-j66g.json | 4 +--- .../09/GHSA-94pj-f953-73h5/GHSA-94pj-f953-73h5.json | 4 +--- .../09/GHSA-99qx-qpwq-jm99/GHSA-99qx-qpwq-jm99.json | 4 +--- .../09/GHSA-c2c6-68mw-462f/GHSA-c2c6-68mw-462f.json | 4 +--- .../09/GHSA-ch3p-mhx6-fjx9/GHSA-ch3p-mhx6-fjx9.json | 4 +--- .../09/GHSA-cwjv-mxfr-rrv9/GHSA-cwjv-mxfr-rrv9.json | 4 +--- .../09/GHSA-cwqr-9j7q-r9xh/GHSA-cwqr-9j7q-r9xh.json | 4 +--- .../09/GHSA-f78v-vf29-36gj/GHSA-f78v-vf29-36gj.json | 4 +--- .../09/GHSA-f7q4-w36g-9gxm/GHSA-f7q4-w36g-9gxm.json | 4 +--- .../09/GHSA-f95m-8pg6-37q7/GHSA-f95m-8pg6-37q7.json | 4 +--- .../09/GHSA-f9m9-68wf-ppcf/GHSA-f9m9-68wf-ppcf.json | 4 +--- .../09/GHSA-fvcf-hj7v-3mj6/GHSA-fvcf-hj7v-3mj6.json | 4 +--- .../09/GHSA-fxq3-rjrf-gqq3/GHSA-fxq3-rjrf-gqq3.json | 4 +--- .../09/GHSA-g922-hx36-gr43/GHSA-g922-hx36-gr43.json | 4 +--- .../09/GHSA-gjx4-p4f2-33wq/GHSA-gjx4-p4f2-33wq.json | 4 +--- .../09/GHSA-gq6r-xfpw-cg3w/GHSA-gq6r-xfpw-cg3w.json | 4 +--- .../09/GHSA-gwp5-2fcr-m24v/GHSA-gwp5-2fcr-m24v.json | 4 +--- .../09/GHSA-h287-xx77-94v5/GHSA-h287-xx77-94v5.json | 4 +--- .../09/GHSA-h66g-2x3f-vgpp/GHSA-h66g-2x3f-vgpp.json | 4 +--- .../09/GHSA-hr8m-c45c-9928/GHSA-hr8m-c45c-9928.json | 4 +--- .../09/GHSA-j4g8-8jw2-7ww9/GHSA-j4g8-8jw2-7ww9.json | 4 +--- .../09/GHSA-j6pg-h597-gcx9/GHSA-j6pg-h597-gcx9.json | 4 +--- .../09/GHSA-m5wh-wcvg-3f5f/GHSA-m5wh-wcvg-3f5f.json | 4 +--- .../09/GHSA-m6pw-mqxx-frjv/GHSA-m6pw-mqxx-frjv.json | 4 +--- .../09/GHSA-m74p-p5fp-95cw/GHSA-m74p-p5fp-95cw.json | 4 +--- .../09/GHSA-mgc5-p43f-72pc/GHSA-mgc5-p43f-72pc.json | 4 +--- .../09/GHSA-mxf3-c3v5-9jpv/GHSA-mxf3-c3v5-9jpv.json | 4 +--- .../09/GHSA-p64c-2wr6-h7wf/GHSA-p64c-2wr6-h7wf.json | 4 +--- .../09/GHSA-pcx7-83rx-78c2/GHSA-pcx7-83rx-78c2.json | 4 +--- .../09/GHSA-pr27-f9rc-q4vm/GHSA-pr27-f9rc-q4vm.json | 4 +--- .../09/GHSA-qmm9-m4wr-gv24/GHSA-qmm9-m4wr-gv24.json | 4 +--- .../09/GHSA-qmr2-j5m9-cq3m/GHSA-qmr2-j5m9-cq3m.json | 4 +--- .../09/GHSA-r3xc-mh5x-gjfq/GHSA-r3xc-mh5x-gjfq.json | 4 +--- .../09/GHSA-r7mf-5w8w-4x2h/GHSA-r7mf-5w8w-4x2h.json | 4 +--- .../09/GHSA-rccv-3qjv-c8h5/GHSA-rccv-3qjv-c8h5.json | 4 +--- .../09/GHSA-rmrm-52j9-f57q/GHSA-rmrm-52j9-f57q.json | 4 +--- .../09/GHSA-v596-cf8q-xgjv/GHSA-v596-cf8q-xgjv.json | 4 +--- .../09/GHSA-v63p-x2p8-f754/GHSA-v63p-x2p8-f754.json | 4 +--- .../09/GHSA-vhfh-pcg2-m599/GHSA-vhfh-pcg2-m599.json | 4 +--- .../09/GHSA-vpc7-hmh5-3wx6/GHSA-vpc7-hmh5-3wx6.json | 4 +--- .../09/GHSA-vrm8-8c2f-82r7/GHSA-vrm8-8c2f-82r7.json | 4 +--- .../09/GHSA-w37h-c34c-gwjm/GHSA-w37h-c34c-gwjm.json | 4 +--- .../09/GHSA-w3mf-5j8r-pqhw/GHSA-w3mf-5j8r-pqhw.json | 4 +--- .../09/GHSA-wx49-gvfc-fhrp/GHSA-wx49-gvfc-fhrp.json | 4 +--- .../09/GHSA-x2m7-9j9x-5v33/GHSA-x2m7-9j9x-5v33.json | 4 +--- .../09/GHSA-x85h-x3fh-9fpv/GHSA-x85h-x3fh-9fpv.json | 4 +--- .../09/GHSA-xp7v-r3c8-pp3w/GHSA-xp7v-r3c8-pp3w.json | 4 +--- .../09/GHSA-xrp2-m33g-q2cv/GHSA-xrp2-m33g-q2cv.json | 4 +--- 936 files changed, 1983 insertions(+), 5949 deletions(-) diff --git a/advisories/github-reviewed/2017/10/GHSA-h835-75hw-pj89/GHSA-h835-75hw-pj89.json b/advisories/github-reviewed/2017/10/GHSA-h835-75hw-pj89/GHSA-h835-75hw-pj89.json index 43944acbac7..b4614e41b71 100644 --- a/advisories/github-reviewed/2017/10/GHSA-h835-75hw-pj89/GHSA-h835-75hw-pj89.json +++ b/advisories/github-reviewed/2017/10/GHSA-h835-75hw-pj89/GHSA-h835-75hw-pj89.json @@ -8,9 +8,7 @@ ], "summary": "activesupport Cross-site Scripting vulnerability", "details": "Cross-site scripting (XSS) vulnerability in `activesupport/lib/active_support/core_ext/string/output_safety.rb` in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 might allow remote attackers to inject arbitrary web script or HTML via vectors involving a ' (quote) character.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/11/GHSA-9ggp-4jpr-7ppj/GHSA-9ggp-4jpr-7ppj.json b/advisories/github-reviewed/2019/11/GHSA-9ggp-4jpr-7ppj/GHSA-9ggp-4jpr-7ppj.json index 1e511e9b07e..6b0db2486b1 100644 --- a/advisories/github-reviewed/2019/11/GHSA-9ggp-4jpr-7ppj/GHSA-9ggp-4jpr-7ppj.json +++ b/advisories/github-reviewed/2019/11/GHSA-9ggp-4jpr-7ppj/GHSA-9ggp-4jpr-7ppj.json @@ -4,14 +4,10 @@ "modified": "2024-10-26T22:38:04Z", "published": "2019-11-20T01:35:53Z", "withdrawn": "2021-02-17T19:44:50Z", - "aliases": [ - - ], + "aliases": [], "summary": "Duplicate Advisory: Possible remote code execution via a remote procedure call", "details": "Withdrawn: duplicate of GHSA-pj4g-4488-wmxm\n\n## Original Description\n\nIn RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default configuration settings.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2019-11-19T03:15:00Z", diff --git a/advisories/github-reviewed/2021/10/GHSA-pjwm-rvh2-c87w/GHSA-pjwm-rvh2-c87w.json b/advisories/github-reviewed/2021/10/GHSA-pjwm-rvh2-c87w/GHSA-pjwm-rvh2-c87w.json index 55f46501161..9ef5757001b 100644 --- a/advisories/github-reviewed/2021/10/GHSA-pjwm-rvh2-c87w/GHSA-pjwm-rvh2-c87w.json +++ b/advisories/github-reviewed/2021/10/GHSA-pjwm-rvh2-c87w/GHSA-pjwm-rvh2-c87w.json @@ -3,9 +3,7 @@ "id": "GHSA-pjwm-rvh2-c87w", "modified": "2023-07-28T15:38:48Z", "published": "2021-10-22T20:38:14Z", - "aliases": [ - - ], + "aliases": [], "summary": "Embedded malware in ua-parser-js", "details": "The npm package `ua-parser-js` had three versions published with malicious code. Users of affected versions (0.7.29, 0.8.0, 1.0.0) should upgrade as soon as possible and check their systems for suspicious activity. See [this issue](https://github.com/faisalman/ua-parser-js/issues/536) for details as they unfold.\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2021/11/GHSA-9wx7-jrvc-28mm/GHSA-9wx7-jrvc-28mm.json b/advisories/github-reviewed/2021/11/GHSA-9wx7-jrvc-28mm/GHSA-9wx7-jrvc-28mm.json index 88ca2d5b89d..afefa0271c5 100644 --- a/advisories/github-reviewed/2021/11/GHSA-9wx7-jrvc-28mm/GHSA-9wx7-jrvc-28mm.json +++ b/advisories/github-reviewed/2021/11/GHSA-9wx7-jrvc-28mm/GHSA-9wx7-jrvc-28mm.json @@ -3,14 +3,10 @@ "id": "GHSA-9wx7-jrvc-28mm", "modified": "2021-11-08T21:34:42Z", "published": "2021-11-08T21:51:18Z", - "aliases": [ - - ], + "aliases": [], "summary": "Signature verification vulnerability in Stark Bank ecdsa libraries", "details": "An attacker can forge signatures on arbitrary messages that will verify for any public key. This may allow attackers to authenticate as any user within the Stark Bank platform, and bypass signature verification needed to perform operations on the platform, such as send payments and transfer funds. Additionally, the ability for attackers to forge signatures may impact other users and projects using these libraries in different and unforeseen ways.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/12/GHSA-qrmm-w75w-3wpx/GHSA-qrmm-w75w-3wpx.json b/advisories/github-reviewed/2021/12/GHSA-qrmm-w75w-3wpx/GHSA-qrmm-w75w-3wpx.json index e7851b24018..a87df8679c2 100644 --- a/advisories/github-reviewed/2021/12/GHSA-qrmm-w75w-3wpx/GHSA-qrmm-w75w-3wpx.json +++ b/advisories/github-reviewed/2021/12/GHSA-qrmm-w75w-3wpx/GHSA-qrmm-w75w-3wpx.json @@ -3,14 +3,10 @@ "id": "GHSA-qrmm-w75w-3wpx", "modified": "2022-05-26T20:08:34Z", "published": "2021-12-09T19:08:38Z", - "aliases": [ - - ], + "aliases": [], "summary": "Server side request forgery in SwaggerUI", "details": "SwaggerUI supports displaying remote OpenAPI definitions through the `?url` parameter. This enables robust demonstration capabilities on sites like `petstore.swagger.io`, `editor.swagger.io`, and similar sites, where users often want to see what their OpenAPI definitions would look like rendered.\n\nHowever, this functionality may pose a risk for users who host their own SwaggerUI instances. In particular, including remote OpenAPI definitions opens a vector for phishing attacks by abusing the trusted names/domains of self-hosted instances.\n\nAn example scenario abusing this functionality could take the following form:\n- `https://example.com/api-docs` hosts a version of SwaggerUI with `?url=` query parameter enabled.\n- Users will trust the domain `https://example.com` and the contents of the OpenAPI definition.\n- A malicious actor may craft a similar OpenAPI definition and service that responds to the defined APIs at `https://evildomain`.\n- Users mistakenly click a phishing URL like `https://example.com/api-docs?url=https://evildomain/fakeapi.yaml` and enters sensitive data via the \"Try-it-out\" feature.\n\nWe do want to stress that this attack vector is limited to scenarios that actively trick users into divulging sensitive information. The ease of this is highly contextual and, therefore, the threat model may be different for individual users and organizations. It is *not* possible to perform non-interactive attacks (e.g., cross-site scripting or code injection) through this mechanism.\n\n### Resolution \nWe've made the decision to [disable query parameters (#4872)](https://github.com/swagger-api/swagger-ui/issues/4872) by default starting with SwaggerUI version `4.1.3`. Please update to this version when it becomes available (**ETA: 2021 December**). Users will still be able to be re-enable the options at their discretion. We'll continue to enable query parameters on the Swagger demo sites.\n\n### Workaround\nIf you host a version of SwaggerUI and wish to mitigate this issue immediately, you are encouraged to add the following custom plugin code:\n\n```js\nSwaggerUI({\n // ...other configuration options,\n plugins: [function UrlParamDisablePlugin() {\n return {\n statePlugins: {\n spec: {\n wrapActions: {\n // Remove the ?url parameter from loading an external OpenAPI definition.\n updateUrl: (oriAction) => (payload) => {\n const url = new URL(window.location.href)\n if (url.searchParams.has('url')) {\n url.searchParams.delete('url')\n window.location.replace(url.toString())\n }\n return oriAction(payload)\n }\n }\n }\n }\n }\n }],\n})\n```\n\n### Future UX work\n\nThrough the exploration of this issue, it became apparent that users may not be aware to which web server the Try-it-out function will send requests. While this information is currently presented at the top of the page, understanding may improve by displaying it closer to the \"Execute\" button where requests are actually made. We'll be exploring these UX improvements over the coming months and welcome community input. Please create a Feature Request under the GitHub Issue tab to start a conversation with us and the community.\n\n## Reflected XSS attack\n\n**Warning** in versions < 3.38.0, it is possible to combine the URL options (as mentioned above) with a vulnerability in DOMPurify (https://www.cvedetails.com/cve/CVE-2020-26870/) to create a reflected XSS vector. If your version of Swagger UI is older than 3.38.0, we suggest you upgrade or implement the workaround as mentioned above.\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-7372-q459-jxhr/GHSA-7372-q459-jxhr.json b/advisories/github-reviewed/2022/05/GHSA-7372-q459-jxhr/GHSA-7372-q459-jxhr.json index fbf1c05efd0..e8350f03459 100644 --- a/advisories/github-reviewed/2022/05/GHSA-7372-q459-jxhr/GHSA-7372-q459-jxhr.json +++ b/advisories/github-reviewed/2022/05/GHSA-7372-q459-jxhr/GHSA-7372-q459-jxhr.json @@ -8,9 +8,7 @@ ], "summary": "pyxdg Arbitrary File Overwrite via Race Condition", "details": "Race condition in the `xdg.BaseDirectory.get_runtime_dir` function in pyxdg 0.25 allows local users to overwrite arbitrary files by pre-creating `/tmp/pyxdg-runtime-dir-fallback-victim` to point to a victim-owned location, then replacing it with a symlink to an attacker-controlled location once the `get_runtime_dir` function is called.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-g283-88v5-rmq2/GHSA-g283-88v5-rmq2.json b/advisories/github-reviewed/2022/05/GHSA-g283-88v5-rmq2/GHSA-g283-88v5-rmq2.json index c1ce99305c3..669453884a2 100644 --- a/advisories/github-reviewed/2022/05/GHSA-g283-88v5-rmq2/GHSA-g283-88v5-rmq2.json +++ b/advisories/github-reviewed/2022/05/GHSA-g283-88v5-rmq2/GHSA-g283-88v5-rmq2.json @@ -54,9 +54,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-04-22T22:20:33Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-rhcg-rwhx-qj3j/GHSA-rhcg-rwhx-qj3j.json b/advisories/github-reviewed/2022/05/GHSA-rhcg-rwhx-qj3j/GHSA-rhcg-rwhx-qj3j.json index d4e0b48741f..87f02b66c28 100644 --- a/advisories/github-reviewed/2022/05/GHSA-rhcg-rwhx-qj3j/GHSA-rhcg-rwhx-qj3j.json +++ b/advisories/github-reviewed/2022/05/GHSA-rhcg-rwhx-qj3j/GHSA-rhcg-rwhx-qj3j.json @@ -8,9 +8,7 @@ ], "summary": "Improper Limitation of a Pathname to a Restricted Directory in Spring Framework", "details": "Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/02/GHSA-22cc-w7xm-rfhx/GHSA-22cc-w7xm-rfhx.json b/advisories/github-reviewed/2024/02/GHSA-22cc-w7xm-rfhx/GHSA-22cc-w7xm-rfhx.json index 6cb50a1688d..ae8e8b755dd 100644 --- a/advisories/github-reviewed/2024/02/GHSA-22cc-w7xm-rfhx/GHSA-22cc-w7xm-rfhx.json +++ b/advisories/github-reviewed/2024/02/GHSA-22cc-w7xm-rfhx/GHSA-22cc-w7xm-rfhx.json @@ -8,9 +8,7 @@ ], "summary": "Mezzanine allows attackers to bypass access controls via manipulating the Host header", "details": "An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-02-28T22:58:40Z", diff --git a/advisories/github-reviewed/2024/04/GHSA-rqgv-292v-5qgr/GHSA-rqgv-292v-5qgr.json b/advisories/github-reviewed/2024/04/GHSA-rqgv-292v-5qgr/GHSA-rqgv-292v-5qgr.json index c1eaf1edebb..8b8f32ee0b7 100644 --- a/advisories/github-reviewed/2024/04/GHSA-rqgv-292v-5qgr/GHSA-rqgv-292v-5qgr.json +++ b/advisories/github-reviewed/2024/04/GHSA-rqgv-292v-5qgr/GHSA-rqgv-292v-5qgr.json @@ -3,9 +3,7 @@ "id": "GHSA-rqgv-292v-5qgr", "modified": "2024-04-23T16:21:10Z", "published": "2024-04-23T16:21:09Z", - "aliases": [ - - ], + "aliases": [], "summary": "Renovate vulnerable to arbitrary command injection via helmv3 manager and registryAliases", "details": "### Summary\n\nAttackers with commit access to the default branch of a repo using Renovate could manipulate helmv3 registryAliases to execute arbitrary commands.\n\n### Details\n\nSince [#26848](https://github.com/renovatebot/renovate/pull/26848), `registryAliases` has become mergeable. This means that the helmv3 manager started honoring its value and uses a `helm repo add ` command for each defined alias. See source code: https://github.com/renovatebot/renovate/blob/23f3df6216375cb5bcfe027b0faee304f877f891/lib/modules/manager/helmv3/artifacts.ts#L80\nThe key was not quoted, leading to the ability to use variable references (`$FOO`) in it and have them printed by Renovate on the pull request, or even running any shell commands.\n\n### PoC\n\nInside a repository where Renovate runs, add a Helm chart with an outdated dependency, for example:\n\ntest-chart/Chart.yaml:\n\n```\napiVersion: v2\nname: redis\nversion: 1.0.0\ndependencies:\n - name: redis\n version: 18.13.10\n repository: oci://registry-1.docker.io/bitnamicharts\n```\n\ntest-chart/Chart.lock:\n\n```\ndependencies:\n- name: redis\n repository: oci://registry-1.docker.io/bitnamicharts\n version: 18.13.10\ndigest: sha256:11267bd32ea6c5c120ddebbb9f21e4a3c7700a961aa1a27ddb55df1fb8059a38\ngenerated: \"2024-02-16T13:31:20.807026334Z\"\n```\n\nThen add the following `renovate.json`:\n\n```json\n{\n \"$schema\": \"https://docs.renovatebot.com/renovate-schema.json\",\n \"extends\": [\n \"config:base\"\n ],\n \"registryAliases\": {\n \"foo/bar || sh -c 'ls /; exit 1' >&2\": \"registry.example.com/proxy\"\n }\n}\n```\n\nOnce Renovate runs on the repository, it will create a pull request, and add a comment titled \"Artifact update problem\" containing the following text:\n\n```\nFile name: test-chart/Chart.lock\n\nCommand failed: helm repo add foo/bar || sh -c 'ls /; exit 1' >&2 registry.example.com/proxy --force-update\nError: \"helm repo add\" requires 2 arguments\n\nUsage: helm repo add [NAME] [URL] [flags]\nbin\nboot\ndev\netc\ngo\nhome\nlib\nlib32\nlib64\nlibx32\nmedia\nmnt\nopt\nproc\nroot\nrun\nsbin\nsrv\nsys\ntmp\nusr\nvar\n```\n\nThis shows that the `ls` command executed successfully, and we can even see its output.\n\nNote that redirecting any output you want to see to stderr (`>&2`) and making sure the final command fails (`exit 1`) is required in this case, as Renovate only adds a comment if the command fails, and it contains only stderr (not stdout) output.\n\n### Impact\n\nAll Renovate versions from 37.158.0 up until 37.199.0 were affected. This vulnerability allows full access to Renovate's execution environment. The level of severity depends on how Renovate is deployed (Docker, Kubernetes, CI pipeline, ...) and whether Renovate is being offered to untrusted users/repositories.\n", "severity": [ diff --git a/advisories/github-reviewed/2024/04/GHSA-w228-rfpx-fhm4/GHSA-w228-rfpx-fhm4.json b/advisories/github-reviewed/2024/04/GHSA-w228-rfpx-fhm4/GHSA-w228-rfpx-fhm4.json index d7f2806ea32..4258bca99ff 100644 --- a/advisories/github-reviewed/2024/04/GHSA-w228-rfpx-fhm4/GHSA-w228-rfpx-fhm4.json +++ b/advisories/github-reviewed/2024/04/GHSA-w228-rfpx-fhm4/GHSA-w228-rfpx-fhm4.json @@ -3,9 +3,7 @@ "id": "GHSA-w228-rfpx-fhm4", "modified": "2024-04-23T16:21:22Z", "published": "2024-04-23T16:21:22Z", - "aliases": [ - - ], + "aliases": [], "summary": "cg vulnerable to an Open Redirect Vulnerability on Referer Header", "details": "### Summary\n\nA vulnerability has been discovered in the handling of the referrer header in the application, which could allow an attacker to conduct open redirects. The issue arises from improper validation of the referrer header in certain conditions. By manipulating the referrer header, an attacker could potentially redirect users to malicious websites, phishing pages, or other dangerous destinations.\n\n### PoC\n\nIf you change the referer header, you will be redirected to that domain without verifying.\n\nhttps://github.com/Clinical-Genomics/cg/blob/master/cg/server/invoices/views.py#L173\n\n### Impact\n\nAn attacker exploiting this vulnerability could trick users into visiting malicious websites or disclose sensitive information by redirecting them to unintended destinations. This could lead to various attacks including phishing, malware distribution, or further exploitation of other vulnerabilities.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-83jv-4prm-34g7/GHSA-83jv-4prm-34g7.json b/advisories/github-reviewed/2024/05/GHSA-83jv-4prm-34g7/GHSA-83jv-4prm-34g7.json index f64ed1be382..c1733443a30 100644 --- a/advisories/github-reviewed/2024/05/GHSA-83jv-4prm-34g7/GHSA-83jv-4prm-34g7.json +++ b/advisories/github-reviewed/2024/05/GHSA-83jv-4prm-34g7/GHSA-83jv-4prm-34g7.json @@ -3,9 +3,7 @@ "id": "GHSA-83jv-4prm-34g7", "modified": "2024-05-21T21:00:39Z", "published": "2024-05-21T21:00:39Z", - "aliases": [ - - ], + "aliases": [], "summary": "Shopware Remote Code Execution Vulnerability", "details": "Under certain circumstances it is possible to execute an authorized foreign code in Shopware version prior to 5.2.25.\n", "severity": [ diff --git a/advisories/unreviewed/2021/11/GHSA-3jrq-x5vv-pvcw/GHSA-3jrq-x5vv-pvcw.json b/advisories/unreviewed/2021/11/GHSA-3jrq-x5vv-pvcw/GHSA-3jrq-x5vv-pvcw.json index 04c9028b2fd..c508398d1cf 100644 --- a/advisories/unreviewed/2021/11/GHSA-3jrq-x5vv-pvcw/GHSA-3jrq-x5vv-pvcw.json +++ b/advisories/unreviewed/2021/11/GHSA-3jrq-x5vv-pvcw/GHSA-3jrq-x5vv-pvcw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-fp8m-q3h7-6ww8/GHSA-fp8m-q3h7-6ww8.json b/advisories/unreviewed/2021/11/GHSA-fp8m-q3h7-6ww8/GHSA-fp8m-q3h7-6ww8.json index 6d4b0af2bce..44eb6974dd0 100644 --- a/advisories/unreviewed/2021/11/GHSA-fp8m-q3h7-6ww8/GHSA-fp8m-q3h7-6ww8.json +++ b/advisories/unreviewed/2021/11/GHSA-fp8m-q3h7-6ww8/GHSA-fp8m-q3h7-6ww8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-jf2c-v9v9-9r3w/GHSA-jf2c-v9v9-9r3w.json b/advisories/unreviewed/2021/11/GHSA-jf2c-v9v9-9r3w/GHSA-jf2c-v9v9-9r3w.json index f03bb401e91..4ebe78cc2e6 100644 --- a/advisories/unreviewed/2021/11/GHSA-jf2c-v9v9-9r3w/GHSA-jf2c-v9v9-9r3w.json +++ b/advisories/unreviewed/2021/11/GHSA-jf2c-v9v9-9r3w/GHSA-jf2c-v9v9-9r3w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-hmgv-4jwm-xc9x/GHSA-hmgv-4jwm-xc9x.json b/advisories/unreviewed/2022/01/GHSA-hmgv-4jwm-xc9x/GHSA-hmgv-4jwm-xc9x.json index 0072d9d08dc..a600bde11ff 100644 --- a/advisories/unreviewed/2022/01/GHSA-hmgv-4jwm-xc9x/GHSA-hmgv-4jwm-xc9x.json +++ b/advisories/unreviewed/2022/01/GHSA-hmgv-4jwm-xc9x/GHSA-hmgv-4jwm-xc9x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-pfq2-x69w-983r/GHSA-pfq2-x69w-983r.json b/advisories/unreviewed/2022/01/GHSA-pfq2-x69w-983r/GHSA-pfq2-x69w-983r.json index 0661033f269..24bcbed294f 100644 --- a/advisories/unreviewed/2022/01/GHSA-pfq2-x69w-983r/GHSA-pfq2-x69w-983r.json +++ b/advisories/unreviewed/2022/01/GHSA-pfq2-x69w-983r/GHSA-pfq2-x69w-983r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-q3cw-hwhf-x8fr/GHSA-q3cw-hwhf-x8fr.json b/advisories/unreviewed/2022/01/GHSA-q3cw-hwhf-x8fr/GHSA-q3cw-hwhf-x8fr.json index ad0b73af8ec..50f5ac56dc6 100644 --- a/advisories/unreviewed/2022/01/GHSA-q3cw-hwhf-x8fr/GHSA-q3cw-hwhf-x8fr.json +++ b/advisories/unreviewed/2022/01/GHSA-q3cw-hwhf-x8fr/GHSA-q3cw-hwhf-x8fr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-2hcr-94vw-mxjh/GHSA-2hcr-94vw-mxjh.json b/advisories/unreviewed/2022/02/GHSA-2hcr-94vw-mxjh/GHSA-2hcr-94vw-mxjh.json index 9713081647f..1c57a01555e 100644 --- a/advisories/unreviewed/2022/02/GHSA-2hcr-94vw-mxjh/GHSA-2hcr-94vw-mxjh.json +++ b/advisories/unreviewed/2022/02/GHSA-2hcr-94vw-mxjh/GHSA-2hcr-94vw-mxjh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-pfmv-2r4f-j9mj/GHSA-pfmv-2r4f-j9mj.json b/advisories/unreviewed/2022/02/GHSA-pfmv-2r4f-j9mj/GHSA-pfmv-2r4f-j9mj.json index 5218f83d28f..e145e234b9a 100644 --- a/advisories/unreviewed/2022/02/GHSA-pfmv-2r4f-j9mj/GHSA-pfmv-2r4f-j9mj.json +++ b/advisories/unreviewed/2022/02/GHSA-pfmv-2r4f-j9mj/GHSA-pfmv-2r4f-j9mj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-38pg-fhjw-6gv5/GHSA-38pg-fhjw-6gv5.json b/advisories/unreviewed/2022/03/GHSA-38pg-fhjw-6gv5/GHSA-38pg-fhjw-6gv5.json index 1a0a5fd0cf8..48add44cbc6 100644 --- a/advisories/unreviewed/2022/03/GHSA-38pg-fhjw-6gv5/GHSA-38pg-fhjw-6gv5.json +++ b/advisories/unreviewed/2022/03/GHSA-38pg-fhjw-6gv5/GHSA-38pg-fhjw-6gv5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-228f-32pf-6cc9/GHSA-228f-32pf-6cc9.json b/advisories/unreviewed/2022/05/GHSA-228f-32pf-6cc9/GHSA-228f-32pf-6cc9.json index 882459830d1..10f2becc054 100644 --- a/advisories/unreviewed/2022/05/GHSA-228f-32pf-6cc9/GHSA-228f-32pf-6cc9.json +++ b/advisories/unreviewed/2022/05/GHSA-228f-32pf-6cc9/GHSA-228f-32pf-6cc9.json @@ -7,12 +7,8 @@ "CVE-2010-4154" ], "details": "Directory traversal vulnerability in Rhino Software, Inc. FTP Voyager 15.2.0.11, and possibly earlier, allows remote FTP servers to write arbitrary files via a \"..\\\" (dot dot backslash) in a filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-22xm-47fv-r79q/GHSA-22xm-47fv-r79q.json b/advisories/unreviewed/2022/05/GHSA-22xm-47fv-r79q/GHSA-22xm-47fv-r79q.json index d2d8147f98f..caa9346cdda 100644 --- a/advisories/unreviewed/2022/05/GHSA-22xm-47fv-r79q/GHSA-22xm-47fv-r79q.json +++ b/advisories/unreviewed/2022/05/GHSA-22xm-47fv-r79q/GHSA-22xm-47fv-r79q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-236h-5c6c-jrfx/GHSA-236h-5c6c-jrfx.json b/advisories/unreviewed/2022/05/GHSA-236h-5c6c-jrfx/GHSA-236h-5c6c-jrfx.json index 91c55109216..152c19721c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-236h-5c6c-jrfx/GHSA-236h-5c6c-jrfx.json +++ b/advisories/unreviewed/2022/05/GHSA-236h-5c6c-jrfx/GHSA-236h-5c6c-jrfx.json @@ -7,12 +7,8 @@ "CVE-2008-7081" ], "details": "userHandler.cgi in RaidSonic ICY BOX NAS firmware 2.3.2.IB.2.RS.1 allows remote attackers to bypass authentication and gain administrator privileges by setting the login parameter to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-236w-f35g-f339/GHSA-236w-f35g-f339.json b/advisories/unreviewed/2022/05/GHSA-236w-f35g-f339/GHSA-236w-f35g-f339.json index cc0f5438d92..0e44ef385d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-236w-f35g-f339/GHSA-236w-f35g-f339.json +++ b/advisories/unreviewed/2022/05/GHSA-236w-f35g-f339/GHSA-236w-f35g-f339.json @@ -7,12 +7,8 @@ "CVE-2008-7094" ], "details": "Campaign/CampaignListener in the listener server in Unica Affinium Campaign 7.2.1.0.55 allows remote attackers to cause a denial of service (server crash) via a crafted length field that triggers (1) connection exhaustion or (2) memory allocation failure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-23g2-8rfg-4ppg/GHSA-23g2-8rfg-4ppg.json b/advisories/unreviewed/2022/05/GHSA-23g2-8rfg-4ppg/GHSA-23g2-8rfg-4ppg.json index 2b7733b6f80..f9b3c801e9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-23g2-8rfg-4ppg/GHSA-23g2-8rfg-4ppg.json +++ b/advisories/unreviewed/2022/05/GHSA-23g2-8rfg-4ppg/GHSA-23g2-8rfg-4ppg.json @@ -7,12 +7,8 @@ "CVE-2010-3426" ], "details": "Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-23gh-5xvj-6hr9/GHSA-23gh-5xvj-6hr9.json b/advisories/unreviewed/2022/05/GHSA-23gh-5xvj-6hr9/GHSA-23gh-5xvj-6hr9.json index fafdf90a08d..1953c3a9ba3 100644 --- a/advisories/unreviewed/2022/05/GHSA-23gh-5xvj-6hr9/GHSA-23gh-5xvj-6hr9.json +++ b/advisories/unreviewed/2022/05/GHSA-23gh-5xvj-6hr9/GHSA-23gh-5xvj-6hr9.json @@ -7,12 +7,8 @@ "CVE-2010-4184" ], "details": "NetSupport Manager (NSM) before 11.00.0005 sends HTTP headers with cleartext fields containing details about client machines, which allows remote attackers to obtain potentially sensitive information by sniffing the network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-25f3-2w4g-m595/GHSA-25f3-2w4g-m595.json b/advisories/unreviewed/2022/05/GHSA-25f3-2w4g-m595/GHSA-25f3-2w4g-m595.json index d39729a8fb6..dfdbc011266 100644 --- a/advisories/unreviewed/2022/05/GHSA-25f3-2w4g-m595/GHSA-25f3-2w4g-m595.json +++ b/advisories/unreviewed/2022/05/GHSA-25f3-2w4g-m595/GHSA-25f3-2w4g-m595.json @@ -7,12 +7,8 @@ "CVE-2010-4225" ], "details": "Unspecified vulnerability in the mod_mono module for XSP in Mono 2.8.x before 2.8.2 allows remote attackers to obtain the source code for .aspx (ASP.NET) applications via unknown vectors related to an \"unloading bug.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-25mc-rjmh-r6x4/GHSA-25mc-rjmh-r6x4.json b/advisories/unreviewed/2022/05/GHSA-25mc-rjmh-r6x4/GHSA-25mc-rjmh-r6x4.json index d6bb93ab56c..22e7beffea5 100644 --- a/advisories/unreviewed/2022/05/GHSA-25mc-rjmh-r6x4/GHSA-25mc-rjmh-r6x4.json +++ b/advisories/unreviewed/2022/05/GHSA-25mc-rjmh-r6x4/GHSA-25mc-rjmh-r6x4.json @@ -7,12 +7,8 @@ "CVE-2010-2133" ], "details": "SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-2942.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-274w-x34j-q3q6/GHSA-274w-x34j-q3q6.json b/advisories/unreviewed/2022/05/GHSA-274w-x34j-q3q6/GHSA-274w-x34j-q3q6.json index 11ee7d30f81..7a5a898fc29 100644 --- a/advisories/unreviewed/2022/05/GHSA-274w-x34j-q3q6/GHSA-274w-x34j-q3q6.json +++ b/advisories/unreviewed/2022/05/GHSA-274w-x34j-q3q6/GHSA-274w-x34j-q3q6.json @@ -7,12 +7,8 @@ "CVE-2010-4098" ], "details": "monotone before 0.48.1, when configured to allow remote commands, allows remote attackers to cause a denial of service (crash) via an empty argument to the mtn command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-29mr-mxx6-f3f5/GHSA-29mr-mxx6-f3f5.json b/advisories/unreviewed/2022/05/GHSA-29mr-mxx6-f3f5/GHSA-29mr-mxx6-f3f5.json index bee04b04e6e..d7a15dd2109 100644 --- a/advisories/unreviewed/2022/05/GHSA-29mr-mxx6-f3f5/GHSA-29mr-mxx6-f3f5.json +++ b/advisories/unreviewed/2022/05/GHSA-29mr-mxx6-f3f5/GHSA-29mr-mxx6-f3f5.json @@ -7,12 +7,8 @@ "CVE-2010-4272" ], "details": "SQL injection vulnerability in the Pulse Infotech Sponsor Wall (com_sponsorwall) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2cxm-7f99-2c44/GHSA-2cxm-7f99-2c44.json b/advisories/unreviewed/2022/05/GHSA-2cxm-7f99-2c44/GHSA-2cxm-7f99-2c44.json index e320db2e119..ee938b87d99 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cxm-7f99-2c44/GHSA-2cxm-7f99-2c44.json +++ b/advisories/unreviewed/2022/05/GHSA-2cxm-7f99-2c44/GHSA-2cxm-7f99-2c44.json @@ -7,12 +7,8 @@ "CVE-2010-2004" ], "details": "Stack-based buffer overflow in BS.Global BS.Player 2.51 Build 1022 Free, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via the Skin parameter in the Options section of a skins file (.bsi), a different vulnerability than CVE-2009-1068.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2f84-jw6x-ffwh/GHSA-2f84-jw6x-ffwh.json b/advisories/unreviewed/2022/05/GHSA-2f84-jw6x-ffwh/GHSA-2f84-jw6x-ffwh.json index b4b53492017..ee6e103106e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f84-jw6x-ffwh/GHSA-2f84-jw6x-ffwh.json +++ b/advisories/unreviewed/2022/05/GHSA-2f84-jw6x-ffwh/GHSA-2f84-jw6x-ffwh.json @@ -7,12 +7,8 @@ "CVE-2010-2588" ], "details": "The dirapi.dll module in Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2587 and CVE-2010-4188.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2g25-9rg6-j46q/GHSA-2g25-9rg6-j46q.json b/advisories/unreviewed/2022/05/GHSA-2g25-9rg6-j46q/GHSA-2g25-9rg6-j46q.json index f88f99293aa..4c74ccea171 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g25-9rg6-j46q/GHSA-2g25-9rg6-j46q.json +++ b/advisories/unreviewed/2022/05/GHSA-2g25-9rg6-j46q/GHSA-2g25-9rg6-j46q.json @@ -7,12 +7,8 @@ "CVE-2010-2856" ], "details": "Cross-site scripting (XSS) vulnerability in admin/currencies.php in osCSS 1.2.2, and probably earlier versions, allows remote attackers to inject arbitrary web script or HTML via the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2g43-c47m-wpf4/GHSA-2g43-c47m-wpf4.json b/advisories/unreviewed/2022/05/GHSA-2g43-c47m-wpf4/GHSA-2g43-c47m-wpf4.json index 2e32cbd4016..7743f0e47d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g43-c47m-wpf4/GHSA-2g43-c47m-wpf4.json +++ b/advisories/unreviewed/2022/05/GHSA-2g43-c47m-wpf4/GHSA-2g43-c47m-wpf4.json @@ -7,12 +7,8 @@ "CVE-2008-7130" ], "details": "Unspecified vulnerability in DB2 Monitoring Console 2.2.4 and earlier allows remote attackers to upload arbitrary files via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2h4h-6mrx-52ff/GHSA-2h4h-6mrx-52ff.json b/advisories/unreviewed/2022/05/GHSA-2h4h-6mrx-52ff/GHSA-2h4h-6mrx-52ff.json index 90af98208f5..f78bf21def1 100644 --- a/advisories/unreviewed/2022/05/GHSA-2h4h-6mrx-52ff/GHSA-2h4h-6mrx-52ff.json +++ b/advisories/unreviewed/2022/05/GHSA-2h4h-6mrx-52ff/GHSA-2h4h-6mrx-52ff.json @@ -7,12 +7,8 @@ "CVE-2010-1983" ], "details": "Directory traversal vulnerability in the redTWITTER (com_redtwitter) component 1.0.x including 1.0b11 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2h5c-85wg-jwx8/GHSA-2h5c-85wg-jwx8.json b/advisories/unreviewed/2022/05/GHSA-2h5c-85wg-jwx8/GHSA-2h5c-85wg-jwx8.json index fe051c669fb..06b46159887 100644 --- a/advisories/unreviewed/2022/05/GHSA-2h5c-85wg-jwx8/GHSA-2h5c-85wg-jwx8.json +++ b/advisories/unreviewed/2022/05/GHSA-2h5c-85wg-jwx8/GHSA-2h5c-85wg-jwx8.json @@ -7,12 +7,8 @@ "CVE-2010-1940" ], "details": "Apple Safari 4.0.5 on Windows sends the \"Authorization: Basic\" header appropriate for one web site to a different web site named in a Location header received from the first site, which allows remote web servers to obtain sensitive information by logging HTTP requests. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2hcx-274x-74jw/GHSA-2hcx-274x-74jw.json b/advisories/unreviewed/2022/05/GHSA-2hcx-274x-74jw/GHSA-2hcx-274x-74jw.json index 9199f15d14a..336063f9e8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hcx-274x-74jw/GHSA-2hcx-274x-74jw.json +++ b/advisories/unreviewed/2022/05/GHSA-2hcx-274x-74jw/GHSA-2hcx-274x-74jw.json @@ -7,12 +7,8 @@ "CVE-2010-4439" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft and JDEdwards Suite 9.0 Bundle #14 and 9.1 Bundle #4 allows remote authenticated users to affect confidentiality via unknown vectors related to eProfile - Manager Desktop.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2hvv-h4pw-wcm2/GHSA-2hvv-h4pw-wcm2.json b/advisories/unreviewed/2022/05/GHSA-2hvv-h4pw-wcm2/GHSA-2hvv-h4pw-wcm2.json index 211a94e736c..8a0ce93ad98 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hvv-h4pw-wcm2/GHSA-2hvv-h4pw-wcm2.json +++ b/advisories/unreviewed/2022/05/GHSA-2hvv-h4pw-wcm2/GHSA-2hvv-h4pw-wcm2.json @@ -7,12 +7,8 @@ "CVE-2010-2526" ], "details": "The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2j92-9gm3-m87q/GHSA-2j92-9gm3-m87q.json b/advisories/unreviewed/2022/05/GHSA-2j92-9gm3-m87q/GHSA-2j92-9gm3-m87q.json index 7e0514ecb1d..20996b34f64 100644 --- a/advisories/unreviewed/2022/05/GHSA-2j92-9gm3-m87q/GHSA-2j92-9gm3-m87q.json +++ b/advisories/unreviewed/2022/05/GHSA-2j92-9gm3-m87q/GHSA-2j92-9gm3-m87q.json @@ -7,12 +7,8 @@ "CVE-2010-2080" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) 2.3.x before 2.3.6 and 2.4.x before 2.4.8 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2mw7-77qm-cmxc/GHSA-2mw7-77qm-cmxc.json b/advisories/unreviewed/2022/05/GHSA-2mw7-77qm-cmxc/GHSA-2mw7-77qm-cmxc.json index 0d072218983..66eef25605b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mw7-77qm-cmxc/GHSA-2mw7-77qm-cmxc.json +++ b/advisories/unreviewed/2022/05/GHSA-2mw7-77qm-cmxc/GHSA-2mw7-77qm-cmxc.json @@ -7,12 +7,8 @@ "CVE-2010-2439" ], "details": "Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list (.maf file).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2p45-c9hc-p9hf/GHSA-2p45-c9hc-p9hf.json b/advisories/unreviewed/2022/05/GHSA-2p45-c9hc-p9hf/GHSA-2p45-c9hc-p9hf.json index 9d031287ec0..538016b5fa6 100644 --- a/advisories/unreviewed/2022/05/GHSA-2p45-c9hc-p9hf/GHSA-2p45-c9hc-p9hf.json +++ b/advisories/unreviewed/2022/05/GHSA-2p45-c9hc-p9hf/GHSA-2p45-c9hc-p9hf.json @@ -7,12 +7,8 @@ "CVE-2010-2724" ], "details": "Cross-site scripting (XSS) vulnerability in the Hierarchical Select module 5.x before 5.x-3.2 and 6.x before 6.x-3.2 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via unspecified vectors in the hierarchical_select form.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2p73-r6vf-7hjq/GHSA-2p73-r6vf-7hjq.json b/advisories/unreviewed/2022/05/GHSA-2p73-r6vf-7hjq/GHSA-2p73-r6vf-7hjq.json index 593e6a9aa92..f6dd96a0b47 100644 --- a/advisories/unreviewed/2022/05/GHSA-2p73-r6vf-7hjq/GHSA-2p73-r6vf-7hjq.json +++ b/advisories/unreviewed/2022/05/GHSA-2p73-r6vf-7hjq/GHSA-2p73-r6vf-7hjq.json @@ -7,12 +7,8 @@ "CVE-2008-7162" ], "details": "Buffer overflow in Hero Super Player 3000 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in a .M3U file. NOTE: this might be related to CVE-2008-4504.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2pqj-vff5-fgh2/GHSA-2pqj-vff5-fgh2.json b/advisories/unreviewed/2022/05/GHSA-2pqj-vff5-fgh2/GHSA-2pqj-vff5-fgh2.json index b16fc22fd1a..4068ec11e37 100644 --- a/advisories/unreviewed/2022/05/GHSA-2pqj-vff5-fgh2/GHSA-2pqj-vff5-fgh2.json +++ b/advisories/unreviewed/2022/05/GHSA-2pqj-vff5-fgh2/GHSA-2pqj-vff5-fgh2.json @@ -7,12 +7,8 @@ "CVE-2010-2697" ], "details": "Cross-site scripting (XSS) vulnerability in Sijio Community Software allows remote authenticated users to inject arbitrary web script or HTML via the title parameter when adding a new blog, related to edit_blog/index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2qvm-65xp-25xh/GHSA-2qvm-65xp-25xh.json b/advisories/unreviewed/2022/05/GHSA-2qvm-65xp-25xh/GHSA-2qvm-65xp-25xh.json index 20761328882..4ef99216810 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qvm-65xp-25xh/GHSA-2qvm-65xp-25xh.json +++ b/advisories/unreviewed/2022/05/GHSA-2qvm-65xp-25xh/GHSA-2qvm-65xp-25xh.json @@ -7,12 +7,8 @@ "CVE-2010-4120" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the TAM console in IBM Tivoli Access Manager for e-business 6.1.0 before 6.1.0-TIV-TAM-FP0006 allow remote attackers to inject arbitrary web script or HTML via (1) the parm1 parameter to ivt/ivtserver, or the method parameter to (2) acl, (3) domain, (4) group, (5) gso, (6) gsogroup, (7) os, (8) pop, (9) rule, (10) user, or (11) webseal in ibm/wpm/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2rg5-632f-rr5j/GHSA-2rg5-632f-rr5j.json b/advisories/unreviewed/2022/05/GHSA-2rg5-632f-rr5j/GHSA-2rg5-632f-rr5j.json index d9f86a3d563..47de7f6f820 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rg5-632f-rr5j/GHSA-2rg5-632f-rr5j.json +++ b/advisories/unreviewed/2022/05/GHSA-2rg5-632f-rr5j/GHSA-2rg5-632f-rr5j.json @@ -7,12 +7,8 @@ "CVE-2008-7152" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Specimen Image Database (SID), when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) client.php or (2) taxonservice.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2w78-874w-f3gw/GHSA-2w78-874w-f3gw.json b/advisories/unreviewed/2022/05/GHSA-2w78-874w-f3gw/GHSA-2w78-874w-f3gw.json index 443cd9af34f..98d9c1b463f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w78-874w-f3gw/GHSA-2w78-874w-f3gw.json +++ b/advisories/unreviewed/2022/05/GHSA-2w78-874w-f3gw/GHSA-2w78-874w-f3gw.json @@ -7,12 +7,8 @@ "CVE-2010-4456" ], "details": "Unspecified vulnerability in Oracle Sun Java System Communications Express 6.2 and 6.3 allows remote attackers to affect integrity via unknown vectors related to Web Mail.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2x7c-3vq5-3crp/GHSA-2x7c-3vq5-3crp.json b/advisories/unreviewed/2022/05/GHSA-2x7c-3vq5-3crp/GHSA-2x7c-3vq5-3crp.json index e15277ee8c9..e6c35a6cc48 100644 --- a/advisories/unreviewed/2022/05/GHSA-2x7c-3vq5-3crp/GHSA-2x7c-3vq5-3crp.json +++ b/advisories/unreviewed/2022/05/GHSA-2x7c-3vq5-3crp/GHSA-2x7c-3vq5-3crp.json @@ -7,12 +7,8 @@ "CVE-2008-7150" ], "details": "Cross-site scripting (XSS) vulnerability in Refine by Taxonomy 5.x before 5.x-0.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a taxonomy term, which is not properly handled by refine_by_taxo when displaying tags.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xq2-3xwx-xh4v/GHSA-2xq2-3xwx-xh4v.json b/advisories/unreviewed/2022/05/GHSA-2xq2-3xwx-xh4v/GHSA-2xq2-3xwx-xh4v.json index 69c0ceb4be2..bfee0b27e69 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xq2-3xwx-xh4v/GHSA-2xq2-3xwx-xh4v.json +++ b/advisories/unreviewed/2022/05/GHSA-2xq2-3xwx-xh4v/GHSA-2xq2-3xwx-xh4v.json @@ -7,12 +7,8 @@ "CVE-2010-2359" ], "details": "SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizType parameter, a different vector than CVE-2007-1706.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xvq-8gjc-grfh/GHSA-2xvq-8gjc-grfh.json b/advisories/unreviewed/2022/05/GHSA-2xvq-8gjc-grfh/GHSA-2xvq-8gjc-grfh.json index 1c79eb530b4..89af32fb308 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xvq-8gjc-grfh/GHSA-2xvq-8gjc-grfh.json +++ b/advisories/unreviewed/2022/05/GHSA-2xvq-8gjc-grfh/GHSA-2xvq-8gjc-grfh.json @@ -7,12 +7,8 @@ "CVE-2008-7040" ], "details": "SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remote attackers to execute arbitrary SQL commands via the u parameter. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xwm-mmjj-m5x4/GHSA-2xwm-mmjj-m5x4.json b/advisories/unreviewed/2022/05/GHSA-2xwm-mmjj-m5x4/GHSA-2xwm-mmjj-m5x4.json index 138a8cf1af5..c54486c2a90 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xwm-mmjj-m5x4/GHSA-2xwm-mmjj-m5x4.json +++ b/advisories/unreviewed/2022/05/GHSA-2xwm-mmjj-m5x4/GHSA-2xwm-mmjj-m5x4.json @@ -7,12 +7,8 @@ "CVE-2010-3212" ], "details": "SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via the frmQuestion parameter in a retrieve action, in conjunction with a user/password PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3276-rg2h-3pr3/GHSA-3276-rg2h-3pr3.json b/advisories/unreviewed/2022/05/GHSA-3276-rg2h-3pr3/GHSA-3276-rg2h-3pr3.json index 7cf6d5f3b1b..184d8822e07 100644 --- a/advisories/unreviewed/2022/05/GHSA-3276-rg2h-3pr3/GHSA-3276-rg2h-3pr3.json +++ b/advisories/unreviewed/2022/05/GHSA-3276-rg2h-3pr3/GHSA-3276-rg2h-3pr3.json @@ -7,12 +7,8 @@ "CVE-2010-2337" ], "details": "Open redirect vulnerability in RSA Federated Identity Manager 4.0 before 4.0.25 and 4.1 before 4.1.26 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3284-h9vj-jh4g/GHSA-3284-h9vj-jh4g.json b/advisories/unreviewed/2022/05/GHSA-3284-h9vj-jh4g/GHSA-3284-h9vj-jh4g.json index 59ce36fceb1..eaf1ef47171 100644 --- a/advisories/unreviewed/2022/05/GHSA-3284-h9vj-jh4g/GHSA-3284-h9vj-jh4g.json +++ b/advisories/unreviewed/2022/05/GHSA-3284-h9vj-jh4g/GHSA-3284-h9vj-jh4g.json @@ -7,12 +7,8 @@ "CVE-2010-1956" ], "details": "Directory traversal vulnerability in the Gadget Factory (com_gadgetfactory) component 1.0.0 and 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-33mp-r2vv-f8h8/GHSA-33mp-r2vv-f8h8.json b/advisories/unreviewed/2022/05/GHSA-33mp-r2vv-f8h8/GHSA-33mp-r2vv-f8h8.json index 5af5f549eeb..a19ba7aed48 100644 --- a/advisories/unreviewed/2022/05/GHSA-33mp-r2vv-f8h8/GHSA-33mp-r2vv-f8h8.json +++ b/advisories/unreviewed/2022/05/GHSA-33mp-r2vv-f8h8/GHSA-33mp-r2vv-f8h8.json @@ -7,12 +7,8 @@ "CVE-2008-7129" ], "details": "XySSL before 0.9 allows remote attackers to cause a denial of service (infinite loop) via an X.509 certificate that does not pass the RSA signature check during verification.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-34g2-p88j-292j/GHSA-34g2-p88j-292j.json b/advisories/unreviewed/2022/05/GHSA-34g2-p88j-292j/GHSA-34g2-p88j-292j.json index 3b5a1ca3dd5..a9aa781cf6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-34g2-p88j-292j/GHSA-34g2-p88j-292j.json +++ b/advisories/unreviewed/2022/05/GHSA-34g2-p88j-292j/GHSA-34g2-p88j-292j.json @@ -7,12 +7,8 @@ "CVE-2010-1714" ], "details": "Directory traversal vulnerability in the Arcade Games (com_arcadegames) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-356w-fr64-xq5w/GHSA-356w-fr64-xq5w.json b/advisories/unreviewed/2022/05/GHSA-356w-fr64-xq5w/GHSA-356w-fr64-xq5w.json index e1d258910c9..4aeb9a81370 100644 --- a/advisories/unreviewed/2022/05/GHSA-356w-fr64-xq5w/GHSA-356w-fr64-xq5w.json +++ b/advisories/unreviewed/2022/05/GHSA-356w-fr64-xq5w/GHSA-356w-fr64-xq5w.json @@ -7,12 +7,8 @@ "CVE-2010-2669" ], "details": "Cross-site scripting (XSS) vulnerability in admin/editors/text/editor-body.php in Orbis CMS 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3834-xp98-q4q8/GHSA-3834-xp98-q4q8.json b/advisories/unreviewed/2022/05/GHSA-3834-xp98-q4q8/GHSA-3834-xp98-q4q8.json index c91a6f7aaf2..5c1fb3782c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-3834-xp98-q4q8/GHSA-3834-xp98-q4q8.json +++ b/advisories/unreviewed/2022/05/GHSA-3834-xp98-q4q8/GHSA-3834-xp98-q4q8.json @@ -7,12 +7,8 @@ "CVE-2010-4455" ], "details": "Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.2 and 11.1.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Apache Plugin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3843-wc38-gc2j/GHSA-3843-wc38-gc2j.json b/advisories/unreviewed/2022/05/GHSA-3843-wc38-gc2j/GHSA-3843-wc38-gc2j.json index a91a953b1c4..1f6b7e94d6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3843-wc38-gc2j/GHSA-3843-wc38-gc2j.json +++ b/advisories/unreviewed/2022/05/GHSA-3843-wc38-gc2j/GHSA-3843-wc38-gc2j.json @@ -7,12 +7,8 @@ "CVE-2010-3488" ], "details": "Directory traversal vulnerability in QuickShare 1.0 allows remote attackers to read arbitrary files via a ... (triple dot) in the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-39hc-fpg9-qhmv/GHSA-39hc-fpg9-qhmv.json b/advisories/unreviewed/2022/05/GHSA-39hc-fpg9-qhmv/GHSA-39hc-fpg9-qhmv.json index 3fc492c9666..ae49eef6eef 100644 --- a/advisories/unreviewed/2022/05/GHSA-39hc-fpg9-qhmv/GHSA-39hc-fpg9-qhmv.json +++ b/advisories/unreviewed/2022/05/GHSA-39hc-fpg9-qhmv/GHSA-39hc-fpg9-qhmv.json @@ -7,12 +7,8 @@ "CVE-2010-3486" ], "details": "Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbitrary files via a (1) ../ (dot dot slash), (2) %5C (encoded backslash), or (3) %255c (double-encoded backslash) in the name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3f9c-f8wr-33fq/GHSA-3f9c-f8wr-33fq.json b/advisories/unreviewed/2022/05/GHSA-3f9c-f8wr-33fq/GHSA-3f9c-f8wr-33fq.json index 40bf408b49f..7bcf28afa0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f9c-f8wr-33fq/GHSA-3f9c-f8wr-33fq.json +++ b/advisories/unreviewed/2022/05/GHSA-3f9c-f8wr-33fq/GHSA-3f9c-f8wr-33fq.json @@ -7,12 +7,8 @@ "CVE-2010-2637" ], "details": "IBM WebSphere MQ 6.0 before 6.0.2.9 and 7.0 before 7.0.1.1 does not encrypt the username and password in the security parameters field, which allows remote attackers to obtain sensitive information by sniffing the network traffic from a .NET client application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3gmf-2qwv-jgjx/GHSA-3gmf-2qwv-jgjx.json b/advisories/unreviewed/2022/05/GHSA-3gmf-2qwv-jgjx/GHSA-3gmf-2qwv-jgjx.json index 99398dcf7df..ac05a7c90c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gmf-2qwv-jgjx/GHSA-3gmf-2qwv-jgjx.json +++ b/advisories/unreviewed/2022/05/GHSA-3gmf-2qwv-jgjx/GHSA-3gmf-2qwv-jgjx.json @@ -7,12 +7,8 @@ "CVE-2010-1996" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS before 2.0.5 allow remote authenticated users, with certain creation privileges, to inject arbitrary web script or HTML via the (1) content parameter in conjunction with a /admin/poll/add PATH_INFO, the (2) meta parameter in conjunction with a /admin/category/add PATH_INFO, and the (3) keyword parameter in conjunction with a /admin/tag/add PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3h26-w882-gmrp/GHSA-3h26-w882-gmrp.json b/advisories/unreviewed/2022/05/GHSA-3h26-w882-gmrp/GHSA-3h26-w882-gmrp.json index 8bb37491c4e..f3aaf6640f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-3h26-w882-gmrp/GHSA-3h26-w882-gmrp.json +++ b/advisories/unreviewed/2022/05/GHSA-3h26-w882-gmrp/GHSA-3h26-w882-gmrp.json @@ -7,12 +7,8 @@ "CVE-2010-2632" ], "details": "Unspecified vulnerability in the FTP Server in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable researcher that this is an issue in the glob implementation in libc that allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3h72-w58w-hgvg/GHSA-3h72-w58w-hgvg.json b/advisories/unreviewed/2022/05/GHSA-3h72-w58w-hgvg/GHSA-3h72-w58w-hgvg.json index afdae17a0d9..1d8e767d1fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-3h72-w58w-hgvg/GHSA-3h72-w58w-hgvg.json +++ b/advisories/unreviewed/2022/05/GHSA-3h72-w58w-hgvg/GHSA-3h72-w58w-hgvg.json @@ -7,12 +7,8 @@ "CVE-2010-2857" ], "details": "Directory traversal vulnerability in the Music Manager component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the cid parameter to album.html.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3jgj-6r4f-qgcx/GHSA-3jgj-6r4f-qgcx.json b/advisories/unreviewed/2022/05/GHSA-3jgj-6r4f-qgcx/GHSA-3jgj-6r4f-qgcx.json index 26a5fc1f737..f9e6424d0a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jgj-6r4f-qgcx/GHSA-3jgj-6r4f-qgcx.json +++ b/advisories/unreviewed/2022/05/GHSA-3jgj-6r4f-qgcx/GHSA-3jgj-6r4f-qgcx.json @@ -7,12 +7,8 @@ "CVE-2010-2142" ], "details": "SQL injection vulnerability in default.asp in Cyberhost allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3jh4-xfq2-x9w9/GHSA-3jh4-xfq2-x9w9.json b/advisories/unreviewed/2022/05/GHSA-3jh4-xfq2-x9w9/GHSA-3jh4-xfq2-x9w9.json index 12fdcd5778f..c5ddfabc0d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jh4-xfq2-x9w9/GHSA-3jh4-xfq2-x9w9.json +++ b/advisories/unreviewed/2022/05/GHSA-3jh4-xfq2-x9w9/GHSA-3jh4-xfq2-x9w9.json @@ -7,12 +7,8 @@ "CVE-2010-4148" ], "details": "Directory traversal vulnerability in AnyConnect 1.2.3.0, and possibly earlier, allows remote FTP servers to write arbitrary files via a \"..\\\" (dot dot backslash) in a filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mgv-3m44-369m/GHSA-3mgv-3m44-369m.json b/advisories/unreviewed/2022/05/GHSA-3mgv-3m44-369m/GHSA-3mgv-3m44-369m.json index d21ba9ad3e5..0191aedf665 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mgv-3m44-369m/GHSA-3mgv-3m44-369m.json +++ b/advisories/unreviewed/2022/05/GHSA-3mgv-3m44-369m/GHSA-3mgv-3m44-369m.json @@ -7,12 +7,8 @@ "CVE-2010-2636" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in sample store pages in IBM WebSphere Commerce 7.0 before 7.0.0.1 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3p3f-hgmm-72qv/GHSA-3p3f-hgmm-72qv.json b/advisories/unreviewed/2022/05/GHSA-3p3f-hgmm-72qv/GHSA-3p3f-hgmm-72qv.json index 3a228446d1f..0d839776fbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-3p3f-hgmm-72qv/GHSA-3p3f-hgmm-72qv.json +++ b/advisories/unreviewed/2022/05/GHSA-3p3f-hgmm-72qv/GHSA-3p3f-hgmm-72qv.json @@ -7,12 +7,8 @@ "CVE-2010-4421" ], "details": "Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3q32-62mw-rw5g/GHSA-3q32-62mw-rw5g.json b/advisories/unreviewed/2022/05/GHSA-3q32-62mw-rw5g/GHSA-3q32-62mw-rw5g.json index 9b52fd44ba9..e5c648de948 100644 --- a/advisories/unreviewed/2022/05/GHSA-3q32-62mw-rw5g/GHSA-3q32-62mw-rw5g.json +++ b/advisories/unreviewed/2022/05/GHSA-3q32-62mw-rw5g/GHSA-3q32-62mw-rw5g.json @@ -7,12 +7,8 @@ "CVE-2010-2332" ], "details": "Impact Financials, Inc. Impact PDF Reader 2.0, 1.2, and other versions for iPhone and iPod touch allows remote attackers to cause a denial of service (server crash) via a \"...\" body in a POST request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3q9m-cg52-56rj/GHSA-3q9m-cg52-56rj.json b/advisories/unreviewed/2022/05/GHSA-3q9m-cg52-56rj/GHSA-3q9m-cg52-56rj.json index be77e6e8ad7..064b4ce3c58 100644 --- a/advisories/unreviewed/2022/05/GHSA-3q9m-cg52-56rj/GHSA-3q9m-cg52-56rj.json +++ b/advisories/unreviewed/2022/05/GHSA-3q9m-cg52-56rj/GHSA-3q9m-cg52-56rj.json @@ -7,12 +7,8 @@ "CVE-2010-3611" ], "details": "ISC DHCP server 4.0 before 4.0.2, 4.1 before 4.1.2, and 4.2 before 4.2.0-P1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a DHCPv6 packet containing a Relay-Forward message without an address in the Relay-Forward link-address field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3rcv-jp3w-f98g/GHSA-3rcv-jp3w-f98g.json b/advisories/unreviewed/2022/05/GHSA-3rcv-jp3w-f98g/GHSA-3rcv-jp3w-f98g.json index 19208d5e40b..3932a0f8a40 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rcv-jp3w-f98g/GHSA-3rcv-jp3w-f98g.json +++ b/advisories/unreviewed/2022/05/GHSA-3rcv-jp3w-f98g/GHSA-3rcv-jp3w-f98g.json @@ -7,12 +7,8 @@ "CVE-2010-2353" ], "details": "The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, which allows remote attackers to discover titles and IDs of controlled nodes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3rp2-pwr4-xjcw/GHSA-3rp2-pwr4-xjcw.json b/advisories/unreviewed/2022/05/GHSA-3rp2-pwr4-xjcw/GHSA-3rp2-pwr4-xjcw.json index d63a83e0d75..5469bb79296 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rp2-pwr4-xjcw/GHSA-3rp2-pwr4-xjcw.json +++ b/advisories/unreviewed/2022/05/GHSA-3rp2-pwr4-xjcw/GHSA-3rp2-pwr4-xjcw.json @@ -7,12 +7,8 @@ "CVE-2010-2428" ], "details": "Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted POST request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vf7-wf97-3857/GHSA-3vf7-wf97-3857.json b/advisories/unreviewed/2022/05/GHSA-3vf7-wf97-3857/GHSA-3vf7-wf97-3857.json index d9891bfde28..455b17a022c 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vf7-wf97-3857/GHSA-3vf7-wf97-3857.json +++ b/advisories/unreviewed/2022/05/GHSA-3vf7-wf97-3857/GHSA-3vf7-wf97-3857.json @@ -7,12 +7,8 @@ "CVE-2010-3510" ], "details": "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.3, 10.0.2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Node Manager.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3w5g-8rr6-f44g/GHSA-3w5g-8rr6-f44g.json b/advisories/unreviewed/2022/05/GHSA-3w5g-8rr6-f44g/GHSA-3w5g-8rr6-f44g.json index a2483c0646e..be0d3745dfe 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w5g-8rr6-f44g/GHSA-3w5g-8rr6-f44g.json +++ b/advisories/unreviewed/2022/05/GHSA-3w5g-8rr6-f44g/GHSA-3w5g-8rr6-f44g.json @@ -7,12 +7,8 @@ "CVE-2010-2137" ], "details": "PHP remote file inclusion vulnerability in _center.php in ProMan 0.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3w5q-79rf-8vf9/GHSA-3w5q-79rf-8vf9.json b/advisories/unreviewed/2022/05/GHSA-3w5q-79rf-8vf9/GHSA-3w5q-79rf-8vf9.json index f94cabe17ff..40a6fc3904c 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w5q-79rf-8vf9/GHSA-3w5q-79rf-8vf9.json +++ b/advisories/unreviewed/2022/05/GHSA-3w5q-79rf-8vf9/GHSA-3w5q-79rf-8vf9.json @@ -7,12 +7,8 @@ "CVE-2010-1923" ], "details": "SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgallery action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wjw-f8gp-589c/GHSA-3wjw-f8gp-589c.json b/advisories/unreviewed/2022/05/GHSA-3wjw-f8gp-589c/GHSA-3wjw-f8gp-589c.json index 0b2b52f12b7..a98295b5738 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wjw-f8gp-589c/GHSA-3wjw-f8gp-589c.json +++ b/advisories/unreviewed/2022/05/GHSA-3wjw-f8gp-589c/GHSA-3wjw-f8gp-589c.json @@ -7,12 +7,8 @@ "CVE-2010-1725" ], "details": "SQL injection vulnerability in offers_buy.php in Alibaba Clone Platinum allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3xrm-g354-vfw9/GHSA-3xrm-g354-vfw9.json b/advisories/unreviewed/2022/05/GHSA-3xrm-g354-vfw9/GHSA-3xrm-g354-vfw9.json index 0d897f66ece..422c26a45bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xrm-g354-vfw9/GHSA-3xrm-g354-vfw9.json +++ b/advisories/unreviewed/2022/05/GHSA-3xrm-g354-vfw9/GHSA-3xrm-g354-vfw9.json @@ -7,12 +7,8 @@ "CVE-2010-3210" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Multi-lingual E-Commerce System 0.2 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) checkout2-CYM.php, (2) checkout2-EN.php, (3) checkout2-FR.php, (4) cat-FR.php, (5) cat-EN.php, (6) cat-CYM.php, (7) checkout1-CYM.php, (8) checkout1-EN.php, (9) checkout1-FR.php, (10) prod-CYM.php, (11) prod-EN.php, and (12) prod-FR.php in inc/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-444r-jhgm-mr5f/GHSA-444r-jhgm-mr5f.json b/advisories/unreviewed/2022/05/GHSA-444r-jhgm-mr5f/GHSA-444r-jhgm-mr5f.json index ed23eeb55dd..ca48f9736a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-444r-jhgm-mr5f/GHSA-444r-jhgm-mr5f.json +++ b/advisories/unreviewed/2022/05/GHSA-444r-jhgm-mr5f/GHSA-444r-jhgm-mr5f.json @@ -7,12 +7,8 @@ "CVE-2010-1962" ], "details": "Unspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.2.1.870.0 allows remote attackers to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-44g8-q969-2xj9/GHSA-44g8-q969-2xj9.json b/advisories/unreviewed/2022/05/GHSA-44g8-q969-2xj9/GHSA-44g8-q969-2xj9.json index fc2f66a89de..983b102976f 100644 --- a/advisories/unreviewed/2022/05/GHSA-44g8-q969-2xj9/GHSA-44g8-q969-2xj9.json +++ b/advisories/unreviewed/2022/05/GHSA-44g8-q969-2xj9/GHSA-44g8-q969-2xj9.json @@ -7,12 +7,8 @@ "CVE-2010-1528" ], "details": "PHP remote file inclusion vulnerability in include/template.php in Uiga Proxy, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44gx-rvj5-7hc2/GHSA-44gx-rvj5-7hc2.json b/advisories/unreviewed/2022/05/GHSA-44gx-rvj5-7hc2/GHSA-44gx-rvj5-7hc2.json index 2dc33569ee2..00c8fcfe830 100644 --- a/advisories/unreviewed/2022/05/GHSA-44gx-rvj5-7hc2/GHSA-44gx-rvj5-7hc2.json +++ b/advisories/unreviewed/2022/05/GHSA-44gx-rvj5-7hc2/GHSA-44gx-rvj5-7hc2.json @@ -7,12 +7,8 @@ "CVE-2008-7141" ], "details": "Cross-site scripting (XSS) vulnerability in setup.php in @lex Poll 2.1 allows remote attackers to inject arbitrary web script or HTML via the language_setup parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-452f-rx2g-gx8c/GHSA-452f-rx2g-gx8c.json b/advisories/unreviewed/2022/05/GHSA-452f-rx2g-gx8c/GHSA-452f-rx2g-gx8c.json index d8f2ae9d660..fe2db2bcc3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-452f-rx2g-gx8c/GHSA-452f-rx2g-gx8c.json +++ b/advisories/unreviewed/2022/05/GHSA-452f-rx2g-gx8c/GHSA-452f-rx2g-gx8c.json @@ -7,12 +7,8 @@ "CVE-2010-4418" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft and JDEdwards Suite 8.50.11 through 8.50.15 and 8.51GA through 8.51.05 allows remote attackers to affect confidentiality, integrity, and availability, related to PIA Core Technology.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-45pg-g48p-xcpm/GHSA-45pg-g48p-xcpm.json b/advisories/unreviewed/2022/05/GHSA-45pg-g48p-xcpm/GHSA-45pg-g48p-xcpm.json index abd0d7b80ba..a4ebda7ecf2 100644 --- a/advisories/unreviewed/2022/05/GHSA-45pg-g48p-xcpm/GHSA-45pg-g48p-xcpm.json +++ b/advisories/unreviewed/2022/05/GHSA-45pg-g48p-xcpm/GHSA-45pg-g48p-xcpm.json @@ -7,12 +7,8 @@ "CVE-2010-3915" ], "details": "Unspecified vulnerability in JustSystems Ichitaro and Ichitaro Government allows remote attackers to execute arbitrary code via a crafted document, a different vulnerability than CVE-2010-3916.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-477r-rmrp-5834/GHSA-477r-rmrp-5834.json b/advisories/unreviewed/2022/05/GHSA-477r-rmrp-5834/GHSA-477r-rmrp-5834.json index 7722f828169..f4577fa4c37 100644 --- a/advisories/unreviewed/2022/05/GHSA-477r-rmrp-5834/GHSA-477r-rmrp-5834.json +++ b/advisories/unreviewed/2022/05/GHSA-477r-rmrp-5834/GHSA-477r-rmrp-5834.json @@ -7,12 +7,8 @@ "CVE-2010-2688" ], "details": "SQL injection vulnerability in detail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrary SQL commands via the ID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-48v8-cjg7-hh69/GHSA-48v8-cjg7-hh69.json b/advisories/unreviewed/2022/05/GHSA-48v8-cjg7-hh69/GHSA-48v8-cjg7-hh69.json index 158932c8fb0..78b553716cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-48v8-cjg7-hh69/GHSA-48v8-cjg7-hh69.json +++ b/advisories/unreviewed/2022/05/GHSA-48v8-cjg7-hh69/GHSA-48v8-cjg7-hh69.json @@ -7,12 +7,8 @@ "CVE-2010-4366" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in forum_new_topic.php in Chameleon Social Networking allow remote attackers to inject arbitrary web script or HTML via the (1) thread_title and (2) thread_description parameters in a message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-48vq-m47w-3x7g/GHSA-48vq-m47w-3x7g.json b/advisories/unreviewed/2022/05/GHSA-48vq-m47w-3x7g/GHSA-48vq-m47w-3x7g.json index 631e9b00fa5..4d43be5b741 100644 --- a/advisories/unreviewed/2022/05/GHSA-48vq-m47w-3x7g/GHSA-48vq-m47w-3x7g.json +++ b/advisories/unreviewed/2022/05/GHSA-48vq-m47w-3x7g/GHSA-48vq-m47w-3x7g.json @@ -7,12 +7,8 @@ "CVE-2010-1744" ], "details": "SQL injection vulnerability in product.html in B2B Gold Script allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-49vq-qc87-chpf/GHSA-49vq-qc87-chpf.json b/advisories/unreviewed/2022/05/GHSA-49vq-qc87-chpf/GHSA-49vq-qc87-chpf.json index 5081981b703..f4df4d142be 100644 --- a/advisories/unreviewed/2022/05/GHSA-49vq-qc87-chpf/GHSA-49vq-qc87-chpf.json +++ b/advisories/unreviewed/2022/05/GHSA-49vq-qc87-chpf/GHSA-49vq-qc87-chpf.json @@ -7,12 +7,8 @@ "CVE-2010-2604" ], "details": "Multiple buffer overflows in the PDF Distiller in the BlackBerry Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server 4.1.3 through 5.0.2, and Enterprise Server Express 5.0.1 and 5.0.2, allow remote attackers to execute arbitrary code via a crafted PDF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4c52-gf37-2pfp/GHSA-4c52-gf37-2pfp.json b/advisories/unreviewed/2022/05/GHSA-4c52-gf37-2pfp/GHSA-4c52-gf37-2pfp.json index 0a887cbaa33..a4eccb48e2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c52-gf37-2pfp/GHSA-4c52-gf37-2pfp.json +++ b/advisories/unreviewed/2022/05/GHSA-4c52-gf37-2pfp/GHSA-4c52-gf37-2pfp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4gp2-553h-2rmm/GHSA-4gp2-553h-2rmm.json b/advisories/unreviewed/2022/05/GHSA-4gp2-553h-2rmm/GHSA-4gp2-553h-2rmm.json index 874e8932c1b..3c529f15f5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gp2-553h-2rmm/GHSA-4gp2-553h-2rmm.json +++ b/advisories/unreviewed/2022/05/GHSA-4gp2-553h-2rmm/GHSA-4gp2-553h-2rmm.json @@ -7,12 +7,8 @@ "CVE-2010-2696" ], "details": "SQL injection vulnerability in gallery/index.php in Sijio Community Software allows remote attackers to execute arbitrary SQL commands via the parent parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4jg3-45hc-h63q/GHSA-4jg3-45hc-h63q.json b/advisories/unreviewed/2022/05/GHSA-4jg3-45hc-h63q/GHSA-4jg3-45hc-h63q.json index 4b8fca9240f..201ee027908 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jg3-45hc-h63q/GHSA-4jg3-45hc-h63q.json +++ b/advisories/unreviewed/2022/05/GHSA-4jg3-45hc-h63q/GHSA-4jg3-45hc-h63q.json @@ -7,12 +7,8 @@ "CVE-2010-2670" ], "details": "SQL injection vulnerability in recipedetail.php in BrotherScripts Recipe Website allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4jpm-9h3f-25gq/GHSA-4jpm-9h3f-25gq.json b/advisories/unreviewed/2022/05/GHSA-4jpm-9h3f-25gq/GHSA-4jpm-9h3f-25gq.json index 77f636385df..52ce2ee6e91 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jpm-9h3f-25gq/GHSA-4jpm-9h3f-25gq.json +++ b/advisories/unreviewed/2022/05/GHSA-4jpm-9h3f-25gq/GHSA-4jpm-9h3f-25gq.json @@ -7,12 +7,8 @@ "CVE-2010-2923" ], "details": "SQL injection vulnerability in the YouTube (com_youtube) component 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_cate parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4jqc-6m5c-wg7v/GHSA-4jqc-6m5c-wg7v.json b/advisories/unreviewed/2022/05/GHSA-4jqc-6m5c-wg7v/GHSA-4jqc-6m5c-wg7v.json index 8ef09e91261..7461d9e71e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jqc-6m5c-wg7v/GHSA-4jqc-6m5c-wg7v.json +++ b/advisories/unreviewed/2022/05/GHSA-4jqc-6m5c-wg7v/GHSA-4jqc-6m5c-wg7v.json @@ -7,12 +7,8 @@ "CVE-2010-2813" ], "details": "functions/imap_general.php in SquirrelMail before 1.4.21 does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption) by making many IMAP login attempts with different usernames, leading to the creation of many preferences files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4m9g-w7wc-fj28/GHSA-4m9g-w7wc-fj28.json b/advisories/unreviewed/2022/05/GHSA-4m9g-w7wc-fj28/GHSA-4m9g-w7wc-fj28.json index 0843a0772a5..4aa1be86805 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m9g-w7wc-fj28/GHSA-4m9g-w7wc-fj28.json +++ b/advisories/unreviewed/2022/05/GHSA-4m9g-w7wc-fj28/GHSA-4m9g-w7wc-fj28.json @@ -7,12 +7,8 @@ "CVE-2010-2360" ], "details": "Multiple buffer overflows in Winny 2.0b7.1 and earlier might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2006-2007.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4mw2-9w62-mvpx/GHSA-4mw2-9w62-mvpx.json b/advisories/unreviewed/2022/05/GHSA-4mw2-9w62-mvpx/GHSA-4mw2-9w62-mvpx.json index 0e129813947..608f245bda7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mw2-9w62-mvpx/GHSA-4mw2-9w62-mvpx.json +++ b/advisories/unreviewed/2022/05/GHSA-4mw2-9w62-mvpx/GHSA-4mw2-9w62-mvpx.json @@ -7,12 +7,8 @@ "CVE-2010-4570" ], "details": "Cross-site scripting (XSS) vulnerability in the duplicate-detection functionality in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web script or HTML via the summary field, related to the DataTable widget in YUI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4r36-c55m-fp5v/GHSA-4r36-c55m-fp5v.json b/advisories/unreviewed/2022/05/GHSA-4r36-c55m-fp5v/GHSA-4r36-c55m-fp5v.json index 081d745857a..941644004a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-4r36-c55m-fp5v/GHSA-4r36-c55m-fp5v.json +++ b/advisories/unreviewed/2022/05/GHSA-4r36-c55m-fp5v/GHSA-4r36-c55m-fp5v.json @@ -7,12 +7,8 @@ "CVE-2008-7112" ], "details": "The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to cause a denial of service (hang or crash) via invalid field length values in a malformed (1) document or (2) request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4r4v-5gvp-ww57/GHSA-4r4v-5gvp-ww57.json b/advisories/unreviewed/2022/05/GHSA-4r4v-5gvp-ww57/GHSA-4r4v-5gvp-ww57.json index 1531990e833..d3a493a3f03 100644 --- a/advisories/unreviewed/2022/05/GHSA-4r4v-5gvp-ww57/GHSA-4r4v-5gvp-ww57.json +++ b/advisories/unreviewed/2022/05/GHSA-4r4v-5gvp-ww57/GHSA-4r4v-5gvp-ww57.json @@ -7,12 +7,8 @@ "CVE-2010-2915" ], "details": "SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4r6q-r4w3-542r/GHSA-4r6q-r4w3-542r.json b/advisories/unreviewed/2022/05/GHSA-4r6q-r4w3-542r/GHSA-4r6q-r4w3-542r.json index 459ff5a8f48..86284b7989e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4r6q-r4w3-542r/GHSA-4r6q-r4w3-542r.json +++ b/advisories/unreviewed/2022/05/GHSA-4r6q-r4w3-542r/GHSA-4r6q-r4w3-542r.json @@ -7,12 +7,8 @@ "CVE-2010-4444" ], "details": "Unspecified vulnerability in Oracle Sun Java System Access Manager and Oracle OpenSSO 7, 7.1, and 8 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vw6-c9w3-qj7g/GHSA-4vw6-c9w3-qj7g.json b/advisories/unreviewed/2022/05/GHSA-4vw6-c9w3-qj7g/GHSA-4vw6-c9w3-qj7g.json index 0d7a91e4315..7f7de37866c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vw6-c9w3-qj7g/GHSA-4vw6-c9w3-qj7g.json +++ b/advisories/unreviewed/2022/05/GHSA-4vw6-c9w3-qj7g/GHSA-4vw6-c9w3-qj7g.json @@ -7,12 +7,8 @@ "CVE-2010-2191" ], "details": "The (1) parse_str, (2) preg_match, (3) unpack, and (4) pack functions; the (5) ZEND_FETCH_RW, (6) ZEND_CONCAT, and (7) ZEND_ASSIGN_CONCAT opcodes; and the (8) ArrayObject::uasort method in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal function or handler. NOTE: vectors 2 through 4 are related to the call time pass by reference feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4xqh-x493-83xm/GHSA-4xqh-x493-83xm.json b/advisories/unreviewed/2022/05/GHSA-4xqh-x493-83xm/GHSA-4xqh-x493-83xm.json index 17cd39b3fed..5b17b690b51 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xqh-x493-83xm/GHSA-4xqh-x493-83xm.json +++ b/advisories/unreviewed/2022/05/GHSA-4xqh-x493-83xm/GHSA-4xqh-x493-83xm.json @@ -7,12 +7,8 @@ "CVE-2010-4442" ], "details": "Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows local users to affect availability via unknown vectors related to the Kernel.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-532r-m868-3f7q/GHSA-532r-m868-3f7q.json b/advisories/unreviewed/2022/05/GHSA-532r-m868-3f7q/GHSA-532r-m868-3f7q.json index 25fb5834b4f..df54cb4d803 100644 --- a/advisories/unreviewed/2022/05/GHSA-532r-m868-3f7q/GHSA-532r-m868-3f7q.json +++ b/advisories/unreviewed/2022/05/GHSA-532r-m868-3f7q/GHSA-532r-m868-3f7q.json @@ -7,12 +7,8 @@ "CVE-2010-4464" ], "details": "Unspecified vulnerability in Oracle Sun Convergence 1.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Webmail.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-53g7-wg5x-3j59/GHSA-53g7-wg5x-3j59.json b/advisories/unreviewed/2022/05/GHSA-53g7-wg5x-3j59/GHSA-53g7-wg5x-3j59.json index 2fe2c184e5d..a2996437378 100644 --- a/advisories/unreviewed/2022/05/GHSA-53g7-wg5x-3j59/GHSA-53g7-wg5x-3j59.json +++ b/advisories/unreviewed/2022/05/GHSA-53g7-wg5x-3j59/GHSA-53g7-wg5x-3j59.json @@ -7,12 +7,8 @@ "CVE-2010-2313" ], "details": "Directory traversal vulnerability in index.php in Anodyne Productions SIMM Management System (SMS) 2.6.10, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter to index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5469-vf4f-5v5j/GHSA-5469-vf4f-5v5j.json b/advisories/unreviewed/2022/05/GHSA-5469-vf4f-5v5j/GHSA-5469-vf4f-5v5j.json index 68ce38081a2..4faaf953839 100644 --- a/advisories/unreviewed/2022/05/GHSA-5469-vf4f-5v5j/GHSA-5469-vf4f-5v5j.json +++ b/advisories/unreviewed/2022/05/GHSA-5469-vf4f-5v5j/GHSA-5469-vf4f-5v5j.json @@ -7,12 +7,8 @@ "CVE-2010-4449" ], "details": "Unspecified vulnerability in the Audit Vault component in Oracle Audit Vault 10.2.3.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that this issue is related to a crafted parameter in an action.execute request to the av component on TCP port 5700.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-55m2-3xw2-r6v4/GHSA-55m2-3xw2-r6v4.json b/advisories/unreviewed/2022/05/GHSA-55m2-3xw2-r6v4/GHSA-55m2-3xw2-r6v4.json index eab49e99ed4..6e1fb46a799 100644 --- a/advisories/unreviewed/2022/05/GHSA-55m2-3xw2-r6v4/GHSA-55m2-3xw2-r6v4.json +++ b/advisories/unreviewed/2022/05/GHSA-55m2-3xw2-r6v4/GHSA-55m2-3xw2-r6v4.json @@ -7,12 +7,8 @@ "CVE-2010-2338" ], "details": "Multiple SQL injection vulnerabilities in redir.asp in VU Web Visitor Analyst allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-55r3-cchv-jc6q/GHSA-55r3-cchv-jc6q.json b/advisories/unreviewed/2022/05/GHSA-55r3-cchv-jc6q/GHSA-55r3-cchv-jc6q.json index 2ad3d00273c..2b5c7af6e8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-55r3-cchv-jc6q/GHSA-55r3-cchv-jc6q.json +++ b/advisories/unreviewed/2022/05/GHSA-55r3-cchv-jc6q/GHSA-55r3-cchv-jc6q.json @@ -7,12 +7,8 @@ "CVE-2010-2357" ], "details": "SQL injection vulnerability in index.php in Eicra Realestate Script 1.0 and 1.6.0 allows remote attackers to execute arbitrary SQL commands via the p_id parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56gp-vg62-4mff/GHSA-56gp-vg62-4mff.json b/advisories/unreviewed/2022/05/GHSA-56gp-vg62-4mff/GHSA-56gp-vg62-4mff.json index 19267f0ac3a..39e4670eafc 100644 --- a/advisories/unreviewed/2022/05/GHSA-56gp-vg62-4mff/GHSA-56gp-vg62-4mff.json +++ b/advisories/unreviewed/2022/05/GHSA-56gp-vg62-4mff/GHSA-56gp-vg62-4mff.json @@ -7,12 +7,8 @@ "CVE-2010-2030" ], "details": "Cross-site scripting (XSS) vulnerability in the External Link Page module 5.x before 5.x-1.0 and 6.x before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to the administration and redirect pages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-579f-rm77-fpx9/GHSA-579f-rm77-fpx9.json b/advisories/unreviewed/2022/05/GHSA-579f-rm77-fpx9/GHSA-579f-rm77-fpx9.json index f517fcceaf8..0b7094f5b47 100644 --- a/advisories/unreviewed/2022/05/GHSA-579f-rm77-fpx9/GHSA-579f-rm77-fpx9.json +++ b/advisories/unreviewed/2022/05/GHSA-579f-rm77-fpx9/GHSA-579f-rm77-fpx9.json @@ -7,12 +7,8 @@ "CVE-2010-3603" ], "details": "Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to hijack the authentication of administrators for requests that rename arbitrary files, as demonstrated by causing the user.config file to be moved, leading to a denial of service (service stop) and possibly the exposure of sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-584j-wcxv-phqw/GHSA-584j-wcxv-phqw.json b/advisories/unreviewed/2022/05/GHSA-584j-wcxv-phqw/GHSA-584j-wcxv-phqw.json index db7670abcf8..d337a3846d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-584j-wcxv-phqw/GHSA-584j-wcxv-phqw.json +++ b/advisories/unreviewed/2022/05/GHSA-584j-wcxv-phqw/GHSA-584j-wcxv-phqw.json @@ -7,12 +7,8 @@ "CVE-2010-3586" ], "details": "Unspecified vulnerability in Oracle Solaris 9 allows local users to affect confidentiality and integrity via unknown vectors related to XScreenSaver.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5cr6-f74m-mvgp/GHSA-5cr6-f74m-mvgp.json b/advisories/unreviewed/2022/05/GHSA-5cr6-f74m-mvgp/GHSA-5cr6-f74m-mvgp.json index 36c448df50f..e65db626c12 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cr6-f74m-mvgp/GHSA-5cr6-f74m-mvgp.json +++ b/advisories/unreviewed/2022/05/GHSA-5cr6-f74m-mvgp/GHSA-5cr6-f74m-mvgp.json @@ -7,12 +7,8 @@ "CVE-2010-2518" ], "details": "Unspecified vulnerability in the P8 Content Engine (P8CE) 4.5.1 before FP3 and the P8 Content Search Engine (P8CSE) before 4.5.0 FP3 and 4.5.1 before FP1, as used in IBM FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), allows remote attackers to gain privileges via unknown vectors. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5fjr-xvv2-4qf4/GHSA-5fjr-xvv2-4qf4.json b/advisories/unreviewed/2022/05/GHSA-5fjr-xvv2-4qf4/GHSA-5fjr-xvv2-4qf4.json index 64e7231b81e..e7a688b0b9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fjr-xvv2-4qf4/GHSA-5fjr-xvv2-4qf4.json +++ b/advisories/unreviewed/2022/05/GHSA-5fjr-xvv2-4qf4/GHSA-5fjr-xvv2-4qf4.json @@ -7,12 +7,8 @@ "CVE-2010-4631" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ASPilot Pilot Cart 7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) countrycode parameter to contact.asp, USERNAME parameter to (2) gateway.asp and (3) cart.asp, and the specific parameter to (4) quote.asp and (5) buyitnow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5j27-hjpv-hq78/GHSA-5j27-hjpv-hq78.json b/advisories/unreviewed/2022/05/GHSA-5j27-hjpv-hq78/GHSA-5j27-hjpv-hq78.json index 9da02b9307d..d507816d70e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5j27-hjpv-hq78/GHSA-5j27-hjpv-hq78.json +++ b/advisories/unreviewed/2022/05/GHSA-5j27-hjpv-hq78/GHSA-5j27-hjpv-hq78.json @@ -7,12 +7,8 @@ "CVE-2010-3589" ], "details": "Unspecified vulnerability in the Oracle Application Object Library component in Oracle Applications 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Logout.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5j8g-v93x-4959/GHSA-5j8g-v93x-4959.json b/advisories/unreviewed/2022/05/GHSA-5j8g-v93x-4959/GHSA-5j8g-v93x-4959.json index 9f8aa3e9022..1f6c1592583 100644 --- a/advisories/unreviewed/2022/05/GHSA-5j8g-v93x-4959/GHSA-5j8g-v93x-4959.json +++ b/advisories/unreviewed/2022/05/GHSA-5j8g-v93x-4959/GHSA-5j8g-v93x-4959.json @@ -7,12 +7,8 @@ "CVE-2010-4355" ], "details": "Cross-site scripting (XSS) vulnerability in DaDaBIK before 4.3 beta2, when the insert or edit feature is enabled, allows remote authenticated users to inject arbitrary web script or HTML via the select_single parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5mhf-ffc5-mcv4/GHSA-5mhf-ffc5-mcv4.json b/advisories/unreviewed/2022/05/GHSA-5mhf-ffc5-mcv4/GHSA-5mhf-ffc5-mcv4.json index ab040d90248..4f3161edbf0 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mhf-ffc5-mcv4/GHSA-5mhf-ffc5-mcv4.json +++ b/advisories/unreviewed/2022/05/GHSA-5mhf-ffc5-mcv4/GHSA-5mhf-ffc5-mcv4.json @@ -7,12 +7,8 @@ "CVE-2010-4617" ], "details": "Directory traversal vulnerability in the JotLoader (com_jotloader) component 2.2.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the section parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5pc4-3627-qr4j/GHSA-5pc4-3627-qr4j.json b/advisories/unreviewed/2022/05/GHSA-5pc4-3627-qr4j/GHSA-5pc4-3627-qr4j.json index 27f06a51822..fd2bbcd90d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pc4-3627-qr4j/GHSA-5pc4-3627-qr4j.json +++ b/advisories/unreviewed/2022/05/GHSA-5pc4-3627-qr4j/GHSA-5pc4-3627-qr4j.json @@ -7,12 +7,8 @@ "CVE-2010-1874" ], "details": "SQL injection vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlisting action to index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5pgp-g2r8-7gjv/GHSA-5pgp-g2r8-7gjv.json b/advisories/unreviewed/2022/05/GHSA-5pgp-g2r8-7gjv/GHSA-5pgp-g2r8-7gjv.json index 943e7222d52..47fcb3d22dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pgp-g2r8-7gjv/GHSA-5pgp-g2r8-7gjv.json +++ b/advisories/unreviewed/2022/05/GHSA-5pgp-g2r8-7gjv/GHSA-5pgp-g2r8-7gjv.json @@ -7,12 +7,8 @@ "CVE-2010-2315" ], "details": "PHP remote file inclusion vulnerability in picturelib.php in SmartISoft phpBazar 2.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5v5r-2x79-f5wc/GHSA-5v5r-2x79-f5wc.json b/advisories/unreviewed/2022/05/GHSA-5v5r-2x79-f5wc/GHSA-5v5r-2x79-f5wc.json index 97eea88b658..9773c4f774a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v5r-2x79-f5wc/GHSA-5v5r-2x79-f5wc.json +++ b/advisories/unreviewed/2022/05/GHSA-5v5r-2x79-f5wc/GHSA-5v5r-2x79-f5wc.json @@ -7,12 +7,8 @@ "CVE-2010-2849" ], "details": "Cross-site scripting (XSS) vulnerability in productionnu2/nuedit.php in nuBuilder 10.04.20, and possibly other versions before 10.07.12, allows remote attackers to inject arbitrary web script or HTML via the f parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5x5p-c5pf-7mmq/GHSA-5x5p-c5pf-7mmq.json b/advisories/unreviewed/2022/05/GHSA-5x5p-c5pf-7mmq/GHSA-5x5p-c5pf-7mmq.json index fbe5c1e517c..f53fbe757e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x5p-c5pf-7mmq/GHSA-5x5p-c5pf-7mmq.json +++ b/advisories/unreviewed/2022/05/GHSA-5x5p-c5pf-7mmq/GHSA-5x5p-c5pf-7mmq.json @@ -7,12 +7,8 @@ "CVE-2010-2129" ], "details": "Directory traversal vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.1 and 1.0.3 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5xrr-g352-hq7j/GHSA-5xrr-g352-hq7j.json b/advisories/unreviewed/2022/05/GHSA-5xrr-g352-hq7j/GHSA-5xrr-g352-hq7j.json index 6f0cc7d260e..ea3b5422502 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xrr-g352-hq7j/GHSA-5xrr-g352-hq7j.json +++ b/advisories/unreviewed/2022/05/GHSA-5xrr-g352-hq7j/GHSA-5xrr-g352-hq7j.json @@ -7,12 +7,8 @@ "CVE-2010-2454" ], "details": "Apple Safari does not properly manage the address bar between the request to open a URL and the retrieval of the new document's content, which might allow remote attackers to conduct spoofing attacks via a crafted HTML document, a related issue to CVE-2010-1206.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6546-f3c3-rp4g/GHSA-6546-f3c3-rp4g.json b/advisories/unreviewed/2022/05/GHSA-6546-f3c3-rp4g/GHSA-6546-f3c3-rp4g.json index cde866c7870..6754489bd69 100644 --- a/advisories/unreviewed/2022/05/GHSA-6546-f3c3-rp4g/GHSA-6546-f3c3-rp4g.json +++ b/advisories/unreviewed/2022/05/GHSA-6546-f3c3-rp4g/GHSA-6546-f3c3-rp4g.json @@ -7,12 +7,8 @@ "CVE-2010-4569" ], "details": "Cross-site scripting (XSS) vulnerability in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web script or HTML via the real name field of a user account, related to the AutoComplete widget in YUI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6737-58mm-3gwv/GHSA-6737-58mm-3gwv.json b/advisories/unreviewed/2022/05/GHSA-6737-58mm-3gwv/GHSA-6737-58mm-3gwv.json index 081c1781127..f00dddbbc1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6737-58mm-3gwv/GHSA-6737-58mm-3gwv.json +++ b/advisories/unreviewed/2022/05/GHSA-6737-58mm-3gwv/GHSA-6737-58mm-3gwv.json @@ -7,12 +7,8 @@ "CVE-2010-1710" ], "details": "Directory traversal vulnerability in login.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the idioma parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-692p-j7fj-c497/GHSA-692p-j7fj-c497.json b/advisories/unreviewed/2022/05/GHSA-692p-j7fj-c497/GHSA-692p-j7fj-c497.json index 3467e01cc95..2ec068e6f7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-692p-j7fj-c497/GHSA-692p-j7fj-c497.json +++ b/advisories/unreviewed/2022/05/GHSA-692p-j7fj-c497/GHSA-692p-j7fj-c497.json @@ -7,12 +7,8 @@ "CVE-2010-2152" ], "details": "Unspecified vulnerability in JustSystems Ichitaro 2004 through 2009, Ichitaro Government 2006 through 2009, and Just School 2008 and 2009 allows remote attackers to execute arbitrary code via unknown vectors related to \"product character attribute processing\" for a document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-69j8-3jrp-rcv2/GHSA-69j8-3jrp-rcv2.json b/advisories/unreviewed/2022/05/GHSA-69j8-3jrp-rcv2/GHSA-69j8-3jrp-rcv2.json index ed147b76ce5..8f6a0f45f9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-69j8-3jrp-rcv2/GHSA-69j8-3jrp-rcv2.json +++ b/advisories/unreviewed/2022/05/GHSA-69j8-3jrp-rcv2/GHSA-69j8-3jrp-rcv2.json @@ -7,12 +7,8 @@ "CVE-2010-4216" ], "details": "IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 does not properly handle invalid buffer references in LDAP BER requests, which might allow remote attackers to cause a denial of service (daemon crash) via vectors involving a buffer that has a memory address near the maximum possible address.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6c98-qgjr-fc37/GHSA-6c98-qgjr-fc37.json b/advisories/unreviewed/2022/05/GHSA-6c98-qgjr-fc37/GHSA-6c98-qgjr-fc37.json index 08160b271e1..5d5ff5cf2df 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c98-qgjr-fc37/GHSA-6c98-qgjr-fc37.json +++ b/advisories/unreviewed/2022/05/GHSA-6c98-qgjr-fc37/GHSA-6c98-qgjr-fc37.json @@ -7,12 +7,8 @@ "CVE-2010-1998" ], "details": "Cross-site scripting (XSS) vulnerability in the CCK TableField module 6.x before 6.x-1.2 for Drupal allows remote authenticated users, with certain node creation or editing privileges, to inject arbitrary web script or HTML via table headers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6gj2-w23f-chf3/GHSA-6gj2-w23f-chf3.json b/advisories/unreviewed/2022/05/GHSA-6gj2-w23f-chf3/GHSA-6gj2-w23f-chf3.json index 98879b4cd04..80c18f011e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gj2-w23f-chf3/GHSA-6gj2-w23f-chf3.json +++ b/advisories/unreviewed/2022/05/GHSA-6gj2-w23f-chf3/GHSA-6gj2-w23f-chf3.json @@ -7,12 +7,8 @@ "CVE-2010-2197" ], "details": "rpmbuild in RPM 4.8.0 and earlier does not properly parse the syntax of spec files, which allows user-assisted remote attackers to remove home directories via vectors involving a ;~ (semicolon tilde) sequence in a Name tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6gj8-xjr6-v47j/GHSA-6gj8-xjr6-v47j.json b/advisories/unreviewed/2022/05/GHSA-6gj8-xjr6-v47j/GHSA-6gj8-xjr6-v47j.json index 78dadbaab5b..d9e63ae6311 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gj8-xjr6-v47j/GHSA-6gj8-xjr6-v47j.json +++ b/advisories/unreviewed/2022/05/GHSA-6gj8-xjr6-v47j/GHSA-6gj8-xjr6-v47j.json @@ -7,12 +7,8 @@ "CVE-2010-2420" ], "details": "Multiple unspecified vulnerabilities in Fenrir Inc. ActiveGeckoBrowser 1.0.0 and 1.0.5 alpha, a module for the Sleipnir web browser, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to the Gecko engine.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6gmg-vxx6-mrxx/GHSA-6gmg-vxx6-mrxx.json b/advisories/unreviewed/2022/05/GHSA-6gmg-vxx6-mrxx/GHSA-6gmg-vxx6-mrxx.json index 54b00cc9d58..8a1f337e208 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gmg-vxx6-mrxx/GHSA-6gmg-vxx6-mrxx.json +++ b/advisories/unreviewed/2022/05/GHSA-6gmg-vxx6-mrxx/GHSA-6gmg-vxx6-mrxx.json @@ -7,12 +7,8 @@ "CVE-2010-4630" ], "details": "Cross-site scripting (XSS) vulnerability in pages/admin/surveys/create.php in the WP Survey And Quiz Tool plugin 1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6h59-cw63-73qp/GHSA-6h59-cw63-73qp.json b/advisories/unreviewed/2022/05/GHSA-6h59-cw63-73qp/GHSA-6h59-cw63-73qp.json index e3b6b768160..e9952d26690 100644 --- a/advisories/unreviewed/2022/05/GHSA-6h59-cw63-73qp/GHSA-6h59-cw63-73qp.json +++ b/advisories/unreviewed/2022/05/GHSA-6h59-cw63-73qp/GHSA-6h59-cw63-73qp.json @@ -7,12 +7,8 @@ "CVE-2010-2616" ], "details": "SQL injection vulnerability in bible.php in PHP Bible Search, probably 0.99, allows remote attackers to execute arbitrary SQL commands via the chapter parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6jgq-cppp-pvm8/GHSA-6jgq-cppp-pvm8.json b/advisories/unreviewed/2022/05/GHSA-6jgq-cppp-pvm8/GHSA-6jgq-cppp-pvm8.json index 2730eb5ceed..7292c89a0ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jgq-cppp-pvm8/GHSA-6jgq-cppp-pvm8.json +++ b/advisories/unreviewed/2022/05/GHSA-6jgq-cppp-pvm8/GHSA-6jgq-cppp-pvm8.json @@ -7,12 +7,8 @@ "CVE-2008-7159" ], "details": "The silc_asn1_encoder function in lib/silcasn1/silcasn1_encode.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.8 allows remote attackers to overwrite a stack location and possibly execute arbitrary code via a crafted OID value, related to incorrect use of a %lu format string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6q5h-57mm-c99g/GHSA-6q5h-57mm-c99g.json b/advisories/unreviewed/2022/05/GHSA-6q5h-57mm-c99g/GHSA-6q5h-57mm-c99g.json index b57a632400c..11f40da9126 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q5h-57mm-c99g/GHSA-6q5h-57mm-c99g.json +++ b/advisories/unreviewed/2022/05/GHSA-6q5h-57mm-c99g/GHSA-6q5h-57mm-c99g.json @@ -7,12 +7,8 @@ "CVE-2010-3982" ], "details": "SAP BusinessObjects Enterprise XI 3.2 allows remote attackers to trigger TCP connections to arbitrary intranet hosts on any port, and obtain potentially sensitive information about open ports, via the apstoken parameter to the CrystalReports/viewrpt.cwr URI, related to an \"internal port scanning\" issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6r7f-rwvw-h287/GHSA-6r7f-rwvw-h287.json b/advisories/unreviewed/2022/05/GHSA-6r7f-rwvw-h287/GHSA-6r7f-rwvw-h287.json index 34852d0d16e..4817457dc4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6r7f-rwvw-h287/GHSA-6r7f-rwvw-h287.json +++ b/advisories/unreviewed/2022/05/GHSA-6r7f-rwvw-h287/GHSA-6r7f-rwvw-h287.json @@ -7,12 +7,8 @@ "CVE-2010-1978" ], "details": "PHP remote file inclusion vulnerability in default_theme.php in FreePHPBlogSoftware 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the phpincdir parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6rp6-x94v-92vx/GHSA-6rp6-x94v-92vx.json b/advisories/unreviewed/2022/05/GHSA-6rp6-x94v-92vx/GHSA-6rp6-x94v-92vx.json index e5fe37b72b5..e39dedea407 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rp6-x94v-92vx/GHSA-6rp6-x94v-92vx.json +++ b/advisories/unreviewed/2022/05/GHSA-6rp6-x94v-92vx/GHSA-6rp6-x94v-92vx.json @@ -7,12 +7,8 @@ "CVE-2008-7101" ], "details": "Unspecified vulnerability in DotNetNuke 4.0 through 4.8.4 and 5.0 allows remote attackers to obtain sensitive information (portal number) by accessing the install wizard page via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6rpw-6v52-q2ff/GHSA-6rpw-6v52-q2ff.json b/advisories/unreviewed/2022/05/GHSA-6rpw-6v52-q2ff/GHSA-6rpw-6v52-q2ff.json index 914f9dbdf71..8c45dbce0e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rpw-6v52-q2ff/GHSA-6rpw-6v52-q2ff.json +++ b/advisories/unreviewed/2022/05/GHSA-6rpw-6v52-q2ff/GHSA-6rpw-6v52-q2ff.json @@ -7,12 +7,8 @@ "CVE-2010-2609" ], "details": "SQL injection vulnerability in show_search_result.php in 2daybiz Job Search Engine Script allows remote attackers to execute arbitrary SQL commands via the keyword parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6rr4-jv72-pv85/GHSA-6rr4-jv72-pv85.json b/advisories/unreviewed/2022/05/GHSA-6rr4-jv72-pv85/GHSA-6rr4-jv72-pv85.json index 0ff0a6cd954..5eef9a208cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rr4-jv72-pv85/GHSA-6rr4-jv72-pv85.json +++ b/advisories/unreviewed/2022/05/GHSA-6rr4-jv72-pv85/GHSA-6rr4-jv72-pv85.json @@ -7,12 +7,8 @@ "CVE-2010-2355" ], "details": "Cross-site scripting (XSS) vulnerability in error.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML via the message parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6v9h-97q3-6h22/GHSA-6v9h-97q3-6h22.json b/advisories/unreviewed/2022/05/GHSA-6v9h-97q3-6h22/GHSA-6v9h-97q3-6h22.json index 2b99a49f175..3accb65ab77 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v9h-97q3-6h22/GHSA-6v9h-97q3-6h22.json +++ b/advisories/unreviewed/2022/05/GHSA-6v9h-97q3-6h22/GHSA-6v9h-97q3-6h22.json @@ -7,12 +7,8 @@ "CVE-2010-4498" ], "details": "Unspecified vulnerability in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers to modify data or obtain sensitive information via a crafted URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6vmf-4ghh-8g4r/GHSA-6vmf-4ghh-8g4r.json b/advisories/unreviewed/2022/05/GHSA-6vmf-4ghh-8g4r/GHSA-6vmf-4ghh-8g4r.json index 775d5afebb5..66bd859f4ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vmf-4ghh-8g4r/GHSA-6vmf-4ghh-8g4r.json +++ b/advisories/unreviewed/2022/05/GHSA-6vmf-4ghh-8g4r/GHSA-6vmf-4ghh-8g4r.json @@ -7,12 +7,8 @@ "CVE-2010-2633" ], "details": "Unspecified vulnerability in EMC Disk Library (EDL) before 3.2.7, 3.3.x before 3.3.2 epatch 8, and 4.0.x before 4.0.1 epatch 4 allows remote attackers to cause a denial of service (communication-module crash) by sending a crafted message through TCP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6w68-xh9m-j92v/GHSA-6w68-xh9m-j92v.json b/advisories/unreviewed/2022/05/GHSA-6w68-xh9m-j92v/GHSA-6w68-xh9m-j92v.json index 81ffc243d24..b23514851cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w68-xh9m-j92v/GHSA-6w68-xh9m-j92v.json +++ b/advisories/unreviewed/2022/05/GHSA-6w68-xh9m-j92v/GHSA-6w68-xh9m-j92v.json @@ -7,12 +7,8 @@ "CVE-2010-2310" ], "details": "SolarWinds TFTP Server 10.4.0.13 allows remote attackers to cause a denial of service (crash) via a long write request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6x64-rm6c-4p72/GHSA-6x64-rm6c-4p72.json b/advisories/unreviewed/2022/05/GHSA-6x64-rm6c-4p72/GHSA-6x64-rm6c-4p72.json index b3edea0360a..7f53ef16314 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x64-rm6c-4p72/GHSA-6x64-rm6c-4p72.json +++ b/advisories/unreviewed/2022/05/GHSA-6x64-rm6c-4p72/GHSA-6x64-rm6c-4p72.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -71,9 +69,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6x9c-w5j8-8h3x/GHSA-6x9c-w5j8-8h3x.json b/advisories/unreviewed/2022/05/GHSA-6x9c-w5j8-8h3x/GHSA-6x9c-w5j8-8h3x.json index 90c2beba59c..89e6d202645 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x9c-w5j8-8h3x/GHSA-6x9c-w5j8-8h3x.json +++ b/advisories/unreviewed/2022/05/GHSA-6x9c-w5j8-8h3x/GHSA-6x9c-w5j8-8h3x.json @@ -7,12 +7,8 @@ "CVE-2010-3204" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Pecio CMS 2.0.5 allow remote attackers to execute arbitrary PHP code via a URL in the template parameter to (1) post.php, (2) article.php, (3) blog.php, or (4) home.php in pec_templates/nova-blue/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xh6-hvhw-h658/GHSA-6xh6-hvhw-h658.json b/advisories/unreviewed/2022/05/GHSA-6xh6-hvhw-h658/GHSA-6xh6-hvhw-h658.json index f2b378c1411..f150ccd7f64 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xh6-hvhw-h658/GHSA-6xh6-hvhw-h658.json +++ b/advisories/unreviewed/2022/05/GHSA-6xh6-hvhw-h658/GHSA-6xh6-hvhw-h658.json @@ -7,12 +7,8 @@ "CVE-2010-2225" ], "details": "Use-after-free vulnerability in the SplObjectStorage unserializer in PHP 5.2.x and 5.3.x through 5.3.2 allows remote attackers to execute arbitrary code or obtain sensitive information via serialized data, related to the PHP unserialize function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7273-4xcg-4p5f/GHSA-7273-4xcg-4p5f.json b/advisories/unreviewed/2022/05/GHSA-7273-4xcg-4p5f/GHSA-7273-4xcg-4p5f.json index 8cf6e8816b4..f0dc111fd02 100644 --- a/advisories/unreviewed/2022/05/GHSA-7273-4xcg-4p5f/GHSA-7273-4xcg-4p5f.json +++ b/advisories/unreviewed/2022/05/GHSA-7273-4xcg-4p5f/GHSA-7273-4xcg-4p5f.json @@ -7,12 +7,8 @@ "CVE-2010-2701" ], "details": "Multiple buffer overflows in the FathFTP ActiveX control 1.7 allow remote attackers to execute arbitrary code via (1) the GetFromURL member or (2) a long argument to the RasIsConnected method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-729q-jrf3-mhg8/GHSA-729q-jrf3-mhg8.json b/advisories/unreviewed/2022/05/GHSA-729q-jrf3-mhg8/GHSA-729q-jrf3-mhg8.json index b815bf7fb20..14a6c42f86e 100644 --- a/advisories/unreviewed/2022/05/GHSA-729q-jrf3-mhg8/GHSA-729q-jrf3-mhg8.json +++ b/advisories/unreviewed/2022/05/GHSA-729q-jrf3-mhg8/GHSA-729q-jrf3-mhg8.json @@ -7,12 +7,8 @@ "CVE-2010-4326" ], "details": "Multiple buffer overflows in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via variables in a VCALENDAR message, as demonstrated by a long (1) REQUEST-STATUS, (2) TZNAME, (3) COMMENT, or (4) RRULE variable in this message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-748g-m8cr-v48g/GHSA-748g-m8cr-v48g.json b/advisories/unreviewed/2022/05/GHSA-748g-m8cr-v48g/GHSA-748g-m8cr-v48g.json index 0442cd9d40e..407947fe89e 100644 --- a/advisories/unreviewed/2022/05/GHSA-748g-m8cr-v48g/GHSA-748g-m8cr-v48g.json +++ b/advisories/unreviewed/2022/05/GHSA-748g-m8cr-v48g/GHSA-748g-m8cr-v48g.json @@ -7,12 +7,8 @@ "CVE-2010-2387" ], "details": "vicious-extensions/ve-misc.c in GNOME Display Manager (gdm) 2.20.x before 2.20.11, when GDM debug is enabled, logs the user password when it contains invalid UTF8 encoded characters, which might allow local users to gain privileges by reading the information from syslog logs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-75pm-pvvg-r2qr/GHSA-75pm-pvvg-r2qr.json b/advisories/unreviewed/2022/05/GHSA-75pm-pvvg-r2qr/GHSA-75pm-pvvg-r2qr.json index 7e50aeee573..10d4de4eca2 100644 --- a/advisories/unreviewed/2022/05/GHSA-75pm-pvvg-r2qr/GHSA-75pm-pvvg-r2qr.json +++ b/advisories/unreviewed/2022/05/GHSA-75pm-pvvg-r2qr/GHSA-75pm-pvvg-r2qr.json @@ -7,12 +7,8 @@ "CVE-2010-3594" ], "details": "Unspecified vulnerability in the Real User Experience Insight component in Oracle Enterprise Manager Grid Control 6.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Processing. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that this is SQL injection in rsynclogdird involving improper escaping of UTF-8 characters while processing log files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7742-43c4-2h75/GHSA-7742-43c4-2h75.json b/advisories/unreviewed/2022/05/GHSA-7742-43c4-2h75/GHSA-7742-43c4-2h75.json index e5681f7064b..c2f0dbc0000 100644 --- a/advisories/unreviewed/2022/05/GHSA-7742-43c4-2h75/GHSA-7742-43c4-2h75.json +++ b/advisories/unreviewed/2022/05/GHSA-7742-43c4-2h75/GHSA-7742-43c4-2h75.json @@ -7,12 +7,8 @@ "CVE-2010-2910" ], "details": "SQL injection vulnerability in the Ozio Gallery (com_oziogallery) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-78rr-56jm-2q7g/GHSA-78rr-56jm-2q7g.json b/advisories/unreviewed/2022/05/GHSA-78rr-56jm-2q7g/GHSA-78rr-56jm-2q7g.json index f3f904fb2e6..2c0b4039b7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-78rr-56jm-2q7g/GHSA-78rr-56jm-2q7g.json +++ b/advisories/unreviewed/2022/05/GHSA-78rr-56jm-2q7g/GHSA-78rr-56jm-2q7g.json @@ -7,12 +7,8 @@ "CVE-2010-4636" ], "details": "SQL injection vulnerability in detail.asp in Site2Nite Business e-Listings allows remote attackers to execute arbitrary SQL commands via the ID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-79pf-r6gg-vhxx/GHSA-79pf-r6gg-vhxx.json b/advisories/unreviewed/2022/05/GHSA-79pf-r6gg-vhxx/GHSA-79pf-r6gg-vhxx.json index 4c9ba41cd5a..df4bac28f74 100644 --- a/advisories/unreviewed/2022/05/GHSA-79pf-r6gg-vhxx/GHSA-79pf-r6gg-vhxx.json +++ b/advisories/unreviewed/2022/05/GHSA-79pf-r6gg-vhxx/GHSA-79pf-r6gg-vhxx.json @@ -7,12 +7,8 @@ "CVE-2010-2330" ], "details": "Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Content-Length header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7cgc-jmfj-p9wc/GHSA-7cgc-jmfj-p9wc.json b/advisories/unreviewed/2022/05/GHSA-7cgc-jmfj-p9wc/GHSA-7cgc-jmfj-p9wc.json index d6dee0ebee8..eecd4d407f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-7cgc-jmfj-p9wc/GHSA-7cgc-jmfj-p9wc.json +++ b/advisories/unreviewed/2022/05/GHSA-7cgc-jmfj-p9wc/GHSA-7cgc-jmfj-p9wc.json @@ -7,12 +7,8 @@ "CVE-2010-2341" ], "details": "PHP remote file inclusion vulnerability in system/application/views/public/commentform.php in EZPX Photoblog 1.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the tpl_base_dir parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7f48-gjxv-cppw/GHSA-7f48-gjxv-cppw.json b/advisories/unreviewed/2022/05/GHSA-7f48-gjxv-cppw/GHSA-7f48-gjxv-cppw.json index 5ba8139fc2e..c230df65126 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f48-gjxv-cppw/GHSA-7f48-gjxv-cppw.json +++ b/advisories/unreviewed/2022/05/GHSA-7f48-gjxv-cppw/GHSA-7f48-gjxv-cppw.json @@ -7,12 +7,8 @@ "CVE-2010-2128" ], "details": "Directory traversal vulnerability in the JE Quotation Form (com_jequoteform) component 1.0b1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the view parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7fh4-f65w-5p7x/GHSA-7fh4-f65w-5p7x.json b/advisories/unreviewed/2022/05/GHSA-7fh4-f65w-5p7x/GHSA-7fh4-f65w-5p7x.json index 6881c392ee5..cb2c80e49b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fh4-f65w-5p7x/GHSA-7fh4-f65w-5p7x.json +++ b/advisories/unreviewed/2022/05/GHSA-7fh4-f65w-5p7x/GHSA-7fh4-f65w-5p7x.json @@ -7,12 +7,8 @@ "CVE-2010-2343" ], "details": "Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbitrary code via a crafted pls playlist file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7gwq-jm8c-29xc/GHSA-7gwq-jm8c-29xc.json b/advisories/unreviewed/2022/05/GHSA-7gwq-jm8c-29xc/GHSA-7gwq-jm8c-29xc.json index 70893f94ac4..6d604eb900b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gwq-jm8c-29xc/GHSA-7gwq-jm8c-29xc.json +++ b/advisories/unreviewed/2022/05/GHSA-7gwq-jm8c-29xc/GHSA-7gwq-jm8c-29xc.json @@ -7,12 +7,8 @@ "CVE-2010-2613" ], "details": "Cross-site scripting (XSS) vulnerability in the JExtensions JE Awd Song (com_awd_song) component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the song review field, which is not properly handled in a view action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7j49-g4cp-8h6j/GHSA-7j49-g4cp-8h6j.json b/advisories/unreviewed/2022/05/GHSA-7j49-g4cp-8h6j/GHSA-7j49-g4cp-8h6j.json index 93a7d0f5991..5bb907a5821 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j49-g4cp-8h6j/GHSA-7j49-g4cp-8h6j.json +++ b/advisories/unreviewed/2022/05/GHSA-7j49-g4cp-8h6j/GHSA-7j49-g4cp-8h6j.json @@ -7,12 +7,8 @@ "CVE-2010-1490" ], "details": "Unspecified vulnerability in IBM Cognos 8 Business Intelligence before 8.4.1 FP1 has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7jqj-9w6c-j4v9/GHSA-7jqj-9w6c-j4v9.json b/advisories/unreviewed/2022/05/GHSA-7jqj-9w6c-j4v9/GHSA-7jqj-9w6c-j4v9.json index 41da2f8bd89..31f4d8c0e70 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jqj-9w6c-j4v9/GHSA-7jqj-9w6c-j4v9.json +++ b/advisories/unreviewed/2022/05/GHSA-7jqj-9w6c-j4v9/GHSA-7jqj-9w6c-j4v9.json @@ -7,12 +7,8 @@ "CVE-2008-7132" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Nuked-Klan 1.3 beta allows remote attackers to inject arbitrary web script or HTML via the nuked_nude parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7m4g-qfmm-hx4m/GHSA-7m4g-qfmm-hx4m.json b/advisories/unreviewed/2022/05/GHSA-7m4g-qfmm-hx4m/GHSA-7m4g-qfmm-hx4m.json index 96c532ccfbd..1881b8463a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-7m4g-qfmm-hx4m/GHSA-7m4g-qfmm-hx4m.json +++ b/advisories/unreviewed/2022/05/GHSA-7m4g-qfmm-hx4m/GHSA-7m4g-qfmm-hx4m.json @@ -7,12 +7,8 @@ "CVE-2010-4099" ], "details": "ess.pm in NitroSecurity NitroView ESM 8.4.0a, when ESSPMDebug is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the Request parameter to ess.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7m99-hppq-9pj6/GHSA-7m99-hppq-9pj6.json b/advisories/unreviewed/2022/05/GHSA-7m99-hppq-9pj6/GHSA-7m99-hppq-9pj6.json index cc2a316a586..fb44126c0a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-7m99-hppq-9pj6/GHSA-7m99-hppq-9pj6.json +++ b/advisories/unreviewed/2022/05/GHSA-7m99-hppq-9pj6/GHSA-7m99-hppq-9pj6.json @@ -7,12 +7,8 @@ "CVE-2010-2040" ], "details": "Cross-site scripting (XSS) vulnerability in search.php in V-EVA Shopzilla Affiliate Script PHP allows remote attackers to inject arbitrary web script or HTML via the s parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7pq7-q7xj-fgj3/GHSA-7pq7-q7xj-fgj3.json b/advisories/unreviewed/2022/05/GHSA-7pq7-q7xj-fgj3/GHSA-7pq7-q7xj-fgj3.json index 93df911113d..f2b8d76d124 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pq7-q7xj-fgj3/GHSA-7pq7-q7xj-fgj3.json +++ b/advisories/unreviewed/2022/05/GHSA-7pq7-q7xj-fgj3/GHSA-7pq7-q7xj-fgj3.json @@ -7,12 +7,8 @@ "CVE-2010-3423" ], "details": "SQL injection vulnerability in the Yr Weatherdata module for Drupal 6.x before 6.x-1.6 allows remote attackers to execute arbitrary SQL commands via the sorting method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7rvv-4q2j-9cv9/GHSA-7rvv-4q2j-9cv9.json b/advisories/unreviewed/2022/05/GHSA-7rvv-4q2j-9cv9/GHSA-7rvv-4q2j-9cv9.json index 1048e0f98d1..b7fb79d8fbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rvv-4q2j-9cv9/GHSA-7rvv-4q2j-9cv9.json +++ b/advisories/unreviewed/2022/05/GHSA-7rvv-4q2j-9cv9/GHSA-7rvv-4q2j-9cv9.json @@ -7,12 +7,8 @@ "CVE-2010-2358" ], "details": "PHP remote file inclusion vulnerability in modules/catalog/upload_photo.php in Nakid CMS 0.5.2, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the core[system_path] parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7v29-vf8p-2rvp/GHSA-7v29-vf8p-2rvp.json b/advisories/unreviewed/2022/05/GHSA-7v29-vf8p-2rvp/GHSA-7v29-vf8p-2rvp.json index 914fbeddf46..c912ac206c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7v29-vf8p-2rvp/GHSA-7v29-vf8p-2rvp.json +++ b/advisories/unreviewed/2022/05/GHSA-7v29-vf8p-2rvp/GHSA-7v29-vf8p-2rvp.json @@ -7,12 +7,8 @@ "CVE-2010-2199" ], "details": "lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade or deletion of the file in an RPM package removal, which might allow local users to bypass intended access restrictions by creating a hard link to a vulnerable file that has a POSIX ACL, a related issue to CVE-2010-2059.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7vgg-x2f9-c6c5/GHSA-7vgg-x2f9-c6c5.json b/advisories/unreviewed/2022/05/GHSA-7vgg-x2f9-c6c5/GHSA-7vgg-x2f9-c6c5.json index c9d106ad904..6dfb9417d0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vgg-x2f9-c6c5/GHSA-7vgg-x2f9-c6c5.json +++ b/advisories/unreviewed/2022/05/GHSA-7vgg-x2f9-c6c5/GHSA-7vgg-x2f9-c6c5.json @@ -7,12 +7,8 @@ "CVE-2010-1915" ], "details": "The preg_quote function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature, modification of ZVALs whose values are not updated in the associated local variables, and access of previously-freed memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7w2g-gjg9-qhmc/GHSA-7w2g-gjg9-qhmc.json b/advisories/unreviewed/2022/05/GHSA-7w2g-gjg9-qhmc/GHSA-7w2g-gjg9-qhmc.json index a516e19a00c..07c52bd490a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7w2g-gjg9-qhmc/GHSA-7w2g-gjg9-qhmc.json +++ b/advisories/unreviewed/2022/05/GHSA-7w2g-gjg9-qhmc/GHSA-7w2g-gjg9-qhmc.json @@ -7,12 +7,8 @@ "CVE-2010-2917" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ Square AJ Article 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) emailid, (2) fname, (3) lname, (4) company, (5) address1, (6) address2, (7) city, (8) state, (9) zipcode, (10) phone, and (11) fax parameters in an update action. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wcv-wc37-6cpx/GHSA-7wcv-wc37-6cpx.json b/advisories/unreviewed/2022/05/GHSA-7wcv-wc37-6cpx/GHSA-7wcv-wc37-6cpx.json index 082b2a215ad..3f706368abf 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wcv-wc37-6cpx/GHSA-7wcv-wc37-6cpx.json +++ b/advisories/unreviewed/2022/05/GHSA-7wcv-wc37-6cpx/GHSA-7wcv-wc37-6cpx.json @@ -7,12 +7,8 @@ "CVE-2010-2924" ], "details": "SQL injection vulnerability in myLDlinker.php in the myLinksDump Plugin 1.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the url parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wg6-9cv7-mw4w/GHSA-7wg6-9cv7-mw4w.json b/advisories/unreviewed/2022/05/GHSA-7wg6-9cv7-mw4w/GHSA-7wg6-9cv7-mw4w.json index 214de760119..a9148b0e00d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wg6-9cv7-mw4w/GHSA-7wg6-9cv7-mw4w.json +++ b/advisories/unreviewed/2022/05/GHSA-7wg6-9cv7-mw4w/GHSA-7wg6-9cv7-mw4w.json @@ -7,12 +7,8 @@ "CVE-2010-3871" ], "details": "Cross-site scripting (XSS) vulnerability in blocktype/groupviews/theme/raw/groupviews.tpl in Mahara before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wj4-6jr7-34qw/GHSA-7wj4-6jr7-34qw.json b/advisories/unreviewed/2022/05/GHSA-7wj4-6jr7-34qw/GHSA-7wj4-6jr7-34qw.json index ce2310b2d39..305688867bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wj4-6jr7-34qw/GHSA-7wj4-6jr7-34qw.json +++ b/advisories/unreviewed/2022/05/GHSA-7wj4-6jr7-34qw/GHSA-7wj4-6jr7-34qw.json @@ -7,12 +7,8 @@ "CVE-2010-2618" ], "details": "PHP remote file inclusion vulnerability in inc/smarty/libs/init.php in AdaptCMS 2.0.0 Beta, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the sitepath parameter. NOTE: it was later reported that 2.0.1 is also affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wqq-c2xh-9759/GHSA-7wqq-c2xh-9759.json b/advisories/unreviewed/2022/05/GHSA-7wqq-c2xh-9759/GHSA-7wqq-c2xh-9759.json index 2de5b4cc581..a89e2eaa533 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wqq-c2xh-9759/GHSA-7wqq-c2xh-9759.json +++ b/advisories/unreviewed/2022/05/GHSA-7wqq-c2xh-9759/GHSA-7wqq-c2xh-9759.json @@ -7,12 +7,8 @@ "CVE-2010-3832" ], "details": "Heap-based buffer overflow in the GSM mobility management implementation in Telephony in Apple iOS before 4.2 on the iPhone and iPad allows remote attackers to execute arbitrary code on the baseband processor via a crafted Temporary Mobile Subscriber Identity (TMSI) field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7x7r-vg2m-69cm/GHSA-7x7r-vg2m-69cm.json b/advisories/unreviewed/2022/05/GHSA-7x7r-vg2m-69cm/GHSA-7x7r-vg2m-69cm.json index b46299a6f1c..fcc2150dca6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7x7r-vg2m-69cm/GHSA-7x7r-vg2m-69cm.json +++ b/advisories/unreviewed/2022/05/GHSA-7x7r-vg2m-69cm/GHSA-7x7r-vg2m-69cm.json @@ -7,12 +7,8 @@ "CVE-2010-1722" ], "details": "Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7xvv-8f53-f3jr/GHSA-7xvv-8f53-f3jr.json b/advisories/unreviewed/2022/05/GHSA-7xvv-8f53-f3jr/GHSA-7xvv-8f53-f3jr.json index d9a87a2966b..ca56dc3cd28 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xvv-8f53-f3jr/GHSA-7xvv-8f53-f3jr.json +++ b/advisories/unreviewed/2022/05/GHSA-7xvv-8f53-f3jr/GHSA-7xvv-8f53-f3jr.json @@ -7,12 +7,8 @@ "CVE-2010-2623" ], "details": "SQL injection vulnerability in pages.php in Internet DM Specialist Bed and Breakfast allows remote attackers to execute arbitrary SQL commands via the pp_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8385-4jvx-fwmx/GHSA-8385-4jvx-fwmx.json b/advisories/unreviewed/2022/05/GHSA-8385-4jvx-fwmx/GHSA-8385-4jvx-fwmx.json index 486eba61cfa..a1ce541b09c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8385-4jvx-fwmx/GHSA-8385-4jvx-fwmx.json +++ b/advisories/unreviewed/2022/05/GHSA-8385-4jvx-fwmx/GHSA-8385-4jvx-fwmx.json @@ -7,12 +7,8 @@ "CVE-2010-3419" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the current_user_id parameter to (1) familynews.php and (2) settings.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-83r4-5rh2-7679/GHSA-83r4-5rh2-7679.json b/advisories/unreviewed/2022/05/GHSA-83r4-5rh2-7679/GHSA-83r4-5rh2-7679.json index 3740ddf672e..feb0a42e430 100644 --- a/advisories/unreviewed/2022/05/GHSA-83r4-5rh2-7679/GHSA-83r4-5rh2-7679.json +++ b/advisories/unreviewed/2022/05/GHSA-83r4-5rh2-7679/GHSA-83r4-5rh2-7679.json @@ -7,12 +7,8 @@ "CVE-2010-2028" ], "details": "Buffer overflow in k23productions TFTPUtil GUI (aka TFTPGUI) 1.4.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long transport mode.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-85v4-r279-j4ww/GHSA-85v4-r279-j4ww.json b/advisories/unreviewed/2022/05/GHSA-85v4-r279-j4ww/GHSA-85v4-r279-j4ww.json index e5f86fac0e3..ef27df0fe4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-85v4-r279-j4ww/GHSA-85v4-r279-j4ww.json +++ b/advisories/unreviewed/2022/05/GHSA-85v4-r279-j4ww/GHSA-85v4-r279-j4ww.json @@ -7,12 +7,8 @@ "CVE-2010-2135" ], "details": "Multiple SQL injection vulnerabilities in login.php in HazelPress Lite 0.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) password fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8668-w4w3-r36q/GHSA-8668-w4w3-r36q.json b/advisories/unreviewed/2022/05/GHSA-8668-w4w3-r36q/GHSA-8668-w4w3-r36q.json index 30d401e0dce..d673984a34b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8668-w4w3-r36q/GHSA-8668-w4w3-r36q.json +++ b/advisories/unreviewed/2022/05/GHSA-8668-w4w3-r36q/GHSA-8668-w4w3-r36q.json @@ -7,12 +7,8 @@ "CVE-2010-1924" ], "details": "SQL injection vulnerability in index.php in Hi Web Wiesbaden Live Shopping Multi Portal System allows remote attackers to execute arbitrary SQL commands via the artikel parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-86c8-5m9f-52c3/GHSA-86c8-5m9f-52c3.json b/advisories/unreviewed/2022/05/GHSA-86c8-5m9f-52c3/GHSA-86c8-5m9f-52c3.json index ce6a91268c0..aa770e5cf33 100644 --- a/advisories/unreviewed/2022/05/GHSA-86c8-5m9f-52c3/GHSA-86c8-5m9f-52c3.json +++ b/advisories/unreviewed/2022/05/GHSA-86c8-5m9f-52c3/GHSA-86c8-5m9f-52c3.json @@ -7,12 +7,8 @@ "CVE-2010-3460" ], "details": "Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers to read arbitrary files via a %5C (encoded backslash) in the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-873w-8wmr-67j9/GHSA-873w-8wmr-67j9.json b/advisories/unreviewed/2022/05/GHSA-873w-8wmr-67j9/GHSA-873w-8wmr-67j9.json index 5f15108f5e2..2a486a4d07f 100644 --- a/advisories/unreviewed/2022/05/GHSA-873w-8wmr-67j9/GHSA-873w-8wmr-67j9.json +++ b/advisories/unreviewed/2022/05/GHSA-873w-8wmr-67j9/GHSA-873w-8wmr-67j9.json @@ -7,12 +7,8 @@ "CVE-2010-4423" ], "details": "Unspecified vulnerability in the Cluster Verify Utility component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1, when running on Windows, allows local users to affect confidentiality, integrity, and availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8765-h9hh-rh5j/GHSA-8765-h9hh-rh5j.json b/advisories/unreviewed/2022/05/GHSA-8765-h9hh-rh5j/GHSA-8765-h9hh-rh5j.json index 0d43b3bb5b7..bdf18a287b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-8765-h9hh-rh5j/GHSA-8765-h9hh-rh5j.json +++ b/advisories/unreviewed/2022/05/GHSA-8765-h9hh-rh5j/GHSA-8765-h9hh-rh5j.json @@ -7,12 +7,8 @@ "CVE-2010-1810" ], "details": "FaceTime in Apple iOS before 4.1 on the iPhone and iPod touch does not properly handle invalid X.509 certificates, which allows man-in-the-middle attackers to redirect calls via a crafted certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8g2r-5pm7-653f/GHSA-8g2r-5pm7-653f.json b/advisories/unreviewed/2022/05/GHSA-8g2r-5pm7-653f/GHSA-8g2r-5pm7-653f.json index 43c0aa9aee9..25bb23cb436 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g2r-5pm7-653f/GHSA-8g2r-5pm7-653f.json +++ b/advisories/unreviewed/2022/05/GHSA-8g2r-5pm7-653f/GHSA-8g2r-5pm7-653f.json @@ -7,12 +7,8 @@ "CVE-2010-4393" ], "details": "Heap-based buffer overflow in vidplin.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.x before 14.0.2, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted header in an AVI file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8h49-6g8c-82vj/GHSA-8h49-6g8c-82vj.json b/advisories/unreviewed/2022/05/GHSA-8h49-6g8c-82vj/GHSA-8h49-6g8c-82vj.json index 8efb20e788e..a7a4e8c2b38 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h49-6g8c-82vj/GHSA-8h49-6g8c-82vj.json +++ b/advisories/unreviewed/2022/05/GHSA-8h49-6g8c-82vj/GHSA-8h49-6g8c-82vj.json @@ -7,12 +7,8 @@ "CVE-2010-4626" ], "details": "The my_rand function in functions.php in MyBB (aka MyBulletinBoard) before 1.4.12 does not properly use the PHP mt_rand function, which makes it easier for remote attackers to obtain access to an arbitrary account by requesting a reset of the account's password, and then conducting a brute-force attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8h8c-6943-5984/GHSA-8h8c-6943-5984.json b/advisories/unreviewed/2022/05/GHSA-8h8c-6943-5984/GHSA-8h8c-6943-5984.json index be98600c764..73753e115a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h8c-6943-5984/GHSA-8h8c-6943-5984.json +++ b/advisories/unreviewed/2022/05/GHSA-8h8c-6943-5984/GHSA-8h8c-6943-5984.json @@ -7,12 +7,8 @@ "CVE-2010-4031" ], "details": "Unspecified vulnerability in HP Insight Control Performance Management before 6.2 allows remote authenticated users to gain privileges via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8jx6-3v53-6qmh/GHSA-8jx6-3v53-6qmh.json b/advisories/unreviewed/2022/05/GHSA-8jx6-3v53-6qmh/GHSA-8jx6-3v53-6qmh.json index 1b66401086c..5edb8a74761 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jx6-3v53-6qmh/GHSA-8jx6-3v53-6qmh.json +++ b/advisories/unreviewed/2022/05/GHSA-8jx6-3v53-6qmh/GHSA-8jx6-3v53-6qmh.json @@ -7,12 +7,8 @@ "CVE-2010-2311" ], "details": "Stack-based buffer overflow in Power Tab Editor 1.7 build 80 allows user-assisted remote attackers to execute arbitrary code via a .ptb file with a long font name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8p5g-5vh8-4rwm/GHSA-8p5g-5vh8-4rwm.json b/advisories/unreviewed/2022/05/GHSA-8p5g-5vh8-4rwm/GHSA-8p5g-5vh8-4rwm.json index 5956511581f..438fb6156ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p5g-5vh8-4rwm/GHSA-8p5g-5vh8-4rwm.json +++ b/advisories/unreviewed/2022/05/GHSA-8p5g-5vh8-4rwm/GHSA-8p5g-5vh8-4rwm.json @@ -7,12 +7,8 @@ "CVE-2010-4268" ], "details": "SQL injection vulnerability in the Pulse Infotech Flip Wall (com_flipwall) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8q39-6pgq-m9mv/GHSA-8q39-6pgq-m9mv.json b/advisories/unreviewed/2022/05/GHSA-8q39-6pgq-m9mv/GHSA-8q39-6pgq-m9mv.json index a989f104829..9d14d1faae3 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q39-6pgq-m9mv/GHSA-8q39-6pgq-m9mv.json +++ b/advisories/unreviewed/2022/05/GHSA-8q39-6pgq-m9mv/GHSA-8q39-6pgq-m9mv.json @@ -7,12 +7,8 @@ "CVE-2010-2602" ], "details": "Multiple buffer overflows in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Enterprise Server 5.0.0 through 5.0.2, 4.1.6, and 4.1.7 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8vfp-xjc3-jjvc/GHSA-8vfp-xjc3-jjvc.json b/advisories/unreviewed/2022/05/GHSA-8vfp-xjc3-jjvc/GHSA-8vfp-xjc3-jjvc.json index 2b47dd18522..f424884dd4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vfp-xjc3-jjvc/GHSA-8vfp-xjc3-jjvc.json +++ b/advisories/unreviewed/2022/05/GHSA-8vfp-xjc3-jjvc/GHSA-8vfp-xjc3-jjvc.json @@ -7,12 +7,8 @@ "CVE-2010-2796" ], "details": "Cross-site scripting (XSS) vulnerability in phpCAS before 1.1.2, when proxy mode is enabled, allows remote attackers to inject arbitrary web script or HTML via a callback URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8vqc-r2hm-5662/GHSA-8vqc-r2hm-5662.json b/advisories/unreviewed/2022/05/GHSA-8vqc-r2hm-5662/GHSA-8vqc-r2hm-5662.json index b6e23ef5846..c7027655eb8 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vqc-r2hm-5662/GHSA-8vqc-r2hm-5662.json +++ b/advisories/unreviewed/2022/05/GHSA-8vqc-r2hm-5662/GHSA-8vqc-r2hm-5662.json @@ -7,12 +7,8 @@ "CVE-2010-1944" ], "details": "Multiple PHP remote file inclusion vulnerabilities in openMairie openCimetiere 2.01, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) autorisation.class.php, (2) courrierautorisation.class.php, (3) droit.class.php, (4) profil.class.php, (5) temp_defunt_sansemplacement.class.php, (6) utils.class.php, (7) cimetiere.class.php, (8) defunt.class.php, (9) emplacement.class.php, (10) tab_emplacement.class.php, (11) temp_emplacement.class.php, (12) voie.class.php, (13) collectivite.class.php, (14) defunttransfert.class.php, (15) entreprise.class.php, (16) temp_autorisation.class.php, (17) travaux.class.php, (18) zone.class.php, (19) courrier.class.php, (20) dossier.class.php, (21) plans.class.php, (22) temp_defunt.class.php, and (23) utilisateur.class.php in obj/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8vqf-2mgv-72m8/GHSA-8vqf-2mgv-72m8.json b/advisories/unreviewed/2022/05/GHSA-8vqf-2mgv-72m8/GHSA-8vqf-2mgv-72m8.json index 036b21e8dff..1d599406d86 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vqf-2mgv-72m8/GHSA-8vqf-2mgv-72m8.json +++ b/advisories/unreviewed/2022/05/GHSA-8vqf-2mgv-72m8/GHSA-8vqf-2mgv-72m8.json @@ -7,12 +7,8 @@ "CVE-2010-4624" ], "details": "MyBB (aka MyBulletinBoard) before 1.4.12 allows remote authenticated users to bypass intended restrictions on the number of [img] MyCodes by editing a post after it has been created.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8vvp-pmvm-x49v/GHSA-8vvp-pmvm-x49v.json b/advisories/unreviewed/2022/05/GHSA-8vvp-pmvm-x49v/GHSA-8vvp-pmvm-x49v.json index e7b1ee1a60e..7516f252b33 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vvp-pmvm-x49v/GHSA-8vvp-pmvm-x49v.json +++ b/advisories/unreviewed/2022/05/GHSA-8vvp-pmvm-x49v/GHSA-8vvp-pmvm-x49v.json @@ -7,12 +7,8 @@ "CVE-2010-3587" ], "details": "Unspecified vulnerability in the Oracle Common Applications component in Oracle Applications 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to User Management.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8wgh-rhq6-89pj/GHSA-8wgh-rhq6-89pj.json b/advisories/unreviewed/2022/05/GHSA-8wgh-rhq6-89pj/GHSA-8wgh-rhq6-89pj.json index ea1864a9637..7282aad6090 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wgh-rhq6-89pj/GHSA-8wgh-rhq6-89pj.json +++ b/advisories/unreviewed/2022/05/GHSA-8wgh-rhq6-89pj/GHSA-8wgh-rhq6-89pj.json @@ -7,12 +7,8 @@ "CVE-2010-2352" ], "details": "The Node Reference module in Content Construction Kit (CCK) module 5.x before 5.x-1.11 and 6.x before 6.x-2.7 for Drupal does not perform access checks before displaying referenced nodes, which allows remote attackers to read controlled nodes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xf2-9w2x-9w9x/GHSA-8xf2-9w2x-9w9x.json b/advisories/unreviewed/2022/05/GHSA-8xf2-9w2x-9w9x/GHSA-8xf2-9w2x-9w9x.json index 0f3c5d1d421..741902e9a61 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xf2-9w2x-9w9x/GHSA-8xf2-9w2x-9w9x.json +++ b/advisories/unreviewed/2022/05/GHSA-8xf2-9w2x-9w9x/GHSA-8xf2-9w2x-9w9x.json @@ -7,12 +7,8 @@ "CVE-2010-2005" ], "details": "Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the selected_language parameter to engine/inc/include/init.php, (2) the config[langs] parameter to engine/inc/help.php, (3) the config[lang] parameter to engine/ajax/pm.php, (4) and the _REQUEST[skin] parameter to engine/ajax/addcomments.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xq7-gqj3-mh42/GHSA-8xq7-gqj3-mh42.json b/advisories/unreviewed/2022/05/GHSA-8xq7-gqj3-mh42/GHSA-8xq7-gqj3-mh42.json index f78a40a4c19..a22f41ea589 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xq7-gqj3-mh42/GHSA-8xq7-gqj3-mh42.json +++ b/advisories/unreviewed/2022/05/GHSA-8xq7-gqj3-mh42/GHSA-8xq7-gqj3-mh42.json @@ -7,12 +7,8 @@ "CVE-2010-2626" ], "details": "index.pl in Miyabi CGI Tools SEO Links 1.02 allows remote attackers to execute arbitrary commands via shell metacharacters in the fn command. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-922g-35pj-pv6f/GHSA-922g-35pj-pv6f.json b/advisories/unreviewed/2022/05/GHSA-922g-35pj-pv6f/GHSA-922g-35pj-pv6f.json index 4513a7be459..cb314a87a43 100644 --- a/advisories/unreviewed/2022/05/GHSA-922g-35pj-pv6f/GHSA-922g-35pj-pv6f.json +++ b/advisories/unreviewed/2022/05/GHSA-922g-35pj-pv6f/GHSA-922g-35pj-pv6f.json @@ -7,12 +7,8 @@ "CVE-2010-3135" ], "details": "Untrusted search path vulnerability in Cisco Packet Tracer 5.2 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wintab32.dll that is located in the same folder as a .pkt or .pkz file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-92xw-jc8h-7jc6/GHSA-92xw-jc8h-7jc6.json b/advisories/unreviewed/2022/05/GHSA-92xw-jc8h-7jc6/GHSA-92xw-jc8h-7jc6.json index ba5a64a05ea..303ac58730b 100644 --- a/advisories/unreviewed/2022/05/GHSA-92xw-jc8h-7jc6/GHSA-92xw-jc8h-7jc6.json +++ b/advisories/unreviewed/2022/05/GHSA-92xw-jc8h-7jc6/GHSA-92xw-jc8h-7jc6.json @@ -7,12 +7,8 @@ "CVE-2010-4010" ], "details": "Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code via a crafted embedded Compact Font Format (CFF) font in a document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-93g6-7v2r-h2r4/GHSA-93g6-7v2r-h2r4.json b/advisories/unreviewed/2022/05/GHSA-93g6-7v2r-h2r4/GHSA-93g6-7v2r-h2r4.json index 5dd91a49834..8beeb6a7491 100644 --- a/advisories/unreviewed/2022/05/GHSA-93g6-7v2r-h2r4/GHSA-93g6-7v2r-h2r4.json +++ b/advisories/unreviewed/2022/05/GHSA-93g6-7v2r-h2r4/GHSA-93g6-7v2r-h2r4.json @@ -7,12 +7,8 @@ "CVE-2010-4572" ], "details": "CRLF injection vulnerability in chart.cgi in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the query string, a different vulnerability than CVE-2010-2761 and CVE-2010-4411.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9595-rj38-7f63/GHSA-9595-rj38-7f63.json b/advisories/unreviewed/2022/05/GHSA-9595-rj38-7f63/GHSA-9595-rj38-7f63.json index 9ec356260ee..89dcc6ff8e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-9595-rj38-7f63/GHSA-9595-rj38-7f63.json +++ b/advisories/unreviewed/2022/05/GHSA-9595-rj38-7f63/GHSA-9595-rj38-7f63.json @@ -7,12 +7,8 @@ "CVE-2010-3425" ], "details": "Cross-site scripting (XSS) vulnerability in UserControls/Popups/frmHelp.aspx in SmarterStats 5.3, 5.3.3819, and possibly other 5.3 versions, allows remote attackers to inject arbitrary web script or HTML via the url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-95qf-v6r5-2v3v/GHSA-95qf-v6r5-2v3v.json b/advisories/unreviewed/2022/05/GHSA-95qf-v6r5-2v3v/GHSA-95qf-v6r5-2v3v.json index 2d44a5bcd95..630b8088a00 100644 --- a/advisories/unreviewed/2022/05/GHSA-95qf-v6r5-2v3v/GHSA-95qf-v6r5-2v3v.json +++ b/advisories/unreviewed/2022/05/GHSA-95qf-v6r5-2v3v/GHSA-95qf-v6r5-2v3v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-963q-pv8m-wcgg/GHSA-963q-pv8m-wcgg.json b/advisories/unreviewed/2022/05/GHSA-963q-pv8m-wcgg/GHSA-963q-pv8m-wcgg.json index f61101fd6fa..330ee8cf393 100644 --- a/advisories/unreviewed/2022/05/GHSA-963q-pv8m-wcgg/GHSA-963q-pv8m-wcgg.json +++ b/advisories/unreviewed/2022/05/GHSA-963q-pv8m-wcgg/GHSA-963q-pv8m-wcgg.json @@ -7,12 +7,8 @@ "CVE-2010-2674" ], "details": "SQL injection vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in an articolo action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-98fv-x3p6-qjrq/GHSA-98fv-x3p6-qjrq.json b/advisories/unreviewed/2022/05/GHSA-98fv-x3p6-qjrq/GHSA-98fv-x3p6-qjrq.json index d1650797778..8122c62295c 100644 --- a/advisories/unreviewed/2022/05/GHSA-98fv-x3p6-qjrq/GHSA-98fv-x3p6-qjrq.json +++ b/advisories/unreviewed/2022/05/GHSA-98fv-x3p6-qjrq/GHSA-98fv-x3p6-qjrq.json @@ -7,12 +7,8 @@ "CVE-2010-3929" ], "details": "SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to AjaxSearch.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9929-5m98-qfvf/GHSA-9929-5m98-qfvf.json b/advisories/unreviewed/2022/05/GHSA-9929-5m98-qfvf/GHSA-9929-5m98-qfvf.json index cc212395235..b3b7d32e7cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-9929-5m98-qfvf/GHSA-9929-5m98-qfvf.json +++ b/advisories/unreviewed/2022/05/GHSA-9929-5m98-qfvf/GHSA-9929-5m98-qfvf.json @@ -7,12 +7,8 @@ "CVE-2010-2926" ], "details": "SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the category parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-99jw-r98g-wv3r/GHSA-99jw-r98g-wv3r.json b/advisories/unreviewed/2022/05/GHSA-99jw-r98g-wv3r/GHSA-99jw-r98g-wv3r.json index d1c6a14b5dc..7bda9cc8ee3 100644 --- a/advisories/unreviewed/2022/05/GHSA-99jw-r98g-wv3r/GHSA-99jw-r98g-wv3r.json +++ b/advisories/unreviewed/2022/05/GHSA-99jw-r98g-wv3r/GHSA-99jw-r98g-wv3r.json @@ -7,12 +7,8 @@ "CVE-2010-3476" ], "details": "Open Ticket Request System (OTRS) 2.3.x before 2.3.6 and 2.4.x before 2.4.8 does not properly handle the matching of Perl regular expressions against HTML e-mail messages, which allows remote attackers to cause a denial of service (CPU consumption) via a large message, a different vulnerability than CVE-2010-2080.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9c9p-hhrq-f5v5/GHSA-9c9p-hhrq-f5v5.json b/advisories/unreviewed/2022/05/GHSA-9c9p-hhrq-f5v5/GHSA-9c9p-hhrq-f5v5.json index 1045f90984b..214b2e77d20 100644 --- a/advisories/unreviewed/2022/05/GHSA-9c9p-hhrq-f5v5/GHSA-9c9p-hhrq-f5v5.json +++ b/advisories/unreviewed/2022/05/GHSA-9c9p-hhrq-f5v5/GHSA-9c9p-hhrq-f5v5.json @@ -7,12 +7,8 @@ "CVE-2010-4267" ], "details": "Stack-based buffer overflow in the hpmud_get_pml function in io/hpmud/pml.c in Hewlett-Packard Linux Imaging and Printing (HPLIP) 1.6.7, 3.9.8, 3.10.9, and probably other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SNMP response with a large length value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9h32-4549-r88j/GHSA-9h32-4549-r88j.json b/advisories/unreviewed/2022/05/GHSA-9h32-4549-r88j/GHSA-9h32-4549-r88j.json index fe2138f38f9..e03afa6d0a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-9h32-4549-r88j/GHSA-9h32-4549-r88j.json +++ b/advisories/unreviewed/2022/05/GHSA-9h32-4549-r88j/GHSA-9h32-4549-r88j.json @@ -7,12 +7,8 @@ "CVE-2010-3461" ], "details": "SQL injection vulnerability in the Publisher module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL commands via the artid parameter in a printarticle action to mod.php, a different vector than CVE-2007-3394.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9h97-c3c6-r77v/GHSA-9h97-c3c6-r77v.json b/advisories/unreviewed/2022/05/GHSA-9h97-c3c6-r77v/GHSA-9h97-c3c6-r77v.json index 0ccb6962f6e..34e213d031f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9h97-c3c6-r77v/GHSA-9h97-c3c6-r77v.json +++ b/advisories/unreviewed/2022/05/GHSA-9h97-c3c6-r77v/GHSA-9h97-c3c6-r77v.json @@ -7,12 +7,8 @@ "CVE-2010-2810" ], "details": "Heap-based buffer overflow in the convert_to_idna function in WWW/Library/Implementation/HTParse.c in Lynx 2.8.8dev.1 through 2.8.8dev.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed URL containing a % (percent) character in the domain name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9jcf-26mj-wqj2/GHSA-9jcf-26mj-wqj2.json b/advisories/unreviewed/2022/05/GHSA-9jcf-26mj-wqj2/GHSA-9jcf-26mj-wqj2.json index 4f063a5860e..be28018cf7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jcf-26mj-wqj2/GHSA-9jcf-26mj-wqj2.json +++ b/advisories/unreviewed/2022/05/GHSA-9jcf-26mj-wqj2/GHSA-9jcf-26mj-wqj2.json @@ -7,12 +7,8 @@ "CVE-2010-3602" ], "details": "Cross-site scripting (XSS) vulnerability in ProfileView.aspx in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to inject arbitrary web script or HTML via the User ID parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9jq8-pf78-365m/GHSA-9jq8-pf78-365m.json b/advisories/unreviewed/2022/05/GHSA-9jq8-pf78-365m/GHSA-9jq8-pf78-365m.json index c3d76ee2d8c..f1ae8c02a48 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jq8-pf78-365m/GHSA-9jq8-pf78-365m.json +++ b/advisories/unreviewed/2022/05/GHSA-9jq8-pf78-365m/GHSA-9jq8-pf78-365m.json @@ -7,12 +7,8 @@ "CVE-2010-2125" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Rotor Banner module 5.x before 5.x-1.8 and 6.x before 6.x-2.5 for Drupal allow remote authenticated users, with \"create rotor item\" or \"edit any rotor item\" privileges, to inject arbitrary web script or HTML via the (1) srs, (2) title, or (3) alt image attribute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9mqf-8hq3-g769/GHSA-9mqf-8hq3-g769.json b/advisories/unreviewed/2022/05/GHSA-9mqf-8hq3-g769/GHSA-9mqf-8hq3-g769.json index be1bb84121f..15a0c737421 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mqf-8hq3-g769/GHSA-9mqf-8hq3-g769.json +++ b/advisories/unreviewed/2022/05/GHSA-9mqf-8hq3-g769/GHSA-9mqf-8hq3-g769.json @@ -7,12 +7,8 @@ "CVE-2010-3598" ], "details": "Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect integrity via unknown vectors related to Import Export Utility.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9p22-mxrj-58pq/GHSA-9p22-mxrj-58pq.json b/advisories/unreviewed/2022/05/GHSA-9p22-mxrj-58pq/GHSA-9p22-mxrj-58pq.json index 9c9fc07267d..e51b0f7dd07 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p22-mxrj-58pq/GHSA-9p22-mxrj-58pq.json +++ b/advisories/unreviewed/2022/05/GHSA-9p22-mxrj-58pq/GHSA-9p22-mxrj-58pq.json @@ -7,12 +7,8 @@ "CVE-2010-2461" ], "details": "SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL commands via the store parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9pjx-6wmc-cjx8/GHSA-9pjx-6wmc-cjx8.json b/advisories/unreviewed/2022/05/GHSA-9pjx-6wmc-cjx8/GHSA-9pjx-6wmc-cjx8.json index faf2e08e5f0..c4fa52a5780 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pjx-6wmc-cjx8/GHSA-9pjx-6wmc-cjx8.json +++ b/advisories/unreviewed/2022/05/GHSA-9pjx-6wmc-cjx8/GHSA-9pjx-6wmc-cjx8.json @@ -7,12 +7,8 @@ "CVE-2010-2721" ], "details": "SQL injection vulnerability in index.php in RightInPoint Lyrics Script 3.0 allows remote attackers to execute arbitrary SQL commands via the artist_id parameter in an addalbum action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9pmr-c76h-69jv/GHSA-9pmr-c76h-69jv.json b/advisories/unreviewed/2022/05/GHSA-9pmr-c76h-69jv/GHSA-9pmr-c76h-69jv.json index c6c23e88178..ee7b3500ac6 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pmr-c76h-69jv/GHSA-9pmr-c76h-69jv.json +++ b/advisories/unreviewed/2022/05/GHSA-9pmr-c76h-69jv/GHSA-9pmr-c76h-69jv.json @@ -7,12 +7,8 @@ "CVE-2010-2919" ], "details": "SQL injection vulnerability in the StaticXT (com_staticxt) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9q85-v4x8-53m9/GHSA-9q85-v4x8-53m9.json b/advisories/unreviewed/2022/05/GHSA-9q85-v4x8-53m9/GHSA-9q85-v4x8-53m9.json index 3db02843c6a..481ec36de28 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q85-v4x8-53m9/GHSA-9q85-v4x8-53m9.json +++ b/advisories/unreviewed/2022/05/GHSA-9q85-v4x8-53m9/GHSA-9q85-v4x8-53m9.json @@ -7,12 +7,8 @@ "CVE-2010-4459" ], "details": "Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability via unknown vectors related to SCTP and Kernel/sockfs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9qg7-2pr2-fwxx/GHSA-9qg7-2pr2-fwxx.json b/advisories/unreviewed/2022/05/GHSA-9qg7-2pr2-fwxx/GHSA-9qg7-2pr2-fwxx.json index 908c16e4277..b080943aeb8 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qg7-2pr2-fwxx/GHSA-9qg7-2pr2-fwxx.json +++ b/advisories/unreviewed/2022/05/GHSA-9qg7-2pr2-fwxx/GHSA-9qg7-2pr2-fwxx.json @@ -7,12 +7,8 @@ "CVE-2010-3593" ], "details": "Unspecified vulnerability in the Health Sciences - Oracle Argus Safety component in Oracle Industry Applications 5.0, 5.0.1, 5.0.2, and 5.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Login and LDAP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9qpg-8qf4-xcm3/GHSA-9qpg-8qf4-xcm3.json b/advisories/unreviewed/2022/05/GHSA-9qpg-8qf4-xcm3/GHSA-9qpg-8qf4-xcm3.json index 952f7e0bc56..05b4d19fb44 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qpg-8qf4-xcm3/GHSA-9qpg-8qf4-xcm3.json +++ b/advisories/unreviewed/2022/05/GHSA-9qpg-8qf4-xcm3/GHSA-9qpg-8qf4-xcm3.json @@ -7,12 +7,8 @@ "CVE-2010-1867" ], "details": "SQL injection vulnerability in the ArticleAttachment::GetAttachmentsByArticleNumber method in javascript/tinymcs/plugins/campsiteattachment/attachments.php in Campsite 3.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the article_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9wfh-rmwp-2j6f/GHSA-9wfh-rmwp-2j6f.json b/advisories/unreviewed/2022/05/GHSA-9wfh-rmwp-2j6f/GHSA-9wfh-rmwp-2j6f.json index a85be83e9c5..0621808915a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wfh-rmwp-2j6f/GHSA-9wfh-rmwp-2j6f.json +++ b/advisories/unreviewed/2022/05/GHSA-9wfh-rmwp-2j6f/GHSA-9wfh-rmwp-2j6f.json @@ -7,12 +7,8 @@ "CVE-2010-4511" ], "details": "Unspecified vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 has unknown impact and attack vectors related to the \"dynamic publishing error message.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9x36-6xcq-gx68/GHSA-9x36-6xcq-gx68.json b/advisories/unreviewed/2022/05/GHSA-9x36-6xcq-gx68/GHSA-9x36-6xcq-gx68.json index a656d49f3dd..b3819a391e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x36-6xcq-gx68/GHSA-9x36-6xcq-gx68.json +++ b/advisories/unreviewed/2022/05/GHSA-9x36-6xcq-gx68/GHSA-9x36-6xcq-gx68.json @@ -7,12 +7,8 @@ "CVE-2010-4146" ], "details": "Cross-site scripting (XSS) vulnerability in Attachmate Reflection for the Web 2008 R2 (builds 10.1.569 and earlier), 2008 R1, and 9.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c447-89c9-f6qg/GHSA-c447-89c9-f6qg.json b/advisories/unreviewed/2022/05/GHSA-c447-89c9-f6qg/GHSA-c447-89c9-f6qg.json index aa7139f1873..b43be370f3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c447-89c9-f6qg/GHSA-c447-89c9-f6qg.json +++ b/advisories/unreviewed/2022/05/GHSA-c447-89c9-f6qg/GHSA-c447-89c9-f6qg.json @@ -7,12 +7,8 @@ "CVE-2008-7140" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in @lex Guestbook 4.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) language_setup parameter to setup.php or (2) test parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: a third party has been reported that the test parameter is not used in @lex Guestbook.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4r6-5789-m28r/GHSA-c4r6-5789-m28r.json b/advisories/unreviewed/2022/05/GHSA-c4r6-5789-m28r/GHSA-c4r6-5789-m28r.json index 79750376716..7ece09c1772 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4r6-5789-m28r/GHSA-c4r6-5789-m28r.json +++ b/advisories/unreviewed/2022/05/GHSA-c4r6-5789-m28r/GHSA-c4r6-5789-m28r.json @@ -7,12 +7,8 @@ "CVE-2010-1979" ], "details": "Directory traversal vulnerability in the Affiliate Datafeeds (com_datafeeds) component build 880 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4xf-g2x3-xwj3/GHSA-c4xf-g2x3-xwj3.json b/advisories/unreviewed/2022/05/GHSA-c4xf-g2x3-xwj3/GHSA-c4xf-g2x3-xwj3.json index d7d12afa861..7a4d5d89743 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4xf-g2x3-xwj3/GHSA-c4xf-g2x3-xwj3.json +++ b/advisories/unreviewed/2022/05/GHSA-c4xf-g2x3-xwj3/GHSA-c4xf-g2x3-xwj3.json @@ -7,12 +7,8 @@ "CVE-2010-2907" ], "details": "SQL injection vulnerability in the Huru Helpdesk (com_huruhelpdesk) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a detail action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c58j-fj65-hr85/GHSA-c58j-fj65-hr85.json b/advisories/unreviewed/2022/05/GHSA-c58j-fj65-hr85/GHSA-c58j-fj65-hr85.json index a1ba927399f..e2043f90c9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c58j-fj65-hr85/GHSA-c58j-fj65-hr85.json +++ b/advisories/unreviewed/2022/05/GHSA-c58j-fj65-hr85/GHSA-c58j-fj65-hr85.json @@ -7,12 +7,8 @@ "CVE-2010-1855" ], "details": "SQL injection vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to execute arbitrary SQL commands via the id_auk parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5g4-vv54-c9mx/GHSA-c5g4-vv54-c9mx.json b/advisories/unreviewed/2022/05/GHSA-c5g4-vv54-c9mx/GHSA-c5g4-vv54-c9mx.json index 5274f474527..721b6340966 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5g4-vv54-c9mx/GHSA-c5g4-vv54-c9mx.json +++ b/advisories/unreviewed/2022/05/GHSA-c5g4-vv54-c9mx/GHSA-c5g4-vv54-c9mx.json @@ -7,12 +7,8 @@ "CVE-2010-2136" ], "details": "Directory traversal vulnerability in admin/index.php in Article Friendly, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c6wm-439x-m8c5/GHSA-c6wm-439x-m8c5.json b/advisories/unreviewed/2022/05/GHSA-c6wm-439x-m8c5/GHSA-c6wm-439x-m8c5.json index f15042f3c5d..c7e80d36e9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6wm-439x-m8c5/GHSA-c6wm-439x-m8c5.json +++ b/advisories/unreviewed/2022/05/GHSA-c6wm-439x-m8c5/GHSA-c6wm-439x-m8c5.json @@ -7,12 +7,8 @@ "CVE-2010-4628" ], "details": "member.php in MyBB (aka MyBulletinBoard) before 1.4.12 makes a certain superfluous call to the SQL COUNT function, which allows remote attackers to cause a denial of service (resource consumption) by making requests to member.php that trigger scans of the entire users table.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c7c4-gg8f-6972/GHSA-c7c4-gg8f-6972.json b/advisories/unreviewed/2022/05/GHSA-c7c4-gg8f-6972/GHSA-c7c4-gg8f-6972.json index 3e267eb73c0..5cb59125016 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7c4-gg8f-6972/GHSA-c7c4-gg8f-6972.json +++ b/advisories/unreviewed/2022/05/GHSA-c7c4-gg8f-6972/GHSA-c7c4-gg8f-6972.json @@ -7,12 +7,8 @@ "CVE-2010-4100" ], "details": "Unspecified vulnerability in HP Insight Control Performance Management before 6.1 update 2 allows remote attackers to read arbitrary files via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c7jp-mf9p-5jw3/GHSA-c7jp-mf9p-5jw3.json b/advisories/unreviewed/2022/05/GHSA-c7jp-mf9p-5jw3/GHSA-c7jp-mf9p-5jw3.json index 0c90779cf74..a73cece605b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7jp-mf9p-5jw3/GHSA-c7jp-mf9p-5jw3.json +++ b/advisories/unreviewed/2022/05/GHSA-c7jp-mf9p-5jw3/GHSA-c7jp-mf9p-5jw3.json @@ -7,12 +7,8 @@ "CVE-2010-2113" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in The Uniform Server 5.6.5 allow remote attackers to hijack the authentication of administrators for requests that change passwords via (1) apsetup.php, (2) psetup.php, (3) sslpsetup.php, or (4) mqsetup.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c7p9-7r66-m278/GHSA-c7p9-7r66-m278.json b/advisories/unreviewed/2022/05/GHSA-c7p9-7r66-m278/GHSA-c7p9-7r66-m278.json index 302a67df4eb..cec142b108a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7p9-7r66-m278/GHSA-c7p9-7r66-m278.json +++ b/advisories/unreviewed/2022/05/GHSA-c7p9-7r66-m278/GHSA-c7p9-7r66-m278.json @@ -7,12 +7,8 @@ "CVE-2010-4032" ], "details": "Cross-site request forgery (CSRF) vulnerability in HP Insight Control Performance Management before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c8c6-gph2-8xgc/GHSA-c8c6-gph2-8xgc.json b/advisories/unreviewed/2022/05/GHSA-c8c6-gph2-8xgc/GHSA-c8c6-gph2-8xgc.json index 97f1810376d..5eb1e8b2a11 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8c6-gph2-8xgc/GHSA-c8c6-gph2-8xgc.json +++ b/advisories/unreviewed/2022/05/GHSA-c8c6-gph2-8xgc/GHSA-c8c6-gph2-8xgc.json @@ -7,12 +7,8 @@ "CVE-2008-7231" ], "details": "Cross-site scripting (XSS) vulnerability in Meridio Document and Records Management before 4.3 SR1 allows remote authenticated users to inject arbitrary web script or HTML via the Title field in a (1) document (subGeneralProps:dmpvDocTitle:PROP_W_title) or (2) container (subGeneralProps:dmpvContainerTitle:PROP_W_title).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c8r5-4v73-vfrf/GHSA-c8r5-4v73-vfrf.json b/advisories/unreviewed/2022/05/GHSA-c8r5-4v73-vfrf/GHSA-c8r5-4v73-vfrf.json index 6ed72e1013b..2f58bff3395 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8r5-4v73-vfrf/GHSA-c8r5-4v73-vfrf.json +++ b/advisories/unreviewed/2022/05/GHSA-c8r5-4v73-vfrf/GHSA-c8r5-4v73-vfrf.json @@ -7,12 +7,8 @@ "CVE-2010-2047" ], "details": "SQL injection vulnerability in index.php in JE CMS 1.0.0 and 1.1 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewcategory action. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c9xc-56mr-2w4p/GHSA-c9xc-56mr-2w4p.json b/advisories/unreviewed/2022/05/GHSA-c9xc-56mr-2w4p/GHSA-c9xc-56mr-2w4p.json index b8b189d435a..e9837300b99 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9xc-56mr-2w4p/GHSA-c9xc-56mr-2w4p.json +++ b/advisories/unreviewed/2022/05/GHSA-c9xc-56mr-2w4p/GHSA-c9xc-56mr-2w4p.json @@ -7,12 +7,8 @@ "CVE-2010-3588" ], "details": "Unspecified vulnerability in the Oracle Discoverer component in Oracle Fusion Middleware 10.1.2.3, 11.1.1.2.0, and 11.1.1.3.0 allows remote authenticated users to affect confidentiality and integrity, related to EUL Code & Schema.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cc87-ccgm-46gj/GHSA-cc87-ccgm-46gj.json b/advisories/unreviewed/2022/05/GHSA-cc87-ccgm-46gj/GHSA-cc87-ccgm-46gj.json index c163e829672..90964f381a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc87-ccgm-46gj/GHSA-cc87-ccgm-46gj.json +++ b/advisories/unreviewed/2022/05/GHSA-cc87-ccgm-46gj/GHSA-cc87-ccgm-46gj.json @@ -7,12 +7,8 @@ "CVE-2010-1935" ], "details": "Directory traversal vulnerability in scr/soustab.php in openMairie Openpresse 1.01, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cff7-mg33-3hwg/GHSA-cff7-mg33-3hwg.json b/advisories/unreviewed/2022/05/GHSA-cff7-mg33-3hwg/GHSA-cff7-mg33-3hwg.json index 38bf7e4d910..1ba21083cef 100644 --- a/advisories/unreviewed/2022/05/GHSA-cff7-mg33-3hwg/GHSA-cff7-mg33-3hwg.json +++ b/advisories/unreviewed/2022/05/GHSA-cff7-mg33-3hwg/GHSA-cff7-mg33-3hwg.json @@ -7,12 +7,8 @@ "CVE-2010-1740" ], "details": "SQL injection vulnerability in newsletter.php in GuppY 4.5.18 allows remote attackers to execute arbitrary SQL commands via the lng parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfrp-668w-c627/GHSA-cfrp-668w-c627.json b/advisories/unreviewed/2022/05/GHSA-cfrp-668w-c627/GHSA-cfrp-668w-c627.json index 12f6b90ce8d..85c96f07106 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfrp-668w-c627/GHSA-cfrp-668w-c627.json +++ b/advisories/unreviewed/2022/05/GHSA-cfrp-668w-c627/GHSA-cfrp-668w-c627.json @@ -7,12 +7,8 @@ "CVE-2010-4218" ], "details": "Unspecified vulnerability in Web Services in IBM ENOVIA 6 has unknown impact and attack vectors, related to a system that becomes \"exposed to the internet.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cgw6-gwvc-637r/GHSA-cgw6-gwvc-637r.json b/advisories/unreviewed/2022/05/GHSA-cgw6-gwvc-637r/GHSA-cgw6-gwvc-637r.json index a00dbbc806d..ef6bbc54182 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgw6-gwvc-637r/GHSA-cgw6-gwvc-637r.json +++ b/advisories/unreviewed/2022/05/GHSA-cgw6-gwvc-637r/GHSA-cgw6-gwvc-637r.json @@ -7,12 +7,8 @@ "CVE-2010-2363" ], "details": "The IPv6 Unicast Reverse Path Forwarding (RPF) implementation on the SEIL/X1, SEIL/X2, and SEIL/B1 routers with firmware 1.00 through 2.73, when strict mode is used, does not properly drop packets, which might allow remote attackers to bypass intended access restrictions via a spoofed IP address.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cjw8-32q9-h987/GHSA-cjw8-32q9-h987.json b/advisories/unreviewed/2022/05/GHSA-cjw8-32q9-h987/GHSA-cjw8-32q9-h987.json index 8bf2b89475c..46ba5510780 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjw8-32q9-h987/GHSA-cjw8-32q9-h987.json +++ b/advisories/unreviewed/2022/05/GHSA-cjw8-32q9-h987/GHSA-cjw8-32q9-h987.json @@ -7,12 +7,8 @@ "CVE-2010-2438" ], "details": "SQL injection vulnerability in G.CMS generator allows remote attackers to execute arbitrary SQL commands via the lang parameter to the default URI, probably index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cp55-63r2-rcpp/GHSA-cp55-63r2-rcpp.json b/advisories/unreviewed/2022/05/GHSA-cp55-63r2-rcpp/GHSA-cp55-63r2-rcpp.json index 08ef155086a..a8f63898f05 100644 --- a/advisories/unreviewed/2022/05/GHSA-cp55-63r2-rcpp/GHSA-cp55-63r2-rcpp.json +++ b/advisories/unreviewed/2022/05/GHSA-cp55-63r2-rcpp/GHSA-cp55-63r2-rcpp.json @@ -7,12 +7,8 @@ "CVE-2010-2148" ], "details": "SQL injection vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pagina parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cpqc-x3qr-2fr9/GHSA-cpqc-x3qr-2fr9.json b/advisories/unreviewed/2022/05/GHSA-cpqc-x3qr-2fr9/GHSA-cpqc-x3qr-2fr9.json index be77ea76f68..8d53c704c01 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpqc-x3qr-2fr9/GHSA-cpqc-x3qr-2fr9.json +++ b/advisories/unreviewed/2022/05/GHSA-cpqc-x3qr-2fr9/GHSA-cpqc-x3qr-2fr9.json @@ -7,12 +7,8 @@ "CVE-2010-4273" ], "details": "SQL injection vulnerability in imoveis.php in DescargarVista ACC IMoveis 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cq98-4r72-wm2g/GHSA-cq98-4r72-wm2g.json b/advisories/unreviewed/2022/05/GHSA-cq98-4r72-wm2g/GHSA-cq98-4r72-wm2g.json index 487e9f79abb..b78b6b6f3aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq98-4r72-wm2g/GHSA-cq98-4r72-wm2g.json +++ b/advisories/unreviewed/2022/05/GHSA-cq98-4r72-wm2g/GHSA-cq98-4r72-wm2g.json @@ -7,12 +7,8 @@ "CVE-2010-2021" ], "details": "Open redirect vulnerability in the Global Redirect module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, when non-clean to clean is enabled, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-crgx-9757-wppq/GHSA-crgx-9757-wppq.json b/advisories/unreviewed/2022/05/GHSA-crgx-9757-wppq/GHSA-crgx-9757-wppq.json index 17e268be21c..b69f7308e96 100644 --- a/advisories/unreviewed/2022/05/GHSA-crgx-9757-wppq/GHSA-crgx-9757-wppq.json +++ b/advisories/unreviewed/2022/05/GHSA-crgx-9757-wppq/GHSA-crgx-9757-wppq.json @@ -7,12 +7,8 @@ "CVE-2010-2079" ], "details": "DataTrack System 3.5 allows remote attackers to bypass intended restrictions on file extensions, and read arbitrary files, via a trailing backslash in a URI, as demonstrated by (1) web.config\\ and (2) .ascx\\ files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cwfr-j24c-gpv5/GHSA-cwfr-j24c-gpv5.json b/advisories/unreviewed/2022/05/GHSA-cwfr-j24c-gpv5/GHSA-cwfr-j24c-gpv5.json index e33aef04c9d..5f9cd17e7ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwfr-j24c-gpv5/GHSA-cwfr-j24c-gpv5.json +++ b/advisories/unreviewed/2022/05/GHSA-cwfr-j24c-gpv5/GHSA-cwfr-j24c-gpv5.json @@ -7,12 +7,8 @@ "CVE-2010-4425" ], "details": "Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.1.3.3.2, 10.1.3.4.0, and 10.1.3.4.1 allows remote authenticated users to affect integrity via unknown vectors related to Web Server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cwqr-wx5w-x96j/GHSA-cwqr-wx5w-x96j.json b/advisories/unreviewed/2022/05/GHSA-cwqr-wx5w-x96j/GHSA-cwqr-wx5w-x96j.json index 4ef3b99eae4..ed9a38fcf03 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwqr-wx5w-x96j/GHSA-cwqr-wx5w-x96j.json +++ b/advisories/unreviewed/2022/05/GHSA-cwqr-wx5w-x96j/GHSA-cwqr-wx5w-x96j.json @@ -7,12 +7,8 @@ "CVE-2010-2127" ], "details": "PHP remote file inclusion vulnerability in gallery.php in JV2 Folder Gallery 3.1 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cwvc-h2j5-j87h/GHSA-cwvc-h2j5-j87h.json b/advisories/unreviewed/2022/05/GHSA-cwvc-h2j5-j87h/GHSA-cwvc-h2j5-j87h.json index 015b452b840..86777b79c96 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwvc-h2j5-j87h/GHSA-cwvc-h2j5-j87h.json +++ b/advisories/unreviewed/2022/05/GHSA-cwvc-h2j5-j87h/GHSA-cwvc-h2j5-j87h.json @@ -7,12 +7,8 @@ "CVE-2010-4555" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) drop-down selection lists, (2) the > (greater than) character in the SquirrelSpell spellchecking plugin, and (3) errors associated with the Index Order (aka options_order) page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cx22-p5qf-h4w5/GHSA-cx22-p5qf-h4w5.json b/advisories/unreviewed/2022/05/GHSA-cx22-p5qf-h4w5/GHSA-cx22-p5qf-h4w5.json index 7a247b252b5..b6881b971ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx22-p5qf-h4w5/GHSA-cx22-p5qf-h4w5.json +++ b/advisories/unreviewed/2022/05/GHSA-cx22-p5qf-h4w5/GHSA-cx22-p5qf-h4w5.json @@ -7,12 +7,8 @@ "CVE-2010-2456" ], "details": "Multiple directory traversal vulnerabilities in index.php in Linker IMG 1.0 and earlier allow remote attackers to read and execute arbitrary local files via a URL in the (1) cook_lan cookie parameter ($lan_dir variable) or possibly (2) Sdb_type parameter. NOTE: this was originally reported as remote file inclusion, but this may be inaccurate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cxj5-9j38-qv4q/GHSA-cxj5-9j38-qv4q.json b/advisories/unreviewed/2022/05/GHSA-cxj5-9j38-qv4q/GHSA-cxj5-9j38-qv4q.json index c4a4b1b4fcd..9bf032008ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxj5-9j38-qv4q/GHSA-cxj5-9j38-qv4q.json +++ b/advisories/unreviewed/2022/05/GHSA-cxj5-9j38-qv4q/GHSA-cxj5-9j38-qv4q.json @@ -7,12 +7,8 @@ "CVE-2010-2044" ], "details": "SQL injection vulnerability in the Konsultasi (com_konsultasi) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in a detail action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f2r3-9369-56wc/GHSA-f2r3-9369-56wc.json b/advisories/unreviewed/2022/05/GHSA-f2r3-9369-56wc/GHSA-f2r3-9369-56wc.json index 9ffd802c222..fbc1785445a 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2r3-9369-56wc/GHSA-f2r3-9369-56wc.json +++ b/advisories/unreviewed/2022/05/GHSA-f2r3-9369-56wc/GHSA-f2r3-9369-56wc.json @@ -7,12 +7,8 @@ "CVE-2010-1727" ], "details": "SQL injection vulnerability in type.asp in JobPost 1.0 allows remote attackers to execute arbitrary SQL commands via the iType parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f2w7-6hg5-cm53/GHSA-f2w7-6hg5-cm53.json b/advisories/unreviewed/2022/05/GHSA-f2w7-6hg5-cm53/GHSA-f2w7-6hg5-cm53.json index c0e0d2fda49..ff7d4a26d57 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2w7-6hg5-cm53/GHSA-f2w7-6hg5-cm53.json +++ b/advisories/unreviewed/2022/05/GHSA-f2w7-6hg5-cm53/GHSA-f2w7-6hg5-cm53.json @@ -7,12 +7,8 @@ "CVE-2010-2913" ], "details": "The Citibank Citi Mobile app before 2.0.3 for iOS stores account data in a file, which allows local users to obtain sensitive information via vectors involving (1) the mobile device or (2) a synchronized computer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f32v-f53x-625g/GHSA-f32v-f53x-625g.json b/advisories/unreviewed/2022/05/GHSA-f32v-f53x-625g/GHSA-f32v-f53x-625g.json index 6c22d26d09d..47d75203f95 100644 --- a/advisories/unreviewed/2022/05/GHSA-f32v-f53x-625g/GHSA-f32v-f53x-625g.json +++ b/advisories/unreviewed/2022/05/GHSA-f32v-f53x-625g/GHSA-f32v-f53x-625g.json @@ -7,12 +7,8 @@ "CVE-2010-1775" ], "details": "Race condition in Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch allows physically proximate attackers to bypass intended passcode requirements, and pair a locked device with a computer and access arbitrary data, via vectors involving the initial boot.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3fr-c2xj-gmgh/GHSA-f3fr-c2xj-gmgh.json b/advisories/unreviewed/2022/05/GHSA-f3fr-c2xj-gmgh/GHSA-f3fr-c2xj-gmgh.json index c81994bc8f9..026ff52f1fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3fr-c2xj-gmgh/GHSA-f3fr-c2xj-gmgh.json +++ b/advisories/unreviewed/2022/05/GHSA-f3fr-c2xj-gmgh/GHSA-f3fr-c2xj-gmgh.json @@ -7,12 +7,8 @@ "CVE-2010-2124" ], "details": "SQL injection vulnerability in firma.php in Bartels Schone ConPresso 4.0.7 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f5rg-3x57-9mv4/GHSA-f5rg-3x57-9mv4.json b/advisories/unreviewed/2022/05/GHSA-f5rg-3x57-9mv4/GHSA-f5rg-3x57-9mv4.json index 46a737ba16d..6e5543fab43 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5rg-3x57-9mv4/GHSA-f5rg-3x57-9mv4.json +++ b/advisories/unreviewed/2022/05/GHSA-f5rg-3x57-9mv4/GHSA-f5rg-3x57-9mv4.json @@ -7,12 +7,8 @@ "CVE-2010-4228" ], "details": "Stack-based buffer overflow in NWFTPD.NLM before 5.10.02 in the FTP server in Novell NetWare allows remote authenticated users to execute arbitrary code or cause a denial of service (abend) via a long DELE command, a different vulnerability than CVE-2010-0625.4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f68p-8hwp-w826/GHSA-f68p-8hwp-w826.json b/advisories/unreviewed/2022/05/GHSA-f68p-8hwp-w826/GHSA-f68p-8hwp-w826.json index 38a3adc5c3b..600bcd40083 100644 --- a/advisories/unreviewed/2022/05/GHSA-f68p-8hwp-w826/GHSA-f68p-8hwp-w826.json +++ b/advisories/unreviewed/2022/05/GHSA-f68p-8hwp-w826/GHSA-f68p-8hwp-w826.json @@ -7,12 +7,8 @@ "CVE-2010-4554" ], "details": "functions/page_header.php in SquirrelMail 1.4.21 and earlier does not prevent page rendering inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6mg-fwxg-7jhc/GHSA-f6mg-fwxg-7jhc.json b/advisories/unreviewed/2022/05/GHSA-f6mg-fwxg-7jhc/GHSA-f6mg-fwxg-7jhc.json index c6fb1d740bd..2f6da9c9608 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6mg-fwxg-7jhc/GHSA-f6mg-fwxg-7jhc.json +++ b/advisories/unreviewed/2022/05/GHSA-f6mg-fwxg-7jhc/GHSA-f6mg-fwxg-7jhc.json @@ -7,12 +7,8 @@ "CVE-2010-2458" ], "details": "Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to inject arbitrary web script or HTML via the videoid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f7cj-p2gc-6mpq/GHSA-f7cj-p2gc-6mpq.json b/advisories/unreviewed/2022/05/GHSA-f7cj-p2gc-6mpq/GHSA-f7cj-p2gc-6mpq.json index e22c0317dce..d60a9ee7f50 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7cj-p2gc-6mpq/GHSA-f7cj-p2gc-6mpq.json +++ b/advisories/unreviewed/2022/05/GHSA-f7cj-p2gc-6mpq/GHSA-f7cj-p2gc-6mpq.json @@ -7,12 +7,8 @@ "CVE-2010-4056" ], "details": "solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing a single integer field, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TCP session on port 1315.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f7f9-2whw-qx53/GHSA-f7f9-2whw-qx53.json b/advisories/unreviewed/2022/05/GHSA-f7f9-2whw-qx53/GHSA-f7f9-2whw-qx53.json index 901f2e478cf..63ee9e5341e 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7f9-2whw-qx53/GHSA-f7f9-2whw-qx53.json +++ b/advisories/unreviewed/2022/05/GHSA-f7f9-2whw-qx53/GHSA-f7f9-2whw-qx53.json @@ -7,12 +7,8 @@ "CVE-2010-4055" ], "details": "Stack consumption vulnerability in solid.exe in IBM solidDB 6.5.0.3 and earlier allows remote attackers to cause a denial of service (memory consumption and daemon crash) by connecting to TCP port 1315 and sending a packet with many integer fields, which trigger many recursive calls of a certain function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f9pg-qgmm-v967/GHSA-f9pg-qgmm-v967.json b/advisories/unreviewed/2022/05/GHSA-f9pg-qgmm-v967/GHSA-f9pg-qgmm-v967.json index 31710096bbe..ca5a3105d1e 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9pg-qgmm-v967/GHSA-f9pg-qgmm-v967.json +++ b/advisories/unreviewed/2022/05/GHSA-f9pg-qgmm-v967/GHSA-f9pg-qgmm-v967.json @@ -7,12 +7,8 @@ "CVE-2010-2687" ], "details": "SQL injection vulnerability in printdetail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrary SQL commands via the Id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ffmr-3456-95g2/GHSA-ffmr-3456-95g2.json b/advisories/unreviewed/2022/05/GHSA-ffmr-3456-95g2/GHSA-ffmr-3456-95g2.json index 0abc4fa3640..b3529a96a17 100644 --- a/advisories/unreviewed/2022/05/GHSA-ffmr-3456-95g2/GHSA-ffmr-3456-95g2.json +++ b/advisories/unreviewed/2022/05/GHSA-ffmr-3456-95g2/GHSA-ffmr-3456-95g2.json @@ -7,12 +7,8 @@ "CVE-2010-1496" ], "details": "SQL injection vulnerability in the JoltCard (com_joltcard) component 1.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cardID parameter in a view action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fh4p-65g7-4cxw/GHSA-fh4p-65g7-4cxw.json b/advisories/unreviewed/2022/05/GHSA-fh4p-65g7-4cxw/GHSA-fh4p-65g7-4cxw.json index 0ac15222f97..1fa25e344c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-fh4p-65g7-4cxw/GHSA-fh4p-65g7-4cxw.json +++ b/advisories/unreviewed/2022/05/GHSA-fh4p-65g7-4cxw/GHSA-fh4p-65g7-4cxw.json @@ -7,12 +7,8 @@ "CVE-2010-2039" ], "details": "Cross-site request forgery (CSRF) vulnerability in gpEasy CMS 1.6.2, 1.6.1, and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an Admin_Users action to index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fj6x-fvp6-8xpx/GHSA-fj6x-fvp6-8xpx.json b/advisories/unreviewed/2022/05/GHSA-fj6x-fvp6-8xpx/GHSA-fj6x-fvp6-8xpx.json index 8ff76630831..1d210a196d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-fj6x-fvp6-8xpx/GHSA-fj6x-fvp6-8xpx.json +++ b/advisories/unreviewed/2022/05/GHSA-fj6x-fvp6-8xpx/GHSA-fj6x-fvp6-8xpx.json @@ -7,12 +7,8 @@ "CVE-2010-4437" ], "details": "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.4, 10.0.2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Servlet Container.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fm3q-mpvm-v84g/GHSA-fm3q-mpvm-v84g.json b/advisories/unreviewed/2022/05/GHSA-fm3q-mpvm-v84g/GHSA-fm3q-mpvm-v84g.json index 391b47fe136..a84ff9494bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm3q-mpvm-v84g/GHSA-fm3q-mpvm-v84g.json +++ b/advisories/unreviewed/2022/05/GHSA-fm3q-mpvm-v84g/GHSA-fm3q-mpvm-v84g.json @@ -7,12 +7,8 @@ "CVE-2010-3447" ], "details": "Cross-site scripting (XSS) vulnerability in view.php in the file viewer in Horde Gollem before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the file parameter in a view_file action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fm76-g8pj-f24f/GHSA-fm76-g8pj-f24f.json b/advisories/unreviewed/2022/05/GHSA-fm76-g8pj-f24f/GHSA-fm76-g8pj-f24f.json index d3cc360a381..f032882e5ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm76-g8pj-f24f/GHSA-fm76-g8pj-f24f.json +++ b/advisories/unreviewed/2022/05/GHSA-fm76-g8pj-f24f/GHSA-fm76-g8pj-f24f.json @@ -7,12 +7,8 @@ "CVE-2010-3607" ], "details": "Cross-site scripting (XSS) vulnerability in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fmmr-m43m-x2x8/GHSA-fmmr-m43m-x2x8.json b/advisories/unreviewed/2022/05/GHSA-fmmr-m43m-x2x8/GHSA-fmmr-m43m-x2x8.json index e8d667260b4..7466a61fb4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmmr-m43m-x2x8/GHSA-fmmr-m43m-x2x8.json +++ b/advisories/unreviewed/2022/05/GHSA-fmmr-m43m-x2x8/GHSA-fmmr-m43m-x2x8.json @@ -7,12 +7,8 @@ "CVE-2010-2262" ], "details": "Galileo Students Team Weborf before 0.12.1 allows remote attackers to cause a denial of service (crash) via a crafted Range header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fp8m-5h9q-mjmp/GHSA-fp8m-5h9q-mjmp.json b/advisories/unreviewed/2022/05/GHSA-fp8m-5h9q-mjmp/GHSA-fp8m-5h9q-mjmp.json index b9839f7a437..dd13800b60b 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp8m-5h9q-mjmp/GHSA-fp8m-5h9q-mjmp.json +++ b/advisories/unreviewed/2022/05/GHSA-fp8m-5h9q-mjmp/GHSA-fp8m-5h9q-mjmp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpfj-66xm-fh42/GHSA-fpfj-66xm-fh42.json b/advisories/unreviewed/2022/05/GHSA-fpfj-66xm-fh42/GHSA-fpfj-66xm-fh42.json index 5ae22872ac2..efec637b6ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpfj-66xm-fh42/GHSA-fpfj-66xm-fh42.json +++ b/advisories/unreviewed/2022/05/GHSA-fpfj-66xm-fh42/GHSA-fpfj-66xm-fh42.json @@ -7,12 +7,8 @@ "CVE-2010-2016" ], "details": "SQL injection vulnerability in details.php in Iceberg CMS allows remote attackers to execute arbitrary SQL commands via the p_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpxv-5mjh-r2rq/GHSA-fpxv-5mjh-r2rq.json b/advisories/unreviewed/2022/05/GHSA-fpxv-5mjh-r2rq/GHSA-fpxv-5mjh-r2rq.json index 1ed57ab931a..a3da4c7cf73 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpxv-5mjh-r2rq/GHSA-fpxv-5mjh-r2rq.json +++ b/advisories/unreviewed/2022/05/GHSA-fpxv-5mjh-r2rq/GHSA-fpxv-5mjh-r2rq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frxf-86wq-56jg/GHSA-frxf-86wq-56jg.json b/advisories/unreviewed/2022/05/GHSA-frxf-86wq-56jg/GHSA-frxf-86wq-56jg.json index 0dba77284b9..48f36ddd9dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-frxf-86wq-56jg/GHSA-frxf-86wq-56jg.json +++ b/advisories/unreviewed/2022/05/GHSA-frxf-86wq-56jg/GHSA-frxf-86wq-56jg.json @@ -7,12 +7,8 @@ "CVE-2010-1498" ], "details": "Multiple SQL injection vulnerabilities in dl_stats before 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) download.php and (2) view_file.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fv6h-j25m-44r8/GHSA-fv6h-j25m-44r8.json b/advisories/unreviewed/2022/05/GHSA-fv6h-j25m-44r8/GHSA-fv6h-j25m-44r8.json index 2a4377c1875..b3a5ca42de9 100644 --- a/advisories/unreviewed/2022/05/GHSA-fv6h-j25m-44r8/GHSA-fv6h-j25m-44r8.json +++ b/advisories/unreviewed/2022/05/GHSA-fv6h-j25m-44r8/GHSA-fv6h-j25m-44r8.json @@ -7,12 +7,8 @@ "CVE-2010-3927" ], "details": "Untrusted search path vulnerability in Lunascape before 6.4.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fvfr-2wj6-cpjw/GHSA-fvfr-2wj6-cpjw.json b/advisories/unreviewed/2022/05/GHSA-fvfr-2wj6-cpjw/GHSA-fvfr-2wj6-cpjw.json index 7e22684d6f5..8da508db553 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvfr-2wj6-cpjw/GHSA-fvfr-2wj6-cpjw.json +++ b/advisories/unreviewed/2022/05/GHSA-fvfr-2wj6-cpjw/GHSA-fvfr-2wj6-cpjw.json @@ -7,12 +7,8 @@ "CVE-2010-2677" ], "details": "PHP remote file inclusion vulnerability in mw_plugin.php in Open Web Analytics (OWA) 1.2.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fvpf-jrm8-v7p6/GHSA-fvpf-jrm8-v7p6.json b/advisories/unreviewed/2022/05/GHSA-fvpf-jrm8-v7p6/GHSA-fvpf-jrm8-v7p6.json index 20ace6629a4..74fd02a8420 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvpf-jrm8-v7p6/GHSA-fvpf-jrm8-v7p6.json +++ b/advisories/unreviewed/2022/05/GHSA-fvpf-jrm8-v7p6/GHSA-fvpf-jrm8-v7p6.json @@ -7,12 +7,8 @@ "CVE-2008-7206" ], "details": "Unspecified vulnerability in Electronic Logbook (ELOG) before 2.7.2 has unknown impact and attack vectors when the \"logbook contains HTML code,\" probably cross-site scripting (XSS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fvpq-4888-9x4p/GHSA-fvpq-4888-9x4p.json b/advisories/unreviewed/2022/05/GHSA-fvpq-4888-9x4p/GHSA-fvpq-4888-9x4p.json index 9b4f0a18015..7ffdf5fddf1 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvpq-4888-9x4p/GHSA-fvpq-4888-9x4p.json +++ b/advisories/unreviewed/2022/05/GHSA-fvpq-4888-9x4p/GHSA-fvpq-4888-9x4p.json @@ -7,12 +7,8 @@ "CVE-2010-2918" ], "details": "PHP remote file inclusion vulnerability in core/include/myMailer.class.php in the Visites (com_joomla-visites) component 1.1 RC2 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fw7j-37p2-4j4w/GHSA-fw7j-37p2-4j4w.json b/advisories/unreviewed/2022/05/GHSA-fw7j-37p2-4j4w/GHSA-fw7j-37p2-4j4w.json index bceb8c24789..9cb1dd18aa1 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw7j-37p2-4j4w/GHSA-fw7j-37p2-4j4w.json +++ b/advisories/unreviewed/2022/05/GHSA-fw7j-37p2-4j4w/GHSA-fw7j-37p2-4j4w.json @@ -7,12 +7,8 @@ "CVE-2010-3459" ], "details": "Cross-site scripting (XSS) vulnerability in the Ajax WebMail interface in AXIGEN Mail Server before 7.4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fxg8-p79j-qgvc/GHSA-fxg8-p79j-qgvc.json b/advisories/unreviewed/2022/05/GHSA-fxg8-p79j-qgvc/GHSA-fxg8-p79j-qgvc.json index 22ba2bca458..f59409b4539 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxg8-p79j-qgvc/GHSA-fxg8-p79j-qgvc.json +++ b/advisories/unreviewed/2022/05/GHSA-fxg8-p79j-qgvc/GHSA-fxg8-p79j-qgvc.json @@ -7,12 +7,8 @@ "CVE-2010-4509" ], "details": "Multiple unspecified vulnerabilities in Movable Type 4.x before 4.35 and 5.x before 5.04 have unknown impact and attack vectors related to the (1) mt:AssetProperty and (2) mt:EntryFlag tags.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g2m6-fh3h-866m/GHSA-g2m6-fh3h-866m.json b/advisories/unreviewed/2022/05/GHSA-g2m6-fh3h-866m/GHSA-g2m6-fh3h-866m.json index 18c6bbbd4f5..696535ea0c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2m6-fh3h-866m/GHSA-g2m6-fh3h-866m.json +++ b/advisories/unreviewed/2022/05/GHSA-g2m6-fh3h-866m/GHSA-g2m6-fh3h-866m.json @@ -7,12 +7,8 @@ "CVE-2010-2460" ], "details": "SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers to execute arbitrary SQL commands via the mechant_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g37h-m5cc-48wj/GHSA-g37h-m5cc-48wj.json b/advisories/unreviewed/2022/05/GHSA-g37h-m5cc-48wj/GHSA-g37h-m5cc-48wj.json index 3e44a42a958..f8635e91957 100644 --- a/advisories/unreviewed/2022/05/GHSA-g37h-m5cc-48wj/GHSA-g37h-m5cc-48wj.json +++ b/advisories/unreviewed/2022/05/GHSA-g37h-m5cc-48wj/GHSA-g37h-m5cc-48wj.json @@ -7,12 +7,8 @@ "CVE-2008-7158" ], "details": "Numara FootPrints 7.5a through 7.5a1 and 8.0 through 8.0a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) transcriptFile parameter to MRcgi/MRchat.pl or (2) LOADFILE parameter to MRcgi/MRABLoad2.pl. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g38c-rrvw-cg3q/GHSA-g38c-rrvw-cg3q.json b/advisories/unreviewed/2022/05/GHSA-g38c-rrvw-cg3q/GHSA-g38c-rrvw-cg3q.json index a36fed8fc16..92d490976ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-g38c-rrvw-cg3q/GHSA-g38c-rrvw-cg3q.json +++ b/advisories/unreviewed/2022/05/GHSA-g38c-rrvw-cg3q/GHSA-g38c-rrvw-cg3q.json @@ -7,12 +7,8 @@ "CVE-2010-2534" ], "details": "The NetworkSyncCommandQueue function in network/network_command.cpp in OpenTTD before 1.0.3 does not properly clear a pointer in a linked list, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted request, related to the client command queue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g3jm-cg9g-h67v/GHSA-g3jm-cg9g-h67v.json b/advisories/unreviewed/2022/05/GHSA-g3jm-cg9g-h67v/GHSA-g3jm-cg9g-h67v.json index f434a212377..be784c79e3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3jm-cg9g-h67v/GHSA-g3jm-cg9g-h67v.json +++ b/advisories/unreviewed/2022/05/GHSA-g3jm-cg9g-h67v/GHSA-g3jm-cg9g-h67v.json @@ -7,12 +7,8 @@ "CVE-2010-3480" ], "details": "Directory traversal vulnerability in index.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g5xq-3448-3grg/GHSA-g5xq-3448-3grg.json b/advisories/unreviewed/2022/05/GHSA-g5xq-3448-3grg/GHSA-g5xq-3448-3grg.json index ce2e0a858b6..7971e3098a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5xq-3448-3grg/GHSA-g5xq-3448-3grg.json +++ b/advisories/unreviewed/2022/05/GHSA-g5xq-3448-3grg/GHSA-g5xq-3448-3grg.json @@ -7,12 +7,8 @@ "CVE-2010-2111" ], "details": "Cross-site request forgery (CSRF) vulnerability in user/user-set.do in Pacific Timesheet 6.74 build 363 allows remote attackers to hijack the authentication of administrators for requests that create a new administrator via a new_admin action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6wr-xh7r-qh7r/GHSA-g6wr-xh7r-qh7r.json b/advisories/unreviewed/2022/05/GHSA-g6wr-xh7r-qh7r/GHSA-g6wr-xh7r-qh7r.json index b304b1a2ba7..bbcab5d7cfc 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6wr-xh7r-qh7r/GHSA-g6wr-xh7r-qh7r.json +++ b/advisories/unreviewed/2022/05/GHSA-g6wr-xh7r-qh7r/GHSA-g6wr-xh7r-qh7r.json @@ -7,12 +7,8 @@ "CVE-2010-4353" ], "details": "Unrestricted file upload vulnerability in modules/gallery/models/item.php in Menalto Gallery before 3.0 and beta allows remote authenticated users with upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g74x-8276-gw6g/GHSA-g74x-8276-gw6g.json b/advisories/unreviewed/2022/05/GHSA-g74x-8276-gw6g/GHSA-g74x-8276-gw6g.json index eb3461ff44f..4f84147ee94 100644 --- a/advisories/unreviewed/2022/05/GHSA-g74x-8276-gw6g/GHSA-g74x-8276-gw6g.json +++ b/advisories/unreviewed/2022/05/GHSA-g74x-8276-gw6g/GHSA-g74x-8276-gw6g.json @@ -7,12 +7,8 @@ "CVE-2010-1858" ], "details": "Directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g87h-m2mj-j8xg/GHSA-g87h-m2mj-j8xg.json b/advisories/unreviewed/2022/05/GHSA-g87h-m2mj-j8xg/GHSA-g87h-m2mj-j8xg.json index a15465e8399..1df18578d24 100644 --- a/advisories/unreviewed/2022/05/GHSA-g87h-m2mj-j8xg/GHSA-g87h-m2mj-j8xg.json +++ b/advisories/unreviewed/2022/05/GHSA-g87h-m2mj-j8xg/GHSA-g87h-m2mj-j8xg.json @@ -7,12 +7,8 @@ "CVE-2010-3207" ], "details": "SQL injection vulnerability in index.php in GaleriaSHQIP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the album_id parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g8gg-rcmj-jj2r/GHSA-g8gg-rcmj-jj2r.json b/advisories/unreviewed/2022/05/GHSA-g8gg-rcmj-jj2r/GHSA-g8gg-rcmj-jj2r.json index 686ec61ef74..b268367946b 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8gg-rcmj-jj2r/GHSA-g8gg-rcmj-jj2r.json +++ b/advisories/unreviewed/2022/05/GHSA-g8gg-rcmj-jj2r/GHSA-g8gg-rcmj-jj2r.json @@ -7,12 +7,8 @@ "CVE-2010-2929" ], "details": "Untrusted search path vulnerability in hsolinkcontrol in hsolink 1.0.118 allows local users to gain privileges via a modified PATH environment variable, which is used during execution of the (1) route, (2) mv, and (3) cp programs, a different vulnerability than CVE-2010-1671.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g9m3-q24q-m9q6/GHSA-g9m3-q24q-m9q6.json b/advisories/unreviewed/2022/05/GHSA-g9m3-q24q-m9q6/GHSA-g9m3-q24q-m9q6.json index 3e05f1877b0..ba63a4de864 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9m3-q24q-m9q6/GHSA-g9m3-q24q-m9q6.json +++ b/advisories/unreviewed/2022/05/GHSA-g9m3-q24q-m9q6/GHSA-g9m3-q24q-m9q6.json @@ -7,12 +7,8 @@ "CVE-2010-4215" ], "details": "UI/Manage.pm in Foswiki 1.1.0 and 1.1.1 allows remote authenticated users to gain privileges by modifying the GROUP and ALLOWTOPICCHANGE preferences in the topic preferences for Main.AdminGroup.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gf36-rwr4-jchr/GHSA-gf36-rwr4-jchr.json b/advisories/unreviewed/2022/05/GHSA-gf36-rwr4-jchr/GHSA-gf36-rwr4-jchr.json index 1e79a846a56..00249693b5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf36-rwr4-jchr/GHSA-gf36-rwr4-jchr.json +++ b/advisories/unreviewed/2022/05/GHSA-gf36-rwr4-jchr/GHSA-gf36-rwr4-jchr.json @@ -7,12 +7,8 @@ "CVE-2010-2467" ], "details": "The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not require setting a password for the FTP server that stores database backups, which makes it easier for remote attackers to download backup files via unspecified FTP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gf95-p6g7-5745/GHSA-gf95-p6g7-5745.json b/advisories/unreviewed/2022/05/GHSA-gf95-p6g7-5745/GHSA-gf95-p6g7-5745.json index 0597ac41742..ee86f65ee22 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf95-p6g7-5745/GHSA-gf95-p6g7-5745.json +++ b/advisories/unreviewed/2022/05/GHSA-gf95-p6g7-5745/GHSA-gf95-p6g7-5745.json @@ -7,12 +7,8 @@ "CVE-2010-3830" ], "details": "Networking in Apple iOS before 4.2 accesses an invalid pointer during the processing of packet filter rules, which allows local users to gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gh64-r29h-qrp4/GHSA-gh64-r29h-qrp4.json b/advisories/unreviewed/2022/05/GHSA-gh64-r29h-qrp4/GHSA-gh64-r29h-qrp4.json index f4c61d82914..45f7a1b8fc7 100644 --- a/advisories/unreviewed/2022/05/GHSA-gh64-r29h-qrp4/GHSA-gh64-r29h-qrp4.json +++ b/advisories/unreviewed/2022/05/GHSA-gh64-r29h-qrp4/GHSA-gh64-r29h-qrp4.json @@ -7,12 +7,8 @@ "CVE-2010-4438" ], "details": "Unspecified vulnerability in Oracle GlassFish 2.1, 2.1.1, and 3.0.1, and Java System Message Queue 4.1 allows local users to affect confidentiality, integrity, and availability, related to Java Message Service (JMS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ghpw-v274-x8mh/GHSA-ghpw-v274-x8mh.json b/advisories/unreviewed/2022/05/GHSA-ghpw-v274-x8mh/GHSA-ghpw-v274-x8mh.json index 7309f02f4a1..1a9b2a0fe7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghpw-v274-x8mh/GHSA-ghpw-v274-x8mh.json +++ b/advisories/unreviewed/2022/05/GHSA-ghpw-v274-x8mh/GHSA-ghpw-v274-x8mh.json @@ -7,12 +7,8 @@ "CVE-2010-4446" ], "details": "Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability via unknown vectors related to RDS and Kernel/InfiniBand.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gj9w-hmvj-m22x/GHSA-gj9w-hmvj-m22x.json b/advisories/unreviewed/2022/05/GHSA-gj9w-hmvj-m22x/GHSA-gj9w-hmvj-m22x.json index 9aa4ae2f2cb..296c6d1bc78 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj9w-hmvj-m22x/GHSA-gj9w-hmvj-m22x.json +++ b/advisories/unreviewed/2022/05/GHSA-gj9w-hmvj-m22x/GHSA-gj9w-hmvj-m22x.json @@ -7,12 +7,8 @@ "CVE-2010-2072" ], "details": "Pyftpd 0.8.4 creates log files with predictable names in a temporary directory, which allows local users to cause a denial of service and obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gm26-863f-73h9/GHSA-gm26-863f-73h9.json b/advisories/unreviewed/2022/05/GHSA-gm26-863f-73h9/GHSA-gm26-863f-73h9.json index 56d46fc5999..1056b1ba301 100644 --- a/advisories/unreviewed/2022/05/GHSA-gm26-863f-73h9/GHSA-gm26-863f-73h9.json +++ b/advisories/unreviewed/2022/05/GHSA-gm26-863f-73h9/GHSA-gm26-863f-73h9.json @@ -7,12 +7,8 @@ "CVE-2010-3905" ], "details": "The password reset feature in the administrator interface for Eucalyptus 2.0.0 and 2.0.1 does not perform authentication, which allows remote attackers to gain privileges by sending password reset requests for other users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gp27-5qqj-ww24/GHSA-gp27-5qqj-ww24.json b/advisories/unreviewed/2022/05/GHSA-gp27-5qqj-ww24/GHSA-gp27-5qqj-ww24.json index 8f0723e8dee..ec3341392c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-gp27-5qqj-ww24/GHSA-gp27-5qqj-ww24.json +++ b/advisories/unreviewed/2022/05/GHSA-gp27-5qqj-ww24/GHSA-gp27-5qqj-ww24.json @@ -7,12 +7,8 @@ "CVE-2010-4147" ], "details": "Multiple SQL injection vulnerabilities in Pentasoft Avactis Shopping Cart 1.9.1 build 8356 free edition and earlier allow remote attackers to execute arbitrary SQL commands via the User-Agent header to (1) index.php and (2) product-list.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gqj3-w7c6-64hm/GHSA-gqj3-w7c6-64hm.json b/advisories/unreviewed/2022/05/GHSA-gqj3-w7c6-64hm/GHSA-gqj3-w7c6-64hm.json index 8d5c4700b7a..ae2fdf12f07 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqj3-w7c6-64hm/GHSA-gqj3-w7c6-64hm.json +++ b/advisories/unreviewed/2022/05/GHSA-gqj3-w7c6-64hm/GHSA-gqj3-w7c6-64hm.json @@ -7,12 +7,8 @@ "CVE-2010-1980" ], "details": "Directory traversal vulnerability in joomlaflickr.php in the Joomla Flickr (com_joomlaflickr) component 1.0.3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gqwx-r9ff-8pph/GHSA-gqwx-r9ff-8pph.json b/advisories/unreviewed/2022/05/GHSA-gqwx-r9ff-8pph/GHSA-gqwx-r9ff-8pph.json index 386ea87b3a4..cd442e92f24 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqwx-r9ff-8pph/GHSA-gqwx-r9ff-8pph.json +++ b/advisories/unreviewed/2022/05/GHSA-gqwx-r9ff-8pph/GHSA-gqwx-r9ff-8pph.json @@ -7,12 +7,8 @@ "CVE-2010-1733" ], "details": "Multiple SQL injection vulnerabilities in OCS Inventory NG before 1.02.3 allow remote attackers to execute arbitrary SQL commands via (1) multiple inventory fields to the search form, reachable through index.php; or (2) the \"Software name\" field to the \"All softwares\" search form, reachable through index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gr46-rm4c-r88p/GHSA-gr46-rm4c-r88p.json b/advisories/unreviewed/2022/05/GHSA-gr46-rm4c-r88p/GHSA-gr46-rm4c-r88p.json index 353e326e839..2d937c5c8e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr46-rm4c-r88p/GHSA-gr46-rm4c-r88p.json +++ b/advisories/unreviewed/2022/05/GHSA-gr46-rm4c-r88p/GHSA-gr46-rm4c-r88p.json @@ -7,12 +7,8 @@ "CVE-2010-3022" ], "details": "Cross-site scripting (XSS) vulnerability in the Performance logging module in the Devel module 5.x before 5.x-1.3 and 6.x before 6.x-1.21 for Drupal allows remote authenticated users, with add url aliases and report access permissions, to inject arbitrary web script or HTML via crafted node paths in a URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gr4w-3rcg-cq27/GHSA-gr4w-3rcg-cq27.json b/advisories/unreviewed/2022/05/GHSA-gr4w-3rcg-cq27/GHSA-gr4w-3rcg-cq27.json index b31d6e5cf39..f73f13b4560 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr4w-3rcg-cq27/GHSA-gr4w-3rcg-cq27.json +++ b/advisories/unreviewed/2022/05/GHSA-gr4w-3rcg-cq27/GHSA-gr4w-3rcg-cq27.json @@ -7,12 +7,8 @@ "CVE-2010-2138" ], "details": "Multiple directory traversal vulnerabilities in ProMan 0.1.1 and earlier allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the _SESSION[userLang] parameter to (1) elisttasks.php, (2) managepmanagers.php, (3) manageusers.php, (4) helpfunc.php, (5) managegroups.php, (6) manageprocess.php, and (7) manageusersgroups.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gr52-m656-xvfr/GHSA-gr52-m656-xvfr.json b/advisories/unreviewed/2022/05/GHSA-gr52-m656-xvfr/GHSA-gr52-m656-xvfr.json index f64d61abd03..cde3c7df0d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr52-m656-xvfr/GHSA-gr52-m656-xvfr.json +++ b/advisories/unreviewed/2022/05/GHSA-gr52-m656-xvfr/GHSA-gr52-m656-xvfr.json @@ -7,12 +7,8 @@ "CVE-2010-2090" ], "details": "The npb_protocol_error function in sna V5router64 in IBM Communications Server for Windows 6.1.3 and Communications Server for AIX (aka CSAIX or CS/AIX) in sna.rte before 6.3.1.2 allows remote attackers to cause a denial of service (daemon crash) via APPC data containing a GDSID variable with a GDS length that is too small.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gvrc-33rc-wf3c/GHSA-gvrc-33rc-wf3c.json b/advisories/unreviewed/2022/05/GHSA-gvrc-33rc-wf3c/GHSA-gvrc-33rc-wf3c.json index d56b865439a..3d9821dbb89 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvrc-33rc-wf3c/GHSA-gvrc-33rc-wf3c.json +++ b/advisories/unreviewed/2022/05/GHSA-gvrc-33rc-wf3c/GHSA-gvrc-33rc-wf3c.json @@ -7,12 +7,8 @@ "CVE-2010-1957" ], "details": "Directory traversal vulnerability in the Love Factory (com_lovefactory) component 1.3.4 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gw52-6qvc-qghx/GHSA-gw52-6qvc-qghx.json b/advisories/unreviewed/2022/05/GHSA-gw52-6qvc-qghx/GHSA-gw52-6qvc-qghx.json index 378f899a275..93a8a68a572 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw52-6qvc-qghx/GHSA-gw52-6qvc-qghx.json +++ b/advisories/unreviewed/2022/05/GHSA-gw52-6qvc-qghx/GHSA-gw52-6qvc-qghx.json @@ -7,12 +7,8 @@ "CVE-2010-2905" ], "details": "SQL injection vulnerability in info.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gx4x-mg2h-gqh7/GHSA-gx4x-mg2h-gqh7.json b/advisories/unreviewed/2022/05/GHSA-gx4x-mg2h-gqh7/GHSA-gx4x-mg2h-gqh7.json index 9b63a610464..e9e78adf950 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx4x-mg2h-gqh7/GHSA-gx4x-mg2h-gqh7.json +++ b/advisories/unreviewed/2022/05/GHSA-gx4x-mg2h-gqh7/GHSA-gx4x-mg2h-gqh7.json @@ -7,12 +7,8 @@ "CVE-2010-3841" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the rev parameter to the view script or (2) the query string to the login script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h3qm-57f6-w9vc/GHSA-h3qm-57f6-w9vc.json b/advisories/unreviewed/2022/05/GHSA-h3qm-57f6-w9vc/GHSA-h3qm-57f6-w9vc.json index 91ccfd4bd03..cb77c5af67a 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3qm-57f6-w9vc/GHSA-h3qm-57f6-w9vc.json +++ b/advisories/unreviewed/2022/05/GHSA-h3qm-57f6-w9vc/GHSA-h3qm-57f6-w9vc.json @@ -7,12 +7,8 @@ "CVE-2010-4556" ], "details": "Stack-based buffer overflow in the SapThemeRepository ActiveX control (sapwdpcd.dll) in SAP NetWeaver Business Client allows remote attackers to execute arbitrary code via the (1) Load and (2) LoadTheme methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h3v9-chrp-f4j9/GHSA-h3v9-chrp-f4j9.json b/advisories/unreviewed/2022/05/GHSA-h3v9-chrp-f4j9/GHSA-h3v9-chrp-f4j9.json index 29c09da7ccf..9ed3d9739b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3v9-chrp-f4j9/GHSA-h3v9-chrp-f4j9.json +++ b/advisories/unreviewed/2022/05/GHSA-h3v9-chrp-f4j9/GHSA-h3v9-chrp-f4j9.json @@ -7,12 +7,8 @@ "CVE-2010-4499" ], "details": "Session fixation vulnerability in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers to hijack web sessions via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h5qj-6vv9-f5jh/GHSA-h5qj-6vv9-f5jh.json b/advisories/unreviewed/2022/05/GHSA-h5qj-6vv9-f5jh/GHSA-h5qj-6vv9-f5jh.json index ed731dbd601..8978732751c 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5qj-6vv9-f5jh/GHSA-h5qj-6vv9-f5jh.json +++ b/advisories/unreviewed/2022/05/GHSA-h5qj-6vv9-f5jh/GHSA-h5qj-6vv9-f5jh.json @@ -7,12 +7,8 @@ "CVE-2010-2610" ], "details": "Multiple SQL injection vulnerabilities in 2daybiz Job Site Script allow remote attackers to execute arbitrary SQL commands via the (1) jid parameter to view_current_job.php, (2) job_iid parameter to show_search_more.php, and (3) left_cat parameter to show_search_result.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h6f2-m5v7-5p44/GHSA-h6f2-m5v7-5p44.json b/advisories/unreviewed/2022/05/GHSA-h6f2-m5v7-5p44/GHSA-h6f2-m5v7-5p44.json index 4e7a2efe82f..3e8a1b2405f 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6f2-m5v7-5p44/GHSA-h6f2-m5v7-5p44.json +++ b/advisories/unreviewed/2022/05/GHSA-h6f2-m5v7-5p44/GHSA-h6f2-m5v7-5p44.json @@ -7,12 +7,8 @@ "CVE-2010-3597" ], "details": "Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.0 allows local users to affect availability, related to Outside In Viewer SDK.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h6v7-5393-j43m/GHSA-h6v7-5393-j43m.json b/advisories/unreviewed/2022/05/GHSA-h6v7-5393-j43m/GHSA-h6v7-5393-j43m.json index 6da53a3311f..14d01d00fcb 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6v7-5393-j43m/GHSA-h6v7-5393-j43m.json +++ b/advisories/unreviewed/2022/05/GHSA-h6v7-5393-j43m/GHSA-h6v7-5393-j43m.json @@ -7,12 +7,8 @@ "CVE-2010-1958" ], "details": "Cross-site scripting (XSS) vulnerability in the FileField module 5.x before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote authenticated users, with create or edit permissions and 'Path to File' or 'URL to File' display enabled, to inject arbitrary web script or HTML via the file name (filepath parameter).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h6wg-55h3-3874/GHSA-h6wg-55h3-3874.json b/advisories/unreviewed/2022/05/GHSA-h6wg-55h3-3874/GHSA-h6wg-55h3-3874.json index f5c5bf917fc..eb421220846 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6wg-55h3-3874/GHSA-h6wg-55h3-3874.json +++ b/advisories/unreviewed/2022/05/GHSA-h6wg-55h3-3874/GHSA-h6wg-55h3-3874.json @@ -7,12 +7,8 @@ "CVE-2010-2018" ], "details": "Directory traversal vulnerability in downlot.php in Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7qm-8pq2-ffp8/GHSA-h7qm-8pq2-ffp8.json b/advisories/unreviewed/2022/05/GHSA-h7qm-8pq2-ffp8/GHSA-h7qm-8pq2-ffp8.json index 9bfa161a1e8..976b65a8f2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7qm-8pq2-ffp8/GHSA-h7qm-8pq2-ffp8.json +++ b/advisories/unreviewed/2022/05/GHSA-h7qm-8pq2-ffp8/GHSA-h7qm-8pq2-ffp8.json @@ -7,12 +7,8 @@ "CVE-2010-1873" ], "details": "SQL injection vulnerability in the Jvehicles (com_jvehicles) component 1.0, 2.0, and 2.1111 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlisting action to index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h8r9-6h89-2cmf/GHSA-h8r9-6h89-2cmf.json b/advisories/unreviewed/2022/05/GHSA-h8r9-6h89-2cmf/GHSA-h8r9-6h89-2cmf.json index 5b30f1a83b1..5ecc495251f 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8r9-6h89-2cmf/GHSA-h8r9-6h89-2cmf.json +++ b/advisories/unreviewed/2022/05/GHSA-h8r9-6h89-2cmf/GHSA-h8r9-6h89-2cmf.json @@ -7,12 +7,8 @@ "CVE-2010-1932" ], "details": "Heap-based buffer overflow in XnView 1.97.4 and possibly earlier allows remote attackers to execute arbitrary code via a MultiBitMap (MBM) file with a Paint Data Section that contains a malformed Encoding field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hfrg-fh8r-qfqx/GHSA-hfrg-fh8r-qfqx.json b/advisories/unreviewed/2022/05/GHSA-hfrg-fh8r-qfqx/GHSA-hfrg-fh8r-qfqx.json index 35e1e91ee98..dce02e0a0ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfrg-fh8r-qfqx/GHSA-hfrg-fh8r-qfqx.json +++ b/advisories/unreviewed/2022/05/GHSA-hfrg-fh8r-qfqx/GHSA-hfrg-fh8r-qfqx.json @@ -7,12 +7,8 @@ "CVE-2010-3925" ], "details": "Contents-Mall before 15 does not properly handle passwords, which allows remote attackers to discover the administrative password, and consequently obtain sensitive information or modify data, via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hg3m-wq4w-f682/GHSA-hg3m-wq4w-f682.json b/advisories/unreviewed/2022/05/GHSA-hg3m-wq4w-f682/GHSA-hg3m-wq4w-f682.json index 019b5d8ddc1..79b33334635 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg3m-wq4w-f682/GHSA-hg3m-wq4w-f682.json +++ b/advisories/unreviewed/2022/05/GHSA-hg3m-wq4w-f682/GHSA-hg3m-wq4w-f682.json @@ -7,12 +7,8 @@ "CVE-2010-1534" ], "details": "Directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hg7f-ch82-693x/GHSA-hg7f-ch82-693x.json b/advisories/unreviewed/2022/05/GHSA-hg7f-ch82-693x/GHSA-hg7f-ch82-693x.json index 8930603c2bd..d07c1fd1d77 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg7f-ch82-693x/GHSA-hg7f-ch82-693x.json +++ b/advisories/unreviewed/2022/05/GHSA-hg7f-ch82-693x/GHSA-hg7f-ch82-693x.json @@ -7,12 +7,8 @@ "CVE-2010-1952" ], "details": "Directory traversal vulnerability in the BeeHeard (com_beeheard) and BeeHeard Lite (com_beeheardlite) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hgp2-5f7q-m5jp/GHSA-hgp2-5f7q-m5jp.json b/advisories/unreviewed/2022/05/GHSA-hgp2-5f7q-m5jp/GHSA-hgp2-5f7q-m5jp.json index b5f222448c2..cf951f0d89e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hgp2-5f7q-m5jp/GHSA-hgp2-5f7q-m5jp.json +++ b/advisories/unreviewed/2022/05/GHSA-hgp2-5f7q-m5jp/GHSA-hgp2-5f7q-m5jp.json @@ -7,12 +7,8 @@ "CVE-2010-4211" ], "details": "The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof a PayPal web server via an arbitrary certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hh3q-37j7-xw97/GHSA-hh3q-37j7-xw97.json b/advisories/unreviewed/2022/05/GHSA-hh3q-37j7-xw97/GHSA-hh3q-37j7-xw97.json index 20c12f1b814..afcd41c7236 100644 --- a/advisories/unreviewed/2022/05/GHSA-hh3q-37j7-xw97/GHSA-hh3q-37j7-xw97.json +++ b/advisories/unreviewed/2022/05/GHSA-hh3q-37j7-xw97/GHSA-hh3q-37j7-xw97.json @@ -7,12 +7,8 @@ "CVE-2010-2141" ], "details": "SQL injection vulnerability in index.php in NITRO Web Gallery allows remote attackers to execute arbitrary SQL commands via the PictureId parameter in an open action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hhcq-96ph-hc6g/GHSA-hhcq-96ph-hc6g.json b/advisories/unreviewed/2022/05/GHSA-hhcq-96ph-hc6g/GHSA-hhcq-96ph-hc6g.json index ccc85851899..c8652358abc 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhcq-96ph-hc6g/GHSA-hhcq-96ph-hc6g.json +++ b/advisories/unreviewed/2022/05/GHSA-hhcq-96ph-hc6g/GHSA-hhcq-96ph-hc6g.json @@ -7,12 +7,8 @@ "CVE-2010-2321" ], "details": "Buffer overflow in Adobe InDesign CS3 10.0 allows user-assisted remote attackers to execute arbitrary code via a crafted .indd file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hhr4-5gv9-vmp2/GHSA-hhr4-5gv9-vmp2.json b/advisories/unreviewed/2022/05/GHSA-hhr4-5gv9-vmp2/GHSA-hhr4-5gv9-vmp2.json index 2cc4b94eac1..3cceba9674a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhr4-5gv9-vmp2/GHSA-hhr4-5gv9-vmp2.json +++ b/advisories/unreviewed/2022/05/GHSA-hhr4-5gv9-vmp2/GHSA-hhr4-5gv9-vmp2.json @@ -7,12 +7,8 @@ "CVE-2010-4107" ], "details": "The default configuration of the PJL Access value in the File System External Access settings on HP LaserJet MFP printers, Color LaserJet MFP printers, and LaserJet 4100, 4200, 4300, 5100, 8150, and 9000 printers enables PJL commands that use the device's filesystem, which allows remote attackers to read arbitrary files via a command inside a print job, as demonstrated by a directory traversal attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hj7g-953m-g64c/GHSA-hj7g-953m-g64c.json b/advisories/unreviewed/2022/05/GHSA-hj7g-953m-g64c/GHSA-hj7g-953m-g64c.json index 9e1db94d1d3..eb17522f30c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj7g-953m-g64c/GHSA-hj7g-953m-g64c.json +++ b/advisories/unreviewed/2022/05/GHSA-hj7g-953m-g64c/GHSA-hj7g-953m-g64c.json @@ -7,12 +7,8 @@ "CVE-2010-4441" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft and JDEdwards Suite 9.1 Bundle #4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Talent Acquisition Manager.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hq62-5x3m-5577/GHSA-hq62-5x3m-5577.json b/advisories/unreviewed/2022/05/GHSA-hq62-5x3m-5577/GHSA-hq62-5x3m-5577.json index 94825ffa569..5a9a8c2136f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hq62-5x3m-5577/GHSA-hq62-5x3m-5577.json +++ b/advisories/unreviewed/2022/05/GHSA-hq62-5x3m-5577/GHSA-hq62-5x3m-5577.json @@ -7,12 +7,8 @@ "CVE-2008-7128" ], "details": "The ssl_parse_client_key_exchange function in XySSL before 0.9 does not protect against certain Bleichenbacher attacks using chosen ciphertext, which allows remote attackers to recover keys via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hq74-v35j-jc5r/GHSA-hq74-v35j-jc5r.json b/advisories/unreviewed/2022/05/GHSA-hq74-v35j-jc5r/GHSA-hq74-v35j-jc5r.json index f31d4b7a357..1ada7003770 100644 --- a/advisories/unreviewed/2022/05/GHSA-hq74-v35j-jc5r/GHSA-hq74-v35j-jc5r.json +++ b/advisories/unreviewed/2022/05/GHSA-hq74-v35j-jc5r/GHSA-hq74-v35j-jc5r.json @@ -7,12 +7,8 @@ "CVE-2010-2459" ], "details": "SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute arbitrary SQL commands via the videoid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvw3-wqpj-8g42/GHSA-hvw3-wqpj-8g42.json b/advisories/unreviewed/2022/05/GHSA-hvw3-wqpj-8g42/GHSA-hvw3-wqpj-8g42.json index 3f31bb11e65..414d92bca29 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvw3-wqpj-8g42/GHSA-hvw3-wqpj-8g42.json +++ b/advisories/unreviewed/2022/05/GHSA-hvw3-wqpj-8g42/GHSA-hvw3-wqpj-8g42.json @@ -7,12 +7,8 @@ "CVE-2010-2912" ], "details": "SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the _a parameter in a downloads action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hw3j-2ppx-mp2f/GHSA-hw3j-2ppx-mp2f.json b/advisories/unreviewed/2022/05/GHSA-hw3j-2ppx-mp2f/GHSA-hw3j-2ppx-mp2f.json index 0d3a6976b8d..7258eddf2ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-hw3j-2ppx-mp2f/GHSA-hw3j-2ppx-mp2f.json +++ b/advisories/unreviewed/2022/05/GHSA-hw3j-2ppx-mp2f/GHSA-hw3j-2ppx-mp2f.json @@ -7,12 +7,8 @@ "CVE-2010-3479" ], "details": "SQL injection vulnerability in list.php in BoutikOne 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hxvx-q4xc-7x53/GHSA-hxvx-q4xc-7x53.json b/advisories/unreviewed/2022/05/GHSA-hxvx-q4xc-7x53/GHSA-hxvx-q4xc-7x53.json index 6ec2a7d2af3..141de6247ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-hxvx-q4xc-7x53/GHSA-hxvx-q4xc-7x53.json +++ b/advisories/unreviewed/2022/05/GHSA-hxvx-q4xc-7x53/GHSA-hxvx-q4xc-7x53.json @@ -7,12 +7,8 @@ "CVE-2010-2339" ], "details": "SQL injection vulnerability in admin/pages.php in Subdreamer CMS 3.x.x allows remote attackers to execute arbitrary SQL commands via the categoryids[] parameter in an update_pages action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j26h-pv9m-hqv4/GHSA-j26h-pv9m-hqv4.json b/advisories/unreviewed/2022/05/GHSA-j26h-pv9m-hqv4/GHSA-j26h-pv9m-hqv4.json index cb3a373ea6c..3ee17ec4559 100644 --- a/advisories/unreviewed/2022/05/GHSA-j26h-pv9m-hqv4/GHSA-j26h-pv9m-hqv4.json +++ b/advisories/unreviewed/2022/05/GHSA-j26h-pv9m-hqv4/GHSA-j26h-pv9m-hqv4.json @@ -7,12 +7,8 @@ "CVE-2010-2692" ], "details": "Cross-site scripting (XSS) vulnerability in 2daybiz Custom T-Shirt Design Script allows remote attackers to inject arbitrary web script or HTML via a review comment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j347-f3mw-c7pr/GHSA-j347-f3mw-c7pr.json b/advisories/unreviewed/2022/05/GHSA-j347-f3mw-c7pr/GHSA-j347-f3mw-c7pr.json index cfc6ab7ed8e..5c4f8e8995f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j347-f3mw-c7pr/GHSA-j347-f3mw-c7pr.json +++ b/advisories/unreviewed/2022/05/GHSA-j347-f3mw-c7pr/GHSA-j347-f3mw-c7pr.json @@ -7,12 +7,8 @@ "CVE-2010-1984" ], "details": "Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb module 5.x before 5.x-1.5 and 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via the taxonomy term name in a Breadcrumb display.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j366-xcc9-rmr5/GHSA-j366-xcc9-rmr5.json b/advisories/unreviewed/2022/05/GHSA-j366-xcc9-rmr5/GHSA-j366-xcc9-rmr5.json index 1d0e983ae1a..e5e174fa956 100644 --- a/advisories/unreviewed/2022/05/GHSA-j366-xcc9-rmr5/GHSA-j366-xcc9-rmr5.json +++ b/advisories/unreviewed/2022/05/GHSA-j366-xcc9-rmr5/GHSA-j366-xcc9-rmr5.json @@ -7,12 +7,8 @@ "CVE-2010-1878" ], "details": "Directory traversal vulnerability in the OrgChart (com_orgchart) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j3h2-rjr7-w6j2/GHSA-j3h2-rjr7-w6j2.json b/advisories/unreviewed/2022/05/GHSA-j3h2-rjr7-w6j2/GHSA-j3h2-rjr7-w6j2.json index e0af4a98090..79895e10ce6 100644 --- a/advisories/unreviewed/2022/05/GHSA-j3h2-rjr7-w6j2/GHSA-j3h2-rjr7-w6j2.json +++ b/advisories/unreviewed/2022/05/GHSA-j3h2-rjr7-w6j2/GHSA-j3h2-rjr7-w6j2.json @@ -7,12 +7,8 @@ "CVE-2010-2638" ], "details": "Unspecified vulnerability in IBM WebSphere MQ 7.0 before 7.0.1.5 allows remote authenticated users to cause a denial of service (disk consumption) via vectors that trigger an FDC with an RM680004 Probe Id value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j4g2-269c-vp7g/GHSA-j4g2-269c-vp7g.json b/advisories/unreviewed/2022/05/GHSA-j4g2-269c-vp7g/GHSA-j4g2-269c-vp7g.json index bdaf58e31d7..17b8959474d 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4g2-269c-vp7g/GHSA-j4g2-269c-vp7g.json +++ b/advisories/unreviewed/2022/05/GHSA-j4g2-269c-vp7g/GHSA-j4g2-269c-vp7g.json @@ -7,12 +7,8 @@ "CVE-2010-2922" ], "details": "SQL injection vulnerability in default.asp in AKY Blog allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j4jf-g93f-79pj/GHSA-j4jf-g93f-79pj.json b/advisories/unreviewed/2022/05/GHSA-j4jf-g93f-79pj/GHSA-j4jf-g93f-79pj.json index f2e19f48e65..8c592593cbc 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4jf-g93f-79pj/GHSA-j4jf-g93f-79pj.json +++ b/advisories/unreviewed/2022/05/GHSA-j4jf-g93f-79pj/GHSA-j4jf-g93f-79pj.json @@ -7,12 +7,8 @@ "CVE-2010-4155" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) rssfeedURL parameter to manual/caferss/example.php and the sumb parameter to (2) modules/news/archive.php, (3) modules/news/topics.php, and (4) modules/contact/index.php, different vectors than CVE-2007-1965.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j4r6-3gh8-mr87/GHSA-j4r6-3gh8-mr87.json b/advisories/unreviewed/2022/05/GHSA-j4r6-3gh8-mr87/GHSA-j4r6-3gh8-mr87.json index 21ea1c0e67b..63de363779f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4r6-3gh8-mr87/GHSA-j4r6-3gh8-mr87.json +++ b/advisories/unreviewed/2022/05/GHSA-j4r6-3gh8-mr87/GHSA-j4r6-3gh8-mr87.json @@ -7,12 +7,8 @@ "CVE-2010-2123" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web script or HTML via the (1) fullname, (2) address, (3) city, (4) provstate (aka state), (5) phone, or (6) taxid parameter in a stormorganization action to index.php; the (7) name parameter in a stormperson action to index.php; the (8) stepno (aka Step no.) or (9) title parameter in a stormtask action to index.php; the (10) title (aka Project) parameter in a stormticket action to index.php; or (11) unspecified parameters in a stormproject action to index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j8hx-xmv6-rgjh/GHSA-j8hx-xmv6-rgjh.json b/advisories/unreviewed/2022/05/GHSA-j8hx-xmv6-rgjh/GHSA-j8hx-xmv6-rgjh.json index 152e8ee7a50..711817cfabb 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8hx-xmv6-rgjh/GHSA-j8hx-xmv6-rgjh.json +++ b/advisories/unreviewed/2022/05/GHSA-j8hx-xmv6-rgjh/GHSA-j8hx-xmv6-rgjh.json @@ -7,12 +7,8 @@ "CVE-2010-4619" ], "details": "SQL injection vulnerability in profil.php in Mafya Oyun Scrpti (aka Mafia Game Script) allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j8w7-wm55-74qc/GHSA-j8w7-wm55-74qc.json b/advisories/unreviewed/2022/05/GHSA-j8w7-wm55-74qc/GHSA-j8w7-wm55-74qc.json index 45f75dc117b..88c30000363 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8w7-wm55-74qc/GHSA-j8w7-wm55-74qc.json +++ b/advisories/unreviewed/2022/05/GHSA-j8w7-wm55-74qc/GHSA-j8w7-wm55-74qc.json @@ -7,12 +7,8 @@ "CVE-2010-1474" ], "details": "Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j97w-8mcp-pr5v/GHSA-j97w-8mcp-pr5v.json b/advisories/unreviewed/2022/05/GHSA-j97w-8mcp-pr5v/GHSA-j97w-8mcp-pr5v.json index bcdf89e9d01..340a8aff9f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-j97w-8mcp-pr5v/GHSA-j97w-8mcp-pr5v.json +++ b/advisories/unreviewed/2022/05/GHSA-j97w-8mcp-pr5v/GHSA-j97w-8mcp-pr5v.json @@ -7,12 +7,8 @@ "CVE-2010-2058" ], "details": "setup.py in Prewikka 0.9.14 installs prewikka.conf with world-readable permissions, which allows local users to obtain the SQL database password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jcvj-9pfw-q2cg/GHSA-jcvj-9pfw-q2cg.json b/advisories/unreviewed/2022/05/GHSA-jcvj-9pfw-q2cg/GHSA-jcvj-9pfw-q2cg.json index 42976c6f4f9..3cb8f9329f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcvj-9pfw-q2cg/GHSA-jcvj-9pfw-q2cg.json +++ b/advisories/unreviewed/2022/05/GHSA-jcvj-9pfw-q2cg/GHSA-jcvj-9pfw-q2cg.json @@ -7,12 +7,8 @@ "CVE-2010-3491" ], "details": "The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administrator components in TIBCO ActiveMatrix Service Grid before 2.3.1, ActiveMatrix Service Bus before 2.3.1, ActiveMatrix BusinessWorks Service Engine before 5.8.1, and ActiveMatrix Service Performance Manager before 1.3.2 do not properly handle JMX connections, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jf64-vfp6-7x6v/GHSA-jf64-vfp6-7x6v.json b/advisories/unreviewed/2022/05/GHSA-jf64-vfp6-7x6v/GHSA-jf64-vfp6-7x6v.json index 9d4c832bc61..7b6bc65b382 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf64-vfp6-7x6v/GHSA-jf64-vfp6-7x6v.json +++ b/advisories/unreviewed/2022/05/GHSA-jf64-vfp6-7x6v/GHSA-jf64-vfp6-7x6v.json @@ -7,12 +7,8 @@ "CVE-2010-2031" ], "details": "KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel memory via a crafted request to IOCTL 0x830020d4 on the KAVSafe device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jf83-r388-q6j5/GHSA-jf83-r388-q6j5.json b/advisories/unreviewed/2022/05/GHSA-jf83-r388-q6j5/GHSA-jf83-r388-q6j5.json index 4baecbf97c3..18d6ea49929 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf83-r388-q6j5/GHSA-jf83-r388-q6j5.json +++ b/advisories/unreviewed/2022/05/GHSA-jf83-r388-q6j5/GHSA-jf83-r388-q6j5.json @@ -7,12 +7,8 @@ "CVE-2010-2147" ], "details": "Cross-site scripting (XSS) vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the modveh parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jgvj-fxm7-hppf/GHSA-jgvj-fxm7-hppf.json b/advisories/unreviewed/2022/05/GHSA-jgvj-fxm7-hppf/GHSA-jgvj-fxm7-hppf.json index 01f2a40c986..105f4c395b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgvj-fxm7-hppf/GHSA-jgvj-fxm7-hppf.json +++ b/advisories/unreviewed/2022/05/GHSA-jgvj-fxm7-hppf/GHSA-jgvj-fxm7-hppf.json @@ -7,12 +7,8 @@ "CVE-2010-2908" ], "details": "SQL injection vulnerability in the Joomdle (com_joomdle) component 0.24 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the course_id parameter in a detail action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jgw8-64jm-9x2f/GHSA-jgw8-64jm-9x2f.json b/advisories/unreviewed/2022/05/GHSA-jgw8-64jm-9x2f/GHSA-jgw8-64jm-9x2f.json index 3fffcf0cca0..abeb8faf3f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgw8-64jm-9x2f/GHSA-jgw8-64jm-9x2f.json +++ b/advisories/unreviewed/2022/05/GHSA-jgw8-64jm-9x2f/GHSA-jgw8-64jm-9x2f.json @@ -7,12 +7,8 @@ "CVE-2010-2053" ], "details": "emesenelib/ProfileManager.py in emesene before 1.6.2 allows local users to overwrite arbitrary files via a symlink attack on the emsnpic temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jgxf-vg8g-7f9c/GHSA-jgxf-vg8g-7f9c.json b/advisories/unreviewed/2022/05/GHSA-jgxf-vg8g-7f9c/GHSA-jgxf-vg8g-7f9c.json index 23478304024..85466cf4b31 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgxf-vg8g-7f9c/GHSA-jgxf-vg8g-7f9c.json +++ b/advisories/unreviewed/2022/05/GHSA-jgxf-vg8g-7f9c/GHSA-jgxf-vg8g-7f9c.json @@ -7,12 +7,8 @@ "CVE-2010-1976" ], "details": "Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb module 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via the node title in a Breadcrumb display.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jh8v-m7x2-75f6/GHSA-jh8v-m7x2-75f6.json b/advisories/unreviewed/2022/05/GHSA-jh8v-m7x2-75f6/GHSA-jh8v-m7x2-75f6.json index 1e2d2920b4f..728f1ad5e49 100644 --- a/advisories/unreviewed/2022/05/GHSA-jh8v-m7x2-75f6/GHSA-jh8v-m7x2-75f6.json +++ b/advisories/unreviewed/2022/05/GHSA-jh8v-m7x2-75f6/GHSA-jh8v-m7x2-75f6.json @@ -7,12 +7,8 @@ "CVE-2010-3590" ], "details": "Unspecified vulnerability in the Oracle Spatial component in Oracle Database Server 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality and integrity, related to MDSYS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jhwj-rxcc-56mw/GHSA-jhwj-rxcc-56mw.json b/advisories/unreviewed/2022/05/GHSA-jhwj-rxcc-56mw/GHSA-jhwj-rxcc-56mw.json index 54ad6f1c5f3..7a667b89591 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhwj-rxcc-56mw/GHSA-jhwj-rxcc-56mw.json +++ b/advisories/unreviewed/2022/05/GHSA-jhwj-rxcc-56mw/GHSA-jhwj-rxcc-56mw.json @@ -7,12 +7,8 @@ "CVE-2010-4443" ], "details": "Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows local users to affect availability, related to Kernel/NFS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jj8p-vp76-pwxh/GHSA-jj8p-vp76-pwxh.json b/advisories/unreviewed/2022/05/GHSA-jj8p-vp76-pwxh/GHSA-jj8p-vp76-pwxh.json index 67c138cc7e0..d2be8d3e404 100644 --- a/advisories/unreviewed/2022/05/GHSA-jj8p-vp76-pwxh/GHSA-jj8p-vp76-pwxh.json +++ b/advisories/unreviewed/2022/05/GHSA-jj8p-vp76-pwxh/GHSA-jj8p-vp76-pwxh.json @@ -7,12 +7,8 @@ "CVE-2010-1713" ], "details": "SQL injection vulnerability in modules.php in PostNuke 0.764 allows remote attackers to execute arbitrary SQL commands via the sid parameter in a News article modload action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jm6w-xv7f-69rg/GHSA-jm6w-xv7f-69rg.json b/advisories/unreviewed/2022/05/GHSA-jm6w-xv7f-69rg/GHSA-jm6w-xv7f-69rg.json index 6d4d2feb3ac..220554387de 100644 --- a/advisories/unreviewed/2022/05/GHSA-jm6w-xv7f-69rg/GHSA-jm6w-xv7f-69rg.json +++ b/advisories/unreviewed/2022/05/GHSA-jm6w-xv7f-69rg/GHSA-jm6w-xv7f-69rg.json @@ -7,12 +7,8 @@ "CVE-2008-7218" ], "details": "Unspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 before 2.2-RC2; Kronolith H3 2.1 before 2.1.7 and H3 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and 2.2 before 2.2-RC2; Horde Groupware 1.0 before 1.0.3 and 1.1 before 1.1-RC2; and Groupware Webmail Edition 1.0 before 1.0.4 and 1.1 before 1.1-RC2 has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -96,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jmw9-7c66-65cm/GHSA-jmw9-7c66-65cm.json b/advisories/unreviewed/2022/05/GHSA-jmw9-7c66-65cm/GHSA-jmw9-7c66-65cm.json index 878d61b1498..12ad0d5bb64 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmw9-7c66-65cm/GHSA-jmw9-7c66-65cm.json +++ b/advisories/unreviewed/2022/05/GHSA-jmw9-7c66-65cm/GHSA-jmw9-7c66-65cm.json @@ -7,12 +7,8 @@ "CVE-2010-1741" ], "details": "SQL injection vulnerability in request_account.php in Billwerx RC 5.2.2 PL2 allows remote attackers to execute arbitrary SQL commands via the primary_number parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jq6p-4382-pqcc/GHSA-jq6p-4382-pqcc.json b/advisories/unreviewed/2022/05/GHSA-jq6p-4382-pqcc/GHSA-jq6p-4382-pqcc.json index 0a826f24224..ae878cc3ecd 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq6p-4382-pqcc/GHSA-jq6p-4382-pqcc.json +++ b/advisories/unreviewed/2022/05/GHSA-jq6p-4382-pqcc/GHSA-jq6p-4382-pqcc.json @@ -7,12 +7,8 @@ "CVE-2008-7126" ], "details": "Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet with a large string length value to UDP port 14000, which triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jrhc-49g7-pg3c/GHSA-jrhc-49g7-pg3c.json b/advisories/unreviewed/2022/05/GHSA-jrhc-49g7-pg3c/GHSA-jrhc-49g7-pg3c.json index 5aa6450635e..a9c3bb2b01a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrhc-49g7-pg3c/GHSA-jrhc-49g7-pg3c.json +++ b/advisories/unreviewed/2022/05/GHSA-jrhc-49g7-pg3c/GHSA-jrhc-49g7-pg3c.json @@ -7,12 +7,8 @@ "CVE-2010-2466" ], "details": "The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not properly prevent downloading of database backups, which allows remote attackers to obtain sensitive information via requests for full_*.dar files with predictable filenames.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jw3p-6pw3-8hmm/GHSA-jw3p-6pw3-8hmm.json b/advisories/unreviewed/2022/05/GHSA-jw3p-6pw3-8hmm/GHSA-jw3p-6pw3-8hmm.json index 1e402fc49e3..0f5bddb6727 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw3p-6pw3-8hmm/GHSA-jw3p-6pw3-8hmm.json +++ b/advisories/unreviewed/2022/05/GHSA-jw3p-6pw3-8hmm/GHSA-jw3p-6pw3-8hmm.json @@ -7,12 +7,8 @@ "CVE-2010-3926" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Shop.cgi in SGX-SP Final before 11.00 and SGX-SP Final NE before 11.00 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jwh7-cj9w-f3p3/GHSA-jwh7-cj9w-f3p3.json b/advisories/unreviewed/2022/05/GHSA-jwh7-cj9w-f3p3/GHSA-jwh7-cj9w-f3p3.json index aee26c933c4..e8b5186ba8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwh7-cj9w-f3p3/GHSA-jwh7-cj9w-f3p3.json +++ b/advisories/unreviewed/2022/05/GHSA-jwh7-cj9w-f3p3/GHSA-jwh7-cj9w-f3p3.json @@ -7,12 +7,8 @@ "CVE-2008-7144" ], "details": "Multiple unspecified vulnerabilities in RARLAB WinRAR before 3.71 have unknown impact and attack vectors related to crafted (1) ACE, (2) ARJ, (3) BZ2, (4) CAB, (5) GZ, (6) LHA, (7) RAR, (8) TAR, or (9) ZIP files, as demonstrated by the OUSPG PROTOS GENOME test suite for Archive Formats.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jwqf-9f82-j3jg/GHSA-jwqf-9f82-j3jg.json b/advisories/unreviewed/2022/05/GHSA-jwqf-9f82-j3jg/GHSA-jwqf-9f82-j3jg.json index 118dd07b7b8..7b6dbfc2f1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwqf-9f82-j3jg/GHSA-jwqf-9f82-j3jg.json +++ b/advisories/unreviewed/2022/05/GHSA-jwqf-9f82-j3jg/GHSA-jwqf-9f82-j3jg.json @@ -7,12 +7,8 @@ "CVE-2010-3928" ], "details": "Ruby Version Manager (RVM) before 1.2.1 writes file contents to a terminal without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via a crafted file, related to an \"escape sequence injection vulnerability.\" NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jx78-jgwx-p7fv/GHSA-jx78-jgwx-p7fv.json b/advisories/unreviewed/2022/05/GHSA-jx78-jgwx-p7fv/GHSA-jx78-jgwx-p7fv.json index 58d6cefe4e7..eac4f0959f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-jx78-jgwx-p7fv/GHSA-jx78-jgwx-p7fv.json +++ b/advisories/unreviewed/2022/05/GHSA-jx78-jgwx-p7fv/GHSA-jx78-jgwx-p7fv.json @@ -7,12 +7,8 @@ "CVE-2010-2709" ], "details": "Stack-based buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long OvJavaLocale value in a cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jxqf-38mj-cx5m/GHSA-jxqf-38mj-cx5m.json b/advisories/unreviewed/2022/05/GHSA-jxqf-38mj-cx5m/GHSA-jxqf-38mj-cx5m.json index f887d2a1c68..9276fb00c14 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxqf-38mj-cx5m/GHSA-jxqf-38mj-cx5m.json +++ b/advisories/unreviewed/2022/05/GHSA-jxqf-38mj-cx5m/GHSA-jxqf-38mj-cx5m.json @@ -7,12 +7,8 @@ "CVE-2010-2320" ], "details": "bozotic HTTP server (aka bozohttpd) before 20100621 allows remote attackers to list the contents of home directories, and determine the existence of user accounts, via multiple requests for URIs beginning with /~ sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m2g8-857v-hv6m/GHSA-m2g8-857v-hv6m.json b/advisories/unreviewed/2022/05/GHSA-m2g8-857v-hv6m/GHSA-m2g8-857v-hv6m.json index 045ea3ea4ea..e539296c27f 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2g8-857v-hv6m/GHSA-m2g8-857v-hv6m.json +++ b/advisories/unreviewed/2022/05/GHSA-m2g8-857v-hv6m/GHSA-m2g8-857v-hv6m.json @@ -7,12 +7,8 @@ "CVE-2010-2911" ], "details": "SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a viewnews action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m4wr-7q8r-j9w6/GHSA-m4wr-7q8r-j9w6.json b/advisories/unreviewed/2022/05/GHSA-m4wr-7q8r-j9w6/GHSA-m4wr-7q8r-j9w6.json index 8068b9c68ba..85011648ba5 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4wr-7q8r-j9w6/GHSA-m4wr-7q8r-j9w6.json +++ b/advisories/unreviewed/2022/05/GHSA-m4wr-7q8r-j9w6/GHSA-m4wr-7q8r-j9w6.json @@ -7,12 +7,8 @@ "CVE-2010-2845" ], "details": "SQL injection vulnerability in the QuickFAQ (com_quickfaq) component 1.0.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a category action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjch-7g5x-p6j8/GHSA-mjch-7g5x-p6j8.json b/advisories/unreviewed/2022/05/GHSA-mjch-7g5x-p6j8/GHSA-mjch-7g5x-p6j8.json index 632632b6c19..56882dfcce4 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjch-7g5x-p6j8/GHSA-mjch-7g5x-p6j8.json +++ b/advisories/unreviewed/2022/05/GHSA-mjch-7g5x-p6j8/GHSA-mjch-7g5x-p6j8.json @@ -7,12 +7,8 @@ "CVE-2010-4269" ], "details": "SQL injection vulnerability in managechat.php in Collabtive 0.65 allows remote attackers to execute arbitrary SQL commands via the chatstart[USERTOID] cookie in a pull action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjpc-3jv3-gwf3/GHSA-mjpc-3jv3-gwf3.json b/advisories/unreviewed/2022/05/GHSA-mjpc-3jv3-gwf3/GHSA-mjpc-3jv3-gwf3.json index eabd232536b..3c30e1749c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjpc-3jv3-gwf3/GHSA-mjpc-3jv3-gwf3.json +++ b/advisories/unreviewed/2022/05/GHSA-mjpc-3jv3-gwf3/GHSA-mjpc-3jv3-gwf3.json @@ -7,12 +7,8 @@ "CVE-2010-2464" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website and (2) name parameters to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mmvj-pjr9-mgcp/GHSA-mmvj-pjr9-mgcp.json b/advisories/unreviewed/2022/05/GHSA-mmvj-pjr9-mgcp/GHSA-mmvj-pjr9-mgcp.json index e5892b1664b..df1cc1cd95e 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmvj-pjr9-mgcp/GHSA-mmvj-pjr9-mgcp.json +++ b/advisories/unreviewed/2022/05/GHSA-mmvj-pjr9-mgcp/GHSA-mmvj-pjr9-mgcp.json @@ -7,12 +7,8 @@ "CVE-2010-1743" ], "details": "SQL injection vulnerability in projects.php in Scratcher allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mp4f-9pjq-jgc3/GHSA-mp4f-9pjq-jgc3.json b/advisories/unreviewed/2022/05/GHSA-mp4f-9pjq-jgc3/GHSA-mp4f-9pjq-jgc3.json index 29ff70c73d8..1f66530a9da 100644 --- a/advisories/unreviewed/2022/05/GHSA-mp4f-9pjq-jgc3/GHSA-mp4f-9pjq-jgc3.json +++ b/advisories/unreviewed/2022/05/GHSA-mp4f-9pjq-jgc3/GHSA-mp4f-9pjq-jgc3.json @@ -7,12 +7,8 @@ "CVE-2010-2932" ], "details": "Buffer overflow in BarCodeWiz BarCode 3.29 ActiveX control (BarcodeWiz.dll) allows remote attackers to execute arbitrary code via a long argument to the LoadProperties method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mp89-6v8w-j8gv/GHSA-mp89-6v8w-j8gv.json b/advisories/unreviewed/2022/05/GHSA-mp89-6v8w-j8gv/GHSA-mp89-6v8w-j8gv.json index 6a51cfadb8c..58fdf1ddfe8 100644 --- a/advisories/unreviewed/2022/05/GHSA-mp89-6v8w-j8gv/GHSA-mp89-6v8w-j8gv.json +++ b/advisories/unreviewed/2022/05/GHSA-mp89-6v8w-j8gv/GHSA-mp89-6v8w-j8gv.json @@ -7,12 +7,8 @@ "CVE-2010-3444" ], "details": "Buffer overflow in the log2vis_utf8 function in pyfribidi.c in GNU FriBidi 0.19.1, 0.19.2, and possibly other versions, as used in PyFriBidi 0.10.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Arabic UTF-8 string that causes original 2-byte UTF-8 sequences to be transformed into 3-byte sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mqhw-5r33-x99w/GHSA-mqhw-5r33-x99w.json b/advisories/unreviewed/2022/05/GHSA-mqhw-5r33-x99w/GHSA-mqhw-5r33-x99w.json index 6e5414174d9..be9e13b337b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqhw-5r33-x99w/GHSA-mqhw-5r33-x99w.json +++ b/advisories/unreviewed/2022/05/GHSA-mqhw-5r33-x99w/GHSA-mqhw-5r33-x99w.json @@ -7,12 +7,8 @@ "CVE-2010-1475" ], "details": "Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mqqh-4pfq-f7mp/GHSA-mqqh-4pfq-f7mp.json b/advisories/unreviewed/2022/05/GHSA-mqqh-4pfq-f7mp/GHSA-mqqh-4pfq-f7mp.json index 9171b8515a9..54035a2a19f 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqqh-4pfq-f7mp/GHSA-mqqh-4pfq-f7mp.json +++ b/advisories/unreviewed/2022/05/GHSA-mqqh-4pfq-f7mp/GHSA-mqqh-4pfq-f7mp.json @@ -7,12 +7,8 @@ "CVE-2010-3205" ], "details": "PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mr2f-cw7q-5j4f/GHSA-mr2f-cw7q-5j4f.json b/advisories/unreviewed/2022/05/GHSA-mr2f-cw7q-5j4f/GHSA-mr2f-cw7q-5j4f.json index 8459b115726..7962445c4bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-mr2f-cw7q-5j4f/GHSA-mr2f-cw7q-5j4f.json +++ b/advisories/unreviewed/2022/05/GHSA-mr2f-cw7q-5j4f/GHSA-mr2f-cw7q-5j4f.json @@ -7,12 +7,8 @@ "CVE-2010-3421" ], "details": "Cross-site scripting (XSS) vulnerability in AffiliateLogin.asp in ProductCart 3, 4.1 SP1, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the redirectUrl parameter, a different vector than CVE-2004-2174 and CVE-2005-0995. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mr44-mp3p-wc79/GHSA-mr44-mp3p-wc79.json b/advisories/unreviewed/2022/05/GHSA-mr44-mp3p-wc79/GHSA-mr44-mp3p-wc79.json index ecd65c5cbe5..30b1acc7eaf 100644 --- a/advisories/unreviewed/2022/05/GHSA-mr44-mp3p-wc79/GHSA-mr44-mp3p-wc79.json +++ b/advisories/unreviewed/2022/05/GHSA-mr44-mp3p-wc79/GHSA-mr44-mp3p-wc79.json @@ -7,12 +7,8 @@ "CVE-2010-2904" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the System Landscape Directory (SLD) component 6.4 through 7.02 in SAP NetWeaver allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter to testsdic and the (2) helpstring parameter to paramhelp.jsp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mrhj-qvw9-qpwx/GHSA-mrhj-qvw9-qpwx.json b/advisories/unreviewed/2022/05/GHSA-mrhj-qvw9-qpwx/GHSA-mrhj-qvw9-qpwx.json index 4b088c5b90a..d11b066d878 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrhj-qvw9-qpwx/GHSA-mrhj-qvw9-qpwx.json +++ b/advisories/unreviewed/2022/05/GHSA-mrhj-qvw9-qpwx/GHSA-mrhj-qvw9-qpwx.json @@ -7,12 +7,8 @@ "CVE-2010-2043" ], "details": "Cross-site scripting (XSS) vulnerability in Home.aspx in DataTrack System 3.5 and 3.5.8019.4 allows remote attackers to inject arbitrary web script or HTML via the Work_Order_Summary parameter (aka the request summary). NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mrw8-gpwg-9pjg/GHSA-mrw8-gpwg-9pjg.json b/advisories/unreviewed/2022/05/GHSA-mrw8-gpwg-9pjg/GHSA-mrw8-gpwg-9pjg.json index a37c7a48745..b2d1c4b35d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrw8-gpwg-9pjg/GHSA-mrw8-gpwg-9pjg.json +++ b/advisories/unreviewed/2022/05/GHSA-mrw8-gpwg-9pjg/GHSA-mrw8-gpwg-9pjg.json @@ -7,12 +7,8 @@ "CVE-2010-2344" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in odCMS 1.06, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the Page parameter to (1) _main/index.php, (2) _members/index.php, (3) _forum/index.php, (4) _docs/index.php, and (5) _announcements/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mvgf-43cx-7vh6/GHSA-mvgf-43cx-7vh6.json b/advisories/unreviewed/2022/05/GHSA-mvgf-43cx-7vh6/GHSA-mvgf-43cx-7vh6.json index d241b9ede18..a3e68261bae 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvgf-43cx-7vh6/GHSA-mvgf-43cx-7vh6.json +++ b/advisories/unreviewed/2022/05/GHSA-mvgf-43cx-7vh6/GHSA-mvgf-43cx-7vh6.json @@ -7,12 +7,8 @@ "CVE-2010-2010" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via a node title.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mvr4-323r-rh68/GHSA-mvr4-323r-rh68.json b/advisories/unreviewed/2022/05/GHSA-mvr4-323r-rh68/GHSA-mvr4-323r-rh68.json index 5c565e7056d..7a86447eefa 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvr4-323r-rh68/GHSA-mvr4-323r-rh68.json +++ b/advisories/unreviewed/2022/05/GHSA-mvr4-323r-rh68/GHSA-mvr4-323r-rh68.json @@ -7,12 +7,8 @@ "CVE-2010-4106" ], "details": "Cross-site request forgery (CSRF) vulnerability in HP Insight Control for Linux before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mx9q-gcm7-q3r8/GHSA-mx9q-gcm7-q3r8.json b/advisories/unreviewed/2022/05/GHSA-mx9q-gcm7-q3r8/GHSA-mx9q-gcm7-q3r8.json index 997dc82964a..eb617d2811d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx9q-gcm7-q3r8/GHSA-mx9q-gcm7-q3r8.json +++ b/advisories/unreviewed/2022/05/GHSA-mx9q-gcm7-q3r8/GHSA-mx9q-gcm7-q3r8.json @@ -7,12 +7,8 @@ "CVE-2010-2698" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Sijio Community Software allow remote authenticated users to inject arbitrary web script or HTML via the title parameter when (1) editing a new blog, (2) adding an album, or (3) editing an album. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p2fc-fp67-8xv9/GHSA-p2fc-fp67-8xv9.json b/advisories/unreviewed/2022/05/GHSA-p2fc-fp67-8xv9/GHSA-p2fc-fp67-8xv9.json index b4501023d16..d05578e1f21 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2fc-fp67-8xv9/GHSA-p2fc-fp67-8xv9.json +++ b/advisories/unreviewed/2022/05/GHSA-p2fc-fp67-8xv9/GHSA-p2fc-fp67-8xv9.json @@ -7,12 +7,8 @@ "CVE-2010-4324" ], "details": "Cross-site scripting (XSS) vulnerability in the Approval Form in the User Application in the Roles Based Provisioning Module 3.7.0 before 370D in Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p2ff-59f4-vxff/GHSA-p2ff-59f4-vxff.json b/advisories/unreviewed/2022/05/GHSA-p2ff-59f4-vxff/GHSA-p2ff-59f4-vxff.json index debaccbf543..720503664d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2ff-59f4-vxff/GHSA-p2ff-59f4-vxff.json +++ b/advisories/unreviewed/2022/05/GHSA-p2ff-59f4-vxff/GHSA-p2ff-59f4-vxff.json @@ -7,12 +7,8 @@ "CVE-2010-4103" ], "details": "Unspecified vulnerability in HP Insight Managed System Setup Wizard before 6.2 allows remote attackers to read arbitrary files via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p2fg-pc9g-5cq8/GHSA-p2fg-pc9g-5cq8.json b/advisories/unreviewed/2022/05/GHSA-p2fg-pc9g-5cq8/GHSA-p2fg-pc9g-5cq8.json index 78f7669f1bc..5cc24455314 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2fg-pc9g-5cq8/GHSA-p2fg-pc9g-5cq8.json +++ b/advisories/unreviewed/2022/05/GHSA-p2fg-pc9g-5cq8/GHSA-p2fg-pc9g-5cq8.json @@ -7,12 +7,8 @@ "CVE-2010-4274" ], "details": "reset_diragent_keys in the Common agent in IBM Systems Director 6.2.0 has 754 permissions, which allows local users to gain privileges by leveraging system group membership.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p4cc-ww2x-83fj/GHSA-p4cc-ww2x-83fj.json b/advisories/unreviewed/2022/05/GHSA-p4cc-ww2x-83fj/GHSA-p4cc-ww2x-83fj.json index e3ea6ca5f45..a156f2854d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4cc-ww2x-83fj/GHSA-p4cc-ww2x-83fj.json +++ b/advisories/unreviewed/2022/05/GHSA-p4cc-ww2x-83fj/GHSA-p4cc-ww2x-83fj.json @@ -7,12 +7,8 @@ "CVE-2010-2126" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Snipe Gallery 3.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the cfg_admin_path parameter to (1) index.php, (2) view.php, (3) image.php, (4) search.php, (5) admin/index.php, (6) admin/gallery/index.php, (7) admin/gallery/view.php, (8) admin/gallery/gallery.php, (9) admin/gallery/image.php, and (10) admin/gallery/crop.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p4pr-p87r-mxm8/GHSA-p4pr-p87r-mxm8.json b/advisories/unreviewed/2022/05/GHSA-p4pr-p87r-mxm8/GHSA-p4pr-p87r-mxm8.json index 5668e5a6268..8a6a33b9218 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4pr-p87r-mxm8/GHSA-p4pr-p87r-mxm8.json +++ b/advisories/unreviewed/2022/05/GHSA-p4pr-p87r-mxm8/GHSA-p4pr-p87r-mxm8.json @@ -7,12 +7,8 @@ "CVE-2010-2134" ], "details": "Multiple SQL injection vulnerabilities in login.php in Project Man 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p4wf-p7fg-ghq6/GHSA-p4wf-p7fg-ghq6.json b/advisories/unreviewed/2022/05/GHSA-p4wf-p7fg-ghq6/GHSA-p4wf-p7fg-ghq6.json index 948a68fa2da..1367d20b480 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4wf-p7fg-ghq6/GHSA-p4wf-p7fg-ghq6.json +++ b/advisories/unreviewed/2022/05/GHSA-p4wf-p7fg-ghq6/GHSA-p4wf-p7fg-ghq6.json @@ -7,12 +7,8 @@ "CVE-2010-2635" ], "details": "SQL injection vulnerability in IBM WebSphere Commerce 6.0 before 6.0.0.10 allows remote authenticated users to execute arbitrary SQL commands via unspecified parameters to \"Commerce Organization Admin Console JavaServer pages.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p5h3-4856-8937/GHSA-p5h3-4856-8937.json b/advisories/unreviewed/2022/05/GHSA-p5h3-4856-8937/GHSA-p5h3-4856-8937.json index a2043002dd1..bc32be9de5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5h3-4856-8937/GHSA-p5h3-4856-8937.json +++ b/advisories/unreviewed/2022/05/GHSA-p5h3-4856-8937/GHSA-p5h3-4856-8937.json @@ -7,12 +7,8 @@ "CVE-2010-2691" ], "details": "Multiple SQL injection vulnerabilities in 2daybiz Custom T-Shirt Design Script allow remote attackers to execute arbitrary SQL commands via the (1) sbid parameter to products_details.php, (2) pid parameter to products/products.php, and (3) designid parameter to designview.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p5q9-c64v-86cv/GHSA-p5q9-c64v-86cv.json b/advisories/unreviewed/2022/05/GHSA-p5q9-c64v-86cv/GHSA-p5q9-c64v-86cv.json index be2b5a0d904..e6d6225675e 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5q9-c64v-86cv/GHSA-p5q9-c64v-86cv.json +++ b/advisories/unreviewed/2022/05/GHSA-p5q9-c64v-86cv/GHSA-p5q9-c64v-86cv.json @@ -7,12 +7,8 @@ "CVE-2010-3592" ], "details": "Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect integrity and availability via unknown vectors related to Internal Operations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p5ww-ppr2-h64x/GHSA-p5ww-ppr2-h64x.json b/advisories/unreviewed/2022/05/GHSA-p5ww-ppr2-h64x/GHSA-p5ww-ppr2-h64x.json index 1d75ba32d43..6b4a9e4fb10 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5ww-ppr2-h64x/GHSA-p5ww-ppr2-h64x.json +++ b/advisories/unreviewed/2022/05/GHSA-p5ww-ppr2-h64x/GHSA-p5ww-ppr2-h64x.json @@ -7,12 +7,8 @@ "CVE-2010-2190" ], "details": "The (1) trim, (2) ltrim, (3) rtrim, and (4) substr_replace functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p6fw-jhvr-w5xg/GHSA-p6fw-jhvr-w5xg.json b/advisories/unreviewed/2022/05/GHSA-p6fw-jhvr-w5xg/GHSA-p6fw-jhvr-w5xg.json index ee67277d6e1..3694696290f 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6fw-jhvr-w5xg/GHSA-p6fw-jhvr-w5xg.json +++ b/advisories/unreviewed/2022/05/GHSA-p6fw-jhvr-w5xg/GHSA-p6fw-jhvr-w5xg.json @@ -7,12 +7,8 @@ "CVE-2010-3467" ], "details": "SQL injection vulnerability in modules/sections/index.php in E-Xoopport Samsara 3.1 and earlier, when the Tutorial module is enabled, allows remote attackers to execute arbitrary SQL commands via the secid parameter in a listarticles action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p6p9-cj4h-xmqp/GHSA-p6p9-cj4h-xmqp.json b/advisories/unreviewed/2022/05/GHSA-p6p9-cj4h-xmqp/GHSA-p6p9-cj4h-xmqp.json index 3545eea6eef..113f5c97c7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6p9-cj4h-xmqp/GHSA-p6p9-cj4h-xmqp.json +++ b/advisories/unreviewed/2022/05/GHSA-p6p9-cj4h-xmqp/GHSA-p6p9-cj4h-xmqp.json @@ -7,12 +7,8 @@ "CVE-2008-7164" ], "details": "Multiple unspecified vulnerabilities in Shareaza before 2.3.1.0 have unknown impact and attack vectors related to \"very important security fixes,\" possibly involving update notifications and a domain that is no longer controlled by the vendor.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p74c-gqrv-v859/GHSA-p74c-gqrv-v859.json b/advisories/unreviewed/2022/05/GHSA-p74c-gqrv-v859/GHSA-p74c-gqrv-v859.json index a1e6444af75..87afb857469 100644 --- a/advisories/unreviewed/2022/05/GHSA-p74c-gqrv-v859/GHSA-p74c-gqrv-v859.json +++ b/advisories/unreviewed/2022/05/GHSA-p74c-gqrv-v859/GHSA-p74c-gqrv-v859.json @@ -7,12 +7,8 @@ "CVE-2010-2307" ], "details": "Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) \"//\" (multiple leading slash), (2) ../ (dot dot) sequences, and encoded dot dot sequences in a URL request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p7c2-7f6q-f6m2/GHSA-p7c2-7f6q-f6m2.json b/advisories/unreviewed/2022/05/GHSA-p7c2-7f6q-f6m2/GHSA-p7c2-7f6q-f6m2.json index f3118b77fc8..ac1e0793f28 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7c2-7f6q-f6m2/GHSA-p7c2-7f6q-f6m2.json +++ b/advisories/unreviewed/2022/05/GHSA-p7c2-7f6q-f6m2/GHSA-p7c2-7f6q-f6m2.json @@ -7,12 +7,8 @@ "CVE-2010-3912" ], "details": "The supportconfig script in supportutils in SUSE Linux Enterprise 11 SP1 and 10 SP3 does not \"disguise passwords\" in configuration files, which has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p8mc-767v-qwwh/GHSA-p8mc-767v-qwwh.json b/advisories/unreviewed/2022/05/GHSA-p8mc-767v-qwwh/GHSA-p8mc-767v-qwwh.json index cd0529f5046..e915d1a9c3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8mc-767v-qwwh/GHSA-p8mc-767v-qwwh.json +++ b/advisories/unreviewed/2022/05/GHSA-p8mc-767v-qwwh/GHSA-p8mc-767v-qwwh.json @@ -7,12 +7,8 @@ "CVE-2010-4445" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft and JDEdwards Suite 9.0 Bundle #14 and 9.1 Bundle #4 allows remote authenticated users to affect confidentiality via unknown vectors related to Talent Acquisition Manager.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p94m-p5xc-rjpp/GHSA-p94m-p5xc-rjpp.json b/advisories/unreviewed/2022/05/GHSA-p94m-p5xc-rjpp/GHSA-p94m-p5xc-rjpp.json index e416f4489b1..b0cfc0ad338 100644 --- a/advisories/unreviewed/2022/05/GHSA-p94m-p5xc-rjpp/GHSA-p94m-p5xc-rjpp.json +++ b/advisories/unreviewed/2022/05/GHSA-p94m-p5xc-rjpp/GHSA-p94m-p5xc-rjpp.json @@ -7,12 +7,8 @@ "CVE-2010-3618" ], "details": "PGP Desktop 10.0.x before 10.0.3 SP2 and 10.1.0 before 10.1.0 SP1 does not properly implement the \"Decrypt/Verify File via Right-Click\" functionality for multi-packet OpenPGP messages that represent multi-message input, which allows remote attackers to spoof signed data by concatenating an additional message to the end of a legitimately signed message, related to a \"piggy-back\" or \"unsigned data injection\" issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pc8j-pfcg-w3f2/GHSA-pc8j-pfcg-w3f2.json b/advisories/unreviewed/2022/05/GHSA-pc8j-pfcg-w3f2/GHSA-pc8j-pfcg-w3f2.json index 79b23fc094e..c474a914b75 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc8j-pfcg-w3f2/GHSA-pc8j-pfcg-w3f2.json +++ b/advisories/unreviewed/2022/05/GHSA-pc8j-pfcg-w3f2/GHSA-pc8j-pfcg-w3f2.json @@ -7,12 +7,8 @@ "CVE-2008-7125" ], "details": "pphoto in Ariadne before 2.6 allows remote authenticated users with certain privileges to execute arbitrary shell commands via vectors related to PINP programs and the annotate command. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pcvq-3c52-8x6w/GHSA-pcvq-3c52-8x6w.json b/advisories/unreviewed/2022/05/GHSA-pcvq-3c52-8x6w/GHSA-pcvq-3c52-8x6w.json index eb25d0e1156..7c846156ec3 100644 --- a/advisories/unreviewed/2022/05/GHSA-pcvq-3c52-8x6w/GHSA-pcvq-3c52-8x6w.json +++ b/advisories/unreviewed/2022/05/GHSA-pcvq-3c52-8x6w/GHSA-pcvq-3c52-8x6w.json @@ -7,12 +7,8 @@ "CVE-2010-4623" ], "details": "WebSEAL in IBM Tivoli Access Manager for e-business 6.1.1 before 6.1.1-TIV-AWS-FP0001 allows remote authenticated users to cause a denial of service (worker thread consumption) via shift-reload actions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pj28-mx3m-9668/GHSA-pj28-mx3m-9668.json b/advisories/unreviewed/2022/05/GHSA-pj28-mx3m-9668/GHSA-pj28-mx3m-9668.json index 27721c4511e..c33e34fb4ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj28-mx3m-9668/GHSA-pj28-mx3m-9668.json +++ b/advisories/unreviewed/2022/05/GHSA-pj28-mx3m-9668/GHSA-pj28-mx3m-9668.json @@ -7,12 +7,8 @@ "CVE-2010-2489" ], "details": "Buffer overflow in Ruby 1.9.x before 1.9.1-p429 on Windows might allow local users to gain privileges via a crafted ARGF.inplace_mode value that is not properly handled when constructing the filenames of the backup files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pm2h-5fwq-4g6q/GHSA-pm2h-5fwq-4g6q.json b/advisories/unreviewed/2022/05/GHSA-pm2h-5fwq-4g6q/GHSA-pm2h-5fwq-4g6q.json index 0f19a7da28a..5885043cc0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-pm2h-5fwq-4g6q/GHSA-pm2h-5fwq-4g6q.json +++ b/advisories/unreviewed/2022/05/GHSA-pm2h-5fwq-4g6q/GHSA-pm2h-5fwq-4g6q.json @@ -7,12 +7,8 @@ "CVE-2010-2716" ], "details": "Multiple SQL injection vulnerabilities in PsNews 1.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) ndetail.php and (2) print.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pp9j-974q-cm92/GHSA-pp9j-974q-cm92.json b/advisories/unreviewed/2022/05/GHSA-pp9j-974q-cm92/GHSA-pp9j-974q-cm92.json index f6b34718a8a..f7f490f25da 100644 --- a/advisories/unreviewed/2022/05/GHSA-pp9j-974q-cm92/GHSA-pp9j-974q-cm92.json +++ b/advisories/unreviewed/2022/05/GHSA-pp9j-974q-cm92/GHSA-pp9j-974q-cm92.json @@ -7,12 +7,8 @@ "CVE-2010-4015" ], "details": "Buffer overflow in the gettoken function in contrib/intarray/_int_bool.c in the intarray array module in PostgreSQL 9.0.x before 9.0.3, 8.4.x before 8.4.7, 8.3.x before 8.3.14, and 8.2.x before 8.2.20 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via integers with a large number of digits to unspecified functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -136,9 +132,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pqg3-798q-wvr8/GHSA-pqg3-798q-wvr8.json b/advisories/unreviewed/2022/05/GHSA-pqg3-798q-wvr8/GHSA-pqg3-798q-wvr8.json index 621f0858197..c4af3b5fdc0 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqg3-798q-wvr8/GHSA-pqg3-798q-wvr8.json +++ b/advisories/unreviewed/2022/05/GHSA-pqg3-798q-wvr8/GHSA-pqg3-798q-wvr8.json @@ -7,12 +7,8 @@ "CVE-2010-2853" ], "details": "SQL injection vulnerability in flashPlayer/playVideo.php in iScripts VisualCaster allows remote attackers to execute arbitrary SQL commands via the product_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-prgm-px5q-c9h6/GHSA-prgm-px5q-c9h6.json b/advisories/unreviewed/2022/05/GHSA-prgm-px5q-c9h6/GHSA-prgm-px5q-c9h6.json index 8e23687ca58..58fe94f1b96 100644 --- a/advisories/unreviewed/2022/05/GHSA-prgm-px5q-c9h6/GHSA-prgm-px5q-c9h6.json +++ b/advisories/unreviewed/2022/05/GHSA-prgm-px5q-c9h6/GHSA-prgm-px5q-c9h6.json @@ -7,12 +7,8 @@ "CVE-2010-4186" ], "details": "SQL injection vulnerability in process.asp in OnlineTechTools Online Work Order System (OWOS) Professional Edition 2.10 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q2jx-hgv6-67hh/GHSA-q2jx-hgv6-67hh.json b/advisories/unreviewed/2022/05/GHSA-q2jx-hgv6-67hh/GHSA-q2jx-hgv6-67hh.json index e9ba2c9be9c..219a8f951ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2jx-hgv6-67hh/GHSA-q2jx-hgv6-67hh.json +++ b/advisories/unreviewed/2022/05/GHSA-q2jx-hgv6-67hh/GHSA-q2jx-hgv6-67hh.json @@ -7,12 +7,8 @@ "CVE-2010-1917" ], "details": "Stack consumption vulnerability in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (PHP crash) via a crafted first argument to the fnmatch function, as demonstrated using a long string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q57r-8v39-g8f8/GHSA-q57r-8v39-g8f8.json b/advisories/unreviewed/2022/05/GHSA-q57r-8v39-g8f8/GHSA-q57r-8v39-g8f8.json index 6c84523f685..a8f94a8a357 100644 --- a/advisories/unreviewed/2022/05/GHSA-q57r-8v39-g8f8/GHSA-q57r-8v39-g8f8.json +++ b/advisories/unreviewed/2022/05/GHSA-q57r-8v39-g8f8/GHSA-q57r-8v39-g8f8.json @@ -7,12 +7,8 @@ "CVE-2010-2260" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Gambit Design Bandwidth Meter, 0.72 and possibly 1.2, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) view_by_name.php or (2) view_by_ip.php in admin/. NOTE: some sources report that the affected product is ShaPlus Bandwidth Meter, but this is incorrect.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q5j9-7x8j-95mg/GHSA-q5j9-7x8j-95mg.json b/advisories/unreviewed/2022/05/GHSA-q5j9-7x8j-95mg/GHSA-q5j9-7x8j-95mg.json index e0f2e7b67f3..d07476a787f 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5j9-7x8j-95mg/GHSA-q5j9-7x8j-95mg.json +++ b/advisories/unreviewed/2022/05/GHSA-q5j9-7x8j-95mg/GHSA-q5j9-7x8j-95mg.json @@ -7,12 +7,8 @@ "CVE-2010-3465" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in XSE Shopping Cart 1.5.2.1 and 1.5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to Default.aspx and the (2) type parameter to SearchResults.aspx.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q62m-m86m-99hc/GHSA-q62m-m86m-99hc.json b/advisories/unreviewed/2022/05/GHSA-q62m-m86m-99hc/GHSA-q62m-m86m-99hc.json index 1ba99fa5cfc..d144c5f831a 100644 --- a/advisories/unreviewed/2022/05/GHSA-q62m-m86m-99hc/GHSA-q62m-m86m-99hc.json +++ b/advisories/unreviewed/2022/05/GHSA-q62m-m86m-99hc/GHSA-q62m-m86m-99hc.json @@ -7,12 +7,8 @@ "CVE-2010-4053" ], "details": "Stack-based buffer overflow in an unspecified logging function in oninit.exe in IBM Informix Dynamic Server (IDS) 11.10 before 11.10.xC2W2 and 11.50 before 11.50.xC1 allows remote authenticated users to execute arbitrary code via a crafted EXPLAIN directive, aka idsdb00154125 and idsdb00154243.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q76f-hqqv-cqmv/GHSA-q76f-hqqv-cqmv.json b/advisories/unreviewed/2022/05/GHSA-q76f-hqqv-cqmv/GHSA-q76f-hqqv-cqmv.json index 6c80b2feb36..a76f465c68a 100644 --- a/advisories/unreviewed/2022/05/GHSA-q76f-hqqv-cqmv/GHSA-q76f-hqqv-cqmv.json +++ b/advisories/unreviewed/2022/05/GHSA-q76f-hqqv-cqmv/GHSA-q76f-hqqv-cqmv.json @@ -7,12 +7,8 @@ "CVE-2010-2195" ], "details": "bozotic HTTP server (aka bozohttpd) 20090522 through 20100512 allows attackers to cause a denial of service via vectors related to a \"wrong code generation interaction with GCC.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q9p3-383j-jvqg/GHSA-q9p3-383j-jvqg.json b/advisories/unreviewed/2022/05/GHSA-q9p3-383j-jvqg/GHSA-q9p3-383j-jvqg.json index 6d0ebdeb287..12ba718a438 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9p3-383j-jvqg/GHSA-q9p3-383j-jvqg.json +++ b/advisories/unreviewed/2022/05/GHSA-q9p3-383j-jvqg/GHSA-q9p3-383j-jvqg.json @@ -7,12 +7,8 @@ "CVE-2010-4175" ], "details": "Integer overflow in the rds_cmsg_rdma_args function (net/rds/rdma.c) in Linux kernel 2.6.35 allows local users to cause a denial of service (crash) and possibly trigger memory corruption via a crafted Reliable Datagram Sockets (RDS) request, a different vulnerability than CVE-2010-3865.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qfqv-cr9x-27pg/GHSA-qfqv-cr9x-27pg.json b/advisories/unreviewed/2022/05/GHSA-qfqv-cr9x-27pg/GHSA-qfqv-cr9x-27pg.json index 0f26afde81d..be1c86af5e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfqv-cr9x-27pg/GHSA-qfqv-cr9x-27pg.json +++ b/advisories/unreviewed/2022/05/GHSA-qfqv-cr9x-27pg/GHSA-qfqv-cr9x-27pg.json @@ -7,12 +7,8 @@ "CVE-2010-4341" ], "details": "The pam_parse_in_data_v2 function in src/responder/pam/pamsrv_cmd.c in the PAM responder in SSSD 1.5.0, 1.4.x, and 1.3 allows local users to cause a denial of service (infinite loop, crash, and login prevention) via a crafted packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qg27-wh8f-4pvh/GHSA-qg27-wh8f-4pvh.json b/advisories/unreviewed/2022/05/GHSA-qg27-wh8f-4pvh/GHSA-qg27-wh8f-4pvh.json index 53e8181eae6..0cfa47ac06b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg27-wh8f-4pvh/GHSA-qg27-wh8f-4pvh.json +++ b/advisories/unreviewed/2022/05/GHSA-qg27-wh8f-4pvh/GHSA-qg27-wh8f-4pvh.json @@ -7,12 +7,8 @@ "CVE-2010-2305" ], "details": "Buffer overflow in an ActiveX control in SSHelper.dll for Symantec Sygate Personal Firewall 5.6 build 2808 allows remote attackers to execute arbitrary code via a long third argument to the SetRegString method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qgqh-rgf4-cmxj/GHSA-qgqh-rgf4-cmxj.json b/advisories/unreviewed/2022/05/GHSA-qgqh-rgf4-cmxj/GHSA-qgqh-rgf4-cmxj.json index 18ce82d4e8f..842ff4eb123 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgqh-rgf4-cmxj/GHSA-qgqh-rgf4-cmxj.json +++ b/advisories/unreviewed/2022/05/GHSA-qgqh-rgf4-cmxj/GHSA-qgqh-rgf4-cmxj.json @@ -7,12 +7,8 @@ "CVE-2008-7135" ], "details": "toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the IsChecked method, a different vector than CVE-2008-7136.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qhrg-rwr6-hrvj/GHSA-qhrg-rwr6-hrvj.json b/advisories/unreviewed/2022/05/GHSA-qhrg-rwr6-hrvj/GHSA-qhrg-rwr6-hrvj.json index 22b328ffb6d..7a7fa777a5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qhrg-rwr6-hrvj/GHSA-qhrg-rwr6-hrvj.json +++ b/advisories/unreviewed/2022/05/GHSA-qhrg-rwr6-hrvj/GHSA-qhrg-rwr6-hrvj.json @@ -7,12 +7,8 @@ "CVE-2010-2715" ], "details": "Cross-site scripting (XSS) vulnerability in photos/index.php in TCW PHP Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the album parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qhwr-8w6q-ccrf/GHSA-qhwr-8w6q-ccrf.json b/advisories/unreviewed/2022/05/GHSA-qhwr-8w6q-ccrf/GHSA-qhwr-8w6q-ccrf.json index 218fef691fd..dc3d92a9939 100644 --- a/advisories/unreviewed/2022/05/GHSA-qhwr-8w6q-ccrf/GHSA-qhwr-8w6q-ccrf.json +++ b/advisories/unreviewed/2022/05/GHSA-qhwr-8w6q-ccrf/GHSA-qhwr-8w6q-ccrf.json @@ -7,12 +7,8 @@ "CVE-2010-2920" ], "details": "Directory traversal vulnerability in the Foobla Suggestions (com_foobla_suggestions) component 1.5.1.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qj32-xx7f-66p6/GHSA-qj32-xx7f-66p6.json b/advisories/unreviewed/2022/05/GHSA-qj32-xx7f-66p6/GHSA-qj32-xx7f-66p6.json index 9364f6cf587..841dca563da 100644 --- a/advisories/unreviewed/2022/05/GHSA-qj32-xx7f-66p6/GHSA-qj32-xx7f-66p6.json +++ b/advisories/unreviewed/2022/05/GHSA-qj32-xx7f-66p6/GHSA-qj32-xx7f-66p6.json @@ -7,12 +7,8 @@ "CVE-2010-4440" ], "details": "Unspecified vulnerability in Oracle 10 and 11 Express allows local users to affect availability via unknown vectors related to the Kernel.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qjw3-gg35-j8hf/GHSA-qjw3-gg35-j8hf.json b/advisories/unreviewed/2022/05/GHSA-qjw3-gg35-j8hf/GHSA-qjw3-gg35-j8hf.json index 7e8e5777689..3cd77cc5e1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjw3-gg35-j8hf/GHSA-qjw3-gg35-j8hf.json +++ b/advisories/unreviewed/2022/05/GHSA-qjw3-gg35-j8hf/GHSA-qjw3-gg35-j8hf.json @@ -7,12 +7,8 @@ "CVE-2010-1928" ], "details": "Directory traversal vulnerability in scr/soustab.php in openMairie openPlanning 1.00, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qmhf-38fc-rg36/GHSA-qmhf-38fc-rg36.json b/advisories/unreviewed/2022/05/GHSA-qmhf-38fc-rg36/GHSA-qmhf-38fc-rg36.json index 4bdfe6c2eea..522d0fc1b40 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmhf-38fc-rg36/GHSA-qmhf-38fc-rg36.json +++ b/advisories/unreviewed/2022/05/GHSA-qmhf-38fc-rg36/GHSA-qmhf-38fc-rg36.json @@ -7,12 +7,8 @@ "CVE-2013-6371" ], "details": "The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qq8x-fmp6-3285/GHSA-qq8x-fmp6-3285.json b/advisories/unreviewed/2022/05/GHSA-qq8x-fmp6-3285/GHSA-qq8x-fmp6-3285.json index a8af5515fae..0216d6331f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-qq8x-fmp6-3285/GHSA-qq8x-fmp6-3285.json +++ b/advisories/unreviewed/2022/05/GHSA-qq8x-fmp6-3285/GHSA-qq8x-fmp6-3285.json @@ -7,12 +7,8 @@ "CVE-2010-2433" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in content/internalError.jsp in IBM WebSphere ILOG JRules 6.7 allow remote attackers to inject arbitrary web script or HTML via an RTS URL to (1) explore/explore.jsp, (2) compose/compose.jsp, or (3) home.jsp in faces/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qqq7-ff89-5hxp/GHSA-qqq7-ff89-5hxp.json b/advisories/unreviewed/2022/05/GHSA-qqq7-ff89-5hxp/GHSA-qqq7-ff89-5hxp.json index 68e826b7c5f..5410684ddef 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqq7-ff89-5hxp/GHSA-qqq7-ff89-5hxp.json +++ b/advisories/unreviewed/2022/05/GHSA-qqq7-ff89-5hxp/GHSA-qqq7-ff89-5hxp.json @@ -7,12 +7,8 @@ "CVE-2010-3505" ], "details": "Unspecified vulnerability in the Agile Core component in Oracle Supply Chain Products Suite 9.3.0.2 and 9.3.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Folders, Files & Attachments, a different vulnerability than CVE-2010-4429.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qrfq-jhxg-f23h/GHSA-qrfq-jhxg-f23h.json b/advisories/unreviewed/2022/05/GHSA-qrfq-jhxg-f23h/GHSA-qrfq-jhxg-f23h.json index a9bf1c9d7af..959450ca28d 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrfq-jhxg-f23h/GHSA-qrfq-jhxg-f23h.json +++ b/advisories/unreviewed/2022/05/GHSA-qrfq-jhxg-f23h/GHSA-qrfq-jhxg-f23h.json @@ -7,12 +7,8 @@ "CVE-2010-2589" ], "details": "Integer overflow in the dirapi.dll module in Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qrp2-qxjh-p3w7/GHSA-qrp2-qxjh-p3w7.json b/advisories/unreviewed/2022/05/GHSA-qrp2-qxjh-p3w7/GHSA-qrp2-qxjh-p3w7.json index a2492ade3d2..23421000e60 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrp2-qxjh-p3w7/GHSA-qrp2-qxjh-p3w7.json +++ b/advisories/unreviewed/2022/05/GHSA-qrp2-qxjh-p3w7/GHSA-qrp2-qxjh-p3w7.json @@ -7,12 +7,8 @@ "CVE-2010-4568" ], "details": "Bugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x before 3.6.4; and 4.0.x before 4.0rc2 does not properly generate random values for cookies and tokens, which allows remote attackers to obtain access to arbitrary accounts via unspecified vectors, related to an insufficient number of calls to the srand function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qrxr-jvmh-w76v/GHSA-qrxr-jvmh-w76v.json b/advisories/unreviewed/2022/05/GHSA-qrxr-jvmh-w76v/GHSA-qrxr-jvmh-w76v.json index fbf83cf63fc..3c330a987dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrxr-jvmh-w76v/GHSA-qrxr-jvmh-w76v.json +++ b/advisories/unreviewed/2022/05/GHSA-qrxr-jvmh-w76v/GHSA-qrxr-jvmh-w76v.json @@ -7,12 +7,8 @@ "CVE-2010-1942" ], "details": "Unspecified vulnerability in the Servlet service in Fujitsu Limited Interstage Application Server 3.0 through 7.0, as used in Interstage Application Framework Suite, Interstage Business Application Server, and Interstage List Manager, allows attackers to obtain sensitive information or force invalid requests to be processed via unknown vectors related to unspecified invalid requests and settings on the load balancing device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qw4m-f928-rmxw/GHSA-qw4m-f928-rmxw.json b/advisories/unreviewed/2022/05/GHSA-qw4m-f928-rmxw/GHSA-qw4m-f928-rmxw.json index 01750314eb4..a0937dcd2d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw4m-f928-rmxw/GHSA-qw4m-f928-rmxw.json +++ b/advisories/unreviewed/2022/05/GHSA-qw4m-f928-rmxw/GHSA-qw4m-f928-rmxw.json @@ -7,12 +7,8 @@ "CVE-2010-1719" ], "details": "Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwhv-gv46-cghm/GHSA-qwhv-gv46-cghm.json b/advisories/unreviewed/2022/05/GHSA-qwhv-gv46-cghm/GHSA-qwhv-gv46-cghm.json index 0e1e2f2fd38..c00c65f512e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwhv-gv46-cghm/GHSA-qwhv-gv46-cghm.json +++ b/advisories/unreviewed/2022/05/GHSA-qwhv-gv46-cghm/GHSA-qwhv-gv46-cghm.json @@ -7,12 +7,8 @@ "CVE-2010-2029" ], "details": "Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the unique ID of the user's cell phone.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qwr4-pw8f-65fh/GHSA-qwr4-pw8f-65fh.json b/advisories/unreviewed/2022/05/GHSA-qwr4-pw8f-65fh/GHSA-qwr4-pw8f-65fh.json index 310fb9d66f4..3a6d6d3622a 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwr4-pw8f-65fh/GHSA-qwr4-pw8f-65fh.json +++ b/advisories/unreviewed/2022/05/GHSA-qwr4-pw8f-65fh/GHSA-qwr4-pw8f-65fh.json @@ -7,12 +7,8 @@ "CVE-2010-1877" ], "details": "SQL injection vulnerability in the JTM Reseller (com_jtm) component 1.9 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the author parameter in a search action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwwx-r45m-fccp/GHSA-qwwx-r45m-fccp.json b/advisories/unreviewed/2022/05/GHSA-qwwx-r45m-fccp/GHSA-qwwx-r45m-fccp.json index 7523787b493..32812ab76ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwwx-r45m-fccp/GHSA-qwwx-r45m-fccp.json +++ b/advisories/unreviewed/2022/05/GHSA-qwwx-r45m-fccp/GHSA-qwwx-r45m-fccp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -71,9 +69,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qxp2-gg8v-38j7/GHSA-qxp2-gg8v-38j7.json b/advisories/unreviewed/2022/05/GHSA-qxp2-gg8v-38j7/GHSA-qxp2-gg8v-38j7.json index 181bc6248f3..a5f7f47024c 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxp2-gg8v-38j7/GHSA-qxp2-gg8v-38j7.json +++ b/advisories/unreviewed/2022/05/GHSA-qxp2-gg8v-38j7/GHSA-qxp2-gg8v-38j7.json @@ -7,12 +7,8 @@ "CVE-2010-2045" ], "details": "Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r3rv-6724-59xh/GHSA-r3rv-6724-59xh.json b/advisories/unreviewed/2022/05/GHSA-r3rv-6724-59xh/GHSA-r3rv-6724-59xh.json index 32323a62f60..dbf2882c343 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3rv-6724-59xh/GHSA-r3rv-6724-59xh.json +++ b/advisories/unreviewed/2022/05/GHSA-r3rv-6724-59xh/GHSA-r3rv-6724-59xh.json @@ -7,12 +7,8 @@ "CVE-2010-2078" ], "details": "DataTrack System 3.5 allows remote attackers to list the root directory via a (1) /%u0085/ or (2) /%u00A0/ URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r4qf-qv9j-pfh2/GHSA-r4qf-qv9j-pfh2.json b/advisories/unreviewed/2022/05/GHSA-r4qf-qv9j-pfh2/GHSA-r4qf-qv9j-pfh2.json index c4bfb78d980..328d984a3d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4qf-qv9j-pfh2/GHSA-r4qf-qv9j-pfh2.json +++ b/advisories/unreviewed/2022/05/GHSA-r4qf-qv9j-pfh2/GHSA-r4qf-qv9j-pfh2.json @@ -7,12 +7,8 @@ "CVE-2010-2714" ], "details": "SQL injection vulnerability in photos/index.php in TCW PHP Album 1.0 allows remote attackers to execute arbitrary SQL commands via the album parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r5vv-cfcv-fxgg/GHSA-r5vv-cfcv-fxgg.json b/advisories/unreviewed/2022/05/GHSA-r5vv-cfcv-fxgg/GHSA-r5vv-cfcv-fxgg.json index d69b845f4e5..14b484bf5b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5vv-cfcv-fxgg/GHSA-r5vv-cfcv-fxgg.json +++ b/advisories/unreviewed/2022/05/GHSA-r5vv-cfcv-fxgg/GHSA-r5vv-cfcv-fxgg.json @@ -7,12 +7,8 @@ "CVE-2010-2930" ], "details": "Multiple stack-based buffer overflows in hsolinkcontrol in hsolink 1.0.118 allow local users to gain privileges via long command-line arguments, a different vulnerability than CVE-2010-1671. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r638-cc42-fmm8/GHSA-r638-cc42-fmm8.json b/advisories/unreviewed/2022/05/GHSA-r638-cc42-fmm8/GHSA-r638-cc42-fmm8.json index c9ebc0ac4ac..4c8ff850898 100644 --- a/advisories/unreviewed/2022/05/GHSA-r638-cc42-fmm8/GHSA-r638-cc42-fmm8.json +++ b/advisories/unreviewed/2022/05/GHSA-r638-cc42-fmm8/GHSA-r638-cc42-fmm8.json @@ -7,12 +7,8 @@ "CVE-2010-4625" ], "details": "MyBB (aka MyBulletinBoard) before 1.4.12 does not properly handle a configuration with a visible forum that contains hidden threads, which allows remote attackers to obtain sensitive information by reading the Latest Threads block of the Portal Page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r6q2-r6w9-r68w/GHSA-r6q2-r6w9-r68w.json b/advisories/unreviewed/2022/05/GHSA-r6q2-r6w9-r68w/GHSA-r6q2-r6w9-r68w.json index 5dc985feb2d..8c45f7ec8a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6q2-r6w9-r68w/GHSA-r6q2-r6w9-r68w.json +++ b/advisories/unreviewed/2022/05/GHSA-r6q2-r6w9-r68w/GHSA-r6q2-r6w9-r68w.json @@ -7,12 +7,8 @@ "CVE-2010-2048" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Heartbeat module 6.x before 6.x-4.9 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r739-rgx6-8fvc/GHSA-r739-rgx6-8fvc.json b/advisories/unreviewed/2022/05/GHSA-r739-rgx6-8fvc/GHSA-r739-rgx6-8fvc.json index 7307255e011..034bc6f3945 100644 --- a/advisories/unreviewed/2022/05/GHSA-r739-rgx6-8fvc/GHSA-r739-rgx6-8fvc.json +++ b/advisories/unreviewed/2022/05/GHSA-r739-rgx6-8fvc/GHSA-r739-rgx6-8fvc.json @@ -7,12 +7,8 @@ "CVE-2010-4629" ], "details": "MyBB (aka MyBulletinBoard) before 1.4.12 does not properly restrict uid values for group join requests, which allows remote attackers to cause a denial of service (resource consumption) by using guest access to submit join request forms for moderated groups, related to usercp.php and managegroup.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r85p-x73w-j6w7/GHSA-r85p-x73w-j6w7.json b/advisories/unreviewed/2022/05/GHSA-r85p-x73w-j6w7/GHSA-r85p-x73w-j6w7.json index a356c76151d..48ff9f88e28 100644 --- a/advisories/unreviewed/2022/05/GHSA-r85p-x73w-j6w7/GHSA-r85p-x73w-j6w7.json +++ b/advisories/unreviewed/2022/05/GHSA-r85p-x73w-j6w7/GHSA-r85p-x73w-j6w7.json @@ -7,12 +7,8 @@ "CVE-2010-2622" ], "details": "SQL injection vulnerability in the Joomanager component, possibly 1.1.1, for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r8gc-4gr6-4vf3/GHSA-r8gc-4gr6-4vf3.json b/advisories/unreviewed/2022/05/GHSA-r8gc-4gr6-4vf3/GHSA-r8gc-4gr6-4vf3.json index b5009b9f55d..a5c074a73e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8gc-4gr6-4vf3/GHSA-r8gc-4gr6-4vf3.json +++ b/advisories/unreviewed/2022/05/GHSA-r8gc-4gr6-4vf3/GHSA-r8gc-4gr6-4vf3.json @@ -7,12 +7,8 @@ "CVE-2010-2809" ], "details": "The default configuration of the binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows user-assisted remote attackers to execute arbitrary commands via a crafted HREF attribute of an A element in an HTML document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r9m4-pj3v-82vg/GHSA-r9m4-pj3v-82vg.json b/advisories/unreviewed/2022/05/GHSA-r9m4-pj3v-82vg/GHSA-r9m4-pj3v-82vg.json index c186fc34192..24bc34ce268 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9m4-pj3v-82vg/GHSA-r9m4-pj3v-82vg.json +++ b/advisories/unreviewed/2022/05/GHSA-r9m4-pj3v-82vg/GHSA-r9m4-pj3v-82vg.json @@ -7,12 +7,8 @@ "CVE-2010-2852" ], "details": "Cross-site scripting (XSS) vulnerability in modules/headlines/magpierss/scripts/magpie_debug.php in RunCms 2.1, when the Headlines module is enabled, allows remote attackers to inject arbitrary web script or HTML via the url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rffm-4cpf-5232/GHSA-rffm-4cpf-5232.json b/advisories/unreviewed/2022/05/GHSA-rffm-4cpf-5232/GHSA-rffm-4cpf-5232.json index 5615b3df173..ca03e8d2b63 100644 --- a/advisories/unreviewed/2022/05/GHSA-rffm-4cpf-5232/GHSA-rffm-4cpf-5232.json +++ b/advisories/unreviewed/2022/05/GHSA-rffm-4cpf-5232/GHSA-rffm-4cpf-5232.json @@ -7,12 +7,8 @@ "CVE-2010-2329" ], "details": "Buffer overflow in Rosoft Audio Converter 4.4.4 allows remote attackers to execute arbitrary code via a long playlist entry in a .m3u file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rgx2-hj64-5vc5/GHSA-rgx2-hj64-5vc5.json b/advisories/unreviewed/2022/05/GHSA-rgx2-hj64-5vc5/GHSA-rgx2-hj64-5vc5.json index 3dc2a259e57..d368d9c2f72 100644 --- a/advisories/unreviewed/2022/05/GHSA-rgx2-hj64-5vc5/GHSA-rgx2-hj64-5vc5.json +++ b/advisories/unreviewed/2022/05/GHSA-rgx2-hj64-5vc5/GHSA-rgx2-hj64-5vc5.json @@ -7,12 +7,8 @@ "CVE-2010-2702" ], "details": "Buffer overflow in the UGameEngine::UpdateConnectingMessage function in the Unreal engine 1, 2, and 2.5, as used in multiple games including Unreal Tournament 2004, Unreal tournament 2003, Postal 2, Raven Shield, and SWAT4, when downloads are enabled, allows remote attackers to execute arbitrary code via a long LEVEL field in a WELCOME response to a download request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rh22-qpv4-cr2w/GHSA-rh22-qpv4-cr2w.json b/advisories/unreviewed/2022/05/GHSA-rh22-qpv4-cr2w/GHSA-rh22-qpv4-cr2w.json index c9f4ce68343..3e210dc3886 100644 --- a/advisories/unreviewed/2022/05/GHSA-rh22-qpv4-cr2w/GHSA-rh22-qpv4-cr2w.json +++ b/advisories/unreviewed/2022/05/GHSA-rh22-qpv4-cr2w/GHSA-rh22-qpv4-cr2w.json @@ -7,12 +7,8 @@ "CVE-2010-2611" ], "details": "SQL injection vulnerability in show_search_result.php in i-netsolution Job Search Engine allows remote attackers to execute arbitrary SQL commands via the keyword parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rh33-jwjp-gp57/GHSA-rh33-jwjp-gp57.json b/advisories/unreviewed/2022/05/GHSA-rh33-jwjp-gp57/GHSA-rh33-jwjp-gp57.json index abebe8be141..914bf790548 100644 --- a/advisories/unreviewed/2022/05/GHSA-rh33-jwjp-gp57/GHSA-rh33-jwjp-gp57.json +++ b/advisories/unreviewed/2022/05/GHSA-rh33-jwjp-gp57/GHSA-rh33-jwjp-gp57.json @@ -7,12 +7,8 @@ "CVE-2010-3828" ], "details": "iAd Content Display in Apple iOS before 4.2 allows man-in-the-middle attackers to make calls via a crafted URL in an ad.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rh6v-2j3r-hcr7/GHSA-rh6v-2j3r-hcr7.json b/advisories/unreviewed/2022/05/GHSA-rh6v-2j3r-hcr7/GHSA-rh6v-2j3r-hcr7.json index 4418c5e8935..d4d1aac5cd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-rh6v-2j3r-hcr7/GHSA-rh6v-2j3r-hcr7.json +++ b/advisories/unreviewed/2022/05/GHSA-rh6v-2j3r-hcr7/GHSA-rh6v-2j3r-hcr7.json @@ -7,12 +7,8 @@ "CVE-2010-2345" ], "details": "Cross-site request forgery (CSRF) vulnerability in odCMS 1.06, and possibly earlier, allows remote attackers to hijack the authentication of administrators for requests that change the administrative password, and other unspecified requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rhfm-3h2p-hpj5/GHSA-rhfm-3h2p-hpj5.json b/advisories/unreviewed/2022/05/GHSA-rhfm-3h2p-hpj5/GHSA-rhfm-3h2p-hpj5.json index 7c8d1adf979..81a8f56f4fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhfm-3h2p-hpj5/GHSA-rhfm-3h2p-hpj5.json +++ b/advisories/unreviewed/2022/05/GHSA-rhfm-3h2p-hpj5/GHSA-rhfm-3h2p-hpj5.json @@ -7,12 +7,8 @@ "CVE-2010-4181" ], "details": "Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\\ (dot dot backslash) and other sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rmph-rx97-825x/GHSA-rmph-rx97-825x.json b/advisories/unreviewed/2022/05/GHSA-rmph-rx97-825x/GHSA-rmph-rx97-825x.json index c461c609bd9..f03a8953105 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmph-rx97-825x/GHSA-rmph-rx97-825x.json +++ b/advisories/unreviewed/2022/05/GHSA-rmph-rx97-825x/GHSA-rmph-rx97-825x.json @@ -7,12 +7,8 @@ "CVE-2010-2362" ], "details": "Winny 2.0b7.1 and earlier does not properly process node information, which has unspecified impact and remote attack vectors that might lead to use of the product's host for DDoS attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rqvx-64rw-7qf7/GHSA-rqvx-64rw-7qf7.json b/advisories/unreviewed/2022/05/GHSA-rqvx-64rw-7qf7/GHSA-rqvx-64rw-7qf7.json index 8c49f0bd536..f65d0f72fa1 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqvx-64rw-7qf7/GHSA-rqvx-64rw-7qf7.json +++ b/advisories/unreviewed/2022/05/GHSA-rqvx-64rw-7qf7/GHSA-rqvx-64rw-7qf7.json @@ -7,12 +7,8 @@ "CVE-2010-2925" ], "details": "SQL injection vulnerability in index.php in Freeway CMS 1.4.3.210 allows remote attackers to execute arbitrary SQL commands via the ecPath parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rrmh-22f3-jwvm/GHSA-rrmh-22f3-jwvm.json b/advisories/unreviewed/2022/05/GHSA-rrmh-22f3-jwvm/GHSA-rrmh-22f3-jwvm.json index b92331e1708..d1517983671 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrmh-22f3-jwvm/GHSA-rrmh-22f3-jwvm.json +++ b/advisories/unreviewed/2022/05/GHSA-rrmh-22f3-jwvm/GHSA-rrmh-22f3-jwvm.json @@ -7,12 +7,8 @@ "CVE-2010-2617" ], "details": "Cross-site scripting (XSS) vulnerability in bible.php in PHP Bible Search allows remote attackers to inject arbitrary web script or HTML via the chapter parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rrv6-v26v-p7x6/GHSA-rrv6-v26v-p7x6.json b/advisories/unreviewed/2022/05/GHSA-rrv6-v26v-p7x6/GHSA-rrv6-v26v-p7x6.json index e6d9d966edd..766a0ba45fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrv6-v26v-p7x6/GHSA-rrv6-v26v-p7x6.json +++ b/advisories/unreviewed/2022/05/GHSA-rrv6-v26v-p7x6/GHSA-rrv6-v26v-p7x6.json @@ -7,12 +7,8 @@ "CVE-2010-1936" ], "details": "Directory traversal vulnerability in scr/soustab.php in openMairie openComInterne 1.01, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rrx5-gxgm-9hrg/GHSA-rrx5-gxgm-9hrg.json b/advisories/unreviewed/2022/05/GHSA-rrx5-gxgm-9hrg/GHSA-rrx5-gxgm-9hrg.json index 13ce4318c26..2fe7e345ceb 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrx5-gxgm-9hrg/GHSA-rrx5-gxgm-9hrg.json +++ b/advisories/unreviewed/2022/05/GHSA-rrx5-gxgm-9hrg/GHSA-rrx5-gxgm-9hrg.json @@ -7,12 +7,8 @@ "CVE-2010-2156" ], "details": "ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rvrf-fv66-542r/GHSA-rvrf-fv66-542r.json b/advisories/unreviewed/2022/05/GHSA-rvrf-fv66-542r/GHSA-rvrf-fv66-542r.json index 4b8816f26d4..3818c798fda 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvrf-fv66-542r/GHSA-rvrf-fv66-542r.json +++ b/advisories/unreviewed/2022/05/GHSA-rvrf-fv66-542r/GHSA-rvrf-fv66-542r.json @@ -7,12 +7,8 @@ "CVE-2010-4567" ], "details": "Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 does not properly handle whitespace preceding a (1) javascript: or (2) data: URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the URL (aka bug_file_loc) field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rx67-45qh-rq2f/GHSA-rx67-45qh-rq2f.json b/advisories/unreviewed/2022/05/GHSA-rx67-45qh-rq2f/GHSA-rx67-45qh-rq2f.json index 97f0f4c8e26..f9c1b661696 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx67-45qh-rq2f/GHSA-rx67-45qh-rq2f.json +++ b/advisories/unreviewed/2022/05/GHSA-rx67-45qh-rq2f/GHSA-rx67-45qh-rq2f.json @@ -7,12 +7,8 @@ "CVE-2010-4153" ], "details": "Directory traversal vulnerability in CrossFTP Pro 1.65a, and probably earlier, allows remote FTP servers to write arbitrary files via a \"..\\\" (dot dot backslash) in a filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v298-4xpp-8q7w/GHSA-v298-4xpp-8q7w.json b/advisories/unreviewed/2022/05/GHSA-v298-4xpp-8q7w/GHSA-v298-4xpp-8q7w.json index 1ea72111115..e7e7d0b0384 100644 --- a/advisories/unreviewed/2022/05/GHSA-v298-4xpp-8q7w/GHSA-v298-4xpp-8q7w.json +++ b/advisories/unreviewed/2022/05/GHSA-v298-4xpp-8q7w/GHSA-v298-4xpp-8q7w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2px-6v66-28pr/GHSA-v2px-6v66-28pr.json b/advisories/unreviewed/2022/05/GHSA-v2px-6v66-28pr/GHSA-v2px-6v66-28pr.json index f4545173c18..87d803806e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2px-6v66-28pr/GHSA-v2px-6v66-28pr.json +++ b/advisories/unreviewed/2022/05/GHSA-v2px-6v66-28pr/GHSA-v2px-6v66-28pr.json @@ -7,12 +7,8 @@ "CVE-2010-3164" ], "details": "Untrusted search path vulnerability in Fenrir Sleipnir 2.9.4 and earlier and Grani 4.3 and earlier allows local users to gain privileges via a Trojan horse executable file in the current working directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v38m-g35p-gq23/GHSA-v38m-g35p-gq23.json b/advisories/unreviewed/2022/05/GHSA-v38m-g35p-gq23/GHSA-v38m-g35p-gq23.json index 23fcfff1bed..fdf5f1d164f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v38m-g35p-gq23/GHSA-v38m-g35p-gq23.json +++ b/advisories/unreviewed/2022/05/GHSA-v38m-g35p-gq23/GHSA-v38m-g35p-gq23.json @@ -7,12 +7,8 @@ "CVE-2010-2927" ], "details": "The slapi_printmessage function in IBM Tivoli Directory Server (ITDS) before 6.0.0.8-TIV-ITDS-IF0006 allows remote attackers to cause a denial of service (daemon crash) via multiple incomplete DIGEST-MD5 connection attempts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v42x-2p48-wv3h/GHSA-v42x-2p48-wv3h.json b/advisories/unreviewed/2022/05/GHSA-v42x-2p48-wv3h/GHSA-v42x-2p48-wv3h.json index f9c6ad9e61a..a5ec2ff3201 100644 --- a/advisories/unreviewed/2022/05/GHSA-v42x-2p48-wv3h/GHSA-v42x-2p48-wv3h.json +++ b/advisories/unreviewed/2022/05/GHSA-v42x-2p48-wv3h/GHSA-v42x-2p48-wv3h.json @@ -7,12 +7,8 @@ "CVE-2010-2711" ], "details": "Unspecified vulnerability in the HP MagCloud app before 1.0.5 for the iPad allows remote attackers to read and modify MagCloud application data via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v4vh-ww37-cwf9/GHSA-v4vh-ww37-cwf9.json b/advisories/unreviewed/2022/05/GHSA-v4vh-ww37-cwf9/GHSA-v4vh-ww37-cwf9.json index 1d577c9e48e..a04500978c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4vh-ww37-cwf9/GHSA-v4vh-ww37-cwf9.json +++ b/advisories/unreviewed/2022/05/GHSA-v4vh-ww37-cwf9/GHSA-v4vh-ww37-cwf9.json @@ -7,12 +7,8 @@ "CVE-2010-3916" ], "details": "Unspecified vulnerability in JustSystems Ichitaro and Ichitaro Government allows remote attackers to execute arbitrary code via a crafted document, a different vulnerability than CVE-2010-3915.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v546-xgjm-f26m/GHSA-v546-xgjm-f26m.json b/advisories/unreviewed/2022/05/GHSA-v546-xgjm-f26m/GHSA-v546-xgjm-f26m.json index 4a7de4ff5d6..ac4137296f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-v546-xgjm-f26m/GHSA-v546-xgjm-f26m.json +++ b/advisories/unreviewed/2022/05/GHSA-v546-xgjm-f26m/GHSA-v546-xgjm-f26m.json @@ -7,12 +7,8 @@ "CVE-2010-1529" ], "details": "SQL injection vulnerability in the Freestyle FAQs Lite (com_fsf) component, possibly 1.3, for Joomla! allows remote attackers to execute arbitrary SQL commands via the faqid parameter in an faq action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v5c5-v293-v6pr/GHSA-v5c5-v293-v6pr.json b/advisories/unreviewed/2022/05/GHSA-v5c5-v293-v6pr/GHSA-v5c5-v293-v6pr.json index 84bea4d1d0d..7115d603443 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5c5-v293-v6pr/GHSA-v5c5-v293-v6pr.json +++ b/advisories/unreviewed/2022/05/GHSA-v5c5-v293-v6pr/GHSA-v5c5-v293-v6pr.json @@ -7,12 +7,8 @@ "CVE-2010-2050" ], "details": "Directory traversal vulnerability in the Moron Solutions MS Comment (com_mscomment) component 0.8.0b for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v624-m74f-mvr7/GHSA-v624-m74f-mvr7.json b/advisories/unreviewed/2022/05/GHSA-v624-m74f-mvr7/GHSA-v624-m74f-mvr7.json index d65598ca6dc..d73f0723402 100644 --- a/advisories/unreviewed/2022/05/GHSA-v624-m74f-mvr7/GHSA-v624-m74f-mvr7.json +++ b/advisories/unreviewed/2022/05/GHSA-v624-m74f-mvr7/GHSA-v624-m74f-mvr7.json @@ -7,12 +7,8 @@ "CVE-2010-4461" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft and JDEdwards Suite 8.9 Bundle #23, 9.0 Bundle #14, and 9.1 Bundle #4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to ePerformance.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v7m3-8qcv-rghh/GHSA-v7m3-8qcv-rghh.json b/advisories/unreviewed/2022/05/GHSA-v7m3-8qcv-rghh/GHSA-v7m3-8qcv-rghh.json index 27a5c4581fe..323c0351841 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7m3-8qcv-rghh/GHSA-v7m3-8qcv-rghh.json +++ b/advisories/unreviewed/2022/05/GHSA-v7m3-8qcv-rghh/GHSA-v7m3-8qcv-rghh.json @@ -7,12 +7,8 @@ "CVE-2010-1736" ], "details": "KrM Haber 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for d_atabase/Krmdb.mdb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v7mv-48xw-jjpg/GHSA-v7mv-48xw-jjpg.json b/advisories/unreviewed/2022/05/GHSA-v7mv-48xw-jjpg/GHSA-v7mv-48xw-jjpg.json index 21e32386f94..9c37c9e8aae 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7mv-48xw-jjpg/GHSA-v7mv-48xw-jjpg.json +++ b/advisories/unreviewed/2022/05/GHSA-v7mv-48xw-jjpg/GHSA-v7mv-48xw-jjpg.json @@ -7,12 +7,8 @@ "CVE-2010-2468" ], "details": "The S2 Security NetBox 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, uses a weak hash algorithm for storing the Administrator password, which makes it easier for context-dependent attackers to obtain privileged access by recovering the cleartext of this password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v7x3-9cqm-7f9x/GHSA-v7x3-9cqm-7f9x.json b/advisories/unreviewed/2022/05/GHSA-v7x3-9cqm-7f9x/GHSA-v7x3-9cqm-7f9x.json index 0107704c146..f27eae6230b 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7x3-9cqm-7f9x/GHSA-v7x3-9cqm-7f9x.json +++ b/advisories/unreviewed/2022/05/GHSA-v7x3-9cqm-7f9x/GHSA-v7x3-9cqm-7f9x.json @@ -7,12 +7,8 @@ "CVE-2010-2587" ], "details": "The dirapi.dll module in Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2588 and CVE-2010-4188.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v883-mm2p-25jv/GHSA-v883-mm2p-25jv.json b/advisories/unreviewed/2022/05/GHSA-v883-mm2p-25jv/GHSA-v883-mm2p-25jv.json index 82a3042abb8..30d22f97009 100644 --- a/advisories/unreviewed/2022/05/GHSA-v883-mm2p-25jv/GHSA-v883-mm2p-25jv.json +++ b/advisories/unreviewed/2022/05/GHSA-v883-mm2p-25jv/GHSA-v883-mm2p-25jv.json @@ -7,12 +7,8 @@ "CVE-2010-4544" ], "details": "Cross-site scripting (XSS) vulnerability in the servlet in IBM Lotus Notes Traveler before 8.5.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v94c-xcvw-4cjr/GHSA-v94c-xcvw-4cjr.json b/advisories/unreviewed/2022/05/GHSA-v94c-xcvw-4cjr/GHSA-v94c-xcvw-4cjr.json index 0c0b12fee28..dd1333536e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-v94c-xcvw-4cjr/GHSA-v94c-xcvw-4cjr.json +++ b/advisories/unreviewed/2022/05/GHSA-v94c-xcvw-4cjr/GHSA-v94c-xcvw-4cjr.json @@ -7,12 +7,8 @@ "CVE-2010-3827" ], "details": "Apple iOS before 4.2 does not properly validate signatures before displaying a configuration profile in the configuration installation utility, which allows remote attackers to spoof profiles via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v98p-5p6g-589f/GHSA-v98p-5p6g-589f.json b/advisories/unreviewed/2022/05/GHSA-v98p-5p6g-589f/GHSA-v98p-5p6g-589f.json index ec4f988203f..29bbc6b5a24 100644 --- a/advisories/unreviewed/2022/05/GHSA-v98p-5p6g-589f/GHSA-v98p-5p6g-589f.json +++ b/advisories/unreviewed/2022/05/GHSA-v98p-5p6g-589f/GHSA-v98p-5p6g-589f.json @@ -7,12 +7,8 @@ "CVE-2008-7168" ], "details": "Insecure method vulnerability in the UUSee UUUpgrade ActiveX control (UUUpgrade.ocx 3.0.2.12) allows remote attackers to force the download and overwrite of arbitrary files via crafted arguments to the Update method, as exploited in the wild in June 2009.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v9g4-4g73-5g38/GHSA-v9g4-4g73-5g38.json b/advisories/unreviewed/2022/05/GHSA-v9g4-4g73-5g38/GHSA-v9g4-4g73-5g38.json index 359db68cfb0..6a4f0ba757b 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9g4-4g73-5g38/GHSA-v9g4-4g73-5g38.json +++ b/advisories/unreviewed/2022/05/GHSA-v9g4-4g73-5g38/GHSA-v9g4-4g73-5g38.json @@ -7,12 +7,8 @@ "CVE-2010-3764" ], "details": "The Old Charts implementation in Bugzilla 2.12 through 3.2.8, 3.4.8, 3.6.2, 3.7.3, and 4.1 creates graph files with predictable names in graphs/, which allows remote attackers to obtain sensitive information via a modified URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v9rq-6m39-qhfv/GHSA-v9rq-6m39-qhfv.json b/advisories/unreviewed/2022/05/GHSA-v9rq-6m39-qhfv/GHSA-v9rq-6m39-qhfv.json index a7c497c647e..193e682d4c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9rq-6m39-qhfv/GHSA-v9rq-6m39-qhfv.json +++ b/advisories/unreviewed/2022/05/GHSA-v9rq-6m39-qhfv/GHSA-v9rq-6m39-qhfv.json @@ -7,12 +7,8 @@ "CVE-2010-4622" ], "details": "Directory traversal vulnerability in WebSEAL in IBM Tivoli Access Manager for e-business 6.1.1 before 6.1.1-TIV-AWS-FP0001 on AIX allows remote attackers to read arbitrary files via a %uff0e%uff0e (encoded dot dot) in a URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v9rw-6hcx-4xmj/GHSA-v9rw-6hcx-4xmj.json b/advisories/unreviewed/2022/05/GHSA-v9rw-6hcx-4xmj/GHSA-v9rw-6hcx-4xmj.json index 7b22c6113cc..1c302bf5bef 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9rw-6hcx-4xmj/GHSA-v9rw-6hcx-4xmj.json +++ b/advisories/unreviewed/2022/05/GHSA-v9rw-6hcx-4xmj/GHSA-v9rw-6hcx-4xmj.json @@ -7,12 +7,8 @@ "CVE-2010-4497" ], "details": "Cross-site scripting (XSS) vulnerability in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vcv4-f36j-f989/GHSA-vcv4-f36j-f989.json b/advisories/unreviewed/2022/05/GHSA-vcv4-f36j-f989/GHSA-vcv4-f36j-f989.json index bce2d9485b6..a759b649f75 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcv4-f36j-f989/GHSA-vcv4-f36j-f989.json +++ b/advisories/unreviewed/2022/05/GHSA-vcv4-f36j-f989/GHSA-vcv4-f36j-f989.json @@ -7,12 +7,8 @@ "CVE-2010-3456" ], "details": "Directory traversal vulnerability in download.php in EnergyScripts (ES) Simple Download 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vhj4-xvq7-8jwv/GHSA-vhj4-xvq7-8jwv.json b/advisories/unreviewed/2022/05/GHSA-vhj4-xvq7-8jwv/GHSA-vhj4-xvq7-8jwv.json index b1f8a40e919..925f8973f32 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhj4-xvq7-8jwv/GHSA-vhj4-xvq7-8jwv.json +++ b/advisories/unreviewed/2022/05/GHSA-vhj4-xvq7-8jwv/GHSA-vhj4-xvq7-8jwv.json @@ -7,12 +7,8 @@ "CVE-2010-1865" ], "details": "Multiple SQL injection vulnerabilities in ClanSphere 2009.0.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the IP address to the cs_getip function in generate.php in the Captcha module, or (2) the s_email parameter to the cs_sql_select function in the MySQL database driver (mysql.php).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vmc5-rw2x-673r/GHSA-vmc5-rw2x-673r.json b/advisories/unreviewed/2022/05/GHSA-vmc5-rw2x-673r/GHSA-vmc5-rw2x-673r.json index 2c67fd5bf93..c9dfd486315 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmc5-rw2x-673r/GHSA-vmc5-rw2x-673r.json +++ b/advisories/unreviewed/2022/05/GHSA-vmc5-rw2x-673r/GHSA-vmc5-rw2x-673r.json @@ -7,12 +7,8 @@ "CVE-2010-2684" ], "details": "SQL injection vulnerability in index.php in Customer Paradigm PageDirector CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vmfq-82qr-6c52/GHSA-vmfq-82qr-6c52.json b/advisories/unreviewed/2022/05/GHSA-vmfq-82qr-6c52/GHSA-vmfq-82qr-6c52.json index bbabe4c68fc..f82b71995c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmfq-82qr-6c52/GHSA-vmfq-82qr-6c52.json +++ b/advisories/unreviewed/2022/05/GHSA-vmfq-82qr-6c52/GHSA-vmfq-82qr-6c52.json @@ -7,12 +7,8 @@ "CVE-2010-4525" ], "details": "Linux kernel 2.6.33 and 2.6.34.y does not initialize the kvm_vcpu_events->interrupt.pad structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vmph-29gv-pcc6/GHSA-vmph-29gv-pcc6.json b/advisories/unreviewed/2022/05/GHSA-vmph-29gv-pcc6/GHSA-vmph-29gv-pcc6.json index d4d9614c761..2f295732581 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmph-29gv-pcc6/GHSA-vmph-29gv-pcc6.json +++ b/advisories/unreviewed/2022/05/GHSA-vmph-29gv-pcc6/GHSA-vmph-29gv-pcc6.json @@ -7,12 +7,8 @@ "CVE-2010-3924" ], "details": "SQL injection vulnerability in Aimluck Aipo before 5.1.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vmpv-2fcj-wmfj/GHSA-vmpv-2fcj-wmfj.json b/advisories/unreviewed/2022/05/GHSA-vmpv-2fcj-wmfj/GHSA-vmpv-2fcj-wmfj.json index e04cdadf2f1..07243578da8 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmpv-2fcj-wmfj/GHSA-vmpv-2fcj-wmfj.json +++ b/advisories/unreviewed/2022/05/GHSA-vmpv-2fcj-wmfj/GHSA-vmpv-2fcj-wmfj.json @@ -7,12 +7,8 @@ "CVE-2010-3600" ], "details": "Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and Enterprise Manager Grid Control 10.2.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that this issue involves an exposed JSP script that accepts XML uploads in conjunction with NULL bytes in an unspecified parameter that allow execution of arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vpc6-xqq7-xh2q/GHSA-vpc6-xqq7-xh2q.json b/advisories/unreviewed/2022/05/GHSA-vpc6-xqq7-xh2q/GHSA-vpc6-xqq7-xh2q.json index d27cada40c2..6e1422cb0d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpc6-xqq7-xh2q/GHSA-vpc6-xqq7-xh2q.json +++ b/advisories/unreviewed/2022/05/GHSA-vpc6-xqq7-xh2q/GHSA-vpc6-xqq7-xh2q.json @@ -7,12 +7,8 @@ "CVE-2010-4506" ], "details": "Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a \"Save As\" dialog that is reachable from the \"Certificate Export\" wizard.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vpg5-v686-gf7m/GHSA-vpg5-v686-gf7m.json b/advisories/unreviewed/2022/05/GHSA-vpg5-v686-gf7m/GHSA-vpg5-v686-gf7m.json index 7635c76e4b3..c7a031757e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpg5-v686-gf7m/GHSA-vpg5-v686-gf7m.json +++ b/advisories/unreviewed/2022/05/GHSA-vpg5-v686-gf7m/GHSA-vpg5-v686-gf7m.json @@ -7,12 +7,8 @@ "CVE-2010-1494" ], "details": "Directory traversal vulnerability in the AWDwall (com_awdwall) component 1.5.4 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vpjv-r4xm-v9c6/GHSA-vpjv-r4xm-v9c6.json b/advisories/unreviewed/2022/05/GHSA-vpjv-r4xm-v9c6/GHSA-vpjv-r4xm-v9c6.json index 583053892ae..0b28f43538f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpjv-r4xm-v9c6/GHSA-vpjv-r4xm-v9c6.json +++ b/advisories/unreviewed/2022/05/GHSA-vpjv-r4xm-v9c6/GHSA-vpjv-r4xm-v9c6.json @@ -7,12 +7,8 @@ "CVE-2010-2639" ], "details": "IBM WebSphere Commerce Enterprise 7.0 before 7.0.0.2 allows remote attackers to read messages intended for other recipients via vectors involving access by the outbound messaging system to the RunTimeProfileCacheCmdImpl class, related to the caching of mutable objects and \"concurrency issues.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vqr2-3g8r-vf72/GHSA-vqr2-3g8r-vf72.json b/advisories/unreviewed/2022/05/GHSA-vqr2-3g8r-vf72/GHSA-vqr2-3g8r-vf72.json index 83a04a45641..59467ab1182 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqr2-3g8r-vf72/GHSA-vqr2-3g8r-vf72.json +++ b/advisories/unreviewed/2022/05/GHSA-vqr2-3g8r-vf72/GHSA-vqr2-3g8r-vf72.json @@ -7,12 +7,8 @@ "CVE-2008-7105" ], "details": "Sophos PureMessage for Microsoft Exchange 3.0 before 3.0.2 allows remote attackers to cause a denial of service (EdgeTransport.exe termination) via a TNEF-encoded message with a crafted rich text body that is not properly handled during conversion to plain text. NOTE: this might be related to CVE-2008-7104.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vr3x-5p25-4vw9/GHSA-vr3x-5p25-4vw9.json b/advisories/unreviewed/2022/05/GHSA-vr3x-5p25-4vw9/GHSA-vr3x-5p25-4vw9.json index 56c75a61bf3..b92f22c8f91 100644 --- a/advisories/unreviewed/2022/05/GHSA-vr3x-5p25-4vw9/GHSA-vr3x-5p25-4vw9.json +++ b/advisories/unreviewed/2022/05/GHSA-vr3x-5p25-4vw9/GHSA-vr3x-5p25-4vw9.json @@ -7,12 +7,8 @@ "CVE-2010-2350" ], "details": "Heap-based buffer overflow in the PNG decoder in Ziproxy 3.1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNG file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vv36-cxp3-6vh8/GHSA-vv36-cxp3-6vh8.json b/advisories/unreviewed/2022/05/GHSA-vv36-cxp3-6vh8/GHSA-vv36-cxp3-6vh8.json index 0574d831f5c..7a40bcead0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-vv36-cxp3-6vh8/GHSA-vv36-cxp3-6vh8.json +++ b/advisories/unreviewed/2022/05/GHSA-vv36-cxp3-6vh8/GHSA-vv36-cxp3-6vh8.json @@ -7,12 +7,8 @@ "CVE-2010-3606" ], "details": "Multiple directory traversal vulnerabilities in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allow remote emote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) folder and (2) action parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vvcj-m38q-p82v/GHSA-vvcj-m38q-p82v.json b/advisories/unreviewed/2022/05/GHSA-vvcj-m38q-p82v/GHSA-vvcj-m38q-p82v.json index 8669e20b067..d0b872c57a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvcj-m38q-p82v/GHSA-vvcj-m38q-p82v.json +++ b/advisories/unreviewed/2022/05/GHSA-vvcj-m38q-p82v/GHSA-vvcj-m38q-p82v.json @@ -7,12 +7,8 @@ "CVE-2010-4615" ], "details": "Multiple SQL injection vulnerabilities in Oto Galeri Sistemi 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) arac parameter to carsdetail.asp and the (2) marka parameter to twohandscars.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vxfc-p6m6-vprf/GHSA-vxfc-p6m6-vprf.json b/advisories/unreviewed/2022/05/GHSA-vxfc-p6m6-vprf/GHSA-vxfc-p6m6-vprf.json index 424ead7a609..eb5831d3271 100644 --- a/advisories/unreviewed/2022/05/GHSA-vxfc-p6m6-vprf/GHSA-vxfc-p6m6-vprf.json +++ b/advisories/unreviewed/2022/05/GHSA-vxfc-p6m6-vprf/GHSA-vxfc-p6m6-vprf.json @@ -7,12 +7,8 @@ "CVE-2010-4460" ], "details": "Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality and integrity via unknown vectors related to Fault Manager Daemon.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w28m-9f8c-36p9/GHSA-w28m-9f8c-36p9.json b/advisories/unreviewed/2022/05/GHSA-w28m-9f8c-36p9/GHSA-w28m-9f8c-36p9.json index fa33889d3e7..8e7aff75eb5 100644 --- a/advisories/unreviewed/2022/05/GHSA-w28m-9f8c-36p9/GHSA-w28m-9f8c-36p9.json +++ b/advisories/unreviewed/2022/05/GHSA-w28m-9f8c-36p9/GHSA-w28m-9f8c-36p9.json @@ -7,12 +7,8 @@ "CVE-2010-1712" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in base/Comments.php in Webmobo WB News 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and possibly (2) message parameters. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w292-3r2c-wh6c/GHSA-w292-3r2c-wh6c.json b/advisories/unreviewed/2022/05/GHSA-w292-3r2c-wh6c/GHSA-w292-3r2c-wh6c.json index 183e1248a10..3d0896ebeb3 100644 --- a/advisories/unreviewed/2022/05/GHSA-w292-3r2c-wh6c/GHSA-w292-3r2c-wh6c.json +++ b/advisories/unreviewed/2022/05/GHSA-w292-3r2c-wh6c/GHSA-w292-3r2c-wh6c.json @@ -7,12 +7,8 @@ "CVE-2010-2680" ], "details": "Directory traversal vulnerability in the JExtensions JE Section/Property Finder (jesectionfinder) component for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the view parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w44h-7mvx-cpmp/GHSA-w44h-7mvx-cpmp.json b/advisories/unreviewed/2022/05/GHSA-w44h-7mvx-cpmp/GHSA-w44h-7mvx-cpmp.json index 0db7984619c..23fbeed966b 100644 --- a/advisories/unreviewed/2022/05/GHSA-w44h-7mvx-cpmp/GHSA-w44h-7mvx-cpmp.json +++ b/advisories/unreviewed/2022/05/GHSA-w44h-7mvx-cpmp/GHSA-w44h-7mvx-cpmp.json @@ -7,12 +7,8 @@ "CVE-2010-3420" ], "details": "Cross-site scripting (XSS) vulnerability in Products_Results.php in PowerStore 3.0 allows remote attackers to inject arbitrary web script or HTML via the totalRows_WADAProducts parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w478-8x45-v99x/GHSA-w478-8x45-v99x.json b/advisories/unreviewed/2022/05/GHSA-w478-8x45-v99x/GHSA-w478-8x45-v99x.json index d8f6e7228bc..8808730b060 100644 --- a/advisories/unreviewed/2022/05/GHSA-w478-8x45-v99x/GHSA-w478-8x45-v99x.json +++ b/advisories/unreviewed/2022/05/GHSA-w478-8x45-v99x/GHSA-w478-8x45-v99x.json @@ -7,12 +7,8 @@ "CVE-2008-7256" ], "details": "mm/shmem.c in the Linux kernel before 2.6.28-rc8, when strict overcommit is enabled and CONFIG_SECURITY is disabled, does not properly handle the export of shmemfs objects by knfsd, which allows attackers to cause a denial of service (NULL pointer dereference and knfsd crash) or possibly have unspecified other impact via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1643.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w496-4p5w-36v4/GHSA-w496-4p5w-36v4.json b/advisories/unreviewed/2022/05/GHSA-w496-4p5w-36v4/GHSA-w496-4p5w-36v4.json index cefa94a8c48..9cede9b6620 100644 --- a/advisories/unreviewed/2022/05/GHSA-w496-4p5w-36v4/GHSA-w496-4p5w-36v4.json +++ b/advisories/unreviewed/2022/05/GHSA-w496-4p5w-36v4/GHSA-w496-4p5w-36v4.json @@ -7,12 +7,8 @@ "CVE-2010-1876" ], "details": "SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatid parameter in a showmaincatlanding action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w4hc-vqpp-rj57/GHSA-w4hc-vqpp-rj57.json b/advisories/unreviewed/2022/05/GHSA-w4hc-vqpp-rj57/GHSA-w4hc-vqpp-rj57.json index daa59ca7248..e38d229ff3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4hc-vqpp-rj57/GHSA-w4hc-vqpp-rj57.json +++ b/advisories/unreviewed/2022/05/GHSA-w4hc-vqpp-rj57/GHSA-w4hc-vqpp-rj57.json @@ -7,12 +7,8 @@ "CVE-2010-2844" ], "details": "Cross-site scripting (XSS) vulnerability in news_show.php in Newanz NewsOffice 2.0.18 allows remote attackers to inject arbitrary web script or HTML via the n-cat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w59f-66x7-v8wv/GHSA-w59f-66x7-v8wv.json b/advisories/unreviewed/2022/05/GHSA-w59f-66x7-v8wv/GHSA-w59f-66x7-v8wv.json index fa20d2b089a..338db11be73 100644 --- a/advisories/unreviewed/2022/05/GHSA-w59f-66x7-v8wv/GHSA-w59f-66x7-v8wv.json +++ b/advisories/unreviewed/2022/05/GHSA-w59f-66x7-v8wv/GHSA-w59f-66x7-v8wv.json @@ -7,12 +7,8 @@ "CVE-2010-4457" ], "details": "Unspecified vulnerability in Oracle Solaris 11 Express allows remote attackers to affect availability, related to SMB and CIFS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w5g5-g39g-7p84/GHSA-w5g5-g39g-7p84.json b/advisories/unreviewed/2022/05/GHSA-w5g5-g39g-7p84/GHSA-w5g5-g39g-7p84.json index bdb5139f033..b09a940d5c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5g5-g39g-7p84/GHSA-w5g5-g39g-7p84.json +++ b/advisories/unreviewed/2022/05/GHSA-w5g5-g39g-7p84/GHSA-w5g5-g39g-7p84.json @@ -7,12 +7,8 @@ "CVE-2013-6370" ], "details": "Buffer overflow in the printbuf APIs in json-c before 0.12 allows remote attackers to cause a denial of service via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w6h2-q33g-f7x5/GHSA-w6h2-q33g-f7x5.json b/advisories/unreviewed/2022/05/GHSA-w6h2-q33g-f7x5/GHSA-w6h2-q33g-f7x5.json index 9c6355a89eb..5025f2f3b3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6h2-q33g-f7x5/GHSA-w6h2-q33g-f7x5.json +++ b/advisories/unreviewed/2022/05/GHSA-w6h2-q33g-f7x5/GHSA-w6h2-q33g-f7x5.json @@ -7,12 +7,8 @@ "CVE-2008-7093" ], "details": "Multiple directory traversal vulnerabilities in Unica Affinium Campaign 7.2.1.0.55 allow remote attackers to (1) create arbitrary directories or files via a .. (dot dot) in the folder name in the new folder functionality or (2) list arbitrary files via a crafted request to Campaign/CampaignListener.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w6v4-7gww-w8wm/GHSA-w6v4-7gww-w8wm.json b/advisories/unreviewed/2022/05/GHSA-w6v4-7gww-w8wm/GHSA-w6v4-7gww-w8wm.json index 1ed4c1622a5..d1613696c25 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6v4-7gww-w8wm/GHSA-w6v4-7gww-w8wm.json +++ b/advisories/unreviewed/2022/05/GHSA-w6v4-7gww-w8wm/GHSA-w6v4-7gww-w8wm.json @@ -7,12 +7,8 @@ "CVE-2010-3481" ], "details": "Multiple SQL injection vulnerabilities in login.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user_name and (2) password variables, possibly related to include/classes/Login.php. NOTE: some of these details are obtained from third party information. NOTE: the password vector might not be vulnerable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w7xq-m6vj-6xpf/GHSA-w7xq-m6vj-6xpf.json b/advisories/unreviewed/2022/05/GHSA-w7xq-m6vj-6xpf/GHSA-w7xq-m6vj-6xpf.json index beeae96d551..2fa3db39826 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7xq-m6vj-6xpf/GHSA-w7xq-m6vj-6xpf.json +++ b/advisories/unreviewed/2022/05/GHSA-w7xq-m6vj-6xpf/GHSA-w7xq-m6vj-6xpf.json @@ -7,12 +7,8 @@ "CVE-2010-4458" ], "details": "Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability, related to ZFS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w854-jxf9-rc9g/GHSA-w854-jxf9-rc9g.json b/advisories/unreviewed/2022/05/GHSA-w854-jxf9-rc9g/GHSA-w854-jxf9-rc9g.json index e2f349025e6..4dcbfb9b1f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-w854-jxf9-rc9g/GHSA-w854-jxf9-rc9g.json +++ b/advisories/unreviewed/2022/05/GHSA-w854-jxf9-rc9g/GHSA-w854-jxf9-rc9g.json @@ -7,12 +7,8 @@ "CVE-2010-4030" ], "details": "Cross-site scripting (XSS) vulnerability in HP Insight Control Performance Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w8h2-5xj2-2jrx/GHSA-w8h2-5xj2-2jrx.json b/advisories/unreviewed/2022/05/GHSA-w8h2-5xj2-2jrx/GHSA-w8h2-5xj2-2jrx.json index 92123cb93b7..b3e0615d68d 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8h2-5xj2-2jrx/GHSA-w8h2-5xj2-2jrx.json +++ b/advisories/unreviewed/2022/05/GHSA-w8h2-5xj2-2jrx/GHSA-w8h2-5xj2-2jrx.json @@ -7,12 +7,8 @@ "CVE-2010-2676" ], "details": "Multiple directory traversal vulnerabilities in index.php in Open Web Analytics (OWA) 1.2.3 might allow remote attackers to read arbitrary files via directory traversal sequences in the (1) owa_action and (2) owa_do parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w9fq-cmgx-h44f/GHSA-w9fq-cmgx-h44f.json b/advisories/unreviewed/2022/05/GHSA-w9fq-cmgx-h44f/GHSA-w9fq-cmgx-h44f.json index b625f60953c..ba2be9cc024 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9fq-cmgx-h44f/GHSA-w9fq-cmgx-h44f.json +++ b/advisories/unreviewed/2022/05/GHSA-w9fq-cmgx-h44f/GHSA-w9fq-cmgx-h44f.json @@ -7,12 +7,8 @@ "CVE-2010-2356" ], "details": "Cross-site scripting (XSS) vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML via the course_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wf3w-5q4p-4cq8/GHSA-wf3w-5q4p-4cq8.json b/advisories/unreviewed/2022/05/GHSA-wf3w-5q4p-4cq8/GHSA-wf3w-5q4p-4cq8.json index 8ae41bc31fc..0df83d4b918 100644 --- a/advisories/unreviewed/2022/05/GHSA-wf3w-5q4p-4cq8/GHSA-wf3w-5q4p-4cq8.json +++ b/advisories/unreviewed/2022/05/GHSA-wf3w-5q4p-4cq8/GHSA-wf3w-5q4p-4cq8.json @@ -7,12 +7,8 @@ "CVE-2010-2719" ], "details": "SQL injection vulnerability in show.php in phpaaCms 0.3.1 UTF-8, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wh68-278m-77rw/GHSA-wh68-278m-77rw.json b/advisories/unreviewed/2022/05/GHSA-wh68-278m-77rw/GHSA-wh68-278m-77rw.json index bbbe4632c7d..e5d34663db0 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh68-278m-77rw/GHSA-wh68-278m-77rw.json +++ b/advisories/unreviewed/2022/05/GHSA-wh68-278m-77rw/GHSA-wh68-278m-77rw.json @@ -7,12 +7,8 @@ "CVE-2008-7133" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in onlinetools.org EasyImageCatalogue 1.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) search and (2) d index.php parameters to index.php, (3) dir parameter to thumber.php, and the d parameter to (4) describe.php and (5) addcomment.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wj7f-q5c3-fxrc/GHSA-wj7f-q5c3-fxrc.json b/advisories/unreviewed/2022/05/GHSA-wj7f-q5c3-fxrc/GHSA-wj7f-q5c3-fxrc.json index e9e0ef39279..57cc8938e62 100644 --- a/advisories/unreviewed/2022/05/GHSA-wj7f-q5c3-fxrc/GHSA-wj7f-q5c3-fxrc.json +++ b/advisories/unreviewed/2022/05/GHSA-wj7f-q5c3-fxrc/GHSA-wj7f-q5c3-fxrc.json @@ -7,12 +7,8 @@ "CVE-2010-4496" ], "details": "Multiple SQL injection vulnerabilities in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allow remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wjwg-g3q4-3f25/GHSA-wjwg-g3q4-3f25.json b/advisories/unreviewed/2022/05/GHSA-wjwg-g3q4-3f25/GHSA-wjwg-g3q4-3f25.json index 016285f5ad8..9803f9d8413 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjwg-g3q4-3f25/GHSA-wjwg-g3q4-3f25.json +++ b/advisories/unreviewed/2022/05/GHSA-wjwg-g3q4-3f25/GHSA-wjwg-g3q4-3f25.json @@ -7,12 +7,8 @@ "CVE-2010-1914" ], "details": "The Zend Engine in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information by interrupting the handler for the (1) ZEND_BW_XOR opcode (shift_left_function), (2) ZEND_SL opcode (bitwise_xor_function), or (3) ZEND_SR opcode (shift_right_function), related to the convert_to_long_base function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wjww-x723-mj8v/GHSA-wjww-x723-mj8v.json b/advisories/unreviewed/2022/05/GHSA-wjww-x723-mj8v/GHSA-wjww-x723-mj8v.json index 0b342c1c4b6..12b312adb8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjww-x723-mj8v/GHSA-wjww-x723-mj8v.json +++ b/advisories/unreviewed/2022/05/GHSA-wjww-x723-mj8v/GHSA-wjww-x723-mj8v.json @@ -7,12 +7,8 @@ "CVE-2008-7127" ], "details": "osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of service (crash) via a crafted packet with a large string length value to UDP port 14000, which triggers a memory allocation failure that is not properly handled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wmqv-c3qg-w3wr/GHSA-wmqv-c3qg-w3wr.json b/advisories/unreviewed/2022/05/GHSA-wmqv-c3qg-w3wr/GHSA-wmqv-c3qg-w3wr.json index a291e6f55ca..990960b1a20 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmqv-c3qg-w3wr/GHSA-wmqv-c3qg-w3wr.json +++ b/advisories/unreviewed/2022/05/GHSA-wmqv-c3qg-w3wr/GHSA-wmqv-c3qg-w3wr.json @@ -7,12 +7,8 @@ "CVE-2010-4144" ], "details": "SQL injection vulnerability in radyo.asp in Kisisel Radyo Script allows remote attackers to execute arbitrary SQL commands via the Id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmv2-59jq-vhm3/GHSA-wmv2-59jq-vhm3.json b/advisories/unreviewed/2022/05/GHSA-wmv2-59jq-vhm3/GHSA-wmv2-59jq-vhm3.json index d6a375fe26f..a41bd79bebc 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmv2-59jq-vhm3/GHSA-wmv2-59jq-vhm3.json +++ b/advisories/unreviewed/2022/05/GHSA-wmv2-59jq-vhm3/GHSA-wmv2-59jq-vhm3.json @@ -7,12 +7,8 @@ "CVE-2010-2682" ], "details": "Directory traversal vulnerability in the Realtyna Translator (com_realtyna) component 1.0.15 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmx4-5cjv-hcj2/GHSA-wmx4-5cjv-hcj2.json b/advisories/unreviewed/2022/05/GHSA-wmx4-5cjv-hcj2/GHSA-wmx4-5cjv-hcj2.json index 21dafb214cd..6d03df12d8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmx4-5cjv-hcj2/GHSA-wmx4-5cjv-hcj2.json +++ b/advisories/unreviewed/2022/05/GHSA-wmx4-5cjv-hcj2/GHSA-wmx4-5cjv-hcj2.json @@ -7,12 +7,8 @@ "CVE-2010-2916" ], "details": "SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wp98-jr7w-5jhh/GHSA-wp98-jr7w-5jhh.json b/advisories/unreviewed/2022/05/GHSA-wp98-jr7w-5jhh/GHSA-wp98-jr7w-5jhh.json index 41faa5fc64b..432bc02e544 100644 --- a/advisories/unreviewed/2022/05/GHSA-wp98-jr7w-5jhh/GHSA-wp98-jr7w-5jhh.json +++ b/advisories/unreviewed/2022/05/GHSA-wp98-jr7w-5jhh/GHSA-wp98-jr7w-5jhh.json @@ -7,12 +7,8 @@ "CVE-2010-1715" ], "details": "Directory traversal vulnerability in the Online Examination (aka Online Exam or com_onlineexam) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wphw-2cf9-9fxg/GHSA-wphw-2cf9-9fxg.json b/advisories/unreviewed/2022/05/GHSA-wphw-2cf9-9fxg/GHSA-wphw-2cf9-9fxg.json index b426aa0adda..43b83bee6cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-wphw-2cf9-9fxg/GHSA-wphw-2cf9-9fxg.json +++ b/advisories/unreviewed/2022/05/GHSA-wphw-2cf9-9fxg/GHSA-wphw-2cf9-9fxg.json @@ -7,12 +7,8 @@ "CVE-2010-2795" ], "details": "phpCAS before 1.1.2 allows remote authenticated users to hijack sessions via a query string containing a crafted ticket value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wpph-jwhf-rw82/GHSA-wpph-jwhf-rw82.json b/advisories/unreviewed/2022/05/GHSA-wpph-jwhf-rw82/GHSA-wpph-jwhf-rw82.json index ff37bdacec4..1bc7564788f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpph-jwhf-rw82/GHSA-wpph-jwhf-rw82.json +++ b/advisories/unreviewed/2022/05/GHSA-wpph-jwhf-rw82/GHSA-wpph-jwhf-rw82.json @@ -7,12 +7,8 @@ "CVE-2008-7131" ], "details": "Unspecified vulnerability in DB2 Monitoring Console 2.2.4 and earlier allows remote attackers to gain access to a database via a link to a victim who is already connected to the database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wvch-gg24-mw28/GHSA-wvch-gg24-mw28.json b/advisories/unreviewed/2022/05/GHSA-wvch-gg24-mw28/GHSA-wvch-gg24-mw28.json index 349d181d305..c9471b8eb9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvch-gg24-mw28/GHSA-wvch-gg24-mw28.json +++ b/advisories/unreviewed/2022/05/GHSA-wvch-gg24-mw28/GHSA-wvch-gg24-mw28.json @@ -7,12 +7,8 @@ "CVE-2010-2720" ], "details": "SQL injection vulnerability in list.php in phpaaCms 0.3.1 UTF-8, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wvm8-ghrc-v96m/GHSA-wvm8-ghrc-v96m.json b/advisories/unreviewed/2022/05/GHSA-wvm8-ghrc-v96m/GHSA-wvm8-ghrc-v96m.json index 05a6a987496..e2d22db9ea2 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvm8-ghrc-v96m/GHSA-wvm8-ghrc-v96m.json +++ b/advisories/unreviewed/2022/05/GHSA-wvm8-ghrc-v96m/GHSA-wvm8-ghrc-v96m.json @@ -7,12 +7,8 @@ "CVE-2010-2291" ], "details": "Unspecified vulnerability in the web interface in snom VoIP Phone firmware 8 before 8.2.35 allows remote attackers to bypass intended restrictions and modify user credentials via unknown vectors. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wwv3-h536-qwmv/GHSA-wwv3-h536-qwmv.json b/advisories/unreviewed/2022/05/GHSA-wwv3-h536-qwmv/GHSA-wwv3-h536-qwmv.json index a457ce0b413..0b41bcfc768 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwv3-h536-qwmv/GHSA-wwv3-h536-qwmv.json +++ b/advisories/unreviewed/2022/05/GHSA-wwv3-h536-qwmv/GHSA-wwv3-h536-qwmv.json @@ -7,12 +7,8 @@ "CVE-2010-2361" ], "details": "Winny 2.0b7.1 and earlier does not properly process BBS information, which has unspecified impact and remote attack vectors that might lead to use of the product's host for DDoS attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x2fr-qhgr-p5jc/GHSA-x2fr-qhgr-p5jc.json b/advisories/unreviewed/2022/05/GHSA-x2fr-qhgr-p5jc/GHSA-x2fr-qhgr-p5jc.json index 946b1eb2fb6..b30f6aac634 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2fr-qhgr-p5jc/GHSA-x2fr-qhgr-p5jc.json +++ b/advisories/unreviewed/2022/05/GHSA-x2fr-qhgr-p5jc/GHSA-x2fr-qhgr-p5jc.json @@ -7,12 +7,8 @@ "CVE-2010-4349" ], "details": "admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to obtain sensitive information via an invalid db_type parameter, which reveals the installation path in an error message, related to an unsafe call by MantisBT to a function in the ADOdb Library for PHP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x2gf-mx86-8jq7/GHSA-x2gf-mx86-8jq7.json b/advisories/unreviewed/2022/05/GHSA-x2gf-mx86-8jq7/GHSA-x2gf-mx86-8jq7.json index 39421e37b36..ee12fa93d1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2gf-mx86-8jq7/GHSA-x2gf-mx86-8jq7.json +++ b/advisories/unreviewed/2022/05/GHSA-x2gf-mx86-8jq7/GHSA-x2gf-mx86-8jq7.json @@ -7,12 +7,8 @@ "CVE-2010-2921" ], "details": "SQL injection vulnerability in the Golf Course Guide (com_golfcourseguide) component 0.9.6.0 beta and 1 beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a golfcourses action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x32m-pghh-vxqf/GHSA-x32m-pghh-vxqf.json b/advisories/unreviewed/2022/05/GHSA-x32m-pghh-vxqf/GHSA-x32m-pghh-vxqf.json index f345b67f85d..a427e964dd9 100644 --- a/advisories/unreviewed/2022/05/GHSA-x32m-pghh-vxqf/GHSA-x32m-pghh-vxqf.json +++ b/advisories/unreviewed/2022/05/GHSA-x32m-pghh-vxqf/GHSA-x32m-pghh-vxqf.json @@ -7,12 +7,8 @@ "CVE-2010-2354" ], "details": "SQL injection vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to execute arbitrary SQL commands via the course_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3gf-fpp5-65hp/GHSA-x3gf-fpp5-65hp.json b/advisories/unreviewed/2022/05/GHSA-x3gf-fpp5-65hp/GHSA-x3gf-fpp5-65hp.json index 4c32afc446e..f991001f1e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3gf-fpp5-65hp/GHSA-x3gf-fpp5-65hp.json +++ b/advisories/unreviewed/2022/05/GHSA-x3gf-fpp5-65hp/GHSA-x3gf-fpp5-65hp.json @@ -7,12 +7,8 @@ "CVE-2010-2348" ], "details": "Stack-based buffer overflow in Batch Audio Converter Lite Edition 1.0.0.0 and earlier allows remote attackers to execute arbitrary code via a long line in a .WAV file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3m3-q3xc-8m5j/GHSA-x3m3-q3xc-8m5j.json b/advisories/unreviewed/2022/05/GHSA-x3m3-q3xc-8m5j/GHSA-x3m3-q3xc-8m5j.json index a541a97d2cc..ea179f25a66 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3m3-q3xc-8m5j/GHSA-x3m3-q3xc-8m5j.json +++ b/advisories/unreviewed/2022/05/GHSA-x3m3-q3xc-8m5j/GHSA-x3m3-q3xc-8m5j.json @@ -7,12 +7,8 @@ "CVE-2010-3829" ], "details": "WebKit in Apple iOS before 4.2 allows remote attackers to bypass the remote image loading setting in Mail via an HTML LINK element with a DNS prefetching property, as demonstrated by an HTML e-mail message that uses a LINK element for X-Confirm-Reading-To functionality, a related issue to CVE-2010-3813.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x743-h4cc-mxrh/GHSA-x743-h4cc-mxrh.json b/advisories/unreviewed/2022/05/GHSA-x743-h4cc-mxrh/GHSA-x743-h4cc-mxrh.json index e1dbdb32dc0..89a3d7c441d 100644 --- a/advisories/unreviewed/2022/05/GHSA-x743-h4cc-mxrh/GHSA-x743-h4cc-mxrh.json +++ b/advisories/unreviewed/2022/05/GHSA-x743-h4cc-mxrh/GHSA-x743-h4cc-mxrh.json @@ -7,12 +7,8 @@ "CVE-2010-3418" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in NetArt Media Car Portal 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) car_id parameter to index.php and (2) y parameter to include/images.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x745-x857-q9jc/GHSA-x745-x857-q9jc.json b/advisories/unreviewed/2022/05/GHSA-x745-x857-q9jc/GHSA-x745-x857-q9jc.json index f27019ea87d..e2d58d5b123 100644 --- a/advisories/unreviewed/2022/05/GHSA-x745-x857-q9jc/GHSA-x745-x857-q9jc.json +++ b/advisories/unreviewed/2022/05/GHSA-x745-x857-q9jc/GHSA-x745-x857-q9jc.json @@ -7,12 +7,8 @@ "CVE-2010-2906" ], "details": "SQL injection vulnerability in articlesdetails.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2010-2905.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x7q5-98p8-3gx3/GHSA-x7q5-98p8-3gx3.json b/advisories/unreviewed/2022/05/GHSA-x7q5-98p8-3gx3/GHSA-x7q5-98p8-3gx3.json index 1049aafac65..c33d48bbaad 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7q5-98p8-3gx3/GHSA-x7q5-98p8-3gx3.json +++ b/advisories/unreviewed/2022/05/GHSA-x7q5-98p8-3gx3/GHSA-x7q5-98p8-3gx3.json @@ -7,12 +7,8 @@ "CVE-2008-7134" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the default URI in Chris LaPointe RedGalaxy Download Center 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter, (2) message parameter in a login action, (3) category parameter in a browse action, (4) now parameter, or (5) search parameter in a search_results action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x7rm-43v9-j38p/GHSA-x7rm-43v9-j38p.json b/advisories/unreviewed/2022/05/GHSA-x7rm-43v9-j38p/GHSA-x7rm-43v9-j38p.json index 9378778b358..8c640fa7240 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7rm-43v9-j38p/GHSA-x7rm-43v9-j38p.json +++ b/advisories/unreviewed/2022/05/GHSA-x7rm-43v9-j38p/GHSA-x7rm-43v9-j38p.json @@ -7,12 +7,8 @@ "CVE-2010-4057" ], "details": "solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing many integer fields with two different values, which allows remote attackers to cause a denial of service (invalid memory access and daemon crash) via a TCP session on port 1315.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x82x-3qv6-2c36/GHSA-x82x-3qv6-2c36.json b/advisories/unreviewed/2022/05/GHSA-x82x-3qv6-2c36/GHSA-x82x-3qv6-2c36.json index d67bf2aa583..abb8b1aaeb1 100644 --- a/advisories/unreviewed/2022/05/GHSA-x82x-3qv6-2c36/GHSA-x82x-3qv6-2c36.json +++ b/advisories/unreviewed/2022/05/GHSA-x82x-3qv6-2c36/GHSA-x82x-3qv6-2c36.json @@ -7,12 +7,8 @@ "CVE-2010-4627" ], "details": "Cross-site request forgery (CSRF) vulnerability in usercp2.php in MyBB (aka MyBulletinBoard) before 1.4.12 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x8mf-jq4w-r293/GHSA-x8mf-jq4w-r293.json b/advisories/unreviewed/2022/05/GHSA-x8mf-jq4w-r293/GHSA-x8mf-jq4w-r293.json index 85298afb84d..da8b4b6bbee 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8mf-jq4w-r293/GHSA-x8mf-jq4w-r293.json +++ b/advisories/unreviewed/2022/05/GHSA-x8mf-jq4w-r293/GHSA-x8mf-jq4w-r293.json @@ -7,12 +7,8 @@ "CVE-2008-7155" ], "details": "NetRisk 1.9.7 does not properly restrict access to admin/change_submit.php, which allows remote attackers to change the password of arbitrary users via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x993-w3pv-6hmf/GHSA-x993-w3pv-6hmf.json b/advisories/unreviewed/2022/05/GHSA-x993-w3pv-6hmf/GHSA-x993-w3pv-6hmf.json index 1249dce1f18..1e6fb3e49cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-x993-w3pv-6hmf/GHSA-x993-w3pv-6hmf.json +++ b/advisories/unreviewed/2022/05/GHSA-x993-w3pv-6hmf/GHSA-x993-w3pv-6hmf.json @@ -7,12 +7,8 @@ "CVE-2010-1875" ], "details": "Directory traversal vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x9h2-w394-8fv9/GHSA-x9h2-w394-8fv9.json b/advisories/unreviewed/2022/05/GHSA-x9h2-w394-8fv9/GHSA-x9h2-w394-8fv9.json index c6beb883380..5641238e5c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9h2-w394-8fv9/GHSA-x9h2-w394-8fv9.json +++ b/advisories/unreviewed/2022/05/GHSA-x9h2-w394-8fv9/GHSA-x9h2-w394-8fv9.json @@ -7,12 +7,8 @@ "CVE-2010-1955" ], "details": "Directory traversal vulnerability in the Deluxe Blog Factory (com_blogfactory) component 1.1.2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xc55-j8g3-8x83/GHSA-xc55-j8g3-8x83.json b/advisories/unreviewed/2022/05/GHSA-xc55-j8g3-8x83/GHSA-xc55-j8g3-8x83.json index b7a269d1440..7ce2e4ed2b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc55-j8g3-8x83/GHSA-xc55-j8g3-8x83.json +++ b/advisories/unreviewed/2022/05/GHSA-xc55-j8g3-8x83/GHSA-xc55-j8g3-8x83.json @@ -7,12 +7,8 @@ "CVE-2010-1716" ], "details": "SQL injection vulnerability in the Agenda Address Book (com_agenda) component 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xf8m-j9rp-c8f4/GHSA-xf8m-j9rp-c8f4.json b/advisories/unreviewed/2022/05/GHSA-xf8m-j9rp-c8f4/GHSA-xf8m-j9rp-c8f4.json index cdc98849614..f5f6298b940 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf8m-j9rp-c8f4/GHSA-xf8m-j9rp-c8f4.json +++ b/advisories/unreviewed/2022/05/GHSA-xf8m-j9rp-c8f4/GHSA-xf8m-j9rp-c8f4.json @@ -7,12 +7,8 @@ "CVE-2010-1739" ], "details": "SQL injection vulnerability in the Newsfeeds (com_newsfeeds) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the feedid parameter in a categories action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xg5x-96p3-r774/GHSA-xg5x-96p3-r774.json b/advisories/unreviewed/2022/05/GHSA-xg5x-96p3-r774/GHSA-xg5x-96p3-r774.json index c07c90c5a58..1cf1427fb97 100644 --- a/advisories/unreviewed/2022/05/GHSA-xg5x-96p3-r774/GHSA-xg5x-96p3-r774.json +++ b/advisories/unreviewed/2022/05/GHSA-xg5x-96p3-r774/GHSA-xg5x-96p3-r774.json @@ -7,12 +7,8 @@ "CVE-2010-2462" ], "details": "SQL injection vulnerability in withdraw_money.php in Toma Cero OroHYIP allows remote attackers to execute arbitrary SQL commands via the id parameter in a cancel action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xgq3-h8hp-5qjg/GHSA-xgq3-h8hp-5qjg.json b/advisories/unreviewed/2022/05/GHSA-xgq3-h8hp-5qjg/GHSA-xgq3-h8hp-5qjg.json index 8cbe7341b12..ea1df5b842a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgq3-h8hp-5qjg/GHSA-xgq3-h8hp-5qjg.json +++ b/advisories/unreviewed/2022/05/GHSA-xgq3-h8hp-5qjg/GHSA-xgq3-h8hp-5qjg.json @@ -7,12 +7,8 @@ "CVE-2010-2132" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1 beta allow remote attackers to execute arbitrary PHP code via a URL in the CONF_INCLUDE_PATH parameter to (1) forum/admin.php and (2) plotgraph/index.php in admin/modules/modules/, and (3) admin_user/mod_admuser.php and (4) ogroup/mod_group.php in admin/modules/user_account/, different vectors than CVE-2007-1446.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xh3j-cw8c-mh94/GHSA-xh3j-cw8c-mh94.json b/advisories/unreviewed/2022/05/GHSA-xh3j-cw8c-mh94/GHSA-xh3j-cw8c-mh94.json index 1339a266c42..b3557e8ac95 100644 --- a/advisories/unreviewed/2022/05/GHSA-xh3j-cw8c-mh94/GHSA-xh3j-cw8c-mh94.json +++ b/advisories/unreviewed/2022/05/GHSA-xh3j-cw8c-mh94/GHSA-xh3j-cw8c-mh94.json @@ -7,12 +7,8 @@ "CVE-2010-3831" ], "details": "Photos in Apple iOS before 4.2 enables support for HTTP Basic Authentication over an unencrypted connection, which allows man-in-the-middle attackers to read MobileMe account passwords by spoofing a MobileMe Gallery server during a \"Send to MobileMe\" action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xhw4-5qgr-c2w2/GHSA-xhw4-5qgr-c2w2.json b/advisories/unreviewed/2022/05/GHSA-xhw4-5qgr-c2w2/GHSA-xhw4-5qgr-c2w2.json index d726c5f75da..1cab82477b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-xhw4-5qgr-c2w2/GHSA-xhw4-5qgr-c2w2.json +++ b/advisories/unreviewed/2022/05/GHSA-xhw4-5qgr-c2w2/GHSA-xhw4-5qgr-c2w2.json @@ -7,12 +7,8 @@ "CVE-2010-2507" ], "details": "Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xqr2-7pjv-2gjp/GHSA-xqr2-7pjv-2gjp.json b/advisories/unreviewed/2022/05/GHSA-xqr2-7pjv-2gjp/GHSA-xqr2-7pjv-2gjp.json index 8d519d01cdd..14b68c98c7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqr2-7pjv-2gjp/GHSA-xqr2-7pjv-2gjp.json +++ b/advisories/unreviewed/2022/05/GHSA-xqr2-7pjv-2gjp/GHSA-xqr2-7pjv-2gjp.json @@ -7,12 +7,8 @@ "CVE-2010-2850" ], "details": "Directory traversal vulnerability in productionnu2/fileuploader.php in nuBuilder 10.04.20, and possibly other versions before 10.07.12, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dir parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xr49-pr22-vxc8/GHSA-xr49-pr22-vxc8.json b/advisories/unreviewed/2022/05/GHSA-xr49-pr22-vxc8/GHSA-xr49-pr22-vxc8.json index 7d3bb85ae37..07a5ba44958 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr49-pr22-vxc8/GHSA-xr49-pr22-vxc8.json +++ b/advisories/unreviewed/2022/05/GHSA-xr49-pr22-vxc8/GHSA-xr49-pr22-vxc8.json @@ -7,12 +7,8 @@ "CVE-2008-7151" ], "details": "Cross-site request forgery (CSRF) vulnerability in Live 5.x before 5.x-0.1, a module for Drupal, allows remote attackers to hijack the authentication of unspecified privileged users for requests that can be leveraged to execute arbitrary PHP code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xv49-2wgv-qvc2/GHSA-xv49-2wgv-qvc2.json b/advisories/unreviewed/2022/05/GHSA-xv49-2wgv-qvc2/GHSA-xv49-2wgv-qvc2.json index 50b9a641a24..561442d7548 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv49-2wgv-qvc2/GHSA-xv49-2wgv-qvc2.json +++ b/advisories/unreviewed/2022/05/GHSA-xv49-2wgv-qvc2/GHSA-xv49-2wgv-qvc2.json @@ -7,12 +7,8 @@ "CVE-2010-3466" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in the hosted_signup module in NetArt Media iBoutique.MALL 1.2 allows remote attackers to inject arbitrary web script or HTML via the tmpl parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xv69-hhpr-w3r5/GHSA-xv69-hhpr-w3r5.json b/advisories/unreviewed/2022/05/GHSA-xv69-hhpr-w3r5/GHSA-xv69-hhpr-w3r5.json index 62f19602893..561143793e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv69-hhpr-w3r5/GHSA-xv69-hhpr-w3r5.json +++ b/advisories/unreviewed/2022/05/GHSA-xv69-hhpr-w3r5/GHSA-xv69-hhpr-w3r5.json @@ -7,12 +7,8 @@ "CVE-2010-4611" ], "details": "Html-edit CMS 3.1.8 allows remote attackers to obtain sensitive information via a direct request to (1) pages.php and (2) menu.php in includes/core_files and (3) extensions/login/frontend/pages/antihacker.php, which reveals the installation path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xvhq-v5ww-mmhx/GHSA-xvhq-v5ww-mmhx.json b/advisories/unreviewed/2022/05/GHSA-xvhq-v5ww-mmhx/GHSA-xvhq-v5ww-mmhx.json index d748fd77552..bfd38ebd116 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvhq-v5ww-mmhx/GHSA-xvhq-v5ww-mmhx.json +++ b/advisories/unreviewed/2022/05/GHSA-xvhq-v5ww-mmhx/GHSA-xvhq-v5ww-mmhx.json @@ -7,12 +7,8 @@ "CVE-2010-1721" ], "details": "SQL injection vulnerability in the Intellectual Property (aka IProperty or com_iproperty) component 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an agentproperties action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xw9f-r7rv-2cfw/GHSA-xw9f-r7rv-2cfw.json b/advisories/unreviewed/2022/05/GHSA-xw9f-r7rv-2cfw/GHSA-xw9f-r7rv-2cfw.json index 8a144194afa..4ab58aa34b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw9f-r7rv-2cfw/GHSA-xw9f-r7rv-2cfw.json +++ b/advisories/unreviewed/2022/05/GHSA-xw9f-r7rv-2cfw/GHSA-xw9f-r7rv-2cfw.json @@ -7,12 +7,8 @@ "CVE-2010-2644" ], "details": "IBM WebSphere Service Registry and Repository (WSRR) 7.0.0 before FP1 does not properly implement access control, which allows remote attackers to perform governance actions via unspecified API requests to an EJB interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xxf2-85hh-x424/GHSA-xxf2-85hh-x424.json b/advisories/unreviewed/2022/05/GHSA-xxf2-85hh-x424/GHSA-xxf2-85hh-x424.json index 718ae119769..6dac68f0032 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxf2-85hh-x424/GHSA-xxf2-85hh-x424.json +++ b/advisories/unreviewed/2022/05/GHSA-xxf2-85hh-x424/GHSA-xxf2-85hh-x424.json @@ -7,12 +7,8 @@ "CVE-2010-2154" ], "details": "Cross-site scripting (XSS) vulnerability in the Search Site in CMScout 2.09, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-6578-hf9h-23c9/GHSA-6578-hf9h-23c9.json b/advisories/unreviewed/2023/07/GHSA-6578-hf9h-23c9/GHSA-6578-hf9h-23c9.json index 872e80ba193..4b18f9d361e 100644 --- a/advisories/unreviewed/2023/07/GHSA-6578-hf9h-23c9/GHSA-6578-hf9h-23c9.json +++ b/advisories/unreviewed/2023/07/GHSA-6578-hf9h-23c9/GHSA-6578-hf9h-23c9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-mgcr-5hwm-m58m/GHSA-mgcr-5hwm-m58m.json b/advisories/unreviewed/2023/07/GHSA-mgcr-5hwm-m58m/GHSA-mgcr-5hwm-m58m.json index 4d4cd84e1f1..efd0f3a1bbd 100644 --- a/advisories/unreviewed/2023/07/GHSA-mgcr-5hwm-m58m/GHSA-mgcr-5hwm-m58m.json +++ b/advisories/unreviewed/2023/07/GHSA-mgcr-5hwm-m58m/GHSA-mgcr-5hwm-m58m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-278m-rc9v-hf3c/GHSA-278m-rc9v-hf3c.json b/advisories/unreviewed/2024/02/GHSA-278m-rc9v-hf3c/GHSA-278m-rc9v-hf3c.json index 975e881bb60..b17ee5cc45c 100644 --- a/advisories/unreviewed/2024/02/GHSA-278m-rc9v-hf3c/GHSA-278m-rc9v-hf3c.json +++ b/advisories/unreviewed/2024/02/GHSA-278m-rc9v-hf3c/GHSA-278m-rc9v-hf3c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-327h-468p-mffv/GHSA-327h-468p-mffv.json b/advisories/unreviewed/2024/02/GHSA-327h-468p-mffv/GHSA-327h-468p-mffv.json index 1f44cf10750..4df195a2bf9 100644 --- a/advisories/unreviewed/2024/02/GHSA-327h-468p-mffv/GHSA-327h-468p-mffv.json +++ b/advisories/unreviewed/2024/02/GHSA-327h-468p-mffv/GHSA-327h-468p-mffv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-38g6-vx2q-23wm/GHSA-38g6-vx2q-23wm.json b/advisories/unreviewed/2024/02/GHSA-38g6-vx2q-23wm/GHSA-38g6-vx2q-23wm.json index e0f9532d64e..cab39d8a055 100644 --- a/advisories/unreviewed/2024/02/GHSA-38g6-vx2q-23wm/GHSA-38g6-vx2q-23wm.json +++ b/advisories/unreviewed/2024/02/GHSA-38g6-vx2q-23wm/GHSA-38g6-vx2q-23wm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-397m-2h32-p5j6/GHSA-397m-2h32-p5j6.json b/advisories/unreviewed/2024/02/GHSA-397m-2h32-p5j6/GHSA-397m-2h32-p5j6.json index 4401b72f94c..e68a9d067c7 100644 --- a/advisories/unreviewed/2024/02/GHSA-397m-2h32-p5j6/GHSA-397m-2h32-p5j6.json +++ b/advisories/unreviewed/2024/02/GHSA-397m-2h32-p5j6/GHSA-397m-2h32-p5j6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-42jj-9j7q-98jv/GHSA-42jj-9j7q-98jv.json b/advisories/unreviewed/2024/02/GHSA-42jj-9j7q-98jv/GHSA-42jj-9j7q-98jv.json index 16c4d1a19e7..466f741b9f7 100644 --- a/advisories/unreviewed/2024/02/GHSA-42jj-9j7q-98jv/GHSA-42jj-9j7q-98jv.json +++ b/advisories/unreviewed/2024/02/GHSA-42jj-9j7q-98jv/GHSA-42jj-9j7q-98jv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-528v-fv7h-v892/GHSA-528v-fv7h-v892.json b/advisories/unreviewed/2024/02/GHSA-528v-fv7h-v892/GHSA-528v-fv7h-v892.json index b1aabec6b01..0e8222dfff7 100644 --- a/advisories/unreviewed/2024/02/GHSA-528v-fv7h-v892/GHSA-528v-fv7h-v892.json +++ b/advisories/unreviewed/2024/02/GHSA-528v-fv7h-v892/GHSA-528v-fv7h-v892.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-5pjp-x72x-j9r3/GHSA-5pjp-x72x-j9r3.json b/advisories/unreviewed/2024/02/GHSA-5pjp-x72x-j9r3/GHSA-5pjp-x72x-j9r3.json index 523a4b2b079..88f9b5d7232 100644 --- a/advisories/unreviewed/2024/02/GHSA-5pjp-x72x-j9r3/GHSA-5pjp-x72x-j9r3.json +++ b/advisories/unreviewed/2024/02/GHSA-5pjp-x72x-j9r3/GHSA-5pjp-x72x-j9r3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -63,9 +61,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-5vcj-fx4r-4xrv/GHSA-5vcj-fx4r-4xrv.json b/advisories/unreviewed/2024/02/GHSA-5vcj-fx4r-4xrv/GHSA-5vcj-fx4r-4xrv.json index 93f81bb5816..b288f12aec3 100644 --- a/advisories/unreviewed/2024/02/GHSA-5vcj-fx4r-4xrv/GHSA-5vcj-fx4r-4xrv.json +++ b/advisories/unreviewed/2024/02/GHSA-5vcj-fx4r-4xrv/GHSA-5vcj-fx4r-4xrv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-6hcj-xq8v-5j7j/GHSA-6hcj-xq8v-5j7j.json b/advisories/unreviewed/2024/02/GHSA-6hcj-xq8v-5j7j/GHSA-6hcj-xq8v-5j7j.json index 7847455605f..16f7a72501e 100644 --- a/advisories/unreviewed/2024/02/GHSA-6hcj-xq8v-5j7j/GHSA-6hcj-xq8v-5j7j.json +++ b/advisories/unreviewed/2024/02/GHSA-6hcj-xq8v-5j7j/GHSA-6hcj-xq8v-5j7j.json @@ -7,12 +7,8 @@ "CVE-2024-25435" ], "details": "A cross-site scripting (XSS) vulnerability in Md1health Md1patient v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Msg parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-6pc7-4x73-wwc6/GHSA-6pc7-4x73-wwc6.json b/advisories/unreviewed/2024/02/GHSA-6pc7-4x73-wwc6/GHSA-6pc7-4x73-wwc6.json index f1d73d5834c..7b787615ece 100644 --- a/advisories/unreviewed/2024/02/GHSA-6pc7-4x73-wwc6/GHSA-6pc7-4x73-wwc6.json +++ b/advisories/unreviewed/2024/02/GHSA-6pc7-4x73-wwc6/GHSA-6pc7-4x73-wwc6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -67,9 +65,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-747m-qmxp-h92f/GHSA-747m-qmxp-h92f.json b/advisories/unreviewed/2024/02/GHSA-747m-qmxp-h92f/GHSA-747m-qmxp-h92f.json index 09607f7c3cb..c945d7c0b21 100644 --- a/advisories/unreviewed/2024/02/GHSA-747m-qmxp-h92f/GHSA-747m-qmxp-h92f.json +++ b/advisories/unreviewed/2024/02/GHSA-747m-qmxp-h92f/GHSA-747m-qmxp-h92f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-7pp5-c4g8-xxc4/GHSA-7pp5-c4g8-xxc4.json b/advisories/unreviewed/2024/02/GHSA-7pp5-c4g8-xxc4/GHSA-7pp5-c4g8-xxc4.json index 6ba141dbdb8..f975b46eb56 100644 --- a/advisories/unreviewed/2024/02/GHSA-7pp5-c4g8-xxc4/GHSA-7pp5-c4g8-xxc4.json +++ b/advisories/unreviewed/2024/02/GHSA-7pp5-c4g8-xxc4/GHSA-7pp5-c4g8-xxc4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-8pq4-pmqh-grvh/GHSA-8pq4-pmqh-grvh.json b/advisories/unreviewed/2024/02/GHSA-8pq4-pmqh-grvh/GHSA-8pq4-pmqh-grvh.json index 68fe3c3741e..3f6fca0690d 100644 --- a/advisories/unreviewed/2024/02/GHSA-8pq4-pmqh-grvh/GHSA-8pq4-pmqh-grvh.json +++ b/advisories/unreviewed/2024/02/GHSA-8pq4-pmqh-grvh/GHSA-8pq4-pmqh-grvh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-8xf7-6cv9-64f7/GHSA-8xf7-6cv9-64f7.json b/advisories/unreviewed/2024/02/GHSA-8xf7-6cv9-64f7/GHSA-8xf7-6cv9-64f7.json index 23878eec5b4..25175ca86da 100644 --- a/advisories/unreviewed/2024/02/GHSA-8xf7-6cv9-64f7/GHSA-8xf7-6cv9-64f7.json +++ b/advisories/unreviewed/2024/02/GHSA-8xf7-6cv9-64f7/GHSA-8xf7-6cv9-64f7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-92f7-c7hw-58cr/GHSA-92f7-c7hw-58cr.json b/advisories/unreviewed/2024/02/GHSA-92f7-c7hw-58cr/GHSA-92f7-c7hw-58cr.json index dabe272ea09..91e6f22c83c 100644 --- a/advisories/unreviewed/2024/02/GHSA-92f7-c7hw-58cr/GHSA-92f7-c7hw-58cr.json +++ b/advisories/unreviewed/2024/02/GHSA-92f7-c7hw-58cr/GHSA-92f7-c7hw-58cr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-92q5-jqvg-mhwp/GHSA-92q5-jqvg-mhwp.json b/advisories/unreviewed/2024/02/GHSA-92q5-jqvg-mhwp/GHSA-92q5-jqvg-mhwp.json index 9870ab87124..e38b47f23ff 100644 --- a/advisories/unreviewed/2024/02/GHSA-92q5-jqvg-mhwp/GHSA-92q5-jqvg-mhwp.json +++ b/advisories/unreviewed/2024/02/GHSA-92q5-jqvg-mhwp/GHSA-92q5-jqvg-mhwp.json @@ -7,12 +7,8 @@ "CVE-2021-47043" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: core: Fix some resource leaks in the error path of 'venus_probe()'\n\nIf an error occurs after a successful 'of_icc_get()' call, it must be\nundone.\n\nUse 'devm_of_icc_get()' instead of 'of_icc_get()' to avoid the leak.\nUpdate the remove function accordingly and axe the now unneeded\n'icc_put()' calls.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json b/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json index a1916122944..3cf92376627 100644 --- a/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json +++ b/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-cf5h-fpjr-xpm5/GHSA-cf5h-fpjr-xpm5.json b/advisories/unreviewed/2024/02/GHSA-cf5h-fpjr-xpm5/GHSA-cf5h-fpjr-xpm5.json index 353686b841d..e924821d188 100644 --- a/advisories/unreviewed/2024/02/GHSA-cf5h-fpjr-xpm5/GHSA-cf5h-fpjr-xpm5.json +++ b/advisories/unreviewed/2024/02/GHSA-cf5h-fpjr-xpm5/GHSA-cf5h-fpjr-xpm5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-f54m-q836-9rr6/GHSA-f54m-q836-9rr6.json b/advisories/unreviewed/2024/02/GHSA-f54m-q836-9rr6/GHSA-f54m-q836-9rr6.json index 845bc57fa9f..d3e6f05011a 100644 --- a/advisories/unreviewed/2024/02/GHSA-f54m-q836-9rr6/GHSA-f54m-q836-9rr6.json +++ b/advisories/unreviewed/2024/02/GHSA-f54m-q836-9rr6/GHSA-f54m-q836-9rr6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-frwj-xv69-m7pr/GHSA-frwj-xv69-m7pr.json b/advisories/unreviewed/2024/02/GHSA-frwj-xv69-m7pr/GHSA-frwj-xv69-m7pr.json index a033d820b4d..169d6684975 100644 --- a/advisories/unreviewed/2024/02/GHSA-frwj-xv69-m7pr/GHSA-frwj-xv69-m7pr.json +++ b/advisories/unreviewed/2024/02/GHSA-frwj-xv69-m7pr/GHSA-frwj-xv69-m7pr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-gp6j-7c6x-xpmx/GHSA-gp6j-7c6x-xpmx.json b/advisories/unreviewed/2024/02/GHSA-gp6j-7c6x-xpmx/GHSA-gp6j-7c6x-xpmx.json index 40d78806d29..7ac893b42c7 100644 --- a/advisories/unreviewed/2024/02/GHSA-gp6j-7c6x-xpmx/GHSA-gp6j-7c6x-xpmx.json +++ b/advisories/unreviewed/2024/02/GHSA-gp6j-7c6x-xpmx/GHSA-gp6j-7c6x-xpmx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-hxqj-hr64-7vf7/GHSA-hxqj-hr64-7vf7.json b/advisories/unreviewed/2024/02/GHSA-hxqj-hr64-7vf7/GHSA-hxqj-hr64-7vf7.json index 9f9fcce99fa..eeb5e52056c 100644 --- a/advisories/unreviewed/2024/02/GHSA-hxqj-hr64-7vf7/GHSA-hxqj-hr64-7vf7.json +++ b/advisories/unreviewed/2024/02/GHSA-hxqj-hr64-7vf7/GHSA-hxqj-hr64-7vf7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-j3p2-wv5r-9x82/GHSA-j3p2-wv5r-9x82.json b/advisories/unreviewed/2024/02/GHSA-j3p2-wv5r-9x82/GHSA-j3p2-wv5r-9x82.json index 1a69d687c97..33631f9c1c1 100644 --- a/advisories/unreviewed/2024/02/GHSA-j3p2-wv5r-9x82/GHSA-j3p2-wv5r-9x82.json +++ b/advisories/unreviewed/2024/02/GHSA-j3p2-wv5r-9x82/GHSA-j3p2-wv5r-9x82.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-jhxw-wgr6-6rqc/GHSA-jhxw-wgr6-6rqc.json b/advisories/unreviewed/2024/02/GHSA-jhxw-wgr6-6rqc/GHSA-jhxw-wgr6-6rqc.json index 1e4fdbe78ac..cf8ef893b55 100644 --- a/advisories/unreviewed/2024/02/GHSA-jhxw-wgr6-6rqc/GHSA-jhxw-wgr6-6rqc.json +++ b/advisories/unreviewed/2024/02/GHSA-jhxw-wgr6-6rqc/GHSA-jhxw-wgr6-6rqc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-m32w-wmcr-wvxf/GHSA-m32w-wmcr-wvxf.json b/advisories/unreviewed/2024/02/GHSA-m32w-wmcr-wvxf/GHSA-m32w-wmcr-wvxf.json index f64733eb60d..22c4fefec6c 100644 --- a/advisories/unreviewed/2024/02/GHSA-m32w-wmcr-wvxf/GHSA-m32w-wmcr-wvxf.json +++ b/advisories/unreviewed/2024/02/GHSA-m32w-wmcr-wvxf/GHSA-m32w-wmcr-wvxf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-mcfj-9jjf-96q9/GHSA-mcfj-9jjf-96q9.json b/advisories/unreviewed/2024/02/GHSA-mcfj-9jjf-96q9/GHSA-mcfj-9jjf-96q9.json index 5651051cfcc..1588a8c274c 100644 --- a/advisories/unreviewed/2024/02/GHSA-mcfj-9jjf-96q9/GHSA-mcfj-9jjf-96q9.json +++ b/advisories/unreviewed/2024/02/GHSA-mcfj-9jjf-96q9/GHSA-mcfj-9jjf-96q9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-p9j3-jrc9-jv9h/GHSA-p9j3-jrc9-jv9h.json b/advisories/unreviewed/2024/02/GHSA-p9j3-jrc9-jv9h/GHSA-p9j3-jrc9-jv9h.json index 86f857bd9bb..3d0d2cd8117 100644 --- a/advisories/unreviewed/2024/02/GHSA-p9j3-jrc9-jv9h/GHSA-p9j3-jrc9-jv9h.json +++ b/advisories/unreviewed/2024/02/GHSA-p9j3-jrc9-jv9h/GHSA-p9j3-jrc9-jv9h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-pp3r-rxpr-h8mc/GHSA-pp3r-rxpr-h8mc.json b/advisories/unreviewed/2024/02/GHSA-pp3r-rxpr-h8mc/GHSA-pp3r-rxpr-h8mc.json index 77b0d9a25de..55dcd0048f6 100644 --- a/advisories/unreviewed/2024/02/GHSA-pp3r-rxpr-h8mc/GHSA-pp3r-rxpr-h8mc.json +++ b/advisories/unreviewed/2024/02/GHSA-pp3r-rxpr-h8mc/GHSA-pp3r-rxpr-h8mc.json @@ -7,12 +7,8 @@ "CVE-2023-45874" ], "details": "An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-prhj-8562-p8gj/GHSA-prhj-8562-p8gj.json b/advisories/unreviewed/2024/02/GHSA-prhj-8562-p8gj/GHSA-prhj-8562-p8gj.json index 3afee648205..a82eb281aa5 100644 --- a/advisories/unreviewed/2024/02/GHSA-prhj-8562-p8gj/GHSA-prhj-8562-p8gj.json +++ b/advisories/unreviewed/2024/02/GHSA-prhj-8562-p8gj/GHSA-prhj-8562-p8gj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-prwg-rhfj-26j7/GHSA-prwg-rhfj-26j7.json b/advisories/unreviewed/2024/02/GHSA-prwg-rhfj-26j7/GHSA-prwg-rhfj-26j7.json index 76ff7d967b1..19879087cd2 100644 --- a/advisories/unreviewed/2024/02/GHSA-prwg-rhfj-26j7/GHSA-prwg-rhfj-26j7.json +++ b/advisories/unreviewed/2024/02/GHSA-prwg-rhfj-26j7/GHSA-prwg-rhfj-26j7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-r5qg-76hh-gr9p/GHSA-r5qg-76hh-gr9p.json b/advisories/unreviewed/2024/02/GHSA-r5qg-76hh-gr9p/GHSA-r5qg-76hh-gr9p.json index 2517342980c..fe517a46896 100644 --- a/advisories/unreviewed/2024/02/GHSA-r5qg-76hh-gr9p/GHSA-r5qg-76hh-gr9p.json +++ b/advisories/unreviewed/2024/02/GHSA-r5qg-76hh-gr9p/GHSA-r5qg-76hh-gr9p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-rfw9-hv5h-2w85/GHSA-rfw9-hv5h-2w85.json b/advisories/unreviewed/2024/02/GHSA-rfw9-hv5h-2w85/GHSA-rfw9-hv5h-2w85.json index e5fbbc002ee..9b2b0560b37 100644 --- a/advisories/unreviewed/2024/02/GHSA-rfw9-hv5h-2w85/GHSA-rfw9-hv5h-2w85.json +++ b/advisories/unreviewed/2024/02/GHSA-rfw9-hv5h-2w85/GHSA-rfw9-hv5h-2w85.json @@ -7,12 +7,8 @@ "CVE-2023-49930" ], "details": "An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json b/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json index 8936e663e2b..f2f22ddbf32 100644 --- a/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json +++ b/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-xfvp-h462-p6q2/GHSA-xfvp-h462-p6q2.json b/advisories/unreviewed/2024/02/GHSA-xfvp-h462-p6q2/GHSA-xfvp-h462-p6q2.json index ec41031f460..f381b520096 100644 --- a/advisories/unreviewed/2024/02/GHSA-xfvp-h462-p6q2/GHSA-xfvp-h462-p6q2.json +++ b/advisories/unreviewed/2024/02/GHSA-xfvp-h462-p6q2/GHSA-xfvp-h462-p6q2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-2cpc-3p3h-5rwq/GHSA-2cpc-3p3h-5rwq.json b/advisories/unreviewed/2024/03/GHSA-2cpc-3p3h-5rwq/GHSA-2cpc-3p3h-5rwq.json index bb617d32018..5d2d242d7a1 100644 --- a/advisories/unreviewed/2024/03/GHSA-2cpc-3p3h-5rwq/GHSA-2cpc-3p3h-5rwq.json +++ b/advisories/unreviewed/2024/03/GHSA-2cpc-3p3h-5rwq/GHSA-2cpc-3p3h-5rwq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-2fv8-55wf-gg3v/GHSA-2fv8-55wf-gg3v.json b/advisories/unreviewed/2024/03/GHSA-2fv8-55wf-gg3v/GHSA-2fv8-55wf-gg3v.json index 5120d59c754..b694ef15d09 100644 --- a/advisories/unreviewed/2024/03/GHSA-2fv8-55wf-gg3v/GHSA-2fv8-55wf-gg3v.json +++ b/advisories/unreviewed/2024/03/GHSA-2fv8-55wf-gg3v/GHSA-2fv8-55wf-gg3v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-2v7w-v8fj-mf99/GHSA-2v7w-v8fj-mf99.json b/advisories/unreviewed/2024/03/GHSA-2v7w-v8fj-mf99/GHSA-2v7w-v8fj-mf99.json index 461414395bd..9e22a0f3e7c 100644 --- a/advisories/unreviewed/2024/03/GHSA-2v7w-v8fj-mf99/GHSA-2v7w-v8fj-mf99.json +++ b/advisories/unreviewed/2024/03/GHSA-2v7w-v8fj-mf99/GHSA-2v7w-v8fj-mf99.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-33v3-2qxj-vgv5/GHSA-33v3-2qxj-vgv5.json b/advisories/unreviewed/2024/03/GHSA-33v3-2qxj-vgv5/GHSA-33v3-2qxj-vgv5.json index f339d197393..c8d2213b61c 100644 --- a/advisories/unreviewed/2024/03/GHSA-33v3-2qxj-vgv5/GHSA-33v3-2qxj-vgv5.json +++ b/advisories/unreviewed/2024/03/GHSA-33v3-2qxj-vgv5/GHSA-33v3-2qxj-vgv5.json @@ -7,12 +7,8 @@ "CVE-2024-26636" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nllc: make llc_ui_sendmsg() more robust against bonding changes\n\nsyzbot was able to trick llc_ui_sendmsg(), allocating an skb with no\nheadroom, but subsequently trying to push 14 bytes of Ethernet header [1]\n\nLike some others, llc_ui_sendmsg() releases the socket lock before\ncalling sock_alloc_send_skb().\nThen it acquires it again, but does not redo all the sanity checks\nthat were performed.\n\nThis fix:\n\n- Uses LL_RESERVED_SPACE() to reserve space.\n- Check all conditions again after socket lock is held again.\n- Do not account Ethernet header for mtu limitation.\n\n[1]\n\nskbuff: skb_under_panic: text:ffff800088baa334 len:1514 put:14 head:ffff0000c9c37000 data:ffff0000c9c36ff2 tail:0x5dc end:0x6c0 dev:bond0\n\n kernel BUG at net/core/skbuff.c:193 !\nInternal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP\nModules linked in:\nCPU: 0 PID: 6875 Comm: syz-executor.0 Not tainted 6.7.0-rc8-syzkaller-00101-g0802e17d9aca-dirty #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023\npstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : skb_panic net/core/skbuff.c:189 [inline]\n pc : skb_under_panic+0x13c/0x140 net/core/skbuff.c:203\n lr : skb_panic net/core/skbuff.c:189 [inline]\n lr : skb_under_panic+0x13c/0x140 net/core/skbuff.c:203\nsp : ffff800096f97000\nx29: ffff800096f97010 x28: ffff80008cc8d668 x27: dfff800000000000\nx26: ffff0000cb970c90 x25: 00000000000005dc x24: ffff0000c9c36ff2\nx23: ffff0000c9c37000 x22: 00000000000005ea x21: 00000000000006c0\nx20: 000000000000000e x19: ffff800088baa334 x18: 1fffe000368261ce\nx17: ffff80008e4ed000 x16: ffff80008a8310f8 x15: 0000000000000001\nx14: 1ffff00012df2d58 x13: 0000000000000000 x12: 0000000000000000\nx11: 0000000000000001 x10: 0000000000ff0100 x9 : e28a51f1087e8400\nx8 : e28a51f1087e8400 x7 : ffff80008028f8d0 x6 : 0000000000000000\nx5 : 0000000000000001 x4 : 0000000000000001 x3 : ffff800082b78714\nx2 : 0000000000000001 x1 : 0000000100000000 x0 : 0000000000000089\nCall trace:\n skb_panic net/core/skbuff.c:189 [inline]\n skb_under_panic+0x13c/0x140 net/core/skbuff.c:203\n skb_push+0xf0/0x108 net/core/skbuff.c:2451\n eth_header+0x44/0x1f8 net/ethernet/eth.c:83\n dev_hard_header include/linux/netdevice.h:3188 [inline]\n llc_mac_hdr_init+0x110/0x17c net/llc/llc_output.c:33\n llc_sap_action_send_xid_c+0x170/0x344 net/llc/llc_s_ac.c:85\n llc_exec_sap_trans_actions net/llc/llc_sap.c:153 [inline]\n llc_sap_next_state net/llc/llc_sap.c:182 [inline]\n llc_sap_state_process+0x1ec/0x774 net/llc/llc_sap.c:209\n llc_build_and_send_xid_pkt+0x12c/0x1c0 net/llc/llc_sap.c:270\n llc_ui_sendmsg+0x7bc/0xb1c net/llc/af_llc.c:997\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg net/socket.c:745 [inline]\n sock_sendmsg+0x194/0x274 net/socket.c:767\n splice_to_socket+0x7cc/0xd58 fs/splice.c:881\n do_splice_from fs/splice.c:933 [inline]\n direct_splice_actor+0xe4/0x1c0 fs/splice.c:1142\n splice_direct_to_actor+0x2a0/0x7e4 fs/splice.c:1088\n do_splice_direct+0x20c/0x348 fs/splice.c:1194\n do_sendfile+0x4bc/0xc70 fs/read_write.c:1254\n __do_sys_sendfile64 fs/read_write.c:1322 [inline]\n __se_sys_sendfile64 fs/read_write.c:1308 [inline]\n __arm64_sys_sendfile64+0x160/0x3b4 fs/read_write.c:1308\n __invoke_syscall arch/arm64/kernel/syscall.c:37 [inline]\n invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:51\n el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:136\n do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:155\n el0_svc+0x54/0x158 arch/arm64/kernel/entry-common.c:678\n el0t_64_sync_handler+0x84/0xfc arch/arm64/kernel/entry-common.c:696\n el0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:595\nCode: aa1803e6 aa1903e7 a90023f5 94792f6a (d4210000)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-35c8-rp3m-p5v6/GHSA-35c8-rp3m-p5v6.json b/advisories/unreviewed/2024/03/GHSA-35c8-rp3m-p5v6/GHSA-35c8-rp3m-p5v6.json index 635297d99ff..5f1992c780d 100644 --- a/advisories/unreviewed/2024/03/GHSA-35c8-rp3m-p5v6/GHSA-35c8-rp3m-p5v6.json +++ b/advisories/unreviewed/2024/03/GHSA-35c8-rp3m-p5v6/GHSA-35c8-rp3m-p5v6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-3gf3-x9x8-839v/GHSA-3gf3-x9x8-839v.json b/advisories/unreviewed/2024/03/GHSA-3gf3-x9x8-839v/GHSA-3gf3-x9x8-839v.json index 761c3a5b810..0e2d6d6d592 100644 --- a/advisories/unreviewed/2024/03/GHSA-3gf3-x9x8-839v/GHSA-3gf3-x9x8-839v.json +++ b/advisories/unreviewed/2024/03/GHSA-3gf3-x9x8-839v/GHSA-3gf3-x9x8-839v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-3pmw-h7mc-vxxq/GHSA-3pmw-h7mc-vxxq.json b/advisories/unreviewed/2024/03/GHSA-3pmw-h7mc-vxxq/GHSA-3pmw-h7mc-vxxq.json index 3082f70a03a..fde2cdf0c00 100644 --- a/advisories/unreviewed/2024/03/GHSA-3pmw-h7mc-vxxq/GHSA-3pmw-h7mc-vxxq.json +++ b/advisories/unreviewed/2024/03/GHSA-3pmw-h7mc-vxxq/GHSA-3pmw-h7mc-vxxq.json @@ -7,12 +7,8 @@ "CVE-2024-26641" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()\n\nsyzbot found __ip6_tnl_rcv() could access unitiliazed data [1].\n\nCall pskb_inet_may_pull() to fix this, and initialize ipv6h\nvariable after this call as it can change skb->head.\n\n[1]\n BUG: KMSAN: uninit-value in __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline]\n BUG: KMSAN: uninit-value in INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline]\n BUG: KMSAN: uninit-value in IP6_ECN_decapsulate+0x7df/0x1e50 include/net/inet_ecn.h:321\n __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline]\n INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline]\n IP6_ECN_decapsulate+0x7df/0x1e50 include/net/inet_ecn.h:321\n ip6ip6_dscp_ecn_decapsulate+0x178/0x1b0 net/ipv6/ip6_tunnel.c:727\n __ip6_tnl_rcv+0xd4e/0x1590 net/ipv6/ip6_tunnel.c:845\n ip6_tnl_rcv+0xce/0x100 net/ipv6/ip6_tunnel.c:888\n gre_rcv+0x143f/0x1870\n ip6_protocol_deliver_rcu+0xda6/0x2a60 net/ipv6/ip6_input.c:438\n ip6_input_finish net/ipv6/ip6_input.c:483 [inline]\n NF_HOOK include/linux/netfilter.h:314 [inline]\n ip6_input+0x15d/0x430 net/ipv6/ip6_input.c:492\n ip6_mc_input+0xa7e/0xc80 net/ipv6/ip6_input.c:586\n dst_input include/net/dst.h:461 [inline]\n ip6_rcv_finish+0x5db/0x870 net/ipv6/ip6_input.c:79\n NF_HOOK include/linux/netfilter.h:314 [inline]\n ipv6_rcv+0xda/0x390 net/ipv6/ip6_input.c:310\n __netif_receive_skb_one_core net/core/dev.c:5532 [inline]\n __netif_receive_skb+0x1a6/0x5a0 net/core/dev.c:5646\n netif_receive_skb_internal net/core/dev.c:5732 [inline]\n netif_receive_skb+0x58/0x660 net/core/dev.c:5791\n tun_rx_batched+0x3ee/0x980 drivers/net/tun.c:1555\n tun_get_user+0x53af/0x66d0 drivers/net/tun.c:2002\n tun_chr_write_iter+0x3af/0x5d0 drivers/net/tun.c:2048\n call_write_iter include/linux/fs.h:2084 [inline]\n new_sync_write fs/read_write.c:497 [inline]\n vfs_write+0x786/0x1200 fs/read_write.c:590\n ksys_write+0x20f/0x4c0 fs/read_write.c:643\n __do_sys_write fs/read_write.c:655 [inline]\n __se_sys_write fs/read_write.c:652 [inline]\n __x64_sys_write+0x93/0xd0 fs/read_write.c:652\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0x6d/0x140 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nUninit was created at:\n slab_post_alloc_hook+0x129/0xa70 mm/slab.h:768\n slab_alloc_node mm/slub.c:3478 [inline]\n kmem_cache_alloc_node+0x5e9/0xb10 mm/slub.c:3523\n kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:560\n __alloc_skb+0x318/0x740 net/core/skbuff.c:651\n alloc_skb include/linux/skbuff.h:1286 [inline]\n alloc_skb_with_frags+0xc8/0xbd0 net/core/skbuff.c:6334\n sock_alloc_send_pskb+0xa80/0xbf0 net/core/sock.c:2787\n tun_alloc_skb drivers/net/tun.c:1531 [inline]\n tun_get_user+0x1e8a/0x66d0 drivers/net/tun.c:1846\n tun_chr_write_iter+0x3af/0x5d0 drivers/net/tun.c:2048\n call_write_iter include/linux/fs.h:2084 [inline]\n new_sync_write fs/read_write.c:497 [inline]\n vfs_write+0x786/0x1200 fs/read_write.c:590\n ksys_write+0x20f/0x4c0 fs/read_write.c:643\n __do_sys_write fs/read_write.c:655 [inline]\n __se_sys_write fs/read_write.c:652 [inline]\n __x64_sys_write+0x93/0xd0 fs/read_write.c:652\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0x6d/0x140 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nCPU: 0 PID: 5034 Comm: syz-executor331 Not tainted 6.7.0-syzkaller-00562-g9f8413c4a66f #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-3q2c-pvp5-3cqp/GHSA-3q2c-pvp5-3cqp.json b/advisories/unreviewed/2024/03/GHSA-3q2c-pvp5-3cqp/GHSA-3q2c-pvp5-3cqp.json index d9825464ee6..52524745a5c 100644 --- a/advisories/unreviewed/2024/03/GHSA-3q2c-pvp5-3cqp/GHSA-3q2c-pvp5-3cqp.json +++ b/advisories/unreviewed/2024/03/GHSA-3q2c-pvp5-3cqp/GHSA-3q2c-pvp5-3cqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-3q9p-96fp-f2w2/GHSA-3q9p-96fp-f2w2.json b/advisories/unreviewed/2024/03/GHSA-3q9p-96fp-f2w2/GHSA-3q9p-96fp-f2w2.json index 06ff7a97aff..11cbe49a7a1 100644 --- a/advisories/unreviewed/2024/03/GHSA-3q9p-96fp-f2w2/GHSA-3q9p-96fp-f2w2.json +++ b/advisories/unreviewed/2024/03/GHSA-3q9p-96fp-f2w2/GHSA-3q9p-96fp-f2w2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-48q5-x6fp-8893/GHSA-48q5-x6fp-8893.json b/advisories/unreviewed/2024/03/GHSA-48q5-x6fp-8893/GHSA-48q5-x6fp-8893.json index 76d3a05f732..3e2ec3cbfc7 100644 --- a/advisories/unreviewed/2024/03/GHSA-48q5-x6fp-8893/GHSA-48q5-x6fp-8893.json +++ b/advisories/unreviewed/2024/03/GHSA-48q5-x6fp-8893/GHSA-48q5-x6fp-8893.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-49h9-qx93-p659/GHSA-49h9-qx93-p659.json b/advisories/unreviewed/2024/03/GHSA-49h9-qx93-p659/GHSA-49h9-qx93-p659.json index cab053d8af5..d8b30016452 100644 --- a/advisories/unreviewed/2024/03/GHSA-49h9-qx93-p659/GHSA-49h9-qx93-p659.json +++ b/advisories/unreviewed/2024/03/GHSA-49h9-qx93-p659/GHSA-49h9-qx93-p659.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-52jg-m3rm-ch68/GHSA-52jg-m3rm-ch68.json b/advisories/unreviewed/2024/03/GHSA-52jg-m3rm-ch68/GHSA-52jg-m3rm-ch68.json index 6e304a75a93..5d058bed487 100644 --- a/advisories/unreviewed/2024/03/GHSA-52jg-m3rm-ch68/GHSA-52jg-m3rm-ch68.json +++ b/advisories/unreviewed/2024/03/GHSA-52jg-m3rm-ch68/GHSA-52jg-m3rm-ch68.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-5gr3-55rj-mm4c/GHSA-5gr3-55rj-mm4c.json b/advisories/unreviewed/2024/03/GHSA-5gr3-55rj-mm4c/GHSA-5gr3-55rj-mm4c.json index 07cffe68c7a..c7fbc7c6eb7 100644 --- a/advisories/unreviewed/2024/03/GHSA-5gr3-55rj-mm4c/GHSA-5gr3-55rj-mm4c.json +++ b/advisories/unreviewed/2024/03/GHSA-5gr3-55rj-mm4c/GHSA-5gr3-55rj-mm4c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-5q32-895v-vf2f/GHSA-5q32-895v-vf2f.json b/advisories/unreviewed/2024/03/GHSA-5q32-895v-vf2f/GHSA-5q32-895v-vf2f.json index 948fc9310bb..a3d8be14b8f 100644 --- a/advisories/unreviewed/2024/03/GHSA-5q32-895v-vf2f/GHSA-5q32-895v-vf2f.json +++ b/advisories/unreviewed/2024/03/GHSA-5q32-895v-vf2f/GHSA-5q32-895v-vf2f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-6847-vh78-7f9c/GHSA-6847-vh78-7f9c.json b/advisories/unreviewed/2024/03/GHSA-6847-vh78-7f9c/GHSA-6847-vh78-7f9c.json index 30782656e9e..13641c323de 100644 --- a/advisories/unreviewed/2024/03/GHSA-6847-vh78-7f9c/GHSA-6847-vh78-7f9c.json +++ b/advisories/unreviewed/2024/03/GHSA-6847-vh78-7f9c/GHSA-6847-vh78-7f9c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-6pc8-76w2-c62h/GHSA-6pc8-76w2-c62h.json b/advisories/unreviewed/2024/03/GHSA-6pc8-76w2-c62h/GHSA-6pc8-76w2-c62h.json index f7ad501818f..633569e0601 100644 --- a/advisories/unreviewed/2024/03/GHSA-6pc8-76w2-c62h/GHSA-6pc8-76w2-c62h.json +++ b/advisories/unreviewed/2024/03/GHSA-6pc8-76w2-c62h/GHSA-6pc8-76w2-c62h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-6q28-45j9-263v/GHSA-6q28-45j9-263v.json b/advisories/unreviewed/2024/03/GHSA-6q28-45j9-263v/GHSA-6q28-45j9-263v.json index e92dd1fe34f..5918470cba7 100644 --- a/advisories/unreviewed/2024/03/GHSA-6q28-45j9-263v/GHSA-6q28-45j9-263v.json +++ b/advisories/unreviewed/2024/03/GHSA-6q28-45j9-263v/GHSA-6q28-45j9-263v.json @@ -7,12 +7,8 @@ "CVE-2024-26640" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: add sanity checks to rx zerocopy\n\nTCP rx zerocopy intent is to map pages initially allocated\nfrom NIC drivers, not pages owned by a fs.\n\nThis patch adds to can_map_frag() these additional checks:\n\n- Page must not be a compound one.\n- page->mapping must be NULL.\n\nThis fixes the panic reported by ZhangPeng.\n\nsyzbot was able to loopback packets built with sendfile(),\nmapping pages owned by an ext4 file to TCP rx zerocopy.\n\nr3 = socket$inet_tcp(0x2, 0x1, 0x0)\nmmap(&(0x7f0000ff9000/0x4000)=nil, 0x4000, 0x0, 0x12, r3, 0x0)\nr4 = socket$inet_tcp(0x2, 0x1, 0x0)\nbind$inet(r4, &(0x7f0000000000)={0x2, 0x4e24, @multicast1}, 0x10)\nconnect$inet(r4, &(0x7f00000006c0)={0x2, 0x4e24, @empty}, 0x10)\nr5 = openat$dir(0xffffffffffffff9c, &(0x7f00000000c0)='./file0\\x00',\n 0x181e42, 0x0)\nfallocate(r5, 0x0, 0x0, 0x85b8)\nsendfile(r4, r5, 0x0, 0x8ba0)\ngetsockopt$inet_tcp_TCP_ZEROCOPY_RECEIVE(r4, 0x6, 0x23,\n &(0x7f00000001c0)={&(0x7f0000ffb000/0x3000)=nil, 0x3000, 0x0, 0x0, 0x0,\n 0x0, 0x0, 0x0, 0x0}, &(0x7f0000000440)=0x40)\nr6 = openat$dir(0xffffffffffffff9c, &(0x7f00000000c0)='./file0\\x00',\n 0x181e42, 0x0)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-6xfp-26pf-r3p6/GHSA-6xfp-26pf-r3p6.json b/advisories/unreviewed/2024/03/GHSA-6xfp-26pf-r3p6/GHSA-6xfp-26pf-r3p6.json index e67e36ab751..ea15d92a8ce 100644 --- a/advisories/unreviewed/2024/03/GHSA-6xfp-26pf-r3p6/GHSA-6xfp-26pf-r3p6.json +++ b/advisories/unreviewed/2024/03/GHSA-6xfp-26pf-r3p6/GHSA-6xfp-26pf-r3p6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-79wp-fmwh-x929/GHSA-79wp-fmwh-x929.json b/advisories/unreviewed/2024/03/GHSA-79wp-fmwh-x929/GHSA-79wp-fmwh-x929.json index 3d9e18d25f1..87934916ace 100644 --- a/advisories/unreviewed/2024/03/GHSA-79wp-fmwh-x929/GHSA-79wp-fmwh-x929.json +++ b/advisories/unreviewed/2024/03/GHSA-79wp-fmwh-x929/GHSA-79wp-fmwh-x929.json @@ -7,12 +7,8 @@ "CVE-2024-26642" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: disallow anonymous set with timeout flag\n\nAnonymous sets are never used with timeout from userspace, reject this.\nException to this rule is NFT_SET_EVAL to ensure legacy meters still work.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-7xrf-xg7m-8rqp/GHSA-7xrf-xg7m-8rqp.json b/advisories/unreviewed/2024/03/GHSA-7xrf-xg7m-8rqp/GHSA-7xrf-xg7m-8rqp.json index 67c659eee99..dc79dc29fbd 100644 --- a/advisories/unreviewed/2024/03/GHSA-7xrf-xg7m-8rqp/GHSA-7xrf-xg7m-8rqp.json +++ b/advisories/unreviewed/2024/03/GHSA-7xrf-xg7m-8rqp/GHSA-7xrf-xg7m-8rqp.json @@ -7,12 +7,8 @@ "CVE-2024-28456" ], "details": "Cross Site Scripting vulnerability in Campcodes Online Marriage Registration System v.1.0 allows a remote attacker to execute arbitrary code via the text fields in the marriage registration request form.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-8p4p-wmq5-rmgp/GHSA-8p4p-wmq5-rmgp.json b/advisories/unreviewed/2024/03/GHSA-8p4p-wmq5-rmgp/GHSA-8p4p-wmq5-rmgp.json index 1344e8468c7..47c4b37b79f 100644 --- a/advisories/unreviewed/2024/03/GHSA-8p4p-wmq5-rmgp/GHSA-8p4p-wmq5-rmgp.json +++ b/advisories/unreviewed/2024/03/GHSA-8p4p-wmq5-rmgp/GHSA-8p4p-wmq5-rmgp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-8q2g-9f98-xxwf/GHSA-8q2g-9f98-xxwf.json b/advisories/unreviewed/2024/03/GHSA-8q2g-9f98-xxwf/GHSA-8q2g-9f98-xxwf.json index f8478639c2a..ec2ee6ee2c3 100644 --- a/advisories/unreviewed/2024/03/GHSA-8q2g-9f98-xxwf/GHSA-8q2g-9f98-xxwf.json +++ b/advisories/unreviewed/2024/03/GHSA-8q2g-9f98-xxwf/GHSA-8q2g-9f98-xxwf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-9rrq-f95g-4wmq/GHSA-9rrq-f95g-4wmq.json b/advisories/unreviewed/2024/03/GHSA-9rrq-f95g-4wmq/GHSA-9rrq-f95g-4wmq.json index 9ea426a52d2..fed7f5f7f0b 100644 --- a/advisories/unreviewed/2024/03/GHSA-9rrq-f95g-4wmq/GHSA-9rrq-f95g-4wmq.json +++ b/advisories/unreviewed/2024/03/GHSA-9rrq-f95g-4wmq/GHSA-9rrq-f95g-4wmq.json @@ -7,12 +7,8 @@ "CVE-2024-26625" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nllc: call sock_orphan() at release time\n\nsyzbot reported an interesting trace [1] caused by a stale sk->sk_wq\npointer in a closed llc socket.\n\nIn commit ff7b11aa481f (\"net: socket: set sock->sk to NULL after\ncalling proto_ops::release()\") Eric Biggers hinted that some protocols\nare missing a sock_orphan(), we need to perform a full audit.\n\nIn net-next, I plan to clear sock->sk from sock_orphan() and\namend Eric patch to add a warning.\n\n[1]\n BUG: KASAN: slab-use-after-free in list_empty include/linux/list.h:373 [inline]\n BUG: KASAN: slab-use-after-free in waitqueue_active include/linux/wait.h:127 [inline]\n BUG: KASAN: slab-use-after-free in sock_def_write_space_wfree net/core/sock.c:3384 [inline]\n BUG: KASAN: slab-use-after-free in sock_wfree+0x9a8/0x9d0 net/core/sock.c:2468\nRead of size 8 at addr ffff88802f4fc880 by task ksoftirqd/1/27\n\nCPU: 1 PID: 27 Comm: ksoftirqd/1 Not tainted 6.8.0-rc1-syzkaller-00049-g6098d87eaf31 #0\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xd9/0x1b0 lib/dump_stack.c:106\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0xc4/0x620 mm/kasan/report.c:488\n kasan_report+0xda/0x110 mm/kasan/report.c:601\n list_empty include/linux/list.h:373 [inline]\n waitqueue_active include/linux/wait.h:127 [inline]\n sock_def_write_space_wfree net/core/sock.c:3384 [inline]\n sock_wfree+0x9a8/0x9d0 net/core/sock.c:2468\n skb_release_head_state+0xa3/0x2b0 net/core/skbuff.c:1080\n skb_release_all net/core/skbuff.c:1092 [inline]\n napi_consume_skb+0x119/0x2b0 net/core/skbuff.c:1404\n e1000_unmap_and_free_tx_resource+0x144/0x200 drivers/net/ethernet/intel/e1000/e1000_main.c:1970\n e1000_clean_tx_irq drivers/net/ethernet/intel/e1000/e1000_main.c:3860 [inline]\n e1000_clean+0x4a1/0x26e0 drivers/net/ethernet/intel/e1000/e1000_main.c:3801\n __napi_poll.constprop.0+0xb4/0x540 net/core/dev.c:6576\n napi_poll net/core/dev.c:6645 [inline]\n net_rx_action+0x956/0xe90 net/core/dev.c:6778\n __do_softirq+0x21a/0x8de kernel/softirq.c:553\n run_ksoftirqd kernel/softirq.c:921 [inline]\n run_ksoftirqd+0x31/0x60 kernel/softirq.c:913\n smpboot_thread_fn+0x660/0xa10 kernel/smpboot.c:164\n kthread+0x2c6/0x3a0 kernel/kthread.c:388\n ret_from_fork+0x45/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:242\n \n\nAllocated by task 5167:\n kasan_save_stack+0x33/0x50 mm/kasan/common.c:47\n kasan_save_track+0x14/0x30 mm/kasan/common.c:68\n unpoison_slab_object mm/kasan/common.c:314 [inline]\n __kasan_slab_alloc+0x81/0x90 mm/kasan/common.c:340\n kasan_slab_alloc include/linux/kasan.h:201 [inline]\n slab_post_alloc_hook mm/slub.c:3813 [inline]\n slab_alloc_node mm/slub.c:3860 [inline]\n kmem_cache_alloc_lru+0x142/0x6f0 mm/slub.c:3879\n alloc_inode_sb include/linux/fs.h:3019 [inline]\n sock_alloc_inode+0x25/0x1c0 net/socket.c:308\n alloc_inode+0x5d/0x220 fs/inode.c:260\n new_inode_pseudo+0x16/0x80 fs/inode.c:1005\n sock_alloc+0x40/0x270 net/socket.c:634\n __sock_create+0xbc/0x800 net/socket.c:1535\n sock_create net/socket.c:1622 [inline]\n __sys_socket_create net/socket.c:1659 [inline]\n __sys_socket+0x14c/0x260 net/socket.c:1706\n __do_sys_socket net/socket.c:1720 [inline]\n __se_sys_socket net/socket.c:1718 [inline]\n __x64_sys_socket+0x72/0xb0 net/socket.c:1718\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xd3/0x250 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nFreed by task 0:\n kasan_save_stack+0x33/0x50 mm/kasan/common.c:47\n kasan_save_track+0x14/0x30 mm/kasan/common.c:68\n kasan_save_free_info+0x3f/0x60 mm/kasan/generic.c:640\n poison_slab_object mm/kasan/common.c:241 [inline]\n __kasan_slab_free+0x121/0x1b0 mm/kasan/common.c:257\n kasan_slab_free include/linux/kasan.h:184 [inline]\n slab_free_hook mm/slub.c:2121 [inlin\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-9wr4-x5hv-2rw2/GHSA-9wr4-x5hv-2rw2.json b/advisories/unreviewed/2024/03/GHSA-9wr4-x5hv-2rw2/GHSA-9wr4-x5hv-2rw2.json index 8b8741c5ec8..b64b85d1948 100644 --- a/advisories/unreviewed/2024/03/GHSA-9wr4-x5hv-2rw2/GHSA-9wr4-x5hv-2rw2.json +++ b/advisories/unreviewed/2024/03/GHSA-9wr4-x5hv-2rw2/GHSA-9wr4-x5hv-2rw2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-c23g-g2cr-qgh6/GHSA-c23g-g2cr-qgh6.json b/advisories/unreviewed/2024/03/GHSA-c23g-g2cr-qgh6/GHSA-c23g-g2cr-qgh6.json index 198d7112971..53a1ccd84d9 100644 --- a/advisories/unreviewed/2024/03/GHSA-c23g-g2cr-qgh6/GHSA-c23g-g2cr-qgh6.json +++ b/advisories/unreviewed/2024/03/GHSA-c23g-g2cr-qgh6/GHSA-c23g-g2cr-qgh6.json @@ -7,12 +7,8 @@ "CVE-2024-27613" ], "details": "Numbas editor before 7.3 mishandles reading of themes and extensions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-c52j-w2rg-37q5/GHSA-c52j-w2rg-37q5.json b/advisories/unreviewed/2024/03/GHSA-c52j-w2rg-37q5/GHSA-c52j-w2rg-37q5.json index 14a79c7698e..41e8910d130 100644 --- a/advisories/unreviewed/2024/03/GHSA-c52j-w2rg-37q5/GHSA-c52j-w2rg-37q5.json +++ b/advisories/unreviewed/2024/03/GHSA-c52j-w2rg-37q5/GHSA-c52j-w2rg-37q5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-c534-6v46-r777/GHSA-c534-6v46-r777.json b/advisories/unreviewed/2024/03/GHSA-c534-6v46-r777/GHSA-c534-6v46-r777.json index da17a6055b3..962f55a3dc8 100644 --- a/advisories/unreviewed/2024/03/GHSA-c534-6v46-r777/GHSA-c534-6v46-r777.json +++ b/advisories/unreviewed/2024/03/GHSA-c534-6v46-r777/GHSA-c534-6v46-r777.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-cf55-f79q-6cgp/GHSA-cf55-f79q-6cgp.json b/advisories/unreviewed/2024/03/GHSA-cf55-f79q-6cgp/GHSA-cf55-f79q-6cgp.json index 9efa7c56f43..efc9c31363d 100644 --- a/advisories/unreviewed/2024/03/GHSA-cf55-f79q-6cgp/GHSA-cf55-f79q-6cgp.json +++ b/advisories/unreviewed/2024/03/GHSA-cf55-f79q-6cgp/GHSA-cf55-f79q-6cgp.json @@ -7,12 +7,8 @@ "CVE-2024-26615" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix illegal rmb_desc access in SMC-D connection dump\n\nA crash was found when dumping SMC-D connections. It can be reproduced\nby following steps:\n\n- run nginx/wrk test:\n smc_run nginx\n smc_run wrk -t 16 -c 1000 -d -H 'Connection: Close' \n\n- continuously dump SMC-D connections in parallel:\n watch -n 1 'smcss -D'\n\n BUG: kernel NULL pointer dereference, address: 0000000000000030\n CPU: 2 PID: 7204 Comm: smcss Kdump: loaded Tainted: G\tE 6.7.0+ #55\n RIP: 0010:__smc_diag_dump.constprop.0+0x5e5/0x620 [smc_diag]\n Call Trace:\n \n ? __die+0x24/0x70\n ? page_fault_oops+0x66/0x150\n ? exc_page_fault+0x69/0x140\n ? asm_exc_page_fault+0x26/0x30\n ? __smc_diag_dump.constprop.0+0x5e5/0x620 [smc_diag]\n ? __kmalloc_node_track_caller+0x35d/0x430\n ? __alloc_skb+0x77/0x170\n smc_diag_dump_proto+0xd0/0xf0 [smc_diag]\n smc_diag_dump+0x26/0x60 [smc_diag]\n netlink_dump+0x19f/0x320\n __netlink_dump_start+0x1dc/0x300\n smc_diag_handler_dump+0x6a/0x80 [smc_diag]\n ? __pfx_smc_diag_dump+0x10/0x10 [smc_diag]\n sock_diag_rcv_msg+0x121/0x140\n ? __pfx_sock_diag_rcv_msg+0x10/0x10\n netlink_rcv_skb+0x5a/0x110\n sock_diag_rcv+0x28/0x40\n netlink_unicast+0x22a/0x330\n netlink_sendmsg+0x1f8/0x420\n __sock_sendmsg+0xb0/0xc0\n ____sys_sendmsg+0x24e/0x300\n ? copy_msghdr_from_user+0x62/0x80\n ___sys_sendmsg+0x7c/0xd0\n ? __do_fault+0x34/0x160\n ? do_read_fault+0x5f/0x100\n ? do_fault+0xb0/0x110\n ? __handle_mm_fault+0x2b0/0x6c0\n __sys_sendmsg+0x4d/0x80\n do_syscall_64+0x69/0x180\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\nIt is possible that the connection is in process of being established\nwhen we dump it. Assumed that the connection has been registered in a\nlink group by smc_conn_create() but the rmb_desc has not yet been\ninitialized by smc_buf_create(), thus causing the illegal access to\nconn->rmb_desc. So fix it by checking before dump.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-fq59-hfgc-4xp6/GHSA-fq59-hfgc-4xp6.json b/advisories/unreviewed/2024/03/GHSA-fq59-hfgc-4xp6/GHSA-fq59-hfgc-4xp6.json index 7a0baf21f30..63883ea03bd 100644 --- a/advisories/unreviewed/2024/03/GHSA-fq59-hfgc-4xp6/GHSA-fq59-hfgc-4xp6.json +++ b/advisories/unreviewed/2024/03/GHSA-fq59-hfgc-4xp6/GHSA-fq59-hfgc-4xp6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-fvc5-hrmq-8hx4/GHSA-fvc5-hrmq-8hx4.json b/advisories/unreviewed/2024/03/GHSA-fvc5-hrmq-8hx4/GHSA-fvc5-hrmq-8hx4.json index f6189ebaf20..dc7634465f5 100644 --- a/advisories/unreviewed/2024/03/GHSA-fvc5-hrmq-8hx4/GHSA-fvc5-hrmq-8hx4.json +++ b/advisories/unreviewed/2024/03/GHSA-fvc5-hrmq-8hx4/GHSA-fvc5-hrmq-8hx4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-g754-37wh-7wv7/GHSA-g754-37wh-7wv7.json b/advisories/unreviewed/2024/03/GHSA-g754-37wh-7wv7/GHSA-g754-37wh-7wv7.json index c51b039c019..ae932a0956f 100644 --- a/advisories/unreviewed/2024/03/GHSA-g754-37wh-7wv7/GHSA-g754-37wh-7wv7.json +++ b/advisories/unreviewed/2024/03/GHSA-g754-37wh-7wv7/GHSA-g754-37wh-7wv7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-gmmm-pvv4-ww8g/GHSA-gmmm-pvv4-ww8g.json b/advisories/unreviewed/2024/03/GHSA-gmmm-pvv4-ww8g/GHSA-gmmm-pvv4-ww8g.json index d12aac7e052..bf7e42e1966 100644 --- a/advisories/unreviewed/2024/03/GHSA-gmmm-pvv4-ww8g/GHSA-gmmm-pvv4-ww8g.json +++ b/advisories/unreviewed/2024/03/GHSA-gmmm-pvv4-ww8g/GHSA-gmmm-pvv4-ww8g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-h4rp-4mpv-g4rm/GHSA-h4rp-4mpv-g4rm.json b/advisories/unreviewed/2024/03/GHSA-h4rp-4mpv-g4rm/GHSA-h4rp-4mpv-g4rm.json index 8445b8fc749..90ec1263174 100644 --- a/advisories/unreviewed/2024/03/GHSA-h4rp-4mpv-g4rm/GHSA-h4rp-4mpv-g4rm.json +++ b/advisories/unreviewed/2024/03/GHSA-h4rp-4mpv-g4rm/GHSA-h4rp-4mpv-g4rm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-hmvg-cx6j-hfj7/GHSA-hmvg-cx6j-hfj7.json b/advisories/unreviewed/2024/03/GHSA-hmvg-cx6j-hfj7/GHSA-hmvg-cx6j-hfj7.json index 07f1712bec5..5063f604768 100644 --- a/advisories/unreviewed/2024/03/GHSA-hmvg-cx6j-hfj7/GHSA-hmvg-cx6j-hfj7.json +++ b/advisories/unreviewed/2024/03/GHSA-hmvg-cx6j-hfj7/GHSA-hmvg-cx6j-hfj7.json @@ -7,12 +7,8 @@ "CVE-2024-26622" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntomoyo: fix UAF write bug in tomoyo_write_control()\n\nSince tomoyo_write_control() updates head->write_buf when write()\nof long lines is requested, we need to fetch head->write_buf after\nhead->io_sem is held. Otherwise, concurrent write() requests can\ncause use-after-free-write and double-free problems.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-hwc8-wrmm-ch4w/GHSA-hwc8-wrmm-ch4w.json b/advisories/unreviewed/2024/03/GHSA-hwc8-wrmm-ch4w/GHSA-hwc8-wrmm-ch4w.json index b9a5665fd61..dc029a67e99 100644 --- a/advisories/unreviewed/2024/03/GHSA-hwc8-wrmm-ch4w/GHSA-hwc8-wrmm-ch4w.json +++ b/advisories/unreviewed/2024/03/GHSA-hwc8-wrmm-ch4w/GHSA-hwc8-wrmm-ch4w.json @@ -7,12 +7,8 @@ "CVE-2024-26645" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Ensure visibility when inserting an element into tracing_map\n\nRunning the following two commands in parallel on a multi-processor\nAArch64 machine can sporadically produce an unexpected warning about\nduplicate histogram entries:\n\n $ while true; do\n echo hist:key=id.syscall:val=hitcount > \\\n /sys/kernel/debug/tracing/events/raw_syscalls/sys_enter/trigger\n cat /sys/kernel/debug/tracing/events/raw_syscalls/sys_enter/hist\n sleep 0.001\n done\n $ stress-ng --sysbadaddr $(nproc)\n\nThe warning looks as follows:\n\n[ 2911.172474] ------------[ cut here ]------------\n[ 2911.173111] Duplicates detected: 1\n[ 2911.173574] WARNING: CPU: 2 PID: 12247 at kernel/trace/tracing_map.c:983 tracing_map_sort_entries+0x3e0/0x408\n[ 2911.174702] Modules linked in: iscsi_ibft(E) iscsi_boot_sysfs(E) rfkill(E) af_packet(E) nls_iso8859_1(E) nls_cp437(E) vfat(E) fat(E) ena(E) tiny_power_button(E) qemu_fw_cfg(E) button(E) fuse(E) efi_pstore(E) ip_tables(E) x_tables(E) xfs(E) libcrc32c(E) aes_ce_blk(E) aes_ce_cipher(E) crct10dif_ce(E) polyval_ce(E) polyval_generic(E) ghash_ce(E) gf128mul(E) sm4_ce_gcm(E) sm4_ce_ccm(E) sm4_ce(E) sm4_ce_cipher(E) sm4(E) sm3_ce(E) sm3(E) sha3_ce(E) sha512_ce(E) sha512_arm64(E) sha2_ce(E) sha256_arm64(E) nvme(E) sha1_ce(E) nvme_core(E) nvme_auth(E) t10_pi(E) sg(E) scsi_mod(E) scsi_common(E) efivarfs(E)\n[ 2911.174738] Unloaded tainted modules: cppc_cpufreq(E):1\n[ 2911.180985] CPU: 2 PID: 12247 Comm: cat Kdump: loaded Tainted: G E 6.7.0-default #2 1b58bbb22c97e4399dc09f92d309344f69c44a01\n[ 2911.182398] Hardware name: Amazon EC2 c7g.8xlarge/, BIOS 1.0 11/1/2018\n[ 2911.183208] pstate: 61400005 (nZCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)\n[ 2911.184038] pc : tracing_map_sort_entries+0x3e0/0x408\n[ 2911.184667] lr : tracing_map_sort_entries+0x3e0/0x408\n[ 2911.185310] sp : ffff8000a1513900\n[ 2911.185750] x29: ffff8000a1513900 x28: ffff0003f272fe80 x27: 0000000000000001\n[ 2911.186600] x26: ffff0003f272fe80 x25: 0000000000000030 x24: 0000000000000008\n[ 2911.187458] x23: ffff0003c5788000 x22: ffff0003c16710c8 x21: ffff80008017f180\n[ 2911.188310] x20: ffff80008017f000 x19: ffff80008017f180 x18: ffffffffffffffff\n[ 2911.189160] x17: 0000000000000000 x16: 0000000000000000 x15: ffff8000a15134b8\n[ 2911.190015] x14: 0000000000000000 x13: 205d373432323154 x12: 5b5d313131333731\n[ 2911.190844] x11: 00000000fffeffff x10: 00000000fffeffff x9 : ffffd1b78274a13c\n[ 2911.191716] x8 : 000000000017ffe8 x7 : c0000000fffeffff x6 : 000000000057ffa8\n[ 2911.192554] x5 : ffff0012f6c24ec0 x4 : 0000000000000000 x3 : ffff2e5b72b5d000\n[ 2911.193404] x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff0003ff254480\n[ 2911.194259] Call trace:\n[ 2911.194626] tracing_map_sort_entries+0x3e0/0x408\n[ 2911.195220] hist_show+0x124/0x800\n[ 2911.195692] seq_read_iter+0x1d4/0x4e8\n[ 2911.196193] seq_read+0xe8/0x138\n[ 2911.196638] vfs_read+0xc8/0x300\n[ 2911.197078] ksys_read+0x70/0x108\n[ 2911.197534] __arm64_sys_read+0x24/0x38\n[ 2911.198046] invoke_syscall+0x78/0x108\n[ 2911.198553] el0_svc_common.constprop.0+0xd0/0xf8\n[ 2911.199157] do_el0_svc+0x28/0x40\n[ 2911.199613] el0_svc+0x40/0x178\n[ 2911.200048] el0t_64_sync_handler+0x13c/0x158\n[ 2911.200621] el0t_64_sync+0x1a8/0x1b0\n[ 2911.201115] ---[ end trace 0000000000000000 ]---\n\nThe problem appears to be caused by CPU reordering of writes issued from\n__tracing_map_insert().\n\nThe check for the presence of an element with a given key in this\nfunction is:\n\n val = READ_ONCE(entry->val);\n if (val && keys_match(key, val->key, map->key_size)) ...\n\nThe write of a new entry is:\n\n elt = get_free_elt(map);\n memcpy(elt->key, key, map->key_size);\n entry->val = elt;\n\nThe \"memcpy(elt->key, key, map->key_size);\" and \"entry->val = elt;\"\nstores may become visible in the reversed order on another CPU. This\nsecond CPU might then incorrectly determine that a new key doesn't match\nan already present val->key and subse\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-j32g-85qg-wf4w/GHSA-j32g-85qg-wf4w.json b/advisories/unreviewed/2024/03/GHSA-j32g-85qg-wf4w/GHSA-j32g-85qg-wf4w.json index 95eca716d24..f6cf2060a83 100644 --- a/advisories/unreviewed/2024/03/GHSA-j32g-85qg-wf4w/GHSA-j32g-85qg-wf4w.json +++ b/advisories/unreviewed/2024/03/GHSA-j32g-85qg-wf4w/GHSA-j32g-85qg-wf4w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-j64p-69wq-hp65/GHSA-j64p-69wq-hp65.json b/advisories/unreviewed/2024/03/GHSA-j64p-69wq-hp65/GHSA-j64p-69wq-hp65.json index 459b27d3fac..dddc528f93d 100644 --- a/advisories/unreviewed/2024/03/GHSA-j64p-69wq-hp65/GHSA-j64p-69wq-hp65.json +++ b/advisories/unreviewed/2024/03/GHSA-j64p-69wq-hp65/GHSA-j64p-69wq-hp65.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-j9cg-5w44-72xh/GHSA-j9cg-5w44-72xh.json b/advisories/unreviewed/2024/03/GHSA-j9cg-5w44-72xh/GHSA-j9cg-5w44-72xh.json index a860c1fb3cc..1cb329b5179 100644 --- a/advisories/unreviewed/2024/03/GHSA-j9cg-5w44-72xh/GHSA-j9cg-5w44-72xh.json +++ b/advisories/unreviewed/2024/03/GHSA-j9cg-5w44-72xh/GHSA-j9cg-5w44-72xh.json @@ -7,12 +7,8 @@ "CVE-2023-52496" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-mf3p-gmch-hc8x/GHSA-mf3p-gmch-hc8x.json b/advisories/unreviewed/2024/03/GHSA-mf3p-gmch-hc8x/GHSA-mf3p-gmch-hc8x.json index 9078bd285de..cc1d2292b98 100644 --- a/advisories/unreviewed/2024/03/GHSA-mf3p-gmch-hc8x/GHSA-mf3p-gmch-hc8x.json +++ b/advisories/unreviewed/2024/03/GHSA-mf3p-gmch-hc8x/GHSA-mf3p-gmch-hc8x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-mfjq-7ffc-qgmv/GHSA-mfjq-7ffc-qgmv.json b/advisories/unreviewed/2024/03/GHSA-mfjq-7ffc-qgmv/GHSA-mfjq-7ffc-qgmv.json index 01ce1487cf5..55725082076 100644 --- a/advisories/unreviewed/2024/03/GHSA-mfjq-7ffc-qgmv/GHSA-mfjq-7ffc-qgmv.json +++ b/advisories/unreviewed/2024/03/GHSA-mfjq-7ffc-qgmv/GHSA-mfjq-7ffc-qgmv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-mxh6-2xpg-m77w/GHSA-mxh6-2xpg-m77w.json b/advisories/unreviewed/2024/03/GHSA-mxh6-2xpg-m77w/GHSA-mxh6-2xpg-m77w.json index 0084725e12d..1a764a1948b 100644 --- a/advisories/unreviewed/2024/03/GHSA-mxh6-2xpg-m77w/GHSA-mxh6-2xpg-m77w.json +++ b/advisories/unreviewed/2024/03/GHSA-mxh6-2xpg-m77w/GHSA-mxh6-2xpg-m77w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-ph5r-c8gc-xg6f/GHSA-ph5r-c8gc-xg6f.json b/advisories/unreviewed/2024/03/GHSA-ph5r-c8gc-xg6f/GHSA-ph5r-c8gc-xg6f.json index 08c2777ca77..b7ed3931d66 100644 --- a/advisories/unreviewed/2024/03/GHSA-ph5r-c8gc-xg6f/GHSA-ph5r-c8gc-xg6f.json +++ b/advisories/unreviewed/2024/03/GHSA-ph5r-c8gc-xg6f/GHSA-ph5r-c8gc-xg6f.json @@ -7,12 +7,8 @@ "CVE-2024-26643" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: mark set as dead when unbinding anonymous set with timeout\n\nWhile the rhashtable set gc runs asynchronously, a race allows it to\ncollect elements from anonymous sets with timeouts while it is being\nreleased from the commit path.\n\nMingi Cho originally reported this issue in a different path in 6.1.x\nwith a pipapo set with low timeouts which is not possible upstream since\n7395dfacfff6 (\"netfilter: nf_tables: use timestamp to check for set\nelement timeout\").\n\nFix this by setting on the dead flag for anonymous sets to skip async gc\nin this case.\n\nAccording to 08e4c8c5919f (\"netfilter: nf_tables: mark newset as dead on\ntransaction abort\"), Florian plans to accelerate abort path by releasing\nobjects via workqueue, therefore, this sets on the dead flag for abort\npath too.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-pj2q-rq9j-ffq5/GHSA-pj2q-rq9j-ffq5.json b/advisories/unreviewed/2024/03/GHSA-pj2q-rq9j-ffq5/GHSA-pj2q-rq9j-ffq5.json index 4594aa7062b..b242d471f87 100644 --- a/advisories/unreviewed/2024/03/GHSA-pj2q-rq9j-ffq5/GHSA-pj2q-rq9j-ffq5.json +++ b/advisories/unreviewed/2024/03/GHSA-pj2q-rq9j-ffq5/GHSA-pj2q-rq9j-ffq5.json @@ -7,12 +7,8 @@ "CVE-2024-26610" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: fix a memory corruption\n\niwl_fw_ini_trigger_tlv::data is a pointer to a __le32, which means that\nif we copy to iwl_fw_ini_trigger_tlv::data + offset while offset is in\nbytes, we'll write past the buffer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-pjqv-pvfh-2w6m/GHSA-pjqv-pvfh-2w6m.json b/advisories/unreviewed/2024/03/GHSA-pjqv-pvfh-2w6m/GHSA-pjqv-pvfh-2w6m.json index d122e1e234c..aafbcefd6d8 100644 --- a/advisories/unreviewed/2024/03/GHSA-pjqv-pvfh-2w6m/GHSA-pjqv-pvfh-2w6m.json +++ b/advisories/unreviewed/2024/03/GHSA-pjqv-pvfh-2w6m/GHSA-pjqv-pvfh-2w6m.json @@ -7,12 +7,8 @@ "CVE-2024-26651" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsr9800: Add check for usbnet_get_endpoints\n\nAdd check for usbnet_get_endpoints() and return the error if it fails\nin order to transfer the error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-pp36-2qc2-w4hw/GHSA-pp36-2qc2-w4hw.json b/advisories/unreviewed/2024/03/GHSA-pp36-2qc2-w4hw/GHSA-pp36-2qc2-w4hw.json index e55cfd95ec3..1cf1284d1ef 100644 --- a/advisories/unreviewed/2024/03/GHSA-pp36-2qc2-w4hw/GHSA-pp36-2qc2-w4hw.json +++ b/advisories/unreviewed/2024/03/GHSA-pp36-2qc2-w4hw/GHSA-pp36-2qc2-w4hw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -63,9 +61,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-pqvp-7fm6-8x84/GHSA-pqvp-7fm6-8x84.json b/advisories/unreviewed/2024/03/GHSA-pqvp-7fm6-8x84/GHSA-pqvp-7fm6-8x84.json index eea84f1d590..6528faf9446 100644 --- a/advisories/unreviewed/2024/03/GHSA-pqvp-7fm6-8x84/GHSA-pqvp-7fm6-8x84.json +++ b/advisories/unreviewed/2024/03/GHSA-pqvp-7fm6-8x84/GHSA-pqvp-7fm6-8x84.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-vc6j-mx82-hrhh/GHSA-vc6j-mx82-hrhh.json b/advisories/unreviewed/2024/03/GHSA-vc6j-mx82-hrhh/GHSA-vc6j-mx82-hrhh.json index f282705bf46..82183a238fd 100644 --- a/advisories/unreviewed/2024/03/GHSA-vc6j-mx82-hrhh/GHSA-vc6j-mx82-hrhh.json +++ b/advisories/unreviewed/2024/03/GHSA-vc6j-mx82-hrhh/GHSA-vc6j-mx82-hrhh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-vfgc-wr54-m4r5/GHSA-vfgc-wr54-m4r5.json b/advisories/unreviewed/2024/03/GHSA-vfgc-wr54-m4r5/GHSA-vfgc-wr54-m4r5.json index 125204e2aca..33e0a45f558 100644 --- a/advisories/unreviewed/2024/03/GHSA-vfgc-wr54-m4r5/GHSA-vfgc-wr54-m4r5.json +++ b/advisories/unreviewed/2024/03/GHSA-vfgc-wr54-m4r5/GHSA-vfgc-wr54-m4r5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-vpgg-8ccq-gwhg/GHSA-vpgg-8ccq-gwhg.json b/advisories/unreviewed/2024/03/GHSA-vpgg-8ccq-gwhg/GHSA-vpgg-8ccq-gwhg.json index 5f4fc84ee5f..0c60ec63a62 100644 --- a/advisories/unreviewed/2024/03/GHSA-vpgg-8ccq-gwhg/GHSA-vpgg-8ccq-gwhg.json +++ b/advisories/unreviewed/2024/03/GHSA-vpgg-8ccq-gwhg/GHSA-vpgg-8ccq-gwhg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-ww23-hvpx-hvvc/GHSA-ww23-hvpx-hvvc.json b/advisories/unreviewed/2024/03/GHSA-ww23-hvpx-hvvc/GHSA-ww23-hvpx-hvvc.json index 5b4c4927908..b1e04b8e2cc 100644 --- a/advisories/unreviewed/2024/03/GHSA-ww23-hvpx-hvvc/GHSA-ww23-hvpx-hvvc.json +++ b/advisories/unreviewed/2024/03/GHSA-ww23-hvpx-hvvc/GHSA-ww23-hvpx-hvvc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-x7cq-pgcc-cqqm/GHSA-x7cq-pgcc-cqqm.json b/advisories/unreviewed/2024/03/GHSA-x7cq-pgcc-cqqm/GHSA-x7cq-pgcc-cqqm.json index 8f0c191eec9..ab1f59c32a8 100644 --- a/advisories/unreviewed/2024/03/GHSA-x7cq-pgcc-cqqm/GHSA-x7cq-pgcc-cqqm.json +++ b/advisories/unreviewed/2024/03/GHSA-x7cq-pgcc-cqqm/GHSA-x7cq-pgcc-cqqm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-xhm6-wpwj-qm56/GHSA-xhm6-wpwj-qm56.json b/advisories/unreviewed/2024/03/GHSA-xhm6-wpwj-qm56/GHSA-xhm6-wpwj-qm56.json index 29bc98c2d9a..a3cc289c0b8 100644 --- a/advisories/unreviewed/2024/03/GHSA-xhm6-wpwj-qm56/GHSA-xhm6-wpwj-qm56.json +++ b/advisories/unreviewed/2024/03/GHSA-xhm6-wpwj-qm56/GHSA-xhm6-wpwj-qm56.json @@ -7,12 +7,8 @@ "CVE-2024-26635" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nllc: Drop support for ETH_P_TR_802_2.\n\nsyzbot reported an uninit-value bug below. [0]\n\nllc supports ETH_P_802_2 (0x0004) and used to support ETH_P_TR_802_2\n(0x0011), and syzbot abused the latter to trigger the bug.\n\n write$tun(r0, &(0x7f0000000040)={@val={0x0, 0x11}, @val, @mpls={[], @llc={@snap={0xaa, 0x1, ')', \"90e5dd\"}}}}, 0x16)\n\nllc_conn_handler() initialises local variables {saddr,daddr}.mac\nbased on skb in llc_pdu_decode_sa()/llc_pdu_decode_da() and passes\nthem to __llc_lookup().\n\nHowever, the initialisation is done only when skb->protocol is\nhtons(ETH_P_802_2), otherwise, __llc_lookup_established() and\n__llc_lookup_listener() will read garbage.\n\nThe missing initialisation existed prior to commit 211ed865108e\n(\"net: delete all instances of special processing for token ring\").\n\nIt removed the part to kick out the token ring stuff but forgot to\nclose the door allowing ETH_P_TR_802_2 packets to sneak into llc_rcv().\n\nLet's remove llc_tr_packet_type and complete the deprecation.\n\n[0]:\nBUG: KMSAN: uninit-value in __llc_lookup_established+0xe9d/0xf90\n __llc_lookup_established+0xe9d/0xf90\n __llc_lookup net/llc/llc_conn.c:611 [inline]\n llc_conn_handler+0x4bd/0x1360 net/llc/llc_conn.c:791\n llc_rcv+0xfbb/0x14a0 net/llc/llc_input.c:206\n __netif_receive_skb_one_core net/core/dev.c:5527 [inline]\n __netif_receive_skb+0x1a6/0x5a0 net/core/dev.c:5641\n netif_receive_skb_internal net/core/dev.c:5727 [inline]\n netif_receive_skb+0x58/0x660 net/core/dev.c:5786\n tun_rx_batched+0x3ee/0x980 drivers/net/tun.c:1555\n tun_get_user+0x53af/0x66d0 drivers/net/tun.c:2002\n tun_chr_write_iter+0x3af/0x5d0 drivers/net/tun.c:2048\n call_write_iter include/linux/fs.h:2020 [inline]\n new_sync_write fs/read_write.c:491 [inline]\n vfs_write+0x8ef/0x1490 fs/read_write.c:584\n ksys_write+0x20f/0x4c0 fs/read_write.c:637\n __do_sys_write fs/read_write.c:649 [inline]\n __se_sys_write fs/read_write.c:646 [inline]\n __x64_sys_write+0x93/0xd0 fs/read_write.c:646\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x44/0x110 arch/x86/entry/common.c:82\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nLocal variable daddr created at:\n llc_conn_handler+0x53/0x1360 net/llc/llc_conn.c:783\n llc_rcv+0xfbb/0x14a0 net/llc/llc_input.c:206\n\nCPU: 1 PID: 5004 Comm: syz-executor994 Not tainted 6.6.0-syzkaller-14500-g1c41041124bd #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/09/2023", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-xqc9-rv8w-5v6g/GHSA-xqc9-rv8w-5v6g.json b/advisories/unreviewed/2024/03/GHSA-xqc9-rv8w-5v6g/GHSA-xqc9-rv8w-5v6g.json index 070f7b597bb..f2078401939 100644 --- a/advisories/unreviewed/2024/03/GHSA-xqc9-rv8w-5v6g/GHSA-xqc9-rv8w-5v6g.json +++ b/advisories/unreviewed/2024/03/GHSA-xqc9-rv8w-5v6g/GHSA-xqc9-rv8w-5v6g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-xr82-8hm6-h468/GHSA-xr82-8hm6-h468.json b/advisories/unreviewed/2024/03/GHSA-xr82-8hm6-h468/GHSA-xr82-8hm6-h468.json index 0cc862fc556..1708f2f75f0 100644 --- a/advisories/unreviewed/2024/03/GHSA-xr82-8hm6-h468/GHSA-xr82-8hm6-h468.json +++ b/advisories/unreviewed/2024/03/GHSA-xr82-8hm6-h468/GHSA-xr82-8hm6-h468.json @@ -7,12 +7,8 @@ "CVE-2024-26644" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don't abort filesystem when attempting to snapshot deleted subvolume\n\nIf the source file descriptor to the snapshot ioctl refers to a deleted\nsubvolume, we get the following abort:\n\n BTRFS: Transaction aborted (error -2)\n WARNING: CPU: 0 PID: 833 at fs/btrfs/transaction.c:1875 create_pending_snapshot+0x1040/0x1190 [btrfs]\n Modules linked in: pata_acpi btrfs ata_piix libata scsi_mod virtio_net blake2b_generic xor net_failover virtio_rng failover scsi_common rng_core raid6_pq libcrc32c\n CPU: 0 PID: 833 Comm: t_snapshot_dele Not tainted 6.7.0-rc6 #2\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-1.fc39 04/01/2014\n RIP: 0010:create_pending_snapshot+0x1040/0x1190 [btrfs]\n RSP: 0018:ffffa09c01337af8 EFLAGS: 00010282\n RAX: 0000000000000000 RBX: ffff9982053e7c78 RCX: 0000000000000027\n RDX: ffff99827dc20848 RSI: 0000000000000001 RDI: ffff99827dc20840\n RBP: ffffa09c01337c00 R08: 0000000000000000 R09: ffffa09c01337998\n R10: 0000000000000003 R11: ffffffffb96da248 R12: fffffffffffffffe\n R13: ffff99820535bb28 R14: ffff99820b7bd000 R15: ffff99820381ea80\n FS: 00007fe20aadabc0(0000) GS:ffff99827dc00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000559a120b502f CR3: 00000000055b6000 CR4: 00000000000006f0\n Call Trace:\n \n ? create_pending_snapshot+0x1040/0x1190 [btrfs]\n ? __warn+0x81/0x130\n ? create_pending_snapshot+0x1040/0x1190 [btrfs]\n ? report_bug+0x171/0x1a0\n ? handle_bug+0x3a/0x70\n ? exc_invalid_op+0x17/0x70\n ? asm_exc_invalid_op+0x1a/0x20\n ? create_pending_snapshot+0x1040/0x1190 [btrfs]\n ? create_pending_snapshot+0x1040/0x1190 [btrfs]\n create_pending_snapshots+0x92/0xc0 [btrfs]\n btrfs_commit_transaction+0x66b/0xf40 [btrfs]\n btrfs_mksubvol+0x301/0x4d0 [btrfs]\n btrfs_mksnapshot+0x80/0xb0 [btrfs]\n __btrfs_ioctl_snap_create+0x1c2/0x1d0 [btrfs]\n btrfs_ioctl_snap_create_v2+0xc4/0x150 [btrfs]\n btrfs_ioctl+0x8a6/0x2650 [btrfs]\n ? kmem_cache_free+0x22/0x340\n ? do_sys_openat2+0x97/0xe0\n __x64_sys_ioctl+0x97/0xd0\n do_syscall_64+0x46/0xf0\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n RIP: 0033:0x7fe20abe83af\n RSP: 002b:00007ffe6eff1360 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\n RAX: ffffffffffffffda RBX: 0000000000000004 RCX: 00007fe20abe83af\n RDX: 00007ffe6eff23c0 RSI: 0000000050009417 RDI: 0000000000000003\n RBP: 0000000000000003 R08: 0000000000000000 R09: 00007fe20ad16cd0\n R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\n R13: 00007ffe6eff13c0 R14: 00007fe20ad45000 R15: 0000559a120b6d58\n \n ---[ end trace 0000000000000000 ]---\n BTRFS: error (device vdc: state A) in create_pending_snapshot:1875: errno=-2 No such entry\n BTRFS info (device vdc: state EA): forced readonly\n BTRFS warning (device vdc: state EA): Skipping commit of aborted transaction.\n BTRFS: error (device vdc: state EA) in cleanup_transaction:2055: errno=-2 No such entry\n\nThis happens because create_pending_snapshot() initializes the new root\nitem as a copy of the source root item. This includes the refs field,\nwhich is 0 for a deleted subvolume. The call to btrfs_insert_root()\ntherefore inserts a root with refs == 0. btrfs_get_new_fs_root() then\nfinds the root and returns -ENOENT if refs == 0, which causes\ncreate_pending_snapshot() to abort.\n\nFix it by checking the source root's refs before attempting the\nsnapshot, but after locking subvol_sem to avoid racing with deletion.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2252-87pv-34g4/GHSA-2252-87pv-34g4.json b/advisories/unreviewed/2024/04/GHSA-2252-87pv-34g4/GHSA-2252-87pv-34g4.json index 9082e5ef294..6a16e369053 100644 --- a/advisories/unreviewed/2024/04/GHSA-2252-87pv-34g4/GHSA-2252-87pv-34g4.json +++ b/advisories/unreviewed/2024/04/GHSA-2252-87pv-34g4/GHSA-2252-87pv-34g4.json @@ -7,12 +7,8 @@ "CVE-2024-26801" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Avoid potential use-after-free in hci_error_reset\n\nWhile handling the HCI_EV_HARDWARE_ERROR event, if the underlying\nBT controller is not responding, the GPIO reset mechanism would\nfree the hci_dev and lead to a use-after-free in hci_error_reset.\n\nHere's the call trace observed on a ChromeOS device with Intel AX201:\n queue_work_on+0x3e/0x6c\n __hci_cmd_sync_sk+0x2ee/0x4c0 [bluetooth ]\n ? init_wait_entry+0x31/0x31\n __hci_cmd_sync+0x16/0x20 [bluetooth ]\n hci_error_reset+0x4f/0xa4 [bluetooth ]\n process_one_work+0x1d8/0x33f\n worker_thread+0x21b/0x373\n kthread+0x13a/0x152\n ? pr_cont_work+0x54/0x54\n ? kthread_blkcg+0x31/0x31\n ret_from_fork+0x1f/0x30\n\nThis patch holds the reference count on the hci_dev while processing\na HCI_EV_HARDWARE_ERROR event to avoid potential crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-29f2-7m5v-qfqv/GHSA-29f2-7m5v-qfqv.json b/advisories/unreviewed/2024/04/GHSA-29f2-7m5v-qfqv/GHSA-29f2-7m5v-qfqv.json index 3ae714c16ab..288d3b8b3f1 100644 --- a/advisories/unreviewed/2024/04/GHSA-29f2-7m5v-qfqv/GHSA-29f2-7m5v-qfqv.json +++ b/advisories/unreviewed/2024/04/GHSA-29f2-7m5v-qfqv/GHSA-29f2-7m5v-qfqv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-2fv8-4462-wxh7/GHSA-2fv8-4462-wxh7.json b/advisories/unreviewed/2024/04/GHSA-2fv8-4462-wxh7/GHSA-2fv8-4462-wxh7.json index 7652aff07ce..0a724656def 100644 --- a/advisories/unreviewed/2024/04/GHSA-2fv8-4462-wxh7/GHSA-2fv8-4462-wxh7.json +++ b/advisories/unreviewed/2024/04/GHSA-2fv8-4462-wxh7/GHSA-2fv8-4462-wxh7.json @@ -7,12 +7,8 @@ "CVE-2024-27536" ], "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2mrh-g8f4-xvjv/GHSA-2mrh-g8f4-xvjv.json b/advisories/unreviewed/2024/04/GHSA-2mrh-g8f4-xvjv/GHSA-2mrh-g8f4-xvjv.json index b1e92435e23..1d7bad3a895 100644 --- a/advisories/unreviewed/2024/04/GHSA-2mrh-g8f4-xvjv/GHSA-2mrh-g8f4-xvjv.json +++ b/advisories/unreviewed/2024/04/GHSA-2mrh-g8f4-xvjv/GHSA-2mrh-g8f4-xvjv.json @@ -7,12 +7,8 @@ "CVE-2024-26695" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp - Fix null pointer dereference in __sev_platform_shutdown_locked\n\nThe SEV platform device can be shutdown with a null psp_master,\ne.g., using DEBUG_TEST_DRIVER_REMOVE. Found using KASAN:\n\n[ 137.148210] ccp 0000:23:00.1: enabling device (0000 -> 0002)\n[ 137.162647] ccp 0000:23:00.1: no command queues available\n[ 137.170598] ccp 0000:23:00.1: sev enabled\n[ 137.174645] ccp 0000:23:00.1: psp enabled\n[ 137.178890] general protection fault, probably for non-canonical address 0xdffffc000000001e: 0000 [#1] PREEMPT SMP DEBUG_PAGEALLOC KASAN NOPTI\n[ 137.182693] KASAN: null-ptr-deref in range [0x00000000000000f0-0x00000000000000f7]\n[ 137.182693] CPU: 93 PID: 1 Comm: swapper/0 Not tainted 6.8.0-rc1+ #311\n[ 137.182693] RIP: 0010:__sev_platform_shutdown_locked+0x51/0x180\n[ 137.182693] Code: 08 80 3c 08 00 0f 85 0e 01 00 00 48 8b 1d 67 b6 01 08 48 b8 00 00 00 00 00 fc ff df 48 8d bb f0 00 00 00 48 89 f9 48 c1 e9 03 <80> 3c 01 00 0f 85 fe 00 00 00 48 8b 9b f0 00 00 00 48 85 db 74 2c\n[ 137.182693] RSP: 0018:ffffc900000cf9b0 EFLAGS: 00010216\n[ 137.182693] RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 000000000000001e\n[ 137.182693] RDX: 0000000000000000 RSI: 0000000000000008 RDI: 00000000000000f0\n[ 137.182693] RBP: ffffc900000cf9c8 R08: 0000000000000000 R09: fffffbfff58f5a66\n[ 137.182693] R10: ffffc900000cf9c8 R11: ffffffffac7ad32f R12: ffff8881e5052c28\n[ 137.182693] R13: ffff8881e5052c28 R14: ffff8881758e43e8 R15: ffffffffac64abf8\n[ 137.182693] FS: 0000000000000000(0000) GS:ffff889de7000000(0000) knlGS:0000000000000000\n[ 137.182693] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 137.182693] CR2: 0000000000000000 CR3: 0000001cf7c7e000 CR4: 0000000000350ef0\n[ 137.182693] Call Trace:\n[ 137.182693] \n[ 137.182693] ? show_regs+0x6c/0x80\n[ 137.182693] ? __die_body+0x24/0x70\n[ 137.182693] ? die_addr+0x4b/0x80\n[ 137.182693] ? exc_general_protection+0x126/0x230\n[ 137.182693] ? asm_exc_general_protection+0x2b/0x30\n[ 137.182693] ? __sev_platform_shutdown_locked+0x51/0x180\n[ 137.182693] sev_firmware_shutdown.isra.0+0x1e/0x80\n[ 137.182693] sev_dev_destroy+0x49/0x100\n[ 137.182693] psp_dev_destroy+0x47/0xb0\n[ 137.182693] sp_destroy+0xbb/0x240\n[ 137.182693] sp_pci_remove+0x45/0x60\n[ 137.182693] pci_device_remove+0xaa/0x1d0\n[ 137.182693] device_remove+0xc7/0x170\n[ 137.182693] really_probe+0x374/0xbe0\n[ 137.182693] ? srso_return_thunk+0x5/0x5f\n[ 137.182693] __driver_probe_device+0x199/0x460\n[ 137.182693] driver_probe_device+0x4e/0xd0\n[ 137.182693] __driver_attach+0x191/0x3d0\n[ 137.182693] ? __pfx___driver_attach+0x10/0x10\n[ 137.182693] bus_for_each_dev+0x100/0x190\n[ 137.182693] ? __pfx_bus_for_each_dev+0x10/0x10\n[ 137.182693] ? __kasan_check_read+0x15/0x20\n[ 137.182693] ? srso_return_thunk+0x5/0x5f\n[ 137.182693] ? _raw_spin_unlock+0x27/0x50\n[ 137.182693] driver_attach+0x41/0x60\n[ 137.182693] bus_add_driver+0x2a8/0x580\n[ 137.182693] driver_register+0x141/0x480\n[ 137.182693] __pci_register_driver+0x1d6/0x2a0\n[ 137.182693] ? srso_return_thunk+0x5/0x5f\n[ 137.182693] ? esrt_sysfs_init+0x1cd/0x5d0\n[ 137.182693] ? __pfx_sp_mod_init+0x10/0x10\n[ 137.182693] sp_pci_init+0x22/0x30\n[ 137.182693] sp_mod_init+0x14/0x30\n[ 137.182693] ? __pfx_sp_mod_init+0x10/0x10\n[ 137.182693] do_one_initcall+0xd1/0x470\n[ 137.182693] ? __pfx_do_one_initcall+0x10/0x10\n[ 137.182693] ? parameq+0x80/0xf0\n[ 137.182693] ? srso_return_thunk+0x5/0x5f\n[ 137.182693] ? __kmalloc+0x3b0/0x4e0\n[ 137.182693] ? kernel_init_freeable+0x92d/0x1050\n[ 137.182693] ? kasan_populate_vmalloc_pte+0x171/0x190\n[ 137.182693] ? srso_return_thunk+0x5/0x5f\n[ 137.182693] kernel_init_freeable+0xa64/0x1050\n[ 137.182693] ? __pfx_kernel_init+0x10/0x10\n[ 137.182693] kernel_init+0x24/0x160\n[ 137.182693] ? __switch_to_asm+0x3e/0x70\n[ 137.182693] ret_from_fork+0x40/0x80\n[ 137.182693] ? __pfx_kernel_init+0x1\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2vqj-rxh7-chjw/GHSA-2vqj-rxh7-chjw.json b/advisories/unreviewed/2024/04/GHSA-2vqj-rxh7-chjw/GHSA-2vqj-rxh7-chjw.json index e709f088728..a2ee07a4b5e 100644 --- a/advisories/unreviewed/2024/04/GHSA-2vqj-rxh7-chjw/GHSA-2vqj-rxh7-chjw.json +++ b/advisories/unreviewed/2024/04/GHSA-2vqj-rxh7-chjw/GHSA-2vqj-rxh7-chjw.json @@ -7,12 +7,8 @@ "CVE-2024-26679" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ninet: read sk->sk_family once in inet_recv_error()\n\ninet_recv_error() is called without holding the socket lock.\n\nIPv6 socket could mutate to IPv4 with IPV6_ADDRFORM\nsocket option and trigger a KCSAN warning.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2vvj-hm96-cr7r/GHSA-2vvj-hm96-cr7r.json b/advisories/unreviewed/2024/04/GHSA-2vvj-hm96-cr7r/GHSA-2vvj-hm96-cr7r.json index 47c73f5813f..c4e4cfc2aa2 100644 --- a/advisories/unreviewed/2024/04/GHSA-2vvj-hm96-cr7r/GHSA-2vvj-hm96-cr7r.json +++ b/advisories/unreviewed/2024/04/GHSA-2vvj-hm96-cr7r/GHSA-2vvj-hm96-cr7r.json @@ -7,12 +7,8 @@ "CVE-2024-26820" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhv_netvsc: Register VF in netvsc_probe if NET_DEVICE_REGISTER missed\n\nIf hv_netvsc driver is unloaded and reloaded, the NET_DEVICE_REGISTER\nhandler cannot perform VF register successfully as the register call\nis received before netvsc_probe is finished. This is because we\nregister register_netdevice_notifier() very early( even before\nvmbus_driver_register()).\nTo fix this, we try to register each such matching VF( if it is visible\nas a netdevice) at the end of netvsc_probe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-389h-6rjg-wxc9/GHSA-389h-6rjg-wxc9.json b/advisories/unreviewed/2024/04/GHSA-389h-6rjg-wxc9/GHSA-389h-6rjg-wxc9.json index 287431d07a6..158b65f3dd5 100644 --- a/advisories/unreviewed/2024/04/GHSA-389h-6rjg-wxc9/GHSA-389h-6rjg-wxc9.json +++ b/advisories/unreviewed/2024/04/GHSA-389h-6rjg-wxc9/GHSA-389h-6rjg-wxc9.json @@ -7,12 +7,8 @@ "CVE-2024-26659" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxhci: handle isoc Babble and Buffer Overrun events properly\n\nxHCI 4.9 explicitly forbids assuming that the xHC has released its\nownership of a multi-TRB TD when it reports an error on one of the\nearly TRBs. Yet the driver makes such assumption and releases the TD,\nallowing the remaining TRBs to be freed or overwritten by new TDs.\n\nThe xHC should also report completion of the final TRB due to its IOC\nflag being set by us, regardless of prior errors. This event cannot\nbe recognized if the TD has already been freed earlier, resulting in\n\"Transfer event TRB DMA ptr not part of current TD\" error message.\n\nFix this by reusing the logic for processing isoc Transaction Errors.\nThis also handles hosts which fail to report the final completion.\n\nFix transfer length reporting on Babble errors. They may be caused by\ndevice malfunction, no guarantee that the buffer has been filled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-3976-477p-x267/GHSA-3976-477p-x267.json b/advisories/unreviewed/2024/04/GHSA-3976-477p-x267/GHSA-3976-477p-x267.json index 946b252732e..3951a1b3581 100644 --- a/advisories/unreviewed/2024/04/GHSA-3976-477p-x267/GHSA-3976-477p-x267.json +++ b/advisories/unreviewed/2024/04/GHSA-3976-477p-x267/GHSA-3976-477p-x267.json @@ -7,12 +7,8 @@ "CVE-2024-26845" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: core: Add TMF to tmr_list handling\n\nAn abort that is responded to by iSCSI itself is added to tmr_list but does\nnot go to target core. A LUN_RESET that goes through tmr_list takes a\nrefcounter on the abort and waits for completion. However, the abort will\nbe never complete because it was not started in target core.\n\n Unable to locate ITT: 0x05000000 on CID: 0\n Unable to locate RefTaskTag: 0x05000000 on CID: 0.\n wait_for_tasks: Stopping tmf LUN_RESET with tag 0x0 ref_task_tag 0x0 i_state 34 t_state ISTATE_PROCESSING refcnt 2 transport_state active,stop,fabric_stop\n wait for tasks: tmf LUN_RESET with tag 0x0 ref_task_tag 0x0 i_state 34 t_state ISTATE_PROCESSING refcnt 2 transport_state active,stop,fabric_stop\n...\n INFO: task kworker/0:2:49 blocked for more than 491 seconds.\n task:kworker/0:2 state:D stack: 0 pid: 49 ppid: 2 flags:0x00000800\n Workqueue: events target_tmr_work [target_core_mod]\nCall Trace:\n __switch_to+0x2c4/0x470\n _schedule+0x314/0x1730\n schedule+0x64/0x130\n schedule_timeout+0x168/0x430\n wait_for_completion+0x140/0x270\n target_put_cmd_and_wait+0x64/0xb0 [target_core_mod]\n core_tmr_lun_reset+0x30/0xa0 [target_core_mod]\n target_tmr_work+0xc8/0x1b0 [target_core_mod]\n process_one_work+0x2d4/0x5d0\n worker_thread+0x78/0x6c0\n\nTo fix this, only add abort to tmr_list if it will be handled by target\ncore.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-3cm8-rv8m-x9gf/GHSA-3cm8-rv8m-x9gf.json b/advisories/unreviewed/2024/04/GHSA-3cm8-rv8m-x9gf/GHSA-3cm8-rv8m-x9gf.json index 0517813e367..5d465e3b6bd 100644 --- a/advisories/unreviewed/2024/04/GHSA-3cm8-rv8m-x9gf/GHSA-3cm8-rv8m-x9gf.json +++ b/advisories/unreviewed/2024/04/GHSA-3cm8-rv8m-x9gf/GHSA-3cm8-rv8m-x9gf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-3v83-crv9-cf9p/GHSA-3v83-crv9-cf9p.json b/advisories/unreviewed/2024/04/GHSA-3v83-crv9-cf9p/GHSA-3v83-crv9-cf9p.json index 766c4328ebb..8e6883152ec 100644 --- a/advisories/unreviewed/2024/04/GHSA-3v83-crv9-cf9p/GHSA-3v83-crv9-cf9p.json +++ b/advisories/unreviewed/2024/04/GHSA-3v83-crv9-cf9p/GHSA-3v83-crv9-cf9p.json @@ -7,12 +7,8 @@ "CVE-2024-26793" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: fix use-after-free and null-ptr-deref in gtp_newlink()\n\nThe gtp_link_ops operations structure for the subsystem must be\nregistered after registering the gtp_net_ops pernet operations structure.\n\nSyzkaller hit 'general protection fault in gtp_genl_dump_pdp' bug:\n\n[ 1010.702740] gtp: GTP module unloaded\n[ 1010.715877] general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI\n[ 1010.715888] KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\n[ 1010.715895] CPU: 1 PID: 128616 Comm: a.out Not tainted 6.8.0-rc6-std-def-alt1 #1\n[ 1010.715899] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.0-alt1 04/01/2014\n[ 1010.715908] RIP: 0010:gtp_newlink+0x4d7/0x9c0 [gtp]\n[ 1010.715915] Code: 80 3c 02 00 0f 85 41 04 00 00 48 8b bb d8 05 00 00 e8 ed f6 ff ff 48 89 c2 48 89 c5 48 b8 00 00 00 00 00 fc ff df 48 c1 ea 03 <80> 3c 02 00 0f 85 4f 04 00 00 4c 89 e2 4c 8b 6d 00 48 b8 00 00 00\n[ 1010.715920] RSP: 0018:ffff888020fbf180 EFLAGS: 00010203\n[ 1010.715929] RAX: dffffc0000000000 RBX: ffff88800399c000 RCX: 0000000000000000\n[ 1010.715933] RDX: 0000000000000001 RSI: ffffffff84805280 RDI: 0000000000000282\n[ 1010.715938] RBP: 000000000000000d R08: 0000000000000001 R09: 0000000000000000\n[ 1010.715942] R10: 0000000000000001 R11: 0000000000000001 R12: ffff88800399cc80\n[ 1010.715947] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000400\n[ 1010.715953] FS: 00007fd1509ab5c0(0000) GS:ffff88805b300000(0000) knlGS:0000000000000000\n[ 1010.715958] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 1010.715962] CR2: 0000000000000000 CR3: 000000001c07a000 CR4: 0000000000750ee0\n[ 1010.715968] PKRU: 55555554\n[ 1010.715972] Call Trace:\n[ 1010.715985] ? __die_body.cold+0x1a/0x1f\n[ 1010.715995] ? die_addr+0x43/0x70\n[ 1010.716002] ? exc_general_protection+0x199/0x2f0\n[ 1010.716016] ? asm_exc_general_protection+0x1e/0x30\n[ 1010.716026] ? gtp_newlink+0x4d7/0x9c0 [gtp]\n[ 1010.716034] ? gtp_net_exit+0x150/0x150 [gtp]\n[ 1010.716042] __rtnl_newlink+0x1063/0x1700\n[ 1010.716051] ? rtnl_setlink+0x3c0/0x3c0\n[ 1010.716063] ? is_bpf_text_address+0xc0/0x1f0\n[ 1010.716070] ? kernel_text_address.part.0+0xbb/0xd0\n[ 1010.716076] ? __kernel_text_address+0x56/0xa0\n[ 1010.716084] ? unwind_get_return_address+0x5a/0xa0\n[ 1010.716091] ? create_prof_cpu_mask+0x30/0x30\n[ 1010.716098] ? arch_stack_walk+0x9e/0xf0\n[ 1010.716106] ? stack_trace_save+0x91/0xd0\n[ 1010.716113] ? stack_trace_consume_entry+0x170/0x170\n[ 1010.716121] ? __lock_acquire+0x15c5/0x5380\n[ 1010.716139] ? mark_held_locks+0x9e/0xe0\n[ 1010.716148] ? kmem_cache_alloc_trace+0x35f/0x3c0\n[ 1010.716155] ? __rtnl_newlink+0x1700/0x1700\n[ 1010.716160] rtnl_newlink+0x69/0xa0\n[ 1010.716166] rtnetlink_rcv_msg+0x43b/0xc50\n[ 1010.716172] ? rtnl_fdb_dump+0x9f0/0x9f0\n[ 1010.716179] ? lock_acquire+0x1fe/0x560\n[ 1010.716188] ? netlink_deliver_tap+0x12f/0xd50\n[ 1010.716196] netlink_rcv_skb+0x14d/0x440\n[ 1010.716202] ? rtnl_fdb_dump+0x9f0/0x9f0\n[ 1010.716208] ? netlink_ack+0xab0/0xab0\n[ 1010.716213] ? netlink_deliver_tap+0x202/0xd50\n[ 1010.716220] ? netlink_deliver_tap+0x218/0xd50\n[ 1010.716226] ? __virt_addr_valid+0x30b/0x590\n[ 1010.716233] netlink_unicast+0x54b/0x800\n[ 1010.716240] ? netlink_attachskb+0x870/0x870\n[ 1010.716248] ? __check_object_size+0x2de/0x3b0\n[ 1010.716254] netlink_sendmsg+0x938/0xe40\n[ 1010.716261] ? netlink_unicast+0x800/0x800\n[ 1010.716269] ? __import_iovec+0x292/0x510\n[ 1010.716276] ? netlink_unicast+0x800/0x800\n[ 1010.716284] __sock_sendmsg+0x159/0x190\n[ 1010.716290] ____sys_sendmsg+0x712/0x880\n[ 1010.716297] ? sock_write_iter+0x3d0/0x3d0\n[ 1010.716304] ? __ia32_sys_recvmmsg+0x270/0x270\n[ 1010.716309] ? lock_acquire+0x1fe/0x560\n[ 1010.716315] ? drain_array_locked+0x90/0x90\n[ 1010.716324] ___sys_sendmsg+0xf8/0x170\n[ 1010.716331] ? sendmsg_copy_msghdr+0x170/0x170\n[ 1010.716337] ? lockdep_init_map\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-3vwc-j35j-g8jv/GHSA-3vwc-j35j-g8jv.json b/advisories/unreviewed/2024/04/GHSA-3vwc-j35j-g8jv/GHSA-3vwc-j35j-g8jv.json index caf5d6d7ffb..b6d389b4399 100644 --- a/advisories/unreviewed/2024/04/GHSA-3vwc-j35j-g8jv/GHSA-3vwc-j35j-g8jv.json +++ b/advisories/unreviewed/2024/04/GHSA-3vwc-j35j-g8jv/GHSA-3vwc-j35j-g8jv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-3w4p-cp93-7566/GHSA-3w4p-cp93-7566.json b/advisories/unreviewed/2024/04/GHSA-3w4p-cp93-7566/GHSA-3w4p-cp93-7566.json index 71e86bb09d6..760cf2944af 100644 --- a/advisories/unreviewed/2024/04/GHSA-3w4p-cp93-7566/GHSA-3w4p-cp93-7566.json +++ b/advisories/unreviewed/2024/04/GHSA-3w4p-cp93-7566/GHSA-3w4p-cp93-7566.json @@ -7,12 +7,8 @@ "CVE-2024-26848" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix endless loop in directory parsing\n\nIf a directory has a block with only \".__afsXXXX\" files in it (from\nuncompleted silly-rename), these .__afsXXXX files are skipped but without\nadvancing the file position in the dir_context. This leads to\nafs_dir_iterate() repeating the block again and again.\n\nFix this by making the code that skips the .__afsXXXX file also manually\nadvance the file position.\n\nThe symptoms are a soft lookup:\n\n watchdog: BUG: soft lockup - CPU#3 stuck for 52s! [check:5737]\n ...\n RIP: 0010:afs_dir_iterate_block+0x39/0x1fd\n ...\n ? watchdog_timer_fn+0x1a6/0x213\n ...\n ? asm_sysvec_apic_timer_interrupt+0x16/0x20\n ? afs_dir_iterate_block+0x39/0x1fd\n afs_dir_iterate+0x10a/0x148\n afs_readdir+0x30/0x4a\n iterate_dir+0x93/0xd3\n __do_sys_getdents64+0x6b/0xd4\n\nThis is almost certainly the actual fix for:\n\n https://bugzilla.kernel.org/show_bug.cgi?id=218496", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-488v-m6fm-php4/GHSA-488v-m6fm-php4.json b/advisories/unreviewed/2024/04/GHSA-488v-m6fm-php4/GHSA-488v-m6fm-php4.json index 1bb53f2045b..955a47bca0b 100644 --- a/advisories/unreviewed/2024/04/GHSA-488v-m6fm-php4/GHSA-488v-m6fm-php4.json +++ b/advisories/unreviewed/2024/04/GHSA-488v-m6fm-php4/GHSA-488v-m6fm-php4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4965-8838-r53x/GHSA-4965-8838-r53x.json b/advisories/unreviewed/2024/04/GHSA-4965-8838-r53x/GHSA-4965-8838-r53x.json index e4e09bb02f3..b25daa35efa 100644 --- a/advisories/unreviewed/2024/04/GHSA-4965-8838-r53x/GHSA-4965-8838-r53x.json +++ b/advisories/unreviewed/2024/04/GHSA-4965-8838-r53x/GHSA-4965-8838-r53x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-49g6-x26j-85g3/GHSA-49g6-x26j-85g3.json b/advisories/unreviewed/2024/04/GHSA-49g6-x26j-85g3/GHSA-49g6-x26j-85g3.json index e07d6b13907..87242d413a0 100644 --- a/advisories/unreviewed/2024/04/GHSA-49g6-x26j-85g3/GHSA-49g6-x26j-85g3.json +++ b/advisories/unreviewed/2024/04/GHSA-49g6-x26j-85g3/GHSA-49g6-x26j-85g3.json @@ -7,12 +7,8 @@ "CVE-2024-26870" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4.2: fix nfs4_listxattr kernel BUG at mm/usercopy.c:102\n\nA call to listxattr() with a buffer size = 0 returns the actual\nsize of the buffer needed for a subsequent call. When size > 0,\nnfs4_listxattr() does not return an error because either\ngeneric_listxattr() or nfs4_listxattr_nfs4_label() consumes\nexactly all the bytes then size is 0 when calling\nnfs4_listxattr_nfs4_user() which then triggers the following\nkernel BUG:\n\n [ 99.403778] kernel BUG at mm/usercopy.c:102!\n [ 99.404063] Internal error: Oops - BUG: 00000000f2000800 [#1] SMP\n [ 99.408463] CPU: 0 PID: 3310 Comm: python3 Not tainted 6.6.0-61.fc40.aarch64 #1\n [ 99.415827] Call trace:\n [ 99.415985] usercopy_abort+0x70/0xa0\n [ 99.416227] __check_heap_object+0x134/0x158\n [ 99.416505] check_heap_object+0x150/0x188\n [ 99.416696] __check_object_size.part.0+0x78/0x168\n [ 99.416886] __check_object_size+0x28/0x40\n [ 99.417078] listxattr+0x8c/0x120\n [ 99.417252] path_listxattr+0x78/0xe0\n [ 99.417476] __arm64_sys_listxattr+0x28/0x40\n [ 99.417723] invoke_syscall+0x78/0x100\n [ 99.417929] el0_svc_common.constprop.0+0x48/0xf0\n [ 99.418186] do_el0_svc+0x24/0x38\n [ 99.418376] el0_svc+0x3c/0x110\n [ 99.418554] el0t_64_sync_handler+0x120/0x130\n [ 99.418788] el0t_64_sync+0x194/0x198\n [ 99.418994] Code: aa0003e3 d000a3e0 91310000 97f49bdb (d4210000)\n\nIssue is reproduced when generic_listxattr() returns 'system.nfs4_acl',\nthus calling lisxattr() with size = 16 will trigger the bug.\n\nAdd check on nfs4_listxattr() to return ERANGE error when it is\ncalled with size > 0 and the return value is greater than size.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4jw4-4g69-7273/GHSA-4jw4-4g69-7273.json b/advisories/unreviewed/2024/04/GHSA-4jw4-4g69-7273/GHSA-4jw4-4g69-7273.json index 3017c5dcebb..fd3ac34d6ed 100644 --- a/advisories/unreviewed/2024/04/GHSA-4jw4-4g69-7273/GHSA-4jw4-4g69-7273.json +++ b/advisories/unreviewed/2024/04/GHSA-4jw4-4g69-7273/GHSA-4jw4-4g69-7273.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-4m6c-v88j-qqxh/GHSA-4m6c-v88j-qqxh.json b/advisories/unreviewed/2024/04/GHSA-4m6c-v88j-qqxh/GHSA-4m6c-v88j-qqxh.json index f656dddbac4..20244dba10d 100644 --- a/advisories/unreviewed/2024/04/GHSA-4m6c-v88j-qqxh/GHSA-4m6c-v88j-qqxh.json +++ b/advisories/unreviewed/2024/04/GHSA-4m6c-v88j-qqxh/GHSA-4m6c-v88j-qqxh.json @@ -7,12 +7,8 @@ "CVE-2024-26778" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: savage: Error out if pixclock equals zero\n\nThe userspace program could pass any values to the driver through\nioctl() interface. If the driver doesn't check the value of pixclock,\nit may cause divide-by-zero error.\n\nAlthough pixclock is checked in savagefb_decode_var(), but it is not\nchecked properly in savagefb_probe(). Fix this by checking whether\npixclock is zero in the function savagefb_check_var() before\ninfo->var.pixclock is used as the divisor.\n\nThis is similar to CVE-2022-3061 in i740fb which was fixed by\ncommit 15cf0b8.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4p7x-7wc6-4gf5/GHSA-4p7x-7wc6-4gf5.json b/advisories/unreviewed/2024/04/GHSA-4p7x-7wc6-4gf5/GHSA-4p7x-7wc6-4gf5.json index 58d7e3b988c..882e8b05e1a 100644 --- a/advisories/unreviewed/2024/04/GHSA-4p7x-7wc6-4gf5/GHSA-4p7x-7wc6-4gf5.json +++ b/advisories/unreviewed/2024/04/GHSA-4p7x-7wc6-4gf5/GHSA-4p7x-7wc6-4gf5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-4r5c-7wgh-g673/GHSA-4r5c-7wgh-g673.json b/advisories/unreviewed/2024/04/GHSA-4r5c-7wgh-g673/GHSA-4r5c-7wgh-g673.json index a4ed3e65361..d58c71d553e 100644 --- a/advisories/unreviewed/2024/04/GHSA-4r5c-7wgh-g673/GHSA-4r5c-7wgh-g673.json +++ b/advisories/unreviewed/2024/04/GHSA-4r5c-7wgh-g673/GHSA-4r5c-7wgh-g673.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-4wch-q26f-448q/GHSA-4wch-q26f-448q.json b/advisories/unreviewed/2024/04/GHSA-4wch-q26f-448q/GHSA-4wch-q26f-448q.json index 2eab6817832..97e7628b381 100644 --- a/advisories/unreviewed/2024/04/GHSA-4wch-q26f-448q/GHSA-4wch-q26f-448q.json +++ b/advisories/unreviewed/2024/04/GHSA-4wch-q26f-448q/GHSA-4wch-q26f-448q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-4xxr-7xxv-w3hj/GHSA-4xxr-7xxv-w3hj.json b/advisories/unreviewed/2024/04/GHSA-4xxr-7xxv-w3hj/GHSA-4xxr-7xxv-w3hj.json index 454ac4eb2d1..53c45817e4b 100644 --- a/advisories/unreviewed/2024/04/GHSA-4xxr-7xxv-w3hj/GHSA-4xxr-7xxv-w3hj.json +++ b/advisories/unreviewed/2024/04/GHSA-4xxr-7xxv-w3hj/GHSA-4xxr-7xxv-w3hj.json @@ -7,12 +7,8 @@ "CVE-2024-26863" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhsr: Fix uninit-value access in hsr_get_node()\n\nKMSAN reported the following uninit-value access issue [1]:\n\n=====================================================\nBUG: KMSAN: uninit-value in hsr_get_node+0xa2e/0xa40 net/hsr/hsr_framereg.c:246\n hsr_get_node+0xa2e/0xa40 net/hsr/hsr_framereg.c:246\n fill_frame_info net/hsr/hsr_forward.c:577 [inline]\n hsr_forward_skb+0xe12/0x30e0 net/hsr/hsr_forward.c:615\n hsr_dev_xmit+0x1a1/0x270 net/hsr/hsr_device.c:223\n __netdev_start_xmit include/linux/netdevice.h:4940 [inline]\n netdev_start_xmit include/linux/netdevice.h:4954 [inline]\n xmit_one net/core/dev.c:3548 [inline]\n dev_hard_start_xmit+0x247/0xa10 net/core/dev.c:3564\n __dev_queue_xmit+0x33b8/0x5130 net/core/dev.c:4349\n dev_queue_xmit include/linux/netdevice.h:3134 [inline]\n packet_xmit+0x9c/0x6b0 net/packet/af_packet.c:276\n packet_snd net/packet/af_packet.c:3087 [inline]\n packet_sendmsg+0x8b1d/0x9f30 net/packet/af_packet.c:3119\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg net/socket.c:745 [inline]\n __sys_sendto+0x735/0xa10 net/socket.c:2191\n __do_sys_sendto net/socket.c:2203 [inline]\n __se_sys_sendto net/socket.c:2199 [inline]\n __x64_sys_sendto+0x125/0x1c0 net/socket.c:2199\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0x6d/0x140 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nUninit was created at:\n slab_post_alloc_hook+0x129/0xa70 mm/slab.h:768\n slab_alloc_node mm/slub.c:3478 [inline]\n kmem_cache_alloc_node+0x5e9/0xb10 mm/slub.c:3523\n kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:560\n __alloc_skb+0x318/0x740 net/core/skbuff.c:651\n alloc_skb include/linux/skbuff.h:1286 [inline]\n alloc_skb_with_frags+0xc8/0xbd0 net/core/skbuff.c:6334\n sock_alloc_send_pskb+0xa80/0xbf0 net/core/sock.c:2787\n packet_alloc_skb net/packet/af_packet.c:2936 [inline]\n packet_snd net/packet/af_packet.c:3030 [inline]\n packet_sendmsg+0x70e8/0x9f30 net/packet/af_packet.c:3119\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg net/socket.c:745 [inline]\n __sys_sendto+0x735/0xa10 net/socket.c:2191\n __do_sys_sendto net/socket.c:2203 [inline]\n __se_sys_sendto net/socket.c:2199 [inline]\n __x64_sys_sendto+0x125/0x1c0 net/socket.c:2199\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0x6d/0x140 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nCPU: 1 PID: 5033 Comm: syz-executor334 Not tainted 6.7.0-syzkaller-00562-g9f8413c4a66f #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023\n=====================================================\n\nIf the packet type ID field in the Ethernet header is either ETH_P_PRP or\nETH_P_HSR, but it is not followed by an HSR tag, hsr_get_skb_sequence_nr()\nreads an invalid value as a sequence number. This causes the above issue.\n\nThis patch fixes the issue by returning NULL if the Ethernet header is not\nfollowed by an HSR tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-57mj-8cw4-cm9w/GHSA-57mj-8cw4-cm9w.json b/advisories/unreviewed/2024/04/GHSA-57mj-8cw4-cm9w/GHSA-57mj-8cw4-cm9w.json index 168f5a9b660..08900153e7e 100644 --- a/advisories/unreviewed/2024/04/GHSA-57mj-8cw4-cm9w/GHSA-57mj-8cw4-cm9w.json +++ b/advisories/unreviewed/2024/04/GHSA-57mj-8cw4-cm9w/GHSA-57mj-8cw4-cm9w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-5cg8-xmcq-jx69/GHSA-5cg8-xmcq-jx69.json b/advisories/unreviewed/2024/04/GHSA-5cg8-xmcq-jx69/GHSA-5cg8-xmcq-jx69.json index 970abd2f76e..74ffa3c6b08 100644 --- a/advisories/unreviewed/2024/04/GHSA-5cg8-xmcq-jx69/GHSA-5cg8-xmcq-jx69.json +++ b/advisories/unreviewed/2024/04/GHSA-5cg8-xmcq-jx69/GHSA-5cg8-xmcq-jx69.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-5fvw-q4g6-wqf7/GHSA-5fvw-q4g6-wqf7.json b/advisories/unreviewed/2024/04/GHSA-5fvw-q4g6-wqf7/GHSA-5fvw-q4g6-wqf7.json index d0fd6e19152..33e6b156217 100644 --- a/advisories/unreviewed/2024/04/GHSA-5fvw-q4g6-wqf7/GHSA-5fvw-q4g6-wqf7.json +++ b/advisories/unreviewed/2024/04/GHSA-5fvw-q4g6-wqf7/GHSA-5fvw-q4g6-wqf7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-5mg2-h7qv-m552/GHSA-5mg2-h7qv-m552.json b/advisories/unreviewed/2024/04/GHSA-5mg2-h7qv-m552/GHSA-5mg2-h7qv-m552.json index bab25b9452d..05f9dacb137 100644 --- a/advisories/unreviewed/2024/04/GHSA-5mg2-h7qv-m552/GHSA-5mg2-h7qv-m552.json +++ b/advisories/unreviewed/2024/04/GHSA-5mg2-h7qv-m552/GHSA-5mg2-h7qv-m552.json @@ -7,12 +7,8 @@ "CVE-2024-27437" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/pci: Disable auto-enable of exclusive INTx IRQ\n\nCurrently for devices requiring masking at the irqchip for INTx, ie.\ndevices without DisINTx support, the IRQ is enabled in request_irq()\nand subsequently disabled as necessary to align with the masked status\nflag. This presents a window where the interrupt could fire between\nthese events, resulting in the IRQ incrementing the disable depth twice.\nThis would be unrecoverable for a user since the masked flag prevents\nnested enables through vfio.\n\nInstead, invert the logic using IRQF_NO_AUTOEN such that exclusive INTx\nis never auto-enabled, then unmask as required.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5r2r-xpfw-pmxc/GHSA-5r2r-xpfw-pmxc.json b/advisories/unreviewed/2024/04/GHSA-5r2r-xpfw-pmxc/GHSA-5r2r-xpfw-pmxc.json index 0f9edb0df9e..0130388d652 100644 --- a/advisories/unreviewed/2024/04/GHSA-5r2r-xpfw-pmxc/GHSA-5r2r-xpfw-pmxc.json +++ b/advisories/unreviewed/2024/04/GHSA-5r2r-xpfw-pmxc/GHSA-5r2r-xpfw-pmxc.json @@ -7,12 +7,8 @@ "CVE-2024-26825" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: free rx_data_reassembly skb on NCI device cleanup\n\nrx_data_reassembly skb is stored during NCI data exchange for processing\nfragmented packets. It is dropped only when the last fragment is processed\nor when an NTF packet with NCI_OP_RF_DEACTIVATE_NTF opcode is received.\nHowever, the NCI device may be deallocated before that which leads to skb\nleak.\n\nAs by design the rx_data_reassembly skb is bound to the NCI device and\nnothing prevents the device to be freed before the skb is processed in\nsome way and cleaned, free it on the NCI device cleanup.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-68mg-2p5r-x33h/GHSA-68mg-2p5r-x33h.json b/advisories/unreviewed/2024/04/GHSA-68mg-2p5r-x33h/GHSA-68mg-2p5r-x33h.json index 3bfc1616dd0..06543814d7b 100644 --- a/advisories/unreviewed/2024/04/GHSA-68mg-2p5r-x33h/GHSA-68mg-2p5r-x33h.json +++ b/advisories/unreviewed/2024/04/GHSA-68mg-2p5r-x33h/GHSA-68mg-2p5r-x33h.json @@ -7,12 +7,8 @@ "CVE-2024-26743" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/qedr: Fix qedr_create_user_qp error flow\n\nAvoid the following warning by making sure to free the allocated\nresources in case that qedr_init_user_queue() fail.\n\n-----------[ cut here ]-----------\nWARNING: CPU: 0 PID: 143192 at drivers/infiniband/core/rdma_core.c:874 uverbs_destroy_ufile_hw+0xcf/0xf0 [ib_uverbs]\nModules linked in: tls target_core_user uio target_core_pscsi target_core_file target_core_iblock ib_srpt ib_srp scsi_transport_srp nfsd nfs_acl rpcsec_gss_krb5 auth_rpcgss nfsv4 dns_resolver nfs lockd grace fscache netfs 8021q garp mrp stp llc ext4 mbcache jbd2 opa_vnic ib_umad ib_ipoib sunrpc rdma_ucm ib_isert iscsi_target_mod target_core_mod ib_iser libiscsi scsi_transport_iscsi rdma_cm iw_cm ib_cm hfi1 intel_rapl_msr intel_rapl_common mgag200 qedr sb_edac drm_shmem_helper rdmavt x86_pkg_temp_thermal drm_kms_helper intel_powerclamp ib_uverbs coretemp i2c_algo_bit kvm_intel dell_wmi_descriptor ipmi_ssif sparse_keymap kvm ib_core rfkill syscopyarea sysfillrect video sysimgblt irqbypass ipmi_si ipmi_devintf fb_sys_fops rapl iTCO_wdt mxm_wmi iTCO_vendor_support intel_cstate pcspkr dcdbas intel_uncore ipmi_msghandler lpc_ich acpi_power_meter mei_me mei fuse drm xfs libcrc32c qede sd_mod ahci libahci t10_pi sg crct10dif_pclmul crc32_pclmul crc32c_intel qed libata tg3\nghash_clmulni_intel megaraid_sas crc8 wmi [last unloaded: ib_srpt]\nCPU: 0 PID: 143192 Comm: fi_rdm_tagged_p Kdump: loaded Not tainted 5.14.0-408.el9.x86_64 #1\nHardware name: Dell Inc. PowerEdge R430/03XKDV, BIOS 2.14.0 01/25/2022\nRIP: 0010:uverbs_destroy_ufile_hw+0xcf/0xf0 [ib_uverbs]\nCode: 5d 41 5c 41 5d 41 5e e9 0f 26 1b dd 48 89 df e8 67 6a ff ff 49 8b 86 10 01 00 00 48 85 c0 74 9c 4c 89 e7 e8 83 c0 cb dd eb 92 <0f> 0b eb be 0f 0b be 04 00 00 00 48 89 df e8 8e f5 ff ff e9 6d ff\nRSP: 0018:ffffb7c6cadfbc60 EFLAGS: 00010286\nRAX: ffff8f0889ee3f60 RBX: ffff8f088c1a5200 RCX: 00000000802a0016\nRDX: 00000000802a0017 RSI: 0000000000000001 RDI: ffff8f0880042600\nRBP: 0000000000000001 R08: 0000000000000001 R09: 0000000000000000\nR10: ffff8f11fffd5000 R11: 0000000000039000 R12: ffff8f0d5b36cd80\nR13: ffff8f088c1a5250 R14: ffff8f1206d91000 R15: 0000000000000000\nFS: 0000000000000000(0000) GS:ffff8f11d7c00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000147069200e20 CR3: 00000001c7210002 CR4: 00000000001706f0\nCall Trace:\n\n? show_trace_log_lvl+0x1c4/0x2df\n? show_trace_log_lvl+0x1c4/0x2df\n? ib_uverbs_close+0x1f/0xb0 [ib_uverbs]\n? uverbs_destroy_ufile_hw+0xcf/0xf0 [ib_uverbs]\n? __warn+0x81/0x110\n? uverbs_destroy_ufile_hw+0xcf/0xf0 [ib_uverbs]\n? report_bug+0x10a/0x140\n? handle_bug+0x3c/0x70\n? exc_invalid_op+0x14/0x70\n? asm_exc_invalid_op+0x16/0x20\n? uverbs_destroy_ufile_hw+0xcf/0xf0 [ib_uverbs]\nib_uverbs_close+0x1f/0xb0 [ib_uverbs]\n__fput+0x94/0x250\ntask_work_run+0x5c/0x90\ndo_exit+0x270/0x4a0\ndo_group_exit+0x2d/0x90\nget_signal+0x87c/0x8c0\narch_do_signal_or_restart+0x25/0x100\n? ib_uverbs_ioctl+0xc2/0x110 [ib_uverbs]\nexit_to_user_mode_loop+0x9c/0x130\nexit_to_user_mode_prepare+0xb6/0x100\nsyscall_exit_to_user_mode+0x12/0x40\ndo_syscall_64+0x69/0x90\n? syscall_exit_work+0x103/0x130\n? syscall_exit_to_user_mode+0x22/0x40\n? do_syscall_64+0x69/0x90\n? syscall_exit_work+0x103/0x130\n? syscall_exit_to_user_mode+0x22/0x40\n? do_syscall_64+0x69/0x90\n? do_syscall_64+0x69/0x90\n? common_interrupt+0x43/0xa0\nentry_SYSCALL_64_after_hwframe+0x72/0xdc\nRIP: 0033:0x1470abe3ec6b\nCode: Unable to access opcode bytes at RIP 0x1470abe3ec41.\nRSP: 002b:00007fff13ce9108 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\nRAX: fffffffffffffffc RBX: 00007fff13ce9218 RCX: 00001470abe3ec6b\nRDX: 00007fff13ce9200 RSI: 00000000c0181b01 RDI: 0000000000000004\nRBP: 00007fff13ce91e0 R08: 0000558d9655da10 R09: 0000558d9655dd00\nR10: 00007fff13ce95c0 R11: 0000000000000246 R12: 00007fff13ce9358\nR13: 0000000000000013 R14: 0000558d9655db50 R15: 00007fff13ce9470\n\n--[ end trace 888a9b92e04c5c97 ]--", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-69h6-fpm9-fc3r/GHSA-69h6-fpm9-fc3r.json b/advisories/unreviewed/2024/04/GHSA-69h6-fpm9-fc3r/GHSA-69h6-fpm9-fc3r.json index d7ab1875f5e..628ec59659e 100644 --- a/advisories/unreviewed/2024/04/GHSA-69h6-fpm9-fc3r/GHSA-69h6-fpm9-fc3r.json +++ b/advisories/unreviewed/2024/04/GHSA-69h6-fpm9-fc3r/GHSA-69h6-fpm9-fc3r.json @@ -7,12 +7,8 @@ "CVE-2024-26813" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/platform: Create persistent IRQ handlers\n\nThe vfio-platform SET_IRQS ioctl currently allows loopback triggering of\nan interrupt before a signaling eventfd has been configured by the user,\nwhich thereby allows a NULL pointer dereference.\n\nRather than register the IRQ relative to a valid trigger, register all\nIRQs in a disabled state in the device open path. This allows mask\noperations on the IRQ to nest within the overall enable state governed\nby a valid eventfd signal. This decouples @masked, protected by the\n@locked spinlock from @trigger, protected via the @igate mutex.\n\nIn doing so, it's guaranteed that changes to @trigger cannot race the\nIRQ handlers because the IRQ handler is synchronously disabled before\nmodifying the trigger, and loopback triggering of the IRQ via ioctl is\nsafe due to serialization with trigger changes via igate.\n\nFor compatibility, request_irq() failures are maintained to be local to\nthe SET_IRQS ioctl rather than a fatal error in the open device path.\nThis allows, for example, a userspace driver with polling mode support\nto continue to work regardless of moving the request_irq() call site.\nThis necessarily blocks all SET_IRQS access to the failed index.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-6fm7-55mm-8gfh/GHSA-6fm7-55mm-8gfh.json b/advisories/unreviewed/2024/04/GHSA-6fm7-55mm-8gfh/GHSA-6fm7-55mm-8gfh.json index eee19513d9a..0916c85d848 100644 --- a/advisories/unreviewed/2024/04/GHSA-6fm7-55mm-8gfh/GHSA-6fm7-55mm-8gfh.json +++ b/advisories/unreviewed/2024/04/GHSA-6fm7-55mm-8gfh/GHSA-6fm7-55mm-8gfh.json @@ -7,12 +7,8 @@ "CVE-2024-26764" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/aio: Restrict kiocb_set_cancel_fn() to I/O submitted via libaio\n\nIf kiocb_set_cancel_fn() is called for I/O submitted via io_uring, the\nfollowing kernel warning appears:\n\nWARNING: CPU: 3 PID: 368 at fs/aio.c:598 kiocb_set_cancel_fn+0x9c/0xa8\nCall trace:\n kiocb_set_cancel_fn+0x9c/0xa8\n ffs_epfile_read_iter+0x144/0x1d0\n io_read+0x19c/0x498\n io_issue_sqe+0x118/0x27c\n io_submit_sqes+0x25c/0x5fc\n __arm64_sys_io_uring_enter+0x104/0xab0\n invoke_syscall+0x58/0x11c\n el0_svc_common+0xb4/0xf4\n do_el0_svc+0x2c/0xb0\n el0_svc+0x2c/0xa4\n el0t_64_sync_handler+0x68/0xb4\n el0t_64_sync+0x1a4/0x1a8\n\nFix this by setting the IOCB_AIO_RW flag for read and write I/O that is\nsubmitted by libaio.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-6m7r-j2xg-cvhq/GHSA-6m7r-j2xg-cvhq.json b/advisories/unreviewed/2024/04/GHSA-6m7r-j2xg-cvhq/GHSA-6m7r-j2xg-cvhq.json index 0da353d3ce9..2810efe457d 100644 --- a/advisories/unreviewed/2024/04/GHSA-6m7r-j2xg-cvhq/GHSA-6m7r-j2xg-cvhq.json +++ b/advisories/unreviewed/2024/04/GHSA-6m7r-j2xg-cvhq/GHSA-6m7r-j2xg-cvhq.json @@ -7,12 +7,8 @@ "CVE-2024-26704" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix double-free of blocks due to wrong extents moved_len\n\nIn ext4_move_extents(), moved_len is only updated when all moves are\nsuccessfully executed, and only discards orig_inode and donor_inode\npreallocations when moved_len is not zero. When the loop fails to exit\nafter successfully moving some extents, moved_len is not updated and\nremains at 0, so it does not discard the preallocations.\n\nIf the moved extents overlap with the preallocated extents, the\noverlapped extents are freed twice in ext4_mb_release_inode_pa() and\next4_process_freed_data() (as described in commit 94d7c16cbbbd (\"ext4:\nFix double-free of blocks with EXT4_IOC_MOVE_EXT\")), and bb_free is\nincremented twice. Hence when trim is executed, a zero-division bug is\ntriggered in mb_update_avg_fragment_size() because bb_free is not zero\nand bb_fragments is zero.\n\nTherefore, update move_len after each extent move to avoid the issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-6r45-w96c-v9jx/GHSA-6r45-w96c-v9jx.json b/advisories/unreviewed/2024/04/GHSA-6r45-w96c-v9jx/GHSA-6r45-w96c-v9jx.json index 6ead61da242..42ce77144d0 100644 --- a/advisories/unreviewed/2024/04/GHSA-6r45-w96c-v9jx/GHSA-6r45-w96c-v9jx.json +++ b/advisories/unreviewed/2024/04/GHSA-6r45-w96c-v9jx/GHSA-6r45-w96c-v9jx.json @@ -7,12 +7,8 @@ "CVE-2024-26895" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wilc1000: prevent use-after-free on vif when cleaning up all interfaces\n\nwilc_netdev_cleanup currently triggers a KASAN warning, which can be\nobserved on interface registration error path, or simply by\nremoving the module/unbinding device from driver:\n\necho spi0.1 > /sys/bus/spi/drivers/wilc1000_spi/unbind\n\n==================================================================\nBUG: KASAN: slab-use-after-free in wilc_netdev_cleanup+0x508/0x5cc\nRead of size 4 at addr c54d1ce8 by task sh/86\n\nCPU: 0 PID: 86 Comm: sh Not tainted 6.8.0-rc1+ #117\nHardware name: Atmel SAMA5\n unwind_backtrace from show_stack+0x18/0x1c\n show_stack from dump_stack_lvl+0x34/0x58\n dump_stack_lvl from print_report+0x154/0x500\n print_report from kasan_report+0xac/0xd8\n kasan_report from wilc_netdev_cleanup+0x508/0x5cc\n wilc_netdev_cleanup from wilc_bus_remove+0xc8/0xec\n wilc_bus_remove from spi_remove+0x8c/0xac\n spi_remove from device_release_driver_internal+0x434/0x5f8\n device_release_driver_internal from unbind_store+0xbc/0x108\n unbind_store from kernfs_fop_write_iter+0x398/0x584\n kernfs_fop_write_iter from vfs_write+0x728/0xf88\n vfs_write from ksys_write+0x110/0x1e4\n ksys_write from ret_fast_syscall+0x0/0x1c\n\n[...]\n\nAllocated by task 1:\n kasan_save_track+0x30/0x5c\n __kasan_kmalloc+0x8c/0x94\n __kmalloc_node+0x1cc/0x3e4\n kvmalloc_node+0x48/0x180\n alloc_netdev_mqs+0x68/0x11dc\n alloc_etherdev_mqs+0x28/0x34\n wilc_netdev_ifc_init+0x34/0x8ec\n wilc_cfg80211_init+0x690/0x910\n wilc_bus_probe+0xe0/0x4a0\n spi_probe+0x158/0x1b0\n really_probe+0x270/0xdf4\n __driver_probe_device+0x1dc/0x580\n driver_probe_device+0x60/0x140\n __driver_attach+0x228/0x5d4\n bus_for_each_dev+0x13c/0x1a8\n bus_add_driver+0x2a0/0x608\n driver_register+0x24c/0x578\n do_one_initcall+0x180/0x310\n kernel_init_freeable+0x424/0x484\n kernel_init+0x20/0x148\n ret_from_fork+0x14/0x28\n\nFreed by task 86:\n kasan_save_track+0x30/0x5c\n kasan_save_free_info+0x38/0x58\n __kasan_slab_free+0xe4/0x140\n kfree+0xb0/0x238\n device_release+0xc0/0x2a8\n kobject_put+0x1d4/0x46c\n netdev_run_todo+0x8fc/0x11d0\n wilc_netdev_cleanup+0x1e4/0x5cc\n wilc_bus_remove+0xc8/0xec\n spi_remove+0x8c/0xac\n device_release_driver_internal+0x434/0x5f8\n unbind_store+0xbc/0x108\n kernfs_fop_write_iter+0x398/0x584\n vfs_write+0x728/0xf88\n ksys_write+0x110/0x1e4\n ret_fast_syscall+0x0/0x1c\n [...]\n\nDavid Mosberger-Tan initial investigation [1] showed that this\nuse-after-free is due to netdevice unregistration during vif list\ntraversal. When unregistering a net device, since the needs_free_netdev has\nbeen set to true during registration, the netdevice object is also freed,\nand as a consequence, the corresponding vif object too, since it is\nattached to it as private netdevice data. The next occurrence of the loop\nthen tries to access freed vif pointer to the list to move forward in the\nlist.\n\nFix this use-after-free thanks to two mechanisms:\n- navigate in the list with list_for_each_entry_safe, which allows to\n safely modify the list as we go through each element. For each element,\n remove it from the list with list_del_rcu\n- make sure to wait for RCU grace period end after each vif removal to make\n sure it is safe to free the corresponding vif too (through\n unregister_netdev)\n\nSince we are in a RCU \"modifier\" path (not a \"reader\" path), and because\nsuch path is expected not to be concurrent to any other modifier (we are\nusing the vif_mutex lock), we do not need to use RCU list API, that's why\nwe can benefit from list_for_each_entry_safe.\n\n[1] https://lore.kernel.org/linux-wireless/ab077dbe58b1ea5de0a3b2ca21f275a07af967d2.camel@egauge.net/", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-6vh7-f36j-r556/GHSA-6vh7-f36j-r556.json b/advisories/unreviewed/2024/04/GHSA-6vh7-f36j-r556/GHSA-6vh7-f36j-r556.json index 8a8aca9915d..1bcaba59ce0 100644 --- a/advisories/unreviewed/2024/04/GHSA-6vh7-f36j-r556/GHSA-6vh7-f36j-r556.json +++ b/advisories/unreviewed/2024/04/GHSA-6vh7-f36j-r556/GHSA-6vh7-f36j-r556.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-7257-c3g3-gcf6/GHSA-7257-c3g3-gcf6.json b/advisories/unreviewed/2024/04/GHSA-7257-c3g3-gcf6/GHSA-7257-c3g3-gcf6.json index 51aea23e8a8..d18d658332b 100644 --- a/advisories/unreviewed/2024/04/GHSA-7257-c3g3-gcf6/GHSA-7257-c3g3-gcf6.json +++ b/advisories/unreviewed/2024/04/GHSA-7257-c3g3-gcf6/GHSA-7257-c3g3-gcf6.json @@ -7,12 +7,8 @@ "CVE-2024-26749" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdns3: fixed memory use after free at cdns3_gadget_ep_disable()\n\n ...\n cdns3_gadget_ep_free_request(&priv_ep->endpoint, &priv_req->request);\n list_del_init(&priv_req->list);\n ...\n\n'priv_req' actually free at cdns3_gadget_ep_free_request(). But\nlist_del_init() use priv_req->list after it.\n\n[ 1542.642868][ T534] BUG: KFENCE: use-after-free read in __list_del_entry_valid+0x10/0xd4\n[ 1542.642868][ T534]\n[ 1542.653162][ T534] Use-after-free read at 0x000000009ed0ba99 (in kfence-#3):\n[ 1542.660311][ T534] __list_del_entry_valid+0x10/0xd4\n[ 1542.665375][ T534] cdns3_gadget_ep_disable+0x1f8/0x388 [cdns3]\n[ 1542.671571][ T534] usb_ep_disable+0x44/0xe4\n[ 1542.675948][ T534] ffs_func_eps_disable+0x64/0xc8\n[ 1542.680839][ T534] ffs_func_set_alt+0x74/0x368\n[ 1542.685478][ T534] ffs_func_disable+0x18/0x28\n\nMove list_del_init() before cdns3_gadget_ep_free_request() to resolve this\nproblem.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-728g-23p2-mf29/GHSA-728g-23p2-mf29.json b/advisories/unreviewed/2024/04/GHSA-728g-23p2-mf29/GHSA-728g-23p2-mf29.json index dbf28da6417..a177a02573d 100644 --- a/advisories/unreviewed/2024/04/GHSA-728g-23p2-mf29/GHSA-728g-23p2-mf29.json +++ b/advisories/unreviewed/2024/04/GHSA-728g-23p2-mf29/GHSA-728g-23p2-mf29.json @@ -7,12 +7,8 @@ "CVE-2024-26771" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: ti: edma: Add some null pointer checks to the edma_probe\n\ndevm_kasprintf() returns a pointer to dynamically allocated memory\nwhich can be NULL upon failure. Ensure the allocation was successful\nby checking the pointer validity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-744q-w332-xxx3/GHSA-744q-w332-xxx3.json b/advisories/unreviewed/2024/04/GHSA-744q-w332-xxx3/GHSA-744q-w332-xxx3.json index d85b9d3fdad..3d7106849a7 100644 --- a/advisories/unreviewed/2024/04/GHSA-744q-w332-xxx3/GHSA-744q-w332-xxx3.json +++ b/advisories/unreviewed/2024/04/GHSA-744q-w332-xxx3/GHSA-744q-w332-xxx3.json @@ -7,12 +7,8 @@ "CVE-2023-48939" ], "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-77mf-44mv-3m36/GHSA-77mf-44mv-3m36.json b/advisories/unreviewed/2024/04/GHSA-77mf-44mv-3m36/GHSA-77mf-44mv-3m36.json index 4a7829bbb1b..76eb6ecc805 100644 --- a/advisories/unreviewed/2024/04/GHSA-77mf-44mv-3m36/GHSA-77mf-44mv-3m36.json +++ b/advisories/unreviewed/2024/04/GHSA-77mf-44mv-3m36/GHSA-77mf-44mv-3m36.json @@ -7,12 +7,8 @@ "CVE-2024-26925" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: release mutex after nft_gc_seq_end from abort path\n\nThe commit mutex should not be released during the critical section\nbetween nft_gc_seq_begin() and nft_gc_seq_end(), otherwise, async GC\nworker could collect expired objects and get the released commit lock\nwithin the same GC sequence.\n\nnf_tables_module_autoload() temporarily releases the mutex to load\nmodule dependencies, then it goes back to replay the transaction again.\nMove it at the end of the abort phase after nft_gc_seq_end() is called.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-782j-786c-25hh/GHSA-782j-786c-25hh.json b/advisories/unreviewed/2024/04/GHSA-782j-786c-25hh/GHSA-782j-786c-25hh.json index 7eba824564e..d2b927ad70e 100644 --- a/advisories/unreviewed/2024/04/GHSA-782j-786c-25hh/GHSA-782j-786c-25hh.json +++ b/advisories/unreviewed/2024/04/GHSA-782j-786c-25hh/GHSA-782j-786c-25hh.json @@ -7,12 +7,8 @@ "CVE-2024-26675" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nppp_async: limit MRU to 64K\n\nsyzbot triggered a warning [1] in __alloc_pages():\n\nWARN_ON_ONCE_GFP(order > MAX_PAGE_ORDER, gfp)\n\nWillem fixed a similar issue in commit c0a2a1b0d631 (\"ppp: limit MRU to 64K\")\n\nAdopt the same sanity check for ppp_async_ioctl(PPPIOCSMRU)\n\n[1]:\n\n WARNING: CPU: 1 PID: 11 at mm/page_alloc.c:4543 __alloc_pages+0x308/0x698 mm/page_alloc.c:4543\nModules linked in:\nCPU: 1 PID: 11 Comm: kworker/u4:0 Not tainted 6.8.0-rc2-syzkaller-g41bccc98fb79 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023\nWorkqueue: events_unbound flush_to_ldisc\npstate: 204000c5 (nzCv daIF +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : __alloc_pages+0x308/0x698 mm/page_alloc.c:4543\n lr : __alloc_pages+0xc8/0x698 mm/page_alloc.c:4537\nsp : ffff800093967580\nx29: ffff800093967660 x28: ffff8000939675a0 x27: dfff800000000000\nx26: ffff70001272ceb4 x25: 0000000000000000 x24: ffff8000939675c0\nx23: 0000000000000000 x22: 0000000000060820 x21: 1ffff0001272ceb8\nx20: ffff8000939675e0 x19: 0000000000000010 x18: ffff800093967120\nx17: ffff800083bded5c x16: ffff80008ac97500 x15: 0000000000000005\nx14: 1ffff0001272cebc x13: 0000000000000000 x12: 0000000000000000\nx11: ffff70001272cec1 x10: 1ffff0001272cec0 x9 : 0000000000000001\nx8 : ffff800091c91000 x7 : 0000000000000000 x6 : 000000000000003f\nx5 : 00000000ffffffff x4 : 0000000000000000 x3 : 0000000000000020\nx2 : 0000000000000008 x1 : 0000000000000000 x0 : ffff8000939675e0\nCall trace:\n __alloc_pages+0x308/0x698 mm/page_alloc.c:4543\n __alloc_pages_node include/linux/gfp.h:238 [inline]\n alloc_pages_node include/linux/gfp.h:261 [inline]\n __kmalloc_large_node+0xbc/0x1fc mm/slub.c:3926\n __do_kmalloc_node mm/slub.c:3969 [inline]\n __kmalloc_node_track_caller+0x418/0x620 mm/slub.c:4001\n kmalloc_reserve+0x17c/0x23c net/core/skbuff.c:590\n __alloc_skb+0x1c8/0x3d8 net/core/skbuff.c:651\n __netdev_alloc_skb+0xb8/0x3e8 net/core/skbuff.c:715\n netdev_alloc_skb include/linux/skbuff.h:3235 [inline]\n dev_alloc_skb include/linux/skbuff.h:3248 [inline]\n ppp_async_input drivers/net/ppp/ppp_async.c:863 [inline]\n ppp_asynctty_receive+0x588/0x186c drivers/net/ppp/ppp_async.c:341\n tty_ldisc_receive_buf+0x12c/0x15c drivers/tty/tty_buffer.c:390\n tty_port_default_receive_buf+0x74/0xac drivers/tty/tty_port.c:37\n receive_buf drivers/tty/tty_buffer.c:444 [inline]\n flush_to_ldisc+0x284/0x6e4 drivers/tty/tty_buffer.c:494\n process_one_work+0x694/0x1204 kernel/workqueue.c:2633\n process_scheduled_works kernel/workqueue.c:2706 [inline]\n worker_thread+0x938/0xef4 kernel/workqueue.c:2787\n kthread+0x288/0x310 kernel/kthread.c:388\n ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:860", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-7g56-3wmh-7x3p/GHSA-7g56-3wmh-7x3p.json b/advisories/unreviewed/2024/04/GHSA-7g56-3wmh-7x3p/GHSA-7g56-3wmh-7x3p.json index ecdf83cdd19..82db3cfa9ea 100644 --- a/advisories/unreviewed/2024/04/GHSA-7g56-3wmh-7x3p/GHSA-7g56-3wmh-7x3p.json +++ b/advisories/unreviewed/2024/04/GHSA-7g56-3wmh-7x3p/GHSA-7g56-3wmh-7x3p.json @@ -7,12 +7,8 @@ "CVE-2024-26698" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhv_netvsc: Fix race condition between netvsc_probe and netvsc_remove\n\nIn commit ac5047671758 (\"hv_netvsc: Disable NAPI before closing the\nVMBus channel\"), napi_disable was getting called for all channels,\nincluding all subchannels without confirming if they are enabled or not.\n\nThis caused hv_netvsc getting hung at napi_disable, when netvsc_probe()\nhas finished running but nvdev->subchan_work has not started yet.\nnetvsc_subchan_work() -> rndis_set_subchannel() has not created the\nsub-channels and because of that netvsc_sc_open() is not running.\nnetvsc_remove() calls cancel_work_sync(&nvdev->subchan_work), for which\nnetvsc_subchan_work did not run.\n\nnetif_napi_add() sets the bit NAPI_STATE_SCHED because it ensures NAPI\ncannot be scheduled. Then netvsc_sc_open() -> napi_enable will clear the\nNAPIF_STATE_SCHED bit, so it can be scheduled. napi_disable() does the\nopposite.\n\nNow during netvsc_device_remove(), when napi_disable is called for those\nsubchannels, napi_disable gets stuck on infinite msleep.\n\nThis fix addresses this problem by ensuring that napi_disable() is not\ngetting called for non-enabled NAPI struct.\nBut netif_napi_del() is still necessary for these non-enabled NAPI struct\nfor cleanup purpose.\n\nCall trace:\n[ 654.559417] task:modprobe state:D stack: 0 pid: 2321 ppid: 1091 flags:0x00004002\n[ 654.568030] Call Trace:\n[ 654.571221] \n[ 654.573790] __schedule+0x2d6/0x960\n[ 654.577733] schedule+0x69/0xf0\n[ 654.581214] schedule_timeout+0x87/0x140\n[ 654.585463] ? __bpf_trace_tick_stop+0x20/0x20\n[ 654.590291] msleep+0x2d/0x40\n[ 654.593625] napi_disable+0x2b/0x80\n[ 654.597437] netvsc_device_remove+0x8a/0x1f0 [hv_netvsc]\n[ 654.603935] rndis_filter_device_remove+0x194/0x1c0 [hv_netvsc]\n[ 654.611101] ? do_wait_intr+0xb0/0xb0\n[ 654.615753] netvsc_remove+0x7c/0x120 [hv_netvsc]\n[ 654.621675] vmbus_remove+0x27/0x40 [hv_vmbus]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-7j5c-w63j-h48p/GHSA-7j5c-w63j-h48p.json b/advisories/unreviewed/2024/04/GHSA-7j5c-w63j-h48p/GHSA-7j5c-w63j-h48p.json index 0cdc2536ab5..2a8be70a129 100644 --- a/advisories/unreviewed/2024/04/GHSA-7j5c-w63j-h48p/GHSA-7j5c-w63j-h48p.json +++ b/advisories/unreviewed/2024/04/GHSA-7j5c-w63j-h48p/GHSA-7j5c-w63j-h48p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-7mjh-m8r7-cjw8/GHSA-7mjh-m8r7-cjw8.json b/advisories/unreviewed/2024/04/GHSA-7mjh-m8r7-cjw8/GHSA-7mjh-m8r7-cjw8.json index 5ff9e2ce017..6bdd081c6ca 100644 --- a/advisories/unreviewed/2024/04/GHSA-7mjh-m8r7-cjw8/GHSA-7mjh-m8r7-cjw8.json +++ b/advisories/unreviewed/2024/04/GHSA-7mjh-m8r7-cjw8/GHSA-7mjh-m8r7-cjw8.json @@ -7,12 +7,8 @@ "CVE-2024-26777" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: sis: Error out if pixclock equals zero\n\nThe userspace program could pass any values to the driver through\nioctl() interface. If the driver doesn't check the value of pixclock,\nit may cause divide-by-zero error.\n\nIn sisfb_check_var(), var->pixclock is used as a divisor to caculate\ndrate before it is checked against zero. Fix this by checking it\nat the beginning.\n\nThis is similar to CVE-2022-3061 in i740fb which was fixed by\ncommit 15cf0b8.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-7vqv-4gqw-665q/GHSA-7vqv-4gqw-665q.json b/advisories/unreviewed/2024/04/GHSA-7vqv-4gqw-665q/GHSA-7vqv-4gqw-665q.json index b3b185179a1..9cbc7b5daa3 100644 --- a/advisories/unreviewed/2024/04/GHSA-7vqv-4gqw-665q/GHSA-7vqv-4gqw-665q.json +++ b/advisories/unreviewed/2024/04/GHSA-7vqv-4gqw-665q/GHSA-7vqv-4gqw-665q.json @@ -7,12 +7,8 @@ "CVE-2024-26791" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: dev-replace: properly validate device names\n\nThere's a syzbot report that device name buffers passed to device\nreplace are not properly checked for string termination which could lead\nto a read out of bounds in getname_kernel().\n\nAdd a helper that validates both source and target device name buffers.\nFor devid as the source initialize the buffer to empty string in case\nsomething tries to read it later.\n\nThis was originally analyzed and fixed in a different way by Edward Adam\nDavis (see links).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-7xpv-78qx-q843/GHSA-7xpv-78qx-q843.json b/advisories/unreviewed/2024/04/GHSA-7xpv-78qx-q843/GHSA-7xpv-78qx-q843.json index fd03c828590..5c8da005f4e 100644 --- a/advisories/unreviewed/2024/04/GHSA-7xpv-78qx-q843/GHSA-7xpv-78qx-q843.json +++ b/advisories/unreviewed/2024/04/GHSA-7xpv-78qx-q843/GHSA-7xpv-78qx-q843.json @@ -7,12 +7,8 @@ "CVE-2024-26805" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetlink: Fix kernel-infoleak-after-free in __skb_datagram_iter\n\nsyzbot reported the following uninit-value access issue [1]:\n\nnetlink_to_full_skb() creates a new `skb` and puts the `skb->data`\npassed as a 1st arg of netlink_to_full_skb() onto new `skb`. The data\nsize is specified as `len` and passed to skb_put_data(). This `len`\nis based on `skb->end` that is not data offset but buffer offset. The\n`skb->end` contains data and tailroom. Since the tailroom is not\ninitialized when the new `skb` created, KMSAN detects uninitialized\nmemory area when copying the data.\n\nThis patch resolved this issue by correct the len from `skb->end` to\n`skb->len`, which is the actual data offset.\n\nBUG: KMSAN: kernel-infoleak-after-free in instrument_copy_to_user include/linux/instrumented.h:114 [inline]\nBUG: KMSAN: kernel-infoleak-after-free in copy_to_user_iter lib/iov_iter.c:24 [inline]\nBUG: KMSAN: kernel-infoleak-after-free in iterate_ubuf include/linux/iov_iter.h:29 [inline]\nBUG: KMSAN: kernel-infoleak-after-free in iterate_and_advance2 include/linux/iov_iter.h:245 [inline]\nBUG: KMSAN: kernel-infoleak-after-free in iterate_and_advance include/linux/iov_iter.h:271 [inline]\nBUG: KMSAN: kernel-infoleak-after-free in _copy_to_iter+0x364/0x2520 lib/iov_iter.c:186\n instrument_copy_to_user include/linux/instrumented.h:114 [inline]\n copy_to_user_iter lib/iov_iter.c:24 [inline]\n iterate_ubuf include/linux/iov_iter.h:29 [inline]\n iterate_and_advance2 include/linux/iov_iter.h:245 [inline]\n iterate_and_advance include/linux/iov_iter.h:271 [inline]\n _copy_to_iter+0x364/0x2520 lib/iov_iter.c:186\n copy_to_iter include/linux/uio.h:197 [inline]\n simple_copy_to_iter+0x68/0xa0 net/core/datagram.c:532\n __skb_datagram_iter+0x123/0xdc0 net/core/datagram.c:420\n skb_copy_datagram_iter+0x5c/0x200 net/core/datagram.c:546\n skb_copy_datagram_msg include/linux/skbuff.h:3960 [inline]\n packet_recvmsg+0xd9c/0x2000 net/packet/af_packet.c:3482\n sock_recvmsg_nosec net/socket.c:1044 [inline]\n sock_recvmsg net/socket.c:1066 [inline]\n sock_read_iter+0x467/0x580 net/socket.c:1136\n call_read_iter include/linux/fs.h:2014 [inline]\n new_sync_read fs/read_write.c:389 [inline]\n vfs_read+0x8f6/0xe00 fs/read_write.c:470\n ksys_read+0x20f/0x4c0 fs/read_write.c:613\n __do_sys_read fs/read_write.c:623 [inline]\n __se_sys_read fs/read_write.c:621 [inline]\n __x64_sys_read+0x93/0xd0 fs/read_write.c:621\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0x44/0x110 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nUninit was stored to memory at:\n skb_put_data include/linux/skbuff.h:2622 [inline]\n netlink_to_full_skb net/netlink/af_netlink.c:181 [inline]\n __netlink_deliver_tap_skb net/netlink/af_netlink.c:298 [inline]\n __netlink_deliver_tap+0x5be/0xc90 net/netlink/af_netlink.c:325\n netlink_deliver_tap net/netlink/af_netlink.c:338 [inline]\n netlink_deliver_tap_kernel net/netlink/af_netlink.c:347 [inline]\n netlink_unicast_kernel net/netlink/af_netlink.c:1341 [inline]\n netlink_unicast+0x10f1/0x1250 net/netlink/af_netlink.c:1368\n netlink_sendmsg+0x1238/0x13d0 net/netlink/af_netlink.c:1910\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg net/socket.c:745 [inline]\n ____sys_sendmsg+0x9c2/0xd60 net/socket.c:2584\n ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2638\n __sys_sendmsg net/socket.c:2667 [inline]\n __do_sys_sendmsg net/socket.c:2676 [inline]\n __se_sys_sendmsg net/socket.c:2674 [inline]\n __x64_sys_sendmsg+0x307/0x490 net/socket.c:2674\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0x44/0x110 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nUninit was created at:\n free_pages_prepare mm/page_alloc.c:1087 [inline]\n free_unref_page_prepare+0xb0/0xa40 mm/page_alloc.c:2347\n free_unref_page_list+0xeb/0x1100 mm/page_alloc.c:2533\n release_pages+0x23d3/0x2410 mm/swap.c:1042\n free_pages_and_swap_cache+0xd9/0xf0 mm/swap_state.c:316\n tlb_batch_pages\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-7xq6-jm62-ww8g/GHSA-7xq6-jm62-ww8g.json b/advisories/unreviewed/2024/04/GHSA-7xq6-jm62-ww8g/GHSA-7xq6-jm62-ww8g.json index 13cf3e2ee3f..84d23b36dbe 100644 --- a/advisories/unreviewed/2024/04/GHSA-7xq6-jm62-ww8g/GHSA-7xq6-jm62-ww8g.json +++ b/advisories/unreviewed/2024/04/GHSA-7xq6-jm62-ww8g/GHSA-7xq6-jm62-ww8g.json @@ -7,12 +7,8 @@ "CVE-2024-26687" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxen/events: close evtchn after mapping cleanup\n\nshutdown_pirq and startup_pirq are not taking the\nirq_mapping_update_lock because they can't due to lock inversion. Both\nare called with the irq_desc->lock being taking. The lock order,\nhowever, is first irq_mapping_update_lock and then irq_desc->lock.\n\nThis opens multiple races:\n- shutdown_pirq can be interrupted by a function that allocates an event\n channel:\n\n CPU0 CPU1\n shutdown_pirq {\n xen_evtchn_close(e)\n __startup_pirq {\n EVTCHNOP_bind_pirq\n -> returns just freed evtchn e\n set_evtchn_to_irq(e, irq)\n }\n xen_irq_info_cleanup() {\n set_evtchn_to_irq(e, -1)\n }\n }\n\n Assume here event channel e refers here to the same event channel\n number.\n After this race the evtchn_to_irq mapping for e is invalid (-1).\n\n- __startup_pirq races with __unbind_from_irq in a similar way. Because\n __startup_pirq doesn't take irq_mapping_update_lock it can grab the\n evtchn that __unbind_from_irq is currently freeing and cleaning up. In\n this case even though the event channel is allocated, its mapping can\n be unset in evtchn_to_irq.\n\nThe fix is to first cleanup the mappings and then close the event\nchannel. In this way, when an event channel gets allocated it's\npotential previous evtchn_to_irq mappings are guaranteed to be unset already.\nThis is also the reverse order of the allocation where first the event\nchannel is allocated and then the mappings are setup.\n\nOn a 5.10 kernel prior to commit 3fcdaf3d7634 (\"xen/events: modify internal\n[un]bind interfaces\"), we hit a BUG like the following during probing of NVMe\ndevices. The issue is that during nvme_setup_io_queues, pci_free_irq\nis called for every device which results in a call to shutdown_pirq.\nWith many nvme devices it's therefore likely to hit this race during\nboot because there will be multiple calls to shutdown_pirq and\nstartup_pirq are running potentially in parallel.\n\n ------------[ cut here ]------------\n blkfront: xvda: barrier or flush: disabled; persistent grants: enabled; indirect descriptors: enabled; bounce buffer: enabled\n kernel BUG at drivers/xen/events/events_base.c:499!\n invalid opcode: 0000 [#1] SMP PTI\n CPU: 44 PID: 375 Comm: kworker/u257:23 Not tainted 5.10.201-191.748.amzn2.x86_64 #1\n Hardware name: Xen HVM domU, BIOS 4.11.amazon 08/24/2006\n Workqueue: nvme-reset-wq nvme_reset_work\n RIP: 0010:bind_evtchn_to_cpu+0xdf/0xf0\n Code: 5d 41 5e c3 cc cc cc cc 44 89 f7 e8 2b 55 ad ff 49 89 c5 48 85 c0 0f 84 64 ff ff ff 4c 8b 68 30 41 83 fe ff 0f 85 60 ff ff ff <0f> 0b 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00\n RSP: 0000:ffffc9000d533b08 EFLAGS: 00010046\n RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000006\n RDX: 0000000000000028 RSI: 00000000ffffffff RDI: 00000000ffffffff\n RBP: ffff888107419680 R08: 0000000000000000 R09: ffffffff82d72b00\n R10: 0000000000000000 R11: 0000000000000000 R12: 00000000000001ed\n R13: 0000000000000000 R14: 00000000ffffffff R15: 0000000000000002\n FS: 0000000000000000(0000) GS:ffff88bc8b500000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000000 CR3: 0000000002610001 CR4: 00000000001706e0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n ? show_trace_log_lvl+0x1c1/0x2d9\n ? show_trace_log_lvl+0x1c1/0x2d9\n ? set_affinity_irq+0xdc/0x1c0\n ? __die_body.cold+0x8/0xd\n ? die+0x2b/0x50\n ? do_trap+0x90/0x110\n ? bind_evtchn_to_cpu+0xdf/0xf0\n ? do_error_trap+0x65/0x80\n ? bind_evtchn_to_cpu+0xdf/0xf0\n ? exc_invalid_op+0x4e/0x70\n ? bind_evtchn_to_cpu+0xdf/0xf0\n ? asm_exc_invalid_op+0x12/0x20\n ? bind_evtchn_to_cpu+0xdf/0x\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-825r-gh5g-48mg/GHSA-825r-gh5g-48mg.json b/advisories/unreviewed/2024/04/GHSA-825r-gh5g-48mg/GHSA-825r-gh5g-48mg.json index 847bb09a5af..3b32a7374b2 100644 --- a/advisories/unreviewed/2024/04/GHSA-825r-gh5g-48mg/GHSA-825r-gh5g-48mg.json +++ b/advisories/unreviewed/2024/04/GHSA-825r-gh5g-48mg/GHSA-825r-gh5g-48mg.json @@ -7,12 +7,8 @@ "CVE-2024-26748" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdns3: fix memory double free when handle zero packet\n\n829 if (request->complete) {\n830 spin_unlock(&priv_dev->lock);\n831 usb_gadget_giveback_request(&priv_ep->endpoint,\n832 request);\n833 spin_lock(&priv_dev->lock);\n834 }\n835\n836 if (request->buf == priv_dev->zlp_buf)\n837 cdns3_gadget_ep_free_request(&priv_ep->endpoint, request);\n\nDriver append an additional zero packet request when queue a packet, which\nlength mod max packet size is 0. When transfer complete, run to line 831,\nusb_gadget_giveback_request() will free this requestion. 836 condition is\ntrue, so cdns3_gadget_ep_free_request() free this request again.\n\nLog:\n\n[ 1920.140696][ T150] BUG: KFENCE: use-after-free read in cdns3_gadget_giveback+0x134/0x2c0 [cdns3]\n[ 1920.140696][ T150]\n[ 1920.151837][ T150] Use-after-free read at 0x000000003d1cd10b (in kfence-#36):\n[ 1920.159082][ T150] cdns3_gadget_giveback+0x134/0x2c0 [cdns3]\n[ 1920.164988][ T150] cdns3_transfer_completed+0x438/0x5f8 [cdns3]\n\nAdd check at line 829, skip call usb_gadget_giveback_request() if it is\nadditional zero length packet request. Needn't call\nusb_gadget_giveback_request() because it is allocated in this driver.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8cvr-95g2-c2x2/GHSA-8cvr-95g2-c2x2.json b/advisories/unreviewed/2024/04/GHSA-8cvr-95g2-c2x2/GHSA-8cvr-95g2-c2x2.json index cbf107497e4..cf28b706d83 100644 --- a/advisories/unreviewed/2024/04/GHSA-8cvr-95g2-c2x2/GHSA-8cvr-95g2-c2x2.json +++ b/advisories/unreviewed/2024/04/GHSA-8cvr-95g2-c2x2/GHSA-8cvr-95g2-c2x2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-8f6m-26fj-7fm5/GHSA-8f6m-26fj-7fm5.json b/advisories/unreviewed/2024/04/GHSA-8f6m-26fj-7fm5/GHSA-8f6m-26fj-7fm5.json index 4b0e0555a4c..d5bbf72b024 100644 --- a/advisories/unreviewed/2024/04/GHSA-8f6m-26fj-7fm5/GHSA-8f6m-26fj-7fm5.json +++ b/advisories/unreviewed/2024/04/GHSA-8f6m-26fj-7fm5/GHSA-8f6m-26fj-7fm5.json @@ -7,12 +7,8 @@ "CVE-2024-26923" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Fix garbage collector racing against connect()\n\nGarbage collector does not take into account the risk of embryo getting\nenqueued during the garbage collection. If such embryo has a peer that\ncarries SCM_RIGHTS, two consecutive passes of scan_children() may see a\ndifferent set of children. Leading to an incorrectly elevated inflight\ncount, and then a dangling pointer within the gc_inflight_list.\n\nsockets are AF_UNIX/SOCK_STREAM\nS is an unconnected socket\nL is a listening in-flight socket bound to addr, not in fdtable\nV's fd will be passed via sendmsg(), gets inflight count bumped\n\nconnect(S, addr)\tsendmsg(S, [V]); close(V)\t__unix_gc()\n----------------\t-------------------------\t-----------\n\nNS = unix_create1()\nskb1 = sock_wmalloc(NS)\nL = unix_find_other(addr)\nunix_state_lock(L)\nunix_peer(S) = NS\n\t\t\t// V count=1 inflight=0\n\n \t\t\tNS = unix_peer(S)\n \t\t\tskb2 = sock_alloc()\n\t\t\tskb_queue_tail(NS, skb2[V])\n\n\t\t\t// V became in-flight\n\t\t\t// V count=2 inflight=1\n\n\t\t\tclose(V)\n\n\t\t\t// V count=1 inflight=1\n\t\t\t// GC candidate condition met\n\n\t\t\t\t\t\tfor u in gc_inflight_list:\n\t\t\t\t\t\t if (total_refs == inflight_refs)\n\t\t\t\t\t\t add u to gc_candidates\n\n\t\t\t\t\t\t// gc_candidates={L, V}\n\n\t\t\t\t\t\tfor u in gc_candidates:\n\t\t\t\t\t\t scan_children(u, dec_inflight)\n\n\t\t\t\t\t\t// embryo (skb1) was not\n\t\t\t\t\t\t// reachable from L yet, so V's\n\t\t\t\t\t\t// inflight remains unchanged\n__skb_queue_tail(L, skb1)\nunix_state_unlock(L)\n\t\t\t\t\t\tfor u in gc_candidates:\n\t\t\t\t\t\t if (u.inflight)\n\t\t\t\t\t\t scan_children(u, inc_inflight_move_tail)\n\n\t\t\t\t\t\t// V count=1 inflight=2 (!)\n\nIf there is a GC-candidate listening socket, lock/unlock its state. This\nmakes GC wait until the end of any ongoing connect() to that socket. After\nflipping the lock, a possibly SCM-laden embryo is already enqueued. And if\nthere is another embryo coming, it can not possibly carry SCM_RIGHTS. At\nthis point, unix_inflight() can not happen because unix_gc_lock is already\ntaken. Inflight graph remains unaffected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8mj5-8fhj-855x/GHSA-8mj5-8fhj-855x.json b/advisories/unreviewed/2024/04/GHSA-8mj5-8fhj-855x/GHSA-8mj5-8fhj-855x.json index 9109ce484e0..e028da0b45d 100644 --- a/advisories/unreviewed/2024/04/GHSA-8mj5-8fhj-855x/GHSA-8mj5-8fhj-855x.json +++ b/advisories/unreviewed/2024/04/GHSA-8mj5-8fhj-855x/GHSA-8mj5-8fhj-855x.json @@ -7,12 +7,8 @@ "CVE-2024-26862" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npacket: annotate data-races around ignore_outgoing\n\nignore_outgoing is read locklessly from dev_queue_xmit_nit()\nand packet_getsockopt()\n\nAdd appropriate READ_ONCE()/WRITE_ONCE() annotations.\n\nsyzbot reported:\n\nBUG: KCSAN: data-race in dev_queue_xmit_nit / packet_setsockopt\n\nwrite to 0xffff888107804542 of 1 bytes by task 22618 on cpu 0:\n packet_setsockopt+0xd83/0xfd0 net/packet/af_packet.c:4003\n do_sock_setsockopt net/socket.c:2311 [inline]\n __sys_setsockopt+0x1d8/0x250 net/socket.c:2334\n __do_sys_setsockopt net/socket.c:2343 [inline]\n __se_sys_setsockopt net/socket.c:2340 [inline]\n __x64_sys_setsockopt+0x66/0x80 net/socket.c:2340\n do_syscall_64+0xd3/0x1d0\n entry_SYSCALL_64_after_hwframe+0x6d/0x75\n\nread to 0xffff888107804542 of 1 bytes by task 27 on cpu 1:\n dev_queue_xmit_nit+0x82/0x620 net/core/dev.c:2248\n xmit_one net/core/dev.c:3527 [inline]\n dev_hard_start_xmit+0xcc/0x3f0 net/core/dev.c:3547\n __dev_queue_xmit+0xf24/0x1dd0 net/core/dev.c:4335\n dev_queue_xmit include/linux/netdevice.h:3091 [inline]\n batadv_send_skb_packet+0x264/0x300 net/batman-adv/send.c:108\n batadv_send_broadcast_skb+0x24/0x30 net/batman-adv/send.c:127\n batadv_iv_ogm_send_to_if net/batman-adv/bat_iv_ogm.c:392 [inline]\n batadv_iv_ogm_emit net/batman-adv/bat_iv_ogm.c:420 [inline]\n batadv_iv_send_outstanding_bat_ogm_packet+0x3f0/0x4b0 net/batman-adv/bat_iv_ogm.c:1700\n process_one_work kernel/workqueue.c:3254 [inline]\n process_scheduled_works+0x465/0x990 kernel/workqueue.c:3335\n worker_thread+0x526/0x730 kernel/workqueue.c:3416\n kthread+0x1d1/0x210 kernel/kthread.c:388\n ret_from_fork+0x4b/0x60 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:243\n\nvalue changed: 0x00 -> 0x01\n\nReported by Kernel Concurrency Sanitizer on:\nCPU: 1 PID: 27 Comm: kworker/u8:1 Tainted: G W 6.8.0-syzkaller-08073-g480e035fc4c7 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/29/2024\nWorkqueue: bat_events batadv_iv_send_outstanding_bat_ogm_packet", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8p54-55f6-pg9j/GHSA-8p54-55f6-pg9j.json b/advisories/unreviewed/2024/04/GHSA-8p54-55f6-pg9j/GHSA-8p54-55f6-pg9j.json index d790ba75e60..1c7fb8e004e 100644 --- a/advisories/unreviewed/2024/04/GHSA-8p54-55f6-pg9j/GHSA-8p54-55f6-pg9j.json +++ b/advisories/unreviewed/2024/04/GHSA-8p54-55f6-pg9j/GHSA-8p54-55f6-pg9j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-8vch-c6pw-5chh/GHSA-8vch-c6pw-5chh.json b/advisories/unreviewed/2024/04/GHSA-8vch-c6pw-5chh/GHSA-8vch-c6pw-5chh.json index 9bf49adcb4e..9f4f9c1ae91 100644 --- a/advisories/unreviewed/2024/04/GHSA-8vch-c6pw-5chh/GHSA-8vch-c6pw-5chh.json +++ b/advisories/unreviewed/2024/04/GHSA-8vch-c6pw-5chh/GHSA-8vch-c6pw-5chh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8vf4-q8g2-79g5/GHSA-8vf4-q8g2-79g5.json b/advisories/unreviewed/2024/04/GHSA-8vf4-q8g2-79g5/GHSA-8vf4-q8g2-79g5.json index bf6362f3dad..df713b62b19 100644 --- a/advisories/unreviewed/2024/04/GHSA-8vf4-q8g2-79g5/GHSA-8vf4-q8g2-79g5.json +++ b/advisories/unreviewed/2024/04/GHSA-8vf4-q8g2-79g5/GHSA-8vf4-q8g2-79g5.json @@ -7,12 +7,8 @@ "CVE-2024-26787" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: mmci: stm32: fix DMA API overlapping mappings warning\n\nTurning on CONFIG_DMA_API_DEBUG_SG results in the following warning:\n\nDMA-API: mmci-pl18x 48220000.mmc: cacheline tracking EEXIST,\noverlapping mappings aren't supported\nWARNING: CPU: 1 PID: 51 at kernel/dma/debug.c:568\nadd_dma_entry+0x234/0x2f4\nModules linked in:\nCPU: 1 PID: 51 Comm: kworker/1:2 Not tainted 6.1.28 #1\nHardware name: STMicroelectronics STM32MP257F-EV1 Evaluation Board (DT)\nWorkqueue: events_freezable mmc_rescan\nCall trace:\nadd_dma_entry+0x234/0x2f4\ndebug_dma_map_sg+0x198/0x350\n__dma_map_sg_attrs+0xa0/0x110\ndma_map_sg_attrs+0x10/0x2c\nsdmmc_idma_prep_data+0x80/0xc0\nmmci_prep_data+0x38/0x84\nmmci_start_data+0x108/0x2dc\nmmci_request+0xe4/0x190\n__mmc_start_request+0x68/0x140\nmmc_start_request+0x94/0xc0\nmmc_wait_for_req+0x70/0x100\nmmc_send_tuning+0x108/0x1ac\nsdmmc_execute_tuning+0x14c/0x210\nmmc_execute_tuning+0x48/0xec\nmmc_sd_init_uhs_card.part.0+0x208/0x464\nmmc_sd_init_card+0x318/0x89c\nmmc_attach_sd+0xe4/0x180\nmmc_rescan+0x244/0x320\n\nDMA API debug brings to light leaking dma-mappings as dma_map_sg and\ndma_unmap_sg are not correctly balanced.\n\nIf an error occurs in mmci_cmd_irq function, only mmci_dma_error\nfunction is called and as this API is not managed on stm32 variant,\ndma_unmap_sg is never called in this error path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-9493-4f82-9rx5/GHSA-9493-4f82-9rx5.json b/advisories/unreviewed/2024/04/GHSA-9493-4f82-9rx5/GHSA-9493-4f82-9rx5.json index 451111ef2cb..9e6c910c3ef 100644 --- a/advisories/unreviewed/2024/04/GHSA-9493-4f82-9rx5/GHSA-9493-4f82-9rx5.json +++ b/advisories/unreviewed/2024/04/GHSA-9493-4f82-9rx5/GHSA-9493-4f82-9rx5.json @@ -7,12 +7,8 @@ "CVE-2024-27537" ], "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-96gr-7mgw-2637/GHSA-96gr-7mgw-2637.json b/advisories/unreviewed/2024/04/GHSA-96gr-7mgw-2637/GHSA-96gr-7mgw-2637.json index 0fe73381b42..b0954df009b 100644 --- a/advisories/unreviewed/2024/04/GHSA-96gr-7mgw-2637/GHSA-96gr-7mgw-2637.json +++ b/advisories/unreviewed/2024/04/GHSA-96gr-7mgw-2637/GHSA-96gr-7mgw-2637.json @@ -7,12 +7,8 @@ "CVE-2024-26897" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath9k: delay all of ath9k_wmi_event_tasklet() until init is complete\n\nThe ath9k_wmi_event_tasklet() used in ath9k_htc assumes that all the data\nstructures have been fully initialised by the time it runs. However, because of\nthe order in which things are initialised, this is not guaranteed to be the\ncase, because the device is exposed to the USB subsystem before the ath9k driver\ninitialisation is completed.\n\nWe already committed a partial fix for this in commit:\n8b3046abc99e (\"ath9k_htc: fix NULL pointer dereference at ath9k_htc_tx_get_packet()\")\n\nHowever, that commit only aborted the WMI_TXSTATUS_EVENTID command in the event\ntasklet, pairing it with an \"initialisation complete\" bit in the TX struct. It\nseems syzbot managed to trigger the race for one of the other commands as well,\nso let's just move the existing synchronisation bit to cover the whole\ntasklet (setting it at the end of ath9k_htc_probe_device() instead of inside\nath9k_tx_init()).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-98m4-jppc-qq3m/GHSA-98m4-jppc-qq3m.json b/advisories/unreviewed/2024/04/GHSA-98m4-jppc-qq3m/GHSA-98m4-jppc-qq3m.json index 0c4641691b6..5c56aa18b80 100644 --- a/advisories/unreviewed/2024/04/GHSA-98m4-jppc-qq3m/GHSA-98m4-jppc-qq3m.json +++ b/advisories/unreviewed/2024/04/GHSA-98m4-jppc-qq3m/GHSA-98m4-jppc-qq3m.json @@ -7,12 +7,8 @@ "CVE-2024-26754" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: fix use-after-free and null-ptr-deref in gtp_genl_dump_pdp()\n\nThe gtp_net_ops pernet operations structure for the subsystem must be\nregistered before registering the generic netlink family.\n\nSyzkaller hit 'general protection fault in gtp_genl_dump_pdp' bug:\n\ngeneral protection fault, probably for non-canonical address\n0xdffffc0000000002: 0000 [#1] PREEMPT SMP KASAN NOPTI\nKASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]\nCPU: 1 PID: 5826 Comm: gtp Not tainted 6.8.0-rc3-std-def-alt1 #1\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.0-alt1 04/01/2014\nRIP: 0010:gtp_genl_dump_pdp+0x1be/0x800 [gtp]\nCode: c6 89 c6 e8 64 e9 86 df 58 45 85 f6 0f 85 4e 04 00 00 e8 c5 ee 86\n df 48 8b 54 24 18 48 b8 00 00 00 00 00 fc ff df 48 c1 ea 03 <80>\n 3c 02 00 0f 85 de 05 00 00 48 8b 44 24 18 4c 8b 30 4c 39 f0 74\nRSP: 0018:ffff888014107220 EFLAGS: 00010202\nRAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000\nRDX: 0000000000000002 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000\nR13: ffff88800fcda588 R14: 0000000000000001 R15: 0000000000000000\nFS: 00007f1be4eb05c0(0000) GS:ffff88806ce80000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f1be4e766cf CR3: 000000000c33e000 CR4: 0000000000750ef0\nPKRU: 55555554\nCall Trace:\n \n ? show_regs+0x90/0xa0\n ? die_addr+0x50/0xd0\n ? exc_general_protection+0x148/0x220\n ? asm_exc_general_protection+0x22/0x30\n ? gtp_genl_dump_pdp+0x1be/0x800 [gtp]\n ? __alloc_skb+0x1dd/0x350\n ? __pfx___alloc_skb+0x10/0x10\n genl_dumpit+0x11d/0x230\n netlink_dump+0x5b9/0xce0\n ? lockdep_hardirqs_on_prepare+0x253/0x430\n ? __pfx_netlink_dump+0x10/0x10\n ? kasan_save_track+0x10/0x40\n ? __kasan_kmalloc+0x9b/0xa0\n ? genl_start+0x675/0x970\n __netlink_dump_start+0x6fc/0x9f0\n genl_family_rcv_msg_dumpit+0x1bb/0x2d0\n ? __pfx_genl_family_rcv_msg_dumpit+0x10/0x10\n ? genl_op_from_small+0x2a/0x440\n ? cap_capable+0x1d0/0x240\n ? __pfx_genl_start+0x10/0x10\n ? __pfx_genl_dumpit+0x10/0x10\n ? __pfx_genl_done+0x10/0x10\n ? security_capable+0x9d/0xe0", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-9fvf-9v35-97qv/GHSA-9fvf-9v35-97qv.json b/advisories/unreviewed/2024/04/GHSA-9fvf-9v35-97qv/GHSA-9fvf-9v35-97qv.json index 41b9a05ee90..43a4f5bc2ba 100644 --- a/advisories/unreviewed/2024/04/GHSA-9fvf-9v35-97qv/GHSA-9fvf-9v35-97qv.json +++ b/advisories/unreviewed/2024/04/GHSA-9fvf-9v35-97qv/GHSA-9fvf-9v35-97qv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-9pfj-cx2g-pfp8/GHSA-9pfj-cx2g-pfp8.json b/advisories/unreviewed/2024/04/GHSA-9pfj-cx2g-pfp8/GHSA-9pfj-cx2g-pfp8.json index d637c3c8b85..6d426f2e475 100644 --- a/advisories/unreviewed/2024/04/GHSA-9pfj-cx2g-pfp8/GHSA-9pfj-cx2g-pfp8.json +++ b/advisories/unreviewed/2024/04/GHSA-9pfj-cx2g-pfp8/GHSA-9pfj-cx2g-pfp8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-9q92-r559-g8xx/GHSA-9q92-r559-g8xx.json b/advisories/unreviewed/2024/04/GHSA-9q92-r559-g8xx/GHSA-9q92-r559-g8xx.json index c8a6424fad7..ae0efa5d8f1 100644 --- a/advisories/unreviewed/2024/04/GHSA-9q92-r559-g8xx/GHSA-9q92-r559-g8xx.json +++ b/advisories/unreviewed/2024/04/GHSA-9q92-r559-g8xx/GHSA-9q92-r559-g8xx.json @@ -7,12 +7,8 @@ "CVE-2024-26855" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ice: Fix potential NULL pointer dereference in ice_bridge_setlink()\n\nThe function ice_bridge_setlink() may encounter a NULL pointer dereference\nif nlmsg_find_attr() returns NULL and br_spec is dereferenced subsequently\nin nla_for_each_nested(). To address this issue, add a check to ensure that\nbr_spec is not NULL before proceeding with the nested attribute iteration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-9r85-wp9w-jjwp/GHSA-9r85-wp9w-jjwp.json b/advisories/unreviewed/2024/04/GHSA-9r85-wp9w-jjwp/GHSA-9r85-wp9w-jjwp.json index 0bdd6cd09fa..ad41c6766b1 100644 --- a/advisories/unreviewed/2024/04/GHSA-9r85-wp9w-jjwp/GHSA-9r85-wp9w-jjwp.json +++ b/advisories/unreviewed/2024/04/GHSA-9r85-wp9w-jjwp/GHSA-9r85-wp9w-jjwp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-9rp8-67w7-gf47/GHSA-9rp8-67w7-gf47.json b/advisories/unreviewed/2024/04/GHSA-9rp8-67w7-gf47/GHSA-9rp8-67w7-gf47.json index 4856f11b9f9..9ffe5e7a33b 100644 --- a/advisories/unreviewed/2024/04/GHSA-9rp8-67w7-gf47/GHSA-9rp8-67w7-gf47.json +++ b/advisories/unreviewed/2024/04/GHSA-9rp8-67w7-gf47/GHSA-9rp8-67w7-gf47.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-9xp8-8c5r-6wfh/GHSA-9xp8-8c5r-6wfh.json b/advisories/unreviewed/2024/04/GHSA-9xp8-8c5r-6wfh/GHSA-9xp8-8c5r-6wfh.json index 2a99dee2306..356e7afd60b 100644 --- a/advisories/unreviewed/2024/04/GHSA-9xp8-8c5r-6wfh/GHSA-9xp8-8c5r-6wfh.json +++ b/advisories/unreviewed/2024/04/GHSA-9xp8-8c5r-6wfh/GHSA-9xp8-8c5r-6wfh.json @@ -7,12 +7,8 @@ "CVE-2024-26689" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: prevent use-after-free in encode_cap_msg()\n\nIn fs/ceph/caps.c, in encode_cap_msg(), \"use after free\" error was\ncaught by KASAN at this line - 'ceph_buffer_get(arg->xattr_buf);'. This\nimplies before the refcount could be increment here, it was freed.\n\nIn same file, in \"handle_cap_grant()\" refcount is decremented by this\nline - 'ceph_buffer_put(ci->i_xattrs.blob);'. It appears that a race\noccurred and resource was freed by the latter line before the former\nline could increment it.\n\nencode_cap_msg() is called by __send_cap() and __send_cap() is called by\nceph_check_caps() after calling __prep_cap(). __prep_cap() is where\narg->xattr_buf is assigned to ci->i_xattrs.blob. This is the spot where\nthe refcount must be increased to prevent \"use after free\" error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-c8f2-2f6p-gpgc/GHSA-c8f2-2f6p-gpgc.json b/advisories/unreviewed/2024/04/GHSA-c8f2-2f6p-gpgc/GHSA-c8f2-2f6p-gpgc.json index a16dd9b3c91..7aeb2197c8b 100644 --- a/advisories/unreviewed/2024/04/GHSA-c8f2-2f6p-gpgc/GHSA-c8f2-2f6p-gpgc.json +++ b/advisories/unreviewed/2024/04/GHSA-c8f2-2f6p-gpgc/GHSA-c8f2-2f6p-gpgc.json @@ -7,12 +7,8 @@ "CVE-2024-26707" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hsr: remove WARN_ONCE() in send_hsr_supervision_frame()\n\nSyzkaller reported [1] hitting a warning after failing to allocate\nresources for skb in hsr_init_skb(). Since a WARN_ONCE() call will\nnot help much in this case, it might be prudent to switch to\nnetdev_warn_once(). At the very least it will suppress syzkaller\nreports such as [1].\n\nJust in case, use netdev_warn_once() in send_prp_supervision_frame()\nfor similar reasons.\n\n[1]\nHSR: Could not send supervision frame\nWARNING: CPU: 1 PID: 85 at net/hsr/hsr_device.c:294 send_hsr_supervision_frame+0x60a/0x810 net/hsr/hsr_device.c:294\nRIP: 0010:send_hsr_supervision_frame+0x60a/0x810 net/hsr/hsr_device.c:294\n...\nCall Trace:\n \n hsr_announce+0x114/0x370 net/hsr/hsr_device.c:382\n call_timer_fn+0x193/0x590 kernel/time/timer.c:1700\n expire_timers kernel/time/timer.c:1751 [inline]\n __run_timers+0x764/0xb20 kernel/time/timer.c:2022\n run_timer_softirq+0x58/0xd0 kernel/time/timer.c:2035\n __do_softirq+0x21a/0x8de kernel/softirq.c:553\n invoke_softirq kernel/softirq.c:427 [inline]\n __irq_exit_rcu kernel/softirq.c:632 [inline]\n irq_exit_rcu+0xb7/0x120 kernel/softirq.c:644\n sysvec_apic_timer_interrupt+0x95/0xb0 arch/x86/kernel/apic/apic.c:1076\n \n \n asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:649\n...\n\nThis issue is also found in older kernels (at least up to 5.10).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-c8hq-5hxw-3w26/GHSA-c8hq-5hxw-3w26.json b/advisories/unreviewed/2024/04/GHSA-c8hq-5hxw-3w26/GHSA-c8hq-5hxw-3w26.json index 765b303a277..68e4849ef03 100644 --- a/advisories/unreviewed/2024/04/GHSA-c8hq-5hxw-3w26/GHSA-c8hq-5hxw-3w26.json +++ b/advisories/unreviewed/2024/04/GHSA-c8hq-5hxw-3w26/GHSA-c8hq-5hxw-3w26.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-c8v3-wvcw-2g23/GHSA-c8v3-wvcw-2g23.json b/advisories/unreviewed/2024/04/GHSA-c8v3-wvcw-2g23/GHSA-c8v3-wvcw-2g23.json index 14538b0a1dd..eea591ae3ff 100644 --- a/advisories/unreviewed/2024/04/GHSA-c8v3-wvcw-2g23/GHSA-c8v3-wvcw-2g23.json +++ b/advisories/unreviewed/2024/04/GHSA-c8v3-wvcw-2g23/GHSA-c8v3-wvcw-2g23.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-cw6h-gvcj-ww9c/GHSA-cw6h-gvcj-ww9c.json b/advisories/unreviewed/2024/04/GHSA-cw6h-gvcj-ww9c/GHSA-cw6h-gvcj-ww9c.json index fe5e989dbbb..7d59f49c195 100644 --- a/advisories/unreviewed/2024/04/GHSA-cw6h-gvcj-ww9c/GHSA-cw6h-gvcj-ww9c.json +++ b/advisories/unreviewed/2024/04/GHSA-cw6h-gvcj-ww9c/GHSA-cw6h-gvcj-ww9c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-cwr2-26gq-v2xr/GHSA-cwr2-26gq-v2xr.json b/advisories/unreviewed/2024/04/GHSA-cwr2-26gq-v2xr/GHSA-cwr2-26gq-v2xr.json index 7a2eb530e04..b1af9fba818 100644 --- a/advisories/unreviewed/2024/04/GHSA-cwr2-26gq-v2xr/GHSA-cwr2-26gq-v2xr.json +++ b/advisories/unreviewed/2024/04/GHSA-cwr2-26gq-v2xr/GHSA-cwr2-26gq-v2xr.json @@ -7,12 +7,8 @@ "CVE-2024-26696" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix hang in nilfs_lookup_dirty_data_buffers()\n\nSyzbot reported a hang issue in migrate_pages_batch() called by mbind()\nand nilfs_lookup_dirty_data_buffers() called in the log writer of nilfs2.\n\nWhile migrate_pages_batch() locks a folio and waits for the writeback to\ncomplete, the log writer thread that should bring the writeback to\ncompletion picks up the folio being written back in\nnilfs_lookup_dirty_data_buffers() that it calls for subsequent log\ncreation and was trying to lock the folio. Thus causing a deadlock.\n\nIn the first place, it is unexpected that folios/pages in the middle of\nwriteback will be updated and become dirty. Nilfs2 adds a checksum to\nverify the validity of the log being written and uses it for recovery at\nmount, so data changes during writeback are suppressed. Since this is\nbroken, an unclean shutdown could potentially cause recovery to fail.\n\nInvestigation revealed that the root cause is that the wait for writeback\ncompletion in nilfs_page_mkwrite() is conditional, and if the backing\ndevice does not require stable writes, data may be modified without\nwaiting.\n\nFix these issues by making nilfs_page_mkwrite() wait for writeback to\nfinish regardless of the stable write requirement of the backing device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-f34w-8j75-rh85/GHSA-f34w-8j75-rh85.json b/advisories/unreviewed/2024/04/GHSA-f34w-8j75-rh85/GHSA-f34w-8j75-rh85.json index a65d31a7e9d..9809e49fed0 100644 --- a/advisories/unreviewed/2024/04/GHSA-f34w-8j75-rh85/GHSA-f34w-8j75-rh85.json +++ b/advisories/unreviewed/2024/04/GHSA-f34w-8j75-rh85/GHSA-f34w-8j75-rh85.json @@ -7,12 +7,8 @@ "CVE-2024-26795" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: Sparse-Memory/vmemmap out-of-bounds fix\n\nOffset vmemmap so that the first page of vmemmap will be mapped\nto the first page of physical memory in order to ensure that\nvmemmap’s bounds will be respected during\npfn_to_page()/page_to_pfn() operations.\nThe conversion macros will produce correct SV39/48/57 addresses\nfor every possible/valid DRAM_BASE inside the physical memory limits.\n\nv2:Address Alex's comments", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-fp6w-hx4c-x44g/GHSA-fp6w-hx4c-x44g.json b/advisories/unreviewed/2024/04/GHSA-fp6w-hx4c-x44g/GHSA-fp6w-hx4c-x44g.json index ecae09d3622..dd31ff5fcfe 100644 --- a/advisories/unreviewed/2024/04/GHSA-fp6w-hx4c-x44g/GHSA-fp6w-hx4c-x44g.json +++ b/advisories/unreviewed/2024/04/GHSA-fp6w-hx4c-x44g/GHSA-fp6w-hx4c-x44g.json @@ -7,12 +7,8 @@ "CVE-2024-26782" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix double-free on socket dismantle\n\nwhen MPTCP server accepts an incoming connection, it clones its listener\nsocket. However, the pointer to 'inet_opt' for the new socket has the same\nvalue as the original one: as a consequence, on program exit it's possible\nto observe the following splat:\n\n BUG: KASAN: double-free in inet_sock_destruct+0x54f/0x8b0\n Free of addr ffff888485950880 by task swapper/25/0\n\n CPU: 25 PID: 0 Comm: swapper/25 Kdump: loaded Not tainted 6.8.0-rc1+ #609\n Hardware name: Supermicro SYS-6027R-72RF/X9DRH-7TF/7F/iTF/iF, BIOS 3.0 07/26/2013\n Call Trace:\n \n dump_stack_lvl+0x32/0x50\n print_report+0xca/0x620\n kasan_report_invalid_free+0x64/0x90\n __kasan_slab_free+0x1aa/0x1f0\n kfree+0xed/0x2e0\n inet_sock_destruct+0x54f/0x8b0\n __sk_destruct+0x48/0x5b0\n rcu_do_batch+0x34e/0xd90\n rcu_core+0x559/0xac0\n __do_softirq+0x183/0x5a4\n irq_exit_rcu+0x12d/0x170\n sysvec_apic_timer_interrupt+0x6b/0x80\n \n \n asm_sysvec_apic_timer_interrupt+0x16/0x20\n RIP: 0010:cpuidle_enter_state+0x175/0x300\n Code: 30 00 0f 84 1f 01 00 00 83 e8 01 83 f8 ff 75 e5 48 83 c4 18 44 89 e8 5b 5d 41 5c 41 5d 41 5e 41 5f c3 cc cc cc cc fb 45 85 ed <0f> 89 60 ff ff ff 48 c1 e5 06 48 c7 43 18 00 00 00 00 48 83 44 2b\n RSP: 0018:ffff888481cf7d90 EFLAGS: 00000202\n RAX: 0000000000000000 RBX: ffff88887facddc8 RCX: 0000000000000000\n RDX: 1ffff1110ff588b1 RSI: 0000000000000019 RDI: ffff88887fac4588\n RBP: 0000000000000004 R08: 0000000000000002 R09: 0000000000043080\n R10: 0009b02ea273363f R11: ffff88887fabf42b R12: ffffffff932592e0\n R13: 0000000000000004 R14: 0000000000000000 R15: 00000022c880ec80\n cpuidle_enter+0x4a/0xa0\n do_idle+0x310/0x410\n cpu_startup_entry+0x51/0x60\n start_secondary+0x211/0x270\n secondary_startup_64_no_verify+0x184/0x18b\n \n\n Allocated by task 6853:\n kasan_save_stack+0x1c/0x40\n kasan_save_track+0x10/0x30\n __kasan_kmalloc+0xa6/0xb0\n __kmalloc+0x1eb/0x450\n cipso_v4_sock_setattr+0x96/0x360\n netlbl_sock_setattr+0x132/0x1f0\n selinux_netlbl_socket_post_create+0x6c/0x110\n selinux_socket_post_create+0x37b/0x7f0\n security_socket_post_create+0x63/0xb0\n __sock_create+0x305/0x450\n __sys_socket_create.part.23+0xbd/0x130\n __sys_socket+0x37/0xb0\n __x64_sys_socket+0x6f/0xb0\n do_syscall_64+0x83/0x160\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\n Freed by task 6858:\n kasan_save_stack+0x1c/0x40\n kasan_save_track+0x10/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x12c/0x1f0\n kfree+0xed/0x2e0\n inet_sock_destruct+0x54f/0x8b0\n __sk_destruct+0x48/0x5b0\n subflow_ulp_release+0x1f0/0x250\n tcp_cleanup_ulp+0x6e/0x110\n tcp_v4_destroy_sock+0x5a/0x3a0\n inet_csk_destroy_sock+0x135/0x390\n tcp_fin+0x416/0x5c0\n tcp_data_queue+0x1bc8/0x4310\n tcp_rcv_state_process+0x15a3/0x47b0\n tcp_v4_do_rcv+0x2c1/0x990\n tcp_v4_rcv+0x41fb/0x5ed0\n ip_protocol_deliver_rcu+0x6d/0x9f0\n ip_local_deliver_finish+0x278/0x360\n ip_local_deliver+0x182/0x2c0\n ip_rcv+0xb5/0x1c0\n __netif_receive_skb_one_core+0x16e/0x1b0\n process_backlog+0x1e3/0x650\n __napi_poll+0xa6/0x500\n net_rx_action+0x740/0xbb0\n __do_softirq+0x183/0x5a4\n\n The buggy address belongs to the object at ffff888485950880\n which belongs to the cache kmalloc-64 of size 64\n The buggy address is located 0 bytes inside of\n 64-byte region [ffff888485950880, ffff8884859508c0)\n\n The buggy address belongs to the physical page:\n page:0000000056d1e95e refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff888485950700 pfn:0x485950\n flags: 0x57ffffc0000800(slab|node=1|zone=2|lastcpupid=0x1fffff)\n page_type: 0xffffffff()\n raw: 0057ffffc0000800 ffff88810004c640 ffffea00121b8ac0 dead000000000006\n raw: ffff888485950700 0000000000200019 00000001ffffffff 0000000000000000\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffff888485950780: fa fb fb\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-fvq5-hfcg-2qjg/GHSA-fvq5-hfcg-2qjg.json b/advisories/unreviewed/2024/04/GHSA-fvq5-hfcg-2qjg/GHSA-fvq5-hfcg-2qjg.json index a6a755db2df..f4807e1f42c 100644 --- a/advisories/unreviewed/2024/04/GHSA-fvq5-hfcg-2qjg/GHSA-fvq5-hfcg-2qjg.json +++ b/advisories/unreviewed/2024/04/GHSA-fvq5-hfcg-2qjg/GHSA-fvq5-hfcg-2qjg.json @@ -7,12 +7,8 @@ "CVE-2023-48938" ], "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-g2rp-ppxj-jr95/GHSA-g2rp-ppxj-jr95.json b/advisories/unreviewed/2024/04/GHSA-g2rp-ppxj-jr95/GHSA-g2rp-ppxj-jr95.json index eef8377a311..148e9ee92fe 100644 --- a/advisories/unreviewed/2024/04/GHSA-g2rp-ppxj-jr95/GHSA-g2rp-ppxj-jr95.json +++ b/advisories/unreviewed/2024/04/GHSA-g2rp-ppxj-jr95/GHSA-g2rp-ppxj-jr95.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-g638-g65r-64rm/GHSA-g638-g65r-64rm.json b/advisories/unreviewed/2024/04/GHSA-g638-g65r-64rm/GHSA-g638-g65r-64rm.json index cfe0fd5dcee..f70a8450884 100644 --- a/advisories/unreviewed/2024/04/GHSA-g638-g65r-64rm/GHSA-g638-g65r-64rm.json +++ b/advisories/unreviewed/2024/04/GHSA-g638-g65r-64rm/GHSA-g638-g65r-64rm.json @@ -7,12 +7,8 @@ "CVE-2024-26840" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: fix memory leak in cachefiles_add_cache()\n\nThe following memory leak was reported after unbinding /dev/cachefiles:\n\n==================================================================\nunreferenced object 0xffff9b674176e3c0 (size 192):\n comm \"cachefilesd2\", pid 680, jiffies 4294881224\n hex dump (first 32 bytes):\n 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace (crc ea38a44b):\n [] kmem_cache_alloc+0x2d5/0x370\n [] prepare_creds+0x26/0x2e0\n [] cachefiles_determine_cache_security+0x1f/0x120\n [] cachefiles_add_cache+0x13c/0x3a0\n [] cachefiles_daemon_write+0x146/0x1c0\n [] vfs_write+0xcb/0x520\n [] ksys_write+0x69/0xf0\n [] do_syscall_64+0x72/0x140\n [] entry_SYSCALL_64_after_hwframe+0x6e/0x76\n==================================================================\n\nPut the reference count of cache_cred in cachefiles_daemon_unbind() to\nfix the problem. And also put cache_cred in cachefiles_add_cache() error\nbranch to avoid memory leaks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-g65w-rrjg-vx49/GHSA-g65w-rrjg-vx49.json b/advisories/unreviewed/2024/04/GHSA-g65w-rrjg-vx49/GHSA-g65w-rrjg-vx49.json index f7c921d18e3..33e60400254 100644 --- a/advisories/unreviewed/2024/04/GHSA-g65w-rrjg-vx49/GHSA-g65w-rrjg-vx49.json +++ b/advisories/unreviewed/2024/04/GHSA-g65w-rrjg-vx49/GHSA-g65w-rrjg-vx49.json @@ -7,12 +7,8 @@ "CVE-2024-26664" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (coretemp) Fix out-of-bounds memory access\n\nFix a bug that pdata->cpu_map[] is set before out-of-bounds check.\nThe problem might be triggered on systems with more than 128 cores per\npackage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-g993-hcw2-pmmf/GHSA-g993-hcw2-pmmf.json b/advisories/unreviewed/2024/04/GHSA-g993-hcw2-pmmf/GHSA-g993-hcw2-pmmf.json index 0bd1d325452..a4f14b015d3 100644 --- a/advisories/unreviewed/2024/04/GHSA-g993-hcw2-pmmf/GHSA-g993-hcw2-pmmf.json +++ b/advisories/unreviewed/2024/04/GHSA-g993-hcw2-pmmf/GHSA-g993-hcw2-pmmf.json @@ -7,12 +7,8 @@ "CVE-2024-26926" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: check offset alignment in binder_get_object()\n\nCommit 6d98eb95b450 (\"binder: avoid potential data leakage when copying\ntxn\") introduced changes to how binder objects are copied. In doing so,\nit unintentionally removed an offset alignment check done through calls\nto binder_alloc_copy_from_buffer() -> check_buffer().\n\nThese calls were replaced in binder_get_object() with copy_from_user(),\nso now an explicit offset alignment check is needed here. This avoids\nlater complications when unwinding the objects gets harder.\n\nIt is worth noting this check existed prior to commit 7a67a39320df\n(\"binder: add function to copy binder object from buffer\"), likely\nremoved due to redundancy at the time.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-gr67-xmxc-qw6m/GHSA-gr67-xmxc-qw6m.json b/advisories/unreviewed/2024/04/GHSA-gr67-xmxc-qw6m/GHSA-gr67-xmxc-qw6m.json index e3851bd961e..27d6da27487 100644 --- a/advisories/unreviewed/2024/04/GHSA-gr67-xmxc-qw6m/GHSA-gr67-xmxc-qw6m.json +++ b/advisories/unreviewed/2024/04/GHSA-gr67-xmxc-qw6m/GHSA-gr67-xmxc-qw6m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-gvgx-pcvr-3pc4/GHSA-gvgx-pcvr-3pc4.json b/advisories/unreviewed/2024/04/GHSA-gvgx-pcvr-3pc4/GHSA-gvgx-pcvr-3pc4.json index 902ba8eece2..e883b6098eb 100644 --- a/advisories/unreviewed/2024/04/GHSA-gvgx-pcvr-3pc4/GHSA-gvgx-pcvr-3pc4.json +++ b/advisories/unreviewed/2024/04/GHSA-gvgx-pcvr-3pc4/GHSA-gvgx-pcvr-3pc4.json @@ -7,12 +7,8 @@ "CVE-2024-26753" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: virtio/akcipher - Fix stack overflow on memcpy\n\nsizeof(struct virtio_crypto_akcipher_session_para) is less than\nsizeof(struct virtio_crypto_op_ctrl_req::u), copying more bytes from\nstack variable leads stack overflow. Clang reports this issue by\ncommands:\nmake -j CC=clang-14 mrproper >/dev/null 2>&1\nmake -j O=/tmp/crypto-build CC=clang-14 allmodconfig >/dev/null 2>&1\nmake -j O=/tmp/crypto-build W=1 CC=clang-14 drivers/crypto/virtio/\n virtio_crypto_akcipher_algs.o", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-h38m-55w3-wc8q/GHSA-h38m-55w3-wc8q.json b/advisories/unreviewed/2024/04/GHSA-h38m-55w3-wc8q/GHSA-h38m-55w3-wc8q.json index 0bc1135e33e..05e5f8a75ef 100644 --- a/advisories/unreviewed/2024/04/GHSA-h38m-55w3-wc8q/GHSA-h38m-55w3-wc8q.json +++ b/advisories/unreviewed/2024/04/GHSA-h38m-55w3-wc8q/GHSA-h38m-55w3-wc8q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-h4jh-5vqp-vw3p/GHSA-h4jh-5vqp-vw3p.json b/advisories/unreviewed/2024/04/GHSA-h4jh-5vqp-vw3p/GHSA-h4jh-5vqp-vw3p.json index d2b59583ac9..03a85900409 100644 --- a/advisories/unreviewed/2024/04/GHSA-h4jh-5vqp-vw3p/GHSA-h4jh-5vqp-vw3p.json +++ b/advisories/unreviewed/2024/04/GHSA-h4jh-5vqp-vw3p/GHSA-h4jh-5vqp-vw3p.json @@ -7,12 +7,8 @@ "CVE-2024-26906" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mm: Disallow vsyscall page read for copy_from_kernel_nofault()\n\nWhen trying to use copy_from_kernel_nofault() to read vsyscall page\nthrough a bpf program, the following oops was reported:\n\n BUG: unable to handle page fault for address: ffffffffff600000\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 3231067 P4D 3231067 PUD 3233067 PMD 3235067 PTE 0\n Oops: 0000 [#1] PREEMPT SMP PTI\n CPU: 1 PID: 20390 Comm: test_progs ...... 6.7.0+ #58\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) ......\n RIP: 0010:copy_from_kernel_nofault+0x6f/0x110\n ......\n Call Trace:\n \n ? copy_from_kernel_nofault+0x6f/0x110\n bpf_probe_read_kernel+0x1d/0x50\n bpf_prog_2061065e56845f08_do_probe_read+0x51/0x8d\n trace_call_bpf+0xc5/0x1c0\n perf_call_bpf_enter.isra.0+0x69/0xb0\n perf_syscall_enter+0x13e/0x200\n syscall_trace_enter+0x188/0x1c0\n do_syscall_64+0xb5/0xe0\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n \n ......\n ---[ end trace 0000000000000000 ]---\n\nThe oops is triggered when:\n\n1) A bpf program uses bpf_probe_read_kernel() to read from the vsyscall\npage and invokes copy_from_kernel_nofault() which in turn calls\n__get_user_asm().\n\n2) Because the vsyscall page address is not readable from kernel space,\na page fault exception is triggered accordingly.\n\n3) handle_page_fault() considers the vsyscall page address as a user\nspace address instead of a kernel space address. This results in the\nfix-up setup by bpf not being applied and a page_fault_oops() is invoked\ndue to SMAP.\n\nConsidering handle_page_fault() has already considered the vsyscall page\naddress as a userspace address, fix the problem by disallowing vsyscall\npage read for copy_from_kernel_nofault().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-h63r-7v46-7432/GHSA-h63r-7v46-7432.json b/advisories/unreviewed/2024/04/GHSA-h63r-7v46-7432/GHSA-h63r-7v46-7432.json index b1089d2fec3..f1f54e34182 100644 --- a/advisories/unreviewed/2024/04/GHSA-h63r-7v46-7432/GHSA-h63r-7v46-7432.json +++ b/advisories/unreviewed/2024/04/GHSA-h63r-7v46-7432/GHSA-h63r-7v46-7432.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-hpjm-r5wj-2jq3/GHSA-hpjm-r5wj-2jq3.json b/advisories/unreviewed/2024/04/GHSA-hpjm-r5wj-2jq3/GHSA-hpjm-r5wj-2jq3.json index 6a379ad6ea1..1d27be6177b 100644 --- a/advisories/unreviewed/2024/04/GHSA-hpjm-r5wj-2jq3/GHSA-hpjm-r5wj-2jq3.json +++ b/advisories/unreviewed/2024/04/GHSA-hpjm-r5wj-2jq3/GHSA-hpjm-r5wj-2jq3.json @@ -7,12 +7,8 @@ "CVE-2024-26922" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: validate the parameters of bo mapping operations more clearly\n\nVerify the parameters of\namdgpu_vm_bo_(map/replace_map/clearing_mappings) in one common place.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-hq4g-8jp3-v42r/GHSA-hq4g-8jp3-v42r.json b/advisories/unreviewed/2024/04/GHSA-hq4g-8jp3-v42r/GHSA-hq4g-8jp3-v42r.json index 969399ff03e..c2764584633 100644 --- a/advisories/unreviewed/2024/04/GHSA-hq4g-8jp3-v42r/GHSA-hq4g-8jp3-v42r.json +++ b/advisories/unreviewed/2024/04/GHSA-hq4g-8jp3-v42r/GHSA-hq4g-8jp3-v42r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-j648-rgv6-ccc8/GHSA-j648-rgv6-ccc8.json b/advisories/unreviewed/2024/04/GHSA-j648-rgv6-ccc8/GHSA-j648-rgv6-ccc8.json index 6d8f3619672..af62695d5f6 100644 --- a/advisories/unreviewed/2024/04/GHSA-j648-rgv6-ccc8/GHSA-j648-rgv6-ccc8.json +++ b/advisories/unreviewed/2024/04/GHSA-j648-rgv6-ccc8/GHSA-j648-rgv6-ccc8.json @@ -7,12 +7,8 @@ "CVE-2024-26773" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found()\n\nDetermine if the group block bitmap is corrupted before using ac_b_ex in\next4_mb_try_best_found() to avoid allocating blocks from a group with a\ncorrupted block bitmap in the following concurrency and making the\nsituation worse.\n\next4_mb_regular_allocator\n ext4_lock_group(sb, group)\n ext4_mb_good_group\n // check if the group bbitmap is corrupted\n ext4_mb_complex_scan_group\n // Scan group gets ac_b_ex but doesn't use it\n ext4_unlock_group(sb, group)\n ext4_mark_group_bitmap_corrupted(group)\n // The block bitmap was corrupted during\n // the group unlock gap.\n ext4_mb_try_best_found\n ext4_lock_group(ac->ac_sb, group)\n ext4_mb_use_best_found\n mb_mark_used\n // Allocating blocks in block bitmap corrupted group", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-j68j-2qh2-c4cq/GHSA-j68j-2qh2-c4cq.json b/advisories/unreviewed/2024/04/GHSA-j68j-2qh2-c4cq/GHSA-j68j-2qh2-c4cq.json index 818d2f50963..cfed9da6a04 100644 --- a/advisories/unreviewed/2024/04/GHSA-j68j-2qh2-c4cq/GHSA-j68j-2qh2-c4cq.json +++ b/advisories/unreviewed/2024/04/GHSA-j68j-2qh2-c4cq/GHSA-j68j-2qh2-c4cq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -67,9 +65,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jg3j-8qg2-gph3/GHSA-jg3j-8qg2-gph3.json b/advisories/unreviewed/2024/04/GHSA-jg3j-8qg2-gph3/GHSA-jg3j-8qg2-gph3.json index f65d4479604..e9a4894e406 100644 --- a/advisories/unreviewed/2024/04/GHSA-jg3j-8qg2-gph3/GHSA-jg3j-8qg2-gph3.json +++ b/advisories/unreviewed/2024/04/GHSA-jg3j-8qg2-gph3/GHSA-jg3j-8qg2-gph3.json @@ -7,12 +7,8 @@ "CVE-2024-26663" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: Check the bearer type before calling tipc_udp_nl_bearer_add()\n\nsyzbot reported the following general protection fault [1]:\n\ngeneral protection fault, probably for non-canonical address 0xdffffc0000000010: 0000 [#1] PREEMPT SMP KASAN\nKASAN: null-ptr-deref in range [0x0000000000000080-0x0000000000000087]\n...\nRIP: 0010:tipc_udp_is_known_peer+0x9c/0x250 net/tipc/udp_media.c:291\n...\nCall Trace:\n \n tipc_udp_nl_bearer_add+0x212/0x2f0 net/tipc/udp_media.c:646\n tipc_nl_bearer_add+0x21e/0x360 net/tipc/bearer.c:1089\n genl_family_rcv_msg_doit+0x1fc/0x2e0 net/netlink/genetlink.c:972\n genl_family_rcv_msg net/netlink/genetlink.c:1052 [inline]\n genl_rcv_msg+0x561/0x800 net/netlink/genetlink.c:1067\n netlink_rcv_skb+0x16b/0x440 net/netlink/af_netlink.c:2544\n genl_rcv+0x28/0x40 net/netlink/genetlink.c:1076\n netlink_unicast_kernel net/netlink/af_netlink.c:1341 [inline]\n netlink_unicast+0x53b/0x810 net/netlink/af_netlink.c:1367\n netlink_sendmsg+0x8b7/0xd70 net/netlink/af_netlink.c:1909\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0xd5/0x180 net/socket.c:745\n ____sys_sendmsg+0x6ac/0x940 net/socket.c:2584\n ___sys_sendmsg+0x135/0x1d0 net/socket.c:2638\n __sys_sendmsg+0x117/0x1e0 net/socket.c:2667\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0x40/0x110 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nThe cause of this issue is that when tipc_nl_bearer_add() is called with\nthe TIPC_NLA_BEARER_UDP_OPTS attribute, tipc_udp_nl_bearer_add() is called\neven if the bearer is not UDP.\n\ntipc_udp_is_known_peer() called by tipc_udp_nl_bearer_add() assumes that\nthe media_ptr field of the tipc_bearer has an udp_bearer type object, so\nthe function goes crazy for non-UDP bearers.\n\nThis patch fixes the issue by checking the bearer type before calling\ntipc_udp_nl_bearer_add() in tipc_nl_bearer_add().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jg7c-h6xh-f8hr/GHSA-jg7c-h6xh-f8hr.json b/advisories/unreviewed/2024/04/GHSA-jg7c-h6xh-f8hr/GHSA-jg7c-h6xh-f8hr.json index 014c53aa2f5..03c86ad59e8 100644 --- a/advisories/unreviewed/2024/04/GHSA-jg7c-h6xh-f8hr/GHSA-jg7c-h6xh-f8hr.json +++ b/advisories/unreviewed/2024/04/GHSA-jg7c-h6xh-f8hr/GHSA-jg7c-h6xh-f8hr.json @@ -7,12 +7,8 @@ "CVE-2024-26878" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nquota: Fix potential NULL pointer dereference\n\nBelow race may cause NULL pointer dereference\n\nP1\t\t\t\t\tP2\ndquot_free_inode\t\t\tquota_off\n\t\t\t\t\t drop_dquot_ref\n\t\t\t\t\t remove_dquot_ref\n\t\t\t\t\t dquots = i_dquot(inode)\n dquots = i_dquot(inode)\n srcu_read_lock\n dquots[cnt]) != NULL (1)\n\t\t\t\t\t dquots[type] = NULL (2)\n spin_lock(&dquots[cnt]->dq_dqb_lock) (3)\n ....\n\nIf dquot_free_inode(or other routines) checks inode's quota pointers (1)\nbefore quota_off sets it to NULL(2) and use it (3) after that, NULL pointer\ndereference will be triggered.\n\nSo let's fix it by using a temporary pointer to avoid this issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jj2v-2j63-rcwf/GHSA-jj2v-2j63-rcwf.json b/advisories/unreviewed/2024/04/GHSA-jj2v-2j63-rcwf/GHSA-jj2v-2j63-rcwf.json index ddc29b9a6f0..0861241d4dc 100644 --- a/advisories/unreviewed/2024/04/GHSA-jj2v-2j63-rcwf/GHSA-jj2v-2j63-rcwf.json +++ b/advisories/unreviewed/2024/04/GHSA-jj2v-2j63-rcwf/GHSA-jj2v-2j63-rcwf.json @@ -7,12 +7,8 @@ "CVE-2024-26835" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: set dormant flag on hook register failure\n\nWe need to set the dormant flag again if we fail to register\nthe hooks.\n\nDuring memory pressure hook registration can fail and we end up\nwith a table marked as active but no registered hooks.\n\nOn table/base chain deletion, nf_tables will attempt to unregister\nthe hook again which yields a warn splat from the nftables core.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jv96-qfmj-26f9/GHSA-jv96-qfmj-26f9.json b/advisories/unreviewed/2024/04/GHSA-jv96-qfmj-26f9/GHSA-jv96-qfmj-26f9.json index 05fca56c4b8..3c51dfa17d2 100644 --- a/advisories/unreviewed/2024/04/GHSA-jv96-qfmj-26f9/GHSA-jv96-qfmj-26f9.json +++ b/advisories/unreviewed/2024/04/GHSA-jv96-qfmj-26f9/GHSA-jv96-qfmj-26f9.json @@ -7,12 +7,8 @@ "CVE-2024-26833" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix memory leak in dm_sw_fini()\n\nAfter destroying dmub_srv, the memory associated with it is\nnot freed, causing a memory leak:\n\nunreferenced object 0xffff896302b45800 (size 1024):\n comm \"(udev-worker)\", pid 222, jiffies 4294894636\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace (crc 6265fd77):\n [] kmalloc_trace+0x29d/0x340\n [] dm_dmub_sw_init+0xb4/0x450 [amdgpu]\n [] dm_sw_init+0x15/0x2b0 [amdgpu]\n [] amdgpu_device_init+0x1417/0x24e0 [amdgpu]\n [] amdgpu_driver_load_kms+0x15/0x190 [amdgpu]\n [] amdgpu_pci_probe+0x187/0x4e0 [amdgpu]\n [] local_pci_probe+0x3e/0x90\n [] pci_device_probe+0xc3/0x230\n [] really_probe+0xe2/0x480\n [] __driver_probe_device+0x78/0x160\n [] driver_probe_device+0x1f/0x90\n [] __driver_attach+0xce/0x1c0\n [] bus_for_each_dev+0x70/0xc0\n [] bus_add_driver+0x112/0x210\n [] driver_register+0x55/0x100\n [] do_one_initcall+0x41/0x300\n\nFix this by freeing dmub_srv after destroying it.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jwqh-57hr-2ggg/GHSA-jwqh-57hr-2ggg.json b/advisories/unreviewed/2024/04/GHSA-jwqh-57hr-2ggg/GHSA-jwqh-57hr-2ggg.json index 9ae02ef886f..ac2ecb3c31b 100644 --- a/advisories/unreviewed/2024/04/GHSA-jwqh-57hr-2ggg/GHSA-jwqh-57hr-2ggg.json +++ b/advisories/unreviewed/2024/04/GHSA-jwqh-57hr-2ggg/GHSA-jwqh-57hr-2ggg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-m6wx-5x43-45rq/GHSA-m6wx-5x43-45rq.json b/advisories/unreviewed/2024/04/GHSA-m6wx-5x43-45rq/GHSA-m6wx-5x43-45rq.json index a22aff6835e..70563327cfe 100644 --- a/advisories/unreviewed/2024/04/GHSA-m6wx-5x43-45rq/GHSA-m6wx-5x43-45rq.json +++ b/advisories/unreviewed/2024/04/GHSA-m6wx-5x43-45rq/GHSA-m6wx-5x43-45rq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-mhpf-x66q-8p92/GHSA-mhpf-x66q-8p92.json b/advisories/unreviewed/2024/04/GHSA-mhpf-x66q-8p92/GHSA-mhpf-x66q-8p92.json index b21e280ff28..71b34e6f96d 100644 --- a/advisories/unreviewed/2024/04/GHSA-mhpf-x66q-8p92/GHSA-mhpf-x66q-8p92.json +++ b/advisories/unreviewed/2024/04/GHSA-mhpf-x66q-8p92/GHSA-mhpf-x66q-8p92.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -59,9 +57,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-mqqf-w892-86vp/GHSA-mqqf-w892-86vp.json b/advisories/unreviewed/2024/04/GHSA-mqqf-w892-86vp/GHSA-mqqf-w892-86vp.json index 9eaaaa9c0be..44da766bf7f 100644 --- a/advisories/unreviewed/2024/04/GHSA-mqqf-w892-86vp/GHSA-mqqf-w892-86vp.json +++ b/advisories/unreviewed/2024/04/GHSA-mqqf-w892-86vp/GHSA-mqqf-w892-86vp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-mvgr-2rgh-283w/GHSA-mvgr-2rgh-283w.json b/advisories/unreviewed/2024/04/GHSA-mvgr-2rgh-283w/GHSA-mvgr-2rgh-283w.json index b7e9419e28a..91648c2d3c1 100644 --- a/advisories/unreviewed/2024/04/GHSA-mvgr-2rgh-283w/GHSA-mvgr-2rgh-283w.json +++ b/advisories/unreviewed/2024/04/GHSA-mvgr-2rgh-283w/GHSA-mvgr-2rgh-283w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-mw2r-2h6j-6g7v/GHSA-mw2r-2h6j-6g7v.json b/advisories/unreviewed/2024/04/GHSA-mw2r-2h6j-6g7v/GHSA-mw2r-2h6j-6g7v.json index 73ecf785de5..46fefa1678d 100644 --- a/advisories/unreviewed/2024/04/GHSA-mw2r-2h6j-6g7v/GHSA-mw2r-2h6j-6g7v.json +++ b/advisories/unreviewed/2024/04/GHSA-mw2r-2h6j-6g7v/GHSA-mw2r-2h6j-6g7v.json @@ -7,12 +7,8 @@ "CVE-2024-26751" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nARM: ep93xx: Add terminator to gpiod_lookup_table\n\nWithout the terminator, if a con_id is passed to gpio_find() that\ndoes not exist in the lookup table the function will not stop looping\ncorrectly, and eventually cause an oops.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-mw3g-jr7f-3gg4/GHSA-mw3g-jr7f-3gg4.json b/advisories/unreviewed/2024/04/GHSA-mw3g-jr7f-3gg4/GHSA-mw3g-jr7f-3gg4.json index 6f41bb6333b..7ce2a2d0ec8 100644 --- a/advisories/unreviewed/2024/04/GHSA-mw3g-jr7f-3gg4/GHSA-mw3g-jr7f-3gg4.json +++ b/advisories/unreviewed/2024/04/GHSA-mw3g-jr7f-3gg4/GHSA-mw3g-jr7f-3gg4.json @@ -7,12 +7,8 @@ "CVE-2024-26816" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86, relocs: Ignore relocations in .notes section\n\nWhen building with CONFIG_XEN_PV=y, .text symbols are emitted into\nthe .notes section so that Xen can find the \"startup_xen\" entry point.\nThis information is used prior to booting the kernel, so relocations\nare not useful. In fact, performing relocations against the .notes\nsection means that the KASLR base is exposed since /sys/kernel/notes\nis world-readable.\n\nTo avoid leaking the KASLR base without breaking unprivileged tools that\nare expecting to read /sys/kernel/notes, skip performing relocations in\nthe .notes section. The values readable in .notes are then identical to\nthose found in System.map.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-p33p-qh45-v5wf/GHSA-p33p-qh45-v5wf.json b/advisories/unreviewed/2024/04/GHSA-p33p-qh45-v5wf/GHSA-p33p-qh45-v5wf.json index 8df3cde97cc..2c165270411 100644 --- a/advisories/unreviewed/2024/04/GHSA-p33p-qh45-v5wf/GHSA-p33p-qh45-v5wf.json +++ b/advisories/unreviewed/2024/04/GHSA-p33p-qh45-v5wf/GHSA-p33p-qh45-v5wf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-p37h-v38c-f75w/GHSA-p37h-v38c-f75w.json b/advisories/unreviewed/2024/04/GHSA-p37h-v38c-f75w/GHSA-p37h-v38c-f75w.json index 639b9a2c5ff..b3ee7a2204e 100644 --- a/advisories/unreviewed/2024/04/GHSA-p37h-v38c-f75w/GHSA-p37h-v38c-f75w.json +++ b/advisories/unreviewed/2024/04/GHSA-p37h-v38c-f75w/GHSA-p37h-v38c-f75w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-p46w-8mq5-8mgj/GHSA-p46w-8mq5-8mgj.json b/advisories/unreviewed/2024/04/GHSA-p46w-8mq5-8mgj/GHSA-p46w-8mq5-8mgj.json index 63b68ef2985..2b1feb25827 100644 --- a/advisories/unreviewed/2024/04/GHSA-p46w-8mq5-8mgj/GHSA-p46w-8mq5-8mgj.json +++ b/advisories/unreviewed/2024/04/GHSA-p46w-8mq5-8mgj/GHSA-p46w-8mq5-8mgj.json @@ -7,12 +7,8 @@ "CVE-2024-26722" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: rt5645: Fix deadlock in rt5645_jack_detect_work()\n\nThere is a path in rt5645_jack_detect_work(), where rt5645->jd_mutex\nis left locked forever. That may lead to deadlock\nwhen rt5645_jack_detect_work() is called for the second time.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-p8g6-7v7w-4whg/GHSA-p8g6-7v7w-4whg.json b/advisories/unreviewed/2024/04/GHSA-p8g6-7v7w-4whg/GHSA-p8g6-7v7w-4whg.json index f895922c759..1b21c0d5c97 100644 --- a/advisories/unreviewed/2024/04/GHSA-p8g6-7v7w-4whg/GHSA-p8g6-7v7w-4whg.json +++ b/advisories/unreviewed/2024/04/GHSA-p8g6-7v7w-4whg/GHSA-p8g6-7v7w-4whg.json @@ -7,12 +7,8 @@ "CVE-2024-26812" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/pci: Create persistent INTx handler\n\nA vulnerability exists where the eventfd for INTx signaling can be\ndeconfigured, which unregisters the IRQ handler but still allows\neventfds to be signaled with a NULL context through the SET_IRQS ioctl\nor through unmask irqfd if the device interrupt is pending.\n\nIdeally this could be solved with some additional locking; the igate\nmutex serializes the ioctl and config space accesses, and the interrupt\nhandler is unregistered relative to the trigger, but the irqfd path\nruns asynchronous to those. The igate mutex cannot be acquired from the\natomic context of the eventfd wake function. Disabling the irqfd\nrelative to the eventfd registration is potentially incompatible with\nexisting userspace.\n\nAs a result, the solution implemented here moves configuration of the\nINTx interrupt handler to track the lifetime of the INTx context object\nand irq_type configuration, rather than registration of a particular\ntrigger eventfd. Synchronization is added between the ioctl path and\neventfd_signal() wrapper such that the eventfd trigger can be\ndynamically updated relative to in-flight interrupts or irqfd callbacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-pfjp-fv5p-fjx7/GHSA-pfjp-fv5p-fjx7.json b/advisories/unreviewed/2024/04/GHSA-pfjp-fv5p-fjx7/GHSA-pfjp-fv5p-fjx7.json index 85b6d5e8bb8..1ffc4dac170 100644 --- a/advisories/unreviewed/2024/04/GHSA-pfjp-fv5p-fjx7/GHSA-pfjp-fv5p-fjx7.json +++ b/advisories/unreviewed/2024/04/GHSA-pfjp-fv5p-fjx7/GHSA-pfjp-fv5p-fjx7.json @@ -7,12 +7,8 @@ "CVE-2024-26809" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_set_pipapo: release elements in clone only from destroy path\n\nClone already always provides a current view of the lookup table, use it\nto destroy the set, otherwise it is possible to destroy elements twice.\n\nThis fix requires:\n\n 212ed75dc5fb (\"netfilter: nf_tables: integrate pipapo into commit protocol\")\n\nwhich came after:\n\n 9827a0e6e23b (\"netfilter: nft_set_pipapo: release elements in clone from abort path\").", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-pgc5-vrj2-c9w5/GHSA-pgc5-vrj2-c9w5.json b/advisories/unreviewed/2024/04/GHSA-pgc5-vrj2-c9w5/GHSA-pgc5-vrj2-c9w5.json index 808744a50b2..c4665a7897f 100644 --- a/advisories/unreviewed/2024/04/GHSA-pgc5-vrj2-c9w5/GHSA-pgc5-vrj2-c9w5.json +++ b/advisories/unreviewed/2024/04/GHSA-pgc5-vrj2-c9w5/GHSA-pgc5-vrj2-c9w5.json @@ -7,12 +7,8 @@ "CVE-2024-26654" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: sh: aica: reorder cleanup operations to avoid UAF bugs\n\nThe dreamcastcard->timer could schedule the spu_dma_work and the\nspu_dma_work could also arm the dreamcastcard->timer.\n\nWhen the snd_pcm_substream is closing, the aica_channel will be\ndeallocated. But it could still be dereferenced in the worker\nthread. The reason is that del_timer() will return directly\nregardless of whether the timer handler is running or not and\nthe worker could be rescheduled in the timer handler. As a result,\nthe UAF bug will happen. The racy situation is shown below:\n\n (Thread 1) | (Thread 2)\nsnd_aicapcm_pcm_close() |\n ... | run_spu_dma() //worker\n | mod_timer()\n flush_work() |\n del_timer() | aica_period_elapsed() //timer\n kfree(dreamcastcard->channel) | schedule_work()\n | run_spu_dma() //worker\n ... | dreamcastcard->channel-> //USE\n\nIn order to mitigate this bug and other possible corner cases,\ncall mod_timer() conditionally in run_spu_dma(), then implement\nPCM sync_stop op to cancel both the timer and worker. The sync_stop\nop will be called from PCM core appropriately when needed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-pvq9-49j8-h86c/GHSA-pvq9-49j8-h86c.json b/advisories/unreviewed/2024/04/GHSA-pvq9-49j8-h86c/GHSA-pvq9-49j8-h86c.json index 1bbe3a3936a..e06ab20bbd8 100644 --- a/advisories/unreviewed/2024/04/GHSA-pvq9-49j8-h86c/GHSA-pvq9-49j8-h86c.json +++ b/advisories/unreviewed/2024/04/GHSA-pvq9-49j8-h86c/GHSA-pvq9-49j8-h86c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-pxc4-f9p3-54rp/GHSA-pxc4-f9p3-54rp.json b/advisories/unreviewed/2024/04/GHSA-pxc4-f9p3-54rp/GHSA-pxc4-f9p3-54rp.json index 94147bb9039..cbb3cdcd403 100644 --- a/advisories/unreviewed/2024/04/GHSA-pxc4-f9p3-54rp/GHSA-pxc4-f9p3-54rp.json +++ b/advisories/unreviewed/2024/04/GHSA-pxc4-f9p3-54rp/GHSA-pxc4-f9p3-54rp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-q342-fw2j-5cj8/GHSA-q342-fw2j-5cj8.json b/advisories/unreviewed/2024/04/GHSA-q342-fw2j-5cj8/GHSA-q342-fw2j-5cj8.json index 9bc485e8209..30cbfb5c782 100644 --- a/advisories/unreviewed/2024/04/GHSA-q342-fw2j-5cj8/GHSA-q342-fw2j-5cj8.json +++ b/advisories/unreviewed/2024/04/GHSA-q342-fw2j-5cj8/GHSA-q342-fw2j-5cj8.json @@ -7,12 +7,8 @@ "CVE-2024-26874" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/mediatek: Fix a null pointer crash in mtk_drm_crtc_finish_page_flip\n\nIt's possible that mtk_crtc->event is NULL in\nmtk_drm_crtc_finish_page_flip().\n\npending_needs_vblank value is set by mtk_crtc->event, but in\nmtk_drm_crtc_atomic_flush(), it's is not guarded by the same\nlock in mtk_drm_finish_page_flip(), thus a race condition happens.\n\nConsider the following case:\n\nCPU1 CPU2\nstep 1:\nmtk_drm_crtc_atomic_begin()\nmtk_crtc->event is not null,\n step 1:\n mtk_drm_crtc_atomic_flush:\n mtk_drm_crtc_update_config(\n !!mtk_crtc->event)\nstep 2:\nmtk_crtc_ddp_irq ->\nmtk_drm_finish_page_flip:\nlock\nmtk_crtc->event set to null,\npending_needs_vblank set to false\nunlock\n pending_needs_vblank set to true,\n\n step 2:\n mtk_crtc_ddp_irq ->\n mtk_drm_finish_page_flip called again,\n pending_needs_vblank is still true\n //null pointer\n\nInstead of guarding the entire mtk_drm_crtc_atomic_flush(), it's more\nefficient to just check if mtk_crtc->event is null before use.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qg9h-x99x-fcvh/GHSA-qg9h-x99x-fcvh.json b/advisories/unreviewed/2024/04/GHSA-qg9h-x99x-fcvh/GHSA-qg9h-x99x-fcvh.json index 8477e3b0b70..a0df32a6002 100644 --- a/advisories/unreviewed/2024/04/GHSA-qg9h-x99x-fcvh/GHSA-qg9h-x99x-fcvh.json +++ b/advisories/unreviewed/2024/04/GHSA-qg9h-x99x-fcvh/GHSA-qg9h-x99x-fcvh.json @@ -7,12 +7,8 @@ "CVE-2024-26665" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntunnels: fix out of bounds access when building IPv6 PMTU error\n\nIf the ICMPv6 error is built from a non-linear skb we get the following\nsplat,\n\n BUG: KASAN: slab-out-of-bounds in do_csum+0x220/0x240\n Read of size 4 at addr ffff88811d402c80 by task netperf/820\n CPU: 0 PID: 820 Comm: netperf Not tainted 6.8.0-rc1+ #543\n ...\n kasan_report+0xd8/0x110\n do_csum+0x220/0x240\n csum_partial+0xc/0x20\n skb_tunnel_check_pmtu+0xeb9/0x3280\n vxlan_xmit_one+0x14c2/0x4080\n vxlan_xmit+0xf61/0x5c00\n dev_hard_start_xmit+0xfb/0x510\n __dev_queue_xmit+0x7cd/0x32a0\n br_dev_queue_push_xmit+0x39d/0x6a0\n\nUse skb_checksum instead of csum_partial who cannot deal with non-linear\nSKBs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qjvp-25fj-gf6v/GHSA-qjvp-25fj-gf6v.json b/advisories/unreviewed/2024/04/GHSA-qjvp-25fj-gf6v/GHSA-qjvp-25fj-gf6v.json index aac653fec00..d62112f561c 100644 --- a/advisories/unreviewed/2024/04/GHSA-qjvp-25fj-gf6v/GHSA-qjvp-25fj-gf6v.json +++ b/advisories/unreviewed/2024/04/GHSA-qjvp-25fj-gf6v/GHSA-qjvp-25fj-gf6v.json @@ -7,12 +7,8 @@ "CVE-2024-26671" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-mq: fix IO hang from sbitmap wakeup race\n\nIn blk_mq_mark_tag_wait(), __add_wait_queue() may be re-ordered\nwith the following blk_mq_get_driver_tag() in case of getting driver\ntag failure.\n\nThen in __sbitmap_queue_wake_up(), waitqueue_active() may not observe\nthe added waiter in blk_mq_mark_tag_wait() and wake up nothing, meantime\nblk_mq_mark_tag_wait() can't get driver tag successfully.\n\nThis issue can be reproduced by running the following test in loop, and\nfio hang can be observed in < 30min when running it on my test VM\nin laptop.\n\n\tmodprobe -r scsi_debug\n\tmodprobe scsi_debug delay=0 dev_size_mb=4096 max_queue=1 host_max_queue=1 submit_queues=4\n\tdev=`ls -d /sys/bus/pseudo/drivers/scsi_debug/adapter*/host*/target*/*/block/* | head -1 | xargs basename`\n\tfio --filename=/dev/\"$dev\" --direct=1 --rw=randrw --bs=4k --iodepth=1 \\\n \t\t--runtime=100 --numjobs=40 --time_based --name=test \\\n \t--ioengine=libaio\n\nFix the issue by adding one explicit barrier in blk_mq_mark_tag_wait(), which\nis just fine in case of running out of tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qp44-g28j-qgqp/GHSA-qp44-g28j-qgqp.json b/advisories/unreviewed/2024/04/GHSA-qp44-g28j-qgqp/GHSA-qp44-g28j-qgqp.json index ea26201057f..b5aace4d38f 100644 --- a/advisories/unreviewed/2024/04/GHSA-qp44-g28j-qgqp/GHSA-qp44-g28j-qgqp.json +++ b/advisories/unreviewed/2024/04/GHSA-qp44-g28j-qgqp/GHSA-qp44-g28j-qgqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-qp64-mm58-qpcj/GHSA-qp64-mm58-qpcj.json b/advisories/unreviewed/2024/04/GHSA-qp64-mm58-qpcj/GHSA-qp64-mm58-qpcj.json index a34b56ebe66..d4eb7cca2c1 100644 --- a/advisories/unreviewed/2024/04/GHSA-qp64-mm58-qpcj/GHSA-qp64-mm58-qpcj.json +++ b/advisories/unreviewed/2024/04/GHSA-qp64-mm58-qpcj/GHSA-qp64-mm58-qpcj.json @@ -7,12 +7,8 @@ "CVE-2023-47357" ], "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qv7c-pjpr-grqx/GHSA-qv7c-pjpr-grqx.json b/advisories/unreviewed/2024/04/GHSA-qv7c-pjpr-grqx/GHSA-qv7c-pjpr-grqx.json index 0c1acaa985c..78c3fbdd2c6 100644 --- a/advisories/unreviewed/2024/04/GHSA-qv7c-pjpr-grqx/GHSA-qv7c-pjpr-grqx.json +++ b/advisories/unreviewed/2024/04/GHSA-qv7c-pjpr-grqx/GHSA-qv7c-pjpr-grqx.json @@ -7,12 +7,8 @@ "CVE-2024-26790" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: fsl-qdma: fix SoC may hang on 16 byte unaligned read\n\nThere is chip (ls1028a) errata:\n\nThe SoC may hang on 16 byte unaligned read transactions by QDMA.\n\nUnaligned read transactions initiated by QDMA may stall in the NOC\n(Network On-Chip), causing a deadlock condition. Stalled transactions will\ntrigger completion timeouts in PCIe controller.\n\nWorkaround:\nEnable prefetch by setting the source descriptor prefetchable bit\n( SD[PF] = 1 ).\n\nImplement this workaround.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qvjm-pcpv-593p/GHSA-qvjm-pcpv-593p.json b/advisories/unreviewed/2024/04/GHSA-qvjm-pcpv-593p/GHSA-qvjm-pcpv-593p.json index d645636bbcf..9551818f6ed 100644 --- a/advisories/unreviewed/2024/04/GHSA-qvjm-pcpv-593p/GHSA-qvjm-pcpv-593p.json +++ b/advisories/unreviewed/2024/04/GHSA-qvjm-pcpv-593p/GHSA-qvjm-pcpv-593p.json @@ -7,12 +7,8 @@ "CVE-2024-26839" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/hfi1: Fix a memleak in init_credit_return\n\nWhen dma_alloc_coherent fails to allocate dd->cr_base[i].va,\ninit_credit_return should deallocate dd->cr_base and\ndd->cr_base[i] that allocated before. Or those resources\nwould be never freed and a memleak is triggered.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-r74x-hfrh-mh6j/GHSA-r74x-hfrh-mh6j.json b/advisories/unreviewed/2024/04/GHSA-r74x-hfrh-mh6j/GHSA-r74x-hfrh-mh6j.json index 86459e1ddd2..bce0154417c 100644 --- a/advisories/unreviewed/2024/04/GHSA-r74x-hfrh-mh6j/GHSA-r74x-hfrh-mh6j.json +++ b/advisories/unreviewed/2024/04/GHSA-r74x-hfrh-mh6j/GHSA-r74x-hfrh-mh6j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-rm2h-rx39-6fc3/GHSA-rm2h-rx39-6fc3.json b/advisories/unreviewed/2024/04/GHSA-rm2h-rx39-6fc3/GHSA-rm2h-rx39-6fc3.json index f6cb95a8d1c..01aa1eb474f 100644 --- a/advisories/unreviewed/2024/04/GHSA-rm2h-rx39-6fc3/GHSA-rm2h-rx39-6fc3.json +++ b/advisories/unreviewed/2024/04/GHSA-rm2h-rx39-6fc3/GHSA-rm2h-rx39-6fc3.json @@ -7,12 +7,8 @@ "CVE-2024-26814" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/fsl-mc: Block calling interrupt handler without trigger\n\nThe eventfd_ctx trigger pointer of the vfio_fsl_mc_irq object is\ninitially NULL and may become NULL if the user sets the trigger\neventfd to -1. The interrupt handler itself is guaranteed that\ntrigger is always valid between request_irq() and free_irq(), but\nthe loopback testing mechanisms to invoke the handler function\nneed to test the trigger. The triggering and setting ioctl paths\nboth make use of igate and are therefore mutually exclusive.\n\nThe vfio-fsl-mc driver does not make use of irqfds, nor does it\nsupport any sort of masking operations, therefore unlike vfio-pci\nand vfio-platform, the flow can remain essentially unchanged.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-rvjh-mwxw-g897/GHSA-rvjh-mwxw-g897.json b/advisories/unreviewed/2024/04/GHSA-rvjh-mwxw-g897/GHSA-rvjh-mwxw-g897.json index f7bc2ffed6e..c8cc9c1f4ea 100644 --- a/advisories/unreviewed/2024/04/GHSA-rvjh-mwxw-g897/GHSA-rvjh-mwxw-g897.json +++ b/advisories/unreviewed/2024/04/GHSA-rvjh-mwxw-g897/GHSA-rvjh-mwxw-g897.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-rw75-4jcc-fx6w/GHSA-rw75-4jcc-fx6w.json b/advisories/unreviewed/2024/04/GHSA-rw75-4jcc-fx6w/GHSA-rw75-4jcc-fx6w.json index 8dc861025f3..3e6f9e74c32 100644 --- a/advisories/unreviewed/2024/04/GHSA-rw75-4jcc-fx6w/GHSA-rw75-4jcc-fx6w.json +++ b/advisories/unreviewed/2024/04/GHSA-rw75-4jcc-fx6w/GHSA-rw75-4jcc-fx6w.json @@ -7,12 +7,8 @@ "CVE-2024-26817" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\namdkfd: use calloc instead of kzalloc to avoid integer overflow\n\nThis uses calloc instead of doing the multiplication which might\noverflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-v6fp-9fjm-v48v/GHSA-v6fp-9fjm-v48v.json b/advisories/unreviewed/2024/04/GHSA-v6fp-9fjm-v48v/GHSA-v6fp-9fjm-v48v.json index ba877f1321b..8cc6d92a2da 100644 --- a/advisories/unreviewed/2024/04/GHSA-v6fp-9fjm-v48v/GHSA-v6fp-9fjm-v48v.json +++ b/advisories/unreviewed/2024/04/GHSA-v6fp-9fjm-v48v/GHSA-v6fp-9fjm-v48v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-v854-7g2j-4x32/GHSA-v854-7g2j-4x32.json b/advisories/unreviewed/2024/04/GHSA-v854-7g2j-4x32/GHSA-v854-7g2j-4x32.json index 14b5acb221f..fae8ef78723 100644 --- a/advisories/unreviewed/2024/04/GHSA-v854-7g2j-4x32/GHSA-v854-7g2j-4x32.json +++ b/advisories/unreviewed/2024/04/GHSA-v854-7g2j-4x32/GHSA-v854-7g2j-4x32.json @@ -7,12 +7,8 @@ "CVE-2024-26673" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations\n\n- Disallow families other than NFPROTO_{IPV4,IPV6,INET}.\n- Disallow layer 4 protocol with no ports, since destination port is a\n mandatory attribute for this object.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-vh2f-wj96-fxxh/GHSA-vh2f-wj96-fxxh.json b/advisories/unreviewed/2024/04/GHSA-vh2f-wj96-fxxh/GHSA-vh2f-wj96-fxxh.json index c34cbbad5f1..63eaaebc086 100644 --- a/advisories/unreviewed/2024/04/GHSA-vh2f-wj96-fxxh/GHSA-vh2f-wj96-fxxh.json +++ b/advisories/unreviewed/2024/04/GHSA-vh2f-wj96-fxxh/GHSA-vh2f-wj96-fxxh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-vmh5-6rg4-ggmq/GHSA-vmh5-6rg4-ggmq.json b/advisories/unreviewed/2024/04/GHSA-vmh5-6rg4-ggmq/GHSA-vmh5-6rg4-ggmq.json index 92efda19a3e..78bb859e619 100644 --- a/advisories/unreviewed/2024/04/GHSA-vmh5-6rg4-ggmq/GHSA-vmh5-6rg4-ggmq.json +++ b/advisories/unreviewed/2024/04/GHSA-vmh5-6rg4-ggmq/GHSA-vmh5-6rg4-ggmq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-vmhf-rfw6-gg6x/GHSA-vmhf-rfw6-gg6x.json b/advisories/unreviewed/2024/04/GHSA-vmhf-rfw6-gg6x/GHSA-vmhf-rfw6-gg6x.json index 5bb0f6fe5ab..18f7b77a217 100644 --- a/advisories/unreviewed/2024/04/GHSA-vmhf-rfw6-gg6x/GHSA-vmhf-rfw6-gg6x.json +++ b/advisories/unreviewed/2024/04/GHSA-vmhf-rfw6-gg6x/GHSA-vmhf-rfw6-gg6x.json @@ -7,12 +7,8 @@ "CVE-2024-26891" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Don't issue ATS Invalidation request when device is disconnected\n\nFor those endpoint devices connect to system via hotplug capable ports,\nusers could request a hot reset to the device by flapping device's link\nthrough setting the slot's link control register, as pciehp_ist() DLLSC\ninterrupt sequence response, pciehp will unload the device driver and\nthen power it off. thus cause an IOMMU device-TLB invalidation (Intel\nVT-d spec, or ATS Invalidation in PCIe spec r6.1) request for non-existence\ntarget device to be sent and deadly loop to retry that request after ITE\nfault triggered in interrupt context.\n\nThat would cause following continuous hard lockup warning and system hang\n\n[ 4211.433662] pcieport 0000:17:01.0: pciehp: Slot(108): Link Down\n[ 4211.433664] pcieport 0000:17:01.0: pciehp: Slot(108): Card not present\n[ 4223.822591] NMI watchdog: Watchdog detected hard LOCKUP on cpu 144\n[ 4223.822622] CPU: 144 PID: 1422 Comm: irq/57-pciehp Kdump: loaded Tainted: G S\n OE kernel version xxxx\n[ 4223.822623] Hardware name: vendorname xxxx 666-106,\nBIOS 01.01.02.03.01 05/15/2023\n[ 4223.822623] RIP: 0010:qi_submit_sync+0x2c0/0x490\n[ 4223.822624] Code: 48 be 00 00 00 00 00 08 00 00 49 85 74 24 20 0f 95 c1 48 8b\n 57 10 83 c1 04 83 3c 1a 03 0f 84 a2 01 00 00 49 8b 04 24 8b 70 34 <40> f6 c6 1\n0 74 17 49 8b 04 24 8b 80 80 00 00 00 89 c2 d3 fa 41 39\n[ 4223.822624] RSP: 0018:ffffc4f074f0bbb8 EFLAGS: 00000093\n[ 4223.822625] RAX: ffffc4f040059000 RBX: 0000000000000014 RCX: 0000000000000005\n[ 4223.822625] RDX: ffff9f3841315800 RSI: 0000000000000000 RDI: ffff9f38401a8340\n[ 4223.822625] RBP: ffff9f38401a8340 R08: ffffc4f074f0bc00 R09: 0000000000000000\n[ 4223.822626] R10: 0000000000000010 R11: 0000000000000018 R12: ffff9f384005e200\n[ 4223.822626] R13: 0000000000000004 R14: 0000000000000046 R15: 0000000000000004\n[ 4223.822626] FS: 0000000000000000(0000) GS:ffffa237ae400000(0000)\nknlGS:0000000000000000\n[ 4223.822627] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 4223.822627] CR2: 00007ffe86515d80 CR3: 000002fd3000a001 CR4: 0000000000770ee0\n[ 4223.822627] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 4223.822628] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400\n[ 4223.822628] PKRU: 55555554\n[ 4223.822628] Call Trace:\n[ 4223.822628] qi_flush_dev_iotlb+0xb1/0xd0\n[ 4223.822628] __dmar_remove_one_dev_info+0x224/0x250\n[ 4223.822629] dmar_remove_one_dev_info+0x3e/0x50\n[ 4223.822629] intel_iommu_release_device+0x1f/0x30\n[ 4223.822629] iommu_release_device+0x33/0x60\n[ 4223.822629] iommu_bus_notifier+0x7f/0x90\n[ 4223.822630] blocking_notifier_call_chain+0x60/0x90\n[ 4223.822630] device_del+0x2e5/0x420\n[ 4223.822630] pci_remove_bus_device+0x70/0x110\n[ 4223.822630] pciehp_unconfigure_device+0x7c/0x130\n[ 4223.822631] pciehp_disable_slot+0x6b/0x100\n[ 4223.822631] pciehp_handle_presence_or_link_change+0xd8/0x320\n[ 4223.822631] pciehp_ist+0x176/0x180\n[ 4223.822631] ? irq_finalize_oneshot.part.50+0x110/0x110\n[ 4223.822632] irq_thread_fn+0x19/0x50\n[ 4223.822632] irq_thread+0x104/0x190\n[ 4223.822632] ? irq_forced_thread_fn+0x90/0x90\n[ 4223.822632] ? irq_thread_check_affinity+0xe0/0xe0\n[ 4223.822633] kthread+0x114/0x130\n[ 4223.822633] ? __kthread_cancel_work+0x40/0x40\n[ 4223.822633] ret_from_fork+0x1f/0x30\n[ 4223.822633] Kernel panic - not syncing: Hard LOCKUP\n[ 4223.822634] CPU: 144 PID: 1422 Comm: irq/57-pciehp Kdump: loaded Tainted: G S\n OE kernel version xxxx\n[ 4223.822634] Hardware name: vendorname xxxx 666-106,\nBIOS 01.01.02.03.01 05/15/2023\n[ 4223.822634] Call Trace:\n[ 4223.822634] \n[ 4223.822635] dump_stack+0x6d/0x88\n[ 4223.822635] panic+0x101/0x2d0\n[ 4223.822635] ? ret_from_fork+0x11/0x30\n[ 4223.822635] nmi_panic.cold.14+0xc/0xc\n[ 4223.822636] watchdog_overflow_callback.cold.8+0x6d/0x81\n[ 4223.822636] __perf_event_overflow+0x4f/0xf0\n[ 4223.822636] handle_pmi_common\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-vrrq-3f8j-8672/GHSA-vrrq-3f8j-8672.json b/advisories/unreviewed/2024/04/GHSA-vrrq-3f8j-8672/GHSA-vrrq-3f8j-8672.json index d0777bee16a..7e80a82645b 100644 --- a/advisories/unreviewed/2024/04/GHSA-vrrq-3f8j-8672/GHSA-vrrq-3f8j-8672.json +++ b/advisories/unreviewed/2024/04/GHSA-vrrq-3f8j-8672/GHSA-vrrq-3f8j-8672.json @@ -7,12 +7,8 @@ "CVE-2024-26736" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Increase buffer size in afs_update_volume_status()\n\nThe max length of volume->vid value is 20 characters.\nSo increase idbuf[] size up to 24 to avoid overflow.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\n[DH: Actually, it's 20 + NUL, so increase it to 24 and use snprintf()]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-vx76-2j88-69mq/GHSA-vx76-2j88-69mq.json b/advisories/unreviewed/2024/04/GHSA-vx76-2j88-69mq/GHSA-vx76-2j88-69mq.json index fa16009e464..2847080a293 100644 --- a/advisories/unreviewed/2024/04/GHSA-vx76-2j88-69mq/GHSA-vx76-2j88-69mq.json +++ b/advisories/unreviewed/2024/04/GHSA-vx76-2j88-69mq/GHSA-vx76-2j88-69mq.json @@ -7,12 +7,8 @@ "CVE-2024-26684" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: xgmac: fix handling of DPP safety error for DMA channels\n\nCommit 56e58d6c8a56 (\"net: stmmac: Implement Safety Features in\nXGMAC core\") checks and reports safety errors, but leaves the\nData Path Parity Errors for each channel in DMA unhandled at all, lead to\na storm of interrupt.\nFix it by checking and clearing the DMA_DPP_Interrupt_Status register.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-w255-5hjq-7p69/GHSA-w255-5hjq-7p69.json b/advisories/unreviewed/2024/04/GHSA-w255-5hjq-7p69/GHSA-w255-5hjq-7p69.json index 6ad595efa71..35a6ad9383d 100644 --- a/advisories/unreviewed/2024/04/GHSA-w255-5hjq-7p69/GHSA-w255-5hjq-7p69.json +++ b/advisories/unreviewed/2024/04/GHSA-w255-5hjq-7p69/GHSA-w255-5hjq-7p69.json @@ -7,12 +7,8 @@ "CVE-2024-26851" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_h323: Add protection for bmp length out of range\n\nUBSAN load reports an exception of BRK#5515 SHIFT_ISSUE:Bitwise shifts\nthat are out of bounds for their data type.\n\nvmlinux get_bitmap(b=75) + 712\n\nvmlinux decode_seq(bs=0xFFFFFFD008037000, f=0xFFFFFFD008037018, level=134443100) + 1956\n\nvmlinux decode_choice(base=0xFFFFFFD0080370F0, level=23843636) + 1216\n\nvmlinux decode_seq(f=0xFFFFFFD0080371A8, level=134443500) + 812\n\nvmlinux decode_choice(base=0xFFFFFFD008037280, level=0) + 1216\n\nvmlinux DecodeRasMessage() + 304\n\nvmlinux ras_help() + 684\n\nvmlinux nf_confirm() + 188\n\n\nDue to abnormal data in skb->data, the extension bitmap length\nexceeds 32 when decoding ras message then uses the length to make\na shift operation. It will change into negative after several loop.\nUBSAN load could detect a negative shift as an undefined behaviour\nand reports exception.\nSo we add the protection to avoid the length exceeding 32. Or else\nit will return out of range error and stop decoding.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-w69g-9g23-pfwc/GHSA-w69g-9g23-pfwc.json b/advisories/unreviewed/2024/04/GHSA-w69g-9g23-pfwc/GHSA-w69g-9g23-pfwc.json index 0a79cd8d41b..17231b08717 100644 --- a/advisories/unreviewed/2024/04/GHSA-w69g-9g23-pfwc/GHSA-w69g-9g23-pfwc.json +++ b/advisories/unreviewed/2024/04/GHSA-w69g-9g23-pfwc/GHSA-w69g-9g23-pfwc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-w9mj-34hr-82rj/GHSA-w9mj-34hr-82rj.json b/advisories/unreviewed/2024/04/GHSA-w9mj-34hr-82rj/GHSA-w9mj-34hr-82rj.json index 7e452e166bd..106aca5b217 100644 --- a/advisories/unreviewed/2024/04/GHSA-w9mj-34hr-82rj/GHSA-w9mj-34hr-82rj.json +++ b/advisories/unreviewed/2024/04/GHSA-w9mj-34hr-82rj/GHSA-w9mj-34hr-82rj.json @@ -7,12 +7,8 @@ "CVE-2024-26727" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not ASSERT() if the newly created subvolume already got read\n\n[BUG]\nThere is a syzbot crash, triggered by the ASSERT() during subvolume\ncreation:\n\n assertion failed: !anon_dev, in fs/btrfs/disk-io.c:1319\n ------------[ cut here ]------------\n kernel BUG at fs/btrfs/disk-io.c:1319!\n invalid opcode: 0000 [#1] PREEMPT SMP KASAN\n RIP: 0010:btrfs_get_root_ref.part.0+0x9aa/0xa60\n \n btrfs_get_new_fs_root+0xd3/0xf0\n create_subvol+0xd02/0x1650\n btrfs_mksubvol+0xe95/0x12b0\n __btrfs_ioctl_snap_create+0x2f9/0x4f0\n btrfs_ioctl_snap_create+0x16b/0x200\n btrfs_ioctl+0x35f0/0x5cf0\n __x64_sys_ioctl+0x19d/0x210\n do_syscall_64+0x3f/0xe0\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n ---[ end trace 0000000000000000 ]---\n\n[CAUSE]\nDuring create_subvol(), after inserting root item for the newly created\nsubvolume, we would trigger btrfs_get_new_fs_root() to get the\nbtrfs_root of that subvolume.\n\nThe idea here is, we have preallocated an anonymous device number for\nthe subvolume, thus we can assign it to the new subvolume.\n\nBut there is really nothing preventing things like backref walk to read\nthe new subvolume.\nIf that happens before we call btrfs_get_new_fs_root(), the subvolume\nwould be read out, with a new anonymous device number assigned already.\n\nIn that case, we would trigger ASSERT(), as we really expect no one to\nread out that subvolume (which is not yet accessible from the fs).\nBut things like backref walk is still possible to trigger the read on\nthe subvolume.\n\nThus our assumption on the ASSERT() is not correct in the first place.\n\n[FIX]\nFix it by removing the ASSERT(), and just free the @anon_dev, reset it\nto 0, and continue.\n\nIf the subvolume tree is read out by something else, it should have\nalready get a new anon_dev assigned thus we only need to free the\npreallocated one.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-wfcg-p9mh-53w7/GHSA-wfcg-p9mh-53w7.json b/advisories/unreviewed/2024/04/GHSA-wfcg-p9mh-53w7/GHSA-wfcg-p9mh-53w7.json index 5d0eacc5acf..b962898141d 100644 --- a/advisories/unreviewed/2024/04/GHSA-wfcg-p9mh-53w7/GHSA-wfcg-p9mh-53w7.json +++ b/advisories/unreviewed/2024/04/GHSA-wfcg-p9mh-53w7/GHSA-wfcg-p9mh-53w7.json @@ -7,12 +7,8 @@ "CVE-2024-26688" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs,hugetlb: fix NULL pointer dereference in hugetlbs_fill_super\n\nWhen configuring a hugetlb filesystem via the fsconfig() syscall, there is\na possible NULL dereference in hugetlbfs_fill_super() caused by assigning\nNULL to ctx->hstate in hugetlbfs_parse_param() when the requested pagesize\nis non valid.\n\nE.g: Taking the following steps:\n\n fd = fsopen(\"hugetlbfs\", FSOPEN_CLOEXEC);\n fsconfig(fd, FSCONFIG_SET_STRING, \"pagesize\", \"1024\", 0);\n fsconfig(fd, FSCONFIG_CMD_CREATE, NULL, NULL, 0);\n\nGiven that the requested \"pagesize\" is invalid, ctxt->hstate will be replaced\nwith NULL, losing its previous value, and we will print an error:\n\n ...\n ...\n case Opt_pagesize:\n ps = memparse(param->string, &rest);\n ctx->hstate = h;\n if (!ctx->hstate) {\n pr_err(\"Unsupported page size %lu MB\\n\", ps / SZ_1M);\n return -EINVAL;\n }\n return 0;\n ...\n ...\n\nThis is a problem because later on, we will dereference ctxt->hstate in\nhugetlbfs_fill_super()\n\n ...\n ...\n sb->s_blocksize = huge_page_size(ctx->hstate);\n ...\n ...\n\nCausing below Oops.\n\nFix this by replacing cxt->hstate value only when then pagesize is known\nto be valid.\n\n kernel: hugetlbfs: Unsupported page size 0 MB\n kernel: BUG: kernel NULL pointer dereference, address: 0000000000000028\n kernel: #PF: supervisor read access in kernel mode\n kernel: #PF: error_code(0x0000) - not-present page\n kernel: PGD 800000010f66c067 P4D 800000010f66c067 PUD 1b22f8067 PMD 0\n kernel: Oops: 0000 [#1] PREEMPT SMP PTI\n kernel: CPU: 4 PID: 5659 Comm: syscall Tainted: G E 6.8.0-rc2-default+ #22 5a47c3fef76212addcc6eb71344aabc35190ae8f\n kernel: Hardware name: Intel Corp. GROVEPORT/GROVEPORT, BIOS GVPRCRB1.86B.0016.D04.1705030402 05/03/2017\n kernel: RIP: 0010:hugetlbfs_fill_super+0xb4/0x1a0\n kernel: Code: 48 8b 3b e8 3e c6 ed ff 48 85 c0 48 89 45 20 0f 84 d6 00 00 00 48 b8 ff ff ff ff ff ff ff 7f 4c 89 e7 49 89 44 24 20 48 8b 03 <8b> 48 28 b8 00 10 00 00 48 d3 e0 49 89 44 24 18 48 8b 03 8b 40 28\n kernel: RSP: 0018:ffffbe9960fcbd48 EFLAGS: 00010246\n kernel: RAX: 0000000000000000 RBX: ffff9af5272ae780 RCX: 0000000000372004\n kernel: RDX: ffffffffffffffff RSI: ffffffffffffffff RDI: ffff9af555e9b000\n kernel: RBP: ffff9af52ee66b00 R08: 0000000000000040 R09: 0000000000370004\n kernel: R10: ffffbe9960fcbd48 R11: 0000000000000040 R12: ffff9af555e9b000\n kernel: R13: ffffffffa66b86c0 R14: ffff9af507d2f400 R15: ffff9af507d2f400\n kernel: FS: 00007ffbc0ba4740(0000) GS:ffff9b0bd7000000(0000) knlGS:0000000000000000\n kernel: CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n kernel: CR2: 0000000000000028 CR3: 00000001b1ee0000 CR4: 00000000001506f0\n kernel: Call Trace:\n kernel: \n kernel: ? __die_body+0x1a/0x60\n kernel: ? page_fault_oops+0x16f/0x4a0\n kernel: ? search_bpf_extables+0x65/0x70\n kernel: ? fixup_exception+0x22/0x310\n kernel: ? exc_page_fault+0x69/0x150\n kernel: ? asm_exc_page_fault+0x22/0x30\n kernel: ? __pfx_hugetlbfs_fill_super+0x10/0x10\n kernel: ? hugetlbfs_fill_super+0xb4/0x1a0\n kernel: ? hugetlbfs_fill_super+0x28/0x1a0\n kernel: ? __pfx_hugetlbfs_fill_super+0x10/0x10\n kernel: vfs_get_super+0x40/0xa0\n kernel: ? __pfx_bpf_lsm_capable+0x10/0x10\n kernel: vfs_get_tree+0x25/0xd0\n kernel: vfs_cmd_create+0x64/0xe0\n kernel: __x64_sys_fsconfig+0x395/0x410\n kernel: do_syscall_64+0x80/0x160\n kernel: ? syscall_exit_to_user_mode+0x82/0x240\n kernel: ? do_syscall_64+0x8d/0x160\n kernel: ? syscall_exit_to_user_mode+0x82/0x240\n kernel: ? do_syscall_64+0x8d/0x160\n kernel: ? exc_page_fault+0x69/0x150\n kernel: entry_SYSCALL_64_after_hwframe+0x6e/0x76\n kernel: RIP: 0033:0x7ffbc0cb87c9\n kernel: Code: 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 97 96 0d 00 f7 d8 64 89 01 48\n kernel: RSP: 002b:00007ffc29d2f388 EFLAGS: 00000206 ORIG_RAX: 00000000000001af\n kernel: RAX: fffffffffff\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-wm8x-c4gv-vvw5/GHSA-wm8x-c4gv-vvw5.json b/advisories/unreviewed/2024/04/GHSA-wm8x-c4gv-vvw5/GHSA-wm8x-c4gv-vvw5.json index 32bee5d959d..6e00cb205fc 100644 --- a/advisories/unreviewed/2024/04/GHSA-wm8x-c4gv-vvw5/GHSA-wm8x-c4gv-vvw5.json +++ b/advisories/unreviewed/2024/04/GHSA-wm8x-c4gv-vvw5/GHSA-wm8x-c4gv-vvw5.json @@ -7,12 +7,8 @@ "CVE-2024-26766" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/hfi1: Fix sdma.h tx->num_descs off-by-one error\n\nUnfortunately the commit `fd8958efe877` introduced another error\ncausing the `descs` array to overflow. This reults in further crashes\neasily reproducible by `sendmsg` system call.\n\n[ 1080.836473] general protection fault, probably for non-canonical address 0x400300015528b00a: 0000 [#1] PREEMPT SMP PTI\n[ 1080.869326] RIP: 0010:hfi1_ipoib_build_ib_tx_headers.constprop.0+0xe1/0x2b0 [hfi1]\n--\n[ 1080.974535] Call Trace:\n[ 1080.976990] \n[ 1081.021929] hfi1_ipoib_send_dma_common+0x7a/0x2e0 [hfi1]\n[ 1081.027364] hfi1_ipoib_send_dma_list+0x62/0x270 [hfi1]\n[ 1081.032633] hfi1_ipoib_send+0x112/0x300 [hfi1]\n[ 1081.042001] ipoib_start_xmit+0x2a9/0x2d0 [ib_ipoib]\n[ 1081.046978] dev_hard_start_xmit+0xc4/0x210\n--\n[ 1081.148347] __sys_sendmsg+0x59/0xa0\n\ncrash> ipoib_txreq 0xffff9cfeba229f00\nstruct ipoib_txreq {\n txreq = {\n list = {\n next = 0xffff9cfeba229f00,\n prev = 0xffff9cfeba229f00\n },\n descp = 0xffff9cfeba229f40,\n coalesce_buf = 0x0,\n wait = 0xffff9cfea4e69a48,\n complete = 0xffffffffc0fe0760 ,\n packet_len = 0x46d,\n tlen = 0x0,\n num_desc = 0x0,\n desc_limit = 0x6,\n next_descq_idx = 0x45c,\n coalesce_idx = 0x0,\n flags = 0x0,\n descs = {{\n qw = {0x8024000120dffb00, 0x4} # SDMA_DESC0_FIRST_DESC_FLAG (bit 63)\n }, {\n qw = { 0x3800014231b108, 0x4}\n }, {\n qw = { 0x310000e4ee0fcf0, 0x8}\n }, {\n qw = { 0x3000012e9f8000, 0x8}\n }, {\n qw = { 0x59000dfb9d0000, 0x8}\n }, {\n qw = { 0x78000e02e40000, 0x8}\n }}\n },\n sdma_hdr = 0x400300015528b000, <<< invalid pointer in the tx request structure\n sdma_status = 0x0, SDMA_DESC0_LAST_DESC_FLAG (bit 62)\n complete = 0x0,\n priv = 0x0,\n txq = 0xffff9cfea4e69880,\n skb = 0xffff9d099809f400\n}\n\nIf an SDMA send consists of exactly 6 descriptors and requires dword\npadding (in the 7th descriptor), the sdma_txreq descriptor array is not\nproperly expanded and the packet will overflow into the container\nstructure. This results in a panic when the send completion runs. The\nexact panic varies depending on what elements of the container structure\nget corrupted. The fix is to use the correct expression in\n_pad_sdma_tx_descs() to test the need to expand the descriptor array.\n\nWith this patch the crashes are no longer reproducible and the machine is\nstable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-wvf9-x8f3-rgpr/GHSA-wvf9-x8f3-rgpr.json b/advisories/unreviewed/2024/04/GHSA-wvf9-x8f3-rgpr/GHSA-wvf9-x8f3-rgpr.json index 95f36eb58a9..286acab47e2 100644 --- a/advisories/unreviewed/2024/04/GHSA-wvf9-x8f3-rgpr/GHSA-wvf9-x8f3-rgpr.json +++ b/advisories/unreviewed/2024/04/GHSA-wvf9-x8f3-rgpr/GHSA-wvf9-x8f3-rgpr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-wwjm-jqc7-c985/GHSA-wwjm-jqc7-c985.json b/advisories/unreviewed/2024/04/GHSA-wwjm-jqc7-c985/GHSA-wwjm-jqc7-c985.json index 195d0cc5a45..5a629da632d 100644 --- a/advisories/unreviewed/2024/04/GHSA-wwjm-jqc7-c985/GHSA-wwjm-jqc7-c985.json +++ b/advisories/unreviewed/2024/04/GHSA-wwjm-jqc7-c985/GHSA-wwjm-jqc7-c985.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-x246-w3fc-9p6h/GHSA-x246-w3fc-9p6h.json b/advisories/unreviewed/2024/04/GHSA-x246-w3fc-9p6h/GHSA-x246-w3fc-9p6h.json index e60e7f946cf..5626b189571 100644 --- a/advisories/unreviewed/2024/04/GHSA-x246-w3fc-9p6h/GHSA-x246-w3fc-9p6h.json +++ b/advisories/unreviewed/2024/04/GHSA-x246-w3fc-9p6h/GHSA-x246-w3fc-9p6h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-x8m6-m5rq-285x/GHSA-x8m6-m5rq-285x.json b/advisories/unreviewed/2024/04/GHSA-x8m6-m5rq-285x/GHSA-x8m6-m5rq-285x.json index 7ca8c562480..f1382d3bcb0 100644 --- a/advisories/unreviewed/2024/04/GHSA-x8m6-m5rq-285x/GHSA-x8m6-m5rq-285x.json +++ b/advisories/unreviewed/2024/04/GHSA-x8m6-m5rq-285x/GHSA-x8m6-m5rq-285x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-xfq9-hwv6-6j67/GHSA-xfq9-hwv6-6j67.json b/advisories/unreviewed/2024/04/GHSA-xfq9-hwv6-6j67/GHSA-xfq9-hwv6-6j67.json index dcab3ce7091..e088ee04c48 100644 --- a/advisories/unreviewed/2024/04/GHSA-xfq9-hwv6-6j67/GHSA-xfq9-hwv6-6j67.json +++ b/advisories/unreviewed/2024/04/GHSA-xfq9-hwv6-6j67/GHSA-xfq9-hwv6-6j67.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-xg7r-7865-v6c7/GHSA-xg7r-7865-v6c7.json b/advisories/unreviewed/2024/04/GHSA-xg7r-7865-v6c7/GHSA-xg7r-7865-v6c7.json index fb7cba1e29a..f4fd92f1488 100644 --- a/advisories/unreviewed/2024/04/GHSA-xg7r-7865-v6c7/GHSA-xg7r-7865-v6c7.json +++ b/advisories/unreviewed/2024/04/GHSA-xg7r-7865-v6c7/GHSA-xg7r-7865-v6c7.json @@ -7,12 +7,8 @@ "CVE-2024-26697" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix data corruption in dsync block recovery for small block sizes\n\nThe helper function nilfs_recovery_copy_block() of\nnilfs_recovery_dsync_blocks(), which recovers data from logs created by\ndata sync writes during a mount after an unclean shutdown, incorrectly\ncalculates the on-page offset when copying repair data to the file's page\ncache. In environments where the block size is smaller than the page\nsize, this flaw can cause data corruption and leak uninitialized memory\nbytes during the recovery process.\n\nFix these issues by correcting this byte offset calculation on the page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-xhg5-m3mp-pf34/GHSA-xhg5-m3mp-pf34.json b/advisories/unreviewed/2024/04/GHSA-xhg5-m3mp-pf34/GHSA-xhg5-m3mp-pf34.json index 4dcce6967c3..9d3a94b4124 100644 --- a/advisories/unreviewed/2024/04/GHSA-xhg5-m3mp-pf34/GHSA-xhg5-m3mp-pf34.json +++ b/advisories/unreviewed/2024/04/GHSA-xhg5-m3mp-pf34/GHSA-xhg5-m3mp-pf34.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-xhj3-2vvm-6mr5/GHSA-xhj3-2vvm-6mr5.json b/advisories/unreviewed/2024/04/GHSA-xhj3-2vvm-6mr5/GHSA-xhj3-2vvm-6mr5.json index e452a264a9b..fdd83d49150 100644 --- a/advisories/unreviewed/2024/04/GHSA-xhj3-2vvm-6mr5/GHSA-xhj3-2vvm-6mr5.json +++ b/advisories/unreviewed/2024/04/GHSA-xhj3-2vvm-6mr5/GHSA-xhj3-2vvm-6mr5.json @@ -7,12 +7,8 @@ "CVE-2024-26752" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nl2tp: pass correct message length to ip6_append_data\n\nl2tp_ip6_sendmsg needs to avoid accounting for the transport header\ntwice when splicing more data into an already partially-occupied skbuff.\n\nTo manage this, we check whether the skbuff contains data using\nskb_queue_empty when deciding how much data to append using\nip6_append_data.\n\nHowever, the code which performed the calculation was incorrect:\n\n ulen = len + skb_queue_empty(&sk->sk_write_queue) ? transhdrlen : 0;\n\n...due to C operator precedence, this ends up setting ulen to\ntranshdrlen for messages with a non-zero length, which results in\ncorrupted packets on the wire.\n\nAdd parentheses to correct the calculation in line with the original\nintent.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-xqrq-q336-f78g/GHSA-xqrq-q336-f78g.json b/advisories/unreviewed/2024/04/GHSA-xqrq-q336-f78g/GHSA-xqrq-q336-f78g.json index 13ad2f563ef..4947703c7b4 100644 --- a/advisories/unreviewed/2024/04/GHSA-xqrq-q336-f78g/GHSA-xqrq-q336-f78g.json +++ b/advisories/unreviewed/2024/04/GHSA-xqrq-q336-f78g/GHSA-xqrq-q336-f78g.json @@ -7,12 +7,8 @@ "CVE-2024-26733" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narp: Prevent overflow in arp_req_get().\n\nsyzkaller reported an overflown write in arp_req_get(). [0]\n\nWhen ioctl(SIOCGARP) is issued, arp_req_get() looks up an neighbour\nentry and copies neigh->ha to struct arpreq.arp_ha.sa_data.\n\nThe arp_ha here is struct sockaddr, not struct sockaddr_storage, so\nthe sa_data buffer is just 14 bytes.\n\nIn the splat below, 2 bytes are overflown to the next int field,\narp_flags. We initialise the field just after the memcpy(), so it's\nnot a problem.\n\nHowever, when dev->addr_len is greater than 22 (e.g. MAX_ADDR_LEN),\narp_netmask is overwritten, which could be set as htonl(0xFFFFFFFFUL)\nin arp_ioctl() before calling arp_req_get().\n\nTo avoid the overflow, let's limit the max length of memcpy().\n\nNote that commit b5f0de6df6dc (\"net: dev: Convert sa_data to flexible\narray in struct sockaddr\") just silenced syzkaller.\n\n[0]:\nmemcpy: detected field-spanning write (size 16) of single field \"r->arp_ha.sa_data\" at net/ipv4/arp.c:1128 (size 14)\nWARNING: CPU: 0 PID: 144638 at net/ipv4/arp.c:1128 arp_req_get+0x411/0x4a0 net/ipv4/arp.c:1128\nModules linked in:\nCPU: 0 PID: 144638 Comm: syz-executor.4 Not tainted 6.1.74 #31\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.0-debian-1.16.0-5 04/01/2014\nRIP: 0010:arp_req_get+0x411/0x4a0 net/ipv4/arp.c:1128\nCode: fd ff ff e8 41 42 de fb b9 0e 00 00 00 4c 89 fe 48 c7 c2 20 6d ab 87 48 c7 c7 80 6d ab 87 c6 05 25 af 72 04 01 e8 5f 8d ad fb <0f> 0b e9 6c fd ff ff e8 13 42 de fb be 03 00 00 00 4c 89 e7 e8 a6\nRSP: 0018:ffffc900050b7998 EFLAGS: 00010286\nRAX: 0000000000000000 RBX: ffff88803a815000 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: ffffffff8641a44a RDI: 0000000000000001\nRBP: ffffc900050b7a98 R08: 0000000000000001 R09: 0000000000000000\nR10: 0000000000000000 R11: 203a7970636d656d R12: ffff888039c54000\nR13: 1ffff92000a16f37 R14: ffff88803a815084 R15: 0000000000000010\nFS: 00007f172bf306c0(0000) GS:ffff88805aa00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f172b3569f0 CR3: 0000000057f12005 CR4: 0000000000770ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \n arp_ioctl+0x33f/0x4b0 net/ipv4/arp.c:1261\n inet_ioctl+0x314/0x3a0 net/ipv4/af_inet.c:981\n sock_do_ioctl+0xdf/0x260 net/socket.c:1204\n sock_ioctl+0x3ef/0x650 net/socket.c:1321\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:870 [inline]\n __se_sys_ioctl fs/ioctl.c:856 [inline]\n __x64_sys_ioctl+0x18e/0x220 fs/ioctl.c:856\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x37/0x90 arch/x86/entry/common.c:81\n entry_SYSCALL_64_after_hwframe+0x64/0xce\nRIP: 0033:0x7f172b262b8d\nCode: 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f172bf300b8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\nRAX: ffffffffffffffda RBX: 00007f172b3abf80 RCX: 00007f172b262b8d\nRDX: 0000000020000000 RSI: 0000000000008954 RDI: 0000000000000003\nRBP: 00007f172b2d3493 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 000000000000000b R14: 00007f172b3abf80 R15: 00007f172bf10000\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-xqvp-j58f-pjf5/GHSA-xqvp-j58f-pjf5.json b/advisories/unreviewed/2024/04/GHSA-xqvp-j58f-pjf5/GHSA-xqvp-j58f-pjf5.json index 90908ac1bd0..cd8d94a24c2 100644 --- a/advisories/unreviewed/2024/04/GHSA-xqvp-j58f-pjf5/GHSA-xqvp-j58f-pjf5.json +++ b/advisories/unreviewed/2024/04/GHSA-xqvp-j58f-pjf5/GHSA-xqvp-j58f-pjf5.json @@ -7,12 +7,8 @@ "CVE-2024-26872" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/srpt: Do not register event handler until srpt device is fully setup\n\nUpon rare occasions, KASAN reports a use-after-free Write\nin srpt_refresh_port().\n\nThis seems to be because an event handler is registered before the\nsrpt device is fully setup and a race condition upon error may leave a\npartially setup event handler in place.\n\nInstead, only register the event handler after srpt device initialization\nis complete.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-xvjp-2q6g-h878/GHSA-xvjp-2q6g-h878.json b/advisories/unreviewed/2024/04/GHSA-xvjp-2q6g-h878/GHSA-xvjp-2q6g-h878.json index 91ad7fd1521..57ec38661d9 100644 --- a/advisories/unreviewed/2024/04/GHSA-xvjp-2q6g-h878/GHSA-xvjp-2q6g-h878.json +++ b/advisories/unreviewed/2024/04/GHSA-xvjp-2q6g-h878/GHSA-xvjp-2q6g-h878.json @@ -7,12 +7,8 @@ "CVE-2024-26763" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-crypt: don't modify the data when using authenticated encryption\n\nIt was said that authenticated encryption could produce invalid tag when\nthe data that is being encrypted is modified [1]. So, fix this problem by\ncopying the data into the clone bio first and then encrypt them inside the\nclone bio.\n\nThis may reduce performance, but it is needed to prevent the user from\ncorrupting the device by writing data with O_DIRECT and modifying them at\nthe same time.\n\n[1] https://lore.kernel.org/all/20240207004723.GA35324@sol.localdomain/T/", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-2cf6-4ffg-wwcf/GHSA-2cf6-4ffg-wwcf.json b/advisories/unreviewed/2024/05/GHSA-2cf6-4ffg-wwcf/GHSA-2cf6-4ffg-wwcf.json index 9587610bbf8..f2b49b6b7da 100644 --- a/advisories/unreviewed/2024/05/GHSA-2cf6-4ffg-wwcf/GHSA-2cf6-4ffg-wwcf.json +++ b/advisories/unreviewed/2024/05/GHSA-2cf6-4ffg-wwcf/GHSA-2cf6-4ffg-wwcf.json @@ -7,12 +7,8 @@ "CVE-2021-47395" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmac80211: limit injected vht mcs/nss in ieee80211_parse_tx_radiotap\n\nLimit max values for vht mcs and nss in ieee80211_parse_tx_radiotap\nroutine in order to fix the following warning reported by syzbot:\n\nWARNING: CPU: 0 PID: 10717 at include/net/mac80211.h:989 ieee80211_rate_set_vht include/net/mac80211.h:989 [inline]\nWARNING: CPU: 0 PID: 10717 at include/net/mac80211.h:989 ieee80211_parse_tx_radiotap+0x101e/0x12d0 net/mac80211/tx.c:2244\nModules linked in:\nCPU: 0 PID: 10717 Comm: syz-executor.5 Not tainted 5.14.0-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\nRIP: 0010:ieee80211_rate_set_vht include/net/mac80211.h:989 [inline]\nRIP: 0010:ieee80211_parse_tx_radiotap+0x101e/0x12d0 net/mac80211/tx.c:2244\nRSP: 0018:ffffc9000186f3e8 EFLAGS: 00010216\nRAX: 0000000000000618 RBX: ffff88804ef76500 RCX: ffffc900143a5000\nRDX: 0000000000040000 RSI: ffffffff888f478e RDI: 0000000000000003\nRBP: 00000000ffffffff R08: 0000000000000000 R09: 0000000000000100\nR10: ffffffff888f46f9 R11: 0000000000000000 R12: 00000000fffffff8\nR13: ffff88804ef7653c R14: 0000000000000001 R15: 0000000000000004\nFS: 00007fbf5718f700(0000) GS:ffff8880b9c00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000001b2de23000 CR3: 000000006a671000 CR4: 00000000001506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000600\nCall Trace:\n ieee80211_monitor_select_queue+0xa6/0x250 net/mac80211/iface.c:740\n netdev_core_pick_tx+0x169/0x2e0 net/core/dev.c:4089\n __dev_queue_xmit+0x6f9/0x3710 net/core/dev.c:4165\n __bpf_tx_skb net/core/filter.c:2114 [inline]\n __bpf_redirect_no_mac net/core/filter.c:2139 [inline]\n __bpf_redirect+0x5ba/0xd20 net/core/filter.c:2162\n ____bpf_clone_redirect net/core/filter.c:2429 [inline]\n bpf_clone_redirect+0x2ae/0x420 net/core/filter.c:2401\n bpf_prog_eeb6f53a69e5c6a2+0x59/0x234\n bpf_dispatcher_nop_func include/linux/bpf.h:717 [inline]\n __bpf_prog_run include/linux/filter.h:624 [inline]\n bpf_prog_run include/linux/filter.h:631 [inline]\n bpf_test_run+0x381/0xa30 net/bpf/test_run.c:119\n bpf_prog_test_run_skb+0xb84/0x1ee0 net/bpf/test_run.c:663\n bpf_prog_test_run kernel/bpf/syscall.c:3307 [inline]\n __sys_bpf+0x2137/0x5df0 kernel/bpf/syscall.c:4605\n __do_sys_bpf kernel/bpf/syscall.c:4691 [inline]\n __se_sys_bpf kernel/bpf/syscall.c:4689 [inline]\n __x64_sys_bpf+0x75/0xb0 kernel/bpf/syscall.c:4689\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\nRIP: 0033:0x4665f9", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-2fxm-8374-c95m/GHSA-2fxm-8374-c95m.json b/advisories/unreviewed/2024/05/GHSA-2fxm-8374-c95m/GHSA-2fxm-8374-c95m.json index 6fba08fee65..12b3655afdc 100644 --- a/advisories/unreviewed/2024/05/GHSA-2fxm-8374-c95m/GHSA-2fxm-8374-c95m.json +++ b/advisories/unreviewed/2024/05/GHSA-2fxm-8374-c95m/GHSA-2fxm-8374-c95m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-2gxx-2hcr-3whr/GHSA-2gxx-2hcr-3whr.json b/advisories/unreviewed/2024/05/GHSA-2gxx-2hcr-3whr/GHSA-2gxx-2hcr-3whr.json index cefd318a805..ce09eb5767f 100644 --- a/advisories/unreviewed/2024/05/GHSA-2gxx-2hcr-3whr/GHSA-2gxx-2hcr-3whr.json +++ b/advisories/unreviewed/2024/05/GHSA-2gxx-2hcr-3whr/GHSA-2gxx-2hcr-3whr.json @@ -7,12 +7,8 @@ "CVE-2024-26965" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: qcom: mmcc-msm8974: fix terminating of frequency table arrays\n\nThe frequency table arrays are supposed to be terminated with an\nempty element. Add such entry to the end of the arrays where it\nis missing in order to avoid possible out-of-bound access when\nthe table is traversed by functions like qcom_find_freq() or\nqcom_find_freq_floor().\n\nOnly compile tested.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-2j3v-48pv-mvcj/GHSA-2j3v-48pv-mvcj.json b/advisories/unreviewed/2024/05/GHSA-2j3v-48pv-mvcj/GHSA-2j3v-48pv-mvcj.json index 8eb55511edb..f9e86fc53b8 100644 --- a/advisories/unreviewed/2024/05/GHSA-2j3v-48pv-mvcj/GHSA-2j3v-48pv-mvcj.json +++ b/advisories/unreviewed/2024/05/GHSA-2j3v-48pv-mvcj/GHSA-2j3v-48pv-mvcj.json @@ -7,12 +7,8 @@ "CVE-2023-52774" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: protect device queue against concurrent access\n\nIn dasd_profile_start() the amount of requests on the device queue are\ncounted. The access to the device queue is unprotected against\nconcurrent access. With a lot of parallel I/O, especially with alias\ndevices enabled, the device queue can change while dasd_profile_start()\nis accessing the queue. In the worst case this leads to a kernel panic\ndue to incorrect pointer accesses.\n\nFix this by taking the device lock before accessing the queue and\ncounting the requests. Additionally the check for a valid profile data\npointer can be done earlier to avoid unnecessary locking in a hot path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-2pp7-rwqg-2gcx/GHSA-2pp7-rwqg-2gcx.json b/advisories/unreviewed/2024/05/GHSA-2pp7-rwqg-2gcx/GHSA-2pp7-rwqg-2gcx.json index b2e1636cd22..db6aec2dbe5 100644 --- a/advisories/unreviewed/2024/05/GHSA-2pp7-rwqg-2gcx/GHSA-2pp7-rwqg-2gcx.json +++ b/advisories/unreviewed/2024/05/GHSA-2pp7-rwqg-2gcx/GHSA-2pp7-rwqg-2gcx.json @@ -7,12 +7,8 @@ "CVE-2021-47409" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc2: check return value after calling platform_get_resource()\n\nIt will cause null-ptr-deref if platform_get_resource() returns NULL,\nwe need check the return value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-2wxq-wgqp-xrwm/GHSA-2wxq-wgqp-xrwm.json b/advisories/unreviewed/2024/05/GHSA-2wxq-wgqp-xrwm/GHSA-2wxq-wgqp-xrwm.json index a182c409e2d..abe3e6a8f37 100644 --- a/advisories/unreviewed/2024/05/GHSA-2wxq-wgqp-xrwm/GHSA-2wxq-wgqp-xrwm.json +++ b/advisories/unreviewed/2024/05/GHSA-2wxq-wgqp-xrwm/GHSA-2wxq-wgqp-xrwm.json @@ -7,12 +7,8 @@ "CVE-2023-52816" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Fix shift out-of-bounds issue\n\n[ 567.613292] shift exponent 255 is too large for 64-bit type 'long unsigned int'\n[ 567.614498] CPU: 5 PID: 238 Comm: kworker/5:1 Tainted: G OE 6.2.0-34-generic #34~22.04.1-Ubuntu\n[ 567.614502] Hardware name: AMD Splinter/Splinter-RPL, BIOS WS43927N_871 09/25/2023\n[ 567.614504] Workqueue: events send_exception_work_handler [amdgpu]\n[ 567.614748] Call Trace:\n[ 567.614750] \n[ 567.614753] dump_stack_lvl+0x48/0x70\n[ 567.614761] dump_stack+0x10/0x20\n[ 567.614763] __ubsan_handle_shift_out_of_bounds+0x156/0x310\n[ 567.614769] ? srso_alias_return_thunk+0x5/0x7f\n[ 567.614773] ? update_sd_lb_stats.constprop.0+0xf2/0x3c0\n[ 567.614780] svm_range_split_by_granularity.cold+0x2b/0x34 [amdgpu]\n[ 567.615047] ? srso_alias_return_thunk+0x5/0x7f\n[ 567.615052] svm_migrate_to_ram+0x185/0x4d0 [amdgpu]\n[ 567.615286] do_swap_page+0x7b6/0xa30\n[ 567.615291] ? srso_alias_return_thunk+0x5/0x7f\n[ 567.615294] ? __free_pages+0x119/0x130\n[ 567.615299] handle_pte_fault+0x227/0x280\n[ 567.615303] __handle_mm_fault+0x3c0/0x720\n[ 567.615311] handle_mm_fault+0x119/0x330\n[ 567.615314] ? lock_mm_and_find_vma+0x44/0x250\n[ 567.615318] do_user_addr_fault+0x1a9/0x640\n[ 567.615323] exc_page_fault+0x81/0x1b0\n[ 567.615328] asm_exc_page_fault+0x27/0x30\n[ 567.615332] RIP: 0010:__get_user_8+0x1c/0x30", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-2x59-7x95-wr65/GHSA-2x59-7x95-wr65.json b/advisories/unreviewed/2024/05/GHSA-2x59-7x95-wr65/GHSA-2x59-7x95-wr65.json index f55cbf8c080..90742995f9e 100644 --- a/advisories/unreviewed/2024/05/GHSA-2x59-7x95-wr65/GHSA-2x59-7x95-wr65.json +++ b/advisories/unreviewed/2024/05/GHSA-2x59-7x95-wr65/GHSA-2x59-7x95-wr65.json @@ -7,12 +7,8 @@ "CVE-2024-26931" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix command flush on cable pull\n\nSystem crash due to command failed to flush back to SCSI layer.\n\n BUG: unable to handle kernel NULL pointer dereference at 0000000000000000\n PGD 0 P4D 0\n Oops: 0000 [#1] SMP NOPTI\n CPU: 27 PID: 793455 Comm: kworker/u130:6 Kdump: loaded Tainted: G OE --------- - - 4.18.0-372.9.1.el8.x86_64 #1\n Hardware name: HPE ProLiant DL360 Gen10/ProLiant DL360 Gen10, BIOS U32 09/03/2021\n Workqueue: nvme-wq nvme_fc_connect_ctrl_work [nvme_fc]\n RIP: 0010:__wake_up_common+0x4c/0x190\n Code: 24 10 4d 85 c9 74 0a 41 f6 01 04 0f 85 9d 00 00 00 48 8b 43 08 48 83 c3 08 4c 8d 48 e8 49 8d 41 18 48 39 c3 0f 84 f0 00 00 00 <49> 8b 41 18 89 54 24 08 31 ed 4c 8d 70 e8 45 8b 29 41 f6 c5 04 75\n RSP: 0018:ffff95f3e0cb7cd0 EFLAGS: 00010086\n RAX: 0000000000000000 RBX: ffff8b08d3b26328 RCX: 0000000000000000\n RDX: 0000000000000001 RSI: 0000000000000003 RDI: ffff8b08d3b26320\n RBP: 0000000000000001 R08: 0000000000000000 R09: ffffffffffffffe8\n R10: 0000000000000000 R11: ffff95f3e0cb7a60 R12: ffff95f3e0cb7d20\n R13: 0000000000000003 R14: 0000000000000000 R15: 0000000000000000\n FS: 0000000000000000(0000) GS:ffff8b2fdf6c0000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000000 CR3: 0000002f1e410002 CR4: 00000000007706e0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n __wake_up_common_lock+0x7c/0xc0\n qla_nvme_ls_req+0x355/0x4c0 [qla2xxx]\n qla2xxx [0000:12:00.1]-f084:3: qlt_free_session_done: se_sess 0000000000000000 / sess ffff8ae1407ca000 from port 21:32:00:02:ac:07:ee:b8 loop_id 0x02 s_id 01:02:00 logout 1 keep 0 els_logo 0\n ? __nvme_fc_send_ls_req+0x260/0x380 [nvme_fc]\n qla2xxx [0000:12:00.1]-207d:3: FCPort 21:32:00:02:ac:07:ee:b8 state transitioned from ONLINE to LOST - portid=010200.\n ? nvme_fc_send_ls_req.constprop.42+0x1a/0x45 [nvme_fc]\n qla2xxx [0000:12:00.1]-2109:3: qla2x00_schedule_rport_del 21320002ac07eeb8. rport ffff8ae598122000 roles 1\n ? nvme_fc_connect_ctrl_work.cold.63+0x1e3/0xa7d [nvme_fc]\n qla2xxx [0000:12:00.1]-f084:3: qlt_free_session_done: se_sess 0000000000000000 / sess ffff8ae14801e000 from port 21:32:01:02:ad:f7:ee:b8 loop_id 0x04 s_id 01:02:01 logout 1 keep 0 els_logo 0\n ? __switch_to+0x10c/0x450\n ? process_one_work+0x1a7/0x360\n qla2xxx [0000:12:00.1]-207d:3: FCPort 21:32:01:02:ad:f7:ee:b8 state transitioned from ONLINE to LOST - portid=010201.\n ? worker_thread+0x1ce/0x390\n ? create_worker+0x1a0/0x1a0\n qla2xxx [0000:12:00.1]-2109:3: qla2x00_schedule_rport_del 21320102adf7eeb8. rport ffff8ae3b2312800 roles 70\n ? kthread+0x10a/0x120\n qla2xxx [0000:12:00.1]-2112:3: qla_nvme_unregister_remote_port: unregister remoteport on ffff8ae14801e000 21320102adf7eeb8\n ? set_kthread_struct+0x40/0x40\n qla2xxx [0000:12:00.1]-2110:3: remoteport_delete of ffff8ae14801e000 21320102adf7eeb8 completed.\n ? ret_from_fork+0x1f/0x40\n qla2xxx [0000:12:00.1]-f086:3: qlt_free_session_done: waiting for sess ffff8ae14801e000 logout\n\nThe system was under memory stress where driver was not able to allocate an\nSRB to carry out error recovery of cable pull. The failure to flush causes\nupper layer to start modifying scsi_cmnd. When the system frees up some\nmemory, the subsequent cable pull trigger another command flush. At this\npoint the driver access a null pointer when attempting to DMA unmap the\nSGL.\n\nAdd a check to make sure commands are flush back on session tear down to\nprevent the null pointer access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-2xv3-4xmw-7ff2/GHSA-2xv3-4xmw-7ff2.json b/advisories/unreviewed/2024/05/GHSA-2xv3-4xmw-7ff2/GHSA-2xv3-4xmw-7ff2.json index 4d74e138cca..b3632e6f66c 100644 --- a/advisories/unreviewed/2024/05/GHSA-2xv3-4xmw-7ff2/GHSA-2xv3-4xmw-7ff2.json +++ b/advisories/unreviewed/2024/05/GHSA-2xv3-4xmw-7ff2/GHSA-2xv3-4xmw-7ff2.json @@ -7,12 +7,8 @@ "CVE-2023-52787" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-mq: make sure active queue usage is held for bio_integrity_prep()\n\nblk_integrity_unregister() can come if queue usage counter isn't held\nfor one bio with integrity prepared, so this request may be completed with\ncalling profile->complete_fn, then kernel panic.\n\nAnother constraint is that bio_integrity_prep() needs to be called\nbefore bio merge.\n\nFix the issue by:\n\n- call bio_integrity_prep() with one queue usage counter grabbed reliably\n\n- call bio_integrity_prep() before bio merge", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3cff-7cgm-mf7g/GHSA-3cff-7cgm-mf7g.json b/advisories/unreviewed/2024/05/GHSA-3cff-7cgm-mf7g/GHSA-3cff-7cgm-mf7g.json index 8ee3d250bb0..c158be37583 100644 --- a/advisories/unreviewed/2024/05/GHSA-3cff-7cgm-mf7g/GHSA-3cff-7cgm-mf7g.json +++ b/advisories/unreviewed/2024/05/GHSA-3cff-7cgm-mf7g/GHSA-3cff-7cgm-mf7g.json @@ -7,12 +7,8 @@ "CVE-2024-27024" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/rds: fix WARNING in rds_conn_connect_if_down\n\nIf connection isn't established yet, get_mr() will fail, trigger connection after\nget_mr().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3p2h-8x46-gvg6/GHSA-3p2h-8x46-gvg6.json b/advisories/unreviewed/2024/05/GHSA-3p2h-8x46-gvg6/GHSA-3p2h-8x46-gvg6.json index 331200a8a36..9ae983c3c43 100644 --- a/advisories/unreviewed/2024/05/GHSA-3p2h-8x46-gvg6/GHSA-3p2h-8x46-gvg6.json +++ b/advisories/unreviewed/2024/05/GHSA-3p2h-8x46-gvg6/GHSA-3p2h-8x46-gvg6.json @@ -7,12 +7,8 @@ "CVE-2024-27399" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout\n\nThere is a race condition between l2cap_chan_timeout() and\nl2cap_chan_del(). When we use l2cap_chan_del() to delete the\nchannel, the chan->conn will be set to null. But the conn could\nbe dereferenced again in the mutex_lock() of l2cap_chan_timeout().\nAs a result the null pointer dereference bug will happen. The\nKASAN report triggered by POC is shown below:\n\n[ 472.074580] ==================================================================\n[ 472.075284] BUG: KASAN: null-ptr-deref in mutex_lock+0x68/0xc0\n[ 472.075308] Write of size 8 at addr 0000000000000158 by task kworker/0:0/7\n[ 472.075308]\n[ 472.075308] CPU: 0 PID: 7 Comm: kworker/0:0 Not tainted 6.9.0-rc5-00356-g78c0094a146b #36\n[ 472.075308] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu4\n[ 472.075308] Workqueue: events l2cap_chan_timeout\n[ 472.075308] Call Trace:\n[ 472.075308] \n[ 472.075308] dump_stack_lvl+0x137/0x1a0\n[ 472.075308] print_report+0x101/0x250\n[ 472.075308] ? __virt_addr_valid+0x77/0x160\n[ 472.075308] ? mutex_lock+0x68/0xc0\n[ 472.075308] kasan_report+0x139/0x170\n[ 472.075308] ? mutex_lock+0x68/0xc0\n[ 472.075308] kasan_check_range+0x2c3/0x2e0\n[ 472.075308] mutex_lock+0x68/0xc0\n[ 472.075308] l2cap_chan_timeout+0x181/0x300\n[ 472.075308] process_one_work+0x5d2/0xe00\n[ 472.075308] worker_thread+0xe1d/0x1660\n[ 472.075308] ? pr_cont_work+0x5e0/0x5e0\n[ 472.075308] kthread+0x2b7/0x350\n[ 472.075308] ? pr_cont_work+0x5e0/0x5e0\n[ 472.075308] ? kthread_blkcg+0xd0/0xd0\n[ 472.075308] ret_from_fork+0x4d/0x80\n[ 472.075308] ? kthread_blkcg+0xd0/0xd0\n[ 472.075308] ret_from_fork_asm+0x11/0x20\n[ 472.075308] \n[ 472.075308] ==================================================================\n[ 472.094860] Disabling lock debugging due to kernel taint\n[ 472.096136] BUG: kernel NULL pointer dereference, address: 0000000000000158\n[ 472.096136] #PF: supervisor write access in kernel mode\n[ 472.096136] #PF: error_code(0x0002) - not-present page\n[ 472.096136] PGD 0 P4D 0\n[ 472.096136] Oops: 0002 [#1] PREEMPT SMP KASAN NOPTI\n[ 472.096136] CPU: 0 PID: 7 Comm: kworker/0:0 Tainted: G B 6.9.0-rc5-00356-g78c0094a146b #36\n[ 472.096136] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu4\n[ 472.096136] Workqueue: events l2cap_chan_timeout\n[ 472.096136] RIP: 0010:mutex_lock+0x88/0xc0\n[ 472.096136] Code: be 08 00 00 00 e8 f8 23 1f fd 4c 89 f7 be 08 00 00 00 e8 eb 23 1f fd 42 80 3c 23 00 74 08 48 88\n[ 472.096136] RSP: 0018:ffff88800744fc78 EFLAGS: 00000246\n[ 472.096136] RAX: 0000000000000000 RBX: 1ffff11000e89f8f RCX: ffffffff8457c865\n[ 472.096136] RDX: 0000000000000001 RSI: 0000000000000008 RDI: ffff88800744fc78\n[ 472.096136] RBP: 0000000000000158 R08: ffff88800744fc7f R09: 1ffff11000e89f8f\n[ 472.096136] R10: dffffc0000000000 R11: ffffed1000e89f90 R12: dffffc0000000000\n[ 472.096136] R13: 0000000000000158 R14: ffff88800744fc78 R15: ffff888007405a00\n[ 472.096136] FS: 0000000000000000(0000) GS:ffff88806d200000(0000) knlGS:0000000000000000\n[ 472.096136] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 472.096136] CR2: 0000000000000158 CR3: 000000000da32000 CR4: 00000000000006f0\n[ 472.096136] Call Trace:\n[ 472.096136] \n[ 472.096136] ? __die_body+0x8d/0xe0\n[ 472.096136] ? page_fault_oops+0x6b8/0x9a0\n[ 472.096136] ? kernelmode_fixup_or_oops+0x20c/0x2a0\n[ 472.096136] ? do_user_addr_fault+0x1027/0x1340\n[ 472.096136] ? _printk+0x7a/0xa0\n[ 472.096136] ? mutex_lock+0x68/0xc0\n[ 472.096136] ? add_taint+0x42/0xd0\n[ 472.096136] ? exc_page_fault+0x6a/0x1b0\n[ 472.096136] ? asm_exc_page_fault+0x26/0x30\n[ 472.096136] ? mutex_lock+0x75/0xc0\n[ 472.096136] ? mutex_lock+0x88/0xc0\n[ 472.096136] ? mutex_lock+0x75/0xc0\n[ 472.096136] l2cap_chan_timeo\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3pwm-r3r4-xpvf/GHSA-3pwm-r3r4-xpvf.json b/advisories/unreviewed/2024/05/GHSA-3pwm-r3r4-xpvf/GHSA-3pwm-r3r4-xpvf.json index 5d4775b02ce..a5439171178 100644 --- a/advisories/unreviewed/2024/05/GHSA-3pwm-r3r4-xpvf/GHSA-3pwm-r3r4-xpvf.json +++ b/advisories/unreviewed/2024/05/GHSA-3pwm-r3r4-xpvf/GHSA-3pwm-r3r4-xpvf.json @@ -7,12 +7,8 @@ "CVE-2023-52781" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: config: fix iteration issue in 'usb_get_bos_descriptor()'\n\nThe BOS descriptor defines a root descriptor and is the base descriptor for\naccessing a family of related descriptors.\n\nFunction 'usb_get_bos_descriptor()' encounters an iteration issue when\nskipping the 'USB_DT_DEVICE_CAPABILITY' descriptor type. This results in\nthe same descriptor being read repeatedly.\n\nTo address this issue, a 'goto' statement is introduced to ensure that the\npointer and the amount read is updated correctly. This ensures that the\nfunction iterates to the next descriptor instead of reading the same\ndescriptor repeatedly.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3qr9-g9f2-22xh/GHSA-3qr9-g9f2-22xh.json b/advisories/unreviewed/2024/05/GHSA-3qr9-g9f2-22xh/GHSA-3qr9-g9f2-22xh.json index 3e2d196ee58..1d4edea45a5 100644 --- a/advisories/unreviewed/2024/05/GHSA-3qr9-g9f2-22xh/GHSA-3qr9-g9f2-22xh.json +++ b/advisories/unreviewed/2024/05/GHSA-3qr9-g9f2-22xh/GHSA-3qr9-g9f2-22xh.json @@ -7,12 +7,8 @@ "CVE-2023-52856" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/bridge: lt8912b: Fix crash on bridge detach\n\nThe lt8912b driver, in its bridge detach function, calls\ndrm_connector_unregister() and drm_connector_cleanup().\n\ndrm_connector_unregister() should be called only for connectors\nexplicitly registered with drm_connector_register(), which is not the\ncase in lt8912b.\n\nThe driver's drm_connector_funcs.destroy hook is set to\ndrm_connector_cleanup().\n\nThus the driver should not call either drm_connector_unregister() nor\ndrm_connector_cleanup() in its lt8912_bridge_detach(), as they cause a\ncrash on bridge detach:\n\nUnable to handle kernel NULL pointer dereference at virtual address 0000000000000000\nMem abort info:\n ESR = 0x0000000096000006\n EC = 0x25: DABT (current EL), IL = 32 bits\n SET = 0, FnV = 0\n EA = 0, S1PTW = 0\n FSC = 0x06: level 2 translation fault\nData abort info:\n ISV = 0, ISS = 0x00000006, ISS2 = 0x00000000\n CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\nuser pgtable: 4k pages, 48-bit VAs, pgdp=00000000858f3000\n[0000000000000000] pgd=0800000085918003, p4d=0800000085918003, pud=0800000085431003, pmd=0000000000000000\nInternal error: Oops: 0000000096000006 [#1] PREEMPT SMP\nModules linked in: tidss(-) display_connector lontium_lt8912b tc358768 panel_lvds panel_simple drm_dma_helper drm_kms_helper drm drm_panel_orientation_quirks\nCPU: 3 PID: 462 Comm: rmmod Tainted: G W 6.5.0-rc2+ #2\nHardware name: Toradex Verdin AM62 on Verdin Development Board (DT)\npstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : drm_connector_cleanup+0x78/0x2d4 [drm]\nlr : lt8912_bridge_detach+0x54/0x6c [lontium_lt8912b]\nsp : ffff800082ed3a90\nx29: ffff800082ed3a90 x28: ffff0000040c1940 x27: 0000000000000000\nx26: 0000000000000000 x25: dead000000000122 x24: dead000000000122\nx23: dead000000000100 x22: ffff000003fb6388 x21: 0000000000000000\nx20: 0000000000000000 x19: ffff000003fb6260 x18: fffffffffffe56e8\nx17: 0000000000000000 x16: 0010000000000000 x15: 0000000000000038\nx14: 0000000000000000 x13: ffff800081914b48 x12: 000000000000040e\nx11: 000000000000015a x10: ffff80008196ebb8 x9 : ffff800081914b48\nx8 : 00000000ffffefff x7 : ffff0000040c1940 x6 : ffff80007aa649d0\nx5 : 0000000000000000 x4 : 0000000000000001 x3 : ffff80008159e008\nx2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000\nCall trace:\n drm_connector_cleanup+0x78/0x2d4 [drm]\n lt8912_bridge_detach+0x54/0x6c [lontium_lt8912b]\n drm_bridge_detach+0x44/0x84 [drm]\n drm_encoder_cleanup+0x40/0xb8 [drm]\n drmm_encoder_alloc_release+0x1c/0x30 [drm]\n drm_managed_release+0xac/0x148 [drm]\n drm_dev_put.part.0+0x88/0xb8 [drm]\n devm_drm_dev_init_release+0x14/0x24 [drm]\n devm_action_release+0x14/0x20\n release_nodes+0x5c/0x90\n devres_release_all+0x8c/0xe0\n device_unbind_cleanup+0x18/0x68\n device_release_driver_internal+0x208/0x23c\n driver_detach+0x4c/0x94\n bus_remove_driver+0x70/0xf4\n driver_unregister+0x30/0x60\n platform_driver_unregister+0x14/0x20\n tidss_platform_driver_exit+0x18/0xb2c [tidss]\n __arm64_sys_delete_module+0x1a0/0x2b4\n invoke_syscall+0x48/0x110\n el0_svc_common.constprop.0+0x60/0x10c\n do_el0_svc_compat+0x1c/0x40\n el0_svc_compat+0x40/0xac\n el0t_32_sync_handler+0xb0/0x138\n el0t_32_sync+0x194/0x198\nCode: 9104a276 f2fbd5b7 aa0203e1 91008af8 (f85c0420)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3r4r-jmwh-rccm/GHSA-3r4r-jmwh-rccm.json b/advisories/unreviewed/2024/05/GHSA-3r4r-jmwh-rccm/GHSA-3r4r-jmwh-rccm.json index fb04aa2a07d..94ffae0501e 100644 --- a/advisories/unreviewed/2024/05/GHSA-3r4r-jmwh-rccm/GHSA-3r4r-jmwh-rccm.json +++ b/advisories/unreviewed/2024/05/GHSA-3r4r-jmwh-rccm/GHSA-3r4r-jmwh-rccm.json @@ -7,12 +7,8 @@ "CVE-2023-52797" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers: perf: Check find_first_bit() return value\n\nWe must check the return value of find_first_bit() before using the\nreturn value as an index array since it happens to overflow the array\nand then panic:\n\n[ 107.318430] Kernel BUG [#1]\n[ 107.319434] CPU: 3 PID: 1238 Comm: kill Tainted: G E 6.6.0-rc6ubuntu-defconfig #2\n[ 107.319465] Hardware name: riscv-virtio,qemu (DT)\n[ 107.319551] epc : pmu_sbi_ovf_handler+0x3a4/0x3ae\n[ 107.319840] ra : pmu_sbi_ovf_handler+0x52/0x3ae\n[ 107.319868] epc : ffffffff80a0a77c ra : ffffffff80a0a42a sp : ffffaf83fecda350\n[ 107.319884] gp : ffffffff823961a8 tp : ffffaf8083db1dc0 t0 : ffffaf83fecda480\n[ 107.319899] t1 : ffffffff80cafe62 t2 : 000000000000ff00 s0 : ffffaf83fecda520\n[ 107.319921] s1 : ffffaf83fecda380 a0 : 00000018fca29df0 a1 : ffffffffffffffff\n[ 107.319936] a2 : 0000000001073734 a3 : 0000000000000004 a4 : 0000000000000000\n[ 107.319951] a5 : 0000000000000040 a6 : 000000001d1c8774 a7 : 0000000000504d55\n[ 107.319965] s2 : ffffffff82451f10 s3 : ffffffff82724e70 s4 : 000000000000003f\n[ 107.319980] s5 : 0000000000000011 s6 : ffffaf8083db27c0 s7 : 0000000000000000\n[ 107.319995] s8 : 0000000000000001 s9 : 00007fffb45d6558 s10: 00007fffb45d81a0\n[ 107.320009] s11: ffffaf7ffff60000 t3 : 0000000000000004 t4 : 0000000000000000\n[ 107.320023] t5 : ffffaf7f80000000 t6 : ffffaf8000000000\n[ 107.320037] status: 0000000200000100 badaddr: 0000000000000000 cause: 0000000000000003\n[ 107.320081] [] pmu_sbi_ovf_handler+0x3a4/0x3ae\n[ 107.320112] [] handle_percpu_devid_irq+0x9e/0x1a0\n[ 107.320131] [] generic_handle_domain_irq+0x28/0x36\n[ 107.320148] [] riscv_intc_irq+0x36/0x4e\n[ 107.320166] [] handle_riscv_irq+0x54/0x86\n[ 107.320189] [] do_irq+0x64/0x96\n[ 107.320271] Code: 85a6 855e b097 ff7f 80e7 9220 b709 9002 4501 bbd9 (9002) 6097\n[ 107.320585] ---[ end trace 0000000000000000 ]---\n[ 107.320704] Kernel panic - not syncing: Fatal exception in interrupt\n[ 107.320775] SMP: stopping secondary CPUs\n[ 107.321219] Kernel Offset: 0x0 from 0xffffffff80000000\n[ 107.333051] ---[ end Kernel panic - not syncing: Fatal exception in interrupt ]---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-576q-7774-8vcq/GHSA-576q-7774-8vcq.json b/advisories/unreviewed/2024/05/GHSA-576q-7774-8vcq/GHSA-576q-7774-8vcq.json index 7524a965c23..4ae76cbe2b2 100644 --- a/advisories/unreviewed/2024/05/GHSA-576q-7774-8vcq/GHSA-576q-7774-8vcq.json +++ b/advisories/unreviewed/2024/05/GHSA-576q-7774-8vcq/GHSA-576q-7774-8vcq.json @@ -7,12 +7,8 @@ "CVE-2024-26937" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gt: Reset queue_priority_hint on parking\n\nOriginally, with strict in order execution, we could complete execution\nonly when the queue was empty. Preempt-to-busy allows replacement of an\nactive request that may complete before the preemption is processed by\nHW. If that happens, the request is retired from the queue, but the\nqueue_priority_hint remains set, preventing direct submission until\nafter the next CS interrupt is processed.\n\nThis preempt-to-busy race can be triggered by the heartbeat, which will\nalso act as the power-management barrier and upon completion allow us to\nidle the HW. We may process the completion of the heartbeat, and begin\nparking the engine before the CS event that restores the\nqueue_priority_hint, causing us to fail the assertion that it is MIN.\n\n<3>[ 166.210729] __engine_park:283 GEM_BUG_ON(engine->sched_engine->queue_priority_hint != (-((int)(~0U >> 1)) - 1))\n<0>[ 166.210781] Dumping ftrace buffer:\n<0>[ 166.210795] ---------------------------------\n...\n<0>[ 167.302811] drm_fdin-1097 2..s1. 165741070us : trace_ports: 0000:00:02.0 rcs0: promote { ccid:20 1217:2 prio 0 }\n<0>[ 167.302861] drm_fdin-1097 2d.s2. 165741072us : execlists_submission_tasklet: 0000:00:02.0 rcs0: preempting last=1217:2, prio=0, hint=2147483646\n<0>[ 167.302928] drm_fdin-1097 2d.s2. 165741072us : __i915_request_unsubmit: 0000:00:02.0 rcs0: fence 1217:2, current 0\n<0>[ 167.302992] drm_fdin-1097 2d.s2. 165741073us : __i915_request_submit: 0000:00:02.0 rcs0: fence 3:4660, current 4659\n<0>[ 167.303044] drm_fdin-1097 2d.s1. 165741076us : execlists_submission_tasklet: 0000:00:02.0 rcs0: context:3 schedule-in, ccid:40\n<0>[ 167.303095] drm_fdin-1097 2d.s1. 165741077us : trace_ports: 0000:00:02.0 rcs0: submit { ccid:40 3:4660* prio 2147483646 }\n<0>[ 167.303159] kworker/-89 11..... 165741139us : i915_request_retire.part.0: 0000:00:02.0 rcs0: fence c90:2, current 2\n<0>[ 167.303208] kworker/-89 11..... 165741148us : __intel_context_do_unpin: 0000:00:02.0 rcs0: context:c90 unpin\n<0>[ 167.303272] kworker/-89 11..... 165741159us : i915_request_retire.part.0: 0000:00:02.0 rcs0: fence 1217:2, current 2\n<0>[ 167.303321] kworker/-89 11..... 165741166us : __intel_context_do_unpin: 0000:00:02.0 rcs0: context:1217 unpin\n<0>[ 167.303384] kworker/-89 11..... 165741170us : i915_request_retire.part.0: 0000:00:02.0 rcs0: fence 3:4660, current 4660\n<0>[ 167.303434] kworker/-89 11d..1. 165741172us : __intel_context_retire: 0000:00:02.0 rcs0: context:1216 retire runtime: { total:56028ns, avg:56028ns }\n<0>[ 167.303484] kworker/-89 11..... 165741198us : __engine_park: 0000:00:02.0 rcs0: parked\n<0>[ 167.303534] -0 5d.H3. 165741207us : execlists_irq_handler: 0000:00:02.0 rcs0: semaphore yield: 00000040\n<0>[ 167.303583] kworker/-89 11..... 165741397us : __intel_context_retire: 0000:00:02.0 rcs0: context:1217 retire runtime: { total:325575ns, avg:0ns }\n<0>[ 167.303756] kworker/-89 11..... 165741777us : __intel_context_retire: 0000:00:02.0 rcs0: context:c90 retire runtime: { total:0ns, avg:0ns }\n<0>[ 167.303806] kworker/-89 11..... 165742017us : __engine_park: __engine_park:283 GEM_BUG_ON(engine->sched_engine->queue_priority_hint != (-((int)(~0U >> 1)) - 1))\n<0>[ 167.303811] ---------------------------------\n<4>[ 167.304722] ------------[ cut here ]------------\n<2>[ 167.304725] kernel BUG at drivers/gpu/drm/i915/gt/intel_engine_pm.c:283!\n<4>[ 167.304731] invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\n<4>[ 167.304734] CPU: 11 PID: 89 Comm: kworker/11:1 Tainted: G W 6.8.0-rc2-CI_DRM_14193-gc655e0fd2804+ #1\n<4>[ 167.304736] Hardware name: Intel Corporation Rocket Lake Client Platform/RocketLake S UDIMM 6L RVP, BIOS RKLSFWI1.R00.3173.A03.2204210138 04/21/2022\n<4>[ 167.304738] Workqueue: i915-unordered retire_work_handler [i915]\n<4>[ 16\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-58c4-h2gx-8qfv/GHSA-58c4-h2gx-8qfv.json b/advisories/unreviewed/2024/05/GHSA-58c4-h2gx-8qfv/GHSA-58c4-h2gx-8qfv.json index f6450591b0f..41ed3dffb08 100644 --- a/advisories/unreviewed/2024/05/GHSA-58c4-h2gx-8qfv/GHSA-58c4-h2gx-8qfv.json +++ b/advisories/unreviewed/2024/05/GHSA-58c4-h2gx-8qfv/GHSA-58c4-h2gx-8qfv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-5h68-7cjq-vgrx/GHSA-5h68-7cjq-vgrx.json b/advisories/unreviewed/2024/05/GHSA-5h68-7cjq-vgrx/GHSA-5h68-7cjq-vgrx.json index 535131f9b9d..74430215cc4 100644 --- a/advisories/unreviewed/2024/05/GHSA-5h68-7cjq-vgrx/GHSA-5h68-7cjq-vgrx.json +++ b/advisories/unreviewed/2024/05/GHSA-5h68-7cjq-vgrx/GHSA-5h68-7cjq-vgrx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-5hhv-hrg6-cwc7/GHSA-5hhv-hrg6-cwc7.json b/advisories/unreviewed/2024/05/GHSA-5hhv-hrg6-cwc7/GHSA-5hhv-hrg6-cwc7.json index 5d7ba8132ae..e060c37a0ae 100644 --- a/advisories/unreviewed/2024/05/GHSA-5hhv-hrg6-cwc7/GHSA-5hhv-hrg6-cwc7.json +++ b/advisories/unreviewed/2024/05/GHSA-5hhv-hrg6-cwc7/GHSA-5hhv-hrg6-cwc7.json @@ -7,12 +7,8 @@ "CVE-2024-27008" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: nv04: Fix out of bounds access\n\nWhen Output Resource (dcb->or) value is assigned in\nfabricate_dcb_output(), there may be out of bounds access to\ndac_users array in case dcb->or is zero because ffs(dcb->or) is\nused as index there.\nThe 'or' argument of fabricate_dcb_output() must be interpreted as a\nnumber of bit to set, not value.\n\nUtilize macros from 'enum nouveau_or' in calls instead of hardcoding.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-5jrf-78p7-hw2r/GHSA-5jrf-78p7-hw2r.json b/advisories/unreviewed/2024/05/GHSA-5jrf-78p7-hw2r/GHSA-5jrf-78p7-hw2r.json index 30a208dd836..2f5c470d930 100644 --- a/advisories/unreviewed/2024/05/GHSA-5jrf-78p7-hw2r/GHSA-5jrf-78p7-hw2r.json +++ b/advisories/unreviewed/2024/05/GHSA-5jrf-78p7-hw2r/GHSA-5jrf-78p7-hw2r.json @@ -7,12 +7,8 @@ "CVE-2023-52851" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/mlx5: Fix init stage error handling to avoid double free of same QP and UAF\n\nIn the unlikely event that workqueue allocation fails and returns NULL in\nmlx5_mkey_cache_init(), delete the call to\nmlx5r_umr_resource_cleanup() (which frees the QP) in\nmlx5_ib_stage_post_ib_reg_umr_init(). This will avoid attempted double\nfree of the same QP when __mlx5_ib_add() does its cleanup.\n\nResolves a splat:\n\n Syzkaller reported a UAF in ib_destroy_qp_user\n\n workqueue: Failed to create a rescuer kthread for wq \"mkey_cache\": -EINTR\n infiniband mlx5_0: mlx5_mkey_cache_init:981:(pid 1642):\n failed to create work queue\n infiniband mlx5_0: mlx5_ib_stage_post_ib_reg_umr_init:4075:(pid 1642):\n mr cache init failed -12\n ==================================================================\n BUG: KASAN: slab-use-after-free in ib_destroy_qp_user (drivers/infiniband/core/verbs.c:2073)\n Read of size 8 at addr ffff88810da310a8 by task repro_upstream/1642\n\n Call Trace:\n \n kasan_report (mm/kasan/report.c:590)\n ib_destroy_qp_user (drivers/infiniband/core/verbs.c:2073)\n mlx5r_umr_resource_cleanup (drivers/infiniband/hw/mlx5/umr.c:198)\n __mlx5_ib_add (drivers/infiniband/hw/mlx5/main.c:4178)\n mlx5r_probe (drivers/infiniband/hw/mlx5/main.c:4402)\n ...\n \n\n Allocated by task 1642:\n __kmalloc (./include/linux/kasan.h:198 mm/slab_common.c:1026\n mm/slab_common.c:1039)\n create_qp (./include/linux/slab.h:603 ./include/linux/slab.h:720\n ./include/rdma/ib_verbs.h:2795 drivers/infiniband/core/verbs.c:1209)\n ib_create_qp_kernel (drivers/infiniband/core/verbs.c:1347)\n mlx5r_umr_resource_init (drivers/infiniband/hw/mlx5/umr.c:164)\n mlx5_ib_stage_post_ib_reg_umr_init (drivers/infiniband/hw/mlx5/main.c:4070)\n __mlx5_ib_add (drivers/infiniband/hw/mlx5/main.c:4168)\n mlx5r_probe (drivers/infiniband/hw/mlx5/main.c:4402)\n ...\n\n Freed by task 1642:\n __kmem_cache_free (mm/slub.c:1826 mm/slub.c:3809 mm/slub.c:3822)\n ib_destroy_qp_user (drivers/infiniband/core/verbs.c:2112)\n mlx5r_umr_resource_cleanup (drivers/infiniband/hw/mlx5/umr.c:198)\n mlx5_ib_stage_post_ib_reg_umr_init (drivers/infiniband/hw/mlx5/main.c:4076\n drivers/infiniband/hw/mlx5/main.c:4065)\n __mlx5_ib_add (drivers/infiniband/hw/mlx5/main.c:4168)\n mlx5r_probe (drivers/infiniband/hw/mlx5/main.c:4402)\n ...", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-5xmm-chg9-ppmr/GHSA-5xmm-chg9-ppmr.json b/advisories/unreviewed/2024/05/GHSA-5xmm-chg9-ppmr/GHSA-5xmm-chg9-ppmr.json index be623ecc582..b5a9a53bfad 100644 --- a/advisories/unreviewed/2024/05/GHSA-5xmm-chg9-ppmr/GHSA-5xmm-chg9-ppmr.json +++ b/advisories/unreviewed/2024/05/GHSA-5xmm-chg9-ppmr/GHSA-5xmm-chg9-ppmr.json @@ -7,12 +7,8 @@ "CVE-2024-26958" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfs: fix UAF in direct writes\n\nIn production we have been hitting the following warning consistently\n\n------------[ cut here ]------------\nrefcount_t: underflow; use-after-free.\nWARNING: CPU: 17 PID: 1800359 at lib/refcount.c:28 refcount_warn_saturate+0x9c/0xe0\nWorkqueue: nfsiod nfs_direct_write_schedule_work [nfs]\nRIP: 0010:refcount_warn_saturate+0x9c/0xe0\nPKRU: 55555554\nCall Trace:\n \n ? __warn+0x9f/0x130\n ? refcount_warn_saturate+0x9c/0xe0\n ? report_bug+0xcc/0x150\n ? handle_bug+0x3d/0x70\n ? exc_invalid_op+0x16/0x40\n ? asm_exc_invalid_op+0x16/0x20\n ? refcount_warn_saturate+0x9c/0xe0\n nfs_direct_write_schedule_work+0x237/0x250 [nfs]\n process_one_work+0x12f/0x4a0\n worker_thread+0x14e/0x3b0\n ? ZSTD_getCParams_internal+0x220/0x220\n kthread+0xdc/0x120\n ? __btf_name_valid+0xa0/0xa0\n ret_from_fork+0x1f/0x30\n\nThis is because we're completing the nfs_direct_request twice in a row.\n\nThe source of this is when we have our commit requests to submit, we\nprocess them and send them off, and then in the completion path for the\ncommit requests we have\n\nif (nfs_commit_end(cinfo.mds))\n\tnfs_direct_write_complete(dreq);\n\nHowever since we're submitting asynchronous requests we sometimes have\none that completes before we submit the next one, so we end up calling\ncomplete on the nfs_direct_request twice.\n\nThe only other place we use nfs_generic_commit_list() is in\n__nfs_commit_inode, which wraps this call in a\n\nnfs_commit_begin();\nnfs_commit_end();\n\nWhich is a common pattern for this style of completion handling, one\nthat is also repeated in the direct code with get_dreq()/put_dreq()\ncalls around where we process events as well as in the completion paths.\n\nFix this by using the same pattern for the commit requests.\n\nBefore with my 200 node rocksdb stress running this warning would pop\nevery 10ish minutes. With my patch the stress test has been running for\nseveral hours without popping.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-68x5-x32c-8c8w/GHSA-68x5-x32c-8c8w.json b/advisories/unreviewed/2024/05/GHSA-68x5-x32c-8c8w/GHSA-68x5-x32c-8c8w.json index bdbb803a993..768a40eb9de 100644 --- a/advisories/unreviewed/2024/05/GHSA-68x5-x32c-8c8w/GHSA-68x5-x32c-8c8w.json +++ b/advisories/unreviewed/2024/05/GHSA-68x5-x32c-8c8w/GHSA-68x5-x32c-8c8w.json @@ -7,12 +7,8 @@ "CVE-2023-52796" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvlan: add ipvlan_route_v6_outbound() helper\n\nInspired by syzbot reports using a stack of multiple ipvlan devices.\n\nReduce stack size needed in ipvlan_process_v6_outbound() by moving\nthe flowi6 struct used for the route lookup in an non inlined\nhelper. ipvlan_route_v6_outbound() needs 120 bytes on the stack,\nimmediately reclaimed.\n\nAlso make sure ipvlan_process_v4_outbound() is not inlined.\n\nWe might also have to lower MAX_NEST_DEV, because only syzbot uses\nsetups with more than four stacked devices.\n\nBUG: TASK stack guard page was hit at ffffc9000e803ff8 (stack is ffffc9000e804000..ffffc9000e808000)\nstack guard page: 0000 [#1] SMP KASAN\nCPU: 0 PID: 13442 Comm: syz-executor.4 Not tainted 6.1.52-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/09/2023\nRIP: 0010:kasan_check_range+0x4/0x2a0 mm/kasan/generic.c:188\nCode: 48 01 c6 48 89 c7 e8 db 4e c1 03 31 c0 5d c3 cc 0f 0b eb 02 0f 0b b8 ea ff ff ff 5d c3 cc 00 00 cc cc 00 00 cc cc 55 48 89 e5 <41> 57 41 56 41 55 41 54 53 b0 01 48 85 f6 0f 84 a4 01 00 00 48 89\nRSP: 0018:ffffc9000e804000 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: 0000000000000000 RCX: ffffffff817e5bf2\nRDX: 0000000000000000 RSI: 0000000000000008 RDI: ffffffff887c6568\nRBP: ffffc9000e804000 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: dffffc0000000001 R12: 1ffff92001d0080c\nR13: dffffc0000000000 R14: ffffffff87e6b100 R15: 0000000000000000\nFS: 00007fd0c55826c0(0000) GS:ffff8881f6800000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: ffffc9000e803ff8 CR3: 0000000170ef7000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n<#DF>\n\n\n[] __kasan_check_read+0x11/0x20 mm/kasan/shadow.c:31\n[] instrument_atomic_read include/linux/instrumented.h:72 [inline]\n[] _test_bit include/asm-generic/bitops/instrumented-non-atomic.h:141 [inline]\n[] cpumask_test_cpu include/linux/cpumask.h:506 [inline]\n[] cpu_online include/linux/cpumask.h:1092 [inline]\n[] trace_lock_acquire include/trace/events/lock.h:24 [inline]\n[] lock_acquire+0xe2/0x590 kernel/locking/lockdep.c:5632\n[] rcu_lock_acquire+0x2e/0x40 include/linux/rcupdate.h:306\n[] rcu_read_lock include/linux/rcupdate.h:747 [inline]\n[] ip6_pol_route+0x15d/0x1440 net/ipv6/route.c:2221\n[] ip6_pol_route_output+0x50/0x80 net/ipv6/route.c:2606\n[] pol_lookup_func include/net/ip6_fib.h:584 [inline]\n[] fib6_rule_lookup+0x265/0x620 net/ipv6/fib6_rules.c:116\n[] ip6_route_output_flags_noref+0x2d9/0x3a0 net/ipv6/route.c:2638\n[] ip6_route_output_flags+0xca/0x340 net/ipv6/route.c:2651\n[] ip6_route_output include/net/ip6_route.h:100 [inline]\n[] ipvlan_process_v6_outbound drivers/net/ipvlan/ipvlan_core.c:473 [inline]\n[] ipvlan_process_outbound drivers/net/ipvlan/ipvlan_core.c:529 [inline]\n[] ipvlan_xmit_mode_l3 drivers/net/ipvlan/ipvlan_core.c:602 [inline]\n[] ipvlan_queue_xmit+0xc33/0x1be0 drivers/net/ipvlan/ipvlan_core.c:677\n[] ipvlan_start_xmit+0x49/0x100 drivers/net/ipvlan/ipvlan_main.c:229\n[] netdev_start_xmit include/linux/netdevice.h:4966 [inline]\n[] xmit_one net/core/dev.c:3644 [inline]\n[] dev_hard_start_xmit+0x320/0x980 net/core/dev.c:3660\n[] __dev_queue_xmit+0x16b2/0x3370 net/core/dev.c:4324\n[] dev_queue_xmit include/linux/netdevice.h:3067 [inline]\n[] neigh_hh_output include/net/neighbour.h:529 [inline]\n[core.\n\nPrior to commit dde4eff47c82 (\"clk: Look for parents with clkdev based\nclk_lookups\") the check IS_ERR_OR_NULL() was performed which would have\ncaught the NULL.\n\nReading the description of this function it talks about returning NULL but\nthat cannot be so at the moment.\n\nUpdate the function to check for hw before dereferencing it and return NULL\nif hw is NULL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-6wq5-2j9j-6rvr/GHSA-6wq5-2j9j-6rvr.json b/advisories/unreviewed/2024/05/GHSA-6wq5-2j9j-6rvr/GHSA-6wq5-2j9j-6rvr.json index 0077639b07a..6d9f1cff1d6 100644 --- a/advisories/unreviewed/2024/05/GHSA-6wq5-2j9j-6rvr/GHSA-6wq5-2j9j-6rvr.json +++ b/advisories/unreviewed/2024/05/GHSA-6wq5-2j9j-6rvr/GHSA-6wq5-2j9j-6rvr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-72f9-x2qq-3795/GHSA-72f9-x2qq-3795.json b/advisories/unreviewed/2024/05/GHSA-72f9-x2qq-3795/GHSA-72f9-x2qq-3795.json index 7c216509437..f86c178fefa 100644 --- a/advisories/unreviewed/2024/05/GHSA-72f9-x2qq-3795/GHSA-72f9-x2qq-3795.json +++ b/advisories/unreviewed/2024/05/GHSA-72f9-x2qq-3795/GHSA-72f9-x2qq-3795.json @@ -7,12 +7,8 @@ "CVE-2023-52859" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf: hisi: Fix use-after-free when register pmu fails\n\nWhen we fail to register the uncore pmu, the pmu context may not been\nallocated. The error handing will call cpuhp_state_remove_instance()\nto call uncore pmu offline callback, which migrate the pmu context.\nSince that's liable to lead to some kind of use-after-free.\n\nUse cpuhp_state_remove_instance_nocalls() instead of\ncpuhp_state_remove_instance() so that the notifiers don't execute after\nthe PMU device has been failed to register.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-733v-mpm2-5g48/GHSA-733v-mpm2-5g48.json b/advisories/unreviewed/2024/05/GHSA-733v-mpm2-5g48/GHSA-733v-mpm2-5g48.json index 76786d8804c..bff045f833d 100644 --- a/advisories/unreviewed/2024/05/GHSA-733v-mpm2-5g48/GHSA-733v-mpm2-5g48.json +++ b/advisories/unreviewed/2024/05/GHSA-733v-mpm2-5g48/GHSA-733v-mpm2-5g48.json @@ -7,12 +7,8 @@ "CVE-2023-52750" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: Restrict CPU_BIG_ENDIAN to GNU as or LLVM IAS 15.x or newer\n\nPrior to LLVM 15.0.0, LLVM's integrated assembler would incorrectly\nbyte-swap NOP when compiling for big-endian, and the resulting series of\nbytes happened to match the encoding of FNMADD S21, S30, S0, S0.\n\nThis went unnoticed until commit:\n\n 34f66c4c4d5518c1 (\"arm64: Use a positive cpucap for FP/SIMD\")\n\nPrior to that commit, the kernel would always enable the use of FPSIMD\nearly in boot when __cpu_setup() initialized CPACR_EL1, and so usage of\nFNMADD within the kernel was not detected, but could result in the\ncorruption of user or kernel FPSIMD state.\n\nAfter that commit, the instructions happen to trap during boot prior to\nFPSIMD being detected and enabled, e.g.\n\n| Unhandled 64-bit el1h sync exception on CPU0, ESR 0x000000001fe00000 -- ASIMD\n| CPU: 0 PID: 0 Comm: swapper Not tainted 6.6.0-rc3-00013-g34f66c4c4d55 #1\n| Hardware name: linux,dummy-virt (DT)\n| pstate: 400000c9 (nZcv daIF -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n| pc : __pi_strcmp+0x1c/0x150\n| lr : populate_properties+0xe4/0x254\n| sp : ffffd014173d3ad0\n| x29: ffffd014173d3af0 x28: fffffbfffddffcb8 x27: 0000000000000000\n| x26: 0000000000000058 x25: fffffbfffddfe054 x24: 0000000000000008\n| x23: fffffbfffddfe000 x22: fffffbfffddfe000 x21: fffffbfffddfe044\n| x20: ffffd014173d3b70 x19: 0000000000000001 x18: 0000000000000005\n| x17: 0000000000000010 x16: 0000000000000000 x15: 00000000413e7000\n| x14: 0000000000000000 x13: 0000000000001bcc x12: 0000000000000000\n| x11: 00000000d00dfeed x10: ffffd414193f2cd0 x9 : 0000000000000000\n| x8 : 0101010101010101 x7 : ffffffffffffffc0 x6 : 0000000000000000\n| x5 : 0000000000000000 x4 : 0101010101010101 x3 : 000000000000002a\n| x2 : 0000000000000001 x1 : ffffd014171f2988 x0 : fffffbfffddffcb8\n| Kernel panic - not syncing: Unhandled exception\n| CPU: 0 PID: 0 Comm: swapper Not tainted 6.6.0-rc3-00013-g34f66c4c4d55 #1\n| Hardware name: linux,dummy-virt (DT)\n| Call trace:\n| dump_backtrace+0xec/0x108\n| show_stack+0x18/0x2c\n| dump_stack_lvl+0x50/0x68\n| dump_stack+0x18/0x24\n| panic+0x13c/0x340\n| el1t_64_irq_handler+0x0/0x1c\n| el1_abort+0x0/0x5c\n| el1h_64_sync+0x64/0x68\n| __pi_strcmp+0x1c/0x150\n| unflatten_dt_nodes+0x1e8/0x2d8\n| __unflatten_device_tree+0x5c/0x15c\n| unflatten_device_tree+0x38/0x50\n| setup_arch+0x164/0x1e0\n| start_kernel+0x64/0x38c\n| __primary_switched+0xbc/0xc4\n\nRestrict CONFIG_CPU_BIG_ENDIAN to a known good assembler, which is\neither GNU as or LLVM's IAS 15.0.0 and newer, which contains the linked\ncommit.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7533-c28p-jp9p/GHSA-7533-c28p-jp9p.json b/advisories/unreviewed/2024/05/GHSA-7533-c28p-jp9p/GHSA-7533-c28p-jp9p.json index 09f98404d93..c808439e405 100644 --- a/advisories/unreviewed/2024/05/GHSA-7533-c28p-jp9p/GHSA-7533-c28p-jp9p.json +++ b/advisories/unreviewed/2024/05/GHSA-7533-c28p-jp9p/GHSA-7533-c28p-jp9p.json @@ -7,12 +7,8 @@ "CVE-2024-26961" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmac802154: fix llsec key resources release in mac802154_llsec_key_del\n\nmac802154_llsec_key_del() can free resources of a key directly without\nfollowing the RCU rules for waiting before the end of a grace period. This\nmay lead to use-after-free in case llsec_lookup_key() is traversing the\nlist of keys in parallel with a key deletion:\n\nrefcount_t: addition on 0; use-after-free.\nWARNING: CPU: 4 PID: 16000 at lib/refcount.c:25 refcount_warn_saturate+0x162/0x2a0\nModules linked in:\nCPU: 4 PID: 16000 Comm: wpan-ping Not tainted 6.7.0 #19\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.2-debian-1.16.2-1 04/01/2014\nRIP: 0010:refcount_warn_saturate+0x162/0x2a0\nCall Trace:\n \n llsec_lookup_key.isra.0+0x890/0x9e0\n mac802154_llsec_encrypt+0x30c/0x9c0\n ieee802154_subif_start_xmit+0x24/0x1e0\n dev_hard_start_xmit+0x13e/0x690\n sch_direct_xmit+0x2ae/0xbc0\n __dev_queue_xmit+0x11dd/0x3c20\n dgram_sendmsg+0x90b/0xd60\n __sys_sendto+0x466/0x4c0\n __x64_sys_sendto+0xe0/0x1c0\n do_syscall_64+0x45/0xf0\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\nAlso, ieee802154_llsec_key_entry structures are not freed by\nmac802154_llsec_key_del():\n\nunreferenced object 0xffff8880613b6980 (size 64):\n comm \"iwpan\", pid 2176, jiffies 4294761134 (age 60.475s)\n hex dump (first 32 bytes):\n 78 0d 8f 18 80 88 ff ff 22 01 00 00 00 00 ad de x.......\".......\n 00 00 00 00 00 00 00 00 03 00 cd ab 00 00 00 00 ................\n backtrace:\n [] __kmem_cache_alloc_node+0x1e2/0x2d0\n [] kmalloc_trace+0x25/0xc0\n [] mac802154_llsec_key_add+0xac9/0xcf0\n [] ieee802154_add_llsec_key+0x5a/0x80\n [] nl802154_add_llsec_key+0x426/0x5b0\n [] genl_family_rcv_msg_doit+0x1fe/0x2f0\n [] genl_rcv_msg+0x531/0x7d0\n [] netlink_rcv_skb+0x169/0x440\n [] genl_rcv+0x28/0x40\n [] netlink_unicast+0x53c/0x820\n [] netlink_sendmsg+0x93b/0xe60\n [] ____sys_sendmsg+0xac5/0xca0\n [] ___sys_sendmsg+0x11d/0x1c0\n [] __sys_sendmsg+0xfa/0x1d0\n [] do_syscall_64+0x45/0xf0\n [] entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\nHandle the proper resource release in the RCU callback function\nmac802154_llsec_key_del_rcu().\n\nNote that if llsec_lookup_key() finds a key, it gets a refcount via\nllsec_key_get() and locally copies key id from key_entry (which is a\nlist element). So it's safe to call llsec_key_put() and free the list\nentry after the RCU grace period elapses.\n\nFound by Linux Verification Center (linuxtesting.org).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-767c-45p6-hv5q/GHSA-767c-45p6-hv5q.json b/advisories/unreviewed/2024/05/GHSA-767c-45p6-hv5q/GHSA-767c-45p6-hv5q.json index 30cd1961c0b..237dd1ef9cc 100644 --- a/advisories/unreviewed/2024/05/GHSA-767c-45p6-hv5q/GHSA-767c-45p6-hv5q.json +++ b/advisories/unreviewed/2024/05/GHSA-767c-45p6-hv5q/GHSA-767c-45p6-hv5q.json @@ -7,12 +7,8 @@ "CVE-2024-26974" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - resolve race condition during AER recovery\n\nDuring the PCI AER system's error recovery process, the kernel driver\nmay encounter a race condition with freeing the reset_data structure's\nmemory. If the device restart will take more than 10 seconds the function\nscheduling that restart will exit due to a timeout, and the reset_data\nstructure will be freed. However, this data structure is used for\ncompletion notification after the restart is completed, which leads\nto a UAF bug.\n\nThis results in a KFENCE bug notice.\n\n BUG: KFENCE: use-after-free read in adf_device_reset_worker+0x38/0xa0 [intel_qat]\n Use-after-free read at 0x00000000bc56fddf (in kfence-#142):\n adf_device_reset_worker+0x38/0xa0 [intel_qat]\n process_one_work+0x173/0x340\n\nTo resolve this race condition, the memory associated to the container\nof the work_struct is freed on the worker if the timeout expired,\notherwise on the function that schedules the worker.\nThe timeout detection can be done by checking if the caller is\nstill waiting for completion or not by using completion_done() function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-76g6-5v2w-pw2h/GHSA-76g6-5v2w-pw2h.json b/advisories/unreviewed/2024/05/GHSA-76g6-5v2w-pw2h/GHSA-76g6-5v2w-pw2h.json index 1f023906455..b22c92e1917 100644 --- a/advisories/unreviewed/2024/05/GHSA-76g6-5v2w-pw2h/GHSA-76g6-5v2w-pw2h.json +++ b/advisories/unreviewed/2024/05/GHSA-76g6-5v2w-pw2h/GHSA-76g6-5v2w-pw2h.json @@ -7,12 +7,8 @@ "CVE-2023-52795" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvhost-vdpa: fix use after free in vhost_vdpa_probe()\n\nThe put_device() calls vhost_vdpa_release_dev() which calls\nida_simple_remove() and frees \"v\". So this call to\nida_simple_remove() is a use after free and a double free.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7grp-x8pq-wh35/GHSA-7grp-x8pq-wh35.json b/advisories/unreviewed/2024/05/GHSA-7grp-x8pq-wh35/GHSA-7grp-x8pq-wh35.json index a869ef92636..4ad911026c9 100644 --- a/advisories/unreviewed/2024/05/GHSA-7grp-x8pq-wh35/GHSA-7grp-x8pq-wh35.json +++ b/advisories/unreviewed/2024/05/GHSA-7grp-x8pq-wh35/GHSA-7grp-x8pq-wh35.json @@ -7,12 +7,8 @@ "CVE-2023-52788" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni915/perf: Fix NULL deref bugs with drm_dbg() calls\n\nWhen i915 perf interface is not available dereferencing it will lead to\nNULL dereferences.\n\nAs returning -ENOTSUPP is pretty clear return when perf interface is not\navailable.\n\n[tursulin: added stable tag]\n(cherry picked from commit 36f27350ff745bd228ab04d7845dfbffc177a889)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7hxp-v79h-r4fw/GHSA-7hxp-v79h-r4fw.json b/advisories/unreviewed/2024/05/GHSA-7hxp-v79h-r4fw/GHSA-7hxp-v79h-r4fw.json index 56c55014af9..58ec2e7d32f 100644 --- a/advisories/unreviewed/2024/05/GHSA-7hxp-v79h-r4fw/GHSA-7hxp-v79h-r4fw.json +++ b/advisories/unreviewed/2024/05/GHSA-7hxp-v79h-r4fw/GHSA-7hxp-v79h-r4fw.json @@ -7,12 +7,8 @@ "CVE-2023-52841" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: vidtv: mux: Add check and kfree for kstrdup\n\nAdd check for the return value of kstrdup() and return the error\nif it fails in order to avoid NULL pointer dereference.\nMoreover, use kfree() in the later error handling in order to avoid\nmemory leak.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7prj-h6r4-gh9j/GHSA-7prj-h6r4-gh9j.json b/advisories/unreviewed/2024/05/GHSA-7prj-h6r4-gh9j/GHSA-7prj-h6r4-gh9j.json index 484aa3de812..0257e1aa87d 100644 --- a/advisories/unreviewed/2024/05/GHSA-7prj-h6r4-gh9j/GHSA-7prj-h6r4-gh9j.json +++ b/advisories/unreviewed/2024/05/GHSA-7prj-h6r4-gh9j/GHSA-7prj-h6r4-gh9j.json @@ -7,12 +7,8 @@ "CVE-2023-52785" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Fix racing issue between ufshcd_mcq_abort() and ISR\n\nIf command timeout happens and cq complete IRQ is raised at the same time,\nufshcd_mcq_abort clears lprb->cmd and a NULL pointer deref happens in the\nISR. Error log:\n\nufshcd_abort: Device abort task at tag 18\nUnable to handle kernel NULL pointer dereference at virtual address\n0000000000000108\npc : [0xffffffe27ef867ac] scsi_dma_unmap+0xc/0x44\nlr : [0xffffffe27f1b898c] ufshcd_release_scsi_cmd+0x24/0x114", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7prp-hfw8-9qcp/GHSA-7prp-hfw8-9qcp.json b/advisories/unreviewed/2024/05/GHSA-7prp-hfw8-9qcp/GHSA-7prp-hfw8-9qcp.json index 5aebc367e93..fd39886cdd2 100644 --- a/advisories/unreviewed/2024/05/GHSA-7prp-hfw8-9qcp/GHSA-7prp-hfw8-9qcp.json +++ b/advisories/unreviewed/2024/05/GHSA-7prp-hfw8-9qcp/GHSA-7prp-hfw8-9qcp.json @@ -7,12 +7,8 @@ "CVE-2023-52778" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: deal with large GSO size\n\nAfter the blamed commit below, the TCP sockets (and the MPTCP subflows)\ncan build egress packets larger than 64K. That exceeds the maximum DSS\ndata size, the length being misrepresent on the wire and the stream being\ncorrupted, as later observed on the receiver:\n\n WARNING: CPU: 0 PID: 9696 at net/mptcp/protocol.c:705 __mptcp_move_skbs_from_subflow+0x2604/0x26e0\n CPU: 0 PID: 9696 Comm: syz-executor.7 Not tainted 6.6.0-rc5-gcd8bdf563d46 #45\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.11.0-2.el7 04/01/2014\n netlink: 8 bytes leftover after parsing attributes in process `syz-executor.4'.\n RIP: 0010:__mptcp_move_skbs_from_subflow+0x2604/0x26e0 net/mptcp/protocol.c:705\n RSP: 0018:ffffc90000006e80 EFLAGS: 00010246\n RAX: ffffffff83e9f674 RBX: ffff88802f45d870 RCX: ffff888102ad0000\n netlink: 8 bytes leftover after parsing attributes in process `syz-executor.4'.\n RDX: 0000000080000303 RSI: 0000000000013908 RDI: 0000000000003908\n RBP: ffffc90000007110 R08: ffffffff83e9e078 R09: 1ffff1100e548c8a\n R10: dffffc0000000000 R11: ffffed100e548c8b R12: 0000000000013908\n R13: dffffc0000000000 R14: 0000000000003908 R15: 000000000031cf29\n FS: 00007f239c47e700(0000) GS:ffff88811b200000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f239c45cd78 CR3: 000000006a66c006 CR4: 0000000000770ef0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000600\n PKRU: 55555554\n Call Trace:\n \n mptcp_data_ready+0x263/0xac0 net/mptcp/protocol.c:819\n subflow_data_ready+0x268/0x6d0 net/mptcp/subflow.c:1409\n tcp_data_queue+0x21a1/0x7a60 net/ipv4/tcp_input.c:5151\n tcp_rcv_established+0x950/0x1d90 net/ipv4/tcp_input.c:6098\n tcp_v6_do_rcv+0x554/0x12f0 net/ipv6/tcp_ipv6.c:1483\n tcp_v6_rcv+0x2e26/0x3810 net/ipv6/tcp_ipv6.c:1749\n ip6_protocol_deliver_rcu+0xd6b/0x1ae0 net/ipv6/ip6_input.c:438\n ip6_input+0x1c5/0x470 net/ipv6/ip6_input.c:483\n ipv6_rcv+0xef/0x2c0 include/linux/netfilter.h:304\n __netif_receive_skb+0x1ea/0x6a0 net/core/dev.c:5532\n process_backlog+0x353/0x660 net/core/dev.c:5974\n __napi_poll+0xc6/0x5a0 net/core/dev.c:6536\n net_rx_action+0x6a0/0xfd0 net/core/dev.c:6603\n __do_softirq+0x184/0x524 kernel/softirq.c:553\n do_softirq+0xdd/0x130 kernel/softirq.c:454\n\nAddress the issue explicitly bounding the maximum GSO size to what MPTCP\nactually allows.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7wx4-4999-cgfj/GHSA-7wx4-4999-cgfj.json b/advisories/unreviewed/2024/05/GHSA-7wx4-4999-cgfj/GHSA-7wx4-4999-cgfj.json index ceb57650629..19f7c424388 100644 --- a/advisories/unreviewed/2024/05/GHSA-7wx4-4999-cgfj/GHSA-7wx4-4999-cgfj.json +++ b/advisories/unreviewed/2024/05/GHSA-7wx4-4999-cgfj/GHSA-7wx4-4999-cgfj.json @@ -7,12 +7,8 @@ "CVE-2023-52805" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix array-index-out-of-bounds in diAlloc\n\nCurrently there is not check against the agno of the iag while\nallocating new inodes to avoid fragmentation problem. Added the check\nwhich is required.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7x33-7jjx-2gmh/GHSA-7x33-7jjx-2gmh.json b/advisories/unreviewed/2024/05/GHSA-7x33-7jjx-2gmh/GHSA-7x33-7jjx-2gmh.json index ff9c4e07f1b..314fc8a334f 100644 --- a/advisories/unreviewed/2024/05/GHSA-7x33-7jjx-2gmh/GHSA-7x33-7jjx-2gmh.json +++ b/advisories/unreviewed/2024/05/GHSA-7x33-7jjx-2gmh/GHSA-7x33-7jjx-2gmh.json @@ -7,12 +7,8 @@ "CVE-2024-26957" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/zcrypt: fix reference counting on zcrypt card objects\n\nTests with hot-plugging crytpo cards on KVM guests with debug\nkernel build revealed an use after free for the load field of\nthe struct zcrypt_card. The reason was an incorrect reference\nhandling of the zcrypt card object which could lead to a free\nof the zcrypt card object while it was still in use.\n\nThis is an example of the slab message:\n\n kernel: 0x00000000885a7512-0x00000000885a7513 @offset=1298. First byte 0x68 instead of 0x6b\n kernel: Allocated in zcrypt_card_alloc+0x36/0x70 [zcrypt] age=18046 cpu=3 pid=43\n kernel: kmalloc_trace+0x3f2/0x470\n kernel: zcrypt_card_alloc+0x36/0x70 [zcrypt]\n kernel: zcrypt_cex4_card_probe+0x26/0x380 [zcrypt_cex4]\n kernel: ap_device_probe+0x15c/0x290\n kernel: really_probe+0xd2/0x468\n kernel: driver_probe_device+0x40/0xf0\n kernel: __device_attach_driver+0xc0/0x140\n kernel: bus_for_each_drv+0x8c/0xd0\n kernel: __device_attach+0x114/0x198\n kernel: bus_probe_device+0xb4/0xc8\n kernel: device_add+0x4d2/0x6e0\n kernel: ap_scan_adapter+0x3d0/0x7c0\n kernel: ap_scan_bus+0x5a/0x3b0\n kernel: ap_scan_bus_wq_callback+0x40/0x60\n kernel: process_one_work+0x26e/0x620\n kernel: worker_thread+0x21c/0x440\n kernel: Freed in zcrypt_card_put+0x54/0x80 [zcrypt] age=9024 cpu=3 pid=43\n kernel: kfree+0x37e/0x418\n kernel: zcrypt_card_put+0x54/0x80 [zcrypt]\n kernel: ap_device_remove+0x4c/0xe0\n kernel: device_release_driver_internal+0x1c4/0x270\n kernel: bus_remove_device+0x100/0x188\n kernel: device_del+0x164/0x3c0\n kernel: device_unregister+0x30/0x90\n kernel: ap_scan_adapter+0xc8/0x7c0\n kernel: ap_scan_bus+0x5a/0x3b0\n kernel: ap_scan_bus_wq_callback+0x40/0x60\n kernel: process_one_work+0x26e/0x620\n kernel: worker_thread+0x21c/0x440\n kernel: kthread+0x150/0x168\n kernel: __ret_from_fork+0x3c/0x58\n kernel: ret_from_fork+0xa/0x30\n kernel: Slab 0x00000372022169c0 objects=20 used=18 fp=0x00000000885a7c88 flags=0x3ffff00000000a00(workingset|slab|node=0|zone=1|lastcpupid=0x1ffff)\n kernel: Object 0x00000000885a74b8 @offset=1208 fp=0x00000000885a7c88\n kernel: Redzone 00000000885a74b0: bb bb bb bb bb bb bb bb ........\n kernel: Object 00000000885a74b8: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk\n kernel: Object 00000000885a74c8: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk\n kernel: Object 00000000885a74d8: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk\n kernel: Object 00000000885a74e8: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk\n kernel: Object 00000000885a74f8: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk\n kernel: Object 00000000885a7508: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 68 4b 6b 6b 6b a5 kkkkkkkkkkhKkkk.\n kernel: Redzone 00000000885a7518: bb bb bb bb bb bb bb bb ........\n kernel: Padding 00000000885a756c: 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a ZZZZZZZZZZZZ\n kernel: CPU: 0 PID: 387 Comm: systemd-udevd Not tainted 6.8.0-HF #2\n kernel: Hardware name: IBM 3931 A01 704 (KVM/Linux)\n kernel: Call Trace:\n kernel: [<00000000ca5ab5b8>] dump_stack_lvl+0x90/0x120\n kernel: [<00000000c99d78bc>] check_bytes_and_report+0x114/0x140\n kernel: [<00000000c99d53cc>] check_object+0x334/0x3f8\n kernel: [<00000000c99d820c>] alloc_debug_processing+0xc4/0x1f8\n kernel: [<00000000c99d852e>] get_partial_node.part.0+0x1ee/0x3e0\n kernel: [<00000000c99d94ec>] ___slab_alloc+0xaf4/0x13c8\n kernel: [<00000000c99d9e38>] __slab_alloc.constprop.0+0x78/0xb8\n kernel: [<00000000c99dc8dc>] __kmalloc+0x434/0x590\n kernel: [<00000000c9b4c0ce>] ext4_htree_store_dirent+0x4e/0x1c0\n kernel: [<00000000c9b908a2>] htree_dirblock_to_tree+0x17a/0x3f0\n kernel: \n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-8crr-8542-6rh6/GHSA-8crr-8542-6rh6.json b/advisories/unreviewed/2024/05/GHSA-8crr-8542-6rh6/GHSA-8crr-8542-6rh6.json index 173145f2793..aca5eaf6121 100644 --- a/advisories/unreviewed/2024/05/GHSA-8crr-8542-6rh6/GHSA-8crr-8542-6rh6.json +++ b/advisories/unreviewed/2024/05/GHSA-8crr-8542-6rh6/GHSA-8crr-8542-6rh6.json @@ -7,12 +7,8 @@ "CVE-2023-52833" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: Add date->evt_skb is NULL check\n\nfix crash because of null pointers\n\n[ 6104.969662] BUG: kernel NULL pointer dereference, address: 00000000000000c8\n[ 6104.969667] #PF: supervisor read access in kernel mode\n[ 6104.969668] #PF: error_code(0x0000) - not-present page\n[ 6104.969670] PGD 0 P4D 0\n[ 6104.969673] Oops: 0000 [#1] SMP NOPTI\n[ 6104.969684] RIP: 0010:btusb_mtk_hci_wmt_sync+0x144/0x220 [btusb]\n[ 6104.969688] RSP: 0018:ffffb8d681533d48 EFLAGS: 00010246\n[ 6104.969689] RAX: 0000000000000000 RBX: ffff8ad560bb2000 RCX: 0000000000000006\n[ 6104.969691] RDX: 0000000000000000 RSI: ffffb8d681533d08 RDI: 0000000000000000\n[ 6104.969692] RBP: ffffb8d681533d70 R08: 0000000000000001 R09: 0000000000000001\n[ 6104.969694] R10: 0000000000000001 R11: 00000000fa83b2da R12: ffff8ad461d1d7c0\n[ 6104.969695] R13: 0000000000000000 R14: ffff8ad459618c18 R15: ffffb8d681533d90\n[ 6104.969697] FS: 00007f5a1cab9d40(0000) GS:ffff8ad578200000(0000) knlGS:00000\n[ 6104.969699] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 6104.969700] CR2: 00000000000000c8 CR3: 000000018620c001 CR4: 0000000000760ef0\n[ 6104.969701] PKRU: 55555554\n[ 6104.969702] Call Trace:\n[ 6104.969708] btusb_mtk_shutdown+0x44/0x80 [btusb]\n[ 6104.969732] hci_dev_do_close+0x470/0x5c0 [bluetooth]\n[ 6104.969748] hci_rfkill_set_block+0x56/0xa0 [bluetooth]\n[ 6104.969753] rfkill_set_block+0x92/0x160\n[ 6104.969755] rfkill_fop_write+0x136/0x1e0\n[ 6104.969759] __vfs_write+0x18/0x40\n[ 6104.969761] vfs_write+0xdf/0x1c0\n[ 6104.969763] ksys_write+0xb1/0xe0\n[ 6104.969765] __x64_sys_write+0x1a/0x20\n[ 6104.969769] do_syscall_64+0x51/0x180\n[ 6104.969771] entry_SYSCALL_64_after_hwframe+0x44/0xa9\n[ 6104.969773] RIP: 0033:0x7f5a21f18fef\n[ 6104.9] RSP: 002b:00007ffeefe39010 EFLAGS: 00000293 ORIG_RAX: 0000000000000001\n[ 6104.969780] RAX: ffffffffffffffda RBX: 000055c10a7560a0 RCX: 00007f5a21f18fef\n[ 6104.969781] RDX: 0000000000000008 RSI: 00007ffeefe39060 RDI: 0000000000000012\n[ 6104.969782] RBP: 00007ffeefe39060 R08: 0000000000000000 R09: 0000000000000017\n[ 6104.969784] R10: 00007ffeefe38d97 R11: 0000000000000293 R12: 0000000000000002\n[ 6104.969785] R13: 00007ffeefe39220 R14: 00007ffeefe391a0 R15: 000055c10a72acf0", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8j29-hrg8-7mvc/GHSA-8j29-hrg8-7mvc.json b/advisories/unreviewed/2024/05/GHSA-8j29-hrg8-7mvc/GHSA-8j29-hrg8-7mvc.json index c3e8c8169f6..42b2019b2a8 100644 --- a/advisories/unreviewed/2024/05/GHSA-8j29-hrg8-7mvc/GHSA-8j29-hrg8-7mvc.json +++ b/advisories/unreviewed/2024/05/GHSA-8j29-hrg8-7mvc/GHSA-8j29-hrg8-7mvc.json @@ -7,12 +7,8 @@ "CVE-2023-52739" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nFix page corruption caused by racy check in __free_pages\n\nWhen we upgraded our kernel, we started seeing some page corruption like\nthe following consistently:\n\n BUG: Bad page state in process ganesha.nfsd pfn:1304ca\n page:0000000022261c55 refcount:0 mapcount:-128 mapping:0000000000000000 index:0x0 pfn:0x1304ca\n flags: 0x17ffffc0000000()\n raw: 0017ffffc0000000 ffff8a513ffd4c98 ffffeee24b35ec08 0000000000000000\n raw: 0000000000000000 0000000000000001 00000000ffffff7f 0000000000000000\n page dumped because: nonzero mapcount\n CPU: 0 PID: 15567 Comm: ganesha.nfsd Kdump: loaded Tainted: P B O 5.10.158-1.nutanix.20221209.el7.x86_64 #1\n Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 04/05/2016\n Call Trace:\n dump_stack+0x74/0x96\n bad_page.cold+0x63/0x94\n check_new_page_bad+0x6d/0x80\n rmqueue+0x46e/0x970\n get_page_from_freelist+0xcb/0x3f0\n ? _cond_resched+0x19/0x40\n __alloc_pages_nodemask+0x164/0x300\n alloc_pages_current+0x87/0xf0\n skb_page_frag_refill+0x84/0x110\n ...\n\nSometimes, it would also show up as corruption in the free list pointer\nand cause crashes.\n\nAfter bisecting the issue, we found the issue started from commit\ne320d3012d25 (\"mm/page_alloc.c: fix freeing non-compound pages\"):\n\n\tif (put_page_testzero(page))\n\t\tfree_the_page(page, order);\n\telse if (!PageHead(page))\n\t\twhile (order-- > 0)\n\t\t\tfree_the_page(page + (1 << order), order);\n\nSo the problem is the check PageHead is racy because at this point we\nalready dropped our reference to the page. So even if we came in with\ncompound page, the page can already be freed and PageHead can return\nfalse and we will end up freeing all the tail pages causing double free.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8j5q-6cq4-63x9/GHSA-8j5q-6cq4-63x9.json b/advisories/unreviewed/2024/05/GHSA-8j5q-6cq4-63x9/GHSA-8j5q-6cq4-63x9.json index 10cb7d137b2..b1e6c9bd046 100644 --- a/advisories/unreviewed/2024/05/GHSA-8j5q-6cq4-63x9/GHSA-8j5q-6cq4-63x9.json +++ b/advisories/unreviewed/2024/05/GHSA-8j5q-6cq4-63x9/GHSA-8j5q-6cq4-63x9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-8r5m-pqvh-q2vm/GHSA-8r5m-pqvh-q2vm.json b/advisories/unreviewed/2024/05/GHSA-8r5m-pqvh-q2vm/GHSA-8r5m-pqvh-q2vm.json index 89545408d6a..b7486cb3de6 100644 --- a/advisories/unreviewed/2024/05/GHSA-8r5m-pqvh-q2vm/GHSA-8r5m-pqvh-q2vm.json +++ b/advisories/unreviewed/2024/05/GHSA-8r5m-pqvh-q2vm/GHSA-8r5m-pqvh-q2vm.json @@ -7,12 +7,8 @@ "CVE-2023-52808" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: hisi_sas: Set debugfs_dir pointer to NULL after removing debugfs\n\nIf init debugfs failed during device registration due to memory allocation\nfailure, debugfs_remove_recursive() is called, after which debugfs_dir is\nnot set to NULL. debugfs_remove_recursive() will be called again during\ndevice removal. As a result, illegal pointer is accessed.\n\n[ 1665.467244] hisi_sas_v3_hw 0000:b4:02.0: failed to init debugfs!\n...\n[ 1669.836708] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000a0\n[ 1669.872669] pc : down_write+0x24/0x70\n[ 1669.876315] lr : down_write+0x1c/0x70\n[ 1669.879961] sp : ffff000036f53a30\n[ 1669.883260] x29: ffff000036f53a30 x28: ffffa027c31549f8\n[ 1669.888547] x27: ffffa027c3140000 x26: 0000000000000000\n[ 1669.893834] x25: ffffa027bf37c270 x24: ffffa027bf37c270\n[ 1669.899122] x23: ffff0000095406b8 x22: ffff0000095406a8\n[ 1669.904408] x21: 0000000000000000 x20: ffffa027bf37c310\n[ 1669.909695] x19: 00000000000000a0 x18: ffff8027dcd86f10\n[ 1669.914982] x17: 0000000000000000 x16: 0000000000000000\n[ 1669.920268] x15: 0000000000000000 x14: ffffa0274014f870\n[ 1669.925555] x13: 0000000000000040 x12: 0000000000000228\n[ 1669.930842] x11: 0000000000000020 x10: 0000000000000bb0\n[ 1669.936129] x9 : ffff000036f537f0 x8 : ffff80273088ca10\n[ 1669.941416] x7 : 000000000000001d x6 : 00000000ffffffff\n[ 1669.946702] x5 : ffff000008a36310 x4 : ffff80273088be00\n[ 1669.951989] x3 : ffff000009513e90 x2 : 0000000000000000\n[ 1669.957276] x1 : 00000000000000a0 x0 : ffffffff00000001\n[ 1669.962563] Call trace:\n[ 1669.965000] down_write+0x24/0x70\n[ 1669.968301] debugfs_remove_recursive+0x5c/0x1b0\n[ 1669.972905] hisi_sas_debugfs_exit+0x24/0x30 [hisi_sas_main]\n[ 1669.978541] hisi_sas_v3_remove+0x130/0x150 [hisi_sas_v3_hw]\n[ 1669.984175] pci_device_remove+0x48/0xd8\n[ 1669.988082] device_release_driver_internal+0x1b4/0x250\n[ 1669.993282] device_release_driver+0x28/0x38\n[ 1669.997534] pci_stop_bus_device+0x84/0xb8\n[ 1670.001611] pci_stop_and_remove_bus_device_locked+0x24/0x40\n[ 1670.007244] remove_store+0xfc/0x140\n[ 1670.010802] dev_attr_store+0x44/0x60\n[ 1670.014448] sysfs_kf_write+0x58/0x80\n[ 1670.018095] kernfs_fop_write+0xe8/0x1f0\n[ 1670.022000] __vfs_write+0x60/0x190\n[ 1670.025472] vfs_write+0xac/0x1c0\n[ 1670.028771] ksys_write+0x6c/0xd8\n[ 1670.032071] __arm64_sys_write+0x24/0x30\n[ 1670.035977] el0_svc_common+0x78/0x130\n[ 1670.039710] el0_svc_handler+0x38/0x78\n[ 1670.043442] el0_svc+0x8/0xc\n\nTo fix this, set debugfs_dir to NULL after debugfs_remove_recursive().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8r78-c2f2-82qm/GHSA-8r78-c2f2-82qm.json b/advisories/unreviewed/2024/05/GHSA-8r78-c2f2-82qm/GHSA-8r78-c2f2-82qm.json index 54b57870ad4..2ea797eef56 100644 --- a/advisories/unreviewed/2024/05/GHSA-8r78-c2f2-82qm/GHSA-8r78-c2f2-82qm.json +++ b/advisories/unreviewed/2024/05/GHSA-8r78-c2f2-82qm/GHSA-8r78-c2f2-82qm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8v7x-4vvg-pgr3/GHSA-8v7x-4vvg-pgr3.json b/advisories/unreviewed/2024/05/GHSA-8v7x-4vvg-pgr3/GHSA-8v7x-4vvg-pgr3.json index 04c76de5ca6..f2c71267093 100644 --- a/advisories/unreviewed/2024/05/GHSA-8v7x-4vvg-pgr3/GHSA-8v7x-4vvg-pgr3.json +++ b/advisories/unreviewed/2024/05/GHSA-8v7x-4vvg-pgr3/GHSA-8v7x-4vvg-pgr3.json @@ -7,12 +7,8 @@ "CVE-2023-52792" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/region: Do not try to cleanup after cxl_region_setup_targets() fails\n\nCommit 5e42bcbc3fef (\"cxl/region: decrement ->nr_targets on error in\ncxl_region_attach()\") tried to avoid 'eiw' initialization errors when\n->nr_targets exceeded 16, by just decrementing ->nr_targets when\ncxl_region_setup_targets() failed.\n\nCommit 86987c766276 (\"cxl/region: Cleanup target list on attach error\")\nextended that cleanup to also clear cxled->pos and p->targets[pos]. The\ninitialization error was incidentally fixed separately by:\nCommit 8d4285425714 (\"cxl/region: Fix port setup uninitialized variable\nwarnings\") which was merged a few days after 5e42bcbc3fef.\n\nBut now the original cleanup when cxl_region_setup_targets() fails\nprevents endpoint and switch decoder resources from being reused:\n\n1) the cleanup does not set the decoder's region to NULL, which results\n in future dpa_size_store() calls returning -EBUSY\n2) the decoder is not properly freed, which results in future commit\n errors associated with the upstream switch\n\nNow that the initialization errors were fixed separately, the proper\ncleanup for this case is to just return immediately. Then the resources\nassociated with this target get cleanup up as normal when the failed\nregion is deleted.\n\nThe ->nr_targets decrement in the error case also helped prevent\na p->targets[] array overflow, so add a new check to prevent against\nthat overflow.\n\nTested by trying to create an invalid region for a 2 switch * 2 endpoint\ntopology, and then following up with creating a valid region.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-93cv-5m73-q9h8/GHSA-93cv-5m73-q9h8.json b/advisories/unreviewed/2024/05/GHSA-93cv-5m73-q9h8/GHSA-93cv-5m73-q9h8.json index de27eea3c21..cccceda46a8 100644 --- a/advisories/unreviewed/2024/05/GHSA-93cv-5m73-q9h8/GHSA-93cv-5m73-q9h8.json +++ b/advisories/unreviewed/2024/05/GHSA-93cv-5m73-q9h8/GHSA-93cv-5m73-q9h8.json @@ -7,12 +7,8 @@ "CVE-2023-52831" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpu/hotplug: Don't offline the last non-isolated CPU\n\nIf a system has isolated CPUs via the \"isolcpus=\" command line parameter,\nthen an attempt to offline the last housekeeping CPU will result in a\nWARN_ON() when rebuilding the scheduler domains and a subsequent panic due\nto and unhandled empty CPU mas in partition_sched_domains_locked().\n\ncpuset_hotplug_workfn()\n rebuild_sched_domains_locked()\n ndoms = generate_sched_domains(&doms, &attr);\n cpumask_and(doms[0], top_cpuset.effective_cpus, housekeeping_cpumask(HK_FLAG_DOMAIN));\n\nThus results in an empty CPU mask which triggers the warning and then the\nsubsequent crash:\n\nWARNING: CPU: 4 PID: 80 at kernel/sched/topology.c:2366 build_sched_domains+0x120c/0x1408\nCall trace:\n build_sched_domains+0x120c/0x1408\n partition_sched_domains_locked+0x234/0x880\n rebuild_sched_domains_locked+0x37c/0x798\n rebuild_sched_domains+0x30/0x58\n cpuset_hotplug_workfn+0x2a8/0x930\n\nUnable to handle kernel paging request at virtual address fffe80027ab37080\n partition_sched_domains_locked+0x318/0x880\n rebuild_sched_domains_locked+0x37c/0x798\n\nAside of the resulting crash, it does not make any sense to offline the last\nlast housekeeping CPU.\n\nPrevent this by masking out the non-housekeeping CPUs when selecting a\ntarget CPU for initiating the CPU unplug operation via the work queue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-97fh-3x83-fvh6/GHSA-97fh-3x83-fvh6.json b/advisories/unreviewed/2024/05/GHSA-97fh-3x83-fvh6/GHSA-97fh-3x83-fvh6.json index a28ef46a687..0202c8bfdea 100644 --- a/advisories/unreviewed/2024/05/GHSA-97fh-3x83-fvh6/GHSA-97fh-3x83-fvh6.json +++ b/advisories/unreviewed/2024/05/GHSA-97fh-3x83-fvh6/GHSA-97fh-3x83-fvh6.json @@ -7,12 +7,8 @@ "CVE-2024-27395" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: Fix Use-After-Free in ovs_ct_exit\n\nSince kfree_rcu, which is called in the hlist_for_each_entry_rcu traversal\nof ovs_ct_limit_exit, is not part of the RCU read critical section, it\nis possible that the RCU grace period will pass during the traversal and\nthe key will be free.\n\nTo prevent this, it should be changed to hlist_for_each_entry_safe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-9mvv-jgf2-gj5c/GHSA-9mvv-jgf2-gj5c.json b/advisories/unreviewed/2024/05/GHSA-9mvv-jgf2-gj5c/GHSA-9mvv-jgf2-gj5c.json index 0071a76881b..ce1ea49d587 100644 --- a/advisories/unreviewed/2024/05/GHSA-9mvv-jgf2-gj5c/GHSA-9mvv-jgf2-gj5c.json +++ b/advisories/unreviewed/2024/05/GHSA-9mvv-jgf2-gj5c/GHSA-9mvv-jgf2-gj5c.json @@ -7,12 +7,8 @@ "CVE-2024-26955" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: prevent kernel bug at submit_bh_wbc()\n\nFix a bug where nilfs_get_block() returns a successful status when\nsearching and inserting the specified block both fail inconsistently. If\nthis inconsistent behavior is not due to a previously fixed bug, then an\nunexpected race is occurring, so return a temporary error -EAGAIN instead.\n\nThis prevents callers such as __block_write_begin_int() from requesting a\nread into a buffer that is not mapped, which would cause the BUG_ON check\nfor the BH_Mapped flag in submit_bh_wbc() to fail.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-9qcj-9374-gfhc/GHSA-9qcj-9374-gfhc.json b/advisories/unreviewed/2024/05/GHSA-9qcj-9374-gfhc/GHSA-9qcj-9374-gfhc.json index c4c5951b738..fe40e819475 100644 --- a/advisories/unreviewed/2024/05/GHSA-9qcj-9374-gfhc/GHSA-9qcj-9374-gfhc.json +++ b/advisories/unreviewed/2024/05/GHSA-9qcj-9374-gfhc/GHSA-9qcj-9374-gfhc.json @@ -7,12 +7,8 @@ "CVE-2023-52834" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\natl1c: Work around the DMA RX overflow issue\n\nThis is based on alx driver commit 881d0327db37 (\"net: alx: Work around\nthe DMA RX overflow issue\").\n\nThe alx and atl1c drivers had RX overflow error which was why a custom\nallocator was created to avoid certain addresses. The simpler workaround\nthen created for alx driver, but not for atl1c due to lack of tester.\n\nInstead of using a custom allocator, check the allocated skb address and\nuse skb_reserve() to move away from problematic 0x...fc0 address.\n\nTested on AR8131 on Acer 4540.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-9vv7-jc87-x8x5/GHSA-9vv7-jc87-x8x5.json b/advisories/unreviewed/2024/05/GHSA-9vv7-jc87-x8x5/GHSA-9vv7-jc87-x8x5.json index 8a0466d1c1b..e0127a28315 100644 --- a/advisories/unreviewed/2024/05/GHSA-9vv7-jc87-x8x5/GHSA-9vv7-jc87-x8x5.json +++ b/advisories/unreviewed/2024/05/GHSA-9vv7-jc87-x8x5/GHSA-9vv7-jc87-x8x5.json @@ -7,12 +7,8 @@ "CVE-2024-27410" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: nl80211: reject iftype change with mesh ID change\n\nIt's currently possible to change the mesh ID when the\ninterface isn't yet in mesh mode, at the same time as\nchanging it into mesh mode. This leads to an overwrite\nof data in the wdev->u union for the interface type it\ncurrently has, causing cfg80211_change_iface() to do\nwrong things when switching.\n\nWe could probably allow setting an interface to mesh\nwhile setting the mesh ID at the same time by doing a\ndifferent order of operations here, but realistically\nthere's no userspace that's going to do this, so just\ndisallow changes in iftype when setting mesh ID.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-9vvj-gw7c-qgmh/GHSA-9vvj-gw7c-qgmh.json b/advisories/unreviewed/2024/05/GHSA-9vvj-gw7c-qgmh/GHSA-9vvj-gw7c-qgmh.json index 4373d9be4ac..be98d27ce16 100644 --- a/advisories/unreviewed/2024/05/GHSA-9vvj-gw7c-qgmh/GHSA-9vvj-gw7c-qgmh.json +++ b/advisories/unreviewed/2024/05/GHSA-9vvj-gw7c-qgmh/GHSA-9vvj-gw7c-qgmh.json @@ -7,12 +7,8 @@ "CVE-2023-52743" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: Do not use WQ_MEM_RECLAIM flag for workqueue\n\nWhen both ice and the irdma driver are loaded, a warning in\ncheck_flush_dependency is being triggered. This is due to ice driver\nworkqueue being allocated with the WQ_MEM_RECLAIM flag and the irdma one\nis not.\n\nAccording to kernel documentation, this flag should be set if the\nworkqueue will be involved in the kernel's memory reclamation flow.\nSince it is not, there is no need for the ice driver's WQ to have this\nflag set so remove it.\n\nExample trace:\n\n[ +0.000004] workqueue: WQ_MEM_RECLAIM ice:ice_service_task [ice] is flushing !WQ_MEM_RECLAIM infiniband:0x0\n[ +0.000139] WARNING: CPU: 0 PID: 728 at kernel/workqueue.c:2632 check_flush_dependency+0x178/0x1a0\n[ +0.000011] Modules linked in: bonding tls xt_CHECKSUM xt_MASQUERADE xt_conntrack ipt_REJECT nf_reject_ipv4 nft_compat nft_cha\nin_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 nf_tables nfnetlink bridge stp llc rfkill vfat fat intel_rapl_msr intel\n_rapl_common isst_if_common skx_edac nfit libnvdimm x86_pkg_temp_thermal intel_powerclamp coretemp kvm_intel kvm irqbypass crct1\n0dif_pclmul crc32_pclmul ghash_clmulni_intel rapl intel_cstate rpcrdma sunrpc rdma_ucm ib_srpt ib_isert iscsi_target_mod target_\ncore_mod ib_iser libiscsi scsi_transport_iscsi rdma_cm ib_cm iw_cm iTCO_wdt iTCO_vendor_support ipmi_ssif irdma mei_me ib_uverbs\nib_core intel_uncore joydev pcspkr i2c_i801 acpi_ipmi mei lpc_ich i2c_smbus intel_pch_thermal ioatdma ipmi_si acpi_power_meter\nacpi_pad xfs libcrc32c sd_mod t10_pi crc64_rocksoft crc64 sg ahci ixgbe libahci ice i40e igb crc32c_intel mdio i2c_algo_bit liba\nta dca wmi dm_mirror dm_region_hash dm_log dm_mod ipmi_devintf ipmi_msghandler fuse\n[ +0.000161] [last unloaded: bonding]\n[ +0.000006] CPU: 0 PID: 728 Comm: kworker/0:2 Tainted: G S 6.2.0-rc2_next-queue-13jan-00458-gc20aabd57164 #1\n[ +0.000006] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0010.010620200716 01/06/2020\n[ +0.000003] Workqueue: ice ice_service_task [ice]\n[ +0.000127] RIP: 0010:check_flush_dependency+0x178/0x1a0\n[ +0.000005] Code: 89 8e 02 01 e8 49 3d 40 00 49 8b 55 18 48 8d 8d d0 00 00 00 48 8d b3 d0 00 00 00 4d 89 e0 48 c7 c7 e0 3b 08\n9f e8 bb d3 07 01 <0f> 0b e9 be fe ff ff 80 3d 24 89 8e 02 00 0f 85 6b ff ff ff e9 06\n[ +0.000004] RSP: 0018:ffff88810a39f990 EFLAGS: 00010282\n[ +0.000005] RAX: 0000000000000000 RBX: ffff888141bc2400 RCX: 0000000000000000\n[ +0.000004] RDX: 0000000000000001 RSI: dffffc0000000000 RDI: ffffffffa1213a80\n[ +0.000003] RBP: ffff888194bf3400 R08: ffffed117b306112 R09: ffffed117b306112\n[ +0.000003] R10: ffff888bd983088b R11: ffffed117b306111 R12: 0000000000000000\n[ +0.000003] R13: ffff888111f84d00 R14: ffff88810a3943ac R15: ffff888194bf3400\n[ +0.000004] FS: 0000000000000000(0000) GS:ffff888bd9800000(0000) knlGS:0000000000000000\n[ +0.000003] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ +0.000003] CR2: 000056035b208b60 CR3: 000000017795e005 CR4: 00000000007706f0\n[ +0.000003] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ +0.000003] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ +0.000002] PKRU: 55555554\n[ +0.000003] Call Trace:\n[ +0.000002] \n[ +0.000003] __flush_workqueue+0x203/0x840\n[ +0.000006] ? mutex_unlock+0x84/0xd0\n[ +0.000008] ? __pfx_mutex_unlock+0x10/0x10\n[ +0.000004] ? __pfx___flush_workqueue+0x10/0x10\n[ +0.000006] ? mutex_lock+0xa3/0xf0\n[ +0.000005] ib_cache_cleanup_one+0x39/0x190 [ib_core]\n[ +0.000174] __ib_unregister_device+0x84/0xf0 [ib_core]\n[ +0.000094] ib_unregister_device+0x25/0x30 [ib_core]\n[ +0.000093] irdma_ib_unregister_device+0x97/0xc0 [irdma]\n[ +0.000064] ? __pfx_irdma_ib_unregister_device+0x10/0x10 [irdma]\n[ +0.000059] ? up_write+0x5c/0x90\n[ +0.000005] irdma_remove+0x36/0x90 [irdma]\n[ +0.000062] auxiliary_bus_remove+0x32/0x50\n[ +0.000007] device_r\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-c352-9339-wrc2/GHSA-c352-9339-wrc2.json b/advisories/unreviewed/2024/05/GHSA-c352-9339-wrc2/GHSA-c352-9339-wrc2.json index 1b1cdde57db..9fa90d3639e 100644 --- a/advisories/unreviewed/2024/05/GHSA-c352-9339-wrc2/GHSA-c352-9339-wrc2.json +++ b/advisories/unreviewed/2024/05/GHSA-c352-9339-wrc2/GHSA-c352-9339-wrc2.json @@ -7,12 +7,8 @@ "CVE-2023-52799" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix array-index-out-of-bounds in dbFindLeaf\n\nCurrently while searching for dmtree_t for sufficient free blocks there\nis an array out of bounds while getting element in tp->dm_stree. To add\nthe required check for out of bound we first need to determine the type\nof dmtree. Thus added an extra parameter to dbFindLeaf so that the type\nof tree can be determined and the required check can be applied.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-cf9c-p3v8-r72c/GHSA-cf9c-p3v8-r72c.json b/advisories/unreviewed/2024/05/GHSA-cf9c-p3v8-r72c/GHSA-cf9c-p3v8-r72c.json index f17e5a6cc04..b8afc2d10ec 100644 --- a/advisories/unreviewed/2024/05/GHSA-cf9c-p3v8-r72c/GHSA-cf9c-p3v8-r72c.json +++ b/advisories/unreviewed/2024/05/GHSA-cf9c-p3v8-r72c/GHSA-cf9c-p3v8-r72c.json @@ -7,12 +7,8 @@ "CVE-2024-27004" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: Get runtime PM before walking tree during disable_unused\n\nDoug reported [1] the following hung task:\n\n INFO: task swapper/0:1 blocked for more than 122 seconds.\n Not tainted 5.15.149-21875-gf795ebc40eb8 #1\n \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n task:swapper/0 state:D stack: 0 pid: 1 ppid: 0 flags:0x00000008\n Call trace:\n __switch_to+0xf4/0x1f4\n __schedule+0x418/0xb80\n schedule+0x5c/0x10c\n rpm_resume+0xe0/0x52c\n rpm_resume+0x178/0x52c\n __pm_runtime_resume+0x58/0x98\n clk_pm_runtime_get+0x30/0xb0\n clk_disable_unused_subtree+0x58/0x208\n clk_disable_unused_subtree+0x38/0x208\n clk_disable_unused_subtree+0x38/0x208\n clk_disable_unused_subtree+0x38/0x208\n clk_disable_unused_subtree+0x38/0x208\n clk_disable_unused+0x4c/0xe4\n do_one_initcall+0xcc/0x2d8\n do_initcall_level+0xa4/0x148\n do_initcalls+0x5c/0x9c\n do_basic_setup+0x24/0x30\n kernel_init_freeable+0xec/0x164\n kernel_init+0x28/0x120\n ret_from_fork+0x10/0x20\n INFO: task kworker/u16:0:9 blocked for more than 122 seconds.\n Not tainted 5.15.149-21875-gf795ebc40eb8 #1\n \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n task:kworker/u16:0 state:D stack: 0 pid: 9 ppid: 2 flags:0x00000008\n Workqueue: events_unbound deferred_probe_work_func\n Call trace:\n __switch_to+0xf4/0x1f4\n __schedule+0x418/0xb80\n schedule+0x5c/0x10c\n schedule_preempt_disabled+0x2c/0x48\n __mutex_lock+0x238/0x488\n __mutex_lock_slowpath+0x1c/0x28\n mutex_lock+0x50/0x74\n clk_prepare_lock+0x7c/0x9c\n clk_core_prepare_lock+0x20/0x44\n clk_prepare+0x24/0x30\n clk_bulk_prepare+0x40/0xb0\n mdss_runtime_resume+0x54/0x1c8\n pm_generic_runtime_resume+0x30/0x44\n __genpd_runtime_resume+0x68/0x7c\n genpd_runtime_resume+0x108/0x1f4\n __rpm_callback+0x84/0x144\n rpm_callback+0x30/0x88\n rpm_resume+0x1f4/0x52c\n rpm_resume+0x178/0x52c\n __pm_runtime_resume+0x58/0x98\n __device_attach+0xe0/0x170\n device_initial_probe+0x1c/0x28\n bus_probe_device+0x3c/0x9c\n device_add+0x644/0x814\n mipi_dsi_device_register_full+0xe4/0x170\n devm_mipi_dsi_device_register_full+0x28/0x70\n ti_sn_bridge_probe+0x1dc/0x2c0\n auxiliary_bus_probe+0x4c/0x94\n really_probe+0xcc/0x2c8\n __driver_probe_device+0xa8/0x130\n driver_probe_device+0x48/0x110\n __device_attach_driver+0xa4/0xcc\n bus_for_each_drv+0x8c/0xd8\n __device_attach+0xf8/0x170\n device_initial_probe+0x1c/0x28\n bus_probe_device+0x3c/0x9c\n deferred_probe_work_func+0x9c/0xd8\n process_one_work+0x148/0x518\n worker_thread+0x138/0x350\n kthread+0x138/0x1e0\n ret_from_fork+0x10/0x20\n\nThe first thread is walking the clk tree and calling\nclk_pm_runtime_get() to power on devices required to read the clk\nhardware via struct clk_ops::is_enabled(). This thread holds the clk\nprepare_lock, and is trying to runtime PM resume a device, when it finds\nthat the device is in the process of resuming so the thread schedule()s\naway waiting for the device to finish resuming before continuing. The\nsecond thread is runtime PM resuming the same device, but the runtime\nresume callback is calling clk_prepare(), trying to grab the\nprepare_lock waiting on the first thread.\n\nThis is a classic ABBA deadlock. To properly fix the deadlock, we must\nnever runtime PM resume or suspend a device with the clk prepare_lock\nheld. Actually doing that is near impossible today because the global\nprepare_lock would have to be dropped in the middle of the tree, the\ndevice runtime PM resumed/suspended, and then the prepare_lock grabbed\nagain to ensure consistency of the clk tree topology. If anything\nchanges with the clk tree in the meantime, we've lost and will need to\nstart the operation all over again.\n\nLuckily, most of the time we're simply incrementing or decrementing the\nruntime PM count on an active device, so we don't have the chance to\nschedule away with the prepare_lock held. Let's fix this immediate\nproblem that can be\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-chwm-xp9x-8vv7/GHSA-chwm-xp9x-8vv7.json b/advisories/unreviewed/2024/05/GHSA-chwm-xp9x-8vv7/GHSA-chwm-xp9x-8vv7.json index 776b5b0d0e2..5bd7acc7621 100644 --- a/advisories/unreviewed/2024/05/GHSA-chwm-xp9x-8vv7/GHSA-chwm-xp9x-8vv7.json +++ b/advisories/unreviewed/2024/05/GHSA-chwm-xp9x-8vv7/GHSA-chwm-xp9x-8vv7.json @@ -7,12 +7,8 @@ "CVE-2023-52789" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntty: vcc: Add check for kstrdup() in vcc_probe()\n\nAdd check for the return value of kstrdup() and return the error, if it\nfails in order to avoid NULL pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-cw5r-8wj2-xpqf/GHSA-cw5r-8wj2-xpqf.json b/advisories/unreviewed/2024/05/GHSA-cw5r-8wj2-xpqf/GHSA-cw5r-8wj2-xpqf.json index f25518f6dda..b64387afc69 100644 --- a/advisories/unreviewed/2024/05/GHSA-cw5r-8wj2-xpqf/GHSA-cw5r-8wj2-xpqf.json +++ b/advisories/unreviewed/2024/05/GHSA-cw5r-8wj2-xpqf/GHSA-cw5r-8wj2-xpqf.json @@ -7,12 +7,8 @@ "CVE-2023-52707" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/psi: Fix use-after-free in ep_remove_wait_queue()\n\nIf a non-root cgroup gets removed when there is a thread that registered\ntrigger and is polling on a pressure file within the cgroup, the polling\nwaitqueue gets freed in the following path:\n\n do_rmdir\n cgroup_rmdir\n kernfs_drain_open_files\n cgroup_file_release\n cgroup_pressure_release\n psi_trigger_destroy\n\nHowever, the polling thread still has a reference to the pressure file and\nwill access the freed waitqueue when the file is closed or upon exit:\n\n fput\n ep_eventpoll_release\n ep_free\n ep_remove_wait_queue\n remove_wait_queue\n\nThis results in use-after-free as pasted below.\n\nThe fundamental problem here is that cgroup_file_release() (and\nconsequently waitqueue's lifetime) is not tied to the file's real lifetime.\nUsing wake_up_pollfree() here might be less than ideal, but it is in line\nwith the comment at commit 42288cb44c4b (\"wait: add wake_up_pollfree()\")\nsince the waitqueue's lifetime is not tied to file's one and can be\nconsidered as another special case. While this would be fixable by somehow\nmaking cgroup_file_release() be tied to the fput(), it would require\nsizable refactoring at cgroups or higher layer which might be more\njustifiable if we identify more cases like this.\n\n BUG: KASAN: use-after-free in _raw_spin_lock_irqsave+0x60/0xc0\n Write of size 4 at addr ffff88810e625328 by task a.out/4404\n\n\tCPU: 19 PID: 4404 Comm: a.out Not tainted 6.2.0-rc6 #38\n\tHardware name: Amazon EC2 c5a.8xlarge/, BIOS 1.0 10/16/2017\n\tCall Trace:\n\t\n\tdump_stack_lvl+0x73/0xa0\n\tprint_report+0x16c/0x4e0\n\tkasan_report+0xc3/0xf0\n\tkasan_check_range+0x2d2/0x310\n\t_raw_spin_lock_irqsave+0x60/0xc0\n\tremove_wait_queue+0x1a/0xa0\n\tep_free+0x12c/0x170\n\tep_eventpoll_release+0x26/0x30\n\t__fput+0x202/0x400\n\ttask_work_run+0x11d/0x170\n\tdo_exit+0x495/0x1130\n\tdo_group_exit+0x100/0x100\n\tget_signal+0xd67/0xde0\n\tarch_do_signal_or_restart+0x2a/0x2b0\n\texit_to_user_mode_prepare+0x94/0x100\n\tsyscall_exit_to_user_mode+0x20/0x40\n\tdo_syscall_64+0x52/0x90\n\tentry_SYSCALL_64_after_hwframe+0x63/0xcd\n\t\n\n Allocated by task 4404:\n\n\tkasan_set_track+0x3d/0x60\n\t__kasan_kmalloc+0x85/0x90\n\tpsi_trigger_create+0x113/0x3e0\n\tpressure_write+0x146/0x2e0\n\tcgroup_file_write+0x11c/0x250\n\tkernfs_fop_write_iter+0x186/0x220\n\tvfs_write+0x3d8/0x5c0\n\tksys_write+0x90/0x110\n\tdo_syscall_64+0x43/0x90\n\tentry_SYSCALL_64_after_hwframe+0x63/0xcd\n\n Freed by task 4407:\n\n\tkasan_set_track+0x3d/0x60\n\tkasan_save_free_info+0x27/0x40\n\t____kasan_slab_free+0x11d/0x170\n\tslab_free_freelist_hook+0x87/0x150\n\t__kmem_cache_free+0xcb/0x180\n\tpsi_trigger_destroy+0x2e8/0x310\n\tcgroup_file_release+0x4f/0xb0\n\tkernfs_drain_open_files+0x165/0x1f0\n\tkernfs_drain+0x162/0x1a0\n\t__kernfs_remove+0x1fb/0x310\n\tkernfs_remove_by_name_ns+0x95/0xe0\n\tcgroup_addrm_files+0x67f/0x700\n\tcgroup_destroy_locked+0x283/0x3c0\n\tcgroup_rmdir+0x29/0x100\n\tkernfs_iop_rmdir+0xd1/0x140\n\tvfs_rmdir+0xfe/0x240\n\tdo_rmdir+0x13d/0x280\n\t__x64_sys_rmdir+0x2c/0x30\n\tdo_syscall_64+0x43/0x90\n\tentry_SYSCALL_64_after_hwframe+0x63/0xcd", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-cwq4-fr9x-6844/GHSA-cwq4-fr9x-6844.json b/advisories/unreviewed/2024/05/GHSA-cwq4-fr9x-6844/GHSA-cwq4-fr9x-6844.json index b3d670da335..342d40e3adf 100644 --- a/advisories/unreviewed/2024/05/GHSA-cwq4-fr9x-6844/GHSA-cwq4-fr9x-6844.json +++ b/advisories/unreviewed/2024/05/GHSA-cwq4-fr9x-6844/GHSA-cwq4-fr9x-6844.json @@ -7,12 +7,8 @@ "CVE-2021-47396" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmac80211-hwsim: fix late beacon hrtimer handling\n\nThomas explained in https://lore.kernel.org/r/87mtoeb4hb.ffs@tglx\nthat our handling of the hrtimer here is wrong: If the timer fires\nlate (e.g. due to vCPU scheduling, as reported by Dmitry/syzbot)\nthen it tries to actually rearm the timer at the next deadline,\nwhich might be in the past already:\n\n 1 2 3 N N+1\n | | | ... | |\n\n ^ intended to fire here (1)\n ^ next deadline here (2)\n ^ actually fired here\n\nThe next time it fires, it's later, but will still try to schedule\nfor the next deadline (now 3), etc. until it catches up with N,\nbut that might take a long time, causing stalls etc.\n\nNow, all of this is simulation, so we just have to fix it, but\nnote that the behaviour is wrong even per spec, since there's no\nvalue then in sending all those beacons unaligned - they should be\naligned to the TBTT (1, 2, 3, ... in the picture), and if we're a\nbit (or a lot) late, then just resume at that point.\n\nTherefore, change the code to use hrtimer_forward_now() which will\nensure that the next firing of the timer would be at N+1 (in the\npicture), i.e. the next interval point after the current time.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-frc8-7f65-3g5r/GHSA-frc8-7f65-3g5r.json b/advisories/unreviewed/2024/05/GHSA-frc8-7f65-3g5r/GHSA-frc8-7f65-3g5r.json index 36b8a2044d8..e51d0af085a 100644 --- a/advisories/unreviewed/2024/05/GHSA-frc8-7f65-3g5r/GHSA-frc8-7f65-3g5r.json +++ b/advisories/unreviewed/2024/05/GHSA-frc8-7f65-3g5r/GHSA-frc8-7f65-3g5r.json @@ -7,12 +7,8 @@ "CVE-2023-52794" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: intel: powerclamp: fix mismatch in get function for max_idle\n\nKASAN reported this\n\n [ 444.853098] BUG: KASAN: global-out-of-bounds in param_get_int+0x77/0x90\n [ 444.853111] Read of size 4 at addr ffffffffc16c9220 by task cat/2105\n ...\n [ 444.853442] The buggy address belongs to the variable:\n [ 444.853443] max_idle+0x0/0xffffffffffffcde0 [intel_powerclamp]\n\nThere is a mismatch between the param_get_int and the definition of\nmax_idle. Replacing param_get_int with param_get_byte resolves this\nissue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-fvjh-jw4x-5w6j/GHSA-fvjh-jw4x-5w6j.json b/advisories/unreviewed/2024/05/GHSA-fvjh-jw4x-5w6j/GHSA-fvjh-jw4x-5w6j.json index 2ff0a84c1b6..916ecfbf691 100644 --- a/advisories/unreviewed/2024/05/GHSA-fvjh-jw4x-5w6j/GHSA-fvjh-jw4x-5w6j.json +++ b/advisories/unreviewed/2024/05/GHSA-fvjh-jw4x-5w6j/GHSA-fvjh-jw4x-5w6j.json @@ -7,12 +7,8 @@ "CVE-2024-27030" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: Use separate handlers for interrupts\n\nFor PF to AF interrupt vector and VF to AF vector same\ninterrupt handler is registered which is causing race condition.\nWhen two interrupts are raised to two CPUs at same time\nthen two cores serve same event corrupting the data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-fwq5-vg2m-5cr5/GHSA-fwq5-vg2m-5cr5.json b/advisories/unreviewed/2024/05/GHSA-fwq5-vg2m-5cr5/GHSA-fwq5-vg2m-5cr5.json index c30dc0588b9..3b5e23af10e 100644 --- a/advisories/unreviewed/2024/05/GHSA-fwq5-vg2m-5cr5/GHSA-fwq5-vg2m-5cr5.json +++ b/advisories/unreviewed/2024/05/GHSA-fwq5-vg2m-5cr5/GHSA-fwq5-vg2m-5cr5.json @@ -7,12 +7,8 @@ "CVE-2023-52732" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: blocklist the kclient when receiving corrupted snap trace\n\nWhen received corrupted snap trace we don't know what exactly has\nhappened in MDS side. And we shouldn't continue IOs and metadatas\naccess to MDS, which may corrupt or get incorrect contents.\n\nThis patch will just block all the further IO/MDS requests\nimmediately and then evict the kclient itself.\n\nThe reason why we still need to evict the kclient just after\nblocking all the further IOs is that the MDS could revoke the caps\nfaster.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-g77r-j94w-3wm3/GHSA-g77r-j94w-3wm3.json b/advisories/unreviewed/2024/05/GHSA-g77r-j94w-3wm3/GHSA-g77r-j94w-3wm3.json index 0d2c94528b5..e6a967ebafb 100644 --- a/advisories/unreviewed/2024/05/GHSA-g77r-j94w-3wm3/GHSA-g77r-j94w-3wm3.json +++ b/advisories/unreviewed/2024/05/GHSA-g77r-j94w-3wm3/GHSA-g77r-j94w-3wm3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-g8c8-mwvp-jcrr/GHSA-g8c8-mwvp-jcrr.json b/advisories/unreviewed/2024/05/GHSA-g8c8-mwvp-jcrr/GHSA-g8c8-mwvp-jcrr.json index 919655c0cbc..85dba4bbf63 100644 --- a/advisories/unreviewed/2024/05/GHSA-g8c8-mwvp-jcrr/GHSA-g8c8-mwvp-jcrr.json +++ b/advisories/unreviewed/2024/05/GHSA-g8c8-mwvp-jcrr/GHSA-g8c8-mwvp-jcrr.json @@ -7,12 +7,8 @@ "CVE-2021-47429" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/64s: Fix unrecoverable MCE calling async handler from NMI\n\nThe machine check handler is not considered NMI on 64s. The early\nhandler is the true NMI handler, and then it schedules the\nmachine_check_exception handler to run when interrupts are enabled.\n\nThis works fine except the case of an unrecoverable MCE, where the true\nNMI is taken when MSR[RI] is clear, it can not recover, so it calls\nmachine_check_exception directly so something might be done about it.\n\nCalling an async handler from NMI context can result in irq state and\nother things getting corrupted. This can also trigger the BUG at\n arch/powerpc/include/asm/interrupt.h:168\n BUG_ON(!arch_irq_disabled_regs(regs) && !(regs->msr & MSR_EE));\n\nFix this by making an _async version of the handler which is called\nin the normal case, and a NMI version that is called for unrecoverable\ninterrupts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gcw5-rpqg-f587/GHSA-gcw5-rpqg-f587.json b/advisories/unreviewed/2024/05/GHSA-gcw5-rpqg-f587/GHSA-gcw5-rpqg-f587.json index 40c0aa5e6b2..9a7436208e4 100644 --- a/advisories/unreviewed/2024/05/GHSA-gcw5-rpqg-f587/GHSA-gcw5-rpqg-f587.json +++ b/advisories/unreviewed/2024/05/GHSA-gcw5-rpqg-f587/GHSA-gcw5-rpqg-f587.json @@ -7,12 +7,8 @@ "CVE-2023-52777" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix gtk offload status event locking\n\nThe ath11k active pdevs are protected by RCU but the gtk offload status\nevent handling code calling ath11k_mac_get_arvif_by_vdev_id() was not\nmarked as a read-side critical section.\n\nMark the code in question as an RCU read-side critical section to avoid\nany potential use-after-free issues.\n\nCompile tested only.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gmgh-9qgw-5r7q/GHSA-gmgh-9qgw-5r7q.json b/advisories/unreviewed/2024/05/GHSA-gmgh-9qgw-5r7q/GHSA-gmgh-9qgw-5r7q.json index 394caf402fc..6ce4be2e5d5 100644 --- a/advisories/unreviewed/2024/05/GHSA-gmgh-9qgw-5r7q/GHSA-gmgh-9qgw-5r7q.json +++ b/advisories/unreviewed/2024/05/GHSA-gmgh-9qgw-5r7q/GHSA-gmgh-9qgw-5r7q.json @@ -7,12 +7,8 @@ "CVE-2024-27025" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnbd: null check for nla_nest_start\n\nnla_nest_start() may fail and return NULL. Insert a check and set errno\nbased on other call sites within the same source code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gpvh-jcjq-x69v/GHSA-gpvh-jcjq-x69v.json b/advisories/unreviewed/2024/05/GHSA-gpvh-jcjq-x69v/GHSA-gpvh-jcjq-x69v.json index 8774160f60b..837b64f0790 100644 --- a/advisories/unreviewed/2024/05/GHSA-gpvh-jcjq-x69v/GHSA-gpvh-jcjq-x69v.json +++ b/advisories/unreviewed/2024/05/GHSA-gpvh-jcjq-x69v/GHSA-gpvh-jcjq-x69v.json @@ -7,12 +7,8 @@ "CVE-2023-52736" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda: Do not unset preset when cleaning up codec\n\nSeveral functions that take part in codec's initialization and removal\nare re-used by ASoC codec drivers implementations. Drivers mimic the\nbehavior of hda_codec_driver_probe/remove() found in\nsound/pci/hda/hda_bind.c with their component->probe/remove() instead.\n\nOne of the reasons for that is the expectation of\nsnd_hda_codec_device_new() to receive a valid pointer to an instance of\nstruct snd_card. This expectation can be met only once sound card\ncomponents probing commences.\n\nAs ASoC sound card may be unbound without codec device being actually\nremoved from the system, unsetting ->preset in\nsnd_hda_codec_cleanup_for_unbind() interferes with module unload -> load\nscenario causing null-ptr-deref. Preset is assigned only once, during\ndevice/driver matching whereas ASoC codec driver's module reloading may\noccur several times throughout the lifetime of an audio stack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gv6c-55ww-r8wv/GHSA-gv6c-55ww-r8wv.json b/advisories/unreviewed/2024/05/GHSA-gv6c-55ww-r8wv/GHSA-gv6c-55ww-r8wv.json index 63e73466936..f9cbde8136a 100644 --- a/advisories/unreviewed/2024/05/GHSA-gv6c-55ww-r8wv/GHSA-gv6c-55ww-r8wv.json +++ b/advisories/unreviewed/2024/05/GHSA-gv6c-55ww-r8wv/GHSA-gv6c-55ww-r8wv.json @@ -7,12 +7,8 @@ "CVE-2023-52786" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix racy may inline data check in dio write\n\nsyzbot reports that the following warning from ext4_iomap_begin()\ntriggers as of the commit referenced below:\n\n if (WARN_ON_ONCE(ext4_has_inline_data(inode)))\n return -ERANGE;\n\nThis occurs during a dio write, which is never expected to encounter\nan inode with inline data. To enforce this behavior,\next4_dio_write_iter() checks the current inline state of the inode\nand clears the MAY_INLINE_DATA state flag to either fall back to\nbuffered writes, or enforce that any other writers in progress on\nthe inode are not allowed to create inline data.\n\nThe problem is that the check for existing inline data and the state\nflag can span a lock cycle. For example, if the ilock is originally\nlocked shared and subsequently upgraded to exclusive, another writer\nmay have reacquired the lock and created inline data before the dio\nwrite task acquires the lock and proceeds.\n\nThe commit referenced below loosens the lock requirements to allow\nsome forms of unaligned dio writes to occur under shared lock, but\nAFAICT the inline data check was technically already racy for any\ndio write that would have involved a lock cycle. Regardless, lift\nclearing of the state bit to the same lock critical section that\nchecks for preexisting inline data on the inode to close the race.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gw29-2hc7-pv7h/GHSA-gw29-2hc7-pv7h.json b/advisories/unreviewed/2024/05/GHSA-gw29-2hc7-pv7h/GHSA-gw29-2hc7-pv7h.json index 7eabf428957..70538d26b58 100644 --- a/advisories/unreviewed/2024/05/GHSA-gw29-2hc7-pv7h/GHSA-gw29-2hc7-pv7h.json +++ b/advisories/unreviewed/2024/05/GHSA-gw29-2hc7-pv7h/GHSA-gw29-2hc7-pv7h.json @@ -7,12 +7,8 @@ "CVE-2023-52842" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio/vsock: Fix uninit-value in virtio_transport_recv_pkt()\n\nKMSAN reported the following uninit-value access issue:\n\n=====================================================\nBUG: KMSAN: uninit-value in virtio_transport_recv_pkt+0x1dfb/0x26a0 net/vmw_vsock/virtio_transport_common.c:1421\n virtio_transport_recv_pkt+0x1dfb/0x26a0 net/vmw_vsock/virtio_transport_common.c:1421\n vsock_loopback_work+0x3bb/0x5a0 net/vmw_vsock/vsock_loopback.c:120\n process_one_work kernel/workqueue.c:2630 [inline]\n process_scheduled_works+0xff6/0x1e60 kernel/workqueue.c:2703\n worker_thread+0xeca/0x14d0 kernel/workqueue.c:2784\n kthread+0x3cc/0x520 kernel/kthread.c:388\n ret_from_fork+0x66/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:304\n\nUninit was stored to memory at:\n virtio_transport_space_update net/vmw_vsock/virtio_transport_common.c:1274 [inline]\n virtio_transport_recv_pkt+0x1ee8/0x26a0 net/vmw_vsock/virtio_transport_common.c:1415\n vsock_loopback_work+0x3bb/0x5a0 net/vmw_vsock/vsock_loopback.c:120\n process_one_work kernel/workqueue.c:2630 [inline]\n process_scheduled_works+0xff6/0x1e60 kernel/workqueue.c:2703\n worker_thread+0xeca/0x14d0 kernel/workqueue.c:2784\n kthread+0x3cc/0x520 kernel/kthread.c:388\n ret_from_fork+0x66/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:304\n\nUninit was created at:\n slab_post_alloc_hook+0x105/0xad0 mm/slab.h:767\n slab_alloc_node mm/slub.c:3478 [inline]\n kmem_cache_alloc_node+0x5a2/0xaf0 mm/slub.c:3523\n kmalloc_reserve+0x13c/0x4a0 net/core/skbuff.c:559\n __alloc_skb+0x2fd/0x770 net/core/skbuff.c:650\n alloc_skb include/linux/skbuff.h:1286 [inline]\n virtio_vsock_alloc_skb include/linux/virtio_vsock.h:66 [inline]\n virtio_transport_alloc_skb+0x90/0x11e0 net/vmw_vsock/virtio_transport_common.c:58\n virtio_transport_reset_no_sock net/vmw_vsock/virtio_transport_common.c:957 [inline]\n virtio_transport_recv_pkt+0x1279/0x26a0 net/vmw_vsock/virtio_transport_common.c:1387\n vsock_loopback_work+0x3bb/0x5a0 net/vmw_vsock/vsock_loopback.c:120\n process_one_work kernel/workqueue.c:2630 [inline]\n process_scheduled_works+0xff6/0x1e60 kernel/workqueue.c:2703\n worker_thread+0xeca/0x14d0 kernel/workqueue.c:2784\n kthread+0x3cc/0x520 kernel/kthread.c:388\n ret_from_fork+0x66/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:304\n\nCPU: 1 PID: 10664 Comm: kworker/1:5 Not tainted 6.6.0-rc3-00146-g9f3ebbef746f #3\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.2-1.fc38 04/01/2014\nWorkqueue: vsock-loopback vsock_loopback_work\n=====================================================\n\nThe following simple reproducer can cause the issue described above:\n\nint main(void)\n{\n int sock;\n struct sockaddr_vm addr = {\n .svm_family = AF_VSOCK,\n .svm_cid = VMADDR_CID_ANY,\n .svm_port = 1234,\n };\n\n sock = socket(AF_VSOCK, SOCK_STREAM, 0);\n connect(sock, (struct sockaddr *)&addr, sizeof(addr));\n return 0;\n}\n\nThis issue occurs because the `buf_alloc` and `fwd_cnt` fields of the\n`struct virtio_vsock_hdr` are not initialized when a new skb is allocated\nin `virtio_transport_init_hdr()`. This patch resolves the issue by\ninitializing these fields during allocation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-h2gq-cg6c-vh9c/GHSA-h2gq-cg6c-vh9c.json b/advisories/unreviewed/2024/05/GHSA-h2gq-cg6c-vh9c/GHSA-h2gq-cg6c-vh9c.json index 510df8d4d09..b75032f295f 100644 --- a/advisories/unreviewed/2024/05/GHSA-h2gq-cg6c-vh9c/GHSA-h2gq-cg6c-vh9c.json +++ b/advisories/unreviewed/2024/05/GHSA-h2gq-cg6c-vh9c/GHSA-h2gq-cg6c-vh9c.json @@ -7,12 +7,8 @@ "CVE-2023-52780" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mvneta: fix calls to page_pool_get_stats\n\nCalling page_pool_get_stats in the mvneta driver without checks\nleads to kernel crashes.\nFirst the page pool is only available if the bm is not used.\nThe page pool is also not allocated when the port is stopped.\nIt can also be not allocated in case of errors.\n\nThe current implementation leads to the following crash calling\nethstats on a port that is down or when calling it at the wrong moment:\n\nble to handle kernel NULL pointer dereference at virtual address 00000070\n[00000070] *pgd=00000000\nInternal error: Oops: 5 [#1] SMP ARM\nHardware name: Marvell Armada 380/385 (Device Tree)\nPC is at page_pool_get_stats+0x18/0x1cc\nLR is at mvneta_ethtool_get_stats+0xa0/0xe0 [mvneta]\npc : [] lr : [] psr: a0000013\nsp : f1439d48 ip : f1439dc0 fp : 0000001d\nr10: 00000100 r9 : c4816b80 r8 : f0d75150\nr7 : bf0b400c r6 : c238f000 r5 : 00000000 r4 : f1439d68\nr3 : c2091040 r2 : ffffffd8 r1 : f1439d68 r0 : 00000000\nFlags: NzCv IRQs on FIQs on Mode SVC_32 ISA ARM Segment none\nControl: 10c5387d Table: 066b004a DAC: 00000051\nRegister r0 information: NULL pointer\nRegister r1 information: 2-page vmalloc region starting at 0xf1438000 allocated at kernel_clone+0x9c/0x390\nRegister r2 information: non-paged memory\nRegister r3 information: slab kmalloc-2k start c2091000 pointer offset 64 size 2048\nRegister r4 information: 2-page vmalloc region starting at 0xf1438000 allocated at kernel_clone+0x9c/0x390\nRegister r5 information: NULL pointer\nRegister r6 information: slab kmalloc-cg-4k start c238f000 pointer offset 0 size 4096\nRegister r7 information: 15-page vmalloc region starting at 0xbf0a8000 allocated at load_module+0xa30/0x219c\nRegister r8 information: 1-page vmalloc region starting at 0xf0d75000 allocated at ethtool_get_stats+0x138/0x208\nRegister r9 information: slab task_struct start c4816b80 pointer offset 0\nRegister r10 information: non-paged memory\nRegister r11 information: non-paged memory\nRegister r12 information: 2-page vmalloc region starting at 0xf1438000 allocated at kernel_clone+0x9c/0x390\nProcess snmpd (pid: 733, stack limit = 0x38de3a88)\nStack: (0xf1439d48 to 0xf143a000)\n9d40: 000000c0 00000001 c238f000 bf0b400c f0d75150 c4816b80\n9d60: 00000100 bf0a98d8 00000000 00000000 00000000 00000000 00000000 00000000\n9d80: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000\n9da0: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000\n9dc0: 00000dc0 5335509c 00000035 c238f000 bf0b2214 01067f50 f0d75000 c0b9b9c8\n9de0: 0000001d 00000035 c2212094 5335509c c4816b80 c238f000 c5ad6e00 01067f50\n9e00: c1b0be80 c4816b80 00014813 c0b9d7f0 00000000 00000000 0000001d 0000001d\n9e20: 00000000 00001200 00000000 00000000 c216ed90 c73943b8 00000000 00000000\n9e40: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000\n9e60: 00000000 c0ad9034 00000000 00000000 00000000 00000000 00000000 00000000\n9e80: 00000000 00000000 00000000 5335509c c1b0be80 f1439ee4 00008946 c1b0be80\n9ea0: 01067f50 f1439ee3 00000000 00000046 b6d77ae0 c0b383f0 00008946 becc83e8\n9ec0: c1b0be80 00000051 0000000b c68ca480 c7172d00 c0ad8ff0 f1439ee3 cf600e40\n9ee0: 01600e40 32687465 00000000 00000000 00000000 01067f50 00000000 00000000\n9f00: 00000000 5335509c 00008946 00008946 00000000 c68ca480 becc83e8 c05e2de0\n9f20: f1439fb0 c03002f0 00000006 5ac3c35a c4816b80 00000006 b6d77ae0 c030caf0\n9f40: c4817350 00000014 f1439e1c 0000000c 00000000 00000051 01000000 00000014\n9f60: 00003fec f1439edc 00000001 c0372abc b6d77ae0 c0372abc cf600e40 5335509c\n9f80: c21e6800 01015c9c 0000000b 00008946 00000036 c03002f0 c4816b80 00000036\n9fa0: b6d77ae0 c03000c0 01015c9c 0000000b 0000000b 00008946 becc83e8 00000000\n9fc0: 01015c9c 0000000b 00008946 00000036 00000035 010678a0 b6d797ec b6d77ae0\n9fe0: b6dbf738 becc838c b6d186d7 b6baa858 40000030 0000000b 00000000 00000000\n page_pool_get_s\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-h37j-8pp8-r22g/GHSA-h37j-8pp8-r22g.json b/advisories/unreviewed/2024/05/GHSA-h37j-8pp8-r22g/GHSA-h37j-8pp8-r22g.json index 2d6cddea696..67843d3f6df 100644 --- a/advisories/unreviewed/2024/05/GHSA-h37j-8pp8-r22g/GHSA-h37j-8pp8-r22g.json +++ b/advisories/unreviewed/2024/05/GHSA-h37j-8pp8-r22g/GHSA-h37j-8pp8-r22g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-h5cg-5c4w-8jch/GHSA-h5cg-5c4w-8jch.json b/advisories/unreviewed/2024/05/GHSA-h5cg-5c4w-8jch/GHSA-h5cg-5c4w-8jch.json index 4d88c49820c..0804c59b0b8 100644 --- a/advisories/unreviewed/2024/05/GHSA-h5cg-5c4w-8jch/GHSA-h5cg-5c4w-8jch.json +++ b/advisories/unreviewed/2024/05/GHSA-h5cg-5c4w-8jch/GHSA-h5cg-5c4w-8jch.json @@ -7,12 +7,8 @@ "CVE-2024-26988" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ninit/main.c: Fix potential static_command_line memory overflow\n\nWe allocate memory of size 'xlen + strlen(boot_command_line) + 1' for\nstatic_command_line, but the strings copied into static_command_line are\nextra_command_line and command_line, rather than extra_command_line and\nboot_command_line.\n\nWhen strlen(command_line) > strlen(boot_command_line), static_command_line\nwill overflow.\n\nThis patch just recovers strlen(command_line) which was miss-consolidated\nwith strlen(boot_command_line) in the commit f5c7310ac73e (\"init/main: add\nchecks for the return value of memblock_alloc*()\")", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-h7cv-m349-g3xp/GHSA-h7cv-m349-g3xp.json b/advisories/unreviewed/2024/05/GHSA-h7cv-m349-g3xp/GHSA-h7cv-m349-g3xp.json index 3efc4571616..dd2e3330ef0 100644 --- a/advisories/unreviewed/2024/05/GHSA-h7cv-m349-g3xp/GHSA-h7cv-m349-g3xp.json +++ b/advisories/unreviewed/2024/05/GHSA-h7cv-m349-g3xp/GHSA-h7cv-m349-g3xp.json @@ -7,12 +7,8 @@ "CVE-2023-52766" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: mipi-i3c-hci: Fix out of bounds access in hci_dma_irq_handler\n\nDo not loop over ring headers in hci_dma_irq_handler() that are not\nallocated and enabled in hci_dma_init(). Otherwise out of bounds access\nwill occur from rings->headers[i] access when i >= number of allocated\nring headers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-h8c3-hrx9-cf8g/GHSA-h8c3-hrx9-cf8g.json b/advisories/unreviewed/2024/05/GHSA-h8c3-hrx9-cf8g/GHSA-h8c3-hrx9-cf8g.json index 039ba0dfc0d..4e493d828b3 100644 --- a/advisories/unreviewed/2024/05/GHSA-h8c3-hrx9-cf8g/GHSA-h8c3-hrx9-cf8g.json +++ b/advisories/unreviewed/2024/05/GHSA-h8c3-hrx9-cf8g/GHSA-h8c3-hrx9-cf8g.json @@ -7,12 +7,8 @@ "CVE-2024-26981" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix OOB in nilfs_set_de_type\n\nThe size of the nilfs_type_by_mode array in the fs/nilfs2/dir.c file is\ndefined as \"S_IFMT >> S_SHIFT\", but the nilfs_set_de_type() function,\nwhich uses this array, specifies the index to read from the array in the\nsame way as \"(mode & S_IFMT) >> S_SHIFT\".\n\nstatic void nilfs_set_de_type(struct nilfs_dir_entry *de, struct inode\n *inode)\n{\n\tumode_t mode = inode->i_mode;\n\n\tde->file_type = nilfs_type_by_mode[(mode & S_IFMT)>>S_SHIFT]; // oob\n}\n\nHowever, when the index is determined this way, an out-of-bounds (OOB)\nerror occurs by referring to an index that is 1 larger than the array size\nwhen the condition \"mode & S_IFMT == S_IFMT\" is satisfied. Therefore, a\npatch to resize the nilfs_type_by_mode array should be applied to prevent\nOOB errors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-h938-55xf-p3vh/GHSA-h938-55xf-p3vh.json b/advisories/unreviewed/2024/05/GHSA-h938-55xf-p3vh/GHSA-h938-55xf-p3vh.json index f651721bd04..447741f32b1 100644 --- a/advisories/unreviewed/2024/05/GHSA-h938-55xf-p3vh/GHSA-h938-55xf-p3vh.json +++ b/advisories/unreviewed/2024/05/GHSA-h938-55xf-p3vh/GHSA-h938-55xf-p3vh.json @@ -7,12 +7,8 @@ "CVE-2023-52782" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Track xmit submission to PTP WQ after populating metadata map\n\nEnsure the skb is available in metadata mapping to skbs before tracking the\nmetadata index for detecting undelivered CQEs. If the metadata index is put\nin the tracking list before putting the skb in the map, the metadata index\nmight be used for detecting undelivered CQEs before the relevant skb is\navailable in the map, which can lead to a null-ptr-deref.\n\nLog:\n general protection fault, probably for non-canonical address 0xdffffc0000000005: 0000 [#1] SMP KASAN\n KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f]\n CPU: 0 PID: 1243 Comm: kworker/0:2 Not tainted 6.6.0-rc4+ #108\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n Workqueue: events mlx5e_rx_dim_work [mlx5_core]\n RIP: 0010:mlx5e_ptp_napi_poll+0x9a4/0x2290 [mlx5_core]\n Code: 8c 24 38 cc ff ff 4c 8d 3c c1 4c 89 f9 48 c1 e9 03 42 80 3c 31 00 0f 85 97 0f 00 00 4d 8b 3f 49 8d 7f 28 48 89 f9 48 c1 e9 03 <42> 80 3c 31 00 0f 85 8b 0f 00 00 49 8b 47 28 48 85 c0 0f 84 05 07\n RSP: 0018:ffff8884d3c09c88 EFLAGS: 00010206\n RAX: 0000000000000069 RBX: ffff8881160349d8 RCX: 0000000000000005\n RDX: ffffed10218f48cf RSI: 0000000000000004 RDI: 0000000000000028\n RBP: ffff888122707700 R08: 0000000000000001 R09: ffffed109a781383\n R10: 0000000000000003 R11: 0000000000000003 R12: ffff88810c7a7a40\n R13: ffff888122707700 R14: dffffc0000000000 R15: 0000000000000000\n FS: 0000000000000000(0000) GS:ffff8884d3c00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f4f878dd6e0 CR3: 000000014d108002 CR4: 0000000000370eb0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n \n ? die_addr+0x3c/0xa0\n ? exc_general_protection+0x144/0x210\n ? asm_exc_general_protection+0x22/0x30\n ? mlx5e_ptp_napi_poll+0x9a4/0x2290 [mlx5_core]\n ? mlx5e_ptp_napi_poll+0x8f6/0x2290 [mlx5_core]\n __napi_poll.constprop.0+0xa4/0x580\n net_rx_action+0x460/0xb80\n ? _raw_spin_unlock_irqrestore+0x32/0x60\n ? __napi_poll.constprop.0+0x580/0x580\n ? tasklet_action_common.isra.0+0x2ef/0x760\n __do_softirq+0x26c/0x827\n irq_exit_rcu+0xc2/0x100\n common_interrupt+0x7f/0xa0\n \n \n asm_common_interrupt+0x22/0x40\n RIP: 0010:__kmem_cache_alloc_node+0xb/0x330\n Code: 41 5d 41 5e 41 5f c3 8b 44 24 14 8b 4c 24 10 09 c8 eb d5 e8 b7 43 ca 01 0f 1f 80 00 00 00 00 0f 1f 44 00 00 55 48 89 e5 41 57 <41> 56 41 89 d6 41 55 41 89 f5 41 54 49 89 fc 53 48 83 e4 f0 48 83\n RSP: 0018:ffff88812c4079c0 EFLAGS: 00000246\n RAX: 1ffffffff083c7fe RBX: ffff888100042dc0 RCX: 0000000000000218\n RDX: 00000000ffffffff RSI: 0000000000000dc0 RDI: ffff888100042dc0\n RBP: ffff88812c4079c8 R08: ffffffffa0289f96 R09: ffffed1025880ea9\n R10: ffff888138839f80 R11: 0000000000000002 R12: 0000000000000dc0\n R13: 0000000000000100 R14: 000000000000008c R15: ffff8881271fc450\n ? cmd_exec+0x796/0x2200 [mlx5_core]\n kmalloc_trace+0x26/0xc0\n cmd_exec+0x796/0x2200 [mlx5_core]\n mlx5_cmd_do+0x22/0xc0 [mlx5_core]\n mlx5_cmd_exec+0x17/0x30 [mlx5_core]\n mlx5_core_modify_cq_moderation+0x139/0x1b0 [mlx5_core]\n ? mlx5_add_cq_to_tasklet+0x280/0x280 [mlx5_core]\n ? lockdep_set_lock_cmp_fn+0x190/0x190\n ? process_one_work+0x659/0x1220\n mlx5e_rx_dim_work+0x9d/0x100 [mlx5_core]\n process_one_work+0x730/0x1220\n ? lockdep_hardirqs_on_prepare+0x400/0x400\n ? max_active_store+0xf0/0xf0\n ? assign_work+0x168/0x240\n worker_thread+0x70f/0x12d0\n ? __kthread_parkme+0xd1/0x1d0\n ? process_one_work+0x1220/0x1220\n kthread+0x2d9/0x3b0\n ? kthread_complete_and_exit+0x20/0x20\n ret_from_fork+0x2d/0x70\n ? kthread_complete_and_exit+0x20/0x20\n ret_from_fork_as\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-h98m-4vr6-fqjf/GHSA-h98m-4vr6-fqjf.json b/advisories/unreviewed/2024/05/GHSA-h98m-4vr6-fqjf/GHSA-h98m-4vr6-fqjf.json index cf864fef4de..e9c3cb21310 100644 --- a/advisories/unreviewed/2024/05/GHSA-h98m-4vr6-fqjf/GHSA-h98m-4vr6-fqjf.json +++ b/advisories/unreviewed/2024/05/GHSA-h98m-4vr6-fqjf/GHSA-h98m-4vr6-fqjf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-hgcx-34qp-j38m/GHSA-hgcx-34qp-j38m.json b/advisories/unreviewed/2024/05/GHSA-hgcx-34qp-j38m/GHSA-hgcx-34qp-j38m.json index b05d11d6c08..56f2d73bd7a 100644 --- a/advisories/unreviewed/2024/05/GHSA-hgcx-34qp-j38m/GHSA-hgcx-34qp-j38m.json +++ b/advisories/unreviewed/2024/05/GHSA-hgcx-34qp-j38m/GHSA-hgcx-34qp-j38m.json @@ -7,12 +7,8 @@ "CVE-2023-52837" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnbd: fix uaf in nbd_open\n\nCommit 4af5f2e03013 (\"nbd: use blk_mq_alloc_disk and\nblk_cleanup_disk\") cleans up disk by blk_cleanup_disk() and it won't set\ndisk->private_data as NULL as before. UAF may be triggered in nbd_open()\nif someone tries to open nbd device right after nbd_put() since nbd has\nbeen free in nbd_dev_remove().\n\nFix this by implementing ->free_disk and free private data in it.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hh96-p296-x7m4/GHSA-hh96-p296-x7m4.json b/advisories/unreviewed/2024/05/GHSA-hh96-p296-x7m4/GHSA-hh96-p296-x7m4.json index e67597806ad..b4789d9cdab 100644 --- a/advisories/unreviewed/2024/05/GHSA-hh96-p296-x7m4/GHSA-hh96-p296-x7m4.json +++ b/advisories/unreviewed/2024/05/GHSA-hh96-p296-x7m4/GHSA-hh96-p296-x7m4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-hm85-cqwx-6v52/GHSA-hm85-cqwx-6v52.json b/advisories/unreviewed/2024/05/GHSA-hm85-cqwx-6v52/GHSA-hm85-cqwx-6v52.json index aa7d774f5cc..1056e46c61a 100644 --- a/advisories/unreviewed/2024/05/GHSA-hm85-cqwx-6v52/GHSA-hm85-cqwx-6v52.json +++ b/advisories/unreviewed/2024/05/GHSA-hm85-cqwx-6v52/GHSA-hm85-cqwx-6v52.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-hmqq-g55h-wvgf/GHSA-hmqq-g55h-wvgf.json b/advisories/unreviewed/2024/05/GHSA-hmqq-g55h-wvgf/GHSA-hmqq-g55h-wvgf.json index c468a33f048..a9244232eff 100644 --- a/advisories/unreviewed/2024/05/GHSA-hmqq-g55h-wvgf/GHSA-hmqq-g55h-wvgf.json +++ b/advisories/unreviewed/2024/05/GHSA-hmqq-g55h-wvgf/GHSA-hmqq-g55h-wvgf.json @@ -7,12 +7,8 @@ "CVE-2023-52706" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: sim: fix a memory leak\n\nFix an inverted logic bug in gpio_sim_remove_hogs() that leads to GPIO\nhog structures never being freed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hwgv-6mjr-cw48/GHSA-hwgv-6mjr-cw48.json b/advisories/unreviewed/2024/05/GHSA-hwgv-6mjr-cw48/GHSA-hwgv-6mjr-cw48.json index 83269b8ad36..a495c3c5743 100644 --- a/advisories/unreviewed/2024/05/GHSA-hwgv-6mjr-cw48/GHSA-hwgv-6mjr-cw48.json +++ b/advisories/unreviewed/2024/05/GHSA-hwgv-6mjr-cw48/GHSA-hwgv-6mjr-cw48.json @@ -7,12 +7,8 @@ "CVE-2024-26999" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial/pmac_zilog: Remove flawed mitigation for rx irq flood\n\nThe mitigation was intended to stop the irq completely. That may be\nbetter than a hard lock-up but it turns out that you get a crash anyway\nif you're using pmac_zilog as a serial console:\n\nttyPZ0: pmz: rx irq flood !\nBUG: spinlock recursion on CPU#0, swapper/0\n\nThat's because the pr_err() call in pmz_receive_chars() results in\npmz_console_write() attempting to lock a spinlock already locked in\npmz_interrupt(). With CONFIG_DEBUG_SPINLOCK=y, this produces a fatal\nBUG splat. The spinlock in question is the one in struct uart_port.\n\nEven when it's not fatal, the serial port rx function ceases to work.\nAlso, the iteration limit doesn't play nicely with QEMU, as can be\nseen in the bug report linked below.\n\nA web search for other reports of the error message \"pmz: rx irq flood\"\ndidn't produce anything. So I don't think this code is needed any more.\nRemove it.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hxgr-6xc2-q9mv/GHSA-hxgr-6xc2-q9mv.json b/advisories/unreviewed/2024/05/GHSA-hxgr-6xc2-q9mv/GHSA-hxgr-6xc2-q9mv.json index 5d6078f49fe..242d4167aad 100644 --- a/advisories/unreviewed/2024/05/GHSA-hxgr-6xc2-q9mv/GHSA-hxgr-6xc2-q9mv.json +++ b/advisories/unreviewed/2024/05/GHSA-hxgr-6xc2-q9mv/GHSA-hxgr-6xc2-q9mv.json @@ -7,12 +7,8 @@ "CVE-2024-26935" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: core: Fix unremoved procfs host directory regression\n\nCommit fc663711b944 (\"scsi: core: Remove the /proc/scsi/${proc_name}\ndirectory earlier\") fixed a bug related to modules loading/unloading, by\nadding a call to scsi_proc_hostdir_rm() on scsi_remove_host(). But that led\nto a potential duplicate call to the hostdir_rm() routine, since it's also\ncalled from scsi_host_dev_release(). That triggered a regression report,\nwhich was then fixed by commit be03df3d4bfe (\"scsi: core: Fix a procfs host\ndirectory removal regression\"). The fix just dropped the hostdir_rm() call\nfrom dev_release().\n\nBut it happens that this proc directory is created on scsi_host_alloc(),\nand that function \"pairs\" with scsi_host_dev_release(), while\nscsi_remove_host() pairs with scsi_add_host(). In other words, it seems the\nreason for removing the proc directory on dev_release() was meant to cover\ncases in which a SCSI host structure was allocated, but the call to\nscsi_add_host() didn't happen. And that pattern happens to exist in some\nerror paths, for example.\n\nSyzkaller causes that by using USB raw gadget device, error'ing on\nusb-storage driver, at usb_stor_probe2(). By checking that path, we can see\nthat the BadDevice label leads to a scsi_host_put() after a SCSI host\nallocation, but there's no call to scsi_add_host() in such path. That leads\nto messages like this in dmesg (and a leak of the SCSI host proc\nstructure):\n\nusb-storage 4-1:87.51: USB Mass Storage device detected\nproc_dir_entry 'scsi/usb-storage' already registered\nWARNING: CPU: 1 PID: 3519 at fs/proc/generic.c:377 proc_register+0x347/0x4e0 fs/proc/generic.c:376\n\nThe proper fix seems to still call scsi_proc_hostdir_rm() on dev_release(),\nbut guard that with the state check for SHOST_CREATED; there is even a\ncomment in scsi_host_dev_release() detailing that: such conditional is\nmeant for cases where the SCSI host was allocated but there was no calls to\n{add,remove}_host(), like the usb-storage case.\n\nThis is what we propose here and with that, the error path of usb-storage\ndoes not trigger the warning anymore.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-j77x-x992-6j7f/GHSA-j77x-x992-6j7f.json b/advisories/unreviewed/2024/05/GHSA-j77x-x992-6j7f/GHSA-j77x-x992-6j7f.json index 9d9e0dff860..bdc17ab4b70 100644 --- a/advisories/unreviewed/2024/05/GHSA-j77x-x992-6j7f/GHSA-j77x-x992-6j7f.json +++ b/advisories/unreviewed/2024/05/GHSA-j77x-x992-6j7f/GHSA-j77x-x992-6j7f.json @@ -7,12 +7,8 @@ "CVE-2023-52742" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: USB: Fix wrong-direction WARNING in plusb.c\n\nThe syzbot fuzzer detected a bug in the plusb network driver: A\nzero-length control-OUT transfer was treated as a read instead of a\nwrite. In modern kernels this error provokes a WARNING:\n\nusb 1-1: BOGUS control dir, pipe 80000280 doesn't match bRequestType c0\nWARNING: CPU: 0 PID: 4645 at drivers/usb/core/urb.c:411\nusb_submit_urb+0x14a7/0x1880 drivers/usb/core/urb.c:411\nModules linked in:\nCPU: 1 PID: 4645 Comm: dhcpcd Not tainted\n6.2.0-rc6-syzkaller-00050-g9f266ccaa2f5 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google\n01/12/2023\nRIP: 0010:usb_submit_urb+0x14a7/0x1880 drivers/usb/core/urb.c:411\n...\nCall Trace:\n \n usb_start_wait_urb+0x101/0x4b0 drivers/usb/core/message.c:58\n usb_internal_control_msg drivers/usb/core/message.c:102 [inline]\n usb_control_msg+0x320/0x4a0 drivers/usb/core/message.c:153\n __usbnet_read_cmd+0xb9/0x390 drivers/net/usb/usbnet.c:2010\n usbnet_read_cmd+0x96/0xf0 drivers/net/usb/usbnet.c:2068\n pl_vendor_req drivers/net/usb/plusb.c:60 [inline]\n pl_set_QuickLink_features drivers/net/usb/plusb.c:75 [inline]\n pl_reset+0x2f/0xf0 drivers/net/usb/plusb.c:85\n usbnet_open+0xcc/0x5d0 drivers/net/usb/usbnet.c:889\n __dev_open+0x297/0x4d0 net/core/dev.c:1417\n __dev_change_flags+0x587/0x750 net/core/dev.c:8530\n dev_change_flags+0x97/0x170 net/core/dev.c:8602\n devinet_ioctl+0x15a2/0x1d70 net/ipv4/devinet.c:1147\n inet_ioctl+0x33f/0x380 net/ipv4/af_inet.c:979\n sock_do_ioctl+0xcc/0x230 net/socket.c:1169\n sock_ioctl+0x1f8/0x680 net/socket.c:1286\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:870 [inline]\n __se_sys_ioctl fs/ioctl.c:856 [inline]\n __x64_sys_ioctl+0x197/0x210 fs/ioctl.c:856\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x39/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nThe fix is to call usbnet_write_cmd() instead of usbnet_read_cmd() and\nremove the USB_DIR_IN flag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-jgx8-h977-4wfh/GHSA-jgx8-h977-4wfh.json b/advisories/unreviewed/2024/05/GHSA-jgx8-h977-4wfh/GHSA-jgx8-h977-4wfh.json index a18cc8ae3fc..1943e479b17 100644 --- a/advisories/unreviewed/2024/05/GHSA-jgx8-h977-4wfh/GHSA-jgx8-h977-4wfh.json +++ b/advisories/unreviewed/2024/05/GHSA-jgx8-h977-4wfh/GHSA-jgx8-h977-4wfh.json @@ -7,12 +7,8 @@ "CVE-2023-52761" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: VMAP_STACK overflow detection thread-safe\n\ncommit 31da94c25aea (\"riscv: add VMAP_STACK overflow detection\") added\nsupport for CONFIG_VMAP_STACK. If overflow is detected, CPU switches to\n`shadow_stack` temporarily before switching finally to per-cpu\n`overflow_stack`.\n\nIf two CPUs/harts are racing and end up in over flowing kernel stack, one\nor both will end up corrupting each other state because `shadow_stack` is\nnot per-cpu. This patch optimizes per-cpu overflow stack switch by\ndirectly picking per-cpu `overflow_stack` and gets rid of `shadow_stack`.\n\nFollowing are the changes in this patch\n\n - Defines an asm macro to obtain per-cpu symbols in destination\n register.\n - In entry.S, when overflow is detected, per-cpu overflow stack is\n located using per-cpu asm macro. Computing per-cpu symbol requires\n a temporary register. x31 is saved away into CSR_SCRATCH\n (CSR_SCRATCH is anyways zero since we're in kernel).\n\nPlease see Links for additional relevant disccussion and alternative\nsolution.\n\nTested by `echo EXHAUST_STACK > /sys/kernel/debug/provoke-crash/DIRECT`\nKernel crash log below\n\n Insufficient stack space to handle exception!/debug/provoke-crash/DIRECT\n Task stack: [0xff20000010a98000..0xff20000010a9c000]\n Overflow stack: [0xff600001f7d98370..0xff600001f7d99370]\n CPU: 1 PID: 205 Comm: bash Not tainted 6.1.0-rc2-00001-g328a1f96f7b9 #34\n Hardware name: riscv-virtio,qemu (DT)\n epc : __memset+0x60/0xfc\n ra : recursive_loop+0x48/0xc6 [lkdtm]\n epc : ffffffff808de0e4 ra : ffffffff0163a752 sp : ff20000010a97e80\n gp : ffffffff815c0330 tp : ff600000820ea280 t0 : ff20000010a97e88\n t1 : 000000000000002e t2 : 3233206874706564 s0 : ff20000010a982b0\n s1 : 0000000000000012 a0 : ff20000010a97e88 a1 : 0000000000000000\n a2 : 0000000000000400 a3 : ff20000010a98288 a4 : 0000000000000000\n a5 : 0000000000000000 a6 : fffffffffffe43f0 a7 : 00007fffffffffff\n s2 : ff20000010a97e88 s3 : ffffffff01644680 s4 : ff20000010a9be90\n s5 : ff600000842ba6c0 s6 : 00aaaaaac29e42b0 s7 : 00fffffff0aa3684\n s8 : 00aaaaaac2978040 s9 : 0000000000000065 s10: 00ffffff8a7cad10\n s11: 00ffffff8a76a4e0 t3 : ffffffff815dbaf4 t4 : ffffffff815dbaf4\n t5 : ffffffff815dbab8 t6 : ff20000010a9bb48\n status: 0000000200000120 badaddr: ff20000010a97e88 cause: 000000000000000f\n Kernel panic - not syncing: Kernel stack overflow\n CPU: 1 PID: 205 Comm: bash Not tainted 6.1.0-rc2-00001-g328a1f96f7b9 #34\n Hardware name: riscv-virtio,qemu (DT)\n Call Trace:\n [] dump_backtrace+0x30/0x38\n [] show_stack+0x40/0x4c\n [] dump_stack_lvl+0x44/0x5c\n [] dump_stack+0x18/0x20\n [] panic+0x126/0x2fe\n [] walk_stackframe+0x0/0xf0\n [] recursive_loop+0x48/0xc6 [lkdtm]\n SMP: stopping secondary CPUs\n ---[ end Kernel panic - not syncing: Kernel stack overflow ]---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-jhvm-33ww-x3q9/GHSA-jhvm-33ww-x3q9.json b/advisories/unreviewed/2024/05/GHSA-jhvm-33ww-x3q9/GHSA-jhvm-33ww-x3q9.json index e25a185dbcc..c2559b068f2 100644 --- a/advisories/unreviewed/2024/05/GHSA-jhvm-33ww-x3q9/GHSA-jhvm-33ww-x3q9.json +++ b/advisories/unreviewed/2024/05/GHSA-jhvm-33ww-x3q9/GHSA-jhvm-33ww-x3q9.json @@ -7,12 +7,8 @@ "CVE-2023-52744" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/irdma: Fix potential NULL-ptr-dereference\n\nin_dev_get() can return NULL which will cause a failure once idev is\ndereferenced in in_dev_for_each_ifa_rtnl(). This patch adds a\ncheck for NULL value in idev beforehand.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-jp9q-c7f4-2fxf/GHSA-jp9q-c7f4-2fxf.json b/advisories/unreviewed/2024/05/GHSA-jp9q-c7f4-2fxf/GHSA-jp9q-c7f4-2fxf.json index 6d173fd2509..e7cd836fdec 100644 --- a/advisories/unreviewed/2024/05/GHSA-jp9q-c7f4-2fxf/GHSA-jp9q-c7f4-2fxf.json +++ b/advisories/unreviewed/2024/05/GHSA-jp9q-c7f4-2fxf/GHSA-jp9q-c7f4-2fxf.json @@ -7,12 +7,8 @@ "CVE-2023-52757" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix potential deadlock when releasing mids\n\nAll release_mid() callers seem to hold a reference of @mid so there is\nno need to call kref_put(&mid->refcount, __release_mid) under\n@server->mid_lock spinlock. If they don't, then an use-after-free bug\nwould have occurred anyways.\n\nBy getting rid of such spinlock also fixes a potential deadlock as\nshown below\n\nCPU 0 CPU 1\n------------------------------------------------------------------\ncifs_demultiplex_thread() cifs_debug_data_proc_show()\n release_mid()\n spin_lock(&server->mid_lock);\n spin_lock(&cifs_tcp_ses_lock)\n\t\t\t\t spin_lock(&server->mid_lock)\n __release_mid()\n smb2_find_smb_tcon()\n spin_lock(&cifs_tcp_ses_lock) *deadlock*", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-jv5m-87g4-wp39/GHSA-jv5m-87g4-wp39.json b/advisories/unreviewed/2024/05/GHSA-jv5m-87g4-wp39/GHSA-jv5m-87g4-wp39.json index a22eb43e06a..42f59a0953c 100644 --- a/advisories/unreviewed/2024/05/GHSA-jv5m-87g4-wp39/GHSA-jv5m-87g4-wp39.json +++ b/advisories/unreviewed/2024/05/GHSA-jv5m-87g4-wp39/GHSA-jv5m-87g4-wp39.json @@ -7,12 +7,8 @@ "CVE-2023-52847" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: bttv: fix use after free error due to btv->timeout timer\n\nThere may be some a race condition between timer function\nbttv_irq_timeout and bttv_remove. The timer is setup in\nprobe and there is no timer_delete operation in remove\nfunction. When it hit kfree btv, the function might still be\ninvoked, which will cause use after free bug.\n\nThis bug is found by static analysis, it may be false positive.\n\nFix it by adding del_timer_sync invoking to the remove function.\n\ncpu0 cpu1\n bttv_probe\n ->timer_setup\n ->bttv_set_dma\n ->mod_timer;\nbttv_remove\n ->kfree(btv);\n ->bttv_irq_timeout\n ->USE btv", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-m923-55g6-m66q/GHSA-m923-55g6-m66q.json b/advisories/unreviewed/2024/05/GHSA-m923-55g6-m66q/GHSA-m923-55g6-m66q.json index 6618f0e05cc..ec820187b4c 100644 --- a/advisories/unreviewed/2024/05/GHSA-m923-55g6-m66q/GHSA-m923-55g6-m66q.json +++ b/advisories/unreviewed/2024/05/GHSA-m923-55g6-m66q/GHSA-m923-55g6-m66q.json @@ -7,12 +7,8 @@ "CVE-2024-26951" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwireguard: netlink: check for dangling peer via is_dead instead of empty list\n\nIf all peers are removed via wg_peer_remove_all(), rather than setting\npeer_list to empty, the peer is added to a temporary list with a head on\nthe stack of wg_peer_remove_all(). If a netlink dump is resumed and the\ncursored peer is one that has been removed via wg_peer_remove_all(), it\nwill iterate from that peer and then attempt to dump freed peers.\n\nFix this by instead checking peer->is_dead, which was explictly created\nfor this purpose. Also move up the device_update_lock lockdep assertion,\nsince reading is_dead relies on that.\n\nIt can be reproduced by a small script like:\n\n echo \"Setting config...\"\n ip link add dev wg0 type wireguard\n wg setconf wg0 /big-config\n (\n while true; do\n echo \"Showing config...\"\n wg showconf wg0 > /dev/null\n done\n ) &\n sleep 4\n wg setconf wg0 <(printf \"[Peer]\\nPublicKey=$(wg genkey)\\n\")\n\nResulting in:\n\n BUG: KASAN: slab-use-after-free in __lock_acquire+0x182a/0x1b20\n Read of size 8 at addr ffff88811956ec70 by task wg/59\n CPU: 2 PID: 59 Comm: wg Not tainted 6.8.0-rc2-debug+ #5\n Call Trace:\n \n dump_stack_lvl+0x47/0x70\n print_address_description.constprop.0+0x2c/0x380\n print_report+0xab/0x250\n kasan_report+0xba/0xf0\n __lock_acquire+0x182a/0x1b20\n lock_acquire+0x191/0x4b0\n down_read+0x80/0x440\n get_peer+0x140/0xcb0\n wg_get_device_dump+0x471/0x1130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-mfqx-8929-rf3c/GHSA-mfqx-8929-rf3c.json b/advisories/unreviewed/2024/05/GHSA-mfqx-8929-rf3c/GHSA-mfqx-8929-rf3c.json index d4ada4af985..4c7d7df44f9 100644 --- a/advisories/unreviewed/2024/05/GHSA-mfqx-8929-rf3c/GHSA-mfqx-8929-rf3c.json +++ b/advisories/unreviewed/2024/05/GHSA-mfqx-8929-rf3c/GHSA-mfqx-8929-rf3c.json @@ -7,12 +7,8 @@ "CVE-2024-26997" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc2: host: Fix dereference issue in DDMA completion flow.\n\nFixed variable dereference issue in DDMA completion flow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-mvq3-v998-w43f/GHSA-mvq3-v998-w43f.json b/advisories/unreviewed/2024/05/GHSA-mvq3-v998-w43f/GHSA-mvq3-v998-w43f.json index c72b5f3ab58..f085e2c9dc1 100644 --- a/advisories/unreviewed/2024/05/GHSA-mvq3-v998-w43f/GHSA-mvq3-v998-w43f.json +++ b/advisories/unreviewed/2024/05/GHSA-mvq3-v998-w43f/GHSA-mvq3-v998-w43f.json @@ -7,12 +7,8 @@ "CVE-2024-27396" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gtp: Fix Use-After-Free in gtp_dellink\n\nSince call_rcu, which is called in the hlist_for_each_entry_rcu traversal\nof gtp_dellink, is not part of the RCU read critical section, it\nis possible that the RCU grace period will pass during the traversal and\nthe key will be free.\n\nTo prevent this, it should be changed to hlist_for_each_entry_safe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-mxqp-c4m3-mg6r/GHSA-mxqp-c4m3-mg6r.json b/advisories/unreviewed/2024/05/GHSA-mxqp-c4m3-mg6r/GHSA-mxqp-c4m3-mg6r.json index 5cbc23412f7..f81fd67d0e9 100644 --- a/advisories/unreviewed/2024/05/GHSA-mxqp-c4m3-mg6r/GHSA-mxqp-c4m3-mg6r.json +++ b/advisories/unreviewed/2024/05/GHSA-mxqp-c4m3-mg6r/GHSA-mxqp-c4m3-mg6r.json @@ -7,12 +7,8 @@ "CVE-2023-52775" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: avoid data corruption caused by decline\n\nWe found a data corruption issue during testing of SMC-R on Redis\napplications.\n\nThe benchmark has a low probability of reporting a strange error as\nshown below.\n\n\"Error: Protocol error, got \"\\xe2\" as reply type byte\"\n\nFinally, we found that the retrieved error data was as follows:\n\n0xE2 0xD4 0xC3 0xD9 0x04 0x00 0x2C 0x20 0xA6 0x56 0x00 0x16 0x3E 0x0C\n0xCB 0x04 0x02 0x01 0x00 0x00 0x20 0x00 0x00 0x00 0x00 0x00 0x00 0x00\n0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0xE2\n\nIt is quite obvious that this is a SMC DECLINE message, which means that\nthe applications received SMC protocol message.\nWe found that this was caused by the following situations:\n\nclient server\n ¦ clc proposal\n ------------->\n ¦ clc accept\n <-------------\n ¦ clc confirm\n ------------->\nwait llc confirm\n\t\t\tsend llc confirm\n ¦failed llc confirm\n ¦ x------\n(after 2s)timeout\n wait llc confirm rsp\n\nwait decline\n\n(after 1s) timeout\n (after 2s) timeout\n ¦ decline\n -------------->\n ¦ decline\n <--------------\n\nAs a result, a decline message was sent in the implementation, and this\nmessage was read from TCP by the already-fallback connection.\n\nThis patch double the client timeout as 2x of the server value,\nWith this simple change, the Decline messages should never cross or\ncollide (during Confirm link timeout).\n\nThis issue requires an immediate solution, since the protocol updates\ninvolve a more long-term solution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p3gx-mhhh-v7wr/GHSA-p3gx-mhhh-v7wr.json b/advisories/unreviewed/2024/05/GHSA-p3gx-mhhh-v7wr/GHSA-p3gx-mhhh-v7wr.json index 7c1ece872fb..f2ff2975ff7 100644 --- a/advisories/unreviewed/2024/05/GHSA-p3gx-mhhh-v7wr/GHSA-p3gx-mhhh-v7wr.json +++ b/advisories/unreviewed/2024/05/GHSA-p3gx-mhhh-v7wr/GHSA-p3gx-mhhh-v7wr.json @@ -7,12 +7,8 @@ "CVE-2023-52790" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nswiotlb: fix out-of-bounds TLB allocations with CONFIG_SWIOTLB_DYNAMIC\n\nLimit the free list length to the size of the IO TLB. Transient pool can be\nsmaller than IO_TLB_SEGSIZE, but the free list is initialized with the\nassumption that the total number of slots is a multiple of IO_TLB_SEGSIZE.\nAs a result, swiotlb_area_find_slots() may allocate slots past the end of\na transient IO TLB buffer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p672-9qr7-4cmf/GHSA-p672-9qr7-4cmf.json b/advisories/unreviewed/2024/05/GHSA-p672-9qr7-4cmf/GHSA-p672-9qr7-4cmf.json index 1292eb60e86..86b1fba2746 100644 --- a/advisories/unreviewed/2024/05/GHSA-p672-9qr7-4cmf/GHSA-p672-9qr7-4cmf.json +++ b/advisories/unreviewed/2024/05/GHSA-p672-9qr7-4cmf/GHSA-p672-9qr7-4cmf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p6xg-gj77-6vpg/GHSA-p6xg-gj77-6vpg.json b/advisories/unreviewed/2024/05/GHSA-p6xg-gj77-6vpg/GHSA-p6xg-gj77-6vpg.json index 4108afd24bc..2e444ac150d 100644 --- a/advisories/unreviewed/2024/05/GHSA-p6xg-gj77-6vpg/GHSA-p6xg-gj77-6vpg.json +++ b/advisories/unreviewed/2024/05/GHSA-p6xg-gj77-6vpg/GHSA-p6xg-gj77-6vpg.json @@ -7,12 +7,8 @@ "CVE-2023-52835" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/core: Bail out early if the request AUX area is out of bound\n\nWhen perf-record with a large AUX area, e.g 4GB, it fails with:\n\n #perf record -C 0 -m ,4G -e arm_spe_0// -- sleep 1\n failed to mmap with 12 (Cannot allocate memory)\n\nand it reveals a WARNING with __alloc_pages():\n\n\t------------[ cut here ]------------\n\tWARNING: CPU: 44 PID: 17573 at mm/page_alloc.c:5568 __alloc_pages+0x1ec/0x248\n\tCall trace:\n\t __alloc_pages+0x1ec/0x248\n\t __kmalloc_large_node+0xc0/0x1f8\n\t __kmalloc_node+0x134/0x1e8\n\t rb_alloc_aux+0xe0/0x298\n\t perf_mmap+0x440/0x660\n\t mmap_region+0x308/0x8a8\n\t do_mmap+0x3c0/0x528\n\t vm_mmap_pgoff+0xf4/0x1b8\n\t ksys_mmap_pgoff+0x18c/0x218\n\t __arm64_sys_mmap+0x38/0x58\n\t invoke_syscall+0x50/0x128\n\t el0_svc_common.constprop.0+0x58/0x188\n\t do_el0_svc+0x34/0x50\n\t el0_svc+0x34/0x108\n\t el0t_64_sync_handler+0xb8/0xc0\n\t el0t_64_sync+0x1a4/0x1a8\n\n'rb->aux_pages' allocated by kcalloc() is a pointer array which is used to\nmaintains AUX trace pages. The allocated page for this array is physically\ncontiguous (and virtually contiguous) with an order of 0..MAX_ORDER. If the\nsize of pointer array crosses the limitation set by MAX_ORDER, it reveals a\nWARNING.\n\nSo bail out early with -ENOMEM if the request AUX area is out of bound,\ne.g.:\n\n #perf record -C 0 -m ,4G -e arm_spe_0// -- sleep 1\n failed to mmap with 12 (Cannot allocate memory)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p9xp-vch3-fpjp/GHSA-p9xp-vch3-fpjp.json b/advisories/unreviewed/2024/05/GHSA-p9xp-vch3-fpjp/GHSA-p9xp-vch3-fpjp.json index e00df0efd39..ef76b623526 100644 --- a/advisories/unreviewed/2024/05/GHSA-p9xp-vch3-fpjp/GHSA-p9xp-vch3-fpjp.json +++ b/advisories/unreviewed/2024/05/GHSA-p9xp-vch3-fpjp/GHSA-p9xp-vch3-fpjp.json @@ -7,12 +7,8 @@ "CVE-2024-27044" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix potential NULL pointer dereferences in 'dcn10_set_output_transfer_func()'\n\nThe 'stream' pointer is used in dcn10_set_output_transfer_func() before\nthe check if 'stream' is NULL.\n\nFixes the below:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn10/dcn10_hwseq.c:1892 dcn10_set_output_transfer_func() warn: variable dereferenced before check 'stream' (see line 1875)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-pcw4-494r-vqvf/GHSA-pcw4-494r-vqvf.json b/advisories/unreviewed/2024/05/GHSA-pcw4-494r-vqvf/GHSA-pcw4-494r-vqvf.json index fdf5349827f..0879a55c497 100644 --- a/advisories/unreviewed/2024/05/GHSA-pcw4-494r-vqvf/GHSA-pcw4-494r-vqvf.json +++ b/advisories/unreviewed/2024/05/GHSA-pcw4-494r-vqvf/GHSA-pcw4-494r-vqvf.json @@ -7,12 +7,8 @@ "CVE-2023-52791" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: core: Run atomic i2c xfer when !preemptible\n\nSince bae1d3a05a8b, i2c transfers are non-atomic if preemption is\ndisabled. However, non-atomic i2c transfers require preemption (e.g. in\nwait_for_completion() while waiting for the DMA).\n\npanic() calls preempt_disable_notrace() before calling\nemergency_restart(). Therefore, if an i2c device is used for the\nrestart, the xfer should be atomic. This avoids warnings like:\n\n[ 12.667612] WARNING: CPU: 1 PID: 1 at kernel/rcu/tree_plugin.h:318 rcu_note_context_switch+0x33c/0x6b0\n[ 12.676926] Voluntary context switch within RCU read-side critical section!\n...\n[ 12.742376] schedule_timeout from wait_for_completion_timeout+0x90/0x114\n[ 12.749179] wait_for_completion_timeout from tegra_i2c_wait_completion+0x40/0x70\n...\n[ 12.994527] atomic_notifier_call_chain from machine_restart+0x34/0x58\n[ 13.001050] machine_restart from panic+0x2a8/0x32c\n\nUse !preemptible() instead, which is basically the same check as\npre-v5.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-pxvx-632v-2p4v/GHSA-pxvx-632v-2p4v.json b/advisories/unreviewed/2024/05/GHSA-pxvx-632v-2p4v/GHSA-pxvx-632v-2p4v.json index 06f7d545230..f4b6c6c7e06 100644 --- a/advisories/unreviewed/2024/05/GHSA-pxvx-632v-2p4v/GHSA-pxvx-632v-2p4v.json +++ b/advisories/unreviewed/2024/05/GHSA-pxvx-632v-2p4v/GHSA-pxvx-632v-2p4v.json @@ -7,12 +7,8 @@ "CVE-2024-27000" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial: mxs-auart: add spinlock around changing cts state\n\nThe uart_handle_cts_change() function in serial_core expects the caller\nto hold uport->lock. For example, I have seen the below kernel splat,\nwhen the Bluetooth driver is loaded on an i.MX28 board.\n\n [ 85.119255] ------------[ cut here ]------------\n [ 85.124413] WARNING: CPU: 0 PID: 27 at /drivers/tty/serial/serial_core.c:3453 uart_handle_cts_change+0xb4/0xec\n [ 85.134694] Modules linked in: hci_uart bluetooth ecdh_generic ecc wlcore_sdio configfs\n [ 85.143314] CPU: 0 PID: 27 Comm: kworker/u3:0 Not tainted 6.6.3-00021-gd62a2f068f92 #1\n [ 85.151396] Hardware name: Freescale MXS (Device Tree)\n [ 85.156679] Workqueue: hci0 hci_power_on [bluetooth]\n (...)\n [ 85.191765] uart_handle_cts_change from mxs_auart_irq_handle+0x380/0x3f4\n [ 85.198787] mxs_auart_irq_handle from __handle_irq_event_percpu+0x88/0x210\n (...)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-q2m9-j68q-x65j/GHSA-q2m9-j68q-x65j.json b/advisories/unreviewed/2024/05/GHSA-q2m9-j68q-x65j/GHSA-q2m9-j68q-x65j.json index 179193cfe6d..865570bceba 100644 --- a/advisories/unreviewed/2024/05/GHSA-q2m9-j68q-x65j/GHSA-q2m9-j68q-x65j.json +++ b/advisories/unreviewed/2024/05/GHSA-q2m9-j68q-x65j/GHSA-q2m9-j68q-x65j.json @@ -7,12 +7,8 @@ "CVE-2024-27043" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: edia: dvbdev: fix a use-after-free\n\nIn dvb_register_device, *pdvbdev is set equal to dvbdev, which is freed\nin several error-handling paths. However, *pdvbdev is not set to NULL\nafter dvbdev's deallocation, causing use-after-frees in many places,\nfor example, in the following call chain:\n\nbudget_register\n |-> dvb_dmxdev_init\n |-> dvb_register_device\n |-> dvb_dmxdev_release\n |-> dvb_unregister_device\n |-> dvb_remove_device\n |-> dvb_device_put\n |-> kref_put\n\nWhen calling dvb_unregister_device, dmxdev->dvbdev (i.e. *pdvbdev in\ndvb_register_device) could point to memory that had been freed in\ndvb_register_device. Thereafter, this pointer is transferred to\nkref_put and triggering a use-after-free.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-q557-gm3j-fg4w/GHSA-q557-gm3j-fg4w.json b/advisories/unreviewed/2024/05/GHSA-q557-gm3j-fg4w/GHSA-q557-gm3j-fg4w.json index 8d4696beb97..632b3f74ddc 100644 --- a/advisories/unreviewed/2024/05/GHSA-q557-gm3j-fg4w/GHSA-q557-gm3j-fg4w.json +++ b/advisories/unreviewed/2024/05/GHSA-q557-gm3j-fg4w/GHSA-q557-gm3j-fg4w.json @@ -7,12 +7,8 @@ "CVE-2024-26966" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: qcom: mmcc-apq8084: fix terminating of frequency table arrays\n\nThe frequency table arrays are supposed to be terminated with an\nempty element. Add such entry to the end of the arrays where it\nis missing in order to avoid possible out-of-bound access when\nthe table is traversed by functions like qcom_find_freq() or\nqcom_find_freq_floor().\n\nOnly compile tested.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qc4m-rx2p-hrfv/GHSA-qc4m-rx2p-hrfv.json b/advisories/unreviewed/2024/05/GHSA-qc4m-rx2p-hrfv/GHSA-qc4m-rx2p-hrfv.json index 3839ce0c8d0..4cb66d6588a 100644 --- a/advisories/unreviewed/2024/05/GHSA-qc4m-rx2p-hrfv/GHSA-qc4m-rx2p-hrfv.json +++ b/advisories/unreviewed/2024/05/GHSA-qc4m-rx2p-hrfv/GHSA-qc4m-rx2p-hrfv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-qfqw-rh34-r78m/GHSA-qfqw-rh34-r78m.json b/advisories/unreviewed/2024/05/GHSA-qfqw-rh34-r78m/GHSA-qfqw-rh34-r78m.json index e68677d7b9d..a6061eb99b8 100644 --- a/advisories/unreviewed/2024/05/GHSA-qfqw-rh34-r78m/GHSA-qfqw-rh34-r78m.json +++ b/advisories/unreviewed/2024/05/GHSA-qfqw-rh34-r78m/GHSA-qfqw-rh34-r78m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-qgwv-qgmf-mmf4/GHSA-qgwv-qgmf-mmf4.json b/advisories/unreviewed/2024/05/GHSA-qgwv-qgmf-mmf4/GHSA-qgwv-qgmf-mmf4.json index 3488c501c99..621067ddb0a 100644 --- a/advisories/unreviewed/2024/05/GHSA-qgwv-qgmf-mmf4/GHSA-qgwv-qgmf-mmf4.json +++ b/advisories/unreviewed/2024/05/GHSA-qgwv-qgmf-mmf4/GHSA-qgwv-qgmf-mmf4.json @@ -7,12 +7,8 @@ "CVE-2023-52740" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/64s/interrupt: Fix interrupt exit race with security mitigation switch\n\nThe RFI and STF security mitigation options can flip the\ninterrupt_exit_not_reentrant static branch condition concurrently with\nthe interrupt exit code which tests that branch.\n\nInterrupt exit tests this condition to set MSR[EE|RI] for exit, then\nagain in the case a soft-masked interrupt is found pending, to recover\nthe MSR so the interrupt can be replayed before attempting to exit\nagain. If the condition changes between these two tests, the MSR and irq\nsoft-mask state will become corrupted, leading to warnings and possible\ncrashes. For example, if the branch is initially true then false,\nMSR[EE] will be 0 but PACA_IRQ_HARD_DIS clear and EE may not get\nenabled, leading to warnings in irq_64.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qppw-2696-658w/GHSA-qppw-2696-658w.json b/advisories/unreviewed/2024/05/GHSA-qppw-2696-658w/GHSA-qppw-2696-658w.json index 9a0c42f99b4..5f586ee8adf 100644 --- a/advisories/unreviewed/2024/05/GHSA-qppw-2696-658w/GHSA-qppw-2696-658w.json +++ b/advisories/unreviewed/2024/05/GHSA-qppw-2696-658w/GHSA-qppw-2696-658w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-qrj2-26jq-rq86/GHSA-qrj2-26jq-rq86.json b/advisories/unreviewed/2024/05/GHSA-qrj2-26jq-rq86/GHSA-qrj2-26jq-rq86.json index 413f6af2653..bbef6ba942c 100644 --- a/advisories/unreviewed/2024/05/GHSA-qrj2-26jq-rq86/GHSA-qrj2-26jq-rq86.json +++ b/advisories/unreviewed/2024/05/GHSA-qrj2-26jq-rq86/GHSA-qrj2-26jq-rq86.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-qrxg-6w43-8h52/GHSA-qrxg-6w43-8h52.json b/advisories/unreviewed/2024/05/GHSA-qrxg-6w43-8h52/GHSA-qrxg-6w43-8h52.json index 4a3cbf30786..49581876bec 100644 --- a/advisories/unreviewed/2024/05/GHSA-qrxg-6w43-8h52/GHSA-qrxg-6w43-8h52.json +++ b/advisories/unreviewed/2024/05/GHSA-qrxg-6w43-8h52/GHSA-qrxg-6w43-8h52.json @@ -7,12 +7,8 @@ "CVE-2023-52747" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/hfi1: Restore allocated resources on failed copyout\n\nFix a resource leak if an error occurs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qwvj-5fwc-qxf7/GHSA-qwvj-5fwc-qxf7.json b/advisories/unreviewed/2024/05/GHSA-qwvj-5fwc-qxf7/GHSA-qwvj-5fwc-qxf7.json index eff37841cab..d11abbb8e2b 100644 --- a/advisories/unreviewed/2024/05/GHSA-qwvj-5fwc-qxf7/GHSA-qwvj-5fwc-qxf7.json +++ b/advisories/unreviewed/2024/05/GHSA-qwvj-5fwc-qxf7/GHSA-qwvj-5fwc-qxf7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -67,9 +65,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-r5hp-gwxj-3824/GHSA-r5hp-gwxj-3824.json b/advisories/unreviewed/2024/05/GHSA-r5hp-gwxj-3824/GHSA-r5hp-gwxj-3824.json index a8c10f5a41b..3d54f40f51a 100644 --- a/advisories/unreviewed/2024/05/GHSA-r5hp-gwxj-3824/GHSA-r5hp-gwxj-3824.json +++ b/advisories/unreviewed/2024/05/GHSA-r5hp-gwxj-3824/GHSA-r5hp-gwxj-3824.json @@ -7,12 +7,8 @@ "CVE-2023-52784" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: stop the device in bond_setup_by_slave()\n\nCommit 9eed321cde22 (\"net: lapbether: only support ethernet devices\")\nhas been able to keep syzbot away from net/lapb, until today.\n\nIn the following splat [1], the issue is that a lapbether device has\nbeen created on a bonding device without members. Then adding a non\nARPHRD_ETHER member forced the bonding master to change its type.\n\nThe fix is to make sure we call dev_close() in bond_setup_by_slave()\nso that the potential linked lapbether devices (or any other devices\nhaving assumptions on the physical device) are removed.\n\nA similar bug has been addressed in commit 40baec225765\n(\"bonding: fix panic on non-ARPHRD_ETHER enslave failure\")\n\n[1]\nskbuff: skb_under_panic: text:ffff800089508810 len:44 put:40 head:ffff0000c78e7c00 data:ffff0000c78e7bea tail:0x16 end:0x140 dev:bond0\nkernel BUG at net/core/skbuff.c:192 !\nInternal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP\nModules linked in:\nCPU: 0 PID: 6007 Comm: syz-executor383 Not tainted 6.6.0-rc3-syzkaller-gbf6547d8715b #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/04/2023\npstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : skb_panic net/core/skbuff.c:188 [inline]\npc : skb_under_panic+0x13c/0x140 net/core/skbuff.c:202\nlr : skb_panic net/core/skbuff.c:188 [inline]\nlr : skb_under_panic+0x13c/0x140 net/core/skbuff.c:202\nsp : ffff800096a06aa0\nx29: ffff800096a06ab0 x28: ffff800096a06ba0 x27: dfff800000000000\nx26: ffff0000ce9b9b50 x25: 0000000000000016 x24: ffff0000c78e7bea\nx23: ffff0000c78e7c00 x22: 000000000000002c x21: 0000000000000140\nx20: 0000000000000028 x19: ffff800089508810 x18: ffff800096a06100\nx17: 0000000000000000 x16: ffff80008a629a3c x15: 0000000000000001\nx14: 1fffe00036837a32 x13: 0000000000000000 x12: 0000000000000000\nx11: 0000000000000201 x10: 0000000000000000 x9 : cb50b496c519aa00\nx8 : cb50b496c519aa00 x7 : 0000000000000001 x6 : 0000000000000001\nx5 : ffff800096a063b8 x4 : ffff80008e280f80 x3 : ffff8000805ad11c\nx2 : 0000000000000001 x1 : 0000000100000201 x0 : 0000000000000086\nCall trace:\nskb_panic net/core/skbuff.c:188 [inline]\nskb_under_panic+0x13c/0x140 net/core/skbuff.c:202\nskb_push+0xf0/0x108 net/core/skbuff.c:2446\nip6gre_header+0xbc/0x738 net/ipv6/ip6_gre.c:1384\ndev_hard_header include/linux/netdevice.h:3136 [inline]\nlapbeth_data_transmit+0x1c4/0x298 drivers/net/wan/lapbether.c:257\nlapb_data_transmit+0x8c/0xb0 net/lapb/lapb_iface.c:447\nlapb_transmit_buffer+0x178/0x204 net/lapb/lapb_out.c:149\nlapb_send_control+0x220/0x320 net/lapb/lapb_subr.c:251\n__lapb_disconnect_request+0x9c/0x17c net/lapb/lapb_iface.c:326\nlapb_device_event+0x288/0x4e0 net/lapb/lapb_iface.c:492\nnotifier_call_chain+0x1a4/0x510 kernel/notifier.c:93\nraw_notifier_call_chain+0x3c/0x50 kernel/notifier.c:461\ncall_netdevice_notifiers_info net/core/dev.c:1970 [inline]\ncall_netdevice_notifiers_extack net/core/dev.c:2008 [inline]\ncall_netdevice_notifiers net/core/dev.c:2022 [inline]\n__dev_close_many+0x1b8/0x3c4 net/core/dev.c:1508\ndev_close_many+0x1e0/0x470 net/core/dev.c:1559\ndev_close+0x174/0x250 net/core/dev.c:1585\nlapbeth_device_event+0x2e4/0x958 drivers/net/wan/lapbether.c:466\nnotifier_call_chain+0x1a4/0x510 kernel/notifier.c:93\nraw_notifier_call_chain+0x3c/0x50 kernel/notifier.c:461\ncall_netdevice_notifiers_info net/core/dev.c:1970 [inline]\ncall_netdevice_notifiers_extack net/core/dev.c:2008 [inline]\ncall_netdevice_notifiers net/core/dev.c:2022 [inline]\n__dev_close_many+0x1b8/0x3c4 net/core/dev.c:1508\ndev_close_many+0x1e0/0x470 net/core/dev.c:1559\ndev_close+0x174/0x250 net/core/dev.c:1585\nbond_enslave+0x2298/0x30cc drivers/net/bonding/bond_main.c:2332\nbond_do_ioctl+0x268/0xc64 drivers/net/bonding/bond_main.c:4539\ndev_ifsioc+0x754/0x9ac\ndev_ioctl+0x4d8/0xd34 net/core/dev_ioctl.c:786\nsock_do_ioctl+0x1d4/0x2d0 net/socket.c:1217\nsock_ioctl+0x4e8/0x834 net/socket.c:1322\nvfs_ioctl fs/ioctl.c:51 [inline]\n__do_\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-r823-qmw9-v7xf/GHSA-r823-qmw9-v7xf.json b/advisories/unreviewed/2024/05/GHSA-r823-qmw9-v7xf/GHSA-r823-qmw9-v7xf.json index ede9937ea95..8e6d5b9f5d1 100644 --- a/advisories/unreviewed/2024/05/GHSA-r823-qmw9-v7xf/GHSA-r823-qmw9-v7xf.json +++ b/advisories/unreviewed/2024/05/GHSA-r823-qmw9-v7xf/GHSA-r823-qmw9-v7xf.json @@ -7,12 +7,8 @@ "CVE-2023-52839" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers: perf: Do not broadcast to other cpus when starting a counter\n\nThis command:\n\n$ perf record -e cycles:k -e instructions:k -c 10000 -m 64M dd if=/dev/zero of=/dev/null count=1000\n\ngives rise to this kernel warning:\n\n[ 444.364395] WARNING: CPU: 0 PID: 104 at kernel/smp.c:775 smp_call_function_many_cond+0x42c/0x436\n[ 444.364515] Modules linked in:\n[ 444.364657] CPU: 0 PID: 104 Comm: perf-exec Not tainted 6.6.0-rc6-00051-g391df82e8ec3-dirty #73\n[ 444.364771] Hardware name: riscv-virtio,qemu (DT)\n[ 444.364868] epc : smp_call_function_many_cond+0x42c/0x436\n[ 444.364917] ra : on_each_cpu_cond_mask+0x20/0x32\n[ 444.364948] epc : ffffffff8009f9e0 ra : ffffffff8009fa5a sp : ff20000000003800\n[ 444.364966] gp : ffffffff81500aa0 tp : ff60000002b83000 t0 : ff200000000038c0\n[ 444.364982] t1 : ffffffff815021f0 t2 : 000000000000001f s0 : ff200000000038b0\n[ 444.364998] s1 : ff60000002c54d98 a0 : ff60000002a73940 a1 : 0000000000000000\n[ 444.365013] a2 : 0000000000000000 a3 : 0000000000000003 a4 : 0000000000000100\n[ 444.365029] a5 : 0000000000010100 a6 : 0000000000f00000 a7 : 0000000000000000\n[ 444.365044] s2 : 0000000000000000 s3 : ffffffffffffffff s4 : ff60000002c54d98\n[ 444.365060] s5 : ffffffff81539610 s6 : ffffffff80c20c48 s7 : 0000000000000000\n[ 444.365075] s8 : 0000000000000000 s9 : 0000000000000001 s10: 0000000000000001\n[ 444.365090] s11: ffffffff80099394 t3 : 0000000000000003 t4 : 00000000eac0c6e6\n[ 444.365104] t5 : 0000000400000000 t6 : ff60000002e010d0\n[ 444.365120] status: 0000000200000100 badaddr: 0000000000000000 cause: 0000000000000003\n[ 444.365226] [] smp_call_function_many_cond+0x42c/0x436\n[ 444.365295] [] on_each_cpu_cond_mask+0x20/0x32\n[ 444.365311] [] pmu_sbi_ctr_start+0x7a/0xaa\n[ 444.365327] [] riscv_pmu_start+0x48/0x66\n[ 444.365339] [] perf_adjust_freq_unthr_context+0x196/0x1ac\n[ 444.365356] [] perf_event_task_tick+0x78/0x8c\n[ 444.365368] [] scheduler_tick+0xe6/0x25e\n[ 444.365383] [] update_process_times+0x80/0x96\n[ 444.365398] [] tick_sched_handle+0x26/0x52\n[ 444.365410] [] tick_sched_timer+0x50/0x98\n[ 444.365422] [] __hrtimer_run_queues+0x126/0x18a\n[ 444.365433] [] hrtimer_interrupt+0xce/0x1da\n[ 444.365444] [] riscv_timer_interrupt+0x30/0x3a\n[ 444.365457] [] handle_percpu_devid_irq+0x80/0x114\n[ 444.365470] [] generic_handle_domain_irq+0x1c/0x2a\n[ 444.365483] [] riscv_intc_irq+0x2e/0x46\n[ 444.365497] [] handle_riscv_irq+0x4a/0x74\n[ 444.365521] [] do_irq+0x7c/0x7e\n[ 444.365796] ---[ end trace 0000000000000000 ]---\n\nThat's because the fix in commit 3fec323339a4 (\"drivers: perf: Fix panic\nin riscv SBI mmap support\") was wrong since there is no need to broadcast\nto other cpus when starting a counter, that's only needed in mmap when\nthe counters could have already been started on other cpus, so simply\nremove this broadcast.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rc69-h6px-vf8q/GHSA-rc69-h6px-vf8q.json b/advisories/unreviewed/2024/05/GHSA-rc69-h6px-vf8q/GHSA-rc69-h6px-vf8q.json index a9d35b4e52c..f0542529b71 100644 --- a/advisories/unreviewed/2024/05/GHSA-rc69-h6px-vf8q/GHSA-rc69-h6px-vf8q.json +++ b/advisories/unreviewed/2024/05/GHSA-rc69-h6px-vf8q/GHSA-rc69-h6px-vf8q.json @@ -7,12 +7,8 @@ "CVE-2023-52840" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - fix use after free in rmi_unregister_function()\n\nThe put_device() calls rmi_release_function() which frees \"fn\" so the\ndereference on the next line \"fn->num_of_irqs\" is a use after free.\nMove the put_device() to the end to fix this.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rhrr-35q8-4p7f/GHSA-rhrr-35q8-4p7f.json b/advisories/unreviewed/2024/05/GHSA-rhrr-35q8-4p7f/GHSA-rhrr-35q8-4p7f.json index 6934f676b22..a5cd1d13b96 100644 --- a/advisories/unreviewed/2024/05/GHSA-rhrr-35q8-4p7f/GHSA-rhrr-35q8-4p7f.json +++ b/advisories/unreviewed/2024/05/GHSA-rhrr-35q8-4p7f/GHSA-rhrr-35q8-4p7f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-rq88-rprp-wpfq/GHSA-rq88-rprp-wpfq.json b/advisories/unreviewed/2024/05/GHSA-rq88-rprp-wpfq/GHSA-rq88-rprp-wpfq.json index 9c49220ae7f..b445638232a 100644 --- a/advisories/unreviewed/2024/05/GHSA-rq88-rprp-wpfq/GHSA-rq88-rprp-wpfq.json +++ b/advisories/unreviewed/2024/05/GHSA-rq88-rprp-wpfq/GHSA-rq88-rprp-wpfq.json @@ -7,12 +7,8 @@ "CVE-2024-26973" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfat: fix uninitialized field in nostale filehandles\n\nWhen fat_encode_fh_nostale() encodes file handle without a parent it\nstores only first 10 bytes of the file handle. However the length of the\nfile handle must be a multiple of 4 so the file handle is actually 12\nbytes long and the last two bytes remain uninitialized. This is not\ngreat at we potentially leak uninitialized information with the handle\nto userspace. Properly initialize the full handle length.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rqgx-53jr-xx5j/GHSA-rqgx-53jr-xx5j.json b/advisories/unreviewed/2024/05/GHSA-rqgx-53jr-xx5j/GHSA-rqgx-53jr-xx5j.json index d4819093256..fd03f783254 100644 --- a/advisories/unreviewed/2024/05/GHSA-rqgx-53jr-xx5j/GHSA-rqgx-53jr-xx5j.json +++ b/advisories/unreviewed/2024/05/GHSA-rqgx-53jr-xx5j/GHSA-rqgx-53jr-xx5j.json @@ -7,12 +7,8 @@ "CVE-2024-26969" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: qcom: gcc-ipq8074: fix terminating of frequency table arrays\n\nThe frequency table arrays are supposed to be terminated with an\nempty element. Add such entry to the end of the arrays where it\nis missing in order to avoid possible out-of-bound access when\nthe table is traversed by functions like qcom_find_freq() or\nqcom_find_freq_floor().\n\nOnly compile tested.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rv5x-862j-q6f6/GHSA-rv5x-862j-q6f6.json b/advisories/unreviewed/2024/05/GHSA-rv5x-862j-q6f6/GHSA-rv5x-862j-q6f6.json index dc1640f0975..6ad76b8c561 100644 --- a/advisories/unreviewed/2024/05/GHSA-rv5x-862j-q6f6/GHSA-rv5x-862j-q6f6.json +++ b/advisories/unreviewed/2024/05/GHSA-rv5x-862j-q6f6/GHSA-rv5x-862j-q6f6.json @@ -7,12 +7,8 @@ "CVE-2024-27001" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncomedi: vmk80xx: fix incomplete endpoint checking\n\nWhile vmk80xx does have endpoint checking implemented, some things\ncan fall through the cracks. Depending on the hardware model,\nURBs can have either bulk or interrupt type, and current version\nof vmk80xx_find_usb_endpoints() function does not take that fully\ninto account. While this warning does not seem to be too harmful,\nat the very least it will crash systems with 'panic_on_warn' set on\nthem.\n\nFix the issue found by Syzkaller [1] by somewhat simplifying the\nendpoint checking process with usb_find_common_endpoints() and\nensuring that only expected endpoint types are present.\n\nThis patch has not been tested on real hardware.\n\n[1] Syzkaller report:\nusb 1-1: BOGUS urb xfer, pipe 1 != type 3\nWARNING: CPU: 0 PID: 781 at drivers/usb/core/urb.c:504 usb_submit_urb+0xc4e/0x18c0 drivers/usb/core/urb.c:503\n...\nCall Trace:\n \n usb_start_wait_urb+0x113/0x520 drivers/usb/core/message.c:59\n vmk80xx_reset_device drivers/comedi/drivers/vmk80xx.c:227 [inline]\n vmk80xx_auto_attach+0xa1c/0x1a40 drivers/comedi/drivers/vmk80xx.c:818\n comedi_auto_config+0x238/0x380 drivers/comedi/drivers.c:1067\n usb_probe_interface+0x5cd/0xb00 drivers/usb/core/driver.c:399\n...\n\nSimilar issue also found by Syzkaller:", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rwq9-67rv-755x/GHSA-rwq9-67rv-755x.json b/advisories/unreviewed/2024/05/GHSA-rwq9-67rv-755x/GHSA-rwq9-67rv-755x.json index ad72ac6c681..85b31ccbe55 100644 --- a/advisories/unreviewed/2024/05/GHSA-rwq9-67rv-755x/GHSA-rwq9-67rv-755x.json +++ b/advisories/unreviewed/2024/05/GHSA-rwq9-67rv-755x/GHSA-rwq9-67rv-755x.json @@ -7,12 +7,8 @@ "CVE-2023-52705" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix underflow in second superblock position calculations\n\nMacro NILFS_SB2_OFFSET_BYTES, which computes the position of the second\nsuperblock, underflows when the argument device size is less than 4096\nbytes. Therefore, when using this macro, it is necessary to check in\nadvance that the device size is not less than a lower limit, or at least\nthat underflow does not occur.\n\nThe current nilfs2 implementation lacks this check, causing out-of-bound\nblock access when mounting devices smaller than 4096 bytes:\n\n I/O error, dev loop0, sector 36028797018963960 op 0x0:(READ) flags 0x0\n phys_seg 1 prio class 2\n NILFS (loop0): unable to read secondary superblock (blocksize = 1024)\n\nIn addition, when trying to resize the filesystem to a size below 4096\nbytes, this underflow occurs in nilfs_resize_fs(), passing a huge number\nof segments to nilfs_sufile_resize(), corrupting parameters such as the\nnumber of segments in superblocks. This causes excessive loop iterations\nin nilfs_sufile_resize() during a subsequent resize ioctl, causing\nsemaphore ns_segctor_sem to block for a long time and hang the writer\nthread:\n\n INFO: task segctord:5067 blocked for more than 143 seconds.\n Not tainted 6.2.0-rc8-syzkaller-00015-gf6feea56f66d #0\n \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n task:segctord state:D stack:23456 pid:5067 ppid:2\n flags:0x00004000\n Call Trace:\n \n context_switch kernel/sched/core.c:5293 [inline]\n __schedule+0x1409/0x43f0 kernel/sched/core.c:6606\n schedule+0xc3/0x190 kernel/sched/core.c:6682\n rwsem_down_write_slowpath+0xfcf/0x14a0 kernel/locking/rwsem.c:1190\n nilfs_transaction_lock+0x25c/0x4f0 fs/nilfs2/segment.c:357\n nilfs_segctor_thread_construct fs/nilfs2/segment.c:2486 [inline]\n nilfs_segctor_thread+0x52f/0x1140 fs/nilfs2/segment.c:2570\n kthread+0x270/0x300 kernel/kthread.c:376\n ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:308\n \n ...\n Call Trace:\n \n folio_mark_accessed+0x51c/0xf00 mm/swap.c:515\n __nilfs_get_page_block fs/nilfs2/page.c:42 [inline]\n nilfs_grab_buffer+0x3d3/0x540 fs/nilfs2/page.c:61\n nilfs_mdt_submit_block+0xd7/0x8f0 fs/nilfs2/mdt.c:121\n nilfs_mdt_read_block+0xeb/0x430 fs/nilfs2/mdt.c:176\n nilfs_mdt_get_block+0x12d/0xbb0 fs/nilfs2/mdt.c:251\n nilfs_sufile_get_segment_usage_block fs/nilfs2/sufile.c:92 [inline]\n nilfs_sufile_truncate_range fs/nilfs2/sufile.c:679 [inline]\n nilfs_sufile_resize+0x7a3/0x12b0 fs/nilfs2/sufile.c:777\n nilfs_resize_fs+0x20c/0xed0 fs/nilfs2/super.c:422\n nilfs_ioctl_resize fs/nilfs2/ioctl.c:1033 [inline]\n nilfs_ioctl+0x137c/0x2440 fs/nilfs2/ioctl.c:1301\n ...\n\nThis fixes these issues by inserting appropriate minimum device size\nchecks or anti-underflow checks, depending on where the macro is used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rwr5-hmxr-6v8j/GHSA-rwr5-hmxr-6v8j.json b/advisories/unreviewed/2024/05/GHSA-rwr5-hmxr-6v8j/GHSA-rwr5-hmxr-6v8j.json index d8661f33912..d60a9a84d01 100644 --- a/advisories/unreviewed/2024/05/GHSA-rwr5-hmxr-6v8j/GHSA-rwr5-hmxr-6v8j.json +++ b/advisories/unreviewed/2024/05/GHSA-rwr5-hmxr-6v8j/GHSA-rwr5-hmxr-6v8j.json @@ -7,12 +7,8 @@ "CVE-2023-52807" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix out-of-bounds access may occur when coalesce info is read via debugfs\n\nThe hns3 driver define an array of string to show the coalesce\ninfo, but if the kernel adds a new mode or a new state,\nout-of-bounds access may occur when coalesce info is read via\ndebugfs, this patch fix the problem.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-w8h9-x2qc-v5qf/GHSA-w8h9-x2qc-v5qf.json b/advisories/unreviewed/2024/05/GHSA-w8h9-x2qc-v5qf/GHSA-w8h9-x2qc-v5qf.json index d1552979e87..bf04f0ac087 100644 --- a/advisories/unreviewed/2024/05/GHSA-w8h9-x2qc-v5qf/GHSA-w8h9-x2qc-v5qf.json +++ b/advisories/unreviewed/2024/05/GHSA-w8h9-x2qc-v5qf/GHSA-w8h9-x2qc-v5qf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-w8wx-3v4m-pwrr/GHSA-w8wx-3v4m-pwrr.json b/advisories/unreviewed/2024/05/GHSA-w8wx-3v4m-pwrr/GHSA-w8wx-3v4m-pwrr.json index b35596d0eb8..0e8793b1291 100644 --- a/advisories/unreviewed/2024/05/GHSA-w8wx-3v4m-pwrr/GHSA-w8wx-3v4m-pwrr.json +++ b/advisories/unreviewed/2024/05/GHSA-w8wx-3v4m-pwrr/GHSA-w8wx-3v4m-pwrr.json @@ -7,12 +7,8 @@ "CVE-2023-52853" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhid: cp2112: Fix duplicate workqueue initialization\n\nPreviously the cp2112 driver called INIT_DELAYED_WORK within\ncp2112_gpio_irq_startup, resulting in duplicate initilizations of the\nworkqueue on subsequent IRQ startups following an initial request. This\nresulted in a warning in set_work_data in workqueue.c, as well as a rare\nNULL dereference within process_one_work in workqueue.c.\n\nInitialize the workqueue within _probe instead.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-w9fv-gm94-h938/GHSA-w9fv-gm94-h938.json b/advisories/unreviewed/2024/05/GHSA-w9fv-gm94-h938/GHSA-w9fv-gm94-h938.json index cae006251b8..bb8aac45515 100644 --- a/advisories/unreviewed/2024/05/GHSA-w9fv-gm94-h938/GHSA-w9fv-gm94-h938.json +++ b/advisories/unreviewed/2024/05/GHSA-w9fv-gm94-h938/GHSA-w9fv-gm94-h938.json @@ -7,12 +7,8 @@ "CVE-2023-52731" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: Fix invalid page access after closing deferred I/O devices\n\nWhen a fbdev with deferred I/O is once opened and closed, the dirty\npages still remain queued in the pageref list, and eventually later\nthose may be processed in the delayed work. This may lead to a\ncorruption of pages, hitting an Oops.\n\nThis patch makes sure to cancel the delayed work and clean up the\npageref list at closing the device for addressing the bug. A part of\nthe cleanup code is factored out as a new helper function that is\ncalled from the common fb_release().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-wmmp-mchh-75gf/GHSA-wmmp-mchh-75gf.json b/advisories/unreviewed/2024/05/GHSA-wmmp-mchh-75gf/GHSA-wmmp-mchh-75gf.json index e25f722a435..734e96f1f1f 100644 --- a/advisories/unreviewed/2024/05/GHSA-wmmp-mchh-75gf/GHSA-wmmp-mchh-75gf.json +++ b/advisories/unreviewed/2024/05/GHSA-wmmp-mchh-75gf/GHSA-wmmp-mchh-75gf.json @@ -7,12 +7,8 @@ "CVE-2024-27401" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirewire: nosy: ensure user_length is taken into account when fetching packet contents\n\nEnsure that packet_buffer_get respects the user_length provided. If\nthe length of the head packet exceeds the user_length, packet_buffer_get\nwill now return 0 to signify to the user that no data were read\nand a larger buffer size is required. Helps prevent user space overflows.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-wpg8-rfjm-9g3w/GHSA-wpg8-rfjm-9g3w.json b/advisories/unreviewed/2024/05/GHSA-wpg8-rfjm-9g3w/GHSA-wpg8-rfjm-9g3w.json index 9ea789f7360..556ecdacccf 100644 --- a/advisories/unreviewed/2024/05/GHSA-wpg8-rfjm-9g3w/GHSA-wpg8-rfjm-9g3w.json +++ b/advisories/unreviewed/2024/05/GHSA-wpg8-rfjm-9g3w/GHSA-wpg8-rfjm-9g3w.json @@ -7,12 +7,8 @@ "CVE-2023-52741" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix use-after-free in rdata->read_into_pages()\n\nWhen the network status is unstable, use-after-free may occur when\nread data from the server.\n\n BUG: KASAN: use-after-free in readpages_fill_pages+0x14c/0x7e0\n\n Call Trace:\n \n dump_stack_lvl+0x38/0x4c\n print_report+0x16f/0x4a6\n kasan_report+0xb7/0x130\n readpages_fill_pages+0x14c/0x7e0\n cifs_readv_receive+0x46d/0xa40\n cifs_demultiplex_thread+0x121c/0x1490\n kthread+0x16b/0x1a0\n ret_from_fork+0x2c/0x50\n \n\n Allocated by task 2535:\n kasan_save_stack+0x22/0x50\n kasan_set_track+0x25/0x30\n __kasan_kmalloc+0x82/0x90\n cifs_readdata_direct_alloc+0x2c/0x110\n cifs_readdata_alloc+0x2d/0x60\n cifs_readahead+0x393/0xfe0\n read_pages+0x12f/0x470\n page_cache_ra_unbounded+0x1b1/0x240\n filemap_get_pages+0x1c8/0x9a0\n filemap_read+0x1c0/0x540\n cifs_strict_readv+0x21b/0x240\n vfs_read+0x395/0x4b0\n ksys_read+0xb8/0x150\n do_syscall_64+0x3f/0x90\n entry_SYSCALL_64_after_hwframe+0x72/0xdc\n\n Freed by task 79:\n kasan_save_stack+0x22/0x50\n kasan_set_track+0x25/0x30\n kasan_save_free_info+0x2e/0x50\n __kasan_slab_free+0x10e/0x1a0\n __kmem_cache_free+0x7a/0x1a0\n cifs_readdata_release+0x49/0x60\n process_one_work+0x46c/0x760\n worker_thread+0x2a4/0x6f0\n kthread+0x16b/0x1a0\n ret_from_fork+0x2c/0x50\n\n Last potentially related work creation:\n kasan_save_stack+0x22/0x50\n __kasan_record_aux_stack+0x95/0xb0\n insert_work+0x2b/0x130\n __queue_work+0x1fe/0x660\n queue_work_on+0x4b/0x60\n smb2_readv_callback+0x396/0x800\n cifs_abort_connection+0x474/0x6a0\n cifs_reconnect+0x5cb/0xa50\n cifs_readv_from_socket.cold+0x22/0x6c\n cifs_read_page_from_socket+0xc1/0x100\n readpages_fill_pages.cold+0x2f/0x46\n cifs_readv_receive+0x46d/0xa40\n cifs_demultiplex_thread+0x121c/0x1490\n kthread+0x16b/0x1a0\n ret_from_fork+0x2c/0x50\n\nThe following function calls will cause UAF of the rdata pointer.\n\nreadpages_fill_pages\n cifs_read_page_from_socket\n cifs_readv_from_socket\n cifs_reconnect\n __cifs_reconnect\n cifs_abort_connection\n mid->callback() --> smb2_readv_callback\n queue_work(&rdata->work) # if the worker completes first,\n # the rdata is freed\n cifs_readv_complete\n kref_put\n cifs_readdata_release\n kfree(rdata)\n return rdata->... # UAF in readpages_fill_pages()\n\nSimilarly, this problem also occurs in the uncache_fill_pages().\n\nFix this by adjusts the order of condition judgment in the return\nstatement.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-ww8p-33xg-gvhc/GHSA-ww8p-33xg-gvhc.json b/advisories/unreviewed/2024/05/GHSA-ww8p-33xg-gvhc/GHSA-ww8p-33xg-gvhc.json index a21af932e03..058d232fbfc 100644 --- a/advisories/unreviewed/2024/05/GHSA-ww8p-33xg-gvhc/GHSA-ww8p-33xg-gvhc.json +++ b/advisories/unreviewed/2024/05/GHSA-ww8p-33xg-gvhc/GHSA-ww8p-33xg-gvhc.json @@ -7,12 +7,8 @@ "CVE-2024-27400" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: once more fix the call oder in amdgpu_ttm_move() v2\n\nThis reverts drm/amdgpu: fix ftrace event amdgpu_bo_move always move\non same heap. The basic problem here is that after the move the old\nlocation is simply not available any more.\n\nSome fixes were suggested, but essentially we should call the move\nnotification before actually moving things because only this way we have\nthe correct order for DMA-buf and VM move notifications as well.\n\nAlso rework the statistic handling so that we don't update the eviction\ncounter before the move.\n\nv2: add missing NULL check", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-x5rp-2v68-jcgf/GHSA-x5rp-2v68-jcgf.json b/advisories/unreviewed/2024/05/GHSA-x5rp-2v68-jcgf/GHSA-x5rp-2v68-jcgf.json index 2201b488366..b45936a508e 100644 --- a/advisories/unreviewed/2024/05/GHSA-x5rp-2v68-jcgf/GHSA-x5rp-2v68-jcgf.json +++ b/advisories/unreviewed/2024/05/GHSA-x5rp-2v68-jcgf/GHSA-x5rp-2v68-jcgf.json @@ -7,12 +7,8 @@ "CVE-2024-26993" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs: sysfs: Fix reference leak in sysfs_break_active_protection()\n\nThe sysfs_break_active_protection() routine has an obvious reference\nleak in its error path. If the call to kernfs_find_and_get() fails then\nkn will be NULL, so the companion sysfs_unbreak_active_protection()\nroutine won't get called (and would only cause an access violation by\ntrying to dereference kn->parent if it was called). As a result, the\nreference to kobj acquired at the start of the function will never be\nreleased.\n\nFix the leak by adding an explicit kobject_put() call when kn is NULL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-x5vm-26pp-xff5/GHSA-x5vm-26pp-xff5.json b/advisories/unreviewed/2024/05/GHSA-x5vm-26pp-xff5/GHSA-x5vm-26pp-xff5.json index 9c0393f6bc6..422da2720cb 100644 --- a/advisories/unreviewed/2024/05/GHSA-x5vm-26pp-xff5/GHSA-x5vm-26pp-xff5.json +++ b/advisories/unreviewed/2024/05/GHSA-x5vm-26pp-xff5/GHSA-x5vm-26pp-xff5.json @@ -7,12 +7,8 @@ "CVE-2023-52737" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: lock the inode in shared mode before starting fiemap\n\nCurrently fiemap does not take the inode's lock (VFS lock), it only locks\na file range in the inode's io tree. This however can lead to a deadlock\nif we have a concurrent fsync on the file and fiemap code triggers a fault\nwhen accessing the user space buffer with fiemap_fill_next_extent(). The\ndeadlock happens on the inode's i_mmap_lock semaphore, which is taken both\nby fsync and btrfs_page_mkwrite(). This deadlock was recently reported by\nsyzbot and triggers a trace like the following:\n\n task:syz-executor361 state:D stack:20264 pid:5668 ppid:5119 flags:0x00004004\n Call Trace:\n \n context_switch kernel/sched/core.c:5293 [inline]\n __schedule+0x995/0xe20 kernel/sched/core.c:6606\n schedule+0xcb/0x190 kernel/sched/core.c:6682\n wait_on_state fs/btrfs/extent-io-tree.c:707 [inline]\n wait_extent_bit+0x577/0x6f0 fs/btrfs/extent-io-tree.c:751\n lock_extent+0x1c2/0x280 fs/btrfs/extent-io-tree.c:1742\n find_lock_delalloc_range+0x4e6/0x9c0 fs/btrfs/extent_io.c:488\n writepage_delalloc+0x1ef/0x540 fs/btrfs/extent_io.c:1863\n __extent_writepage+0x736/0x14e0 fs/btrfs/extent_io.c:2174\n extent_write_cache_pages+0x983/0x1220 fs/btrfs/extent_io.c:3091\n extent_writepages+0x219/0x540 fs/btrfs/extent_io.c:3211\n do_writepages+0x3c3/0x680 mm/page-writeback.c:2581\n filemap_fdatawrite_wbc+0x11e/0x170 mm/filemap.c:388\n __filemap_fdatawrite_range mm/filemap.c:421 [inline]\n filemap_fdatawrite_range+0x175/0x200 mm/filemap.c:439\n btrfs_fdatawrite_range fs/btrfs/file.c:3850 [inline]\n start_ordered_ops fs/btrfs/file.c:1737 [inline]\n btrfs_sync_file+0x4ff/0x1190 fs/btrfs/file.c:1839\n generic_write_sync include/linux/fs.h:2885 [inline]\n btrfs_do_write_iter+0xcd3/0x1280 fs/btrfs/file.c:1684\n call_write_iter include/linux/fs.h:2189 [inline]\n new_sync_write fs/read_write.c:491 [inline]\n vfs_write+0x7dc/0xc50 fs/read_write.c:584\n ksys_write+0x177/0x2a0 fs/read_write.c:637\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n RIP: 0033:0x7f7d4054e9b9\n RSP: 002b:00007f7d404fa2f8 EFLAGS: 00000246 ORIG_RAX: 0000000000000001\n RAX: ffffffffffffffda RBX: 00007f7d405d87a0 RCX: 00007f7d4054e9b9\n RDX: 0000000000000090 RSI: 0000000020000000 RDI: 0000000000000006\n RBP: 00007f7d405a51d0 R08: 0000000000000000 R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000000246 R12: 61635f65646f6e69\n R13: 65646f7475616f6e R14: 7261637369646f6e R15: 00007f7d405d87a8\n \n INFO: task syz-executor361:5697 blocked for more than 145 seconds.\n Not tainted 6.2.0-rc3-syzkaller-00376-g7c6984405241 #0\n \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n task:syz-executor361 state:D stack:21216 pid:5697 ppid:5119 flags:0x00004004\n Call Trace:\n \n context_switch kernel/sched/core.c:5293 [inline]\n __schedule+0x995/0xe20 kernel/sched/core.c:6606\n schedule+0xcb/0x190 kernel/sched/core.c:6682\n rwsem_down_read_slowpath+0x5f9/0x930 kernel/locking/rwsem.c:1095\n __down_read_common+0x54/0x2a0 kernel/locking/rwsem.c:1260\n btrfs_page_mkwrite+0x417/0xc80 fs/btrfs/inode.c:8526\n do_page_mkwrite+0x19e/0x5e0 mm/memory.c:2947\n wp_page_shared+0x15e/0x380 mm/memory.c:3295\n handle_pte_fault mm/memory.c:4949 [inline]\n __handle_mm_fault mm/memory.c:5073 [inline]\n handle_mm_fault+0x1b79/0x26b0 mm/memory.c:5219\n do_user_addr_fault+0x69b/0xcb0 arch/x86/mm/fault.c:1428\n handle_page_fault arch/x86/mm/fault.c:1519 [inline]\n exc_page_fault+0x7a/0x110 arch/x86/mm/fault.c:1575\n asm_exc_page_fault+0x22/0x30 arch/x86/include/asm/idtentry.h:570\n RIP: 0010:copy_user_short_string+0xd/0x40 arch/x86/lib/copy_user_64.S:233\n Code: 74 0a 89 (...)\n RSP: 0018:ffffc9000570f330 EFLAGS: 000502\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-x632-g56x-qcm8/GHSA-x632-g56x-qcm8.json b/advisories/unreviewed/2024/05/GHSA-x632-g56x-qcm8/GHSA-x632-g56x-qcm8.json index 013062476f4..e9b8962b2d8 100644 --- a/advisories/unreviewed/2024/05/GHSA-x632-g56x-qcm8/GHSA-x632-g56x-qcm8.json +++ b/advisories/unreviewed/2024/05/GHSA-x632-g56x-qcm8/GHSA-x632-g56x-qcm8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -75,9 +73,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xchp-7x95-36g7/GHSA-xchp-7x95-36g7.json b/advisories/unreviewed/2024/05/GHSA-xchp-7x95-36g7/GHSA-xchp-7x95-36g7.json index b5028b7b1f0..b4d49279a37 100644 --- a/advisories/unreviewed/2024/05/GHSA-xchp-7x95-36g7/GHSA-xchp-7x95-36g7.json +++ b/advisories/unreviewed/2024/05/GHSA-xchp-7x95-36g7/GHSA-xchp-7x95-36g7.json @@ -7,12 +7,8 @@ "CVE-2021-47407" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Handle SRCU initialization failure during page track init\n\nCheck the return of init_srcu_struct(), which can fail due to OOM, when\ninitializing the page track mechanism. Lack of checking leads to a NULL\npointer deref found by a modified syzkaller.\n\n[Move the call towards the beginning of kvm_arch_init_vm. - Paolo]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xhh8-8jq9-8vf6/GHSA-xhh8-8jq9-8vf6.json b/advisories/unreviewed/2024/05/GHSA-xhh8-8jq9-8vf6/GHSA-xhh8-8jq9-8vf6.json index fe4643a0e1e..625db5be50a 100644 --- a/advisories/unreviewed/2024/05/GHSA-xhh8-8jq9-8vf6/GHSA-xhh8-8jq9-8vf6.json +++ b/advisories/unreviewed/2024/05/GHSA-xhh8-8jq9-8vf6/GHSA-xhh8-8jq9-8vf6.json @@ -7,12 +7,8 @@ "CVE-2023-52804" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/jfs: Add validity check for db_maxag and db_agpref\n\nBoth db_maxag and db_agpref are used as the index of the\ndb_agfree array, but there is currently no validity check for\ndb_maxag and db_agpref, which can lead to errors.\n\nThe following is related bug reported by Syzbot:\n\nUBSAN: array-index-out-of-bounds in fs/jfs/jfs_dmap.c:639:20\nindex 7936 is out of range for type 'atomic_t[128]'\n\nAdd checking that the values of db_maxag and db_agpref are valid\nindexes for the db_agfree array.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xj3r-45pc-vrfq/GHSA-xj3r-45pc-vrfq.json b/advisories/unreviewed/2024/05/GHSA-xj3r-45pc-vrfq/GHSA-xj3r-45pc-vrfq.json index 946c7a95f73..5391f927ca8 100644 --- a/advisories/unreviewed/2024/05/GHSA-xj3r-45pc-vrfq/GHSA-xj3r-45pc-vrfq.json +++ b/advisories/unreviewed/2024/05/GHSA-xj3r-45pc-vrfq/GHSA-xj3r-45pc-vrfq.json @@ -7,12 +7,8 @@ "CVE-2023-52836" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nlocking/ww_mutex/test: Fix potential workqueue corruption\n\nIn some cases running with the test-ww_mutex code, I was seeing\nodd behavior where sometimes it seemed flush_workqueue was\nreturning before all the work threads were finished.\n\nOften this would cause strange crashes as the mutexes would be\nfreed while they were being used.\n\nLooking at the code, there is a lifetime problem as the\ncontrolling thread that spawns the work allocates the\n\"struct stress\" structures that are passed to the workqueue\nthreads. Then when the workqueue threads are finished,\nthey free the stress struct that was passed to them.\n\nUnfortunately the workqueue work_struct node is in the stress\nstruct. Which means the work_struct is freed before the work\nthread returns and while flush_workqueue is waiting.\n\nIt seems like a better idea to have the controlling thread\nboth allocate and free the stress structures, so that we can\nbe sure we don't corrupt the workqueue by freeing the structure\nprematurely.\n\nSo this patch reworks the test to do so, and with this change\nI no longer see the early flush_workqueue returns.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xwvh-fxhh-3qrr/GHSA-xwvh-fxhh-3qrr.json b/advisories/unreviewed/2024/05/GHSA-xwvh-fxhh-3qrr/GHSA-xwvh-fxhh-3qrr.json index cd1dccf1f4e..31066ef57fd 100644 --- a/advisories/unreviewed/2024/05/GHSA-xwvh-fxhh-3qrr/GHSA-xwvh-fxhh-3qrr.json +++ b/advisories/unreviewed/2024/05/GHSA-xwvh-fxhh-3qrr/GHSA-xwvh-fxhh-3qrr.json @@ -7,12 +7,8 @@ "CVE-2021-47402" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sched: flower: protect fl_walk() with rcu\n\nPatch that refactored fl_walk() to use idr_for_each_entry_continue_ul()\nalso removed rcu protection of individual filters which causes following\nuse-after-free when filter is deleted concurrently. Fix fl_walk() to obtain\nrcu read lock while iterating and taking the filter reference and temporary\nrelease the lock while calling arg->fn() callback that can sleep.\n\nKASAN trace:\n\n[ 352.773640] ==================================================================\n[ 352.775041] BUG: KASAN: use-after-free in fl_walk+0x159/0x240 [cls_flower]\n[ 352.776304] Read of size 4 at addr ffff8881c8251480 by task tc/2987\n\n[ 352.777862] CPU: 3 PID: 2987 Comm: tc Not tainted 5.15.0-rc2+ #2\n[ 352.778980] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n[ 352.781022] Call Trace:\n[ 352.781573] dump_stack_lvl+0x46/0x5a\n[ 352.782332] print_address_description.constprop.0+0x1f/0x140\n[ 352.783400] ? fl_walk+0x159/0x240 [cls_flower]\n[ 352.784292] ? fl_walk+0x159/0x240 [cls_flower]\n[ 352.785138] kasan_report.cold+0x83/0xdf\n[ 352.785851] ? fl_walk+0x159/0x240 [cls_flower]\n[ 352.786587] kasan_check_range+0x145/0x1a0\n[ 352.787337] fl_walk+0x159/0x240 [cls_flower]\n[ 352.788163] ? fl_put+0x10/0x10 [cls_flower]\n[ 352.789007] ? __mutex_unlock_slowpath.constprop.0+0x220/0x220\n[ 352.790102] tcf_chain_dump+0x231/0x450\n[ 352.790878] ? tcf_chain_tp_delete_empty+0x170/0x170\n[ 352.791833] ? __might_sleep+0x2e/0xc0\n[ 352.792594] ? tfilter_notify+0x170/0x170\n[ 352.793400] ? __mutex_unlock_slowpath.constprop.0+0x220/0x220\n[ 352.794477] tc_dump_tfilter+0x385/0x4b0\n[ 352.795262] ? tc_new_tfilter+0x1180/0x1180\n[ 352.796103] ? __mod_node_page_state+0x1f/0xc0\n[ 352.796974] ? __build_skb_around+0x10e/0x130\n[ 352.797826] netlink_dump+0x2c0/0x560\n[ 352.798563] ? netlink_getsockopt+0x430/0x430\n[ 352.799433] ? __mutex_unlock_slowpath.constprop.0+0x220/0x220\n[ 352.800542] __netlink_dump_start+0x356/0x440\n[ 352.801397] rtnetlink_rcv_msg+0x3ff/0x550\n[ 352.802190] ? tc_new_tfilter+0x1180/0x1180\n[ 352.802872] ? rtnl_calcit.isra.0+0x1f0/0x1f0\n[ 352.803668] ? tc_new_tfilter+0x1180/0x1180\n[ 352.804344] ? _copy_from_iter_nocache+0x800/0x800\n[ 352.805202] ? kasan_set_track+0x1c/0x30\n[ 352.805900] netlink_rcv_skb+0xc6/0x1f0\n[ 352.806587] ? rht_deferred_worker+0x6b0/0x6b0\n[ 352.807455] ? rtnl_calcit.isra.0+0x1f0/0x1f0\n[ 352.808324] ? netlink_ack+0x4d0/0x4d0\n[ 352.809086] ? netlink_deliver_tap+0x62/0x3d0\n[ 352.809951] netlink_unicast+0x353/0x480\n[ 352.810744] ? netlink_attachskb+0x430/0x430\n[ 352.811586] ? __alloc_skb+0xd7/0x200\n[ 352.812349] netlink_sendmsg+0x396/0x680\n[ 352.813132] ? netlink_unicast+0x480/0x480\n[ 352.813952] ? __import_iovec+0x192/0x210\n[ 352.814759] ? netlink_unicast+0x480/0x480\n[ 352.815580] sock_sendmsg+0x6c/0x80\n[ 352.816299] ____sys_sendmsg+0x3a5/0x3c0\n[ 352.817096] ? kernel_sendmsg+0x30/0x30\n[ 352.817873] ? __ia32_sys_recvmmsg+0x150/0x150\n[ 352.818753] ___sys_sendmsg+0xd8/0x140\n[ 352.819518] ? sendmsg_copy_msghdr+0x110/0x110\n[ 352.820402] ? ___sys_recvmsg+0xf4/0x1a0\n[ 352.821110] ? __copy_msghdr_from_user+0x260/0x260\n[ 352.821934] ? _raw_spin_lock+0x81/0xd0\n[ 352.822680] ? __handle_mm_fault+0xef3/0x1b20\n[ 352.823549] ? rb_insert_color+0x2a/0x270\n[ 352.824373] ? copy_page_range+0x16b0/0x16b0\n[ 352.825209] ? perf_event_update_userpage+0x2d0/0x2d0\n[ 352.826190] ? __fget_light+0xd9/0xf0\n[ 352.826941] __sys_sendmsg+0xb3/0x130\n[ 352.827613] ? __sys_sendmsg_sock+0x20/0x20\n[ 352.828377] ? do_user_addr_fault+0x2c5/0x8a0\n[ 352.829184] ? fpregs_assert_state_consistent+0x52/0x60\n[ 352.830001] ? exit_to_user_mode_prepare+0x32/0x160\n[ 352.830845] do_syscall_64+0x35/0x80\n[ 352.831445] entry_SYSCALL_64_after_hwframe+0x44/0xae\n[ 352.832331] RIP: 0033:0x7f7bee973c17\n[ \n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-4x39-cp3h-x8w9/GHSA-4x39-cp3h-x8w9.json b/advisories/unreviewed/2024/06/GHSA-4x39-cp3h-x8w9/GHSA-4x39-cp3h-x8w9.json index 22dfb7c9d6a..959cc9ab789 100644 --- a/advisories/unreviewed/2024/06/GHSA-4x39-cp3h-x8w9/GHSA-4x39-cp3h-x8w9.json +++ b/advisories/unreviewed/2024/06/GHSA-4x39-cp3h-x8w9/GHSA-4x39-cp3h-x8w9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-7g9c-87vj-jrwv/GHSA-7g9c-87vj-jrwv.json b/advisories/unreviewed/2024/06/GHSA-7g9c-87vj-jrwv/GHSA-7g9c-87vj-jrwv.json index 625c1c5f0d5..2ba5526100c 100644 --- a/advisories/unreviewed/2024/06/GHSA-7g9c-87vj-jrwv/GHSA-7g9c-87vj-jrwv.json +++ b/advisories/unreviewed/2024/06/GHSA-7g9c-87vj-jrwv/GHSA-7g9c-87vj-jrwv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-7rxg-g96w-25cm/GHSA-7rxg-g96w-25cm.json b/advisories/unreviewed/2024/06/GHSA-7rxg-g96w-25cm/GHSA-7rxg-g96w-25cm.json index a3bd672a138..7b00402a2d6 100644 --- a/advisories/unreviewed/2024/06/GHSA-7rxg-g96w-25cm/GHSA-7rxg-g96w-25cm.json +++ b/advisories/unreviewed/2024/06/GHSA-7rxg-g96w-25cm/GHSA-7rxg-g96w-25cm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-8g25-xmmm-86qm/GHSA-8g25-xmmm-86qm.json b/advisories/unreviewed/2024/06/GHSA-8g25-xmmm-86qm/GHSA-8g25-xmmm-86qm.json index 75558ee67e0..64bf252179c 100644 --- a/advisories/unreviewed/2024/06/GHSA-8g25-xmmm-86qm/GHSA-8g25-xmmm-86qm.json +++ b/advisories/unreviewed/2024/06/GHSA-8g25-xmmm-86qm/GHSA-8g25-xmmm-86qm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-9jv6-43px-5ccm/GHSA-9jv6-43px-5ccm.json b/advisories/unreviewed/2024/06/GHSA-9jv6-43px-5ccm/GHSA-9jv6-43px-5ccm.json index c70dd161eba..a9e7e585544 100644 --- a/advisories/unreviewed/2024/06/GHSA-9jv6-43px-5ccm/GHSA-9jv6-43px-5ccm.json +++ b/advisories/unreviewed/2024/06/GHSA-9jv6-43px-5ccm/GHSA-9jv6-43px-5ccm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-f44g-xj93-9xvh/GHSA-f44g-xj93-9xvh.json b/advisories/unreviewed/2024/06/GHSA-f44g-xj93-9xvh/GHSA-f44g-xj93-9xvh.json index 33e11934f86..439b2fa840e 100644 --- a/advisories/unreviewed/2024/06/GHSA-f44g-xj93-9xvh/GHSA-f44g-xj93-9xvh.json +++ b/advisories/unreviewed/2024/06/GHSA-f44g-xj93-9xvh/GHSA-f44g-xj93-9xvh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-g43w-r373-4crq/GHSA-g43w-r373-4crq.json b/advisories/unreviewed/2024/06/GHSA-g43w-r373-4crq/GHSA-g43w-r373-4crq.json index 7dd840f664d..6d1ce1ff642 100644 --- a/advisories/unreviewed/2024/06/GHSA-g43w-r373-4crq/GHSA-g43w-r373-4crq.json +++ b/advisories/unreviewed/2024/06/GHSA-g43w-r373-4crq/GHSA-g43w-r373-4crq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-g8hw-97v7-43q8/GHSA-g8hw-97v7-43q8.json b/advisories/unreviewed/2024/06/GHSA-g8hw-97v7-43q8/GHSA-g8hw-97v7-43q8.json index ffc41442344..51af75d6739 100644 --- a/advisories/unreviewed/2024/06/GHSA-g8hw-97v7-43q8/GHSA-g8hw-97v7-43q8.json +++ b/advisories/unreviewed/2024/06/GHSA-g8hw-97v7-43q8/GHSA-g8hw-97v7-43q8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-m35v-cvxx-vrm6/GHSA-m35v-cvxx-vrm6.json b/advisories/unreviewed/2024/06/GHSA-m35v-cvxx-vrm6/GHSA-m35v-cvxx-vrm6.json index aaba587371a..8efdfe85d47 100644 --- a/advisories/unreviewed/2024/06/GHSA-m35v-cvxx-vrm6/GHSA-m35v-cvxx-vrm6.json +++ b/advisories/unreviewed/2024/06/GHSA-m35v-cvxx-vrm6/GHSA-m35v-cvxx-vrm6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-p4gw-x82g-6gc3/GHSA-p4gw-x82g-6gc3.json b/advisories/unreviewed/2024/06/GHSA-p4gw-x82g-6gc3/GHSA-p4gw-x82g-6gc3.json index 7e2b8f83611..255bd3754fd 100644 --- a/advisories/unreviewed/2024/06/GHSA-p4gw-x82g-6gc3/GHSA-p4gw-x82g-6gc3.json +++ b/advisories/unreviewed/2024/06/GHSA-p4gw-x82g-6gc3/GHSA-p4gw-x82g-6gc3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-vhcq-jvfq-4j3q/GHSA-vhcq-jvfq-4j3q.json b/advisories/unreviewed/2024/06/GHSA-vhcq-jvfq-4j3q/GHSA-vhcq-jvfq-4j3q.json index 31892ee84eb..77e25671780 100644 --- a/advisories/unreviewed/2024/06/GHSA-vhcq-jvfq-4j3q/GHSA-vhcq-jvfq-4j3q.json +++ b/advisories/unreviewed/2024/06/GHSA-vhcq-jvfq-4j3q/GHSA-vhcq-jvfq-4j3q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-w6v3-mr4g-vph6/GHSA-w6v3-mr4g-vph6.json b/advisories/unreviewed/2024/06/GHSA-w6v3-mr4g-vph6/GHSA-w6v3-mr4g-vph6.json index 39954c15931..bf4ab7ee8c8 100644 --- a/advisories/unreviewed/2024/06/GHSA-w6v3-mr4g-vph6/GHSA-w6v3-mr4g-vph6.json +++ b/advisories/unreviewed/2024/06/GHSA-w6v3-mr4g-vph6/GHSA-w6v3-mr4g-vph6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-wqp4-7xmq-ww2w/GHSA-wqp4-7xmq-ww2w.json b/advisories/unreviewed/2024/06/GHSA-wqp4-7xmq-ww2w/GHSA-wqp4-7xmq-ww2w.json index 9a6865398a5..dda84362d29 100644 --- a/advisories/unreviewed/2024/06/GHSA-wqp4-7xmq-ww2w/GHSA-wqp4-7xmq-ww2w.json +++ b/advisories/unreviewed/2024/06/GHSA-wqp4-7xmq-ww2w/GHSA-wqp4-7xmq-ww2w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-jjpv-jrvp-jwr3/GHSA-jjpv-jrvp-jwr3.json b/advisories/unreviewed/2024/07/GHSA-jjpv-jrvp-jwr3/GHSA-jjpv-jrvp-jwr3.json index 1c0be75da8d..f04260ab383 100644 --- a/advisories/unreviewed/2024/07/GHSA-jjpv-jrvp-jwr3/GHSA-jjpv-jrvp-jwr3.json +++ b/advisories/unreviewed/2024/07/GHSA-jjpv-jrvp-jwr3/GHSA-jjpv-jrvp-jwr3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-2m3v-5ccr-mrmf/GHSA-2m3v-5ccr-mrmf.json b/advisories/unreviewed/2024/08/GHSA-2m3v-5ccr-mrmf/GHSA-2m3v-5ccr-mrmf.json index c904ac352ef..884efdab7fd 100644 --- a/advisories/unreviewed/2024/08/GHSA-2m3v-5ccr-mrmf/GHSA-2m3v-5ccr-mrmf.json +++ b/advisories/unreviewed/2024/08/GHSA-2m3v-5ccr-mrmf/GHSA-2m3v-5ccr-mrmf.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-2xh5-xw95-xh7p/GHSA-2xh5-xw95-xh7p.json b/advisories/unreviewed/2024/08/GHSA-2xh5-xw95-xh7p/GHSA-2xh5-xw95-xh7p.json index d5545b86d85..a562f9dcc38 100644 --- a/advisories/unreviewed/2024/08/GHSA-2xh5-xw95-xh7p/GHSA-2xh5-xw95-xh7p.json +++ b/advisories/unreviewed/2024/08/GHSA-2xh5-xw95-xh7p/GHSA-2xh5-xw95-xh7p.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-3p4c-mxjg-9xjw/GHSA-3p4c-mxjg-9xjw.json b/advisories/unreviewed/2024/08/GHSA-3p4c-mxjg-9xjw/GHSA-3p4c-mxjg-9xjw.json index 2bb046096eb..48e3aa7481e 100644 --- a/advisories/unreviewed/2024/08/GHSA-3p4c-mxjg-9xjw/GHSA-3p4c-mxjg-9xjw.json +++ b/advisories/unreviewed/2024/08/GHSA-3p4c-mxjg-9xjw/GHSA-3p4c-mxjg-9xjw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-455v-j4c3-4fqr/GHSA-455v-j4c3-4fqr.json b/advisories/unreviewed/2024/08/GHSA-455v-j4c3-4fqr/GHSA-455v-j4c3-4fqr.json index 0deb0a8f3ea..a5ad347e207 100644 --- a/advisories/unreviewed/2024/08/GHSA-455v-j4c3-4fqr/GHSA-455v-j4c3-4fqr.json +++ b/advisories/unreviewed/2024/08/GHSA-455v-j4c3-4fqr/GHSA-455v-j4c3-4fqr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-4g6m-wpfm-pfxv/GHSA-4g6m-wpfm-pfxv.json b/advisories/unreviewed/2024/08/GHSA-4g6m-wpfm-pfxv/GHSA-4g6m-wpfm-pfxv.json index 2cb0749b765..403df9a2dcc 100644 --- a/advisories/unreviewed/2024/08/GHSA-4g6m-wpfm-pfxv/GHSA-4g6m-wpfm-pfxv.json +++ b/advisories/unreviewed/2024/08/GHSA-4g6m-wpfm-pfxv/GHSA-4g6m-wpfm-pfxv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-7q35-9gpc-jf7h/GHSA-7q35-9gpc-jf7h.json b/advisories/unreviewed/2024/08/GHSA-7q35-9gpc-jf7h/GHSA-7q35-9gpc-jf7h.json index 29e75c18e16..838ad665bfd 100644 --- a/advisories/unreviewed/2024/08/GHSA-7q35-9gpc-jf7h/GHSA-7q35-9gpc-jf7h.json +++ b/advisories/unreviewed/2024/08/GHSA-7q35-9gpc-jf7h/GHSA-7q35-9gpc-jf7h.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-7xq9-rvv2-9fv6/GHSA-7xq9-rvv2-9fv6.json b/advisories/unreviewed/2024/08/GHSA-7xq9-rvv2-9fv6/GHSA-7xq9-rvv2-9fv6.json index 753afb19837..9ac3b5c4759 100644 --- a/advisories/unreviewed/2024/08/GHSA-7xq9-rvv2-9fv6/GHSA-7xq9-rvv2-9fv6.json +++ b/advisories/unreviewed/2024/08/GHSA-7xq9-rvv2-9fv6/GHSA-7xq9-rvv2-9fv6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-97qg-qg86-6rpm/GHSA-97qg-qg86-6rpm.json b/advisories/unreviewed/2024/08/GHSA-97qg-qg86-6rpm/GHSA-97qg-qg86-6rpm.json index 9f633d59e06..af7ae6e8995 100644 --- a/advisories/unreviewed/2024/08/GHSA-97qg-qg86-6rpm/GHSA-97qg-qg86-6rpm.json +++ b/advisories/unreviewed/2024/08/GHSA-97qg-qg86-6rpm/GHSA-97qg-qg86-6rpm.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-pvqw-crx4-ggmg/GHSA-pvqw-crx4-ggmg.json b/advisories/unreviewed/2024/08/GHSA-pvqw-crx4-ggmg/GHSA-pvqw-crx4-ggmg.json index 2bb671f0653..4da4bf47625 100644 --- a/advisories/unreviewed/2024/08/GHSA-pvqw-crx4-ggmg/GHSA-pvqw-crx4-ggmg.json +++ b/advisories/unreviewed/2024/08/GHSA-pvqw-crx4-ggmg/GHSA-pvqw-crx4-ggmg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-qhg4-f6mr-54g9/GHSA-qhg4-f6mr-54g9.json b/advisories/unreviewed/2024/08/GHSA-qhg4-f6mr-54g9/GHSA-qhg4-f6mr-54g9.json index 6bfb7a2abeb..f470bb6fd15 100644 --- a/advisories/unreviewed/2024/08/GHSA-qhg4-f6mr-54g9/GHSA-qhg4-f6mr-54g9.json +++ b/advisories/unreviewed/2024/08/GHSA-qhg4-f6mr-54g9/GHSA-qhg4-f6mr-54g9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-qq6w-9496-259j/GHSA-qq6w-9496-259j.json b/advisories/unreviewed/2024/08/GHSA-qq6w-9496-259j/GHSA-qq6w-9496-259j.json index fb1b2376a7d..81272cfe722 100644 --- a/advisories/unreviewed/2024/08/GHSA-qq6w-9496-259j/GHSA-qq6w-9496-259j.json +++ b/advisories/unreviewed/2024/08/GHSA-qq6w-9496-259j/GHSA-qq6w-9496-259j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-259g-6529-jqq8/GHSA-259g-6529-jqq8.json b/advisories/unreviewed/2024/09/GHSA-259g-6529-jqq8/GHSA-259g-6529-jqq8.json index cddace446a5..326ca427af3 100644 --- a/advisories/unreviewed/2024/09/GHSA-259g-6529-jqq8/GHSA-259g-6529-jqq8.json +++ b/advisories/unreviewed/2024/09/GHSA-259g-6529-jqq8/GHSA-259g-6529-jqq8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-279c-3782-hjv5/GHSA-279c-3782-hjv5.json b/advisories/unreviewed/2024/09/GHSA-279c-3782-hjv5/GHSA-279c-3782-hjv5.json index eb8fe90c892..00752814406 100644 --- a/advisories/unreviewed/2024/09/GHSA-279c-3782-hjv5/GHSA-279c-3782-hjv5.json +++ b/advisories/unreviewed/2024/09/GHSA-279c-3782-hjv5/GHSA-279c-3782-hjv5.json @@ -13,9 +13,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-2x6j-v6mv-vf98/GHSA-2x6j-v6mv-vf98.json b/advisories/unreviewed/2024/09/GHSA-2x6j-v6mv-vf98/GHSA-2x6j-v6mv-vf98.json index c193e3fb763..cf6f92a14db 100644 --- a/advisories/unreviewed/2024/09/GHSA-2x6j-v6mv-vf98/GHSA-2x6j-v6mv-vf98.json +++ b/advisories/unreviewed/2024/09/GHSA-2x6j-v6mv-vf98/GHSA-2x6j-v6mv-vf98.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-36pg-hxf8-378v/GHSA-36pg-hxf8-378v.json b/advisories/unreviewed/2024/09/GHSA-36pg-hxf8-378v/GHSA-36pg-hxf8-378v.json index 9fc5877233d..2dc7c9c0354 100644 --- a/advisories/unreviewed/2024/09/GHSA-36pg-hxf8-378v/GHSA-36pg-hxf8-378v.json +++ b/advisories/unreviewed/2024/09/GHSA-36pg-hxf8-378v/GHSA-36pg-hxf8-378v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-3cmw-x7g9-558m/GHSA-3cmw-x7g9-558m.json b/advisories/unreviewed/2024/09/GHSA-3cmw-x7g9-558m/GHSA-3cmw-x7g9-558m.json index c2a41d5c128..898c9b99a2a 100644 --- a/advisories/unreviewed/2024/09/GHSA-3cmw-x7g9-558m/GHSA-3cmw-x7g9-558m.json +++ b/advisories/unreviewed/2024/09/GHSA-3cmw-x7g9-558m/GHSA-3cmw-x7g9-558m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-3ffp-ffxg-jv46/GHSA-3ffp-ffxg-jv46.json b/advisories/unreviewed/2024/09/GHSA-3ffp-ffxg-jv46/GHSA-3ffp-ffxg-jv46.json index 2c777390d1e..62f41bf300f 100644 --- a/advisories/unreviewed/2024/09/GHSA-3ffp-ffxg-jv46/GHSA-3ffp-ffxg-jv46.json +++ b/advisories/unreviewed/2024/09/GHSA-3ffp-ffxg-jv46/GHSA-3ffp-ffxg-jv46.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-3j8x-8x9q-3m4r/GHSA-3j8x-8x9q-3m4r.json b/advisories/unreviewed/2024/09/GHSA-3j8x-8x9q-3m4r/GHSA-3j8x-8x9q-3m4r.json index 699250f57e8..8f84b313f3e 100644 --- a/advisories/unreviewed/2024/09/GHSA-3j8x-8x9q-3m4r/GHSA-3j8x-8x9q-3m4r.json +++ b/advisories/unreviewed/2024/09/GHSA-3j8x-8x9q-3m4r/GHSA-3j8x-8x9q-3m4r.json @@ -13,9 +13,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-52r8-phxr-cfq6/GHSA-52r8-phxr-cfq6.json b/advisories/unreviewed/2024/09/GHSA-52r8-phxr-cfq6/GHSA-52r8-phxr-cfq6.json index c23ce95ee81..f590c2ae0d9 100644 --- a/advisories/unreviewed/2024/09/GHSA-52r8-phxr-cfq6/GHSA-52r8-phxr-cfq6.json +++ b/advisories/unreviewed/2024/09/GHSA-52r8-phxr-cfq6/GHSA-52r8-phxr-cfq6.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-55jp-9v82-mrww/GHSA-55jp-9v82-mrww.json b/advisories/unreviewed/2024/09/GHSA-55jp-9v82-mrww/GHSA-55jp-9v82-mrww.json index 57a56fb94a0..095edaf3491 100644 --- a/advisories/unreviewed/2024/09/GHSA-55jp-9v82-mrww/GHSA-55jp-9v82-mrww.json +++ b/advisories/unreviewed/2024/09/GHSA-55jp-9v82-mrww/GHSA-55jp-9v82-mrww.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-5rpv-45rh-6r87/GHSA-5rpv-45rh-6r87.json b/advisories/unreviewed/2024/09/GHSA-5rpv-45rh-6r87/GHSA-5rpv-45rh-6r87.json index 45c2a711ca0..b84b40a8212 100644 --- a/advisories/unreviewed/2024/09/GHSA-5rpv-45rh-6r87/GHSA-5rpv-45rh-6r87.json +++ b/advisories/unreviewed/2024/09/GHSA-5rpv-45rh-6r87/GHSA-5rpv-45rh-6r87.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-5wmr-r266-pc3m/GHSA-5wmr-r266-pc3m.json b/advisories/unreviewed/2024/09/GHSA-5wmr-r266-pc3m/GHSA-5wmr-r266-pc3m.json index dff43188028..f91f34793d7 100644 --- a/advisories/unreviewed/2024/09/GHSA-5wmr-r266-pc3m/GHSA-5wmr-r266-pc3m.json +++ b/advisories/unreviewed/2024/09/GHSA-5wmr-r266-pc3m/GHSA-5wmr-r266-pc3m.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-65wq-28c3-vwcw/GHSA-65wq-28c3-vwcw.json b/advisories/unreviewed/2024/09/GHSA-65wq-28c3-vwcw/GHSA-65wq-28c3-vwcw.json index c551aebd0ec..0b7bddbb347 100644 --- a/advisories/unreviewed/2024/09/GHSA-65wq-28c3-vwcw/GHSA-65wq-28c3-vwcw.json +++ b/advisories/unreviewed/2024/09/GHSA-65wq-28c3-vwcw/GHSA-65wq-28c3-vwcw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-6f83-4pfw-m3vj/GHSA-6f83-4pfw-m3vj.json b/advisories/unreviewed/2024/09/GHSA-6f83-4pfw-m3vj/GHSA-6f83-4pfw-m3vj.json index 3f823cbe29a..a294edddde7 100644 --- a/advisories/unreviewed/2024/09/GHSA-6f83-4pfw-m3vj/GHSA-6f83-4pfw-m3vj.json +++ b/advisories/unreviewed/2024/09/GHSA-6f83-4pfw-m3vj/GHSA-6f83-4pfw-m3vj.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-6m68-q6g7-pg37/GHSA-6m68-q6g7-pg37.json b/advisories/unreviewed/2024/09/GHSA-6m68-q6g7-pg37/GHSA-6m68-q6g7-pg37.json index b2c8ee45f16..39def7f431a 100644 --- a/advisories/unreviewed/2024/09/GHSA-6m68-q6g7-pg37/GHSA-6m68-q6g7-pg37.json +++ b/advisories/unreviewed/2024/09/GHSA-6m68-q6g7-pg37/GHSA-6m68-q6g7-pg37.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-6p4p-f7m9-43rh/GHSA-6p4p-f7m9-43rh.json b/advisories/unreviewed/2024/09/GHSA-6p4p-f7m9-43rh/GHSA-6p4p-f7m9-43rh.json index 3c12cbb308d..6bf374f2b91 100644 --- a/advisories/unreviewed/2024/09/GHSA-6p4p-f7m9-43rh/GHSA-6p4p-f7m9-43rh.json +++ b/advisories/unreviewed/2024/09/GHSA-6p4p-f7m9-43rh/GHSA-6p4p-f7m9-43rh.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-6pj4-296c-2375/GHSA-6pj4-296c-2375.json b/advisories/unreviewed/2024/09/GHSA-6pj4-296c-2375/GHSA-6pj4-296c-2375.json index 6d82d03fdfd..7081ea51c5c 100644 --- a/advisories/unreviewed/2024/09/GHSA-6pj4-296c-2375/GHSA-6pj4-296c-2375.json +++ b/advisories/unreviewed/2024/09/GHSA-6pj4-296c-2375/GHSA-6pj4-296c-2375.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-7q39-g4rg-578j/GHSA-7q39-g4rg-578j.json b/advisories/unreviewed/2024/09/GHSA-7q39-g4rg-578j/GHSA-7q39-g4rg-578j.json index 738ec4f6ea2..e8316caea76 100644 --- a/advisories/unreviewed/2024/09/GHSA-7q39-g4rg-578j/GHSA-7q39-g4rg-578j.json +++ b/advisories/unreviewed/2024/09/GHSA-7q39-g4rg-578j/GHSA-7q39-g4rg-578j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-7r6c-3p49-xqvv/GHSA-7r6c-3p49-xqvv.json b/advisories/unreviewed/2024/09/GHSA-7r6c-3p49-xqvv/GHSA-7r6c-3p49-xqvv.json index bb2b6b1e548..18b406874ea 100644 --- a/advisories/unreviewed/2024/09/GHSA-7r6c-3p49-xqvv/GHSA-7r6c-3p49-xqvv.json +++ b/advisories/unreviewed/2024/09/GHSA-7r6c-3p49-xqvv/GHSA-7r6c-3p49-xqvv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-88gp-qchm-x67w/GHSA-88gp-qchm-x67w.json b/advisories/unreviewed/2024/09/GHSA-88gp-qchm-x67w/GHSA-88gp-qchm-x67w.json index d0ef101fa10..4a8213ed2be 100644 --- a/advisories/unreviewed/2024/09/GHSA-88gp-qchm-x67w/GHSA-88gp-qchm-x67w.json +++ b/advisories/unreviewed/2024/09/GHSA-88gp-qchm-x67w/GHSA-88gp-qchm-x67w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-8vp8-g29r-fxpf/GHSA-8vp8-g29r-fxpf.json b/advisories/unreviewed/2024/09/GHSA-8vp8-g29r-fxpf/GHSA-8vp8-g29r-fxpf.json index 0bbee482107..c3fd08539e7 100644 --- a/advisories/unreviewed/2024/09/GHSA-8vp8-g29r-fxpf/GHSA-8vp8-g29r-fxpf.json +++ b/advisories/unreviewed/2024/09/GHSA-8vp8-g29r-fxpf/GHSA-8vp8-g29r-fxpf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-8x2h-c9mx-cx2j/GHSA-8x2h-c9mx-cx2j.json b/advisories/unreviewed/2024/09/GHSA-8x2h-c9mx-cx2j/GHSA-8x2h-c9mx-cx2j.json index dd66d6a303a..2c7a35d80f7 100644 --- a/advisories/unreviewed/2024/09/GHSA-8x2h-c9mx-cx2j/GHSA-8x2h-c9mx-cx2j.json +++ b/advisories/unreviewed/2024/09/GHSA-8x2h-c9mx-cx2j/GHSA-8x2h-c9mx-cx2j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-9362-9gf3-j66g/GHSA-9362-9gf3-j66g.json b/advisories/unreviewed/2024/09/GHSA-9362-9gf3-j66g/GHSA-9362-9gf3-j66g.json index 9ab2883ac4e..faca67149b0 100644 --- a/advisories/unreviewed/2024/09/GHSA-9362-9gf3-j66g/GHSA-9362-9gf3-j66g.json +++ b/advisories/unreviewed/2024/09/GHSA-9362-9gf3-j66g/GHSA-9362-9gf3-j66g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-94pj-f953-73h5/GHSA-94pj-f953-73h5.json b/advisories/unreviewed/2024/09/GHSA-94pj-f953-73h5/GHSA-94pj-f953-73h5.json index c04cd3ec847..0c658929d59 100644 --- a/advisories/unreviewed/2024/09/GHSA-94pj-f953-73h5/GHSA-94pj-f953-73h5.json +++ b/advisories/unreviewed/2024/09/GHSA-94pj-f953-73h5/GHSA-94pj-f953-73h5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-99qx-qpwq-jm99/GHSA-99qx-qpwq-jm99.json b/advisories/unreviewed/2024/09/GHSA-99qx-qpwq-jm99/GHSA-99qx-qpwq-jm99.json index 05b502848f3..7df9c4ea60f 100644 --- a/advisories/unreviewed/2024/09/GHSA-99qx-qpwq-jm99/GHSA-99qx-qpwq-jm99.json +++ b/advisories/unreviewed/2024/09/GHSA-99qx-qpwq-jm99/GHSA-99qx-qpwq-jm99.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-c2c6-68mw-462f/GHSA-c2c6-68mw-462f.json b/advisories/unreviewed/2024/09/GHSA-c2c6-68mw-462f/GHSA-c2c6-68mw-462f.json index d69c8b1f045..33af1885430 100644 --- a/advisories/unreviewed/2024/09/GHSA-c2c6-68mw-462f/GHSA-c2c6-68mw-462f.json +++ b/advisories/unreviewed/2024/09/GHSA-c2c6-68mw-462f/GHSA-c2c6-68mw-462f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-ch3p-mhx6-fjx9/GHSA-ch3p-mhx6-fjx9.json b/advisories/unreviewed/2024/09/GHSA-ch3p-mhx6-fjx9/GHSA-ch3p-mhx6-fjx9.json index 31efb625f64..a392c689ec0 100644 --- a/advisories/unreviewed/2024/09/GHSA-ch3p-mhx6-fjx9/GHSA-ch3p-mhx6-fjx9.json +++ b/advisories/unreviewed/2024/09/GHSA-ch3p-mhx6-fjx9/GHSA-ch3p-mhx6-fjx9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-cwjv-mxfr-rrv9/GHSA-cwjv-mxfr-rrv9.json b/advisories/unreviewed/2024/09/GHSA-cwjv-mxfr-rrv9/GHSA-cwjv-mxfr-rrv9.json index eeae39c5bcd..0e2aab12c38 100644 --- a/advisories/unreviewed/2024/09/GHSA-cwjv-mxfr-rrv9/GHSA-cwjv-mxfr-rrv9.json +++ b/advisories/unreviewed/2024/09/GHSA-cwjv-mxfr-rrv9/GHSA-cwjv-mxfr-rrv9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-cwqr-9j7q-r9xh/GHSA-cwqr-9j7q-r9xh.json b/advisories/unreviewed/2024/09/GHSA-cwqr-9j7q-r9xh/GHSA-cwqr-9j7q-r9xh.json index fceb9ea5a4a..308591b0569 100644 --- a/advisories/unreviewed/2024/09/GHSA-cwqr-9j7q-r9xh/GHSA-cwqr-9j7q-r9xh.json +++ b/advisories/unreviewed/2024/09/GHSA-cwqr-9j7q-r9xh/GHSA-cwqr-9j7q-r9xh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-f78v-vf29-36gj/GHSA-f78v-vf29-36gj.json b/advisories/unreviewed/2024/09/GHSA-f78v-vf29-36gj/GHSA-f78v-vf29-36gj.json index 02a9ad31e40..6689ec08884 100644 --- a/advisories/unreviewed/2024/09/GHSA-f78v-vf29-36gj/GHSA-f78v-vf29-36gj.json +++ b/advisories/unreviewed/2024/09/GHSA-f78v-vf29-36gj/GHSA-f78v-vf29-36gj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-f7q4-w36g-9gxm/GHSA-f7q4-w36g-9gxm.json b/advisories/unreviewed/2024/09/GHSA-f7q4-w36g-9gxm/GHSA-f7q4-w36g-9gxm.json index 202df3597e1..c3308ae43c2 100644 --- a/advisories/unreviewed/2024/09/GHSA-f7q4-w36g-9gxm/GHSA-f7q4-w36g-9gxm.json +++ b/advisories/unreviewed/2024/09/GHSA-f7q4-w36g-9gxm/GHSA-f7q4-w36g-9gxm.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-f95m-8pg6-37q7/GHSA-f95m-8pg6-37q7.json b/advisories/unreviewed/2024/09/GHSA-f95m-8pg6-37q7/GHSA-f95m-8pg6-37q7.json index 0b768e936f4..8c7732daada 100644 --- a/advisories/unreviewed/2024/09/GHSA-f95m-8pg6-37q7/GHSA-f95m-8pg6-37q7.json +++ b/advisories/unreviewed/2024/09/GHSA-f95m-8pg6-37q7/GHSA-f95m-8pg6-37q7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-f9m9-68wf-ppcf/GHSA-f9m9-68wf-ppcf.json b/advisories/unreviewed/2024/09/GHSA-f9m9-68wf-ppcf/GHSA-f9m9-68wf-ppcf.json index a9c8609970c..07181cbe948 100644 --- a/advisories/unreviewed/2024/09/GHSA-f9m9-68wf-ppcf/GHSA-f9m9-68wf-ppcf.json +++ b/advisories/unreviewed/2024/09/GHSA-f9m9-68wf-ppcf/GHSA-f9m9-68wf-ppcf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-fvcf-hj7v-3mj6/GHSA-fvcf-hj7v-3mj6.json b/advisories/unreviewed/2024/09/GHSA-fvcf-hj7v-3mj6/GHSA-fvcf-hj7v-3mj6.json index 0a30ceed7eb..189305a288c 100644 --- a/advisories/unreviewed/2024/09/GHSA-fvcf-hj7v-3mj6/GHSA-fvcf-hj7v-3mj6.json +++ b/advisories/unreviewed/2024/09/GHSA-fvcf-hj7v-3mj6/GHSA-fvcf-hj7v-3mj6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-fxq3-rjrf-gqq3/GHSA-fxq3-rjrf-gqq3.json b/advisories/unreviewed/2024/09/GHSA-fxq3-rjrf-gqq3/GHSA-fxq3-rjrf-gqq3.json index 65ac2950222..9c0ccf49f2d 100644 --- a/advisories/unreviewed/2024/09/GHSA-fxq3-rjrf-gqq3/GHSA-fxq3-rjrf-gqq3.json +++ b/advisories/unreviewed/2024/09/GHSA-fxq3-rjrf-gqq3/GHSA-fxq3-rjrf-gqq3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-g922-hx36-gr43/GHSA-g922-hx36-gr43.json b/advisories/unreviewed/2024/09/GHSA-g922-hx36-gr43/GHSA-g922-hx36-gr43.json index 682e62fbdc8..a14657a0b90 100644 --- a/advisories/unreviewed/2024/09/GHSA-g922-hx36-gr43/GHSA-g922-hx36-gr43.json +++ b/advisories/unreviewed/2024/09/GHSA-g922-hx36-gr43/GHSA-g922-hx36-gr43.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-gjx4-p4f2-33wq/GHSA-gjx4-p4f2-33wq.json b/advisories/unreviewed/2024/09/GHSA-gjx4-p4f2-33wq/GHSA-gjx4-p4f2-33wq.json index c7d681f76ea..9ff9d50a2b3 100644 --- a/advisories/unreviewed/2024/09/GHSA-gjx4-p4f2-33wq/GHSA-gjx4-p4f2-33wq.json +++ b/advisories/unreviewed/2024/09/GHSA-gjx4-p4f2-33wq/GHSA-gjx4-p4f2-33wq.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-gq6r-xfpw-cg3w/GHSA-gq6r-xfpw-cg3w.json b/advisories/unreviewed/2024/09/GHSA-gq6r-xfpw-cg3w/GHSA-gq6r-xfpw-cg3w.json index ce1f52a4acc..07f1b025b0c 100644 --- a/advisories/unreviewed/2024/09/GHSA-gq6r-xfpw-cg3w/GHSA-gq6r-xfpw-cg3w.json +++ b/advisories/unreviewed/2024/09/GHSA-gq6r-xfpw-cg3w/GHSA-gq6r-xfpw-cg3w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-gwp5-2fcr-m24v/GHSA-gwp5-2fcr-m24v.json b/advisories/unreviewed/2024/09/GHSA-gwp5-2fcr-m24v/GHSA-gwp5-2fcr-m24v.json index 5f30d1c9904..5c96278b9d4 100644 --- a/advisories/unreviewed/2024/09/GHSA-gwp5-2fcr-m24v/GHSA-gwp5-2fcr-m24v.json +++ b/advisories/unreviewed/2024/09/GHSA-gwp5-2fcr-m24v/GHSA-gwp5-2fcr-m24v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-h287-xx77-94v5/GHSA-h287-xx77-94v5.json b/advisories/unreviewed/2024/09/GHSA-h287-xx77-94v5/GHSA-h287-xx77-94v5.json index 73b23ff0ca5..51c6b864116 100644 --- a/advisories/unreviewed/2024/09/GHSA-h287-xx77-94v5/GHSA-h287-xx77-94v5.json +++ b/advisories/unreviewed/2024/09/GHSA-h287-xx77-94v5/GHSA-h287-xx77-94v5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-h66g-2x3f-vgpp/GHSA-h66g-2x3f-vgpp.json b/advisories/unreviewed/2024/09/GHSA-h66g-2x3f-vgpp/GHSA-h66g-2x3f-vgpp.json index 0089096450e..3af2144bf17 100644 --- a/advisories/unreviewed/2024/09/GHSA-h66g-2x3f-vgpp/GHSA-h66g-2x3f-vgpp.json +++ b/advisories/unreviewed/2024/09/GHSA-h66g-2x3f-vgpp/GHSA-h66g-2x3f-vgpp.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-hr8m-c45c-9928/GHSA-hr8m-c45c-9928.json b/advisories/unreviewed/2024/09/GHSA-hr8m-c45c-9928/GHSA-hr8m-c45c-9928.json index 809694d8877..7b14126bb2c 100644 --- a/advisories/unreviewed/2024/09/GHSA-hr8m-c45c-9928/GHSA-hr8m-c45c-9928.json +++ b/advisories/unreviewed/2024/09/GHSA-hr8m-c45c-9928/GHSA-hr8m-c45c-9928.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-j4g8-8jw2-7ww9/GHSA-j4g8-8jw2-7ww9.json b/advisories/unreviewed/2024/09/GHSA-j4g8-8jw2-7ww9/GHSA-j4g8-8jw2-7ww9.json index b9e60c1684e..e6071f5c33a 100644 --- a/advisories/unreviewed/2024/09/GHSA-j4g8-8jw2-7ww9/GHSA-j4g8-8jw2-7ww9.json +++ b/advisories/unreviewed/2024/09/GHSA-j4g8-8jw2-7ww9/GHSA-j4g8-8jw2-7ww9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-j6pg-h597-gcx9/GHSA-j6pg-h597-gcx9.json b/advisories/unreviewed/2024/09/GHSA-j6pg-h597-gcx9/GHSA-j6pg-h597-gcx9.json index 6c43afb4c1b..64403336e0d 100644 --- a/advisories/unreviewed/2024/09/GHSA-j6pg-h597-gcx9/GHSA-j6pg-h597-gcx9.json +++ b/advisories/unreviewed/2024/09/GHSA-j6pg-h597-gcx9/GHSA-j6pg-h597-gcx9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-m5wh-wcvg-3f5f/GHSA-m5wh-wcvg-3f5f.json b/advisories/unreviewed/2024/09/GHSA-m5wh-wcvg-3f5f/GHSA-m5wh-wcvg-3f5f.json index fe77f87bbf8..81825233170 100644 --- a/advisories/unreviewed/2024/09/GHSA-m5wh-wcvg-3f5f/GHSA-m5wh-wcvg-3f5f.json +++ b/advisories/unreviewed/2024/09/GHSA-m5wh-wcvg-3f5f/GHSA-m5wh-wcvg-3f5f.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-m6pw-mqxx-frjv/GHSA-m6pw-mqxx-frjv.json b/advisories/unreviewed/2024/09/GHSA-m6pw-mqxx-frjv/GHSA-m6pw-mqxx-frjv.json index 229012f50a3..077ad6f9097 100644 --- a/advisories/unreviewed/2024/09/GHSA-m6pw-mqxx-frjv/GHSA-m6pw-mqxx-frjv.json +++ b/advisories/unreviewed/2024/09/GHSA-m6pw-mqxx-frjv/GHSA-m6pw-mqxx-frjv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-m74p-p5fp-95cw/GHSA-m74p-p5fp-95cw.json b/advisories/unreviewed/2024/09/GHSA-m74p-p5fp-95cw/GHSA-m74p-p5fp-95cw.json index a0741cc0c98..4cd57d195cd 100644 --- a/advisories/unreviewed/2024/09/GHSA-m74p-p5fp-95cw/GHSA-m74p-p5fp-95cw.json +++ b/advisories/unreviewed/2024/09/GHSA-m74p-p5fp-95cw/GHSA-m74p-p5fp-95cw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-mgc5-p43f-72pc/GHSA-mgc5-p43f-72pc.json b/advisories/unreviewed/2024/09/GHSA-mgc5-p43f-72pc/GHSA-mgc5-p43f-72pc.json index a37f46fcf8f..fcfad3bd187 100644 --- a/advisories/unreviewed/2024/09/GHSA-mgc5-p43f-72pc/GHSA-mgc5-p43f-72pc.json +++ b/advisories/unreviewed/2024/09/GHSA-mgc5-p43f-72pc/GHSA-mgc5-p43f-72pc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-mxf3-c3v5-9jpv/GHSA-mxf3-c3v5-9jpv.json b/advisories/unreviewed/2024/09/GHSA-mxf3-c3v5-9jpv/GHSA-mxf3-c3v5-9jpv.json index d6619cd1937..9edc0c91cf3 100644 --- a/advisories/unreviewed/2024/09/GHSA-mxf3-c3v5-9jpv/GHSA-mxf3-c3v5-9jpv.json +++ b/advisories/unreviewed/2024/09/GHSA-mxf3-c3v5-9jpv/GHSA-mxf3-c3v5-9jpv.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-p64c-2wr6-h7wf/GHSA-p64c-2wr6-h7wf.json b/advisories/unreviewed/2024/09/GHSA-p64c-2wr6-h7wf/GHSA-p64c-2wr6-h7wf.json index d0085acd9ec..72257cdabfc 100644 --- a/advisories/unreviewed/2024/09/GHSA-p64c-2wr6-h7wf/GHSA-p64c-2wr6-h7wf.json +++ b/advisories/unreviewed/2024/09/GHSA-p64c-2wr6-h7wf/GHSA-p64c-2wr6-h7wf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-pcx7-83rx-78c2/GHSA-pcx7-83rx-78c2.json b/advisories/unreviewed/2024/09/GHSA-pcx7-83rx-78c2/GHSA-pcx7-83rx-78c2.json index bb3943f2a02..33ccd88235f 100644 --- a/advisories/unreviewed/2024/09/GHSA-pcx7-83rx-78c2/GHSA-pcx7-83rx-78c2.json +++ b/advisories/unreviewed/2024/09/GHSA-pcx7-83rx-78c2/GHSA-pcx7-83rx-78c2.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-pr27-f9rc-q4vm/GHSA-pr27-f9rc-q4vm.json b/advisories/unreviewed/2024/09/GHSA-pr27-f9rc-q4vm/GHSA-pr27-f9rc-q4vm.json index 05bed8407d1..947a3d8a2b5 100644 --- a/advisories/unreviewed/2024/09/GHSA-pr27-f9rc-q4vm/GHSA-pr27-f9rc-q4vm.json +++ b/advisories/unreviewed/2024/09/GHSA-pr27-f9rc-q4vm/GHSA-pr27-f9rc-q4vm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-qmm9-m4wr-gv24/GHSA-qmm9-m4wr-gv24.json b/advisories/unreviewed/2024/09/GHSA-qmm9-m4wr-gv24/GHSA-qmm9-m4wr-gv24.json index 18012673c2e..cc8ddb51ed8 100644 --- a/advisories/unreviewed/2024/09/GHSA-qmm9-m4wr-gv24/GHSA-qmm9-m4wr-gv24.json +++ b/advisories/unreviewed/2024/09/GHSA-qmm9-m4wr-gv24/GHSA-qmm9-m4wr-gv24.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-qmr2-j5m9-cq3m/GHSA-qmr2-j5m9-cq3m.json b/advisories/unreviewed/2024/09/GHSA-qmr2-j5m9-cq3m/GHSA-qmr2-j5m9-cq3m.json index 92227eced63..2183a838af2 100644 --- a/advisories/unreviewed/2024/09/GHSA-qmr2-j5m9-cq3m/GHSA-qmr2-j5m9-cq3m.json +++ b/advisories/unreviewed/2024/09/GHSA-qmr2-j5m9-cq3m/GHSA-qmr2-j5m9-cq3m.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-r3xc-mh5x-gjfq/GHSA-r3xc-mh5x-gjfq.json b/advisories/unreviewed/2024/09/GHSA-r3xc-mh5x-gjfq/GHSA-r3xc-mh5x-gjfq.json index 759cb953bfd..9ea17ef0e7e 100644 --- a/advisories/unreviewed/2024/09/GHSA-r3xc-mh5x-gjfq/GHSA-r3xc-mh5x-gjfq.json +++ b/advisories/unreviewed/2024/09/GHSA-r3xc-mh5x-gjfq/GHSA-r3xc-mh5x-gjfq.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-r7mf-5w8w-4x2h/GHSA-r7mf-5w8w-4x2h.json b/advisories/unreviewed/2024/09/GHSA-r7mf-5w8w-4x2h/GHSA-r7mf-5w8w-4x2h.json index f4c15b79c4e..c5a118def35 100644 --- a/advisories/unreviewed/2024/09/GHSA-r7mf-5w8w-4x2h/GHSA-r7mf-5w8w-4x2h.json +++ b/advisories/unreviewed/2024/09/GHSA-r7mf-5w8w-4x2h/GHSA-r7mf-5w8w-4x2h.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-rccv-3qjv-c8h5/GHSA-rccv-3qjv-c8h5.json b/advisories/unreviewed/2024/09/GHSA-rccv-3qjv-c8h5/GHSA-rccv-3qjv-c8h5.json index fe1d41a1aee..7633c099e79 100644 --- a/advisories/unreviewed/2024/09/GHSA-rccv-3qjv-c8h5/GHSA-rccv-3qjv-c8h5.json +++ b/advisories/unreviewed/2024/09/GHSA-rccv-3qjv-c8h5/GHSA-rccv-3qjv-c8h5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-rmrm-52j9-f57q/GHSA-rmrm-52j9-f57q.json b/advisories/unreviewed/2024/09/GHSA-rmrm-52j9-f57q/GHSA-rmrm-52j9-f57q.json index 70bdf742bed..e671252c5fc 100644 --- a/advisories/unreviewed/2024/09/GHSA-rmrm-52j9-f57q/GHSA-rmrm-52j9-f57q.json +++ b/advisories/unreviewed/2024/09/GHSA-rmrm-52j9-f57q/GHSA-rmrm-52j9-f57q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-v596-cf8q-xgjv/GHSA-v596-cf8q-xgjv.json b/advisories/unreviewed/2024/09/GHSA-v596-cf8q-xgjv/GHSA-v596-cf8q-xgjv.json index 2a6e4340c09..88a7dec2fa0 100644 --- a/advisories/unreviewed/2024/09/GHSA-v596-cf8q-xgjv/GHSA-v596-cf8q-xgjv.json +++ b/advisories/unreviewed/2024/09/GHSA-v596-cf8q-xgjv/GHSA-v596-cf8q-xgjv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-v63p-x2p8-f754/GHSA-v63p-x2p8-f754.json b/advisories/unreviewed/2024/09/GHSA-v63p-x2p8-f754/GHSA-v63p-x2p8-f754.json index 2f90d994218..3c9251cec2a 100644 --- a/advisories/unreviewed/2024/09/GHSA-v63p-x2p8-f754/GHSA-v63p-x2p8-f754.json +++ b/advisories/unreviewed/2024/09/GHSA-v63p-x2p8-f754/GHSA-v63p-x2p8-f754.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-vhfh-pcg2-m599/GHSA-vhfh-pcg2-m599.json b/advisories/unreviewed/2024/09/GHSA-vhfh-pcg2-m599/GHSA-vhfh-pcg2-m599.json index 1536692a8a3..2d231b38eea 100644 --- a/advisories/unreviewed/2024/09/GHSA-vhfh-pcg2-m599/GHSA-vhfh-pcg2-m599.json +++ b/advisories/unreviewed/2024/09/GHSA-vhfh-pcg2-m599/GHSA-vhfh-pcg2-m599.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-vpc7-hmh5-3wx6/GHSA-vpc7-hmh5-3wx6.json b/advisories/unreviewed/2024/09/GHSA-vpc7-hmh5-3wx6/GHSA-vpc7-hmh5-3wx6.json index 2ce9ab40245..7bb3ef10c2e 100644 --- a/advisories/unreviewed/2024/09/GHSA-vpc7-hmh5-3wx6/GHSA-vpc7-hmh5-3wx6.json +++ b/advisories/unreviewed/2024/09/GHSA-vpc7-hmh5-3wx6/GHSA-vpc7-hmh5-3wx6.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-vrm8-8c2f-82r7/GHSA-vrm8-8c2f-82r7.json b/advisories/unreviewed/2024/09/GHSA-vrm8-8c2f-82r7/GHSA-vrm8-8c2f-82r7.json index 45ba9a89292..c8849196d50 100644 --- a/advisories/unreviewed/2024/09/GHSA-vrm8-8c2f-82r7/GHSA-vrm8-8c2f-82r7.json +++ b/advisories/unreviewed/2024/09/GHSA-vrm8-8c2f-82r7/GHSA-vrm8-8c2f-82r7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-w37h-c34c-gwjm/GHSA-w37h-c34c-gwjm.json b/advisories/unreviewed/2024/09/GHSA-w37h-c34c-gwjm/GHSA-w37h-c34c-gwjm.json index 50f2ab3d76d..51681208958 100644 --- a/advisories/unreviewed/2024/09/GHSA-w37h-c34c-gwjm/GHSA-w37h-c34c-gwjm.json +++ b/advisories/unreviewed/2024/09/GHSA-w37h-c34c-gwjm/GHSA-w37h-c34c-gwjm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-w3mf-5j8r-pqhw/GHSA-w3mf-5j8r-pqhw.json b/advisories/unreviewed/2024/09/GHSA-w3mf-5j8r-pqhw/GHSA-w3mf-5j8r-pqhw.json index d5e510eea54..7aeb6905e84 100644 --- a/advisories/unreviewed/2024/09/GHSA-w3mf-5j8r-pqhw/GHSA-w3mf-5j8r-pqhw.json +++ b/advisories/unreviewed/2024/09/GHSA-w3mf-5j8r-pqhw/GHSA-w3mf-5j8r-pqhw.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-wx49-gvfc-fhrp/GHSA-wx49-gvfc-fhrp.json b/advisories/unreviewed/2024/09/GHSA-wx49-gvfc-fhrp/GHSA-wx49-gvfc-fhrp.json index 81ae40b72b0..2238204a5e9 100644 --- a/advisories/unreviewed/2024/09/GHSA-wx49-gvfc-fhrp/GHSA-wx49-gvfc-fhrp.json +++ b/advisories/unreviewed/2024/09/GHSA-wx49-gvfc-fhrp/GHSA-wx49-gvfc-fhrp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-x2m7-9j9x-5v33/GHSA-x2m7-9j9x-5v33.json b/advisories/unreviewed/2024/09/GHSA-x2m7-9j9x-5v33/GHSA-x2m7-9j9x-5v33.json index c52a243a2c4..b0d4313fb1e 100644 --- a/advisories/unreviewed/2024/09/GHSA-x2m7-9j9x-5v33/GHSA-x2m7-9j9x-5v33.json +++ b/advisories/unreviewed/2024/09/GHSA-x2m7-9j9x-5v33/GHSA-x2m7-9j9x-5v33.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-x85h-x3fh-9fpv/GHSA-x85h-x3fh-9fpv.json b/advisories/unreviewed/2024/09/GHSA-x85h-x3fh-9fpv/GHSA-x85h-x3fh-9fpv.json index 69edd4ace70..bfb9deac434 100644 --- a/advisories/unreviewed/2024/09/GHSA-x85h-x3fh-9fpv/GHSA-x85h-x3fh-9fpv.json +++ b/advisories/unreviewed/2024/09/GHSA-x85h-x3fh-9fpv/GHSA-x85h-x3fh-9fpv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-xp7v-r3c8-pp3w/GHSA-xp7v-r3c8-pp3w.json b/advisories/unreviewed/2024/09/GHSA-xp7v-r3c8-pp3w/GHSA-xp7v-r3c8-pp3w.json index c4b3fda8378..5622d25460a 100644 --- a/advisories/unreviewed/2024/09/GHSA-xp7v-r3c8-pp3w/GHSA-xp7v-r3c8-pp3w.json +++ b/advisories/unreviewed/2024/09/GHSA-xp7v-r3c8-pp3w/GHSA-xp7v-r3c8-pp3w.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-xrp2-m33g-q2cv/GHSA-xrp2-m33g-q2cv.json b/advisories/unreviewed/2024/09/GHSA-xrp2-m33g-q2cv/GHSA-xrp2-m33g-q2cv.json index 2bf506af2a8..865c7866a0f 100644 --- a/advisories/unreviewed/2024/09/GHSA-xrp2-m33g-q2cv/GHSA-xrp2-m33g-q2cv.json +++ b/advisories/unreviewed/2024/09/GHSA-xrp2-m33g-q2cv/GHSA-xrp2-m33g-q2cv.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",