diff --git a/advisories/github-reviewed/2023/11/GHSA-54xq-cgqr-rpm3/GHSA-54xq-cgqr-rpm3.json b/advisories/github-reviewed/2023/11/GHSA-54xq-cgqr-rpm3/GHSA-54xq-cgqr-rpm3.json index 4b584953d73..b37f75db38d 100644 --- a/advisories/github-reviewed/2023/11/GHSA-54xq-cgqr-rpm3/GHSA-54xq-cgqr-rpm3.json +++ b/advisories/github-reviewed/2023/11/GHSA-54xq-cgqr-rpm3/GHSA-54xq-cgqr-rpm3.json @@ -3,9 +3,7 @@ "id": "GHSA-54xq-cgqr-rpm3", "modified": "2023-11-16T17:14:15Z", "published": "2023-11-16T17:14:15Z", - "aliases": [ - - ], + "aliases": [], "summary": "sharp vulnerability in libwebp dependency CVE-2023-4863", "details": "## Overview\n\nsharp uses libwebp to decode WebP images and versions prior to the latest 0.32.6 are vulnerable to the high severity https://github.com/advisories/GHSA-j7hp-h8jx-5ppr.\n\n## Who does this affect?\n\nAlmost anyone processing untrusted input with versions of sharp prior to 0.32.6.\n\n## How to resolve this?\n\n### Using prebuilt binaries provided by sharp?\n\nMost people rely on the prebuilt binaries provided by sharp.\n\nPlease upgrade sharp to the latest 0.32.6, which provides libwebp 1.3.2.\n\n### Using a globally-installed libvips?\n\nPlease ensure you are using the latest libwebp 1.3.2.\n\n## Possible workaround\n\nAdd the following to your code to prevent sharp from decoding WebP images.\n```js\nsharp.block({ operation: [\"VipsForeignLoadWebp\"] });\n```", "severity": [ @@ -50,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-11-16T17:14:15Z", diff --git a/advisories/github-reviewed/2024/03/GHSA-73v2-rxqp-7q4f/GHSA-73v2-rxqp-7q4f.json b/advisories/github-reviewed/2024/03/GHSA-73v2-rxqp-7q4f/GHSA-73v2-rxqp-7q4f.json index b898b447e71..4b7ff06e7b5 100644 --- a/advisories/github-reviewed/2024/03/GHSA-73v2-rxqp-7q4f/GHSA-73v2-rxqp-7q4f.json +++ b/advisories/github-reviewed/2024/03/GHSA-73v2-rxqp-7q4f/GHSA-73v2-rxqp-7q4f.json @@ -8,9 +8,7 @@ ], "summary": "aliyundrive-webdav vulnerable to Command Injection", "details": "An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the `action_query_qrcode` component.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/unreviewed/2022/04/GHSA-23f6-33xg-96c7/GHSA-23f6-33xg-96c7.json b/advisories/unreviewed/2022/04/GHSA-23f6-33xg-96c7/GHSA-23f6-33xg-96c7.json index c4f5b1355af..153c917375b 100644 --- a/advisories/unreviewed/2022/04/GHSA-23f6-33xg-96c7/GHSA-23f6-33xg-96c7.json +++ b/advisories/unreviewed/2022/04/GHSA-23f6-33xg-96c7/GHSA-23f6-33xg-96c7.json @@ -7,12 +7,8 @@ "CVE-2004-1845" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-25wj-f645-7mjg/GHSA-25wj-f645-7mjg.json b/advisories/unreviewed/2022/04/GHSA-25wj-f645-7mjg/GHSA-25wj-f645-7mjg.json index 83717565d8c..3e81498101a 100644 --- a/advisories/unreviewed/2022/04/GHSA-25wj-f645-7mjg/GHSA-25wj-f645-7mjg.json +++ b/advisories/unreviewed/2022/04/GHSA-25wj-f645-7mjg/GHSA-25wj-f645-7mjg.json @@ -7,12 +7,8 @@ "CVE-2004-1920" ], "details": "X-Micro WLAN 11b Broadband Router 1.2.2, 1.2.2.3, 1.2.2.4, and 1.6.0.0 has a hardcoded \"super\" username and password, which could allow remote attackers to gain access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-28vf-6j43-vqq5/GHSA-28vf-6j43-vqq5.json b/advisories/unreviewed/2022/04/GHSA-28vf-6j43-vqq5/GHSA-28vf-6j43-vqq5.json index 1e967f74715..132401c5919 100644 --- a/advisories/unreviewed/2022/04/GHSA-28vf-6j43-vqq5/GHSA-28vf-6j43-vqq5.json +++ b/advisories/unreviewed/2022/04/GHSA-28vf-6j43-vqq5/GHSA-28vf-6j43-vqq5.json @@ -7,12 +7,8 @@ "CVE-2004-1910" ], "details": "rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to the GetPrivateProfileString function. NOTE: this issue was originally reported as a buffer overflow, but that specific claim is disputed by the vendor, although a crash is acknowledged.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-29fv-34jg-3cfg/GHSA-29fv-34jg-3cfg.json b/advisories/unreviewed/2022/04/GHSA-29fv-34jg-3cfg/GHSA-29fv-34jg-3cfg.json index af713d98af7..68024cedd6d 100644 --- a/advisories/unreviewed/2022/04/GHSA-29fv-34jg-3cfg/GHSA-29fv-34jg-3cfg.json +++ b/advisories/unreviewed/2022/04/GHSA-29fv-34jg-3cfg/GHSA-29fv-34jg-3cfg.json @@ -7,12 +7,8 @@ "CVE-2004-2027" ], "details": "Buffer overflow in Icecast 2.0.0 and earlier allows remote attackers to cause a denial of service (crash) via a long Basic Authorization header that triggers an out-of-bounds read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2c5m-jj29-px47/GHSA-2c5m-jj29-px47.json b/advisories/unreviewed/2022/04/GHSA-2c5m-jj29-px47/GHSA-2c5m-jj29-px47.json index 488e5901f92..08cb5317117 100644 --- a/advisories/unreviewed/2022/04/GHSA-2c5m-jj29-px47/GHSA-2c5m-jj29-px47.json +++ b/advisories/unreviewed/2022/04/GHSA-2c5m-jj29-px47/GHSA-2c5m-jj29-px47.json @@ -7,12 +7,8 @@ "CVE-2004-1978" ], "details": "Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script via the text parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2cf2-pcwf-57xx/GHSA-2cf2-pcwf-57xx.json b/advisories/unreviewed/2022/04/GHSA-2cf2-pcwf-57xx/GHSA-2cf2-pcwf-57xx.json index d5edfcb6c4c..d3c4462256c 100644 --- a/advisories/unreviewed/2022/04/GHSA-2cf2-pcwf-57xx/GHSA-2cf2-pcwf-57xx.json +++ b/advisories/unreviewed/2022/04/GHSA-2cf2-pcwf-57xx/GHSA-2cf2-pcwf-57xx.json @@ -7,12 +7,8 @@ "CVE-2004-1795" ], "details": "Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2cx4-vf7f-fxv5/GHSA-2cx4-vf7f-fxv5.json b/advisories/unreviewed/2022/04/GHSA-2cx4-vf7f-fxv5/GHSA-2cx4-vf7f-fxv5.json index 1143dab684d..05f55be0a69 100644 --- a/advisories/unreviewed/2022/04/GHSA-2cx4-vf7f-fxv5/GHSA-2cx4-vf7f-fxv5.json +++ b/advisories/unreviewed/2022/04/GHSA-2cx4-vf7f-fxv5/GHSA-2cx4-vf7f-fxv5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-2v65-47pp-8xcp/GHSA-2v65-47pp-8xcp.json b/advisories/unreviewed/2022/04/GHSA-2v65-47pp-8xcp/GHSA-2v65-47pp-8xcp.json index 59b0db83454..669241e6bb6 100644 --- a/advisories/unreviewed/2022/04/GHSA-2v65-47pp-8xcp/GHSA-2v65-47pp-8xcp.json +++ b/advisories/unreviewed/2022/04/GHSA-2v65-47pp-8xcp/GHSA-2v65-47pp-8xcp.json @@ -7,12 +7,8 @@ "CVE-2004-1962" ], "details": "SQL injection vulnerability in index.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection filters by using \"/**/\" sequences in the targeted fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2w54-gxr7-rr24/GHSA-2w54-gxr7-rr24.json b/advisories/unreviewed/2022/04/GHSA-2w54-gxr7-rr24/GHSA-2w54-gxr7-rr24.json index 2e1c5c68f5c..90a563379ab 100644 --- a/advisories/unreviewed/2022/04/GHSA-2w54-gxr7-rr24/GHSA-2w54-gxr7-rr24.json +++ b/advisories/unreviewed/2022/04/GHSA-2w54-gxr7-rr24/GHSA-2w54-gxr7-rr24.json @@ -7,12 +7,8 @@ "CVE-2004-1872" ], "details": "Cross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote attackers to inject arbitrary web script or HTML via the @import URL function in a CSS style tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2xq3-93rc-7m59/GHSA-2xq3-93rc-7m59.json b/advisories/unreviewed/2022/04/GHSA-2xq3-93rc-7m59/GHSA-2xq3-93rc-7m59.json index 6ef6526632d..82707d2b995 100644 --- a/advisories/unreviewed/2022/04/GHSA-2xq3-93rc-7m59/GHSA-2xq3-93rc-7m59.json +++ b/advisories/unreviewed/2022/04/GHSA-2xq3-93rc-7m59/GHSA-2xq3-93rc-7m59.json @@ -7,12 +7,8 @@ "CVE-2004-1858" ], "details": "HP Web Jetadmin 7.5.2546 allows remote attackers to cause a denial of service (crash) via a malformed request, possibly due to a stricmp() error from an invalid use of the \"$\" character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-33j3-f98h-3v38/GHSA-33j3-f98h-3v38.json b/advisories/unreviewed/2022/04/GHSA-33j3-f98h-3v38/GHSA-33j3-f98h-3v38.json index 5a366d75c63..4b558195a79 100644 --- a/advisories/unreviewed/2022/04/GHSA-33j3-f98h-3v38/GHSA-33j3-f98h-3v38.json +++ b/advisories/unreviewed/2022/04/GHSA-33j3-f98h-3v38/GHSA-33j3-f98h-3v38.json @@ -7,12 +7,8 @@ "CVE-2004-1781" ], "details": "Info Touch Surfnet kiosk allows local users to crash Surfnet and access the underlying operating system via the CMD_CREDITCARD_CHARGE command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-33qq-qr49-7phx/GHSA-33qq-qr49-7phx.json b/advisories/unreviewed/2022/04/GHSA-33qq-qr49-7phx/GHSA-33qq-qr49-7phx.json index add63933b98..fe2e736abd8 100644 --- a/advisories/unreviewed/2022/04/GHSA-33qq-qr49-7phx/GHSA-33qq-qr49-7phx.json +++ b/advisories/unreviewed/2022/04/GHSA-33qq-qr49-7phx/GHSA-33qq-qr49-7phx.json @@ -7,12 +7,8 @@ "CVE-2004-1762" ], "details": "Unknown vulnerability in F-Secure Anti-Virus (FSAV) 4.52 for Linux before Hotfix 3 allows the Sober.D worm to bypass FASV.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-33v4-3wc6-5p2f/GHSA-33v4-3wc6-5p2f.json b/advisories/unreviewed/2022/04/GHSA-33v4-3wc6-5p2f/GHSA-33v4-3wc6-5p2f.json index 0c47958c756..bc0d45189ee 100644 --- a/advisories/unreviewed/2022/04/GHSA-33v4-3wc6-5p2f/GHSA-33v4-3wc6-5p2f.json +++ b/advisories/unreviewed/2022/04/GHSA-33v4-3wc6-5p2f/GHSA-33v4-3wc6-5p2f.json @@ -7,12 +7,8 @@ "CVE-2004-1824" ], "details": "Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.0 allows remote attackers to inject arbitrary web script or HTML via the what parameter to memberlist.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-345f-m523-wxr6/GHSA-345f-m523-wxr6.json b/advisories/unreviewed/2022/04/GHSA-345f-m523-wxr6/GHSA-345f-m523-wxr6.json index bbc434d29d4..9e836200383 100644 --- a/advisories/unreviewed/2022/04/GHSA-345f-m523-wxr6/GHSA-345f-m523-wxr6.json +++ b/advisories/unreviewed/2022/04/GHSA-345f-m523-wxr6/GHSA-345f-m523-wxr6.json @@ -7,12 +7,8 @@ "CVE-2004-1977" ], "details": "3com NBX IP VOIP NetSet Configuration Manager allows remote attackers to cause a denial of service (crash) via a Nessus scan in safeChecks mode.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-34f4-6qv2-6hcc/GHSA-34f4-6qv2-6hcc.json b/advisories/unreviewed/2022/04/GHSA-34f4-6qv2-6hcc/GHSA-34f4-6qv2-6hcc.json index e1e8a943f28..edecbf7b89a 100644 --- a/advisories/unreviewed/2022/04/GHSA-34f4-6qv2-6hcc/GHSA-34f4-6qv2-6hcc.json +++ b/advisories/unreviewed/2022/04/GHSA-34f4-6qv2-6hcc/GHSA-34f4-6qv2-6hcc.json @@ -7,12 +7,8 @@ "CVE-2004-1919" ], "details": "The hash_strcmp function in hasch.c in Crackalaka 1.0.8 allows remote attackers to cause a denial of service (crash) via large malformed strings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-36x5-rg8m-ph58/GHSA-36x5-rg8m-ph58.json b/advisories/unreviewed/2022/04/GHSA-36x5-rg8m-ph58/GHSA-36x5-rg8m-ph58.json index 68c74fda6c9..228f8d27a9c 100644 --- a/advisories/unreviewed/2022/04/GHSA-36x5-rg8m-ph58/GHSA-36x5-rg8m-ph58.json +++ b/advisories/unreviewed/2022/04/GHSA-36x5-rg8m-ph58/GHSA-36x5-rg8m-ph58.json @@ -7,12 +7,8 @@ "CVE-2004-1907" ], "details": "The Web Filtering functionality in Kerio Personal Firewall (KPF) 4.0.13 allows remote attackers to cause a denial of service (crash) by sending hex-encoded URLs containing \"%13%12%13\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3785-7xjj-4m88/GHSA-3785-7xjj-4m88.json b/advisories/unreviewed/2022/04/GHSA-3785-7xjj-4m88/GHSA-3785-7xjj-4m88.json index 906360ae040..2450a0cc128 100644 --- a/advisories/unreviewed/2022/04/GHSA-3785-7xjj-4m88/GHSA-3785-7xjj-4m88.json +++ b/advisories/unreviewed/2022/04/GHSA-3785-7xjj-4m88/GHSA-3785-7xjj-4m88.json @@ -7,12 +7,8 @@ "CVE-2004-1760" ], "details": "The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-389h-r2q6-jqgm/GHSA-389h-r2q6-jqgm.json b/advisories/unreviewed/2022/04/GHSA-389h-r2q6-jqgm/GHSA-389h-r2q6-jqgm.json index 8c5b1deddf8..3eccc57cc0f 100644 --- a/advisories/unreviewed/2022/04/GHSA-389h-r2q6-jqgm/GHSA-389h-r2q6-jqgm.json +++ b/advisories/unreviewed/2022/04/GHSA-389h-r2q6-jqgm/GHSA-389h-r2q6-jqgm.json @@ -7,12 +7,8 @@ "CVE-2004-1809" ], "details": "Cross-site scripting (XSS) vulnerability in phpBB 2.0.6d and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) postdays parameter to viewtopic.php or (2) topicdays parameter to viewforum.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-38pq-79pv-7gpm/GHSA-38pq-79pv-7gpm.json b/advisories/unreviewed/2022/04/GHSA-38pq-79pv-7gpm/GHSA-38pq-79pv-7gpm.json index c954fb6c6b0..6092c000bab 100644 --- a/advisories/unreviewed/2022/04/GHSA-38pq-79pv-7gpm/GHSA-38pq-79pv-7gpm.json +++ b/advisories/unreviewed/2022/04/GHSA-38pq-79pv-7gpm/GHSA-38pq-79pv-7gpm.json @@ -7,12 +7,8 @@ "CVE-2004-1914" ], "details": "SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via the eid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3cmp-6g7x-v2gr/GHSA-3cmp-6g7x-v2gr.json b/advisories/unreviewed/2022/04/GHSA-3cmp-6g7x-v2gr/GHSA-3cmp-6g7x-v2gr.json index 8426f5f726b..74eaf36b598 100644 --- a/advisories/unreviewed/2022/04/GHSA-3cmp-6g7x-v2gr/GHSA-3cmp-6g7x-v2gr.json +++ b/advisories/unreviewed/2022/04/GHSA-3cmp-6g7x-v2gr/GHSA-3cmp-6g7x-v2gr.json @@ -7,12 +7,8 @@ "CVE-2004-1777" ], "details": "A \"range check error\" in Skype for Windows before 0.98.0.28 allows local and remote attackers to cause a denial of service (application crash) via long command line arguments or a long callto:// URL, a different vulnerability than CVE-2004-1114.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-3f6m-j22w-8r7f/GHSA-3f6m-j22w-8r7f.json b/advisories/unreviewed/2022/04/GHSA-3f6m-j22w-8r7f/GHSA-3f6m-j22w-8r7f.json index b25152abd46..ad2fde66a7b 100644 --- a/advisories/unreviewed/2022/04/GHSA-3f6m-j22w-8r7f/GHSA-3f6m-j22w-8r7f.json +++ b/advisories/unreviewed/2022/04/GHSA-3f6m-j22w-8r7f/GHSA-3f6m-j22w-8r7f.json @@ -7,12 +7,8 @@ "CVE-2004-1936" ], "details": "ZoneAlarm Pro 4.5.538.001 and possibly other versions allows remote attackers to bypass e-mail protection via attachments whose names contain certain non-English characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3h5c-58g7-j245/GHSA-3h5c-58g7-j245.json b/advisories/unreviewed/2022/04/GHSA-3h5c-58g7-j245/GHSA-3h5c-58g7-j245.json index 6016f168082..eced2b30cbe 100644 --- a/advisories/unreviewed/2022/04/GHSA-3h5c-58g7-j245/GHSA-3h5c-58g7-j245.json +++ b/advisories/unreviewed/2022/04/GHSA-3h5c-58g7-j245/GHSA-3h5c-58g7-j245.json @@ -7,12 +7,8 @@ "CVE-2004-1878" ], "details": "LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl preceded by // (double leading slash).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3mrh-hhw4-729x/GHSA-3mrh-hhw4-729x.json b/advisories/unreviewed/2022/04/GHSA-3mrh-hhw4-729x/GHSA-3mrh-hhw4-729x.json index a27e12afb4f..9280e4285f6 100644 --- a/advisories/unreviewed/2022/04/GHSA-3mrh-hhw4-729x/GHSA-3mrh-hhw4-729x.json +++ b/advisories/unreviewed/2022/04/GHSA-3mrh-hhw4-729x/GHSA-3mrh-hhw4-729x.json @@ -7,12 +7,8 @@ "CVE-2004-1930" ], "details": "Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3mx4-39m2-w2c8/GHSA-3mx4-39m2-w2c8.json b/advisories/unreviewed/2022/04/GHSA-3mx4-39m2-w2c8/GHSA-3mx4-39m2-w2c8.json index 54220d5a442..9f627970d8b 100644 --- a/advisories/unreviewed/2022/04/GHSA-3mx4-39m2-w2c8/GHSA-3mx4-39m2-w2c8.json +++ b/advisories/unreviewed/2022/04/GHSA-3mx4-39m2-w2c8/GHSA-3mx4-39m2-w2c8.json @@ -7,12 +7,8 @@ "CVE-2004-1870" ], "details": "Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comments.php, (3) credit parameter to comments.php, (4) cat parameter to index.php, (5) ppuser parameter to showgallery.php, (6) cat parameter to showgallery.php, (7) cat parameter to uploadphoto.php, (8) albumid parameter to useralbums.php, or (9) albumid parameter to useralbums.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3q7r-7v6p-hf62/GHSA-3q7r-7v6p-hf62.json b/advisories/unreviewed/2022/04/GHSA-3q7r-7v6p-hf62/GHSA-3q7r-7v6p-hf62.json index 24af57ac56c..14d595be12d 100644 --- a/advisories/unreviewed/2022/04/GHSA-3q7r-7v6p-hf62/GHSA-3q7r-7v6p-hf62.json +++ b/advisories/unreviewed/2022/04/GHSA-3q7r-7v6p-hf62/GHSA-3q7r-7v6p-hf62.json @@ -7,12 +7,8 @@ "CVE-2004-1829" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in error.php in Gijza.net Error Manager 2.1 for PHP-Nuke 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pagetitle or (2) error parameters, or (3) certain parameters in the error log.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3xv5-7mgj-868h/GHSA-3xv5-7mgj-868h.json b/advisories/unreviewed/2022/04/GHSA-3xv5-7mgj-868h/GHSA-3xv5-7mgj-868h.json index 01fdb63a242..f30fc5ef531 100644 --- a/advisories/unreviewed/2022/04/GHSA-3xv5-7mgj-868h/GHSA-3xv5-7mgj-868h.json +++ b/advisories/unreviewed/2022/04/GHSA-3xv5-7mgj-868h/GHSA-3xv5-7mgj-868h.json @@ -7,12 +7,8 @@ "CVE-2004-2004" ], "details": "The Live CD in SUSE LINUX 9.1 Personal edition is configured without a password for root, which allows remote attackers to gain privileges via SSH.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3xx8-2m7h-8rhw/GHSA-3xx8-2m7h-8rhw.json b/advisories/unreviewed/2022/04/GHSA-3xx8-2m7h-8rhw/GHSA-3xx8-2m7h-8rhw.json index 2af36c91f83..ecdca9b651a 100644 --- a/advisories/unreviewed/2022/04/GHSA-3xx8-2m7h-8rhw/GHSA-3xx8-2m7h-8rhw.json +++ b/advisories/unreviewed/2022/04/GHSA-3xx8-2m7h-8rhw/GHSA-3xx8-2m7h-8rhw.json @@ -7,12 +7,8 @@ "CVE-2004-1974" ], "details": "paFileDB 3.1 allows remote attackers to gain sensitive information via a direct request to (1) login.php, (2) category.php, (3) search.php, (4) main.php, (5) viewall.php, (6) download.php, (7) email.php, (8) file.php, (9) rate.php, or (10) stats.php, which reveals the path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-427h-jcwm-rr2p/GHSA-427h-jcwm-rr2p.json b/advisories/unreviewed/2022/04/GHSA-427h-jcwm-rr2p/GHSA-427h-jcwm-rr2p.json index ee1a8972cf0..75b036a23ca 100644 --- a/advisories/unreviewed/2022/04/GHSA-427h-jcwm-rr2p/GHSA-427h-jcwm-rr2p.json +++ b/advisories/unreviewed/2022/04/GHSA-427h-jcwm-rr2p/GHSA-427h-jcwm-rr2p.json @@ -7,12 +7,8 @@ "CVE-2004-1863" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allow remote attackers to inject arbitrary web script or HTML via (1) the u2uheader parameter in editprofile.php, the restrict parameter in (2) member.php, (3) misc.php, and (4) today.php, and (5) an arbitrary parameter in phpinfo.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4435-vfjh-hg77/GHSA-4435-vfjh-hg77.json b/advisories/unreviewed/2022/04/GHSA-4435-vfjh-hg77/GHSA-4435-vfjh-hg77.json index 03b7124bfe2..75ada86c910 100644 --- a/advisories/unreviewed/2022/04/GHSA-4435-vfjh-hg77/GHSA-4435-vfjh-hg77.json +++ b/advisories/unreviewed/2022/04/GHSA-4435-vfjh-hg77/GHSA-4435-vfjh-hg77.json @@ -7,12 +7,8 @@ "CVE-2004-1789" ], "details": "Cross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to inject arbitrary web script or HTML via the rpAuth_1 page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-453p-67r6-5c96/GHSA-453p-67r6-5c96.json b/advisories/unreviewed/2022/04/GHSA-453p-67r6-5c96/GHSA-453p-67r6-5c96.json index a250d9eaed4..65ecc71e704 100644 --- a/advisories/unreviewed/2022/04/GHSA-453p-67r6-5c96/GHSA-453p-67r6-5c96.json +++ b/advisories/unreviewed/2022/04/GHSA-453p-67r6-5c96/GHSA-453p-67r6-5c96.json @@ -7,12 +7,8 @@ "CVE-2004-1859" ], "details": "Directory traversal vulnerability in Trend Micro Interscan Web Viruswall in InterScan VirusWall 3.5x allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4543-8mx9-whfp/GHSA-4543-8mx9-whfp.json b/advisories/unreviewed/2022/04/GHSA-4543-8mx9-whfp/GHSA-4543-8mx9-whfp.json index 5e30c8a81bf..f5844b91b6f 100644 --- a/advisories/unreviewed/2022/04/GHSA-4543-8mx9-whfp/GHSA-4543-8mx9-whfp.json +++ b/advisories/unreviewed/2022/04/GHSA-4543-8mx9-whfp/GHSA-4543-8mx9-whfp.json @@ -7,12 +7,8 @@ "CVE-2004-1887" ], "details": "Ada Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a trailing %00 (null).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-486x-ghfj-9wr5/GHSA-486x-ghfj-9wr5.json b/advisories/unreviewed/2022/04/GHSA-486x-ghfj-9wr5/GHSA-486x-ghfj-9wr5.json index daf9377ed1f..bb335dd32bd 100644 --- a/advisories/unreviewed/2022/04/GHSA-486x-ghfj-9wr5/GHSA-486x-ghfj-9wr5.json +++ b/advisories/unreviewed/2022/04/GHSA-486x-ghfj-9wr5/GHSA-486x-ghfj-9wr5.json @@ -7,12 +7,8 @@ "CVE-2004-1934" ], "details": "PHP remote file inclusion vulnerability in affich.php in Gemitel 3.50 allows remote attackers to execute arbitrary PHP code via the base parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-48p2-f7h3-gpww/GHSA-48p2-f7h3-gpww.json b/advisories/unreviewed/2022/04/GHSA-48p2-f7h3-gpww/GHSA-48p2-f7h3-gpww.json index 582bfefc529..f094fe8d80e 100644 --- a/advisories/unreviewed/2022/04/GHSA-48p2-f7h3-gpww/GHSA-48p2-f7h3-gpww.json +++ b/advisories/unreviewed/2022/04/GHSA-48p2-f7h3-gpww/GHSA-48p2-f7h3-gpww.json @@ -7,12 +7,8 @@ "CVE-2004-1916" ], "details": "Multiple buffer overflows in LCDProc 0.4.1, and possibly other 0.4.x versions up to 0.4.4, allows remote attackers to execute arbitrary code via (1) a long invalid command to parse_all_client_messages function, or (2) long argv command to test_func_func function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-48p4-c835-2pjf/GHSA-48p4-c835-2pjf.json b/advisories/unreviewed/2022/04/GHSA-48p4-c835-2pjf/GHSA-48p4-c835-2pjf.json index 96d9fec262f..86980fcfb7b 100644 --- a/advisories/unreviewed/2022/04/GHSA-48p4-c835-2pjf/GHSA-48p4-c835-2pjf.json +++ b/advisories/unreviewed/2022/04/GHSA-48p4-c835-2pjf/GHSA-48p4-c835-2pjf.json @@ -7,12 +7,8 @@ "CVE-2004-1805" ], "details": "Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in class names.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4fwm-xx33-45wp/GHSA-4fwm-xx33-45wp.json b/advisories/unreviewed/2022/04/GHSA-4fwm-xx33-45wp/GHSA-4fwm-xx33-45wp.json index ed95397cba9..4a7b208a6bb 100644 --- a/advisories/unreviewed/2022/04/GHSA-4fwm-xx33-45wp/GHSA-4fwm-xx33-45wp.json +++ b/advisories/unreviewed/2022/04/GHSA-4fwm-xx33-45wp/GHSA-4fwm-xx33-45wp.json @@ -7,12 +7,8 @@ "CVE-2004-1923" ], "details": "Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) banner_click.php, (2) categorize.php, (3) tiki-admin_include_directory.php, (4) tiki-directory_search.php, which reveal the web server path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4g8r-q426-gj34/GHSA-4g8r-q426-gj34.json b/advisories/unreviewed/2022/04/GHSA-4g8r-q426-gj34/GHSA-4g8r-q426-gj34.json index a6cb897cf45..a86652b2fc7 100644 --- a/advisories/unreviewed/2022/04/GHSA-4g8r-q426-gj34/GHSA-4g8r-q426-gj34.json +++ b/advisories/unreviewed/2022/04/GHSA-4g8r-q426-gj34/GHSA-4g8r-q426-gj34.json @@ -7,12 +7,8 @@ "CVE-2004-1784" ], "details": "Buffer overflow in the web server of Webcam Watchdog 3.63 allows remote attackers to execute arbitrary code via a long HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4hqx-53cj-v46r/GHSA-4hqx-53cj-v46r.json b/advisories/unreviewed/2022/04/GHSA-4hqx-53cj-v46r/GHSA-4hqx-53cj-v46r.json index 401af096266..be1b5ea9236 100644 --- a/advisories/unreviewed/2022/04/GHSA-4hqx-53cj-v46r/GHSA-4hqx-53cj-v46r.json +++ b/advisories/unreviewed/2022/04/GHSA-4hqx-53cj-v46r/GHSA-4hqx-53cj-v46r.json @@ -7,12 +7,8 @@ "CVE-2004-1925" ], "details": "Multiple SQL injection vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sort_mode parameter in (1) tiki-usermenu.php, (2) tiki-list_file_gallery.php, (3) tiki-directory_ranking.php, (4) tiki-browse_categories.php, (5) tiki-index.php, (6) tiki-user_tasks.php, (7) tiki-directory_ranking.php, (8) tiki-directory_search.php, (9) tiki-file_galleries.php, (10) tiki-list_faqs.php, (11) tiki-list_trackers.php, (12) tiki-list_blogs.php, or via the offset parameter in (13) tiki-usermenu.php, (14) tiki-browse_categories.php, (15) tiki-index.php, (16) tiki-user_tasks.php, (17) tiki-list_faqs.php, (18) tiki-list_trackers.php, or (19) tiki-list_blogs.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4hv6-2q5x-grr5/GHSA-4hv6-2q5x-grr5.json b/advisories/unreviewed/2022/04/GHSA-4hv6-2q5x-grr5/GHSA-4hv6-2q5x-grr5.json index 2124d15d9a6..804ec438bc7 100644 --- a/advisories/unreviewed/2022/04/GHSA-4hv6-2q5x-grr5/GHSA-4hv6-2q5x-grr5.json +++ b/advisories/unreviewed/2022/04/GHSA-4hv6-2q5x-grr5/GHSA-4hv6-2q5x-grr5.json @@ -7,12 +7,8 @@ "CVE-2004-1965" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) redirect parameter to member.php, (2) to parameter to myhome.php (3) TID parameter to post.php, or (4) redirect parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4rv2-mv82-8rpm/GHSA-4rv2-mv82-8rpm.json b/advisories/unreviewed/2022/04/GHSA-4rv2-mv82-8rpm/GHSA-4rv2-mv82-8rpm.json index 247659f2a69..844e1ab02f6 100644 --- a/advisories/unreviewed/2022/04/GHSA-4rv2-mv82-8rpm/GHSA-4rv2-mv82-8rpm.json +++ b/advisories/unreviewed/2022/04/GHSA-4rv2-mv82-8rpm/GHSA-4rv2-mv82-8rpm.json @@ -7,12 +7,8 @@ "CVE-2004-2039" ], "details": "e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php, (4) counter_menu.php, (5) login_menu.php, and other files, which reveal the full path in a PHP error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4v44-9qpg-fr3q/GHSA-4v44-9qpg-fr3q.json b/advisories/unreviewed/2022/04/GHSA-4v44-9qpg-fr3q/GHSA-4v44-9qpg-fr3q.json index d18ec908b2d..9b9034e7192 100644 --- a/advisories/unreviewed/2022/04/GHSA-4v44-9qpg-fr3q/GHSA-4v44-9qpg-fr3q.json +++ b/advisories/unreviewed/2022/04/GHSA-4v44-9qpg-fr3q/GHSA-4v44-9qpg-fr3q.json @@ -7,12 +7,8 @@ "CVE-2004-1971" ], "details": "modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to gain sensitive information via an HTTP request with an invalid (1) catid or (2) clipid parameter, which reveals the full path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4wx8-g7v3-ccf4/GHSA-4wx8-g7v3-ccf4.json b/advisories/unreviewed/2022/04/GHSA-4wx8-g7v3-ccf4/GHSA-4wx8-g7v3-ccf4.json index 20baf43cb88..eb5bb665452 100644 --- a/advisories/unreviewed/2022/04/GHSA-4wx8-g7v3-ccf4/GHSA-4wx8-g7v3-ccf4.json +++ b/advisories/unreviewed/2022/04/GHSA-4wx8-g7v3-ccf4/GHSA-4wx8-g7v3-ccf4.json @@ -7,12 +7,8 @@ "CVE-2004-1894" ], "details": "TEXutil in ConTEXt, when executed with the --silent option, allows local users to overwrite arbitrary files via a symlink attack on texutil.log.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-553c-w3pr-f6rh/GHSA-553c-w3pr-f6rh.json b/advisories/unreviewed/2022/04/GHSA-553c-w3pr-f6rh/GHSA-553c-w3pr-f6rh.json index 6f2f7cf50d2..8d4515ebc69 100644 --- a/advisories/unreviewed/2022/04/GHSA-553c-w3pr-f6rh/GHSA-553c-w3pr-f6rh.json +++ b/advisories/unreviewed/2022/04/GHSA-553c-w3pr-f6rh/GHSA-553c-w3pr-f6rh.json @@ -7,12 +7,8 @@ "CVE-2004-1950" ], "details": "phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-56c4-96vh-gvqv/GHSA-56c4-96vh-gvqv.json b/advisories/unreviewed/2022/04/GHSA-56c4-96vh-gvqv/GHSA-56c4-96vh-gvqv.json index 8317e86a05c..26a4d84da81 100644 --- a/advisories/unreviewed/2022/04/GHSA-56c4-96vh-gvqv/GHSA-56c4-96vh-gvqv.json +++ b/advisories/unreviewed/2022/04/GHSA-56c4-96vh-gvqv/GHSA-56c4-96vh-gvqv.json @@ -7,12 +7,8 @@ "CVE-2004-1908" ], "details": "McFreeScan.CoMcFreeScan.1 ActiveX object in Mcafee FreeScan allows remote attackers to obtain sensitive information via the GetSpecialFolderLocation function with certain parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-56hh-fr44-f679/GHSA-56hh-fr44-f679.json b/advisories/unreviewed/2022/04/GHSA-56hh-fr44-f679/GHSA-56hh-fr44-f679.json index 2107da344f4..d6d67b6713c 100644 --- a/advisories/unreviewed/2022/04/GHSA-56hh-fr44-f679/GHSA-56hh-fr44-f679.json +++ b/advisories/unreviewed/2022/04/GHSA-56hh-fr44-f679/GHSA-56hh-fr44-f679.json @@ -7,12 +7,8 @@ "CVE-2004-1861" ], "details": "Invision NetSupport School Pro uses a weak encryption algorithm to encrypt passwords, which allows local users to obtain passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-574v-6q35-pc25/GHSA-574v-6q35-pc25.json b/advisories/unreviewed/2022/04/GHSA-574v-6q35-pc25/GHSA-574v-6q35-pc25.json index 655ca1f7368..eaa71b0ce7b 100644 --- a/advisories/unreviewed/2022/04/GHSA-574v-6q35-pc25/GHSA-574v-6q35-pc25.json +++ b/advisories/unreviewed/2022/04/GHSA-574v-6q35-pc25/GHSA-574v-6q35-pc25.json @@ -7,12 +7,8 @@ "CVE-2004-1938" ], "details": "SQL injection vulnerability in userlogin.php in Phorum 3.4.7 allows remote attackers to execute arbitrary SQL commands via doubly hex-encoded characters such as \"%2527\", which is translated to \"'\", as demonstrated using the phorum_uriauth parameter to list.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-57gf-375c-cgqp/GHSA-57gf-375c-cgqp.json b/advisories/unreviewed/2022/04/GHSA-57gf-375c-cgqp/GHSA-57gf-375c-cgqp.json index 24377587faf..006a71b8fed 100644 --- a/advisories/unreviewed/2022/04/GHSA-57gf-375c-cgqp/GHSA-57gf-375c-cgqp.json +++ b/advisories/unreviewed/2022/04/GHSA-57gf-375c-cgqp/GHSA-57gf-375c-cgqp.json @@ -7,12 +7,8 @@ "CVE-2004-2042" ], "details": "Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via (1) content parameter to content.php, (2) content_id parameter to content.php, or (3) list parameter to news.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-57vf-j77f-qh68/GHSA-57vf-j77f-qh68.json b/advisories/unreviewed/2022/04/GHSA-57vf-j77f-qh68/GHSA-57vf-j77f-qh68.json index 138821d67a6..be4d8b78b23 100644 --- a/advisories/unreviewed/2022/04/GHSA-57vf-j77f-qh68/GHSA-57vf-j77f-qh68.json +++ b/advisories/unreviewed/2022/04/GHSA-57vf-j77f-qh68/GHSA-57vf-j77f-qh68.json @@ -7,12 +7,8 @@ "CVE-2004-1811" ], "details": "The SSL HTTP Server in HP Web-enabled Management Software 5.0 through 5.92, with anonymous access enabled, allows remote attackers to compromise the trusted certificates by uploading their own certificates.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-58p4-m4hp-w4m8/GHSA-58p4-m4hp-w4m8.json b/advisories/unreviewed/2022/04/GHSA-58p4-m4hp-w4m8/GHSA-58p4-m4hp-w4m8.json index f9204bbf99d..e82e523f75e 100644 --- a/advisories/unreviewed/2022/04/GHSA-58p4-m4hp-w4m8/GHSA-58p4-m4hp-w4m8.json +++ b/advisories/unreviewed/2022/04/GHSA-58p4-m4hp-w4m8/GHSA-58p4-m4hp-w4m8.json @@ -7,12 +7,8 @@ "CVE-2004-1945" ], "details": "Buffer overflow in Kinesphere eXchange POP3 allows remote attackers to execute arbitrary code via a long MAIL FROM field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-592r-52h4-gh6f/GHSA-592r-52h4-gh6f.json b/advisories/unreviewed/2022/04/GHSA-592r-52h4-gh6f/GHSA-592r-52h4-gh6f.json index 6222cb7064b..45849edc296 100644 --- a/advisories/unreviewed/2022/04/GHSA-592r-52h4-gh6f/GHSA-592r-52h4-gh6f.json +++ b/advisories/unreviewed/2022/04/GHSA-592r-52h4-gh6f/GHSA-592r-52h4-gh6f.json @@ -7,12 +7,8 @@ "CVE-2004-2041" ], "details": "PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modifying the p parameter to reference a URL on a remote web server that contains the code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5c7m-cf2v-r6qf/GHSA-5c7m-cf2v-r6qf.json b/advisories/unreviewed/2022/04/GHSA-5c7m-cf2v-r6qf/GHSA-5c7m-cf2v-r6qf.json index ccf0fb81590..9801cfdd2f8 100644 --- a/advisories/unreviewed/2022/04/GHSA-5c7m-cf2v-r6qf/GHSA-5c7m-cf2v-r6qf.json +++ b/advisories/unreviewed/2022/04/GHSA-5c7m-cf2v-r6qf/GHSA-5c7m-cf2v-r6qf.json @@ -7,12 +7,8 @@ "CVE-2004-1909" ], "details": "Claim Anti-Virus (ClamAV) 0.68 and earlier allows remote attackers to cause a denial of service (crash) via certain RAR archives, such as those generated by the Beagle/Bagle worm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5fmv-rgcw-6pv3/GHSA-5fmv-rgcw-6pv3.json b/advisories/unreviewed/2022/04/GHSA-5fmv-rgcw-6pv3/GHSA-5fmv-rgcw-6pv3.json index 7234ee469ce..f16b64a32a7 100644 --- a/advisories/unreviewed/2022/04/GHSA-5fmv-rgcw-6pv3/GHSA-5fmv-rgcw-6pv3.json +++ b/advisories/unreviewed/2022/04/GHSA-5fmv-rgcw-6pv3/GHSA-5fmv-rgcw-6pv3.json @@ -7,12 +7,8 @@ "CVE-2004-1823" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4 allows remote attackers to inject arbitrary web script or HTML via the (1) page parameter to showthread.php or (2) order parameter to forumdisplay.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5prc-xg5r-wf38/GHSA-5prc-xg5r-wf38.json b/advisories/unreviewed/2022/04/GHSA-5prc-xg5r-wf38/GHSA-5prc-xg5r-wf38.json index 59492d3129c..c5b2ba74706 100644 --- a/advisories/unreviewed/2022/04/GHSA-5prc-xg5r-wf38/GHSA-5prc-xg5r-wf38.json +++ b/advisories/unreviewed/2022/04/GHSA-5prc-xg5r-wf38/GHSA-5prc-xg5r-wf38.json @@ -7,12 +7,8 @@ "CVE-2004-1801" ], "details": "Directory traversal vulnerability in PWebServer 0.3.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5qv2-fhvc-7vj5/GHSA-5qv2-fhvc-7vj5.json b/advisories/unreviewed/2022/04/GHSA-5qv2-fhvc-7vj5/GHSA-5qv2-fhvc-7vj5.json index cb7ac4f30d0..bd8a796a665 100644 --- a/advisories/unreviewed/2022/04/GHSA-5qv2-fhvc-7vj5/GHSA-5qv2-fhvc-7vj5.json +++ b/advisories/unreviewed/2022/04/GHSA-5qv2-fhvc-7vj5/GHSA-5qv2-fhvc-7vj5.json @@ -7,12 +7,8 @@ "CVE-2004-1788" ], "details": "ASP-Nuke 1.3 and earlier places user credentials under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to main.mdb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5rq3-72h6-4g99/GHSA-5rq3-72h6-4g99.json b/advisories/unreviewed/2022/04/GHSA-5rq3-72h6-4g99/GHSA-5rq3-72h6-4g99.json index daa55a6c523..48aed4b719c 100644 --- a/advisories/unreviewed/2022/04/GHSA-5rq3-72h6-4g99/GHSA-5rq3-72h6-4g99.json +++ b/advisories/unreviewed/2022/04/GHSA-5rq3-72h6-4g99/GHSA-5rq3-72h6-4g99.json @@ -7,12 +7,8 @@ "CVE-2004-1844" ], "details": "Cross-site scripting (XSS) vulnerability in Member Management System 2.1 allows remote attackers to inject arbitrary web script or HTML via (1) the err parameter to error.asp or (2) register.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5wph-qqfg-2px4/GHSA-5wph-qqfg-2px4.json b/advisories/unreviewed/2022/04/GHSA-5wph-qqfg-2px4/GHSA-5wph-qqfg-2px4.json index 60d01f49d5d..fc4131c9e1e 100644 --- a/advisories/unreviewed/2022/04/GHSA-5wph-qqfg-2px4/GHSA-5wph-qqfg-2px4.json +++ b/advisories/unreviewed/2022/04/GHSA-5wph-qqfg-2px4/GHSA-5wph-qqfg-2px4.json @@ -7,12 +7,8 @@ "CVE-2004-1780" ], "details": "Info Touch Surfnet kiosk allows local users to deposit extra time into Internet kiosk accounts via repeated authentication attempts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5x6p-wxw3-x7q8/GHSA-5x6p-wxw3-x7q8.json b/advisories/unreviewed/2022/04/GHSA-5x6p-wxw3-x7q8/GHSA-5x6p-wxw3-x7q8.json index ddd15810d8d..20079893297 100644 --- a/advisories/unreviewed/2022/04/GHSA-5x6p-wxw3-x7q8/GHSA-5x6p-wxw3-x7q8.json +++ b/advisories/unreviewed/2022/04/GHSA-5x6p-wxw3-x7q8/GHSA-5x6p-wxw3-x7q8.json @@ -7,12 +7,8 @@ "CVE-2004-1869" ], "details": "Etherlords I 1.07 and earlier and Etherlords II 1.03 and earlier allows remote attackers to cause a denial of service (crash) by sending a packet that specifies the size for the next packet, then sending a larger packet than specified, which causes Etherlords to read unallocated memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-64r9-wcqr-wq62/GHSA-64r9-wcqr-wq62.json b/advisories/unreviewed/2022/04/GHSA-64r9-wcqr-wq62/GHSA-64r9-wcqr-wq62.json index edf1d6d71cb..a671dfea428 100644 --- a/advisories/unreviewed/2022/04/GHSA-64r9-wcqr-wq62/GHSA-64r9-wcqr-wq62.json +++ b/advisories/unreviewed/2022/04/GHSA-64r9-wcqr-wq62/GHSA-64r9-wcqr-wq62.json @@ -7,12 +7,8 @@ "CVE-2004-1835" ], "details": "Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-65gx-74hx-6wm6/GHSA-65gx-74hx-6wm6.json b/advisories/unreviewed/2022/04/GHSA-65gx-74hx-6wm6/GHSA-65gx-74hx-6wm6.json index 46800b13c63..9528cfa71b1 100644 --- a/advisories/unreviewed/2022/04/GHSA-65gx-74hx-6wm6/GHSA-65gx-74hx-6wm6.json +++ b/advisories/unreviewed/2022/04/GHSA-65gx-74hx-6wm6/GHSA-65gx-74hx-6wm6.json @@ -7,12 +7,8 @@ "CVE-2004-1764" ], "details": "Buffer overflow in CDE libDtSvc on HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows local users to gain root privileges via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-68xc-2q5w-63wq/GHSA-68xc-2q5w-63wq.json b/advisories/unreviewed/2022/04/GHSA-68xc-2q5w-63wq/GHSA-68xc-2q5w-63wq.json index 2822bd2e3db..d7e43a02356 100644 --- a/advisories/unreviewed/2022/04/GHSA-68xc-2q5w-63wq/GHSA-68xc-2q5w-63wq.json +++ b/advisories/unreviewed/2022/04/GHSA-68xc-2q5w-63wq/GHSA-68xc-2q5w-63wq.json @@ -7,12 +7,8 @@ "CVE-2004-1791" ], "details": "The web management interface in Edimax AR-6004 ADSL Routers uses a default administrator name and password, which also appear as the default login text for the management interface, which allows remote attackers to gain access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6979-7cwq-22m2/GHSA-6979-7cwq-22m2.json b/advisories/unreviewed/2022/04/GHSA-6979-7cwq-22m2/GHSA-6979-7cwq-22m2.json index 7c02e829967..cbae556a046 100644 --- a/advisories/unreviewed/2022/04/GHSA-6979-7cwq-22m2/GHSA-6979-7cwq-22m2.json +++ b/advisories/unreviewed/2022/04/GHSA-6979-7cwq-22m2/GHSA-6979-7cwq-22m2.json @@ -7,12 +7,8 @@ "CVE-2004-2000" ], "details": "SQL injection vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL via the (1) orderby or (2) sid parameters to modules.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6g7x-c8vf-63fq/GHSA-6g7x-c8vf-63fq.json b/advisories/unreviewed/2022/04/GHSA-6g7x-c8vf-63fq/GHSA-6g7x-c8vf-63fq.json index aa5bc467a7d..c158c28b5c4 100644 --- a/advisories/unreviewed/2022/04/GHSA-6g7x-c8vf-63fq/GHSA-6g7x-c8vf-63fq.json +++ b/advisories/unreviewed/2022/04/GHSA-6g7x-c8vf-63fq/GHSA-6g7x-c8vf-63fq.json @@ -7,12 +7,8 @@ "CVE-2004-2022" ], "details": "ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the system command, which leads to a stack-based buffer overflow. NOTE: it is unclear whether this bug is in Perl or the OS API that is used by Perl.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6mmq-3rm6-xqjm/GHSA-6mmq-3rm6-xqjm.json b/advisories/unreviewed/2022/04/GHSA-6mmq-3rm6-xqjm/GHSA-6mmq-3rm6-xqjm.json index 9af5a4848a6..a044861297d 100644 --- a/advisories/unreviewed/2022/04/GHSA-6mmq-3rm6-xqjm/GHSA-6mmq-3rm6-xqjm.json +++ b/advisories/unreviewed/2022/04/GHSA-6mmq-3rm6-xqjm/GHSA-6mmq-3rm6-xqjm.json @@ -7,12 +7,8 @@ "CVE-2004-1904" ], "details": "Buffer overflow in ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to execute arbitrary code via the Internacional property followed by a long string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6qgj-q2w2-qgcp/GHSA-6qgj-q2w2-qgcp.json b/advisories/unreviewed/2022/04/GHSA-6qgj-q2w2-qgcp/GHSA-6qgj-q2w2-qgcp.json index bdbb6384ad7..c44970ec62a 100644 --- a/advisories/unreviewed/2022/04/GHSA-6qgj-q2w2-qgcp/GHSA-6qgj-q2w2-qgcp.json +++ b/advisories/unreviewed/2022/04/GHSA-6qgj-q2w2-qgcp/GHSA-6qgj-q2w2-qgcp.json @@ -7,12 +7,8 @@ "CVE-2004-1892" ], "details": "Stack-based buffer overflow in DecodeBase16 function, as used in the (1) IRC module and (2) web server in eMule 0.42d, allows remote attackers to execute arbitrary code via a long string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6rrx-hmr4-623r/GHSA-6rrx-hmr4-623r.json b/advisories/unreviewed/2022/04/GHSA-6rrx-hmr4-623r/GHSA-6rrx-hmr4-623r.json index 307a09ed857..55e7ab773bc 100644 --- a/advisories/unreviewed/2022/04/GHSA-6rrx-hmr4-623r/GHSA-6rrx-hmr4-623r.json +++ b/advisories/unreviewed/2022/04/GHSA-6rrx-hmr4-623r/GHSA-6rrx-hmr4-623r.json @@ -7,12 +7,8 @@ "CVE-2004-1926" ], "details": "Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or the (5) Name, (6) Description, (7) URL, or (8) Country fields in a Directory/Add Site operation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-6wp4-7xq4-r96p/GHSA-6wp4-7xq4-r96p.json b/advisories/unreviewed/2022/04/GHSA-6wp4-7xq4-r96p/GHSA-6wp4-7xq4-r96p.json index 7032a019e39..07bcf8ee332 100644 --- a/advisories/unreviewed/2022/04/GHSA-6wp4-7xq4-r96p/GHSA-6wp4-7xq4-r96p.json +++ b/advisories/unreviewed/2022/04/GHSA-6wp4-7xq4-r96p/GHSA-6wp4-7xq4-r96p.json @@ -7,12 +7,8 @@ "CVE-2004-1880" ], "details": "Memory leak in the back-bdb backend for OpenLDAP 2.1.12 and earlier allows remote attackers to cause a denial of service (memory consumption).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6wpq-3g63-3x4f/GHSA-6wpq-3g63-3x4f.json b/advisories/unreviewed/2022/04/GHSA-6wpq-3g63-3x4f/GHSA-6wpq-3g63-3x4f.json index 2a8cf5613da..183f82bbdf1 100644 --- a/advisories/unreviewed/2022/04/GHSA-6wpq-3g63-3x4f/GHSA-6wpq-3g63-3x4f.json +++ b/advisories/unreviewed/2022/04/GHSA-6wpq-3g63-3x4f/GHSA-6wpq-3g63-3x4f.json @@ -7,12 +7,8 @@ "CVE-2004-1881" ], "details": "SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via the strItems parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6x86-v9c9-p52j/GHSA-6x86-v9c9-p52j.json b/advisories/unreviewed/2022/04/GHSA-6x86-v9c9-p52j/GHSA-6x86-v9c9-p52j.json index 5377548ac28..5b61956505e 100644 --- a/advisories/unreviewed/2022/04/GHSA-6x86-v9c9-p52j/GHSA-6x86-v9c9-p52j.json +++ b/advisories/unreviewed/2022/04/GHSA-6x86-v9c9-p52j/GHSA-6x86-v9c9-p52j.json @@ -7,12 +7,8 @@ "CVE-2004-2007" ], "details": "Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to inject arbitrary HTML or web script via the (1) cat parameter in a CatView function or (2) jokeid parameter in a JokeView function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6xg8-8xmf-qghw/GHSA-6xg8-8xmf-qghw.json b/advisories/unreviewed/2022/04/GHSA-6xg8-8xmf-qghw/GHSA-6xg8-8xmf-qghw.json index 1e1d7d9ff3b..741412e5845 100644 --- a/advisories/unreviewed/2022/04/GHSA-6xg8-8xmf-qghw/GHSA-6xg8-8xmf-qghw.json +++ b/advisories/unreviewed/2022/04/GHSA-6xg8-8xmf-qghw/GHSA-6xg8-8xmf-qghw.json @@ -7,12 +7,8 @@ "CVE-2004-1876" ], "details": "The \"%f\" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-726x-824j-cx56/GHSA-726x-824j-cx56.json b/advisories/unreviewed/2022/04/GHSA-726x-824j-cx56/GHSA-726x-824j-cx56.json index 809ca967a48..8e026f453bf 100644 --- a/advisories/unreviewed/2022/04/GHSA-726x-824j-cx56/GHSA-726x-824j-cx56.json +++ b/advisories/unreviewed/2022/04/GHSA-726x-824j-cx56/GHSA-726x-824j-cx56.json @@ -7,12 +7,8 @@ "CVE-2004-1800" ], "details": "Unknown vulnerability in Sysbotz SimpleData 4.0.1 and possibly earlier versions allows remote attackers to gain access via a crafted URL and a certain cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7436-qp9j-h84q/GHSA-7436-qp9j-h84q.json b/advisories/unreviewed/2022/04/GHSA-7436-qp9j-h84q/GHSA-7436-qp9j-h84q.json index 922f127304d..3b4f957d302 100644 --- a/advisories/unreviewed/2022/04/GHSA-7436-qp9j-h84q/GHSA-7436-qp9j-h84q.json +++ b/advisories/unreviewed/2022/04/GHSA-7436-qp9j-h84q/GHSA-7436-qp9j-h84q.json @@ -7,12 +7,8 @@ "CVE-2004-1810" ], "details": "The Javascript engine in Opera 7.23 allows remote attackers to cause a denial of service (crash) by creating a new Array object with a large size value, then writing into that array.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-74fr-mmwf-rxrm/GHSA-74fr-mmwf-rxrm.json b/advisories/unreviewed/2022/04/GHSA-74fr-mmwf-rxrm/GHSA-74fr-mmwf-rxrm.json index ca2690cd06d..d3357420722 100644 --- a/advisories/unreviewed/2022/04/GHSA-74fr-mmwf-rxrm/GHSA-74fr-mmwf-rxrm.json +++ b/advisories/unreviewed/2022/04/GHSA-74fr-mmwf-rxrm/GHSA-74fr-mmwf-rxrm.json @@ -7,12 +7,8 @@ "CVE-2004-2048" ], "details": "radmin in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier starts a process port 25072 that can be accessed with a default \"jstwo\" password, which allows remote attackers to gain access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-76hg-76m7-348w/GHSA-76hg-76m7-348w.json b/advisories/unreviewed/2022/04/GHSA-76hg-76m7-348w/GHSA-76hg-76m7-348w.json index f7e122911cc..e562adeaea8 100644 --- a/advisories/unreviewed/2022/04/GHSA-76hg-76m7-348w/GHSA-76hg-76m7-348w.json +++ b/advisories/unreviewed/2022/04/GHSA-76hg-76m7-348w/GHSA-76hg-76m7-348w.json @@ -7,12 +7,8 @@ "CVE-2004-1821" ], "details": "SQL injection vulnerability in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to gain privileges or perform unauthorized database operations via the gid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-79jf-625m-7xjf/GHSA-79jf-625m-7xjf.json b/advisories/unreviewed/2022/04/GHSA-79jf-625m-7xjf/GHSA-79jf-625m-7xjf.json index 914219ba33d..5f05f3f042c 100644 --- a/advisories/unreviewed/2022/04/GHSA-79jf-625m-7xjf/GHSA-79jf-625m-7xjf.json +++ b/advisories/unreviewed/2022/04/GHSA-79jf-625m-7xjf/GHSA-79jf-625m-7xjf.json @@ -7,12 +7,8 @@ "CVE-2004-1927" ], "details": "Directory traversal vulnerability in the map feature (tiki-map.phtml) in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to determine the existence of arbitrary files via .. (dot dot) sequences in the mapfile parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-7gh7-6hv4-6v8j/GHSA-7gh7-6hv4-6v8j.json b/advisories/unreviewed/2022/04/GHSA-7gh7-6hv4-6v8j/GHSA-7gh7-6hv4-6v8j.json index 8cd64cebf25..6a00ab2fe2a 100644 --- a/advisories/unreviewed/2022/04/GHSA-7gh7-6hv4-6v8j/GHSA-7gh7-6hv4-6v8j.json +++ b/advisories/unreviewed/2022/04/GHSA-7gh7-6hv4-6v8j/GHSA-7gh7-6hv4-6v8j.json @@ -7,12 +7,8 @@ "CVE-2004-1806" ], "details": "SQL injection vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to execute SQL commands via the (1) category_id, (2) product_id, or (3) feature_id parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7pjp-26r9-pjjc/GHSA-7pjp-26r9-pjjc.json b/advisories/unreviewed/2022/04/GHSA-7pjp-26r9-pjjc/GHSA-7pjp-26r9-pjjc.json index 511f3a5ed28..eb8bd0d324e 100644 --- a/advisories/unreviewed/2022/04/GHSA-7pjp-26r9-pjjc/GHSA-7pjp-26r9-pjjc.json +++ b/advisories/unreviewed/2022/04/GHSA-7pjp-26r9-pjjc/GHSA-7pjp-26r9-pjjc.json @@ -7,12 +7,8 @@ "CVE-2004-1976" ], "details": "SMC Barricade broadband router 7008ABR and 7004VBR enable remote administration by default, which allows remote attackers to gain access by connecting to port 1900.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7qv3-f7p8-h5qg/GHSA-7qv3-f7p8-h5qg.json b/advisories/unreviewed/2022/04/GHSA-7qv3-f7p8-h5qg/GHSA-7qv3-f7p8-h5qg.json index fb1d90fe76f..55475d12ba4 100644 --- a/advisories/unreviewed/2022/04/GHSA-7qv3-f7p8-h5qg/GHSA-7qv3-f7p8-h5qg.json +++ b/advisories/unreviewed/2022/04/GHSA-7qv3-f7p8-h5qg/GHSA-7qv3-f7p8-h5qg.json @@ -7,12 +7,8 @@ "CVE-2004-2028" ], "details": "Cross-site scripting (XSS) vulnerability in stats.php in e107 allows remote attackers to inject arbitrary web script or HTML via the referer parameter to log.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7wfh-2c49-26j8/GHSA-7wfh-2c49-26j8.json b/advisories/unreviewed/2022/04/GHSA-7wfh-2c49-26j8/GHSA-7wfh-2c49-26j8.json index 0126d8e8742..b5ba9ee5dc3 100644 --- a/advisories/unreviewed/2022/04/GHSA-7wfh-2c49-26j8/GHSA-7wfh-2c49-26j8.json +++ b/advisories/unreviewed/2022/04/GHSA-7wfh-2c49-26j8/GHSA-7wfh-2c49-26j8.json @@ -7,12 +7,8 @@ "CVE-2004-1918" ], "details": "RSniff 1.0 allows remote attackers to cause a denial of service (connection exhaustion) via a large number of connections with a command other than AUTHENTICATE, or without any data, which prevents the socket from being closed properly.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7whm-25r2-q59c/GHSA-7whm-25r2-q59c.json b/advisories/unreviewed/2022/04/GHSA-7whm-25r2-q59c/GHSA-7whm-25r2-q59c.json index 390c0e53aea..75aa989a941 100644 --- a/advisories/unreviewed/2022/04/GHSA-7whm-25r2-q59c/GHSA-7whm-25r2-q59c.json +++ b/advisories/unreviewed/2022/04/GHSA-7whm-25r2-q59c/GHSA-7whm-25r2-q59c.json @@ -7,12 +7,8 @@ "CVE-2004-1895" ], "details": "YaST Online Update (YOU) in SuSE 8.2 and 9.0 allows local users to overwrite arbitrary files via a symlink attack on you-$USER/cookies.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-82v8-pgpv-7cmv/GHSA-82v8-pgpv-7cmv.json b/advisories/unreviewed/2022/04/GHSA-82v8-pgpv-7cmv/GHSA-82v8-pgpv-7cmv.json index b11173cefa0..b7b7e9e08a0 100644 --- a/advisories/unreviewed/2022/04/GHSA-82v8-pgpv-7cmv/GHSA-82v8-pgpv-7cmv.json +++ b/advisories/unreviewed/2022/04/GHSA-82v8-pgpv-7cmv/GHSA-82v8-pgpv-7cmv.json @@ -7,12 +7,8 @@ "CVE-2004-1782" ], "details": "athenareg.php in Athena Web Registration allows remote attackers to execute arbitrary commands via shell metacharacters in the pass parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-86jg-72jj-vxr7/GHSA-86jg-72jj-vxr7.json b/advisories/unreviewed/2022/04/GHSA-86jg-72jj-vxr7/GHSA-86jg-72jj-vxr7.json index 1b6c6c93ab6..e32782d71bb 100644 --- a/advisories/unreviewed/2022/04/GHSA-86jg-72jj-vxr7/GHSA-86jg-72jj-vxr7.json +++ b/advisories/unreviewed/2022/04/GHSA-86jg-72jj-vxr7/GHSA-86jg-72jj-vxr7.json @@ -7,12 +7,8 @@ "CVE-2004-1899" ], "details": "The administration interface in Monit 1.4 through 4.2 allows remote attackers to cause an off-by-one overflow via a POST that contains 1024 bytes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-87c6-4vv3-cm22/GHSA-87c6-4vv3-cm22.json b/advisories/unreviewed/2022/04/GHSA-87c6-4vv3-cm22/GHSA-87c6-4vv3-cm22.json index ab3ac6d92f8..1c69c45aa61 100644 --- a/advisories/unreviewed/2022/04/GHSA-87c6-4vv3-cm22/GHSA-87c6-4vv3-cm22.json +++ b/advisories/unreviewed/2022/04/GHSA-87c6-4vv3-cm22/GHSA-87c6-4vv3-cm22.json @@ -7,12 +7,8 @@ "CVE-2004-1856" ], "details": "devices_update_printer_fw_upload.hts in HP Web JetAdmin 7.5.2546, when no password is set, allows remote attackers to upload arbitrary files to the printer directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-87rp-rxh5-j283/GHSA-87rp-rxh5-j283.json b/advisories/unreviewed/2022/04/GHSA-87rp-rxh5-j283/GHSA-87rp-rxh5-j283.json index d8081595b2a..134aed3ba40 100644 --- a/advisories/unreviewed/2022/04/GHSA-87rp-rxh5-j283/GHSA-87rp-rxh5-j283.json +++ b/advisories/unreviewed/2022/04/GHSA-87rp-rxh5-j283/GHSA-87rp-rxh5-j283.json @@ -7,12 +7,8 @@ "CVE-2004-1827" ], "details": "Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-88q5-vfrx-jp8m/GHSA-88q5-vfrx-jp8m.json b/advisories/unreviewed/2022/04/GHSA-88q5-vfrx-jp8m/GHSA-88q5-vfrx-jp8m.json index ab1de7e2ba2..f83846acc3f 100644 --- a/advisories/unreviewed/2022/04/GHSA-88q5-vfrx-jp8m/GHSA-88q5-vfrx-jp8m.json +++ b/advisories/unreviewed/2022/04/GHSA-88q5-vfrx-jp8m/GHSA-88q5-vfrx-jp8m.json @@ -7,12 +7,8 @@ "CVE-2004-1785" ], "details": "SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-893j-2hgr-w7r4/GHSA-893j-2hgr-w7r4.json b/advisories/unreviewed/2022/04/GHSA-893j-2hgr-w7r4/GHSA-893j-2hgr-w7r4.json index 97a30878380..29e4feeb11c 100644 --- a/advisories/unreviewed/2022/04/GHSA-893j-2hgr-w7r4/GHSA-893j-2hgr-w7r4.json +++ b/advisories/unreviewed/2022/04/GHSA-893j-2hgr-w7r4/GHSA-893j-2hgr-w7r4.json @@ -7,12 +7,8 @@ "CVE-2004-1828" ], "details": "Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and delete database tables via a direct request to uninstall.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-89g8-gv25-m886/GHSA-89g8-gv25-m886.json b/advisories/unreviewed/2022/04/GHSA-89g8-gv25-m886/GHSA-89g8-gv25-m886.json index 68f5da576f5..d793841e623 100644 --- a/advisories/unreviewed/2022/04/GHSA-89g8-gv25-m886/GHSA-89g8-gv25-m886.json +++ b/advisories/unreviewed/2022/04/GHSA-89g8-gv25-m886/GHSA-89g8-gv25-m886.json @@ -7,12 +7,8 @@ "CVE-2004-1979" ], "details": "Cross-site scripting (XSS) vulnerability in do_search.php in PROPS 0.6.1 allows remote attackers to inject arbitrary HTML or web script via the search_string parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8c59-r54h-654w/GHSA-8c59-r54h-654w.json b/advisories/unreviewed/2022/04/GHSA-8c59-r54h-654w/GHSA-8c59-r54h-654w.json index e3fcd239772..4bd985a2ed0 100644 --- a/advisories/unreviewed/2022/04/GHSA-8c59-r54h-654w/GHSA-8c59-r54h-654w.json +++ b/advisories/unreviewed/2022/04/GHSA-8c59-r54h-654w/GHSA-8c59-r54h-654w.json @@ -7,12 +7,8 @@ "CVE-2004-1990" ], "details": "Aldo's Web Server (aweb) 1.5 allows remote attackers to gain sensitive information via an arbitrary character, which reveals the full path and the user running the aweb process, possibly due to a malformed request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8cc7-483c-fvf3/GHSA-8cc7-483c-fvf3.json b/advisories/unreviewed/2022/04/GHSA-8cc7-483c-fvf3/GHSA-8cc7-483c-fvf3.json index 5f1d36146fe..ac5513efc20 100644 --- a/advisories/unreviewed/2022/04/GHSA-8cc7-483c-fvf3/GHSA-8cc7-483c-fvf3.json +++ b/advisories/unreviewed/2022/04/GHSA-8cc7-483c-fvf3/GHSA-8cc7-483c-fvf3.json @@ -7,12 +7,8 @@ "CVE-2004-1776" ], "details": "Cisco IOS 12.1(3) and 12.1(3)T allows remote attackers to read and modify device configuration data via the cable-docsis read-write community string used by the Data Over Cable Service Interface Specification (DOCSIS) standard.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8cr8-qjq3-88h7/GHSA-8cr8-qjq3-88h7.json b/advisories/unreviewed/2022/04/GHSA-8cr8-qjq3-88h7/GHSA-8cr8-qjq3-88h7.json index 3d305319afb..13af743afea 100644 --- a/advisories/unreviewed/2022/04/GHSA-8cr8-qjq3-88h7/GHSA-8cr8-qjq3-88h7.json +++ b/advisories/unreviewed/2022/04/GHSA-8cr8-qjq3-88h7/GHSA-8cr8-qjq3-88h7.json @@ -7,12 +7,8 @@ "CVE-2004-1943" ], "details": "PHP remote file inclusion vulnerability in album_portal.php in phpBB modified by Przemo 1.8 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8ghf-v9f7-25jp/GHSA-8ghf-v9f7-25jp.json b/advisories/unreviewed/2022/04/GHSA-8ghf-v9f7-25jp/GHSA-8ghf-v9f7-25jp.json index 026ec4b9022..734c0933009 100644 --- a/advisories/unreviewed/2022/04/GHSA-8ghf-v9f7-25jp/GHSA-8ghf-v9f7-25jp.json +++ b/advisories/unreviewed/2022/04/GHSA-8ghf-v9f7-25jp/GHSA-8ghf-v9f7-25jp.json @@ -7,12 +7,8 @@ "CVE-2004-2014" ], "details": "Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8j9v-36fc-2cr6/GHSA-8j9v-36fc-2cr6.json b/advisories/unreviewed/2022/04/GHSA-8j9v-36fc-2cr6/GHSA-8j9v-36fc-2cr6.json index 46d656618d4..ddc24fb26e0 100644 --- a/advisories/unreviewed/2022/04/GHSA-8j9v-36fc-2cr6/GHSA-8j9v-36fc-2cr6.json +++ b/advisories/unreviewed/2022/04/GHSA-8j9v-36fc-2cr6/GHSA-8j9v-36fc-2cr6.json @@ -7,12 +7,8 @@ "CVE-2004-1853" ], "details": "Buffer overflow in Terminator 3: War of the Machines 1.0 allows remote attackers to cause a denial of service via a long ServerInfo variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8mvh-8fhc-49qf/GHSA-8mvh-8fhc-49qf.json b/advisories/unreviewed/2022/04/GHSA-8mvh-8fhc-49qf/GHSA-8mvh-8fhc-49qf.json index cb09b0dc2cc..e66f07dc304 100644 --- a/advisories/unreviewed/2022/04/GHSA-8mvh-8fhc-49qf/GHSA-8mvh-8fhc-49qf.json +++ b/advisories/unreviewed/2022/04/GHSA-8mvh-8fhc-49qf/GHSA-8mvh-8fhc-49qf.json @@ -7,12 +7,8 @@ "CVE-2004-1983" ], "details": "The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local users to cause a denial of service (infinite loop) via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8xcx-prh3-fqx7/GHSA-8xcx-prh3-fqx7.json b/advisories/unreviewed/2022/04/GHSA-8xcx-prh3-fqx7/GHSA-8xcx-prh3-fqx7.json index 200f8ba4821..488cd79ca58 100644 --- a/advisories/unreviewed/2022/04/GHSA-8xcx-prh3-fqx7/GHSA-8xcx-prh3-fqx7.json +++ b/advisories/unreviewed/2022/04/GHSA-8xcx-prh3-fqx7/GHSA-8xcx-prh3-fqx7.json @@ -7,12 +7,8 @@ "CVE-2004-1924" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via via the (1) theme parameter to tiki-switch_theme.php, (2) find and priority parameters to messu-mailbox.php, (3) flag, priority, flagval, sort_mode, or find parameters to messu-read.php, (4) articleId parameter to tiki-read_article.php, (5) parentId parameter to tiki-browse_categories.php, (6) comments_threshold parameter to tiki-index.php (7) articleId parameter to tiki-print_article.php, (8) galleryId parameter to tiki-list_file_gallery.php, (9) galleryId parameter to tiki-upload_file.php, (10) faqId parameter to tiki-view_faq.php, (11) chartId parameter to tiki-view_chart.php, or (12) surveyId parameter to tiki-survey_stats_survey.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-92x5-mpvj-69wx/GHSA-92x5-mpvj-69wx.json b/advisories/unreviewed/2022/04/GHSA-92x5-mpvj-69wx/GHSA-92x5-mpvj-69wx.json index a884d0c18e3..99ac1056718 100644 --- a/advisories/unreviewed/2022/04/GHSA-92x5-mpvj-69wx/GHSA-92x5-mpvj-69wx.json +++ b/advisories/unreviewed/2022/04/GHSA-92x5-mpvj-69wx/GHSA-92x5-mpvj-69wx.json @@ -7,12 +7,8 @@ "CVE-2004-2023" ], "details": "SQL injection vulnerability in login.php in Zen Cart 1.1.2d, 1.1.4 before patch 1, and possibly other versions allows remote attackers to execute arbitrary SQL via the (1) admin_name or (2) admin_pass parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-95rg-xv64-v2pm/GHSA-95rg-xv64-v2pm.json b/advisories/unreviewed/2022/04/GHSA-95rg-xv64-v2pm/GHSA-95rg-xv64-v2pm.json index ba36ecf2e3f..08a8711552a 100644 --- a/advisories/unreviewed/2022/04/GHSA-95rg-xv64-v2pm/GHSA-95rg-xv64-v2pm.json +++ b/advisories/unreviewed/2022/04/GHSA-95rg-xv64-v2pm/GHSA-95rg-xv64-v2pm.json @@ -7,12 +7,8 @@ "CVE-2004-1775" ], "details": "Cisco VACM (View-based Access Control MIB) for Catalyst Operating Software (CatOS) 5.5 and 6.1 and IOS 12.0 and 12.1 allows remote attackers to read and modify device configuration via the read-write community string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-99hm-6xmx-37cp/GHSA-99hm-6xmx-37cp.json b/advisories/unreviewed/2022/04/GHSA-99hm-6xmx-37cp/GHSA-99hm-6xmx-37cp.json index 7a5604a8624..41fde27f46a 100644 --- a/advisories/unreviewed/2022/04/GHSA-99hm-6xmx-37cp/GHSA-99hm-6xmx-37cp.json +++ b/advisories/unreviewed/2022/04/GHSA-99hm-6xmx-37cp/GHSA-99hm-6xmx-37cp.json @@ -7,12 +7,8 @@ "CVE-2004-1866" ], "details": "nstxd in Nstx 1.1 beta3 and earlier allows remote attackers to cause a denial of service (crash) via a large packet, which triggers a null dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9crw-h8v9-v2xf/GHSA-9crw-h8v9-v2xf.json b/advisories/unreviewed/2022/04/GHSA-9crw-h8v9-v2xf/GHSA-9crw-h8v9-v2xf.json index 7a07e6d9718..8a39be2dfcd 100644 --- a/advisories/unreviewed/2022/04/GHSA-9crw-h8v9-v2xf/GHSA-9crw-h8v9-v2xf.json +++ b/advisories/unreviewed/2022/04/GHSA-9crw-h8v9-v2xf/GHSA-9crw-h8v9-v2xf.json @@ -7,12 +7,8 @@ "CVE-2004-1999" ], "details": "Cross-site scripting (XSS) vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to inject arbitrary HTML and web script via the (1) ttitle or (2) sid parameters to modules.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9f2r-cmgr-mc4g/GHSA-9f2r-cmgr-mc4g.json b/advisories/unreviewed/2022/04/GHSA-9f2r-cmgr-mc4g/GHSA-9f2r-cmgr-mc4g.json index b1599815bf7..e04684382a4 100644 --- a/advisories/unreviewed/2022/04/GHSA-9f2r-cmgr-mc4g/GHSA-9f2r-cmgr-mc4g.json +++ b/advisories/unreviewed/2022/04/GHSA-9f2r-cmgr-mc4g/GHSA-9f2r-cmgr-mc4g.json @@ -7,12 +7,8 @@ "CVE-2004-1794" ], "details": "Cross-site scripting (XSS) vulnerability in the VCard4J Toolkit allows remote attackers to inject arbitrary web script or HTML via the NICKNAME tag in a vCard.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9hf7-q79j-g253/GHSA-9hf7-q79j-g253.json b/advisories/unreviewed/2022/04/GHSA-9hf7-q79j-g253/GHSA-9hf7-q79j-g253.json index 53e203ee3c4..5568eadb6e0 100644 --- a/advisories/unreviewed/2022/04/GHSA-9hf7-q79j-g253/GHSA-9hf7-q79j-g253.json +++ b/advisories/unreviewed/2022/04/GHSA-9hf7-q79j-g253/GHSA-9hf7-q79j-g253.json @@ -7,12 +7,8 @@ "CVE-2004-1942" ], "details": "The Solaris 9 patches 113579-02 through 113579-05, and 114342-02 through 114342-05, prevent ypserv and ypxfrd from properly restricting access to secure NIS maps, which allows local users to use ypcat or ypmatch to extract the contents of a secure map such as passwd.adjunct.byname.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9j26-f84r-gm28/GHSA-9j26-f84r-gm28.json b/advisories/unreviewed/2022/04/GHSA-9j26-f84r-gm28/GHSA-9j26-f84r-gm28.json index f9b09efd5eb..25cda909330 100644 --- a/advisories/unreviewed/2022/04/GHSA-9j26-f84r-gm28/GHSA-9j26-f84r-gm28.json +++ b/advisories/unreviewed/2022/04/GHSA-9j26-f84r-gm28/GHSA-9j26-f84r-gm28.json @@ -7,12 +7,8 @@ "CVE-2004-1855" ], "details": "Dark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers to gain sensitive information via a man-in-the-middle attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9ph8-9pf4-4m34/GHSA-9ph8-9pf4-4m34.json b/advisories/unreviewed/2022/04/GHSA-9ph8-9pf4-4m34/GHSA-9ph8-9pf4-4m34.json index 066dea1095c..8ee5d5b2816 100644 --- a/advisories/unreviewed/2022/04/GHSA-9ph8-9pf4-4m34/GHSA-9ph8-9pf4-4m34.json +++ b/advisories/unreviewed/2022/04/GHSA-9ph8-9pf4-4m34/GHSA-9ph8-9pf4-4m34.json @@ -7,12 +7,8 @@ "CVE-2004-1957" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web script or HTML via the (1) lid and query parameters to the Downloads module, (2) query parameter to the Web_links module, or (3) hlpfile parameter to openwindow.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9qm2-fjxr-j5rh/GHSA-9qm2-fjxr-j5rh.json b/advisories/unreviewed/2022/04/GHSA-9qm2-fjxr-j5rh/GHSA-9qm2-fjxr-j5rh.json index 25643a6bd59..addabdaa89a 100644 --- a/advisories/unreviewed/2022/04/GHSA-9qm2-fjxr-j5rh/GHSA-9qm2-fjxr-j5rh.json +++ b/advisories/unreviewed/2022/04/GHSA-9qm2-fjxr-j5rh/GHSA-9qm2-fjxr-j5rh.json @@ -7,12 +7,8 @@ "CVE-2004-1771" ], "details": "Scalable OGo (SOGo) 1.0 allows remote authenticated users to bypass intended permissions and view private appointments of other users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9vg5-q5qw-72m8/GHSA-9vg5-q5qw-72m8.json b/advisories/unreviewed/2022/04/GHSA-9vg5-q5qw-72m8/GHSA-9vg5-q5qw-72m8.json index 488a4646353..3884d9e6784 100644 --- a/advisories/unreviewed/2022/04/GHSA-9vg5-q5qw-72m8/GHSA-9vg5-q5qw-72m8.json +++ b/advisories/unreviewed/2022/04/GHSA-9vg5-q5qw-72m8/GHSA-9vg5-q5qw-72m8.json @@ -7,12 +7,8 @@ "CVE-2004-1833" ], "details": "The admin.ib file in Borland Interbase 7.1 for Linux has default world writable permissions, which allows local users to gain database administrative privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9vp2-wg6r-vp74/GHSA-9vp2-wg6r-vp74.json b/advisories/unreviewed/2022/04/GHSA-9vp2-wg6r-vp74/GHSA-9vp2-wg6r-vp74.json index bbc5d6d2882..665eb1f038d 100644 --- a/advisories/unreviewed/2022/04/GHSA-9vp2-wg6r-vp74/GHSA-9vp2-wg6r-vp74.json +++ b/advisories/unreviewed/2022/04/GHSA-9vp2-wg6r-vp74/GHSA-9vp2-wg6r-vp74.json @@ -7,12 +7,8 @@ "CVE-2004-1873" ], "details": "SQL injection vulnerability in category.asp in A-CART Pro and A-CART 2.0 allows remote attackers to gain privileges via the catcode parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9w3c-r5g2-8r8h/GHSA-9w3c-r5g2-8r8h.json b/advisories/unreviewed/2022/04/GHSA-9w3c-r5g2-8r8h/GHSA-9w3c-r5g2-8r8h.json index e2810704610..e80c7cf0826 100644 --- a/advisories/unreviewed/2022/04/GHSA-9w3c-r5g2-8r8h/GHSA-9w3c-r5g2-8r8h.json +++ b/advisories/unreviewed/2022/04/GHSA-9w3c-r5g2-8r8h/GHSA-9w3c-r5g2-8r8h.json @@ -7,12 +7,8 @@ "CVE-2004-1944" ], "details": "Eudora 6.1 and 6.0.3 for Windows allows remote attackers to cause a denial of service (crash) via a deeply nested multipart MIME message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9ww4-42mh-q457/GHSA-9ww4-42mh-q457.json b/advisories/unreviewed/2022/04/GHSA-9ww4-42mh-q457/GHSA-9ww4-42mh-q457.json index 5bc86f3ac90..4357db73d94 100644 --- a/advisories/unreviewed/2022/04/GHSA-9ww4-42mh-q457/GHSA-9ww4-42mh-q457.json +++ b/advisories/unreviewed/2022/04/GHSA-9ww4-42mh-q457/GHSA-9ww4-42mh-q457.json @@ -7,12 +7,8 @@ "CVE-2004-1948" ], "details": "NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via \"ps aux,\" which displays the URL in the process list.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9x66-8986-f2w2/GHSA-9x66-8986-f2w2.json b/advisories/unreviewed/2022/04/GHSA-9x66-8986-f2w2/GHSA-9x66-8986-f2w2.json index f762259d501..8891296f391 100644 --- a/advisories/unreviewed/2022/04/GHSA-9x66-8986-f2w2/GHSA-9x66-8986-f2w2.json +++ b/advisories/unreviewed/2022/04/GHSA-9x66-8986-f2w2/GHSA-9x66-8986-f2w2.json @@ -7,12 +7,8 @@ "CVE-2004-1947" ], "details": "The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or (2) use the RequestFile method to download and execute arbitrary code via an object codebase that uses bitdefender.cab.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c3rf-282h-rx6r/GHSA-c3rf-282h-rx6r.json b/advisories/unreviewed/2022/04/GHSA-c3rf-282h-rx6r/GHSA-c3rf-282h-rx6r.json index 5d3994d270a..d0a23ad3e1f 100644 --- a/advisories/unreviewed/2022/04/GHSA-c3rf-282h-rx6r/GHSA-c3rf-282h-rx6r.json +++ b/advisories/unreviewed/2022/04/GHSA-c3rf-282h-rx6r/GHSA-c3rf-282h-rx6r.json @@ -7,12 +7,8 @@ "CVE-2004-1973" ], "details": "DiGi Web Server allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request that contains a large number of / (slash) characters, which consumes resources when DiGi converts the slashes to \\ (backslash) characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c5cc-h8q8-m9hw/GHSA-c5cc-h8q8-m9hw.json b/advisories/unreviewed/2022/04/GHSA-c5cc-h8q8-m9hw/GHSA-c5cc-h8q8-m9hw.json index b0c3b43ce3b..f2a7c84ca0f 100644 --- a/advisories/unreviewed/2022/04/GHSA-c5cc-h8q8-m9hw/GHSA-c5cc-h8q8-m9hw.json +++ b/advisories/unreviewed/2022/04/GHSA-c5cc-h8q8-m9hw/GHSA-c5cc-h8q8-m9hw.json @@ -7,12 +7,8 @@ "CVE-2004-1860" ], "details": "Buffer overflow in Check Point SmartDashboard in Check Point NG AI R54 and R55 allows remote authenticated users to cause a denial of service (server disconnect) and possibly execute arbitrary code via a large filter on a column when using SmartView Tracker.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c5g5-jm9m-cwhx/GHSA-c5g5-jm9m-cwhx.json b/advisories/unreviewed/2022/04/GHSA-c5g5-jm9m-cwhx/GHSA-c5g5-jm9m-cwhx.json index ff223a7441f..4e01aa78aed 100644 --- a/advisories/unreviewed/2022/04/GHSA-c5g5-jm9m-cwhx/GHSA-c5g5-jm9m-cwhx.json +++ b/advisories/unreviewed/2022/04/GHSA-c5g5-jm9m-cwhx/GHSA-c5g5-jm9m-cwhx.json @@ -7,12 +7,8 @@ "CVE-2004-1935" ], "details": "Cross-site scripting (XSS) vulnerability in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via onload, onmouseover, and other Javascript events in an e-mail attachment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c6qx-vg4x-8xrp/GHSA-c6qx-vg4x-8xrp.json b/advisories/unreviewed/2022/04/GHSA-c6qx-vg4x-8xrp/GHSA-c6qx-vg4x-8xrp.json index 2fb6b113336..6828e2fa3e2 100644 --- a/advisories/unreviewed/2022/04/GHSA-c6qx-vg4x-8xrp/GHSA-c6qx-vg4x-8xrp.json +++ b/advisories/unreviewed/2022/04/GHSA-c6qx-vg4x-8xrp/GHSA-c6qx-vg4x-8xrp.json @@ -7,12 +7,8 @@ "CVE-2004-1772" ], "details": "Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cjmf-rwpm-q3h6/GHSA-cjmf-rwpm-q3h6.json b/advisories/unreviewed/2022/04/GHSA-cjmf-rwpm-q3h6/GHSA-cjmf-rwpm-q3h6.json index 4ae471f9fb1..be67b8bc179 100644 --- a/advisories/unreviewed/2022/04/GHSA-cjmf-rwpm-q3h6/GHSA-cjmf-rwpm-q3h6.json +++ b/advisories/unreviewed/2022/04/GHSA-cjmf-rwpm-q3h6/GHSA-cjmf-rwpm-q3h6.json @@ -7,12 +7,8 @@ "CVE-2004-1830" ], "details": "error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a PHP error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cmr2-j9xp-h9cf/GHSA-cmr2-j9xp-h9cf.json b/advisories/unreviewed/2022/04/GHSA-cmr2-j9xp-h9cf/GHSA-cmr2-j9xp-h9cf.json index f2af727231f..eb8f1ba7a48 100644 --- a/advisories/unreviewed/2022/04/GHSA-cmr2-j9xp-h9cf/GHSA-cmr2-j9xp-h9cf.json +++ b/advisories/unreviewed/2022/04/GHSA-cmr2-j9xp-h9cf/GHSA-cmr2-j9xp-h9cf.json @@ -7,12 +7,8 @@ "CVE-2004-2010" ], "details": "PHP remote file inclusion vulnerability in index.php in phpShop 0.7.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the base_dir parameter to reference a URL on a remote web server that contains phpshop.cfg.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cr7c-f756-x9p2/GHSA-cr7c-f756-x9p2.json b/advisories/unreviewed/2022/04/GHSA-cr7c-f756-x9p2/GHSA-cr7c-f756-x9p2.json index f7f178db4d8..59eacd52d33 100644 --- a/advisories/unreviewed/2022/04/GHSA-cr7c-f756-x9p2/GHSA-cr7c-f756-x9p2.json +++ b/advisories/unreviewed/2022/04/GHSA-cr7c-f756-x9p2/GHSA-cr7c-f756-x9p2.json @@ -7,12 +7,8 @@ "CVE-2004-1994" ], "details": "FuseTalk 4.0 allows remote attackers to ban other users via a direct request to banning.cfm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-crm6-w28g-73jf/GHSA-crm6-w28g-73jf.json b/advisories/unreviewed/2022/04/GHSA-crm6-w28g-73jf/GHSA-crm6-w28g-73jf.json index 99972886297..eec83744509 100644 --- a/advisories/unreviewed/2022/04/GHSA-crm6-w28g-73jf/GHSA-crm6-w28g-73jf.json +++ b/advisories/unreviewed/2022/04/GHSA-crm6-w28g-73jf/GHSA-crm6-w28g-73jf.json @@ -7,12 +7,8 @@ "CVE-2004-1970" ], "details": "Samsung SmartEther SS6215S switch, and possibly other Samsung switches, allows remote attackers and local users to gain administrative access by providing the admin username followed by a password that is the maximum allowed length, then pressing the enter key after the resulting error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cx7g-jvmq-9xr6/GHSA-cx7g-jvmq-9xr6.json b/advisories/unreviewed/2022/04/GHSA-cx7g-jvmq-9xr6/GHSA-cx7g-jvmq-9xr6.json index f849c541827..b48abe0bbe0 100644 --- a/advisories/unreviewed/2022/04/GHSA-cx7g-jvmq-9xr6/GHSA-cx7g-jvmq-9xr6.json +++ b/advisories/unreviewed/2022/04/GHSA-cx7g-jvmq-9xr6/GHSA-cx7g-jvmq-9xr6.json @@ -7,12 +7,8 @@ "CVE-2004-1815" ], "details": "Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f2fp-44fh-jxwr/GHSA-f2fp-44fh-jxwr.json b/advisories/unreviewed/2022/04/GHSA-f2fp-44fh-jxwr/GHSA-f2fp-44fh-jxwr.json index be9a09aa1d2..10151cc7417 100644 --- a/advisories/unreviewed/2022/04/GHSA-f2fp-44fh-jxwr/GHSA-f2fp-44fh-jxwr.json +++ b/advisories/unreviewed/2022/04/GHSA-f2fp-44fh-jxwr/GHSA-f2fp-44fh-jxwr.json @@ -7,12 +7,8 @@ "CVE-2004-1826" ], "details": "SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f4q8-xff2-rhrg/GHSA-f4q8-xff2-rhrg.json b/advisories/unreviewed/2022/04/GHSA-f4q8-xff2-rhrg/GHSA-f4q8-xff2-rhrg.json index d53f8c76573..59948bb8322 100644 --- a/advisories/unreviewed/2022/04/GHSA-f4q8-xff2-rhrg/GHSA-f4q8-xff2-rhrg.json +++ b/advisories/unreviewed/2022/04/GHSA-f4q8-xff2-rhrg/GHSA-f4q8-xff2-rhrg.json @@ -7,12 +7,8 @@ "CVE-2004-1949" ], "details": "SQL injection vulnerability in PostNuke 7.2.6 and earlier allows remote attackers to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset parameter to changeinfo.php in the Your_Account module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f58x-3j8w-r6xw/GHSA-f58x-3j8w-r6xw.json b/advisories/unreviewed/2022/04/GHSA-f58x-3j8w-r6xw/GHSA-f58x-3j8w-r6xw.json index 436d4cf7920..77a1bc3efb5 100644 --- a/advisories/unreviewed/2022/04/GHSA-f58x-3j8w-r6xw/GHSA-f58x-3j8w-r6xw.json +++ b/advisories/unreviewed/2022/04/GHSA-f58x-3j8w-r6xw/GHSA-f58x-3j8w-r6xw.json @@ -7,12 +7,8 @@ "CVE-2004-2032" ], "details": "Netgear RP114 allows remote attackers to bypass the keyword based URL filtering by requesting a long URL, as demonstrated using a large number of %20 (hex-encoded space) sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f6rh-p7gj-vxrw/GHSA-f6rh-p7gj-vxrw.json b/advisories/unreviewed/2022/04/GHSA-f6rh-p7gj-vxrw/GHSA-f6rh-p7gj-vxrw.json index ca2715c50af..eb9290e61d2 100644 --- a/advisories/unreviewed/2022/04/GHSA-f6rh-p7gj-vxrw/GHSA-f6rh-p7gj-vxrw.json +++ b/advisories/unreviewed/2022/04/GHSA-f6rh-p7gj-vxrw/GHSA-f6rh-p7gj-vxrw.json @@ -7,12 +7,8 @@ "CVE-2004-2015" ], "details": "Cross-site scripting (XSS) vulnerability in WebCT Campus Edition allows remote attackers to inject arbitrary HTML or web script via (1) iframe, (2) img, or (3) object tags.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fj6h-66gp-9xqf/GHSA-fj6h-66gp-9xqf.json b/advisories/unreviewed/2022/04/GHSA-fj6h-66gp-9xqf/GHSA-fj6h-66gp-9xqf.json index 1ccad98ec96..99b3539d61a 100644 --- a/advisories/unreviewed/2022/04/GHSA-fj6h-66gp-9xqf/GHSA-fj6h-66gp-9xqf.json +++ b/advisories/unreviewed/2022/04/GHSA-fj6h-66gp-9xqf/GHSA-fj6h-66gp-9xqf.json @@ -7,12 +7,8 @@ "CVE-2004-1767" ], "details": "The kernel in Solaris 2.6, 7, 8, and 9 allows local users to gain privileges by loading arbitrary loadable kernel modules (LKM), possibly involving the modload function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fmxw-v7gw-cqpg/GHSA-fmxw-v7gw-cqpg.json b/advisories/unreviewed/2022/04/GHSA-fmxw-v7gw-cqpg/GHSA-fmxw-v7gw-cqpg.json index 5e624a3daf9..239eacf4191 100644 --- a/advisories/unreviewed/2022/04/GHSA-fmxw-v7gw-cqpg/GHSA-fmxw-v7gw-cqpg.json +++ b/advisories/unreviewed/2022/04/GHSA-fmxw-v7gw-cqpg/GHSA-fmxw-v7gw-cqpg.json @@ -7,12 +7,8 @@ "CVE-2004-1911" ], "details": "Cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) l parameter (aka language variable) to index.php or (2) id parameter to view.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fpfg-rp56-r3cr/GHSA-fpfg-rp56-r3cr.json b/advisories/unreviewed/2022/04/GHSA-fpfg-rp56-r3cr/GHSA-fpfg-rp56-r3cr.json index 988fe114cea..0a325403cd4 100644 --- a/advisories/unreviewed/2022/04/GHSA-fpfg-rp56-r3cr/GHSA-fpfg-rp56-r3cr.json +++ b/advisories/unreviewed/2022/04/GHSA-fpfg-rp56-r3cr/GHSA-fpfg-rp56-r3cr.json @@ -7,12 +7,8 @@ "CVE-2004-1997" ], "details": "Kolab stores OpenLDAP passwords in plaintext in the slapd.conf file, which may be installed world-readable, which allows local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fpr6-3h88-qm2h/GHSA-fpr6-3h88-qm2h.json b/advisories/unreviewed/2022/04/GHSA-fpr6-3h88-qm2h/GHSA-fpr6-3h88-qm2h.json index b89b68442f0..6503e7ee1ff 100644 --- a/advisories/unreviewed/2022/04/GHSA-fpr6-3h88-qm2h/GHSA-fpr6-3h88-qm2h.json +++ b/advisories/unreviewed/2022/04/GHSA-fpr6-3h88-qm2h/GHSA-fpr6-3h88-qm2h.json @@ -7,12 +7,8 @@ "CVE-2004-1882" ], "details": "Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or HTML via the strImageTag parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-frvx-gppg-h8rp/GHSA-frvx-gppg-h8rp.json b/advisories/unreviewed/2022/04/GHSA-frvx-gppg-h8rp/GHSA-frvx-gppg-h8rp.json index 4e47a6bad51..75eeb0a1458 100644 --- a/advisories/unreviewed/2022/04/GHSA-frvx-gppg-h8rp/GHSA-frvx-gppg-h8rp.json +++ b/advisories/unreviewed/2022/04/GHSA-frvx-gppg-h8rp/GHSA-frvx-gppg-h8rp.json @@ -7,12 +7,8 @@ "CVE-2004-2003" ], "details": "Buffer overflow in the ssl_prcert function in the SSLway filter (sslway.c) for DeleGate 8.9.2 and earlier allows remote attackers to execute arbitrary code via a certificate with a long (1) subject or (2) issuer name field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fwr5-2f5h-8j4r/GHSA-fwr5-2f5h-8j4r.json b/advisories/unreviewed/2022/04/GHSA-fwr5-2f5h-8j4r/GHSA-fwr5-2f5h-8j4r.json index 199ce871a09..a80cbfb3e60 100644 --- a/advisories/unreviewed/2022/04/GHSA-fwr5-2f5h-8j4r/GHSA-fwr5-2f5h-8j4r.json +++ b/advisories/unreviewed/2022/04/GHSA-fwr5-2f5h-8j4r/GHSA-fwr5-2f5h-8j4r.json @@ -7,12 +7,8 @@ "CVE-2004-1985" ], "details": "Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g3r8-r8px-gp93/GHSA-g3r8-r8px-gp93.json b/advisories/unreviewed/2022/04/GHSA-g3r8-r8px-gp93/GHSA-g3r8-r8px-gp93.json index 70469500a0d..ae1c6106181 100644 --- a/advisories/unreviewed/2022/04/GHSA-g3r8-r8px-gp93/GHSA-g3r8-r8px-gp93.json +++ b/advisories/unreviewed/2022/04/GHSA-g3r8-r8px-gp93/GHSA-g3r8-r8px-gp93.json @@ -7,12 +7,8 @@ "CVE-2004-1900" ], "details": "Format string vulnerability in the logging function in IGI 2 Covert Strike server 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in RCON commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g46x-3r99-9fh4/GHSA-g46x-3r99-9fh4.json b/advisories/unreviewed/2022/04/GHSA-g46x-3r99-9fh4/GHSA-g46x-3r99-9fh4.json index 70e1f733120..412028ce720 100644 --- a/advisories/unreviewed/2022/04/GHSA-g46x-3r99-9fh4/GHSA-g46x-3r99-9fh4.json +++ b/advisories/unreviewed/2022/04/GHSA-g46x-3r99-9fh4/GHSA-g46x-3r99-9fh4.json @@ -7,12 +7,8 @@ "CVE-2004-1831" ], "details": "Buffer overflow in Chrome 1.2.0.0 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large length value, which leads to a null dereference or out-of-bounds read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g6r8-pjqh-f6qg/GHSA-g6r8-pjqh-f6qg.json b/advisories/unreviewed/2022/04/GHSA-g6r8-pjqh-f6qg/GHSA-g6r8-pjqh-f6qg.json index d321557a5a0..739985ca672 100644 --- a/advisories/unreviewed/2022/04/GHSA-g6r8-pjqh-f6qg/GHSA-g6r8-pjqh-f6qg.json +++ b/advisories/unreviewed/2022/04/GHSA-g6r8-pjqh-f6qg/GHSA-g6r8-pjqh-f6qg.json @@ -7,12 +7,8 @@ "CVE-2004-2031" ], "details": "Cross-site scripting (XSS) vulnerability in user.php in e107 allows remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) MSN, or (3) AIM fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g7fw-pf32-gw4g/GHSA-g7fw-pf32-gw4g.json b/advisories/unreviewed/2022/04/GHSA-g7fw-pf32-gw4g/GHSA-g7fw-pf32-gw4g.json index 750a792dddb..0444832c29d 100644 --- a/advisories/unreviewed/2022/04/GHSA-g7fw-pf32-gw4g/GHSA-g7fw-pf32-gw4g.json +++ b/advisories/unreviewed/2022/04/GHSA-g7fw-pf32-gw4g/GHSA-g7fw-pf32-gw4g.json @@ -7,12 +7,8 @@ "CVE-2004-1763" ], "details": "Buffer overflow in hsrun.exe for HAHTsite Scenario Server 5.1 Patch 06 (build 91) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long project name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g85p-2pm2-pfr5/GHSA-g85p-2pm2-pfr5.json b/advisories/unreviewed/2022/04/GHSA-g85p-2pm2-pfr5/GHSA-g85p-2pm2-pfr5.json index 91229e65f21..9afa362231e 100644 --- a/advisories/unreviewed/2022/04/GHSA-g85p-2pm2-pfr5/GHSA-g85p-2pm2-pfr5.json +++ b/advisories/unreviewed/2022/04/GHSA-g85p-2pm2-pfr5/GHSA-g85p-2pm2-pfr5.json @@ -7,12 +7,8 @@ "CVE-2004-1993" ], "details": "The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as \"`\" (backticks) in the password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g9ww-rwpm-5j7q/GHSA-g9ww-rwpm-5j7q.json b/advisories/unreviewed/2022/04/GHSA-g9ww-rwpm-5j7q/GHSA-g9ww-rwpm-5j7q.json index 4729ee12d57..adfec9a2665 100644 --- a/advisories/unreviewed/2022/04/GHSA-g9ww-rwpm-5j7q/GHSA-g9ww-rwpm-5j7q.json +++ b/advisories/unreviewed/2022/04/GHSA-g9ww-rwpm-5j7q/GHSA-g9ww-rwpm-5j7q.json @@ -7,12 +7,8 @@ "CVE-2004-1819" ], "details": "4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to obtain sensitive information via a direct request to displaycategory.php, which reveals the path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gc27-423v-4x5r/GHSA-gc27-423v-4x5r.json b/advisories/unreviewed/2022/04/GHSA-gc27-423v-4x5r/GHSA-gc27-423v-4x5r.json index ffebd89d20d..d47c6099fc5 100644 --- a/advisories/unreviewed/2022/04/GHSA-gc27-423v-4x5r/GHSA-gc27-423v-4x5r.json +++ b/advisories/unreviewed/2022/04/GHSA-gc27-423v-4x5r/GHSA-gc27-423v-4x5r.json @@ -7,12 +7,8 @@ "CVE-2004-1946" ], "details": "Format string vulnerability in the PRINT_ERROR function in common.c for Cherokee Web Server 0.4.16 and earlier allows local users to execute arbitrary code via format string specifiers in the -C command line argument. NOTE: it is not clear whether this issue could be exploited remotely, or if Cherokee is running at escalated privileges. Therefore it might not be a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gc9v-mv77-jhqh/GHSA-gc9v-mv77-jhqh.json b/advisories/unreviewed/2022/04/GHSA-gc9v-mv77-jhqh/GHSA-gc9v-mv77-jhqh.json index f6c6689a0e3..d4ee9a12c4d 100644 --- a/advisories/unreviewed/2022/04/GHSA-gc9v-mv77-jhqh/GHSA-gc9v-mv77-jhqh.json +++ b/advisories/unreviewed/2022/04/GHSA-gc9v-mv77-jhqh/GHSA-gc9v-mv77-jhqh.json @@ -7,12 +7,8 @@ "CVE-2004-1822" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_REFERER parameter to login.php, (2) HTTP_REFERER parameter to register.php, or (3) target parameter to profile.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gcww-jc8g-fgxc/GHSA-gcww-jc8g-fgxc.json b/advisories/unreviewed/2022/04/GHSA-gcww-jc8g-fgxc/GHSA-gcww-jc8g-fgxc.json index 6bafa60e964..528f02c6661 100644 --- a/advisories/unreviewed/2022/04/GHSA-gcww-jc8g-fgxc/GHSA-gcww-jc8g-fgxc.json +++ b/advisories/unreviewed/2022/04/GHSA-gcww-jc8g-fgxc/GHSA-gcww-jc8g-fgxc.json @@ -7,12 +7,8 @@ "CVE-2004-1941" ], "details": "Fastream NETFile FTP/Web Server 6.5.1.980 allows remote attackers to cause a denial of service via a username that does not exist.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gfwq-jqh8-jp6j/GHSA-gfwq-jqh8-jp6j.json b/advisories/unreviewed/2022/04/GHSA-gfwq-jqh8-jp6j/GHSA-gfwq-jqh8-jp6j.json index dc227ef386a..94ef6619cf2 100644 --- a/advisories/unreviewed/2022/04/GHSA-gfwq-jqh8-jp6j/GHSA-gfwq-jqh8-jp6j.json +++ b/advisories/unreviewed/2022/04/GHSA-gfwq-jqh8-jp6j/GHSA-gfwq-jqh8-jp6j.json @@ -7,12 +7,8 @@ "CVE-2004-1966" ], "details": "Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) FID parameter in board.php, (2) sortorder, perpage, or id parameters in member.php, (3) forums parameter in search.php, or (4) PID or FID parameters in post.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gj3q-v8c3-5gh4/GHSA-gj3q-v8c3-5gh4.json b/advisories/unreviewed/2022/04/GHSA-gj3q-v8c3-5gh4/GHSA-gj3q-v8c3-5gh4.json index 44be82d1cb8..06a45d65d12 100644 --- a/advisories/unreviewed/2022/04/GHSA-gj3q-v8c3-5gh4/GHSA-gj3q-v8c3-5gh4.json +++ b/advisories/unreviewed/2022/04/GHSA-gj3q-v8c3-5gh4/GHSA-gj3q-v8c3-5gh4.json @@ -7,12 +7,8 @@ "CVE-2004-1906" ], "details": "Mcafee FreeScan allows remote attackers to cause a denial of service and possibly arbitrary code via a long string in the ScanParam property of a COM object, which may trigger a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gj45-c86v-23w5/GHSA-gj45-c86v-23w5.json b/advisories/unreviewed/2022/04/GHSA-gj45-c86v-23w5/GHSA-gj45-c86v-23w5.json index 57fa644a754..92e5ce4340a 100644 --- a/advisories/unreviewed/2022/04/GHSA-gj45-c86v-23w5/GHSA-gj45-c86v-23w5.json +++ b/advisories/unreviewed/2022/04/GHSA-gj45-c86v-23w5/GHSA-gj45-c86v-23w5.json @@ -7,12 +7,8 @@ "CVE-2004-2017" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Turbo Traffic Trader C (TTT-C) 1.0 allow remote attackers to inject arbitrary HTML or web script, as demonstrated via (1) the link parameter to ttt-out, (2) the X-Forwarded-For header in a GET request to ttt-in, (3) the Referer header in a GET request to ttt-in, or the (4) site name or (5) site URL fields in the main control panel.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gjf8-wr7v-8jg5/GHSA-gjf8-wr7v-8jg5.json b/advisories/unreviewed/2022/04/GHSA-gjf8-wr7v-8jg5/GHSA-gjf8-wr7v-8jg5.json index 79a5221f0d6..82afa6437f3 100644 --- a/advisories/unreviewed/2022/04/GHSA-gjf8-wr7v-8jg5/GHSA-gjf8-wr7v-8jg5.json +++ b/advisories/unreviewed/2022/04/GHSA-gjf8-wr7v-8jg5/GHSA-gjf8-wr7v-8jg5.json @@ -7,12 +7,8 @@ "CVE-2004-1837" ], "details": "Cross-site scripting (XSS) vulnerability in Mod_survey 3.0.x before 3.0.16-pre2 and 3.2.x before 3.2.0-pre4 allows remote attackers to inject arbitrary web script or HTML via the certain survey fields or error messages for malformed query strings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gmc2-7xvp-vj74/GHSA-gmc2-7xvp-vj74.json b/advisories/unreviewed/2022/04/GHSA-gmc2-7xvp-vj74/GHSA-gmc2-7xvp-vj74.json index 027e7b460fa..41ccfd208a5 100644 --- a/advisories/unreviewed/2022/04/GHSA-gmc2-7xvp-vj74/GHSA-gmc2-7xvp-vj74.json +++ b/advisories/unreviewed/2022/04/GHSA-gmc2-7xvp-vj74/GHSA-gmc2-7xvp-vj74.json @@ -7,12 +7,8 @@ "CVE-2004-1770" ], "details": "The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gmq2-ghgg-g3f9/GHSA-gmq2-ghgg-g3f9.json b/advisories/unreviewed/2022/04/GHSA-gmq2-ghgg-g3f9/GHSA-gmq2-ghgg-g3f9.json index 4b5451cbaff..db7eed3d82f 100644 --- a/advisories/unreviewed/2022/04/GHSA-gmq2-ghgg-g3f9/GHSA-gmq2-ghgg-g3f9.json +++ b/advisories/unreviewed/2022/04/GHSA-gmq2-ghgg-g3f9/GHSA-gmq2-ghgg-g3f9.json @@ -7,12 +7,8 @@ "CVE-2004-1868" ], "details": "Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-grgp-hrrx-jxvp/GHSA-grgp-hrrx-jxvp.json b/advisories/unreviewed/2022/04/GHSA-grgp-hrrx-jxvp/GHSA-grgp-hrrx-jxvp.json index 4d61bacc974..91eaa420d14 100644 --- a/advisories/unreviewed/2022/04/GHSA-grgp-hrrx-jxvp/GHSA-grgp-hrrx-jxvp.json +++ b/advisories/unreviewed/2022/04/GHSA-grgp-hrrx-jxvp/GHSA-grgp-hrrx-jxvp.json @@ -7,12 +7,8 @@ "CVE-2004-2043" ], "details": "Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows remote attackers to cause a denial of service (crash) via a long database name, as demonstrated using the gsec command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gvxm-8hj2-h5gw/GHSA-gvxm-8hj2-h5gw.json b/advisories/unreviewed/2022/04/GHSA-gvxm-8hj2-h5gw/GHSA-gvxm-8hj2-h5gw.json index 6c1563847c7..41f79f42cda 100644 --- a/advisories/unreviewed/2022/04/GHSA-gvxm-8hj2-h5gw/GHSA-gvxm-8hj2-h5gw.json +++ b/advisories/unreviewed/2022/04/GHSA-gvxm-8hj2-h5gw/GHSA-gvxm-8hj2-h5gw.json @@ -7,12 +7,8 @@ "CVE-2004-1954" ], "details": "Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML via the jcode parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gw25-cpw2-g3m4/GHSA-gw25-cpw2-g3m4.json b/advisories/unreviewed/2022/04/GHSA-gw25-cpw2-g3m4/GHSA-gw25-cpw2-g3m4.json index 8a38851eb68..4c9ad2169b4 100644 --- a/advisories/unreviewed/2022/04/GHSA-gw25-cpw2-g3m4/GHSA-gw25-cpw2-g3m4.json +++ b/advisories/unreviewed/2022/04/GHSA-gw25-cpw2-g3m4/GHSA-gw25-cpw2-g3m4.json @@ -7,12 +7,8 @@ "CVE-2004-1991" ], "details": "Directory traversal vulnerability in Aldo's Web Server (aweb) 1.5 allows remote attackers to view arbitrary files via a .. (dot dot) in an HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-gxh9-45xm-vm79/GHSA-gxh9-45xm-vm79.json b/advisories/unreviewed/2022/04/GHSA-gxh9-45xm-vm79/GHSA-gxh9-45xm-vm79.json index cc985010dbe..0dbe6561319 100644 --- a/advisories/unreviewed/2022/04/GHSA-gxh9-45xm-vm79/GHSA-gxh9-45xm-vm79.json +++ b/advisories/unreviewed/2022/04/GHSA-gxh9-45xm-vm79/GHSA-gxh9-45xm-vm79.json @@ -7,12 +7,8 @@ "CVE-2004-2029" ], "details": "The Util_DecodeHTTPAuth function in BNBT BitTorrent Tracker Beta 7.5 Release 2 and earlier allows remote attackers to cause a denial of service (crash) via a Basic Authorization HTTP request with a \"A==\" value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h6w5-28r7-83h5/GHSA-h6w5-28r7-83h5.json b/advisories/unreviewed/2022/04/GHSA-h6w5-28r7-83h5/GHSA-h6w5-28r7-83h5.json index aedf7f05c0a..3e757e166e7 100644 --- a/advisories/unreviewed/2022/04/GHSA-h6w5-28r7-83h5/GHSA-h6w5-28r7-83h5.json +++ b/advisories/unreviewed/2022/04/GHSA-h6w5-28r7-83h5/GHSA-h6w5-28r7-83h5.json @@ -7,12 +7,8 @@ "CVE-2004-1850" ], "details": "The Rage 1.01 and earlier allows remote attackers to cause a denial of service (infinite loop) via a TCP packet with the port and IP address set to zero.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h7cq-crvr-6j7q/GHSA-h7cq-crvr-6j7q.json b/advisories/unreviewed/2022/04/GHSA-h7cq-crvr-6j7q/GHSA-h7cq-crvr-6j7q.json index d12053db180..17d7ab8480e 100644 --- a/advisories/unreviewed/2022/04/GHSA-h7cq-crvr-6j7q/GHSA-h7cq-crvr-6j7q.json +++ b/advisories/unreviewed/2022/04/GHSA-h7cq-crvr-6j7q/GHSA-h7cq-crvr-6j7q.json @@ -7,12 +7,8 @@ "CVE-2004-1963" ], "details": "nqt.php in Network Query Tool (NQT) 1.6 allows remote attackers to obtain sensitive information via a string in the portNum parameter, which reveals the full path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h8f5-wx67-5qf2/GHSA-h8f5-wx67-5qf2.json b/advisories/unreviewed/2022/04/GHSA-h8f5-wx67-5qf2/GHSA-h8f5-wx67-5qf2.json index 010a3c0a9f5..b60475bd2f2 100644 --- a/advisories/unreviewed/2022/04/GHSA-h8f5-wx67-5qf2/GHSA-h8f5-wx67-5qf2.json +++ b/advisories/unreviewed/2022/04/GHSA-h8f5-wx67-5qf2/GHSA-h8f5-wx67-5qf2.json @@ -7,12 +7,8 @@ "CVE-2004-1921" ], "details": "X-Micro WLAN 11b Broadband Router 1.6.0.1 has a hardcoded \"1502\" username and password, which could allow remote attackers to gain access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h8qw-6f8v-jxp2/GHSA-h8qw-6f8v-jxp2.json b/advisories/unreviewed/2022/04/GHSA-h8qw-6f8v-jxp2/GHSA-h8qw-6f8v-jxp2.json index 54188c58b07..e8556203666 100644 --- a/advisories/unreviewed/2022/04/GHSA-h8qw-6f8v-jxp2/GHSA-h8qw-6f8v-jxp2.json +++ b/advisories/unreviewed/2022/04/GHSA-h8qw-6f8v-jxp2/GHSA-h8qw-6f8v-jxp2.json @@ -7,12 +7,8 @@ "CVE-2004-1817" ], "details": "Cross-site scripting (XSS) vulnerability in modules.php in Php-Nuke 7.1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) Your Name field, (2) e-mail field, (3) nicname field, (4) fname parameter, (5) ratenum parameter, or (6) search field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hcq6-q47h-5jff/GHSA-hcq6-q47h-5jff.json b/advisories/unreviewed/2022/04/GHSA-hcq6-q47h-5jff/GHSA-hcq6-q47h-5jff.json index e9588443740..be4ba122072 100644 --- a/advisories/unreviewed/2022/04/GHSA-hcq6-q47h-5jff/GHSA-hcq6-q47h-5jff.json +++ b/advisories/unreviewed/2022/04/GHSA-hcq6-q47h-5jff/GHSA-hcq6-q47h-5jff.json @@ -7,12 +7,8 @@ "CVE-2004-1981" ], "details": "The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting reports without retrieving the associated image files, which are not cleared from the image file folder.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hfvf-24fm-5q52/GHSA-hfvf-24fm-5q52.json b/advisories/unreviewed/2022/04/GHSA-hfvf-24fm-5q52/GHSA-hfvf-24fm-5q52.json index 136d817d04c..ab8197292fb 100644 --- a/advisories/unreviewed/2022/04/GHSA-hfvf-24fm-5q52/GHSA-hfvf-24fm-5q52.json +++ b/advisories/unreviewed/2022/04/GHSA-hfvf-24fm-5q52/GHSA-hfvf-24fm-5q52.json @@ -7,12 +7,8 @@ "CVE-2004-1766" ], "details": "The default installation of NetScreen-Security Manager before Feature Pack 1 does not enable encryption for communication with devices running ScreenOS 5.0, which allows remote attackers to obtain sensitive information via sniffing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hfx8-3wrm-cvm8/GHSA-hfx8-3wrm-cvm8.json b/advisories/unreviewed/2022/04/GHSA-hfx8-3wrm-cvm8/GHSA-hfx8-3wrm-cvm8.json index e807e042592..421dc09e76c 100644 --- a/advisories/unreviewed/2022/04/GHSA-hfx8-3wrm-cvm8/GHSA-hfx8-3wrm-cvm8.json +++ b/advisories/unreviewed/2022/04/GHSA-hfx8-3wrm-cvm8/GHSA-hfx8-3wrm-cvm8.json @@ -7,12 +7,8 @@ "CVE-2004-1774" ], "details": "Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users to execute arbitrary code via a long LAYER parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hjrq-qr8g-2fxf/GHSA-hjrq-qr8g-2fxf.json b/advisories/unreviewed/2022/04/GHSA-hjrq-qr8g-2fxf/GHSA-hjrq-qr8g-2fxf.json index 0753a2849c5..a9539d8c496 100644 --- a/advisories/unreviewed/2022/04/GHSA-hjrq-qr8g-2fxf/GHSA-hjrq-qr8g-2fxf.json +++ b/advisories/unreviewed/2022/04/GHSA-hjrq-qr8g-2fxf/GHSA-hjrq-qr8g-2fxf.json @@ -7,12 +7,8 @@ "CVE-2004-1897" ], "details": "Administration interface in Monit 1.4 through 4.2 allows remote attackers to cause a denial of service (segmentation fault) by sending a Basic Authentication request without a password, which causes Monit to decrement a null pointer and perform an out-of-bounds read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hp82-x9x6-qxqp/GHSA-hp82-x9x6-qxqp.json b/advisories/unreviewed/2022/04/GHSA-hp82-x9x6-qxqp/GHSA-hp82-x9x6-qxqp.json index 8c3f2d3a00d..34e05c2b11a 100644 --- a/advisories/unreviewed/2022/04/GHSA-hp82-x9x6-qxqp/GHSA-hp82-x9x6-qxqp.json +++ b/advisories/unreviewed/2022/04/GHSA-hp82-x9x6-qxqp/GHSA-hp82-x9x6-qxqp.json @@ -7,12 +7,8 @@ "CVE-2004-1778" ], "details": "Skype 0.92.0.12 and 1.0.0.1 for Linux, and possibly other versions, creates the /usr/share/skype/lang directory with world-writable permissions, which allows local users to modify language files and possibly conduct social engineering or other attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-hvrx-7f87-pv4c/GHSA-hvrx-7f87-pv4c.json b/advisories/unreviewed/2022/04/GHSA-hvrx-7f87-pv4c/GHSA-hvrx-7f87-pv4c.json index d6a118f9629..17d41c38707 100644 --- a/advisories/unreviewed/2022/04/GHSA-hvrx-7f87-pv4c/GHSA-hvrx-7f87-pv4c.json +++ b/advisories/unreviewed/2022/04/GHSA-hvrx-7f87-pv4c/GHSA-hvrx-7f87-pv4c.json @@ -7,12 +7,8 @@ "CVE-2004-1832" ], "details": "Buffer overflow in the GUI admin service in Mac OS X Server 10.3 allows remote attackers to cause a denial of service (crash and restart) via a large amount of data to TCP port 660.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j335-5wx8-vfg6/GHSA-j335-5wx8-vfg6.json b/advisories/unreviewed/2022/04/GHSA-j335-5wx8-vfg6/GHSA-j335-5wx8-vfg6.json index c2ae8941bfb..217dfc567ae 100644 --- a/advisories/unreviewed/2022/04/GHSA-j335-5wx8-vfg6/GHSA-j335-5wx8-vfg6.json +++ b/advisories/unreviewed/2022/04/GHSA-j335-5wx8-vfg6/GHSA-j335-5wx8-vfg6.json @@ -7,12 +7,8 @@ "CVE-2004-1958" ], "details": "Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in a UMOD (Unreal MOD) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j5q2-25f4-p838/GHSA-j5q2-25f4-p838.json b/advisories/unreviewed/2022/04/GHSA-j5q2-25f4-p838/GHSA-j5q2-25f4-p838.json index 354a6e2c919..3607f946bfe 100644 --- a/advisories/unreviewed/2022/04/GHSA-j5q2-25f4-p838/GHSA-j5q2-25f4-p838.json +++ b/advisories/unreviewed/2022/04/GHSA-j5q2-25f4-p838/GHSA-j5q2-25f4-p838.json @@ -7,12 +7,8 @@ "CVE-2004-1802" ], "details": "Chat Anywhere 2.72 and earlier allows remote attackers to hide their IP address by using %00 before the nickname, which causes the IP address to be displayed as $IP$ on the administration web page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j6m7-pmxf-w39j/GHSA-j6m7-pmxf-w39j.json b/advisories/unreviewed/2022/04/GHSA-j6m7-pmxf-w39j/GHSA-j6m7-pmxf-w39j.json index 127ab6e6f98..44e25991787 100644 --- a/advisories/unreviewed/2022/04/GHSA-j6m7-pmxf-w39j/GHSA-j6m7-pmxf-w39j.json +++ b/advisories/unreviewed/2022/04/GHSA-j6m7-pmxf-w39j/GHSA-j6m7-pmxf-w39j.json @@ -7,12 +7,8 @@ "CVE-2004-1839" ], "details": "MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php, or (3) title.php, which reveal the full path in a PHP error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j746-mrw2-7366/GHSA-j746-mrw2-7366.json b/advisories/unreviewed/2022/04/GHSA-j746-mrw2-7366/GHSA-j746-mrw2-7366.json index 467f33750d6..9edfeb9ca05 100644 --- a/advisories/unreviewed/2022/04/GHSA-j746-mrw2-7366/GHSA-j746-mrw2-7366.json +++ b/advisories/unreviewed/2022/04/GHSA-j746-mrw2-7366/GHSA-j746-mrw2-7366.json @@ -7,12 +7,8 @@ "CVE-2004-1913" ], "details": "Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j882-pgg3-j4m7/GHSA-j882-pgg3-j4m7.json b/advisories/unreviewed/2022/04/GHSA-j882-pgg3-j4m7/GHSA-j882-pgg3-j4m7.json index bd2324715a3..a05e25a8e90 100644 --- a/advisories/unreviewed/2022/04/GHSA-j882-pgg3-j4m7/GHSA-j882-pgg3-j4m7.json +++ b/advisories/unreviewed/2022/04/GHSA-j882-pgg3-j4m7/GHSA-j882-pgg3-j4m7.json @@ -7,12 +7,8 @@ "CVE-2004-1972" ], "details": "SQL injection vulnerability in modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to execute arbitrary SQL code via the (1) clipid or (2) catid parameters in a viewclip, viewcat, or voteclip action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j97r-g55p-x5hc/GHSA-j97r-g55p-x5hc.json b/advisories/unreviewed/2022/04/GHSA-j97r-g55p-x5hc/GHSA-j97r-g55p-x5hc.json index 267161cb8fd..6acf5229514 100644 --- a/advisories/unreviewed/2022/04/GHSA-j97r-g55p-x5hc/GHSA-j97r-g55p-x5hc.json +++ b/advisories/unreviewed/2022/04/GHSA-j97r-g55p-x5hc/GHSA-j97r-g55p-x5hc.json @@ -7,12 +7,8 @@ "CVE-2004-1980" ], "details": "Directory traversal vulnerability in glossary.php in PROPS 0.6.1 allows remote attackers to view arbitrary files via a .. (dot dot) in (1) module or (2) format variables.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jg52-mx67-ggv2/GHSA-jg52-mx67-ggv2.json b/advisories/unreviewed/2022/04/GHSA-jg52-mx67-ggv2/GHSA-jg52-mx67-ggv2.json index e6ad04ba668..bc57bac5a05 100644 --- a/advisories/unreviewed/2022/04/GHSA-jg52-mx67-ggv2/GHSA-jg52-mx67-ggv2.json +++ b/advisories/unreviewed/2022/04/GHSA-jg52-mx67-ggv2/GHSA-jg52-mx67-ggv2.json @@ -7,12 +7,8 @@ "CVE-2004-2046" ], "details": "Unknown vulnerability in APC PowerChute Business Edition 6.0 through 7.0.1 allows remote attackers to cause a denial of service via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jg72-25mx-vx8c/GHSA-jg72-25mx-vx8c.json b/advisories/unreviewed/2022/04/GHSA-jg72-25mx-vx8c/GHSA-jg72-25mx-vx8c.json index 2f2c41aca82..5cdd0177a18 100644 --- a/advisories/unreviewed/2022/04/GHSA-jg72-25mx-vx8c/GHSA-jg72-25mx-vx8c.json +++ b/advisories/unreviewed/2022/04/GHSA-jg72-25mx-vx8c/GHSA-jg72-25mx-vx8c.json @@ -7,12 +7,8 @@ "CVE-2004-1862" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Extreme Messageboard (XMB) 1.8 SP3 and 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) xmbuser parameter to xmb.php, (2) folder parameter to u2u.php, (3) viewmost, replymost, or latest parameter to stats.php, (4) message or icons parameter to post.php, (5) threadlist, pagelinks, forumlist, navigation, or (6) forumdisplay parameter to forumdisplay.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jh4p-qrrg-9f8h/GHSA-jh4p-qrrg-9f8h.json b/advisories/unreviewed/2022/04/GHSA-jh4p-qrrg-9f8h/GHSA-jh4p-qrrg-9f8h.json index 187e4699b02..35229c09cb6 100644 --- a/advisories/unreviewed/2022/04/GHSA-jh4p-qrrg-9f8h/GHSA-jh4p-qrrg-9f8h.json +++ b/advisories/unreviewed/2022/04/GHSA-jh4p-qrrg-9f8h/GHSA-jh4p-qrrg-9f8h.json @@ -7,12 +7,8 @@ "CVE-2004-1773" ], "details": "Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary code via (1) long output from wc to shar, or (2) unknown vectors in unshar.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jh6v-2334-hmvr/GHSA-jh6v-2334-hmvr.json b/advisories/unreviewed/2022/04/GHSA-jh6v-2334-hmvr/GHSA-jh6v-2334-hmvr.json index 35ef030b5ff..f52093c3efd 100644 --- a/advisories/unreviewed/2022/04/GHSA-jh6v-2334-hmvr/GHSA-jh6v-2334-hmvr.json +++ b/advisories/unreviewed/2022/04/GHSA-jh6v-2334-hmvr/GHSA-jh6v-2334-hmvr.json @@ -7,12 +7,8 @@ "CVE-2004-1888" ], "details": "display.cgi in Aborior Encore WebForum allows remote to execute arbitrary commands via shell metacharacters in the file variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jq43-gmfx-h2xv/GHSA-jq43-gmfx-h2xv.json b/advisories/unreviewed/2022/04/GHSA-jq43-gmfx-h2xv/GHSA-jq43-gmfx-h2xv.json index b6d757a195a..a623ae9060c 100644 --- a/advisories/unreviewed/2022/04/GHSA-jq43-gmfx-h2xv/GHSA-jq43-gmfx-h2xv.json +++ b/advisories/unreviewed/2022/04/GHSA-jq43-gmfx-h2xv/GHSA-jq43-gmfx-h2xv.json @@ -7,12 +7,8 @@ "CVE-2004-1825" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jv8m-525m-hcvp/GHSA-jv8m-525m-hcvp.json b/advisories/unreviewed/2022/04/GHSA-jv8m-525m-hcvp/GHSA-jv8m-525m-hcvp.json index 33510dcbcb3..114caa93762 100644 --- a/advisories/unreviewed/2022/04/GHSA-jv8m-525m-hcvp/GHSA-jv8m-525m-hcvp.json +++ b/advisories/unreviewed/2022/04/GHSA-jv8m-525m-hcvp/GHSA-jv8m-525m-hcvp.json @@ -7,12 +7,8 @@ "CVE-2004-1808" ], "details": "Extcompose in metamail does not verify the output file before writing to it, which allows local users to overwrite arbitrary files via a symlink attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jvg7-fwfr-45v2/GHSA-jvg7-fwfr-45v2.json b/advisories/unreviewed/2022/04/GHSA-jvg7-fwfr-45v2/GHSA-jvg7-fwfr-45v2.json index cb5a1118b5b..d3b54c76a80 100644 --- a/advisories/unreviewed/2022/04/GHSA-jvg7-fwfr-45v2/GHSA-jvg7-fwfr-45v2.json +++ b/advisories/unreviewed/2022/04/GHSA-jvg7-fwfr-45v2/GHSA-jvg7-fwfr-45v2.json @@ -7,12 +7,8 @@ "CVE-2004-1793" ], "details": "Stack-based buffer overflow in swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote authenticated users to execute arbitrary code via a long message parameter in a SendMsg action to action.htm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jww8-f62q-7957/GHSA-jww8-f62q-7957.json b/advisories/unreviewed/2022/04/GHSA-jww8-f62q-7957/GHSA-jww8-f62q-7957.json index ea06ecabf52..e773325f1c4 100644 --- a/advisories/unreviewed/2022/04/GHSA-jww8-f62q-7957/GHSA-jww8-f62q-7957.json +++ b/advisories/unreviewed/2022/04/GHSA-jww8-f62q-7957/GHSA-jww8-f62q-7957.json @@ -7,12 +7,8 @@ "CVE-2004-1818" ], "details": "Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary script as other users by injecting arbitrary script into the z parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jx58-4hh4-9f7j/GHSA-jx58-4hh4-9f7j.json b/advisories/unreviewed/2022/04/GHSA-jx58-4hh4-9f7j/GHSA-jx58-4hh4-9f7j.json index e29b86cda8f..df78415f2bc 100644 --- a/advisories/unreviewed/2022/04/GHSA-jx58-4hh4-9f7j/GHSA-jx58-4hh4-9f7j.json +++ b/advisories/unreviewed/2022/04/GHSA-jx58-4hh4-9f7j/GHSA-jx58-4hh4-9f7j.json @@ -7,12 +7,8 @@ "CVE-2004-1956" ], "details": "PostNuke 0.7.2.6 allows remote attackers to gain information via a direct HTTP request to files in the (1) includes/blocks directory, (2) pnadodb directory, (3) NS-NewUser module, (4) NS-Your_Account, (5) NS-LostPassword module, or (6) NS-User module which reveals the path to the web server in a PHP error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m25w-37x6-fpxv/GHSA-m25w-37x6-fpxv.json b/advisories/unreviewed/2022/04/GHSA-m25w-37x6-fpxv/GHSA-m25w-37x6-fpxv.json index 55eabc9551a..be6e702d47f 100644 --- a/advisories/unreviewed/2022/04/GHSA-m25w-37x6-fpxv/GHSA-m25w-37x6-fpxv.json +++ b/advisories/unreviewed/2022/04/GHSA-m25w-37x6-fpxv/GHSA-m25w-37x6-fpxv.json @@ -7,12 +7,8 @@ "CVE-2004-1765" ], "details": "Off-by-one buffer overflow in ModSecurity (mod_security) 1.7.4 for Apache 2.x, when SecFilterScanPost is enabled, allows remote attackers to execute arbitrary code via crafted POST requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m634-63gw-qhv4/GHSA-m634-63gw-qhv4.json b/advisories/unreviewed/2022/04/GHSA-m634-63gw-qhv4/GHSA-m634-63gw-qhv4.json index 947a25c65cf..70c8b7a8115 100644 --- a/advisories/unreviewed/2022/04/GHSA-m634-63gw-qhv4/GHSA-m634-63gw-qhv4.json +++ b/advisories/unreviewed/2022/04/GHSA-m634-63gw-qhv4/GHSA-m634-63gw-qhv4.json @@ -7,12 +7,8 @@ "CVE-2004-1917" ], "details": "Format string vulnerability in test_func_func in LCDProc 0.4.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the str variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m82x-j38m-84qv/GHSA-m82x-j38m-84qv.json b/advisories/unreviewed/2022/04/GHSA-m82x-j38m-84qv/GHSA-m82x-j38m-84qv.json index 7d0d95e3d30..c216ab43629 100644 --- a/advisories/unreviewed/2022/04/GHSA-m82x-j38m-84qv/GHSA-m82x-j38m-84qv.json +++ b/advisories/unreviewed/2022/04/GHSA-m82x-j38m-84qv/GHSA-m82x-j38m-84qv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-m84f-vp78-8mq6/GHSA-m84f-vp78-8mq6.json b/advisories/unreviewed/2022/04/GHSA-m84f-vp78-8mq6/GHSA-m84f-vp78-8mq6.json index d69b7bdc2d6..4ac19d4bb42 100644 --- a/advisories/unreviewed/2022/04/GHSA-m84f-vp78-8mq6/GHSA-m84f-vp78-8mq6.json +++ b/advisories/unreviewed/2022/04/GHSA-m84f-vp78-8mq6/GHSA-m84f-vp78-8mq6.json @@ -7,12 +7,8 @@ "CVE-2004-1820" ], "details": "PHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary PHP code by modifying the basepath parameter to reference a URL on a remote web server that contains fileFunctions.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m9hc-vpmc-234m/GHSA-m9hc-vpmc-234m.json b/advisories/unreviewed/2022/04/GHSA-m9hc-vpmc-234m/GHSA-m9hc-vpmc-234m.json index f23ce653557..7175bf1a195 100644 --- a/advisories/unreviewed/2022/04/GHSA-m9hc-vpmc-234m/GHSA-m9hc-vpmc-234m.json +++ b/advisories/unreviewed/2022/04/GHSA-m9hc-vpmc-234m/GHSA-m9hc-vpmc-234m.json @@ -7,12 +7,8 @@ "CVE-2004-1912" ], "details": "The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke, allow remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m9jr-jw96-43qq/GHSA-m9jr-jw96-43qq.json b/advisories/unreviewed/2022/04/GHSA-m9jr-jw96-43qq/GHSA-m9jr-jw96-43qq.json index 83586820b5e..81a375911e7 100644 --- a/advisories/unreviewed/2022/04/GHSA-m9jr-jw96-43qq/GHSA-m9jr-jw96-43qq.json +++ b/advisories/unreviewed/2022/04/GHSA-m9jr-jw96-43qq/GHSA-m9jr-jw96-43qq.json @@ -7,12 +7,8 @@ "CVE-2004-1953" ], "details": "phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mgp4-ph25-p5v6/GHSA-mgp4-ph25-p5v6.json b/advisories/unreviewed/2022/04/GHSA-mgp4-ph25-p5v6/GHSA-mgp4-ph25-p5v6.json index cced55da100..8d2adf32278 100644 --- a/advisories/unreviewed/2022/04/GHSA-mgp4-ph25-p5v6/GHSA-mgp4-ph25-p5v6.json +++ b/advisories/unreviewed/2022/04/GHSA-mgp4-ph25-p5v6/GHSA-mgp4-ph25-p5v6.json @@ -7,12 +7,8 @@ "CVE-2004-2006" ], "details": "Trend Micro OfficeScan 3.0 - 6.0 has default permissions of \"Everyone Full Control\" on the installation directory and registry keys, which allows local users to disable virus protection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mj47-96qq-gghw/GHSA-mj47-96qq-gghw.json b/advisories/unreviewed/2022/04/GHSA-mj47-96qq-gghw/GHSA-mj47-96qq-gghw.json index 6ced57e8579..a166c035dd5 100644 --- a/advisories/unreviewed/2022/04/GHSA-mj47-96qq-gghw/GHSA-mj47-96qq-gghw.json +++ b/advisories/unreviewed/2022/04/GHSA-mj47-96qq-gghw/GHSA-mj47-96qq-gghw.json @@ -7,12 +7,8 @@ "CVE-2004-1813" ], "details": "VocalTec VGW4/8 Gateway 8.0 allows remote attackers to bypass authentication via an HTTP request to home.asp with a trailing slash (/).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mj7j-rjvc-fjwh/GHSA-mj7j-rjvc-fjwh.json b/advisories/unreviewed/2022/04/GHSA-mj7j-rjvc-fjwh/GHSA-mj7j-rjvc-fjwh.json index 8034e8bcca4..0a861bb7a9b 100644 --- a/advisories/unreviewed/2022/04/GHSA-mj7j-rjvc-fjwh/GHSA-mj7j-rjvc-fjwh.json +++ b/advisories/unreviewed/2022/04/GHSA-mj7j-rjvc-fjwh/GHSA-mj7j-rjvc-fjwh.json @@ -7,12 +7,8 @@ "CVE-2004-1838" ], "details": "Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mjmp-9722-7h88/GHSA-mjmp-9722-7h88.json b/advisories/unreviewed/2022/04/GHSA-mjmp-9722-7h88/GHSA-mjmp-9722-7h88.json index 06ea85d13a2..05cff697be2 100644 --- a/advisories/unreviewed/2022/04/GHSA-mjmp-9722-7h88/GHSA-mjmp-9722-7h88.json +++ b/advisories/unreviewed/2022/04/GHSA-mjmp-9722-7h88/GHSA-mjmp-9722-7h88.json @@ -7,12 +7,8 @@ "CVE-2004-1929" ], "details": "SQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass authentication and gain access by injecting base64-encoded SQL code into the user parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mmhg-j83f-h6qc/GHSA-mmhg-j83f-h6qc.json b/advisories/unreviewed/2022/04/GHSA-mmhg-j83f-h6qc/GHSA-mmhg-j83f-h6qc.json index b54f2b2d874..388da4f6667 100644 --- a/advisories/unreviewed/2022/04/GHSA-mmhg-j83f-h6qc/GHSA-mmhg-j83f-h6qc.json +++ b/advisories/unreviewed/2022/04/GHSA-mmhg-j83f-h6qc/GHSA-mmhg-j83f-h6qc.json @@ -7,12 +7,8 @@ "CVE-2004-1847" ], "details": "News Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN parameter in the NEWS_LOGIN cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mp36-76pc-pphx/GHSA-mp36-76pc-pphx.json b/advisories/unreviewed/2022/04/GHSA-mp36-76pc-pphx/GHSA-mp36-76pc-pphx.json index 8346d1b8ba1..2f95852924a 100644 --- a/advisories/unreviewed/2022/04/GHSA-mp36-76pc-pphx/GHSA-mp36-76pc-pphx.json +++ b/advisories/unreviewed/2022/04/GHSA-mp36-76pc-pphx/GHSA-mp36-76pc-pphx.json @@ -7,12 +7,8 @@ "CVE-2004-1799" ], "details": "PF in certain OpenBSD versions, when stateful filtering is enabled, does not limit packets for a session to the original interface, which allows remote attackers to bypass intended packet filters via spoofed packets to other interfaces.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mppw-43vf-5v6h/GHSA-mppw-43vf-5v6h.json b/advisories/unreviewed/2022/04/GHSA-mppw-43vf-5v6h/GHSA-mppw-43vf-5v6h.json index f86269d9627..57faf7483d1 100644 --- a/advisories/unreviewed/2022/04/GHSA-mppw-43vf-5v6h/GHSA-mppw-43vf-5v6h.json +++ b/advisories/unreviewed/2022/04/GHSA-mppw-43vf-5v6h/GHSA-mppw-43vf-5v6h.json @@ -7,12 +7,8 @@ "CVE-2004-1986" ], "details": "Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the startdir parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p4m4-q3m2-fp7j/GHSA-p4m4-q3m2-fp7j.json b/advisories/unreviewed/2022/04/GHSA-p4m4-q3m2-fp7j/GHSA-p4m4-q3m2-fp7j.json index 39ed70cdc93..2d326045d9a 100644 --- a/advisories/unreviewed/2022/04/GHSA-p4m4-q3m2-fp7j/GHSA-p4m4-q3m2-fp7j.json +++ b/advisories/unreviewed/2022/04/GHSA-p4m4-q3m2-fp7j/GHSA-p4m4-q3m2-fp7j.json @@ -7,12 +7,8 @@ "CVE-2004-1761" ], "details": "Unknown vulnerability in Ethereal 0.8.13 to 0.10.2 allows attackers to cause a denial of service (segmentation fault) via a malformed color filter file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p5hc-6fx8-9wf9/GHSA-p5hc-6fx8-9wf9.json b/advisories/unreviewed/2022/04/GHSA-p5hc-6fx8-9wf9/GHSA-p5hc-6fx8-9wf9.json index cc1a1ae3f1b..ed8f2bd6671 100644 --- a/advisories/unreviewed/2022/04/GHSA-p5hc-6fx8-9wf9/GHSA-p5hc-6fx8-9wf9.json +++ b/advisories/unreviewed/2022/04/GHSA-p5hc-6fx8-9wf9/GHSA-p5hc-6fx8-9wf9.json @@ -7,12 +7,8 @@ "CVE-2004-1932" ], "details": "SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p684-hxfc-rq65/GHSA-p684-hxfc-rq65.json b/advisories/unreviewed/2022/04/GHSA-p684-hxfc-rq65/GHSA-p684-hxfc-rq65.json index ee5e4476bf2..3c33b1e6423 100644 --- a/advisories/unreviewed/2022/04/GHSA-p684-hxfc-rq65/GHSA-p684-hxfc-rq65.json +++ b/advisories/unreviewed/2022/04/GHSA-p684-hxfc-rq65/GHSA-p684-hxfc-rq65.json @@ -7,12 +7,8 @@ "CVE-2004-1851" ], "details": "Dameware Mini Remote Control 4.1.0.0 uses insufficiently random data to create the encryption key, which makes it easier for remote attackers to obtain sensitive information via brute force guessing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p7qg-6c5p-v5h5/GHSA-p7qg-6c5p-v5h5.json b/advisories/unreviewed/2022/04/GHSA-p7qg-6c5p-v5h5/GHSA-p7qg-6c5p-v5h5.json index 52fd274742c..0e26d9dc070 100644 --- a/advisories/unreviewed/2022/04/GHSA-p7qg-6c5p-v5h5/GHSA-p7qg-6c5p-v5h5.json +++ b/advisories/unreviewed/2022/04/GHSA-p7qg-6c5p-v5h5/GHSA-p7qg-6c5p-v5h5.json @@ -7,12 +7,8 @@ "CVE-2004-1804" ], "details": "wMCam server 2.1.348 allows remote attackers to cause a denial of service (no new connections) via multiple malformed HTTP requests without the GET command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pfjc-pqq8-xrjh/GHSA-pfjc-pqq8-xrjh.json b/advisories/unreviewed/2022/04/GHSA-pfjc-pqq8-xrjh/GHSA-pfjc-pqq8-xrjh.json index 927f1c9c30c..8fd2e322491 100644 --- a/advisories/unreviewed/2022/04/GHSA-pfjc-pqq8-xrjh/GHSA-pfjc-pqq8-xrjh.json +++ b/advisories/unreviewed/2022/04/GHSA-pfjc-pqq8-xrjh/GHSA-pfjc-pqq8-xrjh.json @@ -7,12 +7,8 @@ "CVE-2004-1875" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to testfile.html, (2) file parameter to erredit.html, (3) dns parameter to dnslook.html, (4) account parameter to ignorelist.html, (5) account parameter to showlog.html, (6) db parameter to repairdb.html, (7) login parameter to doaddftp.html (8) account parameter to editmsg.htm, or (9) ip parameter to del.html. NOTE: the dnslook.html vector was later reported to exist in cPanel 10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-ph59-qghm-32cp/GHSA-ph59-qghm-32cp.json b/advisories/unreviewed/2022/04/GHSA-ph59-qghm-32cp/GHSA-ph59-qghm-32cp.json index fdf202394c2..d7ac49707bc 100644 --- a/advisories/unreviewed/2022/04/GHSA-ph59-qghm-32cp/GHSA-ph59-qghm-32cp.json +++ b/advisories/unreviewed/2022/04/GHSA-ph59-qghm-32cp/GHSA-ph59-qghm-32cp.json @@ -7,12 +7,8 @@ "CVE-2004-1989" ], "details": "PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modifying the THEME_DIR parameter to reference a URL on a remote web server that contains user_list_info_box.inc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ph93-hcr9-mjxh/GHSA-ph93-hcr9-mjxh.json b/advisories/unreviewed/2022/04/GHSA-ph93-hcr9-mjxh/GHSA-ph93-hcr9-mjxh.json index 7c19096c6ea..517e183dbfe 100644 --- a/advisories/unreviewed/2022/04/GHSA-ph93-hcr9-mjxh/GHSA-ph93-hcr9-mjxh.json +++ b/advisories/unreviewed/2022/04/GHSA-ph93-hcr9-mjxh/GHSA-ph93-hcr9-mjxh.json @@ -7,12 +7,8 @@ "CVE-2004-1857" ], "details": "Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to read arbitrary files via a .. (dot dot) in the setinclude parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-phc3-vv24-qgfp/GHSA-phc3-vv24-qgfp.json b/advisories/unreviewed/2022/04/GHSA-phc3-vv24-qgfp/GHSA-phc3-vv24-qgfp.json index 04ad157104a..942e5d4c144 100644 --- a/advisories/unreviewed/2022/04/GHSA-phc3-vv24-qgfp/GHSA-phc3-vv24-qgfp.json +++ b/advisories/unreviewed/2022/04/GHSA-phc3-vv24-qgfp/GHSA-phc3-vv24-qgfp.json @@ -7,12 +7,8 @@ "CVE-2004-1877" ], "details": "The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pj48-m727-5mqc/GHSA-pj48-m727-5mqc.json b/advisories/unreviewed/2022/04/GHSA-pj48-m727-5mqc/GHSA-pj48-m727-5mqc.json index 80f0ce784a9..b056141996b 100644 --- a/advisories/unreviewed/2022/04/GHSA-pj48-m727-5mqc/GHSA-pj48-m727-5mqc.json +++ b/advisories/unreviewed/2022/04/GHSA-pj48-m727-5mqc/GHSA-pj48-m727-5mqc.json @@ -7,12 +7,8 @@ "CVE-2004-2009" ], "details": "NukeJokes 1.7 and 2 Beta allows remote attackers to obtain the full path of the server via (1) a direct call to mainfunctions.php, (2) an invalid jokeid parameter in a JokeView function or (3) an invalid cat parameter in a CatView function, which reveals the path in a PHP error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pq6c-g7jv-6vhh/GHSA-pq6c-g7jv-6vhh.json b/advisories/unreviewed/2022/04/GHSA-pq6c-g7jv-6vhh/GHSA-pq6c-g7jv-6vhh.json index 19b02e6a4f7..8880eb1c5d9 100644 --- a/advisories/unreviewed/2022/04/GHSA-pq6c-g7jv-6vhh/GHSA-pq6c-g7jv-6vhh.json +++ b/advisories/unreviewed/2022/04/GHSA-pq6c-g7jv-6vhh/GHSA-pq6c-g7jv-6vhh.json @@ -7,12 +7,8 @@ "CVE-2004-2018" ], "details": "PHP remote file inclusion vulnerability in index.php in Php-Nuke 6.x through 7.3 allows remote attackers to execute arbitrary PHP code by modifying the modpath parameter to reference a URL on a remote web server that contains the code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pqm2-r3mv-x23f/GHSA-pqm2-r3mv-x23f.json b/advisories/unreviewed/2022/04/GHSA-pqm2-r3mv-x23f/GHSA-pqm2-r3mv-x23f.json index b2b183e5966..9632f56f8be 100644 --- a/advisories/unreviewed/2022/04/GHSA-pqm2-r3mv-x23f/GHSA-pqm2-r3mv-x23f.json +++ b/advisories/unreviewed/2022/04/GHSA-pqm2-r3mv-x23f/GHSA-pqm2-r3mv-x23f.json @@ -7,12 +7,8 @@ "CVE-2004-1982" ], "details": "Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subject field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q595-r7x7-fp46/GHSA-q595-r7x7-fp46.json b/advisories/unreviewed/2022/04/GHSA-q595-r7x7-fp46/GHSA-q595-r7x7-fp46.json index 003be442fa7..f6f7a3db618 100644 --- a/advisories/unreviewed/2022/04/GHSA-q595-r7x7-fp46/GHSA-q595-r7x7-fp46.json +++ b/advisories/unreviewed/2022/04/GHSA-q595-r7x7-fp46/GHSA-q595-r7x7-fp46.json @@ -7,12 +7,8 @@ "CVE-2004-1834" ], "details": "mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -120,9 +116,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q675-4hgh-wr56/GHSA-q675-4hgh-wr56.json b/advisories/unreviewed/2022/04/GHSA-q675-4hgh-wr56/GHSA-q675-4hgh-wr56.json index f98a5b634fb..42cf066a152 100644 --- a/advisories/unreviewed/2022/04/GHSA-q675-4hgh-wr56/GHSA-q675-4hgh-wr56.json +++ b/advisories/unreviewed/2022/04/GHSA-q675-4hgh-wr56/GHSA-q675-4hgh-wr56.json @@ -7,12 +7,8 @@ "CVE-2004-1814" ], "details": "Directory traversal vulnerability in VocalTec VGW4/8 Gateway 8.0 allows remote attackers to read protected files via .. (dot dot) sequences in an HTTP request, as demonstrated using home.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q6rx-427h-5675/GHSA-q6rx-427h-5675.json b/advisories/unreviewed/2022/04/GHSA-q6rx-427h-5675/GHSA-q6rx-427h-5675.json index a7cfec6dd22..76e875e2d72 100644 --- a/advisories/unreviewed/2022/04/GHSA-q6rx-427h-5675/GHSA-q6rx-427h-5675.json +++ b/advisories/unreviewed/2022/04/GHSA-q6rx-427h-5675/GHSA-q6rx-427h-5675.json @@ -7,12 +7,8 @@ "CVE-2004-1984" ], "details": "Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) phpinfo.php, (2) addpic.php, (3) config.php, (4) db_input.php, (5) displayecard.php, (6) ecard.php, (7) crop.inc.php, which reveal the full path in a PHP error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q735-hx6r-7j55/GHSA-q735-hx6r-7j55.json b/advisories/unreviewed/2022/04/GHSA-q735-hx6r-7j55/GHSA-q735-hx6r-7j55.json index 07dd504de00..c2391651b46 100644 --- a/advisories/unreviewed/2022/04/GHSA-q735-hx6r-7j55/GHSA-q735-hx6r-7j55.json +++ b/advisories/unreviewed/2022/04/GHSA-q735-hx6r-7j55/GHSA-q735-hx6r-7j55.json @@ -7,12 +7,8 @@ "CVE-2004-1807" ], "details": "Cross-site scripting (XSS) vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to inject arbitrary web script or HTML via the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q8xc-297m-368w/GHSA-q8xc-297m-368w.json b/advisories/unreviewed/2022/04/GHSA-q8xc-297m-368w/GHSA-q8xc-297m-368w.json index 1eaf1441812..32c30a8bbc1 100644 --- a/advisories/unreviewed/2022/04/GHSA-q8xc-297m-368w/GHSA-q8xc-297m-368w.json +++ b/advisories/unreviewed/2022/04/GHSA-q8xc-297m-368w/GHSA-q8xc-297m-368w.json @@ -7,12 +7,8 @@ "CVE-2004-1871" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ppuser, (2) password, (3) stype, (4) perpage, (5) sort, (6) page, (7) si, or (8) cat parameters to showmembers.php, or the (9) photo name, (10) photo description, (11) album name, or (12) album description fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q95m-g3gg-q299/GHSA-q95m-g3gg-q299.json b/advisories/unreviewed/2022/04/GHSA-q95m-g3gg-q299/GHSA-q95m-g3gg-q299.json index 10e39162921..472ed441d46 100644 --- a/advisories/unreviewed/2022/04/GHSA-q95m-g3gg-q299/GHSA-q95m-g3gg-q299.json +++ b/advisories/unreviewed/2022/04/GHSA-q95m-g3gg-q299/GHSA-q95m-g3gg-q299.json @@ -7,12 +7,8 @@ "CVE-2004-1864" ], "details": "SQL injection vulnerability in Extreme Messageboard (XMB) 1.9 beta allows remote attackers to execute arbitrary SQL commands via the restrict parameter to (1) member.php, (2) misc.php, or (3) today.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qgvq-x96v-cf8x/GHSA-qgvq-x96v-cf8x.json b/advisories/unreviewed/2022/04/GHSA-qgvq-x96v-cf8x/GHSA-qgvq-x96v-cf8x.json index 8f7fe69595d..47c200796e7 100644 --- a/advisories/unreviewed/2022/04/GHSA-qgvq-x96v-cf8x/GHSA-qgvq-x96v-cf8x.json +++ b/advisories/unreviewed/2022/04/GHSA-qgvq-x96v-cf8x/GHSA-qgvq-x96v-cf8x.json @@ -7,12 +7,8 @@ "CVE-2004-1798" ], "details": "RealOne player 6.0.11.868 allows remote attackers to execute arbitrary script in the \"My Computer\" zone via a Synchronized Multimedia Integration Language (SMIL) presentation with a \"file:javascript:\" URL, which is executed in the security context of the previously loaded URL, a different vulnerability than CVE-2003-0726.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qhvc-fwj9-94fp/GHSA-qhvc-fwj9-94fp.json b/advisories/unreviewed/2022/04/GHSA-qhvc-fwj9-94fp/GHSA-qhvc-fwj9-94fp.json index dda4f2d4974..8f7b458bc5a 100644 --- a/advisories/unreviewed/2022/04/GHSA-qhvc-fwj9-94fp/GHSA-qhvc-fwj9-94fp.json +++ b/advisories/unreviewed/2022/04/GHSA-qhvc-fwj9-94fp/GHSA-qhvc-fwj9-94fp.json @@ -7,12 +7,8 @@ "CVE-2004-1879" ], "details": "Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HTML via forum messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qm6f-p4vv-g3v5/GHSA-qm6f-p4vv-g3v5.json b/advisories/unreviewed/2022/04/GHSA-qm6f-p4vv-g3v5/GHSA-qm6f-p4vv-g3v5.json index 87af1f5aa80..c20df134f7b 100644 --- a/advisories/unreviewed/2022/04/GHSA-qm6f-p4vv-g3v5/GHSA-qm6f-p4vv-g3v5.json +++ b/advisories/unreviewed/2022/04/GHSA-qm6f-p4vv-g3v5/GHSA-qm6f-p4vv-g3v5.json @@ -7,12 +7,8 @@ "CVE-2004-1902" ], "details": "The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qmc8-jg49-hmwp/GHSA-qmc8-jg49-hmwp.json b/advisories/unreviewed/2022/04/GHSA-qmc8-jg49-hmwp/GHSA-qmc8-jg49-hmwp.json index 6bf74293b67..dd47d454bba 100644 --- a/advisories/unreviewed/2022/04/GHSA-qmc8-jg49-hmwp/GHSA-qmc8-jg49-hmwp.json +++ b/advisories/unreviewed/2022/04/GHSA-qmc8-jg49-hmwp/GHSA-qmc8-jg49-hmwp.json @@ -7,12 +7,8 @@ "CVE-2004-1792" ], "details": "swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a long packet with two CRLF sequences to the service management port (TCP 8000).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qp6g-5r5j-gqqw/GHSA-qp6g-5r5j-gqqw.json b/advisories/unreviewed/2022/04/GHSA-qp6g-5r5j-gqqw/GHSA-qp6g-5r5j-gqqw.json index 9480f4fde91..987da8f10b1 100644 --- a/advisories/unreviewed/2022/04/GHSA-qp6g-5r5j-gqqw/GHSA-qp6g-5r5j-gqqw.json +++ b/advisories/unreviewed/2022/04/GHSA-qp6g-5r5j-gqqw/GHSA-qp6g-5r5j-gqqw.json @@ -7,12 +7,8 @@ "CVE-2004-1786" ], "details": "PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qr7r-whq7-5ffv/GHSA-qr7r-whq7-5ffv.json b/advisories/unreviewed/2022/04/GHSA-qr7r-whq7-5ffv/GHSA-qr7r-whq7-5ffv.json index 823d43380f0..b1ec428b9ed 100644 --- a/advisories/unreviewed/2022/04/GHSA-qr7r-whq7-5ffv/GHSA-qr7r-whq7-5ffv.json +++ b/advisories/unreviewed/2022/04/GHSA-qr7r-whq7-5ffv/GHSA-qr7r-whq7-5ffv.json @@ -7,12 +7,8 @@ "CVE-2004-1759" ], "details": "Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qw4w-jhg4-f7wc/GHSA-qw4w-jhg4-f7wc.json b/advisories/unreviewed/2022/04/GHSA-qw4w-jhg4-f7wc/GHSA-qw4w-jhg4-f7wc.json index c820ac77076..8e76ec3ccfd 100644 --- a/advisories/unreviewed/2022/04/GHSA-qw4w-jhg4-f7wc/GHSA-qw4w-jhg4-f7wc.json +++ b/advisories/unreviewed/2022/04/GHSA-qw4w-jhg4-f7wc/GHSA-qw4w-jhg4-f7wc.json @@ -7,12 +7,8 @@ "CVE-2004-1893" ], "details": "Dreamweaver MX, when \"Using Driver On Testing Server\" or \"Using DSN on Testing Server\" is selected, uploads the mmhttpdb.asp script to the web site but does not require authentication, which allows remote attackers to obtain sensitive information and possibly execute arbitrary SQL commands via a direct request to mmhttpdb.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qwr6-hppc-6597/GHSA-qwr6-hppc-6597.json b/advisories/unreviewed/2022/04/GHSA-qwr6-hppc-6597/GHSA-qwr6-hppc-6597.json index 45cb83f1659..9e63b7a8e5e 100644 --- a/advisories/unreviewed/2022/04/GHSA-qwr6-hppc-6597/GHSA-qwr6-hppc-6597.json +++ b/advisories/unreviewed/2022/04/GHSA-qwr6-hppc-6597/GHSA-qwr6-hppc-6597.json @@ -7,12 +7,8 @@ "CVE-2004-1998" ], "details": "The Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to gain sensitive information via an invalid show parameter to modules.php, which reveals the full path in a PHP error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r2p4-h4fr-xgqc/GHSA-r2p4-h4fr-xgqc.json b/advisories/unreviewed/2022/04/GHSA-r2p4-h4fr-xgqc/GHSA-r2p4-h4fr-xgqc.json index b6508159eb4..5d834c1f59a 100644 --- a/advisories/unreviewed/2022/04/GHSA-r2p4-h4fr-xgqc/GHSA-r2p4-h4fr-xgqc.json +++ b/advisories/unreviewed/2022/04/GHSA-r2p4-h4fr-xgqc/GHSA-r2p4-h4fr-xgqc.json @@ -7,12 +7,8 @@ "CVE-2004-1779" ], "details": "Cross-site scripting (XSS) vulnerability in board.php for ThWboard before beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the lastvisited parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r47w-m25r-5m77/GHSA-r47w-m25r-5m77.json b/advisories/unreviewed/2022/04/GHSA-r47w-m25r-5m77/GHSA-r47w-m25r-5m77.json index c85c275a573..ae9fc0e5f28 100644 --- a/advisories/unreviewed/2022/04/GHSA-r47w-m25r-5m77/GHSA-r47w-m25r-5m77.json +++ b/advisories/unreviewed/2022/04/GHSA-r47w-m25r-5m77/GHSA-r47w-m25r-5m77.json @@ -7,12 +7,8 @@ "CVE-2004-2036" ], "details": "SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r6mc-hmwr-v7jq/GHSA-r6mc-hmwr-v7jq.json b/advisories/unreviewed/2022/04/GHSA-r6mc-hmwr-v7jq/GHSA-r6mc-hmwr-v7jq.json index 93b1e11f7cb..37c1a7afe20 100644 --- a/advisories/unreviewed/2022/04/GHSA-r6mc-hmwr-v7jq/GHSA-r6mc-hmwr-v7jq.json +++ b/advisories/unreviewed/2022/04/GHSA-r6mc-hmwr-v7jq/GHSA-r6mc-hmwr-v7jq.json @@ -7,12 +7,8 @@ "CVE-2004-1846" ], "details": "Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via the (1) ID parameter to more.asp, (2) ID parameter to category_news.asp, or (3) filter parameter to news_sort.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r7hm-54xg-v8p6/GHSA-r7hm-54xg-v8p6.json b/advisories/unreviewed/2022/04/GHSA-r7hm-54xg-v8p6/GHSA-r7hm-54xg-v8p6.json index c0b9e8843b0..e537dae99a7 100644 --- a/advisories/unreviewed/2022/04/GHSA-r7hm-54xg-v8p6/GHSA-r7hm-54xg-v8p6.json +++ b/advisories/unreviewed/2022/04/GHSA-r7hm-54xg-v8p6/GHSA-r7hm-54xg-v8p6.json @@ -7,12 +7,8 @@ "CVE-2004-1933" ], "details": "Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass access controls and read unauthorized messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rf9q-6p6q-j7mp/GHSA-rf9q-6p6q-j7mp.json b/advisories/unreviewed/2022/04/GHSA-rf9q-6p6q-j7mp/GHSA-rf9q-6p6q-j7mp.json index c2fd8bbb76b..36b76e190c0 100644 --- a/advisories/unreviewed/2022/04/GHSA-rf9q-6p6q-j7mp/GHSA-rf9q-6p6q-j7mp.json +++ b/advisories/unreviewed/2022/04/GHSA-rf9q-6p6q-j7mp/GHSA-rf9q-6p6q-j7mp.json @@ -7,12 +7,8 @@ "CVE-2004-1952" ], "details": "SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rhhf-gqg6-mv8h/GHSA-rhhf-gqg6-mv8h.json b/advisories/unreviewed/2022/04/GHSA-rhhf-gqg6-mv8h/GHSA-rhhf-gqg6-mv8h.json index 3cc0471fda4..bd37ab2754c 100644 --- a/advisories/unreviewed/2022/04/GHSA-rhhf-gqg6-mv8h/GHSA-rhhf-gqg6-mv8h.json +++ b/advisories/unreviewed/2022/04/GHSA-rhhf-gqg6-mv8h/GHSA-rhhf-gqg6-mv8h.json @@ -7,12 +7,8 @@ "CVE-2004-2005" ], "details": "Buffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-mail with (1) a link to a long URL to the C drive or (2) a long attachment name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rm82-8gf2-hpxx/GHSA-rm82-8gf2-hpxx.json b/advisories/unreviewed/2022/04/GHSA-rm82-8gf2-hpxx/GHSA-rm82-8gf2-hpxx.json index bff54b26b36..1c0df3f43e2 100644 --- a/advisories/unreviewed/2022/04/GHSA-rm82-8gf2-hpxx/GHSA-rm82-8gf2-hpxx.json +++ b/advisories/unreviewed/2022/04/GHSA-rm82-8gf2-hpxx/GHSA-rm82-8gf2-hpxx.json @@ -7,12 +7,8 @@ "CVE-2004-2035" ], "details": "MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of trailing CRLF sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rmpw-q9gh-4qqx/GHSA-rmpw-q9gh-4qqx.json b/advisories/unreviewed/2022/04/GHSA-rmpw-q9gh-4qqx/GHSA-rmpw-q9gh-4qqx.json index 648a7065c73..221e17cbe8b 100644 --- a/advisories/unreviewed/2022/04/GHSA-rmpw-q9gh-4qqx/GHSA-rmpw-q9gh-4qqx.json +++ b/advisories/unreviewed/2022/04/GHSA-rmpw-q9gh-4qqx/GHSA-rmpw-q9gh-4qqx.json @@ -7,12 +7,8 @@ "CVE-2004-1937" ], "details": "Multiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote attackers to read or include arbitrary files via .. sequences in (1) the user_langue parameter to index.php or (2) the langue parameter to update.php, or modify arbitrary GLOBAL variables by causing globals.php to be loaded before conf.inc.php via (3) .. sequences in the file parameter with the page parameter set to globals, or (4) ../globals.php in the user_langue parameter, as demonstrated by modifying $nuked[prefix] in the Suggest module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rphj-cr7q-54vg/GHSA-rphj-cr7q-54vg.json b/advisories/unreviewed/2022/04/GHSA-rphj-cr7q-54vg/GHSA-rphj-cr7q-54vg.json index 2ad1fb4ea73..db01db68ccf 100644 --- a/advisories/unreviewed/2022/04/GHSA-rphj-cr7q-54vg/GHSA-rphj-cr7q-54vg.json +++ b/advisories/unreviewed/2022/04/GHSA-rphj-cr7q-54vg/GHSA-rphj-cr7q-54vg.json @@ -7,12 +7,8 @@ "CVE-2004-1796" ], "details": "PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header] parameter to hotnews-engine.inc.php3 or (2) config[incdir] parameter to hnmain.inc.php3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rpjc-9jjq-qgg9/GHSA-rpjc-9jjq-qgg9.json b/advisories/unreviewed/2022/04/GHSA-rpjc-9jjq-qgg9/GHSA-rpjc-9jjq-qgg9.json index f0614621dec..6566761b4b1 100644 --- a/advisories/unreviewed/2022/04/GHSA-rpjc-9jjq-qgg9/GHSA-rpjc-9jjq-qgg9.json +++ b/advisories/unreviewed/2022/04/GHSA-rpjc-9jjq-qgg9/GHSA-rpjc-9jjq-qgg9.json @@ -7,12 +7,8 @@ "CVE-2004-1757" ], "details": "BEA WebLogic Server and Express 8.1, SP1 and earlier, stores the administrator password in cleartext in config.xml, which allows local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rrwc-ph65-5p73/GHSA-rrwc-ph65-5p73.json b/advisories/unreviewed/2022/04/GHSA-rrwc-ph65-5p73/GHSA-rrwc-ph65-5p73.json index 8b1cf6f7118..9344c826430 100644 --- a/advisories/unreviewed/2022/04/GHSA-rrwc-ph65-5p73/GHSA-rrwc-ph65-5p73.json +++ b/advisories/unreviewed/2022/04/GHSA-rrwc-ph65-5p73/GHSA-rrwc-ph65-5p73.json @@ -7,12 +7,8 @@ "CVE-2004-2026" ], "details": "Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format string specifiers in syslog messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rv8x-7664-px9q/GHSA-rv8x-7664-px9q.json b/advisories/unreviewed/2022/04/GHSA-rv8x-7664-px9q/GHSA-rv8x-7664-px9q.json index 8d5986ca54b..738e56f9d27 100644 --- a/advisories/unreviewed/2022/04/GHSA-rv8x-7664-px9q/GHSA-rv8x-7664-px9q.json +++ b/advisories/unreviewed/2022/04/GHSA-rv8x-7664-px9q/GHSA-rv8x-7664-px9q.json @@ -7,12 +7,8 @@ "CVE-2004-1854" ], "details": "Buffer overflow in the logging function in Picophone 1.63 and earlier allows remote attackers to execute arbitrary code via a large packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v3ww-wfpr-x46c/GHSA-v3ww-wfpr-x46c.json b/advisories/unreviewed/2022/04/GHSA-v3ww-wfpr-x46c/GHSA-v3ww-wfpr-x46c.json index ec52dd9b942..835b48d4e1a 100644 --- a/advisories/unreviewed/2022/04/GHSA-v3ww-wfpr-x46c/GHSA-v3ww-wfpr-x46c.json +++ b/advisories/unreviewed/2022/04/GHSA-v3ww-wfpr-x46c/GHSA-v3ww-wfpr-x46c.json @@ -7,12 +7,8 @@ "CVE-2004-1987" ], "details": "picmgmtbatch.inc.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to execute arbitrary commands via shell metacharacters in the (1) $CONFIG['impath'] or (2) $CONFIG['jpeg_qual'] parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v4vm-wxg8-67rq/GHSA-v4vm-wxg8-67rq.json b/advisories/unreviewed/2022/04/GHSA-v4vm-wxg8-67rq/GHSA-v4vm-wxg8-67rq.json index 824c52eea42..457a8c88eed 100644 --- a/advisories/unreviewed/2022/04/GHSA-v4vm-wxg8-67rq/GHSA-v4vm-wxg8-67rq.json +++ b/advisories/unreviewed/2022/04/GHSA-v4vm-wxg8-67rq/GHSA-v4vm-wxg8-67rq.json @@ -7,12 +7,8 @@ "CVE-2004-1841" ], "details": "SQL injection vulnerability in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL via the referer field in an HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v4w2-7m6f-rxm5/GHSA-v4w2-7m6f-rxm5.json b/advisories/unreviewed/2022/04/GHSA-v4w2-7m6f-rxm5/GHSA-v4w2-7m6f-rxm5.json index 4748c677efe..6f19e642239 100644 --- a/advisories/unreviewed/2022/04/GHSA-v4w2-7m6f-rxm5/GHSA-v4w2-7m6f-rxm5.json +++ b/advisories/unreviewed/2022/04/GHSA-v4w2-7m6f-rxm5/GHSA-v4w2-7m6f-rxm5.json @@ -7,12 +7,8 @@ "CVE-2004-1915" ], "details": "Buffer overflow in the parse_all_client_messages function in LCDproc 0.4.x up to 0.4.4 allows remote attackers to execute arbitrary code via a large number of arguments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v6rm-r85m-cc6r/GHSA-v6rm-r85m-cc6r.json b/advisories/unreviewed/2022/04/GHSA-v6rm-r85m-cc6r/GHSA-v6rm-r85m-cc6r.json index 2b61a47dc5d..ecb5743002e 100644 --- a/advisories/unreviewed/2022/04/GHSA-v6rm-r85m-cc6r/GHSA-v6rm-r85m-cc6r.json +++ b/advisories/unreviewed/2022/04/GHSA-v6rm-r85m-cc6r/GHSA-v6rm-r85m-cc6r.json @@ -7,12 +7,8 @@ "CVE-2004-1783" ], "details": "Directory traversal vulnerability in Net2Soft Flash FTP Server 1.0 allows remote attackers to read and create arbitrary files via a /.. (slash dot dot).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v8mh-rhjf-h2w7/GHSA-v8mh-rhjf-h2w7.json b/advisories/unreviewed/2022/04/GHSA-v8mh-rhjf-h2w7/GHSA-v8mh-rhjf-h2w7.json index abb4d9f0c7f..a88fb0070c1 100644 --- a/advisories/unreviewed/2022/04/GHSA-v8mh-rhjf-h2w7/GHSA-v8mh-rhjf-h2w7.json +++ b/advisories/unreviewed/2022/04/GHSA-v8mh-rhjf-h2w7/GHSA-v8mh-rhjf-h2w7.json @@ -7,12 +7,8 @@ "CVE-2004-2011" ], "details": "msxml3.dll in Internet Explorer 6.0.2600.0 allows remote attackers to cause a denial of service (crash) via a single & (ampersand) in a link, which triggers a parsing error, possibly due to missing portions of the URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v8rp-6wh5-2p3m/GHSA-v8rp-6wh5-2p3m.json b/advisories/unreviewed/2022/04/GHSA-v8rp-6wh5-2p3m/GHSA-v8rp-6wh5-2p3m.json index 5a5f05569c2..ba436769c79 100644 --- a/advisories/unreviewed/2022/04/GHSA-v8rp-6wh5-2p3m/GHSA-v8rp-6wh5-2p3m.json +++ b/advisories/unreviewed/2022/04/GHSA-v8rp-6wh5-2p3m/GHSA-v8rp-6wh5-2p3m.json @@ -7,12 +7,8 @@ "CVE-2004-1896" ], "details": "Heap-based buffer overflow in in_mod.dll in Nullsoft Winamp 2.91 through 5.02 allows remote attackers to execute arbitrary code via a Fasttracker 2 (.xm) mod media file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vf93-36m7-4c54/GHSA-vf93-36m7-4c54.json b/advisories/unreviewed/2022/04/GHSA-vf93-36m7-4c54/GHSA-vf93-36m7-4c54.json index 640514d9414..ca5d4fb991d 100644 --- a/advisories/unreviewed/2022/04/GHSA-vf93-36m7-4c54/GHSA-vf93-36m7-4c54.json +++ b/advisories/unreviewed/2022/04/GHSA-vf93-36m7-4c54/GHSA-vf93-36m7-4c54.json @@ -7,12 +7,8 @@ "CVE-2004-1797" ], "details": "Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vfwc-cq87-4vm7/GHSA-vfwc-cq87-4vm7.json b/advisories/unreviewed/2022/04/GHSA-vfwc-cq87-4vm7/GHSA-vfwc-cq87-4vm7.json index a2ec5395d80..8e8843b1d4f 100644 --- a/advisories/unreviewed/2022/04/GHSA-vfwc-cq87-4vm7/GHSA-vfwc-cq87-4vm7.json +++ b/advisories/unreviewed/2022/04/GHSA-vfwc-cq87-4vm7/GHSA-vfwc-cq87-4vm7.json @@ -7,12 +7,8 @@ "CVE-2004-1905" ], "details": "ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to cause a denial of service (crash) by calling the SetSitesFile function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vjcm-w2jx-chjr/GHSA-vjcm-w2jx-chjr.json b/advisories/unreviewed/2022/04/GHSA-vjcm-w2jx-chjr/GHSA-vjcm-w2jx-chjr.json index 92f0d6f2cbe..795074cf118 100644 --- a/advisories/unreviewed/2022/04/GHSA-vjcm-w2jx-chjr/GHSA-vjcm-w2jx-chjr.json +++ b/advisories/unreviewed/2022/04/GHSA-vjcm-w2jx-chjr/GHSA-vjcm-w2jx-chjr.json @@ -7,12 +7,8 @@ "CVE-2004-1836" ], "details": "SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vjgj-h698-pm55/GHSA-vjgj-h698-pm55.json b/advisories/unreviewed/2022/04/GHSA-vjgj-h698-pm55/GHSA-vjgj-h698-pm55.json index 0ac4bbeea66..921f6630f2e 100644 --- a/advisories/unreviewed/2022/04/GHSA-vjgj-h698-pm55/GHSA-vjgj-h698-pm55.json +++ b/advisories/unreviewed/2022/04/GHSA-vjgj-h698-pm55/GHSA-vjgj-h698-pm55.json @@ -7,12 +7,8 @@ "CVE-2004-1969" ], "details": "The avatar upload capability in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to execute arbitrary script by uploading files that include scripting code such as Javascript.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vjxj-m6c9-fgcv/GHSA-vjxj-m6c9-fgcv.json b/advisories/unreviewed/2022/04/GHSA-vjxj-m6c9-fgcv/GHSA-vjxj-m6c9-fgcv.json index f941764f8b3..466511bbcd6 100644 --- a/advisories/unreviewed/2022/04/GHSA-vjxj-m6c9-fgcv/GHSA-vjxj-m6c9-fgcv.json +++ b/advisories/unreviewed/2022/04/GHSA-vjxj-m6c9-fgcv/GHSA-vjxj-m6c9-fgcv.json @@ -7,12 +7,8 @@ "CVE-2004-1960" ], "details": "Cross-site scripting (XSS) vulnerability in blocker_query.php in Protector System 1.15b1 allows remote attackers to inject arbitrary web script or HTML via the (1) target or (2) portNum parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vmm4-7qmq-qh94/GHSA-vmm4-7qmq-qh94.json b/advisories/unreviewed/2022/04/GHSA-vmm4-7qmq-qh94/GHSA-vmm4-7qmq-qh94.json index 2fd87366c1f..6cf7b664ded 100644 --- a/advisories/unreviewed/2022/04/GHSA-vmm4-7qmq-qh94/GHSA-vmm4-7qmq-qh94.json +++ b/advisories/unreviewed/2022/04/GHSA-vmm4-7qmq-qh94/GHSA-vmm4-7qmq-qh94.json @@ -7,12 +7,8 @@ "CVE-2004-1928" ], "details": "The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-vmp6-pc7f-w28v/GHSA-vmp6-pc7f-w28v.json b/advisories/unreviewed/2022/04/GHSA-vmp6-pc7f-w28v/GHSA-vmp6-pc7f-w28v.json index 4a0afc8c005..50adaba4160 100644 --- a/advisories/unreviewed/2022/04/GHSA-vmp6-pc7f-w28v/GHSA-vmp6-pc7f-w28v.json +++ b/advisories/unreviewed/2022/04/GHSA-vmp6-pc7f-w28v/GHSA-vmp6-pc7f-w28v.json @@ -7,12 +7,8 @@ "CVE-2004-1996" ], "details": "Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vq2p-3c23-ghfm/GHSA-vq2p-3c23-ghfm.json b/advisories/unreviewed/2022/04/GHSA-vq2p-3c23-ghfm/GHSA-vq2p-3c23-ghfm.json index 736681bd000..2dc36d8f5d5 100644 --- a/advisories/unreviewed/2022/04/GHSA-vq2p-3c23-ghfm/GHSA-vq2p-3c23-ghfm.json +++ b/advisories/unreviewed/2022/04/GHSA-vq2p-3c23-ghfm/GHSA-vq2p-3c23-ghfm.json @@ -7,12 +7,8 @@ "CVE-2004-1287" ], "details": "Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1194.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-vq7j-qwwp-ggc5/GHSA-vq7j-qwwp-ggc5.json b/advisories/unreviewed/2022/04/GHSA-vq7j-qwwp-ggc5/GHSA-vq7j-qwwp-ggc5.json index 072e55d1baa..4480c0650d8 100644 --- a/advisories/unreviewed/2022/04/GHSA-vq7j-qwwp-ggc5/GHSA-vq7j-qwwp-ggc5.json +++ b/advisories/unreviewed/2022/04/GHSA-vq7j-qwwp-ggc5/GHSA-vq7j-qwwp-ggc5.json @@ -7,12 +7,8 @@ "CVE-2004-2020" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 6.x through 7.3 allow remote attackers to inject arbitrary HTML or web script into the (1) optionbox parameter in the News module, (2) date parameter in the Statistics module, (3) year, month, and month_1 parameters in the Stories_Archive module, (4) mode, order, and thold parameters in the Surveys module, or (5) a SQL statement to index.php, as processed by mainfile.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vv4x-wgcc-mrm8/GHSA-vv4x-wgcc-mrm8.json b/advisories/unreviewed/2022/04/GHSA-vv4x-wgcc-mrm8/GHSA-vv4x-wgcc-mrm8.json index ca2edcf4044..5edaf188672 100644 --- a/advisories/unreviewed/2022/04/GHSA-vv4x-wgcc-mrm8/GHSA-vv4x-wgcc-mrm8.json +++ b/advisories/unreviewed/2022/04/GHSA-vv4x-wgcc-mrm8/GHSA-vv4x-wgcc-mrm8.json @@ -7,12 +7,8 @@ "CVE-2004-1939" ], "details": "Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows remote attackers to inject arbitrary web script or HTML via double encoded slashes (%252F) in the key parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vw9j-rf4j-gmjh/GHSA-vw9j-rf4j-gmjh.json b/advisories/unreviewed/2022/04/GHSA-vw9j-rf4j-gmjh/GHSA-vw9j-rf4j-gmjh.json index 3e20a3c64d6..e752f7cb7e1 100644 --- a/advisories/unreviewed/2022/04/GHSA-vw9j-rf4j-gmjh/GHSA-vw9j-rf4j-gmjh.json +++ b/advisories/unreviewed/2022/04/GHSA-vw9j-rf4j-gmjh/GHSA-vw9j-rf4j-gmjh.json @@ -7,12 +7,8 @@ "CVE-2004-1874" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in (1) deliver.asp and (2) billing.asp in A-CART Pro and A-CART 2.0 allow remote attackers to inject arbitrary web script or HTML via the user information forms.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vwg6-cfrq-8wvg/GHSA-vwg6-cfrq-8wvg.json b/advisories/unreviewed/2022/04/GHSA-vwg6-cfrq-8wvg/GHSA-vwg6-cfrq-8wvg.json index a2d5e31a4ac..c822a436dae 100644 --- a/advisories/unreviewed/2022/04/GHSA-vwg6-cfrq-8wvg/GHSA-vwg6-cfrq-8wvg.json +++ b/advisories/unreviewed/2022/04/GHSA-vwg6-cfrq-8wvg/GHSA-vwg6-cfrq-8wvg.json @@ -7,12 +7,8 @@ "CVE-2004-1843" ], "details": "SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1) resend.asp or (2) news_view.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vxjx-8m3j-mpp3/GHSA-vxjx-8m3j-mpp3.json b/advisories/unreviewed/2022/04/GHSA-vxjx-8m3j-mpp3/GHSA-vxjx-8m3j-mpp3.json index 1a00d83476f..221b44e8488 100644 --- a/advisories/unreviewed/2022/04/GHSA-vxjx-8m3j-mpp3/GHSA-vxjx-8m3j-mpp3.json +++ b/advisories/unreviewed/2022/04/GHSA-vxjx-8m3j-mpp3/GHSA-vxjx-8m3j-mpp3.json @@ -7,12 +7,8 @@ "CVE-2004-1840" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) screen parameter to modules.php, (2) module_name parameter to title.php, (3) sortby parameter to modules.php, or (4) overview parameter to modules.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vxw3-68g9-x558/GHSA-vxw3-68g9-x558.json b/advisories/unreviewed/2022/04/GHSA-vxw3-68g9-x558/GHSA-vxw3-68g9-x558.json index 1d475777dd7..bf262601d41 100644 --- a/advisories/unreviewed/2022/04/GHSA-vxw3-68g9-x558/GHSA-vxw3-68g9-x558.json +++ b/advisories/unreviewed/2022/04/GHSA-vxw3-68g9-x558/GHSA-vxw3-68g9-x558.json @@ -7,12 +7,8 @@ "CVE-2004-1975" ], "details": "Cross-site scripting (XSS) vulnerability in the category module in pafiledb.php for paFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a vulnerability that is closely related to CVE-2004-1551.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w2mv-f4m8-rcvc/GHSA-w2mv-f4m8-rcvc.json b/advisories/unreviewed/2022/04/GHSA-w2mv-f4m8-rcvc/GHSA-w2mv-f4m8-rcvc.json index 92150e5a2cc..ef346f2c056 100644 --- a/advisories/unreviewed/2022/04/GHSA-w2mv-f4m8-rcvc/GHSA-w2mv-f4m8-rcvc.json +++ b/advisories/unreviewed/2022/04/GHSA-w2mv-f4m8-rcvc/GHSA-w2mv-f4m8-rcvc.json @@ -7,12 +7,8 @@ "CVE-2004-1992" ], "details": "Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-w3f5-399x-3cvh/GHSA-w3f5-399x-3cvh.json b/advisories/unreviewed/2022/04/GHSA-w3f5-399x-3cvh/GHSA-w3f5-399x-3cvh.json index da76efa0d7e..c6c5bf074cc 100644 --- a/advisories/unreviewed/2022/04/GHSA-w3f5-399x-3cvh/GHSA-w3f5-399x-3cvh.json +++ b/advisories/unreviewed/2022/04/GHSA-w3f5-399x-3cvh/GHSA-w3f5-399x-3cvh.json @@ -7,12 +7,8 @@ "CVE-2004-1961" ], "details": "blocker.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection protection and execute limited SQL commands via URL-encoded \"'\" characters (\"%27\").", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w4rg-v5fv-3pgx/GHSA-w4rg-v5fv-3pgx.json b/advisories/unreviewed/2022/04/GHSA-w4rg-v5fv-3pgx/GHSA-w4rg-v5fv-3pgx.json index 48dc5caf995..8ca25323485 100644 --- a/advisories/unreviewed/2022/04/GHSA-w4rg-v5fv-3pgx/GHSA-w4rg-v5fv-3pgx.json +++ b/advisories/unreviewed/2022/04/GHSA-w4rg-v5fv-3pgx/GHSA-w4rg-v5fv-3pgx.json @@ -7,12 +7,8 @@ "CVE-2004-1867" ], "details": "Cross-site scripting (XSS) vulnerability in guest.cgi in Fresh Guest Book allows remote attackers to inject arbitrary web script or HTML via the Name field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w95m-6gwv-7rhp/GHSA-w95m-6gwv-7rhp.json b/advisories/unreviewed/2022/04/GHSA-w95m-6gwv-7rhp/GHSA-w95m-6gwv-7rhp.json index 24a61e3fcf8..c59e297bb3d 100644 --- a/advisories/unreviewed/2022/04/GHSA-w95m-6gwv-7rhp/GHSA-w95m-6gwv-7rhp.json +++ b/advisories/unreviewed/2022/04/GHSA-w95m-6gwv-7rhp/GHSA-w95m-6gwv-7rhp.json @@ -7,12 +7,8 @@ "CVE-2004-1951" ], "details": "xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wcj2-4gw4-246h/GHSA-wcj2-4gw4-246h.json b/advisories/unreviewed/2022/04/GHSA-wcj2-4gw4-246h/GHSA-wcj2-4gw4-246h.json index a6cc1fbe6e5..fedf170f234 100644 --- a/advisories/unreviewed/2022/04/GHSA-wcj2-4gw4-246h/GHSA-wcj2-4gw4-246h.json +++ b/advisories/unreviewed/2022/04/GHSA-wcj2-4gw4-246h/GHSA-wcj2-4gw4-246h.json @@ -7,12 +7,8 @@ "CVE-2004-1922" ], "details": "Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cause a denial of service (memory consumption) via a small BMP file with has a large memory size.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wg96-v96x-6mjw/GHSA-wg96-v96x-6mjw.json b/advisories/unreviewed/2022/04/GHSA-wg96-v96x-6mjw/GHSA-wg96-v96x-6mjw.json index 26a271b8d13..68fbb587999 100644 --- a/advisories/unreviewed/2022/04/GHSA-wg96-v96x-6mjw/GHSA-wg96-v96x-6mjw.json +++ b/advisories/unreviewed/2022/04/GHSA-wg96-v96x-6mjw/GHSA-wg96-v96x-6mjw.json @@ -7,12 +7,8 @@ "CVE-2004-2025" ], "details": "SQL injection vulnerability in application_top.php for Zen Cart 1.1.3 before patch 2 may allow remote attackers to execute arbitrary SQL commands via the products_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wm2x-pgq2-vxxm/GHSA-wm2x-pgq2-vxxm.json b/advisories/unreviewed/2022/04/GHSA-wm2x-pgq2-vxxm/GHSA-wm2x-pgq2-vxxm.json index ea699659476..75e6798132d 100644 --- a/advisories/unreviewed/2022/04/GHSA-wm2x-pgq2-vxxm/GHSA-wm2x-pgq2-vxxm.json +++ b/advisories/unreviewed/2022/04/GHSA-wm2x-pgq2-vxxm/GHSA-wm2x-pgq2-vxxm.json @@ -7,12 +7,8 @@ "CVE-2004-1769" ], "details": "The \"Allow cPanel users to reset their password via email\" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the user parameter to resetpass.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wvxw-c559-6g48/GHSA-wvxw-c559-6g48.json b/advisories/unreviewed/2022/04/GHSA-wvxw-c559-6g48/GHSA-wvxw-c559-6g48.json index 3e39de7feba..bbf79fa304f 100644 --- a/advisories/unreviewed/2022/04/GHSA-wvxw-c559-6g48/GHSA-wvxw-c559-6g48.json +++ b/advisories/unreviewed/2022/04/GHSA-wvxw-c559-6g48/GHSA-wvxw-c559-6g48.json @@ -7,12 +7,8 @@ "CVE-2004-1790" ], "details": "Cross-site scripting (XSS) vulnerability in the web management interface in Edimax AR-6004 ADSL Routers allows remote attackers to inject arbitrary web script or HTML via the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x22v-5fx6-wj7x/GHSA-x22v-5fx6-wj7x.json b/advisories/unreviewed/2022/04/GHSA-x22v-5fx6-wj7x/GHSA-x22v-5fx6-wj7x.json index 52171f9502e..1e8bfdc2741 100644 --- a/advisories/unreviewed/2022/04/GHSA-x22v-5fx6-wj7x/GHSA-x22v-5fx6-wj7x.json +++ b/advisories/unreviewed/2022/04/GHSA-x22v-5fx6-wj7x/GHSA-x22v-5fx6-wj7x.json @@ -7,12 +7,8 @@ "CVE-2004-2019" ], "details": "The WebLinks module in Php-Nuke 6.x through 7.3 allows remote attackers to obtain sensitive information via an invalid show parameter, which displays the full path in a PHP error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x38v-xq6h-466m/GHSA-x38v-xq6h-466m.json b/advisories/unreviewed/2022/04/GHSA-x38v-xq6h-466m/GHSA-x38v-xq6h-466m.json index 8946a0e1515..2b7eb47e6fd 100644 --- a/advisories/unreviewed/2022/04/GHSA-x38v-xq6h-466m/GHSA-x38v-xq6h-466m.json +++ b/advisories/unreviewed/2022/04/GHSA-x38v-xq6h-466m/GHSA-x38v-xq6h-466m.json @@ -7,12 +7,8 @@ "CVE-2004-2021" ], "details": "Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the filename argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x4g8-q528-mj92/GHSA-x4g8-q528-mj92.json b/advisories/unreviewed/2022/04/GHSA-x4g8-q528-mj92/GHSA-x4g8-q528-mj92.json index a4951eba7d5..b47eb82183c 100644 --- a/advisories/unreviewed/2022/04/GHSA-x4g8-q528-mj92/GHSA-x4g8-q528-mj92.json +++ b/advisories/unreviewed/2022/04/GHSA-x4g8-q528-mj92/GHSA-x4g8-q528-mj92.json @@ -7,12 +7,8 @@ "CVE-2004-1988" ], "details": "PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by modifying the CPG_M_DIR to reference a URL on a remote web server that contains functions.inc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x5v2-7jcx-j662/GHSA-x5v2-7jcx-j662.json b/advisories/unreviewed/2022/04/GHSA-x5v2-7jcx-j662/GHSA-x5v2-7jcx-j662.json index ddd59c1afc6..1956113118c 100644 --- a/advisories/unreviewed/2022/04/GHSA-x5v2-7jcx-j662/GHSA-x5v2-7jcx-j662.json +++ b/advisories/unreviewed/2022/04/GHSA-x5v2-7jcx-j662/GHSA-x5v2-7jcx-j662.json @@ -7,12 +7,8 @@ "CVE-2004-1955" ], "details": "SQL injection vulnerability in modules.php in phProfession 2.5 allows remote attackers to execute arbitrary SQL code via the offset parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x649-66mv-2jp4/GHSA-x649-66mv-2jp4.json b/advisories/unreviewed/2022/04/GHSA-x649-66mv-2jp4/GHSA-x649-66mv-2jp4.json index bcdbc346b2b..eb85a230638 100644 --- a/advisories/unreviewed/2022/04/GHSA-x649-66mv-2jp4/GHSA-x649-66mv-2jp4.json +++ b/advisories/unreviewed/2022/04/GHSA-x649-66mv-2jp4/GHSA-x649-66mv-2jp4.json @@ -7,12 +7,8 @@ "CVE-2004-2016" ], "details": "Stack-based buffer overflow in the HTTP server in NetChat 7.3 and earlier allows remote attackers to execute arbitrary code via a long GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x764-624g-c724/GHSA-x764-624g-c724.json b/advisories/unreviewed/2022/04/GHSA-x764-624g-c724/GHSA-x764-624g-c724.json index b4c1f0efd9e..6c673b6c07b 100644 --- a/advisories/unreviewed/2022/04/GHSA-x764-624g-c724/GHSA-x764-624g-c724.json +++ b/advisories/unreviewed/2022/04/GHSA-x764-624g-c724/GHSA-x764-624g-c724.json @@ -7,12 +7,8 @@ "CVE-2004-1849" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to dodelautores.html or (2) handle parameter to addhandle.html.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x776-58qh-fr46/GHSA-x776-58qh-fr46.json b/advisories/unreviewed/2022/04/GHSA-x776-58qh-fr46/GHSA-x776-58qh-fr46.json index 1d13eb42bc0..d3b16ce2412 100644 --- a/advisories/unreviewed/2022/04/GHSA-x776-58qh-fr46/GHSA-x776-58qh-fr46.json +++ b/advisories/unreviewed/2022/04/GHSA-x776-58qh-fr46/GHSA-x776-58qh-fr46.json @@ -7,12 +7,8 @@ "CVE-2004-1816" ], "details": "Unknown vulnerability in Sun Java System Application Server 7.0 Update 2 and earlier, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x96w-xjqr-q3h6/GHSA-x96w-xjqr-q3h6.json b/advisories/unreviewed/2022/04/GHSA-x96w-xjqr-q3h6/GHSA-x96w-xjqr-q3h6.json index daad444741e..f209710d2ec 100644 --- a/advisories/unreviewed/2022/04/GHSA-x96w-xjqr-q3h6/GHSA-x96w-xjqr-q3h6.json +++ b/advisories/unreviewed/2022/04/GHSA-x96w-xjqr-q3h6/GHSA-x96w-xjqr-q3h6.json @@ -7,12 +7,8 @@ "CVE-2004-1959" ], "details": "blocker_query.php in Protector System 1.15b1 for PHP-Nuke allows remote attackers to gain sensitive information via a string in the portNum parameter, which reveals the full path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xc66-h8vr-gh7j/GHSA-xc66-h8vr-gh7j.json b/advisories/unreviewed/2022/04/GHSA-xc66-h8vr-gh7j/GHSA-xc66-h8vr-gh7j.json index f90546b5761..6724e293253 100644 --- a/advisories/unreviewed/2022/04/GHSA-xc66-h8vr-gh7j/GHSA-xc66-h8vr-gh7j.json +++ b/advisories/unreviewed/2022/04/GHSA-xc66-h8vr-gh7j/GHSA-xc66-h8vr-gh7j.json @@ -7,12 +7,8 @@ "CVE-2004-2024" ], "details": "The distribution of Zen Cart 1.1.4 before patch 2 includes certain debugging code in the Admin password retrieval functionality, which allows attackers to gain administrative privileges via password_forgotten.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xh4h-8w7q-32rw/GHSA-xh4h-8w7q-32rw.json b/advisories/unreviewed/2022/04/GHSA-xh4h-8w7q-32rw/GHSA-xh4h-8w7q-32rw.json index 4c6130e8853..bec65f9a423 100644 --- a/advisories/unreviewed/2022/04/GHSA-xh4h-8w7q-32rw/GHSA-xh4h-8w7q-32rw.json +++ b/advisories/unreviewed/2022/04/GHSA-xh4h-8w7q-32rw/GHSA-xh4h-8w7q-32rw.json @@ -7,12 +7,8 @@ "CVE-2004-2030" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the message subject.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-xhfv-px5v-xvpj/GHSA-xhfv-px5v-xvpj.json b/advisories/unreviewed/2022/04/GHSA-xhfv-px5v-xvpj/GHSA-xhfv-px5v-xvpj.json index cd5430a1f81..969eeab8a43 100644 --- a/advisories/unreviewed/2022/04/GHSA-xhfv-px5v-xvpj/GHSA-xhfv-px5v-xvpj.json +++ b/advisories/unreviewed/2022/04/GHSA-xhfv-px5v-xvpj/GHSA-xhfv-px5v-xvpj.json @@ -7,12 +7,8 @@ "CVE-2004-2033" ], "details": "Orenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xm94-gcw3-hgpv/GHSA-xm94-gcw3-hgpv.json b/advisories/unreviewed/2022/04/GHSA-xm94-gcw3-hgpv/GHSA-xm94-gcw3-hgpv.json index 8549b5fdc10..298eccd2c66 100644 --- a/advisories/unreviewed/2022/04/GHSA-xm94-gcw3-hgpv/GHSA-xm94-gcw3-hgpv.json +++ b/advisories/unreviewed/2022/04/GHSA-xm94-gcw3-hgpv/GHSA-xm94-gcw3-hgpv.json @@ -7,12 +7,8 @@ "CVE-2004-1968" ], "details": "The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbitrary messages by modifying the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xmw9-gg4q-2f2x/GHSA-xmw9-gg4q-2f2x.json b/advisories/unreviewed/2022/04/GHSA-xmw9-gg4q-2f2x/GHSA-xmw9-gg4q-2f2x.json index 0257cb850cd..4b8103809f4 100644 --- a/advisories/unreviewed/2022/04/GHSA-xmw9-gg4q-2f2x/GHSA-xmw9-gg4q-2f2x.json +++ b/advisories/unreviewed/2022/04/GHSA-xmw9-gg4q-2f2x/GHSA-xmw9-gg4q-2f2x.json @@ -7,12 +7,8 @@ "CVE-2004-1898" ], "details": "Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xpp9-cvrv-9rvf/GHSA-xpp9-cvrv-9rvf.json b/advisories/unreviewed/2022/04/GHSA-xpp9-cvrv-9rvf/GHSA-xpp9-cvrv-9rvf.json index a31321302ef..be5d9bd9ea3 100644 --- a/advisories/unreviewed/2022/04/GHSA-xpp9-cvrv-9rvf/GHSA-xpp9-cvrv-9rvf.json +++ b/advisories/unreviewed/2022/04/GHSA-xpp9-cvrv-9rvf/GHSA-xpp9-cvrv-9rvf.json @@ -7,12 +7,8 @@ "CVE-2004-1787" ], "details": "SQL injection vulnerability in PostCalendar 4.0.0 allows remote attackers to execute arbitrary SQL commands via search queries.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xv5v-4g23-pxj9/GHSA-xv5v-4g23-pxj9.json b/advisories/unreviewed/2022/04/GHSA-xv5v-4g23-pxj9/GHSA-xv5v-4g23-pxj9.json index 39a4209956c..72c6194852d 100644 --- a/advisories/unreviewed/2022/04/GHSA-xv5v-4g23-pxj9/GHSA-xv5v-4g23-pxj9.json +++ b/advisories/unreviewed/2022/04/GHSA-xv5v-4g23-pxj9/GHSA-xv5v-4g23-pxj9.json @@ -7,12 +7,8 @@ "CVE-2004-1903" ], "details": "Buffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an object tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xvhq-4mp3-f354/GHSA-xvhq-4mp3-f354.json b/advisories/unreviewed/2022/04/GHSA-xvhq-4mp3-f354/GHSA-xvhq-4mp3-f354.json index c84ca74a8d9..8e0e6c76746 100644 --- a/advisories/unreviewed/2022/04/GHSA-xvhq-4mp3-f354/GHSA-xvhq-4mp3-f354.json +++ b/advisories/unreviewed/2022/04/GHSA-xvhq-4mp3-f354/GHSA-xvhq-4mp3-f354.json @@ -7,12 +7,8 @@ "CVE-2004-2008" ], "details": "SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xwr7-j9pf-gg7p/GHSA-xwr7-j9pf-gg7p.json b/advisories/unreviewed/2022/04/GHSA-xwr7-j9pf-gg7p/GHSA-xwr7-j9pf-gg7p.json index 9cb6d5a74f0..a27001f8d24 100644 --- a/advisories/unreviewed/2022/04/GHSA-xwr7-j9pf-gg7p/GHSA-xwr7-j9pf-gg7p.json +++ b/advisories/unreviewed/2022/04/GHSA-xwr7-j9pf-gg7p/GHSA-xwr7-j9pf-gg7p.json @@ -7,12 +7,8 @@ "CVE-2004-1964" ], "details": "Cross-site scripting (XSS) vulnerability in nqt.php in Network Query Tool (NQT) 1.6 allows remote attackers to inject arbitrary web script or HTML via the portNum parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-22qf-w2wm-5686/GHSA-22qf-w2wm-5686.json b/advisories/unreviewed/2022/05/GHSA-22qf-w2wm-5686/GHSA-22qf-w2wm-5686.json index 9106ddc335b..a0c088f029b 100644 --- a/advisories/unreviewed/2022/05/GHSA-22qf-w2wm-5686/GHSA-22qf-w2wm-5686.json +++ b/advisories/unreviewed/2022/05/GHSA-22qf-w2wm-5686/GHSA-22qf-w2wm-5686.json @@ -7,12 +7,8 @@ "CVE-2020-10927" ], "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the encryption of firmware update images. The issue results from the use of an inappropriate encryption algorithm. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-9649.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-23cw-p4x6-mcqc/GHSA-23cw-p4x6-mcqc.json b/advisories/unreviewed/2022/05/GHSA-23cw-p4x6-mcqc/GHSA-23cw-p4x6-mcqc.json index 142414c9830..b863dffd9bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-23cw-p4x6-mcqc/GHSA-23cw-p4x6-mcqc.json +++ b/advisories/unreviewed/2022/05/GHSA-23cw-p4x6-mcqc/GHSA-23cw-p4x6-mcqc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-23g6-ppxq-qcwm/GHSA-23g6-ppxq-qcwm.json b/advisories/unreviewed/2022/05/GHSA-23g6-ppxq-qcwm/GHSA-23g6-ppxq-qcwm.json index edd1d997f66..0ecd9775129 100644 --- a/advisories/unreviewed/2022/05/GHSA-23g6-ppxq-qcwm/GHSA-23g6-ppxq-qcwm.json +++ b/advisories/unreviewed/2022/05/GHSA-23g6-ppxq-qcwm/GHSA-23g6-ppxq-qcwm.json @@ -7,12 +7,8 @@ "CVE-2020-10920" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the control service, which listens on TCP port 9999 by default. The issue results from the lack of authentication prior to allowing alterations to the system configuration. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-10493.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-24pm-ccpf-9wgw/GHSA-24pm-ccpf-9wgw.json b/advisories/unreviewed/2022/05/GHSA-24pm-ccpf-9wgw/GHSA-24pm-ccpf-9wgw.json index 7982435fe35..ec3e04bd72b 100644 --- a/advisories/unreviewed/2022/05/GHSA-24pm-ccpf-9wgw/GHSA-24pm-ccpf-9wgw.json +++ b/advisories/unreviewed/2022/05/GHSA-24pm-ccpf-9wgw/GHSA-24pm-ccpf-9wgw.json @@ -7,12 +7,8 @@ "CVE-2020-2077" ], "details": "SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker could read sensitive data from the system by querying for known files using the REST API directly.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-255j-2693-vhwc/GHSA-255j-2693-vhwc.json b/advisories/unreviewed/2022/05/GHSA-255j-2693-vhwc/GHSA-255j-2693-vhwc.json index 4e37317f2f4..6c95dcfc43e 100644 --- a/advisories/unreviewed/2022/05/GHSA-255j-2693-vhwc/GHSA-255j-2693-vhwc.json +++ b/advisories/unreviewed/2022/05/GHSA-255j-2693-vhwc/GHSA-255j-2693-vhwc.json @@ -7,12 +7,8 @@ "CVE-2020-9078" ], "details": "FusionCompute 8.0.0 have local privilege escalation vulnerability. A local, authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-256w-3jc2-hh38/GHSA-256w-3jc2-hh38.json b/advisories/unreviewed/2022/05/GHSA-256w-3jc2-hh38/GHSA-256w-3jc2-hh38.json index 255e298a92b..41a53ef21c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-256w-3jc2-hh38/GHSA-256w-3jc2-hh38.json +++ b/advisories/unreviewed/2022/05/GHSA-256w-3jc2-hh38/GHSA-256w-3jc2-hh38.json @@ -7,12 +7,8 @@ "CVE-2020-16215" ], "details": "Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause a stack-based buffer overflow, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-287m-mj3j-wvc9/GHSA-287m-mj3j-wvc9.json b/advisories/unreviewed/2022/05/GHSA-287m-mj3j-wvc9/GHSA-287m-mj3j-wvc9.json index d34a650f964..ce726ed00dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-287m-mj3j-wvc9/GHSA-287m-mj3j-wvc9.json +++ b/advisories/unreviewed/2022/05/GHSA-287m-mj3j-wvc9/GHSA-287m-mj3j-wvc9.json @@ -7,12 +7,8 @@ "CVE-2020-7518" ], "details": "A CWE-20: Improper input validation vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to modify project configuration files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-28w3-wp3w-h9m8/GHSA-28w3-wp3w-h9m8.json b/advisories/unreviewed/2022/05/GHSA-28w3-wp3w-h9m8/GHSA-28w3-wp3w-h9m8.json index 43fde5211b3..a89913f3e2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-28w3-wp3w-h9m8/GHSA-28w3-wp3w-h9m8.json +++ b/advisories/unreviewed/2022/05/GHSA-28w3-wp3w-h9m8/GHSA-28w3-wp3w-h9m8.json @@ -7,12 +7,8 @@ "CVE-2019-14101" ], "details": "Out of bounds read can happen in diag event set mask command handler when user provided length in the command request is less than expected length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8096, APQ8096AU, APQ8098, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCM2150, QCN7605, QCS404, QCS405, QCS605, QM215, Rennell, SA415M, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-294f-mx29-rgp2/GHSA-294f-mx29-rgp2.json b/advisories/unreviewed/2022/05/GHSA-294f-mx29-rgp2/GHSA-294f-mx29-rgp2.json index b2b2bbc11e1..2628336277e 100644 --- a/advisories/unreviewed/2022/05/GHSA-294f-mx29-rgp2/GHSA-294f-mx29-rgp2.json +++ b/advisories/unreviewed/2022/05/GHSA-294f-mx29-rgp2/GHSA-294f-mx29-rgp2.json @@ -7,12 +7,8 @@ "CVE-2019-20001" ], "details": "An issue was discovered in RICOH Streamline NX Client Tool and RICOH Streamline NX PC Client that allows attackers to escalate local privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fj3-jhcw-972x/GHSA-2fj3-jhcw-972x.json b/advisories/unreviewed/2022/05/GHSA-2fj3-jhcw-972x/GHSA-2fj3-jhcw-972x.json index 450ec6b4774..726841a6035 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fj3-jhcw-972x/GHSA-2fj3-jhcw-972x.json +++ b/advisories/unreviewed/2022/05/GHSA-2fj3-jhcw-972x/GHSA-2fj3-jhcw-972x.json @@ -7,12 +7,8 @@ "CVE-2020-5770" ], "details": "Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2h2r-w6vh-2w6r/GHSA-2h2r-w6vh-2w6r.json b/advisories/unreviewed/2022/05/GHSA-2h2r-w6vh-2w6r/GHSA-2h2r-w6vh-2w6r.json index 17169ad7529..439512f953d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2h2r-w6vh-2w6r/GHSA-2h2r-w6vh-2w6r.json +++ b/advisories/unreviewed/2022/05/GHSA-2h2r-w6vh-2w6r/GHSA-2h2r-w6vh-2w6r.json @@ -7,12 +7,8 @@ "CVE-2020-7827" ], "details": "DaviewIndy 8.98.7 and earlier version contain Use-After-Free vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2hq2-wmqr-66p5/GHSA-2hq2-wmqr-66p5.json b/advisories/unreviewed/2022/05/GHSA-2hq2-wmqr-66p5/GHSA-2hq2-wmqr-66p5.json index c1f24171e55..7cbed663fe0 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hq2-wmqr-66p5/GHSA-2hq2-wmqr-66p5.json +++ b/advisories/unreviewed/2022/05/GHSA-2hq2-wmqr-66p5/GHSA-2hq2-wmqr-66p5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2j77-c722-99hh/GHSA-2j77-c722-99hh.json b/advisories/unreviewed/2022/05/GHSA-2j77-c722-99hh/GHSA-2j77-c722-99hh.json index 616092e4a20..b6a23b1c71f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2j77-c722-99hh/GHSA-2j77-c722-99hh.json +++ b/advisories/unreviewed/2022/05/GHSA-2j77-c722-99hh/GHSA-2j77-c722-99hh.json @@ -7,12 +7,8 @@ "CVE-2020-15925" ], "details": "A SQL injection vulnerability at a tpf URI in Loway QueueMetrics before 19.10.21 allows remote authenticated attackers to execute arbitrary SQL commands via the TPF_XPAR1 parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2jpf-4r7j-42qr/GHSA-2jpf-4r7j-42qr.json b/advisories/unreviewed/2022/05/GHSA-2jpf-4r7j-42qr/GHSA-2jpf-4r7j-42qr.json index bc970e8d058..7419b4e665c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jpf-4r7j-42qr/GHSA-2jpf-4r7j-42qr.json +++ b/advisories/unreviewed/2022/05/GHSA-2jpf-4r7j-42qr/GHSA-2jpf-4r7j-42qr.json @@ -7,12 +7,8 @@ "CVE-2020-14311" ], "details": "There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2mxh-xfhw-gmr5/GHSA-2mxh-xfhw-gmr5.json b/advisories/unreviewed/2022/05/GHSA-2mxh-xfhw-gmr5/GHSA-2mxh-xfhw-gmr5.json index efcb3e782b1..1b4d42314f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mxh-xfhw-gmr5/GHSA-2mxh-xfhw-gmr5.json +++ b/advisories/unreviewed/2022/05/GHSA-2mxh-xfhw-gmr5/GHSA-2mxh-xfhw-gmr5.json @@ -7,12 +7,8 @@ "CVE-2020-17466" ], "details": "Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redirect responses.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2q6p-c398-62rm/GHSA-2q6p-c398-62rm.json b/advisories/unreviewed/2022/05/GHSA-2q6p-c398-62rm/GHSA-2q6p-c398-62rm.json index ea00d6d3461..96353650879 100644 --- a/advisories/unreviewed/2022/05/GHSA-2q6p-c398-62rm/GHSA-2q6p-c398-62rm.json +++ b/advisories/unreviewed/2022/05/GHSA-2q6p-c398-62rm/GHSA-2q6p-c398-62rm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2qxq-774f-5m45/GHSA-2qxq-774f-5m45.json b/advisories/unreviewed/2022/05/GHSA-2qxq-774f-5m45/GHSA-2qxq-774f-5m45.json index 1004604b844..3aa39fe7bba 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qxq-774f-5m45/GHSA-2qxq-774f-5m45.json +++ b/advisories/unreviewed/2022/05/GHSA-2qxq-774f-5m45/GHSA-2qxq-774f-5m45.json @@ -7,12 +7,8 @@ "CVE-2020-16847" ], "details": "Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in a GET request, aka CFD-4887.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2rhr-5rr8-pf6q/GHSA-2rhr-5rr8-pf6q.json b/advisories/unreviewed/2022/05/GHSA-2rhr-5rr8-pf6q/GHSA-2rhr-5rr8-pf6q.json index 95f2a224cff..07b26c7a7fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rhr-5rr8-pf6q/GHSA-2rhr-5rr8-pf6q.json +++ b/advisories/unreviewed/2022/05/GHSA-2rhr-5rr8-pf6q/GHSA-2rhr-5rr8-pf6q.json @@ -7,12 +7,8 @@ "CVE-2020-11623" ], "details": "An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. An attacker with physical access to the UART interface could access additional diagnostic and configuration functionalities as well as the camera's bootloader. Successful exploitation could compromise confidentiality, integrity, and availability of the affected system. It could even render the device inoperable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2v2g-rr8c-cpwh/GHSA-2v2g-rr8c-cpwh.json b/advisories/unreviewed/2022/05/GHSA-2v2g-rr8c-cpwh/GHSA-2v2g-rr8c-cpwh.json index dd3d921bb6d..253e2cae433 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v2g-rr8c-cpwh/GHSA-2v2g-rr8c-cpwh.json +++ b/advisories/unreviewed/2022/05/GHSA-2v2g-rr8c-cpwh/GHSA-2v2g-rr8c-cpwh.json @@ -7,12 +7,8 @@ "CVE-2020-11474" ], "details": "NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2vq8-2cg2-c3hv/GHSA-2vq8-2cg2-c3hv.json b/advisories/unreviewed/2022/05/GHSA-2vq8-2cg2-c3hv/GHSA-2vq8-2cg2-c3hv.json index f8896abbe4b..081e2d5e043 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vq8-2cg2-c3hv/GHSA-2vq8-2cg2-c3hv.json +++ b/advisories/unreviewed/2022/05/GHSA-2vq8-2cg2-c3hv/GHSA-2vq8-2cg2-c3hv.json @@ -7,12 +7,8 @@ "CVE-2020-15059" ], "details": "Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2vqj-8xcw-9566/GHSA-2vqj-8xcw-9566.json b/advisories/unreviewed/2022/05/GHSA-2vqj-8xcw-9566/GHSA-2vqj-8xcw-9566.json index 90773f88d31..a148c96784b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vqj-8xcw-9566/GHSA-2vqj-8xcw-9566.json +++ b/advisories/unreviewed/2022/05/GHSA-2vqj-8xcw-9566/GHSA-2vqj-8xcw-9566.json @@ -7,12 +7,8 @@ "CVE-2020-4498" ], "details": "IBM MQ Appliance 9.1 LTS and 9.1 CD could allow a local privileged user to obtain highly sensitve information due to inclusion of data within trace files. IBM X-Force ID: 182118.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-32pf-q5pw-hg4f/GHSA-32pf-q5pw-hg4f.json b/advisories/unreviewed/2022/05/GHSA-32pf-q5pw-hg4f/GHSA-32pf-q5pw-hg4f.json index 086a0a8433e..9a9409e315a 100644 --- a/advisories/unreviewed/2022/05/GHSA-32pf-q5pw-hg4f/GHSA-32pf-q5pw-hg4f.json +++ b/advisories/unreviewed/2022/05/GHSA-32pf-q5pw-hg4f/GHSA-32pf-q5pw-hg4f.json @@ -7,12 +7,8 @@ "CVE-2020-16269" ], "details": "radare2 4.5.0 misparses DWARF information in executable files, causing a segmentation fault in parse_typedef in type_dwarf.c via a malformed DW_AT_name in the .debug_info section.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-32vc-v3xp-628w/GHSA-32vc-v3xp-628w.json b/advisories/unreviewed/2022/05/GHSA-32vc-v3xp-628w/GHSA-32vc-v3xp-628w.json index 87d78c809e2..1c480b366a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-32vc-v3xp-628w/GHSA-32vc-v3xp-628w.json +++ b/advisories/unreviewed/2022/05/GHSA-32vc-v3xp-628w/GHSA-32vc-v3xp-628w.json @@ -7,12 +7,8 @@ "CVE-2020-15828" ], "details": "In JetBrains TeamCity before 2020.1.1, project parameter values can be retrieved by a user without appropriate permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3353-7c4m-qm7q/GHSA-3353-7c4m-qm7q.json b/advisories/unreviewed/2022/05/GHSA-3353-7c4m-qm7q/GHSA-3353-7c4m-qm7q.json index 24bf33c458f..cf6e4e23773 100644 --- a/advisories/unreviewed/2022/05/GHSA-3353-7c4m-qm7q/GHSA-3353-7c4m-qm7q.json +++ b/advisories/unreviewed/2022/05/GHSA-3353-7c4m-qm7q/GHSA-3353-7c4m-qm7q.json @@ -7,12 +7,8 @@ "CVE-2020-15830" ], "details": "JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-33r6-p8j2-7jxf/GHSA-33r6-p8j2-7jxf.json b/advisories/unreviewed/2022/05/GHSA-33r6-p8j2-7jxf/GHSA-33r6-p8j2-7jxf.json index f164119b3ca..04a0f71e8ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-33r6-p8j2-7jxf/GHSA-33r6-p8j2-7jxf.json +++ b/advisories/unreviewed/2022/05/GHSA-33r6-p8j2-7jxf/GHSA-33r6-p8j2-7jxf.json @@ -7,12 +7,8 @@ "CVE-2020-15879" ], "details": "Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) and certain IPv4 addresses (0.0.0.0/8, 127.0.0.0/8, and 169.254.0.0/16).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-33rv-x9gp-7cfh/GHSA-33rv-x9gp-7cfh.json b/advisories/unreviewed/2022/05/GHSA-33rv-x9gp-7cfh/GHSA-33rv-x9gp-7cfh.json index 129f6977a01..38be1b813dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-33rv-x9gp-7cfh/GHSA-33rv-x9gp-7cfh.json +++ b/advisories/unreviewed/2022/05/GHSA-33rv-x9gp-7cfh/GHSA-33rv-x9gp-7cfh.json @@ -7,12 +7,8 @@ "CVE-2020-13376" ], "details": "SecurEnvoy SecurMail 9.3.503 allows attackers to upload executable files and achieve OS command execution via a crafted SecurEnvoyReply cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-34wg-xv5v-xgh8/GHSA-34wg-xv5v-xgh8.json b/advisories/unreviewed/2022/05/GHSA-34wg-xv5v-xgh8/GHSA-34wg-xv5v-xgh8.json index 2ec3f9c6429..c54bfa99b1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-34wg-xv5v-xgh8/GHSA-34wg-xv5v-xgh8.json +++ b/advisories/unreviewed/2022/05/GHSA-34wg-xv5v-xgh8/GHSA-34wg-xv5v-xgh8.json @@ -7,12 +7,8 @@ "CVE-2020-4186" ], "details": "IBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in further attacks against the system. IBM X-Force ID: 174804.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-355p-v284-v3xp/GHSA-355p-v284-v3xp.json b/advisories/unreviewed/2022/05/GHSA-355p-v284-v3xp/GHSA-355p-v284-v3xp.json index a3276e3f5f2..027a5646444 100644 --- a/advisories/unreviewed/2022/05/GHSA-355p-v284-v3xp/GHSA-355p-v284-v3xp.json +++ b/advisories/unreviewed/2022/05/GHSA-355p-v284-v3xp/GHSA-355p-v284-v3xp.json @@ -7,12 +7,8 @@ "CVE-2020-13365" ], "details": "Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can be used for a TELNET session as root. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0, and V5.21(ABAG.3)C0; NSA325 v2_V4.81(AALS.0)C0 and V4.81(AAAJ.1)C0; NSA310 4.22(AFK.0)C0 and 4.22(AFK.1)C0; NAS326 V5.21(AAZF.8)C0, V5.11(AAZF.4)C0, V5.11(AAZF.2)C0, and V5.11(AAZF.3)C0; NSA310S V4.75(AALH.2)C0; NSA320S V4.75(AANV.2)C0 and V4.75(AANV.1)C0; NSA221 V4.41(AFM.1)C0; and NAS540 V5.21(AATB.5)C0 and V5.21(AATB.3)C0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3587-wxgr-vm9r/GHSA-3587-wxgr-vm9r.json b/advisories/unreviewed/2022/05/GHSA-3587-wxgr-vm9r/GHSA-3587-wxgr-vm9r.json index 442e7bb03c7..b83a970282b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3587-wxgr-vm9r/GHSA-3587-wxgr-vm9r.json +++ b/advisories/unreviewed/2022/05/GHSA-3587-wxgr-vm9r/GHSA-3587-wxgr-vm9r.json @@ -7,12 +7,8 @@ "CVE-2020-4125" ], "details": "Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker could download files from the RHEL environment by doing some modification in the link, giving the attacker access to confidential information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-35hp-m7hg-c3cm/GHSA-35hp-m7hg-c3cm.json b/advisories/unreviewed/2022/05/GHSA-35hp-m7hg-c3cm/GHSA-35hp-m7hg-c3cm.json index f13c1920c39..d230bcfc9f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-35hp-m7hg-c3cm/GHSA-35hp-m7hg-c3cm.json +++ b/advisories/unreviewed/2022/05/GHSA-35hp-m7hg-c3cm/GHSA-35hp-m7hg-c3cm.json @@ -7,12 +7,8 @@ "CVE-2020-9077" ], "details": "HUAWEI P30 smart phones with versions earlier than 10.1.0.160(C00E160R2P11) have an information exposure vulnerability. The system does not properly authenticate the application that access a specified interface. Attackers can trick users into installing malicious software to exploit this vulnerability and obtain some information about the device. Successful exploit may cause information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35pq-fvh7-h49r/GHSA-35pq-fvh7-h49r.json b/advisories/unreviewed/2022/05/GHSA-35pq-fvh7-h49r/GHSA-35pq-fvh7-h49r.json index 374dee8ad20..61576f0a1a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-35pq-fvh7-h49r/GHSA-35pq-fvh7-h49r.json +++ b/advisories/unreviewed/2022/05/GHSA-35pq-fvh7-h49r/GHSA-35pq-fvh7-h49r.json @@ -7,12 +7,8 @@ "CVE-2020-13292" ], "details": "In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3794-c67g-vh97/GHSA-3794-c67g-vh97.json b/advisories/unreviewed/2022/05/GHSA-3794-c67g-vh97/GHSA-3794-c67g-vh97.json index d715356fa28..70ac8f1dfa5 100644 --- a/advisories/unreviewed/2022/05/GHSA-3794-c67g-vh97/GHSA-3794-c67g-vh97.json +++ b/advisories/unreviewed/2022/05/GHSA-3794-c67g-vh97/GHSA-3794-c67g-vh97.json @@ -7,12 +7,8 @@ "CVE-2020-0249" ], "details": "In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.0 Android-8.1 Android-9Android ID: A-154719656", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-38mw-39hm-59rm/GHSA-38mw-39hm-59rm.json b/advisories/unreviewed/2022/05/GHSA-38mw-39hm-59rm/GHSA-38mw-39hm-59rm.json index 06b4e2532ea..12129f375c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-38mw-39hm-59rm/GHSA-38mw-39hm-59rm.json +++ b/advisories/unreviewed/2022/05/GHSA-38mw-39hm-59rm/GHSA-38mw-39hm-59rm.json @@ -7,12 +7,8 @@ "CVE-2020-7829" ], "details": "DaviewIndy 8.98.4 and earlier version contain Heap-based overflow vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-392j-2p2c-c7m3/GHSA-392j-2p2c-c7m3.json b/advisories/unreviewed/2022/05/GHSA-392j-2p2c-c7m3/GHSA-392j-2p2c-c7m3.json index 91ffbdd8349..6f80fff0cb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-392j-2p2c-c7m3/GHSA-392j-2p2c-c7m3.json +++ b/advisories/unreviewed/2022/05/GHSA-392j-2p2c-c7m3/GHSA-392j-2p2c-c7m3.json @@ -7,12 +7,8 @@ "CVE-2020-7520" ], "details": "A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Electric Software Update (SESU), V2.4.0 and prior, which could cause execution of malicious code on the victim's machine. In order to exploit this vulnerability, an attacker requires privileged access on the engineering workstation to modify a Windows registry key which would divert all traffic updates to go through a server in the attacker's possession. A man-in-the-middle attack is then used to complete the exploit.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-39vm-h38v-j867/GHSA-39vm-h38v-j867.json b/advisories/unreviewed/2022/05/GHSA-39vm-h38v-j867/GHSA-39vm-h38v-j867.json index 30da75025ab..ffa8a738dff 100644 --- a/advisories/unreviewed/2022/05/GHSA-39vm-h38v-j867/GHSA-39vm-h38v-j867.json +++ b/advisories/unreviewed/2022/05/GHSA-39vm-h38v-j867/GHSA-39vm-h38v-j867.json @@ -7,12 +7,8 @@ "CVE-2020-11985" ], "details": "IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3g3v-fjwj-v857/GHSA-3g3v-fjwj-v857.json b/advisories/unreviewed/2022/05/GHSA-3g3v-fjwj-v857/GHSA-3g3v-fjwj-v857.json index 85be1dace3f..db5c04dbe97 100644 --- a/advisories/unreviewed/2022/05/GHSA-3g3v-fjwj-v857/GHSA-3g3v-fjwj-v857.json +++ b/advisories/unreviewed/2022/05/GHSA-3g3v-fjwj-v857/GHSA-3g3v-fjwj-v857.json @@ -7,12 +7,8 @@ "CVE-2020-5396" ], "details": "VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.11.1 and 1.10.2, when deployed without a SecurityManager, contain a JMX service available which contains an insecure default configuration. This allows a malicious user to create an MLet mbean leading to remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3g62-9qpr-j338/GHSA-3g62-9qpr-j338.json b/advisories/unreviewed/2022/05/GHSA-3g62-9qpr-j338/GHSA-3g62-9qpr-j338.json index 5f4a1af3cb8..eb9dad21e9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3g62-9qpr-j338/GHSA-3g62-9qpr-j338.json +++ b/advisories/unreviewed/2022/05/GHSA-3g62-9qpr-j338/GHSA-3g62-9qpr-j338.json @@ -7,12 +7,8 @@ "CVE-2020-15826" ], "details": "In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3gg3-qcqf-2r64/GHSA-3gg3-qcqf-2r64.json b/advisories/unreviewed/2022/05/GHSA-3gg3-qcqf-2r64/GHSA-3gg3-qcqf-2r64.json index 735a0cd4ee6..3f289ae9ac2 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gg3-qcqf-2r64/GHSA-3gg3-qcqf-2r64.json +++ b/advisories/unreviewed/2022/05/GHSA-3gg3-qcqf-2r64/GHSA-3gg3-qcqf-2r64.json @@ -7,12 +7,8 @@ "CVE-2020-4573" ], "details": "IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could disclose sensitive information due to responding to unauthenticated HTTP requests. IBM X-Force ID: 184180.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3gp7-xp89-jxh5/GHSA-3gp7-xp89-jxh5.json b/advisories/unreviewed/2022/05/GHSA-3gp7-xp89-jxh5/GHSA-3gp7-xp89-jxh5.json index b3f3f36626b..fcf9a3d8186 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gp7-xp89-jxh5/GHSA-3gp7-xp89-jxh5.json +++ b/advisories/unreviewed/2022/05/GHSA-3gp7-xp89-jxh5/GHSA-3gp7-xp89-jxh5.json @@ -7,12 +7,8 @@ "CVE-2020-0242" ], "details": "In reset of NuPlayerDriver.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-151643722", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3h4f-76g6-g5wc/GHSA-3h4f-76g6-g5wc.json b/advisories/unreviewed/2022/05/GHSA-3h4f-76g6-g5wc/GHSA-3h4f-76g6-g5wc.json index e6ff8e8fd1f..ac47eeab38c 100644 --- a/advisories/unreviewed/2022/05/GHSA-3h4f-76g6-g5wc/GHSA-3h4f-76g6-g5wc.json +++ b/advisories/unreviewed/2022/05/GHSA-3h4f-76g6-g5wc/GHSA-3h4f-76g6-g5wc.json @@ -7,12 +7,8 @@ "CVE-2020-10600" ], "details": "In OSIsoft PI System multiple products and versions, an authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This can result in blocking queries to PI Data Archive.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3hvr-vjfh-gw5w/GHSA-3hvr-vjfh-gw5w.json b/advisories/unreviewed/2022/05/GHSA-3hvr-vjfh-gw5w/GHSA-3hvr-vjfh-gw5w.json index 3208508ac82..3f6666d2e2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hvr-vjfh-gw5w/GHSA-3hvr-vjfh-gw5w.json +++ b/advisories/unreviewed/2022/05/GHSA-3hvr-vjfh-gw5w/GHSA-3hvr-vjfh-gw5w.json @@ -7,12 +7,8 @@ "CVE-2020-7517" ], "details": "A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to read user credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3hw8-h4fg-g6wr/GHSA-3hw8-h4fg-g6wr.json b/advisories/unreviewed/2022/05/GHSA-3hw8-h4fg-g6wr/GHSA-3hw8-h4fg-g6wr.json index e60311e9b5e..39f674014f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hw8-h4fg-g6wr/GHSA-3hw8-h4fg-g6wr.json +++ b/advisories/unreviewed/2022/05/GHSA-3hw8-h4fg-g6wr/GHSA-3hw8-h4fg-g6wr.json @@ -7,12 +7,8 @@ "CVE-2020-15944" ], "details": "An issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is vulnerable to a persistent XSS attack. An attacker can embed the attack vectors in the dashboard of other users. To exploit this vulnerability, an attacker has to be authenticated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3mc3-9p24-hxhq/GHSA-3mc3-9p24-hxhq.json b/advisories/unreviewed/2022/05/GHSA-3mc3-9p24-hxhq/GHSA-3mc3-9p24-hxhq.json index 36c63ed9b0c..f85c5a50cf6 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mc3-9p24-hxhq/GHSA-3mc3-9p24-hxhq.json +++ b/advisories/unreviewed/2022/05/GHSA-3mc3-9p24-hxhq/GHSA-3mc3-9p24-hxhq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mgr-6m8w-82f4/GHSA-3mgr-6m8w-82f4.json b/advisories/unreviewed/2022/05/GHSA-3mgr-6m8w-82f4/GHSA-3mgr-6m8w-82f4.json index 45f1841856c..9aadf2fe2fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mgr-6m8w-82f4/GHSA-3mgr-6m8w-82f4.json +++ b/advisories/unreviewed/2022/05/GHSA-3mgr-6m8w-82f4/GHSA-3mgr-6m8w-82f4.json @@ -7,12 +7,8 @@ "CVE-2020-4397" ], "details": "IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive information in plain text which could be obtained by an attacker using man in the middle techniques. IBM X-Force ID: 179428.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3qwg-86mf-pw6m/GHSA-3qwg-86mf-pw6m.json b/advisories/unreviewed/2022/05/GHSA-3qwg-86mf-pw6m/GHSA-3qwg-86mf-pw6m.json index d43b124fb24..ebfab2855c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qwg-86mf-pw6m/GHSA-3qwg-86mf-pw6m.json +++ b/advisories/unreviewed/2022/05/GHSA-3qwg-86mf-pw6m/GHSA-3qwg-86mf-pw6m.json @@ -7,12 +7,8 @@ "CVE-2020-4375" ], "details": "IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS could allow an attacker to cause a denial of service due to a memory leak caused by an error creating a dynamic queue. IBM X-Force ID: 179080.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vjf-wmm3-x4c7/GHSA-3vjf-wmm3-x4c7.json b/advisories/unreviewed/2022/05/GHSA-3vjf-wmm3-x4c7/GHSA-3vjf-wmm3-x4c7.json index 89c2d005c70..b2d85c93208 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vjf-wmm3-x4c7/GHSA-3vjf-wmm3-x4c7.json +++ b/advisories/unreviewed/2022/05/GHSA-3vjf-wmm3-x4c7/GHSA-3vjf-wmm3-x4c7.json @@ -7,12 +7,8 @@ "CVE-2020-4551" ], "details": "IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183319.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wpp-4hx4-q527/GHSA-3wpp-4hx4-q527.json b/advisories/unreviewed/2022/05/GHSA-3wpp-4hx4-q527/GHSA-3wpp-4hx4-q527.json index 8a26f03395e..bdd5cee9347 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wpp-4hx4-q527/GHSA-3wpp-4hx4-q527.json +++ b/advisories/unreviewed/2022/05/GHSA-3wpp-4hx4-q527/GHSA-3wpp-4hx4-q527.json @@ -7,12 +7,8 @@ "CVE-2020-0243" ], "details": "In clearPropValue of MediaAnalyticsItem.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-8.0 Android-8.1Android ID: A-151644303", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-42qr-q7pq-93c7/GHSA-42qr-q7pq-93c7.json b/advisories/unreviewed/2022/05/GHSA-42qr-q7pq-93c7/GHSA-42qr-q7pq-93c7.json index b5e2b51b352..c31641977ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-42qr-q7pq-93c7/GHSA-42qr-q7pq-93c7.json +++ b/advisories/unreviewed/2022/05/GHSA-42qr-q7pq-93c7/GHSA-42qr-q7pq-93c7.json @@ -7,12 +7,8 @@ "CVE-2020-13404" ], "details": "The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-43gf-9mf8-44g5/GHSA-43gf-9mf8-44g5.json b/advisories/unreviewed/2022/05/GHSA-43gf-9mf8-44g5/GHSA-43gf-9mf8-44g5.json index b1eb9afe6d4..5e555210214 100644 --- a/advisories/unreviewed/2022/05/GHSA-43gf-9mf8-44g5/GHSA-43gf-9mf8-44g5.json +++ b/advisories/unreviewed/2022/05/GHSA-43gf-9mf8-44g5/GHSA-43gf-9mf8-44g5.json @@ -7,12 +7,8 @@ "CVE-2019-4731" ], "details": "IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 172616.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-43qv-gqwc-rjxf/GHSA-43qv-gqwc-rjxf.json b/advisories/unreviewed/2022/05/GHSA-43qv-gqwc-rjxf/GHSA-43qv-gqwc-rjxf.json index 12c9e04aa6d..9d3ee852f65 100644 --- a/advisories/unreviewed/2022/05/GHSA-43qv-gqwc-rjxf/GHSA-43qv-gqwc-rjxf.json +++ b/advisories/unreviewed/2022/05/GHSA-43qv-gqwc-rjxf/GHSA-43qv-gqwc-rjxf.json @@ -7,12 +7,8 @@ "CVE-2020-8317" ], "details": "A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-457v-px4g-7qcg/GHSA-457v-px4g-7qcg.json b/advisories/unreviewed/2022/05/GHSA-457v-px4g-7qcg/GHSA-457v-px4g-7qcg.json index c25ad90d752..76b594976b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-457v-px4g-7qcg/GHSA-457v-px4g-7qcg.json +++ b/advisories/unreviewed/2022/05/GHSA-457v-px4g-7qcg/GHSA-457v-px4g-7qcg.json @@ -7,12 +7,8 @@ "CVE-2020-14486" ], "details": "An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of a permission failure, which may allow unauthorized execution of commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4732-gxvm-37j5/GHSA-4732-gxvm-37j5.json b/advisories/unreviewed/2022/05/GHSA-4732-gxvm-37j5/GHSA-4732-gxvm-37j5.json index bdcf0a5a841..1b50c44257c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4732-gxvm-37j5/GHSA-4732-gxvm-37j5.json +++ b/advisories/unreviewed/2022/05/GHSA-4732-gxvm-37j5/GHSA-4732-gxvm-37j5.json @@ -7,12 +7,8 @@ "CVE-2020-0251" ], "details": "There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-152647626", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-47vq-f5r8-c96h/GHSA-47vq-f5r8-c96h.json b/advisories/unreviewed/2022/05/GHSA-47vq-f5r8-c96h/GHSA-47vq-f5r8-c96h.json index 28ff58ef786..2ca21a05809 100644 --- a/advisories/unreviewed/2022/05/GHSA-47vq-f5r8-c96h/GHSA-47vq-f5r8-c96h.json +++ b/advisories/unreviewed/2022/05/GHSA-47vq-f5r8-c96h/GHSA-47vq-f5r8-c96h.json @@ -7,12 +7,8 @@ "CVE-2020-6526" ], "details": "Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4839-fmx8-4hrv/GHSA-4839-fmx8-4hrv.json b/advisories/unreviewed/2022/05/GHSA-4839-fmx8-4hrv/GHSA-4839-fmx8-4hrv.json index 9f56e06fa41..1c37ab6f95d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4839-fmx8-4hrv/GHSA-4839-fmx8-4hrv.json +++ b/advisories/unreviewed/2022/05/GHSA-4839-fmx8-4hrv/GHSA-4839-fmx8-4hrv.json @@ -7,12 +7,8 @@ "CVE-2020-13280" ], "details": "For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4cg3-gfhj-x3xm/GHSA-4cg3-gfhj-x3xm.json b/advisories/unreviewed/2022/05/GHSA-4cg3-gfhj-x3xm/GHSA-4cg3-gfhj-x3xm.json index 7d16c1b13b3..0f2ca5bf58a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cg3-gfhj-x3xm/GHSA-4cg3-gfhj-x3xm.json +++ b/advisories/unreviewed/2022/05/GHSA-4cg3-gfhj-x3xm/GHSA-4cg3-gfhj-x3xm.json @@ -7,12 +7,8 @@ "CVE-2020-6530" ], "details": "Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4gv5-mmhv-5c45/GHSA-4gv5-mmhv-5c45.json b/advisories/unreviewed/2022/05/GHSA-4gv5-mmhv-5c45/GHSA-4gv5-mmhv-5c45.json index 7c8feb6dbd4..a2a566771a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gv5-mmhv-5c45/GHSA-4gv5-mmhv-5c45.json +++ b/advisories/unreviewed/2022/05/GHSA-4gv5-mmhv-5c45/GHSA-4gv5-mmhv-5c45.json @@ -7,12 +7,8 @@ "CVE-2020-2076" ], "details": "SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST API. An attacker can send unauthorized requests, bypass current authentication controls presented by the application and could potentially write files without authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4h35-wggv-9625/GHSA-4h35-wggv-9625.json b/advisories/unreviewed/2022/05/GHSA-4h35-wggv-9625/GHSA-4h35-wggv-9625.json index 0bf2272d6ce..bc752d6461c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4h35-wggv-9625/GHSA-4h35-wggv-9625.json +++ b/advisories/unreviewed/2022/05/GHSA-4h35-wggv-9625/GHSA-4h35-wggv-9625.json @@ -7,12 +7,8 @@ "CVE-2020-4318" ], "details": "IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operations for Waternamics are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 177356.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4jpm-gf9p-whpf/GHSA-4jpm-gf9p-whpf.json b/advisories/unreviewed/2022/05/GHSA-4jpm-gf9p-whpf/GHSA-4jpm-gf9p-whpf.json index 17efe022368..dcfe59290fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jpm-gf9p-whpf/GHSA-4jpm-gf9p-whpf.json +++ b/advisories/unreviewed/2022/05/GHSA-4jpm-gf9p-whpf/GHSA-4jpm-gf9p-whpf.json @@ -7,12 +7,8 @@ "CVE-2020-16278" ], "details": "A cross-site scripting (XSS) vulnerability in the Permissions component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4pc7-f2vc-2rv4/GHSA-4pc7-f2vc-2rv4.json b/advisories/unreviewed/2022/05/GHSA-4pc7-f2vc-2rv4/GHSA-4pc7-f2vc-2rv4.json index 04e6b0337f2..d6648d7693f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pc7-f2vc-2rv4/GHSA-4pc7-f2vc-2rv4.json +++ b/advisories/unreviewed/2022/05/GHSA-4pc7-f2vc-2rv4/GHSA-4pc7-f2vc-2rv4.json @@ -7,12 +7,8 @@ "CVE-2020-4399" ], "details": "IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could allow an authenticated user to send malformed requests to cause a denial of service against the server. IBM X-Force ID: 179476.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4qr3-p83g-c72j/GHSA-4qr3-p83g-c72j.json b/advisories/unreviewed/2022/05/GHSA-4qr3-p83g-c72j/GHSA-4qr3-p83g-c72j.json index 49b44a79df6..fc0f357bd07 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qr3-p83g-c72j/GHSA-4qr3-p83g-c72j.json +++ b/advisories/unreviewed/2022/05/GHSA-4qr3-p83g-c72j/GHSA-4qr3-p83g-c72j.json @@ -7,12 +7,8 @@ "CVE-2020-8207" ], "details": "Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4qwm-r4v9-8chp/GHSA-4qwm-r4v9-8chp.json b/advisories/unreviewed/2022/05/GHSA-4qwm-r4v9-8chp/GHSA-4qwm-r4v9-8chp.json index 700565fd5da..f4890597e4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qwm-r4v9-8chp/GHSA-4qwm-r4v9-8chp.json +++ b/advisories/unreviewed/2022/05/GHSA-4qwm-r4v9-8chp/GHSA-4qwm-r4v9-8chp.json @@ -7,12 +7,8 @@ "CVE-2020-16143" ], "details": "The seafile-client client 7.0.8 for Seafile is vulnerable to DLL hijacking because it loads exchndl.dll from the current working directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4rmc-8hwg-q3v2/GHSA-4rmc-8hwg-q3v2.json b/advisories/unreviewed/2022/05/GHSA-4rmc-8hwg-q3v2/GHSA-4rmc-8hwg-q3v2.json index acb8488448a..5670e70035a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rmc-8hwg-q3v2/GHSA-4rmc-8hwg-q3v2.json +++ b/advisories/unreviewed/2022/05/GHSA-4rmc-8hwg-q3v2/GHSA-4rmc-8hwg-q3v2.json @@ -7,12 +7,8 @@ "CVE-2020-15922" ], "details": "There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is required.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4vfh-gj5m-9h6r/GHSA-4vfh-gj5m-9h6r.json b/advisories/unreviewed/2022/05/GHSA-4vfh-gj5m-9h6r/GHSA-4vfh-gj5m-9h6r.json index 267b679be51..1f2aea5bd89 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vfh-gj5m-9h6r/GHSA-4vfh-gj5m-9h6r.json +++ b/advisories/unreviewed/2022/05/GHSA-4vfh-gj5m-9h6r/GHSA-4vfh-gj5m-9h6r.json @@ -7,12 +7,8 @@ "CVE-2019-14124" ], "details": "Memory failure in content protection module due to not having pointer within the scope in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, QCS404, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vh5-9j7r-fhh8/GHSA-4vh5-9j7r-fhh8.json b/advisories/unreviewed/2022/05/GHSA-4vh5-9j7r-fhh8/GHSA-4vh5-9j7r-fhh8.json index d7b43f07c32..f6ac1924e5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vh5-9j7r-fhh8/GHSA-4vh5-9j7r-fhh8.json +++ b/advisories/unreviewed/2022/05/GHSA-4vh5-9j7r-fhh8/GHSA-4vh5-9j7r-fhh8.json @@ -7,12 +7,8 @@ "CVE-2020-14158" ], "details": "The ABUS Secvest FUMO50110 hybrid module does not have any security mechanism that ensures confidentiality or integrity of RF packets that are exchanged with an alarm panel. This makes it easier to conduct wAppLoxx authentication-bypass attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vrv-6pj5-3c4x/GHSA-4vrv-6pj5-3c4x.json b/advisories/unreviewed/2022/05/GHSA-4vrv-6pj5-3c4x/GHSA-4vrv-6pj5-3c4x.json index 5318e2cc61f..7761c66aa86 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vrv-6pj5-3c4x/GHSA-4vrv-6pj5-3c4x.json +++ b/advisories/unreviewed/2022/05/GHSA-4vrv-6pj5-3c4x/GHSA-4vrv-6pj5-3c4x.json @@ -7,12 +7,8 @@ "CVE-2020-6515" ], "details": "Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4wqr-p7fx-5x8g/GHSA-4wqr-p7fx-5x8g.json b/advisories/unreviewed/2022/05/GHSA-4wqr-p7fx-5x8g/GHSA-4wqr-p7fx-5x8g.json index 97686377f12..fedfaa630c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wqr-p7fx-5x8g/GHSA-4wqr-p7fx-5x8g.json +++ b/advisories/unreviewed/2022/05/GHSA-4wqr-p7fx-5x8g/GHSA-4wqr-p7fx-5x8g.json @@ -7,12 +7,8 @@ "CVE-2020-15884" ], "details": "A SQL injection vulnerability in TableQuery.php in MunkiReport before 5.6.3 allows attackers to execute arbitrary SQL commands via the order[0][dir] field on POST requests to /datatables/data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4xhv-7g8c-27wc/GHSA-4xhv-7g8c-27wc.json b/advisories/unreviewed/2022/05/GHSA-4xhv-7g8c-27wc/GHSA-4xhv-7g8c-27wc.json index 3bbdd0e1c99..74101c2a113 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xhv-7g8c-27wc/GHSA-4xhv-7g8c-27wc.json +++ b/advisories/unreviewed/2022/05/GHSA-4xhv-7g8c-27wc/GHSA-4xhv-7g8c-27wc.json @@ -7,12 +7,8 @@ "CVE-2020-4408" ], "details": "The IBM QRadar Advisor 1.1 through 2.5.2 with Watson App for IBM QRadar SIEM does not adequately mask all passwords during input, which could be obtained by a physical attacker nearby. IBM X-Force ID: 179536.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-525p-w4cm-hh3q/GHSA-525p-w4cm-hh3q.json b/advisories/unreviewed/2022/05/GHSA-525p-w4cm-hh3q/GHSA-525p-w4cm-hh3q.json index 3414d4bd4d5..444e25fd083 100644 --- a/advisories/unreviewed/2022/05/GHSA-525p-w4cm-hh3q/GHSA-525p-w4cm-hh3q.json +++ b/advisories/unreviewed/2022/05/GHSA-525p-w4cm-hh3q/GHSA-525p-w4cm-hh3q.json @@ -7,12 +7,8 @@ "CVE-2020-6512" ], "details": "Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-532p-r74j-rw26/GHSA-532p-r74j-rw26.json b/advisories/unreviewed/2022/05/GHSA-532p-r74j-rw26/GHSA-532p-r74j-rw26.json index 57a9328629a..4ece84726b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-532p-r74j-rw26/GHSA-532p-r74j-rw26.json +++ b/advisories/unreviewed/2022/05/GHSA-532p-r74j-rw26/GHSA-532p-r74j-rw26.json @@ -7,12 +7,8 @@ "CVE-2020-8213" ], "details": "An information exposure vulnerability exists in UniFi Protect v1.13.3 and prior that allowed unauthenticated attackers access to valid usernames for the UniFi Protect web application via HTTP response code and response timing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-535g-c3ww-mvp7/GHSA-535g-c3ww-mvp7.json b/advisories/unreviewed/2022/05/GHSA-535g-c3ww-mvp7/GHSA-535g-c3ww-mvp7.json index b181d2d43c3..94631257b4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-535g-c3ww-mvp7/GHSA-535g-c3ww-mvp7.json +++ b/advisories/unreviewed/2022/05/GHSA-535g-c3ww-mvp7/GHSA-535g-c3ww-mvp7.json @@ -7,12 +7,8 @@ "CVE-2020-15417" ], "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of string table file uploads. A crafted gui_region in a string table file can trigger an overflow of a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the web server. Was ZDI-CAN-9756.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5463-xg53-cjvw/GHSA-5463-xg53-cjvw.json b/advisories/unreviewed/2022/05/GHSA-5463-xg53-cjvw/GHSA-5463-xg53-cjvw.json index d7f0c9c31cc..af2bc25a593 100644 --- a/advisories/unreviewed/2022/05/GHSA-5463-xg53-cjvw/GHSA-5463-xg53-cjvw.json +++ b/advisories/unreviewed/2022/05/GHSA-5463-xg53-cjvw/GHSA-5463-xg53-cjvw.json @@ -7,12 +7,8 @@ "CVE-2020-5609" ], "details": "Directory traversal vulnerability in CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R8.03.01 allows a remote unauthenticated attacker to create or overwrite arbitrary files and run arbitrary commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-55mp-4rvf-4mgw/GHSA-55mp-4rvf-4mgw.json b/advisories/unreviewed/2022/05/GHSA-55mp-4rvf-4mgw/GHSA-55mp-4rvf-4mgw.json index 250a58b65d4..294a4a47d70 100644 --- a/advisories/unreviewed/2022/05/GHSA-55mp-4rvf-4mgw/GHSA-55mp-4rvf-4mgw.json +++ b/advisories/unreviewed/2022/05/GHSA-55mp-4rvf-4mgw/GHSA-55mp-4rvf-4mgw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56f5-mxf9-5g22/GHSA-56f5-mxf9-5g22.json b/advisories/unreviewed/2022/05/GHSA-56f5-mxf9-5g22/GHSA-56f5-mxf9-5g22.json index 78aec0808c5..80940f8ddc7 100644 --- a/advisories/unreviewed/2022/05/GHSA-56f5-mxf9-5g22/GHSA-56f5-mxf9-5g22.json +++ b/advisories/unreviewed/2022/05/GHSA-56f5-mxf9-5g22/GHSA-56f5-mxf9-5g22.json @@ -7,12 +7,8 @@ "CVE-2019-19704" ], "details": "In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56fm-4wx5-34rr/GHSA-56fm-4wx5-34rr.json b/advisories/unreviewed/2022/05/GHSA-56fm-4wx5-34rr/GHSA-56fm-4wx5-34rr.json index 790b17006ea..ea6f688513a 100644 --- a/advisories/unreviewed/2022/05/GHSA-56fm-4wx5-34rr/GHSA-56fm-4wx5-34rr.json +++ b/advisories/unreviewed/2022/05/GHSA-56fm-4wx5-34rr/GHSA-56fm-4wx5-34rr.json @@ -7,12 +7,8 @@ "CVE-2020-4396" ], "details": "IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 179359.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5758-58rf-wp9r/GHSA-5758-58rf-wp9r.json b/advisories/unreviewed/2022/05/GHSA-5758-58rf-wp9r/GHSA-5758-58rf-wp9r.json index 952334870e8..a6a877fec32 100644 --- a/advisories/unreviewed/2022/05/GHSA-5758-58rf-wp9r/GHSA-5758-58rf-wp9r.json +++ b/advisories/unreviewed/2022/05/GHSA-5758-58rf-wp9r/GHSA-5758-58rf-wp9r.json @@ -7,12 +7,8 @@ "CVE-2020-10928" ], "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of string table file uploads. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the web server. Was ZDI-CAN-9767.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-57qf-p627-66hm/GHSA-57qf-p627-66hm.json b/advisories/unreviewed/2022/05/GHSA-57qf-p627-66hm/GHSA-57qf-p627-66hm.json index 73bb3e73394..9390cc2e5ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-57qf-p627-66hm/GHSA-57qf-p627-66hm.json +++ b/advisories/unreviewed/2022/05/GHSA-57qf-p627-66hm/GHSA-57qf-p627-66hm.json @@ -7,12 +7,8 @@ "CVE-2020-4405" ], "details": "IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could disclose potentially sensitive information to an authenticated user due to world readable log files. IBM X-Force ID: 179484.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-59q4-w53p-6vq9/GHSA-59q4-w53p-6vq9.json b/advisories/unreviewed/2022/05/GHSA-59q4-w53p-6vq9/GHSA-59q4-w53p-6vq9.json index 0a8f096eb50..2c5d0c5e8e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-59q4-w53p-6vq9/GHSA-59q4-w53p-6vq9.json +++ b/advisories/unreviewed/2022/05/GHSA-59q4-w53p-6vq9/GHSA-59q4-w53p-6vq9.json @@ -7,12 +7,8 @@ "CVE-2020-13286" ], "details": "For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-59rm-894j-v57q/GHSA-59rm-894j-v57q.json b/advisories/unreviewed/2022/05/GHSA-59rm-894j-v57q/GHSA-59rm-894j-v57q.json index ff0af9da947..b6522e29f7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-59rm-894j-v57q/GHSA-59rm-894j-v57q.json +++ b/advisories/unreviewed/2022/05/GHSA-59rm-894j-v57q/GHSA-59rm-894j-v57q.json @@ -7,12 +7,8 @@ "CVE-2020-5384" ], "details": "Authentication Bypass Vulnerability RSA MFA Agent 2.0 for Microsoft Windows contains an Authentication Bypass vulnerability. A local unauthenticated attacker could potentially exploit this vulnerability by using an alternate path to bypass authentication in order to gain full access to the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5f74-cc49-6mj7/GHSA-5f74-cc49-6mj7.json b/advisories/unreviewed/2022/05/GHSA-5f74-cc49-6mj7/GHSA-5f74-cc49-6mj7.json index 245b97e1894..0011de944d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f74-cc49-6mj7/GHSA-5f74-cc49-6mj7.json +++ b/advisories/unreviewed/2022/05/GHSA-5f74-cc49-6mj7/GHSA-5f74-cc49-6mj7.json @@ -7,12 +7,8 @@ "CVE-2019-20028" ], "details": "Aspire-derived NEC PBXes operating InMail software, including all versions of SV8100, SV9100, SL1100 and SL2100 devices allow unauthenticated read-only access to voicemails, greetings, and voice response system content through a system's WebPro administration interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5hvv-pmvw-fc3x/GHSA-5hvv-pmvw-fc3x.json b/advisories/unreviewed/2022/05/GHSA-5hvv-pmvw-fc3x/GHSA-5hvv-pmvw-fc3x.json index eafa3bd3e95..8308d88e1b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hvv-pmvw-fc3x/GHSA-5hvv-pmvw-fc3x.json +++ b/advisories/unreviewed/2022/05/GHSA-5hvv-pmvw-fc3x/GHSA-5hvv-pmvw-fc3x.json @@ -7,12 +7,8 @@ "CVE-2020-5772" ], "details": "Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious package file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5j2v-x6c2-63qg/GHSA-5j2v-x6c2-63qg.json b/advisories/unreviewed/2022/05/GHSA-5j2v-x6c2-63qg/GHSA-5j2v-x6c2-63qg.json index 779a07f39f1..c2be98df4f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-5j2v-x6c2-63qg/GHSA-5j2v-x6c2-63qg.json +++ b/advisories/unreviewed/2022/05/GHSA-5j2v-x6c2-63qg/GHSA-5j2v-x6c2-63qg.json @@ -7,12 +7,8 @@ "CVE-2020-4459" ], "details": "IBM Security Verify Access 10.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 181395.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5m75-p956-6hmj/GHSA-5m75-p956-6hmj.json b/advisories/unreviewed/2022/05/GHSA-5m75-p956-6hmj/GHSA-5m75-p956-6hmj.json index 0c499749acf..a3ca741e713 100644 --- a/advisories/unreviewed/2022/05/GHSA-5m75-p956-6hmj/GHSA-5m75-p956-6hmj.json +++ b/advisories/unreviewed/2022/05/GHSA-5m75-p956-6hmj/GHSA-5m75-p956-6hmj.json @@ -7,12 +7,8 @@ "CVE-2016-7063" ], "details": "A flaw was found in pritunl-client before version 1.0.1116.6. Arbitrary write to user specified path may lead to privilege escalation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5mcq-mg28-vj82/GHSA-5mcq-mg28-vj82.json b/advisories/unreviewed/2022/05/GHSA-5mcq-mg28-vj82/GHSA-5mcq-mg28-vj82.json index cf30340d589..fdcc7c24580 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mcq-mg28-vj82/GHSA-5mcq-mg28-vj82.json +++ b/advisories/unreviewed/2022/05/GHSA-5mcq-mg28-vj82/GHSA-5mcq-mg28-vj82.json @@ -7,12 +7,8 @@ "CVE-2020-13282" ], "details": "For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5p65-3pv7-7gq2/GHSA-5p65-3pv7-7gq2.json b/advisories/unreviewed/2022/05/GHSA-5p65-3pv7-7gq2/GHSA-5p65-3pv7-7gq2.json index feb3ea48c5c..2b53bf320df 100644 --- a/advisories/unreviewed/2022/05/GHSA-5p65-3pv7-7gq2/GHSA-5p65-3pv7-7gq2.json +++ b/advisories/unreviewed/2022/05/GHSA-5p65-3pv7-7gq2/GHSA-5p65-3pv7-7gq2.json @@ -7,12 +7,8 @@ "CVE-2020-15651" ], "details": "A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < 28.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5p7r-6jmj-6mcv/GHSA-5p7r-6jmj-6mcv.json b/advisories/unreviewed/2022/05/GHSA-5p7r-6jmj-6mcv/GHSA-5p7r-6jmj-6mcv.json index 2c1159b72c0..7f18aabe51e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5p7r-6jmj-6mcv/GHSA-5p7r-6jmj-6mcv.json +++ b/advisories/unreviewed/2022/05/GHSA-5p7r-6jmj-6mcv/GHSA-5p7r-6jmj-6mcv.json @@ -7,12 +7,8 @@ "CVE-2020-2078" ], "details": "Passwords are stored in plain text within the configuration of SICK Package Analytics software up to and including V04.1.1. An authorized attacker could access these stored plaintext credentials and gain access to the ftp service. Storing a password in plaintext allows attackers to easily gain access to systems, potentially compromising personal information or other sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5phg-ff74-gp62/GHSA-5phg-ff74-gp62.json b/advisories/unreviewed/2022/05/GHSA-5phg-ff74-gp62/GHSA-5phg-ff74-gp62.json index aa316cb8949..7025aa96df9 100644 --- a/advisories/unreviewed/2022/05/GHSA-5phg-ff74-gp62/GHSA-5phg-ff74-gp62.json +++ b/advisories/unreviewed/2022/05/GHSA-5phg-ff74-gp62/GHSA-5phg-ff74-gp62.json @@ -7,12 +7,8 @@ "CVE-2020-0250" ], "details": "In requestCellInfoUpdateInternal of PhoneInterfaceManager.java, there is a missing permission check. This could lead to local information disclosure of location data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-154934934", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5qg8-pmfr-f7fc/GHSA-5qg8-pmfr-f7fc.json b/advisories/unreviewed/2022/05/GHSA-5qg8-pmfr-f7fc/GHSA-5qg8-pmfr-f7fc.json index c5e1f187ba8..551ce58c029 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qg8-pmfr-f7fc/GHSA-5qg8-pmfr-f7fc.json +++ b/advisories/unreviewed/2022/05/GHSA-5qg8-pmfr-f7fc/GHSA-5qg8-pmfr-f7fc.json @@ -7,12 +7,8 @@ "CVE-2020-4645" ], "details": "IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 185717.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5qmp-36gw-8g5g/GHSA-5qmp-36gw-8g5g.json b/advisories/unreviewed/2022/05/GHSA-5qmp-36gw-8g5g/GHSA-5qmp-36gw-8g5g.json index 5b00f0d9d8b..bb71ab4c160 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qmp-36gw-8g5g/GHSA-5qmp-36gw-8g5g.json +++ b/advisories/unreviewed/2022/05/GHSA-5qmp-36gw-8g5g/GHSA-5qmp-36gw-8g5g.json @@ -7,12 +7,8 @@ "CVE-2020-8202" ], "details": "Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when using a very long password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5qmr-p529-g6c8/GHSA-5qmr-p529-g6c8.json b/advisories/unreviewed/2022/05/GHSA-5qmr-p529-g6c8/GHSA-5qmr-p529-g6c8.json index 1b48cada30a..ef97c8ee025 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qmr-p529-g6c8/GHSA-5qmr-p529-g6c8.json +++ b/advisories/unreviewed/2022/05/GHSA-5qmr-p529-g6c8/GHSA-5qmr-p529-g6c8.json @@ -7,12 +7,8 @@ "CVE-2020-17364" ], "details": "USVN (aka User-friendly SVN) before 1.0.9 allows XSS via SVN logs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5r6m-66fx-q4cm/GHSA-5r6m-66fx-q4cm.json b/advisories/unreviewed/2022/05/GHSA-5r6m-66fx-q4cm/GHSA-5r6m-66fx-q4cm.json index dda36e722b2..88d15df8d57 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r6m-66fx-q4cm/GHSA-5r6m-66fx-q4cm.json +++ b/advisories/unreviewed/2022/05/GHSA-5r6m-66fx-q4cm/GHSA-5r6m-66fx-q4cm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5r6p-9vjr-8fm7/GHSA-5r6p-9vjr-8fm7.json b/advisories/unreviewed/2022/05/GHSA-5r6p-9vjr-8fm7/GHSA-5r6p-9vjr-8fm7.json index c2714baca64..d9547738201 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r6p-9vjr-8fm7/GHSA-5r6p-9vjr-8fm7.json +++ b/advisories/unreviewed/2022/05/GHSA-5r6p-9vjr-8fm7/GHSA-5r6p-9vjr-8fm7.json @@ -7,12 +7,8 @@ "CVE-2020-3461" ], "details": "A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. The vulnerability is due to missing authentication on a specific part of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the interface. A successful exploit could allow the attacker to read confidential information from an affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5rg6-44mc-c264/GHSA-5rg6-44mc-c264.json b/advisories/unreviewed/2022/05/GHSA-5rg6-44mc-c264/GHSA-5rg6-44mc-c264.json index 9ffdbc2b1f6..9661d05ff8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5rg6-44mc-c264/GHSA-5rg6-44mc-c264.json +++ b/advisories/unreviewed/2022/05/GHSA-5rg6-44mc-c264/GHSA-5rg6-44mc-c264.json @@ -7,12 +7,8 @@ "CVE-2020-15712" ], "details": "rConfig 3.9.5 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a crafted request to the ajaxGetFileByPath.php script containing hexadecimal encoded \"dot dot\" sequences (%2f..%2f) in the path parameter to view arbitrary files on the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5v84-vq6c-9vxq/GHSA-5v84-vq6c-9vxq.json b/advisories/unreviewed/2022/05/GHSA-5v84-vq6c-9vxq/GHSA-5v84-vq6c-9vxq.json index de3cda234da..30312e4e47a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v84-vq6c-9vxq/GHSA-5v84-vq6c-9vxq.json +++ b/advisories/unreviewed/2022/05/GHSA-5v84-vq6c-9vxq/GHSA-5v84-vq6c-9vxq.json @@ -7,12 +7,8 @@ "CVE-2020-13918" ], "details": "Incorrect access control in webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to leak system information (that can be used for a jailbreak) via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and T710s devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5w2j-m7jf-c94r/GHSA-5w2j-m7jf-c94r.json b/advisories/unreviewed/2022/05/GHSA-5w2j-m7jf-c94r/GHSA-5w2j-m7jf-c94r.json index 0482169ae28..18299eb1d07 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w2j-m7jf-c94r/GHSA-5w2j-m7jf-c94r.json +++ b/advisories/unreviewed/2022/05/GHSA-5w2j-m7jf-c94r/GHSA-5w2j-m7jf-c94r.json @@ -7,12 +7,8 @@ "CVE-2020-4385" ], "details": "IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 179266.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5wmx-jr6q-wx42/GHSA-5wmx-jr6q-wx42.json b/advisories/unreviewed/2022/05/GHSA-5wmx-jr6q-wx42/GHSA-5wmx-jr6q-wx42.json index 0d810951ebc..14a45b221a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wmx-jr6q-wx42/GHSA-5wmx-jr6q-wx42.json +++ b/advisories/unreviewed/2022/05/GHSA-5wmx-jr6q-wx42/GHSA-5wmx-jr6q-wx42.json @@ -7,12 +7,8 @@ "CVE-2020-9529" ], "details": "Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions of Internet of Things devices, suffers from a privilege escalation vulnerability that allows attackers on the local network to reset the device's administrator password. This affects products marketed under the following brand names: Accfly, Alptop, Anlink, Besdersec, BOAVISION, COOAU, CPVAN, Ctronics, D3D Security, Dericam, Elex System, Elite Security, ENSTER, ePGes, Escam, FLOUREON, GENBOLT, Hongjingtian (HJT), ICAMI, Iegeek, Jecurity, Jennov, KKMoon, LEFTEK, Loosafe, Luowice, Nesuniq, Nettoly, ProElite, QZT, Royallite, SDETER, SV3C, SY2L, Tenvis, ThinkValue, TOMLOV, TPTEK, WGCC, and ZILINK.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5xhf-4vrf-2v55/GHSA-5xhf-4vrf-2v55.json b/advisories/unreviewed/2022/05/GHSA-5xhf-4vrf-2v55/GHSA-5xhf-4vrf-2v55.json index 93a4c1483a4..0c1e93d7573 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xhf-4vrf-2v55/GHSA-5xhf-4vrf-2v55.json +++ b/advisories/unreviewed/2022/05/GHSA-5xhf-4vrf-2v55/GHSA-5xhf-4vrf-2v55.json @@ -7,12 +7,8 @@ "CVE-2020-9684" ], "details": "Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5xrp-m9jg-rvh4/GHSA-5xrp-m9jg-rvh4.json b/advisories/unreviewed/2022/05/GHSA-5xrp-m9jg-rvh4/GHSA-5xrp-m9jg-rvh4.json index d5f3f548897..16c87668aac 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xrp-m9jg-rvh4/GHSA-5xrp-m9jg-rvh4.json +++ b/advisories/unreviewed/2022/05/GHSA-5xrp-m9jg-rvh4/GHSA-5xrp-m9jg-rvh4.json @@ -7,12 +7,8 @@ "CVE-2020-13178" ], "details": "A function in the Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to version 20.04.1 does not properly validate the signature of an external binary, which could allow an attacker to gain elevated privileges via execution in the context of the PCoIP Agent process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-65m5-fvm9-qxv6/GHSA-65m5-fvm9-qxv6.json b/advisories/unreviewed/2022/05/GHSA-65m5-fvm9-qxv6/GHSA-65m5-fvm9-qxv6.json index f280c8c71d8..99d0eedf3e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-65m5-fvm9-qxv6/GHSA-65m5-fvm9-qxv6.json +++ b/advisories/unreviewed/2022/05/GHSA-65m5-fvm9-qxv6/GHSA-65m5-fvm9-qxv6.json @@ -7,12 +7,8 @@ "CVE-2020-3383" ], "details": "A vulnerability in the archive utility of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to a lack of proper input validation of paths that are embedded within archive files. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to write arbitrary files in the system with the privileges of the logged-in user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-66f5-9hwv-gw9h/GHSA-66f5-9hwv-gw9h.json b/advisories/unreviewed/2022/05/GHSA-66f5-9hwv-gw9h/GHSA-66f5-9hwv-gw9h.json index 86bcaae7b02..2994ecb12c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-66f5-9hwv-gw9h/GHSA-66f5-9hwv-gw9h.json +++ b/advisories/unreviewed/2022/05/GHSA-66f5-9hwv-gw9h/GHSA-66f5-9hwv-gw9h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67jg-mxq3-434p/GHSA-67jg-mxq3-434p.json b/advisories/unreviewed/2022/05/GHSA-67jg-mxq3-434p/GHSA-67jg-mxq3-434p.json index 436175a4dd0..803ee608607 100644 --- a/advisories/unreviewed/2022/05/GHSA-67jg-mxq3-434p/GHSA-67jg-mxq3-434p.json +++ b/advisories/unreviewed/2022/05/GHSA-67jg-mxq3-434p/GHSA-67jg-mxq3-434p.json @@ -7,12 +7,8 @@ "CVE-2020-14520" ], "details": "The affected product is vulnerable to an information leak, which may allow an attacker to obtain sensitive information on the Ignition 8 (all versions prior to 8.0.13).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-67p7-mf7h-x6j5/GHSA-67p7-mf7h-x6j5.json b/advisories/unreviewed/2022/05/GHSA-67p7-mf7h-x6j5/GHSA-67p7-mf7h-x6j5.json index 6ed29023d42..d7e261897f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-67p7-mf7h-x6j5/GHSA-67p7-mf7h-x6j5.json +++ b/advisories/unreviewed/2022/05/GHSA-67p7-mf7h-x6j5/GHSA-67p7-mf7h-x6j5.json @@ -7,12 +7,8 @@ "CVE-2020-15467" ], "details": "The administrative interface of Cohesive Networks vns3:vpn appliances before version 4.11.1 is vulnerable to authenticated remote code execution leading to server compromise.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-68q8-gcx9-m4rq/GHSA-68q8-gcx9-m4rq.json b/advisories/unreviewed/2022/05/GHSA-68q8-gcx9-m4rq/GHSA-68q8-gcx9-m4rq.json index 1ae6ab0a171..f2d01f920d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-68q8-gcx9-m4rq/GHSA-68q8-gcx9-m4rq.json +++ b/advisories/unreviewed/2022/05/GHSA-68q8-gcx9-m4rq/GHSA-68q8-gcx9-m4rq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-69gj-p4vx-w4jg/GHSA-69gj-p4vx-w4jg.json b/advisories/unreviewed/2022/05/GHSA-69gj-p4vx-w4jg/GHSA-69gj-p4vx-w4jg.json index 44602168d0a..fee33b3aa3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-69gj-p4vx-w4jg/GHSA-69gj-p4vx-w4jg.json +++ b/advisories/unreviewed/2022/05/GHSA-69gj-p4vx-w4jg/GHSA-69gj-p4vx-w4jg.json @@ -7,12 +7,8 @@ "CVE-2020-4534" ], "details": "IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper handling of UNC paths. By scheduling a task with a specially-crafted UNC path, an attacker could exploit this vulnerability to execute arbitrary code with higher privileges. IBM X-Force ID: 182808.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6c68-84gq-j9gr/GHSA-6c68-84gq-j9gr.json b/advisories/unreviewed/2022/05/GHSA-6c68-84gq-j9gr/GHSA-6c68-84gq-j9gr.json index fb51b489037..ad028e13f52 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c68-84gq-j9gr/GHSA-6c68-84gq-j9gr.json +++ b/advisories/unreviewed/2022/05/GHSA-6c68-84gq-j9gr/GHSA-6c68-84gq-j9gr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6c6c-hp4f-xg67/GHSA-6c6c-hp4f-xg67.json b/advisories/unreviewed/2022/05/GHSA-6c6c-hp4f-xg67/GHSA-6c6c-hp4f-xg67.json index 38fee9f78f1..bd39ba8eaec 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c6c-hp4f-xg67/GHSA-6c6c-hp4f-xg67.json +++ b/advisories/unreviewed/2022/05/GHSA-6c6c-hp4f-xg67/GHSA-6c6c-hp4f-xg67.json @@ -7,12 +7,8 @@ "CVE-2020-13293" ], "details": "In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6f8f-rchr-mhp3/GHSA-6f8f-rchr-mhp3.json b/advisories/unreviewed/2022/05/GHSA-6f8f-rchr-mhp3/GHSA-6f8f-rchr-mhp3.json index 6ec27983bd7..58fae0e1e2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6f8f-rchr-mhp3/GHSA-6f8f-rchr-mhp3.json +++ b/advisories/unreviewed/2022/05/GHSA-6f8f-rchr-mhp3/GHSA-6f8f-rchr-mhp3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fcj-pp7h-r47q/GHSA-6fcj-pp7h-r47q.json b/advisories/unreviewed/2022/05/GHSA-6fcj-pp7h-r47q/GHSA-6fcj-pp7h-r47q.json index 96bdf88f3f2..b486fcb8473 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fcj-pp7h-r47q/GHSA-6fcj-pp7h-r47q.json +++ b/advisories/unreviewed/2022/05/GHSA-6fcj-pp7h-r47q/GHSA-6fcj-pp7h-r47q.json @@ -7,12 +7,8 @@ "CVE-2020-16227" ], "details": "Delta Electronics TPEditor Versions 1.97 and prior. An improper input validation may be exploited by processing a specially crafted project file not validated when the data is entered by a user. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fg8-3m77-gwrp/GHSA-6fg8-3m77-gwrp.json b/advisories/unreviewed/2022/05/GHSA-6fg8-3m77-gwrp/GHSA-6fg8-3m77-gwrp.json index de34dc0f8ac..9823f33db7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fg8-3m77-gwrp/GHSA-6fg8-3m77-gwrp.json +++ b/advisories/unreviewed/2022/05/GHSA-6fg8-3m77-gwrp/GHSA-6fg8-3m77-gwrp.json @@ -7,12 +7,8 @@ "CVE-2020-17352" ], "details": "Two OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to remotely execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6hf8-hv66-q62p/GHSA-6hf8-hv66-q62p.json b/advisories/unreviewed/2022/05/GHSA-6hf8-hv66-q62p/GHSA-6hf8-hv66-q62p.json index 131b43efdcd..7f266962daf 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hf8-hv66-q62p/GHSA-6hf8-hv66-q62p.json +++ b/advisories/unreviewed/2022/05/GHSA-6hf8-hv66-q62p/GHSA-6hf8-hv66-q62p.json @@ -7,12 +7,8 @@ "CVE-2020-13281" ], "details": "For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6j45-8qmh-g3p2/GHSA-6j45-8qmh-g3p2.json b/advisories/unreviewed/2022/05/GHSA-6j45-8qmh-g3p2/GHSA-6j45-8qmh-g3p2.json index 0dc72c6c1eb..b02878a5599 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j45-8qmh-g3p2/GHSA-6j45-8qmh-g3p2.json +++ b/advisories/unreviewed/2022/05/GHSA-6j45-8qmh-g3p2/GHSA-6j45-8qmh-g3p2.json @@ -7,12 +7,8 @@ "CVE-2019-4366" ], "details": "IBM Cognos Analytics 11.0 and 11.1 is susceptible to an information disclosure vulnerability where an attacker could gain access to cached browser data. IBM X-Force ID: 161748.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6m9c-h626-jp3r/GHSA-6m9c-h626-jp3r.json b/advisories/unreviewed/2022/05/GHSA-6m9c-h626-jp3r/GHSA-6m9c-h626-jp3r.json index 861c343b548..5eb3a4606d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-6m9c-h626-jp3r/GHSA-6m9c-h626-jp3r.json +++ b/advisories/unreviewed/2022/05/GHSA-6m9c-h626-jp3r/GHSA-6m9c-h626-jp3r.json @@ -7,12 +7,8 @@ "CVE-2020-12620" ], "details": "Pi-hole 4.4 allows a user able to write to /etc/pihole/dns-servers.conf to escalate privileges through command injection (shell metacharacters after an IP address).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6p3r-vmr8-vfcg/GHSA-6p3r-vmr8-vfcg.json b/advisories/unreviewed/2022/05/GHSA-6p3r-vmr8-vfcg/GHSA-6p3r-vmr8-vfcg.json index c84fe424e11..fb4c46fd02a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6p3r-vmr8-vfcg/GHSA-6p3r-vmr8-vfcg.json +++ b/advisories/unreviewed/2022/05/GHSA-6p3r-vmr8-vfcg/GHSA-6p3r-vmr8-vfcg.json @@ -7,12 +7,8 @@ "CVE-2020-5414" ], "details": "VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains an App Autoscaler that logs the UAA admin password. This credential is redacted on VMware Tanzu Operations Manager; however, the unredacted logs are available to authenticated users of the BOSH Director. This credential would grant administrative privileges to a malicious user. The same versions of App Autoscaler also log the App Autoscaler Broker password. Prior to newer versions of Operations Manager, this credential was not redacted from logs. This credential allows a malicious user to create, delete, and modify App Autoscaler services instances. Operations Manager started redacting this credential from logs as of its versions 2.7.15, 2.8.6, and 2.9.1. Note that these logs are typically only visible to foundation administrators and operators.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6ppm-q587-qrq9/GHSA-6ppm-q587-qrq9.json b/advisories/unreviewed/2022/05/GHSA-6ppm-q587-qrq9/GHSA-6ppm-q587-qrq9.json index f9d72fe97b1..51a2d2fcf80 100644 --- a/advisories/unreviewed/2022/05/GHSA-6ppm-q587-qrq9/GHSA-6ppm-q587-qrq9.json +++ b/advisories/unreviewed/2022/05/GHSA-6ppm-q587-qrq9/GHSA-6ppm-q587-qrq9.json @@ -7,12 +7,8 @@ "CVE-2020-9243" ], "details": "HUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a denial of service vulnerability. The system does not properly limit the depth of recursion, an attacker should trick the user installing and execute a malicious application. Successful exploit could cause a denial of service condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6q95-r497-79jw/GHSA-6q95-r497-79jw.json b/advisories/unreviewed/2022/05/GHSA-6q95-r497-79jw/GHSA-6q95-r497-79jw.json index f205535f0da..165f2a6edb3 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q95-r497-79jw/GHSA-6q95-r497-79jw.json +++ b/advisories/unreviewed/2022/05/GHSA-6q95-r497-79jw/GHSA-6q95-r497-79jw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6qmw-fm65-3cg3/GHSA-6qmw-fm65-3cg3.json b/advisories/unreviewed/2022/05/GHSA-6qmw-fm65-3cg3/GHSA-6qmw-fm65-3cg3.json index 99e091c144f..4e85b739012 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qmw-fm65-3cg3/GHSA-6qmw-fm65-3cg3.json +++ b/advisories/unreviewed/2022/05/GHSA-6qmw-fm65-3cg3/GHSA-6qmw-fm65-3cg3.json @@ -7,12 +7,8 @@ "CVE-2020-6536" ], "details": "Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to install a PWA to spoof the contents of the Omnibox (URL bar) via a crafted PWA.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6rm4-hmwm-3853/GHSA-6rm4-hmwm-3853.json b/advisories/unreviewed/2022/05/GHSA-6rm4-hmwm-3853/GHSA-6rm4-hmwm-3853.json index 4456521e740..1c26fd312a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rm4-hmwm-3853/GHSA-6rm4-hmwm-3853.json +++ b/advisories/unreviewed/2022/05/GHSA-6rm4-hmwm-3853/GHSA-6rm4-hmwm-3853.json @@ -7,12 +7,8 @@ "CVE-2020-3462" ], "details": "A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by authenticating to the application and sending malicious requests to an affected system. A successful exploit could allow the attacker to obtain and modify sensitive information that is stored in the underlying database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6wcp-gj2x-5f4w/GHSA-6wcp-gj2x-5f4w.json b/advisories/unreviewed/2022/05/GHSA-6wcp-gj2x-5f4w/GHSA-6wcp-gj2x-5f4w.json index dbf2384703b..fb09ca8445e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6wcp-gj2x-5f4w/GHSA-6wcp-gj2x-5f4w.json +++ b/advisories/unreviewed/2022/05/GHSA-6wcp-gj2x-5f4w/GHSA-6wcp-gj2x-5f4w.json @@ -7,12 +7,8 @@ "CVE-2020-7361" ], "details": "The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct and send arbitrary OS commands via the POST parameter 'path', and those commands will run in an elevated SYSTEM context on the underlying Windows operating system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6wgf-f4fv-8p8m/GHSA-6wgf-f4fv-8p8m.json b/advisories/unreviewed/2022/05/GHSA-6wgf-f4fv-8p8m/GHSA-6wgf-f4fv-8p8m.json index 7b80fe090fb..d6f1dfa1e81 100644 --- a/advisories/unreviewed/2022/05/GHSA-6wgf-f4fv-8p8m/GHSA-6wgf-f4fv-8p8m.json +++ b/advisories/unreviewed/2022/05/GHSA-6wgf-f4fv-8p8m/GHSA-6wgf-f4fv-8p8m.json @@ -7,12 +7,8 @@ "CVE-2019-20027" ], "details": "Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if incorrectly configured to allow a blank username and password combination to be entered as a valid, successfully authenticating account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-72pg-265r-qmhq/GHSA-72pg-265r-qmhq.json b/advisories/unreviewed/2022/05/GHSA-72pg-265r-qmhq/GHSA-72pg-265r-qmhq.json index da7e8981c26..787e88742b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-72pg-265r-qmhq/GHSA-72pg-265r-qmhq.json +++ b/advisories/unreviewed/2022/05/GHSA-72pg-265r-qmhq/GHSA-72pg-265r-qmhq.json @@ -7,12 +7,8 @@ "CVE-2020-6511" ], "details": "Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-73gf-w4w2-j9pc/GHSA-73gf-w4w2-j9pc.json b/advisories/unreviewed/2022/05/GHSA-73gf-w4w2-j9pc/GHSA-73gf-w4w2-j9pc.json index 1a5c0094d8e..254944c4548 100644 --- a/advisories/unreviewed/2022/05/GHSA-73gf-w4w2-j9pc/GHSA-73gf-w4w2-j9pc.json +++ b/advisories/unreviewed/2022/05/GHSA-73gf-w4w2-j9pc/GHSA-73gf-w4w2-j9pc.json @@ -7,12 +7,8 @@ "CVE-2020-16199" ], "details": "Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73hh-256q-9c49/GHSA-73hh-256q-9c49.json b/advisories/unreviewed/2022/05/GHSA-73hh-256q-9c49/GHSA-73hh-256q-9c49.json index f85e65f7472..c751b35a39f 100644 --- a/advisories/unreviewed/2022/05/GHSA-73hh-256q-9c49/GHSA-73hh-256q-9c49.json +++ b/advisories/unreviewed/2022/05/GHSA-73hh-256q-9c49/GHSA-73hh-256q-9c49.json @@ -7,12 +7,8 @@ "CVE-2020-14319" ], "details": "It was found that the AMQ Online console is vulnerable to a Cross-Site Request Forgery (CSRF) which is exploitable in cases where preflight checks are not instigated or bypassed. For example authorised users using an older browser with Adobe Flash are vulnerable when targeted by an attacker. This flaw affects all versions of AMQ-Online prior to 1.5.2 and Enmasse versions 0.31.0-rc1 up until but not including 0.32.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73rh-fgwv-4hpw/GHSA-73rh-fgwv-4hpw.json b/advisories/unreviewed/2022/05/GHSA-73rh-fgwv-4hpw/GHSA-73rh-fgwv-4hpw.json index 3394d97fa5f..c41bbc9e8b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-73rh-fgwv-4hpw/GHSA-73rh-fgwv-4hpw.json +++ b/advisories/unreviewed/2022/05/GHSA-73rh-fgwv-4hpw/GHSA-73rh-fgwv-4hpw.json @@ -7,12 +7,8 @@ "CVE-2020-5616" ], "details": "[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and earlier, [Telop01] free edition ver1.0.0, [Gallery01] free edition ver1.0.3 and earlier, [CalendarForm01] free edition ver1.0.3 and earlier, and [Link01] free edition ver1.0.0 allows remote attackers to bypass authentication and log in to the product with administrative privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-74g8-qm3r-62cr/GHSA-74g8-qm3r-62cr.json b/advisories/unreviewed/2022/05/GHSA-74g8-qm3r-62cr/GHSA-74g8-qm3r-62cr.json index b8d90a96533..af61bd309a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-74g8-qm3r-62cr/GHSA-74g8-qm3r-62cr.json +++ b/advisories/unreviewed/2022/05/GHSA-74g8-qm3r-62cr/GHSA-74g8-qm3r-62cr.json @@ -7,12 +7,8 @@ "CVE-2020-15947" ], "details": "A SQL injection vulnerability in the qm_adm/qm_export_stats_run.do endpoint of Loway QueueMetrics before 19.10.21 allows remote authenticated users to execute arbitrary SQL commands via the exportId parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-74j3-65q6-x5h9/GHSA-74j3-65q6-x5h9.json b/advisories/unreviewed/2022/05/GHSA-74j3-65q6-x5h9/GHSA-74j3-65q6-x5h9.json index f1a75d6a5d0..7b4fd2f1113 100644 --- a/advisories/unreviewed/2022/05/GHSA-74j3-65q6-x5h9/GHSA-74j3-65q6-x5h9.json +++ b/advisories/unreviewed/2022/05/GHSA-74j3-65q6-x5h9/GHSA-74j3-65q6-x5h9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-75r7-g667-c286/GHSA-75r7-g667-c286.json b/advisories/unreviewed/2022/05/GHSA-75r7-g667-c286/GHSA-75r7-g667-c286.json index 50212cec5fa..40256959239 100644 --- a/advisories/unreviewed/2022/05/GHSA-75r7-g667-c286/GHSA-75r7-g667-c286.json +++ b/advisories/unreviewed/2022/05/GHSA-75r7-g667-c286/GHSA-75r7-g667-c286.json @@ -7,12 +7,8 @@ "CVE-2020-6518" ], "details": "Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-76f8-hj3g-qcfw/GHSA-76f8-hj3g-qcfw.json b/advisories/unreviewed/2022/05/GHSA-76f8-hj3g-qcfw/GHSA-76f8-hj3g-qcfw.json index 75d2d592b98..bb4b9f81a25 100644 --- a/advisories/unreviewed/2022/05/GHSA-76f8-hj3g-qcfw/GHSA-76f8-hj3g-qcfw.json +++ b/advisories/unreviewed/2022/05/GHSA-76f8-hj3g-qcfw/GHSA-76f8-hj3g-qcfw.json @@ -7,12 +7,8 @@ "CVE-2020-3375" ], "details": "A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to information that they are not authorized to access, make changes to the system that they are not authorized to make, and execute commands on an affected system with privileges of the root user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-78c7-w9g8-rxrh/GHSA-78c7-w9g8-rxrh.json b/advisories/unreviewed/2022/05/GHSA-78c7-w9g8-rxrh/GHSA-78c7-w9g8-rxrh.json index df8cc2964e3..7b123252a55 100644 --- a/advisories/unreviewed/2022/05/GHSA-78c7-w9g8-rxrh/GHSA-78c7-w9g8-rxrh.json +++ b/advisories/unreviewed/2022/05/GHSA-78c7-w9g8-rxrh/GHSA-78c7-w9g8-rxrh.json @@ -7,12 +7,8 @@ "CVE-2020-15916" ], "details": "goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-795r-6pcp-7494/GHSA-795r-6pcp-7494.json b/advisories/unreviewed/2022/05/GHSA-795r-6pcp-7494/GHSA-795r-6pcp-7494.json index abf458fd865..f6400118542 100644 --- a/advisories/unreviewed/2022/05/GHSA-795r-6pcp-7494/GHSA-795r-6pcp-7494.json +++ b/advisories/unreviewed/2022/05/GHSA-795r-6pcp-7494/GHSA-795r-6pcp-7494.json @@ -7,12 +7,8 @@ "CVE-2020-0239" ], "details": "In getDocumentMetadata of DocumentsContract.java, there is a possible disclosure of location metadata from a file due to a permissions bypass. This could lead to local information disclosure from a file (eg. a photo) containing location metadata with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-151095863", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-79j3-2528-mw7j/GHSA-79j3-2528-mw7j.json b/advisories/unreviewed/2022/05/GHSA-79j3-2528-mw7j/GHSA-79j3-2528-mw7j.json index bb8160bdc92..aee6c5ae932 100644 --- a/advisories/unreviewed/2022/05/GHSA-79j3-2528-mw7j/GHSA-79j3-2528-mw7j.json +++ b/advisories/unreviewed/2022/05/GHSA-79j3-2528-mw7j/GHSA-79j3-2528-mw7j.json @@ -7,12 +7,8 @@ "CVE-2019-20032" ], "details": "An attacker with access to an InMail voicemail box equipped with the find me/follow me feature on Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices, may access the system's administration modem.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-79jq-9hhm-7rfm/GHSA-79jq-9hhm-7rfm.json b/advisories/unreviewed/2022/05/GHSA-79jq-9hhm-7rfm/GHSA-79jq-9hhm-7rfm.json index 8dd66f83256..6e91ecfce53 100644 --- a/advisories/unreviewed/2022/05/GHSA-79jq-9hhm-7rfm/GHSA-79jq-9hhm-7rfm.json +++ b/advisories/unreviewed/2022/05/GHSA-79jq-9hhm-7rfm/GHSA-79jq-9hhm-7rfm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7c24-46m8-4q8r/GHSA-7c24-46m8-4q8r.json b/advisories/unreviewed/2022/05/GHSA-7c24-46m8-4q8r/GHSA-7c24-46m8-4q8r.json index c9a1db5b97c..e4b0738c29f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c24-46m8-4q8r/GHSA-7c24-46m8-4q8r.json +++ b/advisories/unreviewed/2022/05/GHSA-7c24-46m8-4q8r/GHSA-7c24-46m8-4q8r.json @@ -7,12 +7,8 @@ "CVE-2019-20026" ], "details": "The WebPro interface in NEC SV9100 software releases 7.0 or higher allows unauthenticated remote attackers to reset all existing usernames and passwords to default values via a crafted request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7f3h-w49m-gjpq/GHSA-7f3h-w49m-gjpq.json b/advisories/unreviewed/2022/05/GHSA-7f3h-w49m-gjpq/GHSA-7f3h-w49m-gjpq.json index dc150a7a046..dc61986310a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f3h-w49m-gjpq/GHSA-7f3h-w49m-gjpq.json +++ b/advisories/unreviewed/2022/05/GHSA-7f3h-w49m-gjpq/GHSA-7f3h-w49m-gjpq.json @@ -7,12 +7,8 @@ "CVE-2020-3701" ], "details": "Use after free issue while processing error notification from camx driver due to not properly releasing the sequence data in Snapdragon Mobile in Saipan, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7f7j-qhc3-4fvp/GHSA-7f7j-qhc3-4fvp.json b/advisories/unreviewed/2022/05/GHSA-7f7j-qhc3-4fvp/GHSA-7f7j-qhc3-4fvp.json index 870b1646270..0a33f216279 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f7j-qhc3-4fvp/GHSA-7f7j-qhc3-4fvp.json +++ b/advisories/unreviewed/2022/05/GHSA-7f7j-qhc3-4fvp/GHSA-7f7j-qhc3-4fvp.json @@ -7,12 +7,8 @@ "CVE-2020-15650" ], "details": "Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite Firefox settings (but not access the previous profile). *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.11.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7fcg-7xhc-3997/GHSA-7fcg-7xhc-3997.json b/advisories/unreviewed/2022/05/GHSA-7fcg-7xhc-3997/GHSA-7fcg-7xhc-3997.json index 83fbd8f1be0..ae218882c05 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fcg-7xhc-3997/GHSA-7fcg-7xhc-3997.json +++ b/advisories/unreviewed/2022/05/GHSA-7fcg-7xhc-3997/GHSA-7fcg-7xhc-3997.json @@ -7,12 +7,8 @@ "CVE-2020-11984" ], "details": "Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7fw6-29gc-7f7f/GHSA-7fw6-29gc-7f7f.json b/advisories/unreviewed/2022/05/GHSA-7fw6-29gc-7f7f/GHSA-7fw6-29gc-7f7f.json index 0f61e92a28d..c2cf7a9a453 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fw6-29gc-7f7f/GHSA-7fw6-29gc-7f7f.json +++ b/advisories/unreviewed/2022/05/GHSA-7fw6-29gc-7f7f/GHSA-7fw6-29gc-7f7f.json @@ -7,12 +7,8 @@ "CVE-2019-14099" ], "details": "Device misbehavior may be observed when incorrect offset, length or number of buffers is passed by user space in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8053, MDM9206, MDM9207C, MDM9607, MSM8909W, MSM8917, MSM8953, Nicobar, QCM2150, QCS405, QCS605, QM215, Saipan, SC8180X, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7h9m-xcfj-p257/GHSA-7h9m-xcfj-p257.json b/advisories/unreviewed/2022/05/GHSA-7h9m-xcfj-p257/GHSA-7h9m-xcfj-p257.json index 13f4dbb02d1..d231acdce9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7h9m-xcfj-p257/GHSA-7h9m-xcfj-p257.json +++ b/advisories/unreviewed/2022/05/GHSA-7h9m-xcfj-p257/GHSA-7h9m-xcfj-p257.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7j58-55gj-jc8g/GHSA-7j58-55gj-jc8g.json b/advisories/unreviewed/2022/05/GHSA-7j58-55gj-jc8g/GHSA-7j58-55gj-jc8g.json index 2417a80d37e..1952f9b96b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j58-55gj-jc8g/GHSA-7j58-55gj-jc8g.json +++ b/advisories/unreviewed/2022/05/GHSA-7j58-55gj-jc8g/GHSA-7j58-55gj-jc8g.json @@ -7,12 +7,8 @@ "CVE-2020-12779" ], "details": "Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with malicious script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "WEB", diff --git a/advisories/unreviewed/2022/05/GHSA-7jf9-3fj5-v5px/GHSA-7jf9-3fj5-v5px.json b/advisories/unreviewed/2022/05/GHSA-7jf9-3fj5-v5px/GHSA-7jf9-3fj5-v5px.json index 07f598364c8..c477965fd9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jf9-3fj5-v5px/GHSA-7jf9-3fj5-v5px.json +++ b/advisories/unreviewed/2022/05/GHSA-7jf9-3fj5-v5px/GHSA-7jf9-3fj5-v5px.json @@ -7,12 +7,8 @@ "CVE-2020-15058" ], "details": "Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7mjr-xg74-fp36/GHSA-7mjr-xg74-fp36.json b/advisories/unreviewed/2022/05/GHSA-7mjr-xg74-fp36/GHSA-7mjr-xg74-fp36.json index f91eb44006b..c4e0a70e69f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mjr-xg74-fp36/GHSA-7mjr-xg74-fp36.json +++ b/advisories/unreviewed/2022/05/GHSA-7mjr-xg74-fp36/GHSA-7mjr-xg74-fp36.json @@ -7,12 +7,8 @@ "CVE-2020-13793" ], "details": "Unsafe storage of AD credentials in Ivanti DSM netinst 5.1 due to a static, hard-coded encryption key.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7q4r-vh4x-gr7v/GHSA-7q4r-vh4x-gr7v.json b/advisories/unreviewed/2022/05/GHSA-7q4r-vh4x-gr7v/GHSA-7q4r-vh4x-gr7v.json index f913eb19fcb..dfcefc9cc30 100644 --- a/advisories/unreviewed/2022/05/GHSA-7q4r-vh4x-gr7v/GHSA-7q4r-vh4x-gr7v.json +++ b/advisories/unreviewed/2022/05/GHSA-7q4r-vh4x-gr7v/GHSA-7q4r-vh4x-gr7v.json @@ -7,12 +7,8 @@ "CVE-2019-20025" ], "details": "Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with a hardcoded username and password, aka a Static Credential Vulnerability. The vulnerability is due to an undocumented user account with manufacturer privilege level. An attacker could exploit this vulnerability by using this account to remotely log into an affected device. A successful exploit could allow the attacker to log into the device with manufacturer level access. This vulnerability affects SV9100 PBXes that are running software release 6.0 or higher. This vulnerability does not affect SV9100 software releases prior to 6.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7qq3-vgfq-7f3m/GHSA-7qq3-vgfq-7f3m.json b/advisories/unreviewed/2022/05/GHSA-7qq3-vgfq-7f3m/GHSA-7qq3-vgfq-7f3m.json index 179dc70648a..c9ed7b111e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qq3-vgfq-7f3m/GHSA-7qq3-vgfq-7f3m.json +++ b/advisories/unreviewed/2022/05/GHSA-7qq3-vgfq-7f3m/GHSA-7qq3-vgfq-7f3m.json @@ -7,12 +7,8 @@ "CVE-2020-15647" ], "details": "A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7qrv-c764-rg7p/GHSA-7qrv-c764-rg7p.json b/advisories/unreviewed/2022/05/GHSA-7qrv-c764-rg7p/GHSA-7qrv-c764-rg7p.json index 83ad192aee7..b5e185e1aca 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qrv-c764-rg7p/GHSA-7qrv-c764-rg7p.json +++ b/advisories/unreviewed/2022/05/GHSA-7qrv-c764-rg7p/GHSA-7qrv-c764-rg7p.json @@ -7,12 +7,8 @@ "CVE-2020-15055" ], "details": "TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7vv8-8vrw-6j74/GHSA-7vv8-8vrw-6j74.json b/advisories/unreviewed/2022/05/GHSA-7vv8-8vrw-6j74/GHSA-7vv8-8vrw-6j74.json index 085cbdf0622..54b67473ae3 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vv8-8vrw-6j74/GHSA-7vv8-8vrw-6j74.json +++ b/advisories/unreviewed/2022/05/GHSA-7vv8-8vrw-6j74/GHSA-7vv8-8vrw-6j74.json @@ -7,12 +7,8 @@ "CVE-2020-6514" ], "details": "Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -128,9 +124,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7vxf-797g-778q/GHSA-7vxf-797g-778q.json b/advisories/unreviewed/2022/05/GHSA-7vxf-797g-778q/GHSA-7vxf-797g-778q.json index f73ef17fb60..4ab0fb9dd20 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vxf-797g-778q/GHSA-7vxf-797g-778q.json +++ b/advisories/unreviewed/2022/05/GHSA-7vxf-797g-778q/GHSA-7vxf-797g-778q.json @@ -7,12 +7,8 @@ "CVE-2020-4539" ], "details": "IBM Jazz Reporting Service 6.0.2, 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7wc2-93p7-cpqv/GHSA-7wc2-93p7-cpqv.json b/advisories/unreviewed/2022/05/GHSA-7wc2-93p7-cpqv/GHSA-7wc2-93p7-cpqv.json index 1d74791e044..4fb54ebdc22 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wc2-93p7-cpqv/GHSA-7wc2-93p7-cpqv.json +++ b/advisories/unreviewed/2022/05/GHSA-7wc2-93p7-cpqv/GHSA-7wc2-93p7-cpqv.json @@ -7,12 +7,8 @@ "CVE-2020-15907" ], "details": "In Mahara 19.04 before 19.04.6, 19.10 before 19.10.4, and 20.04 before 20.04.1, certain places could execute file or folder names containing JavaScript.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7wh3-q4mq-pgf4/GHSA-7wh3-q4mq-pgf4.json b/advisories/unreviewed/2022/05/GHSA-7wh3-q4mq-pgf4/GHSA-7wh3-q4mq-pgf4.json index d2a7ed9060a..8ea0a2cbd00 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wh3-q4mq-pgf4/GHSA-7wh3-q4mq-pgf4.json +++ b/advisories/unreviewed/2022/05/GHSA-7wh3-q4mq-pgf4/GHSA-7wh3-q4mq-pgf4.json @@ -7,12 +7,8 @@ "CVE-2020-15825" ], "details": "In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wjc-2c4g-g553/GHSA-7wjc-2c4g-g553.json b/advisories/unreviewed/2022/05/GHSA-7wjc-2c4g-g553/GHSA-7wjc-2c4g-g553.json index 8d91fab45d8..5bbaa3d691b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wjc-2c4g-g553/GHSA-7wjc-2c4g-g553.json +++ b/advisories/unreviewed/2022/05/GHSA-7wjc-2c4g-g553/GHSA-7wjc-2c4g-g553.json @@ -7,12 +7,8 @@ "CVE-2020-12499" ], "details": "In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on import of project files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7xmx-g36g-cqwh/GHSA-7xmx-g36g-cqwh.json b/advisories/unreviewed/2022/05/GHSA-7xmx-g36g-cqwh/GHSA-7xmx-g36g-cqwh.json index 3ca4d865c13..2b658f8e6f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xmx-g36g-cqwh/GHSA-7xmx-g36g-cqwh.json +++ b/advisories/unreviewed/2022/05/GHSA-7xmx-g36g-cqwh/GHSA-7xmx-g36g-cqwh.json @@ -7,12 +7,8 @@ "CVE-2020-4410" ], "details": "IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to send a specially crafted HTTP GET request to read attachments on the server that they should not have access to. IBM X-Force ID: 179539.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7xv5-2fmr-w625/GHSA-7xv5-2fmr-w625.json b/advisories/unreviewed/2022/05/GHSA-7xv5-2fmr-w625/GHSA-7xv5-2fmr-w625.json index b989fd86601..4a51044583e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xv5-2fmr-w625/GHSA-7xv5-2fmr-w625.json +++ b/advisories/unreviewed/2022/05/GHSA-7xv5-2fmr-w625/GHSA-7xv5-2fmr-w625.json @@ -7,12 +7,8 @@ "CVE-2020-4631" ], "details": "IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned access to everyone with full control permissions, which could allow a local user to cause interruption of the service operations. IBM X-Force ID: 185372.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7xw4-rm32-rvwj/GHSA-7xw4-rm32-rvwj.json b/advisories/unreviewed/2022/05/GHSA-7xw4-rm32-rvwj/GHSA-7xw4-rm32-rvwj.json index e8596095c43..252e8be2369 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xw4-rm32-rvwj/GHSA-7xw4-rm32-rvwj.json +++ b/advisories/unreviewed/2022/05/GHSA-7xw4-rm32-rvwj/GHSA-7xw4-rm32-rvwj.json @@ -7,12 +7,8 @@ "CVE-2020-5615" ], "details": "Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1.0.0 allows remote attackers to hijack the authentication of administrators via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7xw8-h3mg-6x9g/GHSA-7xw8-h3mg-6x9g.json b/advisories/unreviewed/2022/05/GHSA-7xw8-h3mg-6x9g/GHSA-7xw8-h3mg-6x9g.json index df1dd55bc5a..3b3daa26d73 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xw8-h3mg-6x9g/GHSA-7xw8-h3mg-6x9g.json +++ b/advisories/unreviewed/2022/05/GHSA-7xw8-h3mg-6x9g/GHSA-7xw8-h3mg-6x9g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8359-42rq-7mfj/GHSA-8359-42rq-7mfj.json b/advisories/unreviewed/2022/05/GHSA-8359-42rq-7mfj/GHSA-8359-42rq-7mfj.json index a0662a6e326..050c9d7d21a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8359-42rq-7mfj/GHSA-8359-42rq-7mfj.json +++ b/advisories/unreviewed/2022/05/GHSA-8359-42rq-7mfj/GHSA-8359-42rq-7mfj.json @@ -7,12 +7,8 @@ "CVE-2019-18619" ], "details": "Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8382-whm2-5r8x/GHSA-8382-whm2-5r8x.json b/advisories/unreviewed/2022/05/GHSA-8382-whm2-5r8x/GHSA-8382-whm2-5r8x.json index b8ca499e598..8e794705d95 100644 --- a/advisories/unreviewed/2022/05/GHSA-8382-whm2-5r8x/GHSA-8382-whm2-5r8x.json +++ b/advisories/unreviewed/2022/05/GHSA-8382-whm2-5r8x/GHSA-8382-whm2-5r8x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-83fh-hgc9-f5wp/GHSA-83fh-hgc9-f5wp.json b/advisories/unreviewed/2022/05/GHSA-83fh-hgc9-f5wp/GHSA-83fh-hgc9-f5wp.json index 313fbf8f65f..334807de2d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-83fh-hgc9-f5wp/GHSA-83fh-hgc9-f5wp.json +++ b/advisories/unreviewed/2022/05/GHSA-83fh-hgc9-f5wp/GHSA-83fh-hgc9-f5wp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-83vw-qmcc-rxwg/GHSA-83vw-qmcc-rxwg.json b/advisories/unreviewed/2022/05/GHSA-83vw-qmcc-rxwg/GHSA-83vw-qmcc-rxwg.json index 0e83b716f16..42209feecb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-83vw-qmcc-rxwg/GHSA-83vw-qmcc-rxwg.json +++ b/advisories/unreviewed/2022/05/GHSA-83vw-qmcc-rxwg/GHSA-83vw-qmcc-rxwg.json @@ -7,12 +7,8 @@ "CVE-2020-13295" ], "details": "For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-849g-hq59-rhj8/GHSA-849g-hq59-rhj8.json b/advisories/unreviewed/2022/05/GHSA-849g-hq59-rhj8/GHSA-849g-hq59-rhj8.json index 2fc6eaa2f56..bcbd12fa795 100644 --- a/advisories/unreviewed/2022/05/GHSA-849g-hq59-rhj8/GHSA-849g-hq59-rhj8.json +++ b/advisories/unreviewed/2022/05/GHSA-849g-hq59-rhj8/GHSA-849g-hq59-rhj8.json @@ -7,12 +7,8 @@ "CVE-2020-4317" ], "details": "IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operations for Waternamics are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 177355.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-849w-6cw8-9p7m/GHSA-849w-6cw8-9p7m.json b/advisories/unreviewed/2022/05/GHSA-849w-6cw8-9p7m/GHSA-849w-6cw8-9p7m.json index 3bffdebf050..432329b2d27 100644 --- a/advisories/unreviewed/2022/05/GHSA-849w-6cw8-9p7m/GHSA-849w-6cw8-9p7m.json +++ b/advisories/unreviewed/2022/05/GHSA-849w-6cw8-9p7m/GHSA-849w-6cw8-9p7m.json @@ -7,12 +7,8 @@ "CVE-2020-14310" ], "details": "There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file which has a name with UINT32_MAX, leading to read_section_as_string() to an arithmetic overflow, zero-sized allocation and further heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-85wr-m437-h8xf/GHSA-85wr-m437-h8xf.json b/advisories/unreviewed/2022/05/GHSA-85wr-m437-h8xf/GHSA-85wr-m437-h8xf.json index 38b3944308c..484b30cf940 100644 --- a/advisories/unreviewed/2022/05/GHSA-85wr-m437-h8xf/GHSA-85wr-m437-h8xf.json +++ b/advisories/unreviewed/2022/05/GHSA-85wr-m437-h8xf/GHSA-85wr-m437-h8xf.json @@ -7,12 +7,8 @@ "CVE-2020-6516" ], "details": "Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-869x-gj57-wpqr/GHSA-869x-gj57-wpqr.json b/advisories/unreviewed/2022/05/GHSA-869x-gj57-wpqr/GHSA-869x-gj57-wpqr.json index 19c123784b4..d61775b1684 100644 --- a/advisories/unreviewed/2022/05/GHSA-869x-gj57-wpqr/GHSA-869x-gj57-wpqr.json +++ b/advisories/unreviewed/2022/05/GHSA-869x-gj57-wpqr/GHSA-869x-gj57-wpqr.json @@ -7,12 +7,8 @@ "CVE-2020-11583" ], "details": "A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-86qf-5646-chg9/GHSA-86qf-5646-chg9.json b/advisories/unreviewed/2022/05/GHSA-86qf-5646-chg9/GHSA-86qf-5646-chg9.json index a5ac6bcb4c1..b05e0997031 100644 --- a/advisories/unreviewed/2022/05/GHSA-86qf-5646-chg9/GHSA-86qf-5646-chg9.json +++ b/advisories/unreviewed/2022/05/GHSA-86qf-5646-chg9/GHSA-86qf-5646-chg9.json @@ -7,12 +7,8 @@ "CVE-2020-0257" ], "details": "In SpecializeCommon of com_android_internal_os_Zygote.cpp, there is a permissions bypass due to an incomplete cleanup. This could lead to local escalation of privilege in isolated processes with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-156741968", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-87c7-xx7r-6cw2/GHSA-87c7-xx7r-6cw2.json b/advisories/unreviewed/2022/05/GHSA-87c7-xx7r-6cw2/GHSA-87c7-xx7r-6cw2.json index aa6be8519e5..7be238d1e6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-87c7-xx7r-6cw2/GHSA-87c7-xx7r-6cw2.json +++ b/advisories/unreviewed/2022/05/GHSA-87c7-xx7r-6cw2/GHSA-87c7-xx7r-6cw2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-87hv-wrhm-fv9f/GHSA-87hv-wrhm-fv9f.json b/advisories/unreviewed/2022/05/GHSA-87hv-wrhm-fv9f/GHSA-87hv-wrhm-fv9f.json index c7cd91d624f..63a45e3b0d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-87hv-wrhm-fv9f/GHSA-87hv-wrhm-fv9f.json +++ b/advisories/unreviewed/2022/05/GHSA-87hv-wrhm-fv9f/GHSA-87hv-wrhm-fv9f.json @@ -7,12 +7,8 @@ "CVE-2020-9677" ], "details": "Adobe Prelude versions 9.0 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-87q6-48j2-hggg/GHSA-87q6-48j2-hggg.json b/advisories/unreviewed/2022/05/GHSA-87q6-48j2-hggg/GHSA-87q6-48j2-hggg.json index ab029ed8dab..12ecec119a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-87q6-48j2-hggg/GHSA-87q6-48j2-hggg.json +++ b/advisories/unreviewed/2022/05/GHSA-87q6-48j2-hggg/GHSA-87q6-48j2-hggg.json @@ -7,12 +7,8 @@ "CVE-2020-9687" ], "details": "Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-87rc-rw9m-r58v/GHSA-87rc-rw9m-r58v.json b/advisories/unreviewed/2022/05/GHSA-87rc-rw9m-r58v/GHSA-87rc-rw9m-r58v.json index c68cc7f4772..070686d9cb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-87rc-rw9m-r58v/GHSA-87rc-rw9m-r58v.json +++ b/advisories/unreviewed/2022/05/GHSA-87rc-rw9m-r58v/GHSA-87rc-rw9m-r58v.json @@ -7,12 +7,8 @@ "CVE-2020-6525" ], "details": "Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-88j7-9543-qfmf/GHSA-88j7-9543-qfmf.json b/advisories/unreviewed/2022/05/GHSA-88j7-9543-qfmf/GHSA-88j7-9543-qfmf.json index 162066a7336..fb49c5f4403 100644 --- a/advisories/unreviewed/2022/05/GHSA-88j7-9543-qfmf/GHSA-88j7-9543-qfmf.json +++ b/advisories/unreviewed/2022/05/GHSA-88j7-9543-qfmf/GHSA-88j7-9543-qfmf.json @@ -7,12 +7,8 @@ "CVE-2020-15065" ], "details": "DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to denial-of-service the device via long input values.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8932-q9ph-8rjc/GHSA-8932-q9ph-8rjc.json b/advisories/unreviewed/2022/05/GHSA-8932-q9ph-8rjc/GHSA-8932-q9ph-8rjc.json index 0d1812418b7..8a89ee9ec06 100644 --- a/advisories/unreviewed/2022/05/GHSA-8932-q9ph-8rjc/GHSA-8932-q9ph-8rjc.json +++ b/advisories/unreviewed/2022/05/GHSA-8932-q9ph-8rjc/GHSA-8932-q9ph-8rjc.json @@ -7,12 +7,8 @@ "CVE-2020-15056" ], "details": "TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8932-qxvp-f4gm/GHSA-8932-qxvp-f4gm.json b/advisories/unreviewed/2022/05/GHSA-8932-qxvp-f4gm/GHSA-8932-qxvp-f4gm.json index 20a3f375214..12a4f9f5e48 100644 --- a/advisories/unreviewed/2022/05/GHSA-8932-qxvp-f4gm/GHSA-8932-qxvp-f4gm.json +++ b/advisories/unreviewed/2022/05/GHSA-8932-qxvp-f4gm/GHSA-8932-qxvp-f4gm.json @@ -7,12 +7,8 @@ "CVE-2020-4549" ], "details": "IBM i2 Analyst Notebook 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183317.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-89jc-6wpm-mq54/GHSA-89jc-6wpm-mq54.json b/advisories/unreviewed/2022/05/GHSA-89jc-6wpm-mq54/GHSA-89jc-6wpm-mq54.json index 46a4b8ca90c..a17c0b8b5c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-89jc-6wpm-mq54/GHSA-89jc-6wpm-mq54.json +++ b/advisories/unreviewed/2022/05/GHSA-89jc-6wpm-mq54/GHSA-89jc-6wpm-mq54.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-89mq-r3q6-9q3q/GHSA-89mq-r3q6-9q3q.json b/advisories/unreviewed/2022/05/GHSA-89mq-r3q6-9q3q/GHSA-89mq-r3q6-9q3q.json index 092fbe79a23..93277dbda78 100644 --- a/advisories/unreviewed/2022/05/GHSA-89mq-r3q6-9q3q/GHSA-89mq-r3q6-9q3q.json +++ b/advisories/unreviewed/2022/05/GHSA-89mq-r3q6-9q3q/GHSA-89mq-r3q6-9q3q.json @@ -7,12 +7,8 @@ "CVE-2020-11993" ], "details": "Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above \"info\" will mitigate this vulnerability for unpatched servers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cwp-mjww-pqc2/GHSA-8cwp-mjww-pqc2.json b/advisories/unreviewed/2022/05/GHSA-8cwp-mjww-pqc2/GHSA-8cwp-mjww-pqc2.json index 1c419499ca6..ede4600fe0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cwp-mjww-pqc2/GHSA-8cwp-mjww-pqc2.json +++ b/advisories/unreviewed/2022/05/GHSA-8cwp-mjww-pqc2/GHSA-8cwp-mjww-pqc2.json @@ -7,12 +7,8 @@ "CVE-2020-11934" ], "details": "It was discovered that snapctl user-open allowed altering the $XDG_DATA_DIRS environment variable when calling the system xdg-open. OpenURL() in usersession/userd/launcher.go would alter $XDG_DATA_DIRS to append a path to a directory controlled by the calling snap. A malicious snap could exploit this to bypass intended access restrictions to control how the host system xdg-open script opens the URL and, for example, execute a script shipped with the snap without confinement. This issue did not affect Ubuntu Core systems. Fixed in snapd versions 2.45.1ubuntu0.2, 2.45.1+18.04.2 and 2.45.1+20.04.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8f6j-9hh3-9c9x/GHSA-8f6j-9hh3-9c9x.json b/advisories/unreviewed/2022/05/GHSA-8f6j-9hh3-9c9x/GHSA-8f6j-9hh3-9c9x.json index 452e3d6df00..b0ad595e457 100644 --- a/advisories/unreviewed/2022/05/GHSA-8f6j-9hh3-9c9x/GHSA-8f6j-9hh3-9c9x.json +++ b/advisories/unreviewed/2022/05/GHSA-8f6j-9hh3-9c9x/GHSA-8f6j-9hh3-9c9x.json @@ -7,12 +7,8 @@ "CVE-2020-16094" ], "details": "In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8fw8-r7q6-4p56/GHSA-8fw8-r7q6-4p56.json b/advisories/unreviewed/2022/05/GHSA-8fw8-r7q6-4p56/GHSA-8fw8-r7q6-4p56.json index 7a105c9b227..40bafcb0495 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fw8-r7q6-4p56/GHSA-8fw8-r7q6-4p56.json +++ b/advisories/unreviewed/2022/05/GHSA-8fw8-r7q6-4p56/GHSA-8fw8-r7q6-4p56.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8gmw-2xw9-283q/GHSA-8gmw-2xw9-283q.json b/advisories/unreviewed/2022/05/GHSA-8gmw-2xw9-283q/GHSA-8gmw-2xw9-283q.json index 33be9b9c696..4848e425eff 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gmw-2xw9-283q/GHSA-8gmw-2xw9-283q.json +++ b/advisories/unreviewed/2022/05/GHSA-8gmw-2xw9-283q/GHSA-8gmw-2xw9-283q.json @@ -7,12 +7,8 @@ "CVE-2020-8575" ], "details": "Active IQ Unified Manager for VMware vSphere and Windows versions prior to 9.5 are susceptible to a vulnerability which allows administrative users to cause Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8m2x-cw74-m4cg/GHSA-8m2x-cw74-m4cg.json b/advisories/unreviewed/2022/05/GHSA-8m2x-cw74-m4cg/GHSA-8m2x-cw74-m4cg.json index 621f8f9be57..abf05b5224f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8m2x-cw74-m4cg/GHSA-8m2x-cw74-m4cg.json +++ b/advisories/unreviewed/2022/05/GHSA-8m2x-cw74-m4cg/GHSA-8m2x-cw74-m4cg.json @@ -7,12 +7,8 @@ "CVE-2019-4589" ], "details": "IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the \"My schedules and subscriptions\" page is visible and accessible to a less privileged user. IBM X-Force ID: 167449.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8m8x-whvq-8mjm/GHSA-8m8x-whvq-8mjm.json b/advisories/unreviewed/2022/05/GHSA-8m8x-whvq-8mjm/GHSA-8m8x-whvq-8mjm.json index 6bfc7a32607..b6c6e500969 100644 --- a/advisories/unreviewed/2022/05/GHSA-8m8x-whvq-8mjm/GHSA-8m8x-whvq-8mjm.json +++ b/advisories/unreviewed/2022/05/GHSA-8m8x-whvq-8mjm/GHSA-8m8x-whvq-8mjm.json @@ -7,12 +7,8 @@ "CVE-2020-9680" ], "details": "Adobe Prelude versions 9.0 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8p4g-mphq-f8x8/GHSA-8p4g-mphq-f8x8.json b/advisories/unreviewed/2022/05/GHSA-8p4g-mphq-f8x8/GHSA-8p4g-mphq-f8x8.json index dc999ef9974..4107b6d3428 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p4g-mphq-f8x8/GHSA-8p4g-mphq-f8x8.json +++ b/advisories/unreviewed/2022/05/GHSA-8p4g-mphq-f8x8/GHSA-8p4g-mphq-f8x8.json @@ -7,12 +7,8 @@ "CVE-2020-15827" ], "details": "In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8r2j-4c64-vcw7/GHSA-8r2j-4c64-vcw7.json b/advisories/unreviewed/2022/05/GHSA-8r2j-4c64-vcw7/GHSA-8r2j-4c64-vcw7.json index 76c40e38f94..7b60dd1813c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8r2j-4c64-vcw7/GHSA-8r2j-4c64-vcw7.json +++ b/advisories/unreviewed/2022/05/GHSA-8r2j-4c64-vcw7/GHSA-8r2j-4c64-vcw7.json @@ -7,12 +7,8 @@ "CVE-2020-13819" ], "details": "Extreme EAC Appliance 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8rv2-vrwv-jfx5/GHSA-8rv2-vrwv-jfx5.json b/advisories/unreviewed/2022/05/GHSA-8rv2-vrwv-jfx5/GHSA-8rv2-vrwv-jfx5.json index 6d7ad0236f3..352d03f5bc9 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rv2-vrwv-jfx5/GHSA-8rv2-vrwv-jfx5.json +++ b/advisories/unreviewed/2022/05/GHSA-8rv2-vrwv-jfx5/GHSA-8rv2-vrwv-jfx5.json @@ -7,12 +7,8 @@ "CVE-2015-9549" ], "details": "A reflected Cross-site Scripting (XSS) vulnerability exists in OcPortal 9.0.20 via the OCF_EMOTICON_CELL.tpl FIELD_NAME field to data/emoticons.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8v3f-75h6-vppr/GHSA-8v3f-75h6-vppr.json b/advisories/unreviewed/2022/05/GHSA-8v3f-75h6-vppr/GHSA-8v3f-75h6-vppr.json index 7761da4bafc..a64b16b97f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v3f-75h6-vppr/GHSA-8v3f-75h6-vppr.json +++ b/advisories/unreviewed/2022/05/GHSA-8v3f-75h6-vppr/GHSA-8v3f-75h6-vppr.json @@ -7,12 +7,8 @@ "CVE-2020-15823" ], "details": "JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8whj-mpcj-4jv6/GHSA-8whj-mpcj-4jv6.json b/advisories/unreviewed/2022/05/GHSA-8whj-mpcj-4jv6/GHSA-8whj-mpcj-4jv6.json index ba922203bf1..0926873ecb3 100644 --- a/advisories/unreviewed/2022/05/GHSA-8whj-mpcj-4jv6/GHSA-8whj-mpcj-4jv6.json +++ b/advisories/unreviewed/2022/05/GHSA-8whj-mpcj-4jv6/GHSA-8whj-mpcj-4jv6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-927w-mm9x-fr54/GHSA-927w-mm9x-fr54.json b/advisories/unreviewed/2022/05/GHSA-927w-mm9x-fr54/GHSA-927w-mm9x-fr54.json index 1ce1aaae4a4..0d691d5370a 100644 --- a/advisories/unreviewed/2022/05/GHSA-927w-mm9x-fr54/GHSA-927w-mm9x-fr54.json +++ b/advisories/unreviewed/2022/05/GHSA-927w-mm9x-fr54/GHSA-927w-mm9x-fr54.json @@ -7,12 +7,8 @@ "CVE-2020-4554" ], "details": "IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183322.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-92g9-cf99-2j4r/GHSA-92g9-cf99-2j4r.json b/advisories/unreviewed/2022/05/GHSA-92g9-cf99-2j4r/GHSA-92g9-cf99-2j4r.json index cbaaef51577..f7de5180241 100644 --- a/advisories/unreviewed/2022/05/GHSA-92g9-cf99-2j4r/GHSA-92g9-cf99-2j4r.json +++ b/advisories/unreviewed/2022/05/GHSA-92g9-cf99-2j4r/GHSA-92g9-cf99-2j4r.json @@ -7,12 +7,8 @@ "CVE-2020-15954" ], "details": "KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-943v-975q-f779/GHSA-943v-975q-f779.json b/advisories/unreviewed/2022/05/GHSA-943v-975q-f779/GHSA-943v-975q-f779.json index 24b51ed9151..90ba93e2dfc 100644 --- a/advisories/unreviewed/2022/05/GHSA-943v-975q-f779/GHSA-943v-975q-f779.json +++ b/advisories/unreviewed/2022/05/GHSA-943v-975q-f779/GHSA-943v-975q-f779.json @@ -7,12 +7,8 @@ "CVE-2020-3460" ], "details": "A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by intercepting a request from a user and injecting malicious data into an HTTP header. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-946x-5j76-f99g/GHSA-946x-5j76-f99g.json b/advisories/unreviewed/2022/05/GHSA-946x-5j76-f99g/GHSA-946x-5j76-f99g.json index a580cfe7fb9..12afbfc62ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-946x-5j76-f99g/GHSA-946x-5j76-f99g.json +++ b/advisories/unreviewed/2022/05/GHSA-946x-5j76-f99g/GHSA-946x-5j76-f99g.json @@ -7,12 +7,8 @@ "CVE-2020-7828" ], "details": "DaviewIndy 8.98.4 and earlier version contain Heap-based overflow vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9482-q473-qwhj/GHSA-9482-q473-qwhj.json b/advisories/unreviewed/2022/05/GHSA-9482-q473-qwhj/GHSA-9482-q473-qwhj.json index d3d169d3b31..297367668f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-9482-q473-qwhj/GHSA-9482-q473-qwhj.json +++ b/advisories/unreviewed/2022/05/GHSA-9482-q473-qwhj/GHSA-9482-q473-qwhj.json @@ -7,12 +7,8 @@ "CVE-2020-10609" ], "details": "Grundfos CIM 500 v06.16.00 stores plaintext credentials, which may allow sensitive information to be read or allow modification to system settings by someone with access to the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-955p-xvq6-xggj/GHSA-955p-xvq6-xggj.json b/advisories/unreviewed/2022/05/GHSA-955p-xvq6-xggj/GHSA-955p-xvq6-xggj.json index d393c2c1d1f..297cc467453 100644 --- a/advisories/unreviewed/2022/05/GHSA-955p-xvq6-xggj/GHSA-955p-xvq6-xggj.json +++ b/advisories/unreviewed/2022/05/GHSA-955p-xvq6-xggj/GHSA-955p-xvq6-xggj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-95gr-j6v5-xvxf/GHSA-95gr-j6v5-xvxf.json b/advisories/unreviewed/2022/05/GHSA-95gr-j6v5-xvxf/GHSA-95gr-j6v5-xvxf.json index 8e5e20a6ece..1397cdb092c 100644 --- a/advisories/unreviewed/2022/05/GHSA-95gr-j6v5-xvxf/GHSA-95gr-j6v5-xvxf.json +++ b/advisories/unreviewed/2022/05/GHSA-95gr-j6v5-xvxf/GHSA-95gr-j6v5-xvxf.json @@ -7,12 +7,8 @@ "CVE-2020-15416" ], "details": "This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9703.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-962c-595j-rvvh/GHSA-962c-595j-rvvh.json b/advisories/unreviewed/2022/05/GHSA-962c-595j-rvvh/GHSA-962c-595j-rvvh.json index 183ebd2cd15..14309b1fad3 100644 --- a/advisories/unreviewed/2022/05/GHSA-962c-595j-rvvh/GHSA-962c-595j-rvvh.json +++ b/advisories/unreviewed/2022/05/GHSA-962c-595j-rvvh/GHSA-962c-595j-rvvh.json @@ -7,12 +7,8 @@ "CVE-2020-15492" ], "details": "An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP port 85) includes user input into a filesystem access without any further validation. This might allow an unauthenticated attacker to read files on the server via Directory Traversal, or possibly have unspecified other impact.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-973v-v8wv-cw5w/GHSA-973v-v8wv-cw5w.json b/advisories/unreviewed/2022/05/GHSA-973v-v8wv-cw5w/GHSA-973v-v8wv-cw5w.json index 3960c70d565..4569c835129 100644 --- a/advisories/unreviewed/2022/05/GHSA-973v-v8wv-cw5w/GHSA-973v-v8wv-cw5w.json +++ b/advisories/unreviewed/2022/05/GHSA-973v-v8wv-cw5w/GHSA-973v-v8wv-cw5w.json @@ -7,12 +7,8 @@ "CVE-2019-11286" ], "details": "VMware GemFire versions prior to 9.10.0, 9.9.1, 9.8.5, and 9.7.5, and VMware Tanzu GemFire for VMs versions prior to 1.11.0, 1.10.1, 1.9.2, and 1.8.2, contain a JMX service available to the network which does not properly restrict input. A remote authenticated malicious user may request against the service with a crafted set of credentials leading to remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9759-cv86-jj63/GHSA-9759-cv86-jj63.json b/advisories/unreviewed/2022/05/GHSA-9759-cv86-jj63/GHSA-9759-cv86-jj63.json index bf4bc4b4e26..be93e918992 100644 --- a/advisories/unreviewed/2022/05/GHSA-9759-cv86-jj63/GHSA-9759-cv86-jj63.json +++ b/advisories/unreviewed/2022/05/GHSA-9759-cv86-jj63/GHSA-9759-cv86-jj63.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9cmf-h6cw-82xx/GHSA-9cmf-h6cw-82xx.json b/advisories/unreviewed/2022/05/GHSA-9cmf-h6cw-82xx/GHSA-9cmf-h6cw-82xx.json index 04a998f8e26..ccc80b4530d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cmf-h6cw-82xx/GHSA-9cmf-h6cw-82xx.json +++ b/advisories/unreviewed/2022/05/GHSA-9cmf-h6cw-82xx/GHSA-9cmf-h6cw-82xx.json @@ -7,12 +7,8 @@ "CVE-2019-14093" ], "details": "Array out of bound access can occur in display module due to lack of bound check on input parcel received in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, QCM2150, QCS405, QCS605, QM215, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM636, SDM660, SDX20", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9crf-r9gg-4qcg/GHSA-9crf-r9gg-4qcg.json b/advisories/unreviewed/2022/05/GHSA-9crf-r9gg-4qcg/GHSA-9crf-r9gg-4qcg.json index fff38ac4480..925a7f03b52 100644 --- a/advisories/unreviewed/2022/05/GHSA-9crf-r9gg-4qcg/GHSA-9crf-r9gg-4qcg.json +++ b/advisories/unreviewed/2022/05/GHSA-9crf-r9gg-4qcg/GHSA-9crf-r9gg-4qcg.json @@ -7,12 +7,8 @@ "CVE-2020-15819" ], "details": "JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9h84-2w3v-5r29/GHSA-9h84-2w3v-5r29.json b/advisories/unreviewed/2022/05/GHSA-9h84-2w3v-5r29/GHSA-9h84-2w3v-5r29.json index 429e0256580..e42747e5a49 100644 --- a/advisories/unreviewed/2022/05/GHSA-9h84-2w3v-5r29/GHSA-9h84-2w3v-5r29.json +++ b/advisories/unreviewed/2022/05/GHSA-9h84-2w3v-5r29/GHSA-9h84-2w3v-5r29.json @@ -7,12 +7,8 @@ "CVE-2020-15924" ], "details": "There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is required. The injection point resides in one of the authentication parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9h8r-g835-9q7j/GHSA-9h8r-g835-9q7j.json b/advisories/unreviewed/2022/05/GHSA-9h8r-g835-9q7j/GHSA-9h8r-g835-9q7j.json index b42e3d7f61a..24f0846788f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9h8r-g835-9q7j/GHSA-9h8r-g835-9q7j.json +++ b/advisories/unreviewed/2022/05/GHSA-9h8r-g835-9q7j/GHSA-9h8r-g835-9q7j.json @@ -7,12 +7,8 @@ "CVE-2020-15829" ], "details": "In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9j7p-fvvp-cp57/GHSA-9j7p-fvvp-cp57.json b/advisories/unreviewed/2022/05/GHSA-9j7p-fvvp-cp57/GHSA-9j7p-fvvp-cp57.json index ba2d4e9aeb6..8ecba5183b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j7p-fvvp-cp57/GHSA-9j7p-fvvp-cp57.json +++ b/advisories/unreviewed/2022/05/GHSA-9j7p-fvvp-cp57/GHSA-9j7p-fvvp-cp57.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9j98-c4pq-wvqj/GHSA-9j98-c4pq-wvqj.json b/advisories/unreviewed/2022/05/GHSA-9j98-c4pq-wvqj/GHSA-9j98-c4pq-wvqj.json index 03840e4e29d..2a0cd63e0b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j98-c4pq-wvqj/GHSA-9j98-c4pq-wvqj.json +++ b/advisories/unreviewed/2022/05/GHSA-9j98-c4pq-wvqj/GHSA-9j98-c4pq-wvqj.json @@ -7,12 +7,8 @@ "CVE-2020-7205" ], "details": "A potential security vulnerability has been identified in HPE Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit. The vulnerability could be locally exploited to allow arbitrary code execution during the boot process. **Note:** This vulnerability is related to using insmod in GRUB2 in the specific impacted HPE product and HPE is addressing this issue. HPE has made the following software updates and mitigation information to resolve the vulnerability in Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit. HPE provided latest Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting Toolkit which includes the GRUB2 patch to resolve this vulnerability. These new boot images will update GRUB2 and the Forbidden Signature Database (DBX). After the DBX is updated, users will not be able to boot to the older IP, SPP or Scripting ToolKit with Secure Boot enabled. HPE have provided a standalone DBX update tool to work with Microsoft Windows, and supported Linux Operating Systems. These tools can be used to update the Forbidden Signature Database (DBX) from within the OS. **Note:** This DBX update mitigates the GRUB2 issue with insmod enabled, and the \"Boot Hole\" issue for HPE signed GRUB2 applications.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9jhg-945x-fwm5/GHSA-9jhg-945x-fwm5.json b/advisories/unreviewed/2022/05/GHSA-9jhg-945x-fwm5/GHSA-9jhg-945x-fwm5.json index d76f39cfb6c..78be7b73c16 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jhg-945x-fwm5/GHSA-9jhg-945x-fwm5.json +++ b/advisories/unreviewed/2022/05/GHSA-9jhg-945x-fwm5/GHSA-9jhg-945x-fwm5.json @@ -7,12 +7,8 @@ "CVE-2020-6519" ], "details": "Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9jvm-w6r6-8g8m/GHSA-9jvm-w6r6-8g8m.json b/advisories/unreviewed/2022/05/GHSA-9jvm-w6r6-8g8m/GHSA-9jvm-w6r6-8g8m.json index b32b1029552..5a9465e66ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jvm-w6r6-8g8m/GHSA-9jvm-w6r6-8g8m.json +++ b/advisories/unreviewed/2022/05/GHSA-9jvm-w6r6-8g8m/GHSA-9jvm-w6r6-8g8m.json @@ -7,12 +7,8 @@ "CVE-2020-4553" ], "details": "IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183321.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9qx2-wch6-c3mw/GHSA-9qx2-wch6-c3mw.json b/advisories/unreviewed/2022/05/GHSA-9qx2-wch6-c3mw/GHSA-9qx2-wch6-c3mw.json index ea26e5dd30e..c524d5e6f45 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qx2-wch6-c3mw/GHSA-9qx2-wch6-c3mw.json +++ b/advisories/unreviewed/2022/05/GHSA-9qx2-wch6-c3mw/GHSA-9qx2-wch6-c3mw.json @@ -7,12 +7,8 @@ "CVE-2020-4486" ], "details": "IBM QRadar 7.2.0 thorugh 7.2.9 could allow an authenticated user to overwrite or delete arbitrary files due to a flaw after WinCollect installation. IBM X-Force ID: 181861.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9rj4-m4p5-2v9x/GHSA-9rj4-m4p5-2v9x.json b/advisories/unreviewed/2022/05/GHSA-9rj4-m4p5-2v9x/GHSA-9rj4-m4p5-2v9x.json index b3a130a52b5..e96b9dcee66 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rj4-m4p5-2v9x/GHSA-9rj4-m4p5-2v9x.json +++ b/advisories/unreviewed/2022/05/GHSA-9rj4-m4p5-2v9x/GHSA-9rj4-m4p5-2v9x.json @@ -7,12 +7,8 @@ "CVE-2020-3699" ], "details": "Possible out of bound access while processing assoc response from host due to improper length check before copying into buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, Nicobar, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCM2150, QCN7605, QCS405, QCS605, QM215, SA6155P, Saipan, SC8180X, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9rvq-6f2m-cpq4/GHSA-9rvq-6f2m-cpq4.json b/advisories/unreviewed/2022/05/GHSA-9rvq-6f2m-cpq4/GHSA-9rvq-6f2m-cpq4.json index 0bf8c605b69..77b5e965327 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rvq-6f2m-cpq4/GHSA-9rvq-6f2m-cpq4.json +++ b/advisories/unreviewed/2022/05/GHSA-9rvq-6f2m-cpq4/GHSA-9rvq-6f2m-cpq4.json @@ -7,12 +7,8 @@ "CVE-2020-6522" ], "details": "Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9v3j-42rv-3cwm/GHSA-9v3j-42rv-3cwm.json b/advisories/unreviewed/2022/05/GHSA-9v3j-42rv-3cwm/GHSA-9v3j-42rv-3cwm.json index 8fe12940fef..e24166dabc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v3j-42rv-3cwm/GHSA-9v3j-42rv-3cwm.json +++ b/advisories/unreviewed/2022/05/GHSA-9v3j-42rv-3cwm/GHSA-9v3j-42rv-3cwm.json @@ -7,12 +7,8 @@ "CVE-2020-4400" ], "details": "IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 179478.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9vmm-5mw9-grvh/GHSA-9vmm-5mw9-grvh.json b/advisories/unreviewed/2022/05/GHSA-9vmm-5mw9-grvh/GHSA-9vmm-5mw9-grvh.json index 2567b095e30..aecd1df2a81 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vmm-5mw9-grvh/GHSA-9vmm-5mw9-grvh.json +++ b/advisories/unreviewed/2022/05/GHSA-9vmm-5mw9-grvh/GHSA-9vmm-5mw9-grvh.json @@ -7,12 +7,8 @@ "CVE-2020-15713" ], "details": "rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.php script using the sortBy parameter, which could allow the attacker to view, add, modify, or delete information in the back-end database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9vr3-4v95-j9jw/GHSA-9vr3-4v95-j9jw.json b/advisories/unreviewed/2022/05/GHSA-9vr3-4v95-j9jw/GHSA-9vr3-4v95-j9jw.json index e8e9b47eae6..ce1026c795a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vr3-4v95-j9jw/GHSA-9vr3-4v95-j9jw.json +++ b/advisories/unreviewed/2022/05/GHSA-9vr3-4v95-j9jw/GHSA-9vr3-4v95-j9jw.json @@ -7,12 +7,8 @@ "CVE-2020-6531" ], "details": "Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9wp9-6795-j8rm/GHSA-9wp9-6795-j8rm.json b/advisories/unreviewed/2022/05/GHSA-9wp9-6795-j8rm/GHSA-9wp9-6795-j8rm.json index 51be08d94b2..a66a1bb7c61 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wp9-6795-j8rm/GHSA-9wp9-6795-j8rm.json +++ b/advisories/unreviewed/2022/05/GHSA-9wp9-6795-j8rm/GHSA-9wp9-6795-j8rm.json @@ -7,12 +7,8 @@ "CVE-2020-5761" ], "details": "Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in the TR-069 service. Unauthenticated remote attackers can trigger this case by sending a one character TCP message to the TR-069 service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9x6g-2x83-c3xj/GHSA-9x6g-2x83-c3xj.json b/advisories/unreviewed/2022/05/GHSA-9x6g-2x83-c3xj/GHSA-9x6g-2x83-c3xj.json index b81dac370d4..5526d4dbc5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x6g-2x83-c3xj/GHSA-9x6g-2x83-c3xj.json +++ b/advisories/unreviewed/2022/05/GHSA-9x6g-2x83-c3xj/GHSA-9x6g-2x83-c3xj.json @@ -7,12 +7,8 @@ "CVE-2019-14123" ], "details": "Possible buffer overflow and over read possible due to missing bounds checks for fixed limits if we consider widevine HLOS client as non-trustable in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, QCS404, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c48w-gpm6-r75x/GHSA-c48w-gpm6-r75x.json b/advisories/unreviewed/2022/05/GHSA-c48w-gpm6-r75x/GHSA-c48w-gpm6-r75x.json index af53e764907..8a1439d33ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-c48w-gpm6-r75x/GHSA-c48w-gpm6-r75x.json +++ b/advisories/unreviewed/2022/05/GHSA-c48w-gpm6-r75x/GHSA-c48w-gpm6-r75x.json @@ -7,12 +7,8 @@ "CVE-2020-15060" ], "details": "Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c4hq-jhc8-9v84/GHSA-c4hq-jhc8-9v84.json b/advisories/unreviewed/2022/05/GHSA-c4hq-jhc8-9v84/GHSA-c4hq-jhc8-9v84.json index ceb6b0b3b99..5e23f958f9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4hq-jhc8-9v84/GHSA-c4hq-jhc8-9v84.json +++ b/advisories/unreviewed/2022/05/GHSA-c4hq-jhc8-9v84/GHSA-c4hq-jhc8-9v84.json @@ -7,12 +7,8 @@ "CVE-2020-0240" ], "details": "In NewFixedDoubleArray of factory.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150706594", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c692-7w5j-72mx/GHSA-c692-7w5j-72mx.json b/advisories/unreviewed/2022/05/GHSA-c692-7w5j-72mx/GHSA-c692-7w5j-72mx.json index 5dbdfd42915..a711d0a893a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c692-7w5j-72mx/GHSA-c692-7w5j-72mx.json +++ b/advisories/unreviewed/2022/05/GHSA-c692-7w5j-72mx/GHSA-c692-7w5j-72mx.json @@ -7,12 +7,8 @@ "CVE-2020-5608" ], "details": "CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R8.03.01 allows a remote unauthenticated attacker to bypass authentication and send altered communication packets via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c6fc-w3j5-9p2g/GHSA-c6fc-w3j5-9p2g.json b/advisories/unreviewed/2022/05/GHSA-c6fc-w3j5-9p2g/GHSA-c6fc-w3j5-9p2g.json index cf61d17ffd5..25c8cb204c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6fc-w3j5-9p2g/GHSA-c6fc-w3j5-9p2g.json +++ b/advisories/unreviewed/2022/05/GHSA-c6fc-w3j5-9p2g/GHSA-c6fc-w3j5-9p2g.json @@ -7,12 +7,8 @@ "CVE-2020-4243" ], "details": "IBM Security Identity Governance and Intelligence 5.2.6 Virtual Appliance could allow a remote attacker to obtain sensitive information using man in the middle techniques due to not properly invalidating session tokens. IBM X-Force ID: 175420.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c7j7-c678-p6mm/GHSA-c7j7-c678-p6mm.json b/advisories/unreviewed/2022/05/GHSA-c7j7-c678-p6mm/GHSA-c7j7-c678-p6mm.json index 75a0c176860..dadf9dd1029 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7j7-c678-p6mm/GHSA-c7j7-c678-p6mm.json +++ b/advisories/unreviewed/2022/05/GHSA-c7j7-c678-p6mm/GHSA-c7j7-c678-p6mm.json @@ -7,12 +7,8 @@ "CVE-2020-15724" ], "details": "In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking to bypass the hips could execute arbitrary code on the Local system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cc3p-6vjw-w26p/GHSA-cc3p-6vjw-w26p.json b/advisories/unreviewed/2022/05/GHSA-cc3p-6vjw-w26p/GHSA-cc3p-6vjw-w26p.json index d0cc5cd4d6e..7aa2e2e0c9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc3p-6vjw-w26p/GHSA-cc3p-6vjw-w26p.json +++ b/advisories/unreviewed/2022/05/GHSA-cc3p-6vjw-w26p/GHSA-cc3p-6vjw-w26p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "WEB", diff --git a/advisories/unreviewed/2022/05/GHSA-ccch-f948-2h8c/GHSA-ccch-f948-2h8c.json b/advisories/unreviewed/2022/05/GHSA-ccch-f948-2h8c/GHSA-ccch-f948-2h8c.json index ec6b4134d3b..53fb9c426d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccch-f948-2h8c/GHSA-ccch-f948-2h8c.json +++ b/advisories/unreviewed/2022/05/GHSA-ccch-f948-2h8c/GHSA-ccch-f948-2h8c.json @@ -7,12 +7,8 @@ "CVE-2020-17448" ], "details": "Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use of the chat window with a filename that lacks an extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cf3m-2v8x-jmm5/GHSA-cf3m-2v8x-jmm5.json b/advisories/unreviewed/2022/05/GHSA-cf3m-2v8x-jmm5/GHSA-cf3m-2v8x-jmm5.json index d96be28e5b3..15c2b44da9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cf3m-2v8x-jmm5/GHSA-cf3m-2v8x-jmm5.json +++ b/advisories/unreviewed/2022/05/GHSA-cf3m-2v8x-jmm5/GHSA-cf3m-2v8x-jmm5.json @@ -7,12 +7,8 @@ "CVE-2020-3671" ], "details": "Use-after-free issue could occur due to dangling pointer when generating a frame buffer in OpenGL ES in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in APQ8009, Nicobar, QCM2150, QCS405, Saipan, SDM845, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cfmm-v9fq-4h4j/GHSA-cfmm-v9fq-4h4j.json b/advisories/unreviewed/2022/05/GHSA-cfmm-v9fq-4h4j/GHSA-cfmm-v9fq-4h4j.json index fea8eb71713..34b7c18839c 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfmm-v9fq-4h4j/GHSA-cfmm-v9fq-4h4j.json +++ b/advisories/unreviewed/2022/05/GHSA-cfmm-v9fq-4h4j/GHSA-cfmm-v9fq-4h4j.json @@ -7,12 +7,8 @@ "CVE-2020-5760" ], "details": "Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Unauthenticated remote attackers can execute arbitrary commands as root by crafting a special configuration file and sending a crafted SIP message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cgmv-g682-v286/GHSA-cgmv-g682-v286.json b/advisories/unreviewed/2022/05/GHSA-cgmv-g682-v286/GHSA-cgmv-g682-v286.json index e871363cae5..061d214d8d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgmv-g682-v286/GHSA-cgmv-g682-v286.json +++ b/advisories/unreviewed/2022/05/GHSA-cgmv-g682-v286/GHSA-cgmv-g682-v286.json @@ -7,12 +7,8 @@ "CVE-2020-16272" ], "details": "The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 is missing validation for a client-provided parameter, which allows remote attackers to read and modify data in the KeePass database via an A=0 WebSocket connection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-chqg-m3mf-jxhx/GHSA-chqg-m3mf-jxhx.json b/advisories/unreviewed/2022/05/GHSA-chqg-m3mf-jxhx/GHSA-chqg-m3mf-jxhx.json index 22b3cdb7901..a46c0701eb5 100644 --- a/advisories/unreviewed/2022/05/GHSA-chqg-m3mf-jxhx/GHSA-chqg-m3mf-jxhx.json +++ b/advisories/unreviewed/2022/05/GHSA-chqg-m3mf-jxhx/GHSA-chqg-m3mf-jxhx.json @@ -7,12 +7,8 @@ "CVE-2020-15821" ], "details": "In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-chrj-qx57-jxqj/GHSA-chrj-qx57-jxqj.json b/advisories/unreviewed/2022/05/GHSA-chrj-qx57-jxqj/GHSA-chrj-qx57-jxqj.json index e211250f7cb..61706c21cb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-chrj-qx57-jxqj/GHSA-chrj-qx57-jxqj.json +++ b/advisories/unreviewed/2022/05/GHSA-chrj-qx57-jxqj/GHSA-chrj-qx57-jxqj.json @@ -7,12 +7,8 @@ "CVE-2020-15479" ], "details": "An issue was discovered in PassMark BurnInTest through 9.1, OSForensics through 7.1, and PerformanceTest through 10. The driver's IOCTL request handler attempts to copy the input buffer onto the stack without checking its size and can cause a buffer overflow. This could lead to arbitrary Ring-0 code execution and escalation of privileges. This affects DirectIo32.sys and DirectIo64.sys.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cj3m-c468-w963/GHSA-cj3m-c468-w963.json b/advisories/unreviewed/2022/05/GHSA-cj3m-c468-w963/GHSA-cj3m-c468-w963.json index 0e5c4469363..79a364a1747 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj3m-c468-w963/GHSA-cj3m-c468-w963.json +++ b/advisories/unreviewed/2022/05/GHSA-cj3m-c468-w963/GHSA-cj3m-c468-w963.json @@ -7,12 +7,8 @@ "CVE-2020-0256" ], "details": "In LoadPartitionTable of gpt.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege when inserting a malicious USB device, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-8.0Android ID: A-152874864", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cjg8-2ch5-p3hm/GHSA-cjg8-2ch5-p3hm.json b/advisories/unreviewed/2022/05/GHSA-cjg8-2ch5-p3hm/GHSA-cjg8-2ch5-p3hm.json index 7e8c15c442c..b6537a0d3cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjg8-2ch5-p3hm/GHSA-cjg8-2ch5-p3hm.json +++ b/advisories/unreviewed/2022/05/GHSA-cjg8-2ch5-p3hm/GHSA-cjg8-2ch5-p3hm.json @@ -7,12 +7,8 @@ "CVE-2020-14489" ], "details": "OpenClinic GA 5.09.02 and 5.89.05b stores passwords using inadequate hashing complexity, which may allow an attacker to recover passwords using known password cracking techniques.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cjmx-h785-pr4r/GHSA-cjmx-h785-pr4r.json b/advisories/unreviewed/2022/05/GHSA-cjmx-h785-pr4r/GHSA-cjmx-h785-pr4r.json index 7cc8ab32241..721dbd471a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjmx-h785-pr4r/GHSA-cjmx-h785-pr4r.json +++ b/advisories/unreviewed/2022/05/GHSA-cjmx-h785-pr4r/GHSA-cjmx-h785-pr4r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cjwf-2r6c-6h5f/GHSA-cjwf-2r6c-6h5f.json b/advisories/unreviewed/2022/05/GHSA-cjwf-2r6c-6h5f/GHSA-cjwf-2r6c-6h5f.json index 34a3f9402a6..30939b74642 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjwf-2r6c-6h5f/GHSA-cjwf-2r6c-6h5f.json +++ b/advisories/unreviewed/2022/05/GHSA-cjwf-2r6c-6h5f/GHSA-cjwf-2r6c-6h5f.json @@ -7,12 +7,8 @@ "CVE-2020-8607" ], "details": "An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentially lead to code execution in kernel mode. An attacker must already have obtained administrator access on the target machine (either legitimately or via a separate unrelated attack) to exploit this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cm54-w897-v424/GHSA-cm54-w897-v424.json b/advisories/unreviewed/2022/05/GHSA-cm54-w897-v424/GHSA-cm54-w897-v424.json index bec70ea5769..bc3d9e98d37 100644 --- a/advisories/unreviewed/2022/05/GHSA-cm54-w897-v424/GHSA-cm54-w897-v424.json +++ b/advisories/unreviewed/2022/05/GHSA-cm54-w897-v424/GHSA-cm54-w897-v424.json @@ -7,12 +7,8 @@ "CVE-2020-17476" ], "details": "Mibew Messenger before 3.2.7 allows XSS via a crafted user name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cmx9-v2vm-9c6q/GHSA-cmx9-v2vm-9c6q.json b/advisories/unreviewed/2022/05/GHSA-cmx9-v2vm-9c6q/GHSA-cmx9-v2vm-9c6q.json index 954b8237dab..802355b3efd 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmx9-v2vm-9c6q/GHSA-cmx9-v2vm-9c6q.json +++ b/advisories/unreviewed/2022/05/GHSA-cmx9-v2vm-9c6q/GHSA-cmx9-v2vm-9c6q.json @@ -7,12 +7,8 @@ "CVE-2020-12301" ], "details": "Improper initialization in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a privileged user to potentially enable escalation of privilege via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cq6w-8339-ph8x/GHSA-cq6w-8339-ph8x.json b/advisories/unreviewed/2022/05/GHSA-cq6w-8339-ph8x/GHSA-cq6w-8339-ph8x.json index af03ea7231e..913ac537ee7 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq6w-8339-ph8x/GHSA-cq6w-8339-ph8x.json +++ b/advisories/unreviewed/2022/05/GHSA-cq6w-8339-ph8x/GHSA-cq6w-8339-ph8x.json @@ -7,12 +7,8 @@ "CVE-2020-16277" ], "details": "An SQL injection vulnerability in the Analytics component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, authenticated attacker to gain unauthorized access to the database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cqgh-444q-45w8/GHSA-cqgh-444q-45w8.json b/advisories/unreviewed/2022/05/GHSA-cqgh-444q-45w8/GHSA-cqgh-444q-45w8.json index 985e18a1f74..38da33e6aaa 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqgh-444q-45w8/GHSA-cqgh-444q-45w8.json +++ b/advisories/unreviewed/2022/05/GHSA-cqgh-444q-45w8/GHSA-cqgh-444q-45w8.json @@ -7,12 +7,8 @@ "CVE-2020-12774" ], "details": "D-Link DSL-7740C does not properly validate user input, which allows an authenticated LAN user to inject arbitrary command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cr4g-c9cq-96wj/GHSA-cr4g-c9cq-96wj.json b/advisories/unreviewed/2022/05/GHSA-cr4g-c9cq-96wj/GHSA-cr4g-c9cq-96wj.json index bd056509846..a3c7487cc87 100644 --- a/advisories/unreviewed/2022/05/GHSA-cr4g-c9cq-96wj/GHSA-cr4g-c9cq-96wj.json +++ b/advisories/unreviewed/2022/05/GHSA-cr4g-c9cq-96wj/GHSA-cr4g-c9cq-96wj.json @@ -7,12 +7,8 @@ "CVE-2020-10614" ], "details": "In OSIsoft PI System multiple products and versions, an authenticated remote attacker with write access to PI Vision databases could inject code into a display. Unauthorized information disclosure, deletion, or modification is possible if a victim views the infected display.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cv8v-qqh2-qx57/GHSA-cv8v-qqh2-qx57.json b/advisories/unreviewed/2022/05/GHSA-cv8v-qqh2-qx57/GHSA-cv8v-qqh2-qx57.json index 1a4989e3b65..4ccbc47e7f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv8v-qqh2-qx57/GHSA-cv8v-qqh2-qx57.json +++ b/advisories/unreviewed/2022/05/GHSA-cv8v-qqh2-qx57/GHSA-cv8v-qqh2-qx57.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cvp7-c3qw-m5fw/GHSA-cvp7-c3qw-m5fw.json b/advisories/unreviewed/2022/05/GHSA-cvp7-c3qw-m5fw/GHSA-cvp7-c3qw-m5fw.json index e2189916e33..03b4f50126f 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvp7-c3qw-m5fw/GHSA-cvp7-c3qw-m5fw.json +++ b/advisories/unreviewed/2022/05/GHSA-cvp7-c3qw-m5fw/GHSA-cvp7-c3qw-m5fw.json @@ -7,12 +7,8 @@ "CVE-2020-3377" ], "details": "A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the affected device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted arguments to a specific field within the application. A successful exploit could allow the attacker to run commands as the administrator on the DCNM.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cvw9-82mp-3chf/GHSA-cvw9-82mp-3chf.json b/advisories/unreviewed/2022/05/GHSA-cvw9-82mp-3chf/GHSA-cvw9-82mp-3chf.json index 85723a2401e..d1c73785c48 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvw9-82mp-3chf/GHSA-cvw9-82mp-3chf.json +++ b/advisories/unreviewed/2022/05/GHSA-cvw9-82mp-3chf/GHSA-cvw9-82mp-3chf.json @@ -7,12 +7,8 @@ "CVE-2020-4644" ], "details": "IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 185716.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cwv4-27xg-6829/GHSA-cwv4-27xg-6829.json b/advisories/unreviewed/2022/05/GHSA-cwv4-27xg-6829/GHSA-cwv4-27xg-6829.json index 01b0ff7ea66..ab9e4f04f27 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwv4-27xg-6829/GHSA-cwv4-27xg-6829.json +++ b/advisories/unreviewed/2022/05/GHSA-cwv4-27xg-6829/GHSA-cwv4-27xg-6829.json @@ -7,12 +7,8 @@ "CVE-2020-13364" ], "details": "A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0, and V5.21(ABAG.3)C0; NSA325 v2_V4.81(AALS.0)C0 and V4.81(AAAJ.1)C0; NSA310 4.22(AFK.0)C0 and 4.22(AFK.1)C0; NAS326 V5.21(AAZF.8)C0, V5.11(AAZF.4)C0, V5.11(AAZF.2)C0, and V5.11(AAZF.3)C0; NSA310S V4.75(AALH.2)C0; NSA320S V4.75(AANV.2)C0 and V4.75(AANV.1)C0; NSA221 V4.41(AFM.1)C0; and NAS540 V5.21(AATB.5)C0 and V5.21(AATB.3)C0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cx37-rm6g-whq9/GHSA-cx37-rm6g-whq9.json b/advisories/unreviewed/2022/05/GHSA-cx37-rm6g-whq9/GHSA-cx37-rm6g-whq9.json index f722ec8b087..e07fdf891b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx37-rm6g-whq9/GHSA-cx37-rm6g-whq9.json +++ b/advisories/unreviewed/2022/05/GHSA-cx37-rm6g-whq9/GHSA-cx37-rm6g-whq9.json @@ -7,12 +7,8 @@ "CVE-2020-16276" ], "details": "An SQL injection vulnerability in the Assets component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, authenticated attacker to gain unauthorized access to the database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f2jh-cwgj-5mqc/GHSA-f2jh-cwgj-5mqc.json b/advisories/unreviewed/2022/05/GHSA-f2jh-cwgj-5mqc/GHSA-f2jh-cwgj-5mqc.json index c97cce081b1..0830c0cbd03 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2jh-cwgj-5mqc/GHSA-f2jh-cwgj-5mqc.json +++ b/advisories/unreviewed/2022/05/GHSA-f2jh-cwgj-5mqc/GHSA-f2jh-cwgj-5mqc.json @@ -7,12 +7,8 @@ "CVE-2020-15632" ], "details": "This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-842 3.13B05 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of HNAP GetCAPTCHAsetting requests. The issue results from the lack of proper handling of sessions. An attacker can leverage this vulnerability to execute arbitrary code in the context of the device. Was ZDI-CAN-10083.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f2jx-wr3j-25w5/GHSA-f2jx-wr3j-25w5.json b/advisories/unreviewed/2022/05/GHSA-f2jx-wr3j-25w5/GHSA-f2jx-wr3j-25w5.json index eb3d1f5ec41..1ac21238d17 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2jx-wr3j-25w5/GHSA-f2jx-wr3j-25w5.json +++ b/advisories/unreviewed/2022/05/GHSA-f2jx-wr3j-25w5/GHSA-f2jx-wr3j-25w5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f2vf-492v-9x6w/GHSA-f2vf-492v-9x6w.json b/advisories/unreviewed/2022/05/GHSA-f2vf-492v-9x6w/GHSA-f2vf-492v-9x6w.json index 12373cc62f2..64cc8341b3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2vf-492v-9x6w/GHSA-f2vf-492v-9x6w.json +++ b/advisories/unreviewed/2022/05/GHSA-f2vf-492v-9x6w/GHSA-f2vf-492v-9x6w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f329-rp43-94r4/GHSA-f329-rp43-94r4.json b/advisories/unreviewed/2022/05/GHSA-f329-rp43-94r4/GHSA-f329-rp43-94r4.json index b5516124f6a..e8dc32daae4 100644 --- a/advisories/unreviewed/2022/05/GHSA-f329-rp43-94r4/GHSA-f329-rp43-94r4.json +++ b/advisories/unreviewed/2022/05/GHSA-f329-rp43-94r4/GHSA-f329-rp43-94r4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f37m-f94x-28cq/GHSA-f37m-f94x-28cq.json b/advisories/unreviewed/2022/05/GHSA-f37m-f94x-28cq/GHSA-f37m-f94x-28cq.json index 2157b677f71..badc761200b 100644 --- a/advisories/unreviewed/2022/05/GHSA-f37m-f94x-28cq/GHSA-f37m-f94x-28cq.json +++ b/advisories/unreviewed/2022/05/GHSA-f37m-f94x-28cq/GHSA-f37m-f94x-28cq.json @@ -7,12 +7,8 @@ "CVE-2020-10929" ], "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of string table file uploads. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-9768.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f3q5-x55r-fcfp/GHSA-f3q5-x55r-fcfp.json b/advisories/unreviewed/2022/05/GHSA-f3q5-x55r-fcfp/GHSA-f3q5-x55r-fcfp.json index b40078a6724..84def2b1c94 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3q5-x55r-fcfp/GHSA-f3q5-x55r-fcfp.json +++ b/advisories/unreviewed/2022/05/GHSA-f3q5-x55r-fcfp/GHSA-f3q5-x55r-fcfp.json @@ -7,12 +7,8 @@ "CVE-2020-0241" ], "details": "In NuPlayerStreamListener of NuPlayerStreamListener.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-151456667", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f43w-mfrf-mv66/GHSA-f43w-mfrf-mv66.json b/advisories/unreviewed/2022/05/GHSA-f43w-mfrf-mv66/GHSA-f43w-mfrf-mv66.json index 4cc3f521015..98651fc19d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-f43w-mfrf-mv66/GHSA-f43w-mfrf-mv66.json +++ b/advisories/unreviewed/2022/05/GHSA-f43w-mfrf-mv66/GHSA-f43w-mfrf-mv66.json @@ -7,12 +7,8 @@ "CVE-2020-13699" ], "details": "TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10: --play URL. An attacker could force a victim to send an NTLM authentication request and either relay the request or capture the hash for offline password cracking. This affects teamviewer10, teamviewer8, teamviewerapi, tvchat1, tvcontrol1, tvfiletransfer1, tvjoinv8, tvpresent1, tvsendfile1, tvsqcustomer1, tvsqsupport1, tvvideocall1, and tvvpn1. The issue is fixed in 8.0.258861, 9.0.258860, 10.0.258873, 11.0.258870, 12.0.258869, 13.2.36220, 14.2.56676, 14.7.48350, and 15.8.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4g3-g5f8-wrw6/GHSA-f4g3-g5f8-wrw6.json b/advisories/unreviewed/2022/05/GHSA-f4g3-g5f8-wrw6/GHSA-f4g3-g5f8-wrw6.json index 1f5a70a148a..3e4fd22e818 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4g3-g5f8-wrw6/GHSA-f4g3-g5f8-wrw6.json +++ b/advisories/unreviewed/2022/05/GHSA-f4g3-g5f8-wrw6/GHSA-f4g3-g5f8-wrw6.json @@ -7,12 +7,8 @@ "CVE-2020-16131" ], "details": "Tiki before 21.2 allows XSS because [\\s\\/\"\\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f4m7-j2g3-gvpf/GHSA-f4m7-j2g3-gvpf.json b/advisories/unreviewed/2022/05/GHSA-f4m7-j2g3-gvpf/GHSA-f4m7-j2g3-gvpf.json index ff7db0fd307..7924e37335e 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4m7-j2g3-gvpf/GHSA-f4m7-j2g3-gvpf.json +++ b/advisories/unreviewed/2022/05/GHSA-f4m7-j2g3-gvpf/GHSA-f4m7-j2g3-gvpf.json @@ -7,12 +7,8 @@ "CVE-2020-15714" ], "details": "rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.crud.php script using the custom_Location parameter, which could allow the attacker to view, add, modify, or delete information in the back-end database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f534-3845-rvj6/GHSA-f534-3845-rvj6.json b/advisories/unreviewed/2022/05/GHSA-f534-3845-rvj6/GHSA-f534-3845-rvj6.json index 9859c08eb86..bffd18fee4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f534-3845-rvj6/GHSA-f534-3845-rvj6.json +++ b/advisories/unreviewed/2022/05/GHSA-f534-3845-rvj6/GHSA-f534-3845-rvj6.json @@ -7,12 +7,8 @@ "CVE-2020-15597" ], "details": "SOPlanning 1.46.01 allows persistent XSS via the Project Name, Statutes Comment, Places Comment, or Resources Comment field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f5qr-fc99-3gg6/GHSA-f5qr-fc99-3gg6.json b/advisories/unreviewed/2022/05/GHSA-f5qr-fc99-3gg6/GHSA-f5qr-fc99-3gg6.json index d9667ed3637..80857b64dad 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5qr-fc99-3gg6/GHSA-f5qr-fc99-3gg6.json +++ b/advisories/unreviewed/2022/05/GHSA-f5qr-fc99-3gg6/GHSA-f5qr-fc99-3gg6.json @@ -7,12 +7,8 @@ "CVE-2020-12299" ], "details": "Improper input validation in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a privileged user to potentially enable escalation of privilege via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f692-3mc6-m68j/GHSA-f692-3mc6-m68j.json b/advisories/unreviewed/2022/05/GHSA-f692-3mc6-m68j/GHSA-f692-3mc6-m68j.json index c9b9f8a4b27..f2080626f20 100644 --- a/advisories/unreviewed/2022/05/GHSA-f692-3mc6-m68j/GHSA-f692-3mc6-m68j.json +++ b/advisories/unreviewed/2022/05/GHSA-f692-3mc6-m68j/GHSA-f692-3mc6-m68j.json @@ -7,12 +7,8 @@ "CVE-2019-14130" ], "details": "Memory corruption can occurs in trusted application if offset size from HLOS is more than actual mapped buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, QCS404, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6wr-qrpc-cgq3/GHSA-f6wr-qrpc-cgq3.json b/advisories/unreviewed/2022/05/GHSA-f6wr-qrpc-cgq3/GHSA-f6wr-qrpc-cgq3.json index 3770ad1beb4..91d8f9fc504 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6wr-qrpc-cgq3/GHSA-f6wr-qrpc-cgq3.json +++ b/advisories/unreviewed/2022/05/GHSA-f6wr-qrpc-cgq3/GHSA-f6wr-qrpc-cgq3.json @@ -7,12 +7,8 @@ "CVE-2020-5773" ], "details": "Improper Access Control in Teltonika firmware TRB2_R_00.02.04.01 allows a low privileged user to perform unauthorized write operations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f84c-pj2g-x4f3/GHSA-f84c-pj2g-x4f3.json b/advisories/unreviewed/2022/05/GHSA-f84c-pj2g-x4f3/GHSA-f84c-pj2g-x4f3.json index 33fe686fb44..218285e420d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f84c-pj2g-x4f3/GHSA-f84c-pj2g-x4f3.json +++ b/advisories/unreviewed/2022/05/GHSA-f84c-pj2g-x4f3/GHSA-f84c-pj2g-x4f3.json @@ -7,12 +7,8 @@ "CVE-2020-16169" ], "details": "Temi Robox OS 117.21 through 119.24 allows Authentication Bypass via an Alternate Path or Channel.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f984-9xfw-9437/GHSA-f984-9xfw-9437.json b/advisories/unreviewed/2022/05/GHSA-f984-9xfw-9437/GHSA-f984-9xfw-9437.json index f9bedb11f59..8c1ca79efff 100644 --- a/advisories/unreviewed/2022/05/GHSA-f984-9xfw-9437/GHSA-f984-9xfw-9437.json +++ b/advisories/unreviewed/2022/05/GHSA-f984-9xfw-9437/GHSA-f984-9xfw-9437.json @@ -7,12 +7,8 @@ "CVE-2020-15661" ], "details": "A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain. This vulnerability affects Firefox for iOS < 28.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f98h-fhjw-57pm/GHSA-f98h-fhjw-57pm.json b/advisories/unreviewed/2022/05/GHSA-f98h-fhjw-57pm/GHSA-f98h-fhjw-57pm.json index 13f7eeb7d89..b99f3fd270d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f98h-fhjw-57pm/GHSA-f98h-fhjw-57pm.json +++ b/advisories/unreviewed/2022/05/GHSA-f98h-fhjw-57pm/GHSA-f98h-fhjw-57pm.json @@ -7,12 +7,8 @@ "CVE-2020-14483" ], "details": "A timeout during a TLS handshake can result in the connection failing to terminate. This can result in a Niagara thread hanging and requires a manual restart of Niagara (Versions 4.6.96.28, 4.7.109.20, 4.7.110.32, 4.8.0.110) and Niagara Enterprise Security (Versions 2.4.31, 2.4.45, 4.8.0.35) to correct.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f9hx-r2xv-24c7/GHSA-f9hx-r2xv-24c7.json b/advisories/unreviewed/2022/05/GHSA-f9hx-r2xv-24c7/GHSA-f9hx-r2xv-24c7.json index 4384d78eca6..927c489b3b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9hx-r2xv-24c7/GHSA-f9hx-r2xv-24c7.json +++ b/advisories/unreviewed/2022/05/GHSA-f9hx-r2xv-24c7/GHSA-f9hx-r2xv-24c7.json @@ -7,12 +7,8 @@ "CVE-2020-14493" ], "details": "A low-privilege user may use SQL syntax to write arbitrary files to the OpenClinic GA 5.09.02 and 5.89.05b server, which may allow the execution of arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fc36-5hq8-56hm/GHSA-fc36-5hq8-56hm.json b/advisories/unreviewed/2022/05/GHSA-fc36-5hq8-56hm/GHSA-fc36-5hq8-56hm.json index 67e79c2190b..68b7277690b 100644 --- a/advisories/unreviewed/2022/05/GHSA-fc36-5hq8-56hm/GHSA-fc36-5hq8-56hm.json +++ b/advisories/unreviewed/2022/05/GHSA-fc36-5hq8-56hm/GHSA-fc36-5hq8-56hm.json @@ -7,12 +7,8 @@ "CVE-2020-1425" ], "details": "A remoted code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1457.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fc79-vjq3-f6j4/GHSA-fc79-vjq3-f6j4.json b/advisories/unreviewed/2022/05/GHSA-fc79-vjq3-f6j4/GHSA-fc79-vjq3-f6j4.json index ae849b7655f..60b7ee6e8b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-fc79-vjq3-f6j4/GHSA-fc79-vjq3-f6j4.json +++ b/advisories/unreviewed/2022/05/GHSA-fc79-vjq3-f6j4/GHSA-fc79-vjq3-f6j4.json @@ -7,12 +7,8 @@ "CVE-2020-15956" ], "details": "ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer overflow and application termination via a malformed payload.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fcc6-r285-r3cg/GHSA-fcc6-r285-r3cg.json b/advisories/unreviewed/2022/05/GHSA-fcc6-r285-r3cg/GHSA-fcc6-r285-r3cg.json index fe020b6f7ce..226fc47b2ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcc6-r285-r3cg/GHSA-fcc6-r285-r3cg.json +++ b/advisories/unreviewed/2022/05/GHSA-fcc6-r285-r3cg/GHSA-fcc6-r285-r3cg.json @@ -7,12 +7,8 @@ "CVE-2020-4567" ], "details": "IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 184156.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcfw-r6pj-x447/GHSA-fcfw-r6pj-x447.json b/advisories/unreviewed/2022/05/GHSA-fcfw-r6pj-x447/GHSA-fcfw-r6pj-x447.json index 14b5c5416aa..00cae1694e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcfw-r6pj-x447/GHSA-fcfw-r6pj-x447.json +++ b/advisories/unreviewed/2022/05/GHSA-fcfw-r6pj-x447/GHSA-fcfw-r6pj-x447.json @@ -7,12 +7,8 @@ "CVE-2020-11937" ], "details": "In whoopsie, parse_report() from whoopsie.c allows a local attacker to cause a denial of service via a crafted file. The DoS is caused by resource exhaustion due to a memory leak. Fixed in 0.2.52.5ubuntu0.5, 0.2.62ubuntu0.5 and 0.2.69ubuntu0.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcjh-xxf4-45hh/GHSA-fcjh-xxf4-45hh.json b/advisories/unreviewed/2022/05/GHSA-fcjh-xxf4-45hh/GHSA-fcjh-xxf4-45hh.json index d41cc4bc302..8609f792b85 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcjh-xxf4-45hh/GHSA-fcjh-xxf4-45hh.json +++ b/advisories/unreviewed/2022/05/GHSA-fcjh-xxf4-45hh/GHSA-fcjh-xxf4-45hh.json @@ -7,12 +7,8 @@ "CVE-2020-4481" ], "details": "IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181848.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcmg-prff-jxrr/GHSA-fcmg-prff-jxrr.json b/advisories/unreviewed/2022/05/GHSA-fcmg-prff-jxrr/GHSA-fcmg-prff-jxrr.json index 7fc0497c45f..d6590a03176 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcmg-prff-jxrr/GHSA-fcmg-prff-jxrr.json +++ b/advisories/unreviewed/2022/05/GHSA-fcmg-prff-jxrr/GHSA-fcmg-prff-jxrr.json @@ -7,12 +7,8 @@ "CVE-2020-11440" ], "details": "httpRpmFs in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 has no check for an escape from the web root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcrq-wmf7-mhqw/GHSA-fcrq-wmf7-mhqw.json b/advisories/unreviewed/2022/05/GHSA-fcrq-wmf7-mhqw/GHSA-fcrq-wmf7-mhqw.json index b4d5184f8c2..b9e06d87229 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcrq-wmf7-mhqw/GHSA-fcrq-wmf7-mhqw.json +++ b/advisories/unreviewed/2022/05/GHSA-fcrq-wmf7-mhqw/GHSA-fcrq-wmf7-mhqw.json @@ -7,12 +7,8 @@ "CVE-2019-14037" ], "details": "Close and bind operations done on a socket can lead to a Use-After-Free condition. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8996, MSM8996AU, QCN7605, QCN7606, QCS605, SC8180X, SDA660, SDA845, SDM439, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SDX24, SDX55, SM8150, SXR1130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fgqc-x34q-558f/GHSA-fgqc-x34q-558f.json b/advisories/unreviewed/2022/05/GHSA-fgqc-x34q-558f/GHSA-fgqc-x34q-558f.json index 7e2cc517dae..009ee4d9ac0 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgqc-x34q-558f/GHSA-fgqc-x34q-558f.json +++ b/advisories/unreviewed/2022/05/GHSA-fgqc-x34q-558f/GHSA-fgqc-x34q-558f.json @@ -7,12 +7,8 @@ "CVE-2020-13913" ], "details": "An XSS issue in emfd in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute JavaScript code via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and T710s devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fjx8-7rjg-vfv7/GHSA-fjx8-7rjg-vfv7.json b/advisories/unreviewed/2022/05/GHSA-fjx8-7rjg-vfv7/GHSA-fjx8-7rjg-vfv7.json index 2001a6fb1ad..e9ad24c5f4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjx8-7rjg-vfv7/GHSA-fjx8-7rjg-vfv7.json +++ b/advisories/unreviewed/2022/05/GHSA-fjx8-7rjg-vfv7/GHSA-fjx8-7rjg-vfv7.json @@ -7,12 +7,8 @@ "CVE-2020-15063" ], "details": "DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fm45-3257-fjcr/GHSA-fm45-3257-fjcr.json b/advisories/unreviewed/2022/05/GHSA-fm45-3257-fjcr/GHSA-fm45-3257-fjcr.json index f9140d5968c..266ca5edc0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm45-3257-fjcr/GHSA-fm45-3257-fjcr.json +++ b/advisories/unreviewed/2022/05/GHSA-fm45-3257-fjcr/GHSA-fm45-3257-fjcr.json @@ -7,12 +7,8 @@ "CVE-2020-7817" ], "details": "MyBrowserPlus downloads the files needed to run the program through the setup file (Setup.inf). At this time, there is a vulnerability in downloading arbitrary files due to insufficient integrity verification of the files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fp2p-fx97-wr62/GHSA-fp2p-fx97-wr62.json b/advisories/unreviewed/2022/05/GHSA-fp2p-fx97-wr62/GHSA-fp2p-fx97-wr62.json index 1e04ab294b9..1cbe753e225 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp2p-fx97-wr62/GHSA-fp2p-fx97-wr62.json +++ b/advisories/unreviewed/2022/05/GHSA-fp2p-fx97-wr62/GHSA-fp2p-fx97-wr62.json @@ -7,12 +7,8 @@ "CVE-2020-15806" ], "details": "CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpgh-jxj5-435h/GHSA-fpgh-jxj5-435h.json b/advisories/unreviewed/2022/05/GHSA-fpgh-jxj5-435h/GHSA-fpgh-jxj5-435h.json index 5647216dc40..8684a9bf5a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpgh-jxj5-435h/GHSA-fpgh-jxj5-435h.json +++ b/advisories/unreviewed/2022/05/GHSA-fpgh-jxj5-435h/GHSA-fpgh-jxj5-435h.json @@ -7,12 +7,8 @@ "CVE-2020-16271" ], "details": "The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 generates insufficiently random numbers, which allows remote attackers to read and modify data in the KeePass database via a WebSocket connection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fq6m-28xv-2hw5/GHSA-fq6m-28xv-2hw5.json b/advisories/unreviewed/2022/05/GHSA-fq6m-28xv-2hw5/GHSA-fq6m-28xv-2hw5.json index 1ab22282f7c..297fd839a52 100644 --- a/advisories/unreviewed/2022/05/GHSA-fq6m-28xv-2hw5/GHSA-fq6m-28xv-2hw5.json +++ b/advisories/unreviewed/2022/05/GHSA-fq6m-28xv-2hw5/GHSA-fq6m-28xv-2hw5.json @@ -7,12 +7,8 @@ "CVE-2020-9036" ], "details": "Jeedom through 4.0.38 allows XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fq9h-r4hc-877j/GHSA-fq9h-r4hc-877j.json b/advisories/unreviewed/2022/05/GHSA-fq9h-r4hc-877j/GHSA-fq9h-r4hc-877j.json index 5bcec6fc21e..18eff75922b 100644 --- a/advisories/unreviewed/2022/05/GHSA-fq9h-r4hc-877j/GHSA-fq9h-r4hc-877j.json +++ b/advisories/unreviewed/2022/05/GHSA-fq9h-r4hc-877j/GHSA-fq9h-r4hc-877j.json @@ -7,12 +7,8 @@ "CVE-2020-15061" ], "details": "Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to denial-of-service the device via long input values.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fr2f-9qmm-c7w2/GHSA-fr2f-9qmm-c7w2.json b/advisories/unreviewed/2022/05/GHSA-fr2f-9qmm-c7w2/GHSA-fr2f-9qmm-c7w2.json index 00f5f4d9ec3..4d3b22a0efc 100644 --- a/advisories/unreviewed/2022/05/GHSA-fr2f-9qmm-c7w2/GHSA-fr2f-9qmm-c7w2.json +++ b/advisories/unreviewed/2022/05/GHSA-fr2f-9qmm-c7w2/GHSA-fr2f-9qmm-c7w2.json @@ -7,12 +7,8 @@ "CVE-2020-7515" ], "details": "A CWE-321: Use of hard-coded cryptographic key stored in cleartext vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to decrypt a password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fvcr-v4xc-77jv/GHSA-fvcr-v4xc-77jv.json b/advisories/unreviewed/2022/05/GHSA-fvcr-v4xc-77jv/GHSA-fvcr-v4xc-77jv.json index 9631975a2c3..20ae71fbbec 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvcr-v4xc-77jv/GHSA-fvcr-v4xc-77jv.json +++ b/advisories/unreviewed/2022/05/GHSA-fvcr-v4xc-77jv/GHSA-fvcr-v4xc-77jv.json @@ -7,12 +7,8 @@ "CVE-2020-13917" ], "details": "rkscli in Ruckus Wireless Unleashed through 200.7.10.92 allows a remote attacker to achieve command injection and jailbreak the CLI via a crafted CLI command. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and T710s devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fw6x-5hx8-99vr/GHSA-fw6x-5hx8-99vr.json b/advisories/unreviewed/2022/05/GHSA-fw6x-5hx8-99vr/GHSA-fw6x-5hx8-99vr.json index d79689f590d..06ecbc4408b 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw6x-5hx8-99vr/GHSA-fw6x-5hx8-99vr.json +++ b/advisories/unreviewed/2022/05/GHSA-fw6x-5hx8-99vr/GHSA-fw6x-5hx8-99vr.json @@ -7,12 +7,8 @@ "CVE-2020-4185" ], "details": "IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174803.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fxg8-w3hh-r94m/GHSA-fxg8-w3hh-r94m.json b/advisories/unreviewed/2022/05/GHSA-fxg8-w3hh-r94m/GHSA-fxg8-w3hh-r94m.json index 71650b67316..69171e2337f 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxg8-w3hh-r94m/GHSA-fxg8-w3hh-r94m.json +++ b/advisories/unreviewed/2022/05/GHSA-fxg8-w3hh-r94m/GHSA-fxg8-w3hh-r94m.json @@ -7,12 +7,8 @@ "CVE-2020-13177" ], "details": "The support bundler in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows versions prior to 20.04.1 and 20.07.0 does not use hard coded paths for certain Windows binaries, which allows an attacker to gain elevated privileges via execution of a malicious binary placed in the system path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fxvf-vgj9-gphr/GHSA-fxvf-vgj9-gphr.json b/advisories/unreviewed/2022/05/GHSA-fxvf-vgj9-gphr/GHSA-fxvf-vgj9-gphr.json index 543d0e9e485..4790d429fc8 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxvf-vgj9-gphr/GHSA-fxvf-vgj9-gphr.json +++ b/advisories/unreviewed/2022/05/GHSA-fxvf-vgj9-gphr/GHSA-fxvf-vgj9-gphr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g2pj-29c7-96vw/GHSA-g2pj-29c7-96vw.json b/advisories/unreviewed/2022/05/GHSA-g2pj-29c7-96vw/GHSA-g2pj-29c7-96vw.json index 2987f70d741..014a328797b 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2pj-29c7-96vw/GHSA-g2pj-29c7-96vw.json +++ b/advisories/unreviewed/2022/05/GHSA-g2pj-29c7-96vw/GHSA-g2pj-29c7-96vw.json @@ -7,12 +7,8 @@ "CVE-2020-10983" ], "details": "Gambio GX before 4.0.1.0 allows SQL Injection in admin/mobile.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g3fq-76v3-jcj7/GHSA-g3fq-76v3-jcj7.json b/advisories/unreviewed/2022/05/GHSA-g3fq-76v3-jcj7/GHSA-g3fq-76v3-jcj7.json index d18c31760cf..3cbb226212c 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3fq-76v3-jcj7/GHSA-g3fq-76v3-jcj7.json +++ b/advisories/unreviewed/2022/05/GHSA-g3fq-76v3-jcj7/GHSA-g3fq-76v3-jcj7.json @@ -7,12 +7,8 @@ "CVE-2020-0253" ], "details": "There is a possible memory corruption due to a use after free.Product: AndroidVersions: Android SoCAndroid ID: A-152647365", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g3w5-xmfj-m528/GHSA-g3w5-xmfj-m528.json b/advisories/unreviewed/2022/05/GHSA-g3w5-xmfj-m528/GHSA-g3w5-xmfj-m528.json index e0632b4d7fb..cbbe9627e19 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3w5-xmfj-m528/GHSA-g3w5-xmfj-m528.json +++ b/advisories/unreviewed/2022/05/GHSA-g3w5-xmfj-m528/GHSA-g3w5-xmfj-m528.json @@ -7,12 +7,8 @@ "CVE-2020-13820" ], "details": "Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g422-jr4c-64px/GHSA-g422-jr4c-64px.json b/advisories/unreviewed/2022/05/GHSA-g422-jr4c-64px/GHSA-g422-jr4c-64px.json index 94971917670..355674c2a2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-g422-jr4c-64px/GHSA-g422-jr4c-64px.json +++ b/advisories/unreviewed/2022/05/GHSA-g422-jr4c-64px/GHSA-g422-jr4c-64px.json @@ -7,12 +7,8 @@ "CVE-2020-9683" ], "details": "Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g55h-q572-52j6/GHSA-g55h-q572-52j6.json b/advisories/unreviewed/2022/05/GHSA-g55h-q572-52j6/GHSA-g55h-q572-52j6.json index 833be5035d6..a29f78c0307 100644 --- a/advisories/unreviewed/2022/05/GHSA-g55h-q572-52j6/GHSA-g55h-q572-52j6.json +++ b/advisories/unreviewed/2022/05/GHSA-g55h-q572-52j6/GHSA-g55h-q572-52j6.json @@ -7,12 +7,8 @@ "CVE-2020-8025" ], "details": "A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Tumbleweed sets the permissions for some of the directories of the pcp package to unintended settings. This issue affects: SUSE Linux Enterprise Server 12-SP4 permissions versions prior to 20170707-3.24.1. SUSE Linux Enterprise Server 15-LTSS permissions versions prior to 20180125-3.27.1. SUSE Linux Enterprise Server for SAP 15 permissions versions prior to 20180125-3.27.1. openSUSE Leap 15.1 permissions versions prior to 20181116-lp151.4.24.1. openSUSE Tumbleweed permissions versions prior to 20200624.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g78v-7xhx-6j98/GHSA-g78v-7xhx-6j98.json b/advisories/unreviewed/2022/05/GHSA-g78v-7xhx-6j98/GHSA-g78v-7xhx-6j98.json index 9ecbb7c1486..5b34fbf61bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-g78v-7xhx-6j98/GHSA-g78v-7xhx-6j98.json +++ b/advisories/unreviewed/2022/05/GHSA-g78v-7xhx-6j98/GHSA-g78v-7xhx-6j98.json @@ -7,12 +7,8 @@ "CVE-2020-10921" ], "details": "This vulnerability allows remote attackers to issue commands on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the EA-HTTP.exe process. The issue results from the lack of authentication prior to allowing alterations to the system configuration. An attacker can leverage this vulnerability to issue commands to the physical equipment controlled by the device. Was ZDI-CAN-10482.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g7qp-996v-xxqp/GHSA-g7qp-996v-xxqp.json b/advisories/unreviewed/2022/05/GHSA-g7qp-996v-xxqp/GHSA-g7qp-996v-xxqp.json index f6be8beea2a..be9d2f505d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7qp-996v-xxqp/GHSA-g7qp-996v-xxqp.json +++ b/advisories/unreviewed/2022/05/GHSA-g7qp-996v-xxqp/GHSA-g7qp-996v-xxqp.json @@ -7,12 +7,8 @@ "CVE-2020-16201" ], "details": "Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple out-of-bounds read vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gf7v-83rf-3674/GHSA-gf7v-83rf-3674.json b/advisories/unreviewed/2022/05/GHSA-gf7v-83rf-3674/GHSA-gf7v-83rf-3674.json index 14b4f8f9464..29d553ac728 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf7v-83rf-3674/GHSA-gf7v-83rf-3674.json +++ b/advisories/unreviewed/2022/05/GHSA-gf7v-83rf-3674/GHSA-gf7v-83rf-3674.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ggph-m8pj-5jhv/GHSA-ggph-m8pj-5jhv.json b/advisories/unreviewed/2022/05/GHSA-ggph-m8pj-5jhv/GHSA-ggph-m8pj-5jhv.json index be7911f1c51..e340a3e995b 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggph-m8pj-5jhv/GHSA-ggph-m8pj-5jhv.json +++ b/advisories/unreviewed/2022/05/GHSA-ggph-m8pj-5jhv/GHSA-ggph-m8pj-5jhv.json @@ -7,12 +7,8 @@ "CVE-2020-6513" ], "details": "Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ggvm-cfcf-j5g6/GHSA-ggvm-cfcf-j5g6.json b/advisories/unreviewed/2022/05/GHSA-ggvm-cfcf-j5g6/GHSA-ggvm-cfcf-j5g6.json index bc3e1d17155..e861c864c80 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggvm-cfcf-j5g6/GHSA-ggvm-cfcf-j5g6.json +++ b/advisories/unreviewed/2022/05/GHSA-ggvm-cfcf-j5g6/GHSA-ggvm-cfcf-j5g6.json @@ -7,12 +7,8 @@ "CVE-2020-5611" ], "details": "Cross-site request forgery (CSRF) vulnerability in Social Sharing Plugin versions prior to 1.2.10 allows remote attackers to hijack the authentication of administrators via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gjfj-j9px-jqww/GHSA-gjfj-j9px-jqww.json b/advisories/unreviewed/2022/05/GHSA-gjfj-j9px-jqww/GHSA-gjfj-j9px-jqww.json index 436604c1aa0..b58b70c90a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjfj-j9px-jqww/GHSA-gjfj-j9px-jqww.json +++ b/advisories/unreviewed/2022/05/GHSA-gjfj-j9px-jqww/GHSA-gjfj-j9px-jqww.json @@ -7,12 +7,8 @@ "CVE-2020-8574" ], "details": "Active IQ Unified Manager for Linux versions prior to 9.6 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service enabled allowing unauthorized code execution to local users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gqxx-7rgw-867q/GHSA-gqxx-7rgw-867q.json b/advisories/unreviewed/2022/05/GHSA-gqxx-7rgw-867q/GHSA-gqxx-7rgw-867q.json index 43d980401b9..5f8ab5c2488 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqxx-7rgw-867q/GHSA-gqxx-7rgw-867q.json +++ b/advisories/unreviewed/2022/05/GHSA-gqxx-7rgw-867q/GHSA-gqxx-7rgw-867q.json @@ -7,12 +7,8 @@ "CVE-2020-5762" ], "details": "Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticated remote attacker can stop the service due to a NULL pointer dereference in the TR-069 service. This condition is triggered due to mishandling of the HTTP Authentication field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gvc5-74jp-jqc2/GHSA-gvc5-74jp-jqc2.json b/advisories/unreviewed/2022/05/GHSA-gvc5-74jp-jqc2/GHSA-gvc5-74jp-jqc2.json index 5dd096e124d..8276b45491f 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvc5-74jp-jqc2/GHSA-gvc5-74jp-jqc2.json +++ b/advisories/unreviewed/2022/05/GHSA-gvc5-74jp-jqc2/GHSA-gvc5-74jp-jqc2.json @@ -7,12 +7,8 @@ "CVE-2020-4552" ], "details": "IBM i2 Analyst Notebook 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183320.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gwvq-f55m-p654/GHSA-gwvq-f55m-p654.json b/advisories/unreviewed/2022/05/GHSA-gwvq-f55m-p654/GHSA-gwvq-f55m-p654.json index b425e53e4bc..a1c37c36c37 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwvq-f55m-p654/GHSA-gwvq-f55m-p654.json +++ b/advisories/unreviewed/2022/05/GHSA-gwvq-f55m-p654/GHSA-gwvq-f55m-p654.json @@ -7,12 +7,8 @@ "CVE-2020-15919" ], "details": "A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gx2p-6h82-ccjf/GHSA-gx2p-6h82-ccjf.json b/advisories/unreviewed/2022/05/GHSA-gx2p-6h82-ccjf/GHSA-gx2p-6h82-ccjf.json index bf430e629a0..71693a5e995 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx2p-6h82-ccjf/GHSA-gx2p-6h82-ccjf.json +++ b/advisories/unreviewed/2022/05/GHSA-gx2p-6h82-ccjf/GHSA-gx2p-6h82-ccjf.json @@ -7,12 +7,8 @@ "CVE-2020-9525" ], "details": "CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that allows remote attackers to perform a man-in-the-middle attack, as demonstrated by eavesdropping on user video/audio streams, capturing credentials, and compromising devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gx4h-j395-68qw/GHSA-gx4h-j395-68qw.json b/advisories/unreviewed/2022/05/GHSA-gx4h-j395-68qw/GHSA-gx4h-j395-68qw.json index daa837a4734..74226a1ce11 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx4h-j395-68qw/GHSA-gx4h-j395-68qw.json +++ b/advisories/unreviewed/2022/05/GHSA-gx4h-j395-68qw/GHSA-gx4h-j395-68qw.json @@ -7,12 +7,8 @@ "CVE-2020-3384" ], "details": "A vulnerability in specific REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system with the privileges of the logged-in user. The vulnerability is due to insufficient validation of user-supplied input to the API. An attacker could exploit this vulnerability by sending a crafted request to the API. A successful exploit could allow the attacker to inject arbitrary commands on the underlying operating system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gx64-5mxv-c598/GHSA-gx64-5mxv-c598.json b/advisories/unreviewed/2022/05/GHSA-gx64-5mxv-c598/GHSA-gx64-5mxv-c598.json index a77b28eb03b..44522720d8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx64-5mxv-c598/GHSA-gx64-5mxv-c598.json +++ b/advisories/unreviewed/2022/05/GHSA-gx64-5mxv-c598/GHSA-gx64-5mxv-c598.json @@ -7,12 +7,8 @@ "CVE-2020-9251" ], "details": "HUAWEI Mate 20 smartphones with versions earlier than 10.1.0.160(C00E160R2P11) have an improper authorization vulnerability. The software does not properly restrict certain operation in certain scenario, the attacker should do certain configuration before the user turns on student mode function. Successful exploit could allow the attacker to bypass the limit of student mode function. Affected product versions include: HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxmc-v8jp-jvf3/GHSA-gxmc-v8jp-jvf3.json b/advisories/unreviewed/2022/05/GHSA-gxmc-v8jp-jvf3/GHSA-gxmc-v8jp-jvf3.json index c7a34816649..d95c8970da6 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxmc-v8jp-jvf3/GHSA-gxmc-v8jp-jvf3.json +++ b/advisories/unreviewed/2022/05/GHSA-gxmc-v8jp-jvf3/GHSA-gxmc-v8jp-jvf3.json @@ -7,12 +7,8 @@ "CVE-2020-13179" ], "details": "Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to 20.04.1 are not cleaned up in server memory, which may allow an attacker to read confidential information from a memory dump via forcing a crashing during the single sign-on procedure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h2gv-99w3-wrfr/GHSA-h2gv-99w3-wrfr.json b/advisories/unreviewed/2022/05/GHSA-h2gv-99w3-wrfr/GHSA-h2gv-99w3-wrfr.json index 8f48aa1300b..10999bbec61 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2gv-99w3-wrfr/GHSA-h2gv-99w3-wrfr.json +++ b/advisories/unreviewed/2022/05/GHSA-h2gv-99w3-wrfr/GHSA-h2gv-99w3-wrfr.json @@ -7,12 +7,8 @@ "CVE-2020-5763" ], "details": "Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a root shell by correctly answering a challenge prompt.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h2gw-wr24-mgw2/GHSA-h2gw-wr24-mgw2.json b/advisories/unreviewed/2022/05/GHSA-h2gw-wr24-mgw2/GHSA-h2gw-wr24-mgw2.json index 86f5e395de2..3c3c5a789f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2gw-wr24-mgw2/GHSA-h2gw-wr24-mgw2.json +++ b/advisories/unreviewed/2022/05/GHSA-h2gw-wr24-mgw2/GHSA-h2gw-wr24-mgw2.json @@ -7,12 +7,8 @@ "CVE-2020-7810" ], "details": "hslogin2.dll ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method. This is due to a lack of integrity verification of the policy files referenced in the update process, and a remote attacker could induce a user to crafted web page, causing damage such as malicious code infection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h2jc-jq9c-94x8/GHSA-h2jc-jq9c-94x8.json b/advisories/unreviewed/2022/05/GHSA-h2jc-jq9c-94x8/GHSA-h2jc-jq9c-94x8.json index bbe87025314..fbd20eebcc0 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2jc-jq9c-94x8/GHSA-h2jc-jq9c-94x8.json +++ b/advisories/unreviewed/2022/05/GHSA-h2jc-jq9c-94x8/GHSA-h2jc-jq9c-94x8.json @@ -7,12 +7,8 @@ "CVE-2019-18834" ], "details": "Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Billing Details are mishandled in WCS_Admin_Post_Types in class-wcs-admin-post-types.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h2q5-5r2x-c27g/GHSA-h2q5-5r2x-c27g.json b/advisories/unreviewed/2022/05/GHSA-h2q5-5r2x-c27g/GHSA-h2q5-5r2x-c27g.json index 55d2eb83305..437ee59ebc8 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2q5-5r2x-c27g/GHSA-h2q5-5r2x-c27g.json +++ b/advisories/unreviewed/2022/05/GHSA-h2q5-5r2x-c27g/GHSA-h2q5-5r2x-c27g.json @@ -7,12 +7,8 @@ "CVE-2020-4533" ], "details": "IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182717.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h44q-56vc-mpp6/GHSA-h44q-56vc-mpp6.json b/advisories/unreviewed/2022/05/GHSA-h44q-56vc-mpp6/GHSA-h44q-56vc-mpp6.json index da747e96582..4c2e9e7f165 100644 --- a/advisories/unreviewed/2022/05/GHSA-h44q-56vc-mpp6/GHSA-h44q-56vc-mpp6.json +++ b/advisories/unreviewed/2022/05/GHSA-h44q-56vc-mpp6/GHSA-h44q-56vc-mpp6.json @@ -7,12 +7,8 @@ "CVE-2020-15511" ], "details": "HashiCorp Terraform Enterprise up to v202006-1 contained a default signup page that allowed user registration even when disabled, bypassing SAML enforcement. Fixed in v202007-1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7g5-wh6v-fwfq/GHSA-h7g5-wh6v-fwfq.json b/advisories/unreviewed/2022/05/GHSA-h7g5-wh6v-fwfq/GHSA-h7g5-wh6v-fwfq.json index 1552e0a87ab..d97b606bd41 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7g5-wh6v-fwfq/GHSA-h7g5-wh6v-fwfq.json +++ b/advisories/unreviewed/2022/05/GHSA-h7g5-wh6v-fwfq/GHSA-h7g5-wh6v-fwfq.json @@ -7,12 +7,8 @@ "CVE-2020-15943" ], "details": "An issue was discovered in the Gantt-Chart module before 5.5.4 for Jira. Due to a missing privilege check, it is possible to read and write to the module configuration of other users. This can also be used to deliver an XSS payload to other users' dashboards. To exploit this vulnerability, an attacker has to be authenticated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h8x5-w868-8g3c/GHSA-h8x5-w868-8g3c.json b/advisories/unreviewed/2022/05/GHSA-h8x5-w868-8g3c/GHSA-h8x5-w868-8g3c.json index c3731dc8f4d..f21f42677c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8x5-w868-8g3c/GHSA-h8x5-w868-8g3c.json +++ b/advisories/unreviewed/2022/05/GHSA-h8x5-w868-8g3c/GHSA-h8x5-w868-8g3c.json @@ -7,12 +7,8 @@ "CVE-2020-16203" ], "details": "Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. An uninitialized pointer may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h9cr-cxm7-hxwf/GHSA-h9cr-cxm7-hxwf.json b/advisories/unreviewed/2022/05/GHSA-h9cr-cxm7-hxwf/GHSA-h9cr-cxm7-hxwf.json index e5bf4c61bbf..37775dac705 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9cr-cxm7-hxwf/GHSA-h9cr-cxm7-hxwf.json +++ b/advisories/unreviewed/2022/05/GHSA-h9cr-cxm7-hxwf/GHSA-h9cr-cxm7-hxwf.json @@ -7,12 +7,8 @@ "CVE-2020-15609" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When parsing the service_stop parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9726.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hc3q-25wm-mcp8/GHSA-hc3q-25wm-mcp8.json b/advisories/unreviewed/2022/05/GHSA-hc3q-25wm-mcp8/GHSA-hc3q-25wm-mcp8.json index 0b628462920..378d2925795 100644 --- a/advisories/unreviewed/2022/05/GHSA-hc3q-25wm-mcp8/GHSA-hc3q-25wm-mcp8.json +++ b/advisories/unreviewed/2022/05/GHSA-hc3q-25wm-mcp8/GHSA-hc3q-25wm-mcp8.json @@ -7,12 +7,8 @@ "CVE-2020-17447" ], "details": "MyBB before 1.8.24 allows XSS because the visual editor mishandles [align], [size], [quote], and [font] in MyCode.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "WEB", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hf38-9jxh-8cg7/GHSA-hf38-9jxh-8cg7.json b/advisories/unreviewed/2022/05/GHSA-hf38-9jxh-8cg7/GHSA-hf38-9jxh-8cg7.json index 716eaad90a2..226552ea368 100644 --- a/advisories/unreviewed/2022/05/GHSA-hf38-9jxh-8cg7/GHSA-hf38-9jxh-8cg7.json +++ b/advisories/unreviewed/2022/05/GHSA-hf38-9jxh-8cg7/GHSA-hf38-9jxh-8cg7.json @@ -7,12 +7,8 @@ "CVE-2020-6528" ], "details": "Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hgjq-9w99-jfwx/GHSA-hgjq-9w99-jfwx.json b/advisories/unreviewed/2022/05/GHSA-hgjq-9w99-jfwx/GHSA-hgjq-9w99-jfwx.json index 899ecc3b4ba..d30ab82a4d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-hgjq-9w99-jfwx/GHSA-hgjq-9w99-jfwx.json +++ b/advisories/unreviewed/2022/05/GHSA-hgjq-9w99-jfwx/GHSA-hgjq-9w99-jfwx.json @@ -7,12 +7,8 @@ "CVE-2020-11584" ], "details": "A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hh72-hh2x-wx4w/GHSA-hh72-hh2x-wx4w.json b/advisories/unreviewed/2022/05/GHSA-hh72-hh2x-wx4w/GHSA-hh72-hh2x-wx4w.json index b2b38fe978f..6b384d6530e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hh72-hh2x-wx4w/GHSA-hh72-hh2x-wx4w.json +++ b/advisories/unreviewed/2022/05/GHSA-hh72-hh2x-wx4w/GHSA-hh72-hh2x-wx4w.json @@ -7,12 +7,8 @@ "CVE-2020-15918" ], "details": "Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hhqj-j8pr-wh7g/GHSA-hhqj-j8pr-wh7g.json b/advisories/unreviewed/2022/05/GHSA-hhqj-j8pr-wh7g/GHSA-hhqj-j8pr-wh7g.json index 59a2ecb407a..a5a5674f722 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhqj-j8pr-wh7g/GHSA-hhqj-j8pr-wh7g.json +++ b/advisories/unreviewed/2022/05/GHSA-hhqj-j8pr-wh7g/GHSA-hhqj-j8pr-wh7g.json @@ -7,12 +7,8 @@ "CVE-2020-9663" ], "details": "Adobe Reader Mobile versions 20.0.1 and earlier have a directory traversal vulnerability. Successful exploitation could lead to information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hqj4-jqvv-8f53/GHSA-hqj4-jqvv-8f53.json b/advisories/unreviewed/2022/05/GHSA-hqj4-jqvv-8f53/GHSA-hqj4-jqvv-8f53.json index 64972d38efe..75287b4b824 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqj4-jqvv-8f53/GHSA-hqj4-jqvv-8f53.json +++ b/advisories/unreviewed/2022/05/GHSA-hqj4-jqvv-8f53/GHSA-hqj4-jqvv-8f53.json @@ -7,12 +7,8 @@ "CVE-2020-6507" ], "details": "Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hqq9-hv7p-jh7g/GHSA-hqq9-hv7p-jh7g.json b/advisories/unreviewed/2022/05/GHSA-hqq9-hv7p-jh7g/GHSA-hqq9-hv7p-jh7g.json index f0a49773e31..b962287e762 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqq9-hv7p-jh7g/GHSA-hqq9-hv7p-jh7g.json +++ b/advisories/unreviewed/2022/05/GHSA-hqq9-hv7p-jh7g/GHSA-hqq9-hv7p-jh7g.json @@ -7,12 +7,8 @@ "CVE-2020-5613" ], "details": "Cross-site scripting vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to execute an arbitrary script via a specially crafted URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hqvg-c75v-f3jx/GHSA-hqvg-c75v-f3jx.json b/advisories/unreviewed/2022/05/GHSA-hqvg-c75v-f3jx/GHSA-hqvg-c75v-f3jx.json index 71d4f95f666..00c27563366 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqvg-c75v-f3jx/GHSA-hqvg-c75v-f3jx.json +++ b/advisories/unreviewed/2022/05/GHSA-hqvg-c75v-f3jx/GHSA-hqvg-c75v-f3jx.json @@ -7,12 +7,8 @@ "CVE-2020-10926" ], "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of firmware updates. The issue results from the lack of proper validation of the firmware image prior to performing an upgrade. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-9648.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hrww-g57w-hvr9/GHSA-hrww-g57w-hvr9.json b/advisories/unreviewed/2022/05/GHSA-hrww-g57w-hvr9/GHSA-hrww-g57w-hvr9.json index f0b8b565d8b..107fb29cb88 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrww-g57w-hvr9/GHSA-hrww-g57w-hvr9.json +++ b/advisories/unreviewed/2022/05/GHSA-hrww-g57w-hvr9/GHSA-hrww-g57w-hvr9.json @@ -7,12 +7,8 @@ "CVE-2020-15715" ], "details": "rConfig 3.9.5 could allow a remote authenticated attacker to execute arbitrary code on the system, because of an error in the search.crud.php script. An attacker could exploit this vulnerability using the nodeId parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j2gp-5gr4-5w9f/GHSA-j2gp-5gr4-5w9f.json b/advisories/unreviewed/2022/05/GHSA-j2gp-5gr4-5w9f/GHSA-j2gp-5gr4-5w9f.json index d1d6990a10a..25061f42bda 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2gp-5gr4-5w9f/GHSA-j2gp-5gr4-5w9f.json +++ b/advisories/unreviewed/2022/05/GHSA-j2gp-5gr4-5w9f/GHSA-j2gp-5gr4-5w9f.json @@ -7,12 +7,8 @@ "CVE-2020-10982" ], "details": "Gambio GX before 4.0.1.0 allows SQL Injection in admin/gv_mail.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j2j4-j7cr-p458/GHSA-j2j4-j7cr-p458.json b/advisories/unreviewed/2022/05/GHSA-j2j4-j7cr-p458/GHSA-j2j4-j7cr-p458.json index 1d9a622b6a6..802c3dfa4cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2j4-j7cr-p458/GHSA-j2j4-j7cr-p458.json +++ b/advisories/unreviewed/2022/05/GHSA-j2j4-j7cr-p458/GHSA-j2j4-j7cr-p458.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j2w8-mvfp-q4rg/GHSA-j2w8-mvfp-q4rg.json b/advisories/unreviewed/2022/05/GHSA-j2w8-mvfp-q4rg/GHSA-j2w8-mvfp-q4rg.json index 54acc5fe536..98e90d1493a 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2w8-mvfp-q4rg/GHSA-j2w8-mvfp-q4rg.json +++ b/advisories/unreviewed/2022/05/GHSA-j2w8-mvfp-q4rg/GHSA-j2w8-mvfp-q4rg.json @@ -7,12 +7,8 @@ "CVE-2020-12300" ], "details": "Uninitialized pointer in BIOS firmware for Intel(R) Server Board Families S2600CW, S2600KP, S2600TP, and S2600WT may allow a privileged user to potentially enable escalation of privilege via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j89v-2w65-5qmq/GHSA-j89v-2w65-5qmq.json b/advisories/unreviewed/2022/05/GHSA-j89v-2w65-5qmq/GHSA-j89v-2w65-5qmq.json index 7ddf6cef922..2bb0254cb00 100644 --- a/advisories/unreviewed/2022/05/GHSA-j89v-2w65-5qmq/GHSA-j89v-2w65-5qmq.json +++ b/advisories/unreviewed/2022/05/GHSA-j89v-2w65-5qmq/GHSA-j89v-2w65-5qmq.json @@ -7,12 +7,8 @@ "CVE-2020-16117" ], "details": "In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j8cv-gf68-463p/GHSA-j8cv-gf68-463p.json b/advisories/unreviewed/2022/05/GHSA-j8cv-gf68-463p/GHSA-j8cv-gf68-463p.json index 9c1ce443a9f..0c943d5c341 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8cv-gf68-463p/GHSA-j8cv-gf68-463p.json +++ b/advisories/unreviewed/2022/05/GHSA-j8cv-gf68-463p/GHSA-j8cv-gf68-463p.json @@ -7,12 +7,8 @@ "CVE-2020-10924" ], "details": "This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the UPnP service, which listens on TCP port 5000 by default. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9643.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j8w5-rfgv-wq62/GHSA-j8w5-rfgv-wq62.json b/advisories/unreviewed/2022/05/GHSA-j8w5-rfgv-wq62/GHSA-j8w5-rfgv-wq62.json index 8186ea0b83c..d25ced32de4 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8w5-rfgv-wq62/GHSA-j8w5-rfgv-wq62.json +++ b/advisories/unreviewed/2022/05/GHSA-j8w5-rfgv-wq62/GHSA-j8w5-rfgv-wq62.json @@ -7,12 +7,8 @@ "CVE-2020-5614" ], "details": "Directory traversal vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to read arbitrary files via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j99m-3q8x-q82h/GHSA-j99m-3q8x-q82h.json b/advisories/unreviewed/2022/05/GHSA-j99m-3q8x-q82h/GHSA-j99m-3q8x-q82h.json index d60054273ab..0cc4bd216ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-j99m-3q8x-q82h/GHSA-j99m-3q8x-q82h.json +++ b/advisories/unreviewed/2022/05/GHSA-j99m-3q8x-q82h/GHSA-j99m-3q8x-q82h.json @@ -7,12 +7,8 @@ "CVE-2020-9685" ], "details": "Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jcx7-mqqf-7jxj/GHSA-jcx7-mqqf-7jxj.json b/advisories/unreviewed/2022/05/GHSA-jcx7-mqqf-7jxj/GHSA-jcx7-mqqf-7jxj.json index 5eee98a6ef2..f857c6542fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcx7-mqqf-7jxj/GHSA-jcx7-mqqf-7jxj.json +++ b/advisories/unreviewed/2022/05/GHSA-jcx7-mqqf-7jxj/GHSA-jcx7-mqqf-7jxj.json @@ -7,12 +7,8 @@ "CVE-2020-5377" ], "details": "Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. An unauthenticated remote attacker could potentially exploit these vulnerabilities by sending a crafted Web API request containing directory traversal character sequences to gain file system access on the compromised management station.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jf2p-5456-5593/GHSA-jf2p-5456-5593.json b/advisories/unreviewed/2022/05/GHSA-jf2p-5456-5593/GHSA-jf2p-5456-5593.json index 37d82e5976c..1a70cfc51e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf2p-5456-5593/GHSA-jf2p-5456-5593.json +++ b/advisories/unreviewed/2022/05/GHSA-jf2p-5456-5593/GHSA-jf2p-5456-5593.json @@ -7,12 +7,8 @@ "CVE-2020-12638" ], "details": "An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3.0.3, and ESP8266_RTOS_SDK devices through 3.3. Broadcasting forged beacon frames forces a device to change its authentication mode to OPEN, effectively disabling its 802.11 encryption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jf53-7299-h2m3/GHSA-jf53-7299-h2m3.json b/advisories/unreviewed/2022/05/GHSA-jf53-7299-h2m3/GHSA-jf53-7299-h2m3.json index 0e26189c7c3..f8cbedaed91 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf53-7299-h2m3/GHSA-jf53-7299-h2m3.json +++ b/advisories/unreviewed/2022/05/GHSA-jf53-7299-h2m3/GHSA-jf53-7299-h2m3.json @@ -7,12 +7,8 @@ "CVE-2020-6510" ], "details": "Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jfcv-g6r7-w56q/GHSA-jfcv-g6r7-w56q.json b/advisories/unreviewed/2022/05/GHSA-jfcv-g6r7-w56q/GHSA-jfcv-g6r7-w56q.json index 51310598065..1d365630bff 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfcv-g6r7-w56q/GHSA-jfcv-g6r7-w56q.json +++ b/advisories/unreviewed/2022/05/GHSA-jfcv-g6r7-w56q/GHSA-jfcv-g6r7-w56q.json @@ -7,12 +7,8 @@ "CVE-2020-4550" ], "details": "IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183318.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jhcg-52pw-m42j/GHSA-jhcg-52pw-m42j.json b/advisories/unreviewed/2022/05/GHSA-jhcg-52pw-m42j/GHSA-jhcg-52pw-m42j.json index 3bd9a0a6956..41b359bab6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhcg-52pw-m42j/GHSA-jhcg-52pw-m42j.json +++ b/advisories/unreviewed/2022/05/GHSA-jhcg-52pw-m42j/GHSA-jhcg-52pw-m42j.json @@ -7,12 +7,8 @@ "CVE-2020-7822" ], "details": "DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed image file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jq98-fhjv-vfh7/GHSA-jq98-fhjv-vfh7.json b/advisories/unreviewed/2022/05/GHSA-jq98-fhjv-vfh7/GHSA-jq98-fhjv-vfh7.json index f13192954fa..ad46acf9301 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq98-fhjv-vfh7/GHSA-jq98-fhjv-vfh7.json +++ b/advisories/unreviewed/2022/05/GHSA-jq98-fhjv-vfh7/GHSA-jq98-fhjv-vfh7.json @@ -7,12 +7,8 @@ "CVE-2020-14488" ], "details": "OpenClinic GA 5.09.02 and 5.89.05b does not properly verify uploaded files, which may allow a low-privilege user to upload and execute arbitrary files on the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jrmg-2w74-rwc9/GHSA-jrmg-2w74-rwc9.json b/advisories/unreviewed/2022/05/GHSA-jrmg-2w74-rwc9/GHSA-jrmg-2w74-rwc9.json index 9acc2136bdd..84b9fccd852 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrmg-2w74-rwc9/GHSA-jrmg-2w74-rwc9.json +++ b/advisories/unreviewed/2022/05/GHSA-jrmg-2w74-rwc9/GHSA-jrmg-2w74-rwc9.json @@ -7,12 +7,8 @@ "CVE-2020-15648" ], "details": "Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jrwr-g23m-c7xm/GHSA-jrwr-g23m-c7xm.json b/advisories/unreviewed/2022/05/GHSA-jrwr-g23m-c7xm/GHSA-jrwr-g23m-c7xm.json index 94aaacf8b14..1fcfc4f69ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrwr-g23m-c7xm/GHSA-jrwr-g23m-c7xm.json +++ b/advisories/unreviewed/2022/05/GHSA-jrwr-g23m-c7xm/GHSA-jrwr-g23m-c7xm.json @@ -7,12 +7,8 @@ "CVE-2020-0247" ], "details": "In Threshold::getHistogram of ImageProcessHelper.java, there is a possible crash loop due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-8.0 Android-8.1Android ID: A-156087409", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jv2p-68ph-w4mw/GHSA-jv2p-68ph-w4mw.json b/advisories/unreviewed/2022/05/GHSA-jv2p-68ph-w4mw/GHSA-jv2p-68ph-w4mw.json index d340923327e..4480d2c0f25 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv2p-68ph-w4mw/GHSA-jv2p-68ph-w4mw.json +++ b/advisories/unreviewed/2022/05/GHSA-jv2p-68ph-w4mw/GHSA-jv2p-68ph-w4mw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jv87-phf9-vqrx/GHSA-jv87-phf9-vqrx.json b/advisories/unreviewed/2022/05/GHSA-jv87-phf9-vqrx/GHSA-jv87-phf9-vqrx.json index da62eff1d10..e6ead8bc653 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv87-phf9-vqrx/GHSA-jv87-phf9-vqrx.json +++ b/advisories/unreviewed/2022/05/GHSA-jv87-phf9-vqrx/GHSA-jv87-phf9-vqrx.json @@ -7,12 +7,8 @@ "CVE-2020-9404" ], "details": "In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in an insecure manner, and may be modified by an attacker with no knowledge of the current passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jvwc-5h95-6j3j/GHSA-jvwc-5h95-6j3j.json b/advisories/unreviewed/2022/05/GHSA-jvwc-5h95-6j3j/GHSA-jvwc-5h95-6j3j.json index cfe02ea2b47..a8b23437245 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvwc-5h95-6j3j/GHSA-jvwc-5h95-6j3j.json +++ b/advisories/unreviewed/2022/05/GHSA-jvwc-5h95-6j3j/GHSA-jvwc-5h95-6j3j.json @@ -7,12 +7,8 @@ "CVE-2020-12107" ], "details": "The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full control over this module's Operating System.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jx8x-69j8-c7fj/GHSA-jx8x-69j8-c7fj.json b/advisories/unreviewed/2022/05/GHSA-jx8x-69j8-c7fj/GHSA-jx8x-69j8-c7fj.json index 49a6ba4d47b..5df7403b101 100644 --- a/advisories/unreviewed/2022/05/GHSA-jx8x-69j8-c7fj/GHSA-jx8x-69j8-c7fj.json +++ b/advisories/unreviewed/2022/05/GHSA-jx8x-69j8-c7fj/GHSA-jx8x-69j8-c7fj.json @@ -7,12 +7,8 @@ "CVE-2020-9244" ], "details": "HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Versions earlier than 10.1.0.270(C431E7R1P5),Versions earlier than 10.1.0.270(C635E3R1P5),Versions earlier than 10.1.0.273(C636E7R2P4);HUAWEI Mate 20 X versions Versions earlier than 10.1.0.160(C00E160R2P8);HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11);HUAWEI P30 Pro versions Versions earlier than 10.1.0.160(C00E160R2P8);HUAWEI Mate 20 RS versions Versions earlier than 10.1.0.160(C786E160R3P8);HonorMagic2 versions Versions earlier than 10.0.0.187(C00E61R2P11);Honor20 versions Versions earlier than 10.0.0.175(C00E58R4P11);Honor20 PRO versions Versions earlier than 10.0.0.194(C00E62R8P12);HonorMagic2 versions Versions earlier than 10.0.0.187(C00E61R2P11);HonorV20 versions Versions earlier than 10.0.0.188(C00E62R2P11) have an improper authentication vulnerability. The system does not properly sign certain encrypted file, the attacker should gain the key used to encrypt the file, successful exploit could cause certain file be forged", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m277-4pfg-jc3f/GHSA-m277-4pfg-jc3f.json b/advisories/unreviewed/2022/05/GHSA-m277-4pfg-jc3f/GHSA-m277-4pfg-jc3f.json index 31c5de53478..0efac973afe 100644 --- a/advisories/unreviewed/2022/05/GHSA-m277-4pfg-jc3f/GHSA-m277-4pfg-jc3f.json +++ b/advisories/unreviewed/2022/05/GHSA-m277-4pfg-jc3f/GHSA-m277-4pfg-jc3f.json @@ -7,12 +7,8 @@ "CVE-2020-6527" ], "details": "Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m2cj-gv2p-qwgr/GHSA-m2cj-gv2p-qwgr.json b/advisories/unreviewed/2022/05/GHSA-m2cj-gv2p-qwgr/GHSA-m2cj-gv2p-qwgr.json index f4a89698e06..bbefdeba413 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2cj-gv2p-qwgr/GHSA-m2cj-gv2p-qwgr.json +++ b/advisories/unreviewed/2022/05/GHSA-m2cj-gv2p-qwgr/GHSA-m2cj-gv2p-qwgr.json @@ -7,12 +7,8 @@ "CVE-2020-10985" ], "details": "Gambio GX before 4.0.1.0 allows XSS in admin/coupon_admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m3m4-q36r-mrf5/GHSA-m3m4-q36r-mrf5.json b/advisories/unreviewed/2022/05/GHSA-m3m4-q36r-mrf5/GHSA-m3m4-q36r-mrf5.json index 3cf9fb68271..112a5a610fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3m4-q36r-mrf5/GHSA-m3m4-q36r-mrf5.json +++ b/advisories/unreviewed/2022/05/GHSA-m3m4-q36r-mrf5/GHSA-m3m4-q36r-mrf5.json @@ -7,12 +7,8 @@ "CVE-2020-17487" ], "details": "radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in r_x509_parse_algorithmidentifier in libr/util/x509.c. This is due to a malformed object identifier in IMAGE_DIRECTORY_ENTRY_SECURITY.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m3qf-xv59-6w6h/GHSA-m3qf-xv59-6w6h.json b/advisories/unreviewed/2022/05/GHSA-m3qf-xv59-6w6h/GHSA-m3qf-xv59-6w6h.json index 925298b72c6..458b1618e44 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3qf-xv59-6w6h/GHSA-m3qf-xv59-6w6h.json +++ b/advisories/unreviewed/2022/05/GHSA-m3qf-xv59-6w6h/GHSA-m3qf-xv59-6w6h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m5g4-cg24-mc6m/GHSA-m5g4-cg24-mc6m.json b/advisories/unreviewed/2022/05/GHSA-m5g4-cg24-mc6m/GHSA-m5g4-cg24-mc6m.json index f82741cb3ea..9daea3fcf05 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5g4-cg24-mc6m/GHSA-m5g4-cg24-mc6m.json +++ b/advisories/unreviewed/2022/05/GHSA-m5g4-cg24-mc6m/GHSA-m5g4-cg24-mc6m.json @@ -7,12 +7,8 @@ "CVE-2020-17451" ], "details": "flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title, page_content, or page_extracontent parameter, or the acp/acp.php?tn=system&sub=sys_pref prefs_pagename, prefs_pagetitle, or prefs_pagesubtitle parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m67c-r98h-r497/GHSA-m67c-r98h-r497.json b/advisories/unreviewed/2022/05/GHSA-m67c-r98h-r497/GHSA-m67c-r98h-r497.json index 300561e59d8..a48bb06a1fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-m67c-r98h-r497/GHSA-m67c-r98h-r497.json +++ b/advisories/unreviewed/2022/05/GHSA-m67c-r98h-r497/GHSA-m67c-r98h-r497.json @@ -7,12 +7,8 @@ "CVE-2020-11625" ], "details": "An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. Failed web UI login attempts elicit different responses depending on whether a user account exists. Because the responses indicate whether a submitted username is valid or not, they make it easier to identify legitimate usernames. If a login request is sent to ISAPI/Security/sessionLogin/capabilities using a username that exists, it will return the value of the salt given to that username, even if the password is incorrect. However, if a login request is sent using a username that is not present in the database, it will return an empty salt value. This allows attackers to enumerate legitimate usernames, facilitating brute-force attacks. NOTE: this is different from CVE-2020-7057.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m99h-7jcp-j7w9/GHSA-m99h-7jcp-j7w9.json b/advisories/unreviewed/2022/05/GHSA-m99h-7jcp-j7w9/GHSA-m99h-7jcp-j7w9.json index a00ea51a52c..1532d12a37e 100644 --- a/advisories/unreviewed/2022/05/GHSA-m99h-7jcp-j7w9/GHSA-m99h-7jcp-j7w9.json +++ b/advisories/unreviewed/2022/05/GHSA-m99h-7jcp-j7w9/GHSA-m99h-7jcp-j7w9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mcvv-v9fp-qqw7/GHSA-mcvv-v9fp-qqw7.json b/advisories/unreviewed/2022/05/GHSA-mcvv-v9fp-qqw7/GHSA-mcvv-v9fp-qqw7.json index d467cc7b3a9..2ac0a4976a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcvv-v9fp-qqw7/GHSA-mcvv-v9fp-qqw7.json +++ b/advisories/unreviewed/2022/05/GHSA-mcvv-v9fp-qqw7/GHSA-mcvv-v9fp-qqw7.json @@ -7,12 +7,8 @@ "CVE-2020-7298" ], "details": "Unexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real time scanning via a specially crafted object making a specific function call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mf72-cf87-p3p2/GHSA-mf72-cf87-p3p2.json b/advisories/unreviewed/2022/05/GHSA-mf72-cf87-p3p2/GHSA-mf72-cf87-p3p2.json index e27e18102d1..06a880725b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf72-cf87-p3p2/GHSA-mf72-cf87-p3p2.json +++ b/advisories/unreviewed/2022/05/GHSA-mf72-cf87-p3p2/GHSA-mf72-cf87-p3p2.json @@ -7,12 +7,8 @@ "CVE-2020-15707" ], "details": "Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mghr-9r72-32fv/GHSA-mghr-9r72-32fv.json b/advisories/unreviewed/2022/05/GHSA-mghr-9r72-32fv/GHSA-mghr-9r72-32fv.json index 0bde9c04d28..5fd79b99dc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-mghr-9r72-32fv/GHSA-mghr-9r72-32fv.json +++ b/advisories/unreviewed/2022/05/GHSA-mghr-9r72-32fv/GHSA-mghr-9r72-32fv.json @@ -7,12 +7,8 @@ "CVE-2020-13914" ], "details": "webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to cause a denial of service (Segmentation fault) to the webserver via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and T710s devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mh3c-hpgm-9fqj/GHSA-mh3c-hpgm-9fqj.json b/advisories/unreviewed/2022/05/GHSA-mh3c-hpgm-9fqj/GHSA-mh3c-hpgm-9fqj.json index e01b275c2a7..fc188706fb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh3c-hpgm-9fqj/GHSA-mh3c-hpgm-9fqj.json +++ b/advisories/unreviewed/2022/05/GHSA-mh3c-hpgm-9fqj/GHSA-mh3c-hpgm-9fqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mh5x-6mg7-gjp9/GHSA-mh5x-6mg7-gjp9.json b/advisories/unreviewed/2022/05/GHSA-mh5x-6mg7-gjp9/GHSA-mh5x-6mg7-gjp9.json index 808ca059521..c9bd852ad55 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh5x-6mg7-gjp9/GHSA-mh5x-6mg7-gjp9.json +++ b/advisories/unreviewed/2022/05/GHSA-mh5x-6mg7-gjp9/GHSA-mh5x-6mg7-gjp9.json @@ -7,12 +7,8 @@ "CVE-2020-4463" ], "details": "IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181484.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mjfv-7ccm-vjfr/GHSA-mjfv-7ccm-vjfr.json b/advisories/unreviewed/2022/05/GHSA-mjfv-7ccm-vjfr/GHSA-mjfv-7ccm-vjfr.json index 32be01ac7cd..42f60958544 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjfv-7ccm-vjfr/GHSA-mjfv-7ccm-vjfr.json +++ b/advisories/unreviewed/2022/05/GHSA-mjfv-7ccm-vjfr/GHSA-mjfv-7ccm-vjfr.json @@ -7,12 +7,8 @@ "CVE-2020-4541" ], "details": "IBM Jazz Reporting Service 7.0 and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183039.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mjvf-gr25-6fx5/GHSA-mjvf-gr25-6fx5.json b/advisories/unreviewed/2022/05/GHSA-mjvf-gr25-6fx5/GHSA-mjvf-gr25-6fx5.json index 8131e082d09..aeaf7f5a6da 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjvf-gr25-6fx5/GHSA-mjvf-gr25-6fx5.json +++ b/advisories/unreviewed/2022/05/GHSA-mjvf-gr25-6fx5/GHSA-mjvf-gr25-6fx5.json @@ -7,12 +7,8 @@ "CVE-2020-6523" ], "details": "Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mq2v-3xvx-978w/GHSA-mq2v-3xvx-978w.json b/advisories/unreviewed/2022/05/GHSA-mq2v-3xvx-978w/GHSA-mq2v-3xvx-978w.json index aa33d340a3a..fd67ce08720 100644 --- a/advisories/unreviewed/2022/05/GHSA-mq2v-3xvx-978w/GHSA-mq2v-3xvx-978w.json +++ b/advisories/unreviewed/2022/05/GHSA-mq2v-3xvx-978w/GHSA-mq2v-3xvx-978w.json @@ -7,12 +7,8 @@ "CVE-2020-16843" ], "details": "In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. This can result in a denial of service on the microVM when it is configured with a single network interface, and an availability problem for the microVM network interface on which the issue is triggered.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mw42-fpx9-595r/GHSA-mw42-fpx9-595r.json b/advisories/unreviewed/2022/05/GHSA-mw42-fpx9-595r/GHSA-mw42-fpx9-595r.json index 4500d038d87..dc0aceca869 100644 --- a/advisories/unreviewed/2022/05/GHSA-mw42-fpx9-595r/GHSA-mw42-fpx9-595r.json +++ b/advisories/unreviewed/2022/05/GHSA-mw42-fpx9-595r/GHSA-mw42-fpx9-595r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "WEB", diff --git a/advisories/unreviewed/2022/05/GHSA-mwgq-j58h-pv6j/GHSA-mwgq-j58h-pv6j.json b/advisories/unreviewed/2022/05/GHSA-mwgq-j58h-pv6j/GHSA-mwgq-j58h-pv6j.json index 2b48e2e82be..4ec4a0b1a55 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwgq-j58h-pv6j/GHSA-mwgq-j58h-pv6j.json +++ b/advisories/unreviewed/2022/05/GHSA-mwgq-j58h-pv6j/GHSA-mwgq-j58h-pv6j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mww4-2jjr-hwq6/GHSA-mww4-2jjr-hwq6.json b/advisories/unreviewed/2022/05/GHSA-mww4-2jjr-hwq6/GHSA-mww4-2jjr-hwq6.json index be4337a3600..d91a22d9920 100644 --- a/advisories/unreviewed/2022/05/GHSA-mww4-2jjr-hwq6/GHSA-mww4-2jjr-hwq6.json +++ b/advisories/unreviewed/2022/05/GHSA-mww4-2jjr-hwq6/GHSA-mww4-2jjr-hwq6.json @@ -7,12 +7,8 @@ "CVE-2020-4525" ], "details": "IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182435.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mwwm-6m8g-p8pv/GHSA-mwwm-6m8g-p8pv.json b/advisories/unreviewed/2022/05/GHSA-mwwm-6m8g-p8pv/GHSA-mwwm-6m8g-p8pv.json index 592c928be43..fa659302aad 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwwm-6m8g-p8pv/GHSA-mwwm-6m8g-p8pv.json +++ b/advisories/unreviewed/2022/05/GHSA-mwwm-6m8g-p8pv/GHSA-mwwm-6m8g-p8pv.json @@ -7,12 +7,8 @@ "CVE-2020-11852" ], "details": "DKIM key management page vulnerability on Micro Focus Secure Messaging Gateway (SMG). Affecting all SMG Appliance running releases prior to July 2020. The vulnerability could allow a logged in user with rights to generate DKIM key information to inject system commands into the call to the DKIM system command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mx3g-vxfx-q944/GHSA-mx3g-vxfx-q944.json b/advisories/unreviewed/2022/05/GHSA-mx3g-vxfx-q944/GHSA-mx3g-vxfx-q944.json index 5aa72bce7ea..04c16f35c18 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx3g-vxfx-q944/GHSA-mx3g-vxfx-q944.json +++ b/advisories/unreviewed/2022/05/GHSA-mx3g-vxfx-q944/GHSA-mx3g-vxfx-q944.json @@ -7,12 +7,8 @@ "CVE-2020-15817" ], "details": "In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p2h2-c6c9-9wpx/GHSA-p2h2-c6c9-9wpx.json b/advisories/unreviewed/2022/05/GHSA-p2h2-c6c9-9wpx/GHSA-p2h2-c6c9-9wpx.json index 0160dd6baaa..8abbbfe6f69 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2h2-c6c9-9wpx/GHSA-p2h2-c6c9-9wpx.json +++ b/advisories/unreviewed/2022/05/GHSA-p2h2-c6c9-9wpx/GHSA-p2h2-c6c9-9wpx.json @@ -7,12 +7,8 @@ "CVE-2020-9245" ], "details": "HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11);HUAWEI P30 Pro versions Versions earlier than 10.1.0.160(C00E160R2P8) have a denial of service vulnerability. Certain system configuration can be modified because of improper authorization. The attacker could trick the user installing and executing a malicious application, successful exploit could cause a denial of service condition of PHONE function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p38c-f9r4-phgg/GHSA-p38c-f9r4-phgg.json b/advisories/unreviewed/2022/05/GHSA-p38c-f9r4-phgg/GHSA-p38c-f9r4-phgg.json index 97f2383fa21..4b06571aff1 100644 --- a/advisories/unreviewed/2022/05/GHSA-p38c-f9r4-phgg/GHSA-p38c-f9r4-phgg.json +++ b/advisories/unreviewed/2022/05/GHSA-p38c-f9r4-phgg/GHSA-p38c-f9r4-phgg.json @@ -7,12 +7,8 @@ "CVE-2020-14490" ], "details": "OpenClinic GA 5.09.02 and 5.89.05b includes arbitrary local files specified within its parameter and executes some files, which may allow disclosure of sensitive files or the execution of malicious uploaded files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p38g-jh93-54hr/GHSA-p38g-jh93-54hr.json b/advisories/unreviewed/2022/05/GHSA-p38g-jh93-54hr/GHSA-p38g-jh93-54hr.json index 7efd39ddbc6..44d52298364 100644 --- a/advisories/unreviewed/2022/05/GHSA-p38g-jh93-54hr/GHSA-p38g-jh93-54hr.json +++ b/advisories/unreviewed/2022/05/GHSA-p38g-jh93-54hr/GHSA-p38g-jh93-54hr.json @@ -7,12 +7,8 @@ "CVE-2020-5612" ], "details": "Cross-site scripting vulnerability in KonaWiki 2.2.0 and earlier allows remote attackers to execute an arbitrary script via a specially crafted URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p3w6-4fw6-pj7x/GHSA-p3w6-4fw6-pj7x.json b/advisories/unreviewed/2022/05/GHSA-p3w6-4fw6-pj7x/GHSA-p3w6-4fw6-pj7x.json index 3a7e1b11129..76451cc6906 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3w6-4fw6-pj7x/GHSA-p3w6-4fw6-pj7x.json +++ b/advisories/unreviewed/2022/05/GHSA-p3w6-4fw6-pj7x/GHSA-p3w6-4fw6-pj7x.json @@ -7,12 +7,8 @@ "CVE-2020-10984" ], "details": "Gambio GX before 4.0.1.0 allows admin/admin.php CSRF.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p4g5-c242-jpp7/GHSA-p4g5-c242-jpp7.json b/advisories/unreviewed/2022/05/GHSA-p4g5-c242-jpp7/GHSA-p4g5-c242-jpp7.json index 6589ab7ac7e..b435f876e19 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4g5-c242-jpp7/GHSA-p4g5-c242-jpp7.json +++ b/advisories/unreviewed/2022/05/GHSA-p4g5-c242-jpp7/GHSA-p4g5-c242-jpp7.json @@ -7,12 +7,8 @@ "CVE-2020-15477" ], "details": "The WebControl in RaspberryTortoise through 2012-10-28 is vulnerable to remote code execution via shell metacharacters in a URI. The file nodejs/raspberryTortoise.js has no validation on the parameter incomingString before passing it to the child_process.exec function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p845-8rw7-6wm9/GHSA-p845-8rw7-6wm9.json b/advisories/unreviewed/2022/05/GHSA-p845-8rw7-6wm9/GHSA-p845-8rw7-6wm9.json index d967cb235ff..8efd49e1a56 100644 --- a/advisories/unreviewed/2022/05/GHSA-p845-8rw7-6wm9/GHSA-p845-8rw7-6wm9.json +++ b/advisories/unreviewed/2022/05/GHSA-p845-8rw7-6wm9/GHSA-p845-8rw7-6wm9.json @@ -7,12 +7,8 @@ "CVE-2020-10923" ], "details": "This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UPnP service, which listens on TCP port 5000. A crafted UPnP message can be used to bypass authentication. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-9642.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p8pw-f2qh-mrc2/GHSA-p8pw-f2qh-mrc2.json b/advisories/unreviewed/2022/05/GHSA-p8pw-f2qh-mrc2/GHSA-p8pw-f2qh-mrc2.json index e3a1622329b..107be5a5f66 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8pw-f2qh-mrc2/GHSA-p8pw-f2qh-mrc2.json +++ b/advisories/unreviewed/2022/05/GHSA-p8pw-f2qh-mrc2/GHSA-p8pw-f2qh-mrc2.json @@ -7,12 +7,8 @@ "CVE-2020-14337" ], "details": "A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages from the default organization and verify existing usernames. The highest threat from this vulnerability is to data confidentiality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p92m-c9r4-7vc4/GHSA-p92m-c9r4-7vc4.json b/advisories/unreviewed/2022/05/GHSA-p92m-c9r4-7vc4/GHSA-p92m-c9r4-7vc4.json index 85b24b0577e..0929efa2a06 100644 --- a/advisories/unreviewed/2022/05/GHSA-p92m-c9r4-7vc4/GHSA-p92m-c9r4-7vc4.json +++ b/advisories/unreviewed/2022/05/GHSA-p92m-c9r4-7vc4/GHSA-p92m-c9r4-7vc4.json @@ -7,12 +7,8 @@ "CVE-2019-18618" ], "details": "Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p933-rhpc-9rpr/GHSA-p933-rhpc-9rpr.json b/advisories/unreviewed/2022/05/GHSA-p933-rhpc-9rpr/GHSA-p933-rhpc-9rpr.json index e5cb5314a2e..a6fd0a128a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-p933-rhpc-9rpr/GHSA-p933-rhpc-9rpr.json +++ b/advisories/unreviewed/2022/05/GHSA-p933-rhpc-9rpr/GHSA-p933-rhpc-9rpr.json @@ -7,12 +7,8 @@ "CVE-2020-15064" ], "details": "DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p9j7-3cxr-4hj8/GHSA-p9j7-3cxr-4hj8.json b/advisories/unreviewed/2022/05/GHSA-p9j7-3cxr-4hj8/GHSA-p9j7-3cxr-4hj8.json index 6355b63a4bf..2056d4f7694 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9j7-3cxr-4hj8/GHSA-p9j7-3cxr-4hj8.json +++ b/advisories/unreviewed/2022/05/GHSA-p9j7-3cxr-4hj8/GHSA-p9j7-3cxr-4hj8.json @@ -7,12 +7,8 @@ "CVE-2020-10925" ], "details": "This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloading of files via HTTPS. The issue results from the lack of proper validation of the certificate presented by the server. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-9647.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p9rf-vr4w-4gg7/GHSA-p9rf-vr4w-4gg7.json b/advisories/unreviewed/2022/05/GHSA-p9rf-vr4w-4gg7/GHSA-p9rf-vr4w-4gg7.json index 1d1ea940e37..42f84a28f03 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9rf-vr4w-4gg7/GHSA-p9rf-vr4w-4gg7.json +++ b/advisories/unreviewed/2022/05/GHSA-p9rf-vr4w-4gg7/GHSA-p9rf-vr4w-4gg7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "WEB", diff --git a/advisories/unreviewed/2022/05/GHSA-pc74-h374-5v7m/GHSA-pc74-h374-5v7m.json b/advisories/unreviewed/2022/05/GHSA-pc74-h374-5v7m/GHSA-pc74-h374-5v7m.json index 2c20d7bc550..7a3de8f3346 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc74-h374-5v7m/GHSA-pc74-h374-5v7m.json +++ b/advisories/unreviewed/2022/05/GHSA-pc74-h374-5v7m/GHSA-pc74-h374-5v7m.json @@ -7,12 +7,8 @@ "CVE-2020-10643" ], "details": "An authenticated remote attacker could use specially crafted URLs to send a victim using PI Vision 2019 mobile to a vulnerable web page due to a known issue in a third-party component.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pch4-wfwx-j685/GHSA-pch4-wfwx-j685.json b/advisories/unreviewed/2022/05/GHSA-pch4-wfwx-j685/GHSA-pch4-wfwx-j685.json index 3ebcd27572d..f0bc02572c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-pch4-wfwx-j685/GHSA-pch4-wfwx-j685.json +++ b/advisories/unreviewed/2022/05/GHSA-pch4-wfwx-j685/GHSA-pch4-wfwx-j685.json @@ -7,12 +7,8 @@ "CVE-2019-20033" ], "details": "On Aspire-derived NEC PBXes, including all versions of SV8100 devices, a set of documented, static login credentials may be used to access the DIM interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pf54-mm4h-p6g9/GHSA-pf54-mm4h-p6g9.json b/advisories/unreviewed/2022/05/GHSA-pf54-mm4h-p6g9/GHSA-pf54-mm4h-p6g9.json index f5de6ec8822..bdffc32725d 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf54-mm4h-p6g9/GHSA-pf54-mm4h-p6g9.json +++ b/advisories/unreviewed/2022/05/GHSA-pf54-mm4h-p6g9/GHSA-pf54-mm4h-p6g9.json @@ -7,12 +7,8 @@ "CVE-2020-4560" ], "details": "IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pj5q-9mff-24rh/GHSA-pj5q-9mff-24rh.json b/advisories/unreviewed/2022/05/GHSA-pj5q-9mff-24rh/GHSA-pj5q-9mff-24rh.json index fe69cc23dde..58d0855366b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj5q-9mff-24rh/GHSA-pj5q-9mff-24rh.json +++ b/advisories/unreviewed/2022/05/GHSA-pj5q-9mff-24rh/GHSA-pj5q-9mff-24rh.json @@ -7,12 +7,8 @@ "CVE-2020-3386" ], "details": "A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with a low-privileged account to bypass authorization on the API of an affected device. The vulnerability is due to insufficient authorization of certain API functions. An attacker could exploit this vulnerability by sending a crafted request to the API using low-privileged credentials. A successful exploit could allow the attacker to perform arbitrary actions through the REST API with administrative privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pjj8-w7g3-6hwq/GHSA-pjj8-w7g3-6hwq.json b/advisories/unreviewed/2022/05/GHSA-pjj8-w7g3-6hwq/GHSA-pjj8-w7g3-6hwq.json index ecbeba12890..d39373d2356 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjj8-w7g3-6hwq/GHSA-pjj8-w7g3-6hwq.json +++ b/advisories/unreviewed/2022/05/GHSA-pjj8-w7g3-6hwq/GHSA-pjj8-w7g3-6hwq.json @@ -7,12 +7,8 @@ "CVE-2020-5771" ], "details": "Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious backup archive.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pq8h-22gg-vpmw/GHSA-pq8h-22gg-vpmw.json b/advisories/unreviewed/2022/05/GHSA-pq8h-22gg-vpmw/GHSA-pq8h-22gg-vpmw.json index 47d30353779..e8db7889133 100644 --- a/advisories/unreviewed/2022/05/GHSA-pq8h-22gg-vpmw/GHSA-pq8h-22gg-vpmw.json +++ b/advisories/unreviewed/2022/05/GHSA-pq8h-22gg-vpmw/GHSA-pq8h-22gg-vpmw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pw7r-jv82-2wcp/GHSA-pw7r-jv82-2wcp.json b/advisories/unreviewed/2022/05/GHSA-pw7r-jv82-2wcp/GHSA-pw7r-jv82-2wcp.json index 753a3ab70ee..6ca8a8f6272 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw7r-jv82-2wcp/GHSA-pw7r-jv82-2wcp.json +++ b/advisories/unreviewed/2022/05/GHSA-pw7r-jv82-2wcp/GHSA-pw7r-jv82-2wcp.json @@ -7,12 +7,8 @@ "CVE-2020-1457" ], "details": "A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1425.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pw8m-2rrm-gmpm/GHSA-pw8m-2rrm-gmpm.json b/advisories/unreviewed/2022/05/GHSA-pw8m-2rrm-gmpm/GHSA-pw8m-2rrm-gmpm.json index dff692478c3..36ad3e22299 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw8m-2rrm-gmpm/GHSA-pw8m-2rrm-gmpm.json +++ b/advisories/unreviewed/2022/05/GHSA-pw8m-2rrm-gmpm/GHSA-pw8m-2rrm-gmpm.json @@ -7,12 +7,8 @@ "CVE-2020-6524" ], "details": "Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q373-mg22-49p8/GHSA-q373-mg22-49p8.json b/advisories/unreviewed/2022/05/GHSA-q373-mg22-49p8/GHSA-q373-mg22-49p8.json index d703f27f2fd..f10331bbb3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-q373-mg22-49p8/GHSA-q373-mg22-49p8.json +++ b/advisories/unreviewed/2022/05/GHSA-q373-mg22-49p8/GHSA-q373-mg22-49p8.json @@ -7,12 +7,8 @@ "CVE-2020-0248" ], "details": "In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-154627439", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q3h2-mgqx-8rg3/GHSA-q3h2-mgqx-8rg3.json b/advisories/unreviewed/2022/05/GHSA-q3h2-mgqx-8rg3/GHSA-q3h2-mgqx-8rg3.json index 9a27d3c4938..e9e38936f8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3h2-mgqx-8rg3/GHSA-q3h2-mgqx-8rg3.json +++ b/advisories/unreviewed/2022/05/GHSA-q3h2-mgqx-8rg3/GHSA-q3h2-mgqx-8rg3.json @@ -7,12 +7,8 @@ "CVE-2020-7519" ], "details": "A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to compromise a user account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q464-q2vj-24m2/GHSA-q464-q2vj-24m2.json b/advisories/unreviewed/2022/05/GHSA-q464-q2vj-24m2/GHSA-q464-q2vj-24m2.json index 37bbfa951bb..e781923e570 100644 --- a/advisories/unreviewed/2022/05/GHSA-q464-q2vj-24m2/GHSA-q464-q2vj-24m2.json +++ b/advisories/unreviewed/2022/05/GHSA-q464-q2vj-24m2/GHSA-q464-q2vj-24m2.json @@ -7,12 +7,8 @@ "CVE-2020-0554" ], "details": "Race condition in software installer for some Intel(R) Wireless Bluetooth(R) products on Windows* 7, 8.1 and 10 may allow an unprivileged user to potentially enable escalation of privilege via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q49w-v89m-366g/GHSA-q49w-v89m-366g.json b/advisories/unreviewed/2022/05/GHSA-q49w-v89m-366g/GHSA-q49w-v89m-366g.json index 0eaa26e0dda..65e950e722e 100644 --- a/advisories/unreviewed/2022/05/GHSA-q49w-v89m-366g/GHSA-q49w-v89m-366g.json +++ b/advisories/unreviewed/2022/05/GHSA-q49w-v89m-366g/GHSA-q49w-v89m-366g.json @@ -7,12 +7,8 @@ "CVE-2020-13291" ], "details": "In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q4rv-9jhx-3frp/GHSA-q4rv-9jhx-3frp.json b/advisories/unreviewed/2022/05/GHSA-q4rv-9jhx-3frp/GHSA-q4rv-9jhx-3frp.json index e109341c561..c06b62a158a 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4rv-9jhx-3frp/GHSA-q4rv-9jhx-3frp.json +++ b/advisories/unreviewed/2022/05/GHSA-q4rv-9jhx-3frp/GHSA-q4rv-9jhx-3frp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q562-x7c7-5fc9/GHSA-q562-x7c7-5fc9.json b/advisories/unreviewed/2022/05/GHSA-q562-x7c7-5fc9/GHSA-q562-x7c7-5fc9.json index b96db8ed4f7..5bb9989d40e 100644 --- a/advisories/unreviewed/2022/05/GHSA-q562-x7c7-5fc9/GHSA-q562-x7c7-5fc9.json +++ b/advisories/unreviewed/2022/05/GHSA-q562-x7c7-5fc9/GHSA-q562-x7c7-5fc9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q58r-gqw4-9cvh/GHSA-q58r-gqw4-9cvh.json b/advisories/unreviewed/2022/05/GHSA-q58r-gqw4-9cvh/GHSA-q58r-gqw4-9cvh.json index 3a3f3e5fee7..fae24baaab6 100644 --- a/advisories/unreviewed/2022/05/GHSA-q58r-gqw4-9cvh/GHSA-q58r-gqw4-9cvh.json +++ b/advisories/unreviewed/2022/05/GHSA-q58r-gqw4-9cvh/GHSA-q58r-gqw4-9cvh.json @@ -7,12 +7,8 @@ "CVE-2020-4542" ], "details": "IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 183046.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q6v8-jc2v-7p36/GHSA-q6v8-jc2v-7p36.json b/advisories/unreviewed/2022/05/GHSA-q6v8-jc2v-7p36/GHSA-q6v8-jc2v-7p36.json index 2f788a76323..83a79efe3ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6v8-jc2v-7p36/GHSA-q6v8-jc2v-7p36.json +++ b/advisories/unreviewed/2022/05/GHSA-q6v8-jc2v-7p36/GHSA-q6v8-jc2v-7p36.json @@ -7,12 +7,8 @@ "CVE-2020-12106" ], "details": "The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing credentials of the Administrator account or connect the product to a rogue access point.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q6xw-gw5p-2f92/GHSA-q6xw-gw5p-2f92.json b/advisories/unreviewed/2022/05/GHSA-q6xw-gw5p-2f92/GHSA-q6xw-gw5p-2f92.json index 880c29362d6..211a2bb6882 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6xw-gw5p-2f92/GHSA-q6xw-gw5p-2f92.json +++ b/advisories/unreviewed/2022/05/GHSA-q6xw-gw5p-2f92/GHSA-q6xw-gw5p-2f92.json @@ -7,12 +7,8 @@ "CVE-2020-0238" ], "details": "In updatePreferenceIntents of AccountTypePreferenceLoader, there is a possible confused deputy attack due to a race condition. This could lead to local escalation of privilege and launching privileged activities with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-8.0Android ID: A-150946634", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q7wx-433j-27hv/GHSA-q7wx-433j-27hv.json b/advisories/unreviewed/2022/05/GHSA-q7wx-433j-27hv/GHSA-q7wx-433j-27hv.json index 8fb39acb485..8c6c6a81a0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7wx-433j-27hv/GHSA-q7wx-433j-27hv.json +++ b/advisories/unreviewed/2022/05/GHSA-q7wx-433j-27hv/GHSA-q7wx-433j-27hv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q8xc-9j26-pwf8/GHSA-q8xc-9j26-pwf8.json b/advisories/unreviewed/2022/05/GHSA-q8xc-9j26-pwf8/GHSA-q8xc-9j26-pwf8.json index 8e3063042f5..79ad1bed340 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8xc-9j26-pwf8/GHSA-q8xc-9j26-pwf8.json +++ b/advisories/unreviewed/2022/05/GHSA-q8xc-9j26-pwf8/GHSA-q8xc-9j26-pwf8.json @@ -7,12 +7,8 @@ "CVE-2020-14487" ], "details": "OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly turned off this account, which may allow an attacker to login and execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q9r7-c339-rwv2/GHSA-q9r7-c339-rwv2.json b/advisories/unreviewed/2022/05/GHSA-q9r7-c339-rwv2/GHSA-q9r7-c339-rwv2.json index 2e35e127d2f..93973b8b7a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9r7-c339-rwv2/GHSA-q9r7-c339-rwv2.json +++ b/advisories/unreviewed/2022/05/GHSA-q9r7-c339-rwv2/GHSA-q9r7-c339-rwv2.json @@ -7,12 +7,8 @@ "CVE-2020-13919" ], "details": "emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to achieve command injection via a crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and T710s devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qfqq-45wx-88xc/GHSA-qfqq-45wx-88xc.json b/advisories/unreviewed/2022/05/GHSA-qfqq-45wx-88xc/GHSA-qfqq-45wx-88xc.json index d487614bc3a..7096ecd2ad3 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfqq-45wx-88xc/GHSA-qfqq-45wx-88xc.json +++ b/advisories/unreviewed/2022/05/GHSA-qfqq-45wx-88xc/GHSA-qfqq-45wx-88xc.json @@ -7,12 +7,8 @@ "CVE-2020-6529" ], "details": "Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qfr6-gxpj-wr4q/GHSA-qfr6-gxpj-wr4q.json b/advisories/unreviewed/2022/05/GHSA-qfr6-gxpj-wr4q/GHSA-qfr6-gxpj-wr4q.json index dbe84e9ea58..3a5c78bbca7 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfr6-gxpj-wr4q/GHSA-qfr6-gxpj-wr4q.json +++ b/advisories/unreviewed/2022/05/GHSA-qfr6-gxpj-wr4q/GHSA-qfr6-gxpj-wr4q.json @@ -7,12 +7,8 @@ "CVE-2020-11624" ], "details": "An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. They do not require users to change the default password for the admin account. They only show a pop-up window suggesting a change but there's no enforcement. An administrator can click Cancel and proceed to use the device without changing the password. Additionally, they disclose the default username within the login.js script. Since many attacks for IoT devices, including malware and exploits, are based on the usage of default credentials, it makes these cameras an easy target for malicious actors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qg5g-q63w-qf8c/GHSA-qg5g-q63w-qf8c.json b/advisories/unreviewed/2022/05/GHSA-qg5g-q63w-qf8c/GHSA-qg5g-q63w-qf8c.json index 1ac48af6f30..7f48dfa21df 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg5g-q63w-qf8c/GHSA-qg5g-q63w-qf8c.json +++ b/advisories/unreviewed/2022/05/GHSA-qg5g-q63w-qf8c/GHSA-qg5g-q63w-qf8c.json @@ -7,12 +7,8 @@ "CVE-2020-4328" ], "details": "IBM Financial Transaction Manager 3.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 177839.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qj8p-w7h4-v2qg/GHSA-qj8p-w7h4-v2qg.json b/advisories/unreviewed/2022/05/GHSA-qj8p-w7h4-v2qg/GHSA-qj8p-w7h4-v2qg.json index 8a4d8c9c1ff..4bf46d30689 100644 --- a/advisories/unreviewed/2022/05/GHSA-qj8p-w7h4-v2qg/GHSA-qj8p-w7h4-v2qg.json +++ b/advisories/unreviewed/2022/05/GHSA-qj8p-w7h4-v2qg/GHSA-qj8p-w7h4-v2qg.json @@ -7,12 +7,8 @@ "CVE-2020-9079" ], "details": "FusionSphere OpenStack 8.0.0 have a protection mechanism failure vulnerability. The product incorrectly uses a protection mechanism. An attacker has to find a way to exploit the vulnerability to conduct directed attacks against the affected product.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qjcg-gr4j-p5wc/GHSA-qjcg-gr4j-p5wc.json b/advisories/unreviewed/2022/05/GHSA-qjcg-gr4j-p5wc/GHSA-qjcg-gr4j-p5wc.json index d424ff593a1..ed3469cbb46 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjcg-gr4j-p5wc/GHSA-qjcg-gr4j-p5wc.json +++ b/advisories/unreviewed/2022/05/GHSA-qjcg-gr4j-p5wc/GHSA-qjcg-gr4j-p5wc.json @@ -7,12 +7,8 @@ "CVE-2017-18923" ], "details": "beroNet VoIP Gateways before 3.0.16 have a PHP script that allows downloading arbitrary files, including ones with credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qmpw-v8j3-m6wq/GHSA-qmpw-v8j3-m6wq.json b/advisories/unreviewed/2022/05/GHSA-qmpw-v8j3-m6wq/GHSA-qmpw-v8j3-m6wq.json index 7d397954ff8..40da000bcaa 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmpw-v8j3-m6wq/GHSA-qmpw-v8j3-m6wq.json +++ b/advisories/unreviewed/2022/05/GHSA-qmpw-v8j3-m6wq/GHSA-qmpw-v8j3-m6wq.json @@ -7,12 +7,8 @@ "CVE-2020-9528" ], "details": "Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions of Internet of Things devices, suffers from cryptographic issues that allow remote attackers to access user session data, as demonstrated by eavesdropping on user video/audio streams, capturing credentials, and compromising devices. This affects products marketed under the following brand names: Accfly, Alptop, Anlink, Besdersec, BOAVISION, COOAU, CPVAN, Ctronics, D3D Security, Dericam, Elex System, Elite Security, ENSTER, ePGes, Escam, FLOUREON, GENBOLT, Hongjingtian (HJT), ICAMI, Iegeek, Jecurity, Jennov, KKMoon, LEFTEK, Loosafe, Luowice, Nesuniq, Nettoly, ProElite, QZT, Royallite, SDETER, SV3C, SY2L, Tenvis, ThinkValue, TOMLOV, TPTEK, WGCC, and ZILINK.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qp4w-65rx-2h9g/GHSA-qp4w-65rx-2h9g.json b/advisories/unreviewed/2022/05/GHSA-qp4w-65rx-2h9g/GHSA-qp4w-65rx-2h9g.json index efb004e0370..89a22cbeb6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp4w-65rx-2h9g/GHSA-qp4w-65rx-2h9g.json +++ b/advisories/unreviewed/2022/05/GHSA-qp4w-65rx-2h9g/GHSA-qp4w-65rx-2h9g.json @@ -7,12 +7,8 @@ "CVE-2020-16167" ], "details": "Temi Launcher OS 11969 through 13146 has Missing Authentication for a Critical Function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qp9w-fqwx-r4j3/GHSA-qp9w-fqwx-r4j3.json b/advisories/unreviewed/2022/05/GHSA-qp9w-fqwx-r4j3/GHSA-qp9w-fqwx-r4j3.json index 50be5796f97..3cf97355761 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp9w-fqwx-r4j3/GHSA-qp9w-fqwx-r4j3.json +++ b/advisories/unreviewed/2022/05/GHSA-qp9w-fqwx-r4j3/GHSA-qp9w-fqwx-r4j3.json @@ -7,12 +7,8 @@ "CVE-2020-14313" ], "details": "An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories within any namespace.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qpcx-m7r7-r4x6/GHSA-qpcx-m7r7-r4x6.json b/advisories/unreviewed/2022/05/GHSA-qpcx-m7r7-r4x6/GHSA-qpcx-m7r7-r4x6.json index 55367ee5b5e..3a4a4f30d54 100644 --- a/advisories/unreviewed/2022/05/GHSA-qpcx-m7r7-r4x6/GHSA-qpcx-m7r7-r4x6.json +++ b/advisories/unreviewed/2022/05/GHSA-qpcx-m7r7-r4x6/GHSA-qpcx-m7r7-r4x6.json @@ -7,12 +7,8 @@ "CVE-2020-9686" ], "details": "Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qpfx-fjm2-5crf/GHSA-qpfx-fjm2-5crf.json b/advisories/unreviewed/2022/05/GHSA-qpfx-fjm2-5crf/GHSA-qpfx-fjm2-5crf.json index 8d23a55889f..cfd4f28e46e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qpfx-fjm2-5crf/GHSA-qpfx-fjm2-5crf.json +++ b/advisories/unreviewed/2022/05/GHSA-qpfx-fjm2-5crf/GHSA-qpfx-fjm2-5crf.json @@ -7,12 +7,8 @@ "CVE-2020-15631" ], "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 1.04B03_HOTFIX WiFi extenders. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the HNAP service, which listens on TCP port 80 by default. When parsing the SOAPAction header, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-10084.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qpq7-cvfh-63c4/GHSA-qpq7-cvfh-63c4.json b/advisories/unreviewed/2022/05/GHSA-qpq7-cvfh-63c4/GHSA-qpq7-cvfh-63c4.json index 59a3f6f04ee..7c4f2a2fff5 100644 --- a/advisories/unreviewed/2022/05/GHSA-qpq7-cvfh-63c4/GHSA-qpq7-cvfh-63c4.json +++ b/advisories/unreviewed/2022/05/GHSA-qpq7-cvfh-63c4/GHSA-qpq7-cvfh-63c4.json @@ -7,12 +7,8 @@ "CVE-2020-4447" ], "details": "IBM FileNet Content Manager 5.5.3 and 5.5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 181227.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qrgc-2qmf-qw4g/GHSA-qrgc-2qmf-qw4g.json b/advisories/unreviewed/2022/05/GHSA-qrgc-2qmf-qw4g/GHSA-qrgc-2qmf-qw4g.json index 2e253be92df..0b529d1976c 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrgc-2qmf-qw4g/GHSA-qrgc-2qmf-qw4g.json +++ b/advisories/unreviewed/2022/05/GHSA-qrgc-2qmf-qw4g/GHSA-qrgc-2qmf-qw4g.json @@ -7,12 +7,8 @@ "CVE-2020-12739" ], "details": "A vulnerability in the Fanuc i Series CNC (0i-MD and 0i Mate-MD) could allow an unauthenticated, remote attacker to cause an affected CNC to become inaccessible to other devices. The vulnerability is due to improper design or implementation of the Ethernet communication modules of the CNC. An attacker could exploit this vulnerability by sending a series of malformed packets to port 8193/tcp, resulting in a denial of service (DoS) condition, where the affected device would require a manual power cycle of the CNC to recover.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrx2-jhp2-f6v8/GHSA-qrx2-jhp2-f6v8.json b/advisories/unreviewed/2022/05/GHSA-qrx2-jhp2-f6v8/GHSA-qrx2-jhp2-f6v8.json index da5cd77bb46..4500470f78a 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrx2-jhp2-f6v8/GHSA-qrx2-jhp2-f6v8.json +++ b/advisories/unreviewed/2022/05/GHSA-qrx2-jhp2-f6v8/GHSA-qrx2-jhp2-f6v8.json @@ -7,12 +7,8 @@ "CVE-2020-3688" ], "details": "Possible buffer overflow while parsing mp4 clip with corrupted sample atoms due to improper validation of index in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Kamorta, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA6574AU, QCM2150, QCS405, QCS605, QM215, Rennell, SA6155P, Saipan, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qx9j-q623-p5fh/GHSA-qx9j-q623-p5fh.json b/advisories/unreviewed/2022/05/GHSA-qx9j-q623-p5fh/GHSA-qx9j-q623-p5fh.json index c4bafed5043..e59f0ca3cd4 100644 --- a/advisories/unreviewed/2022/05/GHSA-qx9j-q623-p5fh/GHSA-qx9j-q623-p5fh.json +++ b/advisories/unreviewed/2022/05/GHSA-qx9j-q623-p5fh/GHSA-qx9j-q623-p5fh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r2p6-cvv5-qcq5/GHSA-r2p6-cvv5-qcq5.json b/advisories/unreviewed/2022/05/GHSA-r2p6-cvv5-qcq5/GHSA-r2p6-cvv5-qcq5.json index 88e0865639e..602e0378cd0 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2p6-cvv5-qcq5/GHSA-r2p6-cvv5-qcq5.json +++ b/advisories/unreviewed/2022/05/GHSA-r2p6-cvv5-qcq5/GHSA-r2p6-cvv5-qcq5.json @@ -7,12 +7,8 @@ "CVE-2020-15659" ], "details": "Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r38f-qc7w-78mg/GHSA-r38f-qc7w-78mg.json b/advisories/unreviewed/2022/05/GHSA-r38f-qc7w-78mg/GHSA-r38f-qc7w-78mg.json index 2637e34d70d..1ed0d69fc68 100644 --- a/advisories/unreviewed/2022/05/GHSA-r38f-qc7w-78mg/GHSA-r38f-qc7w-78mg.json +++ b/advisories/unreviewed/2022/05/GHSA-r38f-qc7w-78mg/GHSA-r38f-qc7w-78mg.json @@ -7,12 +7,8 @@ "CVE-2019-17339" ], "details": "The VirtualRouter component of TIBCO Software Inc.'s TIBCO Silver Fabric contains a vulnerability that theoretically allows an attacker to inject scripts via URLs. The attacker could theoretically social engineer an authenticated user into submitting the URL, thus executing the script on the affected system with the privileges of the user. Affected releases are TIBCO Software Inc.'s TIBCO Silver Fabric: versions 6.0.0 and below.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r4mf-xwrc-457g/GHSA-r4mf-xwrc-457g.json b/advisories/unreviewed/2022/05/GHSA-r4mf-xwrc-457g/GHSA-r4mf-xwrc-457g.json index 6d19c10cb95..43e04b9924a 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4mf-xwrc-457g/GHSA-r4mf-xwrc-457g.json +++ b/advisories/unreviewed/2022/05/GHSA-r4mf-xwrc-457g/GHSA-r4mf-xwrc-457g.json @@ -7,12 +7,8 @@ "CVE-2020-0108" ], "details": "In postNotification of ServiceRecord.java, there is a possible bypass of foreground process restrictions due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.1 Android-9Android ID: A-140108616", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r4wq-566g-h3jw/GHSA-r4wq-566g-h3jw.json b/advisories/unreviewed/2022/05/GHSA-r4wq-566g-h3jw/GHSA-r4wq-566g-h3jw.json index cd0c2420329..6dac577fc32 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4wq-566g-h3jw/GHSA-r4wq-566g-h3jw.json +++ b/advisories/unreviewed/2022/05/GHSA-r4wq-566g-h3jw/GHSA-r4wq-566g-h3jw.json @@ -7,12 +7,8 @@ "CVE-2020-6521" ], "details": "Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r542-g4pm-8f6m/GHSA-r542-g4pm-8f6m.json b/advisories/unreviewed/2022/05/GHSA-r542-g4pm-8f6m/GHSA-r542-g4pm-8f6m.json index 0a64591dd62..dcfa608d2a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-r542-g4pm-8f6m/GHSA-r542-g4pm-8f6m.json +++ b/advisories/unreviewed/2022/05/GHSA-r542-g4pm-8f6m/GHSA-r542-g4pm-8f6m.json @@ -7,12 +7,8 @@ "CVE-2020-4319" ], "details": "IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 LTS, and 9.1 CD could allow under special circumstances, an authenticated user to obtain sensitive information due to a data leak from an error message within the pre-v7 pubsub logic. IBM X-Force ID: 177402.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r54p-7rgw-qq7j/GHSA-r54p-7rgw-qq7j.json b/advisories/unreviewed/2022/05/GHSA-r54p-7rgw-qq7j/GHSA-r54p-7rgw-qq7j.json index 6c0caff01b1..e225e451921 100644 --- a/advisories/unreviewed/2022/05/GHSA-r54p-7rgw-qq7j/GHSA-r54p-7rgw-qq7j.json +++ b/advisories/unreviewed/2022/05/GHSA-r54p-7rgw-qq7j/GHSA-r54p-7rgw-qq7j.json @@ -7,12 +7,8 @@ "CVE-2020-6535" ], "details": "Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r68r-r23h-fpvc/GHSA-r68r-r23h-fpvc.json b/advisories/unreviewed/2022/05/GHSA-r68r-r23h-fpvc/GHSA-r68r-r23h-fpvc.json index 01ae40a8874..e8f6e4bd0b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-r68r-r23h-fpvc/GHSA-r68r-r23h-fpvc.json +++ b/advisories/unreviewed/2022/05/GHSA-r68r-r23h-fpvc/GHSA-r68r-r23h-fpvc.json @@ -7,12 +7,8 @@ "CVE-2020-13288" ], "details": "In GitLab before 13.0.12, 13.1.6, and 13.2.3, a stored XSS vulnerability exists in the CI/CD Jobs page", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r6p7-w5c2-g76j/GHSA-r6p7-w5c2-g76j.json b/advisories/unreviewed/2022/05/GHSA-r6p7-w5c2-g76j/GHSA-r6p7-w5c2-g76j.json index 858175b4fea..c0318368307 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6p7-w5c2-g76j/GHSA-r6p7-w5c2-g76j.json +++ b/advisories/unreviewed/2022/05/GHSA-r6p7-w5c2-g76j/GHSA-r6p7-w5c2-g76j.json @@ -7,12 +7,8 @@ "CVE-2020-13283" ], "details": "For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issues list via milestone title.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r78f-c926-j84x/GHSA-r78f-c926-j84x.json b/advisories/unreviewed/2022/05/GHSA-r78f-c926-j84x/GHSA-r78f-c926-j84x.json index d8599fabe53..71d50717c0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-r78f-c926-j84x/GHSA-r78f-c926-j84x.json +++ b/advisories/unreviewed/2022/05/GHSA-r78f-c926-j84x/GHSA-r78f-c926-j84x.json @@ -7,12 +7,8 @@ "CVE-2020-9403" ], "details": "In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in a recoverable format, and may be retrieved by any user with access to the PACTware workstation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r7jq-2wvx-j3g6/GHSA-r7jq-2wvx-j3g6.json b/advisories/unreviewed/2022/05/GHSA-r7jq-2wvx-j3g6/GHSA-r7jq-2wvx-j3g6.json index 039ecd2273e..30a68ac70ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7jq-2wvx-j3g6/GHSA-r7jq-2wvx-j3g6.json +++ b/advisories/unreviewed/2022/05/GHSA-r7jq-2wvx-j3g6/GHSA-r7jq-2wvx-j3g6.json @@ -7,12 +7,8 @@ "CVE-2020-7516" ], "details": "A CWE-316: Cleartext Storage of Sensitive Information in Memory vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker access to login credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rc5j-fh2q-crhv/GHSA-rc5j-fh2q-crhv.json b/advisories/unreviewed/2022/05/GHSA-rc5j-fh2q-crhv/GHSA-rc5j-fh2q-crhv.json index 2d18d77d68c..3fe60660ce2 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc5j-fh2q-crhv/GHSA-rc5j-fh2q-crhv.json +++ b/advisories/unreviewed/2022/05/GHSA-rc5j-fh2q-crhv/GHSA-rc5j-fh2q-crhv.json @@ -7,12 +7,8 @@ "CVE-2020-10918" ], "details": "This vulnerability allows remote attackers to bypass authentication on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the authentication mechanism. The issue is due to insufficient authentication on post-authentication requests. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from unauthenticated users. Was ZDI-CAN-10182.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rc74-rr58-4f4g/GHSA-rc74-rr58-4f4g.json b/advisories/unreviewed/2022/05/GHSA-rc74-rr58-4f4g/GHSA-rc74-rr58-4f4g.json index 54d55488f35..cac2cdc6371 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc74-rr58-4f4g/GHSA-rc74-rr58-4f4g.json +++ b/advisories/unreviewed/2022/05/GHSA-rc74-rr58-4f4g/GHSA-rc74-rr58-4f4g.json @@ -7,12 +7,8 @@ "CVE-2020-3700" ], "details": "Possible out of bounds read due to a missing bounds check and could lead to local information disclosure in the wifi driver with no additional execution privileges needed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8053, APQ8096AU, IPQ4019, IPQ8064, IPQ8074, MDM9607, MSM8909W, MSM8996AU, QCA6574AU, QCA9531, QCA9558, QCA9980, SC8180X, SDM439, SDX55, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rc98-2856-g86f/GHSA-rc98-2856-g86f.json b/advisories/unreviewed/2022/05/GHSA-rc98-2856-g86f/GHSA-rc98-2856-g86f.json index cc387fe8eba..54a00d1ad9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc98-2856-g86f/GHSA-rc98-2856-g86f.json +++ b/advisories/unreviewed/2022/05/GHSA-rc98-2856-g86f/GHSA-rc98-2856-g86f.json @@ -7,12 +7,8 @@ "CVE-2020-16087" ], "details": "An issue was discovered in Zalo.exe in VNG Zalo Desktop 19.8.1.0. An attacker can run arbitrary commands on a remote Windows machine running the Zalo client by sending the user of the device a crafted file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rcrp-5hwf-f7f2/GHSA-rcrp-5hwf-f7f2.json b/advisories/unreviewed/2022/05/GHSA-rcrp-5hwf-f7f2/GHSA-rcrp-5hwf-f7f2.json index 4e3f9c98057..eda72adfc60 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcrp-5hwf-f7f2/GHSA-rcrp-5hwf-f7f2.json +++ b/advisories/unreviewed/2022/05/GHSA-rcrp-5hwf-f7f2/GHSA-rcrp-5hwf-f7f2.json @@ -7,12 +7,8 @@ "CVE-2017-18112" ], "details": "Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability in the logging feature. The affected versions are before version 4.8.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rf45-pfxr-h83v/GHSA-rf45-pfxr-h83v.json b/advisories/unreviewed/2022/05/GHSA-rf45-pfxr-h83v/GHSA-rf45-pfxr-h83v.json index 1d02bb09acc..631a8d2e19f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf45-pfxr-h83v/GHSA-rf45-pfxr-h83v.json +++ b/advisories/unreviewed/2022/05/GHSA-rf45-pfxr-h83v/GHSA-rf45-pfxr-h83v.json @@ -7,12 +7,8 @@ "CVE-2020-15820" ], "details": "In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rf94-4gm4-mj5j/GHSA-rf94-4gm4-mj5j.json b/advisories/unreviewed/2022/05/GHSA-rf94-4gm4-mj5j/GHSA-rf94-4gm4-mj5j.json index 3cd5e7c0d13..85c0aac2ad7 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf94-4gm4-mj5j/GHSA-rf94-4gm4-mj5j.json +++ b/advisories/unreviewed/2022/05/GHSA-rf94-4gm4-mj5j/GHSA-rf94-4gm4-mj5j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rg33-3c9v-cfv6/GHSA-rg33-3c9v-cfv6.json b/advisories/unreviewed/2022/05/GHSA-rg33-3c9v-cfv6/GHSA-rg33-3c9v-cfv6.json index ecfd936222e..28e301fdb84 100644 --- a/advisories/unreviewed/2022/05/GHSA-rg33-3c9v-cfv6/GHSA-rg33-3c9v-cfv6.json +++ b/advisories/unreviewed/2022/05/GHSA-rg33-3c9v-cfv6/GHSA-rg33-3c9v-cfv6.json @@ -7,12 +7,8 @@ "CVE-2020-3698" ], "details": "Out of bound write while QoS DSCP mapping due to improper input validation for data received from association response frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, Nicobar, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCM2150, QCN7605, QCS405, QCS605, QM215, SA6155P, Saipan, SC8180X, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SDX55, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rh9f-46xr-5c59/GHSA-rh9f-46xr-5c59.json b/advisories/unreviewed/2022/05/GHSA-rh9f-46xr-5c59/GHSA-rh9f-46xr-5c59.json index 04feb51c7c0..2b45002226c 100644 --- a/advisories/unreviewed/2022/05/GHSA-rh9f-46xr-5c59/GHSA-rh9f-46xr-5c59.json +++ b/advisories/unreviewed/2022/05/GHSA-rh9f-46xr-5c59/GHSA-rh9f-46xr-5c59.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rjwj-p23j-79pm/GHSA-rjwj-p23j-79pm.json b/advisories/unreviewed/2022/05/GHSA-rjwj-p23j-79pm/GHSA-rjwj-p23j-79pm.json index 5d764c2ad9e..7be718754ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjwj-p23j-79pm/GHSA-rjwj-p23j-79pm.json +++ b/advisories/unreviewed/2022/05/GHSA-rjwj-p23j-79pm/GHSA-rjwj-p23j-79pm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rqf5-hjhw-r93g/GHSA-rqf5-hjhw-r93g.json b/advisories/unreviewed/2022/05/GHSA-rqf5-hjhw-r93g/GHSA-rqf5-hjhw-r93g.json index fe0ed0c6075..1b14ff8a40c 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqf5-hjhw-r93g/GHSA-rqf5-hjhw-r93g.json +++ b/advisories/unreviewed/2022/05/GHSA-rqf5-hjhw-r93g/GHSA-rqf5-hjhw-r93g.json @@ -7,12 +7,8 @@ "CVE-2020-8326" ], "details": "An unquoted service path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rvqm-8pmm-p6m6/GHSA-rvqm-8pmm-p6m6.json b/advisories/unreviewed/2022/05/GHSA-rvqm-8pmm-p6m6/GHSA-rvqm-8pmm-p6m6.json index 9e767750063..5a26e575d26 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvqm-8pmm-p6m6/GHSA-rvqm-8pmm-p6m6.json +++ b/advisories/unreviewed/2022/05/GHSA-rvqm-8pmm-p6m6/GHSA-rvqm-8pmm-p6m6.json @@ -7,12 +7,8 @@ "CVE-2020-12287" ], "details": "Incorrect permissions in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2020.2 may allow an authenticated user to potentially enable escalation of privilege via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rx8q-gf7p-3fvp/GHSA-rx8q-gf7p-3fvp.json b/advisories/unreviewed/2022/05/GHSA-rx8q-gf7p-3fvp/GHSA-rx8q-gf7p-3fvp.json index aa13d33c714..bd824ed7f50 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx8q-gf7p-3fvp/GHSA-rx8q-gf7p-3fvp.json +++ b/advisories/unreviewed/2022/05/GHSA-rx8q-gf7p-3fvp/GHSA-rx8q-gf7p-3fvp.json @@ -7,12 +7,8 @@ "CVE-2020-7356" ], "details": "CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and execute SYSTEM commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v343-8p34-76p3/GHSA-v343-8p34-76p3.json b/advisories/unreviewed/2022/05/GHSA-v343-8p34-76p3/GHSA-v343-8p34-76p3.json index f2f3f4e1198..30de72e300f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v343-8p34-76p3/GHSA-v343-8p34-76p3.json +++ b/advisories/unreviewed/2022/05/GHSA-v343-8p34-76p3/GHSA-v343-8p34-76p3.json @@ -7,12 +7,8 @@ "CVE-2020-11933" ], "details": "cloud-init as managed by snapd on Ubuntu Core 16 and Ubuntu Core 18 devices was run without restrictions on every boot, which a physical attacker could exploit by crafting cloud-init user-data/meta-data via external media to perform arbitrary changes on the device to bypass intended security mechanisms such as full disk encryption. This issue did not affect traditional Ubuntu systems. Fixed in snapd version 2.45.2, revision 8539 and core version 2.45.2, revision 9659.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v482-3xvq-fffx/GHSA-v482-3xvq-fffx.json b/advisories/unreviewed/2022/05/GHSA-v482-3xvq-fffx/GHSA-v482-3xvq-fffx.json index da90d6f4167..5c002ae7454 100644 --- a/advisories/unreviewed/2022/05/GHSA-v482-3xvq-fffx/GHSA-v482-3xvq-fffx.json +++ b/advisories/unreviewed/2022/05/GHSA-v482-3xvq-fffx/GHSA-v482-3xvq-fffx.json @@ -7,12 +7,8 @@ "CVE-2020-16192" ], "details": "LimeSurvey 4.3.2 allows reflected XSS because application/controllers/LSBaseController.php lacks code to validate parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v675-cj9m-348p/GHSA-v675-cj9m-348p.json b/advisories/unreviewed/2022/05/GHSA-v675-cj9m-348p/GHSA-v675-cj9m-348p.json index 4f8722db3ba..92bb5ce582c 100644 --- a/advisories/unreviewed/2022/05/GHSA-v675-cj9m-348p/GHSA-v675-cj9m-348p.json +++ b/advisories/unreviewed/2022/05/GHSA-v675-cj9m-348p/GHSA-v675-cj9m-348p.json @@ -7,12 +7,8 @@ "CVE-2020-17478" ], "details": "ECDSA/EC/Point.pm in Crypt::Perl before 0.33 does not properly consider timing attacks against the EC point multiplication algorithm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v752-pfhq-9hm8/GHSA-v752-pfhq-9hm8.json b/advisories/unreviewed/2022/05/GHSA-v752-pfhq-9hm8/GHSA-v752-pfhq-9hm8.json index cba8b4d6399..bac56dee8b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-v752-pfhq-9hm8/GHSA-v752-pfhq-9hm8.json +++ b/advisories/unreviewed/2022/05/GHSA-v752-pfhq-9hm8/GHSA-v752-pfhq-9hm8.json @@ -7,12 +7,8 @@ "CVE-2020-15057" ], "details": "TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to denial-of-service the device via long input values.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v7pf-gv4p-63p2/GHSA-v7pf-gv4p-63p2.json b/advisories/unreviewed/2022/05/GHSA-v7pf-gv4p-63p2/GHSA-v7pf-gv4p-63p2.json index b128101763d..3fca5acccab 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7pf-gv4p-63p2/GHSA-v7pf-gv4p-63p2.json +++ b/advisories/unreviewed/2022/05/GHSA-v7pf-gv4p-63p2/GHSA-v7pf-gv4p-63p2.json @@ -7,12 +7,8 @@ "CVE-2020-6517" ], "details": "Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v7x5-v6p6-2wvj/GHSA-v7x5-v6p6-2wvj.json b/advisories/unreviewed/2022/05/GHSA-v7x5-v6p6-2wvj/GHSA-v7x5-v6p6-2wvj.json index 2ca002f34cd..119efec5276 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7x5-v6p6-2wvj/GHSA-v7x5-v6p6-2wvj.json +++ b/advisories/unreviewed/2022/05/GHSA-v7x5-v6p6-2wvj/GHSA-v7x5-v6p6-2wvj.json @@ -7,12 +7,8 @@ "CVE-2019-14100" ], "details": "Register write via debugfs is disabled by default to prevent register writing via debugfs. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9206, MDM9207C, MDM9607, Nicobar, QCS405, SA6155P, SC8180X, SDX55, SM8150", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v8ph-72jw-j36g/GHSA-v8ph-72jw-j36g.json b/advisories/unreviewed/2022/05/GHSA-v8ph-72jw-j36g/GHSA-v8ph-72jw-j36g.json index 34f797aa27a..061f79d564f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8ph-72jw-j36g/GHSA-v8ph-72jw-j36g.json +++ b/advisories/unreviewed/2022/05/GHSA-v8ph-72jw-j36g/GHSA-v8ph-72jw-j36g.json @@ -7,12 +7,8 @@ "CVE-2020-17452" ], "details": "flatCore before 1.5.7 allows upload and execution of a .php file by an admin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v94m-px3x-gg3c/GHSA-v94m-px3x-gg3c.json b/advisories/unreviewed/2022/05/GHSA-v94m-px3x-gg3c/GHSA-v94m-px3x-gg3c.json index 353af29248a..abbcd9fd736 100644 --- a/advisories/unreviewed/2022/05/GHSA-v94m-px3x-gg3c/GHSA-v94m-px3x-gg3c.json +++ b/advisories/unreviewed/2022/05/GHSA-v94m-px3x-gg3c/GHSA-v94m-px3x-gg3c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v9h6-785v-rc7j/GHSA-v9h6-785v-rc7j.json b/advisories/unreviewed/2022/05/GHSA-v9h6-785v-rc7j/GHSA-v9h6-785v-rc7j.json index 1bd18e7fcc5..fbf508833b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9h6-785v-rc7j/GHSA-v9h6-785v-rc7j.json +++ b/advisories/unreviewed/2022/05/GHSA-v9h6-785v-rc7j/GHSA-v9h6-785v-rc7j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vfpj-rcwj-86vm/GHSA-vfpj-rcwj-86vm.json b/advisories/unreviewed/2022/05/GHSA-vfpj-rcwj-86vm/GHSA-vfpj-rcwj-86vm.json index da5009a7e02..25d56023a8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfpj-rcwj-86vm/GHSA-vfpj-rcwj-86vm.json +++ b/advisories/unreviewed/2022/05/GHSA-vfpj-rcwj-86vm/GHSA-vfpj-rcwj-86vm.json @@ -7,12 +7,8 @@ "CVE-2020-17489" ], "details": "An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible for a brief moment upon a logout. (If the password were never shown in cleartext, only the password length is revealed.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vghr-3w2c-h96p/GHSA-vghr-3w2c-h96p.json b/advisories/unreviewed/2022/05/GHSA-vghr-3w2c-h96p/GHSA-vghr-3w2c-h96p.json index 4847b8ae435..a9d49bc79d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-vghr-3w2c-h96p/GHSA-vghr-3w2c-h96p.json +++ b/advisories/unreviewed/2022/05/GHSA-vghr-3w2c-h96p/GHSA-vghr-3w2c-h96p.json @@ -7,12 +7,8 @@ "CVE-2020-13916" ], "details": "A stack buffer overflow in webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute code via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and T710s devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vhcp-vwq7-69fw/GHSA-vhcp-vwq7-69fw.json b/advisories/unreviewed/2022/05/GHSA-vhcp-vwq7-69fw/GHSA-vhcp-vwq7-69fw.json index 2399d0f148d..1880d4c480d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhcp-vwq7-69fw/GHSA-vhcp-vwq7-69fw.json +++ b/advisories/unreviewed/2022/05/GHSA-vhcp-vwq7-69fw/GHSA-vhcp-vwq7-69fw.json @@ -7,12 +7,8 @@ "CVE-2020-15824" ], "details": "In JetBrains Kotlin before 1.4.0, there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vhp9-5mw9-c7wp/GHSA-vhp9-5mw9-c7wp.json b/advisories/unreviewed/2022/05/GHSA-vhp9-5mw9-c7wp/GHSA-vhp9-5mw9-c7wp.json index 0de2368009c..900bdffd016 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhp9-5mw9-c7wp/GHSA-vhp9-5mw9-c7wp.json +++ b/advisories/unreviewed/2022/05/GHSA-vhp9-5mw9-c7wp/GHSA-vhp9-5mw9-c7wp.json @@ -7,12 +7,8 @@ "CVE-2020-15662" ], "details": "A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the user downloading an unintended file. This vulnerability affects Firefox for iOS < 28.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vjwm-h4mx-972h/GHSA-vjwm-h4mx-972h.json b/advisories/unreviewed/2022/05/GHSA-vjwm-h4mx-972h/GHSA-vjwm-h4mx-972h.json index 6e72bb1c0ee..82f650d517f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjwm-h4mx-972h/GHSA-vjwm-h4mx-972h.json +++ b/advisories/unreviewed/2022/05/GHSA-vjwm-h4mx-972h/GHSA-vjwm-h4mx-972h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vjxw-wpjh-c887/GHSA-vjxw-wpjh-c887.json b/advisories/unreviewed/2022/05/GHSA-vjxw-wpjh-c887/GHSA-vjxw-wpjh-c887.json index b3b7850cf84..7b00c8eda34 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjxw-wpjh-c887/GHSA-vjxw-wpjh-c887.json +++ b/advisories/unreviewed/2022/05/GHSA-vjxw-wpjh-c887/GHSA-vjxw-wpjh-c887.json @@ -7,12 +7,8 @@ "CVE-2020-15831" ], "details": "JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vpcp-6873-3cx5/GHSA-vpcp-6873-3cx5.json b/advisories/unreviewed/2022/05/GHSA-vpcp-6873-3cx5/GHSA-vpcp-6873-3cx5.json index 1f4e4a81a30..04f843940b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpcp-6873-3cx5/GHSA-vpcp-6873-3cx5.json +++ b/advisories/unreviewed/2022/05/GHSA-vpcp-6873-3cx5/GHSA-vpcp-6873-3cx5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vqj7-7v57-m3xh/GHSA-vqj7-7v57-m3xh.json b/advisories/unreviewed/2022/05/GHSA-vqj7-7v57-m3xh/GHSA-vqj7-7v57-m3xh.json index 5b02eba955d..9bae875bbc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqj7-7v57-m3xh/GHSA-vqj7-7v57-m3xh.json +++ b/advisories/unreviewed/2022/05/GHSA-vqj7-7v57-m3xh/GHSA-vqj7-7v57-m3xh.json @@ -7,12 +7,8 @@ "CVE-2020-14063" ], "details": "A stored Cross-Site Scripting (XSS) vulnerability in the TC Custom JavaScript plugin before 1.2.2 for WordPress allows unauthenticated remote attackers to inject arbitrary JavaScript via the tccj-content parameter. This is displayed in the page footer of every front-end page and executed in the browser of visitors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vw35-vgjr-5jhv/GHSA-vw35-vgjr-5jhv.json b/advisories/unreviewed/2022/05/GHSA-vw35-vgjr-5jhv/GHSA-vw35-vgjr-5jhv.json index 230392e70e2..6483e2dc783 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw35-vgjr-5jhv/GHSA-vw35-vgjr-5jhv.json +++ b/advisories/unreviewed/2022/05/GHSA-vw35-vgjr-5jhv/GHSA-vw35-vgjr-5jhv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vw9w-fmv7-hq4h/GHSA-vw9w-fmv7-hq4h.json b/advisories/unreviewed/2022/05/GHSA-vw9w-fmv7-hq4h/GHSA-vw9w-fmv7-hq4h.json index abc53dc2ccb..304d19ab11f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw9w-fmv7-hq4h/GHSA-vw9w-fmv7-hq4h.json +++ b/advisories/unreviewed/2022/05/GHSA-vw9w-fmv7-hq4h/GHSA-vw9w-fmv7-hq4h.json @@ -7,12 +7,8 @@ "CVE-2020-9248" ], "details": "Huawei FusionComput 8.0.0 have an improper authorization vulnerability. A module does not verify some input correctly and authorizes files with incorrect access. Attackers can exploit this vulnerability to launch privilege escalation attack. This can compromise normal service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vwq3-qwxp-84h4/GHSA-vwq3-qwxp-84h4.json b/advisories/unreviewed/2022/05/GHSA-vwq3-qwxp-84h4/GHSA-vwq3-qwxp-84h4.json index 7c909b08709..8fbfd637df4 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwq3-qwxp-84h4/GHSA-vwq3-qwxp-84h4.json +++ b/advisories/unreviewed/2022/05/GHSA-vwq3-qwxp-84h4/GHSA-vwq3-qwxp-84h4.json @@ -7,12 +7,8 @@ "CVE-2020-15818" ], "details": "In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vxw8-wvxp-5f2r/GHSA-vxw8-wvxp-5f2r.json b/advisories/unreviewed/2022/05/GHSA-vxw8-wvxp-5f2r/GHSA-vxw8-wvxp-5f2r.json index 038be71a4cd..a9c544c06da 100644 --- a/advisories/unreviewed/2022/05/GHSA-vxw8-wvxp-5f2r/GHSA-vxw8-wvxp-5f2r.json +++ b/advisories/unreviewed/2022/05/GHSA-vxw8-wvxp-5f2r/GHSA-vxw8-wvxp-5f2r.json @@ -7,12 +7,8 @@ "CVE-2020-15657" ], "details": "Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w225-jhfh-p325/GHSA-w225-jhfh-p325.json b/advisories/unreviewed/2022/05/GHSA-w225-jhfh-p325/GHSA-w225-jhfh-p325.json index 62e9e72e0a5..870cbdc7442 100644 --- a/advisories/unreviewed/2022/05/GHSA-w225-jhfh-p325/GHSA-w225-jhfh-p325.json +++ b/advisories/unreviewed/2022/05/GHSA-w225-jhfh-p325/GHSA-w225-jhfh-p325.json @@ -7,12 +7,8 @@ "CVE-2020-13915" ], "details": "Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to overwrite admin credentials via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and T710s devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w23m-925x-fcpw/GHSA-w23m-925x-fcpw.json b/advisories/unreviewed/2022/05/GHSA-w23m-925x-fcpw/GHSA-w23m-925x-fcpw.json index 3e15563da2a..a20532f2536 100644 --- a/advisories/unreviewed/2022/05/GHSA-w23m-925x-fcpw/GHSA-w23m-925x-fcpw.json +++ b/advisories/unreviewed/2022/05/GHSA-w23m-925x-fcpw/GHSA-w23m-925x-fcpw.json @@ -7,12 +7,8 @@ "CVE-2020-6520" ], "details": "Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w586-m4mc-5cg7/GHSA-w586-m4mc-5cg7.json b/advisories/unreviewed/2022/05/GHSA-w586-m4mc-5cg7/GHSA-w586-m4mc-5cg7.json index e50e7e17a66..c1cdafb9c85 100644 --- a/advisories/unreviewed/2022/05/GHSA-w586-m4mc-5cg7/GHSA-w586-m4mc-5cg7.json +++ b/advisories/unreviewed/2022/05/GHSA-w586-m4mc-5cg7/GHSA-w586-m4mc-5cg7.json @@ -7,12 +7,8 @@ "CVE-2020-15932" ], "details": "Overwolf before 0.149.2.30 mishandles Symbolic Links during updates, causing elevation of privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w59r-wjpf-fgqc/GHSA-w59r-wjpf-fgqc.json b/advisories/unreviewed/2022/05/GHSA-w59r-wjpf-fgqc/GHSA-w59r-wjpf-fgqc.json index b538e51eef6..ebee0c75d3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-w59r-wjpf-fgqc/GHSA-w59r-wjpf-fgqc.json +++ b/advisories/unreviewed/2022/05/GHSA-w59r-wjpf-fgqc/GHSA-w59r-wjpf-fgqc.json @@ -7,12 +7,8 @@ "CVE-2020-9527" ], "details": "Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20, after 2018-08-09 through 2020), as used by many different vendors in millions of Internet of Things devices, suffers from buffer overflow vulnerability that allows unauthenticated remote attackers to execute arbitrary code via the peer-to-peer (P2P) service. This affects products marketed under the following brand names: Accfly, Alptop, Anlink, Besdersec, BOAVISION, COOAU, CPVAN, Ctronics, D3D Security, Dericam, Elex System, Elite Security, ENSTER, ePGes, Escam, FLOUREON, GENBOLT, Hongjingtian (HJT), ICAMI, Iegeek, Jecurity, Jennov, KKMoon, LEFTEK, Loosafe, Luowice, Nesuniq, Nettoly, ProElite, QZT, Royallite, SDETER, SV3C, SY2L, Tenvis, ThinkValue, TOMLOV, TPTEK, WGCC, and ZILINK.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w5pf-gqqf-7mw9/GHSA-w5pf-gqqf-7mw9.json b/advisories/unreviewed/2022/05/GHSA-w5pf-gqqf-7mw9/GHSA-w5pf-gqqf-7mw9.json index 501c7a99425..129b5096b0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5pf-gqqf-7mw9/GHSA-w5pf-gqqf-7mw9.json +++ b/advisories/unreviewed/2022/05/GHSA-w5pf-gqqf-7mw9/GHSA-w5pf-gqqf-7mw9.json @@ -7,12 +7,8 @@ "CVE-2020-9679" ], "details": "Adobe Prelude versions 9.0 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w5rc-c785-5ccm/GHSA-w5rc-c785-5ccm.json b/advisories/unreviewed/2022/05/GHSA-w5rc-c785-5ccm/GHSA-w5rc-c785-5ccm.json index 0fee4942986..51bf2fc39ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5rc-c785-5ccm/GHSA-w5rc-c785-5ccm.json +++ b/advisories/unreviewed/2022/05/GHSA-w5rc-c785-5ccm/GHSA-w5rc-c785-5ccm.json @@ -7,12 +7,8 @@ "CVE-2020-15071" ], "details": "content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w5rx-p7h2-mfj5/GHSA-w5rx-p7h2-mfj5.json b/advisories/unreviewed/2022/05/GHSA-w5rx-p7h2-mfj5/GHSA-w5rx-p7h2-mfj5.json index a02be357644..924b1650fbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5rx-p7h2-mfj5/GHSA-w5rx-p7h2-mfj5.json +++ b/advisories/unreviewed/2022/05/GHSA-w5rx-p7h2-mfj5/GHSA-w5rx-p7h2-mfj5.json @@ -7,12 +7,8 @@ "CVE-2020-6533" ], "details": "Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w5w3-5g8c-cmq9/GHSA-w5w3-5g8c-cmq9.json b/advisories/unreviewed/2022/05/GHSA-w5w3-5g8c-cmq9/GHSA-w5w3-5g8c-cmq9.json index d21663ce120..02206878874 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5w3-5g8c-cmq9/GHSA-w5w3-5g8c-cmq9.json +++ b/advisories/unreviewed/2022/05/GHSA-w5w3-5g8c-cmq9/GHSA-w5w3-5g8c-cmq9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w6gv-63rm-rv7h/GHSA-w6gv-63rm-rv7h.json b/advisories/unreviewed/2022/05/GHSA-w6gv-63rm-rv7h/GHSA-w6gv-63rm-rv7h.json index c2863eee22c..c89266beb16 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6gv-63rm-rv7h/GHSA-w6gv-63rm-rv7h.json +++ b/advisories/unreviewed/2022/05/GHSA-w6gv-63rm-rv7h/GHSA-w6gv-63rm-rv7h.json @@ -7,12 +7,8 @@ "CVE-2020-5610" ], "details": "Global TechStream (GTS) for TOYOTA dealers version 15.10.032 and earlier allows an attacker to cause a denial-of-service (DoS) condition and execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w739-fjv8-98pq/GHSA-w739-fjv8-98pq.json b/advisories/unreviewed/2022/05/GHSA-w739-fjv8-98pq/GHSA-w739-fjv8-98pq.json index 2a509b757ee..e061119084a 100644 --- a/advisories/unreviewed/2022/05/GHSA-w739-fjv8-98pq/GHSA-w739-fjv8-98pq.json +++ b/advisories/unreviewed/2022/05/GHSA-w739-fjv8-98pq/GHSA-w739-fjv8-98pq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w7f8-p623-gp6f/GHSA-w7f8-p623-gp6f.json b/advisories/unreviewed/2022/05/GHSA-w7f8-p623-gp6f/GHSA-w7f8-p623-gp6f.json index 3483b46a92d..c9fbff479b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7f8-p623-gp6f/GHSA-w7f8-p623-gp6f.json +++ b/advisories/unreviewed/2022/05/GHSA-w7f8-p623-gp6f/GHSA-w7f8-p623-gp6f.json @@ -7,12 +7,8 @@ "CVE-2020-16134" ], "details": "An issue was discovered on Swisscom Internet Box 2, Internet Box Standard, Internet Box Plus prior to 10.04.38, Internet Box 3 prior to 11.01.20, and Internet Box light prior to 08.06.06. Given the (user-configurable) credentials for the local Web interface or physical access to a device's plus or reset button, an attacker can create a user with elevated privileges on the Sysbus-API. This can then be used to modify local or remote SSH access, thus allowing a login session as the superuser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w9v6-fcfc-9xr5/GHSA-w9v6-fcfc-9xr5.json b/advisories/unreviewed/2022/05/GHSA-w9v6-fcfc-9xr5/GHSA-w9v6-fcfc-9xr5.json index 9466782ee46..210e56936a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9v6-fcfc-9xr5/GHSA-w9v6-fcfc-9xr5.json +++ b/advisories/unreviewed/2022/05/GHSA-w9v6-fcfc-9xr5/GHSA-w9v6-fcfc-9xr5.json @@ -7,12 +7,8 @@ "CVE-2020-12432" ], "details": "The WOPI API integration for Vereign Collabora CODE through 4.2.2 does not properly restrict delivery of JavaScript to a victim's browser, and lacks proper MIME type access control, which could lead to XSS that steals account credentials via cookies or local storage. The attacker must first obtain an API access token, which can be accomplished if the attacker is able to upload a .docx or .odt file. The associated API endpoints for exploitation are /wopi/files and /wopi/getAccessToken.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wc8r-7hj6-v6fg/GHSA-wc8r-7hj6-v6fg.json b/advisories/unreviewed/2022/05/GHSA-wc8r-7hj6-v6fg/GHSA-wc8r-7hj6-v6fg.json index 3e5189598f4..871dc2be578 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc8r-7hj6-v6fg/GHSA-wc8r-7hj6-v6fg.json +++ b/advisories/unreviewed/2022/05/GHSA-wc8r-7hj6-v6fg/GHSA-wc8r-7hj6-v6fg.json @@ -7,12 +7,8 @@ "CVE-2016-7064" ], "details": "A flaw was found in pritunl-client before version 1.0.1116.6. A lack of signature verification leads to sensitive information leakage", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wcf2-mm7g-vqrm/GHSA-wcf2-mm7g-vqrm.json b/advisories/unreviewed/2022/05/GHSA-wcf2-mm7g-vqrm/GHSA-wcf2-mm7g-vqrm.json index 5fc920d3bfe..47297051de4 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcf2-mm7g-vqrm/GHSA-wcf2-mm7g-vqrm.json +++ b/advisories/unreviewed/2022/05/GHSA-wcf2-mm7g-vqrm/GHSA-wcf2-mm7g-vqrm.json @@ -7,12 +7,8 @@ "CVE-2020-10922" ], "details": "This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the EA-HTTP.exe process. The issue results from the lack of proper input validation prior to further processing user requests. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-10527.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wcwj-33h6-vxqv/GHSA-wcwj-33h6-vxqv.json b/advisories/unreviewed/2022/05/GHSA-wcwj-33h6-vxqv/GHSA-wcwj-33h6-vxqv.json index 16d74cc5623..c3abde1916b 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcwj-33h6-vxqv/GHSA-wcwj-33h6-vxqv.json +++ b/advisories/unreviewed/2022/05/GHSA-wcwj-33h6-vxqv/GHSA-wcwj-33h6-vxqv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wcxg-jm87-f9v5/GHSA-wcxg-jm87-f9v5.json b/advisories/unreviewed/2022/05/GHSA-wcxg-jm87-f9v5/GHSA-wcxg-jm87-f9v5.json index 2d91a7b825e..9c3748673e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcxg-jm87-f9v5/GHSA-wcxg-jm87-f9v5.json +++ b/advisories/unreviewed/2022/05/GHSA-wcxg-jm87-f9v5/GHSA-wcxg-jm87-f9v5.json @@ -7,12 +7,8 @@ "CVE-2020-8108" ], "details": "Improper Authentication vulnerability in Bitdefender Endpoint Security for Mac allows an unprivileged process to restart the main service and potentially inject third-party code into a trusted process. This issue affects: Bitdefender Endpoint Security for Mac versions prior to 4.12.80.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wg7m-wv28-cvcr/GHSA-wg7m-wv28-cvcr.json b/advisories/unreviewed/2022/05/GHSA-wg7m-wv28-cvcr/GHSA-wg7m-wv28-cvcr.json index c3d2948bb67..a89be59d96e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg7m-wv28-cvcr/GHSA-wg7m-wv28-cvcr.json +++ b/advisories/unreviewed/2022/05/GHSA-wg7m-wv28-cvcr/GHSA-wg7m-wv28-cvcr.json @@ -7,12 +7,8 @@ "CVE-2020-15649" ], "details": "Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actually files picked. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.11.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wm6r-c63f-9w6h/GHSA-wm6r-c63f-9w6h.json b/advisories/unreviewed/2022/05/GHSA-wm6r-c63f-9w6h/GHSA-wm6r-c63f-9w6h.json index d31a2a0a659..e5cb1d6efb5 100644 --- a/advisories/unreviewed/2022/05/GHSA-wm6r-c63f-9w6h/GHSA-wm6r-c63f-9w6h.json +++ b/advisories/unreviewed/2022/05/GHSA-wm6r-c63f-9w6h/GHSA-wm6r-c63f-9w6h.json @@ -7,12 +7,8 @@ "CVE-2019-10580" ], "details": "When kernel thread unregistered listener, Use after free issue happened as the listener client`s private data has been already freed in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9607, MSM8909W, Nicobar, QCM2150, QCS405, QCS605, Saipan, SC8180X, SDM429W, SDX55, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wm7x-g8j8-cw8f/GHSA-wm7x-g8j8-cw8f.json b/advisories/unreviewed/2022/05/GHSA-wm7x-g8j8-cw8f/GHSA-wm7x-g8j8-cw8f.json index efe9c4e59ab..60b07d679be 100644 --- a/advisories/unreviewed/2022/05/GHSA-wm7x-g8j8-cw8f/GHSA-wm7x-g8j8-cw8f.json +++ b/advisories/unreviewed/2022/05/GHSA-wm7x-g8j8-cw8f/GHSA-wm7x-g8j8-cw8f.json @@ -7,12 +7,8 @@ "CVE-2020-9526" ], "details": "CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure flaw that exposes user session data to supernodes in the network, as demonstrated by passively eavesdropping on user video/audio streams, capturing credentials, and compromising devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmp9-25gr-rffr/GHSA-wmp9-25gr-rffr.json b/advisories/unreviewed/2022/05/GHSA-wmp9-25gr-rffr/GHSA-wmp9-25gr-rffr.json index 86d430f9272..ea49bc5089c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmp9-25gr-rffr/GHSA-wmp9-25gr-rffr.json +++ b/advisories/unreviewed/2022/05/GHSA-wmp9-25gr-rffr/GHSA-wmp9-25gr-rffr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "WEB", diff --git a/advisories/unreviewed/2022/05/GHSA-wpxh-7mhx-fc98/GHSA-wpxh-7mhx-fc98.json b/advisories/unreviewed/2022/05/GHSA-wpxh-7mhx-fc98/GHSA-wpxh-7mhx-fc98.json index 2685c83907d..08fa694c864 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpxh-7mhx-fc98/GHSA-wpxh-7mhx-fc98.json +++ b/advisories/unreviewed/2022/05/GHSA-wpxh-7mhx-fc98/GHSA-wpxh-7mhx-fc98.json @@ -7,12 +7,8 @@ "CVE-2020-7823" ], "details": "DaviewIndy has a Memory corruption vulnerability, triggered when the user opens a malformed image file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wqmj-9hmf-rw4x/GHSA-wqmj-9hmf-rw4x.json b/advisories/unreviewed/2022/05/GHSA-wqmj-9hmf-rw4x/GHSA-wqmj-9hmf-rw4x.json index 4b0486d89ea..f1fa9512690 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqmj-9hmf-rw4x/GHSA-wqmj-9hmf-rw4x.json +++ b/advisories/unreviewed/2022/05/GHSA-wqmj-9hmf-rw4x/GHSA-wqmj-9hmf-rw4x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wqpf-2j2m-q8q9/GHSA-wqpf-2j2m-q8q9.json b/advisories/unreviewed/2022/05/GHSA-wqpf-2j2m-q8q9/GHSA-wqpf-2j2m-q8q9.json index 3a555200708..98fea9a549f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqpf-2j2m-q8q9/GHSA-wqpf-2j2m-q8q9.json +++ b/advisories/unreviewed/2022/05/GHSA-wqpf-2j2m-q8q9/GHSA-wqpf-2j2m-q8q9.json @@ -7,12 +7,8 @@ "CVE-2020-4377" ], "details": "IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 179156.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wr3q-48h2-426r/GHSA-wr3q-48h2-426r.json b/advisories/unreviewed/2022/05/GHSA-wr3q-48h2-426r/GHSA-wr3q-48h2-426r.json index 57a39269d63..7e1831f0255 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr3q-48h2-426r/GHSA-wr3q-48h2-426r.json +++ b/advisories/unreviewed/2022/05/GHSA-wr3q-48h2-426r/GHSA-wr3q-48h2-426r.json @@ -7,12 +7,8 @@ "CVE-2020-3374" ], "details": "A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization, enabling them to access sensitive information, modify the system configuration, or impact the availability of the affected system. The vulnerability is due to insufficient authorization checking on the affected system. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to gain privileges beyond what would normally be authorized for their configured user authorization level. The attacker may be able to access sensitive information, modify the system configuration, or impact the availability of the affected system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wr42-7mgr-v6qx/GHSA-wr42-7mgr-v6qx.json b/advisories/unreviewed/2022/05/GHSA-wr42-7mgr-v6qx/GHSA-wr42-7mgr-v6qx.json index 721da36d3f3..6effc9ece95 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr42-7mgr-v6qx/GHSA-wr42-7mgr-v6qx.json +++ b/advisories/unreviewed/2022/05/GHSA-wr42-7mgr-v6qx/GHSA-wr42-7mgr-v6qx.json @@ -7,12 +7,8 @@ "CVE-2020-15723" ], "details": "In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking to bypass the hips could execute arbitrary code on the Local system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wwjw-pff4-pg5g/GHSA-wwjw-pff4-pg5g.json b/advisories/unreviewed/2022/05/GHSA-wwjw-pff4-pg5g/GHSA-wwjw-pff4-pg5g.json index 0792ddf04fd..dc06fc8bf9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwjw-pff4-pg5g/GHSA-wwjw-pff4-pg5g.json +++ b/advisories/unreviewed/2022/05/GHSA-wwjw-pff4-pg5g/GHSA-wwjw-pff4-pg5g.json @@ -7,12 +7,8 @@ "CVE-2020-5617" ], "details": "Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unauthorized privileges and modify/obtain sensitive information or perform unintended operations via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wx3x-f6f5-3q4p/GHSA-wx3x-f6f5-3q4p.json b/advisories/unreviewed/2022/05/GHSA-wx3x-f6f5-3q4p/GHSA-wx3x-f6f5-3q4p.json index 3a1cd45c06d..636ffc169b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx3x-f6f5-3q4p/GHSA-wx3x-f6f5-3q4p.json +++ b/advisories/unreviewed/2022/05/GHSA-wx3x-f6f5-3q4p/GHSA-wx3x-f6f5-3q4p.json @@ -7,12 +7,8 @@ "CVE-2020-15054" ], "details": "TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxc6-2gpf-5hvp/GHSA-wxc6-2gpf-5hvp.json b/advisories/unreviewed/2022/05/GHSA-wxc6-2gpf-5hvp/GHSA-wxc6-2gpf-5hvp.json index c2e539afa73..a179406e047 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxc6-2gpf-5hvp/GHSA-wxc6-2gpf-5hvp.json +++ b/advisories/unreviewed/2022/05/GHSA-wxc6-2gpf-5hvp/GHSA-wxc6-2gpf-5hvp.json @@ -7,12 +7,8 @@ "CVE-2020-15062" ], "details": "DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxqp-g33r-6xx2/GHSA-wxqp-g33r-6xx2.json b/advisories/unreviewed/2022/05/GHSA-wxqp-g33r-6xx2/GHSA-wxqp-g33r-6xx2.json index 49d886ea392..8ff6ce797ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxqp-g33r-6xx2/GHSA-wxqp-g33r-6xx2.json +++ b/advisories/unreviewed/2022/05/GHSA-wxqp-g33r-6xx2/GHSA-wxqp-g33r-6xx2.json @@ -7,12 +7,8 @@ "CVE-2019-20030" ], "details": "An attacker with knowledge of the modem access number on a NEC UM8000 voicemail system may use SSH tunneling or standard Linux utilities to gain access to the system's LAN port. All versions are affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wxrg-wm3p-qgwq/GHSA-wxrg-wm3p-qgwq.json b/advisories/unreviewed/2022/05/GHSA-wxrg-wm3p-qgwq/GHSA-wxrg-wm3p-qgwq.json index 048c3920cf6..f108e412443 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxrg-wm3p-qgwq/GHSA-wxrg-wm3p-qgwq.json +++ b/advisories/unreviewed/2022/05/GHSA-wxrg-wm3p-qgwq/GHSA-wxrg-wm3p-qgwq.json @@ -7,12 +7,8 @@ "CVE-2020-0252" ], "details": "There is a possible memory corruption due to a use after free.Product: AndroidVersions: Android SoCAndroid ID: A-152236803", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3p9-c74w-j5mx/GHSA-x3p9-c74w-j5mx.json b/advisories/unreviewed/2022/05/GHSA-x3p9-c74w-j5mx/GHSA-x3p9-c74w-j5mx.json index bacaa0e798c..7b5685a79b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3p9-c74w-j5mx/GHSA-x3p9-c74w-j5mx.json +++ b/advisories/unreviewed/2022/05/GHSA-x3p9-c74w-j5mx/GHSA-x3p9-c74w-j5mx.json @@ -7,12 +7,8 @@ "CVE-2020-15408" ], "details": "An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admin page console via the end-user web interface because of a rewrite.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x476-7xh5-hq84/GHSA-x476-7xh5-hq84.json b/advisories/unreviewed/2022/05/GHSA-x476-7xh5-hq84/GHSA-x476-7xh5-hq84.json index 94e1908cc6d..d2b6a02b72b 100644 --- a/advisories/unreviewed/2022/05/GHSA-x476-7xh5-hq84/GHSA-x476-7xh5-hq84.json +++ b/advisories/unreviewed/2022/05/GHSA-x476-7xh5-hq84/GHSA-x476-7xh5-hq84.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x839-xh4j-fgrf/GHSA-x839-xh4j-fgrf.json b/advisories/unreviewed/2022/05/GHSA-x839-xh4j-fgrf/GHSA-x839-xh4j-fgrf.json index fd5c283aab3..73029c0cc83 100644 --- a/advisories/unreviewed/2022/05/GHSA-x839-xh4j-fgrf/GHSA-x839-xh4j-fgrf.json +++ b/advisories/unreviewed/2022/05/GHSA-x839-xh4j-fgrf/GHSA-x839-xh4j-fgrf.json @@ -7,12 +7,8 @@ "CVE-2020-14162" ], "details": "An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core script as root without a password, which could allow an attacker to obtain root access via shell metacharacters to this script's setdns command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x97g-525f-hjwr/GHSA-x97g-525f-hjwr.json b/advisories/unreviewed/2022/05/GHSA-x97g-525f-hjwr/GHSA-x97g-525f-hjwr.json index c19071b7db9..cdf2d2fad61 100644 --- a/advisories/unreviewed/2022/05/GHSA-x97g-525f-hjwr/GHSA-x97g-525f-hjwr.json +++ b/advisories/unreviewed/2022/05/GHSA-x97g-525f-hjwr/GHSA-x97g-525f-hjwr.json @@ -7,12 +7,8 @@ "CVE-2020-3376" ], "details": "A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions on an affected device. The vulnerability is due to a failure in the software to perform proper authentication. An attacker could exploit this vulnerability by browsing to one of the hosted URLs in Cisco DCNM. A successful exploit could allow the attacker to interact with and use certain functions within the Cisco DCNM.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xcr6-53hx-vmwq/GHSA-xcr6-53hx-vmwq.json b/advisories/unreviewed/2022/05/GHSA-xcr6-53hx-vmwq/GHSA-xcr6-53hx-vmwq.json index 27afd382a08..44e727642ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcr6-53hx-vmwq/GHSA-xcr6-53hx-vmwq.json +++ b/advisories/unreviewed/2022/05/GHSA-xcr6-53hx-vmwq/GHSA-xcr6-53hx-vmwq.json @@ -7,12 +7,8 @@ "CVE-2020-9249" ], "details": "HUAWEI P30 smartphones with versions earlier than 10.1.0.160(C00E160R2P11) have a denial of service vulnerability. A module does not deal with mal-crafted messages and it leads to memory leak. Attackers can exploit this vulnerability to make the device denial of service.Affected product versions include: HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xf45-w5fj-69f6/GHSA-xf45-w5fj-69f6.json b/advisories/unreviewed/2022/05/GHSA-xf45-w5fj-69f6/GHSA-xf45-w5fj-69f6.json index fb3bd061d92..218680eb25d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf45-w5fj-69f6/GHSA-xf45-w5fj-69f6.json +++ b/advisories/unreviewed/2022/05/GHSA-xf45-w5fj-69f6/GHSA-xf45-w5fj-69f6.json @@ -7,12 +7,8 @@ "CVE-2020-4572" ], "details": "IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 184179.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xg8x-7gj7-5m8c/GHSA-xg8x-7gj7-5m8c.json b/advisories/unreviewed/2022/05/GHSA-xg8x-7gj7-5m8c/GHSA-xg8x-7gj7-5m8c.json index 25f79676876..aca745affd6 100644 --- a/advisories/unreviewed/2022/05/GHSA-xg8x-7gj7-5m8c/GHSA-xg8x-7gj7-5m8c.json +++ b/advisories/unreviewed/2022/05/GHSA-xg8x-7gj7-5m8c/GHSA-xg8x-7gj7-5m8c.json @@ -7,12 +7,8 @@ "CVE-2020-4485" ], "details": "IBM QRadar 7.2.0 through 7.2.9 could allow an authenticated user to disable the Wincollect service which could aid an attacker in bypassing security mechanisms in future attacks. IBM X-Force ID: 181860.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xgcj-c5c8-wm98/GHSA-xgcj-c5c8-wm98.json b/advisories/unreviewed/2022/05/GHSA-xgcj-c5c8-wm98/GHSA-xgcj-c5c8-wm98.json index 61e5f0c30c5..74d4f413cc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgcj-c5c8-wm98/GHSA-xgcj-c5c8-wm98.json +++ b/advisories/unreviewed/2022/05/GHSA-xgcj-c5c8-wm98/GHSA-xgcj-c5c8-wm98.json @@ -7,12 +7,8 @@ "CVE-2020-9678" ], "details": "Adobe Prelude versions 9.0 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xgr2-w47g-6j54/GHSA-xgr2-w47g-6j54.json b/advisories/unreviewed/2022/05/GHSA-xgr2-w47g-6j54/GHSA-xgr2-w47g-6j54.json index dbadd582f96..ed84634b555 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgr2-w47g-6j54/GHSA-xgr2-w47g-6j54.json +++ b/advisories/unreviewed/2022/05/GHSA-xgr2-w47g-6j54/GHSA-xgr2-w47g-6j54.json @@ -7,12 +7,8 @@ "CVE-2020-3382" ], "details": "A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability exists because different installations share a static encryption key. An attacker could exploit this vulnerability by using the static key to craft a valid session token. A successful exploit could allow the attacker to perform arbitrary actions through the REST API with administrative privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xh36-cr78-92jc/GHSA-xh36-cr78-92jc.json b/advisories/unreviewed/2022/05/GHSA-xh36-cr78-92jc/GHSA-xh36-cr78-92jc.json index a11e22ad779..41cb526a133 100644 --- a/advisories/unreviewed/2022/05/GHSA-xh36-cr78-92jc/GHSA-xh36-cr78-92jc.json +++ b/advisories/unreviewed/2022/05/GHSA-xh36-cr78-92jc/GHSA-xh36-cr78-92jc.json @@ -7,12 +7,8 @@ "CVE-2020-16275" ], "details": "A cross-site scripting (XSS) vulnerability in the Credential Manager component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xjqq-782m-q873/GHSA-xjqq-782m-q873.json b/advisories/unreviewed/2022/05/GHSA-xjqq-782m-q873/GHSA-xjqq-782m-q873.json index abf2eb6fd2b..004b04f1931 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjqq-782m-q873/GHSA-xjqq-782m-q873.json +++ b/advisories/unreviewed/2022/05/GHSA-xjqq-782m-q873/GHSA-xjqq-782m-q873.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjww-fj3c-cmgx/GHSA-xjww-fj3c-cmgx.json b/advisories/unreviewed/2022/05/GHSA-xjww-fj3c-cmgx/GHSA-xjww-fj3c-cmgx.json index 2bf86eb907f..0aff7df0b1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjww-fj3c-cmgx/GHSA-xjww-fj3c-cmgx.json +++ b/advisories/unreviewed/2022/05/GHSA-xjww-fj3c-cmgx/GHSA-xjww-fj3c-cmgx.json @@ -7,12 +7,8 @@ "CVE-2020-12081" ], "details": "An information disclosure vulnerability has been identified in FlexNet Publisher lmadmin.exe 11.14.0.2. The web portal link can be used to access to system files or other important files on the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xmx2-vxw5-6rg6/GHSA-xmx2-vxw5-6rg6.json b/advisories/unreviewed/2022/05/GHSA-xmx2-vxw5-6rg6/GHSA-xmx2-vxw5-6rg6.json index 8257e09ef1b..047bc1d5284 100644 --- a/advisories/unreviewed/2022/05/GHSA-xmx2-vxw5-6rg6/GHSA-xmx2-vxw5-6rg6.json +++ b/advisories/unreviewed/2022/05/GHSA-xmx2-vxw5-6rg6/GHSA-xmx2-vxw5-6rg6.json @@ -7,12 +7,8 @@ "CVE-2019-20031" ], "details": "NEC UM8000, UM4730 and prior non-InMail voicemail systems with all known software versions may permit an infinite number of login attempts in the telephone user interface (TUI), effectively allowing brute force attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xp65-q44f-qvpj/GHSA-xp65-q44f-qvpj.json b/advisories/unreviewed/2022/05/GHSA-xp65-q44f-qvpj/GHSA-xp65-q44f-qvpj.json index 2c2d13d7fd0..19c5df4fc43 100644 --- a/advisories/unreviewed/2022/05/GHSA-xp65-q44f-qvpj/GHSA-xp65-q44f-qvpj.json +++ b/advisories/unreviewed/2022/05/GHSA-xp65-q44f-qvpj/GHSA-xp65-q44f-qvpj.json @@ -7,12 +7,8 @@ "CVE-2020-6534" ], "details": "Heap buffer overflow in WebRTC in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xp9g-2jr8-5wm3/GHSA-xp9g-2jr8-5wm3.json b/advisories/unreviewed/2022/05/GHSA-xp9g-2jr8-5wm3/GHSA-xp9g-2jr8-5wm3.json index eff87e6c596..8161ee001d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-xp9g-2jr8-5wm3/GHSA-xp9g-2jr8-5wm3.json +++ b/advisories/unreviewed/2022/05/GHSA-xp9g-2jr8-5wm3/GHSA-xp9g-2jr8-5wm3.json @@ -7,12 +7,8 @@ "CVE-2020-15596" ], "details": "The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a \"fake\" DLL file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xr77-4rxw-6357/GHSA-xr77-4rxw-6357.json b/advisories/unreviewed/2022/05/GHSA-xr77-4rxw-6357/GHSA-xr77-4rxw-6357.json index bb67584facb..8820f209253 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr77-4rxw-6357/GHSA-xr77-4rxw-6357.json +++ b/advisories/unreviewed/2022/05/GHSA-xr77-4rxw-6357/GHSA-xr77-4rxw-6357.json @@ -7,12 +7,8 @@ "CVE-2020-4465" ], "details": "IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS is vulnerable to a buffer overflow vulnerability due to an error within the channel processing code. A remote attacker could overflow the buffer using an older client and cause a denial of service. IBM X-Force ID: 181562.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xr9p-wqhw-3w78/GHSA-xr9p-wqhw-3w78.json b/advisories/unreviewed/2022/05/GHSA-xr9p-wqhw-3w78/GHSA-xr9p-wqhw-3w78.json index b30c85ad6ae..b8c6f2dfc25 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr9p-wqhw-3w78/GHSA-xr9p-wqhw-3w78.json +++ b/advisories/unreviewed/2022/05/GHSA-xr9p-wqhw-3w78/GHSA-xr9p-wqhw-3w78.json @@ -7,12 +7,8 @@ "CVE-2020-3681" ], "details": "Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recoverable from code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xvq7-6cjq-gwh7/GHSA-xvq7-6cjq-gwh7.json b/advisories/unreviewed/2022/05/GHSA-xvq7-6cjq-gwh7/GHSA-xvq7-6cjq-gwh7.json index 12dbb9947b4..0bdddd161cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvq7-6cjq-gwh7/GHSA-xvq7-6cjq-gwh7.json +++ b/advisories/unreviewed/2022/05/GHSA-xvq7-6cjq-gwh7/GHSA-xvq7-6cjq-gwh7.json @@ -7,12 +7,8 @@ "CVE-2020-0254" ], "details": "There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-152647751", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xvv3-3j3q-vgxg/GHSA-xvv3-3j3q-vgxg.json b/advisories/unreviewed/2022/05/GHSA-xvv3-3j3q-vgxg/GHSA-xvv3-3j3q-vgxg.json index 76c314c3efd..a6c017acb89 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvv3-3j3q-vgxg/GHSA-xvv3-3j3q-vgxg.json +++ b/advisories/unreviewed/2022/05/GHSA-xvv3-3j3q-vgxg/GHSA-xvv3-3j3q-vgxg.json @@ -7,12 +7,8 @@ "CVE-2019-20029" ], "details": "An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices. A specially crafted HTTP POST can cause privilege escalation resulting in a higher privileged account, including an undocumented developer level of access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xw98-6cfw-p3wh/GHSA-xw98-6cfw-p3wh.json b/advisories/unreviewed/2022/05/GHSA-xw98-6cfw-p3wh/GHSA-xw98-6cfw-p3wh.json index bce240aaf6e..96f0440ca48 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw98-6cfw-p3wh/GHSA-xw98-6cfw-p3wh.json +++ b/advisories/unreviewed/2022/05/GHSA-xw98-6cfw-p3wh/GHSA-xw98-6cfw-p3wh.json @@ -7,12 +7,8 @@ "CVE-2020-10917" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RMI service. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10007.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xwp8-2vq8-v6xg/GHSA-xwp8-2vq8-v6xg.json b/advisories/unreviewed/2022/05/GHSA-xwp8-2vq8-v6xg/GHSA-xwp8-2vq8-v6xg.json index df4204f06eb..1109795782c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwp8-2vq8-v6xg/GHSA-xwp8-2vq8-v6xg.json +++ b/advisories/unreviewed/2022/05/GHSA-xwp8-2vq8-v6xg/GHSA-xwp8-2vq8-v6xg.json @@ -7,12 +7,8 @@ "CVE-2019-7005" ], "details": "A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated user with network access to gain sensitive information. Affected versions of IP Office include: 9.x, 10.0 through 10.1.0.7 and 11.0 through 11.0.4.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/06/GHSA-xvxf-7p3q-7mmg/GHSA-xvxf-7p3q-7mmg.json b/advisories/unreviewed/2022/06/GHSA-xvxf-7p3q-7mmg/GHSA-xvxf-7p3q-7mmg.json index b0dc334b99b..981ef32197f 100644 --- a/advisories/unreviewed/2022/06/GHSA-xvxf-7p3q-7mmg/GHSA-xvxf-7p3q-7mmg.json +++ b/advisories/unreviewed/2022/06/GHSA-xvxf-7p3q-7mmg/GHSA-xvxf-7p3q-7mmg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-25w9-jc8c-rx9w/GHSA-25w9-jc8c-rx9w.json b/advisories/unreviewed/2022/11/GHSA-25w9-jc8c-rx9w/GHSA-25w9-jc8c-rx9w.json index 5948c264f29..e9ae557e91b 100644 --- a/advisories/unreviewed/2022/11/GHSA-25w9-jc8c-rx9w/GHSA-25w9-jc8c-rx9w.json +++ b/advisories/unreviewed/2022/11/GHSA-25w9-jc8c-rx9w/GHSA-25w9-jc8c-rx9w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-f39f-g3gv-88jq/GHSA-f39f-g3gv-88jq.json b/advisories/unreviewed/2022/11/GHSA-f39f-g3gv-88jq/GHSA-f39f-g3gv-88jq.json index 881d4222ac3..8dbab4b5918 100644 --- a/advisories/unreviewed/2022/11/GHSA-f39f-g3gv-88jq/GHSA-f39f-g3gv-88jq.json +++ b/advisories/unreviewed/2022/11/GHSA-f39f-g3gv-88jq/GHSA-f39f-g3gv-88jq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-vjx6-6r3w-rpqc/GHSA-vjx6-6r3w-rpqc.json b/advisories/unreviewed/2022/12/GHSA-vjx6-6r3w-rpqc/GHSA-vjx6-6r3w-rpqc.json index 884b1650bb6..9715e31c175 100644 --- a/advisories/unreviewed/2022/12/GHSA-vjx6-6r3w-rpqc/GHSA-vjx6-6r3w-rpqc.json +++ b/advisories/unreviewed/2022/12/GHSA-vjx6-6r3w-rpqc/GHSA-vjx6-6r3w-rpqc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-xjvv-99gp-jgrm/GHSA-xjvv-99gp-jgrm.json b/advisories/unreviewed/2022/12/GHSA-xjvv-99gp-jgrm/GHSA-xjvv-99gp-jgrm.json index b0cc19535c0..3d0b2430fa6 100644 --- a/advisories/unreviewed/2022/12/GHSA-xjvv-99gp-jgrm/GHSA-xjvv-99gp-jgrm.json +++ b/advisories/unreviewed/2022/12/GHSA-xjvv-99gp-jgrm/GHSA-xjvv-99gp-jgrm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-2v9m-mhmr-2xcw/GHSA-2v9m-mhmr-2xcw.json b/advisories/unreviewed/2023/01/GHSA-2v9m-mhmr-2xcw/GHSA-2v9m-mhmr-2xcw.json index e8169ef62c4..cc82e437668 100644 --- a/advisories/unreviewed/2023/01/GHSA-2v9m-mhmr-2xcw/GHSA-2v9m-mhmr-2xcw.json +++ b/advisories/unreviewed/2023/01/GHSA-2v9m-mhmr-2xcw/GHSA-2v9m-mhmr-2xcw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-6rwg-62q4-wcw9/GHSA-6rwg-62q4-wcw9.json b/advisories/unreviewed/2023/01/GHSA-6rwg-62q4-wcw9/GHSA-6rwg-62q4-wcw9.json index c44fdb76b25..cf67dcbf835 100644 --- a/advisories/unreviewed/2023/01/GHSA-6rwg-62q4-wcw9/GHSA-6rwg-62q4-wcw9.json +++ b/advisories/unreviewed/2023/01/GHSA-6rwg-62q4-wcw9/GHSA-6rwg-62q4-wcw9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-gr48-q88f-726j/GHSA-gr48-q88f-726j.json b/advisories/unreviewed/2023/01/GHSA-gr48-q88f-726j/GHSA-gr48-q88f-726j.json index 1a599da0c02..212e460c76d 100644 --- a/advisories/unreviewed/2023/01/GHSA-gr48-q88f-726j/GHSA-gr48-q88f-726j.json +++ b/advisories/unreviewed/2023/01/GHSA-gr48-q88f-726j/GHSA-gr48-q88f-726j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-v833-mfjc-7qr5/GHSA-v833-mfjc-7qr5.json b/advisories/unreviewed/2023/01/GHSA-v833-mfjc-7qr5/GHSA-v833-mfjc-7qr5.json index 813494c5ff6..2c934384e8a 100644 --- a/advisories/unreviewed/2023/01/GHSA-v833-mfjc-7qr5/GHSA-v833-mfjc-7qr5.json +++ b/advisories/unreviewed/2023/01/GHSA-v833-mfjc-7qr5/GHSA-v833-mfjc-7qr5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-3cjm-9wq5-p7gj/GHSA-3cjm-9wq5-p7gj.json b/advisories/unreviewed/2023/02/GHSA-3cjm-9wq5-p7gj/GHSA-3cjm-9wq5-p7gj.json index 6164c73859c..0364537306f 100644 --- a/advisories/unreviewed/2023/02/GHSA-3cjm-9wq5-p7gj/GHSA-3cjm-9wq5-p7gj.json +++ b/advisories/unreviewed/2023/02/GHSA-3cjm-9wq5-p7gj/GHSA-3cjm-9wq5-p7gj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-6g7p-j2q6-fp39/GHSA-6g7p-j2q6-fp39.json b/advisories/unreviewed/2023/02/GHSA-6g7p-j2q6-fp39/GHSA-6g7p-j2q6-fp39.json index 8dcd8472d04..0625bd0339f 100644 --- a/advisories/unreviewed/2023/02/GHSA-6g7p-j2q6-fp39/GHSA-6g7p-j2q6-fp39.json +++ b/advisories/unreviewed/2023/02/GHSA-6g7p-j2q6-fp39/GHSA-6g7p-j2q6-fp39.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-6w2p-cgh8-m9q9/GHSA-6w2p-cgh8-m9q9.json b/advisories/unreviewed/2023/02/GHSA-6w2p-cgh8-m9q9/GHSA-6w2p-cgh8-m9q9.json index b8b7445c106..5c2c52ccc5f 100644 --- a/advisories/unreviewed/2023/02/GHSA-6w2p-cgh8-m9q9/GHSA-6w2p-cgh8-m9q9.json +++ b/advisories/unreviewed/2023/02/GHSA-6w2p-cgh8-m9q9/GHSA-6w2p-cgh8-m9q9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-7p66-5494-38w3/GHSA-7p66-5494-38w3.json b/advisories/unreviewed/2023/02/GHSA-7p66-5494-38w3/GHSA-7p66-5494-38w3.json index 9f589961a46..e2d0777bd80 100644 --- a/advisories/unreviewed/2023/02/GHSA-7p66-5494-38w3/GHSA-7p66-5494-38w3.json +++ b/advisories/unreviewed/2023/02/GHSA-7p66-5494-38w3/GHSA-7p66-5494-38w3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-84hw-65xp-5cx9/GHSA-84hw-65xp-5cx9.json b/advisories/unreviewed/2023/02/GHSA-84hw-65xp-5cx9/GHSA-84hw-65xp-5cx9.json index aa9f2c31d7f..15bd0a9b1c4 100644 --- a/advisories/unreviewed/2023/02/GHSA-84hw-65xp-5cx9/GHSA-84hw-65xp-5cx9.json +++ b/advisories/unreviewed/2023/02/GHSA-84hw-65xp-5cx9/GHSA-84hw-65xp-5cx9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-865w-mq7p-j8f4/GHSA-865w-mq7p-j8f4.json b/advisories/unreviewed/2023/02/GHSA-865w-mq7p-j8f4/GHSA-865w-mq7p-j8f4.json index 48a77613881..41b310b53c1 100644 --- a/advisories/unreviewed/2023/02/GHSA-865w-mq7p-j8f4/GHSA-865w-mq7p-j8f4.json +++ b/advisories/unreviewed/2023/02/GHSA-865w-mq7p-j8f4/GHSA-865w-mq7p-j8f4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-9h73-4h32-23wp/GHSA-9h73-4h32-23wp.json b/advisories/unreviewed/2023/02/GHSA-9h73-4h32-23wp/GHSA-9h73-4h32-23wp.json index 378fe2da310..49686f6adbd 100644 --- a/advisories/unreviewed/2023/02/GHSA-9h73-4h32-23wp/GHSA-9h73-4h32-23wp.json +++ b/advisories/unreviewed/2023/02/GHSA-9h73-4h32-23wp/GHSA-9h73-4h32-23wp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-gw47-4qv6-6qmx/GHSA-gw47-4qv6-6qmx.json b/advisories/unreviewed/2023/02/GHSA-gw47-4qv6-6qmx/GHSA-gw47-4qv6-6qmx.json index 275e27a9900..a54b9a8d1cd 100644 --- a/advisories/unreviewed/2023/02/GHSA-gw47-4qv6-6qmx/GHSA-gw47-4qv6-6qmx.json +++ b/advisories/unreviewed/2023/02/GHSA-gw47-4qv6-6qmx/GHSA-gw47-4qv6-6qmx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-jj8v-mj23-mw67/GHSA-jj8v-mj23-mw67.json b/advisories/unreviewed/2023/02/GHSA-jj8v-mj23-mw67/GHSA-jj8v-mj23-mw67.json index 5edae23ad36..ce411b5a2cc 100644 --- a/advisories/unreviewed/2023/02/GHSA-jj8v-mj23-mw67/GHSA-jj8v-mj23-mw67.json +++ b/advisories/unreviewed/2023/02/GHSA-jj8v-mj23-mw67/GHSA-jj8v-mj23-mw67.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-qhjw-g4rm-w3v5/GHSA-qhjw-g4rm-w3v5.json b/advisories/unreviewed/2023/02/GHSA-qhjw-g4rm-w3v5/GHSA-qhjw-g4rm-w3v5.json index e4ebc512637..8470477c367 100644 --- a/advisories/unreviewed/2023/02/GHSA-qhjw-g4rm-w3v5/GHSA-qhjw-g4rm-w3v5.json +++ b/advisories/unreviewed/2023/02/GHSA-qhjw-g4rm-w3v5/GHSA-qhjw-g4rm-w3v5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-qwfq-hhqp-jvfx/GHSA-qwfq-hhqp-jvfx.json b/advisories/unreviewed/2023/02/GHSA-qwfq-hhqp-jvfx/GHSA-qwfq-hhqp-jvfx.json index b03429e487f..325739e2edb 100644 --- a/advisories/unreviewed/2023/02/GHSA-qwfq-hhqp-jvfx/GHSA-qwfq-hhqp-jvfx.json +++ b/advisories/unreviewed/2023/02/GHSA-qwfq-hhqp-jvfx/GHSA-qwfq-hhqp-jvfx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-xv58-xpg4-8jv9/GHSA-xv58-xpg4-8jv9.json b/advisories/unreviewed/2023/02/GHSA-xv58-xpg4-8jv9/GHSA-xv58-xpg4-8jv9.json index 013aea585aa..be13b47bf72 100644 --- a/advisories/unreviewed/2023/02/GHSA-xv58-xpg4-8jv9/GHSA-xv58-xpg4-8jv9.json +++ b/advisories/unreviewed/2023/02/GHSA-xv58-xpg4-8jv9/GHSA-xv58-xpg4-8jv9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-23pq-q969-c5vw/GHSA-23pq-q969-c5vw.json b/advisories/unreviewed/2023/03/GHSA-23pq-q969-c5vw/GHSA-23pq-q969-c5vw.json index a053344eb68..04443fe61ab 100644 --- a/advisories/unreviewed/2023/03/GHSA-23pq-q969-c5vw/GHSA-23pq-q969-c5vw.json +++ b/advisories/unreviewed/2023/03/GHSA-23pq-q969-c5vw/GHSA-23pq-q969-c5vw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-76q7-gm7v-vj5q/GHSA-76q7-gm7v-vj5q.json b/advisories/unreviewed/2023/03/GHSA-76q7-gm7v-vj5q/GHSA-76q7-gm7v-vj5q.json index d9fffd65de8..b96d9955e54 100644 --- a/advisories/unreviewed/2023/03/GHSA-76q7-gm7v-vj5q/GHSA-76q7-gm7v-vj5q.json +++ b/advisories/unreviewed/2023/03/GHSA-76q7-gm7v-vj5q/GHSA-76q7-gm7v-vj5q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-g874-7753-4g62/GHSA-g874-7753-4g62.json b/advisories/unreviewed/2023/03/GHSA-g874-7753-4g62/GHSA-g874-7753-4g62.json index ced4d5e7d65..edd9eef53bf 100644 --- a/advisories/unreviewed/2023/03/GHSA-g874-7753-4g62/GHSA-g874-7753-4g62.json +++ b/advisories/unreviewed/2023/03/GHSA-g874-7753-4g62/GHSA-g874-7753-4g62.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-gg3f-99q3-f2qp/GHSA-gg3f-99q3-f2qp.json b/advisories/unreviewed/2023/03/GHSA-gg3f-99q3-f2qp/GHSA-gg3f-99q3-f2qp.json index a1563c0b4ae..8854e517ddf 100644 --- a/advisories/unreviewed/2023/03/GHSA-gg3f-99q3-f2qp/GHSA-gg3f-99q3-f2qp.json +++ b/advisories/unreviewed/2023/03/GHSA-gg3f-99q3-f2qp/GHSA-gg3f-99q3-f2qp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-ghmc-655x-wwhc/GHSA-ghmc-655x-wwhc.json b/advisories/unreviewed/2023/03/GHSA-ghmc-655x-wwhc/GHSA-ghmc-655x-wwhc.json index 5e92c35d1f2..13c262a12b7 100644 --- a/advisories/unreviewed/2023/03/GHSA-ghmc-655x-wwhc/GHSA-ghmc-655x-wwhc.json +++ b/advisories/unreviewed/2023/03/GHSA-ghmc-655x-wwhc/GHSA-ghmc-655x-wwhc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-m967-grxx-4qjp/GHSA-m967-grxx-4qjp.json b/advisories/unreviewed/2023/03/GHSA-m967-grxx-4qjp/GHSA-m967-grxx-4qjp.json index aab5b3755eb..d172199723d 100644 --- a/advisories/unreviewed/2023/03/GHSA-m967-grxx-4qjp/GHSA-m967-grxx-4qjp.json +++ b/advisories/unreviewed/2023/03/GHSA-m967-grxx-4qjp/GHSA-m967-grxx-4qjp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-pp3c-rj85-cc8g/GHSA-pp3c-rj85-cc8g.json b/advisories/unreviewed/2023/03/GHSA-pp3c-rj85-cc8g/GHSA-pp3c-rj85-cc8g.json index 279f5514046..a5c8aa5e011 100644 --- a/advisories/unreviewed/2023/03/GHSA-pp3c-rj85-cc8g/GHSA-pp3c-rj85-cc8g.json +++ b/advisories/unreviewed/2023/03/GHSA-pp3c-rj85-cc8g/GHSA-pp3c-rj85-cc8g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-w82x-wr5m-8q52/GHSA-w82x-wr5m-8q52.json b/advisories/unreviewed/2023/03/GHSA-w82x-wr5m-8q52/GHSA-w82x-wr5m-8q52.json index c21577ac3aa..7912c23f136 100644 --- a/advisories/unreviewed/2023/03/GHSA-w82x-wr5m-8q52/GHSA-w82x-wr5m-8q52.json +++ b/advisories/unreviewed/2023/03/GHSA-w82x-wr5m-8q52/GHSA-w82x-wr5m-8q52.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-w96g-mgv6-rxw4/GHSA-w96g-mgv6-rxw4.json b/advisories/unreviewed/2023/03/GHSA-w96g-mgv6-rxw4/GHSA-w96g-mgv6-rxw4.json index e6170bcb7fb..69e1221be25 100644 --- a/advisories/unreviewed/2023/03/GHSA-w96g-mgv6-rxw4/GHSA-w96g-mgv6-rxw4.json +++ b/advisories/unreviewed/2023/03/GHSA-w96g-mgv6-rxw4/GHSA-w96g-mgv6-rxw4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-2f2p-6v5f-w6gc/GHSA-2f2p-6v5f-w6gc.json b/advisories/unreviewed/2023/04/GHSA-2f2p-6v5f-w6gc/GHSA-2f2p-6v5f-w6gc.json index 1843da33cb7..dec90e45ed4 100644 --- a/advisories/unreviewed/2023/04/GHSA-2f2p-6v5f-w6gc/GHSA-2f2p-6v5f-w6gc.json +++ b/advisories/unreviewed/2023/04/GHSA-2f2p-6v5f-w6gc/GHSA-2f2p-6v5f-w6gc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-2jfh-rvm8-7qg4/GHSA-2jfh-rvm8-7qg4.json b/advisories/unreviewed/2023/04/GHSA-2jfh-rvm8-7qg4/GHSA-2jfh-rvm8-7qg4.json index bcba06f8c02..5f3b07a104a 100644 --- a/advisories/unreviewed/2023/04/GHSA-2jfh-rvm8-7qg4/GHSA-2jfh-rvm8-7qg4.json +++ b/advisories/unreviewed/2023/04/GHSA-2jfh-rvm8-7qg4/GHSA-2jfh-rvm8-7qg4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-4q8x-qfxw-4fg4/GHSA-4q8x-qfxw-4fg4.json b/advisories/unreviewed/2023/04/GHSA-4q8x-qfxw-4fg4/GHSA-4q8x-qfxw-4fg4.json index 71b8e57df31..4e1fae2314d 100644 --- a/advisories/unreviewed/2023/04/GHSA-4q8x-qfxw-4fg4/GHSA-4q8x-qfxw-4fg4.json +++ b/advisories/unreviewed/2023/04/GHSA-4q8x-qfxw-4fg4/GHSA-4q8x-qfxw-4fg4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-56ff-j3fw-2cmr/GHSA-56ff-j3fw-2cmr.json b/advisories/unreviewed/2023/04/GHSA-56ff-j3fw-2cmr/GHSA-56ff-j3fw-2cmr.json index cab5786e08c..16ab3b2c67c 100644 --- a/advisories/unreviewed/2023/04/GHSA-56ff-j3fw-2cmr/GHSA-56ff-j3fw-2cmr.json +++ b/advisories/unreviewed/2023/04/GHSA-56ff-j3fw-2cmr/GHSA-56ff-j3fw-2cmr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-56v8-jwp3-cmmh/GHSA-56v8-jwp3-cmmh.json b/advisories/unreviewed/2023/04/GHSA-56v8-jwp3-cmmh/GHSA-56v8-jwp3-cmmh.json index c7e9618f1a0..b014c810c79 100644 --- a/advisories/unreviewed/2023/04/GHSA-56v8-jwp3-cmmh/GHSA-56v8-jwp3-cmmh.json +++ b/advisories/unreviewed/2023/04/GHSA-56v8-jwp3-cmmh/GHSA-56v8-jwp3-cmmh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-7mqr-6r89-272v/GHSA-7mqr-6r89-272v.json b/advisories/unreviewed/2023/04/GHSA-7mqr-6r89-272v/GHSA-7mqr-6r89-272v.json index 53f00522493..1181bcb316b 100644 --- a/advisories/unreviewed/2023/04/GHSA-7mqr-6r89-272v/GHSA-7mqr-6r89-272v.json +++ b/advisories/unreviewed/2023/04/GHSA-7mqr-6r89-272v/GHSA-7mqr-6r89-272v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-7qvj-p8pj-mfvq/GHSA-7qvj-p8pj-mfvq.json b/advisories/unreviewed/2023/04/GHSA-7qvj-p8pj-mfvq/GHSA-7qvj-p8pj-mfvq.json index 35ec8fa3b62..7d42d34c61d 100644 --- a/advisories/unreviewed/2023/04/GHSA-7qvj-p8pj-mfvq/GHSA-7qvj-p8pj-mfvq.json +++ b/advisories/unreviewed/2023/04/GHSA-7qvj-p8pj-mfvq/GHSA-7qvj-p8pj-mfvq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-8chj-4w27-gc2r/GHSA-8chj-4w27-gc2r.json b/advisories/unreviewed/2023/04/GHSA-8chj-4w27-gc2r/GHSA-8chj-4w27-gc2r.json index 86420f7c4b7..67012f4db16 100644 --- a/advisories/unreviewed/2023/04/GHSA-8chj-4w27-gc2r/GHSA-8chj-4w27-gc2r.json +++ b/advisories/unreviewed/2023/04/GHSA-8chj-4w27-gc2r/GHSA-8chj-4w27-gc2r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-92hj-xmf6-8m47/GHSA-92hj-xmf6-8m47.json b/advisories/unreviewed/2023/04/GHSA-92hj-xmf6-8m47/GHSA-92hj-xmf6-8m47.json index fc1492ac142..58fa19f30f1 100644 --- a/advisories/unreviewed/2023/04/GHSA-92hj-xmf6-8m47/GHSA-92hj-xmf6-8m47.json +++ b/advisories/unreviewed/2023/04/GHSA-92hj-xmf6-8m47/GHSA-92hj-xmf6-8m47.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-9cpg-q9f9-cq47/GHSA-9cpg-q9f9-cq47.json b/advisories/unreviewed/2023/04/GHSA-9cpg-q9f9-cq47/GHSA-9cpg-q9f9-cq47.json index 77fb2c88559..ea3a90a0eff 100644 --- a/advisories/unreviewed/2023/04/GHSA-9cpg-q9f9-cq47/GHSA-9cpg-q9f9-cq47.json +++ b/advisories/unreviewed/2023/04/GHSA-9cpg-q9f9-cq47/GHSA-9cpg-q9f9-cq47.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-9g4c-xm3g-f8hq/GHSA-9g4c-xm3g-f8hq.json b/advisories/unreviewed/2023/04/GHSA-9g4c-xm3g-f8hq/GHSA-9g4c-xm3g-f8hq.json index 6d513f02290..a96945c0ffb 100644 --- a/advisories/unreviewed/2023/04/GHSA-9g4c-xm3g-f8hq/GHSA-9g4c-xm3g-f8hq.json +++ b/advisories/unreviewed/2023/04/GHSA-9g4c-xm3g-f8hq/GHSA-9g4c-xm3g-f8hq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-g4vj-r7jx-86jx/GHSA-g4vj-r7jx-86jx.json b/advisories/unreviewed/2023/04/GHSA-g4vj-r7jx-86jx/GHSA-g4vj-r7jx-86jx.json index 256ef1e8039..310f1f15622 100644 --- a/advisories/unreviewed/2023/04/GHSA-g4vj-r7jx-86jx/GHSA-g4vj-r7jx-86jx.json +++ b/advisories/unreviewed/2023/04/GHSA-g4vj-r7jx-86jx/GHSA-g4vj-r7jx-86jx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-gprg-q8r6-84hw/GHSA-gprg-q8r6-84hw.json b/advisories/unreviewed/2023/04/GHSA-gprg-q8r6-84hw/GHSA-gprg-q8r6-84hw.json index 1b1798d7c74..1c18015dcf9 100644 --- a/advisories/unreviewed/2023/04/GHSA-gprg-q8r6-84hw/GHSA-gprg-q8r6-84hw.json +++ b/advisories/unreviewed/2023/04/GHSA-gprg-q8r6-84hw/GHSA-gprg-q8r6-84hw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-m3hw-qcrg-c646/GHSA-m3hw-qcrg-c646.json b/advisories/unreviewed/2023/04/GHSA-m3hw-qcrg-c646/GHSA-m3hw-qcrg-c646.json index 107260aeffc..fce0d3769f6 100644 --- a/advisories/unreviewed/2023/04/GHSA-m3hw-qcrg-c646/GHSA-m3hw-qcrg-c646.json +++ b/advisories/unreviewed/2023/04/GHSA-m3hw-qcrg-c646/GHSA-m3hw-qcrg-c646.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-m8vg-xvq5-45f2/GHSA-m8vg-xvq5-45f2.json b/advisories/unreviewed/2023/04/GHSA-m8vg-xvq5-45f2/GHSA-m8vg-xvq5-45f2.json index 6b4214fa41b..307837a49be 100644 --- a/advisories/unreviewed/2023/04/GHSA-m8vg-xvq5-45f2/GHSA-m8vg-xvq5-45f2.json +++ b/advisories/unreviewed/2023/04/GHSA-m8vg-xvq5-45f2/GHSA-m8vg-xvq5-45f2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-p2qq-f3cc-2hrf/GHSA-p2qq-f3cc-2hrf.json b/advisories/unreviewed/2023/04/GHSA-p2qq-f3cc-2hrf/GHSA-p2qq-f3cc-2hrf.json index 2f61cd6768c..4cd625f1f05 100644 --- a/advisories/unreviewed/2023/04/GHSA-p2qq-f3cc-2hrf/GHSA-p2qq-f3cc-2hrf.json +++ b/advisories/unreviewed/2023/04/GHSA-p2qq-f3cc-2hrf/GHSA-p2qq-f3cc-2hrf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-pvcj-gmv9-5qjf/GHSA-pvcj-gmv9-5qjf.json b/advisories/unreviewed/2023/04/GHSA-pvcj-gmv9-5qjf/GHSA-pvcj-gmv9-5qjf.json index 722c6f922e2..ebc5f7caf4b 100644 --- a/advisories/unreviewed/2023/04/GHSA-pvcj-gmv9-5qjf/GHSA-pvcj-gmv9-5qjf.json +++ b/advisories/unreviewed/2023/04/GHSA-pvcj-gmv9-5qjf/GHSA-pvcj-gmv9-5qjf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-q7gw-cx2f-mh8f/GHSA-q7gw-cx2f-mh8f.json b/advisories/unreviewed/2023/04/GHSA-q7gw-cx2f-mh8f/GHSA-q7gw-cx2f-mh8f.json index 694ea2501cb..de738404a42 100644 --- a/advisories/unreviewed/2023/04/GHSA-q7gw-cx2f-mh8f/GHSA-q7gw-cx2f-mh8f.json +++ b/advisories/unreviewed/2023/04/GHSA-q7gw-cx2f-mh8f/GHSA-q7gw-cx2f-mh8f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-qvxf-85c9-rwwv/GHSA-qvxf-85c9-rwwv.json b/advisories/unreviewed/2023/04/GHSA-qvxf-85c9-rwwv/GHSA-qvxf-85c9-rwwv.json index 891b02ae0b4..867399dd90d 100644 --- a/advisories/unreviewed/2023/04/GHSA-qvxf-85c9-rwwv/GHSA-qvxf-85c9-rwwv.json +++ b/advisories/unreviewed/2023/04/GHSA-qvxf-85c9-rwwv/GHSA-qvxf-85c9-rwwv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-rfh2-62gc-x7hw/GHSA-rfh2-62gc-x7hw.json b/advisories/unreviewed/2023/04/GHSA-rfh2-62gc-x7hw/GHSA-rfh2-62gc-x7hw.json index 18e6efb1dff..2d00b22c3fe 100644 --- a/advisories/unreviewed/2023/04/GHSA-rfh2-62gc-x7hw/GHSA-rfh2-62gc-x7hw.json +++ b/advisories/unreviewed/2023/04/GHSA-rfh2-62gc-x7hw/GHSA-rfh2-62gc-x7hw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-v5rh-cm7j-gpp6/GHSA-v5rh-cm7j-gpp6.json b/advisories/unreviewed/2023/04/GHSA-v5rh-cm7j-gpp6/GHSA-v5rh-cm7j-gpp6.json index 01011e929e1..7e649d92847 100644 --- a/advisories/unreviewed/2023/04/GHSA-v5rh-cm7j-gpp6/GHSA-v5rh-cm7j-gpp6.json +++ b/advisories/unreviewed/2023/04/GHSA-v5rh-cm7j-gpp6/GHSA-v5rh-cm7j-gpp6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-w5cc-jw53-c2fj/GHSA-w5cc-jw53-c2fj.json b/advisories/unreviewed/2023/04/GHSA-w5cc-jw53-c2fj/GHSA-w5cc-jw53-c2fj.json index 6cc6eda3e49..0b1b0a15d2d 100644 --- a/advisories/unreviewed/2023/04/GHSA-w5cc-jw53-c2fj/GHSA-w5cc-jw53-c2fj.json +++ b/advisories/unreviewed/2023/04/GHSA-w5cc-jw53-c2fj/GHSA-w5cc-jw53-c2fj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-4844-xhp4-vx37/GHSA-4844-xhp4-vx37.json b/advisories/unreviewed/2023/05/GHSA-4844-xhp4-vx37/GHSA-4844-xhp4-vx37.json index d1a577a9d5c..825233f51e5 100644 --- a/advisories/unreviewed/2023/05/GHSA-4844-xhp4-vx37/GHSA-4844-xhp4-vx37.json +++ b/advisories/unreviewed/2023/05/GHSA-4844-xhp4-vx37/GHSA-4844-xhp4-vx37.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-9q2q-93hf-g3jq/GHSA-9q2q-93hf-g3jq.json b/advisories/unreviewed/2023/05/GHSA-9q2q-93hf-g3jq/GHSA-9q2q-93hf-g3jq.json index 2d0e63cbf3f..446a352cb0b 100644 --- a/advisories/unreviewed/2023/05/GHSA-9q2q-93hf-g3jq/GHSA-9q2q-93hf-g3jq.json +++ b/advisories/unreviewed/2023/05/GHSA-9q2q-93hf-g3jq/GHSA-9q2q-93hf-g3jq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-ghph-wprw-47q4/GHSA-ghph-wprw-47q4.json b/advisories/unreviewed/2023/05/GHSA-ghph-wprw-47q4/GHSA-ghph-wprw-47q4.json index 9a54bde5861..26c6044f721 100644 --- a/advisories/unreviewed/2023/05/GHSA-ghph-wprw-47q4/GHSA-ghph-wprw-47q4.json +++ b/advisories/unreviewed/2023/05/GHSA-ghph-wprw-47q4/GHSA-ghph-wprw-47q4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-hcjj-cw6r-35f8/GHSA-hcjj-cw6r-35f8.json b/advisories/unreviewed/2023/05/GHSA-hcjj-cw6r-35f8/GHSA-hcjj-cw6r-35f8.json index 1acb6bd6ba7..ebe33039714 100644 --- a/advisories/unreviewed/2023/05/GHSA-hcjj-cw6r-35f8/GHSA-hcjj-cw6r-35f8.json +++ b/advisories/unreviewed/2023/05/GHSA-hcjj-cw6r-35f8/GHSA-hcjj-cw6r-35f8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-j5pp-6f4w-r5r6/GHSA-j5pp-6f4w-r5r6.json b/advisories/unreviewed/2023/05/GHSA-j5pp-6f4w-r5r6/GHSA-j5pp-6f4w-r5r6.json index 63cb8ac4c03..425421a7881 100644 --- a/advisories/unreviewed/2023/05/GHSA-j5pp-6f4w-r5r6/GHSA-j5pp-6f4w-r5r6.json +++ b/advisories/unreviewed/2023/05/GHSA-j5pp-6f4w-r5r6/GHSA-j5pp-6f4w-r5r6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-j9gj-58qx-h9vw/GHSA-j9gj-58qx-h9vw.json b/advisories/unreviewed/2023/05/GHSA-j9gj-58qx-h9vw/GHSA-j9gj-58qx-h9vw.json index 586978d50b2..f7f1df33ee0 100644 --- a/advisories/unreviewed/2023/05/GHSA-j9gj-58qx-h9vw/GHSA-j9gj-58qx-h9vw.json +++ b/advisories/unreviewed/2023/05/GHSA-j9gj-58qx-h9vw/GHSA-j9gj-58qx-h9vw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-jv36-3qpq-7g23/GHSA-jv36-3qpq-7g23.json b/advisories/unreviewed/2023/05/GHSA-jv36-3qpq-7g23/GHSA-jv36-3qpq-7g23.json index 16ff4c8d1ef..0647613cb6a 100644 --- a/advisories/unreviewed/2023/05/GHSA-jv36-3qpq-7g23/GHSA-jv36-3qpq-7g23.json +++ b/advisories/unreviewed/2023/05/GHSA-jv36-3qpq-7g23/GHSA-jv36-3qpq-7g23.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-qhr2-29wh-7gwf/GHSA-qhr2-29wh-7gwf.json b/advisories/unreviewed/2023/05/GHSA-qhr2-29wh-7gwf/GHSA-qhr2-29wh-7gwf.json index 28ab1160b41..cf89b5e6dd0 100644 --- a/advisories/unreviewed/2023/05/GHSA-qhr2-29wh-7gwf/GHSA-qhr2-29wh-7gwf.json +++ b/advisories/unreviewed/2023/05/GHSA-qhr2-29wh-7gwf/GHSA-qhr2-29wh-7gwf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-rmmq-jh8c-24p5/GHSA-rmmq-jh8c-24p5.json b/advisories/unreviewed/2023/05/GHSA-rmmq-jh8c-24p5/GHSA-rmmq-jh8c-24p5.json index d4db0c564d6..93398f18013 100644 --- a/advisories/unreviewed/2023/05/GHSA-rmmq-jh8c-24p5/GHSA-rmmq-jh8c-24p5.json +++ b/advisories/unreviewed/2023/05/GHSA-rmmq-jh8c-24p5/GHSA-rmmq-jh8c-24p5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-w8mq-qvgq-hhjw/GHSA-w8mq-qvgq-hhjw.json b/advisories/unreviewed/2023/05/GHSA-w8mq-qvgq-hhjw/GHSA-w8mq-qvgq-hhjw.json index 52137e0ac6d..3f349e6358e 100644 --- a/advisories/unreviewed/2023/05/GHSA-w8mq-qvgq-hhjw/GHSA-w8mq-qvgq-hhjw.json +++ b/advisories/unreviewed/2023/05/GHSA-w8mq-qvgq-hhjw/GHSA-w8mq-qvgq-hhjw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-3652-93x3-2rrr/GHSA-3652-93x3-2rrr.json b/advisories/unreviewed/2023/06/GHSA-3652-93x3-2rrr/GHSA-3652-93x3-2rrr.json index f709c910ba6..0a3b8b6b446 100644 --- a/advisories/unreviewed/2023/06/GHSA-3652-93x3-2rrr/GHSA-3652-93x3-2rrr.json +++ b/advisories/unreviewed/2023/06/GHSA-3652-93x3-2rrr/GHSA-3652-93x3-2rrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-5f7f-rfrw-976q/GHSA-5f7f-rfrw-976q.json b/advisories/unreviewed/2023/06/GHSA-5f7f-rfrw-976q/GHSA-5f7f-rfrw-976q.json index f3d00001019..72fe6af8c61 100644 --- a/advisories/unreviewed/2023/06/GHSA-5f7f-rfrw-976q/GHSA-5f7f-rfrw-976q.json +++ b/advisories/unreviewed/2023/06/GHSA-5f7f-rfrw-976q/GHSA-5f7f-rfrw-976q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-65v5-9w4x-xh53/GHSA-65v5-9w4x-xh53.json b/advisories/unreviewed/2023/06/GHSA-65v5-9w4x-xh53/GHSA-65v5-9w4x-xh53.json index 0952eafad6e..351430b78d8 100644 --- a/advisories/unreviewed/2023/06/GHSA-65v5-9w4x-xh53/GHSA-65v5-9w4x-xh53.json +++ b/advisories/unreviewed/2023/06/GHSA-65v5-9w4x-xh53/GHSA-65v5-9w4x-xh53.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-7vvx-qrjq-rx5x/GHSA-7vvx-qrjq-rx5x.json b/advisories/unreviewed/2023/06/GHSA-7vvx-qrjq-rx5x/GHSA-7vvx-qrjq-rx5x.json index 3436bf1b9f8..250de60c841 100644 --- a/advisories/unreviewed/2023/06/GHSA-7vvx-qrjq-rx5x/GHSA-7vvx-qrjq-rx5x.json +++ b/advisories/unreviewed/2023/06/GHSA-7vvx-qrjq-rx5x/GHSA-7vvx-qrjq-rx5x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-9mv8-4v9g-hm48/GHSA-9mv8-4v9g-hm48.json b/advisories/unreviewed/2023/06/GHSA-9mv8-4v9g-hm48/GHSA-9mv8-4v9g-hm48.json index 8e3661fe610..38892d041e4 100644 --- a/advisories/unreviewed/2023/06/GHSA-9mv8-4v9g-hm48/GHSA-9mv8-4v9g-hm48.json +++ b/advisories/unreviewed/2023/06/GHSA-9mv8-4v9g-hm48/GHSA-9mv8-4v9g-hm48.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-g2r6-mg39-w7jm/GHSA-g2r6-mg39-w7jm.json b/advisories/unreviewed/2023/06/GHSA-g2r6-mg39-w7jm/GHSA-g2r6-mg39-w7jm.json index af35c706126..12e3ae72d6d 100644 --- a/advisories/unreviewed/2023/06/GHSA-g2r6-mg39-w7jm/GHSA-g2r6-mg39-w7jm.json +++ b/advisories/unreviewed/2023/06/GHSA-g2r6-mg39-w7jm/GHSA-g2r6-mg39-w7jm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-gqxx-2w9g-jhx9/GHSA-gqxx-2w9g-jhx9.json b/advisories/unreviewed/2023/06/GHSA-gqxx-2w9g-jhx9/GHSA-gqxx-2w9g-jhx9.json index f001720b949..d7a9da5ee1f 100644 --- a/advisories/unreviewed/2023/06/GHSA-gqxx-2w9g-jhx9/GHSA-gqxx-2w9g-jhx9.json +++ b/advisories/unreviewed/2023/06/GHSA-gqxx-2w9g-jhx9/GHSA-gqxx-2w9g-jhx9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-vq4w-gf5m-899r/GHSA-vq4w-gf5m-899r.json b/advisories/unreviewed/2023/06/GHSA-vq4w-gf5m-899r/GHSA-vq4w-gf5m-899r.json index 514e0aa9527..027d6849bca 100644 --- a/advisories/unreviewed/2023/06/GHSA-vq4w-gf5m-899r/GHSA-vq4w-gf5m-899r.json +++ b/advisories/unreviewed/2023/06/GHSA-vq4w-gf5m-899r/GHSA-vq4w-gf5m-899r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-vwhx-3qh6-75xf/GHSA-vwhx-3qh6-75xf.json b/advisories/unreviewed/2023/06/GHSA-vwhx-3qh6-75xf/GHSA-vwhx-3qh6-75xf.json index 449ed276c49..7fccfc41c08 100644 --- a/advisories/unreviewed/2023/06/GHSA-vwhx-3qh6-75xf/GHSA-vwhx-3qh6-75xf.json +++ b/advisories/unreviewed/2023/06/GHSA-vwhx-3qh6-75xf/GHSA-vwhx-3qh6-75xf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-wf3v-g5fj-2649/GHSA-wf3v-g5fj-2649.json b/advisories/unreviewed/2023/06/GHSA-wf3v-g5fj-2649/GHSA-wf3v-g5fj-2649.json index a8f31e77577..899ffe53295 100644 --- a/advisories/unreviewed/2023/06/GHSA-wf3v-g5fj-2649/GHSA-wf3v-g5fj-2649.json +++ b/advisories/unreviewed/2023/06/GHSA-wf3v-g5fj-2649/GHSA-wf3v-g5fj-2649.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-2g94-9xch-xc29/GHSA-2g94-9xch-xc29.json b/advisories/unreviewed/2023/07/GHSA-2g94-9xch-xc29/GHSA-2g94-9xch-xc29.json index 4632dfdcee2..aebd9c4eae8 100644 --- a/advisories/unreviewed/2023/07/GHSA-2g94-9xch-xc29/GHSA-2g94-9xch-xc29.json +++ b/advisories/unreviewed/2023/07/GHSA-2g94-9xch-xc29/GHSA-2g94-9xch-xc29.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-557w-q722-xx5g/GHSA-557w-q722-xx5g.json b/advisories/unreviewed/2023/07/GHSA-557w-q722-xx5g/GHSA-557w-q722-xx5g.json index 4e56d6aa5a0..a49cec53fef 100644 --- a/advisories/unreviewed/2023/07/GHSA-557w-q722-xx5g/GHSA-557w-q722-xx5g.json +++ b/advisories/unreviewed/2023/07/GHSA-557w-q722-xx5g/GHSA-557w-q722-xx5g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-574q-p5x8-j64w/GHSA-574q-p5x8-j64w.json b/advisories/unreviewed/2023/07/GHSA-574q-p5x8-j64w/GHSA-574q-p5x8-j64w.json index 113919ecff9..e17f2ffeb91 100644 --- a/advisories/unreviewed/2023/07/GHSA-574q-p5x8-j64w/GHSA-574q-p5x8-j64w.json +++ b/advisories/unreviewed/2023/07/GHSA-574q-p5x8-j64w/GHSA-574q-p5x8-j64w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-76r6-q666-w6fg/GHSA-76r6-q666-w6fg.json b/advisories/unreviewed/2023/07/GHSA-76r6-q666-w6fg/GHSA-76r6-q666-w6fg.json index 7103ff43004..52d706991a6 100644 --- a/advisories/unreviewed/2023/07/GHSA-76r6-q666-w6fg/GHSA-76r6-q666-w6fg.json +++ b/advisories/unreviewed/2023/07/GHSA-76r6-q666-w6fg/GHSA-76r6-q666-w6fg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-7cf2-f2c4-4qv4/GHSA-7cf2-f2c4-4qv4.json b/advisories/unreviewed/2023/07/GHSA-7cf2-f2c4-4qv4/GHSA-7cf2-f2c4-4qv4.json index 3be93d6e2e6..a192e9e4ffe 100644 --- a/advisories/unreviewed/2023/07/GHSA-7cf2-f2c4-4qv4/GHSA-7cf2-f2c4-4qv4.json +++ b/advisories/unreviewed/2023/07/GHSA-7cf2-f2c4-4qv4/GHSA-7cf2-f2c4-4qv4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-9gm9-9rq7-5mcj/GHSA-9gm9-9rq7-5mcj.json b/advisories/unreviewed/2023/07/GHSA-9gm9-9rq7-5mcj/GHSA-9gm9-9rq7-5mcj.json index 2934de39ee5..106f357976b 100644 --- a/advisories/unreviewed/2023/07/GHSA-9gm9-9rq7-5mcj/GHSA-9gm9-9rq7-5mcj.json +++ b/advisories/unreviewed/2023/07/GHSA-9gm9-9rq7-5mcj/GHSA-9gm9-9rq7-5mcj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-9jc9-7p44-pm6c/GHSA-9jc9-7p44-pm6c.json b/advisories/unreviewed/2023/07/GHSA-9jc9-7p44-pm6c/GHSA-9jc9-7p44-pm6c.json index c0250ea7d0e..d64336211f7 100644 --- a/advisories/unreviewed/2023/07/GHSA-9jc9-7p44-pm6c/GHSA-9jc9-7p44-pm6c.json +++ b/advisories/unreviewed/2023/07/GHSA-9jc9-7p44-pm6c/GHSA-9jc9-7p44-pm6c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-f7p2-4f5g-hfv9/GHSA-f7p2-4f5g-hfv9.json b/advisories/unreviewed/2023/07/GHSA-f7p2-4f5g-hfv9/GHSA-f7p2-4f5g-hfv9.json index a28c560d68a..d470eb656d6 100644 --- a/advisories/unreviewed/2023/07/GHSA-f7p2-4f5g-hfv9/GHSA-f7p2-4f5g-hfv9.json +++ b/advisories/unreviewed/2023/07/GHSA-f7p2-4f5g-hfv9/GHSA-f7p2-4f5g-hfv9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-hpg6-hp9w-vxqp/GHSA-hpg6-hp9w-vxqp.json b/advisories/unreviewed/2023/07/GHSA-hpg6-hp9w-vxqp/GHSA-hpg6-hp9w-vxqp.json index 243e414a05e..031d68b1f4f 100644 --- a/advisories/unreviewed/2023/07/GHSA-hpg6-hp9w-vxqp/GHSA-hpg6-hp9w-vxqp.json +++ b/advisories/unreviewed/2023/07/GHSA-hpg6-hp9w-vxqp/GHSA-hpg6-hp9w-vxqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-jffq-5gqv-qfcx/GHSA-jffq-5gqv-qfcx.json b/advisories/unreviewed/2023/07/GHSA-jffq-5gqv-qfcx/GHSA-jffq-5gqv-qfcx.json index edd5573c551..54795f4faf7 100644 --- a/advisories/unreviewed/2023/07/GHSA-jffq-5gqv-qfcx/GHSA-jffq-5gqv-qfcx.json +++ b/advisories/unreviewed/2023/07/GHSA-jffq-5gqv-qfcx/GHSA-jffq-5gqv-qfcx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-qxpv-rxq7-rg72/GHSA-qxpv-rxq7-rg72.json b/advisories/unreviewed/2023/07/GHSA-qxpv-rxq7-rg72/GHSA-qxpv-rxq7-rg72.json index 14e457a1417..dc0b23ee07a 100644 --- a/advisories/unreviewed/2023/07/GHSA-qxpv-rxq7-rg72/GHSA-qxpv-rxq7-rg72.json +++ b/advisories/unreviewed/2023/07/GHSA-qxpv-rxq7-rg72/GHSA-qxpv-rxq7-rg72.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-rgcq-ff8p-h25q/GHSA-rgcq-ff8p-h25q.json b/advisories/unreviewed/2023/07/GHSA-rgcq-ff8p-h25q/GHSA-rgcq-ff8p-h25q.json index d848d855b7a..8d6aac4aa54 100644 --- a/advisories/unreviewed/2023/07/GHSA-rgcq-ff8p-h25q/GHSA-rgcq-ff8p-h25q.json +++ b/advisories/unreviewed/2023/07/GHSA-rgcq-ff8p-h25q/GHSA-rgcq-ff8p-h25q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-vhf9-5f69-9hjm/GHSA-vhf9-5f69-9hjm.json b/advisories/unreviewed/2023/07/GHSA-vhf9-5f69-9hjm/GHSA-vhf9-5f69-9hjm.json index 3663176e7b6..ade01e0ca0b 100644 --- a/advisories/unreviewed/2023/07/GHSA-vhf9-5f69-9hjm/GHSA-vhf9-5f69-9hjm.json +++ b/advisories/unreviewed/2023/07/GHSA-vhf9-5f69-9hjm/GHSA-vhf9-5f69-9hjm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-2792-x8v5-77wp/GHSA-2792-x8v5-77wp.json b/advisories/unreviewed/2023/08/GHSA-2792-x8v5-77wp/GHSA-2792-x8v5-77wp.json index cbbcfbbc769..69cc21aa562 100644 --- a/advisories/unreviewed/2023/08/GHSA-2792-x8v5-77wp/GHSA-2792-x8v5-77wp.json +++ b/advisories/unreviewed/2023/08/GHSA-2792-x8v5-77wp/GHSA-2792-x8v5-77wp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-3267-6r86-f245/GHSA-3267-6r86-f245.json b/advisories/unreviewed/2023/08/GHSA-3267-6r86-f245/GHSA-3267-6r86-f245.json index 7447e5200fc..fb629ce6469 100644 --- a/advisories/unreviewed/2023/08/GHSA-3267-6r86-f245/GHSA-3267-6r86-f245.json +++ b/advisories/unreviewed/2023/08/GHSA-3267-6r86-f245/GHSA-3267-6r86-f245.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-73qf-r7xg-3ghc/GHSA-73qf-r7xg-3ghc.json b/advisories/unreviewed/2023/08/GHSA-73qf-r7xg-3ghc/GHSA-73qf-r7xg-3ghc.json index 958d0f8f1d3..9b178d83337 100644 --- a/advisories/unreviewed/2023/08/GHSA-73qf-r7xg-3ghc/GHSA-73qf-r7xg-3ghc.json +++ b/advisories/unreviewed/2023/08/GHSA-73qf-r7xg-3ghc/GHSA-73qf-r7xg-3ghc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/08/GHSA-7j4j-pg3j-97q6/GHSA-7j4j-pg3j-97q6.json b/advisories/unreviewed/2023/08/GHSA-7j4j-pg3j-97q6/GHSA-7j4j-pg3j-97q6.json index ce6f3169a3f..33493dfbce2 100644 --- a/advisories/unreviewed/2023/08/GHSA-7j4j-pg3j-97q6/GHSA-7j4j-pg3j-97q6.json +++ b/advisories/unreviewed/2023/08/GHSA-7j4j-pg3j-97q6/GHSA-7j4j-pg3j-97q6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-9fj4-8443-vg2m/GHSA-9fj4-8443-vg2m.json b/advisories/unreviewed/2023/08/GHSA-9fj4-8443-vg2m/GHSA-9fj4-8443-vg2m.json index 2a1e1f938e7..05a760e08ef 100644 --- a/advisories/unreviewed/2023/08/GHSA-9fj4-8443-vg2m/GHSA-9fj4-8443-vg2m.json +++ b/advisories/unreviewed/2023/08/GHSA-9fj4-8443-vg2m/GHSA-9fj4-8443-vg2m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-9rfp-wq3q-rh78/GHSA-9rfp-wq3q-rh78.json b/advisories/unreviewed/2023/08/GHSA-9rfp-wq3q-rh78/GHSA-9rfp-wq3q-rh78.json index 931a1d53d78..1022fbeb379 100644 --- a/advisories/unreviewed/2023/08/GHSA-9rfp-wq3q-rh78/GHSA-9rfp-wq3q-rh78.json +++ b/advisories/unreviewed/2023/08/GHSA-9rfp-wq3q-rh78/GHSA-9rfp-wq3q-rh78.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-h88m-cg6q-8fqm/GHSA-h88m-cg6q-8fqm.json b/advisories/unreviewed/2023/08/GHSA-h88m-cg6q-8fqm/GHSA-h88m-cg6q-8fqm.json index c0dddab22e2..e6d3e94b48d 100644 --- a/advisories/unreviewed/2023/08/GHSA-h88m-cg6q-8fqm/GHSA-h88m-cg6q-8fqm.json +++ b/advisories/unreviewed/2023/08/GHSA-h88m-cg6q-8fqm/GHSA-h88m-cg6q-8fqm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-jrp3-72m5-5jpj/GHSA-jrp3-72m5-5jpj.json b/advisories/unreviewed/2023/08/GHSA-jrp3-72m5-5jpj/GHSA-jrp3-72m5-5jpj.json index 636eeb54a9b..f9aa0d64d90 100644 --- a/advisories/unreviewed/2023/08/GHSA-jrp3-72m5-5jpj/GHSA-jrp3-72m5-5jpj.json +++ b/advisories/unreviewed/2023/08/GHSA-jrp3-72m5-5jpj/GHSA-jrp3-72m5-5jpj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-rh4f-h4j5-8rq9/GHSA-rh4f-h4j5-8rq9.json b/advisories/unreviewed/2023/08/GHSA-rh4f-h4j5-8rq9/GHSA-rh4f-h4j5-8rq9.json index 014de38b944..eb0808939c6 100644 --- a/advisories/unreviewed/2023/08/GHSA-rh4f-h4j5-8rq9/GHSA-rh4f-h4j5-8rq9.json +++ b/advisories/unreviewed/2023/08/GHSA-rh4f-h4j5-8rq9/GHSA-rh4f-h4j5-8rq9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-rr8m-c39g-g72x/GHSA-rr8m-c39g-g72x.json b/advisories/unreviewed/2023/08/GHSA-rr8m-c39g-g72x/GHSA-rr8m-c39g-g72x.json index 152169b71b3..c66b0bc95d4 100644 --- a/advisories/unreviewed/2023/08/GHSA-rr8m-c39g-g72x/GHSA-rr8m-c39g-g72x.json +++ b/advisories/unreviewed/2023/08/GHSA-rr8m-c39g-g72x/GHSA-rr8m-c39g-g72x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-w8hm-59h4-7ff2/GHSA-w8hm-59h4-7ff2.json b/advisories/unreviewed/2023/08/GHSA-w8hm-59h4-7ff2/GHSA-w8hm-59h4-7ff2.json index ab98ca038e3..47accd37578 100644 --- a/advisories/unreviewed/2023/08/GHSA-w8hm-59h4-7ff2/GHSA-w8hm-59h4-7ff2.json +++ b/advisories/unreviewed/2023/08/GHSA-w8hm-59h4-7ff2/GHSA-w8hm-59h4-7ff2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-x6g3-wgpm-qhcq/GHSA-x6g3-wgpm-qhcq.json b/advisories/unreviewed/2023/08/GHSA-x6g3-wgpm-qhcq/GHSA-x6g3-wgpm-qhcq.json index dfceb1842c6..19209db9d45 100644 --- a/advisories/unreviewed/2023/08/GHSA-x6g3-wgpm-qhcq/GHSA-x6g3-wgpm-qhcq.json +++ b/advisories/unreviewed/2023/08/GHSA-x6g3-wgpm-qhcq/GHSA-x6g3-wgpm-qhcq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-27v9-jf76-68p4/GHSA-27v9-jf76-68p4.json b/advisories/unreviewed/2023/09/GHSA-27v9-jf76-68p4/GHSA-27v9-jf76-68p4.json index e200d53c4a2..6aa26b5f68a 100644 --- a/advisories/unreviewed/2023/09/GHSA-27v9-jf76-68p4/GHSA-27v9-jf76-68p4.json +++ b/advisories/unreviewed/2023/09/GHSA-27v9-jf76-68p4/GHSA-27v9-jf76-68p4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-69cm-qhp7-ch23/GHSA-69cm-qhp7-ch23.json b/advisories/unreviewed/2023/09/GHSA-69cm-qhp7-ch23/GHSA-69cm-qhp7-ch23.json index f107eeea3e1..cebc1e9fd99 100644 --- a/advisories/unreviewed/2023/09/GHSA-69cm-qhp7-ch23/GHSA-69cm-qhp7-ch23.json +++ b/advisories/unreviewed/2023/09/GHSA-69cm-qhp7-ch23/GHSA-69cm-qhp7-ch23.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-8rhg-98vw-7qqh/GHSA-8rhg-98vw-7qqh.json b/advisories/unreviewed/2023/09/GHSA-8rhg-98vw-7qqh/GHSA-8rhg-98vw-7qqh.json index 48fe48f6a7b..18c34b66c70 100644 --- a/advisories/unreviewed/2023/09/GHSA-8rhg-98vw-7qqh/GHSA-8rhg-98vw-7qqh.json +++ b/advisories/unreviewed/2023/09/GHSA-8rhg-98vw-7qqh/GHSA-8rhg-98vw-7qqh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-c534-95qp-3jw4/GHSA-c534-95qp-3jw4.json b/advisories/unreviewed/2023/09/GHSA-c534-95qp-3jw4/GHSA-c534-95qp-3jw4.json index af743ab5d3e..099b5df014f 100644 --- a/advisories/unreviewed/2023/09/GHSA-c534-95qp-3jw4/GHSA-c534-95qp-3jw4.json +++ b/advisories/unreviewed/2023/09/GHSA-c534-95qp-3jw4/GHSA-c534-95qp-3jw4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-c8f6-fgc7-qf74/GHSA-c8f6-fgc7-qf74.json b/advisories/unreviewed/2023/09/GHSA-c8f6-fgc7-qf74/GHSA-c8f6-fgc7-qf74.json index 3d73cc7a10d..5d40ecc9d5d 100644 --- a/advisories/unreviewed/2023/09/GHSA-c8f6-fgc7-qf74/GHSA-c8f6-fgc7-qf74.json +++ b/advisories/unreviewed/2023/09/GHSA-c8f6-fgc7-qf74/GHSA-c8f6-fgc7-qf74.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-fx87-2qcr-264f/GHSA-fx87-2qcr-264f.json b/advisories/unreviewed/2023/09/GHSA-fx87-2qcr-264f/GHSA-fx87-2qcr-264f.json index 4e1ac477e5b..d73c1844739 100644 --- a/advisories/unreviewed/2023/09/GHSA-fx87-2qcr-264f/GHSA-fx87-2qcr-264f.json +++ b/advisories/unreviewed/2023/09/GHSA-fx87-2qcr-264f/GHSA-fx87-2qcr-264f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-j495-3vfg-6j5m/GHSA-j495-3vfg-6j5m.json b/advisories/unreviewed/2023/09/GHSA-j495-3vfg-6j5m/GHSA-j495-3vfg-6j5m.json index c8f0521c5fd..cc2fced598d 100644 --- a/advisories/unreviewed/2023/09/GHSA-j495-3vfg-6j5m/GHSA-j495-3vfg-6j5m.json +++ b/advisories/unreviewed/2023/09/GHSA-j495-3vfg-6j5m/GHSA-j495-3vfg-6j5m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-jrp5-w8q4-6m33/GHSA-jrp5-w8q4-6m33.json b/advisories/unreviewed/2023/09/GHSA-jrp5-w8q4-6m33/GHSA-jrp5-w8q4-6m33.json index 243f304e6a5..3a9618ea216 100644 --- a/advisories/unreviewed/2023/09/GHSA-jrp5-w8q4-6m33/GHSA-jrp5-w8q4-6m33.json +++ b/advisories/unreviewed/2023/09/GHSA-jrp5-w8q4-6m33/GHSA-jrp5-w8q4-6m33.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-q37h-x4w3-m9rw/GHSA-q37h-x4w3-m9rw.json b/advisories/unreviewed/2023/09/GHSA-q37h-x4w3-m9rw/GHSA-q37h-x4w3-m9rw.json index 7e1fcf89a57..67f17c29e96 100644 --- a/advisories/unreviewed/2023/09/GHSA-q37h-x4w3-m9rw/GHSA-q37h-x4w3-m9rw.json +++ b/advisories/unreviewed/2023/09/GHSA-q37h-x4w3-m9rw/GHSA-q37h-x4w3-m9rw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-q6jm-c3w4-43r4/GHSA-q6jm-c3w4-43r4.json b/advisories/unreviewed/2023/09/GHSA-q6jm-c3w4-43r4/GHSA-q6jm-c3w4-43r4.json index 84644d1b77c..75c312ffc45 100644 --- a/advisories/unreviewed/2023/09/GHSA-q6jm-c3w4-43r4/GHSA-q6jm-c3w4-43r4.json +++ b/advisories/unreviewed/2023/09/GHSA-q6jm-c3w4-43r4/GHSA-q6jm-c3w4-43r4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-v6j2-97g4-v527/GHSA-v6j2-97g4-v527.json b/advisories/unreviewed/2023/09/GHSA-v6j2-97g4-v527/GHSA-v6j2-97g4-v527.json index 92ef823a85b..fd006868790 100644 --- a/advisories/unreviewed/2023/09/GHSA-v6j2-97g4-v527/GHSA-v6j2-97g4-v527.json +++ b/advisories/unreviewed/2023/09/GHSA-v6j2-97g4-v527/GHSA-v6j2-97g4-v527.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-vgcj-8v54-qjm5/GHSA-vgcj-8v54-qjm5.json b/advisories/unreviewed/2023/09/GHSA-vgcj-8v54-qjm5/GHSA-vgcj-8v54-qjm5.json index 1a0e3955567..c55075cd6c9 100644 --- a/advisories/unreviewed/2023/09/GHSA-vgcj-8v54-qjm5/GHSA-vgcj-8v54-qjm5.json +++ b/advisories/unreviewed/2023/09/GHSA-vgcj-8v54-qjm5/GHSA-vgcj-8v54-qjm5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-vhx8-cppg-v89v/GHSA-vhx8-cppg-v89v.json b/advisories/unreviewed/2023/09/GHSA-vhx8-cppg-v89v/GHSA-vhx8-cppg-v89v.json index 84a3cf57e1f..2924fe9f0da 100644 --- a/advisories/unreviewed/2023/09/GHSA-vhx8-cppg-v89v/GHSA-vhx8-cppg-v89v.json +++ b/advisories/unreviewed/2023/09/GHSA-vhx8-cppg-v89v/GHSA-vhx8-cppg-v89v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-w545-288r-rf3p/GHSA-w545-288r-rf3p.json b/advisories/unreviewed/2023/09/GHSA-w545-288r-rf3p/GHSA-w545-288r-rf3p.json index 4d37624562a..07acfc5a60c 100644 --- a/advisories/unreviewed/2023/09/GHSA-w545-288r-rf3p/GHSA-w545-288r-rf3p.json +++ b/advisories/unreviewed/2023/09/GHSA-w545-288r-rf3p/GHSA-w545-288r-rf3p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-wv8q-whpg-vf5v/GHSA-wv8q-whpg-vf5v.json b/advisories/unreviewed/2023/09/GHSA-wv8q-whpg-vf5v/GHSA-wv8q-whpg-vf5v.json index fe38c9246af..95740af1cb7 100644 --- a/advisories/unreviewed/2023/09/GHSA-wv8q-whpg-vf5v/GHSA-wv8q-whpg-vf5v.json +++ b/advisories/unreviewed/2023/09/GHSA-wv8q-whpg-vf5v/GHSA-wv8q-whpg-vf5v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-37mg-42pw-cvp2/GHSA-37mg-42pw-cvp2.json b/advisories/unreviewed/2023/11/GHSA-37mg-42pw-cvp2/GHSA-37mg-42pw-cvp2.json index df00ad5fb06..5dfe7439343 100644 --- a/advisories/unreviewed/2023/11/GHSA-37mg-42pw-cvp2/GHSA-37mg-42pw-cvp2.json +++ b/advisories/unreviewed/2023/11/GHSA-37mg-42pw-cvp2/GHSA-37mg-42pw-cvp2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-38vg-j2xv-fm9g/GHSA-38vg-j2xv-fm9g.json b/advisories/unreviewed/2023/11/GHSA-38vg-j2xv-fm9g/GHSA-38vg-j2xv-fm9g.json index 316a7e79fa5..28854e4082e 100644 --- a/advisories/unreviewed/2023/11/GHSA-38vg-j2xv-fm9g/GHSA-38vg-j2xv-fm9g.json +++ b/advisories/unreviewed/2023/11/GHSA-38vg-j2xv-fm9g/GHSA-38vg-j2xv-fm9g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-3pfh-v74g-m5vg/GHSA-3pfh-v74g-m5vg.json b/advisories/unreviewed/2023/11/GHSA-3pfh-v74g-m5vg/GHSA-3pfh-v74g-m5vg.json index 129dfc7d54d..c739f2fa36a 100644 --- a/advisories/unreviewed/2023/11/GHSA-3pfh-v74g-m5vg/GHSA-3pfh-v74g-m5vg.json +++ b/advisories/unreviewed/2023/11/GHSA-3pfh-v74g-m5vg/GHSA-3pfh-v74g-m5vg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-48gf-p4m2-h6g7/GHSA-48gf-p4m2-h6g7.json b/advisories/unreviewed/2023/11/GHSA-48gf-p4m2-h6g7/GHSA-48gf-p4m2-h6g7.json index 1297b4af1df..5f9b147d26d 100644 --- a/advisories/unreviewed/2023/11/GHSA-48gf-p4m2-h6g7/GHSA-48gf-p4m2-h6g7.json +++ b/advisories/unreviewed/2023/11/GHSA-48gf-p4m2-h6g7/GHSA-48gf-p4m2-h6g7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-4w8g-cx67-fxgx/GHSA-4w8g-cx67-fxgx.json b/advisories/unreviewed/2023/11/GHSA-4w8g-cx67-fxgx/GHSA-4w8g-cx67-fxgx.json index 4f8fb28e773..8c39c694e79 100644 --- a/advisories/unreviewed/2023/11/GHSA-4w8g-cx67-fxgx/GHSA-4w8g-cx67-fxgx.json +++ b/advisories/unreviewed/2023/11/GHSA-4w8g-cx67-fxgx/GHSA-4w8g-cx67-fxgx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-5wv5-hfhp-m8j4/GHSA-5wv5-hfhp-m8j4.json b/advisories/unreviewed/2023/11/GHSA-5wv5-hfhp-m8j4/GHSA-5wv5-hfhp-m8j4.json index 0c824472aab..2a209590818 100644 --- a/advisories/unreviewed/2023/11/GHSA-5wv5-hfhp-m8j4/GHSA-5wv5-hfhp-m8j4.json +++ b/advisories/unreviewed/2023/11/GHSA-5wv5-hfhp-m8j4/GHSA-5wv5-hfhp-m8j4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-69xw-vqxv-v3g5/GHSA-69xw-vqxv-v3g5.json b/advisories/unreviewed/2023/11/GHSA-69xw-vqxv-v3g5/GHSA-69xw-vqxv-v3g5.json index 456cac0a689..53dca4430c1 100644 --- a/advisories/unreviewed/2023/11/GHSA-69xw-vqxv-v3g5/GHSA-69xw-vqxv-v3g5.json +++ b/advisories/unreviewed/2023/11/GHSA-69xw-vqxv-v3g5/GHSA-69xw-vqxv-v3g5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-6cfj-76qv-55ww/GHSA-6cfj-76qv-55ww.json b/advisories/unreviewed/2023/11/GHSA-6cfj-76qv-55ww/GHSA-6cfj-76qv-55ww.json index 7cd01377004..a18f4cb87be 100644 --- a/advisories/unreviewed/2023/11/GHSA-6cfj-76qv-55ww/GHSA-6cfj-76qv-55ww.json +++ b/advisories/unreviewed/2023/11/GHSA-6cfj-76qv-55ww/GHSA-6cfj-76qv-55ww.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-6gfp-56xh-5xv7/GHSA-6gfp-56xh-5xv7.json b/advisories/unreviewed/2023/11/GHSA-6gfp-56xh-5xv7/GHSA-6gfp-56xh-5xv7.json index 0294f9f52d7..6bf22b86b8e 100644 --- a/advisories/unreviewed/2023/11/GHSA-6gfp-56xh-5xv7/GHSA-6gfp-56xh-5xv7.json +++ b/advisories/unreviewed/2023/11/GHSA-6gfp-56xh-5xv7/GHSA-6gfp-56xh-5xv7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-764w-jhrm-cmvw/GHSA-764w-jhrm-cmvw.json b/advisories/unreviewed/2023/11/GHSA-764w-jhrm-cmvw/GHSA-764w-jhrm-cmvw.json index a15cad3c9d1..4684ffd4ed4 100644 --- a/advisories/unreviewed/2023/11/GHSA-764w-jhrm-cmvw/GHSA-764w-jhrm-cmvw.json +++ b/advisories/unreviewed/2023/11/GHSA-764w-jhrm-cmvw/GHSA-764w-jhrm-cmvw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-7h3x-rv39-x7rm/GHSA-7h3x-rv39-x7rm.json b/advisories/unreviewed/2023/11/GHSA-7h3x-rv39-x7rm/GHSA-7h3x-rv39-x7rm.json index 229cb41ad87..2ea09f41e71 100644 --- a/advisories/unreviewed/2023/11/GHSA-7h3x-rv39-x7rm/GHSA-7h3x-rv39-x7rm.json +++ b/advisories/unreviewed/2023/11/GHSA-7h3x-rv39-x7rm/GHSA-7h3x-rv39-x7rm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-9h2x-9q5j-rf33/GHSA-9h2x-9q5j-rf33.json b/advisories/unreviewed/2023/11/GHSA-9h2x-9q5j-rf33/GHSA-9h2x-9q5j-rf33.json index 7fbdeb12e96..83e9dbe30de 100644 --- a/advisories/unreviewed/2023/11/GHSA-9h2x-9q5j-rf33/GHSA-9h2x-9q5j-rf33.json +++ b/advisories/unreviewed/2023/11/GHSA-9h2x-9q5j-rf33/GHSA-9h2x-9q5j-rf33.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-9hg8-gv7c-hrqj/GHSA-9hg8-gv7c-hrqj.json b/advisories/unreviewed/2023/11/GHSA-9hg8-gv7c-hrqj/GHSA-9hg8-gv7c-hrqj.json index c51ef851295..eb5cde282d2 100644 --- a/advisories/unreviewed/2023/11/GHSA-9hg8-gv7c-hrqj/GHSA-9hg8-gv7c-hrqj.json +++ b/advisories/unreviewed/2023/11/GHSA-9hg8-gv7c-hrqj/GHSA-9hg8-gv7c-hrqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-9j2h-6p55-cjpp/GHSA-9j2h-6p55-cjpp.json b/advisories/unreviewed/2023/11/GHSA-9j2h-6p55-cjpp/GHSA-9j2h-6p55-cjpp.json index 2597be84fd8..591b6fb06b6 100644 --- a/advisories/unreviewed/2023/11/GHSA-9j2h-6p55-cjpp/GHSA-9j2h-6p55-cjpp.json +++ b/advisories/unreviewed/2023/11/GHSA-9j2h-6p55-cjpp/GHSA-9j2h-6p55-cjpp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-9rh3-jvpx-vjch/GHSA-9rh3-jvpx-vjch.json b/advisories/unreviewed/2023/11/GHSA-9rh3-jvpx-vjch/GHSA-9rh3-jvpx-vjch.json index f44d5d5bcc3..8b36b43d1fe 100644 --- a/advisories/unreviewed/2023/11/GHSA-9rh3-jvpx-vjch/GHSA-9rh3-jvpx-vjch.json +++ b/advisories/unreviewed/2023/11/GHSA-9rh3-jvpx-vjch/GHSA-9rh3-jvpx-vjch.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-c5c2-62v4-q5vq/GHSA-c5c2-62v4-q5vq.json b/advisories/unreviewed/2023/11/GHSA-c5c2-62v4-q5vq/GHSA-c5c2-62v4-q5vq.json index 24946bf6d78..61638edf756 100644 --- a/advisories/unreviewed/2023/11/GHSA-c5c2-62v4-q5vq/GHSA-c5c2-62v4-q5vq.json +++ b/advisories/unreviewed/2023/11/GHSA-c5c2-62v4-q5vq/GHSA-c5c2-62v4-q5vq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-c5cf-xxh6-rp65/GHSA-c5cf-xxh6-rp65.json b/advisories/unreviewed/2023/11/GHSA-c5cf-xxh6-rp65/GHSA-c5cf-xxh6-rp65.json index d403cf741d7..31ed1cfdd80 100644 --- a/advisories/unreviewed/2023/11/GHSA-c5cf-xxh6-rp65/GHSA-c5cf-xxh6-rp65.json +++ b/advisories/unreviewed/2023/11/GHSA-c5cf-xxh6-rp65/GHSA-c5cf-xxh6-rp65.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-f2f5-xcrp-m3x6/GHSA-f2f5-xcrp-m3x6.json b/advisories/unreviewed/2023/11/GHSA-f2f5-xcrp-m3x6/GHSA-f2f5-xcrp-m3x6.json index da700fab5fb..5f5d95a64c6 100644 --- a/advisories/unreviewed/2023/11/GHSA-f2f5-xcrp-m3x6/GHSA-f2f5-xcrp-m3x6.json +++ b/advisories/unreviewed/2023/11/GHSA-f2f5-xcrp-m3x6/GHSA-f2f5-xcrp-m3x6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-g96g-hxm2-7qvq/GHSA-g96g-hxm2-7qvq.json b/advisories/unreviewed/2023/11/GHSA-g96g-hxm2-7qvq/GHSA-g96g-hxm2-7qvq.json index 5fb001eb88f..9caaeddecba 100644 --- a/advisories/unreviewed/2023/11/GHSA-g96g-hxm2-7qvq/GHSA-g96g-hxm2-7qvq.json +++ b/advisories/unreviewed/2023/11/GHSA-g96g-hxm2-7qvq/GHSA-g96g-hxm2-7qvq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-gr8p-cq4m-m5pp/GHSA-gr8p-cq4m-m5pp.json b/advisories/unreviewed/2023/11/GHSA-gr8p-cq4m-m5pp/GHSA-gr8p-cq4m-m5pp.json index 212c4a889eb..75ecf7500f8 100644 --- a/advisories/unreviewed/2023/11/GHSA-gr8p-cq4m-m5pp/GHSA-gr8p-cq4m-m5pp.json +++ b/advisories/unreviewed/2023/11/GHSA-gr8p-cq4m-m5pp/GHSA-gr8p-cq4m-m5pp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-hh5p-6f3p-22qm/GHSA-hh5p-6f3p-22qm.json b/advisories/unreviewed/2023/11/GHSA-hh5p-6f3p-22qm/GHSA-hh5p-6f3p-22qm.json index d3a5372ba8f..b9bfe3b2064 100644 --- a/advisories/unreviewed/2023/11/GHSA-hh5p-6f3p-22qm/GHSA-hh5p-6f3p-22qm.json +++ b/advisories/unreviewed/2023/11/GHSA-hh5p-6f3p-22qm/GHSA-hh5p-6f3p-22qm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-m98q-2r5j-2rxg/GHSA-m98q-2r5j-2rxg.json b/advisories/unreviewed/2023/11/GHSA-m98q-2r5j-2rxg/GHSA-m98q-2r5j-2rxg.json index 08e415f6fb6..1decfd1e196 100644 --- a/advisories/unreviewed/2023/11/GHSA-m98q-2r5j-2rxg/GHSA-m98q-2r5j-2rxg.json +++ b/advisories/unreviewed/2023/11/GHSA-m98q-2r5j-2rxg/GHSA-m98q-2r5j-2rxg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-mv6q-6xx6-cmh5/GHSA-mv6q-6xx6-cmh5.json b/advisories/unreviewed/2023/11/GHSA-mv6q-6xx6-cmh5/GHSA-mv6q-6xx6-cmh5.json index dd2b5b0b5d2..4432c86c448 100644 --- a/advisories/unreviewed/2023/11/GHSA-mv6q-6xx6-cmh5/GHSA-mv6q-6xx6-cmh5.json +++ b/advisories/unreviewed/2023/11/GHSA-mv6q-6xx6-cmh5/GHSA-mv6q-6xx6-cmh5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-mwhv-r97r-43pc/GHSA-mwhv-r97r-43pc.json b/advisories/unreviewed/2023/11/GHSA-mwhv-r97r-43pc/GHSA-mwhv-r97r-43pc.json index fe01b4b4e1d..4ab85467481 100644 --- a/advisories/unreviewed/2023/11/GHSA-mwhv-r97r-43pc/GHSA-mwhv-r97r-43pc.json +++ b/advisories/unreviewed/2023/11/GHSA-mwhv-r97r-43pc/GHSA-mwhv-r97r-43pc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-pr5g-9xwm-42qc/GHSA-pr5g-9xwm-42qc.json b/advisories/unreviewed/2023/11/GHSA-pr5g-9xwm-42qc/GHSA-pr5g-9xwm-42qc.json index 97e1ba81b42..2886e35d462 100644 --- a/advisories/unreviewed/2023/11/GHSA-pr5g-9xwm-42qc/GHSA-pr5g-9xwm-42qc.json +++ b/advisories/unreviewed/2023/11/GHSA-pr5g-9xwm-42qc/GHSA-pr5g-9xwm-42qc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-qvh7-wf2p-5vp8/GHSA-qvh7-wf2p-5vp8.json b/advisories/unreviewed/2023/11/GHSA-qvh7-wf2p-5vp8/GHSA-qvh7-wf2p-5vp8.json index af4387156fc..563edf5c9f5 100644 --- a/advisories/unreviewed/2023/11/GHSA-qvh7-wf2p-5vp8/GHSA-qvh7-wf2p-5vp8.json +++ b/advisories/unreviewed/2023/11/GHSA-qvh7-wf2p-5vp8/GHSA-qvh7-wf2p-5vp8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-rwp9-5vgw-8w4x/GHSA-rwp9-5vgw-8w4x.json b/advisories/unreviewed/2023/11/GHSA-rwp9-5vgw-8w4x/GHSA-rwp9-5vgw-8w4x.json index fbaec1d6b35..c3fa0f4eabd 100644 --- a/advisories/unreviewed/2023/11/GHSA-rwp9-5vgw-8w4x/GHSA-rwp9-5vgw-8w4x.json +++ b/advisories/unreviewed/2023/11/GHSA-rwp9-5vgw-8w4x/GHSA-rwp9-5vgw-8w4x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-w69h-jwj5-jm7c/GHSA-w69h-jwj5-jm7c.json b/advisories/unreviewed/2023/11/GHSA-w69h-jwj5-jm7c/GHSA-w69h-jwj5-jm7c.json index e6b6ca6568e..4c3510d9733 100644 --- a/advisories/unreviewed/2023/11/GHSA-w69h-jwj5-jm7c/GHSA-w69h-jwj5-jm7c.json +++ b/advisories/unreviewed/2023/11/GHSA-w69h-jwj5-jm7c/GHSA-w69h-jwj5-jm7c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-wjmc-mrpc-8vmf/GHSA-wjmc-mrpc-8vmf.json b/advisories/unreviewed/2023/11/GHSA-wjmc-mrpc-8vmf/GHSA-wjmc-mrpc-8vmf.json index 6499d4356d0..af836015a81 100644 --- a/advisories/unreviewed/2023/11/GHSA-wjmc-mrpc-8vmf/GHSA-wjmc-mrpc-8vmf.json +++ b/advisories/unreviewed/2023/11/GHSA-wjmc-mrpc-8vmf/GHSA-wjmc-mrpc-8vmf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-x8x4-h4w2-j78g/GHSA-x8x4-h4w2-j78g.json b/advisories/unreviewed/2023/11/GHSA-x8x4-h4w2-j78g/GHSA-x8x4-h4w2-j78g.json index d4fa62e1f01..a12f1f51e6b 100644 --- a/advisories/unreviewed/2023/11/GHSA-x8x4-h4w2-j78g/GHSA-x8x4-h4w2-j78g.json +++ b/advisories/unreviewed/2023/11/GHSA-x8x4-h4w2-j78g/GHSA-x8x4-h4w2-j78g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-xgpc-gxx7-52hw/GHSA-xgpc-gxx7-52hw.json b/advisories/unreviewed/2023/11/GHSA-xgpc-gxx7-52hw/GHSA-xgpc-gxx7-52hw.json index 3827213494d..092c04acd5c 100644 --- a/advisories/unreviewed/2023/11/GHSA-xgpc-gxx7-52hw/GHSA-xgpc-gxx7-52hw.json +++ b/advisories/unreviewed/2023/11/GHSA-xgpc-gxx7-52hw/GHSA-xgpc-gxx7-52hw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-xpfj-6cxg-mxrr/GHSA-xpfj-6cxg-mxrr.json b/advisories/unreviewed/2023/11/GHSA-xpfj-6cxg-mxrr/GHSA-xpfj-6cxg-mxrr.json index d5bcadbc0f8..fe445385420 100644 --- a/advisories/unreviewed/2023/11/GHSA-xpfj-6cxg-mxrr/GHSA-xpfj-6cxg-mxrr.json +++ b/advisories/unreviewed/2023/11/GHSA-xpfj-6cxg-mxrr/GHSA-xpfj-6cxg-mxrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-xx5j-44wr-pgrh/GHSA-xx5j-44wr-pgrh.json b/advisories/unreviewed/2023/11/GHSA-xx5j-44wr-pgrh/GHSA-xx5j-44wr-pgrh.json index 7d6bbafbebf..9fced4dd95e 100644 --- a/advisories/unreviewed/2023/11/GHSA-xx5j-44wr-pgrh/GHSA-xx5j-44wr-pgrh.json +++ b/advisories/unreviewed/2023/11/GHSA-xx5j-44wr-pgrh/GHSA-xx5j-44wr-pgrh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-xx86-qq8v-6h29/GHSA-xx86-qq8v-6h29.json b/advisories/unreviewed/2023/11/GHSA-xx86-qq8v-6h29/GHSA-xx86-qq8v-6h29.json index 533657bd32e..9ce70da26e2 100644 --- a/advisories/unreviewed/2023/11/GHSA-xx86-qq8v-6h29/GHSA-xx86-qq8v-6h29.json +++ b/advisories/unreviewed/2023/11/GHSA-xx86-qq8v-6h29/GHSA-xx86-qq8v-6h29.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-4gwv-75cm-wm4v/GHSA-4gwv-75cm-wm4v.json b/advisories/unreviewed/2023/12/GHSA-4gwv-75cm-wm4v/GHSA-4gwv-75cm-wm4v.json index 714f5867746..4b0a287e049 100644 --- a/advisories/unreviewed/2023/12/GHSA-4gwv-75cm-wm4v/GHSA-4gwv-75cm-wm4v.json +++ b/advisories/unreviewed/2023/12/GHSA-4gwv-75cm-wm4v/GHSA-4gwv-75cm-wm4v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-4jq3-g2q7-4pr6/GHSA-4jq3-g2q7-4pr6.json b/advisories/unreviewed/2023/12/GHSA-4jq3-g2q7-4pr6/GHSA-4jq3-g2q7-4pr6.json index 47e060c1189..909c73af1e2 100644 --- a/advisories/unreviewed/2023/12/GHSA-4jq3-g2q7-4pr6/GHSA-4jq3-g2q7-4pr6.json +++ b/advisories/unreviewed/2023/12/GHSA-4jq3-g2q7-4pr6/GHSA-4jq3-g2q7-4pr6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-5p3m-2m9c-whvw/GHSA-5p3m-2m9c-whvw.json b/advisories/unreviewed/2023/12/GHSA-5p3m-2m9c-whvw/GHSA-5p3m-2m9c-whvw.json index 664f16d58fe..41ef8ea6a2e 100644 --- a/advisories/unreviewed/2023/12/GHSA-5p3m-2m9c-whvw/GHSA-5p3m-2m9c-whvw.json +++ b/advisories/unreviewed/2023/12/GHSA-5p3m-2m9c-whvw/GHSA-5p3m-2m9c-whvw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-68mg-jchw-j7f7/GHSA-68mg-jchw-j7f7.json b/advisories/unreviewed/2023/12/GHSA-68mg-jchw-j7f7/GHSA-68mg-jchw-j7f7.json index eff38a860cd..aeb070f3086 100644 --- a/advisories/unreviewed/2023/12/GHSA-68mg-jchw-j7f7/GHSA-68mg-jchw-j7f7.json +++ b/advisories/unreviewed/2023/12/GHSA-68mg-jchw-j7f7/GHSA-68mg-jchw-j7f7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-6rmr-87cv-5h7f/GHSA-6rmr-87cv-5h7f.json b/advisories/unreviewed/2023/12/GHSA-6rmr-87cv-5h7f/GHSA-6rmr-87cv-5h7f.json index 29835334f9c..c82fa852231 100644 --- a/advisories/unreviewed/2023/12/GHSA-6rmr-87cv-5h7f/GHSA-6rmr-87cv-5h7f.json +++ b/advisories/unreviewed/2023/12/GHSA-6rmr-87cv-5h7f/GHSA-6rmr-87cv-5h7f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-8v5w-3h96-3px9/GHSA-8v5w-3h96-3px9.json b/advisories/unreviewed/2023/12/GHSA-8v5w-3h96-3px9/GHSA-8v5w-3h96-3px9.json index 1b60b2b47b0..b10c55c3bd7 100644 --- a/advisories/unreviewed/2023/12/GHSA-8v5w-3h96-3px9/GHSA-8v5w-3h96-3px9.json +++ b/advisories/unreviewed/2023/12/GHSA-8v5w-3h96-3px9/GHSA-8v5w-3h96-3px9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-9m5x-6848-gc4c/GHSA-9m5x-6848-gc4c.json b/advisories/unreviewed/2023/12/GHSA-9m5x-6848-gc4c/GHSA-9m5x-6848-gc4c.json index 17c69a453e3..78afabae87c 100644 --- a/advisories/unreviewed/2023/12/GHSA-9m5x-6848-gc4c/GHSA-9m5x-6848-gc4c.json +++ b/advisories/unreviewed/2023/12/GHSA-9m5x-6848-gc4c/GHSA-9m5x-6848-gc4c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-fq73-5jcx-23vh/GHSA-fq73-5jcx-23vh.json b/advisories/unreviewed/2023/12/GHSA-fq73-5jcx-23vh/GHSA-fq73-5jcx-23vh.json index 6fffbfa806a..a676a895ed8 100644 --- a/advisories/unreviewed/2023/12/GHSA-fq73-5jcx-23vh/GHSA-fq73-5jcx-23vh.json +++ b/advisories/unreviewed/2023/12/GHSA-fq73-5jcx-23vh/GHSA-fq73-5jcx-23vh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-mgj3-mgvf-x3r8/GHSA-mgj3-mgvf-x3r8.json b/advisories/unreviewed/2023/12/GHSA-mgj3-mgvf-x3r8/GHSA-mgj3-mgvf-x3r8.json index 6f90298a7a5..85fb4929156 100644 --- a/advisories/unreviewed/2023/12/GHSA-mgj3-mgvf-x3r8/GHSA-mgj3-mgvf-x3r8.json +++ b/advisories/unreviewed/2023/12/GHSA-mgj3-mgvf-x3r8/GHSA-mgj3-mgvf-x3r8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-pc2w-444v-gxhc/GHSA-pc2w-444v-gxhc.json b/advisories/unreviewed/2023/12/GHSA-pc2w-444v-gxhc/GHSA-pc2w-444v-gxhc.json index 0e6144ea64e..b73022c2737 100644 --- a/advisories/unreviewed/2023/12/GHSA-pc2w-444v-gxhc/GHSA-pc2w-444v-gxhc.json +++ b/advisories/unreviewed/2023/12/GHSA-pc2w-444v-gxhc/GHSA-pc2w-444v-gxhc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-qmhg-rfwq-j2vh/GHSA-qmhg-rfwq-j2vh.json b/advisories/unreviewed/2023/12/GHSA-qmhg-rfwq-j2vh/GHSA-qmhg-rfwq-j2vh.json index a799366ebf2..b81f119dc70 100644 --- a/advisories/unreviewed/2023/12/GHSA-qmhg-rfwq-j2vh/GHSA-qmhg-rfwq-j2vh.json +++ b/advisories/unreviewed/2023/12/GHSA-qmhg-rfwq-j2vh/GHSA-qmhg-rfwq-j2vh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-r9vv-6834-c7fq/GHSA-r9vv-6834-c7fq.json b/advisories/unreviewed/2023/12/GHSA-r9vv-6834-c7fq/GHSA-r9vv-6834-c7fq.json index 4034ab1f5b3..6c8278a0e15 100644 --- a/advisories/unreviewed/2023/12/GHSA-r9vv-6834-c7fq/GHSA-r9vv-6834-c7fq.json +++ b/advisories/unreviewed/2023/12/GHSA-r9vv-6834-c7fq/GHSA-r9vv-6834-c7fq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-vvj2-xxxq-p34c/GHSA-vvj2-xxxq-p34c.json b/advisories/unreviewed/2023/12/GHSA-vvj2-xxxq-p34c/GHSA-vvj2-xxxq-p34c.json index d784d6e54b5..170a93bcf36 100644 --- a/advisories/unreviewed/2023/12/GHSA-vvj2-xxxq-p34c/GHSA-vvj2-xxxq-p34c.json +++ b/advisories/unreviewed/2023/12/GHSA-vvj2-xxxq-p34c/GHSA-vvj2-xxxq-p34c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-6j2c-47fh-6728/GHSA-6j2c-47fh-6728.json b/advisories/unreviewed/2024/01/GHSA-6j2c-47fh-6728/GHSA-6j2c-47fh-6728.json index 385cbc8852d..f16f9909b59 100644 --- a/advisories/unreviewed/2024/01/GHSA-6j2c-47fh-6728/GHSA-6j2c-47fh-6728.json +++ b/advisories/unreviewed/2024/01/GHSA-6j2c-47fh-6728/GHSA-6j2c-47fh-6728.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-rh5p-x36q-j9gf/GHSA-rh5p-x36q-j9gf.json b/advisories/unreviewed/2024/01/GHSA-rh5p-x36q-j9gf/GHSA-rh5p-x36q-j9gf.json index c6f4480d7a8..9d37317e4d9 100644 --- a/advisories/unreviewed/2024/01/GHSA-rh5p-x36q-j9gf/GHSA-rh5p-x36q-j9gf.json +++ b/advisories/unreviewed/2024/01/GHSA-rh5p-x36q-j9gf/GHSA-rh5p-x36q-j9gf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-vp9f-3rqh-83pc/GHSA-vp9f-3rqh-83pc.json b/advisories/unreviewed/2024/01/GHSA-vp9f-3rqh-83pc/GHSA-vp9f-3rqh-83pc.json index 27449b4b20b..263b839dcaf 100644 --- a/advisories/unreviewed/2024/01/GHSA-vp9f-3rqh-83pc/GHSA-vp9f-3rqh-83pc.json +++ b/advisories/unreviewed/2024/01/GHSA-vp9f-3rqh-83pc/GHSA-vp9f-3rqh-83pc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-xg6g-4cpc-5wf2/GHSA-xg6g-4cpc-5wf2.json b/advisories/unreviewed/2024/01/GHSA-xg6g-4cpc-5wf2/GHSA-xg6g-4cpc-5wf2.json index 59691a70468..749da0281ad 100644 --- a/advisories/unreviewed/2024/01/GHSA-xg6g-4cpc-5wf2/GHSA-xg6g-4cpc-5wf2.json +++ b/advisories/unreviewed/2024/01/GHSA-xg6g-4cpc-5wf2/GHSA-xg6g-4cpc-5wf2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-gccr-qg9r-6mhw/GHSA-gccr-qg9r-6mhw.json b/advisories/unreviewed/2024/02/GHSA-gccr-qg9r-6mhw/GHSA-gccr-qg9r-6mhw.json index a76464acfac..c92f624337b 100644 --- a/advisories/unreviewed/2024/02/GHSA-gccr-qg9r-6mhw/GHSA-gccr-qg9r-6mhw.json +++ b/advisories/unreviewed/2024/02/GHSA-gccr-qg9r-6mhw/GHSA-gccr-qg9r-6mhw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-28f4-f5wq-36wr/GHSA-28f4-f5wq-36wr.json b/advisories/unreviewed/2024/03/GHSA-28f4-f5wq-36wr/GHSA-28f4-f5wq-36wr.json index a531b9307e9..ac0f883be80 100644 --- a/advisories/unreviewed/2024/03/GHSA-28f4-f5wq-36wr/GHSA-28f4-f5wq-36wr.json +++ b/advisories/unreviewed/2024/03/GHSA-28f4-f5wq-36wr/GHSA-28f4-f5wq-36wr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-2gjv-8mpf-hmgr/GHSA-2gjv-8mpf-hmgr.json b/advisories/unreviewed/2024/03/GHSA-2gjv-8mpf-hmgr/GHSA-2gjv-8mpf-hmgr.json index 04ab63311ee..eba9cbd9a17 100644 --- a/advisories/unreviewed/2024/03/GHSA-2gjv-8mpf-hmgr/GHSA-2gjv-8mpf-hmgr.json +++ b/advisories/unreviewed/2024/03/GHSA-2gjv-8mpf-hmgr/GHSA-2gjv-8mpf-hmgr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-2jc7-rj7p-gqwv/GHSA-2jc7-rj7p-gqwv.json b/advisories/unreviewed/2024/03/GHSA-2jc7-rj7p-gqwv/GHSA-2jc7-rj7p-gqwv.json index 0921edc75c3..6d0d1061dcb 100644 --- a/advisories/unreviewed/2024/03/GHSA-2jc7-rj7p-gqwv/GHSA-2jc7-rj7p-gqwv.json +++ b/advisories/unreviewed/2024/03/GHSA-2jc7-rj7p-gqwv/GHSA-2jc7-rj7p-gqwv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-32p2-vr3j-c4gw/GHSA-32p2-vr3j-c4gw.json b/advisories/unreviewed/2024/03/GHSA-32p2-vr3j-c4gw/GHSA-32p2-vr3j-c4gw.json index 86895bbaaeb..7592118818a 100644 --- a/advisories/unreviewed/2024/03/GHSA-32p2-vr3j-c4gw/GHSA-32p2-vr3j-c4gw.json +++ b/advisories/unreviewed/2024/03/GHSA-32p2-vr3j-c4gw/GHSA-32p2-vr3j-c4gw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-35gq-67f6-phh5/GHSA-35gq-67f6-phh5.json b/advisories/unreviewed/2024/03/GHSA-35gq-67f6-phh5/GHSA-35gq-67f6-phh5.json index aa72896032c..1d549f5f382 100644 --- a/advisories/unreviewed/2024/03/GHSA-35gq-67f6-phh5/GHSA-35gq-67f6-phh5.json +++ b/advisories/unreviewed/2024/03/GHSA-35gq-67f6-phh5/GHSA-35gq-67f6-phh5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-4jhg-h526-7c6c/GHSA-4jhg-h526-7c6c.json b/advisories/unreviewed/2024/03/GHSA-4jhg-h526-7c6c/GHSA-4jhg-h526-7c6c.json index fd92641466e..80eac0a0e92 100644 --- a/advisories/unreviewed/2024/03/GHSA-4jhg-h526-7c6c/GHSA-4jhg-h526-7c6c.json +++ b/advisories/unreviewed/2024/03/GHSA-4jhg-h526-7c6c/GHSA-4jhg-h526-7c6c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-6826-vrr5-pj78/GHSA-6826-vrr5-pj78.json b/advisories/unreviewed/2024/03/GHSA-6826-vrr5-pj78/GHSA-6826-vrr5-pj78.json index 56cb08761f0..a5453e5d3de 100644 --- a/advisories/unreviewed/2024/03/GHSA-6826-vrr5-pj78/GHSA-6826-vrr5-pj78.json +++ b/advisories/unreviewed/2024/03/GHSA-6826-vrr5-pj78/GHSA-6826-vrr5-pj78.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-782v-93vg-549q/GHSA-782v-93vg-549q.json b/advisories/unreviewed/2024/03/GHSA-782v-93vg-549q/GHSA-782v-93vg-549q.json index 09d07612e2b..14b9e6f511c 100644 --- a/advisories/unreviewed/2024/03/GHSA-782v-93vg-549q/GHSA-782v-93vg-549q.json +++ b/advisories/unreviewed/2024/03/GHSA-782v-93vg-549q/GHSA-782v-93vg-549q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-7wv7-r7c6-6vxj/GHSA-7wv7-r7c6-6vxj.json b/advisories/unreviewed/2024/03/GHSA-7wv7-r7c6-6vxj/GHSA-7wv7-r7c6-6vxj.json index f8cbda21b88..b7075c4f00e 100644 --- a/advisories/unreviewed/2024/03/GHSA-7wv7-r7c6-6vxj/GHSA-7wv7-r7c6-6vxj.json +++ b/advisories/unreviewed/2024/03/GHSA-7wv7-r7c6-6vxj/GHSA-7wv7-r7c6-6vxj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-8m9r-q2w3-mv25/GHSA-8m9r-q2w3-mv25.json b/advisories/unreviewed/2024/03/GHSA-8m9r-q2w3-mv25/GHSA-8m9r-q2w3-mv25.json index f3f3726c7cf..32be617f9a0 100644 --- a/advisories/unreviewed/2024/03/GHSA-8m9r-q2w3-mv25/GHSA-8m9r-q2w3-mv25.json +++ b/advisories/unreviewed/2024/03/GHSA-8m9r-q2w3-mv25/GHSA-8m9r-q2w3-mv25.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-8q58-m2fq-vx7q/GHSA-8q58-m2fq-vx7q.json b/advisories/unreviewed/2024/03/GHSA-8q58-m2fq-vx7q/GHSA-8q58-m2fq-vx7q.json index 03d24445bde..31ae6bceb6c 100644 --- a/advisories/unreviewed/2024/03/GHSA-8q58-m2fq-vx7q/GHSA-8q58-m2fq-vx7q.json +++ b/advisories/unreviewed/2024/03/GHSA-8q58-m2fq-vx7q/GHSA-8q58-m2fq-vx7q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-9h2h-gpqp-6qgg/GHSA-9h2h-gpqp-6qgg.json b/advisories/unreviewed/2024/03/GHSA-9h2h-gpqp-6qgg/GHSA-9h2h-gpqp-6qgg.json index f52aa15691a..8eb81f9372e 100644 --- a/advisories/unreviewed/2024/03/GHSA-9h2h-gpqp-6qgg/GHSA-9h2h-gpqp-6qgg.json +++ b/advisories/unreviewed/2024/03/GHSA-9h2h-gpqp-6qgg/GHSA-9h2h-gpqp-6qgg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-9v2j-c2x9-mg6g/GHSA-9v2j-c2x9-mg6g.json b/advisories/unreviewed/2024/03/GHSA-9v2j-c2x9-mg6g/GHSA-9v2j-c2x9-mg6g.json index 170cc8925f9..08e456eec5d 100644 --- a/advisories/unreviewed/2024/03/GHSA-9v2j-c2x9-mg6g/GHSA-9v2j-c2x9-mg6g.json +++ b/advisories/unreviewed/2024/03/GHSA-9v2j-c2x9-mg6g/GHSA-9v2j-c2x9-mg6g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-c6xc-566p-8x98/GHSA-c6xc-566p-8x98.json b/advisories/unreviewed/2024/03/GHSA-c6xc-566p-8x98/GHSA-c6xc-566p-8x98.json index ba33eaaa3ae..0490abb4359 100644 --- a/advisories/unreviewed/2024/03/GHSA-c6xc-566p-8x98/GHSA-c6xc-566p-8x98.json +++ b/advisories/unreviewed/2024/03/GHSA-c6xc-566p-8x98/GHSA-c6xc-566p-8x98.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-cr67-8hmx-xg5c/GHSA-cr67-8hmx-xg5c.json b/advisories/unreviewed/2024/03/GHSA-cr67-8hmx-xg5c/GHSA-cr67-8hmx-xg5c.json index 8e29aedbef7..75b64e4d7d9 100644 --- a/advisories/unreviewed/2024/03/GHSA-cr67-8hmx-xg5c/GHSA-cr67-8hmx-xg5c.json +++ b/advisories/unreviewed/2024/03/GHSA-cr67-8hmx-xg5c/GHSA-cr67-8hmx-xg5c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-f24r-grxv-qh73/GHSA-f24r-grxv-qh73.json b/advisories/unreviewed/2024/03/GHSA-f24r-grxv-qh73/GHSA-f24r-grxv-qh73.json index b7e6c219a68..5d4c71762bf 100644 --- a/advisories/unreviewed/2024/03/GHSA-f24r-grxv-qh73/GHSA-f24r-grxv-qh73.json +++ b/advisories/unreviewed/2024/03/GHSA-f24r-grxv-qh73/GHSA-f24r-grxv-qh73.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-fqf7-66f9-wqff/GHSA-fqf7-66f9-wqff.json b/advisories/unreviewed/2024/03/GHSA-fqf7-66f9-wqff/GHSA-fqf7-66f9-wqff.json index 03b6595bd56..042d3d87d43 100644 --- a/advisories/unreviewed/2024/03/GHSA-fqf7-66f9-wqff/GHSA-fqf7-66f9-wqff.json +++ b/advisories/unreviewed/2024/03/GHSA-fqf7-66f9-wqff/GHSA-fqf7-66f9-wqff.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-fqwf-c5xq-hmcf/GHSA-fqwf-c5xq-hmcf.json b/advisories/unreviewed/2024/03/GHSA-fqwf-c5xq-hmcf/GHSA-fqwf-c5xq-hmcf.json index ae6e0c7e9a1..f67f941b74c 100644 --- a/advisories/unreviewed/2024/03/GHSA-fqwf-c5xq-hmcf/GHSA-fqwf-c5xq-hmcf.json +++ b/advisories/unreviewed/2024/03/GHSA-fqwf-c5xq-hmcf/GHSA-fqwf-c5xq-hmcf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-fr96-wc8w-hg4c/GHSA-fr96-wc8w-hg4c.json b/advisories/unreviewed/2024/03/GHSA-fr96-wc8w-hg4c/GHSA-fr96-wc8w-hg4c.json index a7822db4dd6..e278c343f0e 100644 --- a/advisories/unreviewed/2024/03/GHSA-fr96-wc8w-hg4c/GHSA-fr96-wc8w-hg4c.json +++ b/advisories/unreviewed/2024/03/GHSA-fr96-wc8w-hg4c/GHSA-fr96-wc8w-hg4c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-fvj3-jc98-5xq5/GHSA-fvj3-jc98-5xq5.json b/advisories/unreviewed/2024/03/GHSA-fvj3-jc98-5xq5/GHSA-fvj3-jc98-5xq5.json index 20015d4216f..0117bad27ae 100644 --- a/advisories/unreviewed/2024/03/GHSA-fvj3-jc98-5xq5/GHSA-fvj3-jc98-5xq5.json +++ b/advisories/unreviewed/2024/03/GHSA-fvj3-jc98-5xq5/GHSA-fvj3-jc98-5xq5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-gwcc-j6r9-59p8/GHSA-gwcc-j6r9-59p8.json b/advisories/unreviewed/2024/03/GHSA-gwcc-j6r9-59p8/GHSA-gwcc-j6r9-59p8.json index d7bf68d2271..2c5ce7408e4 100644 --- a/advisories/unreviewed/2024/03/GHSA-gwcc-j6r9-59p8/GHSA-gwcc-j6r9-59p8.json +++ b/advisories/unreviewed/2024/03/GHSA-gwcc-j6r9-59p8/GHSA-gwcc-j6r9-59p8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-h396-qp5c-h728/GHSA-h396-qp5c-h728.json b/advisories/unreviewed/2024/03/GHSA-h396-qp5c-h728/GHSA-h396-qp5c-h728.json index 79875f93ca2..2cb98e5fb8a 100644 --- a/advisories/unreviewed/2024/03/GHSA-h396-qp5c-h728/GHSA-h396-qp5c-h728.json +++ b/advisories/unreviewed/2024/03/GHSA-h396-qp5c-h728/GHSA-h396-qp5c-h728.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-hhx8-g69h-8rqr/GHSA-hhx8-g69h-8rqr.json b/advisories/unreviewed/2024/03/GHSA-hhx8-g69h-8rqr/GHSA-hhx8-g69h-8rqr.json index 72de5d1e5c2..f945602b402 100644 --- a/advisories/unreviewed/2024/03/GHSA-hhx8-g69h-8rqr/GHSA-hhx8-g69h-8rqr.json +++ b/advisories/unreviewed/2024/03/GHSA-hhx8-g69h-8rqr/GHSA-hhx8-g69h-8rqr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-j4v2-46x2-2r5q/GHSA-j4v2-46x2-2r5q.json b/advisories/unreviewed/2024/03/GHSA-j4v2-46x2-2r5q/GHSA-j4v2-46x2-2r5q.json index 14d10d21963..ed4da7709f2 100644 --- a/advisories/unreviewed/2024/03/GHSA-j4v2-46x2-2r5q/GHSA-j4v2-46x2-2r5q.json +++ b/advisories/unreviewed/2024/03/GHSA-j4v2-46x2-2r5q/GHSA-j4v2-46x2-2r5q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-j6w7-v73w-6pw3/GHSA-j6w7-v73w-6pw3.json b/advisories/unreviewed/2024/03/GHSA-j6w7-v73w-6pw3/GHSA-j6w7-v73w-6pw3.json index c1264f97514..05f3f8f3688 100644 --- a/advisories/unreviewed/2024/03/GHSA-j6w7-v73w-6pw3/GHSA-j6w7-v73w-6pw3.json +++ b/advisories/unreviewed/2024/03/GHSA-j6w7-v73w-6pw3/GHSA-j6w7-v73w-6pw3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-m26f-2hcm-4fw2/GHSA-m26f-2hcm-4fw2.json b/advisories/unreviewed/2024/03/GHSA-m26f-2hcm-4fw2/GHSA-m26f-2hcm-4fw2.json index f528e634fb2..b47981c56ab 100644 --- a/advisories/unreviewed/2024/03/GHSA-m26f-2hcm-4fw2/GHSA-m26f-2hcm-4fw2.json +++ b/advisories/unreviewed/2024/03/GHSA-m26f-2hcm-4fw2/GHSA-m26f-2hcm-4fw2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-mw2p-r2fm-9p6g/GHSA-mw2p-r2fm-9p6g.json b/advisories/unreviewed/2024/03/GHSA-mw2p-r2fm-9p6g/GHSA-mw2p-r2fm-9p6g.json index b7b3d6a9c53..57a7994785e 100644 --- a/advisories/unreviewed/2024/03/GHSA-mw2p-r2fm-9p6g/GHSA-mw2p-r2fm-9p6g.json +++ b/advisories/unreviewed/2024/03/GHSA-mw2p-r2fm-9p6g/GHSA-mw2p-r2fm-9p6g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-pm5x-67pp-5cc7/GHSA-pm5x-67pp-5cc7.json b/advisories/unreviewed/2024/03/GHSA-pm5x-67pp-5cc7/GHSA-pm5x-67pp-5cc7.json index 0aa7b6b21a1..5a60916d6cc 100644 --- a/advisories/unreviewed/2024/03/GHSA-pm5x-67pp-5cc7/GHSA-pm5x-67pp-5cc7.json +++ b/advisories/unreviewed/2024/03/GHSA-pm5x-67pp-5cc7/GHSA-pm5x-67pp-5cc7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-pprg-rj4x-j7w4/GHSA-pprg-rj4x-j7w4.json b/advisories/unreviewed/2024/03/GHSA-pprg-rj4x-j7w4/GHSA-pprg-rj4x-j7w4.json index 0c64c20e821..9c51103c6c5 100644 --- a/advisories/unreviewed/2024/03/GHSA-pprg-rj4x-j7w4/GHSA-pprg-rj4x-j7w4.json +++ b/advisories/unreviewed/2024/03/GHSA-pprg-rj4x-j7w4/GHSA-pprg-rj4x-j7w4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-q3f6-347p-3qc9/GHSA-q3f6-347p-3qc9.json b/advisories/unreviewed/2024/03/GHSA-q3f6-347p-3qc9/GHSA-q3f6-347p-3qc9.json index 41f5f5a4391..f0ef4cbea74 100644 --- a/advisories/unreviewed/2024/03/GHSA-q3f6-347p-3qc9/GHSA-q3f6-347p-3qc9.json +++ b/advisories/unreviewed/2024/03/GHSA-q3f6-347p-3qc9/GHSA-q3f6-347p-3qc9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-q5gv-8p63-3qrr/GHSA-q5gv-8p63-3qrr.json b/advisories/unreviewed/2024/03/GHSA-q5gv-8p63-3qrr/GHSA-q5gv-8p63-3qrr.json index 03df73985d2..31996f127cf 100644 --- a/advisories/unreviewed/2024/03/GHSA-q5gv-8p63-3qrr/GHSA-q5gv-8p63-3qrr.json +++ b/advisories/unreviewed/2024/03/GHSA-q5gv-8p63-3qrr/GHSA-q5gv-8p63-3qrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-qvq4-5qf4-mpxm/GHSA-qvq4-5qf4-mpxm.json b/advisories/unreviewed/2024/03/GHSA-qvq4-5qf4-mpxm/GHSA-qvq4-5qf4-mpxm.json index 1b4d0e7c4e2..4ce98429fca 100644 --- a/advisories/unreviewed/2024/03/GHSA-qvq4-5qf4-mpxm/GHSA-qvq4-5qf4-mpxm.json +++ b/advisories/unreviewed/2024/03/GHSA-qvq4-5qf4-mpxm/GHSA-qvq4-5qf4-mpxm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-qx2q-rhgv-qcr8/GHSA-qx2q-rhgv-qcr8.json b/advisories/unreviewed/2024/03/GHSA-qx2q-rhgv-qcr8/GHSA-qx2q-rhgv-qcr8.json index 71d737e435f..6399040bb04 100644 --- a/advisories/unreviewed/2024/03/GHSA-qx2q-rhgv-qcr8/GHSA-qx2q-rhgv-qcr8.json +++ b/advisories/unreviewed/2024/03/GHSA-qx2q-rhgv-qcr8/GHSA-qx2q-rhgv-qcr8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-r2xx-gprx-q489/GHSA-r2xx-gprx-q489.json b/advisories/unreviewed/2024/03/GHSA-r2xx-gprx-q489/GHSA-r2xx-gprx-q489.json index b64c644799e..c723b6766ef 100644 --- a/advisories/unreviewed/2024/03/GHSA-r2xx-gprx-q489/GHSA-r2xx-gprx-q489.json +++ b/advisories/unreviewed/2024/03/GHSA-r2xx-gprx-q489/GHSA-r2xx-gprx-q489.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-rm34-2767-5m5f/GHSA-rm34-2767-5m5f.json b/advisories/unreviewed/2024/03/GHSA-rm34-2767-5m5f/GHSA-rm34-2767-5m5f.json index 7fb8c2cb0f1..b7edb50adfd 100644 --- a/advisories/unreviewed/2024/03/GHSA-rm34-2767-5m5f/GHSA-rm34-2767-5m5f.json +++ b/advisories/unreviewed/2024/03/GHSA-rm34-2767-5m5f/GHSA-rm34-2767-5m5f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-rpqx-wxvq-jh8m/GHSA-rpqx-wxvq-jh8m.json b/advisories/unreviewed/2024/03/GHSA-rpqx-wxvq-jh8m/GHSA-rpqx-wxvq-jh8m.json index b030620c0f1..31b40ad8d6d 100644 --- a/advisories/unreviewed/2024/03/GHSA-rpqx-wxvq-jh8m/GHSA-rpqx-wxvq-jh8m.json +++ b/advisories/unreviewed/2024/03/GHSA-rpqx-wxvq-jh8m/GHSA-rpqx-wxvq-jh8m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-v5r4-gjfm-m9v2/GHSA-v5r4-gjfm-m9v2.json b/advisories/unreviewed/2024/03/GHSA-v5r4-gjfm-m9v2/GHSA-v5r4-gjfm-m9v2.json index 708d74b854a..fbb644da99b 100644 --- a/advisories/unreviewed/2024/03/GHSA-v5r4-gjfm-m9v2/GHSA-v5r4-gjfm-m9v2.json +++ b/advisories/unreviewed/2024/03/GHSA-v5r4-gjfm-m9v2/GHSA-v5r4-gjfm-m9v2.json @@ -7,12 +7,8 @@ "CVE-2024-26628" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Fix lock dependency warning\n\n======================================================\nWARNING: possible circular locking dependency detected\n6.5.0-kfd-fkuehlin #276 Not tainted\n------------------------------------------------------\nkworker/8:2/2676 is trying to acquire lock:\nffff9435aae95c88 ((work_completion)(&svm_bo->eviction_work)){+.+.}-{0:0}, at: __flush_work+0x52/0x550\n\nbut task is already holding lock:\nffff9435cd8e1720 (&svms->lock){+.+.}-{3:3}, at: svm_range_deferred_list_work+0xe8/0x340 [amdgpu]\n\nwhich lock already depends on the new lock.\n\nthe existing dependency chain (in reverse order) is:\n\n-> #2 (&svms->lock){+.+.}-{3:3}:\n __mutex_lock+0x97/0xd30\n kfd_ioctl_alloc_memory_of_gpu+0x6d/0x3c0 [amdgpu]\n kfd_ioctl+0x1b2/0x5d0 [amdgpu]\n __x64_sys_ioctl+0x86/0xc0\n do_syscall_64+0x39/0x80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\n-> #1 (&mm->mmap_lock){++++}-{3:3}:\n down_read+0x42/0x160\n svm_range_evict_svm_bo_worker+0x8b/0x340 [amdgpu]\n process_one_work+0x27a/0x540\n worker_thread+0x53/0x3e0\n kthread+0xeb/0x120\n ret_from_fork+0x31/0x50\n ret_from_fork_asm+0x11/0x20\n\n-> #0 ((work_completion)(&svm_bo->eviction_work)){+.+.}-{0:0}:\n __lock_acquire+0x1426/0x2200\n lock_acquire+0xc1/0x2b0\n __flush_work+0x80/0x550\n __cancel_work_timer+0x109/0x190\n svm_range_bo_release+0xdc/0x1c0 [amdgpu]\n svm_range_free+0x175/0x180 [amdgpu]\n svm_range_deferred_list_work+0x15d/0x340 [amdgpu]\n process_one_work+0x27a/0x540\n worker_thread+0x53/0x3e0\n kthread+0xeb/0x120\n ret_from_fork+0x31/0x50\n ret_from_fork_asm+0x11/0x20\n\nother info that might help us debug this:\n\nChain exists of:\n (work_completion)(&svm_bo->eviction_work) --> &mm->mmap_lock --> &svms->lock\n\n Possible unsafe locking scenario:\n\n CPU0 CPU1\n ---- ----\n lock(&svms->lock);\n lock(&mm->mmap_lock);\n lock(&svms->lock);\n lock((work_completion)(&svm_bo->eviction_work));\n\nI believe this cannot really lead to a deadlock in practice, because\nsvm_range_evict_svm_bo_worker only takes the mmap_read_lock if the BO\nrefcount is non-0. That means it's impossible that svm_range_bo_release\nis running concurrently. However, there is no good way to annotate this.\n\nTo avoid the problem, take a BO reference in\nsvm_range_schedule_evict_svm_bo instead of in the worker. That way it's\nimpossible for a BO to get freed while eviction work is pending and the\ncancel_work_sync call in svm_range_bo_release can be eliminated.\n\nv2: Use svm_bo_ref_unless_zero and explained why that's safe. Also\nremoved redundant checks that are already done in\namdkfd_fence_enable_signaling.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-v797-jg7x-7796/GHSA-v797-jg7x-7796.json b/advisories/unreviewed/2024/03/GHSA-v797-jg7x-7796/GHSA-v797-jg7x-7796.json index f0fa60778c3..d94c3aea300 100644 --- a/advisories/unreviewed/2024/03/GHSA-v797-jg7x-7796/GHSA-v797-jg7x-7796.json +++ b/advisories/unreviewed/2024/03/GHSA-v797-jg7x-7796/GHSA-v797-jg7x-7796.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-w44h-wfp7-qpq7/GHSA-w44h-wfp7-qpq7.json b/advisories/unreviewed/2024/03/GHSA-w44h-wfp7-qpq7/GHSA-w44h-wfp7-qpq7.json index 4327693f949..3e1f3037268 100644 --- a/advisories/unreviewed/2024/03/GHSA-w44h-wfp7-qpq7/GHSA-w44h-wfp7-qpq7.json +++ b/advisories/unreviewed/2024/03/GHSA-w44h-wfp7-qpq7/GHSA-w44h-wfp7-qpq7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-w56w-4mw9-32p3/GHSA-w56w-4mw9-32p3.json b/advisories/unreviewed/2024/03/GHSA-w56w-4mw9-32p3/GHSA-w56w-4mw9-32p3.json index a1d8661bf05..5aa8e5b88fc 100644 --- a/advisories/unreviewed/2024/03/GHSA-w56w-4mw9-32p3/GHSA-w56w-4mw9-32p3.json +++ b/advisories/unreviewed/2024/03/GHSA-w56w-4mw9-32p3/GHSA-w56w-4mw9-32p3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-w7w6-42mw-922h/GHSA-w7w6-42mw-922h.json b/advisories/unreviewed/2024/03/GHSA-w7w6-42mw-922h/GHSA-w7w6-42mw-922h.json index dbc50dcc414..b39ced506cb 100644 --- a/advisories/unreviewed/2024/03/GHSA-w7w6-42mw-922h/GHSA-w7w6-42mw-922h.json +++ b/advisories/unreviewed/2024/03/GHSA-w7w6-42mw-922h/GHSA-w7w6-42mw-922h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-whxq-h93c-wvrx/GHSA-whxq-h93c-wvrx.json b/advisories/unreviewed/2024/03/GHSA-whxq-h93c-wvrx/GHSA-whxq-h93c-wvrx.json index 6991b2bc951..9eedbd2f245 100644 --- a/advisories/unreviewed/2024/03/GHSA-whxq-h93c-wvrx/GHSA-whxq-h93c-wvrx.json +++ b/advisories/unreviewed/2024/03/GHSA-whxq-h93c-wvrx/GHSA-whxq-h93c-wvrx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-wwf3-3r88-2q8v/GHSA-wwf3-3r88-2q8v.json b/advisories/unreviewed/2024/03/GHSA-wwf3-3r88-2q8v/GHSA-wwf3-3r88-2q8v.json index 1689262021e..b9ea7d408d1 100644 --- a/advisories/unreviewed/2024/03/GHSA-wwf3-3r88-2q8v/GHSA-wwf3-3r88-2q8v.json +++ b/advisories/unreviewed/2024/03/GHSA-wwf3-3r88-2q8v/GHSA-wwf3-3r88-2q8v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",