diff --git a/advisories/github-reviewed/2017/10/GHSA-5726-g6r9-5f22/GHSA-5726-g6r9-5f22.json b/advisories/github-reviewed/2017/10/GHSA-5726-g6r9-5f22/GHSA-5726-g6r9-5f22.json index 7a7c5036618..f04bbe2c357 100644 --- a/advisories/github-reviewed/2017/10/GHSA-5726-g6r9-5f22/GHSA-5726-g6r9-5f22.json +++ b/advisories/github-reviewed/2017/10/GHSA-5726-g6r9-5f22/GHSA-5726-g6r9-5f22.json @@ -8,9 +8,7 @@ ], "summary": "Potential for Script Injection in syntax-error", "details": "Versions of `syntax-error` prior to 1.1.1 are affected by a cross-site scripting vulnerability which may allow a malicious file to execute code when browserified. \n\n## Recommendation\n\nUpdate to version 1.1.1 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-5j3g-jfq3-7jwx/GHSA-5j3g-jfq3-7jwx.json b/advisories/github-reviewed/2017/10/GHSA-5j3g-jfq3-7jwx/GHSA-5j3g-jfq3-7jwx.json index 23f93f12318..afea3e621d8 100644 --- a/advisories/github-reviewed/2017/10/GHSA-5j3g-jfq3-7jwx/GHSA-5j3g-jfq3-7jwx.json +++ b/advisories/github-reviewed/2017/10/GHSA-5j3g-jfq3-7jwx/GHSA-5j3g-jfq3-7jwx.json @@ -8,9 +8,7 @@ ], "summary": "Arbitrary JavaScript Execution in bassmaster", "details": "A vulnerability exists in bassmaster <= 1.5.1 that allows for an attacker to provide arbitrary JavaScript that is then executed server side via eval.\n\n\n## Recommendation\n\nUpdate to bassmaster version 1.5.2 or greater.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/06/GHSA-4662-j96g-mv46/GHSA-4662-j96g-mv46.json b/advisories/github-reviewed/2018/06/GHSA-4662-j96g-mv46/GHSA-4662-j96g-mv46.json index be080b38ad0..b0ab3b3ca67 100644 --- a/advisories/github-reviewed/2018/06/GHSA-4662-j96g-mv46/GHSA-4662-j96g-mv46.json +++ b/advisories/github-reviewed/2018/06/GHSA-4662-j96g-mv46/GHSA-4662-j96g-mv46.json @@ -8,9 +8,7 @@ ], "summary": "Arbitrary Code Injection in reduce-css-calc", "details": "Affected versions of `reduce-css-calc` pass input directly to `eval`. If user input is passed into the calc function, this may result in cross-site scripting on the browser, or remote code execution on the server.\n\n## Proof of Concept\n\n```\nconst reduceCSSCalc = require('reduce-css-calc');\nconsole.log(reduceCSSCalc(`calc( (Buffer(10000)))`));\nconsole.log(reduceCSSCalc(`calc( (global['fs'] = require('fs')))`));\nconsole.log(reduceCSSCalc(`calc( (fs['readFileSync'](\"/etc/passwd\", \"utf-8\")))`));\n```\n\n\n\n## Recommendation\n\nUpdate to version 1.2.5 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/07/GHSA-69mv-3642-wj3w/GHSA-69mv-3642-wj3w.json b/advisories/github-reviewed/2018/07/GHSA-69mv-3642-wj3w/GHSA-69mv-3642-wj3w.json index 236a054daf3..d870c350848 100644 --- a/advisories/github-reviewed/2018/07/GHSA-69mv-3642-wj3w/GHSA-69mv-3642-wj3w.json +++ b/advisories/github-reviewed/2018/07/GHSA-69mv-3642-wj3w/GHSA-69mv-3642-wj3w.json @@ -9,9 +9,7 @@ ], "summary": "Low severity vulnerability that affects sensu", "details": "The sensu rubygem prior to version 1.2.0 contains a CWE-522 (Insufficiently Protected Credentials) flaw that can result in sensitive configuration data (e.g. passwords) being logged in clear-text. \n\nUsers are advised to upgrade to rubygem version 1.2.1 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -68,9 +66,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:18:47Z", diff --git a/advisories/github-reviewed/2018/08/GHSA-44vc-fpcg-5cc5/GHSA-44vc-fpcg-5cc5.json b/advisories/github-reviewed/2018/08/GHSA-44vc-fpcg-5cc5/GHSA-44vc-fpcg-5cc5.json index cacbde41298..4180094d39b 100644 --- a/advisories/github-reviewed/2018/08/GHSA-44vc-fpcg-5cc5/GHSA-44vc-fpcg-5cc5.json +++ b/advisories/github-reviewed/2018/08/GHSA-44vc-fpcg-5cc5/GHSA-44vc-fpcg-5cc5.json @@ -4,14 +4,10 @@ "modified": "2020-06-16T21:30:40Z", "published": "2018-08-08T22:29:49Z", "withdrawn": "2020-06-16T20:57:19Z", - "aliases": [ - - ], + "aliases": [], "summary": "Moderate severity vulnerability that affects safemode", "details": "Withdrawn, accidental duplicate publish.\n\nThe Safemode gem before 1.2.4 for Ruby, when initialized with a delegate object that is a Rails controller, allows context-dependent attackers to obtain sensitive information via the inspect method.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-16T20:57:19Z", diff --git a/advisories/github-reviewed/2018/08/GHSA-4j59-hfw6-6w7h/GHSA-4j59-hfw6-6w7h.json b/advisories/github-reviewed/2018/08/GHSA-4j59-hfw6-6w7h/GHSA-4j59-hfw6-6w7h.json index a7c4aedc146..a27fd4ad060 100644 --- a/advisories/github-reviewed/2018/08/GHSA-4j59-hfw6-6w7h/GHSA-4j59-hfw6-6w7h.json +++ b/advisories/github-reviewed/2018/08/GHSA-4j59-hfw6-6w7h/GHSA-4j59-hfw6-6w7h.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in cmake", "details": "Affected versions of `cmake` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `cmake`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available, or installing the cmake binaries via a system package manager, such as `apt-get`.\n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/09/GHSA-544j-77x9-h938/GHSA-544j-77x9-h938.json b/advisories/github-reviewed/2018/09/GHSA-544j-77x9-h938/GHSA-544j-77x9-h938.json index 7741d0a7b24..321fde7ec19 100644 --- a/advisories/github-reviewed/2018/09/GHSA-544j-77x9-h938/GHSA-544j-77x9-h938.json +++ b/advisories/github-reviewed/2018/09/GHSA-544j-77x9-h938/GHSA-544j-77x9-h938.json @@ -4,14 +4,10 @@ "modified": "2021-12-03T14:12:20Z", "published": "2018-09-17T21:53:30Z", "withdrawn": "2020-06-16T20:59:59Z", - "aliases": [ - - ], + "aliases": [], "summary": "Moderate severity vulnerability that affects actionpack", "details": "Withdrawn, accidental duplicate publish.\n\nactionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Rails 4.x before 4.2.5.1 and 5.x before 5.0.0.beta1.1 allows remote attackers to cause a denial of service (superfluous caching and memory consumption) by leveraging an application's use of a wildcard controller route.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -69,9 +65,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-16T20:59:59Z", diff --git a/advisories/github-reviewed/2018/09/GHSA-5xmj-wm96-fmw8/GHSA-5xmj-wm96-fmw8.json b/advisories/github-reviewed/2018/09/GHSA-5xmj-wm96-fmw8/GHSA-5xmj-wm96-fmw8.json index d5a8341935f..12fcfc9e412 100644 --- a/advisories/github-reviewed/2018/09/GHSA-5xmj-wm96-fmw8/GHSA-5xmj-wm96-fmw8.json +++ b/advisories/github-reviewed/2018/09/GHSA-5xmj-wm96-fmw8/GHSA-5xmj-wm96-fmw8.json @@ -4,14 +4,10 @@ "modified": "2020-06-16T21:38:53Z", "published": "2018-09-17T21:54:37Z", "withdrawn": "2020-06-16T21:17:39Z", - "aliases": [ - - ], + "aliases": [], "summary": "Moderate severity vulnerability that affects actionpack", "details": "Withdrawn, accidental duplicate publish.\n\nDirectory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via vectors involving a \\ (backslash) character, a similar issue to CVE-2014-7818.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -82,9 +78,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:17:39Z", diff --git a/advisories/github-reviewed/2018/09/GHSA-6834-r92f-jj42/GHSA-6834-r92f-jj42.json b/advisories/github-reviewed/2018/09/GHSA-6834-r92f-jj42/GHSA-6834-r92f-jj42.json index ff0aeaeb419..00f8a57ee4c 100644 --- a/advisories/github-reviewed/2018/09/GHSA-6834-r92f-jj42/GHSA-6834-r92f-jj42.json +++ b/advisories/github-reviewed/2018/09/GHSA-6834-r92f-jj42/GHSA-6834-r92f-jj42.json @@ -4,14 +4,10 @@ "modified": "2021-12-03T14:23:09Z", "published": "2018-09-17T21:55:54Z", "withdrawn": "2020-06-16T21:18:20Z", - "aliases": [ - - ], + "aliases": [], "summary": "Moderate severity vulnerability that affects actionview", "details": "Withdrawn, accidental duplicate publish.\n\nDirectory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -69,9 +65,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:18:20Z", diff --git a/advisories/github-reviewed/2018/10/GHSA-4mv7-cq75-3qjm/GHSA-4mv7-cq75-3qjm.json b/advisories/github-reviewed/2018/10/GHSA-4mv7-cq75-3qjm/GHSA-4mv7-cq75-3qjm.json index 93e1565ff34..bd711f11963 100644 --- a/advisories/github-reviewed/2018/10/GHSA-4mv7-cq75-3qjm/GHSA-4mv7-cq75-3qjm.json +++ b/advisories/github-reviewed/2018/10/GHSA-4mv7-cq75-3qjm/GHSA-4mv7-cq75-3qjm.json @@ -8,9 +8,7 @@ ], "summary": "Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15", "details": "The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an \"invalid curve attack.\"", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/10/GHSA-568q-9fw5-28wf/GHSA-568q-9fw5-28wf.json b/advisories/github-reviewed/2018/10/GHSA-568q-9fw5-28wf/GHSA-568q-9fw5-28wf.json index a840b7d1f76..b4b8734ee25 100644 --- a/advisories/github-reviewed/2018/10/GHSA-568q-9fw5-28wf/GHSA-568q-9fw5-28wf.json +++ b/advisories/github-reviewed/2018/10/GHSA-568q-9fw5-28wf/GHSA-568q-9fw5-28wf.json @@ -8,9 +8,7 @@ ], "summary": "Moderate severity vulnerability that affects org.postgresql:pgjdbc-aggregate", "details": "A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it was signed by a trusted CA.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/11/GHSA-3rhm-67j6-42jq/GHSA-3rhm-67j6-42jq.json b/advisories/github-reviewed/2018/11/GHSA-3rhm-67j6-42jq/GHSA-3rhm-67j6-42jq.json index aefdb6f048d..1f10c191c02 100644 --- a/advisories/github-reviewed/2018/11/GHSA-3rhm-67j6-42jq/GHSA-3rhm-67j6-42jq.json +++ b/advisories/github-reviewed/2018/11/GHSA-3rhm-67j6-42jq/GHSA-3rhm-67j6-42jq.json @@ -65,9 +65,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2020-06-16T20:56:11Z", diff --git a/advisories/github-reviewed/2019/01/GHSA-3wc8-659g-r88q/GHSA-3wc8-659g-r88q.json b/advisories/github-reviewed/2019/01/GHSA-3wc8-659g-r88q/GHSA-3wc8-659g-r88q.json index 97a7bc56fdb..ceb080b13c1 100644 --- a/advisories/github-reviewed/2019/01/GHSA-3wc8-659g-r88q/GHSA-3wc8-659g-r88q.json +++ b/advisories/github-reviewed/2019/01/GHSA-3wc8-659g-r88q/GHSA-3wc8-659g-r88q.json @@ -8,9 +8,7 @@ ], "summary": "Low severity vulnerability that affects org.springframework.batch:spring-batch-core", "details": "Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-3vv5-42wr-m32g/GHSA-3vv5-42wr-m32g.json b/advisories/github-reviewed/2019/02/GHSA-3vv5-42wr-m32g/GHSA-3vv5-42wr-m32g.json index bf627c45087..67cc9f12ddb 100644 --- a/advisories/github-reviewed/2019/02/GHSA-3vv5-42wr-m32g/GHSA-3vv5-42wr-m32g.json +++ b/advisories/github-reviewed/2019/02/GHSA-3vv5-42wr-m32g/GHSA-3vv5-42wr-m32g.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in scala-bin", "details": "Affected versions of `scala-bin` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `scala-bin`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-3x83-p476-vv95/GHSA-3x83-p476-vv95.json b/advisories/github-reviewed/2019/02/GHSA-3x83-p476-vv95/GHSA-3x83-p476-vv95.json index 5412ce8158a..2b39d623d05 100644 --- a/advisories/github-reviewed/2019/02/GHSA-3x83-p476-vv95/GHSA-3x83-p476-vv95.json +++ b/advisories/github-reviewed/2019/02/GHSA-3x83-p476-vv95/GHSA-3x83-p476-vv95.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in selenium-standalone-painful", "details": "Affected versions of `selenium-standalone-painful` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `selenium-standalone-painful`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-455m-q3h9-34pf/GHSA-455m-q3h9-34pf.json b/advisories/github-reviewed/2019/02/GHSA-455m-q3h9-34pf/GHSA-455m-q3h9-34pf.json index 85469a18c19..0007a639a20 100644 --- a/advisories/github-reviewed/2019/02/GHSA-455m-q3h9-34pf/GHSA-455m-q3h9-34pf.json +++ b/advisories/github-reviewed/2019/02/GHSA-455m-q3h9-34pf/GHSA-455m-q3h9-34pf.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in windows-seleniumjar-mirror", "details": "Affected versions of `windows-seleniumjar-mirror` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `windows-seleniumjar-mirror`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nCurrently, the best mitigation is to download the selenium jar file manually from [seleniumHQ](https://www.seleniumhq.org/download/).\n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-45j8-pm75-5v8x/GHSA-45j8-pm75-5v8x.json b/advisories/github-reviewed/2019/02/GHSA-45j8-pm75-5v8x/GHSA-45j8-pm75-5v8x.json index e90e8c4a64e..6bf665cfea1 100644 --- a/advisories/github-reviewed/2019/02/GHSA-45j8-pm75-5v8x/GHSA-45j8-pm75-5v8x.json +++ b/advisories/github-reviewed/2019/02/GHSA-45j8-pm75-5v8x/GHSA-45j8-pm75-5v8x.json @@ -8,9 +8,7 @@ ], "summary": "Path Traversal in simplehttpserver", "details": "Versions of `simplehttpserver` prior to 0.2.1 are vulnerable to Path Traversal. Due to insufficient input sanitization, attackers can access server files by using relative paths. \n\n\n## Recommendation\n\nUpgrade to version 0.2.1 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-476p-r2wx-2wch/GHSA-476p-r2wx-2wch.json b/advisories/github-reviewed/2019/02/GHSA-476p-r2wx-2wch/GHSA-476p-r2wx-2wch.json index c2e217ccc0d..40cdbeb7d3e 100644 --- a/advisories/github-reviewed/2019/02/GHSA-476p-r2wx-2wch/GHSA-476p-r2wx-2wch.json +++ b/advisories/github-reviewed/2019/02/GHSA-476p-r2wx-2wch/GHSA-476p-r2wx-2wch.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in ntfserver", "details": "Affected versions of `ntfserver` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `ntfserver`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-4q79-fch7-g78q/GHSA-4q79-fch7-g78q.json b/advisories/github-reviewed/2019/02/GHSA-4q79-fch7-g78q/GHSA-4q79-fch7-g78q.json index 07fd7678458..9e22d71a3d9 100644 --- a/advisories/github-reviewed/2019/02/GHSA-4q79-fch7-g78q/GHSA-4q79-fch7-g78q.json +++ b/advisories/github-reviewed/2019/02/GHSA-4q79-fch7-g78q/GHSA-4q79-fch7-g78q.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in grunt-webdriver-qunit", "details": "Affected versions of `grunt-webdriver-qunit` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `grunt-webdriver-qunit`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability, and the package author has marked the package as deprecated.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-4v2c-g2xc-47fv/GHSA-4v2c-g2xc-47fv.json b/advisories/github-reviewed/2019/02/GHSA-4v2c-g2xc-47fv/GHSA-4v2c-g2xc-47fv.json index f7d3b761429..1322f1c6029 100644 --- a/advisories/github-reviewed/2019/02/GHSA-4v2c-g2xc-47fv/GHSA-4v2c-g2xc-47fv.json +++ b/advisories/github-reviewed/2019/02/GHSA-4v2c-g2xc-47fv/GHSA-4v2c-g2xc-47fv.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in massif", "details": "Affected versions of `massif` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `massif`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability, and the package has not seen an update since 2013.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-4wm5-q7wv-6jx3/GHSA-4wm5-q7wv-6jx3.json b/advisories/github-reviewed/2019/02/GHSA-4wm5-q7wv-6jx3/GHSA-4wm5-q7wv-6jx3.json index 6882dae191d..0b0f7e87edf 100644 --- a/advisories/github-reviewed/2019/02/GHSA-4wm5-q7wv-6jx3/GHSA-4wm5-q7wv-6jx3.json +++ b/advisories/github-reviewed/2019/02/GHSA-4wm5-q7wv-6jx3/GHSA-4wm5-q7wv-6jx3.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in bkjs-wand", "details": "Affected versions of `bkjs-wand` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `bkjs-wand`.\n\n\n## Recommendation\n\nUpdate to version 0.3.2 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-4x5j-v9v9-w8gw/GHSA-4x5j-v9v9-w8gw.json b/advisories/github-reviewed/2019/02/GHSA-4x5j-v9v9-w8gw/GHSA-4x5j-v9v9-w8gw.json index 3bc43eb8517..384bb309441 100644 --- a/advisories/github-reviewed/2019/02/GHSA-4x5j-v9v9-w8gw/GHSA-4x5j-v9v9-w8gw.json +++ b/advisories/github-reviewed/2019/02/GHSA-4x5j-v9v9-w8gw/GHSA-4x5j-v9v9-w8gw.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in httpsync", "details": "Affected versions of `httpsync` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `httpsync`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-5pq8-2q24-mj3p/GHSA-5pq8-2q24-mj3p.json b/advisories/github-reviewed/2019/02/GHSA-5pq8-2q24-mj3p/GHSA-5pq8-2q24-mj3p.json index 19a3633636a..78b767b9b47 100644 --- a/advisories/github-reviewed/2019/02/GHSA-5pq8-2q24-mj3p/GHSA-5pq8-2q24-mj3p.json +++ b/advisories/github-reviewed/2019/02/GHSA-5pq8-2q24-mj3p/GHSA-5pq8-2q24-mj3p.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in fis-parser-sass-bin", "details": "Affected versions of `fis-parser-sass-bin` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `fis-parser-sass-bin`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-5q5w-mf87-57x4/GHSA-5q5w-mf87-57x4.json b/advisories/github-reviewed/2019/02/GHSA-5q5w-mf87-57x4/GHSA-5q5w-mf87-57x4.json index 32cf8868ecd..201bfe588cb 100644 --- a/advisories/github-reviewed/2019/02/GHSA-5q5w-mf87-57x4/GHSA-5q5w-mf87-57x4.json +++ b/advisories/github-reviewed/2019/02/GHSA-5q5w-mf87-57x4/GHSA-5q5w-mf87-57x4.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in sfml", "details": "Affected versions of `sfml` insecurely download resources over HTTP. \n\nIn scenarios where an attacker has a privileged network position, they can modify or read such resources at will. While the exact severity of impact for a vulnerability like this is highly variable and depends on the behavior of the package itself, it ranges from being able to read sensitive information all the way up to and including remote code execution.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-5rm3-qhxf-rh3r/GHSA-5rm3-qhxf-rh3r.json b/advisories/github-reviewed/2019/02/GHSA-5rm3-qhxf-rh3r/GHSA-5rm3-qhxf-rh3r.json index 37dfd50bfc3..64217b39656 100644 --- a/advisories/github-reviewed/2019/02/GHSA-5rm3-qhxf-rh3r/GHSA-5rm3-qhxf-rh3r.json +++ b/advisories/github-reviewed/2019/02/GHSA-5rm3-qhxf-rh3r/GHSA-5rm3-qhxf-rh3r.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in co-cli-installer", "details": "Affected versions of `co-cli-installer` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `co-cli-installer`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-5w4p-h4gm-3w26/GHSA-5w4p-h4gm-3w26.json b/advisories/github-reviewed/2019/02/GHSA-5w4p-h4gm-3w26/GHSA-5w4p-h4gm-3w26.json index 08c96f4b9d8..9a9ca2c7582 100644 --- a/advisories/github-reviewed/2019/02/GHSA-5w4p-h4gm-3w26/GHSA-5w4p-h4gm-3w26.json +++ b/advisories/github-reviewed/2019/02/GHSA-5w4p-h4gm-3w26/GHSA-5w4p-h4gm-3w26.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in jser-stat", "details": "Affected versions of `jser-stat` insecurely downloads resources over HTTP. \n\nIn scenarios where an attacker has a privileged network position, they can modify or read such resources at will. While the exact severity of impact for a vulnerability like this is highly variable and depends on the behavior of the package itself, it ranges from being able to read sensitive information all the way up to and including remote code execution.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-6663-c963-2gqg/GHSA-6663-c963-2gqg.json b/advisories/github-reviewed/2019/02/GHSA-6663-c963-2gqg/GHSA-6663-c963-2gqg.json index 22d0312263b..073d4a39cfa 100644 --- a/advisories/github-reviewed/2019/02/GHSA-6663-c963-2gqg/GHSA-6663-c963-2gqg.json +++ b/advisories/github-reviewed/2019/02/GHSA-6663-c963-2gqg/GHSA-6663-c963-2gqg.json @@ -8,9 +8,7 @@ ], "summary": "DoS due to excessively large websocket message in ws", "details": "Affected versions of `ws` do not appropriately limit the size of incoming websocket payloads, which may result in a denial of service condition when the node process crashes after receiving a large payload.\n\n\n\n## Recommendation\n\nUpdate to version 1.1.1 or later. \nAlternatively, set the `maxpayload` option for the `ws` server to a value smaller than 256MB.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-69r7-cw26-px6h/GHSA-69r7-cw26-px6h.json b/advisories/github-reviewed/2019/02/GHSA-69r7-cw26-px6h/GHSA-69r7-cw26-px6h.json index 6cc78e2e8d1..c7daff71b88 100644 --- a/advisories/github-reviewed/2019/02/GHSA-69r7-cw26-px6h/GHSA-69r7-cw26-px6h.json +++ b/advisories/github-reviewed/2019/02/GHSA-69r7-cw26-px6h/GHSA-69r7-cw26-px6h.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in google-closure-tools-latest", "details": "Affected versions of `google-closure-tools-latest` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `google-closure-tools-latest`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, and instead install the [closure compiler](https://github.com/google/closure-compiler) manually.\n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-6cpc-mj5c-m9rq/GHSA-6cpc-mj5c-m9rq.json b/advisories/github-reviewed/2019/02/GHSA-6cpc-mj5c-m9rq/GHSA-6cpc-mj5c-m9rq.json index d48109d0440..08edd6cda8a 100644 --- a/advisories/github-reviewed/2019/02/GHSA-6cpc-mj5c-m9rq/GHSA-6cpc-mj5c-m9rq.json +++ b/advisories/github-reviewed/2019/02/GHSA-6cpc-mj5c-m9rq/GHSA-6cpc-mj5c-m9rq.json @@ -8,9 +8,7 @@ ], "summary": "Arbitrary File Write in cli", "details": "Affected versions of `cli` use predictable temporary file names. If an attacker can create a symbolic link at the location of one of these temporarly file names, the attacker can arbitrarily write to any file that the user which owns the `cli` process has permission to write to.\n\n\n## Proof of Concept\n\nBy creating Symbolic Links at the following locations, the target of the link can be written to.\n```\nlock_file = '/tmp/' + cli.app + '.pid',\nlog_file = '/tmp/' + cli.app + '.log';\n```\n\n\n## Recommendation\n\nUpdate to version 1.0.0 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/06/GHSA-4vr3-9v7h-5f8v/GHSA-4vr3-9v7h-5f8v.json b/advisories/github-reviewed/2019/06/GHSA-4vr3-9v7h-5f8v/GHSA-4vr3-9v7h-5f8v.json index 937586b02b2..7034569288b 100644 --- a/advisories/github-reviewed/2019/06/GHSA-4vr3-9v7h-5f8v/GHSA-4vr3-9v7h-5f8v.json +++ b/advisories/github-reviewed/2019/06/GHSA-4vr3-9v7h-5f8v/GHSA-4vr3-9v7h-5f8v.json @@ -3,14 +3,10 @@ "id": "GHSA-4vr3-9v7h-5f8v", "modified": "2021-12-03T14:36:23Z", "published": "2019-06-18T15:38:41Z", - "aliases": [ - - ], + "aliases": [], "summary": "Low severity vulnerability that affects Gw2Sharp", "details": "## Leaking cached authenticated requests\n\n### Impact\nIf you've been using one `MemoryCacheMethod` object in multiple instances of `Gw2WebApiClient` and are requesting authenticated endpoints with different access tokens, then you are likely to run into this bug.\n\nWhen using an instance of `MemoryCacheMethod` and using it with multiple instances of `Gw2WebApiClient`, there's a possibility that cached authenticated responses are leaking to another request to the same endpoint, but with a different Guild Wars 2 access token. The latter request wouldn't start however, and would return the first cached response immediately. This means that the second response (or later responses) may contain the same data as the first response, therefore leaking data from another authenticated endpoint.\n\nThe occurence of this is limited however. The Guild Wars 2 API doesn't use the `Expires` header on most (if not all) authenticated endpoints. This header is checked when caching responses. If this header isn't available, the response isn't cached at all. You should still update to at least version 0.3.1 in order to be certain that it won't happen.\n\n### Patches\nThis bug has been fixed in version 0.3.1. When using an authenticated endpoint, it will prepend the SHA-1 hash of the access token to the cache id.\n\n### Workarounds\nFor version 0.3.0 and lower, you can use one separate instance of `MemoryCacheMethod` per `Gw2WebApiClient` if you need to use it.\n\n### For more information\nIf you have any questions or comments about this advisory, you can open an issue in [the Gw2Sharp repository](https://github.com/Archomeda/Gw2Sharp) or contact me on [Discord](https://discord.gg/hNcpDT3).\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -47,9 +43,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2020-06-16T20:59:21Z", diff --git a/advisories/github-reviewed/2019/06/GHSA-gc94-6w89-hpqr/GHSA-gc94-6w89-hpqr.json b/advisories/github-reviewed/2019/06/GHSA-gc94-6w89-hpqr/GHSA-gc94-6w89-hpqr.json index 215accbf418..fbe891379a5 100644 --- a/advisories/github-reviewed/2019/06/GHSA-gc94-6w89-hpqr/GHSA-gc94-6w89-hpqr.json +++ b/advisories/github-reviewed/2019/06/GHSA-gc94-6w89-hpqr/GHSA-gc94-6w89-hpqr.json @@ -3,14 +3,10 @@ "id": "GHSA-gc94-6w89-hpqr", "modified": "2021-09-16T20:59:56Z", "published": "2019-06-12T16:37:07Z", - "aliases": [ - - ], + "aliases": [], "summary": "Command Injection in fs-path", "details": "All versions of `fs-path` are vulnerable to command injection is unsanitized user input is passed in.\n\n\n## Recommendation\n\nNo fix is currently available for this vulnerability. It is our recommendation to not install or use this module until a fix is available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/09/GHSA-62gw-3rmj-wmp2/GHSA-62gw-3rmj-wmp2.json b/advisories/github-reviewed/2019/09/GHSA-62gw-3rmj-wmp2/GHSA-62gw-3rmj-wmp2.json index 98e4f51845b..d2981c7b6dd 100644 --- a/advisories/github-reviewed/2019/09/GHSA-62gw-3rmj-wmp2/GHSA-62gw-3rmj-wmp2.json +++ b/advisories/github-reviewed/2019/09/GHSA-62gw-3rmj-wmp2/GHSA-62gw-3rmj-wmp2.json @@ -73,9 +73,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:17:47Z", diff --git a/advisories/github-reviewed/2019/10/GHSA-67cx-rhhq-mfhq/GHSA-67cx-rhhq-mfhq.json b/advisories/github-reviewed/2019/10/GHSA-67cx-rhhq-mfhq/GHSA-67cx-rhhq-mfhq.json index 7b1b392717c..e238824a4f1 100644 --- a/advisories/github-reviewed/2019/10/GHSA-67cx-rhhq-mfhq/GHSA-67cx-rhhq-mfhq.json +++ b/advisories/github-reviewed/2019/10/GHSA-67cx-rhhq-mfhq/GHSA-67cx-rhhq-mfhq.json @@ -3,14 +3,10 @@ "id": "GHSA-67cx-rhhq-mfhq", "modified": "2021-09-01T22:40:23Z", "published": "2019-10-11T18:28:07Z", - "aliases": [ - - ], + "aliases": [], "summary": "High severity vulnerability that affects indico", "details": "## Local file disclosure through LaTeX injection\n\n### Impact\nAn external audit of the Indico codebase has discovered a vulnerability in Indico's LaTeX sanitization code, which could have malicious users to run unsafe LaTeX commands on the server. Such commands allowed for example to read local files (e.g. `indico.conf`).\n\nAs far as we know it is not possible to write files or execute code using this vulnerability.\n\n### Patches\nYou need to update to [Indico 2.2.3](https://github.com/indico/indico/releases/tag/v2.2.3) as soon as possible.\nWe also released [Indico 2.1.10](https://github.com/indico/indico/releases/tag/v2.1.10) in case you cannot update to 2.2 for some reason.\nSee https://docs.getindico.io/en/stable/installation/upgrade/ for instructions on how to update.\n\n### Workarounds\nSetting `XELATEX_PATH = None` in `indico.conf` will result in an error when building a PDF, but without being able to run xelatex, the vulnerability cannot be abused.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open a thread in [our forum](https://talk.getindico.io/)\n* Email us privately at [indico-team@cern.ch](mailto:indico-team@cern.ch)\n\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/11/GHSA-4j6x-w426-6rc6/GHSA-4j6x-w426-6rc6.json b/advisories/github-reviewed/2019/11/GHSA-4j6x-w426-6rc6/GHSA-4j6x-w426-6rc6.json index a21b5d19daf..933ad27e2bf 100644 --- a/advisories/github-reviewed/2019/11/GHSA-4j6x-w426-6rc6/GHSA-4j6x-w426-6rc6.json +++ b/advisories/github-reviewed/2019/11/GHSA-4j6x-w426-6rc6/GHSA-4j6x-w426-6rc6.json @@ -3,14 +3,10 @@ "id": "GHSA-4j6x-w426-6rc6", "modified": "2020-06-16T20:58:26Z", "published": "2019-11-08T17:31:17Z", - "aliases": [ - - ], + "aliases": [], "summary": "Default Express middleware security check is ignored in production", "details": "## Default Express middleware security check is ignored in production\n\n### Impact\nAll Cube.js deployments that use affected versions of `@cubejs-backend/api-gateway` with default express authentication middleware in production environment are affected.\n\n### Patches\n@cubejs-backend/api-gateway@0.11.17\n\n### Workarounds\nOverride default authentication express middleware: https://cube.dev/docs/@cubejs-backend-server-core#options-reference-check-auth-middleware\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in https://github.com/cube-js/cube.js/issues\n* Reach out us in community Slack: https://slack.cube.dev/\n\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -46,9 +42,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-16T20:58:26Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-6c6r-39cv-x5fq/GHSA-6c6r-39cv-x5fq.json b/advisories/github-reviewed/2022/05/GHSA-6c6r-39cv-x5fq/GHSA-6c6r-39cv-x5fq.json index 50a87d605c9..588ee479ad8 100644 --- a/advisories/github-reviewed/2022/05/GHSA-6c6r-39cv-x5fq/GHSA-6c6r-39cv-x5fq.json +++ b/advisories/github-reviewed/2022/05/GHSA-6c6r-39cv-x5fq/GHSA-6c6r-39cv-x5fq.json @@ -62,9 +62,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-07-19T18:48:44Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-wwfw-m54g-gv72/GHSA-wwfw-m54g-gv72.json b/advisories/github-reviewed/2022/05/GHSA-wwfw-m54g-gv72/GHSA-wwfw-m54g-gv72.json index 0a65aeaf1c5..d711385ae97 100644 --- a/advisories/github-reviewed/2022/05/GHSA-wwfw-m54g-gv72/GHSA-wwfw-m54g-gv72.json +++ b/advisories/github-reviewed/2022/05/GHSA-wwfw-m54g-gv72/GHSA-wwfw-m54g-gv72.json @@ -62,9 +62,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-07-19T18:45:29Z", diff --git a/advisories/github-reviewed/2024/03/GHSA-pmf3-c36m-g5cf/GHSA-pmf3-c36m-g5cf.json b/advisories/github-reviewed/2024/03/GHSA-pmf3-c36m-g5cf/GHSA-pmf3-c36m-g5cf.json index 3210aabf75c..9d0104174fc 100644 --- a/advisories/github-reviewed/2024/03/GHSA-pmf3-c36m-g5cf/GHSA-pmf3-c36m-g5cf.json +++ b/advisories/github-reviewed/2024/03/GHSA-pmf3-c36m-g5cf/GHSA-pmf3-c36m-g5cf.json @@ -3,14 +3,10 @@ "id": "GHSA-pmf3-c36m-g5cf", "modified": "2024-04-05T18:36:17Z", "published": "2024-03-19T20:06:52Z", - "aliases": [ - - ], + "aliases": [], "summary": "Container escape at build time", "details": "### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nUsers running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed.\n\n### Patches\nFrom @nalind \n```\n# cat /root/cve-2024-1753.diff\n--- internal/volumes/volumes.go\n+++ internal/volumes/volumes.go\n@@ -11,6 +11,7 @@ import (\n \n \t\"errors\"\n \n+\t\"github.com/containers/buildah/copier\"\n \t\"github.com/containers/buildah/define\"\n \t\"github.com/containers/buildah/internal\"\n \tinternalParse \"github.com/containers/buildah/internal/parse\"\n@@ -189,7 +190,11 @@ func GetBindMount(ctx *types.SystemContext, args []string, contextDir string, st\n \t// buildkit parity: support absolute path for sources from current build context\n \tif contextDir != \"\" {\n \t\t// path should be /contextDir/specified path\n-\t\tnewMount.Source = filepath.Join(contextDir, filepath.Clean(string(filepath.Separator)+newMount.Source))\n+\t\tevaluated, err := copier.Eval(contextDir, newMount.Source, copier.EvalOptions{})\n+\t\tif err != nil {\n+\t\t\treturn newMount, \"\", err\n+\t\t}\n+\t\tnewMount.Source = evaluated\n \t} else {\n \t\t// looks like its coming from `build run --mount=type=bind` allow using absolute path\n \t\t// error out if no source is set\n```\n### Reproducer\n\nPrior to testing, as root, add a memorable username to `/etc/passwd` via adduser or your favorite editor. Also create a memorably named file in `/`. Suggest: `touch /SHOULDNTSEETHIS.txt` and `adduser SHOULDNTSEETHIS`. After testing, remember to remove both the file and the user from your system.\n\nUse the following Containerfile\n\n```\n# cat ~/cve_Containerfile\nFROM alpine as base\n\nRUN ln -s / /rootdir\nRUN ln -s /etc /etc2\n\nFROM alpine\n\nRUN echo \"ls container root\"\nRUN ls -l /\n\nRUN echo \"With exploit show host root, not the container's root, and create /BIND_BREAKOUT in / on the host\"\nRUN --mount=type=bind,from=base,source=/rootdir,destination=/exploit,rw ls -l /exploit; touch /exploit/BIND_BREAKOUT; ls -l /exploit\n\nRUN echo \"With exploit show host /etc/passwd, not the container's, and create /BIND_BREAKOUT2 in /etc on the host\"\nRUN --mount=type=bind,rw,source=/etc2,destination=/etc2,from=base ls -l /; ls -l /etc2/passwd; cat /etc2/passwd; touch /etc2/BIND_BREAKOUT2; ls -l /etc2 \n```\n\n#### To Test\n\n##### Testing with an older version of Buildah with the issue\n```\nsetenforce 0\nbuildah build -f ~/cve_Containerfile .\n```\n\nAs part of the printout from the build, you should be able to see the contents of the `/' and `/etc` directories, including the `/SHOULDNOTSEETHIS.txt` file that you created, and the contents of the `/etc/passwd` file which will include the `SHOULDNOTSEETHIS` user that you created. In addition, the file `/BIND_BREAKOUT` and `/etc/BIND_BREAKOUT2` will exist on the host after the command is completed. Be sure to remove those two files between tests. \n\n```\nbuildah rm -a\nbuildah rmi -a\nrm /BIND_BREAKOUT\nrm /etc/BIND_BREAKOUT2\nsetenforce 1\nbuildah build -f ~/cve_Containerfile .\n```\nNeither the `/BIND_BREAKEOUT` or `/etc/BIND_BREAKOUT2` files should be created. An error should be raised during the build when both files are trying to be created. Also, errors will be raised when the build tries to display the contents of the `/etc/passwd` file, and nothing will be displayed from that file. \n\nHowever, the files in both the `/` and `/etc` directories on the host system will be displayed.\n\n##### Testing with the patch\n\nUse the same commands as testing with an older version of Buildah.\n\nWhen running using the patched version of Buildah, regardless of the `setenforce` settings, you should not see the file that you created or the user that you added. Also the `/BIND_BREAKOUT` and the `/etc/BIND_BREAKOUT` will not exist on the host after the test completes.\n\nNOTE: With the fix, the contents of the `/` and `/etc` directories, and the `/etc/passwd` file will be displayed, however, it will be the file and contents from the container image, and NOT the host system. Also the `/BIND_BREAKOUT` and `/etc/BIND_BREAKOUT` files will be created in the container image.\n\n\n### Workarounds\nEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With \"setenforce 0\" set, which is not at all advised, the root file system is open for modification with this exploit. With \"setenfoce 1\" set, which is the recommendation, files can not be changed. However, the contents of the `/` directory can be displayed. I.e., `ls -alF /` will show the contents of the host directory.\n\n### References\n\nUnknown.\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/04/GHSA-65pc-76pq-pvf5/GHSA-65pc-76pq-pvf5.json b/advisories/github-reviewed/2024/04/GHSA-65pc-76pq-pvf5/GHSA-65pc-76pq-pvf5.json index a271d318fe7..979b0d6d0b2 100644 --- a/advisories/github-reviewed/2024/04/GHSA-65pc-76pq-pvf5/GHSA-65pc-76pq-pvf5.json +++ b/advisories/github-reviewed/2024/04/GHSA-65pc-76pq-pvf5/GHSA-65pc-76pq-pvf5.json @@ -4,9 +4,7 @@ "modified": "2024-04-05T15:06:16Z", "published": "2024-04-04T15:30:34Z", "withdrawn": "2024-04-05T15:06:16Z", - "aliases": [ - - ], + "aliases": [], "summary": "Duplicate Advisory: Pebble service manager's file pull API allows access by any user", "details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-4685-2x5r-65pj. This link is maintained to preserve external references.\n\n## Original Description\nIt was discovered that Pebble's read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged local users to read files with root-equivalent permissions when Pebble was running as root. Fixes are also available as backports to v1.1.1, v1.4.2, and v1.7.4.", "severity": [ @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-04-05T15:06:16Z", diff --git a/advisories/github-reviewed/2024/04/GHSA-q6cp-qfwq-4gcv/GHSA-q6cp-qfwq-4gcv.json b/advisories/github-reviewed/2024/04/GHSA-q6cp-qfwq-4gcv/GHSA-q6cp-qfwq-4gcv.json index b6527ad1eb0..df4dc894641 100644 --- a/advisories/github-reviewed/2024/04/GHSA-q6cp-qfwq-4gcv/GHSA-q6cp-qfwq-4gcv.json +++ b/advisories/github-reviewed/2024/04/GHSA-q6cp-qfwq-4gcv/GHSA-q6cp-qfwq-4gcv.json @@ -3,9 +3,7 @@ "id": "GHSA-q6cp-qfwq-4gcv", "modified": "2024-04-05T15:05:32Z", "published": "2024-04-05T15:05:32Z", - "aliases": [ - - ], + "aliases": [], "summary": "h2 servers vulnerable to degradation of service with CONTINUATION Flood", "details": "An attacker can send a flood of CONTINUATION frames, causing `h2` to process them indefinitely. This results in an increase in CPU usage.\n\nTokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency.\n\nMore details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/.\n\nPatches available for 0.4.x and 0.3.x versions.\n", "severity": [ diff --git a/advisories/github-reviewed/2024/04/GHSA-w5w5-8vfh-xcjq/GHSA-w5w5-8vfh-xcjq.json b/advisories/github-reviewed/2024/04/GHSA-w5w5-8vfh-xcjq/GHSA-w5w5-8vfh-xcjq.json index a10b4bff0a0..9e50ecbb1e1 100644 --- a/advisories/github-reviewed/2024/04/GHSA-w5w5-8vfh-xcjq/GHSA-w5w5-8vfh-xcjq.json +++ b/advisories/github-reviewed/2024/04/GHSA-w5w5-8vfh-xcjq/GHSA-w5w5-8vfh-xcjq.json @@ -3,9 +3,7 @@ "id": "GHSA-w5w5-8vfh-xcjq", "modified": "2024-04-05T15:39:19Z", "published": "2024-04-05T15:39:19Z", - "aliases": [ - - ], + "aliases": [], "summary": "whoami stack buffer overflow on several Unix platforms", "details": "With versions of the whoami crate >= 0.5.3 and < 1.5.0, calling any of these functions leads to an immediate stack buffer overflow on illumos and Solaris:\n\n- `whoami::username`\n- `whoami::realname`\n- `whoami::username_os`\n- `whoami::realname_os`\n\nWith versions of the whoami crate >= 0.5.3 and < 1.0.1, calling any of the above functions also leads to a stack buffer overflow on these platforms:\n\n- Bitrig\n- DragonFlyBSD\n- FreeBSD\n- NetBSD\n- OpenBSD\n\nThis occurs because of an incorrect definition of the `passwd` struct on those platforms.\n\nAs a result of this issue, denial of service and data corruption have both been observed in the wild. The issue is possibly exploitable as well.\n\nThis vulnerability also affects other Unix platforms that aren't Linux or macOS.\n\nThis issue has been addressed in whoami 1.5.0.\n\nFor more information, see [this GitHub issue](https://github.com/ardaku/whoami/issues/91).\n", "severity": [ diff --git a/advisories/unreviewed/2022/01/GHSA-7v89-wqr4-9x78/GHSA-7v89-wqr4-9x78.json b/advisories/unreviewed/2022/01/GHSA-7v89-wqr4-9x78/GHSA-7v89-wqr4-9x78.json index 243b95136e7..c3c301ad3a4 100644 --- a/advisories/unreviewed/2022/01/GHSA-7v89-wqr4-9x78/GHSA-7v89-wqr4-9x78.json +++ b/advisories/unreviewed/2022/01/GHSA-7v89-wqr4-9x78/GHSA-7v89-wqr4-9x78.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-85fp-hp45-wj39/GHSA-85fp-hp45-wj39.json b/advisories/unreviewed/2022/01/GHSA-85fp-hp45-wj39/GHSA-85fp-hp45-wj39.json index 259fb125e48..d9f2af95755 100644 --- a/advisories/unreviewed/2022/01/GHSA-85fp-hp45-wj39/GHSA-85fp-hp45-wj39.json +++ b/advisories/unreviewed/2022/01/GHSA-85fp-hp45-wj39/GHSA-85fp-hp45-wj39.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-c5j7-636j-xr7g/GHSA-c5j7-636j-xr7g.json b/advisories/unreviewed/2022/01/GHSA-c5j7-636j-xr7g/GHSA-c5j7-636j-xr7g.json index 4f92c6600a6..802a0683da8 100644 --- a/advisories/unreviewed/2022/01/GHSA-c5j7-636j-xr7g/GHSA-c5j7-636j-xr7g.json +++ b/advisories/unreviewed/2022/01/GHSA-c5j7-636j-xr7g/GHSA-c5j7-636j-xr7g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-frr5-j95h-h8q2/GHSA-frr5-j95h-h8q2.json b/advisories/unreviewed/2022/01/GHSA-frr5-j95h-h8q2/GHSA-frr5-j95h-h8q2.json index 6dd1f1bacbf..22b8de73b71 100644 --- a/advisories/unreviewed/2022/01/GHSA-frr5-j95h-h8q2/GHSA-frr5-j95h-h8q2.json +++ b/advisories/unreviewed/2022/01/GHSA-frr5-j95h-h8q2/GHSA-frr5-j95h-h8q2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-gq7v-v27c-rx72/GHSA-gq7v-v27c-rx72.json b/advisories/unreviewed/2022/01/GHSA-gq7v-v27c-rx72/GHSA-gq7v-v27c-rx72.json index 16417f9de30..81dc1574b27 100644 --- a/advisories/unreviewed/2022/01/GHSA-gq7v-v27c-rx72/GHSA-gq7v-v27c-rx72.json +++ b/advisories/unreviewed/2022/01/GHSA-gq7v-v27c-rx72/GHSA-gq7v-v27c-rx72.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-h7fm-qf2w-2pw2/GHSA-h7fm-qf2w-2pw2.json b/advisories/unreviewed/2022/01/GHSA-h7fm-qf2w-2pw2/GHSA-h7fm-qf2w-2pw2.json index 5a3e45980b4..45ea6fcd315 100644 --- a/advisories/unreviewed/2022/01/GHSA-h7fm-qf2w-2pw2/GHSA-h7fm-qf2w-2pw2.json +++ b/advisories/unreviewed/2022/01/GHSA-h7fm-qf2w-2pw2/GHSA-h7fm-qf2w-2pw2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-j532-8pqq-78jr/GHSA-j532-8pqq-78jr.json b/advisories/unreviewed/2022/01/GHSA-j532-8pqq-78jr/GHSA-j532-8pqq-78jr.json index 136107d4204..41f1e57975a 100644 --- a/advisories/unreviewed/2022/01/GHSA-j532-8pqq-78jr/GHSA-j532-8pqq-78jr.json +++ b/advisories/unreviewed/2022/01/GHSA-j532-8pqq-78jr/GHSA-j532-8pqq-78jr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-mvjm-xvhc-97rr/GHSA-mvjm-xvhc-97rr.json b/advisories/unreviewed/2022/01/GHSA-mvjm-xvhc-97rr/GHSA-mvjm-xvhc-97rr.json index f689b1f8dfc..2b38b07ed57 100644 --- a/advisories/unreviewed/2022/01/GHSA-mvjm-xvhc-97rr/GHSA-mvjm-xvhc-97rr.json +++ b/advisories/unreviewed/2022/01/GHSA-mvjm-xvhc-97rr/GHSA-mvjm-xvhc-97rr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-pqcw-x89x-vfmm/GHSA-pqcw-x89x-vfmm.json b/advisories/unreviewed/2022/01/GHSA-pqcw-x89x-vfmm/GHSA-pqcw-x89x-vfmm.json index b934aa61cd7..a0e2d9b7aa5 100644 --- a/advisories/unreviewed/2022/01/GHSA-pqcw-x89x-vfmm/GHSA-pqcw-x89x-vfmm.json +++ b/advisories/unreviewed/2022/01/GHSA-pqcw-x89x-vfmm/GHSA-pqcw-x89x-vfmm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-qmxq-6r7j-56rw/GHSA-qmxq-6r7j-56rw.json b/advisories/unreviewed/2022/01/GHSA-qmxq-6r7j-56rw/GHSA-qmxq-6r7j-56rw.json index d2f9bfec7e5..48b133437b7 100644 --- a/advisories/unreviewed/2022/01/GHSA-qmxq-6r7j-56rw/GHSA-qmxq-6r7j-56rw.json +++ b/advisories/unreviewed/2022/01/GHSA-qmxq-6r7j-56rw/GHSA-qmxq-6r7j-56rw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-vchm-32r9-6qh2/GHSA-vchm-32r9-6qh2.json b/advisories/unreviewed/2022/01/GHSA-vchm-32r9-6qh2/GHSA-vchm-32r9-6qh2.json index 2be3f81a78a..f3630147878 100644 --- a/advisories/unreviewed/2022/01/GHSA-vchm-32r9-6qh2/GHSA-vchm-32r9-6qh2.json +++ b/advisories/unreviewed/2022/01/GHSA-vchm-32r9-6qh2/GHSA-vchm-32r9-6qh2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-wx84-5mw2-8vx6/GHSA-wx84-5mw2-8vx6.json b/advisories/unreviewed/2022/01/GHSA-wx84-5mw2-8vx6/GHSA-wx84-5mw2-8vx6.json index 29830b4225b..c88146e4003 100644 --- a/advisories/unreviewed/2022/01/GHSA-wx84-5mw2-8vx6/GHSA-wx84-5mw2-8vx6.json +++ b/advisories/unreviewed/2022/01/GHSA-wx84-5mw2-8vx6/GHSA-wx84-5mw2-8vx6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-9wpj-h5jq-88p9/GHSA-9wpj-h5jq-88p9.json b/advisories/unreviewed/2022/02/GHSA-9wpj-h5jq-88p9/GHSA-9wpj-h5jq-88p9.json index 306682dfca8..f3cafe9ecd2 100644 --- a/advisories/unreviewed/2022/02/GHSA-9wpj-h5jq-88p9/GHSA-9wpj-h5jq-88p9.json +++ b/advisories/unreviewed/2022/02/GHSA-9wpj-h5jq-88p9/GHSA-9wpj-h5jq-88p9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-4rv9-8872-9582/GHSA-4rv9-8872-9582.json b/advisories/unreviewed/2022/03/GHSA-4rv9-8872-9582/GHSA-4rv9-8872-9582.json index 47694f61004..940395ed801 100644 --- a/advisories/unreviewed/2022/03/GHSA-4rv9-8872-9582/GHSA-4rv9-8872-9582.json +++ b/advisories/unreviewed/2022/03/GHSA-4rv9-8872-9582/GHSA-4rv9-8872-9582.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-5c63-m98j-vx6v/GHSA-5c63-m98j-vx6v.json b/advisories/unreviewed/2022/03/GHSA-5c63-m98j-vx6v/GHSA-5c63-m98j-vx6v.json index 48a03d99c01..2fe0fd29389 100644 --- a/advisories/unreviewed/2022/03/GHSA-5c63-m98j-vx6v/GHSA-5c63-m98j-vx6v.json +++ b/advisories/unreviewed/2022/03/GHSA-5c63-m98j-vx6v/GHSA-5c63-m98j-vx6v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-6685-ffxp-xm6f/GHSA-6685-ffxp-xm6f.json b/advisories/unreviewed/2022/03/GHSA-6685-ffxp-xm6f/GHSA-6685-ffxp-xm6f.json index d5be71b5b5b..19fcc4942ac 100644 --- a/advisories/unreviewed/2022/03/GHSA-6685-ffxp-xm6f/GHSA-6685-ffxp-xm6f.json +++ b/advisories/unreviewed/2022/03/GHSA-6685-ffxp-xm6f/GHSA-6685-ffxp-xm6f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-jr52-cgg9-p2ph/GHSA-jr52-cgg9-p2ph.json b/advisories/unreviewed/2022/03/GHSA-jr52-cgg9-p2ph/GHSA-jr52-cgg9-p2ph.json index fb347a8a0d1..8ca7c2965c4 100644 --- a/advisories/unreviewed/2022/03/GHSA-jr52-cgg9-p2ph/GHSA-jr52-cgg9-p2ph.json +++ b/advisories/unreviewed/2022/03/GHSA-jr52-cgg9-p2ph/GHSA-jr52-cgg9-p2ph.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-rrjx-7fgp-4597/GHSA-rrjx-7fgp-4597.json b/advisories/unreviewed/2022/03/GHSA-rrjx-7fgp-4597/GHSA-rrjx-7fgp-4597.json index f670cd8b332..7d8aec04933 100644 --- a/advisories/unreviewed/2022/03/GHSA-rrjx-7fgp-4597/GHSA-rrjx-7fgp-4597.json +++ b/advisories/unreviewed/2022/03/GHSA-rrjx-7fgp-4597/GHSA-rrjx-7fgp-4597.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-vvgm-gfhp-rj9x/GHSA-vvgm-gfhp-rj9x.json b/advisories/unreviewed/2022/03/GHSA-vvgm-gfhp-rj9x/GHSA-vvgm-gfhp-rj9x.json index b19d252462a..5259b3f30d6 100644 --- a/advisories/unreviewed/2022/03/GHSA-vvgm-gfhp-rj9x/GHSA-vvgm-gfhp-rj9x.json +++ b/advisories/unreviewed/2022/03/GHSA-vvgm-gfhp-rj9x/GHSA-vvgm-gfhp-rj9x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-32vw-hmgx-hqv2/GHSA-32vw-hmgx-hqv2.json b/advisories/unreviewed/2022/04/GHSA-32vw-hmgx-hqv2/GHSA-32vw-hmgx-hqv2.json index 8ce324a775a..6948353c06e 100644 --- a/advisories/unreviewed/2022/04/GHSA-32vw-hmgx-hqv2/GHSA-32vw-hmgx-hqv2.json +++ b/advisories/unreviewed/2022/04/GHSA-32vw-hmgx-hqv2/GHSA-32vw-hmgx-hqv2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-82gm-q2vc-g3x3/GHSA-82gm-q2vc-g3x3.json b/advisories/unreviewed/2022/04/GHSA-82gm-q2vc-g3x3/GHSA-82gm-q2vc-g3x3.json index 41eaa3c7e09..2bad392b82c 100644 --- a/advisories/unreviewed/2022/04/GHSA-82gm-q2vc-g3x3/GHSA-82gm-q2vc-g3x3.json +++ b/advisories/unreviewed/2022/04/GHSA-82gm-q2vc-g3x3/GHSA-82gm-q2vc-g3x3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-chvr-7r2f-642r/GHSA-chvr-7r2f-642r.json b/advisories/unreviewed/2022/04/GHSA-chvr-7r2f-642r/GHSA-chvr-7r2f-642r.json index 8913827f523..2ea537b12f5 100644 --- a/advisories/unreviewed/2022/04/GHSA-chvr-7r2f-642r/GHSA-chvr-7r2f-642r.json +++ b/advisories/unreviewed/2022/04/GHSA-chvr-7r2f-642r/GHSA-chvr-7r2f-642r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-cjmw-x525-6p4f/GHSA-cjmw-x525-6p4f.json b/advisories/unreviewed/2022/04/GHSA-cjmw-x525-6p4f/GHSA-cjmw-x525-6p4f.json index 1d8b7de2b5f..6f3a853b09e 100644 --- a/advisories/unreviewed/2022/04/GHSA-cjmw-x525-6p4f/GHSA-cjmw-x525-6p4f.json +++ b/advisories/unreviewed/2022/04/GHSA-cjmw-x525-6p4f/GHSA-cjmw-x525-6p4f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-f7m8-j9p6-w6r3/GHSA-f7m8-j9p6-w6r3.json b/advisories/unreviewed/2022/04/GHSA-f7m8-j9p6-w6r3/GHSA-f7m8-j9p6-w6r3.json index e12b3444e62..2740cb3b242 100644 --- a/advisories/unreviewed/2022/04/GHSA-f7m8-j9p6-w6r3/GHSA-f7m8-j9p6-w6r3.json +++ b/advisories/unreviewed/2022/04/GHSA-f7m8-j9p6-w6r3/GHSA-f7m8-j9p6-w6r3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-hw43-fp5c-9f72/GHSA-hw43-fp5c-9f72.json b/advisories/unreviewed/2022/04/GHSA-hw43-fp5c-9f72/GHSA-hw43-fp5c-9f72.json index c0873ff0619..2c3520a6057 100644 --- a/advisories/unreviewed/2022/04/GHSA-hw43-fp5c-9f72/GHSA-hw43-fp5c-9f72.json +++ b/advisories/unreviewed/2022/04/GHSA-hw43-fp5c-9f72/GHSA-hw43-fp5c-9f72.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-j7p4-45q8-j6xx/GHSA-j7p4-45q8-j6xx.json b/advisories/unreviewed/2022/04/GHSA-j7p4-45q8-j6xx/GHSA-j7p4-45q8-j6xx.json index 7315d609967..22b43a6b289 100644 --- a/advisories/unreviewed/2022/04/GHSA-j7p4-45q8-j6xx/GHSA-j7p4-45q8-j6xx.json +++ b/advisories/unreviewed/2022/04/GHSA-j7p4-45q8-j6xx/GHSA-j7p4-45q8-j6xx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2273-wjr4-jh7g/GHSA-2273-wjr4-jh7g.json b/advisories/unreviewed/2022/05/GHSA-2273-wjr4-jh7g/GHSA-2273-wjr4-jh7g.json index 440b78a1ebf..53efa1a748a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2273-wjr4-jh7g/GHSA-2273-wjr4-jh7g.json +++ b/advisories/unreviewed/2022/05/GHSA-2273-wjr4-jh7g/GHSA-2273-wjr4-jh7g.json @@ -7,12 +7,8 @@ "CVE-2007-2195" ], "details": "aMSN (aka Alvaro's Messenger) 0.96 and earlier allows remote attackers to cause a denial of service (application crash) by sending invalid data to TCP port 31337.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-239r-76x2-4c6j/GHSA-239r-76x2-4c6j.json b/advisories/unreviewed/2022/05/GHSA-239r-76x2-4c6j/GHSA-239r-76x2-4c6j.json index f7c359e82fd..3f6d23bf51a 100644 --- a/advisories/unreviewed/2022/05/GHSA-239r-76x2-4c6j/GHSA-239r-76x2-4c6j.json +++ b/advisories/unreviewed/2022/05/GHSA-239r-76x2-4c6j/GHSA-239r-76x2-4c6j.json @@ -7,12 +7,8 @@ "CVE-2007-2643" ], "details": "Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-23r3-843h-8x2j/GHSA-23r3-843h-8x2j.json b/advisories/unreviewed/2022/05/GHSA-23r3-843h-8x2j/GHSA-23r3-843h-8x2j.json index 65697c17a9c..63b4d7d3420 100644 --- a/advisories/unreviewed/2022/05/GHSA-23r3-843h-8x2j/GHSA-23r3-843h-8x2j.json +++ b/advisories/unreviewed/2022/05/GHSA-23r3-843h-8x2j/GHSA-23r3-843h-8x2j.json @@ -7,12 +7,8 @@ "CVE-2007-2484" ], "details": "PHP remote file inclusion vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-24g5-659f-65j9/GHSA-24g5-659f-65j9.json b/advisories/unreviewed/2022/05/GHSA-24g5-659f-65j9/GHSA-24g5-659f-65j9.json index 5b39f258af1..df4a890681c 100644 --- a/advisories/unreviewed/2022/05/GHSA-24g5-659f-65j9/GHSA-24g5-659f-65j9.json +++ b/advisories/unreviewed/2022/05/GHSA-24g5-659f-65j9/GHSA-24g5-659f-65j9.json @@ -7,12 +7,8 @@ "CVE-2007-2171" ], "details": "Stack-based buffer overflow in the base64_decode function in GWINTER.exe in Novell GroupWise (GW) WebAccess before 7.0 SP2 allows remote attackers to execute arbitrary code via long base64 content in an HTTP Basic Authentication request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2532-fj77-38p3/GHSA-2532-fj77-38p3.json b/advisories/unreviewed/2022/05/GHSA-2532-fj77-38p3/GHSA-2532-fj77-38p3.json index 5f5c3f231c8..2e90e07b980 100644 --- a/advisories/unreviewed/2022/05/GHSA-2532-fj77-38p3/GHSA-2532-fj77-38p3.json +++ b/advisories/unreviewed/2022/05/GHSA-2532-fj77-38p3/GHSA-2532-fj77-38p3.json @@ -7,12 +7,8 @@ "CVE-2007-2364" ], "details": "Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) mysql.class.php or (2) postgres.class.php in lib/db/; or (3) authuser.php, (4) misc.php, or (5) connect.php in lib/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2595-gj6q-jrrp/GHSA-2595-gj6q-jrrp.json b/advisories/unreviewed/2022/05/GHSA-2595-gj6q-jrrp/GHSA-2595-gj6q-jrrp.json index f79a15fbd63..b3896ae26b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-2595-gj6q-jrrp/GHSA-2595-gj6q-jrrp.json +++ b/advisories/unreviewed/2022/05/GHSA-2595-gj6q-jrrp/GHSA-2595-gj6q-jrrp.json @@ -7,12 +7,8 @@ "CVE-2007-2475" ], "details": "Unspecified vulnerability in the ADSCHEMA utility in Novell SecureLogin (NSL) 6 SP1 before 6.0.106 has unknown impact and remote attack vectors, related to granting \"users excess permissions to their own attributes.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-26qf-34q8-32jq/GHSA-26qf-34q8-32jq.json b/advisories/unreviewed/2022/05/GHSA-26qf-34q8-32jq/GHSA-26qf-34q8-32jq.json index 824d72ceab0..7f2d54c0901 100644 --- a/advisories/unreviewed/2022/05/GHSA-26qf-34q8-32jq/GHSA-26qf-34q8-32jq.json +++ b/advisories/unreviewed/2022/05/GHSA-26qf-34q8-32jq/GHSA-26qf-34q8-32jq.json @@ -7,12 +7,8 @@ "CVE-2007-2306" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) memberlist parameter to extra/login.php and the (2) title parameter to extra/today.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-27pv-53mj-ff4j/GHSA-27pv-53mj-ff4j.json b/advisories/unreviewed/2022/05/GHSA-27pv-53mj-ff4j/GHSA-27pv-53mj-ff4j.json index f4ad7c611fd..6a10dbea319 100644 --- a/advisories/unreviewed/2022/05/GHSA-27pv-53mj-ff4j/GHSA-27pv-53mj-ff4j.json +++ b/advisories/unreviewed/2022/05/GHSA-27pv-53mj-ff4j/GHSA-27pv-53mj-ff4j.json @@ -7,12 +7,8 @@ "CVE-2007-2205" ], "details": "PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2877-5pv6-3w5q/GHSA-2877-5pv6-3w5q.json b/advisories/unreviewed/2022/05/GHSA-2877-5pv6-3w5q/GHSA-2877-5pv6-3w5q.json index 72332286119..18ebd30806a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2877-5pv6-3w5q/GHSA-2877-5pv6-3w5q.json +++ b/advisories/unreviewed/2022/05/GHSA-2877-5pv6-3w5q/GHSA-2877-5pv6-3w5q.json @@ -7,12 +7,8 @@ "CVE-2007-2629" ], "details": "Bradford CampusManager Network Control Application Server 3.1(6) allows remote attackers to obtain sensitive information (backup, log, and configuration files) via direct request for certain files in (1) /runTime/ or (2) /remediationReports/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-28px-82cg-wrw5/GHSA-28px-82cg-wrw5.json b/advisories/unreviewed/2022/05/GHSA-28px-82cg-wrw5/GHSA-28px-82cg-wrw5.json index 5b096b725b5..51928719572 100644 --- a/advisories/unreviewed/2022/05/GHSA-28px-82cg-wrw5/GHSA-28px-82cg-wrw5.json +++ b/advisories/unreviewed/2022/05/GHSA-28px-82cg-wrw5/GHSA-28px-82cg-wrw5.json @@ -7,12 +7,8 @@ "CVE-2007-2573" ], "details": "PHP remote file inclusion vulnerability in plugin/HP_DEV/cms2.php in PHPtree 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_dir parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-293j-3754-3xrj/GHSA-293j-3754-3xrj.json b/advisories/unreviewed/2022/05/GHSA-293j-3754-3xrj/GHSA-293j-3754-3xrj.json index 40359402665..ae663297815 100644 --- a/advisories/unreviewed/2022/05/GHSA-293j-3754-3xrj/GHSA-293j-3754-3xrj.json +++ b/advisories/unreviewed/2022/05/GHSA-293j-3754-3xrj/GHSA-293j-3754-3xrj.json @@ -7,12 +7,8 @@ "CVE-2007-2485" ], "details": "PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2c4w-2px5-9x3x/GHSA-2c4w-2px5-9x3x.json b/advisories/unreviewed/2022/05/GHSA-2c4w-2px5-9x3x/GHSA-2c4w-2px5-9x3x.json index 425f6224dec..d92d0eb0068 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c4w-2px5-9x3x/GHSA-2c4w-2px5-9x3x.json +++ b/advisories/unreviewed/2022/05/GHSA-2c4w-2px5-9x3x/GHSA-2c4w-2px5-9x3x.json @@ -7,12 +7,8 @@ "CVE-2007-2353" ], "details": "Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2f4x-p9hx-9v3c/GHSA-2f4x-p9hx-9v3c.json b/advisories/unreviewed/2022/05/GHSA-2f4x-p9hx-9v3c/GHSA-2f4x-p9hx-9v3c.json index 6e9242c48e6..bd9f87eda18 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f4x-p9hx-9v3c/GHSA-2f4x-p9hx-9v3c.json +++ b/advisories/unreviewed/2022/05/GHSA-2f4x-p9hx-9v3c/GHSA-2f4x-p9hx-9v3c.json @@ -7,12 +7,8 @@ "CVE-2007-2549" ], "details": "SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) c or (2) quantity parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2g7v-93hf-j2h4/GHSA-2g7v-93hf-j2h4.json b/advisories/unreviewed/2022/05/GHSA-2g7v-93hf-j2h4/GHSA-2g7v-93hf-j2h4.json index ebccc35ad27..be3a73fad79 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g7v-93hf-j2h4/GHSA-2g7v-93hf-j2h4.json +++ b/advisories/unreviewed/2022/05/GHSA-2g7v-93hf-j2h4/GHSA-2g7v-93hf-j2h4.json @@ -7,12 +7,8 @@ "CVE-2007-2472" ], "details": "Cross-site scripting (XSS) vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the form parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2gvr-cr49-92f3/GHSA-2gvr-cr49-92f3.json b/advisories/unreviewed/2022/05/GHSA-2gvr-cr49-92f3/GHSA-2gvr-cr49-92f3.json index 923c25bce79..8ab998d1dbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gvr-cr49-92f3/GHSA-2gvr-cr49-92f3.json +++ b/advisories/unreviewed/2022/05/GHSA-2gvr-cr49-92f3/GHSA-2gvr-cr49-92f3.json @@ -7,12 +7,8 @@ "CVE-2007-2318" ], "details": "Multiple format string vulnerabilities in FileZilla before 2.2.32 allow remote attackers to execute arbitrary code via format string specifiers in (1) FTP server responses or (2) data sent by an FTP server. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2h98-r334-3wg6/GHSA-2h98-r334-3wg6.json b/advisories/unreviewed/2022/05/GHSA-2h98-r334-3wg6/GHSA-2h98-r334-3wg6.json index cbed81575f2..31e69b07594 100644 --- a/advisories/unreviewed/2022/05/GHSA-2h98-r334-3wg6/GHSA-2h98-r334-3wg6.json +++ b/advisories/unreviewed/2022/05/GHSA-2h98-r334-3wg6/GHSA-2h98-r334-3wg6.json @@ -7,12 +7,8 @@ "CVE-2007-2017" ], "details": "siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify user information via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2hq5-m4w6-6x9c/GHSA-2hq5-m4w6-6x9c.json b/advisories/unreviewed/2022/05/GHSA-2hq5-m4w6-6x9c/GHSA-2hq5-m4w6-6x9c.json index e26da7a2485..59a41ad53dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hq5-m4w6-6x9c/GHSA-2hq5-m4w6-6x9c.json +++ b/advisories/unreviewed/2022/05/GHSA-2hq5-m4w6-6x9c/GHSA-2hq5-m4w6-6x9c.json @@ -7,12 +7,8 @@ "CVE-2007-2138" ], "details": "Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the privileges of the function owner, related to \"search_path settings.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -144,9 +140,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2j3q-vc9h-xvcv/GHSA-2j3q-vc9h-xvcv.json b/advisories/unreviewed/2022/05/GHSA-2j3q-vc9h-xvcv/GHSA-2j3q-vc9h-xvcv.json index ba5b53374e3..71c946f6040 100644 --- a/advisories/unreviewed/2022/05/GHSA-2j3q-vc9h-xvcv/GHSA-2j3q-vc9h-xvcv.json +++ b/advisories/unreviewed/2022/05/GHSA-2j3q-vc9h-xvcv/GHSA-2j3q-vc9h-xvcv.json @@ -7,12 +7,8 @@ "CVE-2007-2670" ], "details": "PHPChain 1.0 and earlier allows remote attackers to obtain the installation path via invalid values of the catid parameter to (1) settings.php or (2) cat.php, as demonstrated by XSS manipulations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2j4j-cgfm-hpg2/GHSA-2j4j-cgfm-hpg2.json b/advisories/unreviewed/2022/05/GHSA-2j4j-cgfm-hpg2/GHSA-2j4j-cgfm-hpg2.json index 32889c7b993..6abd5474b94 100644 --- a/advisories/unreviewed/2022/05/GHSA-2j4j-cgfm-hpg2/GHSA-2j4j-cgfm-hpg2.json +++ b/advisories/unreviewed/2022/05/GHSA-2j4j-cgfm-hpg2/GHSA-2j4j-cgfm-hpg2.json @@ -7,12 +7,8 @@ "CVE-2007-2675" ], "details": "SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2jp9-gw7w-3j29/GHSA-2jp9-gw7w-3j29.json b/advisories/unreviewed/2022/05/GHSA-2jp9-gw7w-3j29/GHSA-2jp9-gw7w-3j29.json index 4a272ed6092..70b52107838 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jp9-gw7w-3j29/GHSA-2jp9-gw7w-3j29.json +++ b/advisories/unreviewed/2022/05/GHSA-2jp9-gw7w-3j29/GHSA-2jp9-gw7w-3j29.json @@ -7,12 +7,8 @@ "CVE-2007-2321" ], "details": "Unspecified vulnerability in the search functionality in SilverStripe 2.0.0 has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2jw9-vv7m-64m4/GHSA-2jw9-vv7m-64m4.json b/advisories/unreviewed/2022/05/GHSA-2jw9-vv7m-64m4/GHSA-2jw9-vv7m-64m4.json index d7562c2e41b..b272b05aaf6 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jw9-vv7m-64m4/GHSA-2jw9-vv7m-64m4.json +++ b/advisories/unreviewed/2022/05/GHSA-2jw9-vv7m-64m4/GHSA-2jw9-vv7m-64m4.json @@ -7,12 +7,8 @@ "CVE-2007-2288" ], "details": "PHP remote file inclusion vulnerability in info.php in Doruk100.net doruk100net allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2m54-c69q-qw3j/GHSA-2m54-c69q-qw3j.json b/advisories/unreviewed/2022/05/GHSA-2m54-c69q-qw3j/GHSA-2m54-c69q-qw3j.json index 8a4555e47e2..b21394f95cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-2m54-c69q-qw3j/GHSA-2m54-c69q-qw3j.json +++ b/advisories/unreviewed/2022/05/GHSA-2m54-c69q-qw3j/GHSA-2m54-c69q-qw3j.json @@ -7,12 +7,8 @@ "CVE-2007-2316" ], "details": "Unspecified vulnerability in the admin script in Open Business Management (OBM) before 2.0.0 allows remote attackers to have an unknown impact by calling the script \"in txt mode from a browser.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2mf5-fw29-w5cx/GHSA-2mf5-fw29-w5cx.json b/advisories/unreviewed/2022/05/GHSA-2mf5-fw29-w5cx/GHSA-2mf5-fw29-w5cx.json index 4f794318fd9..f78c064173d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mf5-fw29-w5cx/GHSA-2mf5-fw29-w5cx.json +++ b/advisories/unreviewed/2022/05/GHSA-2mf5-fw29-w5cx/GHSA-2mf5-fw29-w5cx.json @@ -7,12 +7,8 @@ "CVE-2007-2527" ], "details": "Multiple PHP remote file inclusion vulnerabilities in DynamicPAD before 1.03.31 allow remote attackers to execute arbitrary PHP code via a URL in the HomeDir parameter to (1) dp_logs.php or (2) index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2mhh-8chh-jm97/GHSA-2mhh-8chh-jm97.json b/advisories/unreviewed/2022/05/GHSA-2mhh-8chh-jm97/GHSA-2mhh-8chh-jm97.json index 596129883b3..62cb8d3a229 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mhh-8chh-jm97/GHSA-2mhh-8chh-jm97.json +++ b/advisories/unreviewed/2022/05/GHSA-2mhh-8chh-jm97/GHSA-2mhh-8chh-jm97.json @@ -7,12 +7,8 @@ "CVE-2007-2496" ], "details": "The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) GotoPage, (6) Save, (7) SaveWebFile, (8) HttpDownloadFile, (9) Open, (10) OpenWebFile, (11) SaveAs, or (12) ShowWordStandardDialog property value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2q5q-67x8-5hg2/GHSA-2q5q-67x8-5hg2.json b/advisories/unreviewed/2022/05/GHSA-2q5q-67x8-5hg2/GHSA-2q5q-67x8-5hg2.json index c96fe9057ab..3601796f195 100644 --- a/advisories/unreviewed/2022/05/GHSA-2q5q-67x8-5hg2/GHSA-2q5q-67x8-5hg2.json +++ b/advisories/unreviewed/2022/05/GHSA-2q5q-67x8-5hg2/GHSA-2q5q-67x8-5hg2.json @@ -7,12 +7,8 @@ "CVE-2007-2455" ], "details": "Parallels allows local users to cause a denial of service (virtual machine abort) via (1) certain INT instructions, as demonstrated by INT 0xAA; (2) an IRET instruction when an invalid address is at the top of the stack; (3) a malformed MOVNTI instruction, as demonstrated by using a register as a destination; or a write operation to (4) SEGR6 or (5) SEGR7.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2q82-hqvj-364r/GHSA-2q82-hqvj-364r.json b/advisories/unreviewed/2022/05/GHSA-2q82-hqvj-364r/GHSA-2q82-hqvj-364r.json index 97c8a2f0a74..737d50077e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-2q82-hqvj-364r/GHSA-2q82-hqvj-364r.json +++ b/advisories/unreviewed/2022/05/GHSA-2q82-hqvj-364r/GHSA-2q82-hqvj-364r.json @@ -7,12 +7,8 @@ "CVE-2007-2160" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the Database Administration (dba) module 4.6.x-*, and before 4.7.x-1.2 in the 4.7.x-1.* series, for Drupal allow remote attackers to perform unauthorized actions as an arbitrary user, a related issue to CVE-2006-5476.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2rxh-g7fp-j3f7/GHSA-2rxh-g7fp-j3f7.json b/advisories/unreviewed/2022/05/GHSA-2rxh-g7fp-j3f7/GHSA-2rxh-g7fp-j3f7.json index 6dc2e616a2f..0b253a7972e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rxh-g7fp-j3f7/GHSA-2rxh-g7fp-j3f7.json +++ b/advisories/unreviewed/2022/05/GHSA-2rxh-g7fp-j3f7/GHSA-2rxh-g7fp-j3f7.json @@ -7,12 +7,8 @@ "CVE-2007-2535" ], "details": "WinAce allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2vmv-r5mh-gqqw/GHSA-2vmv-r5mh-gqqw.json b/advisories/unreviewed/2022/05/GHSA-2vmv-r5mh-gqqw/GHSA-2vmv-r5mh-gqqw.json index 48875f59f93..47425ba9299 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vmv-r5mh-gqqw/GHSA-2vmv-r5mh-gqqw.json +++ b/advisories/unreviewed/2022/05/GHSA-2vmv-r5mh-gqqw/GHSA-2vmv-r5mh-gqqw.json @@ -7,12 +7,8 @@ "CVE-2007-2279" ], "details": "The Scheduler Service (VxSchedService.exe) in Symantec Storage Foundation for Windows 5.0 allows remote attackers to bypass authentication and execute arbitrary code via certain requests to the service socket that create (1) PreScript or (2) PostScript registry values under Veritas\\VxSvc\\CurrentVersion\\Schedules specifying future command execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2wrq-53r8-rc4c/GHSA-2wrq-53r8-rc4c.json b/advisories/unreviewed/2022/05/GHSA-2wrq-53r8-rc4c/GHSA-2wrq-53r8-rc4c.json index 113fc2ee6fd..c5c06b1548a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wrq-53r8-rc4c/GHSA-2wrq-53r8-rc4c.json +++ b/advisories/unreviewed/2022/05/GHSA-2wrq-53r8-rc4c/GHSA-2wrq-53r8-rc4c.json @@ -7,12 +7,8 @@ "CVE-2007-2480" ], "details": "The _udp_lib_get_port function in net/ipv4/udp.c in Linux kernel 2.6.21 and earlier does not prevent a bind to a port with a local address when there is already a bind to that port with a wildcard local address, which might allow local users to intercept local traffic for daemons or other applications.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2x77-fxv4-pcjj/GHSA-2x77-fxv4-pcjj.json b/advisories/unreviewed/2022/05/GHSA-2x77-fxv4-pcjj/GHSA-2x77-fxv4-pcjj.json index ef85fd4498e..24687b4d39a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2x77-fxv4-pcjj/GHSA-2x77-fxv4-pcjj.json +++ b/advisories/unreviewed/2022/05/GHSA-2x77-fxv4-pcjj/GHSA-2x77-fxv4-pcjj.json @@ -7,12 +7,8 @@ "CVE-2007-2273" ], "details": "PHP remote file inclusion vulnerability in include/loading.php in Alessandro Lulli wavewoo 0.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_include parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2xxv-v658-gjc8/GHSA-2xxv-v658-gjc8.json b/advisories/unreviewed/2022/05/GHSA-2xxv-v658-gjc8/GHSA-2xxv-v658-gjc8.json index 93439d6f6b4..c517d8bddf4 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xxv-v658-gjc8/GHSA-2xxv-v658-gjc8.json +++ b/advisories/unreviewed/2022/05/GHSA-2xxv-v658-gjc8/GHSA-2xxv-v658-gjc8.json @@ -7,12 +7,8 @@ "CVE-2007-2600" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php; or the (3) search parameter to search.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-32jw-x745-fx6j/GHSA-32jw-x745-fx6j.json b/advisories/unreviewed/2022/05/GHSA-32jw-x745-fx6j/GHSA-32jw-x745-fx6j.json index 8165158dd72..5a7597314f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-32jw-x745-fx6j/GHSA-32jw-x745-fx6j.json +++ b/advisories/unreviewed/2022/05/GHSA-32jw-x745-fx6j/GHSA-32jw-x745-fx6j.json @@ -7,12 +7,8 @@ "CVE-2007-2143" ], "details": "PHP remote file inclusion vulnerability in index.php in the Be2004-2 template for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-32r8-8mcq-93v7/GHSA-32r8-8mcq-93v7.json b/advisories/unreviewed/2022/05/GHSA-32r8-8mcq-93v7/GHSA-32r8-8mcq-93v7.json index ca09af1aa35..6e80be83e85 100644 --- a/advisories/unreviewed/2022/05/GHSA-32r8-8mcq-93v7/GHSA-32r8-8mcq-93v7.json +++ b/advisories/unreviewed/2022/05/GHSA-32r8-8mcq-93v7/GHSA-32r8-8mcq-93v7.json @@ -7,12 +7,8 @@ "CVE-2007-2187" ], "details": "Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote attackers to execute arbitrary code via a long DNS response. NOTE: this might be related to CVE-2006-6926.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-33wr-rmg5-rhwf/GHSA-33wr-rmg5-rhwf.json b/advisories/unreviewed/2022/05/GHSA-33wr-rmg5-rhwf/GHSA-33wr-rmg5-rhwf.json index 530131717b9..a50bde20d8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-33wr-rmg5-rhwf/GHSA-33wr-rmg5-rhwf.json +++ b/advisories/unreviewed/2022/05/GHSA-33wr-rmg5-rhwf/GHSA-33wr-rmg5-rhwf.json @@ -7,12 +7,8 @@ "CVE-2007-2405" ], "details": "Integer underflow in Preview in PDFKit on Apple Mac OS X 10.4.10 allows remote attackers to execute arbitrary code via a crafted PDF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-343h-59g9-rg9p/GHSA-343h-59g9-rg9p.json b/advisories/unreviewed/2022/05/GHSA-343h-59g9-rg9p/GHSA-343h-59g9-rg9p.json index ddf9ceb3b30..2d4d32cb140 100644 --- a/advisories/unreviewed/2022/05/GHSA-343h-59g9-rg9p/GHSA-343h-59g9-rg9p.json +++ b/advisories/unreviewed/2022/05/GHSA-343h-59g9-rg9p/GHSA-343h-59g9-rg9p.json @@ -7,12 +7,8 @@ "CVE-2007-2203" ], "details": "Cross-site scripting (XSS) vulnerability in Big Blue Guestbook allows remote attackers to inject arbitrary web script or HTML via the message field in the guestbook entry submission form.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-347f-rx79-6332/GHSA-347f-rx79-6332.json b/advisories/unreviewed/2022/05/GHSA-347f-rx79-6332/GHSA-347f-rx79-6332.json index 345950a63c6..eef0cea1cf9 100644 --- a/advisories/unreviewed/2022/05/GHSA-347f-rx79-6332/GHSA-347f-rx79-6332.json +++ b/advisories/unreviewed/2022/05/GHSA-347f-rx79-6332/GHSA-347f-rx79-6332.json @@ -7,12 +7,8 @@ "CVE-2007-2389" ], "details": "Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not clear potentially sensitive memory before use, which allows remote attackers to read memory from a web browser via unknown vectors related to Java applets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-34gx-7858-4cgx/GHSA-34gx-7858-4cgx.json b/advisories/unreviewed/2022/05/GHSA-34gx-7858-4cgx/GHSA-34gx-7858-4cgx.json index 8ec4cdb9c73..aa6cb2920d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-34gx-7858-4cgx/GHSA-34gx-7858-4cgx.json +++ b/advisories/unreviewed/2022/05/GHSA-34gx-7858-4cgx/GHSA-34gx-7858-4cgx.json @@ -7,12 +7,8 @@ "CVE-2007-2155" ], "details": "Directory traversal vulnerability in template.php in in phpFaber TopSites 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the modify parameter in a template action to admin/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-35h8-v5vr-r4m7/GHSA-35h8-v5vr-r4m7.json b/advisories/unreviewed/2022/05/GHSA-35h8-v5vr-r4m7/GHSA-35h8-v5vr-r4m7.json index 2464e02e259..14cafb1a6f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-35h8-v5vr-r4m7/GHSA-35h8-v5vr-r4m7.json +++ b/advisories/unreviewed/2022/05/GHSA-35h8-v5vr-r4m7/GHSA-35h8-v5vr-r4m7.json @@ -7,12 +7,8 @@ "CVE-2007-2246" ], "details": "Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.1; allows remote attackers to cause a denial of service via unknown attack vectors. NOTE: due to the lack of details from HP, it is not known whether this issue is a duplicate of another CVE such as CVE-2006-1173 or CVE-2006-4434.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-367v-6g5w-8w9w/GHSA-367v-6g5w-8w9w.json b/advisories/unreviewed/2022/05/GHSA-367v-6g5w-8w9w/GHSA-367v-6g5w-8w9w.json index 5963ffcf9e9..59a16ca631a 100644 --- a/advisories/unreviewed/2022/05/GHSA-367v-6g5w-8w9w/GHSA-367v-6g5w-8w9w.json +++ b/advisories/unreviewed/2022/05/GHSA-367v-6g5w-8w9w/GHSA-367v-6g5w-8w9w.json @@ -7,12 +7,8 @@ "CVE-2007-2346" ], "details": "Multiple PHP remote file inclusion vulnerabilities in PHP-Generics 1.0 beta allow remote attackers to execute arbitrary PHP code via a URL in the _APP_RELATIVE_PATH parameter to (1) include.php, (2) dbcommon/include.php, and (3) exception/include.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-38p5-v5hj-w48g/GHSA-38p5-v5hj-w48g.json b/advisories/unreviewed/2022/05/GHSA-38p5-v5hj-w48g/GHSA-38p5-v5hj-w48g.json index 798c738362f..6c56872b47a 100644 --- a/advisories/unreviewed/2022/05/GHSA-38p5-v5hj-w48g/GHSA-38p5-v5hj-w48g.json +++ b/advisories/unreviewed/2022/05/GHSA-38p5-v5hj-w48g/GHSA-38p5-v5hj-w48g.json @@ -7,12 +7,8 @@ "CVE-2007-2613" ], "details": "WikkaWiki (Wikka Wiki) before 1.1.6.3 allows attackers in a shared virtual host server environment to upload and execute an arbitrary configuration file by modifying the WAKKA_CONFIG environment variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3cmq-696r-cgp7/GHSA-3cmq-696r-cgp7.json b/advisories/unreviewed/2022/05/GHSA-3cmq-696r-cgp7/GHSA-3cmq-696r-cgp7.json index 301f2ca4d0b..bcbc9640746 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cmq-696r-cgp7/GHSA-3cmq-696r-cgp7.json +++ b/advisories/unreviewed/2022/05/GHSA-3cmq-696r-cgp7/GHSA-3cmq-696r-cgp7.json @@ -7,12 +7,8 @@ "CVE-2007-2018" ], "details": "SQL injection vulnerability in msg.php in AlstraSoft Video Share Enterprise allows remote authenticated users to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3cp2-4fv4-fx43/GHSA-3cp2-4fv4-fx43.json b/advisories/unreviewed/2022/05/GHSA-3cp2-4fv4-fx43/GHSA-3cp2-4fv4-fx43.json index 19c42b8b864..44e8450787f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cp2-4fv4-fx43/GHSA-3cp2-4fv4-fx43.json +++ b/advisories/unreviewed/2022/05/GHSA-3cp2-4fv4-fx43/GHSA-3cp2-4fv4-fx43.json @@ -7,12 +7,8 @@ "CVE-2007-2277" ], "details": "Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3cr8-c5g6-qr8f/GHSA-3cr8-c5g6-qr8f.json b/advisories/unreviewed/2022/05/GHSA-3cr8-c5g6-qr8f/GHSA-3cr8-c5g6-qr8f.json index 394ebde84ec..86d283a4b01 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cr8-c5g6-qr8f/GHSA-3cr8-c5g6-qr8f.json +++ b/advisories/unreviewed/2022/05/GHSA-3cr8-c5g6-qr8f/GHSA-3cr8-c5g6-qr8f.json @@ -7,12 +7,8 @@ "CVE-2007-2282" ], "details": "Cisco Network Services (CNS) NetFlow Collection Engine (NFC) before 6.0 has an nfcuser account with the default password nfcuser, which allows remote attackers to modify the product configuration and, when installed on Linux, obtain login access to the host operating system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3f6g-r82m-2vg5/GHSA-3f6g-r82m-2vg5.json b/advisories/unreviewed/2022/05/GHSA-3f6g-r82m-2vg5/GHSA-3f6g-r82m-2vg5.json index 83f01f2c9bf..cf3870b4e66 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f6g-r82m-2vg5/GHSA-3f6g-r82m-2vg5.json +++ b/advisories/unreviewed/2022/05/GHSA-3f6g-r82m-2vg5/GHSA-3f6g-r82m-2vg5.json @@ -7,12 +7,8 @@ "CVE-2007-2366" ], "details": "Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3f7x-wq77-2867/GHSA-3f7x-wq77-2867.json b/advisories/unreviewed/2022/05/GHSA-3f7x-wq77-2867/GHSA-3f7x-wq77-2867.json index 84232e81c64..4f74d957766 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f7x-wq77-2867/GHSA-3f7x-wq77-2867.json +++ b/advisories/unreviewed/2022/05/GHSA-3f7x-wq77-2867/GHSA-3f7x-wq77-2867.json @@ -7,12 +7,8 @@ "CVE-2007-2200" ], "details": "Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and possibly delete arbitrary files via a .. (dot dot) in the asolute parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3fr9-36vx-rp62/GHSA-3fr9-36vx-rp62.json b/advisories/unreviewed/2022/05/GHSA-3fr9-36vx-rp62/GHSA-3fr9-36vx-rp62.json index e7c82a91d32..e6ef6af7519 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fr9-36vx-rp62/GHSA-3fr9-36vx-rp62.json +++ b/advisories/unreviewed/2022/05/GHSA-3fr9-36vx-rp62/GHSA-3fr9-36vx-rp62.json @@ -7,12 +7,8 @@ "CVE-2007-2218" ], "details": "Unspecified vulnerability in the Windows Schannel Security Package for Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, allows remote servers to execute arbitrary code or cause a denial of service via crafted digital signatures that are processed during an SSL handshake.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3fwh-xpjw-6p29/GHSA-3fwh-xpjw-6p29.json b/advisories/unreviewed/2022/05/GHSA-3fwh-xpjw-6p29/GHSA-3fwh-xpjw-6p29.json index 2240ac24853..df09d5c95be 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fwh-xpjw-6p29/GHSA-3fwh-xpjw-6p29.json +++ b/advisories/unreviewed/2022/05/GHSA-3fwh-xpjw-6p29/GHSA-3fwh-xpjw-6p29.json @@ -7,12 +7,8 @@ "CVE-2007-2003" ], "details": "InoutMailingListManager 3.1 and earlier sends a Location redirect header but does not exit after an authorization check fails, which allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by ignoring the redirect.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3g33-62q3-g457/GHSA-3g33-62q3-g457.json b/advisories/unreviewed/2022/05/GHSA-3g33-62q3-g457/GHSA-3g33-62q3-g457.json index fc3c6aed619..2b75ad6d044 100644 --- a/advisories/unreviewed/2022/05/GHSA-3g33-62q3-g457/GHSA-3g33-62q3-g457.json +++ b/advisories/unreviewed/2022/05/GHSA-3g33-62q3-g457/GHSA-3g33-62q3-g457.json @@ -7,12 +7,8 @@ "CVE-2007-2141" ], "details": "Direct static code injection vulnerability in shoutbox.php in ShoutPro 1.5.2 allows remote attackers to inject arbitrary PHP code into shouts.php via the shout parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3hf5-wj4j-gfv8/GHSA-3hf5-wj4j-gfv8.json b/advisories/unreviewed/2022/05/GHSA-3hf5-wj4j-gfv8/GHSA-3hf5-wj4j-gfv8.json index 87cd7f83c8a..19fc2e17e93 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hf5-wj4j-gfv8/GHSA-3hf5-wj4j-gfv8.json +++ b/advisories/unreviewed/2022/05/GHSA-3hf5-wj4j-gfv8/GHSA-3hf5-wj4j-gfv8.json @@ -7,12 +7,8 @@ "CVE-2007-2394" ], "details": "Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via crafted (1) title and (2) author fields in an SMIL file, related to improper calculations for memory allocation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3hp6-grf9-hxg4/GHSA-3hp6-grf9-hxg4.json b/advisories/unreviewed/2022/05/GHSA-3hp6-grf9-hxg4/GHSA-3hp6-grf9-hxg4.json index a47ef4ec93f..12b936095f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hp6-grf9-hxg4/GHSA-3hp6-grf9-hxg4.json +++ b/advisories/unreviewed/2022/05/GHSA-3hp6-grf9-hxg4/GHSA-3hp6-grf9-hxg4.json @@ -7,12 +7,8 @@ "CVE-2007-2322" ], "details": "NMMediaServer.exe in Nero MediaHome 2.5.5.0 and CE 1.3.0.4 allows remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted packet that contains two CRLF sequences. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mc8-8xr7-cw36/GHSA-3mc8-8xr7-cw36.json b/advisories/unreviewed/2022/05/GHSA-3mc8-8xr7-cw36/GHSA-3mc8-8xr7-cw36.json index 223160123c0..951ed8f3c7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mc8-8xr7-cw36/GHSA-3mc8-8xr7-cw36.json +++ b/advisories/unreviewed/2022/05/GHSA-3mc8-8xr7-cw36/GHSA-3mc8-8xr7-cw36.json @@ -7,12 +7,8 @@ "CVE-2007-2275" ], "details": "Unspecified vulnerability in HP StorageWorks Command View Advanced Edition for XP before 5.6.0-01, XP Replication Monitor before 5.6.0-01, and XP Tiered Storage Manager before 5.5.0-02 allows local users to access other accounts via unspecified vectors during registration or addition of new users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3mp5-8f97-395w/GHSA-3mp5-8f97-395w.json b/advisories/unreviewed/2022/05/GHSA-3mp5-8f97-395w/GHSA-3mp5-8f97-395w.json index b4fa373c574..68ca2b3ff99 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mp5-8f97-395w/GHSA-3mp5-8f97-395w.json +++ b/advisories/unreviewed/2022/05/GHSA-3mp5-8f97-395w/GHSA-3mp5-8f97-395w.json @@ -7,12 +7,8 @@ "CVE-2007-2467" ], "details": "ZoneAlarm Pro 6.5.737.000, 6.1.744.001, and possibly earlier versions and other products, allows local users to cause a denial of service (system crash) by sending malformed data to the vsdatant device driver, which causes an invalid memory access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3q7q-248p-fr45/GHSA-3q7q-248p-fr45.json b/advisories/unreviewed/2022/05/GHSA-3q7q-248p-fr45/GHSA-3q7q-248p-fr45.json index a8b24a01549..a7aef035805 100644 --- a/advisories/unreviewed/2022/05/GHSA-3q7q-248p-fr45/GHSA-3q7q-248p-fr45.json +++ b/advisories/unreviewed/2022/05/GHSA-3q7q-248p-fr45/GHSA-3q7q-248p-fr45.json @@ -7,12 +7,8 @@ "CVE-2007-2373" ], "details": "SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3qfw-fw67-fvr8/GHSA-3qfw-fw67-fvr8.json b/advisories/unreviewed/2022/05/GHSA-3qfw-fw67-fvr8/GHSA-3qfw-fw67-fvr8.json index f1c6c0b8911..b2a926f780f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qfw-fw67-fvr8/GHSA-3qfw-fw67-fvr8.json +++ b/advisories/unreviewed/2022/05/GHSA-3qfw-fw67-fvr8/GHSA-3qfw-fw67-fvr8.json @@ -7,12 +7,8 @@ "CVE-2007-2418" ], "details": "Heap-based buffer overflow in the Rendezvous / Extensible Messaging and Presence Protocol (XMPP) component (plugins\\rendezvous.dll) for Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to execute arbitrary code via a message that triggers the overflow from expansion that occurs during encoding.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3v8c-79pr-r3c8/GHSA-3v8c-79pr-r3c8.json b/advisories/unreviewed/2022/05/GHSA-3v8c-79pr-r3c8/GHSA-3v8c-79pr-r3c8.json index 6d05063a59c..b795e42ee86 100644 --- a/advisories/unreviewed/2022/05/GHSA-3v8c-79pr-r3c8/GHSA-3v8c-79pr-r3c8.json +++ b/advisories/unreviewed/2022/05/GHSA-3v8c-79pr-r3c8/GHSA-3v8c-79pr-r3c8.json @@ -7,12 +7,8 @@ "CVE-2007-2337" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS 0.96.6 Alpha and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (b) magpie_simple.php in external/magpierss/scripts/, the (2) rss_url parameter to (c) magpie_slashbox.php in external/magpierss/scripts/, and the (3) body parameter to the (d) weblogmodule (aka Weblog Comments) module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vxj-488p-mqrx/GHSA-3vxj-488p-mqrx.json b/advisories/unreviewed/2022/05/GHSA-3vxj-488p-mqrx/GHSA-3vxj-488p-mqrx.json index dea0de712a3..120019ed2f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vxj-488p-mqrx/GHSA-3vxj-488p-mqrx.json +++ b/advisories/unreviewed/2022/05/GHSA-3vxj-488p-mqrx/GHSA-3vxj-488p-mqrx.json @@ -7,12 +7,8 @@ "CVE-2007-2623" ], "details": "Multiple buffer overflows in RControl.dll in Remote Display Dev kit 1.2.1.0 allow remote attackers to cause a denial of service (Internet Explorer 7 crash) via (1) a long first argument to the connect function or (2) a long InternalServer property value, possibly involving ntdll.dll.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3w6x-g2w9-f5ph/GHSA-3w6x-g2w9-f5ph.json b/advisories/unreviewed/2022/05/GHSA-3w6x-g2w9-f5ph/GHSA-3w6x-g2w9-f5ph.json index 3dad2466073..4766a4a2022 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w6x-g2w9-f5ph/GHSA-3w6x-g2w9-f5ph.json +++ b/advisories/unreviewed/2022/05/GHSA-3w6x-g2w9-f5ph/GHSA-3w6x-g2w9-f5ph.json @@ -7,12 +7,8 @@ "CVE-2007-2123" ], "details": "Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.3 up to 10.1.3.2.0, 10.1.2 up to 10.1.2.2.0, and 9.0.4.3 has unknown impact and attack vectors, aka AS04.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3xh6-2cvw-6jh4/GHSA-3xh6-2cvw-6jh4.json b/advisories/unreviewed/2022/05/GHSA-3xh6-2cvw-6jh4/GHSA-3xh6-2cvw-6jh4.json index b22d256f6a9..bd9d62201e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xh6-2cvw-6jh4/GHSA-3xh6-2cvw-6jh4.json +++ b/advisories/unreviewed/2022/05/GHSA-3xh6-2cvw-6jh4/GHSA-3xh6-2cvw-6jh4.json @@ -7,12 +7,8 @@ "CVE-2007-2545" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Persism CMS 0.9.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the system[path] parameter to (1) blocks/headerfile.php, (2) files/blocks/latest_files.php, (3) filters/headerfile.php, (4) forums/blocks/latest_posts.php, (5) groups/headerfile.php, (6) links/blocks/links.php, (7) menu/headerfile.php, (8) news/blocks/latest_news.php, (9) settings/headerfile.php, or (10) users/headerfile.php, in modules/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3xjj-j3q7-p3p7/GHSA-3xjj-j3q7-p3p7.json b/advisories/unreviewed/2022/05/GHSA-3xjj-j3q7-p3p7/GHSA-3xjj-j3q7-p3p7.json index bc663134e8e..7248ef846dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xjj-j3q7-p3p7/GHSA-3xjj-j3q7-p3p7.json +++ b/advisories/unreviewed/2022/05/GHSA-3xjj-j3q7-p3p7/GHSA-3xjj-j3q7-p3p7.json @@ -7,12 +7,8 @@ "CVE-2007-2526" ], "details": "Heap-based buffer overflow in the ConnectAsyncEx function in VNC Viewer ActiveX control (scvncctrl.dll) in the SmartCode VNC Manager 3.6 allows remote attackers to execute arbitrary code via a long argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-423c-qxjp-p4hr/GHSA-423c-qxjp-p4hr.json b/advisories/unreviewed/2022/05/GHSA-423c-qxjp-p4hr/GHSA-423c-qxjp-p4hr.json index fc810c5015c..a0e5fdae4b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-423c-qxjp-p4hr/GHSA-423c-qxjp-p4hr.json +++ b/advisories/unreviewed/2022/05/GHSA-423c-qxjp-p4hr/GHSA-423c-qxjp-p4hr.json @@ -7,12 +7,8 @@ "CVE-2007-2404" ], "details": "CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in an unspecified context. NOTE: this can be leveraged for cross-site scripting (XSS) attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4329-9f98-hhhp/GHSA-4329-9f98-hhhp.json b/advisories/unreviewed/2022/05/GHSA-4329-9f98-hhhp/GHSA-4329-9f98-hhhp.json index b68fc3155bf..3ca4d8e0ac6 100644 --- a/advisories/unreviewed/2022/05/GHSA-4329-9f98-hhhp/GHSA-4329-9f98-hhhp.json +++ b/advisories/unreviewed/2022/05/GHSA-4329-9f98-hhhp/GHSA-4329-9f98-hhhp.json @@ -7,12 +7,8 @@ "CVE-2007-2630" ], "details": "Incomplete blacklist vulnerability in filemanager/browser/default/connectors/php/config.php in the FCKeditor module, as used in ActiveCampaign 1-2-All (aka 12All) 4.50 through 4.53.13, and possibly other products, allows remote authenticated administrators to upload and possibly execute .php4 and .php5 files via unspecified vectors. NOTE: this issue is reachable through filemanager/browser/default/browser.html.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-43gr-pj36-rwvj/GHSA-43gr-pj36-rwvj.json b/advisories/unreviewed/2022/05/GHSA-43gr-pj36-rwvj/GHSA-43gr-pj36-rwvj.json index 736b1ac6362..c25ad596abd 100644 --- a/advisories/unreviewed/2022/05/GHSA-43gr-pj36-rwvj/GHSA-43gr-pj36-rwvj.json +++ b/advisories/unreviewed/2022/05/GHSA-43gr-pj36-rwvj/GHSA-43gr-pj36-rwvj.json @@ -7,12 +7,8 @@ "CVE-2007-2281" ], "details": "Integer overflow in the _ncp32._NtrpTCPReceiveMsg function in rds.exe in the Cell Manager Database Service in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via a large value in the size parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-44wf-6h25-4x7x/GHSA-44wf-6h25-4x7x.json b/advisories/unreviewed/2022/05/GHSA-44wf-6h25-4x7x/GHSA-44wf-6h25-4x7x.json index 1f8f975d530..4838b322518 100644 --- a/advisories/unreviewed/2022/05/GHSA-44wf-6h25-4x7x/GHSA-44wf-6h25-4x7x.json +++ b/advisories/unreviewed/2022/05/GHSA-44wf-6h25-4x7x/GHSA-44wf-6h25-4x7x.json @@ -7,12 +7,8 @@ "CVE-2007-2432" ], "details": "Cross-site scripting (XSS) vulnerability in utilities/search.asp in nukedit 4.9.7b allows remote attackers to inject arbitrary web script or HTML via the terms parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-44x9-mhh2-9wm8/GHSA-44x9-mhh2-9wm8.json b/advisories/unreviewed/2022/05/GHSA-44x9-mhh2-9wm8/GHSA-44x9-mhh2-9wm8.json index f6d39ef3a6f..4ee16823506 100644 --- a/advisories/unreviewed/2022/05/GHSA-44x9-mhh2-9wm8/GHSA-44x9-mhh2-9wm8.json +++ b/advisories/unreviewed/2022/05/GHSA-44x9-mhh2-9wm8/GHSA-44x9-mhh2-9wm8.json @@ -7,12 +7,8 @@ "CVE-2007-2163" ], "details": "Apple Safari allows remote attackers to cause a denial of service (browser crash) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-44xp-496v-cvw6/GHSA-44xp-496v-cvw6.json b/advisories/unreviewed/2022/05/GHSA-44xp-496v-cvw6/GHSA-44xp-496v-cvw6.json index 8f008bd03d5..434ad958781 100644 --- a/advisories/unreviewed/2022/05/GHSA-44xp-496v-cvw6/GHSA-44xp-496v-cvw6.json +++ b/advisories/unreviewed/2022/05/GHSA-44xp-496v-cvw6/GHSA-44xp-496v-cvw6.json @@ -7,12 +7,8 @@ "CVE-2007-2302" ], "details": "PHP remote file inclusion vulnerability in autoindex.php in Expow 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4545-9hjr-7769/GHSA-4545-9hjr-7769.json b/advisories/unreviewed/2022/05/GHSA-4545-9hjr-7769/GHSA-4545-9hjr-7769.json index 688020f2e3c..d619ec6d1ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-4545-9hjr-7769/GHSA-4545-9hjr-7769.json +++ b/advisories/unreviewed/2022/05/GHSA-4545-9hjr-7769/GHSA-4545-9hjr-7769.json @@ -7,12 +7,8 @@ "CVE-2007-2344" ], "details": "The BOOTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, on Windows allows remote attackers to cause a denial of service (daemon crash) via a UDP packet that contains an invalid \"packet type\" field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-463h-f22v-55wq/GHSA-463h-f22v-55wq.json b/advisories/unreviewed/2022/05/GHSA-463h-f22v-55wq/GHSA-463h-f22v-55wq.json index 5b9be27865f..aaa9f2fd2d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-463h-f22v-55wq/GHSA-463h-f22v-55wq.json +++ b/advisories/unreviewed/2022/05/GHSA-463h-f22v-55wq/GHSA-463h-f22v-55wq.json @@ -7,12 +7,8 @@ "CVE-2007-2420" ], "details": "SQL injection vulnerability in bry.asp in Burak Yilmaz Blog 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-46c9-23qf-qv56/GHSA-46c9-23qf-qv56.json b/advisories/unreviewed/2022/05/GHSA-46c9-23qf-qv56/GHSA-46c9-23qf-qv56.json index 51f3068502f..f2e3e114e4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-46c9-23qf-qv56/GHSA-46c9-23qf-qv56.json +++ b/advisories/unreviewed/2022/05/GHSA-46c9-23qf-qv56/GHSA-46c9-23qf-qv56.json @@ -7,12 +7,8 @@ "CVE-2007-2684" ], "details": "Jetbox CMS 2.1 allows remote attackers to obtain sensitive information via (1) a direct request to (a) main_page.php, (b) open_tree.php, and (c) outputs.php; (2) a malformed view parameter to index.php, as demonstrated with an SQL injection manipulation; or (3) the id[] parameter to admin/cms/opentree.php, which reveals the installation path in the resulting error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-46f7-973c-q8p8/GHSA-46f7-973c-q8p8.json b/advisories/unreviewed/2022/05/GHSA-46f7-973c-q8p8/GHSA-46f7-973c-q8p8.json index 9fe87805d3e..e4d344536ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-46f7-973c-q8p8/GHSA-46f7-973c-q8p8.json +++ b/advisories/unreviewed/2022/05/GHSA-46f7-973c-q8p8/GHSA-46f7-973c-q8p8.json @@ -7,12 +7,8 @@ "CVE-2007-2268" ], "details": "Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter to (1) login.php3 or (2) login_up.php3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-474g-rjf9-53mq/GHSA-474g-rjf9-53mq.json b/advisories/unreviewed/2022/05/GHSA-474g-rjf9-53mq/GHSA-474g-rjf9-53mq.json index 2fd30ce647b..2d5dda8fffa 100644 --- a/advisories/unreviewed/2022/05/GHSA-474g-rjf9-53mq/GHSA-474g-rjf9-53mq.json +++ b/advisories/unreviewed/2022/05/GHSA-474g-rjf9-53mq/GHSA-474g-rjf9-53mq.json @@ -7,12 +7,8 @@ "CVE-2007-2579" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ACP3 4.0 beta 3 allow remote attackers to inject arbitrary web script or HTML via (1) the form[mail] parameter to contact/contact/index.php; the (2) form[mods][] or (3) form[search_term] parameter to search/list/action_search/index.php; (4) the id parameter to modules/dl/download.php; (5) the form[cat] parameter to news/list/index.php; the (6) form[cat], (7) form[name], or (8) form[message] parameter to certain news/details/id_*/action_create/index.php files; or (9) the form[mail] parameter to newsletter/create/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-488g-2jcc-pf9r/GHSA-488g-2jcc-pf9r.json b/advisories/unreviewed/2022/05/GHSA-488g-2jcc-pf9r/GHSA-488g-2jcc-pf9r.json index 95437e8e0e7..0f18de5c4db 100644 --- a/advisories/unreviewed/2022/05/GHSA-488g-2jcc-pf9r/GHSA-488g-2jcc-pf9r.json +++ b/advisories/unreviewed/2022/05/GHSA-488g-2jcc-pf9r/GHSA-488g-2jcc-pf9r.json @@ -7,12 +7,8 @@ "CVE-2007-2014" ], "details": "PHP remote file inclusion vulnerability in include/blocks/week_events.php in MyNews 4.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter, a different vector than CVE-2007-0633.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-49c3-6339-jcv2/GHSA-49c3-6339-jcv2.json b/advisories/unreviewed/2022/05/GHSA-49c3-6339-jcv2/GHSA-49c3-6339-jcv2.json index 8c25a6c7a99..5b23a734c67 100644 --- a/advisories/unreviewed/2022/05/GHSA-49c3-6339-jcv2/GHSA-49c3-6339-jcv2.json +++ b/advisories/unreviewed/2022/05/GHSA-49c3-6339-jcv2/GHSA-49c3-6339-jcv2.json @@ -7,12 +7,8 @@ "CVE-2007-2378" ], "details": "The Google Web Toolkit (GWT) framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka \"JavaScript Hijacking.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-49px-c282-f5wm/GHSA-49px-c282-f5wm.json b/advisories/unreviewed/2022/05/GHSA-49px-c282-f5wm/GHSA-49px-c282-f5wm.json index e4fae8e1cf1..e139393971e 100644 --- a/advisories/unreviewed/2022/05/GHSA-49px-c282-f5wm/GHSA-49px-c282-f5wm.json +++ b/advisories/unreviewed/2022/05/GHSA-49px-c282-f5wm/GHSA-49px-c282-f5wm.json @@ -7,12 +7,8 @@ "CVE-2007-2625" ], "details": "Cross-site scripting (XSS) vulnerability in shared/code/cp_authorization.php in All In One Control Panel (AIOCP) before 1.3.016 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-49wp-8p26-hh26/GHSA-49wp-8p26-hh26.json b/advisories/unreviewed/2022/05/GHSA-49wp-8p26-hh26/GHSA-49wp-8p26-hh26.json index 217e8d805bf..a16aa8e4108 100644 --- a/advisories/unreviewed/2022/05/GHSA-49wp-8p26-hh26/GHSA-49wp-8p26-hh26.json +++ b/advisories/unreviewed/2022/05/GHSA-49wp-8p26-hh26/GHSA-49wp-8p26-hh26.json @@ -7,12 +7,8 @@ "CVE-2007-2566" ], "details": "The SaveBarCode function in the Taltech Tal Bar Code ActiveX control allows remote attackers to cause a denial of service (disk consumption) by uploading multiple bar codes, as demonstrated by a WSF package.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-49xx-hhcj-4g3j/GHSA-49xx-hhcj-4g3j.json b/advisories/unreviewed/2022/05/GHSA-49xx-hhcj-4g3j/GHSA-49xx-hhcj-4g3j.json index 502ee46341a..3531117b15f 100644 --- a/advisories/unreviewed/2022/05/GHSA-49xx-hhcj-4g3j/GHSA-49xx-hhcj-4g3j.json +++ b/advisories/unreviewed/2022/05/GHSA-49xx-hhcj-4g3j/GHSA-49xx-hhcj-4g3j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4c97-8fc5-38qw/GHSA-4c97-8fc5-38qw.json b/advisories/unreviewed/2022/05/GHSA-4c97-8fc5-38qw/GHSA-4c97-8fc5-38qw.json index bd6ca8027d4..fc0e3ad7820 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c97-8fc5-38qw/GHSA-4c97-8fc5-38qw.json +++ b/advisories/unreviewed/2022/05/GHSA-4c97-8fc5-38qw/GHSA-4c97-8fc5-38qw.json @@ -7,12 +7,8 @@ "CVE-2007-1988" ], "details": "Cross-site scripting (XSS) vulnerability in kernel/filters.inc.php in PHPEcho CMS 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4cfr-8c5p-5jg6/GHSA-4cfr-8c5p-5jg6.json b/advisories/unreviewed/2022/05/GHSA-4cfr-8c5p-5jg6/GHSA-4cfr-8c5p-5jg6.json index 0761ec397f1..302375c5ca7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cfr-8c5p-5jg6/GHSA-4cfr-8c5p-5jg6.json +++ b/advisories/unreviewed/2022/05/GHSA-4cfr-8c5p-5jg6/GHSA-4cfr-8c5p-5jg6.json @@ -7,12 +7,8 @@ "CVE-2007-2452" ], "details": "Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4cg3-gvpw-4qmv/GHSA-4cg3-gvpw-4qmv.json b/advisories/unreviewed/2022/05/GHSA-4cg3-gvpw-4qmv/GHSA-4cg3-gvpw-4qmv.json index 66c02d8f25c..a6ba79be93c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cg3-gvpw-4qmv/GHSA-4cg3-gvpw-4qmv.json +++ b/advisories/unreviewed/2022/05/GHSA-4cg3-gvpw-4qmv/GHSA-4cg3-gvpw-4qmv.json @@ -7,12 +7,8 @@ "CVE-2007-2594" ], "details": "PHP remote file inclusion vulnerability in inc/articles.inc.php in phpMyPortal 3.0.0 RC3 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[CHEMINMODULES] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4cp7-6pr7-m98g/GHSA-4cp7-6pr7-m98g.json b/advisories/unreviewed/2022/05/GHSA-4cp7-6pr7-m98g/GHSA-4cp7-6pr7-m98g.json index a89c4cacbca..e95fcc7eedb 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cp7-6pr7-m98g/GHSA-4cp7-6pr7-m98g.json +++ b/advisories/unreviewed/2022/05/GHSA-4cp7-6pr7-m98g/GHSA-4cp7-6pr7-m98g.json @@ -7,12 +7,8 @@ "CVE-2007-2634" ], "details": "PHP remote file inclusion vulnerability in common/errormsg.php in aForum 1.32 and possibly earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the header parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4fph-fwq5-pwx5/GHSA-4fph-fwq5-pwx5.json b/advisories/unreviewed/2022/05/GHSA-4fph-fwq5-pwx5/GHSA-4fph-fwq5-pwx5.json index 3f889d11513..99dbd58cee5 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fph-fwq5-pwx5/GHSA-4fph-fwq5-pwx5.json +++ b/advisories/unreviewed/2022/05/GHSA-4fph-fwq5-pwx5/GHSA-4fph-fwq5-pwx5.json @@ -7,12 +7,8 @@ "CVE-2007-2671" ], "details": "Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in an HREF attribute in an A element, which triggers an out-of-bounds memory access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4fv5-g6r3-cjxh/GHSA-4fv5-g6r3-cjxh.json b/advisories/unreviewed/2022/05/GHSA-4fv5-g6r3-cjxh/GHSA-4fv5-g6r3-cjxh.json index 53c59651b49..b171765405d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fv5-g6r3-cjxh/GHSA-4fv5-g6r3-cjxh.json +++ b/advisories/unreviewed/2022/05/GHSA-4fv5-g6r3-cjxh/GHSA-4fv5-g6r3-cjxh.json @@ -7,12 +7,8 @@ "CVE-2007-2176" ], "details": "Unspecified vulnerability in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving Javascript errors. NOTE: this might be the same issue as CVE-2007-2175.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4g9m-wrg6-29mr/GHSA-4g9m-wrg6-29mr.json b/advisories/unreviewed/2022/05/GHSA-4g9m-wrg6-29mr/GHSA-4g9m-wrg6-29mr.json index 1d11d32045f..a08036482f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-4g9m-wrg6-29mr/GHSA-4g9m-wrg6-29mr.json +++ b/advisories/unreviewed/2022/05/GHSA-4g9m-wrg6-29mr/GHSA-4g9m-wrg6-29mr.json @@ -7,12 +7,8 @@ "CVE-2007-2005" ], "details": "Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) contact_type.php, (2) itemstatus_type.php, (3) projectstatus_type.php, (4) request_type.php, (5) responses_type.php, (6) timelog_type.php, or (7) urgency_type.php in inc/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4jcc-qmqj-6p2x/GHSA-4jcc-qmqj-6p2x.json b/advisories/unreviewed/2022/05/GHSA-4jcc-qmqj-6p2x/GHSA-4jcc-qmqj-6p2x.json index faba18d8fbc..a8c3dabbb32 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jcc-qmqj-6p2x/GHSA-4jcc-qmqj-6p2x.json +++ b/advisories/unreviewed/2022/05/GHSA-4jcc-qmqj-6p2x/GHSA-4jcc-qmqj-6p2x.json @@ -7,12 +7,8 @@ "CVE-2007-2139" ], "details": "Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite 2, and Business Protection Suite 2, allow remote attackers to execute arbitrary code via malformed RPC strings, a different vulnerability than CVE-2006-5171, CVE-2006-5172, and CVE-2007-1785.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4jmf-47xq-xvf3/GHSA-4jmf-47xq-xvf3.json b/advisories/unreviewed/2022/05/GHSA-4jmf-47xq-xvf3/GHSA-4jmf-47xq-xvf3.json index 334cc4fe541..00356af5d73 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jmf-47xq-xvf3/GHSA-4jmf-47xq-xvf3.json +++ b/advisories/unreviewed/2022/05/GHSA-4jmf-47xq-xvf3/GHSA-4jmf-47xq-xvf3.json @@ -7,12 +7,8 @@ "CVE-2007-2198" ], "details": "Cross-site scripting (XSS) vulnerability in LAN Management System (LMS) before 1.6.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably involving the OD parameter to contrib/formularz_przelewu_wplaty/druk.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4m64-fp2m-vhfj/GHSA-4m64-fp2m-vhfj.json b/advisories/unreviewed/2022/05/GHSA-4m64-fp2m-vhfj/GHSA-4m64-fp2m-vhfj.json index 9d122897fba..221b21d5f6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m64-fp2m-vhfj/GHSA-4m64-fp2m-vhfj.json +++ b/advisories/unreviewed/2022/05/GHSA-4m64-fp2m-vhfj/GHSA-4m64-fp2m-vhfj.json @@ -7,12 +7,8 @@ "CVE-2007-2533" ], "details": "Multiple buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2- Build 1174 allow remote attackers to execute arbitrary code via a crafted RPC message processed by the (1) the RPCFN_ActiveRollback function in (a) stcommon.dll, or the (2) ENG_SetRealTimeScanConfigInfo or (3) ENG_SendEmail functions in (b) eng50.dll.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4p2p-6cv5-fxv8/GHSA-4p2p-6cv5-fxv8.json b/advisories/unreviewed/2022/05/GHSA-4p2p-6cv5-fxv8/GHSA-4p2p-6cv5-fxv8.json index bd8486faa2c..663042f322b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p2p-6cv5-fxv8/GHSA-4p2p-6cv5-fxv8.json +++ b/advisories/unreviewed/2022/05/GHSA-4p2p-6cv5-fxv8/GHSA-4p2p-6cv5-fxv8.json @@ -7,12 +7,8 @@ "CVE-2007-2254" ], "details": "PHP remote file inclusion vulnerability in admin/setup/level2.php in PHP Classifieds 6.04, and probably earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this product was referred to as \"Allfaclassfieds\" in the original disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4q3g-xq49-mpmw/GHSA-4q3g-xq49-mpmw.json b/advisories/unreviewed/2022/05/GHSA-4q3g-xq49-mpmw/GHSA-4q3g-xq49-mpmw.json index a8a1ef918b7..e672721fc28 100644 --- a/advisories/unreviewed/2022/05/GHSA-4q3g-xq49-mpmw/GHSA-4q3g-xq49-mpmw.json +++ b/advisories/unreviewed/2022/05/GHSA-4q3g-xq49-mpmw/GHSA-4q3g-xq49-mpmw.json @@ -7,12 +7,8 @@ "CVE-2007-2524" ], "details": "Cross-site scripting (XSS) vulnerability in index.pl in Open Ticket Request System (OTRS) 2.0.x allows remote attackers to inject arbitrary web script or HTML via the Subaction parameter in an AgentTicketMailbox Action. NOTE: DEBIAN:DSA-1299 originally used this identifier for an ipsec-tools issue, but the proper identifier for the ipsec-tools issue is CVE-2007-1841.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4qc5-qj4v-hc88/GHSA-4qc5-qj4v-hc88.json b/advisories/unreviewed/2022/05/GHSA-4qc5-qj4v-hc88/GHSA-4qc5-qj4v-hc88.json index 70ea5600ad8..32bb2f010b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qc5-qj4v-hc88/GHSA-4qc5-qj4v-hc88.json +++ b/advisories/unreviewed/2022/05/GHSA-4qc5-qj4v-hc88/GHSA-4qc5-qj4v-hc88.json @@ -7,12 +7,8 @@ "CVE-2007-2332" ], "details": "Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 6_05.140 uses a fixed DES key to encrypt passwords, which allows remote authenticated users to obtain a password via a brute force attack on a hash from the LDAP store.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4r5w-gxp2-jf38/GHSA-4r5w-gxp2-jf38.json b/advisories/unreviewed/2022/05/GHSA-4r5w-gxp2-jf38/GHSA-4r5w-gxp2-jf38.json index d720b3a90f1..f4fa41a6d4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4r5w-gxp2-jf38/GHSA-4r5w-gxp2-jf38.json +++ b/advisories/unreviewed/2022/05/GHSA-4r5w-gxp2-jf38/GHSA-4r5w-gxp2-jf38.json @@ -7,12 +7,8 @@ "CVE-2007-2543" ], "details": "SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4v9r-hr3m-4m95/GHSA-4v9r-hr3m-4m95.json b/advisories/unreviewed/2022/05/GHSA-4v9r-hr3m-4m95/GHSA-4v9r-hr3m-4m95.json index ceed097eeae..6e0b0ecaf89 100644 --- a/advisories/unreviewed/2022/05/GHSA-4v9r-hr3m-4m95/GHSA-4v9r-hr3m-4m95.json +++ b/advisories/unreviewed/2022/05/GHSA-4v9r-hr3m-4m95/GHSA-4v9r-hr3m-4m95.json @@ -7,12 +7,8 @@ "CVE-2007-2584" ], "details": "Buffer overflow in the IsOldAppInstalled function in the McSubMgr.McSubMgr Subscription Manager ActiveX control (MCSUBMGR.DLL) in McAfee SecurityCenter before 6.0.25 and 7.x before 7.2.147 allows remote attackers to execute arbitrary code via a crafted argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vrm-366f-288x/GHSA-4vrm-366f-288x.json b/advisories/unreviewed/2022/05/GHSA-4vrm-366f-288x/GHSA-4vrm-366f-288x.json index 3b18441e25f..a6b9eb5e2b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vrm-366f-288x/GHSA-4vrm-366f-288x.json +++ b/advisories/unreviewed/2022/05/GHSA-4vrm-366f-288x/GHSA-4vrm-366f-288x.json @@ -7,12 +7,8 @@ "CVE-2007-2010" ], "details": "Double free vulnerability in bftpd before 1.8 allows remote authenticated users to cause a denial of service (daemon crash) via a (1) get or (2) mget command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4wv3-vrp8-r748/GHSA-4wv3-vrp8-r748.json b/advisories/unreviewed/2022/05/GHSA-4wv3-vrp8-r748/GHSA-4wv3-vrp8-r748.json index fced3b6e842..effde1eb567 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wv3-vrp8-r748/GHSA-4wv3-vrp8-r748.json +++ b/advisories/unreviewed/2022/05/GHSA-4wv3-vrp8-r748/GHSA-4wv3-vrp8-r748.json @@ -7,12 +7,8 @@ "CVE-2007-2296" ], "details": "Integer overflow in the FlipFileTypeAtom_BtoN function in Apple Quicktime 7.1.5, and other versions before 7.2, allows remote attackers to execute arbitrary code via a crafted M4V (MP4) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4xh7-8hqg-hhwm/GHSA-4xh7-8hqg-hhwm.json b/advisories/unreviewed/2022/05/GHSA-4xh7-8hqg-hhwm/GHSA-4xh7-8hqg-hhwm.json index 1d9335eacdb..eecd7a14a64 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xh7-8hqg-hhwm/GHSA-4xh7-8hqg-hhwm.json +++ b/advisories/unreviewed/2022/05/GHSA-4xh7-8hqg-hhwm/GHSA-4xh7-8hqg-hhwm.json @@ -7,12 +7,8 @@ "CVE-2007-2676" ], "details": "PHP remote file inclusion vulnerability in skins/header.php in Open Translation Engine (OTE) 0.7.8 allows remote attackers to execute arbitrary PHP code via a URL in the ote_home parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-526x-g8gf-5374/GHSA-526x-g8gf-5374.json b/advisories/unreviewed/2022/05/GHSA-526x-g8gf-5374/GHSA-526x-g8gf-5374.json index fd6f526eb7d..32563d444ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-526x-g8gf-5374/GHSA-526x-g8gf-5374.json +++ b/advisories/unreviewed/2022/05/GHSA-526x-g8gf-5374/GHSA-526x-g8gf-5374.json @@ -7,12 +7,8 @@ "CVE-2007-2585" ], "details": "Stack-based buffer overflow in the Verify function in the BarCodeWiz ActiveX control 2.0 and 2.52 (BarcodeWiz.dll) allows remote attackers to execute arbitrary code via a long argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-52rp-w429-m5h3/GHSA-52rp-w429-m5h3.json b/advisories/unreviewed/2022/05/GHSA-52rp-w429-m5h3/GHSA-52rp-w429-m5h3.json index 2c4ea8f41a5..cba81f85119 100644 --- a/advisories/unreviewed/2022/05/GHSA-52rp-w429-m5h3/GHSA-52rp-w429-m5h3.json +++ b/advisories/unreviewed/2022/05/GHSA-52rp-w429-m5h3/GHSA-52rp-w429-m5h3.json @@ -7,12 +7,8 @@ "CVE-2007-2673" ], "details": "SQL injection vulnerability in includes/funcs_vendors.php in Censura 1.15.04, and other versions before 1.16.04, allows remote attackers to execute arbitrary SQL commands via the vendorid parameter in a vendor_info cmd action to censura.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5425-rmvf-3g7c/GHSA-5425-rmvf-3g7c.json b/advisories/unreviewed/2022/05/GHSA-5425-rmvf-3g7c/GHSA-5425-rmvf-3g7c.json index 1960af7a8cf..bdce396db28 100644 --- a/advisories/unreviewed/2022/05/GHSA-5425-rmvf-3g7c/GHSA-5425-rmvf-3g7c.json +++ b/advisories/unreviewed/2022/05/GHSA-5425-rmvf-3g7c/GHSA-5425-rmvf-3g7c.json @@ -7,12 +7,8 @@ "CVE-2007-2409" ], "details": "Cross-domain vulnerability in WebCore on Apple Mac OS X 10.3.9 and 10.4.10 allows remote attackers to obtain sensitive information via a popup window, which is able to read the current URL of the parent window.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-54rc-mc5j-qmh6/GHSA-54rc-mc5j-qmh6.json b/advisories/unreviewed/2022/05/GHSA-54rc-mc5j-qmh6/GHSA-54rc-mc5j-qmh6.json index 6ae7af932e0..5e7a9229c9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-54rc-mc5j-qmh6/GHSA-54rc-mc5j-qmh6.json +++ b/advisories/unreviewed/2022/05/GHSA-54rc-mc5j-qmh6/GHSA-54rc-mc5j-qmh6.json @@ -7,12 +7,8 @@ "CVE-2007-2641" ], "details": "SQL injection vulnerability in W1L3D4_bolum.asp in W1L3D4 Philboard 0.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter, a different vector than CVE-2007-0920.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-552w-ccwr-xp2x/GHSA-552w-ccwr-xp2x.json b/advisories/unreviewed/2022/05/GHSA-552w-ccwr-xp2x/GHSA-552w-ccwr-xp2x.json index d6e3b980c87..bbfdd5caf65 100644 --- a/advisories/unreviewed/2022/05/GHSA-552w-ccwr-xp2x/GHSA-552w-ccwr-xp2x.json +++ b/advisories/unreviewed/2022/05/GHSA-552w-ccwr-xp2x/GHSA-552w-ccwr-xp2x.json @@ -7,12 +7,8 @@ "CVE-2007-2652" ], "details": "Multiple unspecified vulnerabilities in Free-SA before 1.2.2 allow remote attackers to execute arbitrary code via unspecified vectors involving certain (1) sprintf and (2) vsprintf calls in (a) r_index.c, (b) r_reports.c, (c) r_topsites.c, (d) r_topuser.c, (e) r_typical.c, (f) r_userdatetime.c, and (g) r_users.c in reports/; and (h) w_fs.c, (i) w_internal.c, and (j) w_log_operations.c in work/, probably related to buffer overflows. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5773-38m5-4h98/GHSA-5773-38m5-4h98.json b/advisories/unreviewed/2022/05/GHSA-5773-38m5-4h98/GHSA-5773-38m5-4h98.json index 95654c0f83f..7e24b9b6325 100644 --- a/advisories/unreviewed/2022/05/GHSA-5773-38m5-4h98/GHSA-5773-38m5-4h98.json +++ b/advisories/unreviewed/2022/05/GHSA-5773-38m5-4h98/GHSA-5773-38m5-4h98.json @@ -7,12 +7,8 @@ "CVE-2007-2416" ], "details": "SQL injection vulnerability in home.php in E-Annu allows remote attackers to execute arbitrary SQL commands via the a parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-58f8-vv6f-x94q/GHSA-58f8-vv6f-x94q.json b/advisories/unreviewed/2022/05/GHSA-58f8-vv6f-x94q/GHSA-58f8-vv6f-x94q.json index b14c0fd1f61..1ed63745c38 100644 --- a/advisories/unreviewed/2022/05/GHSA-58f8-vv6f-x94q/GHSA-58f8-vv6f-x94q.json +++ b/advisories/unreviewed/2022/05/GHSA-58f8-vv6f-x94q/GHSA-58f8-vv6f-x94q.json @@ -7,12 +7,8 @@ "CVE-2007-2341" ], "details": "PHP remote file inclusion vulnerability in suite/index.php in phpBandManager 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-58jx-v4q9-wgxj/GHSA-58jx-v4q9-wgxj.json b/advisories/unreviewed/2022/05/GHSA-58jx-v4q9-wgxj/GHSA-58jx-v4q9-wgxj.json index 3f9e327af44..5b08522964f 100644 --- a/advisories/unreviewed/2022/05/GHSA-58jx-v4q9-wgxj/GHSA-58jx-v4q9-wgxj.json +++ b/advisories/unreviewed/2022/05/GHSA-58jx-v4q9-wgxj/GHSA-58jx-v4q9-wgxj.json @@ -7,12 +7,8 @@ "CVE-2007-2575" ], "details": "PHP remote file inclusion vulnerability in watermark.php in the vm (aka Jean-Francois Laflamme) watermark 0.4.1 mod for Gallery allows remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-58vw-4wjx-hwmx/GHSA-58vw-4wjx-hwmx.json b/advisories/unreviewed/2022/05/GHSA-58vw-4wjx-hwmx/GHSA-58vw-4wjx-hwmx.json index 7914203beeb..aeeffd30702 100644 --- a/advisories/unreviewed/2022/05/GHSA-58vw-4wjx-hwmx/GHSA-58vw-4wjx-hwmx.json +++ b/advisories/unreviewed/2022/05/GHSA-58vw-4wjx-hwmx/GHSA-58vw-4wjx-hwmx.json @@ -7,12 +7,8 @@ "CVE-2007-2531" ], "details": "PHP remote file inclusion vulnerability in berylium-classes.php in Berylium2 2003-08-18 allows remote attackers to execute arbitrary PHP code via a URL in the beryliumroot parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-58xq-rpm3-xwc2/GHSA-58xq-rpm3-xwc2.json b/advisories/unreviewed/2022/05/GHSA-58xq-rpm3-xwc2/GHSA-58xq-rpm3-xwc2.json index e10e83f5777..faf7cf45310 100644 --- a/advisories/unreviewed/2022/05/GHSA-58xq-rpm3-xwc2/GHSA-58xq-rpm3-xwc2.json +++ b/advisories/unreviewed/2022/05/GHSA-58xq-rpm3-xwc2/GHSA-58xq-rpm3-xwc2.json @@ -7,12 +7,8 @@ "CVE-2007-2644" ], "details": "A certain ActiveX control in Morovia Barcode ActiveX Professional 3.3.1304 allows remote attackers to overwrite arbitrary files by calling the Save method with an arbitrary filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5f5v-hf9p-3jjx/GHSA-5f5v-hf9p-3jjx.json b/advisories/unreviewed/2022/05/GHSA-5f5v-hf9p-3jjx/GHSA-5f5v-hf9p-3jjx.json index 93cf20f7d99..829f04e4986 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f5v-hf9p-3jjx/GHSA-5f5v-hf9p-3jjx.json +++ b/advisories/unreviewed/2022/05/GHSA-5f5v-hf9p-3jjx/GHSA-5f5v-hf9p-3jjx.json @@ -7,12 +7,8 @@ "CVE-2007-2189" ], "details": "PHP remote file inclusion vulnerability in admin/admin_album_otf.php in the MX Smartor Full Album Pack (FAP) 2.0 RC1 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5hf6-562j-g393/GHSA-5hf6-562j-g393.json b/advisories/unreviewed/2022/05/GHSA-5hf6-562j-g393/GHSA-5hf6-562j-g393.json index 56875bef03e..cb3a8f558d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hf6-562j-g393/GHSA-5hf6-562j-g393.json +++ b/advisories/unreviewed/2022/05/GHSA-5hf6-562j-g393/GHSA-5hf6-562j-g393.json @@ -7,12 +7,8 @@ "CVE-2007-2577" ], "details": "Multiple SQL injection vulnerabilities in ACP3 4.0 beta 3 allow remote attackers to execute arbitrary SQL commands via (1) the mode parameter to feeds.php, the (2) form[cat] parameter to (a) news/list/index.php or (b) certain news/details/id_*/action_create/index.php files, or (3) the form[mods][] parameter to search/list/action_search/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5hfx-qqxc-xf62/GHSA-5hfx-qqxc-xf62.json b/advisories/unreviewed/2022/05/GHSA-5hfx-qqxc-xf62/GHSA-5hfx-qqxc-xf62.json index 79a4c2a8b4f..0529b22065a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hfx-qqxc-xf62/GHSA-5hfx-qqxc-xf62.json +++ b/advisories/unreviewed/2022/05/GHSA-5hfx-qqxc-xf62/GHSA-5hfx-qqxc-xf62.json @@ -7,12 +7,8 @@ "CVE-2007-2224" ], "details": "Object linking and embedding (OLE) Automation, as used in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Office 2004 for Mac, and Visual Basic 6.0 allows remote attackers to execute arbitrary code via the substringData method on a TextNode object, which causes an integer overflow that leads to a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jfq-g5rx-47mh/GHSA-5jfq-g5rx-47mh.json b/advisories/unreviewed/2022/05/GHSA-5jfq-g5rx-47mh/GHSA-5jfq-g5rx-47mh.json index dc5be3070ba..4fe03440f6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jfq-g5rx-47mh/GHSA-5jfq-g5rx-47mh.json +++ b/advisories/unreviewed/2022/05/GHSA-5jfq-g5rx-47mh/GHSA-5jfq-g5rx-47mh.json @@ -7,12 +7,8 @@ "CVE-2007-2659" ], "details": "Directory traversal vulnerability in index.php in PHP Advanced Transfer Manager (phpATM) 1.30 allows remote attackers to read arbitrary files and obtain script source code via a .. (dot dot) in the directory parameter in a downloadfile action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5mhv-62mq-c5pf/GHSA-5mhv-62mq-c5pf.json b/advisories/unreviewed/2022/05/GHSA-5mhv-62mq-c5pf/GHSA-5mhv-62mq-c5pf.json index 632814095a8..b579cb800f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mhv-62mq-c5pf/GHSA-5mhv-62mq-c5pf.json +++ b/advisories/unreviewed/2022/05/GHSA-5mhv-62mq-c5pf/GHSA-5mhv-62mq-c5pf.json @@ -7,12 +7,8 @@ "CVE-2007-2255" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Download-Engine 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) eng_dir parameter to addmember.php, (2) lang_path parameter to admin/enginelib/class.phpmailer.php, and the (3) spaw_root parameter to admin/includes/spaw/dialogs/colorpicker.php, different vectors than CVE-2006-5291 and CVE-2006-5459. NOTE: vector 3 might be an issue in SPAW.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5p82-w985-h72p/GHSA-5p82-w985-h72p.json b/advisories/unreviewed/2022/05/GHSA-5p82-w985-h72p/GHSA-5p82-w985-h72p.json index 67b550a1a54..c25274adf27 100644 --- a/advisories/unreviewed/2022/05/GHSA-5p82-w985-h72p/GHSA-5p82-w985-h72p.json +++ b/advisories/unreviewed/2022/05/GHSA-5p82-w985-h72p/GHSA-5p82-w985-h72p.json @@ -7,12 +7,8 @@ "CVE-2007-2493" ], "details": "PHP remote file inclusion vulnerability in faq.php in the FAQ & RULES 2.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5pmr-56fp-2w3m/GHSA-5pmr-56fp-2w3m.json b/advisories/unreviewed/2022/05/GHSA-5pmr-56fp-2w3m/GHSA-5pmr-56fp-2w3m.json index e7d463f84bb..4d5489a16e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pmr-56fp-2w3m/GHSA-5pmr-56fp-2w3m.json +++ b/advisories/unreviewed/2022/05/GHSA-5pmr-56fp-2w3m/GHSA-5pmr-56fp-2w3m.json @@ -7,12 +7,8 @@ "CVE-2007-2278" ], "details": "Multiple PHP remote file inclusion vulnerabilities in DCP-Portal 6.1.1 allow remote attackers to execute arbitrary PHP code via a URL in (1) the path parameter to library/adodb/adodb.inc.php, (2) the abs_path_editor parameter to library/editor/editor.php, or (3) the cfgfile_to_load parameter to admin/phpMyAdmin/libraries/common.lib.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5pr6-chwj-gjpq/GHSA-5pr6-chwj-gjpq.json b/advisories/unreviewed/2022/05/GHSA-5pr6-chwj-gjpq/GHSA-5pr6-chwj-gjpq.json index a57121c846f..f2b6e96ea52 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pr6-chwj-gjpq/GHSA-5pr6-chwj-gjpq.json +++ b/advisories/unreviewed/2022/05/GHSA-5pr6-chwj-gjpq/GHSA-5pr6-chwj-gjpq.json @@ -7,12 +7,8 @@ "CVE-2007-2008" ], "details": "Directory traversal vulnerability in admin.php in pL-PHP beta 0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5q5m-mjqc-gj8w/GHSA-5q5m-mjqc-gj8w.json b/advisories/unreviewed/2022/05/GHSA-5q5m-mjqc-gj8w/GHSA-5q5m-mjqc-gj8w.json index 7015149d5c9..e03015d79c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-5q5m-mjqc-gj8w/GHSA-5q5m-mjqc-gj8w.json +++ b/advisories/unreviewed/2022/05/GHSA-5q5m-mjqc-gj8w/GHSA-5q5m-mjqc-gj8w.json @@ -7,12 +7,8 @@ "CVE-2007-2167" ], "details": "Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into config.php via the number parameter in an update action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5qx7-4v6g-86g4/GHSA-5qx7-4v6g-86g4.json b/advisories/unreviewed/2022/05/GHSA-5qx7-4v6g-86g4/GHSA-5qx7-4v6g-86g4.json index 6b8cd938d36..57807f3e096 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qx7-4v6g-86g4/GHSA-5qx7-4v6g-86g4.json +++ b/advisories/unreviewed/2022/05/GHSA-5qx7-4v6g-86g4/GHSA-5qx7-4v6g-86g4.json @@ -7,12 +7,8 @@ "CVE-2007-2448" ], "details": "Subversion 1.4.3 and earlier does not properly implement the \"partial access\" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5r33-5w5f-f47j/GHSA-5r33-5w5f-f47j.json b/advisories/unreviewed/2022/05/GHSA-5r33-5w5f-f47j/GHSA-5r33-5w5f-f47j.json index 3e5031e47e4..c6f5a28da5b 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r33-5w5f-f47j/GHSA-5r33-5w5f-f47j.json +++ b/advisories/unreviewed/2022/05/GHSA-5r33-5w5f-f47j/GHSA-5r33-5w5f-f47j.json @@ -7,12 +7,8 @@ "CVE-2007-2591" ], "details": "usrmgr/userList.asp in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to modify user account details and cause a denial of service (account deactivation) via the userid parameter in an update action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5vv4-2x34-6cq2/GHSA-5vv4-2x34-6cq2.json b/advisories/unreviewed/2022/05/GHSA-5vv4-2x34-6cq2/GHSA-5vv4-2x34-6cq2.json index ce153cedfc9..ff12a6327a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vv4-2x34-6cq2/GHSA-5vv4-2x34-6cq2.json +++ b/advisories/unreviewed/2022/05/GHSA-5vv4-2x34-6cq2/GHSA-5vv4-2x34-6cq2.json @@ -7,12 +7,8 @@ "CVE-2007-2440" ], "details": "Directory traversal vulnerability in Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to read certain files via a .. (dot dot) in a URI containing a \"\\web-inf\" sequence.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5w58-cwpp-6wrj/GHSA-5w58-cwpp-6wrj.json b/advisories/unreviewed/2022/05/GHSA-5w58-cwpp-6wrj/GHSA-5w58-cwpp-6wrj.json index bba71c52007..b51027f8b00 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w58-cwpp-6wrj/GHSA-5w58-cwpp-6wrj.json +++ b/advisories/unreviewed/2022/05/GHSA-5w58-cwpp-6wrj/GHSA-5w58-cwpp-6wrj.json @@ -7,12 +7,8 @@ "CVE-2007-2147" ], "details": "admin/options.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier does not check for administrative credentials, which allows remote attackers to read and modify the classes/vars.php and classes/varstuff.php configuration files via direct requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5x4g-m68v-9h8f/GHSA-5x4g-m68v-9h8f.json b/advisories/unreviewed/2022/05/GHSA-5x4g-m68v-9h8f/GHSA-5x4g-m68v-9h8f.json index df5d2f0e1b8..0030307dd06 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x4g-m68v-9h8f/GHSA-5x4g-m68v-9h8f.json +++ b/advisories/unreviewed/2022/05/GHSA-5x4g-m68v-9h8f/GHSA-5x4g-m68v-9h8f.json @@ -7,12 +7,8 @@ "CVE-2007-2645" ], "details": "Integer overflow in the exif_data_load_data_entry function in exif-data.c in libexif before 0.6.14 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted EXIF data, involving the (1) doff or (2) s variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -108,9 +104,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-628g-c62g-r2j2/GHSA-628g-c62g-r2j2.json b/advisories/unreviewed/2022/05/GHSA-628g-c62g-r2j2/GHSA-628g-c62g-r2j2.json index 043f8a8aeb4..833436cab01 100644 --- a/advisories/unreviewed/2022/05/GHSA-628g-c62g-r2j2/GHSA-628g-c62g-r2j2.json +++ b/advisories/unreviewed/2022/05/GHSA-628g-c62g-r2j2/GHSA-628g-c62g-r2j2.json @@ -7,12 +7,8 @@ "CVE-2007-2508" ], "details": "Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote attackers to execute arbitrary code via crafted data to (1) TCP port 5168, which triggers an overflow in the CAgRpcClient::CreateBinding function in the AgRpcCln.dll library in SpntSvc.exe; or (2) TCP port 3628, which triggers an overflow in EarthAgent.exe. NOTE: both issues are reachable via TmRpcSrv.dll.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-62qw-x966-x9vh/GHSA-62qw-x966-x9vh.json b/advisories/unreviewed/2022/05/GHSA-62qw-x966-x9vh/GHSA-62qw-x966-x9vh.json index 7f736d2e0bb..461075a583a 100644 --- a/advisories/unreviewed/2022/05/GHSA-62qw-x966-x9vh/GHSA-62qw-x966-x9vh.json +++ b/advisories/unreviewed/2022/05/GHSA-62qw-x966-x9vh/GHSA-62qw-x966-x9vh.json @@ -7,12 +7,8 @@ "CVE-2007-1986" ], "details": "Multiple PHP remote file inclusion vulnerabilities in barnraiser AROUNDMe 0.7.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) language_path_core parameter to inc/core_profile.header.php, the (2) template_path_core parameter to template/barnraiser_01/maint_contact_view.tpl.php, and the (3) template_path parameter to template/barnraiser_01/default.tpl.php. NOTE: this issue might overlap CVE-2006-5533.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-63m8-pjhm-9hgq/GHSA-63m8-pjhm-9hgq.json b/advisories/unreviewed/2022/05/GHSA-63m8-pjhm-9hgq/GHSA-63m8-pjhm-9hgq.json index 621adc1b3ed..a9925040820 100644 --- a/advisories/unreviewed/2022/05/GHSA-63m8-pjhm-9hgq/GHSA-63m8-pjhm-9hgq.json +++ b/advisories/unreviewed/2022/05/GHSA-63m8-pjhm-9hgq/GHSA-63m8-pjhm-9hgq.json @@ -7,12 +7,8 @@ "CVE-2007-2664" ], "details": "PHP remote file inclusion vulnerability in includes/common.php in Yaap 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter, possibly related to the __autoload function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-63v5-44pf-fr9h/GHSA-63v5-44pf-fr9h.json b/advisories/unreviewed/2022/05/GHSA-63v5-44pf-fr9h/GHSA-63v5-44pf-fr9h.json index 41f8cbcffe7..7dbcdb89ffb 100644 --- a/advisories/unreviewed/2022/05/GHSA-63v5-44pf-fr9h/GHSA-63v5-44pf-fr9h.json +++ b/advisories/unreviewed/2022/05/GHSA-63v5-44pf-fr9h/GHSA-63v5-44pf-fr9h.json @@ -7,12 +7,8 @@ "CVE-2007-2312" ], "details": "Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the n parameter to extra/online.php and other unspecified scripts in extra/. NOTE: this might be same vulnerability as CVE-2006-4142; however, there is an intervening vendor fix announcement.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-64j7-8j49-mhvq/GHSA-64j7-8j49-mhvq.json b/advisories/unreviewed/2022/05/GHSA-64j7-8j49-mhvq/GHSA-64j7-8j49-mhvq.json index d3e16adbce2..ecaf11e23a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-64j7-8j49-mhvq/GHSA-64j7-8j49-mhvq.json +++ b/advisories/unreviewed/2022/05/GHSA-64j7-8j49-mhvq/GHSA-64j7-8j49-mhvq.json @@ -7,12 +7,8 @@ "CVE-2007-2197" ], "details": "Race condition in the NeatUpload ASP.NET component 1.2.11 through 1.2.16, 1.1.18 through 1.1.23, and trunk.379 through trunk.445 allows remote attackers to obtain other clients' HTTP responses via multiple simultaneous requests, which triggers multiple calls to HttpWorkerRequest.FlushResponse for the same HttpWorkerRequest object and causes a buffer to be reused for a different request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-66x7-w73j-m8cw/GHSA-66x7-w73j-m8cw.json b/advisories/unreviewed/2022/05/GHSA-66x7-w73j-m8cw/GHSA-66x7-w73j-m8cw.json index 06ae86ec619..ce4f1bd8220 100644 --- a/advisories/unreviewed/2022/05/GHSA-66x7-w73j-m8cw/GHSA-66x7-w73j-m8cw.json +++ b/advisories/unreviewed/2022/05/GHSA-66x7-w73j-m8cw/GHSA-66x7-w73j-m8cw.json @@ -7,12 +7,8 @@ "CVE-2007-2240" ], "details": "The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate digital signatures of downloaded software, which makes it easier for remote attackers to spoof a download.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6785-cq9h-6279/GHSA-6785-cq9h-6279.json b/advisories/unreviewed/2022/05/GHSA-6785-cq9h-6279/GHSA-6785-cq9h-6279.json index cc2819f53c4..7da382ca346 100644 --- a/advisories/unreviewed/2022/05/GHSA-6785-cq9h-6279/GHSA-6785-cq9h-6279.json +++ b/advisories/unreviewed/2022/05/GHSA-6785-cq9h-6279/GHSA-6785-cq9h-6279.json @@ -7,12 +7,8 @@ "CVE-2007-2598" ], "details": "SQL injection vulnerability in print.php in SimpleNews 1.0.0 FINAL allows remote attackers to execute arbitrary SQL commands via the news_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-68mr-m968-6x2w/GHSA-68mr-m968-6x2w.json b/advisories/unreviewed/2022/05/GHSA-68mr-m968-6x2w/GHSA-68mr-m968-6x2w.json index cd73d8b21ac..06cf616cf55 100644 --- a/advisories/unreviewed/2022/05/GHSA-68mr-m968-6x2w/GHSA-68mr-m968-6x2w.json +++ b/advisories/unreviewed/2022/05/GHSA-68mr-m968-6x2w/GHSA-68mr-m968-6x2w.json @@ -7,12 +7,8 @@ "CVE-2007-2274" ], "details": "The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and application crash) via a malformed torrent file. NOTE: the original disclosure refers to this as a memory leak, but it is not certain.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-69f9-9jhq-r4jq/GHSA-69f9-9jhq-r4jq.json b/advisories/unreviewed/2022/05/GHSA-69f9-9jhq-r4jq/GHSA-69f9-9jhq-r4jq.json index 7b8de976259..df33e17ced5 100644 --- a/advisories/unreviewed/2022/05/GHSA-69f9-9jhq-r4jq/GHSA-69f9-9jhq-r4jq.json +++ b/advisories/unreviewed/2022/05/GHSA-69f9-9jhq-r4jq/GHSA-69f9-9jhq-r4jq.json @@ -7,12 +7,8 @@ "CVE-2007-2514" ], "details": "Stack-based buffer overflow in XferWan.exe as used in multiple products including (1) Symantec Discovery 6.5, (2) Numara Asset Manager 8.0, and (3) Centennial UK Ltd Discovery 2006 Feature Pack, allows remote attackers to execute arbitrary code via a long request. NOTE: this might be a reservation duplicate of CVE-2007-1173.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6ccg-9jj9-744f/GHSA-6ccg-9jj9-744f.json b/advisories/unreviewed/2022/05/GHSA-6ccg-9jj9-744f/GHSA-6ccg-9jj9-744f.json index 371df7b2446..27af5c42191 100644 --- a/advisories/unreviewed/2022/05/GHSA-6ccg-9jj9-744f/GHSA-6ccg-9jj9-744f.json +++ b/advisories/unreviewed/2022/05/GHSA-6ccg-9jj9-744f/GHSA-6ccg-9jj9-744f.json @@ -7,12 +7,8 @@ "CVE-2007-2542" ], "details": "PHP remote file inclusion vulnerability in header.php in workbench survival guide 0.11 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6f2w-vw3w-mpcm/GHSA-6f2w-vw3w-mpcm.json b/advisories/unreviewed/2022/05/GHSA-6f2w-vw3w-mpcm/GHSA-6f2w-vw3w-mpcm.json index b203077f2ee..a9e7d4f1904 100644 --- a/advisories/unreviewed/2022/05/GHSA-6f2w-vw3w-mpcm/GHSA-6f2w-vw3w-mpcm.json +++ b/advisories/unreviewed/2022/05/GHSA-6f2w-vw3w-mpcm/GHSA-6f2w-vw3w-mpcm.json @@ -7,12 +7,8 @@ "CVE-2007-2538" ], "details": "SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the executed_queries array parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6gr4-p52c-wwrr/GHSA-6gr4-p52c-wwrr.json b/advisories/unreviewed/2022/05/GHSA-6gr4-p52c-wwrr/GHSA-6gr4-p52c-wwrr.json index e6b98e6bbb7..17635d0b53f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gr4-p52c-wwrr/GHSA-6gr4-p52c-wwrr.json +++ b/advisories/unreviewed/2022/05/GHSA-6gr4-p52c-wwrr/GHSA-6gr4-p52c-wwrr.json @@ -7,12 +7,8 @@ "CVE-2007-2571" ], "details": "SQL injection vulnerability in index.php in the wfquotes 1.0 0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6h5f-75j3-335c/GHSA-6h5f-75j3-335c.json b/advisories/unreviewed/2022/05/GHSA-6h5f-75j3-335c/GHSA-6h5f-75j3-335c.json index ef229163b76..c096ee7b844 100644 --- a/advisories/unreviewed/2022/05/GHSA-6h5f-75j3-335c/GHSA-6h5f-75j3-335c.json +++ b/advisories/unreviewed/2022/05/GHSA-6h5f-75j3-335c/GHSA-6h5f-75j3-335c.json @@ -7,12 +7,8 @@ "CVE-2007-2194" ], "details": "Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6j57-mwc4-hw6r/GHSA-6j57-mwc4-hw6r.json b/advisories/unreviewed/2022/05/GHSA-6j57-mwc4-hw6r/GHSA-6j57-mwc4-hw6r.json index 65e08f6f1ef..f6975c291de 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j57-mwc4-hw6r/GHSA-6j57-mwc4-hw6r.json +++ b/advisories/unreviewed/2022/05/GHSA-6j57-mwc4-hw6r/GHSA-6j57-mwc4-hw6r.json @@ -7,12 +7,8 @@ "CVE-2007-2271" ], "details": "Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the dnld parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6m3q-62rm-rrw9/GHSA-6m3q-62rm-rrw9.json b/advisories/unreviewed/2022/05/GHSA-6m3q-62rm-rrw9/GHSA-6m3q-62rm-rrw9.json index ba4ae72f8d3..b3d7931f936 100644 --- a/advisories/unreviewed/2022/05/GHSA-6m3q-62rm-rrw9/GHSA-6m3q-62rm-rrw9.json +++ b/advisories/unreviewed/2022/05/GHSA-6m3q-62rm-rrw9/GHSA-6m3q-62rm-rrw9.json @@ -7,12 +7,8 @@ "CVE-2007-2193" ], "details": "Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build 195 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6mhw-7qg9-h9x4/GHSA-6mhw-7qg9-h9x4.json b/advisories/unreviewed/2022/05/GHSA-6mhw-7qg9-h9x4/GHSA-6mhw-7qg9-h9x4.json index e75e9674e54..fc31bb87d26 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mhw-7qg9-h9x4/GHSA-6mhw-7qg9-h9x4.json +++ b/advisories/unreviewed/2022/05/GHSA-6mhw-7qg9-h9x4/GHSA-6mhw-7qg9-h9x4.json @@ -7,12 +7,8 @@ "CVE-2007-2247" ], "details": "SQL injection vulnerability in modules/news/article.php in phpMySpace Gold 8.10 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6mmv-f2gv-mm85/GHSA-6mmv-f2gv-mm85.json b/advisories/unreviewed/2022/05/GHSA-6mmv-f2gv-mm85/GHSA-6mmv-f2gv-mm85.json index b5734ed5bd3..4d5b2f9349f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mmv-f2gv-mm85/GHSA-6mmv-f2gv-mm85.json +++ b/advisories/unreviewed/2022/05/GHSA-6mmv-f2gv-mm85/GHSA-6mmv-f2gv-mm85.json @@ -7,12 +7,8 @@ "CVE-2007-2129" ], "details": "Unspecified vulnerability in the Agent component in Oracle Enterprise Manager 9.2.0.8 has unknown impact and remote attack vectors, aka EM01.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6mxh-h8cv-wf4j/GHSA-6mxh-h8cv-wf4j.json b/advisories/unreviewed/2022/05/GHSA-6mxh-h8cv-wf4j/GHSA-6mxh-h8cv-wf4j.json index 94cb01bbd9c..5cd2a7e3b2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mxh-h8cv-wf4j/GHSA-6mxh-h8cv-wf4j.json +++ b/advisories/unreviewed/2022/05/GHSA-6mxh-h8cv-wf4j/GHSA-6mxh-h8cv-wf4j.json @@ -7,12 +7,8 @@ "CVE-2007-2377" ], "details": "The Getahead Direct Web Remoting (DWR) framework 1.1.4 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka \"JavaScript Hijacking.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6p2c-4gh8-g4c5/GHSA-6p2c-4gh8-g4c5.json b/advisories/unreviewed/2022/05/GHSA-6p2c-4gh8-g4c5/GHSA-6p2c-4gh8-g4c5.json index 9ad80e83e15..c4144bfeabf 100644 --- a/advisories/unreviewed/2022/05/GHSA-6p2c-4gh8-g4c5/GHSA-6p2c-4gh8-g4c5.json +++ b/advisories/unreviewed/2022/05/GHSA-6p2c-4gh8-g4c5/GHSA-6p2c-4gh8-g4c5.json @@ -7,12 +7,8 @@ "CVE-2007-2209" ], "details": "Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.20 and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted .CLP file. NOTE: some details were obtained from third party sources.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6q3f-wf4j-86jw/GHSA-6q3f-wf4j-86jw.json b/advisories/unreviewed/2022/05/GHSA-6q3f-wf4j-86jw/GHSA-6q3f-wf4j-86jw.json index 17ad9c76540..104860dfb23 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q3f-wf4j-86jw/GHSA-6q3f-wf4j-86jw.json +++ b/advisories/unreviewed/2022/05/GHSA-6q3f-wf4j-86jw/GHSA-6q3f-wf4j-86jw.json @@ -7,12 +7,8 @@ "CVE-2007-2510" ], "details": "Buffer overflow in the make_http_soap_request function in PHP before 5.2.2 has unknown impact and remote attack vectors, possibly related to \"/\" (slash) characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6qm3-gv23-wcjv/GHSA-6qm3-gv23-wcjv.json b/advisories/unreviewed/2022/05/GHSA-6qm3-gv23-wcjv/GHSA-6qm3-gv23-wcjv.json index ed81df7d0b2..5ebea253908 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qm3-gv23-wcjv/GHSA-6qm3-gv23-wcjv.json +++ b/advisories/unreviewed/2022/05/GHSA-6qm3-gv23-wcjv/GHSA-6qm3-gv23-wcjv.json @@ -7,12 +7,8 @@ "CVE-2007-2669" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PHPChain 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the catid parameter to (1) settings.php or (2) cat.php. NOTE: certain parameter values also trigger path disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6rx7-hfpx-vp36/GHSA-6rx7-hfpx-vp36.json b/advisories/unreviewed/2022/05/GHSA-6rx7-hfpx-vp36/GHSA-6rx7-hfpx-vp36.json index 1d67fb3d928..ece0d73a747 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rx7-hfpx-vp36/GHSA-6rx7-hfpx-vp36.json +++ b/advisories/unreviewed/2022/05/GHSA-6rx7-hfpx-vp36/GHSA-6rx7-hfpx-vp36.json @@ -7,12 +7,8 @@ "CVE-2007-1978" ], "details": "SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view_game_list action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-72wq-j3f9-x5wf/GHSA-72wq-j3f9-x5wf.json b/advisories/unreviewed/2022/05/GHSA-72wq-j3f9-x5wf/GHSA-72wq-j3f9-x5wf.json index 9d6d27f9d30..cc21b70b1a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-72wq-j3f9-x5wf/GHSA-72wq-j3f9-x5wf.json +++ b/advisories/unreviewed/2022/05/GHSA-72wq-j3f9-x5wf/GHSA-72wq-j3f9-x5wf.json @@ -7,12 +7,8 @@ "CVE-2007-2011" ], "details": "Cross-site scripting (XSS) vulnerability in login.php in DeskPro 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-732x-fmvh-2fq4/GHSA-732x-fmvh-2fq4.json b/advisories/unreviewed/2022/05/GHSA-732x-fmvh-2fq4/GHSA-732x-fmvh-2fq4.json index 312b6399144..3474bf882c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-732x-fmvh-2fq4/GHSA-732x-fmvh-2fq4.json +++ b/advisories/unreviewed/2022/05/GHSA-732x-fmvh-2fq4/GHSA-732x-fmvh-2fq4.json @@ -7,12 +7,8 @@ "CVE-2007-2323" ], "details": "Multiple buffer overflows in the WinDVDX ActiveX control in InterVideo Home Theater 2.1.13.0 and 2.5.13.58 allow remote attackers to execute arbitrary code via a long string argument to the (1) GetDiscType or (2) AddFileList method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73rr-42r7-rv3h/GHSA-73rr-42r7-rv3h.json b/advisories/unreviewed/2022/05/GHSA-73rr-42r7-rv3h/GHSA-73rr-42r7-rv3h.json index dc0af157fff..3740559b0b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-73rr-42r7-rv3h/GHSA-73rr-42r7-rv3h.json +++ b/advisories/unreviewed/2022/05/GHSA-73rr-42r7-rv3h/GHSA-73rr-42r7-rv3h.json @@ -7,12 +7,8 @@ "CVE-2007-2560" ], "details": "Directory traversal vulnerability in theme/acgv.php in ACGVannu 1.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the rubrik parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-74cw-gq4c-qfqj/GHSA-74cw-gq4c-qfqj.json b/advisories/unreviewed/2022/05/GHSA-74cw-gq4c-qfqj/GHSA-74cw-gq4c-qfqj.json index e06502c2047..cec0509b15a 100644 --- a/advisories/unreviewed/2022/05/GHSA-74cw-gq4c-qfqj/GHSA-74cw-gq4c-qfqj.json +++ b/advisories/unreviewed/2022/05/GHSA-74cw-gq4c-qfqj/GHSA-74cw-gq4c-qfqj.json @@ -7,12 +7,8 @@ "CVE-2007-2211" ], "details": "SQL injection vulnerability in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a dayview action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7536-g6f6-346j/GHSA-7536-g6f6-346j.json b/advisories/unreviewed/2022/05/GHSA-7536-g6f6-346j/GHSA-7536-g6f6-346j.json index df80715476b..cd2bd977a6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7536-g6f6-346j/GHSA-7536-g6f6-346j.json +++ b/advisories/unreviewed/2022/05/GHSA-7536-g6f6-346j/GHSA-7536-g6f6-346j.json @@ -7,12 +7,8 @@ "CVE-2007-2597" ], "details": "Multiple PHP remote file inclusion vulnerabilities in telltarget CMS 1.3.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) ordnertiefe parameter to site_conf.php; or the (2) tt_docroot parameter to (a) class.csv.php, (b) produkte_nach_serie.php, or (c) ref_kd_rubrik.php in functionen/; (d) hg_referenz_jobgalerie.php, (e) surfer_anmeldung_NWL.php, (f) produkte_nach_serie_alle.php, (g) surfer_aendern.php, (h) ref_kd_rubrik.php, or (i) referenz.php in module/; or (j) 1/lay.php or (k) 3/lay.php in standard/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-75qx-jx75-r768/GHSA-75qx-jx75-r768.json b/advisories/unreviewed/2022/05/GHSA-75qx-jx75-r768/GHSA-75qx-jx75-r768.json index b0e6420c494..ca8c0f8a7b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-75qx-jx75-r768/GHSA-75qx-jx75-r768.json +++ b/advisories/unreviewed/2022/05/GHSA-75qx-jx75-r768/GHSA-75qx-jx75-r768.json @@ -7,12 +7,8 @@ "CVE-2007-2424" ], "details": "PHP remote file inclusion vulnerability in help/index.php in The Merchant (themerchant) 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the show parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-769c-mjpc-3rqq/GHSA-769c-mjpc-3rqq.json b/advisories/unreviewed/2022/05/GHSA-769c-mjpc-3rqq/GHSA-769c-mjpc-3rqq.json index 1a44dff8c75..ed4dbc4296c 100644 --- a/advisories/unreviewed/2022/05/GHSA-769c-mjpc-3rqq/GHSA-769c-mjpc-3rqq.json +++ b/advisories/unreviewed/2022/05/GHSA-769c-mjpc-3rqq/GHSA-769c-mjpc-3rqq.json @@ -7,12 +7,8 @@ "CVE-2007-2294" ], "details": "The Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by using MD5 authentication to authenticate a user that does not have a password defined in manager.conf, resulting in a NULL pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-77f8-35wm-83m8/GHSA-77f8-35wm-83m8.json b/advisories/unreviewed/2022/05/GHSA-77f8-35wm-83m8/GHSA-77f8-35wm-83m8.json index 65b2f4e2b5d..8146d4b44e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-77f8-35wm-83m8/GHSA-77f8-35wm-83m8.json +++ b/advisories/unreviewed/2022/05/GHSA-77f8-35wm-83m8/GHSA-77f8-35wm-83m8.json @@ -7,12 +7,8 @@ "CVE-2007-2636" ], "details": "Unspecified vulnerability in phpTodo before 0.8.1 allows remote attackers to have an unknown impact via newlines in regular expressions to (1) index.php, (2) feed.php, (3) prefs.php, and (4) todolist.php; and (5) classTodoItem.php and (6) phpTodoUser.php in libs/. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-77m8-v7xq-gqvg/GHSA-77m8-v7xq-gqvg.json b/advisories/unreviewed/2022/05/GHSA-77m8-v7xq-gqvg/GHSA-77m8-v7xq-gqvg.json index e081a2b8183..0adcebc575a 100644 --- a/advisories/unreviewed/2022/05/GHSA-77m8-v7xq-gqvg/GHSA-77m8-v7xq-gqvg.json +++ b/advisories/unreviewed/2022/05/GHSA-77m8-v7xq-gqvg/GHSA-77m8-v7xq-gqvg.json @@ -7,12 +7,8 @@ "CVE-2007-2665" ], "details": "PHP remote file inclusion vulnerability in block.php in PhpFirstPost 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the Include parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-79jm-rjrp-g4xq/GHSA-79jm-rjrp-g4xq.json b/advisories/unreviewed/2022/05/GHSA-79jm-rjrp-g4xq/GHSA-79jm-rjrp-g4xq.json index d7bb65357a3..1a6c42c5279 100644 --- a/advisories/unreviewed/2022/05/GHSA-79jm-rjrp-g4xq/GHSA-79jm-rjrp-g4xq.json +++ b/advisories/unreviewed/2022/05/GHSA-79jm-rjrp-g4xq/GHSA-79jm-rjrp-g4xq.json @@ -7,12 +7,8 @@ "CVE-2007-2236" ], "details": "footer.php in PunBB 1.2.14 and earlier allows remote attackers to include local files in include/user/ via a cross-site scripting (XSS) attack, or via the pun_include tag, as demonstrated by use of admin_options.php to execute PHP code from an uploaded avatar file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7cjp-9p56-j27r/GHSA-7cjp-9p56-j27r.json b/advisories/unreviewed/2022/05/GHSA-7cjp-9p56-j27r/GHSA-7cjp-9p56-j27r.json index 864284c242d..6725686157c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7cjp-9p56-j27r/GHSA-7cjp-9p56-j27r.json +++ b/advisories/unreviewed/2022/05/GHSA-7cjp-9p56-j27r/GHSA-7cjp-9p56-j27r.json @@ -7,12 +7,8 @@ "CVE-2007-2286" ], "details": "PHP remote file inclusion vulnerability in config.php in Built2Go PHP Link Portal 1.79 allows remote attackers to execute arbitrary PHP code via a URL in the full_path_to_db parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7j3r-7mf4-66hf/GHSA-7j3r-7mf4-66hf.json b/advisories/unreviewed/2022/05/GHSA-7j3r-7mf4-66hf/GHSA-7j3r-7mf4-66hf.json index 0399338bcd4..94fd8a19a1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j3r-7mf4-66hf/GHSA-7j3r-7mf4-66hf.json +++ b/advisories/unreviewed/2022/05/GHSA-7j3r-7mf4-66hf/GHSA-7j3r-7mf4-66hf.json @@ -7,12 +7,8 @@ "CVE-2007-2601" ], "details": "Buffer overflow in a certain ActiveX control in the GDivX Zenith Player AviFixer class in fix.dll 1.0.0.1 allows remote attackers to execute arbitrary code via a long SetInputFile property value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7mph-9r86-93q7/GHSA-7mph-9r86-93q7.json b/advisories/unreviewed/2022/05/GHSA-7mph-9r86-93q7/GHSA-7mph-9r86-93q7.json index 9c1c25e59d3..6378a99258e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mph-9r86-93q7/GHSA-7mph-9r86-93q7.json +++ b/advisories/unreviewed/2022/05/GHSA-7mph-9r86-93q7/GHSA-7mph-9r86-93q7.json @@ -7,12 +7,8 @@ "CVE-2007-2456" ], "details": "Multiple PHP remote file inclusion vulnerabilities in FireFly 1.1.01 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root parameter to (1) localize.php or (2) config.php in modules/admin/include/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7p48-v557-ccv7/GHSA-7p48-v557-ccv7.json b/advisories/unreviewed/2022/05/GHSA-7p48-v557-ccv7/GHSA-7p48-v557-ccv7.json index 048fc27ffcf..aba68abd487 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p48-v557-ccv7/GHSA-7p48-v557-ccv7.json +++ b/advisories/unreviewed/2022/05/GHSA-7p48-v557-ccv7/GHSA-7p48-v557-ccv7.json @@ -7,12 +7,8 @@ "CVE-2007-2330" ], "details": "PHP remote file inclusion vulnerability in includes_handler.php in DynaTracker 151 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7pf3-4xfm-r5v2/GHSA-7pf3-4xfm-r5v2.json b/advisories/unreviewed/2022/05/GHSA-7pf3-4xfm-r5v2/GHSA-7pf3-4xfm-r5v2.json index 3b0fb64abab..6a5f5c3e32d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pf3-4xfm-r5v2/GHSA-7pf3-4xfm-r5v2.json +++ b/advisories/unreviewed/2022/05/GHSA-7pf3-4xfm-r5v2/GHSA-7pf3-4xfm-r5v2.json @@ -7,12 +7,8 @@ "CVE-2007-2267" ], "details": "Unspecified vulnerability in Sun Cluster 3.1 and Solaris Cluster 3.2 before 20070424 allows remote authenticated users, operating from a different cluster node, to cause a denial of service (data corruption or send_mondo panic) via unspecified vectors, as demonstrated by EMC Symcli backup software 6.2.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7qqv-v567-jwh2/GHSA-7qqv-v567-jwh2.json b/advisories/unreviewed/2022/05/GHSA-7qqv-v567-jwh2/GHSA-7qqv-v567-jwh2.json index a9d0a719ade..8b28e480a9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qqv-v567-jwh2/GHSA-7qqv-v567-jwh2.json +++ b/advisories/unreviewed/2022/05/GHSA-7qqv-v567-jwh2/GHSA-7qqv-v567-jwh2.json @@ -7,12 +7,8 @@ "CVE-2007-2298" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertoire_config parameter to index.php in (1) cpe/, (2) direction/, or (3) professeurs/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7vvf-9wv5-9fw7/GHSA-7vvf-9wv5-9fw7.json b/advisories/unreviewed/2022/05/GHSA-7vvf-9wv5-9fw7/GHSA-7vvf-9wv5-9fw7.json index e95e79f055c..13bf982b301 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vvf-9wv5-9fw7/GHSA-7vvf-9wv5-9fw7.json +++ b/advisories/unreviewed/2022/05/GHSA-7vvf-9wv5-9fw7/GHSA-7vvf-9wv5-9fw7.json @@ -7,12 +7,8 @@ "CVE-2007-2398" ], "details": "Apple Safari 3.0.1 beta (522.12.12) on Windows allows remote attackers to modify the window title and address bar while filling the main window with arbitrary content by setting the location bar and using setTimeout() to create an event that modifies the window content, which could facilitate phishing attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7vwq-vq44-r563/GHSA-7vwq-vq44-r563.json b/advisories/unreviewed/2022/05/GHSA-7vwq-vq44-r563/GHSA-7vwq-vq44-r563.json index b66a6941148..cbda47cc568 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vwq-vq44-r563/GHSA-7vwq-vq44-r563.json +++ b/advisories/unreviewed/2022/05/GHSA-7vwq-vq44-r563/GHSA-7vwq-vq44-r563.json @@ -7,12 +7,8 @@ "CVE-2007-2568" ], "details": "Multiple stack-based buffer overflows in VCDGear 3.55 allow user-assisted remote attackers to execute arbitrary code via a long (1) tag or (2) track type in a CUE file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-829x-7jw5-28q3/GHSA-829x-7jw5-28q3.json b/advisories/unreviewed/2022/05/GHSA-829x-7jw5-28q3/GHSA-829x-7jw5-28q3.json index 9f71c7d1e30..4d45bac7301 100644 --- a/advisories/unreviewed/2022/05/GHSA-829x-7jw5-28q3/GHSA-829x-7jw5-28q3.json +++ b/advisories/unreviewed/2022/05/GHSA-829x-7jw5-28q3/GHSA-829x-7jw5-28q3.json @@ -7,12 +7,8 @@ "CVE-2007-2589" ], "details": "Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail 1.4.0 through 1.4.9a allows remote attackers to send e-mails from arbitrary users via certain data in the SRC attribute of an IMG element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82pq-c8g4-m2jw/GHSA-82pq-c8g4-m2jw.json b/advisories/unreviewed/2022/05/GHSA-82pq-c8g4-m2jw/GHSA-82pq-c8g4-m2jw.json index aaf3bfa81f2..a64c3576262 100644 --- a/advisories/unreviewed/2022/05/GHSA-82pq-c8g4-m2jw/GHSA-82pq-c8g4-m2jw.json +++ b/advisories/unreviewed/2022/05/GHSA-82pq-c8g4-m2jw/GHSA-82pq-c8g4-m2jw.json @@ -7,12 +7,8 @@ "CVE-2007-2127" ], "details": "Multiple unspecified vulnerabilities in Oracle E-Business Suite 12.0.0 have unknown impact and remote attack vectors via (1) Application Object Library (APPS04), iStore (2) APPS05 and (3) APPS06, (4) iSupport (APPS07), (5) Trade Management (APPS09), (6) Applications Manager (APPS10), and (7) Oracle Report Manager (APPS03).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-82r9-j2c5-gpfv/GHSA-82r9-j2c5-gpfv.json b/advisories/unreviewed/2022/05/GHSA-82r9-j2c5-gpfv/GHSA-82r9-j2c5-gpfv.json index fcd195ee0a9..22d178659e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-82r9-j2c5-gpfv/GHSA-82r9-j2c5-gpfv.json +++ b/advisories/unreviewed/2022/05/GHSA-82r9-j2c5-gpfv/GHSA-82r9-j2c5-gpfv.json @@ -7,12 +7,8 @@ "CVE-2007-2154" ], "details": "PHP remote file inclusion vulnerability in services/samples/inclusionService.php in Cabron Connector 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the CabronServiceFolder parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-82wj-rwrj-39cc/GHSA-82wj-rwrj-39cc.json b/advisories/unreviewed/2022/05/GHSA-82wj-rwrj-39cc/GHSA-82wj-rwrj-39cc.json index 89204c99373..f21307d1d71 100644 --- a/advisories/unreviewed/2022/05/GHSA-82wj-rwrj-39cc/GHSA-82wj-rwrj-39cc.json +++ b/advisories/unreviewed/2022/05/GHSA-82wj-rwrj-39cc/GHSA-82wj-rwrj-39cc.json @@ -7,12 +7,8 @@ "CVE-2007-2229" ], "details": "Microsoft Windows Vista uses insecure default permissions for unspecified \"local user information data stores\" in the registry and the file system, which allows local users to obtain sensitive information such as administrative passwords, aka \"Permissive User Information Store ACLs Information Disclosure Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-82x2-77j4-6g2v/GHSA-82x2-77j4-6g2v.json b/advisories/unreviewed/2022/05/GHSA-82x2-77j4-6g2v/GHSA-82x2-77j4-6g2v.json index 9d6048addac..0143dc3d7dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-82x2-77j4-6g2v/GHSA-82x2-77j4-6g2v.json +++ b/advisories/unreviewed/2022/05/GHSA-82x2-77j4-6g2v/GHSA-82x2-77j4-6g2v.json @@ -7,12 +7,8 @@ "CVE-2007-2002" ], "details": "InoutMailingListManager 3.1 and earlier allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by setting an arbitrary admin cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-833x-32f7-qpr7/GHSA-833x-32f7-qpr7.json b/advisories/unreviewed/2022/05/GHSA-833x-32f7-qpr7/GHSA-833x-32f7-qpr7.json index 2d55b349474..513234643f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-833x-32f7-qpr7/GHSA-833x-32f7-qpr7.json +++ b/advisories/unreviewed/2022/05/GHSA-833x-32f7-qpr7/GHSA-833x-32f7-qpr7.json @@ -7,12 +7,8 @@ "CVE-2007-2159" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Database Administration (dba) module 4.6.x-*, and before 4.7.x-1.2 in the 4.7.x-1.* series, for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors relating to (1) direct display of data from the database and (2) other portions of the user interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-835m-rqrf-284r/GHSA-835m-rqrf-284r.json b/advisories/unreviewed/2022/05/GHSA-835m-rqrf-284r/GHSA-835m-rqrf-284r.json index 522bed9110a..f477214e327 100644 --- a/advisories/unreviewed/2022/05/GHSA-835m-rqrf-284r/GHSA-835m-rqrf-284r.json +++ b/advisories/unreviewed/2022/05/GHSA-835m-rqrf-284r/GHSA-835m-rqrf-284r.json @@ -7,12 +7,8 @@ "CVE-2007-2019" ], "details": "PHP remote file inclusion vulnerability in init.gallery.php in phpGalleryScript 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the include_class parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-83qf-hj98-xp2q/GHSA-83qf-hj98-xp2q.json b/advisories/unreviewed/2022/05/GHSA-83qf-hj98-xp2q/GHSA-83qf-hj98-xp2q.json index 5ab573df26b..8c6cbfb5327 100644 --- a/advisories/unreviewed/2022/05/GHSA-83qf-hj98-xp2q/GHSA-83qf-hj98-xp2q.json +++ b/advisories/unreviewed/2022/05/GHSA-83qf-hj98-xp2q/GHSA-83qf-hj98-xp2q.json @@ -7,12 +7,8 @@ "CVE-2007-2326" ], "details": "Multiple PHP remote file inclusion vulnerabilities in HYIP Manager Pro allow remote attackers to execute arbitrary PHP code via a URL in the plugin_file parameter to (1) Smarty.class.php and (2) Smarty_Compiler.class.php in inc/libs/; (3) core.display_debug_console.php, (4) core.load_plugins.php, (5) core.load_resource_plugin.php, (6) core.process_cached_inserts.php, (7) core.process_compiled_include.php, and (8) core.read_cache_file.php in inc/libs/core/; and other unspecified files. NOTE: (1) and (2) might be incorrectly reported vectors in Smarty.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-83rw-h84w-77x9/GHSA-83rw-h84w-77x9.json b/advisories/unreviewed/2022/05/GHSA-83rw-h84w-77x9/GHSA-83rw-h84w-77x9.json index edb7f6af232..b85af008604 100644 --- a/advisories/unreviewed/2022/05/GHSA-83rw-h84w-77x9/GHSA-83rw-h84w-77x9.json +++ b/advisories/unreviewed/2022/05/GHSA-83rw-h84w-77x9/GHSA-83rw-h84w-77x9.json @@ -7,12 +7,8 @@ "CVE-2007-2357" ], "details": "Cross-site scripting (XSS) vulnerability in mods/Core/result.php in SineCms 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the stringa parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-83w3-xxm9-4ff8/GHSA-83w3-xxm9-4ff8.json b/advisories/unreviewed/2022/05/GHSA-83w3-xxm9-4ff8/GHSA-83w3-xxm9-4ff8.json index 5e612e50c2f..b9f2ee98861 100644 --- a/advisories/unreviewed/2022/05/GHSA-83w3-xxm9-4ff8/GHSA-83w3-xxm9-4ff8.json +++ b/advisories/unreviewed/2022/05/GHSA-83w3-xxm9-4ff8/GHSA-83w3-xxm9-4ff8.json @@ -7,12 +7,8 @@ "CVE-2007-1995" ], "details": "bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MP_REACH_NLRI and MP_UNREACH_NLRI attributes, which allows remote attackers to cause a denial of service (daemon crash or exit) via crafted UPDATE messages that trigger an assertion error or out of bounds read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-842j-cgp8-h39h/GHSA-842j-cgp8-h39h.json b/advisories/unreviewed/2022/05/GHSA-842j-cgp8-h39h/GHSA-842j-cgp8-h39h.json index 3535b0123bb..824282e8438 100644 --- a/advisories/unreviewed/2022/05/GHSA-842j-cgp8-h39h/GHSA-842j-cgp8-h39h.json +++ b/advisories/unreviewed/2022/05/GHSA-842j-cgp8-h39h/GHSA-842j-cgp8-h39h.json @@ -7,12 +7,8 @@ "CVE-2007-2251" ], "details": "Unspecified vulnerability in the Roles module in Xaraya 1.1.2 and earlier allows attackers to gain privileges via unspecified vectors, probably related to incorrect permission checking in xartemplates/user-view.xd.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-847q-f954-45mj/GHSA-847q-f954-45mj.json b/advisories/unreviewed/2022/05/GHSA-847q-f954-45mj/GHSA-847q-f954-45mj.json index 978f3c041dd..330ba411511 100644 --- a/advisories/unreviewed/2022/05/GHSA-847q-f954-45mj/GHSA-847q-f954-45mj.json +++ b/advisories/unreviewed/2022/05/GHSA-847q-f954-45mj/GHSA-847q-f954-45mj.json @@ -7,12 +7,8 @@ "CVE-2007-2201" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Post Revolution 6.6 and 7.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) common.php or (2) themes/default/preview_post_completo.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-85qr-hv25-pvmw/GHSA-85qr-hv25-pvmw.json b/advisories/unreviewed/2022/05/GHSA-85qr-hv25-pvmw/GHSA-85qr-hv25-pvmw.json index 5c0cc5c5305..11d18d5e875 100644 --- a/advisories/unreviewed/2022/05/GHSA-85qr-hv25-pvmw/GHSA-85qr-hv25-pvmw.json +++ b/advisories/unreviewed/2022/05/GHSA-85qr-hv25-pvmw/GHSA-85qr-hv25-pvmw.json @@ -7,12 +7,8 @@ "CVE-2007-2580" ], "details": "Unspecified vulnerability in Apple Safari allows local users to obtain sensitive information (saved keychain passwords) via the document.loginform.password.value JavaScript parameter loaded from an AppleScript script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-85rg-2jgh-frvj/GHSA-85rg-2jgh-frvj.json b/advisories/unreviewed/2022/05/GHSA-85rg-2jgh-frvj/GHSA-85rg-2jgh-frvj.json index c6cd79147a9..45494d7230c 100644 --- a/advisories/unreviewed/2022/05/GHSA-85rg-2jgh-frvj/GHSA-85rg-2jgh-frvj.json +++ b/advisories/unreviewed/2022/05/GHSA-85rg-2jgh-frvj/GHSA-85rg-2jgh-frvj.json @@ -7,12 +7,8 @@ "CVE-2007-2419" ], "details": "Multiple buffer overflows in an ActiveX control (boisweb.dll) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allow remote attackers to execute arbitrary code via the (1) the second parameter to the DownloadAndExecute method and (2) third parameter to the AddFileEx method, a different vulnerability than CVE-2007-0328.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-88h9-7hmj-878q/GHSA-88h9-7hmj-878q.json b/advisories/unreviewed/2022/05/GHSA-88h9-7hmj-878q/GHSA-88h9-7hmj-878q.json index f753dfe4007..05f11939304 100644 --- a/advisories/unreviewed/2022/05/GHSA-88h9-7hmj-878q/GHSA-88h9-7hmj-878q.json +++ b/advisories/unreviewed/2022/05/GHSA-88h9-7hmj-878q/GHSA-88h9-7hmj-878q.json @@ -7,12 +7,8 @@ "CVE-2007-2624" ], "details": "Dynamic variable evaluation vulnerability in shared/config/cp_config.php in All In One Control Panel (AIOCP) before 1.3.016 allows remote attackers to conduct cross-site scripting (XSS) and possibly other attacks via the SERVER superglobal array. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-88m6-mx5f-rjjp/GHSA-88m6-mx5f-rjjp.json b/advisories/unreviewed/2022/05/GHSA-88m6-mx5f-rjjp/GHSA-88m6-mx5f-rjjp.json index ba55a573ec3..b82dcb63ccc 100644 --- a/advisories/unreviewed/2022/05/GHSA-88m6-mx5f-rjjp/GHSA-88m6-mx5f-rjjp.json +++ b/advisories/unreviewed/2022/05/GHSA-88m6-mx5f-rjjp/GHSA-88m6-mx5f-rjjp.json @@ -7,12 +7,8 @@ "CVE-2007-2465" ], "details": "Unspecified vulnerability in Sun Solaris 9, when Solaris Auditing (BSM) is enabled for file read, write, attribute modify, create, or delete audit classes, allows local users to cause a denial of service (panic) via unknown vectors, possibly related to the audit_savepath function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-898q-fcfm-qrjw/GHSA-898q-fcfm-qrjw.json b/advisories/unreviewed/2022/05/GHSA-898q-fcfm-qrjw/GHSA-898q-fcfm-qrjw.json index 80290ffcdf1..01a10403689 100644 --- a/advisories/unreviewed/2022/05/GHSA-898q-fcfm-qrjw/GHSA-898q-fcfm-qrjw.json +++ b/advisories/unreviewed/2022/05/GHSA-898q-fcfm-qrjw/GHSA-898q-fcfm-qrjw.json @@ -7,12 +7,8 @@ "CVE-2007-2291" ], "details": "CRLF injection vulnerability in the Digest Authentication support for Microsoft Internet Explorer 7.0.5730.11 allows remote attackers to conduct HTTP response splitting attacks via a LF (%0a) in the username attribute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8c5w-487x-q6x4/GHSA-8c5w-487x-q6x4.json b/advisories/unreviewed/2022/05/GHSA-8c5w-487x-q6x4/GHSA-8c5w-487x-q6x4.json index 86df4fbb21c..d7394b00cad 100644 --- a/advisories/unreviewed/2022/05/GHSA-8c5w-487x-q6x4/GHSA-8c5w-487x-q6x4.json +++ b/advisories/unreviewed/2022/05/GHSA-8c5w-487x-q6x4/GHSA-8c5w-487x-q6x4.json @@ -7,12 +7,8 @@ "CVE-2007-2362" ], "details": "Multiple buffer overflows in MyDNS 1.1.0 allow remote attackers to (1) cause a denial of service (daemon crash) and possibly execute arbitrary code via a certain update, which triggers a heap-based buffer overflow in update.c; and (2) cause a denial of service (daemon crash) via unspecified vectors that trigger an off-by-one stack-based buffer overflow in update.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8cm4-3rmp-7f9m/GHSA-8cm4-3rmp-7f9m.json b/advisories/unreviewed/2022/05/GHSA-8cm4-3rmp-7f9m/GHSA-8cm4-3rmp-7f9m.json index a591cf01ad9..c501804ff82 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cm4-3rmp-7f9m/GHSA-8cm4-3rmp-7f9m.json +++ b/advisories/unreviewed/2022/05/GHSA-8cm4-3rmp-7f9m/GHSA-8cm4-3rmp-7f9m.json @@ -7,12 +7,8 @@ "CVE-2007-2385" ], "details": "The Yahoo! UI framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka \"JavaScript Hijacking.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8cvf-5jgg-fw72/GHSA-8cvf-5jgg-fw72.json b/advisories/unreviewed/2022/05/GHSA-8cvf-5jgg-fw72/GHSA-8cvf-5jgg-fw72.json index 8f7585e7590..c7d43849863 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cvf-5jgg-fw72/GHSA-8cvf-5jgg-fw72.json +++ b/advisories/unreviewed/2022/05/GHSA-8cvf-5jgg-fw72/GHSA-8cvf-5jgg-fw72.json @@ -7,12 +7,8 @@ "CVE-2007-2687" ], "details": "Stack-based buffer overflow in the MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan before 9.0.718.1 allows remote attackers to execute arbitrary code via a long command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8fv7-cr78-jp82/GHSA-8fv7-cr78-jp82.json b/advisories/unreviewed/2022/05/GHSA-8fv7-cr78-jp82/GHSA-8fv7-cr78-jp82.json index a71710b4b38..0cd1c89d307 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fv7-cr78-jp82/GHSA-8fv7-cr78-jp82.json +++ b/advisories/unreviewed/2022/05/GHSA-8fv7-cr78-jp82/GHSA-8fv7-cr78-jp82.json @@ -7,12 +7,8 @@ "CVE-2007-2356" ], "details": "Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attackers to execute arbitrary code via a crafted RAS file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8g2w-q2x8-86mf/GHSA-8g2w-q2x8-86mf.json b/advisories/unreviewed/2022/05/GHSA-8g2w-q2x8-86mf/GHSA-8g2w-q2x8-86mf.json index 9ec42365f45..fd35822eb7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g2w-q2x8-86mf/GHSA-8g2w-q2x8-86mf.json +++ b/advisories/unreviewed/2022/05/GHSA-8g2w-q2x8-86mf/GHSA-8g2w-q2x8-86mf.json @@ -7,12 +7,8 @@ "CVE-2007-2248" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Phorum before 5.1.22 allow remote attackers to inject arbitrary web script or HTML via the (1) group_id parameter in the groups module or (2) the smiley_id parameter in the smileys modsettings module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8gh7-9ww2-4ph8/GHSA-8gh7-9ww2-4ph8.json b/advisories/unreviewed/2022/05/GHSA-8gh7-9ww2-4ph8/GHSA-8gh7-9ww2-4ph8.json index 243934e47fc..0828c0c5b6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gh7-9ww2-4ph8/GHSA-8gh7-9ww2-4ph8.json +++ b/advisories/unreviewed/2022/05/GHSA-8gh7-9ww2-4ph8/GHSA-8gh7-9ww2-4ph8.json @@ -7,12 +7,8 @@ "CVE-2007-2595" ], "details": "RSAuction 2.73.1.3 allows remote authenticated users to move their own account status from Suspended to Active via a direct request for the activation URL that is provided at the time of account registration. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8gv2-jv6w-q9f2/GHSA-8gv2-jv6w-q9f2.json b/advisories/unreviewed/2022/05/GHSA-8gv2-jv6w-q9f2/GHSA-8gv2-jv6w-q9f2.json index 5eea910d99e..c32920cce00 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gv2-jv6w-q9f2/GHSA-8gv2-jv6w-q9f2.json +++ b/advisories/unreviewed/2022/05/GHSA-8gv2-jv6w-q9f2/GHSA-8gv2-jv6w-q9f2.json @@ -7,12 +7,8 @@ "CVE-2007-2441" ], "details": "Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to obtain the system path via certain URLs associated with (1) deploying web applications or (2) displaying .xtp files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8hj4-g75w-c8w9/GHSA-8hj4-g75w-c8w9.json b/advisories/unreviewed/2022/05/GHSA-8hj4-g75w-c8w9/GHSA-8hj4-g75w-c8w9.json index 30202a6a482..22362f76f07 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hj4-g75w-c8w9/GHSA-8hj4-g75w-c8w9.json +++ b/advisories/unreviewed/2022/05/GHSA-8hj4-g75w-c8w9/GHSA-8hj4-g75w-c8w9.json @@ -7,12 +7,8 @@ "CVE-2007-2374" ], "details": "Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8j8p-vqwm-hpgg/GHSA-8j8p-vqwm-hpgg.json b/advisories/unreviewed/2022/05/GHSA-8j8p-vqwm-hpgg/GHSA-8j8p-vqwm-hpgg.json index 08413ab6d8e..84508731d32 100644 --- a/advisories/unreviewed/2022/05/GHSA-8j8p-vqwm-hpgg/GHSA-8j8p-vqwm-hpgg.json +++ b/advisories/unreviewed/2022/05/GHSA-8j8p-vqwm-hpgg/GHSA-8j8p-vqwm-hpgg.json @@ -7,12 +7,8 @@ "CVE-2007-2309" ], "details": "Cross-site scripting (XSS) vulnerability in cas.php in FloweRS 2.0 allows remote attackers to inject arbitrary web script or HTML via the den parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8mcc-528j-m5qc/GHSA-8mcc-528j-m5qc.json b/advisories/unreviewed/2022/05/GHSA-8mcc-528j-m5qc/GHSA-8mcc-528j-m5qc.json index 165bd2b90d1..8b55594e001 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mcc-528j-m5qc/GHSA-8mcc-528j-m5qc.json +++ b/advisories/unreviewed/2022/05/GHSA-8mcc-528j-m5qc/GHSA-8mcc-528j-m5qc.json @@ -7,12 +7,8 @@ "CVE-2007-2225" ], "details": "A component in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle certain HTTP headers when processing MHTML protocol URLs, which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka \"URL Parsing Cross Domain Information Disclosure Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8phr-7r8f-j385/GHSA-8phr-7r8f-j385.json b/advisories/unreviewed/2022/05/GHSA-8phr-7r8f-j385/GHSA-8phr-7r8f-j385.json index 966f43d0275..a6d1b20cc19 100644 --- a/advisories/unreviewed/2022/05/GHSA-8phr-7r8f-j385/GHSA-8phr-7r8f-j385.json +++ b/advisories/unreviewed/2022/05/GHSA-8phr-7r8f-j385/GHSA-8phr-7r8f-j385.json @@ -7,12 +7,8 @@ "CVE-2007-2009" ], "details": "PHP remote file inclusion vulnerability in index.php in SimpCMS Light 04.10.2007 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8pmc-2r7m-mjxq/GHSA-8pmc-2r7m-mjxq.json b/advisories/unreviewed/2022/05/GHSA-8pmc-2r7m-mjxq/GHSA-8pmc-2r7m-mjxq.json index ab6dad94efb..b6997d4f1f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pmc-2r7m-mjxq/GHSA-8pmc-2r7m-mjxq.json +++ b/advisories/unreviewed/2022/05/GHSA-8pmc-2r7m-mjxq/GHSA-8pmc-2r7m-mjxq.json @@ -7,12 +7,8 @@ "CVE-2007-2567" ], "details": "Buffer overflow in the SaveBarCode function in the Taltech Tal Bar Code ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8prw-jfc2-ww83/GHSA-8prw-jfc2-ww83.json b/advisories/unreviewed/2022/05/GHSA-8prw-jfc2-ww83/GHSA-8prw-jfc2-ww83.json index 524b57044f0..fb50acb9640 100644 --- a/advisories/unreviewed/2022/05/GHSA-8prw-jfc2-ww83/GHSA-8prw-jfc2-ww83.json +++ b/advisories/unreviewed/2022/05/GHSA-8prw-jfc2-ww83/GHSA-8prw-jfc2-ww83.json @@ -7,12 +7,8 @@ "CVE-2007-2539" ], "details": "The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadata) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8pxx-h62p-4h8x/GHSA-8pxx-h62p-4h8x.json b/advisories/unreviewed/2022/05/GHSA-8pxx-h62p-4h8x/GHSA-8pxx-h62p-4h8x.json index 86e5bf050c7..515672da9d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pxx-h62p-4h8x/GHSA-8pxx-h62p-4h8x.json +++ b/advisories/unreviewed/2022/05/GHSA-8pxx-h62p-4h8x/GHSA-8pxx-h62p-4h8x.json @@ -7,12 +7,8 @@ "CVE-2007-2547" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to inject arbitrary web script or HTML via the l parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8q3h-j3f7-xvww/GHSA-8q3h-j3f7-xvww.json b/advisories/unreviewed/2022/05/GHSA-8q3h-j3f7-xvww/GHSA-8q3h-j3f7-xvww.json index bb43de7fdc5..0070f0266b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q3h-j3f7-xvww/GHSA-8q3h-j3f7-xvww.json +++ b/advisories/unreviewed/2022/05/GHSA-8q3h-j3f7-xvww/GHSA-8q3h-j3f7-xvww.json @@ -7,12 +7,8 @@ "CVE-2007-2012" ], "details": "Multiple directory traversal vulnerabilities in MimarSinan CompreXX 4.1 allow remote attackers to create files in arbitrary directories via a .. (dot dot) in a (1) .rar, (2) .jar or (3) .zip archive.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8qfr-2vxg-8g3g/GHSA-8qfr-2vxg-8g3g.json b/advisories/unreviewed/2022/05/GHSA-8qfr-2vxg-8g3g/GHSA-8qfr-2vxg-8g3g.json index 961ce5fa908..6a8bd746104 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qfr-2vxg-8g3g/GHSA-8qfr-2vxg-8g3g.json +++ b/advisories/unreviewed/2022/05/GHSA-8qfr-2vxg-8g3g/GHSA-8qfr-2vxg-8g3g.json @@ -7,12 +7,8 @@ "CVE-2007-2231" ], "details": "Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8r6h-xfvr-p56w/GHSA-8r6h-xfvr-p56w.json b/advisories/unreviewed/2022/05/GHSA-8r6h-xfvr-p56w/GHSA-8r6h-xfvr-p56w.json index 7e33e47c384..3825e330d60 100644 --- a/advisories/unreviewed/2022/05/GHSA-8r6h-xfvr-p56w/GHSA-8r6h-xfvr-p56w.json +++ b/advisories/unreviewed/2022/05/GHSA-8r6h-xfvr-p56w/GHSA-8r6h-xfvr-p56w.json @@ -7,12 +7,8 @@ "CVE-2007-2564" ], "details": "Multiple stack-based buffer overflows in the Sienzo Digital Music Mentor (DMM) 2.6.0.4 ActiveX control (DSKernel2.dll) allow remote attackers to execute arbitrary code via a long argument to the (1) LockModules or (2) UnlockModule function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8rq7-qcxc-ch26/GHSA-8rq7-qcxc-ch26.json b/advisories/unreviewed/2022/05/GHSA-8rq7-qcxc-ch26/GHSA-8rq7-qcxc-ch26.json index a64a9fc1db6..d33214e2219 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rq7-qcxc-ch26/GHSA-8rq7-qcxc-ch26.json +++ b/advisories/unreviewed/2022/05/GHSA-8rq7-qcxc-ch26/GHSA-8rq7-qcxc-ch26.json @@ -7,12 +7,8 @@ "CVE-2007-2650" ], "details": "The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that triggers an infinite loop, as demonstrated via a crafted DOC file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8v64-jpf9-w7wf/GHSA-8v64-jpf9-w7wf.json b/advisories/unreviewed/2022/05/GHSA-8v64-jpf9-w7wf/GHSA-8v64-jpf9-w7wf.json index 89c4ce33f40..2ab587957a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v64-jpf9-w7wf/GHSA-8v64-jpf9-w7wf.json +++ b/advisories/unreviewed/2022/05/GHSA-8v64-jpf9-w7wf/GHSA-8v64-jpf9-w7wf.json @@ -7,12 +7,8 @@ "CVE-2007-2596" ], "details": "PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CommonAbsDir parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8wmv-65jp-mqqj/GHSA-8wmv-65jp-mqqj.json b/advisories/unreviewed/2022/05/GHSA-8wmv-65jp-mqqj/GHSA-8wmv-65jp-mqqj.json index 5410d70fc29..a759473cb22 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wmv-65jp-mqqj/GHSA-8wmv-65jp-mqqj.json +++ b/advisories/unreviewed/2022/05/GHSA-8wmv-65jp-mqqj/GHSA-8wmv-65jp-mqqj.json @@ -7,12 +7,8 @@ "CVE-2007-2553" ], "details": "Unspecified vulnerability in dop in HP Tru64 UNIX 5.1B-4, 5.1B-3, and 5.1A PK6 allows local users to gain privileges via a large amount of data in the environment, as demonstrated by a long environment variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8x3f-9rwp-j5vc/GHSA-8x3f-9rwp-j5vc.json b/advisories/unreviewed/2022/05/GHSA-8x3f-9rwp-j5vc/GHSA-8x3f-9rwp-j5vc.json index bd1618a6d4c..ac124fd851b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8x3f-9rwp-j5vc/GHSA-8x3f-9rwp-j5vc.json +++ b/advisories/unreviewed/2022/05/GHSA-8x3f-9rwp-j5vc/GHSA-8x3f-9rwp-j5vc.json @@ -7,12 +7,8 @@ "CVE-2007-2605" ], "details": "Unspecified vulnerability in the GetPropertyById function in ISoftomateObj in SoftomateLib in BRUJULA4.NET.DLL in the Brujula Toolbar (Brujula.net toolbar) allows attackers to cause a denial of service (NULL dereference and browser crash) via certain arguments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-926v-8r5r-f64w/GHSA-926v-8r5r-f64w.json b/advisories/unreviewed/2022/05/GHSA-926v-8r5r-f64w/GHSA-926v-8r5r-f64w.json index 778176d2a08..984bc2c32ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-926v-8r5r-f64w/GHSA-926v-8r5r-f64w.json +++ b/advisories/unreviewed/2022/05/GHSA-926v-8r5r-f64w/GHSA-926v-8r5r-f64w.json @@ -7,12 +7,8 @@ "CVE-2007-2338" ], "details": "Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unauthorized banlist deletions as an administrator via the delete parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9278-w4jw-67jj/GHSA-9278-w4jw-67jj.json b/advisories/unreviewed/2022/05/GHSA-9278-w4jw-67jj/GHSA-9278-w4jw-67jj.json index 61004d089f3..88b6908d2df 100644 --- a/advisories/unreviewed/2022/05/GHSA-9278-w4jw-67jj/GHSA-9278-w4jw-67jj.json +++ b/advisories/unreviewed/2022/05/GHSA-9278-w4jw-67jj/GHSA-9278-w4jw-67jj.json @@ -7,12 +7,8 @@ "CVE-2007-2548" ], "details": "Unspecified vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 has unknown impact and an l remote attack vector, related to \"Cookie Manipulation.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-92ch-h5qf-x8rm/GHSA-92ch-h5qf-x8rm.json b/advisories/unreviewed/2022/05/GHSA-92ch-h5qf-x8rm/GHSA-92ch-h5qf-x8rm.json index 08fd11378dd..290e9881f7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-92ch-h5qf-x8rm/GHSA-92ch-h5qf-x8rm.json +++ b/advisories/unreviewed/2022/05/GHSA-92ch-h5qf-x8rm/GHSA-92ch-h5qf-x8rm.json @@ -7,12 +7,8 @@ "CVE-2007-2136" ], "details": "Stack-based buffer overflow in bgs_sdservice.exe in BMC Patrol PerformAgent allows remote attackers to execute arbitrary code by connecting to TCP port 10128 and sending certain XDR data, which is not properly parsed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-935q-32w8-v333/GHSA-935q-32w8-v333.json b/advisories/unreviewed/2022/05/GHSA-935q-32w8-v333/GHSA-935q-32w8-v333.json index 0da60f349fd..6554e057201 100644 --- a/advisories/unreviewed/2022/05/GHSA-935q-32w8-v333/GHSA-935q-32w8-v333.json +++ b/advisories/unreviewed/2022/05/GHSA-935q-32w8-v333/GHSA-935q-32w8-v333.json @@ -7,12 +7,8 @@ "CVE-2007-2607" ], "details": "PHP remote file inclusion vulnerability in views/print/printbar.php in LaVague 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the views_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-93g8-99xv-wchf/GHSA-93g8-99xv-wchf.json b/advisories/unreviewed/2022/05/GHSA-93g8-99xv-wchf/GHSA-93g8-99xv-wchf.json index 53a70594af8..fcd57c82011 100644 --- a/advisories/unreviewed/2022/05/GHSA-93g8-99xv-wchf/GHSA-93g8-99xv-wchf.json +++ b/advisories/unreviewed/2022/05/GHSA-93g8-99xv-wchf/GHSA-93g8-99xv-wchf.json @@ -7,12 +7,8 @@ "CVE-2007-2355" ], "details": "The get_url function in DODS_Dispatch.pm for the CGI_server in OPeNDAP 3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-93h6-x643-97x3/GHSA-93h6-x643-97x3.json b/advisories/unreviewed/2022/05/GHSA-93h6-x643-97x3/GHSA-93h6-x643-97x3.json index 99c11602843..d2800aeb3d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-93h6-x643-97x3/GHSA-93h6-x643-97x3.json +++ b/advisories/unreviewed/2022/05/GHSA-93h6-x643-97x3/GHSA-93h6-x643-97x3.json @@ -7,12 +7,8 @@ "CVE-2007-2556" ], "details": "SQL injection vulnerability in Nuked-klaN 1.7.6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For (X_FORWARDED_FOR) HTTP header, as demonstrated by a request to the /nk/ URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9457-pwmc-r2x4/GHSA-9457-pwmc-r2x4.json b/advisories/unreviewed/2022/05/GHSA-9457-pwmc-r2x4/GHSA-9457-pwmc-r2x4.json index ec8f1820972..a5dc34999cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-9457-pwmc-r2x4/GHSA-9457-pwmc-r2x4.json +++ b/advisories/unreviewed/2022/05/GHSA-9457-pwmc-r2x4/GHSA-9457-pwmc-r2x4.json @@ -7,12 +7,8 @@ "CVE-2007-2307" ], "details": "PHP remote file inclusion vulnerability in engine/engine.inc.php in WebKalk2 1.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-96jg-7cc3-fxr9/GHSA-96jg-7cc3-fxr9.json b/advisories/unreviewed/2022/05/GHSA-96jg-7cc3-fxr9/GHSA-96jg-7cc3-fxr9.json index 4c911213e4d..186d5696999 100644 --- a/advisories/unreviewed/2022/05/GHSA-96jg-7cc3-fxr9/GHSA-96jg-7cc3-fxr9.json +++ b/advisories/unreviewed/2022/05/GHSA-96jg-7cc3-fxr9/GHSA-96jg-7cc3-fxr9.json @@ -7,12 +7,8 @@ "CVE-2007-2611" ], "details": "Multiple PHP remote file inclusion vulnerabilities in CGX 20050314 allow remote attackers to execute arbitrary PHP code via a URL in the pathCGX parameter to (1) mtdialogo.php, (2) ltdialogo.php, (3) login.php, and (4) logingecon.php in inc/; and multiple unspecified files in frm/, sql/, and cns/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-96x7-r2p5-3fqw/GHSA-96x7-r2p5-3fqw.json b/advisories/unreviewed/2022/05/GHSA-96x7-r2p5-3fqw/GHSA-96x7-r2p5-3fqw.json index 76a9a533a42..ff42108065a 100644 --- a/advisories/unreviewed/2022/05/GHSA-96x7-r2p5-3fqw/GHSA-96x7-r2p5-3fqw.json +++ b/advisories/unreviewed/2022/05/GHSA-96x7-r2p5-3fqw/GHSA-96x7-r2p5-3fqw.json @@ -7,12 +7,8 @@ "CVE-2007-2648" ], "details": "Stack-based buffer overflow in the Clever Database Comparer 2.2 ActiveX control (comparerax.ocx) allows remote attackers to execute arbitrary code via a long argument to the ConnectToDatabase function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-97jg-4x8h-53r4/GHSA-97jg-4x8h-53r4.json b/advisories/unreviewed/2022/05/GHSA-97jg-4x8h-53r4/GHSA-97jg-4x8h-53r4.json index 5f242b570a3..d3097e21636 100644 --- a/advisories/unreviewed/2022/05/GHSA-97jg-4x8h-53r4/GHSA-97jg-4x8h-53r4.json +++ b/advisories/unreviewed/2022/05/GHSA-97jg-4x8h-53r4/GHSA-97jg-4x8h-53r4.json @@ -7,12 +7,8 @@ "CVE-2007-2305" ], "details": "Multiple SQL injection vulnerabilities in authenticate.php in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-98mf-x6gj-mfg3/GHSA-98mf-x6gj-mfg3.json b/advisories/unreviewed/2022/05/GHSA-98mf-x6gj-mfg3/GHSA-98mf-x6gj-mfg3.json index 0ac0fff9282..31e43f1f3f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-98mf-x6gj-mfg3/GHSA-98mf-x6gj-mfg3.json +++ b/advisories/unreviewed/2022/05/GHSA-98mf-x6gj-mfg3/GHSA-98mf-x6gj-mfg3.json @@ -7,12 +7,8 @@ "CVE-2007-2300" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Endy Kristanto Surat kabar / News Management Online (aka phpwebnews) 0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the m_txt parameter to (1) iklan.php, (2) index.php, or (3) bukutamu.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-98xx-c784-66x3/GHSA-98xx-c784-66x3.json b/advisories/unreviewed/2022/05/GHSA-98xx-c784-66x3/GHSA-98xx-c784-66x3.json index ed75171d78e..2c1b1891a8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-98xx-c784-66x3/GHSA-98xx-c784-66x3.json +++ b/advisories/unreviewed/2022/05/GHSA-98xx-c784-66x3/GHSA-98xx-c784-66x3.json @@ -7,12 +7,8 @@ "CVE-2007-2280" ], "details": "Stack-based buffer overflow in OmniInet.exe (aka the backup client service daemon) in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via an MSG_PROTOCOL command with long arguments, a different vulnerability than CVE-2009-3844.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-993q-wpwh-rhvq/GHSA-993q-wpwh-rhvq.json b/advisories/unreviewed/2022/05/GHSA-993q-wpwh-rhvq/GHSA-993q-wpwh-rhvq.json index 8081438036b..a3d95bde581 100644 --- a/advisories/unreviewed/2022/05/GHSA-993q-wpwh-rhvq/GHSA-993q-wpwh-rhvq.json +++ b/advisories/unreviewed/2022/05/GHSA-993q-wpwh-rhvq/GHSA-993q-wpwh-rhvq.json @@ -7,12 +7,8 @@ "CVE-2007-2135" ], "details": "The ADI_BINARY component in the Oracle E-Business Suite allows remote attackers to download arbitrary documents from the APPS.FND_DOCUMENTS table via the ADI_DISPLAY_REPORT function, when passed a certain parameter. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE identifiers such as CVE-2007-2126, CVE-2007-2127, or CVE-2007-2128.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-997v-pwx6-qjfq/GHSA-997v-pwx6-qjfq.json b/advisories/unreviewed/2022/05/GHSA-997v-pwx6-qjfq/GHSA-997v-pwx6-qjfq.json index 2be1d4df0d7..d70504e440a 100644 --- a/advisories/unreviewed/2022/05/GHSA-997v-pwx6-qjfq/GHSA-997v-pwx6-qjfq.json +++ b/advisories/unreviewed/2022/05/GHSA-997v-pwx6-qjfq/GHSA-997v-pwx6-qjfq.json @@ -7,12 +7,8 @@ "CVE-2007-2354" ], "details": "Progress Webspeed Messenger allows remote attackers to obtain sensitive information via a WService parameter containing \"wsbroker1/webutil/about.r\", which reveals the operating system and product information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9cxq-qfj2-hvjw/GHSA-9cxq-qfj2-hvjw.json b/advisories/unreviewed/2022/05/GHSA-9cxq-qfj2-hvjw/GHSA-9cxq-qfj2-hvjw.json index 8e708f4202f..bc4075b2f72 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cxq-qfj2-hvjw/GHSA-9cxq-qfj2-hvjw.json +++ b/advisories/unreviewed/2022/05/GHSA-9cxq-qfj2-hvjw/GHSA-9cxq-qfj2-hvjw.json @@ -7,12 +7,8 @@ "CVE-2007-2581" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in \"every main page,\" as demonstrated by default.aspx.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9ffv-4whq-h9qg/GHSA-9ffv-4whq-h9qg.json b/advisories/unreviewed/2022/05/GHSA-9ffv-4whq-h9qg/GHSA-9ffv-4whq-h9qg.json index f4944e5fd76..e5c99780c4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9ffv-4whq-h9qg/GHSA-9ffv-4whq-h9qg.json +++ b/advisories/unreviewed/2022/05/GHSA-9ffv-4whq-h9qg/GHSA-9ffv-4whq-h9qg.json @@ -7,12 +7,8 @@ "CVE-2007-2435" ], "details": "Sun Java Web Start in JDK and JRE 5.0 Update 10 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, allows remote attackers to perform unauthorized actions via an application that grants privileges to itself, related to \"Incorrect Use of System Classes\" and probably related to support for JNLP files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -144,9 +140,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9gcp-2jfc-jfrv/GHSA-9gcp-2jfc-jfrv.json b/advisories/unreviewed/2022/05/GHSA-9gcp-2jfc-jfrv/GHSA-9gcp-2jfc-jfrv.json index 6ba7fc976a8..ce17bb88f7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gcp-2jfc-jfrv/GHSA-9gcp-2jfc-jfrv.json +++ b/advisories/unreviewed/2022/05/GHSA-9gcp-2jfc-jfrv/GHSA-9gcp-2jfc-jfrv.json @@ -7,12 +7,8 @@ "CVE-2007-2221" ], "details": "Unspecified vulnerability in the mdsauth.dll COM object in Microsoft Windows Media Server in the Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; or 7 on Windows Vista allows remote attackers to overwrite arbitrary files via unspecified vectors, aka the \"Arbitrary File Rewrite Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9gf3-h693-qh48/GHSA-9gf3-h693-qh48.json b/advisories/unreviewed/2022/05/GHSA-9gf3-h693-qh48/GHSA-9gf3-h693-qh48.json index fbd4bee1a10..47177deb5d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gf3-h693-qh48/GHSA-9gf3-h693-qh48.json +++ b/advisories/unreviewed/2022/05/GHSA-9gf3-h693-qh48/GHSA-9gf3-h693-qh48.json @@ -7,12 +7,8 @@ "CVE-2007-2434" ], "details": "Buffer overflow in asnsp.dll in Aventail Connect 4.1.2.13 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a malformed DNS query.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9gpj-6mg9-3q6q/GHSA-9gpj-6mg9-3q6q.json b/advisories/unreviewed/2022/05/GHSA-9gpj-6mg9-3q6q/GHSA-9gpj-6mg9-3q6q.json index 2a626544f1e..7a4ac85640d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gpj-6mg9-3q6q/GHSA-9gpj-6mg9-3q6q.json +++ b/advisories/unreviewed/2022/05/GHSA-9gpj-6mg9-3q6q/GHSA-9gpj-6mg9-3q6q.json @@ -7,12 +7,8 @@ "CVE-2007-2654" ], "details": "xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gv6-chw7-g9x8/GHSA-9gv6-chw7-g9x8.json b/advisories/unreviewed/2022/05/GHSA-9gv6-chw7-g9x8/GHSA-9gv6-chw7-g9x8.json index 0604e1f3bdc..3775519606c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gv6-chw7-g9x8/GHSA-9gv6-chw7-g9x8.json +++ b/advisories/unreviewed/2022/05/GHSA-9gv6-chw7-g9x8/GHSA-9gv6-chw7-g9x8.json @@ -7,12 +7,8 @@ "CVE-2007-2541" ], "details": "PHP remote file inclusion vulnerability in includes/ajax_listado.php in Versado CMS 1.07 allows remote attackers to execute arbitrary PHP code via a URL in the urlModulo parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9jm8-7q7r-mfj7/GHSA-9jm8-7q7r-mfj7.json b/advisories/unreviewed/2022/05/GHSA-9jm8-7q7r-mfj7/GHSA-9jm8-7q7r-mfj7.json index b786cc71966..8914f614985 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jm8-7q7r-mfj7/GHSA-9jm8-7q7r-mfj7.json +++ b/advisories/unreviewed/2022/05/GHSA-9jm8-7q7r-mfj7/GHSA-9jm8-7q7r-mfj7.json @@ -7,12 +7,8 @@ "CVE-2007-2661" ], "details": "SQL injection vulnerability in archshow.asp in BlogMe 3.0 allows remote attackers to execute arbitrary SQL commands via the var parameter, a different vector than CVE-2006-5976.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9p38-m4m8-2mfm/GHSA-9p38-m4m8-2mfm.json b/advisories/unreviewed/2022/05/GHSA-9p38-m4m8-2mfm/GHSA-9p38-m4m8-2mfm.json index e326f077129..59e034134fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p38-m4m8-2mfm/GHSA-9p38-m4m8-2mfm.json +++ b/advisories/unreviewed/2022/05/GHSA-9p38-m4m8-2mfm/GHSA-9p38-m4m8-2mfm.json @@ -7,12 +7,8 @@ "CVE-2007-2128" ], "details": "Unspecified vulnerability in the Sales Online component for Oracle E-Business Suite 11.5.10 has unknown impact and remote authenticated attack vectors, aka APPS08.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9q22-r645-j34j/GHSA-9q22-r645-j34j.json b/advisories/unreviewed/2022/05/GHSA-9q22-r645-j34j/GHSA-9q22-r645-j34j.json index 51fa9c90a66..ade23952bb5 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q22-r645-j34j/GHSA-9q22-r645-j34j.json +++ b/advisories/unreviewed/2022/05/GHSA-9q22-r645-j34j/GHSA-9q22-r645-j34j.json @@ -7,12 +7,8 @@ "CVE-2007-2546" ], "details": "Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9qg6-8frf-7w59/GHSA-9qg6-8frf-7w59.json b/advisories/unreviewed/2022/05/GHSA-9qg6-8frf-7w59/GHSA-9qg6-8frf-7w59.json index ec2ecb73fd0..c649bbaabdc 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qg6-8frf-7w59/GHSA-9qg6-8frf-7w59.json +++ b/advisories/unreviewed/2022/05/GHSA-9qg6-8frf-7w59/GHSA-9qg6-8frf-7w59.json @@ -7,12 +7,8 @@ "CVE-2007-2325" ], "details": "PHP remote file inclusion vulnerability in include.php in MyNewsGroups :) allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9qq6-882v-v8qg/GHSA-9qq6-882v-v8qg.json b/advisories/unreviewed/2022/05/GHSA-9qq6-882v-v8qg/GHSA-9qq6-882v-v8qg.json index b19b3e39d87..ec46563e9db 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qq6-882v-v8qg/GHSA-9qq6-882v-v8qg.json +++ b/advisories/unreviewed/2022/05/GHSA-9qq6-882v-v8qg/GHSA-9qq6-882v-v8qg.json @@ -7,12 +7,8 @@ "CVE-2007-2339" ], "details": "Multiple SQL injection vulnerabilities in Phorum before 5.1.22 allow remote attackers to execute arbitrary SQL commands via (1) a modified recipients parameter name in (a) pm.php; (2) the curr parameter to the (b) badwords (aka censorlist) or (c) banlist module in admin.php; or (3) the \"Edit groups / Add group\" field in the (d) groups module in admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9v54-3hqm-3pfm/GHSA-9v54-3hqm-3pfm.json b/advisories/unreviewed/2022/05/GHSA-9v54-3hqm-3pfm/GHSA-9v54-3hqm-3pfm.json index c902b50a3a5..00c8ab531f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v54-3hqm-3pfm/GHSA-9v54-3hqm-3pfm.json +++ b/advisories/unreviewed/2022/05/GHSA-9v54-3hqm-3pfm/GHSA-9v54-3hqm-3pfm.json @@ -7,12 +7,8 @@ "CVE-2007-2489" ], "details": "Heap-based buffer overflow in LiveData Protocol Server 5.00.045, and other versions before update 500062 (5.00.062), allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted request for a WSDL file that causes a negative length to be used in a strncpy call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9vjc-rvgp-29xx/GHSA-9vjc-rvgp-29xx.json b/advisories/unreviewed/2022/05/GHSA-9vjc-rvgp-29xx/GHSA-9vjc-rvgp-29xx.json index 1f923a5aae6..6da1482425a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vjc-rvgp-29xx/GHSA-9vjc-rvgp-29xx.json +++ b/advisories/unreviewed/2022/05/GHSA-9vjc-rvgp-29xx/GHSA-9vjc-rvgp-29xx.json @@ -7,12 +7,8 @@ "CVE-2007-2359" ], "details": "Buffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, allows local users to gain privileges via a long string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9vm2-vjcq-7hjj/GHSA-9vm2-vjcq-7hjj.json b/advisories/unreviewed/2022/05/GHSA-9vm2-vjcq-7hjj/GHSA-9vm2-vjcq-7hjj.json index 6a4f50d50d1..9c61db07ef5 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vm2-vjcq-7hjj/GHSA-9vm2-vjcq-7hjj.json +++ b/advisories/unreviewed/2022/05/GHSA-9vm2-vjcq-7hjj/GHSA-9vm2-vjcq-7hjj.json @@ -7,12 +7,8 @@ "CVE-2007-2486" ], "details": "Directory traversal vulnerability in download.asp in Motobit 1.3 and 1.5 (aka PStruh-CZ) allows remote attackers to read arbitrary files via a .. (dot dot) in the File parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9w2x-f6qm-vmqw/GHSA-9w2x-f6qm-vmqw.json b/advisories/unreviewed/2022/05/GHSA-9w2x-f6qm-vmqw/GHSA-9w2x-f6qm-vmqw.json index 42a0be9bb2a..2af5d8d9146 100644 --- a/advisories/unreviewed/2022/05/GHSA-9w2x-f6qm-vmqw/GHSA-9w2x-f6qm-vmqw.json +++ b/advisories/unreviewed/2022/05/GHSA-9w2x-f6qm-vmqw/GHSA-9w2x-f6qm-vmqw.json @@ -7,12 +7,8 @@ "CVE-2007-1962" ], "details": "SQL injection vulnerability in index.php in the WF-Snippets 1.02 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9w4q-9546-j7r2/GHSA-9w4q-9546-j7r2.json b/advisories/unreviewed/2022/05/GHSA-9w4q-9546-j7r2/GHSA-9w4q-9546-j7r2.json index 04b3b29c521..a338654d8cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-9w4q-9546-j7r2/GHSA-9w4q-9546-j7r2.json +++ b/advisories/unreviewed/2022/05/GHSA-9w4q-9546-j7r2/GHSA-9w4q-9546-j7r2.json @@ -7,12 +7,8 @@ "CVE-2007-2228" ], "details": "rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS service stop and system restart) via an RPC request that uses NTLMSSP PACKET authentication with a zero-valued verification trailer signature, which triggers an invalid dereference. NOTE: this also affects Windows 2000 SP4, although the impact is an information leak.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9wvc-63gx-rw59/GHSA-9wvc-63gx-rw59.json b/advisories/unreviewed/2022/05/GHSA-9wvc-63gx-rw59/GHSA-9wvc-63gx-rw59.json index d2bd25ddb29..0897ec70f74 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wvc-63gx-rw59/GHSA-9wvc-63gx-rw59.json +++ b/advisories/unreviewed/2022/05/GHSA-9wvc-63gx-rw59/GHSA-9wvc-63gx-rw59.json @@ -7,12 +7,8 @@ "CVE-2007-2421" ], "details": "Buffer overflow in Hitachi Groupmax Mobile Option for Mobile-Phone 07-00 through 07-30, 5 for i-mode 05-11 through 05-23, and 6 for EZweb 06-00 through 06-04 allows remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c2xp-7rqx-ffqj/GHSA-c2xp-7rqx-ffqj.json b/advisories/unreviewed/2022/05/GHSA-c2xp-7rqx-ffqj/GHSA-c2xp-7rqx-ffqj.json index ebdf1322c0a..5939fb36321 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2xp-7rqx-ffqj/GHSA-c2xp-7rqx-ffqj.json +++ b/advisories/unreviewed/2022/05/GHSA-c2xp-7rqx-ffqj/GHSA-c2xp-7rqx-ffqj.json @@ -7,12 +7,8 @@ "CVE-2007-2117" ], "details": "Unspecified vulnerability in the Oracle Text component in Oracle Database 9.0.1.5+ and 9.2.0.5 has unknown impact and attack vectors, aka DB12. NOTE: as of 20070424, Oracle has not disputed reliable claims that this involves a buffer overflow in the ctxsrv server daemon.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c36r-h4vm-4w2p/GHSA-c36r-h4vm-4w2p.json b/advisories/unreviewed/2022/05/GHSA-c36r-h4vm-4w2p/GHSA-c36r-h4vm-4w2p.json index 3f4208066f8..47ee8c05c9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-c36r-h4vm-4w2p/GHSA-c36r-h4vm-4w2p.json +++ b/advisories/unreviewed/2022/05/GHSA-c36r-h4vm-4w2p/GHSA-c36r-h4vm-4w2p.json @@ -7,12 +7,8 @@ "CVE-2007-2506" ], "details": "WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attackers to cause a denial of service (infinite loop and daemon hang) via a messenger URL that invokes _edit.r with no additional parameters, as demonstrated by requests for cgiip.exe or wsisa.dll with WService=wsbroker1/_edit.r in the PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c38m-8pv6-fj8r/GHSA-c38m-8pv6-fj8r.json b/advisories/unreviewed/2022/05/GHSA-c38m-8pv6-fj8r/GHSA-c38m-8pv6-fj8r.json index af8b4b2f7f6..674b3c38171 100644 --- a/advisories/unreviewed/2022/05/GHSA-c38m-8pv6-fj8r/GHSA-c38m-8pv6-fj8r.json +++ b/advisories/unreviewed/2022/05/GHSA-c38m-8pv6-fj8r/GHSA-c38m-8pv6-fj8r.json @@ -7,12 +7,8 @@ "CVE-2007-2015" ], "details": "PHP remote file inclusion vulnerability in index.php in Request It 1.0b allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c3h9-q6vg-353f/GHSA-c3h9-q6vg-353f.json b/advisories/unreviewed/2022/05/GHSA-c3h9-q6vg-353f/GHSA-c3h9-q6vg-353f.json index 6bb46325999..e6aede4e90b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3h9-q6vg-353f/GHSA-c3h9-q6vg-353f.json +++ b/advisories/unreviewed/2022/05/GHSA-c3h9-q6vg-353f/GHSA-c3h9-q6vg-353f.json @@ -7,12 +7,8 @@ "CVE-2007-1974" ], "details": "SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as used in Xoops modules such as (1) Zmagazine 1.0, (2) Happy Linux XFsection 1.07 and earlier, and possibly other modules, allows remote attackers to execute arbitrary SQL commands via the articleid parameter to print.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -96,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c3rv-g49g-jwmm/GHSA-c3rv-g49g-jwmm.json b/advisories/unreviewed/2022/05/GHSA-c3rv-g49g-jwmm/GHSA-c3rv-g49g-jwmm.json index 4f1cc9c6a7c..abc22e18d27 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3rv-g49g-jwmm/GHSA-c3rv-g49g-jwmm.json +++ b/advisories/unreviewed/2022/05/GHSA-c3rv-g49g-jwmm/GHSA-c3rv-g49g-jwmm.json @@ -7,12 +7,8 @@ "CVE-2007-2425" ], "details": "Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the album parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c42v-8gv7-m6cq/GHSA-c42v-8gv7-m6cq.json b/advisories/unreviewed/2022/05/GHSA-c42v-8gv7-m6cq/GHSA-c42v-8gv7-m6cq.json index e713af1942e..0aec9039d62 100644 --- a/advisories/unreviewed/2022/05/GHSA-c42v-8gv7-m6cq/GHSA-c42v-8gv7-m6cq.json +++ b/advisories/unreviewed/2022/05/GHSA-c42v-8gv7-m6cq/GHSA-c42v-8gv7-m6cq.json @@ -7,12 +7,8 @@ "CVE-2007-2674" ], "details": "SQL injection vulnerability in detail.php in Pre Shopping Mall 1.0 allows remote attackers to execute arbitrary SQL commands via the prodid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c4rj-xq5w-qw4w/GHSA-c4rj-xq5w-qw4w.json b/advisories/unreviewed/2022/05/GHSA-c4rj-xq5w-qw4w/GHSA-c4rj-xq5w-qw4w.json index 9e3d370cc62..62e8d8aa378 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4rj-xq5w-qw4w/GHSA-c4rj-xq5w-qw4w.json +++ b/advisories/unreviewed/2022/05/GHSA-c4rj-xq5w-qw4w/GHSA-c4rj-xq5w-qw4w.json @@ -7,12 +7,8 @@ "CVE-2007-2633" ], "details": "Directory traversal vulnerability in H-Sphere SiteStudio 1.6 allows remote attackers to read, or include and execute, arbitrary local files via a .. (dot dot) in the template parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c6cv-wqgc-8v6m/GHSA-c6cv-wqgc-8v6m.json b/advisories/unreviewed/2022/05/GHSA-c6cv-wqgc-8v6m/GHSA-c6cv-wqgc-8v6m.json index 1d19f5a1db5..4be6ae74ed7 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6cv-wqgc-8v6m/GHSA-c6cv-wqgc-8v6m.json +++ b/advisories/unreviewed/2022/05/GHSA-c6cv-wqgc-8v6m/GHSA-c6cv-wqgc-8v6m.json @@ -7,12 +7,8 @@ "CVE-2007-2609" ], "details": "Multiple PHP remote file inclusion vulnerabilities in gnuedu 1.3b2 allow remote attackers to execute arbitrary PHP code via a URL in the (a) ETCDIR parameter to (1) libs/lom.php; (2) lom_update.php, (3) check-lom.php, and (4) weigh_keywords.php in scripts/; the (b) LIBSDIR parameter to (5) logout.php, (6) help.php, (7) index.php, (8) login.php; and the ETCDIR parameter to (9) web/lom.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c6h8-qr22-65qm/GHSA-c6h8-qr22-65qm.json b/advisories/unreviewed/2022/05/GHSA-c6h8-qr22-65qm/GHSA-c6h8-qr22-65qm.json index 03d60e47e8b..c1af7461fdf 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6h8-qr22-65qm/GHSA-c6h8-qr22-65qm.json +++ b/advisories/unreviewed/2022/05/GHSA-c6h8-qr22-65qm/GHSA-c6h8-qr22-65qm.json @@ -7,12 +7,8 @@ "CVE-2007-2683" ], "details": "Buffer overflow in Mutt 1.4.2 might allow local users to execute arbitrary code via \"&\" characters in the GECOS field, which triggers the overflow during alias expansion.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c6p3-c4g7-pprg/GHSA-c6p3-c4g7-pprg.json b/advisories/unreviewed/2022/05/GHSA-c6p3-c4g7-pprg/GHSA-c6p3-c4g7-pprg.json index 64b32dbf879..2dc9c49e9c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6p3-c4g7-pprg/GHSA-c6p3-c4g7-pprg.json +++ b/advisories/unreviewed/2022/05/GHSA-c6p3-c4g7-pprg/GHSA-c6p3-c4g7-pprg.json @@ -7,12 +7,8 @@ "CVE-2007-2500" ], "details": "server/parser/sprite_definition.cpp in GNU Gnash (aka GNU Flash Player) 0.7.2 allows remote attackers to execute arbitrary code via a large number of SHOWFRAME elements within a DEFINESPRITE element, which triggers memory corruption and enables the attacker to call free with an arbitrary address, probably resultant from a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c6pc-rjfg-j46c/GHSA-c6pc-rjfg-j46c.json b/advisories/unreviewed/2022/05/GHSA-c6pc-rjfg-j46c/GHSA-c6pc-rjfg-j46c.json index 37c418572b3..2d26a216d5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6pc-rjfg-j46c/GHSA-c6pc-rjfg-j46c.json +++ b/advisories/unreviewed/2022/05/GHSA-c6pc-rjfg-j46c/GHSA-c6pc-rjfg-j46c.json @@ -7,12 +7,8 @@ "CVE-2007-2620" ], "details": "PHP remote file inclusion vulnerability in inc/config.inc.php in Jakub Steiner (aka jimmac) original 0.11 allows remote attackers to execute arbitrary PHP code via a URL in the x[1] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c7vp-x84f-c377/GHSA-c7vp-x84f-c377.json b/advisories/unreviewed/2022/05/GHSA-c7vp-x84f-c377/GHSA-c7vp-x84f-c377.json index c64d3d10652..9529fc50fcd 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7vp-x84f-c377/GHSA-c7vp-x84f-c377.json +++ b/advisories/unreviewed/2022/05/GHSA-c7vp-x84f-c377/GHSA-c7vp-x84f-c377.json @@ -7,12 +7,8 @@ "CVE-2007-2678" ], "details": "Buffer overflow in the isChecked function in toolbar.dll in Netsprint Toolbar 1.1 might allow remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c7ww-hhc7-6x2g/GHSA-c7ww-hhc7-6x2g.json b/advisories/unreviewed/2022/05/GHSA-c7ww-hhc7-6x2g/GHSA-c7ww-hhc7-6x2g.json index cd722c6a071..cbb7c72fa17 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7ww-hhc7-6x2g/GHSA-c7ww-hhc7-6x2g.json +++ b/advisories/unreviewed/2022/05/GHSA-c7ww-hhc7-6x2g/GHSA-c7ww-hhc7-6x2g.json @@ -7,12 +7,8 @@ "CVE-2007-2304" ], "details": "Multiple directory traversal vulnerabilities in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter to categories.php and other unspecified files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c897-2cj6-j4xv/GHSA-c897-2cj6-j4xv.json b/advisories/unreviewed/2022/05/GHSA-c897-2cj6-j4xv/GHSA-c897-2cj6-j4xv.json index ce8c1207c7d..0d756359ba0 100644 --- a/advisories/unreviewed/2022/05/GHSA-c897-2cj6-j4xv/GHSA-c897-2cj6-j4xv.json +++ b/advisories/unreviewed/2022/05/GHSA-c897-2cj6-j4xv/GHSA-c897-2cj6-j4xv.json @@ -7,12 +7,8 @@ "CVE-2007-2451" ], "details": "Unspecified vulnerability in drivers/crypto/geode-aes.c in GEODE-AES in the Linux kernel before 2.6.21.3 allows attackers to obtain sensitive information via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c954-w2fm-c62r/GHSA-c954-w2fm-c62r.json b/advisories/unreviewed/2022/05/GHSA-c954-w2fm-c62r/GHSA-c954-w2fm-c62r.json index f1e1e4ae8af..9335989ad6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c954-w2fm-c62r/GHSA-c954-w2fm-c62r.json +++ b/advisories/unreviewed/2022/05/GHSA-c954-w2fm-c62r/GHSA-c954-w2fm-c62r.json @@ -7,12 +7,8 @@ "CVE-2007-2612" ], "details": "SQL injection vulnerability in libs/Wakka.class.php in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to execute arbitrary SQL commands via the limit parameter. NOTE: this issue only applies to a \"modified installation.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c9jf-rpph-c99p/GHSA-c9jf-rpph-c99p.json b/advisories/unreviewed/2022/05/GHSA-c9jf-rpph-c99p/GHSA-c9jf-rpph-c99p.json index d43616bf00b..3e6c8006f9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9jf-rpph-c99p/GHSA-c9jf-rpph-c99p.json +++ b/advisories/unreviewed/2022/05/GHSA-c9jf-rpph-c99p/GHSA-c9jf-rpph-c99p.json @@ -7,12 +7,8 @@ "CVE-2007-2340" ], "details": "Multiple PHP remote file inclusion vulnerabilities in inc/include_all.inc.php in phporacleview allow remote attackers to execute arbitrary PHP code via a URL in the (1) page_dir or (2) inc_dir parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cc7g-59jw-rfxv/GHSA-cc7g-59jw-rfxv.json b/advisories/unreviewed/2022/05/GHSA-cc7g-59jw-rfxv/GHSA-cc7g-59jw-rfxv.json index 1ed87e049cf..5efbf06f296 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc7g-59jw-rfxv/GHSA-cc7g-59jw-rfxv.json +++ b/advisories/unreviewed/2022/05/GHSA-cc7g-59jw-rfxv/GHSA-cc7g-59jw-rfxv.json @@ -7,12 +7,8 @@ "CVE-2007-2470" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in FileRun 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) module, or (3) section parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ccvr-fpg6-9xrj/GHSA-ccvr-fpg6-9xrj.json b/advisories/unreviewed/2022/05/GHSA-ccvr-fpg6-9xrj/GHSA-ccvr-fpg6-9xrj.json index 89bf5748925..7d999f8cde5 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccvr-fpg6-9xrj/GHSA-ccvr-fpg6-9xrj.json +++ b/advisories/unreviewed/2022/05/GHSA-ccvr-fpg6-9xrj/GHSA-ccvr-fpg6-9xrj.json @@ -7,12 +7,8 @@ "CVE-2007-2299" ], "details": "Multiple SQL injection vulnerabilities in Frogss CMS 0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) dzial parameter to (a) katalog.php, or the (2) t parameter to (b) forum.php or (c) forum/viewtopic.php, different vectors than CVE-2006-4536.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cf9x-92wq-p2j8/GHSA-cf9x-92wq-p2j8.json b/advisories/unreviewed/2022/05/GHSA-cf9x-92wq-p2j8/GHSA-cf9x-92wq-p2j8.json index 5bd2112c721..29f95d864f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-cf9x-92wq-p2j8/GHSA-cf9x-92wq-p2j8.json +++ b/advisories/unreviewed/2022/05/GHSA-cf9x-92wq-p2j8/GHSA-cf9x-92wq-p2j8.json @@ -7,12 +7,8 @@ "CVE-2007-2476" ], "details": "Unspecified vulnerability in Novell SecureLogin (NSL) 6 SP1 before 6.0.106 has unknown impact and remote attack vectors, related to Active Directory (AD) password changes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cfv5-24f5-vx22/GHSA-cfv5-24f5-vx22.json b/advisories/unreviewed/2022/05/GHSA-cfv5-24f5-vx22/GHSA-cfv5-24f5-vx22.json index 76efd5edaad..b963513f27d 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfv5-24f5-vx22/GHSA-cfv5-24f5-vx22.json +++ b/advisories/unreviewed/2022/05/GHSA-cfv5-24f5-vx22/GHSA-cfv5-24f5-vx22.json @@ -7,12 +7,8 @@ "CVE-2007-2572" ], "details": "PHP remote file inclusion vulnerability in modules/noevents/templates/mfa_theme.php in NoAh (aka PHP Content Architect, phparch) 0.9 pre 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tpls[1] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfwg-x2fv-2v2c/GHSA-cfwg-x2fv-2v2c.json b/advisories/unreviewed/2022/05/GHSA-cfwg-x2fv-2v2c/GHSA-cfwg-x2fv-2v2c.json index 7226e7d8a28..fa10ea84faf 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfwg-x2fv-2v2c/GHSA-cfwg-x2fv-2v2c.json +++ b/advisories/unreviewed/2022/05/GHSA-cfwg-x2fv-2v2c/GHSA-cfwg-x2fv-2v2c.json @@ -7,12 +7,8 @@ "CVE-2007-2173" ], "details": "Eval injection vulnerability in (1) courier-imapd.indirect and (2) courier-pop3d.indirect in Courier-IMAP before 4.0.6-r2, and 4.1.x before 4.1.2-r1, on Gentoo Linux allows remote attackers to execute arbitrary commands via the XMAILDIR variable, related to the LOGINRUN variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cj7j-6rg9-9523/GHSA-cj7j-6rg9-9523.json b/advisories/unreviewed/2022/05/GHSA-cj7j-6rg9-9523/GHSA-cj7j-6rg9-9523.json index 590caca4320..74e17aba027 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj7j-6rg9-9523/GHSA-cj7j-6rg9-9523.json +++ b/advisories/unreviewed/2022/05/GHSA-cj7j-6rg9-9523/GHSA-cj7j-6rg9-9523.json @@ -7,12 +7,8 @@ "CVE-2007-2016" ], "details": "Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the lang[] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cjxg-667g-2p2g/GHSA-cjxg-667g-2p2g.json b/advisories/unreviewed/2022/05/GHSA-cjxg-667g-2p2g/GHSA-cjxg-667g-2p2g.json index a880810957a..db67177b6b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjxg-667g-2p2g/GHSA-cjxg-667g-2p2g.json +++ b/advisories/unreviewed/2022/05/GHSA-cjxg-667g-2p2g/GHSA-cjxg-667g-2p2g.json @@ -7,12 +7,8 @@ "CVE-2007-2145" ], "details": "The imagecomments function in classes.php in MiniGal b13 allows remote attackers to inject arbitrary PHP code into a file in the thumbs/ directory via the input parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cjxh-xgwx-v2w6/GHSA-cjxh-xgwx-v2w6.json b/advisories/unreviewed/2022/05/GHSA-cjxh-xgwx-v2w6/GHSA-cjxh-xgwx-v2w6.json index 37f22f922ee..3af4cb5c35e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjxh-xgwx-v2w6/GHSA-cjxh-xgwx-v2w6.json +++ b/advisories/unreviewed/2022/05/GHSA-cjxh-xgwx-v2w6/GHSA-cjxh-xgwx-v2w6.json @@ -7,12 +7,8 @@ "CVE-2007-1973" ], "details": "Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0 allows local users to modify memory and gain privileges via the temporary \\Device\\PhysicalMemory section handle, a related issue to CVE-2007-1206.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cpgg-88ph-4x7j/GHSA-cpgg-88ph-4x7j.json b/advisories/unreviewed/2022/05/GHSA-cpgg-88ph-4x7j/GHSA-cpgg-88ph-4x7j.json index 0d3a24d4962..cdcfa72e626 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpgg-88ph-4x7j/GHSA-cpgg-88ph-4x7j.json +++ b/advisories/unreviewed/2022/05/GHSA-cpgg-88ph-4x7j/GHSA-cpgg-88ph-4x7j.json @@ -7,12 +7,8 @@ "CVE-2007-2582" ], "details": "Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier allow remote attackers to (1) execute arbitrary code via a crafted packet to the DB2JDS service on tcp/6789; and cause a denial of service via (2) an invalid LANG parameter or (2) a long packet that generates a \"MemTree overflow.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cr23-vq27-p59f/GHSA-cr23-vq27-p59f.json b/advisories/unreviewed/2022/05/GHSA-cr23-vq27-p59f/GHSA-cr23-vq27-p59f.json index 0d0e10d9ef1..1216e38bc71 100644 --- a/advisories/unreviewed/2022/05/GHSA-cr23-vq27-p59f/GHSA-cr23-vq27-p59f.json +++ b/advisories/unreviewed/2022/05/GHSA-cr23-vq27-p59f/GHSA-cr23-vq27-p59f.json @@ -7,12 +7,8 @@ "CVE-2007-2458" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter to psg.smarty.lib.php and certain include and library scripts, a different vector than CVE-2007-2457.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cv57-mh69-23jg/GHSA-cv57-mh69-23jg.json b/advisories/unreviewed/2022/05/GHSA-cv57-mh69-23jg/GHSA-cv57-mh69-23jg.json index 41019c2234b..46d1be76872 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv57-mh69-23jg/GHSA-cv57-mh69-23jg.json +++ b/advisories/unreviewed/2022/05/GHSA-cv57-mh69-23jg/GHSA-cv57-mh69-23jg.json @@ -7,12 +7,8 @@ "CVE-2007-2272" ], "details": "PHP remote file inclusion vulnerability in docs/front-end-demo/cart2.php in Advanced Webhost Billing System (AWBS) 2.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the workdir parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cw49-h9r2-pr6m/GHSA-cw49-h9r2-pr6m.json b/advisories/unreviewed/2022/05/GHSA-cw49-h9r2-pr6m/GHSA-cw49-h9r2-pr6m.json index fad4c350681..af1d4549663 100644 --- a/advisories/unreviewed/2022/05/GHSA-cw49-h9r2-pr6m/GHSA-cw49-h9r2-pr6m.json +++ b/advisories/unreviewed/2022/05/GHSA-cw49-h9r2-pr6m/GHSA-cw49-h9r2-pr6m.json @@ -7,12 +7,8 @@ "CVE-2007-2395" ], "details": "Unspecified vulnerability in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via a crafted image description atom in a movie file, related to \"memory corruption.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cx6g-56cf-6737/GHSA-cx6g-56cf-6737.json b/advisories/unreviewed/2022/05/GHSA-cx6g-56cf-6737/GHSA-cx6g-56cf-6737.json index d1b0ad082dc..c2bfa021717 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx6g-56cf-6737/GHSA-cx6g-56cf-6737.json +++ b/advisories/unreviewed/2022/05/GHSA-cx6g-56cf-6737/GHSA-cx6g-56cf-6737.json @@ -7,12 +7,8 @@ "CVE-2007-2375" ], "details": "The agent remote upgrade interface in Symantec Enterprise Security Manager (ESM) before 20070405 does not verify the authenticity of upgrades, which allows remote attackers to execute arbitrary code via software that implements the agent upgrade protocol.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cx7j-6x8v-hjf9/GHSA-cx7j-6x8v-hjf9.json b/advisories/unreviewed/2022/05/GHSA-cx7j-6x8v-hjf9/GHSA-cx7j-6x8v-hjf9.json index ff8d1b0df3f..b47a73bb2c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx7j-6x8v-hjf9/GHSA-cx7j-6x8v-hjf9.json +++ b/advisories/unreviewed/2022/05/GHSA-cx7j-6x8v-hjf9/GHSA-cx7j-6x8v-hjf9.json @@ -7,12 +7,8 @@ "CVE-2007-2245" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cx8m-5mrc-m3rm/GHSA-cx8m-5mrc-m3rm.json b/advisories/unreviewed/2022/05/GHSA-cx8m-5mrc-m3rm/GHSA-cx8m-5mrc-m3rm.json index 9ccf5cf47cd..9a5f43829d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx8m-5mrc-m3rm/GHSA-cx8m-5mrc-m3rm.json +++ b/advisories/unreviewed/2022/05/GHSA-cx8m-5mrc-m3rm/GHSA-cx8m-5mrc-m3rm.json @@ -7,12 +7,8 @@ "CVE-2007-2681" ], "details": "Directory traversal vulnerability in blogs/index.php in b2evolution 1.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the core_subdir parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cxxq-wr83-qfr5/GHSA-cxxq-wr83-qfr5.json b/advisories/unreviewed/2022/05/GHSA-cxxq-wr83-qfr5/GHSA-cxxq-wr83-qfr5.json index c2067f516a2..07dc2b61383 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxxq-wr83-qfr5/GHSA-cxxq-wr83-qfr5.json +++ b/advisories/unreviewed/2022/05/GHSA-cxxq-wr83-qfr5/GHSA-cxxq-wr83-qfr5.json @@ -7,12 +7,8 @@ "CVE-2007-2423" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in MoinMoin 1.5.7 allows remote attackers to inject arbitrary web script or HTML via the do parameter in an AttachFile action, a different vulnerability than CVE-2007-0857. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f363-c9mp-hmh3/GHSA-f363-c9mp-hmh3.json b/advisories/unreviewed/2022/05/GHSA-f363-c9mp-hmh3/GHSA-f363-c9mp-hmh3.json index c0a9d7c8f8d..546f889cca8 100644 --- a/advisories/unreviewed/2022/05/GHSA-f363-c9mp-hmh3/GHSA-f363-c9mp-hmh3.json +++ b/advisories/unreviewed/2022/05/GHSA-f363-c9mp-hmh3/GHSA-f363-c9mp-hmh3.json @@ -7,12 +7,8 @@ "CVE-2007-2646" ], "details": "Heap-based buffer overflow in yEnc32 1.0.7.207 allows user-assisted remote attackers to execute arbitrary code via a long filename in an NTX file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f375-997g-gxgr/GHSA-f375-997g-gxgr.json b/advisories/unreviewed/2022/05/GHSA-f375-997g-gxgr/GHSA-f375-997g-gxgr.json index 19133feeed0..799a018b146 100644 --- a/advisories/unreviewed/2022/05/GHSA-f375-997g-gxgr/GHSA-f375-997g-gxgr.json +++ b/advisories/unreviewed/2022/05/GHSA-f375-997g-gxgr/GHSA-f375-997g-gxgr.json @@ -7,12 +7,8 @@ "CVE-2007-2301" ], "details": "Multiple PHP remote file inclusion vulnerabilities in audioCMS arash 0.1.4 allow remote attackers to execute arbitrary PHP code via a URL in the arashlib_dir parameter to (1) edit.inc.php and (2) list_features.inc.php in arash_lib/include, and (3) arash_gadmin.class.php and (4) arash_sadmin.class.php in arash_lib/class/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f49v-rg74-6fq8/GHSA-f49v-rg74-6fq8.json b/advisories/unreviewed/2022/05/GHSA-f49v-rg74-6fq8/GHSA-f49v-rg74-6fq8.json index 5d4971f6cba..24ecf306e4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-f49v-rg74-6fq8/GHSA-f49v-rg74-6fq8.json +++ b/advisories/unreviewed/2022/05/GHSA-f49v-rg74-6fq8/GHSA-f49v-rg74-6fq8.json @@ -7,12 +7,8 @@ "CVE-2007-2622" ], "details": "Multiple SQL injection vulnerabilities in TaskDriver 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to login.php or (2) the taskid parameter to notes.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f5cp-3c4w-p43v/GHSA-f5cp-3c4w-p43v.json b/advisories/unreviewed/2022/05/GHSA-f5cp-3c4w-p43v/GHSA-f5cp-3c4w-p43v.json index e627bf7827e..15675d4a30f 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5cp-3c4w-p43v/GHSA-f5cp-3c4w-p43v.json +++ b/advisories/unreviewed/2022/05/GHSA-f5cp-3c4w-p43v/GHSA-f5cp-3c4w-p43v.json @@ -7,12 +7,8 @@ "CVE-2007-2495" ], "details": "Multiple stack-based buffer overflows in the ExcelOCX ActiveX control in ExcelViewer.ocx 3.1.0.6 allow remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) Save, (6) SaveWebFile, (7) HttpDownloadFile, (8) Open, or (9) OpenWebFile property value. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f5mf-h898-jw3m/GHSA-f5mf-h898-jw3m.json b/advisories/unreviewed/2022/05/GHSA-f5mf-h898-jw3m/GHSA-f5mf-h898-jw3m.json index 46883ee233a..5a0bd3b4992 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5mf-h898-jw3m/GHSA-f5mf-h898-jw3m.json +++ b/advisories/unreviewed/2022/05/GHSA-f5mf-h898-jw3m/GHSA-f5mf-h898-jw3m.json @@ -7,12 +7,8 @@ "CVE-2007-2387" ], "details": "Apple Xserve Lights-Out Management before Firmware Update 1.0 on Intel hardware does not require a password for remote access to IPMI, which allows remote attackers to gain administrative access via unspecified requests with ipmitool.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f8hv-p37q-8vrh/GHSA-f8hv-p37q-8vrh.json b/advisories/unreviewed/2022/05/GHSA-f8hv-p37q-8vrh/GHSA-f8hv-p37q-8vrh.json index 408fb65edbe..ee5bce0d9cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8hv-p37q-8vrh/GHSA-f8hv-p37q-8vrh.json +++ b/advisories/unreviewed/2022/05/GHSA-f8hv-p37q-8vrh/GHSA-f8hv-p37q-8vrh.json @@ -7,12 +7,8 @@ "CVE-2007-2314" ], "details": "Multiple SQL injection vulnerabilities in Crea-Book 1.0, and possibly earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) pseudo or (2) passe parameter to (a) configurer.php, (b) connect.php, (c) delete.php, (d) delete2.php, (e) index.php, (f) infos.php, (g) membres.php, (h) modif-infos.php, (i) modif-message.php, (j) modif.php, (k) uninstall.php, or (l) uninstall_table.php in admin/, different vectors than CVE-2007-2000. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f9vv-62q4-g5r8/GHSA-f9vv-62q4-g5r8.json b/advisories/unreviewed/2022/05/GHSA-f9vv-62q4-g5r8/GHSA-f9vv-62q4-g5r8.json index 64404e6b6fb..fe264be4232 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9vv-62q4-g5r8/GHSA-f9vv-62q4-g5r8.json +++ b/advisories/unreviewed/2022/05/GHSA-f9vv-62q4-g5r8/GHSA-f9vv-62q4-g5r8.json @@ -7,12 +7,8 @@ "CVE-2007-2469" ], "details": "SQL injection vulnerability in index.php in FileRun 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fc84-396x-x24g/GHSA-fc84-396x-x24g.json b/advisories/unreviewed/2022/05/GHSA-fc84-396x-x24g/GHSA-fc84-396x-x24g.json index ac66fc31cd2..e7953014c85 100644 --- a/advisories/unreviewed/2022/05/GHSA-fc84-396x-x24g/GHSA-fc84-396x-x24g.json +++ b/advisories/unreviewed/2022/05/GHSA-fc84-396x-x24g/GHSA-fc84-396x-x24g.json @@ -7,12 +7,8 @@ "CVE-2007-2522" ], "details": "Stack-based buffer overflow in the inoweb Console Server in CA Anti-Virus for the Enterprise r8, Threat Manager r8, Anti-Spyware for the Enterprise r8, and Protection Suites r3 allows remote attackers to execute arbitrary code via a long (1) username or (2) password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fchj-96vm-p9r2/GHSA-fchj-96vm-p9r2.json b/advisories/unreviewed/2022/05/GHSA-fchj-96vm-p9r2/GHSA-fchj-96vm-p9r2.json index 240d45cc653..8b8c0605e8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-fchj-96vm-p9r2/GHSA-fchj-96vm-p9r2.json +++ b/advisories/unreviewed/2022/05/GHSA-fchj-96vm-p9r2/GHSA-fchj-96vm-p9r2.json @@ -7,12 +7,8 @@ "CVE-2007-2263" ], "details": "Heap-based buffer overflow in RealNetworks RealPlayer 10.0, 10.1, and possibly 10.5, RealOne Player, and RealPlayer Enterprise allows remote attackers to execute arbitrary code via an SWF (Flash) file with malformed record headers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fgjf-p6xg-w4q9/GHSA-fgjf-p6xg-w4q9.json b/advisories/unreviewed/2022/05/GHSA-fgjf-p6xg-w4q9/GHSA-fgjf-p6xg-w4q9.json index d1cfa7f7dc3..573bc297ec2 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgjf-p6xg-w4q9/GHSA-fgjf-p6xg-w4q9.json +++ b/advisories/unreviewed/2022/05/GHSA-fgjf-p6xg-w4q9/GHSA-fgjf-p6xg-w4q9.json @@ -7,12 +7,8 @@ "CVE-2007-2239" ], "details": "Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamControl.ocx in AXIS 2100, 2110, 2120, 2130 PTZ, 2420, 2420-IR, 2400, 2400+, 2401, 2401+, 2411, and Panorama PTZ allows remote attackers to cause a denial of service (Internet Explorer crash) or execute arbitrary code via a long argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fgr5-3mrf-hq8x/GHSA-fgr5-3mrf-hq8x.json b/advisories/unreviewed/2022/05/GHSA-fgr5-3mrf-hq8x/GHSA-fgr5-3mrf-hq8x.json index eb3cfab628b..5214933996e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgr5-3mrf-hq8x/GHSA-fgr5-3mrf-hq8x.json +++ b/advisories/unreviewed/2022/05/GHSA-fgr5-3mrf-hq8x/GHSA-fgr5-3mrf-hq8x.json @@ -7,12 +7,8 @@ "CVE-2007-2283" ], "details": "Buffer overflow in Fresh View 7.15 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fgwf-g47p-3m7h/GHSA-fgwf-g47p-3m7h.json b/advisories/unreviewed/2022/05/GHSA-fgwf-g47p-3m7h/GHSA-fgwf-g47p-3m7h.json index 2429378518b..96e3635695d 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgwf-g47p-3m7h/GHSA-fgwf-g47p-3m7h.json +++ b/advisories/unreviewed/2022/05/GHSA-fgwf-g47p-3m7h/GHSA-fgwf-g47p-3m7h.json @@ -7,12 +7,8 @@ "CVE-2007-2400" ], "details": "Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhone before 1.0.1, allows remote attackers to bypass the JavaScript security model and modify pages outside of the security domain and conduct cross-site scripting (XSS) attacks via vectors related to page updating and HTTP redirects.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fgx3-c2gx-wcrm/GHSA-fgx3-c2gx-wcrm.json b/advisories/unreviewed/2022/05/GHSA-fgx3-c2gx-wcrm/GHSA-fgx3-c2gx-wcrm.json index 570abd26673..6452a4b3e27 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgx3-c2gx-wcrm/GHSA-fgx3-c2gx-wcrm.json +++ b/advisories/unreviewed/2022/05/GHSA-fgx3-c2gx-wcrm/GHSA-fgx3-c2gx-wcrm.json @@ -7,12 +7,8 @@ "CVE-2007-2000" ], "details": "Multiple SQL injection vulnerabilities in admin/admin.php in Crea-Book 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pseudo or (2) passe parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fhp8-2h74-w5rm/GHSA-fhp8-2h74-w5rm.json b/advisories/unreviewed/2022/05/GHSA-fhp8-2h74-w5rm/GHSA-fhp8-2h74-w5rm.json index c1d6d64e0e1..6b7ade71b83 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhp8-2h74-w5rm/GHSA-fhp8-2h74-w5rm.json +++ b/advisories/unreviewed/2022/05/GHSA-fhp8-2h74-w5rm/GHSA-fhp8-2h74-w5rm.json @@ -7,12 +7,8 @@ "CVE-2007-2403" ], "details": "CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 does not properly validate ftp: URIs, which allows remote attackers to trigger the transmission of arbitrary FTP commands to arbitrary FTP servers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fjm4-mhgh-x9f2/GHSA-fjm4-mhgh-x9f2.json b/advisories/unreviewed/2022/05/GHSA-fjm4-mhgh-x9f2/GHSA-fjm4-mhgh-x9f2.json index b6d652542fa..01f649da1be 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjm4-mhgh-x9f2/GHSA-fjm4-mhgh-x9f2.json +++ b/advisories/unreviewed/2022/05/GHSA-fjm4-mhgh-x9f2/GHSA-fjm4-mhgh-x9f2.json @@ -7,12 +7,8 @@ "CVE-2007-2561" ], "details": "SQL injection vulnerability in index.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter, a different vector than CVE-2006-6115.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fm7f-hwmh-f544/GHSA-fm7f-hwmh-f544.json b/advisories/unreviewed/2022/05/GHSA-fm7f-hwmh-f544/GHSA-fm7f-hwmh-f544.json index 795ddc209af..1cea044f1d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm7f-hwmh-f544/GHSA-fm7f-hwmh-f544.json +++ b/advisories/unreviewed/2022/05/GHSA-fm7f-hwmh-f544/GHSA-fm7f-hwmh-f544.json @@ -7,12 +7,8 @@ "CVE-2007-2023" ], "details": "USB20.dll in Secustick USB flash drive decouples the authorization and file access routines, which allows local users to bypass authentication requirements by altering the return value of the VerifyPassWord function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fmp6-6vj9-c43j/GHSA-fmp6-6vj9-c43j.json b/advisories/unreviewed/2022/05/GHSA-fmp6-6vj9-c43j/GHSA-fmp6-6vj9-c43j.json index 200e0bf725d..8d50815b53b 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmp6-6vj9-c43j/GHSA-fmp6-6vj9-c43j.json +++ b/advisories/unreviewed/2022/05/GHSA-fmp6-6vj9-c43j/GHSA-fmp6-6vj9-c43j.json @@ -7,12 +7,8 @@ "CVE-2007-2393" ], "details": "The design of QuickTime for Java in Apple Quicktime before 7.2 allows remote attackers to bypass certain security controls and write to process memory via Java applets, possibly leading to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fp2p-h4pr-r7qj/GHSA-fp2p-h4pr-r7qj.json b/advisories/unreviewed/2022/05/GHSA-fp2p-h4pr-r7qj/GHSA-fp2p-h4pr-r7qj.json index 2abc68836a3..19a70e0061c 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp2p-h4pr-r7qj/GHSA-fp2p-h4pr-r7qj.json +++ b/advisories/unreviewed/2022/05/GHSA-fp2p-h4pr-r7qj/GHSA-fp2p-h4pr-r7qj.json @@ -7,12 +7,8 @@ "CVE-2007-2190" ], "details": "PHP remote file inclusion vulnerability in admin/public/webpages.php in Eba News 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the filename parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fp9p-v798-8f32/GHSA-fp9p-v798-8f32.json b/advisories/unreviewed/2022/05/GHSA-fp9p-v798-8f32/GHSA-fp9p-v798-8f32.json index 51d34a5bdc6..c4e20f9e97a 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp9p-v798-8f32/GHSA-fp9p-v798-8f32.json +++ b/advisories/unreviewed/2022/05/GHSA-fp9p-v798-8f32/GHSA-fp9p-v798-8f32.json @@ -7,12 +7,8 @@ "CVE-2007-2501" ], "details": "Eval injection vulnerability in codepress.html in CodePress before 0.9.4 allows remote attackers to execute arbitrary code via certain input that is used in an eval function call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fpr8-hq4f-4x67/GHSA-fpr8-hq4f-4x67.json b/advisories/unreviewed/2022/05/GHSA-fpr8-hq4f-4x67/GHSA-fpr8-hq4f-4x67.json index 83fe17def38..eaca6715dec 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpr8-hq4f-4x67/GHSA-fpr8-hq4f-4x67.json +++ b/advisories/unreviewed/2022/05/GHSA-fpr8-hq4f-4x67/GHSA-fpr8-hq4f-4x67.json @@ -7,12 +7,8 @@ "CVE-2007-2227" ], "details": "The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle Content-Disposition \"notifications,\" which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka \"Content Disposition Parsing Cross Domain Information Disclosure Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fpvm-x2pg-q52h/GHSA-fpvm-x2pg-q52h.json b/advisories/unreviewed/2022/05/GHSA-fpvm-x2pg-q52h/GHSA-fpvm-x2pg-q52h.json index 8e204a6ea38..9a795e45179 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpvm-x2pg-q52h/GHSA-fpvm-x2pg-q52h.json +++ b/advisories/unreviewed/2022/05/GHSA-fpvm-x2pg-q52h/GHSA-fpvm-x2pg-q52h.json @@ -7,12 +7,8 @@ "CVE-2007-1993" ], "details": "Buffer overflow in the pfs_mountd.rpc RPC daemon in the Portable File System (PFS) in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to execute arbitrary code by sending \"a call to procedure 5, followed by a crafted payload to procedure 2.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpwr-6qp2-5267/GHSA-fpwr-6qp2-5267.json b/advisories/unreviewed/2022/05/GHSA-fpwr-6qp2-5267/GHSA-fpwr-6qp2-5267.json index c1ba13c78f1..6fd528fb00f 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpwr-6qp2-5267/GHSA-fpwr-6qp2-5267.json +++ b/advisories/unreviewed/2022/05/GHSA-fpwr-6qp2-5267/GHSA-fpwr-6qp2-5267.json @@ -7,12 +7,8 @@ "CVE-2007-1984" ], "details": "PHP remote file inclusion vulnerability in index.php in lite-cms 0.2.1 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fq6v-g5cf-j8rf/GHSA-fq6v-g5cf-j8rf.json b/advisories/unreviewed/2022/05/GHSA-fq6v-g5cf-j8rf/GHSA-fq6v-g5cf-j8rf.json index 5108e4d6f43..4f67ebbbd0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-fq6v-g5cf-j8rf/GHSA-fq6v-g5cf-j8rf.json +++ b/advisories/unreviewed/2022/05/GHSA-fq6v-g5cf-j8rf/GHSA-fq6v-g5cf-j8rf.json @@ -7,12 +7,8 @@ "CVE-2007-2390" ], "details": "Buffer overflow in iChat in Apple Mac OS X 10.3.9 and 10.4.9 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fq7c-87gr-rq4x/GHSA-fq7c-87gr-rq4x.json b/advisories/unreviewed/2022/05/GHSA-fq7c-87gr-rq4x/GHSA-fq7c-87gr-rq4x.json index a293467520b..457f51b55fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-fq7c-87gr-rq4x/GHSA-fq7c-87gr-rq4x.json +++ b/advisories/unreviewed/2022/05/GHSA-fq7c-87gr-rq4x/GHSA-fq7c-87gr-rq4x.json @@ -7,12 +7,8 @@ "CVE-2007-2635" ], "details": "Unspecified vulnerability in Interchange before 5.4.2 allows remote attackers to cause an unspecified denial of service (possibly server hang) via crafted HTTP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fw2w-69jg-69h7/GHSA-fw2w-69jg-69h7.json b/advisories/unreviewed/2022/05/GHSA-fw2w-69jg-69h7/GHSA-fw2w-69jg-69h7.json index 1c13eb1ef29..d6b4f4e4401 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw2w-69jg-69h7/GHSA-fw2w-69jg-69h7.json +++ b/advisories/unreviewed/2022/05/GHSA-fw2w-69jg-69h7/GHSA-fw2w-69jg-69h7.json @@ -7,12 +7,8 @@ "CVE-2007-2213" ], "details": "Unspecified vulnerability in the Initialize function in NetscapeFTPHandler in WS_FTP Home and Professional 2007 allows remote attackers to cause a denial of service (NULL dereference and application crash) via unspecified vectors related to \"improper arguments.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fw93-4hm4-6q99/GHSA-fw93-4hm4-6q99.json b/advisories/unreviewed/2022/05/GHSA-fw93-4hm4-6q99/GHSA-fw93-4hm4-6q99.json index c125bd8c536..7eaee713762 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw93-4hm4-6q99/GHSA-fw93-4hm4-6q99.json +++ b/advisories/unreviewed/2022/05/GHSA-fw93-4hm4-6q99/GHSA-fw93-4hm4-6q99.json @@ -7,12 +7,8 @@ "CVE-2007-2284" ], "details": "Buffer overflow in ABC-View Manager 1.42 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fwv6-mh56-rxwc/GHSA-fwv6-mh56-rxwc.json b/advisories/unreviewed/2022/05/GHSA-fwv6-mh56-rxwc/GHSA-fwv6-mh56-rxwc.json index b1fe81485c9..ebb5dd159b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwv6-mh56-rxwc/GHSA-fwv6-mh56-rxwc.json +++ b/advisories/unreviewed/2022/05/GHSA-fwv6-mh56-rxwc/GHSA-fwv6-mh56-rxwc.json @@ -7,12 +7,8 @@ "CVE-2007-2430" ], "details": "shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by placing file contents and directory traversal manipulations into a SessionUserLang cookie to public/code/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fww3-v7c4-qv2v/GHSA-fww3-v7c4-qv2v.json b/advisories/unreviewed/2022/05/GHSA-fww3-v7c4-qv2v/GHSA-fww3-v7c4-qv2v.json index b11d1319c0f..89117bc6bdb 100644 --- a/advisories/unreviewed/2022/05/GHSA-fww3-v7c4-qv2v/GHSA-fww3-v7c4-qv2v.json +++ b/advisories/unreviewed/2022/05/GHSA-fww3-v7c4-qv2v/GHSA-fww3-v7c4-qv2v.json @@ -7,12 +7,8 @@ "CVE-2007-2557" ], "details": "MOStlyDB Admin in Mambo 4.6.1 does not properly check privileges, which allows remote authenticated administrators to have an unknown impact via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fx6p-j7rc-gxcx/GHSA-fx6p-j7rc-gxcx.json b/advisories/unreviewed/2022/05/GHSA-fx6p-j7rc-gxcx/GHSA-fx6p-j7rc-gxcx.json index 5d48eae913f..5e846237051 100644 --- a/advisories/unreviewed/2022/05/GHSA-fx6p-j7rc-gxcx/GHSA-fx6p-j7rc-gxcx.json +++ b/advisories/unreviewed/2022/05/GHSA-fx6p-j7rc-gxcx/GHSA-fx6p-j7rc-gxcx.json @@ -7,12 +7,8 @@ "CVE-2007-2317" ], "details": "Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other products, allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to bb_plugins.php in (1) components/minibb/ or (2) components/com_minibb, or (3) configuration.php. NOTE: the com_minibb.php vector is already covered by CVE-2006-3690.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fxjr-7h6r-6j9v/GHSA-fxjr-7h6r-6j9v.json b/advisories/unreviewed/2022/05/GHSA-fxjr-7h6r-6j9v/GHSA-fxjr-7h6r-6j9v.json index 8af7d8f0547..c987f75734e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxjr-7h6r-6j9v/GHSA-fxjr-7h6r-6j9v.json +++ b/advisories/unreviewed/2022/05/GHSA-fxjr-7h6r-6j9v/GHSA-fxjr-7h6r-6j9v.json @@ -7,12 +7,8 @@ "CVE-2007-1992" ], "details": "Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) EXIF_Makernote.php or (2) EXIF.php in classes/iptc/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g2gj-vcrp-4v75/GHSA-g2gj-vcrp-4v75.json b/advisories/unreviewed/2022/05/GHSA-g2gj-vcrp-4v75/GHSA-g2gj-vcrp-4v75.json index f038facaf0a..a6b97621bcd 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2gj-vcrp-4v75/GHSA-g2gj-vcrp-4v75.json +++ b/advisories/unreviewed/2022/05/GHSA-g2gj-vcrp-4v75/GHSA-g2gj-vcrp-4v75.json @@ -7,12 +7,8 @@ "CVE-2007-2235" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PunBB 1.2.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Referer HTTP header to misc.php or the (2) category name when deleting a category in admin_categories.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g385-472x-mccv/GHSA-g385-472x-mccv.json b/advisories/unreviewed/2022/05/GHSA-g385-472x-mccv/GHSA-g385-472x-mccv.json index 1758e11e815..32606f5d30f 100644 --- a/advisories/unreviewed/2022/05/GHSA-g385-472x-mccv/GHSA-g385-472x-mccv.json +++ b/advisories/unreviewed/2022/05/GHSA-g385-472x-mccv/GHSA-g385-472x-mccv.json @@ -7,12 +7,8 @@ "CVE-2007-2261" ], "details": "PHP remote file inclusion vulnerability in espaces/communiques/annotations.php in C-Arbre 0.6PR7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter, a different vector than CVE-2007-1721.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g394-4frv-jxj3/GHSA-g394-4frv-jxj3.json b/advisories/unreviewed/2022/05/GHSA-g394-4frv-jxj3/GHSA-g394-4frv-jxj3.json index 3087e0ad8f0..94e2aa1afb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-g394-4frv-jxj3/GHSA-g394-4frv-jxj3.json +++ b/advisories/unreviewed/2022/05/GHSA-g394-4frv-jxj3/GHSA-g394-4frv-jxj3.json @@ -7,12 +7,8 @@ "CVE-2007-2168" ], "details": "Static code injection vulnerability in process.php in AimStats 3.2 and earlier allows remote attackers to inject PHP code into config.php via the databasehost parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g4p9-3mw4-76j8/GHSA-g4p9-3mw4-76j8.json b/advisories/unreviewed/2022/05/GHSA-g4p9-3mw4-76j8/GHSA-g4p9-3mw4-76j8.json index 3bbc77919a1..f3789887f04 100644 --- a/advisories/unreviewed/2022/05/GHSA-g4p9-3mw4-76j8/GHSA-g4p9-3mw4-76j8.json +++ b/advisories/unreviewed/2022/05/GHSA-g4p9-3mw4-76j8/GHSA-g4p9-3mw4-76j8.json @@ -7,12 +7,8 @@ "CVE-2007-2536" ], "details": "PicoZip allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g4x5-qfgc-f49g/GHSA-g4x5-qfgc-f49g.json b/advisories/unreviewed/2022/05/GHSA-g4x5-qfgc-f49g/GHSA-g4x5-qfgc-f49g.json index 450caadc0cc..e4854de2fc0 100644 --- a/advisories/unreviewed/2022/05/GHSA-g4x5-qfgc-f49g/GHSA-g4x5-qfgc-f49g.json +++ b/advisories/unreviewed/2022/05/GHSA-g4x5-qfgc-f49g/GHSA-g4x5-qfgc-f49g.json @@ -7,12 +7,8 @@ "CVE-2007-2689" ], "details": "Check Point Web Intelligence does not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g546-8rgj-38hx/GHSA-g546-8rgj-38hx.json b/advisories/unreviewed/2022/05/GHSA-g546-8rgj-38hx/GHSA-g546-8rgj-38hx.json index 47aac9e57cb..96418c24343 100644 --- a/advisories/unreviewed/2022/05/GHSA-g546-8rgj-38hx/GHSA-g546-8rgj-38hx.json +++ b/advisories/unreviewed/2022/05/GHSA-g546-8rgj-38hx/GHSA-g546-8rgj-38hx.json @@ -7,12 +7,8 @@ "CVE-2007-2520" ], "details": "SQL injection vulnerability in admin.php in MyNews 0.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authacc cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g7f5-5j5h-6jg7/GHSA-g7f5-5j5h-6jg7.json b/advisories/unreviewed/2022/05/GHSA-g7f5-5j5h-6jg7/GHSA-g7f5-5j5h-6jg7.json index 9e1d7563d2b..a543da224f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7f5-5j5h-6jg7/GHSA-g7f5-5j5h-6jg7.json +++ b/advisories/unreviewed/2022/05/GHSA-g7f5-5j5h-6jg7/GHSA-g7f5-5j5h-6jg7.json @@ -7,12 +7,8 @@ "CVE-2007-2576" ], "details": "Buffer overflow in the East Wind Software advdaudio.ocx 1.5.1.1 ActiveX control allows user-assisted remote attackers to execute arbitrary code via a long OpenDVD property value. NOTE: this issue might be related to CVE-2007-0976.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g7fw-7775-6f78/GHSA-g7fw-7775-6f78.json b/advisories/unreviewed/2022/05/GHSA-g7fw-7775-6f78/GHSA-g7fw-7775-6f78.json index f2ff9f9e7e3..2d6d38ad5a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7fw-7775-6f78/GHSA-g7fw-7775-6f78.json +++ b/advisories/unreviewed/2022/05/GHSA-g7fw-7775-6f78/GHSA-g7fw-7775-6f78.json @@ -7,12 +7,8 @@ "CVE-2007-2146" ], "details": "The imagecomments function in classes.php in MiniGal b13 allow remote attackers to inject arbitrary PHP code into a file in the thumbs/ directory via the (1) name or (2) email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g8gg-vr6j-4v4c/GHSA-g8gg-vr6j-4v4c.json b/advisories/unreviewed/2022/05/GHSA-g8gg-vr6j-4v4c/GHSA-g8gg-vr6j-4v4c.json index 4ae402c6ffa..6bc29a8970e 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8gg-vr6j-4v4c/GHSA-g8gg-vr6j-4v4c.json +++ b/advisories/unreviewed/2022/05/GHSA-g8gg-vr6j-4v4c/GHSA-g8gg-vr6j-4v4c.json @@ -7,12 +7,8 @@ "CVE-2007-2352" ], "details": "Multiple format string vulnerabilities in AFFLIB 2.2.6 allow remote attackers to execute arbitrary code via certain command line parameters, which are used in (1) warn and (2) err calls, possibly involving (a) lib/s3.cpp, (b) tools/afconvert.cpp, (c) tools/afcopy.cpp, (d) tools/afinfo.cpp, (e) aimage/imager.cpp, and (f) tools/afxml.cpp. NOTE: this identifier is intended to address the vectors that were not fixed in CVE-2007-2054, but the unfixed vectors were not explicitly listed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g94r-xccx-9762/GHSA-g94r-xccx-9762.json b/advisories/unreviewed/2022/05/GHSA-g94r-xccx-9762/GHSA-g94r-xccx-9762.json index 746c2e72434..986a45eeca4 100644 --- a/advisories/unreviewed/2022/05/GHSA-g94r-xccx-9762/GHSA-g94r-xccx-9762.json +++ b/advisories/unreviewed/2022/05/GHSA-g94r-xccx-9762/GHSA-g94r-xccx-9762.json @@ -7,12 +7,8 @@ "CVE-2007-2382" ], "details": "The Moo.fx framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka \"JavaScript Hijacking.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g98h-xvfp-4q9x/GHSA-g98h-xvfp-4q9x.json b/advisories/unreviewed/2022/05/GHSA-g98h-xvfp-4q9x/GHSA-g98h-xvfp-4q9x.json index 06a54e93f6a..3b66d6ef7b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-g98h-xvfp-4q9x/GHSA-g98h-xvfp-4q9x.json +++ b/advisories/unreviewed/2022/05/GHSA-g98h-xvfp-4q9x/GHSA-g98h-xvfp-4q9x.json @@ -7,12 +7,8 @@ "CVE-2019-12957" ], "details": "In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the index number is larger than the charset array bounds. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g9jj-hcxp-4x79/GHSA-g9jj-hcxp-4x79.json b/advisories/unreviewed/2022/05/GHSA-g9jj-hcxp-4x79/GHSA-g9jj-hcxp-4x79.json index d7fec5a1987..02009ae1f2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9jj-hcxp-4x79/GHSA-g9jj-hcxp-4x79.json +++ b/advisories/unreviewed/2022/05/GHSA-g9jj-hcxp-4x79/GHSA-g9jj-hcxp-4x79.json @@ -7,12 +7,8 @@ "CVE-2007-2414" ], "details": "MyServer before 0.8.8 allows remote attackers to cause a denial of service via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gc73-hf46-8rfq/GHSA-gc73-hf46-8rfq.json b/advisories/unreviewed/2022/05/GHSA-gc73-hf46-8rfq/GHSA-gc73-hf46-8rfq.json index 66265a860ef..cec88eb68f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc73-hf46-8rfq/GHSA-gc73-hf46-8rfq.json +++ b/advisories/unreviewed/2022/05/GHSA-gc73-hf46-8rfq/GHSA-gc73-hf46-8rfq.json @@ -7,12 +7,8 @@ "CVE-2007-2363" ], "details": "Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gf25-q755-f96h/GHSA-gf25-q755-f96h.json b/advisories/unreviewed/2022/05/GHSA-gf25-q755-f96h/GHSA-gf25-q755-f96h.json index c200b6df76e..dc15390df44 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf25-q755-f96h/GHSA-gf25-q755-f96h.json +++ b/advisories/unreviewed/2022/05/GHSA-gf25-q755-f96h/GHSA-gf25-q755-f96h.json @@ -7,12 +7,8 @@ "CVE-2007-2204" ], "details": "Multiple PHP remote file inclusion vulnerabilities in GPL PHP Board (GPB) unstable-2001.11.14-1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) db.mysql.inc.php or (2) gpb.inc.php in include/, or the (3) theme parameter to themes/ubb/login.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gf2r-m9f5-gm87/GHSA-gf2r-m9f5-gm87.json b/advisories/unreviewed/2022/05/GHSA-gf2r-m9f5-gm87/GHSA-gf2r-m9f5-gm87.json index ee2622fb6d4..e2449e4971b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf2r-m9f5-gm87/GHSA-gf2r-m9f5-gm87.json +++ b/advisories/unreviewed/2022/05/GHSA-gf2r-m9f5-gm87/GHSA-gf2r-m9f5-gm87.json @@ -7,12 +7,8 @@ "CVE-2007-2429" ], "details": "ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for the mysql program, as demonstrated by the \"-port 2345\" and \"-u root\" arguments. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gfmp-6wvc-g9jj/GHSA-gfmp-6wvc-g9jj.json b/advisories/unreviewed/2022/05/GHSA-gfmp-6wvc-g9jj/GHSA-gfmp-6wvc-g9jj.json index 3ea27d9324c..ea5dbe25a8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfmp-6wvc-g9jj/GHSA-gfmp-6wvc-g9jj.json +++ b/advisories/unreviewed/2022/05/GHSA-gfmp-6wvc-g9jj/GHSA-gfmp-6wvc-g9jj.json @@ -7,12 +7,8 @@ "CVE-2007-2199" ], "details": "PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gfv5-27qx-cv4m/GHSA-gfv5-27qx-cv4m.json b/advisories/unreviewed/2022/05/GHSA-gfv5-27qx-cv4m/GHSA-gfv5-27qx-cv4m.json index d7396628ab8..69480e9fc4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfv5-27qx-cv4m/GHSA-gfv5-27qx-cv4m.json +++ b/advisories/unreviewed/2022/05/GHSA-gfv5-27qx-cv4m/GHSA-gfv5-27qx-cv4m.json @@ -7,12 +7,8 @@ "CVE-2007-2384" ], "details": "The Script.aculo.us framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka \"JavaScript Hijacking.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ggm4-536h-f6c7/GHSA-ggm4-536h-f6c7.json b/advisories/unreviewed/2022/05/GHSA-ggm4-536h-f6c7/GHSA-ggm4-536h-f6c7.json index 73f3643ccd8..4732b4ff45f 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggm4-536h-f6c7/GHSA-ggm4-536h-f6c7.json +++ b/advisories/unreviewed/2022/05/GHSA-ggm4-536h-f6c7/GHSA-ggm4-536h-f6c7.json @@ -7,12 +7,8 @@ "CVE-2007-2619" ], "details": "Symantec pcAnywhere 11.5.x and 12.0.x retains unencrypted login credentials for the most recent login within process memory, which allows local administrators to obtain the credentials by reading process memory, a different vulnerability than CVE-2006-3785.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gh92-xgwc-mx9x/GHSA-gh92-xgwc-mx9x.json b/advisories/unreviewed/2022/05/GHSA-gh92-xgwc-mx9x/GHSA-gh92-xgwc-mx9x.json index f1b085c2e61..f94511e281f 100644 --- a/advisories/unreviewed/2022/05/GHSA-gh92-xgwc-mx9x/GHSA-gh92-xgwc-mx9x.json +++ b/advisories/unreviewed/2022/05/GHSA-gh92-xgwc-mx9x/GHSA-gh92-xgwc-mx9x.json @@ -7,12 +7,8 @@ "CVE-2007-2471" ], "details": "Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrary files via a full pathname in the form parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gj98-hgg3-qjh7/GHSA-gj98-hgg3-qjh7.json b/advisories/unreviewed/2022/05/GHSA-gj98-hgg3-qjh7/GHSA-gj98-hgg3-qjh7.json index a2fa3586958..8affe784397 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj98-hgg3-qjh7/GHSA-gj98-hgg3-qjh7.json +++ b/advisories/unreviewed/2022/05/GHSA-gj98-hgg3-qjh7/GHSA-gj98-hgg3-qjh7.json @@ -7,12 +7,8 @@ "CVE-2007-2188" ], "details": "eXtremail 2.1.1 and earlier does not verify the ID field (aka transaction id) in DNS responses, which makes it easier for remote attackers to conduct DNS spoofing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gjqq-f3mg-pp9x/GHSA-gjqq-f3mg-pp9x.json b/advisories/unreviewed/2022/05/GHSA-gjqq-f3mg-pp9x/GHSA-gjqq-f3mg-pp9x.json index 3e920ba5f96..db04a0463d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjqq-f3mg-pp9x/GHSA-gjqq-f3mg-pp9x.json +++ b/advisories/unreviewed/2022/05/GHSA-gjqq-f3mg-pp9x/GHSA-gjqq-f3mg-pp9x.json @@ -7,12 +7,8 @@ "CVE-2007-2555" ], "details": "Unspecified vulnerability in Default.aspx in Podium CMS allows remote attackers to have an unknown impact, possibly session fixation, via a META HTTP-EQUIV Set-cookie expression in the id parameter, related to \"cookie manipulation.\" NOTE: this issue might be cross-site scripting (XSS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gpc9-9gpx-9r9x/GHSA-gpc9-9gpx-9r9x.json b/advisories/unreviewed/2022/05/GHSA-gpc9-9gpx-9r9x/GHSA-gpc9-9gpx-9r9x.json index 939717eb5fe..78913072cd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpc9-9gpx-9r9x/GHSA-gpc9-9gpx-9r9x.json +++ b/advisories/unreviewed/2022/05/GHSA-gpc9-9gpx-9r9x/GHSA-gpc9-9gpx-9r9x.json @@ -7,12 +7,8 @@ "CVE-2007-2408" ], "details": "WebKit in Apple Safari 3 Beta before Update 3.0.3 does not properly recognize an unchecked \"Enable Java\" setting, which allows remote attackers to execute Java applets via a crafted web page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gpwx-5qfc-8xgj/GHSA-gpwx-5qfc-8xgj.json b/advisories/unreviewed/2022/05/GHSA-gpwx-5qfc-8xgj/GHSA-gpwx-5qfc-8xgj.json index e39f9d7efe9..21599569ac0 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpwx-5qfc-8xgj/GHSA-gpwx-5qfc-8xgj.json +++ b/advisories/unreviewed/2022/05/GHSA-gpwx-5qfc-8xgj/GHSA-gpwx-5qfc-8xgj.json @@ -7,12 +7,8 @@ "CVE-2007-2310" ], "details": "Cross-site scripting (XSS) vulnerability in plugins/spaw/img_popup.php in BloofoxCMS 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the img_url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gq2c-rqg7-fr3g/GHSA-gq2c-rqg7-fr3g.json b/advisories/unreviewed/2022/05/GHSA-gq2c-rqg7-fr3g/GHSA-gq2c-rqg7-fr3g.json index 515e31f3cb3..8ed4355303a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gq2c-rqg7-fr3g/GHSA-gq2c-rqg7-fr3g.json +++ b/advisories/unreviewed/2022/05/GHSA-gq2c-rqg7-fr3g/GHSA-gq2c-rqg7-fr3g.json @@ -7,12 +7,8 @@ "CVE-2007-2185" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Supasite 1.23b allow remote attackers to execute arbitrary PHP code via a URL in the supa[db_path] parameter to (1) common_functions.php, (2) admin_auth_cookies.php, (3) admin_mods.php, (4) admin_news.php, (5) admin_topics.php, (6) admin_users.php, (7) admin_utilities.php, (8) site_comment.php, or (9) site_news.php; or the supa[include_path] parameter to (10) admin_settings.php or (11) backend_site.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gq6v-r7qv-9cm5/GHSA-gq6v-r7qv-9cm5.json b/advisories/unreviewed/2022/05/GHSA-gq6v-r7qv-9cm5/GHSA-gq6v-r7qv-9cm5.json index c9f9e96bd9c..4915f04c490 100644 --- a/advisories/unreviewed/2022/05/GHSA-gq6v-r7qv-9cm5/GHSA-gq6v-r7qv-9cm5.json +++ b/advisories/unreviewed/2022/05/GHSA-gq6v-r7qv-9cm5/GHSA-gq6v-r7qv-9cm5.json @@ -7,12 +7,8 @@ "CVE-2007-2266" ], "details": "Progress Webspeed Messenger allows remote attackers to read, create, modify, and execute arbitrary files by invoking webutil/_cpyfile.p in the WService parameter to (1) cgiip.exe or (2) wsisa.dll in scripts/, as demonstrated by using the save,editor options to create a new file using the fileName parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gqg7-9h2q-r4q3/GHSA-gqg7-9h2q-r4q3.json b/advisories/unreviewed/2022/05/GHSA-gqg7-9h2q-r4q3/GHSA-gqg7-9h2q-r4q3.json index 1f3c7595c2c..dc85417db9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqg7-9h2q-r4q3/GHSA-gqg7-9h2q-r4q3.json +++ b/advisories/unreviewed/2022/05/GHSA-gqg7-9h2q-r4q3/GHSA-gqg7-9h2q-r4q3.json @@ -7,12 +7,8 @@ "CVE-2007-2651" ], "details": "Multiple off-by-one errors in VooDoo cIRCle before 1.1.beta27 allow remote attackers to cause a denial of service (connection loss) or possibly execute arbitrary code via a (1) DNS name response of the exact length as a buffer; or a long (2) channel name, (3) partyline channel name, or unspecified vectors in crafted BOTNET packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gr9j-fc2w-4cjh/GHSA-gr9j-fc2w-4cjh.json b/advisories/unreviewed/2022/05/GHSA-gr9j-fc2w-4cjh/GHSA-gr9j-fc2w-4cjh.json index 26079fdd999..638c0f043f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr9j-fc2w-4cjh/GHSA-gr9j-fc2w-4cjh.json +++ b/advisories/unreviewed/2022/05/GHSA-gr9j-fc2w-4cjh/GHSA-gr9j-fc2w-4cjh.json @@ -7,12 +7,8 @@ "CVE-2007-2604" ], "details": "Unspecified vulnerability in the FlexLabel ActiveX control allows remote attackers to cause a denial of service (unstable behavior) via an improper initialization, as demonstrated by a certain value of the Caption property.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gv7q-m6rf-wx37/GHSA-gv7q-m6rf-wx37.json b/advisories/unreviewed/2022/05/GHSA-gv7q-m6rf-wx37/GHSA-gv7q-m6rf-wx37.json index c76f418423a..ac43bb1fcfb 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv7q-m6rf-wx37/GHSA-gv7q-m6rf-wx37.json +++ b/advisories/unreviewed/2022/05/GHSA-gv7q-m6rf-wx37/GHSA-gv7q-m6rf-wx37.json @@ -7,12 +7,8 @@ "CVE-2007-2250" ], "details": "admin.php in Phorum before 5.1.22 allows remote attackers to obtain the full path via the module[] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gvqx-5wm2-crr2/GHSA-gvqx-5wm2-crr2.json b/advisories/unreviewed/2022/05/GHSA-gvqx-5wm2-crr2/GHSA-gvqx-5wm2-crr2.json index df9c7598639..d2edf9df633 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvqx-5wm2-crr2/GHSA-gvqx-5wm2-crr2.json +++ b/advisories/unreviewed/2022/05/GHSA-gvqx-5wm2-crr2/GHSA-gvqx-5wm2-crr2.json @@ -7,12 +7,8 @@ "CVE-2007-2686" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter in a sendpwd task.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gxp8-xh27-r994/GHSA-gxp8-xh27-r994.json b/advisories/unreviewed/2022/05/GHSA-gxp8-xh27-r994/GHSA-gxp8-xh27-r994.json index c9e8edc3ac3..0d863152000 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxp8-xh27-r994/GHSA-gxp8-xh27-r994.json +++ b/advisories/unreviewed/2022/05/GHSA-gxp8-xh27-r994/GHSA-gxp8-xh27-r994.json @@ -7,12 +7,8 @@ "CVE-2007-2172" ], "details": "A typo in Linux kernel 2.6 before 2.6.21-rc6 and 2.4 before 2.4.35 causes RTA_MAX to be used as an array size instead of RTN_MAX, which leads to an \"out of bound access\" by the (1) dn_fib_props (dn_fib.c, DECNet) and (2) fib_props (fib_semantics.c, IPv4) functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxq5-r64w-rpjm/GHSA-gxq5-r64w-rpjm.json b/advisories/unreviewed/2022/05/GHSA-gxq5-r64w-rpjm/GHSA-gxq5-r64w-rpjm.json index 1ed9f5902f1..88bf47e4186 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxq5-r64w-rpjm/GHSA-gxq5-r64w-rpjm.json +++ b/advisories/unreviewed/2022/05/GHSA-gxq5-r64w-rpjm/GHSA-gxq5-r64w-rpjm.json @@ -7,12 +7,8 @@ "CVE-2007-2505" ], "details": "Stack-based buffer overflow in InterVations MailCOPA 8.01 20070323 allows user-assisted remote attackers to execute arbitrary code via a long command line argument, as demonstrated by a long string in the subject field in a mailto URI. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h24f-49f9-gqhv/GHSA-h24f-49f9-gqhv.json b/advisories/unreviewed/2022/05/GHSA-h24f-49f9-gqhv/GHSA-h24f-49f9-gqhv.json index 4e77e2701b1..07ecf5b403d 100644 --- a/advisories/unreviewed/2022/05/GHSA-h24f-49f9-gqhv/GHSA-h24f-49f9-gqhv.json +++ b/advisories/unreviewed/2022/05/GHSA-h24f-49f9-gqhv/GHSA-h24f-49f9-gqhv.json @@ -7,12 +7,8 @@ "CVE-2007-2402" ], "details": "QuickTime for Java in Apple Quicktime before 7.2 does not perform sufficient \"access control,\" which allows remote attackers to obtain sensitive information (screen content) via crafted Java applets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h2gj-j3wh-6965/GHSA-h2gj-j3wh-6965.json b/advisories/unreviewed/2022/05/GHSA-h2gj-j3wh-6965/GHSA-h2gj-j3wh-6965.json index e3d8d042798..62ab583cdc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2gj-j3wh-6965/GHSA-h2gj-j3wh-6965.json +++ b/advisories/unreviewed/2022/05/GHSA-h2gj-j3wh-6965/GHSA-h2gj-j3wh-6965.json @@ -7,12 +7,8 @@ "CVE-2007-2289" ], "details": "PHP remote file inclusion vulnerability in admin/includes/spaw/dialogs/insert_link.php in download engine (Download-Engine) 1.4.1 allows remote authenticated users to execute arbitrary PHP code via a URL in the spaw_root parameter, a different vector than CVE-2007-2255. NOTE: this may be an issue in SPAW.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h3hj-j528-h53w/GHSA-h3hj-j528-h53w.json b/advisories/unreviewed/2022/05/GHSA-h3hj-j528-h53w/GHSA-h3hj-j528-h53w.json index a2e77fd2678..06541c2a7b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3hj-j528-h53w/GHSA-h3hj-j528-h53w.json +++ b/advisories/unreviewed/2022/05/GHSA-h3hj-j528-h53w/GHSA-h3hj-j528-h53w.json @@ -7,12 +7,8 @@ "CVE-2007-2446" ], "details": "Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involving (1) DFSEnum (netdfs_io_dfs_EnumInfo_d), (2) RFNPCNEX (smb_io_notify_option_type_data), (3) LsarAddPrivilegesToAccount (lsa_io_privilege_set), (4) NetSetFileSecurity (sec_io_acl), or (5) LsarLookupSids/LsarLookupSids2 (lsa_io_trans_names).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h4rr-mmcx-w68q/GHSA-h4rr-mmcx-w68q.json b/advisories/unreviewed/2022/05/GHSA-h4rr-mmcx-w68q/GHSA-h4rr-mmcx-w68q.json index 3d57e94a509..e8e8e72398b 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4rr-mmcx-w68q/GHSA-h4rr-mmcx-w68q.json +++ b/advisories/unreviewed/2022/05/GHSA-h4rr-mmcx-w68q/GHSA-h4rr-mmcx-w68q.json @@ -7,12 +7,8 @@ "CVE-2007-2181" ], "details": "PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter, a different product and vector than CVE-2005-0748.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h6m4-wh5q-f97x/GHSA-h6m4-wh5q-f97x.json b/advisories/unreviewed/2022/05/GHSA-h6m4-wh5q-f97x/GHSA-h6m4-wh5q-f97x.json index f2812c6dbed..dc4cb8b6cdc 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6m4-wh5q-f97x/GHSA-h6m4-wh5q-f97x.json +++ b/advisories/unreviewed/2022/05/GHSA-h6m4-wh5q-f97x/GHSA-h6m4-wh5q-f97x.json @@ -7,12 +7,8 @@ "CVE-2007-1998" ], "details": "Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP code via the Email field, which results in code execution through a direct request to gb.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h6p8-49r2-h64m/GHSA-h6p8-49r2-h64m.json b/advisories/unreviewed/2022/05/GHSA-h6p8-49r2-h64m/GHSA-h6p8-49r2-h64m.json index 524fbe7313b..6d813360b95 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6p8-49r2-h64m/GHSA-h6p8-49r2-h64m.json +++ b/advisories/unreviewed/2022/05/GHSA-h6p8-49r2-h64m/GHSA-h6p8-49r2-h64m.json @@ -7,12 +7,8 @@ "CVE-2007-2544" ], "details": "PHP remote file inclusion vulnerability in templates/default/tpl_message.php in PHP TopTree BBS 2.0.1a and earlier allows remote attackers to execute arbitrary PHP code via a URL in the right_file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h78v-7wxx-7wmv/GHSA-h78v-7wxx-7wmv.json b/advisories/unreviewed/2022/05/GHSA-h78v-7wxx-7wmv/GHSA-h78v-7wxx-7wmv.json index f1f4fdc6d1a..93051ceff1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-h78v-7wxx-7wmv/GHSA-h78v-7wxx-7wmv.json +++ b/advisories/unreviewed/2022/05/GHSA-h78v-7wxx-7wmv/GHSA-h78v-7wxx-7wmv.json @@ -7,12 +7,8 @@ "CVE-2007-2006" ], "details": "Multiple SQL injection vulnerabilities in login.php in pL-PHP beta 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) pass parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h7pj-cwh9-5339/GHSA-h7pj-cwh9-5339.json b/advisories/unreviewed/2022/05/GHSA-h7pj-cwh9-5339/GHSA-h7pj-cwh9-5339.json index 06d557320eb..dc98c1f2b09 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7pj-cwh9-5339/GHSA-h7pj-cwh9-5339.json +++ b/advisories/unreviewed/2022/05/GHSA-h7pj-cwh9-5339/GHSA-h7pj-cwh9-5339.json @@ -7,12 +7,8 @@ "CVE-2007-2563" ], "details": "Buffer overflow in the AddFile function in VersalSoft HTTP File Upload ActiveX control (UFileUploaderD.dll) allows remote attackers to execute arbitrary code via a long argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h8jw-wrch-v25p/GHSA-h8jw-wrch-v25p.json b/advisories/unreviewed/2022/05/GHSA-h8jw-wrch-v25p/GHSA-h8jw-wrch-v25p.json index f2d8f90bf4c..1eb5a859c1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8jw-wrch-v25p/GHSA-h8jw-wrch-v25p.json +++ b/advisories/unreviewed/2022/05/GHSA-h8jw-wrch-v25p/GHSA-h8jw-wrch-v25p.json @@ -7,12 +7,8 @@ "CVE-2007-2428" ], "details": "Multiple PHP remote file inclusion vulnerabilities in page.php in Ahhp-Portal allow remote attackers to execute arbitrary PHP code via a URL in the (1) fp or (2) sc parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h8pf-qhq6-5c94/GHSA-h8pf-qhq6-5c94.json b/advisories/unreviewed/2022/05/GHSA-h8pf-qhq6-5c94/GHSA-h8pf-qhq6-5c94.json index 03fffbb1b32..fd23cde4266 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8pf-qhq6-5c94/GHSA-h8pf-qhq6-5c94.json +++ b/advisories/unreviewed/2022/05/GHSA-h8pf-qhq6-5c94/GHSA-h8pf-qhq6-5c94.json @@ -7,12 +7,8 @@ "CVE-2007-2499" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in DVDdb 0.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the movieid parameter to loan.php or (2) the s parameter to listmovies.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h8r6-qv42-qvgx/GHSA-h8r6-qv42-qvgx.json b/advisories/unreviewed/2022/05/GHSA-h8r6-qv42-qvgx/GHSA-h8r6-qv42-qvgx.json index 6cae3c08035..b32fb587b61 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8r6-qv42-qvgx/GHSA-h8r6-qv42-qvgx.json +++ b/advisories/unreviewed/2022/05/GHSA-h8r6-qv42-qvgx/GHSA-h8r6-qv42-qvgx.json @@ -7,12 +7,8 @@ "CVE-2007-2331" ], "details": "PHP remote file inclusion vulnerability in cart.php in Shop-Script 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the lang_list parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hcp3-6p74-64v4/GHSA-hcp3-6p74-64v4.json b/advisories/unreviewed/2022/05/GHSA-hcp3-6p74-64v4/GHSA-hcp3-6p74-64v4.json index 81dde9b7298..8a9c0f84900 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcp3-6p74-64v4/GHSA-hcp3-6p74-64v4.json +++ b/advisories/unreviewed/2022/05/GHSA-hcp3-6p74-64v4/GHSA-hcp3-6p74-64v4.json @@ -7,12 +7,8 @@ "CVE-2007-2639" ], "details": "Directory traversal vulnerability in TFTPdWin 0.4.2 allows remote attackers to read or modify arbitrary files outside the TFTP root via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hf23-jpgj-4fhg/GHSA-hf23-jpgj-4fhg.json b/advisories/unreviewed/2022/05/GHSA-hf23-jpgj-4fhg/GHSA-hf23-jpgj-4fhg.json index 7d2ec69520a..dea41ea14e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-hf23-jpgj-4fhg/GHSA-hf23-jpgj-4fhg.json +++ b/advisories/unreviewed/2022/05/GHSA-hf23-jpgj-4fhg/GHSA-hf23-jpgj-4fhg.json @@ -7,12 +7,8 @@ "CVE-2007-2583" ], "details": "The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -124,9 +120,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hf3p-wrj3-r34r/GHSA-hf3p-wrj3-r34r.json b/advisories/unreviewed/2022/05/GHSA-hf3p-wrj3-r34r/GHSA-hf3p-wrj3-r34r.json index 57405ca1af8..d534aa56b7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-hf3p-wrj3-r34r/GHSA-hf3p-wrj3-r34r.json +++ b/advisories/unreviewed/2022/05/GHSA-hf3p-wrj3-r34r/GHSA-hf3p-wrj3-r34r.json @@ -7,12 +7,8 @@ "CVE-2007-2647" ], "details": "Static code injection vulnerability in admin/admin_configuration.php in Monalbum 0.8.7 allows remote authenticated users to inject arbitrary PHP code into the conf/config.inc.php file via the (1) gadm_pass, (2) gadm_user, (3) gcfgHote, (4) gcfgPass, (5) gcfgUser, (6) gclassement_rep, (7) gcontour, (8) gfond, (9) ggd_version, (10) ghome, (11) ghor, (12) gimg_copyright, (13) glangage, (14) gmenu_visible, (15) gmini_hasard, (16) gordre_rep, (17) gpage, (18) gracine, (19) grech_inactive, (20) grep_mini, (21) grepertoire, (22) gsite, (23) gslide, (24) gtitre, (25) guse_copyright, (26) gversion, (27) gvert, or (28) gcfgBase parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hfx9-m8mc-4gvm/GHSA-hfx9-m8mc-4gvm.json b/advisories/unreviewed/2022/05/GHSA-hfx9-m8mc-4gvm/GHSA-hfx9-m8mc-4gvm.json index d4ec8b345dd..084d289e18d 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfx9-m8mc-4gvm/GHSA-hfx9-m8mc-4gvm.json +++ b/advisories/unreviewed/2022/05/GHSA-hfx9-m8mc-4gvm/GHSA-hfx9-m8mc-4gvm.json @@ -7,12 +7,8 @@ "CVE-2007-2537" ], "details": "Multiple SQL injection vulnerabilities in mainfile.php in NPDS 5.10 and earlier allow remote authenticated users to execute arbitrary SQL commands via a (1) nickname or (2) Id in a cookie, or (3) the X-Forwarded-For (X_FORWARDED_FOR) HTTP header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hg6j-xggx-2xw6/GHSA-hg6j-xggx-2xw6.json b/advisories/unreviewed/2022/05/GHSA-hg6j-xggx-2xw6/GHSA-hg6j-xggx-2xw6.json index 0d8ef2ce48f..15d4ef95356 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg6j-xggx-2xw6/GHSA-hg6j-xggx-2xw6.json +++ b/advisories/unreviewed/2022/05/GHSA-hg6j-xggx-2xw6/GHSA-hg6j-xggx-2xw6.json @@ -7,12 +7,8 @@ "CVE-2007-2602" ], "details": "Buffer overflow in MIBEXTRA.EXE in Ipswitch WhatsUp Gold 11 allows attackers to cause a denial of service (application crash) or execute arbitrary code via a long MIB filename argument. NOTE: If there is not a common scenario under which MIBEXTRA.EXE is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hjff-7g2c-88cw/GHSA-hjff-7g2c-88cw.json b/advisories/unreviewed/2022/05/GHSA-hjff-7g2c-88cw/GHSA-hjff-7g2c-88cw.json index e9a0abee718..a632aa2136c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjff-7g2c-88cw/GHSA-hjff-7g2c-88cw.json +++ b/advisories/unreviewed/2022/05/GHSA-hjff-7g2c-88cw/GHSA-hjff-7g2c-88cw.json @@ -7,12 +7,8 @@ "CVE-2007-2290" ], "details": "Multiple PHP remote file inclusion vulnerabilities in B2 Weblog and News Publishing Tool 0.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the b2inc parameter to (1) b2archives.php, (2) b2categories.php, or (3) b2mail.php. NOTE: this may overlap CVE-2002-1466.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hjj7-wfq5-75m5/GHSA-hjj7-wfq5-75m5.json b/advisories/unreviewed/2022/05/GHSA-hjj7-wfq5-75m5/GHSA-hjj7-wfq5-75m5.json index 822b79d4ca2..c536c971842 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjj7-wfq5-75m5/GHSA-hjj7-wfq5-75m5.json +++ b/advisories/unreviewed/2022/05/GHSA-hjj7-wfq5-75m5/GHSA-hjj7-wfq5-75m5.json @@ -7,12 +7,8 @@ "CVE-2007-2497" ], "details": "RealNetworks RealPlayer 10 Gold allows remote attackers to cause a denial of service (memory consumption) via a certain .ra file. NOTE: this issue was referred to as a \"memory leak,\" but it is not clear if this is correct.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hjwq-r37x-vhq8/GHSA-hjwq-r37x-vhq8.json b/advisories/unreviewed/2022/05/GHSA-hjwq-r37x-vhq8/GHSA-hjwq-r37x-vhq8.json index 0c23d1a1edb..0c5b93a4875 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjwq-r37x-vhq8/GHSA-hjwq-r37x-vhq8.json +++ b/advisories/unreviewed/2022/05/GHSA-hjwq-r37x-vhq8/GHSA-hjwq-r37x-vhq8.json @@ -7,12 +7,8 @@ "CVE-2007-2487" ], "details": "Stack-based buffer overflow in AtomixMP3 allows remote attackers to execute arbitrary code via a long filename in an MP3 file, a different vector than CVE-2006-6287.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hmcv-vmjh-v7xp/GHSA-hmcv-vmjh-v7xp.json b/advisories/unreviewed/2022/05/GHSA-hmcv-vmjh-v7xp/GHSA-hmcv-vmjh-v7xp.json index 85d272c6aed..f9e87e4b0ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-hmcv-vmjh-v7xp/GHSA-hmcv-vmjh-v7xp.json +++ b/advisories/unreviewed/2022/05/GHSA-hmcv-vmjh-v7xp/GHSA-hmcv-vmjh-v7xp.json @@ -7,12 +7,8 @@ "CVE-2007-2124" ], "details": "Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.4.1.0 has unknown impact and remote attack vectors, aka AS05.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hmhp-6x62-gr89/GHSA-hmhp-6x62-gr89.json b/advisories/unreviewed/2022/05/GHSA-hmhp-6x62-gr89/GHSA-hmhp-6x62-gr89.json index b65ff903634..cef80392846 100644 --- a/advisories/unreviewed/2022/05/GHSA-hmhp-6x62-gr89/GHSA-hmhp-6x62-gr89.json +++ b/advisories/unreviewed/2022/05/GHSA-hmhp-6x62-gr89/GHSA-hmhp-6x62-gr89.json @@ -7,12 +7,8 @@ "CVE-2007-1981" ], "details": "The safevoid_vsnprintf function in Metamod-P 1.19p29 and earlier on Windows allows remote attackers to cause a denial of service (daemon crash) via a long meta list command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hmwf-46rq-28cj/GHSA-hmwf-46rq-28cj.json b/advisories/unreviewed/2022/05/GHSA-hmwf-46rq-28cj/GHSA-hmwf-46rq-28cj.json index 991a5ef3bab..e0c1ef7e3b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-hmwf-46rq-28cj/GHSA-hmwf-46rq-28cj.json +++ b/advisories/unreviewed/2022/05/GHSA-hmwf-46rq-28cj/GHSA-hmwf-46rq-28cj.json @@ -7,12 +7,8 @@ "CVE-2007-2244" ], "details": "Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DIB, or (3) RLE file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hpwj-79q2-6jvm/GHSA-hpwj-79q2-6jvm.json b/advisories/unreviewed/2022/05/GHSA-hpwj-79q2-6jvm/GHSA-hpwj-79q2-6jvm.json index e8c6cdcef70..b4a72ff9c51 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpwj-79q2-6jvm/GHSA-hpwj-79q2-6jvm.json +++ b/advisories/unreviewed/2022/05/GHSA-hpwj-79q2-6jvm/GHSA-hpwj-79q2-6jvm.json @@ -7,12 +7,8 @@ "CVE-2007-2453" ], "details": "The random number feature in Linux kernel 2.6 before 2.6.20.13, and 2.6.21.x before 2.6.21.4, (1) does not properly seed pools when there is no entropy, or (2) uses an incorrect cast when extracting entropy, which might cause the random number generator to provide the same values after reboots on systems without an entropy source.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -128,9 +124,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hq9f-9pv4-876v/GHSA-hq9f-9pv4-876v.json b/advisories/unreviewed/2022/05/GHSA-hq9f-9pv4-876v/GHSA-hq9f-9pv4-876v.json index 39fd803bfcb..e3aa4a3b4d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-hq9f-9pv4-876v/GHSA-hq9f-9pv4-876v.json +++ b/advisories/unreviewed/2022/05/GHSA-hq9f-9pv4-876v/GHSA-hq9f-9pv4-876v.json @@ -7,12 +7,8 @@ "CVE-2007-2642" ], "details": "Directory traversal vulnerability in galeria.php in R2K Gallery 1.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang2 parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hqm7-3r56-4rr6/GHSA-hqm7-3r56-4rr6.json b/advisories/unreviewed/2022/05/GHSA-hqm7-3r56-4rr6/GHSA-hqm7-3r56-4rr6.json index aed02ba3c81..ca2a042e31f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqm7-3r56-4rr6/GHSA-hqm7-3r56-4rr6.json +++ b/advisories/unreviewed/2022/05/GHSA-hqm7-3r56-4rr6/GHSA-hqm7-3r56-4rr6.json @@ -7,12 +7,8 @@ "CVE-2007-2532" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Minh Nguyen Duong Obie Website Mini Web Shop 2 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) to (1) sendmail.php or (2) order_form.php, different vectors than CVE-2006-6734.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hrjq-v9hf-9f57/GHSA-hrjq-v9hf-9f57.json b/advisories/unreviewed/2022/05/GHSA-hrjq-v9hf-9f57/GHSA-hrjq-v9hf-9f57.json index 2beecce51a6..ce3dea20f6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrjq-v9hf-9f57/GHSA-hrjq-v9hf-9f57.json +++ b/advisories/unreviewed/2022/05/GHSA-hrjq-v9hf-9f57/GHSA-hrjq-v9hf-9f57.json @@ -7,12 +7,8 @@ "CVE-2007-2238" ], "details": "Multiple stack-based buffer overflows in the Whale Client Components ActiveX control (WhlMgr.dll), as used in Microsoft Intelligent Application Gateway (IAG) before 3.7 SP2, allow remote attackers to execute arbitrary code via long arguments to the (1) CheckForUpdates or (2) UpdateComponents methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hrm2-xm5m-6mfh/GHSA-hrm2-xm5m-6mfh.json b/advisories/unreviewed/2022/05/GHSA-hrm2-xm5m-6mfh/GHSA-hrm2-xm5m-6mfh.json index bd3f7463b81..340973b5605 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrm2-xm5m-6mfh/GHSA-hrm2-xm5m-6mfh.json +++ b/advisories/unreviewed/2022/05/GHSA-hrm2-xm5m-6mfh/GHSA-hrm2-xm5m-6mfh.json @@ -7,12 +7,8 @@ "CVE-2007-2293" ], "details": "Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 allow remote attackers to execute arbitrary code via a long (1) T38FaxRateManagement or (2) T38FaxUdpEC SDP parameter in an SIP message, as demonstrated using SIP INVITE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hvg7-4869-2r3w/GHSA-hvg7-4869-2r3w.json b/advisories/unreviewed/2022/05/GHSA-hvg7-4869-2r3w/GHSA-hvg7-4869-2r3w.json index 60ecc8377f2..f16279d6b9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvg7-4869-2r3w/GHSA-hvg7-4869-2r3w.json +++ b/advisories/unreviewed/2022/05/GHSA-hvg7-4869-2r3w/GHSA-hvg7-4869-2r3w.json @@ -7,12 +7,8 @@ "CVE-2007-2137" ], "details": "Heap-based buffer overflow in kde.dll in IBM Tivoli Monitoring Express 6.1.0 before Fix Pack 2, as used in Tivoli Universal Agent, Windows OS Monitoring agent, and Enterprise Portal Server, allows remote attackers to execute arbitrary code by sending a long string to a certain TCP port.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hvmv-gx83-pp3p/GHSA-hvmv-gx83-pp3p.json b/advisories/unreviewed/2022/05/GHSA-hvmv-gx83-pp3p/GHSA-hvmv-gx83-pp3p.json index eb98d7617f2..0639557a735 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvmv-gx83-pp3p/GHSA-hvmv-gx83-pp3p.json +++ b/advisories/unreviewed/2022/05/GHSA-hvmv-gx83-pp3p/GHSA-hvmv-gx83-pp3p.json @@ -7,12 +7,8 @@ "CVE-2007-2610" ], "details": "Cross-site scripting (XSS) vulnerability in OpenLD before 1.1.9, and 1.1-modified before 1.1-modified3, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the Search feature, possibly the term parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hvmw-63v6-mpv5/GHSA-hvmw-63v6-mpv5.json b/advisories/unreviewed/2022/05/GHSA-hvmw-63v6-mpv5/GHSA-hvmw-63v6-mpv5.json index 78b18ba2019..fb11334463a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvmw-63v6-mpv5/GHSA-hvmw-63v6-mpv5.json +++ b/advisories/unreviewed/2022/05/GHSA-hvmw-63v6-mpv5/GHSA-hvmw-63v6-mpv5.json @@ -7,12 +7,8 @@ "CVE-2007-2126" ], "details": "Unspecified vulnerability in Oracle E-Business Suite 11.5.10CU2 has unknown impact and remote attack vectors in the (1) Common Applications (APPS01) and (2) iProcurement (APPS02).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hx4p-j84q-ch4q/GHSA-hx4p-j84q-ch4q.json b/advisories/unreviewed/2022/05/GHSA-hx4p-j84q-ch4q/GHSA-hx4p-j84q-ch4q.json index 9a80690419e..c237fa33a19 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx4p-j84q-ch4q/GHSA-hx4p-j84q-ch4q.json +++ b/advisories/unreviewed/2022/05/GHSA-hx4p-j84q-ch4q/GHSA-hx4p-j84q-ch4q.json @@ -7,12 +7,8 @@ "CVE-2007-2343" ], "details": "Stack-based buffer overflow in the TFTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via crafted request packets that contain long file names.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hxvh-2v5v-v83v/GHSA-hxvh-2v5v-v83v.json b/advisories/unreviewed/2022/05/GHSA-hxvh-2v5v-v83v/GHSA-hxvh-2v5v-v83v.json index 9a80f2b4100..8ae9b78eac3 100644 --- a/advisories/unreviewed/2022/05/GHSA-hxvh-2v5v-v83v/GHSA-hxvh-2v5v-v83v.json +++ b/advisories/unreviewed/2022/05/GHSA-hxvh-2v5v-v83v/GHSA-hxvh-2v5v-v83v.json @@ -7,12 +7,8 @@ "CVE-2007-2370" ], "details": "SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a jobsview action. NOTE: the module name was originally reported as Job Listings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hxx6-rmq4-pmj6/GHSA-hxx6-rmq4-pmj6.json b/advisories/unreviewed/2022/05/GHSA-hxx6-rmq4-pmj6/GHSA-hxx6-rmq4-pmj6.json index 1d53b26efde..14f6fa86756 100644 --- a/advisories/unreviewed/2022/05/GHSA-hxx6-rmq4-pmj6/GHSA-hxx6-rmq4-pmj6.json +++ b/advisories/unreviewed/2022/05/GHSA-hxx6-rmq4-pmj6/GHSA-hxx6-rmq4-pmj6.json @@ -7,12 +7,8 @@ "CVE-2007-2336" ], "details": "Unspecified vulnerability in InterVations NaviCOPA Web Server 2.01 20070323 allows remote attackers to cause a denial of service (daemon crash) via crafted HTTP requests, as demonstrated by long requests containing '\\A' characters, probably a different issue than CVE-2006-5112 and CVE-2007-1733. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j427-f3h9-q6xj/GHSA-j427-f3h9-q6xj.json b/advisories/unreviewed/2022/05/GHSA-j427-f3h9-q6xj/GHSA-j427-f3h9-q6xj.json index 6f75dc107cf..014f925e165 100644 --- a/advisories/unreviewed/2022/05/GHSA-j427-f3h9-q6xj/GHSA-j427-f3h9-q6xj.json +++ b/advisories/unreviewed/2022/05/GHSA-j427-f3h9-q6xj/GHSA-j427-f3h9-q6xj.json @@ -7,12 +7,8 @@ "CVE-2007-2615" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Crie seu PHPLojaFacil 0.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the path_local parameter to (1) ftp.php, (2) libs/db.php, and (3) libs/ftp.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j44r-c574-p2hv/GHSA-j44r-c574-p2hv.json b/advisories/unreviewed/2022/05/GHSA-j44r-c574-p2hv/GHSA-j44r-c574-p2hv.json index 2d3216405e9..42a7b60f99c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j44r-c574-p2hv/GHSA-j44r-c574-p2hv.json +++ b/advisories/unreviewed/2022/05/GHSA-j44r-c574-p2hv/GHSA-j44r-c574-p2hv.json @@ -7,12 +7,8 @@ "CVE-2007-2233" ], "details": "cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (\\r) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j4c6-g9j4-3cc7/GHSA-j4c6-g9j4-3cc7.json b/advisories/unreviewed/2022/05/GHSA-j4c6-g9j4-3cc7/GHSA-j4c6-g9j4-3cc7.json index 66ac7d2011a..1233b5f460c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4c6-g9j4-3cc7/GHSA-j4c6-g9j4-3cc7.json +++ b/advisories/unreviewed/2022/05/GHSA-j4c6-g9j4-3cc7/GHSA-j4c6-g9j4-3cc7.json @@ -7,12 +7,8 @@ "CVE-2007-2662" ], "details": "SQL injection vulnerability in EfesTECH Haber 5.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to the top-level URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j4j9-pcm6-mm7w/GHSA-j4j9-pcm6-mm7w.json b/advisories/unreviewed/2022/05/GHSA-j4j9-pcm6-mm7w/GHSA-j4j9-pcm6-mm7w.json index e7cb252bd3d..7b80cafa429 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4j9-pcm6-mm7w/GHSA-j4j9-pcm6-mm7w.json +++ b/advisories/unreviewed/2022/05/GHSA-j4j9-pcm6-mm7w/GHSA-j4j9-pcm6-mm7w.json @@ -7,12 +7,8 @@ "CVE-2007-2179" ], "details": "Multiple unspecified vulnerabilities in IXceedCompression in XceddZipLib (RaidenFTPD.dll) in RaidenFTPD 2.4 allow remote attackers to cause a denial of service (crash) via unspecified vectors involving the (1) CalculateCrc, (2) Compress, and (3) Uncompress functions, which result in a NULL pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j5vw-526q-m7h7/GHSA-j5vw-526q-m7h7.json b/advisories/unreviewed/2022/05/GHSA-j5vw-526q-m7h7/GHSA-j5vw-526q-m7h7.json index e8188f3c9bb..3801249236c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5vw-526q-m7h7/GHSA-j5vw-526q-m7h7.json +++ b/advisories/unreviewed/2022/05/GHSA-j5vw-526q-m7h7/GHSA-j5vw-526q-m7h7.json @@ -7,12 +7,8 @@ "CVE-2007-2523" ], "details": "CA Anti-Virus for the Enterprise r8 and Threat Manager r8 before 20070510 use weak permissions (NULL security descriptor) for the Task Service shared file mapping, which allows local users to modify this mapping and gain privileges by triggering a stack-based buffer overflow in InoCore.dll before 8.0.448.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j5wg-388j-rrv5/GHSA-j5wg-388j-rrv5.json b/advisories/unreviewed/2022/05/GHSA-j5wg-388j-rrv5/GHSA-j5wg-388j-rrv5.json index 79ec123de4f..3934669439b 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5wg-388j-rrv5/GHSA-j5wg-388j-rrv5.json +++ b/advisories/unreviewed/2022/05/GHSA-j5wg-388j-rrv5/GHSA-j5wg-388j-rrv5.json @@ -7,12 +7,8 @@ "CVE-2007-2249" ], "details": "include/controlcenter/users.php in Phorum before 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_ids POST parameter or (2) userdata array.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j5wx-pm8j-mmcq/GHSA-j5wx-pm8j-mmcq.json b/advisories/unreviewed/2022/05/GHSA-j5wx-pm8j-mmcq/GHSA-j5wx-pm8j-mmcq.json index 90e29255a5f..494408aebcb 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5wx-pm8j-mmcq/GHSA-j5wx-pm8j-mmcq.json +++ b/advisories/unreviewed/2022/05/GHSA-j5wx-pm8j-mmcq/GHSA-j5wx-pm8j-mmcq.json @@ -7,12 +7,8 @@ "CVE-2007-2315" ], "details": "MiniShare 1.5.4, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a flood of requests for new connections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j62r-gh7r-3r6w/GHSA-j62r-gh7r-3r6w.json b/advisories/unreviewed/2022/05/GHSA-j62r-gh7r-3r6w/GHSA-j62r-gh7r-3r6w.json index 73d7eae3f35..73c0b829a7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j62r-gh7r-3r6w/GHSA-j62r-gh7r-3r6w.json +++ b/advisories/unreviewed/2022/05/GHSA-j62r-gh7r-3r6w/GHSA-j62r-gh7r-3r6w.json @@ -7,12 +7,8 @@ "CVE-2007-2617" ], "details": "srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file permissions when opening files, which allows local users to read the first line of arbitrary files via the -d and -v options.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j633-pqvg-fr89/GHSA-j633-pqvg-fr89.json b/advisories/unreviewed/2022/05/GHSA-j633-pqvg-fr89/GHSA-j633-pqvg-fr89.json index 055eeccc327..fe16ed9c3dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-j633-pqvg-fr89/GHSA-j633-pqvg-fr89.json +++ b/advisories/unreviewed/2022/05/GHSA-j633-pqvg-fr89/GHSA-j633-pqvg-fr89.json @@ -7,12 +7,8 @@ "CVE-2007-2666" ], "details": "Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attackers to execute arbitrary code via certain Ruby (.rb) files with long lines. NOTE: this was originally reported as a vulnerability in notepad++.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j693-mwv9-pgm6/GHSA-j693-mwv9-pgm6.json b/advisories/unreviewed/2022/05/GHSA-j693-mwv9-pgm6/GHSA-j693-mwv9-pgm6.json index ac71afdc79d..420399a3c3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-j693-mwv9-pgm6/GHSA-j693-mwv9-pgm6.json +++ b/advisories/unreviewed/2022/05/GHSA-j693-mwv9-pgm6/GHSA-j693-mwv9-pgm6.json @@ -7,12 +7,8 @@ "CVE-2007-2677" ], "details": "Multiple PHP remote file inclusion vulnerabilities in phpChess Community Edition 2.0 allow remote attackers to execute arbitrary PHP code via a URL in (1) the config parameter to includes/language.php, or the Root_Path parameter to (2) layout_admin_cfg.php, (3) layout_cfg.php, or (4) layout_t_top.php in skins/phpchess/. NOTE: vector 1 has been disputed by CVE, since the code is defined within a function that is not called from within includes/language.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j6q2-cg9j-qxq4/GHSA-j6q2-cg9j-qxq4.json b/advisories/unreviewed/2022/05/GHSA-j6q2-cg9j-qxq4/GHSA-j6q2-cg9j-qxq4.json index 0e5085e233a..1f42e2caa77 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6q2-cg9j-qxq4/GHSA-j6q2-cg9j-qxq4.json +++ b/advisories/unreviewed/2022/05/GHSA-j6q2-cg9j-qxq4/GHSA-j6q2-cg9j-qxq4.json @@ -7,12 +7,8 @@ "CVE-2007-2313" ], "details": "PHP remote file inclusion vulnerability in getinfo1.php in the Shotcast 1.0 RC2 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j82p-p2jg-jj2f/GHSA-j82p-p2jg-jj2f.json b/advisories/unreviewed/2022/05/GHSA-j82p-p2jg-jj2f/GHSA-j82p-p2jg-jj2f.json index 815744142f7..faa1bab3bc5 100644 --- a/advisories/unreviewed/2022/05/GHSA-j82p-p2jg-jj2f/GHSA-j82p-p2jg-jj2f.json +++ b/advisories/unreviewed/2022/05/GHSA-j82p-p2jg-jj2f/GHSA-j82p-p2jg-jj2f.json @@ -7,12 +7,8 @@ "CVE-2007-2437" ], "details": "The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to cause a denial of service (daemon crash) via crafted values to the (1) XRenderCompositeTrapezoids and (2) XRenderAddTraps functions, which trigger a divide-by-zero error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j863-r7c3-8m9h/GHSA-j863-r7c3-8m9h.json b/advisories/unreviewed/2022/05/GHSA-j863-r7c3-8m9h/GHSA-j863-r7c3-8m9h.json index 8a149aec30e..ca79a968142 100644 --- a/advisories/unreviewed/2022/05/GHSA-j863-r7c3-8m9h/GHSA-j863-r7c3-8m9h.json +++ b/advisories/unreviewed/2022/05/GHSA-j863-r7c3-8m9h/GHSA-j863-r7c3-8m9h.json @@ -7,12 +7,8 @@ "CVE-2007-2396" ], "details": "The JDirect support in QuickTime for Java in Apple Quicktime before 7.2 exposes certain dangerous interfaces, which allows remote attackers to execute arbitrary code via crafted Java applets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j8j6-m4fh-36gw/GHSA-j8j6-m4fh-36gw.json b/advisories/unreviewed/2022/05/GHSA-j8j6-m4fh-36gw/GHSA-j8j6-m4fh-36gw.json index 14b83276b9c..4c388e50eae 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8j6-m4fh-36gw/GHSA-j8j6-m4fh-36gw.json +++ b/advisories/unreviewed/2022/05/GHSA-j8j6-m4fh-36gw/GHSA-j8j6-m4fh-36gw.json @@ -7,12 +7,8 @@ "CVE-2007-1985" ], "details": "Multiple PHP remote file inclusion vulnerabilities in phpexplorator.php in phpexplorator 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) cmd or (2) lang_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j8vm-7jf8-5cqv/GHSA-j8vm-7jf8-5cqv.json b/advisories/unreviewed/2022/05/GHSA-j8vm-7jf8-5cqv/GHSA-j8vm-7jf8-5cqv.json index b741e981bd1..e08fd1f8aa1 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8vm-7jf8-5cqv/GHSA-j8vm-7jf8-5cqv.json +++ b/advisories/unreviewed/2022/05/GHSA-j8vm-7jf8-5cqv/GHSA-j8vm-7jf8-5cqv.json @@ -7,12 +7,8 @@ "CVE-2007-2202" ], "details": "PHP remote file inclusion vulnerability in inc_ACVS/SOAP/Transport.php in Accueil et Conseil en Visites et Sejours Web Services (ACVSWS) PHP5 (ACVSWS_PHP5) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the CheminInclude parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j9hq-mqc5-42vq/GHSA-j9hq-mqc5-42vq.json b/advisories/unreviewed/2022/05/GHSA-j9hq-mqc5-42vq/GHSA-j9hq-mqc5-42vq.json index 930ae896ae4..4f3d6716ecd 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9hq-mqc5-42vq/GHSA-j9hq-mqc5-42vq.json +++ b/advisories/unreviewed/2022/05/GHSA-j9hq-mqc5-42vq/GHSA-j9hq-mqc5-42vq.json @@ -7,12 +7,8 @@ "CVE-2007-2222" ], "details": "Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers memory corruption, as demonstrated via the ModeName parameter to the FindEngine function in ACTIVEVOICEPROJECTLib.DirectSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j9j7-g8mx-jx3c/GHSA-j9j7-g8mx-jx3c.json b/advisories/unreviewed/2022/05/GHSA-j9j7-g8mx-jx3c/GHSA-j9j7-g8mx-jx3c.json index 12dfd70f758..4bee82e73a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9j7-g8mx-jx3c/GHSA-j9j7-g8mx-jx3c.json +++ b/advisories/unreviewed/2022/05/GHSA-j9j7-g8mx-jx3c/GHSA-j9j7-g8mx-jx3c.json @@ -7,12 +7,8 @@ "CVE-2007-1982" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) __IncludeFilePHPClass, (2) __ClassPath, and (3) __class parameters to (a) rspa/framework/Controller_v5.php, and (b) rspa/framework/Controller_v4.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j9x7-2cqg-54fc/GHSA-j9x7-2cqg-54fc.json b/advisories/unreviewed/2022/05/GHSA-j9x7-2cqg-54fc/GHSA-j9x7-2cqg-54fc.json index a0ed769e350..4e2859751c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9x7-2cqg-54fc/GHSA-j9x7-2cqg-54fc.json +++ b/advisories/unreviewed/2022/05/GHSA-j9x7-2cqg-54fc/GHSA-j9x7-2cqg-54fc.json @@ -7,12 +7,8 @@ "CVE-2007-2528" ], "details": "Buffer overflow in AgRpcCln.dll for Trend Micro ServerProtect 5.58 for Windows before Security Patch 3 Build 1176 allows remote attackers to execute arbitrary code via unknown vectors related to RPC requests. NOTE: this is probably a different vulnerability than CVE-2007-2508.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jf9x-f8vv-jv8c/GHSA-jf9x-f8vv-jv8c.json b/advisories/unreviewed/2022/05/GHSA-jf9x-f8vv-jv8c/GHSA-jf9x-f8vv-jv8c.json index d2184a59e07..4a02dd5270b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf9x-f8vv-jv8c/GHSA-jf9x-f8vv-jv8c.json +++ b/advisories/unreviewed/2022/05/GHSA-jf9x-f8vv-jv8c/GHSA-jf9x-f8vv-jv8c.json @@ -7,12 +7,8 @@ "CVE-2007-2164" ], "details": "Konqueror 3.5.5 release 45.4 allows remote attackers to cause a denial of service (browser crash or abort) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jffc-8c3j-qfxw/GHSA-jffc-8c3j-qfxw.json b/advisories/unreviewed/2022/05/GHSA-jffc-8c3j-qfxw/GHSA-jffc-8c3j-qfxw.json index 06f285abbb2..140316417d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-jffc-8c3j-qfxw/GHSA-jffc-8c3j-qfxw.json +++ b/advisories/unreviewed/2022/05/GHSA-jffc-8c3j-qfxw/GHSA-jffc-8c3j-qfxw.json @@ -7,12 +7,8 @@ "CVE-2007-2333" ], "details": "Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 includes the FIPSecryptedtest1219 and FIPSunecryptedtest1219 default accounts in the LDAP template, which might allow remote attackers to access the private network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jfm8-h62j-3rpc/GHSA-jfm8-h62j-3rpc.json b/advisories/unreviewed/2022/05/GHSA-jfm8-h62j-3rpc/GHSA-jfm8-h62j-3rpc.json index f4375c01ae1..2e32f224b2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfm8-h62j-3rpc/GHSA-jfm8-h62j-3rpc.json +++ b/advisories/unreviewed/2022/05/GHSA-jfm8-h62j-3rpc/GHSA-jfm8-h62j-3rpc.json @@ -7,12 +7,8 @@ "CVE-2007-2369" ], "details": "Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jg22-m6v9-7rwj/GHSA-jg22-m6v9-7rwj.json b/advisories/unreviewed/2022/05/GHSA-jg22-m6v9-7rwj/GHSA-jg22-m6v9-7rwj.json index 713888198db..dedce179552 100644 --- a/advisories/unreviewed/2022/05/GHSA-jg22-m6v9-7rwj/GHSA-jg22-m6v9-7rwj.json +++ b/advisories/unreviewed/2022/05/GHSA-jg22-m6v9-7rwj/GHSA-jg22-m6v9-7rwj.json @@ -7,12 +7,8 @@ "CVE-2007-2554" ], "details": "Associated Press (AP) Newspower 4.0.1 and earlier uses a default blank password for the MySQL root account, which allows remote attackers to insert or modify news articles via shows.tblscript.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jghh-hwvc-hgv7/GHSA-jghh-hwvc-hgv7.json b/advisories/unreviewed/2022/05/GHSA-jghh-hwvc-hgv7/GHSA-jghh-hwvc-hgv7.json index e962bfc769c..c1c370c2e41 100644 --- a/advisories/unreviewed/2022/05/GHSA-jghh-hwvc-hgv7/GHSA-jghh-hwvc-hgv7.json +++ b/advisories/unreviewed/2022/05/GHSA-jghh-hwvc-hgv7/GHSA-jghh-hwvc-hgv7.json @@ -7,12 +7,8 @@ "CVE-2007-2492" ], "details": "SQL injection vulnerability in index.php in the v4bJournal module for PostNuke allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a journal_comment action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jh8j-hmrf-jm4h/GHSA-jh8j-hmrf-jm4h.json b/advisories/unreviewed/2022/05/GHSA-jh8j-hmrf-jm4h/GHSA-jh8j-hmrf-jm4h.json index 9c056c4c271..123df52ac4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jh8j-hmrf-jm4h/GHSA-jh8j-hmrf-jm4h.json +++ b/advisories/unreviewed/2022/05/GHSA-jh8j-hmrf-jm4h/GHSA-jh8j-hmrf-jm4h.json @@ -7,12 +7,8 @@ "CVE-2007-2320" ], "details": "SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL commands via the menuid parameter, a different vector than CVE-2005-4478.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jj7h-7pwq-mjvc/GHSA-jj7h-7pwq-mjvc.json b/advisories/unreviewed/2022/05/GHSA-jj7h-7pwq-mjvc/GHSA-jj7h-7pwq-mjvc.json index bcff8e3e673..cbcbcc1033e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jj7h-7pwq-mjvc/GHSA-jj7h-7pwq-mjvc.json +++ b/advisories/unreviewed/2022/05/GHSA-jj7h-7pwq-mjvc/GHSA-jj7h-7pwq-mjvc.json @@ -7,12 +7,8 @@ "CVE-2007-2191" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecified other SIP protocol fields, which are stored in /var/log/asterisk/full and displayed by admin/modules/logfiles/asterisk-full-log.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jjj9-qcp9-535g/GHSA-jjj9-qcp9-535g.json b/advisories/unreviewed/2022/05/GHSA-jjj9-qcp9-535g/GHSA-jjj9-qcp9-535g.json index 40bbbbad228..7f0efcb0fa2 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjj9-qcp9-535g/GHSA-jjj9-qcp9-535g.json +++ b/advisories/unreviewed/2022/05/GHSA-jjj9-qcp9-535g/GHSA-jjj9-qcp9-535g.json @@ -7,12 +7,8 @@ "CVE-2007-1964" ], "details": "member.php in MyBB (aka MyBulletinBoard), when debug mode is available, allows remote authenticated users to change the password of any account by providing the account's registered e-mail address in a debug request for a do_lostpw action, which prints the change password verification code in the debug output.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jjp5-x4p5-qff6/GHSA-jjp5-x4p5-qff6.json b/advisories/unreviewed/2022/05/GHSA-jjp5-x4p5-qff6/GHSA-jjp5-x4p5-qff6.json index bf3e2f07896..720c4b7ef27 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjp5-x4p5-qff6/GHSA-jjp5-x4p5-qff6.json +++ b/advisories/unreviewed/2022/05/GHSA-jjp5-x4p5-qff6/GHSA-jjp5-x4p5-qff6.json @@ -7,12 +7,8 @@ "CVE-2007-2214" ], "details": "Unrestricted file upload vulnerability in includes/upload_file.php in DmCMS allows remote attackers to upload arbitrary PHP scripts by placing a script's contents in both the File2 and File3 parameters, and sending a ok.php?do=act Referer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jjpj-fj74-73gv/GHSA-jjpj-fj74-73gv.json b/advisories/unreviewed/2022/05/GHSA-jjpj-fj74-73gv/GHSA-jjpj-fj74-73gv.json index 0a2141f383c..f19f7e40fcb 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjpj-fj74-73gv/GHSA-jjpj-fj74-73gv.json +++ b/advisories/unreviewed/2022/05/GHSA-jjpj-fj74-73gv/GHSA-jjpj-fj74-73gv.json @@ -7,12 +7,8 @@ "CVE-2007-2292" ], "details": "CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allows remote attackers to conduct HTTP request splitting attacks via LF (%0a) bytes in the username attribute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jp4q-w3xg-fqxv/GHSA-jp4q-w3xg-fqxv.json b/advisories/unreviewed/2022/05/GHSA-jp4q-w3xg-fqxv/GHSA-jp4q-w3xg-fqxv.json index b37f938e6ec..3dcd3d6301a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp4q-w3xg-fqxv/GHSA-jp4q-w3xg-fqxv.json +++ b/advisories/unreviewed/2022/05/GHSA-jp4q-w3xg-fqxv/GHSA-jp4q-w3xg-fqxv.json @@ -7,12 +7,8 @@ "CVE-2007-2208" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Extreme PHPBB2 3.0 Pre Final allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) functions.php or (2) functions_portal.php in includes/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jrc4-mg9p-mfr6/GHSA-jrc4-mg9p-mfr6.json b/advisories/unreviewed/2022/05/GHSA-jrc4-mg9p-mfr6/GHSA-jrc4-mg9p-mfr6.json index 0f28074d643..9bce0896156 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrc4-mg9p-mfr6/GHSA-jrc4-mg9p-mfr6.json +++ b/advisories/unreviewed/2022/05/GHSA-jrc4-mg9p-mfr6/GHSA-jrc4-mg9p-mfr6.json @@ -7,12 +7,8 @@ "CVE-2007-2133" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise Human Capital Management component in Oracle PeopleSoft Enterprise 8.9 has unknown impact and attack vectors, aka PSEHCM01.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jv2c-3p5q-6f75/GHSA-jv2c-3p5q-6f75.json b/advisories/unreviewed/2022/05/GHSA-jv2c-3p5q-6f75/GHSA-jv2c-3p5q-6f75.json index 204eed2452e..ccf97e2b827 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv2c-3p5q-6f75/GHSA-jv2c-3p5q-6f75.json +++ b/advisories/unreviewed/2022/05/GHSA-jv2c-3p5q-6f75/GHSA-jv2c-3p5q-6f75.json @@ -7,12 +7,8 @@ "CVE-2007-2162" ], "details": "(1) Mozilla Firefox 2.0.0.3 and (2) GNU IceWeasel 2.0.0.3 allow remote attackers to cause a denial of service (browser crash or system hang) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jv6m-h4m5-f426/GHSA-jv6m-h4m5-f426.json b/advisories/unreviewed/2022/05/GHSA-jv6m-h4m5-f426/GHSA-jv6m-h4m5-f426.json index d472bdbb8c6..64c94ff300f 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv6m-h4m5-f426/GHSA-jv6m-h4m5-f426.json +++ b/advisories/unreviewed/2022/05/GHSA-jv6m-h4m5-f426/GHSA-jv6m-h4m5-f426.json @@ -7,12 +7,8 @@ "CVE-2007-2407" ], "details": "The Samba server on Apple Mac OS X 10.3.9 and 10.4.10, when Windows file sharing is enabled, does not enforce disk quotas after dropping privileges, which allows remote authenticated users to use disk space in excess of quota.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jw6v-3c7m-938x/GHSA-jw6v-3c7m-938x.json b/advisories/unreviewed/2022/05/GHSA-jw6v-3c7m-938x/GHSA-jw6v-3c7m-938x.json index a573435a8aa..8f04b6527e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw6v-3c7m-938x/GHSA-jw6v-3c7m-938x.json +++ b/advisories/unreviewed/2022/05/GHSA-jw6v-3c7m-938x/GHSA-jw6v-3c7m-938x.json @@ -7,12 +7,8 @@ "CVE-2007-2241" ], "details": "Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5.0a3, when recursion is enabled, allows remote attackers to cause a denial of service (daemon exit) via a sequence of queries processed by the query_addsoa function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jwv4-h8g3-3qmm/GHSA-jwv4-h8g3-3qmm.json b/advisories/unreviewed/2022/05/GHSA-jwv4-h8g3-3qmm/GHSA-jwv4-h8g3-3qmm.json index 575e6875422..30c83e6b520 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwv4-h8g3-3qmm/GHSA-jwv4-h8g3-3qmm.json +++ b/advisories/unreviewed/2022/05/GHSA-jwv4-h8g3-3qmm/GHSA-jwv4-h8g3-3qmm.json @@ -7,12 +7,8 @@ "CVE-2007-2667" ], "details": "Buffer overflow in the DB Software Laboratory VImpX ActiveX control in VImpX.ocx 4.7.3 allows remote attackers to execute arbitrary code via a long LogFile parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jxcw-5f6w-xx32/GHSA-jxcw-5f6w-xx32.json b/advisories/unreviewed/2022/05/GHSA-jxcw-5f6w-xx32/GHSA-jxcw-5f6w-xx32.json index e1c6a104be4..f8b5a010743 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxcw-5f6w-xx32/GHSA-jxcw-5f6w-xx32.json +++ b/advisories/unreviewed/2022/05/GHSA-jxcw-5f6w-xx32/GHSA-jxcw-5f6w-xx32.json @@ -7,12 +7,8 @@ "CVE-2007-2360" ], "details": "Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore point images are configured, encrypt network share credentials with a key formed by a hash of the username, which allows local users to obtain the credentials by calculating the key.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m2c7-rvhj-fhcm/GHSA-m2c7-rvhj-fhcm.json b/advisories/unreviewed/2022/05/GHSA-m2c7-rvhj-fhcm/GHSA-m2c7-rvhj-fhcm.json index 5b700877318..3e5d7feb9f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2c7-rvhj-fhcm/GHSA-m2c7-rvhj-fhcm.json +++ b/advisories/unreviewed/2022/05/GHSA-m2c7-rvhj-fhcm/GHSA-m2c7-rvhj-fhcm.json @@ -7,12 +7,8 @@ "CVE-2007-2308" ], "details": "Cross-site scripting (XSS) vulnerability in cas.php in FloweRS 2.0 allows remote attackers to inject arbitrary web script or HTML via the rok parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m39x-x67c-c7wf/GHSA-m39x-x67c-c7wf.json b/advisories/unreviewed/2022/05/GHSA-m39x-x67c-c7wf/GHSA-m39x-x67c-c7wf.json index 4fdaf8194af..719ec8010f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-m39x-x67c-c7wf/GHSA-m39x-x67c-c7wf.json +++ b/advisories/unreviewed/2022/05/GHSA-m39x-x67c-c7wf/GHSA-m39x-x67c-c7wf.json @@ -7,12 +7,8 @@ "CVE-2007-2259" ], "details": "SQL injection vulnerability in forum.php in EsForum 3.0 allows remote attackers to execute arbitrary SQL commands via the idsalon parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m3f9-6m4r-6x2c/GHSA-m3f9-6m4r-6x2c.json b/advisories/unreviewed/2022/05/GHSA-m3f9-6m4r-6x2c/GHSA-m3f9-6m4r-6x2c.json index 5184af6710b..83be9608a0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3f9-6m4r-6x2c/GHSA-m3f9-6m4r-6x2c.json +++ b/advisories/unreviewed/2022/05/GHSA-m3f9-6m4r-6x2c/GHSA-m3f9-6m4r-6x2c.json @@ -7,12 +7,8 @@ "CVE-2007-2397" ], "details": "QuickTime for Java in Apple Quicktime before 7.2 does not properly check permissions, which allows remote attackers to disable security controls and execute arbitrary code via crafted Java applets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m3vc-4q6p-fwgq/GHSA-m3vc-4q6p-fwgq.json b/advisories/unreviewed/2022/05/GHSA-m3vc-4q6p-fwgq/GHSA-m3vc-4q6p-fwgq.json index 18a7737958c..60e677c0a26 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3vc-4q6p-fwgq/GHSA-m3vc-4q6p-fwgq.json +++ b/advisories/unreviewed/2022/05/GHSA-m3vc-4q6p-fwgq/GHSA-m3vc-4q6p-fwgq.json @@ -7,12 +7,8 @@ "CVE-2007-2253" ], "details": "Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrol.php and (2) sdk/blanks/file_modules.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m623-5pqp-69vm/GHSA-m623-5pqp-69vm.json b/advisories/unreviewed/2022/05/GHSA-m623-5pqp-69vm/GHSA-m623-5pqp-69vm.json index c902ded9fe2..1034b2bd2e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-m623-5pqp-69vm/GHSA-m623-5pqp-69vm.json +++ b/advisories/unreviewed/2022/05/GHSA-m623-5pqp-69vm/GHSA-m623-5pqp-69vm.json @@ -7,12 +7,8 @@ "CVE-2007-2616" ], "details": "Stack-based buffer overflow in the SSL version of the NMDMC.EXE service in Novell NetMail 3.52e FTF2 and probably earlier allows remote attackers to execute arbitrary code via a crafted request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m68f-9p4q-h53x/GHSA-m68f-9p4q-h53x.json b/advisories/unreviewed/2022/05/GHSA-m68f-9p4q-h53x/GHSA-m68f-9p4q-h53x.json index eb7af4ee7d3..01837da0f57 100644 --- a/advisories/unreviewed/2022/05/GHSA-m68f-9p4q-h53x/GHSA-m68f-9p4q-h53x.json +++ b/advisories/unreviewed/2022/05/GHSA-m68f-9p4q-h53x/GHSA-m68f-9p4q-h53x.json @@ -7,12 +7,8 @@ "CVE-2007-2184" ], "details": "Directory traversal vulnerability in imgsrv.php in jchit counter 1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the acc parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m6rp-qfpx-jwj7/GHSA-m6rp-qfpx-jwj7.json b/advisories/unreviewed/2022/05/GHSA-m6rp-qfpx-jwj7/GHSA-m6rp-qfpx-jwj7.json index 12b5afaeac7..6cff5790ab2 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6rp-qfpx-jwj7/GHSA-m6rp-qfpx-jwj7.json +++ b/advisories/unreviewed/2022/05/GHSA-m6rp-qfpx-jwj7/GHSA-m6rp-qfpx-jwj7.json @@ -7,12 +7,8 @@ "CVE-2007-2349" ], "details": "Cross-site scripting (XSS) vulnerability in Invision Power Board (IP.Board) 2.1.x and 2.2.x allows remote attackers to inject arbitrary web script or HTML by uploading crafted images or PDF files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m74q-f67v-r8xx/GHSA-m74q-f67v-r8xx.json b/advisories/unreviewed/2022/05/GHSA-m74q-f67v-r8xx/GHSA-m74q-f67v-r8xx.json index 69a80b97ce5..4e45e0ac4b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-m74q-f67v-r8xx/GHSA-m74q-f67v-r8xx.json +++ b/advisories/unreviewed/2022/05/GHSA-m74q-f67v-r8xx/GHSA-m74q-f67v-r8xx.json @@ -7,12 +7,8 @@ "CVE-2007-2351" ], "details": "Unspecified vulnerability in the HP Power Manager Remote Agent (RA) 4.0Build10 and earlier in HP-UX B.11.11 and B.11.23 allows local users to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m7pv-hqh5-6gm8/GHSA-m7pv-hqh5-6gm8.json b/advisories/unreviewed/2022/05/GHSA-m7pv-hqh5-6gm8/GHSA-m7pv-hqh5-6gm8.json index c687038f424..3f2f367a930 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7pv-hqh5-6gm8/GHSA-m7pv-hqh5-6gm8.json +++ b/advisories/unreviewed/2022/05/GHSA-m7pv-hqh5-6gm8/GHSA-m7pv-hqh5-6gm8.json @@ -7,12 +7,8 @@ "CVE-2007-2345" ], "details": "PHP remote file inclusion vulnerability in include/include_stream.inc.php in CodeWand phpBrowse allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m7rm-76f9-7g7j/GHSA-m7rm-76f9-7g7j.json b/advisories/unreviewed/2022/05/GHSA-m7rm-76f9-7g7j/GHSA-m7rm-76f9-7g7j.json index a9232065871..709eef544e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7rm-76f9-7g7j/GHSA-m7rm-76f9-7g7j.json +++ b/advisories/unreviewed/2022/05/GHSA-m7rm-76f9-7g7j/GHSA-m7rm-76f9-7g7j.json @@ -7,12 +7,8 @@ "CVE-2007-2631" ], "details": "Cross-site request forgery (CSRF) vulnerability in SquirrelMail 1.4.8-4.fc6 and earlier allows remote attackers to perform unspecified actions as arbitrary users via unspecified vectors. NOTE: this issue might overlap CVE-2007-2589 or CVE-2002-1648.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m86q-m239-j5q7/GHSA-m86q-m239-j5q7.json b/advisories/unreviewed/2022/05/GHSA-m86q-m239-j5q7/GHSA-m86q-m239-j5q7.json index fec1253ca1a..8f9700e9cda 100644 --- a/advisories/unreviewed/2022/05/GHSA-m86q-m239-j5q7/GHSA-m86q-m239-j5q7.json +++ b/advisories/unreviewed/2022/05/GHSA-m86q-m239-j5q7/GHSA-m86q-m239-j5q7.json @@ -7,12 +7,8 @@ "CVE-2007-2295" ], "details": "Heap-based buffer overflow in the JVTCompEncodeFrame function in Apple Quicktime 7.1.5 and other versions before 7.2 allows remote attackers to execute arbitrary code via a crafted H.264 MOV file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m8v7-79j6-gf3v/GHSA-m8v7-79j6-gf3v.json b/advisories/unreviewed/2022/05/GHSA-m8v7-79j6-gf3v/GHSA-m8v7-79j6-gf3v.json index d661d5525ca..2ff16e23004 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8v7-79j6-gf3v/GHSA-m8v7-79j6-gf3v.json +++ b/advisories/unreviewed/2022/05/GHSA-m8v7-79j6-gf3v/GHSA-m8v7-79j6-gf3v.json @@ -7,12 +7,8 @@ "CVE-2007-2150" ], "details": "BlueArc-FTPD in BlueArc Titan 2x00 devices with firmware 4.2.944b allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command, a variant of CVE-1999-0017.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m9mf-c2gx-w7pp/GHSA-m9mf-c2gx-w7pp.json b/advisories/unreviewed/2022/05/GHSA-m9mf-c2gx-w7pp/GHSA-m9mf-c2gx-w7pp.json index c50d96e0cc3..6733fb9d017 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9mf-c2gx-w7pp/GHSA-m9mf-c2gx-w7pp.json +++ b/advisories/unreviewed/2022/05/GHSA-m9mf-c2gx-w7pp/GHSA-m9mf-c2gx-w7pp.json @@ -7,12 +7,8 @@ "CVE-2007-2260" ], "details": "Multiple PHP remote file inclusion vulnerabilities in bibtex mase beta 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the bibtexrootrel parameter to (1) unavailable.php, (2) source.php, (3) log.php, (4) latex.php, (5) indexinfo.php, (6) index.php, (7) importinfo.php, (8) import.php, (9) examplefile.php, (10) clearinfo.php, (11) clear.php, (12) aboutinfo.php, (13) about.php, and other unspecified files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mcfj-6fcp-4c64/GHSA-mcfj-6fcp-4c64.json b/advisories/unreviewed/2022/05/GHSA-mcfj-6fcp-4c64/GHSA-mcfj-6fcp-4c64.json index bc5207003f7..f0c47dd7cc6 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcfj-6fcp-4c64/GHSA-mcfj-6fcp-4c64.json +++ b/advisories/unreviewed/2022/05/GHSA-mcfj-6fcp-4c64/GHSA-mcfj-6fcp-4c64.json @@ -7,12 +7,8 @@ "CVE-2007-2177" ], "details": "Stack-based buffer overflow in the Microgaming Download Helper ActiveX control (dlhelper.dll) before 7.2.0.19, and the WebHandler Class control, allows remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mcfq-88hw-mrc4/GHSA-mcfq-88hw-mrc4.json b/advisories/unreviewed/2022/05/GHSA-mcfq-88hw-mrc4/GHSA-mcfq-88hw-mrc4.json index 0e96296e376..1bddb5524db 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcfq-88hw-mrc4/GHSA-mcfq-88hw-mrc4.json +++ b/advisories/unreviewed/2022/05/GHSA-mcfq-88hw-mrc4/GHSA-mcfq-88hw-mrc4.json @@ -7,12 +7,8 @@ "CVE-2007-2638" ], "details": "eFileCabinet 3.3 allows remote attackers to bypass authentication and access restricted portions of the interface via an invalid filecabinetnumber, which can be leveraged to obtain sensitive information or create new data structures.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mcfx-m3pc-p797/GHSA-mcfx-m3pc-p797.json b/advisories/unreviewed/2022/05/GHSA-mcfx-m3pc-p797/GHSA-mcfx-m3pc-p797.json index ebfe206d8df..27ecb8b835d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcfx-m3pc-p797/GHSA-mcfx-m3pc-p797.json +++ b/advisories/unreviewed/2022/05/GHSA-mcfx-m3pc-p797/GHSA-mcfx-m3pc-p797.json @@ -7,12 +7,8 @@ "CVE-2007-2490" ], "details": "Unspecified vulnerability in LiveData Server before 5.00.62 allows remote attackers to cause a denial of service (exit) via crafted Connection-Oriented Transport Protocol (COTP) packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mf24-5gmm-wmj9/GHSA-mf24-5gmm-wmj9.json b/advisories/unreviewed/2022/05/GHSA-mf24-5gmm-wmj9/GHSA-mf24-5gmm-wmj9.json index f9e700ac386..d03a686d55e 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf24-5gmm-wmj9/GHSA-mf24-5gmm-wmj9.json +++ b/advisories/unreviewed/2022/05/GHSA-mf24-5gmm-wmj9/GHSA-mf24-5gmm-wmj9.json @@ -7,12 +7,8 @@ "CVE-2007-2328" ], "details": "PHP remote file inclusion vulnerability in addvip.php in phpMYTGP 1.4b allows remote attackers to execute arbitrary PHP code via a URL in the msetstr[PROGSDIR] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mg8p-xrp5-m4fh/GHSA-mg8p-xrp5-m4fh.json b/advisories/unreviewed/2022/05/GHSA-mg8p-xrp5-m4fh/GHSA-mg8p-xrp5-m4fh.json index 19fc5cb332c..749e30ca8d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-mg8p-xrp5-m4fh/GHSA-mg8p-xrp5-m4fh.json +++ b/advisories/unreviewed/2022/05/GHSA-mg8p-xrp5-m4fh/GHSA-mg8p-xrp5-m4fh.json @@ -7,12 +7,8 @@ "CVE-2007-2270" ], "details": "The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) character in the From header, and possibly certain other locations, in a SIP INVITE request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mgpj-7m2g-h43r/GHSA-mgpj-7m2g-h43r.json b/advisories/unreviewed/2022/05/GHSA-mgpj-7m2g-h43r/GHSA-mgpj-7m2g-h43r.json index e2587478e3c..c1e5f8f82f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgpj-7m2g-h43r/GHSA-mgpj-7m2g-h43r.json +++ b/advisories/unreviewed/2022/05/GHSA-mgpj-7m2g-h43r/GHSA-mgpj-7m2g-h43r.json @@ -7,12 +7,8 @@ "CVE-2007-2655" ], "details": "Unspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a format string vulnerability that allows remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mhmc-6rv6-c2f9/GHSA-mhmc-6rv6-c2f9.json b/advisories/unreviewed/2022/05/GHSA-mhmc-6rv6-c2f9/GHSA-mhmc-6rv6-c2f9.json index 9772df88af8..4c1e0f2b39f 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhmc-6rv6-c2f9/GHSA-mhmc-6rv6-c2f9.json +++ b/advisories/unreviewed/2022/05/GHSA-mhmc-6rv6-c2f9/GHSA-mhmc-6rv6-c2f9.json @@ -7,12 +7,8 @@ "CVE-2007-2552" ], "details": "The RecentChanges feature in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to obtain the names, and possibly revision notes and dates, of private pages via RSS feeds.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mhv3-h4q9-c5v3/GHSA-mhv3-h4q9-c5v3.json b/advisories/unreviewed/2022/05/GHSA-mhv3-h4q9-c5v3/GHSA-mhv3-h4q9-c5v3.json index a9f2dc995c9..bb42d197d36 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhv3-h4q9-c5v3/GHSA-mhv3-h4q9-c5v3.json +++ b/advisories/unreviewed/2022/05/GHSA-mhv3-h4q9-c5v3/GHSA-mhv3-h4q9-c5v3.json @@ -7,12 +7,8 @@ "CVE-2007-2169" ], "details": "Static code injection vulnerability in add.php in Mozzers SubSystem 1.0 allows remote attackers to inject PHP code into subs.php via the (1) Sub-name or (2) Sub-url field. NOTE: an earlier report indicated that the add action can be reached through a request to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mjp7-jvwp-6467/GHSA-mjp7-jvwp-6467.json b/advisories/unreviewed/2022/05/GHSA-mjp7-jvwp-6467/GHSA-mjp7-jvwp-6467.json index 0054d4ece7f..529ac3adcb8 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjp7-jvwp-6467/GHSA-mjp7-jvwp-6467.json +++ b/advisories/unreviewed/2022/05/GHSA-mjp7-jvwp-6467/GHSA-mjp7-jvwp-6467.json @@ -7,12 +7,8 @@ "CVE-2007-2494" ], "details": "Multiple stack-based buffer overflows in the PowerPointOCX ActiveX control in PowerPointViewer.ocx 3.1.0.3 allow remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) Save, (6) SaveWebFile, (7) HttpDownloadFile, (8) Open, or (9) OpenWebFile property value. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mpgw-4rqw-9638/GHSA-mpgw-4rqw-9638.json b/advisories/unreviewed/2022/05/GHSA-mpgw-4rqw-9638/GHSA-mpgw-4rqw-9638.json index c068cd4b452..55c1f6c1862 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpgw-4rqw-9638/GHSA-mpgw-4rqw-9638.json +++ b/advisories/unreviewed/2022/05/GHSA-mpgw-4rqw-9638/GHSA-mpgw-4rqw-9638.json @@ -7,12 +7,8 @@ "CVE-2007-2507" ], "details": "Directory traversal vulnerability in includes/download.php in Treble Designs 1024 CMS 0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the item parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mpp5-3g49-3p3w/GHSA-mpp5-3g49-3p3w.json b/advisories/unreviewed/2022/05/GHSA-mpp5-3g49-3p3w/GHSA-mpp5-3g49-3p3w.json index 5e8f18c57a7..ea021211dbc 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpp5-3g49-3p3w/GHSA-mpp5-3g49-3p3w.json +++ b/advisories/unreviewed/2022/05/GHSA-mpp5-3g49-3p3w/GHSA-mpp5-3g49-3p3w.json @@ -7,12 +7,8 @@ "CVE-2007-2401" ], "details": "CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing headers via the setRequestHeader function. NOTE: this issue can be leveraged for cross-site scripting (XSS) attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mr3f-crc3-c6gx/GHSA-mr3f-crc3-c6gx.json b/advisories/unreviewed/2022/05/GHSA-mr3f-crc3-c6gx/GHSA-mr3f-crc3-c6gx.json index bb42ff9cbd1..6da7ce28b1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mr3f-crc3-c6gx/GHSA-mr3f-crc3-c6gx.json +++ b/advisories/unreviewed/2022/05/GHSA-mr3f-crc3-c6gx/GHSA-mr3f-crc3-c6gx.json @@ -7,12 +7,8 @@ "CVE-2007-2570" ], "details": "PHP remote file inclusion vulnerability in handlers/page/show.php in Wikivi5 allows remote attackers to execute arbitrary PHP code via a URL in the sous_rep parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mr7c-fpg4-36pw/GHSA-mr7c-fpg4-36pw.json b/advisories/unreviewed/2022/05/GHSA-mr7c-fpg4-36pw/GHSA-mr7c-fpg4-36pw.json index 6ba09b3798e..5e86a748caa 100644 --- a/advisories/unreviewed/2022/05/GHSA-mr7c-fpg4-36pw/GHSA-mr7c-fpg4-36pw.json +++ b/advisories/unreviewed/2022/05/GHSA-mr7c-fpg4-36pw/GHSA-mr7c-fpg4-36pw.json @@ -7,12 +7,8 @@ "CVE-2007-2628" ], "details": "PHP remote file inclusion vulnerability in include/logout.php in Justin Koivisto SecurityAdmin for PHP (aka PHPSecurityAdmin, PSA) 4.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the PSA_PATH parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mrfq-vp5m-vgh8/GHSA-mrfq-vp5m-vgh8.json b/advisories/unreviewed/2022/05/GHSA-mrfq-vp5m-vgh8/GHSA-mrfq-vp5m-vgh8.json index 0fd8c6f2dce..9c9da0a5582 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrfq-vp5m-vgh8/GHSA-mrfq-vp5m-vgh8.json +++ b/advisories/unreviewed/2022/05/GHSA-mrfq-vp5m-vgh8/GHSA-mrfq-vp5m-vgh8.json @@ -7,12 +7,8 @@ "CVE-2007-2347" ], "details": "PHP remote file inclusion vulnerability in main/forum/komentar.php in OneClick CMS (aka Sisplet CMS) 05.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mx9x-v3ff-m9c3/GHSA-mx9x-v3ff-m9c3.json b/advisories/unreviewed/2022/05/GHSA-mx9x-v3ff-m9c3/GHSA-mx9x-v3ff-m9c3.json index 794c1c7583b..869f4740054 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx9x-v3ff-m9c3/GHSA-mx9x-v3ff-m9c3.json +++ b/advisories/unreviewed/2022/05/GHSA-mx9x-v3ff-m9c3/GHSA-mx9x-v3ff-m9c3.json @@ -7,12 +7,8 @@ "CVE-2007-2192" ], "details": "Buffer overflow in Photofiltre Studio 8.1.1 allows user-assisted remote attackers to execute arbitrary code via a crafted .tif file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mxhv-qqm4-rmgv/GHSA-mxhv-qqm4-rmgv.json b/advisories/unreviewed/2022/05/GHSA-mxhv-qqm4-rmgv/GHSA-mxhv-qqm4-rmgv.json index 27431904d2b..2fbbd1d2227 100644 --- a/advisories/unreviewed/2022/05/GHSA-mxhv-qqm4-rmgv/GHSA-mxhv-qqm4-rmgv.json +++ b/advisories/unreviewed/2022/05/GHSA-mxhv-qqm4-rmgv/GHSA-mxhv-qqm4-rmgv.json @@ -7,12 +7,8 @@ "CVE-2007-2361" ], "details": "Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore points images are configured, uses weak permissions (world readable) for a configuration file with network share credentials, which allows local users to obtain the credentials by reading the file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mxmv-pjj2-646c/GHSA-mxmv-pjj2-646c.json b/advisories/unreviewed/2022/05/GHSA-mxmv-pjj2-646c/GHSA-mxmv-pjj2-646c.json index 827fa997379..6163ce6bd61 100644 --- a/advisories/unreviewed/2022/05/GHSA-mxmv-pjj2-646c/GHSA-mxmv-pjj2-646c.json +++ b/advisories/unreviewed/2022/05/GHSA-mxmv-pjj2-646c/GHSA-mxmv-pjj2-646c.json @@ -7,12 +7,8 @@ "CVE-2007-2410" ], "details": "WebCore on Apple Mac OS X 10.3.9 and 10.4.10 retains properties of certain global objects when a new URL is visited in the same window, which allows remote attackers to conduct cross-site scripting (XSS) attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p2ch-5xfx-q36f/GHSA-p2ch-5xfx-q36f.json b/advisories/unreviewed/2022/05/GHSA-p2ch-5xfx-q36f/GHSA-p2ch-5xfx-q36f.json index 8b2864b69fc..123252f3a87 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2ch-5xfx-q36f/GHSA-p2ch-5xfx-q36f.json +++ b/advisories/unreviewed/2022/05/GHSA-p2ch-5xfx-q36f/GHSA-p2ch-5xfx-q36f.json @@ -7,12 +7,8 @@ "CVE-2007-2178" ], "details": "Multiple unspecified vulnerabilities in Objective Development Sharity before 3.3 allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p2r3-9xrf-64q4/GHSA-p2r3-9xrf-64q4.json b/advisories/unreviewed/2022/05/GHSA-p2r3-9xrf-64q4/GHSA-p2r3-9xrf-64q4.json index f6509d2bcff..ccc88095c01 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2r3-9xrf-64q4/GHSA-p2r3-9xrf-64q4.json +++ b/advisories/unreviewed/2022/05/GHSA-p2r3-9xrf-64q4/GHSA-p2r3-9xrf-64q4.json @@ -7,12 +7,8 @@ "CVE-2007-2474" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) include/payment/payflow_pro.php, (2) global.php, or (3) libsecure.php, different vectors than CVE-2007-2070.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p3h3-f734-pmm9/GHSA-p3h3-f734-pmm9.json b/advisories/unreviewed/2022/05/GHSA-p3h3-f734-pmm9/GHSA-p3h3-f734-pmm9.json index 0763ed854e1..8c2b7fa44ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3h3-f734-pmm9/GHSA-p3h3-f734-pmm9.json +++ b/advisories/unreviewed/2022/05/GHSA-p3h3-f734-pmm9/GHSA-p3h3-f734-pmm9.json @@ -7,12 +7,8 @@ "CVE-2007-2569" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Friendly 1.0d1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the friendly_path parameter to (1) core/data/yaml.inc.php, or _load.php in (2) core/data/, (3) core/display/, or (4) core/support/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p3pj-frvc-gch9/GHSA-p3pj-frvc-gch9.json b/advisories/unreviewed/2022/05/GHSA-p3pj-frvc-gch9/GHSA-p3pj-frvc-gch9.json index d38647c9983..b268f8da802 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3pj-frvc-gch9/GHSA-p3pj-frvc-gch9.json +++ b/advisories/unreviewed/2022/05/GHSA-p3pj-frvc-gch9/GHSA-p3pj-frvc-gch9.json @@ -7,12 +7,8 @@ "CVE-2007-2680" ], "details": "Cross-site scripting (XSS) vulnerability in the management interface in Canon Network Camera Server VB100 and VB101 with firmware 3.0 R69 and earlier, and VB150 with firmware 1.1 R39 and earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p522-c4h9-c8rw/GHSA-p522-c4h9-c8rw.json b/advisories/unreviewed/2022/05/GHSA-p522-c4h9-c8rw/GHSA-p522-c4h9-c8rw.json index f3d59a0f7a6..a7861773197 100644 --- a/advisories/unreviewed/2022/05/GHSA-p522-c4h9-c8rw/GHSA-p522-c4h9-c8rw.json +++ b/advisories/unreviewed/2022/05/GHSA-p522-c4h9-c8rw/GHSA-p522-c4h9-c8rw.json @@ -7,12 +7,8 @@ "CVE-2007-1980" ], "details": "SQL injection vulnerability in index.php in the Topliste 1.0 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the cid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p592-g5c7-x7w6/GHSA-p592-g5c7-x7w6.json b/advisories/unreviewed/2022/05/GHSA-p592-g5c7-x7w6/GHSA-p592-g5c7-x7w6.json index 74480e48e08..5189d4d6d55 100644 --- a/advisories/unreviewed/2022/05/GHSA-p592-g5c7-x7w6/GHSA-p592-g5c7-x7w6.json +++ b/advisories/unreviewed/2022/05/GHSA-p592-g5c7-x7w6/GHSA-p592-g5c7-x7w6.json @@ -7,12 +7,8 @@ "CVE-2007-1997" ], "details": "Integer signedness error in the (1) cab_unstore and (2) cab_extract functions in libclamav/cab.c in Clam AntiVirus (ClamAV) before 0.90.2 allow remote attackers to execute arbitrary code via a crafted CHM file that contains a negative integer, which passes a signed comparison and leads to a stack-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -112,9 +108,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p5mx-m79g-73hx/GHSA-p5mx-m79g-73hx.json b/advisories/unreviewed/2022/05/GHSA-p5mx-m79g-73hx/GHSA-p5mx-m79g-73hx.json index 66fe47c6a9b..a3046a2cfba 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5mx-m79g-73hx/GHSA-p5mx-m79g-73hx.json +++ b/advisories/unreviewed/2022/05/GHSA-p5mx-m79g-73hx/GHSA-p5mx-m79g-73hx.json @@ -7,12 +7,8 @@ "CVE-2007-2243" ], "details": "OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p5qw-rrm8-hxfg/GHSA-p5qw-rrm8-hxfg.json b/advisories/unreviewed/2022/05/GHSA-p5qw-rrm8-hxfg/GHSA-p5qw-rrm8-hxfg.json index e2fea7cb079..c9a3799369b 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5qw-rrm8-hxfg/GHSA-p5qw-rrm8-hxfg.json +++ b/advisories/unreviewed/2022/05/GHSA-p5qw-rrm8-hxfg/GHSA-p5qw-rrm8-hxfg.json @@ -7,12 +7,8 @@ "CVE-2007-2649" ], "details": "Deutsche Telekom (T-com) Speedport W 700v uses JavaScript delays for invalid authentication attempts to the CGI script, which allows remote attackers to bypass the delays and conduct brute-force attacks via direct calls to the authentication CGI script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p6rq-hc9w-gm4m/GHSA-p6rq-hc9w-gm4m.json b/advisories/unreviewed/2022/05/GHSA-p6rq-hc9w-gm4m/GHSA-p6rq-hc9w-gm4m.json index b7e71f879b6..37c0d73f5fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6rq-hc9w-gm4m/GHSA-p6rq-hc9w-gm4m.json +++ b/advisories/unreviewed/2022/05/GHSA-p6rq-hc9w-gm4m/GHSA-p6rq-hc9w-gm4m.json @@ -7,12 +7,8 @@ "CVE-2007-2511" ], "details": "Buffer overflow in the user_filter_factory_create function in PHP before 5.2.2 has unknown impact and local attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p6x4-678w-q6rq/GHSA-p6x4-678w-q6rq.json b/advisories/unreviewed/2022/05/GHSA-p6x4-678w-q6rq/GHSA-p6x4-678w-q6rq.json index cf119e42701..1b283b0d6a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6x4-678w-q6rq/GHSA-p6x4-678w-q6rq.json +++ b/advisories/unreviewed/2022/05/GHSA-p6x4-678w-q6rq/GHSA-p6x4-678w-q6rq.json @@ -7,12 +7,8 @@ "CVE-2007-2216" ], "details": "The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation, which allows remote attackers to execute arbitrary code by requesting the HelpString property, involving a crafted DLL file argument to the TypeLibInfoFromFile function, which overwrites the HelpStringDll property to call the DLLGetDocumentation function in another DLL file, aka \"ActiveX Object Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p7x2-95q8-393h/GHSA-p7x2-95q8-393h.json b/advisories/unreviewed/2022/05/GHSA-p7x2-95q8-393h/GHSA-p7x2-95q8-393h.json index b9b30735e15..82d766c0707 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7x2-95q8-393h/GHSA-p7x2-95q8-393h.json +++ b/advisories/unreviewed/2022/05/GHSA-p7x2-95q8-393h/GHSA-p7x2-95q8-393h.json @@ -7,12 +7,8 @@ "CVE-2007-2588" ], "details": "Multiple buffer overflows in the Office Viewer OCX ActiveX control (oa.ocx) 3.2 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long argument to the (1) HttpDownloadFile, (2) Open, (3) OpenWebFile, (4) DoOleCommand, (5) FTPDownloadFile, (6) FTPUploadFile, (7) HttpUploadFile, (8) Save, or (9) SaveWebFile function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p8jx-5489-g4q8/GHSA-p8jx-5489-g4q8.json b/advisories/unreviewed/2022/05/GHSA-p8jx-5489-g4q8/GHSA-p8jx-5489-g4q8.json index c76047854b5..8c077cd8360 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8jx-5489-g4q8/GHSA-p8jx-5489-g4q8.json +++ b/advisories/unreviewed/2022/05/GHSA-p8jx-5489-g4q8/GHSA-p8jx-5489-g4q8.json @@ -7,12 +7,8 @@ "CVE-2007-1994" ], "details": "Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.00 allows local users to cause a denial of service via unknown vectors. NOTE: due to lack of vendor details, it is not clear whether this is the same as CVE-2007-0916.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p8xw-m97m-vrf2/GHSA-p8xw-m97m-vrf2.json b/advisories/unreviewed/2022/05/GHSA-p8xw-m97m-vrf2/GHSA-p8xw-m97m-vrf2.json index 3825510d706..85d7e014196 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8xw-m97m-vrf2/GHSA-p8xw-m97m-vrf2.json +++ b/advisories/unreviewed/2022/05/GHSA-p8xw-m97m-vrf2/GHSA-p8xw-m97m-vrf2.json @@ -7,12 +7,8 @@ "CVE-2007-2417" ], "details": "Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager 6.0 and 6.1, SecurID Appliance 2.0, ACE/Server 5.2, and possibly other products, allows remote attackers to execute arbitrary code via crafted packets. NOTE: this issue might overlap CVE-2007-3491.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p9rq-xc33-gv5r/GHSA-p9rq-xc33-gv5r.json b/advisories/unreviewed/2022/05/GHSA-p9rq-xc33-gv5r/GHSA-p9rq-xc33-gv5r.json index 506b58dc201..529f6fed63a 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9rq-xc33-gv5r/GHSA-p9rq-xc33-gv5r.json +++ b/advisories/unreviewed/2022/05/GHSA-p9rq-xc33-gv5r/GHSA-p9rq-xc33-gv5r.json @@ -7,12 +7,8 @@ "CVE-2007-2478" ], "details": "Multiple heap-based buffer overflows in the IRC component in Cerulean Studios Trillian Pro before 3.1.5.1 allow remote attackers to corrupt memory and possibly execute arbitrary code via (1) a URL with a long UTF-8 string, which triggers the overflow when the user highlights it, or (2) a font HTML tag with a face attribute containing a long UTF-8 string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pf54-q886-7rw3/GHSA-pf54-q886-7rw3.json b/advisories/unreviewed/2022/05/GHSA-pf54-q886-7rw3/GHSA-pf54-q886-7rw3.json index 790a57dab86..bc9d1eac5db 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf54-q886-7rw3/GHSA-pf54-q886-7rw3.json +++ b/advisories/unreviewed/2022/05/GHSA-pf54-q886-7rw3/GHSA-pf54-q886-7rw3.json @@ -7,12 +7,8 @@ "CVE-2007-2140" ], "details": "PHP remote file inclusion vulnerability in everything.php in Franklin Huang Flip (aka Flip-search-add-on) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the incpath parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pfc6-8rc2-mpvv/GHSA-pfc6-8rc2-mpvv.json b/advisories/unreviewed/2022/05/GHSA-pfc6-8rc2-mpvv/GHSA-pfc6-8rc2-mpvv.json index 941f633e842..b6f3d897a79 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfc6-8rc2-mpvv/GHSA-pfc6-8rc2-mpvv.json +++ b/advisories/unreviewed/2022/05/GHSA-pfc6-8rc2-mpvv/GHSA-pfc6-8rc2-mpvv.json @@ -7,12 +7,8 @@ "CVE-2007-2380" ], "details": "The Microsoft Atlas framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka \"JavaScript Hijacking.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ph99-jr94-mp8m/GHSA-ph99-jr94-mp8m.json b/advisories/unreviewed/2022/05/GHSA-ph99-jr94-mp8m/GHSA-ph99-jr94-mp8m.json index f54071c3ff9..86b794b1eef 100644 --- a/advisories/unreviewed/2022/05/GHSA-ph99-jr94-mp8m/GHSA-ph99-jr94-mp8m.json +++ b/advisories/unreviewed/2022/05/GHSA-ph99-jr94-mp8m/GHSA-ph99-jr94-mp8m.json @@ -7,12 +7,8 @@ "CVE-2007-2482" ], "details": "Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the wpPATH parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pmm6-hpj2-3r8h/GHSA-pmm6-hpj2-3r8h.json b/advisories/unreviewed/2022/05/GHSA-pmm6-hpj2-3r8h/GHSA-pmm6-hpj2-3r8h.json index c407281f5c8..85aaca355a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmm6-hpj2-3r8h/GHSA-pmm6-hpj2-3r8h.json +++ b/advisories/unreviewed/2022/05/GHSA-pmm6-hpj2-3r8h/GHSA-pmm6-hpj2-3r8h.json @@ -7,12 +7,8 @@ "CVE-2007-2460" ], "details": "PHP remote file inclusion vulnerability in modules/admin/include/config.php in FireFly 1.1.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pppf-g86g-w4gf/GHSA-pppf-g86g-w4gf.json b/advisories/unreviewed/2022/05/GHSA-pppf-g86g-w4gf/GHSA-pppf-g86g-w4gf.json index c0160134dee..3c3d342277a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pppf-g86g-w4gf/GHSA-pppf-g86g-w4gf.json +++ b/advisories/unreviewed/2022/05/GHSA-pppf-g86g-w4gf/GHSA-pppf-g86g-w4gf.json @@ -7,12 +7,8 @@ "CVE-2007-2603" ], "details": "Unspecified vulnerability in the Init function in the Audio CD Ripper OCX (AudioCDRipperOCX.ocx) 1.0 ActiveX control allows remote attackers to cause a denial of service (NULL dereference and Internet Explorer crash) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pqp9-jxcw-2mjm/GHSA-pqp9-jxcw-2mjm.json b/advisories/unreviewed/2022/05/GHSA-pqp9-jxcw-2mjm/GHSA-pqp9-jxcw-2mjm.json index 05726acfbee..b16d1b10a91 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqp9-jxcw-2mjm/GHSA-pqp9-jxcw-2mjm.json +++ b/advisories/unreviewed/2022/05/GHSA-pqp9-jxcw-2mjm/GHSA-pqp9-jxcw-2mjm.json @@ -7,12 +7,8 @@ "CVE-2007-2287" ], "details": "PHP remote file inclusion vulnerability in accept.php in comus 2.0 Final allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pqx5-jj73-9xw4/GHSA-pqx5-jj73-9xw4.json b/advisories/unreviewed/2022/05/GHSA-pqx5-jj73-9xw4/GHSA-pqx5-jj73-9xw4.json index 438ddbacecf..92cc5ed98d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqx5-jj73-9xw4/GHSA-pqx5-jj73-9xw4.json +++ b/advisories/unreviewed/2022/05/GHSA-pqx5-jj73-9xw4/GHSA-pqx5-jj73-9xw4.json @@ -7,12 +7,8 @@ "CVE-2007-2473" ], "details": "SQL injection vulnerability in stylesheet.php in CMS Made Simple 1.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via the templateid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pvg7-hvf6-hwvw/GHSA-pvg7-hvf6-hwvw.json b/advisories/unreviewed/2022/05/GHSA-pvg7-hvf6-hwvw/GHSA-pvg7-hvf6-hwvw.json index 95be7e6bb52..a25af75dc61 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvg7-hvf6-hwvw/GHSA-pvg7-hvf6-hwvw.json +++ b/advisories/unreviewed/2022/05/GHSA-pvg7-hvf6-hwvw/GHSA-pvg7-hvf6-hwvw.json @@ -7,12 +7,8 @@ "CVE-2007-2578" ], "details": "Unspecified vulnerability in search/list/action_search/index.php in ACP3 4.0 beta 3 allows remote attackers to have unknown impact, relating to \"Cookie Manipulation\", via the form[search_term] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pvp3-v3gm-wmv4/GHSA-pvp3-v3gm-wmv4.json b/advisories/unreviewed/2022/05/GHSA-pvp3-v3gm-wmv4/GHSA-pvp3-v3gm-wmv4.json index 50262b0ae28..eecdf78b44c 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvp3-v3gm-wmv4/GHSA-pvp3-v3gm-wmv4.json +++ b/advisories/unreviewed/2022/05/GHSA-pvp3-v3gm-wmv4/GHSA-pvp3-v3gm-wmv4.json @@ -7,12 +7,8 @@ "CVE-2007-2350" ], "details": "admin/config.php in the music-on-hold module in freePBX 2.2.x allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the del parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pvw4-9q37-8pfv/GHSA-pvw4-9q37-8pfv.json b/advisories/unreviewed/2022/05/GHSA-pvw4-9q37-8pfv/GHSA-pvw4-9q37-8pfv.json index 6712eff24b3..9adc31a331f 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvw4-9q37-8pfv/GHSA-pvw4-9q37-8pfv.json +++ b/advisories/unreviewed/2022/05/GHSA-pvw4-9q37-8pfv/GHSA-pvw4-9q37-8pfv.json @@ -7,12 +7,8 @@ "CVE-2007-2574" ], "details": "Directory traversal vulnerability in index.php in Archangel Weblog 0.90.02 allows remote attackers to read arbitrary files via a .. (dot dot) in the index parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pvxp-mv8r-jg5p/GHSA-pvxp-mv8r-jg5p.json b/advisories/unreviewed/2022/05/GHSA-pvxp-mv8r-jg5p/GHSA-pvxp-mv8r-jg5p.json index e4a7484ff97..6b52e4a652f 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvxp-mv8r-jg5p/GHSA-pvxp-mv8r-jg5p.json +++ b/advisories/unreviewed/2022/05/GHSA-pvxp-mv8r-jg5p/GHSA-pvxp-mv8r-jg5p.json @@ -7,12 +7,8 @@ "CVE-2007-2466" ], "details": "Unspecified vulnerability in the LDAP Software Development Kit (SDK) for C, as used in Sun Java System Directory Server 5.2 up to Patch 4 and Sun ONE Directory Server 5.1, allows remote attackers to cause a denial of service (crash) via certain BER encodings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pw39-q62j-5h8w/GHSA-pw39-q62j-5h8w.json b/advisories/unreviewed/2022/05/GHSA-pw39-q62j-5h8w/GHSA-pw39-q62j-5h8w.json index ef40b43914b..769105da850 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw39-q62j-5h8w/GHSA-pw39-q62j-5h8w.json +++ b/advisories/unreviewed/2022/05/GHSA-pw39-q62j-5h8w/GHSA-pw39-q62j-5h8w.json @@ -7,12 +7,8 @@ "CVE-2007-2498" ], "details": "libmp4v2.dll in Winamp 5.02 through 5.34 allows user-assisted remote attackers to execute arbitrary code via a certain .MP4 file. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pxhq-xq33-27qf/GHSA-pxhq-xq33-27qf.json b/advisories/unreviewed/2022/05/GHSA-pxhq-xq33-27qf/GHSA-pxhq-xq33-27qf.json index 5e498f4c3e3..802e0a5a55c 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxhq-xq33-27qf/GHSA-pxhq-xq33-27qf.json +++ b/advisories/unreviewed/2022/05/GHSA-pxhq-xq33-27qf/GHSA-pxhq-xq33-27qf.json @@ -7,12 +7,8 @@ "CVE-2007-2502" ], "details": "Unspecified vulnerability in HP ProCurve 9300m Series switches with software 08.0.01c through 08.0.01j allows remote attackers to cause a denial of service via unknown vectors, a different switch series than CVE-2006-4015.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q24r-vvm4-c48g/GHSA-q24r-vvm4-c48g.json b/advisories/unreviewed/2022/05/GHSA-q24r-vvm4-c48g/GHSA-q24r-vvm4-c48g.json index fc5470eb9f4..0d7bc63d9ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-q24r-vvm4-c48g/GHSA-q24r-vvm4-c48g.json +++ b/advisories/unreviewed/2022/05/GHSA-q24r-vvm4-c48g/GHSA-q24r-vvm4-c48g.json @@ -7,12 +7,8 @@ "CVE-2007-2262" ], "details": "Multiple PHP remote file inclusion vulnerabilities in html/php/detail.php in Sinato jmuffin allow remote attackers to execute arbitrary PHP code via a URL in the (1) relPath and (2) folder parameters. NOTE: this product was originally reported as \"File117\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q26c-r44c-gj49/GHSA-q26c-r44c-gj49.json b/advisories/unreviewed/2022/05/GHSA-q26c-r44c-gj49/GHSA-q26c-r44c-gj49.json index a67e2c42169..3f9fc3774cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-q26c-r44c-gj49/GHSA-q26c-r44c-gj49.json +++ b/advisories/unreviewed/2022/05/GHSA-q26c-r44c-gj49/GHSA-q26c-r44c-gj49.json @@ -7,12 +7,8 @@ "CVE-2007-2252" ], "details": "Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive information via a .. (dot dot) in the icodir parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q446-jpj5-h34r/GHSA-q446-jpj5-h34r.json b/advisories/unreviewed/2022/05/GHSA-q446-jpj5-h34r/GHSA-q446-jpj5-h34r.json index 096524c8c41..85eddc5b35d 100644 --- a/advisories/unreviewed/2022/05/GHSA-q446-jpj5-h34r/GHSA-q446-jpj5-h34r.json +++ b/advisories/unreviewed/2022/05/GHSA-q446-jpj5-h34r/GHSA-q446-jpj5-h34r.json @@ -7,12 +7,8 @@ "CVE-2007-2256" ], "details": "Cross-site scripting (XSS) vulnerability in you.php in TJSChat 0.95 allows remote attackers to inject arbitrary web script or HTML via the user parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q866-9m3h-92xr/GHSA-q866-9m3h-92xr.json b/advisories/unreviewed/2022/05/GHSA-q866-9m3h-92xr/GHSA-q866-9m3h-92xr.json index 51cbc2b0fe0..da5510264ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-q866-9m3h-92xr/GHSA-q866-9m3h-92xr.json +++ b/advisories/unreviewed/2022/05/GHSA-q866-9m3h-92xr/GHSA-q866-9m3h-92xr.json @@ -7,12 +7,8 @@ "CVE-2007-1991" ], "details": "Cross-site scripting (XSS) vulnerability in mail/signup.asp in CmailServer WebMail 5.4.3, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the Comment parameter, a different vector than CVE-2007-1927.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q8hg-7g5g-737m/GHSA-q8hg-7g5g-737m.json b/advisories/unreviewed/2022/05/GHSA-q8hg-7g5g-737m/GHSA-q8hg-7g5g-737m.json index a0a9c14261f..404a20d64f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8hg-7g5g-737m/GHSA-q8hg-7g5g-737m.json +++ b/advisories/unreviewed/2022/05/GHSA-q8hg-7g5g-737m/GHSA-q8hg-7g5g-737m.json @@ -7,12 +7,8 @@ "CVE-2007-2530" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Tropicalm Crowell Resource 4.5.2 allow remote attackers to execute arbitrary PHP code via a URL in the RESPATH parameter to (1) dosearch.php or (2) printfriendly.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q9cj-fx8w-w7gr/GHSA-q9cj-fx8w-w7gr.json b/advisories/unreviewed/2022/05/GHSA-q9cj-fx8w-w7gr/GHSA-q9cj-fx8w-w7gr.json index 246e7a174af..20e1e3b23df 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9cj-fx8w-w7gr/GHSA-q9cj-fx8w-w7gr.json +++ b/advisories/unreviewed/2022/05/GHSA-q9cj-fx8w-w7gr/GHSA-q9cj-fx8w-w7gr.json @@ -7,12 +7,8 @@ "CVE-2007-2013" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in JEx-Treme Einfacher Passworschutz allows remote attackers to inject arbitrary web script or HTML via the msg parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qgq2-pf5j-2fvq/GHSA-qgq2-pf5j-2fvq.json b/advisories/unreviewed/2022/05/GHSA-qgq2-pf5j-2fvq/GHSA-qgq2-pf5j-2fvq.json index 9bda817766c..f386181e442 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgq2-pf5j-2fvq/GHSA-qgq2-pf5j-2fvq.json +++ b/advisories/unreviewed/2022/05/GHSA-qgq2-pf5j-2fvq/GHSA-qgq2-pf5j-2fvq.json @@ -7,12 +7,8 @@ "CVE-2007-2383" ], "details": "The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka \"JavaScript Hijacking.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qmj7-h5mr-4c44/GHSA-qmj7-h5mr-4c44.json b/advisories/unreviewed/2022/05/GHSA-qmj7-h5mr-4c44/GHSA-qmj7-h5mr-4c44.json index 1811feb30e1..550ab1ed5bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmj7-h5mr-4c44/GHSA-qmj7-h5mr-4c44.json +++ b/advisories/unreviewed/2022/05/GHSA-qmj7-h5mr-4c44/GHSA-qmj7-h5mr-4c44.json @@ -7,12 +7,8 @@ "CVE-2007-2285" ], "details": "Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote attackers to read arbitrary files via a .. (dot dot) in the feed parameter. NOTE: analysis by third party researchers indicates that this issue might be platform dependent.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qp76-4p7c-6pvj/GHSA-qp76-4p7c-6pvj.json b/advisories/unreviewed/2022/05/GHSA-qp76-4p7c-6pvj/GHSA-qp76-4p7c-6pvj.json index a75783e8cca..21ec1688b77 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp76-4p7c-6pvj/GHSA-qp76-4p7c-6pvj.json +++ b/advisories/unreviewed/2022/05/GHSA-qp76-4p7c-6pvj/GHSA-qp76-4p7c-6pvj.json @@ -7,12 +7,8 @@ "CVE-2007-2269" ], "details": "Directory traversal vulnerability in top.php3 in SWsoft Plesk for Windows 8.1 and 8.1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qqc7-5g46-wrvr/GHSA-qqc7-5g46-wrvr.json b/advisories/unreviewed/2022/05/GHSA-qqc7-5g46-wrvr/GHSA-qqc7-5g46-wrvr.json index 70abf64b461..e23e809f8e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqc7-5g46-wrvr/GHSA-qqc7-5g46-wrvr.json +++ b/advisories/unreviewed/2022/05/GHSA-qqc7-5g46-wrvr/GHSA-qqc7-5g46-wrvr.json @@ -7,12 +7,8 @@ "CVE-2007-2131" ], "details": "Unspecified vulnerability in PeopleTools in Oracle PeopleSoft Enterprise 8.22.14, 8.47.12, and 8.48.08 has unknown impact and attack vectors, aka PSE01.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qqmg-fjc7-vh75/GHSA-qqmg-fjc7-vh75.json b/advisories/unreviewed/2022/05/GHSA-qqmg-fjc7-vh75/GHSA-qqmg-fjc7-vh75.json index 3fcd01d1197..ef6c41bd99f 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqmg-fjc7-vh75/GHSA-qqmg-fjc7-vh75.json +++ b/advisories/unreviewed/2022/05/GHSA-qqmg-fjc7-vh75/GHSA-qqmg-fjc7-vh75.json @@ -7,12 +7,8 @@ "CVE-2007-2599" ], "details": "Multiple SQL injection vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php; or (3) the search parameter to search.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qqqw-7xxh-gvpq/GHSA-qqqw-7xxh-gvpq.json b/advisories/unreviewed/2022/05/GHSA-qqqw-7xxh-gvpq/GHSA-qqqw-7xxh-gvpq.json index de057497b7a..ff0f2efa737 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqqw-7xxh-gvpq/GHSA-qqqw-7xxh-gvpq.json +++ b/advisories/unreviewed/2022/05/GHSA-qqqw-7xxh-gvpq/GHSA-qqqw-7xxh-gvpq.json @@ -7,12 +7,8 @@ "CVE-2007-2427" ], "details": "SQL injection vulnerability in index.php in the pnFlashGames 1.5 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qr35-j46m-j7h3/GHSA-qr35-j46m-j7h3.json b/advisories/unreviewed/2022/05/GHSA-qr35-j46m-j7h3/GHSA-qr35-j46m-j7h3.json index 9cddf40cffc..4e9595d62f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-qr35-j46m-j7h3/GHSA-qr35-j46m-j7h3.json +++ b/advisories/unreviewed/2022/05/GHSA-qr35-j46m-j7h3/GHSA-qr35-j46m-j7h3.json @@ -7,12 +7,8 @@ "CVE-2007-2550" ], "details": "Multiple CRLF injection vulnerabilities in Devellion CubeCart 3.0.15 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a cookie name beginning with \"ccSID\" to (1) cart.php or (2) index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qrmw-vh25-8vhc/GHSA-qrmw-vh25-8vhc.json b/advisories/unreviewed/2022/05/GHSA-qrmw-vh25-8vhc/GHSA-qrmw-vh25-8vhc.json index 306c42faad1..1644797fc89 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrmw-vh25-8vhc/GHSA-qrmw-vh25-8vhc.json +++ b/advisories/unreviewed/2022/05/GHSA-qrmw-vh25-8vhc/GHSA-qrmw-vh25-8vhc.json @@ -7,12 +7,8 @@ "CVE-2007-2621" ], "details": "SQL injection vulnerability in event_view.php in Thyme Calendar 1.3 allows remote attackers to execute arbitrary SQL commands via the eid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qrxj-cxvr-q267/GHSA-qrxj-cxvr-q267.json b/advisories/unreviewed/2022/05/GHSA-qrxj-cxvr-q267/GHSA-qrxj-cxvr-q267.json index 43b149ff8cc..617972a8fba 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrxj-cxvr-q267/GHSA-qrxj-cxvr-q267.json +++ b/advisories/unreviewed/2022/05/GHSA-qrxj-cxvr-q267/GHSA-qrxj-cxvr-q267.json @@ -7,12 +7,8 @@ "CVE-2007-2559" ], "details": "Multiple PHP remote file inclusion vulnerabilities in american cart 3.5 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php, (2) checkout.php, and (3) libsecure.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qvxr-389g-385v/GHSA-qvxr-389g-385v.json b/advisories/unreviewed/2022/05/GHSA-qvxr-389g-385v/GHSA-qvxr-389g-385v.json index 6ad9dab3cfa..9eefc7d9b99 100644 --- a/advisories/unreviewed/2022/05/GHSA-qvxr-389g-385v/GHSA-qvxr-389g-385v.json +++ b/advisories/unreviewed/2022/05/GHSA-qvxr-389g-385v/GHSA-qvxr-389g-385v.json @@ -7,12 +7,8 @@ "CVE-2007-2457" ], "details": "PHP remote file inclusion vulnerability in resources/includes/class.Smarty.php in Pixaria Gallery before 1.4.3 allows remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qwg4-pcxj-2658/GHSA-qwg4-pcxj-2658.json b/advisories/unreviewed/2022/05/GHSA-qwg4-pcxj-2658/GHSA-qwg4-pcxj-2658.json index c3757c83f4d..87022a5472b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwg4-pcxj-2658/GHSA-qwg4-pcxj-2658.json +++ b/advisories/unreviewed/2022/05/GHSA-qwg4-pcxj-2658/GHSA-qwg4-pcxj-2658.json @@ -7,12 +7,8 @@ "CVE-2007-2324" ], "details": "Directory traversal vulnerability in file.php in JulmaCMS 1.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qxrc-mpfr-xpp8/GHSA-qxrc-mpfr-xpp8.json b/advisories/unreviewed/2022/05/GHSA-qxrc-mpfr-xpp8/GHSA-qxrc-mpfr-xpp8.json index cc1cf03b193..f664323feb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxrc-mpfr-xpp8/GHSA-qxrc-mpfr-xpp8.json +++ b/advisories/unreviewed/2022/05/GHSA-qxrc-mpfr-xpp8/GHSA-qxrc-mpfr-xpp8.json @@ -7,12 +7,8 @@ "CVE-2007-2521" ], "details": "PHP remote file inclusion vulnerability in common.php in E-GADS! before 2.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the locale parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r2rv-q8mh-m7x6/GHSA-r2rv-q8mh-m7x6.json b/advisories/unreviewed/2022/05/GHSA-r2rv-q8mh-m7x6/GHSA-r2rv-q8mh-m7x6.json index 9507d017c3a..7b99d899605 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2rv-q8mh-m7x6/GHSA-r2rv-q8mh-m7x6.json +++ b/advisories/unreviewed/2022/05/GHSA-r2rv-q8mh-m7x6/GHSA-r2rv-q8mh-m7x6.json @@ -7,12 +7,8 @@ "CVE-2007-2640" ], "details": "LibTMCG before 1.1.1 does not perform a range check to avoid \"trivial group generators,\" which allows attackers to obtain sensitive information about private cards.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r35c-m26c-wp9q/GHSA-r35c-m26c-wp9q.json b/advisories/unreviewed/2022/05/GHSA-r35c-m26c-wp9q/GHSA-r35c-m26c-wp9q.json index bf85969a571..aee461e4d76 100644 --- a/advisories/unreviewed/2022/05/GHSA-r35c-m26c-wp9q/GHSA-r35c-m26c-wp9q.json +++ b/advisories/unreviewed/2022/05/GHSA-r35c-m26c-wp9q/GHSA-r35c-m26c-wp9q.json @@ -7,12 +7,8 @@ "CVE-2007-2004" ], "details": "Multiple SQL injection vulnerabilities in InoutMailingListManager 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to changename.php and other unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r35q-386g-w8xq/GHSA-r35q-386g-w8xq.json b/advisories/unreviewed/2022/05/GHSA-r35q-386g-w8xq/GHSA-r35q-386g-w8xq.json index fe96158d4ba..38d5ca0fd10 100644 --- a/advisories/unreviewed/2022/05/GHSA-r35q-386g-w8xq/GHSA-r35q-386g-w8xq.json +++ b/advisories/unreviewed/2022/05/GHSA-r35q-386g-w8xq/GHSA-r35q-386g-w8xq.json @@ -7,12 +7,8 @@ "CVE-2007-2658" ], "details": "Unspecified vulnerability in the ID Automation Linear Barcode 1.6.0.5 ActiveX control in IDAutomationLinear6.dll allows remote attackers to cause a denial of service via a long argument to the SaveEnhWMF method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r482-54vx-vgj4/GHSA-r482-54vx-vgj4.json b/advisories/unreviewed/2022/05/GHSA-r482-54vx-vgj4/GHSA-r482-54vx-vgj4.json index d2374892705..89984b6dafb 100644 --- a/advisories/unreviewed/2022/05/GHSA-r482-54vx-vgj4/GHSA-r482-54vx-vgj4.json +++ b/advisories/unreviewed/2022/05/GHSA-r482-54vx-vgj4/GHSA-r482-54vx-vgj4.json @@ -7,12 +7,8 @@ "CVE-2007-2174" ], "details": "The IOCTL handling in srescan.sys in the ZoneAlarm Spyware Removal Engine (SRE) in Check Point ZoneAlarm before 5.0.156.0 allows local users to execute arbitrary code via certain IOCTL lrp parameter addresses.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r4m7-rxm5-ww7r/GHSA-r4m7-rxm5-ww7r.json b/advisories/unreviewed/2022/05/GHSA-r4m7-rxm5-ww7r/GHSA-r4m7-rxm5-ww7r.json index fc17022406d..1072f8ff38c 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4m7-rxm5-ww7r/GHSA-r4m7-rxm5-ww7r.json +++ b/advisories/unreviewed/2022/05/GHSA-r4m7-rxm5-ww7r/GHSA-r4m7-rxm5-ww7r.json @@ -7,12 +7,8 @@ "CVE-2007-2672" ], "details": "SQL injection vulnerability in index.php in PHP Coupon Script 3.0 allows remote attackers to execute arbitrary SQL commands via the bus parameter in a viewbus page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r58r-pm5c-hh48/GHSA-r58r-pm5c-hh48.json b/advisories/unreviewed/2022/05/GHSA-r58r-pm5c-hh48/GHSA-r58r-pm5c-hh48.json index 6ba1ab50dc9..a5eafd17505 100644 --- a/advisories/unreviewed/2022/05/GHSA-r58r-pm5c-hh48/GHSA-r58r-pm5c-hh48.json +++ b/advisories/unreviewed/2022/05/GHSA-r58r-pm5c-hh48/GHSA-r58r-pm5c-hh48.json @@ -7,12 +7,8 @@ "CVE-2019-0620" ], "details": "A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0709, CVE-2019-0722.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r6w7-xqr4-v3v2/GHSA-r6w7-xqr4-v3v2.json b/advisories/unreviewed/2022/05/GHSA-r6w7-xqr4-v3v2/GHSA-r6w7-xqr4-v3v2.json index 538e5a4beac..0ea068657ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6w7-xqr4-v3v2/GHSA-r6w7-xqr4-v3v2.json +++ b/advisories/unreviewed/2022/05/GHSA-r6w7-xqr4-v3v2/GHSA-r6w7-xqr4-v3v2.json @@ -7,12 +7,8 @@ "CVE-2007-2182" ], "details": "Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP files via a trailing %00 in a filename in the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r6xx-c56h-r63m/GHSA-r6xx-c56h-r63m.json b/advisories/unreviewed/2022/05/GHSA-r6xx-c56h-r63m/GHSA-r6xx-c56h-r63m.json index baa7b6f3edd..769d5de6b34 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6xx-c56h-r63m/GHSA-r6xx-c56h-r63m.json +++ b/advisories/unreviewed/2022/05/GHSA-r6xx-c56h-r63m/GHSA-r6xx-c56h-r63m.json @@ -7,12 +7,8 @@ "CVE-2007-2342" ], "details": "SQL injection vulnerability in error.asp in CreaScripts CreaDirectory 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-6083.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r73m-5g7h-cj4f/GHSA-r73m-5g7h-cj4f.json b/advisories/unreviewed/2022/05/GHSA-r73m-5g7h-cj4f/GHSA-r73m-5g7h-cj4f.json index 3ead50f52a9..7f30ca6adaa 100644 --- a/advisories/unreviewed/2022/05/GHSA-r73m-5g7h-cj4f/GHSA-r73m-5g7h-cj4f.json +++ b/advisories/unreviewed/2022/05/GHSA-r73m-5g7h-cj4f/GHSA-r73m-5g7h-cj4f.json @@ -7,12 +7,8 @@ "CVE-2007-2426" ], "details": "PHP remote file inclusion vulnerability in myfunctions/mygallerybrowser.php in the myGallery 1.4b4 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the myPath parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r7hv-v69f-fvfr/GHSA-r7hv-v69f-fvfr.json b/advisories/unreviewed/2022/05/GHSA-r7hv-v69f-fvfr/GHSA-r7hv-v69f-fvfr.json index 5683fefbc3b..59311014266 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7hv-v69f-fvfr/GHSA-r7hv-v69f-fvfr.json +++ b/advisories/unreviewed/2022/05/GHSA-r7hv-v69f-fvfr/GHSA-r7hv-v69f-fvfr.json @@ -7,12 +7,8 @@ "CVE-2007-2529" ], "details": "Integer signedness error in the acl (facl) system call in Solaris 10 before 20070507 allows local users to cause a denial of service (kernel panic) and possibly gain privileges via a certain argument, related to ACE_SETACL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rf4c-m93m-m5w7/GHSA-rf4c-m93m-m5w7.json b/advisories/unreviewed/2022/05/GHSA-rf4c-m93m-m5w7/GHSA-rf4c-m93m-m5w7.json index 9940d444958..c3114a061c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf4c-m93m-m5w7/GHSA-rf4c-m93m-m5w7.json +++ b/advisories/unreviewed/2022/05/GHSA-rf4c-m93m-m5w7/GHSA-rf4c-m93m-m5w7.json @@ -7,12 +7,8 @@ "CVE-2007-2491" ], "details": "The PIIX4 power management subsystem in EMC VMware Workstation 5.5.3.34685 and VMware Server 1.0.1.29996 allows local users to write to arbitrary memory locations via a crafted poke to I/O port 0x1004, triggering a denial of service (virtual machine crash) or other unspecified impact, a related issue to CVE-2007-1337.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rf76-q24f-7pxj/GHSA-rf76-q24f-7pxj.json b/advisories/unreviewed/2022/05/GHSA-rf76-q24f-7pxj/GHSA-rf76-q24f-7pxj.json index 35a0ca02073..871d38f8756 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf76-q24f-7pxj/GHSA-rf76-q24f-7pxj.json +++ b/advisories/unreviewed/2022/05/GHSA-rf76-q24f-7pxj/GHSA-rf76-q24f-7pxj.json @@ -7,12 +7,8 @@ "CVE-2007-2319" ], "details": "PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to mod_as_category.php in (1) modules/mod_as_category/ or (2) modules/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rhhq-2rwf-cr4q/GHSA-rhhq-2rwf-cr4q.json b/advisories/unreviewed/2022/05/GHSA-rhhq-2rwf-cr4q/GHSA-rhhq-2rwf-cr4q.json index 330f8865d14..e2343aa5541 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhhq-2rwf-cr4q/GHSA-rhhq-2rwf-cr4q.json +++ b/advisories/unreviewed/2022/05/GHSA-rhhq-2rwf-cr4q/GHSA-rhhq-2rwf-cr4q.json @@ -7,12 +7,8 @@ "CVE-2007-2391" ], "details": "Cross-site scripting (XSS) vulnerability in Apple Safari Beta 3.0.1 for Windows allows remote attackers to inject arbitrary web script or HTML via a web page that includes a windows.setTimeout function that is activated after the user has moved from the current page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rj6w-x66c-qm7f/GHSA-rj6w-x66c-qm7f.json b/advisories/unreviewed/2022/05/GHSA-rj6w-x66c-qm7f/GHSA-rj6w-x66c-qm7f.json index 98926c04b7b..8874181b690 100644 --- a/advisories/unreviewed/2022/05/GHSA-rj6w-x66c-qm7f/GHSA-rj6w-x66c-qm7f.json +++ b/advisories/unreviewed/2022/05/GHSA-rj6w-x66c-qm7f/GHSA-rj6w-x66c-qm7f.json @@ -7,12 +7,8 @@ "CVE-2007-2513" ], "details": "Novell GroupWise 7 before SP2 20070524, and GroupWise 6 before 6.5 post-SP6 20070522, allows remote attackers to obtain credentials via a man-in-the-middle attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rp3r-mxcw-m2v4/GHSA-rp3r-mxcw-m2v4.json b/advisories/unreviewed/2022/05/GHSA-rp3r-mxcw-m2v4/GHSA-rp3r-mxcw-m2v4.json index 2661b448719..376ea880a86 100644 --- a/advisories/unreviewed/2022/05/GHSA-rp3r-mxcw-m2v4/GHSA-rp3r-mxcw-m2v4.json +++ b/advisories/unreviewed/2022/05/GHSA-rp3r-mxcw-m2v4/GHSA-rp3r-mxcw-m2v4.json @@ -7,12 +7,8 @@ "CVE-2007-2217" ], "details": "Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote attackers to execute arbitrary code via crafted image files that trigger memory corruption, as demonstrated by a certain .tif (TIFF) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rr6h-6gx2-wjcq/GHSA-rr6h-6gx2-wjcq.json b/advisories/unreviewed/2022/05/GHSA-rr6h-6gx2-wjcq/GHSA-rr6h-6gx2-wjcq.json index 011c80a549b..39ae0f1ee1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rr6h-6gx2-wjcq/GHSA-rr6h-6gx2-wjcq.json +++ b/advisories/unreviewed/2022/05/GHSA-rr6h-6gx2-wjcq/GHSA-rr6h-6gx2-wjcq.json @@ -7,12 +7,8 @@ "CVE-2007-2562" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 3.00.90 allows remote attackers to inject arbitrary web script or HTML via the _m parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rv2p-mqf6-rm29/GHSA-rv2p-mqf6-rm29.json b/advisories/unreviewed/2022/05/GHSA-rv2p-mqf6-rm29/GHSA-rv2p-mqf6-rm29.json index c7f9e604ded..7b61dbb4f85 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv2p-mqf6-rm29/GHSA-rv2p-mqf6-rm29.json +++ b/advisories/unreviewed/2022/05/GHSA-rv2p-mqf6-rm29/GHSA-rv2p-mqf6-rm29.json @@ -7,12 +7,8 @@ "CVE-2007-2632" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PHP Multi User Randomizer (phpMUR) 2006.09.13 allow remote attackers to inject arbitrary web script or HTML via (1) the edit_plugin parameter to configure_plugin.tpl.php, or (2) certain array parameters to web/phpinfo.php, as demonstrated by 1[] or a[].", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rv66-f66p-9v9q/GHSA-rv66-f66p-9v9q.json b/advisories/unreviewed/2022/05/GHSA-rv66-f66p-9v9q/GHSA-rv66-f66p-9v9q.json index b7d91d2ecd7..07624da190c 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv66-f66p-9v9q/GHSA-rv66-f66p-9v9q.json +++ b/advisories/unreviewed/2022/05/GHSA-rv66-f66p-9v9q/GHSA-rv66-f66p-9v9q.json @@ -7,12 +7,8 @@ "CVE-2007-2392" ], "details": "Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via a crafted movie file that triggers memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rvmx-q4vh-c94v/GHSA-rvmx-q4vh-c94v.json b/advisories/unreviewed/2022/05/GHSA-rvmx-q4vh-c94v/GHSA-rvmx-q4vh-c94v.json index 8d522521c19..de7e2461884 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvmx-q4vh-c94v/GHSA-rvmx-q4vh-c94v.json +++ b/advisories/unreviewed/2022/05/GHSA-rvmx-q4vh-c94v/GHSA-rvmx-q4vh-c94v.json @@ -7,12 +7,8 @@ "CVE-2007-2153" ], "details": "Cross-site scripting (XSS) vulnerability in atmail.php in @Mail 5.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rvp2-7p9h-x2p7/GHSA-rvp2-7p9h-x2p7.json b/advisories/unreviewed/2022/05/GHSA-rvp2-7p9h-x2p7/GHSA-rvp2-7p9h-x2p7.json index 77ebcd900a7..4eef604f380 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvp2-7p9h-x2p7/GHSA-rvp2-7p9h-x2p7.json +++ b/advisories/unreviewed/2022/05/GHSA-rvp2-7p9h-x2p7/GHSA-rvp2-7p9h-x2p7.json @@ -7,12 +7,8 @@ "CVE-2007-2679" ], "details": "PHP file inclusion vulnerability in index.php in Ivan Peevski gallery 0.3 in Simple PHP Scripts (sphp) allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the gallery parameter, which is accessed by the file_exists function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v42f-h49w-98mp/GHSA-v42f-h49w-98mp.json b/advisories/unreviewed/2022/05/GHSA-v42f-h49w-98mp/GHSA-v42f-h49w-98mp.json index 60ec32354b5..66dc19ee65d 100644 --- a/advisories/unreviewed/2022/05/GHSA-v42f-h49w-98mp/GHSA-v42f-h49w-98mp.json +++ b/advisories/unreviewed/2022/05/GHSA-v42f-h49w-98mp/GHSA-v42f-h49w-98mp.json @@ -7,12 +7,8 @@ "CVE-2007-2688" ], "details": "The Cisco Intrusion Prevention System (IPS) and IOS with Firewall/IPS Feature Set do not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v4pf-5vjx-5c3g/GHSA-v4pf-5vjx-5c3g.json b/advisories/unreviewed/2022/05/GHSA-v4pf-5vjx-5c3g/GHSA-v4pf-5vjx-5c3g.json index 3ed86c6f205..b737121fa50 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4pf-5vjx-5c3g/GHSA-v4pf-5vjx-5c3g.json +++ b/advisories/unreviewed/2022/05/GHSA-v4pf-5vjx-5c3g/GHSA-v4pf-5vjx-5c3g.json @@ -7,12 +7,8 @@ "CVE-2007-2329" ], "details": "PHP remote file inclusion vulnerability in searchbot.php in Searchactivity allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v52h-q97r-4w5h/GHSA-v52h-q97r-4w5h.json b/advisories/unreviewed/2022/05/GHSA-v52h-q97r-4w5h/GHSA-v52h-q97r-4w5h.json index 5401125d60b..5d05988e1a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-v52h-q97r-4w5h/GHSA-v52h-q97r-4w5h.json +++ b/advisories/unreviewed/2022/05/GHSA-v52h-q97r-4w5h/GHSA-v52h-q97r-4w5h.json @@ -7,12 +7,8 @@ "CVE-2007-2606" ], "details": "Multiple buffer overflows in Firebird 2.1 allow attackers to trigger memory corruption and possibly have other unspecified impact via certain input processed by (1) config\\ConfigFile.cpp or (2) msgs\\check_msgs.epp. NOTE: if ConfigFile.cpp reads a configuration file with restrictive permissions, then the ConfigFile.cpp vector may not cross privilege boundaries and perhaps should not be included in CVE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v58r-vg3c-hjmm/GHSA-v58r-vg3c-hjmm.json b/advisories/unreviewed/2022/05/GHSA-v58r-vg3c-hjmm/GHSA-v58r-vg3c-hjmm.json index ba6d2e482f6..7b230770497 100644 --- a/advisories/unreviewed/2022/05/GHSA-v58r-vg3c-hjmm/GHSA-v58r-vg3c-hjmm.json +++ b/advisories/unreviewed/2022/05/GHSA-v58r-vg3c-hjmm/GHSA-v58r-vg3c-hjmm.json @@ -7,12 +7,8 @@ "CVE-2007-2175" ], "details": "Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbitrary code via parameters to the toQTPointer method in quicktime.util.QTHandleRef, which can be used to modify arbitrary memory when creating QTPointerRef objects, as demonstrated during the \"PWN 2 0WN\" contest at CanSecWest 2007.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v5f3-g9pp-rm52/GHSA-v5f3-g9pp-rm52.json b/advisories/unreviewed/2022/05/GHSA-v5f3-g9pp-rm52/GHSA-v5f3-g9pp-rm52.json index 5750978e2ef..25e4472af29 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5f3-g9pp-rm52/GHSA-v5f3-g9pp-rm52.json +++ b/advisories/unreviewed/2022/05/GHSA-v5f3-g9pp-rm52/GHSA-v5f3-g9pp-rm52.json @@ -7,12 +7,8 @@ "CVE-2007-2327" ], "details": "PHP remote file inclusion vulnerability in _editor.php in HTMLeditbox 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the settings[app_dir] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v69m-9r45-9fxf/GHSA-v69m-9r45-9fxf.json b/advisories/unreviewed/2022/05/GHSA-v69m-9r45-9fxf/GHSA-v69m-9r45-9fxf.json index 1056eff130b..c04fd0d8772 100644 --- a/advisories/unreviewed/2022/05/GHSA-v69m-9r45-9fxf/GHSA-v69m-9r45-9fxf.json +++ b/advisories/unreviewed/2022/05/GHSA-v69m-9r45-9fxf/GHSA-v69m-9r45-9fxf.json @@ -7,12 +7,8 @@ "CVE-2007-2685" ], "details": "Multiple SQL injection vulnerabilities in index.php in Jetbox CMS 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) view or (2) login parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v72c-q9w5-gcvr/GHSA-v72c-q9w5-gcvr.json b/advisories/unreviewed/2022/05/GHSA-v72c-q9w5-gcvr/GHSA-v72c-q9w5-gcvr.json index 748104a0204..d8c0b9d9ca5 100644 --- a/advisories/unreviewed/2022/05/GHSA-v72c-q9w5-gcvr/GHSA-v72c-q9w5-gcvr.json +++ b/advisories/unreviewed/2022/05/GHSA-v72c-q9w5-gcvr/GHSA-v72c-q9w5-gcvr.json @@ -7,12 +7,8 @@ "CVE-2007-2592" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to de/pda/dev_logon.asp and (2) multiple unspecified vectors in (a) usrmgr/registerAccount.asp, (b) de/create_account.asp, and other files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v73v-2jgh-w8c6/GHSA-v73v-2jgh-w8c6.json b/advisories/unreviewed/2022/05/GHSA-v73v-2jgh-w8c6/GHSA-v73v-2jgh-w8c6.json index aa7f6fb9045..43e03315d5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v73v-2jgh-w8c6/GHSA-v73v-2jgh-w8c6.json +++ b/advisories/unreviewed/2022/05/GHSA-v73v-2jgh-w8c6/GHSA-v73v-2jgh-w8c6.json @@ -7,12 +7,8 @@ "CVE-2007-2399" ], "details": "WebKit in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1 performs an \"invalid type conversion\", which allows remote attackers to execute arbitrary code via unspecified frame sets that trigger memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v7q3-w86w-cjcj/GHSA-v7q3-w86w-cjcj.json b/advisories/unreviewed/2022/05/GHSA-v7q3-w86w-cjcj/GHSA-v7q3-w86w-cjcj.json index 1c442a893ec..efbc041bae8 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7q3-w86w-cjcj/GHSA-v7q3-w86w-cjcj.json +++ b/advisories/unreviewed/2022/05/GHSA-v7q3-w86w-cjcj/GHSA-v7q3-w86w-cjcj.json @@ -7,12 +7,8 @@ "CVE-2007-2454" ], "details": "Heap-based buffer overflow in the VGA device in Parallels allows local users, with root access to the guest operating system, to terminate the virtual machine and possibly execute arbitrary code in the host operating system via unspecified vectors related to bitblt operations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v86v-xvm4-877w/GHSA-v86v-xvm4-877w.json b/advisories/unreviewed/2022/05/GHSA-v86v-xvm4-877w/GHSA-v86v-xvm4-877w.json index 7f96d4200dc..754625073d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-v86v-xvm4-877w/GHSA-v86v-xvm4-877w.json +++ b/advisories/unreviewed/2022/05/GHSA-v86v-xvm4-877w/GHSA-v86v-xvm4-877w.json @@ -7,12 +7,8 @@ "CVE-2007-2483" ], "details": "Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the wpPATH parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v8g5-rxh2-j66m/GHSA-v8g5-rxh2-j66m.json b/advisories/unreviewed/2022/05/GHSA-v8g5-rxh2-j66m/GHSA-v8g5-rxh2-j66m.json index b50f20f67ee..35c49134d91 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8g5-rxh2-j66m/GHSA-v8g5-rxh2-j66m.json +++ b/advisories/unreviewed/2022/05/GHSA-v8g5-rxh2-j66m/GHSA-v8g5-rxh2-j66m.json @@ -7,12 +7,8 @@ "CVE-2007-2334" ], "details": "Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 has two template HTML files lacking certain verification tags, which allows remote attackers to access the administration interface and change the device configuration via certain requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v92m-h6q5-w9gg/GHSA-v92m-h6q5-w9gg.json b/advisories/unreviewed/2022/05/GHSA-v92m-h6q5-w9gg/GHSA-v92m-h6q5-w9gg.json index 4177d106c86..9e419e0ddb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-v92m-h6q5-w9gg/GHSA-v92m-h6q5-w9gg.json +++ b/advisories/unreviewed/2022/05/GHSA-v92m-h6q5-w9gg/GHSA-v92m-h6q5-w9gg.json @@ -7,12 +7,8 @@ "CVE-2007-2459" ], "details": "Heap-based buffer overflow in the BMP reader (bmp.c) in Imager perl module (libimager-perl) 0.45 through 0.56 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted 8-bit/pixel compressed BMP files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v9v7-xmqp-c9gw/GHSA-v9v7-xmqp-c9gw.json b/advisories/unreviewed/2022/05/GHSA-v9v7-xmqp-c9gw/GHSA-v9v7-xmqp-c9gw.json index b7ecffaef8f..a1d53febe40 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9v7-xmqp-c9gw/GHSA-v9v7-xmqp-c9gw.json +++ b/advisories/unreviewed/2022/05/GHSA-v9v7-xmqp-c9gw/GHSA-v9v7-xmqp-c9gw.json @@ -7,12 +7,8 @@ "CVE-2007-2433" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Ariadne 2.4.1 allows remote attackers to inject arbitrary web script or HTML via the ARLogin parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v9w9-h5qw-3rxw/GHSA-v9w9-h5qw-3rxw.json b/advisories/unreviewed/2022/05/GHSA-v9w9-h5qw-3rxw/GHSA-v9w9-h5qw-3rxw.json index ea49094999a..530b075c41d 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9w9-h5qw-3rxw/GHSA-v9w9-h5qw-3rxw.json +++ b/advisories/unreviewed/2022/05/GHSA-v9w9-h5qw-3rxw/GHSA-v9w9-h5qw-3rxw.json @@ -7,12 +7,8 @@ "CVE-2007-2132" ], "details": "Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise 8.47.12 and 8.48.08 has unknown impact and attack vectors, aka PSE02.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v9wg-49f7-4f43/GHSA-v9wg-49f7-4f43.json b/advisories/unreviewed/2022/05/GHSA-v9wg-49f7-4f43/GHSA-v9wg-49f7-4f43.json index 7b8f7cdb3ff..02b0beb9e1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9wg-49f7-4f43/GHSA-v9wg-49f7-4f43.json +++ b/advisories/unreviewed/2022/05/GHSA-v9wg-49f7-4f43/GHSA-v9wg-49f7-4f43.json @@ -7,12 +7,8 @@ "CVE-2007-2445" ], "details": "The png_handle_tRNS function in pngrutil.c in libpng before 1.0.25 and 1.2.x before 1.2.17 allows remote attackers to cause a denial of service (application crash) via a grayscale PNG image with a bad tRNS chunk CRC value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -224,9 +220,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vc9h-qrr4-gm2x/GHSA-vc9h-qrr4-gm2x.json b/advisories/unreviewed/2022/05/GHSA-vc9h-qrr4-gm2x/GHSA-vc9h-qrr4-gm2x.json index b5a8078331b..272e2e99ee5 100644 --- a/advisories/unreviewed/2022/05/GHSA-vc9h-qrr4-gm2x/GHSA-vc9h-qrr4-gm2x.json +++ b/advisories/unreviewed/2022/05/GHSA-vc9h-qrr4-gm2x/GHSA-vc9h-qrr4-gm2x.json @@ -7,12 +7,8 @@ "CVE-2007-2007" ], "details": "admin.php in pL-PHP beta 0.9 allows remote attackers to bypass authentication by setting the is_admin parameter to 1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vcfj-c4p9-w6vj/GHSA-vcfj-c4p9-w6vj.json b/advisories/unreviewed/2022/05/GHSA-vcfj-c4p9-w6vj/GHSA-vcfj-c4p9-w6vj.json index e6b90e427ea..71c59356ea6 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcfj-c4p9-w6vj/GHSA-vcfj-c4p9-w6vj.json +++ b/advisories/unreviewed/2022/05/GHSA-vcfj-c4p9-w6vj/GHSA-vcfj-c4p9-w6vj.json @@ -7,12 +7,8 @@ "CVE-2007-2614" ], "details": "PHP remote file inclusion vulnerability in examples/widget8.php in phpHtmlLib 2.4.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phphtmllib parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vfvg-47gf-j92q/GHSA-vfvg-47gf-j92q.json b/advisories/unreviewed/2022/05/GHSA-vfvg-47gf-j92q/GHSA-vfvg-47gf-j92q.json index 892fdde17e2..9f80ed15ed1 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfvg-47gf-j92q/GHSA-vfvg-47gf-j92q.json +++ b/advisories/unreviewed/2022/05/GHSA-vfvg-47gf-j92q/GHSA-vfvg-47gf-j92q.json @@ -7,12 +7,8 @@ "CVE-2007-2415" ], "details": "Pi3Web Web Server 2.0.3 PL1 allows remote attackers to cause a denial of service (application exit) via a long URI. NOTE: this issue was originally reported as a crash, but the vendor states that the impact is a \"clean\" exit in which \"the server I/O loop finishes and the process exits normally.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vg9j-j27r-chqg/GHSA-vg9j-j27r-chqg.json b/advisories/unreviewed/2022/05/GHSA-vg9j-j27r-chqg/GHSA-vg9j-j27r-chqg.json index fe771052244..be5f4419da6 100644 --- a/advisories/unreviewed/2022/05/GHSA-vg9j-j27r-chqg/GHSA-vg9j-j27r-chqg.json +++ b/advisories/unreviewed/2022/05/GHSA-vg9j-j27r-chqg/GHSA-vg9j-j27r-chqg.json @@ -7,12 +7,8 @@ "CVE-2007-1990" ], "details": "PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the id parameter, a different vector than CVE-2007-1968. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vm2q-qmjf-qfhq/GHSA-vm2q-qmjf-qfhq.json b/advisories/unreviewed/2022/05/GHSA-vm2q-qmjf-qfhq/GHSA-vm2q-qmjf-qfhq.json index 9b6c8a08adf..9466a954c5b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm2q-qmjf-qfhq/GHSA-vm2q-qmjf-qfhq.json +++ b/advisories/unreviewed/2022/05/GHSA-vm2q-qmjf-qfhq/GHSA-vm2q-qmjf-qfhq.json @@ -7,12 +7,8 @@ "CVE-2007-2001" ], "details": "Multiple direct static code injection vulnerabilities in admin/configurer2.php in Crea-Book 1.0 and earlier allow remote authenticated administrators to execute arbitrary PHP code via the \"Fond de la page\" (background color) field and other unspecified fields, which injects into config.inc.php3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vp7h-3q7r-gx68/GHSA-vp7h-3q7r-gx68.json b/advisories/unreviewed/2022/05/GHSA-vp7h-3q7r-gx68/GHSA-vp7h-3q7r-gx68.json index 542a19405bc..26b5c959269 100644 --- a/advisories/unreviewed/2022/05/GHSA-vp7h-3q7r-gx68/GHSA-vp7h-3q7r-gx68.json +++ b/advisories/unreviewed/2022/05/GHSA-vp7h-3q7r-gx68/GHSA-vp7h-3q7r-gx68.json @@ -7,12 +7,8 @@ "CVE-2007-2264" ], "details": "Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a RAM (.ra or .ram) file with a large size value in the RA header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vp9g-rcxv-hwmh/GHSA-vp9g-rcxv-hwmh.json b/advisories/unreviewed/2022/05/GHSA-vp9g-rcxv-hwmh/GHSA-vp9g-rcxv-hwmh.json index 38e1ff49c07..b3204224e1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vp9g-rcxv-hwmh/GHSA-vp9g-rcxv-hwmh.json +++ b/advisories/unreviewed/2022/05/GHSA-vp9g-rcxv-hwmh/GHSA-vp9g-rcxv-hwmh.json @@ -7,12 +7,8 @@ "CVE-2007-2234" ], "details": "include/common.php in PunBB 1.2.14 and earlier does not properly handle a disabled ini_get function when checking the register_globals setting, which allows remote attackers to register global parameters, as demonstrated by an SQL injection attack on the search_id parameter to search.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vpj8-2w67-c8qh/GHSA-vpj8-2w67-c8qh.json b/advisories/unreviewed/2022/05/GHSA-vpj8-2w67-c8qh/GHSA-vpj8-2w67-c8qh.json index 8f26aed9565..db69f27ccf7 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpj8-2w67-c8qh/GHSA-vpj8-2w67-c8qh.json +++ b/advisories/unreviewed/2022/05/GHSA-vpj8-2w67-c8qh/GHSA-vpj8-2w67-c8qh.json @@ -7,12 +7,8 @@ "CVE-2007-2186" ], "details": "Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vpjf-j2jf-ghm8/GHSA-vpjf-j2jf-ghm8.json b/advisories/unreviewed/2022/05/GHSA-vpjf-j2jf-ghm8/GHSA-vpjf-j2jf-ghm8.json index 27ff01af969..3a7e0098a61 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpjf-j2jf-ghm8/GHSA-vpjf-j2jf-ghm8.json +++ b/advisories/unreviewed/2022/05/GHSA-vpjf-j2jf-ghm8/GHSA-vpjf-j2jf-ghm8.json @@ -7,12 +7,8 @@ "CVE-2007-2525" ], "details": "Memory leak in the PPP over Ethernet (PPPoE) socket implementation in the Linux kernel before 2.6.21-git8 allows local users to cause a denial of service (memory consumption) by creating a socket using connect, and releasing it before the PPPIOCGCHAN ioctl is initialized.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -140,9 +136,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vq64-3whj-gvwm/GHSA-vq64-3whj-gvwm.json b/advisories/unreviewed/2022/05/GHSA-vq64-3whj-gvwm/GHSA-vq64-3whj-gvwm.json index 00a2902dddb..a0659f10996 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq64-3whj-gvwm/GHSA-vq64-3whj-gvwm.json +++ b/advisories/unreviewed/2022/05/GHSA-vq64-3whj-gvwm/GHSA-vq64-3whj-gvwm.json @@ -7,12 +7,8 @@ "CVE-2007-2682" ], "details": "The installer for Adobe Version Cue CS3 Server on Apple Mac OS X, as used in Adobe Creative Suite 3 (CS3), does not re-enable the personal firewall after completing the product installation, which allows remote attackers to bypass intended firewall rules.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vrgx-7r4m-fqpg/GHSA-vrgx-7r4m-fqpg.json b/advisories/unreviewed/2022/05/GHSA-vrgx-7r4m-fqpg/GHSA-vrgx-7r4m-fqpg.json index 309ac8f7bd8..db55de9706d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrgx-7r4m-fqpg/GHSA-vrgx-7r4m-fqpg.json +++ b/advisories/unreviewed/2022/05/GHSA-vrgx-7r4m-fqpg/GHSA-vrgx-7r4m-fqpg.json @@ -7,12 +7,8 @@ "CVE-2007-2371" ], "details": "admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows remote attackers to cause a denial of service (loss of configuration data), and possibly perform direct static code injection, via a saveGlobalconfig action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vrh3-hvpj-7864/GHSA-vrh3-hvpj-7864.json b/advisories/unreviewed/2022/05/GHSA-vrh3-hvpj-7864/GHSA-vrh3-hvpj-7864.json index 77039f85e64..0f63e6619fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrh3-hvpj-7864/GHSA-vrh3-hvpj-7864.json +++ b/advisories/unreviewed/2022/05/GHSA-vrh3-hvpj-7864/GHSA-vrh3-hvpj-7864.json @@ -7,12 +7,8 @@ "CVE-2007-2627" ], "details": "Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF), a different vulnerability than CVE-2007-1622.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vrqh-qwvr-mr23/GHSA-vrqh-qwvr-mr23.json b/advisories/unreviewed/2022/05/GHSA-vrqh-qwvr-mr23/GHSA-vrqh-qwvr-mr23.json index e5fd269223c..94370d2ff45 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrqh-qwvr-mr23/GHSA-vrqh-qwvr-mr23.json +++ b/advisories/unreviewed/2022/05/GHSA-vrqh-qwvr-mr23/GHSA-vrqh-qwvr-mr23.json @@ -7,12 +7,8 @@ "CVE-2007-2170" ], "details": "The APPLSYS.FND_DM_NODES package in Oracle E-Business Suite does not check for valid sessions, which allows remote attackers to delete arbitrary nodes. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE identifiers such as CVE-2007-2126, CVE-2007-2127, or CVE-2007-2128.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vw24-x99x-q736/GHSA-vw24-x99x-q736.json b/advisories/unreviewed/2022/05/GHSA-vw24-x99x-q736/GHSA-vw24-x99x-q736.json index a8696291ce2..21c535f782a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw24-x99x-q736/GHSA-vw24-x99x-q736.json +++ b/advisories/unreviewed/2022/05/GHSA-vw24-x99x-q736/GHSA-vw24-x99x-q736.json @@ -7,12 +7,8 @@ "CVE-2007-2481" ], "details": "PHP remote file inclusion vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vwph-q4w8-v42m/GHSA-vwph-q4w8-v42m.json b/advisories/unreviewed/2022/05/GHSA-vwph-q4w8-v42m/GHSA-vwph-q4w8-v42m.json index 68de1589739..4e7a424113f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwph-q4w8-v42m/GHSA-vwph-q4w8-v42m.json +++ b/advisories/unreviewed/2022/05/GHSA-vwph-q4w8-v42m/GHSA-vwph-q4w8-v42m.json @@ -7,12 +7,8 @@ "CVE-2007-2368" ], "details": "picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vwxq-hvr2-6m4q/GHSA-vwxq-hvr2-6m4q.json b/advisories/unreviewed/2022/05/GHSA-vwxq-hvr2-6m4q/GHSA-vwxq-hvr2-6m4q.json index be2c4604789..1411b653a25 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwxq-hvr2-6m4q/GHSA-vwxq-hvr2-6m4q.json +++ b/advisories/unreviewed/2022/05/GHSA-vwxq-hvr2-6m4q/GHSA-vwxq-hvr2-6m4q.json @@ -7,12 +7,8 @@ "CVE-2007-2406" ], "details": "Quartz Composer on Apple Mac OS X 10.4.10 does not initialize a certain object pointer, which might allow user-assisted remote attackers to execute arbitrary code via a crafted Quartz Composer file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w22m-8gr9-p75j/GHSA-w22m-8gr9-p75j.json b/advisories/unreviewed/2022/05/GHSA-w22m-8gr9-p75j/GHSA-w22m-8gr9-p75j.json index cc0a18888dc..2fcdb7711d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-w22m-8gr9-p75j/GHSA-w22m-8gr9-p75j.json +++ b/advisories/unreviewed/2022/05/GHSA-w22m-8gr9-p75j/GHSA-w22m-8gr9-p75j.json @@ -7,12 +7,8 @@ "CVE-2007-2488" ], "details": "The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss of transmitted data, and possibly obtain sensitive information (memory contents) or cause a denial of service (application crash), by sending a frame that lacks a 0 byte.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w2cx-3pp9-7qw4/GHSA-w2cx-3pp9-7qw4.json b/advisories/unreviewed/2022/05/GHSA-w2cx-3pp9-7qw4/GHSA-w2cx-3pp9-7qw4.json index 5c86f8d2398..a849cb37a02 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2cx-3pp9-7qw4/GHSA-w2cx-3pp9-7qw4.json +++ b/advisories/unreviewed/2022/05/GHSA-w2cx-3pp9-7qw4/GHSA-w2cx-3pp9-7qw4.json @@ -7,12 +7,8 @@ "CVE-2007-2149" ], "details": "Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier stores usernames and unencrypted passwords in (1) classes/vars.php and (2) classes/varstuff.php, and recommends 0666 or 0777 permissions for these files, which allows local users to gain privileges by reading the files, and allows remote attackers to obtain credentials via a direct request for admin/options.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w2cx-mr55-3j2f/GHSA-w2cx-mr55-3j2f.json b/advisories/unreviewed/2022/05/GHSA-w2cx-mr55-3j2f/GHSA-w2cx-mr55-3j2f.json index 4bd9e47be71..71bbc84a987 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2cx-mr55-3j2f/GHSA-w2cx-mr55-3j2f.json +++ b/advisories/unreviewed/2022/05/GHSA-w2cx-mr55-3j2f/GHSA-w2cx-mr55-3j2f.json @@ -7,12 +7,8 @@ "CVE-2007-2372" ], "details": "admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and list_id fields; and send the message via a direct request for the MsgId value under admin/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w2p4-pwh6-fg6p/GHSA-w2p4-pwh6-fg6p.json b/advisories/unreviewed/2022/05/GHSA-w2p4-pwh6-fg6p/GHSA-w2p4-pwh6-fg6p.json index b14f954706c..81651e9221e 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2p4-pwh6-fg6p/GHSA-w2p4-pwh6-fg6p.json +++ b/advisories/unreviewed/2022/05/GHSA-w2p4-pwh6-fg6p/GHSA-w2p4-pwh6-fg6p.json @@ -7,12 +7,8 @@ "CVE-2007-2144" ], "details": "PHP remote file inclusion vulnerability in includes/CAltInstaller.php in the JoomlaPack (com_jpack) 1.0.4a2 RE component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w3jr-jp8f-r2vr/GHSA-w3jr-jp8f-r2vr.json b/advisories/unreviewed/2022/05/GHSA-w3jr-jp8f-r2vr/GHSA-w3jr-jp8f-r2vr.json index ad46a02b10b..fa7b07fa336 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3jr-jp8f-r2vr/GHSA-w3jr-jp8f-r2vr.json +++ b/advisories/unreviewed/2022/05/GHSA-w3jr-jp8f-r2vr/GHSA-w3jr-jp8f-r2vr.json @@ -7,12 +7,8 @@ "CVE-2007-2297" ], "details": "The SIP channel driver (chan_sip) in Asterisk before 1.2.18 and 1.4.x before 1.4.3 does not properly parse SIP UDP packets that do not contain a valid response code, which allows remote attackers to cause a denial of service (crash).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w3ph-xq76-6prc/GHSA-w3ph-xq76-6prc.json b/advisories/unreviewed/2022/05/GHSA-w3ph-xq76-6prc/GHSA-w3ph-xq76-6prc.json index 74667752bd0..73f71bedf8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3ph-xq76-6prc/GHSA-w3ph-xq76-6prc.json +++ b/advisories/unreviewed/2022/05/GHSA-w3ph-xq76-6prc/GHSA-w3ph-xq76-6prc.json @@ -7,12 +7,8 @@ "CVE-2007-2242" ], "details": "The IPv6 protocol allows remote attackers to cause a denial of service via crafted IPv6 type 0 route headers (IPV6_RTHDR_TYPE_0) that create network amplification between two routers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -172,9 +168,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w43h-5c7v-39w8/GHSA-w43h-5c7v-39w8.json b/advisories/unreviewed/2022/05/GHSA-w43h-5c7v-39w8/GHSA-w43h-5c7v-39w8.json index 9608c8078c8..edab03022a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-w43h-5c7v-39w8/GHSA-w43h-5c7v-39w8.json +++ b/advisories/unreviewed/2022/05/GHSA-w43h-5c7v-39w8/GHSA-w43h-5c7v-39w8.json @@ -7,12 +7,8 @@ "CVE-2007-2608" ], "details": "PHP remote file inclusion vulnerability in lib/smarty/SmartyFU.class.php in Miplex2 Alpha 1 allows remote attackers to execute arbitrary PHP code via a URL in the system[smarty][dir] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w4mm-7hr6-qxr5/GHSA-w4mm-7hr6-qxr5.json b/advisories/unreviewed/2022/05/GHSA-w4mm-7hr6-qxr5/GHSA-w4mm-7hr6-qxr5.json index 12a8df3ec92..89f64e33eb1 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4mm-7hr6-qxr5/GHSA-w4mm-7hr6-qxr5.json +++ b/advisories/unreviewed/2022/05/GHSA-w4mm-7hr6-qxr5/GHSA-w4mm-7hr6-qxr5.json @@ -7,12 +7,8 @@ "CVE-2007-2439" ], "details": "Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to cause a denial of service (device hang) and read data from a COM or LPT device via a DOS device name with an arbitrary extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w4p3-mf5w-2mr6/GHSA-w4p3-mf5w-2mr6.json b/advisories/unreviewed/2022/05/GHSA-w4p3-mf5w-2mr6/GHSA-w4p3-mf5w-2mr6.json index 6d95ecfa504..7ba05eebd0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4p3-mf5w-2mr6/GHSA-w4p3-mf5w-2mr6.json +++ b/advisories/unreviewed/2022/05/GHSA-w4p3-mf5w-2mr6/GHSA-w4p3-mf5w-2mr6.json @@ -7,12 +7,8 @@ "CVE-2007-2519" ], "details": "Directory traversal vulnerability in the installer in PEAR 1.0 through 1.5.3 allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the (1) install-as attribute in the file element in package.xml 1.0 or the (2) as attribute in the install element in package.xml 2.0. NOTE: it could be argued that this does not cross privilege boundaries in typical installations, since the code being installed could perform the same actions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w4r7-hg3m-m4gf/GHSA-w4r7-hg3m-m4gf.json b/advisories/unreviewed/2022/05/GHSA-w4r7-hg3m-m4gf/GHSA-w4r7-hg3m-m4gf.json index 013a48705c3..c46587d07cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4r7-hg3m-m4gf/GHSA-w4r7-hg3m-m4gf.json +++ b/advisories/unreviewed/2022/05/GHSA-w4r7-hg3m-m4gf/GHSA-w4r7-hg3m-m4gf.json @@ -7,12 +7,8 @@ "CVE-2007-2512" ], "details": "Alcatel-Lucent IP-Touch Telephone running OmniPCX Enterprise 7.0 and later enables the mini switch by default, which allows attackers to gain access to the voice VLAN via daisy-chained systems.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w595-h3v3-m9rf/GHSA-w595-h3v3-m9rf.json b/advisories/unreviewed/2022/05/GHSA-w595-h3v3-m9rf/GHSA-w595-h3v3-m9rf.json index 5ae87d46e3e..6b6ddcdc033 100644 --- a/advisories/unreviewed/2022/05/GHSA-w595-h3v3-m9rf/GHSA-w595-h3v3-m9rf.json +++ b/advisories/unreviewed/2022/05/GHSA-w595-h3v3-m9rf/GHSA-w595-h3v3-m9rf.json @@ -7,12 +7,8 @@ "CVE-2007-2593" ], "details": "The Terminal Server in Microsoft Windows 2003 Server, when using TLS, allows remote attackers to bypass SSL and self-signed certificate requirements, downgrade the server security, and possibly conduct man-in-the-middle attacks via unspecified vectors, as demonstrated using the Remote Desktop Protocol (RDP) 6.0 client. NOTE: a third party claims that the vendor may have fixed this in approximately 2006.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w652-7cch-5354/GHSA-w652-7cch-5354.json b/advisories/unreviewed/2022/05/GHSA-w652-7cch-5354/GHSA-w652-7cch-5354.json index c4b0886f63c..eeeb2a943be 100644 --- a/advisories/unreviewed/2022/05/GHSA-w652-7cch-5354/GHSA-w652-7cch-5354.json +++ b/advisories/unreviewed/2022/05/GHSA-w652-7cch-5354/GHSA-w652-7cch-5354.json @@ -7,12 +7,8 @@ "CVE-2007-2258" ], "details": "PHP remote file inclusion vulnerability in includes/init.inc.php in PHPMyBibli allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w77h-x78h-77gv/GHSA-w77h-x78h-77gv.json b/advisories/unreviewed/2022/05/GHSA-w77h-x78h-77gv/GHSA-w77h-x78h-77gv.json index 3e0dd3cf12e..f10078aed84 100644 --- a/advisories/unreviewed/2022/05/GHSA-w77h-x78h-77gv/GHSA-w77h-x78h-77gv.json +++ b/advisories/unreviewed/2022/05/GHSA-w77h-x78h-77gv/GHSA-w77h-x78h-77gv.json @@ -7,12 +7,8 @@ "CVE-2007-2232" ], "details": "The CHECK command in Cosign 2.0.1 and earlier allows remote attackers to bypass authentication requirements via CR (\\r) sequences in the cosign cookie parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w7gg-m9pv-r528/GHSA-w7gg-m9pv-r528.json b/advisories/unreviewed/2022/05/GHSA-w7gg-m9pv-r528/GHSA-w7gg-m9pv-r528.json index 3db31b2bf44..9d8cdfc6e77 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7gg-m9pv-r528/GHSA-w7gg-m9pv-r528.json +++ b/advisories/unreviewed/2022/05/GHSA-w7gg-m9pv-r528/GHSA-w7gg-m9pv-r528.json @@ -7,12 +7,8 @@ "CVE-2007-2335" ], "details": "Cross-site scripting (XSS) vulnerability in the RSS feed reader functionality in Lunascape 4.1.3 build2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w8jf-2gpq-9xxx/GHSA-w8jf-2gpq-9xxx.json b/advisories/unreviewed/2022/05/GHSA-w8jf-2gpq-9xxx/GHSA-w8jf-2gpq-9xxx.json index b88579924e5..d56d2b2f087 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8jf-2gpq-9xxx/GHSA-w8jf-2gpq-9xxx.json +++ b/advisories/unreviewed/2022/05/GHSA-w8jf-2gpq-9xxx/GHSA-w8jf-2gpq-9xxx.json @@ -7,12 +7,8 @@ "CVE-2007-2618" ], "details": "CRLF injection vulnerability in index.php in Drake CMS 0.4.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the lang parameter. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated \"We do not consider security reports valid until the first official release of Drake CMS.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w974-2v58-4q97/GHSA-w974-2v58-4q97.json b/advisories/unreviewed/2022/05/GHSA-w974-2v58-4q97/GHSA-w974-2v58-4q97.json index 50e0d2c341a..7eea4157813 100644 --- a/advisories/unreviewed/2022/05/GHSA-w974-2v58-4q97/GHSA-w974-2v58-4q97.json +++ b/advisories/unreviewed/2022/05/GHSA-w974-2v58-4q97/GHSA-w974-2v58-4q97.json @@ -7,12 +7,8 @@ "CVE-2007-2656" ], "details": "Stack-based buffer overflow in the Hewlett-Packard (HP) Magview ActiveX control in hpqvwocx.dll 1.0.0.309 allows remote attackers to cause a denial of service (application crash) and possibly have other impact via a long argument to the DeleteProfile method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w97x-8w5v-6mh4/GHSA-w97x-8w5v-6mh4.json b/advisories/unreviewed/2022/05/GHSA-w97x-8w5v-6mh4/GHSA-w97x-8w5v-6mh4.json index 46dc1f76bb9..353295c32b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-w97x-8w5v-6mh4/GHSA-w97x-8w5v-6mh4.json +++ b/advisories/unreviewed/2022/05/GHSA-w97x-8w5v-6mh4/GHSA-w97x-8w5v-6mh4.json @@ -7,12 +7,8 @@ "CVE-2007-2379" ], "details": "The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka \"JavaScript Hijacking.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wc7m-24r5-4cvw/GHSA-wc7m-24r5-4cvw.json b/advisories/unreviewed/2022/05/GHSA-wc7m-24r5-4cvw/GHSA-wc7m-24r5-4cvw.json index f8e6aa3895e..4ff283c2b68 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc7m-24r5-4cvw/GHSA-wc7m-24r5-4cvw.json +++ b/advisories/unreviewed/2022/05/GHSA-wc7m-24r5-4cvw/GHSA-wc7m-24r5-4cvw.json @@ -7,12 +7,8 @@ "CVE-2007-2183" ], "details": "SQL injection vulnerability in index.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9 allows remote attackers to execute arbitrary SQL commands via the ring parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wf7g-p3ph-4jgq/GHSA-wf7g-p3ph-4jgq.json b/advisories/unreviewed/2022/05/GHSA-wf7g-p3ph-4jgq/GHSA-wf7g-p3ph-4jgq.json index 67986218474..0250868322b 100644 --- a/advisories/unreviewed/2022/05/GHSA-wf7g-p3ph-4jgq/GHSA-wf7g-p3ph-4jgq.json +++ b/advisories/unreviewed/2022/05/GHSA-wf7g-p3ph-4jgq/GHSA-wf7g-p3ph-4jgq.json @@ -7,12 +7,8 @@ "CVE-2007-1989" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in DotClear before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post_id parameter to ecrire/trackback.php or the (2) tool_url parameter to tools/thememng/index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wf94-c37g-7c29/GHSA-wf94-c37g-7c29.json b/advisories/unreviewed/2022/05/GHSA-wf94-c37g-7c29/GHSA-wf94-c37g-7c29.json index 2c3475ae59f..7adff2b2011 100644 --- a/advisories/unreviewed/2022/05/GHSA-wf94-c37g-7c29/GHSA-wf94-c37g-7c29.json +++ b/advisories/unreviewed/2022/05/GHSA-wf94-c37g-7c29/GHSA-wf94-c37g-7c29.json @@ -7,12 +7,8 @@ "CVE-2007-2130" ], "details": "Unspecified vulnerability in Workflow Cartridge, as used in Oracle Database Server 9.2.0.1, 10.1.0.2, and 10.2.0.1; Application Server 9.0.4.3 and 10.1.2.0.2; Collaboration Suite 10.1.2; and E-Business Suite; has unknown impact and remote authenticated attack vectors, aka OWF01.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wjj7-rg76-c4fh/GHSA-wjj7-rg76-c4fh.json b/advisories/unreviewed/2022/05/GHSA-wjj7-rg76-c4fh/GHSA-wjj7-rg76-c4fh.json index eae964bbed8..9b14717e6b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjj7-rg76-c4fh/GHSA-wjj7-rg76-c4fh.json +++ b/advisories/unreviewed/2022/05/GHSA-wjj7-rg76-c4fh/GHSA-wjj7-rg76-c4fh.json @@ -7,12 +7,8 @@ "CVE-2007-2206" ], "details": "Cross-site scripting (XSS) vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a leading \"<"<\" in the ripeformpost parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wm52-v3hr-63v8/GHSA-wm52-v3hr-63v8.json b/advisories/unreviewed/2022/05/GHSA-wm52-v3hr-63v8/GHSA-wm52-v3hr-63v8.json index 7277f738ed3..2a9fdfe3f9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wm52-v3hr-63v8/GHSA-wm52-v3hr-63v8.json +++ b/advisories/unreviewed/2022/05/GHSA-wm52-v3hr-63v8/GHSA-wm52-v3hr-63v8.json @@ -7,12 +7,8 @@ "CVE-2007-2303" ], "details": "Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wmjh-g52p-x87p/GHSA-wmjh-g52p-x87p.json b/advisories/unreviewed/2022/05/GHSA-wmjh-g52p-x87p/GHSA-wmjh-g52p-x87p.json index 942bc9585a5..2630650a25e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmjh-g52p-x87p/GHSA-wmjh-g52p-x87p.json +++ b/advisories/unreviewed/2022/05/GHSA-wmjh-g52p-x87p/GHSA-wmjh-g52p-x87p.json @@ -7,12 +7,8 @@ "CVE-2007-1996" ], "details": "PHP remote file inclusion vulnerability in codebreak.php in CodeBreak, probably 1.1.2 and earlier, allows remote attackers to execute arbitrary PHP code via a URL in the process_method parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wp93-g5p4-57jw/GHSA-wp93-g5p4-57jw.json b/advisories/unreviewed/2022/05/GHSA-wp93-g5p4-57jw/GHSA-wp93-g5p4-57jw.json index f45c3b0848d..82f0a1966fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-wp93-g5p4-57jw/GHSA-wp93-g5p4-57jw.json +++ b/advisories/unreviewed/2022/05/GHSA-wp93-g5p4-57jw/GHSA-wp93-g5p4-57jw.json @@ -7,12 +7,8 @@ "CVE-2007-2657" ], "details": "Unspecified vulnerability in the PrecisionID Barcode 1.3 ActiveX control in PrecisionID_DataMatrix.DLL allows remote attackers to cause a denial of service via a long argument to the SaveBarCode method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wpfg-wmp7-mj7g/GHSA-wpfg-wmp7-mj7g.json b/advisories/unreviewed/2022/05/GHSA-wpfg-wmp7-mj7g/GHSA-wpfg-wmp7-mj7g.json index 9f05484e7bc..e35950fdb3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpfg-wmp7-mj7g/GHSA-wpfg-wmp7-mj7g.json +++ b/advisories/unreviewed/2022/05/GHSA-wpfg-wmp7-mj7g/GHSA-wpfg-wmp7-mj7g.json @@ -7,12 +7,8 @@ "CVE-2007-2210" ], "details": "A certain ActiveX control in askPopStp.dll in Netsprint Ask IE Toolbar 1.1 allows remote attackers to cause a denial of service (Internet Explorer crash) via a long AddAllowed property value, related to \"improper memory handling,\" possibly a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wppq-5927-w9p8/GHSA-wppq-5927-w9p8.json b/advisories/unreviewed/2022/05/GHSA-wppq-5927-w9p8/GHSA-wppq-5927-w9p8.json index 2cd29d36913..9de262913ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-wppq-5927-w9p8/GHSA-wppq-5927-w9p8.json +++ b/advisories/unreviewed/2022/05/GHSA-wppq-5927-w9p8/GHSA-wppq-5927-w9p8.json @@ -7,12 +7,8 @@ "CVE-2007-1999" ], "details": "PHP remote file inclusion vulnerability in index.php in Weatimages 1.7.1 and earlier, when weatimages.ini is missing, allows remote attackers to execute arbitrary PHP code via a URL in the ini[langpack] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wpx4-v8wc-37cm/GHSA-wpx4-v8wc-37cm.json b/advisories/unreviewed/2022/05/GHSA-wpx4-v8wc-37cm/GHSA-wpx4-v8wc-37cm.json index 5cb60e79a32..20f32a4e64d 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpx4-v8wc-37cm/GHSA-wpx4-v8wc-37cm.json +++ b/advisories/unreviewed/2022/05/GHSA-wpx4-v8wc-37cm/GHSA-wpx4-v8wc-37cm.json @@ -7,12 +7,8 @@ "CVE-2007-2180" ], "details": "Buffer overflow in Nullsoft Winamp 5.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted WMV file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wr78-fj5w-cgcv/GHSA-wr78-fj5w-cgcv.json b/advisories/unreviewed/2022/05/GHSA-wr78-fj5w-cgcv/GHSA-wr78-fj5w-cgcv.json index e8009636cc7..772fe3462af 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr78-fj5w-cgcv/GHSA-wr78-fj5w-cgcv.json +++ b/advisories/unreviewed/2022/05/GHSA-wr78-fj5w-cgcv/GHSA-wr78-fj5w-cgcv.json @@ -7,12 +7,8 @@ "CVE-2007-2388" ], "details": "Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not properly restrict QTObject subclassing, which allows remote attackers to execute arbitrary code via a web page containing a user-defined class that accesses unsafe functions that can be leveraged to write to arbitrary memory locations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wv2c-652m-j8wx/GHSA-wv2c-652m-j8wx.json b/advisories/unreviewed/2022/05/GHSA-wv2c-652m-j8wx/GHSA-wv2c-652m-j8wx.json index c1e9d97b4b5..097cdfff7ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv2c-652m-j8wx/GHSA-wv2c-652m-j8wx.json +++ b/advisories/unreviewed/2022/05/GHSA-wv2c-652m-j8wx/GHSA-wv2c-652m-j8wx.json @@ -7,12 +7,8 @@ "CVE-2007-2207" ], "details": "SQL injection vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ripeformpost parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x29q-pqw3-mf49/GHSA-x29q-pqw3-mf49.json b/advisories/unreviewed/2022/05/GHSA-x29q-pqw3-mf49/GHSA-x29q-pqw3-mf49.json index 16f37ef44c1..601969cecc5 100644 --- a/advisories/unreviewed/2022/05/GHSA-x29q-pqw3-mf49/GHSA-x29q-pqw3-mf49.json +++ b/advisories/unreviewed/2022/05/GHSA-x29q-pqw3-mf49/GHSA-x29q-pqw3-mf49.json @@ -7,12 +7,8 @@ "CVE-2007-2431" ], "details": "Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earlier allows remote attackers to conduct cross-site scripting (XSS) and possibly other attacks by modifying critical variables such as $_SERVER, as demonstrated by injecting web script via the _SERVER[SCRIPT_NAME] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x2c8-h488-vjrg/GHSA-x2c8-h488-vjrg.json b/advisories/unreviewed/2022/05/GHSA-x2c8-h488-vjrg/GHSA-x2c8-h488-vjrg.json index 199fe5a5ef3..bcc25a7a534 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2c8-h488-vjrg/GHSA-x2c8-h488-vjrg.json +++ b/advisories/unreviewed/2022/05/GHSA-x2c8-h488-vjrg/GHSA-x2c8-h488-vjrg.json @@ -7,12 +7,8 @@ "CVE-2007-2265" ], "details": "Cross-site scripting (XSS) vulnerability in YA Book 0.98-alpha allows remote attackers to inject arbitrary web script or HTML via the City field in a sign action in index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x2f5-352x-j9w7/GHSA-x2f5-352x-j9w7.json b/advisories/unreviewed/2022/05/GHSA-x2f5-352x-j9w7/GHSA-x2f5-352x-j9w7.json index ff7390fdef7..1b462498d9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2f5-352x-j9w7/GHSA-x2f5-352x-j9w7.json +++ b/advisories/unreviewed/2022/05/GHSA-x2f5-352x-j9w7/GHSA-x2f5-352x-j9w7.json @@ -7,12 +7,8 @@ "CVE-2007-2438" ], "details": "The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow user-assisted attackers to execute shell commands and write files via modelines.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -140,9 +136,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x2w6-mjgc-ggqw/GHSA-x2w6-mjgc-ggqw.json b/advisories/unreviewed/2022/05/GHSA-x2w6-mjgc-ggqw/GHSA-x2w6-mjgc-ggqw.json index a719de09010..55d96c8f241 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2w6-mjgc-ggqw/GHSA-x2w6-mjgc-ggqw.json +++ b/advisories/unreviewed/2022/05/GHSA-x2w6-mjgc-ggqw/GHSA-x2w6-mjgc-ggqw.json @@ -7,12 +7,8 @@ "CVE-2007-2590" ], "details": "Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to obtain user names and other sensitive information via a direct request to (1) usrmgr/userList.asp or (2) usrmgr/userStatusList.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3cm-hj4w-q575/GHSA-x3cm-hj4w-q575.json b/advisories/unreviewed/2022/05/GHSA-x3cm-hj4w-q575/GHSA-x3cm-hj4w-q575.json index 46c36d53ccb..5fe3128cace 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3cm-hj4w-q575/GHSA-x3cm-hj4w-q575.json +++ b/advisories/unreviewed/2022/05/GHSA-x3cm-hj4w-q575/GHSA-x3cm-hj4w-q575.json @@ -7,12 +7,8 @@ "CVE-2007-2365" ], "details": "Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3rw-f6gx-r4vr/GHSA-x3rw-f6gx-r4vr.json b/advisories/unreviewed/2022/05/GHSA-x3rw-f6gx-r4vr/GHSA-x3rw-f6gx-r4vr.json index a7adb80d298..5021cfa763a 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3rw-f6gx-r4vr/GHSA-x3rw-f6gx-r4vr.json +++ b/advisories/unreviewed/2022/05/GHSA-x3rw-f6gx-r4vr/GHSA-x3rw-f6gx-r4vr.json @@ -7,12 +7,8 @@ "CVE-2007-2257" ], "details": "PHP remote file inclusion vulnerability in subscp.php in Fully Modded phpBB2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x3xg-mc2f-hj3q/GHSA-x3xg-mc2f-hj3q.json b/advisories/unreviewed/2022/05/GHSA-x3xg-mc2f-hj3q/GHSA-x3xg-mc2f-hj3q.json index a34eabb8c8e..a1fc7fcb4a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3xg-mc2f-hj3q/GHSA-x3xg-mc2f-hj3q.json +++ b/advisories/unreviewed/2022/05/GHSA-x3xg-mc2f-hj3q/GHSA-x3xg-mc2f-hj3q.json @@ -7,12 +7,8 @@ "CVE-2007-2021" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Pineapple Technologies Lore 1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang_path parameter to third_party/phpmailer/class.phpmailer.php or the (2) get_plugin_file_path parameter to third_party/smarty/libs/plugins/function.html_checkboxes.php. NOTE: the affected files might be from other software packages, so this might not be a vulnerability in Lore itself. NOTE: (1) might be the same issue as CVE-2006-5734.4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x48p-7gcv-2946/GHSA-x48p-7gcv-2946.json b/advisories/unreviewed/2022/05/GHSA-x48p-7gcv-2946/GHSA-x48p-7gcv-2946.json index 4387689617e..16cb887be5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x48p-7gcv-2946/GHSA-x48p-7gcv-2946.json +++ b/advisories/unreviewed/2022/05/GHSA-x48p-7gcv-2946/GHSA-x48p-7gcv-2946.json @@ -7,12 +7,8 @@ "CVE-2007-2668" ], "details": "Buffer overflow in webdesproxy 0.0.1 allows remote attackers to execute arbitrary code via a long URL, possibly involving the process_connection_request function in webdesproxy.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x7qh-xv7g-wv62/GHSA-x7qh-xv7g-wv62.json b/advisories/unreviewed/2022/05/GHSA-x7qh-xv7g-wv62/GHSA-x7qh-xv7g-wv62.json index 78da874a239..1d92153a4c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7qh-xv7g-wv62/GHSA-x7qh-xv7g-wv62.json +++ b/advisories/unreviewed/2022/05/GHSA-x7qh-xv7g-wv62/GHSA-x7qh-xv7g-wv62.json @@ -7,12 +7,8 @@ "CVE-2007-2587" ], "details": "The IOS FTP Server in Cisco IOS 11.3 through 12.4 allows remote authenticated users to cause a denial of service (IOS reload) via unspecified vectors involving transferring files (aka bug ID CSCse29244).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x894-663w-mqmw/GHSA-x894-663w-mqmw.json b/advisories/unreviewed/2022/05/GHSA-x894-663w-mqmw/GHSA-x894-663w-mqmw.json index 83f6ca6d5c2..3355ed1b66d 100644 --- a/advisories/unreviewed/2022/05/GHSA-x894-663w-mqmw/GHSA-x894-663w-mqmw.json +++ b/advisories/unreviewed/2022/05/GHSA-x894-663w-mqmw/GHSA-x894-663w-mqmw.json @@ -7,12 +7,8 @@ "CVE-2007-2367" ], "details": "Buffer overflow in wserve_console.exe in Wserve HTTP Server (whttp) 4.6 allows remote attackers to cause a denial of service (forced application exit) via a long directory name in the URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xcjr-h88g-mrg5/GHSA-xcjr-h88g-mrg5.json b/advisories/unreviewed/2022/05/GHSA-xcjr-h88g-mrg5/GHSA-xcjr-h88g-mrg5.json index 921f72f7ed2..d53f62f84c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcjr-h88g-mrg5/GHSA-xcjr-h88g-mrg5.json +++ b/advisories/unreviewed/2022/05/GHSA-xcjr-h88g-mrg5/GHSA-xcjr-h88g-mrg5.json @@ -7,12 +7,8 @@ "CVE-2007-2134" ], "details": "Unspecified vulnerability in the HTML Server in Oracle JD Edwards EnterpriseOne SP23_Q1 and 8.96.I1 has unknown impact and local attack vectors, aka JDE01.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xcrc-x88c-9gc9/GHSA-xcrc-x88c-9gc9.json b/advisories/unreviewed/2022/05/GHSA-xcrc-x88c-9gc9/GHSA-xcrc-x88c-9gc9.json index 8e2b35f9b59..44e13dc9437 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcrc-x88c-9gc9/GHSA-xcrc-x88c-9gc9.json +++ b/advisories/unreviewed/2022/05/GHSA-xcrc-x88c-9gc9/GHSA-xcrc-x88c-9gc9.json @@ -7,12 +7,8 @@ "CVE-2007-2152" ], "details": "Buffer overflow in the On-Access Scanner in McAfee VirusScan Enterprise before 8.0i Patch 12 allows user-assisted remote attackers to execute arbitrary code via a long filename containing multi-byte (Unicode) characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xcv3-8774-8394/GHSA-xcv3-8774-8394.json b/advisories/unreviewed/2022/05/GHSA-xcv3-8774-8394/GHSA-xcv3-8774-8394.json index 63078479d35..e6e327d2cb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcv3-8774-8394/GHSA-xcv3-8774-8394.json +++ b/advisories/unreviewed/2022/05/GHSA-xcv3-8774-8394/GHSA-xcv3-8774-8394.json @@ -7,12 +7,8 @@ "CVE-2007-2509" ], "details": "CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xfjm-f4wh-hqq3/GHSA-xfjm-f4wh-hqq3.json b/advisories/unreviewed/2022/05/GHSA-xfjm-f4wh-hqq3/GHSA-xfjm-f4wh-hqq3.json index bde2d398809..c52a70d2c2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xfjm-f4wh-hqq3/GHSA-xfjm-f4wh-hqq3.json +++ b/advisories/unreviewed/2022/05/GHSA-xfjm-f4wh-hqq3/GHSA-xfjm-f4wh-hqq3.json @@ -7,12 +7,8 @@ "CVE-2007-2219" ], "details": "Unspecified vulnerability in the Win32 API on Microsoft Windows 2000, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via certain parameters to an unspecified function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xfpr-jqm6-vw54/GHSA-xfpr-jqm6-vw54.json b/advisories/unreviewed/2022/05/GHSA-xfpr-jqm6-vw54/GHSA-xfpr-jqm6-vw54.json index ac47c034e8c..da814169cbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-xfpr-jqm6-vw54/GHSA-xfpr-jqm6-vw54.json +++ b/advisories/unreviewed/2022/05/GHSA-xfpr-jqm6-vw54/GHSA-xfpr-jqm6-vw54.json @@ -7,12 +7,8 @@ "CVE-2007-1979" ], "details": "SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the postid parameter, possibly involving the get_blogid_from_postid function in class/PopnupBlogUtils.php. NOTE: later versions such as 3.03 and 3.05 might also be affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xh3h-4jg9-r3p2/GHSA-xh3h-4jg9-r3p2.json b/advisories/unreviewed/2022/05/GHSA-xh3h-4jg9-r3p2/GHSA-xh3h-4jg9-r3p2.json index 7e51bc72c62..0889ea61db6 100644 --- a/advisories/unreviewed/2022/05/GHSA-xh3h-4jg9-r3p2/GHSA-xh3h-4jg9-r3p2.json +++ b/advisories/unreviewed/2022/05/GHSA-xh3h-4jg9-r3p2/GHSA-xh3h-4jg9-r3p2.json @@ -7,12 +7,8 @@ "CVE-2007-2223" ], "details": "Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xm6g-87mj-5cf7/GHSA-xm6g-87mj-5cf7.json b/advisories/unreviewed/2022/05/GHSA-xm6g-87mj-5cf7/GHSA-xm6g-87mj-5cf7.json index 4e2e25a2a19..2a1a79822bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm6g-87mj-5cf7/GHSA-xm6g-87mj-5cf7.json +++ b/advisories/unreviewed/2022/05/GHSA-xm6g-87mj-5cf7/GHSA-xm6g-87mj-5cf7.json @@ -7,12 +7,8 @@ "CVE-2007-2125" ], "details": "Unspecified vulnerability in Collaborative Workspace in Oracle Collaboration Suite 10.1.2 has unknown impact and attack vectors, aka OCS01.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xm85-v7jp-c72p/GHSA-xm85-v7jp-c72p.json b/advisories/unreviewed/2022/05/GHSA-xm85-v7jp-c72p/GHSA-xm85-v7jp-c72p.json index 4c13818b77e..f5329f59d1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm85-v7jp-c72p/GHSA-xm85-v7jp-c72p.json +++ b/advisories/unreviewed/2022/05/GHSA-xm85-v7jp-c72p/GHSA-xm85-v7jp-c72p.json @@ -7,12 +7,8 @@ "CVE-2007-2212" ], "details": "Multiple SQL injection vulnerabilities in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) month parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xpm5-rj8g-g87f/GHSA-xpm5-rj8g-g87f.json b/advisories/unreviewed/2022/05/GHSA-xpm5-rj8g-g87f/GHSA-xpm5-rj8g-g87f.json index 48bae3b8c48..c2868b5874c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xpm5-rj8g-g87f/GHSA-xpm5-rj8g-g87f.json +++ b/advisories/unreviewed/2022/05/GHSA-xpm5-rj8g-g87f/GHSA-xpm5-rj8g-g87f.json @@ -7,12 +7,8 @@ "CVE-2007-2565" ], "details": "Cdelia Software ImageProcessing allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted BMP file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xqp4-4g25-fhqx/GHSA-xqp4-4g25-fhqx.json b/advisories/unreviewed/2022/05/GHSA-xqp4-4g25-fhqx/GHSA-xqp4-4g25-fhqx.json index cbcdd2d06cf..e8f40509caf 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqp4-4g25-fhqx/GHSA-xqp4-4g25-fhqx.json +++ b/advisories/unreviewed/2022/05/GHSA-xqp4-4g25-fhqx/GHSA-xqp4-4g25-fhqx.json @@ -7,12 +7,8 @@ "CVE-2007-2551" ], "details": "Cross-site scripting (XSS) vulnerability in usersettings.php in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to inject arbitrary web script or HTML via the name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xr5r-hmj6-546j/GHSA-xr5r-hmj6-546j.json b/advisories/unreviewed/2022/05/GHSA-xr5r-hmj6-546j/GHSA-xr5r-hmj6-546j.json index 5713e92c937..fd68e6f42e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr5r-hmj6-546j/GHSA-xr5r-hmj6-546j.json +++ b/advisories/unreviewed/2022/05/GHSA-xr5r-hmj6-546j/GHSA-xr5r-hmj6-546j.json @@ -7,12 +7,8 @@ "CVE-2007-2540" ], "details": "Multiple PHP remote file inclusion vulnerabilities in PMECMS 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the config[pathMod] parameter to index.php in (1) mod/image/, (2) mod/liens/, (3) mod/liste/, (4) mod/special/, or (5) mod/texte/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xrff-wf45-h7mh/GHSA-xrff-wf45-h7mh.json b/advisories/unreviewed/2022/05/GHSA-xrff-wf45-h7mh/GHSA-xrff-wf45-h7mh.json index 551eb9dbedc..5eb5dd3e4ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-xrff-wf45-h7mh/GHSA-xrff-wf45-h7mh.json +++ b/advisories/unreviewed/2022/05/GHSA-xrff-wf45-h7mh/GHSA-xrff-wf45-h7mh.json @@ -7,12 +7,8 @@ "CVE-2007-2158" ], "details": "PHP remote file inclusion vulnerability in index.php in jGallery 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the G_JGALL[inc_path] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xrgw-2g7f-5735/GHSA-xrgw-2g7f-5735.json b/advisories/unreviewed/2022/05/GHSA-xrgw-2g7f-5735/GHSA-xrgw-2g7f-5735.json index 1816c9b479e..4d384f57473 100644 --- a/advisories/unreviewed/2022/05/GHSA-xrgw-2g7f-5735/GHSA-xrgw-2g7f-5735.json +++ b/advisories/unreviewed/2022/05/GHSA-xrgw-2g7f-5735/GHSA-xrgw-2g7f-5735.json @@ -7,12 +7,8 @@ "CVE-2007-2386" ], "details": "Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xw6r-x75r-2fh4/GHSA-xw6r-x75r-2fh4.json b/advisories/unreviewed/2022/05/GHSA-xw6r-x75r-2fh4/GHSA-xw6r-x75r-2fh4.json index eaa1dbbc59b..03d101d3f57 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw6r-x75r-2fh4/GHSA-xw6r-x75r-2fh4.json +++ b/advisories/unreviewed/2022/05/GHSA-xw6r-x75r-2fh4/GHSA-xw6r-x75r-2fh4.json @@ -7,12 +7,8 @@ "CVE-2007-2381" ], "details": "The MochiKit framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka \"JavaScript Hijacking.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xwv2-xfhg-6wqw/GHSA-xwv2-xfhg-6wqw.json b/advisories/unreviewed/2022/05/GHSA-xwv2-xfhg-6wqw/GHSA-xwv2-xfhg-6wqw.json index 37f4a587708..6829d344a82 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwv2-xfhg-6wqw/GHSA-xwv2-xfhg-6wqw.json +++ b/advisories/unreviewed/2022/05/GHSA-xwv2-xfhg-6wqw/GHSA-xwv2-xfhg-6wqw.json @@ -7,12 +7,8 @@ "CVE-2007-2663" ], "details": "PHP remote file inclusion vulnerability in language/1/splash.lang.php in Beacon 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the languagePath parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xx4g-mv9m-95fg/GHSA-xx4g-mv9m-95fg.json b/advisories/unreviewed/2022/05/GHSA-xx4g-mv9m-95fg/GHSA-xx4g-mv9m-95fg.json index 1c8cf5547b3..64f8f31d2e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-xx4g-mv9m-95fg/GHSA-xx4g-mv9m-95fg.json +++ b/advisories/unreviewed/2022/05/GHSA-xx4g-mv9m-95fg/GHSA-xx4g-mv9m-95fg.json @@ -7,12 +7,8 @@ "CVE-2007-2376" ], "details": "The Dojo framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka \"JavaScript Hijacking.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xxqh-84mj-whcj/GHSA-xxqh-84mj-whcj.json b/advisories/unreviewed/2022/05/GHSA-xxqh-84mj-whcj/GHSA-xxqh-84mj-whcj.json index ce0ec5eb361..a54bc019ea8 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxqh-84mj-whcj/GHSA-xxqh-84mj-whcj.json +++ b/advisories/unreviewed/2022/05/GHSA-xxqh-84mj-whcj/GHSA-xxqh-84mj-whcj.json @@ -7,12 +7,8 @@ "CVE-2007-2447" ], "details": "The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the \"username map script\" smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -240,9 +236,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/10/GHSA-2mqf-694r-32x9/GHSA-2mqf-694r-32x9.json b/advisories/unreviewed/2023/10/GHSA-2mqf-694r-32x9/GHSA-2mqf-694r-32x9.json index 3c1243e0ad7..1ab0d844227 100644 --- a/advisories/unreviewed/2023/10/GHSA-2mqf-694r-32x9/GHSA-2mqf-694r-32x9.json +++ b/advisories/unreviewed/2023/10/GHSA-2mqf-694r-32x9/GHSA-2mqf-694r-32x9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-3c9r-8wrp-84w3/GHSA-3c9r-8wrp-84w3.json b/advisories/unreviewed/2023/10/GHSA-3c9r-8wrp-84w3/GHSA-3c9r-8wrp-84w3.json index e1d8acd5d61..2d9e8fab70e 100644 --- a/advisories/unreviewed/2023/10/GHSA-3c9r-8wrp-84w3/GHSA-3c9r-8wrp-84w3.json +++ b/advisories/unreviewed/2023/10/GHSA-3c9r-8wrp-84w3/GHSA-3c9r-8wrp-84w3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-63h9-pmmv-4m65/GHSA-63h9-pmmv-4m65.json b/advisories/unreviewed/2023/10/GHSA-63h9-pmmv-4m65/GHSA-63h9-pmmv-4m65.json index 7f970f7aa59..01dc870e7a4 100644 --- a/advisories/unreviewed/2023/10/GHSA-63h9-pmmv-4m65/GHSA-63h9-pmmv-4m65.json +++ b/advisories/unreviewed/2023/10/GHSA-63h9-pmmv-4m65/GHSA-63h9-pmmv-4m65.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/10/GHSA-8j8g-9794-h995/GHSA-8j8g-9794-h995.json b/advisories/unreviewed/2023/10/GHSA-8j8g-9794-h995/GHSA-8j8g-9794-h995.json index 0ff1b9c74c7..7aafabedfc8 100644 --- a/advisories/unreviewed/2023/10/GHSA-8j8g-9794-h995/GHSA-8j8g-9794-h995.json +++ b/advisories/unreviewed/2023/10/GHSA-8j8g-9794-h995/GHSA-8j8g-9794-h995.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-93rg-x44m-w3fg/GHSA-93rg-x44m-w3fg.json b/advisories/unreviewed/2023/10/GHSA-93rg-x44m-w3fg/GHSA-93rg-x44m-w3fg.json index 4096282065d..5d0afee62f0 100644 --- a/advisories/unreviewed/2023/10/GHSA-93rg-x44m-w3fg/GHSA-93rg-x44m-w3fg.json +++ b/advisories/unreviewed/2023/10/GHSA-93rg-x44m-w3fg/GHSA-93rg-x44m-w3fg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-9jm2-h589-xc6m/GHSA-9jm2-h589-xc6m.json b/advisories/unreviewed/2023/10/GHSA-9jm2-h589-xc6m/GHSA-9jm2-h589-xc6m.json index fa7a9722701..e1e8d0aee2c 100644 --- a/advisories/unreviewed/2023/10/GHSA-9jm2-h589-xc6m/GHSA-9jm2-h589-xc6m.json +++ b/advisories/unreviewed/2023/10/GHSA-9jm2-h589-xc6m/GHSA-9jm2-h589-xc6m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/10/GHSA-9mvw-c7r6-xcpq/GHSA-9mvw-c7r6-xcpq.json b/advisories/unreviewed/2023/10/GHSA-9mvw-c7r6-xcpq/GHSA-9mvw-c7r6-xcpq.json index 81a5d0fad76..b5a81ca7337 100644 --- a/advisories/unreviewed/2023/10/GHSA-9mvw-c7r6-xcpq/GHSA-9mvw-c7r6-xcpq.json +++ b/advisories/unreviewed/2023/10/GHSA-9mvw-c7r6-xcpq/GHSA-9mvw-c7r6-xcpq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/10/GHSA-9qr5-85g4-f6rq/GHSA-9qr5-85g4-f6rq.json b/advisories/unreviewed/2023/10/GHSA-9qr5-85g4-f6rq/GHSA-9qr5-85g4-f6rq.json index 9c0af081b69..606683bbdd7 100644 --- a/advisories/unreviewed/2023/10/GHSA-9qr5-85g4-f6rq/GHSA-9qr5-85g4-f6rq.json +++ b/advisories/unreviewed/2023/10/GHSA-9qr5-85g4-f6rq/GHSA-9qr5-85g4-f6rq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-c5qj-vxvj-r553/GHSA-c5qj-vxvj-r553.json b/advisories/unreviewed/2023/10/GHSA-c5qj-vxvj-r553/GHSA-c5qj-vxvj-r553.json index 38f45c8e633..290b556e8ee 100644 --- a/advisories/unreviewed/2023/10/GHSA-c5qj-vxvj-r553/GHSA-c5qj-vxvj-r553.json +++ b/advisories/unreviewed/2023/10/GHSA-c5qj-vxvj-r553/GHSA-c5qj-vxvj-r553.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-cggm-fc75-c35c/GHSA-cggm-fc75-c35c.json b/advisories/unreviewed/2023/10/GHSA-cggm-fc75-c35c/GHSA-cggm-fc75-c35c.json index c4b655115bb..1ab81d646b2 100644 --- a/advisories/unreviewed/2023/10/GHSA-cggm-fc75-c35c/GHSA-cggm-fc75-c35c.json +++ b/advisories/unreviewed/2023/10/GHSA-cggm-fc75-c35c/GHSA-cggm-fc75-c35c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-f43r-fv98-jc2w/GHSA-f43r-fv98-jc2w.json b/advisories/unreviewed/2023/10/GHSA-f43r-fv98-jc2w/GHSA-f43r-fv98-jc2w.json index fc3da2b2bc2..92e0411c7de 100644 --- a/advisories/unreviewed/2023/10/GHSA-f43r-fv98-jc2w/GHSA-f43r-fv98-jc2w.json +++ b/advisories/unreviewed/2023/10/GHSA-f43r-fv98-jc2w/GHSA-f43r-fv98-jc2w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-fcv4-fw97-74j9/GHSA-fcv4-fw97-74j9.json b/advisories/unreviewed/2023/10/GHSA-fcv4-fw97-74j9/GHSA-fcv4-fw97-74j9.json index c32be7bcbc7..06798057f43 100644 --- a/advisories/unreviewed/2023/10/GHSA-fcv4-fw97-74j9/GHSA-fcv4-fw97-74j9.json +++ b/advisories/unreviewed/2023/10/GHSA-fcv4-fw97-74j9/GHSA-fcv4-fw97-74j9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-fq72-4xq4-w8hg/GHSA-fq72-4xq4-w8hg.json b/advisories/unreviewed/2023/10/GHSA-fq72-4xq4-w8hg/GHSA-fq72-4xq4-w8hg.json index ba07172bf2e..6aaaa9d2a29 100644 --- a/advisories/unreviewed/2023/10/GHSA-fq72-4xq4-w8hg/GHSA-fq72-4xq4-w8hg.json +++ b/advisories/unreviewed/2023/10/GHSA-fq72-4xq4-w8hg/GHSA-fq72-4xq4-w8hg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-j7wf-qmpf-6v3c/GHSA-j7wf-qmpf-6v3c.json b/advisories/unreviewed/2023/10/GHSA-j7wf-qmpf-6v3c/GHSA-j7wf-qmpf-6v3c.json index fe18337871c..e98c85509a1 100644 --- a/advisories/unreviewed/2023/10/GHSA-j7wf-qmpf-6v3c/GHSA-j7wf-qmpf-6v3c.json +++ b/advisories/unreviewed/2023/10/GHSA-j7wf-qmpf-6v3c/GHSA-j7wf-qmpf-6v3c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-jpq4-mchv-jv8r/GHSA-jpq4-mchv-jv8r.json b/advisories/unreviewed/2023/10/GHSA-jpq4-mchv-jv8r/GHSA-jpq4-mchv-jv8r.json index 5c972b1dff3..8fcb6466000 100644 --- a/advisories/unreviewed/2023/10/GHSA-jpq4-mchv-jv8r/GHSA-jpq4-mchv-jv8r.json +++ b/advisories/unreviewed/2023/10/GHSA-jpq4-mchv-jv8r/GHSA-jpq4-mchv-jv8r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-mm89-gccr-q279/GHSA-mm89-gccr-q279.json b/advisories/unreviewed/2023/10/GHSA-mm89-gccr-q279/GHSA-mm89-gccr-q279.json index c5b46c78de0..06419b8eac7 100644 --- a/advisories/unreviewed/2023/10/GHSA-mm89-gccr-q279/GHSA-mm89-gccr-q279.json +++ b/advisories/unreviewed/2023/10/GHSA-mm89-gccr-q279/GHSA-mm89-gccr-q279.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-pjgc-q78w-v6ph/GHSA-pjgc-q78w-v6ph.json b/advisories/unreviewed/2023/10/GHSA-pjgc-q78w-v6ph/GHSA-pjgc-q78w-v6ph.json index 1f0fdaec733..d6ddd86af1d 100644 --- a/advisories/unreviewed/2023/10/GHSA-pjgc-q78w-v6ph/GHSA-pjgc-q78w-v6ph.json +++ b/advisories/unreviewed/2023/10/GHSA-pjgc-q78w-v6ph/GHSA-pjgc-q78w-v6ph.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-q499-4369-cpxq/GHSA-q499-4369-cpxq.json b/advisories/unreviewed/2023/10/GHSA-q499-4369-cpxq/GHSA-q499-4369-cpxq.json index c618e14828e..4c44cc4e371 100644 --- a/advisories/unreviewed/2023/10/GHSA-q499-4369-cpxq/GHSA-q499-4369-cpxq.json +++ b/advisories/unreviewed/2023/10/GHSA-q499-4369-cpxq/GHSA-q499-4369-cpxq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/10/GHSA-qh48-5646-82cv/GHSA-qh48-5646-82cv.json b/advisories/unreviewed/2023/10/GHSA-qh48-5646-82cv/GHSA-qh48-5646-82cv.json index 1d27e0de1a6..6913a404c2a 100644 --- a/advisories/unreviewed/2023/10/GHSA-qh48-5646-82cv/GHSA-qh48-5646-82cv.json +++ b/advisories/unreviewed/2023/10/GHSA-qh48-5646-82cv/GHSA-qh48-5646-82cv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/10/GHSA-r3xw-5c7m-743g/GHSA-r3xw-5c7m-743g.json b/advisories/unreviewed/2023/10/GHSA-r3xw-5c7m-743g/GHSA-r3xw-5c7m-743g.json index d97e58a4660..382b1102644 100644 --- a/advisories/unreviewed/2023/10/GHSA-r3xw-5c7m-743g/GHSA-r3xw-5c7m-743g.json +++ b/advisories/unreviewed/2023/10/GHSA-r3xw-5c7m-743g/GHSA-r3xw-5c7m-743g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/10/GHSA-rgg4-rgq7-84pp/GHSA-rgg4-rgq7-84pp.json b/advisories/unreviewed/2023/10/GHSA-rgg4-rgq7-84pp/GHSA-rgg4-rgq7-84pp.json index 3224193856d..2711e8fdb93 100644 --- a/advisories/unreviewed/2023/10/GHSA-rgg4-rgq7-84pp/GHSA-rgg4-rgq7-84pp.json +++ b/advisories/unreviewed/2023/10/GHSA-rgg4-rgq7-84pp/GHSA-rgg4-rgq7-84pp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-vg5x-5wm4-7r4x/GHSA-vg5x-5wm4-7r4x.json b/advisories/unreviewed/2023/10/GHSA-vg5x-5wm4-7r4x/GHSA-vg5x-5wm4-7r4x.json index 9fb1ca5262b..45d97ef3300 100644 --- a/advisories/unreviewed/2023/10/GHSA-vg5x-5wm4-7r4x/GHSA-vg5x-5wm4-7r4x.json +++ b/advisories/unreviewed/2023/10/GHSA-vg5x-5wm4-7r4x/GHSA-vg5x-5wm4-7r4x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/10/GHSA-xrwj-6h7r-w997/GHSA-xrwj-6h7r-w997.json b/advisories/unreviewed/2023/10/GHSA-xrwj-6h7r-w997/GHSA-xrwj-6h7r-w997.json index 985a6abeb15..679f9142f7d 100644 --- a/advisories/unreviewed/2023/10/GHSA-xrwj-6h7r-w997/GHSA-xrwj-6h7r-w997.json +++ b/advisories/unreviewed/2023/10/GHSA-xrwj-6h7r-w997/GHSA-xrwj-6h7r-w997.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-2wg5-v4cg-mmvr/GHSA-2wg5-v4cg-mmvr.json b/advisories/unreviewed/2023/11/GHSA-2wg5-v4cg-mmvr/GHSA-2wg5-v4cg-mmvr.json index 4829302d31d..fe2beee3996 100644 --- a/advisories/unreviewed/2023/11/GHSA-2wg5-v4cg-mmvr/GHSA-2wg5-v4cg-mmvr.json +++ b/advisories/unreviewed/2023/11/GHSA-2wg5-v4cg-mmvr/GHSA-2wg5-v4cg-mmvr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-3929-x7hw-wqqf/GHSA-3929-x7hw-wqqf.json b/advisories/unreviewed/2023/12/GHSA-3929-x7hw-wqqf/GHSA-3929-x7hw-wqqf.json index 992d6ce228e..24261ca322f 100644 --- a/advisories/unreviewed/2023/12/GHSA-3929-x7hw-wqqf/GHSA-3929-x7hw-wqqf.json +++ b/advisories/unreviewed/2023/12/GHSA-3929-x7hw-wqqf/GHSA-3929-x7hw-wqqf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-vv5h-96wr-c27f/GHSA-vv5h-96wr-c27f.json b/advisories/unreviewed/2023/12/GHSA-vv5h-96wr-c27f/GHSA-vv5h-96wr-c27f.json index f84d36d0458..11112392941 100644 --- a/advisories/unreviewed/2023/12/GHSA-vv5h-96wr-c27f/GHSA-vv5h-96wr-c27f.json +++ b/advisories/unreviewed/2023/12/GHSA-vv5h-96wr-c27f/GHSA-vv5h-96wr-c27f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-wjp2-7h9f-2jxg/GHSA-wjp2-7h9f-2jxg.json b/advisories/unreviewed/2023/12/GHSA-wjp2-7h9f-2jxg/GHSA-wjp2-7h9f-2jxg.json index 3923f4b77eb..bd3a08f8af9 100644 --- a/advisories/unreviewed/2023/12/GHSA-wjp2-7h9f-2jxg/GHSA-wjp2-7h9f-2jxg.json +++ b/advisories/unreviewed/2023/12/GHSA-wjp2-7h9f-2jxg/GHSA-wjp2-7h9f-2jxg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-xwmv-cv85-273r/GHSA-xwmv-cv85-273r.json b/advisories/unreviewed/2023/12/GHSA-xwmv-cv85-273r/GHSA-xwmv-cv85-273r.json index b1219ebe60e..553cf96c018 100644 --- a/advisories/unreviewed/2023/12/GHSA-xwmv-cv85-273r/GHSA-xwmv-cv85-273r.json +++ b/advisories/unreviewed/2023/12/GHSA-xwmv-cv85-273r/GHSA-xwmv-cv85-273r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-2548-xwx6-3r34/GHSA-2548-xwx6-3r34.json b/advisories/unreviewed/2024/01/GHSA-2548-xwx6-3r34/GHSA-2548-xwx6-3r34.json index b7f2d9a5398..05527b1a1ab 100644 --- a/advisories/unreviewed/2024/01/GHSA-2548-xwx6-3r34/GHSA-2548-xwx6-3r34.json +++ b/advisories/unreviewed/2024/01/GHSA-2548-xwx6-3r34/GHSA-2548-xwx6-3r34.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-342m-47g4-wcgj/GHSA-342m-47g4-wcgj.json b/advisories/unreviewed/2024/01/GHSA-342m-47g4-wcgj/GHSA-342m-47g4-wcgj.json index fb104611683..c1fe25fd0b2 100644 --- a/advisories/unreviewed/2024/01/GHSA-342m-47g4-wcgj/GHSA-342m-47g4-wcgj.json +++ b/advisories/unreviewed/2024/01/GHSA-342m-47g4-wcgj/GHSA-342m-47g4-wcgj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-3g32-r9h6-fv6m/GHSA-3g32-r9h6-fv6m.json b/advisories/unreviewed/2024/01/GHSA-3g32-r9h6-fv6m/GHSA-3g32-r9h6-fv6m.json index 9052f32f9b0..114bdc7b736 100644 --- a/advisories/unreviewed/2024/01/GHSA-3g32-r9h6-fv6m/GHSA-3g32-r9h6-fv6m.json +++ b/advisories/unreviewed/2024/01/GHSA-3g32-r9h6-fv6m/GHSA-3g32-r9h6-fv6m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-5j2r-c4r4-2f9c/GHSA-5j2r-c4r4-2f9c.json b/advisories/unreviewed/2024/01/GHSA-5j2r-c4r4-2f9c/GHSA-5j2r-c4r4-2f9c.json index c439756acde..e793a64eb2f 100644 --- a/advisories/unreviewed/2024/01/GHSA-5j2r-c4r4-2f9c/GHSA-5j2r-c4r4-2f9c.json +++ b/advisories/unreviewed/2024/01/GHSA-5j2r-c4r4-2f9c/GHSA-5j2r-c4r4-2f9c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-6m28-3r86-ccr3/GHSA-6m28-3r86-ccr3.json b/advisories/unreviewed/2024/01/GHSA-6m28-3r86-ccr3/GHSA-6m28-3r86-ccr3.json index 10b65e4f729..051f7aa6945 100644 --- a/advisories/unreviewed/2024/01/GHSA-6m28-3r86-ccr3/GHSA-6m28-3r86-ccr3.json +++ b/advisories/unreviewed/2024/01/GHSA-6m28-3r86-ccr3/GHSA-6m28-3r86-ccr3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-c93f-7m77-g46f/GHSA-c93f-7m77-g46f.json b/advisories/unreviewed/2024/01/GHSA-c93f-7m77-g46f/GHSA-c93f-7m77-g46f.json index b8f2a0627c0..169b9c06d07 100644 --- a/advisories/unreviewed/2024/01/GHSA-c93f-7m77-g46f/GHSA-c93f-7m77-g46f.json +++ b/advisories/unreviewed/2024/01/GHSA-c93f-7m77-g46f/GHSA-c93f-7m77-g46f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-cf7q-84pj-gw7g/GHSA-cf7q-84pj-gw7g.json b/advisories/unreviewed/2024/01/GHSA-cf7q-84pj-gw7g/GHSA-cf7q-84pj-gw7g.json index 5eec3762a59..ccb02b1d461 100644 --- a/advisories/unreviewed/2024/01/GHSA-cf7q-84pj-gw7g/GHSA-cf7q-84pj-gw7g.json +++ b/advisories/unreviewed/2024/01/GHSA-cf7q-84pj-gw7g/GHSA-cf7q-84pj-gw7g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-cggv-xvc5-x9mm/GHSA-cggv-xvc5-x9mm.json b/advisories/unreviewed/2024/01/GHSA-cggv-xvc5-x9mm/GHSA-cggv-xvc5-x9mm.json index 4ffd12772b5..e3238d5037f 100644 --- a/advisories/unreviewed/2024/01/GHSA-cggv-xvc5-x9mm/GHSA-cggv-xvc5-x9mm.json +++ b/advisories/unreviewed/2024/01/GHSA-cggv-xvc5-x9mm/GHSA-cggv-xvc5-x9mm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-ffxf-wxjm-c2gq/GHSA-ffxf-wxjm-c2gq.json b/advisories/unreviewed/2024/01/GHSA-ffxf-wxjm-c2gq/GHSA-ffxf-wxjm-c2gq.json index 2fed6350ace..316d4d76691 100644 --- a/advisories/unreviewed/2024/01/GHSA-ffxf-wxjm-c2gq/GHSA-ffxf-wxjm-c2gq.json +++ b/advisories/unreviewed/2024/01/GHSA-ffxf-wxjm-c2gq/GHSA-ffxf-wxjm-c2gq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-fjfp-5xx8-cgr2/GHSA-fjfp-5xx8-cgr2.json b/advisories/unreviewed/2024/01/GHSA-fjfp-5xx8-cgr2/GHSA-fjfp-5xx8-cgr2.json index 58a3bd00440..ae43f3df961 100644 --- a/advisories/unreviewed/2024/01/GHSA-fjfp-5xx8-cgr2/GHSA-fjfp-5xx8-cgr2.json +++ b/advisories/unreviewed/2024/01/GHSA-fjfp-5xx8-cgr2/GHSA-fjfp-5xx8-cgr2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-g698-8w35-cq5r/GHSA-g698-8w35-cq5r.json b/advisories/unreviewed/2024/01/GHSA-g698-8w35-cq5r/GHSA-g698-8w35-cq5r.json index 48cca431ffb..670b02cbc7f 100644 --- a/advisories/unreviewed/2024/01/GHSA-g698-8w35-cq5r/GHSA-g698-8w35-cq5r.json +++ b/advisories/unreviewed/2024/01/GHSA-g698-8w35-cq5r/GHSA-g698-8w35-cq5r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-g9rv-78v8-8hq5/GHSA-g9rv-78v8-8hq5.json b/advisories/unreviewed/2024/01/GHSA-g9rv-78v8-8hq5/GHSA-g9rv-78v8-8hq5.json index e954337f30b..9b497a783a3 100644 --- a/advisories/unreviewed/2024/01/GHSA-g9rv-78v8-8hq5/GHSA-g9rv-78v8-8hq5.json +++ b/advisories/unreviewed/2024/01/GHSA-g9rv-78v8-8hq5/GHSA-g9rv-78v8-8hq5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-gv7v-cr3p-w5q7/GHSA-gv7v-cr3p-w5q7.json b/advisories/unreviewed/2024/01/GHSA-gv7v-cr3p-w5q7/GHSA-gv7v-cr3p-w5q7.json index cb9e412a5d1..e11ff2e8e9a 100644 --- a/advisories/unreviewed/2024/01/GHSA-gv7v-cr3p-w5q7/GHSA-gv7v-cr3p-w5q7.json +++ b/advisories/unreviewed/2024/01/GHSA-gv7v-cr3p-w5q7/GHSA-gv7v-cr3p-w5q7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-h2jx-f8c9-6v68/GHSA-h2jx-f8c9-6v68.json b/advisories/unreviewed/2024/01/GHSA-h2jx-f8c9-6v68/GHSA-h2jx-f8c9-6v68.json index e606eb90372..7bf766ae77f 100644 --- a/advisories/unreviewed/2024/01/GHSA-h2jx-f8c9-6v68/GHSA-h2jx-f8c9-6v68.json +++ b/advisories/unreviewed/2024/01/GHSA-h2jx-f8c9-6v68/GHSA-h2jx-f8c9-6v68.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-hj28-g29j-qvp6/GHSA-hj28-g29j-qvp6.json b/advisories/unreviewed/2024/01/GHSA-hj28-g29j-qvp6/GHSA-hj28-g29j-qvp6.json index efc8bde5794..a86254ca641 100644 --- a/advisories/unreviewed/2024/01/GHSA-hj28-g29j-qvp6/GHSA-hj28-g29j-qvp6.json +++ b/advisories/unreviewed/2024/01/GHSA-hj28-g29j-qvp6/GHSA-hj28-g29j-qvp6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-j44v-ghf8-cf8j/GHSA-j44v-ghf8-cf8j.json b/advisories/unreviewed/2024/01/GHSA-j44v-ghf8-cf8j/GHSA-j44v-ghf8-cf8j.json index 6814f465a76..0a250a33d7f 100644 --- a/advisories/unreviewed/2024/01/GHSA-j44v-ghf8-cf8j/GHSA-j44v-ghf8-cf8j.json +++ b/advisories/unreviewed/2024/01/GHSA-j44v-ghf8-cf8j/GHSA-j44v-ghf8-cf8j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-jh6m-g253-f37c/GHSA-jh6m-g253-f37c.json b/advisories/unreviewed/2024/01/GHSA-jh6m-g253-f37c/GHSA-jh6m-g253-f37c.json index 03957f5478f..7d080e171ba 100644 --- a/advisories/unreviewed/2024/01/GHSA-jh6m-g253-f37c/GHSA-jh6m-g253-f37c.json +++ b/advisories/unreviewed/2024/01/GHSA-jh6m-g253-f37c/GHSA-jh6m-g253-f37c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-m93g-v4mv-3ggr/GHSA-m93g-v4mv-3ggr.json b/advisories/unreviewed/2024/01/GHSA-m93g-v4mv-3ggr/GHSA-m93g-v4mv-3ggr.json index cca19b505eb..94da0921a3f 100644 --- a/advisories/unreviewed/2024/01/GHSA-m93g-v4mv-3ggr/GHSA-m93g-v4mv-3ggr.json +++ b/advisories/unreviewed/2024/01/GHSA-m93g-v4mv-3ggr/GHSA-m93g-v4mv-3ggr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-mcwj-fc2v-3xc2/GHSA-mcwj-fc2v-3xc2.json b/advisories/unreviewed/2024/01/GHSA-mcwj-fc2v-3xc2/GHSA-mcwj-fc2v-3xc2.json index cdb9112d18b..50495c537bf 100644 --- a/advisories/unreviewed/2024/01/GHSA-mcwj-fc2v-3xc2/GHSA-mcwj-fc2v-3xc2.json +++ b/advisories/unreviewed/2024/01/GHSA-mcwj-fc2v-3xc2/GHSA-mcwj-fc2v-3xc2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-mpwp-23xv-7j3h/GHSA-mpwp-23xv-7j3h.json b/advisories/unreviewed/2024/01/GHSA-mpwp-23xv-7j3h/GHSA-mpwp-23xv-7j3h.json index 54aec2e72aa..fe5963d5dc2 100644 --- a/advisories/unreviewed/2024/01/GHSA-mpwp-23xv-7j3h/GHSA-mpwp-23xv-7j3h.json +++ b/advisories/unreviewed/2024/01/GHSA-mpwp-23xv-7j3h/GHSA-mpwp-23xv-7j3h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-q4gv-76qv-qh34/GHSA-q4gv-76qv-qh34.json b/advisories/unreviewed/2024/01/GHSA-q4gv-76qv-qh34/GHSA-q4gv-76qv-qh34.json index 379535da681..ff64c02b260 100644 --- a/advisories/unreviewed/2024/01/GHSA-q4gv-76qv-qh34/GHSA-q4gv-76qv-qh34.json +++ b/advisories/unreviewed/2024/01/GHSA-q4gv-76qv-qh34/GHSA-q4gv-76qv-qh34.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-q8wr-886h-q847/GHSA-q8wr-886h-q847.json b/advisories/unreviewed/2024/01/GHSA-q8wr-886h-q847/GHSA-q8wr-886h-q847.json index fd0d761f009..e3f423f95e5 100644 --- a/advisories/unreviewed/2024/01/GHSA-q8wr-886h-q847/GHSA-q8wr-886h-q847.json +++ b/advisories/unreviewed/2024/01/GHSA-q8wr-886h-q847/GHSA-q8wr-886h-q847.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-r287-6vw5-j92p/GHSA-r287-6vw5-j92p.json b/advisories/unreviewed/2024/01/GHSA-r287-6vw5-j92p/GHSA-r287-6vw5-j92p.json index 57e9118b6e4..01e7701449f 100644 --- a/advisories/unreviewed/2024/01/GHSA-r287-6vw5-j92p/GHSA-r287-6vw5-j92p.json +++ b/advisories/unreviewed/2024/01/GHSA-r287-6vw5-j92p/GHSA-r287-6vw5-j92p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-rjfr-rgjj-mvh5/GHSA-rjfr-rgjj-mvh5.json b/advisories/unreviewed/2024/01/GHSA-rjfr-rgjj-mvh5/GHSA-rjfr-rgjj-mvh5.json index 60f73bc3eab..787b571f59b 100644 --- a/advisories/unreviewed/2024/01/GHSA-rjfr-rgjj-mvh5/GHSA-rjfr-rgjj-mvh5.json +++ b/advisories/unreviewed/2024/01/GHSA-rjfr-rgjj-mvh5/GHSA-rjfr-rgjj-mvh5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-wvgv-79m5-4g2m/GHSA-wvgv-79m5-4g2m.json b/advisories/unreviewed/2024/01/GHSA-wvgv-79m5-4g2m/GHSA-wvgv-79m5-4g2m.json index dd9d29f30f5..5aabd6959eb 100644 --- a/advisories/unreviewed/2024/01/GHSA-wvgv-79m5-4g2m/GHSA-wvgv-79m5-4g2m.json +++ b/advisories/unreviewed/2024/01/GHSA-wvgv-79m5-4g2m/GHSA-wvgv-79m5-4g2m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-xxcm-q624-6hcv/GHSA-xxcm-q624-6hcv.json b/advisories/unreviewed/2024/01/GHSA-xxcm-q624-6hcv/GHSA-xxcm-q624-6hcv.json index 16f791c346b..54bb3147833 100644 --- a/advisories/unreviewed/2024/01/GHSA-xxcm-q624-6hcv/GHSA-xxcm-q624-6hcv.json +++ b/advisories/unreviewed/2024/01/GHSA-xxcm-q624-6hcv/GHSA-xxcm-q624-6hcv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-2hrm-9gxc-3c35/GHSA-2hrm-9gxc-3c35.json b/advisories/unreviewed/2024/02/GHSA-2hrm-9gxc-3c35/GHSA-2hrm-9gxc-3c35.json index b45bb8cd0d3..6281e11a6b8 100644 --- a/advisories/unreviewed/2024/02/GHSA-2hrm-9gxc-3c35/GHSA-2hrm-9gxc-3c35.json +++ b/advisories/unreviewed/2024/02/GHSA-2hrm-9gxc-3c35/GHSA-2hrm-9gxc-3c35.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-2wwc-57w4-gp7m/GHSA-2wwc-57w4-gp7m.json b/advisories/unreviewed/2024/02/GHSA-2wwc-57w4-gp7m/GHSA-2wwc-57w4-gp7m.json index 1e729f4f216..e41d249df3a 100644 --- a/advisories/unreviewed/2024/02/GHSA-2wwc-57w4-gp7m/GHSA-2wwc-57w4-gp7m.json +++ b/advisories/unreviewed/2024/02/GHSA-2wwc-57w4-gp7m/GHSA-2wwc-57w4-gp7m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-33cc-g737-2r5g/GHSA-33cc-g737-2r5g.json b/advisories/unreviewed/2024/02/GHSA-33cc-g737-2r5g/GHSA-33cc-g737-2r5g.json index 0bc2d090fc4..5b4e3411de0 100644 --- a/advisories/unreviewed/2024/02/GHSA-33cc-g737-2r5g/GHSA-33cc-g737-2r5g.json +++ b/advisories/unreviewed/2024/02/GHSA-33cc-g737-2r5g/GHSA-33cc-g737-2r5g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-365x-5gg7-66qg/GHSA-365x-5gg7-66qg.json b/advisories/unreviewed/2024/02/GHSA-365x-5gg7-66qg/GHSA-365x-5gg7-66qg.json index 0eb22c634b2..401a2eb6e63 100644 --- a/advisories/unreviewed/2024/02/GHSA-365x-5gg7-66qg/GHSA-365x-5gg7-66qg.json +++ b/advisories/unreviewed/2024/02/GHSA-365x-5gg7-66qg/GHSA-365x-5gg7-66qg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-3f9f-wff5-c5pp/GHSA-3f9f-wff5-c5pp.json b/advisories/unreviewed/2024/02/GHSA-3f9f-wff5-c5pp/GHSA-3f9f-wff5-c5pp.json index 6b11009cdf2..25405125777 100644 --- a/advisories/unreviewed/2024/02/GHSA-3f9f-wff5-c5pp/GHSA-3f9f-wff5-c5pp.json +++ b/advisories/unreviewed/2024/02/GHSA-3f9f-wff5-c5pp/GHSA-3f9f-wff5-c5pp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-3fgw-x27j-xm6w/GHSA-3fgw-x27j-xm6w.json b/advisories/unreviewed/2024/02/GHSA-3fgw-x27j-xm6w/GHSA-3fgw-x27j-xm6w.json index b6fbd71249e..cc66135d60a 100644 --- a/advisories/unreviewed/2024/02/GHSA-3fgw-x27j-xm6w/GHSA-3fgw-x27j-xm6w.json +++ b/advisories/unreviewed/2024/02/GHSA-3fgw-x27j-xm6w/GHSA-3fgw-x27j-xm6w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-3whp-4394-49gc/GHSA-3whp-4394-49gc.json b/advisories/unreviewed/2024/02/GHSA-3whp-4394-49gc/GHSA-3whp-4394-49gc.json index bbfeb86f3d3..eb2387039a7 100644 --- a/advisories/unreviewed/2024/02/GHSA-3whp-4394-49gc/GHSA-3whp-4394-49gc.json +++ b/advisories/unreviewed/2024/02/GHSA-3whp-4394-49gc/GHSA-3whp-4394-49gc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-4f2m-qf8w-84rw/GHSA-4f2m-qf8w-84rw.json b/advisories/unreviewed/2024/02/GHSA-4f2m-qf8w-84rw/GHSA-4f2m-qf8w-84rw.json index 7f870cdb411..79e781ea94c 100644 --- a/advisories/unreviewed/2024/02/GHSA-4f2m-qf8w-84rw/GHSA-4f2m-qf8w-84rw.json +++ b/advisories/unreviewed/2024/02/GHSA-4f2m-qf8w-84rw/GHSA-4f2m-qf8w-84rw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-5gwx-vhc7-55r8/GHSA-5gwx-vhc7-55r8.json b/advisories/unreviewed/2024/02/GHSA-5gwx-vhc7-55r8/GHSA-5gwx-vhc7-55r8.json index 48b58f2a113..ebf609695e5 100644 --- a/advisories/unreviewed/2024/02/GHSA-5gwx-vhc7-55r8/GHSA-5gwx-vhc7-55r8.json +++ b/advisories/unreviewed/2024/02/GHSA-5gwx-vhc7-55r8/GHSA-5gwx-vhc7-55r8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-5gx7-f5j6-6r9q/GHSA-5gx7-f5j6-6r9q.json b/advisories/unreviewed/2024/02/GHSA-5gx7-f5j6-6r9q/GHSA-5gx7-f5j6-6r9q.json index c165941c567..56833d2b547 100644 --- a/advisories/unreviewed/2024/02/GHSA-5gx7-f5j6-6r9q/GHSA-5gx7-f5j6-6r9q.json +++ b/advisories/unreviewed/2024/02/GHSA-5gx7-f5j6-6r9q/GHSA-5gx7-f5j6-6r9q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-5rmh-6fjp-jmcp/GHSA-5rmh-6fjp-jmcp.json b/advisories/unreviewed/2024/02/GHSA-5rmh-6fjp-jmcp/GHSA-5rmh-6fjp-jmcp.json index ee736a070c5..3eeba18c515 100644 --- a/advisories/unreviewed/2024/02/GHSA-5rmh-6fjp-jmcp/GHSA-5rmh-6fjp-jmcp.json +++ b/advisories/unreviewed/2024/02/GHSA-5rmh-6fjp-jmcp/GHSA-5rmh-6fjp-jmcp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-6jf4-4jp9-4wmw/GHSA-6jf4-4jp9-4wmw.json b/advisories/unreviewed/2024/02/GHSA-6jf4-4jp9-4wmw/GHSA-6jf4-4jp9-4wmw.json index 21f218af711..1b73c50deaf 100644 --- a/advisories/unreviewed/2024/02/GHSA-6jf4-4jp9-4wmw/GHSA-6jf4-4jp9-4wmw.json +++ b/advisories/unreviewed/2024/02/GHSA-6jf4-4jp9-4wmw/GHSA-6jf4-4jp9-4wmw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-7674-fj4m-c42f/GHSA-7674-fj4m-c42f.json b/advisories/unreviewed/2024/02/GHSA-7674-fj4m-c42f/GHSA-7674-fj4m-c42f.json index e2327415b92..ef8a3f2ae21 100644 --- a/advisories/unreviewed/2024/02/GHSA-7674-fj4m-c42f/GHSA-7674-fj4m-c42f.json +++ b/advisories/unreviewed/2024/02/GHSA-7674-fj4m-c42f/GHSA-7674-fj4m-c42f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-7jpg-53q7-h4w6/GHSA-7jpg-53q7-h4w6.json b/advisories/unreviewed/2024/02/GHSA-7jpg-53q7-h4w6/GHSA-7jpg-53q7-h4w6.json index 10b3a1ea3f3..7dfcb9ad292 100644 --- a/advisories/unreviewed/2024/02/GHSA-7jpg-53q7-h4w6/GHSA-7jpg-53q7-h4w6.json +++ b/advisories/unreviewed/2024/02/GHSA-7jpg-53q7-h4w6/GHSA-7jpg-53q7-h4w6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-8h6j-vxpr-4ff5/GHSA-8h6j-vxpr-4ff5.json b/advisories/unreviewed/2024/02/GHSA-8h6j-vxpr-4ff5/GHSA-8h6j-vxpr-4ff5.json index 827e7b51a32..6e4051936b2 100644 --- a/advisories/unreviewed/2024/02/GHSA-8h6j-vxpr-4ff5/GHSA-8h6j-vxpr-4ff5.json +++ b/advisories/unreviewed/2024/02/GHSA-8h6j-vxpr-4ff5/GHSA-8h6j-vxpr-4ff5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-8j25-5vwv-hm2f/GHSA-8j25-5vwv-hm2f.json b/advisories/unreviewed/2024/02/GHSA-8j25-5vwv-hm2f/GHSA-8j25-5vwv-hm2f.json index 33c5fec76e7..9ca0ad27cc1 100644 --- a/advisories/unreviewed/2024/02/GHSA-8j25-5vwv-hm2f/GHSA-8j25-5vwv-hm2f.json +++ b/advisories/unreviewed/2024/02/GHSA-8j25-5vwv-hm2f/GHSA-8j25-5vwv-hm2f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-98x5-562f-mwvp/GHSA-98x5-562f-mwvp.json b/advisories/unreviewed/2024/02/GHSA-98x5-562f-mwvp/GHSA-98x5-562f-mwvp.json index 18797582a7b..72bb6bed3eb 100644 --- a/advisories/unreviewed/2024/02/GHSA-98x5-562f-mwvp/GHSA-98x5-562f-mwvp.json +++ b/advisories/unreviewed/2024/02/GHSA-98x5-562f-mwvp/GHSA-98x5-562f-mwvp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-9fx9-j289-p7f2/GHSA-9fx9-j289-p7f2.json b/advisories/unreviewed/2024/02/GHSA-9fx9-j289-p7f2/GHSA-9fx9-j289-p7f2.json index b1f1aabd5c7..d26795f9973 100644 --- a/advisories/unreviewed/2024/02/GHSA-9fx9-j289-p7f2/GHSA-9fx9-j289-p7f2.json +++ b/advisories/unreviewed/2024/02/GHSA-9fx9-j289-p7f2/GHSA-9fx9-j289-p7f2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-9x4x-qwhq-g8f7/GHSA-9x4x-qwhq-g8f7.json b/advisories/unreviewed/2024/02/GHSA-9x4x-qwhq-g8f7/GHSA-9x4x-qwhq-g8f7.json index 3e9460ff815..e5941519ea8 100644 --- a/advisories/unreviewed/2024/02/GHSA-9x4x-qwhq-g8f7/GHSA-9x4x-qwhq-g8f7.json +++ b/advisories/unreviewed/2024/02/GHSA-9x4x-qwhq-g8f7/GHSA-9x4x-qwhq-g8f7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-9xc4-66pr-rw85/GHSA-9xc4-66pr-rw85.json b/advisories/unreviewed/2024/02/GHSA-9xc4-66pr-rw85/GHSA-9xc4-66pr-rw85.json index b900562f0c3..2c8a3054b94 100644 --- a/advisories/unreviewed/2024/02/GHSA-9xc4-66pr-rw85/GHSA-9xc4-66pr-rw85.json +++ b/advisories/unreviewed/2024/02/GHSA-9xc4-66pr-rw85/GHSA-9xc4-66pr-rw85.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-c9vq-9q39-5j32/GHSA-c9vq-9q39-5j32.json b/advisories/unreviewed/2024/02/GHSA-c9vq-9q39-5j32/GHSA-c9vq-9q39-5j32.json index 0fe4c5e4223..6fa8154d1e9 100644 --- a/advisories/unreviewed/2024/02/GHSA-c9vq-9q39-5j32/GHSA-c9vq-9q39-5j32.json +++ b/advisories/unreviewed/2024/02/GHSA-c9vq-9q39-5j32/GHSA-c9vq-9q39-5j32.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-cj4f-m7fj-58gv/GHSA-cj4f-m7fj-58gv.json b/advisories/unreviewed/2024/02/GHSA-cj4f-m7fj-58gv/GHSA-cj4f-m7fj-58gv.json index f50229ae6a4..a5139ce2e14 100644 --- a/advisories/unreviewed/2024/02/GHSA-cj4f-m7fj-58gv/GHSA-cj4f-m7fj-58gv.json +++ b/advisories/unreviewed/2024/02/GHSA-cj4f-m7fj-58gv/GHSA-cj4f-m7fj-58gv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-f93f-4q67-pcmr/GHSA-f93f-4q67-pcmr.json b/advisories/unreviewed/2024/02/GHSA-f93f-4q67-pcmr/GHSA-f93f-4q67-pcmr.json index 43a45ae6e9a..f8ceeb752bc 100644 --- a/advisories/unreviewed/2024/02/GHSA-f93f-4q67-pcmr/GHSA-f93f-4q67-pcmr.json +++ b/advisories/unreviewed/2024/02/GHSA-f93f-4q67-pcmr/GHSA-f93f-4q67-pcmr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-fvmx-33hg-gjq5/GHSA-fvmx-33hg-gjq5.json b/advisories/unreviewed/2024/02/GHSA-fvmx-33hg-gjq5/GHSA-fvmx-33hg-gjq5.json index a9cac0966a7..a0bb8675bc7 100644 --- a/advisories/unreviewed/2024/02/GHSA-fvmx-33hg-gjq5/GHSA-fvmx-33hg-gjq5.json +++ b/advisories/unreviewed/2024/02/GHSA-fvmx-33hg-gjq5/GHSA-fvmx-33hg-gjq5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-fvr5-4qp7-xwjc/GHSA-fvr5-4qp7-xwjc.json b/advisories/unreviewed/2024/02/GHSA-fvr5-4qp7-xwjc/GHSA-fvr5-4qp7-xwjc.json index 5057f480032..d2eda09e696 100644 --- a/advisories/unreviewed/2024/02/GHSA-fvr5-4qp7-xwjc/GHSA-fvr5-4qp7-xwjc.json +++ b/advisories/unreviewed/2024/02/GHSA-fvr5-4qp7-xwjc/GHSA-fvr5-4qp7-xwjc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-fvxf-3hr7-h5gc/GHSA-fvxf-3hr7-h5gc.json b/advisories/unreviewed/2024/02/GHSA-fvxf-3hr7-h5gc/GHSA-fvxf-3hr7-h5gc.json index 6ce88a67baa..de36bf3cbb0 100644 --- a/advisories/unreviewed/2024/02/GHSA-fvxf-3hr7-h5gc/GHSA-fvxf-3hr7-h5gc.json +++ b/advisories/unreviewed/2024/02/GHSA-fvxf-3hr7-h5gc/GHSA-fvxf-3hr7-h5gc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-g85h-w3x6-7g28/GHSA-g85h-w3x6-7g28.json b/advisories/unreviewed/2024/02/GHSA-g85h-w3x6-7g28/GHSA-g85h-w3x6-7g28.json index 67e6ded8c78..57e96685a5d 100644 --- a/advisories/unreviewed/2024/02/GHSA-g85h-w3x6-7g28/GHSA-g85h-w3x6-7g28.json +++ b/advisories/unreviewed/2024/02/GHSA-g85h-w3x6-7g28/GHSA-g85h-w3x6-7g28.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-g9mf-qvgg-vwxr/GHSA-g9mf-qvgg-vwxr.json b/advisories/unreviewed/2024/02/GHSA-g9mf-qvgg-vwxr/GHSA-g9mf-qvgg-vwxr.json index 3fe13d51dcb..24797e6cb76 100644 --- a/advisories/unreviewed/2024/02/GHSA-g9mf-qvgg-vwxr/GHSA-g9mf-qvgg-vwxr.json +++ b/advisories/unreviewed/2024/02/GHSA-g9mf-qvgg-vwxr/GHSA-g9mf-qvgg-vwxr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-hhg2-g5jr-6wrx/GHSA-hhg2-g5jr-6wrx.json b/advisories/unreviewed/2024/02/GHSA-hhg2-g5jr-6wrx/GHSA-hhg2-g5jr-6wrx.json index 22dd15d722d..2ace0e395ea 100644 --- a/advisories/unreviewed/2024/02/GHSA-hhg2-g5jr-6wrx/GHSA-hhg2-g5jr-6wrx.json +++ b/advisories/unreviewed/2024/02/GHSA-hhg2-g5jr-6wrx/GHSA-hhg2-g5jr-6wrx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-hx29-fw56-x5wj/GHSA-hx29-fw56-x5wj.json b/advisories/unreviewed/2024/02/GHSA-hx29-fw56-x5wj/GHSA-hx29-fw56-x5wj.json index de847e1dd0f..1a1584f8d64 100644 --- a/advisories/unreviewed/2024/02/GHSA-hx29-fw56-x5wj/GHSA-hx29-fw56-x5wj.json +++ b/advisories/unreviewed/2024/02/GHSA-hx29-fw56-x5wj/GHSA-hx29-fw56-x5wj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-j347-m6ww-35jg/GHSA-j347-m6ww-35jg.json b/advisories/unreviewed/2024/02/GHSA-j347-m6ww-35jg/GHSA-j347-m6ww-35jg.json index 306959b7662..3b0bb615040 100644 --- a/advisories/unreviewed/2024/02/GHSA-j347-m6ww-35jg/GHSA-j347-m6ww-35jg.json +++ b/advisories/unreviewed/2024/02/GHSA-j347-m6ww-35jg/GHSA-j347-m6ww-35jg.json @@ -7,12 +7,8 @@ "CVE-2024-25940" ], "details": "`bhyveload -h ` may be used to grant loader access to the directory tree on the host. Affected versions of bhyveload(8) do not make any attempt to restrict loader's access to , allowing the loader to read any file the host user has access to. In the bhyveload(8) model, the host supplies a userboot.so to boot with, but the loader scripts generally come from the guest image. A maliciously crafted script could be used to exfiltrate sensitive data from the host accessible to the user running bhyhveload(8), which is often the system root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-j525-244m-q96j/GHSA-j525-244m-q96j.json b/advisories/unreviewed/2024/02/GHSA-j525-244m-q96j/GHSA-j525-244m-q96j.json index 101b92a05ca..f77ee82f078 100644 --- a/advisories/unreviewed/2024/02/GHSA-j525-244m-q96j/GHSA-j525-244m-q96j.json +++ b/advisories/unreviewed/2024/02/GHSA-j525-244m-q96j/GHSA-j525-244m-q96j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-j98c-9xhr-mrff/GHSA-j98c-9xhr-mrff.json b/advisories/unreviewed/2024/02/GHSA-j98c-9xhr-mrff/GHSA-j98c-9xhr-mrff.json index 41ca8c14e2f..f65a7c1e8ab 100644 --- a/advisories/unreviewed/2024/02/GHSA-j98c-9xhr-mrff/GHSA-j98c-9xhr-mrff.json +++ b/advisories/unreviewed/2024/02/GHSA-j98c-9xhr-mrff/GHSA-j98c-9xhr-mrff.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-jpmx-v3pp-6rp5/GHSA-jpmx-v3pp-6rp5.json b/advisories/unreviewed/2024/02/GHSA-jpmx-v3pp-6rp5/GHSA-jpmx-v3pp-6rp5.json index 3ad8b346a79..d9cb17ba851 100644 --- a/advisories/unreviewed/2024/02/GHSA-jpmx-v3pp-6rp5/GHSA-jpmx-v3pp-6rp5.json +++ b/advisories/unreviewed/2024/02/GHSA-jpmx-v3pp-6rp5/GHSA-jpmx-v3pp-6rp5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-jrxj-mm3c-m6gg/GHSA-jrxj-mm3c-m6gg.json b/advisories/unreviewed/2024/02/GHSA-jrxj-mm3c-m6gg/GHSA-jrxj-mm3c-m6gg.json index 0f73eaa2364..3031fda5e3b 100644 --- a/advisories/unreviewed/2024/02/GHSA-jrxj-mm3c-m6gg/GHSA-jrxj-mm3c-m6gg.json +++ b/advisories/unreviewed/2024/02/GHSA-jrxj-mm3c-m6gg/GHSA-jrxj-mm3c-m6gg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-p23g-c2fc-p76q/GHSA-p23g-c2fc-p76q.json b/advisories/unreviewed/2024/02/GHSA-p23g-c2fc-p76q/GHSA-p23g-c2fc-p76q.json index 89850f05890..a6d18e9b1fd 100644 --- a/advisories/unreviewed/2024/02/GHSA-p23g-c2fc-p76q/GHSA-p23g-c2fc-p76q.json +++ b/advisories/unreviewed/2024/02/GHSA-p23g-c2fc-p76q/GHSA-p23g-c2fc-p76q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-p45j-q5hm-cc64/GHSA-p45j-q5hm-cc64.json b/advisories/unreviewed/2024/02/GHSA-p45j-q5hm-cc64/GHSA-p45j-q5hm-cc64.json index b9ef461e584..934c66fa61a 100644 --- a/advisories/unreviewed/2024/02/GHSA-p45j-q5hm-cc64/GHSA-p45j-q5hm-cc64.json +++ b/advisories/unreviewed/2024/02/GHSA-p45j-q5hm-cc64/GHSA-p45j-q5hm-cc64.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-pp49-8w45-9fxr/GHSA-pp49-8w45-9fxr.json b/advisories/unreviewed/2024/02/GHSA-pp49-8w45-9fxr/GHSA-pp49-8w45-9fxr.json index 4b44afcc244..43bd50a326e 100644 --- a/advisories/unreviewed/2024/02/GHSA-pp49-8w45-9fxr/GHSA-pp49-8w45-9fxr.json +++ b/advisories/unreviewed/2024/02/GHSA-pp49-8w45-9fxr/GHSA-pp49-8w45-9fxr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-rhmj-w54j-qcf6/GHSA-rhmj-w54j-qcf6.json b/advisories/unreviewed/2024/02/GHSA-rhmj-w54j-qcf6/GHSA-rhmj-w54j-qcf6.json index c8c97ddfdc6..33dc421a9f9 100644 --- a/advisories/unreviewed/2024/02/GHSA-rhmj-w54j-qcf6/GHSA-rhmj-w54j-qcf6.json +++ b/advisories/unreviewed/2024/02/GHSA-rhmj-w54j-qcf6/GHSA-rhmj-w54j-qcf6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-vrg6-343w-wxr6/GHSA-vrg6-343w-wxr6.json b/advisories/unreviewed/2024/02/GHSA-vrg6-343w-wxr6/GHSA-vrg6-343w-wxr6.json index 4dc4075b7f0..a79ce0b30ed 100644 --- a/advisories/unreviewed/2024/02/GHSA-vrg6-343w-wxr6/GHSA-vrg6-343w-wxr6.json +++ b/advisories/unreviewed/2024/02/GHSA-vrg6-343w-wxr6/GHSA-vrg6-343w-wxr6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-w6v7-mjp2-pwcf/GHSA-w6v7-mjp2-pwcf.json b/advisories/unreviewed/2024/02/GHSA-w6v7-mjp2-pwcf/GHSA-w6v7-mjp2-pwcf.json index d98c5795416..744676864ab 100644 --- a/advisories/unreviewed/2024/02/GHSA-w6v7-mjp2-pwcf/GHSA-w6v7-mjp2-pwcf.json +++ b/advisories/unreviewed/2024/02/GHSA-w6v7-mjp2-pwcf/GHSA-w6v7-mjp2-pwcf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-wp68-xh4w-r326/GHSA-wp68-xh4w-r326.json b/advisories/unreviewed/2024/02/GHSA-wp68-xh4w-r326/GHSA-wp68-xh4w-r326.json index f47750f8981..fe89e345d4a 100644 --- a/advisories/unreviewed/2024/02/GHSA-wp68-xh4w-r326/GHSA-wp68-xh4w-r326.json +++ b/advisories/unreviewed/2024/02/GHSA-wp68-xh4w-r326/GHSA-wp68-xh4w-r326.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-x9rp-8j88-vh76/GHSA-x9rp-8j88-vh76.json b/advisories/unreviewed/2024/02/GHSA-x9rp-8j88-vh76/GHSA-x9rp-8j88-vh76.json index 9b2e403abb3..e96e91277b4 100644 --- a/advisories/unreviewed/2024/02/GHSA-x9rp-8j88-vh76/GHSA-x9rp-8j88-vh76.json +++ b/advisories/unreviewed/2024/02/GHSA-x9rp-8j88-vh76/GHSA-x9rp-8j88-vh76.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-24jp-gg22-pxj3/GHSA-24jp-gg22-pxj3.json b/advisories/unreviewed/2024/03/GHSA-24jp-gg22-pxj3/GHSA-24jp-gg22-pxj3.json index edc27c44aa5..98ea03b4e18 100644 --- a/advisories/unreviewed/2024/03/GHSA-24jp-gg22-pxj3/GHSA-24jp-gg22-pxj3.json +++ b/advisories/unreviewed/2024/03/GHSA-24jp-gg22-pxj3/GHSA-24jp-gg22-pxj3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-3x6c-xfwc-qp7m/GHSA-3x6c-xfwc-qp7m.json b/advisories/unreviewed/2024/03/GHSA-3x6c-xfwc-qp7m/GHSA-3x6c-xfwc-qp7m.json index 9980b7c9021..79a500c2963 100644 --- a/advisories/unreviewed/2024/03/GHSA-3x6c-xfwc-qp7m/GHSA-3x6c-xfwc-qp7m.json +++ b/advisories/unreviewed/2024/03/GHSA-3x6c-xfwc-qp7m/GHSA-3x6c-xfwc-qp7m.json @@ -7,12 +7,8 @@ "CVE-2023-49234" ], "details": "An XML external entity (XXE) vulnerability was found in Stilog Visual Planning 8. It allows an authenticated attacker to access local server files and exfiltrate data to an external server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-77m3-8vw3-fw8w/GHSA-77m3-8vw3-fw8w.json b/advisories/unreviewed/2024/03/GHSA-77m3-8vw3-fw8w/GHSA-77m3-8vw3-fw8w.json index 6a57dae048b..e4047ff6ee6 100644 --- a/advisories/unreviewed/2024/03/GHSA-77m3-8vw3-fw8w/GHSA-77m3-8vw3-fw8w.json +++ b/advisories/unreviewed/2024/03/GHSA-77m3-8vw3-fw8w/GHSA-77m3-8vw3-fw8w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-8h97-3wj9-m4mh/GHSA-8h97-3wj9-m4mh.json b/advisories/unreviewed/2024/03/GHSA-8h97-3wj9-m4mh/GHSA-8h97-3wj9-m4mh.json index 304f2a50b5d..7b1f89ff325 100644 --- a/advisories/unreviewed/2024/03/GHSA-8h97-3wj9-m4mh/GHSA-8h97-3wj9-m4mh.json +++ b/advisories/unreviewed/2024/03/GHSA-8h97-3wj9-m4mh/GHSA-8h97-3wj9-m4mh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-948m-5vcf-j8g5/GHSA-948m-5vcf-j8g5.json b/advisories/unreviewed/2024/03/GHSA-948m-5vcf-j8g5/GHSA-948m-5vcf-j8g5.json index 521b456fe25..caf9ed2e339 100644 --- a/advisories/unreviewed/2024/03/GHSA-948m-5vcf-j8g5/GHSA-948m-5vcf-j8g5.json +++ b/advisories/unreviewed/2024/03/GHSA-948m-5vcf-j8g5/GHSA-948m-5vcf-j8g5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-9hpm-6w4c-hxh2/GHSA-9hpm-6w4c-hxh2.json b/advisories/unreviewed/2024/03/GHSA-9hpm-6w4c-hxh2/GHSA-9hpm-6w4c-hxh2.json index 56afa783ce3..5639f04757b 100644 --- a/advisories/unreviewed/2024/03/GHSA-9hpm-6w4c-hxh2/GHSA-9hpm-6w4c-hxh2.json +++ b/advisories/unreviewed/2024/03/GHSA-9hpm-6w4c-hxh2/GHSA-9hpm-6w4c-hxh2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-gj62-r5fm-pg3q/GHSA-gj62-r5fm-pg3q.json b/advisories/unreviewed/2024/03/GHSA-gj62-r5fm-pg3q/GHSA-gj62-r5fm-pg3q.json index 0d2c44799f8..bcdf09a5cf1 100644 --- a/advisories/unreviewed/2024/03/GHSA-gj62-r5fm-pg3q/GHSA-gj62-r5fm-pg3q.json +++ b/advisories/unreviewed/2024/03/GHSA-gj62-r5fm-pg3q/GHSA-gj62-r5fm-pg3q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-h64q-p2cr-jmw7/GHSA-h64q-p2cr-jmw7.json b/advisories/unreviewed/2024/03/GHSA-h64q-p2cr-jmw7/GHSA-h64q-p2cr-jmw7.json index 84f6f0b0157..10a2e342fcf 100644 --- a/advisories/unreviewed/2024/03/GHSA-h64q-p2cr-jmw7/GHSA-h64q-p2cr-jmw7.json +++ b/advisories/unreviewed/2024/03/GHSA-h64q-p2cr-jmw7/GHSA-h64q-p2cr-jmw7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-j3p2-j2wj-5w6g/GHSA-j3p2-j2wj-5w6g.json b/advisories/unreviewed/2024/03/GHSA-j3p2-j2wj-5w6g/GHSA-j3p2-j2wj-5w6g.json index 0a253de92b6..c2c3a986488 100644 --- a/advisories/unreviewed/2024/03/GHSA-j3p2-j2wj-5w6g/GHSA-j3p2-j2wj-5w6g.json +++ b/advisories/unreviewed/2024/03/GHSA-j3p2-j2wj-5w6g/GHSA-j3p2-j2wj-5w6g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-jg48-xvhq-mrmw/GHSA-jg48-xvhq-mrmw.json b/advisories/unreviewed/2024/03/GHSA-jg48-xvhq-mrmw/GHSA-jg48-xvhq-mrmw.json index 9b378824839..be046f10880 100644 --- a/advisories/unreviewed/2024/03/GHSA-jg48-xvhq-mrmw/GHSA-jg48-xvhq-mrmw.json +++ b/advisories/unreviewed/2024/03/GHSA-jg48-xvhq-mrmw/GHSA-jg48-xvhq-mrmw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-mrx6-42xr-335p/GHSA-mrx6-42xr-335p.json b/advisories/unreviewed/2024/03/GHSA-mrx6-42xr-335p/GHSA-mrx6-42xr-335p.json index 1ce8fff4c03..b2915bd5a34 100644 --- a/advisories/unreviewed/2024/03/GHSA-mrx6-42xr-335p/GHSA-mrx6-42xr-335p.json +++ b/advisories/unreviewed/2024/03/GHSA-mrx6-42xr-335p/GHSA-mrx6-42xr-335p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-pg2q-wfgh-r323/GHSA-pg2q-wfgh-r323.json b/advisories/unreviewed/2024/03/GHSA-pg2q-wfgh-r323/GHSA-pg2q-wfgh-r323.json index 041227d3d48..bac2f00ee89 100644 --- a/advisories/unreviewed/2024/03/GHSA-pg2q-wfgh-r323/GHSA-pg2q-wfgh-r323.json +++ b/advisories/unreviewed/2024/03/GHSA-pg2q-wfgh-r323/GHSA-pg2q-wfgh-r323.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-r2c4-w9mv-hxcf/GHSA-r2c4-w9mv-hxcf.json b/advisories/unreviewed/2024/03/GHSA-r2c4-w9mv-hxcf/GHSA-r2c4-w9mv-hxcf.json index b22bea03926..cdb5f473aee 100644 --- a/advisories/unreviewed/2024/03/GHSA-r2c4-w9mv-hxcf/GHSA-r2c4-w9mv-hxcf.json +++ b/advisories/unreviewed/2024/03/GHSA-r2c4-w9mv-hxcf/GHSA-r2c4-w9mv-hxcf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-v82h-9xhx-c8hg/GHSA-v82h-9xhx-c8hg.json b/advisories/unreviewed/2024/03/GHSA-v82h-9xhx-c8hg/GHSA-v82h-9xhx-c8hg.json index a4c368f2c9e..486600cf815 100644 --- a/advisories/unreviewed/2024/03/GHSA-v82h-9xhx-c8hg/GHSA-v82h-9xhx-c8hg.json +++ b/advisories/unreviewed/2024/03/GHSA-v82h-9xhx-c8hg/GHSA-v82h-9xhx-c8hg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-vmqf-grh3-9rrr/GHSA-vmqf-grh3-9rrr.json b/advisories/unreviewed/2024/03/GHSA-vmqf-grh3-9rrr/GHSA-vmqf-grh3-9rrr.json index 9d4dbed9a43..7d473d0077d 100644 --- a/advisories/unreviewed/2024/03/GHSA-vmqf-grh3-9rrr/GHSA-vmqf-grh3-9rrr.json +++ b/advisories/unreviewed/2024/03/GHSA-vmqf-grh3-9rrr/GHSA-vmqf-grh3-9rrr.json @@ -7,12 +7,8 @@ "CVE-2021-47178" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: core: Avoid smp_processor_id() in preemptible code\n\nThe BUG message \"BUG: using smp_processor_id() in preemptible [00000000]\ncode\" was observed for TCMU devices with kernel config DEBUG_PREEMPT.\n\nThe message was observed when blktests block/005 was run on TCMU devices\nwith fileio backend or user:zbc backend [1]. The commit 1130b499b4a7\n(\"scsi: target: tcm_loop: Use LIO wq cmd submission helper\") triggered the\nsymptom. The commit modified work queue to handle commands and changed\n'current->nr_cpu_allowed' at smp_processor_id() call.\n\nThe message was also observed at system shutdown when TCMU devices were not\ncleaned up [2]. The function smp_processor_id() was called in SCSI host\nwork queue for abort handling, and triggered the BUG message. This symptom\nwas observed regardless of the commit 1130b499b4a7 (\"scsi: target:\ntcm_loop: Use LIO wq cmd submission helper\").\n\nTo avoid the preemptible code check at smp_processor_id(), get CPU ID with\nraw_smp_processor_id() instead. The CPU ID is used for performance\nimprovement then thread move to other CPU will not affect the code.\n\n[1]\n\n[ 56.468103] run blktests block/005 at 2021-05-12 14:16:38\n[ 57.369473] check_preemption_disabled: 85 callbacks suppressed\n[ 57.369480] BUG: using smp_processor_id() in preemptible [00000000] code: fio/1511\n[ 57.369506] BUG: using smp_processor_id() in preemptible [00000000] code: fio/1510\n[ 57.369512] BUG: using smp_processor_id() in preemptible [00000000] code: fio/1506\n[ 57.369552] caller is __target_init_cmd+0x157/0x170 [target_core_mod]\n[ 57.369606] CPU: 4 PID: 1506 Comm: fio Not tainted 5.13.0-rc1+ #34\n[ 57.369613] Hardware name: System manufacturer System Product Name/PRIME Z270-A, BIOS 1302 03/15/2018\n[ 57.369617] Call Trace:\n[ 57.369621] BUG: using smp_processor_id() in preemptible [00000000] code: fio/1507\n[ 57.369628] dump_stack+0x6d/0x89\n[ 57.369642] check_preemption_disabled+0xc8/0xd0\n[ 57.369628] caller is __target_init_cmd+0x157/0x170 [target_core_mod]\n[ 57.369655] __target_init_cmd+0x157/0x170 [target_core_mod]\n[ 57.369695] target_init_cmd+0x76/0x90 [target_core_mod]\n[ 57.369732] tcm_loop_queuecommand+0x109/0x210 [tcm_loop]\n[ 57.369744] scsi_queue_rq+0x38e/0xc40\n[ 57.369761] __blk_mq_try_issue_directly+0x109/0x1c0\n[ 57.369779] blk_mq_try_issue_directly+0x43/0x90\n[ 57.369790] blk_mq_submit_bio+0x4e5/0x5d0\n[ 57.369812] submit_bio_noacct+0x46e/0x4e0\n[ 57.369830] __blkdev_direct_IO_simple+0x1a3/0x2d0\n[ 57.369859] ? set_init_blocksize.isra.0+0x60/0x60\n[ 57.369880] generic_file_read_iter+0x89/0x160\n[ 57.369898] blkdev_read_iter+0x44/0x60\n[ 57.369906] new_sync_read+0x102/0x170\n[ 57.369929] vfs_read+0xd4/0x160\n[ 57.369941] __x64_sys_pread64+0x6e/0xa0\n[ 57.369946] ? lockdep_hardirqs_on+0x79/0x100\n[ 57.369958] do_syscall_64+0x3a/0x70\n[ 57.369965] entry_SYSCALL_64_after_hwframe+0x44/0xae\n[ 57.369973] RIP: 0033:0x7f7ed4c1399f\n[ 57.369979] Code: 08 89 3c 24 48 89 4c 24 18 e8 7d f3 ff ff 4c 8b 54 24 18 48 8b 54 24 10 41 89 c0 48 8b 74 24 08 8b 3c 24 b8 11 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 31 44 89 c7 48 89 04 24 e8 cd f3 ff ff 48 8b\n[ 57.369983] RSP: 002b:00007ffd7918c580 EFLAGS: 00000293 ORIG_RAX: 0000000000000011\n[ 57.369990] RAX: ffffffffffffffda RBX: 00000000015b4540 RCX: 00007f7ed4c1399f\n[ 57.369993] RDX: 0000000000001000 RSI: 00000000015de000 RDI: 0000000000000009\n[ 57.369996] RBP: 00000000015b4540 R08: 0000000000000000 R09: 0000000000000001\n[ 57.369999] R10: 0000000000e5c000 R11: 0000000000000293 R12: 00007f7eb5269a70\n[ 57.370002] R13: 0000000000000000 R14: 0000000000001000 R15: 00000000015b4568\n[ 57.370031] CPU: 7 PID: 1507 Comm: fio Not tainted 5.13.0-rc1+ #34\n[ 57.370036] Hardware name: System manufacturer System Product Name/PRIME Z270-A, BIOS 1302 03/15/2018\n[ 57.370039] Call Trace:\n[ 57.370045] dump_stack+0x6d/0x89\n[ 57.370056] ch\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-xcwm-wrf2-369r/GHSA-xcwm-wrf2-369r.json b/advisories/unreviewed/2024/03/GHSA-xcwm-wrf2-369r/GHSA-xcwm-wrf2-369r.json index ec42693e1f4..e60382c781f 100644 --- a/advisories/unreviewed/2024/03/GHSA-xcwm-wrf2-369r/GHSA-xcwm-wrf2-369r.json +++ b/advisories/unreviewed/2024/03/GHSA-xcwm-wrf2-369r/GHSA-xcwm-wrf2-369r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-225x-44w7-hh2f/GHSA-225x-44w7-hh2f.json b/advisories/unreviewed/2024/04/GHSA-225x-44w7-hh2f/GHSA-225x-44w7-hh2f.json index e17e2a35a53..1322896771a 100644 --- a/advisories/unreviewed/2024/04/GHSA-225x-44w7-hh2f/GHSA-225x-44w7-hh2f.json +++ b/advisories/unreviewed/2024/04/GHSA-225x-44w7-hh2f/GHSA-225x-44w7-hh2f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-2pv2-gg54-r8f4/GHSA-2pv2-gg54-r8f4.json b/advisories/unreviewed/2024/04/GHSA-2pv2-gg54-r8f4/GHSA-2pv2-gg54-r8f4.json index 01943441748..62bc797252f 100644 --- a/advisories/unreviewed/2024/04/GHSA-2pv2-gg54-r8f4/GHSA-2pv2-gg54-r8f4.json +++ b/advisories/unreviewed/2024/04/GHSA-2pv2-gg54-r8f4/GHSA-2pv2-gg54-r8f4.json @@ -7,12 +7,8 @@ "CVE-2024-26783" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vmscan: fix a bug calling wakeup_kswapd() with a wrong zone index\n\nWith numa balancing on, when a numa system is running where a numa node\ndoesn't have its local memory so it has no managed zones, the following\noops has been observed. It's because wakeup_kswapd() is called with a\nwrong zone index, -1. Fixed it by checking the index before calling\nwakeup_kswapd().\n\n> BUG: unable to handle page fault for address: 00000000000033f3\n> #PF: supervisor read access in kernel mode\n> #PF: error_code(0x0000) - not-present page\n> PGD 0 P4D 0\n> Oops: 0000 [#1] PREEMPT SMP NOPTI\n> CPU: 2 PID: 895 Comm: masim Not tainted 6.6.0-dirty #255\n> Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\n> rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\n> RIP: 0010:wakeup_kswapd (./linux/mm/vmscan.c:7812)\n> Code: (omitted)\n> RSP: 0000:ffffc90004257d58 EFLAGS: 00010286\n> RAX: ffffffffffffffff RBX: ffff88883fff0480 RCX: 0000000000000003\n> RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88883fff0480\n> RBP: ffffffffffffffff R08: ff0003ffffffffff R09: ffffffffffffffff\n> R10: ffff888106c95540 R11: 0000000055555554 R12: 0000000000000003\n> R13: 0000000000000000 R14: 0000000000000000 R15: ffff88883fff0940\n> FS: 00007fc4b8124740(0000) GS:ffff888827c00000(0000) knlGS:0000000000000000\n> CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n> CR2: 00000000000033f3 CR3: 000000026cc08004 CR4: 0000000000770ee0\n> DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n> DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n> PKRU: 55555554\n> Call Trace:\n> \n> ? __die\n> ? page_fault_oops\n> ? __pte_offset_map_lock\n> ? exc_page_fault\n> ? asm_exc_page_fault\n> ? wakeup_kswapd\n> migrate_misplaced_page\n> __handle_mm_fault\n> handle_mm_fault\n> do_user_addr_fault\n> exc_page_fault\n> asm_exc_page_fault\n> RIP: 0033:0x55b897ba0808\n> Code: (omitted)\n> RSP: 002b:00007ffeefa821a0 EFLAGS: 00010287\n> RAX: 000055b89983acd0 RBX: 00007ffeefa823f8 RCX: 000055b89983acd0\n> RDX: 00007fc2f8122010 RSI: 0000000000020000 RDI: 000055b89983acd0\n> RBP: 00007ffeefa821a0 R08: 0000000000000037 R09: 0000000000000075\n> R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000000000\n> R13: 00007ffeefa82410 R14: 000055b897ba5dd8 R15: 00007fc4b8340000\n> ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2q2v-8vjq-r8m5/GHSA-2q2v-8vjq-r8m5.json b/advisories/unreviewed/2024/04/GHSA-2q2v-8vjq-r8m5/GHSA-2q2v-8vjq-r8m5.json index 2433ad9a96f..3fd6361fb78 100644 --- a/advisories/unreviewed/2024/04/GHSA-2q2v-8vjq-r8m5/GHSA-2q2v-8vjq-r8m5.json +++ b/advisories/unreviewed/2024/04/GHSA-2q2v-8vjq-r8m5/GHSA-2q2v-8vjq-r8m5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2v7w-h3hv-34rp/GHSA-2v7w-h3hv-34rp.json b/advisories/unreviewed/2024/04/GHSA-2v7w-h3hv-34rp/GHSA-2v7w-h3hv-34rp.json index 9a6c9e02df1..efa788e6d35 100644 --- a/advisories/unreviewed/2024/04/GHSA-2v7w-h3hv-34rp/GHSA-2v7w-h3hv-34rp.json +++ b/advisories/unreviewed/2024/04/GHSA-2v7w-h3hv-34rp/GHSA-2v7w-h3hv-34rp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-346g-pfrw-wm3v/GHSA-346g-pfrw-wm3v.json b/advisories/unreviewed/2024/04/GHSA-346g-pfrw-wm3v/GHSA-346g-pfrw-wm3v.json index 9d1d8b2c40e..6203a08da2a 100644 --- a/advisories/unreviewed/2024/04/GHSA-346g-pfrw-wm3v/GHSA-346g-pfrw-wm3v.json +++ b/advisories/unreviewed/2024/04/GHSA-346g-pfrw-wm3v/GHSA-346g-pfrw-wm3v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-459v-rpwc-w8fx/GHSA-459v-rpwc-w8fx.json b/advisories/unreviewed/2024/04/GHSA-459v-rpwc-w8fx/GHSA-459v-rpwc-w8fx.json index b9e1277cd2c..780cc148390 100644 --- a/advisories/unreviewed/2024/04/GHSA-459v-rpwc-w8fx/GHSA-459v-rpwc-w8fx.json +++ b/advisories/unreviewed/2024/04/GHSA-459v-rpwc-w8fx/GHSA-459v-rpwc-w8fx.json @@ -7,12 +7,8 @@ "CVE-2024-29743" ], "details": "In tmu_set_temp_lut of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4fv5-487x-c795/GHSA-4fv5-487x-c795.json b/advisories/unreviewed/2024/04/GHSA-4fv5-487x-c795/GHSA-4fv5-487x-c795.json index 039795fa143..2ba94c5dd16 100644 --- a/advisories/unreviewed/2024/04/GHSA-4fv5-487x-c795/GHSA-4fv5-487x-c795.json +++ b/advisories/unreviewed/2024/04/GHSA-4fv5-487x-c795/GHSA-4fv5-487x-c795.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-53x2-fcg3-m32m/GHSA-53x2-fcg3-m32m.json b/advisories/unreviewed/2024/04/GHSA-53x2-fcg3-m32m/GHSA-53x2-fcg3-m32m.json index 7431cf8f480..d3c1af9acc1 100644 --- a/advisories/unreviewed/2024/04/GHSA-53x2-fcg3-m32m/GHSA-53x2-fcg3-m32m.json +++ b/advisories/unreviewed/2024/04/GHSA-53x2-fcg3-m32m/GHSA-53x2-fcg3-m32m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-54gx-9g28-h45h/GHSA-54gx-9g28-h45h.json b/advisories/unreviewed/2024/04/GHSA-54gx-9g28-h45h/GHSA-54gx-9g28-h45h.json index a6334cf06f9..a9933366f17 100644 --- a/advisories/unreviewed/2024/04/GHSA-54gx-9g28-h45h/GHSA-54gx-9g28-h45h.json +++ b/advisories/unreviewed/2024/04/GHSA-54gx-9g28-h45h/GHSA-54gx-9g28-h45h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-57r3-6fx2-p6rg/GHSA-57r3-6fx2-p6rg.json b/advisories/unreviewed/2024/04/GHSA-57r3-6fx2-p6rg/GHSA-57r3-6fx2-p6rg.json index 9b9c7a20bd9..dc28204642d 100644 --- a/advisories/unreviewed/2024/04/GHSA-57r3-6fx2-p6rg/GHSA-57r3-6fx2-p6rg.json +++ b/advisories/unreviewed/2024/04/GHSA-57r3-6fx2-p6rg/GHSA-57r3-6fx2-p6rg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-6426-p644-ffcf/GHSA-6426-p644-ffcf.json b/advisories/unreviewed/2024/04/GHSA-6426-p644-ffcf/GHSA-6426-p644-ffcf.json index a3f8fb1c82e..08d72da5370 100644 --- a/advisories/unreviewed/2024/04/GHSA-6426-p644-ffcf/GHSA-6426-p644-ffcf.json +++ b/advisories/unreviewed/2024/04/GHSA-6426-p644-ffcf/GHSA-6426-p644-ffcf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-6mrw-fw7h-8g24/GHSA-6mrw-fw7h-8g24.json b/advisories/unreviewed/2024/04/GHSA-6mrw-fw7h-8g24/GHSA-6mrw-fw7h-8g24.json index f5415227ab1..cb212b65720 100644 --- a/advisories/unreviewed/2024/04/GHSA-6mrw-fw7h-8g24/GHSA-6mrw-fw7h-8g24.json +++ b/advisories/unreviewed/2024/04/GHSA-6mrw-fw7h-8g24/GHSA-6mrw-fw7h-8g24.json @@ -7,12 +7,8 @@ "CVE-2024-29782" ], "details": "In tmu_get_tr_num_thresholds of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-6pfx-3rw7-5c4g/GHSA-6pfx-3rw7-5c4g.json b/advisories/unreviewed/2024/04/GHSA-6pfx-3rw7-5c4g/GHSA-6pfx-3rw7-5c4g.json index 164383a28eb..9f08cfb4987 100644 --- a/advisories/unreviewed/2024/04/GHSA-6pfx-3rw7-5c4g/GHSA-6pfx-3rw7-5c4g.json +++ b/advisories/unreviewed/2024/04/GHSA-6pfx-3rw7-5c4g/GHSA-6pfx-3rw7-5c4g.json @@ -7,12 +7,8 @@ "CVE-2024-29738" ], "details": "In gov_init, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-6w9f-jx26-wxpp/GHSA-6w9f-jx26-wxpp.json b/advisories/unreviewed/2024/04/GHSA-6w9f-jx26-wxpp/GHSA-6w9f-jx26-wxpp.json index df497471d3a..81ff170864a 100644 --- a/advisories/unreviewed/2024/04/GHSA-6w9f-jx26-wxpp/GHSA-6w9f-jx26-wxpp.json +++ b/advisories/unreviewed/2024/04/GHSA-6w9f-jx26-wxpp/GHSA-6w9f-jx26-wxpp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-7w6v-jhvx-qx5c/GHSA-7w6v-jhvx-qx5c.json b/advisories/unreviewed/2024/04/GHSA-7w6v-jhvx-qx5c/GHSA-7w6v-jhvx-qx5c.json index 68da47eaf0b..e442e49ffb7 100644 --- a/advisories/unreviewed/2024/04/GHSA-7w6v-jhvx-qx5c/GHSA-7w6v-jhvx-qx5c.json +++ b/advisories/unreviewed/2024/04/GHSA-7w6v-jhvx-qx5c/GHSA-7w6v-jhvx-qx5c.json @@ -7,12 +7,8 @@ "CVE-2024-26792" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix double free of anonymous device after snapshot creation failure\n\nWhen creating a snapshot we may do a double free of an anonymous device\nin case there's an error committing the transaction. The second free may\nresult in freeing an anonymous device number that was allocated by some\nother subsystem in the kernel or another btrfs filesystem.\n\nThe steps that lead to this:\n\n1) At ioctl.c:create_snapshot() we allocate an anonymous device number\n and assign it to pending_snapshot->anon_dev;\n\n2) Then we call btrfs_commit_transaction() and end up at\n transaction.c:create_pending_snapshot();\n\n3) There we call btrfs_get_new_fs_root() and pass it the anonymous device\n number stored in pending_snapshot->anon_dev;\n\n4) btrfs_get_new_fs_root() frees that anonymous device number because\n btrfs_lookup_fs_root() returned a root - someone else did a lookup\n of the new root already, which could some task doing backref walking;\n\n5) After that some error happens in the transaction commit path, and at\n ioctl.c:create_snapshot() we jump to the 'fail' label, and after\n that we free again the same anonymous device number, which in the\n meanwhile may have been reallocated somewhere else, because\n pending_snapshot->anon_dev still has the same value as in step 1.\n\nRecently syzbot ran into this and reported the following trace:\n\n ------------[ cut here ]------------\n ida_free called for id=51 which is not allocated.\n WARNING: CPU: 1 PID: 31038 at lib/idr.c:525 ida_free+0x370/0x420 lib/idr.c:525\n Modules linked in:\n CPU: 1 PID: 31038 Comm: syz-executor.2 Not tainted 6.8.0-rc4-syzkaller-00410-gc02197fc9076 #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/25/2024\n RIP: 0010:ida_free+0x370/0x420 lib/idr.c:525\n Code: 10 42 80 3c 28 (...)\n RSP: 0018:ffffc90015a67300 EFLAGS: 00010246\n RAX: be5130472f5dd000 RBX: 0000000000000033 RCX: 0000000000040000\n RDX: ffffc90009a7a000 RSI: 000000000003ffff RDI: 0000000000040000\n RBP: ffffc90015a673f0 R08: ffffffff81577992 R09: 1ffff92002b4cdb4\n R10: dffffc0000000000 R11: fffff52002b4cdb5 R12: 0000000000000246\n R13: dffffc0000000000 R14: ffffffff8e256b80 R15: 0000000000000246\n FS: 00007fca3f4b46c0(0000) GS:ffff8880b9500000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f167a17b978 CR3: 000000001ed26000 CR4: 0000000000350ef0\n Call Trace:\n \n btrfs_get_root_ref+0xa48/0xaf0 fs/btrfs/disk-io.c:1346\n create_pending_snapshot+0xff2/0x2bc0 fs/btrfs/transaction.c:1837\n create_pending_snapshots+0x195/0x1d0 fs/btrfs/transaction.c:1931\n btrfs_commit_transaction+0xf1c/0x3740 fs/btrfs/transaction.c:2404\n create_snapshot+0x507/0x880 fs/btrfs/ioctl.c:848\n btrfs_mksubvol+0x5d0/0x750 fs/btrfs/ioctl.c:998\n btrfs_mksnapshot+0xb5/0xf0 fs/btrfs/ioctl.c:1044\n __btrfs_ioctl_snap_create+0x387/0x4b0 fs/btrfs/ioctl.c:1306\n btrfs_ioctl_snap_create_v2+0x1ca/0x400 fs/btrfs/ioctl.c:1393\n btrfs_ioctl+0xa74/0xd40\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:871 [inline]\n __se_sys_ioctl+0xfe/0x170 fs/ioctl.c:857\n do_syscall_64+0xfb/0x240\n entry_SYSCALL_64_after_hwframe+0x6f/0x77\n RIP: 0033:0x7fca3e67dda9\n Code: 28 00 00 00 (...)\n RSP: 002b:00007fca3f4b40c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\n RAX: ffffffffffffffda RBX: 00007fca3e7abf80 RCX: 00007fca3e67dda9\n RDX: 00000000200005c0 RSI: 0000000050009417 RDI: 0000000000000003\n RBP: 00007fca3e6ca47a R08: 0000000000000000 R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\n R13: 000000000000000b R14: 00007fca3e7abf80 R15: 00007fff6bf95658\n \n\nWhere we get an explicit message where we attempt to free an anonymous\ndevice number that is not currently allocated. It happens in a different\ncode path from the example below, at btrfs_get_root_ref(), so this change\nmay not fix the case triggered by sy\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-85f3-pf99-4rpm/GHSA-85f3-pf99-4rpm.json b/advisories/unreviewed/2024/04/GHSA-85f3-pf99-4rpm/GHSA-85f3-pf99-4rpm.json index 1870484a77f..c060289c4d3 100644 --- a/advisories/unreviewed/2024/04/GHSA-85f3-pf99-4rpm/GHSA-85f3-pf99-4rpm.json +++ b/advisories/unreviewed/2024/04/GHSA-85f3-pf99-4rpm/GHSA-85f3-pf99-4rpm.json @@ -7,12 +7,8 @@ "CVE-2024-29744" ], "details": "In tmu_get_gov_time_windows, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-866j-mv4h-26jh/GHSA-866j-mv4h-26jh.json b/advisories/unreviewed/2024/04/GHSA-866j-mv4h-26jh/GHSA-866j-mv4h-26jh.json index 47c33ef18a4..d987bf3734a 100644 --- a/advisories/unreviewed/2024/04/GHSA-866j-mv4h-26jh/GHSA-866j-mv4h-26jh.json +++ b/advisories/unreviewed/2024/04/GHSA-866j-mv4h-26jh/GHSA-866j-mv4h-26jh.json @@ -7,12 +7,8 @@ "CVE-2024-26803" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: veth: clear GRO when clearing XDP even when down\n\nveth sets NETIF_F_GRO automatically when XDP is enabled,\nbecause both features use the same NAPI machinery.\n\nThe logic to clear NETIF_F_GRO sits in veth_disable_xdp() which\nis called both on ndo_stop and when XDP is turned off.\nTo avoid the flag from being cleared when the device is brought\ndown, the clearing is skipped when IFF_UP is not set.\nBringing the device down should indeed not modify its features.\n\nUnfortunately, this means that clearing is also skipped when\nXDP is disabled _while_ the device is down. And there's nothing\non the open path to bring the device features back into sync.\nIOW if user enables XDP, disables it and then brings the device\nup we'll end up with a stray GRO flag set but no NAPI instances.\n\nWe don't depend on the GRO flag on the datapath, so the datapath\nwon't crash. We will crash (or hang), however, next time features\nare sync'ed (either by user via ethtool or peer changing its config).\nThe GRO flag will go away, and veth will try to disable the NAPIs.\nBut the open path never created them since XDP was off, the GRO flag\nwas a stray. If NAPI was initialized before we'll hang in napi_disable().\nIf it never was we'll crash trying to stop uninitialized hrtimer.\n\nMove the GRO flag updates to the XDP enable / disable paths,\ninstead of mixing them with the ndo_open / ndo_close paths.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-87f6-4648-854h/GHSA-87f6-4648-854h.json b/advisories/unreviewed/2024/04/GHSA-87f6-4648-854h/GHSA-87f6-4648-854h.json index 9d7695c5931..7c51883865a 100644 --- a/advisories/unreviewed/2024/04/GHSA-87f6-4648-854h/GHSA-87f6-4648-854h.json +++ b/advisories/unreviewed/2024/04/GHSA-87f6-4648-854h/GHSA-87f6-4648-854h.json @@ -7,12 +7,8 @@ "CVE-2024-29754" ], "details": "In TMU_IPC_GET_TABLE, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-92rg-x2hq-jc97/GHSA-92rg-x2hq-jc97.json b/advisories/unreviewed/2024/04/GHSA-92rg-x2hq-jc97/GHSA-92rg-x2hq-jc97.json index 09ac5e95ebf..6e5c8ecf1bc 100644 --- a/advisories/unreviewed/2024/04/GHSA-92rg-x2hq-jc97/GHSA-92rg-x2hq-jc97.json +++ b/advisories/unreviewed/2024/04/GHSA-92rg-x2hq-jc97/GHSA-92rg-x2hq-jc97.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-95rc-29j2-q3vr/GHSA-95rc-29j2-q3vr.json b/advisories/unreviewed/2024/04/GHSA-95rc-29j2-q3vr/GHSA-95rc-29j2-q3vr.json index fc7d465e102..6b5329d8eff 100644 --- a/advisories/unreviewed/2024/04/GHSA-95rc-29j2-q3vr/GHSA-95rc-29j2-q3vr.json +++ b/advisories/unreviewed/2024/04/GHSA-95rc-29j2-q3vr/GHSA-95rc-29j2-q3vr.json @@ -7,12 +7,8 @@ "CVE-2024-26780" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Fix task hung while purging oob_skb in GC.\n\nsyzbot reported a task hung; at the same time, GC was looping infinitely\nin list_for_each_entry_safe() for OOB skb. [0]\n\nsyzbot demonstrated that the list_for_each_entry_safe() was not actually\nsafe in this case.\n\nA single skb could have references for multiple sockets. If we free such\na skb in the list_for_each_entry_safe(), the current and next sockets could\nbe unlinked in a single iteration.\n\nunix_notinflight() uses list_del_init() to unlink the socket, so the\nprefetched next socket forms a loop itself and list_for_each_entry_safe()\nnever stops.\n\nHere, we must use while() and make sure we always fetch the first socket.\n\n[0]:\nSending NMI from CPU 0 to CPUs 1:\nNMI backtrace for cpu 1\nCPU: 1 PID: 5065 Comm: syz-executor236 Not tainted 6.8.0-rc3-syzkaller-00136-g1f719a2f3fa6 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/25/2024\nRIP: 0010:preempt_count arch/x86/include/asm/preempt.h:26 [inline]\nRIP: 0010:check_kcov_mode kernel/kcov.c:173 [inline]\nRIP: 0010:__sanitizer_cov_trace_pc+0xd/0x60 kernel/kcov.c:207\nCode: cc cc cc cc 66 0f 1f 84 00 00 00 00 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 65 48 8b 14 25 40 c2 03 00 <65> 8b 05 b4 7c 78 7e a9 00 01 ff 00 48 8b 34 24 74 0f f6 c4 01 74\nRSP: 0018:ffffc900033efa58 EFLAGS: 00000283\nRAX: ffff88807b077800 RBX: ffff88807b077800 RCX: 1ffffffff27b1189\nRDX: ffff88802a5a3b80 RSI: ffffffff8968488d RDI: ffff88807b077f70\nRBP: ffffc900033efbb0 R08: 0000000000000001 R09: fffffbfff27a900c\nR10: ffffffff93d48067 R11: ffffffff8ae000eb R12: ffff88807b077800\nR13: dffffc0000000000 R14: ffff88807b077e40 R15: 0000000000000001\nFS: 0000000000000000(0000) GS:ffff8880b9500000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000564f4fc1e3a8 CR3: 000000000d57a000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n \n \n unix_gc+0x563/0x13b0 net/unix/garbage.c:319\n unix_release_sock+0xa93/0xf80 net/unix/af_unix.c:683\n unix_release+0x91/0xf0 net/unix/af_unix.c:1064\n __sock_release+0xb0/0x270 net/socket.c:659\n sock_close+0x1c/0x30 net/socket.c:1421\n __fput+0x270/0xb80 fs/file_table.c:376\n task_work_run+0x14f/0x250 kernel/task_work.c:180\n exit_task_work include/linux/task_work.h:38 [inline]\n do_exit+0xa8a/0x2ad0 kernel/exit.c:871\n do_group_exit+0xd4/0x2a0 kernel/exit.c:1020\n __do_sys_exit_group kernel/exit.c:1031 [inline]\n __se_sys_exit_group kernel/exit.c:1029 [inline]\n __x64_sys_exit_group+0x3e/0x50 kernel/exit.c:1029\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xd5/0x270 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x6f/0x77\nRIP: 0033:0x7f9d6cbdac09\nCode: Unable to access opcode bytes at 0x7f9d6cbdabdf.\nRSP: 002b:00007fff5952feb8 EFLAGS: 00000246 ORIG_RAX: 00000000000000e7\nRAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f9d6cbdac09\nRDX: 000000000000003c RSI: 00000000000000e7 RDI: 0000000000000000\nRBP: 00007f9d6cc552b0 R08: ffffffffffffffb8 R09: 0000000000000006\nR10: 0000000000000006 R11: 0000000000000246 R12: 00007f9d6cc552b0\nR13: 0000000000000000 R14: 00007f9d6cc55d00 R15: 00007f9d6cbabe70\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-9m7w-p6hr-xv2x/GHSA-9m7w-p6hr-xv2x.json b/advisories/unreviewed/2024/04/GHSA-9m7w-p6hr-xv2x/GHSA-9m7w-p6hr-xv2x.json index fe09d5f7880..8bf7ac41611 100644 --- a/advisories/unreviewed/2024/04/GHSA-9m7w-p6hr-xv2x/GHSA-9m7w-p6hr-xv2x.json +++ b/advisories/unreviewed/2024/04/GHSA-9m7w-p6hr-xv2x/GHSA-9m7w-p6hr-xv2x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-9xr8-gjj4-777r/GHSA-9xr8-gjj4-777r.json b/advisories/unreviewed/2024/04/GHSA-9xr8-gjj4-777r/GHSA-9xr8-gjj4-777r.json index d3c5ad93dbe..6e007fd0bbb 100644 --- a/advisories/unreviewed/2024/04/GHSA-9xr8-gjj4-777r/GHSA-9xr8-gjj4-777r.json +++ b/advisories/unreviewed/2024/04/GHSA-9xr8-gjj4-777r/GHSA-9xr8-gjj4-777r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-c52r-8hmj-x4qg/GHSA-c52r-8hmj-x4qg.json b/advisories/unreviewed/2024/04/GHSA-c52r-8hmj-x4qg/GHSA-c52r-8hmj-x4qg.json index ede26411cda..80cc0a25b21 100644 --- a/advisories/unreviewed/2024/04/GHSA-c52r-8hmj-x4qg/GHSA-c52r-8hmj-x4qg.json +++ b/advisories/unreviewed/2024/04/GHSA-c52r-8hmj-x4qg/GHSA-c52r-8hmj-x4qg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-cjgj-qv8v-fhgh/GHSA-cjgj-qv8v-fhgh.json b/advisories/unreviewed/2024/04/GHSA-cjgj-qv8v-fhgh/GHSA-cjgj-qv8v-fhgh.json index 0a8f8796cf0..48a0d1ca42d 100644 --- a/advisories/unreviewed/2024/04/GHSA-cjgj-qv8v-fhgh/GHSA-cjgj-qv8v-fhgh.json +++ b/advisories/unreviewed/2024/04/GHSA-cjgj-qv8v-fhgh/GHSA-cjgj-qv8v-fhgh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-cq4r-22pw-4cc7/GHSA-cq4r-22pw-4cc7.json b/advisories/unreviewed/2024/04/GHSA-cq4r-22pw-4cc7/GHSA-cq4r-22pw-4cc7.json index e4d36ff65bc..3732fccd65a 100644 --- a/advisories/unreviewed/2024/04/GHSA-cq4r-22pw-4cc7/GHSA-cq4r-22pw-4cc7.json +++ b/advisories/unreviewed/2024/04/GHSA-cq4r-22pw-4cc7/GHSA-cq4r-22pw-4cc7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-cxc3-9vgm-w6pp/GHSA-cxc3-9vgm-w6pp.json b/advisories/unreviewed/2024/04/GHSA-cxc3-9vgm-w6pp/GHSA-cxc3-9vgm-w6pp.json index ada2c79f0c8..8ce640b0f65 100644 --- a/advisories/unreviewed/2024/04/GHSA-cxc3-9vgm-w6pp/GHSA-cxc3-9vgm-w6pp.json +++ b/advisories/unreviewed/2024/04/GHSA-cxc3-9vgm-w6pp/GHSA-cxc3-9vgm-w6pp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-f3hc-9q6r-j846/GHSA-f3hc-9q6r-j846.json b/advisories/unreviewed/2024/04/GHSA-f3hc-9q6r-j846/GHSA-f3hc-9q6r-j846.json index fdd97c01af0..41737e4dff6 100644 --- a/advisories/unreviewed/2024/04/GHSA-f3hc-9q6r-j846/GHSA-f3hc-9q6r-j846.json +++ b/advisories/unreviewed/2024/04/GHSA-f3hc-9q6r-j846/GHSA-f3hc-9q6r-j846.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-fqqx-226c-w34m/GHSA-fqqx-226c-w34m.json b/advisories/unreviewed/2024/04/GHSA-fqqx-226c-w34m/GHSA-fqqx-226c-w34m.json index 10e8af75a40..a9e54cc8161 100644 --- a/advisories/unreviewed/2024/04/GHSA-fqqx-226c-w34m/GHSA-fqqx-226c-w34m.json +++ b/advisories/unreviewed/2024/04/GHSA-fqqx-226c-w34m/GHSA-fqqx-226c-w34m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-frw5-678v-439g/GHSA-frw5-678v-439g.json b/advisories/unreviewed/2024/04/GHSA-frw5-678v-439g/GHSA-frw5-678v-439g.json index 06117a72767..32dd2d317e1 100644 --- a/advisories/unreviewed/2024/04/GHSA-frw5-678v-439g/GHSA-frw5-678v-439g.json +++ b/advisories/unreviewed/2024/04/GHSA-frw5-678v-439g/GHSA-frw5-678v-439g.json @@ -7,12 +7,8 @@ "CVE-2024-26746" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: Ensure safe user copy of completion record\n\nIf CONFIG_HARDENED_USERCOPY is enabled, copying completion record from\nevent log cache to user triggers a kernel bug.\n\n[ 1987.159822] usercopy: Kernel memory exposure attempt detected from SLUB object 'dsa0' (offset 74, size 31)!\n[ 1987.170845] ------------[ cut here ]------------\n[ 1987.176086] kernel BUG at mm/usercopy.c:102!\n[ 1987.180946] invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\n[ 1987.186866] CPU: 17 PID: 528 Comm: kworker/17:1 Not tainted 6.8.0-rc2+ #5\n[ 1987.194537] Hardware name: Intel Corporation AvenueCity/AvenueCity, BIOS BHSDCRB1.86B.2492.D03.2307181620 07/18/2023\n[ 1987.206405] Workqueue: wq0.0 idxd_evl_fault_work [idxd]\n[ 1987.212338] RIP: 0010:usercopy_abort+0x72/0x90\n[ 1987.217381] Code: 58 65 9c 50 48 c7 c2 17 85 61 9c 57 48 c7 c7 98 fd 6b 9c 48 0f 44 d6 48 c7 c6 b3 08 62 9c 4c 89 d1 49 0f 44 f3 e8 1e 2e d5 ff <0f> 0b 49 c7 c1 9e 42 61 9c 4c 89 cf 4d 89 c8 eb a9 66 66 2e 0f 1f\n[ 1987.238505] RSP: 0018:ff62f5cf20607d60 EFLAGS: 00010246\n[ 1987.244423] RAX: 000000000000005f RBX: 000000000000001f RCX: 0000000000000000\n[ 1987.252480] RDX: 0000000000000000 RSI: ffffffff9c61429e RDI: 00000000ffffffff\n[ 1987.260538] RBP: ff62f5cf20607d78 R08: ff2a6a89ef3fffe8 R09: 00000000fffeffff\n[ 1987.268595] R10: ff2a6a89eed00000 R11: 0000000000000003 R12: ff2a66934849c89a\n[ 1987.276652] R13: 0000000000000001 R14: ff2a66934849c8b9 R15: ff2a66934849c899\n[ 1987.284710] FS: 0000000000000000(0000) GS:ff2a66b22fe40000(0000) knlGS:0000000000000000\n[ 1987.293850] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 1987.300355] CR2: 00007fe291a37000 CR3: 000000010fbd4005 CR4: 0000000000f71ef0\n[ 1987.308413] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 1987.316470] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400\n[ 1987.324527] PKRU: 55555554\n[ 1987.327622] Call Trace:\n[ 1987.330424] \n[ 1987.332826] ? show_regs+0x6e/0x80\n[ 1987.336703] ? die+0x3c/0xa0\n[ 1987.339988] ? do_trap+0xd4/0xf0\n[ 1987.343662] ? do_error_trap+0x75/0xa0\n[ 1987.347922] ? usercopy_abort+0x72/0x90\n[ 1987.352277] ? exc_invalid_op+0x57/0x80\n[ 1987.356634] ? usercopy_abort+0x72/0x90\n[ 1987.360988] ? asm_exc_invalid_op+0x1f/0x30\n[ 1987.365734] ? usercopy_abort+0x72/0x90\n[ 1987.370088] __check_heap_object+0xb7/0xd0\n[ 1987.374739] __check_object_size+0x175/0x2d0\n[ 1987.379588] idxd_copy_cr+0xa9/0x130 [idxd]\n[ 1987.384341] idxd_evl_fault_work+0x127/0x390 [idxd]\n[ 1987.389878] process_one_work+0x13e/0x300\n[ 1987.394435] ? __pfx_worker_thread+0x10/0x10\n[ 1987.399284] worker_thread+0x2f7/0x420\n[ 1987.403544] ? _raw_spin_unlock_irqrestore+0x2b/0x50\n[ 1987.409171] ? __pfx_worker_thread+0x10/0x10\n[ 1987.414019] kthread+0x107/0x140\n[ 1987.417693] ? __pfx_kthread+0x10/0x10\n[ 1987.421954] ret_from_fork+0x3d/0x60\n[ 1987.426019] ? __pfx_kthread+0x10/0x10\n[ 1987.430281] ret_from_fork_asm+0x1b/0x30\n[ 1987.434744] \n\nThe issue arises because event log cache is created using\nkmem_cache_create() which is not suitable for user copy.\n\nFix the issue by creating event log cache with\nkmem_cache_create_usercopy(), ensuring safe user copy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-g42r-4xc7-377c/GHSA-g42r-4xc7-377c.json b/advisories/unreviewed/2024/04/GHSA-g42r-4xc7-377c/GHSA-g42r-4xc7-377c.json index 459d713020c..e9366f11703 100644 --- a/advisories/unreviewed/2024/04/GHSA-g42r-4xc7-377c/GHSA-g42r-4xc7-377c.json +++ b/advisories/unreviewed/2024/04/GHSA-g42r-4xc7-377c/GHSA-g42r-4xc7-377c.json @@ -7,12 +7,8 @@ "CVE-2024-29747" ], "details": "In _dvfs_get_lv of dvfs.c, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-gj3p-9jv7-cm49/GHSA-gj3p-9jv7-cm49.json b/advisories/unreviewed/2024/04/GHSA-gj3p-9jv7-cm49/GHSA-gj3p-9jv7-cm49.json index c39d5041db9..4066474789a 100644 --- a/advisories/unreviewed/2024/04/GHSA-gj3p-9jv7-cm49/GHSA-gj3p-9jv7-cm49.json +++ b/advisories/unreviewed/2024/04/GHSA-gj3p-9jv7-cm49/GHSA-gj3p-9jv7-cm49.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-gj98-2c7c-vmc4/GHSA-gj98-2c7c-vmc4.json b/advisories/unreviewed/2024/04/GHSA-gj98-2c7c-vmc4/GHSA-gj98-2c7c-vmc4.json index e5e4f66d625..e3bf18aa70f 100644 --- a/advisories/unreviewed/2024/04/GHSA-gj98-2c7c-vmc4/GHSA-gj98-2c7c-vmc4.json +++ b/advisories/unreviewed/2024/04/GHSA-gj98-2c7c-vmc4/GHSA-gj98-2c7c-vmc4.json @@ -7,12 +7,8 @@ "CVE-2024-31852" ], "details": "LLVM before 18.1.3 generates code in which the LR register can be overwritten without data being saved to the stack, and thus there can sometimes be an exploitable error in the flow of control. This affects the ARM backend and can be demonstrated with Clang. NOTE: the vendor perspective is \"we don't have strong objections for a CVE to be created ... It does seem that the likelihood of this miscompile enabling an exploit remains very low, because the miscompile resulting in this JOP gadget is such that the function is most likely to crash on most valid inputs to the function. So, if this function is covered by any testing, the miscompile is most likely to be discovered before the binary is shipped to production.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-h2vw-qxx3-m3jv/GHSA-h2vw-qxx3-m3jv.json b/advisories/unreviewed/2024/04/GHSA-h2vw-qxx3-m3jv/GHSA-h2vw-qxx3-m3jv.json index 61cbd1faf0c..bde15f417f4 100644 --- a/advisories/unreviewed/2024/04/GHSA-h2vw-qxx3-m3jv/GHSA-h2vw-qxx3-m3jv.json +++ b/advisories/unreviewed/2024/04/GHSA-h2vw-qxx3-m3jv/GHSA-h2vw-qxx3-m3jv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-hg8p-x2hq-57m9/GHSA-hg8p-x2hq-57m9.json b/advisories/unreviewed/2024/04/GHSA-hg8p-x2hq-57m9/GHSA-hg8p-x2hq-57m9.json index 47448df0ae8..295be873147 100644 --- a/advisories/unreviewed/2024/04/GHSA-hg8p-x2hq-57m9/GHSA-hg8p-x2hq-57m9.json +++ b/advisories/unreviewed/2024/04/GHSA-hg8p-x2hq-57m9/GHSA-hg8p-x2hq-57m9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-hhxq-r4w4-4f7m/GHSA-hhxq-r4w4-4f7m.json b/advisories/unreviewed/2024/04/GHSA-hhxq-r4w4-4f7m/GHSA-hhxq-r4w4-4f7m.json index 9e8bd8d7cbe..9c7db874fa1 100644 --- a/advisories/unreviewed/2024/04/GHSA-hhxq-r4w4-4f7m/GHSA-hhxq-r4w4-4f7m.json +++ b/advisories/unreviewed/2024/04/GHSA-hhxq-r4w4-4f7m/GHSA-hhxq-r4w4-4f7m.json @@ -7,12 +7,8 @@ "CVE-2024-26784" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npmdomain: arm: Fix NULL dereference on scmi_perf_domain removal\n\nOn unloading of the scmi_perf_domain module got the below splat, when in\nthe DT provided to the system under test the '#power-domain-cells' property\nwas missing. Indeed, this particular setup causes the probe to bail out\nearly without giving any error, which leads to the ->remove() callback gets\nto run too, but without all the expected initialized structures in place.\n\nAdd a check and bail out early on remove too.\n\n Call trace:\n scmi_perf_domain_remove+0x28/0x70 [scmi_perf_domain]\n scmi_dev_remove+0x28/0x40 [scmi_core]\n device_remove+0x54/0x90\n device_release_driver_internal+0x1dc/0x240\n driver_detach+0x58/0xa8\n bus_remove_driver+0x78/0x108\n driver_unregister+0x38/0x70\n scmi_driver_unregister+0x28/0x180 [scmi_core]\n scmi_perf_domain_driver_exit+0x18/0xb78 [scmi_perf_domain]\n __arm64_sys_delete_module+0x1a8/0x2c0\n invoke_syscall+0x50/0x128\n el0_svc_common.constprop.0+0x48/0xf0\n do_el0_svc+0x24/0x38\n el0_svc+0x34/0xb8\n el0t_64_sync_handler+0x100/0x130\n el0t_64_sync+0x190/0x198\n Code: a90153f3 f9403c14 f9414800 955f8a05 (b9400a80)\n ---[ end trace 0000000000000000 ]---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-j947-jfqc-5v3q/GHSA-j947-jfqc-5v3q.json b/advisories/unreviewed/2024/04/GHSA-j947-jfqc-5v3q/GHSA-j947-jfqc-5v3q.json index 66cf05c7d7a..dfe748ff33c 100644 --- a/advisories/unreviewed/2024/04/GHSA-j947-jfqc-5v3q/GHSA-j947-jfqc-5v3q.json +++ b/advisories/unreviewed/2024/04/GHSA-j947-jfqc-5v3q/GHSA-j947-jfqc-5v3q.json @@ -7,12 +7,8 @@ "CVE-2024-29783" ], "details": "In tmu_get_tr_thresholds, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jh5x-r89q-r9g4/GHSA-jh5x-r89q-r9g4.json b/advisories/unreviewed/2024/04/GHSA-jh5x-r89q-r9g4/GHSA-jh5x-r89q-r9g4.json index 3c4542dfb43..1a7f5cb6174 100644 --- a/advisories/unreviewed/2024/04/GHSA-jh5x-r89q-r9g4/GHSA-jh5x-r89q-r9g4.json +++ b/advisories/unreviewed/2024/04/GHSA-jh5x-r89q-r9g4/GHSA-jh5x-r89q-r9g4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-jjfv-x9mq-7m6v/GHSA-jjfv-x9mq-7m6v.json b/advisories/unreviewed/2024/04/GHSA-jjfv-x9mq-7m6v/GHSA-jjfv-x9mq-7m6v.json index 84f6e54c892..bdc6547089a 100644 --- a/advisories/unreviewed/2024/04/GHSA-jjfv-x9mq-7m6v/GHSA-jjfv-x9mq-7m6v.json +++ b/advisories/unreviewed/2024/04/GHSA-jjfv-x9mq-7m6v/GHSA-jjfv-x9mq-7m6v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-m52h-743p-4255/GHSA-m52h-743p-4255.json b/advisories/unreviewed/2024/04/GHSA-m52h-743p-4255/GHSA-m52h-743p-4255.json index 63ef5fc7347..54e92ca3a4d 100644 --- a/advisories/unreviewed/2024/04/GHSA-m52h-743p-4255/GHSA-m52h-743p-4255.json +++ b/advisories/unreviewed/2024/04/GHSA-m52h-743p-4255/GHSA-m52h-743p-4255.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-mcgw-94j6-6g4q/GHSA-mcgw-94j6-6g4q.json b/advisories/unreviewed/2024/04/GHSA-mcgw-94j6-6g4q/GHSA-mcgw-94j6-6g4q.json index e092a096038..5849b30ca30 100644 --- a/advisories/unreviewed/2024/04/GHSA-mcgw-94j6-6g4q/GHSA-mcgw-94j6-6g4q.json +++ b/advisories/unreviewed/2024/04/GHSA-mcgw-94j6-6g4q/GHSA-mcgw-94j6-6g4q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-pf5m-h35j-7c4j/GHSA-pf5m-h35j-7c4j.json b/advisories/unreviewed/2024/04/GHSA-pf5m-h35j-7c4j/GHSA-pf5m-h35j-7c4j.json index 371c9a8e4b3..a88730304f2 100644 --- a/advisories/unreviewed/2024/04/GHSA-pf5m-h35j-7c4j/GHSA-pf5m-h35j-7c4j.json +++ b/advisories/unreviewed/2024/04/GHSA-pf5m-h35j-7c4j/GHSA-pf5m-h35j-7c4j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-qgf9-6cxx-q2qv/GHSA-qgf9-6cxx-q2qv.json b/advisories/unreviewed/2024/04/GHSA-qgf9-6cxx-q2qv/GHSA-qgf9-6cxx-q2qv.json index 50f1d89cea8..df8de843e9a 100644 --- a/advisories/unreviewed/2024/04/GHSA-qgf9-6cxx-q2qv/GHSA-qgf9-6cxx-q2qv.json +++ b/advisories/unreviewed/2024/04/GHSA-qgf9-6cxx-q2qv/GHSA-qgf9-6cxx-q2qv.json @@ -7,12 +7,8 @@ "CVE-2024-29375" ], "details": "CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to the Project Description, Identifiers, Custom Triangle Name (inside Input Triangles) and Yield Curve Name parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qhq3-q3p4-4fxm/GHSA-qhq3-q3p4-4fxm.json b/advisories/unreviewed/2024/04/GHSA-qhq3-q3p4-4fxm/GHSA-qhq3-q3p4-4fxm.json index 9e351f68300..c9e0b8ad309 100644 --- a/advisories/unreviewed/2024/04/GHSA-qhq3-q3p4-4fxm/GHSA-qhq3-q3p4-4fxm.json +++ b/advisories/unreviewed/2024/04/GHSA-qhq3-q3p4-4fxm/GHSA-qhq3-q3p4-4fxm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-r596-ggc2-8m6g/GHSA-r596-ggc2-8m6g.json b/advisories/unreviewed/2024/04/GHSA-r596-ggc2-8m6g/GHSA-r596-ggc2-8m6g.json index e792ba3ba06..01da806f5e7 100644 --- a/advisories/unreviewed/2024/04/GHSA-r596-ggc2-8m6g/GHSA-r596-ggc2-8m6g.json +++ b/advisories/unreviewed/2024/04/GHSA-r596-ggc2-8m6g/GHSA-r596-ggc2-8m6g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-v45f-j4h4-qjp6/GHSA-v45f-j4h4-qjp6.json b/advisories/unreviewed/2024/04/GHSA-v45f-j4h4-qjp6/GHSA-v45f-j4h4-qjp6.json index 18b056a6424..a8c38e82d74 100644 --- a/advisories/unreviewed/2024/04/GHSA-v45f-j4h4-qjp6/GHSA-v45f-j4h4-qjp6.json +++ b/advisories/unreviewed/2024/04/GHSA-v45f-j4h4-qjp6/GHSA-v45f-j4h4-qjp6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-vhhh-r6h5-2r9f/GHSA-vhhh-r6h5-2r9f.json b/advisories/unreviewed/2024/04/GHSA-vhhh-r6h5-2r9f/GHSA-vhhh-r6h5-2r9f.json index 3a017321f85..ced276b2219 100644 --- a/advisories/unreviewed/2024/04/GHSA-vhhh-r6h5-2r9f/GHSA-vhhh-r6h5-2r9f.json +++ b/advisories/unreviewed/2024/04/GHSA-vhhh-r6h5-2r9f/GHSA-vhhh-r6h5-2r9f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-w322-w9fv-rx3m/GHSA-w322-w9fv-rx3m.json b/advisories/unreviewed/2024/04/GHSA-w322-w9fv-rx3m/GHSA-w322-w9fv-rx3m.json index 8ddb5a4858e..51ac94a0b1b 100644 --- a/advisories/unreviewed/2024/04/GHSA-w322-w9fv-rx3m/GHSA-w322-w9fv-rx3m.json +++ b/advisories/unreviewed/2024/04/GHSA-w322-w9fv-rx3m/GHSA-w322-w9fv-rx3m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-w68v-jm79-7cvv/GHSA-w68v-jm79-7cvv.json b/advisories/unreviewed/2024/04/GHSA-w68v-jm79-7cvv/GHSA-w68v-jm79-7cvv.json index 206c9f8b39c..a1e09b54084 100644 --- a/advisories/unreviewed/2024/04/GHSA-w68v-jm79-7cvv/GHSA-w68v-jm79-7cvv.json +++ b/advisories/unreviewed/2024/04/GHSA-w68v-jm79-7cvv/GHSA-w68v-jm79-7cvv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-w7r3-xv3m-6g2f/GHSA-w7r3-xv3m-6g2f.json b/advisories/unreviewed/2024/04/GHSA-w7r3-xv3m-6g2f/GHSA-w7r3-xv3m-6g2f.json index 1dde4ec9859..d9723db56ee 100644 --- a/advisories/unreviewed/2024/04/GHSA-w7r3-xv3m-6g2f/GHSA-w7r3-xv3m-6g2f.json +++ b/advisories/unreviewed/2024/04/GHSA-w7r3-xv3m-6g2f/GHSA-w7r3-xv3m-6g2f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-wm99-2g28-jp5m/GHSA-wm99-2g28-jp5m.json b/advisories/unreviewed/2024/04/GHSA-wm99-2g28-jp5m/GHSA-wm99-2g28-jp5m.json index 5884aaddb4a..873a3061b3e 100644 --- a/advisories/unreviewed/2024/04/GHSA-wm99-2g28-jp5m/GHSA-wm99-2g28-jp5m.json +++ b/advisories/unreviewed/2024/04/GHSA-wm99-2g28-jp5m/GHSA-wm99-2g28-jp5m.json @@ -7,12 +7,8 @@ "CVE-2024-26798" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbcon: always restore the old font data in fbcon_do_set_font()\n\nCommit a5a923038d70 (fbdev: fbcon: Properly revert changes when\nvc_resize() failed) started restoring old font data upon failure (of\nvc_resize()). But it performs so only for user fonts. It means that the\n\"system\"/internal fonts are not restored at all. So in result, the very\nfirst call to fbcon_do_set_font() performs no restore at all upon\nfailing vc_resize().\n\nThis can be reproduced by Syzkaller to crash the system on the next\ninvocation of font_get(). It's rather hard to hit the allocation failure\nin vc_resize() on the first font_set(), but not impossible. Esp. if\nfault injection is used to aid the execution/failure. It was\ndemonstrated by Sirius:\n BUG: unable to handle page fault for address: fffffffffffffff8\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD cb7b067 P4D cb7b067 PUD cb7d067 PMD 0\n Oops: 0000 [#1] PREEMPT SMP KASAN\n CPU: 1 PID: 8007 Comm: poc Not tainted 6.7.0-g9d1694dc91ce #20\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n RIP: 0010:fbcon_get_font+0x229/0x800 drivers/video/fbdev/core/fbcon.c:2286\n Call Trace:\n \n con_font_get drivers/tty/vt/vt.c:4558 [inline]\n con_font_op+0x1fc/0xf20 drivers/tty/vt/vt.c:4673\n vt_k_ioctl drivers/tty/vt/vt_ioctl.c:474 [inline]\n vt_ioctl+0x632/0x2ec0 drivers/tty/vt/vt_ioctl.c:752\n tty_ioctl+0x6f8/0x1570 drivers/tty/tty_io.c:2803\n vfs_ioctl fs/ioctl.c:51 [inline]\n ...\n\nSo restore the font data in any case, not only for user fonts. Note the\nlater 'if' is now protected by 'old_userfont' and not 'old_data' as the\nlatter is always set now. (And it is supposed to be non-NULL. Otherwise\nwe would see the bug above again.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-x4pp-356g-v2qr/GHSA-x4pp-356g-v2qr.json b/advisories/unreviewed/2024/04/GHSA-x4pp-356g-v2qr/GHSA-x4pp-356g-v2qr.json index 9b5cde45131..4d766b0355f 100644 --- a/advisories/unreviewed/2024/04/GHSA-x4pp-356g-v2qr/GHSA-x4pp-356g-v2qr.json +++ b/advisories/unreviewed/2024/04/GHSA-x4pp-356g-v2qr/GHSA-x4pp-356g-v2qr.json @@ -7,12 +7,8 @@ "CVE-2024-26796" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers: perf: ctr_get_width function for legacy is not defined\n\nWith parameters CONFIG_RISCV_PMU_LEGACY=y and CONFIG_RISCV_PMU_SBI=n\nlinux kernel crashes when you try perf record:\n\n$ perf record ls\n[ 46.749286] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n[ 46.750199] Oops [#1]\n[ 46.750342] Modules linked in:\n[ 46.750608] CPU: 0 PID: 107 Comm: perf-exec Not tainted 6.6.0 #2\n[ 46.750906] Hardware name: riscv-virtio,qemu (DT)\n[ 46.751184] epc : 0x0\n[ 46.751430] ra : arch_perf_update_userpage+0x54/0x13e\n[ 46.751680] epc : 0000000000000000 ra : ffffffff8072ee52 sp : ff2000000022b8f0\n[ 46.751958] gp : ffffffff81505988 tp : ff6000000290d400 t0 : ff2000000022b9c0\n[ 46.752229] t1 : 0000000000000001 t2 : 0000000000000003 s0 : ff2000000022b930\n[ 46.752451] s1 : ff600000028fb000 a0 : 0000000000000000 a1 : ff600000028fb000\n[ 46.752673] a2 : 0000000ae2751268 a3 : 00000000004fb708 a4 : 0000000000000004\n[ 46.752895] a5 : 0000000000000000 a6 : 000000000017ffe3 a7 : 00000000000000d2\n[ 46.753117] s2 : ff600000028fb000 s3 : 0000000ae2751268 s4 : 0000000000000000\n[ 46.753338] s5 : ffffffff8153e290 s6 : ff600000863b9000 s7 : ff60000002961078\n[ 46.753562] s8 : ff60000002961048 s9 : ff60000002961058 s10: 0000000000000001\n[ 46.753783] s11: 0000000000000018 t3 : ffffffffffffffff t4 : ffffffffffffffff\n[ 46.754005] t5 : ff6000000292270c t6 : ff2000000022bb30\n[ 46.754179] status: 0000000200000100 badaddr: 0000000000000000 cause: 000000000000000c\n[ 46.754653] Code: Unable to access instruction at 0xffffffffffffffec.\n[ 46.754939] ---[ end trace 0000000000000000 ]---\n[ 46.755131] note: perf-exec[107] exited with irqs disabled\n[ 46.755546] note: perf-exec[107] exited with preempt_count 4\n\nThis happens because in the legacy case the ctr_get_width function was not\ndefined, but it is used in arch_perf_update_userpage.\n\nAlso remove extra check in riscv_pmu_ctr_get_width_mask", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-x8rm-m93r-jqp2/GHSA-x8rm-m93r-jqp2.json b/advisories/unreviewed/2024/04/GHSA-x8rm-m93r-jqp2/GHSA-x8rm-m93r-jqp2.json index 42ccf0d63b5..a962cbcf71b 100644 --- a/advisories/unreviewed/2024/04/GHSA-x8rm-m93r-jqp2/GHSA-x8rm-m93r-jqp2.json +++ b/advisories/unreviewed/2024/04/GHSA-x8rm-m93r-jqp2/GHSA-x8rm-m93r-jqp2.json @@ -7,12 +7,8 @@ "CVE-2024-27232" ], "details": "In asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-xwrr-gvqm-j58v/GHSA-xwrr-gvqm-j58v.json b/advisories/unreviewed/2024/04/GHSA-xwrr-gvqm-j58v/GHSA-xwrr-gvqm-j58v.json index 0dca4407ec6..1dd650d2d0f 100644 --- a/advisories/unreviewed/2024/04/GHSA-xwrr-gvqm-j58v/GHSA-xwrr-gvqm-j58v.json +++ b/advisories/unreviewed/2024/04/GHSA-xwrr-gvqm-j58v/GHSA-xwrr-gvqm-j58v.json @@ -7,12 +7,8 @@ "CVE-2024-29741" ], "details": "In pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-23r3-wg3q-c3xm/GHSA-23r3-wg3q-c3xm.json b/advisories/unreviewed/2024/05/GHSA-23r3-wg3q-c3xm/GHSA-23r3-wg3q-c3xm.json index fa9ea372af9..ed8dbcf9c51 100644 --- a/advisories/unreviewed/2024/05/GHSA-23r3-wg3q-c3xm/GHSA-23r3-wg3q-c3xm.json +++ b/advisories/unreviewed/2024/05/GHSA-23r3-wg3q-c3xm/GHSA-23r3-wg3q-c3xm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-2j2w-gm6q-cv65/GHSA-2j2w-gm6q-cv65.json b/advisories/unreviewed/2024/05/GHSA-2j2w-gm6q-cv65/GHSA-2j2w-gm6q-cv65.json index f25c73d0a91..8b80aef03cd 100644 --- a/advisories/unreviewed/2024/05/GHSA-2j2w-gm6q-cv65/GHSA-2j2w-gm6q-cv65.json +++ b/advisories/unreviewed/2024/05/GHSA-2j2w-gm6q-cv65/GHSA-2j2w-gm6q-cv65.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-2p92-vrh7-9m5h/GHSA-2p92-vrh7-9m5h.json b/advisories/unreviewed/2024/05/GHSA-2p92-vrh7-9m5h/GHSA-2p92-vrh7-9m5h.json index 4ca233488c3..b63b50ff454 100644 --- a/advisories/unreviewed/2024/05/GHSA-2p92-vrh7-9m5h/GHSA-2p92-vrh7-9m5h.json +++ b/advisories/unreviewed/2024/05/GHSA-2p92-vrh7-9m5h/GHSA-2p92-vrh7-9m5h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-2prv-mjpr-4qpj/GHSA-2prv-mjpr-4qpj.json b/advisories/unreviewed/2024/05/GHSA-2prv-mjpr-4qpj/GHSA-2prv-mjpr-4qpj.json index 2233b6e378a..9cd2793f3a6 100644 --- a/advisories/unreviewed/2024/05/GHSA-2prv-mjpr-4qpj/GHSA-2prv-mjpr-4qpj.json +++ b/advisories/unreviewed/2024/05/GHSA-2prv-mjpr-4qpj/GHSA-2prv-mjpr-4qpj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-2x67-wqw2-r8c8/GHSA-2x67-wqw2-r8c8.json b/advisories/unreviewed/2024/05/GHSA-2x67-wqw2-r8c8/GHSA-2x67-wqw2-r8c8.json index 4f721259015..838559ca70b 100644 --- a/advisories/unreviewed/2024/05/GHSA-2x67-wqw2-r8c8/GHSA-2x67-wqw2-r8c8.json +++ b/advisories/unreviewed/2024/05/GHSA-2x67-wqw2-r8c8/GHSA-2x67-wqw2-r8c8.json @@ -7,12 +7,8 @@ "CVE-2024-27404" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix data races on remote_id\n\nSimilar to the previous patch, address the data race on\nremote_id, adding the suitable ONCE annotations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-36gm-66fp-prv4/GHSA-36gm-66fp-prv4.json b/advisories/unreviewed/2024/05/GHSA-36gm-66fp-prv4/GHSA-36gm-66fp-prv4.json index 766be662aa8..645c2735277 100644 --- a/advisories/unreviewed/2024/05/GHSA-36gm-66fp-prv4/GHSA-36gm-66fp-prv4.json +++ b/advisories/unreviewed/2024/05/GHSA-36gm-66fp-prv4/GHSA-36gm-66fp-prv4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-3ch4-xrp6-59fq/GHSA-3ch4-xrp6-59fq.json b/advisories/unreviewed/2024/05/GHSA-3ch4-xrp6-59fq/GHSA-3ch4-xrp6-59fq.json index f3825c67135..87debc1fab2 100644 --- a/advisories/unreviewed/2024/05/GHSA-3ch4-xrp6-59fq/GHSA-3ch4-xrp6-59fq.json +++ b/advisories/unreviewed/2024/05/GHSA-3ch4-xrp6-59fq/GHSA-3ch4-xrp6-59fq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-3r27-2vg8-fjmx/GHSA-3r27-2vg8-fjmx.json b/advisories/unreviewed/2024/05/GHSA-3r27-2vg8-fjmx/GHSA-3r27-2vg8-fjmx.json index 7dcb6f32c42..a0b6743c416 100644 --- a/advisories/unreviewed/2024/05/GHSA-3r27-2vg8-fjmx/GHSA-3r27-2vg8-fjmx.json +++ b/advisories/unreviewed/2024/05/GHSA-3r27-2vg8-fjmx/GHSA-3r27-2vg8-fjmx.json @@ -7,12 +7,8 @@ "CVE-2024-35826" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: Fix page refcounts for unaligned buffers in __bio_release_pages()\n\nFix an incorrect number of pages being released for buffers that do not\nstart at the beginning of a page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3v8c-qpgc-x2p9/GHSA-3v8c-qpgc-x2p9.json b/advisories/unreviewed/2024/05/GHSA-3v8c-qpgc-x2p9/GHSA-3v8c-qpgc-x2p9.json index 7c55635fb9b..827fcacd00e 100644 --- a/advisories/unreviewed/2024/05/GHSA-3v8c-qpgc-x2p9/GHSA-3v8c-qpgc-x2p9.json +++ b/advisories/unreviewed/2024/05/GHSA-3v8c-qpgc-x2p9/GHSA-3v8c-qpgc-x2p9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-46pr-93vx-57gx/GHSA-46pr-93vx-57gx.json b/advisories/unreviewed/2024/05/GHSA-46pr-93vx-57gx/GHSA-46pr-93vx-57gx.json index 2a5aa27a028..a34bcaabd9d 100644 --- a/advisories/unreviewed/2024/05/GHSA-46pr-93vx-57gx/GHSA-46pr-93vx-57gx.json +++ b/advisories/unreviewed/2024/05/GHSA-46pr-93vx-57gx/GHSA-46pr-93vx-57gx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-46x4-m2v6-xg6w/GHSA-46x4-m2v6-xg6w.json b/advisories/unreviewed/2024/05/GHSA-46x4-m2v6-xg6w/GHSA-46x4-m2v6-xg6w.json index 8e73ab9a59c..213e1ec6073 100644 --- a/advisories/unreviewed/2024/05/GHSA-46x4-m2v6-xg6w/GHSA-46x4-m2v6-xg6w.json +++ b/advisories/unreviewed/2024/05/GHSA-46x4-m2v6-xg6w/GHSA-46x4-m2v6-xg6w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-48x6-4hw3-jv54/GHSA-48x6-4hw3-jv54.json b/advisories/unreviewed/2024/05/GHSA-48x6-4hw3-jv54/GHSA-48x6-4hw3-jv54.json index e75653dbb82..b58d4e362ff 100644 --- a/advisories/unreviewed/2024/05/GHSA-48x6-4hw3-jv54/GHSA-48x6-4hw3-jv54.json +++ b/advisories/unreviewed/2024/05/GHSA-48x6-4hw3-jv54/GHSA-48x6-4hw3-jv54.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-4ghh-5wcp-69w2/GHSA-4ghh-5wcp-69w2.json b/advisories/unreviewed/2024/05/GHSA-4ghh-5wcp-69w2/GHSA-4ghh-5wcp-69w2.json index 2e9346033c6..d74c60d7d57 100644 --- a/advisories/unreviewed/2024/05/GHSA-4ghh-5wcp-69w2/GHSA-4ghh-5wcp-69w2.json +++ b/advisories/unreviewed/2024/05/GHSA-4ghh-5wcp-69w2/GHSA-4ghh-5wcp-69w2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-4rx2-3f77-xv9x/GHSA-4rx2-3f77-xv9x.json b/advisories/unreviewed/2024/05/GHSA-4rx2-3f77-xv9x/GHSA-4rx2-3f77-xv9x.json index fe04d42fb29..44d74fc94f6 100644 --- a/advisories/unreviewed/2024/05/GHSA-4rx2-3f77-xv9x/GHSA-4rx2-3f77-xv9x.json +++ b/advisories/unreviewed/2024/05/GHSA-4rx2-3f77-xv9x/GHSA-4rx2-3f77-xv9x.json @@ -7,12 +7,8 @@ "CVE-2023-52697" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: sof_sdw_rt_sdca_jack_common: ctx->headset_codec_dev = NULL\n\nsof_sdw_rt_sdca_jack_exit() are used by different codecs, and some of\nthem use the same dai name.\nFor example, rt712 and rt713 both use \"rt712-sdca-aif1\" and\nsof_sdw_rt_sdca_jack_exit().\nAs a result, sof_sdw_rt_sdca_jack_exit() will be called twice by\nmc_dailink_exit_loop(). Set ctx->headset_codec_dev = NULL; after\nput_device(ctx->headset_codec_dev); to avoid ctx->headset_codec_dev\nbeing put twice.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-4v3r-334q-j7qc/GHSA-4v3r-334q-j7qc.json b/advisories/unreviewed/2024/05/GHSA-4v3r-334q-j7qc/GHSA-4v3r-334q-j7qc.json index 51439d03c01..e80c5824c5f 100644 --- a/advisories/unreviewed/2024/05/GHSA-4v3r-334q-j7qc/GHSA-4v3r-334q-j7qc.json +++ b/advisories/unreviewed/2024/05/GHSA-4v3r-334q-j7qc/GHSA-4v3r-334q-j7qc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-4x6w-78cr-j4xh/GHSA-4x6w-78cr-j4xh.json b/advisories/unreviewed/2024/05/GHSA-4x6w-78cr-j4xh/GHSA-4x6w-78cr-j4xh.json index 5dce4121241..8bed19e2a12 100644 --- a/advisories/unreviewed/2024/05/GHSA-4x6w-78cr-j4xh/GHSA-4x6w-78cr-j4xh.json +++ b/advisories/unreviewed/2024/05/GHSA-4x6w-78cr-j4xh/GHSA-4x6w-78cr-j4xh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-536g-7m64-v9jp/GHSA-536g-7m64-v9jp.json b/advisories/unreviewed/2024/05/GHSA-536g-7m64-v9jp/GHSA-536g-7m64-v9jp.json index c40a7e6604f..1411910ab80 100644 --- a/advisories/unreviewed/2024/05/GHSA-536g-7m64-v9jp/GHSA-536g-7m64-v9jp.json +++ b/advisories/unreviewed/2024/05/GHSA-536g-7m64-v9jp/GHSA-536g-7m64-v9jp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-55ff-crw4-233h/GHSA-55ff-crw4-233h.json b/advisories/unreviewed/2024/05/GHSA-55ff-crw4-233h/GHSA-55ff-crw4-233h.json index 5065c2e079e..0ce899aa919 100644 --- a/advisories/unreviewed/2024/05/GHSA-55ff-crw4-233h/GHSA-55ff-crw4-233h.json +++ b/advisories/unreviewed/2024/05/GHSA-55ff-crw4-233h/GHSA-55ff-crw4-233h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-56vf-fgp4-xjqj/GHSA-56vf-fgp4-xjqj.json b/advisories/unreviewed/2024/05/GHSA-56vf-fgp4-xjqj/GHSA-56vf-fgp4-xjqj.json index c722ed52405..092495df68a 100644 --- a/advisories/unreviewed/2024/05/GHSA-56vf-fgp4-xjqj/GHSA-56vf-fgp4-xjqj.json +++ b/advisories/unreviewed/2024/05/GHSA-56vf-fgp4-xjqj/GHSA-56vf-fgp4-xjqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-57gg-77r2-5v5h/GHSA-57gg-77r2-5v5h.json b/advisories/unreviewed/2024/05/GHSA-57gg-77r2-5v5h/GHSA-57gg-77r2-5v5h.json index d2b30733d05..4ff0e680583 100644 --- a/advisories/unreviewed/2024/05/GHSA-57gg-77r2-5v5h/GHSA-57gg-77r2-5v5h.json +++ b/advisories/unreviewed/2024/05/GHSA-57gg-77r2-5v5h/GHSA-57gg-77r2-5v5h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-5c5w-jm9h-wvq9/GHSA-5c5w-jm9h-wvq9.json b/advisories/unreviewed/2024/05/GHSA-5c5w-jm9h-wvq9/GHSA-5c5w-jm9h-wvq9.json index 65db26ebcc1..90f7fb44f31 100644 --- a/advisories/unreviewed/2024/05/GHSA-5c5w-jm9h-wvq9/GHSA-5c5w-jm9h-wvq9.json +++ b/advisories/unreviewed/2024/05/GHSA-5c5w-jm9h-wvq9/GHSA-5c5w-jm9h-wvq9.json @@ -7,12 +7,8 @@ "CVE-2024-35841" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tls, fix WARNIING in __sk_msg_free\n\nA splice with MSG_SPLICE_PAGES will cause tls code to use the\ntls_sw_sendmsg_splice path in the TLS sendmsg code to move the user\nprovided pages from the msg into the msg_pl. This will loop over the\nmsg until msg_pl is full, checked by sk_msg_full(msg_pl). The user\ncan also set the MORE flag to hint stack to delay sending until receiving\nmore pages and ideally a full buffer.\n\nIf the user adds more pages to the msg than can fit in the msg_pl\nscatterlist (MAX_MSG_FRAGS) we should ignore the MORE flag and send\nthe buffer anyways.\n\nWhat actually happens though is we abort the msg to msg_pl scatterlist\nsetup and then because we forget to set 'full record' indicating we\ncan no longer consume data without a send we fallthrough to the 'continue'\npath which will check if msg_data_left(msg) has more bytes to send and\nthen attempts to fit them in the already full msg_pl. Then next\niteration of sender doing send will encounter a full msg_pl and throw\nthe warning in the syzbot report.\n\nTo fix simply check if we have a full_record in splice code path and\nif not send the msg regardless of MORE flag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-5p77-whcf-2g2h/GHSA-5p77-whcf-2g2h.json b/advisories/unreviewed/2024/05/GHSA-5p77-whcf-2g2h/GHSA-5p77-whcf-2g2h.json index bdf960f0ce0..ef01eb3db18 100644 --- a/advisories/unreviewed/2024/05/GHSA-5p77-whcf-2g2h/GHSA-5p77-whcf-2g2h.json +++ b/advisories/unreviewed/2024/05/GHSA-5p77-whcf-2g2h/GHSA-5p77-whcf-2g2h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-5q3f-cvfm-98xq/GHSA-5q3f-cvfm-98xq.json b/advisories/unreviewed/2024/05/GHSA-5q3f-cvfm-98xq/GHSA-5q3f-cvfm-98xq.json index 76c2e873a5d..84a5a24b9ba 100644 --- a/advisories/unreviewed/2024/05/GHSA-5q3f-cvfm-98xq/GHSA-5q3f-cvfm-98xq.json +++ b/advisories/unreviewed/2024/05/GHSA-5q3f-cvfm-98xq/GHSA-5q3f-cvfm-98xq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-5xh2-79x5-2x6c/GHSA-5xh2-79x5-2x6c.json b/advisories/unreviewed/2024/05/GHSA-5xh2-79x5-2x6c/GHSA-5xh2-79x5-2x6c.json index 5e617358797..8ef7e24e6ba 100644 --- a/advisories/unreviewed/2024/05/GHSA-5xh2-79x5-2x6c/GHSA-5xh2-79x5-2x6c.json +++ b/advisories/unreviewed/2024/05/GHSA-5xh2-79x5-2x6c/GHSA-5xh2-79x5-2x6c.json @@ -7,12 +7,8 @@ "CVE-2024-35787" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/md-bitmap: fix incorrect usage for sb_index\n\nCommit d7038f951828 (\"md-bitmap: don't use ->index for pages backing the\nbitmap file\") removed page->index from bitmap code, but left wrong code\nlogic for clustered-md. current code never set slot offset for cluster\nnodes, will sometimes cause crash in clustered env.\n\nCall trace (partly):\n md_bitmap_file_set_bit+0x110/0x1d8 [md_mod]\n md_bitmap_startwrite+0x13c/0x240 [md_mod]\n raid1_make_request+0x6b0/0x1c08 [raid1]\n md_handle_request+0x1dc/0x368 [md_mod]\n md_submit_bio+0x80/0xf8 [md_mod]\n __submit_bio+0x178/0x300\n submit_bio_noacct_nocheck+0x11c/0x338\n submit_bio_noacct+0x134/0x614\n submit_bio+0x28/0xdc\n submit_bh_wbc+0x130/0x1cc\n submit_bh+0x1c/0x28", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-625f-58w6-wj9f/GHSA-625f-58w6-wj9f.json b/advisories/unreviewed/2024/05/GHSA-625f-58w6-wj9f/GHSA-625f-58w6-wj9f.json index c4569baf6be..3d079278cc3 100644 --- a/advisories/unreviewed/2024/05/GHSA-625f-58w6-wj9f/GHSA-625f-58w6-wj9f.json +++ b/advisories/unreviewed/2024/05/GHSA-625f-58w6-wj9f/GHSA-625f-58w6-wj9f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-64cr-fv76-jh9m/GHSA-64cr-fv76-jh9m.json b/advisories/unreviewed/2024/05/GHSA-64cr-fv76-jh9m/GHSA-64cr-fv76-jh9m.json index 0052afc5970..40631a6084c 100644 --- a/advisories/unreviewed/2024/05/GHSA-64cr-fv76-jh9m/GHSA-64cr-fv76-jh9m.json +++ b/advisories/unreviewed/2024/05/GHSA-64cr-fv76-jh9m/GHSA-64cr-fv76-jh9m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-6589-39cq-p9hw/GHSA-6589-39cq-p9hw.json b/advisories/unreviewed/2024/05/GHSA-6589-39cq-p9hw/GHSA-6589-39cq-p9hw.json index 60abd6eefa7..5002414efce 100644 --- a/advisories/unreviewed/2024/05/GHSA-6589-39cq-p9hw/GHSA-6589-39cq-p9hw.json +++ b/advisories/unreviewed/2024/05/GHSA-6589-39cq-p9hw/GHSA-6589-39cq-p9hw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-65c7-6p4f-55jx/GHSA-65c7-6p4f-55jx.json b/advisories/unreviewed/2024/05/GHSA-65c7-6p4f-55jx/GHSA-65c7-6p4f-55jx.json index 5c49972d9bd..842844e894e 100644 --- a/advisories/unreviewed/2024/05/GHSA-65c7-6p4f-55jx/GHSA-65c7-6p4f-55jx.json +++ b/advisories/unreviewed/2024/05/GHSA-65c7-6p4f-55jx/GHSA-65c7-6p4f-55jx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-684g-9624-2cvp/GHSA-684g-9624-2cvp.json b/advisories/unreviewed/2024/05/GHSA-684g-9624-2cvp/GHSA-684g-9624-2cvp.json index dea0c9acc72..73ea8331f94 100644 --- a/advisories/unreviewed/2024/05/GHSA-684g-9624-2cvp/GHSA-684g-9624-2cvp.json +++ b/advisories/unreviewed/2024/05/GHSA-684g-9624-2cvp/GHSA-684g-9624-2cvp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-68x2-v9x5-vw53/GHSA-68x2-v9x5-vw53.json b/advisories/unreviewed/2024/05/GHSA-68x2-v9x5-vw53/GHSA-68x2-v9x5-vw53.json index 0522c60f1e0..582fad9b856 100644 --- a/advisories/unreviewed/2024/05/GHSA-68x2-v9x5-vw53/GHSA-68x2-v9x5-vw53.json +++ b/advisories/unreviewed/2024/05/GHSA-68x2-v9x5-vw53/GHSA-68x2-v9x5-vw53.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-6hx5-97h6-52x3/GHSA-6hx5-97h6-52x3.json b/advisories/unreviewed/2024/05/GHSA-6hx5-97h6-52x3/GHSA-6hx5-97h6-52x3.json index 3daca76440c..6100b5b705f 100644 --- a/advisories/unreviewed/2024/05/GHSA-6hx5-97h6-52x3/GHSA-6hx5-97h6-52x3.json +++ b/advisories/unreviewed/2024/05/GHSA-6hx5-97h6-52x3/GHSA-6hx5-97h6-52x3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-6mf2-2736-w39m/GHSA-6mf2-2736-w39m.json b/advisories/unreviewed/2024/05/GHSA-6mf2-2736-w39m/GHSA-6mf2-2736-w39m.json index 34096499a39..0363c4c6711 100644 --- a/advisories/unreviewed/2024/05/GHSA-6mf2-2736-w39m/GHSA-6mf2-2736-w39m.json +++ b/advisories/unreviewed/2024/05/GHSA-6mf2-2736-w39m/GHSA-6mf2-2736-w39m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-6mpf-666c-hqcg/GHSA-6mpf-666c-hqcg.json b/advisories/unreviewed/2024/05/GHSA-6mpf-666c-hqcg/GHSA-6mpf-666c-hqcg.json index 5dbcf0eb7a9..be0ecfcdf88 100644 --- a/advisories/unreviewed/2024/05/GHSA-6mpf-666c-hqcg/GHSA-6mpf-666c-hqcg.json +++ b/advisories/unreviewed/2024/05/GHSA-6mpf-666c-hqcg/GHSA-6mpf-666c-hqcg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-6r6g-263h-fpjq/GHSA-6r6g-263h-fpjq.json b/advisories/unreviewed/2024/05/GHSA-6r6g-263h-fpjq/GHSA-6r6g-263h-fpjq.json index 098d5e5fe72..1cbc37d9457 100644 --- a/advisories/unreviewed/2024/05/GHSA-6r6g-263h-fpjq/GHSA-6r6g-263h-fpjq.json +++ b/advisories/unreviewed/2024/05/GHSA-6r6g-263h-fpjq/GHSA-6r6g-263h-fpjq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-6rhx-7f5j-52mj/GHSA-6rhx-7f5j-52mj.json b/advisories/unreviewed/2024/05/GHSA-6rhx-7f5j-52mj/GHSA-6rhx-7f5j-52mj.json index cb0c23ed427..7c84b5c8a24 100644 --- a/advisories/unreviewed/2024/05/GHSA-6rhx-7f5j-52mj/GHSA-6rhx-7f5j-52mj.json +++ b/advisories/unreviewed/2024/05/GHSA-6rhx-7f5j-52mj/GHSA-6rhx-7f5j-52mj.json @@ -7,12 +7,8 @@ "CVE-2023-52688" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix the error handler of rfkill config\n\nWhen the core rfkill config throws error, it should free the\nallocated resources. Currently it is not freeing the core pdev\ncreate resources. Avoid this issue by calling the core pdev\ndestroy in the error handler of core rfkill config.\n\nFound this issue in the code review and it is compile tested only.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-6x8f-vpgx-h5h9/GHSA-6x8f-vpgx-h5h9.json b/advisories/unreviewed/2024/05/GHSA-6x8f-vpgx-h5h9/GHSA-6x8f-vpgx-h5h9.json index 685421e3196..14223cb24ef 100644 --- a/advisories/unreviewed/2024/05/GHSA-6x8f-vpgx-h5h9/GHSA-6x8f-vpgx-h5h9.json +++ b/advisories/unreviewed/2024/05/GHSA-6x8f-vpgx-h5h9/GHSA-6x8f-vpgx-h5h9.json @@ -7,12 +7,8 @@ "CVE-2024-35850" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: qca: fix NULL-deref on non-serdev setup\n\nQualcomm ROME controllers can be registered from the Bluetooth line\ndiscipline and in this case the HCI UART serdev pointer is NULL.\n\nAdd the missing sanity check to prevent a NULL-pointer dereference when\nsetup() is called for a non-serdev controller.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7257-q8p3-hc2f/GHSA-7257-q8p3-hc2f.json b/advisories/unreviewed/2024/05/GHSA-7257-q8p3-hc2f/GHSA-7257-q8p3-hc2f.json index 37eea39388d..015f6f01bff 100644 --- a/advisories/unreviewed/2024/05/GHSA-7257-q8p3-hc2f/GHSA-7257-q8p3-hc2f.json +++ b/advisories/unreviewed/2024/05/GHSA-7257-q8p3-hc2f/GHSA-7257-q8p3-hc2f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-7fv8-vr6g-q8qw/GHSA-7fv8-vr6g-q8qw.json b/advisories/unreviewed/2024/05/GHSA-7fv8-vr6g-q8qw/GHSA-7fv8-vr6g-q8qw.json index c59756d640b..74edeef80d4 100644 --- a/advisories/unreviewed/2024/05/GHSA-7fv8-vr6g-q8qw/GHSA-7fv8-vr6g-q8qw.json +++ b/advisories/unreviewed/2024/05/GHSA-7fv8-vr6g-q8qw/GHSA-7fv8-vr6g-q8qw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-7mh5-2fw8-7x58/GHSA-7mh5-2fw8-7x58.json b/advisories/unreviewed/2024/05/GHSA-7mh5-2fw8-7x58/GHSA-7mh5-2fw8-7x58.json index 4b7d5d680fc..ce7a397a736 100644 --- a/advisories/unreviewed/2024/05/GHSA-7mh5-2fw8-7x58/GHSA-7mh5-2fw8-7x58.json +++ b/advisories/unreviewed/2024/05/GHSA-7mh5-2fw8-7x58/GHSA-7mh5-2fw8-7x58.json @@ -7,12 +7,8 @@ "CVE-2024-27406" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nlib/Kconfig.debug: TEST_IOV_ITER depends on MMU\n\nTrying to run the iov_iter unit test on a nommu system such as the qemu\nkc705-nommu emulation results in a crash.\n\n KTAP version 1\n # Subtest: iov_iter\n # module: kunit_iov_iter\n 1..9\nBUG: failure at mm/nommu.c:318/vmap()!\nKernel panic - not syncing: BUG!\n\nThe test calls vmap() directly, but vmap() is not supported on nommu\nsystems, causing the crash. TEST_IOV_ITER therefore needs to depend on\nMMU.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7w4f-6jhh-cw34/GHSA-7w4f-6jhh-cw34.json b/advisories/unreviewed/2024/05/GHSA-7w4f-6jhh-cw34/GHSA-7w4f-6jhh-cw34.json index 861fcd610b1..ab8f5291d93 100644 --- a/advisories/unreviewed/2024/05/GHSA-7w4f-6jhh-cw34/GHSA-7w4f-6jhh-cw34.json +++ b/advisories/unreviewed/2024/05/GHSA-7w4f-6jhh-cw34/GHSA-7w4f-6jhh-cw34.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-7xf4-wr6x-3r95/GHSA-7xf4-wr6x-3r95.json b/advisories/unreviewed/2024/05/GHSA-7xf4-wr6x-3r95/GHSA-7xf4-wr6x-3r95.json index cc071897e57..b9598bf3770 100644 --- a/advisories/unreviewed/2024/05/GHSA-7xf4-wr6x-3r95/GHSA-7xf4-wr6x-3r95.json +++ b/advisories/unreviewed/2024/05/GHSA-7xf4-wr6x-3r95/GHSA-7xf4-wr6x-3r95.json @@ -7,12 +7,8 @@ "CVE-2024-27418" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mctp: take ownership of skb in mctp_local_output\n\nCurrently, mctp_local_output only takes ownership of skb on success, and\nwe may leak an skb if mctp_local_output fails in specific states; the\nskb ownership isn't transferred until the actual output routing occurs.\n\nInstead, make mctp_local_output free the skb on all error paths up to\nthe route action, so it always consumes the passed skb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-82rx-89fp-4w49/GHSA-82rx-89fp-4w49.json b/advisories/unreviewed/2024/05/GHSA-82rx-89fp-4w49/GHSA-82rx-89fp-4w49.json index 5b7ceb88d73..d4215c94d69 100644 --- a/advisories/unreviewed/2024/05/GHSA-82rx-89fp-4w49/GHSA-82rx-89fp-4w49.json +++ b/advisories/unreviewed/2024/05/GHSA-82rx-89fp-4w49/GHSA-82rx-89fp-4w49.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-852g-jv3v-hqv3/GHSA-852g-jv3v-hqv3.json b/advisories/unreviewed/2024/05/GHSA-852g-jv3v-hqv3/GHSA-852g-jv3v-hqv3.json index 8803a7d7c4d..6badf8d4332 100644 --- a/advisories/unreviewed/2024/05/GHSA-852g-jv3v-hqv3/GHSA-852g-jv3v-hqv3.json +++ b/advisories/unreviewed/2024/05/GHSA-852g-jv3v-hqv3/GHSA-852g-jv3v-hqv3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-8m7w-h5g5-j89j/GHSA-8m7w-h5g5-j89j.json b/advisories/unreviewed/2024/05/GHSA-8m7w-h5g5-j89j/GHSA-8m7w-h5g5-j89j.json index 458335082db..9d7ca64517e 100644 --- a/advisories/unreviewed/2024/05/GHSA-8m7w-h5g5-j89j/GHSA-8m7w-h5g5-j89j.json +++ b/advisories/unreviewed/2024/05/GHSA-8m7w-h5g5-j89j/GHSA-8m7w-h5g5-j89j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-8p46-c7vp-cvj5/GHSA-8p46-c7vp-cvj5.json b/advisories/unreviewed/2024/05/GHSA-8p46-c7vp-cvj5/GHSA-8p46-c7vp-cvj5.json index dce692db65a..217393c320d 100644 --- a/advisories/unreviewed/2024/05/GHSA-8p46-c7vp-cvj5/GHSA-8p46-c7vp-cvj5.json +++ b/advisories/unreviewed/2024/05/GHSA-8p46-c7vp-cvj5/GHSA-8p46-c7vp-cvj5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-8w8v-r4xj-j99j/GHSA-8w8v-r4xj-j99j.json b/advisories/unreviewed/2024/05/GHSA-8w8v-r4xj-j99j/GHSA-8w8v-r4xj-j99j.json index c2a33e620bb..5aef3a88bea 100644 --- a/advisories/unreviewed/2024/05/GHSA-8w8v-r4xj-j99j/GHSA-8w8v-r4xj-j99j.json +++ b/advisories/unreviewed/2024/05/GHSA-8w8v-r4xj-j99j/GHSA-8w8v-r4xj-j99j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-934r-h8mp-qw4r/GHSA-934r-h8mp-qw4r.json b/advisories/unreviewed/2024/05/GHSA-934r-h8mp-qw4r/GHSA-934r-h8mp-qw4r.json index 569cf1b250e..595c5bd28eb 100644 --- a/advisories/unreviewed/2024/05/GHSA-934r-h8mp-qw4r/GHSA-934r-h8mp-qw4r.json +++ b/advisories/unreviewed/2024/05/GHSA-934r-h8mp-qw4r/GHSA-934r-h8mp-qw4r.json @@ -7,12 +7,8 @@ "CVE-2024-27415" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: confirm multicast packets before passing them up the stack\n\nconntrack nf_confirm logic cannot handle cloned skbs referencing\nthe same nf_conn entry, which will happen for multicast (broadcast)\nframes on bridges.\n\n Example:\n macvlan0\n |\n br0\n / \\\n ethX ethY\n\n ethX (or Y) receives a L2 multicast or broadcast packet containing\n an IP packet, flow is not yet in conntrack table.\n\n 1. skb passes through bridge and fake-ip (br_netfilter)Prerouting.\n -> skb->_nfct now references a unconfirmed entry\n 2. skb is broad/mcast packet. bridge now passes clones out on each bridge\n interface.\n 3. skb gets passed up the stack.\n 4. In macvlan case, macvlan driver retains clone(s) of the mcast skb\n and schedules a work queue to send them out on the lower devices.\n\n The clone skb->_nfct is not a copy, it is the same entry as the\n original skb. The macvlan rx handler then returns RX_HANDLER_PASS.\n 5. Normal conntrack hooks (in NF_INET_LOCAL_IN) confirm the orig skb.\n\nThe Macvlan broadcast worker and normal confirm path will race.\n\nThis race will not happen if step 2 already confirmed a clone. In that\ncase later steps perform skb_clone() with skb->_nfct already confirmed (in\nhash table). This works fine.\n\nBut such confirmation won't happen when eb/ip/nftables rules dropped the\npackets before they reached the nf_confirm step in postrouting.\n\nPablo points out that nf_conntrack_bridge doesn't allow use of stateful\nnat, so we can safely discard the nf_conn entry and let inet call\nconntrack again.\n\nThis doesn't work for bridge netfilter: skb could have a nat\ntransformation. Also bridge nf prevents re-invocation of inet prerouting\nvia 'sabotage_in' hook.\n\nWork around this problem by explicit confirmation of the entry at LOCAL_IN\ntime, before upper layer has a chance to clone the unconfirmed entry.\n\nThe downside is that this disables NAT and conntrack helpers.\n\nAlternative fix would be to add locking to all code parts that deal with\nunconfirmed packets, but even if that could be done in a sane way this\nopens up other problems, for example:\n\n-m physdev --physdev-out eth0 -j SNAT --snat-to 1.2.3.4\n-m physdev --physdev-out eth1 -j SNAT --snat-to 1.2.3.5\n\nFor multicast case, only one of such conflicting mappings will be\ncreated, conntrack only handles 1:1 NAT mappings.\n\nUsers should set create a setup that explicitly marks such traffic\nNOTRACK (conntrack bypass) to avoid this, but we cannot auto-bypass\nthem, ruleset might have accept rules for untracked traffic already,\nso user-visible behaviour would change.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-93fh-97qr-4f47/GHSA-93fh-97qr-4f47.json b/advisories/unreviewed/2024/05/GHSA-93fh-97qr-4f47/GHSA-93fh-97qr-4f47.json index efdeb8a1b1b..e2a7b20b55f 100644 --- a/advisories/unreviewed/2024/05/GHSA-93fh-97qr-4f47/GHSA-93fh-97qr-4f47.json +++ b/advisories/unreviewed/2024/05/GHSA-93fh-97qr-4f47/GHSA-93fh-97qr-4f47.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-99mj-3x29-5mm3/GHSA-99mj-3x29-5mm3.json b/advisories/unreviewed/2024/05/GHSA-99mj-3x29-5mm3/GHSA-99mj-3x29-5mm3.json index 0e90a02d732..91c109282e7 100644 --- a/advisories/unreviewed/2024/05/GHSA-99mj-3x29-5mm3/GHSA-99mj-3x29-5mm3.json +++ b/advisories/unreviewed/2024/05/GHSA-99mj-3x29-5mm3/GHSA-99mj-3x29-5mm3.json @@ -7,12 +7,8 @@ "CVE-2024-35795" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix deadlock while reading mqd from debugfs\n\nAn errant disk backup on my desktop got into debugfs and triggered the\nfollowing deadlock scenario in the amdgpu debugfs files. The machine\nalso hard-resets immediately after those lines are printed (although I\nwasn't able to reproduce that part when reading by hand):\n\n[ 1318.016074][ T1082] ======================================================\n[ 1318.016607][ T1082] WARNING: possible circular locking dependency detected\n[ 1318.017107][ T1082] 6.8.0-rc7-00015-ge0c8221b72c0 #17 Not tainted\n[ 1318.017598][ T1082] ------------------------------------------------------\n[ 1318.018096][ T1082] tar/1082 is trying to acquire lock:\n[ 1318.018585][ T1082] ffff98c44175d6a0 (&mm->mmap_lock){++++}-{3:3}, at: __might_fault+0x40/0x80\n[ 1318.019084][ T1082]\n[ 1318.019084][ T1082] but task is already holding lock:\n[ 1318.020052][ T1082] ffff98c4c13f55f8 (reservation_ww_class_mutex){+.+.}-{3:3}, at: amdgpu_debugfs_mqd_read+0x6a/0x250 [amdgpu]\n[ 1318.020607][ T1082]\n[ 1318.020607][ T1082] which lock already depends on the new lock.\n[ 1318.020607][ T1082]\n[ 1318.022081][ T1082]\n[ 1318.022081][ T1082] the existing dependency chain (in reverse order) is:\n[ 1318.023083][ T1082]\n[ 1318.023083][ T1082] -> #2 (reservation_ww_class_mutex){+.+.}-{3:3}:\n[ 1318.024114][ T1082] __ww_mutex_lock.constprop.0+0xe0/0x12f0\n[ 1318.024639][ T1082] ww_mutex_lock+0x32/0x90\n[ 1318.025161][ T1082] dma_resv_lockdep+0x18a/0x330\n[ 1318.025683][ T1082] do_one_initcall+0x6a/0x350\n[ 1318.026210][ T1082] kernel_init_freeable+0x1a3/0x310\n[ 1318.026728][ T1082] kernel_init+0x15/0x1a0\n[ 1318.027242][ T1082] ret_from_fork+0x2c/0x40\n[ 1318.027759][ T1082] ret_from_fork_asm+0x11/0x20\n[ 1318.028281][ T1082]\n[ 1318.028281][ T1082] -> #1 (reservation_ww_class_acquire){+.+.}-{0:0}:\n[ 1318.029297][ T1082] dma_resv_lockdep+0x16c/0x330\n[ 1318.029790][ T1082] do_one_initcall+0x6a/0x350\n[ 1318.030263][ T1082] kernel_init_freeable+0x1a3/0x310\n[ 1318.030722][ T1082] kernel_init+0x15/0x1a0\n[ 1318.031168][ T1082] ret_from_fork+0x2c/0x40\n[ 1318.031598][ T1082] ret_from_fork_asm+0x11/0x20\n[ 1318.032011][ T1082]\n[ 1318.032011][ T1082] -> #0 (&mm->mmap_lock){++++}-{3:3}:\n[ 1318.032778][ T1082] __lock_acquire+0x14bf/0x2680\n[ 1318.033141][ T1082] lock_acquire+0xcd/0x2c0\n[ 1318.033487][ T1082] __might_fault+0x58/0x80\n[ 1318.033814][ T1082] amdgpu_debugfs_mqd_read+0x103/0x250 [amdgpu]\n[ 1318.034181][ T1082] full_proxy_read+0x55/0x80\n[ 1318.034487][ T1082] vfs_read+0xa7/0x360\n[ 1318.034788][ T1082] ksys_read+0x70/0xf0\n[ 1318.035085][ T1082] do_syscall_64+0x94/0x180\n[ 1318.035375][ T1082] entry_SYSCALL_64_after_hwframe+0x46/0x4e\n[ 1318.035664][ T1082]\n[ 1318.035664][ T1082] other info that might help us debug this:\n[ 1318.035664][ T1082]\n[ 1318.036487][ T1082] Chain exists of:\n[ 1318.036487][ T1082] &mm->mmap_lock --> reservation_ww_class_acquire --> reservation_ww_class_mutex\n[ 1318.036487][ T1082]\n[ 1318.037310][ T1082] Possible unsafe locking scenario:\n[ 1318.037310][ T1082]\n[ 1318.037838][ T1082] CPU0 CPU1\n[ 1318.038101][ T1082] ---- ----\n[ 1318.038350][ T1082] lock(reservation_ww_class_mutex);\n[ 1318.038590][ T1082] lock(reservation_ww_class_acquire);\n[ 1318.038839][ T1082] lock(reservation_ww_class_mutex);\n[ 1318.039083][ T1082] rlock(&mm->mmap_lock);\n[ 1318.039328][ T1082]\n[ 1318.039328][ T1082] *** DEADLOCK ***\n[ 1318.039328][ T1082]\n[ 1318.040029][ T1082] 1 lock held by tar/1082:\n[ 1318.040259][ T1082] #0: ffff98c4c13f55f8 (reservation_ww_class_mutex){+.+.}-{3:3}, at: amdgpu_debugfs_mqd_read+0x6a/0x250 [amdgpu]\n[ 1318.040560][ T1082]\n[ 1318.040560][ T1082] stack backtrace:\n[\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-9cgq-rxjf-33c6/GHSA-9cgq-rxjf-33c6.json b/advisories/unreviewed/2024/05/GHSA-9cgq-rxjf-33c6/GHSA-9cgq-rxjf-33c6.json index 8d47064d606..97893da463a 100644 --- a/advisories/unreviewed/2024/05/GHSA-9cgq-rxjf-33c6/GHSA-9cgq-rxjf-33c6.json +++ b/advisories/unreviewed/2024/05/GHSA-9cgq-rxjf-33c6/GHSA-9cgq-rxjf-33c6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-9f74-xw28-qc4r/GHSA-9f74-xw28-qc4r.json b/advisories/unreviewed/2024/05/GHSA-9f74-xw28-qc4r/GHSA-9f74-xw28-qc4r.json index 65734de7854..cf1029745cb 100644 --- a/advisories/unreviewed/2024/05/GHSA-9f74-xw28-qc4r/GHSA-9f74-xw28-qc4r.json +++ b/advisories/unreviewed/2024/05/GHSA-9f74-xw28-qc4r/GHSA-9f74-xw28-qc4r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-9gr6-mqx6-vvv6/GHSA-9gr6-mqx6-vvv6.json b/advisories/unreviewed/2024/05/GHSA-9gr6-mqx6-vvv6/GHSA-9gr6-mqx6-vvv6.json index c4563176dce..5da5567f23f 100644 --- a/advisories/unreviewed/2024/05/GHSA-9gr6-mqx6-vvv6/GHSA-9gr6-mqx6-vvv6.json +++ b/advisories/unreviewed/2024/05/GHSA-9gr6-mqx6-vvv6/GHSA-9gr6-mqx6-vvv6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-9p3p-4642-mmp8/GHSA-9p3p-4642-mmp8.json b/advisories/unreviewed/2024/05/GHSA-9p3p-4642-mmp8/GHSA-9p3p-4642-mmp8.json index 077e719e58e..b5716b6001c 100644 --- a/advisories/unreviewed/2024/05/GHSA-9p3p-4642-mmp8/GHSA-9p3p-4642-mmp8.json +++ b/advisories/unreviewed/2024/05/GHSA-9p3p-4642-mmp8/GHSA-9p3p-4642-mmp8.json @@ -7,12 +7,8 @@ "CVE-2024-27411" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau: keep DMA buffers required for suspend/resume\n\nNouveau deallocates a few buffers post GPU init which are required for GPU suspend/resume to function correctly.\nThis is likely not as big an issue on systems where the NVGPU is the only GPU, but on multi-GPU set ups it leads to a regression where the kernel module errors and results in a system-wide rendering freeze.\n\nThis commit addresses that regression by moving the two buffers required for suspend and resume to be deallocated at driver unload instead of post init.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-9vcc-9gv3-fjq8/GHSA-9vcc-9gv3-fjq8.json b/advisories/unreviewed/2024/05/GHSA-9vcc-9gv3-fjq8/GHSA-9vcc-9gv3-fjq8.json index 379bc269cbf..1b2b6647050 100644 --- a/advisories/unreviewed/2024/05/GHSA-9vcc-9gv3-fjq8/GHSA-9vcc-9gv3-fjq8.json +++ b/advisories/unreviewed/2024/05/GHSA-9vcc-9gv3-fjq8/GHSA-9vcc-9gv3-fjq8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-9x6v-hgqm-vvp7/GHSA-9x6v-hgqm-vvp7.json b/advisories/unreviewed/2024/05/GHSA-9x6v-hgqm-vvp7/GHSA-9x6v-hgqm-vvp7.json index aebfe864c9f..269df5f8e24 100644 --- a/advisories/unreviewed/2024/05/GHSA-9x6v-hgqm-vvp7/GHSA-9x6v-hgqm-vvp7.json +++ b/advisories/unreviewed/2024/05/GHSA-9x6v-hgqm-vvp7/GHSA-9x6v-hgqm-vvp7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-9x9h-w57w-jv86/GHSA-9x9h-w57w-jv86.json b/advisories/unreviewed/2024/05/GHSA-9x9h-w57w-jv86/GHSA-9x9h-w57w-jv86.json index 52cae052c0b..fe40e96d149 100644 --- a/advisories/unreviewed/2024/05/GHSA-9x9h-w57w-jv86/GHSA-9x9h-w57w-jv86.json +++ b/advisories/unreviewed/2024/05/GHSA-9x9h-w57w-jv86/GHSA-9x9h-w57w-jv86.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-c4h6-2ghf-2fp8/GHSA-c4h6-2ghf-2fp8.json b/advisories/unreviewed/2024/05/GHSA-c4h6-2ghf-2fp8/GHSA-c4h6-2ghf-2fp8.json index d991677e6bb..a209f71d315 100644 --- a/advisories/unreviewed/2024/05/GHSA-c4h6-2ghf-2fp8/GHSA-c4h6-2ghf-2fp8.json +++ b/advisories/unreviewed/2024/05/GHSA-c4h6-2ghf-2fp8/GHSA-c4h6-2ghf-2fp8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-c562-6qmh-q9qg/GHSA-c562-6qmh-q9qg.json b/advisories/unreviewed/2024/05/GHSA-c562-6qmh-q9qg/GHSA-c562-6qmh-q9qg.json index 54eee9dc0b3..4630ce164af 100644 --- a/advisories/unreviewed/2024/05/GHSA-c562-6qmh-q9qg/GHSA-c562-6qmh-q9qg.json +++ b/advisories/unreviewed/2024/05/GHSA-c562-6qmh-q9qg/GHSA-c562-6qmh-q9qg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-c79h-9pj9-mgqp/GHSA-c79h-9pj9-mgqp.json b/advisories/unreviewed/2024/05/GHSA-c79h-9pj9-mgqp/GHSA-c79h-9pj9-mgqp.json index 2eaa85e73dd..0a2db140ed4 100644 --- a/advisories/unreviewed/2024/05/GHSA-c79h-9pj9-mgqp/GHSA-c79h-9pj9-mgqp.json +++ b/advisories/unreviewed/2024/05/GHSA-c79h-9pj9-mgqp/GHSA-c79h-9pj9-mgqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-c7p9-328q-3x8f/GHSA-c7p9-328q-3x8f.json b/advisories/unreviewed/2024/05/GHSA-c7p9-328q-3x8f/GHSA-c7p9-328q-3x8f.json index 83b3a4bcbe3..623754bd9cd 100644 --- a/advisories/unreviewed/2024/05/GHSA-c7p9-328q-3x8f/GHSA-c7p9-328q-3x8f.json +++ b/advisories/unreviewed/2024/05/GHSA-c7p9-328q-3x8f/GHSA-c7p9-328q-3x8f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-cf96-w592-hc5w/GHSA-cf96-w592-hc5w.json b/advisories/unreviewed/2024/05/GHSA-cf96-w592-hc5w/GHSA-cf96-w592-hc5w.json index e9dbce77234..795f8f3f6d1 100644 --- a/advisories/unreviewed/2024/05/GHSA-cf96-w592-hc5w/GHSA-cf96-w592-hc5w.json +++ b/advisories/unreviewed/2024/05/GHSA-cf96-w592-hc5w/GHSA-cf96-w592-hc5w.json @@ -7,12 +7,8 @@ "CVE-2023-52668" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: zoned: fix lock ordering in btrfs_zone_activate()\n\nThe btrfs CI reported a lockdep warning as follows by running generic\ngeneric/129.\n\n WARNING: possible circular locking dependency detected\n 6.7.0-rc5+ #1 Not tainted\n ------------------------------------------------------\n kworker/u5:5/793427 is trying to acquire lock:\n ffff88813256d028 (&cache->lock){+.+.}-{2:2}, at: btrfs_zone_finish_one_bg+0x5e/0x130\n but task is already holding lock:\n ffff88810a23a318 (&fs_info->zone_active_bgs_lock){+.+.}-{2:2}, at: btrfs_zone_finish_one_bg+0x34/0x130\n which lock already depends on the new lock.\n\n the existing dependency chain (in reverse order) is:\n -> #1 (&fs_info->zone_active_bgs_lock){+.+.}-{2:2}:\n ...\n -> #0 (&cache->lock){+.+.}-{2:2}:\n ...\n\nThis is because we take fs_info->zone_active_bgs_lock after a block_group's\nlock in btrfs_zone_activate() while doing the opposite in other places.\n\nFix the issue by expanding the fs_info->zone_active_bgs_lock's critical\nsection and taking it before a block_group's lock.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-cgcq-r8px-29cj/GHSA-cgcq-r8px-29cj.json b/advisories/unreviewed/2024/05/GHSA-cgcq-r8px-29cj/GHSA-cgcq-r8px-29cj.json index d50edff8772..8a98d105528 100644 --- a/advisories/unreviewed/2024/05/GHSA-cgcq-r8px-29cj/GHSA-cgcq-r8px-29cj.json +++ b/advisories/unreviewed/2024/05/GHSA-cgcq-r8px-29cj/GHSA-cgcq-r8px-29cj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-cjr8-gj3h-wpfp/GHSA-cjr8-gj3h-wpfp.json b/advisories/unreviewed/2024/05/GHSA-cjr8-gj3h-wpfp/GHSA-cjr8-gj3h-wpfp.json index acad0bca101..1ad4db055a6 100644 --- a/advisories/unreviewed/2024/05/GHSA-cjr8-gj3h-wpfp/GHSA-cjr8-gj3h-wpfp.json +++ b/advisories/unreviewed/2024/05/GHSA-cjr8-gj3h-wpfp/GHSA-cjr8-gj3h-wpfp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-cxjp-8rhj-f8c5/GHSA-cxjp-8rhj-f8c5.json b/advisories/unreviewed/2024/05/GHSA-cxjp-8rhj-f8c5/GHSA-cxjp-8rhj-f8c5.json index 8c660cfe328..0357fb2cb9b 100644 --- a/advisories/unreviewed/2024/05/GHSA-cxjp-8rhj-f8c5/GHSA-cxjp-8rhj-f8c5.json +++ b/advisories/unreviewed/2024/05/GHSA-cxjp-8rhj-f8c5/GHSA-cxjp-8rhj-f8c5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-f2w4-4w88-537q/GHSA-f2w4-4w88-537q.json b/advisories/unreviewed/2024/05/GHSA-f2w4-4w88-537q/GHSA-f2w4-4w88-537q.json index 4d18e481b4e..817cb63aa7b 100644 --- a/advisories/unreviewed/2024/05/GHSA-f2w4-4w88-537q/GHSA-f2w4-4w88-537q.json +++ b/advisories/unreviewed/2024/05/GHSA-f2w4-4w88-537q/GHSA-f2w4-4w88-537q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-f3jw-96pp-6m3w/GHSA-f3jw-96pp-6m3w.json b/advisories/unreviewed/2024/05/GHSA-f3jw-96pp-6m3w/GHSA-f3jw-96pp-6m3w.json index af189a8824b..a6c89a36ba6 100644 --- a/advisories/unreviewed/2024/05/GHSA-f3jw-96pp-6m3w/GHSA-f3jw-96pp-6m3w.json +++ b/advisories/unreviewed/2024/05/GHSA-f3jw-96pp-6m3w/GHSA-f3jw-96pp-6m3w.json @@ -7,12 +7,8 @@ "CVE-2024-35858" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bcmasp: fix memory leak when bringing down interface\n\nWhen bringing down the TX rings we flush the rings but forget to\nreclaimed the flushed packets. This leads to a memory leak since we\ndo not free the dma mapped buffers. This also leads to tx control\nblock corruption when bringing down the interface for power\nmanagement.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-f3p6-32mj-fj25/GHSA-f3p6-32mj-fj25.json b/advisories/unreviewed/2024/05/GHSA-f3p6-32mj-fj25/GHSA-f3p6-32mj-fj25.json index de8a9fd264b..ae1d744e8e0 100644 --- a/advisories/unreviewed/2024/05/GHSA-f3p6-32mj-fj25/GHSA-f3p6-32mj-fj25.json +++ b/advisories/unreviewed/2024/05/GHSA-f3p6-32mj-fj25/GHSA-f3p6-32mj-fj25.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-f4c4-g4g8-j6f6/GHSA-f4c4-g4g8-j6f6.json b/advisories/unreviewed/2024/05/GHSA-f4c4-g4g8-j6f6/GHSA-f4c4-g4g8-j6f6.json index 9124e6d2a34..9159e7ebf16 100644 --- a/advisories/unreviewed/2024/05/GHSA-f4c4-g4g8-j6f6/GHSA-f4c4-g4g8-j6f6.json +++ b/advisories/unreviewed/2024/05/GHSA-f4c4-g4g8-j6f6/GHSA-f4c4-g4g8-j6f6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-f7fm-5pq5-rq4p/GHSA-f7fm-5pq5-rq4p.json b/advisories/unreviewed/2024/05/GHSA-f7fm-5pq5-rq4p/GHSA-f7fm-5pq5-rq4p.json index ff66e9bce0b..fdeecf648e3 100644 --- a/advisories/unreviewed/2024/05/GHSA-f7fm-5pq5-rq4p/GHSA-f7fm-5pq5-rq4p.json +++ b/advisories/unreviewed/2024/05/GHSA-f7fm-5pq5-rq4p/GHSA-f7fm-5pq5-rq4p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-ff4w-3r3w-h925/GHSA-ff4w-3r3w-h925.json b/advisories/unreviewed/2024/05/GHSA-ff4w-3r3w-h925/GHSA-ff4w-3r3w-h925.json index c79e05a91e8..adbd8aa5b1e 100644 --- a/advisories/unreviewed/2024/05/GHSA-ff4w-3r3w-h925/GHSA-ff4w-3r3w-h925.json +++ b/advisories/unreviewed/2024/05/GHSA-ff4w-3r3w-h925/GHSA-ff4w-3r3w-h925.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-g5h8-25hr-rhch/GHSA-g5h8-25hr-rhch.json b/advisories/unreviewed/2024/05/GHSA-g5h8-25hr-rhch/GHSA-g5h8-25hr-rhch.json index 25577d08bff..2b9d371ba25 100644 --- a/advisories/unreviewed/2024/05/GHSA-g5h8-25hr-rhch/GHSA-g5h8-25hr-rhch.json +++ b/advisories/unreviewed/2024/05/GHSA-g5h8-25hr-rhch/GHSA-g5h8-25hr-rhch.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-g8hj-4pg6-q26c/GHSA-g8hj-4pg6-q26c.json b/advisories/unreviewed/2024/05/GHSA-g8hj-4pg6-q26c/GHSA-g8hj-4pg6-q26c.json index f66c7a1bdcb..11ade3cc655 100644 --- a/advisories/unreviewed/2024/05/GHSA-g8hj-4pg6-q26c/GHSA-g8hj-4pg6-q26c.json +++ b/advisories/unreviewed/2024/05/GHSA-g8hj-4pg6-q26c/GHSA-g8hj-4pg6-q26c.json @@ -7,12 +7,8 @@ "CVE-2024-27409" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: dw-edma: HDMA: Add sync read before starting the DMA transfer in remote setup\n\nThe Linked list element and pointer are not stored in the same memory as\nthe HDMA controller register. If the doorbell register is toggled before\nthe full write of the linked list a race condition error will occur.\nIn remote setup we can only use a readl to the memory to assure the full\nwrite has occurred.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-g9rf-g2jw-pr5m/GHSA-g9rf-g2jw-pr5m.json b/advisories/unreviewed/2024/05/GHSA-g9rf-g2jw-pr5m/GHSA-g9rf-g2jw-pr5m.json index 832de9c05fe..b85b9079191 100644 --- a/advisories/unreviewed/2024/05/GHSA-g9rf-g2jw-pr5m/GHSA-g9rf-g2jw-pr5m.json +++ b/advisories/unreviewed/2024/05/GHSA-g9rf-g2jw-pr5m/GHSA-g9rf-g2jw-pr5m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-gf77-wgv9-4v74/GHSA-gf77-wgv9-4v74.json b/advisories/unreviewed/2024/05/GHSA-gf77-wgv9-4v74/GHSA-gf77-wgv9-4v74.json index 582c5257850..5682a4e5f5e 100644 --- a/advisories/unreviewed/2024/05/GHSA-gf77-wgv9-4v74/GHSA-gf77-wgv9-4v74.json +++ b/advisories/unreviewed/2024/05/GHSA-gf77-wgv9-4v74/GHSA-gf77-wgv9-4v74.json @@ -7,12 +7,8 @@ "CVE-2024-35792" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: rk3288 - Fix use after free in unprepare\n\nThe unprepare call must be carried out before the finalize call\nas the latter can free the request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gh7x-5rqw-m74q/GHSA-gh7x-5rqw-m74q.json b/advisories/unreviewed/2024/05/GHSA-gh7x-5rqw-m74q/GHSA-gh7x-5rqw-m74q.json index aaa8a6a9526..d284bbf98ea 100644 --- a/advisories/unreviewed/2024/05/GHSA-gh7x-5rqw-m74q/GHSA-gh7x-5rqw-m74q.json +++ b/advisories/unreviewed/2024/05/GHSA-gh7x-5rqw-m74q/GHSA-gh7x-5rqw-m74q.json @@ -7,12 +7,8 @@ "CVE-2023-52682" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to wait on block writeback for post_read case\n\nIf inode is compressed, but not encrypted, it missed to call\nf2fs_wait_on_block_writeback() to wait for GCed page writeback\nin IPU write path.\n\nThread A\t\t\t\tGC-Thread\n\t\t\t\t\t- f2fs_gc\n\t\t\t\t\t - do_garbage_collect\n\t\t\t\t\t - gc_data_segment\n\t\t\t\t\t - move_data_block\n\t\t\t\t\t - f2fs_submit_page_write\n\t\t\t\t\t migrate normal cluster's block via\n\t\t\t\t\t meta_inode's page cache\n- f2fs_write_single_data_page\n - f2fs_do_write_data_page\n - f2fs_inplace_write_data\n - f2fs_submit_page_bio\n\nIRQ\n- f2fs_read_end_io\n\t\t\t\t\tIRQ\n\t\t\t\t\told data overrides new data due to\n\t\t\t\t\tout-of-order GC and common IO.\n\t\t\t\t\t- f2fs_read_end_io", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gjvv-2p97-659w/GHSA-gjvv-2p97-659w.json b/advisories/unreviewed/2024/05/GHSA-gjvv-2p97-659w/GHSA-gjvv-2p97-659w.json index a942a84b84d..4a756057c3e 100644 --- a/advisories/unreviewed/2024/05/GHSA-gjvv-2p97-659w/GHSA-gjvv-2p97-659w.json +++ b/advisories/unreviewed/2024/05/GHSA-gjvv-2p97-659w/GHSA-gjvv-2p97-659w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-gm3q-v8hh-f27h/GHSA-gm3q-v8hh-f27h.json b/advisories/unreviewed/2024/05/GHSA-gm3q-v8hh-f27h/GHSA-gm3q-v8hh-f27h.json index c44296c2c71..88a4113f440 100644 --- a/advisories/unreviewed/2024/05/GHSA-gm3q-v8hh-f27h/GHSA-gm3q-v8hh-f27h.json +++ b/advisories/unreviewed/2024/05/GHSA-gm3q-v8hh-f27h/GHSA-gm3q-v8hh-f27h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-gmm7-m6g9-q9wv/GHSA-gmm7-m6g9-q9wv.json b/advisories/unreviewed/2024/05/GHSA-gmm7-m6g9-q9wv/GHSA-gmm7-m6g9-q9wv.json index a140e27d70c..0978993d1b7 100644 --- a/advisories/unreviewed/2024/05/GHSA-gmm7-m6g9-q9wv/GHSA-gmm7-m6g9-q9wv.json +++ b/advisories/unreviewed/2024/05/GHSA-gmm7-m6g9-q9wv/GHSA-gmm7-m6g9-q9wv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-gqxw-6vwv-vmcv/GHSA-gqxw-6vwv-vmcv.json b/advisories/unreviewed/2024/05/GHSA-gqxw-6vwv-vmcv/GHSA-gqxw-6vwv-vmcv.json index 094a6191606..b3ba353872c 100644 --- a/advisories/unreviewed/2024/05/GHSA-gqxw-6vwv-vmcv/GHSA-gqxw-6vwv-vmcv.json +++ b/advisories/unreviewed/2024/05/GHSA-gqxw-6vwv-vmcv/GHSA-gqxw-6vwv-vmcv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-grmr-5779-p323/GHSA-grmr-5779-p323.json b/advisories/unreviewed/2024/05/GHSA-grmr-5779-p323/GHSA-grmr-5779-p323.json index 007eb5c2718..d1d1c52e456 100644 --- a/advisories/unreviewed/2024/05/GHSA-grmr-5779-p323/GHSA-grmr-5779-p323.json +++ b/advisories/unreviewed/2024/05/GHSA-grmr-5779-p323/GHSA-grmr-5779-p323.json @@ -7,12 +7,8 @@ "CVE-2023-52695" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check writeback connectors in create_validate_stream_for_sink\n\n[WHY & HOW]\nThis is to check connector type to avoid\nunhandled null pointer for writeback connectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gvhq-x742-r9xf/GHSA-gvhq-x742-r9xf.json b/advisories/unreviewed/2024/05/GHSA-gvhq-x742-r9xf/GHSA-gvhq-x742-r9xf.json index f1dc4cc1e84..f15fb1e3c13 100644 --- a/advisories/unreviewed/2024/05/GHSA-gvhq-x742-r9xf/GHSA-gvhq-x742-r9xf.json +++ b/advisories/unreviewed/2024/05/GHSA-gvhq-x742-r9xf/GHSA-gvhq-x742-r9xf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-gx36-99wr-f3mm/GHSA-gx36-99wr-f3mm.json b/advisories/unreviewed/2024/05/GHSA-gx36-99wr-f3mm/GHSA-gx36-99wr-f3mm.json index c65b2dfb62a..1c13f7ff5d9 100644 --- a/advisories/unreviewed/2024/05/GHSA-gx36-99wr-f3mm/GHSA-gx36-99wr-f3mm.json +++ b/advisories/unreviewed/2024/05/GHSA-gx36-99wr-f3mm/GHSA-gx36-99wr-f3mm.json @@ -7,12 +7,8 @@ "CVE-2023-52658" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"net/mlx5: Block entering switchdev mode with ns inconsistency\"\n\nThis reverts commit 662404b24a4c4d839839ed25e3097571f5938b9b.\nThe revert is required due to the suspicion it is not good for anything\nand cause crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-h742-3phr-pg87/GHSA-h742-3phr-pg87.json b/advisories/unreviewed/2024/05/GHSA-h742-3phr-pg87/GHSA-h742-3phr-pg87.json index 70bab55095e..ebc38cc1a06 100644 --- a/advisories/unreviewed/2024/05/GHSA-h742-3phr-pg87/GHSA-h742-3phr-pg87.json +++ b/advisories/unreviewed/2024/05/GHSA-h742-3phr-pg87/GHSA-h742-3phr-pg87.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-hc55-23qr-xx8h/GHSA-hc55-23qr-xx8h.json b/advisories/unreviewed/2024/05/GHSA-hc55-23qr-xx8h/GHSA-hc55-23qr-xx8h.json index 06779971a30..0b0334f134b 100644 --- a/advisories/unreviewed/2024/05/GHSA-hc55-23qr-xx8h/GHSA-hc55-23qr-xx8h.json +++ b/advisories/unreviewed/2024/05/GHSA-hc55-23qr-xx8h/GHSA-hc55-23qr-xx8h.json @@ -7,12 +7,8 @@ "CVE-2023-52661" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/tegra: rgb: Fix missing clk_put() in the error handling paths of tegra_dc_rgb_probe()\n\nIf clk_get_sys(..., \"pll_d2_out0\") fails, the clk_get_sys() call must be\nundone.\n\nAdd the missing clk_put and a new 'put_pll_d_out0' label in the error\nhandling path, and use it.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hg9c-4q92-whw7/GHSA-hg9c-4q92-whw7.json b/advisories/unreviewed/2024/05/GHSA-hg9c-4q92-whw7/GHSA-hg9c-4q92-whw7.json index 4e22cbf1b9b..f73bdec669b 100644 --- a/advisories/unreviewed/2024/05/GHSA-hg9c-4q92-whw7/GHSA-hg9c-4q92-whw7.json +++ b/advisories/unreviewed/2024/05/GHSA-hg9c-4q92-whw7/GHSA-hg9c-4q92-whw7.json @@ -7,12 +7,8 @@ "CVE-2024-35784" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix deadlock with fiemap and extent locking\n\nWhile working on the patchset to remove extent locking I got a lockdep\nsplat with fiemap and pagefaulting with my new extent lock replacement\nlock.\n\nThis deadlock exists with our normal code, we just don't have lockdep\nannotations with the extent locking so we've never noticed it.\n\nSince we're copying the fiemap extent to user space on every iteration\nwe have the chance of pagefaulting. Because we hold the extent lock for\nthe entire range we could mkwrite into a range in the file that we have\nmmap'ed. This would deadlock with the following stack trace\n\n[<0>] lock_extent+0x28d/0x2f0\n[<0>] btrfs_page_mkwrite+0x273/0x8a0\n[<0>] do_page_mkwrite+0x50/0xb0\n[<0>] do_fault+0xc1/0x7b0\n[<0>] __handle_mm_fault+0x2fa/0x460\n[<0>] handle_mm_fault+0xa4/0x330\n[<0>] do_user_addr_fault+0x1f4/0x800\n[<0>] exc_page_fault+0x7c/0x1e0\n[<0>] asm_exc_page_fault+0x26/0x30\n[<0>] rep_movs_alternative+0x33/0x70\n[<0>] _copy_to_user+0x49/0x70\n[<0>] fiemap_fill_next_extent+0xc8/0x120\n[<0>] emit_fiemap_extent+0x4d/0xa0\n[<0>] extent_fiemap+0x7f8/0xad0\n[<0>] btrfs_fiemap+0x49/0x80\n[<0>] __x64_sys_ioctl+0x3e1/0xb50\n[<0>] do_syscall_64+0x94/0x1a0\n[<0>] entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\nI wrote an fstest to reproduce this deadlock without my replacement lock\nand verified that the deadlock exists with our existing locking.\n\nTo fix this simply don't take the extent lock for the entire duration of\nthe fiemap. This is safe in general because we keep track of where we\nare when we're searching the tree, so if an ordered extent updates in\nthe middle of our fiemap call we'll still emit the correct extents\nbecause we know what offset we were on before.\n\nThe only place we maintain the lock is searching delalloc. Since the\ndelalloc stuff can change during writeback we want to lock the extent\nrange so we have a consistent view of delalloc at the time we're\nchecking to see if we need to set the delalloc flag.\n\nWith this patch applied we no longer deadlock with my testcase.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hh8j-q6h7-p5m3/GHSA-hh8j-q6h7-p5m3.json b/advisories/unreviewed/2024/05/GHSA-hh8j-q6h7-p5m3/GHSA-hh8j-q6h7-p5m3.json index 14658ed0d21..646947d1f8d 100644 --- a/advisories/unreviewed/2024/05/GHSA-hh8j-q6h7-p5m3/GHSA-hh8j-q6h7-p5m3.json +++ b/advisories/unreviewed/2024/05/GHSA-hh8j-q6h7-p5m3/GHSA-hh8j-q6h7-p5m3.json @@ -7,12 +7,8 @@ "CVE-2024-27403" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_flow_offload: reset dst in route object after setting up flow\n\ndst is transferred to the flow object, route object does not own it\nanymore. Reset dst in route object, otherwise if flow_offload_add()\nfails, error path releases dst twice, leading to a refcount underflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hj5g-whq8-wmhg/GHSA-hj5g-whq8-wmhg.json b/advisories/unreviewed/2024/05/GHSA-hj5g-whq8-wmhg/GHSA-hj5g-whq8-wmhg.json index e65e32e564b..f8ed3b202f0 100644 --- a/advisories/unreviewed/2024/05/GHSA-hj5g-whq8-wmhg/GHSA-hj5g-whq8-wmhg.json +++ b/advisories/unreviewed/2024/05/GHSA-hj5g-whq8-wmhg/GHSA-hj5g-whq8-wmhg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-hqrx-h9xj-6qqq/GHSA-hqrx-h9xj-6qqq.json b/advisories/unreviewed/2024/05/GHSA-hqrx-h9xj-6qqq/GHSA-hqrx-h9xj-6qqq.json index ed13abd95b6..a21e3c945a8 100644 --- a/advisories/unreviewed/2024/05/GHSA-hqrx-h9xj-6qqq/GHSA-hqrx-h9xj-6qqq.json +++ b/advisories/unreviewed/2024/05/GHSA-hqrx-h9xj-6qqq/GHSA-hqrx-h9xj-6qqq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-hw9q-4579-p566/GHSA-hw9q-4579-p566.json b/advisories/unreviewed/2024/05/GHSA-hw9q-4579-p566/GHSA-hw9q-4579-p566.json index 8ad0c220350..6d944a20a64 100644 --- a/advisories/unreviewed/2024/05/GHSA-hw9q-4579-p566/GHSA-hw9q-4579-p566.json +++ b/advisories/unreviewed/2024/05/GHSA-hw9q-4579-p566/GHSA-hw9q-4579-p566.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-hwvm-hrp8-hmq8/GHSA-hwvm-hrp8-hmq8.json b/advisories/unreviewed/2024/05/GHSA-hwvm-hrp8-hmq8/GHSA-hwvm-hrp8-hmq8.json index 27112b29ca5..30a226e40a5 100644 --- a/advisories/unreviewed/2024/05/GHSA-hwvm-hrp8-hmq8/GHSA-hwvm-hrp8-hmq8.json +++ b/advisories/unreviewed/2024/05/GHSA-hwvm-hrp8-hmq8/GHSA-hwvm-hrp8-hmq8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-j448-fpw2-xvgr/GHSA-j448-fpw2-xvgr.json b/advisories/unreviewed/2024/05/GHSA-j448-fpw2-xvgr/GHSA-j448-fpw2-xvgr.json index 3b9e326ffd5..a81aec2a7ff 100644 --- a/advisories/unreviewed/2024/05/GHSA-j448-fpw2-xvgr/GHSA-j448-fpw2-xvgr.json +++ b/advisories/unreviewed/2024/05/GHSA-j448-fpw2-xvgr/GHSA-j448-fpw2-xvgr.json @@ -7,12 +7,8 @@ "CVE-2023-52692" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: scarlett2: Add missing error check to scarlett2_usb_set_config()\n\nscarlett2_usb_set_config() calls scarlett2_usb_get() but was not\nchecking the result. Return the error if it fails rather than\ncontinuing with an invalid value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-jcw3-r84f-h8jq/GHSA-jcw3-r84f-h8jq.json b/advisories/unreviewed/2024/05/GHSA-jcw3-r84f-h8jq/GHSA-jcw3-r84f-h8jq.json index 98e25f43b56..72a239f51d0 100644 --- a/advisories/unreviewed/2024/05/GHSA-jcw3-r84f-h8jq/GHSA-jcw3-r84f-h8jq.json +++ b/advisories/unreviewed/2024/05/GHSA-jcw3-r84f-h8jq/GHSA-jcw3-r84f-h8jq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-jgvf-4vq4-6744/GHSA-jgvf-4vq4-6744.json b/advisories/unreviewed/2024/05/GHSA-jgvf-4vq4-6744/GHSA-jgvf-4vq4-6744.json index d0ba3718212..9603abe07b3 100644 --- a/advisories/unreviewed/2024/05/GHSA-jgvf-4vq4-6744/GHSA-jgvf-4vq4-6744.json +++ b/advisories/unreviewed/2024/05/GHSA-jgvf-4vq4-6744/GHSA-jgvf-4vq4-6744.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-jhwf-w92w-56f8/GHSA-jhwf-w92w-56f8.json b/advisories/unreviewed/2024/05/GHSA-jhwf-w92w-56f8/GHSA-jhwf-w92w-56f8.json index a0ccb927ce6..c9fe1d15b27 100644 --- a/advisories/unreviewed/2024/05/GHSA-jhwf-w92w-56f8/GHSA-jhwf-w92w-56f8.json +++ b/advisories/unreviewed/2024/05/GHSA-jhwf-w92w-56f8/GHSA-jhwf-w92w-56f8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-jj58-2436-6mc6/GHSA-jj58-2436-6mc6.json b/advisories/unreviewed/2024/05/GHSA-jj58-2436-6mc6/GHSA-jj58-2436-6mc6.json index 9e6da6d414a..98847312155 100644 --- a/advisories/unreviewed/2024/05/GHSA-jj58-2436-6mc6/GHSA-jj58-2436-6mc6.json +++ b/advisories/unreviewed/2024/05/GHSA-jj58-2436-6mc6/GHSA-jj58-2436-6mc6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-jpp4-rwwf-g5qm/GHSA-jpp4-rwwf-g5qm.json b/advisories/unreviewed/2024/05/GHSA-jpp4-rwwf-g5qm/GHSA-jpp4-rwwf-g5qm.json index 530a8d2dbae..99101fa3ea9 100644 --- a/advisories/unreviewed/2024/05/GHSA-jpp4-rwwf-g5qm/GHSA-jpp4-rwwf-g5qm.json +++ b/advisories/unreviewed/2024/05/GHSA-jpp4-rwwf-g5qm/GHSA-jpp4-rwwf-g5qm.json @@ -7,12 +7,8 @@ "CVE-2023-52659" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mm: Ensure input to pfn_to_kaddr() is treated as a 64-bit type\n\nOn 64-bit platforms, the pfn_to_kaddr() macro requires that the input\nvalue is 64 bits in order to ensure that valid address bits don't get\nlost when shifting that input by PAGE_SHIFT to calculate the physical\naddress to provide a virtual address for.\n\nOne such example is in pvalidate_pages() (used by SEV-SNP guests), where\nthe GFN in the struct used for page-state change requests is a 40-bit\nbit-field, so attempts to pass this GFN field directly into\npfn_to_kaddr() ends up causing guest crashes when dealing with addresses\nabove the 1TB range due to the above.\n\nFix this issue with SEV-SNP guests, as well as any similar cases that\nmight cause issues in current/future code, by using an inline function,\ninstead of a macro, so that the input is implicitly cast to the\nexpected 64-bit input type prior to performing the shift operation.\n\nWhile it might be argued that the issue is on the caller side, other\narchs/macros have taken similar approaches to deal with instances like\nthis, such as ARM explicitly casting the input to phys_addr_t:\n\n e48866647b48 (\"ARM: 8396/1: use phys_addr_t in pfn_to_kaddr()\")\n\nA C inline function is even better though.\n\n[ mingo: Refined the changelog some more & added __always_inline. ]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-jw95-5cpm-5722/GHSA-jw95-5cpm-5722.json b/advisories/unreviewed/2024/05/GHSA-jw95-5cpm-5722/GHSA-jw95-5cpm-5722.json index 1395ede8ee7..3992727606b 100644 --- a/advisories/unreviewed/2024/05/GHSA-jw95-5cpm-5722/GHSA-jw95-5cpm-5722.json +++ b/advisories/unreviewed/2024/05/GHSA-jw95-5cpm-5722/GHSA-jw95-5cpm-5722.json @@ -7,12 +7,8 @@ "CVE-2023-52663" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: amd: Fix memory leak in amd_sof_acp_probe()\n\nDriver uses kasprintf() to initialize fw_{code,data}_bin members of\nstruct acp_dev_data, but kfree() is never called to deallocate the\nmemory, which results in a memory leak.\n\nFix the issue by switching to devm_kasprintf(). Additionally, ensure the\nallocation was successful by checking the pointer validity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-m24h-53q9-4m44/GHSA-m24h-53q9-4m44.json b/advisories/unreviewed/2024/05/GHSA-m24h-53q9-4m44/GHSA-m24h-53q9-4m44.json index e53865ee34a..74ac07cb80b 100644 --- a/advisories/unreviewed/2024/05/GHSA-m24h-53q9-4m44/GHSA-m24h-53q9-4m44.json +++ b/advisories/unreviewed/2024/05/GHSA-m24h-53q9-4m44/GHSA-m24h-53q9-4m44.json @@ -7,12 +7,8 @@ "CVE-2024-27432" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: mtk_eth_soc: fix PPE hanging issue\n\nA patch to resolve an issue was found in MediaTek's GPL-licensed SDK:\nIn the mtk_ppe_stop() function, the PPE scan mode is not disabled before\ndisabling the PPE. This can potentially lead to a hang during the process\nof disabling the PPE.\n\nWithout this patch, the PPE may experience a hang during the reboot test.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-m34m-7f6x-5pmq/GHSA-m34m-7f6x-5pmq.json b/advisories/unreviewed/2024/05/GHSA-m34m-7f6x-5pmq/GHSA-m34m-7f6x-5pmq.json index 83df473e089..be6d93bebff 100644 --- a/advisories/unreviewed/2024/05/GHSA-m34m-7f6x-5pmq/GHSA-m34m-7f6x-5pmq.json +++ b/advisories/unreviewed/2024/05/GHSA-m34m-7f6x-5pmq/GHSA-m34m-7f6x-5pmq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-m99v-vmm7-frwm/GHSA-m99v-vmm7-frwm.json b/advisories/unreviewed/2024/05/GHSA-m99v-vmm7-frwm/GHSA-m99v-vmm7-frwm.json index 479ee57a3e4..d768e662a40 100644 --- a/advisories/unreviewed/2024/05/GHSA-m99v-vmm7-frwm/GHSA-m99v-vmm7-frwm.json +++ b/advisories/unreviewed/2024/05/GHSA-m99v-vmm7-frwm/GHSA-m99v-vmm7-frwm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-mcwq-w6hv-xqv4/GHSA-mcwq-w6hv-xqv4.json b/advisories/unreviewed/2024/05/GHSA-mcwq-w6hv-xqv4/GHSA-mcwq-w6hv-xqv4.json index 712453a4bb9..d44c172b4f2 100644 --- a/advisories/unreviewed/2024/05/GHSA-mcwq-w6hv-xqv4/GHSA-mcwq-w6hv-xqv4.json +++ b/advisories/unreviewed/2024/05/GHSA-mcwq-w6hv-xqv4/GHSA-mcwq-w6hv-xqv4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-mqf4-w45q-79ww/GHSA-mqf4-w45q-79ww.json b/advisories/unreviewed/2024/05/GHSA-mqf4-w45q-79ww/GHSA-mqf4-w45q-79ww.json index e2619792d27..2408a9b40b2 100644 --- a/advisories/unreviewed/2024/05/GHSA-mqf4-w45q-79ww/GHSA-mqf4-w45q-79ww.json +++ b/advisories/unreviewed/2024/05/GHSA-mqf4-w45q-79ww/GHSA-mqf4-w45q-79ww.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-mv98-f7mm-q5qq/GHSA-mv98-f7mm-q5qq.json b/advisories/unreviewed/2024/05/GHSA-mv98-f7mm-q5qq/GHSA-mv98-f7mm-q5qq.json index 332551756bd..577edaed7d8 100644 --- a/advisories/unreviewed/2024/05/GHSA-mv98-f7mm-q5qq/GHSA-mv98-f7mm-q5qq.json +++ b/advisories/unreviewed/2024/05/GHSA-mv98-f7mm-q5qq/GHSA-mv98-f7mm-q5qq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-p2hc-4rhj-56fc/GHSA-p2hc-4rhj-56fc.json b/advisories/unreviewed/2024/05/GHSA-p2hc-4rhj-56fc/GHSA-p2hc-4rhj-56fc.json index 66920c9db02..1b8464e105f 100644 --- a/advisories/unreviewed/2024/05/GHSA-p2hc-4rhj-56fc/GHSA-p2hc-4rhj-56fc.json +++ b/advisories/unreviewed/2024/05/GHSA-p2hc-4rhj-56fc/GHSA-p2hc-4rhj-56fc.json @@ -7,12 +7,8 @@ "CVE-2023-52657" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"drm/amd/pm: resolve reboot exception for si oland\"\n\nThis reverts commit e490d60a2f76bff636c68ce4fe34c1b6c34bbd86.\n\nThis causes hangs on SI when DC is enabled and errors on driver\nreboot and power off cycles.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p66v-4j4j-vfw7/GHSA-p66v-4j4j-vfw7.json b/advisories/unreviewed/2024/05/GHSA-p66v-4j4j-vfw7/GHSA-p66v-4j4j-vfw7.json index 1ef118cfd31..9419903acf3 100644 --- a/advisories/unreviewed/2024/05/GHSA-p66v-4j4j-vfw7/GHSA-p66v-4j4j-vfw7.json +++ b/advisories/unreviewed/2024/05/GHSA-p66v-4j4j-vfw7/GHSA-p66v-4j4j-vfw7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-p7h5-86fq-j7r3/GHSA-p7h5-86fq-j7r3.json b/advisories/unreviewed/2024/05/GHSA-p7h5-86fq-j7r3/GHSA-p7h5-86fq-j7r3.json index ab485724967..5db1fc0d03a 100644 --- a/advisories/unreviewed/2024/05/GHSA-p7h5-86fq-j7r3/GHSA-p7h5-86fq-j7r3.json +++ b/advisories/unreviewed/2024/05/GHSA-p7h5-86fq-j7r3/GHSA-p7h5-86fq-j7r3.json @@ -7,12 +7,8 @@ "CVE-2023-52664" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: atlantic: eliminate double free in error handling logic\n\nDriver has a logic leak in ring data allocation/free,\nwhere aq_ring_free could be called multiple times on same ring,\nif system is under stress and got memory allocation error.\n\nRing pointer was used as an indicator of failure, but this is\nnot correct since only ring data is allocated/deallocated.\nRing itself is an array member.\n\nChanging ring allocation functions to return error code directly.\nThis simplifies error handling and eliminates aq_ring_free\non higher layer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p7q7-p9r8-m9q3/GHSA-p7q7-p9r8-m9q3.json b/advisories/unreviewed/2024/05/GHSA-p7q7-p9r8-m9q3/GHSA-p7q7-p9r8-m9q3.json index e57466c4176..6f795a634c6 100644 --- a/advisories/unreviewed/2024/05/GHSA-p7q7-p9r8-m9q3/GHSA-p7q7-p9r8-m9q3.json +++ b/advisories/unreviewed/2024/05/GHSA-p7q7-p9r8-m9q3/GHSA-p7q7-p9r8-m9q3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-p7vx-23x6-fwwc/GHSA-p7vx-23x6-fwwc.json b/advisories/unreviewed/2024/05/GHSA-p7vx-23x6-fwwc/GHSA-p7vx-23x6-fwwc.json index 0f12d62dccb..96c7c4ab4cd 100644 --- a/advisories/unreviewed/2024/05/GHSA-p7vx-23x6-fwwc/GHSA-p7vx-23x6-fwwc.json +++ b/advisories/unreviewed/2024/05/GHSA-p7vx-23x6-fwwc/GHSA-p7vx-23x6-fwwc.json @@ -7,12 +7,8 @@ "CVE-2024-27408" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: dw-edma: eDMA: Add sync read before starting the DMA transfer in remote setup\n\nThe Linked list element and pointer are not stored in the same memory as\nthe eDMA controller register. If the doorbell register is toggled before\nthe full write of the linked list a race condition error will occur.\nIn remote setup we can only use a readl to the memory to assure the full\nwrite has occurred.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p8f7-vf4m-x6j6/GHSA-p8f7-vf4m-x6j6.json b/advisories/unreviewed/2024/05/GHSA-p8f7-vf4m-x6j6/GHSA-p8f7-vf4m-x6j6.json index 52d62d2851a..956dce76e5a 100644 --- a/advisories/unreviewed/2024/05/GHSA-p8f7-vf4m-x6j6/GHSA-p8f7-vf4m-x6j6.json +++ b/advisories/unreviewed/2024/05/GHSA-p8f7-vf4m-x6j6/GHSA-p8f7-vf4m-x6j6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-pf2v-x6jh-mcxq/GHSA-pf2v-x6jh-mcxq.json b/advisories/unreviewed/2024/05/GHSA-pf2v-x6jh-mcxq/GHSA-pf2v-x6jh-mcxq.json index 40161be43ed..adafd120100 100644 --- a/advisories/unreviewed/2024/05/GHSA-pf2v-x6jh-mcxq/GHSA-pf2v-x6jh-mcxq.json +++ b/advisories/unreviewed/2024/05/GHSA-pf2v-x6jh-mcxq/GHSA-pf2v-x6jh-mcxq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-pjq8-j3mp-fhvg/GHSA-pjq8-j3mp-fhvg.json b/advisories/unreviewed/2024/05/GHSA-pjq8-j3mp-fhvg/GHSA-pjq8-j3mp-fhvg.json index d2897165635..7cbebdd42d2 100644 --- a/advisories/unreviewed/2024/05/GHSA-pjq8-j3mp-fhvg/GHSA-pjq8-j3mp-fhvg.json +++ b/advisories/unreviewed/2024/05/GHSA-pjq8-j3mp-fhvg/GHSA-pjq8-j3mp-fhvg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-prmv-r26v-qgx9/GHSA-prmv-r26v-qgx9.json b/advisories/unreviewed/2024/05/GHSA-prmv-r26v-qgx9/GHSA-prmv-r26v-qgx9.json index d300af8231f..fbc05d6eb95 100644 --- a/advisories/unreviewed/2024/05/GHSA-prmv-r26v-qgx9/GHSA-prmv-r26v-qgx9.json +++ b/advisories/unreviewed/2024/05/GHSA-prmv-r26v-qgx9/GHSA-prmv-r26v-qgx9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-pv8w-5hmg-8mf4/GHSA-pv8w-5hmg-8mf4.json b/advisories/unreviewed/2024/05/GHSA-pv8w-5hmg-8mf4/GHSA-pv8w-5hmg-8mf4.json index c151bcef2c2..d40ed126e71 100644 --- a/advisories/unreviewed/2024/05/GHSA-pv8w-5hmg-8mf4/GHSA-pv8w-5hmg-8mf4.json +++ b/advisories/unreviewed/2024/05/GHSA-pv8w-5hmg-8mf4/GHSA-pv8w-5hmg-8mf4.json @@ -7,12 +7,8 @@ "CVE-2024-35793" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndebugfs: fix wait/cancellation handling during remove\n\nBen Greear further reports deadlocks during concurrent debugfs\nremove while files are being accessed, even though the code in\nquestion now uses debugfs cancellations. Turns out that despite\nall the review on the locking, we missed completely that the\nlogic is wrong: if the refcount hits zero we can finish (and\nneed not wait for the completion), but if it doesn't we have\nto trigger all the cancellations. As written, we can _never_\nget into the loop triggering the cancellations. Fix this, and\nexplain it better while at it.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-q4q7-p37f-x9p2/GHSA-q4q7-p37f-x9p2.json b/advisories/unreviewed/2024/05/GHSA-q4q7-p37f-x9p2/GHSA-q4q7-p37f-x9p2.json index 96cda676180..b04307ab626 100644 --- a/advisories/unreviewed/2024/05/GHSA-q4q7-p37f-x9p2/GHSA-q4q7-p37f-x9p2.json +++ b/advisories/unreviewed/2024/05/GHSA-q4q7-p37f-x9p2/GHSA-q4q7-p37f-x9p2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-q8m3-j662-prvh/GHSA-q8m3-j662-prvh.json b/advisories/unreviewed/2024/05/GHSA-q8m3-j662-prvh/GHSA-q8m3-j662-prvh.json index 1242bff1829..b1eca7fe84a 100644 --- a/advisories/unreviewed/2024/05/GHSA-q8m3-j662-prvh/GHSA-q8m3-j662-prvh.json +++ b/advisories/unreviewed/2024/05/GHSA-q8m3-j662-prvh/GHSA-q8m3-j662-prvh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-qp5v-mr8w-r9gw/GHSA-qp5v-mr8w-r9gw.json b/advisories/unreviewed/2024/05/GHSA-qp5v-mr8w-r9gw/GHSA-qp5v-mr8w-r9gw.json index 6fa98caae6a..cd243224ced 100644 --- a/advisories/unreviewed/2024/05/GHSA-qp5v-mr8w-r9gw/GHSA-qp5v-mr8w-r9gw.json +++ b/advisories/unreviewed/2024/05/GHSA-qp5v-mr8w-r9gw/GHSA-qp5v-mr8w-r9gw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-qpfh-8wq3-6fx5/GHSA-qpfh-8wq3-6fx5.json b/advisories/unreviewed/2024/05/GHSA-qpfh-8wq3-6fx5/GHSA-qpfh-8wq3-6fx5.json index 9a33ff4df53..bdb4ac7ae02 100644 --- a/advisories/unreviewed/2024/05/GHSA-qpfh-8wq3-6fx5/GHSA-qpfh-8wq3-6fx5.json +++ b/advisories/unreviewed/2024/05/GHSA-qpfh-8wq3-6fx5/GHSA-qpfh-8wq3-6fx5.json @@ -7,12 +7,8 @@ "CVE-2023-52660" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rkisp1: Fix IRQ handling due to shared interrupts\n\nThe driver requests the interrupts as IRQF_SHARED, so the interrupt\nhandlers can be called at any time. If such a call happens while the ISP\nis powered down, the SoC will hang as the driver tries to access the\nISP registers.\n\nThis can be reproduced even without the platform sharing the IRQ line:\nEnable CONFIG_DEBUG_SHIRQ and unload the driver, and the board will\nhang.\n\nFix this by adding a new field, 'irqs_enabled', which is used to bail\nout from the interrupt handler when the ISP is not operational.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qrm4-m4fg-rjcv/GHSA-qrm4-m4fg-rjcv.json b/advisories/unreviewed/2024/05/GHSA-qrm4-m4fg-rjcv/GHSA-qrm4-m4fg-rjcv.json index 51345b59062..5e1b2a9bfbf 100644 --- a/advisories/unreviewed/2024/05/GHSA-qrm4-m4fg-rjcv/GHSA-qrm4-m4fg-rjcv.json +++ b/advisories/unreviewed/2024/05/GHSA-qrm4-m4fg-rjcv/GHSA-qrm4-m4fg-rjcv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-qvv7-6wf2-wr97/GHSA-qvv7-6wf2-wr97.json b/advisories/unreviewed/2024/05/GHSA-qvv7-6wf2-wr97/GHSA-qvv7-6wf2-wr97.json index 65b72ba0072..808a4a6c937 100644 --- a/advisories/unreviewed/2024/05/GHSA-qvv7-6wf2-wr97/GHSA-qvv7-6wf2-wr97.json +++ b/advisories/unreviewed/2024/05/GHSA-qvv7-6wf2-wr97/GHSA-qvv7-6wf2-wr97.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-r33x-hqm4-h3rc/GHSA-r33x-hqm4-h3rc.json b/advisories/unreviewed/2024/05/GHSA-r33x-hqm4-h3rc/GHSA-r33x-hqm4-h3rc.json index 97ffa0f2773..249f4bab1d1 100644 --- a/advisories/unreviewed/2024/05/GHSA-r33x-hqm4-h3rc/GHSA-r33x-hqm4-h3rc.json +++ b/advisories/unreviewed/2024/05/GHSA-r33x-hqm4-h3rc/GHSA-r33x-hqm4-h3rc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-r486-5wgv-7gjh/GHSA-r486-5wgv-7gjh.json b/advisories/unreviewed/2024/05/GHSA-r486-5wgv-7gjh/GHSA-r486-5wgv-7gjh.json index 1167b6f56c9..3999b31000d 100644 --- a/advisories/unreviewed/2024/05/GHSA-r486-5wgv-7gjh/GHSA-r486-5wgv-7gjh.json +++ b/advisories/unreviewed/2024/05/GHSA-r486-5wgv-7gjh/GHSA-r486-5wgv-7gjh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-rcwh-cv92-f282/GHSA-rcwh-cv92-f282.json b/advisories/unreviewed/2024/05/GHSA-rcwh-cv92-f282/GHSA-rcwh-cv92-f282.json index f6347a2714a..dde7af78f0d 100644 --- a/advisories/unreviewed/2024/05/GHSA-rcwh-cv92-f282/GHSA-rcwh-cv92-f282.json +++ b/advisories/unreviewed/2024/05/GHSA-rcwh-cv92-f282/GHSA-rcwh-cv92-f282.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-rf68-6p49-rhhg/GHSA-rf68-6p49-rhhg.json b/advisories/unreviewed/2024/05/GHSA-rf68-6p49-rhhg/GHSA-rf68-6p49-rhhg.json index f300b273e41..bb6e96aebd7 100644 --- a/advisories/unreviewed/2024/05/GHSA-rf68-6p49-rhhg/GHSA-rf68-6p49-rhhg.json +++ b/advisories/unreviewed/2024/05/GHSA-rf68-6p49-rhhg/GHSA-rf68-6p49-rhhg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-rfx7-w9r4-5hj4/GHSA-rfx7-w9r4-5hj4.json b/advisories/unreviewed/2024/05/GHSA-rfx7-w9r4-5hj4/GHSA-rfx7-w9r4-5hj4.json index 4215fdcfd84..5d5e8881482 100644 --- a/advisories/unreviewed/2024/05/GHSA-rfx7-w9r4-5hj4/GHSA-rfx7-w9r4-5hj4.json +++ b/advisories/unreviewed/2024/05/GHSA-rfx7-w9r4-5hj4/GHSA-rfx7-w9r4-5hj4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-rgfx-ffpf-rhj3/GHSA-rgfx-ffpf-rhj3.json b/advisories/unreviewed/2024/05/GHSA-rgfx-ffpf-rhj3/GHSA-rgfx-ffpf-rhj3.json index 049ba36a9bf..8a79d1a1b09 100644 --- a/advisories/unreviewed/2024/05/GHSA-rgfx-ffpf-rhj3/GHSA-rgfx-ffpf-rhj3.json +++ b/advisories/unreviewed/2024/05/GHSA-rgfx-ffpf-rhj3/GHSA-rgfx-ffpf-rhj3.json @@ -7,12 +7,8 @@ "CVE-2024-35788" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix bounds check for dcn35 DcfClocks\n\n[Why]\nNumFclkLevelsEnabled is used for DcfClocks bounds check\ninstead of designated NumDcfClkLevelsEnabled.\nThat can cause array index out-of-bounds access.\n\n[How]\nUse designated variable for dcn35 DcfClocks bounds check.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-v876-q68f-39fv/GHSA-v876-q68f-39fv.json b/advisories/unreviewed/2024/05/GHSA-v876-q68f-39fv/GHSA-v876-q68f-39fv.json index 149b4bd4da4..6e99150b09c 100644 --- a/advisories/unreviewed/2024/05/GHSA-v876-q68f-39fv/GHSA-v876-q68f-39fv.json +++ b/advisories/unreviewed/2024/05/GHSA-v876-q68f-39fv/GHSA-v876-q68f-39fv.json @@ -7,12 +7,8 @@ "CVE-2024-27434" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: don't set the MFP flag for the GTK\n\nThe firmware doesn't need the MFP flag for the GTK, it can even make the\nfirmware crash. in case the AP is configured with: group cipher TKIP and\nMFPC. We would send the GTK with cipher = TKIP and MFP which is of course\nnot possible.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-v8qq-c98c-j8wf/GHSA-v8qq-c98c-j8wf.json b/advisories/unreviewed/2024/05/GHSA-v8qq-c98c-j8wf/GHSA-v8qq-c98c-j8wf.json index 390a27720c3..c52c0b76930 100644 --- a/advisories/unreviewed/2024/05/GHSA-v8qq-c98c-j8wf/GHSA-v8qq-c98c-j8wf.json +++ b/advisories/unreviewed/2024/05/GHSA-v8qq-c98c-j8wf/GHSA-v8qq-c98c-j8wf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-vj9c-27hg-w432/GHSA-vj9c-27hg-w432.json b/advisories/unreviewed/2024/05/GHSA-vj9c-27hg-w432/GHSA-vj9c-27hg-w432.json index 3ce893f584d..4eee527b86a 100644 --- a/advisories/unreviewed/2024/05/GHSA-vj9c-27hg-w432/GHSA-vj9c-27hg-w432.json +++ b/advisories/unreviewed/2024/05/GHSA-vj9c-27hg-w432/GHSA-vj9c-27hg-w432.json @@ -7,12 +7,8 @@ "CVE-2024-27433" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: mediatek: mt7622-apmixedsys: Fix an error handling path in clk_mt8135_apmixed_probe()\n\n'clk_data' is allocated with mtk_devm_alloc_clk_data(). So calling\nmtk_free_clk_data() explicitly in the remove function would lead to a\ndouble-free.\n\nRemove the redundant call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-vw6h-3mr6-jprc/GHSA-vw6h-3mr6-jprc.json b/advisories/unreviewed/2024/05/GHSA-vw6h-3mr6-jprc/GHSA-vw6h-3mr6-jprc.json index 84edbfcc278..e9d8d7f1ee8 100644 --- a/advisories/unreviewed/2024/05/GHSA-vw6h-3mr6-jprc/GHSA-vw6h-3mr6-jprc.json +++ b/advisories/unreviewed/2024/05/GHSA-vw6h-3mr6-jprc/GHSA-vw6h-3mr6-jprc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-vwv8-8wch-7m4g/GHSA-vwv8-8wch-7m4g.json b/advisories/unreviewed/2024/05/GHSA-vwv8-8wch-7m4g/GHSA-vwv8-8wch-7m4g.json index 5cf3bbdec34..a8cc92efff7 100644 --- a/advisories/unreviewed/2024/05/GHSA-vwv8-8wch-7m4g/GHSA-vwv8-8wch-7m4g.json +++ b/advisories/unreviewed/2024/05/GHSA-vwv8-8wch-7m4g/GHSA-vwv8-8wch-7m4g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-w32p-xp8f-5vqc/GHSA-w32p-xp8f-5vqc.json b/advisories/unreviewed/2024/05/GHSA-w32p-xp8f-5vqc/GHSA-w32p-xp8f-5vqc.json index 82ff887c8fb..b4f59919963 100644 --- a/advisories/unreviewed/2024/05/GHSA-w32p-xp8f-5vqc/GHSA-w32p-xp8f-5vqc.json +++ b/advisories/unreviewed/2024/05/GHSA-w32p-xp8f-5vqc/GHSA-w32p-xp8f-5vqc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-w36h-73v6-wg8q/GHSA-w36h-73v6-wg8q.json b/advisories/unreviewed/2024/05/GHSA-w36h-73v6-wg8q/GHSA-w36h-73v6-wg8q.json index 84a04647e24..25b2489dc5c 100644 --- a/advisories/unreviewed/2024/05/GHSA-w36h-73v6-wg8q/GHSA-w36h-73v6-wg8q.json +++ b/advisories/unreviewed/2024/05/GHSA-w36h-73v6-wg8q/GHSA-w36h-73v6-wg8q.json @@ -7,12 +7,8 @@ "CVE-2024-35786" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau: fix stale locked mutex in nouveau_gem_ioctl_pushbuf\n\nIf VM_BIND is enabled on the client the legacy submission ioctl can't be\nused, however if a client tries to do so regardless it will return an\nerror. In this case the clients mutex remained unlocked leading to a\ndeadlock inside nouveau_drm_postclose or any other nouveau ioctl call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-w75q-q662-m9v3/GHSA-w75q-q662-m9v3.json b/advisories/unreviewed/2024/05/GHSA-w75q-q662-m9v3/GHSA-w75q-q662-m9v3.json index 686cf7ec527..69a10d82476 100644 --- a/advisories/unreviewed/2024/05/GHSA-w75q-q662-m9v3/GHSA-w75q-q662-m9v3.json +++ b/advisories/unreviewed/2024/05/GHSA-w75q-q662-m9v3/GHSA-w75q-q662-m9v3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-w8v2-xq2g-x7q2/GHSA-w8v2-xq2g-x7q2.json b/advisories/unreviewed/2024/05/GHSA-w8v2-xq2g-x7q2/GHSA-w8v2-xq2g-x7q2.json index f571eb9cb8b..db5503a816f 100644 --- a/advisories/unreviewed/2024/05/GHSA-w8v2-xq2g-x7q2/GHSA-w8v2-xq2g-x7q2.json +++ b/advisories/unreviewed/2024/05/GHSA-w8v2-xq2g-x7q2/GHSA-w8v2-xq2g-x7q2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-wc2h-7hh3-87g6/GHSA-wc2h-7hh3-87g6.json b/advisories/unreviewed/2024/05/GHSA-wc2h-7hh3-87g6/GHSA-wc2h-7hh3-87g6.json index 2daba24042f..3e2bf73c978 100644 --- a/advisories/unreviewed/2024/05/GHSA-wc2h-7hh3-87g6/GHSA-wc2h-7hh3-87g6.json +++ b/advisories/unreviewed/2024/05/GHSA-wc2h-7hh3-87g6/GHSA-wc2h-7hh3-87g6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-wf84-8c7c-pxc6/GHSA-wf84-8c7c-pxc6.json b/advisories/unreviewed/2024/05/GHSA-wf84-8c7c-pxc6/GHSA-wf84-8c7c-pxc6.json index 3ad47541b6f..1cb6c2e81d5 100644 --- a/advisories/unreviewed/2024/05/GHSA-wf84-8c7c-pxc6/GHSA-wf84-8c7c-pxc6.json +++ b/advisories/unreviewed/2024/05/GHSA-wf84-8c7c-pxc6/GHSA-wf84-8c7c-pxc6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-wmx4-9pgv-5565/GHSA-wmx4-9pgv-5565.json b/advisories/unreviewed/2024/05/GHSA-wmx4-9pgv-5565/GHSA-wmx4-9pgv-5565.json index ac06a3739b7..2c363b875b4 100644 --- a/advisories/unreviewed/2024/05/GHSA-wmx4-9pgv-5565/GHSA-wmx4-9pgv-5565.json +++ b/advisories/unreviewed/2024/05/GHSA-wmx4-9pgv-5565/GHSA-wmx4-9pgv-5565.json @@ -7,12 +7,8 @@ "CVE-2024-35794" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-raid: really frozen sync_thread during suspend\n\n1) commit f52f5c71f3d4 (\"md: fix stopping sync thread\") remove\n MD_RECOVERY_FROZEN from __md_stop_writes() and doesn't realize that\n dm-raid relies on __md_stop_writes() to frozen sync_thread\n indirectly. Fix this problem by adding MD_RECOVERY_FROZEN in\n md_stop_writes(), and since stop_sync_thread() is only used for\n dm-raid in this case, also move stop_sync_thread() to\n md_stop_writes().\n2) The flag MD_RECOVERY_FROZEN doesn't mean that sync thread is frozen,\n it only prevent new sync_thread to start, and it can't stop the\n running sync thread; In order to frozen sync_thread, after seting the\n flag, stop_sync_thread() should be used.\n3) The flag MD_RECOVERY_FROZEN doesn't mean that writes are stopped, use\n it as condition for md_stop_writes() in raid_postsuspend() doesn't\n look correct. Consider that reentrant stop_sync_thread() do nothing,\n always call md_stop_writes() in raid_postsuspend().\n4) raid_message can set/clear the flag MD_RECOVERY_FROZEN at anytime,\n and if MD_RECOVERY_FROZEN is cleared while the array is suspended,\n new sync_thread can start unexpected. Fix this by disallow\n raid_message() to change sync_thread status during suspend.\n\nNote that after commit f52f5c71f3d4 (\"md: fix stopping sync thread\"), the\ntest shell/lvconvert-raid-reshape.sh start to hang in stop_sync_thread(),\nand with previous fixes, the test won't hang there anymore, however, the\ntest will still fail and complain that ext4 is corrupted. And with this\npatch, the test won't hang due to stop_sync_thread() or fail due to ext4\nis corrupted anymore. However, there is still a deadlock related to\ndm-raid456 that will be fixed in following patches.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-wr6q-54pc-3f46/GHSA-wr6q-54pc-3f46.json b/advisories/unreviewed/2024/05/GHSA-wr6q-54pc-3f46/GHSA-wr6q-54pc-3f46.json index 8b41b42a4ff..b51832a0b61 100644 --- a/advisories/unreviewed/2024/05/GHSA-wr6q-54pc-3f46/GHSA-wr6q-54pc-3f46.json +++ b/advisories/unreviewed/2024/05/GHSA-wr6q-54pc-3f46/GHSA-wr6q-54pc-3f46.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-ww5r-g6pm-54rj/GHSA-ww5r-g6pm-54rj.json b/advisories/unreviewed/2024/05/GHSA-ww5r-g6pm-54rj/GHSA-ww5r-g6pm-54rj.json index e2ae464aeb9..8c5038b2cef 100644 --- a/advisories/unreviewed/2024/05/GHSA-ww5r-g6pm-54rj/GHSA-ww5r-g6pm-54rj.json +++ b/advisories/unreviewed/2024/05/GHSA-ww5r-g6pm-54rj/GHSA-ww5r-g6pm-54rj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-x3cp-9cgr-m6gc/GHSA-x3cp-9cgr-m6gc.json b/advisories/unreviewed/2024/05/GHSA-x3cp-9cgr-m6gc/GHSA-x3cp-9cgr-m6gc.json index 6632514667f..5495d579d13 100644 --- a/advisories/unreviewed/2024/05/GHSA-x3cp-9cgr-m6gc/GHSA-x3cp-9cgr-m6gc.json +++ b/advisories/unreviewed/2024/05/GHSA-x3cp-9cgr-m6gc/GHSA-x3cp-9cgr-m6gc.json @@ -7,12 +7,8 @@ "CVE-2024-35804" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Mark target gfn of emulated atomic instruction as dirty\n\nWhen emulating an atomic access on behalf of the guest, mark the target\ngfn dirty if the CMPXCHG by KVM is attempted and doesn't fault. This\nfixes a bug where KVM effectively corrupts guest memory during live\nmigration by writing to guest memory without informing userspace that the\npage is dirty.\n\nMarking the page dirty got unintentionally dropped when KVM's emulated\nCMPXCHG was converted to do a user access. Before that, KVM explicitly\nmapped the guest page into kernel memory, and marked the page dirty during\nthe unmap phase.\n\nMark the page dirty even if the CMPXCHG fails, as the old data is written\nback on failure, i.e. the page is still written. The value written is\nguaranteed to be the same because the operation is atomic, but KVM's ABI\nis that all writes are dirty logged regardless of the value written. And\nmore importantly, that's what KVM did before the buggy commit.\n\nHuge kudos to the folks on the Cc list (and many others), who did all the\nactual work of triaging and debugging.\n\nbase-commit: 6769ea8da8a93ed4630f1ce64df6aafcaabfce64", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-x43h-289c-p8r5/GHSA-x43h-289c-p8r5.json b/advisories/unreviewed/2024/05/GHSA-x43h-289c-p8r5/GHSA-x43h-289c-p8r5.json index d2cabacbd3c..52523dad924 100644 --- a/advisories/unreviewed/2024/05/GHSA-x43h-289c-p8r5/GHSA-x43h-289c-p8r5.json +++ b/advisories/unreviewed/2024/05/GHSA-x43h-289c-p8r5/GHSA-x43h-289c-p8r5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-x5m5-jxc3-3g5c/GHSA-x5m5-jxc3-3g5c.json b/advisories/unreviewed/2024/05/GHSA-x5m5-jxc3-3g5c/GHSA-x5m5-jxc3-3g5c.json index bf50330d098..b1f325af833 100644 --- a/advisories/unreviewed/2024/05/GHSA-x5m5-jxc3-3g5c/GHSA-x5m5-jxc3-3g5c.json +++ b/advisories/unreviewed/2024/05/GHSA-x5m5-jxc3-3g5c/GHSA-x5m5-jxc3-3g5c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-xjhx-x9fp-x5mx/GHSA-xjhx-x9fp-x5mx.json b/advisories/unreviewed/2024/05/GHSA-xjhx-x9fp-x5mx/GHSA-xjhx-x9fp-x5mx.json index 7c9681ea52d..d94c7f485f6 100644 --- a/advisories/unreviewed/2024/05/GHSA-xjhx-x9fp-x5mx/GHSA-xjhx-x9fp-x5mx.json +++ b/advisories/unreviewed/2024/05/GHSA-xjhx-x9fp-x5mx/GHSA-xjhx-x9fp-x5mx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-xmjc-7969-ffgm/GHSA-xmjc-7969-ffgm.json b/advisories/unreviewed/2024/05/GHSA-xmjc-7969-ffgm/GHSA-xmjc-7969-ffgm.json index 916c0f19f27..581fdf0b65f 100644 --- a/advisories/unreviewed/2024/05/GHSA-xmjc-7969-ffgm/GHSA-xmjc-7969-ffgm.json +++ b/advisories/unreviewed/2024/05/GHSA-xmjc-7969-ffgm/GHSA-xmjc-7969-ffgm.json @@ -7,12 +7,8 @@ "CVE-2024-35834" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: recycle buffer in case Rx queue was full\n\nAdd missing xsk_buff_free() call when __xsk_rcv_zc() failed to produce\ndescriptor to XSK Rx queue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xp92-3q3c-qcqj/GHSA-xp92-3q3c-qcqj.json b/advisories/unreviewed/2024/05/GHSA-xp92-3q3c-qcqj/GHSA-xp92-3q3c-qcqj.json index 96b839b1d3f..917bb9e2d87 100644 --- a/advisories/unreviewed/2024/05/GHSA-xp92-3q3c-qcqj/GHSA-xp92-3q3c-qcqj.json +++ b/advisories/unreviewed/2024/05/GHSA-xp92-3q3c-qcqj/GHSA-xp92-3q3c-qcqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-xpqv-f82r-327v/GHSA-xpqv-f82r-327v.json b/advisories/unreviewed/2024/05/GHSA-xpqv-f82r-327v/GHSA-xpqv-f82r-327v.json index dc42c34b044..1fdda3ad07c 100644 --- a/advisories/unreviewed/2024/05/GHSA-xpqv-f82r-327v/GHSA-xpqv-f82r-327v.json +++ b/advisories/unreviewed/2024/05/GHSA-xpqv-f82r-327v/GHSA-xpqv-f82r-327v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-xq4p-6j59-jfv4/GHSA-xq4p-6j59-jfv4.json b/advisories/unreviewed/2024/05/GHSA-xq4p-6j59-jfv4/GHSA-xq4p-6j59-jfv4.json index 52e8275ce69..53f2140f08c 100644 --- a/advisories/unreviewed/2024/05/GHSA-xq4p-6j59-jfv4/GHSA-xq4p-6j59-jfv4.json +++ b/advisories/unreviewed/2024/05/GHSA-xq4p-6j59-jfv4/GHSA-xq4p-6j59-jfv4.json @@ -7,12 +7,8 @@ "CVE-2024-35790" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: altmodes/displayport: create sysfs nodes as driver's default device attribute group\n\nThe DisplayPort driver's sysfs nodes may be present to the userspace before\ntypec_altmode_set_drvdata() completes in dp_altmode_probe. This means that\na sysfs read can trigger a NULL pointer error by deferencing dp->hpd in\nhpd_show or dp->lock in pin_assignment_show, as dev_get_drvdata() returns\nNULL in those cases.\n\nRemove manual sysfs node creation in favor of adding attribute group as\ndefault for devices bound to the driver. The ATTRIBUTE_GROUPS() macro is\nnot used here otherwise the path to the sysfs nodes is no longer compliant\nwith the ABI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-37f5-2pjr-46xw/GHSA-37f5-2pjr-46xw.json b/advisories/unreviewed/2024/06/GHSA-37f5-2pjr-46xw/GHSA-37f5-2pjr-46xw.json index 8e439aad670..ee55abf1663 100644 --- a/advisories/unreviewed/2024/06/GHSA-37f5-2pjr-46xw/GHSA-37f5-2pjr-46xw.json +++ b/advisories/unreviewed/2024/06/GHSA-37f5-2pjr-46xw/GHSA-37f5-2pjr-46xw.json @@ -7,12 +7,8 @@ "CVE-2024-24550" ], "details": "A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which leads to arbitrary code execution on the server. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-628q-5gqp-mr86/GHSA-628q-5gqp-mr86.json b/advisories/unreviewed/2024/06/GHSA-628q-5gqp-mr86/GHSA-628q-5gqp-mr86.json index bab7a45fd64..c7c17858911 100644 --- a/advisories/unreviewed/2024/06/GHSA-628q-5gqp-mr86/GHSA-628q-5gqp-mr86.json +++ b/advisories/unreviewed/2024/06/GHSA-628q-5gqp-mr86/GHSA-628q-5gqp-mr86.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-7xr5-w5mj-r2jm/GHSA-7xr5-w5mj-r2jm.json b/advisories/unreviewed/2024/06/GHSA-7xr5-w5mj-r2jm/GHSA-7xr5-w5mj-r2jm.json index 5b8bbb96a74..c178c153232 100644 --- a/advisories/unreviewed/2024/06/GHSA-7xr5-w5mj-r2jm/GHSA-7xr5-w5mj-r2jm.json +++ b/advisories/unreviewed/2024/06/GHSA-7xr5-w5mj-r2jm/GHSA-7xr5-w5mj-r2jm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-cg88-8hv4-jpxm/GHSA-cg88-8hv4-jpxm.json b/advisories/unreviewed/2024/06/GHSA-cg88-8hv4-jpxm/GHSA-cg88-8hv4-jpxm.json index 4e2e6674ac5..02029fd0ada 100644 --- a/advisories/unreviewed/2024/06/GHSA-cg88-8hv4-jpxm/GHSA-cg88-8hv4-jpxm.json +++ b/advisories/unreviewed/2024/06/GHSA-cg88-8hv4-jpxm/GHSA-cg88-8hv4-jpxm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-cv9m-q4c9-4vr9/GHSA-cv9m-q4c9-4vr9.json b/advisories/unreviewed/2024/06/GHSA-cv9m-q4c9-4vr9/GHSA-cv9m-q4c9-4vr9.json index 7d233e6fb3a..4d1eafb13f3 100644 --- a/advisories/unreviewed/2024/06/GHSA-cv9m-q4c9-4vr9/GHSA-cv9m-q4c9-4vr9.json +++ b/advisories/unreviewed/2024/06/GHSA-cv9m-q4c9-4vr9/GHSA-cv9m-q4c9-4vr9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",